International Cyber Digest
7.65K subscribers
1.37K photos
69 videos
2 files
258 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
❗️ The European Commission is proposing an age ladder rather than an outright ban, covering social media, online games, AI companion chatbots and video-sharing platforms.

All these platforms will be forced to verify users' ages.

Under 13: only accounts opened and controlled by a parent.

13 to 15: "introductory" accounts with screen-time limits, parental controls and restrictions on contact with strangers.

From 15: teenagers can sign up on their own.

The EU Kids Act is due Thursday, according to POLITICO, which has seen the preparatory documents.
πŸ’©29πŸ‘9🀬6πŸ€ͺ2
We're so back πŸ‡ΊπŸ‡Έ πŸ¦…
😭39🀣16πŸ‘3🀬3❀1
‼️ BREAKING: We're in contact with the Revolut hacker. According to them, they didn't only take Revolut data, they've also compromised multiple Italian law enforcement departments.

They say the operation targeting Revolut ran for six months, and that they used Italian law enforcement systems to send data requests to Revolut.

They claim to hold 147 GB taken from the Italian side, including internal docs, calendars and personal material, among it the chat logs of a federal officer arguing with his wife.

They've also launched a website today.

Threat actor IAmNotAVillain says most of the Revolut data comes from Switzerland and France, but claims Revolut also handed over data on residents of the following countries:

Cyprus, Portugal, Germany, Spain, Bulgaria, Czechia, Romania, Poland, Malta, Norway, Sweden, Italy, Greece, Netherlands, Latvia, Austria, Belgium, Estonia, Croatia, Ireland, Slovakia, Finland, Lithuania, Hungary, Denmark, Turkey, Monaco, Luxembourg, Bahamas, Slovenia, United Kingdom.

They say the data includes high-profile individuals, among them a player at Barcelona, Georges Mikautadze.
πŸ”₯23❀4πŸ’―4
❗️ IP intelligence company Spur pushed a PR containing comments from their AI saying they'd copied competitor Synthient's CLI.

Spur raised $200 million this year.

Synthient is just one guy named Ben.

https://github.com/spurintel/cli/commit/fb19e4cf0496294f8367470c02f353305f98ef73#diff-e162232bf6c899ce60163d3f64fbadbd1e983a3734e6f4a4b3c45f05dbae1d77R15
πŸ’©17❀3πŸ‘1
‼️ BREAKING: The official HBO Max Reddit account was hijacked and ran malvertising with a ClickFix attack on Reddit for 48 hours, pushing macOS malware to users.

The ad led to a convincing HBO Max landing page where the download button started no download. Instead it produced a prompt telling visitors to copy a command and paste it into Terminal.

A Reddit user flagged the ad in r/cybersecurity, and admins paused it pending an investigation.

By then the account had run 108 ads, fewer than half of them HBO Max lures. Another 47 pitched AI coding tools at developers and 15 a macOS disk cleaner.

Hudson Rock and ADAMnetworks traced the pasted command to a delivery system they call PasteSwitch, which selects a payload based on the visitor.

The payloads include macOS stealers that take browser credentials, Apple Notes and saved passwords; counterfeit Ledger, Trezor and Exodus apps built to capture wallet recovery phrases; and a Windows stealer loaded straight into memory.
🀣23❀5
German police will do anything to protect a transgender ex-police officer who raped a 15-year-old girl in a gas station toilet and uploaded child sexual abuse material to Instagram.

They're even blurring the tattoos on today's photos.

Meanwhile, they are posing with human pups.
🀬26πŸ’©11πŸ€”3πŸ‘1😁1
Foreign intelligence agencies have issued a warning that Iranian state hackers are targeting dissidents, activists and journalists, tricking them into opening fake Telegram or KeePass apps or bogus MRI scan results while posing as someone the target already knows.

A convincing decoy screen appears while the file quietly installs spyware dubbed Chosen Brick.

The attackers can then take screenshots, switch on the microphone, steal email, and copy WhatsApp and Telegram data from the browser. Those screenshots can reveal a victim's contacts, location and daily routine.

They often try a work computer first. If that fails or looks too risky, they ask the target to open the file on a personal device, where corporate security can't catch it.

Some victims' personal details have already surfaced on pro-Iranian leak sites. Victims have been found in the UK, the US and the Netherlands, and the agencies say those affected have been notified.

https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists
😒4
‼️ Meet transgender Maja Schmid from Rosenheim, who stood trial today for raping a 15-year-old girl, repeatedly raping a dog, and possessing and distributing child pornography.

They also have an OnlyFans with the bio "always horny and with no limits πŸ’‹πŸ”₯"

All while standing trial for sexual abuse.

Maja is tall and strong, and they were also part of GSG 9 (short for Grenzschutzgruppe 9, or Border Guard Group 9), the elite counter-terrorism and special operations tactical unit of the German Federal Police (Bundespolizei).
1🀬20πŸ’©5😱2❀1πŸ€”1πŸ’―1😭1