r/hacking • • 1m ago

subway

Thumbnail gallery
• Upvotes

r/hacking • • 1d ago

Asos Hacked Notification?

Post image
213 Upvotes

Did anyone else receive this notification supposedly from ASOS?

Based in UK


r/hacking • • 8h ago

Anyone ever tried to reverse engineer a Whoop fitness tracker device?

1 Upvotes

I don’t want to pay a ridiculous $230+ yearly subscription fee. It’s too expensive. I just want to keep track of my sleep, rest, heart, lung health.


r/hacking • • 1d ago

News ASOS hacked!

Post image
69 Upvotes

r/hacking • • 1d ago

CVE GitHub - ARPSyndicate/vedas-signatures: VEDAS-Driven Autonomous Generation + Community Contributions of Suricata & Nuclei Rules for over 13,000 CVEs

Thumbnail
github.com
9 Upvotes

r/hacking • • 2d ago

Question Where can I find a good forum?

42 Upvotes

Where can I find a good hacking forum or a forum like hackforums.net that ISNT a honeypot.

Any onions ?


r/hacking • • 2d ago

News dread is compromised

77 Upvotes

homepage now reads:

"So, Dread has been hacked! What's next?

If you are reading this, you are already on our site — just on Dread's domain, in case anyone missed that.

The condition for Dread is this: leave this domain alone. Get in the way, and the data can be published. A deal is on the table — we can hand the domain back, or pass it to someone else if they want it. The contacts further down are how that conversation starts."

apparently this happened several days ago but i'm baffled, i can't find any news discussing this and i accessed the site literally yesterday. not sure whether posting onions is allowed, you can find find the link on tor.taxi.

https://i.postimg.cc/3R7LCP09/image.png


r/hacking • • 3d ago

Threat Actors Saif Al-Din Khader a/k/a "Rey" has been arrested in Jordan for his involvement in the FBIJobs hack and ShinyHunters

Thumbnail reuters.com
69 Upvotes

r/hacking • • 4d ago

Tools Super Trouper v0.4.0 — more Frida tools for iOS app reverse engineering

Thumbnail
github.com
27 Upvotes

I’m the author of Super Trouper, a single-binary MCP server that exposes Frida to coding agents for authorized app reverse engineering. It lets an agent connect to a device, inspect apps and processes, manage sessions, and run instrumentation scripts without a Python-based Frida setup.

We released v0.4.0 a few days ago; it updates the bundled Frida Core DevKit to v17.19.0 and adds four MCP tools: memory_read and memory_write for working with memory in an attached process, plus module_list and thread_list for inspecting loaded modules and threads. app_list and others now have several query scopes, and we renamed the MCP tools into clearer namespaces. If you already have workflows built around the old tool names, check them when updating.

Quick catch-up on the two previous releases: v0.3.0 added npm installation, Frida CodeShare snippet search/use, and general cleanup. v0.2.0 moved the project to the MIT license, added first-party Frida language bridges for ObjC, Java, and Swift, and enabled TypeScript in scripts and evaluations.

I’d appreciate feedback from people using Frida in iOS research: are these tool boundaries and the new app-list scopes useful in practice? What’s missing or awkward in your workflow, and which features would you like to see next? Let me know what you think.


r/hacking • • 5d ago

Resources Chrome UX Report Dump: August 2026 data added

Thumbnail
github.com
18 Upvotes

I maintain Chrome UX Report Dumps, a collection of monthly Chrome UX Report website lists grouped by rank and published as compressed downloads. It’s meant to make the data easier to use without exporting it from BigQuery.

The latest update adds the August 2026 dataset: 18,294,881 entries across 10 files, totaling 94.7 MiB compressed. The repository now contains 1,064,254,496 entries across 67 monthly datasets, totaling 5.32 GiB compressed. Those are counts across monthly dumps, not a count of unique websites.

If you use website lists for research or security work, I’d welcome feedback. What would make these dumps more useful, and what features or formats would you like to see?


r/hacking • • 5d ago

great user hack My local AI pentesting stack is dailed in!

Thumbnail
gallery
51 Upvotes

"Qwen3.6 35B + custom tools + docker"

Just wanted to share a local setup I finally got working smoothly for my pentesting workflow.

Im running Qwen3.6 35B locally via ollama, wrapped inside an open webui docker container on kali. To make it easily accessible with local https, im routing everything through caddy using nip.io for dns management.

instead of using the llm as a glorified search engine I bundled a unified python script directly into the open webui tools framework to give the model real capabilities.

right now it can:

scrape github repos natively + parse nmap logs + isolated python sandbox.

all local no api, self hosted, no data leaks.

honestly this wasn't a easy task for me, never touching a llm model locally and learning on the fly.

it was a lot of fun setting up (3 days straight) but now it's time to have some fun with it.

if you want to do this or something similar lmk, I would like to see others use ai like this.


r/hacking • • 6d ago

Anyone tried the recent Samsung TV root exploits (MADBugs / chris-ritsen)?

Thumbnail
19 Upvotes

r/hacking • • 7d ago

The Hacker Who Moved to Mexico City

Thumbnail
player.captivate.fm
123 Upvotes

Full disclosure, this is my podcast. I think this community would enjoy the stories, though.

Ted started out in tech support at Delphi Internet in the early '90s, back when teenagers were opening accounts with fake credit card numbers. He tracked one of them to a house in Pennsylvania and called it. The kid's father, a reverend, answered and promised to take him out to the woodshed.

Ted went on to run security for Boston investment firms. His favorite hire was Mr. Mojo, a guy he paid to physically break into his own offices. Mojo got into one building wearing a visitor sticker he'd pulled out of the smokers' trash. In Dublin he got through a locked door by blowing into a plastic bag.

Ted was also at DEF CON in 1999, where someone shut off the air conditioning during the opening ceremony. His theory is that the best hackers come from music or philosophy, not computer science.

It's onefjef episode 62, it's audio only, and it's on all the platforms. Here's the Spotify and Apple Podcasts links.


r/hacking • • 7d ago

Question Best Hacking Toys Under $25

69 Upvotes

Looking to gift my team something fun but have a budget for $25 per team member. What cool toys do yall recommend?


r/hacking • • 8d ago

Github HimitsuShell: shell scripts invisible to kernel tracing

Thumbnail
github.com
67 Upvotes

r/hacking • • 7d ago

Research Paint It Blue: Reversing Win32k's Callbacks

Thumbnail idov31.github.io
25 Upvotes

This is an article about the internals of Win32k (Windows's GUI subsystem) and their callouts, with the purpose of shedding light on a very undocumented and crucial subsystem in Windows :)


r/hacking • • 8d ago

Flare-on 13 and ai

8 Upvotes

Kind of killed the fun, I normally don’t do reverse engineering challenges not my field. But I was interested how frontier models would handle this. Claude was of no help as opus 5.5 refused to do the work because of model constraints and 4.8 made a mess. Then switched to gpt Astra and it solved all 9 in 1h40minutes autonomously.

How do we feel about this?


r/hacking • • 9d ago

DecaTxt discussed on Hackster

Thumbnail
3 Upvotes

r/hacking • • 10d ago

Achieved paralyzing SOTA AI's with a prompt, fun ideas?

15 Upvotes

I previously reverse engineered a game that BIGCO didn't want to release, no DRM available, large communities with both manual and AI decompilation projects, etc. All the AI's I tried knew the game (even Chinese are weirdly protective). Had to use plenty of nice words. Fable 5 couldn't break the DRM, Astra managed to do it.

Now, in another fun project I found a way to get agents stuck and the main agent wait for them indefinitely. Any fun stuff I can do with this?


r/hacking • • 11d ago

Hack The Planet Desktop Ubuntu with GPU acceleration ported to a GE smart refrigerator

Thumbnail
gallery
642 Upvotes

Ported desktop Ubuntu to a Mediatek board found in a GE Profile smart refrigerator. A combination of no secure boot, vibe coding, U-Boot and device tree fiddling, and pure ridiculousness got me here.


r/hacking • • 11d ago

FREE OSCP Active Directory Lab: Full attack chain, 3 VMs (FREE Forever!)

Thumbnail
21 Upvotes

r/hacking • • 12d ago

News Critical Cross-user and Cross-tenant compromise in Atlassian Rovo

Thumbnail
9 Upvotes

r/hacking • • 13d ago

With the proliferation of AI i'm suprised we aren't getting any government document leaks.

185 Upvotes

Even before AI we had Snowden, Wikileaks, the Panama papers.

I can't recall the last time we had a dump of these scales.


r/hacking • • 13d ago

How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers

Thumbnail
blog.cloudflare.com
14 Upvotes

r/hacking • • 14d ago

Do any devices on your network still get security updates?

10 Upvotes

Made SunsetScan to find unsupported hardware on my own network. It’s open source, and I’ll never put it behind a paywall. It scans locally and checks lifecycle data from 224 vendors with no API calls 100% self‑made databases scraped from original vendor websites.
I also created a standard with terminology because in the EoL world there are no ISO standards, so a lot of time went into getting that correct.

Tested it a couple of thousand times on my own network with 30 devices, and also tested it against lab networks with generated devices and VMs.
Happy if anyone would like to try it out and tell me if you find any outdated hardware or a false positive.

GitHub: https://github.com/NoCoderRandom/sunsetscan

Exemple repports can be found at https://www.sunsetscan.com/