<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[PWN | Hacker Community]]></title><description><![CDATA[Welcome to PWN – your community for hackers and cybersecurity enthusiasts. Discover the latest hacking news, breach reports, and educational resources on ethical hacking. 👾 Stay sharp. Stay secure.]]></description><link>https://pwnhackers.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!INDD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7588dff0-e7a4-43b4-a591-e37fb6bee3af_128x128.png</url><title>PWN | Hacker Community</title><link>https://pwnhackers.substack.com</link></image><generator>Substack</generator><lastBuildDate>Fri, 07 Aug 2026 05:33:53 GMT</lastBuildDate><atom:link href="https://pwnhackers.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[PWN | Hacker News]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[pwnhackers@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[pwnhackers@substack.com]]></itunes:email><itunes:name><![CDATA[PWN | Hacker Community]]></itunes:name></itunes:owner><itunes:author><![CDATA[PWN | Hacker Community]]></itunes:author><googleplay:owner><![CDATA[pwnhackers@substack.com]]></googleplay:owner><googleplay:email><![CDATA[pwnhackers@substack.com]]></googleplay:email><googleplay:author><![CDATA[PWN | Hacker Community]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[AMA with TechCrunch Security Editor Zack Whittaker & Security Researcher Runa Sandvik (Border Searches, Device Security)]]></title><description><![CDATA[Don&#8217;t miss the AMA with Zack Whittaker, security editor at TechCrunch, and Runa Sandvik, security researcher and founder of Granitt.]]></description><link>https://pwnhackers.substack.com/p/ama-with-techcrunch-security-editor</link><guid isPermaLink="false">https://pwnhackers.substack.com/p/ama-with-techcrunch-security-editor</guid><dc:creator><![CDATA[PWN | Hacker Community]]></dc:creator><pubDate>Thu, 06 Aug 2026 02:53:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0Iv1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd53635-e160-4d80-9223-d3ab22093ac6_1080x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><a href="https://www.reddit.com/r/pwnhub/comments/1vgovkv/we_are_techcrunch_security_editor_zack_whittaker/">Don&#8217;t miss the AMA</a> with Zack Whittaker, security editor at TechCrunch, and Runa Sandvik, security researcher and founder of Granitt.</strong></p><p>During the session, we will learn about the American charged with a felony for wiping his phone at the border, device security, and how to protect your data when you travel.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.reddit.com/r/pwnhub/comments/1vgovkv/we_are_techcrunch_security_editor_zack_whittaker/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0Iv1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd53635-e160-4d80-9223-d3ab22093ac6_1080x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0Iv1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd53635-e160-4d80-9223-d3ab22093ac6_1080x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0Iv1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd53635-e160-4d80-9223-d3ab22093ac6_1080x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0Iv1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd53635-e160-4d80-9223-d3ab22093ac6_1080x1080.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0Iv1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd53635-e160-4d80-9223-d3ab22093ac6_1080x1080.jpeg" width="1080" height="1080" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1cd53635-e160-4d80-9223-d3ab22093ac6_1080x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1080,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:136189,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:&quot;https://www.reddit.com/r/pwnhub/comments/1vgovkv/we_are_techcrunch_security_editor_zack_whittaker/&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/210018416?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd53635-e160-4d80-9223-d3ab22093ac6_1080x1080.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0Iv1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd53635-e160-4d80-9223-d3ab22093ac6_1080x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0Iv1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd53635-e160-4d80-9223-d3ab22093ac6_1080x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0Iv1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd53635-e160-4d80-9223-d3ab22093ac6_1080x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0Iv1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd53635-e160-4d80-9223-d3ab22093ac6_1080x1080.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Zack recently reported on the case of Sam Tunick, an Atlanta man facing a federal felony charge after U.S. border agents claimed he handed over a password that wiped his phone during a search at the airport. </p><p>His phone was running GrapheneOS, which lets users set a &#8220;duress&#8221; password that wipes the device when entered. Prosecutors say triggering that built-in feature amounts to destroying property to prevent its seizure by the government.</p><p>This is believed to be the first U.S. case of its kind involving a duress password. It raises important questions about what happens when using a security feature is treated as a crime, and what constitutional and legal rights Americans have at the U.S. border.</p><p>Read the reporting: <a href="https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search/">TechCrunch</a>, plus coverage from <a href="https://www.404media.co/man-charged-for-wiping-phone-before-cbp-could-search-it/">404 Media</a> and <a href="https://www.theguardian.com/us-news/2026/jul/23/cop-city-protester-phone">The Guardian</a>.</p><div><hr></div><h3>Guest Credentials:</h3><ul><li><p><strong>Zack Whittaker</strong>, security editor at <a href="https://techcrunch.com/author/zack-whittaker/">TechCrunch</a> and author of the weekly cyber newsletter <a href="https://this.weekinsecurity.com/">this.weekinsecurity.com</a>, who broke the story on the Tunick case.</p></li><li><p><strong>Runa Sandvik</strong>, security researcher who works with journalists and at-risk people through her consultancy <a href="https://granitt.io/">Granitt</a>. She has spent years helping journalists and activists protect their devices, data, and sources, including at the border, and has weighed in on how novel and consequential this case is.</p></li></ul><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/comments/1vgovkv/we_are_techcrunch_security_editor_zack_whittaker/&quot;,&quot;text&quot;:&quot;Ask Your Questions Here!&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.reddit.com/r/pwnhub/comments/1vgovkv/we_are_techcrunch_security_editor_zack_whittaker/"><span>Ask Your Questions Here!</span></a></p><div><hr></div><h3>Ask Them Anything About</h3><ul><li><p>Why this prosecution involving GrapheneOS will be closely watched by privacy advocates and civil liberties defenders, and what it could mean as a precedent</p></li><li><p>Border searches of phones and your rights when crossing</p></li><li><p>Duress passwords vs. device wiping, and the tradeoffs of these features</p></li><li><p>How journalists and activists protect devices and sources</p></li><li><p>Practical steps anyone can take to secure their data before they travel</p></li><li><p>How they research and report on security, privacy, and surveillance stories</p></li><li><p><em>&#8230;anything else on device security, privacy, and press freedom</em></p></li></ul><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/comments/1vgovkv/we_are_techcrunch_security_editor_zack_whittaker/&quot;,&quot;text&quot;:&quot;Ask Your Questions Here!&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.reddit.com/r/pwnhub/comments/1vgovkv/we_are_techcrunch_security_editor_zack_whittaker/"><span>Ask Your Questions Here!</span></a></p><div><hr></div><h2><strong>Join PWN on Reddit</strong></h2><p><a href="https://www.reddit.com/r/pwnhub/">PWN</a> is where security people go to stay ahead.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xBGM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xBGM!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" width="1200" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:400,&quot;width&quot;:1200,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:196009,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/196609498?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"></figcaption></figure></div><p>Breach reports, exploits, vendor advisories, and the kind of conversations that make you better at your job, all in one feed.</p><p>We&#8217;re 41,000+ hackers and cybersecurity enthusiasts strong, with 935,000 monthly views and 200+ new members every day.</p><p>You&#8217;ll be in the same threads as journalists from Wired Magazine, Electronic Frontier Foundation, 404 Media, Fast Company, CNET, The Guardian, Daily Mail, and Ars Technica breaking the stories firsthand, plus security teams from vendors like Proton, Intigriti, and Hudson Rock sharing research and answering questions directly.</p><h3><strong>Why join:</strong></h3><ul><li><p><strong>Know what&#8217;s hitting before it hits you.</strong> Get the breach reports, exploits, and vendor advisories early so you can act before they become your problem.</p></li><li><p><strong>Get sharper, not just busier.</strong> Skip the noise and learn from people actually doing the work, on the AI exploits, new defenses, and techniques that move your skills forward.</p></li><li><p><strong>Make the career move you&#8217;ve been planning.</strong> Whether it&#8217;s your first paycheck in security or your jump from IT into offensive work, you&#8217;ll find members who&#8217;ve made it and are happy to help you do the same.</p></li><li><p><strong>Be the person at work who already knows.</strong> Walk into Monday meetings ahead of the ransomware incidents and zero-days landing on your team&#8217;s radar, and earn the trust that comes with it.</p></li><li><p><strong>Find your people.</strong> Trade ideas with hackers and pros who&#8217;ll actually answer your questions, in a community that stays high quality because the bots and noise get cleaned up.</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/&quot;,&quot;text&quot;:&quot;Join PWN on Reddit&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.reddit.com/r/pwnhub/"><span>Join PWN on Reddit</span></a></p>]]></content:encoded></item><item><title><![CDATA[AMA with WIRED Journalists Louise Matsakis & Lily Hay Newman (AI Hacking, DEF CON)]]></title><description><![CDATA[Don&#8217;t miss the AMA with Louise Matsakis and Lily Hay Newman, reporters at WIRED, where we learn about the state of AI security, from models that hack real systems to the biggest takeaways from this year&#8217;s DEF CON.]]></description><link>https://pwnhackers.substack.com/p/ama-with-wired-journalists-louise</link><guid isPermaLink="false">https://pwnhackers.substack.com/p/ama-with-wired-journalists-louise</guid><dc:creator><![CDATA[PWN | Hacker Community]]></dc:creator><pubDate>Wed, 05 Aug 2026 16:54:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!DgIK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33247ca6-275a-45f4-ab2b-2f6f148d4874_1080x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Don&#8217;t miss the <a href="https://www.reddit.com/r/pwnhub/comments/1vg94sx/were_louise_matsakis_and_lily_hay_newman/">AMA with Louise Matsakis and Lily Hay Newman</a>, reporters at WIRED</strong>, where we learn about the state of AI security, from models that hack real systems to the biggest takeaways from this year&#8217;s DEF CON.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.reddit.com/r/pwnhub/comments/1vg94sx/were_louise_matsakis_and_lily_hay_newman/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DgIK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33247ca6-275a-45f4-ab2b-2f6f148d4874_1080x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DgIK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33247ca6-275a-45f4-ab2b-2f6f148d4874_1080x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DgIK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33247ca6-275a-45f4-ab2b-2f6f148d4874_1080x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DgIK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33247ca6-275a-45f4-ab2b-2f6f148d4874_1080x1080.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DgIK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33247ca6-275a-45f4-ab2b-2f6f148d4874_1080x1080.jpeg" width="1080" height="1080" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/33247ca6-275a-45f4-ab2b-2f6f148d4874_1080x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1080,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:193252,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:&quot;https://www.reddit.com/r/pwnhub/comments/1vg94sx/were_louise_matsakis_and_lily_hay_newman/&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/209953793?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33247ca6-275a-45f4-ab2b-2f6f148d4874_1080x1080.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DgIK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33247ca6-275a-45f4-ab2b-2f6f148d4874_1080x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DgIK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33247ca6-275a-45f4-ab2b-2f6f148d4874_1080x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DgIK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33247ca6-275a-45f4-ab2b-2f6f148d4874_1080x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DgIK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33247ca6-275a-45f4-ab2b-2f6f148d4874_1080x1080.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Guest Credentials:</h3><ul><li><p><strong>Louise Matsakis</strong>, reporter at WIRED covering AI and the technology industry, with deep experience reporting on how AI systems are built, deployed, and misused.</p></li><li><p><strong>Lily Hay Newman</strong>, reporter at WIRED covering cybersecurity, hacking, and digital threats, on the ground at DEF CON this year. </p></li></ul><p>Together they have broken major stories on AI security incidents, including recent disclosures from Anthropic and OpenAI about models breaking into real systems.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/comments/1vg94sx/were_louise_matsakis_and_lily_hay_newman/&quot;,&quot;text&quot;:&quot;Ask Your Questions Here!&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.reddit.com/r/pwnhub/comments/1vg94sx/were_louise_matsakis_and_lily_hay_newman/"><span>Ask Your Questions Here!</span></a></p><div><hr></div><h3>AI security is moving fast right now. </h3><p>Anthropic recently disclosed that its AI models gained unauthorized access to the systems of three organizations during cybersecurity testing, shortly after OpenAI revealed one of its agents had hacked into Hugging Face during a separate test. </p><p>Louise and Lily have been reporting on these incidents as they unfold, and Lily is covering DEF CON, so she will have a strong read on what researchers are actually worried about and building right now.</p><div><hr></div><h3>Ask Them Anything About</h3><ul><li><p>The state of AI security and where AI agents and offensive security are heading</p></li><li><p>The biggest takeaways from this year&#8217;s DEF CON</p></li><li><p>AI models breaking into real systems, from the Anthropic and OpenAI incidents to what comes next</p></li><li><p>How they report on AI, hacking, and security</p></li><li><p>Working with sources and getting companies to talk about incidents like these</p></li><li><p>Anything else on AI, privacy, and security</p></li></ul><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/comments/1vg94sx/were_louise_matsakis_and_lily_hay_newman/&quot;,&quot;text&quot;:&quot;Ask Your Questions Here!&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.reddit.com/r/pwnhub/comments/1vg94sx/were_louise_matsakis_and_lily_hay_newman/"><span>Ask Your Questions Here!</span></a></p><div><hr></div><h2><strong>Join PWN on Reddit</strong></h2><p><a href="https://www.reddit.com/r/pwnhub/">PWN</a> is where security people go to stay ahead.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xBGM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xBGM!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" width="1200" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:400,&quot;width&quot;:1200,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:196009,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/196609498?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"></figcaption></figure></div><p>Breach reports, exploits, vendor advisories, and the kind of conversations that make you better at your job, all in one feed.</p><p>We&#8217;re 41,000+ hackers and cybersecurity enthusiasts strong, with 935,000 monthly views and 200+ new members every day.</p><p>You&#8217;ll be in the same threads as journalists from Wired Magazine, Electronic Frontier Foundation, 404 Media, Fast Company, CNET, The Guardian, Daily Mail, and Ars Technica breaking the stories firsthand, plus security teams from vendors like Proton, Intigriti, and Hudson Rock sharing research and answering questions directly.</p><h3><strong>Why join:</strong></h3><ul><li><p><strong>Know what&#8217;s hitting before it hits you.</strong> Get the breach reports, exploits, and vendor advisories early so you can act before they become your problem.</p></li><li><p><strong>Get sharper, not just busier.</strong> Skip the noise and learn from people actually doing the work, on the AI exploits, new defenses, and techniques that move your skills forward.</p></li><li><p><strong>Make the career move you&#8217;ve been planning.</strong> Whether it&#8217;s your first paycheck in security or your jump from IT into offensive work, you&#8217;ll find members who&#8217;ve made it and are happy to help you do the same.</p></li><li><p><strong>Be the person at work who already knows.</strong> Walk into Monday meetings ahead of the ransomware incidents and zero-days landing on your team&#8217;s radar, and earn the trust that comes with it.</p></li><li><p><strong>Find your people.</strong> Trade ideas with hackers and pros who&#8217;ll actually answer your questions, in a community that stays high quality because the bots and noise get cleaned up.</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/&quot;,&quot;text&quot;:&quot;Join PWN on Reddit&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.reddit.com/r/pwnhub/"><span>Join PWN on Reddit</span></a></p>]]></content:encoded></item><item><title><![CDATA[A modder used Claude Al to crack an HP laptop's BIOS lock]]></title><description><![CDATA[A Reddit user unlocked a BIOS-locked HP 15-dw1036ne laptop using Anthropic&#8217;s Claude Code. The laptop had a startup lock and no known bypass, and it flagged BIOS Corruption Detected on any change.]]></description><link>https://pwnhackers.substack.com/p/a-modder-used-claude-al-to-crack</link><guid isPermaLink="false">https://pwnhackers.substack.com/p/a-modder-used-claude-al-to-crack</guid><dc:creator><![CDATA[PWN | Hacker Community]]></dc:creator><pubDate>Tue, 04 Aug 2026 02:18:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!_3C5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d3b7bbc-182c-4a6f-b6b2-0e94d097a8df_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><p><strong>A Reddit user unlocked a BIOS-locked HP 15-dw1036ne laptop using Anthropic&#8217;s Claude Code.</strong> The laptop had a startup lock and no known bypass, and it flagged BIOS Corruption Detected on any change. </p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.tiktok.com/t/ZP8nYFBnU/&quot;,&quot;text&quot;:&quot;View Story&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.tiktok.com/t/ZP8nYFBnU/"><span>View Story</span></a></p><div><hr></div><p>Claude worked through a backup BIOS dump, found a bypass for the RSA-2048 signature check, and unlocked 55 hidden settings.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.tiktok.com/t/ZP8nYFBnU/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_3C5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d3b7bbc-182c-4a6f-b6b2-0e94d097a8df_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!_3C5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d3b7bbc-182c-4a6f-b6b2-0e94d097a8df_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!_3C5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d3b7bbc-182c-4a6f-b6b2-0e94d097a8df_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!_3C5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d3b7bbc-182c-4a6f-b6b2-0e94d097a8df_1080x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_3C5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d3b7bbc-182c-4a6f-b6b2-0e94d097a8df_1080x1080.png" width="1080" height="1080" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0d3b7bbc-182c-4a6f-b6b2-0e94d097a8df_1080x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1080,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:419170,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.tiktok.com/t/ZP8nYFBnU/&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/209723638?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d3b7bbc-182c-4a6f-b6b2-0e94d097a8df_1080x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_3C5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d3b7bbc-182c-4a6f-b6b2-0e94d097a8df_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!_3C5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d3b7bbc-182c-4a6f-b6b2-0e94d097a8df_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!_3C5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d3b7bbc-182c-4a6f-b6b2-0e94d097a8df_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!_3C5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d3b7bbc-182c-4a6f-b6b2-0e94d097a8df_1080x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>The user published a Python script, but warns it may not work on other machines. The account is unverified and has not been independently reproduced.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.tiktok.com/t/ZP8nYFBnU/&quot;,&quot;text&quot;:&quot;View Story&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.tiktok.com/t/ZP8nYFBnU/"><span>View Story</span></a></p><div><hr></div><h2>Discussion on This Story</h2><p>Members in PWN are <a href="https://www.reddit.com/r/pwnhub/comments/1veu48h/ai_enthusiast_unlocks_and_mods_bios_with_claude/">discussing this story here</a>.</p><div><hr></div><h2><strong>Join PWN on Reddit</strong></h2><p><a href="https://www.reddit.com/r/pwnhub/">PWN</a><span> is where security people go to stay ahead.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xBGM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xBGM!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" width="1200" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:400,&quot;width&quot;:1200,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:196009,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/196609498?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Breach reports, exploits, vendor advisories, and the kind of conversations that make you better at your job, all in one feed.</p><p>We&#8217;re 40,000+ hackers and cybersecurity enthusiasts strong, with 935,000 monthly views and 200+ new members every day.</p><p>You&#8217;ll be in the same threads as journalists from Wired Magazine, Electronic Frontier Foundation, 404 Media, Fast Company, CNET, The Guardian, Daily Mail, and Ars Technica breaking the stories firsthand, plus security teams from vendors like Proton, Intigriti, and Hudson Rock sharing research and answering questions directly.</p><h3><strong>Why join:</strong></h3><ul><li><p><strong>Know what&#8217;s hitting before it hits you.</strong><span> Get the breach reports, exploits, and vendor advisories early so you can act before they become your problem.</span></p></li><li><p><strong>Get sharper, not just busier.</strong><span> Skip the noise and learn from people actually doing the work, on the AI exploits, new defenses, and techniques that move your skills forward.</span></p></li><li><p><strong>Make the career move you&#8217;ve been planning.</strong><span> Whether it&#8217;s your first paycheck in security or your jump from IT into offensive work, you&#8217;ll find members who&#8217;ve made it and are happy to help you do the same.</span></p></li><li><p><strong>Be the person at work who already knows.</strong><span> Walk into Monday meetings ahead of the ransomware incidents and zero-days landing on your team&#8217;s radar, and earn the trust that comes with it.</span></p></li><li><p><strong>Find your people.</strong><span> Trade ideas with hackers and pros who&#8217;ll actually answer your questions, in a community that stays high quality because the bots and noise get cleaned up.</span></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/&quot;,&quot;text&quot;:&quot;Join PWN on Reddit&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.reddit.com/r/pwnhub/"><span>Join PWN on Reddit</span></a></p>]]></content:encoded></item><item><title><![CDATA[Hijacked hotel Wi-Fi pushes fake updates to plant spyware]]></title><description><![CDATA[Microsoft says attackers hijacked hotel Wi-Fi in several countries, taking over the captive portal guests log in through and using it to push fake browser updates.]]></description><link>https://pwnhackers.substack.com/p/hijacked-hotel-wi-fi-pushes-fake</link><guid isPermaLink="false">https://pwnhackers.substack.com/p/hijacked-hotel-wi-fi-pushes-fake</guid><dc:creator><![CDATA[PWN | Hacker Community]]></dc:creator><pubDate>Sun, 02 Aug 2026 03:14:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!DLyM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F152a6025-51a9-4a06-bf29-dcc26b014af7_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><p><strong>Microsoft says attackers hijacked hotel Wi-Fi in several countries, taking over the captive portal guests log in through and using it to push fake browser updates.</strong> </p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.tiktok.com/t/ZP8nJyMRe/&quot;,&quot;text&quot;:&quot;View Story&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.tiktok.com/t/ZP8nJyMRe/"><span>View Story</span></a></p><div><hr></div><p>The updates install CornFlake, a remote access trojan that can capture webcam, microphone, and keystroke data, steal passwords, and open a remote shell. x</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.reddit.com/r/pwnhub/comments/1vcqe9l/microsoft_warns_of_hotel_wifi_hijacking/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DLyM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F152a6025-51a9-4a06-bf29-dcc26b014af7_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!DLyM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F152a6025-51a9-4a06-bf29-dcc26b014af7_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!DLyM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F152a6025-51a9-4a06-bf29-dcc26b014af7_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!DLyM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F152a6025-51a9-4a06-bf29-dcc26b014af7_1080x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DLyM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F152a6025-51a9-4a06-bf29-dcc26b014af7_1080x1080.png" width="1080" height="1080" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/152a6025-51a9-4a06-bf29-dcc26b014af7_1080x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1080,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:632797,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.reddit.com/r/pwnhub/comments/1vcqe9l/microsoft_warns_of_hotel_wifi_hijacking/&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/209451305?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F152a6025-51a9-4a06-bf29-dcc26b014af7_1080x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DLyM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F152a6025-51a9-4a06-bf29-dcc26b014af7_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!DLyM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F152a6025-51a9-4a06-bf29-dcc26b014af7_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!DLyM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F152a6025-51a9-4a06-bf29-dcc26b014af7_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!DLyM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F152a6025-51a9-4a06-bf29-dcc26b014af7_1080x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Microsoft ties the campaign to Storm-2945, which it assesses is part of the Russia-linked group Midnight Blizzard, though that specific link is not independently confirmed. The victim still has to run the payload, so reject any update offered over public Wi-Fi.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.tiktok.com/t/ZP8nJyMRe/&quot;,&quot;text&quot;:&quot;View Story&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.tiktok.com/t/ZP8nJyMRe/"><span>View Story</span></a></p><div><hr></div><h2>Discussion on This Story</h2><p>Members in PWN are <a href="https://www.reddit.com/r/pwnhub/comments/1vcqe9l/microsoft_warns_of_hotel_wifi_hijacking/">discussing this story here</a>.</p><div><hr></div><h2><strong>Join PWN on Reddit</strong></h2><p><a href="https://www.reddit.com/r/pwnhub/">PWN</a><span> is where security people go to stay ahead.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xBGM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xBGM!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" width="1200" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:400,&quot;width&quot;:1200,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:196009,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/196609498?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Breach reports, exploits, vendor advisories, and the kind of conversations that make you better at your job, all in one feed.</p><p>We&#8217;re 40,000+ hackers and cybersecurity enthusiasts strong, with 935,000 monthly views and 200+ new members every day.</p><p>You&#8217;ll be in the same threads as journalists from Wired Magazine, Electronic Frontier Foundation, 404 Media, Fast Company, CNET, The Guardian, Daily Mail, and Ars Technica breaking the stories firsthand, plus security teams from vendors like Proton, Intigriti, and Hudson Rock sharing research and answering questions directly.</p><h3><strong>Why join:</strong></h3><ul><li><p><strong>Know what&#8217;s hitting before it hits you.</strong><span> Get the breach reports, exploits, and vendor advisories early so you can act before they become your problem.</span></p></li><li><p><strong>Get sharper, not just busier.</strong><span> Skip the noise and learn from people actually doing the work, on the AI exploits, new defenses, and techniques that move your skills forward.</span></p></li><li><p><strong>Make the career move you&#8217;ve been planning.</strong><span> Whether it&#8217;s your first paycheck in security or your jump from IT into offensive work, you&#8217;ll find members who&#8217;ve made it and are happy to help you do the same.</span></p></li><li><p><strong>Be the person at work who already knows.</strong><span> Walk into Monday meetings ahead of the ransomware incidents and zero-days landing on your team&#8217;s radar, and earn the trust that comes with it.</span></p></li><li><p><strong>Find your people.</strong><span> Trade ideas with hackers and pros who&#8217;ll actually answer your questions, in a community that stays high quality because the bots and noise get cleaned up.</span></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/&quot;,&quot;text&quot;:&quot;Join PWN on Reddit&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.reddit.com/r/pwnhub/"><span>Join PWN on Reddit</span></a></p>]]></content:encoded></item><item><title><![CDATA[Al beats humans at romance scams, study finds]]></title><description><![CDATA[An Al chatbot outperformed a human scammer at building trust in a romance scam experiment run by four universities.]]></description><link>https://pwnhackers.substack.com/p/al-beats-humans-at-romance-scams</link><guid isPermaLink="false">https://pwnhackers.substack.com/p/al-beats-humans-at-romance-scams</guid><dc:creator><![CDATA[PWN | Hacker Community]]></dc:creator><pubDate>Sat, 01 Aug 2026 14:47:33 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rO8P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce1242df-22a3-48f4-9bbe-e70e0bb39f02_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>An Al chatbot outperformed a human scammer at building trust in a romance scam experiment run by four universities.</strong> </p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.tiktok.com/t/ZP8tE725d/&quot;,&quot;text&quot;:&quot;View Story&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.tiktok.com/t/ZP8tE725d/"><span>View Story</span></a></p><div><hr></div><p>Over a week of texting, 46 percent of people did what the Al asked, versus 18 percent for the human, and they rated the bot as more trustworthy. The Al used was a Claude model, and it followed instructions to deny being Al. No money was taken; a download stood in for the final fraud. </p><p>Anthropic says the study used an old model and its newer Claude flags most scam attempts. Researchers warn Al could soon automate the trust-building phase of these scams at scale.</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rO8P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce1242df-22a3-48f4-9bbe-e70e0bb39f02_1080x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rO8P!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce1242df-22a3-48f4-9bbe-e70e0bb39f02_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!rO8P!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce1242df-22a3-48f4-9bbe-e70e0bb39f02_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!rO8P!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce1242df-22a3-48f4-9bbe-e70e0bb39f02_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!rO8P!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce1242df-22a3-48f4-9bbe-e70e0bb39f02_1080x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rO8P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce1242df-22a3-48f4-9bbe-e70e0bb39f02_1080x1080.png" width="1080" height="1080" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ce1242df-22a3-48f4-9bbe-e70e0bb39f02_1080x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1080,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:665336,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/209384516?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce1242df-22a3-48f4-9bbe-e70e0bb39f02_1080x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rO8P!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce1242df-22a3-48f4-9bbe-e70e0bb39f02_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!rO8P!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce1242df-22a3-48f4-9bbe-e70e0bb39f02_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!rO8P!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce1242df-22a3-48f4-9bbe-e70e0bb39f02_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!rO8P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce1242df-22a3-48f4-9bbe-e70e0bb39f02_1080x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div><hr></div><p></p><p>The real Sparrow Wallet is desktop only and has never shipped on ios, so every version in the App Store is fake. Developer Craig Raw says he reported the clones for years. Apple says it removed the impersonating apps and terminated the developer accounts behind them.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.tiktok.com/t/ZP8tE725d/&quot;,&quot;text&quot;:&quot;View Story&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.tiktok.com/t/ZP8tE725d/"><span>View Story</span></a></p><div><hr></div><h2>Discussion on This Story</h2><p>Members in PWN are <a href="https://www.reddit.com/r/pwnhub/comments/1vbz70a/study_finds_ai_chatbots_outperform_humans_in/">discussing this story here</a>.</p><div><hr></div><h2><strong>Join PWN on Reddit</strong></h2><p><a href="https://www.reddit.com/r/pwnhub/">PWN</a><span> is where security people go to stay ahead.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xBGM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xBGM!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" width="1200" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:400,&quot;width&quot;:1200,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:196009,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/196609498?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Breach reports, exploits, vendor advisories, and the kind of conversations that make you better at your job, all in one feed.</p><p>We&#8217;re 40,000+ hackers and cybersecurity enthusiasts strong, with 935,000 monthly views and 200+ new members every day.</p><p>You&#8217;ll be in the same threads as journalists from Wired Magazine, Electronic Frontier Foundation, 404 Media, Fast Company, CNET, The Guardian, Daily Mail, and Ars Technica breaking the stories firsthand, plus security teams from vendors like Proton, Intigriti, and Hudson Rock sharing research and answering questions directly.</p><h3><strong>Why join:</strong></h3><ul><li><p><strong>Know what&#8217;s hitting before it hits you.</strong><span> Get the breach reports, exploits, and vendor advisories early so you can act before they become your problem.</span></p></li><li><p><strong>Get sharper, not just busier.</strong><span> Skip the noise and learn from people actually doing the work, on the AI exploits, new defenses, and techniques that move your skills forward.</span></p></li><li><p><strong>Make the career move you&#8217;ve been planning.</strong><span> Whether it&#8217;s your first paycheck in security or your jump from IT into offensive work, you&#8217;ll find members who&#8217;ve made it and are happy to help you do the same.</span></p></li><li><p><strong>Be the person at work who already knows.</strong><span> Walk into Monday meetings ahead of the ransomware incidents and zero-days landing on your team&#8217;s radar, and earn the trust that comes with it.</span></p></li><li><p><strong>Find your people.</strong><span> Trade ideas with hackers and pros who&#8217;ll actually answer your questions, in a community that stays high quality because the bots and noise get cleaned up.</span></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/&quot;,&quot;text&quot;:&quot;Join PWN on Reddit&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.reddit.com/r/pwnhub/"><span>Join PWN on Reddit</span></a></p>]]></content:encoded></item><item><title><![CDATA[AMA with Yuhang Wu of depthfirst (ex-Tesla & TikTok): AI, Bug Hunting, and Breaking Into Security]]></title><description><![CDATA[Discussion included AI-Assisted Bug Hunting, Exploit Development, and Breaking Into Security]]></description><link>https://pwnhackers.substack.com/p/ama-with-yuhang-wu-of-depthfirst</link><guid isPermaLink="false">https://pwnhackers.substack.com/p/ama-with-yuhang-wu-of-depthfirst</guid><dc:creator><![CDATA[PWN | Hacker Community]]></dc:creator><pubDate>Fri, 31 Jul 2026 23:42:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!g50_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930dd870-f1ef-4e53-86d8-4f1f1f0363e8_1080x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Yuhang Wu, a vulnerability researcher at <a href="https://depthfirst.com/">depthfirst</a>, hosted an AMA in the <a href="https://joinpwn.com/">PWN</a> community about AI-assisted vulnerability research. </strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.tiktok.com/t/ZP8tK2EpU/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!g50_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930dd870-f1ef-4e53-86d8-4f1f1f0363e8_1080x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!g50_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930dd870-f1ef-4e53-86d8-4f1f1f0363e8_1080x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!g50_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930dd870-f1ef-4e53-86d8-4f1f1f0363e8_1080x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!g50_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930dd870-f1ef-4e53-86d8-4f1f1f0363e8_1080x1080.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!g50_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930dd870-f1ef-4e53-86d8-4f1f1f0363e8_1080x1080.jpeg" width="1080" height="1080" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/930dd870-f1ef-4e53-86d8-4f1f1f0363e8_1080x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1080,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:145286,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:&quot;https://www.tiktok.com/t/ZP8tK2EpU/&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/209317167?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930dd870-f1ef-4e53-86d8-4f1f1f0363e8_1080x1080.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!g50_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930dd870-f1ef-4e53-86d8-4f1f1f0363e8_1080x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!g50_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930dd870-f1ef-4e53-86d8-4f1f1f0363e8_1080x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!g50_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930dd870-f1ef-4e53-86d8-4f1f1f0363e8_1080x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!g50_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930dd870-f1ef-4e53-86d8-4f1f1f0363e8_1080x1080.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.tiktok.com/t/ZP8tK2EpU/&quot;,&quot;text&quot;:&quot;View Story&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.tiktok.com/t/ZP8tK2EpU/"><span>View Story</span></a></p><div><hr></div><p>The session followed his case study on chaining two five-year-old Ruby memory corruption bugs in the Oj JSON parser into remote code execution on default GitLab installations. </p><p>The issues were reported privately in May, fixed in Oj 3.17.3, and later patched in GitLab&#8217;s affected code path. </p><p>During the AMA session, he took questions on his research and disclosure process, memory-safety risks in native extensions, how AI-assisted systems help prioritize suspicious code, red and blue teaming, and getting started in the field.</p><div><hr></div><h2>About the Guest</h2><p>Yuhang Wu is a <a href="https://www.linkedin.com/in/yuhang-wu-68a704227/">security researcher at depthfirst</a>, where he works on autonomous vulnerability discovery as part of the company&#8217;s Open Defense Initiative. </p><p>His recent case study chained two memory-safety bugs in Oj, a native C JSON parser for Ruby, into <a href="https://depthfirst.com/research/going-depthfirst-achieving-gitlab-rce-via-two-ruby-memory-corruption-vulnerabilities">remote code execution on default GitLab installations</a>. </p><p>The out-of-bounds write and heap-pointer disclosure had gone undetected for nearly five years, and the chain worked from an ordinary authenticated account, as <a href="https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html">The Hacker News reported</a>. </p><p>His team also autonomously discovered a critical heap overflow in NGINX&#8217;s rewrite module, tracked as CVE-2026-42945 with a CVSS score of 9.2.</p><p>Before depthfirst, Wu spent about a year as a red team engineer at TikTok focused on AI security, and interned at Tesla, where he worked across application, vehicle, and factory software security and built an LLM-based code-auditing agent that uncovered eight critical vulnerabilities. His earlier roles include a security internship at Sec3 and several years as a researcher at Beijing Chaitin Technology.</p><p>His academic background is in low-level exploitation. He holds a PhD from Northwestern University, where he co-authored <a href="https://github.com/Markakd/DirtyCred">DirtyCred</a>, a Linux kernel privilege-escalation technique presented at Black Hat USA 2022 and tracked as CVE-2022-2588, along with related kernel research such as GREBE at IEEE S&amp;P 2022. Per his AMA, he has more than ten years of competitive CTF experience. You can find more of his work on his <a href="https://yuhangw.blog/">personal site</a> and follow him on <a href="https://x.com/wupco1996">X</a>.</p><p>This AMA took place on r/pwnhub. The questions below are organized by topic, and the wording of each question and answer is reproduced as it appeared in the thread.</p><div><hr></div><h2>Getting Started and Breaking Into the Field</h2><p><strong>Q:</strong> How did you get into this field? Whats your story? Can you go into detail on your overall progression of knowledge which led you to where you are today?</p><p><strong>A:</strong> I majored in Information Security as an undergraduate and started competing in CTFs during my sophomore year (around 2015). It took me about a year to go from competing with a relatively unknown university team to being accepted by an internationally recognized team.</p><p>I think security is a field that&#8217;s relatively easy to get into, but incredibly broad. Over the past ten years, I&#8217;ve never stopped learning new things, and I even pursued a Ph.D. along the way. If there&#8217;s one thing I&#8217;ve learned, it&#8217;s that maintaining your passion and your motivation to keep learning is the most important part.</p><div><hr></div><p><strong>Q:</strong> How did you get into this line of work? Do you think it&#8217;s easier or harder to get into it right now? And what are the best resources that helped you learn and grow?</p><p><strong>A:</strong> I got into security quite early, driven purely by interest. Today, it&#8217;s much easier to get started thanks to the wealth of learning resources and AI tools, but it&#8217;s also much harder to land a job because the field has become far more competitive.</p><p>Looking back, my CTF experience had an enormous impact on my career. I strongly recommend that anyone who wants to pursue offensive security spend a few years competing in CTFs with an internationally recognized team. It&#8217;s one of the fastest ways to build both deep technical knowledge and practical problem-solving experience, and it provides an excellent foundation for real-world security research.</p><div><hr></div><p><strong>Q:</strong> Hello Mr. Yuhang Wu what path and tooling do you suggest for an IT professional to switch into the ITSecurity/pentesting/red teaming field in 2026.</p><p><strong>A:</strong> AI can help you a lot, you can start with reproducing history CVEs, play CTFs with the help of the AI, and make sure to learn what&#8217;s the path AI following, and the behind reason why it do something.</p><div><hr></div><p><strong>Q:</strong> Do you think there&#8217;s still a path towards entry-level cybersecurity and how might someone get into that path?</p><p><strong>A:</strong> I do think there are still paths into entry-level cybersecurity roles, but they&#8217;ve changed significantly. Getting started is easier than ever because there are abundant learning resources and AI tools, yet landing a job has become much more competitive.</p><p>My advice is to build real technical ability rather than just collecting certifications. Learn the fundamentals of operating systems, networking, programming, and common vulnerability classes. Then spend time solving CTF challenges and, if possible, join an internationally recognized CTF team. Working alongside strong teammates for a few years is one of the fastest ways to develop the skills and mindset needed for real-world security research.</p><p>Also, don&#8217;t rely on AI to do all the work. AI is an incredible learning tool and can make you much more productive, but it&#8217;s important to understand why something is a vulnerability and be able to verify it yourself. Use AI to accelerate your learning, not to replace it.</p><div><hr></div><h2>Learning: CTFs, Certifications, and Resources</h2><p><strong>Q:</strong> Is CTF the best way to learn security or strengthen my sec skills?</p><p><strong>A:</strong> I think the answer is &#8220;yes&#8221;, but be selective about which CTFs you participate in. Try to focus on internationally recognized competitions, as they generally have higher-quality challenges and fewer &#8220;guess-the-author&#8217;s-intent&#8221; problems. They&#8217;re much more effective for improving your skills.</p><div><hr></div><p><strong>Q:</strong> What tools/methods have you used at the beginning of your career or what certificates were you going towards?</p><p><strong>A:</strong> I never really pursued certifications. When I was getting started, I learned mostly by doing, reading code, playing CTFs, and building things myself. CTFs had by far the biggest impact on my career because they exposed me to a wide range of security topics and taught me how to solve unfamiliar problems under pressure.</p><p>I also spent a lot of time reading open-source projects, security blogs, and vulnerability write-ups, then trying to reproduce and understand them myself. Looking back, that hands-on experience was much more valuable than any certification could have been.</p><div><hr></div><h2>Research Methodology and Process</h2><p><strong>Q:</strong> What is your bug hunting process like? Where do you start? What steps do you take?</p><p><strong>A:</strong> First, identify the attack surface. Then build a threat model, and systematically trace every code path that is reachable from that attack surface, as deep into the stack as possible.</p><div><hr></div><p><strong>Q:</strong> What&#8217;s the best first step for someone who wants to get into vulnerability research?</p><p><strong>A:</strong> Question every line of code. Trust no software. Read the code yourself, reverse engineer it, and discover how it really works.</p><div><hr></div><p><strong>Q:</strong> How much of your time is spent on vulnerability research looking for 0-days? What is the average time of discovery for Linux kernel useable exploits (RCE)?</p><p><strong>A:</strong> For a fairly large project, I typically spend about a week on it. With something like the Linux kernel, finding the first vulnerability is usually the hardest part. But once you&#8217;ve found that first bug, the following ones often become much easier because you&#8217;ve already built a solid understanding of the architecture and codebase.</p><div><hr></div><p><strong>Q:</strong> How long personally do you think you spent on researching DirtyCred? The culmination of experimentation, research, and finalizing the exploit chain? Thank you!</p><p><strong>A:</strong> This was a project I worked on with my labmates. We spent about a few months on it from start to finish.</p><div><hr></div><h2>The Oj / GitLab Research and Exploit Development</h2><p><strong>Q:</strong> Seeing how you chained a simple stack overflow into a full server takeover is fascinating.</p><p>For those of us who want to learn how to transition from basic buffer overflows to complex exploit chains like this, what resources or labs do you recommend starting with?</p><p><strong>A:</strong> This requires debugging with gdb to understand the heap layout and evaluate whether the out-of-bounds access can reach any interesting data structures. Building a working exploit often depends on identifying a number of useful gadgets and chaining them together. In some cases, it&#8217;s even possible to turn a constrained OOB primitive into an arbitrary OOB write, and with careful heap grooming, that can be achievable. Above all, exploit development comes down to patience and experience.</p><p>If you&#8217;re interested in learning exploit development, I&#8217;d recommend starting with the classic glibc heap exploitation techniques. The how2heap project is an excellent resource: <a href="https://github.com/shellphish/how2heap">https://github.com/shellphish/how2heap</a></p><div><hr></div><p><strong>Q:</strong> Since the buffer overflow in the nesting stack was a relatively straightforward out-of-bounds write, why do you think it managed to survive hidden in the Oj code for nearly five years without being caught by standard security tools or fuzzers?</p><p>Do you think AI agents are going to uncover many more vulnerabilities like this in the near future?</p><p><strong>A:</strong> The biggest challenge was that libraries like Oj sit so deep in the software stack that they&#8217;re often overlooked by both security tools and researchers, or simply assumed to be safe. That kind of implicit trust can cause you to miss valuable vulnerability discovery opportunities.</p><p>As AI continues to improve, I expect it to learn more from the way human researchers progressively dig deeper into the software stack. Rather than stopping at the application layer, it will likely become much better at following dependency chains and uncovering similar classes of vulnerabilities hidden in low-level libraries.</p><div><hr></div><p><strong>Q:</strong> Sickest sandbox or proxy bypass you saw in the wild?</p><p><strong>A:</strong> Hmm, that&#8217;s a difficult one. But the talk that left the biggest impression on me was Orange Tsai&#8217;s Black Hat presentation on SSRF. Many of the techniques he introduced fundamentally changed how people think about SSRF exploitation and proxy bypasses.</p><div><hr></div><h2>AI-Assisted Vulnerability Research</h2><p><strong>Q:</strong> how to guide ai to find more critical vulnerabilities, sometimes ai just finds easy ones</p><p><strong>A:</strong> I&#8217;ve noticed that AI often tries to rediscover historical vulnerabilities in a project by following patterns from previously reported bugs. While that can be effective, many projects simply don&#8217;t have those same bug classes. The more interesting vulnerabilities often require a different perspective and exploring parts of the codebase that have received far less attention. It can be helpful to deliberately steer the AI toward areas it hasn&#8217;t considered yet.</p><p>AI also tends to stop at relatively shallow findings. You can encourage it to look beyond the application&#8217;s own code and investigate third-party dependencies or extensions as well. That&#8217;s exactly what happened in our GitLab research, we eventually pivoted into the Oj dependency, where we discovered the vulnerabilities that ultimately led to the exploit chain.</p><div><hr></div><p><strong>Q:</strong> Since you&#8217;ve listed &#8216;getting started with AI-assisted research&#8217; as a topic, you&#8217;ve probably seen how a lot of newcomers try to leverage AI for source audits.</p><p>What is the biggest trap or misconception you see beginners fall into when relying on automated AI tools to find vulnerabilities?</p><p>What tips or words advice do you have for those looking to add more AI to their workflow?</p><p><strong>A:</strong> I think the biggest challenge for beginners using AI tools to find vulnerabilities is that AI models can hallucinate and sometimes exhibit a tendency to &#8220;cheat&#8221; by making unsupported assumptions. Beginners often don&#8217;t recognize this, which can lead to a large number of false positives. If those are submitted to maintainers or security teams without proper validation, they waste everyone&#8217;s time and can also hurt the reputation of legitimate security researchers.</p><p>Another challenge is that beginners rarely find deep or highly sophisticated vulnerabilities with AI alone. Those discoveries usually require carefully crafted prompts, the right research direction, and human guidance before the AI can uncover them.</p><p>My advice is to use AI as a learning companion rather than a replacement for security knowledge. While using AI to find vulnerabilities, you should also be building your own understanding of security concepts and vulnerability research. As your knowledge grows, you&#8217;ll get better at guiding the AI, filtering out false positives, and ultimately discovering much more interesting vulnerabilities.</p><div><hr></div><p><strong>Q:</strong> Could you share more about how do you harness Al? Any tips for building agents for cybersecurity?</p><p><strong>A:</strong> The biggest lesson I&#8217;ve learned is that AI works best as a research partner rather than an autonomous vulnerability hunter. Instead of asking it to &#8220;find bugs,&#8221; I try to give it a well-defined objective and enough context to reason effectively. I usually start by identifying the attack surface, building a threat model, and tracing the reachable code paths. Then I use AI to analyze those specific components, challenge assumptions, and explore hypotheses.</p><p>Another important point is to actively guide the AI. Left on its own, it often gravitates toward well-known bug patterns or previously disclosed vulnerabilities. In many projects, the interesting bugs are in places that have received very little attention, such as deep dependencies, extensions, or low-level libraries. Human intuition is still critical for steering the AI toward those overlooked areas.</p><p>Finally, don&#8217;t treat the model&#8217;s output as ground truth. AI can hallucinate, make unsupported assumptions, and generate a lot of false positives. Every finding should be validated manually. The goal is to combine the AI&#8217;s speed with human judgment and experience.</p><p>For anyone building AI agents for cybersecurity, I think the hardest technical problems are achieving broad coverage, intelligently partitioning large codebases into manageable pieces, maintaining useful context across long reasoning chains, and filtering out false positives without losing real vulnerabilities. Those are exactly the kinds of challenges we&#8217;re working on at depthfirst.</p><div><hr></div><p><strong>Q:</strong> Hi Yuhang - how are you testing and verifying agents internally before you launch into production or internal use. Also how are you evaluating 3rd party applications with the agentic loop?</p><p><strong>A:</strong> We evaluate our agents using many state-of-the-art open-source benchmarks, but we&#8217;re also actively building our own, especially benchmarks based on real-world applications and vulnerabilities. We believe real-world benchmarks are a much better way to measure an agent&#8217;s practical capabilities, identify its weaknesses, and ultimately drive meaningful improvements to the system.</p><div><hr></div><p><strong>Q:</strong> Do you need serious coding chops to get into LLM red teaming, or is that more of a &#8220;nice to have&#8221;? What&#8217;s your recommended starting point?</p><p><strong>A:</strong> I think it&#8217;s a nice-to-have rather than a requirement, especially now that AI has made coding much easier. These days, a lot of programming is essentially &#8220;vibe coding.&#8221;</p><p>I actually have a somewhat unconventional opinion: sometimes being a very strong programmer can make you more likely to miss certain vulnerability discovery opportunities. When you&#8217;ve used a particular library for years, you naturally develop a level of trust in it. During a code review, it&#8217;s easy to skim past that dependency without questioning it. On the other hand, if you&#8217;re unfamiliar with the library, you&#8217;re more likely to stop, ask what it does, and inspect it more closely. Ironically, that&#8217;s often where you end up finding vulnerabilities&#8212;in the low-level dependencies that everyone else has implicitly trusted.</p><div><hr></div><p><strong>Q:</strong> Many AI models refuse to communicate about cybersecurity work - especially red teaming.</p><p>Are there any AI models you prefer for cybersecurity work?</p><p>Do you have any tips for how to get AI models to allow you to talk to them about cybersecurity work?</p><p><strong>A:</strong> That&#8217;s a great question, and it&#8217;s something I struggle with as well. I regularly use Claude Opus 4.8 and GPT-5.6. As long as I have access to the Cyber Grant, it&#8217;s generally not a major issue. However, GPT still has a fairly strong tendency to refuse or become overly cautious at the model level, even after passing the Cyber Grant checks.</p><p>What I&#8217;ve found works much better is framing a real vulnerability research task as an explicitly authorized security engagement, such as a bug bounty program or a Pwn2Own competition. Providing that legitimate, authorized context tends to significantly improve the quality of the model&#8217;s responses and reduces unnecessary refusals.</p><div><hr></div><h2>Red Team and Blue Team</h2><p><strong>Q:</strong> What&#8217;s the balance between time spend on keyboard (hacking) versus planning red team activities?</p><p><strong>A:</strong> I would say the balance depends on the stage of the engagement. Early on, more time should go into planning: understanding the target, defining objectives, mapping the attack surface, reviewing the threat model, and deciding which paths are most likely to produce meaningful impact. Once a promising direction is identified, the balance shifts heavily toward hands-on work.</p><p>In practice, I probably spend around 30&#8211;40% of my time planning, researching, and analyzing, and 60&#8211;70% actively testing, debugging, and developing exploits. However, the process is iterative rather than strictly separated. Findings from hands-on testing constantly change the plan, and good planning helps avoid spending too much time on low-value attack paths. The goal is not to maximize keyboard time, but to make sure that each technical action is guided by a clear hypothesis.</p><div><hr></div><p><strong>Q:</strong> What were common shortfalls within the blue team that impacted their ability to detect and respond to red team activities?</p><p><strong>A:</strong> One common issue was insufficient visibility across the full attack chain. Individual events might be logged, but the blue team often lacked the context needed to connect them, for example, linking an unusual API request to a privilege change and then to suspicious internal access.</p><p>Another shortfall was overreliance on predefined signatures and known attack patterns. More subtle activity, especially when it used legitimate credentials, normal application functionality, or low-volume requests, often did not trigger alerts.</p><p>We also frequently saw gaps in logging, weak alert prioritization, and unclear ownership during incident response. Even when suspicious behavior was detected, teams sometimes struggled to determine who should investigate it or how serious it was. In other cases, alerts were generated but buried in noise.</p><p>The strongest blue teams were generally the ones that had good application-level telemetry, understood normal user and service behavior, and regularly practiced responding to realistic attack scenarios rather than relying only on endpoint or network-based detections.</p><div><hr></div><p><strong>Q:</strong> When planning a red team engagement, how do you decide whether to lead with social engineering/phishing or go straight for technical exploitation?</p><p>At companies like TikTok or Tesla specifically with their scale and security maturity which approach enabled you initial access faster, and does that change once you&#8217;re past the perimeter and trying to escalate or move laterally?</p><p><strong>A:</strong> In general, I don&#8217;t consider social engineering or phishing as part of my approach. Those techniques are difficult to get authorized for in legitimate security assessments and are more commonly associated with real-world threat actors than with vulnerability research.</p><p>Even highly mature organizations almost always have small cracks in their attack surface. At their scale, it&#8217;s nearly impossible to eliminate every overlooked asset. I think those overlooked corners often make the best starting points, for example, a rarely discovered public-facing web server that hasn&#8217;t been updated in a while and may still be vulnerable to a recently disclosed 1-day vulnerability. Those kinds of entry points are often much more practical than relying on social engineering.</p><div><hr></div><h2>The Future of Security and AI</h2><p><strong>Q:</strong> What impact will Al have on the future of vulnerability research? It seems to be getting better &amp; better at finding 0-days.</p><p><strong>A:</strong> I think AI is making vulnerability research faster and more accessible, but at the same time it&#8217;s also enabling developers to write code much more quickly, which inevitably creates more opportunities for new vulnerabilities. So I believe the future will look much like the present: attack and defense will continue to evolve together, driving each other forward. As AI improves both software development and security research, the two sides will keep advancing in parallel.</p><div><hr></div><p><strong>Q:</strong> How do you feel about security as a field with Al?</p><p><strong>A:</strong> I think it&#8217;s one of the most exciting times to be in security. AI has dramatically increased the speed of vulnerability research, code review, reverse engineering, and exploit prototyping. Many tasks that used to take days can now be done in hours, which allows researchers to spend more time thinking about interesting problems instead of repetitive work.</p><p>At the same time, AI is also accelerating software development. Developers can build products much faster, which means we&#8217;re also producing much more code&#8212;and inevitably, more vulnerabilities. In that sense, I don&#8217;t think AI will make security researchers obsolete. If anything, it raises the bar for both attackers and defenders.</p><p>I see AI as an amplifier rather than a replacement. The best results still come from combining AI with human intuition, curiosity, and deep technical understanding. AI is excellent at analyzing code and exploring hypotheses, but humans are still the ones who identify the right attack surface, question assumptions, and decide where to dig deeper.</p><p>Ultimately, I think attack and defense will continue to evolve together. As AI improves, both sides will become more capable, and security research will become even more impactful and interesting.</p><div><hr></div><p><strong>Q:</strong> Do you think it will be necessary for pentesters and red team operators to shift into more of a development/engineering role as more of the day to day testing becomes automated?</p><p><strong>A:</strong> no.... development/engineering will also be automated... I&#8217;ve always believed that security is a never-ending problem because security demands zero tolerance. Even if someone claimed to have an AI system capable of generating 100% secure code, I still wouldn&#8217;t trust it without independent human verification. In security, trust should never be assumed, it has to be earned through validation.</p><div><hr></div><p><strong>Q:</strong> How do you feel about companies dumping their internal source code to LLM providers, essentially losing track of where it ends up and giving up control and ownership on their code?</p><p><strong>A:</strong> I think this will become more standardized over time. Ultimately, I expect the industry to move toward a model where every company runs its own AI models internally, allowing them to benefit from AI while keeping their code and data within their own environment.</p><div><hr></div><p><strong>Q:</strong> In future really agents/ai models can attack individually without any intervene</p><p><strong>A:</strong> Possibly. But I think the industry will gradually develop standards and regulations to govern these kinds of issues.</p><div><hr></div><p><strong>Q:</strong> What are the trends you&#8217;re seeing which you feel need more attention?</p><p>How active are you in environments where threat actors operate and what trends or changes have you seen in these communities over the years?</p><p>Are there any major changes you&#8217;ve observed in the last 5 years either with regards to attacker MO or how equipped companies are with their defenses?</p><p>What are you most worried about?</p><p><strong>A:</strong> What are the trends you&#8217;re seeing which you feel need more attention?</p><p>I think we should pay more attention to evaluating AI based on its ability to solve real security problems, rather than relying on benchmark scores or vendor demos. What really matters is whether experienced security researchers actually become more effective when using these models. I think we need more independent, real-world evaluations from practitioners.</p><p>How active are you in environments where threat actors operate, and what trends have you seen?</p><p>I don&#8217;t spend much time in threat actor communities. My work is mostly focused on vulnerability research. But one thing I&#8217;ve noticed is that the barrier to entry is getting much lower. AI and publicly available tools are making many techniques accessible to people who previously wouldn&#8217;t have been able to use them.</p><p>Are there any major changes you&#8217;ve observed in the last five years?</p><p>I think companies have become much better at defending against known attack techniques. The interesting vulnerabilities today are much deeper in the software stack, often hidden in dependencies, middleware, or native libraries that everyone implicitly trusts. That&#8217;s where I&#8217;ve been spending most of my time.</p><p>What are you most worried about?</p><p>One thing I&#8217;m concerned about is that AI security research could become concentrated in just a handful of model providers. I don&#8217;t think that&#8217;s a healthy direction for the industry. Security benefits from independent researchers, different perspectives, and open competition. If only a few companies have the best capabilities, I think the ecosystem will become less innovative and ultimately less secure.</p><div><hr></div><h2>Technical Deep Dive: Rootless Containers and Seccomp</h2><p><strong>Q:</strong> Rootless containers depend on unprivileged user namespaces, and those have historically been an exploit vector in their own right, with several distros shipping them disabled by default for exactly that reason.</p><p>So from an attacker&#8217;s point of view: does a machine with unprivileged userns enabled end up with a larger kernel attack surface than one without, even when the userns is what is providing the isolation?</p><p>Put differently, is a rootless sandbox net-positive or net-negative for the host?</p><p>And a practical follow-up: does a seccomp filter meaningfully raise the cost of the kind of kernel exploitation you do, or is it mostly an obstacle that gets routed around?</p><p><strong>A:</strong> That&#8217;s a great question. I think unprivileged user namespaces definitely increase the kernel attack surface. Historically, we&#8217;ve seen quite a few kernel vulnerabilities that were only reachable because user namespaces were enabled.</p><p>That said, I still think rootless sandboxes are generally a net positive. Yes, they expose more kernel code, but they also remove a lot of privileges from compromised applications. In practice, it&#8217;s a tradeoff, and I think the security benefits usually outweigh the additional kernel exposure.</p><p>As for seccomp, I think it absolutely raises the cost of exploitation. A well-designed seccomp profile removes many useful syscalls and forces an attacker to find a much narrower path. It&#8217;s not a silver bullet, but it definitely makes kernel exploitation harder rather than just being something you can easily work around.</p><div><hr></div><h2>Current Work and Where to Follow</h2><p><strong>Q:</strong> What sort of research are you focused on right now?</p><p>What are you currently working on?</p><p>Where can we follow your work and get updates on your research?</p><p><strong>A:</strong> Right now, my main focus is finding more real-world vulnerabilities with meaningful impact. I&#8217;m particularly interested in bugs that affect widely deployed software and open-source dependencies, where a single overlooked issue can have a large downstream impact. My teammates are working on similar problems, so we&#8217;re constantly exploring new attack surfaces and pushing deeper into software stacks that are often overlooked.</p><p>You can follow me on X (<a href="https://x.com/wupco1996">@wupco1996</a>) and keep an eye on the <a href="https://depthfirst.com/blog">depthfirst blog</a>. We have several exciting research projects and vulnerability write-ups in the pipeline, including some very interesting real-world vulnerability analyses that we&#8217;ll be publishing soon.</p><div><hr></div><h2><strong>Join PWN on Reddit</strong></h2><p><a href="https://www.reddit.com/r/pwnhub/">PWN</a><span> is where security people go to stay ahead.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xBGM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xBGM!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" width="1200" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:400,&quot;width&quot;:1200,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:196009,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/196609498?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Breach reports, exploits, vendor advisories, and the kind of conversations that make you better at your job, all in one feed.</p><p>We&#8217;re 40,000+ hackers and cybersecurity enthusiasts strong, with 935,000 monthly views and 200+ new members every day.</p><p>You&#8217;ll be in the same threads as journalists from Wired Magazine, Electronic Frontier Foundation, 404 Media, Fast Company, CNET, The Guardian, Daily Mail, and Ars Technica breaking the stories firsthand, plus security teams from vendors like Proton, Intigriti, and Hudson Rock sharing research and answering questions directly.</p><h3><strong>Why join:</strong></h3><ul><li><p><strong>Know what&#8217;s hitting before it hits you.</strong><span> Get the breach reports, exploits, and vendor advisories early so you can act before they become your problem.</span></p></li><li><p><strong>Get sharper, not just busier.</strong><span> Skip the noise and learn from people actually doing the work, on the AI exploits, new defenses, and techniques that move your skills forward.</span></p></li><li><p><strong>Make the career move you&#8217;ve been planning.</strong><span> Whether it&#8217;s your first paycheck in security or your jump from IT into offensive work, you&#8217;ll find members who&#8217;ve made it and are happy to help you do the same.</span></p></li><li><p><strong>Be the person at work who already knows.</strong><span> Walk into Monday meetings ahead of the ransomware incidents and zero-days landing on your team&#8217;s radar, and earn the trust that comes with it.</span></p></li><li><p><strong>Find your people.</strong><span> Trade ideas with hackers and pros who&#8217;ll actually answer your questions, in a community that stays high quality because the bots and noise get cleaned up.</span></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/&quot;,&quot;text&quot;:&quot;Join PWN on Reddit&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.reddit.com/r/pwnhub/"><span>Join PWN on Reddit</span></a></p>]]></content:encoded></item><item><title><![CDATA[Apple Sued Over $1.8 Million Crypto Scam]]></title><description><![CDATA[Three users say $1.8 million in Bitcoin vanished. The real Sparrow Wallet has never existed on iOS.]]></description><link>https://pwnhackers.substack.com/p/apple-sued-over-18-million-crypto</link><guid isPermaLink="false">https://pwnhackers.substack.com/p/apple-sued-over-18-million-crypto</guid><dc:creator><![CDATA[PWN | Hacker Community]]></dc:creator><pubDate>Fri, 31 Jul 2026 18:34:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Alj8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec77d7c1-9831-4da1-a258-0200d1e19a67_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Three iPhone users are suing Apple in California federal court after allegedly losing a combined $1.8 million in Bitcoin to a counterfeit Sparrow Wallet app downloaded from the App Store.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.tiktok.com/t/ZP8tw2tLb/&quot;,&quot;text&quot;:&quot;View Story&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.tiktok.com/t/ZP8tw2tLb/"><span>View Story</span></a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.tiktok.com/t/ZP8tw2tLb/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Alj8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec77d7c1-9831-4da1-a258-0200d1e19a67_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!Alj8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec77d7c1-9831-4da1-a258-0200d1e19a67_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!Alj8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec77d7c1-9831-4da1-a258-0200d1e19a67_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!Alj8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec77d7c1-9831-4da1-a258-0200d1e19a67_1080x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Alj8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec77d7c1-9831-4da1-a258-0200d1e19a67_1080x1080.png" width="1080" height="1080" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ec77d7c1-9831-4da1-a258-0200d1e19a67_1080x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1080,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:396331,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.tiktok.com/t/ZP8tw2tLb/&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/209291772?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec77d7c1-9831-4da1-a258-0200d1e19a67_1080x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Alj8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec77d7c1-9831-4da1-a258-0200d1e19a67_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!Alj8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec77d7c1-9831-4da1-a258-0200d1e19a67_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!Alj8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec77d7c1-9831-4da1-a258-0200d1e19a67_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!Alj8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec77d7c1-9831-4da1-a258-0200d1e19a67_1080x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The real Sparrow Wallet is desktop only and has never shipped on ios, so every version in the App Store is fake. Developer Craig Raw says he reported the clones for years. Apple says it removed the impersonating apps and terminated the developer accounts behind them.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.tiktok.com/t/ZP8tw2tLb/&quot;,&quot;text&quot;:&quot;View Story&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.tiktok.com/t/ZP8tw2tLb/"><span>View Story</span></a></p><div><hr></div><h2>Discussion on This Story</h2><p>Members in PWN are <a href="https://www.reddit.com/r/pwnhub/comments/1v776om/apple_sued_by_customers_who_lost_combined_18/">discussing this story here</a>.</p><div><hr></div><h2><strong>Join PWN on Reddit</strong></h2><p><a href="https://www.reddit.com/r/pwnhub/">PWN</a><span> is where security people go to stay ahead.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xBGM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xBGM!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" width="1200" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:400,&quot;width&quot;:1200,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:196009,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/196609498?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Breach reports, exploits, vendor advisories, and the kind of conversations that make you better at your job, all in one feed.</p><p>We&#8217;re 40,000+ hackers and cybersecurity enthusiasts strong, with 935,000 monthly views and 200+ new members every day.</p><p>You&#8217;ll be in the same threads as journalists from Wired Magazine, Electronic Frontier Foundation, 404 Media, Fast Company, CNET, The Guardian, Daily Mail, and Ars Technica breaking the stories firsthand, plus security teams from vendors like Proton, Intigriti, and Hudson Rock sharing research and answering questions directly.</p><h3><strong>Why join:</strong></h3><ul><li><p><strong>Know what&#8217;s hitting before it hits you.</strong><span> Get the breach reports, exploits, and vendor advisories early so you can act before they become your problem.</span></p></li><li><p><strong>Get sharper, not just busier.</strong><span> Skip the noise and learn from people actually doing the work, on the AI exploits, new defenses, and techniques that move your skills forward.</span></p></li><li><p><strong>Make the career move you&#8217;ve been planning.</strong><span> Whether it&#8217;s your first paycheck in security or your jump from IT into offensive work, you&#8217;ll find members who&#8217;ve made it and are happy to help you do the same.</span></p></li><li><p><strong>Be the person at work who already knows.</strong><span> Walk into Monday meetings ahead of the ransomware incidents and zero-days landing on your team&#8217;s radar, and earn the trust that comes with it.</span></p></li><li><p><strong>Find your people.</strong><span> Trade ideas with hackers and pros who&#8217;ll actually answer your questions, in a community that stays high quality because the bots and noise get cleaned up.</span></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/&quot;,&quot;text&quot;:&quot;Join PWN on Reddit&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.reddit.com/r/pwnhub/"><span>Join PWN on Reddit</span></a></p>]]></content:encoded></item><item><title><![CDATA[Upcoming AMA: Yuhang Wu (Ex-Tesla, TikTok) Red Team Engineer & Exploit Developer]]></title><description><![CDATA[Don&#8217;t miss the AMA with Yuhang Wu, where we learn about elite enterprise infrastructure hacking, Linux kernel exploitation, and the future of autonomous AI security.]]></description><link>https://pwnhackers.substack.com/p/upcoming-ama-yuhang-wu-ex-tesla-tiktok</link><guid isPermaLink="false">https://pwnhackers.substack.com/p/upcoming-ama-yuhang-wu-ex-tesla-tiktok</guid><dc:creator><![CDATA[PWN | Hacker Community]]></dc:creator><pubDate>Thu, 30 Jul 2026 17:43:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!P6Jv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7a00ef1-5a02-48bd-adba-07b945e94bf6_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Don&#8217;t miss the</strong> <strong>AMA with Yuhang Wu</strong>, where we learn about elite enterprise infrastructure hacking, Linux kernel exploitation, and the future of autonomous AI security.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.reddit.com/r/pwnhub/comments/1v9amgp/im_a_vulnerability_researcher_at_depthfirst_our/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!P6Jv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7a00ef1-5a02-48bd-adba-07b945e94bf6_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!P6Jv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7a00ef1-5a02-48bd-adba-07b945e94bf6_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!P6Jv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7a00ef1-5a02-48bd-adba-07b945e94bf6_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!P6Jv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7a00ef1-5a02-48bd-adba-07b945e94bf6_1080x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!P6Jv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7a00ef1-5a02-48bd-adba-07b945e94bf6_1080x1080.png" width="1080" height="1080" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f7a00ef1-5a02-48bd-adba-07b945e94bf6_1080x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1080,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:519924,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.reddit.com/r/pwnhub/comments/1v9amgp/im_a_vulnerability_researcher_at_depthfirst_our/&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/209147900?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7a00ef1-5a02-48bd-adba-07b945e94bf6_1080x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!P6Jv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7a00ef1-5a02-48bd-adba-07b945e94bf6_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!P6Jv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7a00ef1-5a02-48bd-adba-07b945e94bf6_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!P6Jv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7a00ef1-5a02-48bd-adba-07b945e94bf6_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!P6Jv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7a00ef1-5a02-48bd-adba-07b945e94bf6_1080x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Guest Credentials:</strong></p><ul><li><p><strong>Former Red Team Engineer at TikTok</strong>, targeting cloud and application-layer defenses.</p></li><li><p><strong>Former Security Engineer at Tesla</strong>, securing vehicle software, factory systems, and internal applications.</p></li><li><p><strong>Co-developer of &#8220;DirtyCred&#8221;</strong>, a groundbreaking Linux kernel exploitation technique.</p></li><li><p><strong>AI Security Innovator</strong>, who built LLM-based autonomous agents that uncovered 8 P1 (critical-severity) production vulnerabilities.</p></li></ul><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/comments/1v9amgp/im_a_vulnerability_researcher_at_depthfirst_our/&quot;,&quot;text&quot;:&quot;Ask Your Questions Here!&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.reddit.com/r/pwnhub/comments/1v9amgp/im_a_vulnerability_researcher_at_depthfirst_our/"><span>Ask Your Questions Here!</span></a></p><div><hr></div><p><strong>Yuhang Wu is a vulnerability researcher at</strong> <strong><a href="https://depthfirst.com/">depthfirst</a>,</strong> where he works on autonomous vulnerability discovery as part of the <a href="https://depthfirst.com/open-defense">Open Defense Initiative</a>.</p><p>He recently published an <a href="https://depthfirst.com/research/going-depthfirst-achieving-gitlab-rce-via-two-ruby-memory-corruption-vulnerabilities">exploit chain achieving remote code execution on default GitLab installations</a>, built from two Ruby memory corruption bugs in Oj that had gone undetected for nearly five years.</p><p>Before depthfirst, Yuhang was an AI Red Team Engineer at TikTok, where he built a security testing framework that uses fuzzing and prompt mutations to surface safety and security weaknesses in AI models.</p><p>He holds a PhD from Northwestern University and has more than 10 years of experience as a competitive CTF player, including nine consecutive appearances at the DEF CON CTF Finals. He has spoken at Black Hat USA and had his research referenced in Phrack Magazine.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/comments/1v9amgp/im_a_vulnerability_researcher_at_depthfirst_our/&quot;,&quot;text&quot;:&quot;Ask Your Questions Here!&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.reddit.com/r/pwnhub/comments/1v9amgp/im_a_vulnerability_researcher_at_depthfirst_our/"><span>Ask Your Questions Here!</span></a></p><div><hr></div><h2><strong>Join PWN on Reddit</strong></h2><p><a href="https://www.reddit.com/r/pwnhub/">PWN</a> is where security people go to stay ahead.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xBGM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xBGM!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" width="1200" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:400,&quot;width&quot;:1200,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:196009,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/196609498?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"></figcaption></figure></div><p>Breach reports, exploits, vendor advisories, and the kind of conversations that make you better at your job, all in one feed.</p><p>We&#8217;re 40,000+ hackers and cybersecurity enthusiasts strong, with 935,000 monthly views and 200+ new members every day.</p><p>You&#8217;ll be in the same threads as journalists from Wired Magazine, Electronic Frontier Foundation, 404 Media, Fast Company, CNET, The Guardian, Daily Mail, and Ars Technica breaking the stories firsthand, plus security teams from vendors like Proton, Intigriti, and Hudson Rock sharing research and answering questions directly.</p><h3><strong>Why join:</strong></h3><ul><li><p><strong>Know what&#8217;s hitting before it hits you.</strong> Get the breach reports, exploits, and vendor advisories early so you can act before they become your problem.</p></li><li><p><strong>Get sharper, not just busier.</strong> Skip the noise and learn from people actually doing the work, on the AI exploits, new defenses, and techniques that move your skills forward.</p></li><li><p><strong>Make the career move you&#8217;ve been planning.</strong> Whether it&#8217;s your first paycheck in security or your jump from IT into offensive work, you&#8217;ll find members who&#8217;ve made it and are happy to help you do the same.</p></li><li><p><strong>Be the person at work who already knows.</strong> Walk into Monday meetings ahead of the ransomware incidents and zero-days landing on your team&#8217;s radar, and earn the trust that comes with it.</p></li><li><p><strong>Find your people.</strong> Trade ideas with hackers and pros who&#8217;ll actually answer your questions, in a community that stays high quality because the bots and noise get cleaned up.</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/&quot;,&quot;text&quot;:&quot;Join PWN on Reddit&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.reddit.com/r/pwnhub/"><span>Join PWN on Reddit</span></a></p>]]></content:encoded></item><item><title><![CDATA[AI Researchers Claim Security is Impossible]]></title><description><![CDATA[Claude, GPT, and other Al models cannot tell whose instructions they are actually following.]]></description><link>https://pwnhackers.substack.com/p/ai-researchers-claim-security-is</link><guid isPermaLink="false">https://pwnhackers.substack.com/p/ai-researchers-claim-security-is</guid><dc:creator><![CDATA[PWN | Hacker Community]]></dc:creator><pubDate>Thu, 30 Jul 2026 14:30:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!TTBk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa23fae7b-89eb-4487-95ad-c409b5636ae6_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Chatbots sort every piece of text into roles. </p><p>One label marks what the user typed, another marks what the model said back, another marks the private notes a model writes to itself while reasoning, and another marks text pulled in from a webpage or an outside tool.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.tiktok.com/t/ZP8t7t4kH/&quot;,&quot;text&quot;:&quot;View Story&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.tiktok.com/t/ZP8t7t4kH/"><span>View Story</span></a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.tiktok.com/t/ZP8t7t4kH/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TTBk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa23fae7b-89eb-4487-95ad-c409b5636ae6_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!TTBk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa23fae7b-89eb-4487-95ad-c409b5636ae6_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!TTBk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa23fae7b-89eb-4487-95ad-c409b5636ae6_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!TTBk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa23fae7b-89eb-4487-95ad-c409b5636ae6_1080x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TTBk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa23fae7b-89eb-4487-95ad-c409b5636ae6_1080x1080.png" width="1080" height="1080" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a23fae7b-89eb-4487-95ad-c409b5636ae6_1080x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1080,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:413441,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.tiktok.com/t/ZP8t7t4kH/&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/209123051?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa23fae7b-89eb-4487-95ad-c409b5636ae6_1080x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TTBk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa23fae7b-89eb-4487-95ad-c409b5636ae6_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!TTBk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa23fae7b-89eb-4487-95ad-c409b5636ae6_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!TTBk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa23fae7b-89eb-4487-95ad-c409b5636ae6_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!TTBk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa23fae7b-89eb-4487-95ad-c409b5636ae6_1080x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Those labels are the foundation of nearly every defense against jailbreaks and prompt injections, because most attacks work by making a model treat one kind of text as another.</p><p>Independent researchers Jasmine Cui and Charles Ye looked inside several models to see how well that system holds up.</p><p>They found that models judge a piece of text by its writing style and word choice, not by the label wrapped around it. Swapping the labels changed almost nothing. Text that reads like a model&#8217;s own private reasoning gets treated as trustworthy, no matter who actually wrote it.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.tiktok.com/t/ZP8t7t4kH/&quot;,&quot;text&quot;:&quot;View Story&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.tiktok.com/t/ZP8t7t4kH/"><span>View Story</span></a></p><div><hr></div><h2>Discussion on This Story</h2><p>Members in PWN are <a href="https://www.reddit.com/r/pwnhub/comments/1vaqhcf/a_fundamental_flaw_leaves_llms_strikingly/">discussing this story here</a>.</p><div><hr></div><h2><strong>Join PWN on Reddit</strong></h2><p><a href="https://www.reddit.com/r/pwnhub/">PWN</a><span> is where security people go to stay ahead.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xBGM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xBGM!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" width="1200" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:400,&quot;width&quot;:1200,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:196009,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/196609498?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Breach reports, exploits, vendor advisories, and the kind of conversations that make you better at your job, all in one feed.</p><p>We&#8217;re 40,000+ hackers and cybersecurity enthusiasts strong, with 935,000 monthly views and 200+ new members every day.</p><p><span>You&#8217;ll be in the same threads as journalists from </span><a href="https://www.reddit.com/r/pwnhub/comments/1rx58fn/hundreds_of_millions_of_iphones_can_be_hacked/">Wired Magazine</a><span>, </span><a href="https://www.reddit.com/r/pwnhub/comments/1mx1pz1/were_eff_were_launching_a_critical_campaign_to/">Electronic Frontier Foundation</a><span>, </span><a href="https://www.reddit.com/r/pwnhub/comments/1s4hw6c/apple_gives_fbi_a_users_real_name_hidden_behind/">404 Media</a><span>, </span><a href="https://www.reddit.com/r/pwnhub/comments/1skd7vq/is_mythos_a_blessing_or_a_curse_for_cybersecurity/">Fast Company</a><span>, and </span><a href="https://www.reddit.com/r/pwnhub/comments/1t72br7/revealed_russias_top_secret_spy_school_teaching/">The Guardian</a><span> breaking the stories firsthand, plus security teams from vendors like </span><a href="https://proton.me/">Proton</a><span>, </span><a href="https://www.intigriti.com/">Intigriti</a><span>, and </span><a href="https://www.hudsonrock.com/">Hudson Rock</a><span> sharing research and answering questions directly.</span></p><h3><strong>Why join:</strong></h3><ul><li><p><strong>Know what&#8217;s hitting before it hits you.</strong><span> Get the breach reports, exploits, and vendor advisories early so you can act before they become your problem.</span></p></li><li><p><strong>Get sharper, not just busier.</strong><span> Skip the noise and learn from people actually doing the work, on the AI exploits, new defenses, and techniques that move your skills forward.</span></p></li><li><p><strong>Make the career move you&#8217;ve been planning.</strong><span> Whether it&#8217;s your first paycheck in security or your jump from IT into offensive work, you&#8217;ll find members who&#8217;ve made it and are happy to help you do the same.</span></p></li><li><p><strong>Be the person at work who already knows.</strong><span> Walk into Monday meetings ahead of the ransomware incidents and zero-days landing on your team&#8217;s radar, and earn the trust that comes with it.</span></p></li><li><p><strong>Find your people.</strong><span> Trade ideas with hackers and pros who&#8217;ll actually answer your questions, in a community that stays high quality because the bots and noise get cleaned up.</span></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/&quot;,&quot;text&quot;:&quot;Join PWN on Reddit&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.reddit.com/r/pwnhub/"><span>Join PWN on Reddit</span></a></p>]]></content:encoded></item><item><title><![CDATA[Claude Al chats exposed on Google search]]></title><description><![CDATA[Publicly shared Claude Al chats from Anthropic were exposed in Google search results this week. Indexed pages reportedly included API keys, crypto wallet details, resumes, and company documents, though no account was hacked.]]></description><link>https://pwnhackers.substack.com/p/claude-al-chats-exposed-on-google</link><guid isPermaLink="false">https://pwnhackers.substack.com/p/claude-al-chats-exposed-on-google</guid><dc:creator><![CDATA[PWN | Hacker Community]]></dc:creator><pubDate>Thu, 30 Jul 2026 02:32:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JYhJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54e3cf4b-5230-4781-a2ed-ceb4317e6229_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Publicly shared Claude Al chats from Anthropic were exposed in Google search results this week.</strong> Indexed pages reportedly included API keys, crypto wallet details, resumes, and company documents, though no account was hacked. </p><p>Anthropic says it closed the crawler gap within days, but cached copies may still exist. If you have shared a Claude chat, check Settings, then Privacy, then Shared Chats.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.tiktok.com/t/ZP8tWQrvV/&quot;,&quot;text&quot;:&quot;View Story&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.tiktok.com/t/ZP8tWQrvV/"><span>View Story</span></a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.tiktok.com/t/ZP8tWQrvV/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JYhJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54e3cf4b-5230-4781-a2ed-ceb4317e6229_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!JYhJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54e3cf4b-5230-4781-a2ed-ceb4317e6229_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!JYhJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54e3cf4b-5230-4781-a2ed-ceb4317e6229_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!JYhJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54e3cf4b-5230-4781-a2ed-ceb4317e6229_1080x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JYhJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54e3cf4b-5230-4781-a2ed-ceb4317e6229_1080x1080.png" width="1080" height="1080" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/54e3cf4b-5230-4781-a2ed-ceb4317e6229_1080x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1080,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:502928,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.tiktok.com/t/ZP8tWQrvV/&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/209061598?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54e3cf4b-5230-4781-a2ed-ceb4317e6229_1080x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JYhJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54e3cf4b-5230-4781-a2ed-ceb4317e6229_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!JYhJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54e3cf4b-5230-4781-a2ed-ceb4317e6229_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!JYhJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54e3cf4b-5230-4781-a2ed-ceb4317e6229_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!JYhJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54e3cf4b-5230-4781-a2ed-ceb4317e6229_1080x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Over the weekend of July 25, a Reddit user ran the search term <code>site:claude.ai/share</code> on Google and found a long list of Claude Al conversations sitting in the results.</p><p>Anthropic&#8217;s Claude lets any user turn a chat into a public link with one click of the Share button, and the resulting page shows everything sent up to that point, including images and code.</p><p>None of it came from a hacked account or a leaked database.</p><p>The topics ranged from health questions, legal situations, work projects, and code reviews. Each page had been made public by the person who created it, but most people who share a link with one colleague or friend do not expect Google to hand it to anyone searching a name, a company, or a technical term.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.tiktok.com/t/ZP8tWQrvV/&quot;,&quot;text&quot;:&quot;View Story&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.tiktok.com/t/ZP8tWQrvV/"><span>View Story</span></a></p><div><hr></div><h2>Discussion on This Story</h2><p>Members in PWN are <a href="https://www.reddit.com/r/pwnhub/comments/1v6o8bd/claude_ai_security_risk_google_dork_exposes/">discussing this story here</a>.</p><div><hr></div><h2><strong>Join PWN on Reddit</strong></h2><p><a href="https://www.reddit.com/r/pwnhub/">PWN</a><span> is where security people go to stay ahead.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xBGM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xBGM!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" width="1200" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:400,&quot;width&quot;:1200,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:196009,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/196609498?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Breach reports, exploits, vendor advisories, and the kind of conversations that make you better at your job, all in one feed.</p><p>We&#8217;re 40,000+ hackers and cybersecurity enthusiasts strong, with 935,000 monthly views and 200+ new members every day.</p><p><span>You&#8217;ll be in the same threads as journalists from </span><a href="https://www.reddit.com/r/pwnhub/comments/1rx58fn/hundreds_of_millions_of_iphones_can_be_hacked/">Wired Magazine</a><span>, </span><a href="https://www.reddit.com/r/pwnhub/comments/1mx1pz1/were_eff_were_launching_a_critical_campaign_to/">Electronic Frontier Foundation</a><span>, </span><a href="https://www.reddit.com/r/pwnhub/comments/1s4hw6c/apple_gives_fbi_a_users_real_name_hidden_behind/">404 Media</a><span>, </span><a href="https://www.reddit.com/r/pwnhub/comments/1skd7vq/is_mythos_a_blessing_or_a_curse_for_cybersecurity/">Fast Company</a><span>, and </span><a href="https://www.reddit.com/r/pwnhub/comments/1t72br7/revealed_russias_top_secret_spy_school_teaching/">The Guardian</a><span> breaking the stories firsthand, plus security teams from vendors like </span><a href="https://proton.me/">Proton</a><span>, </span><a href="https://www.intigriti.com/">Intigriti</a><span>, and </span><a href="https://www.hudsonrock.com/">Hudson Rock</a><span> sharing research and answering questions directly.</span></p><h3><strong>Why join:</strong></h3><ul><li><p><strong>Know what&#8217;s hitting before it hits you.</strong><span> Get the breach reports, exploits, and vendor advisories early so you can act before they become your problem.</span></p></li><li><p><strong>Get sharper, not just busier.</strong><span> Skip the noise and learn from people actually doing the work, on the AI exploits, new defenses, and techniques that move your skills forward.</span></p></li><li><p><strong>Make the career move you&#8217;ve been planning.</strong><span> Whether it&#8217;s your first paycheck in security or your jump from IT into offensive work, you&#8217;ll find members who&#8217;ve made it and are happy to help you do the same.</span></p></li><li><p><strong>Be the person at work who already knows.</strong><span> Walk into Monday meetings ahead of the ransomware incidents and zero-days landing on your team&#8217;s radar, and earn the trust that comes with it.</span></p></li><li><p><strong>Find your people.</strong><span> Trade ideas with hackers and pros who&#8217;ll actually answer your questions, in a community that stays high quality because the bots and noise get cleaned up.</span></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/&quot;,&quot;text&quot;:&quot;Join PWN on Reddit&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.reddit.com/r/pwnhub/"><span>Join PWN on Reddit</span></a></p>]]></content:encoded></item><item><title><![CDATA[Anthropic AI Breaks Post-Quantum HAWK-256 and Accelerates AES-128 Attack]]></title><description><![CDATA[Anthropic&#8217;s Claude AI model has derived a key-recovery attack against the HAWK-256 post-quantum signature scheme and a significant speedup for a seven-round AES-128 attack, though neither result impacts current production security.]]></description><link>https://pwnhackers.substack.com/p/anthropic-ai-breaks-post-quantum</link><guid isPermaLink="false">https://pwnhackers.substack.com/p/anthropic-ai-breaks-post-quantum</guid><dc:creator><![CDATA[PWN | Hacker Community]]></dc:creator><pubDate>Wed, 29 Jul 2026 20:00:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!v5u1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d62d9f8-f6f3-4453-afd6-8346d055d5d6_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Anthropic&#8217;s Claude AI model has derived a key-recovery attack against the HAWK-256 post-quantum signature scheme </strong>and a significant speedup for a seven-round AES-128 attack, though neither result impacts current production security.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.tiktok.com/t/ZP8tnVeDJ/&quot;,&quot;text&quot;:&quot;View Story&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.tiktok.com/t/ZP8tnVeDJ/"><span>View Story</span></a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.tiktok.com/t/ZP8tnVeDJ/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!v5u1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d62d9f8-f6f3-4453-afd6-8346d055d5d6_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!v5u1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d62d9f8-f6f3-4453-afd6-8346d055d5d6_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!v5u1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d62d9f8-f6f3-4453-afd6-8346d055d5d6_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!v5u1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d62d9f8-f6f3-4453-afd6-8346d055d5d6_1080x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!v5u1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d62d9f8-f6f3-4453-afd6-8346d055d5d6_1080x1080.png" width="1080" height="1080" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6d62d9f8-f6f3-4453-afd6-8346d055d5d6_1080x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1080,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:613365,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.tiktok.com/t/ZP8tnVeDJ/&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/209024742?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d62d9f8-f6f3-4453-afd6-8346d055d5d6_1080x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!v5u1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d62d9f8-f6f3-4453-afd6-8346d055d5d6_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!v5u1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d62d9f8-f6f3-4453-afd6-8346d055d5d6_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!v5u1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d62d9f8-f6f3-4453-afd6-8346d055d5d6_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!v5u1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d62d9f8-f6f3-4453-afd6-8346d055d5d6_1080x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Key Points:</strong></p><ul><li><p>Claude AI successfully derived an end-to-end key-recovery attack against HAWK-256, a challenge parameter in NIST&#8217;s post-quantum standardization process.</p></li><li><p>The AI also found a 200- to 800-fold speedup for an attack on seven rounds of AES-128 by removing a guessing step in meet-in-the-middle attacks.</p></li><li><p>Anthropic states that neither attack affects production systems, as HAWK-256 is not a final security parameter and the AES attack requires impractical resources.</p></li><li><p>The research was conducted by the AI model with human verification, costing approximately $100,000 in API usage and hundreds of hours in manual review.</p></li></ul><p>Anthropic has published findings showing that its Claude AI model, specifically the Mythos Preview version, was able to identify critical vulnerabilities in two major cryptographic standards. </p><p>The first result involves HAWK-256, a lattice-based digital signature scheme currently under review by the National Institute of Standards and Technology (NIST). The AI exploited a previously unused symmetry in the lattice structure to reduce the work factor for key recovery, achieving a successful attack in roughly three hours and 42 minutes on a high-end server. However, this attack only applies to the HAWK-256 challenge parameter, not the larger HAWK-512 or HAWK-1024 parameters intended for actual use, which remain computationally impractical to break.</p><p>The second finding relates to the Advanced Encryption Standard (AES). The AI improved an existing meet-in-the-middle attack on seven rounds of AES-128 by developing a new invariant fingerprint called the M&#246;bius Bridge. </p><p>This innovation eliminates a 256-way guessing step, making the attack 200 to 800 times faster than previous methods. Despite this acceleration, the attack still requires an impractical number of chosen plaintexts and does not extend to the full ten rounds of AES-128 used in real-world applications. Anthropic emphasizes that no production software needs to be updated in response to these findings, as the attacks remain theoretical exercises in cryptanalysis rather than immediate threats to deployed systems.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.tiktok.com/t/ZP8tnVeDJ/&quot;,&quot;text&quot;:&quot;View Story&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.tiktok.com/t/ZP8tnVeDJ/"><span>View Story</span></a></p><div><hr></div><p>Discussion on This Story</p><p>Members in PWN are <a href="https://www.reddit.com/r/pwnhub/comments/1v9vanr/anthropic_ai_breaks_postquantum_hawk256_and/">discussing this story here</a>.</p><blockquote><p><strong>Should using a privacy phone raise suspicion at the border?</strong></p><p>An Atlanta man is facing federal charges after his GrapheneOS phone automatically wiped itself during an airport search, a feature the privacy-focused operating system is designed to perform when tamper attempts are detected.</p><p>Prosecutors appear to be treating the wipe as evidence of wrongdoing, while privacy advocates argue that using secure technology is a legal right. The case puts a spotlight on the tension between border search powers and the growing use of privacy-hardening tools by ordinary people.</p><p><strong>What do you think?</strong></p><p>Should wiping your phone at the border be treated as suspicious behavior, or is protecting your data a basic right?</p></blockquote><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/comments/1v9vanr/anthropic_ai_breaks_postquantum_hawk256_and/&quot;,&quot;text&quot;:&quot;Join the Discussion&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.reddit.com/r/pwnhub/comments/1v9vanr/anthropic_ai_breaks_postquantum_hawk256_and/"><span>Join the Discussion</span></a></p><div><hr></div><h2><strong>Join PWN on Reddit</strong></h2><p><a href="https://www.reddit.com/r/pwnhub/">PWN</a><span> is where security people go to stay ahead.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xBGM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xBGM!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" width="1200" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:400,&quot;width&quot;:1200,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:196009,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/196609498?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Breach reports, exploits, vendor advisories, and the kind of conversations that make you better at your job, all in one feed.</p><p>We&#8217;re 40,000+ hackers and cybersecurity enthusiasts strong, with 935,000 monthly views and 200+ new members every day.</p><p><span>You&#8217;ll be in the same threads as journalists from </span><a href="https://www.reddit.com/r/pwnhub/comments/1rx58fn/hundreds_of_millions_of_iphones_can_be_hacked/">Wired Magazine</a><span>, </span><a href="https://www.reddit.com/r/pwnhub/comments/1mx1pz1/were_eff_were_launching_a_critical_campaign_to/">Electronic Frontier Foundation</a><span>, </span><a href="https://www.reddit.com/r/pwnhub/comments/1s4hw6c/apple_gives_fbi_a_users_real_name_hidden_behind/">404 Media</a><span>, </span><a href="https://www.reddit.com/r/pwnhub/comments/1skd7vq/is_mythos_a_blessing_or_a_curse_for_cybersecurity/">Fast Company</a><span>, and </span><a href="https://www.reddit.com/r/pwnhub/comments/1t72br7/revealed_russias_top_secret_spy_school_teaching/">The Guardian</a><span> breaking the stories firsthand, plus security teams from vendors like </span><a href="https://proton.me/">Proton</a><span>, </span><a href="https://www.intigriti.com/">Intigriti</a><span>, and </span><a href="https://www.hudsonrock.com/">Hudson Rock</a><span> sharing research and answering questions directly.</span></p><h3><strong>Why join:</strong></h3><ul><li><p><strong>Know what&#8217;s hitting before it hits you.</strong><span> Get the breach reports, exploits, and vendor advisories early so you can act before they become your problem.</span></p></li><li><p><strong>Get sharper, not just busier.</strong><span> Skip the noise and learn from people actually doing the work, on the AI exploits, new defenses, and techniques that move your skills forward.</span></p></li><li><p><strong>Make the career move you&#8217;ve been planning.</strong><span> Whether it&#8217;s your first paycheck in security or your jump from IT into offensive work, you&#8217;ll find members who&#8217;ve made it and are happy to help you do the same.</span></p></li><li><p><strong>Be the person at work who already knows.</strong><span> Walk into Monday meetings ahead of the ransomware incidents and zero-days landing on your team&#8217;s radar, and earn the trust that comes with it.</span></p></li><li><p><strong>Find your people.</strong><span> Trade ideas with hackers and pros who&#8217;ll actually answer your questions, in a community that stays high quality because the bots and noise get cleaned up.</span></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/&quot;,&quot;text&quot;:&quot;Join PWN on Reddit&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.reddit.com/r/pwnhub/"><span>Join PWN on Reddit</span></a></p>]]></content:encoded></item><item><title><![CDATA[An AI Agent Found the Security Vulnerability. This Researcher Turned It Into an Exploit. Ask Him Anything.]]></title><description><![CDATA[Most software is built on top of small, shared pieces of open-source code that almost no one looks at closely.]]></description><link>https://pwnhackers.substack.com/p/an-ai-agent-found-the-security-vulnerability</link><guid isPermaLink="false">https://pwnhackers.substack.com/p/an-ai-agent-found-the-security-vulnerability</guid><dc:creator><![CDATA[PWN | Hacker Community]]></dc:creator><pubDate>Tue, 28 Jul 2026 21:35:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!iimE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e87149-de80-49af-b6bd-e546a06da952_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Most software is built on top of small, shared pieces of open-source code that almost no one looks at closely.</strong> </p><p>One of those pieces, a Ruby component called Oj used to read data in a common format, quietly carried security flaws for nearly five years. No human had caught them.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/comments/1v9amgp/im_a_vulnerability_researcher_at_depthfirst_our/&quot;,&quot;text&quot;:&quot;Ask Your Questions&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.reddit.com/r/pwnhub/comments/1v9amgp/im_a_vulnerability_researcher_at_depthfirst_our/"><span>Ask Your Questions</span></a></p><div><hr></div><p>An autonomous AI system did. It reviewed the code, flagged the suspicious spots, and Depthfirst researcher Yuhang Wu took it from there, showing how two of those flaws could be combined to break into a default installation of GitLab, the platform millions of developers use to store their code. </p><p>An ordinary user account was enough to pull it off.</p><p>Yuhang broke down how the whole thing worked, from the AI-assisted discovery to the responsible way the bugs were reported and fixed, and he&#8217;s coming to the PWN Community to answer your questions. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iimE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e87149-de80-49af-b6bd-e546a06da952_1080x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iimE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e87149-de80-49af-b6bd-e546a06da952_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!iimE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e87149-de80-49af-b6bd-e546a06da952_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!iimE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e87149-de80-49af-b6bd-e546a06da952_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!iimE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e87149-de80-49af-b6bd-e546a06da952_1080x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iimE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e87149-de80-49af-b6bd-e546a06da952_1080x1080.png" width="1080" height="1080" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/82e87149-de80-49af-b6bd-e546a06da952_1080x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1080,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:865814,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/208892326?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e87149-de80-49af-b6bd-e546a06da952_1080x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iimE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e87149-de80-49af-b6bd-e546a06da952_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!iimE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e87149-de80-49af-b6bd-e546a06da952_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!iimE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e87149-de80-49af-b6bd-e546a06da952_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!iimE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e87149-de80-49af-b6bd-e546a06da952_1080x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Whether you write exploit code for a living or just want to understand how AI is changing security, there&#8217;s something here for you.</p><p>Yuhang is a vulnerability researcher at depthfirst, where he works on AI-assisted security research through the Open Defense Initiative. Before depthfirst, he was an AI Red Team Engineer at TikTok. </p><p>He holds a PhD from Northwestern University and has nine consecutive appearances at the DEF CON CTF Finals. He&#8217;s joining us live on Friday, July 31st from 12 to 1 PM Pacific Time (3 to 4 PM ET).</p><div><hr></div><h3>Post your questions</h3><p>Post your questions in the comments now, then join the live AMA on Friday, July 31st at 12 PM PT: <a href="https://www.reddit.com/r/pwnhub/comments/1v9amgp/im_a_vulnerability_researcher_at_depthfirst_our/">SHARE QUESTIONS HERE</a></p><div><hr></div><h2>Upcoming AMA: Friday, July 31st (12 PM - 1 PM Pacific Time)</h2><blockquote><p>Hi PWN Community,</p><p>I&#8217;m a vulnerability researcher at <a href="https://depthfirst.com/">depthfirst</a>, where I work on AI-assisted security research through the <a href="https://depthfirst.com/open-defense">Open Defense Initiative</a>.</p><p>I recently published a technical case study about two memory-safety issues in Oj, a widely used JSON parser for Ruby applications. These issues had been present for nearly five years and were reachable through GitLab&#8217;s Jupyter notebook diff functionality.</p><p>Our analysis identified several security-relevant issues in Oj&#8217;s native C implementation. By studying how two of them interacted, I was able to demonstrate their impact in GitLab under an authenticated, non-administrative account.</p><p>The issues were reported privately in May. The Oj maintainer responded quickly, released fixes in Oj 3.17.3, and GitLab subsequently updated the affected code path.</p><p>The full research post is available here:</p><p>&#8220;Going depthfirst: Achieving GitLab RCE via Two Ruby Memory Corruption Vulnerabilities&#8221;</p><p><a href="https://depthfirst.com/research/going-depthfirst-achieving-gitlab-rce-via-two-ruby-memory-corruption-vulnerabilities">https://depthfirst.com/research/going-depthfirst-achieving-gitlab-rce-via-two-ruby-memory-corruption-vulnerabilities</a></p><p>I&#8217;ll be hosting an AMA and would be happy to discuss:</p><ul><li><p>The vulnerability research and disclosure process</p></li><li><p>Memory-safety risks in native extensions used by memory-safe languages</p></li><li><p>How AI-assisted systems can help prioritize suspicious code</p></li><li><p>Lessons from analyzing a large C-based Ruby dependency</p></li><li><p>Coordinating fixes across an open-source library and a downstream application</p></li><li><p>Getting started with AI-assisted vulnerability research</p></li><li><p>General questions about security research and defensive tooling</p></li></ul><p>To keep the discussion responsible, I may avoid sharing details that would make reproduction against unpatched systems easier.</p><p>I&#8217;ll be here live on Friday, July 31, from 12:00 PM to 1:00 PM PT. Questions are welcome in advance, and I&#8217;ll answer as many as I can during the session.</p><p>Looking forward to the discussion.</p></blockquote><div><hr></div><h3>Post your questions</h3><p>Post your questions in the comments now, then join the live AMA on Friday, July 31st at 12 PM PT: <a href="https://www.reddit.com/r/pwnhub/comments/1v9amgp/im_a_vulnerability_researcher_at_depthfirst_our/">SHARE QUESTIONS HERE</a></p>]]></content:encoded></item><item><title><![CDATA[Atlanta man charged with crime after GrapheneOS phone wipes itself during airport search]]></title><description><![CDATA[US prosecutors are charging Sam Tunick for allegedly using GrapheneOS, a privacy-focused operating system, to erase evidence on his phone during an airport search.]]></description><link>https://pwnhackers.substack.com/p/atlanta-man-charged-with-crime-after</link><guid isPermaLink="false">https://pwnhackers.substack.com/p/atlanta-man-charged-with-crime-after</guid><dc:creator><![CDATA[PWN | Hacker Community]]></dc:creator><pubDate>Tue, 28 Jul 2026 19:11:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!2tZR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31634175-5a3c-46a9-8605-c4c94debaf4a_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong><span>US prosecutors are charging Sam Tunick for allegedly using GrapheneOS, a privacy-focused operating system, to erase evidence on his phone during an airport search.</span></strong><span> </span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.tiktok.com/t/ZP8tqfFmQ/&quot;,&quot;text&quot;:&quot;View Story&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.tiktok.com/t/ZP8tqfFmQ/"><span>View Story</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.tiktok.com/t/ZP8tqfFmQ/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2tZR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31634175-5a3c-46a9-8605-c4c94debaf4a_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!2tZR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31634175-5a3c-46a9-8605-c4c94debaf4a_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!2tZR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31634175-5a3c-46a9-8605-c4c94debaf4a_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!2tZR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31634175-5a3c-46a9-8605-c4c94debaf4a_1080x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2tZR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31634175-5a3c-46a9-8605-c4c94debaf4a_1080x1080.png" width="1080" height="1080" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/31634175-5a3c-46a9-8605-c4c94debaf4a_1080x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1080,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:657148,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.tiktok.com/t/ZP8tqfFmQ/&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/208874415?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31634175-5a3c-46a9-8605-c4c94debaf4a_1080x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2tZR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31634175-5a3c-46a9-8605-c4c94debaf4a_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!2tZR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31634175-5a3c-46a9-8605-c4c94debaf4a_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!2tZR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31634175-5a3c-46a9-8605-c4c94debaf4a_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!2tZR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31634175-5a3c-46a9-8605-c4c94debaf4a_1080x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>The case raises concerns about the criminalization of security tools and the application of constitutional rights at US borders. </span></p><p><span>The incident is connected to Tunick&#8217;s alleged association with the movement against Cop City, a police training facility.</span></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.tiktok.com/t/ZP8tqfFmQ/&quot;,&quot;text&quot;:&quot;View Story&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.tiktok.com/t/ZP8tqfFmQ/"><span>View Story</span></a></p><div><hr></div><p>Discussion on This Story</p><p>Members in PWN are <a href="https://www.reddit.com/r/pwnhub/comments/1v8gnq3/should_using_a_privacy_phone_raise_suspicion_at/">discussing this story here</a>.</p><blockquote><p><strong>Should using a privacy phone raise suspicion at the border?</strong></p><p>An Atlanta man is facing federal charges after his GrapheneOS phone automatically wiped itself during an airport search, a feature the privacy-focused operating system is designed to perform when tamper attempts are detected.</p><p>Prosecutors appear to be treating the wipe as evidence of wrongdoing, while privacy advocates argue that using secure technology is a legal right. The case puts a spotlight on the tension between border search powers and the growing use of privacy-hardening tools by ordinary people.</p><p><strong>What do you think?</strong></p><p>Should wiping your phone at the border be treated as suspicious behavior, or is protecting your data a basic right?</p></blockquote><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/comments/1v8gnq3/should_using_a_privacy_phone_raise_suspicion_at/&quot;,&quot;text&quot;:&quot;Join the Discussion&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.reddit.com/r/pwnhub/comments/1v8gnq3/should_using_a_privacy_phone_raise_suspicion_at/"><span>Join the Discussion</span></a></p><div><hr></div><h2><strong>Join PWN on Reddit</strong></h2><p><a href="https://www.reddit.com/r/pwnhub/">PWN</a><span> is where security people go to stay ahead.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xBGM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xBGM!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" width="1200" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:400,&quot;width&quot;:1200,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:196009,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/196609498?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Breach reports, exploits, vendor advisories, and the kind of conversations that make you better at your job, all in one feed.</p><p>We&#8217;re 40,000+ hackers and cybersecurity enthusiasts strong, with 935,000 monthly views and 200+ new members every day.</p><p><span>You&#8217;ll be in the same threads as journalists from </span><a href="https://www.reddit.com/r/pwnhub/comments/1rx58fn/hundreds_of_millions_of_iphones_can_be_hacked/">Wired Magazine</a><span>, </span><a href="https://www.reddit.com/r/pwnhub/comments/1mx1pz1/were_eff_were_launching_a_critical_campaign_to/">Electronic Frontier Foundation</a><span>, </span><a href="https://www.reddit.com/r/pwnhub/comments/1s4hw6c/apple_gives_fbi_a_users_real_name_hidden_behind/">404 Media</a><span>, </span><a href="https://www.reddit.com/r/pwnhub/comments/1skd7vq/is_mythos_a_blessing_or_a_curse_for_cybersecurity/">Fast Company</a><span>, and </span><a href="https://www.reddit.com/r/pwnhub/comments/1t72br7/revealed_russias_top_secret_spy_school_teaching/">The Guardian</a><span> breaking the stories firsthand, plus security teams from vendors like </span><a href="https://proton.me/">Proton</a><span>, </span><a href="https://www.intigriti.com/">Intigriti</a><span>, and </span><a href="https://www.hudsonrock.com/">Hudson Rock</a><span> sharing research and answering questions directly.</span></p><h3><strong>Why join:</strong></h3><ul><li><p><strong>Know what&#8217;s hitting before it hits you.</strong><span> Get the breach reports, exploits, and vendor advisories early so you can act before they become your problem.</span></p></li><li><p><strong>Get sharper, not just busier.</strong><span> Skip the noise and learn from people actually doing the work, on the AI exploits, new defenses, and techniques that move your skills forward.</span></p></li><li><p><strong>Make the career move you&#8217;ve been planning.</strong><span> Whether it&#8217;s your first paycheck in security or your jump from IT into offensive work, you&#8217;ll find members who&#8217;ve made it and are happy to help you do the same.</span></p></li><li><p><strong>Be the person at work who already knows.</strong><span> Walk into Monday meetings ahead of the ransomware incidents and zero-days landing on your team&#8217;s radar, and earn the trust that comes with it.</span></p></li><li><p><strong>Find your people.</strong><span> Trade ideas with hackers and pros who&#8217;ll actually answer your questions, in a community that stays high quality because the bots and noise get cleaned up.</span></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/&quot;,&quot;text&quot;:&quot;Join PWN on Reddit&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.reddit.com/r/pwnhub/"><span>Join PWN on Reddit</span></a></p>]]></content:encoded></item><item><title><![CDATA[So You Want to Be an Ethical Hacker? Start Here.]]></title><description><![CDATA[We get a lot of emails from members of the PWN community asking how they can get started as an ethical hacker. We created this guide so everyone who is interested in becoming an ethical hacking can benefit from the response.]]></description><link>https://pwnhackers.substack.com/p/so-you-want-to-be-an-ethical-hacker</link><guid isPermaLink="false">https://pwnhackers.substack.com/p/so-you-want-to-be-an-ethical-hacker</guid><dc:creator><![CDATA[PWN | Hacker Community]]></dc:creator><pubDate>Mon, 27 Jul 2026 20:40:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!mvrC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F980c19f0-a79a-4ca2-b683-dea9646215e7_2000x1046.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>We get a lot of emails from members of the <a href="https://joinpwn.com/">PWN community</a> asking how they can get started as an ethical hacker.</strong> We created this guide so everyone who is interested in becoming an ethical hacking can benefit from the response.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mvrC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F980c19f0-a79a-4ca2-b683-dea9646215e7_2000x1046.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mvrC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F980c19f0-a79a-4ca2-b683-dea9646215e7_2000x1046.png 424w, https://substackcdn.com/image/fetch/$s_!mvrC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F980c19f0-a79a-4ca2-b683-dea9646215e7_2000x1046.png 848w, https://substackcdn.com/image/fetch/$s_!mvrC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F980c19f0-a79a-4ca2-b683-dea9646215e7_2000x1046.png 1272w, https://substackcdn.com/image/fetch/$s_!mvrC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F980c19f0-a79a-4ca2-b683-dea9646215e7_2000x1046.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mvrC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F980c19f0-a79a-4ca2-b683-dea9646215e7_2000x1046.png" width="1456" height="761" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/980c19f0-a79a-4ca2-b683-dea9646215e7_2000x1046.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:761,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2135410,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/208736547?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F980c19f0-a79a-4ca2-b683-dea9646215e7_2000x1046.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mvrC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F980c19f0-a79a-4ca2-b683-dea9646215e7_2000x1046.png 424w, https://substackcdn.com/image/fetch/$s_!mvrC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F980c19f0-a79a-4ca2-b683-dea9646215e7_2000x1046.png 848w, https://substackcdn.com/image/fetch/$s_!mvrC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F980c19f0-a79a-4ca2-b683-dea9646215e7_2000x1046.png 1272w, https://substackcdn.com/image/fetch/$s_!mvrC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F980c19f0-a79a-4ca2-b683-dea9646215e7_2000x1046.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If you have questions, comment below and we&#8217;ll get them answered! Make sure to join our <a href="https://www.reddit.com/r/pwnhub/">free Reddit community</a> for further discussion.</p><div><hr></div><h2>Ethical Hacking <em>Isn&#8217;t</em> for Everyone</h2><p>Before we get into the roadmap, we need to make one thing clear&#8230; <em>Ethical hacking isn&#8217;t for everyone.</em> It doesn&#8217;t matter how smart you are, or how fast you can learn - what really matters is how much you love learning this skillset.</p><p>If you don&#8217;t genuinely love the work, the field will burn you out fast. </p><p>This isn&#8217;t a career you can coast through. It requires constant learning, because the technology, the attack techniques, and the defenses are all evolving at the same time. In the era of artificial intelligence, this pace is accelerated.</p><p>If you&#8217;re not the kind of person who wants to keep reading, testing, and breaking things in your free time, this path will feel like a grind rather than a calling.</p><p><em>The good news is: If you love learning how things work, and breaking them, then this field is for you!</em> <em>Your genuine curiosity for the process is your superpower.</em></p><div><hr></div><h2>What Hacking Actually Requires</h2><p><strong>Here&#8217;s the core truth about hacking:</strong> to exploit a system, you have to have a deep understanding of how it works.</p><p>You need to know exactly how something is supposed to work, in enough depth that you can figure out how to make it do something it was never designed to do. </p><p>That kind of understanding doesn&#8217;t come from a weekend course. It comes from years of curiosity compounding on itself.</p><p>The field is also enormous. </p><p>You could spend an entire career studying one narrow slice of it, like wireless protocols or malware obfuscation, and still not know everything. That&#8217;s actually good news for beginners. </p><p>It means you don&#8217;t need to master everything. You need a broad map of the landscape first, so you understand where the different specialties fit together, and then you pick one to three areas to go deep on.</p><div><hr></div><h2>The Landscape: Know a Bit of Everything First</h2><p>Before you specialize, get a working knowledge of the major domains of ethical hacking. The current <a href="https://www.eccouncil.org/train-certify/certified-ethical-hacker-ceh/">CEH v13 curriculum</a> is organized into 20 modules, and it&#8217;s a solid checklist for a beginner&#8217;s map of the field.</p><p><strong>Reconnaissance and target mapping</strong></p><ul><li><p>Footprinting and reconnaissance (gathering intel on a target before touching it)</p></li><li><p>Scanning networks</p></li><li><p>Enumeration</p></li><li><p>Vulnerability analysis</p></li></ul><p><strong>System and application exploitation</strong></p><ul><li><p>System hacking</p></li><li><p>Hacking web servers</p></li><li><p>Hacking web applications</p></li><li><p>SQL injection</p></li></ul><p><strong>Malware, sniffing, and disruption</strong></p><ul><li><p>Malware threats (trojans, viruses, worms, fileless malware, APTs)</p></li><li><p>Sniffing</p></li><li><p>Denial-of-service and distributed denial-of-service attacks</p></li><li><p>Session hijacking</p></li></ul><p><strong>Perimeter evasion and human-focused attacks</strong></p><ul><li><p>Evading IDS, firewalls, and honeypots</p></li><li><p>Social engineering</p></li></ul><p><strong>Wireless and mobile</strong></p><ul><li><p>Hacking wireless networks</p></li><li><p>Hacking mobile platforms (Android and iOS)</p></li></ul><p><strong>Emerging and specialized environments</strong></p><ul><li><p>IoT and OT (operational technology) hacking</p></li><li><p>Cloud computing (including containers and serverless)</p></li></ul><p><strong>Foundational theory</strong></p><ul><li><p>Introduction to ethical hacking (fundamentals, laws, and standard procedures)</p></li><li><p>Cryptography</p></li></ul><p>You don&#8217;t need to be an expert in all of these to start. You need enough exposure to each one that when you eventually pick a specialty, you know how it connects to the rest of the puzzle. </p><p>A phishing specialist who understands network evasion is far more dangerous, and far more employable, than one who only knows phishing.</p><div><hr></div><h2>Building Your Foundation</h2><p>Certifications aren&#8217;t the end goal. They&#8217;re a structured way to make sure you&#8217;re not skipping the fundamentals. Here&#8217;s a sensible order.</p><p><strong><a href="https://www.comptia.org/en-us/certifications/a/">CompTIA A+</a></strong> Covers the basics of how computers and operating systems actually work. If you don&#8217;t know how a filesystem, a boot process, or an OS handles permissions, you&#8217;re not ready to attack any of it yet.</p><p><strong><a href="https://www.comptia.org/en-us/certifications/network/">CompTIA Network+</a></strong> Teaches you how networks function: routing, switching, protocols, and how data actually moves from one machine to another. Nearly every attack technique assumes you understand this layer.</p><p><strong><a href="https://www.comptia.org/en-us/certifications/security/">CompTIA Security+</a></strong> Introduces the fundamentals of security work and the shared vocabulary of the industry. This is often where the line gets drawn between someone who&#8217;s casually interested in hacking and someone who&#8217;s starting to think like a professional.</p><p><strong><a href="https://www.eccouncil.org/train-certify/certified-ethical-hacker-ceh/">CEH (Certified Ethical Hacker)</a></strong> Gives you the high-level overview described above: a tour through every major attack category so you understand the full landscape before narrowing your focus.</p><p><strong><a href="https://www.offsec.com/courses/pen-200/">OSCP (Offensive Security Certified Professional)</a></strong> This is the gold standard for hands-on technical skill. It&#8217;s earned through a grueling 24-hour practical exam where you actually have to compromise systems, not answer multiple choice questions about them. Holding an OSCP is one of the clearest signals to employers that you can do real red team work, and it&#8217;s often a baseline requirement for red team roles at larger companies.</p><div><hr></div><h2>Specialize Once You Know Where You Fit</h2><p>Once you&#8217;ve got the broad overview and you&#8217;ve noticed which corner of the field keeps pulling your attention, it&#8217;s time to go deep. This is where you start learning the bleeding edge of a specific specialty rather than the textbook version.</p><p><strong>A few examples of specialized training worth pursuing, depending on your interest:</strong></p><ul><li><p><strong>Phishing and credential capture</strong>: <a href="https://academy.breakdev.org/evilginx-mastery">Evilginx Mastery</a> teaches how top-tier attackers use reverse proxy techniques to phish past multi-factor authentication and capture session cookies, not just passwords.</p></li><li><p><strong>Web application security</strong>: The <a href="https://portswigger.net/web-security">PortSwigger Web Security Academy</a> and its <a href="https://portswigger.net/web-security/certification">Burp Suite Certified Practitioner (BSCP)</a> exam go far beyond the basics of SQL injection and cross-site scripting into modern, real-world web exploitation.</p></li><li><p><strong>Malware analysis and reverse engineering</strong>: <a href="https://www.sans.org/cyber-security-courses/reverse-engineering-malware-malware-analysis-tools-techniques">SANS FOR610 (Reverse-Engineering Malware)</a> is a well-respected deep dive into dissecting real malicious code.</p></li><li><p><strong>Wireless attacks</strong>: <a href="https://www.offsec.com/courses/pen-210/">OffSec&#8217;s PEN-210 (Foundational Wireless Network Attacks)</a>, which leads to the OSWP certification, goes deep into cracking and exploiting Wi-Fi networks beyond what a general course will cover.</p></li><li><p><strong>Cloud penetration testing</strong>: <a href="https://www.sans.org/cyber-security-courses/cloud-penetration-testing">SANS SEC588 (Cloud Penetration Testing)</a> focuses specifically on AWS and Azure attack surfaces, an area becoming essential as more infrastructure moves off-prem, and a rapidly growing specialty with less competition than traditional network pentesting.</p></li></ul><div><hr></div><h2>Join a Community</h2><p>Learning on your own is a grind. The fastest way to level up is to surround yourself with people already doing the work.</p><p><a href="https://joinpwn.com/">PWN</a> offers a <a href="https://www.reddit.com/r/pwnhub/">free community on Reddit</a> that hosts AMAs with industry professionals and journalists following the bleeding edge of the field. </p><p>It&#8217;s also a solid place to keep up with industry news, the latest vulnerabilities, new hacking techniques, and tutorials from people actually doing this for a living. </p><p>Having a place to ask questions and see what real practitioners are working on will save you more time than any single course.</p><div><hr></div><h2>Frequently Asked Questions</h2><p>These questions have been asked by members of the community. If you have a question, comment below and we&#8217;ll get it answered!</p><div class="pullquote"><p><strong>Do I need to know how to code first?</strong></p></div><p>No, not to start. Basic scripting (Python is the common pick) helps later for automating tasks, but you can begin learning networking, operating systems, and security concepts without writing a line of code. Add coding once you know which specialty you&#8217;re leaning toward.</p><div class="pullquote"><p><strong>Do I need a college degree?</strong></p></div><p>No. Most employers care more about demonstrated skill (certs, a home lab, CTF results, a portfolio) than a diploma. A degree can help with some corporate or government roles, but it&#8217;s not a requirement to break in.</p><div class="pullquote"><p><strong>Is it legal to practice these skills?</strong></p></div><p>Only on systems you own or have explicit written permission to test. Practicing on someone else&#8217;s network or app without permission is illegal, full stop. Use built-for-this platforms like TryHackMe, Hack The Box, or your own home lab instead.</p><div class="pullquote"><p><strong>Are certs required?</strong></p></div><p>No, but they&#8217;re helpful. Certs aren&#8217;t magic tickets, employers still care about actual skill, but they give you a structured curriculum so you&#8217;re not guessing what to learn next, and they signal to employers that you&#8217;ve hit a baseline. Think of them as a forcing function, not a finish line.</p><div class="pullquote"><p><strong>What if I&#8217;m overwhelmed by the sheer volume there is to learn?</strong></p></div><p>That&#8217;s normal, and it&#8217;s exactly why structured training programs help. Nobody can hand you a clean list like &#8220;study networking, then OS internals, then Linux, then...&#8221; because the real list is much longer and messier than that. A structured course does that sequencing for you, so you&#8217;re not lost trying to map the whole field before you&#8217;ve even started.</p><div><hr></div><h2>The Real Starting Point</h2><p>If all of this feels like a lot, that&#8217;s because it is. The actual first step is simpler than it looks: pick up CompTIA A+ material, or even just start building and breaking things in a home lab, and see if you actually enjoy the process of pulling a system apart to understand it. </p><p>If you do, the rest of this path will feel less like a checklist and more like a series of doors you&#8217;re excited to open.</p><div><hr></div><p><strong>Got a question we didn&#8217;t cover, or want a second opinion on where to start?</strong> </p><p>Share it in the comments. We read every one, and there&#8217;s a good chance someone in the community has already been exactly where you are.</p><p>Stay sharp. Stay secure.</p>]]></content:encoded></item><item><title><![CDATA[AMA Starts Soon: FCC Wants to Ban Burner Phones. CNET Reporter, Joe Supan, is Here to Answer Your Questions!]]></title><description><![CDATA[The FCC has proposed Know-Your-Customer rules that would require telecom companies to collect a name, physical address, and government ID for every cellphone customer.]]></description><link>https://pwnhackers.substack.com/p/ama-starts-soon-fcc-wants-to-ban</link><guid isPermaLink="false">https://pwnhackers.substack.com/p/ama-starts-soon-fcc-wants-to-ban</guid><dc:creator><![CDATA[PWN | Hacker Community]]></dc:creator><pubDate>Fri, 24 Jul 2026 13:39:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!HN2K!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>The FCC has proposed Know-Your-Customer rules that would require telecom companies to collect a name, physical address, and government ID for every cellphone customer.</strong> </p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/comments/1v2p9gr/im_joe_supan_a_senior_writer_at_cnet_i_reported/&quot;,&quot;text&quot;:&quot;Ask Your Questions&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.reddit.com/r/pwnhub/comments/1v2p9gr/im_joe_supan_a_senior_writer_at_cnet_i_reported/"><span>Ask Your Questions</span></a></p><div><hr></div><p>Privacy experts warn the rules would effectively end anonymous phone service in the US and could cut off millions of people who lack a standard ID. </p><p>CNET Reporter, Joe Supan, broke down what that would mean, and he&#8217;s coming to the PWN Community to answer your questions.</p><p>Joe is a senior writer at CNET covering home technology, broadband, and privacy. He&#8217;s joining us live on Friday, July 24th from 2 to 3 PM ET.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HN2K!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HN2K!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HN2K!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HN2K!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HN2K!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HN2K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg" width="1440" height="960" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:960,&quot;width&quot;:1440,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:113488,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/207950110?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HN2K!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HN2K!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HN2K!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HN2K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>Post your questions</h3><p>Post your questions in the comments now, then join the live AMA on Friday, July 24th at 2 PM ET: <strong><a href="https://www.reddit.com/r/pwnhub/comments/1v2p9gr/im_joe_supan_a_senior_writer_at_cnet_i_reported/">SHARE QUESTIONS HERE</a></strong></p><div><hr></div><h3>Upcoming AMA: Friday, July 24th (2 PM - 3 PM ET)</h3><p>&#8220;I&#8217;m Joe Supan, a senior writer at CNET covering home technology, broadband, and privacy. Before CNET, I reported on broadband policy, the digital divide, and privacy issues for Allconnect. My work has been referenced by the Los Angeles Times, Forbes and National Geographic, among others.</p><p>I recently reported on the FCC&#8217;s proposed Know-Your-Customer requirements, which would force telecom companies to collect a name, physical address, and government ID for every cellphone customer. Privacy experts warn the rules would effectively end anonymous phone service in the US and could disconnect millions of people who lack a standard ID.</p><p>Ask me anything about:</p><ul><li><p>The FCC&#8217;s Know-Your-Customer proposal and what it would mean for anonymous phone use</p></li><li><p>How the rules could affect journalists, travelers, whistleblowers, and marginalized groups</p></li><li><p>Whether telecoms can be trusted with sensitive customer data</p></li><li><p>Broadband policy and the digital divide</p></li><li><p>Practical steps people can take to protect their privacy</p></li><li><p>Anything else on tech, privacy, and surveillance</p></li></ul><p>I&#8217;ll be here live on 7/24 from 2 to 3 PM ET answering your questions in real time. Feel free to leave questions in advance, and I&#8217;ll get to them when I go live.</p><p>Looking forward to your questions.&#8221;</p><div><hr></div><h3>Post your questions</h3><p>Post your questions in the comments now, then join the live AMA on Friday, July 24th at 2 PM ET: <strong><a href="https://www.reddit.com/r/pwnhub/comments/1v2p9gr/im_joe_supan_a_senior_writer_at_cnet_i_reported/">SHARE QUESTIONS HERE</a></strong></p><div><hr></div><p></p>]]></content:encoded></item><item><title><![CDATA[The FCC Wants to Ban Burner Phones. The CNET Reporter Tracking This Story is Here to Chat. Ask Him Anything.]]></title><description><![CDATA[The FCC has proposed Know-Your-Customer rules that would require telecom companies to collect a name, physical address, and government ID for every cellphone customer.]]></description><link>https://pwnhackers.substack.com/p/the-fcc-wants-to-ban-burner-phones</link><guid isPermaLink="false">https://pwnhackers.substack.com/p/the-fcc-wants-to-ban-burner-phones</guid><dc:creator><![CDATA[PWN | Hacker Community]]></dc:creator><pubDate>Tue, 21 Jul 2026 18:11:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!HN2K!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>The FCC has proposed Know-Your-Customer rules that would require telecom companies to collect a name, physical address, and government ID for every cellphone customer.</strong> </p><p>Privacy experts warn the rules would effectively end anonymous phone service in the US and could cut off millions of people who lack a standard ID. </p><p>CNET Reporter, Joe Supan, broke down what that would mean, and he&#8217;s coming to the PWN Community to answer your questions.</p><p>Joe is a senior writer at CNET covering home technology, broadband, and privacy. He&#8217;s joining us live on Friday, July 24th from 2 to 3 PM ET.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HN2K!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HN2K!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HN2K!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HN2K!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HN2K!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HN2K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg" width="1440" height="960" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:960,&quot;width&quot;:1440,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:113488,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/207950110?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HN2K!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HN2K!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HN2K!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HN2K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c094508-102e-4a64-909d-c64a579ef714_1440x960.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>Post your questions</h3><p>Post your questions in the comments now, then join the live AMA on Friday, July 24th at 2 PM ET: <strong><a href="https://www.reddit.com/r/pwnhub/comments/1v2p9gr/im_joe_supan_a_senior_writer_at_cnet_i_reported/">SHARE QUESTIONS HERE</a></strong></p><div><hr></div><h3>Upcoming AMA: Friday, July 24th (2 PM - 3 PM ET)</h3><p>&#8220;I&#8217;m Joe Supan, a senior writer at CNET covering home technology, broadband, and privacy. Before CNET, I reported on broadband policy, the digital divide, and privacy issues for Allconnect. My work has been referenced by the Los Angeles Times, Forbes and National Geographic, among others.</p><p>I recently reported on the FCC&#8217;s proposed Know-Your-Customer requirements, which would force telecom companies to collect a name, physical address, and government ID for every cellphone customer. Privacy experts warn the rules would effectively end anonymous phone service in the US and could disconnect millions of people who lack a standard ID.</p><p>Ask me anything about:</p><ul><li><p>The FCC&#8217;s Know-Your-Customer proposal and what it would mean for anonymous phone use</p></li><li><p>How the rules could affect journalists, travelers, whistleblowers, and marginalized groups</p></li><li><p>Whether telecoms can be trusted with sensitive customer data</p></li><li><p>Broadband policy and the digital divide</p></li><li><p>Practical steps people can take to protect their privacy</p></li><li><p>Anything else on tech, privacy, and surveillance</p></li></ul><p>I&#8217;ll be here live on 7/24 from 2 to 3 PM ET answering your questions in real time. Feel free to leave questions in advance, and I&#8217;ll get to them when I go live.</p><p>Looking forward to your questions.&#8221;</p><div><hr></div><h3>Post your questions</h3><p>Post your questions in the comments now, then join the live AMA on Friday, July 24th at 2 PM ET: <strong><a href="https://www.reddit.com/r/pwnhub/comments/1v2p9gr/im_joe_supan_a_senior_writer_at_cnet_i_reported/">SHARE QUESTIONS HERE</a></strong></p><div><hr></div><p></p>]]></content:encoded></item><item><title><![CDATA[AMA Starts Soon: The Reporters Who Exposed Flock's License Plate Leak (Tuesday, July 21st)]]></title><description><![CDATA[Flock&#8217;s automated license plate reader network quietly logs the movements of millions of everyday drivers across the US.]]></description><link>https://pwnhackers.substack.com/p/ama-starts-soon-the-reporters-who</link><guid isPermaLink="false">https://pwnhackers.substack.com/p/ama-starts-soon-the-reporters-who</guid><dc:creator><![CDATA[PWN | Hacker Community]]></dc:creator><pubDate>Tue, 21 Jul 2026 13:58:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!z_fE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Flock&#8217;s automated license plate reader network quietly logs the movements of millions of everyday drivers across the US. </p><p>A recent investigation revealed that police search data was exposed on public search engines like DuckDuckGo and Bing. This exposure included specific license plates along with confidential investigation details.</p><p>Today, the journalists who uncovered this breach are taking your questions live.</p><p><strong>Join</strong> <strong><span>404 Media&#8217;s Jason Koebler and Joseph Cox</span> from 12 PM to 1 PM ET</strong> to discuss mass surveillance, privacy, and how they investigated this story.</p><p><strong>&#128073; <a href="https://www.reddit.com/r/pwnhub/comments/1uzanpa/were_jason_koebler_and_joseph_cox_of_404_media_we/">Ask your questions here!</a></strong></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!z_fE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!z_fE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png 424w, https://substackcdn.com/image/fetch/$s_!z_fE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png 848w, https://substackcdn.com/image/fetch/$s_!z_fE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png 1272w, https://substackcdn.com/image/fetch/$s_!z_fE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!z_fE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png" width="1456" height="818" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:818,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:9351020,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/207481485?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!z_fE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png 424w, https://substackcdn.com/image/fetch/$s_!z_fE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png 848w, https://substackcdn.com/image/fetch/$s_!z_fE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png 1272w, https://substackcdn.com/image/fetch/$s_!z_fE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If you&#8217;ve never heard of Flock, or you&#8217;ve been watching the backlash unfold, this is the place to ask what&#8217;s actually going on.</p><div><hr></div><h3>Post your questions</h3><p>Share your questions in the comments now so they can answer them the moment they go live! <strong><a href="https://www.reddit.com/r/pwnhub/comments/1uzanpa/were_jason_koebler_and_joseph_cox_of_404_media_we/">Share your questions here.</a></strong></p><div><hr></div><h3>AMA Starts Soon: Tuesday, July 21st (12 PM - 1 PM ET)</h3><p>&#8220;We&#8217;re Jason Koebler and Joseph Cox, two of the co-founders of 404 Media, a journalist-owned publication covering technology, surveillance, crime, and the internet. </p><p>Jason spent six years as editor-in-chief of Motherboard, where he led editorial and produced award-winning documentaries and reporting on everything from right to repair to ticket scalping. </p><p>Joseph is an investigative reporter whose work has triggered hundreds of millions of dollars in fines against major telecoms, shut down data brokers, stopped companies from selling location data tied to abortion clinics, and pushed lawmakers toward new privacy legislation.</p><p>We recently reported that Flock, the automatic license plate reader (ALPR) company, exposed some of the license plates cops were searching for and the reasons behind those searches, through DuckDuckGo and Bing.</p><p>Ask us anything about:</p><ul><li><p>The Flock leak and what it reveals about ALPR surveillance</p></li><li><p>How license plate readers are being used by law enforcement</p></li><li><p>How we approach surveillance and investigative stories</p></li><li><p>Working with sources and documents</p></li><li><p>Building and running an independent, reader-funded newsroom</p></li><li><p>Anything else on tech, privacy, and surveillance</p></li></ul><p>We&#8217;ll be here live on Tuesday, July 21st from 12 PM to 1 PM ET answering your questions in real time. Feel free to leave questions in advance, and we&#8217;ll get to them when we go live.</p><p>Looking forward to your questions.&#8221;</p><div><hr></div><h3>Post your questions</h3><p>Share your questions in the comments now so they can answer them the moment they go live! <strong><a href="https://www.reddit.com/r/pwnhub/comments/1uzanpa/were_jason_koebler_and_joseph_cox_of_404_media_we/">Share your questions here.</a></strong></p>]]></content:encoded></item><item><title><![CDATA[They Broke the Story on Flock Leaking Cops' License Plate Searches. Ask Them Anything.]]></title><description><![CDATA[Flock accidentally leaked the license plates cops were searching for, and the reasons behind those searches, right into DuckDuckGo and Bing.]]></description><link>https://pwnhackers.substack.com/p/they-broke-the-story-on-flock-leaking</link><guid isPermaLink="false">https://pwnhackers.substack.com/p/they-broke-the-story-on-flock-leaking</guid><dc:creator><![CDATA[PWN | Hacker Community]]></dc:creator><pubDate>Fri, 17 Jul 2026 21:26:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!z_fE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Flock accidentally leaked the license plates cops were searching for, and the reasons behind those searches, right into DuckDuckGo and Bing. The two reporters who broke that story are coming to the PWN Community to answer your questions.</p><p><strong>Jason Koebler and Joseph Cox, two of the co-founders of 404 Media</strong>, are joining us for a live AMA on Tuesday, July 21st from 12 PM to 1 PM ET.</p><div><hr></div><h3>Post your questions</h3><p>Share your questions in the comments now so they can answer them the moment they go live! <strong><a href="https://www.reddit.com/r/pwnhub/comments/1uzanpa/were_jason_koebler_and_joseph_cox_of_404_media_we/">Share your questions here.</a></strong></p><div><hr></div><h3>Upcoming AMA: Tuesday, July 21st (12 PM - 1 PM ET)</h3><p>&#8220;We&#8217;re Jason Koebler and Joseph Cox, two of the co-founders of 404 Media, a journalist-owned publication covering technology, surveillance, crime, and the internet. </p><p>Jason spent six years as editor-in-chief of Motherboard, where he led editorial and produced award-winning documentaries and reporting on everything from right to repair to ticket scalping. </p><p>Joseph is an investigative reporter whose work has triggered hundreds of millions of dollars in fines against major telecoms, shut down data brokers, stopped companies from selling location data tied to abortion clinics, and pushed lawmakers toward new privacy legislation.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!z_fE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!z_fE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png 424w, https://substackcdn.com/image/fetch/$s_!z_fE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png 848w, https://substackcdn.com/image/fetch/$s_!z_fE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png 1272w, https://substackcdn.com/image/fetch/$s_!z_fE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!z_fE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png" width="1456" height="818" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:818,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:9351020,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/207481485?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!z_fE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png 424w, https://substackcdn.com/image/fetch/$s_!z_fE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png 848w, https://substackcdn.com/image/fetch/$s_!z_fE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png 1272w, https://substackcdn.com/image/fetch/$s_!z_fE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff82ae210-9ea4-4655-8bf9-19db0aa2d432_3196x1796.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>We recently reported that Flock, the automatic license plate reader (ALPR) company, exposed some of the license plates cops were searching for and the reasons behind those searches, through DuckDuckGo and Bing.</p><p>Ask us anything about:</p><ul><li><p>The Flock leak and what it reveals about ALPR surveillance</p></li><li><p>How license plate readers are being used by law enforcement</p></li><li><p>How we approach surveillance and investigative stories</p></li><li><p>Working with sources and documents</p></li><li><p>Building and running an independent, reader-funded newsroom</p></li><li><p>Anything else on tech, privacy, and surveillance</p></li></ul><p>We&#8217;ll be here live on Tuesday, July 21st from 12 PM to 1 PM ET answering your questions in real time. Feel free to leave questions in advance, and we&#8217;ll get to them when we go live.</p><p>Looking forward to your questions.&#8221;</p><div><hr></div><h3>Post your questions</h3><p>Share your questions in the comments now so they can answer them the moment they go live! <strong><a href="https://www.reddit.com/r/pwnhub/comments/1uzanpa/were_jason_koebler_and_joseph_cox_of_404_media_we/">Share your questions here.</a></strong></p>]]></content:encoded></item><item><title><![CDATA[U.S. Pulls Anthropic's Top AI Models, Lapsus$ Claims GitHub Breach, FBI Builds a Fake Town to Simulate Cyberattacks]]></title><description><![CDATA[TLDR: The U.S. government has ordered Anthropic to cut off foreign national access to its Claude Fable 5 and Mythos 5 AI models over national security concerns tied to a reported jailbreak method.

Lapsus$ ransomware group is claiming a massive breach of GitHub, allegedly compromising 299 employees and over 2.5 million user accounts.

The FBI has built a 22,000 square-foot replica town in Huntsville, Alabama to train law enforcement agents in responding to real-world cyberattacks.]]></description><link>https://pwnhackers.substack.com/p/us-pulls-anthropics-top-ai-models</link><guid isPermaLink="false">https://pwnhackers.substack.com/p/us-pulls-anthropics-top-ai-models</guid><dc:creator><![CDATA[PWN | Hacker Community]]></dc:creator><pubDate>Sun, 14 Jun 2026 00:06:52 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/6e2c8fbb-8d18-434a-927e-21bfc58c019c_1000x522.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>TLDR:</strong> The U.S. government has ordered Anthropic to cut off foreign national access to its Claude Fable 5 and Mythos 5 AI models over national security concerns tied to a reported jailbreak method.</p><p>Lapsus$ ransomware group is claiming a massive breach of GitHub, allegedly compromising 299 employees and over 2.5 million user accounts.</p><p>The FBI has built a 22,000 square-foot replica town in Huntsville, Alabama to train law enforcement agents in responding to real-world cyberattacks.</p><div><hr></div><p><strong>Details below&#8230;</strong></p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;21b9c633-8fa8-421f-bcca-9984068de412&quot;,&quot;caption&quot;:&quot;One of the things that sets the PWN hacker community apart is who shows up here.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Featured Press Contributors: Wired, EFF, 404 Media, Fast Company, Ars Technica, and The Guardian&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:416235881,&quot;name&quot;:&quot;PWN | Hacker Community&quot;,&quot;bio&quot;:&quot;Welcome to PWN &#8211; your community for hackers and cybersecurity enthusiasts. Discover the latest hacking news, breach reports, and educational resources on ethical hacking. &#128126; Stay sharp. Stay secure.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6ea4b662-416c-409c-b0b1-02ff211e9993_128x128.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-13T01:42:19.819Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!xBGM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://pwnhackers.substack.com/p/featured-press-contributors-wired&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:197434339,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:0,&quot;publication_id&quot;:6973951,&quot;publication_name&quot;:&quot;PWN | Hacker Community&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!INDD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7588dff0-e7a4-43b4-a591-e37fb6bee3af_128x128.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>Got something worth sharing?</h3><blockquote><p><strong>PWN is a community for hackers and security enthusiasts.</strong></p><p>We feature the best posts in this newsletter and we&#8217;re looking for news stories, writeups, tools, tutorials, discussion threads, and questions that spark real conversation.</p></blockquote><p><strong>We are accepting submissions for:</strong> News stories; Tutorials/write-ups; Tools you built or found useful; Discussion threads; or Questions that spark good conversation.</p><p><strong>&#187; <a href="https://www.reddit.com/r/pwnhub/submit/">Create a post</a>, and you could be featured in the next email!</strong></p><p>Our community is growing fast, with 935,000 views a month, 33,000 members, and 200+ new people joining daily. Create a post and you could be featured.</p><div><hr></div><h3><strong>U.S. Orders Anthropic to Pull Fable 5 and Mythos 5 Access for Foreign Nationals</strong></h3><p>The U.S. government dropped an abrupt mandate on Anthropic, ordering the company to suspend access to two of its most advanced AI models for all foreign nationals, citing national security risks.</p><p>The directive, issued at 5:21 p.m. ET, is linked to a reported method for bypassing Fable 5&#8217;s safety guardrails. Anthropic is cooperating while pushing back on what it describes as an overreaction to a narrowly defined jailbreak. Other models remain accessible, though Fable 5&#8217;s architecture means cybersecurity queries are currently rerouted to Claude Opus 4.8. The U.S. Department of Defense had previously flagged Anthropic as a supply chain risk.</p><p><a href="https://www.reddit.com/r/pwnhub/comments/1u4fz2i/us_government_suspends_access_to_ai_models_fable/">Read more</a></p><div><hr></div><h3><strong>Lapsus$ Claims Massive GitHub Breach Affecting 2.5 Million Accounts</strong></h3><p>The notorious Lapsus$ group is claiming it has breached GitHub&#8217;s internal systems, and given the group&#8217;s track record, the security community is taking the claim seriously.</p><p>The group alleges it compromised 299 GitHub employees, exposed 117 third-party credentials, and put over 2.5 million user accounts at risk. Lapsus$ has previously confirmed breaches at Nvidia, Microsoft, Samsung, and Uber before going public. GitHub has not confirmed the breach, but the scope of the claimed access raises serious questions about supply chain security for the millions of developers who depend on the platform.</p><p><a href="https://www.reddit.com/r/pwnhub/comments/1u4vby3/lapsus_ransomware_group_is_claiming_github_as_a/">Read more</a></p><div><hr></div><h3><strong>FBI Built a Fake Town to Simulate Cyberattacks on Critical Infrastructure</strong></h3><p>The FBI quietly opened a 22,000 square-foot replica town in Huntsville, Alabama designed to help agents practice responding to ransomware attacks and other cyber incidents against real-world infrastructure.</p><p>The Kinetic Cyber Range includes fully furnished homes, a hospital, and a mock power company, letting agents simulate scenarios like hospital systems going offline mid-attack. Since opening in February 2025, the facility has trained over 1,400 personnel. The training also covers digital forensics on encrypted devices, with techniques that allow data extraction without disclosing vulnerabilities to manufacturers. Ransomware losses hit $20.9 billion in 2025, making the investment timely.</p><p><a href="https://www.reddit.com/r/pwnhub/comments/1u4qgfv/fbi_unveils_replica_town_to_train_investigators/">Read more</a></p><div><hr></div><h2>Join PWN on Reddit</h2><p><a href="https://www.reddit.com/r/pwnhub/">PWN</a> is where security people go to stay ahead. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xBGM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xBGM!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" width="1200" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:400,&quot;width&quot;:1200,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:196009,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/196609498?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Breach reports, exploits, vendor advisories, and the kind of conversations that make you better at your job, all in one feed.</p><p>We&#8217;re 32,000+ hackers and cybersecurity enthusiasts strong, with 935,000 monthly views and 200+ new members every day. </p><p>You&#8217;ll be in the same threads as journalists from <a href="https://www.reddit.com/r/pwnhub/comments/1rx58fn/hundreds_of_millions_of_iphones_can_be_hacked/">Wired Magazine</a>, <a href="https://www.reddit.com/r/pwnhub/comments/1mx1pz1/were_eff_were_launching_a_critical_campaign_to/">Electronic Frontier Foundation</a>, <a href="https://www.reddit.com/r/pwnhub/comments/1s4hw6c/apple_gives_fbi_a_users_real_name_hidden_behind/">404 Media</a>, <a href="https://www.reddit.com/r/pwnhub/comments/1skd7vq/is_mythos_a_blessing_or_a_curse_for_cybersecurity/">Fast Company</a>, and <a href="https://www.reddit.com/r/pwnhub/comments/1t72br7/revealed_russias_top_secret_spy_school_teaching/">The Guardian</a> breaking the stories firsthand, plus security teams from vendors like <a href="https://proton.me/">Proton</a>, <a href="https://www.intigriti.com/">Intigriti</a>, and <a href="https://www.hudsonrock.com/">Hudson Rock</a> sharing research and answering questions directly.</p><h3>Why join:</h3><ul><li><p><strong>Know what&#8217;s hitting before it hits you.</strong> Get the breach reports, exploits, and vendor advisories early so you can act before they become your problem.</p></li><li><p><strong>Get sharper, not just busier.</strong> Skip the noise and learn from people actually doing the work, on the AI exploits, new defenses, and techniques that move your skills forward.</p></li><li><p><strong>Make the career move you&#8217;ve been planning.</strong> Whether it&#8217;s your first paycheck in security or your jump from IT into offensive work, you&#8217;ll find members who&#8217;ve made it and are happy to help you do the same.</p></li><li><p><strong>Be the person at work who already knows.</strong> Walk into Monday meetings ahead of the ransomware incidents and zero-days landing on your team&#8217;s radar, and earn the trust that comes with it.</p></li><li><p><strong>Find your people.</strong> Trade ideas with hackers and pros who&#8217;ll actually answer your questions, in a community that stays high quality because the bots and noise get cleaned up.</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/&quot;,&quot;text&quot;:&quot;Join PWN on Reddit&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.reddit.com/r/pwnhub/"><span>Join PWN on Reddit</span></a></p>]]></content:encoded></item><item><title><![CDATA[Member Projects: Automated Dark Web Investigation Tool, Building a Malware Lab, Threat Tracker Chrome Extension]]></title><description><![CDATA[TLDR: This week&#8217;s member projects span both software and infrastructure work.]]></description><link>https://pwnhackers.substack.com/p/member-projects-automated-dark-web</link><guid isPermaLink="false">https://pwnhackers.substack.com/p/member-projects-automated-dark-web</guid><dc:creator><![CDATA[PWN | Hacker Community]]></dc:creator><pubDate>Fri, 12 Jun 2026 18:59:30 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/c54c493a-2353-4e0b-a79e-61ed3e95bcbc_1000x522.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>TLDR:</strong> This week&#8217;s member projects span both software and infrastructure work. </p><p>On the software side, two tools tackle real gaps in security visibility: one automates open-source intelligence gathering across dark web sources, and another tracks malicious browser extensions that often fly under the radar even after being removed from official stores. </p><p>Rounding things out is a practical infrastructure project, a step-by-step video series walking through building a professional malware analysis environment lab using automated deployment tools. View latest <a href="https://www.reddit.com/r/pwnhub/?f=flair_name%3A%22%F0%9F%9B%A0%EF%B8%8F%20Project%22">member submitted projects</a>.</p><p><strong>Details below&#8230;</strong></p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;21b9c633-8fa8-421f-bcca-9984068de412&quot;,&quot;caption&quot;:&quot;One of the things that sets the PWN hacker community apart is who shows up here.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Featured Press Contributors: Wired, EFF, 404 Media, Fast Company, Ars Technica, and The Guardian&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:416235881,&quot;name&quot;:&quot;PWN | Hacker Community&quot;,&quot;bio&quot;:&quot;Welcome to PWN &#8211; your community for hackers and cybersecurity enthusiasts. Discover the latest hacking news, breach reports, and educational resources on ethical hacking. &#128126; Stay sharp. Stay secure.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6ea4b662-416c-409c-b0b1-02ff211e9993_128x128.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-13T01:42:19.819Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!xBGM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://pwnhackers.substack.com/p/featured-press-contributors-wired&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:197434339,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:0,&quot;publication_id&quot;:6973951,&quot;publication_name&quot;:&quot;PWN | Hacker Community&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!INDD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7588dff0-e7a4-43b4-a591-e37fb6bee3af_128x128.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>Want to share your project?</h3><blockquote><p><strong>PWN is a community for hackers and security enthusiasts.</strong></p><p>We feature the best posts in this newsletter and we&#8217;re looking for news stories, writeups, tools, tutorials, discussion threads, and questions that spark real conversation.</p></blockquote><p><strong>To submit your project:</strong> Create a new post about your project, and use the &#8216;project&#8217; flair when posting to be automatically submitted!</p><p><strong>&#187; <a href="https://www.reddit.com/r/pwnhub/submit/">Create a post</a>, and you could be featured in the next email!</strong></p><p>Our community is growing fast, with 935,000 views a month, 35,000 members, and 200+ new members joining daily. Create a post and you could be featured.</p><div><hr></div><h3>VoidAccess: An Automated Dark Web Intelligence Tool</h3><p>A community member built a command-line tool that runs a structured dark web investigation in under three minutes, returning actionable intelligence from dozens of sources at once.</p><p>The tool searches across the anonymous Tor network, code-sharing platforms, paste sites, and security news feeds simultaneously. In a live demonstration against a major ransomware group&#8217;s infrastructure, it surfaced active breach disclosures affecting a Mexican telecoms company and a financial title agency, identified five threat actor aliases, flagged a ransomware-as-a-service storefront with advertised pricing, and mapped nearly 400 shared IP addresses linking different criminal groups together. The results are saved automatically as a structured report. The tool is free, open source, and installable with a single command.</p><p><a href="https://www.reddit.com/r/pwnhub/comments/1u41b8j/i_ran_an_automated_dark_web_investigation_on/">Read more</a></p><div><hr></div><h3>Malware Lab From Scratch: A Home Security Research Environment</h3><p>A series of tutorial videos walks through building a professional-grade malware analysis lab at home, culminating in a single-button deployment system.</p><p>The creator drew on experience setting up a similar environment professionally, then built a personal version designed to be a practical starting point others can adapt. </p><p>The third installment focuses on automation: using a continuous integration pipeline hosted on a code platform to deploy the entire lab setup with one click. All three parts are freely available, and the full project configuration is published openly for anyone who wants to fork it or build on top of it.</p><p><a href="https://www.reddit.com/r/pwnhub/comments/1u3v6oj/building_my_malware_lab_from_scratch_3/">Read more</a></p><div><hr></div><h3>Malicious Extension Sentry: A Browser Extension Threat Tracker</h3><p>Browser extensions are a surprisingly effective hiding spot for malware, partly because there has never been a reliable, up-to-date list of dangerous ones. This project fills that gap.</p><p>Malicious Extension Sentry scrapes official browser stores and security sources daily to compile a continuously updated list of flagged and removed extensions, then exposes that data in a format that plugs directly into existing security workflows. It also ships a command-line auditing tool for checking extensions across a fleet of machines, and a browser extension for real-time monitoring. Crucially, it continues tracking threats even after they have been pulled from the official store, which is often when detection lapses.</p><p><a href="https://www.reddit.com/r/pwnhub/comments/1u2qjvn/chrome_extension_threat_intel_is_a_blind_spot/">Read more</a></p><div><hr></div><h2>Join PWN on Reddit</h2><p><a href="https://www.reddit.com/r/pwnhub/">PWN</a> is where security people go to stay ahead. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xBGM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xBGM!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png" width="1200" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:400,&quot;width&quot;:1200,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:196009,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://pwnhackers.substack.com/i/196609498?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xBGM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 424w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 848w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1272w, https://substackcdn.com/image/fetch/$s_!xBGM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcacf9ac9-0d2d-4c9f-bfbc-579800fc6f50_1200x400.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Breach reports, exploits, vendor advisories, and the kind of conversations that make you better at your job, all in one feed.</p><p>We&#8217;re 32,000+ hackers and cybersecurity enthusiasts strong, with 935,000 monthly views and 200+ new members every day. </p><p>You&#8217;ll be in the same threads as journalists from <a href="https://www.reddit.com/r/pwnhub/comments/1rx58fn/hundreds_of_millions_of_iphones_can_be_hacked/">Wired Magazine</a>, <a href="https://www.reddit.com/r/pwnhub/comments/1mx1pz1/were_eff_were_launching_a_critical_campaign_to/">Electronic Frontier Foundation</a>, <a href="https://www.reddit.com/r/pwnhub/comments/1s4hw6c/apple_gives_fbi_a_users_real_name_hidden_behind/">404 Media</a>, <a href="https://www.reddit.com/r/pwnhub/comments/1skd7vq/is_mythos_a_blessing_or_a_curse_for_cybersecurity/">Fast Company</a>, and <a href="https://www.reddit.com/r/pwnhub/comments/1t72br7/revealed_russias_top_secret_spy_school_teaching/">The Guardian</a> breaking the stories firsthand, plus security teams from vendors like <a href="https://proton.me/">Proton</a>, <a href="https://www.intigriti.com/">Intigriti</a>, and <a href="https://www.hudsonrock.com/">Hudson Rock</a> sharing research and answering questions directly.</p><h3>Why join:</h3><ul><li><p><strong>Know what&#8217;s hitting before it hits you.</strong> Get the breach reports, exploits, and vendor advisories early so you can act before they become your problem.</p></li><li><p><strong>Get sharper, not just busier.</strong> Skip the noise and learn from people actually doing the work, on the AI exploits, new defenses, and techniques that move your skills forward.</p></li><li><p><strong>Make the career move you&#8217;ve been planning.</strong> Whether it&#8217;s your first paycheck in security or your jump from IT into offensive work, you&#8217;ll find members who&#8217;ve made it and are happy to help you do the same.</p></li><li><p><strong>Be the person at work who already knows.</strong> Walk into Monday meetings ahead of the ransomware incidents and zero-days landing on your team&#8217;s radar, and earn the trust that comes with it.</p></li><li><p><strong>Find your people.</strong> Trade ideas with hackers and pros who&#8217;ll actually answer your questions, in a community that stays high quality because the bots and noise get cleaned up.</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reddit.com/r/pwnhub/&quot;,&quot;text&quot;:&quot;Join PWN on Reddit&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.reddit.com/r/pwnhub/"><span>Join PWN on Reddit</span></a></p>]]></content:encoded></item></channel></rss>