fa
Feedback
ᴛʜᴇ ɢʜᴏꜱᴛ ɪɴ ᴛʜᴇ ᴍᴀᴄʜɪɴᴇ

ᴛʜᴇ ɢʜᴏꜱᴛ ɪɴ ᴛʜᴇ ᴍᴀᴄʜɪɴᴇ

رفتن به کانال در Telegram

A coalition focused on cyber resistance.

نمایش بیشتر
إسرائيل2 693دسته بندی مشخص نشده است
343
مشترکین
اطلاعاتی وجود ندارد24 ساعت
+37 روز
+2530 روز
آرشیو پست ها
La resistencia y coraje de los cubanos es intolerante para el imperio. ¡CUBA NO SE RINDE!
La resistencia y coraje de los cubanos es intolerante para el imperio. ¡CUBA NO SE RINDE!

Turkiye busts Israel-linked 'Scam Empire' accused of defrauding victims out of $266 million Turkish security forces have dismantled an Israel-linked fraudulent trading network accused of defrauding victims across Europe, Asia, and Africa of at least $266 million over the past two years, Turkish Justice Minister Akin Gurlek said on Friday.

UAE and Saudi Arabia made up nearly half of Gulf cyberattacks in H1 2026. UAE 35%, Iran 17%, Saudi 15%. Top methods: vulnerabilities 38%, malware 31%, social engineering 27%. Government orgs were 27% of successful targets.

Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE.

Amazon says its cloud infrastructure in Bahrain and the UAE is beyond saving after missile strikes. The Gulf is now rebuilding AI data centers with war-proofing: underground sites, missile interceptors, dispersal, hardened power. The cloud is no longer just IT. It’s a target.

Google hires Israeli chip team to develop AI chip Google has formed a team in Israel, led by former Hailo CEO Guy Kaminitz and including a former Nvidia manager, to build on-device AI chips for robots and autonomous systems. #TGITM

¡Viva Cuba Socialista! ¡Abajo el bloqueo yanqui!

There is one more vector that many people forget. Telegram voice calls default to a peer-to-peer connection for better quality and reduced latency. To establish this, the app uses the STUN protocol, which reveals your device's public IP address to the person you are calling. Researcher Denis Simonov, known as n0a, demonstrated this by adding a target to contacts, initiating a call, and extracting the IP address using Wireshark to detect STUN traffic. The fix is simple but almost nobody does it. Go to Settings → Privacy and Security → Calls → Peer-to-Peer and change it to "Never." This routes all calls through Telegram's relay servers, masking your IP. The Phone Number Problem Telegram's primary identifier is your phone number. Even with a perfect VPN, if you registered with your real number, you are identifiable. Telegram's updated policy explicitly permits disclosure of your phone number to authorities in valid legal cases. The mitigation is a burner number. Services allow you to verify a Telegram account without giving up your primary number. You should also go to Settings → Privacy and Security → Phone Number and set "Who can see my phone number" to Nobody. A burner number is not perfect. But it is a critical layer. Operational Checklist: What to Do Today For all users: Never click on unknown proxy links. Even if they look like a standard Telegram username or a t.me URL. This is the primary vector for the one-click leak. Disable peer-to-peer calls. Settings → Privacy and Security → Calls → Peer-to-Peer → Never. Use a burner number to register. Do not tie your real identity to your Telegram account. Understand that Secret Chats are the only end-to-end encrypted conversations on Telegram. Cloud chats are not. You must opt in to use them. For Android users: Your "Block connections without VPN" setting is not enough. The Tiny UDP Cannon bug bypasses it. You need a second layer. Use Rethink DNS + Firewall. Its "Isolate" mode allows you to restrict Telegram to connect only to specific, necessary IP addresses, blocking it from pinging unknown proxy servers. The developer of Rethink DNS has confirmed using Isolate mode to restrict Telegram to a small number of static IPs. Apply the ADB mitigation for the QUIC leak: adb shell device_config put tethering close_quic_connection -1 adb reboot This disables the QUIC graceful shutdown feature and closes the leak. The mitigation persists across reboots but may be undone by system updates, in which case you repeat the steps. Consider GrapheneOS. If you are on a Pixel device, GrapheneOS has already patched the Android 16 VPN bypass bug that Google refuses to fix. It is the most robust mobile privacy option available today. For iOS users: Enable Lockdown Mode immediately. Settings → Privacy & Security → Lockdown Mode. This is the single most effective defense against the proxy leak on iOS. It blocks the background connections that Telegram uses to test proxy links. Update to the latest iOS version. Understand that iOS has no system-wide kill switch. Your VPN is one layer, not a guarantee. Conclusion The vulnerability landscape is clear. Telegram's one-click proxy leak affects both platforms. Android's Tiny UDP Cannon bypasses the kill switch Google built to protect you. iOS has Lockdown Mode as a defense, but no system-level kill switch. And Telegram's policy now permits disclosure of your IP and phone number under valid legal requests. No single tool fixes this. You need layers. A VPN. A firewall. Lockdown Mode on iOS. Rethink DNS on Android. A burner number. P2P calls disabled. And the discipline to never click a link you did not expect. The threat model matters. If you are a journalist protecting a source, every layer counts. If you are a casual user, the one-click leak is still a real risk from a malicious contact or a compromised channel. Stay aware. Stay layered. And never assume that "private" means "anonymous." #TGITM

For stock Android users, the mitigation is an ADB command: adb shell device_config put tethering close_quic_connection -1 adb reboot This disables the QUIC graceful shutdown feature and closes the leak. The setting persists across reboots but may be undone by system updates, requiring reapplication. Threat Three: The iOS Reality — Same Flaw, Built-In Defense iOS users are vulnerable to the same one-click proxy leak as Android users. The Telegram iOS client behaves identically: tapping a disguised proxy link triggers an automatic connection attempt from the device's native network stack, bypassing the VPN and logging the real IP. However, iOS provides a built-in countermeasure that Android currently lacks: Lockdown Mode. When enabled, Lockdown Mode applies stricter firewall policies that block apps from initiating unnecessary background TCP connections. More specifically for this vector, Lockdown Mode disables all link preview functionality. The core trigger for the proxy leak is Telegram's automatic attempt to resolve a proxy link to generate a preview. In Lockdown Mode, Telegram cannot silently connect to those links in the background, which breaks the silent IP leak path. Research on exploit kits has demonstrated that some attackers explicitly check for Lockdown Mode and abort if they detect it. To enable it: Settings → Privacy & Security → Lockdown Mode. Apple's support documentation confirms this is available on iOS 16 and later. Critical iOS Limitation: No System-Wide Kill Switch There is no true system-level VPN kill switch on iOS. The "Block connections without VPN" setting that exists on Android does not exist as a full kill switch on iPhones. App-level kill switches only work for selected apps, and standard App Store VPN clients cannot block all traffic outside the tunnel. This means an iOS user relying solely on a VPN has no system-level protection if the tunnel drops momentarily. Lockdown Mode helps fill that gap by restricting background connections, but it is not a complete substitute for a kill switch. This is an architectural limitation of the platform, not a configuration error. The Legal Reality: Telegram's Policy Has Changed Beyond technical vulnerabilities, there is a policy shift that must be understood. In September 2024, Telegram updated its privacy policy. The new language states: "If Telegram receives a valid order from the relevant judicial authorities that confirms you're a suspect in a case involving criminal activities that violate the Telegram Terms of Service, we will perform a legal analysis of the request and may disclose your IP address and phone number to the relevant authorities". Previously, this policy only applied to terror suspects. The scope has been expanded. Pavel Durov, Telegram's CEO, posted publicly: "We've made it clear that the IP addresses and phone numbers of those who violate our rules can be disclosed to relevant authorities in response to valid legal requests". If you are using a VPN, the IP address Telegram has on record is your VPN's IP, not your real one. But this brings us to the weakest link in the chain. The Weak Link: Your VPN Provider A VPN only protects you if it does not know who you are — or will not tell. Many VPN providers keep connection logs. If authorities subpoena the VPN provider, those logs can link your account to the VPN IP address that Telegram provided. Even a "no-logs" VPN can be legally compelled to cooperate. A centralized VPN is a single point of failure. And there is another trail: payment records. If you have ever purchased Telegram Premium using a personal card, that transaction went through a payment processor. Those processors have your full card details and are subject to subpoenas. A payment trail is one of the most reliable ways law enforcement connects an anonymous account to a real identity. The Voice Call Leak: Still Active

The Hidden IP Leak — How Telegram Can Expose Your Real Location on Mobile, and How to Actually Stop It By Yara Tabet This is a technical briefing on a threat that affects every Telegram user on a smartphone — Android and iOS alike. The research is current, the exploits are documented, and the mitigations are actionable. Threat One: The One-Click Proxy Leak In January 2026, security researcher @/0x6rss demonstrated on X a vulnerability in Telegram's mobile clients that allows an attacker to log a user's real IP address with a single click — bypassing all configured proxies, VPNs, and SOCKS5 settings. The mechanism is straightforward. Telegram mobile clients automatically test proxy links before adding them. When a user taps a t.me/proxy?... link, the app initiates a direct TCP connection to the proxy server defined in that link, verifying that it is online. This connection originates from the device's native network stack. It does not pass through the VPN tunnel. It does not respect your proxy configuration. It goes directly out, and the attacker's server logs the source IP address. The attacker disguises the malicious proxy link as a harmless username or a standard t.me URL. Telegram's rich text formatting allows a link that technically points to t.me/proxy?server=attacker_ip to display as something entirely innocuous. You tap once. The proxy test fires silently in the background. Your real IP, your approximate geolocation, and network metadata are captured. This affects both Android and iOS clients. @/0x6rss compared the behavior to NTLM hash leaks on Windows, where a single interaction with a crafted resource triggers an automatic outbound request that betrays the client's identity. Telegram has acknowledged the issue and stated it will add warnings to proxy links in a future update. As of this briefing, the silent auto-test behavior remains present in current builds. Threat Two: The Android 16 VPN Bypass — "Tiny UDP Cannon" For Android users who believe their VPN kill switch provides absolute protection, there is a second vulnerability that demands attention. In May 2026, a security researcher operating as lowlevel/Yusuf disclosed a flaw in Android 16's networking stack dubbed "Tiny UDP Cannon". The bug exploits a method called registerQuicConnectionClosePayload on the ConnectivityManager system service. This method was designed to allow graceful teardowns of QUIC connections by sending a final payload to the server. The implementation does not properly ensure that the payload is sent into the VPN tunnel. The exploit mechanism is technically elegant. A malicious app does not send the packet itself. It hands the bytes and a destination to system_server — UID 1000 — which operates with elevated privileges and is exempt from VPN routing rules. When the app exits or the socket is destroyed, system_server opens a UDP socket on the physical network interface, such as Wi-Fi, and transmits the attacker-controlled payload directly. The VPN never sees it. The destination sees the device's real public IP. The critical fact: this bypass works even with "Always-On VPN" and "Block connections without VPN" both enabled. These are the two settings Android provides to guarantee that no traffic leaves the device outside the VPN tunnel. They do not hold against this attack. Google closed the issue as "Won't Fix (Infeasible)" within six days of the report. Google's public position, as provided to Android Authority, is that the issue only affects devices that have downloaded a malicious app, and that Google Play Protect automatically protects against known malicious apps. That is factually correct as far as it goes. The precondition is that a malicious app must already be on the device. But if that precondition is met through a sideloaded APK, a zero-day, or a supply-chain compromise, the VPN lockdown you trusted is bypassed. GrapheneOS, the security-hardened Android distribution, patched the issue in release 2026050400 by disabling the vulnerable QUIC graceful shutdown optimization entirely.

#OnThisDay in 1982, the Lebanese Phalangist militia (Kataeb Party), backed by lsrael, perpetrated a massacre in the southern Beirut neighborhood of Sabra and Palestinian refugee camp Shatila that lasted 3 days (16 - 18 September) and claimed the lives of thousands of Palestinian refugees and Lebanese citizens. On 16 December 1982, the UN General Assembly declared the massacre "an act of genocide."

"If you are neutral in situations of injustice, you have chosen the side of the oppressor." - Desmond Tutu

Wanting all humans to be treated equal should never be controversial.

On June 18, 1959, Che Guevara visited Gaza—the first prominent international revolutionary after the Nakba. Touring Palestini
On June 18, 1959, Che Guevara visited Gaza—the first prominent international revolutionary after the Nakba. Touring Palestinian refugee camps, he told a fellow Cuban officer: “Look, this is the work of the Gringos [United States].” #CheGuevara #Gaza #Palestine

On June 18, 1959, Che Guevara visited Gaza—the first prominent international revolutionary after the Nakba. Touring Palestini
On June 18, 1959, Che Guevara visited Gaza—the first prominent international revolutionary after the Nakba. Touring Palestinian refugee camps, he told a fellow Cuban officer: “Look, this is the work of the Gringos [United States].” 🇵🇸 #CheGuevara #Gaza #Palestine

On June 18, 1959, Che Guevara visited Gaza—the first prominent international revolutionary after the Nakba. Touring Palestini
On June 18, 1959, Che Guevara visited Gaza—the first prominent international revolutionary after the Nakba. Touring Palestinian refugee camps, he told a fellow Cuban officer: “Look, this is the work of the Gringos [United States].” 🇵🇸 No mention of the Egyptian president. You can add hashtags like #CheGuevara #Gaza #Palestine

On June 18, 1959, Che Guevara visited Gaza—the first prominent international revolutionary after the Nakba. Touring Palestini
On June 18, 1959, Che Guevara visited Gaza—the first prominent international revolutionary after the Nakba. Touring Palestinian refugee camps, he told a fellow Cuban officer: “Look, this is the work of the Gringos [United States].” 🇵🇸 No mention of the Egyptian president. You can add hashtags like #CheGuevara #Gaza #Palestine

Google hires Israeli chip team to develop AI chip Google has formed a team in Israel, led by former Hailo CEO Guy Kaminitz and including a former Nvidia manager, to build on-device AI chips for robots and autonomous systems. #TGITM

Israel Top Target for Hacktivists Worldwide · Israel hit with 16% of all hacktivist campaigns in H1 2026 · Over 1000 attacks claims recorded against Israel · 85% of attacks by Pro-Palestine, pro-Russia and anti-Western groups #TGITM @TheGhostITM

"Idiotic": Bjarne Stroustrup Slams AI-Coded Software as a Security Nightmare By #TGITM — Published: September 7, 2026 In a blistering critique that has sent ripples through the developer community, Bjarne Stroustrup—the creator of the C++ programming language—has dismissed the current wave of AI-generated code as not only ineffective but dangerously insecure. Speaking in a recent interview, Stroustrup pulled no punches, calling the idea of using natural language as a programming language "idiotic." While the tech industry races to embed large language models into every development pipeline, the legendary computer scientist warns that the output is a ticking time bomb for safety-critical systems. "Bloated Code, More Bugs, More Holes" Stroustrup's primary grievance lies with code quality. He argued that AI tools do not write lean, efficient code—they generate "bloated code" that introduces "more bugs, more security holes," and consumes excessive memory. "It's hard to validate, " he stated, pointing to a fundamental flaw: unlike human-written patches, which are typically localized and traceable, AI-generated changes are opaque. "You don't actually know where it's changed. You have to try and figure that out. " This lack of transparency, he warned, creates a validation crisis. The very experts capable of auditing this machine-written code—senior developers—are starting to retire rather than deal with the Sisyphean task of re-validating code that "changes every time you make a change in your prompts. " The 10–20% That Matters Most While acknowledging that AI might handle mundane or boilerplate tasks, Stroustrup made it clear where the line must be drawn. "It's not, at least now, good at safety-critical, performance-critical code, " he said. He conceded that AI could potentially manage "70 or 80% of the world's code," but dismissed that as irrelevant. "It's that 10 or 20% of the code that I'm interested in. And there, it's not there. " Repeating Old Mistakes Perhaps most damning is his observation that LLMs are merely regurgitating the past. "LLM-based code is imitating old code and getting old performance and old bugs again, " he noted. Rather than advancing software engineering, AI risks fossilizing legacy vulnerabilities and inefficiencies. The Bottom Line For security professionals, Stroustrup's message is clear: Do not trust AI to write critical infrastructure code. While the industry chases productivity gains, the hidden costs—memory bloat, validation debt, and unpatched vulnerabilities—may outweigh any speed benefits. As he put it simply: "In the field I’m mostly interested in... code will still be written by humans. " #AI #C++ @TheGhostITM