This media is not supported in your browser
VIEW IN TELEGRAM
Security researchers at Calif used a wormable zero-click RCE vulnerability to take over WeChat accounts just by calling them. The victim didn't have to pick up, and anyone who answered heard only silence while the exploit ran.
The hijacked account then called its own contacts and took them over the same way. Calif's demo worm jumped from an Android phone to an iPhone to another Android phone, gaining full control of each account: reading and sending messages and making calls as the victim.
Calif says it found the flaw in WeChat's calling feature with AI and had a working exploit in about two days.
Tencent has mitigated it for all users since Calif reported it in July.
Calif's write-up:
https://calif.io/research/weworm
The hijacked account then called its own contacts and took them over the same way. Calif's demo worm jumped from an Android phone to an iPhone to another Android phone, gaining full control of each account: reading and sending messages and making calls as the victim.
Calif says it found the flaw in WeChat's calling feature with AI and had a working exploit in about two days.
Tencent has mitigated it for all users since Calif reported it in July.
Calif's write-up:
https://calif.io/research/weworm
π10π7π₯6π±1
Dutch bank bunq took a security expert to court after he gave journalists his professional opinion on scams hitting its customers
In 2024, Dutch journalists investigated bunq customers who lost up to β¬200,000 to phishing texts and callers posing as bank staff. Fraud expert Shairesh Algoe told them the attacks weren't new, and that while fraud can't be prevented 100%, he believed banks generally detect it. Bunq read that as a comment on its own systems. Algoe says it was a general remark, since he doesn't know bunq's systems from the inside.
Soon after, bunq CEO Ali Niknam, whom Algoe has known since their student days, called him and asked whether an expert could talk to him about his quotes. Algoe agreed. The call came from Niknam's media lawyer instead.
A year later, a bailiff arrived at his home with a request to question him under oath. Bunq offered to drop it if he signed an account of his contacts with the journalists. The notary refused to record it after Algoe said he'd been pressured, so bunq sued to force his signature.
On Monday, the judge brokered a deal: bunq withdraws the case and pays his court costs. The statement both sides signed confirms the account is accurate, but says it was produced under pressure and intimidation Algoe experienced from bunq's lawyer.
It isn't the first time. Bunq has tried at least three times to make people testify under oath about their contacts with Dutch journalists. A judge refused, finding in part that the bank was fishing for the newspaper's sources. NRC pointed to the EU's anti-SLAPP directive, which targets lawsuits meant to silence journalists and their sources.
In 2024, Dutch journalists investigated bunq customers who lost up to β¬200,000 to phishing texts and callers posing as bank staff. Fraud expert Shairesh Algoe told them the attacks weren't new, and that while fraud can't be prevented 100%, he believed banks generally detect it. Bunq read that as a comment on its own systems. Algoe says it was a general remark, since he doesn't know bunq's systems from the inside.
Soon after, bunq CEO Ali Niknam, whom Algoe has known since their student days, called him and asked whether an expert could talk to him about his quotes. Algoe agreed. The call came from Niknam's media lawyer instead.
A year later, a bailiff arrived at his home with a request to question him under oath. Bunq offered to drop it if he signed an account of his contacts with the journalists. The notary refused to record it after Algoe said he'd been pressured, so bunq sued to force his signature.
On Monday, the judge brokered a deal: bunq withdraws the case and pays his court costs. The statement both sides signed confirms the account is accurate, but says it was produced under pressure and intimidation Algoe experienced from bunq's lawyer.
It isn't the first time. Bunq has tried at least three times to make people testify under oath about their contacts with Dutch journalists. A judge refused, finding in part that the bank was fishing for the newspaper's sources. NRC pointed to the EU's anti-SLAPP directive, which targets lawsuits meant to silence journalists and their sources.
π©19
βΌοΈ Meet the man charged in the UK under the National Security Act with assisting Russian intelligence, who, it turns out, also works as an escort available to hire 24/7 from Β£30 for 15 minutes.
π€£17π16π₯΄4π±2
βΌοΈ BREAKING: Chinese labs DeepSeek and Moonshot were quietly relaying customer prompts to Claude through fraudulent accounts. Users thought they were using Chinese AI, but were actually getting answers from Claude.
Their customers' sensitive data now is in Anthropic's hands. One user, who is tied to China's military, asked Kimi whether a person tracked across hundreds of CCTV cameras in Chengdu was behaving abnormally. DeepSeek passed along live credentials for a Russian government database, shared by an IT operator handling data from a Defense Ministry-linked agency.
The two Chinese labs relayed customer prompts to Claude through fraudulent accounts and saved the exchanges to train their own models. Moonshot forwarded almost 300,000 customer requests in a single ten-day stretch. DeepSeek flagged users running its models inside coding tools like Claude Code and OpenCode, then routed some of them to Opus.
Anthropic's report names seven China-based labs it says ran campaigns to copy Claude's capabilities, which Anthropic calls illicit distillation. The largest, attributed to Alibaba, topped 151 million exchanges between May and July
Source: Anthropic
https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf
Their customers' sensitive data now is in Anthropic's hands. One user, who is tied to China's military, asked Kimi whether a person tracked across hundreds of CCTV cameras in Chengdu was behaving abnormally. DeepSeek passed along live credentials for a Russian government database, shared by an IT operator handling data from a Defense Ministry-linked agency.
The two Chinese labs relayed customer prompts to Claude through fraudulent accounts and saved the exchanges to train their own models. Moonshot forwarded almost 300,000 customer requests in a single ten-day stretch. DeepSeek flagged users running its models inside coding tools like Claude Code and OpenCode, then routed some of them to Opus.
Anthropic's report names seven China-based labs it says ran campaigns to copy Claude's capabilities, which Anthropic calls illicit distillation. The largest, attributed to Alibaba, topped 151 million exchanges between May and July
Source: Anthropic
https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf
π€£34π€―8β€2π©1
βΌοΈ BREAKING: OpenAI is pausing the resource-intensive $200 Pro plan. Member of technical staff Tibo said he "shouldnβt have underestimated Astra" after many people pointed out that heβd claimed last month there was enough compute.
π€£23
βΌοΈ BREAKING: Kash Patel wanted FBI staff to run an influence campaign on X by replying to Epstein tweets with bureau stats.
He then asked his spokesman to reply to IfindRetards' post, saying it had gotten 277k responses.
His spokesman corrected him: it had 277k views and just 400 replies. He also warned that engaging "would look bad on you."
https://vault.fbi.gov/records-regarding-the-review-of-the-investigative-holdings-related-to-jeffrey-epstein/records-regarding-the-review-of-the-investigative-holdings-related-to-jeffrey-epstein-part-11/view
He then asked his spokesman to reply to IfindRetards' post, saying it had gotten 277k responses.
His spokesman corrected him: it had 277k views and just 400 replies. He also warned that engaging "would look bad on you."
https://vault.fbi.gov/records-regarding-the-review-of-the-investigative-holdings-related-to-jeffrey-epstein/records-regarding-the-review-of-the-investigative-holdings-related-to-jeffrey-epstein-part-11/view
π€£9π©5β€3π€1
βΌοΈ BREAKING: Extortion group FulcrumSec says it is behind the Dustin breach and that it received an email from Dustin's negotiator saying they "saw Novo Nordisk in the news" and "have no intention of becoming a headline."
Yet, according to FulcrumSec, Dustin refused to pay, so the group has partially released the stolen data.
FulcrumSec's leak page lists the source code behind Dustin's webshops and records for more than a million customer portal users.
Customers it names, with the number of active accounts in the data:
- Ericsson (1,445)
- NAV, Norway's welfare agency (1,041)
- Statnett, Norwegian grid operator (180)
- SEB (78)
- City of Copenhagen (43)
- Dutch National Police (9)
- Enexis (9)
- UWV, Dutch benefits agency (5)
- Dutch Ministry of Defence (4)
- ABN AMRO (3)
- Gasunie (3)
- Radboud UMC (3)
- Rabobank (2)
- City of Rotterdam (2)
- UMCG (2)
Dustin, which is still investigating, has told customers that personal data in the portal may have been accessed, but describes it as non-sensitive business information. The group says the leak goes further, with support tickets containing 92 Swedish personal identity numbers.
Yet, according to FulcrumSec, Dustin refused to pay, so the group has partially released the stolen data.
FulcrumSec's leak page lists the source code behind Dustin's webshops and records for more than a million customer portal users.
Customers it names, with the number of active accounts in the data:
- Ericsson (1,445)
- NAV, Norway's welfare agency (1,041)
- Statnett, Norwegian grid operator (180)
- SEB (78)
- City of Copenhagen (43)
- Dutch National Police (9)
- Enexis (9)
- UWV, Dutch benefits agency (5)
- Dutch Ministry of Defence (4)
- ABN AMRO (3)
- Gasunie (3)
- Radboud UMC (3)
- Rabobank (2)
- City of Rotterdam (2)
- UMCG (2)
Dustin, which is still investigating, has told customers that personal data in the portal may have been accessed, but describes it as non-sensitive business information. The group says the leak goes further, with support tickets containing 92 Swedish personal identity numbers.
π4β€2π2
βΌοΈ A terrorist cell in Yemen used Claude to develop and test weapons, including guided and hypersonic missiles and a multi-stage ballistic missile with a stated range goal above 2,000 km.
They test-fired a guided rocket, and when the launch failed, they fed the data into Claude to find out why.
They used Claude to integrate an open-source autopilot onto a phone-class flight computer and and to perform flight simulation
Claude Code took the place of human engineers, with several instances working as a team: one writing guidance code, one researching, one reviewing.
Anthropic's safeguards blocked many of their requests, but not all. The cell hid what the software was for and split the work across sessions so no single chat gave away the plan.
Anthropic banned the accounts and says it has no evidence the cell fielded an operational weapon. But the cell had already built an offline weapons simulation toolkit that runs without Claude.
Read page 112 of the Anthropic safety report: https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf
They test-fired a guided rocket, and when the launch failed, they fed the data into Claude to find out why.
They used Claude to integrate an open-source autopilot onto a phone-class flight computer and and to perform flight simulation
Claude Code took the place of human engineers, with several instances working as a team: one writing guidance code, one researching, one reviewing.
Anthropic's safeguards blocked many of their requests, but not all. The cell hid what the software was for and split the work across sessions so no single chat gave away the plan.
Anthropic banned the accounts and says it has no evidence the cell fielded an operational weapon. But the cell had already built an offline weapons simulation toolkit that runs without Claude.
Read page 112 of the Anthropic safety report: https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf
π€£12β€5π©5π¨3π€¬2π±1
βΌοΈ Russians used Claude to build autonomous military kamikaze drones that pick their own targets.
One of the target classes was "person," and the onboard model could order the detonation with no human in the loop.
They flashed firmware onto live boards and wired up real hardware.
Anthropic says the team trained the drones' vision system on scraped Ukrainian combat footage, sorting what the camera sees into "enemy" and "friendly" and allow-listing Russian equipment.
A fixed coordinate in Donetsk Oblast served as the demonstration strike point.
Nine accounts were tied to the group. Eight were used for ordinary freelance work.
One of the target classes was "person," and the onboard model could order the detonation with no human in the loop.
They flashed firmware onto live boards and wired up real hardware.
Anthropic says the team trained the drones' vision system on scraped Ukrainian combat footage, sorting what the camera sees into "enemy" and "friendly" and allow-listing Russian equipment.
A fixed coordinate in Donetsk Oblast served as the demonstration strike point.
Nine accounts were tied to the group. Eight were used for ordinary freelance work.
π€£11π±8π€¬2