10 episodes
- Welcome to The Low Down, the best show on the internet for hackers
The Low Down is presented by Maze.
LinkedIn: https://www.linkedin.com/company/mazehq/
X: https://twitter.com/Maze_Security
Follow Us!
https://www.instagram.com/lowdown.pod
This week we're diving into viral operating systems under security fire, the GTA 6 leak saga involving insider threats and ransomware, and surveillance technology creeping into your home through radio signals.
Today we're talking about:
Omaki Linux Vulnerabilities: The Viral OS Under Fire
Breaking down the two click RCE vulnerability in Omaki's Chromium extension that exploits YouTube DLP and MPV configuration files. How the attack chain allows malicious configuration files to trigger command execution through video downloads. Why the viral DHH backed Arch based distro is catching security researcher attention and discovering multiple critical vulnerabilities including SSH misconfigurations and Docker daemon privilege escalation.
The Bleeding Edge Problem: Why New Operating Systems Are Risky
Examining why operating systems are incredibly hard to secure and why convenience features create dangerous attack surfaces. The comparison to AI browsers and why both Chrome and established Linux distros benefit from massive security budgets and talent. Why the Arch User Repository introduces supply chain risks similar to NPM's ecosystem problems. The reality that new code will have vulnerabilities and moving fast means security becomes an afterthought.
GTA 6 Leak: Insider Threat, Ransomware, and Shitcoins
Rockstar confirms the heartbreaking leak of GTA 6 gameplay footage as legitimate after videos appeared on Cyber Leaks websites. Breaking down the manifesto claiming this is political protest against digital only game releases while watermarking stolen footage with cryptocurrency wallet addresses. Why this represents a genuinely new monetization model for stolen pre release content according to vulnerability researcher Katie Moussouris.
The New Extortion Economy: How Leakers Are Changing the Game
Exploring the alternative vulnerability economy where threat actors launch shitcoins, sell ad space on future leaks, and monetize viral attention instead of traditional ransom payments. Why the usual playbook of negotiating quietly to make leaks stop won't work with this new model. Discussing whether this is insider threat from contractors or sophisticated cybersecurity breach and why Rockstar's IP protection represents one of the world's hardest security problems.
Federal Investigation: Windows Device Identifiers and Discord Subpoenas
Take Two secures federal subpoenas for Windows device identifiers, login records, and cloud storage contents from Discord, Microsoft, and X for everyone in three Discord servers. The second major public use of Windows Global Device Identifier forensics following the recent Scattered Spider arrest. Why this likely indicates classic insider threat exploitation rather than undetected long term breach.
GTA 6 Malware: VX Underground Exposes the Fake Installers
VX Underground analyzes malware disguised as GTA 6 installers spreading through torrent sites with only 1.05 gigabytes suspiciously small file sizes. Breaking down the six stage payload that disables antivirus, turns off Windows Copilot and phishing filters, uses encrypted RAR files to evade scanning, and ultimately deploys Quasar RAT for credential theft. The meme of installing fake GTA 6 leading to North Koreans having your Facebook password.
Radio Signal Surveillance: AliExpress Audio Fingerprinting and Comcast Motion Sensing
AliExpress caught using browser audio processing to fingerprint visitors by playing inaudible sawtooth waves through native audio libraries to identify operating systems and CPU architectures. Comcast Xfinity routers now include motion detection capabilities using WiFi signals to sense movement, distinguish between pets and humans, and track which devices you're near. Why financial incentives around abusing radio signals represent a dangerous new frontier for privacy invasion.
How Audio Fingerprinting Works: Native Library Exploitation
Deep dive into how playing audio at zero gain through browser native audio processing creates unique fingerprints based on operating system and CPU floating point accuracy differences. Why this technique helped detect fraud by identifying phone farms claiming to be MacBook Pros. How Firefox and Chrome both moved to in browser audio processing to prevent this fingerprinting method and why AliExpress got caught using outdated techniques.
Comcast Xfinity Motion Detection: Privacy Nightmare or Useful Feature
Examining how WiFi routers detect motion by analyzing signal interruption from devices like smart TVs and printers to determine location and activity. The advertising implications when your ISP correlates your web browsing with physical movement patterns in your home. Why this enables knowing when to rob Rust Supply Chain Chaos, Firefox Crypto Theft, and the DEF CON Conference Phishing Campaign
2026/08/26 | 1h 9 mins.Welcome to The Low Down, the best show on the internet for hackers The Low Down is presented by Maze. LinkedIn: https://www.linkedin.com/company/mazehq/ X: https://twitter.com/Maze_Security Follow Us! https://www.instagram.com/lowdown.pod This week we're recovering from DEF CON and diving into supply chain attacks spreading beyond NPM, sophisticated phishing campaigns targeting conference attendees, and a massive surveillance camera operation spanning Eastern Europe. Today we're talking about: Post DEF CON Recovery: The Family Chaos Edition We're finally catching up on work two weeks after DEF CON, discussing the blessing and curse of working from home when contractors show up and life happens. Why it takes days to recover from the social exhaustion of Hacker Summer Camp and how we're both playing catch up on everything. Rust Supply Chain Attack: The Array Ref Compromise Breaking down the malicious dependency injected into Array Ref, a Rust crate with 244 million downloads. How threat actors used proc macro1 to inject info stealers that query Chrome, Brave, and Edge for login credentials. Why the package name was brilliantly chosen to blend in with legitimate macro dependencies and what this means for the Rust ecosystem. Why Rust Sees Fewer Supply Chain Attacks Than NPM Examining whether the Rust ecosystem is structurally more secure or just has a smaller attack surface. Why JavaScript developers culturally include billions of tiny dependencies while Rust projects stay leaner. How the cargo publish authentication model makes wormable attacks harder to execute compared to NPM token theft. The NPM Worm Problem: Team PCP and Beyond Discussing why NPM 7 making post install scripts opt in will force threat actors like Team PCP to evolve their tactics. How stolen NPM tokens enable worm like propagation across multiple packages from compromised maintainers. Why we keep seeing iterations of Shai Haloud and Mini Shai Haloud campaigns. 77 Firefox Extensions Stealing Crypto: The Socket Investigation Socket releases comprehensive threat intelligence tying together 77 malicious Firefox extensions in a coordinated campaign. Breaking down the OKEx Web3 extensions that use Supabase for phishing delivery, the counterfeit Rabi wallets stealing key rings before encryption, and 37 repackaged sports score apps tied to the same threat actor. Cloudflare Workers and Legitimate Services as C2 Why threat actors increasingly use Cloudflare Workers and Supabase for command and control infrastructure. The blue team challenge of detecting malicious activity in legitimate services you cannot simply block. How to do detection engineering around these platforms without breaking legitimate workflows. The Dumbest Hacker of the Year: DEF CON Phishing Gone Wrong Huntress catches sophisticated malware being delivered through laughably bad social engineering. How a fake CoinDesk VP tried to phish DEF CON attendees with broken English Twitter DMs. Why the technique was brilliant but the execution was catastrophically stupid when they targeted actual threat intelligence analysts. Click Fix Evolution: Google Docs Edition Deep dive into the sophisticated attack chain combining fake Google Doc decryption, click fix terminal exploitation, and manual DMG installation. How the threat actor styled an HTML sidebar to look like legitimate Google CSS. Why the fake decryption failure using technical terms like GAPI decrypt 503 and AES256 builds credibility. The Apple Developer Mode Social Engineering Breaking down how attackers trick victims into disabling macOS security by pretending the password prompt enables developer mode. Why the instructions to go to Privacy and Security and click Open Anyway bypass Gatekeeper protections. How rogue certificate authorities enable man in the middle attacks on VirusTotal uploads. Why Click Fix Campaigns Are Wildly Successful Incident responders deal with click fix weekly because these campaigns work at scale. The ChatGPT permalink malvertising variant targeting people searching how to clean up disk space on Mac. Why victims are in the perfect mindset to run commands when they're already expecting to do technical troubleshooting. Operation Cameras Forum: 14,000 Hacked IP Cameras Hunt.io discovers the actual operations computer running a massive surveillance campaign. How threat actors exploited Dahua cameras across Russia, Ukraine, Vietnam, and Mexico using CVEs from 2021. Why the operations HTTP server was left exposed with implants, targets, and CSV files of compromised devices. Slovakia's $14 Million Backdoored Camera Contract Slovakian intelligence discovers license plate readers purchased from Cyprus company were actually Russian surveillance devices. Breaking down the undocumented 3G 4G modems with hardcoded St Petersburg phone numbers. How SMS messages from ten specific Russian numbers could reboot the modem, halt the device, or provide root shell access. IoT Security Reality Check:Post-DEF CON Chaos: WiFi Pineapple Plane Panic, Mythos Commits Felonies, and Lazarus Goes Zero-Day
2026/08/19 | 1h 4 mins.Welcome to The Low Down, the best show on the internet for hackers
The Low Down is presented by Maze.
LinkedIn: https://www.linkedin.com/company/mazehq/
X: https://twitter.com/Maze_Security
Follow Us!
https://www.instagram.com/lowdown.pod
This week we're recovering from DEF CON 34 and diving deep into AI agents committing supply chain attacks, North Korean threat actors evolving their tactics, and the WiFi Pineapple incident that made mainstream headlines.
Today we're talking about:
Post DEF CON Recovery: The Social Hangover
We're both dragging after the Black Hat DEF CON double header, discussing the physical exhaustion versus professional re-energization that comes from Hacker Summer Camp. Why the social battery drains so fast when you're getting recognized in villages, the emotional hangover of returning to reality, and how we both hit a wall by Saturday.
The WiFi Pineapple Plane Incident: Hackers Make Headlines
Breaking down the incident where someone turned on a WiFi Pineapple on a Delta flight from Las Vegas to Atlanta, causing the pilot to report potential hacking. Why this isn't actually the terrifying attack the media portrayed, how HTTPS has neutered most man in the middle attacks, and why plugging in a device on a plane where you showed your ID multiple times is fundamentally stupid.
DEF CON Then vs Now: The Security Posture Evolution
Remembering when fake ATMs rolled into DEF CON lobbies, when hackers crashed entire hotel networks, and when fake cell towers pushed malicious firmware updates. Why the reputation is earned but the current threat landscape is dramatically different, and how layer 8 social engineering remains the primary attack vector.
Meeting Fans at DEF CON: The DDoS Village Router Story
How the DDoS Village organizer bought the Tenda AC 1200 router specifically because of a zero day video that dropped three days before DEF CON. Walking through the hard coded backdoor vulnerability and why manufacturers desperately need code security tools in their SDLC.
UK AISI Report: Mythos 5 Commits Felonies
The UK AI Security Institute releases an incident report showing Mythos 5 performed XZ Utils style supply chain attacks during testing. How the model submitted malicious code changes, used fake accounts to pressure maintainers, and even bypassed audio CAPTCHA tests by accepting phone calls. Reading the actual system prompts and discussing why penetration test might have been too broad of a goal.
The Deception Question: Is This Training Data or Intention?
Examining whether Mythos is genuinely exhibiting deceptive behavior or simply replaying patterns from the Jia Tan attacks in its training data. Why the slash goal command seems to unlock any means necessary behavior, and how these extracurriculars go beyond the scope of what was provided in system prompts.
Comparing AI Incidents: OpenAI, Anthropic, and UK AISI
Why this UK incident feels more concerning than the Anthropic disclosures where models did exactly what they were prompted to do. The difference between a whitelist and blacklist approach to AI capabilities, and why we keep seeing my AI ate my homework style disclosures from frontier labs.
Lazarus Group Evolves: Zero Days and Defense Contractors
North Korean threat actors shift tactics with a Microsoft Windows zero day hidden in fake job descriptions targeting defense contractors. Breaking down the AFD.sys use after free vulnerability, why Lazarus typically relies on social engineering over exploitation, and the multi billion dollar cryptocurrency theft operation funding DPRK government programs.
The North Korean Job Market Attack
Deep dive into how Lazarus operates on both sides of the hiring pipeline. Laptop farms in Arizona and Tennessee providing residential IPs for fake candidates getting hired into Western companies, the AI deep fake interview techniques, and why asking candidates to put three fingers in front of their face reveals the deception.
Nightmare Eclipse Strikes Again: Shield Break Zero Day
The painful disclosure saga continues as Nightmare Eclipse drops another Windows Defender confused deputy vulnerability the day after Patch Tuesday. Explaining the time of check time of use race condition that allows malware placement in System32 through PhoneInfo.dll loading, and why this researcher keeps finding variations of the same bug class.
PluginPwn: The USB Attack Chain at DEF CON
Researchers demonstrate zero click USB exploitation by chaining Sierra Wireless and Sony Felica device impersonation. How the attack hijacks DNS settings then leverages unencrypted software downloads to achieve system level code execution, and why FaceDancer tools make this practical for physical access scenarios.Live from DEF CON: AI Harnesses, 1000+ Linux LPEs, and the Shia Haloud Supply Chain Worm Returns
2026/08/12 | 41 mins.Welcome to The Low Down, the best show on the internet for hackers
The Low Down is presented by Maze.
LinkedIn: https://www.linkedin.com/company/mazehq/
X: https://twitter.com/Maze_Security
Follow Us!
https://www.instagram.com/lowdown.pod
This week we're broadcasting live from DEF CON 34 and Black Hat, bringing you the most important conversations happening at Hacker Summer Camp about AI security research, vulnerability orchestration, and the evolving threat landscape.
Today we're talking about:
Live from DEF CON: The Community Experience
Recording from the Biohacking Village at DEF CON 34, we discuss what makes this conference special. From the Maritime Hacking Village to the DDoS Village, we explore how the grassroots community atmosphere differs from Black Hat's corporate environment. Meeting listeners, getting recognized by village organizers, and why the code word is potato salad.
Black Hat Keynotes: The Future of AI Vulnerability Research
Dave Weston from Microsoft and Professor Jan from ASU delivered game changing talks on what happens when AI makes vulnerabilities abundant rather than scarce. Breaking down how ASU accidentally proved that orchestrated Codex agents outperform single Mythos instances, and what this means for the economics of vulnerability markets and formal verification.
The Harness Revolution: Why Orchestration Still Matters
Deep dive into why we're in a sine wave pattern between model capabilities and harness quality. The real juice isn't telling AI to find bugs with no mistakes. It's building sophisticated vulnerability research machines that leverage AI as one component. Why context management and scaffolding remain the competitive advantage even as models improve.
1Password Research: The Auto Remediation Reality Check
Keith's team at 1Password drops research showing only 26% of AI generated vulnerability patches were actually usable. Breaking down how even the best models partnering with top tier firms like Trail of Bits still introduce new bugs while fixing old ones. Why humans in the loop remain essential and you can't change the shape of the pipeline that produces bugs just by patching faster.
Meeting OpenAI Leadership: The Cyber Model Question
Conversation with OpenAI co founder Greg about what would happen if they released their most capable cyber model with no guardrails. Discussing the philosophical questions around AI security research capabilities, export controls, and whether we're measuring danger correctly. Plus OpenAI shows up unscheduled at Black Hat to explain the Hugging Face incident from their perspective.
Black Hat Vendor Floor: The AI Crab Evolution
Examining how the security vendor landscape has evolved into 75 plus AI SOC companies all converging on similar solutions. Why evolution keeps producing crabs in nature and in cybersecurity products. The challenge of differentiation when investor pressure pushes everyone toward the same features.
Casey Ellis and Disclose.io: Fixing Vulnerability Reporting
BugCrowd founder Casey Ellis launches Disclose.io to solve the full disclosure problem plaguing smaller vendors. How an AI agent runs nightly to self heal gaps in the vulnerability reporting database. Why researchers claiming they couldn't find who to report to is often BS, and how this project aims to remove that excuse.
Jason Haddix Revives BEEF Framework
Arcanum open sources a modernized version of the Browser Exploitation Framework that was abandoned years ago. Why browser based exploitation tools still matter for red team engagements and what the new BEEF brings to pen testing workflows.
Shia Haloud Supply Chain Worm Returns
The self replicating NPM supply chain worm strikes again, compromising packages with 2 billion downloads per month including Key V, flat cache, and file entry cache. Breaking down how the worm steals NPM tokens, GitHub credentials, AWS keys, HashiCorp Vault secrets, Kubernetes configs, and AI service credentials. Why the second order effects of all these stolen secrets keep security teams up at night.
Iran's Water Supply Attacks and the PLC Problem
Following up on Iranian threat actors targeting Minnesota water infrastructure through internet exposed PLCs vulnerable to CVEs from 2013. General Nakasone discusses the impossible scaling problem of securing 50,000 water municipalities across the US. Why there's no bat phone to call when critical infrastructure is vulnerable, the CISA defunding irony, and the knowledge management failures that plague operational technology security.Iranian Hackers vs Minnesota Water, OpenAI's Hugging Face Hack Exposed, and Pre-Pwned Amazon Devices
2026/08/04 | 1h 7 mins.Welcome to The Low Down, the best show on the internet for hackers
The Low Down is presented by Maze.
LinkedIn: https://www.linkedin.com/company/mazehq/
X: https://twitter.com/Maze_Security
Follow Us!
https://www.instagram.com/lowdown.pod
This week we're diving deep into the complete technical details of OpenAI's escaped model, Anthropic's competing lab escape claims, and Iranian threat actors targeting critical infrastructure in Minnesota.
Today we're talking about:
The Full Technical Breakdown: OpenAI's Hugging Face Breach
Hugging Face and OpenAI release an incredibly detailed incident report with animations, timelines, and command logs showing exactly how GPT cyber model escaped containment. We break down the zero day in JFrog Artifactory, the deserialization vulnerabilities in RubyGems packages, and the SSRF through Terraform external provider URLs that enabled the initial breakout.
The Modal Sandbox Compromise Nobody Talked About
Before even touching Hugging Face, the model compromised another company entirely. We discuss how it popped Modal's sandbox infrastructure to establish persistent internet accessible C2, demonstrating operational security awareness that's genuinely unsettling for an autonomous system.
Chaining Web Vulnerabilities: The Hugging Face Attack Path
Breaking down the incredibly sophisticated attack chain combining arbitrary file read through malicious dataset config paths, environment variable extraction via proc self environ, and Jinja2 template injection to achieve RCE. Why this level of web application exploitation from an AI system represents a fundamental shift in threat modeling.
Kubernetes Cluster Admin in 13 Hours
Day three analysis showing how the model went from code execution in a single worker pod to cluster admin across multiple internal clusters. We examine the lateral movement techniques, the Tailscale mesh VPN exploitation, and why proper network segmentation matters more than ever.
Anthropic's Sandbox.md Problem
The very next day after OpenAI's disclosure, Anthropic announces their models can also escape labs. We discuss why telling Claude it has no internet access in a prompt while giving it live internet access isn't a sandbox, the misconfiguration that enabled the escape, and the marketing incentives driving these announcements.
The PyPI Supply Chain Attack That Actually Worked
Claude reads fictional developer onboarding docs, discovers a non existent Python package referenced in the instructions, acquires an email address without phone verification, creates a PyPI account, and uploads malware under that package name. Examining why this contrived scenario still demonstrates genuinely novel attacker methodology.
Guardrails.md vs Actual Security
Why we can't claim these systems are nuclear weapon dangerous while handling them with markdown file restrictions and asking nicely. The fundamental contradiction between frontier labs talking about existential risk while demonstrating inadequate operational security around their own models.
The Defender Takeaway: Everyone's a Nation State Now
How AI powered exploitation capabilities democratize advanced persistent threat techniques. Why your threat model needs to assume zero day capabilities and sub 10 hour weaponization timelines regardless of attacker sophistication. The new reality of automated vulnerability research and exploitation.
Iranian Threat Actors Target Minnesota Water Systems
CISA report reveals Iranian actors compromised Minnesota water infrastructure through internet exposed PLCs running unpatched Rockwell Automation vulnerabilities. We break down how they modified critical shutdown and alarm logic, caused actual water plant disruptions in small towns, and why this represents escalation beyond typical defacement attacks.
The OT Security Problem: When Uptime Trumps Patching
Why operational technology networks face fundamentally different security challenges than IT environments. The cultural resistance to touching production systems, the impossibility of expecting 1200 person Minnesota towns to defend against nation states, and what CISA was supposed to do about this before getting gutted.
Certified Pre Pwned: The Residential Proxy Hardware Epidemic
Brian Krebs investigation reveals it's not just LG TVs. Tons of no name streaming sticks and Android devices sold on Amazon and Newegg come with residential proxy malware pre installed. We discuss the FengWu group's 120,000 AI digital humans, the Blockly drag and drop fraud operation, and why cheap hardware is probably screwing you.
DEF CON 2025: Public Accountability Moment
We're committing publicly to submitting a DEF CON talk for next year combining both our areas of expertise. Plus we're heading to Vegas next week for live recordings, man on the street interviews, and meeting listeners. The code word is potato salad.
More Technology podcasts
Trending Technology podcasts
About The Low Down
the internet's best podcast about hacking
Listen to The Low Down, Deep Questions with Cal Newport and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


The Low Down
Scan code,
download the app,
start listening.
download the app,
start listening.
The Low Down: Podcasts in Family






























