International Cyber Digest
4.73K subscribers
382 photos
19 videos
2 files
46 links
Your weekly go-to cybersecurity newsletter, curated and commented on by our senior analysts.
Download Telegram
🚨 The Vercel breach traces back to a Context[.]ai gooner employee infected with Lumma infostealer. The malware harvested his Google Workspace credentials, porn and anime site logins, and the in-game username "lecoonjames" (see profile pic below, he changed the username post-infection, I wonder why).

Stolen records included "support@context[.]ai," assessed as a core Context-Inc Vercel team account, likely enabling privilege escalation into Vercel infrastructure.
🀣33❀2😱1😭1πŸ€ͺ1
β€ΌοΈπŸ‡«πŸ‡· The threat actor behind the ANTS breach told us he doesn't want any money, he just wanted to prove government systems are easy to hack.

ANTS was breached via an IDOR access control flaw. 80GB of passwords, source code, logs, and PII stolen.

We've seen the samples...
πŸ₯°15πŸ”₯8😁4πŸ€”2🀬2🀣1
❗️ Interesting move from the French police: they posted on a breaches forum directly from a threat actor's account after they arrested him.
🀣26🀬3
🚨 Unauthorized users have had access to Anthropic's closed model 'Mythos,' capable of finding vulnerabilities across every system and software. The users were part of a Discord group hunting for unreleased models.
😭16🀯6❀4πŸ”₯2πŸ₯°2
Oh my, if you're having a bad day you should look at this person's day. πŸ’€
😭35🀣9😁1
❗️ Meta has installed trackers on employees' computers and plans to train AI on their mouse movements and keystrokes.

At the same time, Meta is preparing to lay off 10% of its global workforce starting May 20, with more cuts to follow later this year.
πŸ’©24🀣6🀬4😒4πŸ”₯3❀2
🚨πŸ‡ͺπŸ‡Έ Ten years of piracy ends as Spanish police take down one of the largest illegal manga distribution platforms.

The site pulled in over €4,000,000 from pop-up advertising.

Police also seized two USB drives hidden inside a wall thermometer, holding cold wallets worth over €400,000.
😭24🀬8🀣1
🚨 Bybit's security team has uncovered a malware campaign targeting macOS users searching for Claude Code. SEO poisoning redirects victims to fake installer pages built to steal crypto wallet credentials and grant remote device access.
❀3πŸ₯°3πŸ”₯1😁1
🚨 Apple has finally patched the notification storage vulnerability that retained deleted messages for 30+ days, leaving them accessible to law enforcement extraction.

Happy to have contributed to this together with you, my followers, by making this go viral. πŸ’ͺ
πŸ‘27❀3πŸ”₯2😁2πŸ€”2
🚨 Password manager Bitwarden CLI v2026.4.0 was compromised in the ongoing Checkmarx supply chain campaign.

Attackers abused a GitHub Action in Bitwarden's CI/CD pipeline to ship malicious code.


Source:
https://socket.dev/blog/bitwarden-cli-compromised
🀣3❀2πŸ‘2
πŸš¨πŸ‡«πŸ‡· End of the line for 21-year-old French threat actor 'HexDex.' He’s been arrested in VendΓ©e, placed in pre-trial detention, and indicted for organized intrusion, extraction, obstruction, and fraudulent modification of state data systems.

He was preparing to sell 160M+ records on 30M people, sourced from a service used by French police.
❀2πŸ‘1πŸ€”1🀣1
πŸš¨πŸ‡©πŸ‡ͺ Russian intelligence fully compromised the Signal account of Germany's parliament speaker Julia KlΓΆckner by pretending to be Signal support.

She is the second-highest state official and shared a CDU executive Signal group with Chancellor Merz. His phone came back clean, hers did not.

The Signal hack goes way beyond KlΓΆckner. 300+ are confirmed German victims, including a top CDU MP and the ex-deputy chief of German foreign intelligence.

German counterintelligence says parliamentary group chats are likely being read live, right now.

The FBI and CISA peg global victims in the thousands.
🀣7😭4❀2😁1