A newly discovered zero-day vulnerability in Windows has been weaponized by the North Korean hacking group Lazarus as part of their ongoing Operation Dream Job campaign. This sophisticated threat targets defense and aviation sector employees with enticing job offers, only to infect their systems through fake PDF viewer software.
At the heart of this operation lies CVE-2026-68820, a previously unknown vulnerability in the Windows Ancillary Function Driver (AFD.sys) with a severity rating of 7.0. This flaw allows attackers to escalate privileges directly to the highest system level, SYSTEM, granting them complete control over the compromised machine.
Microsoft acknowledged the issue on July 31 and released a patch on August 11 as part of their scheduled security updates.
The latest iteration of this campaign involves victims being lured to install a counterfeit application called SecurityPDF, distributed through fraudulent websites impersonating the legitimate company Enveil. Once a specially crafted document is opened within this fake viewer, a new backdoor named Troy is deployed. This malicious tool supports 17 distinct commands, enabling extensive remote control capabilities.
Individuals and organizations that continue relying on Windows or MacOS as primary work tools are increasingly making a risky choice. The reality is stark. Windows vulnerabilities show no signs of ending. Some security experts argue that certain flaws are intentionally embedded to enable law enforcement investigative capabilities, yet these same backdoors inevitably become weapons for cybercriminals once discovered or leaked.
Companies still tied to proprietary operating systems face an endless cycle of patches and emergency fixes.
Meanwhile, open-source alternatives like Linux offer transparency and community-driven security audits that significantly reduce hidden vulnerabilities. For privacy-focused users and businesses handling sensitive data, migrating to Linux is not just advisable. It is becoming essential for long-term digital sovereignty.
Transitioning does not mean abandoning your workflow entirely. Many professional applications have Linux-compatible alternatives or run through containers. Start with a dual-boot setup to test compatibility with your daily tools. Distributions like Ubuntu, Fedora, or Debian provide enterprise-grade stability while maintaining full control over your system.
#LazarusGroup #ZeroDay #WindowsSecurity #LinuxMigration #DigitalSovereignty
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
â9đ7đ3đ¤3đ3 1
Are your Twitch broadcasts truly private? Unfortunately, they are not. Your face, voice, chat interactions, clips, and content are currently feeding Amazon's artificial intelligence systems without your knowledge. This process runs silently in the background, enabled automatically from day one.
Amazon and Twitch explained their reasoning quite bluntly: if participation required active consent, virtually nobody would agree. This straightforward admission shows how creator privacy ranks below data collection objectives. The platform's documentation confirms that user content trains models capable of generating text, audio, images, and video.
Without manual intervention, Amazon accesses your entire footprint on the platform. Live broadcasts, archived videos, fan-made clips, and real-time chat messages all become potential training material.
Every image and word displayed on your channel enters this extensive pool, turning personal broadcasts into corporate assets without asking permission.
Questions about previously collected data receive no clear answers. When asked whether specific content had already been used, Twitch leadership admitted they could not confirm what Amazon processed historically. Statements from 2024 acknowledged Amazon was pulling Twitch content for AI purposes, yet creators stay uninformed about how much has disappeared into training systems. Once absorbed into these pipelines, removing your data becomes practically impossible.
You can stop future data collection through simple settings adjustments. Navigate to your profile picture â settings â security and privacy. Scroll down until you find the "Generative AI Training" option and turn it off completely. Pay attention because some users report this switch toggling back on unexpectedly, demanding regular checks.
Two important caveats deserve attention. Opting out protects only your own channel content. When you join chat rooms on other streamers' broadcasts, their settings control your visibility regardless of your preferences. Furthermore, this action prevents only incoming training sessions. No mechanism exists to recover or identify what has already been consumed by Amazon's systems.
#TwitchAI #DataPrivacy #CreatorRights #AmazonAI #DigitalSecurity
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
â7đ4đ2đ¤ˇââ1đ1đ¤1 1
Think penetration testing requires weeks of manual work and expensive security consultants? Strix challenges that assumption by combining artificial intelligence with the same offensive security tools professional ethical hackers use.
This open-source platform empowers developers and security teams to identify and fix vulnerabilities faster than traditional methods allow.
Strix agents deploy a comprehensive security toolkit directly into your development workflow. From HTTP interception proxies with full request manipulation to automated browser exploitation for XSS and CSRF testing, the platform mirrors what human pentesters accomplish manually. The shell execution environment enables interactive exploit development while the custom Python sandbox validates proof-of-concept exploits safely. Reconnaissance capabilities automatically map attack surfaces through subdomain enumeration and fingerprinting without human intervention.
Unlike conventional scanners drowning teams in false positives, Strix combines SAST and DAST capabilities with vulnerability intelligence. Each finding includes CVSS scoring and OWASP classification with structured details and reproduction steps. The dashboard displays live agent activity, severity breakdowns, and allows mid-scan steering instructions through the browser interface. Teams can browse historical runs and generate shareable reports emailed directly to stakeholders.
The platform scales from individual developers to organizations needing compliance-ready documentation. SOC 2, ISO 27001, and PCI DSS reporting comes standard alongside SSO integration via SAML or OIDC.
Custom deployment options include VPC hosting and self-hosted configurations with bring-your-own-key model support. Security teams maintain full control while benefiting from dedicated SLA-backed support channels.
#AIsecurity #Pentesting #DevSecOps #OpenSource #AppSec
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
đ8đ5â3đ2 1
This media is not supported in your browser
VIEW IN TELEGRAM
A private company based in Atlanta has quietly built one of the most expansive surveillance networks ever seen on US soil. Flock Safety, founded in 2017, has deployed roughly 120,000 automated license plate reader cameras across 49 states, capturing vehicle data in real time and building a permanent record of citizen movement.
Marketed as a public safety tool, the system has sparked fierce opposition from privacy advocates and civil liberties organizations who warn that it effectively eliminates anonymity in public spaces.
These devices are self-contained units powered by solar panels or LTE connections, mounted on traffic poles, lampposts, and other public fixtures. Each camera captures not only license plates but also vehicle make, model, color, and what the company calls a "vehicle signature." The AI processes this data instantly and cross-references it against databases of stolen vehicles, Amber Alerts, and custom watchlists created by local law enforcement.
What makes this particularly alarming is the retroactive search capability. Officers can look back weeks or even months to reconstruct the movement history of any vehicle, without needing prior suspicion of a crime. This turns ordinary traffic into a searchable database of human behavior, where every trip to the store, a doctor's appointment, or a protest becomes a data point permanently stored and queryable by more than 5,000 law enforcement agencies nationwide.
The ACLU and other organizations have raised serious concerns about the indefinite storage of data belonging to innocent citizens. Reports have emerged of this information being accessed by federal agencies such as ICE for immigration enforcement, expanding the system's reach far beyond its original public safety purpose.
Without federal regulation, data retention policies vary wildly between jurisdictions. Some areas keep records indefinitely, creating an ever-growing database of personal movement patterns. Critics have drawn parallels to dystopian literature, noting that constant surveillance produces a chilling effect on free speech and peaceful assembly. People have reportedly avoided attending protests, political meetings, or medical facilities out of fear of being tracked and catalogued.
There are also documented cases of security vulnerabilities. Researcher Benn Jordan discovered that some Flock cameras were left live-streaming to the open internet, and that company executives had accessed live feeds from cameras near schools and gymnastics facilities. The company's CEO even sent emails to police department customers claiming that Flock and law enforcement were "under attack" by YouTube videos exposing these issues.
While completely avoiding cameras in urban environments is nearly impossible, there are meaningful actions you can take. Community mapping tools like DeFlock allow you to identify known ALPR locations near you and plan routes that minimize exposure. Supporting local legislation that limits data retention periods and requires warrants for retrospective searches is another powerful way to push back. Organizations like the EFF and ACLU actively monitor surveillance deployments and provide resources for community advocacy. You can also demand transparency from your local government regarding contracts with surveillance companies and how your data is handled.
https://deflock.org
https://maps.deflock.org
#MassSurveillance #PrivacyRights #FlockSafety #CivilLiberties #ALPR
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
đ6đ¤4â3đ2đ1
Collecting web data today means dealing with serious anti-bot defenses. That's where nodriver comes in. As the successor to Undetected-Chromedriver, this library handles asynchronous web automation and scraping while slipping past detection systems like Captcha and CloudFlare. For developers who need reliable access to web data, it's built to work when other tools fail.
Unlike Selenium-heavy solutions, nodriver runs light and fast. You can start a browser session with literally one line of code. Each execution automatically cleans up user profiles afterward, which helps avoid fingerprinting issues. The element search and selection methods are also more advanced than what you get with traditional libraries, saving time on complex interactions.
Speed is noticeably better thanks to the async architecture. Data collection happens faster, but the real win is how it holds up against WAFs and bot mitigation systems. I've seen scrapers that normally block within minutes keep running for hours with nodriver. For both quick prototypes and production setups, that reliability makes a difference.
If your project involves scraping sites known for blocking automation, or you need to navigate flows that aggressively detect bots, this tool gives you the flexibility to stay under the radar. It's particularly useful when you're tired of constantly tweaking scripts just to get through basic pages.
Powerful tools come with responsibility. Here's how to use them without causing issues:
#Python #WebScraping #Automation #CyberSecurity #OpenSource
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
â6đ5đ2đ¤1đ1 1 1
Big tech giants like Google, ChatGPT, and Midjourney profit from your data. Every click, message, and upload can end up in advertisers hands. But you don't have to accept this trade-off anymore.
This collection curates 100 tools that put you in control. Swap out mainstream services for private file managers, discreet app stores, local AI models, encrypted cloud storage, and keyboards built for privacy. Each option keeps your information local or encrypts it before it ever touches a server.
Make security a habit: enable end-to-end encryption on everything you can, choose open-source software whenever possible, limit what you store in the cloud, and remember that free services usually monetize through your data. Small changes add up to real protection.
#Privacy #OpenSource #CyberSecurity #DataProtection #DigitalRights
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
đ6â4đ¤3đ2 1 1 1
This is who we are. This is what we believe. Ten principles that guide everything we share.
Knowledge should never sit behind paywalls or borders. The moment we accept only those who can afford it deserve to be informed, we lose something fundamental. Security awareness, threat intelligence, defensive techniques, all of it should flow freely.
Core security knowledge should not become a luxury item. When protecting yourself online comes with a price tag, something has gone wrong. Exceptions exist, but openness is always the default.
Support should come from conviction, never pressure. No forced subscriptions, no hidden fees, no holding content hostage. Support grows organically when people truly believe in what you do.
Your right to walk down a street without tracking and browse without profiling are the same fight. Both matter equally. Freedom is not a setting you toggle, it is a baseline.
Skills are tools. Vulnerability disclosure can save millions or get sold to exploit them. The difference lies in the hands that hold the knowledge. We choose protection, always.
Secret algorithms shape what you see. Hidden data collection profiles who you are. None of this survives public scrutiny intact, which is why scrutiny matters. Openness is the foundation of security.
Being safe online should not depend on affording premium software. Basic digital hygiene, encrypted communication, strong authentication, these are not perks for the privileged. They are minimum standards everyone deserves.
Anonymity protects journalists, activists, survivors, and ordinary citizens who do not want every move catalogued. It is not about hiding wrongdoing, it is about surviving.
You cannot defend what you do not understand. Knowing how tracking works, why apps want your location, what permissions mean, this is survival literacy for the digital age. We break down complex concepts into language anyone can follow.
Wanting a private life does not make you suspicious. Encrypting messages does not make you a target. Refusing to share personal data means you understand your life belongs to you, not a corporation or algorithm.
Privacy Not A Crime. It never was. And it never should be.
These ten commandments are who we are. If they resonate with you, you are already one of us.
#PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
đĨ°22đ17â7đ4đ¤2đ1
Which operating system is most vulnerable to these attacks: GrapheneOS, iOS, or standard Android? Which one is more secure in preventing real-time remote access by government spyware and zero-click attacks where the user doesnât have to do anything, but simply by inserting the SIM card and connecting to the network, the phone becomes infected and is accessed remotely?
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
đĨ°15â1 1
Chinese AI firm Z.ai has unveiled GLM-5.3, and its most striking achievement wasn't winning standard coding benchmarks. Instead, when tasked with auditing real-world open-source repositories, the GLM family of models identified a staggering 2,436 vulnerabilities across 269 projects. This discovery highlights a growing shift where AI is becoming a primary tool for automated security research, potentially outperforming traditional static analysis tools in finding complex logic flaws.
While many AI models are praised for their ability to generate code, GLM-5.3 demonstrated exceptional prowess in breaking it. The audit covered a wide range of popular open-source libraries, revealing critical issues that had gone unnoticed by human maintainers for years. The sheer volume over two thousand distinct flaws suggests that the current pace of software development may be outstripping our ability to manually review security implications.
This capability poses an interesting dynamic in the AI landscape. While Western models focus heavily on alignment and general utility, this Chinese-developed model has carved a niche in aggressive vulnerability scanning. It raises questions about whether future AI safety standards will need to include offensive capabilities as a core requirement for securing the global software supply chain.
For the open-source community, this is a double-edged sword. On one hand, having an AI that can instantly flag thousands of bugs accelerates the patching process and strengthens the ecosystem. On the other, it implies that malicious actors could potentially use similar models to scan for zero-day exploits just as quickly. The barrier to finding critical vulnerabilities is lowering, which means the window of exposure for unpatched software is shrinking rapidly.
Developers should anticipate a future where AI-assisted code review becomes mandatory before merging pull requests. Relying solely on human intuition or legacy linting tools may no longer be sufficient against the speed and depth of modern AI auditors.
#Vulnerabilities
#OpenSource #GLM53 #CyberSecurity #CodeAudit
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
đĨ°15đ3
A malicious update disguised as Google Chrome has infected Android devices in 26 countries, giving attackers near-total control over victims' phones.
The malware, called DragonDoll, uses "special functions" to bypass security measures and steal sensitive data from encrypted messaging apps like Telegram, WhatsApp, and Signal.
The attack relies on social engineering, tricking users into installing a fake version of the browser. Once installed, DragonDoll doesn't just steal files. It watches screen activity in real-time, intercepts incoming calls, and captures PINs and passwords as people type them. Most worryingly, it targets end-to-end encrypted apps by reading notifications and screen overlays, essentially bypassing the privacy protections users count on for secure chats.
The campaign has spread fast across 26 nations. The sophistication behind DragonDoll points to a well-funded group behind it, possibly state-sponsored or part of a major cybercrime network. Being able to read Signal messages, a platform known for rock-solid security, shows how serious this breach is. The attack happens at the device level, not by breaking the encryption itself.
#CyberSecurity #AndroidSafety #DragonDoll #PrivacyMatters #SpywareAlert
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
đĨ°17â4 1
Running AI agents comes with risks. They might touch files they shouldn't or access data they were never meant to see. That's where Ai Jail comes in handy. This multi-platform tool creates a controlled environment for AI agents, locking them down so they can only access what you explicitly allow.
Ai Jail uses built-in operating system features to do its job. On Linux, it leverages bwrap. On macOS, it relies on sandbox-exec. What happens is straightforward: the tool mounts only the directories an agent actually needs for its task.
So when you're testing a code-writing bot or a data-analysis script, that agent literally cannot see files outside its assigned sandbox. It's similar to containerization, but built specifically for the unique risks that come with autonomous AI decision-making.
Here's the thing, AI agents are getting smarter, and with that power comes greater potential for problems. A model might accidentally delete important files, pull credentials from your home directory, or reach out to external networks if left unconstrained. Ai Jail tackles this by taking a "deny-by-default" approach.
Developers and security researchers get a reliable way to test how an agent behaves without risking the rest of their machine.
#CyberSecurity #AISafety #OpenSource #DevOps #PrivacyTools
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
â4đ4
A new neural network called MessiahGPT has emerged on the dark web, significantly lowering the barrier to entry for cybercrime. For approximately eight dollars a month, this clandestine service allows users to generate sophisticated attack tools with a single prompt. The creators are even offering the first 50 requests completely free and without registration, making it accessible to anyone with an internet connection.
The implications are stark: you no longer need to be a skilled hacker or possess deep technical knowledge to launch a cyberattack. With MessiahGPT, a user can instantly generate an extortion scheme, create a convincing phishing page, and craft a detailed deception script, all in one go.
This turns complex cyber warfare into a consumer-grade service. Individuals with malicious intent but zero coding skills can now execute high-impact attacks.
Instead of spending weeks learning exploits or buying fragmented tools, criminals can rely on this AI to orchestrate the entire attack vector. This shift suggests a worrying trend where the technical expertise required for severe breaches is becoming obsolete, replaced by simple subscription fees and prompt engineering.
#MessiahGPT #Cybercrime #DarkWeb #AIThreats #Phishing
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
â5đ2 2
This media is not supported in your browser
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
đ6â2đ1
An open-source initiative called Deep State is changing how we visualize global naval activity. The project tracks 292 submarines currently operating across 30+ navies worldwide, offering a level of transparency that was previously unthinkable for underwater military movements.
The platform is built around a dynamic, real-time interactive map powered by open-source intelligence (OSINT). Instead of relying on classified reports, it pulls together publicly available data to display submarine positions as they are detected.
The system auto-updates every 6 hours, keeping the information fresh and aligned with the ever-changing geopolitical picture.
#Geoint #NavalTracking #OSINT #Submarines #DefenseTech
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
â4đ3 1