International Cyber Digest
3.4K subscribers
178 photos
11 videos
2 files
22 links
Your weekly go-to cybersecurity newsletter, curated and commented on by our senior analysts.
Download Telegram
Media is too big
VIEW IN TELEGRAM
Join the resistance.
🀣9πŸ‘5❀2😁1
πŸš¨β€ΌοΈ"Team PCP" β€” the group behind the Trivy compromise β€” have likely hit more software vendors and repos, stealing even more credentials in the process. LiteLLM is just one of many.

More disclosures are expected in the coming days. Stay alert!
πŸ”₯1🀣1
πŸš¨β€ΌοΈ We're in contact with the actor behind the Trivy and LiteLLM hack. They told us they are currently extorting several multi-billion-dollar companies from which they've exfiltrated data.

They've obtained 300 GB of compressed credentials and are working their way through them as we speak.

The LiteLLM compromise alone led to half a million stolen credentials, according to the threat actor.

Their message to the world: "TeamPCP is here to stay. Long live the supply chain."

They've sent us their new logo (see image) and also teamed up with several threat actors, including Xploiters and Vect.
πŸ”₯8❀1
Almost 100k followers...
Time to reflect...

Thank you to my followers from the bottom of my heart...
I will never betray you...

Countless nights...
I received dick pics from haters...
I received job offers from law enforcement...
I received job offers from news outlets...
I received threats from threat actors...
I got to know my heroes...
I got to work with my heroes...
I received a lot of hate for no reason...
I received a lot of love...

I saw threat actors go to jail...
I got calls from multi-billion-dollar companies' C-level employees...
I saw legit cybersecurity professionals and their families get threatened by threat actors for doing their job...
I saw threat actors who did their time...
I saw threat actors struggle trying to stay on the right path after doing their time...

I was falsely accused countless times of spreading fake news...
I was suspended for no reason...

I picked up important research and pushed scoops into the world...
I helped journalists cover important stories...
I gave people a voice and told their stories...
I enjoyed every bit of it...

I missed a lot of time with my kids...
When others were relaxing after work, I was working...
When others were having weekends, I was working on this channel...
When others were having holidays, I was working to not miss an important story...

I have worked 80-hour work weeks for the past months...
I have developed an insane drive for this channel...

I am not in it for the money...
I am in it for the passion...

I am just one man...
I have one mission...
That is to inform you...
To create transparency...
To help SOCs/CDCs/CSIRTs...
To inform tech professionals and enthusiasts...
To not let corporations or governments get away with negligence or malice...

Almost 100k followers...
All thanks to you...
Thank you from the bottom of my heart...
❀21
πŸš¨β€ΌοΈ BREAKING: Apple has activated age verification in iOS 26.4 for UK citizens.

After updating to the latest version, users are prompted to verify their age. If you don't, some restrictions can't be overridden. And you won't be able to download or purchase certain apps.
😒7❀1πŸ‘1🀬1
❗️A hack at one of Europe's biggest football clubs Ajax made it possible to steal season tickets, attend matches, and even lift stadium bans.

RTL news found you can see which 500+ supporters are banned from the stadium and remove their bans...

Revealed by
danielverlaan
🀣9
Media is too big
VIEW IN TELEGRAM
β—οΈπŸ‡·πŸ‡Ί Russian police arrested the administrator of LeakBase, one of the world's largest cybercriminal forums.

LeakBase launched in 2021 and hosted hacked databases with hundreds of millions of usernames, passwords, bank account and routing info, and credit card numbers.
❀4🀯4
❗️Just 13 hours after TeamPCP's Trivy supply chain exploitation, one of the groups involved was already recruiting negotiators.

Today the group announced a partnership with BreachForums: every forum user automatically becomes an affiliate, with ransomware and support included.
❀5
This media is not supported in your browser
VIEW IN TELEGRAM
Saudi pranks remain undefeated πŸ˜‚
🀣9😁3❀1
A clone of Epstein’s Google Calendar with his schedule from the past 20 years.

jmail.world/calendar
πŸ‘2
‼️ BREAKING: Reddit's CEO announced he is forcing human verification on the platform.

He will force users to verify through biometrics on their device, a third party, or government ID.

Every single option compromises your anonymity. On a platform built on anonymity.

Read: https://old.reddit.com/user/spez/comments/1s3ezrc/humans_welcome_bots_must_wear_name_tags/
😒8🀣7🀬6❀1πŸ₯΄1
‼️Trivy/LiteLLM supply chain compromise update:

TeamPCP's spokesperson told us that the largest data exfiltration is multiple terabytes of government, military, and public services data, obtained through contractors of the US, UK, and Australia.

"A lot of companies hard code shit or don't gitignore .env files," they told us.
😱9
πŸš¨β€ΌοΈ BREAKING: The SQL database of BreachForums v5 has been leaked by Shiny.

Usernames, emails, passwords, and more exposed.
😱7πŸ”₯1