Cyber Dispatch™️
393 subscribers
32 photos
2 videos
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Reports indicate that a hacker known as "CyberLeek" sold an older version of the GTA 6 game, dating back to 2023, for $350,000.
Cyber Dispatch™️
Reports indicate that a hacker known as "CyberLeek" sold an older version of the GTA 6 game, dating back to 2023, for $350,000.
Just hours after the release of this version, download links for it were posted on file-sharing networks and torrent sites; however, experts have warned about the risks of downloading these files.

The versions released on these networks may be infected with malware, steal information, or be part of a botnet. Users who download the leaked version of the game hoping to play it may find their computers.
Cisco has addressed 9 security vulnerabilities in its Crosswork and Secure Workload products, with 5 of them classified as having the highest level of risk, a score of 10 out of 10.
The complete exploit code for the CVE-2026-69414 vulnerability, known as "ShieldBreak," in Microsoft Defender has been released, even though a patch has not yet been provided.
Apple confirmed it sent a large wave of “mercenary spyware” threat notifications to iPhone users in 110 countries on Aug 13, 2026. These are high‑confidence alerts tied to ultra‑targeted, government‑linked attacks. If you get one: take it seriously, enable Lockdown Mode, and don’t click links in fake alerts.
Cyber Dispatch™️
Apple confirmed it sent a large wave of “mercenary spyware” threat notifications to iPhone users in 110 countries on Aug 13, 2026. These are high‑confidence alerts tied to ultra‑targeted, government‑linked attacks. If you get one: take it seriously, enable…
Apple doesn’t name a specific spyware tool or operator in its threat alerts—but it has previously cited the Israeli-linked NSO Group’s Pegasus as an example of the kind of “mercenary spyware” behind these ultra-targeted, government-linked attacks.
14 npm packages drop RedC2 4.0 on Linux.

The packages work as advertised, but also launch its RedShell beacon on import. RedC2 includes an LLM-backed agent that turns natural-language instructions into beacon commands.
Android car head units are getting malware through built-in updaters.

Attackers abused DoFun’s update channel to deliver malware for ad fraud and proxy botnet activity. It can also download and run arbitrary code.
The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands.

The malware now requests VPN service permissions to create a local interface that allows it to control network traffic passing through it. The feature enables ToxicPanda 2.0 to block communication from Google Play and Google Play Services.
Experts say agentic AI and machine identities create significant security risk. As AI shifts from generating content to taking actions, organizations will increasingly need to treat each agent as a privileged identity with access to sensitive systems and data. At the same time, AI-enabled phishing, impersonation, and automated reconnaissance are making traditional indicators of trust less reliable. Defenders are responding with stronger identity controls, phishing-resistant authentication, behavioral monitoring, and zero-trust principles.
The United Arab Emirates is focusing on developing AI-based defense systems in response to a surge in cyberattacks targeting critical infrastructure. According to the country's Cybersecurity Council, attempted intrusions have reached approximately 800,000 per day, four times the level before the war.
Microsoft has confirmed that some Windows applications are encountering errors when printing or creating PDF files after installing the August 2026 updates.
Prosecutors in Taiwan have announced that nine individuals are being investigated for illegally exporting artificial intelligence servers containing advanced Nvidia chips to China.
At the World Humanoid Robot Competition in Beijing, the Chinese robot "Tiangong Ultra" ran the 100 meters in 9.39 seconds, surpassing Usain Bolt's record of 9.58 seconds.
China's 'Bilibili' reportedly paying creators $0.70 per 1k views — quickly rising to challenge RIVAL platform Youtube.
According to the Cyberban International Task Force, the UK and Ukraine have signed an agreement to jointly develop artificial intelligence technologies in the fields of defense and security. Under this agreement, British researchers will have access to data from the Ukrainian battlefield to train AI systems.
Researchers Uncover Covert Global Telecom Surveillance Campaigns

Citizen Lab has uncovered two sophisticated surveillance campaigns exploiting the infrastructure that connects mobile operators around the world.

The investigation provides rare real-world visibility into how suspected commercial surveillance vendors can abuse trusted telecom signalling networks to covertly locate and track mobile subscribers.

* Attackers combined 3G SS7 and 4G Diameter signalling techniques

* One campaign used specially crafted SMS messages containing hidden SIM commands designed to extract location information

* Surveillance tooling spoofed mobile-operator identities and manipulated signalling protocols and routing paths

* Researchers observed infrastructure and identifiers associated with operators across numerous countries, including the UK, Israel, China, Thailand, Sweden, Italy, Cambodia, Mozambique, Uganda, Rwanda, Poland, Switzerland, Morocco, Namibia and others

* Some operator identifiers were reportedly reused for years, indicating persistent surveillance activity

* Researchers identified routing mismatches suggesting surveillance traffic could enter the SS7 ecosystem through third-party interconnect providers

* Both actors manipulated signalling identifiers to obscure the true origin of their traffic

* Citizen Lab describes these actors as effectively operating as "Ghost Operators" — hiding behind legitimate telecom identities while conducting surveillance

What could attackers obtain?

Observed signalling queries sought information including:

* Current device location
* Cell ID and network location information
* Subscriber/network status
* IMEI
* Radio access technology
* Local time zone
* 4G tracking-area and cell information

This research highlights a cybersecurity layer most users never see.

An attacker does not necessarily need to compromise the smartphone itself to conduct surveillance. Access to trusted telecom signalling infrastructure can potentially enable remote location tracking while much of the activity remains inside private carrier networks.

The larger problem is architectural: global roaming was built around trust between telecommunications providers, and sophisticated surveillance actors appear to be exploiting that trust.

Importantly, Citizen Lab does NOT attribute these campaigns to a specific government or organization and cautions that operator identifiers observed in malicious traffic do not necessarily mean those operators knowingly participated.

Source: Citizen Lab — "Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors"

#TGITM
Yemeni Cyberattack on the Zionist Regime's Power Grid

The hacking group "Uways al-Qarani" (أويس القرني) claimed in a statement that it carried out a cyber operation against the Zionist regime's electricity infrastructure.

The group stated that in this operation, the power grid's industrial control systems were targeted, and a large solar power plant near Tel Aviv, comprising more than 5,000 solar panels, was taken offline.

Hebrew-language media covered the news with concern, and in referencing this attack, warned about the vulnerability of the Zionist regime's critical infrastructure to cyberattacks.

This attack shows that Yemen has extended its confrontation with the Zionist regime into cyberspace, targeting the regime's critical infrastructure.

#CyberAttack #Yemen #ZionistRegime #Hacking #CyberWarfare #TGITM

@TheGhostITM
According to the Cyber Security Task Force, the Australian Cyber Security Centre has issued a warning about the active exploitation of a critical vulnerability, CVE-2026-63077, in the TeamCity platform developed by JetBrains.
A Marimo notebook can launch MCP commands before cells run.

CVE-2026-75149 triggers when a crafted notebook is opened in edit mode. It affects versions before 0.23.15.
Marimo fixed it in 0.23.15.
WhatsApp now supports multiple passkeys per account.

Users can now use phishing-resistant passkeys across iOS and Android. It’s also adding full passwords for two-step verification and more context for unknown Android calls.

WhatsApp says 1 billion+ people already use them.