SITREP - Independent OSINT Channel
23K subscribers
17.2K photos
9.79K videos
6 files
23.2K links
AI, technology, mass surveillance, and intelligence โ€” everything you need to know about tomorrow.
Download Telegram
๐Ÿ“ก Pentagon launches mobile SCIF program for cleared industry access

The Defense Department has started the Secure Space Network, an initiative to design and produce about 50 mobile Sensitive Compartmented Information Facilities with related information systems. The transportable units are intended for rapid deployment to military bases, industry sites, and other locations where classified work is required.

The move directly targets a known bottleneck in the defense industrial base: smaller and non-traditional firms often lack accredited spaces for classified development and integration. A scalable, surge-capable mobile SCIF fleet lowers entry barriers and expands the pool of companies able to participate in sensitive programs.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
๐Ÿค– Anthropic still flagged as risk to defense industrial base, US official says

A U.S. defense official says Anthropic remains designated a โ€œSupply Chain Riskโ€ at the Department of Defense and across the wider defense industrial base. The statement directly rejects claims of easing tensions between the AI company and the administration.

For defense procurement and trusted-tech screening, the designation matters more than public messaging. A standing supply-chain risk flag can shape vendor access, partnership decisions, and integration pathways across contractors handling sensitive programs.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
๐Ÿ” ICE exposed restricted data via Palantir app before vetting

ICE deportation officers reportedly received the ELITE app on issued phones as a standard tool, including hires whose background checks were still incomplete. The Palantir-built system aggregates addresses, criminal histories, immigration records, court data, and other personally identifiable information, while DHS has not published a dedicated privacy impact assessment for ELITE.

Operationally, this combines accelerated hiring with immediate access to a sensitive targeting platform. The reported gap is not only personnel vetting, but governance: a fielded AI-enabled enforcement tool handling broad personal data without the full privacy documentation normally meant to define oversight, safeguards, and accountability.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
๐Ÿ“ก Air Force accelerates MQ-9 replacement after heavy wartime attrition

The U.S. Air Force is moving faster on the Massed Modular Aircraft program after losing 45 MQ-9A Reapers in Operation Epic Fury, roughly a quarter of the fleet by mid-August. Officials now want at least 180 lower-cost aircraft at about $10 million per air vehicle, using mature technology and accepting reduced performance and survivability to speed fielding.

The shift marks a clear move from small numbers of expensive ISR-strike drones toward attritable capacity. Cost per effect, production volume, and shorter service life are being prioritized over long-term sustainment, indicating combat losses have forced a reassessment of what is operationally replaceable at scale.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
๐Ÿ“ก U.S. Navy and Quad partners expand AI tracking of dark fleets in the Pacific

NIWC Pacific has awarded Vantor a contract to provide Maritime Sentry for Indo-Pacific maritime domain awareness. The system fuses satellite imagery, SAR, AIS data, and AI-based vessel fingerprinting to detect and track ships that disable, spoof, or never transmit identification signals. The effort will support U.S. and partner workflows, including Indian Navy systems and SeaVision.

The key shift is not just detection but integration: Vantorโ€™s output will feed directly into existing operational platforms used across Quad-linked partners. That improves shared maritime picture-building across a vast theater where non-compliant shipping, sanctions evasion, and covert activity exploit AIS blind spots.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
๐Ÿ“ก US military turns off ad trackers on devices amid Middle East targeting reports

The U.S. military has disabled advertising trackers on a range of phones and computers after reports that commercially available location data was used to target American forces in the Middle East. The move surfaced through statements and letters tied to Senator Ron Wyden.

Operationally, this frames ad-tech telemetry as a direct force protection issue rather than a privacy concern alone. It also underlines how routine mobile and device data can become actionable targeting intelligence when aggregated, sold, and matched against military patterns.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
๐Ÿ“ก Textron expands Navy contractor-run ISR support in the Pacific

Textron Systems received two NAVAIR task orders for contractor-owned, contractor-operated drone ISR services supporting the 7th Fleet and other U.S. forces. The awards, dated Aug. 24 and Aug. 31, carry ceiling values of about $43 million and $42 million over up to five years. The task orders cover Maritime B-Kits providing continuous sensor data and full-motion video, with up to 175 sensor data hours per month.

The move increases maritime ISR capacity without adding Navy-owned airframes or lifecycle burden. Textron says it will use the VTOL Aerosonde Mk. 4.7, aligning with prior Navy demand for runway-independent systems able to operate in austere, adverse-weather and GPS-degraded conditions.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
๐Ÿ” UK launches Project PANOPTES for autonomous anti-drone laser defense

The UK Ministry of Defence has opened Project PANOPTES, a ยฃ5 million competition for a vehicle-mounted counter-UAS system able to detect, track, and defeat NATO Class 1 drones autonomously. The requirement explicitly includes repeated, sequential, and simultaneous attacks, with laser directed-energy weapons identified as the preferred effector. First-stage submissions close on 23 September.

The tender shows UK planning is shifting from trials toward fieldable protection against low-cost saturation attacks that can drain conventional interceptors. The emphasis on autonomy, mobility, and non-depleting engagement capacity points to force protection as the immediate priority.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
๐Ÿ” Ted Backdoor Patches HAProxy to Intercept Traffic

A newly described implant dubbed Ted is designed to hide inside a victimโ€™s own HAProxy build, giving operators a stealthy position inside the web traffic path. The malware modifies the proxy binary rather than deploying as a separate process, allowing interception within routine application delivery workflows detailed in HAProxy builds already trusted in production.

The tradecraft matters because it shifts detection away from conventional process hunting toward binary integrity checks, build-pipeline validation, and proxy-level telemetry. Any compromise at this layer can expose session data and application traffic while blending into normal load-balancing infrastructure.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
๐Ÿ” CrowdStrike 'FalconFlank' zero-day enables SYSTEM privilege escalation

An exploit dubbed FalconFlank was released by the researcher Nightmare Eclipse, targeting CrowdStrike Falcon on fully updated Windows 11 25H2 and Windows Server 2025 systems. The flaw reportedly abuses Falcon's Office malicious macros remediation path to spawn a command prompt with SYSTEM privileges. CrowdStrike said it is investigating and advised customers to disable the Microsoft Office File Suspicious Macro Removal policy setting.

The issue is significant because it turns a defensive control inside endpoint security software into a local privilege escalation path on current builds. Until a public advisory, CVE, or patch is available, mitigation guidance is limited to configuration changes rather than a vendor fix.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
๐Ÿ” PostgreSQL flaw enables low-privilege server takeover

PostgreSQL has patched CVE-2026-6471, a flaw present since 2014 that allows accounts with REPLICATION privilege to load arbitrary files via logical decoding plugins and execute code as the database service account. Affected branches include 9.4 through 18, with fixes issued in 18.6, 17.11, 16.15, 15.19, and 14.24.

The issue turns routine replication access used by backup, monitoring, and data pipeline tooling into a direct path to persistent PostgreSQL superuser control and underlying host compromise across Windows, Linux, and macOS. Immediate patching and review of all replication-enabled accounts are now a priority.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
๐Ÿ” CISA flags exploited Chromium V8 flaw in KEV

U.S. CISA has added CVE-2026-85046 to its Known Exploited Vulnerabilities catalog after Google confirmed in-the-wild exploitation. The type confusion bug in Chromiumโ€™s V8 engine affects JavaScript and WebAssembly handling and can allow arbitrary code execution inside the browser sandbox via a crafted HTML page. Federal agencies have until 18 September 2026 to remediate.

The KEV addition formalizes the flaw as an active enterprise risk, not just a browser patching issue. It is the sixth exploited Chrome zero-day disclosed by Google in 2026, reinforcing V8 as a recurring attack surface with direct exposure through routine web content.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
๐Ÿ” Phishing campaign uses invisible Unicode to scale filter evasion

A newly tracked phishing campaign is sending millions of emails that embed invisible Unicode characters to bypass content filters and detection logic. The technique alters message text without visibly changing it for recipients, allowing payloads and lures to pass through systems that rely on standard string matching.

The operational value is straightforward: a low-visibility modification at text level can degrade email security controls at scale without changing user-facing content. For defenders, this highlights a gap between human-readable inspection and machine parsing in mail filtering pipelines.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
๐Ÿ” Congress presses DoD over troop tracking via commercial location data

US lawmakers Ron Wyden and Pat Harrigan have asked the DoD Inspector General to examine why commercially sold mobile location data can still expose US military movements. The Army, Navy, Air Force, Marine Corps, and SOCOM say ad identifiers are now disabled on government devices, but a DoD investigation request says data tied to DoD facilities remains available.

That suggests the exposure may now sit with personal devices, app SDK collection, or newer tracking methods beyond ad IDs, leaving force protection at risk despite branch-level policy changes.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
๐Ÿ” APT28-linked HOOKEDGE used in European espionage campaign

BlueDelta, tracked as APT28/Forest Blizzard, used the Windows backdoor HOOKEDGE against diplomatic, government, and defense targets in Romania, Spain, and Turkey. Activity ran from late September 2025 to early April 2026, with new variants in June and July 2026. Initial access relied on macro-enabled Word lures, followed by scheduled-task persistence and browser-mediated C2 via Microsoft Edge and webhook.site.

The tradecraft is notable for blending command traffic into normal HTTPS browser activity while keeping the malware lightweight and disposable. Reported beaconing intervals from 5 to 61 minutes indicate victim prioritization and efforts to limit infrastructure use while reducing forensic visibility.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
๐Ÿค– AI agents cut enterprise intrusion time to under 10 hours

Palo Alto Networksโ€™ Unit 42 documented an intrusion in which a threat actor used frontier models and agentic frameworks to breach an enterprise network, map internal services, search code repositories for secrets, access a secrets-management platform, and obtain root credentials. The operation used over 50 MITRE ATT&CK techniques and also abused DevOps workflows to exfiltrate cloud keys.

The case shows the shift was not novel access but machine-speed execution of known tradecraft. Branch protection blocked Terraform backdooring, but the attacker still repurposed the victimโ€™s own AI endpoints and cloud compute for post-compromise activity, compressing multiple attack phases into a single automated loop.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
๐Ÿ” PostgreSQL flaw exposed replication accounts for 12 years

A critical PostgreSQL bug, CVE-2026-6471, allowed low-privileged backup and replication accounts to execute arbitrary code via logical replication and malicious output plugins, then escalate to database superuser. The issue, detailed as PostGREShell, affected versions back to 9.4 and was patched on 22 August 2026.

The weakness sits on a trusted operational path: replication roles widely used for backups, migrations, CDC, and standby systems. Successful exploitation breaks the SQL permission model, enables persistence through config changes and preload libraries, and turns routine service accounts into full database compromise paths.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
๐Ÿ” JetBrains Cadence hit through unpatched TeamCity

Attackers breached JetBrains Cadence by exploiting an unpatched TeamCity instance and extracted AWS credentials, as detailed in the JetBrains Cadence incident. The intrusion chain centers on CI/CD exposure and credential access rather than a purely isolated application compromise.

Operationally, the case underscores how build infrastructure remains a high-value entry point: a single unpatched CI server can expose cloud access keys and widen downstream risk across development and production environments.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
๐Ÿ” Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

More than 5,400 compromised websites are being used to deliver ClickFix malware payloads, with the malicious code reportedly hosted in smart contracts on the BNB Smart Chain. The setup links mass website compromise with blockchain-based payload storage.

Operationally, this points to a scalable distribution model that blends conventional web compromise with decentralized infrastructure. For defenders, it complicates takedown and detection by separating initial delivery from payload hosting and spreading exposure across thousands of legitimate but hacked domains.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports