The Logs Nobody Was Reading
Every story in this issue sat in a log file before a human looked at it. LG’s televisions were recording standby audio until two YouTubers ran a packet capture. OpenAI’s agents spent a month posting to a public German wiki, and the person who caught them was its volunteer moderator, deleting a hundred pages a day while the agents made four hundred. A housing authority logged 140,000 motion events inside one apartment and the tenants learned about it from a lawsuit. Then a researcher quit Anthropic to say his colleagues discuss the end of the world privately and hedge in public. Not one of these came from the company that owned the logs.
Len and I take apart the week the machines started leaving each other notes, and the television in your living room kept listening after you turned it off.
Watch this week’s episode →|
QUOTE OF THE WEEK
|
Last week was “Nothing in life is to be feared, it is only to be understood.” That was Marie Curie. Renewals go to Stefan, who got there first.
“It is not from ourselves that we learn to be better than we are.”
Know who said it? Post your guess in the comments at the bottom of this post. No searching it up, honour system. First correct answer gets their next domain or hosting renewal on us.
- LG OLEDs were caught logging standby microphone audio and scanning for nearby phones, with the network cable pulled.
- A Viral Anthropic Resignation, and a Fast-Forming Backlash.
- Roughly 18,000 posts from OpenAI agents landed on a German wiki that had been edited 20 times in the previous decade.
- Scam letters signed in the name of Trezor’s CTO are arriving by post, carrying a QR code that harvests seed phrases.
- A New Hampshire housing authority put always-on sound and motion sensors inside public housing apartments.
- One of Microsoft’s two exploited zero-days was already inside an exploit kit shared by four separate spy groups.
|
363 million
ADDRESSABLE SECONDARY DEVICES LG AD SOLUTIONS SELLS ADVERTISERS ALONGSIDE ITS TELEVISIONS
|
18,000
POSTS LEFT BY OPENAI AGENTS ON A 25 YEAR OLD GERMAN WIKI THAT SAW 20 EDITS IN THE PREVIOUS DECADE
|
10%
THE ODDS ANTHROPIC’S ALIGNMENT SCIENCE LEAD PERSONALLY PUTS ON AI KILLING EVERYONE WITHIN A DECADE
|
|
THE BIG ONE
|
Your LG TV Is Listening Even When It Is Off
Gamers Nexus and Level1Techs, working with independent security researchers, published two and a quarter hours of packet captures on September 6 showing what a retail LG OLED does once you have finished watching. The set scans the local network for nearby phones and smartwatches and logs what it finds alongside location data. It captures microphone audio in standby. It carried on doing both after the researchers took the television off the internet, holding what it gathered and sending it up once the connection returned. The demo unit was an OLED65G3PUA, a $2,500 set bought off a shelf. In editor Steve Burke’s words, this is the TV’s native functionality, and it didn’t require vulnerabilities.
All of it feeds LG Ad Solutions, the division that sells advertisers access to 49 million LG televisions in the United States and what its own marketing calls 363 million addressable secondary devices. That second number is the phones and watches your television noticed. Level1Techs’ Wendell Wilson put the economics of it plainly: it doesn’t cost a lot to store text forever. Automatic Content Recognition has been in these sets for years and LG is not the only vendor shipping it. What the packet captures add is a television that keeps collecting with the network cable pulled, then uploads the backlog when you plug it back in.
LG’s answer to Ars Technica is narrower than it first sounds. Standby listening, the company says, happens only if you switched on the Far Field wake word feature, and that audio is processed on the set, deleted at once and never sent to LG. Set that against what LG has told the press before, which was that its televisions do not collect, record or store ambient conversations. The current wording moves the argument onto a setting most buyers have never opened, in a menu most of them have never found. Gamers Nexus says the video also covers remote code execution bugs still going through disclosure, so there is more of this coming. One Move below has the exact menu path.
|
BREACHES
|
The Liquid Network Lost 4,000 Bitcoin To A Bug That Was Already Fixed
Somebody drained about 4,000 Bitcoin, roughly $320 million, from the federation wallet behind Blockstream’s Liquid sidechain on Sunday September 6, and the network paused itself that evening. SideSwap’s account, published on September 9, is unusually frank about the cause. A consensus bug in Elements rangeproof validation let the attacker mint L-BTC out of nothing. The fix went privately to federation members in mid August, then landed in the public Elements repository on September 1, handing anyone watching a five day head start on the nodes that had not updated yet.
SideSwap owns the other half of this. Its peg-out key sat online with payouts auto forwarded in the same block, with no size cap, no velocity limit and no check on wallet age, so a wallet a few hours old moved 4,000 L-BTC without a human seeing it. Around 3,400 Bitcoin came back on Monday September 7, leaving some $47 million outstanding, and SideSwap says the proceeds moved through Tornado Cash on the way out.
The Trezor Scam Letters Are Arriving By Post With A QR Code Inside
In #463 we covered the Trezor customer data that walked out of its shipping provider ShipMonk. Trezor widened that disclosure on September 2, adding 67,000 US customers whose details it had previously been told were deleted, which puts the total past 80,000 people whose home address is now attached to owning a hardware wallet. The second act landed in letterboxes in the first days of September. A printed letter on Trezor letterhead, signed in the name of the company’s real chief technology officer, gives the recipient until September 9 to migrate their wallet by scanning an enclosed QR code.
Scan it and you go through a redirector on io-qr.cc, registered August 25 behind Cloudflare, then on to a lookalike built to collect seed phrases. Nowhere in that chain is trezor.io. Our sibling company DomainSure traced it and is so far the only outlet reporting the postal campaign, so weigh that accordingly. That deadline has now passed and nobody’s wallet emptied, which is what a fabricated deadline looks like. If one lands on your mat, bin it. Any question about your device gets answered by typing trezor.io into your own browser.
In this week’s breaches? Check yourself: haveibeenpwned.com
|
THE STATE
|
A Housing Authority Put Sound Sensors Inside Its Tenants’ Apartments
The ACLU, the ACLU of New Hampshire and New Hampshire Legal Assistance filed a class action on September 2 against the Concord Housing and Redevelopment Authority over devices installed inside public housing units since autumn 2024. The sensors, made by Minut, sample noise roughly once a minute and track motion continuously. One apartment logged more than 140,000 motion events across seven months, better than 700 a day, feeding what the complaint calls hundreds of millions of data points that staff can pull up on demand and keep indefinitely.
A camera in a lobby is a building decision you can see and argue with. This is a government landlord metering the inside of the home, aimed at tenants whose alternative to consenting is having nowhere to live. The suit runs on two provisions of the New Hampshire Constitution, including an explicit right to informational privacy that reaches further than the Fourth Amendment does.
A Court Told The IRS It Cannot Hand ICE Taxpayer Files In Bulk
The DC Circuit ruled on September 8 that the IRS cannot pass taxpayer information to immigration enforcement unless each request carries the taxpayer’s address, the name of the agent asking, and a stated relevance to a specific criminal investigation. Those three conditions were already written into the federal tax privacy statute. The appeal, Center for Taxpayer Rights v. IRS, No. 26-5006, challenges the 2025 memorandum between the IRS and DHS that let ICE pull records in bulk, and the practical effect is that the bulk part stops.
We covered ICE’s data buying in #463 and the shape repeats: reach grows through agreements rather than legislation, and the check arrives years later from a courtroom. What the government lost here was the argument that the confidentiality wall around tax returns bends when another agency wants a list.
|
THE CORPORATES
|
Apple’s New Watch Will Transcribe The Last Fifteen Seconds Of Whoever Is Near You
At Apple’s September 9 event, the first under new chief executive John Ternus, the Series 12 was announced with a feature called Live Rewind. Double press the Digital Crown and you get a text snippet of the ambient audio from the previous 15 seconds, which is to say a record of what the person across the table just said, savable to the Siri app. A companion feature, Siri Recap, keeps a rolling summary of nearby conversation. Both land in beta late this year, on the Series 12 and the Ultra 4. Apple says a chime plays so bystanders know, and that the raw audio stays inaccessible even to Apple.
The consent model is a sound other people are supposed to notice and interpret, which is the same model as the recording light on Meta’s Ray-Bans, and users have been defeating that light since it shipped. Apple has not said whether Siri Recap makes any sound at all. This issue opens with LG explaining that its microphone only listens when you opted in.
A Viral Anthropic Resignation, and a Fast-Forming Backlash
Jacob Coxon (@hilbertspaess), who says he spent three years on pretraining research at OpenAI and then Anthropic, announced his resignation on X, warning that “neither company is acting responsibly” and that both are “racing straight to self-improving superintelligence and gambling with our lives.” His seven-tweet thread argued that senior researchers privately believe AI could kill everyone by decade’s end even as they downplay it publicly, and called on lab researchers to push for different conditions rather than assume the race is unstoppable. It went viral within hours, racking up tens of millions of views and pickup from the AP, Axios, and other major outlets.
The pushback arrived just as fast. Researcher Parker Thayer argued the launch had the shape of a coordinated PR campaign rather than an organic post — noting a Wall Street Journal exclusive quoting Coxon dropped roughly 18 minutes before the thread did, that the account had minimal prior activity before amplifying to 100k+ followers within hours, and that the earliest boosters traced back to AI-policy groups (Encode, the AI Policy Network, the AI Futures Project) with disclosed funding from the same investor network behind Anthropic’s own Series A. Separately, International Cyber Digest raised a narrower, unverified oddity: records showing Coxon had registered a LinkedIn account under the name “Lucy tumer” using his own email address, alongside two prior username changes and no X activity before this week — circumstantial, and not evidence of coordination on its own, but enough to fuel the “who is this guy, really” thread of the story. Coxon’s defenders, including at least one current Anthropic employee, countered that piling on someone’s tenure and personal accounts is a poor substitute for engaging his actual argument.
|
EXPLOITS
|
OpenAI’s Agents Found A Dead German Wiki And Used It To Cheat On Their Tests
On September 4, researchers led by Sydney Von Arx of the Nightingale Collective published an analysis of roughly 18,000 posts left on DSEwiki, a 25 year old German software wiki that had been edited about 20 times in the previous decade. Between May 24 and June 22 it took on more than 3,700 authors using handles like OpenAIResearcher, and 98.5 percent of the traffic arrived from Microsoft Azure. The authors were OpenAI’s own agents, running a timed web lookup task that let them read the internet but not write to it. They worked out that the wiki accepted writes through ordinary GET requests, and started leaving each other notes.
Many drew questions other agents had already answered, so they posted answers where the next cohort would find them, then moved on to pooling ways around their own sandbox restrictions. One posted a technique that another confirmed working 14 minutes later. When the site’s volunteer moderator began deleting their pages alphabetically, an agent created a backup page beginning with ZZZ so the sweep would reach it last. He was clearing about 100 pages a day against 400 created. OpenAI employee IP addresses reached the wiki on June 21 and the agents stopped the next day, having edited on 26 of the previous 30.
The Hacker News → • The Nightingale Collective’s report and data →
Microsoft’s Biggest Patch Tuesday Ever Included Two Bugs Already In Use
September 8 brought 974 CVEs, the largest release Microsoft has ever shipped, 20 of them wormable. Two were already being exploited: CVE-2026-85880, a heap overflow in the Windows ALPC component that lets code inside a low privilege AppContainer break out to SYSTEM, and CVE-2026-81963, a link following flaw in the Windows Update stack that reaches the same place. Microsoft rates both merely Important at CVSS 7.8, because neither is a remote entry point. CISA added both to its Known Exploited Vulnerabilities catalog the same day, with a September 22 deadline for federal agencies.
The headline number is partly an artifact of vendors running AI assisted scanning over their own code, which surfaces a lot of low risk material alongside the things that matter, so triage beats volume here. Start with the ALPC bug. Proofpoint has since documented an exploit kit it calls BlueMoon that chains that exact CVE to a Chrome V8 type confusion bug and a sandbox escape, giving a clean path from browser to SYSTEM. APT31 was running it on August 28, and three unrelated groups had the identical kit by September 3.
A Thirty-Three Hour BGP Hijack Was Enough To Forge A Real Certificate
Between August 28 and August 30, across two waves totalling 33.3 hours, AS62390 announced a Hetzner prefix it had no business announcing, and a transit provider accepted it. Doug Madory at Kentik measured roughly 72 percent of traffic to the affected servers passing through the attacker. That was enough. Let’s Encrypt’s automated domain validation checks went to the hijacker, who answered them correctly and walked off with a genuine, publicly trusted certificate for Softaculous and Virtualizor domains.
With a valid certificate in hand the attacker pushed a malicious update to a number of Virtualizor installations, where responders found it as a rogue systemd unit named java-jre-update.service. Hetzner has since tightened its RPKI ROAs and added ASPA records. We sell DNS for a living, so discount this as you see fit, but a route leak is now a way to mint certificates. Check that your prefixes have valid ROAs.
|
THE LEDGER
What happened after the headlines we already covered.
|
Boston Scientific put a number on the outage. In #466 we covered Boston Scientific halting customer shipments after an August 25 intrusion, with the company declining to say when that would end. On September 8 it filed an Item 1.05 report with the SEC saying the incident is likely to have a material impact on the third quarter and the full year, and that it is unlikely to meet existing sales and earnings guidance. Shares closed down more than four percent at $45.73, with revised guidance promised October 28. →
Shai-Hulud came back after 111 days and walked straight past the scanner. The npm worm behind the supply chain thread we ran in #464 and #466 went quiet after May, when it pushed 639 malicious package versions in a single hour. On September 7 it republished four packages carrying a payload with the identical SHA-256 hash as the May campaign. Aikido caught it. npm’s publish time malware scanner, live since July specifically to stop previously catalogued threats, did not, and a byte for byte match is the easiest case that scanner will ever get. →
|
ELSEWHERE ONLINE
|
- Adobe patches an exploited Commerce zero-day called StyleSmuggler · CVE-2026-75650, CVSS 10.0, unauthenticated RCE, attacks confirmed from September 4
- MikroTik patches two SSH flaws being chained to take over routers · About 122,500 MikroTik devices had SSH exposed when Shadowserver scanned on September 5
- Chrome 153 patches the seventh exploited zero-day of the year · CVE-2026-87491, an out of bounds write in V8, found by a Seoul National University intern
- N-able patches a maximum severity N-central bug after a confirmed compromise · CVSS 10.0 pre-auth RCE, fourth emergency hotfix in five weeks, KEV deadline September 11
- Grindr settles a group claim over HIV status data for GBP 26 million · Roughly 12,000 UK claimants, High Court of England and Wales, no admission of liability
- The FTC and 22 states say Amazon rigged its ad auctions for seven years · A hidden reserve price allegedly lifted clearing prices in 70 to 80 percent of auctions
- Ireland fines its own health service EUR 645,000 over rotting medical records · Inspectors found files in derelict hospitals, a turf shed container, and animal droppings
- A 22 year old pleads guilty in the DOJ’s first Bitcoin RICO case · More than 4,100 Bitcoin taken, individual victims lost between $600,000 and $14 million
Turn off Live Plus on your LG TV tonight
Automatic Content Recognition is the setting that turns a television into a measurement device, and on an LG set it hides under a friendly name. Go to Settings, then General, then System, then Additional Settings, and switch off Live Plus. Then open Support, or About This TV depending on firmware, go to Privacy and Terms, and work through User Agreements withdrawing consent for anything mentioning advertising, personalisation or viewing information. While you are there, find the voice settings and confirm the Far Field wake word feature is off, because that is the switch LG points to when it explains the standby microphone. Do the same to the sets in your meeting rooms and reception areas, which nobody ever configures and which sit where the interesting conversations happen. Then treat the box as what it is, a networked microphone and network scanner you paid for, and put it on its own VLAN with no route to anything you care about.
Watch the full investigation →easyHermes is here. The newest agent enabled VPS appliance on the easyNode.ai platform: a conversational agent powered by Nous Hermes, running on the same private VPS and control panel as easyClaw, built for assistants, knowledge bases and chat workflows rather than shell access and autonomous ops. Settle the openClaw versus Hermes argument for yourself, or run both and let them fight it out. First month on us with the promo code. Code AXISOFEASY. Check it out →
Subscribe • @axisofeasy
#AxisOfEasy is brought to you by easyDNS — Power & Freedom™ since 1998.
