International Cyber Digest
4.73K subscribers
382 photos
19 videos
2 files
46 links
Your weekly go-to cybersecurity newsletter, curated and commented on by our senior analysts.
Download Telegram
‼️ Booking[.]com has been breached β€” threat actors accessed customer data and reservations, and are actively abusing it.

A Reddit user says he reported the breach over two weeks ago after being phished with his own reservation details, but Booking said everything was fine on their end.

"Given how weak their security appears to be, I'm not surprised"
🀬12❀3πŸ€”1
This media is not supported in your browser
VIEW IN TELEGRAM
The future is here… Watch as a Chinese man uses AR glasses to live-translate what Russian tourists in the subway are saying.

Unfortunately, I have no idea if the translations are accurate, I don't read or understand Chinese. Nor do I understand Russian. But it looks cool!
πŸ”₯12😁2😱1πŸ’©1
🚨 A fake Ledger Live app in the Apple App Store led to $9.5M stolen from over 50 victims in under one week, according to recent work by crypto detective ZachXBT.

The app even has fake 5-star reviews describing it as "incredibly smooth and reliable."

ZachXBT has mapped all suspected victims in a recent post in his Telegram channel.

The app was released by developer "SAS Software Company" and published under "Leva Heal Limited".

Link to fake app: https://archive.ph/4RVLf
🀣6🀯2
‼️ The CEO of PUBG's owner Krafton used ChatGPT to design a corporate takeover strategy to block an acquired studio from earning a $250M payout.

ChatGPT codenamed it "Project X", and suggested locking their Steam account to prevent Subnautica 2's launch. He followed it, against his legal team's advice. He then went on to delete his ChatGPT logs.

Source: https://courts.delaware.gov/Opinions/Download.aspx?id=392880
🀣22❀1πŸ”₯1😁1
No way πŸ˜‚ A Redditor installed malware without realising it, it kept changing his browser's search engine to Yahoo. Instead of removing the malware, he vibecoded a browser extension that also acts like malware to redirect Yahoo back to Google and published it in Google Web Store.

He has absolutely no intention of removing the malware or bloatware. Instead he says this is not a solution, but it makes "the experience less annoying."

You can now download and install his extension... Although I wouldn't recommend it. LOL.
😭30❀4😱1
‼️ It amazes me that Signal, with "state-of-the-art E2E encryption" and a promise that "no one else can" read your messages, fails to turn off notification previews by default, while it has been known for over a decade that Apple stores them cleartext in notification storage.

Remember folks.. even your disappearing messages and deleted messages are still stored in your iOS notification storage when notification previews are on... For 1-2 months.. just sitting there waiting for whoever has the means to extract them...
πŸ₯΄9😱4😁3❀1πŸ‘1
🚨 SPGlobal and Guesty have been listed as supply chain attack victims on Vect ransomware's vibe-coded website. Their data will be published in a couple of days.
❗️X lost its 4th court battle today against a European user β€” a tech lecturer who filed a GDPR data request after getting shadowbanned. He just wanted to see his data.

X intimidated the plaintiff after their first loss by sending two lawyers to one of his lectures at Leiden University. X then asked the court to impose a gag order on him, claiming he was talking about the case during his lecture β€” which he wasn't.

Elon Musk promised more transparency on X in 2022, including on shadowbans β€” where an account isn't actually banned, but its posts are quietly suppressed and hidden from search results. X has been doing exactly the opposite ever since the ownership changed.

For example, X is the only tech giant exploiting a loophole against Out-of-Court Dispute Settlement Bodies in the EU β€” by simply not paying them. These are independent, certified entities designed to resolve disputes between users and platforms over suspensions, shadowbans, etc. Because X doesn't pay, all of these bodies refuse to take on X cases.

X users are the only major platform users in Europe who are effectively forced to sue in court just to get their rights.

Source: https://uitspraken.rechtspraak.nl/details?id=ECLI:NL:GHAMS:2026:961
πŸ‘6❀4
🚨 Element[.]io is experiencing a worldwide outage due to "legal reasons."

Element is a free and open-source instant messaging client based on the Matrix protocol. It provides secure, end-to-end encrypted communication for individuals, teams, and organizations.

They're working on getting it fixed right now.
😒11
β—οΈπŸ‡ΊπŸ‡ΈπŸ‡°πŸ‡΅ Two U.S. nationals have been sentenced to 108 and 92 months in prison for running North Korean IT "laptop farms" that helped North Koreans pose as Americans and get hired at over 100 U.S. companies, including Fortune 500s.

The scheme generated $5M+ in revenue for North Korea, and gave them access to confidential data, including US defense contractor files.

https://www.justice.gov/opa/pr/two-us-nationals-sentenced-facilitating-fraudulent-remote-information-technology-worker
😁9πŸ‘3🀬3😒2πŸ€”1