Privacy Not A Crime
669 subscribers
195 photos
19 videos
233 links
🔐 Take control of your digital freedom.

Curated tools and expert insights on Privacy, Cybersecurity and OSINT. Actionable guides to protect your data and communications.

Defend your rights online. 🔰
Download Telegram
This media is not supported in your browser
VIEW IN TELEGRAM
🙋‍♂️ NSW bill would let police clone your phone at a traffic stop, without a warrant

A piece of legislation with serious privacy implications just landed in New South Wales. On Friday, the Minns government introduced a bill that would allow police to plug your phone into military-grade extraction hardware and copy its contents, and a simple roadside stop could be enough. The technology is the Universal Forensic Extraction Device (UFED) built by Israeli firm Cellebrite, the same equipment used by ICE and border agents in the United States. In minutes it can download contacts, messages, photos, browsing history, call logs, health data and even files you believed were gone forever.

❌ Refusing to unlock is no longer a real option

Here's where it gets thorny. The draft legislation states that invoking the traditional right against self-incrimination is not a valid reason to refuse to unlock your device, effectively removing a legal shield people assumed they had. And while Cellebrite's UFED kit is widely reported to be capable of bypassing locked phones and brute forcing passcodes, so withholding your PIN may not protect you either.

The tooling is also known to extract content from encrypted apps like WhatsApp, Signal and Telegram, along with location history and metadata.

⚖️ Two separate measures often blurred together

Public debate has mixed up two distinct parts of the bill, so it's worth setting them straight. The first gives police access to unredacted images from toll road cameras, although the government insists this will be restricted to investigations into serious indictable offences or missing person cases, with a staged rollout beginning at the Sydney Harbour Bridge and Tunnel. The second measure adds NSW driver licence photos to the National Driver Licence Facial Recognition Solution, a national database that South Australia and Western Australia already feed into. Civil liberties groups warn that database lacks meaningful safeguards, and that Cellebrite use carries no reporting requirements, no known policies on how downloaded data is stored or shared, and no obligation to destroy it once a matter concludes.

🤩 Sold as an organised-crime weapon, used on the beat

Officially, the package targets organised crime, giving NSW Police and the Crime Commission stronger tools against sophisticated networks. Critics counter that the powers reach well beyond crime bosses to anyone pulled over or caught up in an inquiry. Until now, this extraction technology required a warrant for serious investigations; the bill extends it to everyday policing. One nuance matters here: legal commentators note that the self-incrimination override applies to forced device examinations, not to criminal trials themselves, where the presumption of innocence formally remains intact.

🛡 How to protect yourself

A few practical steps are worth taking right now. Use a long alphanumeric passcode rather than a short PIN, since longer codes are dramatically harder to crack. Disable lock-screen message previews, and learn your phone's lockdown features that block biometric unlock. Keep sensitive material off cloud syncs and rely on local backups, use disappearing messages for private conversations, and carry a clean secondary device if your work makes you a likely target.

Most importantly, minimise what permanently lives on your phone, because deleted files are evidently not safe either.

😊 Follow us to stay informed about the latest threats and protect yourself.

#SurveillanceState #NSWPolice #DigitalPrivacy #CivilLiberties #PhoneSecurity

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
1🤬6👌4👀1
This media is not supported in your browser
VIEW IN TELEGRAM
📱 SIM swap vs SIM cloning: Two ways criminals steal your number

Your phone number is far more than a way to call your family. It is the key that unlocks your banking apps, your email recovery options and your entire digital life. Attackers know this, and they have developed two very different techniques to take control of it: SIM swapping and SIM cloning. Understanding how each one works is the first step to protecting yourself.

🔄 SIM swap: The attack without touching your phone

In a SIM swap attack, criminals convince your operator to transfer your number to a SIM card they control. They usually do this through social engineering: posing as the victim with stolen personal data, bribing insiders inside the carrier, or exploiting weak porting procedures.

The victim noticed nothing until their phone showed no signal. By then, every call and SMS had been landing on the attacker's device, including one-time codes for email, banking and social media. Accounts relying on SMS-based two-factor authentication fall like dominoes.

📄 SIM cloning: Copying the card itself

SIM cloning takes a different path. Instead of tricking the operator, the attacker gets physical access to the victim's SIM card for a few minutes. Using a card reader connected to a computer and a blank programmable SIM, they extract the identity data and the secret authentication key stored in the chip, then write it onto the duplicate. Once inserted into another phone, the clone behaves exactly like the original, receiving calls and messages while the victim keeps using their own phone, often without noticing anything wrong.

Here is the catch: extracting the secret key was feasible with older cards that used the weak COMP128-1 algorithm, popular in the 90s and 2000s. Modern SIMs use far stronger cryptography, and operators migrated their networks precisely to block this. That is why cloning is rare in real-world attacks today, though it remains possible against outdated cards, test SIMs or operators with poor security controls, a problem still discussed among telecom security researchers.

⚠️ Which one is more dangerous?

Both attacks end the same way: the criminal intercepts your communications and verification codes. But their requirements differ. Cloning demands physical access to your card and succeeds mainly against weak or legacy chips, while both SIMs can remain active simultaneously. Swapping requires zero contact with your device; everything happens inside the operator's systems, and the victim simply loses coverage.

The dominant threat today is the swap, because it scales, exploits human trust and needs no hardware. Yet demonstrations of SIM cloning keep circulating online, reminding us that legacy infrastructure in mobile networks remains a real attack surface.

🙂 How to defend yourself

Start by eliminating the weakest link: replace SMS codes with authenticator apps or hardware security keys on every critical account. Request a porting PIN or additional verification from your carrier so nobody can move your line without your explicit approval. Never hand your phone to strangers, and keep the SIM tray protected.

Watch for warning signs such as sudden loss of signal or unexpected SIM deactivation messages, and call your operator immediately if they occur.

Operators are deploying anti-fraud measures and closer monitoring of rogue SIM activity, but your best defense is acting before the attack: reduce what criminals can learn about you, since both techniques feed on leaked personal data and oversharing on social media.

😊 Follow us to stay informed about the latest threats and protect yourself.

#CyberSecurity #SimSwap #SimCloning #MobileSecurity #PrivacyMatters

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
2🤷‍♂5🤬4👀31
📺 Cyber trap disguised as cinema: Hackers hide trojans in broken MP4s

There are videos that were never meant to be played. Specialists from Censys discovered a campaign in which structurally valid MP4 files, impossible to reproduce on any player, serve only as camouflage to smuggle a remote access tool: NetSupport Manager, a legitimate application converted into a dangerous RAT.

🧍‍♂️ An invisible video for everyone except malware

The file passes as normal media in automated inspections, which is precisely its purpose. Technically it is correct, but it lacks dimensions and decoding parameters. Almost all of its content, around 99.95% of its 6.5 MB, is a hidden UUID box, a marker that indicates to the malware where the payload is stored inside the false container. As Censys describes it, it is "a convincing shell designed solely to pass automated file-type inspections while masking the transport of a large script".

🦠 The route of infection begins with you

As almost always in these cases, the initial push comes from a victim's mistake through the ClickFix technique: a fake CAPTCHA or a "paste and run" instruction convinces the user to execute a malicious command. The first-stage dropper verifies the computer name looking for sandbox traces, hides the PowerShell window and downloads the MP4 impersonating Chrome's user agent, so the traffic looks like ordinary video streaming. Then it decrypts, decompresses and leaves a secondary script in the %TEMP% folder.

The operators constantly rotate file names, from 333.mp4 to web02message.mp4, and use Russian-language business sites as a facade for their command-and-control infrastructure. So coordinated is the operation that Censys observed two gateway domains registered barely 77 seconds apart.

👀 What they are looking for and how to defend yourself

With NetSupport Manager installed, attackers gain complete visibility over the infected system: credential theft, espionage, lateral movement, cryptocurrency mining or resale of access to other groups.

The good news: just opening one of these MP4 files does not compromise your computer. The bad news: a single click on a false verification is enough. To protect yourself, never paste commands into the Run dialog or PowerShell that come from websites, distrust pages that ask you to "confirm you are human" with strange key combinations, block PowerShell execution for standard users through group policies and rely on solutions that analyze file content, not just the extension.

😊 Follow us to stay informed about the latest threats and protect yourself.

#Cybersecurity #ClickFix #Malware #Trojans #MP4

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
2👀8✍4👌3😈3🙈3🤷‍♂2🤔211
👮‍♂️ Bribing a cop and blackmail material on a billionaire: Inside Andrew Tate's secret "War Room" club

Leaked courses from Andrew Tate's private club, the War Room, reveal far more than money-making tips and dating advice. Members were being taught how to bribe officials, spot surveillance, and dig up compromising material on wealthy and powerful people, all while the Tate brothers sit in a Miami federal detention centre fighting extradition to the United Kingdom.

7️⃣ How the leak happened

An anonymous security researcher uncovered the materials while examining the publicly visible code behind Tate's infrastructure. No hacking was required: the sites themselves exposed internal links and technical metadata, and part of the supposedly private content remained accessible due to poorly configured protections. In total, the researcher found more than 12 TB of material. The collective DDoSecrets described an archive of 11.16 TB containing over 100,000 files, though access to this collection is granted only to journalists and researchers.

Part of the War Room material is already public. In June, DDoSecrets published around 19.55 GB of video courses, and back in December 2024 it released 75 recordings of closed meetings and events totalling 14.9 GB. The new discovery significantly expands what's known about the project's internal media library.

📚 Courses on bribery and counter-surveillance

One of the most striking programs, called Operator, instructed participants on how to bribe government employees abroad. For low-ranking police officers, the course suggested modest payments of between $20 and $50. It also covered how to behave during interrogations and taught counter-surveillance techniques, including ways to notice when someone might be following you.

Another closed course, Penetrating the Elite, proposed applying intelligence-style tactics against wealthy and influential individuals. Students were told to find a target's weak spots, get close to them, and turn the information gathered into leverage during business negotiations. The materials claimed this approach had already been used against a well-known Hollywood director, a UFC athlete, a Fortune 500 executive and an Arab billionaire. There is no independent confirmation of these claims.

🕹 Controlling women

Separate lessons focused on relationships. Women were categorised by their supposed degree of vulnerability, and members were encouraged to control their partner's social circle, clothing, daily routine and even diet. The Date Magnet System course taught men to build an attractive but artificial lifestyle image and to approach roughly 20 women a day.

If you're concerned about your own privacy in a world where surveillance tactics like these are being sold as courses, some basics go a long way: use end-to-end encrypted messaging, limit what personal information you share publicly, watch for repeated strangers or vehicles around you, disable location tracking on apps you don't trust, and never assume that a private community online keeps its contents private.

😊 Follow us to stay informed about the latest threats and protect yourself.

#AndrewTate #DDoSecrets #WarRoom #Leaks #Surveillance

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
🤣3👀21
This media is not supported in your browser
VIEW IN TELEGRAM
📰 Weekly Cybersecurity News Roundup

The week started with a cryptographic wake-up call from the G7: everything encrypted today could be decrypted by quantum computers within a few years, so the shift to post-quantum algorithms must begin right now. While the world prepares for that transition, the FBI tore down a Chinese cyber espionage infrastructure, Nvidia swallowed Hugging Face for nearly $13 billion, and ransomware crews kept healthcare and federal agencies on high alert.

📰 Here is the most interesting news of the week gathered in one place.

⚡️ Around the globe

🔹 OpenAI unveiled GPT-6 Astra, a model that runs autonomously on a computer, hunts for vulnerabilities and solves problems that previously took human teams hours to crack.

🔹 Washington and Beijing are negotiating a new communication channel designed to reduce the risk of escalation if an out-of-control AI interferes with critical infrastructure or launches a cyberattack.

🔹 The G7 has declared a cryptographic alert: the transition to post-quantum algorithms will be the biggest encryption overhaul in half a century, and any file created today risks becoming public sooner than expected. Attackers are already running harvest now, decrypt later schemes, so the window to act is now.

🔹 Nvidia is acquiring Hugging Face for $12.93 billion, taking ownership of the platform along with more than 3 million models and an audience of over 18 million developers.

🔹 The US Department of Justice has authorized OpenAI to train its models with texts from major global publications, effectively rewriting the rules of the game for the entire media industry in a single day.

✨ Security headlines

🔹 Qilin claims it hacked the ATF and stole research materials, including smartphone data and IP addresses tied to federal investigations: the United States is actively looking into the incident.

🔹 The White House has launched a two-year transition of federal services to single sign-on authentication through Login.gov: one account for the entire government.

🔹 ShinyHunters claims it stole a terabyte of data from pharmaceutical giant McKesson: roughly 284 million medical records and a $55.2 million ransom are at stake.

🔹 The Drama Rat trojan disguises itself as VPN and banking apps, intercepts passwords, hides its icon and blocks settings if you try to remove it.

🔹 The FBI has dismantled a Chinese state-linked cyber espionage infrastructure, removing a network that had been quietly targeting organizations abroad for years.

🔹 In Ukraine, a network of fraudulent call centers known as "Kárfagen" was run by the sitting head of the cyber police: the official's career ended with his arrest by NABU.

🗣 Share in the comments how your week went and which news surprised you the most.

😊 Follow us to stay informed about the latest threats and protect yourself.

#CyberSecurity #PostQuantum #RansomwareWatch #DataPrivacy #WeeklyNews

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
👀411
💻 Myth busted: macOS logs 33% more threats than Windows

For years, the idea that Mac users can skip antivirus software was treated as gospel. Apple's marketing built an empire on the message that macOS simply doesn't get infected. Well, new global data from Kaspersky is here to ruin that comfortable story: over the past year, 12% of macOS users reported a malware infection, compared to just 9% on Windows. That's a third more threats hitting the platform everyone assumed was bulletproof.

⚠️ The dangerous side effect of feeling invincible

Here's the twist: it's not that Macs are inherently weaker. It's that confidence breeds carelessness. Only 35% of Mac owners run dedicated security software, versus 42% of Windows users. The habit gap shows up everywhere else too. On macOS, just 51% avoid opening suspicious emails or links compared to 62% of Windows users, complex passwords are used by 45% versus 52%, and multifactor authentication trails at 46% against 51%. Only in a few privacy-related practices, like reviewing privacy settings or checking whether leaked credentials are exposed, do Mac users come out slightly ahead.

📊 And the attack numbers back it up

It's not just malware. During the last year, macOS users reported more phishing incidents (12% vs 9%), more online scams and fraudulent investment schemes (16% vs 13%), more privacy violations (11% vs 8%) and a noticeably higher rate of personal data theft: 12% compared to 7% on Windows.

😎 Criminals stopped caring which OS you use

The threat landscape has fundamentally shifted. Cybercriminals no longer build attacks around a specific operating system. Instead, they lean on phishing and supply chain attacks, techniques that hit anyone regardless of whether they're typing on a MacBook or a Windows laptop. The old argument that Macs were safe simply because fewer people used them died the moment attackers realized Mac users pay real money and guard it poorly.

😊 Follow us to stay informed about the latest threats and protect yourself.

#MacSecurity #MalwareTrends #PhishingAlert #CyberHygiene #PrivacyMatters

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
👀71
🔴 Your LG smart TV is watching, listening and mapping your home

Smart TVs have quietly become one of the biggest privacy blind spots in the average household, and a new investigation shows just how far LG has taken things. Researchers led by Gamers Nexus, working alongside Level1Techs, spent weeks putting an LG OLED G5 under the microscope with packet-capturing tools like Wireshark. What they found reads like something out of a surveillance manual.

🎙 Recording with the screen "off"

The most alarming discovery came right away. The television kept listening through its microphone even in standby mode, while the screen looked completely dark. With the network disconnected, that audio was stored locally. The moment connectivity came back, everything got uploaded. In other words, unplugging the cable doesn't erase what was captured, it just postpones the upload.

⚠️ Scanning every device in your house

But the TV wasn't satisfied with watching its owner. It actively scanned the local network, fingerprinting smartphones, smartwatches and other gadgets, and even cataloged nearby Wi-Fi networks along with their signal strength. All of this flows back to LG Ad Solutions, the company's advertising division, which openly brags about holding data from 216 million smart TVs worldwide, 49 million of them in the United States.

🖥 "We control the screen"

That's LG's own pitch to advertisers, promoting the ability to dominate the living room using data harvested from a television people paid thousands of dollars for. The company has publicly insisted its sets "do not collect, record or store ambient conversations," a statement that sits very awkwardly next to the researchers' findings.

📷 The ACR problem and where these screens live

Automatic Content Recognition, or ACR, takes what makes the practice worse: it snapshots the screen and samples audio to identify exactly what you're watching, even when the TV is used purely as an HDMI monitor. A compromised set could therefore capture sound from calls or presentations routed through that cable. And these panels aren't confined to living rooms: they hang in hospitals, waiting rooms, boardrooms and hotels, which raises uncomfortable questions about patient and corporate confidentiality.

🛡 How to protect yourself

If you own an LG smart TV, the researchers' advice is blunt: take it off the network entirely. Pull the Ethernet cable out physically, disable Wi-Fi in the TV's settings, and don't count on an external streaming box like an Apple TV as a fix, because the TV keeps spying on its own regardless. If you have several sets and can't isolate them all, block LG's telemetry domains at the router or firewall level, though the device may still log data locally. And as a universal habit, switch off ACR and personalized advertising in any smart TV's privacy menu, mute the microphone where possible, and assume every "smart" screen in your home phones home by default.

😊 If you enjoyed the article share it with your friends and follow us.

#SmartTV #LG #Privacy #DataCollection #Surveillance

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
1👀6🤔4🤬332
👥 One username, hundreds of accounts: meet nexfil

When it comes to open-source intelligence, one of the most common starting points is a simple username. People tend to reuse the same alias across dozens of platforms, which makes it a surprisingly powerful pivot for mapping someone's digital footprint. That's exactly where nexfil shines: a high-speed username lookup tool written in Rust, built for speed above everything else.

🚀 Built for raw speed

Traditional username enumeration tools check platforms one by one and can take ages to finish. Nexfil takes a different approach, relying on multiprocessing and finely tuned requests to verify a given username across more than 350 services about ten times faster than the usual alternatives.

Instead of waiting minutes for results, you get them in a fraction of the time, which makes a real difference during live investigations.

✅ Simple on purpose

Nexfil deliberately avoids bloat. There are no unnecessary extras, no confusing menus, just a clean and efficient workflow: give it a username and it reports where that alias exists. This makes it ideal for quickly checking the online presence of a person or a company during the early stages of an OSINT investigation, without wasting time on features you will never use.

🔎 Don't make it easy for others to find you

Since this technique is so easy to execute, it is worth taking precautions on the defensive side too. Using unique usernames for each service breaks the chain that links your accounts together. Avoid reusing your gaming alias on professional platforms like LinkedIn or GitHub, and keep your accounts set to private whenever possible. It is also worth periodically searching your own nicknames to see what a stranger could find, because reducing cross-platform correlation is one of the simplest yet most effective privacy measures available.

🐱 Check this awesome tool at GitHub

😊 If you enjoyed the article share it with your friends and follow us.

#OSINT #UsernameSearch #PrivacyTools #Reconnaissance #DigitalFootprint

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
10👌13👀4✍211
This media is not supported in your browser
VIEW IN TELEGRAM
❤️Support Privacy Not A Crime: Donate securely with crypto

We have some important news for our community. We have decided to abandon donations through Telegram, and the reason is simple: The @tribute platform collects a huge amount of data along the way. Defending privacy while using tools that harvest your information simply doesn't make sense, so we're switching to a way of contributing that actually matches our values.

💵 Donate with cryptocurrency, without middlemen

From now on, you can support the channel with Bitcoin, Ethereum or TRON. Crypto donations let you contribute without exposing your identity, without intermediaries and without third parties building a profile out of your generosity.

Any amount, no matter how small, helps us keep the channel updated, ad-free and fully independent.

🚩 Where your support goes

Every contribution goes straight into keeping this project alive: researching new threats, publishing weekly news, reviewing open-source security tools and spreading awareness about surveillance and digital rights. By donating, you're not just supporting a channel, you're taking an active part in the defense of the right to privacy.

Thank you for being here, for sharing our articles and for believing in this cause. Together we are stronger.

☕️ Buy us a coffee

🗽 Remember, privacy is not a crime, privacy is defended.
Please open Telegram to view this post
VIEW IN TELEGRAM
2✍10😁3👌2👀211
📱 Your phone can be hacked by a single call without you even answering

Most people believe that ignoring unknown numbers keeps them safe. The WeWorm attack proved the opposite: just an incoming call was enough to turn a smartphone into the next link in a digital infection chain.

🪱 A worm that spreads itself

Researchers at Calif built WeWorm as a laboratory zero-click worm targeting WeChat, the messaging giant whose ecosystem reaches 1.44 billion monthly users across Weixin and WeChat. Even without answering the call, the victim's account was taken over, and then the compromised account automatically started calling its own contacts to repeat the attack. The demonstration worked between Android and iOS devices with zero interaction from the owners.

🔴 Where the flaw lives

At the heart of WeWorm sits a memory corruption bug in the VoIP stack of WeChat, the component that handles voice calls. There is one catch: the attacker must already be in the victim's friends list. But after the first compromise, that condition stops mattering, because the hijacked account can call its trusted contacts and continue the chain on its own.

In the test, a Pixel 10a called an iPhone 17e and gained control of WeChat while the phone was still ringing. The captured iPhone then called a second Pixel 10a and repeated the whole process. The entire exploit took mere seconds.

Answering the call did not save the device, and rejecting it only stopped that specific attempt, since the attacker could simply ring again.

🦈 What the attacker actually gets

The exploit hands over full control of the WeChat account: reading and sending messages, making calls, acting on behalf of the owner. WeWorm alone does not seize the entire phone, though Calif sees full device takeover as a plausible scenario if chained with other Android or iOS bugs, something never confirmed in the demo.

🤖 AI accelerated everything

Neural networks played a starring role here. Calif says AI helped uncover the flaw, the remote code execution exploit was ready in about two days, and a full working worm took roughly another week. The team learned of the issue on July 23 and had the cross-platform demonstration done by August 11.

🛡 Patched, but lessons remain

Tencent got word on July 24. Versions 8.0.77 for Android and 8.0.76 for iOS, released on August 21, neutralize the attack, and by August 28 Calif confirmed a server-side block covering all users. So far, there are no signs of WeWorm spreading in the wild.

And that is the uncomfortable part. Attacks like this ignore old habits: it does not matter whether you pick up or not. Keep WeChat updated at all times, install updates the day they ship, think twice before adding unfamiliar contacts to your list, and turn on any extra account protection the app offers. Silence is no longer a defense.

😊 Follow us to stay informed about the latest threats and protect yourself.

#Cybersecurity #ZeroClick #WeChat #MobileThreats #AIHacking

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
✍9
🎤 Your repositories finally speak human: Meet Git-Friend

Every developer knows the feeling: you land on a GitHub repository that could solve exactly the problem you have, only to spend the next hour drowning in undocumented code and a README written three years ago by someone who quit the project. That frustration is precisely what a new open-source assistant called Git-Friend was built to eliminate.

❓ What it actually does

Git-Friend is an AI-powered GitHub companion built with React, TypeScript and Firebase. Instead of forcing you to scroll endlessly through commits and folders, it puts three practical helpers in one place: a smart AI chat that resolves Git and GitHub doubts on the fly, a README generator capable of turning a neglected project into clean, professional documentation, and Gitmoji support to keep your commit history readable and consistent.

🤝 Who benefits the most

For open-source contributors, it lowers the barrier of making a project approachable to newcomers. For team leads, it standardizes documentation and commit conventions across a whole organization. And if you are just starting out with Git, having an assistant explain best practices in plain language beats copying commands from Stack Overflow without understanding them. The project is completely free and welcome to contributions, so anyone can raise an issue, get assigned and improve the tool.

🔹 Give it a spin

The code is fully available on GitHub, so you can clone it, run it locally with your own API keys and start exploring repositories in a friendlier way. Sometimes the best security and productivity tips come from the simplest tools, and this one fits right in.

🐱 Check it at GitHub

😊 If you enjoyed the article share it with your friends and follow us.

#GitFriend #GitHub #OpenSource #AI #DevTools

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
🤩43👀11
Thanks to @anyrun_app for the information.
🤩2
Forwarded from ANY.RUN
Phishing activity in the past 7 days 🐟
👉 Track latest phishing threats in TI Lookup

#TopPhishingThreats
1🤩2🤷‍♂1👀11
This media is not supported in your browser
VIEW IN TELEGRAM
IoT side channel (correlation) attack using WiFi.

Heuristic surveillance data is both widely under-reported and difficult to mitigate without tossing your devices and living in the stone age.
👀5✍3🤩2🤣2🆒21
🦠 A trojanized HAProxy wiretap uncovered in South Korea

A previously undocumented Linux toolkit, dubbed Ted, has been found compiled directly into the HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. According to researchers at Rapid7, the implant points to a targeted and highly stealthy operation.

7️⃣ How the compromise works

Ted is not a HAProxy vulnerability. Installing it requires code execution on the target host and the ability to swap the running binary for a trojanized build, compiled directly into the victim's own installation, in this case version 2.8.12. This deep integration lets the implant abuse the load balancer's native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic, while legitimate load balancing keeps working normally.

The real danger lies in the position this software occupies: the load balancer is the SSL/TLS termination point, which means it decrypts every HTTPS connection before forwarding traffic to backend servers. Once the backdoor was live, the attackers could read, modify, and log every decrypted session passing through it without ever touching a backend server.

🧍‍♂️ Why it stays invisible

Evasion was baked into Ted's design from the ground up. Commands from the attacker's infrastructure arrived disguised as requests for a specific image path, terminating at the load balancer without ever reaching a backend server. The implant then decremented HAProxy's live connection counters, effectively erasing the connection from the load balancer's own statistics. As a result, nothing showed up in monitoring dashboards, backend logs, or load balancer statistics.

Before serving a manipulated page, the implant filtered requests using several criteria, including User-Agent, URL, referrer patterns, and client IP addresses, delivering malicious content only to chosen visitors in a watering-hole style loop. It also manipulated HTTP headers to hide any evidence of the tampered page from the visitors themselves.

⭕️ Attribution and the wider toolkit

Rapid7 Labs attributed the framework with medium confidence to North Korean state-sponsored actors, placing the two victims in South Korea's automotive and media sectors. Keep in mind that attribution at this confidence level should be treated as indicative rather than definitive. Beyond the backdoor itself, the campaign included trojanized versions of crond, agetty, atd, sshd, and polkitd.

The trojanized SSH daemon worked as a keylogger for harvesting passwords, while a companion remote access trojan, curlRAT, enabled data exfiltration, remote command execution, and script injection from internal servers. Evidence suggests the attackers may have gained their initial foothold through an exposed Groupware portal, a popular Korean enterprise collaboration platform.

😊  If you enjoyed the article share it with your friends and follow us.

#CyberSecurity #TedBackdoor #HAProxy #ThreatIntelligence #Espionage

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
👀4🥱11
🕵️‍♂️ Signal & Shadow: A complete OSINT architecture built in the open

Most OSINT resources online are scattered blog posts or abandoned tool lists. Signal & Shadow, created by Derek Bowler, takes a different approach: it treats open-source intelligence as a full investigative discipline, with structured methodology, verified reporting and a reference library that covers nearly every investigative domain you can think of.

📡 The Signal: Verified dispatches with real findings

The heart of the project is The Signal, an investigative newsletter with a published verification standard behind it. A recent example shows the depth of its work: France 24 geolocated a contested wedding-strike site in Iran, and the analysis measures a 135-metre gap between the strike location and its likely target, a discrepancy that CENTCOM's own statement leaves unaddressed. This is not opinion; it is geolocation, measurement and corroboration applied to contested footage, the kind of analysis often reserved for state agencies.

📚 The OSINT Card Library: Pick the card that matches your problem

The reference card library is organized by domain rather than alphabetically, which mirrors how real investigators work. Each card maps to a real investigative question across domains including Maritime, Aviation, SOCMINT, Financial Intelligence, Geospatial & Satellite, TELCO, Dark Web, Legal & Court Records, Corporate Intelligence, HUMINT, MEDINT, OPSEC and Geopolitical Risk. Practical examples show how deep it goes: one card cross-references Global Forest Watch loss alerts against IBAMA fines and Trase data to attribute illegal deforestation to named landowners and exporters.

🟠 Methodology, AI and hands-on tools, not just theory

Beyond the cards, the site offers step-by-step OSINT guides, methodology frameworks, and tutorials on AI techniques for investigations, plus integrated capstones such as verifying crisis footage end-to-end using geolocation, chronolocation, source verification and satellite corroboration in a single workflow. There is also a practical toolkit: an Admiralty Grader for source reliability, a Chronolocation Calculator, a Geolocation Verifier, a Hash Generator, and an OSINT Source Index. Free tier access gets you started, while the full archive unlocks everything.

🛡 How to apply this safely yourself

Anyone doing OSINT, even passively reading, should protect their footprint. Use browser isolation (a dedicated profile or virtual machine), connect through a reputable VPN, and never log into personal accounts from the same session used for research. Prefer services with strong privacy policies, avoid clicking raw links to unknown sites, keep signed copies (hashes) of evidence you collect, and always verify a source's provenance before sharing its claims.

🌐 Check the official website

😊 If you enjoyed the article share it with your friends and follow us.

#OSINT #DigitalForensics #Investigation #OSINTEducation #Privacy

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
5👌6😁2👀2🤝11
🧿 Farming aura and digital footprint: What happens when a kid becomes a meme overnight

The so-called "aura battles" are sweeping social feeds everywhere: challenges, poses and quick moments recorded on a phone that can turn a minor into the protagonist of the night. What starts as an innocent clip filmed for a couple of classmates can end up traveling far beyond its original context, landing in front of millions of strangers who were never meant to see it.

❤️ The problem runs deeper than a viral video

Once a clip spreads outside its original circle, pulling it back is nearly impossible. Strangers can stitch footage together, link profiles across platforms or spot personal details hiding in plain sight: a school badge, a street sign, a schedule glowing on a nearby screen. Memes rarely stay harmless either, because ridicule, harassment and messages from unknown adults can quickly follow a single viral moment.

🟥 A permanent puzzle assembled clip by clip

Every recorded moment adds another piece to a footprint that never truly fades. Enough scattered fragments let someone map daily routines, build a fake identity or approach the child posing as a friend. And unlike an adult's trail, a minor's footprint grows silently for years before anyone measures how much of it is already out there.

🔘 The takeaway

The aura lasts a few seconds. The digital footprint lasts much longer, sometimes a lifetime. That's exactly why privacy, secure accounts and digital education matter more than ever in a world where any kid can become a meme overnight without ever choosing it.

😊 Follow us to stay informed about the latest threats and protect yourself.

#AuraFarming #DigitalFootprint #ChildPrivacy #OnlineSafety #DigitalEducation

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
2👌6🤷‍♂4✍3😁32
🤖 Strix: An AI pentester shaking things up on GitHub

Automated security testing just got a serious upgrade. Strix, an open-source AI-powered penetration testing tool, has been trending lately and quickly climbed past 50,000 stars on GitHub. Instead of sitting down and manually walking through an application step by step, you hand it over to a team of AI agents that behave like real attackers: probing the app, hunting for bugs, and figuring out whether those bugs are actually exploitable.

⏏️ Beyond simple scanner alerts

This is where Strix stands apart from typical static scanners. It doesn't just report "SQL Injection found here." The agents actively attempt to run the exploit themselves, validate the finding, and then deliver a full report including the vulnerability, a Proof-of-Concept, and clear reproduction steps. That validation stage matters a lot, because one of the biggest headaches in security work is drowning in false positives.

🛡 Why this matters for defenders

By thinking like an attacker rather than just pattern-matching signatures, Strix helps teams prioritize what's truly dangerous. Findings come backed with working evidence, so developers can go straight to fixing the real problems instead of chasing ghosts.

7️⃣ How to protect yourself and your projects

Tools like this are powerful, but they complement rather than replace good practices. Keep your dependencies updated, enforce input validation and parameterized queries to prevent injection attacks, adopt secure coding reviews, and run regular pentests as part of your development cycle. If you use automated testing agents, always do so only on systems you own or have explicit permission to test, unauthorized testing is illegal in most jurisdictions.

🐱 Check it for free at GitHub

😊 If you enjoyed the article share it with your friends and follow us.

#CyberSecurity #PenetrationTesting #OpenSource #AIAgents #Vulnerabilities

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
1👌6🤩4🤷‍♂2👀211
💩4🤣4🦄3👀2