# Someone Downloaded All of Spotify - Threat Wire

Source: https://www.youtube.com/watch?v=JFyVU0LONLA
Recap page: https://rapidrecap.app/video/JFyVU0LONLA
Generated: 2025-12-26T17:34:21.706+00:00

---
## Quick Overview

Anna Diamond reports on two major cybersecurity stories: the Anna's Archive music data dump, which includes nearly all of Spotify's metadata and 86 million music files (representing 99.6% of listeners), and a supply chain attack against the documentation platform Mintlify, which exposed customer data including users from major companies like Discord and Twitter.

**Key Points:**
- Anna's Archive backed up Spotify, including metadata and music files, totaling approximately 300TB, representing 99.6% of listeners.
- The Spotify backup includes 256 million tracks and 86 million music files, which will be released in bulk over the coming months.
- A supply chain attack on Mintlify, an AI documentation platform, allowed hackers to achieve Remote Code Execution (RCE) via Cross-Site Scripting (XSS) in server-side rendering.
- The Mintlify vulnerability affected major customers like Discord, Twitter, Vercel, and Cursor, exposing their documentation data.
- The hackers who discovered the Mintlify vulnerability were rewarded $11,000 by Mintlify and other affected companies.
- The Linux Kernel saw its first CVE vulnerability for Rust code, CVE-2025-68260, related to a race condition in the Android Binder rewrite, which causes a crash.
- SoundCloud experienced outages due to a security issue caused by threat actors stealing databases containing user emails and profile information.

![Screenshot at 00:14: The blog post from Anna's Archive detailing the massive backup of Spotify metadata and music files, including 256 million tracks and 86 million music files.](https://ss.rapidrecap.app/screens/JFyVU0LONLA/00-00-14.jpg)

**Context:** The video is a cybersecurity news roundup called "Threat Wire," hosted by Anna Diamond. It covers recent security incidents and vulnerabilities discussed across the tech and security community, focusing on a massive data preservation effort by Anna's Archive, a supply chain compromise involving the documentation platform Mintlify, and the first ever Common Vulnerabilities and Exposures (CVE) assigned to code written in Rust within the Linux kernel.

## Detailed Analysis

The segment begins with the news that Anna's Archive has successfully backed up nearly all of Spotify's music data, including metadata and music files, totaling about 300TB, representing 99.6% of listeners. This data release, which includes 256 million tracks and 186 million unique ISRCs, will be distributed in bulk over the next few months. Anna's Archive traditionally focuses on text but made an exception due to the high information density of music data. Following this, the host discusses a major supply chain incident involving Mintlify, an AI documentation platform used by top companies. Three hackers—Eva, Daniel, and MDL—found critical vulnerabilities allowing them to inject malicious scripts via server-side rendering, leading to RCE and exposing customer documentation, including that of Discord, Twitter, Vercel, and Cursor. The hackers were rewarded $11,000. The vulnerability was traced to an insecure part of the rendering engine. The hackers' write-ups detail how they leveraged this to affect other tenants' documentation. Finally, the video covers the first-ever CVE assigned to Rust code in the Linux kernel (CVE-2025-68260), which was a race condition in the Android Binder rewrite that could lead to memory corruption and crashes. This CVE was announced the same day Rust support was fully included in the kernel. The segment concludes with trending news about SoundCloud experiencing outages due to threat actors stealing user data via a breach of its mixed panel, and mentions that while the holiday season is ongoing, security threats persist.

### Spotify Data Preservation

- Anna's Archive backed up Spotify metadata and music files (300TB total)
- Included 256M tracks and 86M music files (99.6% of listeners)
- Release planned in parts over coming months

### Mintlify Supply Chain Attack

- Hackers found critical vulnerabilities in Mintlify's server-side rendering
- Achieved RCE via Cross-Site Scripting (XSS)
- Exposed documentation for major clients like Discord, Twitter, Vercel, and Cursor
- Hackers were rewarded $11,000

### First Rust for Linux CVE

- CVE-2025-68260 assigned to Rust code in the Linux kernel
- Vulnerability was a race condition in the Android Binder rewrite
- Could lead to memory corruption and crashes
- Announced the same day full Rust inclusion in kernel was finalized

### Trending News

- SoundCloud streaming platform suffered outages due to a security issue
- Threat actors stole user emails and profile information
- Google announced it will no longer support its dark web reporting tool

![Screenshot at 00:07: Aerial satellite view of a city grid with red crosshairs indicating a search or target area.](https://ss.rapidrecap.app/screens/JFyVU0LONLA/00-00-07.jpg)
![Screenshot at 00:08: Early graphic overlay showing a futuristic HUD design typical of security news segments.](https://ss.rapidrecap.app/screens/JFyVU0LONLA/00-00-08.jpg)
![Screenshot at 00:14: A screenshot of Anna's Blog post titled 'Backing up Spotify,' detailing the collection size \(300TB, 256M tracks\).](https://ss.rapidrecap.app/screens/JFyVU0LONLA/00-00-14.jpg)
![Screenshot at 00:38: A screenshot of the GitHub write-up titled 'How we owned X \(Twitter\), Vercel, Cursor, and hundreds of companies through a supply-chain attack' by hackermondev.](https://ss.rapidrecap.app/screens/JFyVU0LONLA/00-00-38.jpg)
![Screenshot at 06:01: A black terminal screen displaying patch notes related to the Rust for Linux kernel project, highlighting fixes.](https://ss.rapidrecap.app/screens/JFyVU0LONLA/00-06-01.jpg)
