# Do we need an AI Vulnerability Scoring System? - Threat Wire

Source: https://www.youtube.com/watch?v=l4ptm5A-gBE
Recap page: https://rapidrecap.app/video/l4ptm5A-gBE
Generated: 2025-11-13T15:32:31.777+00:00

---
## Quick Overview

The video discusses two main cybersecurity topics: the confirmation of a hack on the US Congressional Budget Office (CBO) and the introduction of a new AI Vulnerability Scoring System (AIVSS) by OWASP to address shortcomings in the traditional CVSS framework for AI systems, alongside reporting on the Landfall spyware targeting Samsung devices.

**Key Points:**
- The US Congressional Budget Office (CBO) confirmed a hack occurred on November 6th, potentially exposing government data to malicious actors, but stated the breach was contained.
- The CBO hack's details remain vague, though a congressperson stated the attack was done by a 'complex foreign actor' targeting emails and CBO analyses.
- OWASP introduced the AI Vulnerability Scoring System (AIVSS), which builds on CVSS but adds parameters for AI-specific risks like autonomy and non-determinism.
- The AIVSS score calculation involves a base CVSS score, an agentic capabilities assessment, division by two, and multiplication by an environmental context factor.
- Palo Alto Networks Unit 42 discovered the 'Landfall' spyware family exploiting CVE-2025-21042 in Samsung's image-processing library, patched in April 2025.
- The Landfall exploit extracts shared object library files from an embedded ZIP archive to run the spyware on Samsung Android phones, potentially as part of a zero-click exploit chain.

![Screenshot at 0:07: The transition graphic showing an aerial view of Washington D.C. with red crosshairs superimposed, setting the scene for the first news item regarding the hack on a US government entity.](https://ss.rapidrecap.app/screens/l4ptm5A-gBE/00-00-07.png)

**Context:** This episode of Threat Wire, hosted by Ally Diamond, serves as a weekly roundup of significant cybersecurity news. The discussion centers on three key events: a confirmed data breach at the US Congressional Budget Office, the development of a new vulnerability scoring standard tailored for Artificial Intelligence systems by OWASP, and the discovery of a commercial-grade Android spyware family dubbed 'Landfall' specifically targeting Samsung devices through an image processing library vulnerability.

## Detailed Analysis

The broadcast begins by confirming that the Congressional Budget Office (CBO) was hacked, an incident confirmed on November 6th, potentially exposing sensitive government data. While the CBO stated the incident was contained, details were scarce, although a congressperson suggested the attacker was a 'complex foreign actor' targeting emails and internal analyses. The second major topic introduced the new OWASP AI Vulnerability Scoring System (AIVSS), proposed as a necessary evolution from the standard CVSS to account for the unique risks posed by AI systems, such as autonomy and non-determinism. The AIVSS score is calculated by taking a base CVSS score, incorporating an agentic capabilities assessment, then dividing the combined result by two and multiplying it by an environmental context factor to produce a final score. Finally, the segment covers the discovery of the 'Landfall' spyware family by Palo Alto Networks Unit 42, which exploits CVE-2025-21042 in Samsung's image-processing library (libimagecodec.quram.so), patched in April 2025. This exploit allows the spyware to be delivered via a zero-click chain, utilizing files extracted from an embedded ZIP archive, highlighting the ongoing threat landscape for mobile operating systems.

### CBO Hack Confirmation

- CBO confirmed a hack on November 6th, potentially disclosing data to malicious actors
- Details remain vague, but a congressperson suggested a 'complex foreign actor' was involved
- The attack targeted emails and CBO analyses.

### OWASP AI Vulnerability Scoring System (AIVSS)

- OWASP created AIVSS to address CVSS limitations with AI systems
- The system incorporates agentic capabilities assessment, autonomy, non-determinism, and tool use factors
- The final score is calculated by combining base CVSS with agentic assessment, dividing by two, and multiplying by an environmental context factor.

### Landfall Spyware on Samsung

- Palo Alto Networks Unit 42 discovered commercial-grade Android spyware named Landfall targeting Samsung devices
- The malware exploits CVE-2025-21042 in the image processing library libimagecodec.quram.so, patched in April 2025
- The exploit extracts shared object library (.so) files from an embedded ZIP archive to run the spyware, potentially as part of a zero-click chain.

![Screenshot at 0:00: Host Ally Diamond introducing the weekly cybersecurity roundup segment, Threat Wire.](https://ss.rapidrecap.app/screens/l4ptm5A-gBE/00-00-00.png)
![Screenshot at 0:07: Animated graphic showing an aerial map of Washington D.C. with a red crosshair, symbolizing the CBO hack news item.](https://ss.rapidrecap.app/screens/l4ptm5A-gBE/00-00-07.png)
![Screenshot at 0:09: Title card transition graphic for 'THREAT WIRE' over a world map graphic.](https://ss.rapidrecap.app/screens/l4ptm5A-gBE/00-00-09.png)
![Screenshot at 0:21: Screenshot of the Associated Press article confirming the hack on the Congressional Budget Office.](https://ss.rapidrecap.app/screens/l4ptm5A-gBE/00-00-21.png)
![Screenshot at 1:27: On-screen graphic introducing the topic: 'New CVSS Scoring System'.](https://ss.rapidrecap.app/screens/l4ptm5A-gBE/00-01-27.png)
![Screenshot at 1:52: Detailed quote explaining the structure of the new AI Vulnerability Scoring System \(AIVSS\) based on the CVSS model.](https://ss.rapidrecap.app/screens/l4ptm5A-gBE/00-01-52.png)
![Screenshot at 2:49: On-screen graphic introducing the second news story: 'New Spyware Family Attacks Samsung'.](https://ss.rapidrecap.app/screens/l4ptm5A-gBE/00-02-49.png)
![Screenshot at 2:50: Screenshot of the Palo Alto Networks Unit 42 report titled 'LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices'.](https://ss.rapidrecap.app/screens/l4ptm5A-gBE/00-02-50.png)
