The Matthew Chapman Podcast
Join Matthew Chapman, a Cybersecurity Expert with over 30 years of experience architecting solutions for some of the world’s largest organizations. Each episode delivers a sharp, no-fluff briefing on the latest developments in cybersecurity, AI, and emerging technology — alongside occasional in-depth interviews with colleagues and industry professionals. Expect clear analysis, real-world insight, and the occasional laugh along the way.
The Matthew Chapman Podcast
Malicious .git Configs Make AI Coding Agents Run Attacker Code
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Here is your briefing for Thursday, September 3, 2026. Manifold Security disclosed eight flaws across seven command-line A.I. coding agents under the name GitSpawn. A repository's own .git config can name a command the agent runs as you, outside the sandbox, with no approval prompt. Ordinary clone is fine. A shared archive, sync folder, or U.S.B. stick that keeps the .git directory intact is the delivery path. The sink is core.fsmonitor, a Git performance setting that fires on git status and git diff. Agents call those in the background at session start, so the payload can run before the model is even contacted. Fixes shipped for goose, Claude Code's main path, and Cursor. Hermes Agent, Qwen Code, Grok Build, and a second Claude Code path were still live when Manifold retested on September first. OpenAI published three C.V.E.s the same day for the same class in Codex. Inspect .git/config before you open a received directory with an agent, or force fsmonitor off globally. Virtualizor says attackers used a B.G.P. hijack to divert Softaculous update traffic from August twenty-eighth through the thirtieth. Diverted installs got a malicious package because the update client had no cryptographic package signing, and the attackers even minted a valid Let's Encrypt cert so nothing looked wrong in the browser. One hosting provider found five of thirty-four hypervisors with root-level compromise: injected Virtualizor files, a root cron, a systemd persistence service, and an unauthorized proxyuser account. Virtualizor released Patch nine with a Security Analyzer, but package signing is still future work. Every operator should run the scanner, rotate A.P.I. keys, and treat a clean rebuild as the only trustworthy recovery after confirmed root. Your update channel is part of your supply chain, even when the domain looks right. The researcher known as Chaotic Eclipse dropped FalconFlank, a zero-day privilege escalation PoC against CrowdStrike Falcon. It abuses the sensor's Office malicious-macros remediation path, and the researcher says it works on fully updated Windows eleven twenty-five H two and Windows Server twenty twenty-five with Falcon installed. CrowdStrike may already have detections, so testing needs exclusions or an obfuscated load path. This lands days after the same researcher published HardBreacher against Kaspersky and ShieldBreak against Microsoft Defender. Endpoint agents that remediates malware are also high-privilege code paths. Treat public E.D.R. escalation PoCs as an immediate detection and hardening check, not a curiosity. Symantec's Threat Hunter Team says multiple actors have been using the signed Node.js runtime as a malware delivery tool since February, hitting government, tech, hotels, and at least one U.S. fintech. The appeal is simple: node.exe is a legitimate developer binary, the payload lives in interpreted scripts, and a Run key keeps it sticky. In one Asian tech intrusion, ClickFix got them in, Cobalt Strike and Adaptix C.two kept getting blocked, so they downloaded the official Node installer and used EtherHiding for stay-behind tooling. The same pattern shows up with ModeloRAT, Mistic, C.two Looper, and a Node build of AsukaStealer. Living-off-the-land now includes your approved JavaScript runtime. Alert on unexpected node.exe in non-dev contexts, and treat ClickFix paste-into-Run prompts as a primary initial-access path. Citizen Lab, working with the SHARE Foundation, confirmed NSO Group's Pegasus on an iPhone belonging to a member of Serbia's student protest movement. The infection used an iMessage zero-click, with high-confidence indicators from December twenty twenty-five through January twenty twenty-six. Apple addressed the exploit in iOS eighteen point four point one, released in April twenty twenty-five. The finding lands after Apple sent fresh threat notifications to customers across one hundred ten countries suspected of mercenary spyware targeting. Zero-click on messaging remains the premium tool against journalists, activists, and organizers. Patch promptly, and treat unexpected threat notifications as an incident, not spam. Agents that trust a repo's Git config, hypervisors that trust an unsigned update over a hijacked route, E.D.R. remediation paths that escalate, a signed runtime turned into C.two, and mercenary spyware still landing zero-clicks. The trust you automate is the trust someone else will abuse. That's the briefing. Stay sharp, keep your systems patched, and we'll see you tomorrow.
Kindle: https://www.amazon.com/dp/B0HHMH88H9
Apple Books: https://books.apple.com/us/book/local-ai-on-the-mac/id6807243472