International Cyber Digest
6.84K subscribers
1.18K photos
59 videos
2 files
218 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
This media is not supported in your browser
VIEW IN TELEGRAM
❗️🚨 Microsoft Edge keeps every saved password in process memory as cleartext from the moment it launches. Microsoft's responsed when reported: "by design."

All of them. Including credentials for sites you won't open this session.

Researcher L1v1ng0ffTh3L4N tested every major Chromium browser. Edge is the only one that behaves this way.

Chrome decrypts credentials on demand, and App-Bound Encryption locks the keys to an authenticated Chrome process so other processes can't reuse them.

In Chrome, plaintext surfaces only during autofill or when a password is viewed, making memory scraping far less useful.

What makes this extra weird is that Edge still demands re-authentication before revealing those passwords in its Password Manager UI, while the same browser process already holds every one of them in plaintext.

In shared environments, this turns into a credential harvest. On a terminal server, an attacker with admin rights can read the memory of every logged-on user process. In the published PoC video, a compromised admin account lifts stored credentials from two other logged-on (and even disconnected) users with Edge running.

Microsoft's official response when notified: "by design."

The finding was disclosed April 29 at BigBiteOfTech by PaloAltoNtwks Norway, alongside a small educational tool that lets anyone verify the cleartext storage for themselves.
🤣19💩8🔥42
🚨🇹🇼 BREAKING: A 23-year-old college student in Taiwan brought three high-speed trains to an emergency stop by hijacking the rail network's radio communications.

A month ago Taiwan High Speed Rail Corp's operations control center received an alarm from what appeared to be a handheld radio belonging to its maintenance department. Three operating trains halted immediately. Service resumed 20 minutes later, after inspections cleared the line.

When the control center called back, the responses kept changing. Then the radio went dead.

A full inventory confirmed every THSRC handheld was accounted for and working. The signal had come from an outsider.

THSRC reported the incident on April 6. The Railway Police Bureau and the Criminal Investigation Bureau's Electronic Investigation Brigade traced the transmission to a male university student, surname Lin, studying at a university in central Taiwan.

A radio enthusiast, he allegedly used his own equipment to impersonate THSRC radio parameters and inject the false alarm into the network.

Police searched his residence and workplaces, seizing radio communication gear and electronic devices.

He was taken into custody and released the same night on bail.

Charges: violations of the Railway Act for unlawfully exploiting system vulnerabilities to intrude into core railway communication infrastructure and using electromagnetic methods to interfere with railway equipment, plus a Criminal Code charge for endangering public transportation...

That's going to stick with him for a while.
10👏5😁3🥰1🤬1
‼️🚨 BREAKING: US military defense contractor Schemata exposed the personal data of active US military personnel for 150 days.

Schemata holds millions in active DoD contracts and runs sensitive simulations for Army grenadiers, Air Force operators, and naval personnel. The fix should have been simple. Instead, the platform shipped with effectively no authorization layer on its API.

Strix AI self-registered an account. That single session gave them full read access to:

- User lists with names, emails, and the specific military bases where U.S. service members are stationed
- Hundreds of confidential course manuals, served via direct S3 links to operational training modules
- Full write access to mutate or delete courses

The flaw was uncovered by an open-source AI agent, which decomposed the assessment into 20 parallel agents. 37 minutes. 520 tool calls. First validated finding in 11 minutes. The chain ran API recon, JS route mining, cross-tenant validation, auth review, and report generation end-to-end.

Strix reached out for a responsible disclosure channel in December 2025. Schemata stayed silent for 150 days. They finally replied and patched the exposed endpoints on May 1, 2026.

Read: https://www.strix.ai/blog/how-strix-found-zero-auth-vulnerability-dod-backed-startup
5😁2
🚨 The official DAEMON Tools website has been serving backdoored installers since April 8.

Thousands of infections have already taken place across 100+ countries.

The latest versions are still infected. The installers are signed with legitimate developer certificates.

Source: https://www.kaspersky.com/blog/daemon-tools-supply-chain-attack/55691/
🤔7😁2
‼️ Google paid $57,000 for two Chrome vulnerabilities found by a researcher using a $20/month AI subscription.

The input-output asymmetry of the AI era is staggering.
🤯15🤪7😁31
RIP sane mind.
😱19😭8😁1💩1
❗️🚨 Meta's AI will analyze users' bone structure and height for age verification, combined with text analysis of profiles, posts, and replies.

Accounts flagged as minors are deactivated. The user is then forced through Meta's age verification process to regain access.

Instagram and Facebook require users to be at least 13. To find accounts that violate this, Meta's AI will sweep entire profiles for "contextual clues" such as birthday mentions, school grades referenced in posts, profile information, and replies.

A visual analysis layer runs alongside it. AI scans photos and videos for visual cues to estimate the user's age.

Meta insists this is not facial recognition. According to the company, the AI looks at general traits and visual indicators (like height or bone structure) to estimate age, without identifying the individual in the image. Meta claims combining these visual signals with text and interaction analysis lets it find and remove far more underage accounts.

Read: https://about.fb.com/news/2026/05/ai-age-assurance-teens/
🤣7🤪21
‼️🚨 Microsoft calls this "intended behaviour," so here we go.

How to dump the credentials of every user stored in Microsoft Edge:

1. Open Edge. Don't browse anywhere, just open it.
2. Flip to Task Manager, find Edge, expand the task.
3. Highlight the "browser" sub-task, right-click, and choose "Create Memory Dump."
4. Open the dump file and look for credentials.

The logged-in Windows user can dump every stored Edge credential with no additional rights. Which means any malware that user executes has those credentials for the asking.

Thanks to Rob VandenBrink at SANS: https://isc.sans.edu/diary/32954
😭14😁5🤯3🔥2
‼️🚨 CRITICAL: Palo Alto Networks has disclosed CVE-2026-0300, a buffer overflow in PAN-OS that is already being exploited in the wild.

CVSS 4.0 score: 9.3.

Unauthenticated attackers can hit the User-ID Authentication Portal (the Captive Portal service) with crafted packets and pop a root shell on the firewall.

The flaw is an out-of-bounds write (CWE-787) in PA-Series and VM-Series firewalls. Prisma Access, Cloud NGFW, and Panorama are not affected. The vulnerability only triggers when the User-ID Authentication Portal is enabled and reachable from untrusted networks.

Affected branches:

- PAN-OS 10.2 below 10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, 10.2.18-h6
- PAN-OS 11.1 below 11.1.4-h33, 11.1.6-h32, 11.1.7-h6, 11.1.10-h25, 11.1.13-h5, 11.1.15
- PAN-OS 11.2 below 11.2.4-h17, 11.2.7-h13, 11.2.10-h6, 11.2.12
- PAN-OS 12.1 below 12.1.4-h5, 12.1.7

Patches roll out between May 13 and May 28, 2026. A Threat Prevention signature for PAN-OS 11.1 and above shipped on May 5.

Mitigations before patches roll out:

- Restrict Authentication Portal access to trusted internal IPs only
- Disable the User-ID Authentication Portal entirely if not needed

Compromising a perimeter firewall as root opens the door to lateral movement, traffic interception, credential harvesting, and full network takeover. Audit Device > User Identification > Authentication Portal Settings and treat any internet-exposed portal as an emergency.

https://security.paloaltonetworks.com/CVE-2026-0300
2💯1
🚨 Germany's entire .de namespace went dark overnight. A DNS service failure at DENIC, the registry running .de, broke resolution for every signed DNSSEC-signed domain in the country for hours.

The root cause is still under investigation.
🥴10👏2😁2🎉2
‼️🇪🇺 BREAKING: Europol ran a shadow IT system stuffed with more than 2 petabytes of sensitive data on people who were never even suspected of a crime, and part of the data was kept outside of formal oversight...

This lands as the European Commission prepares to expand Europol's mandate and double its budget.

"They protect the law while breaking it," according to a former Europol senior official.

A joint investigation by Solomon, Correctiv, and Computer Weekly uncovered that Europol operated for years outside its own legal limits, with no functioning audit logs, no access controls, and admin rights handed out by the dozen.

They call the system the Computer Forensic Network, or CFN. Built in 2012 to triage forensic data, it became Europol's primary analytical platform. By 2019, the CFN held at least 2 petabytes of operational data, roughly 420 times the size of Europol's official non-forensic database. Drewer, the data protection officer, found that 99% of Europol's data sat in the CFN, processed without basic data protection or security safeguards.

The 2019 internal security assessment listed 32 separate failures. Among them:

- Ineffective assignment of security roles
- Insufficient management of privileged access rights
- Unrestricted software installation
- Lack of password management
- Lack of administrative usage logs
- Insufficient event logging and monitoring
- Insufficient network access control

Independent experts who reviewed the findings called the volume of admin accounts a textbook breach of confidentiality and an open door for both rogue insiders and external attackers. Logs could be modified or deleted by anyone with admin rights, meaning data tampering and unauthorised access could not be reliably traced.

Then there is the Pressure Cooker. A separate clandestine environment run by Europol's Internet Referral Unit, used to pull open-source data without ICT involvement and outside formal oversight. Internal staff flagged it as an "irregular situation" in October 2022. The EU's privacy watchdog, the EDPS, says it was never told about it during the original 2019 investigation.

After almost a decade of negotiation, the EDPS closed its monitoring of the CFN in February 2026. 15 of 150 recommendations remained unimplemented, including ones the watchdog flagged as concerning "issues of particular importance," covering core security safeguards.

Source:
https://www.computerweekly.com/news/366642525/They-protect-the-law-while-breaking-it-Inside-Europols-shadow-IT-system
🤬12🤯72😢1