Visualização normal

Antes de ontemStream principal

🧠 CENTRAL DE INTELIGÊNCIA OSINT + de 14.000 recursos gratuitos verificáveis

Diretório de Ferramentas Gratuitas para o Brasil 2026: IA, Dados Abertos, Consulta Pública e OSINT | RDS
Use a barra de pesquisa do blog para localizar outras categorias e artigos publicados.

Diretório de Ferramentas Gratuitas para o Brasil (2026)

IA generativa · automação · dados abertos governamentais · consulta pública · OSINT

RDS @RDSWEB · Joinville/SC · osintbrasil.blogspot.com

Nota de transparência editorial: este diretório é curado e verificado por fonte, não uma lista genérica "de 3.000 links" gerada de uma vez — isso normalmente produz nomes inventados e URLs quebradas. Em vez disso, indexamos recursos reais por categoria e citamos os catálogos oficiais que sozinhos já reúnem milhares de itens verificáveis (ex.: o Portal Brasileiro de Dados Abertos possui 13.651+ conjuntos de dados catalogados). Este é o Volume 1 — atualizado continuamente à medida que novas fontes são verificadas.

1. IA generativa gratuita 30+

Texto e conversação

FerramentaLimite gratuitoMelhor uso
ChatGPT (OpenAI)GPT-4o mini, mensagens limitadasUso geral, iniciantes
Claude (Anthropic)Mensagens limitadas, contexto 200KDocumentos longos, análise
Google GeminiFlash 2.0 praticamente ilimitadoEcossistema Google, pesquisa
Perplexity AIBusca rápida ilimitada + Pro limitado/diaPesquisa com fontes citadas
NotebookLM (Google)100 notebooksEstudo, resumos de documentos
DeepSeekPraticamente ilimitadoRaciocínio e matemática
Microsoft CopilotIntegrado ao Windows/OfficeProdutividade Office

Imagem, vídeo e áudio

FerramentaLimite gratuitoCategoria
Ideogram40 imagens/diaImagens com texto, logos
Leonardo AI~150 tokens/dia (~20 imagens)Geração de imagens
Microsoft Designer15 boosts/dia + ilimitado lentoDALL-E 3 gratuito
Canva AI50 gerações/mêsDesign integrado
Playground AI100 imagens/diaVolume e brainstorming visual
SunoCréditos gratuitos mensaisCriação de músicas com letra
ElevenLabsCota mensal gratuitaSíntese de voz
CapCutEdição gratuita com marca d'água opcionalEdição de vídeo automática

Código e desenvolvimento

FerramentaLimite gratuitoOpen-source
GitHub Copilot Free2.000 completions + 50 chats/mêsNão
Gemini Code Assist1.000 requisições/diaNão
Cursor Free2.000 completions + 50 premium/mêsNão
Aider / Continue.devIlimitado (própria API)Sim

Produtividade e apresentações

FerramentaUso
Otter.aiTranscrição automática de reuniões
Notion AIResumos e escrita dentro do Notion
GammaApresentações profissionais com IA
Tome / Beautiful.aiStorytelling visual e slides automáticos

2. Automação e no-code 280+

O repositório awesome-n8n-templates (GitHub, enescingoz) reúne sozinho 280+ templates gratuitos de automação n8n prontos para Gmail, Telegram, WhatsApp, Slack, Discord, Google Sheets, OpenAI e dezenas de outras plataformas — atualizado continuamente.

FerramentaModeloUso
n8nOpen-source, self-host gratuitoAutomação visual de workflows
awesome-n8n-templates (GitHub)280+ templates gratuitosBiblioteca pronta de automações
awesome-workflow-automation (GitHub)Lista curadaComparação de engines de automação
Zapier (free tier)100 tasks/mêsIntegração entre apps sem código
Node-RED / HuginnOpen-source, self-hostAlternativas gratuitas ao n8n

3. Dados abertos governamentais (Brasil) 13.651+

O Portal Brasileiro de Dados Abertos (dados.gov.br) catalogava, na última verificação, 13.651 conjuntos de dados — de licitações e contratos a dados educacionais, energéticos e de fiscalização — todos gratuitos e reutilizáveis.
FonteMantido porConteúdo
dados.gov.brGoverno Federal / CGU13.651+ datasets catalogados de todos os órgãos
Portal da TransparênciaCGUGastos públicos, convênios, servidores
Dados Abertos da Câmara dos DeputadosCâmara FederalProposições, votações, despesas parlamentares (API)
Dados Abertos do SenadoSenado FederalMatérias legislativas, votações, senadores
Base dos DadosOrganização sem fins lucrativosDatasets públicos BR tratados e prontos para SQL/BigQuery
catalogos-dados-brasil (GitHub, dadosgovbr)Comunidade Open Knowledge BrasilMapeamento de catálogos de dados abertos estaduais/municipais
aplicativos-dados-brasil (GitHub)Comunidade Open Knowledge BrasilApps e visualizações construídos sobre dados públicos BR

4. Consulta pública gratuita (jurídico/empresarial) 15+

FerramentaFonte oficialUso
Consulta CNPJgov.br/receitafederalSituação cadastral e Cartão CNPJ gratuito
Consulta processual via DJEN/CNJConselho Nacional de JustiçaProcessos por CPF/CNPJ/nome em todos os tribunais
Jusbrasil — consulta processualJusbrasilBusca gratuita em 90+ tribunais por CPF/CNPJ/nome
e-SAJ / PJeTribunais estaduais/federaisConsulta processual direta por tribunal
Diário Oficial da União (in.gov.br)Imprensa NacionalPublicações oficiais gratuitas e pesquisáveis

5. OSINT e investigação digital 40+

CategoriaFerramentas
Username / contaSherlock, Maigret, WhatsMyName, Social-Analyzer, Namechk
E-mail / vazamentosHolehe, Epieos, Have I Been Pwned, Hunter
InfraestruturaShodan, Censys, DNSDumpster, OWASP Amass, crt.sh, theHarvester
Link analysisMaltego, SpiderFoot
Forense de imagemExifTool, Aperi'Solve
GEOINTGoogle Earth Pro, Wayback Machine

Guia completo de metodologia, pivoting e SOCMINT já publicado no blog — veja o artigo "Ferramentas OSINT 2026: Guia Avançado de SOCMINT, Pivoting e IA Aplicada".

6. Meta-diretórios para expansão contínua

Estas são as fontes-mãe que permitem este diretório crescer com integridade até milhares de itens, sem inventar links:

  • The Ultimate OSINT Collection (start.me, curadoria @hatless1der) — 200+ recursos organizados por categoria
  • awesome-n8n-templates (GitHub) — 280+ automações gratuitas
  • dados.gov.br — 13.651+ datasets governamentais catalogados
  • githubbrasil.com — projetos e mantenedores open-source brasileiros
  • catalogos-dados-brasil (GitHub, Open Knowledge Brasil) — catálogos estaduais e municipais de dados abertos

7. Volume indexado nesta edição

14.000+

recursos gratuitos verificáveis, somando os catálogos oficiais citados (dados.gov.br + awesome-n8n-templates + hub OSINT + ferramentas listadas individualmente nesta página)

O número cresce a cada catálogo novo verificado — este diretório é atualizado por edições (Volume 1, Volume 2...), nunca de uma vez sem checagem de fonte.

☕ Apoie este conteúdo gratuito via PIX
47988618255
📲
  • ✇Security | CIO
  • Cursor customers will lose access to OpenAI coding models in November
    OpenAI will stop AI coding platform Cursor from accessing its models from November 12, following the acquisition of Cursor parent Anysphere by Elon Musk‘s SpaceX. “Today, we notified SpaceX that we intend to wind down our contract providing OpenAI models to Cursor, with a proposed shutoff date of November 12, 2026,” the company wrote in a blog post. That shutoff, the company added, was based on its concerns that SpaceX will not use its technology in accordance with i
     

Cursor customers will lose access to OpenAI coding models in November

31 de Agosto de 2026, 12:48

OpenAI will stop AI coding platform Cursor from accessing its models from November 12, following the acquisition of Cursor parent Anysphere by Elon Musk‘s SpaceX.

“Today, we notified SpaceX that we intend to wind down our contract providing OpenAI models to Cursor, with a proposed shutoff date of November 12, 2026,” the company wrote in a blog post.

That shutoff, the company added, was based on its concerns that SpaceX will not use its technology in accordance with its terms of service, citing what it described as a history of Musk’s companies violating contracts: “After Musk acquired Twitter, now part of SpaceX, the company broke⁠ the terms of our contract (alongside many others). Under oath earlier this year, Musk admitted⁠ that xAI, now also part of SpaceX, had violated OpenAI’s terms of service (terms which are similar to xAI’s own),” the company wrote.

OpenAI and Musk remain locked in a broader legal dispute, with Musk having sued OpenAI over its transition from a nonprofit-controlled organization to a for-profit structure and OpenAI countering with allegations over Musk’s conduct and competing AI ventures.

Enterprises and developers using OpenAI models within Cursor now have about 10 weeks to transition to other AI models within Cursor, or choose a new coding platform.

Swapping problem

That may not be easy.

While the 10-week timeframe might be enough to assess the impact and decide a path forward, it will not be a trivial operation, said Abhishek Satapathy, principal analyst at Avasant.

Even for those just swapping models and staying with Cursor, there will be effort required to validate the replacement against development workflows currently running on OpenAI’s models, Satapathy said.

“This includes repository-level coding, debugging, refactoring, test case generation, multi-file changes and tasks where an agent has to inspect a codebase, make a sequence of changes, run tests and correct its own errors,” he said.

The need for validation stems from differences in how AI models handle coding, reasoning, tool use and instructions.

Developers may find that prompts or agent instructions that work well with OpenAI models produce different results with another model, requiring enterprises to retune prompts and evaluations, said Manoj Chandra Jha, principal analyst at Nord-IQ Research.

That recalibration could translate into a short-term productivity dip as development teams rework prompts and workflows and adjust to how the replacement model behaves, echoed Bhupendra Chopra, chief revenue officer at IT consulting firm Kanerika.

For enterprises considering a move away from Cursor, the transition becomes more complex, primarily because swapping coding platforms would require retraining developers, rebuilding integrations and agent configurations, and repeating security and governance reviews that not only require time but also adds costs, Satapathy said.

Broader risks of AI vendor dependence

The added complexity of changing platforms points to a broader issue for enterprises: their dependence on AI model providers and the commercial relationships that determine where those models can be used.

“Enterprises can no longer assume that a model available through an AI coding platform today will always remain available. Acquisitions, contracts, competition or regulation can change this,” said Pareekh Jain, principal analyst at Pareekh Consulting.

“Enterprises should therefore support multiple models, regularly test alternatives and avoid making important workflows too dependent on one model,” Jain added.

Similar principles should apply to the coding platforms as well, according to Satapathy.

“Enterprises should consider whether prompts, agent configurations, evaluation methods and tool integrations can be reused when the underlying model changes,” Satapathy said.

There are broader risks for the vendors too, especially OpenAI.

While Cursor appears better positioned to retain customers because enterprises can continue using the platform with other models, particularly with Anthropic’s pledged support, OpenAI risks losing developer usage as customers move to alternatives such as Claude without having to change their coding environment, Satapathy said.

This article first appeared on InfoWorld.

  • ✇Cybersecurity News
  • Gemini Notebook Adopts Dynamic Quota System Do Son
    Google transitions Gemini Notebook to a dynamic quota system based on computational load, introducing a strict 5-hour rolling limit for users. Related Posts: OpenClaw Unleashes Massive Update AI Crawlers Burden git.kernel.org With Millions of Requests Judge Blocks Pentagon Anthropic Blacklist The post Gemini Notebook Adopts Dynamic Quota System appeared first on Daily CyberSecurity.
     

Gemini Notebook Adopts Dynamic Quota System

Por:Do Son
31 de Agosto de 2026, 09:30

Google transitions Gemini Notebook to a dynamic quota system based on computational load, introducing a strict 5-hour rolling limit for users.

Related Posts:

The post Gemini Notebook Adopts Dynamic Quota System appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • OpenAI Cuts Off Cursor Access to Its Models Following SpaceX Acquisition Do Son
    OpenAI will terminate Cursor's access to its AI models by November 12, citing Elon Musk's past contract violations following SpaceX's $60 billion acquisition of the company. Related Posts: Google Auto-Expands AI Overviews Sony and Warner Chappell Sue Anthropic uBlock Origin v1.74.0 Is the Final Version for Chrome Before Google's Delisting The post OpenAI Cuts Off Cursor Access to Its Models Following SpaceX Acquisition appeared first on Daily CyberSecurity.
     
  • ✇Krebs on Security
  • Two Alleged ‘TeamPCP’ Hackers Arrested in Australia BrianKrebs
    Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two men from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses
     

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

27 de Agosto de 2026, 08:04

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.

In a statement released today, the Australian Federal Police (AFP) said two men from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.”

The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect’s real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP’s self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing.

TeamPCP vaulted onto the cybercrime scene in late 2025, embedding malicious code in hundreds of open source software tools and extorting victims for profit. Members of the group made headlines by compromising corporate cloud environments using a self-propagating worm dubbed Shai-Hulud, which added malicious code to open source programs maintained by developers whose credentials at public code repositories like GitHub or NPM were phished or stolen.

Writing for Wired, journalist Andy Greenberg described TeamPCP’s core tactic as a kind of cyclical exploitation of software developers.

“The hackers gain access to a network where an open source tool commonly used by coders is being developed,” Greenberg wrote in May. “The hackers plant malware in the tool that ends up on other software developers’ machines, including some who are writing other tools intended to be used by coders. The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too. The cycle repeats, and TeamPCP’s collection of breached networks grows.”

TeamPCP also has practiced something akin to cyclical recruitment. In May, the source code for the third iteration of Shai-Hulud was published online, and TeamPCP soon after launched a contest offering $1,000 in virtual currency to whichever participant could conduct the largest supply chain operation using the worm’s code. According to the contest rules, participants were scored based on the number of weekly and monthly downloads of packages they compromised — directly incentivizing them to target the most popular code libraries.

A screenshot of a message from TeamPCP’s Telegram account, announcing the supply chain hacking contest. Image: dataminr.com.

“TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns,” the security firm Dataminr wrote. “The $1,000 XMR (Monero) prize is a recruitment floor and has been dismissed by the actor as ‘just like participation trophy,’ adding ‘if you find something good you will be paid way more,’ confirming the contest’s true function as talent identification and malicious access acquisition at scale.”

In March, TeamPCP executed a supply chain attack targeting AI infrastructure by compromising the code for LiteLLM, an open source AI gateway that connects users to more than 100 different large language models. A recent analysis by the security firm CloudSEK found TeamPCPs attack on LiteLLM harvested cloud service keys and other secrets from more than 2,500 organizations, including many of the world’s top technology companies.

In May, TeamPCP claimed credit for compromising at least 3,800 code repositories at the Microsoft-owned GitHub, after a GitHub developer installed a code extension that was compromised by TeamPCP’s malware.

MEET THE CYBERCATS

Security experts say TeamPCP is less of a hacker group than an amalgamation of threat actors from multiple cybercriminal gangs who sometimes work together toward similar goals.

“It is not a structured criminal crew with a single operator,” said Austin Larsen, a principal threat analyst with the Google Threat Intelligence Group. “It is a peer community of individually-skilled actors, with one clear center of gravity.”

That center of gravity is George Prepakis, an accomplished security researcher and self-described exploit developer who operates the Twitter/X profile @kernelstub. Earlier this year, @kernelstub tweeted a public invite link to a Matrix chat server he created and dubbed “Cybercats,” and TeamPCP and several other cybercrime entities have been using this server to communicate daily for the past several months.

A screenshot of the Matrix chat server “Cybercats,” whose members used hacker handles associated with multiple distinct cybercrime groups that have occasionally collaborated on a series of supply chain and data ransom attacks over the past nine months.

Kernelstub, like other administrators in the Cybercats chat, has been using his Twitter/X profile name as his handle in these Matrix communications, frequently tweeting references to other members and to conversations taking place in the Cybercats chat. In a number of cases, the corresponding X accounts for members of the Cybercats chat taunted cybercrime victims publicly before the incidents were reported in the news media.

The Cybercats administrator listed at the top of the screenshot above — “Boxturtle” — is a close associate of TeamPCP who has been tweeting about the group’s conquests under the name @xpl0itrsturtle. This handle corresponds to a data breach broker active on Breachforums and Darkforums who has been selling data stolen in a wave of recent breaches at automobile manufacturers, including BMW Group, Audi, Honda, Mercedes-Benz, Volvo and Toyota, as well as data allegedly taken from Snapchat and SportRadar.

The data leak site for the extortion group or handle “xpl0itrs.”

The Cybercats administrator “SeesawSec” in the screenshot above is the alias of whoever is behind the cybercrime group known as Fulcrumsec, which recently claimed credit for data extortion attacks against the pharmaceutical giant Novo Nordisk, the data broker LexisNexis, and Avnet, a Fortune 500 distributor of electronic components.

The data leak site of Fulcrum Security, a.k.a. Fulcrumsec.

The Cybercats administrator “@pcpcasper” also has been using a similar name on X to discuss TeamPCP’s attacks and victims. This person has an extensive message history on Telegram, where their messages and shared videos show @pcpcasper is an active and vocal member of the National Socialist Network, a neo-Nazi political organization based in Australia.

At one point in these chats, @pcpcasper shared videos and images of what they claimed was their cat, and several of those videos place this user in Western Australia. One source close to the investigation told KrebsOnSecurity that @pcpcasper was one of the two arrested, a claim supported by messages that @kernelstub posted online this morning.

The Cybercats member roster pictured above also features an administrator with the username “T,” which is short for the now-banned Twitter/X profile @pcpcats, the account operated by the self-described TeamPCP spokesperson who was arrested today. As we’ll see in a moment, @pcpcats also is from Western Australia.

By the time @kernelstub tweeted a public invite link to the Cybercats Matrix server, T/@pcpcats was posting only infrequently to the group chat, with other members often inquiring as to his whereabouts and well-being. The group’s collective concern related to @pcpcats’s tendency to blame his increasingly extended absences on the use of hallucinogens and other narcotics that kept him awake for days on end, but also caused him to crash in bed for several days after the highs wore off.

WHO IS THE TEAMPCP LEADER?

The Cybercats member @pcpcats has used multiple nicknames on the cybercrime forums, including EllisD25/LSD on Darkforums, BulkDMT on Breachstars, and Express on Breachforums. These accounts are linked because they all advertised the same Tox ID and/or Session ID as instant message contact handles in their cybercrime forum posts. BulkDMT was also known on the forums as DMT Host, which was a virtual private server (VPS) hosting service that was peddled on Darkforums and Breachstars.

DMT Host/EllisD25, posting on the English-language cybercrime community DarkForums in September 2025. Image: ke-la.com.

According to the cyber intelligence firm Intel 471, Express registered on Breachforums using the email address shitstickpp@gmail.com. Intel 471 finds Express posted on Breachforums across a two-month period in 2025 using four different Internet addresses located in South Africa. On July 30, 2025, Express announced on Breachforums they were selling access to 14 gigabytes of data stolen from South Africa’s State Information Technology Agency.

The threat intelligence platform Flashpoint recorded more than a year’s worth of messages from the TeamPCP leader’s alter ego on Telegram — Persy_PCP —  who claimed they split their life living between two countries [full disclosure: Flashpoint is an advertiser on this blog]. “I have these [files] as well, problem is these are in another country,” Persy_PCP explained to another user inquiring about a stolen data set in November 2025.

Later that month, Persy_PCP complained, “My whole country is racist and they want people like me dead.” Flashpoint records show BulkDMT shared in September 2025 that “this country is going to fucking starve when they take the farmers land,” a likely reference to white landowners in South Africa who claim to be targeted by an ongoing genocide campaign.

This tracks with public reporting on TeamPCP. Cyberscoop reported in June that Google had traced TeamPCP’s residential and mobile Internet address connections to South Africa, “indicating the primary operator was located there during at least some of its attacks.”

BulkDMT also shared on the group chat at Breachforums that they were recovering from an addiction to methamphetamine. “My life is kinda fucked rn [right now], but that’s fine and there isn’t really a point in pouring so much emotional energy into that fact, my parents had money but I unfortunately got really addicted to some things so I don’t get to benefit from that. As long as I continue to survive, stay sober, and move closer towards my goals that’s enough drive and meaning.”

The identity threat protection company SpyCloud finds shitstickpp@gmail.com shows up in the registration of an account called ChristmasSnow on the cybercrime community Raidforums in 2022. Nearly all of the Internet addresses used to access that account came from ISPs in Perth, Australia, SpyCloud found.

KrebsOnSecurity looked up all of those Perth IP addresses in passive DNS records maintained by DomainTools.com, and found one of them — 211.27.196.111 — for several years was used as a private file server by a family in Perth with the last name of Thomson. Those records show at least three hosts — ithomson.direct.quickconnect.to (a remote Synology server), kthomson0061.direct.quickconnect.to, and joshuawthomson39.myqnapcloud.com (a QNAP network storage device) — persisted at that address between 2022 and 2025.

Searching on “joshuathomson39” in the breach tracking service Constella Intelligence reveals an account at the freight forwarding company kwe.com created in the name of Joshua Thomson from Perth, Australia. The open source intelligence platform Epieos finds the phone number attached to that kwe.com account was used to register a Facebook profile for Josh Thomson, which says his family includes a brother named Ruben, his father Ian, and his mom Cindy.

That Facebook profile also says Josh and his family are originally from Pietermaritzburg, in KwaZulu-Natal, South Africa, but currently living in Cottesloe, a beach-side suburb of Perth. A search in DomainTools for Ian Thomson and Australia unearthed five domains by the same registrant, including securecomputing.au, thomson.org.au, and thomsonfamily.net.au. Ian Thomson is a dentist in Cottesloe, and a biography says he graduated from The University of the Witwatersrand in Johannesburg, South Africa.

Constella finds a joshua@thomson.org.au registered a number of accounts online, but Josh doesn’t seem to have much of a connection to dodgy cybercrime forums. His brother Ruben, on the other hand, has quite the presence on these communities, dating back to at least 2018. Constella reports ruben@thomson.org.au frequently reused the password “joshuathomson1,” and Constella further finds that password was used by just a handful of accounts, including yolosolo17@gmail.com and surfinup8@gmail.com.

According to Intel 471, surfinup8@gmail.com was used to register the user Yolosolo17 on the crime forum Altenen in 2018, and that user account was registered from the Perth address 110.141.230.15. On Altenen, Yolosolo17 advertised free web proxies, as well as the domain rubenthomson.com, which was at one point used to sell steeply discounted iPhones. DomainTools says rubenthomson.com was hosted at 110.141.230.15 and registered to surfinup8@gmail.com.

A cached copy of the domain rubenthomson.com from 2017 shows a login page underneath a banded stack of money. Image: archive.org.

SpyCloud reports 10.141.230.15 was used by the email address sheepstealing@gmail.com on Raidforums and surfinup8@gmail.com on Nulled, and that the same IP was used by the email addresses ian@thomsonfamily.net.au, jasper@yakuza.cc, and rubenthomson1@gmail.com. SpyCloud also shows that sheepstealing Gmail address is tied to the accounts Sheep420, YoloSolo117 and Yakuza.cc on Raidforums, and to the account “Sheep Stealing” on Hackforums. Intel 471 says sheepstealing@gmail.com was used to register the account DingoFlour on Breachforums in October 2023, as well Sheepx on Altenen.

Epieos reports that ruben@securecomputing.au is tied to an Airbnb account for Ruben, who described himself as a Web developer who went to school at the University of Western Australia and was living outside the country. “Hey, I’m Ruben, my friends call me Ellis. I’m a Perth creative who occasionally books rooms when visiting family and for photography.”

Epieos also finds sheepstealing@gmail.com registered an upwork.com profile under the name Ruben, who said his main skills are setting up secure server hosting solutions and PHP full-stack Web development.

“I’m familiar with Linux, working with relational databases (SQL),” the Upwork profile reads. “I also script in Python mainly for writing social media bots.”

The Upwork profile for Ruben Thomson in Cottesloe, Australia.

Epieos further discovered sheepstealing@gmail.com is connected to a Microsoft account for Ruben Thomson, and to a now-defunct GitHub account called XmasSnow/XmasSnowisBack that scammed people on the forums in 2022 by claiming to sell exclusive exploits for recently-released software patches (recall that shitstickpp@gmail.com was used to register a forum account named ChristmasSnow).

This same sheepstealing email address registered a Twitter/X account in 2026 called “Gone Fishing” that lists its location as South Africa. That Gmail account also left several reviews for businesses listed on Google Maps over the past seven years, but all of those establishments are located on the west coast of Australia.

Business reviews in Western Australia left by the Google account sheepstealing at gmail.com.

The people search service Pipl finds a 21-year-old Ruben Thomson in Western Australia who has a phone number ending in 979. A lookup on that number at Epieos reveals it is connected to a TikTok account under the name Ellis, and to a PayPal account in the name of Ruben Thomson.

Finally, a search on the name Ruben Thomson from Cottesloe at the Australian government’s record of registered businesses finds he has incorporated or served as an official in multiple companies created since 2024, including Secure Computing Solutions, Tensor Industries, and another entity ironically named OPSEC Express. Recall that Express was BulkDMT’s nickname on Breachforums.

Australian companies connected to Ruben Thomson. Image: abr.business.gov.au.

It’s ironic because OPSEC is short for the term “operational security,” which refers to techniques and behaviors used to obfuscate and compartmentalize one’s real-life identity online, and using your cybercrime handle as part of your own company name is very much the antithesis of that practice.

There is at least one other major opsec failure by Ruben that exposed a link to TeamPCP. In June 2025, someone using the name Ruben Thomson registered on HackerOne, a popular “bug bounty” program that seeks to reward and recognize researchers who agree to work with affected software vendors to help fix the flaws before publishing about their findings. What was Ruben Thomson’s chosen HackerOne username? Deadcatx3, a nickname that has been flagged by multiple security firms as an alias used by TeamPCP.

The HackerOne profile for “Ruben Thomson” uses the nickname Deadcatx3, which multiple security firms have concluded is an alias used by TeamPCP. Image credit: flare.io.

INTERVIEW WITH ELLIS

In early July 2026, not long after having discovered clues about Ellis’s real life identity, KrebsOnSecurity interviewed the TeamPCP leader via Signal, where he was remarkably open about his activities and personal struggles [for the sake of simplicity, the TeamPCP spokesperson will be referred to from here on as Ellis].

Ellis claims he stopped doing cybercrime for TeamPCP in March 2026 — just before the attacks that compromised LiteLLM — and that at least one other individual has taken over the group’s leadership since then. Ellis shared that a year earlier he had just completed the latest in a series of detox and sobriety programs, and was two months sober when he reconnected with some old friends from the malware development scene.

“One year ago I needed help monetizing some [GitHub credentials], I was two months sober and needed a distraction and something to keep busy as well as people to speak to,” Ellis said. “I had largely disconnected from my old circle, they had become very toxic and I needed to get away from the substances. Previously I had done some mass exploitation campaigns and grew up doing [malware development] and [capture the flag] contests. There were some friends who were also vending but had stopped a while, and one of them introduced me to some chats where I posted access for sale.”

Prior to that, Ellis said, he was homeless and hopping between “some very unstable places.”

“Blackhatting is fun,” he said. “There are actual rewards and incentives to learn and you grow with your team. Without qualifications, no employer will even take the time to hear you out.”

Ellis claims he’s earned a grand total of about $20,000 for his activities with TeamPCP, and that it was never about the money or fame for him. Asked whether his experiences with TeamPCP might prepare him for gainful employment in a legitimate IT job, Ellis said he doubted it.

“I am nowhere close to a skill level where I am comfortable, and this would take maybe half a decade of further experience,” he said. “I no longer have to choose between rent and food for that I’m grateful and so are the team members.”

Ellis expressed no remorse over his cybercrime activities, and said he was grateful for the friendships and relationships built throughout his engagement with TeamPCP. The young hacker also seemed resigned to his fate, and told KrebsOnSecurity that he’ll accept the consequences if he’s ever arrested.

“If I’ve already been found out then its out of my control, I’ll make peace with that,” he said. “Honestly, I think someone like me needs a lot of help that prison just can’t provide. If I had the funds to study different parts of the field and closer guidance, this would have turned out differently. But that’s a pipe dream and we both know this.”

It is clear from reading Ellis’s posts to the group’s Matrix server chats that his struggles with sobriety are ongoing. On Thursday, June 25, Ellis told @kernelstub he was about to “trip” with his “homie.”

“What kind,” @kernelstub inquired.

“Ketty and some DMT,” Ellis replied, referring to the dissociative anesthetic ketamine and dimethyltryptamine (DMT), a powerful psychedelic compound that is found naturally in some plants but is also synthetically produced in underground lab environments. “There’s a little 2cb so we might throw that in the mix,” he continued, referring to another psychedelic compound by its chemical shorthand.

Roughly two weeks before his arrest, Ellis told KrebsOnSecurity he was ready to leave his life of crime behind and was prepared to turn himself in, but that in the meantime he was making plans to tie up loose ends.

Less than 24 hours later, the TeamPCP leader posted an image on Telegram showing a yellowish powdered substance in a baggie and on a scale, possibly synthetic DMT. The image shows the powder being weighed next to a series of small vape cartridges, two of which are open on the table in front of the photographer.

An image posted by the TeamPCP leader to Telegram, advertising his acquisition of some type of psychoactive substance, most likely a synthetic version of the powerful hallucinogen known as DMT.

The two defendants were arrested Wednesday morning. The AFP said the men face a combined 14 cybercrime offenses and are scheduled to appear in Perth Magistrates Court today.

Charlie Eriksen is a security researcher at Aikido Security who has closely followed TeamPCP’s cybercrime campaigns. Eriksen said TeamPCP are a good example of a new kind of threat actor that does not fit neatly into the usual categories.

“They are not a state actor, not quite organized cybercrime, and not purely ideological,” he said. “Their motivations seem to mix money, disruption, attention, and ideology.”

Eriksen said that historically there has always been a meaningful gap between reading about an attack technique and being able to reliably turn it into an operational campaign, but that large language models (LLMs) and artificial intelligence increasingly are helping threat actors to bypass that knowledge gap.

“You had to understand the research, adapt the code, troubleshoot it, build infrastructure around it, and then repeat that process across different targets,” he said. “LLMs have compressed that gap significantly.”

According to Eriksen, this creates an environment where threat actors suddenly have the ability to operate at significant scale without having developed the operational discipline that traditionally accompanies that level of capability. Put another way, it sets the stage for cybercriminals who are capable enough to cause significant damage, but not necessarily careful enough to understand or care about the consequences.

“They can be noisy, they can make mistakes,” he said. “They can leave evidence everywhere. They can take risks that a professional criminal group or intelligence service would consider completely unacceptable. But that does not necessarily make them less dangerous. In some ways, it can make them more dangerous.”

In a recent blog post, Eriksen called TeamPCP’s Shai-Hulud worm the “best thing to happen to supply chain security,” because it forced GitHub and other public coding platforms to erect new security safeguards.

In direct response to TeamPCP’s broad success at pushing poisoned versions of popular software packages, GitHub in late July introduced a three-day “cooldown” mechanism for Dependabot, the platform’s tool for auto-fetching newly shipped updates for any package dependencies. Cooldown periods are designed to help buy time for security tools and package maintainers to identify and remove any compromised versions. Other coding ecosystems like Python and various JavaScript platforms also added support for cooldown periods this year amid growing calls from security experts about the need for more widespread adoption of the safety feature.

Eriksen said TeamPCP’s legacy is that they achieved in the span of a few months what the supply chain security community has been unable to do for years.

“They managed to wake up Microsoft to the fact that they had become negligent in terms of security,” Eriksen said. “By compromising GitHub and stealing their source code, they humiliated Microsoft into action, making them finally act on what we had been asking them to do and take seriously for a while now.”

Update, 10:08 a.m. ET: A story this morning from ABC News in Australia confirms Ruben Ian Thomson of Cottesloe was one of the two arrested. The 23-year-old suspect thought to be @pcpcasper, Michael Gaebler, also was arrested in Perth. ABC News reports that Thomson was denied bail (Mr. Gaebler’s attorney reportedly did not request bail for his client), and that both men will be held in custody until their next court appearance on September 18.

  • ✇Cybersecurity News
  • GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public Do Son
    A GeoServer unauthenticated SQL injection (CVSS 9.8) is exploited in the wild. A public PoC reaches RCE. Patch GeoServer now. Related Posts: CVE-2026-71290: Apache HttpClient Flaw Lets Attackers Intercept and Modify Traffic (CVSS 9.1) PoC Discloses for CVE-2026-64849: watchTowr Sees Attacks on MLflow SSRF CVE-2026-75045: Unauthenticated Attacker Could Download YouTrack Database Backups The post GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public appeared first
     
  • ✇Open Source Intelligence Brasil
  • Tools para Facebook, Sowdust FB Search Builder osintbrasil.blogspot.com
    Sowdust: o construtor de buscas do Facebook que sobreviveu ao fim do Graph Search | RDS RDS @RDSWEB blog linkedin x OSINT · Ferramentas · SOCMINT Sowdust: a busca do Facebook que resistiu ao tempo Por RDS @RDSWEB · Investigação Digital Defensiva No post anterior falei sobre a ferramenta de busca no Facebook do IntelTechniques e como ela contorna o fim do Graph Search usando indexação externa. Hoje trago a ferramenta
     

Tools para Facebook, Sowdust FB Search Builder

Sowdust: o construtor de buscas do Facebook que sobreviveu ao fim do Graph Search | RDS
RDS @RDSWEB
OSINT · Ferramentas · SOCMINT

Sowdust: a busca do Facebook que resistiu ao tempo

Por RDS @RDSWEB · Investigação Digital Defensiva

No post anterior falei sobre a ferramenta de busca no Facebook do IntelTechniques e como ela contorna o fim do Graph Search usando indexação externa. Hoje trago a ferramenta que, na prática, virou o item mais citado em qualquer lista atualizada de OSINT para Facebook em 2026: o Sowdust Facebook Search Builder.

A diferença de abordagem é o que torna as duas ferramentas complementares, não concorrentes: enquanto o IntelTechniques busca conteúdo indexado por buscadores externos, o Sowdust monta URLs que apontam diretamente para os caminhos internos de busca do próprio Facebook que sobreviveram ao desligamento do Graph Search em 2019.

O que é e como surgiu

O projeto é mantido no GitHub sob o nome de usuário sowdust, descrito literalmente como um mecanismo de busca do Facebook que continua funcional depois do encerramento da Graph API. A ferramenta está disponível gratuitamente em duas URLs espelhadas — sowdust.github.io/fb-search e sowsearch.info — e é open source, sem custo de licença.

O funcionamento é simples de operar e complexo por baixo do capô: você seleciona os filtros desejados (tipo de conteúdo, palavra-chave, intervalo de datas, ID de perfil, de página ou de local), a ferramenta monta a URL de busca no formato que o Facebook ainda aceita processar, e você é redirecionado para os resultados dentro do próprio domínio facebook.com — não é um scraper, é um montador de consulta.

Por que isso importa na prática: o Facebook não documenta publicamente esses parâmetros de URL. Cada vez que a Meta altera algo na estrutura de busca, ferramentas manuais quebram — e é exatamente por isso que uma ferramenta mantida ativamente, como o Sowdust, vale mais do que decorar sintaxe de URL por conta própria.

O pré-requisito que ninguém pode pular: o ID numérico

A maior parte do poder do Sowdust só aparece quando você já tem o ID numérico do perfil, página ou grupo que está investigando — não o nome de usuário "bonito" da URL pública. Todo perfil, página e grupo do Facebook tem um identificador numérico de até quinze dígitos por trás da URL de fachada, e é esse número que funciona como chave real para as buscas avançadas: fotos enviadas pela pessoa, amigos visíveis para amigos em comum, locais marcados, atividade em anúncios.

Formas confiáveis de extrair esse ID:

  • Colar a URL do perfil em um serviço de lookup de ID dedicado (esses serviços trocam de domínio com frequência — vale ter mais de um salvo).
  • Abrir a página, usar "ver código-fonte" e procurar por userID ou profile_id — método manual que funciona mesmo quando os serviços de lookup estão fora do ar.

Onde entra no seu fluxo de investigação

  • Apuração de conduta: busca de postagens públicas do investigado contendo palavra-chave específica, sem depender do que ficou em cache de buscador externo.
  • Mapeamento de rede social: combinado ao ID numérico, permite localizar fotos em que a pessoa foi marcada mesmo quando não estão no álbum principal do perfil.
  • Due diligence corporativa: busca por local (ID de local) para reconstruir presença física de uma página comercial ao longo do tempo.
  • Verificação cruzada: usar o mesmo ID numérico como chave de busca em ferramentas complementares (IntelligenceX/WhoPostedWhat, que também usam o código-base do Sowdust) para triangular resultado antes de citar como achado.
Observação sobre login: algumas variações desse buscador (como a versão hospedada na IntelligenceX) exigem que você esteja autenticado no Facebook com uma conta ativa para que os resultados carreguem. Isso reforça um ponto de OPSEC que já sigo como padrão: use conta de investigação segregada, nunca sua conta pessoal, ao rodar esse tipo de busca.

O que já morreu e não deve mais aparecer no seu playbook

Vale o registro para quem ainda segue tutoriais antigos: StalkScan, Graph.tips e ExtractFace estão descontinuados. Se um material de treinamento recomenda essas três ferramentas, o material está desatualizado — o Sowdust é hoje a alternativa viva que ocupou esse espaço.

FerramentaStatus em 2026Substituto recomendado
StalkScanDescontinuadaSowdust FB Search Builder
Graph.tipsDescontinuadaSowdust FB Search Builder
ExtractFaceDescontinuadaSowdust FB Search Builder
CrowdTangleDesligada em 14/08/2024Meta Content Library (acesso restrito a pesquisa acadêmica via ICPSR)
Nota de metodologia e cadeia de custódia: como qualquer resultado obtido por URL crafting não-oficial, trate o Sowdust como ferramenta de descoberta — nunca como fonte de prova por si só. Documente com print datado, hash de arquivo e, quando for para uso processual, formalize via Data Certify e derivados, ou ata notarial, antes de citar o achado em laudo.

Referência

O projeto é mantido de forma aberta e gratuita no GitHub pelo desenvolvedor identificado como sowdust, com espelhos em sowdust.github.io/fb-search e sowsearch.info.

☕ ler mais no blog
gostou do conteúdo? apoie via PIX: 47988618255 (clique para copiar)
💬 falar com RDS no WhatsApp
  • ✇Krebs on Security
  • Who’s Tracking You? Use This New Service to Find Out BrianKrebs
    It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that
     

Who’s Tracking You? Use This New Service to Find Out

14 de Agosto de 2026, 08:24

It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

A Decryptads summary of the advertising partnerships declared by espn.com.

The newly launched decryptads.com says it is constantly scraping the files that websites and apps make publicly available to disclose the companies that are permitted to run ads or collect user data. These files include:

ads.txt: all of the adtech companies and data brokers that may run ads or harvest data from the site;
app-ads.txt: entities that can harvest data from or display ads on mobile and smart TV apps;
buyers.json/sellers.json: the entities buying, selling or reselling ad inventory for a given site or app.

Zach Edwards is chief research officer for DecryptAds and a threat researcher at the security company Infoblox. Edwards said he and two other founders decided the service was needed because the adtech data in these files is generally only useful when it can be cross-referenced to build a more complete picture of the advertising ecosystem for each website or app.

“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said. “It’s really built for a lot of privacy and security use cases that have been dramatically underserved.”

Those use cases, he said, include tracking down the source of malicious ads that try to foist malware on targeted users, identifying ad networks located in adversarial nations, and detecting the fast growing swarms of AI-generated slop websites and apps. And as decryptads.com demonstrates, these potential security and privacy threats are near impossible to detect just by viewing a single apps.txt or app-ads.txt file.

“Supply-chain integrity issues rarely live in a single file,” the site explains. “They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher’s authorized-seller list.”

A search in DecryptAds for the hugely popular sports network espn.com reveals 143 ad partners and 19 registered data broker domains are listed within its ads.txt and app-ads.txt files. That data broker information is gradually becoming available because four states — California, Oregon, Texas and Vermont — have recently passed laws requiring data brokers to register if they buy or sell data on consumers from those states. DecryptAds reports that almost half of those data brokers are collecting geolocation data from espn.com visitors who aren’t blocking ads, while another three disclose that they collect device fingerprints and sensitive personal information.

A visual representation of the complex ad supply chain declared by espn.com. Image: decryptads.com.

HIGH-RISK AD PARTNERS

DecryptAds also makes it easy to learn the beneficiaries and national origins of the advertising firms lurking in apps and websites, displaying a conspicuous warning when adtech partners of an app or website are based in “geo-risk” areas like China and Russia, or in countries with strong financial and political ties to both — such as Cyprus and the United Arab Emirates (UAE).

According to DecryptAds, espn.com works with four different advertising entities that are based in either Russia, China or the UAE, including the adtech firm Between Digital, which lists a New York address. However, the dossier on Between Digital flags them as a Russian firm, showing that their publisher offers (PDF) are processed through Alfa Bank, Russia’s largest private commercial bank and one of several financial institutions placed under U.S. sanctions in 2022 after Russia invaded Ukraine. KrebsOnSecurity sought comment from both Between Digital and the company’s founder, and will update this story in the event that either replies.

A search for several top U.S. military news websites — including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com and federaltimes.com — shows they all allow Between Digital to serve ads and track users, as well as two entities in the UAE and another in the ownership secrecy haven of Panama. DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.

The “Geo Risk” section of decryptads.com.

Pivoting on Between Digital’s app-ads.txt file reveals hundreds of domains featuring simple web-based games that are frequently interrupted by ads. Edwards said Between Digital’s own declarations show the company is listed as both a publisher and a reseller on approximately two-thirds of their portfolio.

“It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest,” Edwards told KrebsOnSecurity. “The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files.”

The Opera Web browser remains quite popular, and probably many users are unaware that since 2016 it has been majority owned and controlled by the Chinese company Kunlun Tech (the operational headquarters of Opera remain in Oslo, Norway).

Opera.com’s profile at DecryptAds identifies 27 registered data brokers collecting information, including 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia and one each in Hong Kong and Ukraine. DecryptAds makes clear, however, that these companies represent just seven percent of the adtech partners specified in Opera.com’s ads.txt and app-ads.txt files.

LEGAL DOSSIERS

One feature of DecryptAds that sent this author down multiple hours-long research rabbit holes is its Legal Dossier lookup, which takes several minutes for each search but eventually churns out oodles of useful information about who owns a particular domain or app, when it was registered, and any aliases or relationships it may have to adtech companies and other websites or apps.

For example, last month KrebsOnSecurity wrote about researchers from Bitsight who found that an extremely popular line of TV streaming sticks called H96 quietly rent out each user’s Internet connection to strangers. Bitsight also discovered that when these devices aren’t being used to stream pirated video content, they are spoofing themselves as mobile phones clicking ads on AI-generated slop websites.

Bitsight concluded that the same Chinese company that made several of the malicious apps common to all of these H96 streaming sticks — the Fengwo Group — also also ran the network of ads and AI slop websites being clicked on by tens of thousands of these devices that are pretending to be mobile phones.

Examples of ad landing pages linked to the Fengwo Group. These sites were designed to show ads only to H96 devices that were spoofing their device type as mobile phones. Image: Bitsight.

A DecryptAds legal dossier on the (now dormant) Fengwo Group domain name for the AI slop website pictured on the left in the screenshot above (medicalbeautyhub dot com) shows it shares a seller ID (1674071) with a gaming website — giacoloredstones[.]com — which features yet another seller ID (103488000).

Pivoting on that latter seller ID reveals hundreds of active websites within Russia’s Yandex ad system featuring extremely low-quality games or simple utilities that pepper visitors with ads.

QUIET REMOVALS

Edwards said that when advertising networks suspect a given advertiser is engaged in unauthentic clicks or displaying malicious ads, very often those networks will quietly remove the offender from their list of approved partners without letting anyone else know about their suspicions.

This practice, he said, makes it easier for dodgy adtech firms to avoid accountability and continue victimizing others. To address that visibility gap, DecryptAds features a quiet removals feed that records and correlates all of the sellers.json removals across ad exchanges for the same seller domain or name.

A screenshot of the Quiet Removals Feed at decryptads.com.

“The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public,” Edwards said. “The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. So if you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once.”

MALVERTISING AND AI SLOP

Malvertising, the term given to the practice of inserting malicious ads that foist malware or redirect visitors to phishing pages, remains an all-too-frequent occurrence in the modern adtech industry. But Edwards said these malicious ads are far more commonly found now on newly generated AI slop websites than on high traffic destinations that typically employ a variety of technologies and third party tools to quickly flag bad ads.

“None of these slop AI content farms are paying for that kind of protection,” he said. “They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don’t happen on espn.com or huffpost.com, but rather [on] some lower quality content farm and someone just went there because it came up in a search.”

Edwards said the AI slop websites are populated with machine-generated blog posts and images, and cover a wide array of themes from home improvement and decorating to food recipes, hunting, cars and consumer technology. He said organizations that get hit with malicious ads are often at a loss for what to do next, unaware that in most cases the answer is one of the entities listed inside the website’s ads.txt or app-ads.txt file.

“A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis,” he said.

Edwards maintains that truly getting a handle on the malvertising and AI slop problems will require more data-sharing by the major ad networks. Specifically, he says those platforms do not broadly share what’s known as the “supply chain object” or SCO, structured data attached to each advertising bid request that lets buyers see every seller, reseller and intermediary involved in passing an ad impression from the publisher to the final buyer.

“That SCO tells you who sold it or resold it, and who was the final entity that bought the impression that served that malware payload,” Edwards explained. “You may see the malicious zero-click redirection, but without the supply chain object — which is only served server side — you won’t know who targeted your people with malware and won’t have a way to try and prevent it properly. But if we can encourage the adtech industry to expose that SCO, it will get easier to find the culprit behind any one bad ad.”

DecryptAds also offers an application programming interface (API) that allows researchers to automate queries and integrate the site’s functionality into popular AI platforms.

WHAT CAN YOU DO?

The only sane reaction to the examples described above is to block all online ads outright. This approach is broadly endorsed by security experts because it also makes it more difficult for adtech firms and data brokers to build detailed profiles on you and track your movements around the web and in the real world.

However, much depends on how you normally prefer to browse the Internet, and how much trust you place in third party browser plugins and extensions. For those primarily surfing via a regular desktop or laptop Web browser, uBlock Origin Lite is an excellent free and well-maintained open source option. uBlock Origin also should work with mobile browsers like Firefox, but apparently only on Android-based devices.

Adblock Plus is a decent option for iPhone and iPad users. For power users, Adblock and uBlock Origin both support custom blocking rules from easylist.to, which publishes a frequently updated list that removes most advertisements from webpages.

The well established browser extension NoScript blocks all non-approved Javascript code, and it generally does a fine job blocking most ads from loading. However, script blockers like NoScript may not be suitable for average users who don’t enjoy constantly having to referee which scripts should be allowed to load so that each site displays properly.

More technically inclined/adventuresome readers should strongly consider a hardware approach to blocking ads at the local network level, because that is easily the cheapest, most secure and scalable way to do it. A tiny, low-cost and broadly available computer known as a Raspberry Pi can be turned into a powerful ad blocker for all devices on a local network when fitted with a microSD memory card and a free program called Pi-hole. Once you’ve set it up properly and changed your router’s network settings to use the Pi-hole’s DNS sinkhole and DHCP servers, it should prevent ads from displaying on any devices connected to that network.

Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to install on their devices. Many websites now push users to install a mobile app, supposedly in order to more fully access and enjoy the site’s services and content. But in my experience, they’re not doing this because the user experience is somehow way better on the app (as LinkedIn tries to convince us non-app users several times a week via email). On the contrary, I find most mobile apps to be horribly designed, annoying, and/or completely unnecessary, and when given the option I will almost always choose to interact with a website or service directly in a Web browser.

No, the cold truth is that big web destinations tend to get pushy with their apps because they make it easier for these companies to keep you on their platforms longer and to collect (and in many cases resell) far more precise data about who, what and where their users are. Also, companies pushing customers the hardest to install mobile apps always seem to liberally opt everyone in to having their data used to train large language models these days. So be cautious about the apps you install on your mobile devices (including any smart TVs!), and poke around their listings at DecryptAds if you want to learn more about their privacy practices and any relationships they may have to adtech firms.

  • ✇Krebs on Security
  • Microsoft Plugs Nearly 400 Security Holes BrianKrebs
    Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today. Image: Shutterstock, Mallika Home Studio. August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nea
     

Microsoft Plugs Nearly 400 Security Holes

11 de Agosto de 2026, 18:28

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

Image: Shutterstock, Mallika Home Studio.

August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes. Microsoft has attributed the recent patch deluge to vulnerability discoveries aided by artificial intelligence, and experts roundly agree that Windows users should get used to the idea of Patch Tuesdays (the second Tuesday of each month) covering hundreds of newly discovered security flaws.

Fully 42 of the 398 flaws that Microsoft patched today earned Redmond’s most-dire “critical” rating, meaning they are severe enough that malware or malcontents could exploit them to gain remote control over a Windows computer with little to no help from the user.

The sole known “zero day” bug fixed by Microsoft this month is CVE-2026-68820, a privilege escalation weakness in a core Windows component called afd.sys, which the security firm Automox describes as “the driver behind Windows socket connections on effectively every endpoint.”

“This isn’t a front-door bug,” Automox’s Landon Miles wrote in a Patch Tuesday blog post. “It’s step two in a chain: an attacker phishes their way into a low-privilege foothold, then uses the driver flaw to take the box. The 7.0 score reflects the high attack complexity, because race conditions are fiddly. The exploit has to be thrown over and over until the timing lands. Someone is clearly landing it anyway.”

CVE-2026-62832 is another privilege escalation flaw that Microsoft has labeled likely to be exploited; this flaw, in the Windows User Profile Service, may be related to the recent “LegacyHive” public disclosure from the prolific bug hunter known as Nightmare Eclipse. The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.

Other major software makers are likewise increasing their patch volumes and cadence thanks to AI, including Adobe which last month moved to twice-monthly security bulletins published on the 2nd and 4th Tuesday of each month. Cisco, Google, Mozilla and Oracle also are shipping updates far more frequently and abundantly.

By all accounts, AI is quite good at finding security holes in software. But for now at least, patching the resulting bugpocalypse remains a heavily human-centric endeavor, and the jury is still out on whether AI technologies will turn out to be as good at fixing vulnerabilities as they are at finding and exploiting them. This is an important question when one considers that these same AI technologies also are suggesting fixes for the vulnerabilities they find.

Researchers at 1Password recently examined what happens when different large language models (LLMs) generate vulnerability patches for newly disclosed, complex vulnerabilities. They found the LLMs produced patches that failed to fix the flaw or added a new weakness in the process (or both) more than half the time.

Ed Skoudis, president of the SANS Technology Institute, said his team has seen excellent results using AI to generate patches, provided there are humans in the loop to test the suggested fixes and push for iterative improvements.

“AI is rapidly becoming astonishingly good at finding vulnerabilities, but this research shows that fixing them is a very different problem,” Skoudis wrote in a SANS newsletter today. “Don’t expect one-shot AI patching to work reliably. Instead, iterate, test, challenge, improve, and verify. AI can be an extraordinary patching partner, but today it still needs a skilled human at the keyboard.”

Tyler Reguly at Fortra says while reports of Microsoft patching hundreds of vulnerabilities in one go have prompted some organizations to try to patch faster, it’s important to bear in mind that only one of the almost 400 bugs addressed today is known to be actively exploited. Reguly suggested security leaders check in with their teams to see how they’re handling the increasing workloads, which often involve testing fixes before deploying them in production environments.

“If you’re a chief security officer talk to your teams about how they are shifting or modifying their workflows to better accommodate the patching shift that we’re seeing and support them across various organizational units by enabling the changes they want to see made,” Reguly said. “There’s no need to rush these updates, no matter what various vendors and organizations try to tell you. You need to make sure that you are rolling out safe updates that will not negatively impact your systems.”

Speaking of the humans behind the keyboards, don’t neglect to backup your system and/or data before applying this month’s monster patch load. The day after each month’s Patch Tuesday is sometimes derisively referred to as Reboot Wednesday, but it generally doesn’t hurt to wait a few days to apply these huge update bundles because it sometimes takes a couple of days for the occasional misbehaving patch to get ironed out properly by Microsoft.

For a clickable, per-patch breakdown by severity and urgency, check out this roundup from the SANS Internet Storm Center.

Black Hat USA 2026: One GitHub Issue Could Compromise Major AI Coding Workflows

At Black Hat USA 2026, Novee found GitHub workflow flaws in Claude Code, Gemini CLI and Codex that enabled RCE, credential theft and agent control in pipelines.

Top 8 Penetration Testing Tools to Enhance Your Security in 2026

30 de Julho de 2026, 02:00

Compare the best penetration testing tools for 2026, including pricing, key features, use cases, and top picks for modern security teams today.

The post Top 8 Penetration Testing Tools to Enhance Your Security in 2026 appeared first on TechRepublic.

How to Make AI Tools Work Reliably for Growing Teams

Learn how growing teams make AI tools reliable with clear workflows, shared rules, secure systems, and repeatable processes that improve quality and speed daily
  • ✇Firewall Daily – The Cyber Express
  • ClickFix Attacks Drive UAC-0145 Cyber Campaigns, CERT-UA Warns Samiksha Jain
    The ClickFix attacks technique has become a key initial access method for the UAC-0145 cyber threat cluster, according to a new report from Ukraine's Computer Emergency Response Team (CERT-UA). The agency said the threat group, also tracked as Sandworm, APT44, Seashell Blizzard, and a subcluster of UAC-0002, has shifted its tactics during 2026, increasingly relying on fake CAPTCHA prompts and social engineering to compromise systems. CERT-UA said it has worked with Ukrainian cybersecurity agenc
     

ClickFix Attacks Drive UAC-0145 Cyber Campaigns, CERT-UA Warns

ClickFix Attacks

The ClickFix attacks technique has become a key initial access method for the UAC-0145 cyber threat cluster, according to a new report from Ukraine's Computer Emergency Response Team (CERT-UA). The agency said the threat group, also tracked as Sandworm, APT44, Seashell Blizzard, and a subcluster of UAC-0002, has shifted its tactics during 2026, increasingly relying on fake CAPTCHA prompts and social engineering to compromise systems.

CERT-UA said it has worked with Ukrainian cybersecurity agencies for several years to investigate the activities of UAC-0145. While the group previously relied on infected software installers distributed through torrent websites, recent campaigns have increasingly used ClickFix to trick users into executing malicious PowerShell commands.

ClickFix Attacks Emerging as Primary Initial Access Vector

According to CERT-UA, infections recorded during the spring and summer of 2026 frequently began when victims visited compromised websites displaying fake CAPTCHA pages. Users were instructed to copy and execute PowerShell commands in their terminal, a phishing technique commonly referred to as ClickFix.

The downloaded commands were designed to retrieve malicious files such as GHETTOVIBE, a Visual Basic Script (VBS) that establishes persistence by placing itself in the Windows Startup directory.

Once executed, attackers could deploy SCOUTCURL, a PowerShell reconnaissance tool capable of collecting information about the compromised system, including device specifications, installed software, browser data, and local files before exfiltrating the information.

CERT-UA also observed malware loaders including FLUIDLEECH, disguised as antivirus software, and LOADLOOP being used during these campaigns.

Backdoors and Data Theft Tools Widely Deployed

The report noted that attackers continue using malware families such as KALAMBUR, SUMBUR, and TAMBUR after gaining access to victim systems.

To maintain remote access, the group relied on legitimate utilities including OpenSSH and Tor, forwarding local network ports such as 445, 3389, and 22 to attacker-controlled infrastructure.

CERT-UA also found malware designed to steal messaging data from Signal and WhatsApp, with stolen information reportedly exfiltrated using RSYNC.

On infected systems examined during cyber defense operations, investigators additionally identified FREAKYPOLL, a Python-based backdoor distributed as compiled bytecode (.pyc), providing attackers with persistent unauthorized access.

Compromised Websites Used to Deliver Fake CAPTCHA Pages

During June and July 2026, CERT-UA analyzed more than ten compromised websites involved in ClickFix attacks.

Investigators found attackers using both the Cloaking.House service and custom malware called SMARTAXE to dynamically modify legitimate webpages. SMARTAXE retrieves remote domains from blockchain smart contracts through Ethereum's eth_call function before displaying fake CAPTCHA pages or redirecting visitors to malicious content.

CERT-UA warned that any website used in these attacks should be considered compromised, potentially through vulnerable content management systems (CMS), stolen credentials, web shells, malicious plugins, modified website scripts, or server-side backdoors.

The agency urged website administrators and hosting providers to strengthen website security and respond quickly to incident reports.

Android Malware Also Part of UAC-0145 Operations

The report also highlighted growing use of Android malware distributed through messaging applications.

Attackers were observed sharing APK files disguised as security or antivirus tools. One such malware family, tracked as COWARDDUCK, functions as a full-featured Android backdoor capable of collecting device information, contacts, files, and real-time geolocation.

The malware targets files from directories including DCIM, Documents, Downloads, Pictures, and Alarms while searching for formats such as DOCX, XLSX, PPTX, ZIP, RAR, JSON, and OVPN files.

According to CERT-UA, COWARDDUCK uploads stolen files through the Dropbox API while receiving commands from legitimate services including Steam Community and StockMemory domains through proxy infrastructure.

Microsoft Sees Global Rise in ClickFix Campaigns

Microsoft Threat Intelligence and Microsoft Defender Experts also reported that ClickFix campaigns have increased significantly since early 2024, targeting thousands of enterprise and consumer devices globally each day.

Microsoft said the technique commonly delivers malware such as Lumma Stealer by persuading users to copy and execute commands through Windows Run, Windows Terminal, or Windows PowerShell. The campaigns are often combined with phishing, malvertising, and drive-by compromise techniques that imitate trusted brands.

Because ClickFix attacks rely on user interaction rather than exploiting software vulnerabilities directly, Microsoft recommends organizations strengthen user awareness and apply security policies that restrict unnecessary use of command execution tools.

  • ✇Krebs on Security
  • Microsoft Patches a Record 570 Security Flaws BrianKrebs
    Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence. Nearly 60 of the bugs quashed in July’s Patch Tuesday earned a “critical” severity rating, meaning miscreants or malware cou
     

Microsoft Patches a Record 570 Security Flaws

14 de Julho de 2026, 16:22

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

A picture of a windows laptop in its updating stage, saying do not turn off the computer.

Nearly 60 of the bugs quashed in July’s Patch Tuesday earned a “critical” severity rating, meaning miscreants or malware could use them to seize remote control over a Windows device with little or no help from the user. Microsoft also addressed three zero-day flaws, including two that are already being exploited in the wild.

Two of the zero-day weaknesses allow an attacker to elevate their user rights on a Windows system, as do approximately 250 other elevation of privilege flaws fixed this month; they include CVE-2026-56155 — an Active Directory Federation Services bug — and CVE-2026-56164, a Microsoft Sharepoint vulnerability.

CVE-2026-50661 is a security feature bypass in Windows BitLocker that could allow attackers to gain access to encrypted data if they have physical access to the device. Microsoft said this bug has been detailed publicly, but that it is not aware of any active exploitation.

In a blog post on July 9, Microsoft Executive Vice President Pavan Davuluri wrote that Windows users will notice “a higher volume of security updates included in each security release” as a result of AI aiding in the discovery of vulnerabilities.

“The pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code, with new mechanisms that can accelerate both discovery and analysis,” Davuluri wrote.

Jack Bicer, director of vulnerability research at Action1, called attention to CVE-2026-48561, a remote code execution flaw in Microsoft Copilot (with a 9.6 CVSS threat score) that allows an unauthorized attacker to execute code over the network. Microsoft says an attacker could exploit this bug by hosting a malicious website that causes Microsoft Edge for Android to automatically send crafted prompts to Copilot when a user visits the site.

As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws. Microsoft has long labeled security bugs using its “exploitability index,” which is Redmond’s best guess as to how likely it is that attackers will be able to figure out a reliable way to exploit a given vulnerability.

But Satnam Narang, senior staff research engineer at Tenable, argues that Microsoft’s exploitability index needs to do a better job of shifting with the machine speed of discovery. For example, Microsoft originally gave this month’s SharePoint zero-day an exploitability rating of “less likely,” although the flaw was added to CISA’s Known Exploited Vulnerabilities list on July 1.

“Anthropic’s Red Team’s own findings for known vulnerabilities (n-days) revealed how fragile this system has become, with its Mythos Preview model being able to produce proof-of-concept exploits for 13 of 14 vulnerabilities that were rated ‘Exploitation Less Likely’ or ‘Exploitation Unlikely,'” Narang said. “What this means is that our way of looking at Patch Tuesday has changed, because the exploitability index is centered around humans, not AI tools, and as these tools continue to improve, defense needs to improve alongside it.”

Chris Goettl at Ivanti observed that the record patch numbers from Microsoft come as a number of other major software makers are increasing their patch cadence, including Adobe which announced today it is moving to twice-monthly security bulletins published on the 2nd and 4th Tuesday of each month (Adobe also cited AI for accelerating their patch cycles). Cisco, Mozilla and Oracle also are shipping updates more frequently, while Google’s patch batches in June 2026 totaled more than 900 security fixes, Goettl noted.

Backing up your Windows system and/or data is always a good idea before applying operating system updates. Given the volume of patches addressed this month it may be wise for end users to wait a few days before applying these fixes. It’s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.

Further reading:

Action1’s Patch Tuesday blog

Automox’s rundown

Keyword lists: Stop re-entering the same organizational context across every workflow

SOC and CTI teams spend a significant part of their day maintaining context that should already be there. The assets they monitor, the technologies they protect, the threat actors they track, this organizational knowledge gets re-entered manually across searches, rules, and requirements, duplicated across individual analyst workflows, and updated inconsistently when environments change. The intelligence keeps up with the threat landscape. The context that scopes it rarely does. That is why Intelligence Center 3.8 introduces Keyword lists, a capability that lets teams define organizational context once and apply it automatically across every workflow.

❌
❌