Cyber Dispatch™️
394 subscribers
33 photos
2 videos
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Chinese Espionage Using AI-Powered Malware

The "Silk Parasite" cyber espionage campaign, attributed to Chinese military hackers, has targeted government institutions in Central Asian countries using phishing emails and new malware.
From Phone Phreaks to AI Agents: How Hacking Evolved—and Why Hackers Are Turning to AI

By Yara Tabet (The Ghost In The Machine)

Hacking has never been static. It evolves with technology, culture, and power. Today, we are witnessing perhaps the fastest transformation yet: hackers are increasingly turning to artificial intelligence (AI) not just as a tool, but as a collaborator. To understand why, we must trace how hacking has changed from the 1980s to the 2020s—and what AI means for the future of cyber conflict, crime, and activism.

The 1980s–1990s: Curiosity, Counterculture, and Code

In the 1980s, hacking was largely driven by curiosity and countercultural ethos. Early hackers—often teenagers with dial-up modems—explored telephone networks (“phone phreaking”) and nascent computer systems like ARPANET. They wrote their own scripts in BASIC or assembly, reverse-engineered software, and shared knowledge through underground zines and bulletin board systems (BBS). Talent was measured by deep technical understanding: knowing how memory worked, how to exploit buffer overflows, or how to write a packet sniffer from scratch.

This era also produced figures who would later redefine information warfare. Julian Assange, then known by the handle “Mendax,” was a founding member of the International Subversives, a small Australian hacking group that penetrated telecommunications systems and, allegedly, military networks like MILNET. Assange’s trajectory—from teenage hacker to cypherpunk to founder of WikiLeaks—epitomizes how hacking culture seeded modern transparency activism.

The 1990s saw hacking mature alongside the public internet. Groups like Legion of Doom and Cult of the Dead Cow became legendary. Hacktivism emerged, with collectives using defacements and early distributed denial-of-service (DDoS) attacks to make political statements. Tools were still largely handcrafted: Perl scripts for scanning, custom C code for exploits, and manually coordinated botnets for DDoS. Skill barriers were high; you needed to understand networking, operating systems, and programming intimately.

The 2000s–2010s: Criminalization, Commodification, and Scale

The 2000s brought monetization. Cybercrime became industrialized with ransomware, banking trojans, and exploit kits sold on underground forums. Script kiddies could launch attacks using point-and-click tools, lowering the barrier to entry. Meanwhile, nation-states entered the arena: Stuxnet (2010) demonstrated how hacking could achieve geopolitical objectives.

This period also saw the rise of sophisticated botnet architectures. Early botnets relied on Internet Relay Chat (IRC) servers as command-and-control (C2) channels: compromised machines—“zombies”—would connect to an IRC channel and await commands from the botmaster. The 1999 Trin00 botnet, used in the first major DDoS attacks against Yahoo and other sites, exemplified this model. Later, web-based C2 and peer-to-peer (P2P) botnets like Storm Worm made takedowns harder by decentralizing control.

Hacktivism scaled with tools like LOIC (Low Orbit Ion Cannon), but also with more advanced techniques. LulzSec, a splinter group from Anonymous active in 2011, combined traditional DDoS with Remote File Include (RFI) attacks to hijack web servers and turn them into DDoS bots. Their operations against the CIA, Sony, and PBS demonstrated how hacktivists could blend social engineering, SQL injection, and botnet-like tactics without relying on traditional zombie networks. Anonymous, meanwhile, leveraged volunteer-driven “ops” where participants manually launched DDoS attacks in coordinated waves.

The 2020s: AI Enters the Chat

Today, AI is reshaping every layer of hacking. Generative AI models—powered by specialized AI chips in massive data centers—can write code, analyze vulnerabilities, craft phishing lures, and even adapt malware in real time. Unlike earlier tools, AI doesn’t just execute commands; it reasons, learns, and iterates.
1
What is AI, and what are AI chips?
Artificial intelligence refers to systems that perform tasks requiring human-like intelligence: understanding language, recognizing patterns, making decisions. Modern AI relies on neural networks trained on vast datasets using AI chips—specialized processors (like GPUs, TPUs, or custom ASICs) designed for parallel computation. These chips, built by companies like Nvidia, Google, and Huawei, enable the training and deployment of large language models (LLMs) that power everything from ChatGPT to autonomous cyber agents.

Old-School Hackers vs. AI-Era Hackers

The difference between old-school and modern hackers is profound:

- Old-school hackers were artisans. They wrote every line of code, understood every syscall, and prized deep expertise. Their talent lay in creativity, persistence, and technical mastery.
- Today’s hackers are increasingly orchestrators. They use AI to automate reconnaissance, generate exploits, and evade detection. A novice can now prompt an LLM to produce working malware or scan a network for vulnerabilities—tasks that once required months of study.

This isn’t laziness; it’s leverage. AI amplifies impact. One operator can now launch campaigns that previously required entire teams.

Hacktivism Then and Now: From IRC Botnets to AI-Driven DDoS

In the 2000s and 2010s, hacktivist DDoS attacks relied on volunteer botnets, IRC-based C2, and tools like LOIC. Participants manually joined “operations,” flooding targets with traffic. Impact was limited by coordination and bandwidth.

Today, AI transforms DDoS in three ways:

1. Automation: AI agents can identify high-value targets, spin up cloud instances, and launch attacks without human intervention.
2. Adaptation: Machine learning models adjust attack patterns in real time to bypass mitigation systems, mimicking legitimate traffic or rotating IPs dynamically.
3. Scale: AI-powered botnets can recruit compromised IoT devices or cloud resources autonomously, creating larger, more resilient attack networks.

Hacktivists now use AI not just for DDoS, but for deepfake propaganda, automated disinformation campaigns, and targeted spear-phishing against officials. The goal remains political—but the methods are faster, smarter, and harder to trace.

Why Hackers Are Turning to AI

Hackers adopt AI for the same reasons militaries and corporations do: efficiency, scale, and advantage.

- Speed: AI reduces the time from vulnerability disclosure to exploit from weeks to hours.
- Accessibility: LLMs democratize hacking, enabling less-skilled actors to perform advanced attacks.
- Evasion: AI-generated code can polymorphically change its signature, evading traditional antivirus and endpoint detection.
- Autonomy: Emerging AI agents can operate with minimal human oversight, probing networks, escalating privileges, and exfiltrating data.

This shift doesn’t eliminate the need for skill—but it changes its nature. The most dangerous hackers today are those who can effectively direct AI systems, combining strategic thinking with prompt engineering and adversarial machine learning.

The Road Ahead

AI is not replacing hackers; it is augmenting them. Just as the internet scaled hacking in the 1990s, AI is scaling it again—this time with intelligence baked in. Defenders must respond not only with better tools, but with new paradigms: continuous validation, AI-augmented threat hunting, and international norms around autonomous cyber operations.

The spirit of hacking—curiosity, rebellion, mastery—endures. But the interface has changed. From phone phreaks to AI agents, the evolution continues. And in this new era, understanding AI is no longer optional for cybersecurity professionals; it is essential.

The author is a Lebanese professor of cybersecurity with experience in offensive security, threat intelligence, and AI policy. Views expressed are personal.

@TheGhostITM
3
Blackwater founder Erik Prince launched a company selling air defense by subscription to protect data centers, military bases, shipping lanes and refineries.

The founder has launched Vectus Air Defense Systems — jammers, cannons and interceptors sold as-a-service to owners of critical sites. Drone-swarming firm Swarmer holds a 20% founding stake.
TikTok Reaches $400 Million Settlement with the U.S. Department of Justice

According to the Cyberban International Task Force, TikTok has reached a settlement of $400 million with the U.S. Department of Justice, resolving a lawsuit alleging violations of federal child privacy laws. The lawsuit accused TikTok and its parent company, ByteDance, of collecting information from children under the age of 13 without parental consent.
Cyber Dispatch™️
TikTok Reaches $400 Million Settlement with the U.S. Department of Justice According to the Cyberban International Task Force, TikTok has reached a settlement of $400 million with the U.S. Department of Justice, resolving a lawsuit alleging violations of…
The Department of Justice called the agreement a significant step in protecting children. This case is being closed as TikTok and other social media platforms face increasing legal pressure regarding the privacy and safety of children in the United States and other countries.
The South Korean company SK Hynix is considering building a large factory for the production of memory chips in Japan. This move aims to increase production capacity and address the global shortage of memory chips, and could be one of the company's largest manufacturing investments outside of South Korea.
China’s HUAWEI launches ANTI-SPY PHONE feature that BLURS SCREEN when SOMEONE PEEKS.
HACKERS TAKE UK POWER PLANT OFFLINE for 4 DAYS.
The Chinese video platform Bilibili, a major competitor to YouTube in China, is planning to expand its operations outside of China by launching an international application.
Cyber Dispatch™️
The Chinese video platform Bilibili, a major competitor to YouTube in China, is planning to expand its operations outside of China by launching an international application.
The company aims to attract content creators and YouTubers and intends to offer both Chinese and international content on a single platform.

Bilibili also plans to establish offices in cities such as Los Angeles, London, and Tokyo. The Android version of the application is now available, and the iOS version will be released soon.
Reports indicate that a hacker known as "CyberLeek" sold an older version of the GTA 6 game, dating back to 2023, for $350,000.
Cyber Dispatch™️
Reports indicate that a hacker known as "CyberLeek" sold an older version of the GTA 6 game, dating back to 2023, for $350,000.
Just hours after the release of this version, download links for it were posted on file-sharing networks and torrent sites; however, experts have warned about the risks of downloading these files.

The versions released on these networks may be infected with malware, steal information, or be part of a botnet. Users who download the leaked version of the game hoping to play it may find their computers.
Cisco has addressed 9 security vulnerabilities in its Crosswork and Secure Workload products, with 5 of them classified as having the highest level of risk, a score of 10 out of 10.
The complete exploit code for the CVE-2026-69414 vulnerability, known as "ShieldBreak," in Microsoft Defender has been released, even though a patch has not yet been provided.
Apple confirmed it sent a large wave of “mercenary spyware” threat notifications to iPhone users in 110 countries on Aug 13, 2026. These are high‑confidence alerts tied to ultra‑targeted, government‑linked attacks. If you get one: take it seriously, enable Lockdown Mode, and don’t click links in fake alerts.
Cyber Dispatch™️
Apple confirmed it sent a large wave of “mercenary spyware” threat notifications to iPhone users in 110 countries on Aug 13, 2026. These are high‑confidence alerts tied to ultra‑targeted, government‑linked attacks. If you get one: take it seriously, enable…
Apple doesn’t name a specific spyware tool or operator in its threat alerts—but it has previously cited the Israeli-linked NSO Group’s Pegasus as an example of the kind of “mercenary spyware” behind these ultra-targeted, government-linked attacks.
14 npm packages drop RedC2 4.0 on Linux.

The packages work as advertised, but also launch its RedShell beacon on import. RedC2 includes an LLM-backed agent that turns natural-language instructions into beacon commands.
Android car head units are getting malware through built-in updaters.

Attackers abused DoFun’s update channel to deliver malware for ad fraud and proxy botnet activity. It can also download and run arbitrary code.
The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands.

The malware now requests VPN service permissions to create a local interface that allows it to control network traffic passing through it. The feature enables ToxicPanda 2.0 to block communication from Google Play and Google Play Services.
Experts say agentic AI and machine identities create significant security risk. As AI shifts from generating content to taking actions, organizations will increasingly need to treat each agent as a privileged identity with access to sensitive systems and data. At the same time, AI-enabled phishing, impersonation, and automated reconnaissance are making traditional indicators of trust less reliable. Defenders are responding with stronger identity controls, phishing-resistant authentication, behavioral monitoring, and zero-trust principles.