======================================================================== MAKE / BREAK issue #00 THE ONE WHERE YOU START MAKE - 23 Sep 2026 - by the Norfolk Hacker ======================================================================== This week's security in plain English, a beginner's tip that beats any antivirus, and a build: a plasma you make and break live on the page. colour edition: https://makebreak.co.uk/issues/00.html Welcome to MAKE / BREAK. Every other week you get three things: what actually happened in security (minus the jargon), one tip if you're new to all this, and something to build or break with your own hands. Let's go. ------------------------------------------------------------------------ [ 1. THIS WEEK IN SECURITY ] Four things worth 60 seconds of your attention. Two are updates you can do before the kettle boils; the other two are phishing, which is why the beginner's tip below exists. * Two Chrome holes in a week, both already being used. Google patched one actively exploited bug on 2 September (CVE-2026-85046), then had to do it again a week later for another (CVE-2026-87491) -- the seventh Chrome zero-day this year. A dodgy web page is all it takes. You've probably got the fix downloaded and sitting there, waiting for a restart you keep putting off. -> do this: Chrome menu -> Help -> About Google Chrome -> Relaunch. You want version 153 or later. Edge, Brave, Opera and Vivaldi share the same engine, so update those too. (source) [1] * Got a Pixel? Someone's already been using this one. Google fixed a flaw in the Pixel's modem -- the chip that handles calls and mobile data -- that was being used in "limited, targeted" attacks, which usually means spyware aimed at particular people. Other Android phones aren't affected by that bug, and iPhones had their own record-sized batch of fixes in iOS 27 on 14 September. -> do this: Pixel: Settings -> Security & privacy -> System & updates -> Security update, and check it says 5 September 2026 or later. iPhone: Settings -> General -> Software Update. Turn on automatic updates while you're in there. (source) [2] * Revolut handed customer IDs to a fake government. Someone sent Revolut an official-looking data request from a real government email domain, and Revolut obliged: passports, licences, verification selfies, addresses, transaction histories. Two days after it owned up, customers started getting texts (nobody's proven they're connected, but I wouldn't bet against it) that slot into their real Revolut message thread and lead to a fake "turn your head" selfie check, then a password box. -> do this: if you bank with Revolut (or anyone), never do an ID check or log in from a link in a text. Open the app yourself. If it doesn't ask you there, nobody's asking. (source) [3] * "Your parcel couldn't be delivered." No, it could. Fake courier texts are doing the rounds again: a tiny fee, a couple of quid, to "rebook delivery". The fee is bait. The fake site then wants your full card details and your bank account number, which no redelivery has ever needed. -> do this: if you're actually expecting something, check the tracking in the courier's own app or website. A small fee plus a request for bank details is a scam every single time. (source) [4] ------------------------------------------------------------------------ [ 2. BEGINNER'S CORNER ] New to all this? One skill here will protect you more than any paid antivirus: smelling a phish. Three tells, ten seconds. * 1. It's rushing you. "Account will be closed", "points expire today", "act now". Manufactured panic is the oldest lever there is. Real companies don't threaten you into clicking. * 2. The link doesn't match the words. Hover over it on a computer, or long-press on a phone, and read the actual address. If the message says T-Mobile but the link is tmobile-rewards-claim.xyz, it's a fake. * 3. It wants you to log in from the message. Don't. Ever. Open a fresh tab and type the site's address yourself. Same rule for QR codes. That single habit beats the vast majority of attacks. That's the whole skill: slow down, check the link, log in yourself. You're now harder to phish than most people with a security team. ------------------------------------------------------------------------ [ 3. THE PROJECT ] A SCREEN THAT BREATHES The main event. Build a colour-cycling plasma in ~30 lines -- then drag it around and break it, right here. This is a plasma: the colour-cycling, liquid-light effect the demoscene has been showing off since the early 90s. It's alive below -- poke the sliders. [ live demo: https://makebreak.co.uk/issues/00.html ] That's ~130,000 pixels recomputed every frame, in your browser, from three sliders. No library. >> 01. Make it yourself Save this as breathe.html and open it. That's the whole thing: >> 02. Why it works The shape is a sum of sine waves over x, y, x+y and distance-from-centre. Each is a ripple; stacked, they interfere into something organic. That last term -- distance from the middle -- gives the radial breathing. The colour is the demoscene trick: take that one value and feed it into three sines shifted by 120 deg (2.094 and 4.188 radians) for R/G/B. Nudge everything by t each frame and that's the cycling. Drag colour spread to feel it. >> 03. Now break it Don't just run it -- maul it. Change the 0.04 / 0.03 constants (the ripple slider): bigger = tighter and chaotic, smaller = vast and slow. Then add a kaleidoscope fold -- mirror the coordinates at the top of the loop: const fx = Math.abs(px - W/2), fy = Math.abs(y - H/2); // then use fx / fy in the waves instead of px / y Instant symmetry. That's issue #01's whole world -- you just previewed it. ------------------------------------------------------------------------ [ 4. YOUR TURN ] * Make the plasma follow your mouse -- feed the pointer's position into the ripple, or move the centre point to wherever the cursor is. Ten minutes, tops. Reply with a ten-second screen-grab and the best one runs at the top of issue #01, with your name on it. Go on. ------------------------------------------------------------------------ A new one every other week -- free, right here: https://makebreak.co.uk/issues/ No paywall, no ads, no sponsor telling me what to say. If an issue earned you a brew: https://buymeacoffee.com/androidacid -- the Norfolk Hacker next: #01 Fold the light https://makebreak.co.uk/issues/01.txt ------------------------------------------------------------------------ LINKS [1] https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html [2] https://www.malwarebytes.com/blog/mobile/2026/09/google-pixel-owners-urged-to-patch-actively-exploited-modem-flaw [3] https://www.malwarebytes.com/blog/threat-intel/2026/09/revolut-phishing-texts-appear-days-after-data-breach [4] https://www.malwarebytes.com/blog/scams/2026/09/fake-parcel-delivery-messages-steal-your-card-and-bank-details ========================================================================