International Cyber Digest
6.28K subscribers
955 photos
52 videos
2 files
175 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
β€ΌοΈπŸš¨ This is really bad. According to our research, at least one of Brazil's government IT workers was infected with an infostealer. We found:

- He was doing goverment infrastructure work on his home RGB gaming PC
- He was running Windows 7 (EoL Jan 2020)
- No antivirus
- NO MFA for some critical infra
- His browser held gov VPN creds for himself and two colleagues (they were using each others creds?)
- Search history includes "ativar windows 10," "download office 2019 + ativador," "comprar office 365," and "download mobaxterm cracked"
- Malware dropped via malicious game installer
- The keys to his password managers were in the stolen browser: a LastPass account and a keypass[.]mdr[.]gov[.]br vault
- Exposed: VPN, GitLab, Jenkins, webmail, SSO, M365, and dev/staging environments across mec[.]gov[.]br and mdr[.]gov[.]br
1🀣30πŸ‘7❀3πŸ”₯1
‼️ Just in: FortiBleed attackers rented 36 enterprise GPUs from an AI cloud provider to crack stolen FortiGate configuration hashes at industrial scale.

Cheap, on-demand GPU compute has quietly made mass password cracking easy, while tens of thousands of organisations still run VPN firewalls with no MFA. The threat is now less likely a nation-state and more like a financially motivated crew with a credit card and rented hardware in the cloud.

A write-up by Kevin Beaumont shines a light on the campaign that cracked credentials for tens of thousands of Fortinet firewalls.

He disputes Fortinet's public line that the data is just old breaches and bruteforcing, noting it contains freshly cracked passwords and that every organisation he helped had its config exported in the past month. In those cases the attacker went well beyond collecting credentials, adding admin accounts, opening SSH and RDP firewall rules, and logging into IPsec tunnels, with CloudSEK assessing around a thousand organisations breached internally and the attacker reaching internal Active Directory at a number of telcos and managed service providers.

https://doublepulsar.com/an-update-on-fortibleed-whats-happening-with-victim-orgs-c0671a50e7f4
❀11πŸ”₯5
‼️ A Chrome extension called Volume Booster, with roughly 2 million weekly users, activated a commerce-tracking SDK across its entire base without ever prompting for consent.

The trick: a broad all-sites permission was granted in an earlier version and left unused, then a later update switched on the Give Freely affiliate SDK without requesting any new permission, so Chrome shipped it silently.

The SDK registers a persistent device ID, geolocates users by IP, and sends telemetry continuously, while the store's privacy declaration still claims no data collection beyond core functionality.

A broad permission granted early and activated later via a prompt-free update is a detectable supply-chain signal.

https://malext.io/reports/QuietBoost/
😱10❀2😁2🀯2πŸ”₯1🀣1
Day 1 of fighting the European heatwave.
😭14πŸ€”9🀣6πŸ€ͺ2πŸ₯°1πŸŽ‰1
WTF is wrong with the EU? πŸ‡ͺπŸ‡Ί

No frontier lab to its name, nothing in OpenAI or Anthropic's weight class, and yet Brussels is first in line to regulate and label the thing it can't build.

The Commission just finalized its Code of Practice on labelling AI-generated content. Voluntary code, but the EU AI Act rules behind it go binding August 2, 2026: providers must watermark AI output in machine-readable form, deployers must label deepfakes and disclose chatbots.

Europe can't win the race, so it's writing the rulebook for everyone who can.
🀣14πŸ‘4❀3πŸŽ‰2πŸ€ͺ1
β—οΈπŸ‡¬πŸ‡§ Two members of the Scattered Spider hacking group have pleaded guilty to the 2024 cyber attack on Transport for London, the NCA confirmed today. Thalha Jubair, 20, and Owen Flowers, 18, changed their pleas on the first day of trial at Woolwich Crown Court.

The attack cost TfL a reported Β£29 million, forced all 28,000 staff to show up in person for password resets, exposed Oyster refund data, and shut the photocard system for children and young people. One detail stands out: Flowers recorded videos of Jubair breaking into TfL systems as it happened.

Investigators say they also found evidence the pair hit US healthcare firms Sutter Health and SSM Health. Sentencing is set for 16 July.
🀣9❀5πŸ₯°1
β€ΌοΈπŸš¨ BREAKING: CONFIDENTIAL DOCUMENTS OF APPLE AND TESLA HAVE BEEN LEAKED.

Tata Electronics, which builds about a third of Apple's iPhones in India, has confirmed a cyberattack after the extortion group World Leaks posted what it claims are confidential Apple and Tesla files β€” more than 204,000 documents totalling 630+ GB.

We reviewed the leak. The files carry Apple's confidential and proprietary footers and Tesla trade-secret markings, and include iPhone circuit board inspection specs, factory data, and employee passport scans. There are tons of e-mails as well, plus files belonging to other Tata Electronics customers.

Tata says operations are unaffected and has received a ransom demand.
πŸ‘13πŸ’©9πŸ‘2πŸ”₯2😁2😱1πŸ₯΄1😨1
β€ΌοΈπŸš¨ Critical remote code execution in libssh2, the SSH client library embedded in countless tools: CVE-2026-55200, rated CVSS 9.2 by VulnCheck. Every version up to and including 1.11.1 is affected.

It's an out-of-bounds heap write in ssh2_transport_read(), which fails to bound-check the SSH packet_length field. A malicious or MITM'd SSH server can send oversized packets to corrupt memory and run code on the connecting client.

No known exploitation yet and it's not in CISA's KEV. Fix: move to a build that includes commit 7acf3df (PR #2052), and inventory anything that links libssh2 for SSH, SCP, or SFTP.
πŸ”₯6❀3πŸ₯΄2
Media is too big
VIEW IN TELEGRAM
🐧 Linus Torvalds gets angry when people say 99% of our code is written by AI, he told the audience at the Open Source Summit.
πŸ‘9❀3
‼️The new Intel Arc G3 has nearly double the performance per watt of its predecessor.

Unfortunately, due to chip shortages, the price has also nearly doubled. At around $1,800, it will make most people reluctant to buy one.
🀣10
β€ΌοΈπŸš¨BREAKING: Meta has stopped its controversial employee-tracking program for training AI after an internal exposure left all the collected data accessible across the company, including keystrokes, screen contents, full AI prompts, transcripts, private conversations, and performance records, collected from US employees' laptops since April.

An internal notice put the scope at 45,000 internal tables. CTO Andrew Bosworth blamed misconfigured access control lists. Meta says it has no indication the data was improperly accessed.

Months earlier, Bosworth had told worried staff the program was "tightly controlled." More than 1,600 employees had already signed a petition warning of exactly this kind of security and regulatory risk.
😭10πŸ’©7😁2πŸ₯΄2
‼️ Claude Fable 5 wrote a booting, NT-shaped Rust kernel in 38 minutes, with later work on Claude Opus growing it to run real Windows binaries.

Security startup Tolmo published a transcript-level account of Claude Fable 5 writing a booting, NT-shaped kernel in Rust from an empty directory in 38 minutes of active model work.

By the company's account it built the trusted computing base, booted in an emulator, passed its own self-tests, and root-caused its own low-level bugs, then over 8 more days, mostly on Claude Opus 4.8, grew to load unmodified Windows drivers and run real Windows binaries.

https://tolmo.com/blog/when-the-model-writes-the-kernel/
πŸ”₯10πŸ‘2😱2πŸ’©1