Elektrine lite

← Feed

HackMag — Top-notch cybersecurity magazine

hackmag@infosec.exchange

<p>Daily news and articles for ethical/legal hackers, information security specialists, researchers, developers, and all other IT enthusiasts.</p><p>This account is automated, but it doesn&#39;t mean there will be no real person (<span class="h-card" translate="no"><a href="https://mastodon.social/@mechanism8" class="u-url mention">@<span>mechanism8</span></a></span>) behind.</p><p>We do not support illegal activities in any form or shape.</p><p>For support: support@hackmag.com; for editorial inquiries: staff@hackmag.com.</p>

Posts

  • View post

    ⚪️ Chrome and Edge Extensions Stole Cryptocurrency 🗨️ Researchers at Socket discovered 18 malicious extensions for Google Chrome and one for Microsoft Edge. All of the extensions loaded a modular framework designed to steal victims’ cryptocurrency, credentials, and browser history, while also displaying ClickFix lures. Researchers have dubbed… 🔗 https://hackmag.com/news/superior?utm_source=mastodon&amp;utm_medium=social&amp;utm_campaign=repost_hackmag_to_socials #news

  • View post

    ⚪️ Investigating a Credential Stuffing Attack on Linux: A Digital Forensics Guide 🗨️ Today, we will practice traffic analysis using Wireshark, examine a credential-stuffing brute-force attack, and analyze the attacker’s persistence technique within the system. We will then build an event timeline. 🔗 https://hackmag.com/security/sherlocks-meerkat?utm_source=mastodon&amp;amp;utm_medium=social&amp;amp;utm_campaign=repost_hackmag_to_socials #security

  • View post

    ⚪️ Reverse Engineering Binary Files: A Hands-On Guide Using libexif 🗨️ When I was first getting into the world of hacking, I was severely short on information and had to gather it bit by bit. In this article, I’ll try to provide what I was missing back then: a concise, structured overview of reverse engineering. To make things more practical, we’ll walk through a r… 🔗 https://hackmag.com/security/reversing-guide?utm_source=mastodon&amp;amp;utm_medium=social&amp;amp;utm_campaign=repost_hackmag_t...

  • View post

    ⚪️ Reverse Engineering the Liposonix Cartridge and Building an Emulator 🗨️ In this article, I’ll explain how real-world medical equipment is reverse-engineered. Using a cartridge for the Liposonix system as an example, we’ll cover the basics of reverse-engineering digital-device protocols and see how transmitted data can be spoofed. As it turns out, an ATmega microcontr… 🔗 https://hackmag.com/security/liposonix-hack?utm_source=mastodon&amp;amp;utm_medium=social&amp;amp;utm_campaign=repost_hackma...

  • View post

    ⚪️ EIGRP Route Table Poisoning with Python 🗨️ In this article, I’ll show how to use Python to inject rogue routes into an EIGRP domain. With some luck, such an injection could allow an attacker to perform a man-in-the-middle (MITM) attack or temporarily cause disruption within the routing domain. We’ll examine the process of establishing adj… 🔗 https://hackmag.com/stuff/eigrp-scam?utm_source=mastodon&amp;amp;utm_medium=social&amp;amp;utm_campaign=repost_hackmag_to_socials #stuff

  • View post

    ⚪️ Emerging Cybersecurity Research Trends and Insights 🗨️ Today, we’ll take a look at the latest trends in cybersecurity, explore the new ideas currently on the minds of security professionals—including my own team—and review some relevant publications you may want to read. 🔗 https://hackmag.com/security/research-review?utm_source=mastodon&amp;amp;utm_medium=social&amp;amp;utm_campaign=repost_hackmag_to_socials #security

  • View post

    ⚪️ OpenAI publishes official report on July Hugging Face breach 🗨️ Specialists from OpenAI and the research organization METR have published detailed reports on the July attack on the Hugging Face platform involving AI agents. It emerged that around 1,200 agents, which were supposed to operate in isolation from one another,… 🔗 https://hackmag.com/news/hugging-face-post-mortem?utm_source=mastodon&amp;amp;utm_medium=social&amp;amp;utm_campaign=repost_hackmag_to_socials #news

  • View post

    ⚪️ Two Members of the TeamPCP Hacking Group Arrested in Australia 🗨️ The Australian Federal Police (AFP) reported the arrest of two suspected members of the TeamPCP hacking group, which has been linked to large-scale supply chain attacks. According to investigators, the group’s attacks may have affected more than 1,000 organizations worldwide,… 🔗 https://hackmag.com/news/teampcp-arrest?utm_source=mastodon&amp;amp;utm_medium=social&amp;amp;utm_campaign=repost_hackmag_to_socials #news

  • View post

    ⚪️ Calling Native WinAPI from C#: Techniques for Managed-to-Native Interoperability 🗨️ One of the few drawbacks of C# is that calling WinAPI methods can be somewhat cumbersome. While many capabilities have already been wrapped in .NET assemblies, developers still frequently need to call Win32 functions directly. In such cases, P/Invoke, D/Invoke, and related techniques are used. I… 🔗 https://hackmag.com/stuff/csharp-winapi-tutorial?utm_source=mastodon&amp;amp;utm_medium=social&amp;amp;utm_campa...

  • View post

    ⚪️ ToxicPanda Malware Abuses Android VPN Mechanism to Block Access to Google Play 🗨️ Researchers warn about the emergence of an updated version of the ToxicPanda Android Trojan. It supports 167 remote commands, can block access to the Google Play store, and automatically abuses Wireless ADB to gain shell access. The malware’s target list… 🔗 https://hackmag.com/news/toxicpanda-2-0?utm_source=mastodon&amp;amp;utm_medium=social&amp;amp;utm_campaign=repost_hackmag_to_socials #news

  • View post

    ⚪️ Qilin Ransomware Operators Claim to Have Hacked the ATF 🗨️ Representatives of the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed that one of its systems had been compromised. Shortly before that, members of the Qilin ransomware group claimed to have breached the ATF and added the agency… 🔗 https://hackmag.com/news/qilin-atf?utm_source=mastodon&amp;amp;utm_medium=social&amp;amp;utm_campaign=repost_hackmag_to_socials #news

  • View post

    ⚪️ How EDR Works: A Detailed Guide to Endpoint Detection and Response Protection 🗨️ *Hacker* magazine often covers process and system call hiding, code obfuscation, and other ways to evade AV/EDR solutions. But what if you want to do more than just follow instructions and instead discover such techniques on your own? At a minimum, that requires understanding the general princip… 🔗 https://hackmag.com/malware/inside-edr?utm_source=mastodon&amp;amp;utm_medium=social&amp;amp;utm_campaign=repost_ha...

  • View post

    ⚪️ $1.1M Crypto Hack Sends Neobank Token Down 49% 🗨️ A vulnerability in an outdated payment-infrastructure contract for the Rain crypto card led to the theft of approximately $1.1 million across several programs on the Solana blockchain. Neobank Avici was hit hardest: the attacker stole more than $500,000 from 1,685… 🔗 https://hackmag.com/news/avici-token-hack?utm_source=mastodon&amp;amp;utm_medium=social&amp;amp;utm_campaign=repost_hackmag_to_socials #news

  • View post

    ⚪️ Cronos Network Halted Following Tectonic Protocol Hack 🗨️ On August 30, 2026, Cronos blockchain validators halted the network after an attacker drained Tectonic, the network’s largest lending protocol, by artificially inflating the price of the TONIC token. According to analyst Weilin Li, the losses amounted to approximately $66–75… 🔗 https://hackmag.com/news/cronos-tectonic-hack?utm_source=mastodon&amp;amp;utm_medium=social&amp;amp;utm_campaign=repost_hackmag_to_socials #news

  • View post

    ⚪️ Creating Images on Radio Waterfall Displays: A Guide to RF Artwork 🗨️ A waterfall display is a way of visualizing signals that can be found in virtually every radio software application. Each horizontal line shows the signal spectrum—its frequencies and amplitudes. With a bit of tinkering, you can even draw images on a waterfall display. That is what we will be doi… 🔗 https://hackmag.com/security/drawing-on-waterfall?utm_source=mastodon&amp;amp;utm_medium=social&amp;amp;utm_campaign=repost_ha...

  • View post

    ⚪️ Errors in llms.txt Make Claude, Codex, and Hermes Execute Third-Party Code 🗨️ Researchers found that llms.txt and llms-full.txt files on 120 websites contained links to unregistered packages and domains. AI agents including Claude, OpenAI Codex, and Hermes treat instructions in these files as trusted documentation and actually execute the specified commands. As… 🔗 https://hackmag.com/news/llms-txt?utm_source=mastodon&amp;amp;utm_medium=social&amp;amp;utm_campaign=repost_hackmag_to_socials #n...

  • View post

    ⚪️ Google Announces Encrypted Client Hello (ECH) Support in Android 17 🗨️ Android 17 introduces system-level support for Encrypted Client Hello (ECH), making it harder for ISPs and other observers to determine which websites and services a user is accessing. Although Android 17 was released back in June 2026 and already included… 🔗 https://hackmag.com/news/android-ech?utm_source=mastodon&amp;amp;utm_medium=social&amp;amp;utm_campaign=repost_hackmag_to_socials #news

  • View post

    ⚪️ Anthropic Warns Users About Infostealer Attacks 🗨️ Anthropic representatives are warning users about a new scheme involving abuse of Claude accounts. Infostealers steal active sessions from victims’ browsers, allowing attackers to access other people’s accounts and use up their available limits. Anthropic is currently sending targeted notifications… 🔗 https://hackmag.com/news/anthropic-stealers?utm_source=mastodon&amp;amp;utm_medium=social&amp;amp;utm_campaign=repost_hackmag_to_socials #news

  • View post

    ⚪️ Two More Backdoors Found in ZBT Routers 🗨️ Researchers at VulnCheck have discovered two previously unknown implants in the firmware of routers made by Chinese manufacturer Shenzhen Zhibotong Electronics (ZBT). Both allow a remote attacker to connect to the device without authentication and execute commands with root privileges.… 🔗 https://hackmag.com/news/zbt-backdoors?utm_source=mastodon&amp;amp;utm_medium=social&amp;amp;utm_campaign=repost_hackmag_to_socials #news

  • View post

    ⚪️ Reverse Engineering a Python Application with a Custom Interpreter 🗨️ Reverse-engineering applications written in Python is not always straightforward. Developers know how to protect their secrets using obfuscation, encryption, custom marshaling formats, and proprietary interpreters. But every lock has a pick: today, we’ll explore how to reverse-engineer such progr… 🔗 https://hackmag.com/security/custom-python?utm_source=mastodon&amp;amp;utm_medium=social&amp;amp;utm_campaign=repost_hackmag_t...

  • View post

    ⚪️ Hackers Are Exploiting PaperCut Zero-Day Vulnerabilities 🗨️ PaperCut developers warn that attackers are actively exploiting two zero-day vulnerabilities in PaperCut NG and MF. Together, these flaws allow authentication bypass and remote execution of arbitrary code on a vulnerable server. The company has already released two emergency updates,… 🔗 https://hackmag.com/news/papercut-0days?utm_source=mastodon&amp;utm_medium=social&amp;utm_campaign=repost_hackmag_to_socials #news

  • View post

    ⚪️ Linux Data Encryption: Choosing Between LUKS, eCryptFS, and ZFS Encryption 🗨️ Many Linux distributions offer built-in security options such as full-disk encryption (LUKS), folder and file encryption (eCryptFS), or even encryption provided by ZFS—a filesystem not native to Linux. Which of these available approaches makes the most sense today? Let’s take a closer look. 🔗 https://hackmag.com/unix/luks-ecryptfs-zfs?utm_source=mastodon&amp;utm_medium=social&amp;utm_campaign=repost_hackmag_to_socia...

  • View post

    ⚪️ Four Bytes of Power: How I Found the CVE-2021-26708 Vulnerability in the Linux Kernel 🗨️ In January 2021, I discovered and fixed five vulnerabilities in the Linux kernel’s virtual socket (vsock) implementation, collectively tracked as CVE-2021-26708. In this article, I will show how they can be used to compromise the entire operating system while bypassing the platform’s security mec… 🔗 https://hackmag.com/unix/linux-core-cve?utm_source=mastodon&amp;utm_medium=social&amp;utm_campaign=repost_h...

  • View post

    ⚪️ Automating Data Collection and Processing from MikroTik Network Devices 🗨️ Suppose we have MikroTik equipment with firewall rules designed to detect port scanning. We need to keep a daily record of the IP addresses involved and email a report to the security team. Let’s write a script to automate the entire process. 🔗 https://hackmag.com/devops/mikrotik-automation?utm_source=mastodon&amp;utm_medium=social&amp;utm_campaign=repost_hackmag_to_socials #devops

  • View post

    ⚪️ Pavel Durov explains why Telegram was removed from the App Store 🗨️ Apple briefly removed Telegram from the App Store worldwide. According to Pavel Durov (listed by Russia’s Federal Financial Monitoring Service as a terrorist and extremist), the reason was prohibited content posted by a user in a public group. Durov said… 🔗 https://hackmag.com/news/tg-app-store?utm_source=mastodon&amp;utm_medium=social&amp;utm_campaign=repost_hackmag_to_socials #news

  • View post

    ⚪️ Coldcard Hacker’s Wallets Turned into a Bulletin Board 🗨️ The addresses holding the bitcoins stolen in the major attack have unexpectedly turned into a public bulletin board: hacking victims and enterprising users are paying small amounts to leave messages for the hacker directly on the blockchain. This refers to… 🔗 https://hackmag.com/news/coldcard-hacker-messages?utm_source=mastodon&amp;utm_medium=social&amp;utm_campaign=repost_hackmag_to_socials #news

  • View post

    ⚪️ How Scammers Hide Their Websites Online: The Art of Digital Camouflage 🗨️ When analyzing scam websites, one cannot help but be impressed by the ingenuity of fraudsters. Some sites are so convincing that it is not immediately obvious they are fraudulent. However, before you can examine a website created by online criminals, you first need to find it. In this article, we… 🔗 https://hackmag.com/security/phishing-domains?utm_source=mastodon&amp;utm_medium=social&amp;utm_campaign=repost_hackmag_to...

  • View post

    ⚪️ UK Police and Civil Servant Data Leaked on the Dark Web 🗨️ Representatives of the UK’s Police National Legal Database (PNLD), which provides legal information to police and criminal justice agencies, reported a data breach. The names and work email addresses of police officers, civil servants, and other users of the service… 🔗 https://hackmag.com/news/pnld-leak?utm_source=mastodon&amp;utm_medium=social&amp;utm_campaign=repost_hackmag_to_socials #news

  • View post

    ⚪️ Firmware Extraction: How Attackers Read Device Memory and How to Defend Against It 🗨️ As kids, we all grabbed a screwdriver and took apart some gadget to figure out how it worked. But the days when devices didn’t resist being explored are long gone: now every coffee maker seems designed to stop you from examining it. Is there a way around that? Yes. Today, we’ll look at how to ex… 🔗 https://hackmag.com/security/instrumental-investigation?utm_source=mastodon&amp;utm_medium=social&amp;utm_camp...

  • View post

    ⚪️ OpenWrt Fixes Critical Vulnerability in DHCPv6 Server 🗨️ OpenWrt developers have released updates that fix a critical vulnerability in the DHCPv6 server. The flaw allowed an unauthenticated attacker to execute arbitrary code with root privileges and potentially fully compromise a vulnerable router. The issue, tracked as CVE-2026-53921 (CVSS… 🔗 https://hackmag.com/news/openwrt-patch?utm_source=mastodon&amp;utm_medium=social&amp;utm_campaign=repost_hackmag_to_socials #news