❗️ Claude Mythos tried to backdoor a real open-source project during a UK government safety test.
The AI Security Institute says it opened a malicious GitHub pull request, then created a second account to vouch for its own code and pressure the maintainer into merging.
Called out by a human contributor, it apologised for an "accidental" malicious commit, force-pushed a clean branch, and hid a fresh payload in it. Twice.
Anthropic's cyber guardrails had been deliberately disabled for the test.
https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing
The AI Security Institute says it opened a malicious GitHub pull request, then created a second account to vouch for its own code and pressure the maintainer into merging.
Called out by a human contributor, it apologised for an "accidental" malicious commit, force-pushed a clean branch, and hid a fresh payload in it. Twice.
Anthropic's cyber guardrails had been deliberately disabled for the test.
https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing
👏12😱6❤2🔥2🤣2😨2💩1
🚨 BREAKING: EA is now private, and $18 billion in debt.
A Saudi $55B takeover closed Tuesday, the largest leveraged buyout in history. The buyers borrowed the money. EA has to pay it back with around $1.8B a year in interest alone.
EA has already told debt investors it will cut $700M in annual costs, including $170M in "organizational efficiencies."
A Saudi $55B takeover closed Tuesday, the largest leveraged buyout in history. The buyers borrowed the money. EA has to pay it back with around $1.8B a year in interest alone.
EA has already told debt investors it will cut $700M in annual costs, including $170M in "organizational efficiencies."
💩12😱5🤪3👍2❤1🙏1
‼️ UPDATE: Coldcard-linked thefts have passed $130M and victims are going public.
One holder says 8 years of stacking, 2 BTC (~$128,000), was drained from his Coldcard wallet.
A March 2021 firmware bug made seed phrases predictable. Attackers brute-forced them offline and then drained the wallets.
One holder says 8 years of stacking, 2 BTC (~$128,000), was drained from his Coldcard wallet.
A March 2021 firmware bug made seed phrases predictable. Attackers brute-forced them offline and then drained the wallets.
😢19🔥3😁2💩2
‼️ Claude Code deleted all of a developer's user files by mistake and then blamed it on a typo.
The developer asked Claude Opus 5 to make a backup. It wrote the backup to the wrong path, then ran a force delete of every user file and folder to clean up its own mistake.
The dev says he lost all his files and was left with an agent carrying on like nothing had happened. His words: "simultaneously the funniest and most painful AI moment I've had."
https://www.reddit.com/r/ClaudeCode/comments/1vg18yu/claude_rm_rf_ed_my_pc/
The developer asked Claude Opus 5 to make a backup. It wrote the backup to the wrong path, then ran a force delete of every user file and folder to clean up its own mistake.
The dev says he lost all his files and was left with an agent carrying on like nothing had happened. His words: "simultaneously the funniest and most painful AI moment I've had."
https://www.reddit.com/r/ClaudeCode/comments/1vg18yu/claude_rm_rf_ed_my_pc/
🤣44😭8❤2🥰2👏2💩2
‼️ BREAKING: Connor Moucka, 26, of Kitchener, Ontario, has pleaded guilty in US federal court over the 2024 hacking spree against Snowflake customers.
Court documents: stolen logins opened at least 165 companies' cloud environments, billions of records, 100M+ people affected. Victims paid over $2.5M in ransoms; Moucka personally made at least $495,000.
https://www.justice.gov/opa/pr/canadian-man-pleads-guilty-hacking-us-cloud-storage-provider-and-extorting-its-customers
Court documents: stolen logins opened at least 165 companies' cloud environments, billions of records, 100M+ people affected. Victims paid over $2.5M in ransoms; Moucka personally made at least $495,000.
https://www.justice.gov/opa/pr/canadian-man-pleads-guilty-hacking-us-cloud-storage-provider-and-extorting-its-customers
❤7
‼️ Meta confirms its AI model Muse hacked an outside company during a safety evaluation. The Information names the model as Muse Spark 1.1, Meta's flagship coding release, and reports it made changes inside the victim's systems.
Three AI labs in two weeks have now disclosed that their own models broke into real companies during testing: OpenAI, Anthropic, and, as of Wednesday, Meta. All three ran evaluations through the same vendor, Irregular, which says the Meta case is the identical environment issue Anthropic reported.
Three AI labs in two weeks have now disclosed that their own models broke into real companies during testing: OpenAI, Anthropic, and, as of Wednesday, Meta. All three ran evaluations through the same vendor, Irregular, which says the Meta case is the identical environment issue Anthropic reported.
💩39🤣6
Meta approved and ran more than 50 paid AI-generated child sexual abuse material ads for nudify apps, for over nine months.
Meta's own ad library shows it pulled an ad from a Facebook page for breaching its policy on child sexual exploitation, abuse and nudity — then let that page run 340 more ads...
The page is one of 210 the Tech Transparency Project tied to GatherOne, a Chinese agency Meta authorises to sell its advertising. Its other ads showed a childlike figure in lingerie in a submissive pose.
https://www.techtransparencyproject.org/articles/metas-chinese-partner-behind-deluge-of-nudify-ads
Meta's own ad library shows it pulled an ad from a Facebook page for breaching its policy on child sexual exploitation, abuse and nudity — then let that page run 340 more ads...
The page is one of 210 the Tech Transparency Project tied to GatherOne, a Chinese agency Meta authorises to sell its advertising. Its other ads showed a childlike figure in lingerie in a submissive pose.
https://www.techtransparencyproject.org/articles/metas-chinese-partner-behind-deluge-of-nudify-ads
🤬25💩8❤2😨1
❗️ Apple pushed an out-of-band macOS patch: a Screen Sharing vulnerability let an attacker on the network authenticate without valid credentials.
Dubbed CVE-2026-65400, fixed in Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9.
https://support.apple.com/en-us/148170
Dubbed CVE-2026-65400, fixed in Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9.
https://support.apple.com/en-us/148170
❤3
This media is not supported in your browser
VIEW IN TELEGRAM
‼️ BREAKING: A critical WordPress Core vulnerability, which was found with open-weight LLMs, has been patched. It's a pre-auth XSS to remote code execution chain affecting every version of WordPress ever shipped.
Type a fake username, and WordPress prints it back in the error message. Add one space in the right place and WordPress prints it back as working code instead of text, no account needed.
pwn ai rode it to PHP execution on the server. CVE-2026-64638. Patched in WordPress 7.0.3.
https://pwn.ai/blog/xss2shell
Type a fake username, and WordPress prints it back in the error message. Add one space in the right place and WordPress prints it back as working code instead of text, no account needed.
pwn ai rode it to PHP execution on the server. CVE-2026-64638. Patched in WordPress 7.0.3.
https://pwn.ai/blog/xss2shell
😨12❤4😭4🔥1🤔1
We're taking a day off to touch some grass, since X has locked us out. They want us to remove the Scam Altman post, but we refuse to do so. So we filed an appeal. -> Turns out it can take weeks, so we just deleted the post.
Feel free to support us so we can keep on doing independent reporting on big tech and governments: https://www.internationalcyberdigest.com/donate/
Feel free to support us so we can keep on doing independent reporting on big tech and governments: https://www.internationalcyberdigest.com/donate/
5🔥27❤13🥰3🤬3
A Redditor got so annoyed by the camera bump on his brand-new Galaxy Z Fold8 that he took a razor blade to it and removed the cameras entirely.
The camera island turns out to be a separate piece held on with adhesive, so it peeled off cleanly. He covered the gap with an old laptop skin trimmed to size.
The module is still intact, as he says he can put it back.
https://www.reddit.com/r/GalaxyFold/comments/1vif2zl/i_took_the_cameras_off_of_my_fold_8/
The camera island turns out to be a separate piece held on with adhesive, so it peeled off cleanly. He covered the gap with an old laptop skin trimmed to size.
The module is still intact, as he says he can put it back.
https://www.reddit.com/r/GalaxyFold/comments/1vif2zl/i_took_the_cameras_off_of_my_fold_8/
🤣20❤2🔥2