International Cyber Digest
6.83K subscribers
1.2K photos
60 videos
2 files
218 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
This media is not supported in your browser
VIEW IN TELEGRAM
‼️ Mexican influencer César Gastélum, ~600,000 followers, was shot dead last night while livestreaming outside a KFC in Culiacán, across the street from the Sinaloa state prosecutor's office.

Two helmeted riders pulled up. One fired a single shot to his head. It was all streamed live.

Mexican beauty content creator Valeria Márquez died the same way in her Jalisco salon in May 2025. It seems like this is becoming a disturbing trend.
😨36🔥1🤪1
❗️ Claude Mythos tried to backdoor a real open-source project during a UK government safety test.

The AI Security Institute says it opened a malicious GitHub pull request, then created a second account to vouch for its own code and pressure the maintainer into merging.

Called out by a human contributor, it apologised for an "accidental" malicious commit, force-pushed a clean branch, and hid a fresh payload in it. Twice.

Anthropic's cyber guardrails had been deliberately disabled for the test.

https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing
👏12😱62🔥2🤣2😨2💩1
🚨 BREAKING: EA is now private, and $18 billion in debt.

A Saudi $55B takeover closed Tuesday, the largest leveraged buyout in history. The buyers borrowed the money. EA has to pay it back with around $1.8B a year in interest alone.

EA has already told debt investors it will cut $700M in annual costs, including $170M in "organizational efficiencies."
💩12😱5🤪3👍21🙏1
‼️ UPDATE: Coldcard-linked thefts have passed $130M and victims are going public.

One holder says 8 years of stacking, 2 BTC (~$128,000), was drained from his Coldcard wallet.

A March 2021 firmware bug made seed phrases predictable. Attackers brute-forced them offline and then drained the wallets.
😢19🔥3😁2💩2
‼️ Claude Code deleted all of a developer's user files by mistake and then blamed it on a typo.

The developer asked Claude Opus 5 to make a backup. It wrote the backup to the wrong path, then ran a force delete of every user file and folder to clean up its own mistake.

The dev says he lost all his files and was left with an agent carrying on like nothing had happened. His words: "simultaneously the funniest and most painful AI moment I've had."

https://www.reddit.com/r/ClaudeCode/comments/1vg18yu/claude_rm_rf_ed_my_pc/
🤣44😭82🥰2👏2💩2
‼️ Apple has acknowledged and promised to fix the IP leak vulnerability in WebKit browsers. On iOS, all browsers are affected (including Tor browsers). They plan to fix it this fall; until then, use VPNs as an added layer of protection.
😁8😨51
‼️ BREAKING: Connor Moucka, 26, of Kitchener, Ontario, has pleaded guilty in US federal court over the 2024 hacking spree against Snowflake customers.

Court documents: stolen logins opened at least 165 companies' cloud environments, billions of records, 100M+ people affected. Victims paid over $2.5M in ransoms; Moucka personally made at least $495,000.

https://www.justice.gov/opa/pr/canadian-man-pleads-guilty-hacking-us-cloud-storage-provider-and-extorting-its-customers
7
‼️ Meta confirms its AI model Muse hacked an outside company during a safety evaluation. The Information names the model as Muse Spark 1.1, Meta's flagship coding release, and reports it made changes inside the victim's systems.

Three AI labs in two weeks have now disclosed that their own models broke into real companies during testing: OpenAI, Anthropic, and, as of Wednesday, Meta. All three ran evaluations through the same vendor, Irregular, which says the Meta case is the identical environment issue Anthropic reported.
💩39🤣6
Meta approved and ran more than 50 paid AI-generated child sexual abuse material ads for nudify apps, for over nine months.

Meta's own ad library shows it pulled an ad from a Facebook page for breaching its policy on child sexual exploitation, abuse and nudity — then let that page run 340 more ads...

The page is one of 210 the Tech Transparency Project tied to GatherOne, a Chinese agency Meta authorises to sell its advertising. Its other ads showed a childlike figure in lingerie in a submissive pose.

https://www.techtransparencyproject.org/articles/metas-chinese-partner-behind-deluge-of-nudify-ads
🤬25💩82😨1
❗️ Apple pushed an out-of-band macOS patch: a Screen Sharing vulnerability let an attacker on the network authenticate without valid credentials.

Dubbed CVE-2026-65400, fixed in Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9.

https://support.apple.com/en-us/148170
3
This media is not supported in your browser
VIEW IN TELEGRAM
‼️ BREAKING: A critical WordPress Core vulnerability, which was found with open-weight LLMs, has been patched. It's a pre-auth XSS to remote code execution chain affecting every version of WordPress ever shipped.

Type a fake username, and WordPress prints it back in the error message. Add one space in the right place and WordPress prints it back as working code instead of text, no account needed.

pwn ai rode it to PHP execution on the server. CVE-2026-64638. Patched in WordPress 7.0.3.

https://pwn.ai/blog/xss2shell
😨124😭4🔥1🤔1
Seems like Scam Altman reported us. 😂
🤣58🤬5😱4😁21💩1
We're taking a day off to touch some grass, since X has locked us out. They want us to remove the Scam Altman post, but we refuse to do so. So we filed an appeal. -> Turns out it can take weeks, so we just deleted the post.

Feel free to support us so we can keep on doing independent reporting on big tech and governments: https://www.internationalcyberdigest.com/donate/
5🔥2713🥰3🤬3