Thank you to Josef (OE3JJS) for writing in and sharing with us the release of his new open-source software called SDROxide, an SDR client designed for HAMs and SWLs (short-wave listeners), written in Rust. The software supports Linux, Windows, macOS, and also has a web client. As it supports SoapySDR, RTL-SDR dongles are supported for RX. Josef writes about SDROxide:
It's a completely new project written in Rust, supporting many SDR interfaces (CAT/Audio, CAT/IQ, SoapySDR, HPSDR, TCI) and with loads of features built in that used to require extra programs: FT8/FT4, SSTV, RTTY, PSK, OLIVIA, THOR, FSQ, a CW/RTTY/PSK skimmer, there's dx cluster and sota/pota spotting, a logbook with integrations for QRZ.com, HamQTH, eQSL, LoTW, there's neural-network noise reduction, a 3D "hamclock" that visualizes QSOs, satellites, Aurora, CME cones, with up-to-date images of the sun's surface, and you can run the client locally, remote with native binary, or remote via the web (WASM).
Jhestyr takes pride in being punctual, but a local railroad crossing keeps getting in the way. Trains sometimes park across it for hours at a time, and there is no way to know one is sitting there until you have already driven out to it. Every wasted trip to the crossing and back out to an alternative route costs him a significant chunk of time and fuel.
This is why Jhestyr used two RTL-SDR dongles to build isTrain, an open source program that decodes End-of-Train brake pressure and motion telemetry on 457.9375 and 452.9375 MHz, transcribes railroad voice traffic in the 160 to 162 MHz band via Whisper, and fuses both sources into a single live verdict on whether the crossing is blocked.
The program generates a webpage that can be accessed, providing a YES/NO verdict on whether there is a train blocking the crossing. A live public instance of Jhestyr's isTrain webpage is available here https://istrain.jhestyr.net.
AI-Disclaimer: Jhestyr notes that the code was developed with a 60/40 agentic/human split.
Back in June, we posted about VibeSDR, an AI vibecoded free and open-source mobile SDR client for rtl_tcp and UberSDR/KiwiSDR/OpenWebRX servers developed for iOS and Android. Recently, Stuart Carr (Stuey3D) wrote in again to let us know that VibeSDR is now available on the Apple App Store for £2.99 and is soon to be available on the Android Play Store too.
In terms of updates, Stuart also notes that he's now developed VibeServer, which provides a more network-efficient way to share RTL-SDRs remotely via an Android phone. VibeServer compresses the data and transfers it at 120KB/s instead of the full 4.8MB/s required by rtl_tcp.
Stuart has also developed an Apple Watch Buddy app version of VibeSDR which runs directly on an Apple Watch, allowing you to view and listen to the spectrum on your wrist. The watch version is still in beta, but Stuart notes that you can join the free beta on TestFlight.
Finally, Stuart has provided us with 20 free promo codes to give away for the Apple App Store version of VibeSDR. To win a promo code, simply comment on this post (making sure to enter an email in the email field), reply to the X post, or comment on the Facebook Post (note that for Facebook you must montior your comment for a reply as Facebook does not allow private messages).
Update: All promo codes have now been allocated, thanks!
AI-Disclaimer: This software was vibecoded with Claude.
VibeSDR Running on an Apple Watch
Introducing VibeSDR Jr: A full SDR Client on your wrist.
Researchers from the University of Shandong have recently demonstrated in a paper that they can transmit data from an air-gapped PC by using a Trojan to implement imperceptible pixel modulation in a monitor.
Every electronic device unintentionally emits RF, and PC monitors, TVs, and screens are no exception. In the past, we have shown that with simple TEMPEST tools, it is easy to recover the image on a screen over a distance using an RTL-SDR or Airspy SDR.
TrojPix relies on the unintentional emitted RF from a PC monitor's video cable. By subtly modulating the pixels on a screen, it is possible to enable data transfer via the unintentional emissions. This means that any PC infected with the TrojPix Trojan could transfer data wirelessly to a snooper, even if the PC is totally disconnected from any wired or wireless network. The only way to stop such an attack would be to completely shield the PC with a faraday cage.
The team note that they were able to achieve a peak data throughput of 8.1 MBps over a max range of 208 meters. They tested nine commercially available monitors and fifteen digital video cables, each demonstrating significant usable RF leakage.
The receiver hardware used was a USRP X310 software-defined radio sampling at 10 MHz and the transmissions appear to have been at 148.5 MHz and 297 MHz.
TrojPix Experiment: Receiving Data over 210 neters,.
Dragon Labs have recently announced that the CR-8 model is getting ready for crowdfunding on CrowdSupply. The CR-8 is an 8-channel coherent software-defined radio with a 12-bit ADC, a tuning range of 25 MHz to 1750 MHz, and 8 MHz of bandwidth per channel. A coherent SDR unlocks various applications such as radio direction finding, beamforming, and antenna diversity.
The CR-8 was originally designed for a Master's thesis by Alexandre Rouma, who is also the creator of the popular SDR++ software, which is commonly used by RTL-SDR enthusiasts.
The core of the build appears to consist of R860 tuners for each channel and an MCP3721-200 analog-to-digital converter (ADC). The MCP3721-200 is a chip commonly used for radar, imaging, and cellular base station applications, as it naturally provides aligned samples with built-in fractional delay recovery, making it ideal for coherent applications. A seperate signal source on the PCB provides the needed signal for the phase calibration of the tuners.
SDR++ and SatDump will natively support the CR-8, and there is also a GNU Radio source block. While the C API is open source, they note that the firmware will be closed source.
Pricing has yet to be announced, but we found a recent comment from the team indicating a target price of US$500 - $600 for the bare PCB, with a CNC-milled enclosure available as an optional add-on.
Over on Reddit and YouTube, user Hubquhq has shown how he created a live incident map using an RTL-SDR, Whisper and an LLM. The idea behind the system is to monitor multiple public safety voice communication channels with an RTL-SDR, transcribe everything into text using Whisper, and then use an LLM to categorize events and extract details such as addresses. Categorized incidents are then plotted on a map, allowing the user to visualize patterns.
For example, in his YouTube video, he shows how he mapped cardiac, animal, drug overdose, vehicle collision, rescue, and hazmat events over time, building a powerful database of what is happening in his city.
The program and code does not seem to be available for download anywhere, but Hubquhq does provide a contact link for anyone interested.
Systems that can monitor every RF voice and data channel on the spectrum and summarize them via an LLM are something we expect to see more of in the future as AI and LLMs improve.
Over on her YouTube channel SignalsEverywhere, Sarah has uploaded an interesting video showing her doing a wardrive for DECT devices, with an Android device connected to a HackRF, running her own Android version of DECT toolkit. In the past, we also covered her DeDECTive software, which is a fully DECT scanner and voice decoder for Linux and the HackRF.
DECT is a digital wireless protocol operating at around 1.9 GHz, which is typically used by modern cordless home phones, baby monitors, headsets, intercoms, and more. If you are unfamiliar with the term wardriving, this is when someone drives around in a vehicle and looks for interesting signals around the area. Wardriving is typically associated with mapping out the local WiFi environment and looking for security flaws, but it can apply to any signal.
During her wardrive, Sarah finds mostly VTech cordless phones, but a few other models like 'Binatone' and 'RTX' pop up, which she suspects are headsets, one possibly from a local McDonald's. She notes that only one active call was found, although the video has voice decoding stripped out for privacy reasons. She also notes that no encryption was found to be enabled on any device, despite DECT supporting it. The Android App also records the GPS position of any found DECT devices on a map.
Over on X @lambdaprog, (aka Youssef Touil), the developer of SDR#, has been teasing development of a new web client called "WebSpy" for Airspy software-defined radios. The web client allows users to tune in to a remote Airspy SDR via a web browser interface that mimics the SDR# Windows software. Before WebSpy, it has only been possible to access Airspy devices remotely via the SpyServer server software and the SDR# Windows application.
While the software is still in development and not yet available for download, you can access a demo version (HF server) (Broadcast FM server) that Youssef has currently set up on his own server in France. From the X posts on the development of the software, it seems that WebSpy boasts some impressive efficiency in terms of the low 6 kB/s network bandwidth required. This means that even over slow connections, the FFT and audio should be smooth and clear. The web interface also works well on mobile, providing a touch-optimized interface.
Youssef wrote in and wanted to share some additional information about how SharpIQ and SharpFFT work:
Under the hood, WebSpy streams both the radio signal and the spectrum display using two purpose-built compression codecs: SharpIQ for the channel data and SharpFFT for the FFT display.
A key design choice is what gets streamed: unlike most web receivers, which demodulate on the server and send you compressed audio, WebSpy sends the raw IQ signal of the tuned channel and does all the demodulation right in your browser — the same DSP chain as the gold standard SDR#. This matters more than it might sound: with server-side audio you're listening to a lossy rendition of what the server decided to demodulate, with voice-codec artifacts baked in; with local IQ, the actual signal arrives at your machine, so demodulation, filtering and mode changes happen instantly and the audio quality is limited only by the signal itself, not by an audio codec.
Unlike general-purpose compressors, SharpIQ and SharpFFT were designed from the ground up for radio: they adapt in real time to what's actually happening on the band, spending bits only where there is information worth keeping, while preserving the weak-signal fidelity that SDR users care about — a CW signal buried near the noise floor comes through intact.
The result is that a complete listening session — channel IQ, live spectrum, waterfall and all — typically fits in about 5 kB/s, a fraction of what conventional audio streaming would need. That's low enough to comfortably operate a remote receiver over a modest mobile connection, which is precisely what makes a full SDR experience in a browser tab practical — nothing to install, nothing left behind, just a tab you can close; and at 5 kB/s the stream itself hides in the noise of ordinary web traffic. Discreet SIGINT, if you're so inclined.