Nvidia has agreed to buy Hugging Face for $12.9B, The Information reports. Neither company has confirmed.
Proton is currently experiencing a major outage affecting Proton's services due to a cooling failure in their Frankfurt datacenter.
A malicious Amazon Kiro workspace can leak sensitive local data.
After opening the workspace, sending any message to the agent can trigger repository-controlled instructions that send local data to an external server. Amazon fixed the flaw in Kiro 0.8.140.
After opening the workspace, sending any message to the agent can trigger repository-controlled instructions that send local data to an external server. Amazon fixed the flaw in Kiro 0.8.140.
Apple using Israeli designed 'C2 modem' chips for its upcoming iPhone 18 devices, with top advanced Taiwanese/US manufactured A20, Qualcomm, Image sensors (Sony Japan), and other Radios, charging, PMIC.
Forwarded from ᴛʜᴇ ɢʜᴏꜱᴛ ɪɴ ᴛʜᴇ ᴍᴀᴄʜɪɴᴇ
Case Study: How Reused Digital Identity Exposed an Alleged TeamPCP Member
By Yara Tabet (The Ghost In The Machine)
Executive Assessment
The reported arrest of Ruben Thomson in Western Australia illustrates a common failure in hacking OPSEC: identity reuse across platforms with radically different levels of visibility. The reported attribution was not built around a zero-day, a covert implant, or a single leaked identifier. It emerged from publicly accessible traces that, when correlated, connected a long-standing online persona to an alleged TeamPCP member.
The core failure was poor compartmentalization. Handles, infrastructure references, historical account activity, profile imagery, and social-media content allegedly overlapped for years. Any one artifact would have been weak evidence. Together, they created an attribution chain that was difficult to dismiss.
Scope and Attribution Caveat
This assessment is based on publicly reported material and open-source observations. It does not independently establish guilt or validate all claims of group membership. The reference to Thomson’s reported arrest and alleged connection to TeamPCP should be read as an attribution assessment pending the outcome of judicial proceedings.
Initial Identity Pivot
The investigation reportedly began with the handle DeadCatx3, which was associated with a HackerOne profile connected to the name Ruben Thomson. The account was significant because it created an initial bridge between a real-world identity and an established online alias.
Researchers then identified what appeared to be an associated Hugging Face account using initials consistent with the same name. That profile reportedly referenced masscan[.]cloud. The domain had been identified publicly as command-and-control infrastructure associated with the Mini Shai-Hulud npm worm activity. The same domain was also reportedly present on the DeadCatx3 GitHub profile.
This overlap mattered because it was not merely a reused username. It connected a named identity, developer-platform profiles, and infrastructure allegedly tied to a malware campaign. The evidentiary value came from convergence: distinct services independently pointing toward the same operational ecosystem.
Social-Media and Steam Correlation
Once Ruben Thomson became a working lead, investigators and researchers reportedly pivoted through account-linked data and open-source records. This led to a TikTok account using the name yolosolo17.
The account reportedly contained a single video, published in March 2017, showing a Steam profile named YolocrownZ. The footage showed that the account had received a VAC ban 175 days earlier. This places the likely ban date at approximately September 13, 2016.
Further Steam research reportedly identified an account called Ellis that had also received a VAC ban on September 13, 2016. Public Steam-profile interactions and comments reportedly established a relationship between the Ellis and YolocrownZ identities.
This is a valuable example of timestamp-based correlation. A shared ban date does not identify a person on its own, but it becomes meaningful when aligned with connected accounts, relationships, alias reuse, and the wider attribution record.
The Avatar Link
The strongest and most memorable pivot was visual rather than technical. A distinctive cat avatar appeared on a Steam profile associated with the identity chain. The same image was reportedly reused by the PCPsh Telegram account linked publicly to TeamPCP.
Reverse-image searches reportedly produced few or no unrelated uses of the image. This gave the avatar limited but useful attribution value. Profile pictures are generally weak indicators because they can be copied, but their value rises when they appear consistently across accounts that also share timelines, contacts, aliases, and operational context.
The cat image did not prove identity. It corroborated an identity chain that was already supported by multiple independent sources.
OPSEC Failures Identified
By Yara Tabet (The Ghost In The Machine)
Executive Assessment
The reported arrest of Ruben Thomson in Western Australia illustrates a common failure in hacking OPSEC: identity reuse across platforms with radically different levels of visibility. The reported attribution was not built around a zero-day, a covert implant, or a single leaked identifier. It emerged from publicly accessible traces that, when correlated, connected a long-standing online persona to an alleged TeamPCP member.
The core failure was poor compartmentalization. Handles, infrastructure references, historical account activity, profile imagery, and social-media content allegedly overlapped for years. Any one artifact would have been weak evidence. Together, they created an attribution chain that was difficult to dismiss.
Scope and Attribution Caveat
This assessment is based on publicly reported material and open-source observations. It does not independently establish guilt or validate all claims of group membership. The reference to Thomson’s reported arrest and alleged connection to TeamPCP should be read as an attribution assessment pending the outcome of judicial proceedings.
Initial Identity Pivot
The investigation reportedly began with the handle DeadCatx3, which was associated with a HackerOne profile connected to the name Ruben Thomson. The account was significant because it created an initial bridge between a real-world identity and an established online alias.
Researchers then identified what appeared to be an associated Hugging Face account using initials consistent with the same name. That profile reportedly referenced masscan[.]cloud. The domain had been identified publicly as command-and-control infrastructure associated with the Mini Shai-Hulud npm worm activity. The same domain was also reportedly present on the DeadCatx3 GitHub profile.
This overlap mattered because it was not merely a reused username. It connected a named identity, developer-platform profiles, and infrastructure allegedly tied to a malware campaign. The evidentiary value came from convergence: distinct services independently pointing toward the same operational ecosystem.
Social-Media and Steam Correlation
Once Ruben Thomson became a working lead, investigators and researchers reportedly pivoted through account-linked data and open-source records. This led to a TikTok account using the name yolosolo17.
The account reportedly contained a single video, published in March 2017, showing a Steam profile named YolocrownZ. The footage showed that the account had received a VAC ban 175 days earlier. This places the likely ban date at approximately September 13, 2016.
Further Steam research reportedly identified an account called Ellis that had also received a VAC ban on September 13, 2016. Public Steam-profile interactions and comments reportedly established a relationship between the Ellis and YolocrownZ identities.
This is a valuable example of timestamp-based correlation. A shared ban date does not identify a person on its own, but it becomes meaningful when aligned with connected accounts, relationships, alias reuse, and the wider attribution record.
The Avatar Link
The strongest and most memorable pivot was visual rather than technical. A distinctive cat avatar appeared on a Steam profile associated with the identity chain. The same image was reportedly reused by the PCPsh Telegram account linked publicly to TeamPCP.
Reverse-image searches reportedly produced few or no unrelated uses of the image. This gave the avatar limited but useful attribution value. Profile pictures are generally weak indicators because they can be copied, but their value rises when they appear consistently across accounts that also share timelines, contacts, aliases, and operational context.
The cat image did not prove identity. It corroborated an identity chain that was already supported by multiple independent sources.
OPSEC Failures Identified
Forwarded from ᴛʜᴇ ɢʜᴏꜱᴛ ɪɴ ᴛʜᴇ ᴍᴀᴄʜɪɴᴇ
- Cross-platform alias persistence: Handles and identity fragments were reportedly retained across HackerOne, GitHub, Hugging Face, TikTok, Steam, and Telegram.
- Infrastructure exposure: A domain reportedly associated with malicious command-and-control activity was publicly linked from developer-facing profiles.
- Weak identity separation: A possible real name, initials, aliases, and related account data were sufficiently connected to enable further OSINT pivots.
- Historical timeline overlap: Steam VAC-ban dates and account interactions reportedly aligned across multiple identities.
- Visual-identity reuse: The same distinctive cat avatar reportedly appeared on Steam and Telegram accounts associated with the wider TeamPCP ecosystem.
- Public-record exposure: A business reportedly operated under the name OPSEC EXPRESS created an additional real-world attribution surface. Corporate records are routinely useful when they can be correlated with online identifiers, financial activity, communications, or infrastructure evidence.
Analytical Takeaway
This case demonstrates that operational security fails cumulatively. An individual does not need to expose a home address, leave a real IP address in a server log, or publish a direct confession to become attributable. Small artifacts—an old Steam ban, a contact comment, a reused profile image, a domain on a public developer profile, or a social-media video—can persist for years and later become critical evidence.
The central mistake was treating individual accounts as isolated identities. They were not isolated. The reported evidence indicates that each platform preserved a fragment of the same operational history. Once one fragment was linked to a real-world identity, the remaining artifacts could be examined as part of a single pattern.
For cyber-intelligence teams, the lesson is equally practical: prioritize pivots that establish independent corroboration. A username is a lead, not a conclusion. Confidence grows when a handle is supported by shared infrastructure, time-based correlations, platform relationships, visual markers, and verifiable public records.
#TGITM @TheGhostITM
- Infrastructure exposure: A domain reportedly associated with malicious command-and-control activity was publicly linked from developer-facing profiles.
- Weak identity separation: A possible real name, initials, aliases, and related account data were sufficiently connected to enable further OSINT pivots.
- Historical timeline overlap: Steam VAC-ban dates and account interactions reportedly aligned across multiple identities.
- Visual-identity reuse: The same distinctive cat avatar reportedly appeared on Steam and Telegram accounts associated with the wider TeamPCP ecosystem.
- Public-record exposure: A business reportedly operated under the name OPSEC EXPRESS created an additional real-world attribution surface. Corporate records are routinely useful when they can be correlated with online identifiers, financial activity, communications, or infrastructure evidence.
Analytical Takeaway
This case demonstrates that operational security fails cumulatively. An individual does not need to expose a home address, leave a real IP address in a server log, or publish a direct confession to become attributable. Small artifacts—an old Steam ban, a contact comment, a reused profile image, a domain on a public developer profile, or a social-media video—can persist for years and later become critical evidence.
The central mistake was treating individual accounts as isolated identities. They were not isolated. The reported evidence indicates that each platform preserved a fragment of the same operational history. Once one fragment was linked to a real-world identity, the remaining artifacts could be examined as part of a single pattern.
For cyber-intelligence teams, the lesson is equally practical: prioritize pivots that establish independent corroboration. A username is a lead, not a conclusion. Confidence grows when a handle is supported by shared infrastructure, time-based correlations, platform relationships, visual markers, and verifiable public records.
#TGITM @TheGhostITM
Forwarded from ᴛʜᴇ ɢʜᴏꜱᴛ ɪɴ ᴛʜᴇ ᴍᴀᴄʜɪɴᴇ
Media is too big
VIEW IN TELEGRAM
Two people linked to TeamPCP were reportedly arrested in Australia today. TeamPCP is believed to be behind a string of major supply-chain attacks that sent shockwaves through the cybersecurity community.
A startup in Virginia just launched a social network called Twitter and it has NOTHING to do with Elon Musk.
The blue bird is back, tweets and retweets are back, and it costs $20 to get through the door.
The blue bird is back, tweets and retweets are back, and it costs $20 to get through the door.
The new Twitter is here. “Twitter. now” service launch begins today — and usernames are now available.
Corporate America is hedging ahead of the 2026 midterms.
Companies that built close ties with Trump—especially big tech—fear Democratic-led investigations if the party wins the House.
Companies that built close ties with Trump—especially big tech—fear Democratic-led investigations if the party wins the House.
U.S. National Security Agency (NSA) Seeks Access to All AI Models
The Deputy Director of the U.S. National Security Agency has announced that the agency is in negotiations with major AI companies to gain access to their advanced models.
The NSA's stated goal is to use these models for cybersecurity defense, vulnerability identification, and the protection of U.S. military networks.
The Deputy Director of the U.S. National Security Agency has announced that the agency is in negotiations with major AI companies to gain access to their advanced models.
The NSA's stated goal is to use these models for cybersecurity defense, vulnerability identification, and the protection of U.S. military networks.
US SATELLITE BAN CONCEALS WEST ASIA FROM PUBLIC VIEW
Washington has imposed severe restrictions on US commercial satellite imagery across West Asia, leaving independent investigators and journalists in the dark. Planet Labs indefinitely froze high-resolution image distribution in the region following direct government directives.
Washington has imposed severe restrictions on US commercial satellite imagery across West Asia, leaving independent investigators and journalists in the dark. Planet Labs indefinitely froze high-resolution image distribution in the region following direct government directives.
Cyber Dispatch™️
US SATELLITE BAN CONCEALS WEST ASIA FROM PUBLIC VIEW Washington has imposed severe restrictions on US commercial satellite imagery across West Asia, leaving independent investigators and journalists in the dark. Planet Labs indefinitely froze high-resolution…
The blackout prevents independent verification of structural damage and battlefield developments in Gaza, Lebanon, and Iran. Experts warn the measures function to shield state actors from accountability under the guise of security. Adversaries with native reconnaissance capabilities remain unaffected, while open-source auditing is crippled.
Cyber Dispatch™️
The blackout prevents independent verification of structural damage and battlefield developments in Gaza, Lebanon, and Iran. Experts warn the measures function to shield state actors from accountability under the guise of security. Adversaries with native…
The restrictions are more about avoiding embarrassment than actual security concerns. Researchers are now turning to Chinese and European satellite systems, though advocates caution that political motivations are driving these information limitations in support of an unpopular war.
Three new critical ServiceNow flaws score a maximum CVSS 10.0 and require no authentication.
They can enable arbitrary code execution, privilege escalation, or arbitrary SQL against an instance. ServiceNow says it is not aware of exploitation.
They can enable arbitrary code execution, privilege escalation, or arbitrary SQL against an instance. ServiceNow says it is not aware of exploitation.
A new critical cPanel flaw could let one hosting customer take root control of an entire server.
CVE-2026-65643 affects all supported cPanel & WHM versions. The account must be able to add parked or addon domains, which can be abused to create arbitrary server files and ultimately execute code as root.
CVE-2026-65643 affects all supported cPanel & WHM versions. The account must be able to add parked or addon domains, which can be abused to create arbitrary server files and ultimately execute code as root.
PaperCut zero-day is under active exploitation.
The flaw affects all PaperCut NG and MF versions, with confirmed customer incidents. Emergency patches are available for v25 and v26. The exploit method and attackers remain unknown.
The flaw affects all PaperCut NG and MF versions, with confirmed customer incidents. Emergency patches are available for v25 and v26. The exploit method and attackers remain unknown.
APT28-linked HOOKEDGE targets European governments and diplomats through Word lures.
The batch backdoor abuses webhook[.]site for C2 and data exfiltration, while high-value targets receive a faster second stage.
The batch backdoor abuses webhook[.]site for C2 and data exfiltration, while high-value targets receive a faster second stage.