π¨ A Redditor's brand-new MacBook M5 arced, zapped, and went totally dead within 48 hours of unboxing, just from moving the hinge.
Source: https://www.reddit.com/r/mac/comments/1t1qgqe/i_have_had_this_m5_mac_for_less_than_48_hours_and/
Source: https://www.reddit.com/r/mac/comments/1t1qgqe/i_have_had_this_m5_mac_for_less_than_48_hours_and/
π€―11π±4π€¬3π₯1
Media is too big
VIEW IN TELEGRAM
βοΈπΊπ¦ GTA V is being used to train drone operators. Ukraine's Ministry of Defense drone school WeTrueGun has turned GTA V into a working FPV drone simulator. Soldiers say it feels "surprisingly close" to a real setup.
WeTrueGun is one of the most serious FPV training operations in Ukraine. The school trains future Armed Forces pilots to become UAV operators, is officially accredited by Ukraine's Ministry of Defense, and runs a 35-37 day course covering 340 academic hours: drone assembly, programming, tactical theory, electronic warfare countermeasures, situational-awareness systems like Kropyva and Delta, aviation meteorology, and live-fire flight training on targets.
The team built an FPV simulator inside GTA V's open world. Pilots can connect a real radio controller (the Radiomaster TX16S MK3 in the demo), fly anywhere on the massive map, design their own missions, and tune the simulated drone to match the response of their real rig. The mod even includes thermal vision modes.
Why GTA V instead of a dedicated simulator:
π΄ The map is enormous and unrestricted, no arbitrary boundaries
π΄ Dense urban terrain, moving vehicles, and pedestrian targets mirror real combat scenarios
π΄ No software gating, mission scripts, or canned scenarios
π΄ Pilots can practice tracking moving targets through complex environments
WeTrueGun is clear that GTA V is not a replacement for actual training. The GTA V build is for keeping fingers sharp between sessions, experimenting with mission design, and lowering the barrier for new recruits.
WeTrueGun is one of the most serious FPV training operations in Ukraine. The school trains future Armed Forces pilots to become UAV operators, is officially accredited by Ukraine's Ministry of Defense, and runs a 35-37 day course covering 340 academic hours: drone assembly, programming, tactical theory, electronic warfare countermeasures, situational-awareness systems like Kropyva and Delta, aviation meteorology, and live-fire flight training on targets.
The team built an FPV simulator inside GTA V's open world. Pilots can connect a real radio controller (the Radiomaster TX16S MK3 in the demo), fly anywhere on the massive map, design their own missions, and tune the simulated drone to match the response of their real rig. The mod even includes thermal vision modes.
Why GTA V instead of a dedicated simulator:
π΄ The map is enormous and unrestricted, no arbitrary boundaries
π΄ Dense urban terrain, moving vehicles, and pedestrian targets mirror real combat scenarios
π΄ No software gating, mission scripts, or canned scenarios
π΄ Pilots can practice tracking moving targets through complex environments
WeTrueGun is clear that GTA V is not a replacement for actual training. The GTA V build is for keeping fingers sharp between sessions, experimenting with mission design, and lowering the barrier for new recruits.
π₯13π€£9π3β€1
π¨ BREAKING: GTFO ICE, the new anti-ICE "rapid response network" launched by ex-DHS Chief of Staff Miles Taylor, has allegedly exposed 17,662 users' names, emails, phones, and ZIPs on a public API.
The exposed data was sent to law enforcement agencies by the people who found it. They are now sending the following email to everyone who was exposed on the list.
βοΈ Why the GTFO ICE breach matters beyond the open API:
π΄ 17,662 anti-ICE signups reportedly handed to FBI, ICE, HSI by the researchers
π΄ Affected users were not notified by the operator(s) first
π΄ No allegation of user crime, no GDPR-style breach process
π΄ This inverts responsible disclosure into political targeting
The exposed data was sent to law enforcement agencies by the people who found it. They are now sending the following email to everyone who was exposed on the list.
βοΈ Why the GTFO ICE breach matters beyond the open API:
π΄ 17,662 anti-ICE signups reportedly handed to FBI, ICE, HSI by the researchers
π΄ Affected users were not notified by the operator(s) first
π΄ No allegation of user crime, no GDPR-style breach process
π΄ This inverts responsible disclosure into political targeting
π€£11π₯6π2
βΌοΈπ¨ NEW RESEARCH: Fiber-optic cables can be turned into a hidden microphone and used for eavesdropping.
Researchers from Hong Kong's PolyU and CUHK just proved it works in real conditions. The paper was presented at NDSS 2026, one of the top cybersecurity conferences in the world.
When someone talks in a room, the sound waves cause tiny vibrations in everything around them, including the thin glass fiber that runs into your apartment from your internet provider. Those vibrations slightly disturb the laser light traveling through the cable. If an attacker plugs the other end of that cable into a special device called a Distributed Acoustic Sensing system, they can read those tiny disturbances and turn them back into recognizable speech.
The problem for the attacker: a normal fiber lying along your baseboard is not sensitive enough on its own. Sound fades too fast in the air, and the fiber is too thin to pick it up.
So the researchers built a small device they call a "Sensory Receptor." It is basically a 65mm plastic cylinder with about 15 meters of fiber wound around it. The cylinder catches and amplifies sound waves enough for the fiber to register them. Crucially, it is small enough to hide inside the same little plastic junction box your internet installer leaves on the wall to manage extra cable.
What the attack can actually pick up:
π΄ Daily activities (typing, walking, snoring, washing dishes): 83% recognition accuracy
π΄ Where in the room a sound is coming from: accurate to within about one meter
π΄ Spoken words at meters from the receptor
π΄ In a real office test, with the receptor hidden in a fiber box and the attacker 50+ meters away in another room, around 80% of the conversation was recoverable
Why this attack is different from a hidden microphone:
π΄ No electricity, no batteries, no radio signals
π΄ Cannot be found by professional bug sweeps that look for hidden mics or cameras
π΄ Cannot be jammed by ultrasonic jammers (the kind some boardrooms use against phone microphones)
π΄ Looks identical to a normal fiber cable
The researchers tested a commercial ultrasonic jammer right next to their device and it had zero effect. The defenses meant to protect sensitive meetings simply do not see this attack coming.
What you can do:
π΄ If you run a sensitive office or meeting room, ask your IT team about polished fiber connectors and optical isolators. Both make this attack much harder.
π΄ Do not let your internet installer leave excess fiber coiled up inside the room. Have them coil it inside the wall or in a sealed box outside the room.
π΄ Keep fiber cable runs away from desks and walls that resonate with conversation.
π΄ In high-security spaces, soundproof the walls and ceilings where fiber runs.
The researchers have published actual audio samples reconstructed from fiber vibrations: osf.io/wna5d/
Researchers from Hong Kong's PolyU and CUHK just proved it works in real conditions. The paper was presented at NDSS 2026, one of the top cybersecurity conferences in the world.
When someone talks in a room, the sound waves cause tiny vibrations in everything around them, including the thin glass fiber that runs into your apartment from your internet provider. Those vibrations slightly disturb the laser light traveling through the cable. If an attacker plugs the other end of that cable into a special device called a Distributed Acoustic Sensing system, they can read those tiny disturbances and turn them back into recognizable speech.
The problem for the attacker: a normal fiber lying along your baseboard is not sensitive enough on its own. Sound fades too fast in the air, and the fiber is too thin to pick it up.
So the researchers built a small device they call a "Sensory Receptor." It is basically a 65mm plastic cylinder with about 15 meters of fiber wound around it. The cylinder catches and amplifies sound waves enough for the fiber to register them. Crucially, it is small enough to hide inside the same little plastic junction box your internet installer leaves on the wall to manage extra cable.
What the attack can actually pick up:
π΄ Daily activities (typing, walking, snoring, washing dishes): 83% recognition accuracy
π΄ Where in the room a sound is coming from: accurate to within about one meter
π΄ Spoken words at meters from the receptor
π΄ In a real office test, with the receptor hidden in a fiber box and the attacker 50+ meters away in another room, around 80% of the conversation was recoverable
Why this attack is different from a hidden microphone:
π΄ No electricity, no batteries, no radio signals
π΄ Cannot be found by professional bug sweeps that look for hidden mics or cameras
π΄ Cannot be jammed by ultrasonic jammers (the kind some boardrooms use against phone microphones)
π΄ Looks identical to a normal fiber cable
The researchers tested a commercial ultrasonic jammer right next to their device and it had zero effect. The defenses meant to protect sensitive meetings simply do not see this attack coming.
What you can do:
π΄ If you run a sensitive office or meeting room, ask your IT team about polished fiber connectors and optical isolators. Both make this attack much harder.
π΄ Do not let your internet installer leave excess fiber coiled up inside the room. Have them coil it inside the wall or in a sealed box outside the room.
π΄ Keep fiber cable runs away from desks and walls that resonate with conversation.
π΄ In high-security spaces, soundproof the walls and ceilings where fiber runs.
The researchers have published actual audio samples reconstructed from fiber vibrations: osf.io/wna5d/
π€13π5π3β€2π1π₯1
π¬π§ The first major assessment of the UK's Online Safety Act is out. Turns out kids are fooling the age checks by drawing moustaches on their faces.
"I did catch my son using an eyebrow pencil to draw a moustache on his face, and it verified him as 15 years old." Mum of a 12-year-old, in a new report from Internet Matters, the UK's leading online-safety NGO.
That single line tells you almost everything you need to know about how the UK's Online Safety Act is going.
This is the law that:
π΄ Forced UK platforms to demand government IDs, facial scans, and credit-card checks from adults to access ordinary websites
π΄ Drove a 1,800%+ spike in VPN downloads the week the porn-site age checks went live in July 2025
π΄ Pushed millions of users into handing biometric data to private third-party verification vendors
π΄ Sits at the front of a global wave: Greece's anonymity ban, France's "VPNs are next" comments, Utah's VPN crackdown, and the EU's 27-state rollout deadline of December 2026
The headline numbers from the assessment:
π΄ 46% of children say age checks are easy to bypass. Only 17% say they are difficult.
π΄ 32% of children have already bypassed them in the past two months
π΄ 49% of children still report experiencing harm online in the past month
The bypass methods kids reported, in their own words:
π΄ Drawing on facial hair with eyebrow pencil to fool facial age estimation
π΄ Holding up a video game character's head turning during the face-scan
π΄ Submitting a video of a different person's face entirely
π΄ Using a parent's ID (often with parental consent)
π΄ Entering a fake birthday (still works on most platforms)
π΄ Using someone else's login or device
π΄ In a small minority of cases, VPNs
One 12-year-old girl explained the system to researchers: "Every time I go live on TikTok, it tells me I have to be 18, but when the AI detects that I'm not 18 they ban me. But they only ban me for 10 minutes and then I can go live again." That is the entire enforcement model.
A 14-year-old summed up the broader picture: "It's not practical because the more you restrict it, the more people are going to want to get past that age restriction." A 16-year-old, more bluntly: "I think it's a great idea in theory and I applaud its intentions, but I don't see how that's feasible, because kids will always find a way."
Even when verification works, it works against the children. A 12-year-old boy on Roblox: "I put my face in and I got 15 when I'm 12, so I'm chatting with people older than me when I shouldn't be." A 13-year-old non-binary child: "Adults can very easily use a face they searched on the internet to trick it into thinking you're someone you're not, so there might be adults in kids' age groups trying to groom them." Recent reporting confirms exactly that. Underage Roblox accounts are now being sold online to predators precisely because they bypass the new "safety" measures.
One detail in the report stops you cold. Multiple children described being unintentionally exposed through their feeds to the assassination of Charlie Kirk. A 14-year-old: "I saw it on Snapchat. I broke down into tears and then told my mum immediately." Violent content, racist content, content promoting unrealistic body types: all explicitly prohibited under the Children's Safety Codes. All still landing in feeds at scale.
Read the report: https://www.internetmatters.org/hub/research/online-safety-act-report-2026/
"I did catch my son using an eyebrow pencil to draw a moustache on his face, and it verified him as 15 years old." Mum of a 12-year-old, in a new report from Internet Matters, the UK's leading online-safety NGO.
That single line tells you almost everything you need to know about how the UK's Online Safety Act is going.
This is the law that:
π΄ Forced UK platforms to demand government IDs, facial scans, and credit-card checks from adults to access ordinary websites
π΄ Drove a 1,800%+ spike in VPN downloads the week the porn-site age checks went live in July 2025
π΄ Pushed millions of users into handing biometric data to private third-party verification vendors
π΄ Sits at the front of a global wave: Greece's anonymity ban, France's "VPNs are next" comments, Utah's VPN crackdown, and the EU's 27-state rollout deadline of December 2026
The headline numbers from the assessment:
π΄ 46% of children say age checks are easy to bypass. Only 17% say they are difficult.
π΄ 32% of children have already bypassed them in the past two months
π΄ 49% of children still report experiencing harm online in the past month
The bypass methods kids reported, in their own words:
π΄ Drawing on facial hair with eyebrow pencil to fool facial age estimation
π΄ Holding up a video game character's head turning during the face-scan
π΄ Submitting a video of a different person's face entirely
π΄ Using a parent's ID (often with parental consent)
π΄ Entering a fake birthday (still works on most platforms)
π΄ Using someone else's login or device
π΄ In a small minority of cases, VPNs
One 12-year-old girl explained the system to researchers: "Every time I go live on TikTok, it tells me I have to be 18, but when the AI detects that I'm not 18 they ban me. But they only ban me for 10 minutes and then I can go live again." That is the entire enforcement model.
A 14-year-old summed up the broader picture: "It's not practical because the more you restrict it, the more people are going to want to get past that age restriction." A 16-year-old, more bluntly: "I think it's a great idea in theory and I applaud its intentions, but I don't see how that's feasible, because kids will always find a way."
Even when verification works, it works against the children. A 12-year-old boy on Roblox: "I put my face in and I got 15 when I'm 12, so I'm chatting with people older than me when I shouldn't be." A 13-year-old non-binary child: "Adults can very easily use a face they searched on the internet to trick it into thinking you're someone you're not, so there might be adults in kids' age groups trying to groom them." Recent reporting confirms exactly that. Underage Roblox accounts are now being sold online to predators precisely because they bypass the new "safety" measures.
One detail in the report stops you cold. Multiple children described being unintentionally exposed through their feeds to the assassination of Charlie Kirk. A 14-year-old: "I saw it on Snapchat. I broke down into tears and then told my mum immediately." Violent content, racist content, content promoting unrealistic body types: all explicitly prohibited under the Children's Safety Codes. All still landing in feeds at scale.
Read the report: https://www.internetmatters.org/hub/research/online-safety-act-report-2026/
π€£15π€ͺ3β€2π₯΄1
This media is not supported in your browser
VIEW IN TELEGRAM
βοΈπ¨ Microsoft Edge keeps every saved password in process memory as cleartext from the moment it launches. Microsoft's responsed when reported: "by design."
All of them. Including credentials for sites you won't open this session.
Researcher L1v1ng0ffTh3L4N tested every major Chromium browser. Edge is the only one that behaves this way.
Chrome decrypts credentials on demand, and App-Bound Encryption locks the keys to an authenticated Chrome process so other processes can't reuse them.
In Chrome, plaintext surfaces only during autofill or when a password is viewed, making memory scraping far less useful.
What makes this extra weird is that Edge still demands re-authentication before revealing those passwords in its Password Manager UI, while the same browser process already holds every one of them in plaintext.
In shared environments, this turns into a credential harvest. On a terminal server, an attacker with admin rights can read the memory of every logged-on user process. In the published PoC video, a compromised admin account lifts stored credentials from two other logged-on (and even disconnected) users with Edge running.
Microsoft's official response when notified: "by design."
The finding was disclosed April 29 at BigBiteOfTech by PaloAltoNtwks Norway, alongside a small educational tool that lets anyone verify the cleartext storage for themselves.
All of them. Including credentials for sites you won't open this session.
Researcher L1v1ng0ffTh3L4N tested every major Chromium browser. Edge is the only one that behaves this way.
Chrome decrypts credentials on demand, and App-Bound Encryption locks the keys to an authenticated Chrome process so other processes can't reuse them.
In Chrome, plaintext surfaces only during autofill or when a password is viewed, making memory scraping far less useful.
What makes this extra weird is that Edge still demands re-authentication before revealing those passwords in its Password Manager UI, while the same browser process already holds every one of them in plaintext.
In shared environments, this turns into a credential harvest. On a terminal server, an attacker with admin rights can read the memory of every logged-on user process. In the published PoC video, a compromised admin account lifts stored credentials from two other logged-on (and even disconnected) users with Edge running.
Microsoft's official response when notified: "by design."
The finding was disclosed April 29 at BigBiteOfTech by PaloAltoNtwks Norway, alongside a small educational tool that lets anyone verify the cleartext storage for themselves.
π€£19π©8π₯4β€2
π¨πΉπΌ BREAKING: A 23-year-old college student in Taiwan brought three high-speed trains to an emergency stop by hijacking the rail network's radio communications.
A month ago Taiwan High Speed Rail Corp's operations control center received an alarm from what appeared to be a handheld radio belonging to its maintenance department. Three operating trains halted immediately. Service resumed 20 minutes later, after inspections cleared the line.
When the control center called back, the responses kept changing. Then the radio went dead.
A full inventory confirmed every THSRC handheld was accounted for and working. The signal had come from an outsider.
THSRC reported the incident on April 6. The Railway Police Bureau and the Criminal Investigation Bureau's Electronic Investigation Brigade traced the transmission to a male university student, surname Lin, studying at a university in central Taiwan.
A radio enthusiast, he allegedly used his own equipment to impersonate THSRC radio parameters and inject the false alarm into the network.
Police searched his residence and workplaces, seizing radio communication gear and electronic devices.
He was taken into custody and released the same night on bail.
Charges: violations of the Railway Act for unlawfully exploiting system vulnerabilities to intrude into core railway communication infrastructure and using electromagnetic methods to interfere with railway equipment, plus a Criminal Code charge for endangering public transportation...
That's going to stick with him for a while.
A month ago Taiwan High Speed Rail Corp's operations control center received an alarm from what appeared to be a handheld radio belonging to its maintenance department. Three operating trains halted immediately. Service resumed 20 minutes later, after inspections cleared the line.
When the control center called back, the responses kept changing. Then the radio went dead.
A full inventory confirmed every THSRC handheld was accounted for and working. The signal had come from an outsider.
THSRC reported the incident on April 6. The Railway Police Bureau and the Criminal Investigation Bureau's Electronic Investigation Brigade traced the transmission to a male university student, surname Lin, studying at a university in central Taiwan.
A radio enthusiast, he allegedly used his own equipment to impersonate THSRC radio parameters and inject the false alarm into the network.
Police searched his residence and workplaces, seizing radio communication gear and electronic devices.
He was taken into custody and released the same night on bail.
Charges: violations of the Railway Act for unlawfully exploiting system vulnerabilities to intrude into core railway communication infrastructure and using electromagnetic methods to interfere with railway equipment, plus a Criminal Code charge for endangering public transportation...
That's going to stick with him for a while.
β€10π5π3π₯°1π€¬1
βΌοΈπ¨ BREAKING: US military defense contractor Schemata exposed the personal data of active US military personnel for 150 days.
Schemata holds millions in active DoD contracts and runs sensitive simulations for Army grenadiers, Air Force operators, and naval personnel. The fix should have been simple. Instead, the platform shipped with effectively no authorization layer on its API.
Strix AI self-registered an account. That single session gave them full read access to:
- User lists with names, emails, and the specific military bases where U.S. service members are stationed
- Hundreds of confidential course manuals, served via direct S3 links to operational training modules
- Full write access to mutate or delete courses
The flaw was uncovered by an open-source AI agent, which decomposed the assessment into 20 parallel agents. 37 minutes. 520 tool calls. First validated finding in 11 minutes. The chain ran API recon, JS route mining, cross-tenant validation, auth review, and report generation end-to-end.
Strix reached out for a responsible disclosure channel in December 2025. Schemata stayed silent for 150 days. They finally replied and patched the exposed endpoints on May 1, 2026.
Read: https://www.strix.ai/blog/how-strix-found-zero-auth-vulnerability-dod-backed-startup
Schemata holds millions in active DoD contracts and runs sensitive simulations for Army grenadiers, Air Force operators, and naval personnel. The fix should have been simple. Instead, the platform shipped with effectively no authorization layer on its API.
Strix AI self-registered an account. That single session gave them full read access to:
- User lists with names, emails, and the specific military bases where U.S. service members are stationed
- Hundreds of confidential course manuals, served via direct S3 links to operational training modules
- Full write access to mutate or delete courses
The flaw was uncovered by an open-source AI agent, which decomposed the assessment into 20 parallel agents. 37 minutes. 520 tool calls. First validated finding in 11 minutes. The chain ran API recon, JS route mining, cross-tenant validation, auth review, and report generation end-to-end.
Strix reached out for a responsible disclosure channel in December 2025. Schemata stayed silent for 150 days. They finally replied and patched the exposed endpoints on May 1, 2026.
Read: https://www.strix.ai/blog/how-strix-found-zero-auth-vulnerability-dod-backed-startup
β€5π2
π¨ The official DAEMON Tools website has been serving backdoored installers since April 8.
Thousands of infections have already taken place across 100+ countries.
The latest versions are still infected. The installers are signed with legitimate developer certificates.
Source: https://www.kaspersky.com/blog/daemon-tools-supply-chain-attack/55691/
Thousands of infections have already taken place across 100+ countries.
The latest versions are still infected. The installers are signed with legitimate developer certificates.
Source: https://www.kaspersky.com/blog/daemon-tools-supply-chain-attack/55691/
π€7π2