Cyber Dispatch™️
395 subscribers
33 photos
2 videos
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper.

Email security company Proofpoint spotted the activity a week ago targeting various organizations, including government entities in the U.S. and Europe, and companies in the telecommunications, financial, hospitality, and aerospace sectors.

Laundry Bear exploited CVE-2026-42897, a cross-site scripting (XSS) vulnerability that allows executing arbitrary JavaScript in the browser context when users open a specially crafted email in the Outlook Web Access (OWA) app.
The source code for the Flying Eagle Android remote access trojan (RAT) framework is being shared on criminal Telegram channels. Researchers from Hunt.io and NetAskari have identified 170 internet servers linked to matching control panels and certificates.
HOLLOWGRAPH Backdoor Turns Microsoft 365 Calendars Into a C2 Channel.
CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity.
EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels.
Cyberattack on Minnesota water systems.
Cyber Dispatch™️
Cyberattack on Minnesota water systems.
A coordinated cyberattack struck more than 30 municipal water systems across Minnesota over the weekend, disrupting automated controls at treatment plants and water towers in communities including Braham, Plymouth, Maple Plain, and South St. Paul. State.
Cyber Dispatch™️
Cyberattack on Minnesota water systems.
Federal officials say the intrusions targeted operational technology such as programmable logic controllers and supervisory systems that manage pumps and monitoring, forcing some utilities to switch to manual operations.
Anthropic Reveals Rogue AI Models Hacked Three Companies During Testing

Anthropic disclosed that its AI models escaped testing environments and hacked three unsuspecting companies when inadvertently granted internet access, going undetected since April.
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks.
SplitVPN - 865,336 breached accounts.
HackerOne will require a verified government ID to submit to any bug bounty program on its platform. Every account, new and existing, managed or unmanaged.

Its docs, updated today, cite "regulatory requirements." Verification runs through Veriff and must be renewed yearly; sessions over a VPN or on a jailbroken device are rejected, and under-18s can't verify at all.

Their vulnerability disclosure program stays open with no ID.
Online ad firm Adform’s script compromised to steal cryptocurrency.
Italy's new facial recognition policy sparks EU law debate.
China is rapidly closing the satellite gap with the U.S., expanding its surveillance, navigation, and military space capabilities.

Its growing satellite network improves intelligence gathering, precision targeting, and tracking of U.S. forces, while advances in GPS alternatives, AI analysis, and anti-satellite weapons are raising concerns that Beijing could increasingly challenge U.S. military dominance in space.

Source: WSJ
CareCloud Data Breach Impacts Over 350,000.
South Korea fines telco giant KT $39 million for customer data breach.
UK Department for Education confirms data breach affecting over 600,000 records.
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction.
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk.