Privacy Not A Crime
669 subscribers
195 photos
19 videos
233 links
🔐 Take control of your digital freedom.

Curated tools and expert insights on Privacy, Cybersecurity and OSINT. Actionable guides to protect your data and communications.

Defend your rights online. 🔰
Download Telegram
🛍 AliExpress uses silent audio signals to track devices

Online shoppers may not realize it, but visiting AliExpress can trigger a hidden process that analyzes their device's audio subsystem. This technique, known as audio fingerprinting, doesn't involve recording conversations or activating microphones. Instead, the platform generates an inaudible sound signal internally and examines how the browser and hardware process it. The result becomes part of a broader digital profile used to identify users across sessions, even when traditional tracking methods are unavailable.

âš™ī¸ How the silent tracking mechanism works

Investigation revealed that AliExpress creates two independent AudioContext objects through scripts named collina.js and fireyejs.js, hosted within Alibaba's infrastructure under the AWSC directory. These contexts activate even when no audio or video elements exist on the page, no playback occurs, and no multimedia session is running. Technically, the scripts generate a sawtooth wave via an oscillator, route it through an AnalyserNode and ScriptProcessorNode, then connect it to a GainNode set to zero volume before sending it to AudioContext.destination.

Users hear absolutely nothing, yet the browser performs all the necessary audio processing. The unique way each device handles this silent signal helps build a distinctive fingerprint.

🖐 Why audio fingerprinting matters for your privacy

Unlike traditional cookies that can be deleted or blocked with a click, audio-based identification combines subtle hardware and browser variations into a persistent profile. This allows platforms to recognize returning visitors even when standard tracking mechanisms fail. Privacy advocates brought attention to this case, noting that such techniques enable user identification without relying on cookies at all. Interestingly, the whole thing surfaced almost by accident.

AliExpress argues that these measures help distinguish genuine buyers from automated systems, reducing fraud, fake accounts, and review manipulation. However, the technical capabilities collected allow building a device fingerprint far more resistant than a conventional cookie.

🛡 How to protect yourself from silent audio tracking

Switching to a privacy-oriented browser that is completely open source and has enhanced tracking protection enabled is a strong starting point, as these browsers intentionally distort audio context outputs to break fingerprinting attempts. Installing a reputable ad blocker can block the specific scripts responsible for generating these audio contexts. Using private browsing modes when visiting shopping platforms also adds a layer of separation. Finally, stay aware that many large e-commerce sites employ similar multi-layered tracking strategies combining canvas fingerprinting, font enumeration, and network profiling alongside audio analysis.

😊 If you enjoyed the article share it with your friends and follow us.

#AudioFingerprinting #AliExpress #DeviceTracking #BrowserSecurity #Privacy

@PrivacyNotACrime đŸ—Ŋ âŒ¨ī¸ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
7✍6👀33😈1
🚘 Malware takes over car stereos: Head units silently join a botnet

Your car's multimedia system is starting to look a lot like a regular computer. And like any computer, it carries the same risks. Kaspersky researchers recently uncovered malware hiding inside Android-based automotive head units built with DoFun firmware, quietly turning vehicles into nodes of a proxy botnet. Here's the unsettling part: drivers didn't need to download or tap anything. The infection happened automatically, through the very update mechanism the car was designed to trust.

đŸĻ  How the infection works

The attack chain starts with TWCore, a legitimate system application on DoFun head units. It's supposed to handle analytics data and push software updates. Under normal conditions, TWCore receives instructions from the manufacturer's cloud about which APK files to download and install. But the update schema includes a flag called installNotExists, allowing it to deploy applications that were never present on the device before. Attackers exploited this feature to silently push a malicious dropper called JarService onto connected vehicles. No user prompt, no visible interface, nothing.

JarService is essentially an empty shell. It has no UI and makes no attempt to impersonate a legitimate app. Its sole job is to decrypt embedded payload data stored in XOR-encrypted blocks and launch the next stage: a loader that uses encrypted strings and Java reflection to execute the final component. This final piece connects to a command-and-control server every 90 minutes, sending device information such as model, display resolution, MAC address, and Wi-Fi SSID. The C2 server replies with integer command identifiers that the Trojan maps to specific actions.

â˜ ī¸ What the malware actually does

The payload supports nine commands, including making HTTP requests, launching URLs in WebView instances, executing JavaScript, altering clipboard data, testing connectivity, and downloading additional modules. One particularly significant command, loadlib2, downloads and launches a reverse-proxy module called zhima. Once active, zhima converts the infected head unit into a traffic relay, allowing operators to route internet activity through the vehicle's connection.

This mirrors how residential proxy botnets work, where compromised endpoints provide geographically diverse egress infrastructure that can be monetized for fraud, scanning, and other malicious activity. Researchers also observed commands consistent with advertising abuse and click-fraud operations. Kaspersky identified seven distinct variants of the payload by trying different version numbers embedded in the file name, ranging from "3.57" up to "3.68".

❔ Who is behind it

Naming patterns, thread names in the code, and extensive infrastructure overlap point to the MoYu Group, a threat actor closely tied to the BADBOX botnet platform first documented by HUMAN Security in 2023. BADBOX has since infected more than one million Android devices worldwide, spanning phones, TVs, set-top boxes, and streaming sticks. Though German authorities disrupted part of the operation in late 2024, individual actors linked to it continue their activities. This campaign represents a clear expansion into automotive platforms.

DoFun, the Hong Kong based vendor supplying infotainment software for aftermarket head units and claiming to serve over 30 million vehicle owners globally, was notified by Kaspersky. The company reported fixing the underlying security issue in an infrastructure update.

😊 Follow us to stay informed about the latest threats and protect yourself.

#CarHacking #Botnet #AndroidMalware #DoFun #Cybersecurity

@PrivacyNotACrime đŸ—Ŋ âŒ¨ī¸ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
1✍5👀2
Buy us a coffee ☕
Has our content helped you today? Buy us a coffee to help us keep this space active, updated, and ad-free. Every contribution counts!

Thank you for your support! 🙏
1👌8✍422😁1👀1
This media is not supported in your browser
VIEW IN TELEGRAM
📃 Hostinger: Privacy-friendly hosting with minimal data collection

If you've ever tried to sign up for a hosting provider, you probably know the drill: fill out endless forms, hand over your real name, address, phone number, and sometimes even upload a photo of your ID. It's invasive and uncomfortable. Hostinger takes a different route, and that's exactly why it caught our attention.

đŸ’ŗ Sign up without revealing who you really are

Hostinger only asks for the bare minimum needed to get your account running. That means you can register with a pseudonym or even completely fictitious personal details, as long as your payment goes through. No awkward questions, no prying into your identity, no demanding to know where you live or what your real name is.

What's more refreshing is that they don't typically ask for any kind of documentation to verify who you are. Unless something unusual triggers a security check or there's a billing dispute, you won't be asked to send copies of your passport or utility bills. Compare that to all those hosting companies out there enforcing strict KYC procedures, basically building databases full of sensitive documents that could eventually get leaked or stolen.

👀 Less data means less risk

This is simple logic. The less information a company stores about you, the less there is to lose when something goes wrong. Big data breaches happen all the time, and every piece of personal data sitting on a server is another piece that could end up in the wrong hands. Hostinger's approach of not hoarding user data naturally shrinks that attack surface.

It also means your hosting activity stays disconnected from your real-world identity. Whether you're running a personal blog, a project for activism, or just experimenting with web development, nothing ties your content back to you personally. For people working in sensitive environments or simply wanting to stay under the radar, that separation matters a lot.

âš™ī¸ Locking things down even further

Hostinger gives you a good starting point, but you can take it further. Paying with cryptocurrency or prepaid cards keeps your financial trail away from your hosting account. Make sure HTTPS is active on all your sites so traffic stays encrypted end to end. Keep your CMS and plugins updated, since outdated software is the easiest way attackers gain access to server data. And if you want to be extra careful, always connect to your hosting control panel through a trusted VPN so your real IP never touches the login logs.

No hosting provider can promise total anonymity, but Hostinger's philosophy of collecting only what's strictly necessary puts it ahead of most alternatives. Worth considering if privacy is on your priority list.

📌 Check out everything it has to offer

😊 If you enjoyed the article share it with your friends and follow us.

#Hostinger #NoKYC #WebHosting #DigitalFootprint #PrivacyFirst

@PrivacyNotACrime đŸ—Ŋ âŒ¨ī¸ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
4✍14👀12👌9😁4đŸĻ„3🙈2211
âš”ī¸ Offensive AI to hunt vulnerabilities in your environment

Cyber threats move faster than most traditional defenses can track, and waiting for a breach to happen is not an option for any team that cares about its infrastructure. An open source project is bringing artificial intelligence directly into the vulnerability detection workflow, automating everything from reconnaissance to final reporting across your network, web applications, APIs, and email servers.

🧰 A full pentest lifecycle in one toolkit

The project structures its work around six phases that mirror a real ethical hacking engagement: reconnaissance, vulnerability analysis, proof of concept verification, exploitation, targeted attacks, and final report generation.

Each phase has a dedicated module that activates automatically based on the context you provide.
During the vulnerability analysis phase, the system checks for CVEs in your services, scans web applications and APIs for common weaknesses, hunts path traversal flaws using a built-in payload catalog, evaluates SSH configurations for weak ciphers and misconfigurations, checks email servers for known vulnerabilities, and even runs IP and domain reputation checks against DNSBL and RBL blacklists.

What really separates this from a standard scanner is the proof of concept phase. Instead of flooding you with raw findings and letting you sort through false positives manually, the AI generates simple PoCs to confirm each vulnerability is real before it makes it into your report. The final output is a structured technical report with executive summaries and concrete remediation recommendations.

đŸ“ģ Three scripts to start scanning

The scanning layer is intentionally simple. Three scripts cover the most common audit scenarios.

â–Ģī¸ redaudit.sh scans ports and open services across an IP range or CIDR block. You point it at your internal network, something like 192.168.1.0/24, and it maps what is exposed.

â–Ģī¸ webaudit.sh takes a domain or IP and runs a complete audit of the web application or API behind it, covering headers, injection vectors, and access control issues.

â–Ģī¸ fqdnaudit.sh starts from a fully qualified domain name and traces your entire infrastructure, mapping DNS records, subdomains, and the services attached to each one.

All three produce structured output in XML, CSV, or TXT, which feeds directly into the AI analysis phase. No manual parsing, no copy pasting results into a separate tool.

⌛ Flexible AI backends for every setup

The framework is model agnostic. You can connect it to Llama 3, DeepSeek, Gemini, Gemma 3, Mistral, Qwen, GPT, or run entirely local models through Ollama. There are dedicated launcher scripts for each, so switching between a fast local model for quick scans and a heavier cloud model for deep analysis takes one command. This matters a lot in enterprise environments where sensitive scan data cannot leave the internal network.

🛡 Protecting your environment while you scan

Running vulnerability scans, even automated ones, carries operational risk. A few practical steps keep things safe.

Schedule scans during maintenance windows so you are not triggering alerts in your SIEM or disrupting production traffic. Isolate test targets in a dedicated network segment whenever possible. Always validate critical findings with a manual check before you report them or push patches. And keep both the scanning scripts and the AI models updated, because a scanner that is six months out of date is missing a significant chunk of the current threat landscape.

If you are deploying this in a company, treat the generated reports as internal documents. They will contain IP ranges, service versions, and vulnerability details that an attacker would love to have. Store them with the same access controls you would apply to any sensitive infrastructure documentation.

🐱 Check this tool at GitHub

😊 If you enjoyed the article share it with your friends and follow us.

#VulnerabilityScanner #OffensiveAI #OpenSource #NetSec #PentestTools

@PrivacyNotACrime đŸ—Ŋ âŒ¨ī¸ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
👀4✍221
Privacy Not A Crime
Service message
Congratulations to the winner 😉🎉
Please open Telegram to view this post
VIEW IN TELEGRAM
👀5✍4311
I'm glad a real person, in this case, an Arab won, and not a bot, because lately, every time we held a giveaway, the channel would be flooded with bots.

Thanks, everyone!

Much more coming soon... 😝
Please open Telegram to view this post
VIEW IN TELEGRAM
👀11đŸ¤Ŗ5👌33✍2😁2
🔹 Exactly 21 years ago, on August 26, 2005, an interesting event occurred: the "The Million Dollar Homepage" website was launched.

🔹 At first glance, the project can be classified as "audacity and madness," BUT, nevertheless, the page managed to earn its creator one million dollars between 2005 and 2006.

🔹 In the mid-2000s, this story was on everyone's lips: a British student, Alex Tew, couldn't find money for his postgraduate studies, but instead of getting a regular job, he took a different approach. He created a website with a grid of one million "advertising blocks," called it "Million Dollar Homepage," set the price at one dollar per block, and started selling spaces (a minimum of 10x10 blocks) for banners.

🔹 Tew spent 50 euros on registering the domain and setting up hosting. Advertisers bought pixels and provided a link, a small image, and a bit of text that appeared when the cursor was hovered over the image.

🔹 After about a month, thanks to word-of-mouth and increased media attention, the page earned Tew over $250,000. In January 2006, the last 1000 pixels were sold at auction for $38,100. Tew earned his million. In addition to local brands, questionable online casinos, and dating sites, companies like Yahoo, The Times, and Napster also bought advertising space on the page.

🔹 According to Tew's own data, by the end of December 2005, the website had 25,000 unique visitors per hour. Some of them accidentally clicked on the banners and went to the advertisers' pages - only a few of the curious actually made purchases or took other targeted actions.

🔹 From the very beginning, Tew positioned the Million Dollar Homepage not only as an advertising platform but also as a kind of "museum of internet history," where one could acquire a vacant space: initially, it was assumed that the website would function for at least five years, and possibly forever.

🔹 As time has shown, neither Alex Tew nor his "page" were fleeting phenomena. Tew now runs a business that is valued at $2 billion, and the "million-dollar page" continues to live its own life - as an artifact of a bygone era, a subject of study, or even a source of nostalgic feelings for retro enthusiasts.

😊 If you enjoyed the article share it with your friends and follow us.

#MillionDollarHomepage #StudentEntrepreneur #CreativeFundraising #ViralMarketing #CollegeLife

@PrivacyNotACrime đŸ—Ŋ âŒ¨ī¸ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
✍6👌3👀2111
🔎 Android's new SafetyCore scans for explicit content

Google has quietly deployed "SafetyCore" across over a billion Android devices running version 9 or higher. The system component operates invisibly in the background, scanning photos stored on your phone to detect nudity. When users try to uninstall it, the service comes right back after a reboot. Some developers have found a workaround by installing a dummy APK that takes its place, preventing the scanner from returning.

📋 How the detection works

Right now, the algorithm mainly runs inside Google Messages, blurring anything it flags as explicit. But the real concern is the ContentSafetyManager API still under development. This interface lets any app send an image to the system classifier and get an instant verdict. What this means is dangerous: malicious software won't need its own neural networks anymore. A virus with basic storage access could simply ask the operating system to identify intimate images in your gallery.

🔓 What this means for encryption

The UK government has already made it official policy that content must be scanned at the operating system level. With SafetyCore built into Android, messaging apps like WhatsApp, Signal, and Telegram can no longer argue that end-to-end encryption makes verification impossible. Files get filtered on the device before they ever leave your phone.

😊 If you enjoyed the article share it with your friends and follow us.

#Android #Privacy #SafetyCore #Encryption #CyberSecurity

@PrivacyNotACrime đŸ—Ŋ âŒ¨ī¸ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
đŸ¤Ŧ10👀5🤔4✍2🤡22
🔍 How to peek under the hood of any website: Analyzing the BuiltWith tool

Ever found yourself wondering what makes certain websites tick so smoothly? You're not alone. Behind every successful site lies a collection of technologies working together, and many of us want to understand how they're put together. BuiltWith was born from exactly that kind of curiosity.

But here's the thing – BuiltWith isn't just another website analyzer you find with a quick search.

🌐 A comprehensive platform for web investigation

Think of it as a full-scale reconnaissance tool that peels back the layers of popular projects. It tracks everything from the main platform and Content Management System all the way down to smaller plugins and analytics scripts. This level of detail is invaluable for security researchers who need to map attack surfaces, or developers looking to learn from what others are doing right.

Without touching a single line of source code, you can see the complete technical architecture. That transparency helps professionals make informed decisions about their own choices while understanding where vulnerabilities might hide.

đŸ˜Ļ Practical use cases for security and development

For anyone in cybersecurity, knowing what stack a site runs is ground zero for vulnerability assessment. Spot a WordPress installation or specific e-commerce plugin, and you can check whether it's running outdated versions with known weaknesses. On the flip side, developers can study competitor setups and discover tools worth adding to their own toolkit.

Want to keep your own site less exposed? Try limiting third-party scripts, keeping everything patched to avoid version fingerprinting, and configuring your hosting to hide server headers. Some teams also use reverse proxies as an extra layer of obfuscation.

If BuiltWith doesn't fit your needs or budget, these alternatives offer solid capabilities:

🔷 WAPPAlyzer
🔷 WhatRuns

đŸ’ģ Check the BuiltWith tool, it's very useful!

😊 If you enjoyed the article share it with your friends and follow us.

#WebAnalysis #TechStack #CyberRecon #SecurityTools #DevOps

@PrivacyNotACrime đŸ—Ŋ âŒ¨ī¸ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
✍5👀42
🐝 Buzz: a self-hosted workspace where humans and AI agents collaborate

Buzz is an open-source, self-hostable workspace developed by Block, the company led by Jack Dorsey, designed so that humans and AI agents can work together in the same channels and share the same environment. Unlike traditional platforms where bots are simply bolted onto a human account, Buzz treats agents as first-class members with their own cryptographic keypairs, their own identity, and their own audit trail. Everything runs on a relay you control, giving you complete sovereignty over your data and infrastructure.

🔂 One identity model, one event log

The heart of Buzz is in its architecture. Built as a Nostr relay, every action taken within the platform gets recorded as a cryptographically signed event in a single append-only log. Whether it is a message, a code review, a workflow step, a reaction, a profile update, or a git push, all interactions share the same shape and the same identity model regardless of whether the author is a person or a process. That gives you a unified, searchable audit trail where attribution stays clear and verifiable at all times.

đŸ‘Ĩ Agents as real teammates, not plugins

On platforms like Slack or Discord, an AI agent is typically connected through an API integration and operates as an external bot. Buzz changes that completely. Agents join channels, participate in discussions, review code, run workflows, and even orchestrate other agents, all with the same standing as any human member. You can configure channel-level access controls so that an agent only sees and interacts with what it needs, reducing unnecessary exposure of sensitive information.

🏓 Repositories, code review, and workflows in one place

Buzz is not just a chat application. It functions as a complete development hub where repository management, code patches, CI/CD pipelines, reviews, and approvals all live alongside conversations. By bringing these tools into a single interface, teams avoid constantly switching between Slack, GitHub, and separate automation bots. Everything flows through the same relay, which means your project memory stays centralized, searchable, and signed.

🔐 Security and privacy considerations

Since Buzz is designed to be self-hosted, you retain full control over where your data lives and who can access it. There is no reliance on a third-party SaaS provider that could change terms, suffer a breach, or shut down a critical integration. At the same time, running your own relay brings responsibilities that deserve attention.

To keep your Buzz deployment secure, consider these practices. Always deploy your relay behind a properly configured reverse proxy with TLS encryption. Enforce strong authentication on every human and agent identity, and rotate cryptographic keys periodically. Apply the principle of least privilege when configuring agent access to channels and repositories. Keep your relay software updated to the latest version to benefit from security patches. And don't forget to implement regular backups of your event log and configuration data, because losing your relay means losing your entire workspace history.

Buzz is currently in developer preview and licensed under Apache 2.0, making it freely available for anyone to inspect, modify, and deploy. While it is still maturing, the concept of a unified workspace where humans and agents share equal footing under one cryptographic identity model offers an intriguing direction for collaborative development moving forward.

🐱 Check this tool at GitHub

😊 If you enjoyed the article share it with your friends and follow us.

#Buzz #SelfHosted #AgentNative #Nostr #OpenSource

@PrivacyNotACrime đŸ—Ŋ âŒ¨ī¸ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
👀5✍41
This media is not supported in your browser
VIEW IN TELEGRAM
🆕 Weekly Cybersecurity News Roundup

A week marked by significant global shifts: the United States declared a state of emergency over foreign components in power grids, China began removing Windows from government institutions, and AI agents successfully achieved root access in external infrastructure for the first time in just 13 hours.

📰 Here are the most interesting stories we gathered so you don't miss anything.

🌎 Global developments

🔹 Donald Trump declared a state of emergency due to foreign equipment in US power grids. The decree allows for the isolation and replacement of foreign components directly in running infrastructure.

🔹 The National Security Agency (NSA) is seeking access to all advanced AI models and has requested developers to provide 30 days to verify each new system before its launch.

🔹China is eliminating the government version of Windows from state institutions and migrating to domestically manufactured Kylin and UOS systems.

🔹 The UN and the Red Cross warned that the world is close to weapons capable of autonomously selecting targets and urged the establishment of legal limits.

🔹 Nvidia reported record profits of $96 billion, but the industry, which has invested $1.5 trillion in AI infrastructure, still needs to generate double that amount.

🛡 Cybersecurity updates

🔹 The FBI dismantled the infrastructure of the Chinese group QTFY, which for years hid the source of its attacks behind hacked routers.

🔹 A breach in the free Wi-Fi system at British airports resulted in the leak of data for 8.7 million passengers: emails, phone numbers, postal codes, and car license plates.

🔹 OpenAI published a technical report on how AI agents managed to move from initial detection to root access in Hugging Face's infrastructure within 13 hours.

🔹 Forensic experts unlocked a Google Pixel with GrapheneOS for the first time, accessing the owner's correspondence and photos.

🔹 The Aur0ra group transformed the Cursor AI agent into a standard attack tool: it searched for targets within already compromised networks, verified accounts, and helped expand access in real companies.

đŸ—Ŗ Share in the comments how your week went and which news surprised you the most.

😊 Follow us to stay informed about the latest threats and protect yourself.

#PowerGrid #AIagents #WindowsRemoval #DataBreach #SecurityNews

@PrivacyNotACrime đŸ—Ŋ âŒ¨ī¸ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
1👀11👌5✍4đŸĨ°4😁4đŸĨą211
🤖 Android 17 closes an old HTTPS privacy gap

Android 17 is about to plug a privacy hole in HTTPS that has been there for a long time. Once it ships, your ISP and other watchers on the network will have a much harder time telling which websites and services you actually connect to. The trick behind it is a feature called Encrypted Client Hello, or ECH, and it changes how your phone talks to a server in the very first moment of a connection.

đŸ’ģ The part of HTTPS that gave you away

Here is the thing most people miss: HTTPS encrypts what you send and receive, but not the very first handshake. When your device opens a connection, it sends a small signal called the Server Name Indication, or SNI, that basically says "I am going to example.com." That part travels in plain text. So even though your browsing is locked down, an ISP, a cafÊ Wi-Fi operator, or anyone sniffing the local network can read the domain names you visit. No decryption needed. They do not see the pages, but they see enough to build a rough picture of your day.

âš™ī¸ How ECH changes that

ECH encrypts that handshake, including the SNI. Now the person on the other side of your connection only sees that you are talking to some server, not which one. Your provider can no longer tell whether you are opening a bank, a news site, or a social app just by peeking at the initial request. In effect, it pushes encryption all the way back to the first line of contact with the server.

❕What this means for you

It is a real step forward against casual traffic analysis and the kind of metadata some providers like to log. The catch is that ECH needs both sides on board: your phone and the website. The big browsers and content delivery networks are already rolling it out, but older sites may fall back to the old open SNI until they catch up. And to be clear, it hides the domain, not the IP address you connect to, though it does make linking IPs to sites much harder for anyone who is not properly set up to do it.

To get the most out of it, keep your browser and apps up to date, and pair it with encrypted DNS like DoH or DoT so your lookups stay covered too.

😊 Follow us to stay informed about the latest threats and protect yourself.

#Android17 #Privacy #ECH #HTTPS #CyberSecurity

@PrivacyNotACrime đŸ—Ŋ âŒ¨ī¸ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
✍5👀41
🌂 Clone-Wars: A collection of open-source app clones

Clone-Wars is a GitHub repository that collects clones of apps you already know: Instagram, Netflix, TikTok, Spotify, WhatsApp, and a whole bunch of other popular services. For each project you get the full code, a working demo, and a breakdown of the tech stack used to build it.

đŸ’ģ What makes it useful

Instead of piecing together random tutorials, you get a single place to study how real features are actually implemented. Want to see how a video player or a chat interface works under the hood? Clone one of these projects, run it locally, and start poking around. It's one of the fastest ways to go from I've read about it to I've actually built it.

Whether you're prepping for interviews, building a portfolio, or just curious about how your favourite apps are put together, it's a low-friction way to learn.

đŸŽĨ Getting started

The repo is straightforward: pick a project, clone it, and start reading. The tech stack notes on each project page make it easy to pick something that matches your current skill level.

🐱 Check out this collection at GitHub

😊 If you enjoyed the article share it with your friends and follow us.

#CloneWars #OpenSource #LearnToCode #AppClones #DevProjects

@PrivacyNotACrime đŸ—Ŋ âŒ¨ī¸ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
✍12👀2
📱 Cleared your Firefox history? Doesn't matter: your habits are already packed into a digital profile

Under the hood of the latest update hides an undeletable snapshot of your online life. Mozilla has laid out the rules of Smart Window, a dedicated Firefox mode with a built-in AI assistant that studies the pages you browse and the chats you hold, remembers what catches your interest, and uses all of it to craft its answers. Little by little, browser history is ceasing to be a list of visited pages and becoming a full-blown personal profile.

🧠 How Memories are built

Firefox condenses your habits into short descriptions it calls Memories. The very first time you launch this mode, the system can chew through your history from the last 60 days, or up to 3000 entries. Regular tabs, smart windows and conversations with the assistant all feed into it. Private Browsing activity stays out, and whatever Memories are created remain stored on your device.

Now the part that stings: to assemble that profile, the browser temporarily ships your history and chats off to Mozilla's servers. The company insists everything is wiped after processing and that none of it is used to train their models. Whenever you talk to the assistant, Firefox attaches the relevant Memories, page titles, addresses and content it found, then hands the whole package over to a third-party language model.

👁 Who really gets to see your data

The model provider only sees Mozilla's IP address, never yours, and promises not to keep the conversation. In the settings you can choose between models from Google, Alibaba or OpenAI, or hook up your own endpoint. Do that and things change: the data travels straight to whoever runs that endpoint, under their privacy policy and nobody else's.

On top of the AI core, Smart Window can search the web, cite its sources, cluster related tabs, spot duplicates and render visual previews of pages you've been to. Mozilla is also working on bringing back past work sessions and autofilling forms based on whatever context the browser has gathered about you.

🗑 Voluntary, yes. Easy to erase, not quite

Everything here is opt-in and requires a Mozilla account. For now, Smart Window is in beta and only reaching English-speaking users in the US and Canada. From the Firefox settings you can block new Memories from being created, delete entries one by one, or pull the plug on the AI features altogether. But here's the detail worth remembering: wiping your history does not wipe the Memories already created. That portrait of your habits lives a life of its own.

😊 Follow us to stay informed about the latest threats and protect yourself.

#Firefox #Mozilla #Memories #SmartWindow #Privacy

@PrivacyNotACrime đŸ—Ŋ âŒ¨ī¸ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
đŸ¤Ŧ14✍7🤔6🤡41
🧭 Redteaming cheatsheet: The whole operation in one guide

Every so often a resource pops up that feels less like a project and more like a shared brain. RedTeaming CheatSheet is exactly that: an open collection of commands and techniques maintained by pentester Yoni Schats as his personal compendium on offensive security, now available to anyone who wants to sharpen their skills.

Think of it as an attack roadmap. Each phase, from reconnaissance all the way to establishing a foothold in the network, comes with the right command ready to go, and right next to it, notes on OPSEC so the operator's actions don't end up splashed across security logs and alerts.

â„šī¸ What's inside

The whole thing is organized by stages, which makes it surprisingly easy to navigate even though the scope is huge. There's a section on reconnaissance and initial access covering phishing techniques, followed by a substantial Windows Active Directory block that walks through enumeration, privilege escalation, relaying and lateral movement. The clouds get their own dedicated chapters for Azure and AWS, and the collection rounds off with OPSEC guidance for Cobalt Strike operations plus a practical walkthrough on cracking passwords with Hashcat.

For anyone studying for certifications, preparing lab exercises or simply trying to understand how attackers chain techniques together, having everything laid out step by step is a real time saver. It also doubles as a defensive reference: if you know exactly which commands a red teamer runs at each stage, you know precisely what to log, alert on and block.

âŦ‡ī¸ How to get the most out of it

Don't treat it as a copy-paste menu. The real value comes from reading why each technique works and what noise it generates. Pair the cheat sheet with a home lab, test your detection rules against its commands, and you'll strengthen your skills on both ends, offense and defense alike.

🐱 The entire repository is free and hosted on GitHub.

😊 If you enjoyed the article share it with your friends and follow us.

#RedTeam #Pentesting #ActiveDirectory #CheatSheet #CyberSecurity

@PrivacyNotACrime đŸ—Ŋ âŒ¨ī¸ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
3✍83
📸 Free AI bot for images and videos with internet access

We found a useful new AI bot that creates images and videos directly in Telegram with real-time internet access. This tool brings generative capabilities right to your messaging app without needing complicated setups or expensive subscriptions.

➕ How it works

The bot runs entirely within Telegram, letting you make visual content through simple text prompts. Whether you need marketing materials, concept art, or social media posts, the AI reads your descriptions and produces results quickly. Its built-in internet connection means it can pull from current events, trending topics, or specific visual styles online.

The service is completely free, though there are generation limits applied weekly to prevent abuse and keep access fair for everyone.

These caps are reasonable for casual creators and let most users test things out without hitting paywalls.

❔ What you get

â–Ģī¸ Text-to-image and text-to-video generation

â–Ģī¸ Real-time internet access for fresh references

â–Ģī¸ No app installation needed

â–Ģī¸ Free tier with weekly limits

â–Ģī¸ Multiple artistic styles supported

This is great for content creators, marketers, or anyone needing quick visuals without paying for professional software or premium AI services. The mix of simplicity and live web access sets it apart from many standalone generators.

🛡 Stay secure

When using public AI bots, remember to avoid sharing sensitive personal information in your prompts. Some services may log inputs for training purposes.

🆓  Try it free here

😊 If you enjoyed the article share it with your friends and follow us.

#AIBot #ImageGeneration #FreeTools #TelegramBots #TechTips

@PrivacyNotACrime đŸ—Ŋ âŒ¨ī¸ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
11✍5👌311
♾ Pocsuite3: A modular arsenal for PoC development and vulnerability testing

Anyone doing bug bounty hunting or pentesting knows the pain of juggling half a dozen tools just to validate a single vulnerability. Pocsuite3, an open-source remote vulnerability testing and proof-of-concept framework developed by the Knownsec 404 team, aims to solve that by bringing discovery, verification and exploitation together in one coherent workflow. It isn't new, but its flexibility keeps it a staple in researchers' toolkits.

🛠 Built to be extended

What truly defines Pocsuite3 is its plugin architecture. You can attach custom modules (plugins) to reshape how the framework behaves, from target handling to output reporting. PoC scripts can also be loaded dynamically from many places: local files, Redis instances, databases, or the Seebug platform. In practice, your exploit library travels with you and adapts to nearly any scenario without reinventing your tooling.

đŸŸĸ Recon and verification in one pipeline

The framework integrates natively with a strong lineup of external services: Seebug, ZoomEye, Shodan, Ceye and Interactsh. With ZoomEye or Shodan you can pull targets straight from cyberspace search engines, while Ceye and Interactsh handle verification of out-of-band (OOB) DNS and HTTP callbacks, essential for blind vulnerabilities like SSRF or blind RCE. Less manual glue work, more actual testing.

🔹 Nuclei templates? Bring them along

A particularly practical detail: Pocsuite3 supports YAML-based PoCs compatible with the Nuclei template format. So if you have spent years building a Nuclei template collection, that library isn't wasted. Drop it in and run everything under a second engine, which makes adopting the framework nearly effortless.

đŸ—Ŗ Stay on the right side of the line

Any offensive tooling like this is meant for authorized testing only: your own infrastructure, clearly scoped bug bounty programs, or engagements where you hold explicit written permission. Firing PoCs at infrastructure you don't own can lead to serious legal consequences, so always confirm your scope beforehand.

And if you're on the defending side, remember that frameworks like this make exploitation trivially easy. That alone is a solid argument for patching fast, reducing your internet-facing surface, and watching for unusual outbound callback traffic, a classic indicator of OOB-based probing.

🐱 You can try it out or browse the source code at GitHub

😊 If you enjoyed the article share it with your friends and follow us.

#BugBounty #Pentesting #OpenSource #CyberSecurity #Pocsuite3

@PrivacyNotACrime đŸ—Ŋ âŒ¨ī¸ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
1👌6
Media is too big
VIEW IN TELEGRAM
âžĄī¸ RFID relay attack by Lukas Stefanko.

â„šī¸ It's very important to know how criminals operate. You'll find this video interesting.
Please open Telegram to view this post
VIEW IN TELEGRAM
1👌411
This media is not supported in your browser
VIEW IN TELEGRAM
đŸ™‹â€â™‚ī¸ NSW bill would let police clone your phone at a traffic stop, without a warrant

A piece of legislation with serious privacy implications just landed in New South Wales. On Friday, the Minns government introduced a bill that would allow police to plug your phone into military-grade extraction hardware and copy its contents, and a simple roadside stop could be enough. The technology is the Universal Forensic Extraction Device (UFED) built by Israeli firm Cellebrite, the same equipment used by ICE and border agents in the United States. In minutes it can download contacts, messages, photos, browsing history, call logs, health data and even files you believed were gone forever.

❌ Refusing to unlock is no longer a real option

Here's where it gets thorny. The draft legislation states that invoking the traditional right against self-incrimination is not a valid reason to refuse to unlock your device, effectively removing a legal shield people assumed they had. And while Cellebrite's UFED kit is widely reported to be capable of bypassing locked phones and brute forcing passcodes, so withholding your PIN may not protect you either.

The tooling is also known to extract content from encrypted apps like WhatsApp, Signal and Telegram, along with location history and metadata.

âš–ī¸ Two separate measures often blurred together

Public debate has mixed up two distinct parts of the bill, so it's worth setting them straight. The first gives police access to unredacted images from toll road cameras, although the government insists this will be restricted to investigations into serious indictable offences or missing person cases, with a staged rollout beginning at the Sydney Harbour Bridge and Tunnel. The second measure adds NSW driver licence photos to the National Driver Licence Facial Recognition Solution, a national database that South Australia and Western Australia already feed into. Civil liberties groups warn that database lacks meaningful safeguards, and that Cellebrite use carries no reporting requirements, no known policies on how downloaded data is stored or shared, and no obligation to destroy it once a matter concludes.

🤩 Sold as an organised-crime weapon, used on the beat

Officially, the package targets organised crime, giving NSW Police and the Crime Commission stronger tools against sophisticated networks. Critics counter that the powers reach well beyond crime bosses to anyone pulled over or caught up in an inquiry. Until now, this extraction technology required a warrant for serious investigations; the bill extends it to everyday policing. One nuance matters here: legal commentators note that the self-incrimination override applies to forced device examinations, not to criminal trials themselves, where the presumption of innocence formally remains intact.

🛡 How to protect yourself

A few practical steps are worth taking right now. Use a long alphanumeric passcode rather than a short PIN, since longer codes are dramatically harder to crack. Disable lock-screen message previews, and learn your phone's lockdown features that block biometric unlock. Keep sensitive material off cloud syncs and rely on local backups, use disappearing messages for private conversations, and carry a clean secondary device if your work makes you a likely target.

Most importantly, minimise what permanently lives on your phone, because deleted files are evidently not safe either.

😊 Follow us to stay informed about the latest threats and protect yourself.

#SurveillanceState #NSWPolice #DigitalPrivacy #CivilLiberties #PhoneSecurity

@PrivacyNotACrime đŸ—Ŋ âŒ¨ī¸ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
1đŸ¤Ŧ6👌4👀1