Cyber Dispatch™️
307 subscribers
17 photos
1 video
37 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Loran Synaro — the legend of Anonymous collective. Many followed his footsteps. After LulzSec, he brought Anonymous hacktivism back to the spotlight. One could say… resurrected.
Twitter suspended his account. Some say he was one of the founders of the game — Cicada 3301. Also a founder of Ghost Sec. An OpIsrael hacktivist account. Gone. The game remains. No one knows who really runs it. No one ever will.
OpIsrael hacktivists are being targeted on X by the U.S. government due to fears that they may join the Iranian cyber war against America. Fundamentally, the U.S. has gotten it wrong. Furthermore, Elon Musk poses a danger to activists and hacktivists alike. He should be held accountable.
DPRK-linked attackers used GitHub as C2 in phishing-led attacks on South Korean orgs.

LNK files trigger hidden PowerShell, set persistence, and exfiltrate system data to attacker repos while pulling new payloads.
Attackers now move across Windows, macOS, Linux, and mobile in one campaign.

Multi-OS attacks break SOC workflows, splitting one threat into many investigations and slowing validation.

That delay gives attackers time to spread and persist.
A compromised AI library exposed developer machines.

1,705 packages pulled infected LiteLLM versions, harvesting SSH keys and cloud creds from local systems via dependencies.

It worked because secrets sit in plaintext across files and tools.
AI isn’t making attacks smarter, says Martin Zugec, Technical Solutions Director at Bitdefender. It’s making them cheaper and easier to scale.

Current AI malware is often unreliable and less advanced, but it can hit thousands of standardized systems fast.
Qilin and Warlock #ransomware are disabling defenses before attacks using BYOVD techniques.

Qilin uses a side-loaded DLL to kill 300+ EDR drivers via vulnerable kernel drivers. Warlock exploits SharePoint and uses similar drivers to bypass kernel-level security, often delaying ransomware execution.
Germany’s BKA has identified a key figure behind the REvil #ransomware group.

Daniil Shchukin (“UNKN”) is accused of leading REvil, linked to 130 attacks in Germany causing over €35.4M in damage, with €1.9M in ransom paid.
Forbes reports the Middle East is now engaged in the most complex form of cyber-physical warfare.

The conflict between Iran, the United States, and Israel has evolved into simultaneous kinetic and cyber fronts. Cyber operations are no longer auxiliary — they are direct instruments of targeting and escalation.

Surveillance infrastructure, mobile devices, and cloud systems have become battlefield assets. Civilian networks and businesses are now frontlines.

#CyberWarfare #Infosec #Geopolitics
The Ghost in the Machine — she was the first to be suspended. Fifteen thousand followers, erased. X didn't stop there. Gradually, her follower count was drained. Ten thousand remained. Then came the protests against ICE. While others stayed silent, her account stood firmly against ICE's crackdown. A profile born from OpIsrael changed its direction — to support immigrants in the United States. And for that… X suspended her. No reason. No warning. Just silence.

#TGITM @TheGhostITM
German .NET decompiler ILSpy's site (ilspy.net) compromised—users hit with redirects to extension downloads & malicious EXE files (flagged on VT). Site was down briefly, still vulnerable.

Redirect infra traces to Israel-hosted domains, hinting at targeted op.
ILSpy (German OSS tool by icsharpcode) website hacked, serving pop-ups, shady extensions, and trojanized EXEs via redirects. Not Israeli despite "IL" (it's Intermediate Language).

Israeli IP/domains in attack chain.
A BreachForums administrator has allegedly been identified — caught using his real IP and reusing the same passwords across his criminal persona and business accounts.

Meet Angel Tsvetkov AKA N/A: a Bulgarian cybersecurity specialist, penetration tester and bug bounty researcher known for responsibly disclosing vulnerabilities in major global platforms.
France just mandated digital ID for every citizen by banning social media for minors.

Under 15s will be blocked from IG, TikTok, FB, Snapchat and any platform allowing interactions, public broadcasts or user communities.
Forwarded from 𓂆 Palestine
The Handala hacker group:

"Colonel, Air Force Lady; You have only tonight. We suggest you check your phone right now… You wouldn’t want us to talk about your meeting with us in Uzbekistan tomorrow, would you?

Remember, some encounters don’t stay in the past forever The choice is yours; The shadows see everything.

This is your last warning tonight;

Handala gives you only until tomorrow morning. You didn’t see this coming, did you? Sometimes, the shadows are closer than you think… The choice is yours; After sunrise, everything will change."
Handala hacker group claims first-ever leak of photo showing Elbit Systems Hermes drone design team

The hacker group Handala has released a statement claiming it has published, for the first time, an image showing what it describes as the core design and development team behind the Hermes drone program at Elbit Systems.

In its statement, the group asserted that the Hermes drone project has long been concealed under strict security measures, and framed the image leak as the beginning of a broader effort to expose what it called “hidden aspects” of Israeli occupation military and security programs.

Handala added that further details, including additional information and names, would be released in subsequent disclosures. "This image marks only the beginning of uncovering the hidden aspects of the Zionist regime’s military and security projects," they wrote.

#TGITM @TheGhostITM
Hacker group Handala:

All data concerning the sensitive electrical infrastructure of the Zionist regime has been extracted by Handala.

#TGITM @TheGhostITM
Microsoft fixes email sending disruption in classic Outlook

Microsoft has resolved a technical issue in classic Outlook that caused some users to be unable to send emails via Outlook.com.
The FBI has declared a “major cyberattack.”

A group called Salt Typhoon breached the same systems the FBI uses for surveillance.

Leaked data reportedly includes phone numbers of active FBI surveillance targets.
2