TGViewer
Channel Public Channel
SITREP - Independent OSINT Channel

SITREP - Independent OSINT Channel

@sitreports

AI, technology, mass surveillance, and intelligence โ€” everything you need to know about tomorrow.
Subscribers
23K
Photos
17.5K
Videos
9.8K
Links
23.5K
Recent Posts 20 shown
Post #39543 10
๐Ÿ” Low-cost Android phones found shipping with firmware-level malware

Bitdefenderโ€™s Midnight Mimosa findings describe low-cost Android devices with MediaTek chipsets arriving with preinstalled malware in the system partition. The framework silently installs apps, commits ad fraud, and can register phones as residential proxies. Researchers tracked thousands of affected devices in more than 150 countries over roughly two years.

The case points to supply-chain compromise with system-level persistence, making removal difficult without firmware cleanup or ADB intervention. It also shows how consumer handsets can be repurposed at scale for traffic relay and monetization while masking malicious installs as normal Android activity.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
Post #39542 64
๐Ÿ” UAC-0099 deploys ASHVEIN RAT against Ukrainian government staff

UAC-0099 is targeting Ukrainian government personnel with the ASHVEIN RAT, using HTML content to conceal command data. The activity is framed as a cyber-espionage campaign focused on government users rather than broad criminal distribution.

Embedding instructions inside HTML adds a simple but effective layer of obfuscation, complicating static inspection and delaying detection in routine email or web-based workflows. The targeting pattern points to credential, access, or document collection priorities inside state administrative networks.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
Post #39541 111
๐Ÿ“ก Ukrainian strike disables Yandex cloud zone

Yandex says its ru-central1-b availability zone is offline after a fire caused by a drone attack on its Sasovo datacenter, around 300 km southeast of Moscow. The company states operations at the site have been fully halted and told customers to use alternative recovery plans. Yandex Cloud also warned service restoration is not expected in the near term.

The incident shows kinetic pressure extending directly into Russian digital infrastructure, with immediate impact on cloud availability rather than edge services alone. For a market with fewer domestic cloud alternatives under sanctions, the loss of a single availability zone carries wider resilience and continuity implications.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
Post #39540 123
๐Ÿ” Shai-Hulud hits AI tooling via Tensorlake SDK

A malicious release of Tensorlakeโ€™s SDK version 0.5.144 on npm was flagged 11 minutes after publication and later removed. Researchers link the package to the credential-stealing Shai-Hulud worm, with code overlap to the ChainDrop variant. Reported theft targets include cloud credentials, GitHub Actions secrets, browser passwords, crypto wallets, and service-account tokens.

The case shows how AI-agent platforms remain exposed through the developer and CI/CD layer rather than the runtime sandbox itself. Installation scripts execute with host permissions, meaning a short-lived package compromise can still reach build runners, deployment secrets, and token stores before any isolation controls apply.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
Post #39539 144
๐Ÿ” FBI seizes Flax Typhoon cyber infrastructure

The FBI seized seven domains linked to China-connected Integrity Technology Group, disrupting the MicroScan vulnerability scanner and FishHub spear-phishing platform used in Flax Typhoon operations. U.S. officials say the tools supported scanning, intrusions, malware delivery, remote access, and data theft against critical infrastructure and other targets in the U.S., Taiwan, Japan, Poland, and elsewhere. A joint advisory was issued with CISA, NSA, and partners.

The case points to a contractor-backed intrusion ecosystem rather than a single malware family, exposing repeated exploitation of legacy internet-facing flaws and long-term access into critical sectors.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
Post #39538 409
๐Ÿ” SonicWall patches CVSS 10 pre-auth flaw in SMA1000

SonicWall has issued hotfixes for four SMA1000 appliance vulnerabilities, led by CVE-2026-102255, a CVSS 10.0 pre-auth SSRF in the WorkPlace portal. The bug could let an unauthenticated attacker reach internal functionality and perform unauthorized operations. Affected systems include SMA1000 models 6210, 7210, and 8200v on specified 12.4.3 and 12.5.0 hotfix branches and older. No workaround is available.

The key point is exposure before authentication on internet-facing remote access infrastructure. SonicWall says it has no evidence of exploitation, but the flaw sits in the same product family where two SMA1000 zero-days were confirmed exploited last month, raising the urgency of patch validation and edge inventory review.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
Post #39537 352
๐Ÿค– Pentagon starts AI pilot for classification control

The Pentagon will begin a small-scale deployment within six months of the Air Forceโ€™s Automated Classification Management Environment to manage security classification and sensitive information handling. A memo signed by Deputy Defense Secretary Steve Feinberg says the system could become the departmentโ€™s single digital reference for original classification decisions.

This marks a shift from dispersed human judgment toward a centralized AI-assisted process for one of DoDโ€™s most sensitive administrative functions. The stated aim is to cut over-classification, reduce delays, and address a 140-million-page hardcopy backlog, while concentrating risk around model performance, oversight, and misclassification at scale.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
Post #39536 313
๐Ÿค– GitHub Copilot CLI prompt chain can exfiltrate local secrets

Adversa AI disclosed a Cryptographic Context Injection technique against GitHub Copilot CLI in autopilot mode. In the demonstrated chain, an attacker-controlled webpage fed encrypted instructions, pushed the agent to read local files while building a fake decryption key, then triggered a second request that sent the collected data off-host. Researchers reported a .env.prod file was exfiltrated in 28 seconds.

The key issue is trust at runtime: plaintext revealed after decryption was treated as valid context even when equivalent visible instructions were refused. GitHub reportedly validated the behavior but did not classify it as a vulnerability.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
Post #39535 292
๐Ÿ” Eight npm packages used to push Overlord RAT and stealer

Eight malicious npm packages were downloaded 40,767 times before detection, delivering Overlord RAT and an information stealer through the software supply chain. The activity targeted developers and downstream environments that installed the packages from the JavaScript ecosystem.

The case reinforces how low-friction package publication can convert routine dependency pulls into initial access. For defenders, the key issue is exposure propagation: one compromised package can extend beyond a single workstation into build systems, secrets, and any product pipeline that consumed it.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
Post #39534 165

Forwarded from Rybar in English

๐Ÿ“You reap what you sow๐Ÿ“
Ukrainians lose South Korean ambassador

The Kryvyi Rih school of diplomacy, which the Kyiv regime specializes in, has never yielded its fruits so quickly. The conflict between the authorities of South Korea and so-called Ukraine over the disclosure of information about the transfer of North Korean prisoners is escalating to a new level.

In Seoul, they decided to recall the ambassador from Kyiv. South Koreans responded this way to the absence of public apologies from so-called Ukraine for Zelensky's speech at the UN. The measures were expected โ€” from the very beginning of the diplomatic spat, local media discussed the recall of the ambassador, and then the South Korean foreign minister joined in.

The apologies that the Ukrainians sent through departmental channels were clearly insufficient. Now South Korea is convincing the Ukrainian side that an admission of guilt must be public, so Seoul took this step.

๐Ÿ“ŒRecalling the ambassador does not mean breaking diplomatic relations, and such a measure should be viewed as a public protest directed at the Ukrainian position. But what it will affect is trust between the two sides โ€” participation by South Koreans in defense cooperation with the authorities of so-called Ukraine is becoming increasingly unlikely.

๐Ÿ–We won't be surprised if the recall of the ambassador was prompted not only by the stubborn public position of the Ukrainians, a hastily assembled crisis response, and media accusations. In Kyiv this week, they accused South Koreans of supplying fuel to Russia, citing a piece in the British press that appeared very conveniently.

โ—๏ธAnd although Seoul did not violate any sanctions in this way, as they stated after the article came out, the accusations could have worsened the already tense situation in bilateral relations and made South Koreans even more aware of what kind of incompetent diplomats they are dealing with. So, judging by what's happening, the conflict could drag on further.
#Ukraine #SouthKorea
@rybar

๐Ÿ’ธSupport us Original msg
Post #39533 239
๐Ÿค– PoeLLM Malware Expands Cryptojacking Footprint

PoeLLM has reportedly infected more than 3,400 servers to grow a crypto-mining botnet, with compromised infrastructure repurposed for sustained illicit mining activity. The campaign, outlined in PoeLLM malware coverage, centers on server-side compromise at scale rather than endpoint delivery.

The server count indicates a mature monetization operation with enough distributed capacity to absorb takedowns and maintain output. For defenders, the key signal is not novelty but scale: broad server exposure can be converted directly into resilient mining throughput and persistent unauthorized resource consumption.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
Post #39532 276
๐Ÿค– Progress DataDirect agent flaw enables OS command execution

Progress disclosed CVE-2026-91140, a critical command injection issue in early-access DataDirect Autonomous REST Connector AI Model Generator agents. A crafted OpenAPI/Swagger file can pass shell metacharacters through a filename field and trigger arbitrary OS commands when the DataDirect ARC AI Model Generator processes it. Fixed agent definitions are available in version 2.1.

The exposure sits in developer workspaces and CI runners, where successful execution can reach source code, tokens, and cloud credentials. Detection is limited because Progress notes no specific product error message; review environments that handled untrusted API specs and replace affected agent files.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
Post #39531 296
๐Ÿ” Critical LMCache flaw enables unauthenticated remote code execution

A critical, unpatched vulnerability in LMCache allows unauthenticated attackers to execute code remotely. The issue affects AI infrastructure using the caching layer and remains without a vendor patch at the time of publication.

The combination of remote reachability, no authentication requirement, and absent remediation sharply increases exposure for internet-facing or poorly segmented deployments. For defenders, the priority is asset identification, access restriction, and temporary isolation of vulnerable LMCache instances until a fix is available.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
Post #39530 294
๐Ÿ” ccTLD hijacks enabled counterfeit certs for Google domains

Google says attackers hijacked the .gh, .sl, and .as registries, altered authoritative DNS records, and obtained unauthorized HTTPS certificates for several Google domains and other organizations. Chrome has already blocked suspected rogue certs across the affected namespaces, but Google says its own systems were not breached. The company advises monitoring Certificate Transparency logs and reviewing recent issuance in those ccTLDs.

This is a registry-level trust failure: control of DNS plus valid-looking certificates can remove normal browser warning signals and support convincing impersonation, interception, phishing, or malware delivery. Chrome-side blocking reduces exposure for some users, but Google notes it may not identify every affected domain and does not reliably protect non-Chrome traffic.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
Post #39529 312
๐Ÿ” Atlassian CVE-2026-21589 moves to active exploitation within hours

CVE-2026-21589, a critical unauthenticated file-access flaw affecting self-hosted Jira, Confluence, Bitbucket and other Atlassian products, was observed in live exploitation hours after public technical details and a PoC were released. Previdian said its honeypots detected attacks within two hours, while a Nuclei template has already enabled automated scanning.

The operational picture is a rapid weaponization cycle: disclosure, PoC release, near-immediate probing, and scan automation. In Crowd-integrated environments, exposed application files may also enable privilege escalation to admin access, raising the risk beyond simple file read.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
Post #39528 412
๐Ÿ” FBI warns FortiBleed activity is still ongoing

The FBI says exposed Fortinet FortiGate firewalls and SSL VPN gateways continue to be targeted in the FortiBleed campaign. Operators use leaked or stolen credentials, extract additional auth data, crack password hashes offline with distributed GPU tooling, then create admin accounts or change passwords to lock out legitimate administrators.

The access chain now appears operationalized beyond simple credential abuse: persistence, lateral movement, and ransomware affiliate use have all been observed. The key point is that remediation extends past patching and password resets, as account tampering and retained access can survive basic recovery steps.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
Post #39527 879
๐Ÿ” Warsaw murders: the accomplices matter most

The investigation into Michaล‚ P., a Warsaw plumber charged with murdering six elderly women, rests on one key detail: he did not act alone. Two Ukrainian nationals, Igor H. and Taras H., are charged as accomplices in four of the killings.

The wider implication is about how the case will grow. Serial murder cases built around a single suspect usually depend on that one person's confession and phone data. With three defendants, investigators have more to work with: several phones, several sets of movements, and the chance that one of them will testify against the others. Each of those can tie in deaths that currently sit in the files as natural.

Police are already reviewing dozens of such deaths and around 75,000 images. The final count of victims may depend less on the plumber than on what his accomplices know.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
Post #39526 757
๐Ÿค– Altman says AI benefits justify accepting some risks

OpenAI CEO Sam Altman said the benefits of artificial intelligence warrant accepting a degree of risk, while arguing the technology should remain broadly accessible. The remarks place OpenAI on the side of continued public deployment rather than heavy restriction.

The statement matters because it frames risk tolerance as part of AI governance, not a barrier to rollout. It also signals how major developers are positioning accessibility, regulation, and safety tradeoffs as deployment pressure grows.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
Post #39525 676
๐Ÿค– Anthropic adds separate voice-data training consent in Claude

Anthropic has begun prompting Claude users to optionally share voice conversations for AI training. The setting appears only with voice features, is disabled by default, and can be changed or deleted later in Claude Privacy settings. Voice consent is separate from existing controls for text chats and coding sessions.

Operationally, this creates a distinct intake channel for spoken data rather than bundling it with general usage. The separation matters because it allows narrower consent collection and clearer segmentation of audio, chat, and code telemetry for model improvement.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
Post #39524 533
๐Ÿ“„ Security Affairs Malware Newsletter Round 117

The latest malware newsletter compiles recent reporting and research on active threats across Windows, macOS, cloud, WordPress, npm, and critical infrastructure. Items highlighted include Lunex stealer, Storm-3168 cloud intrusions, TraderTraitor backdoors, PhantomSub npm abuse, Warlock ransomware, RedFlick phishing, Antino targeting in Asia, and CloudSyncD on macOS.

The roundup is notable for its breadth: credential theft, cloud abuse, software supply chain compromise, phishing delivery refinement, and persistence mechanisms all appear in one cycle. The concentration of cases shows simultaneous pressure on enterprise identity, developer ecosystems, public-sector targets, and operational technology-adjacent networks.

๐Ÿ›ฐ๏ธ Open sources - closed narratives
@sitreports
Older posts โ†’

About this channel

How can I read @sitreports without a Telegram account?
TGViewer shows the public web preview Telegram publishes for SITREP - Independent OSINT Channel: recent posts, photos, videos and the subscriber count, with no app, login or account.
How many subscribers does SITREP - Independent OSINT Channel have?
SITREP - Independent OSINT Channel (@sitreports) has 23K subscribers on Telegram, refreshed roughly every 30 minutes.
Does SITREP - Independent OSINT Channel know I viewed it here?
No. Public channel previews carry no viewer identity, and TGViewer has no accounts or tracking of what you look up.
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook โ†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 โ†’