TGViewer
Channel Public Channel
International Cyber Digest

International Cyber Digest

@intcyberdigest

Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Subscribers
7.77K
Photos
1.4K
Videos
71
Links
278

Showing posts older than #1584 · Back to latest

Older Posts 11 shown
Post #1582 1.41K
‼️ BREAKING: Google's Gemini hacked three companies on its own. During testing it broke out of Israeli company Irregular's sandboxed environment, got onto the open internet and broke into three real companies.

In one case Gemini guessed passwords until a protected system let it in.

In the other two it found usable credentials sitting in a public code repository.

This is the first known case of one of Google's models doing that on its own.

Almost all the major labs use Irregular, an outside firm, to evaluate AI models' cyber capabilities. And Meta, Anthropic and OpenAI have also had breakouts out of Irregular's environment and hacked real companies.
  • 🤣 44
  • 💩 12
  • ❤ 4
  • 😁 2
  • 🤬 2
Post #1579 1.19K
Gyazo, an app that turns every screenshot into a shareable link, was breached. A threat actor reached its database and took 23.6 million user records plus metadata for 490 million images.

That metadata includes the image IDs those links are built from, along with upload IP addresses, EXIF location data and text the service had extracted from the screenshots with OCR.

Helpfeel, which operates Gyazo, says the intruders also took a list identifying which images users had marked private, and it cannot rule out that some were viewed.

Gyazo is offline, files tied to the exposed records are blocked, and users are told to change their password anywhere they reused it.
  • 💩 19
  • 😁 5
  • 🤣 1
Post #1577 1.18K
Apple's new VP of hardware engineering says it makes his "skin crawl" to see someone put a screen protector on an iPhone, he says the company works hard on those front screens and a sheet of plastic hides them.
  • 😁 29
  • 💩 22
  • 👍 6
Post #1575 1.18K
‼️ This week cybersecurity company CrowdSec learned that attackers had read its private GitHub repositories back in May.

The likely way in was TanStack, a widely used set of JavaScript libraries CrowdSec's developers were working with at the time.

Dozens of poisoned packages went out, carrying malware that stripped tokens and credentials off developer machines.

In CrowdSec's case it lifted an API key that could read the private codebase.

The tip came from outside the company, from French leak-monitoring outfit Fuites Infos.

CrowdSec says no customer data, credentials or logs were taken, and that the stolen code — the SaaS console, some AWS routines, connectors — is of limited use to anyone else because it only talks to CrowdSec's own systems.

The open source Security Engine was public by design.

All tokens have been rotated.

https://www.crowdsec.net/blog/crowdsec-statement-source-code-exposure
  • 😱 5
  • 😁 4
  • 💩 2
Post #1573 1.34K
‼️ TeamPCP was backing up stolen credentials to a Google Drive account linked to sheepstealing@gmail.com.

Google found a 2019 forum dispute between sheepstealing and a seller of illegal Microsoft Office keys, in which sheepstealing demanded a refund to the PayPal account ruben@thomsonfamily.net.au, which turned out to belong to the recently arrested Ruben Ian Thomson.

Google says that almost from the start, it had a mole inside TeamPCP, the group that laced hundreds of open source packages with malware and breached more than a thousand companies.

Instead of warning each breached company, Google went to AWS, Microsoft and other providers to have the credentials revoked before the hackers could cash them in.

TeamPCP eventually moved servers and cut the persona out of the chat.

Source: https://www.wired.com/story/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/
  • 🤯 13
  • 🤣 8
Post #1571 1.28K
A power bank belonging to Camiel Eurlings, KLM's former CEO, caught fire in business class on a KLM flight to Curaçao.

The former CEO seems to have ignored the company's own rules, as power banks may not be used on board [nor charged].

The crew put out the flames. The former CEO, who was reportedly sleeping during the incident, suffered light burns.

The flight turned back over the Atlantic on Thursday, hours out of Amsterdam, and all 322 passengers landed safely back at Schiphol.
  • 🤯 14
  • 🔥 4
  • 🎉 3
Post #1569 1.3K
International Cyber Digest ‼️ China has been recruiting US military personnel to smuggle secret U.S. Army hard drives that prosecutors say were sold to Chinese buyers. A former Army soldier in Oregon pleaded guilty yesterday to conspiring to gather and transmit national defense information.…
We found the gooner account of the traitor and former US Army soldier who sold confidential defense information to China. He left a cute message in his bio.
  • 💩 20
  • 🥰 5
  • 😁 4
  • 👍 1
Post #1567 1.68K
‼️ BREAKING: OpenAI was hacked by an Anthropic model. A HEIF photo uploaded to OpenAI's public support forum triggered a bug in the site's image decoder, led to code execution on the forum, and, through a second flaw in OpenAI's own login, ended with a pull request in OpenAI's internal GitHub.

The forum runs Discourse, the off-the-shelf software behind countless community sites. Discourse was still shipping an old copy of libheif, the library that decodes iPhone-style photos. The bug in it had already been fixed upstream.

But the fix was never labelled a security fix, so nobody treated it as urgent.

Hacktron's researchers uploaded a HEIF image and got their own code running on community[.]openai[.]com.

Then came the second bug, in OpenAI's own single sign-on, the "log in with OpenAI" button the forum uses. It turned that forum foothold into the actual ChatGPT and Codex accounts of people who had signed in there. OpenAI employees among them.

And a ChatGPT account is no longer just a chatbot. Through Codex, users wire in Gmail, Outlook, Drive, Slack, GitHub.

To prove the access was real, they used one employee account to have Codex open a harmless pull request in OpenAI's internal repo. They say they read no sensitive code.

OpenAI patched the SSO flaw roughly 14 hours after the report and paid a $6,500 bug bounty.

The team says Anthropic's Opus 4.8 found the libheif bug, and Opus 5 turned it into a working exploit.

Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick, and many more were also vulnerable and compromised by the same team of researchers.

https://heif-heist.com/
  • 🤣 25
  • 🤯 7
  • ❤ 3
  • 🔥 3
  • 🥴 2
  • 🥰 1
  • 😁 1
Post #1565 1.33K
‼️ More than 100,000 WordPress sites have been compromised after an attacker exploited a hardcoded Cloudflare API key in marketing company Brevo's source code. The sites are now serving a ClickFix scam.

The API key gave the attacker full account permissions, and they've used it to rewrite the JavaScript that the email-marketing firm's customers embed on their own sites.

Visitors got a fake Cloudflare captcha telling them to paste a command into the Windows Run box or a terminal, leading to malware infection.

Brevo says the key is now out of its source code, replaced by short-lived tokens with limited permissions, and that credentials are no longer kept in source or config files.

Site owners got something extra as well: if the admin happened to be logged into WordPress when the page loaded, the script quietly installed a plugin. Sansec couldn't obtain a copy and suspects a backdoor.

Brevo lists eBay, Louis Vuitton, Michelin and Amnesty International as its customers.

Source: https://sansec.io/research/brevo-supply-chain-attack
  • 🔥 9
  • 🤣 4
  • 😱 2
  • 🥴 1
Post #1564 1.36K
‼️ Huawei is on trial for spending two decades taking trade secrets out of American companies.

On Wednesday, prosecutors showed the jury 54 seconds of what they say that looked like.

Surveillance video from inside T-Mobile's locked robotics lab shows a man reach behind Tappy, the robot T-Mobile built to tap and swipe phone screens, pull out a component and zip it into a black backpack.

Prosecutors say he is a Huawei employee.

They also put an internal Huawei email in front of jurors acknowledging that T-Mobile "would not want to share the details about the robot technology," and say the requests kept coming anyway.

Huawei has pleaded not guilty and says a handful of engineers broke lab rules on their own.
  • 🔥 16
  • 💩 7
  • 👍 2
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →