Cyber Dispatch™️
393 subscribers
32 photos
2 videos
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Anthropic now invisibly marks Claude-generated content worldwide, following new EU AI Act transparency rules effective August 2026.

Supported Claude models embed machine-readable watermarks directly into text, which can survive copy-pasting.

Generated images/files can carry signed C2PA provenance metadata.
ICYMI: One click from a logged-in WordPress admin can trigger a chain from pre-auth XSS to PHP code execution.

CVE-2026-64638 affects all WordPress versions, and the login-page XSS itself requires no authentication.
Mozilla revoked the Firefox and Thunderbird Linux signing key after an unencrypted copy was accidentally committed to a private repo.

No unauthorized access was found, but older downloads can stop verifying and some Firefox RPM updates may fail.
A malicious SIM can take over the modem from inside the device.

Researchers found 9 of 26 tested phones and cellular modules accept RUN AT commands from the SIM, including 6 of the 8 modules. On one commercial EV charger, they chained the interface to code execution.
Gunra ransomware breaches networks, steals data, and destroys backups.

Attacks have exploited Fortinet FortiOS/FortiProxy and Schneider Electric PowerLogic P5 flaws for initial access, before encrypting databases, NAS systems, and other key assets.
Historical reminder: In 2013, documents disclosed by Edward Snowden revealed a 2009 NSA–Israel SIGINT-sharing memorandum. The arrangement allowed Israel to receive raw, unminimized intelligence—including transcripts, emails, voice communications, and metadata—that could contain Americans’ communications. Although privacy guidelines were included, the memorandum stated that they were not legally binding.
1
FAA has hired 2,000+ gamers to train as air traffic controllers after targeting gaming skills like multitasking, quick decision-making, and problem-solving.

The April campaign helped the FAA reach 94% of its hiring goal, with another 2,000+ candidates in the pipeline.
North Korean hackers have been exploiting a newly patched Windows zero-day vulnerability to take over victims’ systems, Check Point reports.

Attributed to the infamous Lazarus Group APT, the attacks represent a continuation of the long-running Operation Dream Job campaign targeting job seekers with fake work opportunities at well-known companies. North Korean hackers have been mounting fake job attack variations regularly.
Cisco warns of ASA and FTD VPN flaw exploited to crash devices.
421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one.
Spain's national police have arrested a cybercriminal who allegedly made 38 attempts to impersonate 30 individuals to obtain digital certificates. The suspect is accused of using sophisticated techniques, including deepfake technology and forged documents, to bypass identity verification processes. The investigation was complicated by the suspect's use of numerous devices and stolen identities, with further coverage provided by The Register.
Signal adds an extra layer of security to make sure you're actually chatting with the right person.
ExfilSquad targets 13 organizations, uses torrents for data distribution.
Wesco investigates cybersecurity incident after data extortion group claims breach.
Adobe on Tuesday rolled out patches for over 50 vulnerabilities across its products, including critical-severity bugs in ColdFusion, Campaign Classic, and Commerce.

With a priority 1 rating, the ColdFusion update fixes 15 security defects, including three flagged as critical that could lead to arbitrary code execution and application denial-of-service (DoS).

These include an OS command injection tracked as CVE-2026-48362 (CVSS score of 10/10), an eval injection tracked as CVE-2026-48273 (CVSS score of 9.9/10), and an incorrect authorization tracked as CVE-2026-71384 (CVSS score of 9.6/10).
1
In 2026, researchers reported a new cyber‑espionage campaign linked to the Armored Likho group (also known as Eagle Werewolf). The operation focused mainly on users in Russia, including private individuals, large companies, and public organizations.

The attackers used a fake charity application as their entry point. The app looked like a legitimate donation platform, but it actually acted as a dropper, silently installing further malware in the background while showing users a normal-looking interface.

The most notable discovery was a new toolkit written in Rust, called the Still Toolkit. It has two core parts: Still Sync and Still Audio. Still Sync targets Telegram Desktop by searching for the tdata folder, stealing session information, and then using the Telegram API to download chats, media, and account details. This allows long‑term access without directly compromising passwords.

Still Audio turns the victim’s machine into a covert listening device. It monitors audio input, detects when someone is speaking, records those conversations, compresses them, and sends them to a remote server.

Overall, this campaign shows how modern threat actors combine data theft and audio surveillance to build a powerful, flexible spying ecosystem.

- Cyber Dispatch
Trump administration lifts ban on TikTok for federal devices.
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts.
Colombia's Ministry of Justice hit by ransomware attack.

#TGITM @TheGhostITM
Security researchers from Palo Alto Networks’ Unit 42 have spotted a new version of the Kimwolf botnet that focuses on stealth and resilience. Kimwolf, active since 2024 and linked to the Aisuru ecosystem, has already infected well over a million Android and IoT devices, especially cheap Android TV and set‑top boxes.

The latest release, Kimwolf v7, introduces an HTTP/2 DDoS feature that tries to mimic real Chrome browser traffic. By generating detailed browser fingerprints, its attack traffic can blend in with normal visitors, making it harder for defenses to filter out. The botnet now supports 15 different DDoS methods, including TCP, UDP, DNS, ICMP, TLS/HTTPS, and HTTP/2 floods, with one UDP mode tuned for ARM chips often found in TV boxes. Interestingly, scanning and exploitation functions appear removed, suggesting Kimwolf now relies on other tools to handle initial infections.

The operators have also hardened their command‑and‑control setup. Kimwolf can pull server details from Ethereum Name Service (ENS) records using public Ethereum RPC providers, and it has a Tor fallback if that fails. Users are urged to treat low‑cost Android TV boxes with caution, disable or restrict ADB, and watch for unusual Ethereum, Tor traffic, or suspicious processes such as “netd_service”.

- Cyber Dispatch
Thailand plans mandatory multi-factor authentication after massive data leak.