home.social

#steganography — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #steganography, aggregated by home.social.

  1. Stegano 3.0.0 is out! 🎉

    This release fixes silent corruption of Unicode messages (emoji, CJK, accented characters…) in the LSB image and WAV techniques: messages are now embedded as encoded bytes.

    ⚠️ The hidden-message format changed: payloads hidden with ≤ 2.5.0 must be hidden again.

    Thanks to ~lechynte for the report and the initial patch!

    github.com/cedricbonhomme/Steg

  2. Stegano 3.0.0 is out! 🎉

    This release fixes silent corruption of Unicode messages (emoji, CJK, accented characters…) in the LSB image and WAV techniques: messages are now embedded as encoded bytes.

    ⚠️ The hidden-message format changed: payloads hidden with ≤ 2.5.0 must be hidden again.

    Thanks to ~lechynte for the report and the initial patch!

    github.com/cedricbonhomme/Steg

    #Python #steganography #FOSS

  3. Contagious Interview malware in SVG images: DPRK campaign

    A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.

    Pulse ID: 6a5a8ba0229db5a5b2686baa
    Pulse Link: otx.alienvault.com/pulse/6a5a8
    Pulse Author: AlienVault
    Created: 2026-07-17 20:08:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault

  4. Contagious Interview malware in SVG images: DPRK campaign

    A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.

    Pulse ID: 6a5a8ba0229db5a5b2686baa
    Pulse Link: otx.alienvault.com/pulse/6a5a8
    Pulse Author: AlienVault
    Created: 2026-07-17 20:08:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault

  5. Contagious Interview malware in SVG images: DPRK campaign

    A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.

    Pulse ID: 6a5a8ba0229db5a5b2686baa
    Pulse Link: otx.alienvault.com/pulse/6a5a8
    Pulse Author: AlienVault
    Created: 2026-07-17 20:08:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault

  6. Contagious Interview malware in SVG images: DPRK campaign

    A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.

    Pulse ID: 6a5a8ba0229db5a5b2686baa
    Pulse Link: otx.alienvault.com/pulse/6a5a8
    Pulse Author: AlienVault
    Created: 2026-07-17 20:08:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault

  7. Contagious Interview malware in SVG images: DPRK campaign

    A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.

    Pulse ID: 6a5a8ba0229db5a5b2686baa
    Pulse Link: otx.alienvault.com/pulse/6a5a8
    Pulse Author: AlienVault
    Created: 2026-07-17 20:08:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault

  8. ACR Stealer: Two observed intrusion chains amid increased threat activity

    Between late April and mid-June 2026, Microsoft observed heightened ACR Stealer activity targeting enterprise environments through ClickFix social engineering lures. This information-stealing malware, associated with Amatera Stealer rebranding and offered as malware-as-a-service, deployed through two distinct campaigns. The first utilized WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control resolution. The second employed a fileless approach using MSHTA and steganography-concealed payloads within images. Both campaigns harvested browser credentials, authentication tokens, and sensitive documents from compromised systems. Threat actors leveraged obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution techniques to evade detection. Notable tactics included masquerading as legitimate software updates, utilizing Windows DPAPI for credential decryption, and targeting PDF and Microsoft 365 documents. The blockchain dead-drop technique enabled dynamic i...

    Pulse ID: 6a59832ac2ebd9e525a462b9
    Pulse Link: otx.alienvault.com/pulse/6a598
    Pulse Author: AlienVault
    Created: 2026-07-17 01:19:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Browser #CyberSecurity #ICS #InfoSec #Malware #MalwareAsAService #Microsoft #OTX #OpenThreatExchange #PDF #PowerShell #Python #SocialEngineering #Steganography #Windows #bot #AlienVault

  9. ACR Stealer: Two observed intrusion chains amid increased threat activity

    Between late April and mid-June 2026, Microsoft observed heightened ACR Stealer activity targeting enterprise environments through ClickFix social engineering lures. This information-stealing malware, associated with Amatera Stealer rebranding and offered as malware-as-a-service, deployed through two distinct campaigns. The first utilized WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control resolution. The second employed a fileless approach using MSHTA and steganography-concealed payloads within images. Both campaigns harvested browser credentials, authentication tokens, and sensitive documents from compromised systems. Threat actors leveraged obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution techniques to evade detection. Notable tactics included masquerading as legitimate software updates, utilizing Windows DPAPI for credential decryption, and targeting PDF and Microsoft 365 documents. The blockchain dead-drop technique enabled dynamic i...

    Pulse ID: 6a59832ac2ebd9e525a462b9
    Pulse Link: otx.alienvault.com/pulse/6a598
    Pulse Author: AlienVault
    Created: 2026-07-17 01:19:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Browser #CyberSecurity #ICS #InfoSec #Malware #MalwareAsAService #Microsoft #OTX #OpenThreatExchange #PDF #PowerShell #Python #SocialEngineering #Steganography #Windows #bot #AlienVault

  10. Need to hide a message in plain sight? Steganography lets you embed secret data inside images, audio, or text without drawing attention

    Here are some free steganography tools to check out 😎👇

    Find a high-res pdf ebook with all my cybersecurity related infographics from study-notes.org/

    #cybersecurity #infosec #informationsecurity #datasecurity #steganography

  11. From the archive! Steganography With Images In PHP

    Steganography is the process of hiding data in plain sight. Instead of relying on encryption you simply create output or files that contain the hidden data, if you know what to look for.

    In this article, Phil Norton looks at using PHP to hide messages in an image using steganography.

    hashbangcode.com/article/stega

  12. Stegano 2.5.0 is out! 🎉

    This release adds a reversible data hiding technique based on histogram shifting (Ni et al., IEEE TCSVT 2006): unlike LSB, the original cover image can be recovered pixel-for-pixel after the hidden message is extracted. Includes a new stegano-rdh command line tool.

    Thanks to Eesh Saxena for the contribution!

    github.com/cedricbonhomme/Steg

  13. Stegano 2.5.0 is out! 🎉

    This release adds a reversible data hiding technique based on histogram shifting (Ni et al., IEEE TCSVT 2006): unlike LSB, the original cover image can be recovered pixel-for-pixel after the hidden message is extracted. Includes a new stegano-rdh command line tool.

    Thanks to Eesh Saxena for the contribution!

    github.com/cedricbonhomme/Steg

    #steganography #Python #FOSS

  14. AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign

    A widespread phishing campaign distributing AsyncRAT and Remcos RATs has been observed targeting organizations across manufacturing, media, professional services, agriculture, and chemical industries globally. The attack leverages malicious Excel spreadsheets sent via emails impersonating business communications like purchase orders and payment advice. When macros are enabled, VBA code retrieves HTA payloads through URL shorteners and Cloudflare Workers infrastructure. The multi-stage infection chain employs heavy obfuscation including Base64 encoding, steganography in PNG files, and character substitution. The campaign intensified during June 2026, affecting organizations across Europe, Asia-Pacific, and the Americas. Infrastructure includes distinctive HTA naming conventions using concatenated positive English words. The operation likely uses automation for payload generation and may leverage LLMs for development efficiency.

    Pulse ID: 6a471de4dcdacfc396979ab8
    Pulse Link: otx.alienvault.com/pulse/6a471
    Pulse Author: AlienVault
    Created: 2026-07-03 02:26:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Americas #Asia #AsyncRAT #Cloud #CyberSecurity #Email #Europe #Excel #InfoSec #Mac #Manufacturing #OTX #OpenThreatExchange #Phishing #RAT #Remcos #RemcosRAT #Steganography #Word #bot #AlienVault

  15. AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign

    A widespread phishing campaign distributing AsyncRAT and Remcos RATs has been observed targeting organizations across manufacturing, media, professional services, agriculture, and chemical industries globally. The attack leverages malicious Excel spreadsheets sent via emails impersonating business communications like purchase orders and payment advice. When macros are enabled, VBA code retrieves HTA payloads through URL shorteners and Cloudflare Workers infrastructure. The multi-stage infection chain employs heavy obfuscation including Base64 encoding, steganography in PNG files, and character substitution. The campaign intensified during June 2026, affecting organizations across Europe, Asia-Pacific, and the Americas. Infrastructure includes distinctive HTA naming conventions using concatenated positive English words. The operation likely uses automation for payload generation and may leverage LLMs for development efficiency.

    Pulse ID: 6a471de4dcdacfc396979ab8
    Pulse Link: otx.alienvault.com/pulse/6a471
    Pulse Author: AlienVault
    Created: 2026-07-03 02:26:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Americas #Asia #AsyncRAT #Cloud #CyberSecurity #Email #Europe #Excel #InfoSec #Mac #Manufacturing #OTX #OpenThreatExchange #Phishing #RAT #Remcos #RemcosRAT #Steganography #Word #bot #AlienVault

  16. @MissConstrue

    Probably you meant #steganography instead of stenography?

    Though stenographers could certainly be employed in a steganographic attack, if there were stenographers any more (outside of courtooms).

  17. @MissConstrue

    Probably you meant #steganography instead of stenography?

    Though stenographers could certainly be employed in a steganographic attack, if there were stenographers any more (outside of courtooms).

  18. Ok, to start, let me define "#steganography" in #infosec. Steganography in computer security is the practice of hiding information within another file, message, image, or video, making the concealed information undetectable to an unsuspecting observer.

    It is not necessarily malicious, but it certainly can be. I tell you that story to tell you this one:

    #Claude Code Is Steganographically Marking Requests

    CC silently alters the system prompt using invisible-ish Unicode markers. It encodes proxy / gateway classification into a sentence that looks like plain English. It hides the domain list behind XOR and base64.

    Is it malicious? Probably not. Is a pretty big marker on the "Why not to trust AI companies" list of reasons? Yeah, yeah it is.

    thereallo.dev/blog/claude-code

    #AI #security #ClaudeCode #Anthropic

    (Edit: doh, fingers faster than brain)

  19. Ok, to start, let me define "#steganography" in #infosec. Steganography in computer security is the practice of hiding information within another file, message, image, or video, making the concealed information undetectable to an unsuspecting observer.

    It is not necessarily malicious, but it certainly can be. I tell you that story to tell you this one:

    #Claude Code Is Steganographically Marking Requests

    CC silently alters the system prompt using invisible-ish Unicode markers. It encodes proxy / gateway classification into a sentence that looks like plain English. It hides the domain list behind XOR and base64.

    Is it malicious? Probably not. Is a pretty big marker on the "Why not to trust AI companies" list of reasons? Yeah, yeah it is.

    thereallo.dev/blog/claude-code

    #AI #security #ClaudeCode #Anthropic

    (Edit: doh, fingers faster than brain)

  20. AsyncRAT and Remcos delivered in an optimistic campaign

    A global phishing campaign targets business functions with emails carrying malicious Excel attachments that initiate a multi-stage infection chain when macros are enabled.
    The attack uses layered obfuscation, including HTA scripts, PowerShell, encoded payloads, and steganography in PNG files, to deliver and execute Remote Access Trojans such as Remcos and AsyncRAT in a largely fileless manner.
    It achieves scale and persistence through high variability, automation, disposable infrastructure, and consistent patterns that help evade detection despite relatively simple techniques.

    Pulse ID: 6a3ba45b3fef31b3a05d9cb0
    Pulse Link: otx.alienvault.com/pulse/6a3ba
    Pulse Author: AlienVault
    Created: 2026-06-24 09:33:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AsyncRAT #CyberSecurity #Email #Excel #InfoSec #Mac #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #Remcos #RemoteAccessTrojan #Steganography #Trojan #bot #AlienVault

  21. AsyncRAT and Remcos delivered in an optimistic campaign

    A global phishing campaign targets business functions with emails carrying malicious Excel attachments that initiate a multi-stage infection chain when macros are enabled.
    The attack uses layered obfuscation, including HTA scripts, PowerShell, encoded payloads, and steganography in PNG files, to deliver and execute Remote Access Trojans such as Remcos and AsyncRAT in a largely fileless manner.
    It achieves scale and persistence through high variability, automation, disposable infrastructure, and consistent patterns that help evade detection despite relatively simple techniques.

    Pulse ID: 6a3ba45b3fef31b3a05d9cb0
    Pulse Link: otx.alienvault.com/pulse/6a3ba
    Pulse Author: AlienVault
    Created: 2026-06-24 09:33:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AsyncRAT #CyberSecurity #Email #Excel #InfoSec #Mac #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #Remcos #RemoteAccessTrojan #Steganography #Trojan #bot #AlienVault

  22. I built this for learning purposes (I know JPEG steganography is not new, but I couldn't find much combining it with a multimodal LLM attack vector, so I thought why not?). Small C tool, LSB + spread spectrum where payload survives recompression.

    github.com/FrancescoPaoloL/img

    #infosec #llmsecurity #steganography

  23. I built this for learning purposes (I know JPEG steganography is not new, but I couldn't find much combining it with a multimodal LLM attack vector, so I thought why not?). Small C tool, LSB + spread spectrum where payload survives recompression.

    github.com/FrancescoPaoloL/img

    #infosec #llmsecurity #steganography

  24. A Multi-Stage Steganographic Loader Campaign Deploying Diverse Payloads Globally

    A sophisticated phishing campaign was identified distributing multiple malware families through a multi-stage loader utilizing steganography and fileless techniques. The infection chain begins with archive attachments containing files disguised as financial documents, primarily targeting Indian organizations using names related to GST, NEFT, RTGS, and IMPS transactions. The loader employs in-memory execution to avoid disk-based artifacts and uses embedded .NET Bitmap objects to conceal payloads. Various malware families have been deployed including Remcos RAT, Agent Tesla, MassLogger, Phantom Stealer, Dark Cloud, Red Line Stealer, Snake keyloggers, Formbook, and xworm. The final payloads establish persistence through registry Run keys, perform process hollowing, steal browser credentials, record audio and webcam, and exfiltrate data to command-and-control infrastructure. The campaign exhibits characteristics of a loader-as-a-service operation serving multiple threat actors globally.

    Pulse ID: 6a3ac3d87dd519f2fec1d2ea
    Pulse Link: otx.alienvault.com/pulse/6a3ac
    Pulse Author: AlienVault
    Created: 2026-06-23 17:35:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AgentTesla #Browser #Cloud #CyberSecurity #FormBook #ICS #India #InfoSec #KeyLogger #Malware #NET #OTX #OpenThreatExchange #Phishing #RAT #Remcos #RemcosRAT #SSL #Steganography #Tesla #Worm #XWorm #bot #AlienVault

  25. A Multi-Stage Steganographic Loader Campaign Deploying Diverse Payloads Globally

    A sophisticated phishing campaign was identified distributing multiple malware families through a multi-stage loader utilizing steganography and fileless techniques. The infection chain begins with archive attachments containing files disguised as financial documents, primarily targeting Indian organizations using names related to GST, NEFT, RTGS, and IMPS transactions. The loader employs in-memory execution to avoid disk-based artifacts and uses embedded .NET Bitmap objects to conceal payloads. Various malware families have been deployed including Remcos RAT, Agent Tesla, MassLogger, Phantom Stealer, Dark Cloud, Red Line Stealer, Snake keyloggers, Formbook, and xworm. The final payloads establish persistence through registry Run keys, perform process hollowing, steal browser credentials, record audio and webcam, and exfiltrate data to command-and-control infrastructure. The campaign exhibits characteristics of a loader-as-a-service operation serving multiple threat actors globally.

    Pulse ID: 6a3ac3d87dd519f2fec1d2ea
    Pulse Link: otx.alienvault.com/pulse/6a3ac
    Pulse Author: AlienVault
    Created: 2026-06-23 17:35:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AgentTesla #Browser #Cloud #CyberSecurity #FormBook #ICS #India #InfoSec #KeyLogger #Malware #NET #OTX #OpenThreatExchange #Phishing #RAT #Remcos #RemcosRAT #SSL #Steganography #Tesla #Worm #XWorm #bot #AlienVault

  26. 🕶️ Nouveau sur Merci.pics !

    Cachez un message secret dans vos images ✨
    • Watermark 🏷️
    • Texte visible ✍️
    • Stéganographie 🕶️
    • Extraction 🔍

    🔒 100% local · pas de cookies · pas de pub · pas de suivi
    📷 Votre image ne quitte JAMAIS votre appareil

    🗻 merci.pics/merci1.html

    C'est gratuit. C'est silencieux. C'est respectueux. 🤍

    #Privacy #Steganography #FrenchCulture #FreeTools #NoTracking #merci

  27. 🕶️ Nouveau sur Merci.pics !

    Cachez un message secret dans vos images ✨
    • Watermark 🏷️
    • Texte visible ✍️
    • Stéganographie 🕶️
    • Extraction 🔍

    🔒 100% local · pas de cookies · pas de pub · pas de suivi
    📷 Votre image ne quitte JAMAIS votre appareil

    🗻 merci.pics/merci1.html

    C'est gratuit. C'est silencieux. C'est respectueux. 🤍

  28. Paper 2/2:

    I know the idea is rather trivial but during Christmas I played around with IoT devices and how they can be used for censorship circumvention and time-decoupled covert transmissions.

    AdullamoT: Using IoT Devices as Relays for Time-decoupled
    Secret Exchange & Censorship Circumvention

    PDF: wendzel.de/dr.org/files/Papers

    #censorship #internetcensorship #covertchannels #steganography #cybersecurity #infosec #iot

  29. Paper 2/2:

    I know the idea is rather trivial but during Christmas I played around with IoT devices and how they can be used for censorship circumvention and time-decoupled covert transmissions.

    AdullamoT: Using IoT Devices as Relays for Time-decoupled
    Secret Exchange & Censorship Circumvention

    PDF: wendzel.de/dr.org/files/Papers

    #censorship #internetcensorship #covertchannels #steganography #cybersecurity #infosec #iot

  30. Want to hide data inside PNGs using JavaScript? 🖼️🔐

    Check out this cool pure JS library that offers two clever ways to encode data into images using lossless compression:

    1️⃣ Data-to-Image: Converts raw data bytes directly into RGB channels.
    2️⃣ Steganography: Inject up to 1 byte per pixel into an existing image by subtly shifting color gradations, making the data virtually invisible!

    Read the full breakdown and grab the code: meefik.dev/2020/02/22/aspng/

    #JavaScript #Steganography #Coding #OpenSource

  31. CW: Long thread/10

    @pluralistic

    Absolutely, we do need better political and legal backing.

    But one answer that assumes a dystopian state is something ive seen very little of. And thats #steganography.

    If you cant use effective #cryptography without backdoors or not at all, stego is a way to hide real communication inside milquetoast boring communication without anybody else figuring out theres even hidden messages. If there was a text stego, you could even hide it in (ick!) Facebook messages, if thats what you have to use.

    I saw some stego tools back around the turn of the millenium, primarily with least significant bit used on images. Aside some work, its dated at best.

    Counter to that, stego is being used extensively with very low bandwidth detection in movie copyrighted works, to identify what theater and what show a cam came from. And also the LLM dealers are also starting to mess with stego as well, as a stealth way to detect LLM generated stuff.

  32. CW: Long thread/10

    @pluralistic

    Absolutely, we do need better political and legal backing.

    But one answer that assumes a dystopian state is something ive seen very little of. And thats #steganography.

    If you cant use effective #cryptography without backdoors or not at all, stego is a way to hide real communication inside milquetoast boring communication without anybody else figuring out theres even hidden messages. If there was a text stego, you could even hide it in (ick!) Facebook messages, if thats what you have to use.

    I saw some stego tools back around the turn of the millenium, primarily with least significant bit used on images. Aside some work, its dated at best.

    Counter to that, stego is being used extensively with very low bandwidth detection in movie copyrighted works, to identify what theater and what show a cam came from. And also the LLM dealers are also starting to mess with stego as well, as a stealth way to detect LLM generated stuff.

  33. Porting SafeText and analyzing digital content with Apache Tika

    by @beet_keeper

    Last year I wrote about pitfalls in modern journalism, especially with regards to receiving documents and information from whistleblowers without offering them adequate protection.

    The tl;dr is that you, as a whistleblower, need to protect yourself; and you, as an editor or journalist, need to protect your whistleblowers.

    Steganographic fingerprints might be one method adopted to detect someone leaking information. Steganographic characters replace common textual characters with unusual but hard to detect variants, e.g. they look the same to the human eye, or are actually invisible. Using a tool called SafeText by David Jacobson we can identify these hidden fingerprints in the content that you share.

    I firmly believe we can find clues about what is important to preserve, or learn to preserve, when we analyse the content of the digital record and not just the (file) format of the digital record.

    A file can contain many different features and these are all challenges to their future interpretation, and thus preservation.

    I wanted to use SafeText in some of my other non-Python tooling and so I decided to port the code to Golang as a composable module and binary.

    By coincidence at the time I started writing this I had also just written about revisiting tikalinkextract and so I thought I would write this small explanation about how you might combine Tika and SafeText to perform some content analysis of your own.

    Who knows, maybe we will find a conspiracy. Maybe we’ll find secret codes in our own digital records. Maybe we’ll learn something new about our records…

    Lets have a look at putting Tika and SafeText together and see where it goes.


    #ApacheTika #authenticity #Code #Coding #ContentAnalysis #Data #DigitalHumanities #digitalLiteracy #DigitalPreservation #Golang #integrity #Metadata #Paradata #SafeText #steganography
  34. Porting SafeText and analyzing digital content with Apache Tika

    by @beet_keeper

    Last year I wrote about pitfalls in modern journalism, especially with regards to receiving documents and information from whistleblowers without offering them adequate protection.

    The tl;dr is that you, as a whistleblower, need to protect yourself; and you, as an editor or journalist, need to protect your whistleblowers.

    Steganographic fingerprints might be one method adopted to detect someone leaking information. Steganographic characters replace common textual characters with unusual but hard to detect variants, e.g. they look the same to the human eye, or are actually invisible. Using a tool called SafeText by David Jacobson we can identify these hidden fingerprints in the content that you share.

    I firmly believe we can find clues about what is important to preserve, or learn to preserve, when we analyse the content of the digital record and not just the (file) format of the digital record.

    A file can contain many different features and these are all challenges to their future interpretation, and thus preservation.

    I wanted to use SafeText in some of my other non-Python tooling and so I decided to port the code to Golang as a composable module and binary.

    By coincidence at the time I started writing this I had also just written about revisiting tikalinkextract and so I thought I would write this small explanation about how you might combine Tika and SafeText to perform some content analysis of your own.

    Who knows, maybe we will find a conspiracy. Maybe we’ll find secret codes in our own digital records. Maybe we’ll learn something new about our records…

    Lets have a look at putting Tika and SafeText together and see where it goes.


    #ApacheTika #authenticity #Code #Coding #ContentAnalysis #Data #DigitalHumanities #digitalLiteracy #DigitalPreservation #Golang #integrity #Metadata #Paradata #SafeText #steganography
  35. Porting SafeText and analyzing digital content with Apache Tika

    by @beet_keeper

    Last year I wrote about pitfalls in modern journalism, especially with regards to receiving documents and information from whistleblowers without offering them adequate protection.

    The tl;dr is that you, as a whistleblower, need to protect yourself; and you, as an editor or journalist, need to protect your whistleblowers.

    Steganographic fingerprints might be one method adopted to detect someone leaking information. Steganographic characters replace common textual characters with unusual but hard to detect variants, e.g. they look the same to the human eye, or are actually invisible. Using a tool called SafeText by David Jacobson we can identify these hidden fingerprints in the content that you share.

    I firmly believe we can find clues about what is important to preserve, or learn to preserve, when we analyse the content of the digital record and not just the (file) format of the digital record.

    A file can contain many different features and these are all challenges to their future interpretation, and thus preservation.

    I wanted to use SafeText in some of my other non-Python tooling and so I decided to port the code to Golang as a composable module and binary.

    By coincidence at the time I started writing this I had also just written about revisiting tikalinkextract and so I thought I would write this small explanation about how you might combine Tika and SafeText to perform some content analysis of your own.

    Who knows, maybe we will find a conspiracy. Maybe we’ll find secret codes in our own digital records. Maybe we’ll learn something new about our records…

    Lets have a look at putting Tika and SafeText together and see where it goes.


    #ApacheTika #authenticity #Code #Coding #ContentAnalysis #Data #DigitalHumanities #digitalLiteracy #DigitalPreservation #Golang #integrity #Journalism #Metadata #Paradata #SafeText #steganography #Whistleblow #Whistleblower
  36. Porting SafeText and analyzing digital content with Apache Tika

    by @beet_keeper

    Last year I wrote about pitfalls in modern journalism, especially with regards to receiving documents and information from whistleblowers without offering them adequate protection.

    The tl;dr is that you, as a whistleblower, need to protect yourself; and you, as an editor or journalist, need to protect your whistleblowers.

    Steganographic fingerprints might be one method adopted to detect someone leaking information. Steganographic characters replace common textual characters with unusual but hard to detect variants, e.g. they look the same to the human eye, or are actually invisible. Using a tool called SafeText by David Jacobson we can identify these hidden fingerprints in the content that you share.

    I firmly believe we can find clues about what is important to preserve, or learn to preserve, when we analyse the content of the digital record and not just the (file) format of the digital record.

    A file can contain many different features and these are all challenges to their future interpretation, and thus preservation.

    I wanted to use SafeText in some of my other non-Python tooling and so I decided to port the code to Golang as a composable module and binary.

    By coincidence at the time I started writing this I had also just written about revisiting tikalinkextract and so I thought I would write this small explanation about how you might combine Tika and SafeText to perform some content analysis of your own.

    Who knows, maybe we will find a conspiracy. Maybe we’ll find secret codes in our own digital records. Maybe we’ll learn something new about our records…

    Lets have a look at putting Tika and SafeText together and see where it goes.

    Continue reading “Porting SafeText and analyzing digital content with Apache Tika”


    #ApacheTika #authenticity #Code #Coding #ContentAnalysis #Data #DigitalHumanities #digitalLiteracy #DigitalPreservation #Golang #integrity #Journalism #Metadata #Paradata #SafeText #steganography #Whistleblow #Whistleblower
  37. 🕶️ 2026.lat – Invisible watermark tool.

    Compress images, rename sequentially, and hide ANY secret text inside pixels (LSB steganography). No server uploads. No tracking. 100% local.🤍

    Choose visible watermark or invisible message. Extract later with one click.🧊

    🔗 2026.lat

    #Privacy #Steganography #OpenWeb #NoTracking #mastodon

    ---
    #culture #photo

  38. Hello. I'm @[email protected] in yet another Sisyphean task to find an alternative #Fediverse instance as Calckey is facing lots of Bad Gateways and, as of recently, an annoying influx of spam (which also ends up contributing to the Bad Gateways). Seems like Ruud (Calckey admin) didn't see my report regarding the latter, and this worries me as this means that server could be seen as "unmoderated" and defederated by other instances I interact with. I'm yet to see how federated is this Catodon instance, because other Misskey-like instances I tried in the past (such as Evil Social) had little to no federation with Lemmy instances.

    As this is my first post for this account, I'll try to describe the kind of content I'm used to post in the next paragraphs (while also testing how similar this instance is to the Calckey instance I'm used to).

    I often post my
    #digitaldrawings and other kinds of #occult #art centered on my actual beliefs. My #artistic expressions, which mostly stems from actual #gnosis, sometimes manifest as #poetry and/or #Blender #3dmodeling scenarios and/or #memes and/or #code (because I'm also a #dev who codes in several #programming languages, including #javascript, #ruby and #python, and I use #arch #linux, btw). Many of my artistic expressions, particularly my #drawings and my #writings, are NSFW and will be labeled as so. Oh, sometimes I do ancient writing, too, including actual attempts on Sumerian texts (based on actual, available Sumerian Lexicons). And I sometimes do #steganography as well (I'm quite fond of things such as #math #puzzles and hidden messages; and, no, this post has no hidden message, I'm quite in a mental budget here). I'm a detail-oriented person, as you may notice from this post alone.

    As for my beliefs, I have a syncretic worship for
    #Lilith Who, I believe, has the same cosmic principle that from #Ereshkigal, #Kali, #Hecate, #Pombagiras (esp. Dama da Noite and Rosa Caveira), among many other names across belief systems, as my syncretism is based on several belief systems such as #Thelema, #Luciferianism, #Gnosticism, #Hermeticism, #Sumerian, #Egyptian, #Quimbanda and others. I also believe in other entities, not with the same worshiping, but with similar respect for #Lucifer, #Baphomet and #Stolas (I don't agree with the Goetian approach of constrained summoning, for Stolas and other Daemons are cosmic teachers who deserve our due respect).

    I've been hyper-fixated on
    #owls, especially some #owl species such as Athene cunicularia (burrowing owls), _Bubo ascalaphus (Pharaoh Eagle-owl), because owls are one of the main theophanic manifestations of the #goddess. See the taxonomic binomials? Yes, I often do this bizarre intertwining between the religious and the scientific, because I don't believe in siloed knowledge.

    I'm
    #Brazilian and some of my posts will be in #portuguese, sometimes alongside English text, tal como estou fazendo nesse parágrafo.

    I'm likely
    #neurodivergent and #audhd (albeit undiagnosed), hence why my posts (including this one I'm composing) is so prolifically lengthy and mixing concepts/skills so disparate, for my mind is always agitated and restless.

    I'm mostly
    #anarchist and I don't believe humanity is the only intelligent species on this Pale Blue Dot, for there are countless other species such as corvids (esp. New Caledonian crows; I believe crows and ravens as manifestations of Lucifer just like owls are manifestations of Lilith) who are as intelligent (if not more) as us Homo sapiens.

    I'm mostly
    #nihilist and #pessimist with certain inspiration from philosophers such as Philipp Mainländer. I may sound depressive (do I sound this way in this post? It doesn't seem so) because I am depressive since my childhood and, yes, I tried mental health care to no avail (psychiatrists can't understand, for example, how #Demiurge and his archons sucks and how the Goddess is our true cosmic Mother).

    That's mostly me. "Mostly" because I'm not really able to fit labels or tribes. I don't quite belong. I really liked the 5000 char limit from this instance.

    #introduction

  39. Hello. I'm @[email protected] in yet another Sisyphean task to find an alternative #Fediverse instance as Calckey is facing lots of Bad Gateways and, as of recently, an annoying influx of spam (which also ends up contributing to the Bad Gateways). Seems like Ruud (Calckey admin) didn't see my report regarding the latter, and this worries me as this means that server could be seen as "unmoderated" and defederated by other instances I interact with. I'm yet to see how federated is this Catodon instance, because other Misskey-like instances I tried in the past (such as Evil Social) had little to no federation with Lemmy instances.

    As this is my first post for this account, I'll try to describe the kind of content I'm used to post in the next paragraphs (while also testing how similar this instance is to the Calckey instance I'm used to).

    I often post my
    #digitaldrawings and other kinds of #occult #art centered on my actual beliefs. My #artistic expressions, which mostly stems from actual #gnosis, sometimes manifest as #poetry and/or #Blender #3dmodeling scenarios and/or #memes and/or #code (because I'm also a #dev who codes in several #programming languages, including #javascript, #ruby and #python, and I use #arch #linux, btw). Many of my artistic expressions, particularly my #drawings and my #writings, are NSFW and will be labeled as so. Oh, sometimes I do ancient writing, too, including actual attempts on Sumerian texts (based on actual, available Sumerian Lexicons). And I sometimes do #steganography as well (I'm quite fond of things such as #math #puzzles and hidden messages; and, no, this post has no hidden message, I'm quite in a mental budget here). I'm a detail-oriented person, as you may notice from this post alone.

    As for my beliefs, I have a syncretic worship for
    #Lilith Who, I believe, has the same cosmic principle that from #Ereshkigal, #Kali, #Hecate, #Pombagiras (esp. Dama da Noite and Rosa Caveira), among many other names across belief systems, as my syncretism is based on several belief systems such as #Thelema, #Luciferianism, #Gnosticism, #Hermeticism, #Sumerian, #Egyptian, #Quimbanda and others. I also believe in other entities, not with the same worshiping, but with similar respect for #Lucifer, #Baphomet and #Stolas (I don't agree with the Goetian approach of constrained summoning, for Stolas and other Daemons are cosmic teachers who deserve our due respect).

    I've been hyper-fixated on
    #owls, especially some #owl species such as Athene cunicularia (burrowing owls), _Bubo ascalaphus (Pharaoh Eagle-owl), because owls are one of the main theophanic manifestations of the #goddess. See the taxonomic binomials? Yes, I often do this bizarre intertwining between the religious and the scientific, because I don't believe in siloed knowledge.

    I'm
    #Brazilian and some of my posts will be in #portuguese, sometimes alongside English text, tal como estou fazendo nesse parágrafo.

    I'm likely
    #neurodivergent and #audhd (albeit undiagnosed), hence why my posts (including this one I'm composing) is so prolifically lengthy and mixing concepts/skills so disparate, for my mind is always agitated and restless.

    I'm mostly
    #anarchist and I don't believe humanity is the only intelligent species on this Pale Blue Dot, for there are countless other species such as corvids (esp. New Caledonian crows; I believe crows and ravens as manifestations of Lucifer just like owls are manifestations of Lilith) who are as intelligent (if not more) as us Homo sapiens.

    I'm mostly
    #nihilist and #pessimist with certain inspiration from philosophers such as Philipp Mainländer. I may sound depressive (do I sound this way in this post? It doesn't seem so) because I am depressive since my childhood and, yes, I tried mental health care to no avail (psychiatrists can't understand, for example, how #Demiurge and his archons sucks and how the Goddess is our true cosmic Mother).

    That's mostly me. "Mostly" because I'm not really able to fit labels or tribes. I don't quite belong. I really liked the 5000 char limit from this instance.

    #introduction

  40. Hello. I'm @[email protected] in yet another Sisyphean task to find an alternative #Fediverse instance as Calckey is facing lots of Bad Gateways and, as of recently, an annoying influx of spam (which also ends up contributing to the Bad Gateways). Seems like Ruud (Calckey admin) didn't see my report regarding the latter, and this worries me as this means that server could be seen as "unmoderated" and defederated by other instances I interact with. I'm yet to see how federated is this Catodon instance, because other Misskey-like instances I tried in the past (such as Evil Social) had little to no federation with Lemmy instances.

    As this is my first post for this account, I'll try to describe the kind of content I'm used to post in the next paragraphs (while also testing how similar this instance is to the Calckey instance I'm used to).

    I often post my
    #digitaldrawings and other kinds of #occult #art centered on my actual beliefs. My #artistic expressions, which mostly stems from actual #gnosis, sometimes manifest as #poetry and/or #Blender #3dmodeling scenarios and/or #memes and/or #code (because I'm also a #dev who codes in several #programming languages, including #javascript, #ruby and #python, and I use #arch #linux, btw). Many of my artistic expressions, particularly my #drawings and my #writings, are NSFW and will be labeled as so. Oh, sometimes I do ancient writing, too, including actual attempts on Sumerian texts (based on actual, available Sumerian Lexicons). And I sometimes do #steganography as well (I'm quite fond of things such as #math #puzzles and hidden messages; and, no, this post has no hidden message, I'm quite in a mental budget here). I'm a detail-oriented person, as you may notice from this post alone.

    As for my beliefs, I have a syncretic worship for
    #Lilith Who, I believe, has the same cosmic principle that from #Ereshkigal, #Kali, #Hecate, #Pombagiras (esp. Dama da Noite and Rosa Caveira), among many other names across belief systems, as my syncretism is based on several belief systems such as #Thelema, #Luciferianism, #Gnosticism, #Hermeticism, #Sumerian, #Egyptian, #Quimbanda and others. I also believe in other entities, not with the same worshiping, but with similar respect for #Lucifer, #Baphomet and #Stolas (I don't agree with the Goetian approach of constrained summoning, for Stolas and other Daemons are cosmic teachers who deserve our due respect).

    I've been hyper-fixated on
    #owls, especially some #owl species such as Athene cunicularia (burrowing owls), Bubo ascalaphus (Pharaoh Eagle-owl), because owls are one of the main theophanic manifestations of the #goddess. See the taxonomic binomials? Yes, I often do this bizarre intertwining between the religious and the scientific, because I don't believe in siloed knowledge.

    I'm
    #Brazilian and some of my posts will be in #portuguese, sometimes alongside English text, tal como estou fazendo nesse parágrafo.

    I'm likely
    #neurodivergent and #audhd (albeit undiagnosed), hence why my posts (including this one I'm composing) are so prolifically lengthy and mixing concepts/skills so disparate, for my mind is always agitated and restless. I may sound depressive (do I sound this way in this post? It doesn't seem so) because I am depressive since my childhood and, yes, I tried mental health care to no avail (psychiatrists can't understand, for example, how #Demiurge and his archons sucks and how the Goddess is our true cosmic Mother).

    I'm mostly
    #nihilist and #pessimist with certain inspiration from philosophers such as Philipp Mainländer.

    I'm mostly
    #anarchist and I don't believe humanity is the only intelligent species on this Pale Blue Dot, for there are countless other species such as corvids (esp. New Caledonian crows; I believe crows and ravens as manifestations of Lucifer just like owls are manifestations of Lilith) who are as intelligent (if not more) as us Homo sapiens.

    That's mostly me. "Mostly" because I'm not really able to fit labels or tribes. I don't quite belong. I really liked the 5000 char limit from this instance.

    #introduction

  41. Steganography Exploits LLMs with Hidden Text Techniques

    Want to hide text in plain sight? Try using white text on a white background or black text on a black background - simple yet effective visual tricks that can evade human eyes while remaining readable by machines.

    osintsights.com/steganography-

    #Steganography #HiddenTextTechniques #LlmExploits #VisualObfuscation #MachineReadability