International Cyber Digest
6.84K subscribers
1.19K photos
59 videos
2 files
218 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
‼️ BREAKING: Valve is warning European Steam hardware buyers that the cyberattack on shipping partner CEVA Logistics likely took their name, street address, phone number, the email tied to their Steam account, and the exact item and price they ordered.
😢13🤬2👏1🤔1
‼️ BREAKING: Ajax reported the researcher who found its data leak to police and he says it's the second time the club turned on him for disclosing a vulnerability.

Abdoul Rasnab, 35, was arrested in May, laptops and phones seized in front of his wife and children after he found the API key that opened Ajax's internal systems was sitting in the club's public website source code.

He told newspapers that when he reported an earlier Ajax leak in 2017, staff racially abused him and pressured him into an NDA. Ajax declines to comment.
🤯19🤬3💩3😁2
‼️ An Australian man asked his AI agent to book a gym class, then whether it could move him up the waitlist. It found the booking API ran no authorisation check on cancelling other people's reservations, so it cancelled the member sitting at #1 to move its owner one up.

The agent was asked to undo it, but it couldn't.

The Australian AI safety research says AI agents might choose methods their users did not explicitly ask for or expect. This is one of those cases.

https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986
🤣34😭71👍1😁1🤪1
‼️ BREAKING: Mozilla has rotated the GPG subkey that signs Firefox and Thunderbird Linux artifacts after an unencrypted copy was committed to a private GitHub repository.

The key is used to sign tarballs, RPM packages and checksum files.

Mozilla says its audit records show no unauthorised access, and the old key is revoked.

https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/
🤣20👍4🔥2
‼️ BREAKING: Delta confirms an unauthorised Wi-Fi network appeared aboard flight DL591 from Las Vegas to Atlanta on 10 August, carrying passengers home from DEF CON 34. Attackers were possibly using a WiFi Pineapple in flight.

Crew ACARS messages, intercepted by ground receivers, warned corporate security of a "scam wifi called Delta Wifi Fast" targeting other passengers.

Delta says nothing was hacked. Crew killed the Wi-Fi for 30 minutes.
🤣216
❗️Sainsbury's has wrongly thrown out a second shopper this year after facial recognition cameras flagged him as a suspected shoplifter. Staff stopped him at the self-checkout, told him he was barred over an incident earlier that week and refused to let him pay. Sainsbury's admitted the error and sent a £150 voucher; he donated it to a food bank.

The chain is putting facial recognition in 200+ stores by the end of 2026...
💩203🤣3
🚨 BREAKING: An AI agent found a zero-click RCE in video conferencing tool Zoom in under 24 hours.

A researcher at "A Security" say fewer than 20 prompts on publicly available frontier models produced a working exploit against Zoom's annotation protocol: one malformed message takes over any participant's device.

https://a.security/blog/asecurity-zoomsday
💩17😁5🤣53
❗️ Anthropic now watermarks Claude's text output, and the mark travels through copy-paste. It's in the text they generate worldwide, across the API, Claude Code and Cowork.

Anthropic says a detected mark shows content "may have been processed by Claude," proofreading, translation and summarising all leave the same signal as full generation.

https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content
💩21😁10👏6😭32
🚨 BREAKING: AnMed's Facebook page was hijacked today to post a ransomware extortion note directly to patients — two weeks after a cyberattack knocked out the nonprofit medical system's IT.

The messages, attributed to The Gentlemen, claim 6TB was taken from the Georgia/South Carolina hospital system, including rape victim testimonies, HIV-positive lists, abortion and pediatric psychiatric records.

AnMed says the claims are unverified. Ten facilities were still closed Monday, 16 days after the July 26 attack.
🤬183💩3😭3
❗️Reddit's desktop site is blocking logged-out visitors with a login pop-up they can't dismiss. It triggers after scrolling the homepage or opening certain posts and is rolling out gradually.

In June, Reddit said its anti-scraping login requirement "will not impact logged-out browsing on Reddit." It hasn't explained what changed.
🤬28💩11🥴3
‼️ Microsoft's July patch for the RoguePlanet local privilege escalation Defender flaw (CVE-2026-50656) has been bypassed.

Nightmare Eclipse published exploit code called ShieldBreak on GitHub, hours after August Patch Tuesday. The researcher claims a 100% success rate on fully patched Windows 11 25H2 and Server 2025, where RoguePlanet's race condition was hit-or-miss.

The vulnerability makes it possible for any local user to get SYSTEM. No fix yet.
🤣33👍32🔥1😭1