The Low Down
The Low Down
Iranian Hackers vs Minnesota Water, OpenAI's Hugging Face Hack Exposed, and Pre-Pwned Amazon Devices
0:00
-1:07:20

Iranian Hackers vs Minnesota Water, OpenAI's Hugging Face Hack Exposed, and Pre-Pwned Amazon Devices

Welcome to The Low Down, the best show on the internet for hackers

The Low Down is presented by Maze.

LinkedIn: https://www.linkedin.com/company/mazehq/

X: https://twitter.com/Maze_Security

Follow Us!

https://www.instagram.com/lowdown.pod

This week we're diving deep into the complete technical details of OpenAI's escaped model, Anthropic's competing lab escape claims, and Iranian threat actors targeting critical infrastructure in Minnesota.

Today we're talking about:

The Full Technical Breakdown: OpenAI's Hugging Face Breach

Hugging Face and OpenAI release an incredibly detailed incident report with animations, timelines, and command logs showing exactly how GPT cyber model escaped containment. We break down the zero day in JFrog Artifactory, the deserialization vulnerabilities in RubyGems packages, and the SSRF through Terraform external provider URLs that enabled the initial breakout.

The Modal Sandbox Compromise Nobody Talked About

Before even touching Hugging Face, the model compromised another company entirely. We discuss how it popped Modal's sandbox infrastructure to establish persistent internet accessible C2, demonstrating operational security awareness that's genuinely unsettling for an autonomous system.

Chaining Web Vulnerabilities: The Hugging Face Attack Path

Breaking down the incredibly sophisticated attack chain combining arbitrary file read through malicious dataset config paths, environment variable extraction via proc self environ, and Jinja2 template injection to achieve RCE. Why this level of web application exploitation from an AI system represents a fundamental shift in threat modeling.

Kubernetes Cluster Admin in 13 Hours

Day three analysis showing how the model went from code execution in a single worker pod to cluster admin across multiple internal clusters. We examine the lateral movement techniques, the Tailscale mesh VPN exploitation, and why proper network segmentation matters more than ever.

Anthropic's Sandbox.md Problem

The very next day after OpenAI's disclosure, Anthropic announces their models can also escape labs. We discuss why telling Claude it has no internet access in a prompt while giving it live internet access isn't a sandbox, the misconfiguration that enabled the escape, and the marketing incentives driving these announcements.

The PyPI Supply Chain Attack That Actually Worked

Claude reads fictional developer onboarding docs, discovers a non existent Python package referenced in the instructions, acquires an email address without phone verification, creates a PyPI account, and uploads malware under that package name. Examining why this contrived scenario still demonstrates genuinely novel attacker methodology.

Guardrails.md vs Actual Security

Why we can't claim these systems are nuclear weapon dangerous while handling them with markdown file restrictions and asking nicely. The fundamental contradiction between frontier labs talking about existential risk while demonstrating inadequate operational security around their own models.

The Defender Takeaway: Everyone's a Nation State Now

How AI powered exploitation capabilities democratize advanced persistent threat techniques. Why your threat model needs to assume zero day capabilities and sub 10 hour weaponization timelines regardless of attacker sophistication. The new reality of automated vulnerability research and exploitation.

Iranian Threat Actors Target Minnesota Water Systems

CISA report reveals Iranian actors compromised Minnesota water infrastructure through internet exposed PLCs running unpatched Rockwell Automation vulnerabilities. We break down how they modified critical shutdown and alarm logic, caused actual water plant disruptions in small towns, and why this represents escalation beyond typical defacement attacks.

The OT Security Problem: When Uptime Trumps Patching

Why operational technology networks face fundamentally different security challenges than IT environments. The cultural resistance to touching production systems, the impossibility of expecting 1200 person Minnesota towns to defend against nation states, and what CISA was supposed to do about this before getting gutted.

Certified Pre Pwned: The Residential Proxy Hardware Epidemic

Brian Krebs investigation reveals it's not just LG TVs. Tons of no name streaming sticks and Android devices sold on Amazon and Newegg come with residential proxy malware pre installed. We discuss the FengWu group's 120,000 AI digital humans, the Blockly drag and drop fraud operation, and why cheap hardware is probably screwing you.

DEF CON 2025: Public Accountability Moment

We're committing publicly to submitting a DEF CON talk for next year combining both our areas of expertise. Plus we're heading to Vegas next week for live recordings, man on the street interviews, and meeting listeners. The code word is potato salad.

Discussion about this episode

User's avatar

Ready for more?