Researchers from Nanyang Technological University have uncovered 84 previously unknown vulnerabilities in the core software of 4G and 5G networks. Developers have already confirmed 83 of the findings, and 81 have been assigned CVE numbers. The root cause? Excessive trust assumptions between network components, a design flaw that becomes critically exposed as operators move their infrastructure to the cloud.
The vulnerabilities span across seven open-source mobile core implementations, including Open5GS, free5GC, OpenAirInterface, SD-Core, and eUPF. The flaws specifically target critical protocols like GTP-C and PFCP, responsible for session creation, data transmission, and routing rules between internal network elements. When these protocols skip proper verification, attackers can slip through the gaps and intercept traffic or disrupt services.
The researchers didn't limit themselves to open-source projects. They successfully reproduced attacks in two commercial 5G cores running default configurations. One vendor already patched the flaw, tracked as CVE-2026-8233 (4.6 Medium), while the second was still preparing a fix at the time of publication. Another confirmed issue, CVE-2026-8232 (3.5 Low), opened the door to denial of service in a commercial system.
The team behind the research described this class of problems as implicit trust errors. The most common pattern? Programs expecting mandatory fields without bothering to verify they actually exist. Other flaws let attackers inject incorrect values, break connection states, or drain internal memory until network components simply crashed and stopped responding. In some cases, malicious service messages could even be disguised as regular user traffic and routed through base stations straight into the core of the network.
Cloud systems have weakened the traditional network perimeter. A misconfigured or poorly isolated setup can leave internal interfaces wide open to attackers, turning decades of blind trust into a serious security liability.
#5GExposed #NetworkFlaws #TelcoSecurity #ZeroTrust #CyberResearch
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
2✍12😁7🥰5👀4🤷♂3🤡1🙈1
Tor has officially launched Snowflake Volunteer for Android. The setup is remarkably straightforward: download the app, tap a button, and your device instantly becomes a proxy node helping someone whose government blocks access to open internet. No complicated settings, server configurations, or midnight manual reading required. You receive nothing in return, the application simply relays data as a form of pure charitable assistance.
Snowflake traffic rides inside WebRTC, the same protocol enabling browser-based video calls and powering half of all corporate meetings. To Deep Packet Inspection systems, the data streams appear identical to routine messaging app communications. Shutting down this channel entirely would force regulators to block WebRTC across the board, an action that would cripple Zoom, Google Meet, Discord, and countless enterprise platforms at once.
This embodies the classic "collateral freedom" principle: resistance depends not just on encryption strength but on the prohibitive cost of censorship. Authorities pursue selective countermeasures instead, targeting STUN servers and hunting distinctive connection patterns rather than imposing wholesale bans.
Early 2026 saw approximately 146,000 unique volunteer proxy IPs register daily. Those numbers look impressive until you realize most are fleeting browser tabs that disappear the moment users close their websites, lasting mere minutes.
Every closed tab cuts off the person waiting on the other end, forcing them to reconnect again and again. An Android phone left charging overnight on stable Wi-Fi holds connections for around eight hours. More persistent nodes mean fewer dropped connections for anyone trying to access uncensored internet beyond the firewall.
Before volunteering, lock down your device: update the OS regularly to block malware from hijacking your proxy. Download only official releases to avoid compromised versions. For users depending on circumvention tools, stick to encrypted channels and never transmit sensitive data over unsecured links. Watch for strange battery drain or unexpected data spikes, those can signal something is wrong.
#DigitalFreedom #PrivacyTools #AntiCensorship #CyberSecurity #OpenSource #Tor
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
✍10😁3 3😈2 1
HyCanvas is a self-hosted, open-source design platform letting you create graphics, social media posts, presentations, and videos on your own infrastructure. Unlike commercial tools, it runs locally without watermarks or usage limits, keeping your creative work fully under your control.
Since HyCanvas is meant to be self-hosted, all your designs stay on your own server. Nothing gets sent to external clouds or third-party processors. The BYOK model means you provide your own API keys for AI features, so credentials and prompts never pass through a proprietary backend. This setup protects sensitive business designs and personal projects from being exposed to external servers.
Built with TypeScript, Next.js, Go, and PostgreSQL, the tool runs entirely in your browser once deployed. You can export to PNG, PDF, and other formats for both print and digital use. Production builds compile into a single Go binary, making Linux or Docker deployment straightforward. It works well for users needing data sovereignty and open standards in their design workflow.
When running self-hosted tools, keep your instance updated, use strong authentication, and restrict network access to trusted IPs. Regular backups protect your creative assets, and reviewing permissions prevents unintended exposure.
#OpenSource #SelfHosted #PrivacyFirst #DevTools #DesignSoftware
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
15👀10😁7🤔5✍4😈3 2 1
OpenCTI is an open-source solution designed to organize, analyze, and share cyber threat intelligence efficiently. It enables security teams to centralize data about attacks, malicious actors, and vulnerabilities, significantly improving incident response speed and effectiveness.
The platform facilitates structured information storage, allowing visualization of complex relationships between various threats and attacker groups. Its collaborative approach helps teams share knowledge efficiently. Additionally, OpenCTI integrates natively with international standards like STIX and TAXII, simplifying the exchange of updated intelligence within the global cybersecurity ecosystem.
OpenCTI's backend is built on Node.js and exposes a powerful GraphQL API for flexible querying. Data is managed in a graph database, complemented by Elasticsearch and/or Redis for fast searches and caching. The user interface, constructed with React, offers an interactive and smooth experience. Its microservices-based design ensures the platform is highly scalable and adaptable to diverse security environments.
#ThreatIntel #OpenSource #IncidentResponse #CyberDefense #OpenCTI
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
1👀11✍7🥰3 2
Final Results
19%
I am a cybersecurity specialist
3%
I am a software developer
8%
I'm a content creator
66%
I'm passionate about privacy and cybersecurity
4%
Other (Write in the comments)
A simple tap on what looks like an innocent link or username inside Telegram for Android can quietly trigger a Mini App and send your real IP address, User-Agent, and account details straight to the web app owner. No warning, no prompt, no permission asked. The installed Android version also gets exposed in the process, which means anyone running a vulnerable build is essentially leaking identifying information without even realizing it.
What makes this particularly concerning is how seamless the whole thing feels. You are not installing anything or granting permissions. You are just doing what millions of people do every day on Telegram: tapping a link, opening a profile. Behind that innocuous gesture, a Mini App wakes up in the background and starts transmitting technical data about your device along with profile information to a remote server.
Attackers can use the leaked IP address to approximate your geographic location, cross-reference it with other data, and build a profile that ties your anonymous Telegram identity to your real-world self. The User-Agent reveals details about your device and operating system, which makes it easier to craft targeted phishing attempts or select exploits that match your specific setup. Combine all of that with account metadata, and suddenly the anonymity that many users take for granted on Telegram starts to crumble.
Be cautious with links and usernames from unknown or unverified contacts, especially if they seem designed to grab your attention with urgency or curiosity. If you notice a Mini App unexpectedly opening after tapping something, close it right away and review your recent activity. Keeping both Telegram and your Android system fully updated is crucial, since developers tend to patch these exposure vectors once they are publicly documented.
And if you want an extra layer of protection against IP leaks, routing your traffic through a trustworthy VPN can mask your real address even if a Mini App manages to fire off a request in the background.
#Cybersecurity #Privacy #AndroidSecurity #DataLeak #MiniApp
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
2👀13✍4 2 1
Agent failures rarely occur from a single message. Instead, they emerge during extended dialogues, tool calls, and dynamic context shifts. Giskard solves precisely this problem by enabling comprehensive testing of complex AI agent behaviors.
The platform handles intricate scenarios involving multi-stage conversations where traditional testing methods fall short. It detects failures that surface during tool execution and when context changes throughout a session. The specialized verification features focus specifically on LLM-agent behavior patterns, ensuring reliability across different interaction types.
Built in Python, the framework supports cross-platform deployment. Developers can run it on Windows, Linux, or macOS systems without compatibility issues.
#Giskard #AITesting #LLM #MachineLearning #OpenSource
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
🥰10😁6 1
The main threat was hiding where people sought maximum security. Users of anonymous operating systems often trust that no program within the system will reveal their true identity, but sometimes a single flaw in the Linux kernel is enough for that to happen.
For six years, a critical vulnerability remained hidden in the Linux kernel's POSIX CPU-timer subsystem. Tracked as CVE-2026-64560, this use-after-free flaw originates from a race condition between sys_timer_delete() and a non-leader thread performing exec(), which can leave a freed timer object accessible and allow arbitrary code execution with kernel privileges.
Assigned a CVSS score of 7.0, the bug has been present since kernel version 5.7, released on May 31, 2020, affecting all versions up to 6.12.99.
In the context of Tails, the operating system designed to leave no trace and route all traffic through the Tor network, this vulnerability created a particularly dangerous loophole. As the Tails team explained plainly: "If a malicious website that you visit is able to exploit CVE-2026-64560, they might take full control of your Tails and deanonymize you."
Tails 7.10.1, released as an emergency update on August 5, 2026, didn't just fix the kernel vulnerability. It also addressed a separate critical flaw in the Expat XML parsing library, which is used by applications like LibreOffice, Audacity, and Git. If an attacker tricks a user into opening a malicious file in any of these applications, they could exploit this vulnerability to take full control of the system and de-anonymize the user as well.
Both vulnerabilities share the same alarming consequence: the complete loss of anonymity that Tails is specifically built to protect.
The Tails project notes that these attacks are very unlikely but could be carried out by a strong adversary, such as a government or a hacking firm. No confirmed in-the-wild exploitation has been reported so far, but the mere possibility that state-sponsored actors could weaponize a six-year-old kernel bug to deanonymize users is a sobering reminder of how fragile privacy can be.
If you use Tails or any Linux-based distribution focused on privacy, the most urgent step is to update to Tails 7.10.1 immediately, which ships kernel version 6.12.100 with the patch applied. Avoid opening untrusted files in applications that rely on Expat, such as LibreOffice or Audacity, until you have confirmed your system is fully updated.
Beyond updating, consider using additional isolation layers like AppArmor profiles or containers to limit the impact of potential exploits. Disabling JavaScript in the Tor Browser for untrusted sites also reduces the attack surface significantly, as many kernel exploitation techniques rely on initial access through web content.
#Tails #LinuxKernel #CVE2026 #Anonymity #Privacy
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
1🤨7🙈7✍4🤔2👀2
Law enforcement agencies across Europe are increasingly turning to sophisticated digital traps to dismantle organized crime networks operating on messaging platforms. Authorities have begun acquiring or dominating specific search terms within Telegram. When criminals search for illicit goods, services, or specialized groups, the top results are often not legitimate communities, but fictitious groups meticulously crafted and controlled by police forces. This strategy, known as a digital honeypot, lures suspects into a false sense of security, allowing investigators to gather evidence, identify participants, and execute arrests.
While these tactics have proven effective in disrupting criminal supply chains and bringing cybercriminals to justice, they raise profound questions about the integrity of the platform itself. If a user cannot trust that the group they find through search is genuine, the fundamental promise of secure communication starts to weaken. The line between a private conversation and a police operation becomes dangerously blurred. Critics argue that such practices undermine the very concept of anonymity, suggesting that even in a supposedly decentralized environment, users may be walking into a trap set by the state.
Another factor that adds complexity to this issue is Telegram's acknowledged cooperation with European law enforcement authorities. The platform has been recognized by Europol for its collaboration in fighting terrorism and child exploitation, a move many privacy advocates view with skepticism. While official statements emphasize the fight against serious crimes, the existence of these honeypot operations fuels speculation about the scope of data access and surveillance capabilities shared between the platform and authorities. Does this partnership mean Telegram is inadvertently—or perhaps intentionally—facilitating monitoring of its user base?
The emergence of these deceptive tactics serves as a stark warning that no digital space is entirely immune to surveillance. Even if you believe you are communicating securely, the destination you click on could be a fabrication designed to extract your identity. Users must remain vigilant, verifying the authenticity of channels through independent means rather than relying solely on search results. The illusion of total privacy on Telegram may be more fragile than previously thought, especially when powerful entities are actively manipulating the landscape to catch those who break the law.
#CyberSecurity #Telegram #Europol #Privacy #DigitalSurveillance
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
6✍9😁9🤔8🤮8👀6🥰2
Privacy Not A Crime
Please open Telegram to view this post
VIEW IN TELEGRAM
👀2 2
Spotting a fake image by looking at it is becoming nearly impossible these days. JPEG Audit changes the game as a free web platform that brings forensic-level analysis to anyone with a browser. Journalists, investigators, and regular people who care about privacy can now dig deep into what lies beneath a JPEG file without needing expensive software.
Three major metadata standards get analyzed at once: EXIF, IPTC, and XMP. Camera models, shutter speeds, copyright tags, and full edit histories all appear on screen. The standout feature? Embedded GPS coordinates display clearly, so you can pin down exactly where a photo originated. For anyone working with visual evidence, those details matter enormously when separating proof from fabrication.
What sets this tool apart is how far it goes beyond passive viewing. Internal JPEG markers such as DQT, DHT, SOF, and SOS segments become visible at hex level. Forensic experts rely on these to identify double compression, splicing attempts, or other tells of manipulation. The platform also catches color profile mismatches and inconsistent quality metrics, flagging suspicious images for closer inspection.
Want to compare two versions? Side-by-side mode makes differences jump out instantly. The GPS integration connects straight to Google Street View, giving you a chance to verify whether the stated location actually matches the scene in the photograph. Fact-checkers use this daily to bust viral hoaxes, and investigators trace questionable images back to their real origin.
Photos carry hidden information about your device, location, and sometimes even your editing history. Running a quick check before posting helps you understand what you are broadcasting to the world. Strip GPS coordinates from personal travel photos at minimum. Remember that some metadata survives basic removal, making regular checks more of a habit than a one-time fix.
Journalists validate user-submitted images before publication. OSINT researchers track origins and confirm location claims. Cybersecurity analysts perform forensics on suspect files. Legal teams examine photographic evidence during disputes. Photographers discover what private data their uploads expose without realizing it.
What once required specialist software now lives in any browser. Whether you fight misinformation or guard personal privacy, JPEG Audit brings much-needed clarity to digital image verification.
#JPEGAudit #Forensics #Metadata #OSINT #Privacy
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
6😁8🥰5 2 1
Many users think that because Telegram offers cloud storage and fast messaging, their data stays safe. But what the platform collects and keeps is very different from the idea of total privacy. Knowing what gets collected matters if you care about your online privacy.
Unlike end-to-end encrypted messengers where only the participants hold the keys, Telegram's standard chats live on its servers in plain text. This means the service can see the content of your private conversations, including texts, photos, and documents sent in regular chats. While "secret chats" do offer end-to-end encryption, they are not enabled by default and miss key features like cloud sync.
Beyond just messages, Telegram keeps tabs on your activity. The service tracks signals about profiles you interact with, channels you subscribe to, and groups you join. This paints a detailed picture of your interests and communities. Even after you leave a group or channel, traces of your participation may still stay in their systems. Any comments you post in groups or channels get stored and could be reviewed later.
The bigger privacy worry sits in metadata. Telegram gathers info about your device, phone number, and contacts. They study interaction patterns, login times, and usage frequency to build behavioral profiles. On top of that, the app can track which stories and posts you scroll through in channels, letting them watch your content habits beyond who you simply follow.
Here's what matters most: Telegram has confirmed it works with governmental authorities around the world. Data can be shared with law enforcement when valid legal requests arrive, though how transparent this process is depends heavily on the country involved.
Since Telegram holds so much data, you're better off limiting it to entertainment—like following public channels for news or memes where privacy isn't critical. For anything sensitive, money-related, or truly private, you're safer switching to an app that encrypts everything by default. Signal stands out here, making sure neither the service nor anyone else can read your messages or see your metadata.
If you must stick with Telegram, turning on "two-step verification" and using "secret chats" for sensitive topics are must-do security steps. Still, these won't wipe out all the risks built into Telegram's architecture.
#TelegramPrivacy #DataSecurity #Signal #DigitalRights #CyberAware
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
2✍9👀5 1
This media is not supported in your browser
VIEW IN TELEGRAM
This week was far from quiet: the Shai-Hulud worm infected a thousand npm packages with two billion downloads, hackers breached water treatment plants across a dozen U.S. states, and the White House quietly moved advanced AI development into a closed regime.
We've gathered the most interesting stories of the week in one place so you don't miss anything.
#CyberSecurity #SupplyChainAttacks #AIRegulation #CriticalInfrastructure #DataPrivacy
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
👀11🤔6✍5😁5 1
While giants like Google dominate the digital landscape, they often filter out smaller, niche, or older sites in favor of SEO-optimized content and commercial interests. This creates a blind spot where valuable information gets lost.
Fortunately, there are alternative search engines dedicated to uncovering these hidden corners of the web while respecting user privacy. Unlike their mainstream counterparts, they do not track your history or build profiles for advertising.
The modern internet is vast, yet much of it remains invisible to standard algorithms. Large search engines prioritize relevance based on popularity and monetization potential, effectively burying independent blogs, academic archives, and legacy websites. The six search engines highlighted below aim to reverse this trend, offering unique indexing strategies that cater to researchers, privacy advocates, and anyone tired of algorithmic echo chambers.
They focus on raw data, human-curated results, and the preservation of digital diversity.
Marginalia Search stands out by specifically targeting sites that lack professional design but hold valuable content. It ignores SEO tricks and visual polish, focusing instead on the text and structure of pages that are often overlooked. It is an excellent choice for finding genuine discussions and obscure resources without the noise of commercial spam.
Wiby takes a different approach by indexing only small websites. It excludes large corporations and popular domains, ensuring that the results come from individual creators and niche communities. This makes it a treasure trove for authentic voices that would otherwise be drowned out by major media outlets.
Million Short allows users to remove the top 100, 1,000, or even 10 million most popular sites from search results. By filtering out the giants, it reveals the long tail of the internet, showing you what exists beyond the first page of Google. It is a powerful way to bypass the saturation of mainstream content.
Search My Site is a specialized utility that lets you search within specific domains or collections of sites. While not a general crawler, it empowers users to curate their own search environment, ensuring that results come exclusively from trusted sources or specific interest groups they define.
Mwmbl operates as a community-driven, open-source search engine. It aims to create a decentralized alternative to corporate search, where the index is built and maintained by volunteers. This model ensures transparency and prevents the centralization of information control.
Mojeek offers a completely independent crawl of the web, distinct from the indexes used by Google or Bing. It does not track users or store personal data, providing a truly private search experience. Its results are generated solely from its own database, ensuring unbiased and diverse outcomes.
These search engines prove that the internet can still be explored freely, without the constraints of massive algorithms or invasive tracking. Whether you are looking for deep research material or simply want to escape the filter bubble, they offer a refreshing alternative. If privacy matters to you, switching to one of these options is a simple but effective step.
Combine them with a good VPN and a tracker-blocking extension to further reduce your digital footprint.
#SearchEngines #PrivacyFirst #NoTracking #OpenWeb #AltSearch
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
1✍6👀4 2 1 1 1
Telegram keeps growing as a go-to platform for communication, and with that growth comes a whole ecosystem of open source intelligence tools designed to dig into publicly available data.
Whether you are a journalist tracing misinformation, a researcher mapping networks, or a security analyst profiling threats, Telegram offers a surprisingly rich surface area for investigation. The toolkit available covers everything from simple search engines to Maltego transforms that plug directly into professional workflows.
Each of these serves a slightly different purpose, so knowing which one to reach for depends on what you are looking for:
Telegago — Works like a customized Google that only indexes public Telegram content from t.me and telegram.me domains. Supports keyword searches, exact phrases, and date range filtering.
TGStat — Focuses on channel analytics, subscriber growth, and citation indexes. Ideal when you need to understand the reach and influence of a particular channel.
Telegramchannels — Maintains categorized directories of public channels, bots, and groups. Good for discovery by topic.
TelegramDB — Allows searching across channels, groups, bots, and users simultaneously from one interface.
Commentgram CSE — Indexes comments and replies inside channels, which often contain valuable intelligence that gets overlooked.
Lyzem — Offers category-filtered channel discovery with slightly different indexing than Telegago.
Telegram Nearby Map — Surfaces channels and groups tied to specific geographic coordinates. Particularly useful in investigations involving physical locations.
Telegram bots are probably the quickest way to start pulling intelligence without installing anything. They cover a wide range of functions, so here is a breakdown organized by what they actually do:
Message and media search:
@very_new_tgscan_bot — Searches indexed channels for messages and media across the platform.
Searchfirmbot — Handles channel and message discovery by keyword.
Account metadata:
Creationdatebot — Reveals when a Telegram account was registered. Surprisingly useful in building timelines.
Usernametoidbot — Converts usernames into unique numeric identifiers.
@RegDatezbot — Alternative registration date lookup tool.
Identity and cross-platform tracing:
Maigret OSINT bot — Takes a username and checks it across multiple platforms simultaneously.
EyeTON — Performs deep profile analysis on Telegram accounts.
UsInfoBot — Aggregates available user information into a single response.
Domain and infrastructure:
WhoisDomBot — Brings WHOIS domain lookups directly into the chat.
OpenDataUABot — Pulls Ukrainian business registry data tied to users or entities.
Audio and translation:
VoiceMsgBot — Converts voice messages into text, opening up audio content for analysis.
Transcriberbot — Audio transcription with broader language support.
YTranslateBot — Handles content translation when language barriers come up.
When you need to go beyond casual searching, scraping tools let you pull structured data at scale. These require more setup but deliver significantly more depth:
Telepathy — Developed by Jordan Wildon. Archives entire chat histories including replies, media, and reactions. Generates member lists of up to 5,000 users, maps forwarded message chains, looks up users by location, and exports everything to CSV. Runs from the command line and requires a Telegram API key.
TeleTracker — Provides channel activity monitoring and change tracking through simple Python scripts.
TgramSearch — Offers targeted keyword search capabilities across multiple channels.
TeleGraphite — Focuses on structured channel data extraction for further analysis.
#Telegram #OSINT #PrivacyTools #CyberSecurity #Scrapers
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
318🥰6👀5✍1 1 1
Online fraud is on the rise across Spain, with a staggering 81% increase in scams related to fake online stores reported in recent months. Cybercriminals are increasingly exploiting the popularity of e-commerce, creating convincing but fraudulent websites to steal money and personal data from unsuspecting shoppers.
These fraudulent sites often mimic legitimate retailers, offering popular products at unrealistically low prices. Once victims place an order and make a payment, they either receive nothing at all or a counterfeit item. In many cases, the scammers also harvest credit card details and personal information for further identity theft or financial fraud.
The surge coincides with peak shopping periods, including seasonal sales and holiday promotions, when consumers are more likely to browse multiple online shops looking for deals. Attackers leverage social media ads, search engine optimization tricks, and phishing emails to drive traffic to their fake storefronts.
Identifying a scam store isn't always straightforward, but several warning signs can help. Prices that seem too good to be true are often the first clue. Missing or generic contact information, lack of secure payment methods, poor grammar, and unprofessional design are also common indicators. Pay attention to domain names that slightly alter well-known brands to trick users into trusting the site.
To minimize your risk, stick to trusted retailers with verified reputations. Always check for HTTPS encryption in the URL bar, and avoid entering payment details on sites that lack proper security certificates. Use credit cards or payment services that offer buyer protection, and never share sensitive information via email or unsolicited messages.
A couple of extra checks can go a long way: look at the domain registration date of the website. Fake stores are often freshly created, so if a shop claims years of experience but the domain was registered just weeks ago, that's a major red flag. Also, pay attention to customer reviews and their age. Scam sites may post generic five-star ratings, but genuine stores usually have reviews spread out over time with real, detailed feedback. A page flooded with glowing reviews all posted within the same few days should raise suspicion.
If you suspect you've been targeted, report the incident to local authorities and your bank immediately. Many countries have dedicated cybercrime units that track and investigate such fraud.
#EcommerceScams #SpainAlert #FakeShops #CyberSafety #OnlineFraud
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
✍5👀5 1
Security researchers need tools that balance power with privacy when testing web applications. Reqlore emerges as a comprehensive local pentesting platform offering proxy, repeater, intruder, decoder, and scanner capabilities in a unified interface that serves as an accessible alternative to commercial solutions like Burp Suite.
The suite operates through distinct panels handling different aspects of security work. The Proxy module intercepts traffic between browser and target application while History maintains complete request logs for analysis. Repeater enables manual refinement and replay of individual HTTP requests, and Intruder automates payload injection across multiple parameters. Meanwhile the Scanner component identifies known vulnerability patterns and Decoder handles various encoding formats for proper payload preparation.
Reqlore stands out with six different request engine options giving operators flexibility in how they interact with targets. Users can select between httpx, raw, h3 for HTTP/3 testing, and curl-cffi backends depending on specific requirements. This modularity enables bypassing certain network restrictions or testing protocol-specific behaviors that single-engine tools simply cannot address effectively.
Multiple installation approaches support different workflows including Docker deployment and manual Python setup. Containerized environments keep configuration files in a dedicated data directory while authentication relies on argon2id password hashing that never stores plaintext credentials on disk. Debian and Ubuntu users benefit from an installation script handling dependency management automatically.
Tools like Reqlore highlight the importance of robust defensive postures for web applications. Organizations should configure Web Application Firewalls to detect rapid-fire probing patterns, hide administrative interfaces behind strong authentication and IP whitelisting, enable comprehensive logging with real-time alerting for suspicious request volumes, and enforce rate limiting on all public-facing endpoints to slow automated enumeration attempts.
Unlike many security tools overlooking inclusive design, Reqlore integrates accessibility directly into its architecture following WCAG 2.2 AA standards with AAA-strict patterns. The interface ensures compatibility with screen readers including NVDA, JAWS, Orca and VoiceOver, making professional security testing accessible to practitioners with disabilities who previously faced barriers using traditional platforms.
#CyberSecurity #PenTesting #BugBounty #InfoSec #WebSecurity
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
5✍7👀4 1 1
How many times have you shared a link only to find out later that the content was edited or simply disappeared? We've all been there. Archive.ph solves exactly that problem by taking a permanent snapshot of any webpage, preserving both its text and visual layout exactly as it appeared at a given moment. No edits, no deletions, no surprises.
The concept is simple but powerful. When you paste a URL into Archive.ph, the service downloads the page content along with a graphical copy for maximum accuracy. What makes it especially useful is that it strips out all active scripts, pop-ups, and interactive elements from the saved version.
This means the archived page is not only permanent but also completely safe to open, since there's no hidden malware or trackers lurking behind it. You get a short, clean link to an unalterable record.
Here's where things get interesting. When you view a page through Archive.ph, you never actually connect to the original server. The content lives on their infrastructure, which means the target site can't log your IP, track your behavior, or plant cookies on you. For anyone who cares about digital privacy, that's a big deal. You can access content that might be geoblocked in your region without revealing your real location, and since all dynamic scripts are removed, there's no risk of client-side exploits running in the background.
Think about a journalist needing to preserve a politician's tweet before it gets deleted under pressure. Or a lawyer capturing terms of service right before a company quietly rewrites them. Even in everyday life, it comes handy more than you'd expect: saving a job listing before it's taken down, archiving a rental ad that seems too good to be true, or keeping a record of a forum post that could vanish overnight.
Even though Archive.ph gives you a script-free, sanitized view of any page, common sense still applies. Always double-check the URL before archiving to make sure you're capturing the right content. Keep in mind that the original site remains untouched, so don't let your guard down if you later visit the live version. And for extra privacy, consider pairing it with a VPN so not even your connection to the archive itself can be traced back to you.
#Cybersecurity #DigitalPrivacy #WebArchives #InfoSec #OnlineSafety
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
✍6👀3 2 1
The United States has officially declared a state of emergency following a severe cyberattack targeting local police infrastructure. The incident has disrupted critical communication channels and forced authorities to revert to manual operations while security teams work to isolate the breach.
In response to the escalating situation, the city council has formally requested immediate intervention from the Federal Bureau of Investigation (FBI).
Federal agents are now leading the forensic analysis to identify the threat actors and determine the extent of the compromise.
This move underscores the growing reliance on federal resources when local digital defenses are overwhelmed.
This event highlights a critical vulnerability in modern municipal governance: when essential city services depend on a single digital infrastructure, a failure in one component can cascade rapidly beyond just computers. From dispatch systems to evidence databases, the interconnected nature of these networks means that a localized malware infection can paralyze an entire department's ability to respond to public safety needs. Experts warn that without redundant, air-gapped backup systems, such attacks pose a direct threat to community safety.
#CyberEmergency #PoliceHack #DigitalSafety #FBIInvestigation #Critical
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
🤔5😁2 2
Think the SIM card in your phone is just for your carrier? Think again. Behind that small chip lies a miniature computer capable of sending commands directly to your device's modem.
In the wrong hands, this can lead to serious trouble, even on a locked Android phone.
The issue stems from the AT command protocol, a system originally designed in the 1980s for dial-up modems. Decades later, millions of smartphones still rely on this legacy infrastructure. Security researchers have discovered how a maliciously crafted SIM can exploit this inherent trust, injecting commands that bypass Android's lock screen protections. The implications are severe: unauthorized access to messages, location tracking, and network manipulation can occur without ever needing your passcode.
The vulnerability lies within the SIM Application Toolkit, a legitimate feature intended to allow your SIM to interact with phone menus for tasks like checking your balance. However, when developers fail to properly validate these interactions, the toolkit transforms into a backdoor.
Since most modems are designed to inherently trust commands originating from the SIM, a compromised card can execute harmful operations immediately. This means anyone with physical access to your device or someone who convinces you to swap in a fake SIM could gain unexpected control over your communications.
Fortunately, manufacturers are gradually rolling out patches, though the vast number of affected devices means many remain exposed. You can significantly reduce your risk by obtaining SIM cards exclusively from official carriers and avoiding unknown sources.
Keeping your firmware updated is crucial, particularly regarding modem security. If your phone supports eSIM, switching to it eliminates the physical slot entirely, effectively cutting off this attack vector. Additionally, if you notice unusual behavior such as random network disconnections or suspicious text activity, investigate immediately.
#AndroidSecurity #SIMVulnerability #MobilePrivacy #CyberThreats #TechSafety
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
👌7👀3 1
Privacy Not A Crime
Please open Telegram to view this post
VIEW IN TELEGRAM