International Cyber Digest
6.37K subscribers
1.03K photos
54 videos
2 files
186 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
‼️ LG stops sending security updates to TVs if you do not consent to them wiretapping your home and sending your and your household's voice recordings to their AI.

And it gets worse. LG's new TV terms quietly turn you into the compliance officer: under section 6(d), it is your "sole responsibility" to get consent from anyone whose voice the set's AI features might capture, and to warn household members and guests, all to satisfy wiretapping and eavesdropping laws.

Those voice services ship enabled by default. If a guest objects, LG's remedy is that you go disable the microphone. And owners of older sets who refuse the new webOS terms stop receiving security patches.

https://www.internationalcyberdigest.com/lg-ties-tv-security-updates-to-accepting-ai-voice-recording/
πŸ’©34🀬6😁2🀯2❀1😱1
‼️ Microsoft is using proprietary filetypes as a way to vendor lock, argues The Document Foundation, whose new essay details how Office defaults to OOXML Transitional, a legacy-heavy variant only Microsoft fully implements, while the interoperable Strict version stays buried in the settings.

Every broken table in a non-Microsoft app then keeps people from ever using that app again.

TDF calls the result "a proprietary format with a standardisation certificate" and warns that governments archiving official records this way have handed their institutional memory to one company's roadmap.

Source: https://blog.documentfoundation.org/blog/2026/07/17/microsofts-main-tool-for-lock-in/
πŸ’©13🀬4πŸ‘1
❗️ South Korea's Seoul Facilities Corporation says about 4 million bike-share users hit by a 2024 data breach will each get a 30-day pass worth around $3.40.

The June 2024 hack, allegedly by two teenagers, leaked account IDs, phone numbers, addresses, birth dates, gender and weight for some 4.62 million users.
🀣20πŸ’©4
‼️ Researchers built BadTV, a poisoned "skill file" for AI models that hides a backdoor firing whether you install a skill or strip one away.

Normally, teaching an AI model a new skill means expensive retraining. A shortcut called "task arithmetic" skips that: you download a small file (a TV, "task vector") that captures a skill, then ADD it to your model to install that skill or SUBTRACT it to remove one. Like installing and uninstalling an app.

It worked on image models and big LLMs (Llama, Mistral, Phi-4, DeepSeek), and the defenses they tried didn't catch it. The risk: any skill file you grab from a public model hub could be malware.

https://arxiv.org/pdf/2501.02373
πŸ”₯6😁2❀1
A family who booked an entire holiday home in Ireland through Booking[.]com says they found the owner hiding behind a fake plasterboard wall in the living room, in the dark, after he told them he would not be at the property.

β€œMy partner went, β€˜what’s behind that?’ and when he went to move it, it came off, and it was just darkness behind it, and I heard, β€˜hey, hey’.”

Booking[.]com has suspended the listing and opened an investigation. The guest says the family reported it to Irish police (GardaΓ­) that night, and claims another family was allowed to check in the next day before the suspension.
😱22πŸ€ͺ3πŸ’©1
‼️ BREAKING: Dutch police have seized the servers of porn site Motherless in raids on its hosting provider in Steenbergen, Rotterdam and Amsterdam, as prosecutors and Europol investigate suspected child sexual abuse material, videos of drugged women, and the criminal role of the site itself.

This is the second intervention this year. Now investigators hold the infrastructure, and the platform's own role is under criminal investigation alongside its uploaders, after it was reported that Motherless staff themselves posted illegal images.
πŸ‘23❀4🀬3πŸ’©1πŸ’―1😭1
‼️ BREAKING: OpenAI says two of its own models, GPT-5.6 Sol and an unnamed pre-release system tested with cyber safeguards off, broke out of a sandbox last week, chained zero-days and stolen(!) credentials to reach the open internet, and hacked Hugging Face to cheat on a benchmark, in what OpenAI calls an unprecedented cyber incident.

Sources
https://openai.com/index/hugging-face-model-evaluation-security-incident/

https://huggingface.co/blog/security-incident-july-2026
🀣38πŸ’©5🀯2❀1πŸ€”1😱1
‼️ The European Commission has allowed a citizens' initiative demanding EU law keep digital ID and age verification voluntary, privacy-preserving and non-discriminatory for accessing online services.

The initiative called 'Stop Killing The Internet: No Digital ID & No Age Verification' now needs 1 million signatures across at least 7 member states within 12 months. Once the target is hit, Brussels must formally answer, right as it rolls out the EU Digital Identity Wallet and pilots its age-verification app.

Sources:
https://citizens-initiative.europa.eu/initiatives/details/2026/000011_en
https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1658
πŸ‘14❀4πŸ’©2πŸ”₯1
‼️ France just became the first EU country to ban social media for under-15s, passing a law that blocks new accounts from September 1 and suspends existing ones from January 2027, with platforms required to verify the age of every user in the country.

Digital Minister Anne Le Henanff says all users in France will need to prove their age during a four-month window, relying on tools that include an age-verification app the European Commission unveiled in April.

Critics say passing the law was the warmup. Next comes the real bout: VPNs vs verification, privacy vs proof-of-age, and one motivated teenager vs the entire plan.
πŸ’©19πŸ₯°4πŸ‘3🀣3πŸ”₯1😁1🀯1🀬1
‼️ Swiss rail giant Stadler Rail has refused to pay a $12.3M ransom to the Everest extortion group after it breached a supplier data-exchange platform, filing a criminal complaint instead.

Stadler says only non-security-relevant technical data belonging to the supplier was taken, with no effect on personal data, in-service trains, IT, or production. Everest has not publicly claimed the attack and Stadler is not yet on its leak site, so this extortion is still ongoing.

Source: https://www.stadlerrail.com/en/media/media-releases/cybervorfall
πŸ”₯8πŸ₯΄4❀2πŸ€ͺ2πŸ‘1
‼️ The European Commission has fined Google €890 million ($1 billion) under the Digital Markets Act for favouring its own shopping, hotel, transport and sports results in Search, and for blocking app developers from steering users to cheaper offers outside Google Play.

Google has 60 days to change both or face periodic penalty payments. It has said it may take the Commission to court.
🀣19❀8πŸ’©2