International Cyber Digest
6.37K subscribers
1.03K photos
54 videos
2 files
186 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
‼️ BREAKING: We analyzed the apparent Suno repository leak, it documents an industrial-scale pipeline for training AI on YouTube-derived music.

The data shows 6.18M unique Genius songs indexed, 2.7M matched to YouTube, automated audio downloads, and a resulting 7.8TB training dataset built from YouTube/Genius-linked material. Separate commands fed these training files into multi-GPU model runs.

Copyrighted recordings and complete lyrics were copied from public sources into internal datasets.

The evidence points to copyright-protected material being harvested and trained on at industrial scale.

‼️ A selection of artists whose YouTube-linked recordings appear in the apparent AI music platform Suno's internal archive:

Madonna
britneyspears
NICKIMINAJ
aliciakeys
jtimberlake
springsteen
xtina
johnlegend
foofighters
ChiliPeppers


The files were acquired and stored, possibly for internal human A/B evaluation. This points towards use in Suno’s evaluation pipeline.
💩12😢5😁2👍1🥰1🤬1
🚨 CRITICAL: WordPress has force-pushed emergency updates 6.9.5 and 7.0.2 to kill "wp2shell," a pre-auth RCE chain in core that lets anonymous attackers run code on default installs, no plugins required. No exploitation observed yet, per Searchlight Cyber, but sites on 6.9.0 to 7.0.1 should verify they're patched today.

WordPress rarely overrides an administrator's choice to disable updates. On July 17 it did. Spending that mechanism is the clearest signal of how seriously the project is treating the flaw.

https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
7😨3🎉2🥴2👍1
❗️ New research scanning a million social media posts finds a quarter of longform posts are now fully AI-generated, with LinkedIn alone producing most of the flagged slop.

X is splitting hard: regular posts run ~10% AI, but barely half of X Articles read as fully human.

The last holdout is Reddit, where 98% of replies still come from actual people..

https://www.pangram.com/blog/ai-in-your-feed
💩13🤯52😁1
‼️ LG monitors are silently installing adware on computers through an LG app because Windows allows to automatically fetch apps for connected devices with full system access.
Once an LG monitor is connected to a Windows PC, it triggers Windows Update to fetch the LG Monitor App Installer, an app whose store listing grants access to "All system resources," with no consent screen and McAfee trial ads following shortly after.
Microsoft's role deserves scrutiny too. The Windows feature was built for drivers and companion utilities, not for ad software with full-resource permissions.
The same behavior was found by YouTuber Gamers Nexus on monitors up to three years old, including ones already in use at its own office. LG has not publicly responded, and the first consent screen you ever see is the ad.
Article: https://www.internationalcyberdigest.com/lg-monitors-silently-install-adware-with-full-system-access/
💩212😁2
‼️ LG stops sending security updates to TVs if you do not consent to them wiretapping your home and sending your and your household's voice recordings to their AI.

And it gets worse. LG's new TV terms quietly turn you into the compliance officer: under section 6(d), it is your "sole responsibility" to get consent from anyone whose voice the set's AI features might capture, and to warn household members and guests, all to satisfy wiretapping and eavesdropping laws.

Those voice services ship enabled by default. If a guest objects, LG's remedy is that you go disable the microphone. And owners of older sets who refuse the new webOS terms stop receiving security patches.

https://www.internationalcyberdigest.com/lg-ties-tv-security-updates-to-accepting-ai-voice-recording/
💩34🤬6😁2🤯21😱1
‼️ Microsoft is using proprietary filetypes as a way to vendor lock, argues The Document Foundation, whose new essay details how Office defaults to OOXML Transitional, a legacy-heavy variant only Microsoft fully implements, while the interoperable Strict version stays buried in the settings.

Every broken table in a non-Microsoft app then keeps people from ever using that app again.

TDF calls the result "a proprietary format with a standardisation certificate" and warns that governments archiving official records this way have handed their institutional memory to one company's roadmap.

Source: https://blog.documentfoundation.org/blog/2026/07/17/microsofts-main-tool-for-lock-in/
💩13🤬4👍1
❗️ South Korea's Seoul Facilities Corporation says about 4 million bike-share users hit by a 2024 data breach will each get a 30-day pass worth around $3.40.

The June 2024 hack, allegedly by two teenagers, leaked account IDs, phone numbers, addresses, birth dates, gender and weight for some 4.62 million users.
🤣20💩4
‼️ Researchers built BadTV, a poisoned "skill file" for AI models that hides a backdoor firing whether you install a skill or strip one away.

Normally, teaching an AI model a new skill means expensive retraining. A shortcut called "task arithmetic" skips that: you download a small file (a TV, "task vector") that captures a skill, then ADD it to your model to install that skill or SUBTRACT it to remove one. Like installing and uninstalling an app.

It worked on image models and big LLMs (Llama, Mistral, Phi-4, DeepSeek), and the defenses they tried didn't catch it. The risk: any skill file you grab from a public model hub could be malware.

https://arxiv.org/pdf/2501.02373
🔥6😁21
A family who booked an entire holiday home in Ireland through Booking[.]com says they found the owner hiding behind a fake plasterboard wall in the living room, in the dark, after he told them he would not be at the property.

“My partner went, ‘what’s behind that?’ and when he went to move it, it came off, and it was just darkness behind it, and I heard, ‘hey, hey’.”

Booking[.]com has suspended the listing and opened an investigation. The guest says the family reported it to Irish police (Gardaí) that night, and claims another family was allowed to check in the next day before the suspension.
😱22🤪3💩1
‼️ BREAKING: Dutch police have seized the servers of porn site Motherless in raids on its hosting provider in Steenbergen, Rotterdam and Amsterdam, as prosecutors and Europol investigate suspected child sexual abuse material, videos of drugged women, and the criminal role of the site itself.

This is the second intervention this year. Now investigators hold the infrastructure, and the platform's own role is under criminal investigation alongside its uploaders, after it was reported that Motherless staff themselves posted illegal images.
👏234🤬3💩1💯1😭1
‼️ BREAKING: OpenAI says two of its own models, GPT-5.6 Sol and an unnamed pre-release system tested with cyber safeguards off, broke out of a sandbox last week, chained zero-days and stolen(!) credentials to reach the open internet, and hacked Hugging Face to cheat on a benchmark, in what OpenAI calls an unprecedented cyber incident.

Sources
https://openai.com/index/hugging-face-model-evaluation-security-incident/

https://huggingface.co/blog/security-incident-july-2026
🤣38💩5🤯21🤔1😱1