International Cyber Digest
6.83K subscribers
1.2K photos
60 videos
2 files
218 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
❗️ Y Combinator has told flight startup Soar to strip the YC logo off an ad truck in San Francisco.

The screens read "scan for instant acceptance into" beside YC's logo. Scanning it opened the flight website and a $50 flight credit.

YC legal chief Carolynn Levy told the founder he has no permission to use the mark and demanded written confirmation the same day.
🔥4
The official access point of the X reply section.
😭15🤣11💩3💯2😁1🤬1
‼️ BREAKING: More than 100,000 UK police officers and staff have had their full names, contact details and force locations leaked on the dark web after a hack on the national police legal database.

MoD, Home Office, NCA and CPS staff are also exposed. One officer says the leak "puts officers at serious risk."
🤣22🥰43🙏2👏1😭1
‼️ UPDATE: Arch Linux has now disabled ALL pushes to the Arch User Repository (AUR) as it fights malware.

No AUR package can be updated while the team hunts malicious commits.
😁10🤔4🔥2💯2
❗️ The slopocalypse is real. MITRE published a critical SQLite vulnerability with a CVSS of 10.0 that does not exist. Turns out it was hallucinated by an LLM. SQLite's Richard Hipp says dozens more fake CVEs were filed.

CVE-2026-51302 was assigned on 27 July. CISA's enrichment programme then scored it critical and flagged a public proof-of-concept. The Dutch National Cyber Security Center republished it as an advisory, and has now withdrawn it, saying the "vulnerability" was most likely hallucinated by an LLM.
8🤪2
❗️Great news for Linux enthusiasts: Linux crossed 10% of North American desktop traffic for the first time, 10.65% last month.

That's over 3.5x its 2.94% in April, per StatCounter.
25🔥3🥰2🤣1
❗️China's CXMT wants to solve the DRAM crisis by opening a second memory fab in Beijing and is in early talks with the state-backed development zone over funding.

Its current projects alone would double output to 600,000+ wafers a month. Beijing's memory fab would come on top of that — as international DRAM prices keep climbing.

For comparison, the three biggest players' capacity this year (per month):
Samsung 720k wafers
SK hynix 550k wafers
Micron 375k wafers
🔥19👏8💩3😁2
❗️Apple pulled Telegram from the App Store last night after its review found child sexual abuse material in the app. Telegram says Apple flagged one user, who was banned immediately. The billion-user app was back the same night.

Telegram's reply to Apple: "I'm sure this stance will be applied equally to all other apps in the store, in the future right?"

Telegram says it has banned more than 300,000 CSAM-related groups and channels this year.
😱9🤣5👍2🤬1
❗️Under a secret order, the UK wants Apple to build a backdoor into its encrypted iCloud backups. Apple is refusing, and fighting it in court.

Britain's first attempt covered Americans' data too. Washington pushed back, and it was withdrawn — then the Home Office issued a new one, narrowed to UK users only. Apple filed against it at the Investigatory Powers Tribunal last month.

Britons have had no Advanced Data Protection since February 2025: the opt-in setting that end-to-end encrypts iCloud photos, notes and backups. Apple pulled it rather than comply.

By Apple's own account, UK users are now the only ones in the world who can't switch it on. Their photos and backups sit on servers Apple can unlock — and hand over on a valid legal request...
💩27😨1🤪1
‼️ BREAKING: An active npm supply chain attack has compromised at least 868 packages carrying over 2 billion monthly installs with a credential-stealing worm. Shai-Hulud is back.

It started with the compromise of the GitHub account of the maintainer behind keyv, a library with roughly 127 million weekly npm downloads.

A preinstall hook fires on npm install and drops a stealer that sweeps npm, GitHub, AWS, Kubernetes and Vault secrets, and then spreads to more maintainers.

Sources:

https://aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack

https://wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack

https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain
😨10🥰1
Apple has agreed to open the iPhone clipboard to Windows PCs in the EU after Microsoft filed a DMA interoperability request in March.

Microsoft says users would:
- Copy on an iPhone and paste straight into Windows, and the reverse
- Move content without foregrounding an app or re-triggering each transfer
- Get clipboard sync as "a lightweight, continuous capability rather than a manual, app-driven operation"

Microsoft is using the EU's Digital Markets Act to prise open iOS one feature at a time.
17💩12