========================================================================
MAKE / BREAK issue #00
THE ONE WHERE YOU START
MAKE - 23 Sep 2026 - by the Norfolk Hacker
========================================================================
This week's security in plain English, a beginner's tip that beats any
antivirus, and a build: a plasma you make and break live on the page.
colour edition: https://makebreak.co.uk/issues/00.html
Welcome to MAKE / BREAK. Every other week you get three things: what
actually happened in security (minus the jargon), one tip if you're new
to all this, and something to build or break with your own hands. Let's
go.
------------------------------------------------------------------------
[ 1. THIS WEEK IN SECURITY ]
Four things worth 60 seconds of your attention. Two are updates you can
do before the kettle boils; the other two are phishing, which is why the
beginner's tip below exists.
* Two Chrome holes in a week, both already being used. Google patched
one actively exploited bug on 2 September (CVE-2026-85046), then had
to do it again a week later for another (CVE-2026-87491) -- the
seventh Chrome zero-day this year. A dodgy web page is all it takes.
You've probably got the fix downloaded and sitting there, waiting for
a restart you keep putting off.
-> do this: Chrome menu -> Help -> About Google Chrome -> Relaunch.
You want version 153 or later. Edge, Brave, Opera and Vivaldi share
the same engine, so update those too. (source) [1]
* Got a Pixel? Someone's already been using this one. Google fixed a
flaw in the Pixel's modem -- the chip that handles calls and mobile
data -- that was being used in "limited, targeted" attacks, which
usually means spyware aimed at particular people. Other Android
phones aren't affected by that bug, and iPhones had their own
record-sized batch of fixes in iOS 27 on 14 September.
-> do this: Pixel: Settings -> Security & privacy -> System & updates
-> Security update, and check it says 5 September 2026 or later.
iPhone: Settings -> General -> Software Update. Turn on automatic
updates while you're in there. (source) [2]
* Revolut handed customer IDs to a fake government. Someone sent
Revolut an official-looking data request from a real government email
domain, and Revolut obliged: passports, licences, verification
selfies, addresses, transaction histories. Two days after it owned
up, customers started getting texts (nobody's proven they're
connected, but I wouldn't bet against it) that slot into their real
Revolut message thread and lead to a fake "turn your head" selfie
check, then a password box.
-> do this: if you bank with Revolut (or anyone), never do an ID
check or log in from a link in a text. Open the app yourself. If it
doesn't ask you there, nobody's asking. (source) [3]
* "Your parcel couldn't be delivered." No, it could. Fake courier texts
are doing the rounds again: a tiny fee, a couple of quid, to "rebook
delivery". The fee is bait. The fake site then wants your full card
details and your bank account number, which no redelivery has ever
needed.
-> do this: if you're actually expecting something, check the
tracking in the courier's own app or website. A small fee plus a
request for bank details is a scam every single time. (source) [4]
------------------------------------------------------------------------
[ 2. BEGINNER'S CORNER ]
New to all this? One skill here will protect you more than any paid
antivirus: smelling a phish. Three tells, ten seconds.
* 1. It's rushing you. "Account will be closed", "points expire today",
"act now". Manufactured panic is the oldest lever there is. Real
companies don't threaten you into clicking.
* 2. The link doesn't match the words. Hover over it on a computer, or
long-press on a phone, and read the actual address. If the message
says T-Mobile but the link is tmobile-rewards-claim.xyz, it's a fake.
* 3. It wants you to log in from the message. Don't. Ever. Open a fresh
tab and type the site's address yourself. Same rule for QR codes.
That single habit beats the vast majority of attacks.
That's the whole skill: slow down, check the link, log in yourself.
You're now harder to phish than most people with a security team.
------------------------------------------------------------------------
[ 3. THE PROJECT ]
A SCREEN THAT BREATHES
The main event. Build a colour-cycling plasma in ~30 lines -- then drag
it around and break it, right here.
This is a plasma: the colour-cycling, liquid-light effect the demoscene
has been showing off since the early 90s. It's alive below -- poke the
sliders.
[ live demo: https://makebreak.co.uk/issues/00.html ]
That's ~130,000 pixels recomputed every frame, in your browser, from
three sliders. No library.
>> 01. Make it yourself
Save this as breathe.html and open it. That's the whole thing:
>> 02. Why it works
The shape is a sum of sine waves over x, y, x+y and
distance-from-centre. Each is a ripple; stacked, they interfere into
something organic. That last term -- distance from the middle -- gives
the radial breathing.
The colour is the demoscene trick: take that one value and feed it into
three sines shifted by 120 deg (2.094 and 4.188 radians) for R/G/B.
Nudge everything by t each frame and that's the cycling. Drag colour
spread to feel it.
>> 03. Now break it
Don't just run it -- maul it. Change the 0.04 / 0.03 constants (the
ripple slider): bigger = tighter and chaotic, smaller = vast and slow.
Then add a kaleidoscope fold -- mirror the coordinates at the top of the
loop:
const fx = Math.abs(px - W/2), fy = Math.abs(y - H/2);
// then use fx / fy in the waves instead of px / y
Instant symmetry. That's issue #01's whole world -- you just previewed
it.
------------------------------------------------------------------------
[ 4. YOUR TURN ]
* Make the plasma follow your mouse -- feed the pointer's position into
the ripple, or move the centre point to wherever the cursor is. Ten
minutes, tops. Reply with a ten-second screen-grab and the best one
runs at the top of issue #01, with your name on it. Go on.
------------------------------------------------------------------------
A new one every other week -- free, right here:
https://makebreak.co.uk/issues/
No paywall, no ads, no sponsor telling me what to say. If an issue
earned you a brew: https://buymeacoffee.com/androidacid
-- the Norfolk Hacker
next: #01 Fold the light
https://makebreak.co.uk/issues/01.txt
------------------------------------------------------------------------
LINKS
[1] https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html
[2] https://www.malwarebytes.com/blog/mobile/2026/09/google-pixel-owners-urged-to-patch-actively-exploited-modem-flaw
[3] https://www.malwarebytes.com/blog/threat-intel/2026/09/revolut-phishing-texts-appear-days-after-data-breach
[4] https://www.malwarebytes.com/blog/scams/2026/09/fake-parcel-delivery-messages-steal-your-card-and-bank-details
========================================================================