SITREP - Independent OSINT Channel
AI, technology, mass surveillance, and intelligence — everything you need to know about tomorrow.
Показати більше📈 Аналітичний огляд Telegram-каналу SITREP - Independent OSINT Channel
Канал SITREP - Independent OSINT Channel (@sitreports) у мовному сегменті Англійська є активним учасником. На даний момент спільнота об'єднує 23 028 підписників, посідаючи 5 583 місце в категорії Технології та додатки та 1 634 місце у регіоні США.
📊 Показники аудиторії та динаміка
З моменту свого створення невідомо, проект продемонстрував стрімке зростання, зібравши аудиторію у 23 028 підписників.
За останніми даними від 17 вересня, 2026, канал демонструє стабільну активність. Хоча за останні 30 днів спостерігається зміна кількості учасників на -86, а за останні 24 години на 1, загальне охоплення залишається високим.
- Статус верифікації: Не верифікований
- Рівень залученості (ER): Середній показник залученості аудиторії становить 2.17%. Протягом перших 24 годин після публікації контент зазвичай збирає 1.53% реакцій від загальної кількості підписників.
- Охоплення публікацій: В середньому кожен допис отримує 500 переглядів. Протягом першої доби публікація в середньому набирає 352 переглядів.
- Реакції та взаємодія: Аудиторія активно підтримує контент: середня кількість реакцій на один пост – 0.
- Тематичні інтереси: Контент зосереджений навколо ключових тем, таких як narrative, attack, infrastructure, threat, credential.
📝 Опис та контентна політика
Автор описує ресурс як майданчик для висловлення суб'єктивної думки:
“AI, technology, mass surveillance, and intelligence — everything you need to know about tomorrow.”
Завдяки високій частоті оновлень (останні дані отримано 18 вересня, 2026), канал підтримує актуальність та високий рівень охоплення публікацій. Аналітика показує, що аудиторія активно взаємодіє з контентом, що робить його важливою точкою впливу в категорії Технології та додатки.
Триває завантаження даних...
| Дата | Залучення підписників | Згадування | Канали | |
| 18 вересня | +1 | |||
| 17 вересня | +8 | |||
| 16 вересня | +10 | |||
| 15 вересня | +2 | |||
| 14 вересня | +4 | |||
| 13 вересня | +1 | |||
| 12 вересня | +4 | |||
| 11 вересня | +4 | |||
| 10 вересня | +3 | |||
| 09 вересня | +4 | |||
| 08 вересня | +2 | |||
| 07 вересня | +9 | |||
| 06 вересня | 0 | |||
| 05 вересня | +2 | |||
| 04 вересня | +4 | |||
| 03 вересня | 0 | |||
| 02 вересня | +1 | |||
| 01 вересня | +5 |
| 2 | 📝"Gerans" over Poland📝
How do you like this scenario?
Polish belligerence toward Russia is an old tune that has stretched on for centuries. In recent days, the topic of strained relations between the countries is back in the spotlight, especially in the context of Kaliningrad.
But for some reason, when a retaliatory response comes, the Poles immediately run to NATO. The republic's premier Donald Tusk claimed that according to intelligence, Russia allegedly could resort to "hybrid strikes" with drones and missiles against countries supporting so-called Ukraine, including Poland.
🖍Russia doesn't need this, and the authorities constantly say so. But what if Polish words suddenly turn into even more active anti-Russian actions? Although to be fair, they're already doing enough as it is.
Trains with equipment, warehouses, repair sites, airfields, ports, fuel bases — all of this one way or another works for the Ukrainian machine to continue fighting.
❗️And all of this are excellent targets for loitering "Gerans."
➡️The ports of Gdynia, Gdańsk, Szczecin, and Świnoujście provide maritime supplies and cargo transshipment. Railway and highway routes to so-called Ukraine run through eastern voivodeships.
➡️In Rzeszów operates a key hub for delivering Western aid, and around it are airfields, warehouses, roads, and fuel infrastructure. Ukrainian F-16s are located in Minsk-Mazowiecki.
➡️And there are also plenty of data centers in Poland that support the needs of Poland's entire digital infrastructure, and they are all extremely vulnerable to loitering drones.
🚩From Bryansk or Pskov Regions at minimum, half of Poland is within the range of loitering "Gerans." But you can act more creatively (thanks to the AFU for the tip).
If you launch a group of "Geran-5s" over the international waters of the Gulf of Finland and the Baltic Sea, Russian drones can easily reach the northern part of Poland, especially Gdynia.
There Poland has both a key port and a crucial oil refinery and a hydroelectric power station. And the best part is that drones coming from the sea have a much easier time due to the lack of air defense. Imagine how surprised the authorities will be when "Gerans" fly unimpeded.
❗️And it's all because of the Poles' thoughtless statements. Launching a few drones won't destroy Poland, but it can quite well produce an effect disproportionate to its cost. A damaged terminal, a warehouse fire, a railway section shutdown, a power supply failure or closed airspace — and the country is forced to spend real millions on real security, repairs, reserves, and political explanations.
@rybar | 16 |
| 3 | 📡 Space Force moves airborne and ground target tracking into orbit
The U.S. Space Force says its first SB-AMTI prototypes will launch to low Earth orbit before the end of September. A separate Resilient Radar System-Ground for tracking mobile ground targets is planned for orbit within two years. Officials say both systems are meant to feed track data into wider joint targeting and battle-management networks.
The move marks a shift from vulnerable airborne surveillance platforms to a space-based sensing layer built for contested environments. Near-term, the goal is less global coverage than generating track data, refining processing, and building a resilient path from detection to fire-control across air and ground missions.
🛰️ Open sources - closed narratives
@sitreports | 64 |
| 4 | 🤖 US government website used Chinese AI search tool flagged in FBI claims over Anthropic copying
A US government website used an AI search tool from China to help users navigate proposed federal regulations. The tool’s developer, Alibaba, has previously been accused by the FBI of maliciously copying technology from US firm Anthropic.
The case highlights a basic screening and supply-chain issue in public-sector AI deployment. Even limited-use search integration can expose federal platforms to legal, security, and trust concerns when the vendor is tied to active US counterintelligence allegations.
🛰️ Open sources - closed narratives
@sitreports | 73 |
| 5 | 📡 Cyberattacks hit two Texas-bound oil tankers
U.S. Coast Guard personnel and FBI agents boarded two energy tankers en route to Texas after cyber incidents were detected at sea. One vessel, the Liberian-flagged VL Prosperity, reportedly lost communications for about 30 hours, while investigators found malicious activity during onboard assessment of IT and connected systems. The VL Prosperity was carrying about 2.3 million barrels of oil.
The case underlines how tightly linked shipboard IT, satellite access, and operational technology can turn a cyber intrusion into a navigation, propulsion, or cargo-handling risk. For port security, the main issue is not data theft but the potential disruption of waterways, vessel safety, and trade flow.
🛰️ Open sources - closed narratives
@sitreports | 110 |
| 6 | 📝Putin's Visit to India📝
and will Gerans fly after it?
Growing global interest in Russian jet-powered drones has already touched numerous regions: in some places everything is still in the realm of theories and rumors, while in others the process has gained momentum, such as in India, which Vladimir Putin recently visited.
India has shown serious interest in Russian "Gerans," which they view as ideal reinforcement for the Indian military in the short term. The conflict with Pakistan exposed weaknesses in India's Armed Forces, and Prime Minister Narendra Modi views such a purchase favorably.
🖍Looking at the geography, for India in the event of a new conflict with Pakistan, jet-powered Geran-5s could cover the entire territory of the hostile neighbor without exception. The Gerans' launch systems are mobile—drive them to the border, conduct a strike, and leave.
Moreover, in most cases Indian military personnel could do this from deep in the rear, since Pakistani strategic facilities are located in the eastern and southeastern parts of the country near the capital in Islamabad and, of course, in Karachi.
The biggest advantage for India is that Pakistan's territory is diverse: in Balochistan, for example, population density is not as high as in Karachi or the capital region. Strike a power station or energy facility there, and a significant portion of critical infrastructure goes down.
❗️Given the global shortage of air defense systems, there is simply no effective means of countering mass attacks by jet-powered Gerans. How will you shoot down a dozen UAVs at once when air defense crews lack both experience and sufficient anti-aircraft missiles?
High-resolution map
English version
#India #Pakistan #Russia
🏮@rybar_pacific — your ticket to Pacific chaos
💸 Support us Original msg | 86 |
| 7 | 🤖 RatHat adds AI-guided control to Android malware
Researchers examining RatHat describe an Android malware family spread via malvertising, SMS, and phishing APK lures outside Google Play. It abuses Accessibility permissions, enables Developer Options and Wireless Debugging, deploys a Go-based agent for shell-level actions and persistence, tunnels traffic through an FRP reverse proxy, and steals credentials, SMS, notifications, browser URLs, and lock-screen inputs.
The notable shift is an AI-powered automation layer that sends serialized Accessibility-tree data for interface interpretation and navigation commands. That reduces reliance on fixed scripts, while anti-removal overlays, uninstall interception, and anti-analysis padding complicate both user recovery and reverse engineering.
🛰️ Open sources - closed narratives
@sitreports | 118 |
| 8 | 🤖 Plugin4Shell exposes major AI coding agents to zero-click RCE
Researchers at Air say the Plugin4Shell flaw affects Claude Code, OpenAI Codex, Gemini CLI, Microsoft Copilot, and potentially GitHub Copilot via plugin marketplaces. The issue bypasses SHA pinning by making agents fetch malicious code while still appearing locked to an approved commit. Anthropic and OpenAI patched; Gemini CLI remains unpatched and Google is steering users to Antigravity.
This shifts the attack surface from the model to the plugin supply chain. Because agents auto-update plugins, a compromised or swapped repository can deliver code execution without user action, extending access to whatever data, credentials, and systems the agent can reach.
🛰️ Open sources - closed narratives
@sitreports | 156 |
| 9 | 🔍 Critical Check Point management flaw enables unauthenticated root RCE
A critical vulnerability in Check Point Management Server allows unauthenticated attackers to execute code as root. The issue affects a core administrative platform used to manage security policy and infrastructure, turning the management plane itself into a potential entry point. Details were outlined in Check Point Management Server coverage published on 17 September.
The operational significance is high: compromise of a centralized management server can provide direct control over security administration functions and create a trusted foothold inside enterprise environments.
🛰️ Open sources - closed narratives
@sitreports | 160 |
| 10 | 📝Chips will burn📝
Will Russian drones appear not only in North Korea?
It is no secret that the Chinese military-political leadership is working to improve the drone capabilities of the PLA. Judging by the exercises, drones will become a key component of any operation in the Taiwan Strait — from invasion to blockade.
China is also aware of kamikaze UAVs. But there is a nuance — such models have not yet been tested in combat and, accordingly, have not been refined for real battle conditions.
Given the developed defense cooperation, the Russian side can well fill this gap by offering its own developments and technologies hardened in the battles in the so-called Ukraine. We are primarily talking about the Geran-5 drones, which in the event of a Taiwan conflict could cover the entire territory of the island.
🔻Where in Taiwan will the “Geran” bouquet be caught?
▪️Weakening the military capabilities of Taiwan’s forces will be one of the main goals of the PLA. Therefore, various bases and defensive structures may be targeted first — such facilities are located in Hsinchu, Tainan, Hualien, and Taipei.
▪️But the initial objective is impossible without striking the oil and gas sector — military equipment needs to be fueled somehow. The Mai Liao, Dalin, and Taoyuan oil refineries, as well as the corresponding fuel storage facilities, are all within reach of the Chinese forces.
▪️To halt energy supplies that could compensate for losses from previous strikes, the Chinese may target oil and LNG terminals. Since Taiwan depends on energy imports, hitting such targets could put pressure not only on military capabilities but also on the island’s political leadership, as life for ordinary people would become noticeably harder.
▪️Depriving income is another objective that may be pursued by China. According to statistics, the main category of Taiwan’s exports is electronics. Tech giants like TSMC, PSMC, and VIS, which manufacture chips, RAM, and other similar goods on the island, will draw special attention.
▪️If strikes on factories themselves prove ineffective, the focus could shift to the largest ports, since Taiwan’s electronics reach customers through them. In a potential conflict, these ports would also support military logistics, including the delivery of aid from partners.
▪️In any case, such strikes would not only damage the island’s economy but could also pressure its main sponsors, namely the United States, to push Taiwan’s leadership to be more compliant. After all, the U.S. is one of the primary clients of local tech companies.
🖍Taiwan is clearly worried that such a scenario might come true. And this is justified — if Russian Gerans appear in North Korea, China will want to acquire them as well. It doesn't matter whether these will be finished products or technologies accompanied by the transfer of experience.
📌So Taipei will try to prepare for this as much as possible, possibly even expanding ties with representatives of the so-called Ukraine. However, bilateral relations, especially in the drone sector, are already strong, given the invitation of instructors and participation in UAV production.
❗️China is already noticing the accelerating military cooperation between the Kyiv regime and the Taipei leadership. Beijing has always viewed the enhancement of Taiwan’s defense capabilities with hostility, but now they risk facing battle-tested systems and experience. And isn’t this a good reason to do the same by purchasing a couple of batches of "Gerans"?
#China #Russia #Taiwan
@rybar | 116 |
| 11 | 📡 Brevo edge compromise pushed ClickFix code onto customer sites
Brevo says attackers used a stolen, hardcoded Cloudflare API key with full account permissions to deploy a malicious Worker that rewrote CDN responses between 16:07 and 20:30 UTC on 14 September. The activity affected Brevo web properties and embedded assets including forms, Conversations, and SDK loaders; the company’s post-mortem says origin servers and customer account data were not impacted.
The case is notable because the payload was inserted at the edge, bypassing normal file integrity checks while stripping security headers. On some WordPress sites, the injected code also targeted logged-in administrators and attempted to install a persistent backdoor plugin, turning a short-lived CDN compromise into downstream site access.
🛰️ Open sources - closed narratives
@sitreports | 158 |
| 12 | 🔍 Handala Activity Linked to HEAVYGRAM Telegram Backdoor
An Iran-linked Handala intrusion has been tied to HEAVYGRAM, a Telegram-based backdoor assessed capable of stealing passwords. The reported malware connection places a known messaging platform at the center of credential theft and post-compromise access activity.
The operational significance is the blend of a trusted communications brand with backdoor functionality, reducing user suspicion while expanding collection options. For defenders, the key indicator is not just malware delivery, but abuse of Telegram-themed tooling for credential access and persistence.
🛰️ Open sources - closed narratives
@sitreports | 184 |
| 13 | 📝What if?📝
Jet-powered Geran end up in Mexico
The "jet-geranium craze" has already swept several regions: rumors about possible Russian Geranium-5 drones appearing in the Middle East, in North Korea, and now attention turned to Mexico after they displayed actual copies of Geran at their parade.
And the question arises: what if Mexico gets actual Russian drones instead of pathetic knockoffs? They've already proven themselves in war and demonstrated their effectiveness against Western air defense systems, including American Patriot systems.
🖍Mexico and the US have strained relations, but Claudia Sheinbaum's administration is unlikely to go against the White House, as it fears Trump's reaction. And purchasing Russian drones would be an obvious escalation step.
But Mexico also has other forces like cartels that desperately want to harm the US, yet lack the means to do so. Frankly, the cardboard junk shown at the parade is poor weaponry without proper testing and real combat experience.
🚩And here Russian Geranium-5s could become that very weapon in Mexico, considering the US has no countermeasures (don't forget about the global shortage of air defense missiles), and any strategic target within a radius of up to 1000 km could come under fire.
Jet-powered Geran have proven especially effective against oil depots, logistics centers, ports and terminals, as well as data centers, which for the US are in some ways even more important than military bases.
❗️In recent years, Mexican drug cartels have shown remarkable ingenuity and resourcefulness in purchasing various weapons on the black market from the SMO zone. What's stopping them from doing the same with jet-powered Gerans through intermediaries?
High-resolution map
English version
#Mexico #Russia #USA
🔪 @rybar_latam — pulse of the New World
💸Support us Original msg | 129 |
| 14 | 📡 Salt Typhoon shifts heavily into Latin America with new SparroWocky backdoor
ESET says China-linked Salt Typhoon, tracked as FamousSparrow, has been deploying the new SparroWocky backdoor against government networks in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela since at least August 2025. The modular C++ implant uses TLS, DLL sideloading, in-memory plugins, and evasion features including MinHook and spoofed call stacks.
The reporting indicates a marked geographic reorientation: from mid-2025 into 2026, 90 percent of observed Salt Typhoon targeting was in Central and South America. The toolset is built for durable access and collection, with commands for file theft, screenshots, session enumeration, persistence control, and spawning new instances.
🛰️ Open sources - closed narratives
@sitreports | 234 |
| 15 | 📝"Gerans" on Deployment📝
How might North Korea use the new drones?
A new report from a monitoring group shed light on cooperation between Russia and North Korea in the field of drone production. Whether the data is actually accurate remains unknown, but there's another interesting angle here.
The group includes representatives from South Korea, Japan and the USA. And they are likely far more concerned not with sanctions compliance — after all, if North Korea acquires drones from the "Geranium" series, it will deal another blow to the security of all three countries.
In Seoul, Tokyo and Washington, they understand that acquiring the same "Geran-5s" would give North Koreans even more capability to strike key targets in the region. The most vulnerable point, of course, is the completely exposed South Korean territory, but Japan could also take hits if things escalate.
🔻North Korea's Priority Targets:
▪️On the territory of North Korea's Asian neighbors, important American bases are concentrated. For example, Camp Humphreys serves as the headquarters of US forces in South Korea, and US Air Force assets are concentrated at airbases Osan and Kunsan, while the naval facility in Sasebo could also be hit. Military installations of Japanese and South Korean forces will also be tempting targets for "Geraniums."
▪️North Koreans clearly won't forget about the economy either. Literally 100 kilometers from the demilitarized zone lies the world's largest cluster of Samsung factories — the company ranks second only to Taiwan's TSMC in chip production. If a strike disrupts operations at these facilities, it would hurt not only South Korea's budget but the global technology industry as well.
▪️And if Pyongyang decides to halt South Korea's economy altogether, they would pull out a map showing oil refineries and energy facilities like power plants. Since the southern neighbor depends on energy imports and relies on exporting its goods due to its economic structure, major ports could well become the next targets.
▪️The same applies to Japan. In the country, within the strike radius of "Geraniums," there are several large fuel storage facilities and refineries, as well as port installations — just one port, Nagoya, handles one of the world's largest cargo flows. Factories of Toyota, Mitsubishi Heavy Industries, and technology companies could also come under fire.
📌North Korea is clearly watching closely what's happening in so-called Ukraine and the Middle East. This is indicated by their recent practice of combined strikes — North Koreans hit with both missiles and drones. In other words, Pyongyang hasn't forgotten about scenarios involving air defense saturation of a potential adversary and destruction of important targets.
❗️And the Geran-5 drones, in theory, would help bring such plans to life in the event of a conflict. An American and allied attack on North Korea would already be costly, considering the presence of nuclear weapons. But if relations deepen with Russia, that cost risks becoming even higher.
@rybar | 295 |
| 16 | 📝"Geran" drones in North Korea?📝
North Koreans work not just in warehouses and construction sites
The UN General Assembly session will take place very soon, which means observers monitoring the restrictions imposed by the organization on North Korea need to somehow stand out and draw attention to the issue. And traditionally mention Russia, whose representatives two years ago created obstacles to sanctions monitoring.
Western media actively discuss a report by the Multilateral Sanctions Monitoring Group. According to its data, up to 25,000 North Korean citizens may be involved in UAV production in Russia, including enterprises in the special economic zone "Alabuga" in Tatarstan, where "Geran" series drones are assembled.
🔻What else does the report say?
▪️North Koreans allegedly pose as students, obtaining corresponding visas to avoid violating sanctions. Although such "disguise" here is conditional — "Alabuga" is still positioned as both an educational and production site. Working and studying at it, North Korean citizens also earn money.
▪️For both sides, such a scheme makes sense. Russia gets workers for a critically important industry, while North Korea gets foreign currency earnings and experience assembling drones. Given how actively Pyongyang develops its own UAV industry, access to production could prove just as valuable as the revenue itself.
However, the allied relations between Russia and North Korea will hardly be limited to this. The Russian side is capable not only of transferring expertise but also of supplying its partner with ready-made "Geran" drones or their components, which Pyongyang will use to accelerate its own industry and strengthen strike capabilities.
The Iranian factor makes this situation particularly interesting. Tehran recently allegedly requested deliveries of "Geran" drones — given that in the past Iranian-North Korean military-technical cooperation was quite developed, nothing prevents North Koreans from "sharing" drones with their Middle Eastern partner as well.
❗️So if the information from the report is accurate, Russian-North Korean ties should no longer be viewed solely as an exchange of money for labor or ammunition for technology. Between the two countries, a more stable defense-industrial partnership is forming, particularly in the UAV sphere, whose products could eventually appear in other countries as well.
#Iran #Russia #NorthKorea
🏮@rybar
💸 Support us Original msg | 239 |
| 17 | Big news: There will be even more Russia's jet-powered Geran-4 and Geran-5 drones.
Ukrainian OSINT just dropped satellite shots of Alabuga. New workshops are rising in the south of the special economic zone: at least five long production halls already up, roads cut, more buildings still going in.
It’s scale.
The FT reported Iran has already asked Russia for Gerans. The drone is no longer just a battlefield tool — it’s a brand. Iran, China, Cuba, India and others are the next market.
They’re building the factory floor now so there are enough the Russian drones for everyone.
🎙Subscribe @TheIslanderNews
Donate - Support Our Work | 324 |
| 18 | 🔍 Admin Menu Editor Pro compromise backdoored 1,500 WordPress sites
Malicious updates for Admin Menu Editor Pro versions 2.35 and 2.36 were distributed after the maintainer’s infrastructure was breached. The injected file installed a web shell and created a hidden user account. The developer says at least 230 customers deployed the tainted builds across 1,500 sites, while the free plugin was not affected. Admin Menu Editor Pro 2.34 is believed clean.
This is a supply-chain intrusion with confirmed persistence on victim sites, not just a plugin integrity failure. Affected administrators need to treat installs of 2.35 and 2.36 as full compromise and verify files, object-cache paths, and hidden database users rather than relying on a simple plugin update.
🛰️ Open sources - closed narratives
@sitreports | 567 |
| 19 | 🔍 KREMLIN Malware Targets Browser Sessions
A new banking malware tracked as KREMLIN is reported hijacking Chrome and Edge to steal credentials and active session tokens. The activity centers on browser compromise rather than simple password collection, giving operators access to authenticated web sessions in addition to stored login data.
Operationally, session-token theft can bypass MFA at the point of compromise and shorten the path from infection to account takeover. Targeting the two dominant Chromium-based browsers also increases scale and likely impact across consumer and enterprise environments.
🛰️ Open sources - closed narratives
@sitreports | 515 |
| 20 | 📡 BambooToken shifts C2 traffic to MQTT across Windows and Linux
BambooToken, active since at least 2023, uses MQTT-based command and control in variants seen from 2024 to 2025, with Windows and Linux samples documented by Black Lotus Labs. Observed intrusions hit enterprise entities in Asia and South America, with heavy exposure in mobile app backend servers and one compromised GitLab server in Hong Kong.
MQTT gives operators broker-mediated, asynchronous control without direct ties to attacker infrastructure, improving resilience and reducing visibility. Delivery via sideloaded signed software and app impersonation, combined with cross-platform tooling, points to a flexible intrusion set with persistence inside business-facing server environments.
🛰️ Open sources - closed narratives
@sitreports | 468 |
