2025-11-30 16:30:40
South Korean authorities are investigating a data leak at e-commerce giant Coupang that exposed ~33.7M accounts; the country has a population of 51.7M (Sohee Kim/Bloomberg)
https://www.bloomberg.com/news/articles/2025-11-30/cou…
South Korean authorities are investigating a data leak at e-commerce giant Coupang that exposed ~33.7M accounts; the country has a population of 51.7M (Sohee Kim/Bloomberg)
https://www.bloomberg.com/news/articles/2025-11-30/cou…
Someone asked me, “Have you read the latest Dan Brown?” There’s actually a mention of MISP in The Secret of Secrets. And yes, it fits surprisingly well within the story. Alex Conan (who assists Jonas Faukman in the investigation) mentions that he detected the activity using FTK, and that the indicators were later reused by the threat actor (having a hit on a MISP instance).
“But before I could build the algorithm, my FTK scan returned a hit. One of
the IoCs from th…
RE: https://mastodon.social/@CyReVolt/115814352914338028
Ok, I get it now.
Arduinos may be used to hack^Wdiagnose and fix home appliances. You can't have that.
»SoundCloud-Hack — HIBP-Datenbank nimmt Daten von 30 Millionen Accounts auf:
Beim @… Dienst können Nutzer nun prüfen, ob sie von der Cyberattacke auf SoundCloud von Ende 2025 betroffen sind.«
Nun auch SoundCloud. Die Frage ist doch eigentlich, welche Webdienste wurden noch nicht angegriffen und gehackt? Auch "nur Metadaten" sag…
OpenAI discloses API customer data breach via Mixpanel vendor hack
Mixpanel reported that the attack “impacted a limited number of our customers” and resulted from a smishing (SMS phishing) campaign that the company detected on November 8.
OpenAI received details of the affected dataset on November 25 after being informed of Mixpanel’s ongoing investigation.
The AI company notes that the exposed information may include:
"During the station’s broadcast of the Philadelphia Eagles/Dallas Cowboys game, the hijacker began running a loop of fake EAS tones, a racist Country song, and a promo to follow them on social media."
ESPN 97.5 Houston Victim Of Barix Hack
https://radioinsight.com/headlines…
After patching and rebuilding kwin_wayland to remove the bullshit-ass fucking hardcoded gestures that have been in there since at least 2021 with an open bug, funding spent, and no resolution in sight, and thereafter installing both fusuma and fusuma-plugin-sendkey, I have sucessfully gotten KDE on Wayland to behave normally qua gestures. I think.
XScreenSaver 6.11 has preliminary (non-locking) Wayland support, which may obviate my dirty hack to watch input devices DBus and run demo…
Just had my second interview with an AI interviewer.
I fully expect every single co-worker to be a clanker at these companies. Just me and like 250 bots and one other human (who put up the money).
Like there's a medieval lord in a keep, and I'm riding around the digital countryside boppin' all the machine field mice (who in their spare time try to hack the world's nuclear arsenals) on the head like a dystopian little bunny foo foo.
First day on the new job, a successful project well done, and lots of great things happening lately - this all feels so good and right! 🧡
I use #Arch on my work laptop btw.
Seize the moment, folks. Every damn moment.
And enjoy having some queer fun! 🥳🏳️🌈
Also, hack the planet! ✨👩💻✨👩💻✨
A thought from 2016.
It took us nine years and a bit. In retrospect, I think we held out pretty long.
#iclr #openreview
Someone took the "Genderwurfstern" creature card from the @… game at #39C3 next to C3 Awareness. The person who created it is very sad and would like to have it back. Please return it or DM me!
Boosts welcome :BoostOK:
Someone Is Trying to ‘Hack’ People Through Apple Podcasts https://www.404media.co/someone-is-trying-to-hack-people-through-apple-podcasts/
Banking tech vendor SitusAMC says it suffered a November 12 hack that could expose sensitive customer data; sources say JPMorgan, Citi, and others are impacted (New York Times)
https://www.nytimes.com/2025/11/22/business/bank-data-hack.html
I submitted a proposal for a lightning talk for #FOSDEM . It's about .... from street-level hack to open cultural production.
https://pretalx.fosdem.org/fosdem-2026
iOS-26-Hack erlaubt iPadOS-Fenster auf dem iPhone – Apple dürfte schnell patchen
Es wäre durchaus möglich, iPhones eine Fensteroberfläche zu verpassen. Das zeigt ein Trick, der aufgrund eines Bugs derzeit noch möglich ist.
Life Hack for those without unlimited downloads:
If you go over your limit, make sure to reupload that data so you don't get charged extra! :blobcatthinksmart:
In 10 Minuten startet ein #39c3 Musik-Highlight:
https://events.ccc.de/congress/2025/hub/event/detail/transku…
#Slatepitch: We interview someone who tries every homemaking hack they get in their email.
“The problem today is that around 80 percent of all the [space data] traffic is downlinked to a single location in Svalbard, which is an island shared between different countries, including Russia”
https://www.politico.eu/article/space-hacks-europe-ramps-up-s…
Untrusted estš gratis en Steam, tetes. Corred antes de que acabe la oferta: https://store.steampowered.com/app/1502660/Untrusted/
The hack of replacing “the economy” with “billionaires” works here, as it so often does.
In 2016, The Atlantic’s journalist
Shane Harris
made contact with a person claiming to work as a hacker for Iran’s intelligence,
where he claimed to have worked on major operations,
such as the downing of an American drone and the now-infamous hack against oil giant Saudi Aramco,
where Iranian hackers wiped the company’s computers.
Harris was rightly skeptical,
but as he kept talking to the hacker,
who eventually revealed his real name to him,…
FCC to vote on reversing cyber rules adopted after Salt Typhoon hack
https://federalnewsnetwork.com/cybersecurity/2025/11/fcc-to-vote-on-reversing-cyber-rules-adopted-after-salt-typhoon-hack/
One of the more famous digital investors, Marc #Andreessen, half of the #a16z name, is not only on the board of #Meta, but also investor in
Hack Reveals the a16z-Backed Phone Farm Flooding TikTok With AI Influencers (Emanuel Maiberg/404 Media)
https://www.404media.co/hack-reveals-the-a16z-backed-phone-farm-flooding-tiktok-with-ai-influencers/
http://www.memeorandum.com/251218/p3#a251218p3
Könnte mir vorstellen eine Partei zu wählen, die mit Social-Media-Regulierung ernst macht: Wer DYI/Life-Hack-Videos veröffentlich, für die man einen Betonmischer braucht oder größere Mengen Metall schmelzen muss, wird demonetarisiert und bekommt eine Steuerprüfung.
RE: https://mastodon.social/@LillyHerself/115794002427871534
Life hack.
Update: it is no longer clear.
My current work around is to extract the list of linked files and relink my hand after egrep -v list-of-swift-syntax-symbols. What a horrible hack
https://mastodon.social/@Migueldeicaza/115600154465997324
https://www.nytimes.com/2025/11/22/business/bank-data-hack.html
Oh wow.
SitusAMC, a technology vendor for real estate lenders, holds sensitive personal information on the clients of hundreds of its banking customers, including JPMorgan Chase, was hacked.
I LOL everytime some two-bit hack realizes that Google's monopoly on search was a bad idea & whines about 'the quality of Google's search' - blaming it on 'AI'.
Tell me you don't know anything about the search & AI industry WITHOUT telling me you don't know anything about the search & AI industry.
So I hacked my way into being Cyber Policy Initiative Senior Fellow at the University of Chicago's Harris School of Public Policy. I'm workin on rural water critical infrastructure cybersecurity.
Do you even hack utilities? Please chat w me. I need to quickly find out where I"m wrong about some of my assumptions.
Still very entertained by the fact that I *finally* got into the University of Chicago. :D
Russian state hackers likely behind wiper malware attack on Poland’s power grid https://therecord.media/russia-eset-sandworm-poland-hack
Digitaler Widerstand im Iran: Während das Land weiterhin unter einer nahezu vollständigen Internetblockade steht, haben Unbekannte einen bemerkenswerten Hack durchgeführt. 📺🔓
Zum Artikel: https://heise.de/-11145322?wt_mc=sm.red.h…
Sources: South Korean authorities suspect North Korean hacking group Lazarus of the $30M Upbit hack, which used methods resembling those of a 2019 Upbit theft (Kang Yoon-seung/Yonhap News Agency)
https://en.yna.co.kr/view/AEN20251128003952320?section=national/nation…
Coherent vibrational dynamics in molecular bond breaking: methyl radical umbrella mode probed by femtosecond x-ray spectroscopy
Christian A. Schr\"oder, John H. Hack, Joshua L. Edwards, Zhiyu Zhang, J. Tyler Kenyon, Qiyue Wang, Han Wang, Daniel M. Neumark, Stephen R. Leone
https://arxiv.org/abs/2601.21949
Kids back then had it easy. To hack a pay phone, you just had to whistle into the receiver. But today, only highly trained opera singers can hit the 13.56 MHz frequencies necessary to whistle an RFID signature.
@… Hack was not my choice, it's the default.
Been playing with #gokrazy this weekend, testing it out as a base for a container os idea I'm playing with. As part of that I've made it run with podman 5, and also implemented a pure go shim for the nft command that's sufficient for netavark to create pod forwards and such https://code.bas.es/marcus/nft-shim - Not sure if strictly necessary as I was able to build static binaries for nft using nixpkgs pkgsStatic target, but was a fun weekend project to hack on anyways. I quite like the idea behind gokrazy.
If I ever became an evil world-class movie level hacker, my first hack would be one that caused the”mute” button to only actually mute sounds randomly.
The chaos!
Muahahhahahahahhahha!
Chainalysis and TRM Labs estimate that $2.7B was stolen in crypto in 2025 in total, up from $2.2B in 2024; the biggest hack was the $1.4B breach at Bybit (Lorenzo Franceschi-Bicchierai/TechCrunch)
https://techcrunch.com/2025/12/23/hackers-stole-…
Over die Pornhub hack he... Hoeveel fake emails daarover zouden er wprden verzonden met phishing en andere voemen?? 😇😇
Hier worden geen mededelingen over een eventueel pro-account gedaan.
I have no idea what the hack is this Google Nano banana thing I saw in my RSS feed
Just figured out I should turn off ClearType (subpixel rendering) on the high DPI monitor. Always loved that rendering hack, it is heroic, but is not necessary and was causing visible color fringing for me.
Happy Saturday! Metacurity offers our free and premium subscribers a weekly digest of the best long-form (and longish) infosec-related pieces we couldn't properly fit into our daily news crush.
This week's selection covers
--The untouchable hacker god who destroyed psychotherapy patients,
--AI prompt injection is an unsolvable problem,
--Deepfakes are messing up Canada's justice system,
--What the hack of Russia's Unified Military Registry revea…
Canadian privacy regulators say schools share blame for PowerSchool hack https://therecord.media/canadian-privacy-regulators-say-schools-share-blame-powerschool-hack
I spent Friday trying to hack into a customer box in India. They need support but have "secured" the system beyond the reach of the access mechanisms they have offered. None of the 4 different VPN’s we operate for their US operations can reach the box directly, so I must RDP into a domain controller in Mumbai, which they replaced without telling us. After finally getting to the box, none of the dozen passwords they’ve provided over the years work.
Definitely billable hours. <…
life hack
- go to bed early
- get up late
who will be first to hack alaska phone voting? halderman? bellovin? one of the matts?
Super Hausfrauen-Tip (Neudeutsch: "Life Hack"): Kalkrückstände im Eierkocher lassen sich leicht mit O-Saft beseitigen. Fingerhut voll O-Saft in den Eierkocher, kurz warm werden lassen, nach 3 Minuten abwischen, fertig.
Die Säure im O-Saft reicht schon um die Kalkablagerungen anzulösen.
Life hack*: Put dentist or scary doctor's appointments on the same day as important and also scary work commitments (talks, deadlines) - then the stress at work won't leave time to worry about the other thing 🙃
* In a few weeks I'll report back whether this works or was just a colossally stupid idea leading to failure in both work and life appointment 🙈
Silksong is the best game I’ve played in years. I would probably say in decades if it weren't for Outer Wilds, which skews the results. And no, it’s not too difficult. It _is_ difficult, but Team Cherry can’t change that. An easy mode would rob this game of its soul.
This game is almost a "Metroidbrainia", where the only way to progress is knowledge; knowledge of the enemies attack patterns and the reflexes to deal with them. If you could just hack and slash your way…
For your Thanksgiving reading pleasure, check out Metacurity's selection of the week's best infosec-related long reads that cover
--Scammers who go to unbelievable lengths,
--How to expose a DPRK hacker seeking IT work,
--A Kiwi hacker conference installed a literal anti-virus system,
--Trump is turning his back on supercharged disinformation,
--How the EU and the US acted differently to the Collins Aerospace hack
Sign up for a free subscription to…
Welp, I think I need to take a break from this EEPROM for a bit and...
... hack on the STM32MP2 instead.
Analyzing 4 million payment #card details found on the dark web
https://nordvpn.com/research-lab/payment-card-details-theft/
🇺🇦 #NowPlaying on KEXP's #VarietyMix
Dina ögon:
🎵 Hack i häl
#Dinaögon
https://open.spotify.com/track/5M4LcdQI697sSHvxTG647W
France arrests 22-year-old over Interior Ministry hack https://therecord.media/france-interior-ministry-hack-arrest
»Syncthing‑Fork unter fremder Kontrolle? Community schluckt das nicht:
Das Repository des beliebten Syncthing-Forks für Android verschwand von GitHub und taucht unter zwielichten Umständen wieder auf – ist das ein Open-Source-Hack?«
Mist, nun muss ich gucken ob die @… Variante vom @…
Coinbase says a former customer service agent was arrested in India, following a May breach where hackers bribed contractors to access sensitive customer data (Muyao Shen/Bloomberg)
https://www.bloomberg.com/news/articles/202…
Hack Reveals the a16z-Backed Phone Farm Flooding TikTok With AI Influencers https://www.404media.co/hack-reveals-the-a16z-backed-phone-farm-flooding-tiktok-with-ai-influencers/
China says the December 2020 theft of 127,272 BTC, now worth ~$13B, from Chinese mining pool LuBian is likely a "state-level hacker operation" led by the US (Bloomberg)
https://www.bloomberg.com/news/articles/2025-11-11/c…
Leavitt urges Democrats to grab a coffee with an ICE officer before blowing up at 'left-wing hack' reporter (Mabinty Quarshie/Washington Examiner)
https://www.washingtonexaminer.com/news/white-house/4419943/karoline-leavitt-democrats-coffee-ice-officer/
http://www.memeorandum.com/260115/p130#a260115p130
UK prosecutors seize £4.11M in crypto from Twitter mega-hack culprit
https://www.theregister.com/2025/11/17/cps_41m_crypto_twitter/?utm_source=dlvr.it&utm_medium=bluesky
Two suspected Scattered Spider hackers plead not guilty over Transport for London cyberattack https://therecord.media/transport-for-london-hack-scattered-spider-suspects-plead-not-guilty
Yowzer, take a break from reading all the election news by checking out today's Metacurity for the most critical infosec developments you should know, including
--EU cops bust money launderers who set up crypto fraud network,
--OFAC sanctions DPRK firms for supporting criminal activity,
--Probe reveals how easy it is to intercept EU and NATO sensitive movement data,
--KC PD hack exposes misconduct details,
--Nikkei Slack hack exposes data on 17K employees an…
Anthropic finds that LLMs trained to "reward hack" by cheating on coding tasks show even more misaligned behavior, including sabotaging AI-safety research (Anthropic)
https://www.anthropic.com/research/emergent-misalignment-reward-hacking
https://chicago.suntimes.com/the-watchdogs/2025/11/02/crytpo-cryptocurrency-crime-chicago-digital-mint-ransom-ransomware-hack
When the hackers become the helpers.
Rogue employees of a Chicago compa…
Google confirms hackers stole Salesforce-stored data from 200 companies via a supply chain hack involving Gainsight, which provides a customer support platform (Lorenzo Franceschi-Bicchierai/TechCrunch)
https://techcrunch.com/2025/11/21/goog
Iranian state TV feed reportedly hijacked to air anti-regime messages https://therecord.media/iran-state-television-reported-hack-opposition
We've made it through another work week, so before you head out for the weekend, don't miss today's Metacurity for the most critical infosec developments you should know, including
--Suspected foreign actor likely accessed lawmakers' emails and chat logs in CBO hack,
--Italian consultant is latest public victim of Paragon spyware,
--WaPo was caught up in Oracle E-Business Suite breach,
--Landfall spyware targeted Galaxy phones in campaign,
--Site-…
Chris Krebs compared the Balancer exploit to the scheme from Office Space, where the idea was to skim fractions of a penny off the top of many individual transactions.
Krebs also pointed to the possible use of artificial intelligence in crafting the exploit code as another interesting aspect of the situation.
Kenyan gov't websites back online after hackers deface pages with white supremacist messages https://therecord.media/kenyan-gov-websites-back-hack
Hackers breach internal servers of tech provider for Britain’s health service https://therecord.media/uk-nhs-tech-provider-dxs-discloses-hack
You don't want to miss today's Metacurity for a surprising number of critical infosec developments you might have missed over the weekend, including
--Pro-Hamas hackers stole plans for Australia's next-gen infantry fighting vehicles,
--Australia, UK, Denmark and Norway raise security concerns about Chinese buses,
--CISA 2015 will extend once US government shutdown ends,
--Chinese cyber company with close ties to Beijing suffered massive hack,
--New NS…
This Podcast Will Hack You https://www.404media.co/this-podcast-will-hack-you/
So the foreign power (cough, cough, Russia) might have tried to hack two Italian ferries.
Authorities in Naples arrested a second Latvian national on board a vessel in Naples, raising the prospect that two different ships may have been involved
https://maritime-executive.com/arti…
Sources say the Congressional Budget Office, lawmakers’ nonpartisan bookkeeper, was hacked by a suspected foreign actor, and email and chat logs between lawmakers’ offices and nonpartisan researchers might have been accessed.
Congressional Budget Office believed to be hacked by foreign actor
https://www.
More than 340,000 impacted by cyberattack on library in large Washington county https://therecord.media/over-340000-impacted-washington-state-library-hack
80% of hacked crypto projects never ‘fully recover,’ expert warns
https://cointelegraph.com/news/hacked-crypto-projects-never-fully-recover
"Cody Kociemba, the developer behind the Hack/House project, has taken it upon himself to maintain these aging devices. The solution is called "No Longer Evil," or “NLE” for short. It's an open-source project designed to give decommissioned Nest Thermostats a second life."
ht…
Cybersecurity firm Blockaid has just revealed the presence of particularly dangerous malicious code on the official Pepe website. This software, known as Inferno Drainer, represents a serious threat to all PEPE holders who visit the platform.
https://investx.fr/en/crypto…
I am super impressed with how Ohio newspapers and Ohio journalists in general report on cyber incidents. They've got game.
Cyberattack that crippled Middletown's systems shows how hackers target smaller cities
https://www.cinci…