๐จ๐ฉ๐ช Russian intelligence fully compromised the Signal account of Germany's parliament speaker Julia Klรถckner by pretending to be Signal support.
She is the second-highest state official and shared a CDU executive Signal group with Chancellor Merz. His phone came back clean, hers did not.
The Signal hack goes way beyond Klรถckner. 300+ are confirmed German victims, including a top CDU MP and the ex-deputy chief of German foreign intelligence.
German counterintelligence says parliamentary group chats are likely being read live, right now.
The FBI and CISA peg global victims in the thousands.
She is the second-highest state official and shared a CDU executive Signal group with Chancellor Merz. His phone came back clean, hers did not.
The Signal hack goes way beyond Klรถckner. 300+ are confirmed German victims, including a top CDU MP and the ex-deputy chief of German foreign intelligence.
German counterintelligence says parliamentary group chats are likely being read live, right now.
The FBI and CISA peg global victims in the thousands.
๐คฃ28๐ญ6โค4๐3๐คฏ1
This media is not supported in your browser
VIEW IN TELEGRAM
โ๏ธ๐ซ๐ท Following the French government's ban on Windows and its replacement with Linux, French activists are now saying goodbye to Windows 10 and actively encouraging people to embrace freedom and use Linux instead of paying for an upgrade to Windows 11, citing privacy concerns.
๐25โค13๐ค6๐คฃ3๐ฉ1
Media is too big
VIEW IN TELEGRAM
๐จ๐ธ๐พ In 2019, a Syrian militiaman was handed a laptop and asked to repair it. Out of curiosity he clicked on a video file. What he saw froze him in place.
It was a video of Amjad Yousef committing a premeditated massacre.
Yousef lied to victims at the edge of a pre-dug pit in the street. "Run from the sniper," he shouted, sending them sprinting straight into his line of fire.
He personally shot dozens of them, one by one. At least 41 in the main leaked clip alone.
When it was over, he helped cover the pit, poured fuel on the bodies, and set them on fire, joking with colleagues the entire time.
Investigators link him to a wider operation that day that killed an estimated 288 civilians, women and children among them. He later admitted on record: "I killed a lot." "I took revenge." "I'm proud of what I did."
The video existed only because the killers filmed themselves as a trophy. It sat on an intelligence laptop for years.
The leaker passed 27 clips to a Syrian opposition contact in Paris. That contact rushed them to Prof. Uฤur รmit รngรถr at the University of Amsterdam.
รngรถr and Annsar Shahhoud spent years verifying the footage. Geolocation, OSINT, survivor and perpetrator interviews. They even confronted Yousef undercover through a fake pro-regime Facebook persona named "Anna."
The leaker then had to run for his life. He drove from Damascus to Aleppo, paid a $1,500 bribe to a colonel in the regime's 4th Division, and crossed no-man's land into opposition territory.
The crossing was delayed a day because the same colonel's unit was moving an illegal drug shipment along the same route. He eventually reached Turkey, then Europe.
In February 2022, the full evidence was handed to prosecutors in the Netherlands, Germany, and France. In April 2022, the Guardian and New Lines Magazine published the footage.
The world finally saw it. Systematic, pre-planned mass murder of civilians. Direct involvement of Assad's elite military intelligence. The killing machine.
Yousef went into hiding after Assad fell in December 2024. He was tracked for days across the Al-Ghab Plain of Hama before being arrested.
Thirteen years late, the man in the fishing hat is finally in cuffs.
It was a video of Amjad Yousef committing a premeditated massacre.
Yousef lied to victims at the edge of a pre-dug pit in the street. "Run from the sniper," he shouted, sending them sprinting straight into his line of fire.
He personally shot dozens of them, one by one. At least 41 in the main leaked clip alone.
When it was over, he helped cover the pit, poured fuel on the bodies, and set them on fire, joking with colleagues the entire time.
Investigators link him to a wider operation that day that killed an estimated 288 civilians, women and children among them. He later admitted on record: "I killed a lot." "I took revenge." "I'm proud of what I did."
The video existed only because the killers filmed themselves as a trophy. It sat on an intelligence laptop for years.
The leaker passed 27 clips to a Syrian opposition contact in Paris. That contact rushed them to Prof. Uฤur รmit รngรถr at the University of Amsterdam.
รngรถr and Annsar Shahhoud spent years verifying the footage. Geolocation, OSINT, survivor and perpetrator interviews. They even confronted Yousef undercover through a fake pro-regime Facebook persona named "Anna."
The leaker then had to run for his life. He drove from Damascus to Aleppo, paid a $1,500 bribe to a colonel in the regime's 4th Division, and crossed no-man's land into opposition territory.
The crossing was delayed a day because the same colonel's unit was moving an illegal drug shipment along the same route. He eventually reached Turkey, then Europe.
In February 2022, the full evidence was handed to prosecutors in the Netherlands, Germany, and France. In April 2022, the Guardian and New Lines Magazine published the footage.
The world finally saw it. Systematic, pre-planned mass murder of civilians. Direct involvement of Assad's elite military intelligence. The killing machine.
Yousef went into hiding after Assad fell in December 2024. He was tracked for days across the Al-Ghab Plain of Hama before being arrested.
Thirteen years late, the man in the fishing hat is finally in cuffs.
๐17๐ฉ4๐คช4โค2๐1
>be Dutch Justice Ministry
>2014, quietly sign a contract with Palantir
>hand it to the military border police
>plug it into the Advance Passenger Information system
>silently screen millions of Schengen flyers
>names, DOBs, nationalities, passport numbers, all of it
>years pass, no one knows
>Parliament asks the minister: "you using Palantir?"
>minister: "No"
>journalists FOIA the ministry anyway
>documents drop
>leaked invoice surfaces: six figures. for THREE months.
>internal emails show the minister KNEW about the contract while drafting the denial
>journalists, now holding the proof, ask the border police: "you using Palantir?"
>spokesperson, straight face: "never"
>journalist slides the documents across the table
>"ok actually we ran it from 2009 to 2015"
>constitutional law prof: "political mortal sin"
>Article 68 violated, the duty to inform Parliament
>ministry still won't say when the contract really ended
>or if it ended
>or what happened to the data on millions of passengers
>2014, quietly sign a contract with Palantir
>hand it to the military border police
>plug it into the Advance Passenger Information system
>silently screen millions of Schengen flyers
>names, DOBs, nationalities, passport numbers, all of it
>years pass, no one knows
>Parliament asks the minister: "you using Palantir?"
>minister: "No"
>journalists FOIA the ministry anyway
>documents drop
>leaked invoice surfaces: six figures. for THREE months.
>internal emails show the minister KNEW about the contract while drafting the denial
>journalists, now holding the proof, ask the border police: "you using Palantir?"
>spokesperson, straight face: "never"
>journalist slides the documents across the table
>"ok actually we ran it from 2009 to 2015"
>constitutional law prof: "political mortal sin"
>Article 68 violated, the duty to inform Parliament
>ministry still won't say when the contract really ended
>or if it ended
>or what happened to the data on millions of passengers
๐ญ12๐ฉ6๐คช2๐1๐1๐คฌ1
๐ฏ๐ต Japanese users are worried that X is damaging Japan's reputation by auto-translating "low-class" Japanese posts and pushing them onto your timeline, because X's algorithm rewards ragebait.
According to them, the feature mostly amplifies mockery of tourists, contempt for foreign cultures, and complaints framed in ways that were never meant to leave the island. All of it now surfacing in English, Spanish, Portuguese, and beyond, translated and pushed to users worldwide.
For decades, Japan's image abroad as a polite, harmonious society was protected by most foreigners not being able to read Japanese. The ugly corners of Japanese social media stayed local. The polished tourism ads went global.
That's gone now.
According to former TV presenter and YouTuber Kanon Aoki, X's auto-translation feature is pushing the rawest, most hostile Japanese posts straight into foreign timelines.
Aoki's frustration is direct. A minority of what she calls "low-class" Japanese users are now the loudest Japanese voices abroad, simply because the algorithm translates whatever gets engagement. The quiet majority stays invisible. The trolls go viral worldwide.
The result: foreigners' perception of Japan is shifting in real time, and there is no stopping it.
According to them, the feature mostly amplifies mockery of tourists, contempt for foreign cultures, and complaints framed in ways that were never meant to leave the island. All of it now surfacing in English, Spanish, Portuguese, and beyond, translated and pushed to users worldwide.
For decades, Japan's image abroad as a polite, harmonious society was protected by most foreigners not being able to read Japanese. The ugly corners of Japanese social media stayed local. The polished tourism ads went global.
That's gone now.
According to former TV presenter and YouTuber Kanon Aoki, X's auto-translation feature is pushing the rawest, most hostile Japanese posts straight into foreign timelines.
Aoki's frustration is direct. A minority of what she calls "low-class" Japanese users are now the loudest Japanese voices abroad, simply because the algorithm translates whatever gets engagement. The quiet majority stays invisible. The trolls go viral worldwide.
The result: foreigners' perception of Japan is shifting in real time, and there is no stopping it.
1๐คฃ33โค4๐ฉ4๐ฅ2๐ค1๐ฏ1
Proton CEO Andy Yen warns that the global push for age verification is the quiet death of online anonymity, because every passport scan, selfie, and biometric uploaded for "verification" inevitably ends up leaked, hacked, or monetized.
He argues Big Tech and governments cannot be trusted to act as gatekeepers, and the only real protection for ID data is to never collect it in the first place.
Source: https://proton.me/blog/keep-age-verification-from-killing-anonymity-online
He argues Big Tech and governments cannot be trusted to act as gatekeepers, and the only real protection for ID data is to never collect it in the first place.
Source: https://proton.me/blog/keep-age-verification-from-killing-anonymity-online
๐35โค15๐4๐ฅ3๐ฉ2๐1
๐จ๐ช๐บ The European Commission is about to steal your search history in one of the largest forced data grabs in the history of the open internet, and almost nobody is talking about it.
The scope is staggering:
๐ด Every query you type
๐ด Every voice and photo search
๐ด Every autocomplete you accept
๐ด Your language, your device
๐ด Your country pinned to a ~3kmยฒ grid
๐ด Every result you saw, every link you hovered
๐ด Every click and scroll
๐ด The full chronological order of your search sessions
Meaning the European Union now knows your:
๐ด Health symptoms
๐ด Pregnancy
๐ด Sexual orientation
๐ด Political views
๐ด Religious beliefs
๐ด Financial distress
๐ด Legal trouble
๐ด Addictions
๐ด Affairs
Under the proposed measures for DMA Article 6(11), Google would be ordered to ship the daily search behaviour of hundreds of millions of Europeans to multiple third parties through a daily API feed. Any approved "online search engine," AI chatbots included, would get five years of access.
The things people only ever type when they think no one is watching. All of it now scheduled to flow daily into an open-ended list of third parties scattered across the European Union.
Brussels promises "anonymisation." The reality is a thin technical veneer that has been broken in academic literature again and again for over a decade. Search behaviour is a fingerprint. Stripping a name does not change that.
Mass data leaks become inevitable. Every new beneficiary is a new attack surface, and every annual audit is a year of silent exposure between checks. The 2025 Discord vendor breach already showed how fast 70,000 government IDs can leak through a single weak link. Now imagine that link holding Europe's search history.
Surveillance without consent becomes the default. Hundreds of millions of EU citizens never agreed to have their queries packaged and shipped to companies they have never heard of. The legal fiction of "anonymisation" cannot manufacture consent that was never given.
Behavioural search data is a goldmine for phishing, blackmail, social engineering, and corporate espionage.
Foreign intelligence services get a back door without effort. They do not need to breach Google. They only need to compromise the weakest name on the beneficiary list. One insolvent startup. One compromised contractor. One approved entity quietly acquired by a hostile state.
In the name of "competition," the EU is about to manufacture a permanent, distributed, daily-refreshed copy of Europe's collective search history. A surveillance dataset Brussels itself would never approve if any other government tried to build it.
The public consultation closes Friday, May 1, 2026 at 23:59 CEST. The final binding decision lands July 27, 2026.
After that, the door does not close again.
Tag your MEPs! File a response! Make noise!
The scope is staggering:
๐ด Every query you type
๐ด Every voice and photo search
๐ด Every autocomplete you accept
๐ด Your language, your device
๐ด Your country pinned to a ~3kmยฒ grid
๐ด Every result you saw, every link you hovered
๐ด Every click and scroll
๐ด The full chronological order of your search sessions
Meaning the European Union now knows your:
๐ด Health symptoms
๐ด Pregnancy
๐ด Sexual orientation
๐ด Political views
๐ด Religious beliefs
๐ด Financial distress
๐ด Legal trouble
๐ด Addictions
๐ด Affairs
Under the proposed measures for DMA Article 6(11), Google would be ordered to ship the daily search behaviour of hundreds of millions of Europeans to multiple third parties through a daily API feed. Any approved "online search engine," AI chatbots included, would get five years of access.
The things people only ever type when they think no one is watching. All of it now scheduled to flow daily into an open-ended list of third parties scattered across the European Union.
Brussels promises "anonymisation." The reality is a thin technical veneer that has been broken in academic literature again and again for over a decade. Search behaviour is a fingerprint. Stripping a name does not change that.
Mass data leaks become inevitable. Every new beneficiary is a new attack surface, and every annual audit is a year of silent exposure between checks. The 2025 Discord vendor breach already showed how fast 70,000 government IDs can leak through a single weak link. Now imagine that link holding Europe's search history.
Surveillance without consent becomes the default. Hundreds of millions of EU citizens never agreed to have their queries packaged and shipped to companies they have never heard of. The legal fiction of "anonymisation" cannot manufacture consent that was never given.
Behavioural search data is a goldmine for phishing, blackmail, social engineering, and corporate espionage.
Foreign intelligence services get a back door without effort. They do not need to breach Google. They only need to compromise the weakest name on the beneficiary list. One insolvent startup. One compromised contractor. One approved entity quietly acquired by a hostile state.
In the name of "competition," the EU is about to manufacture a permanent, distributed, daily-refreshed copy of Europe's collective search history. A surveillance dataset Brussels itself would never approve if any other government tried to build it.
The public consultation closes Friday, May 1, 2026 at 23:59 CEST. The final binding decision lands July 27, 2026.
After that, the door does not close again.
Tag your MEPs! File a response! Make noise!
๐ฑ33โค8๐คฌ3๐ฅ2๐ค2๐1๐คฃ1
๐จ SaaS platform ClickUp, used by 85% of the Fortune 500, has been leaking customer emails through its homepage for at least 465 days, and counting.
ClickUp has a $4 billion valuation. They are SOC 2 Type 2, ISO 27001, ISO 27017, ISO 27018, ISO 42001, and PCI DSS certified. The fix takes about 90 seconds.
Security researcher
weezerOSINT noticed a hardcoded Split[.]io SDK token sitting in plain text inside ClickUp's production JavaScript bundle. The bundle loads before you log in. View source, copy key, send one unauthenticated GET request, and 4.5MB of ClickUp's internal configuration is exposed: 959 customer emails and 3,165 internal feature flags.
The customer list consists of Home Depot. Fortinet, who sells enterprise firewalls. Tenable, who makes Nessus, the vulnerability scanner half the industry runs on. Autodesk. Rakuten. Mayo Clinic. Permira. Akin Gump. A Microsoft contractor. 71 ClickUp employees. Government workers from Wyoming, Arkansas, North Carolina, Montana, Queensland, and New Zealand.
It gets worse, ClickUp has a flag named "enable-missing-authz-checks." It is active in production. It lists five ClickUp API endpoints the company itself documented as having no authorization. They wrote down their own holes in a config anyone with a browser can read.
At first disclosure, another flag carried a live ClickUp API token tied to Fairfax County Public Schools, one of the largest school districts in the US, serving 180,000 students. The token pulled 1,066 staff records, including Chief Financial Services data. ClickUp removed that one token. They never rotated the SDK key that exposed it.
While that report rotted, the same researcher found a second bug. ClickUp's webhook API has zero SSRF protection. Reported via HackerOne on April 8, 2026. Status: "New." 19 days, zero response.
The original report was filed by weezerOSINT on January 17, 2025 (!). The key is still live. The emails still drop with one GET. ClickUp has had 465 days to rotate a single token. Zero response...
The fix is one click in the Split[.]io dashboard... ClickUp still hasn't replied to the researcher.
Original post of the researcher: https://x.com/weezerOSINT/status/2048662702957134199?s=20
ClickUp has a $4 billion valuation. They are SOC 2 Type 2, ISO 27001, ISO 27017, ISO 27018, ISO 42001, and PCI DSS certified. The fix takes about 90 seconds.
Security researcher
weezerOSINT noticed a hardcoded Split[.]io SDK token sitting in plain text inside ClickUp's production JavaScript bundle. The bundle loads before you log in. View source, copy key, send one unauthenticated GET request, and 4.5MB of ClickUp's internal configuration is exposed: 959 customer emails and 3,165 internal feature flags.
The customer list consists of Home Depot. Fortinet, who sells enterprise firewalls. Tenable, who makes Nessus, the vulnerability scanner half the industry runs on. Autodesk. Rakuten. Mayo Clinic. Permira. Akin Gump. A Microsoft contractor. 71 ClickUp employees. Government workers from Wyoming, Arkansas, North Carolina, Montana, Queensland, and New Zealand.
It gets worse, ClickUp has a flag named "enable-missing-authz-checks." It is active in production. It lists five ClickUp API endpoints the company itself documented as having no authorization. They wrote down their own holes in a config anyone with a browser can read.
At first disclosure, another flag carried a live ClickUp API token tied to Fairfax County Public Schools, one of the largest school districts in the US, serving 180,000 students. The token pulled 1,066 staff records, including Chief Financial Services data. ClickUp removed that one token. They never rotated the SDK key that exposed it.
While that report rotted, the same researcher found a second bug. ClickUp's webhook API has zero SSRF protection. Reported via HackerOne on April 8, 2026. Status: "New." 19 days, zero response.
The original report was filed by weezerOSINT on January 17, 2025 (!). The key is still live. The emails still drop with one GET. ClickUp has had 465 days to rotate a single token. Zero response...
The fix is one click in the Split[.]io dashboard... ClickUp still hasn't replied to the researcher.
Original post of the researcher: https://x.com/weezerOSINT/status/2048662702957134199?s=20
๐คฃ17โค5๐ฑ3
โผ๏ธ The arrogance of the official French Ministry for Europe and Foreign Affairs account is beyond comprehension, something you'd only expect from the Russian MFA.
Ridiculing a just concern about the European Commission's proposal that puts millions of Europeans at risk. The 'French Response' account was launched to fight disinformation, instead it is now mocking citizens for reading the Commission's own published documents...
Ridiculing a just concern about the European Commission's proposal that puts millions of Europeans at risk. The 'French Response' account was launched to fight disinformation, instead it is now mocking citizens for reading the Commission's own published documents...
๐คฌ18๐คฃ3๐ญ3๐2๐คช2โค1
โผ๏ธ๐จ BREAKING: Wiz got access to millions of GitHub repositories across users and organizations using one git push.
CVE-2026-3854: git push -o options injected into an internal header split by semicolons, parsed last-write-wins.
GitHub patched production in 6 hours.
Wiz published an article detailing what they've done: https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
CVE-2026-3854: git push -o options injected into an internal header split by semicolons, parsed last-write-wins.
GitHub patched production in 6 hours.
Wiz published an article detailing what they've done: https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
๐ฑ7โค2๐คฃ1
โผ๏ธ๐ฌ๐ท Greece is moving toward a total ban on anonymous accounts on social media. Every post, every reply, tied to a verified legal identity.
Greece's Digital Governance Minister Dimitris Papastergiou confirmed today that the plan is meant to fight "toxicity," "hoaxes," and "character assassinations."
Mister Papastergiou says modern "digital democracy" should be "inspired" by Ancient Greece, where citizens openly expressed their views.
He apparently forgot the parts of Ancient Greece involving secret ballots, ostracism shards, and pseudonymous political pamphlets. The Athenian Assembly invented anonymous voting precisely because public attribution is dangerous.
Source: https://www.euractiv.com/news/greece-to-ban-anonymity-on-social-media/
Greece's Digital Governance Minister Dimitris Papastergiou confirmed today that the plan is meant to fight "toxicity," "hoaxes," and "character assassinations."
Mister Papastergiou says modern "digital democracy" should be "inspired" by Ancient Greece, where citizens openly expressed their views.
He apparently forgot the parts of Ancient Greece involving secret ballots, ostracism shards, and pseudonymous political pamphlets. The Athenian Assembly invented anonymous voting precisely because public attribution is dangerous.
Source: https://www.euractiv.com/news/greece-to-ban-anonymity-on-social-media/
๐ญ13๐ฉ9๐3๐คฃ3๐จ3โค2๐คฌ1
โ๏ธ๐บ๐ธ๐ฎ๐ฑ Intuit, the US tech giant behind TurboTax, lets employees wear IDF uniforms to work and take months off to fight Israel's wars.
Last month, Intuit data analyst Tom Yacobi joined an all-hands Zoom call in his full IDF uniform.
Roughly 100 million Americans use TurboTax.
Source: https://www.donotpanic.news/p/exclusive-the-us-tech-giant-where
Last month, Intuit data analyst Tom Yacobi joined an all-hands Zoom call in his full IDF uniform.
Roughly 100 million Americans use TurboTax.
Source: https://www.donotpanic.news/p/exclusive-the-us-tech-giant-where
๐จ20โค9๐คฌ6๐ฉ4๐ญ4๐ฅ3๐1๐1๐ฏ1