2026-07-18 19:23:19
According to this updated password hacking table from #HiveSystems, my password system is firmly in the green zone. 💚
https://www.hivesystems.com/password
According to this updated password hacking table from #HiveSystems, my password system is firmly in the green zone. 💚
https://www.hivesystems.com/password
A whistleblower who worked for Morocco’s Direction Générale de la Surveillance du Territoire (DGST) suggests the country’s internal security services began using Pegasus in 2017 and went on to deploy it against domestic and foreign targets over four years.
https://www.
The EU blacklists Russian intelligence group members it says were responsible for spying on and hacking targets across the EU and Ukraine from as early as 2010 (Politico)
https://www.politico.eu/article/eu-sanctions-russian-cyber-spies-for-years-long-…
Our paper “User-space library rootkits revisited: Are user-space detection mechanisms futile?” has been accepted for publication in The Journal of Computer Virology and Hacking Techniques (Springer-Nature) 🦠
Now playing while hacking your shit..
Namakopuri & Us Cracks - Ponpon Shit (Cyberpunk 2077 OST)
https://www.youtube.com/watch?v=J9WSl6BTfns
'ClickFix' attack tricks users into hacking themselves, ACSC warns:
"Verify that you are human" prompt used to deliver Vidar Stealer malware.
The Australian Cyber Security Centre (ACSC) has stepped in to warn users of an active attack campaign targeting Windows users with Vidar Stealer malware, which is delivered through the so-called ClickFix social engineering technique.
🤷
"Hackers have breached tank readers at US gas stations; officials suspect Iran"
See, gas prices aren't really high. Iran has hacked all the signs in every gas station across USA to show higher gas prices and make the administration look bad.
#hacking #gasPrices #sarcasm
Never, ever, is there a slow day in cybersecurity, so don't miss today's Metacurity for the crucial developments you should know, including
--Hackers post alleged blueprints and supplier data from India nuclear project,
--TfL hackers sentenced to 5½ years in prison,
--Hacking suspect once worked at Kaspersky,
--OpenAI unveils AI-powered red teaming tool,
--Ransomware attack disrupts Japan’s food supply chain,
--Qantas cleared after social-engineeri…
Russia’s top secret spy school teaching hacking and election meddling
Documents obtained by consortium of journalists show role of Moscow university in training operatives in military intelligence
The existence of this path, from one of Russia’s most prestigious institutions directly into its military intelligence apparatus, is revealed for the first time in more than 2,000 internal documents from Bauman,
obtained by a consortium of journalists from six outlets: the Guardia…
Prince Harry and six other prominent figures face an up to £50M legal bill after losing their phone-hacking case against Daily Mail owner Associated Newspapers (Michael Savage/The Guardian)
https://www.theguardian.com/media/2026/jul/07/p…
from my link log —
Can we trust Microsoft with Open Source?
https://dusted.codes/can-we-trust-microsoft-with-open-source
saved 2021-10-23
APT37 has posed as police investigators, defense officials and North Korea experts in spear phishing attacks targeting South Korean security and policy figures
https://www.upi.com/Top_News/World-News/20
Wild (long) piece about hacking superyachts. Which I think should always be done. Fuck the rich assholes with these.
https://thewalrus.ca/how-to-hack-a-superyacht
Also, it will always amuse me that the acronym they use for the Russian Soviet era Global Navigation Satellite Sy…
Researchers detail "context bombing", where defenders use prompt injections to trigger guardrails of attackers' LLMs, cutting AI hacking success rates by ~90% (Dan Goodin/Ars Technica)
https://arstechnica.com/security/2026/07/now-d…
«Überwachung — Bestätigt: Microsoft versieht jedes Windows-System mit eindeutiger ID:
Der GDID wurde nun in einem Verfahren gegen eine Hacking-Gruppe als Beweis herangezogen. In Kombination mit anderen gesammelten Daten lässt diese viele Rückschlüsse zu»
Wann begreiffen die Leute / Firmen endlich, dass sie das Produkt von Microsoft sind und nicht ihre marketing technisch aufgedrungene Software? Denn auf Windows haben User kein Durchblick.
😑
I still think it's a good idea to replace «LLM» and «AI» with «cocaine». I can't remember where I picked this up, but the stories make much more sense.
«Cocaine-powered hacking has exploded into industrial-scale threat, Google says»,
«Cocaine to Cognitive Agents : How Cocaine Gains Memory, Planning and Autonomy»
just try it for a day, it'll cheer you up.
The signal-to-noise ratio when it comes to identifying bugs is already insane even without Mythos-level vulnerability scanning.
‘Never-ending’ AI slop strains corporate hacking reward schemes
https://www.ft.com/content/dbec4441-02dc-4053-8500-85677973d3…
Government Hacking Tools Are Now in Criminals' Hands (with Lorenzo Franceschi-Bicchierai) https://www.404media.co/government-hacking-tools-are-now-in-criminals-hands-with-lorenzo-franceschi-bicchierai/
Not good. "Canvas Online Learning Platform Disabled After Breach by Hackers"
"A hacking group that claimed responsibility for attacking Canvas’s parent company said it had gained access to data from more than 275 million people across 9,000 schools."
Both my kids are affected, one in HS, the other in college. My eldest had a final tomorrow which is now optimistically rescheduled for Sunday.
Gift article 🎁
More eyes on the story. This time from a different angle. We Treated Potholes Like Software Bugs and Accidentally Built a Civic Hacking Playbook.
https://hackernoon.com/we-treated-potholes-like-software-bugs-and-accidentally-buil…
from my link log —
Hacking time: spoofing “atomic” radio time broadcasts with audio harmonics.
https://josephhall.org/blog/texture-of-time-wwvb/
saved 2026-05-09
Google says a Chinese-linked hacking group targeted US and Canadian academic, medical, and military research institutions from September 2023 to November 2025 (A.J. Vicens/Reuters)
https://www.reuters.com/legal/litigation/c
The Scattered Spider TfL hackers were each sentenced to five years and six months' imprisonment.
https://www.nationalcrimeagency.gov.uk/news/two-sentenced-for-hacking-transport-for-london-in-uk-s-biggest-ever…
LMAO! Some heads will roll. Or Ukrainian hacking did it again. Or both.
(link to nitter)
https://nitter.net/bayraktar_1love/status/2064360763662172394#m
inb4 the first person gets arrested for using an unlicensed hacking model. See y'all on the other side of Sundevil 2.0
Noch ein paar der zuletzt hier besonders häufig geteilten #News:
Bundespolizei: Koalition bahnt Weg für KI-Echtzeitfahndung und Staatstrojaner
Anthropic's Mythos AI model sparks fears of turbocharged hacking:
Cyberdefenses could be exposed faster than fixes could be deployed.
Anthropic’s new Mythos AI model is raising concern among governments and companies that it could outpace current cyber security defenses, turbocharge hacking, and expose weaknesses faster than they can be fixed.
🔓
Fulcrumsec claims major hack of Novo Nordisk and attempted $25 million extortion
https://www.reuters.com/legal/government/hacking-group-claims-major-hack-novo-nordisk-attempted-25-million-extortion-2026-06-16/
Some days the challenge isn't the code but the tools that build the code.... #buildsystem #hacking
The files, covering several years of activity up to 2025, include course syllabuses, exam records, staff contracts and the career assignments of individual graduates, tracing their path from classroom exercises in hacking and disinformation to postings in some of the most notorious cyber-units in the Russian military intelligence apparatus.
I love this, from @… : 'In their discussions of hacking, building, and making, we see that DH scholars do not generally seek to convey simple technological skills, but instead to cultivate technological imagination. Specific platforms, applications, and even coding languages come and go, but a technological imagination is able to abstract a problem—wh…
Ex-Daily Mail editor Paul Dacre calls Prince Harry's phone hacking case a "conspiracy" to destroy the Mail and the verdict is a "vindication" of its journalism (Alice Brooker/Press Gazette)
https://pressgazette.co.uk/news/paul-d
„868-BACK“ angespielt: Digitales Brettspiel zum Selberhacken
Die Fortsetzung des Hacking-Kultspiels „868-BACK“ ist da. „868-BACK“ bietet komplexe Rundenstrategie auf kleinstem Raum mit kryptischen Regeln.
https:/…
Am Freitag, dem 8. Mai ab 15:45 Uhr geht das C3WTF (= @… CTF) in die nächste Runde, diesmal an der TU Wien, für alle interessierten Wesen. Wie bisher wollen wir gemeinsam kleine IT-Security Challenges aus diversen Richtungen lösen, von Forensik zu Hacking zu Kryptographie zu allem, was uns sonst noch einfällt. Das Level wird möglichst einstiegsfreundlich sein. Wenn …
It being an astonishingly beautiful afternoon here, instead of sitting indoors hacking #Lisp, I am out in the wood with my pussy cat hauling out timber for the sawmill.
It's a hard life.
#TheJoyOfCrofting (unironically, for once)
Oracle warns customers of a critical PeopleSoft flaw after ShinyHunters claimed breaches of 100 organizations using PeopleSoft; Oracle has not issued a patch (Lorenzo Franceschi-Bicchierai/TechCrunch)
https://techcrunch.com/2026/06/11/orac
The US Department of Justice had sought Xu on suspicion of stealing Covid-19 research and hacking charges, alleging he was directed to conduct the operations at the behest of the Chinese government
Italy Decides to Extradite Chinese Man US Wants for Hacking
https://www.
En fin summering av funktionsmedicinen tillsammans med en väldigt snygg och totalt sågande genomgång av en av få studier som har utförts på konceptet
https://www.cremieux.xyz/p/one-weird-trick-to-get-significant
A UK Border Force officer and Hong Kong trade official based in London have been found guilty of spying for China and surveilling dissidents through a “shadow policing” operation.
https://www.theguardian.com/world/2026/may
Einige der zuletzt hier besonders häufig geteilten #News:
Bundespolizei: Koalition bahnt Weg für KI-Echtzeitfahndung und Staatstrojaner
Trying the macOS app Shortcut to replace mouse usage -- you can keep your hands on your keyboard and navigate all the clicking and such:
https://shortcat.app/
I am really liking this. I have an Ultimate Hacking Keyboard, so I can bind a convenient key to launch it and it works really well. This is nice.
Immigration and Customs Enforcement (ICE) contracted with a spyware company that tells customers
it ensures they can use the tool without the agency being caught doing so.
In September, we sued ICE for documents related to its $2 million contract with Paragon,
a company that makes powerful spyware for remotely hacking phones
and accessing encrypted messaging apps.
In response to the lawsuit we’ve now been given the first batch of documents by ICE,
but hav…
Court records: federal prosecutors have prolonged an appeal in former Deadspin editor Timothy Burke's criminal hacking case, leaving him in legal limbo (Matthew Keys/TheDesk.net)
https://thedesk.net/2026/06/timothy-burke-case-prosecutors-delay-appe…
Bluesky and Clemson researchers detail a novel Russian influence campaign that hijacked legitimate, influential accounts to spread pro-Kremlin propaganda (Steven Lee Myers/New York Times)
https://www.nytimes.com/2026/…
Bluesky Says Kremlin Is Hacking Its Platform to Spread Propaganda
https://www.nytimes.com/2026/05/21/business/bluesky-russia-hacking-accounts.html?smtyp=cur&smid=bsky-nytimes
The security industry is somewhat unique. It's probably the only industry created by the worker as a threat. If you talk to hackers who were in the scene before Operation Sundevil, you'll realize that it's always been a Bullshit Job.
Folks in L0ft and cDc were hacking companies and basically blackmailing them into paying for their services. Operation Sundevil "straightened up" the industry. Some people went to prison, some people build security services companies. Pretty much anyone who actually believed in the manifesto was locked up or edged out.
Using the Graeber framework here, hackers are partially duct tapers and partially goons. The critical thing here is that the industry was basically created to give money to people who would otherwise destroy the system.
Neuroatypical folks have always been forced to the margins of society, but computers gave us a super power. Now we were extremely dangerous. Tech, especially hackers, have always been paid a lot to minimize the risk of developing a class consciousness.
Graeber talked about this. Kings and nobles would often find some job or title that they could bestow on potential enemies in order to keep them close, to defang them. What better role than sheriff, a type of goon, for a rebel?
We turned it in to a whole thing. Not only did hackers make their own industry and force everyone else to accept it, we even created a whole parallel box ticker industry of "compliance" as a side effect.
The Hacker's Manifesto was decontectualized and made a fun artifact of the past. We were sold a story of "good hackers" who "protected grandma from the bad hackers." But the whole industry always existed to keep us on a leash. The funny thing is that it was a leash that we made ourselves.
But now we're seeing massive layoffs in tech, even in security. Now that we're this far in, everyone has forgotten the history. Leadership doesn't understand what security people do, so they think that LLMs can replace us. But the people in the industry now, the ones who came to it as a career, don't understand the history.
There was always a split for these weird outsiders, these people who couldn't fit in to the system but now had power over it. Some wanted in and they were willing to use extortion to get in, and others wanted to destroy the system to set everyone free.
Operation Sundevil, and the industry that evolved out of it, existed to neutralize those revolutionary elements by offering extortionists a safe entry. Extortionists trusted the capitalists to not stab them in the back the same way capitalists have stabbed everyone in the back through all of history. Now my LinkedIn feed is full of Meta layoffs, and I wonder if that class consciousness is starting to click for anyone yet.
Vibecoding #Malware Fuels a New Wave Of Stealth Attacks
Vibe coding’s dark side, “vibe hacking,” is on the rise. #Cybersecurity companies such as McAfee and Bitdefender have observed recent spikes in vibe-coded malware, also called “
Today's Metacurity returns to our "AI watch format" with a summary of crucial AI developments followed by a slew of other infosec news stories cyber leaders and defenders need to know, including
--Canada details offensive cyber ops,
--US cloud providers challenge Korean security rules,
--KDDI confirms breach affecting millions,
--Judge keeps Weiss hacking case alive,
--BonkDAO loses $20m in governance attack,
--Crypto wallet flaw exposed milli…
A group of unauthorized users has reportedly gained access to #Mythos, the cybersecurity tool recently announced by #Anthropic.
Much has been made of Mythos and its purported power — an AI product designed for enterprise security that,
in the wrong hands, could become a potent hacking tool, according to the …
Staff at the Cybersecurity and Infrastructure Security Agency said they’re not able to use the latest models from Anthropic and OpenAI, impeding their ability to protect critical U.S. infrastructure.
https://www.forbes.com/sites/thomasbrewste
EU sanctions Russian GRU military hackers over cyberattacks
https://www.bleepingcomputer.com/news/security/eu-and-uk-hit-russia-with-first-joint-cyber-sanctions-package/
Every day, I see a new Iran state-sponsored media report that says Handala engaged in some kind of concerning hack.
Today, it's been reported that the group leaked details on 400 senior Navy officers currently working in the Persian Gulf that it obtained during a hacking operation it calls "Early Death."
This WANA piece shows an excerpt from the leak that looks legit, but without vetting, I'm not going to include it in today's Metacurity.
Just know th…
Microsoft's Digital Crimes Unit says AI helped it link two separate hacking tools, Amadey and StealC, and file a single civil lawsuit to take them down (Lorelei Smillie/Bloomberg)
https://www.bloomberg.com/news/newsletters
Stay ahead of the curve by checking out today's Metacurity for the most important infosec developments you should know, including
--Five Eyes issues unusual warning on China's online recruitment tactics,
--Meta AI's chatbot hacking seems to have continued,
--OpenAI asks for mandatory models' evaluations,
--CISA to release AI directive tomorrow,
--Mullin wants CISA to hire 600 more personnel,
--Hackers accessed Ultrahuman's customer data…
Sources: the Pentagon is launching a task force to study how to safely deploy leading AI tools with hacking capabilities across Cyber Command and NSA missions (Politico)
https://www.politico.com/news/2026/05/20/nsa-cyber-command-ai-task-force-mythos-0…
So little time, so many cybersecurity developments to cover. Check out today's Metacurity for the most important infosec news stories today, including
--Frontier AI Beat: AI security becomes a geopolitical arms race,
--Microsoft uses AI to link malware groups in RICO case,
--Ukraine exposes Russian messenger hacking,
--Nation-state hackers mapped CI for sabotage,
--DPRK-linked election attacks surge 68-fold,
--DraftKings hacker 'Snoopy' gets 18 m…
Take a leisurely scan of today's Metacurity to check out the top infosec developments you should know, including
--Ransomware negotiator cops to conspiring with cybercrims against US companies,
--NSW official charged in data breach involving sensitive documents,
--UK man faces 22 years in US prison for $8m hacking scheme,
--Hack of French government identity website might have exposed users' data,
--Bundesbank pres. wants level playing field for Mythos, L…
Hackers are still exploiting the cPanel bug to gain control of thousands of websites
https://techcrunch.com/2026/05/04/hackers-are-still-exploiting-the-cpanel-bug-to-gain-control-of-thousands-of-websites/
On its Telegram channel, they wrote: ‘Today, merely as a demonstration, and to prove the extent of our intelligence superiority, we have published the full personal details of 2,379 U.S. Marines stationed in the Persian Gulf region.
https://metro.co.uk/2026…
Korean cops arrested 32 members of an international hacking group that hacked BTS’s Jung Kook and 271 other prominent individuals.
https://www.chosun.com/english/national-en/2026/05/21/SFJYUM3HZBHHXFYOIMOOP5AURM/
"The Pentagon’s cyber-warfighting arm is launching a task force to speed up the adoption of cutting-edge artificial intelligence tools with powerful hacking capabilities, according to three people with knowledge of the effort."
https://www.politico.com/news/2026/05/20/n