es
Feedback

¡No caigas en manos de tramposos! Telemetrio encuentra y marca estos canales 👉 Si quieres ver la etiqueta, suscríbete 👈

SITREP - Independent OSINT Channel

SITREP - Independent OSINT Channel

Ir al canal en Telegram

AI, technology, mass surveillance, and intelligence — everything you need to know about tomorrow.

Mostrar más

📈 Análisis del canal de Telegram SITREP - Independent OSINT Channel

El canal SITREP - Independent OSINT Channel (@sitreports) en el segmento lingüístico de Inglés es un actor destacado. Actualmente la comunidad reúne a 22 987 suscriptores, ocupando la posición 5 647 en la categoría Tecnologías y Aplicaciones y el puesto 1 711 en la región EEUU.

📊 Métricas de audiencia y dinámica

Desde su creación el невідомо, el proyecto ha mostrado un crecimiento acelerado, reuniendo a 22 987 suscriptores.

Según los últimos datos del 09 octubre, 2026, el canal mantiene una actividad estable. En los últimos 30 días la variación de miembros fue de -51, y en las últimas 24 horas de 0, conservando un alto alcance.

  • Estado de verificación: No verificado
  • Tasa de interacción (ER): El promedio de interacción de la audiencia es 2.01%. Durante las primeras 24 horas tras publicar, el contenido suele obtener 1.48% de reacciones respecto al total de suscriptores.
  • Alcance de las publicaciones: Cada publicación recibe en promedio 461 visualizaciones. En el primer día suele acumular 341 visualizaciones.
  • Reacciones e interacción: La audiencia responde de forma activa: el promedio de reacciones por publicación es 0.
  • Intereses temáticos: El contenido se centra en temas clave como narrative, attack, infrastructure, threat, credential.

📝 Descripción y política de contenido

El autor describe el recurso como un espacio para expresar opiniones subjetivas:
“AI, technology, mass surveillance, and intelligence — everything you need to know about tomorrow.”

Gracias a la alta frecuencia de actualizaciones (últimos datos recibidos el 10 octubre, 2026), el canal mantiene la vigencia y un amplio alcance. La analítica demuestra que la audiencia interactúa activamente con el contenido, lo que lo convierte en un punto de referencia dentro de la categoría Tecnologías y Aplicaciones.

22 987
Suscriptores
Sin datos24 horas
-17 días
-5130 días
Archivo de publicaciones
🔍 Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks Threat actors are reportedly using Google search
🔍 Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks Threat actors are reportedly using Google search ads and legitimate Bing redirects to steer users toward fake Claude installers that deliver ClickFix malware. The method blends paid placement with trusted redirect infrastructure to mask the final destination. Operationally, the case highlights how legitimate ad ecosystems and redirect chains can be repurposed for initial access. For defenders, it reinforces the value of inspecting ad-driven traffic paths, installer provenance, and user exposure to spoofed AI-branded software. 🛰️ Open sources - closed narratives @sitreports

🔍 Credential-stealing workflows seeded across GitHub repos Malicious GitHub Actions workflows designed to steal credentials
🔍 Credential-stealing workflows seeded across GitHub repos Malicious GitHub Actions workflows designed to steal credentials were reportedly planted in tens of thousands of repositories, creating a broad CI/CD supply-chain exposure inside developer environments. The activity abused repository automation, turning trusted build pipelines into collection points for secrets and tokens, as outlined in GitHub Actions workflows. The significance is scale and access. Compromised workflows can harvest credentials during routine builds, giving attackers a path into codebases, package publishing, and downstream infrastructure without touching endpoint malware. 🛰️ Open sources - closed narratives @sitreports

🔍 Working exploit released for pre-auth AnyDesk Linux root flaw Researchers have published a working exploit for a pre-auth
🔍 Working exploit released for pre-auth AnyDesk Linux root flaw Researchers have published a working exploit for a pre-auth vulnerability in AnyDesk for Linux that can grant root access. The issue affects remote access software in a default high-privilege context, meaning an unauthenticated attacker can move from network reachability to full system compromise via AnyDesk for Linux. The combination of pre-auth reachability, public exploit code, and root-level impact sharply reduces defender reaction time. Systems exposing AnyDesk on Linux now face a direct remote takeover path, making patch status, service exposure, and access controls immediate priorities. 🛰️ Open sources - closed narratives @sitreports

🔍 SonicWall SMA1000 flaw moves from patch to active exploitation SonicWall SMA1000 appliances are now seeing exploitation at
🔍 SonicWall SMA1000 flaw moves from patch to active exploitation SonicWall SMA1000 appliances are now seeing exploitation attempts against CVE-2026-102255, a maximum-severity issue patched three days earlier. The flaw affects the WorkPlace interface on SMA1000 6210, 7210, and 8200v, and can let a remote unauthenticated attacker force the appliance to issue internal requests and perform unauthorized operations. The activity reportedly targeted the WorkPlace Extraweb path to reach internal CouchDB on 127.0.0.1:5984. With more than 400 SMA1000 devices exposed online and the platform already tied to repeated zero-day abuse in 2026, the window between disclosure, patching, and operational exploitation remains extremely short. 🛰️ Open sources - closed narratives @sitreports

🔍 Flax Typhoon activity linked to five exploited flaws before CISA deadline CISA has added five vulnerabilities tied to Flax
🔍 Flax Typhoon activity linked to five exploited flaws before CISA deadline CISA has added five vulnerabilities tied to Flax Typhoon activity to its Known Exploited Vulnerabilities catalog, setting an October 11 remediation deadline for U.S. federal civilian agencies under BOD 22-01. The update places the China-linked intrusion set and the affected flaws into the federal patching queue through the Known Exploited Vulnerabilities catalog. The move elevates these bugs from routine patching to active operational risk. Inclusion in KEV indicates confirmed exploitation, while the short compliance window signals urgent concern for exposed federal networks and prioritizes immediate asset identification, patching, and mitigation. 🛰️ Open sources - closed narratives @sitreports

🔍 Nvidia patches high-severity DCGM Exporter flaw Researchers identified roughly 2,100 internet-exposed GPU servers running
🔍 Nvidia patches high-severity DCGM Exporter flaw Researchers identified roughly 2,100 internet-exposed GPU servers running Nvidia DCGM Exporter, with hundreds potentially vulnerable to CVE-2026-47483. The bug can let unauthenticated attackers trigger memory exhaustion and crash the GPU monitoring service. Nvidia fixed the issue in version 4.8.2. The exposure is operationally significant because DCGM telemetry reveals GPU UUIDs, utilization, memory use, power data, and error events in plaintext over HTTP. That creates both a disruption path against AI infrastructure and a reconnaissance layer for mapping high-value GPU environments. 🛰️ Open sources - closed narratives @sitreports

🔍 FBI details China-linked email access portal The FBI says China-linked hackers operated a web portal that allowed third pa
🔍 FBI details China-linked email access portal The FBI says China-linked hackers operated a web portal that allowed third parties to search and retrieve stolen emails from compromised inboxes. The setup effectively turned harvested correspondence into a shared service, broadening access beyond the initial intrusion team, as outlined in the FBI findings. Operationally, this indicates a structured exploitation pipeline rather than isolated mailbox theft. A portal model shortens the path from compromise to intelligence use, increases the value of each breach, and suggests centralized management of exfiltrated data across multiple users or customer sets. 🛰️ Open sources - closed narratives @sitreports

📡 Ransomware disrupts Japan’s IDCF Cloud IDC Frontier says a ransomware attack hit its IDCF Cloud platform on 7 October, for
📡 Ransomware disrupts Japan’s IDCF Cloud IDC Frontier says a ransomware attack hit its IDCF Cloud platform on 7 October, forcing shutdown of network and systems in East Japan Region 1. The company says 495 firms and local governments are affected. Customer console access has been disabled across all regions during security checks, while the intrusion route and full scope remain under investigation. This is a cloud infrastructure incident with direct downstream impact on public-sector and enterprise tenants. Isolation of one region and precautionary restrictions platform-wide indicate concern over lateral spread inside shared management layers, not just disruption at a single customer environment. 🛰️ Open sources - closed narratives @sitreports

🔍 FakeGit reactivates at scale on GitHub FakeGit has resumed activity with 17,610 malicious GitHub repositories distributing
🔍 FakeGit reactivates at scale on GitHub FakeGit has resumed activity with 17,610 malicious GitHub repositories distributing SmartLoader, with over 13,000 repos pushed in 34 hours and a peak of 2,999 per hour. Researchers found 97% of sampled commits only modified README files, and 88% redirected download buttons to ZIP archives installing SmartLoader. At least 700 accounts appear tied to legitimate developers. FakeGit has been active in similar form since January. The campaign’s persistence comes from reuse, not rebuild: existing repos are simply re-pointed to fresh payload locations, while copies remain in forks, release assets, issue attachments, and separate hosting repos. This makes file-by-file takedowns and URL-based blocking structurally weak. 🛰️ Open sources - closed narratives @sitreports

🔍 Cisco flags five critical NX-OS flaws on Nexus switches Cisco has issued advisories for five critical vulnerabilities in N
🔍 Cisco flags five critical NX-OS flaws on Nexus switches Cisco has issued advisories for five critical vulnerabilities in NX-OS affecting Nexus 3000 and 9000 switches in standalone mode. The flaws impact NX-API, NGOAM, and MPLS OAM and can allow arbitrary code execution with root privileges or force device reloads. Exploitation depends on the affected features being enabled; Nexus 7000 and Nexus 9000 systems in ACI mode are not affected. Cisco recommends patching and disabling unused services in its NX-OS advisories. Operationally, this is a control-plane risk for data center switching fabric rather than a generic edge-device issue. Feature exposure matters: NX-API and MPLS OAM are off by default, while NGOAM-linked attack paths depend on specific network services being active. 🛰️ Open sources - closed narratives @sitreports

🔍 Low-cost Android phones found shipping with firmware-level malware Bitdefender’s Midnight Mimosa findings describe low-cos
🔍 Low-cost Android phones found shipping with firmware-level malware Bitdefender’s Midnight Mimosa findings describe low-cost Android devices with MediaTek chipsets arriving with preinstalled malware in the system partition. The framework silently installs apps, commits ad fraud, and can register phones as residential proxies. Researchers tracked thousands of affected devices in more than 150 countries over roughly two years. The case points to supply-chain compromise with system-level persistence, making removal difficult without firmware cleanup or ADB intervention. It also shows how consumer handsets can be repurposed at scale for traffic relay and monetization while masking malicious installs as normal Android activity. 🛰️ Open sources - closed narratives @sitreports

🔍 UAC-0099 deploys ASHVEIN RAT against Ukrainian government staff UAC-0099 is targeting Ukrainian government personnel with
🔍 UAC-0099 deploys ASHVEIN RAT against Ukrainian government staff UAC-0099 is targeting Ukrainian government personnel with the ASHVEIN RAT, using HTML content to conceal command data. The activity is framed as a cyber-espionage campaign focused on government users rather than broad criminal distribution. Embedding instructions inside HTML adds a simple but effective layer of obfuscation, complicating static inspection and delaying detection in routine email or web-based workflows. The targeting pattern points to credential, access, or document collection priorities inside state administrative networks. 🛰️ Open sources - closed narratives @sitreports

📡 Ukrainian strike disables Yandex cloud zone Yandex says its ru-central1-b availability zone is offline after a fire caused
📡 Ukrainian strike disables Yandex cloud zone Yandex says its ru-central1-b availability zone is offline after a fire caused by a drone attack on its Sasovo datacenter, around 300 km southeast of Moscow. The company states operations at the site have been fully halted and told customers to use alternative recovery plans. Yandex Cloud also warned service restoration is not expected in the near term. The incident shows kinetic pressure extending directly into Russian digital infrastructure, with immediate impact on cloud availability rather than edge services alone. For a market with fewer domestic cloud alternatives under sanctions, the loss of a single availability zone carries wider resilience and continuity implications. 🛰️ Open sources - closed narratives @sitreports

🔍 Shai-Hulud hits AI tooling via Tensorlake SDK A malicious release of Tensorlake’s SDK version 0.5.144 on npm was flagged 1
🔍 Shai-Hulud hits AI tooling via Tensorlake SDK A malicious release of Tensorlake’s SDK version 0.5.144 on npm was flagged 11 minutes after publication and later removed. Researchers link the package to the credential-stealing Shai-Hulud worm, with code overlap to the ChainDrop variant. Reported theft targets include cloud credentials, GitHub Actions secrets, browser passwords, crypto wallets, and service-account tokens. The case shows how AI-agent platforms remain exposed through the developer and CI/CD layer rather than the runtime sandbox itself. Installation scripts execute with host permissions, meaning a short-lived package compromise can still reach build runners, deployment secrets, and token stores before any isolation controls apply. 🛰️ Open sources - closed narratives @sitreports

🔍 FBI seizes Flax Typhoon cyber infrastructure The FBI seized seven domains linked to China-connected Integrity Technology G
🔍 FBI seizes Flax Typhoon cyber infrastructure The FBI seized seven domains linked to China-connected Integrity Technology Group, disrupting the MicroScan vulnerability scanner and FishHub spear-phishing platform used in Flax Typhoon operations. U.S. officials say the tools supported scanning, intrusions, malware delivery, remote access, and data theft against critical infrastructure and other targets in the U.S., Taiwan, Japan, Poland, and elsewhere. A joint advisory was issued with CISA, NSA, and partners. The case points to a contractor-backed intrusion ecosystem rather than a single malware family, exposing repeated exploitation of legacy internet-facing flaws and long-term access into critical sectors. 🛰️ Open sources - closed narratives @sitreports

🔍 SonicWall patches CVSS 10 pre-auth flaw in SMA1000 SonicWall has issued hotfixes for four SMA1000 appliance vulnerabilitie
🔍 SonicWall patches CVSS 10 pre-auth flaw in SMA1000 SonicWall has issued hotfixes for four SMA1000 appliance vulnerabilities, led by CVE-2026-102255, a CVSS 10.0 pre-auth SSRF in the WorkPlace portal. The bug could let an unauthenticated attacker reach internal functionality and perform unauthorized operations. Affected systems include SMA1000 models 6210, 7210, and 8200v on specified 12.4.3 and 12.5.0 hotfix branches and older. No workaround is available. The key point is exposure before authentication on internet-facing remote access infrastructure. SonicWall says it has no evidence of exploitation, but the flaw sits in the same product family where two SMA1000 zero-days were confirmed exploited last month, raising the urgency of patch validation and edge inventory review. 🛰️ Open sources - closed narratives @sitreports

🤖 Pentagon starts AI pilot for classification control The Pentagon will begin a small-scale deployment within six months of
🤖 Pentagon starts AI pilot for classification control The Pentagon will begin a small-scale deployment within six months of the Air Force’s Automated Classification Management Environment to manage security classification and sensitive information handling. A memo signed by Deputy Defense Secretary Steve Feinberg says the system could become the department’s single digital reference for original classification decisions. This marks a shift from dispersed human judgment toward a centralized AI-assisted process for one of DoD’s most sensitive administrative functions. The stated aim is to cut over-classification, reduce delays, and address a 140-million-page hardcopy backlog, while concentrating risk around model performance, oversight, and misclassification at scale. 🛰️ Open sources - closed narratives @sitreports

🤖 GitHub Copilot CLI prompt chain can exfiltrate local secrets Adversa AI disclosed a Cryptographic Context Injection techni
🤖 GitHub Copilot CLI prompt chain can exfiltrate local secrets Adversa AI disclosed a Cryptographic Context Injection technique against GitHub Copilot CLI in autopilot mode. In the demonstrated chain, an attacker-controlled webpage fed encrypted instructions, pushed the agent to read local files while building a fake decryption key, then triggered a second request that sent the collected data off-host. Researchers reported a .env.prod file was exfiltrated in 28 seconds. The key issue is trust at runtime: plaintext revealed after decryption was treated as valid context even when equivalent visible instructions were refused. GitHub reportedly validated the behavior but did not classify it as a vulnerability. 🛰️ Open sources - closed narratives @sitreports

🔍 Eight npm packages used to push Overlord RAT and stealer Eight malicious npm packages were downloaded 40,767 times before
🔍 Eight npm packages used to push Overlord RAT and stealer Eight malicious npm packages were downloaded 40,767 times before detection, delivering Overlord RAT and an information stealer through the software supply chain. The activity targeted developers and downstream environments that installed the packages from the JavaScript ecosystem. The case reinforces how low-friction package publication can convert routine dependency pulls into initial access. For defenders, the key issue is exposure propagation: one compromised package can extend beyond a single workstation into build systems, secrets, and any product pipeline that consumed it. 🛰️ Open sources - closed narratives @sitreports

Repost from Rybar in English
📝You reap what you sow📝 Ukrainians lose South Korean ambassador The Kryvyi Rih school of diplomacy, which the Kyiv regime s
📝You reap what you sow📝 Ukrainians lose South Korean ambassador The Kryvyi Rih school of diplomacy, which the Kyiv regime specializes in, has never yielded its fruits so quickly. The conflict between the authorities of South Korea and so-called Ukraine over the disclosure of information about the transfer of North Korean prisoners is escalating to a new level. In Seoul, they decided to recall the ambassador from Kyiv. South Koreans responded this way to the absence of public apologies from so-called Ukraine for Zelensky's speech at the UN. The measures were expected — from the very beginning of the diplomatic spat, local media discussed the recall of the ambassador, and then the South Korean foreign minister joined in. The apologies that the Ukrainians sent through departmental channels were clearly insufficient. Now South Korea is convincing the Ukrainian side that an admission of guilt must be public, so Seoul took this step. 📌Recalling the ambassador does not mean breaking diplomatic relations, and such a measure should be viewed as a public protest directed at the Ukrainian position. But what it will affect is trust between the two sides — participation by South Koreans in defense cooperation with the authorities of so-called Ukraine is becoming increasingly unlikely. 🖍We won't be surprised if the recall of the ambassador was prompted not only by the stubborn public position of the Ukrainians, a hastily assembled crisis response, and media accusations. In Kyiv this week, they accused South Koreans of supplying fuel to Russia, citing a piece in the British press that appeared very conveniently. ❗️And although Seoul did not violate any sanctions in this way, as they stated after the article came out, the accusations could have worsened the already tense situation in bilateral relations and made South Koreans even more aware of what kind of incompetent diplomats they are dealing with. So, judging by what's happening, the conflict could drag on further. #Ukraine #SouthKorea @rybar 💸Support us Original msg