The Low Down
The Low Down
Live from DEF CON: AI Harnesses, 1000+ Linux LPEs, and the Shia Haloud Supply Chain Worm Returns
0:00
-41:07

Live from DEF CON: AI Harnesses, 1000+ Linux LPEs, and the Shia Haloud Supply Chain Worm Returns

Welcome to The Low Down, the best show on the internet for hackers

The Low Down is presented by Maze.

LinkedIn: https://www.linkedin.com/company/mazehq/

X: https://twitter.com/Maze_Security

Follow Us!

https://www.instagram.com/lowdown.pod

This week we're broadcasting live from DEF CON 34 and Black Hat, bringing you the most important conversations happening at Hacker Summer Camp about AI security research, vulnerability orchestration, and the evolving threat landscape.

Today we're talking about:

Live from DEF CON: The Community Experience

Recording from the Biohacking Village at DEF CON 34, we discuss what makes this conference special. From the Maritime Hacking Village to the DDoS Village, we explore how the grassroots community atmosphere differs from Black Hat's corporate environment. Meeting listeners, getting recognized by village organizers, and why the code word is potato salad.

Black Hat Keynotes: The Future of AI Vulnerability Research

Dave Weston from Microsoft and Professor Jan from ASU delivered game changing talks on what happens when AI makes vulnerabilities abundant rather than scarce. Breaking down how ASU accidentally proved that orchestrated Codex agents outperform single Mythos instances, and what this means for the economics of vulnerability markets and formal verification.

The Harness Revolution: Why Orchestration Still Matters

Deep dive into why we're in a sine wave pattern between model capabilities and harness quality. The real juice isn't telling AI to find bugs with no mistakes. It's building sophisticated vulnerability research machines that leverage AI as one component. Why context management and scaffolding remain the competitive advantage even as models improve.

1Password Research: The Auto Remediation Reality Check

Keith's team at 1Password drops research showing only 26% of AI generated vulnerability patches were actually usable. Breaking down how even the best models partnering with top tier firms like Trail of Bits still introduce new bugs while fixing old ones. Why humans in the loop remain essential and you can't change the shape of the pipeline that produces bugs just by patching faster.

Meeting OpenAI Leadership: The Cyber Model Question

Conversation with OpenAI co founder Greg about what would happen if they released their most capable cyber model with no guardrails. Discussing the philosophical questions around AI security research capabilities, export controls, and whether we're measuring danger correctly. Plus OpenAI shows up unscheduled at Black Hat to explain the Hugging Face incident from their perspective.

Black Hat Vendor Floor: The AI Crab Evolution

Examining how the security vendor landscape has evolved into 75 plus AI SOC companies all converging on similar solutions. Why evolution keeps producing crabs in nature and in cybersecurity products. The challenge of differentiation when investor pressure pushes everyone toward the same features.

Casey Ellis and Disclose.io: Fixing Vulnerability Reporting

BugCrowd founder Casey Ellis launches Disclose.io to solve the full disclosure problem plaguing smaller vendors. How an AI agent runs nightly to self heal gaps in the vulnerability reporting database. Why researchers claiming they couldn't find who to report to is often BS, and how this project aims to remove that excuse.

Jason Haddix Revives BEEF Framework

Arcanum open sources a modernized version of the Browser Exploitation Framework that was abandoned years ago. Why browser based exploitation tools still matter for red team engagements and what the new BEEF brings to pen testing workflows.

Shia Haloud Supply Chain Worm Returns

The self replicating NPM supply chain worm strikes again, compromising packages with 2 billion downloads per month including Key V, flat cache, and file entry cache. Breaking down how the worm steals NPM tokens, GitHub credentials, AWS keys, HashiCorp Vault secrets, Kubernetes configs, and AI service credentials. Why the second order effects of all these stolen secrets keep security teams up at night.

Iran's Water Supply Attacks and the PLC Problem

Following up on Iranian threat actors targeting Minnesota water infrastructure through internet exposed PLCs vulnerable to CVEs from 2013. General Nakasone discusses the impossible scaling problem of securing 50,000 water municipalities across the US. Why there's no bat phone to call when critical infrastructure is vulnerable, the CISA defunding irony, and the knowledge management failures that plague operational technology security.

Discussion about this episode

User's avatar

Ready for more?