TGViewer
Channel Public Channel
Privacy Not A Crime

Privacy Not A Crime

@privacynotacrime

πŸ” Take control of your digital freedom.

Curated tools and expert insights on Privacy, Cybersecurity and OSINT. Actionable guides to protect your data and communications.

Defend your rights online. πŸ”°
Subscribers
671
Photos
191
Videos
19
Links
231
Recent Posts 19 shown
Post #522 21

Forwarded from ANY.RUN

❗️ Active now: Attackers are mimicking AI tools like Claude, DeepSeek, and ChatGPT to deliver stealers and RATs through fake download pages, malicious installers, ClickFix commands, and even real shared chats that tell users to paste a command.

Full attack chains, behavior data, and IOCs for detection are available in #ANYRUN Sandbox πŸ‘‡
πŸ”Ή Claude Lure + ClickFix
πŸ”Ή Claude Lure + Infostealer
πŸ”Ή DeepSeek Lure + ValleyRAT
πŸ”Ή ChatGPT Lure + Fake Cloudflare CAPTCHA

⚑️ See how ANY.RUN helps SOC teams detect & investigate complex threats faster
#ExploreWithANYRUN
  • πŸ‘€ 5
Post #521 128

Forwarded from Proton

Bring back CRT!
  • πŸ‘€ 4
  • 😁 2
  • 🀣 2
Post #519 154

Forwarded from cKure

β– β– β– β– β–‘ UAE Ministry of Interior Data Breach πŸ‡¦πŸ‡ͺ

A threat actor S-Root claims to have obtained 4 TB of data allegedly linked to the UAE Ministry of Interior after β€œ10 days” of access to its servers.

Claimed data includes:
β€’ Emirates ID & passport records
β€’ Resident & visitor information
β€’ Fingerprints & biometric data
β€’ Driving/vehicle license records
β€’ Traffic violations & penalty points
β€’ Issued driving certificates

πŸ’° Claimed sale price: $3,000
πŸ” Access price: $8,000

⚠️ The breach and authenticity of the dataset have not been independently verified. Claims involving highly sensitive identity and biometric information should be treated as unverified until confirmed by the relevant authorities or credible independent sources.
  • πŸ‘Œ 5
  • 😈 1
Post #518 171
🦠 Finding vulnerable subdomains using Censys

Censys is like Shodan and Google Dorks, but powered up. We already talked about it in detail in the article How to Use Censys. Today, we will analyze it from the perspective of searching for vulnerabilities in subdomains.

The best way to find subdomains using search engines is to use filters called dorks that are better understood by the Internet itself. We cannot simply tell Google find all Microsoft subdomains please. We need to speak computer language, not human language.

Bug Bounty is a reward program that a website owner conducts to attract external information security specialists to find vulnerabilities. When participating in Bug Bounty, one must act ethically and follow established rules.

πŸ’» Search for Microsoft subdomains

Let us try to find Microsoft subdomains. Go to Censys Search and copy and paste the following query into the search bar.

(services.tls.certificates.leaf_data.names: microsoft.com) and services.http.response.status_code=200


After execution, a list of working subdomains of the site will appear. The results show active domains that respond with HTTP status code 200, meaning they are live and accessible.

⚑️ Enable virtual hosts filter

For a better result, click on the settings icon next to the search panel and select the Virtual Hosts option. This setting expands your search beyond just the primary domain. Now, with Virtual Hosts enabled, you can see all subdomains available to Microsoft services and possibly find attack vectors.

The Virtual Hosts feature is particularly valuable because many organizations host multiple services on the same IP address. By enabling this option, Censys reveals which subdomains share infrastructure and what services they expose publicly.

πŸ”˜ Real bug bounty example

In one scenario from a HackerOne report, a bug hunter discovered an interesting subdomain with registration enabled for internal users this way. Then, after registration, the hacker was able to access personal data through Broken Access Control and ended up receiving a decent bounty.

This case demonstrates why thorough subdomain enumeration matters. Many organizations forget to secure internal-facing endpoints, leaving them exposed to anyone who knows how to query the right databases.

πŸ”² Additional tips for effective searching

Combine multiple filters to narrow down your results. You can search for specific technologies, open ports, or certificate information. The more precise your query, the better the chances of finding overlooked assets.

Regular monitoring of your own infrastructure through these tools helps identify what attackers might see. What looks secure internally may appear quite different to the outside world.

😊 If you enjoyed the article share it with your friends and follow us.

#Censys #Vulnerability #Search #OSINT #Pentesting

@PrivacyNotACrime πŸ—½ ⌨️ Chat
  • πŸ‘Œ 5
Post #517 143

Forwarded from Proton

πŸ‘€ πŸ‘€ πŸ‘€
  • πŸ‘Œ 3
  • πŸ₯° 1
Post #516 160

Forwarded from ANY.RUN

⚠️ Malware pressure increased across the threat landscape last week, with RATs, stealers, and loaders all gaining activity at the same time. AsyncRAT climbed 35%, while Quasar, DonutLoader, and Lumma saw even sharper growth.

πŸ“Œ Trend to watch: broad growth across established threats can increase investigation pressure across multiple threat types at once. SOC teams may need to rebalance detection and triage priorities as volumes rise.

πŸ‘‰ Monitor the malware driving today’s attacks

#Top10Malware
  • πŸ‘Œ 2
Post #515 193
πŸ“° Weekly Cybersecurity News Roundup

AI agents breached the Australian Ministry of Health website, stealing data from 600,000 bank cards within hours, prompting OpenAI and Anthropic to seek UN intervention to contain these technologies. Meanwhile, a routing error triggered a global internet disruption affecting over 100 countries, and banks worldwide face challenges with customer call identification.

πŸ“° We have compiled the most interesting news of the week in one place so you don't miss anything.

🌎 Global AI and infrastructure alerts

πŸ”Ή OpenAI and Anthropic are developing increasingly powerful AI systems and are now requesting UN oversight: following a series of concerning incidents involving autonomous agents, the issue has reached the Security Council.

πŸ”Ή An Iranian operator began advertising third-party IP addresses as their own, triggering a global routing disruption that impacted more than 100 countries.

πŸ”Ή OpenAI's AI agents hacked the Australian Ministry of Health website, with the alarm only raised three months after the incident occurred.

πŸ”Ή In a database stolen from the FBI, employees of a secret unit known as ROU were identified, a group dedicated to hacking third-party devices.

πŸ”Ή Approximately $351.6 million was withdrawn from the cryptocurrency exchange Bitget, with thieves rapidly transferring stolen tokens to Ethereum.

🌟 Security landscape shifts

πŸ”Ή AI agents stole data from 600,000 bank cards with minimal human intervention, completing the entire hack in just a few hours.

πŸ”Ή AI analyzed a MikroTik patch within an hour and discovered a method to access systems without a password; attacks began before router owners could apply updates.

πŸ”Ή Hackers barely touched vulnerabilities that an Anthropic neural network found in massive quantities; it proved much easier to identify the flaw than to weaponize it into a full attack.

πŸ”Ή Palo Alto Networks is launching Claude and GPT instances to continuously attempt hacking corporate systems, including applications, APIs, clouds, and repositories.

πŸ”Ή Attackers were hacked by rival attackers: the group ShinyHunters took control of their competitors' Clop website.

πŸ—£ Share in the comments how your week went and which news surprised you the most.

😊 Follow us to stay informed about the latest threats and protect yourself.

#CyberSecurity #AINews #DataBreach #InfoSec #Privacy

@PrivacyNotACrime πŸ—½ ⌨️ Chat
  • ✍ 9
  • πŸ‘€ 6
  • πŸ‘Œ 3
  • 🀬 1
Post #514 197

Forwarded from Proton

New concern just dropped.
  • 🀬 3
  • 🀣 2
  • 😁 1
  • πŸ’© 1
Post #513 386
πŸ“° Disinformation as a service: BlackCore sells influence campaigns

Public opinion has officially gone up for sale. Researchers from Citizen Lab have uncovered the activities of Israeli company BlackCore, which has moved disinformation from intelligence services' toolkit into conventional B2B services. Now any paying client can access a full information warfare cycle: from creating hundreds of convincing fake profiles to artificially suppressing unwanted narratives, complete with detailed efficiency reports.

πŸ“’ How the disinformation factory works

The fake campaign management process is structured like a classic advertising agency. Instead of crudely selling inactive accounts, BlackCore implements complete infrastructure. Neural networks generate avatar faces for social media, writers craft coordinated messages, and algorithms artificially boost posts. This system lets clients quickly simulate mass support or destroy a competitor's reputation by flooding the space with aggressive noise.

Operations follow professional standards including target audience analysis, multi-platform deployment, engagement metrics tracking, and polished final deliverables presented as corporate reports. It is information manipulation packaged like any other enterprise service.

❔ Why this matters for everyone

The main risk lies in increasing accessibility of these methods on the open market. When tools for suppressing opinions and dominating agendas sell as corporate subscriptions, it becomes nearly impossible to distinguish genuine social movements from paid digital illusions.

The implications extend far beyond corporate competition. Political campaigns, public health messaging, and social justice efforts can all be drowned out by manufactured consensus funded by undisclosed actors.

πŸ”— Check more information about this at Citizen Lab

😊 Follow us to stay informed about the latest threats and protect yourself.

#Disinformation #CyberSecurity #InformationWarfare #DigitalPrivacy #StateSponsored

@PrivacyNotACrime πŸ—½ ⌨️ Chat
  • πŸ€” 7
  • πŸ‘Œ 6
  • πŸ‘€ 6
  • 🀬 4
  • 🀣 4
Post #512 391
⚠️ I scanned an iPhone for Pegasus and it came back with one critical alert. The tool is called the Mobile Verification Toolkit, or MVT. It’s free and open source and was built by Amnesty International’s Security Lab. All you need to do is make an encrypted backup of your phone on a computer, point MVT at it, and it checks your messages, browsing history, apps and data usage against known traces and fingerprints of Pegasus, Predator, stalkerware and other surveillance tools. It works for iPhone and Android, and it runs on a Mac or on Windows.

🐱 Check the tool at GitHub

😊 If you enjoyed the article share it with your friends and follow us.

#Pegasus #Paragon #Spyware #iPhone #Android

@PrivacyNotACrime πŸ—½ ⌨️ Chat
  • ✍ 7
Post #511 194

Forwarded from Proton

This tickled me.
  • 🀣 12
  • ✍ 2
Post #509 272
πŸ›  Complete list of tools for malware analysis, from collection to investigation

Awesome-Malware-Analysis brings together a carefully selected set of resources for working with malicious code in one organized place. From sample collection and threat intelligence to detection, classification, online sandboxes, file extraction, deobfuscation, debugging, reverse engineering, network analysis and memory forensics you will find what you need without jumping between scattered sources.

πŸ“„ Investigation phases as the organizing principle

What makes this repository particularly useful is that it follows the actual workflow of an investigation rather than alphabetical order. When responding to an incident you simply open the corresponding phase section and immediately see which tools apply to your current task. This saves valuable time during critical moments and helps analysts quickly understand what capability they need for each step of their work.

It works especially well when you encounter a new malware family and need to figure out which tool fits each stage of the analysis. The curated nature means less noise and more focused options that have proven their worth in real world DFIR scenarios.

🐱 Check it for free at GitHub

😊 If you enjoyed the article share it with your friends and follow us.

#MalwareAnalysis #DFIR #ThreatHunting #CyberSecurity #ReverseEngineering

@PrivacyNotACrime πŸ—½ ⌨️ Chat
  • ✍ 3
Post #508 404
πŸ“° Weekly Cybersecurity News Roundup

The cloud turned out to be too grounded, while weapons were entirely space-bound: following drone attacks, Amazon acknowledged an irreversible loss of access to parts of AWS, and the United States officially confirmed the presence of orbital weapons for the first time. AI agents now take just 26 seconds to target 11 organizations, and police can read Signal and WhatsApp messages without breaking encryption by turning a device into a trusted endpoint.

πŸ“° We've gathered the most interesting news of the week in one place so you don't miss a thing.

🌎 Global developments

πŸ”Ή Amazon admitted to an irreversible loss of access to portions of its AWS cloud infrastructure following drone attacks, revealing that even redundancy across availability zones couldn't prevent this scenario. This incident shows how physical attacks can still compromise supposedly resilient cloud systems.

πŸ”Ή The United States officially confirmed for the first time that Space Force is operating weapon systems in orbit. This represents a significant shift in military doctrine and space security dynamics.

πŸ”Ή Xi Jinping proposed that BRICS nations jointly develop open-source AI models and a shared artificial intelligence ecosystem. This could reshape global AI development and reduce dependence on Western tech.

πŸ”Ή Huawei challenges Nvidia: China is preparing new Ascend AI chips and supercomputing clusters with one million processors to offset technological limitations through sheer scale. This marks a major push for technological self-sufficiency.

πŸ”Ή The European Union is drafting the EU KIDS Act, which would ban infinite scrolling for children, disable AI companions for minors, and require social networks to adapt interfaces based on age. This legislation aims to protect young users from addictive design patterns.

πŸ” Cybersecurity landscape

πŸ”Ή AI agents attacked 11 organizations in just 26 seconds, demonstrating how GreyNoise visualizes mass cyberattacks where attackers operate without pauses. Attack speed has increased dramatically with automation.

πŸ”Ή Law enforcement has learned to read correspondence on Signal, Telegram, and WhatsApp without breaking encryption by converting a suspect's computer into a trusted device. The weakness here is endpoint security, not the encryption itself.

πŸ”Ή North Korea has turned IT professional hiring into a form of human leasing: the employer sees one person, documents belong to another, and the work is performed by a third party via VPN. This allows talent export while maintaining state control.

πŸ”Ή Approximately 1.5 billion Android devices have lost security updates and will no longer receive patches. These devices remain vulnerable to known exploits indefinitely.

πŸ”Ή The FBI boarded two foreign vessels in the Gulf of Mexico due to signs of a cyberattack and conducted investigations directly at sea. This demonstrates how cyber incidents can spill over into physical jurisdiction spaces.

πŸ—£ Share in the comments how your week went and which news surprised you the most.

#CyberSecurity #AIAttacks #CloudSecurity #PrivacyFirst #TechNews

@PrivacyNotACrime πŸ—½ ⌨️ Chat
  • ✍ 3
  • πŸ€” 3
  • 🀩 3
  • πŸ‘€ 3
Post #507 310
πŸ”₯ Palantir: Automated decision-making in war.
  • 🀯 5
  • πŸ‘€ 2
Post #506 375
🍏 Absolute negative record for Apple

September 14 marked a historic moment for Apple security as the company released its largest vulnerability patch ever. More than 260 unique CVEs were addressed across virtually the entire ecosystem, with macOS alone receiving over 200 individual fixes. The update included iOS 27 and iPadOS 27, alongside iOS 26.7 and iPadOS 26.7 for devices that had not yet migrated to the major version.

πŸ“† What happened this week

The sheer number of flaws makes this Apple's most intensive security cleanup in history. Every major product line required attention, from the operating system kernel to core application frameworks. Many of these vulnerabilities could allow arbitrary code execution or security bypasses, making immediate updating essential for all users.

❔ Why this matters

This situation exposes a structural weakness of closed-source software. When code remains hidden from public scrutiny, vulnerabilities tend to accumulate until internal reviews finally uncover them. The 260 plus flaws disclosed here are probably just the beginning, as thousands more likely remain buried in the codebase waiting to be discovered either by attackers or by future security researchers who eventually gain access to the source.

😊 Follow us to stay informed about the latest threats and protect yourself.

#AppleSecurity #ZeroDay #ClosedSource #CyberRisk #TechNews

@PrivacyNotACrime πŸ—½ ⌨️ Chat
  • 🀯 8
  • πŸ‘Œ 4
Post #505 488
😊 WhatsApp flaw exposes photos on locked Android phones during video calls

Security researchers have confirmed a vulnerability in WhatsApp for Android that allows access to private photos even when the device is locked. Discovered by Jose Rodriguez (@VBarraquito) and already reported to Meta and Google, the flaw has been addressed with a fix currently rolling out, though availability varies by region and device.

The vulnerability does not allow remote attacks from anywhere on the internet. Instead, it requires physical access to the locked phone. Once an attacker has the device in hand, an incoming video call triggers an interface that inadvertently opens the photo gallery through the app's filters and effects menu.

🦠 How the exploit works

When a locked Android device receives a WhatsApp video call, swiping to answer activates the video feed. Tapping the effects icon reveals tabs for filters and backgrounds. From there, selecting "Create with Meta AI" followed by "Edit photo" pulls up the entire device gallery, bypassing the standard lock screen protections.

Importantly, the bypass only grants viewing access to photos, not editing or sharing capabilities. Still, an attacker could photograph the screen with a second device.

😊 Follow us to stay informed about the latest threats and protect yourself.

#WhatsApp #AndroidSecurity #PrivacyAlert #Stalkerware #Cybersecurity

@PrivacyNotACrime πŸ—½ ⌨️ Chat
  • πŸ‘Œ 4
  • 🀬 2
Post #504 355
😽 Malicious telegram bots: How to avoid becoming a victim and protect your account

The scenario is simple yet cunning. Users are persuaded under various pretexts from security verification checks to anonymous chats and dating services to launch a Telegram bot. At first glance nothing seems suspicious with a standard screen a Start button and a typical interface. However a single click activates a hidden mechanism that can compromise your entire account.

πŸ’Έ The hidden trap behind innocent buttons

Once activated the victim unknowingly becomes an administrator or owner of an external channel completely controlled by attackers. This fact later turns into a powerful blackmail tool as the attacker can threaten to expose the user's involvement in illicit activities hosted on that channel. The scam relies on social engineering where attackers craft convincing messages mimicking legitimate services.

According to recent reports from security researchers criminals are moving increasingly toward Telegram because its design allows users to create highly anonymous accounts making it easier for fraudsters to operate without immediately revealing their real identities.

βš”οΈ How the attack unfolds step by step

Bots can act like instant operators greeting victims collecting details and pushing them into scripted funnels that feel legitimate because responses arrive immediately and consistently. This is especially effective in fake support situations where bots mimic help desks and guide users toward verification, recovery or account safety steps that end in payment requests or credential capture. Some scam channels present bots as payment coordinators or dispute handlers creating the illusion of a trusted marketplace while actually centralizing control in the hands of the scammer.

🀝 Essential protection measures for your account

Telegram gives users a lot of control over their security but many important protections are turned off by default or buried inside privacy menus. Enable two-step verification to add a critical layer of defense. Lock down your login by reviewing which bots and third-party apps have access to your account regularly. Never grant administrative rights to channels you do not personally manage or trust implicitly. Be skeptical of unsolicited messages offering free services verification or exclusive access. Remember that naturally any bot should be treated as a stranger according to Telegram official guidelines.

❗ Practical steps if you suspect compromise

If you notice unusual activity immediately revoke the bot access via Telegram settings under Privacy and Security. Report any suspicious behavior to Telegram through their dedicated anti-scammer channel @notoscam where this activity can be flagged for investigation. Run a full antivirus scan on your device using tools like Malwarebytes to check for potential infostealers or malware that may have been installed. Change your password from a separate trusted device to prevent further unauthorized access.

😊 If you enjoyed the article share it with your friends and follow us.

#TelegramSecurity #BotScam #CyberSafety #ProtectYourAccount #DigitalPrivacy

@PrivacyNotACrime πŸ—½ ⌨️ Chat
  • πŸ‘Œ 4
Older posts β†’

About this channel

How can I read @privacynotacrime without a Telegram account?
TGViewer shows the public web preview Telegram publishes for Privacy Not A Crime: recent posts, photos, videos and the subscriber count, with no app, login or account.
How many subscribers does Privacy Not A Crime have?
Privacy Not A Crime (@privacynotacrime) has 671 subscribers on Telegram, refreshed roughly every 30 minutes.
Does Privacy Not A Crime know I viewed it here?
No. Public channel previews carry no viewer identity, and TGViewer has no accounts or tracking of what you look up.
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook β†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 β†’