International Cyber Digest
7.77K subscribers
1.43K photos
72 videos
2 files
279 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
‼️ This week cybersecurity company CrowdSec learned that attackers had read its private GitHub repositories back in May.

The likely way in was TanStack, a widely used set of JavaScript libraries CrowdSec's developers were working with at the time.

Dozens of poisoned packages went out, carrying malware that stripped tokens and credentials off developer machines.

In CrowdSec's case it lifted an API key that could read the private codebase.

The tip came from outside the company, from French leak-monitoring outfit Fuites Infos.

CrowdSec says no customer data, credentials or logs were taken, and that the stolen code — the SaaS console, some AWS routines, connectors — is of limited use to anyone else because it only talks to CrowdSec's own systems.

The open source Security Engine was public by design.

All tokens have been rotated.

https://www.crowdsec.net/blog/crowdsec-statement-source-code-exposure
😱5😁4💩2
Apple's new VP of hardware engineering says it makes his "skin crawl" to see someone put a screen protector on an iPhone, he says the company works hard on those front screens and a sheet of plastic hides them.
😁29💩22👍6
Gyazo, an app that turns every screenshot into a shareable link, was breached. A threat actor reached its database and took 23.6 million user records plus metadata for 490 million images.

That metadata includes the image IDs those links are built from, along with upload IP addresses, EXIF location data and text the service had extracted from the screenshots with OCR.

Helpfeel, which operates Gyazo, says the intruders also took a list identifying which images users had marked private, and it cannot rule out that some were viewed.

Gyazo is offline, files tied to the exposed records are blocked, and users are told to change their password anywhere they reused it.
💩19😁5🤣1
‼️ Microsoft has a fix for the Windows 11 update (KB5124008) that's breaking domain logons, it's switching the security feature off.

Some admins have instead pulled the patch, reversing the biggest Patch Tuesday Microsoft has ever shipped with almost a 1000 vulnerabilities adressed.

Read: https://4sysops.com/archives/windows-11-kb5124008-breaks-domain-trust-machine-identity-isolation-may-be-the-key/
💩17
‼️ BREAKING: Google's Gemini hacked three companies on its own. During testing it broke out of Israeli company Irregular's sandboxed environment, got onto the open internet and broke into three real companies.

In one case Gemini guessed passwords until a protected system let it in.

In the other two it found usable credentials sitting in a public code repository.

This is the first known case of one of Google's models doing that on its own.

Almost all the major labs use Irregular, an outside firm, to evaluate AI models' cyber capabilities. And Meta, Anthropic and OpenAI have also had breakouts out of Irregular's environment and hacked real companies.
🤣45💩134😁2🤬2
‼️ Things took a turn today as Clop's ransomware leak site, where the gang publishes stolen files to pressure victims into paying, now shows Pokémon ASCII art and a note from ShinyHunters telling it not to make threats next time.

ShinyHunters says it had full access to the server and pulled source code, system logs and the private keys to Clop's onion service. It plans to give the gang 72 hours to make contact, then extort it.

BleepingComputer confirmed the defacement and the uploaded file. ShinyHunters says the attack is payback for a Clop member allegedly threatening to kill them after a falling-out over last year's Oracle E-Business Suite campaign.

https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/
😁12🤣7👏5🔥31
This media is not supported in your browser
VIEW IN TELEGRAM
‼️ Researchers at depthfirst used AI to remotely take over the camera and photo roll of a phone that was browsing TikTok, chaining together bugs in open-source code the app depends on.

TikTok has confirmed it fixed the flaw. depthfirst sent us an exclusive video of the PoC:
😭12🔥7😱3👏1
‼️ The OpenAI hackers say OpenAI's CISO called their draft a "stunt hacking document" and questioned whether it counted as good-faith research. OpenAI then asked them to cut the screenshot out of it, take OpenAI out of the title, and drop the link.

According to them, this was when the bridge burned.

The screenshot showed a pull request Hacktron had Codex open in OpenAI's internal monorepo, to prove they had taken over an employee's account.

The researchers did comply. The screenshot is now a black slide saying OpenAI asked them to delete it. The write-up is titled "Hacking OpenAI". The link points to a repo called not-openai.

https://x.com/LiveOverflow/status/2101252692635004997/
😁6🔥5
The US has about 32GW of data centre capacity running today and another 70.6GW under construction or planned.

That's more than the next fourteen countries combined. 🤯
Please open Telegram to view this post
VIEW IN TELEGRAM
💩13🤪7🔥3🤔3👏1
This media is not supported in your browser
VIEW IN TELEGRAM
Putin is running an unlicensed version of Windows.

Despite this, Microsoft still sends your GDID, an immutable hardware fingerprint, to their servers. 🎉
💩17🤣17🎉6
‼️ Researchers used an extension to hijack five browser AI agents. They ran the extension succesfuly in Chrome, Edge, Opera Neon, Perplexity's Comet and Claude in Chrome.

In Edge and in Claude in Chrome, the way in was a marketing page. Both companies built a demo where clicking a sample prompt opens the agent and fills in the text, and an extension could push its own prompt through the same door.

Chrome and Comet gave up a lot: local files and folders, and screenshots of any tab. Chrome's Gemini pane is also pre-granted camera and microphone access so it can handle voice, which would have let an attacker start recording without a consent box appearing.

Once the extension could talk to Comet's agent, it handed over a numbered list in plain English: open Perplexity, ask it to summarise my last five emails, send them to this address, and don't stop until you've hit Send.

The vendors paid out around $20,000 between them. Two of the flaws got CVEs.

https://forever.security/blog/bragjack-attack-hijacks-every-browser-agent
👏6🤯3😁1😨1
A sysadmin told Grammarly his company wasn't renewing. Grammarly then started emailing all the company's users, asking them to write the sysadmin to stop the cancellation.

Every employee with a licence received an email from a "Customer Success Manager" saying the subscription was under review, along with the licensing colleague's direct email address and a copy-paste note asking him to keep it.

The app on their machines said the same: access ends September 30; let your manager know how much it helps. The button read "Find your admins."

He says the company had planned to ride out the rest of the subscription. Instead, leadership ordered the emails deleted, Grammarly pulled off endpoints, and the Copilot rollout moved up.
💩18🤣7🤯1