SITREP - Independent OSINT Channel
23K subscribers
17.1K photos
9.79K videos
6 files
23.2K links
AI, technology, mass surveillance, and intelligence — everything you need to know about tomorrow.
Download Telegram
🔍 Malicious browser extensions used stores as initial access

Researchers at Socket identified 19 malicious modules delivered through Chrome and Edge extensions, some of them originally benign or acquired from legitimate developers. The framework used encrypted WebSocket C2, stripped CSP protections, injected scripts into visited sites, and targeted crypto wallets, exchange sessions, credentials, browser history, and ClickFix-style fake updates.

The case highlights a supply-chain pattern inside browser add-on ecosystems: trusted extensions can be weaponized post-publication through updates. CSP removal and modular payload delivery gave operators broad access across normal web activity, turning the browser itself into a flexible collection and theft platform.

🛰️ Open sources - closed narratives
@sitreports
🤖 Anthropic flags Claude session hijacks by infostealer malware

Anthropic says some Claude users had active login sessions stolen by infostealer malware, letting attackers access accounts and burn through usage quotas. The company is signing out affected users, removing saved payment methods, and refunding unauthorized charges. Malware families named include Vidar, LummaC2, StealC, RedLine, Acreed, and a smaller number of AMOS cases on macOS, outlined in the Anthropic warning.

The key point is session theft, not password compromise alone: copied authenticated browser sessions can bypass normal login friction, including 2FA. Revoking Claude access contains account abuse, but does not remove the underlying infostealer from the host.

🛰️ Open sources - closed narratives
@sitreports
🤖 Debian approves controlled use of generative AI

The Debian project has adopted its “Responsible Use of Generative AI” position after a community vote, allowing contributors to use AI tools in code, packaging, documentation, and other project media. The policy states Debian neither endorses nor bans such tools, keeps disclosure optional, and makes developers fully responsible for quality, maintainability, testing, and legal compliance of any Debian policy-covered contribution.

Operationally, this sets a governance baseline rather than a technical shift: AI-assisted output is acceptable only under the same review standards as human-written work. The key signal is accountability staying with maintainers, not the model.

🛰️ Open sources - closed narratives
@sitreports
🔍 China-linked Fire Ant uses Cisco routers for credential theft and log suppression

A China-linked intrusion set tracked as Fire Ant was reported exploiting Cisco routers to steal credentials and interfere with security logging, turning edge network devices into collection and concealment points. The activity is detailed in Fire Ant reporting published on 31 August 2026.

The case highlights the dual value of compromised infrastructure devices: they can expose authentication material while also degrading visibility for defenders. Router-level access can give operators durable network insight and reduce the reliability of downstream forensic records.

🛰️ Open sources - closed narratives
@sitreports
🔍 Metasploit Module Expands PaperCut Zero-Day Exposure

A new Metasploit module targets an actively exploited PaperCut NG/MF RCE chain built from CVE-2026-81578 and CVE-2026-82078. The flaws pair authentication bypass with unsafe dynamic class loading, allowing unauthenticated code execution. PaperCut says all NG/MF versions may be affected, with Emergency Patch Release 2 issued for supported 24.x, 25.x, and 26.x branches.

This lowers the barrier from bespoke exploitation to repeatable operator use. PaperCut servers sit deep in enterprise and education networks, making them useful footholds. Immediate priority is restricting Application Server web access and deploying Release 2 across all relevant server roles.

🛰️ Open sources - closed narratives
@sitreports
🔍 HardBreacher PoC claims local EoP path in Kaspersky Endpoint Security

A public HardBreacher PoC claims an unpatched local privilege escalation issue in Kaspersky Endpoint Security for Windows 14.0.0.504 on fully patched Windows 11 25H2. The code is described as unstable, but reportedly can create a DLL in System32 and grant the current user broad permissions. Vendor confirmation is not yet reflected.

The exposure is local, not remote, but it matters because endpoint security software runs with elevated trust and deep OS access. Even unreliable public exploit code can accelerate post-compromise privilege escalation and weaken defensive controls on affected hosts.

🛰️ Open sources - closed narratives
@sitreports
🔍 ValleyRAT backdoor masked by signed adware

A newly detailed ValleyRAT campaign hides the backdoor inside signed adware, using a trust signal that lowers user suspicion and can ease execution on endpoints. The delivery chain is notable because victims are induced to add the software to antivirus exclusion lists, reducing the chance of local detection after installation.

Operationally, the method blends social engineering with abuse of code signing and endpoint policy exceptions. The key takeaway is not just the payload, but the workflow: once an exclusion is user-approved, defensive visibility on the host can be materially degraded.

🛰️ Open sources - closed narratives
@sitreports
Forwarded from Rybar in English
📝On enterprise protection📝
And why think tanks are watching "Alabuga"

While the state of domestic space reconnaissance often only draws a sigh, the Western grouping continuously surveys Russian territory. But sometimes high-quality enemy imagery highlights pleasant things.

The ISIS think tank analyzed satellite images of the plant producing "Geraniums" and discovered that the complex actively acquires several major defensive fortification lines made of nets, frames and other structures.

📌 What's curious here is not so much the ability to take preventive measures ("Alabuga" generally excels at creative unconventional approaches in many things), but rather the reason for such heightened attention to the enterprise.

Against the backdrop of thousands of "Geranium" volleys, Western propaganda's stories about screwdriver assembly of Iranian "Shaheds" look quite unconvincing. Now they have to admit that it's actually about enormous full-cycle domestic production.

And then at ISIS and similar structures they ask themselves: if there's such a scale of product output, then how much could be shipped for export to third countries? And how much in the worst case could already fly to NATO countries?

The conclusions are quite unambiguous.

Therefore, the scale of observations of "Geranium" production and mentions in publications by Western think tanks will only grow. And the backdrop is fitting — in the form of burning surroundings of Kyiv from impacts of attack drones on ammunition depots.
#UAV #mediatechnology #Russia #USA
✈️ RU | ✈️ EN | ✉️ MAX

✉️ VK | ✉️ RuTube | ✉️ OK | ✉️ Zen

💸Support us Original msg
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
Microsoft warns of TerminalFix attacks deploying reverse tunnels

Microsoft has flagged a TerminalFix campaign that uses fake Cloudflare CAPTCHA prompts on compromised websites to push victims into executing malicious PowerShell commands in Windows Terminal. The activity, outlined by Microsoft, deploys reverse tunnels after user execution, indicating hands-on access through social engineering rather than exploit delivery.

Operationally, the use of reverse tunnels points to a stealthy post-compromise access method that can bypass normal perimeter assumptions by having the victim host initiate outbound connectivity. The tradecraft blends browser trust signals, living-off-the-land execution, and remote access persistence in a compact intrusion chain.

🛰️ Open sources - closed narratives
@sitreports
Forwarded from Rybar in English
📝Many cruise missiles📝
but little countermeasures

The "Shock August" in Kyiv forced Western media to actively debate Russian attacks. And what causes even more concern is not ballistics or other missile weapons, but the Geran drones, which in their cruise missile version have become unreachable for Ukrainian air defense.

Against this backdrop, it's no surprise that so-called Ukraine is crying out loud and asking for more missiles for air defense systems, while in the UAV production sector Ukrainians have adjusted priorities and begun developing interceptor drones against cruise missile Gerans.

🖍Ukrainian companies began demonstrating the development of trends in this area back at the beginning of the year. But back then cruise missile UAVs were flying in far fewer numbers, so in Kyiv everyone unanimously shelved this program and concentrated on promoting regular "drone missiles" against standard Gerans.

Now, when so-called Ukraine receives up to 3,000 Gerans monthly, and their numbers will grow in the future (with an emphasis on cruise missile modifications), so-called Ukraine has begun massively producing various "wonder weapons" against such drones.

🚩But here's the problem: for almost two months now, Ukrainian media and various channels regularly publish news about the appearance of one or another interceptor drone against cruise missile UAVs, but there are no results. Russian UAVs continue to fly as before.

And the problem is that cruise missile Gerans reach speeds of 500 km/h, which means the interceptor must fly at an even higher speed. Such speeds will certainly come eventually, but then Ukrainian developers will realize that anti-aircraft missiles were invented for a reason.

❗️This doesn't even mention that the UAV flight path must be predicted within minutes to deploy a mobile air defense system and attempt an interception. For this reason, so-called Ukraine is so insistent on enabling Starlink over Russia.

If they can't shoot them down, they will try to strike Russian launch systems and industrial facilities before the attack. And this is one of the reasons why the scenario of approving Musk's systems should be considered as coercing Russia into peace through force.
#UAV #Russia #Ukraine
✈️ RU | ✈️ EN | ✉️ MAX

✉️ VK | ✉️ RuTube | ✉️
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from Rybar in English
📝«Geran» versus «Shahed»📝
terminological revolution

Western media shows a growing trend – the name «Geran» increasingly replaces «Shahed». The reason is simple: early Geran models shared only the airframe shape with the Iranian Shahed-136, while modern jet-powered versions — «Geran-3» and subsequent ones — have practically nothing in common with the original Iranian apparatus.

We examined search results and found that among 21 major Western and specialized publications, the share of headlines using the term Geran grew from 0% in 2022–2023 to 7.1% in 2024, 8.7% in 2025, and 25% for January–August 2026.

🔻Why such a notable surge precisely in 2026?

The baseline Shahed-136 and Russian «Geran-2» are physically identical in airframe: 3.5 m length, 2.5 m wingspan, two-stroke piston engine MD-550, cruising speed 150–185 km/h. But differences already existed here: the Russian version received a reinforced warhead up to 50–90 kg versus 40–50 kg on the Iranian original, localized components, and improved electronic warfare protection.

With «Geran-3» and subsequent jet-powered versions, similarity to the Iranian predecessor collapses to nearly zero: instead of a piston engine — a turbojet, speed increases to 300–600 km/h versus 150–185 on the original, the tail section shape changed to accommodate the new powerplant, and the air intake is positioned openly outside the fuselage.


🖍The difference is fundamental in combat application as well. The jet modification is 2–3.5 times faster than the classic «moped». Accordingly, the time between detection and reaching the target shrinks dramatically.

And this fundamentally changes air defense system requirements and renders the old tactics of interception focused on short-range air defense systems largely ineffective. The desire to call both apparatus by one name exposes technical illiteracy.

📌Major news agencies still retain Shahed in headlines by the same logic that any recognizable brand continues to live in language even after a change of manufacturer: the audience already knows the word, and the archive of publications under it is enormous.

❗️However, the further new Geran modifications diverge from their, shall we say, progenitors, the less they can be compared, if only due to the ever-widening technological gap that constantly and very rapidly increases.

#UAV #Iran #Russia #Ukraine
✈️ RU | ✈️ EN | ✉️ MAX

✉️ VK | ✉️ RuTube | ✉️
Please open Telegram to view this post
VIEW IN TELEGRAM
🤖 Aurora operators used Cursor AI across 10 ransomware intrusions

Researchers say Aurora ransomware operators used Cursor AI during attacks affecting 10 targets. The reported activity links a commercial coding assistant to intrusion workflows tied to ransomware operations, marking a documented case of an AI development tool appearing inside live attack chains.

The significance is practical rather than theoretical: off-the-shelf AI tools are now showing up in operator tradecraft, potentially compressing scripting, tooling adaptation, and execution cycles. That lowers friction for intrusion teams and adds another observable layer for defenders tracking ransomware workflows.

🛰️ Open sources - closed narratives
@sitreports
📡 Healthcare cyber incidents disrupt implants and expose patient data

Boston Scientific says an ongoing cyberattack on certain on-premise systems is still disrupting manufacturing, shipping, ordering, and activation of remote monitoring for new pacemakers and other cardiac devices implanted after 25 August. Separately, McKesson confirmed data exfiltration from third-party applications tied to a subset of customers in its Oncology & Multispecialty and Medical-Surgical units.

The two cases show dual pressure points in healthcare cyber operations: direct impact on clinical device workflows and parallel compromise of high-value patient data environments. Boston Scientific reports no cloud impact, while McKesson says distribution remains operational and unauthorized access has been contained.

🛰️ Open sources - closed narratives
@sitreports
🤖 Grok and ChatGPT added to Pentagon’s GenAI.mil stack

The Pentagon has expanded GenAI.mil beyond Google Gemini, adding approved versions of OpenAI’s ChatGPT Mil and Starshield AI’s Grok for Government. Officials said both cleared Impact Level 5, allowing use on sensitive unclassified data. ChatGPT Mil is positioned for planning, policy, logistics, administration, files and custom GPT workflows; Grok adds reasoning modes, persistent projects and reusable playbooks.

This marks a shift from a single-model rollout to a multi-vendor enterprise AI environment inside the Pentagon. The operational significance is reduced vendor lock-in, broader model choice for different workflows, and formal authorization of frontier models for department-wide use at scale.

🛰️ Open sources - closed narratives
@sitreports
🔍 Claude sessions hijacked by infostealers

Anthropic says several infostealer families stole active Claude browser sessions from infected Windows and macOS systems, letting attackers access accounts, bypass password, MFA, and SSO checks, and drain paid usage. Impacted users were signed out, saved cards removed, and unauthorized charges refunded. Families identified include Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer on a small number of Macs.

Operationally, this is a session-token compromise problem rather than a platform breach. Revoking sessions and cards contains abuse, but access can be re-established if the endpoint remains infected and captures the next login.

🛰️ Open sources - closed narratives
@sitreports
🤖 AI Shopping Assistant Flaws Let Attackers Execute Code on Retailer’s Backend Servers

A newly disclosed AI shopping assistant report says security flaws in a major US retailer’s customer-facing mobile app could be chained into remote code execution on backend servers. The issue reportedly bridged a public interface and internal infrastructure.

Operationally, this highlights how consumer AI features can expand attack surface beyond the app layer into core retail systems. For defenders, the key signal is the path from exposed user workflows to backend execution, where convenience tooling becomes a direct enterprise risk.

🛰️ Open sources - closed narratives
@sitreports
🔍 Ukraine develops interceptor drones against jet-powered Gerans

Ukraine is expanding work on interceptor UAVs designed to counter newer Russian jet-powered Geran drones, CNN reports. The effort reflects a growing problem for conventional air defense, where faster targets and larger raid sizes can force defenders to commit expensive missiles, radar coverage, mobile groups, and fighter aircraft.

The wider implication is not limited to Ukraine. A large drone campaign does not need to defeat an air-defense network outright to create strategic pressure. It can force a defending country to spread limited assets between energy facilities, transport routes, airfields, command sites, and industrial infrastructure.

Myanmar offers one example of this risk. The country’s prolonged civil conflict has already shown how air power and attacks on civilian infrastructure can deepen displacement and disrupt essential services. The wider availability of long-range, low-cost strike UAVs could make such conflicts harder to contain and more dangerous for civilians.

🛰️ Open sources - closed narratives
@sitreports
📡 Navy starts carrier-based CCA prototype push

The U.S. Navy has issued an request for information for two autonomous carrier-capable Collaborative Combat Aircraft prototypes. NAVAIR wants systems able to operate from Ford- and Nimitz-class carriers, achieve first flight within two years of award, and complete shore-based carrier certification within three years. The target unit cost is $30 million, with compatibility required for catapult launch, arrested recovery, and the MD-5 control system.

The notice shows the Navy is skipping early concept work and asking for relatively mature air vehicles with a defined certification path. That compresses development risk into carrier suitability, autonomy integration, and weapons carriage while aligning naval CCA timelines more closely with parallel Air Force and Marine Corps efforts.

🛰️ Open sources - closed narratives
@sitreports
📡 Army moves TITAN into production with $192M award

The U.S. Army has issued $192 million in delivery orders for the TITAN program, marking its shift from prototyping to production. Palantir received $127 million and Anduril $65 million for eight additional systems over 18 months: four advanced and four basic variants. The Army says 10 prototypes have already been delivered across medium tactical trucks, JLTVs, and two ISV-U platforms.

The award formalizes TITAN as a fielded AI-enabled targeting node for long-range fires, built to fuse geospatial and signals intelligence from multiple sensors into target recommendations. Recent testing also highlighted a push toward vehicle-agnostic deployment and integration into wider command-and-control data meshes rather than a single fixed platform.

🛰️ Open sources - closed narratives
@sitreports
⚖️ Judge Finds DOD Retaliation Against Anthropic Unlawful

A federal judge ruled that the Department of Defense unlawfully retaliated against Anthropic by labeling the company a “supply chain risk” after it refused to allow its AI tools to be used for mass surveillance of U.S. persons. The court held the designation violated the First Amendment; the court’s decision leaves broader questions about whether such product-use restrictions are protected speech unresolved.

The ruling narrows the government’s room to use procurement and security designations as punishment for protected corporate speech. It does not resolve the larger policy gap: federal privacy safeguards still depend heavily on private firms setting their own limits.

🛰️ Open sources - closed narratives
@sitreports