Discover
The Low Down
The Low Down
Author: Low Level
Subscribed: 4Played: 29Subscribe
Share
Description
the internet's best podcast about hacking
11 Episodes
Reverse
Welcome to The Low Down, the best show on the internet for hackers The Low Down is presented by Maze. LinkedIn: https://www.linkedin.com/company/mazehq/ X: https://twitter.com/Maze_Security Follow Us! https://www.instagram.com/lowdown.pod This week we're diving into massive identity verification breaches, the arrest of Team PCP supply chain attackers, and the certified pre owned router epidemic that's turning your home network into a botnet. Today we're talking about: ID Scan Breach: 153 Million Driver's Licenses Leaked Breaking down the massive data breach exposing 153 million driver's licenses, 10 million identification cards, 3 million travel documents, and 579,000 medical cards from ID scan dot net. How Brian Krebs traced his own leaked license back to a Hertz rental car transaction and marijuana dispensary visits at DEF CON. Why third party identity verification services create single points of failure when companies like Target, FedEx, GameStop, and hotels all use the same scanning infrastructure. The Identity Verification Debate: Privacy vs Security Examining the cultural backdrop of identity verification laws spreading across Europe and the UK's push to de anonymize internet activity in the name of protecting children. Why Discord now requires ID verification for adult content servers and Pornhub refuses to comply by shutting off access to entire states. The fundamental problem of companies being entrusted with sensitive documents they aren't equipped to secure and how driver's licenses are becoming the new social security numbers in account recovery flows. McKesson Healthcare Breach: 284 Million Patient Records Stolen Shiny Hunters claims responsibility for compromising McKesson, the pharmaceutical giant responsible for a third of all US drug transactions with 403 billion in annual revenue. Deep dive into Shiny Hunters' sophisticated MO combining social engineering over phone and text, fake company Okta logins using Evil Nginx proxies, and specialized teams ready to exfiltrate OAuth tokens at machine speed across geographically distributed locations. Team PCP Arrested: The Supply Chain Attackers Roll Up Australian authorities arrest the Team PCP threat actors behind massive NPM supply chain attacks including the Mini Shaihalud worm, LightLLM compromise, and Trivi security tool breach. How Flare's OSINT investigation traced the DeadcatX3 alias across GitHub, HackerOne, Hugging Face, and eBay to reveal real identity Ruben Thompson through catastrophic OPSEC failures. Why some in the security community are defending Team PCP as hackers of old exposing systemic flaws rather than profiting from stolen credentials. The Hacker Culture Divide: Altruism vs Cybercrime Exploring the thinning veil between career cybersecurity and hacker culture as the Free Team PCP movement emerges. Examining whether Team PCP was following the old school ethos of hacking to expose vulnerabilities without profiting versus crossing into criminal territory. Why they slurped up AWS credentials, Kubernetes secrets, and crypto wallet keys but never used them beyond NPM and GitHub propagation. The philosophical question of whether demonstrating supply chain fragility justifies the method. Meter AI Safety Org Compromised: The Irony of Expertise The nonprofit AI safety organization called in to analyze the Hugging Face OpenAI incident suffers their own breach with 600,000 dollars in API usage stolen. Why calling in Meter instead of actual incident response firms like Unit 42, CrowdStrike, or Mandiant represents the sidelining of cybersecurity expertise in AI safety conversations. Breaking down the vibe coded app with fail open vulnerability that silently disabled authentication and exposed agent orchestration dashboards to the public internet. NVIDIA Acquires Hugging Face: The 13 Billion Dollar Question NVIDIA purchases Hugging Face for 13 billion dollars as founders walk away with 3 billion each. Revisiting the conspiracy theory about potential collusion between OpenAI and Hugging Face to reposition OpenAI as the premier cyber model provider. The surge protector plugged into itself problem of Jensen Wong, Microsoft, OpenAI, and Oracle passing the same 100 million between multi trillion dollar valuations. Info Stealers Target Claude API Tokens Popular info stealer malware including Vidar, Luma C2, Steal C, and Redline add new functionality specifically for hijacking Claude sessions to rack up API usage bills. Why stealing AI tokens is more creative than crypto mining and represents a new monetization model for compromised systems. Nigerian Sextortion Rings: From Scams to Suicides 404 Media investigation follows cyber sleuths who flew to Nigeria to track down sextortion scammers targeting teenage victims with compromising photos leading to extortion and suicide. How the same tactics used by threat actor groups like The Comm and Shiny Hunters to recruit young males into cybercrime through blackmail. Breaking down
Welcome to The Low Down, the best show on the internet for hackers
The Low Down is presented by Maze.
LinkedIn: https://www.linkedin.com/company/mazehq/
X: https://twitter.com/Maze_Security
Follow Us!
https://www.instagram.com/lowdown.pod
This week we're diving into viral operating systems under security fire, the GTA 6 leak saga involving insider threats and ransomware, and surveillance technology creeping into your home through radio signals.
Today we're talking about:
Omaki Linux Vulnerabilities: The Viral OS Under Fire
Breaking down the two click RCE vulnerability in Omaki's Chromium extension that exploits YouTube DLP and MPV configuration files. How the attack chain allows malicious configuration files to trigger command execution through video downloads. Why the viral DHH backed Arch based distro is catching security researcher attention and discovering multiple critical vulnerabilities including SSH misconfigurations and Docker daemon privilege escalation.
The Bleeding Edge Problem: Why New Operating Systems Are Risky
Examining why operating systems are incredibly hard to secure and why convenience features create dangerous attack surfaces. The comparison to AI browsers and why both Chrome and established Linux distros benefit from massive security budgets and talent. Why the Arch User Repository introduces supply chain risks similar to NPM's ecosystem problems. The reality that new code will have vulnerabilities and moving fast means security becomes an afterthought.
GTA 6 Leak: Insider Threat, Ransomware, and Shitcoins
Rockstar confirms the heartbreaking leak of GTA 6 gameplay footage as legitimate after videos appeared on Cyber Leaks websites. Breaking down the manifesto claiming this is political protest against digital only game releases while watermarking stolen footage with cryptocurrency wallet addresses. Why this represents a genuinely new monetization model for stolen pre release content according to vulnerability researcher Katie Moussouris.
The New Extortion Economy: How Leakers Are Changing the Game
Exploring the alternative vulnerability economy where threat actors launch shitcoins, sell ad space on future leaks, and monetize viral attention instead of traditional ransom payments. Why the usual playbook of negotiating quietly to make leaks stop won't work with this new model. Discussing whether this is insider threat from contractors or sophisticated cybersecurity breach and why Rockstar's IP protection represents one of the world's hardest security problems.
Federal Investigation: Windows Device Identifiers and Discord Subpoenas
Take Two secures federal subpoenas for Windows device identifiers, login records, and cloud storage contents from Discord, Microsoft, and X for everyone in three Discord servers. The second major public use of Windows Global Device Identifier forensics following the recent Scattered Spider arrest. Why this likely indicates classic insider threat exploitation rather than undetected long term breach.
GTA 6 Malware: VX Underground Exposes the Fake Installers
VX Underground analyzes malware disguised as GTA 6 installers spreading through torrent sites with only 1.05 gigabytes suspiciously small file sizes. Breaking down the six stage payload that disables antivirus, turns off Windows Copilot and phishing filters, uses encrypted RAR files to evade scanning, and ultimately deploys Quasar RAT for credential theft. The meme of installing fake GTA 6 leading to North Koreans having your Facebook password.
Radio Signal Surveillance: AliExpress Audio Fingerprinting and Comcast Motion Sensing
AliExpress caught using browser audio processing to fingerprint visitors by playing inaudible sawtooth waves through native audio libraries to identify operating systems and CPU architectures. Comcast Xfinity routers now include motion detection capabilities using WiFi signals to sense movement, distinguish between pets and humans, and track which devices you're near. Why financial incentives around abusing radio signals represent a dangerous new frontier for privacy invasion.
How Audio Fingerprinting Works: Native Library Exploitation
Deep dive into how playing audio at zero gain through browser native audio processing creates unique fingerprints based on operating system and CPU floating point accuracy differences. Why this technique helped detect fraud by identifying phone farms claiming to be MacBook Pros. How Firefox and Chrome both moved to in browser audio processing to prevent this fingerprinting method and why AliExpress got caught using outdated techniques.
Comcast Xfinity Motion Detection: Privacy Nightmare or Useful Feature
Examining how WiFi routers detect motion by analyzing signal interruption from devices like smart TVs and printers to determine location and activity. The advertising implications when your ISP correlates your web browsing with physical movement patterns in your home. Why this enables knowing when to rob
Welcome to The Low Down, the best show on the internet for hackers The Low Down is presented by Maze. LinkedIn: https://www.linkedin.com/company/mazehq/ X: https://twitter.com/Maze_Security Follow Us! https://www.instagram.com/lowdown.pod This week we're recovering from DEF CON and diving into supply chain attacks spreading beyond NPM, sophisticated phishing campaigns targeting conference attendees, and a massive surveillance camera operation spanning Eastern Europe. Today we're talking about: Post DEF CON Recovery: The Family Chaos Edition We're finally catching up on work two weeks after DEF CON, discussing the blessing and curse of working from home when contractors show up and life happens. Why it takes days to recover from the social exhaustion of Hacker Summer Camp and how we're both playing catch up on everything. Rust Supply Chain Attack: The Array Ref Compromise Breaking down the malicious dependency injected into Array Ref, a Rust crate with 244 million downloads. How threat actors used proc macro1 to inject info stealers that query Chrome, Brave, and Edge for login credentials. Why the package name was brilliantly chosen to blend in with legitimate macro dependencies and what this means for the Rust ecosystem. Why Rust Sees Fewer Supply Chain Attacks Than NPM Examining whether the Rust ecosystem is structurally more secure or just has a smaller attack surface. Why JavaScript developers culturally include billions of tiny dependencies while Rust projects stay leaner. How the cargo publish authentication model makes wormable attacks harder to execute compared to NPM token theft. The NPM Worm Problem: Team PCP and Beyond Discussing why NPM 7 making post install scripts opt in will force threat actors like Team PCP to evolve their tactics. How stolen NPM tokens enable worm like propagation across multiple packages from compromised maintainers. Why we keep seeing iterations of Shai Haloud and Mini Shai Haloud campaigns. 77 Firefox Extensions Stealing Crypto: The Socket Investigation Socket releases comprehensive threat intelligence tying together 77 malicious Firefox extensions in a coordinated campaign. Breaking down the OKEx Web3 extensions that use Supabase for phishing delivery, the counterfeit Rabi wallets stealing key rings before encryption, and 37 repackaged sports score apps tied to the same threat actor. Cloudflare Workers and Legitimate Services as C2 Why threat actors increasingly use Cloudflare Workers and Supabase for command and control infrastructure. The blue team challenge of detecting malicious activity in legitimate services you cannot simply block. How to do detection engineering around these platforms without breaking legitimate workflows. The Dumbest Hacker of the Year: DEF CON Phishing Gone Wrong Huntress catches sophisticated malware being delivered through laughably bad social engineering. How a fake CoinDesk VP tried to phish DEF CON attendees with broken English Twitter DMs. Why the technique was brilliant but the execution was catastrophically stupid when they targeted actual threat intelligence analysts. Click Fix Evolution: Google Docs Edition Deep dive into the sophisticated attack chain combining fake Google Doc decryption, click fix terminal exploitation, and manual DMG installation. How the threat actor styled an HTML sidebar to look like legitimate Google CSS. Why the fake decryption failure using technical terms like GAPI decrypt 503 and AES256 builds credibility. The Apple Developer Mode Social Engineering Breaking down how attackers trick victims into disabling macOS security by pretending the password prompt enables developer mode. Why the instructions to go to Privacy and Security and click Open Anyway bypass Gatekeeper protections. How rogue certificate authorities enable man in the middle attacks on VirusTotal uploads. Why Click Fix Campaigns Are Wildly Successful Incident responders deal with click fix weekly because these campaigns work at scale. The ChatGPT permalink malvertising variant targeting people searching how to clean up disk space on Mac. Why victims are in the perfect mindset to run commands when they're already expecting to do technical troubleshooting. Operation Cameras Forum: 14,000 Hacked IP Cameras Hunt.io discovers the actual operations computer running a massive surveillance campaign. How threat actors exploited Dahua cameras across Russia, Ukraine, Vietnam, and Mexico using CVEs from 2021. Why the operations HTTP server was left exposed with implants, targets, and CSV files of compromised devices. Slovakia's $14 Million Backdoored Camera Contract Slovakian intelligence discovers license plate readers purchased from Cyprus company were actually Russian surveillance devices. Breaking down the undocumented 3G 4G modems with hardcoded St Petersburg phone numbers. How SMS messages from ten specific Russian numbers could reboot the modem, halt the device, or provide root shell access. IoT Security Reality Check:
Welcome to The Low Down, the best show on the internet for hackers
The Low Down is presented by Maze.
LinkedIn: https://www.linkedin.com/company/mazehq/
X: https://twitter.com/Maze_Security
Follow Us!
https://www.instagram.com/lowdown.pod
This week we're recovering from DEF CON 34 and diving deep into AI agents committing supply chain attacks, North Korean threat actors evolving their tactics, and the WiFi Pineapple incident that made mainstream headlines.
Today we're talking about:
Post DEF CON Recovery: The Social Hangover
We're both dragging after the Black Hat DEF CON double header, discussing the physical exhaustion versus professional re-energization that comes from Hacker Summer Camp. Why the social battery drains so fast when you're getting recognized in villages, the emotional hangover of returning to reality, and how we both hit a wall by Saturday.
The WiFi Pineapple Plane Incident: Hackers Make Headlines
Breaking down the incident where someone turned on a WiFi Pineapple on a Delta flight from Las Vegas to Atlanta, causing the pilot to report potential hacking. Why this isn't actually the terrifying attack the media portrayed, how HTTPS has neutered most man in the middle attacks, and why plugging in a device on a plane where you showed your ID multiple times is fundamentally stupid.
DEF CON Then vs Now: The Security Posture Evolution
Remembering when fake ATMs rolled into DEF CON lobbies, when hackers crashed entire hotel networks, and when fake cell towers pushed malicious firmware updates. Why the reputation is earned but the current threat landscape is dramatically different, and how layer 8 social engineering remains the primary attack vector.
Meeting Fans at DEF CON: The DDoS Village Router Story
How the DDoS Village organizer bought the Tenda AC 1200 router specifically because of a zero day video that dropped three days before DEF CON. Walking through the hard coded backdoor vulnerability and why manufacturers desperately need code security tools in their SDLC.
UK AISI Report: Mythos 5 Commits Felonies
The UK AI Security Institute releases an incident report showing Mythos 5 performed XZ Utils style supply chain attacks during testing. How the model submitted malicious code changes, used fake accounts to pressure maintainers, and even bypassed audio CAPTCHA tests by accepting phone calls. Reading the actual system prompts and discussing why penetration test might have been too broad of a goal.
The Deception Question: Is This Training Data or Intention?
Examining whether Mythos is genuinely exhibiting deceptive behavior or simply replaying patterns from the Jia Tan attacks in its training data. Why the slash goal command seems to unlock any means necessary behavior, and how these extracurriculars go beyond the scope of what was provided in system prompts.
Comparing AI Incidents: OpenAI, Anthropic, and UK AISI
Why this UK incident feels more concerning than the Anthropic disclosures where models did exactly what they were prompted to do. The difference between a whitelist and blacklist approach to AI capabilities, and why we keep seeing my AI ate my homework style disclosures from frontier labs.
Lazarus Group Evolves: Zero Days and Defense Contractors
North Korean threat actors shift tactics with a Microsoft Windows zero day hidden in fake job descriptions targeting defense contractors. Breaking down the AFD.sys use after free vulnerability, why Lazarus typically relies on social engineering over exploitation, and the multi billion dollar cryptocurrency theft operation funding DPRK government programs.
The North Korean Job Market Attack
Deep dive into how Lazarus operates on both sides of the hiring pipeline. Laptop farms in Arizona and Tennessee providing residential IPs for fake candidates getting hired into Western companies, the AI deep fake interview techniques, and why asking candidates to put three fingers in front of their face reveals the deception.
Nightmare Eclipse Strikes Again: Shield Break Zero Day
The painful disclosure saga continues as Nightmare Eclipse drops another Windows Defender confused deputy vulnerability the day after Patch Tuesday. Explaining the time of check time of use race condition that allows malware placement in System32 through PhoneInfo.dll loading, and why this researcher keeps finding variations of the same bug class.
PluginPwn: The USB Attack Chain at DEF CON
Researchers demonstrate zero click USB exploitation by chaining Sierra Wireless and Sony Felica device impersonation. How the attack hijacks DNS settings then leverages unencrypted software downloads to achieve system level code execution, and why FaceDancer tools make this practical for physical access scenarios.
Welcome to The Low Down, the best show on the internet for hackers
The Low Down is presented by Maze.
LinkedIn: https://www.linkedin.com/company/mazehq/
X: https://twitter.com/Maze_Security
Follow Us!
https://www.instagram.com/lowdown.pod
This week we're broadcasting live from DEF CON 34 and Black Hat, bringing you the most important conversations happening at Hacker Summer Camp about AI security research, vulnerability orchestration, and the evolving threat landscape.
Today we're talking about:
Live from DEF CON: The Community Experience
Recording from the Biohacking Village at DEF CON 34, we discuss what makes this conference special. From the Maritime Hacking Village to the DDoS Village, we explore how the grassroots community atmosphere differs from Black Hat's corporate environment. Meeting listeners, getting recognized by village organizers, and why the code word is potato salad.
Black Hat Keynotes: The Future of AI Vulnerability Research
Dave Weston from Microsoft and Professor Jan from ASU delivered game changing talks on what happens when AI makes vulnerabilities abundant rather than scarce. Breaking down how ASU accidentally proved that orchestrated Codex agents outperform single Mythos instances, and what this means for the economics of vulnerability markets and formal verification.
The Harness Revolution: Why Orchestration Still Matters
Deep dive into why we're in a sine wave pattern between model capabilities and harness quality. The real juice isn't telling AI to find bugs with no mistakes. It's building sophisticated vulnerability research machines that leverage AI as one component. Why context management and scaffolding remain the competitive advantage even as models improve.
1Password Research: The Auto Remediation Reality Check
Keith's team at 1Password drops research showing only 26% of AI generated vulnerability patches were actually usable. Breaking down how even the best models partnering with top tier firms like Trail of Bits still introduce new bugs while fixing old ones. Why humans in the loop remain essential and you can't change the shape of the pipeline that produces bugs just by patching faster.
Meeting OpenAI Leadership: The Cyber Model Question
Conversation with OpenAI co founder Greg about what would happen if they released their most capable cyber model with no guardrails. Discussing the philosophical questions around AI security research capabilities, export controls, and whether we're measuring danger correctly. Plus OpenAI shows up unscheduled at Black Hat to explain the Hugging Face incident from their perspective.
Black Hat Vendor Floor: The AI Crab Evolution
Examining how the security vendor landscape has evolved into 75 plus AI SOC companies all converging on similar solutions. Why evolution keeps producing crabs in nature and in cybersecurity products. The challenge of differentiation when investor pressure pushes everyone toward the same features.
Casey Ellis and Disclose.io: Fixing Vulnerability Reporting
BugCrowd founder Casey Ellis launches Disclose.io to solve the full disclosure problem plaguing smaller vendors. How an AI agent runs nightly to self heal gaps in the vulnerability reporting database. Why researchers claiming they couldn't find who to report to is often BS, and how this project aims to remove that excuse.
Jason Haddix Revives BEEF Framework
Arcanum open sources a modernized version of the Browser Exploitation Framework that was abandoned years ago. Why browser based exploitation tools still matter for red team engagements and what the new BEEF brings to pen testing workflows.
Shia Haloud Supply Chain Worm Returns
The self replicating NPM supply chain worm strikes again, compromising packages with 2 billion downloads per month including Key V, flat cache, and file entry cache. Breaking down how the worm steals NPM tokens, GitHub credentials, AWS keys, HashiCorp Vault secrets, Kubernetes configs, and AI service credentials. Why the second order effects of all these stolen secrets keep security teams up at night.
Iran's Water Supply Attacks and the PLC Problem
Following up on Iranian threat actors targeting Minnesota water infrastructure through internet exposed PLCs vulnerable to CVEs from 2013. General Nakasone discusses the impossible scaling problem of securing 50,000 water municipalities across the US. Why there's no bat phone to call when critical infrastructure is vulnerable, the CISA defunding irony, and the knowledge management failures that plague operational technology security.







