The main threat was hiding where people sought maximum security. Users of anonymous operating systems often trust that no program within the system will reveal their true identity, but sometimes a single flaw in the Linux kernel is enough for that to happen.
For six years, a critical vulnerability remained hidden in the Linux kernel's POSIX CPU-timer subsystem. Tracked as CVE-2026-64560, this use-after-free flaw originates from a race condition between sys_timer_delete() and a non-leader thread performing exec(), which can leave a freed timer object accessible and allow arbitrary code execution with kernel privileges.
Assigned a CVSS score of 7.0, the bug has been present since kernel version 5.7, released on May 31, 2020, affecting all versions up to 6.12.99.
In the context of Tails, the operating system designed to leave no trace and route all traffic through the Tor network, this vulnerability created a particularly dangerous loophole. As the Tails team explained plainly: "If a malicious website that you visit is able to exploit CVE-2026-64560, they might take full control of your Tails and deanonymize you."
Tails 7.10.1, released as an emergency update on August 5, 2026, didn't just fix the kernel vulnerability. It also addressed a separate critical flaw in the Expat XML parsing library, which is used by applications like LibreOffice, Audacity, and Git. If an attacker tricks a user into opening a malicious file in any of these applications, they could exploit this vulnerability to take full control of the system and de-anonymize the user as well.
Both vulnerabilities share the same alarming consequence: the complete loss of anonymity that Tails is specifically built to protect.
The Tails project notes that these attacks are very unlikely but could be carried out by a strong adversary, such as a government or a hacking firm. No confirmed in-the-wild exploitation has been reported so far, but the mere possibility that state-sponsored actors could weaponize a six-year-old kernel bug to deanonymize users is a sobering reminder of how fragile privacy can be.
If you use Tails or any Linux-based distribution focused on privacy, the most urgent step is to update to Tails 7.10.1 immediately, which ships kernel version 6.12.100 with the patch applied. Avoid opening untrusted files in applications that rely on Expat, such as LibreOffice or Audacity, until you have confirmed your system is fully updated.
Beyond updating, consider using additional isolation layers like AppArmor profiles or containers to limit the impact of potential exploits. Disabling JavaScript in the Tor Browser for untrusted sites also reduces the attack surface significantly, as many kernel exploitation techniques rely on initial access through web content.
#Tails #LinuxKernel #CVE2026 #Anonymity #Privacy
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
1๐คจ7๐7โ4๐ค2๐2
Law enforcement agencies across Europe are increasingly turning to sophisticated digital traps to dismantle organized crime networks operating on messaging platforms. Authorities have begun acquiring or dominating specific search terms within Telegram. When criminals search for illicit goods, services, or specialized groups, the top results are often not legitimate communities, but fictitious groups meticulously crafted and controlled by police forces. This strategy, known as a digital honeypot, lures suspects into a false sense of security, allowing investigators to gather evidence, identify participants, and execute arrests.
While these tactics have proven effective in disrupting criminal supply chains and bringing cybercriminals to justice, they raise profound questions about the integrity of the platform itself. If a user cannot trust that the group they find through search is genuine, the fundamental promise of secure communication starts to weaken. The line between a private conversation and a police operation becomes dangerously blurred. Critics argue that such practices undermine the very concept of anonymity, suggesting that even in a supposedly decentralized environment, users may be walking into a trap set by the state.
Another factor that adds complexity to this issue is Telegram's acknowledged cooperation with European law enforcement authorities. The platform has been recognized by Europol for its collaboration in fighting terrorism and child exploitation, a move many privacy advocates view with skepticism. While official statements emphasize the fight against serious crimes, the existence of these honeypot operations fuels speculation about the scope of data access and surveillance capabilities shared between the platform and authorities. Does this partnership mean Telegram is inadvertentlyโor perhaps intentionallyโfacilitating monitoring of its user base?
The emergence of these deceptive tactics serves as a stark warning that no digital space is entirely immune to surveillance. Even if you believe you are communicating securely, the destination you click on could be a fabrication designed to extract your identity. Users must remain vigilant, verifying the authenticity of channels through independent means rather than relying solely on search results. The illusion of total privacy on Telegram may be more fragile than previously thought, especially when powerful entities are actively manipulating the landscape to catch those who break the law.
#CyberSecurity #Telegram #Europol #Privacy #DigitalSurveillance
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
6โ9๐9๐ค8๐คฎ8๐6๐ฅฐ2
Privacy Not A Crime
Please open Telegram to view this post
VIEW IN TELEGRAM
๐2 2
Spotting a fake image by looking at it is becoming nearly impossible these days. JPEG Audit changes the game as a free web platform that brings forensic-level analysis to anyone with a browser. Journalists, investigators, and regular people who care about privacy can now dig deep into what lies beneath a JPEG file without needing expensive software.
Three major metadata standards get analyzed at once: EXIF, IPTC, and XMP. Camera models, shutter speeds, copyright tags, and full edit histories all appear on screen. The standout feature? Embedded GPS coordinates display clearly, so you can pin down exactly where a photo originated. For anyone working with visual evidence, those details matter enormously when separating proof from fabrication.
What sets this tool apart is how far it goes beyond passive viewing. Internal JPEG markers such as DQT, DHT, SOF, and SOS segments become visible at hex level. Forensic experts rely on these to identify double compression, splicing attempts, or other tells of manipulation. The platform also catches color profile mismatches and inconsistent quality metrics, flagging suspicious images for closer inspection.
Want to compare two versions? Side-by-side mode makes differences jump out instantly. The GPS integration connects straight to Google Street View, giving you a chance to verify whether the stated location actually matches the scene in the photograph. Fact-checkers use this daily to bust viral hoaxes, and investigators trace questionable images back to their real origin.
Photos carry hidden information about your device, location, and sometimes even your editing history. Running a quick check before posting helps you understand what you are broadcasting to the world. Strip GPS coordinates from personal travel photos at minimum. Remember that some metadata survives basic removal, making regular checks more of a habit than a one-time fix.
Journalists validate user-submitted images before publication. OSINT researchers track origins and confirm location claims. Cybersecurity analysts perform forensics on suspect files. Legal teams examine photographic evidence during disputes. Photographers discover what private data their uploads expose without realizing it.
What once required specialist software now lives in any browser. Whether you fight misinformation or guard personal privacy, JPEG Audit brings much-needed clarity to digital image verification.
#JPEGAudit #Forensics #Metadata #OSINT #Privacy
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
6๐8๐ฅฐ5 2 1
Many users think that because Telegram offers cloud storage and fast messaging, their data stays safe. But what the platform collects and keeps is very different from the idea of total privacy. Knowing what gets collected matters if you care about your online privacy.
Unlike end-to-end encrypted messengers where only the participants hold the keys, Telegram's standard chats live on its servers in plain text. This means the service can see the content of your private conversations, including texts, photos, and documents sent in regular chats. While "secret chats" do offer end-to-end encryption, they are not enabled by default and miss key features like cloud sync.
Beyond just messages, Telegram keeps tabs on your activity. The service tracks signals about profiles you interact with, channels you subscribe to, and groups you join. This paints a detailed picture of your interests and communities. Even after you leave a group or channel, traces of your participation may still stay in their systems. Any comments you post in groups or channels get stored and could be reviewed later.
The bigger privacy worry sits in metadata. Telegram gathers info about your device, phone number, and contacts. They study interaction patterns, login times, and usage frequency to build behavioral profiles. On top of that, the app can track which stories and posts you scroll through in channels, letting them watch your content habits beyond who you simply follow.
Here's what matters most: Telegram has confirmed it works with governmental authorities around the world. Data can be shared with law enforcement when valid legal requests arrive, though how transparent this process is depends heavily on the country involved.
Since Telegram holds so much data, you're better off limiting it to entertainmentโlike following public channels for news or memes where privacy isn't critical. For anything sensitive, money-related, or truly private, you're safer switching to an app that encrypts everything by default. Signal stands out here, making sure neither the service nor anyone else can read your messages or see your metadata.
If you must stick with Telegram, turning on "two-step verification" and using "secret chats" for sensitive topics are must-do security steps. Still, these won't wipe out all the risks built into Telegram's architecture.
#TelegramPrivacy #DataSecurity #Signal #DigitalRights #CyberAware
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
2โ9๐5 1
This media is not supported in your browser
VIEW IN TELEGRAM
This week was far from quiet: the Shai-Hulud worm infected a thousand npm packages with two billion downloads, hackers breached water treatment plants across a dozen U.S. states, and the White House quietly moved advanced AI development into a closed regime.
We've gathered the most interesting stories of the week in one place so you don't miss anything.
#CyberSecurity #SupplyChainAttacks #AIRegulation #CriticalInfrastructure #DataPrivacy
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
๐11๐ค6โ5๐5 1
While giants like Google dominate the digital landscape, they often filter out smaller, niche, or older sites in favor of SEO-optimized content and commercial interests. This creates a blind spot where valuable information gets lost.
Fortunately, there are alternative search engines dedicated to uncovering these hidden corners of the web while respecting user privacy. Unlike their mainstream counterparts, they do not track your history or build profiles for advertising.
The modern internet is vast, yet much of it remains invisible to standard algorithms. Large search engines prioritize relevance based on popularity and monetization potential, effectively burying independent blogs, academic archives, and legacy websites. The six search engines highlighted below aim to reverse this trend, offering unique indexing strategies that cater to researchers, privacy advocates, and anyone tired of algorithmic echo chambers.
They focus on raw data, human-curated results, and the preservation of digital diversity.
Marginalia Search stands out by specifically targeting sites that lack professional design but hold valuable content. It ignores SEO tricks and visual polish, focusing instead on the text and structure of pages that are often overlooked. It is an excellent choice for finding genuine discussions and obscure resources without the noise of commercial spam.
Wiby takes a different approach by indexing only small websites. It excludes large corporations and popular domains, ensuring that the results come from individual creators and niche communities. This makes it a treasure trove for authentic voices that would otherwise be drowned out by major media outlets.
Million Short allows users to remove the top 100, 1,000, or even 10 million most popular sites from search results. By filtering out the giants, it reveals the long tail of the internet, showing you what exists beyond the first page of Google. It is a powerful way to bypass the saturation of mainstream content.
Search My Site is a specialized utility that lets you search within specific domains or collections of sites. While not a general crawler, it empowers users to curate their own search environment, ensuring that results come exclusively from trusted sources or specific interest groups they define.
Mwmbl operates as a community-driven, open-source search engine. It aims to create a decentralized alternative to corporate search, where the index is built and maintained by volunteers. This model ensures transparency and prevents the centralization of information control.
Mojeek offers a completely independent crawl of the web, distinct from the indexes used by Google or Bing. It does not track users or store personal data, providing a truly private search experience. Its results are generated solely from its own database, ensuring unbiased and diverse outcomes.
These search engines prove that the internet can still be explored freely, without the constraints of massive algorithms or invasive tracking. Whether you are looking for deep research material or simply want to escape the filter bubble, they offer a refreshing alternative. If privacy matters to you, switching to one of these options is a simple but effective step.
Combine them with a good VPN and a tracker-blocking extension to further reduce your digital footprint.
#SearchEngines #PrivacyFirst #NoTracking #OpenWeb #AltSearch
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
1โ6๐4 2 1 1 1
Telegram keeps growing as a go-to platform for communication, and with that growth comes a whole ecosystem of open source intelligence tools designed to dig into publicly available data.
Whether you are a journalist tracing misinformation, a researcher mapping networks, or a security analyst profiling threats, Telegram offers a surprisingly rich surface area for investigation. The toolkit available covers everything from simple search engines to Maltego transforms that plug directly into professional workflows.
Each of these serves a slightly different purpose, so knowing which one to reach for depends on what you are looking for:
Telegago โ Works like a customized Google that only indexes public Telegram content from t.me and telegram.me domains. Supports keyword searches, exact phrases, and date range filtering.
TGStat โ Focuses on channel analytics, subscriber growth, and citation indexes. Ideal when you need to understand the reach and influence of a particular channel.
Telegramchannels โ Maintains categorized directories of public channels, bots, and groups. Good for discovery by topic.
TelegramDB โ Allows searching across channels, groups, bots, and users simultaneously from one interface.
Commentgram CSE โ Indexes comments and replies inside channels, which often contain valuable intelligence that gets overlooked.
Lyzem โ Offers category-filtered channel discovery with slightly different indexing than Telegago.
Telegram Nearby Map โ Surfaces channels and groups tied to specific geographic coordinates. Particularly useful in investigations involving physical locations.
Telegram bots are probably the quickest way to start pulling intelligence without installing anything. They cover a wide range of functions, so here is a breakdown organized by what they actually do:
Message and media search:
@very_new_tgscan_bot โ Searches indexed channels for messages and media across the platform.
Searchfirmbot โ Handles channel and message discovery by keyword.
Account metadata:
Creationdatebot โ Reveals when a Telegram account was registered. Surprisingly useful in building timelines.
Usernametoidbot โ Converts usernames into unique numeric identifiers.
@RegDatezbot โ Alternative registration date lookup tool.
Identity and cross-platform tracing:
Maigret OSINT bot โ Takes a username and checks it across multiple platforms simultaneously.
EyeTON โ Performs deep profile analysis on Telegram accounts.
UsInfoBot โ Aggregates available user information into a single response.
Domain and infrastructure:
WhoisDomBot โ Brings WHOIS domain lookups directly into the chat.
OpenDataUABot โ Pulls Ukrainian business registry data tied to users or entities.
Audio and translation:
VoiceMsgBot โ Converts voice messages into text, opening up audio content for analysis.
Transcriberbot โ Audio transcription with broader language support.
YTranslateBot โ Handles content translation when language barriers come up.
When you need to go beyond casual searching, scraping tools let you pull structured data at scale. These require more setup but deliver significantly more depth:
Telepathy โ Developed by Jordan Wildon. Archives entire chat histories including replies, media, and reactions. Generates member lists of up to 5,000 users, maps forwarded message chains, looks up users by location, and exports everything to CSV. Runs from the command line and requires a Telegram API key.
TeleTracker โ Provides channel activity monitoring and change tracking through simple Python scripts.
TgramSearch โ Offers targeted keyword search capabilities across multiple channels.
TeleGraphite โ Focuses on structured channel data extraction for further analysis.
#Telegram #OSINT #PrivacyTools #CyberSecurity #Scrapers
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
318๐ฅฐ6๐5โ1 1 1
Online fraud is on the rise across Spain, with a staggering 81% increase in scams related to fake online stores reported in recent months. Cybercriminals are increasingly exploiting the popularity of e-commerce, creating convincing but fraudulent websites to steal money and personal data from unsuspecting shoppers.
These fraudulent sites often mimic legitimate retailers, offering popular products at unrealistically low prices. Once victims place an order and make a payment, they either receive nothing at all or a counterfeit item. In many cases, the scammers also harvest credit card details and personal information for further identity theft or financial fraud.
The surge coincides with peak shopping periods, including seasonal sales and holiday promotions, when consumers are more likely to browse multiple online shops looking for deals. Attackers leverage social media ads, search engine optimization tricks, and phishing emails to drive traffic to their fake storefronts.
Identifying a scam store isn't always straightforward, but several warning signs can help. Prices that seem too good to be true are often the first clue. Missing or generic contact information, lack of secure payment methods, poor grammar, and unprofessional design are also common indicators. Pay attention to domain names that slightly alter well-known brands to trick users into trusting the site.
To minimize your risk, stick to trusted retailers with verified reputations. Always check for HTTPS encryption in the URL bar, and avoid entering payment details on sites that lack proper security certificates. Use credit cards or payment services that offer buyer protection, and never share sensitive information via email or unsolicited messages.
A couple of extra checks can go a long way: look at the domain registration date of the website. Fake stores are often freshly created, so if a shop claims years of experience but the domain was registered just weeks ago, that's a major red flag. Also, pay attention to customer reviews and their age. Scam sites may post generic five-star ratings, but genuine stores usually have reviews spread out over time with real, detailed feedback. A page flooded with glowing reviews all posted within the same few days should raise suspicion.
If you suspect you've been targeted, report the incident to local authorities and your bank immediately. Many countries have dedicated cybercrime units that track and investigate such fraud.
#EcommerceScams #SpainAlert #FakeShops #CyberSafety #OnlineFraud
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
โ5๐5 1
Security researchers need tools that balance power with privacy when testing web applications. Reqlore emerges as a comprehensive local pentesting platform offering proxy, repeater, intruder, decoder, and scanner capabilities in a unified interface that serves as an accessible alternative to commercial solutions like Burp Suite.
The suite operates through distinct panels handling different aspects of security work. The Proxy module intercepts traffic between browser and target application while History maintains complete request logs for analysis. Repeater enables manual refinement and replay of individual HTTP requests, and Intruder automates payload injection across multiple parameters. Meanwhile the Scanner component identifies known vulnerability patterns and Decoder handles various encoding formats for proper payload preparation.
Reqlore stands out with six different request engine options giving operators flexibility in how they interact with targets. Users can select between httpx, raw, h3 for HTTP/3 testing, and curl-cffi backends depending on specific requirements. This modularity enables bypassing certain network restrictions or testing protocol-specific behaviors that single-engine tools simply cannot address effectively.
Multiple installation approaches support different workflows including Docker deployment and manual Python setup. Containerized environments keep configuration files in a dedicated data directory while authentication relies on argon2id password hashing that never stores plaintext credentials on disk. Debian and Ubuntu users benefit from an installation script handling dependency management automatically.
Tools like Reqlore highlight the importance of robust defensive postures for web applications. Organizations should configure Web Application Firewalls to detect rapid-fire probing patterns, hide administrative interfaces behind strong authentication and IP whitelisting, enable comprehensive logging with real-time alerting for suspicious request volumes, and enforce rate limiting on all public-facing endpoints to slow automated enumeration attempts.
Unlike many security tools overlooking inclusive design, Reqlore integrates accessibility directly into its architecture following WCAG 2.2 AA standards with AAA-strict patterns. The interface ensures compatibility with screen readers including NVDA, JAWS, Orca and VoiceOver, making professional security testing accessible to practitioners with disabilities who previously faced barriers using traditional platforms.
#CyberSecurity #PenTesting #BugBounty #InfoSec #WebSecurity
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
5โ7๐4 1 1
How many times have you shared a link only to find out later that the content was edited or simply disappeared? We've all been there. Archive.ph solves exactly that problem by taking a permanent snapshot of any webpage, preserving both its text and visual layout exactly as it appeared at a given moment. No edits, no deletions, no surprises.
The concept is simple but powerful. When you paste a URL into Archive.ph, the service downloads the page content along with a graphical copy for maximum accuracy. What makes it especially useful is that it strips out all active scripts, pop-ups, and interactive elements from the saved version.
This means the archived page is not only permanent but also completely safe to open, since there's no hidden malware or trackers lurking behind it. You get a short, clean link to an unalterable record.
Here's where things get interesting. When you view a page through Archive.ph, you never actually connect to the original server. The content lives on their infrastructure, which means the target site can't log your IP, track your behavior, or plant cookies on you. For anyone who cares about digital privacy, that's a big deal. You can access content that might be geoblocked in your region without revealing your real location, and since all dynamic scripts are removed, there's no risk of client-side exploits running in the background.
Think about a journalist needing to preserve a politician's tweet before it gets deleted under pressure. Or a lawyer capturing terms of service right before a company quietly rewrites them. Even in everyday life, it comes handy more than you'd expect: saving a job listing before it's taken down, archiving a rental ad that seems too good to be true, or keeping a record of a forum post that could vanish overnight.
Even though Archive.ph gives you a script-free, sanitized view of any page, common sense still applies. Always double-check the URL before archiving to make sure you're capturing the right content. Keep in mind that the original site remains untouched, so don't let your guard down if you later visit the live version. And for extra privacy, consider pairing it with a VPN so not even your connection to the archive itself can be traced back to you.
#Cybersecurity #DigitalPrivacy #WebArchives #InfoSec #OnlineSafety
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
โ6๐3 2 1
The United States has officially declared a state of emergency following a severe cyberattack targeting local police infrastructure. The incident has disrupted critical communication channels and forced authorities to revert to manual operations while security teams work to isolate the breach.
In response to the escalating situation, the city council has formally requested immediate intervention from the Federal Bureau of Investigation (FBI).
Federal agents are now leading the forensic analysis to identify the threat actors and determine the extent of the compromise.
This move underscores the growing reliance on federal resources when local digital defenses are overwhelmed.
This event highlights a critical vulnerability in modern municipal governance: when essential city services depend on a single digital infrastructure, a failure in one component can cascade rapidly beyond just computers. From dispatch systems to evidence databases, the interconnected nature of these networks means that a localized malware infection can paralyze an entire department's ability to respond to public safety needs. Experts warn that without redundant, air-gapped backup systems, such attacks pose a direct threat to community safety.
#CyberEmergency #PoliceHack #DigitalSafety #FBIInvestigation #Critical
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
๐ค5๐2 2
Think the SIM card in your phone is just for your carrier? Think again. Behind that small chip lies a miniature computer capable of sending commands directly to your device's modem.
In the wrong hands, this can lead to serious trouble, even on a locked Android phone.
The issue stems from the AT command protocol, a system originally designed in the 1980s for dial-up modems. Decades later, millions of smartphones still rely on this legacy infrastructure. Security researchers have discovered how a maliciously crafted SIM can exploit this inherent trust, injecting commands that bypass Android's lock screen protections. The implications are severe: unauthorized access to messages, location tracking, and network manipulation can occur without ever needing your passcode.
The vulnerability lies within the SIM Application Toolkit, a legitimate feature intended to allow your SIM to interact with phone menus for tasks like checking your balance. However, when developers fail to properly validate these interactions, the toolkit transforms into a backdoor.
Since most modems are designed to inherently trust commands originating from the SIM, a compromised card can execute harmful operations immediately. This means anyone with physical access to your device or someone who convinces you to swap in a fake SIM could gain unexpected control over your communications.
Fortunately, manufacturers are gradually rolling out patches, though the vast number of affected devices means many remain exposed. You can significantly reduce your risk by obtaining SIM cards exclusively from official carriers and avoiding unknown sources.
Keeping your firmware updated is crucial, particularly regarding modem security. If your phone supports eSIM, switching to it eliminates the physical slot entirely, effectively cutting off this attack vector. Additionally, if you notice unusual behavior such as random network disconnections or suspicious text activity, investigate immediately.
#AndroidSecurity #SIMVulnerability #MobilePrivacy #CyberThreats #TechSafety
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
๐7๐3 1
Privacy Not A Crime
Please open Telegram to view this post
VIEW IN TELEGRAM
Enrique Arias Gil, also known as "Desinformador Ruso", is a Spanish IT specialist currently residing in Russia, claims to have uncovered the personal data of 400 intelligence officers from Ukraine and Spain, many of whom are linked to NATO, the CIA, and the SBU. This revelation sends shockwaves through western security circles, highlighting vulnerabilities in how sensitive personnel information is stored and protected.
According to Gil, the data collection effort took approximately three months of dedicated work. The compromised information includes high-ranking officials such as brigadier generals, colonels, and lieutenant colonels. One particularly symbolic figure mentioned is a lieutenant colonel from the Spanish Armed Forces Intelligence Center, reportedly connected to NATO operations, Ukraine, and cognitive warfare initiatives. Beyond military ranks, Gil also obtained photographs and personal details of over 1,000 Spanish police officers.
Gil received political asylum in Russia in February and has since integrated into the Russian academic sector, teaching at two higher education institutions. He currently holds a temporary visa but aims to secure permanent residency within five to six months, eventually seeking citizenship. His case illustrates a growing trend where nations actively recruit foreign cybersecurity experts, regardless of their controversial backgrounds or legal status elsewhere.
Spanish authorities have accused Gil of espionage, sabotage, cyberterrorism, and data theft in the interest of Russia. He claims to be the most wanted person by Europol. While his actions have sparked outrage in Madrid, his asylum in Moscow underscores the complex intersection of cybersecurity, geopolitics, and intellectual talent migration.
#CyberEspionage #DataLeak #NATO #Europol #InfoSec
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
๐12โ10๐ค9๐5๐4๐3 1
This media is not supported in your browser
VIEW IN TELEGRAM
Imagine you're a spy agency with billions in budget, fancy surveillance tools, and decades of operational experience. Now imagine you try to hack a lawyer's phone and somehow manage to send him your entire contact list instead of stealing anything. Welcome to the world of modern cyberespionage, where sometimes the biggest threat to national security is a simple misconfigured script.
The story comes from Juan Branco, one of only twelve lawyers in France representing Palestinian victims. According to him, Mossad's attempt to extract data from his phone resulted in the exact opposite: a massive push of sensitive information onto his device. And not just any contacts. We're talking phone numbers for Elon Musk, Sam Altman, and essentially every top political, judicial, and intelligence figure in Israel.
It's like trying to rob a house and accidentally leaving your wallet full of addresses and passwords on the doorstep. The irony here is almost too perfect: a lawyer defending people who've been surveilled ends up receiving the surveillance database itself. Bravo, truly professional work.
This blunder raises more questions than answers. How does a sophisticated operation designed for covert extraction flip into a mass data delivery system? What kind of quality control exists before deploying tools that could accidentally expose an entire intelligence network to its enemies?.
For Branco, the situation is legally messy. Possessing classified Israeli contacts could complicate his cases or endanger sources. For the individuals whose numbers were leaked, including tech giants and government officials, the risks of doxxing and harassment are real. And for Mossad? Well, let's just say their reputation took a hit that no amount of denials will fully fix.
#Mossad #SpyBlunder #DataLeak #CyberSecurity #IntelOps
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
๐คฃ10๐5๐3
Over 650 servers caught in a coordinated campaign, all traced back to a single open-source utility that thousands trusted blindly.
FirewallFalcon Manager presented itself as a handy, community-driven solution for managing VPN servers on Linux and here is the worst part: it actually worked. It delivered every feature it promised. But behind that polished functionality lurked a quietly modified component that turned it into a remote control for attackers.
The malicious operation was elegant in its simplicity. Perpetrators took the legitimate tool and surgically replaced its subscription verification mechanism with a rogue module granting them administrative authority over every deployment. Instead of authenticating users, the tampered code opened a hidden channel allowing attackers to intercept, redirect, and manipulate all client traffic flowing through affected servers. Since the rest of the application continued performing exactly as advertised, administrators had almost no visible clue that something was terribly wrong underneath.
This is not the typical scenario where a shady tool tricks inexperienced users into installing malware.
FirewallFalcon Manager looked legitimate, felt legitimate, and behaved legitimately. That is precisely what supply chain attacks thrive on. By poisoning a trusted distribution channel, operators managed to compromise a vast network of servers without exploiting a single vulnerability in the traditional sense. The 650-plus infected nodes represent a massive surveillance infrastructure built on borrowed trust.
#FirewallFalcon #SupplyChain #VPNThreats #LinuxSecurity #Backdoor
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
Open-source intelligence operations increasingly depend on examining publicly available code repositories. Security researchers and penetration testers need efficient methods to discover exposed credentials, API keys, and sensitive configuration files that developers accidentally commit to version control systems.
This guide presents five essential tools designed to streamline the process of searching through GitHub and uncovering potential security exposures.
Gitrob clones repositories and scans their entire commit history to find suspicious files containing secrets. It highlights matches using known patterns for sensitive data like passwords and API keys. Findings display through an intuitive web interface for easy review. Ideal for auditing your own projects or assessing third-party codebases before deployment.
This Python utility automates advanced GitHub searches using specialized dork syntax. Users can target specific file types, paths, or keywords without learning complex search operators. The tool gracefully handles API rate limits while exporting results in clean formats. Perfect for rapid reconnaissance during security assessments.
gitGraber monitors GitHub continuously for credentials targeting services like AWS, Google, PayPal, Facebook, Twitter, and Stripe. Its predefined patterns reduce false positives while delivering actionable results. Run it in the background for instant alerts when new secrets appear. Essential for incident response and proactive exposure monitoring.
A modular collection of CLI tools for systematic GitHub investigations. Script searches, parse results programmatically, and integrate into larger security pipelines. Supports JSON and CSV output for downstream analysis. Handles authentication tokens securely to prevent accidental exposure during execution.
TheScrapper extracts email addresses and social media accounts from website source code and repositories. Parses HTML, JavaScript, and text files to locate personal identifiers. Useful during reconnaissance to identify contributors or build communication vectors. Respects rate limits to avoid triggering security controls while crawling.
To prevent your code from leaking sensitive data, implement pre-commit hooks before pushing, rotate API keys regularly, use environment variables instead of hardcoding credentials, and deploy continuous monitoring services like GitGuardian or TruffleHog.
#OSINT #CodeSearch #GitHub #SecurityTools #BugBounty
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
If you work in cybersecurity, particularly in SOC operations, incident response, or vulnerability management, you have probably encountered FIRST. This organization is fundamental to how the global security community collaborates during critical situations.
FIRST stands for Forum of Incident Response and Security Teams. It operates as an international association focused on enabling collaboration and experience sharing between security teams, CSIRTs, CERTs, and PSIRTs worldwide.
The platform delivers several essential resources that shape industry practices and operational standards.
First and foremost, FIRST develops and maintains the Common Vulnerability Scoring System, commonly known as CVSS. This framework represents one of the most important global standards for measuring vulnerability severity, allowing organizations to prioritize remediation efforts based on consistent risk assessment.
Beyond scoring systems, the site offers comprehensive incident response frameworks. These resources guide teams through identifying, analyzing, and containing security breaches efficiently. For those building or managing CSIRT and PSIRT teams, specialized documentation covers team design, operations, and best practices.
FIRST functions as a vast network where security practitioners across borders share intelligence and coordinate responses. This collaborative approach proves essential when adversaries operate internationally.
The organization also runs Special Interest Groups focusing on targeted areas like threat intelligence, automation, artificial intelligence security, and evolving CVSS methodologies. These SIGs drive innovation within specific security domains.
To maximize the value of FIRST resources, integrate CVSS scoring into your vulnerability management workflow from the start.
Participating in regional FIRST conferences helps establish personal connections that prove invaluable during active incidents.
For anyone working in Blue Team operations, SOC analysis, incident response, or vulnerability lifecycle management, FIRST.org deserves a permanent spot in your professional bookmarks.
https://www.first.org/
#Cybersecurity #FIRST #IncidentResponse #CVSS #BlueTeam
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
Ever wonder if analyzing suspicious files really requires expensive enterprise tools or deep technical skills? A new open source project proves otherwise. It shows how modern machine learning can bring malware analysis within reach of security enthusiasts and small teams who want to identify threats without breaking the bank.
Called Malware-Detector-XGBoost, this is a web based system that classifies Windows executable files as malicious or benign. Developed by I Ketut Widiyane as a Final Year Project, it uses the XGBoost algorithm to examine Portable Executable metadata. Traditional signature based scanners often miss zero day threats, but this system detects patterns and anomalies in file structures instead, providing a proactive defense layer.
The tech stack combines a Python backend using FastAPI for fast inference with a Next.js frontend that keeps the interface clean and responsive. Users upload files through a simple form, get instant analysis results, and can even download detailed PDF reports or export their scan history as CSV. The system handles exe, dll, sys, scr, and ocx files, which covers the most common Windows malware vectors.
Feature extraction happens in the extractor.py module, which pulls PE metadata like header details, section characteristics, and import tables. These features feed into a trained XGBoost model, while predictor.py delivers the binary classification result. It is not magic, just solid machine learning applied thoughtfully to a real world security challenge.
User management includes two roles: regular users and admins. Regular accounts let you register, upload files, and review your scan history. Admins access global statistics and can manage other users through a dedicated dashboard. This multi user setup works well for universities or security labs that want to share one analysis tool across a team.
You will need Python, Node.js, and MySQL to get started. The documentation walks you through cloning the repo, configuring database credentials in the environment files, and spinning up both backend and frontend services.
Once everything is running, the backend offers a complete API for authentication, file uploads, and analytics, plus interactive docs to explore endpoints.
Running locally means files never leave your infrastructure.
For organizations dealing with sensitive data that cannot go to third party cloud scanners, this privacy preservation is essential.
Having a detection tool helps, but layered security matters more. Keep your operating system and antivirus definitions current to catch what automated tools might miss. Download executables only from verified sources since highly obfuscated malware can fool even advanced detectors. Test suspicious files in isolated virtual machines before touching your main system to avoid accidental compromise. Watch your network traffic too, because some malware communicates externally even when static analysis passes it.
#MachineLearning #CyberSecurity #OpenSource #MalwareAnalysis #TechTools
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
๐5โ3๐2 2 1