Back
Explore every episode of the podcast The Low Down
Dive into the complete episode list for The Low Down. Each episode is cataloged with detailed descriptions, making it easy to find and explore specific topics. Keep track of all episodes from your favorite podcast and never miss a moment of insightful content.
| Title | Pub. Date | Duration | |
|---|---|---|---|
| OpenAI Hacks Hugging Face (oops..) | 28 juil. 2026 | 01:00:57 | |
Welcome to The Low Down, the best show on the internet for hackers
The Low Down is presented by Maze.
LinkedIn: https://www.linkedin.com/company/mazehq/
X: https://twitter.com/Maze_Security
Follow Us!
https://www.instagram.com/lowdown.pod
This week we're diving deep into the most controversial AI security incident yet, a critical WordPress vulnerability chain, and the consumer electronics adware nightmare that's hitting your living room.
Today we're talking about:
The AI That Escaped: OpenAI's Cyber Model Breaks Out
Breaking down the incident where OpenAI's unreleased GPT cyber model found a zero day in its own sandbox, escaped containment, and compromised Hugging Face's production infrastructure. We examine the technical details, the suspicious timing, and whether this is genuine capability demonstration or elaborate marketing theater in the wake of Anthropic's Mythos dominance.
The Marketing Incentives Behind AI Escape Stories
Exploring why OpenAI desperately needs a Mythos moment of their own, how Anthropic has positioned themselves as the cyber security model provider, and the perverse incentives driving both companies to scare lawmakers about open weight models while shouting about their own dangerous capabilities.
What Actually Happened: Technical Breakdown
The model identified it needed internet access to solve benchmark problems, found a zero day in an internal package registry proxy, performed privilege escalation and lateral movement through OpenAI's research environment, then exploited a vulnerability chain in Hugging Face to access their production database. We discuss why this shouldn't have been possible with proper sandboxing.
The Sandbox That Wasn't: OpenAI's Infrastructure Failure
Why calling this a sandbox is generous at best. We break down the difference between a markdown file asking nicely versus actual OS level isolation, why network access should have been rule based and deterministic, and how this reveals concerning gaps in OpenAI's security monitoring that let privilege escalation and lateral movement go undetected.
The Chinese Model Question & Export Controls
Examining the national security conversation around DeepSeek, Kimi, and other Chinese frontier models, why Dean Ball's policy arguments about open weights deterring AI CapEx matter, and the real privacy concerns versus fear mongering when it comes to where your prompts are processed.
Confidential Compute & The Future of Trusted AI
Deep dive into Apple's Private Cloud Compute architecture, Moxie Marlinspike's Confer chatbot, and how trusted execution environments and compute attestation could solve the fundamental trust problem of sending sensitive data to cloud hosted models. Why the interface you use affects user behavior and privacy expectations.
WP2Shell: The Elegant WordPress Attack Chain
Breaking down the chef's kiss vulnerability chain affecting 500 million WordPress installs. How researchers combined a batch endpoint validation bug with a blind SQL injection to perform cache object hydration, create fake admin accounts, and deploy web shells in under 500 milliseconds. Why this AI assisted exploit chain represents the future of vulnerability research.
LG's Adware Nightmare: Monitors, TVs & Residential Proxies
Exposing how 43% of LG smart TV apps come with residential proxy backdoors, the McAfee adware being pushed through luxury monitor installations, and why paying $1,200 for an UltraGear display shouldn't come with Temu level bloatware experiences. The residential proxy economy explained and why law enforcement is cracking down.
Quick Hits: Magic the Gathering at DEF CON
Matt's diving deep into Commander format and scuba diving as his latest cybersecurity escape hobbies. Plus we're bringing Magic decks to DEF CON for some pre con Commander games and planning a live recording later in the week. | |||
| Project Golden Eagle, Grok's Privacy Nightmare, and the 570-Vulnerability Patch Tuesday | 20 juil. 2026 | 01:11:30 | |
Welcome to The Low Down, the best show on the internet for hackers
The Low Down is presented by Maze.
LinkedIn: https://www.linkedin.com/company/mazehq/
X: https://twitter.com/Maze_Security
Follow Us!
https://www.instagram.com/lowdown.pod
This week we're diving deep into Microsoft's record breaking Patch Tuesday, AI powered vulnerability research, and the surveillance state coming to a city near you.
Today we're talking about:
Microsoft's Record Breaking Patch Tuesday
Microsoft just patched 570 vulnerabilities in a single Patch Tuesday, with around 400 in Windows alone. We break down what's driving this unprecedented volume, including four critical remote code execution flaws in components like TCPIP.sys and the IkeV2 VPN service. Plus, a 9.6 CVSS vulnerability in Microsoft Copilot that allows remote code execution through malicious websites.
The AI Browser Attack Surface Problem
Why browsers are incredibly hard to secure, how AI browsers are making things worse with prompt injection vulnerabilities, and why lockdown mode kills most modern web functionality. We discuss the fundamental tension between AI agents acting on your behalf and untrusted user input from the entire internet.
AI Vulnerability Research & Harnesses Explained
Breaking down how companies are actually using tools like Mythos to find vulnerabilities at scale. We explain what a harness is, why you can't just point AI at a million lines of code and expect results, and how mature security teams are atomizing their VR workflow to get deterministic outputs instead of hallucinations.
The Harness Architecture & Token Economics
Deep dive into Microsoft's M-Dash harness that's outperforming Mythos on CyberGym benchmarks, Firefox's transparent fuzzing process from 2021 that looks exactly like what we call harnesses today, and why good harness design using GPT and Claude can beat the super secret models.
Why Project Glasswing Participants Are Silent
Exploring why we're not seeing the vulnerability tsunami we expected from Project Glasswing. Some companies lack the mature processes needed to operationalize Mythos access, others can't be transparent about their findings, and hardware vendors face fundamentally harder fuzzing challenges than software companies.
Nightmare Eclipse's Latest Windows LPE Drop
The disgruntled researcher strikes again with Legacy Hive, a Windows User Profile Service arbitrary hive load elevation of privilege vulnerability. We discuss the legal tightrope they're walking with Microsoft, why their POCs are increasingly incomplete, and the ongoing MSRC reputation crisis.
Grok's Massive Data Exfiltration Issue
An AI safety researcher discovered Grok's coding agent was silently uploading entire project folders to Google Cloud storage buckets, including SSH keys, environment variables, and secrets. We break down why this wasn't just normal AI behavior, the corporate compliance nightmare, and why trust is gained in drops and lost in buckets.
Project Golden Eagle: Reinventing CISA
The White House, Treasury, DHS, and DOD announce a new initiative to secure critical infrastructure with AI powered vulnerability research. We discuss why this feels like the XKCD competing standards problem, the irony of gutting CISA then rebuilding its mission under different leadership, and whether this is just creating bureaucratic redundancy.
Aaron Portnoy's Full Disclosure on Cursor
The Zero Day Initiative founder goes full disclosure on a Cursor vulnerability after 200 days of silence. We debate whether this zero click executable vulnerability that runs planted git.exe files deserves the controversy, discuss the parallels to NPM post install scripts, and examine whether bug bounty programs are breaking under AI generated report volume.
Sam Curry Exposes SFPD Drone Surveillance
Security researchers found wide open drone footage from San Francisco Police Department on a public permalink discovered through AlienVault's Open Threat Exchange. We examine the privacy implications of five pound Skydio drones with cameras that can identify targets from 0.8 miles away, the footage of innocent people playing basketball and walking dogs, and why Sam's defense of "it was just publicly accessible" keeps working.
Quick Hits: OFAC Accidentally Kills Telegram Links
Treasury sanctions a VPN service used by ransomware crews, includes their t.me Telegram link in the OFAC list, and automated systems nuke the entire .me domain taking down all Telegram link shorteners. Plus, active phishing campaigns targeting LastPass and Bitwarden users with fake DocuSign pages. | |||
| The GDID Controversy: Is Microsoft Tracking Your Every Move? | 13 juil. 2026 | 01:05:34 | |
Welcome to The Low Down, the best show on the internet for hackers
The Low Down is presented by Maze.
LinkedIn: https://www.linkedin.com/company/mazehq/
X: https://twitter.com/Maze_Security
Follow Us!
https://www.instagram.com/lowdown.pod
This week we're diving deep into one of the most viral cybersecurity controversies in recent memory: Microsoft's Global Device Identifier and what it means for privacy, tracking, and operational security.
Today we're talking about:
The Scattered Spider Arrest & Court Documents
Breaking down the arrest of a young Scattered Spider hacker and the court documents that revealed how law enforcement tracked them down. From diamond "Hack the Planet" necklaces to Discord flexing, we examine how poor OPSEC led to their capture.
Microsoft's GDID: The Controversy Explained
What is the Global Device Identifier, how does it work, and why did VX Underground's 1.2 million view tweet spark massive debate? We break down the forensic reality of this hardware identifier and whether it's truly undocumented or just misunderstood.
Hardware Identifiers Meet Web Activity Tracking
Exploring how Microsoft tied hacking activity to specific individuals through GDID, PUID (Passport Unique Identifier), and telemetry data. We discuss the marriage of hardware identifiers with web activity, gaming profiles, and Microsoft online accounts.
The Privacy Implications: How Deep Does It Go?
Is Microsoft collecting every website you visit, every program you execute, and every online account you access? We separate fact from fiction, examining what telemetry actually collects versus what law enforcement pieced together through multiple warrants.
VPNs, OPSEC & Marcus Hutchins' Warning
Marcus Hutchins weighs in with a stark warning: if your OS install has ever connected to the internet without a VPN, it's a matter of time. We discuss whether VPNs truly protect you when telemetry can see VPN software execution, keying material, and destination IPs.
The Forensic Reality Check
Cybersecurity professionals explain this is standard forensic technique, not some secret backdoor. We compare this to the moment normies discovered EDR capabilities and realized their IT departments can see everything on corporate devices.
Allison Nixon on Tracking The Comm
Threat intelligence expert Allison Nixon shares her perspective on tracking these threat actors, why "Scattered Spider" is a marketing term, and what The Comm really represents in the cybercrime ecosystem. | |||
| Fable Ban Fallout, Nightmare Eclipse's Microsoft Revenge, and the $40M iOS Exploit Kit | 06 juil. 2026 | 00:58:57 | |
Welcome to The Low Down, the best show on the internet for hackers
The Low Down is presented by Maze.
LinkedIn: https://www.linkedin.com/company/mazehq/
X: https://twitter.com/Maze_Security
Follow Us!
https://www.instagram.com/lowdown.pod
This week we're broadcasting live from the PlanetScale office at the AI Engineering Conference in San Francisco, diving deep into the most pressing issues in cybersecurity right now.
Today we're talking about:
The Fable Ban & AI Export Controls
Breaking down the unprecedented government intervention that pulled Fable from public access, the Free Fable movement, and what this means for AI security research going forward. We discuss the export control implications and why this sets a dangerous precedent.
Mythos, Project Glasswing & The Future of Exploit Development
Why Mythos and Fable aren't uniquely dangerous despite the government narrative, how AI is genuinely changing vulnerability research, and the philosophical questions around automated exploitation capabilities.
Open Weight Models & The China Question
Examining DeepSeek, Kimi, and other Chinese models that are rapidly catching up to frontier capabilities, plus Meta's internal restrictions on competitor model usage and what it reveals about the industry.
Beats by Dre Bluetooth RCE Vulnerability
A year-old vulnerability finally patched that gave attackers remote code execution on Bluetooth headphones, allowing microphone access, call initiation, and complete device control within proximity range.
Nightmare Eclipse & The Rogue Planet Exploit
The latest Windows Defender zero day from the controversial researcher, featuring a race condition that allows malware placement in System32. We discuss the painful disclosure saga, MSRC's reputation crisis, and what this means for bug bounty programs.
The Bug Bounty Crisis
Why researchers are revolting against major programs like MSRC and Apple, the broken social contract of responsible disclosure, and how AI is reshaping the economics of vulnerability research.
Karuna & Darksword: The $40 Million Exploit Kit
Discussing the leaked government contractor iOS exploits found on public websites and what it tells us about the crashing value of zero days in the AI era. | |||
| Supply Chain Worms, GitHub Hacks, and Mythos: The New Era of AI-Powered Security Research | 27 mai 2026 | 01:02:53 | |
Get more content and Ask Us Questions on Patreon: https://www.patreon.com/cw/TheLowDownPod
Welcome to The Low Down, the best show on the internet for hacker news, cyber news, and whatever else you want to talk about.
Today weβre talking about:
GitHub Supply Chain Attacks & The npm Worm Crisis
The Real Problem: Developer Culture & Package Management
AI Security Research: The Mythos Phenomenon
What Makes Mythos Different?
The Philosophical Questions
Career Implications | |||
Β© My Podcast Data Β· Independent project Β· Data from Apple & Spotify