International Cyber Digest
7.77K subscribers
1.44K photos
73 videos
2 files
281 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
‼️ Meet transgender Maja Schmid from Rosenheim, who stood trial today for raping a 15-year-old girl, repeatedly raping a dog, and possessing and distributing child pornography.

They also have an OnlyFans with the bio "always horny and with no limits πŸ’‹πŸ”₯"

All while standing trial for sexual abuse.

Maja is tall and strong, and they were also part of GSG 9 (short for Grenzschutzgruppe 9, or Border Guard Group 9), the elite counter-terrorism and special operations tactical unit of the German Federal Police (Bundespolizei).
1🀬38πŸ’©8πŸ€”4😱2😭2❀1πŸ’―1
One guy in Sweden built a search engine that doesn't run on Google or Bing. It's been online since 2021, and the bills come to about $200 a month.

Viktor LΓΆfgren says most "alternative" search engines are really powered by Google or Bing, or by authoritarian states like Russia and China.

His engine, Marginalia, has its own crawler and index, with no ads, no loans and no investors.

His argument: when nearly all search runs through a few US companies, censorship becomes easy, even by accident, and one country's cultural bias shapes what everyone finds.

He isn't trying to replace Google. He wants Marginalia to be the "minority report" that keeps the big engines honest.

So it ranks what they tend to bury: personal blogs, old university pages, text-heavy sites with nothing to sell.

Every result shows whether a page uses affiliate links or JavaScript, and you can filter those out. An "explore" mode just shows you random sites from the index.

It's keyword-based on purpose. LΓΆfgren argues that the better a search engine gets at answering questions, the worse it gets at finding websites.

It's open source under the AGPL, so you can host your own copy.

https://marginalia-search.com
πŸ‘41❀11πŸ”₯9😁4πŸ’©3
‼️ Google has fixed critical Chrome remote code execution vulnerabilities that could let a malicious website or ad run code on a computer during normal browsing.

They're among 42 security fixes in the new release, 28 of them rated high. Google's release notes don't mention any being exploited in the wild.

https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html
❀6πŸ”₯3πŸ’©1
Valve is telling some Steam hardware buyers that the CEVA Logistics breach didn't expose their data after all.

Last month, Valve warned buyers of devices like the Steam Deck and Steam Controller that their details may have been stolen in the attack on CEVA, which ships Steam hardware across Europe.

In a new email, Valve says the part of CEVA's systems that handled their orders wasn't hit, so the attackers never viewed or took their data.

Many CEVA clients reported their customer's data was stolen.

CEVA hasn't finished its investigation, and it's unclear whether all European hardware buyers are in the clear or only those who got the new email.
❀9
❗️ Meta going to release smart glasses without a camera, as multiple countries are discussing a ban on camera glasses and criticism mounts over its current models letting wearers photograph and film people without them noticing.

The glasses, codenamed Luna, still have six microphones. Wearers use them to talk to Meta AI and the company's new AI agent Muse, and hear the answers through built-in speakers.

Meta hopes to start shipping in October and could unveil them at its Connect event this week.
🀣15πŸ’©7πŸ€ͺ1
‼️ Controversial online casino Duel is selling stolen, unredacted Revolut data in its merch store, packaged as a $29.99 "KYC kit."

The data was obtained from threat actors by one of its employees.

Duel is known for provocative rage bait, including glorifying school shooters and Nazis and stereotyping Muslim, Jewish and Black people.

This is a new low. It's unclear which country Duel operates from, but the casino could face a notice-and-takedown (NTD), and even criminal prosecution.
😁17πŸ’©6❀3πŸ€ͺ1
‼️ BREAKING: Hackers say they breached Russia's Central Election Commission and its contractors, obtaining classified documents, server configurations, passwords, source code, meeting recordings, employee chats and more.

The contractors include the developer of GAS Vybory 2.0, the country's new election system, which will be used for the first time in the upcoming State Duma elections.

The hackers have also made a game using what are the system's real interfaces, in which you play an election official who changes the results.

They're also calling on election commission members to report any fraud to them.

Ironically, in August, election commission head Ella Pamfilova said the system was impossible to hack.

The hacker group, which goes by the name CikLeak, says it did not interfere with voting.

https://cikleak.net/
🀣27πŸ”₯3πŸ€”2🀬1πŸ’©1
‼️ A key developer of the LockerGoga, MegaCortex and Nefilim ransomware has been sentenced in Zurich to 12 years and nine months in prison.

The 52-year-old Ukrainian national, identified as Artem Melnik, told the court that he was merely an IT-security consultant and that ransomware source code found on his systems came from a client.

The court didn't believe him, because investigators had also found extortion messages among his data.

The judge stressed that Melnik was not the mastermind of the operation. He developed the malware and passed it to other, still largely unidentified operators, who selected targets and coordinated the extortion campaigns.

Victims included Stadler Rail, Meier Tobler and Crealogix. Prosecutors put the losses at around CHF 100 million ($123 million).

The case also exposed another figure in the operation.

At the August trial, prosecutors said the attacks involving Melnik were directed by Ukrainian hacker Oleksandr Vitalyevich Ieremenko, who operated from Moscow.

Ieremenko was already wanted by the United States over major hacking and securities-fraud cases. Swiss prosecutors cited testimony alleging that he was protected by Russia's FSB and used a false identity linked to Russian intelligence.

He reportedly died after falling from a window in Moscow in 2022. Prosecutors said they could not determine whether his death was an accident, suicide or killing.

And another major figure in the same ransomware ecosystem is still at large.

US authorities allege that Volodymyr Tymoshchuk, aka "Farnetwork" / "Deadforz," served as an administrator of LockerGoga, MegaCortex and Nefilim and helped compromise hundreds of companies worldwide.

The FBI is offering up to $10 million for information leading to his arrest or conviction.
❀9πŸ€ͺ9🀯5
‼️ Google says a zero-click Pixel cellular modem vulnerability has been spotted being used in the wild in limited, targeted attacks.

A logic error lets an attacker bypass permission checks and gain elevated access, though the CVE record indicates attackers need to be nearby.

The September update (patch level 2026-09-05 or later) fixes CVE-2026-58704. CISA has added it to its Known Exploited Vulnerabilities catalog.

https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01
πŸ€”6πŸ‘3❀1πŸ”₯1😱1
❗️ The FCC says four spectrum auctions planned before the end of 2028 could raise more than $100 billion.

The first, set for 2027, will sell 160 MHz from the middle of the upper C-band (3.98–4.2 GHz).

Chairman Brendan Carr says interest now reaches beyond AT&T, Verizon and T-Mobile, which carry nearly all US mobile connections, and that selling airwaves to more companies will bring new competition.

The FCC has also been making room for satellite broadband. Last week it said it wants more spectrum available for satellite internet, and in May it approved SpaceX's purchase of spectrum from EchoStar.

Source: Reuters
https://www.reuters.com/business/media-telecom/us-official-says-upcoming-spectrum-auctions-could-generate-more-than-100-billion-2026-09-17/
😁2πŸ€ͺ2πŸ‘1
‼️ BREAKING: Attackers have compromised iTorrents, a widely used public repository of torrent files, and used it to spread malware disguised as movies.

Many rely on iTorrents for torrent files, so they unknowingly passed the swapped files to their users. Magnet links delivered a Windows executable posing as a film, such as The Odyssey (2026)

Kaspersky researchers say home users and organizations in Europe were among the victims, including in the Netherlands, Germany, Spain and Belgium. The campaign has several hundred victims worldwide.

Kaspersky saw infection attempts against organizations in government, IT, consulting, retail, transport and agriculture.

Once someone runs it, the malware lets operators browse, download, upload and delete files on the machine.

The repository was still compromised when Kaspersky published its report.

Read: https://securelist.com/moviereaper-malware-torrent-odyssey-solana/121344/
🀣14😱5😁2
❗️ T-Mobile's chief operating officer posted warehouse photos of boxed iPhone 18 Pro units with readable unique device IDs on them: serial numbers and IMEIs.

Those IDs are what carriers and Apple use for activation, warranty, inventory, and lost or stolen reports.

With a public IMEI or serial, someone can try to abuse the systems built around those numbers: attempt a fraudulent lost or stolen report, which can get a device blocked from cellular networks, or clone the number onto counterfeit handsets, a known trick that works by copying IMEIs straight off retail packaging.
🀣36❀4😒2πŸŽ‰2πŸ”₯1