Normal view

There are new articles available, click to refresh the page.
Yesterday — 22 July 2026Hacking and InfoSec

Top Benefits of Earning a Six Sigma Green Belt Certification

 

What helps some professionals stand out when organisations are constantly searching for people who can improve performance? The answer often lies in having the right skills and recognised credentials. Six Sigma Green Belt Training is widely valued because it teaches professionals how to identify problems and support business success. Employers across many industries look for individuals who can contribute to measurable improvements. Earning a Six Sigma Green Belt Certification can strengthen both technical and professional capabilities.

In this blog, we will explore the key benefits of gaining this respected certification.


Table of Content

  • Key Benefits of Achieving a Six Sigma Green Belt Certification 
  • Conclusion


Key Benefits of Achieving a Six Sigma Green Belt Certification

Below are the major benefits that make Six Sigma Green Belt Certification a valuable investment for professionals across different industries:

Enhanced Career Growth Opportunities

The opportunity for job progression is one of the main benefits of obtaining a Six Sigma Green Belt Certification. Professionals who can boost productivity and quality are valued by organisations. 

Opportunities for leadership and increased responsibility are frequently available to certified professionals. Certification is seen by many employers as evidence of one's capacity dedication to ongoing development. When applying for new positions or promotions, this can help professionals stand out.

Stronger Problem Solving Skills

Every organisation has issues that have an impact on performance and productivity. Learning how to address challenges in an organised manner is one of the main advantages of Six Sigma Green Belt Training.

Instead of concentrating solely on symptoms, professionals learn how to find underlying causes. This method aids in the development of durable solutions. In practically every sector and position, having strong problem-solving abilities is beneficial.

Cross Industry Versatility

The applicability of Six Sigma Green Belt Certification in numerous sectors is one of its main advantages. The acquired abilities are not sector-specific.

Six Sigma techniques can be used by manufacturing professionals to raise production quality. Finance professionals are able to minimise errors and streamline procedures. Healthcare businesses can improve patient experiences, and IT specialists can improve service delivery.

Increased Value to Employers

Companies are always looking for people who can enhance business performance. Because they know how to cut waste and enhance procedures, professionals with Six Sigma Green Belt Certification frequently contribute value.

Better client experiences and reduced operating expenses are all advantageous to businesses. Because of this, qualified experts are frequently seen as important contributors to the success of organisations.

Higher Earning Potential 

Many professionals pursue Six Sigma Green Belt Training because it will impact on their earning potential. The particular talents acquired through certification are frequently acknowledged by employers.
 
Organisations are frequently prepared to invest in experts with these skills since they gain from process enhancements and cost reductions. Certification can improve a professional's standing when discussing career advancement, even though income results vary.

Greater Confidence in the Workplace

Possessing the appropriate information and abilities frequently leads to confidence. Professionals who complete Six Sigma Green Belt Training learn best practices and improvement techniques.

This self-assurance can enable people to contribute to significant commercial endeavours and engage more fully in conversations. Credibility in teams is also enhanced by the ability to substantiate concepts with facts and methodical reasoning.

Opportunities Across Multiple Industries

The wide applicability of Six Sigma Green Belt Certification is one of its most alluring features. The concepts are applicable to many industries, including manufacturing and many others.

Certified professionals can pursue a variety of employment options because process improvement is crucial in practically every business. Certification is beneficial for both present and future professional objectives because of its flexibility.

Supports a Culture of Continuous Improvement 

In order to be competitive, modern businesses ask for constant improvement. After completing Six Sigma Green Belt Training, professionals frequently start advocating for constructive change within their teams.

They promote improved working practices and assist in identifying areas for improvement. Both the organisation and the professional gain from this way of thinking.

 

Conclusion

Achieving Six Sigma Green Belt Certification offers benefits that extend far beyond technical knowledge. It supports career progression and helps professionals deliver measurable business results. Organisations also benefit through increased efficiency and improved customer satisfaction.
  
For individuals looking to strengthen their professional capabilities and remain competitive in today's workplace. Lean and Six Sigma Training can provide a strong foundation for long term success and continuous improvement.

Pentesting: A Look at ATM Security

22 July 2026 at 09:05

Welcome back, aspiring cyberwarriors!

Part of our work involves supporting red team engagements. We review completed tests, size up the risk tied to each vulnerability and build out recommendations for shoring up the infrastructure. This time around, we wanted to pull back the curtain on something special. It’s ATM security. 

This article is written to help with security assessments on ATMs, showing possible vulnerabilities you may find. It covers many things, from running malware bought off a forum, to an insider on the bank’s payroll, to a service technician who understands the machine’s internals and has been handed broad access to the equipment. We also look at whether a hacker could get into the bank’s broader network simply because the perimeter wasn’t locked down well enough.

Nothing here is meant as a tutorial. We’re documenting weaknesses hackers could exploit so that defenders know what to fix, not handing anyone a blueprint. We take no responsibility for how this information is used.

With that out of the way, let’s start with where ATMs came from.

The History of ATMs

London got the world’s first working ATM on June 27, 1967. It was primitive by today’s standards, incapable of checking a balance, which is exactly why withdrawals topped out at 10 pounds, and it dispensed cash only against special vouchers rather than reading a card. 

first atm from barclays
Source: Barclays Bank

Nearly six decades later, ATMs look nothing like those early cash dispensers. Now they are multifunctional devices, but the hackers never stopped circling. Part of the appeal is obvious. An ATM sits on a pile of cash and offers quick access to it, and there are simply too many machines scattered across too many places to guard them all closely. A lot of them sit in isolated, low traffic spots that run unattended around the clock, think gas stations. That has shaped decades of security investment, most of it aimed at physical hardening. Today’s units can weigh over half a ton and come loaded with sensors tracking position, internal temperature, and whether a compartment has been pried open.

Here’s the catch, though. The safe holding the cash is genuinely hard to crack, but the compartment housing the control electronics is a different story, and in our assessment, it remains poorly defended. That gap opens the door to logical attacks, ones that skip the crowbar entirely and go after the software instead, and that category has been gaining ground fast.

cisco talos atm malware samples

Cisco Talos has tracked a steady climb in new ATM malware variants since 2009. The raw sample count still looks small next to other malware families, but don’t let that fool you. Europe alone saw logical attacks on ATMs jump 269% in 2020 versus the year prior, and the average payout per incident ballooned nearly a thousandfold across that same window, climbing from roughly a thousand euros to well over a million.

What changed the game was availability. ATM malware used to be a rare, closely guarded tool. Once it started circulating more freely on underground markets, prices fell and so did the skill required to use it. Cutlet Maker, which surfaced in 2017, is a good illustration. It came bundled with a Russian language manual complete with troubleshooting notes for running it against different ATM models.

atm manuals
Screenshot of the troubleshooting guide for Cutlet Maker. The author describes the ATM’s USB port location, along with advice on how to devise a stick for attaching the USB cable and accessing the internal USB port. Source: TrendMicro

Fast forward to 2024, and vendors on those same markets were offering ATM malware through subscription pricing, monthly plans included.

dark web informer

Logical attacks have always had one real weakness. They take skill and patience to pull off. That’s why cheap, well documented malware kits have had such an outsized impact on the trend. Their upside for hackers is just as real. They’re far quieter than smashing a machine open, and they often let the same person come back to a compromised ATM again and again. Manufacturers have started fighting back on the hardware side too, with tamper protected cassettes that flood the cash inside with indelible ink the moment someone tries to force them open, ruining the bills instantly.

Brief Attack Statistics

The numbers tell their own story. ATM related crime climbed 600% between 2019 and 2022, with 165% of that increase packed into 2021 and 2022 alone. Physical break ins, which have always driven the bulk of ATM crime, contributed alongside the rise in logical attacks. Germany had 496 ATM explosions recorded in 2022, a record for the country. Zoom out globally, and incidents of that kind blew past 18,000 in 2023.

Losses have kept pace. Banks worldwide absorbed $2.4 billion in direct losses from ATM fraud by the close of 2023. Europe’s share came to 173 million euros, with 67 million of that tied specifically to skimming. The United States handles just 25.29% of global transaction volume yet accounts for 42.32% of global losses. Skimming remains a big part of why, showing up in 45% of all ATM fraud cases in 2023 and costing North America over $900 million, with more than 315,000 cards compromised across at least 3,000 financial institutions.

None of this is happening in a vacuum. The market for ATM protection has grown right alongside the threat. Still, priorities inside most banks remain lopsided. Physical security tends to get the lion’s share of attention, while the operating system, drivers, and control software logic running underneath often get treated as an afterthought. That imbalance carries real consequences. A 2022 RTM Group study found that hackers could breach an ATM’s housing without setting off an alarm in one out of every two attempts, giving them free rein to tamper with the equipment inside.

How an ATM Is Built

Making sense of how these attacks work starts with understanding what happens inside the machine during an ordinary transaction. We’ll walk through that process using one representative configuration, illustrated in the diagram below.

how an atm is built

The diagram reflects one specific setup we’re using for illustration, not a universal default, since real world configurations vary by device.

1. User Layer

From where the customer stands, using an ATM is simple. They need to present a card and pick a transaction. That wasn’t always the whole story. Inserting a physical card into a reader used to be the only entry point, and that reliance on the magnetic stripe made skimming and shimming, techniques aimed at stealing card data to produce counterfeit copies, a persistent problem for years.

Contactless cards changed the entry point itself. NFC readers now sit alongside traditional card slots on most machines. 

A PIN code layers on additional protection against someone using a stolen card. Entry happens through an encrypting PIN pad, a combination of physical keypad and cryptographic module that ensures the PIN never travels or gets stored anywhere in plain text. Verification of the resulting encrypted PIN block happens back at the processing center. 

Once identity checks clear, you can withdraw cash, check your balance, transfer funds, and so forth. There’s a full computer running inside the housing, but customers never get anywhere near it directly. Every interaction they have flows through a single banking application running in kiosk mode, locked to full screen.

2. OS Layer

That computer we just mentioned lives inside what’s called the service zone, and this section covers what happens there, setting the cash handling hardware aside for the moment. Physically, the service zone is protected by a thin door and a basic lock. Machines from the same product line frequently share an identical key too, one that’s often available for purchase online with minimal effort.

Beyond the system unit itself, the service zone also houses the ATM’s networking equipment and its wired connections to the card reader, contactless reader, PIN pad, and dispenser, typically running over USB, Ethernet, PCI, or COM interfaces depending on the device.

Windows powers most of these systems, historically through Windows Embedded and increasingly through Windows IoT, a Windows 10 variant built for embedded use.

atm

The kiosk application isn’t the only thing running on that OS. Alongside it sits the ATM’s control software plus a handful of security tools. That can be antivirus protection, Windows AppLocker that keeps unauthorized programs from executing, and a VPN client that maintains a secure tunnel back to the bank’s internal network.

Control software is arguably the most important piece at this layer. Core responsibilities for the control software boil down to managing peripherals and communicating with the processing center, though specific implementations often add more on top of that. Some bundle in software for a monitoring server, letting technicians manage an entire network of self service machines remotely. Others are built in a supervisor mode meant purely for technical staff, offering quick access to diagnostic tools through a hidden menu to simplify physical maintenance visits.

3. Network Layer

Selecting a transaction sets off a verification process handled entirely by the processing center, a server living on the bank’s internal network. That server confirms the card data is legitimate, checks the PIN again before letting the transaction through, rules out any restrictions on the account, and verifies there’s enough balance to cover the request.

Everything exchanged between the ATM and the processing center travels encrypted, usually through a VPN tunnel, protecting against interception or tampering along the way. NDC and DDC are the most common messaging protocols in this exchange, functioning as something of an informal industry standard even before multi-vendor control software became widespread. ISO 8583 and its various offshoots see heavy use as well. 

The processing center isn’t the only thing an ATM talks to. Many machines also maintain a connection to a monitoring server used for remote management, health checks, and pushing updates, and unlike the processing center link, this channel frequently runs without any encryption at all.

4. Firmware Layer

Once the processing center signs off, the control software hands things over to the dispenser for a withdrawal, or the deposit module if cash is going in. These components typically sit inside the most fortified section of the ATM, the safe zone, built from tougher materials and secured with its own dedicated key separate from the service zone. 

inside the atm

The dispenser counts out the required banknotes from the ATM’s cassettes, moves them into position at the dispensing tray, then opens the shutter, the physical flap that blocks access to the cash until it’s ready. Data moving between the control software and the dispenser can be encrypted, and both sides authenticate one another before any exchange begins, a safeguard against device spoofing. All of that encryption and authentication logic lives directly in the dispenser’s own firmware. 

Deposits work differently. Incoming banknotes pass through a validator that checks their authenticity.

ATM Attacks

With the mechanics of an ATM covered, we can turn to the threats themselves. Every attack against these machines falls into one of two broad camps, physical or logical, depending on what the hacker is going after and how they approach it.

Physical attacks go straight after the machine or its components, aiming to extract cash or knock the device out of normal operation without touching a line of code. These predate targeted malware by decades and don’t require much specialized skill. Some don’t even target the machine itself, focusing instead on the people standing in front of it.

physical attacks on atms

Logical attacks operate on a different level entirely. They demand genuine technical skill and preparation, built around exploiting weaknesses in the ATM’s software and network layers. They draw less public attention than physical attacks despite posing a bigger threat to banks, largely because they’re quieter and let a hacker return to the same compromised machine to cash in more than once.

System attacks go after functionality or logic running at the ATM’s OS layer, typically aiming to extract cash or sidestep security controls outright. Black box attacks deserve special attention, where a hacker skips gaining OS access altogether and instead wires their own device directly into the dispenser to control it externally. The same technique can target other peripherals, like the banknote validator.

system attacks on atms

Network attacks aim at the ATM’s networking components instead, with hackers looking to intercept, forge, or otherwise abuse data in transit, or to seize remote control of the machine. With weak enough safeguards in place, a hacker can forge the responses coming back to the ATM and push through a cash withdrawal even after the processing center rejected it.

network attacks on atms

Not every attack in this framework ends with cash in hand. A hacker might, say, work to gain remote network access first, then pivot into an OS layer attack from there. 

We have seen cases where compromising a single ATM meant compromising the entire bank because there was no network segmentation in place. Conversely, gaining access to the bank’s internal network could provide a path to ATMs and other critical systems connected to it. Credential reuse and a lack of understanding of Active Directory security can lead to devastating consequences in environments like these.

Summary

ATMs have evolved from simple cash dispensers into complex and networked systems. Their security has evolved unevenly alongside them. Physical hardening has made the cash safe itself genuinely difficult to crack, but the service zone housing the control electronics remains comparatively exposed, and that gap has fueled a steady rise in logical attacks. These attacks demand more skill than a physical break-in, but they’re increasingly accessible because of well-documented malware kits.

Cybersecurity is a vast field, and we offer courses covering a wide range of topics, including Active Directory Hacking, Wi-Fi Hacking, Web Application Hacking, SCADA Security, and much more. Our course library is constantly growing as we continue to add new training, all of which is available through our Member Gold plan. If you want unlimited access to our entire training library, including our most advanced courses, consider upgrading to Subscriber Pro.

The post Pentesting: A Look at ATM Security first appeared on Hackers Arise.

Before yesterdayHacking and InfoSec

Why programming true randomness in emulators is a developer worst nightmare 

14 July 2026 at 02:03

Asking a deterministic machine to behave indeterministically is the cleanest paradox in software engineering, and emulator developers live inside it every working day. The job description sounds reasonable until you read it twice: recreate, with mathematical precision, a piece of silicon that was never mathematically precise to begin with, reproducing on commodity hardware the analog […]

The post Why programming true randomness in emulators is a developer worst nightmare  appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Top Benefits of Earning a Six Sigma Green Belt Certification

What helps some professionals stand out when organisations are constantly searching for people who can improve performance? The answer often lies in having the right skills and recognised credentials. Six Sigma Green Belt Training is widely valued because it teaches professionals how to identify problems and support business success. Employers across many industries look for individuals who can contribute to measurable improvements. Earning a Six Sigma Green Belt Certification can strengthen both technical and professional capabilities.

In this blog, we will explore the key benefits of gaining this respected certification.


Table of Content

  • Key Benefits of Achieving a Six Sigma Green Belt Certification 
  • Conclusion


Key Benefits of Achieving a Six Sigma Green Belt Certification

Below are the major benefits that make Six Sigma Green Belt Certification a valuable investment for professionals across different industries:

Enhanced Career Growth Opportunities

The opportunity for job progression is one of the main benefits of obtaining a Six Sigma Green Belt Certification. Professionals who can boost productivity and quality are valued by organisations. 

Opportunities for leadership and increased responsibility are frequently available to certified professionals. Certification is seen by many employers as evidence of one's capacity dedication to ongoing development. When applying for new positions or promotions, this can help professionals stand out.

Stronger Problem Solving Skills

Every organisation has issues that have an impact on performance and productivity. Learning how to address challenges in an organised manner is one of the main advantages of Six Sigma Green Belt Training.

Instead of concentrating solely on symptoms, professionals learn how to find underlying causes. This method aids in the development of durable solutions. In practically every sector and position, having strong problem-solving abilities is beneficial.

Cross Industry Versatility

The applicability of Six Sigma Green Belt Certification in numerous sectors is one of its main advantages. The acquired abilities are not sector-specific.

Six Sigma techniques can be used by manufacturing professionals to raise production quality. Finance professionals are able to minimise errors and streamline procedures. Healthcare businesses can improve patient experiences, and IT specialists can improve service delivery.

Increased Value to Employers

Companies are always looking for people who can enhance business performance. Because they know how to cut waste and enhance procedures, professionals with Six Sigma Green Belt Certification frequently contribute value.

Better client experiences and reduced operating expenses are all advantageous to businesses. Because of this, qualified experts are frequently seen as important contributors to the success of organisations.

Higher Earning Potential 

Many professionals pursue Six Sigma Green Belt Training because it will impact on their earning potential. The particular talents acquired through certification are frequently acknowledged by employers.
 
Organisations are frequently prepared to invest in experts with these skills since they gain from process enhancements and cost reductions. Certification can improve a professional's standing when discussing career advancement, even though income results vary.

Greater Confidence in the Workplace

Possessing the appropriate information and abilities frequently leads to confidence. Professionals who complete Six Sigma Green Belt Training learn best practices and improvement techniques.

This self-assurance can enable people to contribute to significant commercial endeavours and engage more fully in conversations. Credibility in teams is also enhanced by the ability to substantiate concepts with facts and methodical reasoning.

Opportunities Across Multiple Industries

The wide applicability of Six Sigma Green Belt Certification is one of its most alluring features. The concepts are applicable to many industries, including manufacturing and many others.

Certified professionals can pursue a variety of employment options because process improvement is crucial in practically every business. Certification is beneficial for both present and future professional objectives because of its flexibility.

Supports a Culture of Continuous Improvement 

In order to be competitive, modern businesses ask for constant improvement. After completing Six Sigma Green Belt Training, professionals frequently start advocating for constructive change within their teams.

They promote improved working practices and assist in identifying areas for improvement. Both the organisation and the professional gain from this way of thinking.

 

Conclusion

Achieving Six Sigma Green Belt Certification offers benefits that extend far beyond technical knowledge. It supports career progression and helps professionals deliver measurable business results. Organisations also benefit through increased efficiency and improved customer satisfaction.
  
For individuals looking to strengthen their professional capabilities and remain competitive in today's workplace. Lean and Six Sigma Training can provide a strong foundation for long term success and continuous improvement.

Wi-Fi Hacking: Wi-Fi Can Now Identify You Without Your Phone

8 July 2026 at 10:31

Welcome back, aspiring hackers!

The density of WiFi access points in modern cities has now reached a point where a large-scale surveillance system may be able to identify almost anyone who walks near a router, even if that person is not carrying a mobile phone. Researchers from the Karlsruhe Institute of Technology (KIT) have published a scientific paper describing this kind of system and the technology that makes it possible.

At the center of this surveillance method is a feature called beamforming, which first appeared with the WiFi 5 (802.11ac) standard in 2013–2014. The basic idea was introduced with WiFi 5, but it became much more refined and effective with WiFi 6 (802.11ax), where the technology matured into something more practical.

Beamforming

Beamforming, also called spatial filtering, is a signal processing technique used to send and receive wireless signals in specific directions rather than spreading them evenly in every direction. In simple marketing language, this is often described as a router that “does not broadcast equally everywhere anymore, but instead follows the user with a focused beam.” That description is not wrong, but it leaves out the technical depth behind the idea.

Beamforming

From an engineering point of view, beamforming works by combining several antennas into a group called an array. When the signals from these antennas are timed and lined up correctly, they boost each other in certain directions. In other directions, they cancel each other out. The result is a signal that is far more focused and efficient than older systems, which simply broadcast outward in every direction at once.

Beamforming gives both senders and receivers the ability to focus on signals coming from one direction while blocking out noise from others. Because of that, the technique is used not only in WiFi, but also in radar, sonar, seismology, wireless communications, radio astronomy, acoustics, and biomedical engineering.

Identifying People Through WiFi Signals

As radio waves move through space, they do not simply travel in a straight, clean line. They interact with the world around them in many different ways. They can pass through objects, reflect off surfaces, become absorbed, become polarized, bend around obstacles, scatter in different directions, or refract as they cross boundaries between materials. This means that when a WiFi system sends a signal and later receives it back, the final result contains information about everything the signal encountered along the way. By comparing the expected signal with the received one, it becomes possible to measure interference and use that information to correct transmission errors. But that same interference also reveals details about the environment itself.

For example, when a person enters the path of a WiFi signal, the signal changes. Human bodies affect radio waves in measurable ways. The signal may weaken, shift, scatter, or behave differently depending on movement, posture, and position. If researchers analyze these changes carefully, they can infer a surprising amount of information about the surrounding environment. They may detect whether people are present, what they are doing, and in some cases even who they are.

This whole research area has grown into a separate field known as WiFi Sensing.

Most WiFi Sensing research is presented as useful and harmless, and in many cases it really is. It can support smart-home features, occupancy detection and other practical applications. But the privacy concerns are obvious. When these methods are combined with activity recognition and the massive spread of WiFi hotspots, they can reveal highly sensitive information. One of the most troubling possibilities is that someone could be identified in the range of a hotspot and then tracked over time without ever knowing it.

Using Channel Information for Identification

There are several ways a person can be identified through WiFi. One important method relies on analysis of Channel State Information (CSI), which is sent at the physical layer of WiFi communication. CSI is detailed and useful for WiFi sensing. It gives a rich picture of how the wireless channel behaves. The problem is that CSI is not always easy to access. In many cases, it requires modified firmware and specialized hardware support, which limits how widely it can be used in practice.

Comparison of CSI-based identity recognition methods

The table above compares roughly 25 different systems, evaluating them across several key dimensions. The Paper column lists the name of each system, while the Identities column shows how many different people each system is capable of distinguishing between. The Accuracy column then reflects how reliably each system correctly identifies a person. On the technical side, the Pre-Processing column describes the signal processing techniques each system applies to clean and transform raw WiFi data before passing it to a machine learning model, and the Model Architecture column identifies what type of model is used. The Perspective column shows how subjects were positioned or moving during data collection, such as standing orthogonally, performing gestures, or typing keystrokes.

Beamforming entered the picture for a different reason. As mentioned earlier, it was introduced in WiFi 5 to improve throughput and make wireless communication more efficient. But beamforming also depends on environmental information that is similar to CSI. The difference is that this information is gathered on the transmitter side rather than the receiver side.

Comparison of BFI-based WiFi sensing methods

The key new dimensions here are the Inference column, showing the wide variety of tasks these systems tackle, from respiratory rate monitoring and crowd counting to sign language recognition.

In a typical beamforming setup, client devices send something called Beamforming Feedback Information (BFI) back to the access point. BFI is a condensed snapshot of current signal conditions. It tells the access point how the wireless channel looks so that it can adjust its transmission for better performance.

The key difference between CSI and BFI is that BFI is transmitted back to the access point without encryption. This makes it much easier to collect using standard, off-the-shelf hardware, without needing any special software modifications. That significantly lowers the bar for potential misuse. The privacy concern gets even more serious when you consider that the IEEE is already working on making WiFi sensing an official standard through the upcoming 802.11bf update and based on the current draft, without putting strong privacy protections in place.

KIT Researchers Demonstrate Phone-Free Identification

Researchers at KIT showed that people can be identified using only BFI data, even when they are not carrying a smartphone or any other wireless device. The method does not depend on a person bringing along a tracked gadget. It works using ordinary WiFi devices already present in the environment and already communicating with one another.

Placement of TP-Link Archer BE800 access points, measurement locations, and participant walking routes in the WiFi-based identity recognition experiment

As radio waves move through space and interact with the human body, they create patterns that can be captured, analyzed, and compared. In that sense, the process starts to resemble imaging, almost as if the wireless system were building a rough picture of a scene without using a camera. The result is not a photograph in the normal sense, but the data can carry enough structure to support identity inference.

WiFi Routers as Silent Observers

“The technology turns every router into a potential surveillance device,” says Julian Todt, one of the study’s authors. “If you regularly walk past a café that has a WiFi network, you could be identified without your knowledge and later recognized by government agencies or commercial companies.”

That is a serious warning, and it captures the core concern very well. Intelligence services and cybercriminals already have many easier ways to monitor people, including compromising CCTV systems or intercepting video communications. But wireless networks are different. They create a nearly invisible surveillance layer that already exists in a huge number of places.

Unlike earlier approaches that depended on LiDAR sensors or on reflection-based systems using walls, furniture, and human bodies, this method works with standard WiFi equipment. By collecting BFI data, researchers can build representations of people from several different viewing angles. These representations are then used to distinguish one person from another, even when the number of people is large. Once the machine learning model has been trained, the identification process can happen in just a few seconds.

BFI vs CSI accuracy as the number of WiFi packets increases. BFI reaches near-perfect accuracy almost instantly, while CSI requires hundreds of packets to approach similar performance

Experimental Results

The study involved 197 participants. The researchers reported that they were able to identify individuals with nearly 100% accuracy, regardless of viewing angle or walking style. That is an impressive result, but it did not come easily. To reach that level of accuracy, the model needed a substantial amount of machine learning training. Each person in the training set performed around 20 walking passes before the model was trained.

BFI vs CSI accuracy across different walking styles. BFI maintains near-perfect accuracy regardless of how a person walks or what they carry, while CSI struggles significantly when walking styles change

During the research two TP-Link Archer BE800 routers were used. The experiment relied on channels 37 and 85. It also used two non-overlapping 160 MHz channels in the 6 GHz band available under WiFi 6E. The hardware included Intel AX210 WiFi network adapters.

Accuracy of five WiFi identification systems as the number of people grows. BFId (BFI) and LW-WiID maintain near-perfect accuracy even at 170 individuals, while competing systems degrade sharply with FreeSense dropping to near 15% at scale

The researchers stress that the technology is powerful, but also potentially dangerous. The risks are especially serious in authoritarian states, where systems like this could be used for large-scale population surveillance. In such settings, the ability to identify people without their phones, without cameras and without obvious visible monitoring would be a major privacy threat.

For that reason, the authors strongly recommend that privacy protections and security safeguards be built into the upcoming IEEE 802.11bf standard from the start, rather than added later as an afterthought.

WiFi 6 Routers as Motion Sensors

In fact, WiFi-based sensing has become so effective that some modern routers already include motion-detection features right out of the box, and manufacturers openly advertise them.

Xfinity

Features such as WiFi Motion Detection allow homeowners to monitor activity inside their homes through mobile apps, using nothing more than changes in WiFi signal patterns.

A feature designed for convenience in a home can also become part of a much broader surveillance system when deployed at scale.

Related WiFi and Bluetooth Scanning Tools

As an additional note, several tools already exist that monitor wireless activity in nearby environments. They don’t work exactly the same way as the techniques we covered earlier, but they’re still useful.

Pi.Alert scans devices connected to a WiFi network, detects unknown devices, and sends notifications when devices unexpectedly disconnect from the network. It is often used as a practical awareness tool for keeping track of what is present on a home or local network.

WireTapper discovers nearby wireless signals, including WiFi networks, Bluetooth devices, hidden cameras, vehicles, headphones, televisions, and cellular towers. It gives the user a broader view of the wireless environment around them, which can be useful for awareness and inspection.

Video

We also have an video on this topic with Master OTW and Yaniv Hoffman. In the video, OTW explains how hackers can use SDR, AI, and Wi-Fi signals to detect human movement through walls, how the technology works, and talk about practical ways to defend against it. Feel free to check it out.

Summary

As modern routers gain advanced sensing, they can also become tools for observing and identifying people through the way their bodies interact with wireless signals. The KIT research shows that this is a practical technology that can identify individuals with remarkable accuracy using ordinary WiFi hardware. Although WiFi sensing can be valuable for smart homes and automation, it also raises serious privacy concerns. Privacy protections will need to become just as important as performance improvements.

If you’re interested in Wi-Fi security, our Wi-Fi Hacking training can help you gain the necessary experience. This attack vector is often underestimated, and many organizations are vulnerable to it. It is definitely valuable in penetration testing.

The post Wi-Fi Hacking: Wi-Fi Can Now Identify You Without Your Phone first appeared on Hackers Arise.

Drone Warfare: Ukraine’s Drone Industry, Part 3 – Export Strategy

1 July 2026 at 10:50

Welcome back!

This is the final article of our Drone Warfare series on Ukraine’s rise as a drone powerhouse. But Ukraine’s success story is not one it achieved alone. The country’s drone industry was built with the support of partners from around the world who helped Ukraine during its most difficult times. Here we look at Ukraine’s export strategy and how it can serve as a way to give back by sharing hard-earned battlefield experience and technology with the nations that helped make this success possible.

Battlefield Experience

For most of the war, Ukraine’s drone sector existed on the demand side of the defense market. The country needed huge volumes of FPV drones, interceptor drones and reconnaissance systems simply to keep pace with the battlefield. By 2026, that position began to change. Ukraine started to present itself not only as a state that needed drones, but as a state that could supply them, co-produce them, and teach others how to use them. In March 2026 President Volodymyr Zelenskiy discussed joint arms production with Dutch Prime Minister Rob Jetten and said Ukraine was ready to export interceptor drones that are not needed on its own battlefield.

interceptor
Interceptor drones and the latest AI developments. Source: Ukraine’s Arm Monitor

Ukraine is not trying to sell a platform developed in peacetime and polished for foreign buyers. It is offering weapons and systems that were shaped by daily combat against a technologically capable enemy. That gives Ukrainian exports a different value proposition. They are presented as battlefield-tested tools that have already survived the hardest possible proving ground.

The Export Model

Ukraine’s export strategy depends on the fact that it is producing more than it can immediately absorb on the front line in certain categories, especially interceptor drones. In June 2026 Ukraine said it could produce 2,000 interceptor drones per day, with about half potentially available beyond domestic needs, and that it could supply at least 1,000 interceptor drones a day to allies facing Shahed attacks if investment improves. That is the logic behind the export conversation. Ukraine is not opening the floodgates on every weapon it makes. It is identifying categories where production has moved beyond immediate domestic consumption.

Business Insider also reported that Ukraine wants to protect its own security first and only share technologies that do not compromise its battlefield position. That means exports are likely to focus on systems that are already partially superseded on the Ukrainian front, or on systems that can be co-produced under controlled conditions.

Europe

Europe is the most obvious destination for Ukraine’s export strategy because the continent is already moving in Ukraine’s direction. The Netherlands are going to spend €248 million on drones for Ukraine, with production split between the Netherlands and Ukraine. On 17 June 2026 the Netherlands pledged another €500 million for drones and air defense equipment. These are signs that European governments are beginning to fund drone production as an industrial activity.

drone with a gun attached to it
The Drone Squad Fury unmanned aerial platform developed by OM Defense Systems on display at the Eurosatory defense exhibition in Paris, June 2026. Source: Militarnyi

The broader European defense picture points the same way. It was reported that G7 countries and the United States had agreed to allow Ukraine-based and European firms to produce long-range missiles and air defense systems under license. Europe is no longer only buying Ukrainian results, it wants to buy into the production model behind them.

airbus' new drone models
Source: Airbus’ drone portfolio

The broader European defense market is also moving in Ukraine’s direction. For instance, Airbus partnered with the French counter-drone startup Alta Ares. Under the June 2026 memorandum of understanding, Airbus will integrate Alta Ares’ AI-guided interceptors, including the Black Bird and X-Lock systems, both combat-tested in Ukraine since 2024, into its Fortion IBMS command-and-control platform, connecting Alta Ares’ targeting software and interceptor drones to Airbus’ battle management systems to create a sensor-to-shooter chain against drone and cruise missile threats.

Middle East

The Middle East is the second major market because it faces a different but equally urgent drone threat. In March 2026 Zelenskiy said Ukraine was ready to send instructors to the Middle East and export interceptor drones that are not needed at home. Business Insider added that Ukrainian officials see older Ukrainian counter-drone technology as still useful for allies facing Shahed attacks, even if those systems are already outdated by Ukraine’s own battlefield standards. A weapon does not need to be the newest model to be valuable if the user’s threat environment is less intense than Ukraine’s.

middle east
Ukrainian interceptor drone in open terrain (desert-like background works well for the Middle East angle)

That makes the Middle East a natural fit for Ukraine’s export model because the buyer often wants a system, not just a drone. The package includes interceptor drones, training, radar integration, and electronic warfare resilience. Zelenskiy explicitly framed the issue that way, saying that without radar coverage and software that can operate under jamming, an interceptor is not a real defender.

Production

The most interesting part of Ukraine’s export strategy is not the sale itself. It is the move toward co-production. The point of co-production is to make exports more durable and less vulnerable to disruption. It also lets allies develop industrial capacity while Ukraine keeps access to the newest combat-tested designs. The G7 agreement reported by The Guardian shows a model where production can be shifted into partner territory while still drawing on Ukrainian experience and requirements. That approach helps solve three problems at once. It spreads risk away from the battlefield. It makes procurement faster for partners. And it creates a legal framework for sharing sensitive technology without handing over full control of the most advanced systems.

The Financial Logic

The export strategy also has a budget logic. Drone exports and co-production can help bring in foreign money, expand industrial capacity, and reduce pressure on the domestic defense budget. The Netherlands’ funding would support drones and air defense equipment for Ukraine, while Ukraine’s officials see export volume as a way to unlock more production capacity. The practical idea is that external orders help keep factories busy, while revenue and investment help scale the next generation of systems.

ukraine presents its technologies
Ukraine’s Drone Industry arrives in Düsseldorf. Source: DroneXL

This logic is important in wartime because the domestic state cannot fund every possible expansion on its own. Exports make production more sustainable. They also let Ukraine distribute risk across several partners rather than relying only on its own budget and wartime aid flows. In other words, the export strategy is partly about money, but it is also about industrial resilience.

Main Constraints 

Ukraine’s export strategy is still tightly constrained by its own security needs. Ukrainian officials want to keep priority for domestic forces and treat exports as selective. That means the country is not trying to become a free-market weapons bazaar in the middle of a war. It is trying to manage surplus capacity without weakening the front line. There is also the issue of sensitivity. Not every system can be exported, and not every partner can receive the same level of access. Licensed production in allied countries solves part of that problem, but only part. The more advanced the system, the more likely it is to remain under stricter Ukrainian control. That is why the export strategy is likely to be layered. That means some hardware is going to be sold directly, while some systems will be co-produced, some software and training will be shared for integration, and some capabilities will stay in-house.

Strategic Value

Ukraine’s biggest advantage in the export market is not price alone. It is combat credibility. Allies are interested because Ukraine’s drones and counter-drone systems were developed in the harshest possible environment. A state that has spent years fighting under heavy electronic warfare pressure, missile strikes, and mass drone attacks has something to offer that many peacetime defense industries do not. That does not mean Ukraine will dominate global drone exports. Competition is still strong, and certification with production security all remain real obstacles. But the country has already crossed an important threshold, where it’s no longer only asking for help. It is now a partner that can supply systems, share production, and train others to fight the same kind of war.

Conclusion

Europe wants production. The Middle East wants interception. Ukraine wants revenue and industrial depth. That creates a new model built around selective exports and battlefield-tested expertise. Ukraine is no longer only defending itself with drones, but it is using drone expertise to build alliances. That is the meaning of its export strategy today.

The post Drone Warfare: Ukraine’s Drone Industry, Part 3 – Export Strategy first appeared on Hackers Arise.

❌
❌