Sign in

Zak

@rist138.c2.z4.fyi
31 followers 38 following 62 posts

I write about security stuff...Hack the planet !!

PostsRepliesMedia
Zak @rist138.c2.z4.fyi · 4h
Today is the last day to make a public comment on the proposed revocation of the "roadless rule" protecting our nations forests. Please take a moment to provide a personal public comment, if you're able. www.outdooralliance.org/roadless
outdooralliance.org
Defend the Roadless Rule and Protect National Forests | Outdoor Alliance
Help us protect our backcountry recreation areas. Roadless rules defend forests, and help preserve their clean air, clean water, and local habitat.
000
Zak @rist138.c2.z4.fyi · 06/10/2026
With valid Exchange credentials and a little bit of http request magic, maybe you can read a mailbox that isn't yours 🤣. In all seriousness, they have not disclosed the PoC, so we can only guess. thehackernews.com/2026/10/micr...
thehackernews.com
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Microsoft patches CVE-2026-96940, which lets authenticated attackers read other users' Exchange mailboxes within the same organization.
000
Zak @rist138.c2.z4.fyi · 30/09/2026
This keeps getting worse. thehackernews.com/2026/09/atta...
thehackernews.com
Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
Unknown attackers exploit a patched Citrix NetScaler flaw to gain root access and deploy web shells and a tunneler.
000
Reposted by Zak
#TeslaTakedown @teslatakedown.com · 28/09/2026
First we've seen of a candidate going straight at Elon! Who will be next...? bsky.app/profile/wewi...
44410
Zak @rist138.c2.z4.fyi · 25/09/2026
Scary one ! Keep in mind that this is a local privilege escalation bug. The attacker must already have an unprivileged user account (or be running inside a container) on the target machine. It's not remotely exploitable. Still, patching asap is advised cyberpress.org/14-year-old-...
cyberpress.org
14-Year-Old Linux Kernel Vulnerability Lets Attackers Gain Root and Escape Containers
A 14-year-old Linux kernel flaw in the AF_ALG cryptographic socket interface can allow unprivileged local users to gain root privileges and escape Docker containers.
000
Zak @rist138.c2.z4.fyi · 25/09/2026
There's no escaping Shai Hulud! thehackernews.com/2026/09/comp...
thehackernews.com
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
GitHub disabled two actions-cool Actions again after re-enabled repositories left malicious May 18 tags able to execute credential-stealing code.
000
Reposted by Zak
ACLU @aclu.org · 23/09/2026
Ban Flock cameras. Ban Axon cameras. Ban Motorola cameras. Ban ALL automatic license plate readers. That was our message to the Senate today. The American people agree that it's time for Congress to take immediate action.
17963329
Reposted by Zak
Electronic Frontier Foundation @eff.org · 24/09/2026
“They don’t have to go to a judge, they don’t need to justify why they’re making a search of all this historic (Flock ALPR) data, they can just sit (with) a computer and run a search. And so it is tailor-made for this abuse,” EFF’s @mguariglia.bsky.social told Atlanta’s WSB ABC2.
wsbtv.com
Flock cameras are everywhere. Avoiding them can be next to impossible
Critics see a surveillance network. Police see a crime-fighting tool.
312948
Reposted by Zak
Free Software Foundation @fsf.org · 24/09/2026
They say "rights," we say "restrictions" #DRM are not for your digital /rights/, they are /restrictions/ imposed on you. Celebrate your own intellect by staying away from DRM. Learn more about DRM-free living at u.fsf.org/44y
People outside protesting DRM.
073
Zak @rist138.c2.z4.fyi · 24/09/2026
CERT Polska and CISA confirmed that attackers have been actively exploiting these flaws in the wild. Attack logs show exploitation attempts happening even before patches were publicly released. If you're using a MikroTik router, patch immediately! cert.pl/en/posts/202...
cert.pl
Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended
The CERT Polska team has identified and coordinated the disclosure of six vulnerabilities in MikroTik RouterOS, including two critical ones. The vulnerabilities are already being actively exploited to...
000
Zak @rist138.c2.z4.fyi · 15/09/2026
This is a WILD find, local privilege escalation that allows unprivileged users to execute commands with SYSTEM level privileges on Windows : radar.offseq.com/threat/steam...
radar.offseq.com
Steam vulnerability on Windows lets any normal user silently escalate to SYSTEM - Live Threat Intelligence - Threat Radar | OffSeq.com
Detailed information about Steam vulnerability on Windows lets any normal user silently escalate to SYSTEM. Get real-time updates, technical details, and mitiga
000
Zak @rist138.c2.z4.fyi · 14/09/2026
Yet another major Telegram security issue. Switching to Signal is highly advised: thehackernews.com/2026/09/tele...
thehackernews.com
Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports
Telegram Desktop fixed a flaw that let bot messages embed JavaScript in HTML exports to read or alter messages; old exports remain affected.
000
Zak @rist138.c2.z4.fyi · 13/09/2026
Be advised: thehackernews.com/2026/09/gitl...
thehackernews.com
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab patched CVE-2026-85706, a CVSS 10 path traversal flaw enabling unauthenticated file reads, as in-the-wild probes began.
000
Zak @rist138.c2.z4.fyi · 13/09/2026
What a wonderful timeline we're living in: www.darkreading.com/cyberattacks...
darkreading.com
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.
011
Reposted by Zak
Electronic Frontier Foundation @eff.org · 04/09/2026
"The idea that surveillance makes us safer keeps being used as an excuse," EFF’s Rindala Alajaji told BBC, as tech is "used to criminalise people for being bystanders, with stories of innocent people being pulled over and having guns drawn on them because a licence plate reader read a letter wrong.”
bbc.com
I went looking for surveillance cameras in my neighbourhood: I found so many more than I thought
In the trade-off between privacy and security, it helps to know the extent of your local surveillance infrastructure. There are now easy ways to find out.
018574
Zak @rist138.c2.z4.fyi · 01/09/2026
Can't believe this isn't getting more coverage cybernews.com/security/ali...
cybernews.com
Alibaba’s AliExpress leverages user audio systems for fingerprinting
The Chinese e-commerce giant isn’t actually recording users but instead playing a silent sound and measuring how specific devices processed it.
000
Zak @rist138.c2.z4.fyi · 29/08/2026
Root on a $20,000 humanoid robot from Bluetooth range is a phrase you don't hear every day. boschko.ca/g1-ble-rce/
boschko.ca
UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range
Root on a $20,000 humanoid robot from Bluetooth range. One chain crossing Bluetooth, Unitree’s cloud, mobile, and the firmware running the G1 itself. Here’s the complete technical breakdown of the $6,...
000
Zak @rist138.c2.z4.fyi · 27/08/2026
Remember to shred your expired cards ! thehackernews.com/2026/08/zomb...
thehackernews.com
Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
Zombie Card rewrites Visa NFC expiry data in transit, reviving expired cards at one tested U.S. bank without breaking card cryptography.
000
Zak @rist138.c2.z4.fyi · 27/08/2026
Be advised and update to 1.27.1 immediately if you have not already: thehackernews.com/2026/08/crit...
thehackernews.com
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
CISA adds CVE-2026-60004 to KEV amid active Gitea RCE exploitation; a separate reported attack deployed a miner-like dropper.
000
Reposted by Zak
ACLU @aclu.org · 26/08/2026
Numerous studies, including from the FBI itself, show that invasive mass surveillance tech like Flock and Axon's automatic license plate readers don't help police fight crime. Surveillance is not safety.
futurism.com
Flock Surveillance Cameras Are Actually Horrible for Fighting Crime, FBI Data Shows
New FBI data shows case closure rates for the Atlanta Police Department have not improved despite thousands of ALPRs installed since 2021.
14445191
Zak @rist138.c2.z4.fyi · 23/08/2026
Knowing how PE firms have a habit of spending as little as possible on security and aggressively offshoring, I can't say I'm too surprised : cyberpress.org/apollo-globa...
cyberpress.org
Apollo Global Data Breach Exposes Names, Addresses and Social Security Numbers
Apollo Global Management has disclosed a July cyber incident in which attackers gained unauthorized access to cloud platforms and potentially obtained highly sensitive personal information.
000
Reposted by Zak
Free Software Foundation @fsf.org · 23/08/2026
Want to see your name on the #GNU #CopyrightAssignment list? Contribute to #GNU and assign your copyright to the #FSF today: u.fsf.org/xe
011
Reposted by Zak
Free Software Foundation @fsf.org · 23/08/2026
Cutting out DRM-saddled digital goods is possible, and we have a few ideas to get you started: www.defectivebydesign.org/guide #DRM #DefectiveByDesign
001
Reposted by Zak
Electronic Frontier Foundation @eff.org · 20/08/2026
Age Verification schemes come with a wealth of privacy, security, and access issues. ZKP’s aren’t going to solve any of them, they just kick the problem down the road. www.eff.org/deeplinks/2...
eff.org
Zero-Knowledge Proofs Aren’t Age Verification Silver Bullets
Age verification (laws and regulations requiring platforms and websites to assure or estimate that a user seeking to use an online service is of a certain age) is everywhere. At the time of writing,
210052
Zak @rist138.c2.z4.fyi · 22/08/2026
What an absolute legend ! I'm sad I didn't get to attend this year (I DID get to go to HOPE in NYC and had a blast, don't feel too bad for me). I'll see you next year @defcon.bsky.social
000
Reposted by Zak
ACLU @aclu.org · 21/08/2026
There’s never been a more important time to teach young people about civil rights. Know Your Rights University explores: 🧢 Student free speech rights 📚 Book bans 🏛️ The 3 branches of government 🤝 Civic activism Check it out today.
youtube.com
Know Your Rights University - YouTube
Two curious students at Eastman-Baldwin Junior High learn fun and important lessons about civics and the power of our rights and freedoms from their knowledg...
225595
Reposted by Zak
ACLU @aclu.org · 21/08/2026
From pushing for newly gerrymandered maps and national anti-voter bills to attacking mail-in voting, President Trump has shown he will do whatever it takes to make it harder to cast a ballot. The fight to protect our democracy is as important as ever.
nytimes.com
Opinion | Trump’s Election Interference Is Eroding American Democracy
The president is prioritizing his own interests over the national interest.
323266
Zak @rist138.c2.z4.fyi · 20/08/2026
This is amazing news!
000
Reposted by Zak
Sitting on a corn flake @grrlscientist.bsky.social · 19/08/2026
A full third of registered voters failed a freakin open book test because THEY ARE FUNCTIONAL ILLITERATES and TREASONOUS IDIOTS
45491522217
Reposted by Zak
Dare Obasanjo @carnage4life.bsky.social · 19/08/2026
Republicans are begging AI companies to start creating positive PR about datacenters because they are at risk of losing elections because the GOP is now the pro-datacenter party. Who would have guessed there’d be negative repercussions from bragging about all the job loss AI would create?
axios.com
Exclusive: GOP warns AI companies that data centers are politically radioactive
"This has become a sleeper issue for the entire election cycle," Senate Republicans' committee says.
1910726
Reposted by Zak
Electronic Frontier Foundation @eff.org · 19/08/2026
Do you know how to spot covert automated license plate readers (ALPRs)? Here's what to look out for if you're on the U.S.-Mexico border. www.eff.org/deeplinks/2...
4276139
Reposted by Zak
ACLU @aclu.org · 19/08/2026
Flock cameras are springing up in communities across our country, endangering our privacy. Tell your member of Congress: Enough is enough. Get these creepy cameras off our street.
action.aclu.org
Get the Flock Out
Flock and other automatic license plate readers (ALPRs) are taking over our neighborhoods, tracking our movements, and building detailed databases about us. Tell Congress to rein in this mass surveillance tool: No Flock. No ALPRs. No exceptions.
19408179
Zak @rist138.c2.z4.fyi · 19/08/2026
This one is scary, update ASAP.
000
Zak @rist138.c2.z4.fyi · 19/08/2026
I'm really hoping to make it next year. I got to do HOPE in NYC for the past few years. Next year the plan is to do both !
000
Reposted by Zak
Proton @proton.me · 29/06/2026
If you use Gmail, you need to read this. Google’s AI, Gemini, can read your emails, attachments, bank statements, etc. For many, this feature was switched on without consent. Here's how to turn it off 🧵 1/
231159738
Zak @rist138.c2.z4.fyi · 17/08/2026
Well that's concerning: nerds.xyz/2026/04/copy...
nerds.xyz
Copy Fail exploit lets 732 bytes hijack Linux systems and quietly grab root
A newly disclosed Linux kernel vulnerability called Copy Fail lets a normal user gain root access using just a 732-byte script. The exploit is simple, reliable, and works across major distributions…
000
Zak @rist138.c2.z4.fyi · 16/08/2026
This is a little concerning...attestation should always have a human in the loop: www.darkreading.com/vulnerabilit...
darkreading.com
Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI
Vulnerability volumes continue to surge, driving the National Institute of Standards and Technology to ask if AI can help.
000
Zak @rist138.c2.z4.fyi · 16/08/2026
CVE-2026-55040 is a critical SharePoint authentication bypass. An unauthenticated attacker can exploit weaknesses in JWT validation to forge tokens and impersonate any SharePoint user, including administrators. securityaffairs.com/197137/hacki...
securityaffairs.com
SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit
Attackers are exploiting SharePoint flaw CVE-2026-55040 after a public PoC was released, allowing unauthenticated users to impersonate admins
000
Reposted by Zak
2600 - The Hacker Quarterly @2600.com · 16/08/2026
Last day HOPE tickets on sale for $75 starting Sunday morning, 9 am! New Yorker Hotel, 2nd floor. www.hope.net
hope.net
Hackers On Planet Earth - HOPE
HOPE (Hackers On Planet Earth) is an annual conference for hackers, makers, and tech enthusiasts based in New York City.
194
Zak @rist138.c2.z4.fyi · 15/08/2026
Social engineering is more dangerous than any CVE. People are always the weakest link, that's why training is never a waste of time and money! www.securityweek.com/1-6-million-...
securityweek.com
1.6 Million Likely Impacted by RingCentral Data Breach
ShinyHunters stole the names, addresses, email addresses, and phone numbers of 1.6 million RingCentral customers.
000
Zak @rist138.c2.z4.fyi · 15/08/2026
Apple folks, be advised ! thehackernews.com/2026/08/appl...
thehackernews.com
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
Apple's CVE-2026-65400 Screen Sharing flaw is under active exploitation on internet-exposed Macs to install a Monero miner.
000
Reposted by Zak
404 Media @404media.co · 15/08/2026
Flock told 404 Media in an email it never executed the partnership with Nexar. But the presentation still shows Flock’s ambitious plan to conscript rideshare and delivery drivers to collect license plate data for its network. www.404media.co/flock-pitche...
404media.co
Flock Pitched a Plan To Turn Uber and Lyft Drivers Into Roaming Surveillance Vehicles
A Flock presentation shows the company planned to use around 350,000 Uber, Lyft, and delivery drivers to collect license plate data for its surveillance system.
211158
Reposted by Zak
Electronic Frontier Foundation @eff.org · 26/07/2026
A growing number of police departments are interested in sending a drone to nearly every call for service in their communities. The trend requires heightened public vigilance around use, policy, and data sharing.
eff.org
Hundreds of Drone-as-First-Responder Programs Could Soon Be Launched Across the Country
Police departments across the country are lining up to launch drone-as-first-responder (DFR) programs, and hundreds have cleared a necessary hurdle toward making deployment a reality, expanding aerial...
1111355
Zak @rist138.c2.z4.fyi · 27/07/2026
This is terrifying , every single American needs to be aware of this.
000
Reposted by Zak
ACLU @aclu.org · 27/07/2026
The public is catching on to Flock's surveillance scheme — and successfully fighting back against the company's efforts to expand its network of creepy cameras even more. Flock can't stop the power of the people.
13711273
Zak @rist138.c2.z4.fyi · 19/07/2026
Be advised and update your WordPress servers asap! cyberpress.org/critical-wor...
cyberpress.org
Critical WordPress wp2shell Flaw Lets Anonymous Attackers Execute Remote Code
A critical pre-authentication remote code execution (RCE) vulnerability in WordPress Core, dubbed "wp2shell."
000
Reposted by Zak
ACLU @aclu.org · 28/06/2026
Automatic license plate readers track our every move and funnel our personal information into enormous databases that police can access to spy on us without a warrant. Surveillance company Flock Safety is the largest provider of these cameras — it's time we get all of them out of our communities.
aclu.org
Get The Flock Out
Automatic license plate reader (ALPR) companies like Flock Safety are quietly trying to build a nationwide mass surveillance system. If there are Flock cameras in your city, they are tracking, logging, and sharing your movements without a warrant. But we're not powerless. More and more communities are rejecting these creepy cameras — and yours can be one of them!
15583236
Reposted by Zak
Electronic Frontier Foundation @eff.org · 28/06/2026
Congress could vote on the KIDS Act as soon as tomorrow. The bill would pressure websites to determine users’ ages, and more broadly moderate lawful speech. We’re urging lawmakers to vote NO: act.eff.org/action/tell...
act.eff.org
Tell Congress: Don’t Force Age Checks Online
Congress is preparing to vote on the KIDS Act, a sweeping internet bill that would pressure websites and apps to determine users’ ages before allowing them to read websites, send private messages, or participate in online communities.
5211118
Reposted by Zak
Electronic Frontier Foundation @eff.org · 28/06/2026
Privacy violations can have life-altering consequences for queer people. We’re urging Grindr to change its default settings to prevent users’ data from being used against them. eff.org/deeplinks/2...
eff.org
EFF to Grindr: This Pride Month, Put Safety and Privacy Over Profits
This Pride month, we’re calling on the dating app Grindr to prioritize LGBTQ+ user safety by making privacy the default across its platform. That means no more sharing personal data with advertisers
113652