Cyber Dispatch™️
393 subscribers
32 photos
2 videos
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
New UNPATCHED FatFs vulnerabilities hit a filesystem library bundled into potentially MILLIONS of embedded devices.

Malformed USB drives, SD cards, or update files can trigger memory corruption, crashes, leaks, or hangs.
Kaspersky says the attacks span Russia, Brazil, and Kazakhstan, using BusySnake Stealer, GitHub-hosted payloads, Go2Tunnel reverse tunneling, and patched CVE-2025-9491 LNK abuse.
A compiled AppleScript stages a Rust stealer that validates the entered login password through PAM, then targets browsers, crypto wallets, iCloud Keychain, and clipboard content.
A series of cyberattacks targeting the UAE’s financial sector.
108 malicious packages and extensions were published across npm, Packagist, Go, and Chrome.

North Korea-linked PolinRider uses obfuscated JavaScript loaders, VS Code auto-run tasks, and blockchain services to fetch DEV#POPPER RAT and OmniStealer.
WILD: Meta reportedly paid hundreds of contractors to pretend to be teenagers in a targeted effort to disrupt rival AI companies.
Researchers have found a never-before-seen piece of macOS malware that combines a series of clever tradecraft to infect Macs with stealthy, custom-developed credential-stealing code.
JadePuffer ransomware used AI agent to automate entire attack.
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign.
Apple AirDrop and Android Quick Share flaws expose users to wireless attacks.
ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit.
PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords.
Pegasus Used Against MEP Investigating Pegasus, Citizen Lab Finds.
Cyber Dispatch™️
Pegasus Used Against MEP Investigating Pegasus, Citizen Lab Finds.
The Citizen Lab published a report documenting one of the more darkly ironic findings in recent surveillance research: former Member of the European Parliament Stelios Kouloglou was repeatedly infected with NSO Group‘s Pegasus spyware while serving on the very committee tasked with investigating Pegasus abuses across the EU.
Cavern Manticore is actively targeting Israeli government and IT organizations using “Cavern,” a modular .NET-based C2 framework. The campaign highlights growing sophistication in cyber espionage tactics and modular malware design.
🔥21
New TrojPix attack can leak data from an air-gapped PC through its video cable.
The pro‑resistance hacker group al‑Jabha al‑Isnād al‑Saybrāniyya (Cyber Support Front) claims a cyberattack on three Israeli legal institutions.

It says the targets handled taxation, legal services, administrative disputes & government projects, and were linked to the Israeli Ministry of Defense.

The group also claims to have obtained a large volume of sensitive documents and data.
1
Telco giant KDDI says data breach affects over 12 million people.
Telegram-Hosted RedWing Malware Lets Anyone Rent Android Spyware Tools.
Chinese hackers develop LONGLEASH malware to expand ORB network.

UAT-7810 Expands ORB Network With New LONGLEASH Malware.
Ubiquiti warns of new max severity UniFi OS vulnerability.