A modder used Claude Al to crack an HP laptop's BIOS lock A Reddit user unlocked a BIOS-locked HP 15-dw1036ne laptop using Anthropic's Claude Code. The laptop had a startup lock and no known bypass, and it flagged BIOS Corruption Detected on any change. #claude #ai #bios #tech #righttorepair
PWN | Hacker Community
@pwnhackers.bsky.social
Welcome to PWN – your community for hackers and cybersecurity enthusiasts. Discover the latest hacking news, breach reports, and educational resources on ethical hacking. 👾 Stay sharp. Stay secure.
Security researcher cracks GitLab with an Al agent Security researcher Yuhang Wu of depthfirst, formerly at Tesla and TikTok, used an Al agent to find two memory bugs in Oj, an obscure Ruby JSON package buried inside GitLab for nearly five years. #cybersecurity #ai #hacking #gitlab #infosec
Russia charges Telegram founder Pavel Durov with aiding terrorism Russia's FSB has charged Telegram founder Pavel Durov with aiding terrorist activity and placed him on an international wanted list. #telegram #russia #ukraine #cybersecurity #tech
Flock Left Police Searches Exposed Cops can search a nationwide network of license plate cameras without a warrant, and for a stretch of 2024 and 2025, roughly 70 of those searches were sitting in plain view on DuckDuckGo and Bing. #Flock #Privacy #Cybersecurity #Hacking
So You Want to Be an Ethical Hacker? Start Here. pwnhackers.substack.com/p/so-you-wan... #hackers #ethicalhackers #redteam #cybersecurity
So You Want to Be an Ethical Hacker? Start Here.
We get a lot of emails from members of the PWN community asking how they can get started as an ethical hacker. We created this guide so everyone who is interested in becoming an ethical hacking can be...
pwnhackers.substack.com
Member Projects: A Free Hacking Practice Challenge, a Pocket Hardware Hacking Gadget, and a DIY Malware Lab pwnhackers.substack.com/p/member-pro...
Member Projects: A Free Hacking Practice Challenge, a Pocket Hardware Hacking Gadget, and a DIY Malware Lab
TLDR: Members of the PWN hacker community are shipping an impressive range of hands-on security projects this week.
pwnhackers.substack.com
Thanks for the heads-up! That 19-year Linux flaw is a wild reminder: patch everything. Prioritize Windows Netlogon updates and watch out for AI social engineering. Stay secure!
Microsoft Backs Down After Threatening Researchers Over Zero-Day Disclosure, OpenAI Codex Discovers HTTP/2 Bomb, AI Agents Steal 6 Million Records pwnhackers.substack.com/p/microsoft-...
Microsoft Backs Down After Threatening Researchers Over Zero-Day Disclosure, OpenAI Codex Discovers HTTP/2 Bomb, AI Agents Steal 6 Million Records
TLDR: Microsoft reversed legal threats it made against security researchers who disclosed a zero-day vulnerability, following significant backlash from the security community.
pwnhackers.substack.com
Hackers Tricked Meta AI Into Handing Over Instagram Accounts, 19-Year-Old Linux Kernel Flaw, and Windows Netlogon Actively Exploited pwnhackers.substack.com/p/hackers-tr...
Hackers Tricked Meta AI Into Handing Over Instagram Accounts, 19-Year-Old Linux Kernel Flaw, and Windows Netlogon Actively Exploited
TLDR: Hackers socially engineered Meta AI into granting them access to high-profile Instagram accounts, bypassing normal account security entirely.
pwnhackers.substack.com
Scammers are now using real hotel reservation details to run highly convincing spear phishing attacks on travelers. #News #Scam #Cybersecurity
The FBI is warning that a new phishing kit called Kali365 bypasses multi-factor authentication to hijack Microsoft 365 accounts via stolen tokens. #News #Phishing #Hacking #Cybersecurity
Microsoft banned a security researcher from GitHub after they published zero-day Windows exploits, and the researcher has vowed further retaliation. #Github #Microsoft #Cybersecurity #Hacking
Microsoft Bans Zero-Day Researcher From GitHub, FBI Flags Kali365 MFA Bypass, Hotel Booking Scams Hit Travelers pwnhackers.substack.com/p/microsoft-...
Microsoft Bans Zero-Day Researcher From GitHub, FBI Flags Kali365 MFA Bypass, Hotel Booking Scams Hit Travelers
TLDR: Microsoft banned a security researcher from GitHub after they published zero-day Windows exploits, and the researcher has vowed further retaliation.
pwnhackers.substack.com
7-Zip Code Execution Flaws, ShinyHunters Dumps 7-Eleven Data, and Windows Hit by Post-Patch Zero-Day Blitz pwnhackers.substack.com/p/7-zip-code...
7-Zip Code Execution Flaws, ShinyHunters Dumps 7-Eleven Data, and Windows Hit by Post-Patch Zero-Day Blitz
TLDR: New 7-Zip vulnerabilities allow attackers to execute arbitrary code through malicious archive files, putting millions of installations at risk.
pwnhackers.substack.com
OnlyFans Attacked - A hacker is selling 340 million OnlyFans user records, though the data appears stitched together from older breaches rather than a fresh hack.
Urgent: Supply Chain Attack - A coordinated supply chain attack compromised 34 packages across npm, PyPI, and Crates, putting countless downstream applications at risk.
ShinyHunters leaked a 9.4GB archive containing 185,300 7-Eleven franchisee records after the company refused to negotiate.
ShinyHunters Dumps 7-Eleven Franchisee Data, npm and PyPI Hit by Supply Chain Attack, 340M OnlyFans Records for Sale pwnhackers.substack.com/p/shinyhunte...
ShinyHunters Dumps 7-Eleven Franchisee Data, npm and PyPI Hit by Supply Chain Attack, 340M OnlyFans Records for Sale
TLDR: ShinyHunters leaked a 9.4GB archive containing 185,300 7-Eleven franchisee records after the company refused to negotiate.
pwnhackers.substack.com
Microsoft Voice AI Hijacked by Inaudible Podcast Audio, SolarWinds Treasury Breach Deepens pwnhackers.substack.com/p/microsoft-...
Microsoft Voice AI Hijacked by Inaudible Podcast Audio, SolarWinds Treasury Breach Deepens
TLDR: Researchers reveal hidden inaudible audio in podcasts and videos can secretly hijack AI voice assistants from Microsoft and others.
pwnhackers.substack.com
Microsoft BitLocker Backdoor Claim, Linux Kernel SSH Key Flaw, Grafana GitHub Breach pwnhackers.substack.com/p/microsoft-...
Microsoft BitLocker Backdoor Claim, Linux Kernel SSH Key Flaw, Grafana GitHub Breach
TLDR: A security researcher alleges Microsoft built a secret backdoor into BitLocker and published a working exploit to prove the claim.
pwnhackers.substack.com
Microsoft Teams Turned Into a Malware Loader, Exchange Zero Day Hits, and node-ipc Hijacked on npm pwnhackers.substack.com/p/microsoft-...
Microsoft Teams Turned Into a Malware Loader, Exchange Zero Day Hits, and node-ipc Hijacked on npm
TLDR: Attackers are posing as IT support in Microsoft Teams chats to push PowerShell commands that install ModeloRAT malware on employee machines.
pwnhackers.substack.com
Twin Brothers Nuke 96 Government Databases After Firing, Microsoft BitLocker Backdoor Exposed pwnhackers.substack.com/p/twin-broth...
Twin Brothers Nuke 96 Government Databases After Firing, Microsoft BitLocker Backdoor Exposed
TLDR: Twin brothers wiped 96 government databases within minutes of being fired from their IT jobs.
pwnhackers.substack.com
Linux Kernel “Kill Switch”, npm Supply Chain Attack Hits TanStack and Mistral AI, Windows 11 BitUnlocker Cracks Disks in 5 Min pwnhackers.substack.com/p/linux-kern...
Linux Kernel “Kill Switch”, npm Supply Chain Attack Hits TanStack and Mistral AI, Windows 11 BitUnlocker Cracks Disks in 5 Min
TLDR: Linux kernel maintainers are floating a controversial “kill switch” feature to disable vulnerable functions while patches are pending, splitting the infosec community.
pwnhackers.substack.com
Featured Press Contributors: Wired, EFF, 404 Media, Fast Company, and The Guardian pwnhackers.substack.com/p/featured-p...
Featured Press Contributors: Wired, EFF, 404 Media, Fast Company, and The Guardian
One of the things that sets the PWN hacker community apart is who shows up here.
pwnhackers.substack.com
Grok Drained for $175K, 1M AI Services Exposed, Ollama Bug Hits 300K Deployments pwnhackers.substack.com/p/grok-drain...
Grok Drained for $175K, 1M AI Services Exposed, Ollama Bug Hits 300K Deployments
TLDR: A user tricked Grok AI into transferring $175,000 in crypto by tweeting a hidden command in Morse code.
pwnhackers.substack.com
ShinyHunters Hits Instructure, Utah Holds Websites Liable for VPN Users, CISA Warns of Linux Root Bug pwnhackers.substack.com/p/shinyhunte...
ShinyHunters Hits Instructure, Utah Holds Websites Liable for VPN Users, CISA Warns of Linux Root Bug
TLDR: Utah becomes the first US state to make websites legally responsible when users bypass age checks using VPNs.
pwnhackers.substack.com
BlackCat Ransomware Gang, Most Vulnerable OS to Data Breach, Canonical (Ubuntu) Attacked pwnhackers.substack.com/p/blackcat-r...
BlackCat Ransomware Gang, Most Vulnerable OS to Data Breach, Canonical (Ubuntu) Attacked
TLDR: Two cybersecurity professionals were sentenced to four years each for facilitating BlackCat ransomware attacks that extorted over $1.2 million from victims.
pwnhackers.substack.com