Cyber Dispatch™️
393 subscribers
32 photos
2 videos
48 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Scattered Spider investigation expands: 19-year-old Peter Stokes extradited from Finland to the U.S., accused of operating as “Bouquet.” Prosecutors link him to at least four intrusions, including one involving an $8M crypto ransom demand.
CISA added CVE-2026-45659 to KEV following active exploitation.

The SharePoint Server RCE was patched in May 2026.
Fake GitHub PoC repos are being used to infect vulnerability researchers with ChocoPoC RAT.

The PoC may look clean. The malware hides in Python dependencies like frint and skytext, then steals saved passwords, cookies, browser data, and files.
CVE-2025-3248 exploited to steal secrets, move laterally, hijack Nacos, encrypt 1,342 configuration items, and drop database schemas.
New leaks reveal U.S. officials continued using Signal for sensitive communications despite prior security controversies, reigniting concerns over secure messaging practices.
Startup sues Palo Alto Networks' Koi Security, saying an AI-hallucinated report falsely linked it to Chinese espionage.
Dev says Google warned him about account hijack – then charged him $11,000 anyway.
Google’s Continued Disruption of Malicious Residential Proxy Networks.
Europe Confirms Record €4.1B Penalty Against Google for Android Practices.
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials.
Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival.
Microsoft fixes bug that removed Copilot button in Outlook (it was an improvement not a bug :/).
DHS Breached.
Cyber Dispatch™️
DHS Breached.
A key Department of Homeland Security information-sharing database was accessed by an hacker in recent weeks.
ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API.
WinRAR flaw could allow attackers to take control of your computer.
New UNPATCHED FatFs vulnerabilities hit a filesystem library bundled into potentially MILLIONS of embedded devices.

Malformed USB drives, SD cards, or update files can trigger memory corruption, crashes, leaks, or hangs.
Kaspersky says the attacks span Russia, Brazil, and Kazakhstan, using BusySnake Stealer, GitHub-hosted payloads, Go2Tunnel reverse tunneling, and patched CVE-2025-9491 LNK abuse.
A compiled AppleScript stages a Rust stealer that validates the entered login password through PAM, then targets browsers, crypto wallets, iCloud Keychain, and clipboard content.
A series of cyberattacks targeting the UAE’s financial sector.
108 malicious packages and extensions were published across npm, Packagist, Go, and Chrome.

North Korea-linked PolinRider uses obfuscated JavaScript loaders, VS Code auto-run tasks, and blockchain services to fetch DEV#POPPER RAT and OmniStealer.