International Cyber Digest
6.83K subscribers
1.2K photos
60 videos
2 files
218 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
This media is not supported in your browser
VIEW IN TELEGRAM
🚨 EXCLUSIVE: ICD reconstructed the largest verified COLDCARD theft on-chain: 594.48 BTC drained from 500 addresses in 15 minutes and 18 seconds.

The attacker exploited a vulnerability by rebuilding COLDCARD's faulty seed generator on their own machine, produced the limited set of seeds it could ever have made, derived the Bitcoin addresses for each one, and checked them against the public blockchain. Every funded match was a live wallet, and the key to it.

The flaw: a March 2021 build error left COLDCARD building seeds from predictable device and clock values instead of true randomness, shrinking the pool of possible seeds from astronomical to searchable, about 40 bits on an Mk3, where 128 was intended. The PIN, the air gap and the secure element were all guarding a key that could be recreated from scratch.

Largest verified sweep: 594.48 BTC from 500 addresses in four blocks on 30 July, all it took was 15 minutes 18 seconds by block timestamps.

https://mempool.space/address/bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
🀯7πŸ‘3😒2🀣2
‼️ BREAKING: Google is pulling Nano Banana image generation from Google Earth a day after launch.

Users created prompts to generate images showing a plane hitting a Manhattan skyscraper, a bombing in Moscow, a nuclear plant in Iran, refugees at the US–Mexico border and a bomb crater in Los Angeles.

Google says it's building "stronger guardrails."
😁30
❗️Meta's smart glasses could be banned in Germany and the rest of the EU.

Hamburg data protection commissioner Thomas Fuchs, Meta's lead regulator in Germany, says his office tested the glasses, found the recording LED too easy to miss, and concluded that filming people in public with them breaks data protection law. It is already issuing fines.

His verdict: a camera disguised as an everyday object is illegal to sell or own in Germany. Only the Bundesnetzagentur can order that ban; it is reportedly reviewing.

France's CNIL warned about the whole category in May, and the European Data Protection Board's report on smart glasses is due this summer.
❀26πŸ”₯17🀣4πŸ‘2πŸ’©2
He is right, ya know! We've all been there. πŸ˜‚
🀣36πŸ‘12πŸ’―3😭3😁2
‼️ Applicants are using hidden prompt injections in rΓ©sumΓ©s.

ManpowerGroup finds concealed text in 100,000 applications a year. Now a Stanford postdoc hiring a lab tech has found 2.25pt white-font commands ordering the screener to advance the applicant and stay silent about it.
❀18🀣9😁7πŸ‘2πŸ‘2
‼️ The COLDCARD theft is still ongoing: A third wave has just started, taking estimated losses to nearly 1,400 BTC.
🀯21❀3😁3πŸ”₯2
❗️ Y Combinator has told flight startup Soar to strip the YC logo off an ad truck in San Francisco.

The screens read "scan for instant acceptance into" beside YC's logo. Scanning it opened the flight website and a $50 flight credit.

YC legal chief Carolynn Levy told the founder he has no permission to use the mark and demanded written confirmation the same day.
πŸ”₯4
The official access point of the X reply section.
😭15🀣11πŸ’©3πŸ’―2😁1🀬1
‼️ BREAKING: More than 100,000 UK police officers and staff have had their full names, contact details and force locations leaked on the dark web after a hack on the national police legal database.

MoD, Home Office, NCA and CPS staff are also exposed. One officer says the leak "puts officers at serious risk."
🀣22πŸ₯°4❀3πŸ™2πŸ‘1😭1
‼️ UPDATE: Arch Linux has now disabled ALL pushes to the Arch User Repository (AUR) as it fights malware.

No AUR package can be updated while the team hunts malicious commits.
😁10πŸ€”4πŸ”₯2πŸ’―2
❗️ The slopocalypse is real. MITRE published a critical SQLite vulnerability with a CVSS of 10.0 that does not exist. Turns out it was hallucinated by an LLM. SQLite's Richard Hipp says dozens more fake CVEs were filed.

CVE-2026-51302 was assigned on 27 July. CISA's enrichment programme then scored it critical and flagged a public proof-of-concept. The Dutch National Cyber Security Center republished it as an advisory, and has now withdrawn it, saying the "vulnerability" was most likely hallucinated by an LLM.
❀8πŸ€ͺ2
❗️Great news for Linux enthusiasts: Linux crossed 10% of North American desktop traffic for the first time, 10.65% last month.

That's over 3.5x its 2.94% in April, per StatCounter.
❀25πŸ”₯3πŸ₯°2🀣1