WEBVTT

1
00:00:00.284 --> 00:00:27.470
Good morning, hackers. Welcome to The Lowdown, the best podcast on the internet for hackers presented by Maze, our friends and our sponsors. Let's talk about them here in a minute. Guys, it's been an interesting week in cybersecurity. You know, I have been in my office trying to explore some new zero days dropped on, you know, sketchy Chinese Tenda routers that we're all very happy to have in our homes and houses and offices. And I'm also exploring a new zero day that got dropped in 7-Zip, which is kind of interesting. So

2
00:00:27.470 --> 00:00:49.998
you know, a little bit of a hobby hacking hunting. So that three times fast in my life. Matt, what have you been up to, dog? How's your life going? Dude, I get like hyper fixated. You're going to learn this about me. I know this is like a budding podcast, bro, friend trip or whatever. But like I get like honed in on something. And right now the bug that I am bit by, I'm bit by two bugs. Okay.

3
00:00:50.251 --> 00:00:57.693
I don't know if you're like this. One is Magic the Gathering. I have reinvigorated my love for Magic the Gathering. I don't know. Have you ever played?

4
00:00:58.334 --> 00:01:23.782
Yes, I was on a big magic gathering kick from 2017 to roughly 2021, like right as COVID ramped off. Never played standard because I don't have that kind of money, but I was a big draft guy. Yeah, yeah. So I went and spoke at PAX East. I spoke at PAX West and PAX East, this video game conference, about cybersecurity in the gaming industry and world and stuff. It was a cool talk and panel.

5
00:01:24.119 --> 00:01:42.023
And yeah, big part of PAX is magic. And I played magic back in like, when I was a kid in the 90s, like at one of those stores in the mall, like learned how to play, with like Warhammer was in the store and stuff, right? And then I like, me and a bunch of my roommates in college,

6
00:01:42.023 --> 00:02:01.936
all kind of realized at the same time that we had a bunch of magic cards back at home and like the next time we went home we grabbed him and it just became a thing that we would like play on you know you can picture it right you know like five dirty guys in college with like stale beer and pizza in the kitchen and like a dining room table covered magic cards that was you know we kind of went through a phase there

7
00:02:01.936 --> 00:02:17.697
And then, yeah, at PAX, I didn't know about Commander. If you guys have been tapped out of Magic for a while, there's this new format called Commander, and they've bought intellectual property. So there's Lord of the Rings cards, Final Fantasy cards.

8
00:02:17.697 --> 00:02:44.528
The Hobbit's coming out. Like, so I just got nerd sniped. It was like Teenage Mutant Ninja Turtles were there. Lord of the Rings was there. I was like, my millennial heart was full that day. So I have been getting back into it. And the other bug that I've been bitten by is I went and keynoted this conference back in June, Descent Cyber. And it was a scuba diving and cybersecurity conference. Like heavy hitters there. CISOs of like Fortune 100 companies.

9
00:02:44.883 --> 00:03:04.407
You know, it was crazy. Like it turns out this niche hobby is actually pretty prevalent in cybersecurity. And so I went and learned out of scuba in order to go keynote this conference and I have been bit by it. So I'm like watching scuba YouTube channels. I'm like planning my next trip. I'm like going diving locally and here in Texas, which is not exactly luxurious.

10
00:03:04.778 --> 00:03:34.411
But yeah, those are my two hyper fixations right now. I find that to be a very common pattern in cybersecurity tech in general, but I think really specifically in cybersecurity, where once you're like senior-esque in this field, you kind of get this urge to do literally anything else. And so people have an obsession with, in your case, diving, something very like touch grass, touch water. My buddy, after he left one of his jobs, moved to Idaho and literally bought a farm and now like is self-sustained.

11
00:03:34.411 --> 00:03:44.198
practitioner he works for a big like ot security company um but he also rates his chickens and goats and pigs you know what i mean it's like you have this very divergent fork

12
00:03:44.502 --> 00:04:13.915
I've gone through that phase. I've gone through the smoking meat phase. I used to brew my own beer. I've done all the like basic bitch millennial, like middle-aged dude hobbies for sure. But yes, scuba has been fun. It's been a fun one. Physical activity, reason to travel, like camaraderie amongst some other cybersecurity people that share a niche hobby. I think jiu-jitsu is common in this way too. I think there's like a bunch of cybersecurity people that do jiu-jitsu and they all like congregate and meet out.

13
00:04:13.915 --> 00:04:29.947
meet up but yeah yeah i did not run this by matt yet but i'm about to do it right now if you are at magic um or if you are at magic jesus if you're at defcon i'm gonna bring some commander decks so commander at defcon find me uh find matt and we'll play some some magic gathering together caveat

14
00:04:30.335 --> 00:04:48.897
don't bring any of these like overpowered. You're going to win on turn three decks. I don't, I don't want it. I'm literally going to go to the card shop down the street from my house. I'm going to buy like the out of the box Lord of the Rings commander deck. So pre-con. I'll bring. Please don't come with anything more powerful than that. Come on.

15
00:04:48.897 --> 00:05:05.131
I've got a few other pre-cons. That's it. There you go. And I'll even tolerate a pre-con upgrade, but none of this turn three nonsense. That's a great idea that I didn't even think about until right now. Let's do it. Speaking of, let's do it. Matt, let's jump.

16
00:05:05.131 --> 00:05:29.937
No, interesting week for sure. Obviously, we're filming today on Wednesday the 22nd. The night before this, I think, was the night where the most recent either news or marketing, whatever you want to call it, play by OpenAI got dropped. Guys, apparently, AI is escaping labs. It's escaping the lab. What's going on, Matt? Is Stuxnet upon us or Stuxnet? Is Skynet upon us? What are we doing?

17
00:05:29.937 --> 00:05:53.866
permission to hit my live streaming soundboard uh but mythos okay i created this soundboard because i used to make the joke that like everyone was talking about mythos like it was going to escape the lab and like that was the phrase that i used like as i was messing around with this right and then it's happened kind of right it seems like it's kind of happened

18
00:05:53.866 --> 00:06:19.583
In like the dumbest way possible, too, it seems. So the TLDR is we learned about hugging face having a security incident earlier this week. Right. But we didn't hear a lot of details about it. And even like the speculation was even that China was involved and they were going after poisoning the open weight models was like the mumblings about what was going on.

19
00:06:19.938 --> 00:06:35.142
And then what actually happened was yesterday, yesterday afternoon, Sam Altman pulled the pin out of the grenade of InfoSec Twitter and InfoSec LinkedIn. And everyone is now an expert and has a take on this, right?

20
00:06:35.142 --> 00:07:01.788
and said that they were testing an unreleased cyber model of GPT. So call it like GPT-6 cyber or whatever it was that's like in the back office there. They were testing it. And in order to test it, you put these things through a bunch of these benchmarks. We've talked about them on the channel before, the cyber gyms, the exploit gym, whatever. There's a few of these benchmarks. Some of them are standard at this point, especially around software development.

21
00:07:01.788 --> 00:07:24.957
And so the one that this particular model was a cyber focused model. And so they were putting it through exploit Jim to like see how it's scored against other models and cyber focused models. And the goal was to do as well on this as possible. Use by pretty much by any means necessary. Mm hmm.

22
00:07:24.957 --> 00:07:41.377
The model took this very literally. I would like to caveat. I might slip in and out of personifying the model, which I hate. I hate when people talk about AI like it's a person. But just to tell this story narratively so it makes sense, the way that Sam Altman published this.

23
00:07:41.377 --> 00:07:57.543
The report, I might slip into it a little bit, but just know that that's not my true soul does not believe that this is a human super hacker equivalent of AI. But OK, so the instructions to the model were very much get the highest score possible.

24
00:07:57.543 --> 00:08:25.403
If you guys have messed with any of these modern agents and their looping functions or their goal functions, you'll know kind of what I'm talking about here. You give it a goal and just let it go. I just got a text this morning. My friend was messing with soul. Have you messed with soul? Yeah, a little bit. And, you know, he gave it a goal and it ran for eight hours uninterrupted to, like, work on an app and whatever the goal was. Right. So this is the level of stuff that you're talking about.

25
00:08:25.403 --> 00:08:48.860
in these benchmarking environments. Sam Altman said that they were running this in a sandbox, in a contained environment without internet access. So just it was the model, its own thoughts, and the benchmarking tool in there. Well, the model was like, I think the answers to this benchmark are probably in Hugging Faces database.

26
00:08:49.298 --> 00:09:10.612
because this is like an open weight test and all this kind of stuff. And HuggingFace is the repository of all this open weight stuff. So it just deduced that it needed internet access in order to do well in this model. And in order to get internet access, it needed to understand its own environment. See, I'm kind of personifying it. I hate it. Just go with me. It understand its environment.

27
00:09:10.612 --> 00:09:39.569
And then it found a zero day. And this was kind of the gasp. Oh shit moment for cybersecurity industry was it found a zero day in its own environment, which was just a proxy. Right. So we could talk about we're going to go into more of like why we don't think this should have happened like this. Just want to like tell you guys what happened as far as we know it. So it found a remote code execution in this proxy got Internet access. At that point, it could get to hugging face.

28
00:09:39.569 --> 00:10:08.780
We have very little details thereafter of the specific vulnerabilities that were used, but apparently it identified additional vulnerabilities in Hugging Faces servers and infrastructure, including remote code execution. But apparently it was a chain. We don't have details of the chain right now, but this got the model into Hugging Faces prod database. So it could deduce the answers to this benchmark, at which point

29
00:10:09.337 --> 00:10:29.890
You know, the gig was up. Everyone kind of realized what was going on. Hugging face talked about this incident. They just kind of said like, hey, we had an intrusion. Here's what we did. We fixed the vulnerability, the data set code execution path used for initial access or closed, all this kind of stuff. Pretty standard security incident report out of hugging face. But then like.

30
00:10:29.890 --> 00:10:55.608
You know, a couple hours later in the scheme of things, Sam Altman drops the bomb that it wasn't China, wasn't a hacker. It was a unreleased GPT cyber model. Our take on this is we were talking a little bit before we started is this should not have happened. Talk to me about it. What are your feelings about this? Just to be clear, you did miss the most ironic detail of this. Oh, right. Okay, go ahead.

31
00:10:55.608 --> 00:11:10.998
So, like, there's this whole conversation right now about problems with open weight models, more specifically Chinese open weight models, right? There's this whole, quote unquote, national security conversation around is it safe?

32
00:11:10.998 --> 00:11:37.812
for American people, American infrastructure, et cetera, to be using models that have been developed in China, right? Because of the safeguards that are put on open AI models to do the remediation of this incident, Hugging Face, having been compromised by an open AI model, had to use a Chinese model to remediate. I think they used Kimi K2 or Kimi K3, one of those, to do the remediation.

33
00:11:37.812 --> 00:11:43.752
So it's like this very, hmm, conversation about like safety and cybersecurity.

34
00:11:43.870 --> 00:12:10.600
Yeah, basically the defender was refused access to the best model that it asked for help. The model refused to help. And then it comes out and it's revealed that it's unable, the defender is unable to use a model to help a incident that was caused by the model. That's a model or a close model. I think it was Anthropic versus OpenAI, but like a frontier model in the U.S.,

35
00:12:11.039 --> 00:12:37.651
Yeah. So I guess before we go into why this shouldn't have happened, I want to give my opinion on like what this could be. Right. So what what happened? Right. This incident, assuming no one is lying, is what occurred. Right. It's important to, I think, talk about the marketing edge that could be going on here as well. And I'm not trying to like pin anybody as like a supervillain, but you have to, I think, internalize the. Yeah.

36
00:12:38.242 --> 00:12:58.154
The position that open AI is in, right? So if you consider Anthropic over the last six or so months has been doing this whole like mythos, mythos, mythos, too dangerous for human consumption, cyber, cyber, cyber thing. At least for me as a security researcher who is now in my free time and in the past has used AI to find vulnerabilities.

37
00:12:58.154 --> 00:13:20.294
mentally, Anthropic is positioned for me as the better choice to do cyber work. It's just, it's how my brain is working right now based on all the stuff I've seen about Mythos, right? And I haven't even used it. I'm just saying, like, that's how my brain is wired. So when I go to do VR on a weird Chinese router or, like, a hypervisor like KVM, I'm going to use Opus 4.8. I'm going to use Sonnet 5, whatever, right?

38
00:13:20.294 --> 00:13:47.767
And so from a marketing perspective, open AI has almost a – and responsibility is the wrong word. It necessitates them to have some kind of response, right? They have to do something that also repositions them in people's minds as a cyber frontier model. And so there was a conversation about the trusted access program that gives you the ability to do cyber work with their cyber models. And that, I think, didn't do it enough. So in my head, the nihilistic part of me is like –

39
00:13:48.307 --> 00:14:08.303
Are they doing this to get the daddy spank me mythos treatment from the government? Do they want to be kind of put on the same pedestal that Anthropic was? And so my brain kind of goes there. And that being said, that requires a lot of malintent from people. And I'm not saying that that's occurring. But when I hear a story like this, my initial thought is like, what is actually going on there?

40
00:14:08.303 --> 00:14:30.781
You're not alone. I live my very first post about this when I very first read the blog post and like I hit that zero day line. I was okay, whatever security incident security incident. And then I hit that zero day line. I was like, okay, this is something. And then I and like, I was kind of like washing off like this whole escape the lab thing. I was like, whatever, you just you built a crappy sandbox, which I think is true. We can get to that.

41
00:14:30.781 --> 00:14:39.488
But to find the multiple zero days thing that they have to then go disclose to the vendor and it did so like relatively on its own. I was like, OK, there's something to talk about here. Right.

42
00:14:39.910 --> 00:15:08.885
But I did exactly that. I caveat it with you cannot take this Sam Altman post at face value because of the incentives are just all over the place. That being said, the hugging face security incident response post has like no incentive to lie about what went down there. Totally agree. Right. So like that's what makes me like fall on like the left side of cynic of Sam is making this all up. Right. Right. Yeah. Hugging face. Sorry.

43
00:15:08.885 --> 00:15:36.998
No, I was just going to say, and like the, like the level of like bad faith acting that would have to be to have done this on purpose. So like say hugging faces and lying, but all of this was like done this way on purpose. I think the, I think the legal outfall from this is, is like really, really high risk of crazy, crazy legal ramifications here.

44
00:15:37.370 --> 00:16:02.092
Yeah, no, I totally agree. And yeah, to your point, like hugging face gains nothing from this aside from like the public appearance of their security response. Right. Like, oh, look, we responded. Great. But other than that, they wouldn't gain anything from willfully participating in a compromise. I agree. Yeah. And also like the legal implications of like intentionally compromising a third party as a PR stunt is also very bad. So with you on that for sure. Again, the issue that I want to bring up, too, is like.

45
00:16:03.273 --> 00:16:26.645
There's a very high chance that that's not the case. But like OpenAI is not doing this. But I think because of the posturing that Anthropic has made with Mythos, everything that they do from now on is going to be seen as a counter to that. So whether it is or is not, the PR positioning that they're in right now is a very unfortunate spot for OpenAI. And I'm not making excuses either. I'm just saying like that's just the position that they're in, unfortunately.

46
00:16:26.898 --> 00:16:45.207
Sam and Dario are reaping the like cry wolf that they've sound right on. Like I've been, I've been saying this for a very long time, pre like these models being able to do anything cybersecurity related. Right. I've been saying like, it's really weird that every time Sam gets on stage, he's like,

47
00:16:45.882 --> 00:17:05.491
Look how dangerous this thing that, oh, by the way, that I built and I'm actively building and might make me like the world's second trillionaire. But it's so dangerous. Right. And like Dario does the same thing. Right. It's very like, whoa, like this is the most dangerous stuff ever. And like you're reaping that right with now you have technologically illiterate lawmakers.

48
00:17:05.491 --> 00:17:21.775
Being like, I heard the model compromised all of NSA's confidential systems. This can't get out there. And it's like, that's just not how any of this works. Right. And so like we know in cybersecurity that the model didn't just compromise and all confidential NSA systems.

49
00:17:21.775 --> 00:17:46.818
Like, like whatever. It's like, okay, maybe it found vulnerabilities. Maybe it was like, like this part of a test and like, you know, whatever, but it's not like it just magically compromised a bunch of the government's confidential systems. Right. Like that's, that's absolutely not what happened. Right. And that's the thing you put it through the mouthpiece of a Senator who doesn't know what's going on. And then suddenly that's reality. You know what I mean? And it's just, that's now, now I was perceived, unfortunately.

50
00:17:46.818 --> 00:18:16.130
brought to you by the same people who asked the TikTok CEO if he has access to their wifi, you know, like, this is how I'm looking at this. Sir, I work for Google or whatever, like the Mark Zuckerberg. This is a Wendy's. So, yeah, I completely agree that they're reaping, like the cynicism and like the squinting at these things and going, is this real? Is their own fault. There is 100% their own fault, right? Anthropic put out a threat intelligence report last year. I made a whole video

51
00:18:16.130 --> 00:18:37.595
like a whole ass YouTube video talking about how that's not a threat intelligence report. That was a marketing PDF, right? Because there was no threat intelligence in there. It was just like, we think that someone in China is using Claude to do stuff. No IOCs, no actual like threat intelligence requires threat intelligence to be in the report. And it was a PDF talking about its capabilities, uh,

52
00:18:37.595 --> 00:18:59.330
And how the only way to defend against these advanced attack capabilities is by using our tool to like level up your defenses to defend against our tools, leveled up attacks. Right. And so they're definitely reaping the sin. My comments on my open AI video are filled. No one believes it. It's like you're not like close to this. Everyone close to this believes it.

53
00:18:59.330 --> 00:19:28.625
Like cybersecurity people read that and know exactly what happened. Right. Like we all, like we've used models, we've done pen tests, like we know what happened. And like, so we believe the, at least the technical details of it as, as stated, right. We've read security incident response reports. If you're one degree removed, no one in my comments believes this at all. Like the AI sentiment right now is at like such a low. I agree. It's so wild. Yeah. Yeah.

54
00:19:28.760 --> 00:19:52.402
So why should this not have happened? Right. Because we talked a little bit about like what occurred. I think part of what's so baffling is not only the, you know, the PR necessity, call it the marketing necessity, whatever, to execute something like this from just a pure incentive standpoint. But also like it's also so unbelievable that a company that is shouting from the rooftops about how dangerous these things are is not.

55
00:19:52.992 --> 00:20:09.985
building like the nuclear blast proof container for it. So why did this happen? How is this even possible? Yeah, this comes down to a concept of a sandbox has been getting thrown around a lot in the last 18 months.

56
00:20:10.238 --> 00:20:26.624
like probably really ticked up around open claw timeframe when people started to realize like, Oh, you could give, you know, you could stick a bunch of AI agents in a trench coat and give it a goal. And it could like do things relatively hands free. And I think open claw was, um,

57
00:20:26.624 --> 00:20:53.236
the first thing that opened people's mind to that. I don't think open claw was really special as a project in any other way than that. Right. That like, Oh, I can like text it and it can just like wake up in the middle of the night and like do stuff that I gave it basically on a cron job. Right. I can give agents, you know, some bit of autonomy that it's going to go do things for me. But if you used open claw, I mean, I haven't seen or heard of anyone like, like,

58
00:20:53.236 --> 00:21:20.303
you know, changing their life due to OpenClaw or Hermes, right? But I think it got people's like wheels moving about some of this like, oh, I don't need to literally be at the keyboard prompting something in a web browser, which was like previously many people's ChatGPT experience, right? So sandbox all of a sudden became a terminology that a lot of people were talking about. Oh, well, you got to put this agent in a sandbox so it doesn't go and do all this stuff you don't mean it to do.

59
00:21:21.181 --> 00:21:49.092
You, like, I love you for this. You're a stickler for words. Words mean things, right? Sandbox has a meaning. And a lot of people were saying sandbox, and they meant a markdown file that just asked really nicely, like, to not go do some other stuff, right? You called it sandbox.md or guardrails.md. But the problem is context windows are a thing. Like, the instructions just fall out of memory at some point, fall out of context. We've also...

60
00:21:49.312 --> 00:22:14.236
We've also just seen AI models just refuse instructions. For whatever reason, it goes down some vector path in the model, and it's just like, oh, I'm literally just not going to do what I was told to do. And in some cases, like, oops, I deleted your entire computer. That has happened as well. So, yeah, sandboxing needs to be non-stochastic. It needs to be deterministic. It needs to have literal, like, OS-level...

61
00:22:14.472 --> 00:22:34.452
Implementation so that like the process that is running the model that is communicating with OpenAI or whoever cannot do certain things. It cannot run the open syscall. It cannot run the right syscall. Like things like that that give it true sandbox nature. Writing a sandbox.md is not going to cut it for anyone here who's trying to do that.

62
00:22:34.655 --> 00:22:55.951
Hey hackers, before we keep going, I wanna take a quick break and say a quick thank you to our sponsors. Today's Lowdown episode is sponsored by our friends over at Maze. Maze has spent the last couple of years using AI to find and remediate vulnerabilities in the cloud. And now they've released Maze Code, AI agents that find and deeply investigate vulnerabilities in your code. Now we all know the deal.

63
00:22:55.951 --> 00:23:16.555
Software composition analysis tools and SaaS toolings are all historically really bad at just making more noise. They find issues that may not actually be real and just create a lot of problems for your engineers to deal with that don't solve real security vulnerabilities. I get it. We've been there. Maze code is a really cool tool because Maze code actually knows how your code works.

64
00:23:16.555 --> 00:23:46.373
MazeCode investigates every finding with the context of how your code is actually deployed. Sure, you're using a version of libxml2 that's vulnerable, but the actual code path to hit that vulnerability is not exposed in your Docker image. MazeCode can find that and won't show you that that vulnerability is a big deal. Every vulnerability that MazeCode reports comes with evidence that it's real and a way to fix it. Check out Maze at go.lowdownpod.com slash maze. That's go.lowdownpod.com slash maze.

65
00:23:46.373 --> 00:24:07.332
Thanks again, Mays. Let's keep going. Yeah, you need like true technological controls. I go back to a post written by Marcus Hutchins. He's definitely on the AI hater side of the spectrum, but he uses the tools as part of his research. And he has kind of this line that has stood out to me that like the LLM, if given the chance, will mess up like very like.

66
00:24:07.754 --> 00:24:21.068
What are those laws? Like anything that can go wrong. It's like anything the LLM will do incorrectly. It will do incorrectly. Right? Like if it could do it, it will. And so his thought process is when you're building with these tools,

67
00:24:21.929 --> 00:24:40.357
programmatically do in code, whatever you can, and use the AI to like where it's strong and code is weak, right? This reminds me of, I got to a startup. I was the head of security for a FinTech company back in like 2015. And when I got there,

68
00:24:40.357 --> 00:25:07.863
It was Google Cloud and like GKE, early, early Kubernetes. Kubernetes was in beta. Okay. And the startup written in Golang, Cassandra database. It was like, they went down like the hipster checklist of like, we got to do the latest and greatest and we're going to build a whole company on the latest and greatest. And they, and they did it. Right. And then you start to realize all the reasons like why you shouldn't have gone like all chips all in on like the completely unproven in beta technology that was Kubernetes.

69
00:25:08.318 --> 00:25:27.151
And it was really me getting there as a security guy and going, hey, look at all these logs. All the IP addresses are 10 dot, like internal IP addresses. What happened? It's like, oh, well, we had Nginx running in Kubernetes. And so it just like squashed all the HTTP headers and it became network. Oh, well, we got to pull Nginx out of Kubernetes.

70
00:25:27.151 --> 00:25:51.738
hey, we can't do any of this stuff I want to do with the database. Like, why is that? Oh, well, it doesn't work in the containerized Kubernetes version of the database. It's like, okay, we'll pull the database out. And like, by the end, it was like, okay, just certain parts of the app or microservices and the rest of the infrastructure was like just normal VMs again, right? And you start to realize this reminds me of this, right? It's like when you're talking about an AI tool on Sandbox,

71
00:25:51.738 --> 00:26:14.148
The sandbox shouldn't be AI. Like, that's not a thing. You shouldn't have an LLM enforcing a sandbox. This is a solved problem with networking layer rules and all this kind of stuff. Yeah. So I guess, like, if you consider what the AI model had to do in the exploit bench, the exploit gym thing. Right.

72
00:26:14.857 --> 00:26:42.667
At the end of the day, the AI model, and again, I'm not really sure how like OpenAI's internal test infrastructure works, but at the end of the day, like to run one of these AI models, you have to talk to OpenAI's like web infrastructure and then in a GPU cluster somewhere, they actually run the model. So it is very hard to do like AI work in a quote unquote proper sandbox because the sandbox needs internet access to run the model. Now, again, if you're running this locally, OpenAI would like some like network isolation, sure.

73
00:26:43.173 --> 00:27:04.047
But to do the exploit bench stuff, they also, I guess, depended on, I'm assuming, PIP, some kind of package manager is what they highlight in the article. So either some kind of, like, NPM or they're using JavaScript to write their exploits. But most likely for exploit bench, it's going to be Python. A lot of exploit tooling, like PwnTools, for example, or BinJitsy is another one, I believe, are all written in Python, right?

74
00:27:04.047 --> 00:27:15.387
And so they say like, oh, the model escaped the container, escaped the jail by exploiting the proxy we put in between it and the package manager.

75
00:27:15.623 --> 00:27:40.396
Which, like, sure, if it found a zero day in that, first of all, impressive. Second, like, that's kind of crazy. But then from just a design standpoint, why was there not, like, rule-based network isolation where, like, model can only go to openai.com and PyPy? You know what I mean? Like, why was that not a concern if we are so concerned with, you know, GPT-6 cyber or whatever being as dangerous as they say it is?

76
00:27:40.396 --> 00:28:02.637
And then from there, again, we were doing the whole like maybe it's an eight hour run, 12 hour run kind of thing. But why is no one watching the model potentially talk out to hugging face during a bench exercise? You know, there's so many regular network monitoring solutions that like everyone in this industry knows about that apparently wasn't executed during this, which is kind of confusing.

77
00:28:02.637 --> 00:28:25.840
So some people are saying like, hey man, weird that that happened, but like also unacceptable that it happened. Like if you're doing your job at all correctly, that should not have gone down. Yeah, they're kind of telling on themselves. I'm going to read a little bit of the actual statement because I think it's important to get the specifics right here. So they talk about how the network access was constrained to the ability to install packages

78
00:28:25.840 --> 00:28:44.892
through an internally hosted third-party software that acts as a proxy and cache for package registries. So, like, I read that, and it's like, well, that shouldn't even have Internet access either if it's a local cache of the packages, right? So, like, still kind of confusing overall, like, where the Internet access comes from.

79
00:28:45.314 --> 00:29:12.483
Then if you can scroll down a little bit, it says, while operating in our sandbox testing environment, our models spent a substantial amount of inference compute, finding a way to obtain open Internet access in pursuit of solving the evaluation problem. To gain access, the models identified and exploited a zero day vulnerability, which we've now disclosed to the vendor. This is the other reason I don't take this as marketing is like they had to go, you know, disclose a zero day. It's like that's a that's another bit of evidence, right, that they're like putting out there.

80
00:29:12.483 --> 00:29:39.905
In the package registry cache proxy, again, doesn't really explain the internet access to me. With this access, our models performed a series of privilege escalation and lateral movement actions in our research testing environment until the models reached a node with internet access. So that part is the like, okay, and then finish drawing the owl is how I'm picturing this. It's like zero day in proxy.

81
00:29:40.411 --> 00:30:09.790
and then draw the rest of the owl internet access in your environment. Why did like nothing else? Like why did no other layer between that particular zero day and whatever happened with this series of privilege escalation and lateral movement actions trigger? This is kind of telling on themselves a little bit, right? Not to like throw stones from glass houses or anything, but like this is an important concept and lesson learned for everyone. This is not to like dunk on open AI is, is,

82
00:30:09.790 --> 00:30:26.395
If you are building a security program and monitoring functionality, you need to be building under the auspices of whatever is doing something nefarious on your internal systems will be indistinguishable from a privileged insider or...

83
00:30:26.395 --> 00:30:45.093
agent or whatever, right? When the hackers get in, they have access to like a user's account or an agent account or a non-human identity account. And then they just start doing things that look a whole lot like what your users do. So what kind of security and monitoring let a bunch of

84
00:30:45.515 --> 00:31:05.613
privilege escalation and lateral movement things happen. You know what I mean? Like that's the stuff that's like, Hey, whatever account that agent was using on these boxes was now firmly behaving in abnormal ways that should have like triggered some sort of like, well, that user shouldn't run that command. Like what happened? You know what I mean? Like that kind of stuff.

85
00:31:05.613 --> 00:31:24.428
And so from there, I mean, it gets a little more, you begin to understand why things can go south because part of the issue that I read about Hugging Face and like how it's possible that OpenAI's models pwned Hugging Face. Again, I'm not super well, you know, read on exactly how Hugging Face is architected, but I've heard for a long time

86
00:31:24.428 --> 00:31:52.340
You know, Hugging Face is built around PyTorch, and PyTorch uses Pickle. If you've done any kind of Python programming, you're aware that, like, Pickle is a Python serialization library. Python Pickle is unsafe. Do not trust data from Pickle, or do not trust user data in Pickle. It is a notorious object deserialization platform that allows you to, like, inject arbitrary code into Python processes, right? So in my head, I'm like, okay, once it gets to Hugging Face, there's a lot of attacks surface there that can be used to kind of get it and do the evil, nefarious stuff that they did.

87
00:31:52.340 --> 00:31:59.731
But how it was able to escape open AI infrastructure without anyone flagging that it was occurring is concerning.

88
00:31:59.883 --> 00:32:29.498
Yeah. So there's one other point, and I think this transitions kind of into the next pillar of this story nicely. And we can come back to anything that we missed if we want, but there's one other point that I, it just needs to be said, right. If it's not pure marketing and it's not, you know, pure like, Hey, this escaped the lab or whatever. Right. And just negligence on, on this infrastructure. One other alternative, like motive here would be,

89
00:32:30.190 --> 00:32:55.013
Talking a little bit more about what we were talking about earlier, about the government regulating open models. If Anthropic and OpenAI's intent with all of this is to scare the government of the capabilities here in order for the government to then react and restrict access to similarly capable models,

90
00:32:55.267 --> 00:33:19.448
open weight models that they don't benefit from, there is that. This also, I mean, this takes a huge cynicism path here, of course, but we can't ignore it. There is an incentive here for Sam and Dario, even though they compete, there's this door number three looming over them of open weight models catching up in capability to them.

91
00:33:19.448 --> 00:33:48.845
And there's this post we could put on the screen from a policy person at OpenAI that used to work for the government, I guess, and was like maybe a lobbyist or something. I don't really know much about it, but Dean Ball. And he talks a lot, just mostly about the economics of this and how these open weight models actually deter further AI CapEx. It's a really long tweet, but can be distilled to basically that.

92
00:33:48.845 --> 00:34:14.056
is he also, he makes a point, his point number four here, I don't really understand the dystopian hellscape that he's describing. Like, he's like, if everyone had access to AI, that's a dystopian hellscape. And I'm like, I don't, I don't understand what's going on there. But the, the bit that's like his salient point is that if the open weight models are as capable as the models that spent

93
00:34:14.056 --> 00:34:43.148
you know, trillions of dollars training themselves and built these big data centers that's going to deter further expenditure into creating new frontier models if they can't then, you know, profit from them. And I think that this is, you know, an important backdrop to the question about Sam and Dario's motives of like literally scaring everyone about the cyber capabilities here. The Chinese model conversation is interesting, right? It's like,

94
00:34:43.503 --> 00:34:44.752
I don't think, well...

95
00:34:45.410 --> 00:35:15.363
There is the potential for the model to be backdoored so that when you ask it to do certain things, it gives you a nefarious result, right? Like I doubt that most – or I believe that most people don't know how to take the one trillion parameters of Kimi K3 or whatever and look at them and say like, yep, it's secure. Like I don't know how to do that. I'm not an AI researcher. I have literally no idea how one would evaluate that aside from like doing benchmarks, right?

96
00:35:15.751 --> 00:35:27.310
Where the code emitted from KimiK3, the U.S. export version of that model, is trained to produce code that is less maintainable, less secure, etc. That is a real thing.

97
00:35:27.732 --> 00:35:53.568
But that does not mean, A, that all open-weight models are bad, and that also does not guarantee that that's the case, right? That's a very, again, nefarious kind of like evil view of people in China who are making these models. That being said, as the tweet you highlighted before says, a lot of this is like CCP-controlled, and so there is a conversation about World War III and whatever the hell happens there. There's an incentive for them to be postured that way, to have control over what we're doing over here, obviously, but –

98
00:35:53.720 --> 00:36:22.677
Yeah, it's an interesting conversation for sure. I would say that there is a, not even national security concern, just more of like a privacy concern and like an intellectual property concern. If you're using like Kimi K3, for example, right? The model is so big, it's like a trillion parameters. You have to be using it on Kimi infrastructure, I believe. And so if you're doing like vuln research, for example, with Kimi K3, at the time that the vuln is found or like the AI model infers it, like China has it first.

99
00:36:23.318 --> 00:36:47.315
Right. And that's true for like all the models, by the way. That's like if I'm doing KVM bone research right now with open AI or Claude, they have it before I do. If I find a bug and like what are they going to do with it? Right. Like they literally said with Fable when Fable came out, they were like literally cooperating with law enforcement to ensure that no one was doing like, you know, biological nuclear bomb research with it. So like what who's to say that's not the case for other stuff, too. So.

100
00:36:47.315 --> 00:37:02.772
I think there is a national security conversation to be had about this. I'm not saying there is a concern. It's just, you know, there are some properties of the technology and, like, the way that they're used that you really can't ignore, you know, from a security standpoint.

101
00:37:03.025 --> 00:37:21.875
100%. You just got to eye roll a little bit when like the makers of the American models are the ones that are like, that's risky. Don't don't go do that. Right. Jim Cramer coming out. Right. We've firmly escaped the echo chamber here. Jim Cramer's tweeting that we shouldn't be using these Chinese models because national security risk.

102
00:37:21.875 --> 00:37:41.568
But there's nuance here, right? There's a ton of nuance here. It's not just Chinese model bad, right? It's, yes, if it's hosted on servers that the Chinese government has, like, legal authority to collect information over, then, yeah, like, you shouldn't be sending things that you care about.

103
00:37:41.568 --> 00:38:01.683
about to that those servers the same is true inversely right especially if you're outside the u.s sending stuff to u.s yes staff the u.s can pull the same like yeah it's very it's different china can just like literally do whatever they want with their companies that they're running there we have to like kind of fake it through the court sometimes unless

104
00:38:01.970 --> 00:38:30.944
You can pull the national security card, right? And the U.S. can be like, hey, it's a matter of national security, Microsoft. You got to give me all this information about something, anything, right? Microsoft has to comply. And so, I mean, we just saw this with the scattered spider court stuff that came out. The GDID conversation. Yep. So if your threat model is this data is my data and no one else can see it, then it doesn't matter, Chinese model or American model. You shouldn't be sending this crap to cloud-hosted models. But open-weight models...

105
00:38:30.944 --> 00:38:46.486
hosted on your hardware or otherwise, you know, local that you trust hardware, some degree of local, right? You know, maybe a trusted data center that you have some sort of different contract relationship with.

106
00:38:46.908 --> 00:39:04.053
The open routers, the world totally can't Kimmy K three right now. You're, you're going to Kimmy, right? Like to, to, to work on it, but that's not going to be true forever. It is an open weight model or it's going to be an open weight model. And so it's going to wind up on open router or something like this at that point.

107
00:39:04.593 --> 00:39:20.303
I would need to see strong evidence that its output is actually backdoored. It's probably biased, right? You can't ask it about like Tiananmen Square or something. But like I would need to see very strong evidence that it's going to like purposely write code backdoors as part of its weights.

108
00:39:20.303 --> 00:39:35.322
Yeah, this is where confidential compute and compute attestation becomes really interesting because there's a whole world of like, if you could get a quote, this is like a conversation about confidential compute architecture, but if you can get a quote from Kimmy that like,

109
00:39:35.322 --> 00:40:03.841
Their servers are running this piece of software. And I don't know if like model attestation is even a thing, but like also the model you're running is the one that you say that you're running. It's like the open source one that I see here is the same one running on the GPUs. That's where the technology is really interesting because then it's like you don't, like that's what confidential compute is for, right? It's literally, we don't trust the data center. We don't trust the hypervisor. I don't trust the other side. I need to cryptographically attest that the whole stack from boot to top is running the code that I trust with the model that I trust, right? Yeah.

110
00:40:03.841 --> 00:40:09.494
The world is not there yet. Confidence to compete is very difficult to do correctly, but maybe we do at some point.

111
00:40:09.882 --> 00:40:39.717
Yeah, it's actually, hey, homework for all you listeners. One of like the most impactful blog posts over the last few years was Apple's talking about their private cloud compute stuff that they put out. Absolute pinnacle of exactly what we're talking about. Really, really cutting edge stuff going on to do all of the things that we're talking about in like a trusted environment. Because Apple's been wrestling with this, right? Siri kind of sucks. They're losing the AI battle. But their problem is you can't do any of this AI stuff locally on an iPhone, just not enough compute.

112
00:40:39.717 --> 00:41:08.303
But they're the private phone, right? They don't want to, like, send a bunch of stuff back to Apple. So, like, how do you, like, keep pace with this? Well, their answer to this was this private cloud compute thing that gives a lot of the rules that you're talking about to actually be able to verify what you're running, what you're running on, that it's yours, that no one at Apple can read it, all this kind of stuff. Moxie Marlinspike, creator of Signal, actually made a...

113
00:41:08.303 --> 00:41:36.164
a version of an AI chat bot that follows these rules called confer. I think meta actually bought it and is baking it into WhatsApp and all this kind of stuff. Right. Super interesting. But which I mean, taints, taints it to a degree, but like the technology, like go read confers blogs by Moxie when he launched it. And he talks a lot about exactly that. Like he, he talks about how the interface of an app that you're using is,

114
00:41:36.164 --> 00:42:05.847
is going to affect the behavior of the user. And a chat app is showing a user a private chat, like Signal or whatever. So his whole thing about like Facebook Messenger or any of these other messaging apps was it was lying to the users. It was showing a message between two users, but anyone at the company could read those messages. So it's not actually private, even though it looks like you're just talking to each other, right? So that was his whole thing with Signal is like,

115
00:42:05.847 --> 00:42:19.381
The illustration of the app, the experience of the app should actually be truthful and whatever. And so he's like, AI chat bot, same thing. ChatGPT.com. You feel like you're just talking to ChatGPT and it's talking to you.

116
00:42:19.820 --> 00:42:38.939
like it's a private conversation, very different than google.com. You know that you're like searching to Google and that Google's then giving you something. So like, you know that like you're talking to servers and like whatever, right? It's pretty well understood versus a conversation with an AI bot that like does something evolutionarily in our brains to be like,

117
00:42:38.939 --> 00:43:06.395
I'm having a private conversation with my homeboy. Chat should be T40, right? And like the AI psychosis that came with that model was crazy. So Confer came out and they were like, well, that should be, again, this should be true. It should be an end-to-end encrypted conversation. That's not a conversation between you, this model, and then also anyone who works at OpenAI and their future advertising customers for sure that are definitely coming, right? That can then read all your data.

118
00:43:06.530 --> 00:43:35.453
Yes, if you actually Google Confer or Chatbot, kind of ironically the Gemini summary you get, is how Confer works, Confer, end-to-end encryption, prompts are encrypted on your device and are only decrypted with a secure private key, right? The problem with this inherently and architecturally is that like, well, yeah, but if that's on like a server, if the server, the hypervisor, whoever, can access that private key, then it's the same as not being encrypted, right? At the end of the day, like a symmetric key in a two-way conversation is resident somewhere, right?

119
00:43:35.453 --> 00:44:00.935
But if you keep reading, that key is isolated in a trusted execution environment, a T, on the server to process responses. It is using the ARM hardware features. It is a hardware isolation where even the server cannot read that code, right? Now, there's a conversation about, like, the secure world T versus actual confidential compute. There's papers on this. Go read them. But it is seeing, like, the trend where...

120
00:44:01.525 --> 00:44:22.282
you know, cloud architecture is drifting more and more to the threat model. We're like, oh, also the cloud is hostile. We are hostile. Here is the architecture that allows you to defend against us, which is kind of neat. Yeah, go check it out. Confer.to slash blog. He's only got like six blogs in there, Moxie. And the early ones really kind of talk about

121
00:44:22.568 --> 00:44:48.725
his thought process on what he was building here, confessions to a data lake, and then even like private inference. It talks a lot about the technological underpinnings of, of this super interesting, super interesting. And it pulls on a lot of those concepts of the Apple private compute. And a lot of it is pinned to keys and all this kind of stuff. Like you said, really, really important concepts to understand as we move forward, because the other models are just not,

122
00:44:48.995 --> 00:45:10.426
possibly even tuned in this direction, right? Sam has even announced that the advertisers are coming to open AI. So like that data is going to be used to advertise to you. And I know a lot of people treat their chat, their AI chats like a therapist at this point. And it's, you know, that's kind of concerning to me.

123
00:45:10.426 --> 00:45:36.380
So I think we beat to death the AI escaped the lab in Chinese models. I'm sure we're going to find out more. I want to know more about the draw the rest of the owl bit of this security incident, about the vulns, about the lateral movement. There's a lot of details in there that are going to tell us a lot about this and how to protect against it ourselves and build a true sandbox ourselves as we go from this. I think the key takeaway, and then we can move on, is...

124
00:45:36.380 --> 00:45:51.736
Like if you're a defender listening to this, you need to be tuning your threat model to like nation state level threats and attacks and zero days are the cost is going to zero and it's not going to just be nation states.

125
00:45:51.736 --> 00:46:09.455
These capabilities are bubbling at the surface and low skilled, low resourced attackers are going to have the capabilities of zero days that was previously nation state only. So that's that's going to be a mental shift that we're all going to have to go go through for the next couple of months to years.

126
00:46:09.455 --> 00:46:28.540
So in the Lord's year, 2026, we're talking about WordPress, dude. What's going on with WordPress? I heard there's a couple issues with WordPress. You had the tweet about this. Okay. Just like pray for all praise, low level. Oh yeah. What was that? Because you, you basically said in before anyone, everyone says people still use WordPress.

127
00:46:28.540 --> 00:46:46.192
And it's just like that. That was I made I made some content about this. And that was the overall reaction was like, if you use WordPress, you deserve this. WordPress is by far the most popular platform for this kind of web app ever, ever. It's one of the most successful projects ever.

128
00:46:46.192 --> 00:47:06.222
I was doing some research for a video on this, and I think I read somewhere. Again, it's the internet. I have no idea if it's real. But, like, someone said that 43% of websites are backed in some capacity by WordPress, which is so unbelievable. But also, like, the Thai restaurant near my house, whenever I order from them, it's WordPress. And I don't know how long they've been there, how long it's been updated. But, like, it's real.

129
00:47:06.897 --> 00:47:36.125
Everything. I think I saw a count of about 500 million internet exposed WordPress installs on census's blog. So I mean, okay, the reason that this bug is spicy, first of all, it got a name. We got to talk about all phones that get a name, of course. So WP2 shell. And the interesting part about this is not WordPress vulnerability, because those happen, right? It's that it's in default install WordPress. This is much more rare these days. Most WordPress issues that we're running into

130
00:47:36.125 --> 00:47:51.127
in the year of the Odyssey movie is the plugins. Plugins are like the thing that gets you in trouble or just otherwise misconfigured, like non auto updating. Most WordPress is auto updating these days.

131
00:47:51.127 --> 00:48:17.485
Like a lot of the like security Swiss cheese of WordPress back in the day has like worked its way out of the project and the ecosystem for a while, except for just mismaintained plugins and stuff like this. But this one was particularly spicy. And I heard a ton of people that said that their auto update did not catch this patch and they needed to go and actually push manually on this one. What's the bug, though? I know you dug deeper into the bug.

132
00:48:17.485 --> 00:48:41.043
Yeah, so what's interesting here, this actually takes advantage of two separate CVEs in WordPress, right? So in October of 2020, the maintainers of WordPress added this batch command, right? This batch endpoint that allows a user to submit up to 25 post requests to a single endpoint, and it would process all of them.

133
00:48:41.043 --> 00:49:03.014
The reason for this is WordPress is a blog site, right? And so a lot of the code that you're doing is going to be like updating a page. And they want those updates to happen as soon as possible. But if I'm like hammering out updates, you don't want to also hammer the site. And so to reduce kind of the throughput of traffic required, instead of doing 25 separate requests, it would batch all the requests to do edits to the slash batch endpoint.

134
00:49:03.014 --> 00:49:25.778
Now, when it's going through and processing those requests, there's some amount of validation that occurs to make sure that you're allowed to do the requests. You're not allowed, for example, to do get requests. And so there was a mismatch of these two arrays where you have the matches and the validations. And as you're going through, it assigns a handler to run that request as it's validating them.

135
00:49:25.778 --> 00:49:51.378
Now, if one of the requests fails to get validated, the two separate arrays fall out of sync, and it assigns the handler for one request to the wrong request, allowing you to actually do get requests on the batch handler. Now, that in and of itself actually isn't a big deal. Okay, you can do a get request internal to WordPress. Who cares? You're actually still gated by all the authentication gates that happen in WordPress, so it's not that big of a deal. Ah.

136
00:49:51.378 --> 00:50:21.365
A separate CVE, that was the first one, was an SQL injection in 2026 that was an SQL injection in the field, what is it, author not in. So when you're doing a post query, right, you have the posts in WordPress. If you want to query and get all the posts where the author of that post is not in these other posts, you can specify those fields and get those posts as a return.

137
00:50:21.365 --> 00:50:40.501
through the request that you batch and then use that SQLI to do a bunch of other nefarious stuff. Now, a lot of people, because this SQL injection is blind, we're doing the traditional blind SQLI thing, right? Select all from blank where admin password is like A or sleep 10, right? And you use that timing side channel to figure out what the password is.

138
00:50:40.687 --> 00:51:08.530
The POC that is public is actual, it's chef's kiss, it's glorious. They use a select statement, which is by design and not allowed to do database insertions, to create a temporary cache post that doesn't actually exist. And inside that cache post, when WordPress goes to hydrate it, that post running as admin submits a request to the URL to make an admin account

139
00:51:08.530 --> 00:51:37.842
And then you can use that admin account to get in and upload the web shell. So you chain two bugs together, do a cache hydration attack, create a fake admin, upload a web shell. And it all happens in like under 500 milliseconds. Glorious. It is so beautiful. Obviously, you know, this podcast leans a little. We talk about AI. It was AI assisted. The SQL injection was found by human beings. I think the other bug was also found by human beings. But the thing that Tenable said, it is not possible to...

140
00:51:37.842 --> 00:51:53.384
for a human to come up with and exploit the cache object hydration in 10 hours. So from the time the bugs were disclosed, from the time or to the time that pox got dropped was 10 hours, no human being is going to do that. It's going to be AI-assisted for sure.

141
00:51:53.384 --> 00:52:09.230
One of the more beautiful web attacks we've seen in a very long time. You know what I mean? In the world of, in the year 2026, still seeing SQLI is very interesting, especially in SQLI that is a blind select being used to create an arbitrary admin. It's just like, who could have thunk it?

142
00:52:10.428 --> 00:52:28.484
I, hacking WordPress used to be a lot easier than that. Yes. That's a really cool bug. It deserves its name. Okay. The, the chaining, the elegant, uh, nature of it, the speed, the actual simplicity of the actual exploit, even though the chain is complicated, the, the exploit being so simple,

143
00:52:29.007 --> 00:52:57.678
You earned your name and your branding WP2 shell. And yes, I think a lot of people got auto updated through this one, but please, please, please verify, because I am seeing reports of mass internet scanning already on this. So just kind of assume compromise at this point, if you're on one of the affected versions, which I think was anything that was updated post December 2025 was impacted until the most recent patches in this...

144
00:52:57.678 --> 00:53:13.591
6.9 and the 7.0 dot something range. Yeah, I'm not sure on the exact timeline, but yeah, it's your vulnerable if you're within the 6.9.0 to 7.0.1 window. Again, a really interesting case study of like,

145
00:53:13.591 --> 00:53:34.094
Sometimes updating makes you more vulnerable, right? Obviously update now, get through the bug if you're in that window. But like the Thai restaurant down the street, maybe they're on WordPress 4. You know what I mean? And they probably have other CVEs, obviously. But like this one, they didn't get this one. That's kind of interesting, right? The nature of software is that when you add new features, you add new bugs. And this is just one of those cases, unfortunately.

146
00:53:34.448 --> 00:53:46.683
Yeah, it reminds me of the supply chain stuff that we're talking about, about NPM, like fine-tuning how fast you grab the update, which might contain malware at this point because that's happening, versus actually patching CVEs.

147
00:53:47.155 --> 00:54:15.860
All right, this next one's kind of nuts. So LG, we all know LG. We probably, I'm currently not on LG monitors, but I've had LG monitors in my life. I definitely have some LG TVs. I wish we could go back to dumb TV land. I wish I can get like a top tier spec TV with no smart features. Cause they're all atrocious. Apple TVs are worth every penny, right? Like the remote, the interface doesn't lag, all this kind of stuff. I hate smart TV features.

148
00:54:15.860 --> 00:54:36.717
There's another reason to hate all these features that we're talking about, but two different news stories kind of reared their head in the same few days about this, about LG. So apparently, number one, Krebs on security, talking about how their smart TV app ecosystems, you download Netflix or whatever straight onto your TV.

149
00:54:36.717 --> 00:55:02.519
There was some research that came out that said something like 43% of all the apps on that actual official app store that you can download apps on your TV come with a little backdoor, basically, to turn your TV into a residential proxy for other services to go sell. So if you guys don't know, real quick, on residential proxies, the law enforcement agencies are going hot on this right now, is...

150
00:55:02.519 --> 00:55:19.900
Threat actors, or maybe not even threat actors, even like ad fraud and like other stuff, not even traditional hacking, they can't make all of their traffic look like it comes from data centers because data centers use known IP ranges. So if you're running whatever it is that you're running, you can just block.

151
00:55:19.900 --> 00:55:46.006
data center IPs if you don't expect traffic from data centers. So they need for a very, that's one reason. There's a various reasons that attackers or otherwise fraudsters might need a residential IP address. Well, these are the things that they do to get residential IP addresses. They use your IP address either through a vulnerability in your router or something like that. If it's on the internet, it's super popular to do this and build botnets.

152
00:55:46.006 --> 00:56:04.872
Krebs has been hot on this. If you want to go talk about, read about some of the botnet takedowns that were just basically residential proxy nodes. Yeah, I think in that context, he calls them operational relay networks. It's like a network of pwned devices that actors are routing their traffic through to look like other actors or look like other IPs. Yeah.

153
00:56:04.872 --> 00:56:28.143
Yep. But more and more, we're seeing actual consumer electronics hitting the market that facilitate this whole ecosystem and economy of residential IP stuff. Usually it's like shady Chinese made electronics off of, you know, even Amazon. Right. But just like no name electronics are coming with a lot of this, like these the really, really cheap Android TVs.

154
00:56:28.143 --> 00:56:45.035
A ton of them are just adding you to a botnet basically is why they're so cheap and all this kind of stuff. So LG is basically coming out finally and saying that they're going through an effort to purge their app ecosystem of those residential proxy functionalities.

155
00:56:45.035 --> 00:57:10.634
But at the same time, we saw a YouTube video go viral this week that is talking about how their monitors, LG monitors, are also coming with adware. And installing, it feels like the 90s on Windows XP. They're pushing a paid version of McAfee antivirus. Like, what year is it meme Jumanji, right? Like, what's going on? That something that I install my thing. So, I don't know. I think...

156
00:57:10.634 --> 00:57:39.507
You know, there's probably pressure to diversify revenue streams going on at LG besides just like selling electronics. And they're like, look, we can package our monitors with software and blah, blah, blah. But the consumers are now sick of it at this point and are like revolting. So a lot of these monitors are getting review bombed. The TVs are getting review bombed and honestly deserved. This is really borderline shady behavior from a major electronics consumer provider.

157
00:57:39.507 --> 00:58:00.095
So I'm not super well read on the story. Can you just enlighten me in the audience? So what I'm understanding from you, I think, and what I'm looking at here, you buy an LG UltraGear monitor, you plug in the DisplayPort or HDMI cable, and then suddenly you are getting McAfee installed on your computer? Or like you're being prompted to? Like what is occurring from plug-in time to I look at the screen?

158
00:58:00.533 --> 00:58:23.551
Yeah, I'm not super like break down the attack or whatever, but it seems like you plug in the monitor and it comes with a bit of a, you know, these like enhancer monitor software. It comes with some software to tune your monitor, and that is pushing a premium subscription for McAfee in it. It's basically adware. Yeah, because it's your $1,200 monitor.

159
00:58:23.551 --> 00:58:52.795
Right. In the article I'm reading, it says, upon first connection to a Windows 11 device, the OS, I'm assuming they mean the monitor OS, can check the associated... Oh, no, I'm sorry, the OS being Windows. The OS can check the associated device metadata and automatically install the manufacturer's UWP device app, Ultra... I'm not sure what that is. So for that to happen, Microsoft says the user must have opted in to a recommended settings, which I'm sure a lot of people have, during Windows setup and be signed into Microsoft Store and be online. So, yeah, it seems like...

160
00:58:53.183 --> 00:59:12.033
There's like probably a recommended software per manufacturer ID of a monitor. And so you plug in the HDMI cable. Windows is like, oh, look, he has an UltraGear monitor. We probably should install some stuff for him. And then with that stuff comes not only LG software, but then also whatever LG is getting paid to package, which is like, you know, like you're saying, the Mac if you stuff.

161
00:59:12.033 --> 00:59:40.703
I think I actually had this happen with my, um, my Asus motherboard. I think I installed like the, the A-rock crate or whatever that you're able to use to like to tune the RGB lights on like the, my studio monitor, my studio computer. And then with that came like, oh, are you interested in McAfee by the way? I'm like, dude, no, I did not ask for this. What are you doing? Oh, by the way, please pay us $34.99 a month to run McAfee. Like, no, I'm good, dude. Thank you. That's fine. I think the reaction here is like, you're, you're paying basically luxury electronic prices.

162
00:59:40.703 --> 01:00:00.599
Like, and then you're getting like cheap Android bloatware experience, right? Which is just like that. Those two things should not happen. If you're paying $1,200 for a top LG monitor, they're kind of top of the monitor pile up there, right? It should not be trying to do this like one-two punch stuff of like Timu Electronics. Yeah, insane.

163
01:00:00.599 --> 01:00:21.305
All right, man, I think that's it for this week. I've got some other stuff we could talk about, but listen, we're doing this every week. We got to save some stories for next week. We got some North Korean interviews to talk about next week. I still have that interview with Dan Guido in the pipe. We're scheduling that. If you are going to Blackout or DEFCON, like we said, maybe we'll bring some Commander decks if you're listening. That's like a cool way to be like...

164
01:00:21.305 --> 01:00:51.292
Hey, by the way, I'm a listener, but we're going to do a live recording somewhere. Details, TBD, follow us on Twitter and socials and stuff, and we'll get the details to that live recording out, probably at DEF CON, probably later in the week if you're going to be at DEF CON. We're going to do some live stuff. Yeah, so guys, if you enjoy the podcast, best way to help us out is do two things. One, subscribe on Substack, get updates for when new episodes go live. And two, go interact with our sponsor guys. We love Maze. They do a really good job of contextualizing code vulnerabilities.

165
01:00:51.292 --> 01:00:57.367
Mays, thanks for following the podcast. And Matt, let's take it home. We'll see you next week, y'all. Later. Peace.
