International Cyber Digest
4.72K subscribers
382 photos
19 videos
2 files
46 links
Your weekly go-to cybersecurity newsletter, curated and commented on by our senior analysts.
Download Telegram
โ€ผ๏ธ A good example of a ClickFix attack in the wild. These are becoming a go-to technique for threat actors, bypassing most security protections by tricking users into pasting malicious code into their own Windows terminal.

Be cautious of code you copy from the web and wary of newly registered domains.

This malicious domain was registered yesterday btw...
10๐Ÿ‘14๐Ÿ˜ฑ4โค2๐Ÿ”ฅ2
๐Ÿ‡ฑ๐Ÿ‡ง๐Ÿ‡ฎ๐Ÿ‡ฑ UPDATE: Apple responded to our inquiry. The reports of Lebanese towns being removed from Apple Maps are incorrect, they were never featured to begin with. The newer Apple Maps experience simply isn't available in that region yet.

โ€œWe are aware that some outlets have incorrectly reported that certain village and town names in Lebanon were removed from Apple Maps. These locations have never been featured. The newer, more detailed Apple Maps experience is not currently available in that region. While we continue to expand where the new maps experience is available, it is not available in all regions across the globe.โ€
๐Ÿค”14๐Ÿ’ฉ7โค4๐Ÿ”ฅ2๐Ÿ’ฏ2๐Ÿ‘1
โ—๏ธ Mozilla just called out Microsoft for force-installing Copilot on Windows systems without user consent.

After user backlash, Microsoft partially rolled Copilot back.

Mozilla: "In the most recent case, they let their AI learn and collect data as fast as possible before people had a choice."

According to Mozilla, the same tactics apply to Edge, complex processes to change your default browser, and interfaces designed to pull users back to Microsoft's own products.

Source: https://blog.mozilla.org/en/mozilla/ai/microsoft-copilot-ai-user-choice/
๐Ÿ”ฅ17โค2
๐Ÿšจ Adobe has released an emergency patch addressing the critical Acrobat Reader 0day vulnerability we reported on earlier. Update asap:
https://helpx.adobe.com/security/products/acrobat/apsb26-43.html
๐Ÿ’ฉ8
๐Ÿšจ๐Ÿ‡ณ๐Ÿ‡ฑ ChipSoft confirms the ransomware attack. They shut down the their platform since April 8.

Patient care continues, but patient portals are down and data exchange via their platform is unavailable.
๐Ÿ‘2
You can now check whether your ancestors were Nazis using a new tool introduced by a German newspaper.

They've traced 90% of all NSDAP members, totalling 10.2 million.

Link:
https://www.zeit.de/wissen/geschichte/2026-04/nsdap-vergangenheit-familie-nationalsozialismus-schweigen
๐Ÿคฃ13๐Ÿ”ฅ6๐Ÿคฏ3๐Ÿ‘2๐Ÿ˜ฑ1
๐Ÿšจ Kraken cryptocurrency exchange is being extorted following a breach traced back to an insider threat. The exchange says the threat has been identified and eliminated.
1๐Ÿ‘5๐Ÿ”ฅ2๐Ÿคฃ2
There seems to be some misunderstanding about the use of the word 'eliminated' in my previous post. To clarify: they did not kill the insider... ๐Ÿ˜‚ they eliminated the threat by identifying the insider.
๐Ÿคฃ31๐Ÿ˜4๐Ÿค”2
๐Ÿšจ BREAKING: Rockstar Games breach data obtained through Anodot has been leaked by ShinyHunters.

The files total 8.1GB and contain anti-cheat analytics, player analytics, game data, Zendesk ticket feeds, financial data and more.

25 internal data files from Rockstar Games' production Anodot analytics pipeline were obtained through breaching Anodot.

The dataset spans 7+ years of operational data (2018โ€“2026) and contains detailed financial revenue figures, anti-cheat intelligence, player economy data and customer support metrics, collectively representing one of the most sensitive internal datasets a gaming company could possess.

We will continue to analyse every leaked file. But first, here are some of the categories exposed:

- Actual dollar-value bookings for GTA Online and Red Dead Online
- Two files directly exposing Rockstar's cheat detection methodology
- Files exposing in-game data and player information

All 25 files are CSV data exports from Rockstar's Anodot production environment, covering GTA Online, Red Dead Online, customer support, and internal analytics pipelines.

As far as we can see no direct PII is present in any of these files. All data has been aggregated or stripped before being fed into Anodot.

Some fun metrics..

The COVID effect is visible in raw numbers. May 20, 2020 shows 9.34 million DAU, the highest in the entire dataset. May 16, 2020 saw 1.15 million new players in a single day, almost certainly from Rockstar's free GTA Online PS4 giveaway during lockdown.

Christmas is when Rockstar makes serious money. The top 9 highest ARPU days are all December 25th across consecutive years. Christmas 2021 is the single highest at $1.19 ARPU with a 3% conversion rate, meaning 1 in 33 players who logged in that day spent real money. Christmas 2025 ARPPU hit $60.68, meaning the players who did spend averaged over $60 in a single day.

31 rows in the PC cheat file have a value of exactly 2,147,483,647 VC. That's INT32_MAX... a signed 32-bit integer overflow. The cheat detection system literally couldn't store the number because a cheater's earn was too large for the data type. Rockstar's own monitoring tool was numerically overflowing on the cheats it was trying to track.
โค14๐Ÿ”ฅ6๐Ÿคฌ4๐Ÿฅฐ2
โ€ผ๏ธ Booking[.]com has been breached โ€” threat actors accessed customer data and reservations, and are actively abusing it.

A Reddit user says he reported the breach over two weeks ago after being phished with his own reservation details, but Booking said everything was fine on their end.

"Given how weak their security appears to be, I'm not surprised"
๐Ÿคฌ12โค3๐Ÿค”1
This media is not supported in your browser
VIEW IN TELEGRAM
The future is hereโ€ฆ Watch as a Chinese man uses AR glasses to live-translate what Russian tourists in the subway are saying.

Unfortunately, I have no idea if the translations are accurate, I don't read or understand Chinese. Nor do I understand Russian. But it looks cool!
๐Ÿ”ฅ12๐Ÿ˜2๐Ÿ˜ฑ1๐Ÿ’ฉ1