Malware Steals Claude Sessions, Google Nerfs Pixel 11, EU vs ChatGPT, Chinese Cisco Spy Op
Infostealer malware is quietly harvesting active Claude login sessions and burning through victims' AI quotas, and 2FA won't stop it. Google removed a key hardware security feature from the Pixel 11, and GrapheneOS is now telling people to buy a Motorola instead. The EU has officially decided ChatGPT is a "search engine." And a China-linked hacking group turned compromised Cisco routers into full-blown spy platforms that lie to the administrator looking at them. This week, John and Logan break down six stories covering AI security, phones, regulation, and one very uncomfortable question about your router. Stories in this episode: Malware steals Claude sessions. Anthropic is warning users that infostealer families like Vidar, LummaC2, StealC, RedLine, and Atomic Stealer are harvesting active Claude sessions from infected computers. The attackers don't need your password or 2FA code. They're stealing the session token that says you already authenticated. Some users noticed their Claude usage limit reset and then disappear again while they weren't using it. That's because somebody else was. Google nerfs the Pixel 11. GrapheneOS spent about a week working on its Pixel 11 port before concluding that Google removed hardware Memory Tagging Extension. MTE existed on Pixel 8, 9, and 10, and GrapheneOS builds core exploit protection around it. GrapheneOS is now recommending users not buy the Pixel 11 and pointing instead to a new partnership with Motorola, whose 2027 flagship phones are expected to become the first officially supported non-Pixel devices. EU calls ChatGPT a search engine. Under the Digital Services Act, ChatGPT crossed 45 million monthly EU users and got officially designated a Very Large Online Search Engine. The classification isn't just a label. It brings mandatory systemic risk assessments covering illegal content and child safety (reasonable) but also misinformation, electoral processes, and public discourse (much fuzzier). Non-compliance can trigger fines of up to 6% of worldwide annual turnover. Chinese hackers turn Cisco routers into spy platforms. A China-linked group called Fire Ant compromised Cisco IOS XR routers, TACACS authentication servers, and Linux management systems. Custom router malware suppressed syslog messages, modified show command output, and turned routers into packet capture devices uploading traffic to external FTP servers. If you SSH into your router and everything looks fine, that may be the malware answering your questions. Plus Proton's political neutrality problem (SSH keys in a synced password manager and a $100K donation into one of the most politically charged conflicts on Earth), and California accidentally giving Linux a pass on age verification through the AB 1856 open-source exemption. New episodes weekly. Follow Zero Downtime for cybersecurity, AI, privacy, and the tech stories that actually matter.