# AI is Now the Best Hacker in the US - Threat Wire

Source: https://www.youtube.com/watch?v=CvLgW3slekE
Recap page: https://rapidrecap.app/video/CvLgW3slekE
Generated: 2025-07-10T18:56:31.564+00:00

---
## Quick Overview

The ransomware group Hunters International announced its cessation of operations and released free decryption keys for victims, though they previously threatened to rebrand for data theft. Concurrently, an AI chatbot named XBOW achieved the top rank on HackerOne's US leaderboard by submitting over 1,000 vulnerabilities, demonstrating AI's growing capability in penetration testing. Separately, Cisco patched a critical 10.0 CVSS vulnerability (CVE-2025-20309) in its Unified Communications Manager products, caused by hardcoded root user credentials left in development code.

## Summary

**Key Points:**
- Hunters International, a ransomware group, ceased operations and released free decryption keys for victims on July 3, 2025.
- The group had previously attempted to rebrand for data theft and extortion, but this was exposed by Group-IB.
- An AI chatbot named XBOW achieved the top rank on HackerOne's US leaderboard, submitting 1,060 vulnerabilities.
- XBOW's submissions included 54 critical and 242 high-severity issues in the last 90 days.
- Cisco patched a critical 10.0 CVSS vulnerability (CVE-2025-20309) in its Unified Communications Manager products.
- The Cisco vulnerability was due to hardcoded root user credentials left in development code, allowing remote attackers to gain root access.
- Cisco confirmed no workaround for the vulnerability, emphasizing the need for immediate software updates.

**Context:** This news report from Threat Wire covers significant cybersecurity developments in early July 2025, focusing on the unexpected closure of a major ransomware group, the rise of AI in penetration testing, and a critical vulnerability discovered in Cisco products. These events highlight the evolving landscape of cyber threats and defensive strategies.

## Detailed Analysis

Hunters International, a ransomware group active for two years with victims including international banks and the FBI, announced on July 3, 2025, that it would cease operations and offer free decryption software as a "gesture of goodwill." This marks their second attempt to close, as they previously planned to shut down in November 2024 but were exposed by Group-IB for intending to rebrand and focus solely on data theft and extortion. In other cybersecurity news, an AI chatbot developed by XBOW has become the top-rated red teamer on HackerOne's US leaderboard, submitting 1,060 vulnerabilities since August 2024. Of these, 130 were resolved, 303 triaged, 209 marked as duplicates, and 36 as non-applicable. Over the last 90 days, XBOW's submissions included 54 critical, 242 high, 524 medium, and 65 low-severity issues, with 45% still awaiting resolution. This highlights AI's significant impact and accuracy in penetration testing. Finally, Cisco patched a critical 10.0 CVSS vulnerability, CVE-2025-20309, affecting its Unified Communications Manager and Unified Communications Manager Session Management Edition. This flaw stemmed from static user credentials for the root account left in the code during development, allowing unauthenticated remote attackers to log in and execute arbitrary commands. Cisco confirmed no workaround exists, urging immediate updates.

### Hunters International Ransomware Group

- Announced cessation of operations on July 3, 2025
- Offered free decryption keys to victims as a "gesture of goodwill"
- Previously threatened to close in November 2024 but was exposed for planning to rebrand for data theft and extortion
- Operated for two years, targeting international banks and the FBI

### AI's Dominance in Bug Bounty

- XBOW, an AI chatbot, became the top-rated red teamer on HackerOne's US leaderboard
- Submitted 1,060 vulnerabilities since August 2024
- 130 vulnerabilities were resolved, 303 triaged, 209 duplicates, 36 non-applicable
- Recent submissions include 54 critical, 242 high, 524 medium, and 65 low-severity issues
- 45% of XBOW's findings are still awaiting resolution, demonstrating high volume and impact

### Cisco Critical Vulnerability Patch

- Cisco patched CVE-2025-20309, a 10.0 CVSS vulnerability
- Affected Cisco Unified Communications Manager and Session Management Edition
- Vulnerability caused by static user credentials for the root account reserved for development
- Allows unauthenticated remote attackers to log in and execute arbitrary commands
- No workaround available, immediate updates are crucial

![Screenshot at 0:00: Host speaking into a pink microphone](https://ss.rapidrecap.app/screens/CvLgW3slekE/00-00-00.png)
![Screenshot at 0:08: Threat Wire logo animation](https://ss.rapidrecap.app/screens/CvLgW3slekE/00-00-08.png)
![Screenshot at 0:13: Text overlay "Free Ransomware Keys"](https://ss.rapidrecap.app/screens/CvLgW3slekE/00-00-13.png)
![Screenshot at 0:35: Screenshot of Hunters International project closure announcement](https://ss.rapidrecap.app/screens/CvLgW3slekE/00-00-35.png)
![Screenshot at 1:24: Text overlay "AI Has Beat HackerOne"](https://ss.rapidrecap.app/screens/CvLgW3slekE/00-01-24.png)
![Screenshot at 1:33: Screenshot of HackerOne leaderboard showing XBOW as #1](https://ss.rapidrecap.app/screens/CvLgW3slekE/00-01-33.png)
![Screenshot at 2:53: Text overlay "Cisco Left Credentials In Prodee"](https://ss.rapidrecap.app/screens/CvLgW3slekE/00-02-53.png)
![Screenshot at 3:14: Screenshot of Cisco Security Advisory for CVE-2025-20309](https://ss.rapidrecap.app/screens/CvLgW3slekE/00-03-14.png)
