Welcome to Indigodefense!

The best hacker and cyber security news. Contact us on LinkedIn for cyber security services.

Latest posts

Aug 13, 2026

8 out of 10 Banks in Belgium HATE This One Weird eID RCE

Headline image

The Connective signing extension, used by 8 of the 10 largest banks in Belgium and 60+ government agencies, let any website read your eID and Maestro cards, recover your eID PIN, and trigger a drive-by RCE. All the victim sees is a file download.

Source: amibeingpwned.com

Aug 13, 2026

What Happened to HackerOne?

Headline image

So…what’s going on at HackerOne lately? It might be time for a wellness check. If you are new to the bug bounty space (1-3 years), you might not have any idea what I’m talking about. But as a properly washed-up bug bounty hunter who lived through the golden era of HackerOne, I think it’s time to address the elephant in the room. For some context, I started as a hacker on HackerOne in 2017. When I began working in tech, that hands-on experience was extremely useful for managing a bug bounty program, since I knew what researchers wanted, and how to interact with them.

Aug 13, 2026

Chinese Router Backdoor Opens Root Access on 100,000 Devices Worldwide

Headline image Photo by Towfiqu barbhuiya on Unsplash

Jacob Baines, chief technology officer at security firm VulnCheck, said more than 20 models of Chinese-made Zbtlink routers ship with a hidden backdoor that hands outsiders a route onto the local network, in a finding published August 5. The implant, named ENDLESSDOORS and tracked as CVE-2026-66747 with a severity score of 9.3 out of 10, starts at boot and beacons to a fixed address and a China-registered domain as often as every 35 seconds. Whoever controls those endpoints can issue commands and open a root shell, the highest level of control on the device.

Jul 28, 2026

Iran APT Sabotages US PLCs: CISA Warns of Physical Risk

Headline image

The US government discloses an Iranian APT compromising internet-exposed PLCs in water and energy facilities, disabling safety logic to cause potential… The escalation is assessed as a direct response to geopolitical tensions among Iran, the United States, and Israel. The shift from public defacement in 2023 to silent sabotage of industrial control systems marks an operational turning point with potentially physical consequences. The actors gain initial access by exploiting PLCs and OT devices directly exposed on the internet. The advisory identifies five specific ports: 44818, 2222, 102, 502 for industrial protocols, plus port 22 for SSH modems. This exposure, typical of architectures that assume “security by obscurity,” eliminates any intermediary: the attacker interacts directly with the controller.

Jul 28, 2026

DNS Poisoning Tactics Expand to Hospitality Wi-Fi

Headline image Photo by Misha Feshchak on Unsplash

Adversaries have been compromising public Wi-Fi gateways at hotels, conference centers, and other shared venues to hijack the accounts of traveling corporate employees. Once they control the Wi-Fi gateway, they quietly redirect users to attacker-controlled infrastructure to steal credentials, in activity ongoing since at least June 2026.ReliaQuest assesses this tradecraft is similar to that of “APT28” (also known as “Fancy Bear” and “Forest Blizzard”), a Russian military intelligence group that was previously linked to similar router-based campaigns compromising Microsoft 365 accounts.Organizations can close the primary exposure with one control: enforce always-on, full-tunnel VPN on corporate devices. This routes all traffic—including DNS—through the corporate network before it ever reaches the hotel gateway, effectively stopping the attack.

Jul 28, 2026

There Are Thousands of Inventions the Government Doesn’t Want You to See. A Shady Law Is Hiding Them.

Headline image

A Cold War-era law called the Invention Secrecy Act of 1951 allows U.S. government agencies to suppress patents deemed threats to national security, fueling decades of conspiracy theories about hidden world-changing inventions like the legendary “water engine.”The Invention Secrecy Act lacks clear accountability measures and vaguely defines what constitutes “national security,” making it theoretically possible for the government to suppress inventions to protect corporate interests, though no credible evidence proves this has occurred.In fiscal year 2025 alone, over 6,500 patents were subjected to secrecy orders under the act—more than half the total suppressed during all of World War II—raising questions about whether the government is applying the law too broadly.

Jul 15, 2026

Microsoft’s Secure Boot has been broken for a decade and no one noticed until now

Headline image

An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, that were known to be defective but remained signed by the software company anyway. The images are known as shims, which were invented to extend Secure Boot to Linux devices and utility software. Using a technique simple enough to be performed by novice hackers, these old, forgotten shims can be used to completely circumvent the protection, which is embedded into the UEFI (Unified Extensible Firmware Interface) of the device’s motherboard. The gaffe is the result of the failure by Microsoft, which oversees the signing of shims, to revoke the publicly available images once vulnerabilities were found in them.

Jul 15, 2026

Microsoft Confirms Windows GDID Device Identifier That Cannot Be Disabled, Documented in FBI Case Filing

Headline image

Microsoft has confirmed the existence of a persistent Windows device identifier called GDID, first publicly detailed in an FBI federal complaint against an alleged hacker. Microsoft has publicly acknowledged the existence of the Global Device Identifier (GDID), a device-specific ID assigned to Windows installations, in a federal complaint filed by US prosecutors against an alleged member of the Scattered Spider hacking group. The ID is generated when Windows is set up with a Microsoft Account, persists through Windows updates, and cannot be disabled without affecting Windows activation and Microsoft Store apps.

Jun 30, 2026

Nearly a million passports and photo IDs were left unprotected on the public internet

Headline image

Cannabis Club Systems, also known as Nefos Solutions, left passports and photo IDs potentially exposed on the public web.Nearly a million passports and photo IDs were left unprotected on the public internetThis should be a wakeup call for data security.

Source: theverge.com

Jun 29, 2026

US offers $10 million for info on group behind Signal and WhatsApp hacking spree

Headline image

Federal authorities are offering a reward of up to $10 million for information leading to the identification or location of a Russian state cyber group that has compromised thousands of Signal and WhatsApp accounts belonging to investigative reporters and US government employees.

Source: arstechnica.com