Alexis Cao
@alexiscao.bsky.social
PhD student at Johns Hopkins https://alexiscao.github.io
A journalist filed a brief live blog entry on an apparent Iranian missile strike that hit no one and caused no serious damage. Next thing he knew, angry Polymarket users were demanding he change the story—and threatening his life and family if he refused. My story: wapo.st/4lI6Pon (gift link)
A journalist reported a missile strike. Then came the death threats.
An Israeli war reporter says online gamblers demanded he change a published story so they could win a payout on prediction market Polymarket.
wapo.st
Analysis and Attacks on the Reputation System of Nym (Xinmu Alexis Cao, Matthew Green) ia.cr/2026/101
Hundreds of millions of earbuds, headphones and speakers need a security update (yes, you need to update your earbuds) to prevent a wireless hacking technique that can hijack audio, eavesdrop via mics, and in some cases remotely track the accessory’s location. www.wired.com/story/google...
Hundreds of Millions of Audio Devices Need a Patch to Prevent Wireless Hacking and Tracking
Flaws in how 17 models of headphones and speakers use Google’s one-tap Fast Pair Bluetooth protocol have left devices open to eavesdroppers and stalkers.
wired.com
NEW: The internet in Iran is nearly completely shut down, according to internet monitoring firms. The blackout comes in the midst of countrywide protests that have lasted for days after spikes in prices and shortages of basic goods. The govenrment has responded with a violent crackdown.
Internet collapses in Iran amid protests over economic crisis | TechCrunch
Internet monitoring firms and experts say Iran’s internet has almost completely shut down, as protests spread through major cities.
techcrunch.com
Alexis Cao, a visiting intern from Johns Hopkins University, has joined COSIC to work on enhancing the security and privacy of mixnets this summer. Welcome! #choosecosic #cosic #kuleuven
www.theguardian.com/gnm-press-of...
The Guardian launches Secure Messaging, a world-first from a media organisation, in collaboration with the University of Cambridge
Secure Messaging is a new innovation for confidential story-sharing and source protection, underpinning the Guardian’s commitment to investigative journalism. The Guardian has published the open sourc...
theguardian.com
ESP32 Bluetooth firmware contains 29 hidden HCI commands (0xFC01–0xFC44), enabling RAM/Flash manipulation, MAC spoofing, and LMP/LLCP packet injection. Attackers can achieve persistent implants, device impersonation, firmware checks bypass, and advanced Bluetooth-based pivoting. tinyurl.com/esp32bd
Undocumented "backdoor" found in Bluetooth chip used by a billion devices
The ubiquitous ESP32 microchip made by Chinese manufacturer Espressif and used by over 1 billion units as of 2023 contains an undocumented "backdoor" that could be leveraged for attacks.
bleepingcomputer.com
Oh boy, Sam Curry comes again with yet another critical #vulnerability, now in Subaru vehicles, basically allowing full remote control over the cars. #Automotive security is no joke, but manufacturer's still live by security standards from the beginning of the century. samcurry.net/hacking-subaru
Hacking Subaru: Tracking and Controlling Cars via the STARLINK Admin Panel
On November 20, 2024, Shubham Shah and I discovered a security vulnerability in Subaru’s STARLINK admin panel that gave us unrestricted access to all vehicles and customer accounts in the United State...
samcurry.net
c69cb94fbf0c059e8cf91cf0f369f576 #cyberdeckchallenge #shmoocon