AI is Now the Best Hacker in the US - Threat Wire
Quick Overview
The ransomware group Hunters International announced its cessation of operations and released free decryption keys for victims, though they previously threatened to rebrand for data theft. Concurrently, an AI chatbot named XBOW achieved the top rank on HackerOne's US leaderboard by submitting over 1,000 vulnerabilities, demonstrating AI's growing capability in penetration testing. Separately, Cisco patched a critical 10.0 CVSS vulnerability (CVE-2025-20309) in its Unified Communications Manager products, caused by hardcoded root user credentials left in development code.
Summary
Key Points: Hunters International, a ransomware group, ceased operations and released free decryption keys for victims on July 3, 2025. The group had previously attempted to rebrand for data theft and extortion, but this was exposed by Group-IB. An AI chatbot named XBOW achieved the top rank on HackerOne's US leaderboard, submitting 1,060 vulnerabilities. XBOW's submissions included 54 critical and 242 high-severity issues in the last 90 days. Cisco patched a critical 10.0 CVSS vulnerability (CVE-2025-20309) in its Unified Communications Manager products. The Cisco vulnerability was due to hardcoded root user credentials left in development code, allowing remote attackers to gain root access. Cisco confirmed no workaround for the vulnerability, emphasizing the need for immediate software updates.
Context: This news report from Threat Wire covers significant cybersecurity developments in early July 2025, focusing on the unexpected closure of a major ransomware group, the rise of AI in penetration testing, and a critical vulnerability discovered in Cisco products. These events highlight the evolving landscape of cyber threats and defensive strategies.
Detailed Analysis
Hunters International, a ransomware group active for two years with victims including international banks and the FBI, announced on July 3, 2025, that it would cease operations and offer free decryption software as a "gesture of goodwill." This marks their second attempt to close, as they previously planned to shut down in November 2024 but were exposed by Group-IB for intending to rebrand and focus solely on data theft and extortion. In other cybersecurity news, an AI chatbot developed by XBOW has become the top-rated red teamer on HackerOne's US leaderboard, submitting 1,060 vulnerabilities since August 2024. Of these, 130 were resolved, 303 triaged, 209 marked as duplicates, and 36 as non-applicable. Over the last 90 days, XBOW's submissions included 54 critical, 242 high, 524 medium, and 65 low-severity issues, with 45% still awaiting resolution. This highlights AI's significant impact and accuracy in penetration testing. Finally, Cisco patched a critical 10.0 CVSS vulnerability, CVE-2025-20309, affecting its Unified Communications Manager and Unified Communications Manager Session Management Edition. This flaw stemmed from static user credentials for the root account left in the code during development, allowing unauthenticated remote attackers to log in and execute arbitrary commands. Cisco confirmed no workaround exists, urging immediate updates.