Thank you for report.

Are you able to set U960 manual in DL Mode? So Key Combination is needed.
But I have no idea what to press.

I try to explain a little bit...
"Normal Mode" is under control from AMSS (Firmware like you would start Windows).
Under Windows you can't easily access all files read/write...
During normal Boot. Before U960 is ready to use.
1.
pbl = first Bootloader
loads qscbl... second Bootloader (signed by Qualcomm)... then OEMSBL=third Booltoader...
2. After 3 Bootloader successfully pass and checks each other... then AMSS is load from NAND Memory into SDRAM...
3.
AMSS + EFS is "mixed" into SDRAM
To reach clean Boot procedure for Download Mode. Is to start only the 3 Bootloader...
As OEMSBL contains all Data for QPST Memory Debug to...
So Security issues comes from third Bootloader... these are programmed by Samsung.
To prevent that bad Hackers play with it.

New chance to get more access. Is to copy and execute "Bootloader via Send to Command"...
These Bootloaders are these armprg.HEX files which are in QPST folder... like:
NPRG
7500.hex
U960 use MSM7500A as Chip...
BUT be warned. OEM (Samsung) can modify Standard Commands.
Study a little bit the manual from QPST.
Best Regards