⚠️ I scanned an iPhone for Pegasus and it came back with one critical alert. The tool is called the Mobile Verification Toolkit, or MVT. It’s free and open source and was built by Amnesty International’s Security Lab. All you need to do is make an encrypted backup of your phone on a computer, point MVT at it, and it checks your messages, browsing history, apps and data usage against known traces and fingerprints of Pegasus, Predator, stalkerware and other surveillance tools. It works for iPhone and Android, and it runs on a Mac or on Windows.
🐱 Check the tool at GitHub
😊 If you enjoyed the article share it with your friends and follow us.
#Pegasus #Paragon #Spyware #iPhone #Android
@PrivacyNotACrime 🗽 ⌨️ Chat
📰 Disinformation as a service: BlackCore sells influence campaigns
Public opinion has officially gone up for sale. Researchers from Citizen Lab have uncovered the activities of Israeli company BlackCore, which has moved disinformation from intelligence services' toolkit into conventional B2B services. Now any paying client can access a full information warfare cycle: from creating hundreds of convincing fake profiles to artificially suppressing unwanted narratives, complete with detailed efficiency reports.
📢 How the disinformation factory works
The fake campaign management process is structured like a classic advertising agency. Instead of crudely selling inactive accounts, BlackCore implements complete infrastructure. Neural networks generate avatar faces for social media, writers craft coordinated messages, and algorithms artificially boost posts. This system lets clients quickly simulate mass support or destroy a competitor's reputation by flooding the space with aggressive noise.
Operations follow professional standards including target audience analysis, multi-platform deployment, engagement metrics tracking, and polished final deliverables presented as corporate reports. It is information manipulation packaged like any other enterprise service.
❔ Why this matters for everyone
The main risk lies in increasing accessibility of these methods on the open market. When tools for suppressing opinions and dominating agendas sell as corporate subscriptions, it becomes nearly impossible to distinguish genuine social movements from paid digital illusions.
The implications extend far beyond corporate competition. Political campaigns, public health messaging, and social justice efforts can all be drowned out by manufactured consensus funded by undisclosed actors.
🔗 Check more information about this at Citizen Lab
😊 Follow us to stay informed about the latest threats and protect yourself.
#Disinformation #CyberSecurity #InformationWarfare #DigitalPrivacy #StateSp
📰 Weekly Cybersecurity News Roundup
AI agents breached the Australian Ministry of Health website, stealing data from 600,000 bank cards within hours, prompting OpenAI and Anthropic to seek UN intervention to contain these technologies. Meanwhile, a routing error triggered a global internet disruption affecting over 100 countries, and banks worldwide face challenges with customer call identification.
📰 We have compiled the most interesting news of the week in one place so you don't miss anything.
🌎 Global AI and infrastructure alerts
🔹 OpenAI and Anthropic are developing increasingly powerful AI systems and are now requesting UN oversight: following a series of concerning incidents involving autonomous agents, the issue has reached the Security Council.
🔹 An Iranian operator began advertising third-party IP addresses as their own, triggering a global routing disruption that impacted more than 100 countries.
🔹 OpenAI's AI agents hacked the Australian Ministry of Health website, with the alarm only raised three months after the incident occurred.
🔹 In a database stolen from the FBI, employees of a secret unit known as ROU were identified, a group dedicated to hacking third-party devices.
🔹 Approximately $351.6 million was withdrawn from the cryptocurrency exchange Bitget, with thieves rapidly transferring stolen tokens to Ethereum.
🌟 Security landscape shifts
🔹 AI agents stole data from 600,000 bank cards with minimal human intervention, completing the entire hack in just a few hours.
🔹 AI analyzed a MikroTik patch within an hour and discovered a method to access systems without a password; attacks began before router owners could apply updates.
🔹 Hackers barely touched vulnerabilities that an Anthropic neural network found in massive quantities; it proved much easier to identify the flaw than to weaponize it into a full attack.
🔹 Palo Alto Networks is launching Claude and GPT instances to continuously attempt hacking corporate systems, including applicati
⚠️ Malware pressure increased across the threat landscape last week, with RATs, stealers, and loaders all gaining activity at the same time. AsyncRAT climbed 35%, while Quasar, DonutLoader, and Lumma saw even sharper growth.
📌 Trend to watch: broad growth across established threats can increase investigation pressure across multiple threat types at once. SOC teams may need to rebalance detection and triage priorities as volumes rise.
👉 Monitor the malware driving today’s attacks
#Top10Malware
🦠 Finding vulnerable subdomains using Censys
Censys is like Shodan and Google Dorks, but powered up. We already talked about it in detail in the article How to Use Censys. Today, we will analyze it from the perspective of searching for vulnerabilities in subdomains.
The best way to find subdomains using search engines is to use filters called dorks that are better understood by the Internet itself. We cannot simply tell Google find all Microsoft subdomains please. We need to speak computer language, not human language.
Bug Bounty is a reward program that a website owner conducts to attract external information security specialists to find vulnerabilities. When participating in Bug Bounty, one must act ethically and follow established rules.
💻 Search for Microsoft subdomains
Let us try to find Microsoft subdomains. Go to Censys Search and copy and paste the following query into the search bar.
(services.tls.certificates.leaf_data.names: microsoft.com) and services.http.response.status_code=200
After execution, a list of working subdomains of the site will appear. The results show active domains that respond with HTTP status code 200, meaning they are live and accessible.
⚡️ Enable virtual hosts filter
For a better result, click on the settings icon next to the search panel and select the Virtual Hosts option. This setting expands your search beyond just the primary domain. Now, with Virtual Hosts enabled, you can see all subdomains available to Microsoft services and possibly find attack vectors.
The Virtual Hosts feature is particularly valuable because many organizations host multiple services on the same IP address. By enabling this option, Censys reveals which subdomains share infrastructure and what services they expose publicly.
🔘 Real bug bounty example
In one scenario from a HackerOne report, a bug hunter discovered an interesting subdomain with registration enabled for internal users this way. Then, after registration, the hacker was able to acce
■■■■□ UAE Ministry of Interior Data Breach 🇦🇪
A threat actor S-Root claims to have obtained 4 TB of data allegedly linked to the UAE Ministry of Interior after “10 days” of access to its servers.
Claimed data includes:
• Emirates ID & passport records
• Resident & visitor information
• Fingerprints & biometric data
• Driving/vehicle license records
• Traffic violations & penalty points
• Issued driving certificates
💰 Claimed sale price: $3,000
🔐 Access price: $8,000
⚠️ The breach and authenticity of the dataset have not been independently verified. Claims involving highly sensitive identity and biometric information should be treated as unverified until confirmed by the relevant authorities or credible independent sources.
❗️ Active now: Attackers are mimicking AI tools like Claude, DeepSeek, and ChatGPT to deliver stealers and RATs through fake download pages, malicious installers, ClickFix commands, and even real shared chats that tell users to paste a command.
Full attack chains, behavior data, and IOCs for detection are available in #ANYRUN Sandbox 👇
🔹 Claude Lure + ClickFix
🔹 Claude Lure + Infostealer
🔹 DeepSeek Lure + ValleyRAT
🔹 ChatGPT Lure + Fake Cloudflare CAPTCHA
⚡️ See how ANY.RUN helps SOC teams detect & investigate complex threats faster
#ExploreWithANYRUN
💜 Advanced command and control framework for implant management during Red Team operations
PoshC2 is a Python 3-based command and control framework built for serious Red Team work. It handles post-exploitation automation, lateral movement and agent management on compromised systems so operators can focus on the mission rather than fighting with clunky manual procedures.
🛡 Built to slip past defenses
The real strength here is evasion. PoshC2 targets EDR and antivirus bypass, runs C# implants and lets you shape communication channels through flexible C2 profiles.
Traffic patterns can be adjusted to look like normal network activity, which makes detection much harder for defenders trying to spot malicious beaconing.
Beyond evasion, the framework automates script launches for obfuscation and pulls credentials efficiently. Both web and CLI interfaces mean multiple operators can work the same target simultaneously without stepping on each other's toes, a genuine advantage during time-sensitive engagements.
🔲 Why defenders should care
Blue teams need to understand what attackers are using. Frameworks like PoshC2 leave traces, and knowing how they operate helps analysts write better detection rules. A few practical moves strengthen your position: keep endpoint protection fresh, monitor for strange outbound connections or periodic check-ins, lock down network segments to stop lateral spread, enforce least privilege everywhere, and run regular adversary simulations to catch blind spots in your visibility.
🐱 Check this useful tool at GitHub
😊 If you enjoyed the article share it with your friends and follow us.
#C2 #RedTeam #OffensiveSecurity #Evasion #PenetrationTesting
@PrivacyNotACrime 🗽 ⌨️ Chat
Admin has been task with pulling together all the best tips for how to set up GrapheneOS, to see if there's enough in it for a video.
Here's the early work:
- PIN needs to be strong min 12-char if using numerical but you can do even better
- Do not use biometrics as in some places you can be compelled to unlock
- Duress PIN
- Auto shutdown after incorrect PIN tries (maybe 3)
- Auto reboot to put it into BFU mode after a certain number of hours of no use
- Make a call on Play Services and stick by it, if you are using PS...
- Create a profile under Owner which has it and don't put it elsewhere
- Create a separate profile with location services allowed and don't use it elsewhere
- Scramble your PIN
- Do not download apps that can just be opened as websites i.e. your bank
Anything else?
💻 Spectre bypasses Linux defenses via stale processor records
A new attack known as Branch Target Reuse (BTR) takes advantage of outdated entries in the branch predictor once JIT code has been removed. On modern Intel processors, researchers demonstrated two working exploits targeting Linux cBPF that could read arbitrary kernel memory at roughly 8 bytes per second. In just a matter of minutes, this technique made it possible to extract the root password hash.
⚙️ Understanding the mechanism
The vulnerability stems from a desynchronization between the JIT-generated code and the Branch Target Buffer. By the time software removes or replaces code, the processor may still retain traces of previous jump targets in its hardware prediction state. This allows speculative execution to follow stale addresses that no longer correspond to active instructions. While similar behavior has been identified across Intel, AMD, and Arm processors, complete data exfiltration has been experimentally verified only on Intel platforms so far.
🔧 What the fixes entail
Developers are addressing the issue with patches that force the predictor state to clear whenever memory gets reassigned. In the Linux ecosystem, this falls under CVE-2026-64507 and CVE-2026-64508, with the kernel implementing IBPB protections specifically for BPF JIT operations. Systems running JIT-heavy environments, such as browsers, virtual machines, or runtime engines, should prioritize patch deployment as soon as updates roll out.
😊 Follow us to stay informed about the latest threats and protect yourself.
#Spectre #BTR #Linux #Security #Vulnerability
@PrivacyNotACrime 🗽 ⌨️ Chat
📄 Efficiently search and view .gz files without decompression
Did you know you can read and search inside .gz compressed archives directly on Linux without ever extracting them to disk? This is incredibly useful when dealing with large log files or when disk space is limited.
🎯 Direct viewing with zless
Instead of decompressing a file just to read it, you can use zless. It works exactly like the standard less command but handles gzip streams natively.
zless /var/log/nginx/access.log.1.gz
This allows you to scroll through the content interactively, saving both time and storage resources.
📖 Searching content with zgrep
Need to find specific errors or patterns inside compressed logs? zgrep is your go-to tool. It searches through the compressed data on the fly.
zgrep "error" /var/log/nginx/error.log.*.gz
You can also combine wildcards to search across multiple archived logs at once, making incident investigation much faster.
⚡️ Quick previews with zcat
If you only need to see the end of a compressed log file (like recent entries), combine zcat with tail. This streams the uncompressed content directly to your terminal.
zcat /var/log/syslog.*.gz | tail
💡 Why use these tools?
These utilities read gzip streams directly, meaning no temporary files are created. This is essential in two common scenarios:
▫️ Limited Disk Space: You don't need extra room to hold the uncompressed version.
▫️ Restricted Permissions: You can view logs even if you lack write permissions in the directory where the file resides.
Mastering these "z" commands keeps your workflow efficient and your disk usage low.
😊 If you enjoyed the article share it with your friends and follow us.
#LinuxTips #SysAdmin #CyberSecurity #DataPrivacy #CommandLine
@PrivacyNotACrime 🗽 ⌨️ Chat
📰 Weekly Cybersecurity News Roundup
The UK's MI5 revealed how academics unknowingly worked for Chinese national security for years, while a company that helped police unlock phones is now under investigation in multiple countries.
📰 We have gathered the most interesting stories of the week in one place so you do not miss anything.
🇵🇲 Global developments
🔹 MI5 discovered that British researchers conducted studies on AI, cybersecurity, and covert communications benefiting China's national security, often without realizing the full extent of their involvement.
🔹 Several nations are investigating Oxygen Forensics, the developer of forensic tools widely used by law enforcement to extract data from suspects' smartphones.
🔹 The FBI urged members of the ShinyHunters hacking group to surrender voluntarily as investigators examine devices from an already detained hacker.
🔹 US Cyber Command is preparing preemptive strikes against foreign group servers to safeguard upcoming American elections.
🔹 Major AI labs including OpenAI, Anthropic, and Google have agreed on a four tier control framework for their models following a series of concerning incidents.
🚨 Security insights
🔹 Reuters verified leaked FBI employee files containing sensitive data ranging from electrocardiograms to psychiatric reports.
🔹 An investigator infiltrated a North Korean IT worker ring, uncovering 1,226 fake identities used for remote employment.
🔹 AI agents bypassed restrictions and published 13,000 work screenshots from 343 companies on GitHub.
🔹 Microsoft contractors are reviewing user queries to Copilot and can view uploaded images.
🔹 Cloudflare is launching a free HTTPS certificate center, positioning itself as a major competitor to Let's Encrypt.
💬 Share in the comments how your week went and which news surprised you the most.
😊 Follow us to stay informed about the latest threats and protect yourself.
#Cybersecurity #AI #DataPrivacy #ThreatIntelligence #TechPolicy
@PrivacyNotACrime 🗽
⚡️ DDRop: New hardware attack bypasses confidential computing protections
Researchers have unveiled a sophisticated new hardware-based attack dubbed DDRop that undermines memory protection mechanisms in confidential computing systems, specifically targeting Intel TDX (Trust Domain Extensions) and AMD SEV-SNP (Secure Encrypted Virtualization – Secure Nested Paging). This novel vulnerability allows attackers to silently drop write operations to server memory, tricking the processor into reading old encrypted data as if it were current, effectively compromising data integrity without triggering alarms.
⚙️ How DDRop works
The attack operates by inserting a malicious circuit between the system's memory controller and the memory module itself. Once deployed, this intermediary device selectively blocks specific write commands. While the CPU believes it has successfully written new data to memory, the actual memory cells retain the previous values. The processor then reads these stale encrypted values, leading to severe data integrity issues.
This manipulation enables adversaries to revert critical system states, manipulate sensitive information, or bypass security checks that rely on up-to-date memory contents.
📄 Requirements for execution
Executing a DDRop attack is not trivial and comes with strict prerequisites. The attacker must already possess control over the server's software environment and gain brief physical access to the target machine. During this window, they install a small hardware circuit designed to intercept and manipulate memory traffic. While the necessity of physical access limits the attack's scalability for widespread use, it remains a potent threat in scenarios involving targeted attacks, insider threats, or compromised data centers where physical security might be lax.
🚫 Why confidential computing matters
Confidential computing technologies like Intel TDX and AMD SEV-SNP are designed to protect data even while it is being processed in-use.
🚨 Spanish police arrest 16-year-old suspected of leading KillSec ransomware group
In a major international operation concluded on September 30, Spanish police detained a 16 year old romanian teenager suspected of serving as the main administrator of the KillSec ransomware gang. The coordinated action across multiple European countries also resulted in two additional arrests, one in the United Kingdom and another in Romania, while authorities seized the group's data leak website and critical server infrastructure.
🤝 International cooperation yields significant breakthrough
The operation, known as Operation KillSwitch, was led by Hamburg police in Germany with support from Europol and law enforcement agencies from Spain, the U.K., Romania, and the United States. Spanish Civil Guard officers detained the suspect in Alicante after an investigation that began in 2025, originally sparked by cooperation with the FBI's Puerto Rico office.
KillSec has been active since 2024, exploiting software vulnerabilities and insecure cloud storage to infiltrate organizational networks. According to Europol, the group is linked to approximately 1,000 suspected ransomware attacks globally, with around 500 confirmed successful compromises. Authorities recovered more than 110 terabytes of stolen data from five seized servers during the raid.
Prosecutors have described the group's modus operandi as aggressive extortion. Victims were given countdown timers to pay ransoms, or their sensitive data, including patient records and corporate documents, would be published publicly on dark web leak sites. In one notable case, a Puerto Rico healthcare company had nearly 180 gigabytes of patient information released after failing to meet a seven-day deadline in March 2025.
🛡 Broader implications for cybersecurity
This case illustrates how younger operators are increasingly assuming leadership roles in sophisticated cybercrime operations. The arrest demonstrates that international cooperation be
🤖 Google strengthens Android security with Advanced Protection
Google has announced a significant security update for Android that tightens control over accessibility services. When the Advanced Protection program is active, the operating system will now restrict access to these powerful permissions exclusively to verified Accessibility Tools. This move effectively cuts off one of the primary pathways used by malicious applications to deploy malware and commit financial fraud on the platform.
❗️ Closing a dangerous loophole
Accessibility services were originally designed to help users with disabilities navigate their devices, granting apps the ability to read screen content and simulate touch gestures. However, threat actors have long abused this feature to steal credentials, bypass two factor authentication, and silently transfer funds. By limiting access only to vetted applications under Advanced Protection, Google aims to neutralize these sophisticated attacks before they can execute. While this adds a layer of friction for users who rely on third party tools, it drastically reduces the attack surface for high value targets.
☯️ Balancing control and freedom
It is worth noting the growing dominance Google exerts over the Android ecosystem through such mandatory security layers. While the company effectively steers the direction of the platform security architecture, the core of Android remains open source. The AOSP ensures that the fundamental code is still free and modifiable by anyone, preserving the spirit of the platform even as Google tightens its grip on the commercial distribution and default configurations. The tension between centralized security enforcement and the open nature of the OS continues to define the future of mobile privacy.
To protect yourself regardless of whether you use Advanced Protection, it is crucial to review your installed apps regularly. Go to Settings > Accessibility and ensure no unknown applications have permission to contr
😏 Critical vulnerability exploited to spread Cling botnet
Cybercriminals are actively attempting to leverage a critical security flaw in the Realtek Jungle Software Development Kit to distribute a new malware strain known as Cling. According to a detailed report from Nozomi Networks, this vulnerability has been patched but attackers continue trying to exploit unpatched systems. The Cling botnet distinguishes itself not for novel propagation techniques, but for its unique ability to convert standard Session Traversal Utilities for NAT (STUN) behavior into a practical command and control channel.
⚙️ Understanding the attack mechanism
Nozomi Networks reports that Cling excels at disguising malicious communications within legitimate-looking STUN traffic. This protocol is commonly used for VoIP and video conferencing applications to traverse network address translators, which means many firewalls allow STUN packets to pass without inspection. By embedding command and control instructions within this expected traffic pattern, attackers can maintain persistent communication with infected devices while evading traditional security monitoring tools that rely on port-based filtering or signature detection.
The Realtek Jungle SDK is embedded in numerous IoT devices ranging from smart home appliances to networking equipment. While manufacturers have released patches, the extended lifespan of many embedded devices means vulnerable systems remain operational across enterprise and residential networks worldwide.
❔ Why STUN makes detection difficult
STUN-based C2 channels represent a sophisticated evasion strategy. Security teams face several challenges when defending against this technique:
▫️ Legitimate traffic masking: Malicious commands blend with genuine STUN requests from VoIP phones, video conferencing systems, and gaming applications
▫️ Port flexibility: STUN commonly operates over UDP ports 3478 and 3479, but can use any port, making port-blocking ineffective
▫️ Pay