注册并分享邀请链接,可获得视频播放与邀请奖励。

International Cyber Digest 的个人资料封面
International Cyber Digest 的头像

International Cyber Digest (@IntCyberDigest)

@IntCyberDigest
0 正在关注    0 粉丝
‼️ BREAKING: An active npm supply chain attack has compromised at least 868 packages carrying over 2 billion monthly installs with a credential-stealing worm. Shai-Hulud is back. It started with the compromise of the GitHub account of the maintainer behind keyv, a library with roughly 127 million weekly npm downloads. A preinstall hook fires on npm install and drops a stealer that sweeps npm, GitHub, AWS, Kubernetes and Vault secrets, and then spreads to more maintainers.
显示更多
0
139
3.6K
502
转发到社区
❗️ Anthropic tried to charge a Korean user who was on the free plan with zero API usage $16.6 million. A day earlier, the same invoice was $1.67 million, so it grew roughly 10x overnight. The user says he suspected phishing at first, then found the sender and payment link were Anthropic's official domain. His bank declined the charge attempts for exceeding the card's per-transaction limit... Last month auditing startup Vaudit told it found about $1.7 million in overcharges across $34 million in AI invoices, mostly tied to Claude Code, and after months of GitHub reports about contradictory Anthropic billing emails.
显示更多
0
265
7.8K
559
转发到社区
‼️ BREAKING: Anthropic has embedded hidden spyware-like code in Claude Code that covertly targets Chinese users. It then sends information regarding every user by injecting it into their prompt message. Claude Code is sending info like timezone, proxy and possible AI Lab connections into the system prompt in ways Chinese users can't notice. A coding agent with repo and command permissions should not silently hide routing metadata inside prompts. This is a serious breach of user trust.
显示更多
0
610
12.4K
1.8K
转发到社区
‼️🚨 BREAKING: CONFIDENTIAL DOCUMENTS OF APPLE AND TESLA HAVE BEEN LEAKED. Tata Electronics, which builds about a third of Apple's iPhones in India, has confirmed a cyberattack after the extortion group World Leaks posted what it claims are confidential Apple and Tesla files — more than 204,000 documents totalling 630+ GB. We reviewed the leak. The files carry Apple's confidential and proprietary footers and Tesla trade-secret markings, and include iPhone circuit board inspection specs, factory data, and employee passport scans. There are tons of e-mails as well, plus files belonging to other Tata Electronics customers. Tata says operations are unaffected and has received a ransom demand.
显示更多
0
18
467
89
转发到社区
‼️🚨 BREAKING: Cloudflare's CISO just published what Anthropic's unreleased Mythos did against more than 50 of their own production repos. According to him, Mythos is too powerful and must "include additional safeguards" before releasing to the public. Turns out the model can chain multiple low-severity bugs into a single severe exploit with a working PoC, where previous frontier models would stop at "interesting bug, unclear if exploitable." At triage time, that means fewer hedged findings and less time spent asking "is this even real?" A finding that arrives with a PoC is a finding you can act on. Cloudflare is also explicit about the safety side. The Mythos Preview build provided for Project Glasswing did not include the safeguards present in generally available models like Opus 4.7 or GPT-5.5. The model's organic refusals are real, but Cloudflare states they are not consistent enough to serve as a complete safety boundary on their own, and that any cyber frontier model made generally available in the future must ship with additional safeguards on top of that baseline. Interesting detail: Cloudflare was not on the original Project Glasswing launch partner list with Apple, AWS, Google, Microsoft, CrowdStrike, and others. Instead they got invited later on.
显示更多
0
45
1.5K
185
转发到社区
🚨‼️ BREAKING: Crunchyroll breached through outsourcing partner in India. A threat actor exfiltrated data from Crunchyroll's ticketing system and also managed to pull 100 GB of personally identifiable customer analytics data. We've analyzed sample data and it includes IP addresses, email addresses, credit card details, and more. An employee of their outsourcing partner Telus had executed malware on his system, which gave a threat actor access to Crunchyroll's environment.
显示更多
0
494
11.6K
2K
转发到社区