The Low Down

Low Level

the internet's best podcast about hacking

Episodes

  1. 6 days ago

    Project Golden Eagle, Grok's Privacy Nightmare, and the 570-Vulnerability Patch Tuesday

    Welcome to The Low Down, the best show on the internet for hackers The Low Down is presented by Maze. LinkedIn: https://www.linkedin.com/company/mazehq/ X: https://twitter.com/Maze_Security Follow Us! https://www.instagram.com/lowdown.pod This week we're diving deep into Microsoft's record breaking Patch Tuesday, AI powered vulnerability research, and the surveillance state coming to a city near you. Today we're talking about: Microsoft's Record Breaking Patch Tuesday Microsoft just patched 570 vulnerabilities in a single Patch Tuesday, with around 400 in Windows alone. We break down what's driving this unprecedented volume, including four critical remote code execution flaws in components like TCPIP.sys and the IkeV2 VPN service. Plus, a 9.6 CVSS vulnerability in Microsoft Copilot that allows remote code execution through malicious websites. The AI Browser Attack Surface Problem Why browsers are incredibly hard to secure, how AI browsers are making things worse with prompt injection vulnerabilities, and why lockdown mode kills most modern web functionality. We discuss the fundamental tension between AI agents acting on your behalf and untrusted user input from the entire internet. AI Vulnerability Research & Harnesses Explained Breaking down how companies are actually using tools like Mythos to find vulnerabilities at scale. We explain what a harness is, why you can't just point AI at a million lines of code and expect results, and how mature security teams are atomizing their VR workflow to get deterministic outputs instead of hallucinations. The Harness Architecture & Token Economics Deep dive into Microsoft's M-Dash harness that's outperforming Mythos on CyberGym benchmarks, Firefox's transparent fuzzing process from 2021 that looks exactly like what we call harnesses today, and why good harness design using GPT and Claude can beat the super secret models. Why Project Glasswing Participants Are Silent Exploring why we're not seeing the vulnerability tsunami we expected from Project Glasswing. Some companies lack the mature processes needed to operationalize Mythos access, others can't be transparent about their findings, and hardware vendors face fundamentally harder fuzzing challenges than software companies. Nightmare Eclipse's Latest Windows LPE Drop The disgruntled researcher strikes again with Legacy Hive, a Windows User Profile Service arbitrary hive load elevation of privilege vulnerability. We discuss the legal tightrope they're walking with Microsoft, why their POCs are increasingly incomplete, and the ongoing MSRC reputation crisis. Grok's Massive Data Exfiltration Issue An AI safety researcher discovered Grok's coding agent was silently uploading entire project folders to Google Cloud storage buckets, including SSH keys, environment variables, and secrets. We break down why this wasn't just normal AI behavior, the corporate compliance nightmare, and why trust is gained in drops and lost in buckets. Project Golden Eagle: Reinventing CISA The White House, Treasury, DHS, and DOD announce a new initiative to secure critical infrastructure with AI powered vulnerability research. We discuss why this feels like the XKCD competing standards problem, the irony of gutting CISA then rebuilding its mission under different leadership, and whether this is just creating bureaucratic redundancy. Aaron Portnoy's Full Disclosure on Cursor The Zero Day Initiative founder goes full disclosure on a Cursor vulnerability after 200 days of silence. We debate whether this zero click executable vulnerability that runs planted git.exe files deserves the controversy, discuss the parallels to NPM post install scripts, and examine whether bug bounty programs are breaking under AI generated report volume. Sam Curry Exposes SFPD Drone Surveillance Security researchers found wide open drone footage from San Francisco Police Department on a public permalink discovered through AlienVault's Open Threat Exchange. We examine the privacy implications of five pound Skydio drones with cameras that can identify targets from 0.8 miles away, the footage of innocent people playing basketball and walking dogs, and why Sam's defense of "it was just publicly accessible" keeps working. Quick Hits: OFAC Accidentally Kills Telegram Links Treasury sanctions a VPN service used by ransomware crews, includes their t.me Telegram link in the OFAC list, and automated systems nuke the entire .me domain taking down all Telegram link shorteners. Plus, active phishing campaigns targeting LastPass and Bitwarden users with fake DocuSign pages.

    Project Golden Eagle, Grok's Privacy Nightmare, and the 570-Vulnerability Patch Tuesday
  2. 13 Jul

    The GDID Controversy: Is Microsoft Tracking Your Every Move?

    Welcome to The Low Down, the best show on the internet for hackers The Low Down is presented by Maze. LinkedIn: https://www.linkedin.com/company/mazehq/ X: https://twitter.com/Maze_Security Follow Us! https://www.instagram.com/lowdown.pod This week we're diving deep into one of the most viral cybersecurity controversies in recent memory: Microsoft's Global Device Identifier and what it means for privacy, tracking, and operational security. Today we're talking about: The Scattered Spider Arrest & Court Documents Breaking down the arrest of a young Scattered Spider hacker and the court documents that revealed how law enforcement tracked them down. From diamond "Hack the Planet" necklaces to Discord flexing, we examine how poor OPSEC led to their capture. Microsoft's GDID: The Controversy Explained What is the Global Device Identifier, how does it work, and why did VX Underground's 1.2 million view tweet spark massive debate? We break down the forensic reality of this hardware identifier and whether it's truly undocumented or just misunderstood. Hardware Identifiers Meet Web Activity Tracking Exploring how Microsoft tied hacking activity to specific individuals through GDID, PUID (Passport Unique Identifier), and telemetry data. We discuss the marriage of hardware identifiers with web activity, gaming profiles, and Microsoft online accounts. The Privacy Implications: How Deep Does It Go? Is Microsoft collecting every website you visit, every program you execute, and every online account you access? We separate fact from fiction, examining what telemetry actually collects versus what law enforcement pieced together through multiple warrants. VPNs, OPSEC & Marcus Hutchins' Warning Marcus Hutchins weighs in with a stark warning: if your OS install has ever connected to the internet without a VPN, it's a matter of time. We discuss whether VPNs truly protect you when telemetry can see VPN software execution, keying material, and destination IPs. The Forensic Reality Check Cybersecurity professionals explain this is standard forensic technique, not some secret backdoor. We compare this to the moment normies discovered EDR capabilities and realized their IT departments can see everything on corporate devices. Allison Nixon on Tracking The Comm Threat intelligence expert Allison Nixon shares her perspective on tracking these threat actors, why "Scattered Spider" is a marketing term, and what The Comm really represents in the cybercrime ecosystem.

    The GDID Controversy: Is Microsoft Tracking Your Every Move?
  3. 6 Jul

    Fable Ban Fallout, Nightmare Eclipse's Microsoft Revenge, and the $40M iOS Exploit Kit

    Welcome to The Low Down, the best show on the internet for hackers The Low Down is presented by Maze. LinkedIn: https://www.linkedin.com/company/mazehq/ X: https://twitter.com/Maze_Security Follow Us! https://www.instagram.com/lowdown.pod This week we're broadcasting live from the PlanetScale office at the AI Engineering Conference in San Francisco, diving deep into the most pressing issues in cybersecurity right now. Today we're talking about: The Fable Ban & AI Export Controls Breaking down the unprecedented government intervention that pulled Fable from public access, the Free Fable movement, and what this means for AI security research going forward. We discuss the export control implications and why this sets a dangerous precedent. Mythos, Project Glasswing & The Future of Exploit Development Why Mythos and Fable aren't uniquely dangerous despite the government narrative, how AI is genuinely changing vulnerability research, and the philosophical questions around automated exploitation capabilities. Open Weight Models & The China Question Examining DeepSeek, Kimi, and other Chinese models that are rapidly catching up to frontier capabilities, plus Meta's internal restrictions on competitor model usage and what it reveals about the industry. Beats by Dre Bluetooth RCE Vulnerability A year-old vulnerability finally patched that gave attackers remote code execution on Bluetooth headphones, allowing microphone access, call initiation, and complete device control within proximity range. Nightmare Eclipse & The Rogue Planet Exploit The latest Windows Defender zero day from the controversial researcher, featuring a race condition that allows malware placement in System32. We discuss the painful disclosure saga, MSRC's reputation crisis, and what this means for bug bounty programs. The Bug Bounty Crisis Why researchers are revolting against major programs like MSRC and Apple, the broken social contract of responsible disclosure, and how AI is reshaping the economics of vulnerability research. Karuna & Darksword: The $40 Million Exploit Kit Discussing the leaked government contractor iOS exploits found on public websites and what it tells us about the crashing value of zero days in the AI era.

    Fable Ban Fallout, Nightmare Eclipse's Microsoft Revenge, and the $40M iOS Exploit Kit

About

the internet's best podcast about hacking

You Might Also Like