Search results

  1. Depov

    PirateFi is finally caught. The creator of malicious games on Steam was calculated by orders from Uber Eats

    The FBI Detained 21-year-old Florida on suspicion of organizing a major campaign to steal cryptocurrency through fake video games on the Steam platform. According to U.S. prosecutors, Zaire Wilkins, along with several unidentified accomplices for two years, placed games on Steam...
  2. Depov

    Do You Use 7-Zip? Congratulations, one click on the attachment in the letter will turn your PC into a hacking tool

    A regular archive can turn into a tool to hack a computer. The developer 7-Zip has released a version of 26.02 that closes the vulnerability in XZ file processing. With a successful attack, the attacker could run malicious code with user rights. The problem, which received the...
  3. Depov

    It vacuumed - and leaked the password from Wi-Fi. FlashNinja Vulnerability allows you to control someone else's vacuum cleaner via the Internet

    Robot vacuum cleaners have long been driving around their homes unattended, but some Shark models, along with cleaning, opened an inconspicuous path for outsiders. A security specialist has discovered a critical vulnerability that allows the Internet to execute commands on devices, manage their...
  4. Depov

    5 Habits That Will Make You A Better Hacker

  5. Depov

    Langflow IDOR CVE-2026-55255: step-by-step operation of cross-tenant vulnerabilities in the AI platform

    On June 25, 2026, Sysdig Threat Research Team recorded the first confirmed operation CVE-2026-55255 - IDOR-vulnerability in Langflow. Until this point, not a single report on the use in the wild did not exist. The operator in twenty seconds moved from listing others AI-workflow to the...
  6. Depov

    MuddyWater Operation Olalampo: eublification of attacks through malicious macros Office – Red Team playbook

    Business logic of attack: why emulate MuddyWater APT MuddyWater (Boggy Serpens, Mango Sandstorm, TA450) - a group under the authority of the Ministry of Intelligence and Security of Iran (MOIS), active since 2017 (MITRE ATT&CK G0069) Goals - state institutions, telecom, energy, defense, oil and...
  7. Depov

    GPT-5.6 users encountered deleting personal files and databases

    The more rights the AI agent receives, the more expensive even a small error is - soon after the launch of the GPT-5.6, several users faced deleting files without confirmation. The OpenAI acknowledged the problem and reported that it was preparing additional restrictions for dangerous...
  8. Depov

    Just enter the phone number and read other people's correspondence. How NSO Group turned total surveillance into a convenient web service

    To hack a smartphone with Pegasus, the operator often needs to know the victim’s phone number. The rest of the work is taken by the complex infrastructure of the NSO Group, which determines the model of the device, selects a way of infection, hides the source of the attack and delivers stolen...
  9. Depov

    Nightmare Eclipse has ruined Microsoft’s weekend. Meet the electlite LegacyHive

    Even fully updated Windows does not always protect against already known techniques: published exploit LegacyHive allows the average user to prepare the code with administrator rights the next time the privileged account is entered. The author under the pseudonym Nightmare...
  10. Depov

    Protection of corporate SaaS from hacking: ShinyHunters attacks on Salesforce and SharePoint

    In October 2025, the extortion group ShinyHunters launched a darknet platform with the data of six organizations - Albertsons, Fujifilm, Gap, Qantas, Engen Resources, Vietnam Airlines - and announced the compromising about a billion records from Salesforce-instorms of 39 companies. Among the...
  11. Depov

    GitHub Supply Chain Attack: Megalodon Campaign Analysis and CI/CD Pipple Line Protection

    Discallimmer: The "Megaloodon" campaign is described on the basis of the publications StepSecurity and SafeDeep, which at the time of writing were not independently verified and not confirmed by NVD, CISA or other reputable sources. All IoCs (IP addresses, email, SHA of commissions, names of the...
  12. Depov

    Do you use a webcam in the bedroom? Urgently update the firmware until Wi-Fi neighbors intercept access to the broadcast

    Home cameras rarely leave the LAN, but vulnerabilities in the TP-Link Kasa EC70 and EC71 allow the attacker inside it to intercept administrator accounts and receive information about the location of the device. The most dangerous vulnerability CVE-2026-9770 received a score of 8.6 points on...
  13. Depov

    Do you trust the code from artificial intelligence? Congratulations, hackers have learned to introduce vulnerabilities there for only $100

    Replacing the behavior of the neural network was easier and cheaper than many expected. Cybersecurity specialist Kathy Paxton-Fair introduced a hidden vulnerability into an open-weight model about an hour and spent less than $100 experiment on the experiment. At first, Paxton-Fir...
  14. Depov

    The 502 error, and Gemini fixed it himself. AI in six minutes unfolded a new server to control the botnet

    The hacking version of Gemini deployed a new botnet control server in six minutes, corrected the error and helped bring the infected computers back to the network. At the same time, a person only set tasks in colloquial language and followed the hints of artificial intelligence. The...
  15. Depov

    The Mistake That Changed Hacking Forever

  16. Depov

    ICS Industrial Robot Pentest: Operation CVE-2026-8153 in Universal Robots PolyScope

    In May 2026, CISA and Universal Robots simultaneously rolled out on the advisory CVE-2026-8153 - OS command injection in Dashboard Server interface PolyScope 5 with CVSS 9.8 (Critical). For operation, you need TCP access to the port of 29999 and zero accounts: the controller takes user input and...
  17. Depov

    UNC1549 Iranian APT campaign 2026: Job Lure, cloud C2 and detection for SOC

    Six new RAT variants in six weeks, C2 traffic goes through Microsoft Azure, initial infection is disguised as the recruitment process in a global airline. Samples are loaded to VirusTotal from organizations in the US and Israel - this is the Unit 42 data, not abstract "experts count". For...
  18. Depov

    Password is not needed, you don’t need access – only one “right” request. NGINX fixes vulnerabilities in its systems

    One unsuccessfully processed query can turn a web server into an entry point for an attack. F5 has uncovered three vulnerabilities in NGINX Plus and NGINX Open Source, which allow you to cause a malfunction of work processes, get fragments of data from memory, and under certain conditions to...
  19. Depov

    Did you think no one would find your profile on onlyFans? The neural network of the personnel officer already compares it with your face in the resume

    Employers are increasingly checking the digital footprint of applicants using artificial intelligence. If earlier personnel officers were limited to a quick search by name, new systems compare data from dozens of sources, find old publications and associate accounts that the person considered...
  20. Depov

    Write a password in the Notebook so that the flash drive erass its past. Enthusiasts have created the perfect drive for paranoid

    Normal encryption protects files until the owner discloses the password. However, in some countries, a person may be forced to unlock the media, and the very fact of having an encrypted section can cause additional questions. The open project Phantomdrive offers a different approach: when...
Top Bottom