Donncha Ó Cearbhaill
@DonnchaC
Followers
6K
Following
3K
Media
110
Statuses
4K
Head of Security Lab at @AmnestyTech - Hunting spyware and unlawful surveillance targeting civil society (He/Him) - Fedi: @[email protected]
Berlin
Joined September 2011
Our team @AmnestyTech is available to support journalists and activists who are concerned about targeted spyware attacks. Please reach out if concerned and share widely with individuals in your networks who may be at risk. https://t.co/b6t9oCPGTr
securitylab.amnesty.org
How to get in touch with the Security Lab.
The mercenary spyware industry is threatening rights defenders and journalists worldwide. Our experts @AmnestyTech can check devices for signs of spyware 🔍. Contact share@amnesty.tech if you're concerned, or if yourself or a colleague has received an attack notification
4
142
190
SCOOP: A man who worked on developing hacking tools for defense contractor L3Harris Trenchant was notified by Apple that his iPhone was targeted with spyware. It's unclear who targeted him, but he believes he was the scapegoat of a leak investigation. https://t.co/dWAhfdE6Tw
techcrunch.com
A developer at Trenchant, a leading Western spyware and zero-day maker, was suspected of leaking company tools and was fired. Weeks later, Apple notified him that his personal iPhone was targeted...
9
130
435
People often ask what it's like behind the scenes at the world's top spy tech trade fair, ISS World. Turns out it's like this
🧵What’s the biggest lie the surveillance industry tells? That they only sell to legal clients. That there are red lines. But what do these companies say when they think nobody is watching? We went undercover to find out
1
16
15
The jawdropping revelations from @LHreports on the global location surveillance industry is an urgent wake up call. The little regulation in the EU and elsewhere is insufficient to protect us, industry where lawlessness appears rampant.
A new @LHreports investigation shows how First Wap, a surveillance company registered in Indonesia, has allegedly been covertly selling its products to state & private actors by exploiting gaps in export control regulations in the surveillance industry. https://t.co/AeewdPuxxM
0
2
5
A new @LHreports investigation shows how First Wap, a surveillance company registered in Indonesia, has allegedly been covertly selling its products to state & private actors by exploiting gaps in export control regulations in the surveillance industry. https://t.co/AeewdPuxxM
lighthousereports.com
Trove of surveillance data challenges what we thought we knew about location tracking tools, who they target and how far they have spread
2
25
35
It was a privilege to deliver the closing keynote at Hexacon yesterday. Great conference! Kudos to the organisers for featuring a defenders perspective. Thanks too to the many offensive researchers who engaged with an open mind, and then many interesting discussions.
It's time for the highly anticipated closing keynote by Donncha Ó Cearbhaill (@DonnchaC): Where the shells land: a forensic perspective on in-the-wild exploitation
0
3
45
Arrived in Paris for what should be an very interesting few days at Hexacon. I welcome DM's or just say hello at the conference in you want to chat
Really excited to have the opportunity to speak at Hexacon next month! I'll share a defender's perspective on offensive cyber based on 10 years of technical investigations into in-the-wild campaigns impacting activists, journalists and civil society.
1
1
10
Alaa is FREE 🎉 After 6 years of unjust imprisonment, Alaa Abdel Fattah is finally reunited with his loved ones. His freedom is a powerful reminder that persistence matters. Thank you to every Amnesty supporter who campaigned tirelessly for his release 💛
10
44
150
Really excited to have the opportunity to speak at Hexacon next month! I'll share a defender's perspective on offensive cyber based on 10 years of technical investigations into in-the-wild campaigns impacting activists, journalists and civil society.
We’re thrilled to announce Donncha Ó Cearbhaill (@DonnchaC) as our keynote speaker for HEXACON 2025! 💥 No doubt he has plenty of juicy stories up his sleeve 👾
2
4
18
Pakistan is running a huge unlawful surveillance and censorship system. It is built with foreign tech and carried out without warrants and safeguards, this is enabling human rights abuses on a massive scale. #BreakTheFirewall
89
2K
3K
Our partner at InterSecLab also have an excellent technical report which analyze a huge leak of Geedge technical docs revealing how Geedge - and likely the Great Firewall - can analyze and block traffic, and even inject targeted spyware infections
interseclab.org
This research reveals groundbreaking findings on how Geedge Networks is selling an extensive suite of next-generation digital repression tools to client governments around the world.
0
1
3
Amnesty's full report goes deep into the history of surveillance technology in Pakistan and the wide range of Chinese, European, Emirati and North American technology vendors which have enabled a wide-scale surveillance apparatus https://t.co/5nKObL0LD4
amnesty.org
Pakistan’s unlawful mass surveillance and censorship expansion is powered by a nexus of companies based in Germany, France, United Arab Emirates (UAE), China, Canada, and the United States, Amnesty...
1
1
3
BREAKING: Amnesty International research found illegal surveillance mass targeted surveillance with LIMS from Utimaco and Datafusion and Chinese commercialized Great Firewall provider active in Pakistan through a leak of documents of Geedge Networks. 🧵#BreakTheFirewall
2
31
63
Jurre van Bergen (@DrWhax) who lead this research at @AmnestyTech has a thread going deep into the findings on Geedge Networks and the Pakstani surveillance ecosystem. https://t.co/lFQYyO1NdI
BREAKING: Amnesty International research found illegal surveillance mass targeted surveillance with LIMS from Utimaco and Datafusion and Chinese commercialized Great Firewall provider active in Pakistan through a leak of documents of Geedge Networks. 🧵#BreakTheFirewall
0
0
2
This investigation would not have been possible without the excellent collaboration between civil society and media partners InterSecLab, Justice For Myanmar, @torproject , @paper_trail_m, Follow The Money, @derStandardat and @globeandmail.
1
0
3
Great Firewall Export: A new investigation by @Amnesty and partners, reveals Geedge Networks, a Chinese company, which is commercialized the tech behind China's notorious "Great Firewall". Geedge surveillance and censorship products found used in Pakistan, Myanmar, and more.
🚨NEW: An investigation by @Amnesty & partners exposes a shadowy surveillance & censorship expansion in Pakistan via foreign firms. It reveals Geedge Networks from China supplying the firewall & German Utimaco providing the LIMS system #BreakTheFirewall
https://t.co/t794FwVPz5
5
9
22
Pakistan is spying on millions of its citizens using a phone-tapping system and a Chinese-built internet firewall that censors social media, in one of the most comprehensive examples of state surveillance outside China, Amnesty International said
reuters.com
Pakistan is spying on millions of its citizens using a phone-tapping system and a Chinese-built internet firewall that censors social media, in one of the most comprehensive examples of state...
389
4K
7K
Also important: the Apple vulnerability was in a core image library, targeting possible through other apps besides WhatsApp. Make sure to update your devices and enabled iOS Lockdown Mode or Android‘s Advanced Protection Mode to help protect against attacks like this
1
1
18
Early indications are that the WhatsApp attack is impacting both iPhone and Android users, civil society individuals among them. Government spyware continues to pose a threat to journalists and human rights defenders. Kudos to WhatsApp and Apple for catching it and notifying
2
2
26
CVE-2025-55177, an authorization bypass in WhatsApp on iOS and Mac, allowed attackers to force "content from arbitrary URL" to be rendered on a target’s device.. A zero-click vulnerability recently patched by Apple (CVE-2025-43300) was also used in the WhatsApp attack 👀
1
20
66
Our team at Amnesty International's Security Lab is actively investigating cases with a number of individuals targeted in this campaign. We are available to support members of civil society who have received the WhatsApp notifications. Contact us at share@amnesty.tech
2
3
44