International Cyber Digest
7.77K subscribers
1.43K photos
72 videos
2 files
278 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
❗️ T-Mobile's chief operating officer posted warehouse photos of boxed iPhone 18 Pro units with readable unique device IDs on them: serial numbers and IMEIs.

Those IDs are what carriers and Apple use for activation, warranty, inventory, and lost or stolen reports.

With a public IMEI or serial, someone can try to abuse the systems built around those numbers: attempt a fraudulent lost or stolen report, which can get a device blocked from cellular networks, or clone the number onto counterfeit handsets, a known trick that works by copying IMEIs straight off retail packaging.
🀣36❀4😒2πŸŽ‰2πŸ”₯1
‼️ China has been recruiting US military personnel to smuggle secret U.S. Army hard drives that prosecutors say were sold to Chinese buyers.

A former Army soldier in Oregon pleaded guilty yesterday to conspiring to gather and transmit national defense information. Ruoyu Duan, 41, recruited two friends still on active duty at Joint Base Lewis-McChord and sold what they took to buyers in China.

It started with a job offer. In 2021 Duan introduced Capt. Li Tian to a Hong Kong contact who wanted a white paper on investment opportunities. Tian got $1,500, then a request for a second paper on his experience managing assets for the Army.

After that, Tian dealt with Duan directly: Stryker brigade documents, technical manuals for an armored vehicle, intelligence reports, all under distribution controls.

They had names for it. The documents were "teaching materials." The handoffs were "lessons." Duan's payments were "tuition."

Agents found 27 intelligence-report files in his Hillsboro home. He was drawing VA disability at the time, medically discharged in 2017 after an on-duty injury.

His first lawyer said Chinese intelligence officers recruited him while posing as headhunters, and that the material was unclassified, some of it public, much of it years old.

Duan also connected Sgt. Jian Zhao to Chinese buyers and moved the money between them.

Both soldiers have pleaded not guilty. Duan is sentenced Dec. 19.

https://www.oregonlive.com/crime/2026/09/hillsboro-man-pleads-guilty-in-china-espionage-case.html
😱7😭4❀2πŸ‘2🀣2
we are so back, AGI is around the corner πŸ”₯
Please open Telegram to view this post
VIEW IN TELEGRAM
🀣56😁4❀2πŸ”₯2
‼️ BREAKING: Apple is doubling down on security and has quietly built a kernel-level security monitor into iOS to stop exploits by monitoring stuff like process injection, an app's code signature going invalid, memory that isn't backed by any file and more.
It can do more than watching only, as opening a file, launching a program, changing memory permissions or reaching into another process stops in the kernel and waits for it to answer allow or deny.
It turned up in a public comparison of the iOS 27.0 release against the 27.2 beta, which added three new kernel extensions, one of them a trimmed-down port of the endpoint security engine Apple built for Macs.
Source: com.apple.iokit.EndpointSecuritySE, absent from iOS 27.0 (24A437), present in the 27.2 beta (24B5084k), with its user-space library alongside it.
See: https://github.com/blacktop/ipsw-diffs/blob/main/27_0_24A437_vs_27_2_24B5084k/README.md
πŸ”₯20❀1πŸ‘1
This media is not supported in your browser
VIEW IN TELEGRAM
‼️ Huawei is on trial for spending two decades taking trade secrets out of American companies.

On Wednesday, prosecutors showed the jury 54 seconds of what they say that looked like.

Surveillance video from inside T-Mobile's locked robotics lab shows a man reach behind Tappy, the robot T-Mobile built to tap and swipe phone screens, pull out a component and zip it into a black backpack.

Prosecutors say he is a Huawei employee.

They also put an internal Huawei email in front of jurors acknowledging that T-Mobile "would not want to share the details about the robot technology," and say the requests kept coming anyway.

Huawei has pleaded not guilty and says a handful of engineers broke lab rules on their own.
πŸ”₯16πŸ’©7πŸ‘2
‼️ More than 100,000 WordPress sites have been compromised after an attacker exploited a hardcoded Cloudflare API key in marketing company Brevo's source code. The sites are now serving a ClickFix scam.

The API key gave the attacker full account permissions, and they've used it to rewrite the JavaScript that the email-marketing firm's customers embed on their own sites.

Visitors got a fake Cloudflare captcha telling them to paste a command into the Windows Run box or a terminal, leading to malware infection.

Brevo says the key is now out of its source code, replaced by short-lived tokens with limited permissions, and that credentials are no longer kept in source or config files.

Site owners got something extra as well: if the admin happened to be logged into WordPress when the page loaded, the script quietly installed a plugin. Sansec couldn't obtain a copy and suspects a backdoor.

Brevo lists eBay, Louis Vuitton, Michelin and Amnesty International as its customers.

Source: https://sansec.io/research/brevo-supply-chain-attack
πŸ”₯9🀣4😱2πŸ₯΄1
‼️ BREAKING: OpenAI was hacked by an Anthropic model. A HEIF photo uploaded to OpenAI's public support forum triggered a bug in the site's image decoder, led to code execution on the forum, and, through a second flaw in OpenAI's own login, ended with a pull request in OpenAI's internal GitHub.

The forum runs Discourse, the off-the-shelf software behind countless community sites. Discourse was still shipping an old copy of libheif, the library that decodes iPhone-style photos. The bug in it had already been fixed upstream.

But the fix was never labelled a security fix, so nobody treated it as urgent.

Hacktron's researchers uploaded a HEIF image and got their own code running on community[.]openai[.]com.

Then came the second bug, in OpenAI's own single sign-on, the "log in with OpenAI" button the forum uses. It turned that forum foothold into the actual ChatGPT and Codex accounts of people who had signed in there. OpenAI employees among them.

And a ChatGPT account is no longer just a chatbot. Through Codex, users wire in Gmail, Outlook, Drive, Slack, GitHub.

To prove the access was real, they used one employee account to have Codex open a harmless pull request in OpenAI's internal repo. They say they read no sensitive code.

OpenAI patched the SSO flaw roughly 14 hours after the report and paid a $6,500 bug bounty.

The team says Anthropic's Opus 4.8 found the libheif bug, and Opus 5 turned it into a working exploit.

Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick, and many more were also vulnerable and compromised by the same team of researchers.

https://heif-heist.com/
🀣25🀯7❀3πŸ”₯3πŸ₯΄2πŸ₯°1😁1
A power bank belonging to Camiel Eurlings, KLM's former CEO, caught fire in business class on a KLM flight to CuraΓ§ao.

The former CEO seems to have ignored the company's own rules, as power banks may not be used on board [nor charged].

The crew put out the flames. The former CEO, who was reportedly sleeping during the incident, suffered light burns.

The flight turned back over the Atlantic on Thursday, hours out of Amsterdam, and all 322 passengers landed safely back at Schiphol.
🀯14πŸ”₯4πŸŽ‰3
‼️ TeamPCP was backing up stolen credentials to a Google Drive account linked to sheepstealing@gmail.com.

Google found a 2019 forum dispute between sheepstealing and a seller of illegal Microsoft Office keys, in which sheepstealing demanded a refund to the PayPal account ruben@thomsonfamily.net.au, which turned out to belong to the recently arrested Ruben Ian Thomson.

Google says that almost from the start, it had a mole inside TeamPCP, the group that laced hundreds of open source packages with malware and breached more than a thousand companies.

Instead of warning each breached company, Google went to AWS, Microsoft and other providers to have the credentials revoked before the hackers could cash them in.

TeamPCP eventually moved servers and cut the persona out of the chat.

Source: https://www.wired.com/story/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/
🀯13🀣8
‼️ This week cybersecurity company CrowdSec learned that attackers had read its private GitHub repositories back in May.

The likely way in was TanStack, a widely used set of JavaScript libraries CrowdSec's developers were working with at the time.

Dozens of poisoned packages went out, carrying malware that stripped tokens and credentials off developer machines.

In CrowdSec's case it lifted an API key that could read the private codebase.

The tip came from outside the company, from French leak-monitoring outfit Fuites Infos.

CrowdSec says no customer data, credentials or logs were taken, and that the stolen code β€” the SaaS console, some AWS routines, connectors β€” is of limited use to anyone else because it only talks to CrowdSec's own systems.

The open source Security Engine was public by design.

All tokens have been rotated.

https://www.crowdsec.net/blog/crowdsec-statement-source-code-exposure
😱5😁4πŸ’©2
Apple's new VP of hardware engineering says it makes his "skin crawl" to see someone put a screen protector on an iPhone, he says the company works hard on those front screens and a sheet of plastic hides them.
😁29πŸ’©22πŸ‘6