Cyber Dispatch™️
400 subscribers
34 photos
2 videos
54 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch
Download Telegram
Nvidia CEO: AI Companies Should Not Be Exempt from Antitrust Laws — Jensen Huang says AI firms seeking new regulations shouldn't simultaneously ask for exemptions from existing antitrust and product liability rules.
Israel is pushing propaganda through YouTube ads being served in Germany, carrying the State emblem and the line "Click to expose the UN's lies."

The ads follow "The UN's Lie Industry," a campaign Israel launched recently to influence the policies of US and European capitals toward Israel.

Google says it no longer serves political ads in the EU at all, yet here we are.
A former U.S. Army soldier who stole call and text metadata of over 100 million AT&T customers has been sentenced to 70 months in prison, after it was revealed that while awaiting sentencing he used other inmates' email accounts to have contacts prompt a commercial AI tool for working exploit code.

Cameron Wagenius, 22, known online as Kiberphant0m and arrested in December 2024, sought Windows privilege escalation scripts and code for the D-Link flaw CVE-2023-45208, and asked for help researching a prison escape, prosecutors say, though they know of no evidence he deployed any of it.

AT&T paid his group a $370,000 ransom, yet he made only around $1,500 selling stolen data.
Google says ShinyHunters is mass-exploiting an Oracle PeopleSoft flaw, using a trick that slips past the firewall rules companies relied on instead of patching, and has planted web shells on dozens of systems worldwide.
ShinyHunters told The Register they hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job and that its FBI hack was "a public relations and marketing initiative for our business."
A 16-year-old hacker broke into an internal Microsoft analytics service with a forged, unsigned login token and ran SQL as admin, reaching databases that held over 17 trillion rows, including Bing search analytics and 17,990 employee email records.

The service, called Titan, checked every field on the token except its signature, so just claiming to be "admin" got him in, writes the researcher, who goes by Faav.
Cyber Dispatch™️
A 16-year-old hacker broke into an internal Microsoft analytics service with a forged, unsigned login token and ran SQL as admin, reaching databases that held over 17 trillion rows, including Bing search analytics and 17,990 employee email records. The service…
He says he only pulled metadata and two single rows of Bing data, never touched customer data, and reported the flaw to Microsoft the same night.

Microsoft locked the endpoint four days later, paid him $5,000, and had editorial control over his write-up, cutting sections and figures and reshaping how the impact was described before it went public.
The Pentagon, the Secret Service and ICE's investigative arm bought phone forensics software from Oxygen Forensics that prosecutors say five Russians secretly controlled through a Cyprus holding company, while selling the same software in Russia to customers including the FSB.
Cyber Dispatch™️
The Pentagon, the Secret Service and ICE's investigative arm bought phone forensics software from Oxygen Forensics that prosecutors say five Russians secretly controlled through a Cyprus holding company, while selling the same software in Russia to customers…
Their CEO Lee Reiber was arrested in Idaho and Russian co-founder Oleg Davydov at London's Heathrow Airport before boarding a flight to Istanbul, and both are charged with conspiracy to commit wire fraud.

Prosecutors say Davydov moved the build servers to U.S. cloud computers so Reiber could tell federal buyers the code was built in America, while a team in Russia kept writing it.
Cyber Dispatch™️
ShinyHunters says it breached the FBI and stole data on agents and job applicants. The FBI says it is investigating claims of unauthorized activity affecting FBIjobs[.]gov. ShinyHunters also claims a PeopleSoft zero-day was used, but no public technical…
The FBI hack exposed members of the Bureau's own secretive hacking team, leaving their addresses, phone numbers and in some cases their spouses' names in the stolen data.

Three entries in the list of 5,000 alleged FBI officials that ShinyHunters shared with media mention the Remote Operations Unit, which builds exploits and tools to break into targets' devices.
US company Meta has, without explanation, disabled Lula’s Instagram and Facebook profiles’ ability to run ads, 10 days from election.

The President’s campaign has complained and threatened legal action, citing this as another example of US interference and manipulation.
Brazilian President Lula bans online gambling ahead of presidential election.
Israel's Diaspora Ministry publishes weekly reports listing upcoming pro-Palestinian protests worldwide with exact dates, times, GPS coordinates, distance to nearest Israeli embassy, organizing groups' names and follower counts, and risk ratings.

The reports cover dozens of countries and have compiled roughly 2,000 entries.

A systematic surveillance and naming of protest organizers.

The reports are publicly posted on http://gov.il as open-source monitoring.
Lunex uses a vulnerable AMD driver to blind security monitoring before stealing browser credentials.

The BYOVD chain zeroes kernel callbacks tied to security products, then the stealer collects credentials and cryptocurrency wallet data.
One URL-encoded character is helping attackers bypass WAF rules protecting Oracle PeopleSoft.

UNC6240/ShinyHunters is exploiting CVE-2026-35273 to deploy web shells on dozens of systems, then using post-exploitation tools including SIDEEYE.
An attacker bypassed auth on an employee-run AI agent, obtained its model provider API key, and racked up the equivalent of $600,000 in token use over three weeks.

There was no spending limit, and dashboard gaps helped the activity go unnoticed.
Elementor CSRF flaw can create a rogue WordPress admin account when an administrator opens a crafted link.

The bug affects 4.3.0 and 4.3.1, bypasses CSRF protection across the site's REST API, and is fixed in 4.3.2.
ShinyHunters' New Tactic Against Oracle Servers — The ShinyHunters group bypassed WAF protections via URL-encoded paths to exploit CVE-2026-35273 in Oracle PeopleSoft, infecting dozens of systems globally with web shells; experts recommend patching instead of relying on WAFs.
New Details on Astrana Health Cyberattack — Attackers impersonated Astrana employees using spoofed phone numbers to breach servers; private data may have been stolen. Systems were restored from backups, and authorities were notified.
China-U.S. Agree on $30 Billion Tariff Cuts — China announced an eight-point deal with the U.S. to mutually cut $30 billion in tariffs and begin talks on AI risks, including a joint business council and a communication channel for AI incidents.
$350 Million Stolen in Bitget Exchange Hack — Crypto exchange Bitget suffered a cyberattack with roughly $350 million in assets stolen; withdrawals were temporarily suspended as the investigation continues.