International Cyber Digest
6.84K subscribers
1.19K photos
59 videos
2 files
218 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
We just found out X didn't even reply to our second appeal. So we sent a third one, this time with a more serious tone.

Combined with challenging them into an out-of-court settlement, we hope to have our account back next week.

If not, we will take X to court.
🔥1🤡1
X's automated systems suspended our 100k cybersecurity channel, and now they're actively deleting my legal appeals from their support queue without responding.

We even subscribed to Premium Plus for premium support. There's no support at all. It's a scam.
🔥2🤡1
Thank you vx ❤️
5🤡2💩1🤪1
Hello people, I've been gone for some time. Was stuck in X suspension-hell after being targeted by threat actors who mass-reported me.

But fear not, I bribed @vxunderground with pizzas to help me get unsuspended. I'll be ordering him an extra spicy Italian sausage pizza together with some mandiapers.

I also believe he promised pizzas to anyone who would help, in my name. I guess I owe more people pizza now.

Seriously though, @vxunderground thank you so much. 🙏

And a thank you to everyone who stayed in contact with me throughout.
2🤡2💩1🤪1
‼️ An Iranian hacktivist group has compromised US medical technologies company Stryker, in retaliation for the US missile strike on an Iranian school that killed almost 168 girls aged 7-12.

Many employees had their device data wiped and cannot access their accounts.

Stryker is also a major DoD supplier of systems used to treat military personnel.
🤡1
This is a big one:

🚨‼️ BREAKING: The source code of Swedish e-government services from CGI's "E-plattform" has been leaked.

A threat actor sent us samples.

Our initial analysis shows the breached repositories originate from an internal CGI GitLab instance. The leak exposes architecture, microservices, and configurations for Sweden's digital public infrastructure.

Leaked files:
▪️ Database passwords
▪️ Email/SMTP passwords
▪️ Keystore/truststore passwords & key passwords
▪️ SHS credentials / keystore details
▪️ Signe portal credentials/config
▪️ Embedded Git credentials
▪️ CGI staff data

Key components exposed:
▪️ Mina Engagemang: Frontend and backend code (me-portals) for citizen-facing apps and case management.
▪️ Signe & e-ID: E-signature portal configs, SAML/OpenSAML metadata (keyservice), and signing workflow templates.
▪️ Företrädarregister: Authorization registry services (foreg) governing who can legally represent organizations.
▪️ SHS Integration: Routing and config files (eintegration3) for secure inter-agency data exchange.

The leaked repos contain .git/config files with embedded credentials, severely elevating the risk of lateral movement or further supply chain compromise.

A major exposure of the trust anchors and identity routing powering Sweden's digital state.

This breach was done by threat actor "bytetobreach".
2👍2🤡1
❗️This is sick: ShinyHunters have allegedly exfiltrated 1 PETABYTE of data from a single breach victim.

They're using a modified version of Google Threat Intelligence tool "Aura Inspector" to mass scan public-facing Experience Cloud sites, extracting data upon finding vulnerable instances.

Due to the countless Salesforce breaches that have occurred, the company has published a guide on how to harden against these attacks.

https://x.com/IntCyberDigest/status/2032224340133970428?s=20
👍1💩1
Sweden's biggest newspaper has now reported on our story. This is expected to be front-page news in Sweden tomorrow and will likely cause political turmoil.

We informed CERT-SE, who mailed us back saying they were already on it.
👍1💩1
WTF?

Edit: Probably a VPN (duh). But the question remains: why pick one based in the Netherlands?
👍2🔥2💩1
🇷🇺‼️ Major opsec fail:

A Russian spy was caught after using Google Translate to coordinate the murders of political enemies with foreign assassins.

He was arrested in Colombia.

The FBI read the clear-text translations of his murder-for-hire plot in real time.
👏1💩1
❗️ Great OSINT investigation by KeyserSoze1337 into ransomware group operator Rey, aka Saif Khader.

Who is known to be associated with Hellcat and ShinyHunters.

His first breach? Age 11. Running two phishing GoDaddy cPanel servers? Age 14.

https://justpaste.it/reyboom
💩1