PP125: News Roundup—Cyberattack Impacts Pacemakers, OpenAI Publishes Eye-Opening Postmortem, and More artwork

PP125: News Roundup—Cyberattack Impacts Pacemakers, OpenAI Publishes Eye-Opening Postmortem, and More

The Fat Pipe - All Packet Pushers Pods

September 8, 2026

If it feels like everything is on fire, today’s News Roundup will not dispel that feeling. We discuss consumer routers that ship with factory-installed backdoors, US law enforcement agencies shutting down hacking domains, and how a threat actor tied to China is targeting Cisco IOS-XR routers.

Speakers Drew Conry-Murray, JJ

TopicsTechnology

Drew Conry-Murray (0:06)

Hey, everybody, Drew here. Just wanted to let you know that JJ and I are going to be at the CyberSecCon Cybersecurity Conference on September 15th and 16th in Houston, Texas. This is 2026 We'll have a booth there. We're going to be giving away some swag, including this exclusive packet protector fridge magnet. If you want to get that or some other stuff, come by and say hello. And also, if you still haven't bought your ticket, you can save 15% off the ticket price using code CSCPacketPushers-26.

That's CSCPacketPushers-26 at the CyberSecurityCon conference. Hope to see you there.

JJ (0:39)

Welcome to Packet Protector, the podcast at the intersection of networking and security. I'm JJ. Here with Drew Conley-Murray. And as usual, this is our news roundup coming into September.

We have a few stories we're hitting today. We actually have a lot of stories we're hitting today.

Drew Conry-Murray (0:53)

Yeah, I don't know why you said few.

JJ (0:54)

I know. I know. Well, but here's a few of the ones. I'm going to give you a quick summary of a few of the ones we're hitting with many more slated. We'll see how far we get down the run sheet. But there's several that I think caught Drew and I's attention. So there's a Wi-Fi router that you can buy on Amazon that ships with the root shell that's listing on the Internet. So there's actually a few ways that this manifest. It's sold under a lot of different brand names.

None of them look like a Chinese thing, but it actually gets worse than that. And we'll get into why here in a minute.

And then Drew, you actually slotted in OpenAI's post-mortem on the Hugging Face breach. You want to tease that a little bit?

Drew Conry-Murray (1:32)

Yeah, they did both their own post-mortem and got a third party to look into what happened and write a report. And I think I'll have some comments, but I think it's really, really interesting and worth everyone's time to go check it out. And I just wanted to make sure we touched on it here.

JJ (1:48)

Okay.

Also, if you have a pacemaker that got implanted after August 25th very recently, there is a slight chance it can't send monitoring data anywhere. So we're going to talk about that and another healthcare breach. And then a UK power plant attack, a small UK power plant attack that happened recently. With a very suspicious lack of detail, we're not diving into it much here other than to kind of call out the fact that it is alarming that nobody's talking about it and we don't know why. Yeah.

Drew Conry-Murray (2:18)

And we'll also get a story about a couple of security researchers or scam researchers who actually flew to Nigeria to confront a sextortionist. So interesting stuff there.

JJ (2:32)

When fact is stranger than fiction.

Drew Conry-Murray (2:34)

Yeah. More to say about that later.

JJ (2:39)

All right.

Drew Conry-Murray (2:39)

So as you mentioned at the top, security researchers have discovered a backdoor implants built into firmware that runs on a variety of home routers built by a Chinese company called ZBT Link. These routers are sold under a bunch of different brand names throughout North America on Amazon and Alibaba.

The security researchers Volchek found three different implants, one's called SpeakingStone, one's called Endless Door. These are phone home implants. They make outbound connections to the manufacturer of cloud infrastructure using hard-coded destinations. There's a third implant called Dark Lantern, that's a listener, but it will accept remote commands.

JJ (3:11)

Yeah. And I want to just in case you're listening to this and not reading the notes, it's ZBT as in like Zebra Beta Tango. There's a lot of Z letters floating around in companies, ZBT. Now, I thought this was really interesting. So apparently, this stuff's been floating around in some of these products since, I think, 2019-ish.

Embedded in the hardware. And there's actually, I think, three different flavors or versions of these different implants that were in different models at different times. And they do different things. So a couple of them accept inbound requests and instructions. And I think the more recent one that they found is outbound, which means it can kind of traverse and find its way out, regardless of what type of network and nading it's sitting in.

Drew Conry-Murray (4:01)

Right. The two outbound ones can make their own connections. The third is just listening. So you have to...

It's like if you've got a firewall or something or you're nading, then an outbound attacker might not be able to reach the listener, but the two outbound ones can initiate their own communications.

50 more minutes of transcript below

Thousands of transcripts fetched by people building searchable podcast archives

Fetch the whole transcript

The demo key returns a sample episode in full, no card needed:

request
curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Markdown with the speakers named, for your notes, your knowledge base, or anything that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.

Using your own key:

request
curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000788526184