International Cyber Digest
6.31K subscribers
973 photos
52 videos
2 files
177 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
🚨 BREAKING: More than 400 Arch Linux User Repository packages have been compromised with infostealer malware and a rootkit.

Attacker posed as a trusted maintainer and "adopted" orphaned packages.

Arch maintainers are purging infected packages now. Audit your AUR installs.

https://discourse.ifin.network/t/400-aur-packages-compromised-with-infostealer-and-rootkit/577
😭18🀣6😁2πŸ₯΄1
β€ΌοΈπŸš¨ BrEaKiNg: Nintendo has allegedly been breached by a threat actor. They've published some data as evidence.

Our preliminary analysis shows this ain't Nintendo being breached, but they've had access to a Nintendo USA tenant on TINYpulse by WebMD, which is an employee feedback and engagement software solution.

The data includes some sensitive stuff, like employees giving feedback on their employer. The data confirms: Nintendo employees are happy at work.

End of story, everybody loves a happy ending.
🀣14😁6😭3❀1
Media is too big
VIEW IN TELEGRAM
This is awesome. These fellas build drones they fly into tornadoes for science.

They're part of the OTUS Project, a self-funded effort founded by students in meteorology and engineering. They build custom UAVs and sensor systems to study tornadoes inside and out.

The goal is to protect lives and property. The wind and thermodynamic data they collect feeds into predictive models, sharpens hazard forecasting, and helps make structures more resilient.

https://www.theotusproject.com/
πŸ”₯9πŸ₯°3😁1
🚨 BrEaKiNg: Splunk, a security product, has zero authentication in its built-in database service and accepts any credentials, according to the security researchers who just dropped a full pre-auth RCE chain for Splunk Enterprise (CVE-2026-20253, CVSS 9.8).

Splunk Enterprise on AWS is vulnerable out of the box.

https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/
πŸ”₯3πŸ₯°2❀1πŸ€ͺ1
β€ΌοΈπŸš¨ BREAKING: Amazon researchers snitched to the US government about jailbreaking Fable 5 and Mythos 5, forcing Anthropic to immediately shut down worldwide access.

A security export control directive from Commerce Secretary Howard Lutnick enforced the action.

Anthropic is fighting the directive and calls it a misunderstanding.

This isn't the first clash. The Trump administration had already tried to get Anthropic to pause the release of its latest models before this directive landed.
πŸ’©14🀯3πŸ‘1
‼️The ban on foreign use of Anthropic's frontier models, might also cripple the development of USA's next-gen models.

Anthropic's stated the order suspends access by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees.
🀯7❀3πŸ”₯1
This media is not supported in your browser
VIEW IN TELEGRAM
Europeans after hearing they can’t use Anthropic’s AI models anymore.
😁15πŸ‘3🀣3❀2😒2πŸ’―1
Dear US government,

Since you've just blocked Fable and Mythos on critical national security grounds, here are some other tools that pose a similar threat to the American people:

- Microsoft Teams
- LinkedIn
- Fortinet
- Salesforce
- Jira
- Outlook
- AWS

Please do what you must to save America πŸ‡ΊπŸ‡Έ
❀47🀣35πŸ₯°6😁2πŸ”₯1πŸ‘1
‼️ This was Trump's power play all along. Before the Mythos/Fable ban, Amazon was responding to his administration's request for feedback when it reported Anthropic to the government. The administration then tried to reach Amodei, but according to officials he was unavailable, attending a wellness retreat. Anthropic says "this is absolutely false."

https://www.politico.com/news/2026/06/13/inside-the-whirlwind-24-hours-that-led-the-white-house-to-slap-export-controls-on-anthropic-00961519
πŸ’©11πŸ‘1
Media is too big
VIEW IN TELEGRAM
❗️ Imagine a whole town built just to fight cybercrime. The FBI's Kinetic Cyber Range in Huntsville, Alabama is a 22,000-sq-ft fully furnished replica of a small U.S. community. Houses, a hospital, a courthouse, a power plant, and even a data center with more than 200 physical servers.

The range lets trainees face the same devices, networks, and operational constraints they'll hit in the field, from cramped server rooms to hospital systems that could go dark in an emergency.
❀8πŸ”₯5🀣2πŸŽ‰1
Claude Fable 5 torrent MalwareZ
πŸ”₯15πŸ’©8🀣8πŸ’―3πŸ‘1
❗️ Microsoft's CEO Satya Guevara is pleading for socialism in AI. His pitch: companies should build a 'frontier ecosystem', not a 'frontier model', so the gains spread broadly instead of pooling inside a few labs.

Without it, AI repeats the first wave of globalisation, where outsourcing hollowed out entire industrial economies and left the damage behind.

The timing is what makes it interesting. The plea lands one day after the Trump administration's power play on Anthropic, which forced the company to disable Fable 5 and Mythos 5.

That is the thread Satya never pulls. He builds an entire case about who captures AI's value, then steps around the national security fight playing out next door. The omission seems deliberate. You don't pick a fight with the Trump administration right when it's reminding everyone who is boss.

https://x.com/satyanadella/status/2066182223213293753
🀣7❀2
β€ΌοΈπŸš¨ Breaking: Hackers are pushing troll messages to Arch Linux users as the drama continues, and maintainers just pushed a deletion request for the malicious package. We decoded the messages:

"you're an idiot using a crap distro, install PIP, don't use AUR for fools; be thankful I didn't add actual malware, only a console reminder,"
"I use Windows,"
"happy pride month,"
"new Albanian virus from Russia,"
❀9🀣8πŸ’©5
🚨 The Council of Europe has allegedly been breached. Over 297 GB of HR and payroll data, more than 429,000 files, has been compromised.

It marks the second major hit on European institutions this year. In March, the EU Commission, ENISA, and the Directorate-General for Digital Services were breached.
🀣15πŸ₯°1
❗️ The hype says frontier models like Mythos will soon find and exploit vulnerabilities at scale. That future is real, but it skips over the present.

The capability is not waiting on a frontier model. With the right setup, the models already in wide use are doing this work today.

Start at the top end. Anthropic disrupted what it called the first AI-orchestrated espionage campaign, run by a group it assessed as Chinese state-sponsored, where the attackers turned Claude Code into the operator and ran an estimated 90% of the tactical steps against roughly thirty global targets.

It is not only nation states. One threat report describes a lone actor who jailbroke a mainstream model and used it to breach Mexican government systems, allegedly walking off with around 150GB of taxpayer and voter records.

The skill bar is collapsing at the same time. A UK-based seller with no real technical ability reportedly used AI to generate ransomware and sold each build for a few hundred dollars.

The aggregate numbers match the anecdotes. Over the past year, AI-assisted actors grew from a third of high-risk cyber cases to more than half, and most of those flagged used AI to help build malware.

The defenders' own data agrees. The 2026 Verizon DBIR ranked software vulnerabilities above stolen credentials as the top breach entry point for the first time in nearly two decades, and CrowdStrike clocked average breakout time at 29 minutes.

Frontier models like Mythos raise the ceiling on what is possible. They did not build the floor adversaries are already walking on.
❀9πŸ”₯1