Hak5
Well-known hacker channel covering a wide range of topics – from network attacks and cybersecurity tools to privacy and hacking gadget reviews – delivered in an educational and entertaining style ([www.analyticsinsight.net](https://www.analyticsinsight.net/cyber-security/10-best-youtube-channels-to-learn-about-cybersecurity-in-2024#:~:text=)).

The Hacker Group Turning Supply Chain Attacks Into a Sport | Threat Wire
The episode spotlights a new wave of software supply‑chain abuse centered on the open‑sourced “mini Shai Hulud” worm. Its creators have partnered with Breach Forums to award a $1,000 crypto prize to the attacker who generates the most downstream package downloads, effectively turning a destructive worm into a competition. In the same week RubyGems endured a coordinated spam‑publish DDoS that forced the registry to suspend new account creation and purge over 500 malicious packages. Meanwhile, the TanStack JavaScript namespace saw 84 malicious versions pushed through a forged pull‑request and GitHub Actions cache‑poisoning technique, affecting 42 packages and later expanding to 373 packages across 169 namespaces. Team PCP added a whimsical twist: a “roulette.py” module that reads time‑zone and language data, rolls a die, and, on a hit, plays loud music before executing an rm‑rf on systems in targeted regions. The worm also installs a dead‑man‑switch monitor that self‑destructs if its GitHub token is revoked, a behavior documented by JFrog and upwind.io. These incidents underscore the fragility of the JavaScript ecosystem, where millions of projects rely on NPM and rapid package publishing. Organizations must enforce strict token management, implement robust rate‑limiting, and treat supply‑chain threats as a core risk, especially as attackers monetize exploits through bounties and public competitions.

Google’s Silent AI Install: What They’re Hiding in Your Files | Threat Wire
Threat Wire’s latest episode reveals that Google has silently embedded AI components, specifically Gemini CLI binaries, into Chrome installations, a move that went unnoticed by most users. The show also highlights the emergence of the Dirty Frag Linux zero‑day, which...

The Fatal 4-Byte Error That Just Broke Linux | Threat Wire
The episode spotlights a critical Linux kernel flaw dubbed “copy‑fail” (CVE‑2026‑31431). Discovered by Xent code’s research team and initially reported by Tayyang Lee in March 2026, the vulnerability earned a CVSS 7.8 rating and affects every kernel compiled between 2017...

Vercel Hacked: A Simple Failure of OAuth Hygiene | THREAT WIRE
The ThreatWire roundup focused on Vercel’s recent security incident, which was traced to a failure in OAuth token management rather than an AI‑driven attack. The breach originated when Context.ai suffered an AWS compromise, exposing OAuth tokens that several of its...

There Are Too Many Stories to Cover #cybersecurity #news @Endingwithali
The video launches “BIDEs news,” a rapid‑fire roundup of community‑driven cybersecurity conferences and recent incidents. Key items include AWS unveiling Security and DevOps agents that automate AI‑driven pentesting and incident response, Railway’s CDN misconfiguration affecting roughly 0.05% of hosted domains and...

Use After Free Bugs Are Out of Control @Endingwithali #threatwire #cybersecurity
The video highlights two critical use‑after‑free vulnerabilities discovered in the world’s leading browsers. Chrome and its open‑source counterpart Chromium are affected by CVE‑20265281, a zero‑day flaw in Dawn, the WebGPU implementation, while Firefox suffers from CVE‑202264688, a sandbox‑escape bug in...
![🔴 [PAYLOAD REVIEW] WiFi Pineapple Pager 📟🍍](/cdn-cgi/image/width=1200,quality=75,format=auto,fit=cover/https://i.ytimg.com/vi/_7A6R_ydNUU/maxresdefault_live.jpg)
🔴 [PAYLOAD REVIEW] WiFi Pineapple Pager 📟🍍
Hack5 announced version 1.0.8 firmware for its WiFi Pineapple Pager, now available via downloads.hack5.com and OTA updates. The release adds payload metadata for authors and a powerful new list-picker UI that supports nested menus, scrolling, and variable-driven payloads, enabling far...

No More Routers In The US - Threat Wire
The episode covers a wave of supply‑chain compromises by the threat actor known as Team PCP, alongside a sweeping FCC decision to ban foreign‑made consumer routers and a scandal involving compliance startup Delve. Alli Diamond walks through each incident, highlighting...

Meta Ending End to End on Instagram- Threat Wire
Meta announced it will retire the end‑to‑end encrypted (E2EE) direct‑message feature on Instagram, with the shutdown slated for May 8, 2026. The capability, introduced in 2021, saw minimal opt‑in rates, prompting the company to pull the option and steer privacy‑focused users toward...

Chrome Is Thinking Quantum - Threat Wire
Google Chrome is rolling out quantum‑resistant HTTPS certificates, leveraging lattice‑based cryptography to safeguard web traffic against future quantum attacks. A self‑propagating JavaScript worm briefly compromised Wikipedia, altering pages before being contained. OpenAI unveiled its "Aardvark" initiative, a suite of tools...
![🔴 [PAYLOAD REVIEW] WiFi Pineapple Pager 📟🍍](/cdn-cgi/image/width=1200,quality=75,format=auto,fit=cover/https://i.ytimg.com/vi/9dmkiMOt5Og/maxresdefault.jpg)
🔴 [PAYLOAD REVIEW] WiFi Pineapple Pager 📟🍍
The Hack Five live stream spotlighted the Wi‑Fi Pineapple Pager, unveiling progress on firmware 1.0.8 and a suite of community‑driven enhancements. Host Ethan walked viewers through the latest codebase, emphasizing low‑level kernel tweaks and UI refinements designed to make the...
![🔴 [PAYLOAD REVIEW] WiFi Pineapple Pager 📟🍍](/cdn-cgi/image/width=1200,quality=75,format=auto,fit=cover/https://i.ytimg.com/vi/Ygwr-ajLhYs/maxresdefault_live.jpg)
🔴 [PAYLOAD REVIEW] WiFi Pineapple Pager 📟🍍
The video is a live walkthrough of the Wi‑Fi Pineapple Pager payload review, hosted by Darren Kitchen, showcasing recent community contributions on Hack5’s GitHub. Kitchen highlights new visual themes, such as the circuitry design by Brain Freak, and walks through the...

Password Managers Are Swiss Cheese - Threat Wire
The latest Threatwire episode delivers a packed cyber‑security briefing, spotlighting three headline stories: a critical flaw in Windows 11’s revamped Notepad, Discord’s upcoming facial‑age verification system, and a new academic analysis exposing weaknesses in leading password managers. Microsoft’s Notepad now parses...

OpenClaw Is A Mess And I Don’t Care - Threat Wire
The weekly Threatwire roundup spotlights a cascade of cyber‑security headlines, with the OpenClaw ecosystem taking center stage. The host warns that nearly 50,000 OpenClaw control panels are publicly exposed, many vulnerable to remote code execution, and that 1.5 million API...
![🔴 [PAYLOAD REVIEW] WiFi Pineapple Pager 📟🍍](/cdn-cgi/image/width=1200,quality=75,format=auto,fit=cover/https://i.ytimg.com/vi/coWaM-KbFOw/maxresdefault.jpg)
🔴 [PAYLOAD REVIEW] WiFi Pineapple Pager 📟🍍
The video spotlights the accelerating integration of artificial intelligence into everyday life, positioning AI no longer as a futuristic novelty but as a tangible driver of consumer and enterprise transformation. The host frames the discussion around how AI technologies have...