Media is too big
VIEW IN TELEGRAM
πͺπΈ Spain's PM unveils proposals to censor the internet and gut free speech protections.
π€¬14π©4π₯°1
Great use of AI: Bellingcat just published how it used machine learning to surface and document civilian-harm posts on Telegram, and open-sourced the notebook.
In Bellingcat's tests, one of the strongest signals that a post showed civilian harm was the number of crying-face π reactions on it.
Bellingcat ranks posts by how likely they are to show civilian harm, cutting search time so researchers can spend their hours verifying instead of scrolling. It was tested on Bellingcat's Ukraine work, which has logged 2,500+ geolocated incidents since 2022.
Source: https://www.bellingcat.com/resources/2026/06/25/how-to-use-ai-to-help-find-civilian-harm-conflict-report-monitor-war-machine-learning-telegram/
In Bellingcat's tests, one of the strongest signals that a post showed civilian harm was the number of crying-face π reactions on it.
Bellingcat ranks posts by how likely they are to show civilian harm, cutting search time so researchers can spend their hours verifying instead of scrolling. It was tested on Bellingcat's Ukraine work, which has logged 2,500+ geolocated incidents since 2022.
Source: https://www.bellingcat.com/resources/2026/06/25/how-to-use-ai-to-help-find-civilian-harm-conflict-report-monitor-war-machine-learning-telegram/
π14β€2π€2π1π1π₯΄1
Media is too big
VIEW IN TELEGRAM
Bodycam footage just came out of a farmer speaking against a planned data center, being handcuffed at a city council meeting for going a few seconds over the 3-minute public comment limit.
Darren Blanchard was speaking in Claremore, Oklahoma when two officers told him to leave, followed him to the front as he tried to hand documents to the council, and cuffed him as the crowd booed. He's charged with criminal trespass, a $200 offense, and is fighting it as retaliatory.
The case has become a marker for the wider fight over data center construction, where residents increasingly clash with developers over water, power, utility rates and farmland. Blanchard's sharpest point is about democracy itself: if attending a public meeting can get you cuffed, the chilling effect reaches well beyond one Oklahoma town.
Darren Blanchard was speaking in Claremore, Oklahoma when two officers told him to leave, followed him to the front as he tried to hand documents to the council, and cuffed him as the crowd booed. He's charged with criminal trespass, a $200 offense, and is fighting it as retaliatory.
The case has become a marker for the wider fight over data center construction, where residents increasingly clash with developers over water, power, utility rates and farmland. Blanchard's sharpest point is about democracy itself: if attending a public meeting can get you cuffed, the chilling effect reaches well beyond one Oklahoma town.
π11π©2π₯1π’1
The EU's Chat Control fight just reignited, and critics warn the worst case is back on the table: mass scanning of private messages, detection orders without a judicial warrant, and the end of anonymous communication through forced age verification.
Former MEP Patrick Breyer is warning of what he calls a "double attack" on encrypted messaging: EU government envoys met Friday to try to revive lapsed rules allowing "voluntary" scanning of private chats, and Monday June 29 brings the final trilogue on the permanent Child Sexual Abuse Regulation (Chat Control 2.0).
Parliament rejected extending the old scanning rules in March and they expired in April. Breyer claims EP President Roberta Metsola is maneuvering to force another vote, which Politico has also reported. Backers, including the Commission, call it child protection.
Civil society has relaunched fightchatcontrol.eu to push MEPs before Monday.
Former MEP Patrick Breyer is warning of what he calls a "double attack" on encrypted messaging: EU government envoys met Friday to try to revive lapsed rules allowing "voluntary" scanning of private chats, and Monday June 29 brings the final trilogue on the permanent Child Sexual Abuse Regulation (Chat Control 2.0).
Parliament rejected extending the old scanning rules in March and they expired in April. Breyer claims EP President Roberta Metsola is maneuvering to force another vote, which Politico has also reported. Backers, including the Commission, call it child protection.
Civil society has relaunched fightchatcontrol.eu to push MEPs before Monday.
π’7π©3π2π1π€ͺ1
The Lapsus$ hacker who leaked 90 clips of unfinished GTA 6 gameplay in 2022 is posting selfies on Snapchat from his prison cell, using a smuggled phone.
Arion Kurtaj was sentenced in 2023 to an indefinite hospital order due to his severe autism, after a judge ruled he remained a high risk of reoffending.
Arion Kurtaj was sentenced in 2023 to an indefinite hospital order due to his severe autism, after a judge ruled he remained a high risk of reoffending.
π19π€£11β€4π3π1
A Wikipedia cofounder just got banned from Wikipedia.
Larry Sanger, who helped launch the site in 2001 and left in 2002, was indefinitely blocked after editors accused him of "off-wiki canvassing": using his X following to influence an internal debate.
He'd been pushing a WikiProject to fight what he calls the site's "globalist, secular, progressive" bias. Editors ruled he's "not here to constructively build the encyclopedia."
His response: "Wikipedia has become more of a mob-rule anarchy than ever."
Larry Sanger, who helped launch the site in 2001 and left in 2002, was indefinitely blocked after editors accused him of "off-wiki canvassing": using his X following to influence an internal debate.
He'd been pushing a WikiProject to fight what he calls the site's "globalist, secular, progressive" bias. Editors ruled he's "not here to constructively build the encyclopedia."
His response: "Wikipedia has become more of a mob-rule anarchy than ever."
π―12π©6β€5π4π2
> be Polymarket
> hacker says you're "compromised"
> make fun of hackers π
> "which VC paid you to post this?"
> we and half of cybersec X tell you not to taunt them
> ignore everyone
> 2 months later a third-party vendor injects a malicious script into your frontend
> ~$3M drained from user wallets, swapped to ETH
> compromised
> hacker says you're "compromised"
> make fun of hackers π
> "which VC paid you to post this?"
> we and half of cybersec X tell you not to taunt them
> ignore everyone
> 2 months later a third-party vendor injects a malicious script into your frontend
> ~$3M drained from user wallets, swapped to ETH
> compromised
π€£38π4β€3
An anonymous GitHub account is mass-dropping exploit PoCs framed as undisclosed 0-days, with a note telling readers to report them and "take credit for the CVE" themselves.
Coordinated disclosure, minus the coordination.
Source: https://github.com/bikini/exploitarium
Coordinated disclosure, minus the coordination.
Source: https://github.com/bikini/exploitarium
π₯15π₯°5β€1
The costliest cyberattack in UK history, that shut down Jaguar Land Rover for five weeks last year, was the work of Russian hackers and not the collective that claimed it, the New York Times reports, citing five people familiar with the investigation. That overturns the earlier assumption that Scattered Lapsus$ Hunters, the collective that publicly claimed the breach, was responsible.
No ransom was ever demanded. Investigators are still working out whether the Kremlin directed the attack or simply allowed it, which would move it from ordinary ransomware toward a state-tolerated strike on a NATO economy.
It cost an estimated $2.5 billion in economic damage and about $350 million to the company, and hit a manufacturer both the British military and the royal family rely on.
No ransom was ever demanded. Investigators are still working out whether the Kremlin directed the attack or simply allowed it, which would move it from ordinary ransomware toward a state-tolerated strike on a NATO economy.
It cost an estimated $2.5 billion in economic damage and about $350 million to the company, and hit a manufacturer both the British military and the royal family rely on.
π10π±5β€1π₯1π1
Google told a security researcher his bug was a 'nice catch', lined up his payout, then eleven days later called it harmless and refused to pay.
The bug, which the researcher named ConfigConfusion, is an unpatched flaw in Google Config Connector that he says lets anyone with basic Kubernetes access grant themselves owner rights over an entire Google Cloud organization. Google's stated reason for the reversal was that the tool works as designed, and it declined to assign a CVE.
Months on, there is still no patch. Google's own docs recommend running Config Connector with organization-level permissions, so plenty of teams are exposed.
The bug, which the researcher named ConfigConfusion, is an unpatched flaw in Google Config Connector that he says lets anyone with basic Kubernetes access grant themselves owner rights over an entire Google Cloud organization. Google's stated reason for the reversal was that the tool works as designed, and it declined to assign a CVE.
Months on, there is still no patch. Google's own docs recommend running Config Connector with organization-level permissions, so plenty of teams are exposed.
π€£20π€2β€1π’1
Holy shit, this guy tried to weaken @sama by facing him alone while astral projecting and got spiritually injured. Turns out Sam is too powerful.
π€£27π4π¨4π1π₯΄1
US House Homeland Security Chair Andrew Garbarino is scared of Mythos's capabilities and says 95% of his colleagues "don't understand what the hell's going on."
By his account, Anthropic told the model to find a vulnerability in a bank and empty accounts. It did, he says, then identified the same flaw and could patch it.
A separate jailbreak demo, of an unspecified model, produced a plan to kidnap a lawmaker in 30 seconds.
By his account, Anthropic told the model to find a vulnerability in a bank and empty accounts. It did, he says, then identified the same flaw and could patch it.
A separate jailbreak demo, of an unspecified model, produced a plan to kidnap a lawmaker in 30 seconds.
π€£31π©4π₯3β€2π1π1π1
Someone released an article about what is basically an offline VirusTotal without burning your payload: a security researcher reverse-engineered four major EDRs (SentinelOne, Cortex XDR, CrowdStrike, and Sophos) and extracted their detection logic from on-disk agent binaries, ML models, YARA rules, and behavioral scripts.
The project rebuilds the kernel telemetry stack those products run on, including Windows process, thread, registry, and handle callbacks plus a file-system minifilter. It even reconstructs access to the ETW Threat Intelligence provider that Windows normally reserves for protected anti-malware processes. Thus, both the detection rules and the sensor layer can be replicated outside the vendorβs agent.
https://blog.otterpwn.com/projects/heavener
The project rebuilds the kernel telemetry stack those products run on, including Windows process, thread, registry, and handle callbacks plus a file-system minifilter. It even reconstructs access to the ETW Threat Intelligence provider that Windows normally reserves for protected anti-malware processes. Thus, both the detection rules and the sensor layer can be replicated outside the vendorβs agent.
https://blog.otterpwn.com/projects/heavener
π13β€6π1π€1