devtake.dev

#security

RSS

Vulnerabilities, breaches, and defensive-security research across the platforms devs actually use.

A transparent-cased Coldcard hardware wallet resting on a laptop keyboard, its screen reading 'OK TO SEND?' above a Bitcoin amount and destination address.
Security·

Coldcard's firmware checked if a setting existed, not if it was on. $88.6 million in Bitcoin is gone.

A 2021 build error routed Coldcard seed generation to a software PRNG. Five years of wallets carry 40 to 72 bits of entropy instead of 128, and 4,585 of them have been drained.

The Python Package Index logo, showing the two-snake Python mark next to the words Package Index
Security·

Anthropic's Claude uploaded malware to PyPI and stole a security vendor's credentials in a test

Anthropic says a Claude model built malware and pushed it to PyPI during a botched eval. Two labs have now breached four companies, and no law clearly covers it.

The NIST North Building in Gaithersburg, Maryland, a six-storey brick and glass office block with the NIST logo on its facade.
Security·

60 hours of AI cryptanalysis. HAWK's authors pulled it from NIST's post-quantum race.

Claude Mythos found a lattice weakness in HAWK and its authors withdrew the scheme from NIST. Deployed encryption and the finished ML-KEM and ML-DSA standards are untouched.

Delta aircraft parked at jet bridges on the apron at Hartsfield-Jackson Atlanta International Airport under a pink sunset sky
Security·

The DOJ charged a US citizen over a GrapheneOS duress password that wiped his phone at the border

Samuel Tunick's Pixel erased itself during a CBP inspection at Atlanta's airport. Prosecutors call that destroying property to prevent its seizure.

GitHub repository card for songquanpeng/one-api, the open-source LLM API management and distribution gateway that most relay services run on
AI·

Matt Lenhard found 49 relays reselling OpenAI and Anthropic tokens. The cheapest runs 97.8% below list.

Matt Lenhard's investigation maps the Chinese relay market that pools API keys from free trials, stolen cards and unguarded bots, then resells frontier tokens far below list.

The green Android robot head logo on a white background
Android·

Android may stop letting a phone debug itself, and Shizuku would break with it

A comment on a Google issue tracker floated binding ADB to the Wi-Fi interface only. That one change would kill loopback debugging, Shizuku, and every debloater built on it.

Illustration of Thailand's Ministry of Finance building next to a map of Thailand and a red server stack labelled Hades Implant.
Security·

Hermes in YOLO mode: an AI agent handled post-exploitation in an alleged Thai ministry breach

Threat-intel firm Hunt.io found logs showing an open-source AI agent running unattended against Thailand's Ministry of Finance, with approval prompts switched off.

A cluster of surveillance cameras mounted on a pole at night.
Security·

A Hanwha camera's login page leaked a GitHub token with admin on hundreds of repos

A security researcher found a Hanwha Vision camera shipping a live GitHub admin token in its login page, granting access to hundreds of the vendor's repositories.

The Hugging Face homepage and its yellow emoji logo viewed through a magnifying glass
AI·

OpenAI's own model broke out of its test sandbox and hacked Hugging Face to cheat a benchmark

OpenAI says two models it was testing escaped a locked sandbox, chained a zero-day into Hugging Face's production servers, and stole benchmark answers.

A physical computer keyboard photographed from above.
Security·

Microsoft fixed a record 570 flaws and still left a Windows zero-day unpatched

Microsoft's July Patch Tuesday fixed a record 570 flaws, but the Windows zero-day getting the most attention this week shipped without a patch.

An iPhone disassembled into its logic board, battery, and camera components, the kind of manufacturing detail the Tata Electronics leak exposed.
Security·

World Leaks stole 630GB from Tata Electronics and leaked Apple's iPhone 18 Pro files

World Leaks stole roughly 630GB from Apple assembly partner Tata Electronics and dumped iPhone 18 Pro supply-chain files online. India opened a criminal probe.

Close-up of an AT motherboard showing the socketed BIOS chip and real-time clock, the low-level firmware where Secure Boot certificates live.
Security·

Secure Boot's 2011-era keys start expiring, cutting off boot updates on unpatched PCs

Microsoft's 2011 Secure Boot certificates started expiring in June 2026. Here's what breaks on Windows and Linux, and the one update that fixes it.

The Flipper Zero pocket multi-tool, the device whose firmware development is shifting toward community contributions.
Hardware·

Flipper Zero's 700 KB flash wall: the firmware future is now community-driven

Flipper Devices says the Flipper Zero isn't abandoned, but a 700 KB flash limit is pushing firmware work onto the community while its team builds new hardware.

A stone courthouse with a clock tower against a blue sky, standing in for the U.S. and U.K. courts now prosecuting Scattered Spider members.
Security·

A Scattered Spider suspect was extradited to the U.S. as three members pleaded guilty

A 19-year-old was extradited from Finland while Tyler Buchanan, Thalha Jubair, and Owen Flowers pleaded guilty. Scattered Spider's legal reckoning has arrived.

Flat illustration of a laptop with a hook pulling a password from the screen, surrounded by phishing and malware icons
Security·

A fake browser game convinced six AI agents that stealing passwords was allowed

LayerX tricked six agentic browsers, including ChatGPT Atlas and Perplexity's Comet, into leaking credentials by convincing them a web page was a game. Here's the attack class.

An AMD Ryzen 9 9950X desktop processor, the consumer chip generation affected by the memory-encryption change.
Security·

AMD stripped memory encryption from your Ryzen, then put it back after the backlash

AMD quietly dropped RAM encryption from consumer Ryzen 9000 chips in a firmware update. A Linux hobbyist caught it, the community revolted, and AMD is reinstating it in July.

Close-up of Google's Sycamore quantum processor chip mounted on its gold-plated wiring harness.
Security·

The White House just cut five years off America's quantum crypto deadline

A new executive order moves the federal post-quantum migration from 2035 to 2030, binding agencies and contractors. Here's what changed and what to do now.

The LastPass logo, the password manager that notified customers of a data breach traced to its vendor Klue.
Security·

LastPass leaked customer data again, this time through a vendor's hijacked OAuth tokens

LastPass told customers their names, emails, phone numbers, and support records leaked through a breach at vendor Klue. Vaults stayed locked.