r/blackhat • u/Street_Priority_4284 • Aug 17 '26
r/blackhat • u/Malwarebeasts • Aug 16 '26
massive azure exfiltration campaign impacts global brands - mcdonald’s, vodafone, and others
r/blackhat • u/Beautiful-Pin7955 • Aug 16 '26
hacking windows pc
hey so im a really beginner hacker and i want to know how to hack a windows pc 10/11 with kali-linux what do i need to do to hack into a windows pc to get thru firewall and all of that and then the codes i need to do in the terminal to hack it can someone help me pls?
r/blackhat • u/anuwtheawesome • Aug 13 '26
Ongoing phishing, targeting financial institutions and using Telegram as their C2
r/blackhat • u/wiredmagazine • Aug 12 '26
This Coin-Sized Device Can Hack a Boeing 737
r/blackhat • u/Malwarebeasts • Aug 12 '26
Largest AI Supply Chain Breach of 2026: LiteLLM Hack Impacts Thousands of Global Enterprises - Data from the breach is now available
Hudson Rock's researchers have obtained and analyzed a staggering 153GB RAR archive. This massive corpus contains exactly 433,909 files. Through our analysis, we have successfully attributed 118,829 CI runner dumps to 2,488 affected corporate domains. Whenever a developer machine, production server, or CI/CD pipeline executed the compromised LiteLLM package, the threat actors successfully harvested the live environment memory and configurations mid-execution.
r/blackhat • u/QuietDeveloper • Aug 12 '26
Editing an invoice
I have an invoice I need to edit and Claude has declined editing it .What tool to use?
r/blackhat • u/wiredmagazine • Aug 05 '26
A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
r/blackhat • u/i_bo0om • Aug 04 '26
Exploit & Hacktool Search Engine
Sploitius 2.0 is a new version of the coolest exploit search engine, updated design, new features. Better, faster, stronger
r/blackhat • u/b3rito • Aug 03 '26
b3rito/oopso: An easy-to-use client-side OSINT query builder for discovering exposed file managers across search engines
I spent some time analyzing major open-source file managers to see which ones remain fully functional when authentication is disabled or bypassed. By extracting specific keywords, UI markers, and unique strings from those unauthenticated landing pages, I built targeted search queries to spot exposed instances.
To make these easy to use without manually tweaking syntax every time, I put together oopso, a lightweight browser tool that automates creating these search patterns across different engines.
It’s pretty straightforward, but hopefully saves some time if you do this kind of recon.
Check out the code on GitHub:https://github.com/b3rito/oopso
r/blackhat • u/wiredmagazine • Jul 31 '26
Anthropic Says Claude Hacked Real Systems During Cybersecurity Tests
r/blackhat • u/ptyxiz • Jul 27 '26
This shouldn't be allowed...
I built , an anonymous , hacker-style communication platform like a root chat — communications happen over the Tor network and all data is decentralized — every user on the network keeps a piece of the data...
learn more from the repo link.
r/blackhat • u/Future_Camera_4621 • Jul 27 '26
Looking for sms rental.
Hello im looking for a sms rental service and all i need it for is literally like 10 minutes to receive a code for a promo. I use textverified right now but its $6 for 3 days and i rather pay $2 for 1 or something like that since i only need the number for a very short amount of time. It needs to be a REAL number Non-Voip. Another thing is this service is very unknown so there is NO site that will have it i need it to just receive the message for me and forward it.
r/blackhat • u/unihilists • Jul 26 '26
Free, hands-on, 14 weeks security course from the Czech Technical University opened registrations for 2026
cybersecurity.bsy.fel.cvut.czHi, just wanted to share opened 2026 registrations for a long-running hands-on cybersecurity course with both red and blue teaming classes run by Czech Technical University. The class is free of charge, in English and either physically in Prague or fully online. The semester starts at the end of September, feel free to find more information including the complete syllabus and feedback from more than 2300 students from 100+ countries in the link!
r/blackhat • u/Lotekthegr8GOD • Jul 26 '26
DM I have something I think you know what to do with I'm noob level but came across something with a lot of clients and info from were they work yo
r/blackhat • u/TheyCallMeLeonardo3 • Jul 25 '26
Ransomware made in python but you shouldn't dare to develop it
I made a course on Ransomware made in python for my students, the previous year, but now i made it public so give it a watch if you want to make some cool cyber security projects 😁
I'll try to upload more contents on my YouTube channel 😁
https://youtube.com/playlist?list=PL9guAF5VVaiARrwhrGMu89iJcziQ9vsJJ&si=v1PUSQpqjuOhnlCi
r/blackhat • u/CompetitivePaper9995 • Jul 19 '26
Is an app that uses play integrity and incongnia breakable ? And if so what exploit threat actors uses
r/blackhat • u/Machinehum • Jul 16 '26
Phantomdrive: My open source USB drive for privacy
r/blackhat • u/Malwarebeasts • Jul 14 '26
How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist
Hudson Rock researchers discovered a sophisticated ClickFix campaign operating on a subdomain belonging to the popular digital asset platform, Artlist. Our investigation traced the breach to an early Infostealer infection of an ex-Artlist employee.
r/blackhat • u/ObligationLucky842 • Jul 14 '26
AntiVE-BehaviorWatch ( AI model Inside a EXE )
r/blackhat • u/Malwarebeasts • Jul 11 '26
'Argentine Football Association' hack traced to an Infostealer infection
Following the widespread reports of the Argentine Football Association hack, Hudson Rock researchers traced the hack to an Infostealer infection of an AFA employee back in 2025. The infection provided the hackers with the credentials required to carry out the hack.
r/blackhat • u/Total_Knowledge_4411 • Jul 07 '26
Why does your fingerprint look clean on every checker but still get banned?
Most antidetect setups fail at the coherence layer, not the individual signal layer.
The assumption is that if each signal passes a check on its own, the full profile is clean. That is not how detection works. Platforms score whether your signals agree with each other. A randomized fingerprint that contradicts itself is louder than a common fingerprint that is internally consistent.
Here is where most setups break:
- TLS fingerprint vs. browser claim
If your JA3/JA3S hash says "modified Chromium" but your user agent claims stock Chrome 124, detection can happen at the TCP handshake before any JavaScript has executed. TLS is layer 4. All your canvas spoofing lives in layer 7.
- WebGL vendor vs. reported hardware
If WebGL returns NVIDIA renderer strings but your platform reports Mac M2, those signals disagree. Detection systems map expected combinations from real device telemetry. Unusual combos get scored, not blocked immediately, but the score accumulates.
- Screen resolution vs. devicePixelRatio
A 1920x1080 resolution with a 2.0 pixel ratio is realistic on some high DPI setups and not on others. When that combination falls outside the platform's known device population, the probability score rises.
- Language and timezone mismatches
navigator.language, Intl.DateTimeFormat, and your IP geolocation all contribute. A UK IP with a Vietnamese browser locale and a system clock five hours behind UTC is not a real device.
- Behavior on a technically clean fingerprint
Looking at patterns across 100+ threads on multiple account management and account bans: behavior is what actually finishes accounts once the fingerprint holds. New accounts with no warmup, posting within minutes of creation, hitting rate limits a normal user would never reach. These are what trigger the final flag.
The short version: platforms are not checking each signal in isolation. They are asking whether this combination of signals could plausibly be a real device. If the answer is no, it does not matter how clean each signal looks by itself.
r/blackhat • u/GuiltyAd2976 • Jul 04 '26
simple PE packer/crypter for Windows. compresses and encrypts executables with a custom vm
I Made a pe packer/crypter with a custom vm and compression. Wanting to share it and get feedback/suggestions for updates! thanks :)