Cyber Dispatch™️
393 subscribers
32 photos
2 videos
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
According to the Cyberban International Task Force, the UK and Ukraine have signed an agreement to jointly develop artificial intelligence technologies in the fields of defense and security. Under this agreement, British researchers will have access to data from the Ukrainian battlefield to train AI systems.
Researchers Uncover Covert Global Telecom Surveillance Campaigns

Citizen Lab has uncovered two sophisticated surveillance campaigns exploiting the infrastructure that connects mobile operators around the world.

The investigation provides rare real-world visibility into how suspected commercial surveillance vendors can abuse trusted telecom signalling networks to covertly locate and track mobile subscribers.

* Attackers combined 3G SS7 and 4G Diameter signalling techniques

* One campaign used specially crafted SMS messages containing hidden SIM commands designed to extract location information

* Surveillance tooling spoofed mobile-operator identities and manipulated signalling protocols and routing paths

* Researchers observed infrastructure and identifiers associated with operators across numerous countries, including the UK, Israel, China, Thailand, Sweden, Italy, Cambodia, Mozambique, Uganda, Rwanda, Poland, Switzerland, Morocco, Namibia and others

* Some operator identifiers were reportedly reused for years, indicating persistent surveillance activity

* Researchers identified routing mismatches suggesting surveillance traffic could enter the SS7 ecosystem through third-party interconnect providers

* Both actors manipulated signalling identifiers to obscure the true origin of their traffic

* Citizen Lab describes these actors as effectively operating as "Ghost Operators" — hiding behind legitimate telecom identities while conducting surveillance

What could attackers obtain?

Observed signalling queries sought information including:

* Current device location
* Cell ID and network location information
* Subscriber/network status
* IMEI
* Radio access technology
* Local time zone
* 4G tracking-area and cell information

This research highlights a cybersecurity layer most users never see.

An attacker does not necessarily need to compromise the smartphone itself to conduct surveillance. Access to trusted telecom signalling infrastructure can potentially enable remote location tracking while much of the activity remains inside private carrier networks.

The larger problem is architectural: global roaming was built around trust between telecommunications providers, and sophisticated surveillance actors appear to be exploiting that trust.

Importantly, Citizen Lab does NOT attribute these campaigns to a specific government or organization and cautions that operator identifiers observed in malicious traffic do not necessarily mean those operators knowingly participated.

Source: Citizen Lab — "Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors"

#TGITM
Yemeni Cyberattack on the Zionist Regime's Power Grid

The hacking group "Uways al-Qarani" (أويس القرني) claimed in a statement that it carried out a cyber operation against the Zionist regime's electricity infrastructure.

The group stated that in this operation, the power grid's industrial control systems were targeted, and a large solar power plant near Tel Aviv, comprising more than 5,000 solar panels, was taken offline.

Hebrew-language media covered the news with concern, and in referencing this attack, warned about the vulnerability of the Zionist regime's critical infrastructure to cyberattacks.

This attack shows that Yemen has extended its confrontation with the Zionist regime into cyberspace, targeting the regime's critical infrastructure.

#CyberAttack #Yemen #ZionistRegime #Hacking #CyberWarfare #TGITM

@TheGhostITM
According to the Cyber Security Task Force, the Australian Cyber Security Centre has issued a warning about the active exploitation of a critical vulnerability, CVE-2026-63077, in the TeamCity platform developed by JetBrains.
A Marimo notebook can launch MCP commands before cells run.

CVE-2026-75149 triggers when a crafted notebook is opened in edit mode. It affects versions before 0.23.15.
Marimo fixed it in 0.23.15.
WhatsApp now supports multiple passkeys per account.

Users can now use phishing-resistant passkeys across iOS and Android. It’s also adding full passwords for two-step verification and more context for unknown Android calls.

WhatsApp says 1 billion+ people already use them.
E4del and PINHOLE RATs hide commands in FTP banners.

The campaigns turn FTP server welcome messages into dead drop resolvers to fetch commands or C2 details.

PINHOLE also uses Pinterest and SurveyMonkey for C2 resolution.
Attackers are actively exploiting a CVSS 10.0 Oracle WebLogic flaw

CVE-2026-21962 can let unauthenticated attackers access or modify critical data in Oracle HTTP Server and WebLogic Server Proxy Plug-in via HTTP.
Cyber Dispatch™️
Yemeni Cyberattack on the Zionist Regime's Power Grid The hacking group "Uways al-Qarani" (أويس القرني) claimed in a statement that it carried out a cyber operation against the Zionist regime's electricity infrastructure. The group stated that in this operation…
Why would a Yemeni cyber group call itself “Uways al-Qarani”? Because names matter. It invokes a revered Yemeni Islamic figure, signaling identity, legitimacy, and ideological purpose—turning cyber ops into part of a wider resistance, not just technical disruption.
A large-scale DDoS attack has targeted the shared infrastructure of Norway's digital government services since Monday, causing disruptions to some public services.
Cyber Dispatch™️
A large-scale DDoS attack has targeted the shared infrastructure of Norway's digital government services since Monday, causing disruptions to some public services.
Systems such as government login, digital identification, electronic signatures, and tax services have experienced outages, slowdowns, or login issues. Norwegian officials have stated that some services are now stable, and there is no evidence of breaches or theft of personal information.
Peru and the Israeli regime are seeking to deepen cooperation in the field of cybersecurity.
Memory chips from the Chinese company CXMT, which previously struggled to reach speeds of 6400 MT/s, have now achieved a speed of 9000 MT/s in DDR5 kits.
New details emerge about the cyberattack on an American oil tanker in Gibraltar.
Cyber Dispatch™️
New details emerge about the cyberattack on an American oil tanker in Gibraltar.
Following reports about the cyberattack on the oil tanker "VL Prosperity" in the Strait of Gibraltar, Captain Mamdouh bin Jaber Al-Saqt, a seasoned Saudi captain, has revealed more details about the incident.

According to Al-Saqt, the oil tanker was targeted by a cyberattack on the night of August 7, 2026. The attackers disrupted the operation of critical parts of the ship by interfering with the engine control systems and fuel tanks. Communication with the vessel was also down for approximately 30 hours.
Researchers have warned about a security vulnerability in NVIDIA NemoClaw that, under certain circumstances, allows an attacker to access a local Ollama instance by redirecting a user to a malicious website, even without authentication.
Meta agrees to $17.1 billion settlement over alleged harms to children.
GTA 6 leak hype abused to distribute Vidar infostealer malware.
Carhartt data breach affects 12.9M, half of what ShinyHunters claimed.
Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges.

The first (tracked as CVE-2026-77537) lets unauthenticated attackers compromise unpatched devices by exploiting an improper input validation weakness in the UniFi Protect Application video surveillance management platform.

Ubiquiti also addressed a CRLF injection flaw (CVE-2026-77550) that remote attackers without privileges can exploit to bypass authentication on UniFi OS devices or instances.
Cyber Dispatch™️
Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges. The first (tracked as CVE-2026-77537) lets unauthenticated attackers compromise unpatched devices by exploiting…
"A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running CRLF Injection to bypass authentication to such UniFi OS devices or instances," it explained.

The third maximum severity vulnerability patched today is a command injection security flaw (CVE-2026-77554) stemming from improper input validation in the UniFi Talk Application Voice over IP (VoIP) phone system.