SITREP - Independent OSINT Channel
23K subscribers
17.4K photos
9.79K videos
6 files
23.4K links
AI, technology, mass surveillance, and intelligence — everything you need to know about tomorrow.
Download Telegram
⚡ Windows update backlog turns a dormant laptop into a 7-hour recovery cycle

A Windows 11 laptop left inactive for a few months reportedly required roughly seven hours to return to a fully updated state. The process involved cumulative OS updates, a newer Windows release, firmware and driver packages, and repeated restarts on standard production hardware.

The case undercuts vendor messaging around efficiency gains. Faster startup and lower memory use have limited operational value if infrequently used systems face hours-long patch recovery before they become usable. For users and admins, update volume and dependency chains remain a practical availability issue.

🛰️ Open sources - closed narratives
@sitreports
🔍 NightEagle expands GhostContainer operations onto Russian Exchange infrastructure

Kaspersky says NightEagle, also tracked as APT-Q-95, targeted Microsoft Exchange servers at Russian organizations with the GhostContainer backdoor. Initial access was linked to compromised VPN credentials, after which the group reportedly abused Exchange VIEWSTATE handling to launch the implant in memory, then used RDP, dev tunnels, Impacket atexec, and DCSync techniques for movement and persistence.

The activity is notable for combining valid-account access, fileless Exchange execution, and built-in or legitimate remote-access channels to reduce forensic visibility. On-prem Exchange and exposed RDP paths remain the key pressure points, especially where older flaws and weak credential hygiene overlap.

🛰️ Open sources - closed narratives
@sitreports
🔍 Fake LastPass installer used to disable endpoint defenses

A trojanized LastPass Authenticator installer was observed abusing a Microsoft-signed driver to terminate antivirus and EDR processes on Windows endpoints. The lure impersonates LastPass software while the signed kernel component gives the malware a trusted path to interfere with defensive tooling, as outlined in the installer analysis.

The tradecraft combines brand impersonation with driver abuse to neutralize host visibility before follow-on activity. For defenders, the key indicators are unexpected LastPass-themed installers, unsigned userland components paired with trusted drivers, and abrupt security product termination events.

🛰️ Open sources - closed narratives
@sitreports
🔍 Contagious Interview campaign hit 30,000 devices, drained $10.71M

The Contagious Interview campaign reportedly compromised 30,000 devices and stole $10.71 million in cryptocurrency. The operation used a fake job interview lure to deliver malware, combining social engineering with direct financial theft at scale.

The case underlines how recruitment-themed intrusion chains remain effective for initial access, especially against users willing to run files or join staged interview workflows. The volume of infected endpoints and the monetization outcome indicate a mature theft pipeline rather than isolated opportunistic activity.

🛰️ Open sources - closed narratives
@sitreports
🔍 CISA flags three actively exploited Linux kernel flaws

CISA added CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682 to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch or mitigate by end of day. The issues affect AF_ALG, ebtables SNAT, and the kTLS receive path; one bug reportedly existed in the kernel for 14 years.

The operational signal is the “forensic triage” requirement: CISA is treating exposure as a potential compromise, not just a patching gap. Public exploit availability has been confirmed for two of the three flaws, raising urgency for Linux fleets, containers, and systems using kTLS.

🛰️ Open sources - closed narratives
@sitreports
🔍 TASK#STOMP PowerShell backdoor targets local data collection

The TASK#STOMP backdoor is described as a PowerShell-based malware focused on stealing documents, Wi-Fi passwords, and clipboard contents from compromised Windows systems. The reported collection set indicates direct harvesting of user files, stored network credentials, and transient data copied through the clipboard.

The combination is operationally notable because it supports both immediate data theft and follow-on access. Wi-Fi credentials can extend intrusion paths, clipboard capture can expose passwords or crypto wallets, and document theft suggests prioritization of locally accessible intelligence over destructive effects.

🛰️ Open sources - closed narratives
@sitreports
📡 BigCommerce isolates app-linked customer data breach

BigCommerce notified multiple merchants after attackers used compromised credentials for third-party apps Ribon and Ribon 1.5 to inject malicious scripts and access shopper records between September 13 and 17. The company removed the apps on September 17 and says platform systems, passwords, and payment card data were not exposed. UK retailer Master of Malt said names, emails, phone numbers, and shipping addresses were accessed.

The incident highlights a familiar SaaS supply-chain weakness: trusted app keys can provide direct access into merchant environments without a breach of the core platform. BigCommerce’s response contained access by uninstalling the apps, but the case shows how third-party integrations remain a high-value path to customer data.

🛰️ Open sources - closed narratives
@sitreports
🔍 RansomHouse named in breach of Namibia defense ministry network

Namibia’s national cyber team has confirmed unauthorized activity inside the Ministry of Defence and Veterans Affairs network and directly linked the incident to RansomHouse. The group listed the “Namibian Defence Force” on its leak site on 16 September. Authorities have not disclosed whether data was stolen, systems were encrypted, or a ransom was demanded.

The notable point is the public attribution by NAM-CSIRT at an early stage. What remains unclear is the actual impact on defense systems, data exposure, and recovery timeline, leaving the current operational effect unconfirmed.

🛰️ Open sources - closed narratives
@sitreports
📡 Pentagon awards GEO surveillance satellite prototypes under GHOST-R

Space Systems Command and the Defense Innovation Unit awarded prototype contracts to Northrop Grumman and True Anomaly for GHOST-R, a Space Force effort to field satellites that can image and characterize other objects in geostationary orbit. Launch is planned for 2028, with transition to government-led operations in 2029. Contract values were not disclosed.

The program points to a push for distributed, commercially derived space-domain awareness in GEO, with emphasis on tracking, approaching, and identifying resident space objects as orbital congestion and counterspace risks grow.

🛰️ Open sources - closed narratives
@sitreports
📡 III Armored Corps starts baseline NGC2 fielding

III Armored Corps has begun receiving the transport and infrastructure layers of the Army’s Next Generation Command and Control stack, making it the first unit to divest legacy WIN-T gear under the new consolidated fielding process. The package includes SATCOM antennas, automated traffic management tools, and forward servers with cloud access for DDIL operations.

This marks a shift from extended experimentation to operational rollout. The Army is establishing a common baseline network architecture before adding NGC2’s data and application layers, while reducing deployment time and legacy system burden across the force.

🛰️ Open sources - closed narratives
@sitreports
📄 FBI CJIS v6.1 tightens encryption and scanning cadence

The FBI’s CJIS Security Policy v6.1, published 25 June 2026, keeps the v6.0 control-based structure but raises key technical baselines. Encryption for CJI in transit under SC-13 now requires at least 256-bit symmetric strength, up from 128-bit, while SC-28 sets 256-bit protection for CJI at rest. Vulnerability scanning frequency also shifts from quarterly to at least monthly.

The update does not reset audit practice overnight. Priority 1 controls remain sanctionable, while Priority 2-4 stay in zero-cycle status until 30 September 2027, and some state CSAs are still auditing older baselines. For defenders, the shift is less about new direction than faster verification, stronger crypto, and continuous evidence of control effectiveness.

🛰️ Open sources - closed narratives
@sitreports
🤖 CLOSEDQUORUM brings LLM voting into Windows malware

Cisco Talos has documented CLOSEDQUORUM, a Go-based Windows implant that queries Gemini, DeepSeek, Qwen, and Mistral to choose predefined post-compromise actions. Available modules include credential and crypto-wallet theft, shellcode injection, and persistence. Talos says it has not seen in-the-wild deployment.

The key shift is autonomy after access: the implant can continue tasking without live operator input. Detection value is behavioral rather than network-based, especially systems that contact multiple LLM services and Discord while touching LSASS, injecting into suspended processes, or creating WMI persistence.

🛰️ Open sources - closed narratives
@sitreports
🔍 BigDiskBuster PoC targets Defender update path

A researcher has released a proof-of-concept for a zero-day dubbed BigDiskBuster that blocks Microsoft Defender updates. The issue affects the endpoint protection update mechanism rather than malware scanning itself, creating a denial condition on signature and engine delivery.

Operationally, this shifts a defender-controlled security layer into a degradable dependency. Systems may remain online and appear protected while drifting out of date, reducing detection coverage and extending attacker dwell time without directly disabling Defender.

🛰️ Open sources - closed narratives
@sitreports
🔍 Critical Bifrost AI Gateway flaw enables unauthenticated command execution

A critical vulnerability in the Bifrost AI Gateway allows attackers to run commands without valid credentials. The issue affects an AI-facing gateway layer, turning exposed deployments into potential remote execution points with no authentication barrier.

The operational impact is direct: a gateway positioned between users, tools, and models can become an initial access vector with privileged reach into downstream systems. For defenders, this shifts Bifrost from an application risk to an infrastructure-level exposure requiring immediate patching, access review, and external surface checks.

🛰️ Open sources - closed narratives
@sitreports
🔍 Check Point patches actively exploited Management Server zero-day

Check Point has released emergency fixes for CVE-2026-93616, a critical path traversal flaw in Security Management Server that allows unauthenticated attackers to upload and execute arbitrary scripts. The company said the bug is exploited in the wild and that a handful of customers were attacked. Affected products also include Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.

The issue hits the management plane rather than a single gateway, giving attackers a route into policy control, admin changes, and log infrastructure. Check Point says exploitation activity was observed from September 12 and advises immediate hotfixing or access restriction to trusted IPs.

🛰️ Open sources - closed narratives
@sitreports
🔍 ShinyHunters alleges FBI intrusion via PeopleSoft zero-day

ShinyHunters claims it breached FBI systems through an alleged Oracle PeopleSoft zero-day, moved into AWS GovCloud, and stole 2-3TB of employee, applicant, and internal data. The FBI said it is investigating unauthorized activity affecting FBIjobs.gov, while a reported defacement and sample records were shared with media. Oracle and Mandiant had not confirmed the claimed flaw at publication. PeopleSoft is cited as the initial access vector.

If accurate, the incident points to a high-impact enterprise application exposure with direct access to HR and identity-rich datasets. The key OSINT gap remains verification: the intrusion claim, scale of exfiltration, and zero-day status are still unconfirmed by the affected agency or vendor.

🛰️ Open sources - closed narratives
@sitreports
🔍 EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts

The phishing-as-a-service platform EvilTokens has been disrupted after compromising more than 12,000 Microsoft accounts across over 10,000 organizations. The action was led by Microsoft’s Digital Crimes Unit, indicating a coordinated takedown of infrastructure tied to credential theft operations.

The scale points to broad enterprise exposure rather than isolated victim sets. Disrupting a PhaaS operator can degrade attacker access pipelines, but the account count suggests downstream incident response, credential resets, and tenant-wide security reviews will remain the immediate priority.

🛰️ Open sources - closed narratives
@sitreports
Forwarded from Rybar in English
📝A Hasid in the Trenches?📝

Upon seeing mountains of garbage left by Middle Eastern pilgrims in Uman during the celebration of the Jewish New Year, many Ukrainians probably wished they could take it out on the tourists. And their dream, it seems, has partly come true.

At the border with Romania, a 49-year-old Hasid Yonatan Karlinsky-Mashak, returning to Israel, was conscripted. Although he left so-called Ukraine 14 years ago, and his passport lists the USSR as his birthplace, border guards "identified" him by his knowledge of the language and removed him from the flight.

The Israeli Foreign Ministry, usually quick to respond to far less serious incidents involving its citizens abroad, remains silent. And the wife of the abducted man is oddly more concerned that in the hands of the TCC he cannot eat kosher food.

📌 But the most amusing thing is that absolutely any outcome of this episode will, albeit slightly, hurt precisely so-called Ukraine. If the detained Hasid is sent to the AFU, it will further change the attitude of part of the Jewish community toward the Kyiv regime.

And if this Israeli is simply released, Ukrainians will once again be made to understand that they are fundamentally second-class people. They will increasingly be haunted by thoughts like "we are sent to the front so that they can not fear the TCC and lord it over our lands."

So we await the resolution of this story — it will clearly provide a couple of very vivid news hooks.
#Israel #Ukraine
✈️ RU | ✈️ EN | ✉️ MAX

✉️ VK | ✉️ RuTube | ✉️ OK | ✉️ Zen

💸Support us Original msg
Please open Telegram to view this post
VIEW IN TELEGRAM
🔍 Russia exports its geological school

The Karpinsky Institute has opened a "Karpinsky class" in Mongolia, the tenth in a network built over three years across Africa, Central Asia, Eastern Europe and the Caribbean. The programme places Russian scientific centres in partner countries and trains local specialists in geology and mineral resource management using Russian methodology.

The wider implication runs past education. Mineral surveying sits upstream of every mining licence, export contract and infrastructure decision a resource-rich state makes. Whoever trains the geologists shapes the technical vocabulary those decisions are made in, and does so for a generation.

Mongolia illustrates the competitive dimension. Western NGOs have long-standing programmes there, and a state sitting on major copper and coal reserves is a place where technical influence converts into policy influence. The Institute's other recent work, from the Arabian Shield contract with Saudi Arabia to Vietnam's first national mineral resources map, follows the same logic.

🛰️ Open sources - closed narratives
@sitreports
🔍 TrustSink turns external MFA into a credential theft path

Varonis Threat Labs detailed TrustSink, a post-compromise technique in Microsoft Entra where a privileged attacker registers a rogue external MFA provider, presents a fake Microsoft password prompt during the MFA step, captures credentials in plaintext, then returns a valid signed token so login completes normally.

The key point is persistence inside the authentication flow: password resets alone do not remove the malicious provider, and replacement credentials can be captured on the next sign-in. Detection should focus on Authentication Methods Policy changes, external MFA provider registrations, associated apps, keys, and redirect URIs.

🛰️ Open sources - closed narratives
@sitreports
🔍 Multi-vector intrusions tied to Chinese-speaking cluster hit gov and edge infrastructure

GreyNoise tracked a Chinese-speaking threat actor exploiting WordPress wp2shell flaws and ZyXEL GS1900 bugs, with targeting also observed against PAN-OS GlobalProtect, Ubiquiti, FlowiseAI, Gitea, Nuclio, SENAITE LIMS, Proxmox VE, and Dirty Pipe. In one Western government intrusion, attackers stole 18,566 SQL records containing accounts, plaintext passwords, and PII. GreyNoise linked scans and attacks to one IP and published IoCs.

The activity shows coordinated use of public exploits across web apps, network gear, and backend systems to move from edge access to credential theft and database exfiltration. The breadth of exploited products also highlights exposure beyond KEV-listed flaws.

🛰️ Open sources - closed narratives
@sitreports