Someone Downloaded All of Spotify - Threat Wire

Quick Overview

Anna Diamond reports on two major cybersecurity stories: the Anna's Archive music data dump, which includes nearly all of Spotify's metadata and 86 million music files (representing 99.6% of listeners), and a supply chain attack against the documentation platform Mintlify, which exposed customer data including users from major companies like Discord and Twitter.

Key Points: Anna's Archive backed up Spotify, including metadata and music files, totaling approximately 300TB, representing 99.6% of listeners. The Spotify backup includes 256 million tracks and 86 million music files, which will be released in bulk over the coming months. A supply chain attack on Mintlify, an AI documentation platform, allowed hackers to achieve Remote Code Execution (RCE) via Cross-Site Scripting (XSS) in server-side rendering. The Mintlify vulnerability affected major customers like Discord, Twitter, Vercel, and Cursor, exposing their documentation data. The hackers who discovered the Mintlify vulnerability were rewarded $11,000 by Mintlify and other affected companies. The Linux Kernel saw its first CVE vulnerability for Rust code, CVE-2025-68260, related to a race condition in the Android Binder rewrite, which causes a crash. SoundCloud experienced outages due to a security issue caused by threat actors stealing databases containing user emails and profile information.

Context: The video is a cybersecurity news roundup called "Threat Wire," hosted by Anna Diamond. It covers recent security incidents and vulnerabilities discussed across the tech and security community, focusing on a massive data preservation effort by Anna's Archive, a supply chain compromise involving the documentation platform Mintlify, and the first ever Common Vulnerabilities and Exposures (CVE) assigned to code written in Rust within the Linux kernel.

Detailed Analysis

The segment begins with the news that Anna's Archive has successfully backed up nearly all of Spotify's music data, including metadata and music files, totaling about 300TB, representing 99.6% of listeners. This data release, which includes 256 million tracks and 186 million unique ISRCs, will be distributed in bulk over the next few months. Anna's Archive traditionally focuses on text but made an exception due to the high information density of music data. Following this, the host discusses a major supply chain incident involving Mintlify, an AI documentation platform used by top companies. Three hackers—Eva, Daniel, and MDL—found critical vulnerabilities allowing them to inject malicious scripts via server-side rendering, leading to RCE and exposing customer documentation, including that of Discord, Twitter, Vercel, and Cursor. The hackers were rewarded $11,000. The vulnerability was traced to an insecure part of the rendering engine. The hackers' write-ups detail how they leveraged this to affect other tenants' documentation. Finally, the video covers the first-ever CVE assigned to Rust code in the Linux kernel (CVE-2025-68260), which was a race condition in the Android Binder rewrite that could lead to memory corruption and crashes. This CVE was announced the same day Rust support was fully included in the kernel. The segment concludes with trending news about SoundCloud experiencing outages due to threat actors stealing user data via a breach of its mixed panel, and mentions that while the holiday season is ongoing, security threats persist.

Raw markdown version of this recap