🇨🇿 Claimed Cyber Attack: Czech Technical University
A threat actor group LunarisSec claims to have targeted:
🎓 Czech Technical University
🧩 Shared content suggests:
• Alleged access to internal data
• Screenshots containing sensitive information
• Public propaganda-style messaging
⚠️ At this stage, the claim remains unverified
🚨 Potential risks:
• Exposure of student / staff data
• Credential leaks leading to further compromise
• Follow-on phishing or impersonation campaigns
Organizations in the education sector should:
• Monitor for leaked data or credentials
• Enforce MFA across all systems
• Review access logs for anomalies
#CyberAttack #DataBreach #ThreatIntel #CyberSecurity #EducationSector
Czech Republic 🇨🇿 - Slavia Pojišťovna has allegedly suffered a data breach resulting in the theft of 150GB of sensitive insurance documents, customer communications, and medical records. https://t.co/r90xCjwIj1
Mullvad was banned on British TV. And then? And then this underground ad got banned by the government body Transport For London.
The argument was clear: you cannot encourage people to engage with a banned TV commercial.
Yeah, so pretty much, like, there is this really sketchy company in Israel named "Paragon". Paragon sells a "product" called GRAPHITE.
Let me explain the background and why this is very silly.
GRAPHITE spyware which allows "customers" to remotely access peoples cell phones and monitor their instant messaging applications such as WhatsApp
It is spyware. It is sometimes called Mercenary Spyware because it is primarily used by governments to spy on political enemies, journalists, and activists.
Very little is known about Paragon, GRAPHITE, and their "customers". However, it was publicly noted by the Trump administration in January, 2025, to be purchased by the United States government and to be used to aid ICE.
Furthermore, in September 2025 the Trump administration noted the usage of Graphite to aid the United States against "domestic terrorist organizations" such as "ANTIFA".
ICE acting director Todd Lyons noted using GRAPHITE to monitor anti-ICE protestors to track "ringleaders and professional agitators".
Citizen Lab and other civil rights organizations have documented the usage of GRAPHITE against individuals in Australia, Canada, Cyprus, Denmark, Israel, Singapore and (unsurprisingly) the United States. It is believed the Canadian government actively uses GRAPHITE in Ontario.
Okay, so why does all of this matter? Yeah, it's super fucked up. But today representatives from Paragon accidentally leaked GRAPHITE screenshots ... ON LINKEDIN. Dawg, that image in the background IS GOVERNMENT FUCKING SPYWARE
It shows phone numbers in Czechia, apps, accounts, media on the phone, "interception status", and phone numbers extracted. THEY LEAKED IT BY ACCIDENT ON LINKEDIN WHILE TAKING SELFIES
Reported phishing domains via a Trusted Reporter Program = Instant takedowns.
Public status page showing who reported it.
Same group getting burned repeatedly.
My inbox had… feedback 😄
After two phishing domains were flagged to us, we decided to take a closer look 👀...
...and found something very familiar on the same cluster of domains.
A criminal group once again has acknowledged our accurate listings, this time by dedicating a domain just for the occasion.🏆
Flattered? Hmm maybe. Effective? Absolutely. 💪
Someone just submitted a ticket asking why their laptop is running slow.
I remote in. They have 3 Chrome windows open with 60+ tabs total.
I close all but 5 tabs. Computer runs fine now.
I write in the ticket: "Resolved - Optimized system memory allocation and cleared background processes."
They reply: "Wow, thank you! What was wrong?"
I reply: "Just some resource management issues. Should be good now."
I didn't lie. I just used technical language to describe "you had way too many tabs open."
If I say "close your tabs," they'll feel scolded. If I say "optimized memory allocation," they'll feel helped.
Same result, better optics.
Also, they'll probably open 60 tabs again next week and submit another ticket.
And I'll "optimize" it again.
This is called job security.
@Touk3n@ParadiseCzech@matheew1525@KulichHonza Nevím co si chceš poslechnout, tvoje vnímání reality je na stejné úrovni už od puberty. Možná až jednou vylezeš všem ostatním z prdele tak ti to dojde, někdy v důchodku.
@WillRiches@zachrip_ @limepurp_ @leetify That's not the case, they are abusing tracking template, you can put 2 domains in the field one tracking and one real URL. right click on the ad and see data-pcu field. See the same method here https://t.co/oA84YTXV2g