Cybersecurity expert Ken Underhill reports from CrowdStrike on the disruption of the 20-year-old Sality botnet and what security teams need to know.
The post CrowdStrike Disrupts Sality Botnet After More Than 20 Years appeared first on TechRepublic.
Cybersecurity expert Ken Underhill reports from CrowdStrike on the disruption of the 20-year-old Sality botnet and what security teams need to know.
The post CrowdStrike Disrupts Sality Botnet After More Than 20 Years appeared first on TechRepublic.
Cybersecurity expert Ken Underhill reports from CrowdStrike on the disruption of the 20-year-old Sality botnet and what security teams need to know.
The post CrowdStrike Disrupts Sality Botnet After More Than 20 Years appeared first on TechRepublic.
Welcome back, aspiring investigators!
We recently updated our article on ShadowBroker, which a lot of you liked. The latest release brought some new features and made the dashboard even richer.
But ShadowBroker is resource intensive and might need you to allocate a good chunk of resources to your VM, which not all systems have. Instead, there’s Osiris and it can do similar things without any installation. You can run it in the browser or host it on your Kali. Both versions are identical.
Osiris is a global intelligence dashboard that aggregates live flight tracking, CCTV, earthquake monitoring, conflict zone mapping and 24/7 news feeds. It’s made to give you situational awareness across multiple intelligence domains. The tool was built with Next.js 16 and MapLibre GL and every data point is rendered via WebGL for 60fps performance even with thousands of concurrent entities on screen.
Let’s start with the live version. It’s available here.
The world looks busy once you enable all the data layers on the left side of the screen.

There’s a huge number of cameras available around the world that are free to access. They are usually scattered across different websites and don’t look nearly as good as they do on a map. The dashboard has integrated a big number of them, marked with green dots on the map.

Here’s a camera in Toronto. Looks empty at 5 am.
All kinds of aircraft and maritime vehicles can be tracked. Not only that, you can do a deep dive on the intel available for each one. Below you can see we picked a random flight over the UAE and the dashboard pulled up the company it belongs to, Tim Clark who is the CEO and some publicly known information on him.

You can do similar things with other objects on the map.
So if you’re monitoring military activity in a certain region, that can come in handy.

There are different data assets you can display by clicking the database icon on the right side of the screen. The data is relevant for various places, but mostly for the US.

Above you can see the critical infrastructure in New York (red) and nationwide (yellow).
Wars, tensions and threats are differentiated by color and notes are assigned to each with a severity level.

When someone loses, someone else wins. Osiris can do some Market AI overview, which you obviously shouldn’t take as legit advice. But you can see it does some basic analysis and warns of potential price spikes.

All kinds of satellites are available on the dashboard and they can also be tracked. Here you can see Starlink flying over the Atlantic and Canada.

Finally, you can view malware threats and attacks on the map. There was a big node in China linked to a lot of attacks, with more scattered around the rest of the country.

Although the live version is stable and its uptime is good, you might still want to run it locally. It’s pretty easy to set up:
kali > sudo apt install npm
kali > git clone https://github.com/simplifaisoul/osiris.git
kali > cd osiris
kali > npm audit fix --force
kali > npm run dev

Then it’ll be available at http://localhost:3000

As you can see, there are different platforms available for different setups. Having compared the two, ShadowBroker looks richer and more professional, but Osiris hosts a live version you can use without any installation and it already has most of what you’d want to test. The installation itself is quick and easy and the dashboard consumes way fewer resources than ShadowBroker. Test it yourself and see what you like.
You can learn more with us! Get our Cybersecurity Starter Bundle II and unlock WiFi Hacking, Python for Hackers, Radio Basics and other training.
The post Open Source Intelligence (OSINT): Using Osiris for Global Intelligence first appeared on Hackers Arise.

When AI Breaks Out of the Sandbox What Happens When AI Escapes? AI assistants are gaining unprecedented access to the inner workings of businesses, but that trust comes with one...
The post Innovator Spotlight: Rubrik Zero Labs appeared first on Cyber Defense Magazine.
A new phishing platform called “JWR” gives attackers real-time control over social engineering attacks, according to researchers at Cisco Talos. The kit livestreams the phishing page to the attacker as the victim is entering information, allowing the attacker to steer the victim’s experience and maximize the damage.
Google’s Threat Intelligence Group (GTIG) is tracking a voice phishing (vishing) campaign that’s targeting hedge funds and financial firms. The researchers attribute the attacks to “UNC6671,” an extortion group formerly known as “BlackFile.” The attackers pose as IT staff informing employees of urgent, mandatory migrations.
Phishing is still the top initial access vector, accounting for more than half of cyberattacks observed during Q2 2026, according to a new report from Cisco Talos.

Widespread Infrastructure Breaches and Novel AI Threats Several significant security breaches and new exploitation patterns are highlighted in the Check Point Research threat bulletin, which was released on August 24,...
The post Check Point Threat Brief: Critical Infrastructure Breaches and Emerging AI Attack Surfaces appeared first on Cyber Defense Magazine.
Social engineering remains a central part of modern cyberattacks, according to a new report from CrowdStrike. Attackers are increasingly turning to voice phishing because it bypasses traditional security controls and leaves little forensic evidence, since the social engineering takes place over the phone.
We all know they’re watching us. But we don’t know who they are, nor why nor how they are doing it.
The post Surveillance – Everything You Wanted to Know, But Were Afraid to Ask appeared first on SecurityWeek.
Researchers at Microsoft warn that phishing emails are still the top initial access vector, with more than 2 billion phishing threats detected each month during the second quarter of 2026.
Welcome back, investigators!
The world is moving fast and it’s hard to keep up with everything happening around us. Not long ago, news from foreign places could take days or weeks to arrive. Now it’s different. Planes, ships, satellites, news and basically everything else is indexed and on the internet. The only problem is there are so many services and this fragmentation can drain your focus fast. But all these things can be integrated into one platform that runs locally.
We want to talk about ShadowBroker today. The developers did a great job making the tool professional, so it does deserve your attention.
ShadowBroker is an OSINT dashboard designed to collect a wide variety of public intelligence feeds into its map interface. It visualizes live information from different sources, which includes aircraft and maritime tracking, satellite orbit data, reports on world conflicts and so much more.
The developers built it using Next.js for the frontend and MapLibre GL for rendering the interactive mapping layer. FastAPI and Python are used for the backend.
Before we start working with the dashboard, we need to set up a couple of things first. The tool does support different OS, but we’ll use Kali.
ShadowBroker needs Docker and Docker Compose to be installed on the system.
Here are the commands that will help you set things up:
kali > sudo apt update
kali > sudo apt install docker.io
kali > sudo systemctl start docker
kali > sudo systemctl enable docker
kali > sudo apt install docker-compose
kali > sudo usermod -aG docker $USER
kali > newgrp docker

When you run these commands, you might be asked to restart different services. Press “Ok” and wait for the installation to complete. After the installation is complete, restart your Kali.
When your Kali boots, the Docker service should already be running. Now we can install ShadowBroker:
kali > git clone https://github.com/BigBodyCobain/Shadowbroker.git
kali > cd Shadowbroker
Once you’re in its directory, you need to run Docker commands with root privileges, otherwise it will throw an error:
kali > sudo su
root > docker compose pull
root > docker compose up -d

It will take a few minutes to install. Time spent on waiting really depends on you hardware and internet speed. It might take roughly 10 minutes. When Docker is done, see if ShadowBroker is up:
root > docker ps

You should see its containers in the output. Your system will keep them running in the background every time you boot.
Now we are ready to test it. Make sure you have allocated enough resources to your Kali VM to let it run smoothly. Open your browser and put this in the search bar: http://localhost:3000 (or try http://127.0.0.1:3000 if it doesn’t open anything).

When you open it for the first time, it will ask you for API keys. These keys are optional and you can skip this part. It will also offer you the option to hook up an AI agent to parse through the data and find correlations, but there is already enough data without it.

On the left side, there is a panel with many Data Layers with information that can be enabled or disabled. They include military flights, private jets, commercial aircraft, maritime vessels, satellite tracking, seismic activity and other global monitoring feeds. The list continues to expand.
It may feel overwhelming at first to work with the dashboard, so there is a legend with icon references. You can find it at the top of the left side, it has a small book icon.

News alerts appear on the lower right side of the interface, categorized by their level of importance.

When significant events occur in a particular region, the platform aggregates related news articles and shows them as yellow clusters on the map. You can open these clusters and see the headlines with links that lead to original sources.

Red clusters contain information collected from Telegram. You can see them scattered across the globe. Quite often they have media attached to them.

There is also Threat Intercept, these are big banners with alerts that you see on the screen in different regions. You can click and see more detailed information

The recent update brought military bases to the map. Here are some of them near the Strait of Hormuz

Antennas and Metastatic nodes are also available in the dashboard. You can tune in or send a message.

Satellites orbiting the Earth have different purposes. Some of them are used for weather forecasting, others give us communication services. There are also some used for recon, military and scientific missions. If you enable the satellite layer, you can see them moving across the planet.

GPS jamming can happen for several reasons, including military exercises, electronic warfare operations or just experimental testing.

Here you can see parts of Romania being jammed near the capital.
The dashboard has several categories of aircraft, including military planes, tracked VIP aircraft and commercial flights.

Some aircraft are tagged with additional information that identifies their owner. The one above belongs to the government of Morocco. You can look up specific individuals in the search bar. For instance, searching for the President of the United States will show the location of his aircraft if he’s flying somewhere.
The satellite captures are updated on a daily basis. They can be useful for environmental monitoring and weather observation.

You can play with different layers under Satellites to see other things. For example, here is VIIRS Nightlight by NASA.

OSINT is generally about connecting many small pieces of publicly available information into one thing. It’s an arduous thing to do, since you have to jump from tab to tab and find ways to piece it all together. ShadowBroker brings all that aggregated and prioritized information into one platform. The developers have been taking good care of the project for almost half a year now since they published it. New things keep getting integrated, expanding the amount of data available for analysis. Given how simple it is to set up, it’s worth giving it a shot.
If you want to improve your OSINT skills, consider our OSINT training. Those who need assistance in finding the truth, don’t hesitate to reach out to us at hackers-arise@protonmail.com. We will conduct an investigation for you.
The post Open Source Intelligence (OSINT): Tracking World Events with ShadowBroker first appeared on Hackers Arise.
Attackers are using compromised hotel Wi-Fi routers to redirect users to Microsoft 365 phishing sites, according to researchers at ReliaQuest. The attacks were observed in multiple U.S. cities, as well as across India and Saudi Arabia. These types of DNS poisoning attacks can send users to phishing sites with very little evidence that something suspicious has taken place.

Background and Threat Evolution A joint alert about a sudden increase in Gunra ransomware assaults was released on August 10, 2026, by US and South Korean cybersecurity officials, including CISA,...
The post Defending Against Gunra: Key Takeaways from the Joint CISA Advisory appeared first on Cyber Defense Magazine.
The Iran-linked threat actor APT42 is using AI-assisted phishing attacks to target U.S. organizations amidst the Iran-US war, according to researchers at DarkAtlas.