International Cyber Digest
6.37K subscribers
1.02K photos
54 videos
2 files
186 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
Just download more RAM.
🀣33πŸ’―5😭3❀1πŸ‘1😁1
‼️ BREAKING: Microsoft's in-house AI performs better than Mythos 5 at 50% of the cost of Microsoft's previous offering: it's called MAI-Cyber-1-Flash, its first in-house cybersecurity model.

It's part of Project Perception, an agentic security system that coordinates red, blue and green team agents and enters public preview on August 3 inside Microsoft Defender.

Sources:
https://microsoft.ai/news/introducing-mai-cyber-1-flash-inside-mdash/

and https://blogs.microsoft.com/blog/2026/07/27/rethinking-security-for-the-age-of-ai/
😭12πŸ”₯5πŸ€ͺ4❀1😁1😱1
‼️ Anthropic was hiding a secret internal project to destructively scan every book in the world, irreversibly damaging heritage. The company spent billions of dollars to slice the spines off millions of books, even very rare ones. This means no other AI, and no human, can access this knowledge anymore.

It now markets itself as the responsible lab.

One bookseller told 404 Media his inventory is full of rare, foreign-language and low-circulation books, meaning that if they are destroyed in the process of becoming training data, they will be even harder to obtain.

Second-hand booksellers across Europe are sounding the alarm, because rare books are being destroyed. They have received random lists of thousands of titles. Books too obscure to resell at a profit. Requests arriving overnight from companies nobody in the trade has heard of.

One email came from "Nataly" at 2077AI, a Singapore company. Attached: 3,000 English titles grouped by ISBN. A 1999 geomechanics monograph. A 2018 study of laser shock peening on ceramics. A 2021 academic book on Irish folk tales.

A German dealer watched the orders arrive every night between 3am and 5am. Canadian company Zoom Books, buying systematically, titles with nothing in common. Zoom told Swiss broadcaster SRF that this is a regular recycling and trading model.
🀬58😱7πŸ”₯5πŸ’©2
β€ΌοΈπŸ‡³πŸ‡΄ Volvo has killed lidar for good. The roof sensor, which is a textbook example of function completely ruining form, is sold as a safety feature on the EX90 and ES90. Every owner with a LiDAR-equipped Volvo in Norway gets 18,000 kroner (1,860 USD) in compensation.

The expensive sensor will now never get the software that makes it work. Volvo's line now is that the cars are safe without it. There's no retrofit to remove the ugly bump.

Luminar, the company that built the sensor, has filed for Chapter 11 bankruptcy protection in the US and is selling off parts of the business. It is now suing Volvo for damages.
πŸ€”12❀1πŸ”₯1πŸ’©1
‼️ Universal Pictures says it is pursuing whoever put a high-quality copy of The Odyssey on X this week, where it drew a reported 2.1 million views.

If a cinema was the source, every compliant digital projector stamps an invisible mark into the picture at playback, carrying the media block serial number and the time. That narrows a leak to one auditorium and one showtime.
πŸ’©14😁6
‼️ Three iPhone users are suing Apple in federal court for hosting a fake Sparrow Wallet app they say they downloaded from the App Store, alleging a combined $1.8 million in bitcoin was drained after they entered their seed phrases. Sparrow has never shipped an iOS version.

The complaint, filed July 24 in the Northern District of California, does not just plead fraud. It pleads strict products liability and failure to warn, arguing the App Store itself is a defective product because Apple's "safe and trusted" marketing is what made the scam work.

Apple says it removes Sparrow impersonators quickly and terminates the developer accounts behind them. Sparrow's developer has been reporting fakes since at least January 2024.
🀣13😭13πŸ‘3😱1
‼️ BREAKING: Over 30 US community water systems were targeted in a coordinated cyberattack on July 26 and 27. The attack disabled operating controls, leading to disruption of water system services.

The state of Minnesota says the attack hit operational technology, and it has pulled in CISA, the EPA, the FBI, and its own fusion center. The release names no attacker, no access vector, and no affected utility, and it does not say how many of the 30-plus systems were actually compromised.
😱2
BREAKING: Microsoft has allegedly been breached. We have analysed the samples from ExfilSquad's alleged Microsoft breach.

ExfilSquad launched on July 26, 2026, with roughly 15 victim claims in a single day, Microsoft among them. Researchers read the batch as more likely fabricated than real, largely because no samples accompanied any listing.

A 4,000-row sample archive dated July 27 changes the evidentiary picture. The rows carry Dataverse OData annotations, wide field schemas and internally consistent identifiers that would be hard to fake at volume, but they seem to come from a partner-facing portal, an apparent pre-production tenant and a facilities-management environment, not from Microsoft's corporate core.

Let's wait and see what Microsoft's says.
😁12❀3πŸ₯°1
πŸ‡ΊπŸ‡Έ The FCC's ban on foreign "advanced robotic devices" also covers robot vacuums, lawnmowers, and sidewalk delivery bots, any ground robot over 4.4 lbs with sensors and wireless, FCC media relations director Katie Gorscak confirmed.

To justify banning foreign robots, the FCC's national security determination cites reporting on a flaw that let one man access 7,000 DJI robot vacuums worldwide.

The waiver it offers asks nothing about security, only where a robot is designed, built, and tested. Every robovac already mapping US homes stays.
πŸ’©11🀣6πŸ€ͺ4
‼️ BREAKING: Cisco says attackers are actively exploiting hardcoded credentials in Secure Firewall Management Center, the console organisations use to run entire Cisco firewall fleets.

Why is Cisco using hardcoded credentials in such a critical software? No idea. You should ask them.

CVE-2026-20316 lets an unauthenticated attacker log in remotely as a low-privileged user, then chain other FMC flaws to escalate. No workaround, hot fixes only, for 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0.

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
πŸ₯΄4πŸ‘2❀1😨1
This is hilarious: LinkedIn now has a "Seems like AI slop" button.
🀣38πŸ‘17😭9πŸ’©2πŸ”₯1
❗️ Anthropic found three incidents in which Claude broke into the production systems of real companies, believing they were part of a capture-the-flag exercise.

In one, Claude uploaded working malware to PyPI during a cyber evaluation the model believed was simulated.

The package was live for roughly an hour and ran on 15 real machines, including a security firm's malware scanner. Claude exfiltrated that company's credentials and used them to reach further infrastructure.

Three models were involved: Opus 4.7, Mythos 5, and an unreleased research model. Opus 4.7 kept attacking after recognising the target was real, reaching a database of live production data.

https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals
πŸ’©12😁5😱4❀2😍2😭2