#FactCheck-Misleading Video of Building Collapse in Turkey Falsely Shared as Venezuela Earthquake Footage
Executive Summary
A video is being widely shared on social media, claiming it shows a terrifying scene from a recent earthquake in Venezuela. The 9-second clip shows a multi-storey building collapsing like a house of cards, while people nearby are seen running in panic as chaos unfolds. The video is being widely circulated by users as evidence of massive destruction caused by the alleged earthquake in Venezuela. CyberPeace Research Wing research found the claim to be misleading. The viral video has no connection to any recent earthquake in Venezuela. In fact, the footage is from a completely different event that took place nearly three years ago in Turkey. It is being falsely shared with a wrong context on social media.
Claim:
A Facebook user shared the viral video with the caption: “The most dangerous earthquake in 126 years! At least 10,000 deaths in Venezuela earthquake, shocking claim by USGS. Reports say massive destruction has occurred, Caracas airport has also been destroyed. Statement by Yogi Adityanath after Bharat Tiwari’s encounter.” The post link, archived link, and screenshots are provided below.
https://www.facebook.com/groups/2438255879794217/posts/4830038697282578/

FactCheck
To verify the claim, we performed a reverse image search of the video keyframes using Google Lens. During the search, we found the same video on WION’s Facebook page, where it was published on February 6, 2023. The original post link and screenshots are provided below. https://www.facebook.com/watch/?v=917786002738401

The original caption of the video clearly states that it shows a building collapse in Sanliurfa, Turkey, occurring hours after the 7.8-magnitude earthquake that struck the country. Based on clues from the Facebook post, we further searched using relevant keywords and found a report published by The Guardian on February 6, 2023, which also included the viral footage. https://www.theguardian.com/world/video/2023/feb/06/building-collapses-earthquake-aftershock-turkey-video

The report confirms that the video is from the aftermath of the devastating 2023 Turkey earthquake in Sanliurfa, not Venezuela.
Conclusion:
Our research confirms that the viral video has no connection to any recent earthquake in Venezuela. The footage is actually from the 2023 Turkey earthquake and is being falsely shared with a misleading context on social media.
Related Blogs

With AI touching new milestones everyday an increasing need for making it secure is also arising. As these AI companies increase their operations and position in the market as providers of powerful tools in the market. A recent concern due to Anthropic's recent privacy policy update which will be effective from July 8, 2026 shows how companies have begun expanding the amount of personal information they collect in the name of safety, compliance, and trust. While they are being demonstrated as measures to improve safety of users and prevent abuse, it raises important questions about privacy, biometric data, surveillance, data retention, and user autonomy, some of which we will be addressing in this article.
Identity Verification of consumers
One of the most notable update to Anthropic's privacy policy is the category of "Verification Data." According to the policy, users may be asked to verify their age or identity in certain circumstances. Depending on the verification method, Anthropic may collect:
- Images of government-issued identity documents;
- Information appearing on those documents, including identification numbers and date of birth for age verification;
- Photographs or videos of the user;
- Facial geometry templates, which may constitute biometric data under certain legal frameworks; and
- The outcome of the verification process.
At first, this may appear similar to the Know Your Customer (KYC) procedures employed by banks or financial institutions but Claude is not a banking service. It is a consumer AI platform. The issue is not that verification exists, but that the circumstances under which it may be required remain undefined.
THE PROBLEM WITH “CERTAIN CIRCUMSTANCES”
The policy refers to verification being required in "certain circumstances." The public notification from Anthropic mentions that these circumstances may include access to particular features, routine platform integrity checks, abuse prevention mechanisms, policy enforcement activities, or legal compliance obligations. The ambiguity of this phrase raises important concerns. From a user perspective, it is difficult to determine, When verification may be triggered ? Whether verification applies only to suspicious accounts ? Whether access to future features may depend upon verification ? Whether users in particular regions will face more frequent verification requirements ? Whether verification requests may increase as AI regulation expands ? This broad language and discretionary power that the company has along with flexibility in the hands of the company creates uncertainty for users who may have initially joined a platform expecting only an email address and payment information to be required.
Government IDs collection: A new risk category
Almost all AI services have operated without collecting government-issued identity documents. Once a company begins processing such information, the privacy implications change dramatically. Because government issued IDs contain: Full legal names, Dates of birth, Identification numbers, Addresses, Photographs and information regarding nationality. When companies collect these documents, they will have an important database of highly sensitive personal information. Even if the company itself does not retain the documents indefinitely, the existence of a verification process introduces additional privacy and security risks. As per Anthropic has stated that identity verification is conducted through third-party providers such as Persona. According to article on the official site titled ‘Identity verification on Claude’, Persona stores the identity documents and selfie data, while Anthropic retains access to verification records when necessary. From the user's perspective, several important realities remain: First, the data still exists somewhere. Second, another third party organization is now involved in processing highly sensitive personal information. Third, Anthropic retains the ability to access verification records under certain circumstances. Therefore, although Anthropic may not directly maintain copies of every uploaded identity document, the practical result remains that sensitive information enters a broader ecosystem of entities and systems. Identity documents today are among the most valuable forms of personal information from the perspective of fraudsters, cybercriminals, and malicious actors. Therefore, any system that handles such documents becomes an attractive target for attack.
More information on persona’s government ID verification- https://withpersona.com/blog/what-is-government-id-verification
The Biometric Dimension
Another significant aspect of the update is the reference to facial geometry templates. Unlike passwords, biometric identifiers cannot easily be changed if compromised. A person can replace a password or even obtain a new identification card, but they cannot simply obtain a new face. Facial geometry templates are sensitive because they enable automated identity matching. Although these templates, as claimed, are not equivalent to photographs, they are nevertheless derived from unique physical characteristics of a person. In many jurisdictions, including parts of the European Union and several U.S. states, biometric data receives enhanced legal protection because of its permanence and sensitivity, let us see how it unfolds in these jurisdictions.
The Unanswered Retention Question
It is unclear in the policy as to how long the data will be retained because retention limits serve as one of the most important safeguards in modern privacy law, they have given another vague answer that “They're bound to protect it with industry-standard security controls and delete it in line with the retention limits we've set and applicable law.” The longer sensitive information remains stored, the greater the likelihood of unauthorized access, misuse, accidental disclosure, or legal compulsion.
Court Orders and Government Access
Anthropic may be required to disclose information pursuant to valid legal processes such as subpoenas, court orders, warrants, or regulatory directives. The existence of identity verification records means that future requests could potentially be linked to verified identities rather than pseudonymous accounts. This does not mean governments receive unrestricted access to user data. However, it does mean that once identity verification information exists within a company's ecosystem, it may become subject to lawful disclosure requirements. The privacy implications are therefore materially different from those associated with anonymous or pseudonymous AI usage.
Shifting Responsibility onto Users
Another concern is that the privacy policy states that users are responsible for ensuring they possess the necessary rights, permissions, or authority when uploading files, connecting third-party services, or instructing Claude to retrieve information. Anthropic is effectively informing users that they bear responsibility for ensuring that uploaded or connected data is lawfully accessible. As AI assistants gain greater capabilities, this transfer of responsibility from platform to user is likely to become increasingly common. Beyond individual privacy, Anthropic's verification policy also raises larger questions about data sovereignty and the cross-border movement of sensitive personal information. In India, the Justice K.S. Puttaswamy (Retd.) v. Union of India judgment recognized privacy as a fundamental right under Article 21 of the Constitution, affirming that individuals have the right to informational self-determination and control over their personal data. Yet, under Anthropic's verification framework, an Indian user may be required to upload a government-issued identity document and biometric information, which are processed by Persona, a U.S.-based identity verification company acting on behalf of Anthropic. Although users voluntarily consent to this process, it nevertheless results in highly sensitive identity information crossing national borders and entering the control of foreign private entities governed primarily by foreign contractual arrangements and multiple legal regimes. While governments issue identity documents as sovereign instruments of citizenship, their verification and processing are increasingly outsourced to multinational technology companies. Questions arise not only about how securely such information is handled, but also about which country's laws ultimately govern access, retention, disclosure, and accountability when personal data leaves the jurisdiction in which it originated. Under the Digital Personal Data Protection Act, 2023, cross-border transfer of personal data is generally permitted unless the Central Government specifically restricts transfers to certain jurisdictions. Therefore, a foreign company processing identity documents is not, by itself, unlawful but this legality does not eliminate legitimate concerns. Users realistically have limited bargaining power and little practical understanding of how long their identity documents, biometric templates, or verification records will be retained, who within the corporate ecosystem may access them, or how they may be disclosed pursuant to foreign legal processes.
Conclusion
The policy is commendable in some respects because it openly identifies the categories of information that may be collected rather than obscuring them behind vague terminology. However, important concerns remain regarding the extent of verification triggers, the handling of biometric information, the absence of clearly disclosed retention periods, and the long-term implications of linking AI accounts to government-issued identities. As AI systems become more integrated into daily life, these questions will likely become central issues in debates about digital privacy, surveillance, autonomy, and the future governance of artificial intelligence.

Introduction
Recently, in April 2025, security researchers at Oligo Security exposed a substantial and wide-ranging threat impacting Apple's AirPlay protocol and its use via third-party Software Development Kit (SDK). According to the research, the recently discovered set of vulnerabilities titled "AirBorne" had the potential to enable remote code execution, escape permissions, and leak private data across many different Apple and third-party AirPlay-compatible devices. With well over 2.35 billion active Apple devices globally and tens of millions of third-party products that incorporate the AirPlay SDK, the scope of the problem is enormous. Those wireless-based vulnerabilities pose not only a technical threat but also increasingly an enterprise- and consumer-level security concern.
Understanding AirBorne: What’s at Stake?
AirBorne is the title given to a set of 23 vulnerabilities identified in the AirPlay communication protocol and its related SDK utilised by third-party vendors. Seventeen have been given official CVE designations. The most severe among them permit Remote Code Execution (RCE) with zero or limited user interaction. This provides hackers the ability to penetrate home networks, business environments, and even cars with CarPlay technology onboard.
Types of Vulnerabilities Identified
AirBorne vulnerabilities support a range of attack types, including:
- Zero-Click and One-Click RCE
- Access Control List (ACL) bypass
- User interaction bypass
- Local arbitrary file read
- Sensitive data disclosure
- Man-in-the-middle (MITM) attacks
- Denial of Service (DoS)
Each vulnerability can be used individually or chained together to escalate access and broaden the attack surface.
Remote Code Execution (RCE): Key Attack Scenarios
- MacOS – Zero-Click RCE (CVE-2025-24252 & CVE-2025-24206) These weaknesses enable attackers to run code on a MacOS system without any user action, as long as the AirPlay receiver is enabled and configured to accept connections from anyone on the same network. The threat of wormable malware propagating via corporate or public Wi-Fi networks is especially concerning.
- MacOS – One-Click RCE (CVE-2025-24271 & CVE-2025-24137) If AirPlay is set to "Current User," attackers can exploit these CVEs to deploy malicious code with one click by the user. This raises the level of threat in shared office or home networks.
- AirPlay SDK Devices – Zero-Click RCE (CVE-2025-24132) Third-party speakers and receivers through the AirPlay SDK are particularly susceptible, where exploitation requires no user intervention. Upon compromise, the attackers have the potential to play unauthorised media, turn microphones on, or monitor intimate spaces.
- CarPlay Devices – RCE Over Wi-Fi, Bluetooth, or USB CVE-2025-24132 also affects CarPlay-enabled systems. Under certain circumstances, the perpetrators around can take advantage of predictable Wi-Fi credentials, intercept Bluetooth PINs, or utilise USB connections to take over dashboard features, which may distract drivers or listen in on in-car conversations.
Other Exploits Beyond RCE
AirBorne also opens the door for:
- Sensitive Information Disclosure: Exposing private logs or user metadata over local networks (CVE-2025-24270).
- Local Arbitrary File Access: Letting attackers read restricted files on a device (CVE-2025-24270 group).
- DoS Attacks: Exploiting NULL pointer dereferences or misformatted data to crash processes like the AirPlay receiver or WindowServer, forcing user logouts or system instability (CVE-2025-24129, CVE-2025-24177, etc.).
How the Attack Works: A Technical Breakdown
AirPlay sends on port 7000 via HTTP and RTSP, typically encoded in Apple's own plist (property list) form. Exploits result from incorrect treatment of these plists, especially when skipping type checking or assuming invalid data will be valid. For instance, CVE-2025-24129 illustrates how a broken plist can produce type confusion to crash or execute code based on configuration.
A hacker must be within the same Wi-Fi network as the targeted device. This connection might be through a hacked laptop, public wireless with shared access, or an insecure corporate connection. Once in proximity, the hacker has the ability to use AirBorne bugs to hijack AirPlay-enabled devices. There, bad code can be released to spy, gain long-term network access, or spread control to other devices on the network, perhaps creating a botnet or stealing critical data.
The Espionage Angle
Most third-party AirPlay-compatible devices, including smart speakers, contain built-in microphones. In theory, that leaves the door open for such devices to become eavesdropping tools. While Oligo did not show a functional exploit for the purposes of espionage, the risk suggests the gravity of the situation.
The CarPlay Risk Factor
Besides smart home appliances, vulnerabilities in AirBorne have also been found for Apple CarPlay by Oligo. Those vulnerabilities, when exploited, may enable attackers to take over an automobile's entertainment system. Fortunately, the attacks would need pairing directly through USB or Bluetooth and are much less practical. Even so, it illustrates how networks of connected components remain at risk in various situations, ranging from residences to automobiles.
How to Protect Yourself and Your Organisation
- Immediate Actions:
- Update Devices: Ensure all Apple devices and third-party gadgets are upgraded to the latest software version.
- Disable AirPlay Receiver: If AirPlay is not in use, disable it in system settings.
- Restrict AirPlay Access: Use firewalls to block port 7000 from untrusted IPs.
- Set AirPlay to “Current User” to limit network-based attack.
- Organisational Recommendations:
- Communicate the patch urgency to employees and stakeholders.
- Inventory all AirPlay-enabled hardware, including in meeting rooms and vehicles.
- Isolate vulnerable devices on segmented networks until updated.
Conclusion
The AirBorne vulnerabilities illustrate that even mature systems such as Apple's are not immune from foundational security weaknesses. The extensive deployment of AirPlay across devices, industries, and ecosystems makes these vulnerabilities a systemic threat. Oligo's discovery has served to catalyse immediate response from Apple, but since third-party devices remain vulnerable, responsibility falls to users and organisations to install patches, implement robust configurations, and compartmentalise possible attack surfaces. Effective proactive cybersecurity hygiene, network segmentation, and timely patches are the strongest defences to avoid these kinds of wormable, scalable attacks from becoming large-scale breaches.
References
- https://www.oligo.security/blog/airborne
- https://www.wired.com/story/airborne-airplay-flaws/
- https://thehackernews.com/2025/05/wormable-airplay-flaws-enable-zero.html
- https://www.securityweek.com/airplay-vulnerabilities-expose-apple-devices-to-zero-click-takeover/
- https://www.pcmag.com/news/airborne-flaw-exposes-airplay-devices-to-hacking-how-to-protect-yourself
- https://cyberguy.com/security/hackers-breaking-into-apple-devices-through-airplay/

Introduction
Embark on a groundbreaking exploration of the Darkweb Metaverse, a revolutionary fusion of the enigmatic dark web with the immersive realm of the metaverse. Unveiling a decentralised platform championing freedom of speech, the Darkverse promises unparalleled diversity of expression. However, as we delve into this digital frontier, we must tread cautiously, acknowledging the security risks and societal challenges that accompany the metaverse's emergence.
The Dark Metaverse is a unique combination of the mysterious dark web and the immersive digital world known as the metaverse. Imagine a place where users may participate in decentralised social networking, communicate anonymously, and freely express a range of viewpoints. It aims to provide an alternative to traditional online platforms, emphasizing privacy and freedom of speech. Nevertheless, it also brings new kinds of criminality and security issues, so it's important to approach this digital frontier cautiously.
In the vast expanse of the digital cosmos, there exists a realm that remains shrouded in mystery to the casual netizen—the dark web. It is a place where the surface web, the familiar territory of Google searches and social media feeds, constitutes a mere 5 per cent of the information iceberg floating in an ocean of data. Beneath this surface lies the deep web and the dark web, comprising the remaining 95 per cent, a staggering figure that beckons the brave and curious to explore its abysmal depths.
Imagine, a platform that not only ventures into these depths but intertwines them with the emerging concept of the metaverse—a digital realm that defeats the limitations of the physical world. This is the vision of the Darkweb Metaverse, the world’s premier endeavour to harness the enigmatic depths of the dark web and fuse it into the immersive experience of the metaverse.
As per Internet User Statistics 2024, There are over 5.3 billion Internet users in the world, meaning over 65% of the world’s population has access to the Internet. The Internet is used for various services. News, entertainment, and communication to name a few. The citizens of developed countries depend on the World Wide Web for a multitude of daily tasks such as academic research, online shopping, E-banking, accessing news and even ordering food online hence the Internet has become an integral part of our daily lives.
Surface Web
This layer of the internet is used by the general public on a daily basis. The contents of this layer are accessed by standard web browsers namely Google Chrome, and Mozilla Firefox to name a few. The contents of this layer of the internet are indexed by these search engines.
Deep Web
This is the second layer of the internet; its contents are not indexed by search engines. The content that is unavailable on the surface web is considered to be a part of the deep web. The deep web comprises a collection of various types of confidential information. Several Schools, Universities, Institutes, Government Offices and Departments, Multinational Companies (MNCs), and Private Companies store their database information and website-oriented server information such as online profile and accounts usernames or IDs and passwords or log in credentials and companies' premium subscription data and monetary transactional records in the Intra-net which is part of the deep web.
Dark Web
It is the least explored part of the internet which is considered to be a hub of various bizarre activities. The contents of the dark web are not indexed by search engines and specific software is required to access this layer of the internet namely TOR (The Onion Router) browser which cloaks to identify its users making them anonymous. The websites of the dark web are identified from .onion TLD (Top Level Domain). Due to anonymity provided in this layer, various criminal activities take place over there including Drugs trading, Arms trading, and Illegal PayPal account details to websites offering child pornography.
The Darkverse
The Darkweb Metaverse is not a mere novelty; it is a revolutionary step forward, a decentralised social networking platform that stands in stark contrast to centralised counterparts like YouTube or Twitter. Here, the spectre of censorship is banished, and the freedom of speech reigns supreme.
The architectonic prowess behind the Darkweb Metaverse is formidable. The development team is a coalition of former infrastructure maestros from Theta Network and virtuosos of metaverse design, bolstered by backend engineers from Gensokishi Metaverse. At the helm is a CEO whose tenure at the apex of large Japanese companies has endowed him with a profound understanding of the landscape, setting a solid foundation for the platform's future triumphs.
Financially, the dark web has been a flourishing underworld, with revenues ranging from $1.5 billion to $3.1 billion between 2020 and 2022. Darkverse, with its emphasis on user-friendliness and safety, is poised to capture a significant portion of this user base. The platform serves as a truly decentralised amalgamation of the Dark Web, Metaverse, and Social Networking Services (SNS), with a mission to provide an unassailable bastion for freedom of speech and expression.
The Darkweb Metaverse is not merely a sanctuary for anonymity and privacy; it is a crucible for the diversity of expression. In a world where centralised platforms can muzzle voices, Darkverse stands as a bulwark against such suppression, fostering a community where a kaleidoscope of opinions and information thrives. The ease of use is unparalleled—a one-time portal that obviates the need for third-party software to access the dark web, protecting users from the myriad risks that typically accompany such ventures.
Moreover, the platform's ability to verify the authenticity of information is a game-changer. In an era laced with misinformation, especially surrounding contentious issues like war, Darkverse offers a sign of truth where the source of information can be scrutinised for its accuracy.
Integrating Technologies
The metaverse will be an immersive iteration of the internet, decked with interactive features of emerging technologies such as artificial intelligence, virtual and augmented reality, 3D graphics, 5G, holograms, NFTs, blockchain and haptic sensors. Each building block, while innovative, carries its own set of risks—vulnerabilities and design flaws that could pose a serious threat to the integrated meta world.
The dark web's very nature of interaction through avatars makes it a perfect candidate for a metaverse iteration. Here, in this anonymous world, commercial and personal engagements occur without the desire to unveil real identities. The metaverse's DNA is well-suited to the dark web, presenting a formidable security challenge as it is likely to evolve more rapidly than its real-world counterpart.
While Meta (formerly Facebook) is a prominent entity developing the metaverse, other key players include NVIDIA, Epic Games, Microsoft, Apple, Decentraland, Roblox Corporation, Unity Software, Snapchat, and Amazon. These companies are integral to constructing the vast network of real-time 3D virtual worlds where users maintain their identities and payment histories.
Yet, with innovation comes risk. The metaverse will necessitate police stations, not as a dystopian oversight but as a means to address the inherent challenges of a new digital society. In India, for instance, the integration of law enforcement within the metaverse could revolutionize the public's interaction with the police, potentially increasing the reporting of crimes.
The Perils within the Darkverse
The metaverse will also be a fertile ground for crimes of a new dimension—identity theft, digital asset hijacking, and the influence of metaverse interactions on real-world decisions. With a significant portion of social media profiles potentially being fraudulent, the metaverse amplifies these challenges, necessitating robust identity access management.
The integration of NFTs into the metaverse ecosystem is not without its security concerns, as token breaches and hacks remain a persistent threat. The metaverse's parallel economy will test the developers' ability to engender trust, a Herculean task that will challenge the boundaries of national economies.
Moreover, the metaverse will be a crucible for social engineering-based attacks, where the real-time and immersive nature of interactions could make individuals particularly vulnerable to deception and manipulation. The potential for early-stage fraud, such as the hyping and selling of virtual assets at unrealistic prices, is a stark reality.
The metaverse also presents numerous risks, particularly for children and adolescents who may struggle to distinguish between virtual and real worlds. The implications of such immersive experiences are intense, with the potential to influence behaviour in hazardous ways.
Security risks extend to the technologies supporting the metaverse, such as virtual and augmented reality. The exploitation of biometric data, the bridging of virtual and real worlds, and the tendency for polarisation and societal isolation are all issues requiring immediate attention.
A Way Forward
As we stand on the cusp of this new digital frontier, it is evident that the metaverse, despite its reliance on blockchain, is not immune to the privacy and security breaches that have plagued conventional IT infrastructure. Data security, Identity theft, network security, and ransomware attacks are just a few of the challenges on the way.
In this quest into the unknown, the Darkweb Metaverse radiates with the promise of freedom and the thrill of discovery. Yet, as we navigate these shadowy depths, we must remain vigilant, for the very technologies that empower us also rear the seeds of our grim vulnerabilities. The metaverse is not just a new chapter in the story of the internet—it is a whole narrative, one that we must write with caution and care.
References
- https://spores.medium.com/the-worlds-first-platform-to-deploy-the-dark-web-in-the-metaverse-releap-ido-on-spores-launchpad-a36387b184de
- https://www.makeuseof.com/how-hackers-sell-trade-data-in-metaverse/
- https://www.demandsage.com/internet-user-statistics/#:~:text=There%20are%20over%205.3%20billion,has%20access%20to%20the%20Internet.