Cyber Dispatch™️
395 subscribers
33 photos
2 videos
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Chinese hackers use AI to automate attacks on 170,000 servers.
Hackers poison arrayref Rust crate to push infostealer malware.
A young security researcher figured out a way to enroll a Linux device into Apple’s Find My network and read live location data from it.

Find My is Apple’s app for, you guessed it, finding things – whether AirTags, iPads, or other supported devices and items. It also works for people. Families can track each other's whereabouts for safety reasons, and friends can tell when others are hanging out without them.
Cyber Dispatch™️
A young security researcher figured out a way to enroll a Linux device into Apple’s Find My network and read live location data from it. Find My is Apple’s app for, you guessed it, finding things – whether AirTags, iPads, or other supported devices and items.…
In typical Apple fashion, though, the full Find My experience is limited to Apple hardware, like an iPhone or Mac. iBiz also offers Find Devices via the iCloud website, although it lacks Find My’s people-tracking feature for viewing locations others have shared with you.

However, the 22-year-old researcher, who goes by “Zerotistic,” devised a way to enroll a Linux-based machine into the iNetwork, tricking Apple into sending the people-location data it exclusively reserves for Apple devices.
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets.
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands.
New Manic Android malware can exfiltrate data through nearby devices.
Three suspected Russian cyber-espionage clusters are abusing legitimate authentication features across WhatsApp, Google, and Microsoft to compromise academics, diplomats, defense personnel, researchers, and government-linked individuals.
Cyber Dispatch™️
Three suspected Russian cyber-espionage clusters are abusing legitimate authentication features across WhatsApp, Google, and Microsoft to compromise academics, diplomats, defense personnel, researchers, and government-linked individuals.
One cluster, tracked as UNC7005, has gone so far as to trick victims into linking WhatsApp accounts to attacker-controlled devices and recording their audio and video through fake calls.

Google tracks the activity as UNC6293, UNC7005, and UNC5976, assessing with high confidence that all three have a Russian nexus. UNC6293 and UNC7005 are further assessed with moderate confidence as initial-access clusters associated with ICE RELIC, Google's name for the threat actor also known as APT29.
Cyberattack on American Company "Alation"

The American company "Alation," which operates in the field of data management and artificial intelligence solutions, has announced the detection of unauthorized access to one of its systems.
Analyzing Stripe Vendors Breach: Confirmed Vendor Exposure and Claims of 20,000 Compromised APIs | InfoStealers.
50 websites that feel like the internet’s hidden toolbox 🧰

1. http://unpaywall.org — Free research papers
2. http://openlibrary.org — Borrow books online
3. http://doaj.org — Free academic journals
4. http://alternativeto.net — App alternatives
5. http://justwatch.com — Find where to stream
6. http://archive.org — Internet archives
7. http://gutenberg.org — 70K+ free books
8. http://openstax.org — Free textbooks
9. http://openculture.com — Free courses
10. http://wolframalpha.com — Solve complex problems
11. http://photopea.com — Photoshop alternative
12. http://squoosh.app — Compress images
13. http://remove.bg — Remove backgrounds
14. http://cleanup.pictures — Remove objects
15. http://unscreen.com — Remove video backgrounds
16. http://carbon.now.sh — Beautiful code images
17. http://ray.so — Code screenshots
18. http://shots.so — Product mockups
19. http://smartmockups.com — Create mockups
20. http://haveibeenpwned.com — Check data breaches
21. http://virustotal.com — Scan files & URLs
22. http://privnote.com — Self-destructing notes
23. http://temp-mail.org — Temporary email
24. http://file.io — Temporary file sharing
25. http://archive.ph — Save webpages
26. http://similarsites.com — Find similar websites
27. http://radio.garden — Explore global radio
28. http://everynoise.com — Discover music genres
29. http://tunefind.com — Find songs from shows
30. http://musicforprogramming.net — Focus music
31. http://mynoise.net — Custom background sounds
32. http://coffitivity.com — Café ambience
33. http://elicit.org — Research assistant
34. http://consensus.app — Research-backed answers
35. http://connectedpapers.com
@sauda_coder
— Research connections
36. http://semanticscholar.org — Academic search
37. http://scispace.com — Understand research papers
38. http://summarize.tech — YouTube summaries
39. http://phind.com — AI for developers
40. http://regex101.com — Test regex
41. http://codebeautify.org — Format code
42. http://jsonformatter.org — Format JSON
43. http://explainshell.com — Understand terminal commands
44. http://raindrop.io — Bookmark manager
45. http://downdetector.com — Check outages
46. http://tineye.com — Reverse image search
47. http://fast.com — Internet speed test
48. http://smallpdf.com — PDF tools
49. http://ilovepdf.com — Merge/split PDFs
50. http://10minutemail.com — Temporary email

Save this. You’ll definitely need some of these later. 🔖
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has announced that hackers are exploiting two vulnerabilities, CVE-2026-72529 and CVE-2026-72530, in the TrueConf Server video conferencing software, and has added these flaws to its list of actively exploited vulnerabilities.
Someone’s Bluetooth headphones kept refusing to hand audio back to their phone. He discovered the cause was an open AliExpress tab that was generating a tone you purposefully never hear, to secretly track you.
Cyber Dispatch™️
Someone’s Bluetooth headphones kept refusing to hand audio back to their phone. He discovered the cause was an open AliExpress tab that was generating a tone you purposefully never hear, to secretly track you.
Alibaba's anti-abuse scripts use a fingerprinting technique with a hidden audio graph on the homepage — a sawtooth tone pushed through the browser's audio engine, then measured on the way out. CPU, OS and browser each process it slightly differently, and that variation results in a fingerprint they can track you with.
Frequent Power Outages Reduce the Resilience of Mobile Networks

The ongoing power outages have highlighted the weakness of the backup batteries at BTS (Base Transceiver Station) sites more than ever. In some sites, outdated batteries can no longer sustain the communication equipment for a sufficient period, and when the power goes out, the mobile antenna becomes unavailable after only a few minutes.
Researchers at the Guangdong Academy of Aerospace Technology in China have developed a star-based navigation system for hypersonic flights, which can determine the aircraft's trajectory and position even if GPS and the BeiDou system are disrupted. This project has recently passed its final evaluation by experts.
Android car head units are getting malware through built-in updaters.

Attackers abused DoFun’s update channel to deliver malware for ad fraud and proxy botnet activity. It can also download and run arbitrary code.
Five CVSS 10.0 flaws affect Cisco Crosswork and Secure Workload.

They’re among nine vulnerabilities Cisco patched, covering SQL injection, missing authentication, access control, path traversal, and other security failures.