Advertisement · 728 × 90

Posts by zh4ck

NIST says that besides focusing on enriching only the big bugs, it will also stop providing its own CVSS severity scores for NVD entries, and will now just show the severity score initially assigned by the organization that issued the CVE.

ruh-roh.... some CVSS drama incoming

1 week ago 6 1 1 2

Agentic AI is about as good at [insert task here] as I was at helping you write letters in 1996.

Back then you all made fun of me until I got fired. What gives?

1 week ago 5 2 0 0
Preview
[un]prompted 2026 - YouTube

I’m excited to let you know that the talks from [un]prompted—the AI Security Practitioner Conference—are now live on YouTube.

No fluff, no hype—just real-world AI security from people actually doing the work.

www.youtube.com/playlist?lis...

4 weeks ago 7 4 0 0
Post image

Spread the word! @phrack.org CFP with demoscene cracktro is live. Turn up the volume and enjoy the awesome stylings of @PiotrBania with some hopefully inspiring text from phrack staff :)
phrack.org

1 month ago 26 17 0 1
Post image

America according to European explorers in 1492

1 month ago 271 24 6 0
Preview
Black Hat USA 2026 Briefings

BlackHat US Call for Paper is open, and we're eagerly awaiting your submissions! I'm proud to be shepherding the Reverse Engineering track again this year and I'll be actively soliciting for cool research 😏😏😏
usa-briefings-cfp.blackhat.com

2 months ago 7 4 1 0
Post image

about to find every single vulnerability out there 💪

2 months ago 8 1 0 0
Wendy's cash register displaying "ALL YOUR BASE ARE BELONG TO US"

Wendy's cash register displaying "ALL YOUR BASE ARE BELONG TO US"

Never has such a meme swept the earth. At one point the HP .com homepage title bar said "All your base are belong to us". My local Wendy's had it scrolling on the cash register: (pic is from June 2001)

2 months ago 23 6 0 0

Me, to my watch: What time is it
My watch (on screen): It is 12:14:36
My watch (speaking): It is twelve, two, thirty six

Google has invented a watch that doesn't understand time

2 months ago 77 11 2 1
Advertisement

Supply chain attack on eScan antivirus


securelist.com ->

A threat that's many people warned about for a long time. A bit ironic to read this on Kaspersky's site...

h/t @zh4ck


Original->

2 months ago 1 1 0 0

Hadn't realised that the third party review of Twitter's chat protocol had been published and wow github.com/trailofbits/...

2 months ago 116 35 2 5
Preview
Revealed: Leaked Chats Expose the Daily Life of a Scam Compound’s Enslaved Workforce A whistleblower trapped inside a “pig butchering” scam compound gave WIRED a vast trove of its internal materials—including 4,200 pages of messages that lay out its operations in unprecedented detail.

A whistleblower trapped inside a “pig butchering” scam compound gave WIRED a vast trove of its internal materials—including 4,200 pages of messages that lay out its operations in unprecedented detail. www.wired.com/story/the-re...

2 months ago 240 89 2 8
Post image
3 months ago 0 0 0 0

According to people smarter than me one needs 2330 logical qubits to break Bitcoin. I will not hold my breath until such quantum computer is built …

5 months ago 2 0 0 0

According to people smarter than me one needs 2330 logical qubits to break Bitcoin. I will not hold my breath until such quantum computer is built …

5 months ago 0 0 1 0
DEF CON 33 - How Not to IoT:Lessons in Security Failures - Zoltan "zh4ck" Balazs
DEF CON 33 - How Not to IoT:Lessons in Security Failures - Zoltan "zh4ck" Balazs YouTube video by DEFCONConference

My DEF CON 33 talk about "How Not to IoT:Lessons in Security Failures" is available on YT \o/ www.youtube.com/watch?v=TTdK...

5 months ago 1 1 0 0
Advertisement
Preview
Inside the Synthient Threat Data Where is your data on the internet? I mean, outside the places you've consciously provided it, where has it now flowed to and is being used and abused in ways you've never expected? The truth is that ...

With support from Synthient, we've just pushed out a corpus of 183M stealer log victims to @haveibeenpwned.com. We'd never seen 16.4M of those before, either, so there's a lot of new stuff in there, and that's just the first part. More here: www.troyhunt.com/inside-the-s...

6 months ago 9 4 0 0
Post image

(comic) Bedtime story

6 months ago 36 6 0 2

I'd like to propose that hackers are the opposite, typically the "bringers of bad news". But we need a better word for this.

Given that the Greek word of the same era for "bad/badly" is either δυς/dys or κακο/caco, but predominantly the first.

The word would be 'dysangelist'. Tech Dysangelism.

6 months ago 23 7 2 0

October is Cybersecurity Awareness Month! Please be aware of cybersecurity. If you encounter cybersecurity, DO NOT APPROACH IT. Back away slowly. Protect children and pets. Make noises to scare it away.

6 months ago 21 5 1 1
Preview
Bose SoundTouch home theater systems regress into dumb speakers Feb. 18 Ending support for SoundTouch may help Bose avoid a Sonos situation.

People who have spent hundreds or even thousands of dollars to equip their home with SoundTouch audio have been frustrated about their gadgets losing some of their most coveted features soon.

6 months ago 17 2 5 4
Preview
Toy Train Joins The Internet Of Things [Zoltan] was developing a workshop on Matter for DEF CON, and wanted to whip up a fun IoT project to go with it. His idea was simple—take a simple toy train, and put it on the Internet of Things. S…

You can't stop the Internet of Things, it will be everywhere

hackaday.com/2025/09/30/t...

6 months ago 1 0 0 0
Post image

New life achievement unlocked - last weekend I presented (a lightning talk) right after the legendary @joegrand.bsky.social a.k.a Kingpin.

Do I have video proof that this happened? No
Do I have witnesses? Yes
Are they gonna testify? No
Do I have circumstantial evidence? Yes

🐊 #HackThePlanet

7 months ago 1 0 0 0
Preview
Age Verification Is A Windfall for Big Tech—And A Death Sentence For If you live in Mississippi, you may have noticed that you are no longer able to log into your Bluesky or Dreamwidth accounts from within the state. That’s because, in a chilling early warning sign

If you think online age verification mandates are the key to holding Big Tech companies accountable, you need to see what’s happening in Mississippi. www.eff.org/deeplinks/2...

7 months ago 124 61 3 3
Post image Post image Post image Post image
8 months ago 0 0 0 0
Advertisement

Infosec celebrities I met this week 😊

@malwarejake.bsky.social
@liveoverflow.bsky.social
Viktor Gazdag
@nmatt0.bsky.social
@johnhammond.bsky.social

8 months ago 0 0 1 0
Post image

So far one of the most interesting stat from #defcon
I am really interested in the back story

8 months ago 2 0 1 0
Post image

DEF CON officially arrived to Las Vegas 😜
#defcon

8 months ago 1 0 0 0

Love me some dumb US news in the morning

...sips coffee

8 months ago 18 3 1 1