Ep. 80 - The AI Harness That Never Checked Its Work: Absence of Evidence Isn't Evidence of Absence
An AI orchestration harness called SecFlow told itself an exploit had worked—then burned 27 follow-on tasks on a foothold that never existed. Host Tova Dvorin and offensive security expert Adrian Culley unpack http://Hunt.io's SecFlow research and Lumen Black Lotus Labs' "Infrastructure Quartermaster" reporting: rented recon and relay infrastructure, LSASS credential dumping inside a government network, steganographic web shells, and the mirror image in your SOC—an AI-written Sigma rule that compiles is not a detection that fires.
00:00 Absence of evidence is not evidence of absence
00:44 What SecFlow is and how it failed?
02:39 The mirror image in detection engineering
05:39 The Infrastructure Quartermaster
06:58 The SecFlow operator and its targets
08:18 GLUTTON, steganographic web shells and the CVEs
11:37 Three Monday morning questions for a SOC lead
13:10 Evaluating AI offensive tooling
14:30 What to watch over the next twelve months
🔗 RESOURCES & LINKS MENTIONED
Hunt.io: Chinese-speaking operator uses AI agents to target government and education systems across Asia: https://hunt.io/blog/chinese-operator-secflow-claude-qwen-deepseek-asia
Lumen Black Lotus Labs: The Infrastructure Quartermaster, inside a China-nexus state enablement model: https://www.lumen.com/blog/en-us/the-infrastructure-quartermaster-inside-a-china-nexus-state-enablement-model
CVE-2016-4437, Apache Shiro rememberMe deserialization: https://nvd.nist.gov/vuln/detail/CVE-2016-4437
CVE-2021-44228, Log4Shell: https://nvd.nist.gov/vuln/detail/CVE-2021-44228
CISA guidance on PRC state-sponsored cyber activity: https://www.cisa.gov/topics/cyber-threats-and-advisories/nation-state-cyber-actors/china
Listen to Ep. 77 - The Scan Factory: Inside China's Industrial Exploitation Business: https://open.spotify.com/episode/3AVeo4O9tP4YN15xzakxjM
#cybersecurity #infosec #CISO #DetectionEngineering #AIsecurity #CTEM #ThreatIntel #BAS