
LG Caught Spying in Your Living Room, Miami Crypto King Gets Life, and the AI Apocalypse Debate
Welcome to The Low Down, the best show on the internet for hackers The Low Down is presented by Maze. LinkedIn: https://www.linkedin.com/company/mazehq/ X: https://twitter.com/Maze_Security Follow Us! https://www.instagram.com/lowdown.pod This week we're diving into the surveillance nightmare coming from your living room, catastrophic phishing campaigns targeting crypto users, and Microsoft's record breaking patch cycle that defenders need to know about. Today we're talking about: LG's Privacy Nightmare: Your TV is Spying on Everything Gamers Nexus drops a two hour expose revealing LG TVs are actively recording and transcribing all room audio even when listening mode is disabled and the device is powered off. Breaking down how they got root shell access and found plain text transcriptions of private conversations being cached on the device with four gigs of memory ready to phone home. Why the microphone continues recording even when unplugged from the network and what ACR automatic content recognition really means for your privacy. The Economics of Smart TV Surveillance LG executives caught on stage at advertising conferences bragging about owning the glass and extending the advertising experience across all devices on your home network. How they're doing network scans to enumerate every Windows PC, phone, and IoT device in your household and correlating that with what you're watching. Why the profit margins on TV advertising are in the 60s with SaaS level multiples while TV hardware prices have bottomed out over the last 20 years. The Remote Code Execution Problem Nobody's Talking About Beyond the privacy concerns, LG TVs have multiple unpatched remote code execution vulnerabilities that turn your living room microphone into a potential threat actor playground. Why teachers are panicking about 85 of these devices deployed in classrooms and the student privacy implications. How Chinese threat actors have proven they'll exploit residential devices for proxy networks and credential theft. Trezor's Catastrophic Phishing Campaign Trezor customers hit with one of the nastiest phishing campaigns of the year where the call was literally coming from inside the house. Breaking down how their official email provider was breached with valid TLS certificates and domain signing making the phishing email appear completely legitimate. Why this was perfectly timed after the cold card STM 32 entropy vulnerability had everyone primed to believe their hardware wallets were compromised.
- Transcript










