Vai al contenuto principale

#iran

Mutual Aid Request Roundup 6 August 2026

1,845 words

8–12 minutes

[1 comment on Mutual Aid Request Roundup 6 August 2026](https://mutualaidspace.org/mutual-aid-request-roundup-6-august-2026

Altro...

1,845 words

8–12 minutes

1 comment on Mutual Aid Request Roundup 6 August 2026

They Fenced the Malls, Then Un-Fenced Them: A State That Manages MemoryI’m writing this from Jakarta, eleven days before the 81st Independence Day, and this week the country’s entire security apparatus stood on one stage at once to tell the public that nothing is happening. Coordinating Minister for Politics and Security Djamari Chaniago, flanked by TNI commander General Agus Subiyanto, National Police Chief General Listyo Sigit Prabowo, intelligence chief Muhammad Herindra, and Attorney General Sanitiar Burhanuddin, held a joint press conference on Wednesday insisting the domestic situation “remains secure and fully under control” and urging the public not to be swayed by “disinformation” about unrest this August. Five of the most powerful men in the country do not typically assemble to deny that nothing is wrong.

What none of those five men explained is the week that led up to that podium. Photos and videos of newly built fences barricading Kota Kasablanka mall in South Jakarta and Pakuwon mall in Bekasi spread across social media, prompting speculation that businesses were quietly bracing for unrest. The fences went up. Then, over the weekend, without explanation, the fences came down. In the gap between those two facts, old footage from last August’s uprising resurfaced online, presented as though it were happening now, alongside claims that Indonesian mainstream media was deliberately burying new protests. The government’s response was not to explain the fences. It was to announce that the Attorney General’s Office and National Police would pursue criminal charges against accounts spreading “hoaxes” about riots, and within days, police in Ciamis Regency, West Java, arrested a forty-five-year-old woman for uploading posts about a planned demonstration. A private citizen went from social media post to police custody faster than a mall fence went up and came back down.

None of this is new, and none of it is incidental. It is almost exactly a year since police in this country ran over a rideshare driver named Affan Kurniawan with an armoured van and kept driving, the video that turned a protest over parliamentary housing perks into the largest uprising this country has seen in a generation: nearly fifty cities, ten dead, more than a thousand injured, over three thousand arrested. Eight of those activists are still facing six to twelve years in prison for the crime of posting on social media about where the protests were. A Human Rights Watch report published barely a week ago documented how the Prabowo government keeps expanding the military’s footprint into mining, palm oil, and so-called food and energy estates, prosecuting the environmental defenders and Indigenous leaders standing in its way. A state apparatus that fences a mall overnight and arrests a woman in Ciamis for a Facebook post, while insisting both are nothing to see, is managing memory rather than disinformation, and this government has practice at that: this is the same state that made a genocider and the most corrupt president in its history (Bevins, 2020) a national hero, within a year after the current president, who’s also a documented human rights abuser, took office. A government fluent enough in rewriting its own history to canonise Soeharto has had plenty of practice managing the story ahead of managing the problem underneath it, and fencing a mall without a word of explanation is just this week’s version of that same habit.

The same expansion into mining, palm oil, and food and energy estates that HRW documented this month is the same mechanism showing up everywhere, not something unique to Jakarta. An economy that depends on extraction, whether it’s Gaza’s aquifers, Hormuz’s shipping lanes, or Kalimantan’s nickel, will always find a reason to militarise its own protection and call the militarisation routine, and a state built around protecting that extraction will always move faster to manage the story than to fix what the story is about. The Jakarta Post’s own editorial page noted this week that Indonesia’s GDP growth has already slowed to 5.29 percent as the Hormuz standoff ripples through import costs, a war Indonesia had no part in starting, absorbed into ordinary import bills while the same government spends its speed fencing malls against imagined unrest at home.

Solidarity that stops at a coastline is tourism. Below is this week’s list. A state that moves this fast to defend a mall has yet to move half that fast for anyone’s rent, anywhere. Give directly, share widely, and don’t let “under control” talk you out of noticing who’s actually being protected, and who’s being made an example of.

✨Mutual Aid Roundup✨

https://blahaj.zone/notes/apkmnch1vzeq1yxk

@SabiLewSounds@mastodon.social @mynameistillian@plush.city @ellespeaks@mastodon.social @sparkshocker@mastodon.social @technocrow@blahaj.zone @magicalgrrrl@indiepocalypse.social @broodcoffee@mastodon.social @cycletherapyHam@mstdn.ca @psychoalpastor@kolektiva.social @FictionAddict@mastodon.social

✨Palestinian Campaign Spotlight✨

Hilal and Mohammad’s Gaza Family Need Help Now

Amidst the rubble of these difficult days, their son’s glasses were broken, leaving him unable to see or move due to severe astigmatism. It pains Hilal and her husband that they’re currently unable to provide a replacement. We appeal to compassionate hearts for a kind gesture so their little one can see his path again.
(View original post)

@Hilalgazayafa@mastodon.social

REDISTRIBUTE

Help Abed and Eman protect their little children

Abed and Eman are a family in Gaza seeking urgent help to protect their young children and survive. Please support their Chuffed campaign and share it widely with others today. (View original post)

@abed_in_gaza123@mastodon.design

REDISTRIBUTE

Gaza Verified Archive


  Verified Palestinian campaigns under $200



  These are verified Palestinian accounts whose campaigns received less than $200 in the past 7 days.






  Nine of many. The archive holds the rest.



  @tamer_2003_@mastodon.social

  @hak51156@mastodon.social

  @RiyadMousa@mastodon.social

  @danyarelkhodari@mastodon.social

  @Raghadfamily@mastodon.social

  @Nesman0@mastodon.social

  @shathamohammed123@mastodon.social

  @tahreersoph@mastodon.social

  @reemmohammed@mastodon.social



  Open the archive, find the campaign link on each account, give directly where possible, and share the campaign links that need movement.



  [View underfunded campaign list](https://gaza.onl/campaigns/accounts?currency=USD&start_time=2026-07-30T00:00:00&sort=amount:asc)

  [About Gaza Verified Campaigns](https://gaza.onl)

🗣️Support Corner🗣️

📱Share this article far and wide. Subscribe to get this update in your inbox!

This space is held together by adisabled Indonesian Muslim woman. Monthly support keeps me fed, medicated, and connected, and helps me keep resisting corporate funding and the humanitarian-industrial complex through my writing and mutual aid projects.

If you find this voluntary work worth supporting, please do so by pledging as little as $1 monthly via Liberapay or other tiers available across Liberapay, ko-fi, and Patreon. One-off support helps too. Any amount genuinely helps.

Paid Membership on Patreon

Ko-fi voluntary monthly support

Liberapay voluntary monthly support

Monthly Support Package

@mutualaid@ovo.st @mutualaid@fedigroups.social @disability@ovo.st @autistics@fedigroups.social @actuallyadhd@fedigroups.social @nillerus@kolektiva.social @khurry@mastodon.social @theleftistlawyer@mastodon.social @Kristenzeta@mastodon.social @frugalcoffee@kolektiva.social @wrzky@kolektiva.social @wrzky@wrzky.com @edendestroyer@social.chinwag.org @QasimRashid@mastodon.social @indonesia@fedigroups.social
#Gaza #Palestine #genocide #ceasefire #anticapitalism #antiimperialism #mutualaid #Islam #ochaopt #ethniccleansing #mutualaidrequest #DisabilityMutualAid #mutualaidspace #DisabilityCrowdfund #transmutualaid #queermutualaid #emergencycrowdfund #gazamutualaid #gazaverified #poverty #healthcare #mentalhealth #disability #neurodivergence #activism #activitypub #fedihelp #fediverse #blackfedi #helpfolkslive2026 #blackmutualaid #bipocma #writer #disabledwriters #writersofmastodon #IRGC #Iran #jakarta #Indonesia

Protesters holding signs at a pro-Palestine rally, with one sign reading “Not war, it’s colonialism. Not eviction, it’s ethnic cleansing. Not conflict, it’s occupation. Not complicated, it’s genocide.” Protesters holding signs at a pro-Palestine rally, with one sign reading “Not war, it’s colonialism. Not eviction, it’s ethnic cleansing. Not conflict, it’s occupation. Not complicated, it’s genocide.”

#activitypub #fediverse #iran #gaza #genocide #activism #anticapitalism #antiimperialism #bipocma #blackfedi #blackmutualaid #ceasefire #disability #disabilitycrowdfund #disabilitymutualaid #disabledwriters #emergencycrowdfund #ethniccleansing #fedihelp #gazamutualaid #gazaverified #healthcare #helpfolkslive2026 #indonesia #irgc #islam #jakarta #mentalhealth #mutualaid #mutualaidrequest #mutualaidspace #neurodivergence #ochaopt #palestine #poverty #queermutualaid #transmutualaid #writer #writersofmastodon

0 0 1

Regional tensions escalate as Iran, U.S., and Israel navigate escalating conflicts

📰 Original title: West Asia LIVE: Pakistan hopes Hormuz agreement

Altro...

Regional tensions escalate as Iran, U.S., and Israel navigate escalating conflicts

📰 Original title: West Asia LIVE: Pakistan hopes Hormuz agreement will lead to resumption of Iran-U.S. talks

🤖 IA: It's not clickbait ✅
👥 Users: It's not clickbait ✅

View full AI summary https://en.killbait.com/regional-tensions-escalate-as-iran-u-s-and-israel-navigate-escalating-conflicts.html?utm_source=mastodon_world&utm_medium=social&utm_campaign=killbait.mastodon_world

#conflict #iran #middleeastcon...

#iran #conflict #middleeastcon

0 0 1

Conservative Criticizes Trump's Conflicting Iran Messaging Amid Missile Shortages

📰 Original title: 'It was bad': Conservative calls out conflicting

Altro...

Conservative Criticizes Trump's Conflicting Iran Messaging Amid Missile Shortages

📰 Original title: 'It was bad': Conservative calls out conflicting Trump messaging he warns could cost lives

🤖 IA: It's clickbait ⚠️
👥 Users: It's clickbait ⚠️

View full AI summary https://en.killbait.com/conservative-criticizes-trump-s-conflicting-iran-messaging-amid-missile-shortages.html?utm_source=mastodon_world&utm_medium=social&utm_campaign=killbait.mastodon_world

#geopolitics #trump #iran #missiles...

#iran #geopolitics #trump #missiles

0 0 1

HollowGraph: la backdoor che trasforma il calendario di Microsoft 365 in un canale C2 cifrato

Un impianto di spionaggio finora sconosciuto ha trasformato uno degli strumenti più banali della vita d’ufficio, il calendario di Microsoft 365, in un

Altro...

Un impianto di spionaggio finora sconosciuto ha trasformato uno degli strumenti più banali della vita d’ufficio, il calendario di Microsoft 365, in un canale di comando e controllo. Si chiama HollowGraph, non sfrutta alcuna vulnerabilità software e per questo è quasi impossibile da rilevare con i controlli di rete tradizionali: il traffico che porta gli ordini dell’attaccante e i file rubati è, a tutti gli effetti, traffico legittimo verso le API di Microsoft Graph.

A scoprirlo è stata Group-IB, che ha pubblicato l’analisi tecnica il 20 luglio 2026 dopo aver individuato l’impianto su almeno 12 macchine compromesse, di cui solo tre attivamente in comunicazione con l’attaccante durante la finestra di osservazione. Il traffico della vittima analizzata copre il periodo dal 3 giugno al 9 luglio 2026, e la casella di posta usata per l’esfiltrazione appartiene a un’organizzazione israeliana. Un’impronta piccola e selettiva, che i ricercatori leggono come spionaggio mirato piuttosto che criminalità opportunistica, anche se la tecnica potrebbe essere riutilizzata su scala molto più ampia.

Il calendario come dead dropHollowGraph è una DLL .NET che supporta solo due comandi, get e send, e non contatta mai direttamente un server dell’attaccante per ricevere istruzioni. Al loro posto usa il calendario della casella compromessa come dead drop bidirezionale: per ricevere i comandi, interroga un evento specifico piazzato dall’operatore e datato 2050-05-13, una data così lontana nel futuro che nessun utente lo scoprirebbe mai scorrendo la propria agenda, e ne legge le istruzioni da un file allegato.

Per l’esfiltrazione il processo si inverte: il malware cifra il file rubato, crea un proprio evento altrettanto lontano nel tempo e carica i dati come uno o più allegati. L’intero scambio è protetto da uno schema ibrido RSA più AES-256, con coppie di chiavi separate per il canale di comando in entrata e per quello di esfiltrazione in uscita. Chi osservasse solo i log di rete vedrebbe esclusivamente chiamate alle API Microsoft Graph, indistinguibili dal traffico generato da un client Outlook qualsiasi.

Il secondo canale: DNS tunneling per restare viviPerché l’accesso a Graph resti valido nel tempo, HollowGraph mantiene un secondo canale, più grezzo ma altrettanto insidioso. Via DNS, il malware aggiorna periodicamente le credenziali dell’applicazione registrata su Entra ID (Azure AD): tenant ID, client ID, client secret e la casella di posta bersaglio. Questi valori vengono decodificati da record AAAA IPv6 restituiti da un dominio controllato dall’attaccante, cloudlanecdn[.]com, e scritti in un file camuffato da log di routine, logAzure.txt. A differenza del traffico sul calendario, qui le credenziali applicative viaggiano in chiaro, il che rende questo canale un punto di osservazione prezioso per i difensori.

Chi c’è dietro: Cavern e l’ombra di TeheranGroup-IB collega HollowGraph al framework backdoor modulare Cavern con alta confidenza, sulla base della sintassi di comando condivisa e di corrispondenze nella logica di tasking interna. Cavern era stato documentato all’inizio di luglio da Check Point, che lo ha attribuito a un cluster legato al Ministero dell’Intelligence e della Sicurezza iraniano (MOIS) soprannominato Cavern Manticore, con sovrapposizioni note verso i gruppi iraniani MuddyWater e Lyceum.

Il legame però riguarda il codice, non necessariamente l’operatore di questa specifica campagna: Group-IB è stata esplicita nel dire di non poter attribuire con sicurezza questa attività a un attore già noto, segnalando solo una sovrapposizione a bassa confidenza con Lyceum, sottogruppo dell’iraniano OilRig. La geografia della vittima, un’organizzazione israeliana, viene trattata dai ricercatori come dato sul bersaglio e non come prova di attribuzione.

Va detto che nascondere il comando e controllo dentro servizi Microsoft fidati non è una novità assoluta: caselle Outlook, cartelle bozze e OneDrive sono già stati abusati in passato con logiche simili. Ciò che rende HollowGraph interessante è aver scelto l’angolo cieco più remoto possibile, un evento di calendario piantato 24 anni nel futuro, in un momento in cui la difesa si concentra sempre di più sul monitoraggio delle identità cloud e delle applicazioni OAuth piuttosto che sui contenuti stessi delle caselle di posta.

Perché conta per i difensoriNon c’è una vulnerabilità Microsoft da patchare: HollowGraph vive su un account compromesso e sulle normali funzionalità dell’API Graph, il che è esattamente ciò che lo rende difficile da individuare. Il lavoro va fatto sul piano dell’identità e dei permessi applicativi, non su quello delle patch. Group-IB raccomanda di restringere e verificare le applicazioni OAuth con credenziali client che possono raggiungere Graph, allertare sulla creazione di nuovi client secret e applicare la consueta igiene su Entra ID: Conditional Access, rotazione delle credenziali e rilevamento di token anomali.

Cercare eventi di calendario con data remota 2050-05-13

Verificare oggetti che siano un GUID nudo o seguano schemi tipo Event ID: o Boss{..}ID{..}

Individuare allegati con nome File{n}.txt

Auditare le modifiche al calendario generate da un’applicazione anziché da una persona (eventi creati, allegati caricati, oggetti rinominati via app)

Monitorare query DNS AAAA insolitamente frequenti verso un singolo dominio, con sottodomini lunghi e ad alta entropia

Cercare il dominio cloudlanecdn[.]com e il file di configurazione logAzure.txt

L’operatore dietro questa campagna resta senza nome, e il traffico della vittima risultava ancora attivo il 9 luglio. Vale la pena controllare fin da ora quegli eventi datati nel remoto futuro: è esattamente lì che nessun analista avrebbe mai pensato di guardare.

Indicatori di compromissioneDominio C2 (DNS tunneling): cloudlanecdn[.]com
File di configurazione: logAzure.txt
Evento calendario esca: data 2050-05-13
Pattern oggetto evento: GUID nudo / "Event ID:" / "Boss{..}ID{..}"
Allegati di comando: File{n}.txt
Framework correlato: Cavern (Cavern Manticore / MOIS-linked, overlap MuddyWater e Lyceum)
Finestra di attività osservata: 3 giugno - 9 luglio 2026
Set completo di IoC e hash: report tecnico Group-IB, "HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels"

#cyberwar #infosec #spyware #apt #backdoor #groupib #cavernmanticore #graphapi #hollowgraph #iran #microsoft365

0 0 0