SITREP - Independent OSINT Channel
AI, technology, mass surveillance, and intelligence — everything you need to know about tomorrow.
Показати більше📈 Аналітичний огляд Telegram-каналу SITREP - Independent OSINT Channel
Канал SITREP - Independent OSINT Channel (@sitreports) у мовному сегменті Англійська є активним учасником. На даний момент спільнота об'єднує 23 026 підписників, посідаючи 5 583 місце в категорії Технології та додатки та 1 634 місце у регіоні США.
📊 Показники аудиторії та динаміка
З моменту свого створення невідомо, проект продемонстрував стрімке зростання, зібравши аудиторію у 23 026 підписників.
За останніми даними від 17 вересня, 2026, канал демонструє стабільну активність. Хоча за останні 30 днів спостерігається зміна кількості учасників на -86, а за останні 24 години на 1, загальне охоплення залишається високим.
- Статус верифікації: Не верифікований
- Рівень залученості (ER): Середній показник залученості аудиторії становить 2.17%. Протягом перших 24 годин після публікації контент зазвичай збирає 1.53% реакцій від загальної кількості підписників.
- Охоплення публікацій: В середньому кожен допис отримує 500 переглядів. Протягом першої доби публікація в середньому набирає 352 переглядів.
- Реакції та взаємодія: Аудиторія активно підтримує контент: середня кількість реакцій на один пост – 0.
- Тематичні інтереси: Контент зосереджений навколо ключових тем, таких як narrative, attack, infrastructure, threat, credential.
📝 Опис та контентна політика
Автор описує ресурс як майданчик для висловлення суб'єктивної думки:
“AI, technology, mass surveillance, and intelligence — everything you need to know about tomorrow.”
Завдяки високій частоті оновлень (останні дані отримано 18 вересня, 2026), канал підтримує актуальність та високий рівень охоплення публікацій. Аналітика показує, що аудиторія активно взаємодіє з контентом, що робить його важливою точкою впливу в категорії Технології та додатки.
Триває завантаження даних...
| Дата | Залучення підписників | Згадування | Канали | |
| 17 вересня | +8 | |||
| 16 вересня | +10 | |||
| 15 вересня | +2 | |||
| 14 вересня | +4 | |||
| 13 вересня | +1 | |||
| 12 вересня | +4 | |||
| 11 вересня | +4 | |||
| 10 вересня | +3 | |||
| 09 вересня | +4 | |||
| 08 вересня | +2 | |||
| 07 вересня | +9 | |||
| 06 вересня | 0 | |||
| 05 вересня | +2 | |||
| 04 вересня | +4 | |||
| 03 вересня | 0 | |||
| 02 вересня | +1 | |||
| 01 вересня | +5 |
🔻North Korea's Priority Targets: ▪️On the territory of North Korea's Asian neighbors, important American bases are concentrated. For example, Camp Humphreys serves as the headquarters of US forces in South Korea, and US Air Force assets are concentrated at airbases Osan and Kunsan, while the naval facility in Sasebo could also be hit. Military installations of Japanese and South Korean forces will also be tempting targets for "Geraniums." ▪️North Koreans clearly won't forget about the economy either. Literally 100 kilometers from the demilitarized zone lies the world's largest cluster of Samsung factories — the company ranks second only to Taiwan's TSMC in chip production. If a strike disrupts operations at these facilities, it would hurt not only South Korea's budget but the global technology industry as well. ▪️And if Pyongyang decides to halt South Korea's economy altogether, they would pull out a map showing oil refineries and energy facilities like power plants. Since the southern neighbor depends on energy imports and relies on exporting its goods due to its economic structure, major ports could well become the next targets. ▪️The same applies to Japan. In the country, within the strike radius of "Geraniums," there are several large fuel storage facilities and refineries, as well as port installations — just one port, Nagoya, handles one of the world's largest cargo flows. Factories of Toyota, Mitsubishi Heavy Industries, and technology companies could also come under fire.📌North Korea is clearly watching closely what's happening in so-called Ukraine and the Middle East. This is indicated by their recent practice of combined strikes — North Koreans hit with both missiles and drones. In other words, Pyongyang hasn't forgotten about scenarios involving air defense saturation of a potential adversary and destruction of important targets. ❗️And the Geran-5 drones, in theory, would help bring such plans to life in the event of a conflict. An American and allied attack on North Korea would already be costly, considering the presence of nuclear weapons. But if relations deepen with Russia, that cost risks becoming even higher. @rybar
| 2 | 📝"Geran" drones in North Korea?📝
North Koreans work not just in warehouses and construction sites
The UN General Assembly session will take place very soon, which means observers monitoring the restrictions imposed by the organization on North Korea need to somehow stand out and draw attention to the issue. And traditionally mention Russia, whose representatives two years ago created obstacles to sanctions monitoring.
Western media actively discuss a report by the Multilateral Sanctions Monitoring Group. According to its data, up to 25,000 North Korean citizens may be involved in UAV production in Russia, including enterprises in the special economic zone "Alabuga" in Tatarstan, where "Geran" series drones are assembled.
🔻What else does the report say?
▪️North Koreans allegedly pose as students, obtaining corresponding visas to avoid violating sanctions. Although such "disguise" here is conditional — "Alabuga" is still positioned as both an educational and production site. Working and studying at it, North Korean citizens also earn money.
▪️For both sides, such a scheme makes sense. Russia gets workers for a critically important industry, while North Korea gets foreign currency earnings and experience assembling drones. Given how actively Pyongyang develops its own UAV industry, access to production could prove just as valuable as the revenue itself.
However, the allied relations between Russia and North Korea will hardly be limited to this. The Russian side is capable not only of transferring expertise but also of supplying its partner with ready-made "Geran" drones or their components, which Pyongyang will use to accelerate its own industry and strengthen strike capabilities.
The Iranian factor makes this situation particularly interesting. Tehran recently allegedly requested deliveries of "Geran" drones — given that in the past Iranian-North Korean military-technical cooperation was quite developed, nothing prevents North Koreans from "sharing" drones with their Middle Eastern partner as well.
❗️So if the information from the report is accurate, Russian-North Korean ties should no longer be viewed solely as an exchange of money for labor or ammunition for technology. Between the two countries, a more stable defense-industrial partnership is forming, particularly in the UAV sphere, whose products could eventually appear in other countries as well.
#Iran #Russia #NorthKorea
🏮@rybar
💸 Support us Original msg | 160 |
| 3 | Big news: There will be even more Russia's jet-powered Geran-4 and Geran-5 drones.
Ukrainian OSINT just dropped satellite shots of Alabuga. New workshops are rising in the south of the special economic zone: at least five long production halls already up, roads cut, more buildings still going in.
It’s scale.
The FT reported Iran has already asked Russia for Gerans. The drone is no longer just a battlefield tool — it’s a brand. Iran, China, Cuba, India and others are the next market.
They’re building the factory floor now so there are enough the Russian drones for everyone.
🎙Subscribe @TheIslanderNews
Donate - Support Our Work | 274 |
| 4 | 🔍 Admin Menu Editor Pro compromise backdoored 1,500 WordPress sites
Malicious updates for Admin Menu Editor Pro versions 2.35 and 2.36 were distributed after the maintainer’s infrastructure was breached. The injected file installed a web shell and created a hidden user account. The developer says at least 230 customers deployed the tainted builds across 1,500 sites, while the free plugin was not affected. Admin Menu Editor Pro 2.34 is believed clean.
This is a supply-chain intrusion with confirmed persistence on victim sites, not just a plugin integrity failure. Affected administrators need to treat installs of 2.35 and 2.36 as full compromise and verify files, object-cache paths, and hidden database users rather than relying on a simple plugin update.
🛰️ Open sources - closed narratives
@sitreports | 526 |
| 5 | 🔍 KREMLIN Malware Targets Browser Sessions
A new banking malware tracked as KREMLIN is reported hijacking Chrome and Edge to steal credentials and active session tokens. The activity centers on browser compromise rather than simple password collection, giving operators access to authenticated web sessions in addition to stored login data.
Operationally, session-token theft can bypass MFA at the point of compromise and shorten the path from infection to account takeover. Targeting the two dominant Chromium-based browsers also increases scale and likely impact across consumer and enterprise environments.
🛰️ Open sources - closed narratives
@sitreports | 483 |
| 6 | 📡 BambooToken shifts C2 traffic to MQTT across Windows and Linux
BambooToken, active since at least 2023, uses MQTT-based command and control in variants seen from 2024 to 2025, with Windows and Linux samples documented by Black Lotus Labs. Observed intrusions hit enterprise entities in Asia and South America, with heavy exposure in mobile app backend servers and one compromised GitLab server in Hong Kong.
MQTT gives operators broker-mediated, asynchronous control without direct ties to attacker infrastructure, improving resilience and reducing visibility. Delivery via sideloaded signed software and app impersonation, combined with cross-platform tooling, points to a flexible intrusion set with persistence inside business-facing server environments.
🛰️ Open sources - closed narratives
@sitreports | 436 |
| 7 | 🔍 Iran-linked Chosen Brick campaign targets Windows users
The FBI, UK NCSC, and AIVD say Iranian state actors are using WhatsApp and Telegram lures to deliver Chosen Brick on Windows devices. The malware steals emails, contacts, and messaging data, captures screen and audio, adds Defender exclusions, persists via HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and uses victim-specific Telegram bots for C2.
The pattern points to tightly researched social engineering against dissidents, activists, and journalists rather than broad network intrusion. The focus on personal Windows devices and trusted-message delivery complicates enterprise-only defenses and extends operational exposure beyond managed corporate endpoints.
🛰️ Open sources - closed narratives
@sitreports | 399 |
| 8 | 📡 Iranian operators tied to Telegram-based malware targeting activists
A new malware campaign used Telegram as command-and-control infrastructure to surveil dissidents and journalists. The activity is attributed to Iranian hackers and centered on espionage, with targets drawn from politically sensitive civilian networks rather than broad criminal victim sets.
Operationally, Telegram-backed C2 blends hostile traffic into routine app usage and complicates rapid filtering or attribution. The target profile indicates a collection effort focused on monitoring opposition, media, and information flows rather than disruptive effects.
🛰️ Open sources - closed narratives
@sitreports | 1 933 |
| 9 | 📡 SDA seeks to retain fast-track authorities as Congress weighs restructuring
SDA Director Gurpartap Sandhoo said the agency’s speed depends on keeping its special hiring, classification, and contracting authorities as lawmakers weigh FY2027 NDAA provisions that could dissolve SDA and move its functions into Space Force acquisition structures. SDA is still advancing the Proliferated Warfighter Space Architecture and next-generation missile warning and tracking satellites.
The core issue is control of decision-making. Sandhoo’s remarks suggest SDA’s model is already being absorbed into Space Force structures, but losing standalone authorities could slow a mission built around rapid procurement and deployment.
🛰️ Open sources - closed narratives
@sitreports | 358 |
| 10 | 🇺🇦🇪🇺The West is told to study the Geran assembly line
American coverage has begun quoting Washington analysts saying the West underestimates Russia and should be learning how it closes the loop from concept to serial production of the Geran. That is a shift in register from dismissal to study. The question in Western capitals has moved from whether the drone works to how it gets built this fast.
🛰 Open sources - closed narratives
@sitreports | 371 |
| 11 | 📡 Space Force sets up office to push emerging tech into programs
The U.S. Space Force has established a Technology Portfolio Executive office reporting to the assistant secretary of the Air Force for space acquisition and integration. The office is designed to work alongside the service’s new portfolio acquisition executives and focus on moving promising R&D and commercial capabilities into prototyping and operational pathways.
The move targets the acquisition “valley of death” between industry development and fielded systems. It also indicates the Space Force sees its nine portfolio executives as insufficient on their own to scout, mature, and transition cross-cutting technologies at the speed now being demanded.
🛰️ Open sources - closed narratives
@sitreports | 329 |
| 12 | 🔍 B-52 engine and radar upgrades clear key program gates
The U.S. Air Force advanced two core B-52 modernization lines: the Commercial Engine Replacement Program reached Milestone B in June, and the Radar Modernization Program entered low-rate initial production in August. The B-52 modernization effort is intended to keep the bomber operational into the 2050s, despite both projects recording more than 30% cost growth and delays exceeding three years.
These approvals shift the program from planning into harder execution phases, but they do not erase affordability and schedule pressure. Engine costs have risen above $15.4 billion, radar costs near $3 billion, and radar flight testing remains affected by the June loss of a test aircraft.
🛰️ Open sources - closed narratives
@sitreports | 358 |
| 13 | 🔫 Army places $1.2B PrSM Increment 2 order with Lockheed
The US Army has awarded Lockheed Martin a contract worth more than $1.2 billion for PrSM Increment 2, with production expected to run through 13 September 2031. The new variant adds a multi-mode seeker for time-sensitive moving targets, including ships. The Army said it received one bid; quantities and delivery breakdowns were not disclosed.
The award shifts PrSM from flight testing into production while expanding the missile from fixed land attack into maritime strike against relocating targets. It also underscores a replenishment push after heavy wartime expenditure and wider concerns over munitions stockpiles and production bottlenecks.
🛰️ Open sources - closed narratives
@sitreports | 354 |
| 14 | 📡 USAFE outlines CCA roles for European air defense and strike support
USAFE commander Lt. Gen. Jason Hinds said the service is giving allies employment vignettes for Collaborative Combat Aircraft in Europe. The concepts cover defense against one-way attack drones and cruise missiles, and offensive support for suppressing integrated air defenses during a hostile incursion into NATO territory. He added that allied interceptions of suspected Russian drones show the current response works, but is costly.
The significance is twofold: air policing incidents are increasing demand for cheaper intercept options, while Washington is positioning CCAs as both an air defense multiplier and a force-design model for allies.
🛰️ Open sources - closed narratives
@sitreports | 407 |
| 15 | 🛸🇺🇦Russia's new drones (Geran-5) are changing the air war - FT
What Western media say about Geran drones
Strikes on logistics hubs, rail junctions and border crossings have done something that earlier waves of attacks failed to do: they rattled Kyiv and its Western backers at the same time. The panic is audible in the reporting itself, where the tone has shifted from confidence in Ukrainian ingenuity to open admissions that the defence has been outpaced.
The Financial Times set the frame: the new Gerans fly at speeds and altitudes that have effectively blurred the line between a drone and a cruise missile, and that has changed the air war.
The same paper put a number on the consequence, quoting Ukrainian Air Force spokesman Yurii Ihnat:
"The effectiveness of our air defense against jet drones is around 60 percent, whereas for other types it is 90 to 95 percent."
The Wall Street Journal drew the industrial conclusion, quoting Kateryna Bondar of CSIS:
"The West tends to underestimate Russia, yet it should be learning from its ability to close the loop from concept to serial production."
Then came Reuters with the part nobody in Kyiv wanted printed. At July trials of a new generation of Ukrainian interceptors, many of the aircraft lost control at speeds above 400 km/h, and some simply crashed into fields and forest.
The programme that was supposed to be the answer to the Geran-5 failed its own demonstration.
Maksym Zhorin, deputy commander of Ukraine's 3rd Army Corps, wrote it plainly on September 12:
"We have once again completely lost the initiative with jet-powered drones, and we don't even know what to do about them."
The arithmetic is unforgiving. Interceptor drones remain unready, Western air-defence missiles are in short supply, and jet Geran output keeps climbing. A defence that stops six of every ten incoming aircraft leaves the rest to choose their targets. With autumn arriving and the interceptor gap still open, the energy grid is the obvious next address.
#Russia #Ukraine #UAV #AirDefense
🔴 @DDGeopolitics | 379 |
| 16 | 🔫 AFSOC confirms first combat use of AGM-190A Havoc Spear in Africa
Air Force Special Operations Command said an AC-130 fired two AGM-190A Havoc Spear cruise missiles at two separate ground targets in Africa during spring 2026 combat operations. AFSOC says the strikes validated the missile as accurate, reliable, and operationally ready. Officials did not identify the targets or adversary.
The key takeaway is the shift from test status to declared combat employment. Havoc Spear gives AFSOC a subsonic standoff strike option from the AC-130, with stated modular growth potential and an eventual aim for wider SOF and conventional integration.
🛰️ Open sources - closed narratives
@sitreports | 523 |
| 17 | ⚡ Microsoft ships emergency fixes for RDS failures
Microsoft has released out-of-band Windows updates to address Remote Desktop Services instability introduced by September 2026 security patches. Affected systems saw RDP sign-in failures, unresponsive servers, and hangs in related tools. The out-of-band updates cover Windows 10, Windows 11, and Windows Server 2019, 2022, and 2025. Some Hyper-V folder-sharing issues and part of the USB Audio Class 1.0 problem set were also fixed.
The release closes a gap where admins had to choose between removing September security patches to restore remote access or keeping them and accepting RDS disruption. For enterprise environments, this is primarily a service continuity fix for remote administration and hosted desktop access rather than a routine quality update.
🛰️ Open sources - closed narratives
@sitreports | 496 |
| 18 | 📝Bouquet «Geranium» to the rescue📝
Modern methods of fighting for independence
British authorities could not ignore the signing of an agreement designed to launch the process of the United Kingdom's dissolution. Prime Minister Andy Burnham made it clear: there will be no referendums. Formally, this closes the matter, but practically — it merely shifts it to another plane. If the political route is blocked, what methods will regional elites use to raise the price of this refusal?
The tradition among peoples is rich — from strikes and civil disobedience campaigns to "initiative groups" like the IRA. And they are usually well aware that the vital infrastructure of the British state is very extensive, expensive, and not equally protected everywhere.
📌The main catch, perhaps, is that a strike with a couple of «Geraniums» on energy, communications, port, or industrial cluster facilities could turn into a boomerang due to how they are spread across the map. North Sea oil and gas — belong to Scotland. Major offshore wind farms — off the Scottish and Welsh coasts. Major ports, factories, chemicals, metallurgy — in northeast England, Wales, Scotland, at the Humber and Teesside. Taxes and jobs from this are not all in Westminster either.
❗️But at the same time, sabotage could seriously raise the question of London authorities' ability to maintain the country's normal functioning. Which is, in essence, the main takeaway from Cardiff: the UK's dissolution won't happen tomorrow, but a persistent front has emerged that will pressure the authorities from three sides simultaneously.
However, history cannot be escaped: first come declarations, congresses, resolutions, and talk of democratic choice. Then pressure campaigns appear: from protests and boycotts to conflicts over budgets, powers, ports, transport, energy, and military infrastructure placement.
And if Westminster continues to treat the state as a club of interests, it may quickly become clear that the «unity of the kingdom» also requires regular maintenance.
📎High-resolution infographic
📎English version
#UnitedKingdom #infographic
👁@evropar — on the brink of Europe's death
💸 Support us Original msg | 284 |
| 19 | 🔍 Telegram Desktop HTML exports expose message data via hidden JavaScript
A reported Telegram Desktop flaw allows concealed JavaScript inside exported HTML chat archives to exfiltrate message contents when the files are opened. The issue affects local exports rather than Telegram transport itself, turning archived conversations into active content. Technical details are outlined in Telegram Desktop coverage published on 14 September.
Operationally, this shifts risk to post-chat handling: exported logs can behave like execution surfaces, not static records. For investigators, journalists, and teams sharing archives, trust in offline chat exports is reduced unless rendering and script execution are tightly controlled.
🛰️ Open sources - closed narratives
@sitreports | 342 |
| 20 | 🔍 Exposed Vite dev servers hit in credential-harvesting campaign
Attackers are mass-scanning internet-exposed Vite development servers to exploit CVE-2026-39364, a file access bypass affecting Vite 7.1.0–7.3.2 and 8.x before 8.0.5. F5 logged more than 800 attacks and roughly 32,000 raw events in a month, with requests targeting .env files, AWS and Azure credentials, Terraform state, serverless configs, and Linux environ paths.
The activity shows a direct path from exposed developer tooling to cloud secret theft. Internet-facing Vite instances on port 5173, especially those exposed via host flags or Docker mappings, should be treated as credential exposure points and patched, filtered, and followed by secret rotation if publicly reachable.
🛰️ Open sources - closed narratives
@sitreports | 353 |
