Cyber Dispatch™️
386 subscribers
22 photos
1 video
56 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
JLR: Payroll data stolen in cybercrime that shook UK economy.
PayPal closes loophole that let scammers send real emails with fake purchase notices.
16TB of MongoDB Database Exposes 4.3 Billion Lead Gen Records.
Ink Dragon, a China-aligned hacking group, is focusing on European government targets while staying active in Asia and South America.

It exploits SharePoint and IIS flaws to drop web shells and maintain long-term access using ShadowPad and FINALDRAFT malware.
Researchers uncover GhostPoster malware hidden in 17 Firefox add-ons with 50,000+ downloads.

Disguised as VPNs, translators, and ad blockers. 50k+ installs.

JavaScript was hidden inside logo images, activated after days, then hijacked links, tracked browsing, and ran ad fraud.
Amazon flagged a new AWS crypto-mining campaign using custom persistence techniques.

Attackers validate permissions with DryRun, deploy miners across ECS and EC2, then enable instance termination protection to block cleanup.
A fake NuGet package stole crypto wallets for more than five years.

It copied a popular .NET tracing library and hid as a normal dependency. One extra letter in the author name led to about 2,000 downloads since 2020.

It exfiltrated Stratis wallet JSON files and passwords to a Russian IP.
Amazon confirms a Russian GRU unit hacked Western energy and infrastructure networks for years.

The threat wasn’t malware, it was silent credential theft from live traffic.

From 2021–2025, APT44 relied less on zero-days and more on exposed routers and VPN gateways.
Fortinet FortiGate devices are under active attack via SSO authentication bypass flaws.

CVE-2025-59718 and CVE-2025-59719 both have CVSS scores of 9.8 and exploit the FortiCloud SSO feature.

Disable FortiCloud SSO until systems are fully updated.
Attackers are abusing React2Shell to plant Linux backdoors like KSwapDoor and ZnDoor.

This hits orgs that left React and Next.js servers unpatched.

Microsoft saw reverse shells, Cobalt Strike, and stolen cloud tokens tied to CVE-2025-55182, and Shadowserver tracks over 111,000 exposed IPs.
Cyber resistance group Handala hacked the personal phone of former Israeli Prime Minister Naftali Bennett.

Dubbed "Operation Octopus", the hackers published the following message for the former Israeli prime minister, along with his phone number, voice logs, photos, videos, and contacts, which include "senior officials of the Zionist regime":

"Dear Naftali Bennett,

You once prided yourself on being a beacon of cybersecurity, parading your expertise before the world. Yet, how ironic that your own iPhone 13 has fallen so easily to the hands of Handala. For all your boasts and bravado, your digital fortress was nothing more than a paper wall waiting to be breached.

Consider this a warning and a lesson. If your personal device can be compromised so effortlessly, imagine the vulnerabilities that lurk within the systems you once claimed to protect. Next time you preach about security, remember: those who live in glass houses shouldn’t throw stones.

Welcome to a new era, where your secrets are only as safe as your weakest password.

Sincerely,
Handala"
👏1
Handala hacked Bennett’s iPhone 13.
Handala succesfully infiltrated Israel’s fuel supply system. 300k classified documents were forcefully grabbed. These files reveal extensive collaboration between Delek Group and the Israeli military, including detailed fuel supply contracts and access to their updated internal databases.
Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App.
CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation.
Kimwolf Botnet Hijacks 1.8 Million Android TVs, Launches Large-Scale DDoS Attacks.
WhatsApp device linking abused in account hijacking attacks.
Amazon: Ongoing cryptomining campaign uses hacked AWS accounts.
Zeroday Cloud hacking event awards $320,0000 for 11 zero days.
France Arrests 22 Year Old After Hack of Interior Ministry Systems.
Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances.