International Cyber Digest
4.72K subscribers
376 photos
19 videos
2 files
45 links
Your weekly go-to cybersecurity newsletter, curated and commented on by our senior analysts.
Download Telegram
🚨 According to sample data we received from the Vercel breach, Vercel's CEO Guillermo Rauch was last seen on March 3, 2026. Who is running the company?

The threat actor told us Vercel's security was poor, and consistent with Vercel's own disclosure, a senior engineer authenticated with a fake third-party AI tool via its Google Workspace OAuth app.

- The breach appears to have started or ended on April 12, 2026
- We were sent records of all employees...
7🤣6🔥2
🚨🇫🇷 France's ANTS portal, the government system issuing IDs, passports, and driver's licenses, has been breached.

Up to 19 million French citizens may be affected. ANTS has confirmed the breach.

Exposed fields include full name, email, address, date and place of birth, phone number, and identity verification data. Confirmed by the Ministry of the Interior.
🤣14🎉10😭4😁3😍21🔥1
🚨‼️ A Dutch NATO ship escorting France's nuclear flagship carrier Charles de Gaulle was tracked via a cheap Bluetooth tracker, mailed to the vessel inside a greeting card by a Dutch TV station.

The Dutch military postal system missed the device entirely. The Ministry of Defense has now banned greeting cards with batteries.
1🤣454
🚨 The Vercel breach traces back to a Context[.]ai gooner employee infected with Lumma infostealer. The malware harvested his Google Workspace credentials, porn and anime site logins, and the in-game username "lecoonjames" (see profile pic below, he changed the username post-infection, I wonder why).

Stolen records included "support@context[.]ai," assessed as a core Context-Inc Vercel team account, likely enabling privilege escalation into Vercel infrastructure.
🤣332😱1😭1🤪1
‼️🇫🇷 The threat actor behind the ANTS breach told us he doesn't want any money, he just wanted to prove government systems are easy to hack.

ANTS was breached via an IDOR access control flaw. 80GB of passwords, source code, logs, and PII stolen.

We've seen the samples...
🥰14🔥8😁4🤔2🤬2
❗️ Interesting move from the French police: they posted on a breaches forum directly from a threat actor's account after they arrested him.
🤣24🤬2
🚨 Unauthorized users have had access to Anthropic's closed model 'Mythos,' capable of finding vulnerabilities across every system and software. The users were part of a Discord group hunting for unreleased models.
😭15🤯63🔥2🥰2
Oh my, if you're having a bad day you should look at this person's day. 💀
😭33🤣7😁1
❗️ Meta has installed trackers on employees' computers and plans to train AI on their mouse movements and keystrokes.

At the same time, Meta is preparing to lay off 10% of its global workforce starting May 20, with more cuts to follow later this year.
💩18🤣5😢4🤬32🔥2
🚨🇪🇸 Ten years of piracy ends as Spanish police take down one of the largest illegal manga distribution platforms.

The site pulled in over €4,000,000 from pop-up advertising.

Police also seized two USB drives hidden inside a wall thermometer, holding cold wallets worth over €400,000.
😭17🤬7
🚨 Bybit's security team has uncovered a malware campaign targeting macOS users searching for Claude Code. SEO poisoning redirects victims to fake installer pages built to steal crypto wallet credentials and grant remote device access.
2🥰1
🚨 Apple has finally patched the notification storage vulnerability that retained deleted messages for 30+ days, leaving them accessible to law enforcement extraction.

Happy to have contributed to this together with you, my followers, by making this go viral. 💪
👍6