Cyber Dispatch™️
395 subscribers
33 photos
2 videos
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Analyzing Stripe Vendors Breach: Confirmed Vendor Exposure and Claims of 20,000 Compromised APIs | InfoStealers.
50 websites that feel like the internet’s hidden toolbox 🧰

1. http://unpaywall.org — Free research papers
2. http://openlibrary.org — Borrow books online
3. http://doaj.org — Free academic journals
4. http://alternativeto.net — App alternatives
5. http://justwatch.com — Find where to stream
6. http://archive.org — Internet archives
7. http://gutenberg.org — 70K+ free books
8. http://openstax.org — Free textbooks
9. http://openculture.com — Free courses
10. http://wolframalpha.com — Solve complex problems
11. http://photopea.com — Photoshop alternative
12. http://squoosh.app — Compress images
13. http://remove.bg — Remove backgrounds
14. http://cleanup.pictures — Remove objects
15. http://unscreen.com — Remove video backgrounds
16. http://carbon.now.sh — Beautiful code images
17. http://ray.so — Code screenshots
18. http://shots.so — Product mockups
19. http://smartmockups.com — Create mockups
20. http://haveibeenpwned.com — Check data breaches
21. http://virustotal.com — Scan files & URLs
22. http://privnote.com — Self-destructing notes
23. http://temp-mail.org — Temporary email
24. http://file.io — Temporary file sharing
25. http://archive.ph — Save webpages
26. http://similarsites.com — Find similar websites
27. http://radio.garden — Explore global radio
28. http://everynoise.com — Discover music genres
29. http://tunefind.com — Find songs from shows
30. http://musicforprogramming.net — Focus music
31. http://mynoise.net — Custom background sounds
32. http://coffitivity.com — Café ambience
33. http://elicit.org — Research assistant
34. http://consensus.app — Research-backed answers
35. http://connectedpapers.com
@sauda_coder
— Research connections
36. http://semanticscholar.org — Academic search
37. http://scispace.com — Understand research papers
38. http://summarize.tech — YouTube summaries
39. http://phind.com — AI for developers
40. http://regex101.com — Test regex
41. http://codebeautify.org — Format code
42. http://jsonformatter.org — Format JSON
43. http://explainshell.com — Understand terminal commands
44. http://raindrop.io — Bookmark manager
45. http://downdetector.com — Check outages
46. http://tineye.com — Reverse image search
47. http://fast.com — Internet speed test
48. http://smallpdf.com — PDF tools
49. http://ilovepdf.com — Merge/split PDFs
50. http://10minutemail.com — Temporary email

Save this. You’ll definitely need some of these later. 🔖
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has announced that hackers are exploiting two vulnerabilities, CVE-2026-72529 and CVE-2026-72530, in the TrueConf Server video conferencing software, and has added these flaws to its list of actively exploited vulnerabilities.
Someone’s Bluetooth headphones kept refusing to hand audio back to their phone. He discovered the cause was an open AliExpress tab that was generating a tone you purposefully never hear, to secretly track you.
Cyber Dispatch™️
Someone’s Bluetooth headphones kept refusing to hand audio back to their phone. He discovered the cause was an open AliExpress tab that was generating a tone you purposefully never hear, to secretly track you.
Alibaba's anti-abuse scripts use a fingerprinting technique with a hidden audio graph on the homepage — a sawtooth tone pushed through the browser's audio engine, then measured on the way out. CPU, OS and browser each process it slightly differently, and that variation results in a fingerprint they can track you with.
Frequent Power Outages Reduce the Resilience of Mobile Networks

The ongoing power outages have highlighted the weakness of the backup batteries at BTS (Base Transceiver Station) sites more than ever. In some sites, outdated batteries can no longer sustain the communication equipment for a sufficient period, and when the power goes out, the mobile antenna becomes unavailable after only a few minutes.
Researchers at the Guangdong Academy of Aerospace Technology in China have developed a star-based navigation system for hypersonic flights, which can determine the aircraft's trajectory and position even if GPS and the BeiDou system are disrupted. This project has recently passed its final evaluation by experts.
Android car head units are getting malware through built-in updaters.

Attackers abused DoFun’s update channel to deliver malware for ad fraud and proxy botnet activity. It can also download and run arbitrary code.
Five CVSS 10.0 flaws affect Cisco Crosswork and Secure Workload.

They’re among nine vulnerabilities Cisco patched, covering SQL injection, missing authentication, access control, path traversal, and other security failures.
Attackers are exploiting a GitLab flaw days after disclosure.

CVE-2026-19478 lets unauthenticated attackers modify or delete public projects and rewrite their data under certain conditions. watchTowr says it saw in-the-wild exploitation against its honeypots.
Attackers can weaponize Defender’s own signed driver to delete security software at boot.

BTR.sys runs from Ring 0 before Defender’s user-mode services start. Check Point showed it deleting the full Defender stack on Windows 11 25H2 with Tamper Protection enabled.
A CVSS 10.0 Entra ID flaw was exploited in the wild.

CVE-2026-69836 allows an unauthorized attacker to remotely execute code through unsafe deserialization.

Microsoft says the flaw is fully mitigated and no customer action is required. How attackers exploited it remains undisclosed.
Rust supply chain attack hits three crates, including 245 million-download arrayref.

A compromised maintainer account pushed malicious releases that pulled in typosquatted proc-macro1, whose build script fetches and runs a remote payload during compilation.
Critical NetScaler flaw can bypass authentication on certain Gateway and AAA configurations.

Citrix patched CVE-2026-19490 (CVSS 9.3). Exposure depends on the NetScaler version and configuration, with SAML required in some cases.
Attackers are exploiting a Zimbra flaw that can lead to unauthenticated RCE.

CVE-2026-73570 affects ZCS before 10.1.20 when zimbra-snmp is installed and SNMP notifications are enabled. Crafted SMTP requests may execute OS commands as the Zimbra user.
Expired Visa payment cards can be revived for real purchases.

New “Zombie Card” attack rewrites the expiry date a contactless terminal reads over NFC, while the card’s cryptography still validates.
Manic can exfiltrate data even when a phone is offline.

New Manic Android malware uses nearby infected devices as C2 relays, with four hops by default. It targets 169 apps and can capture PINs, one-time codes, messages, files, and location data.
NASA AIT-GUI could let unauthenticated attackers issue spacecraft commands.

The operator console also exposed script and sequence execution, while malicious web pages could reach command routes through cross-origin POST requests.
ToxicPanda and GoldDigger are moving beyond credential theft.

ToxicPanda 2.0 adds 167 remote commands, PIN harvesting, lock-screen credential replacement, and shell access. GoldDigger can control banking apps, view screens live, and initiate fraudulent transactions.