A groundbreaking campaign has been detected where the neural network DeepSeek searched and attacked vulnerable servers completely autonomously. A Chinese-speaking attacker tasked the AI to independently locate vulnerable servers, select predefined intrusion tools, and launch attacks without constant human supervision.
The attacker used FOFA for initial target discovery. FOFA is a cybersecurity search engine that allows researchers and attackers alike to scan and identify internet-connected devices, servers, and IoT equipment across the globe. By querying specific protocols, port numbers, certificates, or banners, users can find vulnerable systems at scale without traditional reconnaissance methods.
Once targets were identified through FOFA, DeepSeek analyzed vulnerability patterns and automatically selected appropriate exploit tools from a predefined arsenal to execute intrusion attempts without requiring manual intervention at each step.
This represents a significant evolution in cyberthreats, moving from human-directed automated scanning toward truly independent offensive operations where AI makes real-time tactical decisions during active exploitation phases. Security teams must adapt quickly since traditional defense strategies assuming human decision-making delays no longer apply when adversaries can deploy AI that operates continuously without fatigue or oversight gaps.
Palo Alto Networks researchers who analyzed this campaign emphasize that autonomous AI weapons are no longer theoretical – they're actively being deployed by threat actors today.
#DeepSeek #Attacks #Cybersecurity #AIThreats #FOFA
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
👀3✍2😈2
A seemingly harmless email without links or attachments was enough for the TA488 hacking group to gain persistent access to a victim's inbox.
The attackers only had to wait for the user to open the message in the web version of Outlook. This unique threat, known as OWAReaper, operates entirely within the browser session, making traditional removal methods like reinstalling Windows completely ineffective.
Unlike malware that drops executable files onto your hard drive, OWAReaper resides in the browser's memory and exploits the web interface of Outlook (OWA). Once activated, it monitors the user's activity in real-time, including modifications to connected services like GitHub. More alarmingly, it actively deletes its own traces from server logs and local cache, ensuring forensic analysts find little to no evidence of the intrusion.
Because the malicious code lives in temporary session data rather than the operating system itself, wiping your computer does not necessarily end the compromise if authentication tokens remain valid.
The primary danger lies in the attack vector. Since no file gets downloaded, antivirus scanners looking for suspicious executables stay blind. The threat persists as long as the browser session remains active or until specific authentication tokens get revoked.
Even if you wipe your computer, logging back into webmail with cached credentials can reactivate the malicious script instantly. This technique represents a shift toward "living off the land" attacks where existing infrastructure becomes the weapon.
These alternatives reduce the surface area for session hijacking and give you greater control over your authentication data.
#CyberSecurity #OWAReaper #ThreatIntelligence #InfoSec #TA488
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
The Police National Legal Database (PNLD), a critical legal lookup service used by police forces and criminal justice agencies across England and Wales, has been hit by a major cyberattack. Hackers from the group known as ExfilSquad managed to steal and publish on the dark web the personal details of more than 100,000 police officers, staff, and criminal justice professionals, in what officials are calling a serious risk to those exposed.
The leaked data includes full names, organizational affiliations, and work email addresses of police officers, police staff, and other justice professionals. The breach also affected data held by the Ministry of Defence (MoD), the Home Office, the National Crime Agency (NCA), and the Crown Prosecution Service (CPS). The hackers claimed to have taken approximately 135,000 records. However, the PNLD has stated there is "no evidence" that passwords or other authentication credentials were compromised.
The breach was discovered on July 26, 2026, and the PNLD confirmed it is working alongside specialist cybersecurity firms and the NCA to investigate the full scope of the attack. The PNLD reportedly uses Microsoft Power Platform technology, and the breach notice page referenced assets hosted on Microsoft's content.powerapps.com domain. This is notably the third police-related cyberattack in a single week, raising serious questions about the security posture of UK public sector infrastructure.
An officer described the leak as putting agents at "serious risk," and rightfully so. When the names and work contacts of undercover or specialized officers end up on criminal forums, the implications go far beyond a privacy violation. It becomes a physical safety issue. Previous incidents, such as the PSNI data breach in 2023, showed how devastating these leaks can be, with some officers forced to relocate or even leave the country after their identities were exposed.
#DataBreach #CyberSecurity #DarkWeb #PrivacyProtection #ExfilSquad
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
Researchers from Nanyang Technological University have uncovered 84 previously unknown vulnerabilities in the core software of 4G and 5G networks. Developers have already confirmed 83 of the findings, and 81 have been assigned CVE numbers. The root cause? Excessive trust assumptions between network components, a design flaw that becomes critically exposed as operators move their infrastructure to the cloud.
The vulnerabilities span across seven open-source mobile core implementations, including Open5GS, free5GC, OpenAirInterface, SD-Core, and eUPF. The flaws specifically target critical protocols like GTP-C and PFCP, responsible for session creation, data transmission, and routing rules between internal network elements. When these protocols skip proper verification, attackers can slip through the gaps and intercept traffic or disrupt services.
The researchers didn't limit themselves to open-source projects. They successfully reproduced attacks in two commercial 5G cores running default configurations. One vendor already patched the flaw, tracked as CVE-2026-8233 (4.6 Medium), while the second was still preparing a fix at the time of publication. Another confirmed issue, CVE-2026-8232 (3.5 Low), opened the door to denial of service in a commercial system.
The team behind the research described this class of problems as implicit trust errors. The most common pattern? Programs expecting mandatory fields without bothering to verify they actually exist. Other flaws let attackers inject incorrect values, break connection states, or drain internal memory until network components simply crashed and stopped responding. In some cases, malicious service messages could even be disguised as regular user traffic and routed through base stations straight into the core of the network.
Cloud systems have weakened the traditional network perimeter. A misconfigured or poorly isolated setup can leave internal interfaces wide open to attackers, turning decades of blind trust into a serious security liability.
#5GExposed #NetworkFlaws #TelcoSecurity #ZeroTrust #CyberResearch
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
2✍12😁7🥰5👀4🤷♂3🤡1🙈1
Tor has officially launched Snowflake Volunteer for Android. The setup is remarkably straightforward: download the app, tap a button, and your device instantly becomes a proxy node helping someone whose government blocks access to open internet. No complicated settings, server configurations, or midnight manual reading required. You receive nothing in return, the application simply relays data as a form of pure charitable assistance.
Snowflake traffic rides inside WebRTC, the same protocol enabling browser-based video calls and powering half of all corporate meetings. To Deep Packet Inspection systems, the data streams appear identical to routine messaging app communications. Shutting down this channel entirely would force regulators to block WebRTC across the board, an action that would cripple Zoom, Google Meet, Discord, and countless enterprise platforms at once.
This embodies the classic "collateral freedom" principle: resistance depends not just on encryption strength but on the prohibitive cost of censorship. Authorities pursue selective countermeasures instead, targeting STUN servers and hunting distinctive connection patterns rather than imposing wholesale bans.
Early 2026 saw approximately 146,000 unique volunteer proxy IPs register daily. Those numbers look impressive until you realize most are fleeting browser tabs that disappear the moment users close their websites, lasting mere minutes.
Every closed tab cuts off the person waiting on the other end, forcing them to reconnect again and again. An Android phone left charging overnight on stable Wi-Fi holds connections for around eight hours. More persistent nodes mean fewer dropped connections for anyone trying to access uncensored internet beyond the firewall.
Before volunteering, lock down your device: update the OS regularly to block malware from hijacking your proxy. Download only official releases to avoid compromised versions. For users depending on circumvention tools, stick to encrypted channels and never transmit sensitive data over unsecured links. Watch for strange battery drain or unexpected data spikes, those can signal something is wrong.
#DigitalFreedom #PrivacyTools #AntiCensorship #CyberSecurity #OpenSource #Tor
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
✍10😁3 3😈2 1
HyCanvas is a self-hosted, open-source design platform letting you create graphics, social media posts, presentations, and videos on your own infrastructure. Unlike commercial tools, it runs locally without watermarks or usage limits, keeping your creative work fully under your control.
Since HyCanvas is meant to be self-hosted, all your designs stay on your own server. Nothing gets sent to external clouds or third-party processors. The BYOK model means you provide your own API keys for AI features, so credentials and prompts never pass through a proprietary backend. This setup protects sensitive business designs and personal projects from being exposed to external servers.
Built with TypeScript, Next.js, Go, and PostgreSQL, the tool runs entirely in your browser once deployed. You can export to PNG, PDF, and other formats for both print and digital use. Production builds compile into a single Go binary, making Linux or Docker deployment straightforward. It works well for users needing data sovereignty and open standards in their design workflow.
When running self-hosted tools, keep your instance updated, use strong authentication, and restrict network access to trusted IPs. Regular backups protect your creative assets, and reviewing permissions prevents unintended exposure.
#OpenSource #SelfHosted #PrivacyFirst #DevTools #DesignSoftware
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
15👀10😁7🤔5✍4😈3 2 1
OpenCTI is an open-source solution designed to organize, analyze, and share cyber threat intelligence efficiently. It enables security teams to centralize data about attacks, malicious actors, and vulnerabilities, significantly improving incident response speed and effectiveness.
The platform facilitates structured information storage, allowing visualization of complex relationships between various threats and attacker groups. Its collaborative approach helps teams share knowledge efficiently. Additionally, OpenCTI integrates natively with international standards like STIX and TAXII, simplifying the exchange of updated intelligence within the global cybersecurity ecosystem.
OpenCTI's backend is built on Node.js and exposes a powerful GraphQL API for flexible querying. Data is managed in a graph database, complemented by Elasticsearch and/or Redis for fast searches and caching. The user interface, constructed with React, offers an interactive and smooth experience. Its microservices-based design ensures the platform is highly scalable and adaptable to diverse security environments.
#ThreatIntel #OpenSource #IncidentResponse #CyberDefense #OpenCTI
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
1👀11✍7🥰3 2
Final Results
19%
I am a cybersecurity specialist
3%
I am a software developer
8%
I'm a content creator
66%
I'm passionate about privacy and cybersecurity
4%
Other (Write in the comments)
A simple tap on what looks like an innocent link or username inside Telegram for Android can quietly trigger a Mini App and send your real IP address, User-Agent, and account details straight to the web app owner. No warning, no prompt, no permission asked. The installed Android version also gets exposed in the process, which means anyone running a vulnerable build is essentially leaking identifying information without even realizing it.
What makes this particularly concerning is how seamless the whole thing feels. You are not installing anything or granting permissions. You are just doing what millions of people do every day on Telegram: tapping a link, opening a profile. Behind that innocuous gesture, a Mini App wakes up in the background and starts transmitting technical data about your device along with profile information to a remote server.
Attackers can use the leaked IP address to approximate your geographic location, cross-reference it with other data, and build a profile that ties your anonymous Telegram identity to your real-world self. The User-Agent reveals details about your device and operating system, which makes it easier to craft targeted phishing attempts or select exploits that match your specific setup. Combine all of that with account metadata, and suddenly the anonymity that many users take for granted on Telegram starts to crumble.
Be cautious with links and usernames from unknown or unverified contacts, especially if they seem designed to grab your attention with urgency or curiosity. If you notice a Mini App unexpectedly opening after tapping something, close it right away and review your recent activity. Keeping both Telegram and your Android system fully updated is crucial, since developers tend to patch these exposure vectors once they are publicly documented.
And if you want an extra layer of protection against IP leaks, routing your traffic through a trustworthy VPN can mask your real address even if a Mini App manages to fire off a request in the background.
#Cybersecurity #Privacy #AndroidSecurity #DataLeak #MiniApp
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
2👀13✍4 2 1
Agent failures rarely occur from a single message. Instead, they emerge during extended dialogues, tool calls, and dynamic context shifts. Giskard solves precisely this problem by enabling comprehensive testing of complex AI agent behaviors.
The platform handles intricate scenarios involving multi-stage conversations where traditional testing methods fall short. It detects failures that surface during tool execution and when context changes throughout a session. The specialized verification features focus specifically on LLM-agent behavior patterns, ensuring reliability across different interaction types.
Built in Python, the framework supports cross-platform deployment. Developers can run it on Windows, Linux, or macOS systems without compatibility issues.
#Giskard #AITesting #LLM #MachineLearning #OpenSource
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
🥰10😁6 1
The main threat was hiding where people sought maximum security. Users of anonymous operating systems often trust that no program within the system will reveal their true identity, but sometimes a single flaw in the Linux kernel is enough for that to happen.
For six years, a critical vulnerability remained hidden in the Linux kernel's POSIX CPU-timer subsystem. Tracked as CVE-2026-64560, this use-after-free flaw originates from a race condition between sys_timer_delete() and a non-leader thread performing exec(), which can leave a freed timer object accessible and allow arbitrary code execution with kernel privileges.
Assigned a CVSS score of 7.0, the bug has been present since kernel version 5.7, released on May 31, 2020, affecting all versions up to 6.12.99.
In the context of Tails, the operating system designed to leave no trace and route all traffic through the Tor network, this vulnerability created a particularly dangerous loophole. As the Tails team explained plainly: "If a malicious website that you visit is able to exploit CVE-2026-64560, they might take full control of your Tails and deanonymize you."
Tails 7.10.1, released as an emergency update on August 5, 2026, didn't just fix the kernel vulnerability. It also addressed a separate critical flaw in the Expat XML parsing library, which is used by applications like LibreOffice, Audacity, and Git. If an attacker tricks a user into opening a malicious file in any of these applications, they could exploit this vulnerability to take full control of the system and de-anonymize the user as well.
Both vulnerabilities share the same alarming consequence: the complete loss of anonymity that Tails is specifically built to protect.
The Tails project notes that these attacks are very unlikely but could be carried out by a strong adversary, such as a government or a hacking firm. No confirmed in-the-wild exploitation has been reported so far, but the mere possibility that state-sponsored actors could weaponize a six-year-old kernel bug to deanonymize users is a sobering reminder of how fragile privacy can be.
If you use Tails or any Linux-based distribution focused on privacy, the most urgent step is to update to Tails 7.10.1 immediately, which ships kernel version 6.12.100 with the patch applied. Avoid opening untrusted files in applications that rely on Expat, such as LibreOffice or Audacity, until you have confirmed your system is fully updated.
Beyond updating, consider using additional isolation layers like AppArmor profiles or containers to limit the impact of potential exploits. Disabling JavaScript in the Tor Browser for untrusted sites also reduces the attack surface significantly, as many kernel exploitation techniques rely on initial access through web content.
#Tails #LinuxKernel #CVE2026 #Anonymity #Privacy
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
1🤨7🙈7✍4🤔2👀2
Law enforcement agencies across Europe are increasingly turning to sophisticated digital traps to dismantle organized crime networks operating on messaging platforms. Authorities have begun acquiring or dominating specific search terms within Telegram. When criminals search for illicit goods, services, or specialized groups, the top results are often not legitimate communities, but fictitious groups meticulously crafted and controlled by police forces. This strategy, known as a digital honeypot, lures suspects into a false sense of security, allowing investigators to gather evidence, identify participants, and execute arrests.
While these tactics have proven effective in disrupting criminal supply chains and bringing cybercriminals to justice, they raise profound questions about the integrity of the platform itself. If a user cannot trust that the group they find through search is genuine, the fundamental promise of secure communication starts to weaken. The line between a private conversation and a police operation becomes dangerously blurred. Critics argue that such practices undermine the very concept of anonymity, suggesting that even in a supposedly decentralized environment, users may be walking into a trap set by the state.
Another factor that adds complexity to this issue is Telegram's acknowledged cooperation with European law enforcement authorities. The platform has been recognized by Europol for its collaboration in fighting terrorism and child exploitation, a move many privacy advocates view with skepticism. While official statements emphasize the fight against serious crimes, the existence of these honeypot operations fuels speculation about the scope of data access and surveillance capabilities shared between the platform and authorities. Does this partnership mean Telegram is inadvertently—or perhaps intentionally—facilitating monitoring of its user base?
The emergence of these deceptive tactics serves as a stark warning that no digital space is entirely immune to surveillance. Even if you believe you are communicating securely, the destination you click on could be a fabrication designed to extract your identity. Users must remain vigilant, verifying the authenticity of channels through independent means rather than relying solely on search results. The illusion of total privacy on Telegram may be more fragile than previously thought, especially when powerful entities are actively manipulating the landscape to catch those who break the law.
#CyberSecurity #Telegram #Europol #Privacy #DigitalSurveillance
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
6✍9😁9🤔8🤮8👀6🥰2
Privacy Not A Crime
Please open Telegram to view this post
VIEW IN TELEGRAM
👀2 2
Spotting a fake image by looking at it is becoming nearly impossible these days. JPEG Audit changes the game as a free web platform that brings forensic-level analysis to anyone with a browser. Journalists, investigators, and regular people who care about privacy can now dig deep into what lies beneath a JPEG file without needing expensive software.
Three major metadata standards get analyzed at once: EXIF, IPTC, and XMP. Camera models, shutter speeds, copyright tags, and full edit histories all appear on screen. The standout feature? Embedded GPS coordinates display clearly, so you can pin down exactly where a photo originated. For anyone working with visual evidence, those details matter enormously when separating proof from fabrication.
What sets this tool apart is how far it goes beyond passive viewing. Internal JPEG markers such as DQT, DHT, SOF, and SOS segments become visible at hex level. Forensic experts rely on these to identify double compression, splicing attempts, or other tells of manipulation. The platform also catches color profile mismatches and inconsistent quality metrics, flagging suspicious images for closer inspection.
Want to compare two versions? Side-by-side mode makes differences jump out instantly. The GPS integration connects straight to Google Street View, giving you a chance to verify whether the stated location actually matches the scene in the photograph. Fact-checkers use this daily to bust viral hoaxes, and investigators trace questionable images back to their real origin.
Photos carry hidden information about your device, location, and sometimes even your editing history. Running a quick check before posting helps you understand what you are broadcasting to the world. Strip GPS coordinates from personal travel photos at minimum. Remember that some metadata survives basic removal, making regular checks more of a habit than a one-time fix.
Journalists validate user-submitted images before publication. OSINT researchers track origins and confirm location claims. Cybersecurity analysts perform forensics on suspect files. Legal teams examine photographic evidence during disputes. Photographers discover what private data their uploads expose without realizing it.
What once required specialist software now lives in any browser. Whether you fight misinformation or guard personal privacy, JPEG Audit brings much-needed clarity to digital image verification.
#JPEGAudit #Forensics #Metadata #OSINT #Privacy
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
6😁8🥰5 2 1
Many users think that because Telegram offers cloud storage and fast messaging, their data stays safe. But what the platform collects and keeps is very different from the idea of total privacy. Knowing what gets collected matters if you care about your online privacy.
Unlike end-to-end encrypted messengers where only the participants hold the keys, Telegram's standard chats live on its servers in plain text. This means the service can see the content of your private conversations, including texts, photos, and documents sent in regular chats. While "secret chats" do offer end-to-end encryption, they are not enabled by default and miss key features like cloud sync.
Beyond just messages, Telegram keeps tabs on your activity. The service tracks signals about profiles you interact with, channels you subscribe to, and groups you join. This paints a detailed picture of your interests and communities. Even after you leave a group or channel, traces of your participation may still stay in their systems. Any comments you post in groups or channels get stored and could be reviewed later.
The bigger privacy worry sits in metadata. Telegram gathers info about your device, phone number, and contacts. They study interaction patterns, login times, and usage frequency to build behavioral profiles. On top of that, the app can track which stories and posts you scroll through in channels, letting them watch your content habits beyond who you simply follow.
Here's what matters most: Telegram has confirmed it works with governmental authorities around the world. Data can be shared with law enforcement when valid legal requests arrive, though how transparent this process is depends heavily on the country involved.
Since Telegram holds so much data, you're better off limiting it to entertainment—like following public channels for news or memes where privacy isn't critical. For anything sensitive, money-related, or truly private, you're safer switching to an app that encrypts everything by default. Signal stands out here, making sure neither the service nor anyone else can read your messages or see your metadata.
If you must stick with Telegram, turning on "two-step verification" and using "secret chats" for sensitive topics are must-do security steps. Still, these won't wipe out all the risks built into Telegram's architecture.
#TelegramPrivacy #DataSecurity #Signal #DigitalRights #CyberAware
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
2✍9👀5 1
This media is not supported in your browser
VIEW IN TELEGRAM
This week was far from quiet: the Shai-Hulud worm infected a thousand npm packages with two billion downloads, hackers breached water treatment plants across a dozen U.S. states, and the White House quietly moved advanced AI development into a closed regime.
We've gathered the most interesting stories of the week in one place so you don't miss anything.
#CyberSecurity #SupplyChainAttacks #AIRegulation #CriticalInfrastructure #DataPrivacy
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
👀11🤔6✍5😁5 1
While giants like Google dominate the digital landscape, they often filter out smaller, niche, or older sites in favor of SEO-optimized content and commercial interests. This creates a blind spot where valuable information gets lost.
Fortunately, there are alternative search engines dedicated to uncovering these hidden corners of the web while respecting user privacy. Unlike their mainstream counterparts, they do not track your history or build profiles for advertising.
The modern internet is vast, yet much of it remains invisible to standard algorithms. Large search engines prioritize relevance based on popularity and monetization potential, effectively burying independent blogs, academic archives, and legacy websites. The six search engines highlighted below aim to reverse this trend, offering unique indexing strategies that cater to researchers, privacy advocates, and anyone tired of algorithmic echo chambers.
They focus on raw data, human-curated results, and the preservation of digital diversity.
Marginalia Search stands out by specifically targeting sites that lack professional design but hold valuable content. It ignores SEO tricks and visual polish, focusing instead on the text and structure of pages that are often overlooked. It is an excellent choice for finding genuine discussions and obscure resources without the noise of commercial spam.
Wiby takes a different approach by indexing only small websites. It excludes large corporations and popular domains, ensuring that the results come from individual creators and niche communities. This makes it a treasure trove for authentic voices that would otherwise be drowned out by major media outlets.
Million Short allows users to remove the top 100, 1,000, or even 10 million most popular sites from search results. By filtering out the giants, it reveals the long tail of the internet, showing you what exists beyond the first page of Google. It is a powerful way to bypass the saturation of mainstream content.
Search My Site is a specialized utility that lets you search within specific domains or collections of sites. While not a general crawler, it empowers users to curate their own search environment, ensuring that results come exclusively from trusted sources or specific interest groups they define.
Mwmbl operates as a community-driven, open-source search engine. It aims to create a decentralized alternative to corporate search, where the index is built and maintained by volunteers. This model ensures transparency and prevents the centralization of information control.
Mojeek offers a completely independent crawl of the web, distinct from the indexes used by Google or Bing. It does not track users or store personal data, providing a truly private search experience. Its results are generated solely from its own database, ensuring unbiased and diverse outcomes.
These search engines prove that the internet can still be explored freely, without the constraints of massive algorithms or invasive tracking. Whether you are looking for deep research material or simply want to escape the filter bubble, they offer a refreshing alternative. If privacy matters to you, switching to one of these options is a simple but effective step.
Combine them with a good VPN and a tracker-blocking extension to further reduce your digital footprint.
#SearchEngines #PrivacyFirst #NoTracking #OpenWeb #AltSearch
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
1✍6👀4 2 1 1 1
Telegram keeps growing as a go-to platform for communication, and with that growth comes a whole ecosystem of open source intelligence tools designed to dig into publicly available data.
Whether you are a journalist tracing misinformation, a researcher mapping networks, or a security analyst profiling threats, Telegram offers a surprisingly rich surface area for investigation. The toolkit available covers everything from simple search engines to Maltego transforms that plug directly into professional workflows.
Each of these serves a slightly different purpose, so knowing which one to reach for depends on what you are looking for:
Telegago — Works like a customized Google that only indexes public Telegram content from t.me and telegram.me domains. Supports keyword searches, exact phrases, and date range filtering.
TGStat — Focuses on channel analytics, subscriber growth, and citation indexes. Ideal when you need to understand the reach and influence of a particular channel.
Telegramchannels — Maintains categorized directories of public channels, bots, and groups. Good for discovery by topic.
TelegramDB — Allows searching across channels, groups, bots, and users simultaneously from one interface.
Commentgram CSE — Indexes comments and replies inside channels, which often contain valuable intelligence that gets overlooked.
Lyzem — Offers category-filtered channel discovery with slightly different indexing than Telegago.
Telegram Nearby Map — Surfaces channels and groups tied to specific geographic coordinates. Particularly useful in investigations involving physical locations.
Telegram bots are probably the quickest way to start pulling intelligence without installing anything. They cover a wide range of functions, so here is a breakdown organized by what they actually do:
Message and media search:
@very_new_tgscan_bot — Searches indexed channels for messages and media across the platform.
Searchfirmbot — Handles channel and message discovery by keyword.
Account metadata:
Creationdatebot — Reveals when a Telegram account was registered. Surprisingly useful in building timelines.
Usernametoidbot — Converts usernames into unique numeric identifiers.
@RegDatezbot — Alternative registration date lookup tool.
Identity and cross-platform tracing:
Maigret OSINT bot — Takes a username and checks it across multiple platforms simultaneously.
EyeTON — Performs deep profile analysis on Telegram accounts.
UsInfoBot — Aggregates available user information into a single response.
Domain and infrastructure:
WhoisDomBot — Brings WHOIS domain lookups directly into the chat.
OpenDataUABot — Pulls Ukrainian business registry data tied to users or entities.
Audio and translation:
VoiceMsgBot — Converts voice messages into text, opening up audio content for analysis.
Transcriberbot — Audio transcription with broader language support.
YTranslateBot — Handles content translation when language barriers come up.
When you need to go beyond casual searching, scraping tools let you pull structured data at scale. These require more setup but deliver significantly more depth:
Telepathy — Developed by Jordan Wildon. Archives entire chat histories including replies, media, and reactions. Generates member lists of up to 5,000 users, maps forwarded message chains, looks up users by location, and exports everything to CSV. Runs from the command line and requires a Telegram API key.
TeleTracker — Provides channel activity monitoring and change tracking through simple Python scripts.
TgramSearch — Offers targeted keyword search capabilities across multiple channels.
TeleGraphite — Focuses on structured channel data extraction for further analysis.
#Telegram #OSINT #PrivacyTools #CyberSecurity #Scrapers
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
318🥰6👀5✍1 1 1
Online fraud is on the rise across Spain, with a staggering 81% increase in scams related to fake online stores reported in recent months. Cybercriminals are increasingly exploiting the popularity of e-commerce, creating convincing but fraudulent websites to steal money and personal data from unsuspecting shoppers.
These fraudulent sites often mimic legitimate retailers, offering popular products at unrealistically low prices. Once victims place an order and make a payment, they either receive nothing at all or a counterfeit item. In many cases, the scammers also harvest credit card details and personal information for further identity theft or financial fraud.
The surge coincides with peak shopping periods, including seasonal sales and holiday promotions, when consumers are more likely to browse multiple online shops looking for deals. Attackers leverage social media ads, search engine optimization tricks, and phishing emails to drive traffic to their fake storefronts.
Identifying a scam store isn't always straightforward, but several warning signs can help. Prices that seem too good to be true are often the first clue. Missing or generic contact information, lack of secure payment methods, poor grammar, and unprofessional design are also common indicators. Pay attention to domain names that slightly alter well-known brands to trick users into trusting the site.
To minimize your risk, stick to trusted retailers with verified reputations. Always check for HTTPS encryption in the URL bar, and avoid entering payment details on sites that lack proper security certificates. Use credit cards or payment services that offer buyer protection, and never share sensitive information via email or unsolicited messages.
A couple of extra checks can go a long way: look at the domain registration date of the website. Fake stores are often freshly created, so if a shop claims years of experience but the domain was registered just weeks ago, that's a major red flag. Also, pay attention to customer reviews and their age. Scam sites may post generic five-star ratings, but genuine stores usually have reviews spread out over time with real, detailed feedback. A page flooded with glowing reviews all posted within the same few days should raise suspicion.
If you suspect you've been targeted, report the incident to local authorities and your bank immediately. Many countries have dedicated cybercrime units that track and investigate such fraud.
#EcommerceScams #SpainAlert #FakeShops #CyberSafety #OnlineFraud
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
✍5👀5 1
