International Cyber Digest
7.77K subscribers
1.43K photos
72 videos
2 files
279 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
‼️ Google says a zero-click Pixel cellular modem vulnerability has been spotted being used in the wild in limited, targeted attacks.

A logic error lets an attacker bypass permission checks and gain elevated access, though the CVE record indicates attackers need to be nearby.

The September update (patch level 2026-09-05 or later) fixes CVE-2026-58704. CISA has added it to its Known Exploited Vulnerabilities catalog.

https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01
πŸ€”6πŸ‘3❀1πŸ”₯1😱1
❗️ The FCC says four spectrum auctions planned before the end of 2028 could raise more than $100 billion.

The first, set for 2027, will sell 160 MHz from the middle of the upper C-band (3.98–4.2 GHz).

Chairman Brendan Carr says interest now reaches beyond AT&T, Verizon and T-Mobile, which carry nearly all US mobile connections, and that selling airwaves to more companies will bring new competition.

The FCC has also been making room for satellite broadband. Last week it said it wants more spectrum available for satellite internet, and in May it approved SpaceX's purchase of spectrum from EchoStar.

Source: Reuters
https://www.reuters.com/business/media-telecom/us-official-says-upcoming-spectrum-auctions-could-generate-more-than-100-billion-2026-09-17/
😁2πŸ€ͺ2
‼️ BREAKING: Attackers have compromised iTorrents, a widely used public repository of torrent files, and used it to spread malware disguised as movies.

Many rely on iTorrents for torrent files, so they unknowingly passed the swapped files to their users. Magnet links delivered a Windows executable posing as a film, such as The Odyssey (2026)

Kaspersky researchers say home users and organizations in Europe were among the victims, including in the Netherlands, Germany, Spain and Belgium. The campaign has several hundred victims worldwide.

Kaspersky saw infection attempts against organizations in government, IT, consulting, retail, transport and agriculture.

Once someone runs it, the malware lets operators browse, download, upload and delete files on the machine.

The repository was still compromised when Kaspersky published its report.

Read: https://securelist.com/moviereaper-malware-torrent-odyssey-solana/121344/
🀣14😱5😁2
❗️ T-Mobile's chief operating officer posted warehouse photos of boxed iPhone 18 Pro units with readable unique device IDs on them: serial numbers and IMEIs.

Those IDs are what carriers and Apple use for activation, warranty, inventory, and lost or stolen reports.

With a public IMEI or serial, someone can try to abuse the systems built around those numbers: attempt a fraudulent lost or stolen report, which can get a device blocked from cellular networks, or clone the number onto counterfeit handsets, a known trick that works by copying IMEIs straight off retail packaging.
🀣36❀4😒2πŸŽ‰2πŸ”₯1
‼️ China has been recruiting US military personnel to smuggle secret U.S. Army hard drives that prosecutors say were sold to Chinese buyers.

A former Army soldier in Oregon pleaded guilty yesterday to conspiring to gather and transmit national defense information. Ruoyu Duan, 41, recruited two friends still on active duty at Joint Base Lewis-McChord and sold what they took to buyers in China.

It started with a job offer. In 2021 Duan introduced Capt. Li Tian to a Hong Kong contact who wanted a white paper on investment opportunities. Tian got $1,500, then a request for a second paper on his experience managing assets for the Army.

After that, Tian dealt with Duan directly: Stryker brigade documents, technical manuals for an armored vehicle, intelligence reports, all under distribution controls.

They had names for it. The documents were "teaching materials." The handoffs were "lessons." Duan's payments were "tuition."

Agents found 27 intelligence-report files in his Hillsboro home. He was drawing VA disability at the time, medically discharged in 2017 after an on-duty injury.

His first lawyer said Chinese intelligence officers recruited him while posing as headhunters, and that the material was unclassified, some of it public, much of it years old.

Duan also connected Sgt. Jian Zhao to Chinese buyers and moved the money between them.

Both soldiers have pleaded not guilty. Duan is sentenced Dec. 19.

https://www.oregonlive.com/crime/2026/09/hillsboro-man-pleads-guilty-in-china-espionage-case.html
😱7😭4❀2πŸ‘2🀣2
we are so back, AGI is around the corner πŸ”₯
Please open Telegram to view this post
VIEW IN TELEGRAM
🀣56😁4❀2πŸ”₯2
‼️ BREAKING: Apple is doubling down on security and has quietly built a kernel-level security monitor into iOS to stop exploits by monitoring stuff like process injection, an app's code signature going invalid, memory that isn't backed by any file and more.
It can do more than watching only, as opening a file, launching a program, changing memory permissions or reaching into another process stops in the kernel and waits for it to answer allow or deny.
It turned up in a public comparison of the iOS 27.0 release against the 27.2 beta, which added three new kernel extensions, one of them a trimmed-down port of the endpoint security engine Apple built for Macs.
Source: com.apple.iokit.EndpointSecuritySE, absent from iOS 27.0 (24A437), present in the 27.2 beta (24B5084k), with its user-space library alongside it.
See: https://github.com/blacktop/ipsw-diffs/blob/main/27_0_24A437_vs_27_2_24B5084k/README.md
πŸ”₯20❀1πŸ‘1
This media is not supported in your browser
VIEW IN TELEGRAM
‼️ Huawei is on trial for spending two decades taking trade secrets out of American companies.

On Wednesday, prosecutors showed the jury 54 seconds of what they say that looked like.

Surveillance video from inside T-Mobile's locked robotics lab shows a man reach behind Tappy, the robot T-Mobile built to tap and swipe phone screens, pull out a component and zip it into a black backpack.

Prosecutors say he is a Huawei employee.

They also put an internal Huawei email in front of jurors acknowledging that T-Mobile "would not want to share the details about the robot technology," and say the requests kept coming anyway.

Huawei has pleaded not guilty and says a handful of engineers broke lab rules on their own.
πŸ”₯16πŸ’©7πŸ‘2
‼️ More than 100,000 WordPress sites have been compromised after an attacker exploited a hardcoded Cloudflare API key in marketing company Brevo's source code. The sites are now serving a ClickFix scam.

The API key gave the attacker full account permissions, and they've used it to rewrite the JavaScript that the email-marketing firm's customers embed on their own sites.

Visitors got a fake Cloudflare captcha telling them to paste a command into the Windows Run box or a terminal, leading to malware infection.

Brevo says the key is now out of its source code, replaced by short-lived tokens with limited permissions, and that credentials are no longer kept in source or config files.

Site owners got something extra as well: if the admin happened to be logged into WordPress when the page loaded, the script quietly installed a plugin. Sansec couldn't obtain a copy and suspects a backdoor.

Brevo lists eBay, Louis Vuitton, Michelin and Amnesty International as its customers.

Source: https://sansec.io/research/brevo-supply-chain-attack
πŸ”₯9🀣4😱2πŸ₯΄1
‼️ BREAKING: OpenAI was hacked by an Anthropic model. A HEIF photo uploaded to OpenAI's public support forum triggered a bug in the site's image decoder, led to code execution on the forum, and, through a second flaw in OpenAI's own login, ended with a pull request in OpenAI's internal GitHub.

The forum runs Discourse, the off-the-shelf software behind countless community sites. Discourse was still shipping an old copy of libheif, the library that decodes iPhone-style photos. The bug in it had already been fixed upstream.

But the fix was never labelled a security fix, so nobody treated it as urgent.

Hacktron's researchers uploaded a HEIF image and got their own code running on community[.]openai[.]com.

Then came the second bug, in OpenAI's own single sign-on, the "log in with OpenAI" button the forum uses. It turned that forum foothold into the actual ChatGPT and Codex accounts of people who had signed in there. OpenAI employees among them.

And a ChatGPT account is no longer just a chatbot. Through Codex, users wire in Gmail, Outlook, Drive, Slack, GitHub.

To prove the access was real, they used one employee account to have Codex open a harmless pull request in OpenAI's internal repo. They say they read no sensitive code.

OpenAI patched the SSO flaw roughly 14 hours after the report and paid a $6,500 bug bounty.

The team says Anthropic's Opus 4.8 found the libheif bug, and Opus 5 turned it into a working exploit.

Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick, and many more were also vulnerable and compromised by the same team of researchers.

https://heif-heist.com/
🀣25🀯7❀3πŸ”₯3πŸ₯΄2πŸ₯°1😁1
A power bank belonging to Camiel Eurlings, KLM's former CEO, caught fire in business class on a KLM flight to CuraΓ§ao.

The former CEO seems to have ignored the company's own rules, as power banks may not be used on board [nor charged].

The crew put out the flames. The former CEO, who was reportedly sleeping during the incident, suffered light burns.

The flight turned back over the Atlantic on Thursday, hours out of Amsterdam, and all 322 passengers landed safely back at Schiphol.
🀯14πŸ”₯4πŸŽ‰3