
IT Guy
@T3chFalcon • 46,043 subscribers
Privacy Researcher. Check out my Articles 🥺. DM For Collabs & Partnerships. Founder @PhishCore - Human risk intelligence & Phishing simulation platform.
Shorts
Videos

Malicious charging cables look exactly like normal ones. The cable is the clearest example. looks like a standard Apple Lightning or USB-C cable. a hidden chip inside gives an attacker remote access to your device the moment you plug it in. what it can do: — log every keystroke — inject commands as if someone is typing on your keyboard — exfiltrate files — open a remote shell — operate over WiFi from up to 300 feet away you cannot tell by looking at it. the chip is inside the cable housing. no visible difference. Hak5(Hak5) sells them commercially at $120-$180. They've been found at conference floors. hotel lobbies. left near charging stations in airports. given away as "free" promotional items at events. Never plug a cable you didn't buy sealed from a reputable retailer. never borrow a charging cable from a stranger. ever. if you need to charge using an unknown cable: use a USB data blocker. it's a small pass-through device that allows power but blocks data pins entirely. costs under $10. fits on a keychain. if you need to share a cable at a conference: use a power-only cable. no data pins at all. physically cannot transmit anything other than charge.
IT Guy98,112 views • 4 days ago

In November 2017, Strava released its Global Heatmap, a stunning data visualization built from over a billion activities and trillions of GPS points logged by runners, cyclists, hikers, and other users worldwide. It's goal was to reveal global patterns of physical activity, from city trails to rural paths, using what Strava called the largest dataset of its kind. At first glance, it was beautiful major cities like London, New York, and Paris lit up like constellations of human movement. But then a student noticed something else. Nathan Ruser (Nathan Ruser), a 20-year-old international security student in Australia, wasn’t looking for beautiful maps. When he zoomed in on conflict zones like Syria, Afghanistan, and Djibouti, he saw bright, geometric shapes in the wilderness instead of dark emptiness. Where others saw desert, Ruser saw patterns: perfect rectangles outlining forward operating bases, circles and regular paths where no public running trails should exist, and routes around installations invisible on satellite imagery but clear in activity footprints. The reason was simple: soldiers and contractors stationed overseas were using fitness trackers connected to Strava by default to log their exercise. These workouts were public unless users explicitly changed privacy settings. When dozens or hundreds of service members ran the same routes daily on base, those paths appeared as bright lines on the global map. The map didn’t attach names to data, and Strava said it used anonymized and aggregated information. Still, the patterns were unmistakable: military base perimeters, internal road networks, and personnel movement were visible and sometimes clearly traceable. The discovery sparked a huge outcry across the OSINT and defense communities. Analysts quickly realized the map could reveal the actual locations of overseas bases, the most frequently used buildings and areas within them, patrol routes, likely supply lines, and habitual movement patterns. The U.S. military acknowledged the problem, reviewed its privacy and tech policies, and urged personnel to limit public sharing of location data. In response, Strava improved privacy settings, made opting out clearer, limited detail for non-registered users, and altered how low-activity areas appeared on the map. Credit: Discovery & analysis — Nathan Ruser Source video: The New York Times investigation breakdown
IT Guy676,774 views • 8 months ago
No more content to load