r/hacking • • 1d ago

Threat Actors Saif Al-Din Khader a/k/a "Rey" has been arrested in Jordan for his involvement in the FBIJobs hack and ShinyHunters

Thumbnail reuters.com
70 Upvotes

r/hacking • • 1d ago

Tools Super Trouper v0.4.0 — more Frida tools for iOS app reverse engineering

Thumbnail
github.com
26 Upvotes

I’m the author of Super Trouper, a single-binary MCP server that exposes Frida to coding agents for authorized app reverse engineering. It lets an agent connect to a device, inspect apps and processes, manage sessions, and run instrumentation scripts without a Python-based Frida setup.

We released v0.4.0 a few days ago; it updates the bundled Frida Core DevKit to v17.19.0 and adds four MCP tools: memory_read and memory_write for working with memory in an attached process, plus module_list and thread_list for inspecting loaded modules and threads. app_list and others now have several query scopes, and we renamed the MCP tools into clearer namespaces. If you already have workflows built around the old tool names, check them when updating.

Quick catch-up on the two previous releases: v0.3.0 added npm installation, Frida CodeShare snippet search/use, and general cleanup. v0.2.0 moved the project to the MIT license, added first-party Frida language bridges for ObjC, Java, and Swift, and enabled TypeScript in scripts and evaluations.

I’d appreciate feedback from people using Frida in iOS research: are these tool boundaries and the new app-list scopes useful in practice? What’s missing or awkward in your workflow, and which features would you like to see next? Let me know what you think.


r/hacking • • 2d ago

Resources Chrome UX Report Dump: August 2026 data added

Thumbnail
github.com
18 Upvotes

I maintain Chrome UX Report Dumps, a collection of monthly Chrome UX Report website lists grouped by rank and published as compressed downloads. It’s meant to make the data easier to use without exporting it from BigQuery.

The latest update adds the August 2026 dataset: 18,294,881 entries across 10 files, totaling 94.7 MiB compressed. The repository now contains 1,064,254,496 entries across 67 monthly datasets, totaling 5.32 GiB compressed. Those are counts across monthly dumps, not a count of unique websites.

If you use website lists for research or security work, I’d welcome feedback. What would make these dumps more useful, and what features or formats would you like to see?


r/hacking • • 3d ago

Anyone tried the recent Samsung TV root exploits (MADBugs / chris-ritsen)?

Thumbnail
20 Upvotes

r/hacking • • 4d ago

The Hacker Who Moved to Mexico City

Thumbnail
player.captivate.fm
125 Upvotes

Full disclosure, this is my podcast. I think this community would enjoy the stories, though.

Ted started out in tech support at Delphi Internet in the early '90s, back when teenagers were opening accounts with fake credit card numbers. He tracked one of them to a house in Pennsylvania and called it. The kid's father, a reverend, answered and promised to take him out to the woodshed.

Ted went on to run security for Boston investment firms. His favorite hire was Mr. Mojo, a guy he paid to physically break into his own offices. Mojo got into one building wearing a visitor sticker he'd pulled out of the smokers' trash. In Dublin he got through a locked door by blowing into a plastic bag.

Ted was also at DEF CON in 1999, where someone shut off the air conditioning during the opening ceremony. His theory is that the best hackers come from music or philosophy, not computer science.

It's onefjef episode 62, it's audio only, and it's on all the platforms. Here's the Spotify and Apple Podcasts links.


r/hacking • • 3d ago

great user hack My local AI pentesting stack is dailed in!

Thumbnail
gallery
0 Upvotes

"Qwen3.6 35B + custom tools + docker"

Just wanted to share a local setup I finally got working smoothly for my pentesting workflow.

Im running Qwen3.6 35B locally via ollama, wrapped inside an open webui docker container on kali. To make it easily accessible with local https, im routing everything through caddy using nip.io for dns management.

instead of using the llm as a glorified search engine I bundled a unified python script directly into the open webui tools framework to give the model real capabilities.

right now it can:

scrape github repos natively + parse nmap logs + isolated python sandbox.

all local no api, self hosted, no data leaks.

honestly this wasn't a easy task for me, never touching a llm model locally and learning on the fly.

it was a lot of fun setting up (3 days straight) but now it's time to have some fun with it.

if you want to do this or something similar lmk, I would like to see others use ai like this.


r/hacking • • 5d ago

Question Best Hacking Toys Under $25

60 Upvotes

Looking to gift my team something fun but have a budget for $25 per team member. What cool toys do yall recommend?


r/hacking • • 5d ago

Github HimitsuShell: shell scripts invisible to kernel tracing

Thumbnail
github.com
66 Upvotes

r/hacking • • 5d ago

Research Paint It Blue: Reversing Win32k's Callbacks

Thumbnail idov31.github.io
22 Upvotes

This is an article about the internals of Win32k (Windows's GUI subsystem) and their callouts, with the purpose of shedding light on a very undocumented and crucial subsystem in Windows :)


r/hacking • • 6d ago

Question Alfa usb adapter

Post image
99 Upvotes

Do people use usb wifi adapters like this one, as opposed to models like the ACH? Are they significantly worse?


r/hacking • • 6d ago

Flare-on 13 and ai

10 Upvotes

Kind of killed the fun, I normally don’t do reverse engineering challenges not my field. But I was interested how frontier models would handle this. Claude was of no help as opus 5.5 refused to do the work because of model constraints and 4.8 made a mess. Then switched to gpt Astra and it solved all 9 in 1h40minutes autonomously.

How do we feel about this?


r/hacking • • 6d ago

DecaTxt discussed on Hackster

Thumbnail
4 Upvotes

r/hacking • • 8d ago

Achieved paralyzing SOTA AI's with a prompt, fun ideas?

13 Upvotes

I previously reverse engineered a game that BIGCO didn't want to release, no DRM available, large communities with both manual and AI decompilation projects, etc. All the AI's I tried knew the game (even Chinese are weirdly protective). Had to use plenty of nice words. Fable 5 couldn't break the DRM, Astra managed to do it.

Now, in another fun project I found a way to get agents stuck and the main agent wait for them indefinitely. Any fun stuff I can do with this?


r/hacking • • 9d ago

Hack The Planet Desktop Ubuntu with GPU acceleration ported to a GE smart refrigerator

Thumbnail
gallery
632 Upvotes

Ported desktop Ubuntu to a Mediatek board found in a GE Profile smart refrigerator. A combination of no secure boot, vibe coding, U-Boot and device tree fiddling, and pure ridiculousness got me here.


r/hacking • • 8d ago

FREE OSCP Active Directory Lab: Full attack chain, 3 VMs (FREE Forever!)

Thumbnail
21 Upvotes

r/hacking • • 10d ago

News Critical Cross-user and Cross-tenant compromise in Atlassian Rovo

Thumbnail
10 Upvotes

r/hacking • • 10d ago

With the proliferation of AI i'm suprised we aren't getting any government document leaks.

185 Upvotes

Even before AI we had Snowden, Wikileaks, the Panama papers.

I can't recall the last time we had a dump of these scales.


r/hacking • • 10d ago

How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers

Thumbnail
blog.cloudflare.com
13 Upvotes

r/hacking • • 11d ago

Do any devices on your network still get security updates?

12 Upvotes

Made SunsetScan to find unsupported hardware on my own network. It’s open source, and I’ll never put it behind a paywall. It scans locally and checks lifecycle data from 224 vendors with no API calls 100% self‑made databases scraped from original vendor websites.
I also created a standard with terminology because in the EoL world there are no ISO standards, so a lot of time went into getting that correct.

Tested it a couple of thousand times on my own network with 30 devices, and also tested it against lab networks with generated devices and VMs.
Happy if anyone would like to try it out and tell me if you find any outdated hardware or a false positive.

GitHub: https://github.com/NoCoderRandom/sunsetscan

Exemple repports can be found at https://www.sunsetscan.com/


r/hacking • • 11d ago

Breaking the Superuser Guardrails of managed-PostgreSQL Providers

Thumbnail
mehmetince.net
5 Upvotes

r/hacking • • 12d ago

great user hack Breaking: Hacker group 'ShinyHunters' claims to have stole FBI data, demands the bureau retract Cyber warning in 1 week.

Thumbnail
nextgov.com
368 Upvotes

r/hacking • • 12d ago

News iptresser.com legal battle against the US gov *UPDATE*

Thumbnail
reddit.com
42 Upvotes

Big update, finally, the creator did indeed change his plea and admitted to the facts, so we must now await the sentence.

A recent document made available on Pacermonitor provides us with some interesting new information.

The FBI found evidence that the creator was aware of the illegal use of the service and that users were not running it on their own servers.

The maximum sentence is 10 years in prison and a $250,000 fine, but since he has admitted to the charges, he is likely to receive a sentence at the lower end of the range.

Surprisingly, the creator was making between 11k and 15k in monthly profits.

the creator’s defense made no sense from the start; stress test operators are, by definition, acting illegally, even if these services are supposedly used to test servers owned by the users themselves. This is because the way these services operate relies on spoofing and amplification, which are themselves illegal


r/hacking • • 13d ago

I Could Takeover Any ZTE SmartHome Account Without a Reset Code. 4 CVEs, 100K+ Android Downloads

Thumbnail
minanagehsalalma.github.io
146 Upvotes

I was originally looking at ZTE router firmware and ended up following the SmartLife side into the account API used by the Android app.

After reversing the app and reconstructing its application authentication, I started testing the account flows with my own accounts.

The password reset endpoint accepted an accountId and a new password without asking for the reset code, old password, or a verified reset transaction. The account verification endpoint could also tell me whether an email was registered and return the backend accountId.

On my test account I could enumerate the account, get the ID, change the password, then log in with the password I had just set. The old password stopped working.

ZTE confirmed the findings, patched them, and assigned four CVEs:

CVE-2026-86552
CVE-2026-86553
CVE-2026-86554
CVE-2026-86555

The reset issue, CVE-2026-86553, received a CVSS score of 8.8 High.

The Android app had 100K+ downloads on Google Play alone at the time of the research.

I wrote up the reversing, Frida work, request flow, PoC sequence, SDK surface and disclosure timeline here:


r/hacking • • 13d ago

Hack The Planet 0xCr0ssCrush - Windows Ring 0 AV/EDR killer

Post image
2 Upvotes

A detailed research into BYOVD, singed drivers, kernel primitives and process control/termination etc.
Repo: 0xCr0ssCrush - Github
Proof of Concept demo is below in comments:


r/hacking • • 15d ago

CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes)

Thumbnail
accomplish.ai
132 Upvotes