#FactCheck: Old Jerusalem Clash Video Falsely Shared as Chaos at Tel Aviv Airport
Research Wing
Innovation and Research
PUBLISHED ON
Mar 20, 2026
10
Executive Summary
A video is being widely shared on social media showing a group of people clashing near a counter. The clip is being claimed to be from Ben Gurion Airport in Tel Aviv, Israel. Users allege that panic caused by Iranian missile threats has led people to try to flee the country, resulting in chaos and fights over flight tickets. However, a research by the CyberPeace found the claim to be false. Our findings reveal that the video is not related to the recent tensions and is actually from 2025.
Claim:
The viral video is being shared with the claim that chaos has erupted at Tel Aviv’s airport, with people trying to leave Israel due to Iranian attacks. An X user named “AjjuShane Experience (@AjjuShane)” shared the video with the caption: “We need tickets, we need flights, we want to leave Israel. We will not stay here until Iranian missiles crush us. Clashes are now happening at Tel Aviv’s Ben Gurion Airport.”
To verify the claim, we extracted keyframes from the video and conducted a reverse image search on Google. During the research , we found the same video on a Facebook page named Ynet, where it was shared on July 20, 2025.
The video carried a caption in Hebrew. Upon translation, it stated that the incident took place at “Cinema City” in Jerusalem, where dozens of Jewish youths clashed with Arab cafeteria workers. The visuals showed youths vandalizing property and throwing objects at staff members, while staff retaliated. Some individuals sustained minor injuries, but no serious harm was reported. We also found the same video on the YouTube channel of The Times of India, published on July 20, 2025. The caption mentioned that anti-Arab riots broke out inside a Cinema City theatre in Jerusalem on July 19, showing youths vandalizing the premises and clashing with Arab employees.
Our research clearly shows that the viral video is from 2025 and unrelated to any recent Iran-Israel tensions. It is being misleadingly shared as a recent incident from Tel Aviv airport.
CVE 2024-3094 is a backdoor vulnerability recently found in Kali Linux installations that happened between March 26th to 29th. This vulnerability was found in XZ package version 5.6.0 to 5.6.1. It could allow the malicious actor to compromise SSHD authentication, and grant unauthorized access to the entire system remotely. The users who have installed or updated Kali Linux during the said time are advised to update their system to safeguard against this vulnerability.
The Dangerous Backdoor
The use of the malicious implant found in XZ Utils as a remote code execution tool makes it more dangerous, because of its ability to compromise the affected systems. Initially, researchers believed the vulnerability enabled an authentication bypass for the OpenSSH server (SSHD) process. However, further analysis revealed it is better characterized as a remote code execution (RCE) vulnerability.
The backdoor intercepts the RSA_public_decrypt function, verifies the host's signature using a fixed Ed448 key, and if successful, executes malicious code passed by the attacker via the system() function. This leaves no trace in SSHD logs and makes it difficult to detect the vulnerability.
Impacted Linux Distributions
The compromised versions of XZ Utils have been found in the following Linux distributions released in March 2024:
Kali Linux (between March 26 and March 29)
openSUSE Tumbleweed and openSUSE MicroOS (March 7 to March 28)
Fedora 41, Fedora Rawhide, and Fedora Linux 40 beta
Debian (testing, unstable, and experimental distributions only)
Arch Linux container images (February 29 to March 29)
Meanwhile, distributions such as Red Hat Enterprise Linux (RHEL), SUSE Linux Enterprise, openSUSE Leap, and Debian Stable are not believed to be affected.
How Did This Happen?
The malicious code appears to have been inserted by taking advantage of a typical control transfer vulnerability. The original maintainer of the XZ Libs project on GitHub handed over control of the repository to an account that had been contributing to various data compression-related projects for several years. It was at this point that the backdoor was implanted in the project code.
Fortunately, the Potential Disaster Was Averted
As per Igor Kuznetsov, head of Kaspersky's Global Research and Analysis Team (GReAT), the vulnerability CVE-2024-3094 is considered as the largest scale attack that has happened in the Linux ecosystem history. Because it targeted the primary remote management tool for Linux servers on the internet which is SSH servers.
As this vulnerability was detected in the testing and rolling distributions in the short period of time, where the latest software packages are used. This results to the minimum damage to the linux users and so far no case of CVE-2024-3094 being actively exploited have been detected.
Staying Safe
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) advises that users who installed or updated the affected operating systems in March immediately roll back to XZ Utils 5.4.6 version and be on alert for any malicious activity. It is recommended to change the passwords in the case of a distribution where a weak version of XZ Utils has been installed.
The Yara rule has been released to detect any infected systems by CVE-2024-3094 Vulnerability.
Conclusion
The discovery of the XZ Utils backdoor provides a reminder to be vigilant in the open source software environment. This supply chain attack highlights the importance of strong security measures, elaborate code reviews, and regular distribution of security updates to provide shield against such vulnerabilities. Always staying informed and taking the necessary precautions, Linux users can mitigate the potential impact of this vulnerability to keep their systems safe.
As Tamil Nadu voted in the 2026 Assembly elections, with 84.69 percent polling recorded on April 23, a purported cover page of Frontline magazine began circulating on social media. The viral image featured a massive rally crowd of South Indian actor and Tamilaga Vetri Kazhagam (TVK) chief Joseph Vijay, claiming that a “Vijay Wave” had emerged in the state. The alleged cover also stated that Tamil Nadu was witnessing a new political force after five decades, one that had challenged the dominance of Dravida Munnetra Kazhagam (DMK) and All India Anna Dravida Munnetra Kazhagam (AIADMK).
However, research by the CyberPeace Research Wing found that the viral cover page is fake. Frontline magazine has not published any such edition, and its latest issue is related to health.
Claim:
X user “Dr. Ravishankar Sadasivam” shared the viral image on April 22, 2026, claiming the “wave is real” and suggesting that Vijay could emerge as a top contender in a three-cornered contest. The post further claimed that after MGR, Vijay was drawing the largest spontaneous crowds in Tamil Nadu politics.
To verify the claim, relevant keyword searches were conducted online. During the research, a clarification post from Frontline magazine’s official X account, shared on April 22, 2026, was found. In the post, the publication clearly stated that the viral cover page was fake and had not been published by the magazine. It further said that the fabricated cover was being circulated online by supporters of TVK.
Additionally, the viral image was analyzed using the AI detection tool Hive Moderation, which rated it as 92 percent likely to be AI-generated.
Conclusion:
The claim that Frontline magazine published a cover story on a “Vijay Wave” during the Tamil Nadu Assembly elections is false. The viral cover page is fake and is being circulated online to mislead people.
All citizens are using tech to their advantage, and so we see a lot of upskilling among the population leading to innovation in India. As we go deeper into cyberspace, we must maintain our cyber security efficiently and effectively. When bad actors use technology to their advantage, we often see data loss or financial loss of the victim, In this blog, we will shine light upon two new forms of cyber attacks, causing havoc upon the innocent. The “Daam” Malware and a new malicious app are the two new issues.
Daam Botnet
Since 2021, the DAAM Android botnet has been used to acquire unauthorised access to targeted devices. Cybercriminals use it to carry out different destructive actions. Using the DAAM Android botnet’s APK binding service, threat actors can combine malicious code with a legitimate application. Keylogging, ransomware, VOIP call records, runtime code execution, browser history collecting, incoming call recording, PII data theft, phishing URL opening, photo capture, clipboard data theft, WiFi and data status switching, and browser history gathering are just a few of the functions offered by the DAAM Android botnet. The DAAM botnet tracks user activity using the Accessibility Service and stores keystrokes it has recorded together with the name of the programme package in a database. It also contains a ransomware module that encrypts and decrypts data on the infected device using the AES method.
Additionally, the botnet uses the Accessibility service to monitor the VOIP call-making features of social media apps like WhatsApp, Skype, Telegram, and others. When a user engages with these elements, the virus begins audio recording.
The Malware
CERT-IN, the central nodal institution that reacts to computer security-related issues, claims that Daam connects with various Android APK files to access a phone. The files on the phone are encrypted using the AES encryption technique, and it is distributed through third-party websites.
It is claimed that the malware can damage call recordings and contacts, gain access to the camera, change passwords, take screenshots, steal SMS, download/upload files, and perform a variety of other things.
Safeguards and Guidelines by Cert-In
Cert-In has released the guideline for combating malware. These were issued in the public interest. The recommendations by Cert-In are as follows-
Only download from official app stores to limit the risk of potentially harmful apps.
Before downloading an app, always read the details and user reviews; likewise, always give permissions that are related to the program’s purpose.
Install Android updates solely from Android device vendors as they become available.
Avoid visiting untrustworthy websites or clicking on untrustworthy
Install and keep anti-virus and anti-spyware software up to date.
Be cautious if you see mobile numbers that appear to be something other than genuine/regular mobile numbers.
Conduct sufficient investigation Before clicking on a link supplied in a communication.
Only click on URLs that clearly display the website domain; avoid abbreviated URLs, particularly those employing bit.ly and tinyurl.
Use secure browsing technologies and filtering tools in antivirus, firewall, and filtering services.
Before providing sensitive information, look for authentic encryption certificates by looking for the green lock in your browser’s URL information, look for authentic encryption certificates by looking for the green lock in your browser’s URL bar.
Any ‘strange’ activity in a user’s bank account must be reported immediately to the appropriate bank.
New Malicious App
From the remote parts of Jharkhand, a new form of malicious application has been circulated among people on the pretext of a bank account closure. The bad actors have always used messaging platforms like Whatsapp and Telegram to circulate malicious links among unaware and uneducated people to dupe them of their hard-earned money.
They send an ordinary-looking message on Whatsapp or Telegram where they mention that the user has a bank account at ICICI bank and, due to irregularity with the credentials, their account is being deactivated. Further, they ask users to update their PAN card to reactivate their account by uploading the PAN card on an application. This app, in turn, is a malicious app that downloads all the user’s personal credentials and shares them with the bad actors via text message, allowing them to bypass banks’ two-factor authentication and drain the money from their accounts. The Jharkhand Police Cyber Cells have registered numerous FIRs pertaining to this type of cybercrime and are conducting full-scale investigations to apprehend the criminals.
Conclusion
Malware and phishing attacks have gained momentum in the previous years and have become a major contributor to the tally of cybercrimes in the country. DaaM malware is one of the examples brought into light due to the timely action by Cert-In, but still, a lot of such malware are deployed by bad actors, and we as netizens need to use our best practices to keep such criminals at bay. Phishing crimes are often substantiated by exploiting vulnerabilities and social engineering. Thus working towards a rise in awareness is the need of the hour to safeguard the population by and large.
Become a part of our vision to make the digital world safe for all!
Numerous avenues exist for individuals to unite with us and our collaborators in fostering global cyber security
Awareness
Stay Informed: Elevate Your Awareness with Our Latest Events and News Articles Promoting Cyber Peace and Security.
Your institution or organization can partner with us in any one of our initiatives or policy research activities and complement the region-specific resources and talent we need.