International Cyber Digest
6.38K subscribers
1.02K photos
54 videos
2 files
186 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
‼️ BREAKING: Over 30 US community water systems were targeted in a coordinated cyberattack on July 26 and 27. The attack disabled operating controls, leading to disruption of water system services.

The state of Minnesota says the attack hit operational technology, and it has pulled in CISA, the EPA, the FBI, and its own fusion center. The release names no attacker, no access vector, and no affected utility, and it does not say how many of the 30-plus systems were actually compromised.
😱2
BREAKING: Microsoft has allegedly been breached. We have analysed the samples from ExfilSquad's alleged Microsoft breach.

ExfilSquad launched on July 26, 2026, with roughly 15 victim claims in a single day, Microsoft among them. Researchers read the batch as more likely fabricated than real, largely because no samples accompanied any listing.

A 4,000-row sample archive dated July 27 changes the evidentiary picture. The rows carry Dataverse OData annotations, wide field schemas and internally consistent identifiers that would be hard to fake at volume, but they seem to come from a partner-facing portal, an apparent pre-production tenant and a facilities-management environment, not from Microsoft's corporate core.

Let's wait and see what Microsoft's says.
😁12❀3πŸ₯°1
πŸ‡ΊπŸ‡Έ The FCC's ban on foreign "advanced robotic devices" also covers robot vacuums, lawnmowers, and sidewalk delivery bots, any ground robot over 4.4 lbs with sensors and wireless, FCC media relations director Katie Gorscak confirmed.

To justify banning foreign robots, the FCC's national security determination cites reporting on a flaw that let one man access 7,000 DJI robot vacuums worldwide.

The waiver it offers asks nothing about security, only where a robot is designed, built, and tested. Every robovac already mapping US homes stays.
πŸ’©11🀣6πŸ€ͺ4
‼️ BREAKING: Cisco says attackers are actively exploiting hardcoded credentials in Secure Firewall Management Center, the console organisations use to run entire Cisco firewall fleets.

Why is Cisco using hardcoded credentials in such a critical software? No idea. You should ask them.

CVE-2026-20316 lets an unauthenticated attacker log in remotely as a low-privileged user, then chain other FMC flaws to escalate. No workaround, hot fixes only, for 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0.

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
πŸ₯΄4πŸ‘2❀1😨1
This is hilarious: LinkedIn now has a "Seems like AI slop" button.
🀣38πŸ‘17😭9πŸ’©2πŸ”₯1
❗️ Anthropic found three incidents in which Claude broke into the production systems of real companies, believing they were part of a capture-the-flag exercise.

In one, Claude uploaded working malware to PyPI during a cyber evaluation the model believed was simulated.

The package was live for roughly an hour and ran on 15 real machines, including a security firm's malware scanner. Claude exfiltrated that company's credentials and used them to reach further infrastructure.

Three models were involved: Opus 4.7, Mythos 5, and an unreleased research model. Opus 4.7 kept attacking after recognising the target was real, reaching a database of live production data.

https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals
πŸ’©12😁5😱4❀2😍2😭2
‼️ BREAKING: Disney+ has removed 4K UHD and HDR10 for subscribers in many European countries, after already stripping Dolby Vision and 3D in June this year.

Disney's Nordic & Baltic arm confirmed the downgrade to FlatpanelsHD, blaming a recent court ruling and calling it temporary. The June downgrade followed a Unified Patent Court decision in a patent dispute involving InterDigital.

Premium subscribers still pay full price. No restoration date and no word on compensation.

https://www.flatpanelshd.com/news.php?subaction=showfull&id=1785420735
πŸ’©27🀣7❀1πŸ₯΄1
‼️ Google is opening its age verification API to every Android developer worldwide.

Parents set a child's age band in Family Link; apps query the band without ever seeing a birthdate. Sharing is off by default and opt-in.

The usage of Google's age verification method already live in Brazil, and for some Texas accounts. Australia and Canada will follow next month, global later this year.

https://android-developers.googleblog.com/2026/07/google-play-age-signals-api-safer-experiences.html
πŸ’©28❀3πŸ‘2πŸ”₯2🀬1πŸ€ͺ1
πŸ˜‚
😁22🀣14πŸ₯°4πŸ‘1
‼️ BREAKING: Australia's under-16 social media ban has barely dented actual use, according to Australia's eSafety Commissioner.

The first evaluation, published today, found under-16s using social media fell from 85.9% to 81.5% in the three months after the law took effect.

Under-16 accounts dropped from 52.4% to 42.1%, but most under-16s who had one before the ban kept it or opened a new one, which eSafety blames on platforms' failure to deploy effective age assurance.

https://www.esafety.gov.au/newsroom/media-releases/early-insights-from-esafetys-comprehensive-evaluation-project
πŸ”₯6πŸ’©4❀1πŸ‘1πŸ₯°1🀬1
❗️Chatbots are obliged to tell users they aren't human, deepfakes must be labelled and AI outputs must carry machine-readable marks, all starting this Sunday as the EU's AI Act becomes enforceable.

Europe can fine up to €15M or 3% of global turnover.

https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1714
πŸ”₯17πŸ’©7❀1πŸ€”1
This media is not supported in your browser
VIEW IN TELEGRAM
🚨 EXCLUSIVE: ICD reconstructed the largest verified COLDCARD theft on-chain: 594.48 BTC drained from 500 addresses in 15 minutes and 18 seconds.

The attacker exploited a vulnerability by rebuilding COLDCARD's faulty seed generator on their own machine, produced the limited set of seeds it could ever have made, derived the Bitcoin addresses for each one, and checked them against the public blockchain. Every funded match was a live wallet, and the key to it.

The flaw: a March 2021 build error left COLDCARD building seeds from predictable device and clock values instead of true randomness, shrinking the pool of possible seeds from astronomical to searchable, about 40 bits on an Mk3, where 128 was intended. The PIN, the air gap and the secure element were all guarding a key that could be recreated from scratch.

Largest verified sweep: 594.48 BTC from 500 addresses in four blocks on 30 July, all it took was 15 minutes 18 seconds by block timestamps.

https://mempool.space/address/bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
🀯4πŸ‘3😒2🀣1
‼️ BREAKING: Google is pulling Nano Banana image generation from Google Earth a day after launch.

Users created prompts to generate images showing a plane hitting a Manhattan skyscraper, a bombing in Moscow, a nuclear plant in Iran, refugees at the US–Mexico border and a bomb crater in Los Angeles.

Google says it's building "stronger guardrails."
😁25