Privacy Not A Crime
667 subscribers
195 photos
19 videos
233 links
๐Ÿ” Take control of your digital freedom.

Curated tools and expert insights on Privacy, Cybersecurity and OSINT. Actionable guides to protect your data and communications.

Defend your rights online. ๐Ÿ”ฐ
Download Telegram
๐Ÿฆ  Malware detection made accessible with XGBoost

Ever wonder if analyzing suspicious files really requires expensive enterprise tools or deep technical skills? A new open source project proves otherwise. It shows how modern machine learning can bring malware analysis within reach of security enthusiasts and small teams who want to identify threats without breaking the bank.

๐Ÿ”‚ A modern approach to an old problem

Called Malware-Detector-XGBoost, this is a web based system that classifies Windows executable files as malicious or benign. Developed by I Ketut Widiyane as a Final Year Project, it uses the XGBoost algorithm to examine Portable Executable metadata. Traditional signature based scanners often miss zero day threats, but this system detects patterns and anomalies in file structures instead, providing a proactive defense layer.

The tech stack combines a Python backend using FastAPI for fast inference with a Next.js frontend that keeps the interface clean and responsive. Users upload files through a simple form, get instant analysis results, and can even download detailed PDF reports or export their scan history as CSV. The system handles exe, dll, sys, scr, and ocx files, which covers the most common Windows malware vectors.

๐Ÿ”ฌ Under the hood

Feature extraction happens in the extractor.py module, which pulls PE metadata like header details, section characteristics, and import tables. These features feed into a trained XGBoost model, while predictor.py delivers the binary classification result. It is not magic, just solid machine learning applied thoughtfully to a real world security challenge.

User management includes two roles: regular users and admins. Regular accounts let you register, upload files, and review your scan history. Admins access global statistics and can manage other users through a dedicated dashboard. This multi user setup works well for universities or security labs that want to share one analysis tool across a team.

๐Ÿ”ฌ Setting up your own detection lab

You will need Python, Node.js, and MySQL to get started. The documentation walks you through cloning the repo, configuring database credentials in the environment files, and spinning up both backend and frontend services.

Once everything is running, the backend offers a complete API for authentication, file uploads, and analytics, plus interactive docs to explore endpoints.
Running locally means files never leave your infrastructure.

For organizations dealing with sensitive data that cannot go to third party cloud scanners, this privacy preservation is essential.

๐Ÿง  Smart security practices to complement detection tools

Having a detection tool helps, but layered security matters more. Keep your operating system and antivirus definitions current to catch what automated tools might miss. Download executables only from verified sources since highly obfuscated malware can fool even advanced detectors. Test suspicious files in isolated virtual machines before touching your main system to avoid accidental compromise. Watch your network traffic too, because some malware communicates externally even when static analysis passes it.

๐Ÿฑ Check the tool at GitHub

๐Ÿ˜Š If you enjoyed the article share it with your friends and follow us.

#MachineLearning #CyberSecurity #OpenSource #MalwareAnalysis #TechTools

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘Œ5โœ3๐Ÿ‘€221
๐Ÿ›œ Check your router for hidden vulnerabilities

Think your home network is secure just because you set a strong Wi-Fi password? Maybe not. The router itself, the brain of your connection, might be running outdated firmware with known security holes that hackers can exploit silently. A new open-source project is here to help you discover exactly which risks are lurking behind your gateway.

๐Ÿšจ A practical tool for proactive defense

Security researcher Mikhail Artamonov has released router-cve-audit, a utility designed to scan your router's firmware and cross-reference it against a massive database of known Common Vulnerabilities and Exposures. Unlike generic scanners, this tool focuses specifically on identifying whether your device is running versions vulnerable to publicly documented exploits, giving you a clear picture of your exposure without requiring deep technical expertise.

The project leverages the growing transparency of vulnerability databases to empower regular users. By analyzing the firmware version and model of your router, it can instantly flag issues ranging from remote code execution flaws to weak default credentials that haven't been patched in years. This matters because many routers sit untouched for months or even years, becoming easy targets for botnets and unauthorized access.

๐Ÿง Why this matters for your privacy

Routers often represent the weakest link in home cybersecurity. A compromised router can lead to traffic interception, DNS hijacking, or even full control over your connected devices. With thousands of CVEs affecting popular brands like TP-Link, ASUS, Netgear, and others, assuming it works fine is no longer sufficient. This audit tool bridges the gap between complex security data and actionable insights for everyday users.

๐ŸŒŸ How to protect yourself

Start by downloading the tool from the official repository and running a quick scan against your router's firmware details. If vulnerabilities surface, update your router's firmware immediately using the latest version from the manufacturer.

If no updates exist for your specific model, seriously consider replacing it with a newer device that receives regular security patches.

For advanced users, enabling automatic updates if available, disabling remote management features, and changing default admin credentials remain essential habits. If you suspect compromise, perform a factory reset followed by a firmware flash where possible.

๐Ÿฑ Check this awesome tool at GitHub

๐Ÿ‘ If you enjoyed the article share it with your friends and follow us.

#RouterSecurity #CVEAudit #NetworkPrivacy #FirmwareUpdate #OpenSource

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘Œ7๐Ÿ‘€5โœ21
๐Ÿ’ป Windows 0-day exploited by Lazarus to gain SYSTEM privileges

A newly discovered zero-day vulnerability in Windows has been weaponized by the North Korean hacking group Lazarus as part of their ongoing Operation Dream Job campaign. This sophisticated threat targets defense and aviation sector employees with enticing job offers, only to infect their systems through fake PDF viewer software.

๐Ÿ—ก The mechanics of the attack

At the heart of this operation lies CVE-2026-68820, a previously unknown vulnerability in the Windows Ancillary Function Driver (AFD.sys) with a severity rating of 7.0. This flaw allows attackers to escalate privileges directly to the highest system level, SYSTEM, granting them complete control over the compromised machine.

Microsoft acknowledged the issue on July 31 and released a patch on August 11 as part of their scheduled security updates.

The latest iteration of this campaign involves victims being lured to install a counterfeit application called SecurityPDF, distributed through fraudulent websites impersonating the legitimate company Enveil. Once a specially crafted document is opened within this fake viewer, a new backdoor named Troy is deployed. This malicious tool supports 17 distinct commands, enabling extensive remote control capabilities.

๐Ÿ˜ƒ Why continuing with Windows or MacOS may be a mistake

Individuals and organizations that continue relying on Windows or MacOS as primary work tools are increasingly making a risky choice. The reality is stark. Windows vulnerabilities show no signs of ending. Some security experts argue that certain flaws are intentionally embedded to enable law enforcement investigative capabilities, yet these same backdoors inevitably become weapons for cybercriminals once discovered or leaked.

Companies still tied to proprietary operating systems face an endless cycle of patches and emergency fixes.

Meanwhile, open-source alternatives like Linux offer transparency and community-driven security audits that significantly reduce hidden vulnerabilities. For privacy-focused users and businesses handling sensitive data, migrating to Linux is not just advisable. It is becoming essential for long-term digital sovereignty.

๐Ÿ’ก Practical migration path to Linux

Transitioning does not mean abandoning your workflow entirely. Many professional applications have Linux-compatible alternatives or run through containers. Start with a dual-boot setup to test compatibility with your daily tools. Distributions like Ubuntu, Fedora, or Debian provide enterprise-grade stability while maintaining full control over your system.

๐Ÿ˜Š If you enjoyed the article share it with your friends and follow us.

#LazarusGroup #ZeroDay #WindowsSecurity #LinuxMigration #DigitalSovereignty

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
โœ9๐Ÿ‘€7๐Ÿ˜3๐Ÿค”3๐Ÿ‘Œ31
๐ŸŽฎ Twitch using streams to train Amazon AI by default

Are your Twitch broadcasts truly private? Unfortunately, they are not. Your face, voice, chat interactions, clips, and content are currently feeding Amazon's artificial intelligence systems without your knowledge. This process runs silently in the background, enabled automatically from day one.

๐Ÿ’ต Default opt-out reveals troubling priorities

Amazon and Twitch explained their reasoning quite bluntly: if participation required active consent, virtually nobody would agree. This straightforward admission shows how creator privacy ranks below data collection objectives. The platform's documentation confirms that user content trains models capable of generating text, audio, images, and video.

๐Ÿ”Ž What data is vulnerable

Without manual intervention, Amazon accesses your entire footprint on the platform. Live broadcasts, archived videos, fan-made clips, and real-time chat messages all become potential training material.
Every image and word displayed on your channel enters this extensive pool, turning personal broadcasts into corporate assets without asking permission.

โ“ Uncertainty about past harvesting

Questions about previously collected data receive no clear answers. When asked whether specific content had already been used, Twitch leadership admitted they could not confirm what Amazon processed historically. Statements from 2024 acknowledged Amazon was pulling Twitch content for AI purposes, yet creators stay uninformed about how much has disappeared into training systems. Once absorbed into these pipelines, removing your data becomes practically impossible.

๐Ÿ›ก Protecting yourself step by step

You can stop future data collection through simple settings adjustments. Navigate to your profile picture โ†’ settings โ†’ security and privacy. Scroll down until you find the "Generative AI Training" option and turn it off completely. Pay attention because some users report this switch toggling back on unexpectedly, demanding regular checks.

Two important caveats deserve attention. Opting out protects only your own channel content. When you join chat rooms on other streamers' broadcasts, their settings control your visibility regardless of your preferences. Furthermore, this action prevents only incoming training sessions. No mechanism exists to recover or identify what has already been consumed by Amazon's systems.

๐Ÿ˜Š If you enjoyed the article share it with your friends and follow us.

#TwitchAI #DataPrivacy #CreatorRights #AmazonAI #DigitalSecurity

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
โœ7๐Ÿ‘Œ4๐Ÿ‘€2๐Ÿคทโ€โ™‚1๐Ÿ˜1๐Ÿค”11
๐Ÿค– Strix brings AI-powered pentesting to open source

Think penetration testing requires weeks of manual work and expensive security consultants? Strix challenges that assumption by combining artificial intelligence with the same offensive security tools professional ethical hackers use.

This open-source platform empowers developers and security teams to identify and fix vulnerabilities faster than traditional methods allow.

โš™๏ธ Agentic pentesting meets real-world tools

Strix agents deploy a comprehensive security toolkit directly into your development workflow. From HTTP interception proxies with full request manipulation to automated browser exploitation for XSS and CSRF testing, the platform mirrors what human pentesters accomplish manually. The shell execution environment enables interactive exploit development while the custom Python sandbox validates proof-of-concept exploits safely. Reconnaissance capabilities automatically map attack surfaces through subdomain enumeration and fingerprinting without human intervention.

๐Ÿ“Ž Static analysis finally catches context

Unlike conventional scanners drowning teams in false positives, Strix combines SAST and DAST capabilities with vulnerability intelligence. Each finding includes CVSS scoring and OWASP classification with structured details and reproduction steps. The dashboard displays live agent activity, severity breakdowns, and allows mid-scan steering instructions through the browser interface. Teams can browse historical runs and generate shareable reports emailed directly to stakeholders.

๐ŸŒ Enterprise features without vendor lock-in

The platform scales from individual developers to organizations needing compliance-ready documentation. SOC 2, ISO 27001, and PCI DSS reporting comes standard alongside SSO integration via SAML or OIDC.

Custom deployment options include VPC hosting and self-hosted configurations with bring-your-own-key model support. Security teams maintain full control while benefiting from dedicated SLA-backed support channels.

๐Ÿฑ Check this tool at GitHub

๐Ÿ˜Š If you enjoyed the article share it with your friends and follow us.

#AIsecurity #Pentesting #DevSecOps #OpenSource #AppSec

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘€8๐Ÿ‘Œ5โœ3๐Ÿ˜21
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ“ธ FLOCK: The AI surveillance network watching America

A private company based in Atlanta has quietly built one of the most expansive surveillance networks ever seen on US soil. Flock Safety, founded in 2017, has deployed roughly 120,000 automated license plate reader cameras across 49 states, capturing vehicle data in real time and building a permanent record of citizen movement.

Marketed as a public safety tool, the system has sparked fierce opposition from privacy advocates and civil liberties organizations who warn that it effectively eliminates anonymity in public spaces.

โš™๏ธ How FLOCK cameras operate

These devices are self-contained units powered by solar panels or LTE connections, mounted on traffic poles, lampposts, and other public fixtures. Each camera captures not only license plates but also vehicle make, model, color, and what the company calls a "vehicle signature." The AI processes this data instantly and cross-references it against databases of stolen vehicles, Amber Alerts, and custom watchlists created by local law enforcement.

What makes this particularly alarming is the retroactive search capability. Officers can look back weeks or even months to reconstruct the movement history of any vehicle, without needing prior suspicion of a crime. This turns ordinary traffic into a searchable database of human behavior, where every trip to the store, a doctor's appointment, or a protest becomes a data point permanently stored and queryable by more than 5,000 law enforcement agencies nationwide.

๐Ÿšจ Threats to privacy and civil liberties

The ACLU and other organizations have raised serious concerns about the indefinite storage of data belonging to innocent citizens. Reports have emerged of this information being accessed by federal agencies such as ICE for immigration enforcement, expanding the system's reach far beyond its original public safety purpose.

Without federal regulation, data retention policies vary wildly between jurisdictions. Some areas keep records indefinitely, creating an ever-growing database of personal movement patterns. Critics have drawn parallels to dystopian literature, noting that constant surveillance produces a chilling effect on free speech and peaceful assembly. People have reportedly avoided attending protests, political meetings, or medical facilities out of fear of being tracked and catalogued.

There are also documented cases of security vulnerabilities. Researcher Benn Jordan discovered that some Flock cameras were left live-streaming to the open internet, and that company executives had accessed live feeds from cameras near schools and gymnastics facilities. The company's CEO even sent emails to police department customers claiming that Flock and law enforcement were "under attack" by YouTube videos exposing these issues.

๐ŸŒ Practical steps to reduce your exposure

While completely avoiding cameras in urban environments is nearly impossible, there are meaningful actions you can take. Community mapping tools like DeFlock allow you to identify known ALPR locations near you and plan routes that minimize exposure. Supporting local legislation that limits data retention periods and requires warrants for retrospective searches is another powerful way to push back. Organizations like the EFF and ACLU actively monitor surveillance deployments and provide resources for community advocacy. You can also demand transparency from your local government regarding contracts with surveillance companies and how your data is handled.

๐Ÿ” Find where cameras are installed near you:

https://deflock.org
https://maps.deflock.org

๐Ÿ˜Š If you enjoyed the article share it with your friends and follow us.

#MassSurveillance #PrivacyRights #FlockSafety #CivilLiberties #ALPR

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘€6๐Ÿค”4โœ3๐Ÿ‘Œ2๐Ÿ˜1
๐Ÿค– Nodriver: Advanced automation and web scraping

Collecting web data today means dealing with serious anti-bot defenses. That's where nodriver comes in. As the successor to Undetected-Chromedriver, this library handles asynchronous web automation and scraping while slipping past detection systems like Captcha and CloudFlare. For developers who need reliable access to web data, it's built to work when other tools fail.

๐Ÿ–ฅ Core features and ease of use

Unlike Selenium-heavy solutions, nodriver runs light and fast. You can start a browser session with literally one line of code. Each execution automatically cleans up user profiles afterward, which helps avoid fingerprinting issues. The element search and selection methods are also more advanced than what you get with traditional libraries, saving time on complex interactions.

โ–ถ๏ธ Performance and resilience benefits

Speed is noticeably better thanks to the async architecture. Data collection happens faster, but the real win is how it holds up against WAFs and bot mitigation systems. I've seen scrapers that normally block within minutes keep running for hours with nodriver. For both quick prototypes and production setups, that reliability makes a difference.

๐Ÿ‘จโ€๐Ÿ’ป Ideal use cases

If your project involves scraping sites known for blocking automation, or you need to navigate flows that aggressively detect bots, this tool gives you the flexibility to stay under the radar. It's particularly useful when you're tired of constantly tweaking scripts just to get through basic pages.

๐Ÿ›ก Protection tips for ethical scraping

Powerful tools come with responsibility. Here's how to use them without causing issues:

โ–ซ๏ธ Check robots.txt first โ€” respect what sites allow you to scrape.

โ–ซ๏ธ Add delays between requests so servers don't get overwhelmed.

โ–ซ๏ธ Read Terms of Service before automating access to any site.

โ–ซ๏ธ Watch out for personal data โ€” GDPR and similar regulations still apply.

๐Ÿฑ For those wanting to dive into the code or documentation, check out the official repository

๐Ÿ˜Š If you enjoyed the article share it with your friends and follow us.

#Python #WebScraping #Automation #CyberSecurity #OpenSource

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
โœ6๐Ÿ‘Œ5๐Ÿ˜2๐Ÿค”1๐Ÿ‘€111
๐Ÿ– Discover 100 private services: Free alternatives to leading platforms

Big tech giants like Google, ChatGPT, and Midjourney profit from your data. Every click, message, and upload can end up in advertisers hands. But you don't have to accept this trade-off anymore.

๐Ÿ”› Practical replacements that work

This collection curates 100 tools that put you in control. Swap out mainstream services for private file managers, discreet app stores, local AI models, encrypted cloud storage, and keyboards built for privacy. Each option keeps your information local or encrypts it before it ever touches a server.

๐Ÿ” Simple steps to protect yourself

Make security a habit: enable end-to-end encryption on everything you can, choose open-source software whenever possible, limit what you store in the cloud, and remember that free services usually monetize through your data. Small changes add up to real protection.

๐Ÿฑ Check the full toolkit at Github

๐Ÿ˜Š If you enjoyed the article share it with your friends and follow us.

#Privacy #OpenSource #CyberSecurity #DataProtection #DigitalRights

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ˜6โœ4๐Ÿค”3๐Ÿ‘€2111
๐Ÿ—ฝ The ten commandments of Privacy Not A Crime

This is who we are. This is what we believe. Ten principles that guide everything we share.

๐Ÿ”ข Information must be free and accessible to everyone, at all times

Knowledge should never sit behind paywalls or borders. The moment we accept only those who can afford it deserve to be informed, we lose something fundamental. Security awareness, threat intelligence, defensive techniques, all of it should flow freely.

๐Ÿ”ข Never pay for information, except in rare exceptions

Core security knowledge should not become a luxury item. When protecting yourself online comes with a price tag, something has gone wrong. Exceptions exist, but openness is always the default.

๐Ÿ”ข Economic contributions must always be voluntary

Support should come from conviction, never pressure. No forced subscriptions, no hidden fees, no holding content hostage. Support grows organically when people truly believe in what you do.

๐Ÿ”ข Physical and digital freedom is the number one priority

Your right to walk down a street without tracking and browse without profiling are the same fight. Both matter equally. Freedom is not a setting you toggle, it is a baseline.

๐Ÿ”ข Use learned knowledge to do good and for a just and ethical cause

Skills are tools. Vulnerability disclosure can save millions or get sold to exploit them. The difference lies in the hands that hold the knowledge. We choose protection, always.

๐Ÿ”ข Transparency is the antidote to abuse

Secret algorithms shape what you see. Hidden data collection profiles who you are. None of this survives public scrutiny intact, which is why scrutiny matters. Openness is the foundation of security.

๐Ÿ”ข Security is a human right, not a luxury product

Being safe online should not depend on affording premium software. Basic digital hygiene, encrypted communication, strong authentication, these are not perks for the privileged. They are minimum standards everyone deserves.

๐Ÿ”ข Anonymity is a shield for the vulnerable

Anonymity protects journalists, activists, survivors, and ordinary citizens who do not want every move catalogued. It is not about hiding wrongdoing, it is about surviving.

๐Ÿ”ข Education empowers resistance

You cannot defend what you do not understand. Knowing how tracking works, why apps want your location, what permissions mean, this is survival literacy for the digital age. We break down complex concepts into language anyone can follow.

๐Ÿ”ค Privacy is not a crime, it is a fundamental right

Wanting a private life does not make you suspicious. Encrypting messages does not make you a target. Refusing to share personal data means you understand your life belongs to you, not a corporation or algorithm.

Privacy Not A Crime. It never was. And it never should be.

These ten commandments are who we are. If they resonate with you, you are already one of us.

๐Ÿ˜Š Follow us to stay informed about the latest threats and protect yourself.

#PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿฅฐ22๐Ÿ‘Œ17โœ7๐Ÿ‘€4๐Ÿค”2๐Ÿ˜1
๐Ÿ’ฌ A follower asks us the following question in Spanish:

Which operating system is most vulnerable to these attacks: GrapheneOS, iOS, or standard Android? Which one is more secure in preventing real-time remote access by government spyware and zero-click attacks where the user doesnโ€™t have to do anything, but simply by inserting the SIM card and connecting to the network, the phone becomes infected and is accessed remotely?


๐Ÿ™ First of all, thank you for asking.

๐Ÿ”นThe most vulnerable and exploitable operating systems are those that are closed-source, the ones that the community cannot audit and does not know what lies behind them. That is why we always recommend using the latest version of Android with the latest security patches applied. Note: we mean โ€˜open-sourceโ€™ Android, without proprietary services such as those from Google.

๐Ÿ”นTo prevent remote access to your smartphone, you need to take certain basic security measures; the most important ones are as follows:

โ–ซ๏ธ Manually update your operating system to the latest version and ensure it has the latest security patches. By โ€˜manuallyโ€™, we mean that you should download the update from the providerโ€™s official website and install it from a PC; never update automatically, as this is a common vector for compromise. Always be wary of automatic updates.

โ–ซ๏ธ Never accept automatic updates for any type of app.

โ–ซ๏ธ Never click on any links that are sent to you, no matter how harmless they may seem. Even if they're sent by someone you trust. Just don't do it.

โ–ซ๏ธ Always keep your web browser and apps updated to the latest version, although there are exceptions depending on each person's situation.

โ–ซ๏ธ Do not use proprietary services from companies such as Google, Microsoft, Facebook (Meta), X, YouTube, WhatsApp, etc.

โ–ซ๏ธ Of course, don't install apps from unknown sources unless you know what you're doing.

๐Ÿ”นDisable the network operatorโ€™s services and uninstall apps such as โ€˜SIM Toolkitโ€™, as this is a commonly used attack vector.

๐Ÿ”นAlways opt for an eSIM rather than a physical SIM card to reduce the attack surface.

๐Ÿ”นUse a good, community-maintained smartphone firewall that is regularly updated, and a good VPN that does not keep logs

๐Ÿ”นBlock all private IP addresses on the firewall, but particularly those of the service provider (100.64.0.0/10). The service provider may intercept your traffic and reroute it through that range in order to spy on your communications.

๐Ÿ”นAlways prioritise 5G NR over any other mobile network. Do not confuse this with 5G NR NSA, as NR NSA uses 4G LTE for the control channel and 5G NR for the data channel. This offers no additional security benefits and creates attack vectors such as man-in-the-middle attacks.

๐Ÿ”นUninstall any certificate from the root system unless you fully trust it and know what it is for. If you do not know why it is there, it is best to remove it.

โ• But itโ€™s not all down to the software; the hardware is also very important, and, paradoxically, using a less popular smartphone will help to reduce the attack surface. Most exploits are designed for Samsung and Apple.

๐Ÿ”– These are just a few tips for reducing your attack surface. However, youโ€™ll also need to learn how to identify indicators of compromise so you know when your device might be compromised. But weโ€™ll cover that in another article if our followers show their support.

๐Ÿ‘‹ If youโ€™ve enjoyed this new section, please let us know.

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿฅฐ15โœ11
๐Ÿฅฐ532๐Ÿ‘Œ11
๐Ÿง  GLM-5.3 vs. Claude Mythos 5: Open source model uncovers thousands of vulnerabilities

Chinese AI firm Z.ai has unveiled GLM-5.3, and its most striking achievement wasn't winning standard coding benchmarks. Instead, when tasked with auditing real-world open-source repositories, the GLM family of models identified a staggering 2,436 vulnerabilities across 269 projects. This discovery highlights a growing shift where AI is becoming a primary tool for automated security research, potentially outperforming traditional static analysis tools in finding complex logic flaws.

๐Ÿ“Š The scale of the discovery

While many AI models are praised for their ability to generate code, GLM-5.3 demonstrated exceptional prowess in breaking it. The audit covered a wide range of popular open-source libraries, revealing critical issues that had gone unnoticed by human maintainers for years. The sheer volume over two thousand distinct flaws suggests that the current pace of software development may be outstripping our ability to manually review security implications.

This capability poses an interesting dynamic in the AI landscape. While Western models focus heavily on alignment and general utility, this Chinese-developed model has carved a niche in aggressive vulnerability scanning. It raises questions about whether future AI safety standards will need to include offensive capabilities as a core requirement for securing the global software supply chain.

๐ŸŒŸ What this means for developers

For the open-source community, this is a double-edged sword. On one hand, having an AI that can instantly flag thousands of bugs accelerates the patching process and strengthens the ecosystem. On the other, it implies that malicious actors could potentially use similar models to scan for zero-day exploits just as quickly. The barrier to finding critical vulnerabilities is lowering, which means the window of exposure for unpatched software is shrinking rapidly.

Developers should anticipate a future where AI-assisted code review becomes mandatory before merging pull requests. Relying solely on human intuition or legacy linting tools may no longer be sufficient against the speed and depth of modern AI auditors.

๐Ÿฑ Check the available models at GitHub

๐Ÿ’ธ Chat with the AI right now

๐Ÿ˜Š If you enjoyed the article share it with your friends and follow us.

#Vulnerabilities
#OpenSource #GLM53 #CyberSecurity #CodeAudit

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿฅฐ15๐Ÿ‘Œ3
โœ… Fake Chrome update delivers DragonDoll spyware across 26 countries

A malicious update disguised as Google Chrome has infected Android devices in 26 countries, giving attackers near-total control over victims' phones.

The malware, called DragonDoll, uses "special functions" to bypass security measures and steal sensitive data from encrypted messaging apps like Telegram, WhatsApp, and Signal.

๐Ÿฆ  How the infection works

The attack relies on social engineering, tricking users into installing a fake version of the browser. Once installed, DragonDoll doesn't just steal files. It watches screen activity in real-time, intercepts incoming calls, and captures PINs and passwords as people type them. Most worryingly, it targets end-to-end encrypted apps by reading notifications and screen overlays, essentially bypassing the privacy protections users count on for secure chats.

โšก๏ธ Scope and impact

The campaign has spread fast across 26 nations. The sophistication behind DragonDoll points to a well-funded group behind it, possibly state-sponsored or part of a major cybercrime network. Being able to read Signal messages, a platform known for rock-solid security, shows how serious this breach is. The attack happens at the device level, not by breaking the encryption itself.

๐Ÿ˜Š Follow us to stay informed about the latest threats and protect yourself.

#CyberSecurity #AndroidSafety #DragonDoll #PrivacyMatters #SpywareAlert

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿฅฐ17โœ41
๐Ÿคฃ7๐Ÿ‘€4โœ3
๐Ÿคฉ AI Jail: Secure sandbox for AI agents

Running AI agents comes with risks. They might touch files they shouldn't or access data they were never meant to see. That's where Ai Jail comes in handy. This multi-platform tool creates a controlled environment for AI agents, locking them down so they can only access what you explicitly allow.

๐Ÿ’™ How the isolation works

Ai Jail uses built-in operating system features to do its job. On Linux, it leverages bwrap. On macOS, it relies on sandbox-exec. What happens is straightforward: the tool mounts only the directories an agent actually needs for its task.

So when you're testing a code-writing bot or a data-analysis script, that agent literally cannot see files outside its assigned sandbox. It's similar to containerization, but built specifically for the unique risks that come with autonomous AI decision-making.

๐Ÿ’ก Why this matters for AI safety

Here's the thing, AI agents are getting smarter, and with that power comes greater potential for problems. A model might accidentally delete important files, pull credentials from your home directory, or reach out to external networks if left unconstrained. Ai Jail tackles this by taking a "deny-by-default" approach.

Developers and security researchers get a reliable way to test how an agent behaves without risking the rest of their machine.

๐Ÿฑ Check this tool at GitHub

๐Ÿ˜Š If you enjoyed the article share it with your friends and follow us.

#CyberSecurity #AISafety #OpenSource #DevOps #PrivacyTools

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
โœ4๐Ÿ‘€4
๐Ÿคฃ Dark web launches MessiahGPT for cyberattacks at just eight dollars a month

A new neural network called MessiahGPT has emerged on the dark web, significantly lowering the barrier to entry for cybercrime. For approximately eight dollars a month, this clandestine service allows users to generate sophisticated attack tools with a single prompt. The creators are even offering the first 50 requests completely free and without registration, making it accessible to anyone with an internet connection.

๐Ÿ˜˜ Democratizing cybercrime for everyone

The implications are stark: you no longer need to be a skilled hacker or possess deep technical knowledge to launch a cyberattack. With MessiahGPT, a user can instantly generate an extortion scheme, create a convincing phishing page, and craft a detailed deception script, all in one go.

This turns complex cyber warfare into a consumer-grade service. Individuals with malicious intent but zero coding skills can now execute high-impact attacks.

Instead of spending weeks learning exploits or buying fragmented tools, criminals can rely on this AI to orchestrate the entire attack vector. This shift suggests a worrying trend where the technical expertise required for severe breaches is becoming obsolete, replaced by simple subscription fees and prompt engineering.

๐Ÿ˜† If you enjoyed the article share it with your friends and follow us.

#MessiahGPT #Cybercrime #DarkWeb #AIThreats #Phishing

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
โœ5๐Ÿ‘€22
Buy us a coffee โ˜•
Has our content helped you today? Buy us a coffee to help us keep this space active, updated, and ad-free. Every contribution counts!

Thank you for your support! ๐Ÿ™
1๐Ÿ‘€4โœ32