Cyber Dispatch™️
386 subscribers
22 photos
1 video
56 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Venezuela’s state-owned oil company says cyberattack targeted operations, blames US aggression.

Venezuela’s state-owned oil company PDVSA said on Monday that it was targeted by a cyberattack intended to disrupt its operations, describing the incident as part of a broader campaign of external pressure against the country’s energy sector.
Kali Linux 2025.4 Release (Desktop Environments, Wayland & Halloween Mode): Say hello to Kali Linux 2025.4!

The summary of the changelog since the 2025.3 https://www.kali.org/blog/kali-linux-2025-4-release
The official Kali NetHunter Pro documentation page, which links to the images, is:https://www.kali.org/docs/nethunter-pro/

https://kali.download/nethunter-images/current/
French Interior Minister says hackers breached its email servers.
New SantaStealer malware steals data from browsers, crypto wallets.
Google is shutting down its dark web report feature in January.
Askul confirms theft of 740k customer records in ransomware attack.
Amazon security boss blames Russia's GRU for years-long energy-sector hacks.
PornHub extorted after hackers steal Premium member activity data.
SoundCloud confirms breach after member data stolen, VPN access disrupted.
FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE.
JLR: Payroll data stolen in cybercrime that shook UK economy.
PayPal closes loophole that let scammers send real emails with fake purchase notices.
16TB of MongoDB Database Exposes 4.3 Billion Lead Gen Records.
Ink Dragon, a China-aligned hacking group, is focusing on European government targets while staying active in Asia and South America.

It exploits SharePoint and IIS flaws to drop web shells and maintain long-term access using ShadowPad and FINALDRAFT malware.
Researchers uncover GhostPoster malware hidden in 17 Firefox add-ons with 50,000+ downloads.

Disguised as VPNs, translators, and ad blockers. 50k+ installs.

JavaScript was hidden inside logo images, activated after days, then hijacked links, tracked browsing, and ran ad fraud.
Amazon flagged a new AWS crypto-mining campaign using custom persistence techniques.

Attackers validate permissions with DryRun, deploy miners across ECS and EC2, then enable instance termination protection to block cleanup.
A fake NuGet package stole crypto wallets for more than five years.

It copied a popular .NET tracing library and hid as a normal dependency. One extra letter in the author name led to about 2,000 downloads since 2020.

It exfiltrated Stratis wallet JSON files and passwords to a Russian IP.
Amazon confirms a Russian GRU unit hacked Western energy and infrastructure networks for years.

The threat wasn’t malware, it was silent credential theft from live traffic.

From 2021–2025, APT44 relied less on zero-days and more on exposed routers and VPN gateways.
Fortinet FortiGate devices are under active attack via SSO authentication bypass flaws.

CVE-2025-59718 and CVE-2025-59719 both have CVSS scores of 9.8 and exploit the FortiCloud SSO feature.

Disable FortiCloud SSO until systems are fully updated.