Security researchers find surveillance implants in Chinese-made routers sold worldwide — three different backdoor-like implants hidden in firmware https://t.co/ApWlgfX0AQ
🚨 China-made ZBT routers ship with two factory implants.
One accepts unauthenticated commands over an internet-exposed UDP service to run commands as root. The other can exfiltrate PPPoE credentials, alter DNS hijack lists, and open reverse SSH tunnels.
How the implants work → https://t.co/nTMWHrALkj
Signal's Contact Discovery automatically sends your contact list information to an SGX enclave in the cloud.
V12 broke into that enclave and leaked the key, allowing the server host to decrypt everything.
Two separate critical bugs: arbitrary read and RCE.
Here's how. 🧵
Looking at that chart, post the ~53% drawdown from the Oct 2025 $126k ATH and July lows around $58-62k, we are in the Hope/Optimism stage of recovery.
BTC just ripped 20%+ this week to ~$78k, Fear & Greed flipped to 70 (Greed) from prolonged fear, and multiple capitulation signals (VanEck 8/12) plus Cowen's midterm thesis point to accumulation underway. Still early—far from Belief or Euphoria.
‼️ Warning - Expired Visa payment cards can be revived for real purchases.
New “Zombie Card” attack rewrites the expiry date a contactless terminal reads over NFC, while the card’s cryptography still validates.
See how it works - https://t.co/PCqmL8OKma
You don't need an expensive 3D scanner. Your phone can be the camera.
This is the idea behind photogrammetry.
You simply take a bunch of pictures of an object from different angles.
Then OpenScan processes those images and reconstructs the object as a 3D representation.
No expensive 3D scanner needed.
@Bibliotekarot@A1Makedonija@TelekomMK Go kolnam denot koga se prefrliv na @TelekomMK , ni edna lokacija nema signal kako sto treba, na nekoi mesta ne ni mozes obicen viber video call da napravis. Nez dali postoi nacin za predvremeno raskinuvanje na dogovor
You spent $2,000 on a MacBook Pro for a new hire.
Then $180 a year on the Microsoft 365 seat, $60 on Adobe, $144 on Slack, $240 on Zoom. All assigned to one laptop, one employee, one desk.
Then your CFO asked how many of the 400 laptops in this company are actually being used, and by whom.
You opened the Google Sheet. Half the rows were blank. Employees who left six months ago still had assets assigned.
So IT called ServiceNow. ITAM Standard is $100 per user per month. Professional $150. Enterprise $200+. The median ServiceNow contract on Vendr is $124,364 a year. Implementation runs three to five times the license fee.
Then IT called Lansweeper. $239 a month for 2,000 assets.
Then IT called Freshservice. $19 per agent, then metered on every asset over 500.
You are paying six figures a year to answer "who has laptop DELL-4471" in 2026.
Now meet Snipe-IT.
A free and open source IT asset management platform that runs on your own server and tracks every laptop, phone, license, and cable your company owns. No cloud. No agents. No per-seat fee.
Built in 2013 by a developer named Alison Gianotto who was the CTO of a New York City ad agency when the office had to move. Her team was tracking hundreds of laptops in a Google Doc. She tried every commercial and open source tool. None of them worked. So she wrote her own.
When she finished the first full inventory, she discovered the agency was missing $25,000 in assets.
Her husband nagged her for months to add a PayPal button. She finally did it. Two days later she had a paying customer. Snipe-IT itself stayed free.
14,113 stars. 3,886 forks. AGPL-3.0. Pushed to the repo today.
Here is what Snipe-IT gives you:
- Track every laptop, phone, monitor, cable, and accessory in one place
- Assign assets to users, departments, or locations with full history
- Software license management with seat tracking and expiration alerts
- Barcode and QR code generation for physical labels
- Custom fields, statuses, and categories
- LDAP, SAML, and Google Workspace SSO
- REST API for every endpoint
- Runs on any Linux box, Docker, or a $5 VPS
Here is what Snipe-IT costs:
Zero. Forever. No per-user fee. No asset cap.
ServiceNow charges $100 per user per month. Snipe-IT doesn't.
Lansweeper charges $239 a month for 2,000 assets. Snipe-IT doesn't.
Freshservice meters every asset over 500. Snipe-IT doesn't.
Ivanti and Flexera hide their pricing behind a sales call. Snipe-IT doesn't.
Here's the wildest part:
Snipe-IT is used by Sony, Yale University, Fujitsu, and thousands of school districts, hospitals, and government agencies that couldn't stomach a $124,000 ServiceNow bill. Alison's official title at Grokability is Chief Mohawk Officer.
For a 50-person IT team, you save $60,000 a year.
For a 500-person company, you save $600,000 a year.
Your assets. Your database. Your server.
100% Open Source. (Link in the comments)
“duress” password is incorrectly designed—it shouldn’t be apparent to the attacker that it was triggered and should instead open to an innocuous and data free home screen while nuking everything in the background
@CryptoCyberia You shouldn't give them the duress pin. But you should set the duress pin to your bday so once they try to brute force your phone they might trigger the wipe.