The latest episode of the Smashing Security podcast delivers a trifecta of cybersecurity revelations, from researchers who deliberately got drunk to hack an LG television to a new Android malware strain that graduates from data theft to full-on psychological harassment. The show, hosted by Graham Cluley with guest Lianne Potter, also features an extended interview with Andy Hornegold, Chief Security Technologist at Intruder, exploring how artificial intelligence is reshaping both offensive and defensive cybersecurity operations. Each segment exposes a different facet of the modern security landscape: the opaque data-hungry business models embedded in consumer hardware, the increasing sophistication and malice of mobile malware, and the double-edged sword that AI represents for defenders and attackers alike.
Drunk Researchers, a Loophole, and the LG TV That Never Stops Listening
The most arresting story of the episode centers on a deep-dive investigation published on the Gamers Nexus YouTube channel, where security researchers set out to discover what LG smart televisions actually do behind the scenes. What they found raises fundamental questions about privacy, data ownership, and whether a device you paid for can truly be considered yours.
The researchers faced an immediate legal obstacle: LG’s terms and conditions explicitly prohibit reverse engineering and security testing. To sidestep this, they employed an unusual but legally sound strategy. Their lawyers advised that a contract agreed to while intoxicated cannot be considered binding. So the researchers got drunk — genuinely, demonstrably drunk — before setting up the television and clicking through the EULA. The tactic worked, allowing them to proceed without being bound by the agreement they had technically accepted.
What the Television Was Hiding
The findings were alarming. In one test, the researchers staged a whispered conversation about a fake cryptocurrency scam directly in front of the television while its screen was entirely black and showed no signs of life. Afterward, they discovered that the entire conversation had been transcribed and saved onto the TV itself — word for word. In another test, the television clearly picked up a human voice from approximately 70 feet away through a wall.
These demonstrations required the researchers to first exploit vulnerabilities and hack their way into the television’s operating system — a step most users would not be able to perform. But the critical point is that the capability existed within the hardware, waiting to be activated by anyone with the right access or the wrong intentions. The television had the ability to function as a listening device even when it appeared to be switched off, even when no button was pressed, and even when the person speaking was at a considerable distance.
The reason for this capability is not user convenience. Modern smart televisions generate significant revenue not from hardware sales but from advertising and data monetization. Entire divisions within TV manufacturing companies are devoted to collecting viewer information and selling access to advertisers. LG executives have been quoted as saying the company “owns the glass” — meaning the screen a consumer paid thousands of dollars for is, in their view, still LG’s property, with the user merely borrowing it.
Network Scanning and Data Persistence
Beyond audio surveillance, the researchers discovered that LG televisions quietly scan entire home networks, building inventories of every device connected to the same Wi-Fi — phones, smartwatches, even a 3D printer. The TV also captured nearby Wi-Fi signals, providing enough information to approximate the physical location of the device. This data is valuable for targeted advertising and can be shared with or sold to third parties.
Equally troubling was the behavior of the privacy controls. The “Do Not Sell My Personal Informationaaa” setting was disabled by default, and users could not initially connect the TV to the internet without the data collection being active. Even when users retrospectively disabled data collection and requested deletion of voice recordings, the recordings remained on the device. They disappeared only when the television was completely unplugged from the wall socket — a full power disconnect, not merely a loss of internet connectivity.
The researchers also tested a rooted unit and found that even with the network cable physically removed — no Wi-Fi, no Ethernet, no internet connection at all — the television continued to quietly record and store audio data. The moment the network cable was reinserted, all stored data was uploaded to LG’s servers. The TV does not need to be online at the moment it listens to you; it only needs to reconnect eventually.
LG has disputed the seriousness of these findings, stating that voice processing occurs only when the user deliberately presses a button on the remote or uses a wake word, and that tracking features require explicit opt-in. However, the company’s own advertising division presents a different picture, boasting to advertisers about the volume and granularity of consumer data it can access.
What This Means for Smart TV Owners
The researchers’ practical advice is straightforward: stop using the smart features built into the television itself. Instead, use a separate streaming device such as an Amazon Fire Stick or Apple TV. This approach shifts the data collection burden to a device that may face more regulatory scrutiny and user control options. Of course, as Cluley and Potter noted during the podcast, this solution is imperfect — Amazon and other streaming device manufacturers have their own privacy practices to consider. But the principle of minimizing exposure by decoupling the display hardware from the data-collection software is sound.
MantaXotax: The Android Malware That Does Everything, Then Harasses You
Lianne Potter brought to the episode a story about a piece of Android malware that redefines what mobile threats can do. Named MantaXotax — derived from the Indonesian word “mantax,” meaning awesome — this malware refuses to specialize. Instead, it combines nearly every malicious capability into a single payload.
Once installed on an Android device, typically through sideloaded APKs distributed via Telegram channels, forums, or phishing messages, MantaXotax requests accessibility service permissions. Granting this gives the malware near-total control over the device. It proceeds to steal SMS messages, contacts, browser history, WhatsApp data, and Telegram data. It captures screenshots, records the screen, and takes photos using the device’s camera. Then, as if that were not enough, it encrypts the user’s files and demands a ransom.
The malware communicates with a command-and-control infrastructure, exfiltrating stolen data to its operators. It is particularly effective against older versions of Android, where security updates are no longer available. The attack vector relies on social engineering — users receive convincing messages urging them to install an app from outside the official Google Play Store.
The Jump Scare Feature
What sets MantaXotax apart from other malware strains is a feature the developers explicitly labeled “jump scare.” After the data theft and encryption are complete, the malware begins displaying rapid full-screen videos and images through the device’s speakers, accompanied by text-to-speech messages designed to frighten the victim. The phone essentially becomes a haunted device, screaming at its owner through synthesized voices while the screen flashes disturbing content.
This is not a technical accident — it is a deliberate psychological tactic intended to panic victims into paying the ransom more quickly. The jump scare feature turns what might be a frustrating but manageable incident into a genuinely terrifying experience. Potter described it as turning the device into something possessed, requiring something like the spiritual intervention of the woman from Poltergeist to calm it down.
Defending Against This Threat
The primary defense against MantaXotax is straightforward and widely applicable: do not sideload applications from untrusted sources. The malware does not appear in the official Google Play Store and relies on users installing APKs manually. The second critical defense is keeping the operating system updated. Older Android versions are disproportionately affected because they lack the security patches that mitigate such threats.
Potter’s framing was memorable: sideloading random apps from Telegram is the cybersecurity equivalent of accepting a drink from someone called Kevlar Dave in a nightclub. The advice applies beyond this specific malware strain to the general principle of maintaining hygiene in mobile app installation practices.
AI in Cybersecurity: Intruder’s Vision for Continuous Penetration Testing
The episode’s featured interview with Andy Hornegold of Intruder provided a deep look into how artificial intelligence is being deployed on the defensive side of cybersecurity. Intruder, a UK-based company focused on the mid-market security space, has launched an AI-powered penetration testing platform that represents a significant shift in how organizations can approach vulnerability discovery.
The Mid-Market Security Gap
Hornegold explained that mid-market businesses — organizations that are too large for a founder to handle security personally but too small to maintain a dedicated enterprise security team — face a unique vulnerability profile. Large enterprises have the budget and personnel to fix exposures quickly. Small companies can move fast because they know their codebase intimately. But mid-market organizations often find themselves in a kind of security no-man’s-land, where the time to remediate critical vulnerabilities stretches longer than it should.
These businesses are also under increasing pressure from larger customers to demonstrate adequate security practices. Compliance requirements and supply chain security mandates mean that a mid-market company without proof of regular penetration testing or vulnerability management may find itself unable to win contracts. Intruder’s product is designed specifically to serve this segment, providing automated but thorough security validation at a fraction of the cost of traditional manual penetration testing.
How AI Pen Testing Works
Intruder’s AI pen testing platform uses multiple AI agents to perform what Hornegold describes as “informed white-box testing.” Rather than treating the target application as a black box and probing for vulnerabilities from the outside, the AI agents ingest the entire source code — potentially millions of lines — and map attack paths through the application logic. They then validate findings by launching real attacks against the live application, dramatically reducing false positives.
This approach differs from traditional automated scanners, which often generate large volumes of noise. It also differs from human-led penetration testing, which is expensive, time-consuming, and subject to the variability of individual consultant expertise. The AI model can scale to ingest and analyze codebases that would take a human team weeks to review, and it can do so on demand, without requiring scheduling, scoping calls, or six-week waiting periods.
Hornegold noted that early results have been striking. Organizations that had undergone annual penetration testing for five, six, or seven years were found to have hundreds of vulnerabilities still present in their codebases — vulnerabilities that had been missed by human testers but were identified by the AI’s systematic, code-informed approach.
Safety, Trust, and Model Dependency
Cluley raised a critical question about safety: is it safe to let an AI system test a live production environment? Hornegold acknowledged that human penetration testing has never been entirely risk-free either — a single mistaken command can take a system offline. The same risk controls apply: testing in staging environments, maintaining backups, and tracking all changes made during testing. The AI approach is not inherently more dangerous than human-led testing; it simply requires the same rigorous safeguards.
A more strategic concern emerged around model dependency. In June 2025, the US government briefly forced Anthropic to disable its most advanced Claude model over security concerns, leaving organizations that relied on that model without access. For a company like Intruder, which benchmarks and uses frontier models from multiple providers, this kind of regulatory intervention represents a real business risk. Hornegold indicated that Intruder is actively evaluating open-weight models as a hedge — if a commercial model is suddenly unavailable, the company could fall back to models it runs on its own infrastructure.
On the question of using Chinese-made AI models, Hornegold was measured but clear. He would not rule out using open-weight models that Intruder could deploy on its own infrastructure, but sending customer data to Chinese AI providers is not something a UK company with a predominantly US customer base would likely pursue.
The Asymmetry Problem
Hornegold’s most pointed observation concerned the asymmetry between attackers and defenders when it comes to AI. Attackers face no contractual or safety restrictions. They can bypass safeguards and use AI models to accelerate their operations without concern for terms of service. Defenders, by contrast, must navigate safety guardrails, compliance requirements, and the risk of being banned from a platform they depend on. This gives attackers a structural advantage in the short term.
However, the long-term advantage may tilt toward defenders. The cost of comprehensive security testing has dropped dramatically. Organizations that previously conducted one penetration test per year can now consider continuous, on-demand testing at a fraction of the cost. AI does not eliminate the need for human expertise — Hornegold envisions human testers focusing on the most complex, cutting-edge scenarios while AI handles routine validation — but it does close the gap between the frequency of code changes and the frequency of security testing.
The Landscape Ahead: Hardware Privacy, Mobile Threats, and AI Defense
The convergence of these three stories paints a coherent picture of the current cybersecurity landscape. Consumer hardware manufacturers are embedding surveillance capabilities into everyday devices and monetizing the data in ways that users cannot easily opt out of. Mobile malware is evolving beyond simple data theft into multi-function platforms designed to maximize psychological pressure on victims. And artificial intelligence is simultaneously accelerating attacks and creating new defensive capabilities that may finally make continuous security validation practical and affordable.
For consumers, the lesson is to approach smart devices with skepticism. The television you bought is not just a television — it is a data collection terminal that generates revenue for its manufacturer by watching you. Unplugging it from the internet, using an external streaming device, and being deliberate about the permissions granted during setup are practical steps toward regaining some control.
For organizations, particularly in the mid-market, the message is that the tools for continuous security validation are becoming accessible. The argument that annual penetration testing is insufficient has been made for decades. AI-powered testing may finally provide the mechanism to move beyond that model, not by replacing human judgment but by scaling the systematic discovery of vulnerabilities to match the pace of modern software development. The window for attackers is narrowing, but only for those willing to adopt the new tools available to them.