God I love Microsoft so much
This is yet another thing we can abuse for malware. Imagine someone mounts their phone with this and we have a payload that steals data from their phone
Thank you so much Microsoft, this is awesome
Nebula Security is now backed by Y Combinator.
We’re celebrating by bringing you the world’s first Android 17 root demo — “IonStack”, a url click can let attacker fully control your phone.
This is not only an Android root demo. We’re bringing you a full chain browser-to-kernel exploit with two 0-day vulnerabilities affecting Firefox before v151.0.2 and all Linux distros in 15 years. "IonStack" demonstrates how bad actors can control your phone by sending a malicious URL, but good news, Nebula Security found it before attackers do.
Both 0-day were found by our code scanning agent, VEGA, overshadowing any vulnerabilities found by Mythos or any scanner you name it.
VEGA has demonstrated its extraordinary capability in finding critical bugs in the world’s most complicated software: operating systems and browsers. It can spot the same vulnerabilities in your codebase too.
VEGA support full scan and incremental scan that can integrated into your CI/CD flow. We launched VEGA within YC companies and received overwhelmingly positive feedback. Now it is open to all enterprise customers in private beta.
Book a demo with us: https://t.co/eXHKhnE8gC
> be pakistan government
> develop custom malware
> used to target high profile targets
> used against indian military and political ppl
> named SHEETCREEP
> send indian ppl file
> UAE-India Strategic Partnership Week
> malicious .lnk file
> .lnk executes malicious c sharp code
> does a bunch of stuff for persistence
> exfiltrates data to Google Sheets
> Google Sheets can be used to control victim pcs
> pakistan gov hardcodes google c2 sheet
> PAKISTAN GOV HARDCODES GOOGLE C2 SHEET
> embed access key in payload
> EMBED ACCESS KEY IN PAYLOAD
> malware nerds find it
> look inside
> find all targets from pakistan gov
> monitoring 91 ppl they think important
THEY STARTED SO STRONG. WHY DID YOU HARDCODE EVERYTHING. YOU BURNED YOUR OPERATION
https://t.co/PcCeV05cu3
🇵🇰 A threat actor on an underground forum is claiming to have leaked approximately 39GB of alleged data linked to multiple Pakistani government, military, and intelligence-related organizations.
According to the post, the alleged dataset may include restricted or classified documents, as well as personal details related to military personnel and government officials.
The actor references multiple organizations, including:
• Ministry of Defense
• National Counter Terrorism Authority (NACTA)
• Military Intelligence (MI)
• Federal Investigation Agency (FIA)
• Counter Terrorism Department (CTD)
• Civil Defence
• Intelligence fusion and threat assessment centers
The claims also mention:
• Internal security-related documentation
• Counterterrorism-related material
• Personnel information
• Sensitive operational references
If authentic, this would represent a highly sensitive national security-related exposure with potential geopolitical implications.
Potential risks may include:
• Exposure of intelligence and defense operations
• Targeting of military or government personnel
• Espionage and counterintelligence risks
• Increased geopolitical cyber tensions
• Disinformation and psychological operations
• Operational security (OPSEC) failures
Government and defense-sector leaks are particularly concerning because even partial authenticity can:
• Aid hostile intelligence collection
• Reveal organizational structures
• Expose internal workflows and relationships
• Support future cyber or physical targeting efforts
At this time, the claims remain UNVERIFIED and no independent confirmation has been established.
Due to the sensitive nature of the allegations, all shared information should be treated cautiously until validated by official or technical analysis.
#Pakistan #CyberSecurity #ThreatIntelligence #DataLeak #Government #Military #DailyDarkWeb #DarkWeb #InfoSec
Nothing to see here, move on !
#whatsapp#privacy#infosec
US Closes Probe Into Claims Meta Can Access Encrypted WhatsApp Messages - Bloomberg https://t.co/JFv0uSXdDt
The Pakistan Airports Authority (PAA) appears to have been compromised, their email infrastructure being used to distribute password-protected ZIP archives containing a previously undocumented malware.
The payload is disguised with an .MCU file extension, masquerading as a legitimate Excel document. The phishing campaign leverages a lure titled “Telecom Sector Collaboration for Aviation Modernization,” clearly tailored to target the telecommunications industry within Pakistan.
Interestingly, I found an easter egg inside the remote host, the threat actor behind the campaign claims affiliation with both “Dark Samurai APT” and OceanLotus (APT32). They even included a Vietnamese message: “Ocean Lotus is now a dark samurai coming to thank our Japanese brothers.” (Take this with salt but still very entertaining)
I looked quickly to the dropped malware (DismCore.dll) which is executed via DLL Side loading and mainly designed for data exfiltration and remote access. Malware was named by actor as "Xcheckinx".
IOCs:
Domains Used to Download the XML payload
caapakistaan[.]com
Domain Download the Lure Excel File
datamero[.]org
XML payload + HTML Easter Egg
56e926b816c062078f8acac3bd28e2759447d07d9fb6e1d31d2a032121c110c6
Main Payload
de804318db0cd5ef242e2d0e4e66e322f2fcee5ad41787b264d1576323b35eec
C2 Server
d11d6t6zp1jvtm[.]cloudfront[.]net
@Graham__Hancock There is a concept in Islamic sufism called fiddai (one who sacrifices) that is a path to "dying before you die", making you a witness for divine affairs.
Also used in other spiritual paths.