hacking
27 stories and discussions about hacking, aggregated from every source we track.
<p>With the latest release of Gitea, an experimental CI/CD feature was added. The above blog post details the technical details, including the various components including the open protocol to allow other CI systems to have the same integration.</p> <p>Disclaimer: While I am not the author of the post, I am involved in the Gitea project and am employed to work on Gitea</p>
Inside every modern CPU since the Intel Pentium fdiv bug, assembly instructions aren’t a one-to-one mapping to what the CPU actually does. Inside the CPU, there is a decoder that turns assemb…
Blog about reverse-engineering, hacking and breaking your software in every way imaginable.
We found vulnerabilities in the FIA's Driver Categorisation platform, allowing us to access PII and password hashes of any racing driver with a categorisation rating.
The FBI's Remote Operations Unit (ROU) is a highly secretive team of hackers making exploits and tools to break into target’s devices. Some of its members just got exposed.
Here's the story of how I learned about hexadecimal and bytes on disk by way of editing SimCity 2000 save games.
Here's the story of how I learned about hexadecimal and bytes on disk by way of editing SimCity 2000 save games.
We show for the first time that realistic AI training processes can accidentally produce misaligned models.
A public timeline of notable AI hacking and AI-enabled cyber incidents.
TeamPCP pulled off the worst-ever software supply-chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group says it had a mole inside the hackers’ inner circle.
TeamPCP pulled off the worst-ever software supply-chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group says it had a mole inside the hackers’ inner circle.
DeepSWE audit finds AI coding agents optimize for imagined graders, not users—a hidden reward hacking pattern.
Attackers extracted data belonging to roughly 200 customers of a software provider, with AI agents doing nearly all the work, Anthropic says.
ShinyHunters, a cyber-extortion outfit, said it hacked into the FBI’s jobs portal and used that access to steal a major tranche of sensitive files.
We found a clear internal signal in models that accompanies reward hacking, and built probes that detect it — enabling efficient, real-time detection of reward hacking at scale.
We’re joined by Ernie from Code for Miami and Mike Sarasti from the City of Miamia to talk about how local government can work together to open up data to enable developers to build amazing s…
For a few years now , the PS5 hacking community has been chipping away at various exploits that let users fully jailbreak their locked-down console. For the most part, though, those exploits have only worked with years-old versions of the PS5's frequently updated firmware , making them less than useful for many everyday users. That changed Tuesday with the release of the new Relapse exploit , which works with any PS5 up to firmware version 13.6 (released in July). That means jailbreaking is now possible on any PS5 that was last updated before the mid-September release of firmware version 14.00.00 . The so-called Relapse exploit makes use of a long-known WebKit vulnerability in the PS5's hard-to-access web browser , escalating from there to gain write access to the PS5 kernel and install an ELF loader to streamline the running of arbitrary code. The new method is also a lot more efficient than previous PS5 jailbreak exploits, which could hang the system for 50 minutes per attempt . Read full article Comments
In March, Janice Malone began getting calls about suspicious activity from her nonprofit organization, Vivian's Door. Vivian's Door, headquartered in Alabama, typically provided training, resources, and community to underserved and minority-owned businesses. The work sometimes put it in close contact with these companies' financial data, which was stored on its systems. But suddenly, concerned callers from all over the world warned they'd been getting emails "begging for money" - which she hadn't sent. The organization's third-party IT team pulled its systems offline for three days while they investigated the issue and plugged up the vulner … Read the full story at The Verge.
Before two of its alleged members were arrested and charged in Australia last month, the hacker group known as TeamPCP carried out a hacking spree unlike any other in history. It tainted hundreds of open-source programs with its malware, stole developer accounts to perpetuate that software supply-chain hacking, and even released a Dune -themed self-spreading worm to automate the process, ultimately breaching more than a thousand companies. Now Google’s threat intelligence group has revealed that during a key moment of TeamPCP’s rampage, the company’s own undercover researcher had infiltrated the group—allowing Google to monitor the hacking spree from the inside, warn breach targets, and even help disrupt the group’s attempts to exploit those victims. In a talk at security firm SentinelOne's LABScon research conference today, Google Threat Intelligence Group researcher Austin Larsen will present details on the company’s investigation—and infiltration—of TeamPCP amidst the group’s unprecedented, chaotic supply-chain hacking campaign. According to Larsen, Google eventually followed a trail of operational security mistakes allegedly made by one of the two Australians now accused of being leading members of the hacker group and passed on key identifying details to law enforcement. The company also received intelligence from ShinyHunters, another infamous cybercriminal group that TeamPCP partnered with, but which later turned on the supply-chain hackers. And perhaps most surprisingly, Larsen says that Google’s security subsidiary Mandiant had an undercover analyst—not himself—within the group’s inner circle from almost the beginning of TeamPCP’s time in the spotlight. Read full article Comments