International Cyber Digest
7.94K subscribers
1.55K photos
79 videos
2 files
313 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
The CIA and West German intelligence secretly bought Swiss encryption maker Crypto AG in 1970, turning the machines governments paid to protect their secrets into a way to read them.

Those governments had no idea the machines were rigged to read their messages.

In the 1980s, Crypto devices accounted for roughly 40% of the foreign government messages the NSA decoded.

The CIA didn't sell the company until 2018 and called the operation "the intelligence coup of the century."
🤣18🔥7😁3🤯1💩1
In 2005, Sony BMG music CDs left Windows PCs less secure by secretly installing copy-protection software that hid itself using rootkit techniques.

The rootkit hid any file whose name began with $ SYS $, so malware writers soon gave their own files that prefix to stay invisible.

Sony's fix made it worse, as the web-based uninstaller it released could let any website download and run code on the PC.

A 2007 FTC settlement required Sony BMG to swap the CDs, offer removal tools and pay up to $150 to repair PCs damaged by removal attempts.

Mark Russinovich caught the rootkit with RootkitRevealer, a free tool he and Bryce Cogswell built to expose malware that hides from antivirus software.

It compares what Windows reports with the raw data on disk, so anything being cloaked shows up as a mismatch.

In late October 2005, a test version flagged cloaked files and registry keys on his own PC, which he traced to a Sony CD he'd bought, Van Zant's Get Right With the Man.

The license he'd accepted never mentioned the cloaking, and his Oct. 31 blog post exposing it blew the scandal open.
🤣19❤3
❗️ A San Francisco hackathon rejected a former Israeli intelligence Unit 8200 engineer, telling him it didn't want Israel's military to make participants' pagers, phones and laptops "explode in their faces."

Organiser Mostapha Benhenda pointed to the 2024 pager attacks in Lebanon and later told the former Israeli intelligence member Adam Levi there was "no way to know" he wasn't involved.
👏44🤣18😭9🥴3💩2😁1
❗️ The Dutch intelligence service AIVD is warning people not to hold confidential conversations in or near their cars, saying the microphones in many modern vehicles can technically be switched on remotely to eavesdrop.

Some state actors can request car data from carmakers and other companies or hack in to get it themselves, the agency says.

It advises skipping wireless charging and Bluetooth or Wi-Fi pairing, using a USB data blocker and not taking a car with an external camera to a sensitive location.

https://www.aivd.nl/actueel/nieuws/2026/09/30/digitale-dreigingen-in-slimme-voertuigen
❤14🤣8🤔5😁2
‼️ BREAKING: DeepSeek is building software for Huawei's AI chips to break its dependence on Nvidia, open-sourcing six core tools that take direct aim at CUDA.

Huawei backed the project, which adapts TileLang, a coding language DeepSeek calls simpler than Nvidia's CUDA, for Huawei's Ascend 950 AI chips.

https://mp.weixin.qq.com/s/X41mKH4Ds-VXUAnK6M8Eww
🔥28🤔8👏2
We need Super Intelligence ASAP.
😁30💩13🔥1
‼️ Dutch vulnerability hunters DIVD say attackers breached their systems on 21 September using two zero-days in Zammad, the open-source helpdesk platform.

One lets a Zammad user execute code on the server. The other escalates to root and, per DIVD, affects all Zammad versions. A full fix is not yet available.

DIVD believes AI agents carried out the attack.

https://csirt.divd.nl/cases/DIVD-2026-00015/
🤣12🤯4❤1😁1
❗️ More than half a million credentials leaked on GitHub turned out to still work, and the oldest was committed 17 years ago.

Researchers found 543,699 of them across 224 million public repos, where the median working secret was 784 days old.

npm revokes leaked tokens, so just 1 of 101,886 still worked. Of 126,963 leaked Google Cloud service account credentials, more than half still did.

Link to article: https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them
😁7😱4💩2
❗️ Amazon is giving its delivery drivers smart glasses that snap photos almost constantly to help its AI map neighbourhoods, capturing people and private property across potentially several thousand images per shift.

Asked whether customers can opt out, Amazon's Viraj Chatterjee said, "We haven't thought about that."

Amazon wants 20,000+ pairs on routes by end-2027 and confirmed the images can be obtained with a warrant.
💩48🤪2
❗️ Tech site Android Central's entire staff has been fired because of the rise of AI chatbots.

Several staff confirmed their exit on LinkedIn.

Owner Future plc hasn't commented, and the site is still online.

Google search traffic was falling faster than expected as people transitioned to AI, which led to fewer clicks to their website.
😭22🔥2💩2
‼️ BREAKING: A China-aligned espionage group sent phishing lures to US AI policy experts while posing as a senior Anthropic employee and as Lynne Parker, the former top deputy at the White House science office, Proofpoint says.

One lure arrived with the subject line "Request for Feedback on Military Integration of Claude."

Tracked as TA419, the group used fake OneDrive pages built to hijack Microsoft 365 sessions and bypass MFA.

https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy
❤4🔥4😁2🥰1💩1