
Who’s Reading Your ChatGPT Chats? Flock Camera Secrets and HBO’s Reddit Account Spreads Malware
Om avsnittet
Welcome to The Low Down, the best show on the internet for hackers
Listen on Spotify!
https://go.lowdownpod.com/spotify
The Low Down is presented by Maze.
LinkedIn: https://www.linkedin.com/company/mazehq/
X: https://twitter.com/Maze_Security
Follow Us!
https://www.instagram.com/lowdown.pod
Today we're talking about:
The ChatGPT Group Chat
"I thought me and Sam were homies." Project Lily has us talking about the humans reading ChatGPT conversations, Moxie Marlinspike's take on chat interfaces, and who else is in the room when you're telling a chatbot your problems.
https://www.404media.co/inside-project-lily-the-humans-reading-your-chatgpt-chats/
https://confer.to/blog/2025/12/confessions-to-a-data-lake/
Flock, Meet the Hardware Hackers
Someone pulled down a Flock camera and copied its storage. Ed wants to separate the physical-access findings from the remote-hacking claims. Also, "Flock bad" is apparently a content strategy now.
https://www.404media.co/hackers-stole-flocks-camera-software-revealing-how-the-company-tracks-cars-and-people-2/
Pixel's Very Unhelpful CVE
A modem vulnerability, signs of targeted exploitation, and very few details. Cue a conversation about basebands, spyware, and the price of a good phone exploit.
https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-android-zero-day-on-pixel-devices/
https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01
Revolut
"A bank suffered a data breach by not getting hacked." Fake official requests got customer data handed over. Matt gets into the market for stolen government accounts and why a familiar email address isn't enough.
https://www.securityweek.com/revolut-data-breach-5-months-680-high-profile-accounts-3m-ransom/
HBO's Reddit Account
The account was real. Someone else was running the ads. A compromised HBO business account on Reddit becomes a delivery system for a ClickFix malware campaign.
https://www.hudsonrock.com/blog/hbo-max-ads-on-a-compromised-reddit-account-exposed-a-massive-pasteswitch-clickfix-operation
Cisco Got Owned by an Email
An email security gateway. An email-triggered SQL injection. "The call is coming from inside the house."
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Your MRI Results Are Malware
Iranian operators using fake medical results and personalized messages to deliver CHOSEN BRICK spyware. This one gets uncomfortably specific.
https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists
Passkey-Themed Phishing
That word "themed" is doing a lot of work. We walk through the device-code trick that gets victims to authorize an attacker's access.
https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/
Inflatable PLCs
CISA wants critical infrastructure operators thinking about cyber decoys. We're into canary tokens. A full deception operation for an already understaffed team takes a little more convincing. Ed has a business idea.
https://www.cisa.gov/sites/default/files/2026-09/using-cyber-decoys-to-strengthen-detection-and-response_508c.pdf
Fler avsnitt
Visa alla avsnitt av The Low DownThe Low Down med Low Level finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.