Forwarded from ANY.RUN
Phishing activity in the past 7 days 🐟
👉 Track latest phishing threats in TI Lookup
#TopPhishingThreats
👉 Track latest phishing threats in TI Lookup
#TopPhishingThreats
1🤩2🤷♂1👀1 1
This media is not supported in your browser
VIEW IN TELEGRAM
IoT side channel (correlation) attack using WiFi.
Heuristic surveillance data is both widely under-reported and difficult to mitigate without tossing your devices and living in the stone age.
Heuristic surveillance data is both widely under-reported and difficult to mitigate without tossing your devices and living in the stone age.
👀5✍3🤩2🤣2🆒2 1
A previously undocumented Linux toolkit, dubbed Ted, has been found compiled directly into the HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. According to researchers at Rapid7, the implant points to a targeted and highly stealthy operation.
Ted is not a HAProxy vulnerability. Installing it requires code execution on the target host and the ability to swap the running binary for a trojanized build, compiled directly into the victim's own installation, in this case version 2.8.12. This deep integration lets the implant abuse the load balancer's native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic, while legitimate load balancing keeps working normally.
The real danger lies in the position this software occupies: the load balancer is the SSL/TLS termination point, which means it decrypts every HTTPS connection before forwarding traffic to backend servers. Once the backdoor was live, the attackers could read, modify, and log every decrypted session passing through it without ever touching a backend server.
Evasion was baked into Ted's design from the ground up. Commands from the attacker's infrastructure arrived disguised as requests for a specific image path, terminating at the load balancer without ever reaching a backend server. The implant then decremented HAProxy's live connection counters, effectively erasing the connection from the load balancer's own statistics. As a result, nothing showed up in monitoring dashboards, backend logs, or load balancer statistics.
Before serving a manipulated page, the implant filtered requests using several criteria, including User-Agent, URL, referrer patterns, and client IP addresses, delivering malicious content only to chosen visitors in a watering-hole style loop. It also manipulated HTTP headers to hide any evidence of the tampered page from the visitors themselves.
Rapid7 Labs attributed the framework with medium confidence to North Korean state-sponsored actors, placing the two victims in South Korea's automotive and media sectors. Keep in mind that attribution at this confidence level should be treated as indicative rather than definitive. Beyond the backdoor itself, the campaign included trojanized versions of crond, agetty, atd, sshd, and polkitd.
The trojanized SSH daemon worked as a keylogger for harvesting passwords, while a companion remote access trojan, curlRAT, enabled data exfiltration, remote command execution, and script injection from internal servers. Evidence suggests the attackers may have gained their initial foothold through an exposed Groupware portal, a popular Korean enterprise collaboration platform.
#CyberSecurity #TedBackdoor #HAProxy #ThreatIntelligence #Espionage
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
👀4🥱1 1
Most OSINT resources online are scattered blog posts or abandoned tool lists. Signal & Shadow, created by Derek Bowler, takes a different approach: it treats open-source intelligence as a full investigative discipline, with structured methodology, verified reporting and a reference library that covers nearly every investigative domain you can think of.
The heart of the project is The Signal, an investigative newsletter with a published verification standard behind it. A recent example shows the depth of its work: France 24 geolocated a contested wedding-strike site in Iran, and the analysis measures a 135-metre gap between the strike location and its likely target, a discrepancy that CENTCOM's own statement leaves unaddressed. This is not opinion; it is geolocation, measurement and corroboration applied to contested footage, the kind of analysis often reserved for state agencies.
The reference card library is organized by domain rather than alphabetically, which mirrors how real investigators work. Each card maps to a real investigative question across domains including Maritime, Aviation, SOCMINT, Financial Intelligence, Geospatial & Satellite, TELCO, Dark Web, Legal & Court Records, Corporate Intelligence, HUMINT, MEDINT, OPSEC and Geopolitical Risk. Practical examples show how deep it goes: one card cross-references Global Forest Watch loss alerts against IBAMA fines and Trase data to attribute illegal deforestation to named landowners and exporters.
Beyond the cards, the site offers step-by-step OSINT guides, methodology frameworks, and tutorials on AI techniques for investigations, plus integrated capstones such as verifying crisis footage end-to-end using geolocation, chronolocation, source verification and satellite corroboration in a single workflow. There is also a practical toolkit: an Admiralty Grader for source reliability, a Chronolocation Calculator, a Geolocation Verifier, a Hash Generator, and an OSINT Source Index. Free tier access gets you started, while the full archive unlocks everything.
Anyone doing OSINT, even passively reading, should protect their footprint. Use browser isolation (a dedicated profile or virtual machine), connect through a reputable VPN, and never log into personal accounts from the same session used for research. Prefer services with strong privacy policies, avoid clicking raw links to unknown sites, keep signed copies (hashes) of evidence you collect, and always verify a source's provenance before sharing its claims.
#OSINT #DigitalForensics #Investigation #OSINTEducation #Privacy
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
5👌6😁2👀2🤝1 1
The so-called "aura battles" are sweeping social feeds everywhere: challenges, poses and quick moments recorded on a phone that can turn a minor into the protagonist of the night. What starts as an innocent clip filmed for a couple of classmates can end up traveling far beyond its original context, landing in front of millions of strangers who were never meant to see it.
Once a clip spreads outside its original circle, pulling it back is nearly impossible. Strangers can stitch footage together, link profiles across platforms or spot personal details hiding in plain sight: a school badge, a street sign, a schedule glowing on a nearby screen. Memes rarely stay harmless either, because ridicule, harassment and messages from unknown adults can quickly follow a single viral moment.
Every recorded moment adds another piece to a footprint that never truly fades. Enough scattered fragments let someone map daily routines, build a fake identity or approach the child posing as a friend. And unlike an adult's trail, a minor's footprint grows silently for years before anyone measures how much of it is already out there.
The aura lasts a few seconds. The digital footprint lasts much longer, sometimes a lifetime. That's exactly why privacy, secure accounts and digital education matter more than ever in a world where any kid can become a meme overnight without ever choosing it.
#AuraFarming #DigitalFootprint #ChildPrivacy #OnlineSafety #DigitalEducation
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
2👌6🤷♂4✍3😁3 2
Automated security testing just got a serious upgrade. Strix, an open-source AI-powered penetration testing tool, has been trending lately and quickly climbed past 50,000 stars on GitHub. Instead of sitting down and manually walking through an application step by step, you hand it over to a team of AI agents that behave like real attackers: probing the app, hunting for bugs, and figuring out whether those bugs are actually exploitable.
This is where Strix stands apart from typical static scanners. It doesn't just report "SQL Injection found here." The agents actively attempt to run the exploit themselves, validate the finding, and then deliver a full report including the vulnerability, a Proof-of-Concept, and clear reproduction steps. That validation stage matters a lot, because one of the biggest headaches in security work is drowning in false positives.
By thinking like an attacker rather than just pattern-matching signatures, Strix helps teams prioritize what's truly dangerous. Findings come backed with working evidence, so developers can go straight to fixing the real problems instead of chasing ghosts.
Tools like this are powerful, but they complement rather than replace good practices. Keep your dependencies updated, enforce input validation and parameterized queries to prevent injection attacks, adopt secure coding reviews, and run regular pentests as part of your development cycle. If you use automated testing agents, always do so only on systems you own or have explicit permission to test, unauthorized testing is illegal in most jurisdictions.
#CyberSecurity #PenetrationTesting #OpenSource #AIAgents #Vulnerabilities
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
1👌6🤩4🤷♂2👀2 1 1
This media is not supported in your browser
VIEW IN TELEGRAM
Chase Hughes spent two decades building behavior profiling and influence systems for military and intelligence work.
Please open Telegram to view this post
VIEW IN TELEGRAM
🤔6🤬2👀2
Privacy Not A Crime
We're really happy to have followers like this, especially on a channel as small as ours.
Please open Telegram to view this post
VIEW IN TELEGRAM
👀3 2🤔1 1
A single photograph might be enough to unearth a person's entire digital footprint. Law enforcement agencies are increasingly leveraging facial recognition technology paired with vast public data aggregators to conduct comprehensive background investigations instantly. What was once a manual, time-consuming process of piecing together digital breadcrumbs can now be triggered by just one image of a face.
The core of this capability lies in the integration of advanced facial recognition algorithms with Open Source Intelligence (OSINT) databases. Companies like Clearview AI have scraped billions of images from social media platforms, news sites, and other public corners of the internet to build massive biometric databases. When a photo is submitted, the system matches the facial geometry against these repositories.
Once a match is found, it can unlock a cascade of associated information: social media profiles, employment history, property records, and even family connections.
InquiryIQ and similar platforms take this further by aggregating data from government records, business filings, and consumer databases. Put simply, a law enforcement officer with a smartphone and a target photo can generate a detailed dossier in seconds. Addresses, vehicle registrations, and sometimes even real-time location data if linked to other surveillance networks become accessible almost immediately.
The ability to perform such searches raises profound concerns about civil liberties and the right to anonymity. In many jurisdictions, individuals have no realistic way to opt out of these databases once their images are scraped. Just because your data is "public" doesn't mean you consented to mass surveillance. Then there's the risk of false positives, where algorithmic errors lead to mistaken identities, potentially resulting in wrongful detention or harassment.
The potential for abuse extends well beyond legitimate law enforcement too. Authoritarian regimes or malicious actors could exploit these tools to track dissidents, journalists, or private citizens without any oversight. Add to that the lack of transparency regarding who accesses these databases and for what purpose, and you're looking at a significant accountability gap.
Completely removing your digital footprint is nearly impossible, but you can still reduce your exposure. Start by adjusting privacy settings on all platforms to restrict who can see your photos and profile information. Be careful about posting high-resolution images of your face publicly. Some data brokers allow users to request removal from their databases – tedious work, yes, but it does shrink the pool of available data.
Certain clothing patterns, makeup techniques, or accessories like specific glasses or masks can also confuse facial recognition algorithms. And here's a rule of thumb: assume any image captured in public spaces could be stored and analyzed. Finally, consider supporting organizations pushing to regulate facial recognition technology and enforce stricter data protection laws. Small efforts add up when it comes to preserving privacy rights.
#Clearview #InquiryIQ #OSINT #Biometrics #Privacy
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
🤬3🖕3👀3
This media is not supported in your browser
VIEW IN TELEGRAM
The CIA has declassified reports showing they discussed scenarios of attacks using civilian planes years before September 11. Meanwhile, Anthropic shared details about cyber operations where a person picks the target, then the AI handles reconnaissance, hacking, and code rewriting on its own.
#CyberSecurity #AI #Threats #Privacy #Security
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
👌5👀4 2 1
Forwarded from ANY.RUN
⚠️ RATs, stealers, and loaders all moved higher last week. #LokiBot nearly tripled in activity, while #Remcos jumped by more than 50% alongside growth in #XWorm, #AgentTesla, and #XLoader.
📌 Trend to watch: sharp increases like these can quickly change which threats require closer detection coverage and more investigation resources.
👉 Monitor the malware driving today’s attacks
#Top10Malware
📌 Trend to watch: sharp increases like these can quickly change which threats require closer detection coverage and more investigation resources.
👉 Monitor the malware driving today’s attacks
#Top10Malware
👌2 1
The scenario is simple yet cunning. Users are persuaded under various pretexts from security verification checks to anonymous chats and dating services to launch a Telegram bot. At first glance nothing seems suspicious with a standard screen a Start button and a typical interface. However a single click activates a hidden mechanism that can compromise your entire account.
Once activated the victim unknowingly becomes an administrator or owner of an external channel completely controlled by attackers. This fact later turns into a powerful blackmail tool as the attacker can threaten to expose the user's involvement in illicit activities hosted on that channel. The scam relies on social engineering where attackers craft convincing messages mimicking legitimate services.
According to recent reports from security researchers criminals are moving increasingly toward Telegram because its design allows users to create highly anonymous accounts making it easier for fraudsters to operate without immediately revealing their real identities.
Bots can act like instant operators greeting victims collecting details and pushing them into scripted funnels that feel legitimate because responses arrive immediately and consistently. This is especially effective in fake support situations where bots mimic help desks and guide users toward verification, recovery or account safety steps that end in payment requests or credential capture. Some scam channels present bots as payment coordinators or dispute handlers creating the illusion of a trusted marketplace while actually centralizing control in the hands of the scammer.
Telegram gives users a lot of control over their security but many important protections are turned off by default or buried inside privacy menus. Enable two-step verification to add a critical layer of defense. Lock down your login by reviewing which bots and third-party apps have access to your account regularly. Never grant administrative rights to channels you do not personally manage or trust implicitly. Be skeptical of unsolicited messages offering free services verification or exclusive access. Remember that naturally any bot should be treated as a stranger according to Telegram official guidelines.
If you notice unusual activity immediately revoke the bot access via Telegram settings under Privacy and Security. Report any suspicious behavior to Telegram through their dedicated anti-scammer channel @notoscam where this activity can be flagged for investigation. Run a full antivirus scan on your device using tools like Malwarebytes to check for potential infostealers or malware that may have been installed. Change your password from a separate trusted device to prevent further unauthorized access.
#TelegramSecurity #BotScam #CyberSafety #ProtectYourAccount #DigitalPrivacy
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
👌4 1 1
This media is not supported in your browser
VIEW IN TELEGRAM
Security researchers have confirmed a vulnerability in WhatsApp for Android that allows access to private photos even when the device is locked. Discovered by Jose Rodriguez (@VBarraquito) and already reported to Meta and Google, the flaw has been addressed with a fix currently rolling out, though availability varies by region and device.
The vulnerability does not allow remote attacks from anywhere on the internet. Instead, it requires physical access to the locked phone. Once an attacker has the device in hand, an incoming video call triggers an interface that inadvertently opens the photo gallery through the app's filters and effects menu.
When a locked Android device receives a WhatsApp video call, swiping to answer activates the video feed. Tapping the effects icon reveals tabs for filters and backgrounds. From there, selecting "Create with Meta AI" followed by "Edit photo" pulls up the entire device gallery, bypassing the standard lock screen protections.
Importantly, the bypass only grants viewing access to photos, not editing or sharing capabilities. Still, an attacker could photograph the screen with a second device.
#WhatsApp #AndroidSecurity #PrivacyAlert #Stalkerware #Cybersecurity
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
👌4🤬2 1 1
September 14 marked a historic moment for Apple security as the company released its largest vulnerability patch ever. More than 260 unique CVEs were addressed across virtually the entire ecosystem, with macOS alone receiving over 200 individual fixes. The update included iOS 27 and iPadOS 27, alongside iOS 26.7 and iPadOS 26.7 for devices that had not yet migrated to the major version.
The sheer number of flaws makes this Apple's most intensive security cleanup in history. Every major product line required attention, from the operating system kernel to core application frameworks. Many of these vulnerabilities could allow arbitrary code execution or security bypasses, making immediate updating essential for all users.
This situation exposes a structural weakness of closed-source software. When code remains hidden from public scrutiny, vulnerabilities tend to accumulate until internal reviews finally uncover them. The 260 plus flaws disclosed here are probably just the beginning, as thousands more likely remain buried in the codebase waiting to be discovered either by attackers or by future security researchers who eventually gain access to the source.
#AppleSecurity #ZeroDay #ClosedSource #CyberRisk #TechNews
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
🤯8👌4
Media is too big
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
🤯5 3👀2
This media is not supported in your browser
VIEW IN TELEGRAM
The cloud turned out to be too grounded, while weapons were entirely space-bound: following drone attacks, Amazon acknowledged an irreversible loss of access to parts of AWS, and the United States officially confirmed the presence of orbital weapons for the first time. AI agents now take just 26 seconds to target 11 organizations, and police can read Signal and WhatsApp messages without breaking encryption by turning a device into a trusted endpoint.
#CyberSecurity #AIAttacks #CloudSecurity #PrivacyFirst #TechNews
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
✍3🤔3🤩3👀3 1
Awesome-Malware-Analysis brings together a carefully selected set of resources for working with malicious code in one organized place. From sample collection and threat intelligence to detection, classification, online sandboxes, file extraction, deobfuscation, debugging, reverse engineering, network analysis and memory forensics you will find what you need without jumping between scattered sources.
What makes this repository particularly useful is that it follows the actual workflow of an investigation rather than alphabetical order. When responding to an incident you simply open the corresponding phase section and immediately see which tools apply to your current task. This saves valuable time during critical moments and helps analysts quickly understand what capability they need for each step of their work.
It works especially well when you encounter a new malware family and need to figure out which tool fits each stage of the analysis. The curated nature means less noise and more focused options that have proven their worth in real world DFIR scenarios.
#MalwareAnalysis #DFIR #ThreatHunting #CyberSecurity #ReverseEngineering
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
✍3 3