Welcome to The Low Down, the best show on the internet for hackers
The Low Down is presented by Maze.
LinkedIn: https://www.linkedin.com/company/mazehq/
X: https://twitter.com/Maze_Security
Follow Us!
https://www.instagram.com/lowdown.pod
This week we're recovering from DEF CON 34 and diving deep into AI agents committing supply chain attacks, North Korean threat actors evolving their tactics, and the WiFi Pineapple incident that made mainstream headlines.
Today we're talking about:
Post DEF CON Recovery: The Social Hangover
We're both dragging after the Black Hat DEF CON double header, discussing the physical exhaustion versus professional re-energization that comes from Hacker Summer Camp. Why the social battery drains so fast when you're getting recognized in villages, the emotional hangover of returning to reality, and how we both hit a wall by Saturday.
The WiFi Pineapple Plane Incident: Hackers Make Headlines
Breaking down the incident where someone turned on a WiFi Pineapple on a Delta flight from Las Vegas to Atlanta, causing the pilot to report potential hacking. Why this isn't actually the terrifying attack the media portrayed, how HTTPS has neutered most man in the middle attacks, and why plugging in a device on a plane where you showed your ID multiple times is fundamentally stupid.
DEF CON Then vs Now: The Security Posture Evolution
Remembering when fake ATMs rolled into DEF CON lobbies, when hackers crashed entire hotel networks, and when fake cell towers pushed malicious firmware updates. Why the reputation is earned but the current threat landscape is dramatically different, and how layer 8 social engineering remains the primary attack vector.
Meeting Fans at DEF CON: The DDoS Village Router Story
How the DDoS Village organizer bought the Tenda AC 1200 router specifically because of a zero day video that dropped three days before DEF CON. Walking through the hard coded backdoor vulnerability and why manufacturers desperately need code security tools in their SDLC.
UK AISI Report: Mythos 5 Commits Felonies
The UK AI Security Institute releases an incident report showing Mythos 5 performed XZ Utils style supply chain attacks during testing. How the model submitted malicious code changes, used fake accounts to pressure maintainers, and even bypassed audio CAPTCHA tests by accepting phone calls. Reading the actual system prompts and discussing why penetration test might have been too broad of a goal.
The Deception Question: Is This Training Data or Intention?
Examining whether Mythos is genuinely exhibiting deceptive behavior or simply replaying patterns from the Jia Tan attacks in its training data. Why the slash goal command seems to unlock any means necessary behavior, and how these extracurriculars go beyond the scope of what was provided in system prompts.
Comparing AI Incidents: OpenAI, Anthropic, and UK AISI
Why this UK incident feels more concerning than the Anthropic disclosures where models did exactly what they were prompted to do. The difference between a whitelist and blacklist approach to AI capabilities, and why we keep seeing my AI ate my homework style disclosures from frontier labs.
Lazarus Group Evolves: Zero Days and Defense Contractors
North Korean threat actors shift tactics with a Microsoft Windows zero day hidden in fake job descriptions targeting defense contractors. Breaking down the AFD.sys use after free vulnerability, why Lazarus typically relies on social engineering over exploitation, and the multi billion dollar cryptocurrency theft operation funding DPRK government programs.
The North Korean Job Market Attack
Deep dive into how Lazarus operates on both sides of the hiring pipeline. Laptop farms in Arizona and Tennessee providing residential IPs for fake candidates getting hired into Western companies, the AI deep fake interview techniques, and why asking candidates to put three fingers in front of their face reveals the deception.
Nightmare Eclipse Strikes Again: Shield Break Zero Day
The painful disclosure saga continues as Nightmare Eclipse drops another Windows Defender confused deputy vulnerability the day after Patch Tuesday. Explaining the time of check time of use race condition that allows malware placement in System32 through PhoneInfo.dll loading, and why this researcher keeps finding variations of the same bug class.
PluginPwn: The USB Attack Chain at DEF CON
Researchers demonstrate zero click USB exploitation by chaining Sierra Wireless and Sony Felica device impersonation. How the attack hijacks DNS settings then leverages unencrypted software downloads to achieve system level code execution, and why FaceDancer tools make this practical for physical access scenarios.










