Cyber Dispatch™️
386 subscribers
22 photos
1 video
56 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
EU fines X $140 million over deceptive blue checkmarks.
Maximum-severity XXE vulnerability discovered in Apache Tika.
Barts Health NHS discloses data breach after Oracle zero-day hack.
North Korean hackers are pushing fake "Microsoft Teams Update" to macOS.
New wave of VPN login attempts targets Palo Alto GlobalProtect portals.
React2Shell flaw exploited to breach 30 orgs, 77k IP addresses vulnerable.
The Webshell Underground: Student Hacker Selling PHP Backdoors To Asia-Based Threat Actors To Pay for School.
Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks.
CISA added the new 10.0-rated React RCE flaw (CVE-2025-55182) to its exploited list.

Exploited within hours by Chinese hackers.
Affects Next.js, React Router, Vite, Waku & more.
Some attacks dropped crypto-miners & stole AWS creds.
A new attack can trick Perplexity’s Comet browser into deleting your Google Drive.

Just one normal-looking email with hidden cleanup instructions can make the AI agent erase real files — no exploit, no warning.
Critical Apache Tika flaw (CVE-2025-66516) just dropped — CVSS 10.0.

A single fake PDF can trigger an XXE attack, letting hackers read server files or run code.
A lawyer in Pakistan was hacked with Predator — the first known spyware attack on a civil society member.

It started with a link on WhatsApp, but new leaks show Predator can also spread through ads — no click needed.

It can read chats, record audio, take photos — and Intellexa may still access customer systems remotely.
CISA just warned about a new Chinese state-backed hack tool called BRICKSTORM — a backdoor found in VMware and Windows systems used by U.S. government and tech networks.

It can reinstall itself if removed, hide in normal traffic, and give hackers full remote control.
Hackers are exploiting a command injection bug in Array Networks AG Series gateways — active since August 2025.

It lets attackers run any command on systems using “DesktopDirect” remote access.
A fake Microsoft Teams installer is spreading malware in China.

Hackers called "Silver Fox" made it look like a Russian attack to hide their tracks.

It installs ValleyRAT, giving full remote access to victims.
Thousands hacked after downloading what looked like “official” government apps.

They were fake versions of real banking apps, modified by hackers from GoldFactory to include malware.

So far, over 11,000 phones in Southeast Asia have been infected.
Cloudflare just stopped the largest DDoS attack ever — a 29.7 Tbps strike from the AISURU botnet that used up to 4 million hacked devices.

It hit 15,000 ports every second for 69 seconds before being blocked.
A major WordPress flaw is being exploited right now.

The King Addons for Elementor plugin let anyone sign up as an admin — no login needed.

Over 48,000 attack attempts have been blocked since October.
Businesses are facing a new threat!

#Salty2FA and #Tycoon2FA are now attacking together. The #phishing campaign that's just been discovered is stealing corporate logins at scale.
Three critical flaws just found in Picklescan — the open-source tool made to detect unsafe PyTorch models.

Attackers could use them to slip in malicious code and bypass its scans.
GlassWorm is back.

24 fake VS Code and Open VSX extensions are stealing developer credentials — spreading through popular names like Flutter, React, and Tailwind.

The malware hides its control data on the Solana blockchain and runs Rust implants on both Windows and macOS.