Operation Hollow Index

AI · LINUX · difficulty 2 · ~18 min · 11 steps

One poisoned document taught your company assistant to lie.

Briefing

Your internal assistant answers staff questions from a Postgres/pgvector index built over the company wiki and uploaded docs. Since yesterday it has been telling people to install a package called 'acme-sso-helper' from a stranger's repo, and quoting a 'policy' nobody wrote. Nobody changed the model. Someone changed what it retrieves. Find the poisoned chunk, purge it from the vector table, and close the ingestion path that let it in.

Objectives

Return to the range lobby

THREAT FEED ▲ lateral movement via wmiexec up 18% ▲ new loader family 'GHOSTPULSE' staging via DLL search-order hijack ▲ prompt injection in support queues now routine ▲ cron persistence campaign targeting exposed SSH ▲ poisoned model weights on public hubs ▲ remember: trust nothing, hash everything ▲
operator@dojo:~$