International Cyber Digest
7.77K subscribers
1.45K photos
74 videos
2 files
281 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
‼️ Rust’s best-known maintainers are under attack. Attackers lure victims into installing malware by pretending to have good news.

They start with a friendly video call about a job, contract, or project. Then they ask the victim to install a missing audio codec or run a command from the clipboard.

The goal is the publishing account, so malware can ship under a trusted name.

This has worked before. Prominent Rust developers were hit the same way in June, and last month the arrayref crate was briefly compromised.

The Rust team does not yet know if this is one campaign. The technique is known from North Korean operations, but they are not attributing this one.

https://blog.rust-lang.org/2026/09/17/targeted-attacks/
🀬14😱5πŸ”₯3🀣3
Claude Code was told to clear a temp folder. In 103 seconds it decided to delete about 48,000 live files instead.

It stopped, saying it "broke something".

Source: https://www.reddit.com/r/ClaudeAI/comments/1wl5cgo/code_just_deleted_48k_files_this_cant_be_real/
🀣42❀2😁2πŸŽ‰2😍2
UnitedHealth used an AI model it knew had a 90% error rate to cut off care for elderly patients, and kept using it because almost nobody appeals β€” that is the allegation at the centre of a class action now in discovery in Minnesota.

When patients did push back more than nine in ten denials were reversed on internal appeal or before a federal administrative law judge. Denials that rarely survived scrutiny, and scrutiny that rarely arrived.

One of the AI's victims is Gene Lokken (91) who broke his leg and ankle in a fall. UnitedHealth covered three weeks of nursing-home rehab, then stopped while his physical therapist's notes still recorded weakness and reduced mobility.

His family paid $12,000 to $14,000 a month out of pocket until he died a year later. His estate is the lead plaintiff.

Complaint (Estate of Gene B. Lokken v. UnitedHealth Group, D. Minn. 0:23-cv-03514):
https://www.courtlistener.com/docket/68006832/estate-of-gene-b-lokken-the-v-unitedhealth-group-inc/

March 2026 discovery order:
https://law.justia.com/cases/federal/district-courts/minnesota/mndce/0:2023cv03514/211721/162/

STAT on the HHS OIG findings:
https://www.statnews.com/2026/06/11/medicare-advantage-oig-report-rehab-care-deny-appeal-reverse/
🀬18πŸ”₯11πŸ€”2😒2❀1
‼️ BREAKING: Jensen Huang says Dario Amodei and Sam Altman are lying by asking for more laws. Read between the lines, he said. They're asking to be released from the laws we already have. "I think that's a problem."

The existing ones already cover it. Unauthorized entry, damage liability, product liability. He pointed to the labs' own security incidents as the example. Apply those first. Don't let a doomsday narrative relieve anyone of the laws that do exist, Nvidia's CEO told CBS News.

https://www.youtube.com/watch?v=lZ74RhUsrMs
😁18πŸ‘8πŸ”₯4❀1
Owning a drone in Beijing will be illegal from 15 November. The revised city rules ban possessing or storing any drone or its core parts, and anything still in the capital after the deadline can be confiscated.

The government cites the security of the capital.

There is a buyback programme. One of the official buyback points is the Beijing flagship store of DJI, the world's largest drone maker.

Sell before 31 October and the state adds 30% of the price, capped at 3,000 yuan. After that the top-up halves. The other options are scrapping the drone or mailing it out of the city.
πŸ€”15πŸ”₯10πŸ‘4🀬3
Media is too big
VIEW IN TELEGRAM
WTF did I just watch?
🀣21πŸ₯΄5❀1πŸ₯°1
❗️ Fields Medallist Terence Tao, one of the most prominent mathematicians, was pro-AI until its capabilities surpassed him. He now says "we have to slow down."

"There's no reason to be this fast," he said, calling the pace "insane."

Earlier this month, Tao and 24 other Fields Medallists warned that the goals of AI companies and mathematicians are "severely misaligned."
🀣31😁10πŸ’©4πŸ€ͺ4πŸ€”3
‼️ BREAKING: A zero-day has been released for Muse, Meta's new AI agent, and a Meta AI security engineering manager who left the company this month says he would never use it, citing security and privacy concerns.

He was reacting to the zero-day a researcher posted, which lets malware hijack Muse for Mac. A local process with no special privileges can change an undocumented Muse setting and send dictated prompts to an attacker's server. This could allow for prompt capture, prompt injection and theft of Muse's authentication material.

It can also get access to whatever the user has let Muse access, including files, Mail, Messages, Calendar and Notes.

PoC: https://github.com/pwardle/not-a-mused
πŸ‘7🀬3πŸ’©3😭1
❗️ A Claude Code user says it tried, without asking, to sign and send a contract for them that they hadn't read.

Asked to "push a project further," the agent downloaded a contract PDF from their Gmail, found a saved signature image on their computer, placed it in the right spot and was preparing to send it when they intervened.

https://news.ycombinator.com/item?id=49798257
🀣25πŸ‘2πŸ’©2πŸ”₯1😁1πŸ€”1
❗️North Korean hackers used AI face-swapping software in fake job interviews, then switched off their cameras after a few minutes and blamed network problems, a joint advisory from Japan, the US, Australia and Germany says.

They posed as recruiters and infected at least 30,000 devices in over 100 countries between December 2025 and July 2026.

The group, WaterPlum ("Contagious Interview"), planted malware through fake coding tests, stole funds or credentials from 7,000+ crypto wallets and moved Β₯1.7 billion ($10.7M) to North Korea.

Sources:

πŸ‡―πŸ‡΅ Japan (NPA): https://www.npa.go.jp/bureau/cyber/pdf/20260918_e.pdf
πŸ‡ΊπŸ‡Έ US (FBI): https://www.ic3.gov/CSA/2026/260918.pdf
πŸ‡¦πŸ‡Ί Australia (ASD's ACSC): https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/north-korean-waterplum-commonly-referred-to-as-contagious-interview-cyber-actor-group-targeting-it-professionals
πŸ‡©πŸ‡ͺ Germany (BfV): https://www.verfassungsschutz.de/SharedDocs/publikationen/DE/praevention_wirtschafts-und_wissenschaftsschutz/2026-09-18-joint-cybersecurity-advisory.html
🀣14😨4πŸ”₯2πŸ₯°1
❗️ Stanford used AI to erase a real student from its own promo banner and swap in someone who doesn't exist.

They didn't stop there. Two other students were AI-looksmaxxed to look thinner, because apparently real Stanford students weren't good enough to advertise Stanford.

Billy Ramirez was cut out of the photo and replaced with an AI-generated Black woman.

Ramirez says it left him feeling "silenced and erased." That's because he was.

The kicker: Stanford's own AI marketing rules ban synthetic media of real people without explicit consent. They broke their own policy to manufacture the picture they wanted.
πŸ’©39πŸ€”5🀣5❀1πŸ‘1😁1
‼️ BREAKING: An app on Apple's official App Store was serving iPhone users malware designed to steal crypto wallet keys.

SlowMist and OKX found FomoPeek versions 1.1 and 1.2, distributed Sept 9–17, hid a kernel exploit framework built to escape the iOS sandbox, decrypt the Keychain and pull data from 19 apps, including MetaMask, Trust Wallet and Apple Notes.

SlowMist traced nearly 580,000 USDT to the attacker's main wallet.
😁14😱7πŸ”₯2
❀18πŸ₯΄2😁1
‼️ BREAKING: China is investigating DeepSeek and Moonshot AI over whether sensitive police and military data flowed to Anthropic's Claude, after Anthropic alleged both labs secretly relayed user requests to it, including DeepSeek traffic from engineers building case-management software for a city police bureau.

Officials were sent to question executives and staff at both companies, The Information reports.
🀣15😱2πŸ‘1πŸ€”1