This media is not supported in your browser
VIEW IN TELEGRAM
#Pegasus #Paragon #Spyware #iPhone #Android
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
β7 2 1
Public opinion has officially gone up for sale. Researchers from Citizen Lab have uncovered the activities of Israeli company BlackCore, which has moved disinformation from intelligence services' toolkit into conventional B2B services. Now any paying client can access a full information warfare cycle: from creating hundreds of convincing fake profiles to artificially suppressing unwanted narratives, complete with detailed efficiency reports.
The fake campaign management process is structured like a classic advertising agency. Instead of crudely selling inactive accounts, BlackCore implements complete infrastructure. Neural networks generate avatar faces for social media, writers craft coordinated messages, and algorithms artificially boost posts. This system lets clients quickly simulate mass support or destroy a competitor's reputation by flooding the space with aggressive noise.
Operations follow professional standards including target audience analysis, multi-platform deployment, engagement metrics tracking, and polished final deliverables presented as corporate reports. It is information manipulation packaged like any other enterprise service.
The main risk lies in increasing accessibility of these methods on the open market. When tools for suppressing opinions and dominating agendas sell as corporate subscriptions, it becomes nearly impossible to distinguish genuine social movements from paid digital illusions.
The implications extend far beyond corporate competition. Political campaigns, public health messaging, and social justice efforts can all be drowned out by manufactured consensus funded by undisclosed actors.
#Disinformation #CyberSecurity #InformationWarfare #DigitalPrivacy #StateSponsored
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
π€7π6π6π€¬4π€£4
This media is not supported in your browser
VIEW IN TELEGRAM
AI agents breached the Australian Ministry of Health website, stealing data from 600,000 bank cards within hours, prompting OpenAI and Anthropic to seek UN intervention to contain these technologies. Meanwhile, a routing error triggered a global internet disruption affecting over 100 countries, and banks worldwide face challenges with customer call identification.
#CyberSecurity #AINews #DataBreach #InfoSec #Privacy
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
β9π6π3π€¬1 1
Forwarded from ANY.RUN
β οΈ Malware pressure increased across the threat landscape last week, with RATs, stealers, and loaders all gaining activity at the same time. AsyncRAT climbed 35%, while Quasar, DonutLoader, and Lumma saw even sharper growth.
π Trend to watch: broad growth across established threats can increase investigation pressure across multiple threat types at once. SOC teams may need to rebalance detection and triage priorities as volumes rise.
π Monitor the malware driving todayβs attacks
#Top10Malware
π Trend to watch: broad growth across established threats can increase investigation pressure across multiple threat types at once. SOC teams may need to rebalance detection and triage priorities as volumes rise.
π Monitor the malware driving todayβs attacks
#Top10Malware
π2 1
Censys is like Shodan and Google Dorks, but powered up. We already talked about it in detail in the article How to Use Censys. Today, we will analyze it from the perspective of searching for vulnerabilities in subdomains.
The best way to find subdomains using search engines is to use filters called dorks that are better understood by the Internet itself. We cannot simply tell Google find all Microsoft subdomains please. We need to speak computer language, not human language.
Bug Bounty is a reward program that a website owner conducts to attract external information security specialists to find vulnerabilities. When participating in Bug Bounty, one must act ethically and follow established rules.
Let us try to find Microsoft subdomains. Go to Censys Search and copy and paste the following query into the search bar.
(services.tls.certificates.leaf_data.names: microsoft.com) and services.http.response.status_code=200
After execution, a list of working subdomains of the site will appear. The results show active domains that respond with HTTP status code 200, meaning they are live and accessible.
For a better result, click on the settings icon next to the search panel and select the Virtual Hosts option. This setting expands your search beyond just the primary domain. Now, with Virtual Hosts enabled, you can see all subdomains available to Microsoft services and possibly find attack vectors.
The Virtual Hosts feature is particularly valuable because many organizations host multiple services on the same IP address. By enabling this option, Censys reveals which subdomains share infrastructure and what services they expose publicly.
In one scenario from a HackerOne report, a bug hunter discovered an interesting subdomain with registration enabled for internal users this way. Then, after registration, the hacker was able to access personal data through Broken Access Control and ended up receiving a decent bounty.
This case demonstrates why thorough subdomain enumeration matters. Many organizations forget to secure internal-facing endpoints, leaving them exposed to anyone who knows how to query the right databases.
Combine multiple filters to narrow down your results. You can search for specific technologies, open ports, or certificate information. The more precise your query, the better the chances of finding overlooked assets.
Regular monitoring of your own infrastructure through these tools helps identify what attackers might see. What looks secure internally may appear quite different to the outside world.
#Censys #Vulnerability #Search #OSINT #Pentesting
@PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
π5 2 1
Forwarded from cKure
β β β β β‘ UAE Ministry of Interior Data Breach π¦πͺ
A threat actor S-Root claims to have obtained 4 TB of data allegedly linked to the UAE Ministry of Interior after β10 daysβ of access to its servers.
Claimed data includes:
β’ Emirates ID & passport records
β’ Resident & visitor information
β’ Fingerprints & biometric data
β’ Driving/vehicle license records
β’ Traffic violations & penalty points
β’ Issued driving certificates
π° Claimed sale price: $3,000
π Access price: $8,000
β οΈ The breach and authenticity of the dataset have not been independently verified. Claims involving highly sensitive identity and biometric information should be treated as unverified until confirmed by the relevant authorities or credible independent sources.
A threat actor S-Root claims to have obtained 4 TB of data allegedly linked to the UAE Ministry of Interior after β10 daysβ of access to its servers.
Claimed data includes:
β’ Emirates ID & passport records
β’ Resident & visitor information
β’ Fingerprints & biometric data
β’ Driving/vehicle license records
β’ Traffic violations & penalty points
β’ Issued driving certificates
π° Claimed sale price: $3,000
π Access price: $8,000
β οΈ The breach and authenticity of the dataset have not been independently verified. Claims involving highly sensitive identity and biometric information should be treated as unverified until confirmed by the relevant authorities or credible independent sources.
π5π1
Forwarded from Proton
Headlines like these really annoy me.
https://arstechnica.com/gadgets/2026/09/owners-mourn-spoiled-food-after-firmware-update-bricks-samsung-smart-fridges
https://arstechnica.com/gadgets/2026/09/owners-mourn-spoiled-food-after-firmware-update-bricks-samsung-smart-fridges
π€¬5π3π2π€·ββ1π€‘1
Forwarded from ANY.RUN
βοΈ Active now: Attackers are mimicking AI tools like Claude, DeepSeek, and ChatGPT to deliver stealers and RATs through fake download pages, malicious installers, ClickFix commands, and even real shared chats that tell users to paste a command.
Full attack chains, behavior data, and IOCs for detection are available in #ANYRUN Sandbox π
πΉ Claude Lure + ClickFix
πΉ Claude Lure + Infostealer
πΉ DeepSeek Lure + ValleyRAT
πΉ ChatGPT Lure + Fake Cloudflare CAPTCHA
β‘οΈ See how ANY.RUN helps SOC teams detect & investigate complex threats faster
#ExploreWithANYRUN
Full attack chains, behavior data, and IOCs for detection are available in #ANYRUN Sandbox π
πΉ Claude Lure + ClickFix
πΉ Claude Lure + Infostealer
πΉ DeepSeek Lure + ValleyRAT
πΉ ChatGPT Lure + Fake Cloudflare CAPTCHA
β‘οΈ See how ANY.RUN helps SOC teams detect & investigate complex threats faster
#ExploreWithANYRUN
π5