Posts


Aug. 13, 2026

8 out of 10 Banks in Belgium HATE This One Weird eID RCE

Headline image

The Connective signing extension, used by 8 of the 10 largest banks in Belgium and 60+ government agencies, let any website read your eID and Maestro cards, recover your eID PIN, and trigger a drive-by RCE. All the victim sees is a file download.

Source: amibeingpwned.com

Aug. 13, 2026

What Happened to HackerOne?

Headline image

So…what’s going on at HackerOne lately? It might be time for a wellness check. If you are new to the bug bounty space (1-3 years), you might not have any idea what I’m talking about. But as a properly washed-up bug bounty hunter who lived through the golden era of HackerOne, I think it’s time to address the elephant in the room. For some context, I started as a hacker on HackerOne in 2017. When I began working in tech, that hands-on experience was extremely useful for managing a bug bounty program, since I knew what researchers wanted, and how to interact with them.

Aug. 13, 2026

Chinese Router Backdoor Opens Root Access on 100,000 Devices Worldwide

Headline image Photo by Towfiqu barbhuiya on Unsplash

Jacob Baines, chief technology officer at security firm VulnCheck, said more than 20 models of Chinese-made Zbtlink routers ship with a hidden backdoor that hands outsiders a route onto the local network, in a finding published August 5. The implant, named ENDLESSDOORS and tracked as CVE-2026-66747 with a severity score of 9.3 out of 10, starts at boot and beacons to a fixed address and a China-registered domain as often as every 35 seconds. Whoever controls those endpoints can issue commands and open a root shell, the highest level of control on the device.

Jul. 28, 2026

Iran APT Sabotages US PLCs: CISA Warns of Physical Risk

Headline image

The US government discloses an Iranian APT compromising internet-exposed PLCs in water and energy facilities, disabling safety logic to cause potential… The escalation is assessed as a direct response to geopolitical tensions among Iran, the United States, and Israel. The shift from public defacement in 2023 to silent sabotage of industrial control systems marks an operational turning point with potentially physical consequences. The actors gain initial access by exploiting PLCs and OT devices directly exposed on the internet. The advisory identifies five specific ports: 44818, 2222, 102, 502 for industrial protocols, plus port 22 for SSH modems. This exposure, typical of architectures that assume “security by obscurity,” eliminates any intermediary: the attacker interacts directly with the controller.

Jul. 28, 2026

DNS Poisoning Tactics Expand to Hospitality Wi-Fi

Headline image Photo by Misha Feshchak on Unsplash

Adversaries have been compromising public Wi-Fi gateways at hotels, conference centers, and other shared venues to hijack the accounts of traveling corporate employees. Once they control the Wi-Fi gateway, they quietly redirect users to attacker-controlled infrastructure to steal credentials, in activity ongoing since at least June 2026.ReliaQuest assesses this tradecraft is similar to that of “APT28” (also known as “Fancy Bear” and “Forest Blizzard”), a Russian military intelligence group that was previously linked to similar router-based campaigns compromising Microsoft 365 accounts.Organizations can close the primary exposure with one control: enforce always-on, full-tunnel VPN on corporate devices. This routes all traffic—including DNS—through the corporate network before it ever reaches the hotel gateway, effectively stopping the attack.

Jul. 28, 2026

There Are Thousands of Inventions the Government Doesn’t Want You to See. A Shady Law Is Hiding Them.

Headline image

A Cold War-era law called the Invention Secrecy Act of 1951 allows U.S. government agencies to suppress patents deemed threats to national security, fueling decades of conspiracy theories about hidden world-changing inventions like the legendary “water engine.”The Invention Secrecy Act lacks clear accountability measures and vaguely defines what constitutes “national security,” making it theoretically possible for the government to suppress inventions to protect corporate interests, though no credible evidence proves this has occurred.In fiscal year 2025 alone, over 6,500 patents were subjected to secrecy orders under the act—more than half the total suppressed during all of World War II—raising questions about whether the government is applying the law too broadly.

Jul. 15, 2026

Microsoft’s Secure Boot has been broken for a decade and no one noticed until now

Headline image

An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, that were known to be defective but remained signed by the software company anyway. The images are known as shims, which were invented to extend Secure Boot to Linux devices and utility software. Using a technique simple enough to be performed by novice hackers, these old, forgotten shims can be used to completely circumvent the protection, which is embedded into the UEFI (Unified Extensible Firmware Interface) of the device’s motherboard. The gaffe is the result of the failure by Microsoft, which oversees the signing of shims, to revoke the publicly available images once vulnerabilities were found in them.

Jul. 15, 2026

Microsoft Confirms Windows GDID Device Identifier That Cannot Be Disabled, Documented in FBI Case Filing

Headline image

Microsoft has confirmed the existence of a persistent Windows device identifier called GDID, first publicly detailed in an FBI federal complaint against an alleged hacker. Microsoft has publicly acknowledged the existence of the Global Device Identifier (GDID), a device-specific ID assigned to Windows installations, in a federal complaint filed by US prosecutors against an alleged member of the Scattered Spider hacking group. The ID is generated when Windows is set up with a Microsoft Account, persists through Windows updates, and cannot be disabled without affecting Windows activation and Microsoft Store apps.

Jun. 30, 2026

Nearly a million passports and photo IDs were left unprotected on the public internet

Headline image

Cannabis Club Systems, also known as Nefos Solutions, left passports and photo IDs potentially exposed on the public web.Nearly a million passports and photo IDs were left unprotected on the public internetThis should be a wakeup call for data security.

Source: theverge.com

Jun. 29, 2026

US offers $10 million for info on group behind Signal and WhatsApp hacking spree

Headline image

Federal authorities are offering a reward of up to $10 million for information leading to the identification or location of a Russian state cyber group that has compromised thousands of Signal and WhatsApp accounts belonging to investigative reporters and US government employees.

Source: arstechnica.com

Jun. 26, 2026

Going Through Snowden Documents, Part 7

Headline image Photo by Lianhao Qu on Unsplash

In December 2014, Der Spiegel published one of the most significant articles in the Snowden archive, exposing the scale of NSA and GCHQ efforts to break encryption and compromise encrypted communications. The article was accompanied by 44 supporting documents. One of those documents contains a previously unreported redaction failure that we believe is the most significant in any Snowden publication to date.

Source: libroot.org

Dec. 10, 2020

Hackers steal Pfizer/BioNTech COVID-19 vaccine data in Europe, companies say

Hackers steal Pfizer/BioNTech COVID-19 vaccine data in Europe, companies say

U.S. drugmaker Pfizer and its German partner BioNTech said on Wednesday that documents related to development of their COVID-19 vaccine had been ‘unlawfully accessed’ in a cyberattack on Europe’s medicines regulator. The European Medicines Agency (EMA), which assesses medicines and vaccines for the European Union, said hours earlier it had been targeted in a cyberattack. It gave no further details.

Dec. 2, 2020

iPhone zero-click Wi-Fi exploit is one of the most breathtaking hacks ever

iPhone zero-click Wi-Fi exploit is one of the most breathtaking hacks ever

Earlier this year, Apple patched one of the most breathtaking iPhone vulnerabilities ever: a memory corruption bug in the iOS kernel that gave attackers remote access to the entire device—over Wi-Fi, with no user interaction required at all. Oh, and exploits were wormable—meaning radio-proximity exploits could spread from one nearby device to another, once again, with no user interaction needed. This Wi-Fi packet of death exploit was devised by Ian Beer, a researcher at Project Zero, Google’s vulnerability research arm.

Nov. 11, 2020

179 Arrested in Massive Global Dark Web Takedown

179 Arrested in Massive Global Dark Web Takedown

Operation Disruptor has led to a wave of arrests and seizures, but the dark web drug market has bounced back before. It’s one of the largest global dark web takedowns to date: 179 arrests spread across six countries; 500 kilograms of drugs seized; $6.5 million in cash and cryptocurrency confiscated. And while it was announced this morning, Operation Disruptor traces its roots back to May 3, 2019.

Nov. 8, 2020

FBI: Hackers stole source code from US government agencies and private companies

FBI: Hackers stole source code from US government agencies and private companies

The Federal Bureau of Investigation has sent out a security alert warning that threat actors are abusing misconfigured SonarQube applications to access and steal source code repositories from US government agencies and private businesses. US officials talk about all the methods the Chinese government and its agents have been using to target US companies and universities to steal intellectual property. Intrusions have taken place since at least April 2020, the FBI said inan alertsent out last month and made public this week on its website.

Nov. 7, 2020

Company forced to change name that could be used to hack websites

Company forced to change name that could be used to hack websites

Companies House has forced a company to change its name after it belatedly realised it could pose a security risk. The company now legally known as “THAT COMPANY WHOSE NAME USED TO CONTAIN HTML SCRIPT TAGS LTD” was set up by a British software engineer, who says he did it purely because he thought it would be “a fun playful name” for his consulting business.

Nov. 3, 2020

Fault in NHS Covid app meant thousands at risk did not quarantine

Fault in NHS Covid app meant thousands at risk did not quarantine

A code error in the NHS Covid-19 app meant users had to be next to a highly infectious patient for five times as long as the NHS had decided was risky before being instructed to self-isolate, the Guardian has learned.

Source: theguardian.com

Oct. 16, 2020

Hacked Billboards Can Make Teslas See ‘Phantom Objects,’ Causing Them to Swerve or Stop Abruptly

Hacked Billboards Can Make Teslas See ‘Phantom Objects,’ Causing Them to Swerve or Stop Abruptly

Tesla’s Autopilot system relies on vision rather than LIDAR, which means it can be tricked by messages on billboards and projections created by hackers. Security researchers have demonstrated how Tesla’s Autopilot driver-assistance systems can be tricked into changing speed, swerving or stopping abruptly, simply by projecting fake road signs or virtual objects in front of them. Their hacks worked on both a Tesla running HW3, which is the latest version of the company’s Autopilot driver-assistance system, and the previous generation, HW2.5.

Sep. 25, 2020

FritzFrog: A New Generation of Peer-to-Peer Botnets written in Go

FritzFrog: A New Generation of Peer-to-Peer Botnets written in Go

Guardicore has discovered FritzFrog, a sophisticated peer-to-peer (P2P) botnet which has been actively breaching SSH servers since January 2020. Golang-Based Malware: FritzFrog executes a worm malware which is written in Golang, and is modular, multi-threaded and fileless, leaving no trace on the infected machine’s disk. Actively Targeting Government, Education, Finance and more: FritzFrog has attempted to brute force and propagate to tens of millions of IP addresses of governmental offices, educational institutions, medical centers, banks and numerous telecom companies.

Sep. 25, 2020

Attack of the week: Voice calls in LTE

Attack of the week: Voice calls in LTE

I haven’t written an “attack of the week” post in a while, and it’s been bumming me out. This is not because there’s been a lack of attacks, but mostly because there hasn’t been an attack on something sufficiently widely-used that it can rouse me out of my blogging torpor. But today brings a beautiful attack called ReVoLTE, on a set of protocols that I particularly love to see get broken: namely, cellular protocols.