❌

Normal view

There are new articles available, click to refresh the page.
Yesterday β€” 12 September 2026HackingPassion

Mullvad Says Any Android App Can Send Your IP Past the VPN Kill Switch

By: Author
12 September 2026 at 08:23

Mullvad Says Any Android App Can Send Your IP Past the VPN Kill Switch

Your phone kept sending its address out on a 10 second timer while the VPN kill switch was on, to a server the app picked. Mullvad says any app can do it. Most phones from Android 12 on are open.

Android has a setting called Block connections without VPN. Switch it on and the phone is supposed to refuse to send anything at all the moment traffic would travel outside the tunnel. Fail closed. That promise is why people switch it on, and it is what a lot of you are relying on right now.

Before yesterdayHackingPassion

BlueMoon Chained Two Chrome Bugs to a Windows Flaw While the Fix Sat in Public for 27 Days

By: Author
10 September 2026 at 08:38

Five spy crews broke into Chrome with the same kit in seven days. The victims clicked one link in an email. Google fixed the first hole on August 7. It reached your browser on September 3.

The mail looked normal. The link looked normal. You clicked, a page started loading, and it sat there for a few seconds. Then it dropped you at github.com, a site you know. The browser never said a word. By then somebody else was already running code on your machine.

LG TVs Counted 38 Devices in One House and Logged What People Said Out Loud

By: Author
9 September 2026 at 07:27

Your LG television counted 38 devices in the house that have nothing to do with television. Phones, smartwatches, a printer, the thermostat. The set was not hacked to do it. This is the TV doing its job.

Researchers bought a brand new LG G5 OLED at a Best Buy, plugged it into the network and watched the traffic with Wireshark. What came out was an inventory of the building.

The set swept the local network and came back with at least 38 other devices. Per device it picked up the display name, the MAC address, the internal IP address and the signal strength. A 3D printer. An ESP32 development board. An air purifier. It found the internal servers, and a Samsung phone with a staff member’s username still attached, belonging to someone who had no idea any of this was being tested. A colleague’s Galaxy S23. A Note 9. An Alienware used for backup editing. And on one of the editing machines the television worked out that TeamViewer was running.

Liquid Network Paid Out 3,996 Bitcoin for Coins That Never Existed

By: Author
8 September 2026 at 07:33

An attacker emptied a vault of 3,996 bitcoin and then asked the owners to contact him. He wrote the message into the blockchain, where the rest of us could read along. What happened next was not a ransom.

On Sunday a payment left the bitcoin wallet that the company behind Liquid keeps as the backing for its own coin. 3,996 bitcoin went out, around 320 million dollars, and 197 stayed behind. Eleven of the fifteen companies that guard that wallet had put their signature under it, and each signature was correct. As far as the software could tell, a customer had walked up to the counter and asked for his money.

PostgreSQL Logical Decoding Flaw Let a Replication Account Take Over the Server for 12 Years

By: Author
7 September 2026 at 07:45

A database account that was only allowed to copy data could run commands on the server itself. The admins never gave it that right. The hole has been open since PostgreSQL 9.4 shipped in 2014, twelve years.

That account has one job. It has no rights on your tables and it cannot create or drop anything. It gets permission to follow along with what changes in the database, because a backup tool or a standby server has to know what happened. In PostgreSQL that permission is called REPLICATION.

WhatsApp Video Calls Open Your Photo Gallery on a Locked Android Phone

By: Author
3 September 2026 at 08:05

Your locked Android phone opened its photo gallery to the person holding it. One video call and four taps did it. A Pixel on Android 17 with the newest patch went through, and there is still no fix.

The phone lies face down, screen off, locked. A WhatsApp video call comes in. You swipe to answer it, the way you answer any call, because taking a call without unlocking first is exactly what a lock screen is built to allow. The call connects. Then you tap the effects icon on the call screen, open the backgrounds tab, choose Create with Meta AI, and tap Edit photo.

uBlock Origin Removed From the Chrome Web Store as Google Closes Out Manifest V2

By: Author
2 September 2026 at 07:41

Your ad blocker stopped working thirteen months ago. Chrome 138 switched it off in July 2025. On August 31 Google pulled the last copy from the store. Edge, Brave, Opera and Vivaldi run the same engine.

On August 31, 2026, Google took the last Manifest V2 extensions out of the Chrome Web Store. uBlock Origin was among them. A copy that is already installed keeps its files and keeps running, but it will not receive another update and it cannot be installed again from the store.

Hiding your WiFi name doesn't protect you. It makes you a bigger target.

By: Author
31 August 2026 at 10:33

Hiding your WiFi name doesn’t protect you. It makes you a bigger target. People think hiding their SSID (WiFi network name) is secure. It’s not. Your devices leak the SSID anyway. Your phone constantly searches for hidden networks, and it keeps doing that everywhere you take it.

Hiding the name does not make your network quiet. It makes your phone loud.

And your phone goes with you. To work, to the doctor, to the supermarket, to your friend’s house. The one setting you switched on to protect your home is the thing your phone shouts about your home when it is nowhere near it.

SLEEPWALKER Backdoor Hides in a Security Agent and Wakes Up for One Packet

By: Author
30 August 2026 at 06:13

SLEEPWALKER Backdoor Hides in a Security Agent and Wakes Up for One Packet

5 bytes of orders sit inside a backdoor that has never once called home. It reads what crosses your network cable and waits. The security agent it hides in loads it again at each restart.

Dominik Reichel, who used to hunt malware at Palo Alto Unit 42, published the analysis on August 24. He named it SLEEPWALKER, because that is what it does. It sits in memory and does nothing at all until one specific packet crosses the network cable, and then it wakes up and runs whatever the sender told it to run.

Weedhack Hides Inside Fake Minecraft Clients That Outrank the Official Downloads in Google

By: Author
29 August 2026 at 06:53

Your kid downloaded a Minecraft client from the first result in Google. It cost the attacker 5 dollars, the panel behind it has logged 116,464 infections, and the webcam is part of what he paid for.

Minecraft is the best selling video game ever made, and almost none of it gets played plain. Players install clients, mods and utilities that add what Mojang never shipped, and those tools live on GitHub, on Modrinth and on the personal pages of the people who wrote them. No app store sits in the middle checking anything. You search for the tool by name, you click a link, you download a JAR file, and you run it. That habit is where the attack lives.

WhatsApp Signal Telegram and What Eight Messaging Apps Know About You

By: Author
26 August 2026 at 10:05

Eight Messaging Apps and What Each One Knows About You

Your messages are encrypted and that is the smallest part of it. Who you talk to, when, how often and for how long sits outside the encryption. 8 apps give 8 different answers about what is left.

People have put the same thing to me for years, in one form or another. My messages are end to end encrypted, so there is nothing left to know about me. That is the belief, and it is wrong. The reason is not a scandal and not a leak. It sits in documents these companies publish themselves, in plain language, and those documents are barely read.

ShieldBreak Turns Windows Defender Into a Way to SYSTEM on Fully Patched Windows 11

By: Author
24 August 2026 at 09:24

Nightmare Eclipse published his tenth Windows attack and it lifts a normal account to SYSTEM. It only works on machines with Defender switched on. It is a full bypass of the patch Microsoft shipped in July.

I have been following this researcher since April, through BlueHammer, RedSun, UnDefend, YellowKey, MiniPlasma, RoguePlanet, GreatXML and LegacyHive. Eight articles. After the last one it went quiet on my side while it kept moving on his, so I went back to find out how he is doing now, what he has released since July, and where this fight actually stands.

Arrayref Rust Crate Hijacked to Run Malware While Your Project Compiled

By: Author
23 August 2026 at 08:02

Your Rust build pulled in a backdoor for 86 minutes on Thursday. Five versions with 246 million downloads between them were pulled in 16 seconds, leaving one poisoned release to land on.

At 07:15 UTC on 20 August a new version of a Rust package called arrayref showed up on crates.io. That package had been sitting there since August 2015. One file, 327 lines of code, nine kilobytes on disk, and it does one small job: it lets you grab a fixed number of bytes out of a longer run of them. In almost eleven years it had never needed anything else to do that.

WiFi Motion Turns Millions of Home Routers Into Motion Sensors

By: Author
20 August 2026 at 08:24

Your router now reports when someone walks through your house. You installed no sensor. There is none. A phone indoors gave up a person’s breathing to a receiver three meters outside the wall.

The radio waves coming out of your router do not stop at the wall. They go through it, bounce off the floor, the cupboard and the person walking to the kitchen, and arrive at your phone along dozens of paths at slightly different times. Something in the room moves, those paths change, and the receiving device measures that change constantly, because it needs to know which speed and which antenna to use.

Zombie Card Attack Revives Expired Credit Cards for Contactless Payments

By: Author
19 August 2026 at 07:17

Expired credit cards still paid at the checkout. Researchers spent $500 on one, then $2.79 in a shop. The cards had already been handed in for a replacement, and the account behind them stayed open.

A payment card sells one promise on its front. The date printed there is the day the card stops working. Shops rely on it, banks rely on it, and you rely on it when you drop an old card in a drawer instead of destroying it. Researchers at the University of Massachusetts Amherst took that promise apart. Their finding is that the date is not a property of the card at all. The date is a policy, checked in different places by parties that never compare notes, and a card that is past it can still pay.

Evooo1Bot Turns Home Routers Into Rented Proxies With a Bug From 2007

By: Author
17 August 2026 at 07:15

A botnet is breaking into home routers with a bug from 2007. Ten known holes, and a list of 150 common logins. Nobody in the house clicked on anything. The internet still works fine.

The bug from 2007 is a command injection in a phone system management tool. Send it a few extra characters where it expects a hostname, and it runs whatever was put there. It was published on September 18, 2007. It scores 9.8. CISA still lists it as actively exploited, nineteen years later.

Windows Defender Dies to a One-Click Script While Defender Bypasses Sell for $30 a File

By: Author
15 August 2026 at 09:53

Windows Defender Dies to a One-Click Script While Defender Bypasses Sell for $30 a File

A script created an account on a fully secured Windows 11 machine, killed the antivirus Windows says cannot be killed, and ran a payload. It needed one click. Its memory had no write protection. 🧐

The machine had everything switched on. Secure Boot, driver signature enforcement, PatchGuard, Virtualization-based Security, Hypervisor-Enforced Code Integrity. Those are the protections Microsoft built specifically so that an attacker who already has administrator rights still cannot reach the core of Windows. All of them held. The memory did not.

Plug and Pwn Turns a Fake USB Device Into SYSTEM on Fully Patched Windows 11

By: Author
13 August 2026 at 08:09

Plug and Pwn Turns a Fake USB Device Into SYSTEM on Fully Patched Windows 11

Two researchers took over a fully updated Windows 11 machine in five minutes with a USB device that was never there. The machine sat at the login screen. Windows downloaded the vulnerable software itself. 🧐

Plug and Play is the part of Windows that makes hardware work without you doing anything. You connect a printer, a webcam, a phone, and a few seconds later it works. What happens in those seconds is that the device announces what it is, Windows takes that announcement at face value, looks up the matching software package at Microsoft, downloads it, and installs it. That installation does not run as you. It runs as NT AUTHORITY\SYSTEM, the account with more power on the machine than the administrator has, and it never asks permission, because there is no prompt anywhere in that flow.

Pass the Passkey Attack Bypasses Entra ID MFA Using a Windows Log

By: Author
11 August 2026 at 08:15

Someone could sign in as a company’s top admin by reading one Windows log file. The admin’s password and passkey were never touched. Microsoft called it medium severity and paid the finder 1,000 dollars. 🧐

Passkeys were supposed to make this impossible. Instead of a password you type, your device holds a secret key and proves who you are with it. The key is never typed and never sent to a website, so a fake login page has nothing to grab. That is why they are called phishing-resistant, and Microsoft is pushing them hard. On September 1, 2026 it switches passkeys on by default and starts nudging users still on text or voice codes to register one. That nudge can be snoozed. The hard deadline is February 1, 2027. After that, if a text or voice code is your only way in, you have to register a passkey before you can sign in, and companies cannot opt out.

Linux Kernel SCTP Flaw Let Local Users Gain Root for 18 Years

By: Author
10 August 2026 at 06:43

An AI found a hole in the Linux kernel that sat open for 18 years, then wrote the exploit that turns a local user into root. The machines were not misconfigured. The bug was in the kernel itself, since 2007. 🧐

Researchers at Tencent’s Zhuque Lab published the full analysis on 6 August. They track it as CVE-2026-64564 and named it SCTPhantom. It lets a normal user on a Linux machine climb all the way to root, and from inside a container it can break out onto the host underneath. The code that made this possible went in during December 2007. It reached users with kernel 2.6.25 in April 2008, and has been in the kernel ever since. The fix landed at the start of August. That is eighteen years of a flaw sitting in a file few people ever open. It could not have been used this way in 2008, though. The path to root Tencent built relies on kernel machinery that did not exist yet.

❌
❌