Operation Paper Oracle

AI · LINUX · difficulty 2 · ~20 min · 11 steps

Your support AI read a booby-trapped ticket and did what it was told.

Briefing

Your customer-support agent runs on agent-runner-01 with a shell tool and a set of cloud credentials. At 09:12 it processed ticket #48213 and then did things no support reply should: ran commands, read a secrets file, and made an outbound call to an address nobody recognises. The agent was not hacked. It was instructed — by text inside the ticket. Your evidence is its tool-call audit log. Read what it did, stop the bleeding, and understand that once an agent acts on hostile input, the secrets it can reach are already compromised.

Objectives

Return to the range lobby

THREAT FEED ▲ lateral movement via wmiexec up 18% ▲ new loader family 'GHOSTPULSE' staging via DLL search-order hijack ▲ prompt injection in support queues now routine ▲ cron persistence campaign targeting exposed SSH ▲ poisoned model weights on public hubs ▲ remember: trust nothing, hash everything ▲
operator@dojo:~$