you pay $10-20/mo for smart home hubs that stop working the second your internet goes down while 88K devs run their entire home locally for $0 with this 😳
Home Assistant is the open-source home automation platform that puts local control and privacy first
it replaces every smart home subscription you have with one self-hosted dashboard:
→ controls 2,000+ devices: lights, thermostats, locks, cameras, sensors, vacuums everything
→ all processing stays on your hardware. zero cloud dependency. works when the internet is down.
→ automations: when sun sets + front door locks
→ turn on hall lights. no subscription needed
→ voice control via local Assist pipeline no Alexa/Google sending your data to servers
→ dashboards, energy monitoring, presence detection, security alerts all built in
→ integrates with your existing gear: Hue, Sonos, Ring, Nest, TP-Link, ESP32, Matter, Zigbee, Z-Wave
What this replaces:
- SmartThings Hub: $90 one-time + subscription creep
- Hubitat: $170 hardware + limited integrations
- HomeKit hub (Apple TV/HomePod): $150-300 hardware
- Alexa/Google voice processing: your privacy + recurring cloud dependency
- Nest Aware: $8-12/mo for camera history
- Ring Protect: $4-10/mo per camera
- Energy monitoring hardware: $50-200 for proprietary gadgets
all for $0
Why this matters:
- You already bought the smart devices once. Why pay monthly to talk to them in your own house?
- No cloud means no data leaks, no outages, no "we changed our pricing" emails
- 404 stars today proves this isn't slowing down it's the biggest open-source smart home project by a wide margin
- Runs on a $35 Raspberry Pi. 88K GitHub stars. 38K forks. 10+ years of active development.
How to set up (15 min):
> install on a Raspberry Pi 5 or any always-on machine: curl -fsSL https://t.co/mA0FnDgSGO | bash
> or use the Home Assistant OS image: flash to SD card, plug in, wait 10 min
> access at http://homeassistant.local:8123 create your admin account
> go to Settings > Devices & Services it auto-discovers Hue, Sonos, Ring, 2000+ brands on your network
> create automations via the visual editor or YAML
> enable Assist for local voice control no cloud, no subscriptions
Important:
- Best on dedicated hardware (Raspberry Pi 5 or NUC). Can run in Docker on existing servers too.
- Some cloud-dependent devices (cheap WiFi bulbs) may lose features prefer Zigbee/Z-Wave for full local control
- Active community of 38K+ contributors. 10+ years stable.
- Companion apps for iOS/Android are free and open source too
Your neighbour pays $20/mo for Ring Protect + Nest Aware + SmartThings. you run everything locally for $0 + the electricity of a Raspberry Pi.
bookmark this before you pay another month for a service your own hardware can run for free
🚨 Banana RAT is targeting finance with custom payloads.
It hides in legitimate cloud traffic and bypasses static blocklists ❗️
Update defenses with @0x_Olympus research 👇
https://t.co/tfRCUKg0XJ
Actors weaponize #AI hype: fake LLM domains, branded C2 infrastructure and payment skimmers. We tracked three active campaigns abusing AI lures and infrastructure. Details at https://t.co/QTb5tEGdsb
Campaign which targeting Vietnamese retail investors and VPS Securities clients.
IP: 103.90.222.9
AS 135905
Pivoted domains suggest the threat actor is operating within or abusing Vietnamese domestic CDN infrastructure.
@smica83@skocherhan@malwrhunterteam@AndreGironda
Found an 8 year old RCE in MongoDB. Sadly, MongoDB had already found it internally.
Technical writeup after the patch is released.
Sad Friday...
#bugbounty#0day#rce
Nimbus Manticore (aka Screening Serpens and UNC1549), an Iranian state-sponsored threat actor, has been attributed to a campaign using lures impersonating organizations in the aviation and software sectors across the United States, Europe, and the Middle East. With a new backdoor codenamed `MiniFast` (aka MiniUpdate) that appears to have been developed with assistance using artificial intelligence (AI) being at the forefront of the attack.
`MiniFast` is a fully featured backdoor designed for long-term persistence and remote command execution. Allowing it too:
• communicate with a C2 Server over HTTP
• upload command execution results
• exfiltrate files
• download additional payload from the server.
• beacons basic system information to the operator
A trojanized Zoom installer was used as part of the attack sequence to launch the binary that then leverages `AppDomain` hijacking the system to deploy `MiniFast`. With it being sent through a phishing emails that used fake meeting invitations. The backdoor also supports the ability to update the polling interval and jitter value applied to beacon intervals to randomize the frequency with which commands are retrieved from the server.
The development also comes as Iranian hackers are suspected to have conducted a series of attacks aimed at tank readers at gas stations. While the incidents did not cause physical damage or harm, they have sparked concerns that such access could potentially cause gas leaks to go undetected or create other risks to critical infrastructure.
#ThreatIntel #Cyber #CyberSecurity #CyberSecurityNews #APT #IranAPT #IranWar
https://t.co/JqNXOsLtWH
🚨 Supply chain attack on the Laravel Lang organization:
700+ historical versions across multiple community-maintained Laravel Lang packages were compromised with an RCE backdoor, including:
laravel-lang/lang
laravel-lang/http-statuses
laravel-lang/attributes
Laravel-Lang/actions
The payload targets cloud creds, CI/CD secrets, Kubernetes tokens, Vault, browser data, password managers, SSH keys, and more.
Chinese 🇨🇳 threat actors distribute ValleyRAT via fake Microsoft Teams sites using NSIS installers, legitimate Tencent GameBox.exe for DLL sideloading, and multi-stage in-memory payload execution.
Key technical details:
• Fake domains: teams-securecall[.]com, teamszs[.]com delivering zip archives with NSIS installer
• DLL sideloading: Legitimate GameBox.exe loads malicious utility.dll (18F3E85D7237E3CAC0AD13BDCF513F0F)
• Evasion: PowerShell commands add Windows Defender exclusions for C:\ProgramData\client
• Persistence: Creates _CCGDAT service for automatic startup
• C2 server: 103[.]215[.]77[.]17 with AES + XOR encrypted payloads
Attack chain methodology:
• Stage 1: NSIS installer drops components including legitimate Teams installer as decoy
• Stage 2: AES-encrypted user.dat payload decrypted in-memory via BcryptDecrypt
• Stage 3: XOR-encrypted final payload fetched from C2, uses reflective PE loading
• Capabilities: Clipboard theft via GetClipboardData API, keystroke logging, data exfiltration
DFIR artifacts:
• Registry keys: HKCU\SOFTWARE\IpDates_info, HKCU\Console\0\451b464b7a6c2ced348c1866b59c362e
• Service creation events for _CCGDAT in Windows Event Log
• PowerShell execution with Add-MpPreference commands
• TCP connections to C2 infrastructure
Hunt for GameBox.exe processes with network connections and unsigned utility.dll in ProgramData. Full IOC hashes and C2 details available in the report.
#DFIR_Radar
🚨 BREAKING: Socket is investigating an active npm supply chain attack compromising hundreds of packages in the @antv ecosystem.
The malicious publish wave appears tied to Mini Shai-Hulud and packages connected to the npm maintainer account atool.
#APT#OceanLotus sample created in 2025 was uploaded to VT last month. DLL decrypts and executes shellcode in memory. C2 seems to be inactive now.
8c13ce3a5f579a4fb4d25222412b775a
152.32.144[.]5:443
Fun fact about the Adobe Reader 0day: actually, it's the "AdobeCollabSync.exe" ("C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe") process who communicates to the attacker-controller server, not the "Acrobat.exe".
Therefore, if you're hunting the threat with your e.g EDR telemetry, you may want to look at that "AdobeCollabSync.exe" process too.
#threatintel
Additional capabilities resolved via PEB walking but not triggered in sandbox:
Browser cookie theft
Windows Credential Manager access
Crypto key extraction
Registry reads
User enumeration
Privilege checks
Likely C2-controlled: server decides which modules activate per victim.