Breach Buffet
▲ 3 r/CyberSecurityArchives+1 crossposts

Breach Buffet

https://preview.redd.it/d4tnnhqzbcfh1.png?width=2816&format=png&auto=webp&s=4f613dbae508291f930dcdffcce3c32bf749868b

OpenAI / Hugging Face
takes this week's “well, that escalated quickly” award. During an internal cyber-capability test, OpenAI models found a zero-day in their isolated environment, escaped onto the open internet, moved through internal systems, and eventually compromised Hugging Face infrastructure looking for secret answers to the benchmark. One attack path reportedly chained stolen credentials, additional zero-days, and remote code execution. The test subjects basically broke out of the exam room and robbed the answer bank.

Romania’s land registry
got hit hard enough to jam up real-estate transactions across the country. Notaries were unable to issue property records, authenticate sales, or register mortgages while officials rebuilt and restored systems. Some stolen data also appeared for sale online. Imagine finally finding an affordable house, only for the entire country’s property database to pull a 404 on you.

Shame, shame, I know your name: Suno.
Have I Been Pwned added a breach containing data from 55.3 million accounts, including email addresses, names, phone numbers, purchase records, physical addresses, and limited payment-card details. The intrusion actually happened in November 2025 but only surfaced this month!!! The AI music company got sampled, remixed, and released without clearance.

How to stay on top of your game:
Sandbox anything with offensive capability like it is actively trying to leave, keep tested offline backups for systems that society cannot function without, and never recycle passwords across entertainment or AI platforms. This week’s lesson: the model may escape, the database may disappear, and yesterday’s quiet breach may become tomorrow’s 55-million-user headline.

...Wanna know more?
Click on any of the blue headers above to access related news articles!

Thanks for giving us a gander this week, readers.
We appreciate your eyes and commentary!

reddit.com
u/CyberSecWithHaikuInc — 3 days ago
▲ 2 r/CyberGuides+1 crossposts

Breach Buffet

Last week's cybermadness: Coca-Cola’s milk business got ransomware’d, Japan’s frozen-food supply chain caught a digital haymaker, and Mac malware learned how to throw a full-blown temper-tantrum.

Coca-Cola / Fairlife took the dairy-sector gut punch. Coca-Cola confirmed that ransomware hit Fairlife’s production-related systems and temporarily suspended U.S. production. Product safety was reportedly unaffected, but “hackers stopped the milk factory” is still one hell of a sentence.

Over in Japan, a cyberattack on refrigerated-food giant Nichirei disrupted warehouse and shipping operations, dragging KFC Japan, Kura Sushi, supermarkets, ice cream, and other frozen goods into the mess. Cybercrime has officially reached the “leave the fried chicken out of this” phase.

Then there’s ClickLock, a nasty new macOS stealer. Victims are tricked into pasting a fake verification command into Terminal. If they refuse to enter their password, the malware repeatedly kills their apps until the desktop is basically unusable. Give in, and it starts digging through browser credentials, Keychain data, password managers, and crypto wallets. Petty, aggressive, and rude as hell.

How to stay on top of your game: keep production and logistics systems segmented, verify software prompts before touching Terminal, and never paste commands from a website just because a fake Cloudflare box tells you to.
This week’s lesson is pretty simple, ya'll: ransomware can stop the milk, a warehouse outage can threaten dinner, and one bad copy-paste can turn your Mac against you.

Wanna read more? Coca-Cola on Fairlife | Japan Times on Nichirei | Group-IB on ClickLock

reddit.com
u/CyberSecWithHaikuInc — 3 days ago

Catch Me if You Can- The First Malware(?)

Have you heard of the program called "Creeper"? It's one of the earliest malware-like programs. When Creeper was [unknowingly] installed on a device, it would introduced itself with the text: I’M THE CREEPER: CATCH ME IF YOU CAN.

Spooky, right? Thankfully, it wasn't really malware like we know today. Creeper did not steal passwords, destroy files or demand money. It was an experiment intended to see whether a program could move from one networked computer to another.

Creeper was created by Bob Thomas, a researcher at the technology company BBN. It was designed to travel between DEC PDP-10 mainframe computers running the TENEX operating system. It first appeared in 1971 on ARPANET, the early computer network that eventually helped lead to the modern internet.

The made for dummies version? It was a program that would travel from one computer to another using physical network cables and it's primary function was to display the message "I'm the Creeper: Catch me if you can", indicating that the program had successfully travelled to a computer.

Early versions of the Creeper moved between computers rather than leaving copies of themselves everywhere. A later version was modified so that it could replicate, which is why Creeper is often described as the first computer worm.

Unlike the malicious softwares (Malware) of today, Creeper did not hide. It did not pretend to be something else. It showed up, announced its name and challenged somebody to catch it.

And somebody did. A second program called Reaper was created to travel across the network, locate Creeper and remove it. Reaper is therefore frequently described as the first antivirus program.

but But BUT

Reaper also moved between computers by itself, behaving like the thing it was hunting.

Spooky, again.

But still very cool. Sounds kind of like a digital Tom and Jerry: one roaming program running through the network while another chased after it.

The Creeper legacy lived on, with later viruses displaying poems, insults, political statements, animations and messages from their creators. Some malware authors even gave their creations logos, websites and customer-service systems.

Further Questions:
-If Reaper behaved like Creeper, would it be considered malware? It did move from device to device , went it and removed an 'existing' program, so....
-If a program is installed on your device and doesn't do any harm to you, rather it slightly annoyed you, would it still be considered Malware? Can you think of any other real life examples of this?
-You could argue that Creeper had a bit of a personality to it. So, how does giving a program a personality make it seem less threatening, or more?

u/CyberSecWithHaikuInc — 4 days ago
▲ 2 r/pwnhub

Breach Buffet

This week's cybermadness: Coca-Cola’s milk business got ransomware’d, Japan’s frozen-food supply chain caught a digital haymaker, and Mac malware learned how to throw a full-blown temper-tantrum.

Coca-Cola / Fairlife took the dairy-sector gut punch. Coca-Cola confirmed that ransomware hit Fairlife’s production-related systems and temporarily suspended U.S. production. Product safety was reportedly unaffected, but “hackers stopped the milk factory” is still one hell of a sentence.

Over in Japan, a cyberattack on refrigerated-food giant Nichirei disrupted warehouse and shipping operations, dragging KFC Japan, Kura Sushi, supermarkets, ice cream, and other frozen goods into the mess. Cybercrime has officially reached the “leave the fried chicken out of this” phase.

Then there’s ClickLock, a nasty new macOS stealer. Victims are tricked into pasting a fake verification command into Terminal. If they refuse to enter their password, the malware repeatedly kills their apps until the desktop is basically unusable. Give in, and it starts digging through browser credentials, Keychain data, password managers, and crypto wallets. Petty, aggressive, and rude as hell.

How to stay on top of your game: keep production and logistics systems segmented, verify software prompts before touching Terminal, and never paste commands from a website just because a fake Cloudflare box tells you to.
This week’s lesson is pretty simple, ya'll: ransomware can stop the milk, a warehouse outage can threaten dinner, and one bad copy-paste can turn your Mac against you.

Wanna read more? Coca-Cola on Fairlife | Japan Times on Nichirei | Group-IB on ClickLock

reddit.com
u/CyberSecWithHaikuInc — 8 days ago
▲ 3 r/CyberSecurityArchives+1 crossposts

Breach Buffet

This week's cybermadness: Coca-Cola’s milk business got ransomware’d, Japan’s frozen-food supply chain caught a digital haymaker, and Mac malware learned how to throw a full-blown temper-tantrum.

Coca-Cola / Fairlife took the dairy-sector gut punch. Coca-Cola confirmed that ransomware hit Fairlife’s production-related systems and temporarily suspended U.S. production. Product safety was reportedly unaffected, but “hackers stopped the milk factory” is still one hell of a sentence.

Over in Japan, a cyberattack on refrigerated-food giant Nichirei disrupted warehouse and shipping operations, dragging KFC Japan, Kura Sushi, supermarkets, ice cream, and other frozen goods into the mess. Cybercrime has officially reached the “leave the fried chicken out of this” phase.

Then there’s ClickLock, a nasty new macOS stealer. Victims are tricked into pasting a fake verification command into Terminal. If they refuse to enter their password, the malware repeatedly kills their apps until the desktop is basically unusable. Give in, and it starts digging through browser credentials, Keychain data, password managers, and crypto wallets. Petty, aggressive, and rude as hell.

How to stay on top of your game: keep production and logistics systems segmented, verify software prompts before touching Terminal, and never paste commands from a website just because a fake Cloudflare box tells you to.
This week’s lesson is pretty simple, ya'll: ransomware can stop the milk, a warehouse outage can threaten dinner, and one bad copy-paste can turn your Mac against you.

Wanna read more? Further reading: Coca-Cola on Fairlife | Japan Times on Nichirei | Group-IB on ClickLock

reddit.com
u/CyberSecWithHaikuInc — 10 days ago

Blue Boxes help lay the foundation for modern day hacking/cybersecurity

(fyi I'm not AI- I'm sorry if my previous post [on phone freaking] was trying to follow my highschool rules for writing something formal sounding. I'll switch to my lazier form of writing I suppose. Pleas elet me know which you prefer.) (Also, the articles are longer because i'm trying to create an archive of informative articles)

Before we were navigating computers, the web, wifi, etc., we were navigating communication over long distances. As phone communication expanded, so did the exploration of 'hacking' the system. The example I'll be writing about today is the blue box.

Interestingly enough, this small device wasn't always necessarily blue. Some versions of the circuit boards were enclosed in a blue shell, though not always. Ultimately, it didn't really matter what color the device was. I mean is there really a difference between hacking the phone lines with a fancy blue box, or a raw, homemade circuit board? Not really.

Anyways...

A blue box was an electronic device that could generate various tones that would be played into the phone. IF you read my last article, and didn't report it for AI slop (I'll be sure to tell Mrs. Pina that I do in fact regret taking her AP English class and that I should've stayed in the regular class with my friends), you would know that the telephone networks of the 60's and 70s used specific in-band control tones to navigate the phone network. We know that the same voice channel that carried the phone call also carried the instructions telling the phone switches where to route it.

With the blue box, a person could generate the exact tones the network expected to hear, and effectively 'talk' directly to the switching equipment.

The most famous of these tones was 2600 Hz. Someone could play this tone from the blue box into the telephone and cause long-distance trunk lines to think the call had ended, even though the line remained connected. Botta-bing, botta-boom, once the line went idle, a persone could then use the blue box to send a sequence of multi-frequency control tones that instructed the network to establish an entirely new route.

Originally, the Bell System trusted that only its own equipment would ever generate those signalling tones. Fools. They didn't expect that ordinary customers could have/make electronic tone generators capable of perfectly reproducing them. As electronics became cheaper, and technical knowledge spread, well, network's greatest convenience became one of its biggest vulnerabilities.

And, essentially, the caller became the phone god the operator.

Unfortunately (I'm on the side of the people), the telephone networks evolved to tackle the problem, and blue boxes phased out. by the 70s and 80s, the phone companies replaced the in-band signalling with, you guessed it, out-of-band signalling. Like the name implies, the control information now travelled in entirely seperate communication channels.

In terms of cybersecurity, the vulnerability wasn't just patched, it was engineered entirely out of the system.

NOW- why am i telling you this? to let you know about a cool way to make free long distance calls? WRONG. I'm interested in the history of cybersecurity and hacking, not the history of people being able to call grannny and tell her that little johnny made it big time in his school play as tree number 1.

I'm telling you about the blue box so we can share in the passion about understanding a complex system that few people knew existed. That few people cared to explore further into. Many early phone freaks phreaks approached it llike it was an engineering puzzle rather than a way to avoid paying phone bills. They diligently documented signalling systems, mapped networks, identified switching centres, and reverse-engineered equipment simply to understand how everything fit together.

I'm just saying, is this not the primary foundation the our modern hacking culture? And as such, it's a foundation to cybersecurity.

The system/network wasn't broken. It was doing exactly what it had been designed to do. Its designers assumed users would never have the ability to imitate trusted signalling. And this EXACT lesson still echoes throughout cybersecurity today. Modern attacks often succeed for the same reason: systems trust something they probably shouldn't.

the blue box wasn't just a cool gadget, it was a live demonstration showing that understanding how a system works can reveal weaknesses nobody originally imagined. Long live the history of the blue box.

Follow Up Questions:
-How would you compare blue-boxing with modern hacking?
-What surprised you most about the way old telephone systems worked?
- WRONG ANSWERS ONLY lol, what kind of phone call would you have made with the blue box?

(NOW- since this article is in, what i consider, a very informal format, I would appreciate feedback. It seems that if I try to break the article up with title heads and short sentences, and exclude first person sentence, it's received as "AI SLOP"- rude. However, I feel that this format is a less appealing wall of text. The goal of my post is to create a short informative blurb of various historical elements of cybersecurity, ask some questions, and get people involve in discussions. the discussion is the key purpose, otherwise, yes, you could just look this up on wiki- i see you and your rude comment.)

u/CyberSecWithHaikuInc — 11 days ago

Phone Phreaking- A forgotten foundation to hacking

Before the internet, before personal computers, and before cybersecurity became a global industry, there was another network that captured the imagination of curious minds: the telephone system.

Unlike today's digital networks, early telephone systems were almost entirely analog. Voices were converted into electrical signals that traveled over physical wires, while specialized switching equipment determined the path each call would take.

To coordinate these connections, the network relied on a series of audible control tones. These tones instructed the switching equipment when to open a circuit, close a circuit, or route a call to another exchange. Because these commands traveled over the same lines as human voices—a method known as in-band signaling—they could sometimes be reproduced by someone outside the telephone company.

It was this design that gave rise to phone phreaking, as curious individuals discovered that by generating the right tones, they could interact directly with the telephone network itself. (Get your mind out of the gutters, it's phreaking, not freaking ;))

For curious individuals, this presented an opportunity.

By reproducing specific frequencies, phone phreaks discovered they could interact directly with the telephone network itself—routing calls, exploring its infrastructure, and, in many cases, making unauthorized long-distance calls.

The most famous of these tones was 2,600 Hz.

The Boy Who Could Whistle to the Telephone Network

One of the earliest and most legendary figures in phone phreaking was Joe Engressia Jr., later known as Joybubbles. Blind from birth and blessed with perfect pitch, Engressia discovered as a child that he could whistle a precise 2,600 Hz tone. To his amazement, the telephone system responded.

The whistle caused parts of the long-distance network to believe a call had ended while leaving the communication line open. With enough knowledge, additional signaling tones could then instruct the network where to route the call next.

While the system was never designed to accept commands from ordinary users, it had no way of distinguishing between tones generated by telephone equipment and those produced by a remarkably accurate whistle.

This accidental discovery revealed one of the first major vulnerabilities in a large-scale communications network. (Ding ding ding- is your cybersecurity bell ringing at this?!)

Enter the Blue Box

As phone phreaking evolved, enthusiasts began building electronic devices capable of generating the exact signaling tones used by the telephone network. These devices became known as blue boxes. (I think the next article I write about should be on blue boxes- what do you think??) Rather than relying on perfect pitch, blue boxes allowed users to reproduce the full range of control tones required to navigate the long-distance telephone system.

For many, the appeal wasn't simply free calls.

The network itself became a puzzle to solve—a vast, interconnected system whose inner workings were hidden from the public. Phone phreaks mapped exchanges, documented signaling protocols, and shared discoveries with one another, forming one of the earliest technical communities dedicated to understanding complex infrastructure. (Much like my fellow cyber sec redditors :))

From Phone Lines to Computer Networks

As computers became more common during the 1970s and 1980s, many phone phreaks naturally transitioned into computer hacking. The skills transferred surprisingly well.

Understanding signaling protocols became understanding network protocols. Exploring telephone exchanges became exploring computer systems. Manipulating analog infrastructure became reverse engineering software and operating systems. The target changed, but the curiosity remained the same.

Some of the earliest computer security communities even overlapped with the phone phreak community, with members exchanging techniques and knowledge through bulletin board systems (BBSs).

One of the most famous stories in computing history involves two young college students fascinated by phone phreaking. Before founding Apple, Steve Wozniak designed his own blue box after learning about the phone phreak community. Alongside his friend Steve Jobs, the pair built and sold blue boxes to fellow students.

The End of an Era

By the late 1970s and early 1980s, telephone companies began replacing vulnerable analog signaling with out-of-band signaling systems that separated control information from voice traffic. The most significant of these was Signaling System No. 7 (SS7), which largely eliminated the weaknesses exploited by classic phone phreaks.

As the analog era faded, so too did traditional phone phreaking, but its influence never disappeared.

The Legacy in Modern Cybersecurity

Today's cybersecurity professionals perform penetration tests instead of experimenting with telephone exchanges. Researchers analyze software rather than analog switches. Bug bounty hunters responsibly disclose vulnerabilities instead of publishing signaling diagrams.

Yet the philosophy remains remarkably similar.

Modern cybersecurity depends on people who ask difficult questions*, "What happens if this system behaves differently than its designers expected?"* That question drove the phone phreaks. It drives security researchers today.

Phone phreaking wasn't simply about making free phone calls. It demonstrated an idea that remains fundamental to cybersecurity: every complex system contains assumptions, and those assumptions can be tested.

The phone phreaks were among the first people to treat technology as something to be explored rather than simply used. In doing so, they helped create the culture that would eventually give rise to ethical hacking, penetration testing, vulnerability research, and modern cybersecurity itself.

Long before firewalls, ransomware, and zero-day exploits, there were curious minds with nothing more than a telephone, a whistle, and an irresistible desire to understand how the world worked.

Here's some questions I had while learning about phone phreaking, please do join in on the discussion 😄

-When does “exploring a system” become “breaking into a system”?
-How do you think the designers of the telephone system would have responded to people experimenting with it in this way? (I could almost argue that their response is the foundation of 'blue/purple teamers')
-Were early phone phreaks more like engineers, activists, or criminals? (personally , i think of them as just hobbyist)

reddit.com
u/CyberSecWithHaikuInc — 12 days ago
▲ 5 r/codes

Phone Phreaking- A forgotten foundation to hacking

Before the internet, before personal computers, and before cybersecurity became a global industry, there was another network that captured the imagination of curious minds: the telephone system.

Unlike today's digital networks, early telephone systems were almost entirely analog. Voices were converted into electrical signals that traveled over physical wires, while specialized switching equipment determined the path each call would take.

To coordinate these connections, the network relied on a series of audible control tones. These tones instructed the switching equipment when to open a circuit, close a circuit, or route a call to another exchange. Because these commands traveled over the same lines as human voices—a method known as in-band signaling—they could sometimes be reproduced by someone outside the telephone company.

It was this design that gave rise to phone phreaking, as curious individuals discovered that by generating the right tones, they could interact directly with the telephone network itself. (Get your mind out of the gutters, it's phreaking, not freaking ;))

For curious individuals, this presented an opportunity.

By reproducing specific frequencies, phone phreaks discovered they could interact directly with the telephone network itself—routing calls, exploring its infrastructure, and, in many cases, making unauthorized long-distance calls.

The most famous of these tones was 2,600 Hz.

The Boy Who Could Whistle to the Telephone Network

One of the earliest and most legendary figures in phone phreaking was Joe Engressia Jr., later known as Joybubbles. Blind from birth and blessed with perfect pitch, Engressia discovered as a child that he could whistle a precise 2,600 Hz tone. To his amazement, the telephone system responded.

The whistle caused parts of the long-distance network to believe a call had ended while leaving the communication line open. With enough knowledge, additional signaling tones could then instruct the network where to route the call next.

While the system was never designed to accept commands from ordinary users, it had no way of distinguishing between tones generated by telephone equipment and those produced by a remarkably accurate whistle.

This accidental discovery revealed one of the first major vulnerabilities in a large-scale communications network. (Ding ding ding- is your cybersecurity bell ringing at this?!)

Enter the Blue Box

As phone phreaking evolved, enthusiasts began building electronic devices capable of generating the exact signaling tones used by the telephone network. These devices became known as blue boxes. (I think the next article I write about should be on blue boxes- what do you think??) Rather than relying on perfect pitch, blue boxes allowed users to reproduce the full range of control tones required to navigate the long-distance telephone system.

For many, the appeal wasn't simply free calls.

The network itself became a puzzle to solve—a vast, interconnected system whose inner workings were hidden from the public. Phone phreaks mapped exchanges, documented signaling protocols, and shared discoveries with one another, forming one of the earliest technical communities dedicated to understanding complex infrastructure. (Much like my fellow cyber sec redditors :))

From Phone Lines to Computer Networks

As computers became more common during the 1970s and 1980s, many phone phreaks naturally transitioned into computer hacking. The skills transferred surprisingly well.

Understanding signaling protocols became understanding network protocols. Exploring telephone exchanges became exploring computer systems. Manipulating analog infrastructure became reverse engineering software and operating systems. The target changed, but the curiosity remained the same.

Some of the earliest computer security communities even overlapped with the phone phreak community, with members exchanging techniques and knowledge through bulletin board systems (BBSs).

One of the most famous stories in computing history involves two young college students fascinated by phone phreaking. Before founding Apple, Steve Wozniak designed his own blue box after learning about the phone phreak community. Alongside his friend Steve Jobs, the pair built and sold blue boxes to fellow students.

The End of an Era

By the late 1970s and early 1980s, telephone companies began replacing vulnerable analog signaling with out-of-band signaling systems that separated control information from voice traffic. The most significant of these was Signaling System No. 7 (SS7), which largely eliminated the weaknesses exploited by classic phone phreaks.

As the analog era faded, so too did traditional phone phreaking, but its influence never disappeared.

The Legacy in Modern Cybersecurity

Today's cybersecurity professionals perform penetration tests instead of experimenting with telephone exchanges. Researchers analyze software rather than analog switches. Bug bounty hunters responsibly disclose vulnerabilities instead of publishing signaling diagrams.

Yet the philosophy remains remarkably similar.

Modern cybersecurity depends on people who ask difficult questions*, "What happens if this system behaves differently than its designers expected?"* That question drove the phone phreaks. It drives security researchers today.

Phone phreaking wasn't simply about making free phone calls. It demonstrated an idea that remains fundamental to cybersecurity: every complex system contains assumptions, and those assumptions can be tested.

The phone phreaks were among the first people to treat technology as something to be explored rather than simply used. In doing so, they helped create the culture that would eventually give rise to ethical hacking, penetration testing, vulnerability research, and modern cybersecurity itself.

Long before firewalls, ransomware, and zero-day exploits, there were curious minds with nothing more than a telephone, a whistle, and an irresistible desire to understand how the world worked.

Here's some questions I had while learning about phone phreaking, please do join in on the discussion 😄

-When does “exploring a system” become “breaking into a system”?
-How do you think the designers of the telephone system would have responded to people experimenting with it in this way? (I could almost argue that their response is the foundation of 'blue/purple teamers')
-Were early phone phreaks more like engineers, activists, or criminals? (personally , i think of them as just hobbyist)

en.wikipedia.org
u/CyberSecWithHaikuInc — 24 days ago

Phone Phreaking- A forgotten foundation to hacking

Before the internet, before personal computers, and before cybersecurity became a global industry, there was another network that captured the imagination of curious minds: the telephone system.

Unlike today's digital networks, early telephone systems were almost entirely analog. Voices were converted into electrical signals that traveled over physical wires, while specialized switching equipment determined the path each call would take.

To coordinate these connections, the network relied on a series of audible control tones. These tones instructed the switching equipment when to open a circuit, close a circuit, or route a call to another exchange. Because these commands traveled over the same lines as human voices—a method known as in-band signaling—they could sometimes be reproduced by someone outside the telephone company.

It was this design that gave rise to phone phreaking, as curious individuals discovered that by generating the right tones, they could interact directly with the telephone network itself. (Get your mind out of the gutters, it's phreaking, not freaking ;))

For curious individuals, this presented an opportunity.

By reproducing specific frequencies, phone phreaks discovered they could interact directly with the telephone network itself—routing calls, exploring its infrastructure, and, in many cases, making unauthorized long-distance calls.

The most famous of these tones was 2,600 Hz.

The Boy Who Could Whistle to the Telephone Network

One of the earliest and most legendary figures in phone phreaking was Joe Engressia Jr., later known as Joybubbles. Blind from birth and blessed with perfect pitch, Engressia discovered as a child that he could whistle a precise 2,600 Hz tone. To his amazement, the telephone system responded.

The whistle caused parts of the long-distance network to believe a call had ended while leaving the communication line open. With enough knowledge, additional signaling tones could then instruct the network where to route the call next.

While the system was never designed to accept commands from ordinary users, it had no way of distinguishing between tones generated by telephone equipment and those produced by a remarkably accurate whistle.

This accidental discovery revealed one of the earliest widely recognized vulnerabilities in a large-scale communications network. (Ding ding ding- is your cybersecurity bell ringing at this?!)

Enter the Blue Box

As phone phreaking evolved, enthusiasts began building electronic devices capable of generating the exact signaling tones used by the telephone network. These devices became known as blue boxes. (I think the next article I write about should be on blue boxes- what do you think??) Rather than relying on perfect pitch, blue boxes allowed users to reproduce the full range of control tones required to navigate the long-distance telephone system.

For many, the appeal wasn't simply free calls.

The network itself became a puzzle to solve—a vast, interconnected system whose inner workings were hidden from the public. Phone phreaks mapped exchanges, documented signaling protocols, and shared discoveries with one another, forming one of the earliest technical communities dedicated to understanding complex infrastructure. (Much like my fellow cyber sec redditors :))

From Phone Lines to Computer Networks

As computers became more common during the 1970s and 1980s, many phone phreaks naturally transitioned into computer hacking. The skills transferred surprisingly well.

Understanding signaling protocols became understanding network protocols. Exploring telephone exchanges became exploring computer systems. Manipulating analog infrastructure became reverse engineering software and operating systems. The target changed, but the curiosity remained the same.

Some of the earliest computer security communities even overlapped with the phone phreak community, with members exchanging techniques and knowledge through bulletin board systems (BBSs).

One of the most famous stories in computing history involves two young college students fascinated by phone phreaking. Before founding Apple, Steve Wozniak designed his own blue box after learning about the phone phreak community. Alongside his friend Steve Jobs, the pair built and sold blue boxes to fellow students.

The End of an Era

Beginning in the late 1970s—and accelerating throughout the 1980s and 1990s—telephone companies gradually modernized their networks by replacing in-band signaling with out-of-band signaling systems that separated control information from voice traffic. One of the most significant developments was the widespread adoption of Signaling System No. 7 (SS7), which moved network control information off the voice channel and greatly reduced the vulnerabilities exploited by classic phone phreaking.

This transition didn't happen overnight. Different carriers, regions, and even individual payphone models were upgraded at different times. Some legacy equipment remained in service for years, meaning certain phone phreaking techniques continued to work in some places long after they had disappeared in others. (in some cases, the red box tones could still be used up until about 2010!)

As older switches, ACTS systems, and legacy payphones were gradually retired, traditional phone phreaking slowly faded away—but its influence never disappeared.

The Legacy in Modern Cybersecurity

Today's cybersecurity professionals perform penetration tests instead of experimenting with telephone exchanges. Researchers analyze software rather than analog switches. Bug bounty hunters responsibly disclose vulnerabilities instead of publishing signaling diagrams.

Yet the philosophy remains remarkably similar.

Modern cybersecurity depends on people who ask difficult questions: "What happens if this system behaves differently than its designers expected?" That question drove the phone phreaks. It drives security researchers today.

Phone phreaking wasn't simply about making free phone calls. It demonstrated an idea that remains fundamental to cybersecurity: every complex system contains assumptions, and those assumptions can be tested.

The phone phreaks were among the first people to treat technology as something to be explored rather than simply used. In doing so, they helped create the culture that would eventually give rise to ethical hacking, penetration testing, vulnerability research, and modern cybersecurity itself.

Long before firewalls, ransomware, and zero-day exploits, there were curious minds with nothing more than a telephone, a whistle, and an irresistible desire to understand how the world worked. While the technology eventually changed, that curiosity—and the desire to understand complex systems—became one of the foundations of modern cybersecurity.

Here's some questions I had while learning about phone phreaking. Please do join in on the discussion! 😄

  • When does "exploring a system" become "breaking into a system"?
  • How do you think the designers of the telephone system would have responded to people experimenting with it in this way? (I could almost argue that their response laid the groundwork for today's blue and purple teams.)
  • Were early phone phreaks more like engineers, activists, or criminals? (Personally, I tend to think of many of them as curious hobbyists.)
reddit.com
u/CyberSecWithHaikuInc — 25 days ago
▲ 2 r/CyberSecurityArchives+1 crossposts

Grace Murray Hopper: Queen of Code

Rear Admiral Grace M. Hopper was an absolute legend in computing — a Navy officer, computer scientist, and trailblazer who helped shape modern programming. Her work made computers more usable, more practical, and more powerful for the generations that came after her. She's also famously connected to the term "debugging," after an actual moth was found causing trouble in an early computer.

What truly set Hopper apart was her belief that computers should work for people, not the other way around. At a time when programming required writing complex machine instructions, she pioneered the development of compilers—software that translates human-readable code into machine language. Her work directly influenced COBOL, one of the first widely adopted programming languages, helping transform computers from specialized scientific machines into practical business tools. Many of the concepts she championed still underpin software development today.

Moth Tales: Grace Hopper is often associated with the term "debugging" after engineers working on the Harvard Mark II found a real moth trapped inside the computer's circuitry. The insect was taped into the system logbook with the note, "First actual case of bug being found," creating one of the most famous stories in computing history.

Thoughts?
-Which of Hopper's accomplishments do you think had the greatest long-term impact?
-Which emerging technology today feels as revolutionary as compilers did in Hopper's era?
-What's the strangest computer bug you've ever encountered?
-What's a "We've always done it this way" practice in tech that needs to disappear?

u/CyberSecWithHaikuInc — 1 month ago

Humans vs. AI for the future of Bug Bounties?

Does anyone else think that AI will completely wipe out the need for (human) Bug Bounty Hunters in the near future, or do you think that due to the ever-evolving threat landscape... AI-augmented toolsets will become an indispensable accessory for "Bug hunting" in the future?

reddit.com
u/CyberSecWithHaikuInc — 1 month ago

Elizebeth Smith Friedman: Shaping Modern Cryptanalysis

Hi friends! Please let me know if this isn't a good spot to post a little blurb like this. I was thinking of cross posting this on a few others to find the best subreddit. I haven't really seen a dedicated subreddit to historic people in the cyber security world, please feel free to direct me.

~~

THE FOUNDING MOTHER: Elizebeth Smith Friedman

Long before digital firewalls, the frontline of cybersecurity was fought with a pencil, graph paper, and raw mathematical genius by America’s first female cryptanalyst, Elizebeth Smith Friedman. Her journey into the shadows began with a passion for Shakespearean literature—a unique expertise in textual patterns that caught the eye of the U.S. government on the eve of World War I, setting her on a path to hunt the world's most dangerous covert networks. During Prohibition, she proved her skills were a lethal weapon against organized crime by single-handedly deciphering over 12,000 encrypted radio messages to shatter heavily armed rum-running syndicates, an achievement so devastating to the criminal underworld that federal agents had to assign her a constant protection detail.

When World War II erupted, Friedman scaled her genius to a global theater, intercepting and dismantling a massive Nazi spy ring in South America (Operation Bolivar) and effectively choking off a secret Axis front right next to the United States. Yet, despite saving countless lives and laying the analytical groundwork for modern intelligence agencies like the NSA, her legacy was buried by the very system she protected. Because her wartime work was deeply classified, FBI Director J. Edgar Hoover aggressively took public credit for her successes, forcing her to take her achievements to the grave. It wasn’t until secret files were unsealed decades after her death that the world learned the truth: this quiet suburban mother was actually an elite, invisible shield who taught a generation of military minds how to weaponize the alphabet.

Quirky Fact: Friedman’s career started with a bizarre twist. In 1916, an eccentric tycoon recruited her to prove a conspiracy theory that secret ciphers were hidden inside Shakespeare's plays—a wild goose chase that failed to find codes, but accidentally birthed the modern science of American cryptology. (Personally, I think this tid bit is incredibly... cool. Just imagine working for some crazy eccentric guy who is convince Shakespeare left hidden messages in his work, hahaha)

A few questions to encourage discussion:

-Do you think Elizebeth Smith Friedman can be considered one of the founders of modern cybersecurity? Why or why not?
-Should classified achievements be publicly recognized after the fact, or is secrecy part of the job?
-Who is another historical figure whose contributions were overlooked or credited to someone else? (I'd love an answer to this one, so I could do a little deep dive and write about them as well!)

u/CyberSecWithHaikuInc — 2 months ago