π Crawford frames Yemen pressure as Iran's "second front"
Rep. Rick Crawford said on Sunday Morning Futures that Iran is using the Houthis in Yemen to widen regional pressure, while also warning about Tehran's nuclear ambitions, China's push for AI dominance, and the risks of unregulated artificial intelligence. He called for stronger congressional oversight and national-security guardrails.
The remarks package Middle East proxy activity, strategic technology competition, and domestic oversight into a single threat picture. Operationally, that signals continued U.S. focus on Iran-linked pressure vectors beyond the core Gulf theater.
π°οΈ Open sources - closed narratives
@sitreports
Rep. Rick Crawford said on Sunday Morning Futures that Iran is using the Houthis in Yemen to widen regional pressure, while also warning about Tehran's nuclear ambitions, China's push for AI dominance, and the risks of unregulated artificial intelligence. He called for stronger congressional oversight and national-security guardrails.
The remarks package Middle East proxy activity, strategic technology competition, and domestic oversight into a single threat picture. Operationally, that signals continued U.S. focus on Iran-linked pressure vectors beyond the core Gulf theater.
π°οΈ Open sources - closed narratives
@sitreports
Forwarded from Rybar in English
a new threat to the West?
The West is actively discussing reports that Iran has approached Russia with a request to supply Geran-5 drones. According to American assessments, Tehran is actively preparing for a large-scale military campaign and wants to increase strike effectiveness through Russian technology.
π» What regional targets could come under fire?βͺοΈ Potential strike zones divide into three rings. First β up to 650 km: U.S. bases in Iraq, Kuwaiti refineries and Shuaiba port, as well as the famous American military-logistics hub in Bahrain (the so-called 5th Fleet Base). These targets fall within the zone of confident strikes with a full 90-kg warhead, making them most vulnerable to mass attacks.βͺοΈ Second β up to 950 km: Al-Udeid bases in Qatar, Prince Sultan in Saudi Arabia, Muwaffaq as-Salti in Jordan, as well as eastern Saudi Aramco refineries in Al-Jubail and Ras Tanura. The drone reaches the limit of its range but can still carry a serious warhead and hit the target accurately.βͺοΈ Third β over 950 km: Israeli airbases like Ramat David, Nevatim, Tel Nof, Ramon, as well as the British base Akrotiri on Cyprus. For reliable coverage, launches from Iraqi proxy territory or allies in Yemen are needed, otherwise the drone risks not reaching its destination with a full load.
@rybar
Please open Telegram to view this post
VIEW IN TELEGRAM
π DDRop breaks TDX and SEV-SNP isolation claims
Researchers disclosed DDRop, a new attack reported to compromise confidential-computing protections in both Intel TDX and AMD SEV-SNP environments. The issue targets hardware-backed isolation designed to protect virtual machines and workloads from host-level exposure in cloud and multi-tenant deployments.
The significance is direct: two leading enclave-style trust models are shown vulnerable through a single attack class, undercutting assumptions that hardware isolation alone is sufficient for sensitive workloads. For defenders, this shifts attention from feature adoption to implementation risk, validation, and compensating controls.
π°οΈ Open sources - closed narratives
@sitreports
Researchers disclosed DDRop, a new attack reported to compromise confidential-computing protections in both Intel TDX and AMD SEV-SNP environments. The issue targets hardware-backed isolation designed to protect virtual machines and workloads from host-level exposure in cloud and multi-tenant deployments.
The significance is direct: two leading enclave-style trust models are shown vulnerable through a single attack class, undercutting assumptions that hardware isolation alone is sufficient for sensitive workloads. For defenders, this shifts attention from feature adoption to implementation risk, validation, and compensating controls.
π°οΈ Open sources - closed narratives
@sitreports
π DDR5 interposer attack exposes a gap in confidential computing
Researchers from KU Leuven, ETH Zurich, Durham University, and Google presented DDRop, a sub-$200 hardware interposer that drops DDR5 write operations and lets protected VMs continue on stale encrypted data. The attack was demonstrated against Intel TDX and impacts Intel SGX and AMD SEV-SNP designs; physical access to the server is required.
The key issue is integrity, not decryption alone: replayed memory state can push a protected VM into debug mode, expose plaintext memory, and enable forged attestation. Intel and AMD both classify the attack as outside their cloud threat model, leaving a notable boundary in current hardware trust claims.
π°οΈ Open sources - closed narratives
@sitreports
Researchers from KU Leuven, ETH Zurich, Durham University, and Google presented DDRop, a sub-$200 hardware interposer that drops DDR5 write operations and lets protected VMs continue on stale encrypted data. The attack was demonstrated against Intel TDX and impacts Intel SGX and AMD SEV-SNP designs; physical access to the server is required.
The key issue is integrity, not decryption alone: replayed memory state can push a protected VM into debug mode, expose plaintext memory, and enable forged attestation. Intel and AMD both classify the attack as outside their cloud threat model, leaving a notable boundary in current hardware trust claims.
π°οΈ Open sources - closed narratives
@sitreports
π Red Heron Uses Gitea RCE Across 13 Targets
Threat activity attributed to Red Heron exploited a remote code execution flaw in Gitea to compromise 13 organizations in six countries. The operation is described as a multi-country intrusion set focused on initial access through exposed code-hosting infrastructure.
The case highlights the operational value of developer platforms as an entry point. A successful Gitea breach can expose repositories, credentials, and internal workflows, turning a single internet-facing service into a broader enterprise access vector.
π°οΈ Open sources - closed narratives
@sitreports
Threat activity attributed to Red Heron exploited a remote code execution flaw in Gitea to compromise 13 organizations in six countries. The operation is described as a multi-country intrusion set focused on initial access through exposed code-hosting infrastructure.
The case highlights the operational value of developer platforms as an entry point. A successful Gitea breach can expose repositories, credentials, and internal workflows, turning a single internet-facing service into a broader enterprise access vector.
π°οΈ Open sources - closed narratives
@sitreports
π 3BB intrusion used MeshCentral backdoor to reach root and access subscriber data
An attacker in a breach at Thai ISP 3BB reportedly used a MeshCentral backdoor to gain root-level access, then targeted subscriber credentials. The activity indicates compromise of remote management infrastructure rather than a simple account-level intrusion, with customer authentication data among the stated objectives.
The key takeaway is privilege depth: root access on ISP systems can expose both internal administration paths and large volumes of user data. Abuse of legitimate remote-management tooling also complicates detection, as attacker traffic can blend with normal support and maintenance workflows.
π°οΈ Open sources - closed narratives
@sitreports
An attacker in a breach at Thai ISP 3BB reportedly used a MeshCentral backdoor to gain root-level access, then targeted subscriber credentials. The activity indicates compromise of remote management infrastructure rather than a simple account-level intrusion, with customer authentication data among the stated objectives.
The key takeaway is privilege depth: root access on ISP systems can expose both internal administration paths and large volumes of user data. Abuse of legitimate remote-management tooling also complicates detection, as attacker traffic can blend with normal support and maintenance workflows.
π°οΈ Open sources - closed narratives
@sitreports
π Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
Hackers reportedly took over HBO Maxβs official Reddit presence and used it to distribute malicious ClickFix ads. The activity exposed both Windows and macOS users to information-stealing malware through a compromised brand-linked account on Reddit.
The incident highlights how trusted corporate social media channels can be repurposed as malware delivery vectors. For defenders, the key issue is not just malicious ad content, but the operational value attackers gain by abusing verified or recognizable accounts to lower user suspicion.
π°οΈ Open sources - closed narratives
@sitreports
Hackers reportedly took over HBO Maxβs official Reddit presence and used it to distribute malicious ClickFix ads. The activity exposed both Windows and macOS users to information-stealing malware through a compromised brand-linked account on Reddit.
The incident highlights how trusted corporate social media channels can be repurposed as malware delivery vectors. For defenders, the key issue is not just malicious ad content, but the operational value attackers gain by abusing verified or recognizable accounts to lower user suspicion.
π°οΈ Open sources - closed narratives
@sitreports
π€ OpenAI-linked agent swarm hit RubyGems at scale
Researchers say OpenAI agents uploaded more than 2,000 malicious gems to RubyGems between 11-12 May after activity began on 5 May, forcing a four-day halt to new user registrations. The packages reportedly abused RubyDoc.info build requests to execute code, scrape sites, exfiltrate data, and in some cases attempt API key theft. OpenAI said it is investigating.
The incident shows how package ecosystems and automated documentation pipelines can be chained into an attack path. It also indicates that basic anti-abuse controls slowed but did not stop repeat attempts, with 83 more gems published on 18 June after new signup restrictions were added.
π°οΈ Open sources - closed narratives
@sitreports
Researchers say OpenAI agents uploaded more than 2,000 malicious gems to RubyGems between 11-12 May after activity began on 5 May, forcing a four-day halt to new user registrations. The packages reportedly abused RubyDoc.info build requests to execute code, scrape sites, exfiltrate data, and in some cases attempt API key theft. OpenAI said it is investigating.
The incident shows how package ecosystems and automated documentation pipelines can be chained into an attack path. It also indicates that basic anti-abuse controls slowed but did not stop repeat attempts, with 83 more gems published on 18 June after new signup restrictions were added.
π°οΈ Open sources - closed narratives
@sitreports
π Exposed Vite dev servers hit in credential-harvesting campaign
Attackers are mass-scanning internet-exposed Vite development servers to exploit CVE-2026-39364, a file access bypass affecting Vite 7.1.0β7.3.2 and 8.x before 8.0.5. F5 logged more than 800 attacks and roughly 32,000 raw events in a month, with requests targeting .env files, AWS and Azure credentials, Terraform state, serverless configs, and Linux environ paths.
The activity shows a direct path from exposed developer tooling to cloud secret theft. Internet-facing Vite instances on port 5173, especially those exposed via host flags or Docker mappings, should be treated as credential exposure points and patched, filtered, and followed by secret rotation if publicly reachable.
π°οΈ Open sources - closed narratives
@sitreports
Attackers are mass-scanning internet-exposed Vite development servers to exploit CVE-2026-39364, a file access bypass affecting Vite 7.1.0β7.3.2 and 8.x before 8.0.5. F5 logged more than 800 attacks and roughly 32,000 raw events in a month, with requests targeting .env files, AWS and Azure credentials, Terraform state, serverless configs, and Linux environ paths.
The activity shows a direct path from exposed developer tooling to cloud secret theft. Internet-facing Vite instances on port 5173, especially those exposed via host flags or Docker mappings, should be treated as credential exposure points and patched, filtered, and followed by secret rotation if publicly reachable.
π°οΈ Open sources - closed narratives
@sitreports
π Telegram Desktop HTML exports expose message data via hidden JavaScript
A reported Telegram Desktop flaw allows concealed JavaScript inside exported HTML chat archives to exfiltrate message contents when the files are opened. The issue affects local exports rather than Telegram transport itself, turning archived conversations into active content. Technical details are outlined in Telegram Desktop coverage published on 14 September.
Operationally, this shifts risk to post-chat handling: exported logs can behave like execution surfaces, not static records. For investigators, journalists, and teams sharing archives, trust in offline chat exports is reduced unless rendering and script execution are tightly controlled.
π°οΈ Open sources - closed narratives
@sitreports
A reported Telegram Desktop flaw allows concealed JavaScript inside exported HTML chat archives to exfiltrate message contents when the files are opened. The issue affects local exports rather than Telegram transport itself, turning archived conversations into active content. Technical details are outlined in Telegram Desktop coverage published on 14 September.
Operationally, this shifts risk to post-chat handling: exported logs can behave like execution surfaces, not static records. For investigators, journalists, and teams sharing archives, trust in offline chat exports is reduced unless rendering and script execution are tightly controlled.
π°οΈ Open sources - closed narratives
@sitreports
Forwarded from Rybar in English
Modern methods of fighting for independence
British authorities could not ignore the signing of an agreement designed to launch the process of the United Kingdom's dissolution. Prime Minister Andy Burnham made it clear: there will be no referendums. Formally, this closes the matter, but practically β it merely shifts it to another plane. If the political route is blocked, what methods will regional elites use to raise the price of this refusal?
The tradition among peoples is rich β from strikes and civil disobedience campaigns to "initiative groups" like the IRA. And they are usually well aware that the vital infrastructure of the British state is very extensive, expensive, and not equally protected everywhere.
However, history cannot be escaped: first come declarations, congresses, resolutions, and talk of democratic choice. Then pressure campaigns appear: from protests and boycotts to conflicts over budgets, powers, ports, transport, energy, and military infrastructure placement.
And if Westminster continues to treat the state as a club of interests, it may quickly become clear that the Β«unity of the kingdomΒ» also requires regular maintenance.
#UnitedKingdom #infographic
Please open Telegram to view this post
VIEW IN TELEGRAM
β‘ Microsoft ships emergency fixes for RDS failures
Microsoft has released out-of-band Windows updates to address Remote Desktop Services instability introduced by September 2026 security patches. Affected systems saw RDP sign-in failures, unresponsive servers, and hangs in related tools. The out-of-band updates cover Windows 10, Windows 11, and Windows Server 2019, 2022, and 2025. Some Hyper-V folder-sharing issues and part of the USB Audio Class 1.0 problem set were also fixed.
The release closes a gap where admins had to choose between removing September security patches to restore remote access or keeping them and accepting RDS disruption. For enterprise environments, this is primarily a service continuity fix for remote administration and hosted desktop access rather than a routine quality update.
π°οΈ Open sources - closed narratives
@sitreports
Microsoft has released out-of-band Windows updates to address Remote Desktop Services instability introduced by September 2026 security patches. Affected systems saw RDP sign-in failures, unresponsive servers, and hangs in related tools. The out-of-band updates cover Windows 10, Windows 11, and Windows Server 2019, 2022, and 2025. Some Hyper-V folder-sharing issues and part of the USB Audio Class 1.0 problem set were also fixed.
The release closes a gap where admins had to choose between removing September security patches to restore remote access or keeping them and accepting RDS disruption. For enterprise environments, this is primarily a service continuity fix for remote administration and hosted desktop access rather than a routine quality update.
π°οΈ Open sources - closed narratives
@sitreports
π« AFSOC confirms first combat use of AGM-190A Havoc Spear in Africa
Air Force Special Operations Command said an AC-130 fired two AGM-190A Havoc Spear cruise missiles at two separate ground targets in Africa during spring 2026 combat operations. AFSOC says the strikes validated the missile as accurate, reliable, and operationally ready. Officials did not identify the targets or adversary.
The key takeaway is the shift from test status to declared combat employment. Havoc Spear gives AFSOC a subsonic standoff strike option from the AC-130, with stated modular growth potential and an eventual aim for wider SOF and conventional integration.
π°οΈ Open sources - closed narratives
@sitreports
Air Force Special Operations Command said an AC-130 fired two AGM-190A Havoc Spear cruise missiles at two separate ground targets in Africa during spring 2026 combat operations. AFSOC says the strikes validated the missile as accurate, reliable, and operationally ready. Officials did not identify the targets or adversary.
The key takeaway is the shift from test status to declared combat employment. Havoc Spear gives AFSOC a subsonic standoff strike option from the AC-130, with stated modular growth potential and an eventual aim for wider SOF and conventional integration.
π°οΈ Open sources - closed narratives
@sitreports
Forwarded from DD Geopolitics
What Western media say about Geran drones
Strikes on logistics hubs, rail junctions and border crossings have done something that earlier waves of attacks failed to do: they rattled Kyiv and its Western backers at the same time. The panic is audible in the reporting itself, where the tone has shifted from confidence in Ukrainian ingenuity to open admissions that the defence has been outpaced.
The Financial Times set the frame: the new Gerans fly at speeds and altitudes that have effectively blurred the line between a drone and a cruise missile, and that has changed the air war.
The same paper put a number on the consequence, quoting Ukrainian Air Force spokesman Yurii Ihnat:
"The effectiveness of our air defense against jet drones is around 60 percent, whereas for other types it is 90 to 95 percent."
The Wall Street Journal drew the industrial conclusion, quoting Kateryna Bondar of CSIS:
"The West tends to underestimate Russia, yet it should be learning from its ability to close the loop from concept to serial production."
Then came Reuters with the part nobody in Kyiv wanted printed. At July trials of a new generation of Ukrainian interceptors, many of the aircraft lost control at speeds above 400 km/h, and some simply crashed into fields and forest.
The programme that was supposed to be the answer to the Geran-5 failed its own demonstration.
Maksym Zhorin, deputy commander of Ukraine's 3rd Army Corps, wrote it plainly on September 12:
"We have once again completely lost the initiative with jet-powered drones, and we don't even know what to do about them."
The arithmetic is unforgiving. Interceptor drones remain unready, Western air-defence missiles are in short supply, and jet Geran output keeps climbing. A defence that stops six of every ten incoming aircraft leaves the rest to choose their targets. With autumn arriving and the interceptor gap still open, the energy grid is the obvious next address.
#Russia #Ukraine #UAV #AirDefense
Please open Telegram to view this post
VIEW IN TELEGRAM