A VPN changes the public IP address that external servers see, but it does not interfere with how Windows records activity locally. Every command that runs, every process that spawns, and every network socket that opens is still tracked by the operating system. The misconception comes from confusing network anonymity with endpoint invisibility. Those are two completely different things. The VPN only affects the path traffic takes after leaving the machine. It does not silence the machine itself.
Windows records process creation events, PowerShell script blocks, network connections, and parent-child process relationships. Even when traffic is encrypted and routed through a VPN tunnel, the system still knows which executable initiated the connection. It knows the process ID, start time, command line arguments, and which user account triggered it. This is why forensic investigations focus heavily on endpoint telemetry instead of just firewall logs. If the endpoint is logging correctly, hiding behind a VPN does nothing to erase execution history.
In the terminal below, we first confirm that a VPN adapter is active and that routing priority is set through the tunnel interface. Then we inspect established TCP connections and identify which processes own those connections. We correlate the owning process IDs to actual executables using Get-Process, showing that PowerShell initiated outbound connections while the VPN was active. After that, we query Security Event ID 4688 to reveal process creation logs and confirm exactly when PowerShell was launched and what spawned it. Finally, PowerShell operational logs show recorded script block activity, proving that even with a VPN enabled, Windows preserved a complete execution trail.
🚨 Google Warns of Hackers Leveraging Gemini AI for All Stages of Cyberattacks
Source: https://t.co/eR5gegBVlg
Threat actors have begun leveraging Google's Gemini API to dynamically generate C# code for multi-stage malware, evading traditional detection methods.
HONESTCUE operates as a downloader and launcher that queries Gemini's API with hard-coded prompts to fetch self-contained C# source code.
This code implements stage-two functionality, such as downloading payloads from URLs hosted on CDNs like Discord, without leaving disk artifacts. Threat actors integrate Gemini across phases, from reconnaissance to tooling.
#cybersecuritynews
🌌 Starlink for Kobane – Internet from Space Connecting the World
Starlink is a satellite internet from SpaceX, delivering high-speed internet anywhere – no cables or towers needed.
#kurdtech#starlinkforkobane#inovation4peace
🚨 Apple shipped emergency updates after confirming exploitation of a zero-day in dyld.
The bug (CVE-2026-20700) could allow attackers to execute arbitrary code on vulnerable Apple devices.
🔗 Read: https://t.co/rzNLjfhHAP
Fixes extend across iOS, macOS, visionOS, and legacy platforms.
‼️ The database of https://t.co/wFJUUdo1Si, a hacking-focused AI platform, has been leaked with over 19,000 unique user records posted for download.
The exposed data includes emails, user IDs, priority scores, and subscription details containing payment methods, customer IDs, subscription status, billing amounts, currency, tier levels, token allocations, and Stripe payment metadata.
🐧 Researchers uncovered SSHStalker, a Linux botnet using IRC for control and mass SSH compromise.
It exploits 16 legacy kernel flaws to infect unpatched systems, wipes logs, and maintains silent persistence.
🔗 Details → https://t.co/Hzbt0HNToO
What is Cybersecurity?
Cybersecurity protects systems, networks & data from attacks, fraud and cyber espionage.
Modern security combines Zero Trust, AI-driven threat detection, cloud security & incident response to stop threats proactively.
#CyberSecurity#TechNews#Ai#Future
🚨 Windows Remote Desktop Services 0-Day Vulnerability Exploited in the Wild
Source: https://t.co/KgLUC6AIWu
Microsoft has patched CVE-2026-21533, a zero-day elevation of privilege vulnerability in Windows Remote Desktop Services (RDS) that attackers are exploiting in the wild to gain SYSTEM-level access.
The flaw stems from improper privilege management and was addressed in the February 2026 Patch Tuesday updates released on February 10.
It requires no user interaction and affects the unchanged scope, impacting confidentiality, integrity, and availability at high levels. The vulnerability arises from flawed privilege handling in RDS components.
#cybersecuritynews #vulnerability #microsoft
Cybersecurity is the future.
4M+ open jobs • 12–15% annual growth • €70K–120K salaries
KITN connects Kurdish tech talents across Europe in AI, Data Science & Cybersecurity – building careers, mentoring leaders & shaping the future.
Join the network → @kitn.eu
#kurdtech
⚠️ Singapore’s cyber agency says China-linked UNC3886 targeted all four national telecom operators.
Attackers used a firewall zero-day and rootkits to access parts of critical systems. Espionage activity was contained. No service disruption or customer data theft found.
🔗 Read → https://t.co/T4MpV65h9n
🚀 We are live!
Introducing KITN – Kurdish Informatics & Technology Network.
Our mission:
Connect Kurdish students, alumni & professionals in tech across Europe.
AI • Data • Cyber • Software • Startups
Follow & join the movement #KurdishTech#AI#Cybersecurity#DataSciene