This media is not supported in your browser
VIEW IN TELEGRAM
The CIA has declassified reports showing they discussed scenarios of attacks using civilian planes years before September 11. Meanwhile, Anthropic shared details about cyber operations where a person picks the target, then the AI handles reconnaissance, hacking, and code rewriting on its own.
#CyberSecurity #AI #Threats #Privacy #Security
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
π5π4 2 1
Forwarded from ANY.RUN
β οΈ RATs, stealers, and loaders all moved higher last week. #LokiBot nearly tripled in activity, while #Remcos jumped by more than 50% alongside growth in #XWorm, #AgentTesla, and #XLoader.
π Trend to watch: sharp increases like these can quickly change which threats require closer detection coverage and more investigation resources.
π Monitor the malware driving todayβs attacks
#Top10Malware
π Trend to watch: sharp increases like these can quickly change which threats require closer detection coverage and more investigation resources.
π Monitor the malware driving todayβs attacks
#Top10Malware
π2 1
The scenario is simple yet cunning. Users are persuaded under various pretexts from security verification checks to anonymous chats and dating services to launch a Telegram bot. At first glance nothing seems suspicious with a standard screen a Start button and a typical interface. However a single click activates a hidden mechanism that can compromise your entire account.
Once activated the victim unknowingly becomes an administrator or owner of an external channel completely controlled by attackers. This fact later turns into a powerful blackmail tool as the attacker can threaten to expose the user's involvement in illicit activities hosted on that channel. The scam relies on social engineering where attackers craft convincing messages mimicking legitimate services.
According to recent reports from security researchers criminals are moving increasingly toward Telegram because its design allows users to create highly anonymous accounts making it easier for fraudsters to operate without immediately revealing their real identities.
Bots can act like instant operators greeting victims collecting details and pushing them into scripted funnels that feel legitimate because responses arrive immediately and consistently. This is especially effective in fake support situations where bots mimic help desks and guide users toward verification, recovery or account safety steps that end in payment requests or credential capture. Some scam channels present bots as payment coordinators or dispute handlers creating the illusion of a trusted marketplace while actually centralizing control in the hands of the scammer.
Telegram gives users a lot of control over their security but many important protections are turned off by default or buried inside privacy menus. Enable two-step verification to add a critical layer of defense. Lock down your login by reviewing which bots and third-party apps have access to your account regularly. Never grant administrative rights to channels you do not personally manage or trust implicitly. Be skeptical of unsolicited messages offering free services verification or exclusive access. Remember that naturally any bot should be treated as a stranger according to Telegram official guidelines.
If you notice unusual activity immediately revoke the bot access via Telegram settings under Privacy and Security. Report any suspicious behavior to Telegram through their dedicated anti-scammer channel @notoscam where this activity can be flagged for investigation. Run a full antivirus scan on your device using tools like Malwarebytes to check for potential infostealers or malware that may have been installed. Change your password from a separate trusted device to prevent further unauthorized access.
#TelegramSecurity #BotScam #CyberSafety #ProtectYourAccount #DigitalPrivacy
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
π4 1 1
This media is not supported in your browser
VIEW IN TELEGRAM
Security researchers have confirmed a vulnerability in WhatsApp for Android that allows access to private photos even when the device is locked. Discovered by Jose Rodriguez (@VBarraquito) and already reported to Meta and Google, the flaw has been addressed with a fix currently rolling out, though availability varies by region and device.
The vulnerability does not allow remote attacks from anywhere on the internet. Instead, it requires physical access to the locked phone. Once an attacker has the device in hand, an incoming video call triggers an interface that inadvertently opens the photo gallery through the app's filters and effects menu.
When a locked Android device receives a WhatsApp video call, swiping to answer activates the video feed. Tapping the effects icon reveals tabs for filters and backgrounds. From there, selecting "Create with Meta AI" followed by "Edit photo" pulls up the entire device gallery, bypassing the standard lock screen protections.
Importantly, the bypass only grants viewing access to photos, not editing or sharing capabilities. Still, an attacker could photograph the screen with a second device.
#WhatsApp #AndroidSecurity #PrivacyAlert #Stalkerware #Cybersecurity
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
π4π€¬2 1 1
September 14 marked a historic moment for Apple security as the company released its largest vulnerability patch ever. More than 260 unique CVEs were addressed across virtually the entire ecosystem, with macOS alone receiving over 200 individual fixes. The update included iOS 27 and iPadOS 27, alongside iOS 26.7 and iPadOS 26.7 for devices that had not yet migrated to the major version.
The sheer number of flaws makes this Apple's most intensive security cleanup in history. Every major product line required attention, from the operating system kernel to core application frameworks. Many of these vulnerabilities could allow arbitrary code execution or security bypasses, making immediate updating essential for all users.
This situation exposes a structural weakness of closed-source software. When code remains hidden from public scrutiny, vulnerabilities tend to accumulate until internal reviews finally uncover them. The 260 plus flaws disclosed here are probably just the beginning, as thousands more likely remain buried in the codebase waiting to be discovered either by attackers or by future security researchers who eventually gain access to the source.
#AppleSecurity #ZeroDay #ClosedSource #CyberRisk #TechNews
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
π€―8π4
Media is too big
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
π€―5 3π2
This media is not supported in your browser
VIEW IN TELEGRAM
The cloud turned out to be too grounded, while weapons were entirely space-bound: following drone attacks, Amazon acknowledged an irreversible loss of access to parts of AWS, and the United States officially confirmed the presence of orbital weapons for the first time. AI agents now take just 26 seconds to target 11 organizations, and police can read Signal and WhatsApp messages without breaking encryption by turning a device into a trusted endpoint.
#CyberSecurity #AIAttacks #CloudSecurity #PrivacyFirst #TechNews
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
β3π€3π€©3π3 1
Awesome-Malware-Analysis brings together a carefully selected set of resources for working with malicious code in one organized place. From sample collection and threat intelligence to detection, classification, online sandboxes, file extraction, deobfuscation, debugging, reverse engineering, network analysis and memory forensics you will find what you need without jumping between scattered sources.
What makes this repository particularly useful is that it follows the actual workflow of an investigation rather than alphabetical order. When responding to an incident you simply open the corresponding phase section and immediately see which tools apply to your current task. This saves valuable time during critical moments and helps analysts quickly understand what capability they need for each step of their work.
It works especially well when you encounter a new malware family and need to figure out which tool fits each stage of the analysis. The curated nature means less noise and more focused options that have proven their worth in real world DFIR scenarios.
#MalwareAnalysis #DFIR #ThreatHunting #CyberSecurity #ReverseEngineering
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
β3 3
Forwarded from Proton
Admin did a video about gadgets: https://youtu.be/3VJ5Htyhm7k
π5π3π€£2 2β1
Forwarded from Proton
This media is not supported in your browser
VIEW IN TELEGRAM
This tickled me.
π€£12 3β2 1
This media is not supported in your browser
VIEW IN TELEGRAM
#Pegasus #Paragon #Spyware #iPhone #Android
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
β7 2 1
Public opinion has officially gone up for sale. Researchers from Citizen Lab have uncovered the activities of Israeli company BlackCore, which has moved disinformation from intelligence services' toolkit into conventional B2B services. Now any paying client can access a full information warfare cycle: from creating hundreds of convincing fake profiles to artificially suppressing unwanted narratives, complete with detailed efficiency reports.
The fake campaign management process is structured like a classic advertising agency. Instead of crudely selling inactive accounts, BlackCore implements complete infrastructure. Neural networks generate avatar faces for social media, writers craft coordinated messages, and algorithms artificially boost posts. This system lets clients quickly simulate mass support or destroy a competitor's reputation by flooding the space with aggressive noise.
Operations follow professional standards including target audience analysis, multi-platform deployment, engagement metrics tracking, and polished final deliverables presented as corporate reports. It is information manipulation packaged like any other enterprise service.
The main risk lies in increasing accessibility of these methods on the open market. When tools for suppressing opinions and dominating agendas sell as corporate subscriptions, it becomes nearly impossible to distinguish genuine social movements from paid digital illusions.
The implications extend far beyond corporate competition. Political campaigns, public health messaging, and social justice efforts can all be drowned out by manufactured consensus funded by undisclosed actors.
#Disinformation #CyberSecurity #InformationWarfare #DigitalPrivacy #StateSponsored
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
π€7π6π6π€¬4π€£4
This media is not supported in your browser
VIEW IN TELEGRAM
AI agents breached the Australian Ministry of Health website, stealing data from 600,000 bank cards within hours, prompting OpenAI and Anthropic to seek UN intervention to contain these technologies. Meanwhile, a routing error triggered a global internet disruption affecting over 100 countries, and banks worldwide face challenges with customer call identification.
#CyberSecurity #AINews #DataBreach #InfoSec #Privacy
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
β9π6π3π€¬1 1
Forwarded from ANY.RUN
β οΈ Malware pressure increased across the threat landscape last week, with RATs, stealers, and loaders all gaining activity at the same time. AsyncRAT climbed 35%, while Quasar, DonutLoader, and Lumma saw even sharper growth.
π Trend to watch: broad growth across established threats can increase investigation pressure across multiple threat types at once. SOC teams may need to rebalance detection and triage priorities as volumes rise.
π Monitor the malware driving todayβs attacks
#Top10Malware
π Trend to watch: broad growth across established threats can increase investigation pressure across multiple threat types at once. SOC teams may need to rebalance detection and triage priorities as volumes rise.
π Monitor the malware driving todayβs attacks
#Top10Malware
π2 1
Censys is like Shodan and Google Dorks, but powered up. We already talked about it in detail in the article How to Use Censys. Today, we will analyze it from the perspective of searching for vulnerabilities in subdomains.
The best way to find subdomains using search engines is to use filters called dorks that are better understood by the Internet itself. We cannot simply tell Google find all Microsoft subdomains please. We need to speak computer language, not human language.
Bug Bounty is a reward program that a website owner conducts to attract external information security specialists to find vulnerabilities. When participating in Bug Bounty, one must act ethically and follow established rules.
Let us try to find Microsoft subdomains. Go to Censys Search and copy and paste the following query into the search bar.
(services.tls.certificates.leaf_data.names: microsoft.com) and services.http.response.status_code=200
After execution, a list of working subdomains of the site will appear. The results show active domains that respond with HTTP status code 200, meaning they are live and accessible.
For a better result, click on the settings icon next to the search panel and select the Virtual Hosts option. This setting expands your search beyond just the primary domain. Now, with Virtual Hosts enabled, you can see all subdomains available to Microsoft services and possibly find attack vectors.
The Virtual Hosts feature is particularly valuable because many organizations host multiple services on the same IP address. By enabling this option, Censys reveals which subdomains share infrastructure and what services they expose publicly.
In one scenario from a HackerOne report, a bug hunter discovered an interesting subdomain with registration enabled for internal users this way. Then, after registration, the hacker was able to access personal data through Broken Access Control and ended up receiving a decent bounty.
This case demonstrates why thorough subdomain enumeration matters. Many organizations forget to secure internal-facing endpoints, leaving them exposed to anyone who knows how to query the right databases.
Combine multiple filters to narrow down your results. You can search for specific technologies, open ports, or certificate information. The more precise your query, the better the chances of finding overlooked assets.
Regular monitoring of your own infrastructure through these tools helps identify what attackers might see. What looks secure internally may appear quite different to the outside world.
#Censys #Vulnerability #Search #OSINT #Pentesting
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
π5 2 1
Forwarded from cKure
β β β β β‘ UAE Ministry of Interior Data Breach π¦πͺ
A threat actor S-Root claims to have obtained 4 TB of data allegedly linked to the UAE Ministry of Interior after β10 daysβ of access to its servers.
Claimed data includes:
β’ Emirates ID & passport records
β’ Resident & visitor information
β’ Fingerprints & biometric data
β’ Driving/vehicle license records
β’ Traffic violations & penalty points
β’ Issued driving certificates
π° Claimed sale price: $3,000
π Access price: $8,000
β οΈ The breach and authenticity of the dataset have not been independently verified. Claims involving highly sensitive identity and biometric information should be treated as unverified until confirmed by the relevant authorities or credible independent sources.
A threat actor S-Root claims to have obtained 4 TB of data allegedly linked to the UAE Ministry of Interior after β10 daysβ of access to its servers.
Claimed data includes:
β’ Emirates ID & passport records
β’ Resident & visitor information
β’ Fingerprints & biometric data
β’ Driving/vehicle license records
β’ Traffic violations & penalty points
β’ Issued driving certificates
π° Claimed sale price: $3,000
π Access price: $8,000
β οΈ The breach and authenticity of the dataset have not been independently verified. Claims involving highly sensitive identity and biometric information should be treated as unverified until confirmed by the relevant authorities or credible independent sources.
π5π1
Forwarded from Proton
Headlines like these really annoy me.
https://arstechnica.com/gadgets/2026/09/owners-mourn-spoiled-food-after-firmware-update-bricks-samsung-smart-fridges
https://arstechnica.com/gadgets/2026/09/owners-mourn-spoiled-food-after-firmware-update-bricks-samsung-smart-fridges
π€¬5π3π2π€·ββ1π€‘1
Forwarded from ANY.RUN
βοΈ Active now: Attackers are mimicking AI tools like Claude, DeepSeek, and ChatGPT to deliver stealers and RATs through fake download pages, malicious installers, ClickFix commands, and even real shared chats that tell users to paste a command.
Full attack chains, behavior data, and IOCs for detection are available in #ANYRUN Sandbox π
πΉ Claude Lure + ClickFix
πΉ Claude Lure + Infostealer
πΉ DeepSeek Lure + ValleyRAT
πΉ ChatGPT Lure + Fake Cloudflare CAPTCHA
β‘οΈ See how ANY.RUN helps SOC teams detect & investigate complex threats faster
#ExploreWithANYRUN
Full attack chains, behavior data, and IOCs for detection are available in #ANYRUN Sandbox π
πΉ Claude Lure + ClickFix
πΉ Claude Lure + Infostealer
πΉ DeepSeek Lure + ValleyRAT
πΉ ChatGPT Lure + Fake Cloudflare CAPTCHA
β‘οΈ See how ANY.RUN helps SOC teams detect & investigate complex threats faster
#ExploreWithANYRUN
π5