Ever found yourself wondering what makes certain websites tick so smoothly? You're not alone. Behind every successful site lies a collection of technologies working together, and many of us want to understand how they're put together. BuiltWith was born from exactly that kind of curiosity.
But here's the thing – BuiltWith isn't just another website analyzer you find with a quick search.
Think of it as a full-scale reconnaissance tool that peels back the layers of popular projects. It tracks everything from the main platform and Content Management System all the way down to smaller plugins and analytics scripts. This level of detail is invaluable for security researchers who need to map attack surfaces, or developers looking to learn from what others are doing right.
Without touching a single line of source code, you can see the complete technical architecture. That transparency helps professionals make informed decisions about their own choices while understanding where vulnerabilities might hide.
For anyone in cybersecurity, knowing what stack a site runs is ground zero for vulnerability assessment. Spot a WordPress installation or specific e-commerce plugin, and you can check whether it's running outdated versions with known weaknesses. On the flip side, developers can study competitor setups and discover tools worth adding to their own toolkit.
Want to keep your own site less exposed? Try limiting third-party scripts, keeping everything patched to avoid version fingerprinting, and configuring your hosting to hide server headers. Some teams also use reverse proxies as an extra layer of obfuscation.
If BuiltWith doesn't fit your needs or budget, these alternatives offer solid capabilities:
#WebAnalysis #TechStack #CyberRecon #SecurityTools #DevOps
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
✍5👀4 2
Buzz is an open-source, self-hostable workspace developed by Block, the company led by Jack Dorsey, designed so that humans and AI agents can work together in the same channels and share the same environment. Unlike traditional platforms where bots are simply bolted onto a human account, Buzz treats agents as first-class members with their own cryptographic keypairs, their own identity, and their own audit trail. Everything runs on a relay you control, giving you complete sovereignty over your data and infrastructure.
The heart of Buzz is in its architecture. Built as a Nostr relay, every action taken within the platform gets recorded as a cryptographically signed event in a single append-only log. Whether it is a message, a code review, a workflow step, a reaction, a profile update, or a git push, all interactions share the same shape and the same identity model regardless of whether the author is a person or a process. That gives you a unified, searchable audit trail where attribution stays clear and verifiable at all times.
On platforms like Slack or Discord, an AI agent is typically connected through an API integration and operates as an external bot. Buzz changes that completely. Agents join channels, participate in discussions, review code, run workflows, and even orchestrate other agents, all with the same standing as any human member. You can configure channel-level access controls so that an agent only sees and interacts with what it needs, reducing unnecessary exposure of sensitive information.
Buzz is not just a chat application. It functions as a complete development hub where repository management, code patches, CI/CD pipelines, reviews, and approvals all live alongside conversations. By bringing these tools into a single interface, teams avoid constantly switching between Slack, GitHub, and separate automation bots. Everything flows through the same relay, which means your project memory stays centralized, searchable, and signed.
Since Buzz is designed to be self-hosted, you retain full control over where your data lives and who can access it. There is no reliance on a third-party SaaS provider that could change terms, suffer a breach, or shut down a critical integration. At the same time, running your own relay brings responsibilities that deserve attention.
To keep your Buzz deployment secure, consider these practices. Always deploy your relay behind a properly configured reverse proxy with TLS encryption. Enforce strong authentication on every human and agent identity, and rotate cryptographic keys periodically. Apply the principle of least privilege when configuring agent access to channels and repositories. Keep your relay software updated to the latest version to benefit from security patches. And don't forget to implement regular backups of your event log and configuration data, because losing your relay means losing your entire workspace history.
Buzz is currently in developer preview and licensed under Apache 2.0, making it freely available for anyone to inspect, modify, and deploy. While it is still maturing, the concept of a unified workspace where humans and agents share equal footing under one cryptographic identity model offers an intriguing direction for collaborative development moving forward.
#Buzz #SelfHosted #AgentNative #Nostr #OpenSource
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
👀5✍4 1
This media is not supported in your browser
VIEW IN TELEGRAM
A week marked by significant global shifts: the United States declared a state of emergency over foreign components in power grids, China began removing Windows from government institutions, and AI agents successfully achieved root access in external infrastructure for the first time in just 13 hours.
#PowerGrid #AIagents #WindowsRemoval #DataBreach #SecurityNews
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
1👀11👌5✍4🥰4😁4🥱2 1 1
Android 17 is about to plug a privacy hole in HTTPS that has been there for a long time. Once it ships, your ISP and other watchers on the network will have a much harder time telling which websites and services you actually connect to. The trick behind it is a feature called Encrypted Client Hello, or ECH, and it changes how your phone talks to a server in the very first moment of a connection.
Here is the thing most people miss: HTTPS encrypts what you send and receive, but not the very first handshake. When your device opens a connection, it sends a small signal called the Server Name Indication, or SNI, that basically says "I am going to example.com." That part travels in plain text. So even though your browsing is locked down, an ISP, a café Wi-Fi operator, or anyone sniffing the local network can read the domain names you visit. No decryption needed. They do not see the pages, but they see enough to build a rough picture of your day.
ECH encrypts that handshake, including the SNI. Now the person on the other side of your connection only sees that you are talking to some server, not which one. Your provider can no longer tell whether you are opening a bank, a news site, or a social app just by peeking at the initial request. In effect, it pushes encryption all the way back to the first line of contact with the server.
It is a real step forward against casual traffic analysis and the kind of metadata some providers like to log. The catch is that ECH needs both sides on board: your phone and the website. The big browsers and content delivery networks are already rolling it out, but older sites may fall back to the old open SNI until they catch up. And to be clear, it hides the domain, not the IP address you connect to, though it does make linking IPs to sites much harder for anyone who is not properly set up to do it.
To get the most out of it, keep your browser and apps up to date, and pair it with encrypted DNS like DoH or DoT so your lookups stay covered too.
#Android17 #Privacy #ECH #HTTPS #CyberSecurity
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
✍5👀4 1
Clone-Wars is a GitHub repository that collects clones of apps you already know: Instagram, Netflix, TikTok, Spotify, WhatsApp, and a whole bunch of other popular services. For each project you get the full code, a working demo, and a breakdown of the tech stack used to build it.
Instead of piecing together random tutorials, you get a single place to study how real features are actually implemented. Want to see how a video player or a chat interface works under the hood? Clone one of these projects, run it locally, and start poking around. It's one of the fastest ways to go from I've read about it to I've actually built it.
Whether you're prepping for interviews, building a portfolio, or just curious about how your favourite apps are put together, it's a low-friction way to learn.
The repo is straightforward: pick a project, clone it, and start reading. The tech stack notes on each project page make it easy to pick something that matches your current skill level.
#CloneWars #OpenSource #LearnToCode #AppClones #DevProjects
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
✍12👀2
Under the hood of the latest update hides an undeletable snapshot of your online life. Mozilla has laid out the rules of Smart Window, a dedicated Firefox mode with a built-in AI assistant that studies the pages you browse and the chats you hold, remembers what catches your interest, and uses all of it to craft its answers. Little by little, browser history is ceasing to be a list of visited pages and becoming a full-blown personal profile.
Firefox condenses your habits into short descriptions it calls Memories. The very first time you launch this mode, the system can chew through your history from the last 60 days, or up to 3000 entries. Regular tabs, smart windows and conversations with the assistant all feed into it. Private Browsing activity stays out, and whatever Memories are created remain stored on your device.
Now the part that stings: to assemble that profile, the browser temporarily ships your history and chats off to Mozilla's servers. The company insists everything is wiped after processing and that none of it is used to train their models. Whenever you talk to the assistant, Firefox attaches the relevant Memories, page titles, addresses and content it found, then hands the whole package over to a third-party language model.
The model provider only sees Mozilla's IP address, never yours, and promises not to keep the conversation. In the settings you can choose between models from Google, Alibaba or OpenAI, or hook up your own endpoint. Do that and things change: the data travels straight to whoever runs that endpoint, under their privacy policy and nobody else's.
On top of the AI core, Smart Window can search the web, cite its sources, cluster related tabs, spot duplicates and render visual previews of pages you've been to. Mozilla is also working on bringing back past work sessions and autofilling forms based on whatever context the browser has gathered about you.
Everything here is opt-in and requires a Mozilla account. For now, Smart Window is in beta and only reaching English-speaking users in the US and Canada. From the Firefox settings you can block new Memories from being created, delete entries one by one, or pull the plug on the AI features altogether. But here's the detail worth remembering: wiping your history does not wipe the Memories already created. That portrait of your habits lives a life of its own.
#Firefox #Mozilla #Memories #SmartWindow #Privacy
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
🤬14✍7🤔6🤡4 1
Every so often a resource pops up that feels less like a project and more like a shared brain. RedTeaming CheatSheet is exactly that: an open collection of commands and techniques maintained by pentester Yoni Schats as his personal compendium on offensive security, now available to anyone who wants to sharpen their skills.
Think of it as an attack roadmap. Each phase, from reconnaissance all the way to establishing a foothold in the network, comes with the right command ready to go, and right next to it, notes on OPSEC so the operator's actions don't end up splashed across security logs and alerts.
The whole thing is organized by stages, which makes it surprisingly easy to navigate even though the scope is huge. There's a section on reconnaissance and initial access covering phishing techniques, followed by a substantial Windows Active Directory block that walks through enumeration, privilege escalation, relaying and lateral movement. The clouds get their own dedicated chapters for Azure and AWS, and the collection rounds off with OPSEC guidance for Cobalt Strike operations plus a practical walkthrough on cracking passwords with Hashcat.
For anyone studying for certifications, preparing lab exercises or simply trying to understand how attackers chain techniques together, having everything laid out step by step is a real time saver. It also doubles as a defensive reference: if you know exactly which commands a red teamer runs at each stage, you know precisely what to log, alert on and block.
Don't treat it as a copy-paste menu. The real value comes from reading why each technique works and what noise it generates. Pair the cheat sheet with a home lab, test your detection rules against its commands, and you'll strengthen your skills on both ends, offense and defense alike.
#RedTeam #Pentesting #ActiveDirectory #CheatSheet #CyberSecurity
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
3✍8 3
We found a useful new AI bot that creates images and videos directly in Telegram with real-time internet access. This tool brings generative capabilities right to your messaging app without needing complicated setups or expensive subscriptions.
The bot runs entirely within Telegram, letting you make visual content through simple text prompts. Whether you need marketing materials, concept art, or social media posts, the AI reads your descriptions and produces results quickly. Its built-in internet connection means it can pull from current events, trending topics, or specific visual styles online.
The service is completely free, though there are generation limits applied weekly to prevent abuse and keep access fair for everyone.
These caps are reasonable for casual creators and let most users test things out without hitting paywalls.
This is great for content creators, marketers, or anyone needing quick visuals without paying for professional software or premium AI services. The mix of simplicity and live web access sets it apart from many standalone generators.
When using public AI bots, remember to avoid sharing sensitive personal information in your prompts. Some services may log inputs for training purposes.
#AIBot #ImageGeneration #FreeTools #TelegramBots #TechTips
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
11✍5👌3 1 1
Anyone doing bug bounty hunting or pentesting knows the pain of juggling half a dozen tools just to validate a single vulnerability. Pocsuite3, an open-source remote vulnerability testing and proof-of-concept framework developed by the Knownsec 404 team, aims to solve that by bringing discovery, verification and exploitation together in one coherent workflow. It isn't new, but its flexibility keeps it a staple in researchers' toolkits.
What truly defines Pocsuite3 is its plugin architecture. You can attach custom modules (plugins) to reshape how the framework behaves, from target handling to output reporting. PoC scripts can also be loaded dynamically from many places: local files, Redis instances, databases, or the Seebug platform. In practice, your exploit library travels with you and adapts to nearly any scenario without reinventing your tooling.
The framework integrates natively with a strong lineup of external services: Seebug, ZoomEye, Shodan, Ceye and Interactsh. With ZoomEye or Shodan you can pull targets straight from cyberspace search engines, while Ceye and Interactsh handle verification of out-of-band (OOB) DNS and HTTP callbacks, essential for blind vulnerabilities like SSRF or blind RCE. Less manual glue work, more actual testing.
A particularly practical detail: Pocsuite3 supports YAML-based PoCs compatible with the Nuclei template format. So if you have spent years building a Nuclei template collection, that library isn't wasted. Drop it in and run everything under a second engine, which makes adopting the framework nearly effortless.
Any offensive tooling like this is meant for authorized testing only: your own infrastructure, clearly scoped bug bounty programs, or engagements where you hold explicit written permission. Firing PoCs at infrastructure you don't own can lead to serious legal consequences, so always confirm your scope beforehand.
And if you're on the defending side, remember that frameworks like this make exploitation trivially easy. That alone is a solid argument for patching fast, reducing your internet-facing surface, and watching for unusual outbound callback traffic, a classic indicator of OOB-based probing.
#BugBounty #Pentesting #OpenSource #CyberSecurity #Pocsuite3
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
1👌6
Media is too big
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
1👌4 1 1
This media is not supported in your browser
VIEW IN TELEGRAM
A piece of legislation with serious privacy implications just landed in New South Wales. On Friday, the Minns government introduced a bill that would allow police to plug your phone into military-grade extraction hardware and copy its contents, and a simple roadside stop could be enough. The technology is the Universal Forensic Extraction Device (UFED) built by Israeli firm Cellebrite, the same equipment used by ICE and border agents in the United States. In minutes it can download contacts, messages, photos, browsing history, call logs, health data and even files you believed were gone forever.
Here's where it gets thorny. The draft legislation states that invoking the traditional right against self-incrimination is not a valid reason to refuse to unlock your device, effectively removing a legal shield people assumed they had. And while Cellebrite's UFED kit is widely reported to be capable of bypassing locked phones and brute forcing passcodes, so withholding your PIN may not protect you either.
The tooling is also known to extract content from encrypted apps like WhatsApp, Signal and Telegram, along with location history and metadata.
Public debate has mixed up two distinct parts of the bill, so it's worth setting them straight. The first gives police access to unredacted images from toll road cameras, although the government insists this will be restricted to investigations into serious indictable offences or missing person cases, with a staged rollout beginning at the Sydney Harbour Bridge and Tunnel. The second measure adds NSW driver licence photos to the National Driver Licence Facial Recognition Solution, a national database that South Australia and Western Australia already feed into. Civil liberties groups warn that database lacks meaningful safeguards, and that Cellebrite use carries no reporting requirements, no known policies on how downloaded data is stored or shared, and no obligation to destroy it once a matter concludes.
Officially, the package targets organised crime, giving NSW Police and the Crime Commission stronger tools against sophisticated networks. Critics counter that the powers reach well beyond crime bosses to anyone pulled over or caught up in an inquiry. Until now, this extraction technology required a warrant for serious investigations; the bill extends it to everyday policing. One nuance matters here: legal commentators note that the self-incrimination override applies to forced device examinations, not to criminal trials themselves, where the presumption of innocence formally remains intact.
A few practical steps are worth taking right now. Use a long alphanumeric passcode rather than a short PIN, since longer codes are dramatically harder to crack. Disable lock-screen message previews, and learn your phone's lockdown features that block biometric unlock. Keep sensitive material off cloud syncs and rely on local backups, use disappearing messages for private conversations, and carry a clean secondary device if your work makes you a likely target.
Most importantly, minimise what permanently lives on your phone, because deleted files are evidently not safe either.
#SurveillanceState #NSWPolice #DigitalPrivacy #CivilLiberties #PhoneSecurity
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
1🤬6👌4👀1
This media is not supported in your browser
VIEW IN TELEGRAM
Your phone number is far more than a way to call your family. It is the key that unlocks your banking apps, your email recovery options and your entire digital life. Attackers know this, and they have developed two very different techniques to take control of it: SIM swapping and SIM cloning. Understanding how each one works is the first step to protecting yourself.
In a SIM swap attack, criminals convince your operator to transfer your number to a SIM card they control. They usually do this through social engineering: posing as the victim with stolen personal data, bribing insiders inside the carrier, or exploiting weak porting procedures.
The victim noticed nothing until their phone showed no signal. By then, every call and SMS had been landing on the attacker's device, including one-time codes for email, banking and social media. Accounts relying on SMS-based two-factor authentication fall like dominoes.
SIM cloning takes a different path. Instead of tricking the operator, the attacker gets physical access to the victim's SIM card for a few minutes. Using a card reader connected to a computer and a blank programmable SIM, they extract the identity data and the secret authentication key stored in the chip, then write it onto the duplicate. Once inserted into another phone, the clone behaves exactly like the original, receiving calls and messages while the victim keeps using their own phone, often without noticing anything wrong.
Here is the catch: extracting the secret key was feasible with older cards that used the weak COMP128-1 algorithm, popular in the 90s and 2000s. Modern SIMs use far stronger cryptography, and operators migrated their networks precisely to block this. That is why cloning is rare in real-world attacks today, though it remains possible against outdated cards, test SIMs or operators with poor security controls, a problem still discussed among telecom security researchers.
Both attacks end the same way: the criminal intercepts your communications and verification codes. But their requirements differ. Cloning demands physical access to your card and succeeds mainly against weak or legacy chips, while both SIMs can remain active simultaneously. Swapping requires zero contact with your device; everything happens inside the operator's systems, and the victim simply loses coverage.
The dominant threat today is the swap, because it scales, exploits human trust and needs no hardware. Yet demonstrations of SIM cloning keep circulating online, reminding us that legacy infrastructure in mobile networks remains a real attack surface.
Start by eliminating the weakest link: replace SMS codes with authenticator apps or hardware security keys on every critical account. Request a porting PIN or additional verification from your carrier so nobody can move your line without your explicit approval. Never hand your phone to strangers, and keep the SIM tray protected.
Watch for warning signs such as sudden loss of signal or unexpected SIM deactivation messages, and call your operator immediately if they occur.
Operators are deploying anti-fraud measures and closer monitoring of rogue SIM activity, but your best defense is acting before the attack: reduce what criminals can learn about you, since both techniques feed on leaked personal data and oversharing on social media.
#CyberSecurity #SimSwap #SimCloning #MobileSecurity #PrivacyMatters
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
2🤷♂5🤬4👀3 1
There are videos that were never meant to be played. Specialists from Censys discovered a campaign in which structurally valid MP4 files, impossible to reproduce on any player, serve only as camouflage to smuggle a remote access tool: NetSupport Manager, a legitimate application converted into a dangerous RAT.
The file passes as normal media in automated inspections, which is precisely its purpose. Technically it is correct, but it lacks dimensions and decoding parameters. Almost all of its content, around 99.95% of its 6.5 MB, is a hidden UUID box, a marker that indicates to the malware where the payload is stored inside the false container. As Censys describes it, it is "a convincing shell designed solely to pass automated file-type inspections while masking the transport of a large script".
As almost always in these cases, the initial push comes from a victim's mistake through the ClickFix technique: a fake CAPTCHA or a "paste and run" instruction convinces the user to execute a malicious command. The first-stage dropper verifies the computer name looking for sandbox traces, hides the PowerShell window and downloads the MP4 impersonating Chrome's user agent, so the traffic looks like ordinary video streaming. Then it decrypts, decompresses and leaves a secondary script in the %TEMP% folder.
The operators constantly rotate file names, from 333.mp4 to web02message.mp4, and use Russian-language business sites as a facade for their command-and-control infrastructure. So coordinated is the operation that Censys observed two gateway domains registered barely 77 seconds apart.
With NetSupport Manager installed, attackers gain complete visibility over the infected system: credential theft, espionage, lateral movement, cryptocurrency mining or resale of access to other groups.
The good news: just opening one of these MP4 files does not compromise your computer. The bad news: a single click on a false verification is enough. To protect yourself, never paste commands into the Run dialog or PowerShell that come from websites, distrust pages that ask you to "confirm you are human" with strange key combinations, block PowerShell execution for standard users through group policies and rely on solutions that analyze file content, not just the extension.
#Cybersecurity #ClickFix #Malware #Trojans #MP4
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
2👀8✍4👌3😈3🙈3🤷♂2🤔2 1 1
Leaked courses from Andrew Tate's private club, the War Room, reveal far more than money-making tips and dating advice. Members were being taught how to bribe officials, spot surveillance, and dig up compromising material on wealthy and powerful people, all while the Tate brothers sit in a Miami federal detention centre fighting extradition to the United Kingdom.
An anonymous security researcher uncovered the materials while examining the publicly visible code behind Tate's infrastructure. No hacking was required: the sites themselves exposed internal links and technical metadata, and part of the supposedly private content remained accessible due to poorly configured protections. In total, the researcher found more than 12 TB of material. The collective DDoSecrets described an archive of 11.16 TB containing over 100,000 files, though access to this collection is granted only to journalists and researchers.
Part of the War Room material is already public. In June, DDoSecrets published around 19.55 GB of video courses, and back in December 2024 it released 75 recordings of closed meetings and events totalling 14.9 GB. The new discovery significantly expands what's known about the project's internal media library.
One of the most striking programs, called Operator, instructed participants on how to bribe government employees abroad. For low-ranking police officers, the course suggested modest payments of between $20 and $50. It also covered how to behave during interrogations and taught counter-surveillance techniques, including ways to notice when someone might be following you.
Another closed course, Penetrating the Elite, proposed applying intelligence-style tactics against wealthy and influential individuals. Students were told to find a target's weak spots, get close to them, and turn the information gathered into leverage during business negotiations. The materials claimed this approach had already been used against a well-known Hollywood director, a UFC athlete, a Fortune 500 executive and an Arab billionaire. There is no independent confirmation of these claims.
Separate lessons focused on relationships. Women were categorised by their supposed degree of vulnerability, and members were encouraged to control their partner's social circle, clothing, daily routine and even diet. The Date Magnet System course taught men to build an attractive but artificial lifestyle image and to approach roughly 20 women a day.
If you're concerned about your own privacy in a world where surveillance tactics like these are being sold as courses, some basics go a long way: use end-to-end encrypted messaging, limit what personal information you share publicly, watch for repeated strangers or vehicles around you, disable location tracking on apps you don't trust, and never assume that a private community online keeps its contents private.
#AndrewTate #DDoSecrets #WarRoom #Leaks #Surveillance
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
🤣3👀2 1
This media is not supported in your browser
VIEW IN TELEGRAM
The week started with a cryptographic wake-up call from the G7: everything encrypted today could be decrypted by quantum computers within a few years, so the shift to post-quantum algorithms must begin right now. While the world prepares for that transition, the FBI tore down a Chinese cyber espionage infrastructure, Nvidia swallowed Hugging Face for nearly $13 billion, and ransomware crews kept healthcare and federal agencies on high alert.
#CyberSecurity #PostQuantum #RansomwareWatch #DataPrivacy #WeeklyNews
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
👀4 1 1
For years, the idea that Mac users can skip antivirus software was treated as gospel. Apple's marketing built an empire on the message that macOS simply doesn't get infected. Well, new global data from Kaspersky is here to ruin that comfortable story: over the past year, 12% of macOS users reported a malware infection, compared to just 9% on Windows. That's a third more threats hitting the platform everyone assumed was bulletproof.
Here's the twist: it's not that Macs are inherently weaker. It's that confidence breeds carelessness. Only 35% of Mac owners run dedicated security software, versus 42% of Windows users. The habit gap shows up everywhere else too. On macOS, just 51% avoid opening suspicious emails or links compared to 62% of Windows users, complex passwords are used by 45% versus 52%, and multifactor authentication trails at 46% against 51%. Only in a few privacy-related practices, like reviewing privacy settings or checking whether leaked credentials are exposed, do Mac users come out slightly ahead.
It's not just malware. During the last year, macOS users reported more phishing incidents (12% vs 9%), more online scams and fraudulent investment schemes (16% vs 13%), more privacy violations (11% vs 8%) and a noticeably higher rate of personal data theft: 12% compared to 7% on Windows.
The threat landscape has fundamentally shifted. Cybercriminals no longer build attacks around a specific operating system. Instead, they lean on phishing and supply chain attacks, techniques that hit anyone regardless of whether they're typing on a MacBook or a Windows laptop. The old argument that Macs were safe simply because fewer people used them died the moment attackers realized Mac users pay real money and guard it poorly.
#MacSecurity #MalwareTrends #PhishingAlert #CyberHygiene #PrivacyMatters
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
👀7 1
Smart TVs have quietly become one of the biggest privacy blind spots in the average household, and a new investigation shows just how far LG has taken things. Researchers led by Gamers Nexus, working alongside Level1Techs, spent weeks putting an LG OLED G5 under the microscope with packet-capturing tools like Wireshark. What they found reads like something out of a surveillance manual.
The most alarming discovery came right away. The television kept listening through its microphone even in standby mode, while the screen looked completely dark. With the network disconnected, that audio was stored locally. The moment connectivity came back, everything got uploaded. In other words, unplugging the cable doesn't erase what was captured, it just postpones the upload.
But the TV wasn't satisfied with watching its owner. It actively scanned the local network, fingerprinting smartphones, smartwatches and other gadgets, and even cataloged nearby Wi-Fi networks along with their signal strength. All of this flows back to LG Ad Solutions, the company's advertising division, which openly brags about holding data from 216 million smart TVs worldwide, 49 million of them in the United States.
That's LG's own pitch to advertisers, promoting the ability to dominate the living room using data harvested from a television people paid thousands of dollars for. The company has publicly insisted its sets "do not collect, record or store ambient conversations," a statement that sits very awkwardly next to the researchers' findings.
Automatic Content Recognition, or ACR, takes what makes the practice worse: it snapshots the screen and samples audio to identify exactly what you're watching, even when the TV is used purely as an HDMI monitor. A compromised set could therefore capture sound from calls or presentations routed through that cable. And these panels aren't confined to living rooms: they hang in hospitals, waiting rooms, boardrooms and hotels, which raises uncomfortable questions about patient and corporate confidentiality.
If you own an LG smart TV, the researchers' advice is blunt: take it off the network entirely. Pull the Ethernet cable out physically, disable Wi-Fi in the TV's settings, and don't count on an external streaming box like an Apple TV as a fix, because the TV keeps spying on its own regardless. If you have several sets and can't isolate them all, block LG's telemetry domains at the router or firewall level, though the device may still log data locally. And as a universal habit, switch off ACR and personalized advertising in any smart TV's privacy menu, mute the microphone where possible, and assume every "smart" screen in your home phones home by default.
#SmartTV #LG #Privacy #DataCollection #Surveillance
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
1👀6🤔4🤬3 3 2
When it comes to open-source intelligence, one of the most common starting points is a simple username. People tend to reuse the same alias across dozens of platforms, which makes it a surprisingly powerful pivot for mapping someone's digital footprint. That's exactly where nexfil shines: a high-speed username lookup tool written in Rust, built for speed above everything else.
Traditional username enumeration tools check platforms one by one and can take ages to finish. Nexfil takes a different approach, relying on multiprocessing and finely tuned requests to verify a given username across more than 350 services about ten times faster than the usual alternatives.
Instead of waiting minutes for results, you get them in a fraction of the time, which makes a real difference during live investigations.
Nexfil deliberately avoids bloat. There are no unnecessary extras, no confusing menus, just a clean and efficient workflow: give it a username and it reports where that alias exists. This makes it ideal for quickly checking the online presence of a person or a company during the early stages of an OSINT investigation, without wasting time on features you will never use.
Since this technique is so easy to execute, it is worth taking precautions on the defensive side too. Using unique usernames for each service breaks the chain that links your accounts together. Avoid reusing your gaming alias on professional platforms like LinkedIn or GitHub, and keep your accounts set to private whenever possible. It is also worth periodically searching your own nicknames to see what a stranger could find, because reducing cross-platform correlation is one of the simplest yet most effective privacy measures available.
#OSINT #UsernameSearch #PrivacyTools #Reconnaissance #DigitalFootprint
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
10👌13👀4✍2 1 1
This media is not supported in your browser
VIEW IN TELEGRAM
We have some important news for our community. We have decided to abandon donations through Telegram, and the reason is simple: The @tribute platform collects a huge amount of data along the way. Defending privacy while using tools that harvest your information simply doesn't make sense, so we're switching to a way of contributing that actually matches our values.
From now on, you can support the channel with Bitcoin, Ethereum or TRON. Crypto donations let you contribute without exposing your identity, without intermediaries and without third parties building a profile out of your generosity.
Any amount, no matter how small, helps us keep the channel updated, ad-free and fully independent.
Every contribution goes straight into keeping this project alive: researching new threats, publishing weekly news, reviewing open-source security tools and spreading awareness about surveillance and digital rights. By donating, you're not just supporting a channel, you're taking an active part in the defense of the right to privacy.
Thank you for being here, for sharing our articles and for believing in this cause. Together we are stronger.
Please open Telegram to view this post
VIEW IN TELEGRAM
2✍10😁3👌2👀2 1 1
Most people believe that ignoring unknown numbers keeps them safe. The WeWorm attack proved the opposite: just an incoming call was enough to turn a smartphone into the next link in a digital infection chain.
Researchers at Calif built WeWorm as a laboratory zero-click worm targeting WeChat, the messaging giant whose ecosystem reaches 1.44 billion monthly users across Weixin and WeChat. Even without answering the call, the victim's account was taken over, and then the compromised account automatically started calling its own contacts to repeat the attack. The demonstration worked between Android and iOS devices with zero interaction from the owners.
At the heart of WeWorm sits a memory corruption bug in the VoIP stack of WeChat, the component that handles voice calls. There is one catch: the attacker must already be in the victim's friends list. But after the first compromise, that condition stops mattering, because the hijacked account can call its trusted contacts and continue the chain on its own.
In the test, a Pixel 10a called an iPhone 17e and gained control of WeChat while the phone was still ringing. The captured iPhone then called a second Pixel 10a and repeated the whole process. The entire exploit took mere seconds.
Answering the call did not save the device, and rejecting it only stopped that specific attempt, since the attacker could simply ring again.
The exploit hands over full control of the WeChat account: reading and sending messages, making calls, acting on behalf of the owner. WeWorm alone does not seize the entire phone, though Calif sees full device takeover as a plausible scenario if chained with other Android or iOS bugs, something never confirmed in the demo.
Neural networks played a starring role here. Calif says AI helped uncover the flaw, the remote code execution exploit was ready in about two days, and a full working worm took roughly another week. The team learned of the issue on July 23 and had the cross-platform demonstration done by August 11.
Tencent got word on July 24. Versions 8.0.77 for Android and 8.0.76 for iOS, released on August 21, neutralize the attack, and by August 28 Calif confirmed a server-side block covering all users. So far, there are no signs of WeWorm spreading in the wild.
And that is the uncomfortable part. Attacks like this ignore old habits: it does not matter whether you pick up or not. Keep WeChat updated at all times, install updates the day they ship, think twice before adding unfamiliar contacts to your list, and turn on any extra account protection the app offers. Silence is no longer a defense.
#Cybersecurity #ZeroClick #WeChat #MobileThreats #AIHacking
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
✍9
Privacy Not A Crime
This media is not supported in your browser
VIEW IN TELEGRAM
✍7🤬3 2🤣1👀1 1