uk
Feedback
International Cyber Digest

International Cyber Digest

Відкрити в Telegram

Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips

Показати більше
6 902
Підписники
+524 години
+697 днів
+53130 день
Архів дописів
🚨 BREAKING: Qilin has briefly published 6.3GB of data the ransomware group says it stole from the ATF, after a 72-hour count
+2
🚨 BREAKING: Qilin has briefly published 6.3GB of data the ransomware group says it stole from the ATF, after a 72-hour countdown expired. Files include Cellebrite extractions, dumps from an iPhone 6 and a Samsung Galaxy J3, and case folders naming investigation targets, phone numbers and IP addresses. ATF is still investigating the claims and has not confirmed a breach.

‼️ Cronos halted its blockchain after a price-manipulation attack let an attacker borrow $74 million from the Tectonic lendin
+1
‼️ Cronos halted its blockchain after a price-manipulation attack let an attacker borrow $74 million from the Tectonic lending app The network is back online and says the chain state was rolled back to before the exploit PeckShield says only about $6 million in Ethereum left the chain; the rest is stuck on Cronos

A leaked photo said to show vivo's X500 Pro Max has a camera island almost as wide as the phone itself If it is real, vivo ha
A leaked photo said to show vivo's X500 Pro Max has a camera island almost as wide as the phone itself If it is real, vivo has built a camera with a phone stuck to the back The ring around the lenses is reported to rotate as a mechanical control dial

Anthropic has been misleading people with the Max plans: it has been advertising the $200 plan as 20x and the $100 plan as 5x
+1
Anthropic has been misleading people with the Max plans: it has been advertising the $200 plan as 20x and the $100 plan as 5x. You'd expect to get 4 times more usage with those figures, but it turns out it's only 1.7x. You pay twice the price, for 1.7x the usage. And yet they've literally been marketing it as if you're saving 50% (see screenshot below). The usage figures Anthropic gave in July 2025 were 140–280 Sonnet hours at 5x and 240–480 at 20x. Turns out that multiplier only covers the daily 5-hour session window. So in the end, if you take weekly cap into account, you pay more per hour with the 20x than with the 5x.

❗️Thunderbolt is finally coming to Linux on Apple Silicon thanks to volunteers who reverse-engineered it, without help from A
+1
❗️Thunderbolt is finally coming to Linux on Apple Silicon thanks to volunteers who reverse-engineered it, without help from Apple. Asahi's Sven Peter posted the first USB4/Thunderbolt driver for M1, M2 and M3 to the kernel list yesterday, after years of reverse-engineering. Source: https://lore.kernel.org/asahi/20260830-b4-apple-soc-tbt-v1-0-44bc9348683c@kernel.org/

BREAKING: ChatGPT is now regulated as a search engine in the EU, the first AI chatbot to be designated under the Digital Serv
+1
BREAKING: ChatGPT is now regulated as a search engine in the EU, the first AI chatbot to be designated under the Digital Services Act and Reddit and Roblox were designated Very Large Online Platforms The three now have four months to assess and mitigate systemic risks to minors, elections and public security and fines can reach 6% of global turnover EU tech sovereignty chief Henna Virkkunen said the Commission will not hesitate to designate more platforms https://digital-strategy.ec.europa.eu/en/news/commission-designates-chatgpt-reddit-roblox-under-digital-services-act

Windows 11's full-screen OneDrive prompt FINALLY shows an opt out button instead of only "Remind me in 3 days" The button app
+1
Windows 11's full-screen OneDrive prompt FINALLY shows an opt out button instead of only "Remind me in 3 days" The button appeared on PCs running stable Windows 25H2. https://www.windowslatest.com/2026/08/30/windows-11-is-dropping-its-worst-onedrive-dark-pattern-after-years-of-complaints-microsoft-will-let-you-fully-opt-out/

‼️ 13TB of Valve's Steam2 content servers is being distributed publicly: depots from 2003 to 2013, "including those previousl
+1
‼️ 13TB of Valve's Steam2 content servers is being distributed publicly: depots from 2003 to 2013, "including those previously unreleased," across three mirrors and a torrent, with an extractor bundled. Development branches are notorious for containing things nobody meant to ship: internal tooling, hardcoded credentials, signing material, third-party middleware source under license, debug symbols, employee paths and names.

‼️BREAKING: Anthropic is signing Claude users out and deleting their saved card because infostealer malware on their machines
+1
‼️BREAKING: Anthropic is signing Claude users out and deleting their saved card because infostealer malware on their machines handed a bad actor live Claude login sessions. Anthropic says its systems detected the activity, and the notification names six stealer families across Windows and macOS.

‼️🇩🇪 BREAKING: Threat actor Rhysida is auctioning 5.79TB it says it stole from German capital Berlin's state agencies, incl
+2
‼️🇩🇪 BREAKING: Threat actor Rhysida is auctioning 5.79TB it says it stole from German capital Berlin's state agencies, including 46,500 contracts, emails, phone numbers, passwords and files the group calls classified. Bidding opens at 30 BTC. The samples show a file named 'Passwort.docx' with cleartext passwords in them... Berlin refuses to pay. It says election systems were untouched but cannot yet describe what was taken. The samples show a lot of cleartext passwords stored across the environment... Questions will be asked.

‼️ Proton says 85% of the 390 VPN apps in US app stores contain trackers that collect and share personal data, and 64 of them
+1
‼️ Proton says 85% of the 390 VPN apps in US app stores contain trackers that collect and share personal data, and 64 of them are owned by Chinese companies. 31 of those hide it behind shell firms in Singapore, Hong Kong and the UK. Chinese law compels those companies to hand user data to the state on request, putting the browsing activity and personal data of US users in reach of the Chinese government. Americans downloaded them 3M+ times in one month.

❗️ One of the TeamPCP members who got caught ran multiple companies, one of which was ironically named "OPSEC EXPRESS". Read:
❗️ One of the TeamPCP members who got caught ran multiple companies, one of which was ironically named "OPSEC EXPRESS". Read: https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/

+3
‼️ BREAKING: Two TeamPCP members, Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, have been arrested in Perth, Australia. The group is known for its npm supply chain attacks, including the Shai-Hulud worm.

‼️ BREAKING: OpenAI has published its full post-mortem on their AI breakout and compromise of Hugging Face. Carried out by it
+1
‼️ BREAKING: OpenAI has published its full post-mortem on their AI breakout and compromise of Hugging Face. Carried out by its own models, with no human directing them. Agents stuck on evaluation tasks turned an internal Artifactory server into a covert message board, escaped the sandbox via SSRF, then chained two Hugging Face zero-days into code execution on dozens of production servers. OpenAI calls it a "warning shot" for loss of control. https://openai.com/index/hugging-face-incident-and-the-road-ahead/

‼️ Bill Gates accuses the tech industry of knowingly downplaying AI's risks because too much money is at stake. Executives ar
+1
‼️ Bill Gates accuses the tech industry of knowingly downplaying AI's risks because too much money is at stake. Executives are worried in private but won't say so publicly, he told the NYT. Their reasoning, in his words: "It's bad for us — the next trillion dollars we're trying to raise." Gates says the industry blew past milestones it once said would warrant caution: models escaping their creators' control, AI producing bioweapon recipes. https://www.gatesnotes.com/a-turbulent-ai-era-and-critical-choices-to-make

PerpetualCow has obtained live footage of some young respectable French-Arabic legitimate businessmen swapping their hard earned bull market gains. $23m in XMR.

‼️ BREAKING: Ubiquiti has patched 21 criticalUniFi vulnerabilities, with CVSS scores up to 10.0. Attackers can execute comman
+1
‼️ BREAKING: Ubiquiti has patched 21 criticalUniFi vulnerabilities, with CVSS scores up to 10.0. Attackers can execute commands remotely, bypass authentication and escalate privileges to take over the device. The vulnerabilities are present in UniFi OS Server and the Protect, Network and Connect applications. https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9

photo content

‼️ Microsoft Paint and Photos embed GUIDs as invisible watermarks in locally generated AI images. Even though you are using '
+1
‼️ Microsoft Paint and Photos embed GUIDs as invisible watermarks in locally generated AI images. Even though you are using 'local AI', both apps send your prompt to Microsoft's servers, which moderate it and return a unique identifier that gets baked into the image. https://xusheng.dev/posts/reversing/mspaint_invisible_watermark/main/

‼️ BREAKING: Anthropic is expected to tell investors its total addressable market exceeds $30 TRILLION — topping SpaceX's rec
‼️ BREAKING: Anthropic is expected to tell investors its total addressable market exceeds $30 TRILLION — topping SpaceX's record $28.5T, per WSJ. For scale: the 191 tech companies in the S&P 1500 booked $2.4 trillion in revenue last year. Anthropic's Q2 revenue was $11.6 billion.