frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Hacking your PC using your speaker without ever touching it

https://blog.nns.ee/2026/06/03/katana-badusb/
105•xx_ns•1h ago

Comments

217•1h ago
Can't wait to see a video from a half sloppy channel about this on my youtube front page in roughly 4 business days
tarcon•42m ago
I guess you can still be first to Linkedin and get all of the fame.
exitb•16m ago
Do you know that if you turn off saving YouTube history, you can have no front page at all?
bradley13•1h ago
Good work, and fun to read.

It's crazy that companies just stick their head in the sand, when confronted with serious security issues.

hootz•1h ago
>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk."

So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.

3form•55m ago
AND being able to further reprogram the device to gain control of the PC.

This is negligence of the highest kind.

Uncle_Brumpus•53m ago
"You can just make it type words, what's the risk in that?"

Makes you wonder what other peripheral companies out there are also operating with seemingly no security team. There must be other vulnerabilities like this just waiting to be discovered.

My brother was awoken one morning at 2am because some neighborhood kids connected to his bluetooth speaker and blasted fart sounds on loop at max volume, and that's literally only the absolute tippy top of the malicious bluetooth use iceberg.

hootz•47m ago
Oh yeah, for some reason the companies with the highest risk products seem to be the ones that care less about security. Don't even get me started with "smart" bulbs and cameras that each individually connect to your local network and the Internet. You have 5 lightbulbs? That's 5 different devices you need to track, keep updated and trust the in the vendor firmware's security.
rcxdude•42m ago
Probably most of them. It's not exactly an area with a great focus on quality, let alone security.
KurSix•45m ago
The vendor response is the more worrying part
xnickb
KurSix•47m ago
The fact that the author had to publish a third-party patch because the vendor didn't consider it a vulnerability is not a great look
awedisee•42m ago
Way cool. Thank you for sharing
brogapp•39m ago
Thanks for sharing this. It’s a bit concerning that a consumer soundbar can receive unauthenticated firmware over BLE and then act like a BadUSB-style HID on the host. I’m not sure I agree with the vendor’s "no cybersecurity risk" assessment, considering how much access a trusted keyboard interface typically has.
vessenes•36m ago
Having a guaranteed audio channel makes this so much cooler for exploits -- you can exfiltrate over audio!! I love it. I wonder how many of these were sold. I also imagine based on Creative's response (this is fine) that many other devices in the class have similar security models in place. Def scary.
xx_ns•33m ago
That would've been a cool PoC to work on as well, but seems a fair bit more complicated than the BadUSB-style attack I ended up doing. Would've had to do a lot more RE to figure out how to interact with the whole microphone subsystem, I think.
vessenes•11m ago
I guess you could just construct a wav file from the shell and then play it. Agreed doing it all on device sounds challenging.
SirFatty•35m ago
The real question remains: with this hack, did the OP gain full control of Dr. Sbaitso?
sciencejerk•27m ago
Great research. Thanks for sharing
nickdothutton•21m ago
It is quite common to find device manufacturers, even those of many years standing, who _appear to_ begin with the device and add the software as an afterthought. Paying little attention to security or even the software lifecycle (patches, updates, the changing landscape/ecosystem). I have even known it happen that the device brand subs out the software to a random small developer, who then closes up shop/dies/gets out of that business, and the device company doesnt even have the source code, let alone any ability to further improve/fix the software that drives their device. This leads to layers upon layers of subsequent middleware, UIs, shims etc.
cbdevidal•17m ago
Air-gapped attacks are the most fascinating. Change my mind
Klaus23•12m ago
Why think so small? Perhaps the speaker itself can be used as the attacker.

Any script kiddie with an LLM could write a worm that would spread through the supply chain, possibly even hacking speakers right on the factory floor and blasting Rickroll music or something similar.

It would be interesting to see if Creative would still claim that it "does not present a cybersecurity risk".

cluckindan•7m ago
Flash worm into device and RMA it. Boom.
•
39m ago
Yeah, but we already sold the device, so it's someone else's problem. Now if they were paying us a subscription fee..
riedel•33m ago
This quote on risk seems to completely misunderstand the concept of risk. First we have a vulnerability ( IMHO that is equals a hazard), then we assign both impact and probability and only then we get risk. By definition there are IMHO always vulnerabilities with low impact or low probability and thus low risk. While CVEs have some score, the actual risk and later accepting those risks before or after mitigations is up to the use case to define. No risk => no vulnerability is flawed reasoning by design. No vulnerability => no risk, I think is the only thing we can agree on.

Show HN: Idea-to-build – a Claude brainstorm that pushes back, then builds

https://github.com/winchxyz/idea-to-build
1•winchxyz•1m ago•0 comments

Functional Programming

https://mlochbaum.github.io/BQN/doc/functional.html
1•tosh•3m ago•0 comments

Building for Voice In, Visuals Out

https://allenpike.com/2026/voice-in-visuals-out/
1•surprisetalk•3m ago•0 comments

Tech-favored candidates fell short on California's primary night

https://www.politico.com/news/2026/06/03/tech-favored-candidates-fell-short-on-californias-primar...
1•RickJWagner•3m ago•0 comments

Why Nature Magazine Has Joined TikTok

https://www.nature.com/articles/d41586-026-01723-1
1•bookofjoe•6m ago•0 comments

SpaceX is worth less than half of its $1.75T IPO target, Morningstar says

https://www.cnbc.com/2026/06/03/morningstar-spacex-ipo-target-price-nasdaq.html
4•1vuio0pswjnm7•7m ago•0 comments

Show HN: RNKFlow I wanted HN but live like Digg, it became something much bigger

https://rnkflow.com/
1•JCSlim•9m ago•1 comments

Goldman Sachs CEO says markets in 'greed' mode as AI companies seek billions

https://www.cnbc.com/2026/06/02/goldman-ceo-david-solomon-greed-mode-ai-firms-ipos.html
1•1vuio0pswjnm7•9m ago•0 comments

Introducing Search Generative AI Performance Reports in Google Search Console

https://developers.google.com/search/blog/2026/06/gen-ai-performance-reports
1•thm•12m ago•0 comments

Show HN: VNN – AI news aggregator that verifies every source live

https://vnn.valyrian.tech
1•WouterGlorieux•13m ago•0 comments

Show HN: A self-growing wiki of Andrej Karpathy's public work

https://andrej-karpathy.com/
1•vasa_•14m ago•0 comments

Author

1•victorayomide•14m ago•0 comments

The interface for AI hasn't been invented yet

https://adaptivesoftware.substack.com/p/the-interface-for-ai-hasnt-been-invented
1•iristenteije•14m ago•0 comments

Zero Evidence of AI-Related Job Losses

https://www.apollo.com/wealth/the-daily-spark/zero-evidence-of-ai-related-job-losses
2•RickJWagner•14m ago•0 comments

The sorry state of skill distribution

https://blog.trailofbits.com/2026/06/03/the-sorry-state-of-skill-distribution/
2•ingve•15m ago•0 comments

An interactive map of all of English Wikipedia

https://tobypenner.com/wikigraph/
1•tfpgh•16m ago•0 comments

C++ Special Member Function Guidelines

https://www.foonathan.net/special-member-chart/
1•klaussilveira•16m ago•0 comments

Windsurf is now Devin Desktop

https://devin.ai/blog/windsurf-is-now-devin-desktop/
2•chaz6•17m ago•0 comments

Half a Month of Consolation Writing Advice

https://www.astralcodexten.com/p/half-a-month-of-consolation-writing
1•surprisetalk•18m ago•0 comments

AI Workflows Need Topological Sort

https://arpitbhayani.me/blogs/ai-topological-sort/
1•saikrishnanair•19m ago•1 comments

Show HN: AI Council Toolkit – open-source playbook for AI governance

https://www.aicounciltoolkit.com/
1•RickCraig•19m ago•0 comments

Show HN: A pizza configurator that re-adapts when you change your mind

https://wanderer-flow.de/flows/The-Time-Traveling-Pizza-Configurator-5qdvtptcn0bacbmu9jxbq3kvseua...
1•steampixel•23m ago•0 comments

To Mock a Mockingbird

https://en.wikipedia.org/wiki/To_Mock_a_Mockingbird
1•tosh•24m ago•0 comments

Top AI labs expand research into machine 'consciousness'

https://www.ft.com/content/53e14bcc-788c-4959-b260-7aee363594bc
1•1vuio0pswjnm7•24m ago•0 comments

Why Use Google?

https://bsky.app/profile/annierau.bsky.social/post/3mmx7hsaxw227
1•shaunpud•27m ago•0 comments

KNN early termination in Manticore Search

https://manticoresearch.com/blog/knn-early-termination/
1•snikolaev•27m ago•0 comments

Did Claude Opus 4.8 distill Alibaba's Qwen? Here's what the evidence says

https://blog.kilo.ai/p/did-claude-opus-48-distill-alibabas
8•heymax054•28m ago•4 comments

Light Cone Consistency: I'll Take One Scoop of Each

https://swytchbv.substack.com/p/light-cone-consistency-ill-take-one
1•withinboredom•28m ago•0 comments

Study finds AI chatbots frequently miss possible diagnoses

https://www.nbcboston.com/news/local/study-finds-ai-chatbots-frequently-miss-possible-diagnoses/3...
1•1vuio0pswjnm7•29m ago•0 comments

Case report: transient return of speech in dementia patient after 5G psilocybin

https://psychedelics.co.uk/news/an-80-year-old-woman-with-advanced-alzheimers
3•voisin•29m ago•0 comments