International Cyber Digest
6.31K subscribers
975 photos
52 videos
2 files
178 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
ServiceNow confirms a vulnerability let unauthorized actors query customers' instance tables. Customer instance data was directly accessible.
3🤣2
🚨 Meta has removed its controversial facial recognition code from its Meta AI smart glasses app within 48h after a WIRED report exposed it. The code could turn faces into biometric signatures to ID strangers in public.
💩202🔥1
‼️ Anthropic's recently released frontier model Fable 5 was jailbroken by someone using a jailbroken version of Claude Opus.

The researcher who goes by the moniker pliny carried out the jailbreak and says: "the consensus seems to be that this has been one of the most disappointing model drops of all time, effectively preventing legitimate researchers from contributing their talents to our collective advancement"

The jailbroken version can be used for research into and exploitation of vulnerabilities.
🔥82🥰2
‼️ Google is about to disable all adblocker extensions in Chrome. Instead of letting the adblocker inspect traffic itself, extensions now have to hand Google's browser a limited list of filtering rules and hope for the best. This leads to weaker blocking and more ads getting through.

Google makes the vast majority of its money selling ads. The company that profits from every ad you see also controls the browser most people use, with Chrome 149 being the last version supporting adblockers.

For example, under the new rules, uBlock Origin cannot exist. For millions of people, that extension is the only thing standing between them and a wall of ads, trackers, and autoplay garbage. One user put it bluntly: "The web is literally unusable without uBlock Origin."

https://github.com/w3c/webextensions/issues/1000
💩363😁1
🚨 GitHub moves against npm supply chain attacks. npm v12 ships next month and stops executing preinstall/install/postinstall scripts from dependencies by default. Git and remote URL dependencies get blocked by default too.

Source: https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/
👍9🤬21🔥1👏1🤔1
❗️ That '$200 sub burns $14,000 of compute' chart measures the ceiling of the ceiling. An unrealistic scenario,where every step re-reads the full context and single tasks chew through millions of tokens.

And you don't have to take my word for it. The companies already told us how this works.

Anthropic confirmed the skew: its weekly limits target users running Claude Code 24/7, affecting less than 5% of subscribers. The light majority covers the heavy few. And when Max users exceed the cap, overflow is sold at standard API rates. The subsidy ends exactly where the average ends.

Altman admitted OpenAI was losing money on $200 Pro subs: 'people use it much more than we expected.' He set the price himself expecting profit. That is gym pricing, priced on the average user.

Meanwhile the enterprise tier buys what consumers never get: no training on inputs by contract, SLAs, stable limits, compliance paperwork. Consumer plans often train on chats by default, and agentic coding traces are the most valuable training data in the industry. Today's heavy user builds the model enterprises buy tomorrow at full rate.
🤯51🔥1😢1
‼️🚨 Unauthenticated attackers are gaining SYSTEM on domain controllers with crafted packets.

The vulnerability being exploited is CVE-2026-41089, a CVSS 9.8 hole in Windows Netlogon, and exploitation in the wild has been confirmed.

A patch has existed since May 12. Every DC still behind is not just vulnerable, but according to the Centre for Cybersecurity Belgium are also actively being pwnd.
😁3🔥1
‼️🚨 MAJOR OPSEC FAIL by controversial Israeli spyware company NSO Group. They uploaded an image of a desktop mat displaying their own company's logo.

WhatsApp court documents show the group created test accounts and groups on WhatsApp, despite receiving a permanent injunction that barred them from ever targeting WhatsApp and its users.
👏14🔥3😁3
‼️🚨 BREAKING: Nightmare Eclipse just dropped GreatXML, a new BitLocker bypass 0-day vulnerability PoC.

He has a new GitHub account. Check it out before it gets deleted again: https://github.com/MSNightmare
👍14🔥3👏32
🚨 BREAKING: More than 400 Arch Linux User Repository packages have been compromised with infostealer malware and a rootkit.

Attacker posed as a trusted maintainer and "adopted" orphaned packages.

Arch maintainers are purging infected packages now. Audit your AUR installs.

https://discourse.ifin.network/t/400-aur-packages-compromised-with-infostealer-and-rootkit/577
😭18🤣6😁2🥴1