Dark mode: ON

Infosec Decoded Season 6 #5: Big Brother

With sambowne@infosec.exchange and Doug Spindler

Recorded Fri, Jan 30, 2026

AI

OnlyFans Rival Seemingly Succumbs to AI Psychosis, Which We Dare You to Try Explain to Your Parents
ManyVids is an OnlyFans-like porn platform with millions of users. For roughly the past half-year, its official account on X and on its own website have been posting bizarre, feverishly spiritual rants on topics ranging from aliens to numerology, along with absurd AI-generated images and videos that depict its CEO Bella French. French is suffering from AI psychosis.
Hackers hijack exposed LLM endpoints in Bizarre Bazaar operation
A malicious campaign is actively targeting exposed LLM (Large Language Model) service endpoints to commercialize unauthorized access to AI infrastructure, and:
  • Steal computing resources for cryptocurrency mining
  • Resell API access on darknet markets
  • Exfiltrate data from prompts and conversation history,
  • Attempt to pivot into internal systems via Model Context Protocol (MCP) servers
Users flock to open source Moltbot for always-on AI, despite major risks
The open source “Jarvis” chats via WhatsApp but requires access to your files and accounts. The assistant works with WhatsApp, Telegram, Slack, Discord, Google Chat, Signal, iMessage, Microsoft Teams, and other platforms. It can reach out to users with reminders, alerts, or morning briefings based on calendar events or other triggers.

Heavy use can rack up significant API costs, since agentic systems make many calls behind the scenes and use up a lot of tokens.

Viral Moltbot AI assistant raises concerns over data security
Because Clawdbot auto-approves “local” connections, deployments behind reverse proxies often treat all internet traffic as trusted, so many exposed instances allow unauthenticated access, credential theft, access to conversation history, command execution, and root-level system access.

There is no sandboxing for the AI assistant by default. Risks include exposed gateways and API/OAuth tokens, plaintext storage credentials under ~/.clawdbot/, corporate data leakage via AI-mediated access, and an extended prompt-injection attack surface.

I don’t need Perplexity anymore because my local LLM does it better
AI Is Causing Cultural Stagnation, Researchers Find
A text-to-image generator, when linked up with an image-to-text system and instructed to iterate over and over again, eventually converges on “very generic-looking images” they dubbed “visual elevator music.”

“This finding reveals that, even without additional training, autonomous AI feedback loops naturally drift toward common attractors,” they wrote. “Human-AI collaboration, rather than fully autonomous creation, may be essential to preserve variety and surprise in the increasingly machine-generated creative landscape.”

The CEO of Microsoft Suddenly Sounds Extremely Nervous About AI
The “tell-tale sign of if it’s a bubble,” would be if only tech companies were benefitting from the rise of AI.
'Ralph Wiggum' loop prompts Claude to vibe-clone commercial software for $10 an hour
Here's the script :
while :; do cat PROMPT.md | claude-code ; done
Huntley describes the software as "a bash loop that feeds an AI's output (errors and all) back into itself until it dreams up the correct answer. It is brute force meets persistence." He thinks this will replace developers and only cost $10 per hour.
Free OpenAI tool for scientists stokes worries of more "AI slop" in journals
New “Prism” workspace launches just as studies show AI-assisted papers are flooding journals with diminished quality.
Massive AI Chat App Leaked Millions of Users Private Conversations
The issue is a misconfiguration in the app’s usage of the mobile app development platform Google Firebase, which by default makes it easy for anyone to make themselves an “authenticated” user who can access the app’s backend storage where in many instances user data is stored.

The company fixed the issue across all of its apps within hours, according to Harry.

Politics

Fascism

ICE Is Going on a Surveillance Shopping Spree
They have a massively increased budget, and are buying:
  • Cellebrite service to extract data from seized phones
  • Paragon's Graphite phone-hacking software
  • Webloc and Tangles to gather data from data brokers and social media to build dossiers of targets, including historic and current locations without a need for a warrant
Our concern with ICE buying this software is the likelihood that it will be used against undocumented people and immigrants who are here legally, as well as U.S. citizens who have spoken up against ICE or who work with immigrant communities.
Saudi dissident awarded $4.1 million by UK court for hacking, assault 'by Saudi Arabia'
Ghanem Al-Masarir, whose YouTube channels featuring criticism of the Saudi government have been viewed millions of times, sued Saudi Arabia in 2019, alleging the kingdom used Pegasus spyware to hack his mobile phones in June 2018.
Fleeing TikTokers Claim MAGA Makeover Is ‘Silencing’ Them
Booz Allen Tech Contractor Took IRS Job Specifically to Leak Trump's Tax Records
The US Treasury Department announced yesterday that it was canceling all contracts it holds with consulting firm Booz Allen Hamilton because the company failed to prevent one of its contractors, Charles Littlejohn, from stealing and leaking Trump's tax records years ago.

This is the first time I'm aware that a major federal agency has cancelled significant government contracts over an infosec leak. Even after another Booz Allen contractor – Edward Snowden – stole and leaked a massive cache of documents he downloaded from computers belonging to the National Security Agency, Booz Allen retained its federal contracts with the spy agency.

Both Littlejohn and Snowden said they took the jobs at Booz Allen Hamilton specifically in order to gain access to documents and leak them.

“This Is a Warning”: ICE Agents Follow Protesters Home
Creators of Project 2025 Want to Send Unmarried People to Camps
The camps would serve as reeducation centers for unmarried couples. “Successful completion of the program would mean that couples are ready to walk down the aisle at a communal wedding by the end of the bootcamp.”
Bari Weiss’s new CBS hires include ‘germ theory denialist’ doctor
Mark Carney Took the Stand the Rest of the World Must Now Take
When history is written, I believe this may be remembered as the anti-Chamberlain moment: a leader of a (relatively) powerless nation throwing down the gauntlet and proposing to the democracies of the world that they band together as a unified front against a juvenile, narcissistic would-be hegemon who has never been effectively stood up to in his pampered life.

Other Politics

$40m rights, $35m marketing: Melania Trump documentary sells just one ticket in UK cinemas; netizens call it 'failure'
Indian 'hackers for hire' to continue to thrive under Brussels-New Dehli trade deal
Hot New App Makes Single People Check in Constantly in Case They Die Alone
The app — with the evocative name of “Are You Dead?” — is the most downloaded paid app in the People’s Republic.
“IG is a drug”: Internal messages may doom Meta at social media addiction trial
More than 1,000 personal injury lawsuits against Meta say it causes anxiety, depression, eating disorders, and death in kids.

Facebook internal documents revealed that they know "IG is a drug" causing addiction and harm to kids, and deliberately designed it to maximize this effect.

The Most Effective Treatment for Osteoarthritis Isn’t a Pill or Surgery
It's exercise.
Many UK Users Soon Won't Be Able to Access Pornhub
After six months of complying with the UK’s Online Safety Act, it’s made the choice to restrict access in the country entirely. They say this is because the law requiring age-gating is failing.
China executes 11 members of Myanmar scam mafia
Hundreds of thousands of people have been trafficked to run online scams in Myanmar and elsewhere in South East Asia, according to estimates by the UN. Among them are thousands of Chinese people, and their victims who they swindle billions of dollars from are mainly Chinese too.

Frustrated by the Myanmar military's refusal to stop the scam business, from which it was almost certainly profiting, Beijing tacitly backed an offensive by an ethnic insurgent alliance in Shan State in late 2023.

Infosec

App for Quitting Porn Leaked Users' Masturbation Habits
The issue is a misconfiguration in the app’s usage of the mobile app development platform Google Firebase, which by default makes it easy for anyone to make themselves an “authenticated” user who can access the app’s backend storage where in many instances user data is stored.

The developer has not fixed the issue.

Google takes down massive shady network that was secretly running on millions of Android phones
Google has taken down what it believes to be the world’s largest residential proxy network. Most people end up on Ipidea’s network by installing free apps, games, or desktop software that secretly include proxy code.