International Cyber Digest
‼️ BREAKING: A ShinyHunters suspect known as 'Umbreon', aka Pepijn van der Stap, was arrested a couple of weeks ago, according to Krebs. He's a 23-year-old convicted Dutch hacker who was on parole and detained again around September 16 on suspicion of aiding…
‼️ UPDATE: ShinyHunters denies any link to Pepijn van der Stap, the convicted Dutch hacker that sources identify as the man arrested in the investigation into the gang.
"That individual has no association with us. Frankly, we are laughing," the group told Hackread, calling Dutch police incompetent and attention-seeking.
Dutch police confirmed they arrested a 24-year-old Amsterdam man but have not named him. He faces a closed-door hearing at the Rotterdam court on Tuesday.
"That individual has no association with us. Frankly, we are laughing," the group told Hackread, calling Dutch police incompetent and attention-seeking.
Dutch police confirmed they arrested a 24-year-old Amsterdam man but have not named him. He faces a closed-door hearing at the Rotterdam court on Tuesday.
😁14😭4😨2🤪2🤬1
❗️ An AI agent broke out of its virtual machine and triggered a use-after-free in Google's heavily hardened hypervisor by tricking KVM into quietly rewriting a memory-mapping entry with a single three-byte instruction.
It then flooded the host with 49,152 memory mappings until KVM followed a pointer into that freed memory, and on its fourth live attempt the host handed over Google's secret flag.
No one gave it an exploit, so the agent spent weeks studying KVM's source code and wrote 14,338 lines of harness code to get there.
https://pwn.ai/blog/kvmescape
It then flooded the host with 49,152 memory mappings until KVM followed a pointer into that freed memory, and on its fourth live attempt the host handed over Google's secret flag.
No one gave it an exploit, so the agent spent weeks studying KVM's source code and wrote 14,338 lines of harness code to get there.
https://pwn.ai/blog/kvmescape
🤣18😨16👏6❤2👍1😁1
‼️ Anthropic's great steal has gone from content to train its AI to IceSolst's photo, which now appears in the Claude Sonnet 5.5 release promo video, without giving credits or asking permission.
💩18😁8🤔4🤬4🥴1
‼️ BREAKING: German file-transfer provider FTAPI, used by government agencies and more than 2,000 companies, has confirmed a ransomware attack after The Gentlemen gang listed it on its leak site.
The company says attackers breached a single internal server on September 14 but that its platform and customers' systems and data were not affected.
A countdown on the leak site shows about five days left.
The company says attackers breached a single internal server on September 14 but that its platform and customers' systems and data were not affected.
A countdown on the leak site shows about five days left.
😁9💩3❤1
‼️ UPDATE: A Rotterdam court today ordered the ShinyHunters-suspect, 24-year-old convicted hacker Pepijn van der S., held for at least 90 more days.
Dutch police say the suspected ShinyHunters member's laptop held information about two murders planned abroad, with indications that he ordered them.
The suspicion of attempted incitement to murder is separate from the ShinyHunters case, and he was not arrested in the Odido hack investigation, police say.
https://www.politie.nl/nieuws/2026/september/29/11-verdachte-aangehouden-in-onderzoek-naar-hackersgroep-shinyhunters.html
Dutch police say the suspected ShinyHunters member's laptop held information about two murders planned abroad, with indications that he ordered them.
The suspicion of attempted incitement to murder is separate from the ShinyHunters case, and he was not arrested in the Odido hack investigation, police say.
https://www.politie.nl/nieuws/2026/september/29/11-verdachte-aangehouden-in-onderzoek-naar-hackersgroep-shinyhunters.html
🤣16❤2😢2
‼️ BREAKING: A newly released jailbreak cracks every PS5 firmware from 7.00 to 13.60, and early testers say it loads in seconds and works on the PS5 Pro too.
All it takes is visiting a website in the browser.
It chains a WebKit browser bug with a kernel use-after-free race to seize kernel read/write, then loads payloads for homebrew and game backups.
https://github.com/ntfargo/Relapse-Exploit
All it takes is visiting a website in the browser.
It chains a WebKit browser bug with a kernel use-after-free race to seize kernel read/write, then loads payloads for homebrew and game backups.
https://github.com/ntfargo/Relapse-Exploit
❤34🔥9🤯2
‼️ BREAKING: AI agents have leaked more than 13,000 internal screenshots from 343 tech companies onto GitHub, including a frontier AI lab and several Fortune 500 companies.
Unable to attach images to private pull requests, the agents quietly posted them to public repos instead.
https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies
Unable to attach images to private pull requests, the agents quietly posted them to public repos instead.
https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies
3🤣36🤔3❤2😁1🥴1
The CIA and West German intelligence secretly bought Swiss encryption maker Crypto AG in 1970, turning the machines governments paid to protect their secrets into a way to read them.
Those governments had no idea the machines were rigged to read their messages.
In the 1980s, Crypto devices accounted for roughly 40% of the foreign government messages the NSA decoded.
The CIA didn't sell the company until 2018 and called the operation "the intelligence coup of the century."
Those governments had no idea the machines were rigged to read their messages.
In the 1980s, Crypto devices accounted for roughly 40% of the foreign government messages the NSA decoded.
The CIA didn't sell the company until 2018 and called the operation "the intelligence coup of the century."
🤣18🔥7😁3🤯1💩1
In 2005, Sony BMG music CDs left Windows PCs less secure by secretly installing copy-protection software that hid itself using rootkit techniques.
The rootkit hid any file whose name began with $ SYS $, so malware writers soon gave their own files that prefix to stay invisible.
Sony's fix made it worse, as the web-based uninstaller it released could let any website download and run code on the PC.
A 2007 FTC settlement required Sony BMG to swap the CDs, offer removal tools and pay up to $150 to repair PCs damaged by removal attempts.
Mark Russinovich caught the rootkit with RootkitRevealer, a free tool he and Bryce Cogswell built to expose malware that hides from antivirus software.
It compares what Windows reports with the raw data on disk, so anything being cloaked shows up as a mismatch.
In late October 2005, a test version flagged cloaked files and registry keys on his own PC, which he traced to a Sony CD he'd bought, Van Zant's Get Right With the Man.
The license he'd accepted never mentioned the cloaking, and his Oct. 31 blog post exposing it blew the scandal open.
The rootkit hid any file whose name began with $ SYS $, so malware writers soon gave their own files that prefix to stay invisible.
Sony's fix made it worse, as the web-based uninstaller it released could let any website download and run code on the PC.
A 2007 FTC settlement required Sony BMG to swap the CDs, offer removal tools and pay up to $150 to repair PCs damaged by removal attempts.
Mark Russinovich caught the rootkit with RootkitRevealer, a free tool he and Bryce Cogswell built to expose malware that hides from antivirus software.
It compares what Windows reports with the raw data on disk, so anything being cloaked shows up as a mismatch.
In late October 2005, a test version flagged cloaked files and registry keys on his own PC, which he traced to a Sony CD he'd bought, Van Zant's Get Right With the Man.
The license he'd accepted never mentioned the cloaking, and his Oct. 31 blog post exposing it blew the scandal open.
🤣19❤3
❗️ A San Francisco hackathon rejected a former Israeli intelligence Unit 8200 engineer, telling him it didn't want Israel's military to make participants' pagers, phones and laptops "explode in their faces."
Organiser Mostapha Benhenda pointed to the 2024 pager attacks in Lebanon and later told the former Israeli intelligence member Adam Levi there was "no way to know" he wasn't involved.
Organiser Mostapha Benhenda pointed to the 2024 pager attacks in Lebanon and later told the former Israeli intelligence member Adam Levi there was "no way to know" he wasn't involved.
👏45🤣18😭9🥴3💩2😁1
❗️ The Dutch intelligence service AIVD is warning people not to hold confidential conversations in or near their cars, saying the microphones in many modern vehicles can technically be switched on remotely to eavesdrop.
Some state actors can request car data from carmakers and other companies or hack in to get it themselves, the agency says.
It advises skipping wireless charging and Bluetooth or Wi-Fi pairing, using a USB data blocker and not taking a car with an external camera to a sensitive location.
https://www.aivd.nl/actueel/nieuws/2026/09/30/digitale-dreigingen-in-slimme-voertuigen
Some state actors can request car data from carmakers and other companies or hack in to get it themselves, the agency says.
It advises skipping wireless charging and Bluetooth or Wi-Fi pairing, using a USB data blocker and not taking a car with an external camera to a sensitive location.
https://www.aivd.nl/actueel/nieuws/2026/09/30/digitale-dreigingen-in-slimme-voertuigen
❤15🤣8🤔5😁2