The best hacker and cyber security news. Contact us on
Aug 27, 2026
Photo by Pawel Czerwinski on Unsplash
Shortly after loading the AliExpress homepage, audio from my phone would stop playing. Closing the AliExpress tab fixes it immediately. Muting the tab/Firefox/Windows does not help, and there is no visible video, music, or other media playing on the page.
Source: blog.laserphile.com
Aug 27, 2026
We dive into the decentralized architecture of “The Com,” exposing its hybrid ecosystem of hacking, extortion, and real-life violence. The Community, more widely known as “The Com” is a sophisticated hybrid threat ecosystem in which cybercrime serves as the venture capital for domestic terrorism. Existing since the early 2010s, it operates in the “edgesphere”, a grey area where mainstream social media overlaps with underground criminal networks, blending nihilistic violent extremism (NVE) with high-level financial fraud. In The Com, cybercrime against Fortune 500 companies is the primary revenue stream used by members to fund a domestic terror network that aims to radicalize youth and encourage real-world violence.
Aug 27, 2026
Photo by Boitumelo on Unsplash
An estimated 4 340 URLs related to nihilistic violent extremism were referred during the initiative organised by Europol’s EU Internet Referral Unit - EU IRU and the Spanish Intelligence Centre against Terrorism and Organised Crime (CITCO). This successful action complements the efforts undertaken within Project COMPASS, coordinated by Europol’s European Counter Terrorism Centre, which unites law enforcement authorities from EU…
Source: europol.europa.eu
Aug 27, 2026
The FBI is warning the public about Hacker Com, one of three subsets of the growing and evolving online threat group known as The Com, short for The Community, a primarily English speaking, international, online ecosystem comprised of multiple interconnected networks whose members, many of whom are minors, engage in a variety of criminal violations.
Source: fbi.gov
Aug 23, 2026
Photo by Luca Cavallin on Unsplash
Security researchers found that in less than 60 seconds, they could open a hatch on a plane’s exterior, plug in a tiny device, and redirect the aircraft’s autopilot or sabotage its flight plan. Even as the digital components of so many life-critical systems have proven susceptible to cybersabotage—cars, medical devices, even water utilities and power grids—the computer systems of airplanes have, thankfully, remained uniquely inaccessible to hackers. But one group of academic researchers has spent years testing a different, devious approach to aviation cybersecurity. Perhaps, they suggest, a plane could be hacked the same way that spies and saboteurs have targeted other high-value, offline computers: by surreptitiously gaining physical access to one and plugging in a device designed to silently run the attackers’ malicious code.
Aug 21, 2026
The Memorandum directs agencies to incentivize co-development of space transportation infrastructure with private sector partners, expedite permitting and environmental reviews, develop fair and transparent cost recovery policies for common space services and infrastructure, and develop range scheduling criteria and publish range schedules to maximize allocation of launch resources.
Source: whitehouse.gov
Aug 21, 2026
On August 18th, 2026, a data release occurred on the illicit forum pwnforums. The threat actor known as Satanic published sensitive information extracted from hundreds of vendors utilizing the Stripe payment platform. Figure 1: The initial forum post by Satanic announcing the breach, detailing the compromise of databases and 1,033 API keys, totaling 33GB, along with millions of email matches. Satanic is a known entity within the cybercrime ecosystem, previously verified by Hudson Rock researchers for their involvement in large-scale breaches. We previously documented their activities in the Hot Topic breach. Satanic is a known entity within the cybercrime ecosystem, previously verified by Hudson Rock researchers for their involvement in large-scale breaches. We previously documented their activities in the Hot Topic breach.
Aug 21, 2026
Cybersecurity researchers from TU Graz have disclosed a highly sophisticated Remote-Timer-as-a-Service side-channel execution flaw against serverless edge environments. In a controlled production test, this cloudflare workers spectre attack (a modern evolution of the foundational CVE-2017-5753 Spectre flaw) successfully leaked a JSON Web Token (JWT) from a co-located Worker at an astonishing rate of 12 bits per second (at 99.16% accuracy)—nearly 360 times faster than similar attacks demonstrated in 2021.
Aug 13, 2026
The Connective signing extension, used by 8 of the 10 largest banks in Belgium and 60+ government agencies, let any website read your eID and Maestro cards, recover your eID PIN, and trigger a drive-by RCE. All the victim sees is a file download.
Source: amibeingpwned.com
Aug 13, 2026
So…what’s going on at HackerOne lately? It might be time for a wellness check. If you are new to the bug bounty space (1-3 years), you might not have any idea what I’m talking about. But as a properly washed-up bug bounty hunter who lived through the golden era of HackerOne, I think it’s time to address the elephant in the room. For some context, I started as a hacker on HackerOne in 2017. When I began working in tech, that hands-on experience was extremely useful for managing a bug bounty program, since I knew what researchers wanted, and how to interact with them.