Privacy Not A Crime
671 subscribers
191 photos
19 videos
231 links
πŸ” Take control of your digital freedom.

Curated tools and expert insights on Privacy, Cybersecurity and OSINT. Actionable guides to protect your data and communications.

Defend your rights online. πŸ”°
Download Telegram
This media is not supported in your browser
VIEW IN TELEGRAM
⚠️ I scanned an iPhone for Pegasus and it came back with one critical alert. The tool is called the Mobile Verification Toolkit, or MVT. It’s free and open source and was built by Amnesty International’s Security Lab. All you need to do is make an encrypted backup of your phone on a computer, point MVT at it, and it checks your messages, browsing history, apps and data usage against known traces and fingerprints of Pegasus, Predator, stalkerware and other surveillance tools. It works for iPhone and Android, and it runs on a Mac or on Windows.

🐱 Check the tool at GitHub

😊 If you enjoyed the article share it with your friends and follow us.

#Pegasus #Paragon #Spyware #iPhone #Android

@PrivacyNotACrime πŸ—½ ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
✍721
πŸ“° Disinformation as a service: BlackCore sells influence campaigns

Public opinion has officially gone up for sale. Researchers from Citizen Lab have uncovered the activities of Israeli company BlackCore, which has moved disinformation from intelligence services' toolkit into conventional B2B services. Now any paying client can access a full information warfare cycle: from creating hundreds of convincing fake profiles to artificially suppressing unwanted narratives, complete with detailed efficiency reports.

πŸ“’ How the disinformation factory works

The fake campaign management process is structured like a classic advertising agency. Instead of crudely selling inactive accounts, BlackCore implements complete infrastructure. Neural networks generate avatar faces for social media, writers craft coordinated messages, and algorithms artificially boost posts. This system lets clients quickly simulate mass support or destroy a competitor's reputation by flooding the space with aggressive noise.

Operations follow professional standards including target audience analysis, multi-platform deployment, engagement metrics tracking, and polished final deliverables presented as corporate reports. It is information manipulation packaged like any other enterprise service.

❔ Why this matters for everyone

The main risk lies in increasing accessibility of these methods on the open market. When tools for suppressing opinions and dominating agendas sell as corporate subscriptions, it becomes nearly impossible to distinguish genuine social movements from paid digital illusions.

The implications extend far beyond corporate competition. Political campaigns, public health messaging, and social justice efforts can all be drowned out by manufactured consensus funded by undisclosed actors.

πŸ”— Check more information about this at Citizen Lab

😊 Follow us to stay informed about the latest threats and protect yourself.

#Disinformation #CyberSecurity #InformationWarfare #DigitalPrivacy #StateSponsored

@PrivacyNotACrime πŸ—½ ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ€”7πŸ‘Œ6πŸ‘€6🀬4🀣4
Forwarded from Proton
New concern just dropped.
🀬3🀣2😁1πŸ’©11
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ“° Weekly Cybersecurity News Roundup

AI agents breached the Australian Ministry of Health website, stealing data from 600,000 bank cards within hours, prompting OpenAI and Anthropic to seek UN intervention to contain these technologies. Meanwhile, a routing error triggered a global internet disruption affecting over 100 countries, and banks worldwide face challenges with customer call identification.

πŸ“° We have compiled the most interesting news of the week in one place so you don't miss anything.

🌎 Global AI and infrastructure alerts

πŸ”Ή OpenAI and Anthropic are developing increasingly powerful AI systems and are now requesting UN oversight: following a series of concerning incidents involving autonomous agents, the issue has reached the Security Council.

πŸ”Ή An Iranian operator began advertising third-party IP addresses as their own, triggering a global routing disruption that impacted more than 100 countries.

πŸ”Ή OpenAI's AI agents hacked the Australian Ministry of Health website, with the alarm only raised three months after the incident occurred.

πŸ”Ή In a database stolen from the FBI, employees of a secret unit known as ROU were identified, a group dedicated to hacking third-party devices.

πŸ”Ή Approximately $351.6 million was withdrawn from the cryptocurrency exchange Bitget, with thieves rapidly transferring stolen tokens to Ethereum.

🌟 Security landscape shifts

πŸ”Ή AI agents stole data from 600,000 bank cards with minimal human intervention, completing the entire hack in just a few hours.

πŸ”Ή AI analyzed a MikroTik patch within an hour and discovered a method to access systems without a password; attacks began before router owners could apply updates.

πŸ”Ή Hackers barely touched vulnerabilities that an Anthropic neural network found in massive quantities; it proved much easier to identify the flaw than to weaponize it into a full attack.

πŸ”Ή Palo Alto Networks is launching Claude and GPT instances to continuously attempt hacking corporate systems, including applications, APIs, clouds, and repositories.

πŸ”Ή Attackers were hacked by rival attackers: the group ShinyHunters took control of their competitors' Clop website.

πŸ—£ Share in the comments how your week went and which news surprised you the most.

😊 Follow us to stay informed about the latest threats and protect yourself.

#CyberSecurity #AINews #DataBreach #InfoSec #Privacy

@PrivacyNotACrime πŸ—½ ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
✍9πŸ‘€6πŸ‘Œ3🀬11
Forwarded from ANY.RUN
⚠️ Malware pressure increased across the threat landscape last week, with RATs, stealers, and loaders all gaining activity at the same time. AsyncRAT climbed 35%, while Quasar, DonutLoader, and Lumma saw even sharper growth.

πŸ“Œ Trend to watch: broad growth across established threats can increase investigation pressure across multiple threat types at once. SOC teams may need to rebalance detection and triage priorities as volumes rise.

πŸ‘‰ Monitor the malware driving today’s attacks

#Top10Malware
πŸ‘Œ21
Forwarded from Proton
πŸ‘€ πŸ‘€ πŸ‘€
πŸ‘Œ3πŸ₯°1
🦠 Finding vulnerable subdomains using Censys

Censys is like Shodan and Google Dorks, but powered up. We already talked about it in detail in the article How to Use Censys. Today, we will analyze it from the perspective of searching for vulnerabilities in subdomains.

The best way to find subdomains using search engines is to use filters called dorks that are better understood by the Internet itself. We cannot simply tell Google find all Microsoft subdomains please. We need to speak computer language, not human language.

Bug Bounty is a reward program that a website owner conducts to attract external information security specialists to find vulnerabilities. When participating in Bug Bounty, one must act ethically and follow established rules.

πŸ’» Search for Microsoft subdomains

Let us try to find Microsoft subdomains. Go to Censys Search and copy and paste the following query into the search bar.

(services.tls.certificates.leaf_data.names: microsoft.com) and services.http.response.status_code=200


After execution, a list of working subdomains of the site will appear. The results show active domains that respond with HTTP status code 200, meaning they are live and accessible.

⚑️ Enable virtual hosts filter

For a better result, click on the settings icon next to the search panel and select the Virtual Hosts option. This setting expands your search beyond just the primary domain. Now, with Virtual Hosts enabled, you can see all subdomains available to Microsoft services and possibly find attack vectors.

The Virtual Hosts feature is particularly valuable because many organizations host multiple services on the same IP address. By enabling this option, Censys reveals which subdomains share infrastructure and what services they expose publicly.

πŸ”˜ Real bug bounty example

In one scenario from a HackerOne report, a bug hunter discovered an interesting subdomain with registration enabled for internal users this way. Then, after registration, the hacker was able to access personal data through Broken Access Control and ended up receiving a decent bounty.

This case demonstrates why thorough subdomain enumeration matters. Many organizations forget to secure internal-facing endpoints, leaving them exposed to anyone who knows how to query the right databases.

πŸ”² Additional tips for effective searching

Combine multiple filters to narrow down your results. You can search for specific technologies, open ports, or certificate information. The more precise your query, the better the chances of finding overlooked assets.

Regular monitoring of your own infrastructure through these tools helps identify what attackers might see. What looks secure internally may appear quite different to the outside world.

😊 If you enjoyed the article share it with your friends and follow us.

#Censys #Vulnerability #Search #OSINT #Pentesting

@PrivacyNotACrime πŸ—½ ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘Œ521
Forwarded from cKure
β– β– β– β– β–‘ UAE Ministry of Interior Data Breach πŸ‡¦πŸ‡ͺ

A threat actor S-Root claims to have obtained 4 TB of data allegedly linked to the UAE Ministry of Interior after β€œ10 days” of access to its servers.

Claimed data includes:
β€’ Emirates ID & passport records
β€’ Resident & visitor information
β€’ Fingerprints & biometric data
β€’ Driving/vehicle license records
β€’ Traffic violations & penalty points
β€’ Issued driving certificates

πŸ’° Claimed sale price: $3,000
πŸ” Access price: $8,000

⚠️ The breach and authenticity of the dataset have not been independently verified. Claims involving highly sensitive identity and biometric information should be treated as unverified until confirmed by the relevant authorities or credible independent sources.
πŸ‘Œ5😈1
Forwarded from Proton
🀬5πŸ‘Œ3πŸ‘€2πŸ€·β€β™‚1🀑1
Forwarded from Proton
Bring back CRT!
πŸ‘€4😁2🀣2
Forwarded from ANY.RUN
❗️ Active now: Attackers are mimicking AI tools like Claude, DeepSeek, and ChatGPT to deliver stealers and RATs through fake download pages, malicious installers, ClickFix commands, and even real shared chats that tell users to paste a command.

Full attack chains, behavior data, and IOCs for detection are available in #ANYRUN Sandbox πŸ‘‡
πŸ”Ή Claude Lure + ClickFix
πŸ”Ή Claude Lure + Infostealer
πŸ”Ή DeepSeek Lure + ValleyRAT
πŸ”Ή ChatGPT Lure + Fake Cloudflare CAPTCHA

⚑️ See how ANY.RUN helps SOC teams detect & investigate complex threats faster
#ExploreWithANYRUN
πŸ‘€5