Cyber Dispatch™️
393 subscribers
32 photos
2 videos
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Cisco warns of ASA and FTD VPN flaw exploited to crash devices.
421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one.
Spain's national police have arrested a cybercriminal who allegedly made 38 attempts to impersonate 30 individuals to obtain digital certificates. The suspect is accused of using sophisticated techniques, including deepfake technology and forged documents, to bypass identity verification processes. The investigation was complicated by the suspect's use of numerous devices and stolen identities, with further coverage provided by The Register.
Signal adds an extra layer of security to make sure you're actually chatting with the right person.
ExfilSquad targets 13 organizations, uses torrents for data distribution.
Wesco investigates cybersecurity incident after data extortion group claims breach.
Adobe on Tuesday rolled out patches for over 50 vulnerabilities across its products, including critical-severity bugs in ColdFusion, Campaign Classic, and Commerce.

With a priority 1 rating, the ColdFusion update fixes 15 security defects, including three flagged as critical that could lead to arbitrary code execution and application denial-of-service (DoS).

These include an OS command injection tracked as CVE-2026-48362 (CVSS score of 10/10), an eval injection tracked as CVE-2026-48273 (CVSS score of 9.9/10), and an incorrect authorization tracked as CVE-2026-71384 (CVSS score of 9.6/10).
1
In 2026, researchers reported a new cyber‑espionage campaign linked to the Armored Likho group (also known as Eagle Werewolf). The operation focused mainly on users in Russia, including private individuals, large companies, and public organizations.

The attackers used a fake charity application as their entry point. The app looked like a legitimate donation platform, but it actually acted as a dropper, silently installing further malware in the background while showing users a normal-looking interface.

The most notable discovery was a new toolkit written in Rust, called the Still Toolkit. It has two core parts: Still Sync and Still Audio. Still Sync targets Telegram Desktop by searching for the tdata folder, stealing session information, and then using the Telegram API to download chats, media, and account details. This allows long‑term access without directly compromising passwords.

Still Audio turns the victim’s machine into a covert listening device. It monitors audio input, detects when someone is speaking, records those conversations, compresses them, and sends them to a remote server.

Overall, this campaign shows how modern threat actors combine data theft and audio surveillance to build a powerful, flexible spying ecosystem.

- Cyber Dispatch
Trump administration lifts ban on TikTok for federal devices.
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts.
Colombia's Ministry of Justice hit by ransomware attack.

#TGITM @TheGhostITM
Security researchers from Palo Alto Networks’ Unit 42 have spotted a new version of the Kimwolf botnet that focuses on stealth and resilience. Kimwolf, active since 2024 and linked to the Aisuru ecosystem, has already infected well over a million Android and IoT devices, especially cheap Android TV and set‑top boxes.

The latest release, Kimwolf v7, introduces an HTTP/2 DDoS feature that tries to mimic real Chrome browser traffic. By generating detailed browser fingerprints, its attack traffic can blend in with normal visitors, making it harder for defenses to filter out. The botnet now supports 15 different DDoS methods, including TCP, UDP, DNS, ICMP, TLS/HTTPS, and HTTP/2 floods, with one UDP mode tuned for ARM chips often found in TV boxes. Interestingly, scanning and exploitation functions appear removed, suggesting Kimwolf now relies on other tools to handle initial infections.

The operators have also hardened their command‑and‑control setup. Kimwolf can pull server details from Ethereum Name Service (ENS) records using public Ethereum RPC providers, and it has a Tor fallback if that fails. Users are urged to treat low‑cost Android TV boxes with caution, disable or restrict ADB, and watch for unusual Ethereum, Tor traffic, or suspicious processes such as “netd_service”.

- Cyber Dispatch
Thailand plans mandatory multi-factor authentication after massive data leak.
Ceva Logistics Operations Disrupted by Cyberattack.
FBI: Hackers target online accounts to steal nude photos.
Akira ransomware attacker uses Safe Mode reboot to evade EDR.
Android malware combo takes out loans and relays victims' credit cards.
Crypto wallet maker Trezor confirms 13,000 customers' details exposed in logistics breach.
Happy birthday, Telegram!
Telegram turns 13 today, on August 14, 2026. It launched on August 14, 2013.
🎉1
Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks.

"Apple devices now give you alerts if you're cool and badass."