A campaign targets NGOs and individuals documenting human rights abuses.
HarfangLab tracks the activity as RedKitten, using Excel files themed around deceased protesters to deliver malware.
The tooling relies on GitHub, Google Drive, and Telegram for configuration and control, with indicators suggesting parts of the code may be LLM-assisted.
HarfangLab tracks the activity as RedKitten, using Excel files themed around deceased protesters to deliver malware.
The tooling relies on GitHub, Google Drive, and Telegram for configuration and control, with indicators suggesting parts of the code may be LLM-assisted.
Forwarded from ᴛʜᴇ ɢʜᴏꜱᴛ ɪɴ ᴛʜᴇ ᴍᴀᴄʜɪɴᴇ
Epstein's Shadow Hacker
Jeffrey Epstein's web of influence extended into the digital underworld, according to a bombshell Justice Department document released on January 31, 2026. An FBI informant's 2017 statement claims Epstein employed a "personal hacker"—a redacted Italian cybersecurity expert from Calabria with elite skills in zero-day exploits. This revelation, part of the ongoing Epstein Files disclosures, paints a chilling picture of how the late financier allegedly weaponized cutting-edge hacking talents.
The Hacker's Profile Emerges
The document describes the individual as a master of vulnerabilities in iOS, BlackBerry, and Firefox, crafting offensive cyber tools sold to governments including the US and UK. He reportedly built Saudi Arabia's cyber surveillance program and even sold a zero-day exploit to Hezbollah for a trunk of cash, which he laundered through a California theater company. Earning six-figure sums, he shunned deals with "incompetent" Italy and Asian buyers, preferring high-stakes clients backed by billionaires like Epstein.
Online sleuths can likely pinpoint him: his firm was acquired by CrowdStrike in fall 2017, after which he rose to Vice President. Epstein provided seed money alongside two other tycoons, one tied to a Japanese firm. The informant notes his ties to "old school" European hackers, including phonetic handles like "PH," blending old-world cybercrime with modern zero-days.
Implications for Cybersecurity Elite
This isn't just tabloid fodder—it's a stark reminder of blurred lines between private hacking prowess and criminal patronage. Epstein, known for compromising elites, may have leveraged this talent for surveillance or blackmail ops, mirroring his real-world tactics.
CrowdStrike's involvement demands scrutiny. Did due diligence miss these shadows during acquisition? Post-2017, as VP, could he have influenced endpoint security tools used globally?
Broader Cybercrime Echoes
Epstein's orbit intersects with recent headlines: Empire Market's co-founder pleading guilty to decades in prison; ShinyHunters breaching Crunchbase; CISA flagging exploited flaws in Ivanti, Fortinet, and Microsoft Office. Yet none rival the intrigue of a zero-day dealer bankrolled by a sex-trafficker.
For the hacker, fallout looms. Italian authorities may reopen probes, while US agencies question Epstein-era dealings. Hezbollah cash runs evoke state-sponsored cyber bazaars, where exploits fuel asymmetric warfare.
This story underscores cybersecurity's dark side: geniuses moonlighting for the highest bidder. Victims of Epstein's network deserve full unredacted files—allegations alone erode trust.
As Pierluigi Paganini warns on SecurityAffairs, one ponders why Epstein chose such a figure. The answer likely lies in power: digital dirt as leverage.
@TheGhostsITM
Jeffrey Epstein's web of influence extended into the digital underworld, according to a bombshell Justice Department document released on January 31, 2026. An FBI informant's 2017 statement claims Epstein employed a "personal hacker"—a redacted Italian cybersecurity expert from Calabria with elite skills in zero-day exploits. This revelation, part of the ongoing Epstein Files disclosures, paints a chilling picture of how the late financier allegedly weaponized cutting-edge hacking talents.
The Hacker's Profile Emerges
The document describes the individual as a master of vulnerabilities in iOS, BlackBerry, and Firefox, crafting offensive cyber tools sold to governments including the US and UK. He reportedly built Saudi Arabia's cyber surveillance program and even sold a zero-day exploit to Hezbollah for a trunk of cash, which he laundered through a California theater company. Earning six-figure sums, he shunned deals with "incompetent" Italy and Asian buyers, preferring high-stakes clients backed by billionaires like Epstein.
Online sleuths can likely pinpoint him: his firm was acquired by CrowdStrike in fall 2017, after which he rose to Vice President. Epstein provided seed money alongside two other tycoons, one tied to a Japanese firm. The informant notes his ties to "old school" European hackers, including phonetic handles like "PH," blending old-world cybercrime with modern zero-days.
Implications for Cybersecurity Elite
This isn't just tabloid fodder—it's a stark reminder of blurred lines between private hacking prowess and criminal patronage. Epstein, known for compromising elites, may have leveraged this talent for surveillance or blackmail ops, mirroring his real-world tactics.
CrowdStrike's involvement demands scrutiny. Did due diligence miss these shadows during acquisition? Post-2017, as VP, could he have influenced endpoint security tools used globally?
Broader Cybercrime Echoes
Epstein's orbit intersects with recent headlines: Empire Market's co-founder pleading guilty to decades in prison; ShinyHunters breaching Crunchbase; CISA flagging exploited flaws in Ivanti, Fortinet, and Microsoft Office. Yet none rival the intrigue of a zero-day dealer bankrolled by a sex-trafficker.
For the hacker, fallout looms. Italian authorities may reopen probes, while US agencies question Epstein-era dealings. Hezbollah cash runs evoke state-sponsored cyber bazaars, where exploits fuel asymmetric warfare.
This story underscores cybersecurity's dark side: geniuses moonlighting for the highest bidder. Victims of Epstein's network deserve full unredacted files—allegations alone erode trust.
As Pierluigi Paganini warns on SecurityAffairs, one ponders why Epstein chose such a figure. The answer likely lies in power: digital dirt as leverage.
@TheGhostsITM
انسحاب كامل لجيش الاحتلال بعد تدمير شارع الشالية خلف سوبر ماركت المجد شارع حيفا في مدينة جنين
الأمن الفرنسي يقتحم مقر إكس في باريس للاشتباه بتورط إيلون ماسك بالبيدوفيليا
شركة الإتصالات الفلسطينية:
انقطاع خدمة الإنترنت في شمال قطاع غزة بسبب أعمال صيانة فنية، على أن تعود الخدمة خلال ساعة واحدة.
انقطاع خدمة الإنترنت في شمال قطاع غزة بسبب أعمال صيانة فنية، على أن تعود الخدمة خلال ساعة واحدة.
CVE-2025-7016
Improper Access Control vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Authentication Abuse.This issue affects QR Menu: before s1.05.12.
Improper Access Control vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Authentication Abuse.This issue affects QR Menu: before s1.05.12.
CVE-2025-59818
This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.
This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.
CVE-2026-1819
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Karel Electronics Industry and Trade Inc. ViPort allows Stored XSS.This issue affec...
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Karel Electronics Industry and Trade Inc. ViPort allows Stored XSS.This issue affec...
CVE-2026-1861
Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2026-25510
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.28.5.0, an authenticated.
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.28.5.0, an authenticated.