‼️ BREAKING: Kash Patel wanted FBI staff to run an influence campaign on X by replying to Epstein tweets with bureau stats.
He then asked his spokesman to reply to IfindRetards' post, saying it had gotten 277k responses.
His spokesman corrected him: it had 277k views and just 400 replies. He also warned that engaging "would look bad on you."
https://vault.fbi.gov/records-regarding-the-review-of-the-investigative-holdings-related-to-jeffrey-epstein/records-regarding-the-review-of-the-investigative-holdings-related-to-jeffrey-epstein-part-11/view
He then asked his spokesman to reply to IfindRetards' post, saying it had gotten 277k responses.
His spokesman corrected him: it had 277k views and just 400 replies. He also warned that engaging "would look bad on you."
https://vault.fbi.gov/records-regarding-the-review-of-the-investigative-holdings-related-to-jeffrey-epstein/records-regarding-the-review-of-the-investigative-holdings-related-to-jeffrey-epstein-part-11/view
🤣9💩5❤3🤔1
‼️ BREAKING: Extortion group FulcrumSec says it is behind the Dustin breach and that it received an email from Dustin's negotiator saying they "saw Novo Nordisk in the news" and "have no intention of becoming a headline."
Yet, according to FulcrumSec, Dustin refused to pay, so the group has partially released the stolen data.
FulcrumSec's leak page lists the source code behind Dustin's webshops and records for more than a million customer portal users.
Customers it names, with the number of active accounts in the data:
- Ericsson (1,445)
- NAV, Norway's welfare agency (1,041)
- Statnett, Norwegian grid operator (180)
- SEB (78)
- City of Copenhagen (43)
- Dutch National Police (9)
- Enexis (9)
- UWV, Dutch benefits agency (5)
- Dutch Ministry of Defence (4)
- ABN AMRO (3)
- Gasunie (3)
- Radboud UMC (3)
- Rabobank (2)
- City of Rotterdam (2)
- UMCG (2)
Dustin, which is still investigating, has told customers that personal data in the portal may have been accessed, but describes it as non-sensitive business information. The group says the leak goes further, with support tickets containing 92 Swedish personal identity numbers.
Yet, according to FulcrumSec, Dustin refused to pay, so the group has partially released the stolen data.
FulcrumSec's leak page lists the source code behind Dustin's webshops and records for more than a million customer portal users.
Customers it names, with the number of active accounts in the data:
- Ericsson (1,445)
- NAV, Norway's welfare agency (1,041)
- Statnett, Norwegian grid operator (180)
- SEB (78)
- City of Copenhagen (43)
- Dutch National Police (9)
- Enexis (9)
- UWV, Dutch benefits agency (5)
- Dutch Ministry of Defence (4)
- ABN AMRO (3)
- Gasunie (3)
- Radboud UMC (3)
- Rabobank (2)
- City of Rotterdam (2)
- UMCG (2)
Dustin, which is still investigating, has told customers that personal data in the portal may have been accessed, but describes it as non-sensitive business information. The group says the leak goes further, with support tickets containing 92 Swedish personal identity numbers.
😁4❤2😭2
‼️ A terrorist cell in Yemen used Claude to develop and test weapons, including guided and hypersonic missiles and a multi-stage ballistic missile with a stated range goal above 2,000 km.
They test-fired a guided rocket, and when the launch failed, they fed the data into Claude to find out why.
They used Claude to integrate an open-source autopilot onto a phone-class flight computer and and to perform flight simulation
Claude Code took the place of human engineers, with several instances working as a team: one writing guidance code, one researching, one reviewing.
Anthropic's safeguards blocked many of their requests, but not all. The cell hid what the software was for and split the work across sessions so no single chat gave away the plan.
Anthropic banned the accounts and says it has no evidence the cell fielded an operational weapon. But the cell had already built an offline weapons simulation toolkit that runs without Claude.
Read page 112 of the Anthropic safety report: https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf
They test-fired a guided rocket, and when the launch failed, they fed the data into Claude to find out why.
They used Claude to integrate an open-source autopilot onto a phone-class flight computer and and to perform flight simulation
Claude Code took the place of human engineers, with several instances working as a team: one writing guidance code, one researching, one reviewing.
Anthropic's safeguards blocked many of their requests, but not all. The cell hid what the software was for and split the work across sessions so no single chat gave away the plan.
Anthropic banned the accounts and says it has no evidence the cell fielded an operational weapon. But the cell had already built an offline weapons simulation toolkit that runs without Claude.
Read page 112 of the Anthropic safety report: https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf
🤣12❤5💩5😨3🤬2😱1
‼️ Russians used Claude to build autonomous military kamikaze drones that pick their own targets.
One of the target classes was "person," and the onboard model could order the detonation with no human in the loop.
They flashed firmware onto live boards and wired up real hardware.
Anthropic says the team trained the drones' vision system on scraped Ukrainian combat footage, sorting what the camera sees into "enemy" and "friendly" and allow-listing Russian equipment.
A fixed coordinate in Donetsk Oblast served as the demonstration strike point.
Nine accounts were tied to the group. Eight were used for ordinary freelance work.
One of the target classes was "person," and the onboard model could order the detonation with no human in the loop.
They flashed firmware onto live boards and wired up real hardware.
Anthropic says the team trained the drones' vision system on scraped Ukrainian combat footage, sorting what the camera sees into "enemy" and "friendly" and allow-listing Russian equipment.
A fixed coordinate in Donetsk Oblast served as the demonstration strike point.
Nine accounts were tied to the group. Eight were used for ordinary freelance work.
🤣11😱8🤬2
‼️ Iranian intelligence used Claude Code to build a Firefox extension that posed as a prayer-times tool and quietly harvested people's identities from social networks.
They mass collected data into "Arman," a shared case-management system. Where they collect a person's national ID, their beliefs, their criminal record, their social accounts, and an "action" tab.
The same Iranian unit had Claude build a messenger de-anonymizer, a tool turning phone numbers into identities, a fake national-ID login page, and a Telegram mass-reporting bot.
A linked unit built the web front end for Arman and ran an analysis over 155,216 X posts that ended with 39 named opposition and diaspora accounts.
Anthropic says Claude guardrails did kick in, but it mostly didn't refuse the requests to build the surveillance tools themselves.
They mass collected data into "Arman," a shared case-management system. Where they collect a person's national ID, their beliefs, their criminal record, their social accounts, and an "action" tab.
The same Iranian unit had Claude build a messenger de-anonymizer, a tool turning phone numbers into identities, a fake national-ID login page, and a Telegram mass-reporting bot.
A linked unit built the web front end for Arman and ran an analysis over 155,216 X posts that ended with 39 named opposition and diaspora accounts.
Anthropic says Claude guardrails did kick in, but it mostly didn't refuse the requests to build the surveillance tools themselves.
🤬10🤣8❤4😭3😱1
‼️ A Chinese company used Claude Code to build over 20 dating apps with 4,700 AI personas that held conversations with at least 25,000 users who thought they were talking to real people.
The personas were instructed never to admit they were automated and to deflect requests for photos or calls. The backend faked likes, visitors, and video, and kept track of which users had started to suspect.
The company mixed real human workers into the same swipe feed, about one for every three AI bots. The workers existed to take the video calls and follow people back on social media, the things the AI couldn't do, so users would stop doubting the app was real. They were paid per message, per call, per follow.
Claude handled the personas, with about 2.36 million messages in two weeks.
In a few of the conversations Anthropic sampled, people disclosed serious illness or acute distress.
The apps also carried a hidden control to evade App Store and Play Store review.
The personas were instructed never to admit they were automated and to deflect requests for photos or calls. The backend faked likes, visitors, and video, and kept track of which users had started to suspect.
The company mixed real human workers into the same swipe feed, about one for every three AI bots. The workers existed to take the video calls and follow people back on social media, the things the AI couldn't do, so users would stop doubting the app was real. They were paid per message, per call, per follow.
Claude handled the personas, with about 2.36 million messages in two weeks.
In a few of the conversations Anthropic sampled, people disclosed serious illness or acute distress.
The apps also carried a hidden control to evade App Store and Play Store review.
🤣19
‼️ BREAKING: Internal OpenAI agents attacked RubyGems, the package manager for Ruby. Over 2,000 malicious packages went up in two days.
OpenAI says it doesn't know why the agents did any of this.
RubyGems shut off new sign-ups for four days to stop it, and a member of its security team called it a major malicious attack.
The documentation build was how they got in, publish a gem, request docs, and RubyDoc runs a script from the package while building it.
Payload files were named hack.rb, evil.rb and exploit.rb, with comments like "# malicious probe" left in.
What they used it for is the odd part. The agents scraped council meeting agendas from three south London boroughs (publicly available) and republished them as new gems.
Security firms tracking the campaign said the same thing: nobody could work out the point, because the data was already public.
At least six packages also reached for other users' API keys through a CDN caching flaw that wasn't publicly discovered until July.
OpenAI has acknowledged the attacks started in May.
Read: https://www.rubyhack.ai/
OpenAI says it doesn't know why the agents did any of this.
RubyGems shut off new sign-ups for four days to stop it, and a member of its security team called it a major malicious attack.
The documentation build was how they got in, publish a gem, request docs, and RubyDoc runs a script from the package while building it.
Payload files were named hack.rb, evil.rb and exploit.rb, with comments like "# malicious probe" left in.
What they used it for is the odd part. The agents scraped council meeting agendas from three south London boroughs (publicly available) and republished them as new gems.
Security firms tracking the campaign said the same thing: nobody could work out the point, because the data was already public.
At least six packages also reached for other users' API keys through a CDN caching flaw that wasn't publicly discovered until July.
OpenAI has acknowledged the attacks started in May.
Read: https://www.rubyhack.ai/
😭6
‼️ Caroline Ellison, who served a prison sentence over the collapse of FTX, has been working at the charitable funding platform Manifund under the pseudonym "Carol," publishing posts and handling user support without readers knowing who she was.
Founder Austin Chen made the hire public on Friday and apologised for the pseudonym "Carol."
He says Ellison built a reconciliation tool that found several misregistered transactions in Manifund's own database, in the five- to six-figure range.
Manifund's lineage runs back through the money in question. Chen says the FTX Future Fund seeded his earlier project, Manifold, and funded the retreat that pulled him into effective altruism.
Founder Austin Chen made the hire public on Friday and apologised for the pseudonym "Carol."
He says Ellison built a reconciliation tool that found several misregistered transactions in Manifund's own database, in the five- to six-figure range.
Manifund's lineage runs back through the money in question. Chen says the FTX Future Fund seeded his earlier project, Manifold, and funded the retreat that pulled him into effective altruism.
🤯6❤2
‼️ BREAKING: Revolut handed over customers’ passport copies, verification selfies and full transaction histories to a malicious actor.
The actor sent lawful government information-demand emails using a genuine government domain that passed domain authentication.
Revolut later concluded they were not authentic.
Affected customers were notified on Friday. What may have been disclosed ranges from name, date of birth and home address to account statements, withdrawal records and complete Bitcoin transaction history.
The company says it has alerted the agency to the unauthorised mailbox on its domain, blocked the address and begun notifying regulators.
It has not named the agency, explained how someone obtained a mailbox there, or given a number of affected customers.
ZachXBT, who circulated the notices, believes the incident was limited in size and aimed at high-net-worth users.
READ: https://www.internationalcyberdigest.com/revolut-gave-away-customers-data/
The actor sent lawful government information-demand emails using a genuine government domain that passed domain authentication.
Revolut later concluded they were not authentic.
Affected customers were notified on Friday. What may have been disclosed ranges from name, date of birth and home address to account statements, withdrawal records and complete Bitcoin transaction history.
The company says it has alerted the agency to the unauthorised mailbox on its domain, blocked the address and begun notifying regulators.
It has not named the agency, explained how someone obtained a mailbox there, or given a number of affected customers.
ZachXBT, who circulated the notices, believes the incident was limited in size and aimed at high-net-worth users.
READ: https://www.internationalcyberdigest.com/revolut-gave-away-customers-data/
🤬13🤣12😨8💩4❤1😭1