International Cyber Digest
4.47K subscribers
334 photos
17 videos
2 files
42 links
Your weekly go-to cybersecurity newsletter, curated and commented on by our senior analysts.
Download Telegram
Claude Code uses axios btw ๐Ÿฅด
๐Ÿ˜ญ21๐Ÿ˜5๐Ÿฅด3
Forget the Strait of Hormuz. The world economy now relies on the compromised lead axios maintainer finding a GitHub contact on X...
๐Ÿ˜15๐Ÿ˜ญ7๐Ÿ”ฅ2
Ainโ€™t no npm package crisis complete without this meme ๐Ÿ˜‚
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿคฃ30๐Ÿ˜4
โ€ผ๏ธ Meet the guy almost everyone loves for alerting the axios devs about the supply chain attack.

He built a supply chain monitoring system last week, and was alerted within minutes of the axios compromise.

The world should be thanking Elastic Security's finest:
Joe
X:dez_
๐Ÿคฃ14โค4๐Ÿ™3
This media is not supported in your browser
VIEW IN TELEGRAM
Joe is our saviour. Respect Joe.
๐Ÿคฃ13๐Ÿฅฐ9๐Ÿ’ฉ1
โ€ผ๏ธ Tomorrow we're dropping a TeamPCP supply chain attack victim list, including verification status and more.

Got tips? DM us or use our Signal (see bio).

โค๏ธ rodents.
โค15
๐Ÿšจโ€ผ๏ธ BREAKING: Anthropic has decided to open source their entire codebase and is rebranding their AI to OpenClaude.

Anthropic CEO Dario Amodei said: "Yesterday was no slip-up. If we disappear just like OpenAI is vanishing right now, our code can live on through the community."
๐Ÿคฃ71โค13๐Ÿ”ฅ7๐ŸŽ‰4๐Ÿฅฐ2๐Ÿฅด1
๐Ÿ˜ญ25๐Ÿคช6๐Ÿ”ฅ3๐Ÿ˜2
We're so cooked! ๐Ÿ˜ฑ
๐Ÿคฃ40๐Ÿ˜ฑ6๐Ÿ˜3
โ€ผ๏ธ TeamPCP and ShinyHunters are threatening each other right now. A ShinyHunters spokesperson told us:

"TeamPCP/SkidPCP can do nothing. A better name for them is 'VibePCP' because all they can do is use AI.

It's good we robbed them because we made better use of the credentials than they ever could.

We bet they wouldn't even know what IAM is on AWS.

Maybe they should've asked AI to help secure their storage server so it wouldn't get hacked and backdoored by us."

ShinyHunters declined to comment further, instead they will leak all the data on them (first names: R. is PCP, A. is Vect), along with all their chat logs.
๐Ÿคฃ15โค2
๐Ÿšจโ€ผ๏ธ We've just launched a central dedicated tracker for all alleged TeamPCP supply chain attack victims.

https://teampcp.cyberdigest.international ๐Ÿ‘€

We know the full list would be hundreds if not thousands of victims long, but this is all we could get our hands on.

We welcome feedback and community input. If you can help confirm the status of any alleged TeamPCP victims, reach out.

โ—๏ธA note on sourcing: most of our information came from insiders who infiltrated TeamPCP.
โค4
โ€ผ๏ธ๐Ÿ‡บ๐Ÿ‡ธ Lockheed Martin has allegedly been breached and 375TB of data is being offered for sale on what appears to be a Russian 'Threat Market'.

They've priced the highly confidential data at $598 million...
๐Ÿคฃ21โค2
๐Ÿšจ๐Ÿ‡ฎ๐Ÿ‡ท BREAKING: Iranian nation-state threat actor Handala has breached Israeli defense contractor PSK Wind Technologies.

They've released confidential files showcasing top secret communications systems, internal documents, location photos and more.
๐Ÿคฃ23โค4๐Ÿฅฐ3