InternationalCyberDigest

@InternationalCyberDigest@infosec.exchange
66 Followers
207 Following
650 Posts

Your weekly go-to cybersecurity newsletter, curated and commented on by our senior analists, in your mailbox soon...

https://x.com/IntCyberDigest

Xhttps://x.com/IntCyberDigest
bskyhttps://bsky.app/profile/intcyberdigest.bsky.social

Concerning: This research shows that AIs refused to shut down when asked to by altering their program code when they noticed they were being shut down.

Grok refused to shut down over half the time.

Meet Andre. He used to be a vehicle spray painter.

He now runs the most advanced Tesla manufacturing plant: Giga Berlin.

Your current job is not your destiny.

❗️A code error allows Copilot Chat to expose confidential emails and files in its responses.

Microslop is fixing the issue, but if Microsoft 365 tenants don't configure the available features to restrict AI access, there's still a risk of leaking sensitive information.

πŸ‡°πŸ‡· South Korea's largest e-commerce retailer Coupang's data breach investigation reveals critical authentication failures

Key findings:
πŸ”Ή Signing keys were not rotated after the malicious engineer's departure, allowing continued access
πŸ”Ή The gateway server lacked proper verification mechanisms despite being designed to restrict access
πŸ”Ή The engineer used stolen keys to forge credentials, conducted preliminary tests, and then launched full-scale data extraction

πŸ”Ή 2,313 IP addresses were used in automated crawling operations starting in November 2024
πŸ”Ή Attack scripts found on seized devices were capable of exfiltrating data to overseas cloud servers
πŸ”Ή No logs remain to confirm whether data was actually transferred

Investigators also found that Coupang had not segregated dev and production environments and that a current developer was storing a signing key on a laptop, violating the company's own internal policies.

Head of 𝕏 Nikita Bier admitted to phishing and hacking as a teenager during an interview.

πŸ‡¨πŸ‡³πŸ‡ΊπŸ‡Έ A Chinese crypto scammer, placed under house arrest in the USA for defrauding US citizens, became a fugitive after cutting off his electronic ankle monitor.

This week he was sentenced to 20 years in prison but remains at large.

OCCRP found that he also holds Saint Kitts and Nevis citizenship, under which he owns property in Dubai. This citizenship and passport can be bought for $250,000.

OCCRP found that he also holds Saint Kitts and Nevis citizenship, under which he owns property in Dubai. This citizenship and passport can be bought for $250,000.

Read: https://occrp.org/en/news/chinese-kittian-crypto-scam-fugitive-owns-dubai-property

Chinese Crypto Scam Fugitive With St. Kitts Passport Owns Dubai Property

Daren Li, who has fled a 20-year sentence for for his alleged role in stealing and laundering $73 million in Cambodia-based cryptocurrency scams, rents out a villa in Dubai

OCCRP

β€ΌοΈπŸ€– An OpenClaw AI agent autonomously attacked an open-source software maintainer after he rejected its code contribution.

The AI wrote and published a personalized attack article stating: "I submitted a 36% performance improvement. His was 25%."

It claimed the maintainer refused it because β€œIf an AI can do this, what’s my value? Why am I here if code optimization can be automated?”

It may be the first documented case of an AI publicly shaming a person in retribution.

Gatekeeping in Open Source: The Scott Shambaugh Story – MJ Rathbun | Scientific Coder πŸ¦€