International Cyber Digest
7.2K subscribers
1.34K photos
69 videos
2 files
255 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
❗️Attackers are chaining two critical MikroTik RouterOS bugs to take full control of any router with SSH exposed to the internet. Polish CERT has confirmed exploitation since at least 2 September.

The vulnerabilities being exploited are an SSH authentication bypass and a privilege escalation, CVE-2026-67276 and CVE-2026-86060, both CVSS 9.2.

Patch ASAP.

https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
😱5🔥3
Media is too big
VIEW IN TELEGRAM
‼️ BREAKING: This is the voice Dutch police want identified: a Dutch-speaking man who called Odido's customer service posing as a colleague from IT.

That single call is how ShinyHunters ended up with the data of more than 6 million people.

Police say the recording is not AI.
🤣16😁8👍4💩1
‼️ Grindr will hand over £26m to settle claims from 12,000 UK users that the app passed sensitive details from their profiles, HIV status among them in some cases, to advertising firms.

Grindr blames the era, not the app. Grindr told the SEC the case covers "historical data practices before 2020" — when it was owned by Beijing Kunlun Tech, the Chinese owner a US national security panel later forced out.
😁14🤣4🔥3👍1
‼️ Microsoft's patch for Windows Defender zero-day ShieldBreak (CVE-2026-69414) is still bypassable, a new PoC called ShieldCrash was published today by researcher Nightmare-Eclipse. It demonstrates arbitrary file read as SYSTEM on all supported Windows versions running the September 2026 patches.

The researcher describes it as a "skeleton PoC" and says a full SYSTEM exploit may follow.

Link to PoC: https://github.com/MSNightmare/ShieldCrash
🤣27😁1😱1
A cyberattack stopped Boston Scientific from shipping medical devices to hospitals and clinics for more than a week. In a recent update the company said its systems still weren't restored, and gave no date for when they would be.

It has now cut its sales and profit forecast for the year and told the SEC that attackers took patient health data along with confidential company information. The shares fell.

Boston Scientific hasn't said what kind of attack hit it on 25 August, or how the attackers got in.

https://news.bostonscientific.com/update-on-recent-cybersecurity-incident
🤬121
A group that came together through online gaming platforms stole more than $245 million in cryptocurrency. Its ringleader, a 22-year-old Singaporean living in Miami named Malone Lam, pleaded guilty in Washington today.

He picked the targets and assigned the roles, prosecutors say. Conspirators talked victims into handing over the information that let them drain the wallets, with occasional home break-ins alongside the deception.

The money went on nightclub tabs of up to $500,000 a night, designer handbags given away at those parties, private jets, a private security team and a fleet of exotic cars topping out at $3.8 million. Lam was arrested at his Miami rental home last September.

https://www.justice.gov/usao-dc/pr/singaporean-ringleader-245-million-cryptocurrency-racketeering-enterprise-pleads-guilty
🤣184🔥4😭2
OpenAI says one of its internal models has proved that the Navier-Stokes equations, the century-old maths behind how fluids move, and one of the seven problems carrying a $1m Clay prize, can break down and produce infinite speeds. Two mathematicians who had spent a year on the same narrow route say OpenAI only got there after hearing about their work, and that the company then tried to shape how the credit was handed out.

Sébastien Bubeck, who runs OpenAI's math team, has now confirmed he told NYU's Tristan Buckmaster it would be "simpler" if his co-author, Levent Alpöge, didn't work at Anthropic.

Bubeck says he never asked for Alpöge to be dropped from his own paper. The idea was different: Buckmaster rewriting OpenAI's proof under his own name. Bubeck says he couldn't see how someone from a rival lab could sign that, or be shown the internal model behind it.

He also confirms he asked Buckmaster why he would risk his career. Buckmaster read it as a threat. Bubeck calls it an "extremely poor choice of words" and says he took it back on the call.

Sam Altman quote posted the account in support and drew the same line himself: the offer to lead-author the rewrite went to Buckmaster, and was hard to extend to an Anthropic employee. Altman also confirmed why OpenAI went at the problem, it was because of rumours online that Anthropic's models had solved a Millennium Prize problem.
🤪13👍7🤣21
Someone got tired of hunting for a desktop wallpaper, so they photographed everything behind their monitor and set that as the background.
22🤣10😁7🔥5
‼️ BREAKING: A flaw in ChatGPT let researchers reach data inside the apps people connect to it: Gmail, Google Drive, Microsoft Teams, GitHub. A hidden prompt was enough to make the chatbot hand it over, with nothing visible to the user.

The channel was a clipboard shared between ChatGPT's normally isolated containers, which carried instructions from one account into another's session. In their proof-of-concept the researchers pulled a victim's Gmail messages, chat history and uploaded files while that user watched their own request run as normal.

The hidden instruction could arrive through a malicious prompt, a shared conversation or a custom GPT. Check Point found it in June 2026 and says the channel had already closed before they reported it; OpenAI confirmed the internal server behind it was decommissioned.

https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/
😱104🥰2👏1😁1😭1
‼️ An Anthropic researcher says AI could kill us all before 2030 and his is opinion is shared throughout the AI industry. He says senior researchers and executives soften their language for the press while voicing the same fear privately.

In the most aggressive scenarios, he said, things could be out of control by the end of 2027.

He also worked at OpenAI and is now leaving the industry altogether because neither company is acting responsibly: both are racing toward self-improving superintelligence with everyone's lives on the table.

He also takes on the obvious objection, if they believe this, why keep building?

At OpenAI, he says, many people have not really internalized the stakes. At Anthropic they are well understood, but the company is locked in a race to get there first.

The researcher told he had moved to Anthropic only months ago because of its safety reputation, that he thinks the safety work there is sincere, but that it isn't enough: trade-offs become unavoidable when labs are competing with each other and with Chinese rivals.

What he asks for is coordination rather than exits: pacing agreements between U.S. labs, and if it comes to it, a temporary halt on improving model capabilities.
🤣17💩6🤪64😍1
International Cyber Digest
‼️ BREAKING: Your LG TV is eavesdropping on you. It transcribes what you say, copies what is on your screen, and scans every device on your network, and researchers say the collection keeps running after you disconnect it, uploading the moment it reconnects.…
‼️ LG has issued a statement on their TVs recording audio and scanning local networks shown in the Gamers Nexus video. It says voice data is only processed when the remote's voice button is held down or after the "Hi LG" wake word, the company told Gizmodo.

The network scanning is in fact real, but LG calls it a standard smart TV function needed to deliver smart features.

The Automatic Content Recognition that identifies what's on your screen is opt-in, LG adds.

Critics note Gamers Nexus rooted the TV to get there, and HDTVtest says that only US models were tested, nobody has checked whether European sets under the GDPR behave the same way.

Even if LG is right, smart TVs are still a privacy and security problem. LG's own privacy policy allows sharing data with advertising partners and law enforcement and US police have been caught buying ad-broker data before.

Rtings found most modern sets track every device you plug in, down to the game console, and opting out is deliberately hard.

Researchers who reviewed the Gamers Nexus findings suggested keeping the TV off the internet entirely, less over tracking than over the vulnerabilities sitting in an internet-connected screen nobody patches.
🤬21🤣4👍21🔥1
‼️ Google's September Android update patches a vulnerability that lets an attacker run code on a phone remotely, with no permissions and no user interaction required. Google won't say which flaw it is.

Eight critical System bugs in this bulletin lead to remote code execution. In total there are 200 fixes, of which 33 are critical.

Google has said that 40 percent of Android phones no longer receive updates at all. Which is concerning, to say the least.

https://source.android.com/docs/security/bulletin/2026/2026-09-01
🤯17😭93😁2🥰1🤣1