Cyber Dispatch™️
386 subscribers
22 photos
1 video
56 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
GlassWorm is back.

24 fake VS Code and Open VSX extensions are stealing developer credentials — spreading through popular names like Flutter, React, and Tailwind.

The malware hides its control data on the Solana blockchain and runs Rust implants on both Windows and macOS.
Israel has signed off on a $725M propaganda budget for 2026 to polish its global reputation.
Portugal updates cybercrime law to exempt security researchers.
Porsche outage in Russia serves as a reminder of the risks in connected vehicle security.
Hackers are hiding malware in normal websites.

A new attack called JS#SMUGGLER plants code that quietly runs PowerShell through mshta.exe to install NetSupport RAT — giving attackers full control of your computer.

It even checks your device type to avoid being caught.
Three new Android threats just dropped:

• FvncBot – fake “mBank” app that logs keys, streams screens, and steals banking data.
• SeedSnatcher – spreads via Telegram to steal crypto seed phrases and 2FA codes.
• ClayRat – upgraded spyware faking YouTube & taxi apps for full device control.

All abuse Android’s accessibility features.
Hackers are exploiting a bug in the Sneeit Framework plugin (CVE-2025-6389) to run code on servers and create admin accounts on WordPress sites.

Separately, a flaw in ICTBroadcast (CVE-2025-2611) lets attackers use the BROADCAST cookie for unauthenticated remote shell access on exposed hosts.
MuddyWater hackers are using a new backdoor called "UDPGangster" that hides in fake “election seminar” Word files.

It only runs after checking if your computer is real — not a sandbox — then steals data over UDP to dodge detection.
Spain arrests teen who stole 64 million personal data records.
Four Threat Clusters Using CastleLoader as GrayBravo Expands Its Malware Service Infrastructure.
Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL Sideloading.
US Posts $10 Million Bounty for Iranian Hackers.
UK vows to look at 35-year-old Computer Misuse Act.
STAC6565 Targets Canada in 80% of Attacks as Gold Blade Deploys QWCrypt Ransomware.
Over 300,000 Individuals Impacted by Vitas Hospice Data Breach.
North Korean hackers exploit React2Shell flaw in EtherRAT malware attacks.
New GeminiJack 0-Click Flaw in Gemini AI Exposed Users to Data Leaks.
Ransomware IAB abuses EDR for stealthy malware execution.
Goodbye, dark Telegram: Blocks are pushing the underground out.
Cyber Dispatch™️
Goodbye, dark Telegram: Blocks are pushing the underground out.
Telegram has won over users worldwide. While the average user chooses a messaging app based on convenience, user experience and stability (and perhaps, cool stickers).

When it comes to anonymity, privacy and application independence – essential criteria for a shadow messaging app – Telegram is not as strong as its direct competitors.

It lacks default end-to-end (E2E) encryption for chats.
It has a centralized infrastructure: users cannot set up their own servers for communication.
Its server-side code is closed: users cannot verify what it does.

This architecture requires a high degree of trust in the platform, but experienced cybercriminals prefer not to rely on third parties when it comes to protecting their operations and, more importantly, their personal safety.

That said, Telegram today is widely viewed and used not only as a communication tool (messaging service), but also as a full-fledged dark-market business platform – thanks to several features that underground communities actively exploit.

Is this research, we examine Telegram through the eyes of cybercriminals, evaluate its technical capabilities for running underground operations, and analyze the lifecycle of a Telegram channel from creation to digital death. For this purpose, we analyzed more than 800 blocked Telegram channels, which existed between 2021 and 2024.
Key findings

The median lifespan of a shadow Telegram channel increased from five months in 2021–2022 to nine months in 2023–2024.
The frequency of blocking cybercrime channels has been growing since October 2024.
Cybercriminals have been migrating to other messaging services due to frequent blocks by Telegram.
Researchers Find Malicious VS Code, Go, npm, and Rust Packages Stealing Developer Data.