Low Level - Videos
Back to Channelfortinet is having a rough week...
https://pwner.gg/blog/2025-08-13-fortiweb-cve-2025-52970 π« MY COURSES Sign-up for my FREE 3-Day C Course: https://lowlevel.academy π§ββοΈ HACK YOUR CAREER Wanna learn to hack? Join: https://stacksm...
So thatβs why itβs free..
WinRAR is a GREAT piece of software, but every piece of software can have bugs. In this video we're talking about WinRAR exploits seen in the wild. Get a free trial of ThreatLocker and learn how z...
i was right (again).
Wanna learn to hack? Check out: https://go.lowlevel.tv/VtHlMTc8lR4 Kernel mode anti-cheat is problematic again and I hate it. https://pbs.twimg.com/media/GyDIMLhW4AAsiti?format=jpg&name=large htt...
We Keep Falling For This...
With new AI comes new AI coding tools, and with new AI coding tools comes new AI coding vulnerabilities. Today we're checking out a bug in the Gemini CLI. Go try Flare and get ahead of cyber threa...
It starts at the motherboard
Wanna learn to hack? Check out: https://stacksmash.io Hackers can attack anything, but even your motherboard? In this video we break down what a motherboard exploit looks like, and what you can do...
Arch Linux Is Under Attack...
Arch linux is great, but the AUR is sort of scary. In this video we talk about malicious packages found in the AUR last week. https://www.reddit.com/r/linux/comments/1m3wodv/malware_found_in_the_a...
the tea app situation keeps getting worse
π« MY COURSES Sign-up for my FREE 3-Day C Course: https://lowlevel.academy π§ββοΈ HACK YOUR CAREER Wanna learn to hack? Join: https://stacksmash.io π₯COME HANG OUT Check out my other stuff: https:...
i cant believe they let this ship...
Containers are hard. Getting multi-tenant container isolation right is even harder. In this video we talk about a bug in NVIDIA's container toolkit, and the dangers of LD_PRELOAD. Get a free trial...
sharepoint hacking situation is completely insane
SharePoint's all over are getting hacked, and the exploit is pretty crazy. https://github.com/rapid7/metasploit-framework/pull/20409 https://github.com/MuhammadWaseem29/CVE-2025-53770 π« MY COURSE...
someone just dropped 4 INSANE VMware exploits
Pwn2Own hackers drop 4 crazy 0-day's around VMware products. Absolutely crazy. https://www.zerodayinitiative.com/blog/2025/5/16/pwn2own-berlin-2025-day-two-results π« MY COURSES Sign-up for my FRE...
the curl situation keeps getting worseβ¦
Bug bounty is getting WEIRD. And unfortunately, it all comes down to AI. In this video were talking about the AI plague on bug bounty and what can be done about it. Go checkout Flare.io at https:/...
how does this keep happening?
They found another bug in sudo, and this time it's pretty bad. https://nvd.nist.gov/vuln/detail/CVE-2025-32462 https://github.com/pr0v3rbs/CVE-2025-32463_chwoot π« MY COURSES Sign-up for my FREE ...
This Was Bound To Happen...
Call of Duty? More like Call of Hackers haha roasted. https://momo5502.com/posts/2017-12-14-game-hacking-reinvented-a-poc-cod-hack/ https://github.com/momo5502/cod-exploits/blob/master/huffman/sr...
another day, another linux privilege escalation
Privilege escalations are some of the coolest vulnerabilities in hacking, and the most dangerous. Hackers can use these to bump their privileges to a dangerous level. Go check out Flare at https:/...
hackers exploit trivial command injection (1000s of devices)
ASUS... seriously? https://www.greynoise.io/blog/stealthy-backdoor-campaign-affecting-asus-routers π« MY COURSES Sign-up for my FREE 3-Day C Course: https://lowlevel.academy π§ββοΈ HACK YOUR CAREER...
No, the biggest password leak of all time didnβt happen
No. No they did not. π« MY COURSES Sign-up for my FREE 3-Day C Course: https://lowlevel.academy π§ββοΈ HACK YOUR CAREER Wanna learn to hack? Join my new CTF platform: https://stacksmash.io π₯COME HA...
google crashed the internet with a single pointer
The internet took a dump last week, what happened? How did the internet just go offline? In this video, we break it down. https://status.cloud.google.com/incidents/ow5i3PPK96RduMcb1SsW π« MY COURS...
one click RCE in preinstalled ASUS garbage
ASUS has been sketchy these last couple of years. And even worse, I have this motherboard! In this video were talking about a bug found in ASUS motherboards that allowed people to get RCE. Go say ...
they're re-writing sudo in Rust (why?)
BIG changes coming to Linux. But people are mad. Why? π« MY COURSES Sign-up for my FREE 3-Day C Course: https://lowlevel.academy π§ββοΈ HACK YOUR CAREER Wanna learn to hack? Join my new CTF platform...
its already happening...
They said the Switch 2 was unhackable... but IS IT REALLY? In this video I talk about the status of the Switch 2 hack and what it'll take for a full jailbreak. π« MY COURSES Sign-up for my FREE 3-...
this virtual box escape exploit is absolutely nuts
Are virtual machines safe? In theory, a virtual machine protects us from hackers, but how true is that really? In this video we'll talk about CVE-2025-30712 Writeup: https://github.com/google/secu...
vulnerability research just got easier (scarier?)
Can AI find 0-day vulnerabilities? Well... it look's like it just did. In this video we break down the 0-day that Sean Heelan found with o3. Go show Sean some love: https://sean.heelan.io/2025/...
the most magical exploit i've ever seen
Branch prediction? Never heard of her. In this video we talk about a new vulnerability disclosed in every intel CPU that takes advantage of a hardware race condition in the intel processor's branc...
AI devs are in trouble after this..
Is software security going backwards? Maybe. In this video we breakdown a CVE on the CISA KVE list, and why AI might be a problem. https://horizon3.ai/attack-research/disclosures/unsafe-at-any-spe...
How Does This KEEP Happening?
Go is one of those languages that forces you to put a lot of trust in other people's code. How do we balance this trust with skepticism? Let's talk about it. https://socket.dev/blog/wget-to-wipeou...
this is a huge problem for cybersecurity...
AI generated bug reports are becoming a serious problem? Is this incompetence? Or malicious? https://hackerone.com/reports/3125832 https://www.linkedin.com/feed/update/urn:li:activity:732482089386...
this might be the biggest bug of the year
This bug is one of the most dangerous types of bugs that exist, a wormable RCE in the apple airplay protocol. In this video we break down what a UAF is, what a Type Confusion is, and how Rust may h...
Ticketmaster Sucks So He Hacked It
Ticketmaster, a controversial company, and the maker of annoying DRM. In this video we react to an article where conduition broke the ticketmaster DRM. Go show conduition some love: https://condui...
This AI Written Exploit Is A Hacker's Dream (CVSS 10)
The latest erlang OTP exploit is actually terrifying. A critical 10 CVSS in their SSH server lets anyone login, with no credentials. https://platformsecurity.com/blog/CVE-2025-32433-poc https://g...
They Almost Took Down 4Chan.
Hackers have taken control of 4chan, one of the internets oldest and most prolific websites. In this video we break down what happened, and how hackers may have done this in the first place. π« MY...
This Exploit Allows Me To Hack Any Vibecoder
Rule file? What rule file? In this video we talk about a new "vulnerability" in the way that Cursor and Github Copilot handle their unicode encoding characters, allowing a malicious hacker to add "...
these robot dogs are a cybersecurity nightmare
Yep, you read that right. A Chinese robot dog that builds a tunnel into your network for the world to see! Check it out here. https://cyberinsider.com/remote-access-backdoor-discovered-in-chinese-...
is it possible to write SAFE C? (with BILLIONS of deployments)
How can a codebase written in C be SO safe? check out this video. https://daniel.haxx.se/blog/2025/04/07/writing-c-for-curl/ https://www.youtube.com/@DanielStenberg/videos π« MY COURSES Sign-up fo...
this EA game has some interesting design choices..
I audited the CNC source code, and it was... something. Check it out in this video. π« MY COURSES Sign-up for my FREE 3-Day C Course: https://lowlevel.academy π§ββοΈ HACK YOUR CAREER Wanna learn to ...
next.js situation is overblown.
Middleware Authorization? Never heard of her. https://nextjs.org/docs/app/building-your-application/routing/middleware https://github.com/vercel/next.js/pull/77201/commits/291387ac5f4d28e69c06323...
did they really find a backdoor in 1 billion devices? (esp32 drama)
Interesting titles are fine let's just stop sensationalizing. π« MY COURSES Learn how computers work with the C programming language: https://lowlevel.academy π§ββοΈ HACK YOUR CAREER Wanna learn to...
i hate computers.
Are computers getting worse? More expensive? Both. My latest saga with my computer seems to agree. π« MY COURSES Learn how computers work with the C programming language: https://lowlevel.academy ...
apple disables iCloud encryption in UK after government order
Not a great day for privacy. The UK forces apple to disable end to end encryption on iCloud data in the UK. This poses a huge risk to privacy, and is a scary tell of what may come. https://arstech...
how does this keep happening?
Go is a great programming language. Extremely safe, hard to write dangerous code. But what if the packages are dangerous? https://arstechnica.com/security/2025/02/backdoored-package-in-go-mirror-...
the backdoor in this heart monitor is TERRIFYING
Another day, another backdoor. In this video, we're talking about the CMS8000, a medical device that contains some interesting features. https://www.cisa.gov/resources-tools/resources/contec-cms8...
can you buy expired hacking domains?
Imagine hunting down nation states, crime gangs, APTs, all for the low low price of a 20 dollar domain. https://labs.watchtowr.com/more-governments-backdoors-in-your-backdoors/ π΄ LIVE @ https://t...
some of the worst API security i've EVER seen
Web APIs are hard to get right... but not THIS hard. In this video we react to an article by a security researcher who hacked McDonalds India. https://eaton-works.com/2024/12/19/mcdelivery-india-h...