TGViewer
Channel Public Channel
CyberOps

CyberOps

@operations_cyber

Subscribers
21
Photos
23
Videos
0
Links
34
Recent Posts 20 shown
Post #170 26
Знаешь про водяные знаки на ИИ-картинках? Google вшивает в свои изображения невидимый сигнал SynthID - логотипа не видно, но специальный детектор потом скажет «это сгенерировал ИИ». Штука вроде надёжная.

А теперь представь: берёшь картинку от Google, слегка обрабатываешь через обычный Stable Diffusion 1.5, грузишь в Gemini и спрашиваешь «это ИИ?». Ответ - спокойное «нет».

Наткнулся на работу MARKNULL, где знак стирают в 100% случаев, а требования к атакующему до неприличия скромные. Разбираю три шага, которые всё это ломают.

Полный разбор

@operations_cyber
Post #169 24
You know how Google's AI images carry an invisible watermark called SynthID? It's meant to prove "yes, this was made by AI." I found a trick that quietly wipes it out - using nothing more than Stable Diffusion 1.5.

The method, called MARKNULL, drops watermark detection to 53% accuracy - basically a coin flip - while keeping the image looking cleaner than any other attack. Curious how it fools even Gemini itself?

Full Article

@operations_cyber
Post #167 27
Пентест - это когда ты играешь за хакера с разрешения владельца, чтобы проверить, реально ли что-то сломать. Раньше ИИ-агенты умели решать учебные задачки, а тут случился сдвиг: в новом бенчмарке агент на базе GPT-5.5 запустил готовый эксплойт из Metasploit - и тот не сработал. Тогда он сам написал новый с нуля и взял хост.

А по ходу дела нашёл настоящий 0-day в ComfyUI - движке для генеративного AI с 115K звёзд на GitHub. Разбираем, что теперь умеют агенты.

Полный разбор

@operations_cyber
Post #166 25
You know how AI agents used to just solve staged hacking puzzles (CTF challenges)? Summer 2026 changed that - now they're doing real pentester work: writing exploits from scratch and even hunting for unknown bugs in massive open-source projects.

One agent found a fresh 0-day in software with 115K stars on GitHub. And GPT-5.5 with Codex is leading the pack, cracking real web targets even with almost zero hints.

Curious how far they've actually come?

Full Article

@operations_cyber
Post #165 29
Представь: у тебя в сумке лежит AirTag, чтобы найти её, если потеряешь. Логично же? А теперь представь, что этой же меткой воспользуется вор - заставит трекер пищать по команде и на слух найдёт твою сумку среди сотен других в вагоне метро.

Apple добавила в Find My функцию против слежки: любой может заставить чужой «потерянный» AirTag звенеть. Благородно. Исследователи из HKUST развернули эту защиту против владельца. И собрали всю атаку на обычном Android - без айфона, без дорогого радиооборудования. Разбираем, как Snatcher превращает твою защиту в наводку для похитителя.

Полный разбор

@operations_cyber
Post #164 24
You know those little AirTags people toss in bags to track their stuff? They rely on Apple's Find My network to phone home. Turns out that same system can be turned against you. I found research showing how a regular Android phone can spot a nearby AirTag, then make it play a sound on command - no authentication needed - to pinpoint which bag it's hiding in on a packed subway.

The culprit? Three structural flaws in Find My: an open beacon broadcast in cleartext, unauthenticated sound triggers, and a MAC address that barely rotates. A stalker's dream, built right in.

Full Article

@operations_cyber
Post #163 22
Все хотят повесить рост шифровальщиков на ИИ - удобно, модно, продаётся. А исследователи говорят другое: экосистема просто фрагментировалась. Крупные картели поразвалились, на их месте расплодилась куча мелких групп, порог входа упал, и все дружно пошли туда, где защиты нет - в небольшие конторы, которые никто и не думал прикрывать.

Никакого волшебного AI-оружия, обычная рыночная логика. Спрос есть, барьеры низкие, жертвы беззащитны - вот и весь секрет ускорения.
Dark Reading Ransomware Is Accelerating, but It's Not Because of AI Researchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended organizations.
Post #162 21
Everyone wants to pin the rise of ransomware on AI — it's convenient, trendy, and it sells. But researchers say otherwise: the ecosystem simply fragmented. The big cartels fell apart, and in their place a bunch of small groups sprouted up, the barrier to entry dropped, and everyone flocked to where there's no defense — small shops that nobody ever thought to protect.

No magic AI weapon, just plain market logic. There's demand, the barriers are low, the victims are defenseless — that's the whole secret behind the acceleration.
Dark Reading Ransomware Is Accelerating, but It's Not Because of AI Researchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended organizations.
Post #161 27
Представь: под столом в переговорке приклеен кусочек пластины размером с ноготь. Без батарейки, без проводов, к твоей клавиатуре вообще никак не подключён. А в соседней комнате, за бетонной стеной, сидит приёмник и читает всё, что ты печатаешь - пароли, сообщения, запросы.

Атаку назвали RadKey. Самое неприятное в ней - ей не нужны образцы твоих нажатий. Ноль. Обычные акустические атаки без этого разваливаются, а тут 15 см бетона и высокая точность. Как - разбираем внутри, там и физика тега, и языковая модель.

Полный разбор

@operations_cyber
Post #160 27
You know how keyloggers usually need software on your machine or a device plugged into your keyboard? Forget all that. Imagine a tiny sticker, an inch wide, glued under your desk. No battery, no wires, no link to your keyboard at all. And someone in the next room reads every key you press - passwords, messages, searches.

The wild part? It works through a 15 cm concrete wall, with no direct radio path. The signal just detours through the concrete. They even published the attack code.

Full Article

@operations_cyber
Post #159 29
87 из 109 бюллетеней безопасности Qubes за все годы — это не про баги самого Qubes, а про Xen, микроархитектуру процессоров и прочий upstream. Такой вывод даёт лонгитюдный разбор 109 QSB с 2011 по 2025 год: почти 80% проблем прилетают из компонентов, которые команда Qubes не пишет, а только вынуждена изолировать.

И в этом, кстати, вся суть их архитектуры - границы между виртуалками сделаны так, что дыра в Xen становится дырой в модели безопасности целиком. Автор ещё покопался в трендах: главный перелом в частоте адвизори случился в 2015Q1, а после 2018-го поток раскрытий вышел на плато и статистически держится ровно. S-образные модели предсказания уязвимостей на коротком горизонте, к слову, ничем не обошли банальное скользящее среднее.

Хороший пример того, что качественная изоляция не убирает зависимость от чужого кода - она просто честно её показывает в публичном логе.
arXiv.org Qubes OS Security in the Public Record Qubes OS is a revealing case for security measurement because its architecture makes component boundaries security-relevant. We present a protocol-driven longitudinal analysis of 109 public Qubes...
Post #158 26
87 out of 109 Qubes security bulletins across all the years aren't about bugs in Qubes itself, but about Xen, CPU microarchitecture, and other upstream stuff. That's the conclusion of a longitudinal analysis of 109 QSBs from 2011 to 2025: nearly 80% of the issues come from components that the Qubes team doesn't write, but is merely forced to isolate.

And that, by the way, is the whole essence of their architecture — the boundaries between VMs are built so that a hole in Xen becomes a hole in the entire security model. The author also dug into the trends: the main turning point in advisory frequency happened in 2015Q1, and after 2018 the disclosure flow plateaued and has been statistically holding steady. S-shaped vulnerability prediction models over a short horizon, by the way, didn't beat a plain old moving average in any way.

A good example of how solid isolation doesn't remove the dependency on someone else's code — it just honestly reveals it in a public log.
arXiv.org Qubes OS Security in the Public Record Qubes OS is a revealing case for security measurement because its architecture makes component boundaries security-relevant. We present a protocol-driven longitudinal analysis of 109 public Qubes...
Post #157 30
Ты в рабочем чате Signal, договариваетесь о встрече. Все видят «15:00, третий этаж». Все, кроме тебя - тебе приходит другое время и другая комната. А коллегу Кэрол из ветки будто вырезали, она не увидела ничего. И никакого предупреждения ни от клиента, ни от сервера.

Сквозное шифрование прячет содержимое от сервера, но есть свойство поскромнее - согласованность транскрипта: все участники группы должны в итоге видеть одну и ту же переписку. Оказалось, ни один из четырёх главных мессенджеров этого не гарантирует.

Исследователи собрали рабочие клиенты и провернули атаку на живых WhatsApp, Signal, iMessage и Threema. Жертва сидит в обычном приложении из App Store - и видит то, что ей подсунули. Разбираем, как это устроено и почему все четыре оказались уязвимы.

Полный разбор

@operations_cyber
Post #156 28
You trust that everyone in your group chat sees the same messages, right? Turns out that assumption can break. I found research showing how someone can send different people different versions of the same message - one colleague gets "3 PM, third floor," you get a totally different time and place, and another person gets silently cut out with zero warnings.

I tested this against WhatsApp, Signal, iMessage, and Threema. All four are vulnerable to this group equivocation, and only one resists a nastier variant. Curious which one?

Full Article

@operations_cyber
Post #155 31
MAC-адрес меняется за секунду, IMEI перепрошивается, крипто-ключ генерируется заново. А что если тебя опознают вообще не по этому?

Любое беспроводное устройство - роутер, дрон, наушники - гонит сигнал через усилитель, осциллятор, смеситель. Ни одна деталь не идеальна: на заводе разброс параметров, микроскопическая кривизна характеристик. И каждый передатчик излучает сигнал с уникальным набором искажений. Отпечаток пальца, только у железа.

Метод называется RFF - радиочастотная дактилоскопия. Опознаёт устройство на физическом уровне, где софтом ничего не сотрёшь.

Полный разбор

@operations_cyber
Post #154 29
You can change your MAC address in a second, regenerate crypto keys, even reflash your IMEI. But what if your device could still be tracked - by tiny physical flaws baked into its hardware?

Every transmitter has imperfections: amplifier nonlinearity, frequency offset, oscillator defects. These leave a unique fingerprint in the signal itself, right at the physical layer. It's called RFF, and you cannot fake or reset it like a MAC.

I dug into how this turns your phone into an unavoidable tracking beacon.

Full Article

@operations_cyber
Post #153 30
Cloudflare показала, как построить собственный vulnerability harness — обвязку, которая надёжно воспроизводит уязвимость раз за разом, чтобы не гадать «а точно ли пофиксили».

Разбирают на примере KeyTrap (CVE-2023-50387) — той самой DoS-дыры в DNSSEC, где один специально собранный ответ мог отправить резолвер в бесконечный перемол криптографии и сожрать CPU почти полностью. Штука в том, что без стабильного harness такие баги мучительно тестировать: то воспроизводится, то нет, а патч вроде наложен, но кто его знает.

Хороший материал, если ты хоть раз сидел и тыкал PoC руками, надеясь, что в этот раз сработает. Инженерный подход к тому, что обычно делают на коленке.
Cloudflare Blog Build your own vulnerability harness We break down the technical architecture behind our multi-stage vulnerability discovery harness and automated triage loop. Learn how we manage state controls, squash false positives through adversarial review, and route around LLM context limits.
Post #152 34
Cloudflare showed how to build your own vulnerability harness — a wrapper that reliably reproduces a vulnerability time after time, so you don't have to guess "did they really fix it?"

They break it down using KeyTrap (CVE-2023-50387) as an example — that very DoS hole in DNSSEC where a single specially crafted response could send a resolver into an endless crypto-grinding loop and eat up almost all the CPU. The thing is, without a stable harness such bugs are painful to test: sometimes it reproduces, sometimes it doesn't, and the patch seems applied, but who knows.

Good material if you've ever sat there poking at a PoC by hand, hoping it works this time. An engineering approach to something usually done on the fly.
Cloudflare Blog Build your own vulnerability harness We break down the technical architecture behind our multi-stage vulnerability discovery harness and automated triage loop. Learn how we manage state controls, squash false positives through adversarial review, and route around LLM context limits.
Post #151 50
Атакующему давно не нужен зирудей, чтобы обойти твою автономную защиту. Достаточно прочитать её правила — те самые детекты, пороги и логику реагирования, по которым срабатывает автоматика. И Dark Reading пишет, что доверие к «умным» security-инструментам как раз поэтому и просело: чем предсказуемее твоя система реагирования, тем легче под неё подстроиться и проскользнуть между сработками.

Забавная ирония в том, что мы годами продавали автоматизацию как способ убрать человеческий фактор, а получили другой — жёсткую, задокументированную логику, которую противник изучает как учебник. Живой аналитик хотя бы иногда ведёт себя нестандартно. А rulebook всегда играет по нотам.
Dark Reading Adversaries Don't Need a Zero-Day — They Read Your Rulebook Confidence in autonomous security tools is declining, and here's why.
Older posts →

About this channel

How can I read @operations_cyber without a Telegram account?
TGViewer shows the public web preview Telegram publishes for CyberOps: recent posts, photos, videos and the subscriber count, with no app, login or account.
How many subscribers does CyberOps have?
CyberOps (@operations_cyber) has 21 subscribers on Telegram, refreshed roughly every 30 minutes.
Does CyberOps know I viewed it here?
No. Public channel previews carry no viewer identity, and TGViewer has no accounts or tracking of what you look up.
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →