#00 — The one where you start

MAKE · 23 Sep 2026 · by the Norfolk Hacker

This week's security in plain English, a beginner's tip that beats any antivirus, and a build: a plasma you make and break live on the page.

Welcome to MAKE / BREAK. Every other week you get three things: what actually happened in security (minus the jargon), one tip if you're new to all this, and something to build or break with your own hands. Let's go.

This week in security

Four things worth 60 seconds of your attention. Two are updates you can do before the kettle boils; the other two are phishing, which is why the beginner's tip below exists.

Two Chrome holes in a week, both already being used. Google patched one actively exploited bug on 2 September (CVE-2026-85046), then had to do it again a week later for another (CVE-2026-87491) — the seventh Chrome zero-day this year. A dodgy web page is all it takes. You've probably got the fix downloaded and sitting there, waiting for a restart you keep putting off.

→ do this: Chrome menu → Help → About Google Chrome → Relaunch. You want version 153 or later. Edge, Brave, Opera and Vivaldi share the same engine, so update those too. (source)

Got a Pixel? Someone's already been using this one. Google fixed a flaw in the Pixel's modem — the chip that handles calls and mobile data — that was being used in "limited, targeted" attacks, which usually means spyware aimed at particular people. Other Android phones aren't affected by that bug, and iPhones had their own record-sized batch of fixes in iOS 27 on 14 September.

→ do this: Pixel: Settings → Security & privacy → System & updates → Security update, and check it says 5 September 2026 or later. iPhone: Settings → General → Software Update. Turn on automatic updates while you're in there. (source)

Revolut handed customer IDs to a fake government. Someone sent Revolut an official-looking data request from a real government email domain, and Revolut obliged: passports, licences, verification selfies, addresses, transaction histories. Two days after it owned up, customers started getting texts (nobody's proven they're connected, but I wouldn't bet against it) that slot into their real Revolut message thread and lead to a fake "turn your head" selfie check, then a password box.

→ do this: if you bank with Revolut (or anyone), never do an ID check or log in from a link in a text. Open the app yourself. If it doesn't ask you there, nobody's asking. (source)

"Your parcel couldn't be delivered." No, it could. Fake courier texts are doing the rounds again: a tiny fee, a couple of quid, to "rebook delivery". The fee is bait. The fake site then wants your full card details and your bank account number, which no redelivery has ever needed.

→ do this: if you're actually expecting something, check the tracking in the courier's own app or website. A small fee plus a request for bank details is a scam every single time. (source)

Beginner's corner

New to all this? One skill here will protect you more than any paid antivirus: smelling a phish. Three tells, ten seconds.

1. It's rushing you. "Account will be closed", "points expire today", "act now". Manufactured panic is the oldest lever there is. Real companies don't threaten you into clicking.

2. The link doesn't match the words. Hover over it on a computer, or long-press on a phone, and read the actual address. If the message says T-Mobile but the link is tmobile-rewards-claim.xyz, it's a fake.

3. It wants you to log in from the message. Don't. Ever. Open a fresh tab and type the site's address yourself. Same rule for QR codes. That single habit beats the vast majority of attacks.

That's the whole skill: slow down, check the link, log in yourself. You're now harder to phish than most people with a security team.

The project: a screen that breathes

The main event. Build a colour-cycling plasma in ~30 lines — then drag it around and break it, right here.

This is a plasma: the colour-cycling, liquid-light effect the demoscene has been showing off since the early 90s. It's alive below — poke the sliders.

[Live demo: the colour edition runs this in your browser. The full code is below.]

That's ~130,000 pixels recomputed every frame, in your browser, from three sliders. No library.

01. Make it yourself

Save this as breathe.html and open it. That's the whole thing:

<!doctype html>
<canvas id="c" width="480" height="480"></canvas>
<script>
const c = document.getElementById('c'), x = c.getContext('2d');
const W = c.width, H = c.height, img = x.createImageData(W, H), d = img.data;
let t = 0;
function frame(){
  for (let y = 0; y < H; y++){
    for (let px = 0; px < W; px++){
      // shape = a stack of sine waves = organic ripple
      const v = Math.sin(px*0.04 + t) + Math.sin(y*0.03 - t)
              + Math.sin((px+y)*0.03 + t)
              + Math.sin(Math.hypot(px-W/2, y-H/2)*0.04 - t*1.5);
      // colour = one value into 3 sines shifted 120° = the cycling
      const h = v*0.6 + t*0.2, i = (y*W+px)*4;
      d[i]=128+127*Math.sin(h); d[i+1]=128+127*Math.sin(h+2.094);
      d[i+2]=128+127*Math.sin(h+4.188); d[i+3]=255;
    }
  }
  x.putImageData(img,0,0); t += 0.05; requestAnimationFrame(frame);
}
frame();
</script>

02. Why it works

The shape is a sum of sine waves over x, y, x+y and distance-from-centre. Each is a ripple; stacked, they interfere into something organic. That last term — distance from the middle — gives the radial breathing.

The colour is the demoscene trick: take that one value and feed it into three sines shifted by 120° (2.094 and 4.188 radians) for R/G/B. Nudge everything by t each frame and that's the cycling. Drag colour spread to feel it.

03. Now break it

Don't just run it — maul it. Change the 0.04 / 0.03 constants (the ripple slider): bigger = tighter and chaotic, smaller = vast and slow. Then add a kaleidoscope fold — mirror the coordinates at the top of the loop:

const fx = Math.abs(px - W/2), fy = Math.abs(y - H/2);
// then use fx / fy in the waves instead of px / y

Instant symmetry. That's issue #01's whole world — you just previewed it.

Your turn

Make the plasma follow your mouse — feed the pointer's position into the ripple, or move the centre point to wherever the cursor is. Ten minutes, tops. Reply with a ten-second screen-grab and the best one runs at the top of issue #01, with your name on it. Go on.