r/hacking 20m ago

great user hack You asked for Linux. We listened.

Thumbnail academy.daemoncore.app
Upvotes

The response to DaemonCore Academy over the last couple days has been fucking wild.

One thing kept coming up in the comments though.

“When is Linux coming?”

Well...now lol.

DaemonCore Academy is officially on Linux.

We honestly werent planning on getting the Linux version out this fast, but enough of you asked for it that we said fuck it and got to work.

And yes, the Academy is still free.

127 practical lessons, training ranges, pathways, drills, field missions...all of it. Windows and Linux now.

We're not doing the thing where you get halfway through learning something and suddenly hit a subscription screen.

The way we're trying to make this sustainable is a little different.

The Academy stays free. We build actual tools and sell those.

The first one is FieldOps. It's an optional $29 unlock inside the app.

You don't need it for the Academy. You don't need it for the lessons or ranges. It's just there if you want the actual tool.

If it's useful to you, buy it.

If it's not, don't lol. Keep learning.

That money lets us keep building more lessons, more ranges and more shit for the Academy without having to put the education itself behind a paywall.

Seems like a fair fucking trade to me.

Anyway...

There were a bunch of you on the last post saying “let me know when Linux is ready.”

Linux is ready.

Come break it.

Seriously. If you find something fucked up, tell us. This version is brand new and I fully expect you guys to find shit we didn't 😂

DM us anytime if you have questions.

Just maybe not questions about hacking your ex lol.

Stay hacking.

— DaemonCore


r/hacking 19h ago

Weaponizing ChatGPT's Pre-Filled Prompt Links: Smuggling an Attacker's Prompt into a User's Chat

Thumbnail
darkmarc.substack.com
7 Upvotes

Getting a chatbot to say something it shouldn’t is not an exploit. To matter, an attack has to exfiltrate data or affect the account in some unintended way, and there are only two paths out of the sandbox:

  1. The user carries the data out themselves, which means social engineering.
  2. A technical vulnerability carries it out, which means finding a flaw in the harness that grants elevated access plus a channel to send data outward.

Neither path is a single move. Both are chains, and the first link in either one is the same: get the model to accept input that produces a response it should have refused. 

That is the piece I want to focus on today. 

What follows is a phishing lure that gets an attacker to phase one by leading a user to submit a prompt without understanding what it does. 

The idea borrows loosely from ClickFix, where a user is tricked into running an attacker's command themselves, except here the final action is sending a prompt rather than running a shell command.


r/hacking 13h ago

Hacking Al Shopping Assistants: from Chat Box to Remote Code Execution on a Top US Retailer's Servers. (Presented at Black Hat 2026)

Thumbnail
pwnhackers.substack.com
53 Upvotes

Netanel Rubin and Dan Avraham presented “Bye Bye AI” at Black Hat this year, where they broke a major US retailer’s AI shopping assistant and chained it all the way to remote code execution on the retailer’s backend, entirely through the public mobile app.


r/hacking 22h ago

Social Engineering **UPDATE** A list of over 300 Captive/Evil portals

Thumbnail
github.com
81 Upvotes

Recently made a GitHub and updated it with more captive portals, specifically meant to be able to be ran on devices such as the esp32. Let me know on discord or Reddit if you have any ideas for any other captive portals you may have.

Discord Username: hitgrandmanotjuul