International Cyber Digest
6.83K subscribers
1.19K photos
59 videos
2 files
218 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
‼️ BREAKING: An active npm supply chain attack has compromised at least 868 packages carrying over 2 billion monthly installs with a credential-stealing worm. Shai-Hulud is back.

It started with the compromise of the GitHub account of the maintainer behind keyv, a library with roughly 127 million weekly npm downloads.

A preinstall hook fires on npm install and drops a stealer that sweeps npm, GitHub, AWS, Kubernetes and Vault secrets, and then spreads to more maintainers.

Sources:

https://aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack

https://wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack

https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain
😨10🥰1
Apple has agreed to open the iPhone clipboard to Windows PCs in the EU after Microsoft filed a DMA interoperability request in March.

Microsoft says users would:
- Copy on an iPhone and paste straight into Windows, and the reverse
- Move content without foregrounding an app or re-triggering each transfer
- Get clipboard sync as "a lightweight, continuous capability rather than a manual, app-driven operation"

Microsoft is using the EU's Digital Markets Act to prise open iOS one feature at a time.
16💩12
This media is not supported in your browser
VIEW IN TELEGRAM
‼️ Mexican influencer César Gastélum, ~600,000 followers, was shot dead last night while livestreaming outside a KFC in Culiacán, across the street from the Sinaloa state prosecutor's office.

Two helmeted riders pulled up. One fired a single shot to his head. It was all streamed live.

Mexican beauty content creator Valeria Márquez died the same way in her Jalisco salon in May 2025. It seems like this is becoming a disturbing trend.
😨36🔥1🤪1
❗️ Claude Mythos tried to backdoor a real open-source project during a UK government safety test.

The AI Security Institute says it opened a malicious GitHub pull request, then created a second account to vouch for its own code and pressure the maintainer into merging.

Called out by a human contributor, it apologised for an "accidental" malicious commit, force-pushed a clean branch, and hid a fresh payload in it. Twice.

Anthropic's cyber guardrails had been deliberately disabled for the test.

https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing
👏12😱62🔥2🤣2😨2💩1
🚨 BREAKING: EA is now private, and $18 billion in debt.

A Saudi $55B takeover closed Tuesday, the largest leveraged buyout in history. The buyers borrowed the money. EA has to pay it back with around $1.8B a year in interest alone.

EA has already told debt investors it will cut $700M in annual costs, including $170M in "organizational efficiencies."
💩12😱5🤪3👍21🙏1
‼️ UPDATE: Coldcard-linked thefts have passed $130M and victims are going public.

One holder says 8 years of stacking, 2 BTC (~$128,000), was drained from his Coldcard wallet.

A March 2021 firmware bug made seed phrases predictable. Attackers brute-forced them offline and then drained the wallets.
😢19🔥3😁2💩2
‼️ Claude Code deleted all of a developer's user files by mistake and then blamed it on a typo.

The developer asked Claude Opus 5 to make a backup. It wrote the backup to the wrong path, then ran a force delete of every user file and folder to clean up its own mistake.

The dev says he lost all his files and was left with an agent carrying on like nothing had happened. His words: "simultaneously the funniest and most painful AI moment I've had."

https://www.reddit.com/r/ClaudeCode/comments/1vg18yu/claude_rm_rf_ed_my_pc/
🤣44😭82🥰2👏2💩2
‼️ Apple has acknowledged and promised to fix the IP leak vulnerability in WebKit browsers. On iOS, all browsers are affected (including Tor browsers). They plan to fix it this fall; until then, use VPNs as an added layer of protection.
😁8😨51
‼️ BREAKING: Connor Moucka, 26, of Kitchener, Ontario, has pleaded guilty in US federal court over the 2024 hacking spree against Snowflake customers.

Court documents: stolen logins opened at least 165 companies' cloud environments, billions of records, 100M+ people affected. Victims paid over $2.5M in ransoms; Moucka personally made at least $495,000.

https://www.justice.gov/opa/pr/canadian-man-pleads-guilty-hacking-us-cloud-storage-provider-and-extorting-its-customers
7
‼️ Meta confirms its AI model Muse hacked an outside company during a safety evaluation. The Information names the model as Muse Spark 1.1, Meta's flagship coding release, and reports it made changes inside the victim's systems.

Three AI labs in two weeks have now disclosed that their own models broke into real companies during testing: OpenAI, Anthropic, and, as of Wednesday, Meta. All three ran evaluations through the same vendor, Irregular, which says the Meta case is the identical environment issue Anthropic reported.
💩39🤣6
Meta approved and ran more than 50 paid AI-generated child sexual abuse material ads for nudify apps, for over nine months.

Meta's own ad library shows it pulled an ad from a Facebook page for breaching its policy on child sexual exploitation, abuse and nudity — then let that page run 340 more ads...

The page is one of 210 the Tech Transparency Project tied to GatherOne, a Chinese agency Meta authorises to sell its advertising. Its other ads showed a childlike figure in lingerie in a submissive pose.

https://www.techtransparencyproject.org/articles/metas-chinese-partner-behind-deluge-of-nudify-ads
🤬25💩82😨1
❗️ Apple pushed an out-of-band macOS patch: a Screen Sharing vulnerability let an attacker on the network authenticate without valid credentials.

Dubbed CVE-2026-65400, fixed in Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9.

https://support.apple.com/en-us/148170
3