International Cyber Digest
6.3K subscribers
961 photos
52 videos
2 files
177 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
‼️🚨 Critical remote code execution in libssh2, the SSH client library embedded in countless tools: CVE-2026-55200, rated CVSS 9.2 by VulnCheck. Every version up to and including 1.11.1 is affected.

It's an out-of-bounds heap write in ssh2_transport_read(), which fails to bound-check the SSH packet_length field. A malicious or MITM'd SSH server can send oversized packets to corrupt memory and run code on the connecting client.

No known exploitation yet and it's not in CISA's KEV. Fix: move to a build that includes commit 7acf3df (PR #2052), and inventory anything that links libssh2 for SSH, SCP, or SFTP.
🔥63🥴2
Media is too big
VIEW IN TELEGRAM
🐧 Linus Torvalds gets angry when people say 99% of our code is written by AI, he told the audience at the Open Source Summit.
👍93
‼️The new Intel Arc G3 has nearly double the performance per watt of its predecessor.

Unfortunately, due to chip shortages, the price has also nearly doubled. At around $1,800, it will make most people reluctant to buy one.
🤣10
‼️🚨BREAKING: Meta has stopped its controversial employee-tracking program for training AI after an internal exposure left all the collected data accessible across the company, including keystrokes, screen contents, full AI prompts, transcripts, private conversations, and performance records, collected from US employees' laptops since April.

An internal notice put the scope at 45,000 internal tables. CTO Andrew Bosworth blamed misconfigured access control lists. Meta says it has no indication the data was improperly accessed.

Months earlier, Bosworth had told worried staff the program was "tightly controlled." More than 1,600 employees had already signed a petition warning of exactly this kind of security and regulatory risk.
😭10💩7😁2🥴2
‼️ Claude Fable 5 wrote a booting, NT-shaped Rust kernel in 38 minutes, with later work on Claude Opus growing it to run real Windows binaries.

Security startup Tolmo published a transcript-level account of Claude Fable 5 writing a booting, NT-shaped kernel in Rust from an empty directory in 38 minutes of active model work.

By the company's account it built the trusted computing base, booted in an emulator, passed its own self-tests, and root-caused its own low-level bugs, then over 8 more days, mostly on Claude Opus 4.8, grew to load unmodified Windows drivers and run real Windows binaries.

https://tolmo.com/blog/when-the-model-writes-the-kernel/
🔥10👏2😱2💩1
‼️🚨 A nationwide failure of the German train radio system just brought Deutsche Bahn's entire network to a standstill, halting long-distance, regional, and S-Bahn services across Germany, including every Berlin S-Bahn line.

The cause is not yet known. DB CEO Evelyn Palla told Bild the company doesn't know what happened. Trains were held at or sent to the nearest station because, without working radio, drivers and dispatchers can't reliably exchange emergency stop signals, making running unsafe.

It's a decades-old radio system, which also carries train-control signaling data, taking down a whole country's rail traffic. A similar GSM-R outage halted northern Germany in October 2022 after fiber cables were cut. No attack has been confirmed this time.
🤔9🤣2👏1
A legal study commissioned by the Dutch government has concluded that forcing universal age verification on all users would be disproportionate and clash with the fundamental rights of both children and adults.

The researchers, at the University of Amsterdam, say privacy and freedom of information are at stake, that even the strictest checks are easily bypassed with VPNs or an adult's help, and that the EU's Digital Services Act already requires platforms to make age assurance effective, so rushing to mandate more is risky.

This matters because the Dutch coalition wants a European minimum age of 15 with "privacy-friendly" verification. The study is a caution to every government treating ID checks as the fix, the same fight is playing out in many countries right now.
🔥15💯3😱21🤯1
Huntress appears to have an insider problem. According to one of its ex-employees, an insider passed communications from US law enforcement to a threat actor called "Devman."

The ex-employee, a former Security Analyst, says he resigned over it. He claims that with an IPO on the horizon, Huntress prioritized keeping the incident away from the press rather than disclosing it. He also says the threat actor has been targeting him and his family, and that the company's legal director tried to silence him with legal threats.

He says he will publish his supporting evidence over the next two weeks, including FBI communications, more than four hours of recorded calls, and internal escalations raised weeks before the insider was caught.
😱10🔥1🥰1🤔1🤪1
🇪🇺 European Parliament President Roberta Metsola is trying to push through "chat control" despite her own Parliament voting it down.

Parliament killed it 311 to 228 in March.

In a document seen by Politico, Metsola has invited EU member states in the Council to adopt a first-reading position on the lapsed regulation that lets platforms voluntarily scan for child sexual abuse material (CSAM).

Cyprus, which currently chairs the Council, has put the request to member-state ambassadors for Friday, while admitting in its own note there is no precedent for what is being asked.

Privacy campaigners say the scanning opens the door to mass surveillance and the end of encryption. Reviving a rejected bill through the Council also tests how far one EU institution can route around another's vote.

Source: https://www.politico.eu/article/president-vs-parliament-roberta-metsola-overrides-meps-bid-force-child-abuse-law/
😭9🥰2💩21🤬1🤣1
Google just avoided the next big social-media-harms trial by settling with a 15-year-old Black teen in Florida.

YouTube and Google reached a confidential settlement with the teen plaintiff in the second bellwether case over platform harm to minors, leaving Meta, TikTok and Snap to face a July 27 trial in California.

It's the second of nearly 2,500 consolidated claims. Plaintiffs have gotten past Section 230 of the Communications Decency Act by targeting design features (infinite scroll, autoplay, filters) rather than content.

If the remaining bellwether verdicts land for the plaintiffs, they could anchor a global settlement that plaintiffs' lawyers put in the tens of billions.
🤪4😁1
Media is too big
VIEW IN TELEGRAM
🇪🇸 Spain's PM unveils proposals to censor the internet and gut free speech protections.
🤬14💩4🥰1
ApPLe HiKeS PrIcEs.
🤣19💩7😭3😱2👍1
Great use of AI: Bellingcat just published how it used machine learning to surface and document civilian-harm posts on Telegram, and open-sourced the notebook.

In Bellingcat's tests, one of the strongest signals that a post showed civilian harm was the number of crying-face 😭 reactions on it.

Bellingcat ranks posts by how likely they are to show civilian harm, cutting search time so researchers can spend their hours verifying instead of scrolling. It was tested on Bellingcat's Ukraine work, which has logged 2,500+ geolocated incidents since 2022.

Source: https://www.bellingcat.com/resources/2026/06/25/how-to-use-ai-to-help-find-civilian-harm-conflict-report-monitor-war-machine-learning-telegram/
😭142🤔2👍1👏1🥴1