Cyber Dispatch™️
393 subscribers
32 photos
2 videos
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands.

The malware now requests VPN service permissions to create a local interface that allows it to control network traffic passing through it. The feature enables ToxicPanda 2.0 to block communication from Google Play and Google Play Services.
Experts say agentic AI and machine identities create significant security risk. As AI shifts from generating content to taking actions, organizations will increasingly need to treat each agent as a privileged identity with access to sensitive systems and data. At the same time, AI-enabled phishing, impersonation, and automated reconnaissance are making traditional indicators of trust less reliable. Defenders are responding with stronger identity controls, phishing-resistant authentication, behavioral monitoring, and zero-trust principles.
The United Arab Emirates is focusing on developing AI-based defense systems in response to a surge in cyberattacks targeting critical infrastructure. According to the country's Cybersecurity Council, attempted intrusions have reached approximately 800,000 per day, four times the level before the war.
Microsoft has confirmed that some Windows applications are encountering errors when printing or creating PDF files after installing the August 2026 updates.
Prosecutors in Taiwan have announced that nine individuals are being investigated for illegally exporting artificial intelligence servers containing advanced Nvidia chips to China.
At the World Humanoid Robot Competition in Beijing, the Chinese robot "Tiangong Ultra" ran the 100 meters in 9.39 seconds, surpassing Usain Bolt's record of 9.58 seconds.
China's 'Bilibili' reportedly paying creators $0.70 per 1k views — quickly rising to challenge RIVAL platform Youtube.
According to the Cyberban International Task Force, the UK and Ukraine have signed an agreement to jointly develop artificial intelligence technologies in the fields of defense and security. Under this agreement, British researchers will have access to data from the Ukrainian battlefield to train AI systems.
Researchers Uncover Covert Global Telecom Surveillance Campaigns

Citizen Lab has uncovered two sophisticated surveillance campaigns exploiting the infrastructure that connects mobile operators around the world.

The investigation provides rare real-world visibility into how suspected commercial surveillance vendors can abuse trusted telecom signalling networks to covertly locate and track mobile subscribers.

* Attackers combined 3G SS7 and 4G Diameter signalling techniques

* One campaign used specially crafted SMS messages containing hidden SIM commands designed to extract location information

* Surveillance tooling spoofed mobile-operator identities and manipulated signalling protocols and routing paths

* Researchers observed infrastructure and identifiers associated with operators across numerous countries, including the UK, Israel, China, Thailand, Sweden, Italy, Cambodia, Mozambique, Uganda, Rwanda, Poland, Switzerland, Morocco, Namibia and others

* Some operator identifiers were reportedly reused for years, indicating persistent surveillance activity

* Researchers identified routing mismatches suggesting surveillance traffic could enter the SS7 ecosystem through third-party interconnect providers

* Both actors manipulated signalling identifiers to obscure the true origin of their traffic

* Citizen Lab describes these actors as effectively operating as "Ghost Operators" — hiding behind legitimate telecom identities while conducting surveillance

What could attackers obtain?

Observed signalling queries sought information including:

* Current device location
* Cell ID and network location information
* Subscriber/network status
* IMEI
* Radio access technology
* Local time zone
* 4G tracking-area and cell information

This research highlights a cybersecurity layer most users never see.

An attacker does not necessarily need to compromise the smartphone itself to conduct surveillance. Access to trusted telecom signalling infrastructure can potentially enable remote location tracking while much of the activity remains inside private carrier networks.

The larger problem is architectural: global roaming was built around trust between telecommunications providers, and sophisticated surveillance actors appear to be exploiting that trust.

Importantly, Citizen Lab does NOT attribute these campaigns to a specific government or organization and cautions that operator identifiers observed in malicious traffic do not necessarily mean those operators knowingly participated.

Source: Citizen Lab — "Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors"

#TGITM
Yemeni Cyberattack on the Zionist Regime's Power Grid

The hacking group "Uways al-Qarani" (أويس القرني) claimed in a statement that it carried out a cyber operation against the Zionist regime's electricity infrastructure.

The group stated that in this operation, the power grid's industrial control systems were targeted, and a large solar power plant near Tel Aviv, comprising more than 5,000 solar panels, was taken offline.

Hebrew-language media covered the news with concern, and in referencing this attack, warned about the vulnerability of the Zionist regime's critical infrastructure to cyberattacks.

This attack shows that Yemen has extended its confrontation with the Zionist regime into cyberspace, targeting the regime's critical infrastructure.

#CyberAttack #Yemen #ZionistRegime #Hacking #CyberWarfare #TGITM

@TheGhostITM
According to the Cyber Security Task Force, the Australian Cyber Security Centre has issued a warning about the active exploitation of a critical vulnerability, CVE-2026-63077, in the TeamCity platform developed by JetBrains.
A Marimo notebook can launch MCP commands before cells run.

CVE-2026-75149 triggers when a crafted notebook is opened in edit mode. It affects versions before 0.23.15.
Marimo fixed it in 0.23.15.
WhatsApp now supports multiple passkeys per account.

Users can now use phishing-resistant passkeys across iOS and Android. It’s also adding full passwords for two-step verification and more context for unknown Android calls.

WhatsApp says 1 billion+ people already use them.
E4del and PINHOLE RATs hide commands in FTP banners.

The campaigns turn FTP server welcome messages into dead drop resolvers to fetch commands or C2 details.

PINHOLE also uses Pinterest and SurveyMonkey for C2 resolution.
Attackers are actively exploiting a CVSS 10.0 Oracle WebLogic flaw

CVE-2026-21962 can let unauthenticated attackers access or modify critical data in Oracle HTTP Server and WebLogic Server Proxy Plug-in via HTTP.
Cyber Dispatch™️
Yemeni Cyberattack on the Zionist Regime's Power Grid The hacking group "Uways al-Qarani" (أويس القرني) claimed in a statement that it carried out a cyber operation against the Zionist regime's electricity infrastructure. The group stated that in this operation…
Why would a Yemeni cyber group call itself “Uways al-Qarani”? Because names matter. It invokes a revered Yemeni Islamic figure, signaling identity, legitimacy, and ideological purpose—turning cyber ops into part of a wider resistance, not just technical disruption.
A large-scale DDoS attack has targeted the shared infrastructure of Norway's digital government services since Monday, causing disruptions to some public services.
Cyber Dispatch™️
A large-scale DDoS attack has targeted the shared infrastructure of Norway's digital government services since Monday, causing disruptions to some public services.
Systems such as government login, digital identification, electronic signatures, and tax services have experienced outages, slowdowns, or login issues. Norwegian officials have stated that some services are now stable, and there is no evidence of breaches or theft of personal information.
Peru and the Israeli regime are seeking to deepen cooperation in the field of cybersecurity.
Memory chips from the Chinese company CXMT, which previously struggled to reach speeds of 6400 MT/s, have now achieved a speed of 9000 MT/s in DDR5 kits.
New details emerge about the cyberattack on an American oil tanker in Gibraltar.