International Cyber Digest
6.3K subscribers
959 photos
52 videos
2 files
176 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
‼️ Trump mocked Zuckerberg and Bezos behind their backs, flashing their "kissing my ass" texts to guests. In a conversation with Elon Musk, Trump said of the pair, "They hated me... look at them now," and Musk replied, "First-class groveling."

Bezos allegedly trashed his own Washington Post to Trump too, calling it one of his worst investments and the staff "terrible."

From the forthcoming Haberman and Swan book Regime Change, obtained by WIRED ahead of its June 23 release.
🤣16💩3
‼️🚨 BREAKING: A breach at competitive-intelligence platform Klue let attackers steal OAuth tokens and pull Salesforce CRM data from multiple customers, with Huntress, Recorded Future, Tanium and Jamf disclosing impact.

The new extortion group Icarus is already emailing victims demanding contact within 48 hours, and Salesforce has disabled the Klue Battlecards integration.

Links:
https://huntress.com/blog/klue-breach-investigation

https://klue.com/blog/an-update-on-recent-klue-security-incidentklue%20battlecard
🥰4😭4
Media is too big
VIEW IN TELEGRAM
‼️U.S. Commerce Secretary Lutnick is concerned one of ASML's lithography chipmaking machines may have ended up in China.

ASML's extreme ultraviolet lithography machines cost around $370 million and take multiple 747s to transport.

ASML denies the allegation, saying it has never shipped an EUV machine to China.
🔥10🥰3💩1
❗️💿 A man got criminally convicted in 2026 for pirating CDs. Physical CDs. Burned on a laptop and sold on eBay.

Marc Kearns, 47, aka DJ Marc Landish, ran the operation for five years and pulled in £220,979 selling copyright-infringing discs on eBay, Facebook and his own site. His defense was that he thought copyright was only a civil matter. Hull Crown Court disagreed.

The judge noted Kearns had pirated other artists' work but went after someone for copying his own, calling it "hypocrisy of the highest order." He avoided jail: suspended sentence, 250 hours unpaid work, £21,885 costs.
🤣194🔥3👏2😁2🤔1💯1
‼️🚨 A hacker breached Brazil's national emergency alert system, and woke up everyone by pushing a fake "Extreme Alert" reading "misantropi4" to phones across São Paulo, Rio, Brasília and other states, overriding silent mode in the middle of the night.

Telecoms regulator Anatel pulled the national warning platform offline and the Federal Police are investigating what officials call a probable remote intrusion into Brazil's critical public-warning infrastructure.
1🤣18👏54
‼️🇳🇴 Norway bans the use of AI in primary schools due to declining school results.

A new national recommendation says pupils should largely not use AI in schoolwork. The government's reasoning is sequencing: kids need to master reading, writing and arithmetic first, and it says research shows uncritical use of generative AI lets them skip the hard parts of learning.

The backdrop is a years-long slide in basic skills. The government cites data showing one in four Norwegian pupils now reads below the minimum level, and says it won't repeat the mistake of rushing digital devices onto young children.
👏284🤣4💩2
‼️🚨 This is really bad. According to our research, at least one of Brazil's government IT workers was infected with an infostealer. We found:

- He was doing goverment infrastructure work on his home RGB gaming PC
- He was running Windows 7 (EoL Jan 2020)
- No antivirus
- NO MFA for some critical infra
- His browser held gov VPN creds for himself and two colleagues (they were using each others creds?)
- Search history includes "ativar windows 10," "download office 2019 + ativador," "comprar office 365," and "download mobaxterm cracked"
- Malware dropped via malicious game installer
- The keys to his password managers were in the stolen browser: a LastPass account and a keypass[.]mdr[.]gov[.]br vault
- Exposed: VPN, GitLab, Jenkins, webmail, SSO, M365, and dev/staging environments across mec[.]gov[.]br and mdr[.]gov[.]br
1🤣30👍73🔥1
‼️ Just in: FortiBleed attackers rented 36 enterprise GPUs from an AI cloud provider to crack stolen FortiGate configuration hashes at industrial scale.

Cheap, on-demand GPU compute has quietly made mass password cracking easy, while tens of thousands of organisations still run VPN firewalls with no MFA. The threat is now less likely a nation-state and more like a financially motivated crew with a credit card and rented hardware in the cloud.

A write-up by Kevin Beaumont shines a light on the campaign that cracked credentials for tens of thousands of Fortinet firewalls.

He disputes Fortinet's public line that the data is just old breaches and bruteforcing, noting it contains freshly cracked passwords and that every organisation he helped had its config exported in the past month. In those cases the attacker went well beyond collecting credentials, adding admin accounts, opening SSH and RDP firewall rules, and logging into IPsec tunnels, with CloudSEK assessing around a thousand organisations breached internally and the attacker reaching internal Active Directory at a number of telcos and managed service providers.

https://doublepulsar.com/an-update-on-fortibleed-whats-happening-with-victim-orgs-c0671a50e7f4
11🔥5
‼️ A Chrome extension called Volume Booster, with roughly 2 million weekly users, activated a commerce-tracking SDK across its entire base without ever prompting for consent.

The trick: a broad all-sites permission was granted in an earlier version and left unused, then a later update switched on the Give Freely affiliate SDK without requesting any new permission, so Chrome shipped it silently.

The SDK registers a persistent device ID, geolocates users by IP, and sends telemetry continuously, while the store's privacy declaration still claims no data collection beyond core functionality.

A broad permission granted early and activated later via a prompt-free update is a detectable supply-chain signal.

https://malext.io/reports/QuietBoost/
😱102😁2🤯2🔥1🤣1
Day 1 of fighting the European heatwave.
😭14🤔9🤣6🤪2🥰1🎉1
WTF is wrong with the EU? 🇪🇺

No frontier lab to its name, nothing in OpenAI or Anthropic's weight class, and yet Brussels is first in line to regulate and label the thing it can't build.

The Commission just finalized its Code of Practice on labelling AI-generated content. Voluntary code, but the EU AI Act rules behind it go binding August 2, 2026: providers must watermark AI output in machine-readable form, deployers must label deepfakes and disclose chatbots.

Europe can't win the race, so it's writing the rulebook for everyone who can.
🤣14👏43🎉2🤪1
❗️🇬🇧 Two members of the Scattered Spider hacking group have pleaded guilty to the 2024 cyber attack on Transport for London, the NCA confirmed today. Thalha Jubair, 20, and Owen Flowers, 18, changed their pleas on the first day of trial at Woolwich Crown Court.

The attack cost TfL a reported £29 million, forced all 28,000 staff to show up in person for password resets, exposed Oyster refund data, and shut the photocard system for children and young people. One detail stands out: Flowers recorded videos of Jubair breaking into TfL systems as it happened.

Investigators say they also found evidence the pair hit US healthcare firms Sutter Health and SSM Health. Sentencing is set for 16 July.
🤣95🥰1