Category: Security

2026

18

May

How WordPress Attackers Get Their Dirty Fingers into your System

Most WordPress malware does not begin with a shadowy genius manually editing your theme at midnight. It begins with bots, bored plugins, sloppy permissions, and one unlucky functions.php file that became writable. This is the story of how attackers get the pen, why they keep writing, and why deleting one dirty file is rarely enough.

Read more

14

May

The WordPress Backdoor That Forgot to Be PHP

A WordPress backdoor hidden in functions.php is bad enough. One pasted after the closing ?> tag is almost poetic: malware that forgot to become PHP and instead printed its own confession. Here is a technical walk-through of a hidden admin account, query tampering, fake user counts, and the grim beauty of neglected WordPress hygiene.

Read more

04

May

Rclone: Zero-Trust Cloud Storage Without the Friction

Stop trusting cloud providers with your personal data. Here is how to use rclone to build a transparent, client-side encryption layer over Dropbox or pCloud

Read more

26

Apr

April 26: A 40-Year Anniversary of Meltdowns

April 26 marks the 40th anniversary of the Pripyat disaster. It also marks the detonation date of the most destructive virus of the 90s: the CIH space-filler

Read more

22

Apr

gh is watching you

Github is watching you

github has a nice and easy cli tool to use, but if you thought that it would let you keep your privacy – think again!

Read more

20

Apr

Meshtastic vs Reticulum: Why Reticulum Wins for Scalable Sovereign LoRa Networks

Meshtastic is currently dominating the off-grid communication hype cycle. But when we look under the hood at its managed flooding architecture and symmetric cryptography, does it actually hold up as a foundation for sovereign infrastructure? Here is a deep dive into why I am shifting my focus to the Reticulum Network Stack.

Read more

06

Apr

The Cryptographic Zombie: How Keybase Went from Privacy Darling to Zoom’s Cleanup Crew

Once the ultimate geek flex for cypherpunks, Keybase promised to make PGP cryptography accessible to mere mortals. Today, it hovers in the digital ether as a “zombie” app. Here is the story of how a revolutionary open-source identity platform was cannibalized to become Zoom’s corporate cleanup crew.

Read more

2025

24

Sep

Malware with a Mind of Its Own – a case study in 4 acts

A new armsrace has begun and in many ways it seems like we have started something we cannot stop again – like Skynet, but real!
So I set out to explore this a bit and write about it.

Read more

27

Feb

Random MAC address for anonymity

Ever feel like your phone is snitching on you? That’s because it probably is — at least, its MAC address is. In this deep-dive post, we explore how your devices quietly broadcast your identity through Wi-Fi and Bluetooth, and how you can fight back by randomizing your MAC address. From Linux laptops to iPhones and Androids, we break down how to go full digital chameleon, one spoofed packet at a time. Bonus points for keeping your sneakers-buying habits off the grid.

Read more

2024

09

Oct

How to crash macOS Sequoia in 10 lines of code

Apple always brag about the stability of their products, and this is a claim that their users tend to echo. Having had a debugger connected to macOS and IOS more than a few times, I know that it is more about hiding the crashes than actually preventing them (it is amazing how often the IOS […]

Read more