Cybersecurity — Posts
25 posts on "Cybersecurity" by Shlomo Strauss — bilingual writing on technology, science, and business.
- Can Hackers Really Steal Your Fingerprints From Selfies? — While extracting fingerprints from photos is technically possible, modern scanner security and image compression make the actual risk extremely low.
- CanisterWorm: the worm that wipes Iranian systems and can't be shut — A new self-replicating worm spreads via a compromised supply-chain scanner, selectively wipes Iranian systems, and runs a command server on a…
- How bots tried to corner the RAM market with 10 million crafty — DataDome exposed a bot campaign that scraped RAM product pages over 10 million times, aiming to scalp inventory and deepen an AI-driven memory shortage.
- When crypto thieves knock on the door: the rise of physical robbery — As cold wallets and stronger cybersecurity close digital attack routes, criminals are turning to physical home invasions to steal crypto — with over 200…
- How an RCE attack turned a Linux server into a zombie botnet node — A port-scanning alert exposed a Linux server infected via RCE with Gafgyt malware — a firsthand account of the attack, the investigation, and the…
- Why a 2002 PS2 game suddenly sells for $400 — and nobody plays it — A leak of PlayStation 5 boot keys revealed that exploiting a critical vulnerability requires a rare physical copy of Star Wars Racer Revenge, sending its…
- How stolen Motorola technology helps China track Tibetan refugees in — Stolen Motorola source code, surveillance cameras, and economic incentives have turned Nepal into a Chinese-operated tracking ground for Tibetan exiles.
- PROMPTSTEAL: the malware that uses AI to build itself after — Google researchers exposed a Russian-linked malware that carries no malicious code upfront, instead querying an AI model post-installation to generate…
- How a $10,000 card-shuffling machine became the tool of a global — Federal charges against 31 suspects across 11 countries detail how the DeckMate 2 shuffler was compromised via its USB and network ports to signal winning
- How an SS7 security flaw became a tool for tracking and killing — A shell-company operation exploited a decades-old flaw in the SS7 telecom protocol to sell real-time phone location tracking to corrupt regimes, with…
- Pig butchering on a massive scale: the $15 billion Bitcoin seizure — The U.S. Justice Department seized $15 billion in Bitcoin tied to a Cambodian forced-labor fraud network running large-scale pig butchering scams.
- How one stolen iPhone unraveled an international theft ring in London — A stolen iPhone that kept broadcasting its location led London police to a shipment of stolen devices at Heathrow, exposing a ring that supplied iPhones…
- Where true randomness comes from and why it matters for encryption — A practical look at true versus pseudo-random number generation, the hardware and software methods behind it, and the real-world consequences of getting…
- Why Catalan police are taking a close look at Google Pixel owners — Because Pixel phones are the only devices that run the privacy-hardened GrapheneOS, Catalan police now treat ownership as a potential red flag in…
- How the CIA hid a spy network inside a Star Wars fan site — In the early 2000s the CIA ran a covert network of fan sites to communicate with field agents, until a captured spy in Iran exposed the operation's…
- Fake plant seeds generated by AI are selling online for real money — Scammers are using AI-generated plant images to sell seeds for species that never existed, earning thousands of dollars and eroding trust in real…
- Steganography: hiding a file inside an ordinary image — A look at digital steganography and the open-source tool OpenStego, which can conceal files inside images in seconds with no visible trace.
- How botnet operators hide commands inside DNS records — Infected machines can be silently commanded to launch DDoS attacks by reading instructions embedded in ordinary DNS text records, bypassing the need for…
- Shodan: the search engine that maps millions of exposed devices — Shodan scans open ports across the internet and indexes exposed devices, making it both a vital security tool and a ready resource for attackers.
- Apple ties iPhone components to user accounts to deter theft — A recent iOS update lets Apple lock hardware components like the battery and camera to a user's Apple account, rendering stolen parts unusable on other…
- The IPTV piracy scheme that unraveled because of a YouTube flex — A man who ran an illegal IPTV restreaming operation earning $34 million was caught after flaunting his wealth on YouTube, and sentenced to five and a half
- How DDoS attacks work and how to defend against them — A clear breakdown of how DDoS attacks are built and commanded, including zombie networks and DNS-based instructions, with practical advice on free…
- How default passwords expose servers to ransomware — A compromised Linux server illustrates why leaving default passwords unchanged exposes critical systems to automated bot attacks and ransomware.
- UK authorities dismantle the LockBit ransomware network — British authorities dismantled the LockBit ransomware group and now plan to unmask its founder, who once offered a $10 million bounty for his identity.
- Securing WordPress websites against increased cyber attacks — This guide outlines ten actionable steps, including two-factor authentication and geolocation blocking, to protect websites from rising cyber threats.