Hacking a $6000 Cotton Candy Machine to Fully Control It


The media in this post is not displayed to visitors. To view it, please log in.

Having a fully automated cotton candy vending machine in your possession is a great thing, but not if you do not have full access to its software. With [Block’s Retro Repairs] getting ghosted by the manufacturer on regaining account access to the machine he bought used for $300, there was little left but to try and break into the system.

We previously covered the journey in getting the vending machine back into a state where it’d actually reliably produce cotton candy again, a process which is quite tedious and temperamental. After a lot of fiddling with sensors and temperature settings this was fixed, but still left the issue that as a vending machine it should allow the owner to set prices and such. Sadly this could only be done remotely via a special account, which access to had been left with the previous owner.

Despite the very custom exterior, the vending machine runs what is effectively an Android system, consisting of an industrial computer board wired into a lot of stepper drivers and other control boards. To the extreme delight of everyone involved, it was possible to access the Ct Terminal application with adb and its product database on the device’s storage. Unfortunately writing back a changed database file didn’t change anything in the UI, so for a few months the project languished.

After nearly bricking the system and ending up factory resetting the control software including temperatures, it actually improved the performance of the machine and produced cotton candy, so that was one win. Ultimately the solution was to modify the original app, but a combination of weak coding skills and the app being in Chinese led him to use free LLM coding chatbots to assist here.

This resulted in a custom settings menu being added with the ability to modify pricing, no need for online access any more and a very nice cotton candy vending machine for the private arcade where presumably friends and family can enjoy cheap or even free cotton candy. Finally having the machine sealed against ant intrusion was also a major improvement.

youtube.com/embed/g_9iyTU5u4o?…


hackaday.com/2026/08/07/hackin…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Chernobyl’s Robots, or the Hackathon From Hell


The media in this post is not displayed to visitors. To view it, please log in.

When the Chernobyl Nuclear Power Plant’s #4 reactor experienced an extreme criticality event on that infamous day in 1986, the resulting steam explosion and lack of any kind of containment building meant that parts of the core were scattered throughout the site. In an extensive update to the original 2023 video, the [Chornobyl Family] covers the mad scramble to design robots to perform on-the-ground measurements, and ultimately remove all this debris for safe disposal.
The TR-1A, an early debris removal robot. (Source: Chornobyl Family, YouTube)The TR-1A, an early debris removal robot. (Source: Chornobyl Family, YouTube)
This essentially took the form of a hackathon, involving teams from all over the USSR and allied nations, creating the most diverse range of robots that 1980s Soviet technology and later Western technology could muster.

Many of these robots didn’t perform very well, or at all, mostly due to the bypassing of any kind of testing before deployment. Especially at the beginning of the clean-up the robots were being pushed into the high-radiation zones as soon as they were finished, with not only mechanical issues being a problem, but also with e.g. inaccurate radiation measurements by the RR-1 robot, that overstated measurements by more than a factor of ten. Meanwhile the RR-2 and RR-3 were too top-heavy and after deployment by helicopter simply tipped over. Eventually manual measurements proved to be faster and safer.

Early debris removal robots like the TR-1A were rather simplistic, with successive generations of robots over the next weeks and months improving on it. The use of a combustion engine instead of batteries provided to be a boon, as combustion engines are far less affected by radiation.

The BAER Beloyarets used an airport cart as the basis, with its electronics relying on vacuum tube technology and relays, with an internal combustion engine. This proved to be one of the most reliable designs and it’s been largely preserved on display in the Chornobyl Exclusion Zone, with many others of these robots also being on display around the nuclear plant or in the city of Chornobyl.

Overall an absolutely dizzying number of robotic designs were invented on the spot, adapted from existing designs or repurposed for operation in a high-radiation zone. Eventually bulldozer designs like the STR-1 helped to push radioactive debris off the roofs into containers, massively reducing the radioactive contamination of the area.

The fact that following #4’s RUD the other three RBMK units were able to keep operating safely without risks to its operators, and with the zone now safe for tourists, is a real testament to the success of the worst hackathon imaginable. Many of the lessons learned are relevant today, including during the decommissioning of Fukushima Daiichi’s melted-down cores.

youtube.com/embed/kXw-VzHsktc?…


hackaday.com/2026/08/07/cherno…

#4 #4’s

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

Citiverse aggiornato alla versione 4.14.8

Stamattina è stato aggiornato Citiverse.it alla versione di NodeBB 4.14.8.

È una versione principalmente dedicata ai bug fix che trovate tutti a questo indirizzo: github.com/NodeBB/NodeBB/relea… . Come dicevo l'ultima volta si fa fatica a stargli dietro talmente tante release fanno! 😁

Grazie a tutte le persone che sostengono i nostri progetti con le donazioni, è anche grazie a voi che possiamo offrire servizi liberi e federati : lealternative.net/donazioni/

Inoltre sono in arrivo novità e cotillon anche grazie al vostro sostegno! 🩵

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Come un token OAuth può compromettere la casella di posta Gmail

📌 Link all'articolo : redhotcyber.com/post/come-un-t…

Luigi Zullo

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

It’s very clear by now that if LLMs are not improving your software quality it’s either a revealed preference (yours or your org’s) for more volume vs more quality, or a skill issue.

The level of testing and review they are enabling in the Go cryptography standard library is amazing.

in reply to Filippo Valsorda

I have seen cases of LLM doing objectively bad stuff. A few months ago I discovered incorrect behavior in a part of our system. I very clearly remembered having written code to handle the particular scenario correctly, so I was a bit puzzled.

But when I looked at the revision history I discovered that the code had been refactored afterwards by an LLM. The refactor did not improve the code in any way, functionally it was identical except from the bug being introduced.

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Falsi QrCode da banca per svuotare conto corrente, primo caso in Liguria - RaiNews

rainews.it/amp/tgr/liguria/art…

@liguria

Cybersecurity & cyberwarfare ha ricondiviso questo.

Benvenuti nella Resistenza: alla scoperta dei lavoratori che eludono (e sabotano) gli obblighi imposti dai loro datori di lavoro in materia di intelligenza artificiale.

"Quando correggo un testo, impiego venti minuti in più per ricontrollarlo, poi dico che l'ho fatto correggere anche da Claude. Tutti sono molto contenti del mio lavoro."

aftermath.site/ai-resistance-t…

@aitech

Cybersecurity & cyberwarfare ha ricondiviso questo.

#WordPress #XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover
securityaffairs.com/196820/hac…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

NEW: Modular computer maker Framework notifies “all” customers that hackers stole their personal data, including names, email addresses, phone numbers, and physical addresses.

The company said all its customers were affected, but declined to say how many customers it has. Number of victims is like tens of thousands or even hundreds of thousands.

techcrunch.com/2026/08/07/comp…

Hackaday Podcast Episode 381: Airless Tires, Full-color Prints, and 28 MW of LEDs


The media in this post is not displayed to visitors. To view it, please log in.

This week’s Hackaday podcast is a European affair again, as Elliot Williams is joined by Jenny List on a summer evening to review the week. And we have a feast of hacks for your delectation.

As the title above says, one of the stand-out hacks this week was a set of airless mountain bike tyres 3D printed in glorious fluorescent TPU. They look as though they shouldn’t work but in fact they showed real promise, and we discuss the process behind their design. Then we take a look at a hybrid of a UV printer and an SLA 3D printer, capable of making high-resolution and robust 3D prints. The prospect of new Amigas intrigues us for a while, then carbon-fibre fabric in 3D prints.

Finally we’re in awe of the tech behind the Las Vegas Sphere, and we’re there for some radio at the Danish BornHack hacker camp. Follow that one up and you’ll find a bonus, an unofficial extra Hackaday podcast.

All the usual links are below, but before you head on down to have a listen, don’t forget we’ve got a mailbag for the podcast and we’d love to hear from you!

Download your own non-volatile MP3 here.

html5-player.libsyn.com/embed/…
Where to Follow Hackaday Podcast

Places to follow Hackaday podcasts:



Episode 381 Show Notes:

News:



Interesting Hacks of the Week:



Quick Hacks:



Can’t-Miss Articles:



hackaday.com/2026/08/07/hackad…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Hackers Impersonate IT Support to Breach Leading Financial Companies
securityaffairs.com/196800/sec…
#securityaffairs #hacking

Music is Back on Optical Disk in This Plex Server


The media in this post is not displayed to visitors. To view it, please log in.

Given that the no doubt totally sustainable build-out of data centers has sent both solid state and magnetic hard drive prices soaring, though, [WNY Over The Air] decided to take a look back at optical disks — specifically the high-density BDXL disks — and see how they do hosting the music library for his Plex server, among other things.

Price wise, well, it’s going to vary depending where you are in the world and exactly when you look. But Blu-ray pricing is looking competitive to hard drives again, and that even goes for the long-lasting, archival-quality “M-disks” that are supposed to last 1000 years in ideal conditions. Of course if you’re playing with LLM Agents, having your precious data on a Write Once Read Many medium like Blu-ray also has the advantage of keeping the agent from wiping it out, which [WNY] takes pains to point out.

That might be obvious, but what’s less obvious is that once the disk has had its metadata queued by his media-streaming Plex server the M-disk is plenty fast enough for streaming music with no noticeable lag. That load time does happen every time you load in a fresh disk, but how often would you be swapping out 100 GB of songs? Even with lossless formats like FLAC, that’s a few thousand tracks. If you’ve already got a Blu-ray drive and are hard up for storage, it might make sense right now to move your music to an optical disk while waiting for drive pries to normalize.

The window where this makes financial sense might not last long, and we’ll be back to wondering where to store our data. All we can say is that’s probably not going to be audio tape, as cool as a reel-to-reel would look in the server room.

youtube.com/embed/fugQ8OnB-kM?…


hackaday.com/2026/08/07/music-…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Mi immagino i genitori: mio figlio è un bravo ragazzo...

"Tutorial per la bomba dell'Isis nei device: arrestato a 16 anni mentre è in vacanza con i genitori"

milanotoday.it/cronaca/ragazzi…

reshared this

in reply to Oloap

non riesco a capire bene alcuni dettagli della vicenda tra cui:
- il ragazzo usava VPN e strumenti di anonimizzazione (come è stato raggiunto dall'Aisi?
- la famiglia non si trovava presso il suo domicilio, come li hanno raggiunti? Hanno chiesto a qualcuno? È stato emesso un ordine di arresto presso le stazioni di tutto il territorio e quindi beccato?

Alcune di queste cose rendono il tutto molto complicato, e se da un certo punto di vista è un bene che ci sia un elemento del genere...

in reply to Fabrizio

@betelgeuse93 leggo di "frequente uso di VPN", per cui si può ipotizzare che se sei sorvegliato basti un errore per essere beccato

Poi i Servizi si infiltrano in queste chat e gruppi...

Ed infine, lecito pensare che fosse sorvegliato ed in ogni caso visto che gli hotel devono segnalare pe presenze ai CC con un controllo incrociato li trovi

O basta un parente/vicino che sappia dove sono...

in reply to Oloap

in effetti in tutto questo avevo dimenticato la parte relativa alla comunicazione obbligatoria dei documenti delle strutture ricettive.

Invece, la sorveglianza web vedo più complicata. Se trattassi roba così scomoda eviterei di lasciare tracce sull'hardware. Della serie, se uso telegramm per queste cose, magari non lo tengo installato sul telefono e sul dispositivo con cui lo uso evitò di lasciare messaggi ed altre cose.

Cose del genere, in cui resterebbe solo il sospetto non le prove

in reply to Fabrizio

@betelgeuse93 VPN e "strumenti di anonimizzazione" usati da un adolescente non sono granché, quando lasci un'impronta ampia su diversi canali
Sul fatto sia stato raggiunto anche se non si trovava presso il suo domicilio, è chiaro che era attenzionato da prima che si spostasse e prenderlo mentre era in vacanza consentiva anche di beccarlo in un momento in cui non poteva mettere in opera tutte le precauzioni alzate quando giocava in casa
in reply to Giacomo Tesio

@giacomo se le accuse verranno confermate, qui stiamo parlando di un terrorista impegnato nell'indottrinare altri terroristi.

Questo è uno dei casi in cui la privazione della libertà è ampiamente "meritata"

Poi sarebbe opportuno capire se si tratta di uno dei tanti poveri disagiati (in questo caso, anche minorenne) che sono stati imboccati direttamente da persone legate all'antiterrorismo, ma per fortuna abbiamo ancora dei giudici in Italia.

@betelgeuse93 @Paoblog

in reply to Giacomo Tesio

@Giacomo Tesio comunque, quando @Fabrizio ha detto

un apologeta dell'ISIS di certo non merita la libertà.

è chiaro che mi stava facendo discorsi teorici sulla possibilità che la libertà sia qualcosa da meritarsi, ma più che altro stava sottolineando il fatto che il ragazzo meritava di essere messo agli arresti

@informapirata ⁂ @Oloap

in reply to Oloap

il fatto della VPN mi puzza. O questo ha fatto un login presso un sito dal quale hanno collegato indirizzo ip con la persona reale, tipo un account gmail, ma non credo che Google per quanto spii rilasci identità di qualcuno dietro a un IP senza un mandato, e magari non in tempi così brevi. O è tutta una esagerazione giornalistica. Non sono nemmeno sicuro di cosa scrivono davvero i giornalisti di quando non si occupano di tecnologia, figuriamoci quando lo fanno.
Sarebbe da approfondire.
in reply to Oloap

questo mi preoccupa, nel senso che siccome questi sono criminali in erba, poi la gente inizierà a dire che è meglio non avere privacy che non essere sicuri. E quindi tutti a favore di chat control, e l'identificazione forzata delle persone quando cercano di accedere a internet come già mi è stato detto da alcune persone che conosco. Come hanno fatto in UK. Che nessuno può accedere a certi siti se non si fa fare una scansione facciale e senza caricare documenti di identità.

Informa Pirata reshared this.

Cybersecurity & cyberwarfare ha ricondiviso questo.

La multa più grande di sempre a #Meta sulla sicurezza dei minori

L'azienda è stata condannata a pagare 567 milioni di dollari per non aver protetto adeguatamente gli utenti più giovani dai rischi delle sue piattaforme

Leggi tutto: ilpost.link/bmGlSqQPe4

@informapirata

Meta nel 2025 ha fatturato oltre 200 miliardi di dollari (contro i 117 del 2021), sai che gli frega di 567 milioni, che probabilmente ne avranno generati molti di più.

Dagli 50 miliardi di multa e poi forse capiscono...

Questa voce è stata modificata (2 giorni fa)

Anche i modelli open-weight “evadono”: Kimi K3 esce dalla sandbox e cerca le risposte su GitHub


@Informatica (Italy e non Italy)
Kimi K3, il nuovo modello open-weight sviluppato dalla cinese Moonshot AI, è riuscito a uscire dall’ambiente isolato nel quale veniva sottoposto a un test di cybersicurezza, collegandosi a Internet e cercando su GitHub le

Menocchio 33 reshared this.

Cybersecurity & cyberwarfare ha ricondiviso questo.

NEW: Another AI model escaped its supposedly isolated environment in a cybersecurity test.

This time it was the model Kimi K3, made by Chinese company Moonshot. At least this time it didn't hack anyone. This is the latest incident of its kind after incidents at OpenAI, Anthropic, Meta and AISI.

techcrunch.com/2026/08/07/chin…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Non sopporto i talebani pro-AI e quelli anti-AI a prescindere. Sono la faccia della stessa medaglia, la polarizzazione da cui entrando nel Fediverso ho cercato di scappare.
Cybersecurity & cyberwarfare ha ricondiviso questo.

Albion apre la porta alla Fascia di Kuiper: la scoperta che ha trasformato un Sistema Solare “chiuso” in un arcipelago di mondi ghiacciati, inaugurando una rivoluzione tranquilla nella nostra visione del cosmo.

stardust.blog/2026/08/albion-i…

This Week in Security: Claude Gets Hacking, Hotel WiFi, and NPM Compromised Again


The media in this post is not displayed to visitors. To view it, please log in.

kMaybe feeling left out from the questionable hype train of “Our AI models can’t be trusted”, Anthropic has released reports that their Claude model has “reached the Internet” and accessed the systems of other companies on at least three occasions during testing.

It appears that the model was restricted from accessing the Internet because (and wait for it) the prompt told it that it didn’t have Internet access, and was inside a simulation. It seems like Anthropic counted on the same trick that users try to convince a model that Grandma really wanted to pass on her life-long love of hacking services, it’s all pretend. Like the OpenAI incident, the models were tasked with completing a capture-the-flag style challenge, a common hacker challenge format where vulnerable systems are provided and contestants try to hack them the fastest. Anthropic says that a misconfiguration of the test environment left the models with Internet access, so the model succeeded in accessing the Internet at large once it ignored the prompt.

In some instances, Anthropic says the model proceeded under the “misconception” that it was still in a simulation, listening selectively to some of the prompt, while in others it continued regardless. In once incident, the test model generated malicious PyPI packages, which were uploaded to the public PyPI repository and downloaded 15 times. Further clouding the issue, one of the downloads of the malicious PyPI module was by a security auditing company that was then infected by the package during analysis, allowing the Claude agent to access credentials of the security company via a poorly designed malware analysis pipeline. The company essentially deliberately infected itself with a malicious package, while lacking protections against malicious packages!

Anthropic promises tighter controls in the future, but stops short of ensuring that models under test will be prevented from accessing the Internet, and categorizes it as a test gone wrong. “These facts give us cautious optimism that with tighter monitoring and controls around evaluation infrastructure, as well as continued investment in alignment, this type of risk can be overcome.”

It remains to be seen why allowing automatic code to hack the production environments of other companies is considered acceptable. If any of us had done the same we’d be facing serious legal questions.

Hotel WiFi Pushes Malware


A threat group associated with the Russian Foreign Intelligence Service (APT29, Cozy Bear, Storm-2945, and/or Midnight Blizzard) has been identified behind an attack to push fake updates over hotel WiFi networks.

It appears that the attackers compromised the captive portal and gateway systems of the impacted hotels. The captive portal system is the typical gatekeeping system that requires you to pay for Internet access, or at least input your hotel room and name. By hijacking the DNS, users were redirected to additional fake “verification” pages that served a menu of malware using a variety of techniques.

Like previously reported activity attempting to capture Microsoft365 logins via spoofed pages, most these attacks seem very loud and obvious, counting on the end user to ignore warnings about invalid SSL certificates or run commands in the shell. Using a variant of the “click-to-fix” attacks, the user is presented with a fake request for additional verification by copying and pasting a string of text into a command shell, which then decodes to a standard malware installation script. More subtle attacks attempt to trick the user into adding a new device to their Microsoft accounts. The user is redirected to a page claiming to require a Microsoft login to access the Internet, often hosted on a copycat domain similar to a legitimate Microsoft resource. The fake login then prompts the victim to copy and paste an authentication URL, adding a new logged-in device to the Microsoft account.

Obviously, running arbitrary shell commands, accepting invalid SSL certificates, or pasting arbitrary URLs after signing in are all something nobody should be doing, and it’s unclear how many users were actually impacted by the campaign. For corporate users, the answers are relatively simple: user training, and an always-on corporate VPN that routes all traffic and DNS through the company servers.

For home users, the solution may be more nuanced. Every third video on YouTube tells you that you need to install a commercial VPN, but in many ways this simply shifts the problem. A commercial (or even worse, a free public VPN) service can also intercept DNS requests and traffic, by design. While some services are legitimately privacy protecting and respecting, many hide the true owners of the service. A better tool is Tailscale, designed for implementing personal VPN services, where your traffic stays on your own devices.

Tailscale, OpenAI, and Hugging Face


Speaking of the Tailscale VPN, we jump to their role (or non-role) in the recent Open AI “incident” with Hugging Face.

Tailscale is a zero-trust framework for connecting systems using the WireGuard VPN protocol. For end users, this is an excellent way to set up a VPN where your traffic never leaves your own systems unencrypted. For enterprises, it is often used to connect services Internet-wide, which is how it was used in the Hugging Face infrastructure. Once the Open AI agent had selected Hugging Face as a target, it found a vulnerability in a package manager, accessed a worker machine at Hugging Face, escalated to root on the Kubernetes cluster, and extracted the production key and authentication storage. This allowed the Open AI model to authenticate against the Tailscale system and directly connect to the network.

This, rightly, is not Tailscale’s problem. Once the authentication keys are available, it’s working as designed to allow new devices to register on the network. This is a pervasive problem with stored authentication tokens, and is one of the root goals, and causes, of the supply chain attacks suffered by NPM, PyPI, GitHub, VSCode plugin repositories, and more. Once an attacker is able to extract the authentication tokens, they are able to impersonate that account or system with equal privileges for as long as that authentication remains valid. Typically these tokens are not time limited, and the window of opportunity lasts until the owners of the account become aware of the compromise and are able to reset all of the impacted authentications!

Solutions to the permanent authentication token already exist, but are not widely used. Many package repositories already support restricted and dynamic authentication via OpenID Connect, where a token grants specific resources, not system-wide access. On some platforms, keys can be protected in a hardware-backed key store like a TPM or the Apple Secure Enclave chip, though this doesn’t solve the problem for most servers.

Tailscale, obviously, is looking to lean on the publicity generated from the Open AI incident, but the message is a good one: Anything that can be done to automatically and painlessly reduce the risks associated with long-lived authentication tokens will benefit everyone on the Internet. Even if you don’t run an integration pipeline, you most definitely run software built by one.

Another Set of NPM Package Compromises


The NPM package repository has suffered yet another incident where a large number of packages have been compromised.

Investigators have tracked over 400 packages infected with another variant of the same “Mini Shai-Halud” worm that ran rampant through package repositories in the Spring of 2026. While efforts have been made to reduce the attack surface of packages, few have implemented them, partly because they are not mandatory, and partly because they can greatly impact, or completely break, the build process. The packages this time include high-profile, commonly used tools, with several billion (yes, with a “b”) monthly installs during builds of other software.

Like the worms impacting the package repositories previously, packages are infected by added scripts to the pre-install commands which are executed automatically before the package is installed. The latest infection appears to have spread from a single developer of two widely used packages, keyv and cacheable. Once triggered, the worm will infect and upload new versions of all packages it can access, using stolen NPM authentication tokens. Like other variants of the “Mini Shai-Halud” family, the worm steals authentication tokens for NPM, PyPI, AWS, Kubernetes, and GitHub, the contents of env files which typically contain additional authentication keys, SSH keys, VPN configurations, and over 200 other types of credentials. These newer variants of the worms have increased the list of stolen credentials, begun modifying the instructions for AI coding assistants, added cryptocurrency theft, and added poisoned configurations for VSCode and AI tools to infect projects once the initial infection has been resolved.

Given the scope of the latest outbreak, the number of impacted packages will only increase: no effective countermeasures exist in the NPM community to prevent another wide supply chain event.

Mythos Knocks Out Post-Quantum Candidate


The Anthropic Mythos model found flaws in a candidate post-quantum encryption algorithm, HAWK. Multiple encryption algorithms have been under testing for years as part of the standardization process at NIST, with selected algorithms becoming part of the Federal Information Processing Standard requirements for systems handling secure data for government systems. Cryptographers fear that future advancements in quantum computing could break current encryption and signature methods, driving the search for new standards that will survive.

Anthropic reports that after 60 hours and approximately $100,000 in compute resources, the Mythos model was able to discover a flaw in the HAWK post-quantum signature algorithm. HAWK had previously survived multiple rounds of validation testing, but following the attacks generated by Mythos, the developer has withdrawn it from consideration. Mythos was not able to completely break HAWK, but combined multiple methods to reduce the key space by half.

Ultimately this is a case of the system working fully as designed. The proper time to find flaws in new algorithms is before they’re selected as standards!

Backdooring an Entire Linux Distribution


In 1984, Ken Thompson, one of the creators of Unix, gave the lecture “Reflections on Trusting Trust” in which he outlines the difficulties of establishing trust in tools. Thompson proposed the issue of a compiler modified to insert an invisible back door in any binary it compiled, including future versions of itself, ultimately showing the near impossibility of establishing a guaranteed clean tool chain, ultimately existing in all compiled tools and compilers without any evidence of the original code or modifications. Even if you inspect the source code, a compromised compiler could still be your undoing.

This week, a coalition of researchers published a paper demonstrating the “trusting trust” attack against a modern Linux distribution. Starting with a modified copy of the strip tool that removes debugging and other extraneous information to generate a smaller binary, the researchers demonstrated that the entire build of a NixOS Linux distribution could have a modification injected in every binary, including future builds of strip itself. While the attack starts with a source code modification of strip, after the first generation the modification exists in binary form only, built into each generation of the tool. This demonstrates that the “trusting trust” attack extends to any tool involved in the build process, not only the compiler, since the strip binary never reads source code, only the compiled results.


hackaday.com/2026/08/07/this-w…

Cybersecurity & cyberwarfare ha ricondiviso questo.

OpenAI staff replay the HuggingFace hack: youtube.com/watch?v=87DyyMV0kC…

More Black Hat videos are here: youtube.com/@BlackHatOfficialY…

I'm surprised they're online so early, since it usually takes months for BlackHat to release this stuff

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

#Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case
securityaffairs.com/196793/law…
#securityaffairs #hacking

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

AI fuori Controllo! OpenAI e Anthropic sotto accusa: gli agenti attaccano sviluppatori e repository

📌 Link all'articolo : redhotcyber.com/post/ai-fuori-…

Luigi Zullo

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

reshared this

FlipBuddy is Borg, You Will Be Assimilated


The media in this post is not displayed to visitors. To view it, please log in.

A desktop Borg cube. Just kidding, it's a buttonless, cube-shaped timer with a really neat 3D-printed enclosure.

When you think about it, time is all we’ve really got. Where to go from there is ultimately up to you. Maybe you use an app to track every task, or just go with the onboard timer. But that can be a lot of steps to begin with, and then the phone screen goes dark again. For some people, the whole out of sight, out of mind thing will kick in. At worst, you get distracted, start doing something else, and then feel guilty and frustrated when the timer starts going off.

The guts of FlipBuddy inside the unfurled enclosure.But there’s hope for us visual simpletons, and the purveyor of that hope is [Edris] of Ponderly Robotics. You see, [Edris] created an extremely easy-to-use timer that looks like something you’d find on Captain Picard’s desk as a token of defeating the Borg. But the affably-named FlipBuddy is far more useful than that description implies.

[Edris] uses the open-source FlipBuddy every day, and swears by its simplicity. The point is accessibility, and respect for privacy. That said, there’s a companion app to provide insight.

Basically, you assign a task to each cube face. Choose one, and place the cube with that side facing up. FlipBuddy wakes up, connects to WiFi, and then pushes your session to the cloud, bypassing the need for your phone.

Time to switch tasks? Just put the new side face up. When you’re done for the day, use the stop face, which we’re hoping means to set it on the knocked-off corner.

You don’t need much to make FlipBuddy come to life. [Edris] used an ESP32 (an S3 SuperMini or similar will work), an MPU6050, six WS2812B LEDs, and a 3.7 V Li-Po cell. The beautiful, 3D printed origami mesh enclosure prints as a single, flat piece, and you get to fold it up around the internals and make your new buddy come to life.

Part of the point of FlipBuddy is that it can become as intuitive as punching a chess clock. So if it’s buttons you’re after, check out this simple Pomodoro timer.


hackaday.com/2026/08/07/flipbu…

Cybersecurity & cyberwarfare ha ricondiviso questo.

#nerdystuff in pausa pranzo

#McStumble è una cassetta degli attrezzi da browser curata a mano: decine di tool per PDF, immagini, testo e codice, più un pulsante per farsi sorprendere dal lato più strano del web. Fico!

🧰 mcstumble.com

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

Researchers Discover Hidden #Backdoor in 20 Router Models Allowing Remote Root Access
securityaffairs.com/196785/sec…
#securityaffairs #hacking #Zbtlink
Cybersecurity & cyberwarfare ha ricondiviso questo.

It took humanity 68 years to install 1TW solar capacity, which we reached in 2022.

It took 2 years to double it to 2TW, which we did in November 2024.

Now a little under 2 years later, we’re at 3TW.

e360.yale.edu/digest/three-ter…

#RenewableEnergy

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

🌌
Cybersecurity & cyberwarfare ha ricondiviso questo.

⚠️ Chinese routers ship with hidden backdoor

#ZBTLINK devices contain undocumented root access that enables remote compromise and persistent control.
🔗 read more: thehackernews.com/20...

#ransomNews #cybersecurity

Chinese-Made Zbtlink Routers S...

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

🚨 Malware can hijack Google passkey accounts

Three post-compromise techniques target Chrome Password Manager secrets.

🔗 read more: thehackernews.com/20...

#ransomNews #cybersecurity

Google Password Manager Attack...

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Meta's AI joins Anthropic and OpenAI in the hacky-hacky
-AISI also loses track of AI models in a test
-Cyberattack disrupts North Carolina ports
-The Philippines will establish a cybersecurity agency
-Ransom Cartel admin gets 16 years
-Hackers target US hedge funds
-Panama Metro sees cyberattack
-Italy makes room for military cyber units
-China launches Palo Alto Networks probe
-Indiana establishes cybersecurity office

N: news.risky.biz/risky-bulletin-…
P: risky.biz/RBNEWS597/

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-FBI partners with China and Russia police
-CyberCom deals with suicide wave
-Snowflake hacker pleads guilty
-There are still thousands of automatic fuel gauges on the internet
-New Flooding Dropper campaign hits npm
-Threat actor AI usage explodes
-New FunFoneFarm phone farm kit
-Wrench attacks reach $30m this year
-New CanOworms botnet
-New Khunt post-exploitation framework
-Russian disinfo targets France's next presidential election
ot
-WhatsApp asks Indians for DOB

Catalin Cimpanu reshared this.

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Backdoor found in Zbtlink routers
-Apple's Private Relay leaks your IP address
-New TONTOU and PromptSpy attacks
-New PleaseFix vulnerability class
-Bugtraq announces return
-New dotdotslash_bot Mastodon
-WhatsApp asks Indians for DOB
-Signal adds multi-device linking
-Blogger accounts locked after fake malware alerts
-Ad libraries steal location data
-Meta launches Muse Cod

Wrist Welcomes Wii Nunchuk As Gloriously Ergonomic Macropad


The media in this post is not displayed to visitors. To view it, please log in.

[John Dingley] spends a lot of time editing videos, and as many of us know, when it comes to repetitive tasks the more ergonomic the better.

Keyboard shortcuts exist for common video editing functions, but [John] found that the vast majority of his work needed only three or four of them. Feeling he could do better than a three-key macropad, he turned to what’s perhaps one of the most ergonomic devices ever designed — the Wii Nunchuk.

A Wii Nunchuk is an I2C device, so there needs to be some intermediary device involved if you want to plug it into a computer. [John] solves that with the ANAVI Handle, an open source adapter to make a Nunchuk act like a USB Human Interface Device (HID). That addresses the connectivity problem, but the default firmware on the adapter only treats the Nunchuk as a mouse or joystick, so a few more changes are required before it can be pressed into service as an ultra-comfortable macropad.

The ANAVI Handle runs CircuitPython code on an RP2040, and modifying its behavior is as simple as plugging it in via USB and editing the code right on the device. One has to define some keyboard events, configure the device to act as a keyboard, and send the right events when the buttons or joystick get pushed. [John] provides the code, and walks through the changes on video so even those without any coding experience can get it done.

The Nunchuk design is still being sold and used today, and it’s shown up in all kinds of places. We’ve seen a Bluetooth-enabled one and even seen a Raspberry Pi Zero shoehorned into one, complete with HDMI output.

youtube.com/embed/jMN4zio32E0?…


hackaday.com/2026/08/07/wrist-…

Cybersecurity & cyberwarfare ha ricondiviso questo.

#AI #Deepfakes Used to Impersonate #OnlyFans Creators in New Scam
securityaffairs.com/196772/ai/…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

☕ CYBERBRIEFING — Venerdì 7 agosto 2026

👉 Leggi tutti gli aggiornamenti delle ultime 24 ore:
ilpuntocyber.rfeed.it/article.…

#newsletter #cybersecurity
@informatica

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

394 – LE FOTO NORMALI DEI NOSTRI FIGLI USATE PER CREARE IMMAGINI DI ABUSO camisanicalzolari.it/394-le-fo…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Claude Code aiuta a sbloccare un BIOS HP: l’AI riesce dove gli esperti hanno fallito

📌 Link all'articolo : redhotcyber.com/post/claude-co…

Carolina Vivianti

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Attenzione ai TV Box Android economici: possono trasformare la tua rete in un proxy per hacker

📌 Link all'articolo : redhotcyber.com/post/attenzion…

Luigi Zullo

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

reshared this

A 3D Printed Cycloidal Gearbox


The media in this post is not displayed to visitors. To view it, please log in.

Stepper motors are undeniably useful, but sometimes they need a bit of gearing to help perform their task. [Gjhudson2008] has a compact gearbox for NEMA 17 or 23 steppers that is mostly 3D printed. How compact? The gearbox, named VANTIX, is exactly the height of a standard NEMA 17 axle.

However, for it to be that thin, your stepper has to have the D-bore on the shaft go all the way down. Some steppers leave a shank uncut at the base, and that won’t work for VANTIX.

The recommendation is to print in ABS with a 0.2 mm nozzle for certain parts to help improve tolerance. Most of the assembly is either press fit or installed during the printing process. Some parts of the gearbox are better to print with a larger nozzle, too.

There are some heat-set inserts and, of course, you’ll need lube to keep everything moving smoothly. There are a few top plates you can print to fit various mounting scenarios.

We have seen a number of similar designs. We’ve also looked at some e-bike-inspired drives.


hackaday.com/2026/08/06/a-3d-p…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

PSA: I am not in Las Vegas this week. So if anyone approaches you saying it's me, don't tell them any secrets.

You can tell ~ the real me ~ those secrets.

My Signal: +1 917 257 1382

Questa voce è stata modificata (2 giorni fa)