Cybercrime & Hacking — Posts
41 posts on "Cybercrime & Hacking" by Shlomo Strauss — bilingual writing on technology, science, and business.
- Power Grid Anomalies Expose Transnational Crypto Laundering — A Chinese crime syndicate's hidden Bitcoin mining and money-laundering operation was dismantled after algorithms detected power grid anomalies.
- Can Hackers Really Steal Your Fingerprints From Selfies? — While extracting fingerprints from photos is technically possible, modern scanner security and image compression make the actual risk extremely low.
- CanisterWorm: the worm that wipes Iranian systems and can't be shut — A new self-replicating worm spreads via a compromised supply-chain scanner, selectively wipes Iranian systems, and runs a command server on a…
- Agentic browsers and open-source platforms make a surprisingly — Pairing mature open-source platforms with an agentic AI browser bridges the gap between an empty self-hosted stack and a fully configured, working system…
- How bots tried to corner the RAM market with 10 million crafty — DataDome exposed a bot campaign that scraped RAM product pages over 10 million times, aiming to scalp inventory and deepen an AI-driven memory shortage.
- Anthropic vs. the Pentagon: a $200M contract and a question of who — After Anthropic refused to lift Claude's safety restrictions for the Pentagon, losing a $200M contract, the clash raises hard questions about corporate…
- Building a low-latency cloud infrastructure for algorithmic trading — A hands-on account of architecting a high-security, GPU-capable cloud server with 0.3 ms latency and cross-continental database replication for a private…
- How Nvidia quietly sought pirated data from Anna's Archive to train — An internal Nvidia email revealed the company pursued access to Anna's Archive's illegal dataset for AI training, exposing the ethical compromises driving
- When crypto thieves knock on the door: the rise of physical robbery — As cold wallets and stronger cybersecurity close digital attack routes, criminals are turning to physical home invasions to steal crypto — with over 200…
- How an RCE attack turned a Linux server into a zombie botnet node — A port-scanning alert exposed a Linux server infected via RCE with Gafgyt malware — a firsthand account of the attack, the investigation, and the…
- Why a 2002 PS2 game suddenly sells for $400 — and nobody plays it — A leak of PlayStation 5 boot keys revealed that exploiting a critical vulnerability requires a rare physical copy of Star Wars Racer Revenge, sending its…
- How stolen Motorola technology helps China track Tibetan refugees in — Stolen Motorola source code, surveillance cameras, and economic incentives have turned Nepal into a Chinese-operated tracking ground for Tibetan exiles.
- How a Chinese entrepreneur seized millions of IP addresses meant for — A single entrepreneur obtained roughly 10 million IPv4 addresses allocated to Africa and now leases them globally, leaving the continent short of a…
- PROMPTSTEAL: the malware that uses AI to build itself after — Google researchers exposed a Russian-linked malware that carries no malicious code upfront, instead querying an AI model post-installation to generate…
- How a $10,000 card-shuffling machine became the tool of a global — Federal charges against 31 suspects across 11 countries detail how the DeckMate 2 shuffler was compromised via its USB and network ports to signal winning
- How an SS7 security flaw became a tool for tracking and killing — A shell-company operation exploited a decades-old flaw in the SS7 telecom protocol to sell real-time phone location tracking to corrupt regimes, with…
- Pig butchering on a massive scale: the $15 billion Bitcoin seizure — The U.S. Justice Department seized $15 billion in Bitcoin tied to a Cambodian forced-labor fraud network running large-scale pig butchering scams.
- How one stolen iPhone unraveled an international theft ring in London — A stolen iPhone that kept broadcasting its location led London police to a shipment of stolen devices at Heathrow, exposing a ring that supplied iPhones…
- Russia's research ship Yantar and the threat to undersea — Russia's Yantar vessel systematically maps undersea cables and gas pipelines across European waters, raising fears of a future infrastructure attack that…
- Behind U.S. moves on Intel: intelligence, not economics — A new opinion column argues that U.S. government actions regarding Intel are likely driven by intelligence-gathering motives rather than purely economic…
- Where true randomness comes from and why it matters for encryption — A practical look at true versus pseudo-random number generation, the hardware and software methods behind it, and the real-world consequences of getting…
- Why Catalan police are taking a close look at Google Pixel owners — Because Pixel phones are the only devices that run the privacy-hardened GrapheneOS, Catalan police now treat ownership as a potential red flag in…
- How the CIA hid a spy network inside a Star Wars fan site — In the early 2000s the CIA ran a covert network of fan sites to communicate with field agents, until a captured spy in Iran exposed the operation's…
- Fake plant seeds generated by AI are selling online for real money — Scammers are using AI-generated plant images to sell seeds for species that never existed, earning thousands of dollars and eroding trust in real…
- Steganography: hiding a file inside an ordinary image — A look at digital steganography and the open-source tool OpenStego, which can conceal files inside images in seconds with no visible trace.
- How botnet operators hide commands inside DNS records — Infected machines can be silently commanded to launch DDoS attacks by reading instructions embedded in ordinary DNS text records, bypassing the need for…
- Shodan: the search engine that maps millions of exposed devices — Shodan scans open ports across the internet and indexes exposed devices, making it both a vital security tool and a ready resource for attackers.
- Your router's Wi-Fi signals can map your movements through walls — Researchers trained a model on paired Wi-Fi signals and camera footage, enabling human presence and movement detection through walls without any camera.
- Apple ties iPhone components to user accounts to deter theft — A recent iOS update lets Apple lock hardware components like the battery and camera to a user's Apple account, rendering stolen parts unusable on other…
- The IPTV piracy scheme that unraveled because of a YouTube flex — A man who ran an illegal IPTV restreaming operation earning $34 million was caught after flaunting his wealth on YouTube, and sentenced to five and a half
- From SSH terminal to a secured web hosting server: a full setup — A practical breakdown of deploying an AlmaLinux server with WHM/cPanel, covering security hardening, automated backups, and two-factor authentication.
- Modern slavery: how Asian crime cartels recruit workers for online — A Wall Street Journal investigation into the story of Billy from Ethiopia exposes a vast forced-labor industry running online scams across lawless corners
- How a server audit cut a small business's hosting costs in half — A full server audit for a small U.S. business uncovered security gaps, missing backups, and broken contact forms — all resolved within a month while…
- Zigbee explained: the protocol powering your smart home — A clear breakdown of how Zigbee works, why it differs from Wi-Fi, and what role a smart home hub plays in bridging the two protocols.
- How DDoS attacks work and how to defend against them — A clear breakdown of how DDoS attacks are built and commanded, including zombie networks and DNS-based instructions, with practical advice on free…
- Why economic pressure on Israel and China tends to backfire — Attempts to weaken Israel and China through war or trade restrictions have repeatedly pushed both to build stronger, more self-reliant industries — a…
- MAC Address: the unique identifier behind every network card — A clear explanation of what a MAC address is, how it is structured, and its practical uses — from local network communication to Windows OEM license…
- How default passwords expose servers to ransomware — A compromised Linux server illustrates why leaving default passwords unchanged exposes critical systems to automated bot attacks and ransomware.
- Telegram's slow climb from niche app to messaging giant — A personal decade with Telegram traces its technical edge over WhatsApp, its growth to 800 million monthly users, and its gradual crackdown on piracy.
- UK authorities dismantle the LockBit ransomware network — British authorities dismantled the LockBit ransomware group and now plan to unmask its founder, who once offered a $10 million bounty for his identity.
- Securing WordPress websites against increased cyber attacks — This guide outlines ten actionable steps, including two-factor authentication and geolocation blocking, to protect websites from rising cyber threats.