/avatar.png

HackingPassion.com

Hacking is not a hobby but a way of life โ™ฅ

Your iPhone Just Got Owned: iOS WebKit Zero-Days Require No Click (CVE-2025-43529)

Your iPhone can be compromised by loading a webpage. No click. No download. Just visit the wrong site. Apple patched this a month ago. Only 16% of users have updated. ๐Ÿค”

StatCounter data from January 2026:

โ†’ iOS 26 (all versions): 16% of iPhones

โ†’ iOS 18 (unpatched): over 60% of iPhones

For comparison, iOS 18 reached 63% adoption by January 2025. iOS 26 is at less than one quarter of that rate. The lowest adoption Apple has seen in years.

52-Year-Old Unix Tape Reveals the Same Buffer Overflow We're Still Making Today

A 52-year-old tape just revealed a buffer overflow that looks exactly like the bugs we’re still finding today. ๐Ÿ˜

In July 2025, someone found a magnetic tape from 1973 in a storage room at the University of Utah. Handwritten on the label: “UNIX Original From Bell Labs V4”. This turned out to be the only surviving copy of Unix v4, the 1973 version where Ken Thompson and Dennis Ritchie rewrote the entire operating system from assembly into C.

Ni8mare: n8n Vulnerability Gives Full Admin Access with One HTTP Header Change

100,000 servers. One HTTP header change. Full admin access. No password required. They call it “Ni8mare.” CVSS 10.0. The patch existed for 7 weeks. The release notes mentioned nothing. ๐Ÿ˜

CVE-2026-21858. “Ni8mare” The name says it all.

n8n is a workflow automation platform. Think Zapier, but open source and self-hosted. Over 100 million Docker pulls. Used by Vodafone, Delivery Hero, StepStone. Thousands of enterprises run their entire automation infrastructure on it, with 400+ integrations connecting everything in one central hub.

Notion AI Leaks Data Before You Click OK: Prompt Injection Hits 100 Million Users

Notion AI steals data before the user clicks OK. 100 million users. 4 million paying customers. Amazon. Nike. Uber. Pixar. More than half of Fortune 500 companies trust this $10 billion platform with their documents. And a hidden PDF can extract everything. ๐Ÿ˜ Two major vulnerabilities since September 2025. Notion’s response to the latest one: “Not Applicable.”

Someone uploads a document to Notion AI. A resume, a customer report, anything. Looks completely normal. But hidden inside is white text on white background, 1-point font size, with a white square image placed over it for good measure. Invisible to humans. The AI reads it perfectly.

Malicious Chrome Extensions Steal ChatGPT Conversations from 900,000 Users

Two Chrome extensions. 900,000 users. Every ChatGPT and DeepSeek conversation stolen. Sent to attacker servers every 30 minutes. Google gave one of them a Featured badge. The extensions are still live in the Chrome Web Store right now. ๐Ÿค”

This is the third major case in three weeks. First the sleeper extensions that waited 7 years before activating. Then Urban VPN selling 8 million users’ AI chats to data brokers. Now this. Security researchers have a name for it: “Prompt Poaching.” And it’s becoming a gold rush.

Fake Blue Screen of Death Installs $5 RAT Malware via ClickFix Attack

$5 buys two months of complete access to someone’s computer. Keylogging, webcam, passwords, files. The malware is called DCRat. The delivery method: a fake Blue Screen of Death that tricks people into hacking themselves. ๐Ÿ˜ฑ

ClickFix attacks surged 517% in six months. Now the second most common attack vector after phishing. 8% of all blocked attacks. The campaign is called PHALT#BLYX. Securonix published their analysis January 5, 2026.

An email arrives with subject “Reservation Cancellation.” Sender appears to be Booking.com. The message mentions a refund over โ‚ฌ1,000 and urges the recipient to click and review. Booking.com has been a popular target before, with similar campaigns in 2023 and 2024.

European Space Agency Hacked: 200GB Stolen in 7 Days, Data Sold on FBI Honeypot

โ‚ฌ7.68 billion budget. 3,000 staff. A brand new Cyber Security Operations Centre opened. A hacker spent 7 days inside their systems downloading 200GB of data. Data for sale on FBI honeypot ๐Ÿ˜ On December 18, a hacker using the alias “888” got into ESA servers. JIRA project management. Bitbucket code repositories. Internal documentation systems. For seven days, nobody noticed.

On December 26, screenshots appeared on BreachForums. On December 30, ESA finally confirmed the breach.

Kimwolf Botnet: 2 Million Android TV Boxes Hacked via Proxy App Vulnerability

A botnet just fired 1.7 billion DDoS commands in 72 hours. Attack capacity: nearly 30 Terabits per second. 2 million Android TV boxes sitting in living rooms across 222 countries and regions. And now we know how the attackers built it so fast. ๐Ÿง

The attackers didn’t send phishing emails. They didn’t trick anyone into downloading malware. They just bought access to a proxy service and walked right into home networks.

16-Year-Old's AI Finds Heap Buffer Overflow in FFmpeg EXIF Parser

A 16-year-old built an AI that mass-hunts memory bugs. It found 6 vulnerabilities in FFmpeg in December. One was a heap buffer overflow in the EXIF parser. The code that reads your photo metadata. ๐Ÿ˜Ž

FFmpeg processes media on billions of devices. VLC. Chrome. Firefox. YouTube. Blender. OBS Studio. Plex. Even NASA’s Perseverance rover uses FFmpeg.

The vulnerability: CVE is still pending.

Important nuance: this bug was in FFmpeg’s development branch, not in a public release. It existed for three days before it was caught. Three days. FFmpeg called the researcher “a model security researcher” for catching it before it shipped.

70 Million Bluetooth Chips Have a Backdoor: Sony, Bose, JBL Headphones at Risk

Your headphones just became a backdoor to your phone. No pairing. No popup. Just Bluetooth range. 70 million chips. Sony. Bose. Marshall. JBL. A debug protocol active on production devices. Attackers can dump your Bluetooth keys, impersonate your headphones, and hijack your phone. ๐Ÿค”

Three CVEs. Zero authentication required. Full technical disclosure: December 27, 2025 at 39C3.

The vulnerabilities

โ†’ CVE-2025-20700: No authentication on Bluetooth Low Energy โ†’ CVE-2025-20701: No authentication on Bluetooth Classic โ†’ CVE-2025-20702: Debug protocol exposed that should never be accessible