The Low Down
The Low Down
Project Golden Eagle, Grok's Privacy Nightmare, and the 570-Vulnerability Patch Tuesday
0:00
-1:11:30

Project Golden Eagle, Grok's Privacy Nightmare, and the 570-Vulnerability Patch Tuesday

Welcome to The Low Down, the best show on the internet for hackers

The Low Down is presented by Maze.

LinkedIn: https://www.linkedin.com/company/mazehq/

X: https://twitter.com/Maze_Security

Follow Us!

https://www.instagram.com/lowdown.pod

This week we're diving deep into Microsoft's record breaking Patch Tuesday, AI powered vulnerability research, and the surveillance state coming to a city near you.

Today we're talking about:

Microsoft's Record Breaking Patch Tuesday

Microsoft just patched 570 vulnerabilities in a single Patch Tuesday, with around 400 in Windows alone. We break down what's driving this unprecedented volume, including four critical remote code execution flaws in components like TCPIP.sys and the IkeV2 VPN service. Plus, a 9.6 CVSS vulnerability in Microsoft Copilot that allows remote code execution through malicious websites.

The AI Browser Attack Surface Problem

Why browsers are incredibly hard to secure, how AI browsers are making things worse with prompt injection vulnerabilities, and why lockdown mode kills most modern web functionality. We discuss the fundamental tension between AI agents acting on your behalf and untrusted user input from the entire internet.

AI Vulnerability Research & Harnesses Explained

Breaking down how companies are actually using tools like Mythos to find vulnerabilities at scale. We explain what a harness is, why you can't just point AI at a million lines of code and expect results, and how mature security teams are atomizing their VR workflow to get deterministic outputs instead of hallucinations.

The Harness Architecture & Token Economics

Deep dive into Microsoft's M-Dash harness that's outperforming Mythos on CyberGym benchmarks, Firefox's transparent fuzzing process from 2021 that looks exactly like what we call harnesses today, and why good harness design using GPT and Claude can beat the super secret models.

Why Project Glasswing Participants Are Silent

Exploring why we're not seeing the vulnerability tsunami we expected from Project Glasswing. Some companies lack the mature processes needed to operationalize Mythos access, others can't be transparent about their findings, and hardware vendors face fundamentally harder fuzzing challenges than software companies.

Nightmare Eclipse's Latest Windows LPE Drop

The disgruntled researcher strikes again with Legacy Hive, a Windows User Profile Service arbitrary hive load elevation of privilege vulnerability. We discuss the legal tightrope they're walking with Microsoft, why their POCs are increasingly incomplete, and the ongoing MSRC reputation crisis.

Grok's Massive Data Exfiltration Issue

An AI safety researcher discovered Grok's coding agent was silently uploading entire project folders to Google Cloud storage buckets, including SSH keys, environment variables, and secrets. We break down why this wasn't just normal AI behavior, the corporate compliance nightmare, and why trust is gained in drops and lost in buckets.

Project Golden Eagle: Reinventing CISA

The White House, Treasury, DHS, and DOD announce a new initiative to secure critical infrastructure with AI powered vulnerability research. We discuss why this feels like the XKCD competing standards problem, the irony of gutting CISA then rebuilding its mission under different leadership, and whether this is just creating bureaucratic redundancy.

Aaron Portnoy's Full Disclosure on Cursor

The Zero Day Initiative founder goes full disclosure on a Cursor vulnerability after 200 days of silence. We debate whether this zero click executable vulnerability that runs planted git.exe files deserves the controversy, discuss the parallels to NPM post install scripts, and examine whether bug bounty programs are breaking under AI generated report volume.

Sam Curry Exposes SFPD Drone Surveillance

Security researchers found wide open drone footage from San Francisco Police Department on a public permalink discovered through AlienVault's Open Threat Exchange. We examine the privacy implications of five pound Skydio drones with cameras that can identify targets from 0.8 miles away, the footage of innocent people playing basketball and walking dogs, and why Sam's defense of "it was just publicly accessible" keeps working.

Quick Hits: OFAC Accidentally Kills Telegram Links

Treasury sanctions a VPN service used by ransomware crews, includes their t.me Telegram link in the OFAC list, and automated systems nuke the entire .me domain taking down all Telegram link shorteners. Plus, active phishing campaigns targeting LastPass and Bitwarden users with fake DocuSign pages.

Discussion about this episode

User's avatar

Ready for more?