#FactCheck - Viral image circulating on social media depicts a natural optical illusion from Epirus, Greece.
Executive Summary:
A viral image circulating on social media claims it to be a natural optical illusion from Epirus, Greece. However, upon fact-checking, it was found that the image is an AI-generated artwork created by Iranian artist Hamidreza Edalatnia using the Stable Diffusion AI tool. CyberPeace Research Team found it through reverse image search and analysis with an AI content detection tool named HIVE Detection, which indicated a 100% likelihood of AI generation. The claim of the image being a natural phenomenon from Epirus, Greece, is false, as no evidence of such optical illusions in the region was found.

Claims:
The viral image circulating on social media depicts a natural optical illusion from Epirus, Greece. Users share on X (formerly known as Twitter), YouTube Video, and Facebook. It’s spreading very fast across Social Media.

Similar Posts:


Fact Check:
Upon receiving the Posts, the CyberPeace Research Team first checked for any Synthetic Media detection, and the Hive AI Detection tool found it to be 100% AI generated, which is proof that the Image is AI Generated. Then, we checked for the source of the image and did a reverse image search for it. We landed on similar Posts from where an Instagram account is linked, and the account of similar visuals was made by the creator named hamidreza.edalatnia. The account we landed posted a photo of similar types of visuals.

We searched for the viral image in his account, and it was confirmed that the viral image was created by this person.

The Photo was posted on 10th December, 2023 and he mentioned using AI Stable Diffusion the image was generated . Hence, the Claim made in the Viral image of the optical illusion from Epirus, Greece is Misleading.
Conclusion:
The image claiming to show a natural optical illusion in Epirus, Greece, is not genuine, and it's False. It is an artificial artwork created by Hamidreza Edalatnia, an artist from Iran, using the artificial intelligence tool Stable Diffusion. Hence the claim is false.
Related Blogs

Introduction
In an extensive order of 144 pages passed on May 29, 2026, Justice Sachin Datta of the Delhi High Court inter alia affirmed the right of an acquitted or discharged person to reinstate their digital identity. In a batch of more than 30 petitions relating to acquittals, family dispute cases, quashed criminal cases, and parties to proceedings, the petitioners argued that court documents and accusations, having lost their purpose, have kept occupying the search engine, leading to infringement of dignity, privacy, and career and personal life of these individuals. Citing Article 21 of the Indian Constitution as its foundation, the court affirmed that a right to life and personal liberty also includes a right to privacy and to leave behind failed proceedings and adopted wide de-indexing policies, including, where necessary, global de-indexing, thereby ushering in India's "right to be forgotten."
The Constitutional Argument: Article 21 and the Digital Self
The constitutional basis of the right to be forgotten in India rests on the landmark nine-judge bench ruling in Justice K.S. Puttaswamy v. Union of India. In 2017, the Supreme Court ruled privacy to be a fundamental right under Article 21 of the Constitution and stated informational privacy is a facet of personal liberty. The Supreme Court observed that individuals have an interest in determining how the information concerning them is gathered, disseminated, and accessed.
Building upon this precedent, Justice Sachin Datta held that the right to be forgotten flows naturally from the constitutional guarantee of informational privacy. The judgment represents one of the most significant judicial applications of the Puttaswamy principles, particularly in the context of search engines and online judicial records. Noting the absence of a fully operational statutory framework despite the enactment of the Digital Personal Data Protection Act, 2023, the court exercised its constitutional jurisdiction to protect individuals from enduring digital harm caused by continued public accessibility of outdated or irrelevant personal information.
INDIAN APPLICATION OF THE GLOBAL PRECEDENT
Tracing back the genesis of this right, it lies in the worldwide jurisdiction on privacy, especially the European Court of Justice's landmark ruling of 2014 in Google Spain SL v. AEPD and Mario Costeja Gonzlez, where it ruled that it is within one's power to ask search engines to de-list links that show personal information that is found to be outdated or irrelevant. This led to a legislated right to erasure by the inclusion of Article 17 in the General Data Protection Regulation (GDPR), creating the right throughout the EU. India, on the other hand, saw a slow process of evolution when it came to this right. The Madras High Court acknowledged the right to be forgotten partially in 2021 when it directed a petitioner's name to be deleted from an acquittal judgment, which was affirmed by a Division Bench in 2024. Nevertheless, the above were merely judgments confined to the facts of a particular case. However, the decision of the Delhi High Court dated May 2026 proves to be the benchmark in laying down a comprehensive constitutional framework under Article 21 with guiding principles on when a request for de-linking would be entertained and, if warranted, would be extended throughout the world.
Anatomy of the Framework by the Delhi High Court
While Justice Sachin Datta’s ruling recognizes the right to be forgotten, its actual import lies in devising an operative framework. The Court noted that it would maintain judicial records indefinitely in keeping with open justice principles, but an individual's name may not act as a perennial search key with respect to private entities' search engines. Thus, courts will be allowed to de-index judicial records (except their legal reasoning, findings, and ratio decidendi, which will continue to be accessible) from the names appearing therein from search engines and legal databases. While personally identifying data will be obfuscated, the underlying legal reasoning will not be rendered unusable, as access to unredacted records will continue to be available to courts, parties, and authorities. Such orders are also possible to be effective internationally, rendering avoidance difficult. However, the right cannot be absolute, as it is largely unavailable for convicted individuals (particularly if convicted of offenses against women or children or crimes of breach of trust). Courts must pass a proportionality test in considering the balance between privacy and the public right to know. By stating that masking information has an impact on discoverability, not access, it achieves a reconciliation between informational privacy and open justice so that acquitted accused are not held hostage to past accusations forever in the online age.
The Road to Implementation
However, the judgment presents a thick knot of practical issues, the solution to which may take considerable time to untangle. How will petitions for masking orders be filed by those who need them? Will there be a prescribed form? How will legal database systems such as Indian Kanoon and SCC Online operationalize name-based de-indexing while keeping their vast archives usable for lawyers? More significantly, what kind of legal force will global directions for de-indexing hold over those search engines whose main servers lie outside of Indian territory?
This is not to say the judgment isn't important. It simply presents a predictable, almost mundane set of issues that all ambitious pronouncements on constitutional rights face when translated into the world of administration issues that came up even when the EU was first struggling with enforcing the GDPR in 2018. India now has its framework, and the details of its implementation will undoubtedly come through future rounds of litigation, guidelines, and perhaps even legislation.
What remains abundantly clear, though, is the message conveyed by the Delhi High Court that digital permanency is a crime, especially when it causes the most incriminating of a person's legal actions to follow them perpetually, even long after they have been given due process by the system. As Justice Datta eloquently put it, privacy in the digital age is 'not about secrecy but about an individual's control over the dissemination of personal information.' "Now an element of constitutional law in India, the verdict is a declaration that will resonate long beyond the thirty-odd petitions that called it into being.
Conclusion
The ultimate finding of the 2026 right-to-be-forgotten judgment in Delhi High Court reinforces human dignity in the digital era. The Court has acknowledged the need for acquittals and exonerations to have meaningful implications offline, ensuring an individual is not eternally punished through online searches for alleged wrongdoing. Building on the right to privacy established by K.S. Puttaswamy v. Union of India, informational privacy now stands at the core of constitutional guarantees, and India joins the nations establishing precedents to balance openness with dignity.

2025 is knocking firmly at our door and we have promises to make and resolutions to keep. Time you make your list for the New Year and check it twice.
- Lifestyle targets 🡪 Check
- Family targets 🡪 Check
- Social targets 🡪 Check
Umm, so far so good, but what about your cybersecurity targets for the year? Hey, you look confused and concerned. Wait a minute, you do not have one, do you?
I get it. Though the digital world still puzzles, and sometimes outright scares us, we still are not in the ‘Take-Charge-Of-Your-Digital-Safety Mode. We prefer to depend on whatever software security we are using and keep our fingers crossed that the bad guys (read threat actors) do not find us.
Let me illustrate why cybersecurity should be one of your top priorities. You know that stress is a major threat to our continued good health, right? However, if your devices, social media accounts, office e-mail or network, or God forbid, bank accounts become compromised, would that not cause stress? Think about it and the probable repercussions and you will comprehend why I am harping on prioritising security.
Fret not. We will keep it brief as we well know you have 101 things to do in the next few days leading up to 01/01/2025. Just add cyber health to the list and put in motion the following:
- Install and activate comprehensive security software on ALL internet-enabled devices you have at home. Yes, including your smartphones.
- Set yourself a date to change and create separate unique passwords for all accounts. Or use the password manager that comes with all reputed security software to make life simpler.
- Keep home Wi-Fi turned off at night
- Do not set social media accounts to auto-download photos/documents
- Activate parental controls on all the devices used by your children to monitor and mentor them. But keep them apprised.
- Do not blindly trust anyone or anything online – this includes videos, speeches, emails, voice calls, and video calls. Be aware of fakes.
- Be aware of the latest threats and talk about unsafe cyber practices and behaviour often at home.
Short and sweet, as promised.
We will be back, with more tips, and answers to your queries. Drop us a line anytime, and we will be happy to resolve your doubts.
Ciao!

Introduction
Web applications are essential in various sectors, including online shopping, social networks, banking, and healthcare systems. However, they also pose numerous security threats, including Cross-Site Scripting (XSS), a client-side code injection vulnerability. XSS attacks exploit the trust relationship between users and websites, allowing them to change web content, steal private information, hijack sessions, and gain full control of user accounts without breaking into the core server. This vulnerability is part of the OWASP Top 10 Web Application Security Risks.
What is Cross-Site Scripting (XSS)?
An XSS attack occurs when an attacker injects client-side scripts into web pages viewed by other users. When users visit the affected pages, their browsers naively execute the inserted scripts. The exploit takes advantage of web applications that allow users to submit content without properly sanitising inputs or encoding outputs. These scripts can cause a wide range of damage, including but not limited to stealing session cookies for session hijacking, redirecting users to malicious sites, logging keystrokes to capture credentials, and altering the DOM to display fake or phishing content.
How Does XSS Work?
- Injection: A malicious user submits code through a website input, like a comment or form.
- Execution: The submitted code runs automatically in the browsers of other users who view the page.
- Exploitation:The attacker can steal session information, capture credentials, redirect users, or modify the page content.
The fundamental cause behind the XSS vulnerabilities is the application of:
- Accepting trusted input from the users.
- After users' input, web pages have the strings embedded without any sanitisation.
- Not abiding by security policies like Content Security Policy (CSP).
With such vulnerabilities, attackers can generate malicious payloads like: <script>alert('XSS');</script>
This code might seem simple, but its execution provides the attacker with the possibility to do the following:
- Copy session tokens through hidden HTTP requests.
- From attacker-controlled domains, load attacker scripts.
- Change the DOM structure to show fake login forms for phishing.
Types of XSS Attacks: XSS (Cross-Site Scripting) attacks can occur in three main variations:
- Stored XSS: This type of attack occurs when an attacker injects an administered payload into the database or a message board. The script then runs whenever a user visits the affected board.
- Reflected XSS: In this attack, the danger lies in a parameter of the URL. Its social engineering techniques are attacks, in which it requires tricking people to click on a specially designed link. For example:
- DOM-Based XSS: This technique injects anything harmful without the need for server-side scripts, in contrast to other approaches. It targets JavaScript client-side scripts such as `document.write` and `innerHTML`. Without carrying out any safety checks, these scripts will alter the page's look (DOM stands for Document Object Model). If the hash is given a malicious string, it is run directly within the browser.
What Makes XSS a Threat?
A Cross-Site Scripting attack is only a primary attack vector, and can lead to significant damage that includes the following:
- Statement Hijacking. This uses scripts to steal cookies, which are then used to pose as authorized users.
- Theft of Credentials. Users’ passwords and usernames are wrenched from keystroke trackers.
- Phishing. Users are prompted with deceitful login forms that are used to capture sensitive details.
- Website Vandalism. Modified website material lowers the esteem of the brand.
- Monetary and Legal Consequences. There are compounding effects to GDPR and DPDP Act compliance in case of Data breaches, which incur penalties and fines.
Incidents in the Real World
In 2021, an XSS Stored attack occurred on a famous e-commerce platform eBay, through their product review system. The malicious JavaScript code was set to trigger every time an infected product page was accessed by customers. This caused a lot of problems, including account takeovers, unauthorised purchases, and damage to the company’s reputation. This example further worsens the fact that even reputed platforms can be targeted by XSS attacks.
How to Prevent XSS?
Addressing XSS vulnerabilities demands attention to detail and coordinated efforts across functions, as illustrated in the steps below:
Input Validation and Output Encoding:
- Ensure input validation is in place on the client and server.
- Perform output encoding relative to context: HTML: <, >, &.
- JavaScript: Escape quotes and slashes
Content Security Policy (CSP): CSP allows scripts to be executed only from the verified sources, which helps diminish the odds of harmful scripts running on your website. For example, the Header in the code could look to some degree like this: Content-Security-Policy: script-src 'self';
Unsafe APIs should be dodged: Avoid the use of document.write(), innerHTML, and eval(), and make sure to use:
- TextContent for inserting text.
- CreateElement() and other DOM creation methods for structured content.
Secure Cookies: Apply the HttpOnly and Secure cookie flags to block JavaScript access.
Framework Protections: Use the protective features in frameworks such as:
- React, which escapes data embedded in JSX automatically.
- Angular, which uses context-aware sanitisation.
Periodic Security Assessment:
- Use DAST tools to test the security posture of an application.
- Perform thorough penetration testing and security-oriented code reviews.
Best Practices for Developers: Assume a Secure Development Lifecycle (SDLC) integrating XSS stoppage at each point.
- Educate developers on OWASP secure coding guidelines.
- Automate scanning for vulnerabilities in CI/CD pipelines.
Conclusion:
To reduce the potential danger of XSS, both developers and companies must be diligent in their safety initiatives, ranging from using Content Security Policies (CSP) to verifying user input. Web applications can shield consumers and the company from the subtle but long-lasting threat of Cross-Site Scripting if security controls are implemented during the web application development stage and regular vulnerability scans are conducted.
References
- https://owasp.org/www-community/attacks/xss/
- https://www.paloaltonetworks.com/cyberpedia/xss-cross-site-scripting
- https://developer.mozilla.org/en-US/docs/Glossary/Cross-site_scripting
- https://www.cloudflare.com/learning/security/threats/cross-site-scripting/