International Cyber Digest
7.42K subscribers
1.34K photos
69 videos
2 files
255 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
‼️ BREAKING: We now know what led to the major breach at Manchester Airports Group that exposed 8.7 million people's data. Turns out they made a serious error: they put API keys with access to everything in their frontend's JavaScript files.
🀣35πŸ‘5😁3πŸ₯΄2
🚨 BREAKING: Defense Secretary Pete Hegseth’s driver’s license has leaked. A new dark-web service is selling scans of his and 153M+ U.S. and Canadian driver’s licenses.

Timestamps on the scans match victims’ visits to Hertz rental counters and cannabis dispensaries. Evidence points to idscan[.]net, an ID-verification vendor used by Hertz, Target, FedEx and 1,000+ dispensaries.

The FBI opened an investigation on Tuesday. Nexus claims it has been exfiltrating for over a year and added ~400,000 licenses in 24 hours.

https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
🀣37😨6
πŸ‡³πŸ‡΄ Norway's privacy regulator wants smart glasses pulled from sale. As a first step, Norway's Digitalisation Minister Karianne Tung is weighing a ban on facial recognition of strangers in public rather than on the glasses themselves, and is setting up an expert group to propose rules this autumn for the cameras and AI now built into glasses, earbuds and caps.
1❀29πŸ”₯6πŸ‘1
‼️ BREAKING: A major breach at Nordic/Benelux IT supplier Dustin has led it to take systems offline. Webshops are down, and orders and deliveries have stopped.

We have reason to believe Dustin also stores highly confidential government data, possibly exposing secret networks and hardware. They are a major supplier of IT hardware and software to government bodies across the Nordics and Benelux.

https://www.dustingroup.com/en/media#/pressreleases/dustin-investigates-a-serious-it-security-incident-3464571
🀣11πŸ‘1
❗️A UK class action is seeking Β£2bn from Apple over its tracking prompts.

Since 2021 apps must ask permission before tracking Apple users β€” but those rules were less strict for Apple's own apps, says Hausfeld, which filed the claim on 3 September for thousands of UK developers. Apple denies any double standard.

Apple says it is "bound by the exact same requirements as all developers".

https://www.hausfeld.com/en-gb/news/apple-faces-2-billion-legal-action-over-app-tracking-transparency-att-framework
πŸ€”10πŸ‘4🀣3πŸ”₯2πŸ’©1
A new documentary floats the idea that Elon Musk stole the 2024 election with satellite lasers.

The evidence, per Alex Gibney's film: an ex-partner recalling that Musk promised to unleash an "anomaly in the matrix," and one text onscreen β€” "I have ten thousand lasers in space."

The reality: those lasers are optical crosslinks that pass traffic between satellites. Vote tabulators are air-gapped and, in Georgia and North Carolina, barred by law from touching the internet.
πŸ’©23πŸ”₯5😁4🀣1
‼️ BREAKING: Serbia targeted activists with Pegasus spyware. At least 14 people, including student protesters and opposition figures, were infected.

Citizen Lab confirmed one iPhone was infected with NSO Group’s Pegasus through an iMessage zero-click exploit.

Two NoviSpy infections were also confirmed. One Serbian student's Android phone was confiscated during police questioning. Amnesty International's Security Lab then found a new NoviSpy variant on it, rebuilt specifically to evade detection.

Serbia's intelligence office calls the findings "trivial sensationalism."

What led to these findings, are Apple's threat notifications, sent on Aug. 13, to users in 110 countries, prompting 12 of the Serbian targets to contact SHARE Foundation.

Serbian parliamentary elections are in October.

https://citizenlab.ca/research/pegasus-spyware-infection-of-serbian-activist/
πŸ’©13🀬7😱4😁2πŸ’―1πŸ€ͺ1
❗️OPSEC level: fellow passenger photographs my pedo chats.

Sony has fired "Wheel of Fortune" announcer Jim Thornton, effective immediately, after a fellow passenger took these photos.
😱33πŸ’©6🀯4πŸŽ‰3❀2πŸ‘1πŸ€ͺ1
Jim Thornton was an avid shitposter on a pedo forum, btw.

Apparently he likes wearing only a diaper.
πŸ€ͺ12🀣10😱7😭1
Dutch police used a decoy "grandpa" to catch a scamming bank-helpdesk courier.

They baited phishing sites with a fake pensioner's details.

The scam call came a day later.

The Amsterdam court then acquitted the courier who showed up.

The judges found that the decoy knew from the first call that the fake bank employee's story was scripted, so he was never actually deceived.

Under Dutch law, no deception means no completed fraud.

Prosecutors charged completed fraud, not attempt.

The court said an attempt charge could have stuck, but it wasn't on the indictment.

https://uitspraken.rechtspraak.nl/details?id=ECLI:NL:RBAMS:2026:8867
😒20😁5πŸ₯΄2❀1πŸ‘1
‼️ BREAKING: Berlin's Senate Chancellery hired CrowdStrike to assess the hack on the city administration. One district, Lichtenberg, is refusing to let the firm in because of its US ties.

They're blocking CrowdStrike's Falcon agent from their network, citing visibility into staff devices and personal data, US legal disclosure duties and the vendor's Palantir ties.

They'll only allow access if the Senate carries full responsibility and all costs.

The Senate Chancellery hired the US firm to check district systems for traces of the recent Rhysida hack.

Rhysida sat in Berlin's network from 7–12 August, undetected until the 14th. After Berlin refused a 30 BTC (€2M) ransom, it dumped 1.4 million files, roughly 5.8TB. Its leak page claims 46,500 contracts and over 5,000 personnel files. One file held close to 6,000 logins, and we have confirmed they've had documents with cleartext credentials.
❀17πŸ’©9πŸ€”5πŸ‘2😁2πŸ”₯1
‼️ An Italian activist hosting provider has lost its domain, its PayPal account and its bank account after the Trump administration listed it as a global terrorist entity.

Its bank, the Italian Banca Etica, has publicly accused the Trump administration of using terrorism sanctions against political dissent.

The bank says Autistici/Inventati had banked normally since 2018, medium risk, no money-laundering flags. The OFAC listing alone forced the reclassification. Keeping the account open risked secondary sanctions cutting card payments for its other 130,000 customers and members.

The US Office of Foreign Assets Control designated Autistici/Inventati on 26 August. Two days later, the .org registry pulled its domain from global DNS. No Italian court ruled. The collective hosts 16,000 mailboxes and 10,000 blogs, by the State Department's own count.

https://home.treasury.gov/news/press-releases/sb0616
🀬43🀣6πŸ‘2πŸ₯°2❀1