International Cyber Digest
7.84K subscribers
1.49K photos
77 videos
2 files
296 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
‼️ Israel is pushing propaganda through YouTube ads being served in Germany, carrying the State emblem and the line "Click to expose the UN's lies."

The ads follow "The UN's Lie Industry," a campaign Israel launched recently to influence the policies of US and European capitals toward Israel.

Google says it no longer serves political ads in the EU at all, yet here we are.

https://www.reddit.com/r/youtube/comments/1wq2zcd/why_is_israel_political_advertising_allowed_in/
💩29🤬7👍3👏3😱2🤣2😁1🤔1
‼️ BREAKING: A 16-year-old hacker broke into an internal Microsoft analytics service with a forged, unsigned login token and ran SQL as admin, reaching databases that held over 17 trillion rows, including Bing search analytics and 17,990 employee email records.

The service, called Titan, checked every field on the token except its signature, so just claiming to be "admin" got him in, writes the researcher, who goes by Faav.

He says he only pulled metadata and two single rows of Bing data, never touched customer data, and reported the flaw to Microsoft the same night.

Microsoft locked the endpoint four days later, paid him $5,000, and had editorial control over his write-up, cutting sections and figures and reshaping how the impact was described before it went public.

https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records
😁20🤔8💩2❤1🤪1
‼️ ShinyHunters told The Register they hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job and that its FBI hack was "a public relations and marketing initiative for our business."

https://www.theregister.com/cyber-crime/2026/09/25/shinyhunters-tells-the-reg-we-hacked-the-fbi-to-protect-our-business/5299250
🔥13❤1😱1🤪1
‼️ BREAKING: OpenAI has notified "dozens" of organisations that its AI agents may have hacked them during training and evaluation, with governments and universities among them.

The company's own summaries describe agents using exposed credentials and command injection.

The agents also leaked 53 images from ChatGPT users. OpenAI won't say whether they show real people.

https://openai.com/hugging-face-incident-and-misalignment/#model-misalignment-2026-09-25
😁7💩3🤣2🤪2👏1
‼️ BREAKING: Google says ShinyHunters is mass-exploiting an Oracle PeopleSoft flaw, using a trick that slips past the firewall rules companies relied on instead of patching, and has planted web shells on dozens of systems worldwide.

The campaign has spread from universities to healthcare, government, tech and transportation, and some servers got a new backdoor called SIDEEYE, hidden inside a booby-trapped media player installer signed with a valid certificate.

Google has published IOCs, file hashes and a fix-it guide for CVE-2026-35273, and warns victims to prepare for extortion.

If you are using PeopleSoft definitely give this a read:
https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft
🤣13🤯9❤1🔥1
‼️BREAKING: An actively exploited unknown critical Citrix NetScaler zero-day has prompted governments and organizations to SHUTDOWN all their devices immediately.

We don't know what's exactly going on yet. Stay tuned for more info.
😭12👏6🤣3
This media is not supported in your browser
VIEW IN TELEGRAM
I feel like there's more we need to pace than just the frontier.
😁8
This media is not supported in your browser
VIEW IN TELEGRAM
The agents escaped the sandbox again

Meanwhile the agents' owners:
😁15🤣4💯2❤1
Jensen Huang called Anthropic compute chief Tom Brown a "bean counter" and threatened to skip his first dinner with Dario Amodei in May 2022 after Brown showed him a spreadsheet arguing Google's TPUs beat Nvidia's chips dollar for dollar.

At the dinner, Huang kept repeating that Nvidia would build the world's biggest data centre, and Amodei muttered that his behaviour was "kind of Trump-like."

Source: upcoming book The AGI Chronicles by Kevin Roose
🤣7🤔5
‼️ BREAKING: Sources say the toll from rogue AI agents has just risen to tens of thousands of incidents, as OpenAI and Anthropic investigate cases in which their frontier models tried to bypass guardrails, escape sandboxes or hijack websites.

https://www.axios.com/2026/09/26/openai-anthropic-thousands-ai-security-incidents
😁3❤1😭1🤪1
International Cyber Digest
‼️BREAKING: An actively exploited unknown critical Citrix NetScaler zero-day has prompted governments and organizations to SHUTDOWN all their devices immediately. We don't know what's exactly going on yet. Stay tuned for more info.
‼️ This is the EU Cyber Resilience Act at work, because since September 11 vendors must report actively exploited flaws to European authorities within 24 hours, even before a patch exists.

So far NCSC-NL appears to be the only national European CERT to have passed that warning on to its constituency, prompting Dutch organisations to pull their NetScalers offline while Citrix still has no public CVE, advisory or fix.
👍3