Cyber Dispatch™️
403 subscribers
34 photos
4 videos
56 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch
Download Telegram
Cyber Dispatch™️
Indian shadow accounts: A fake Indian Instagram profile was used to request the removal of posts about a Brazilian senator’s assets during the 2026 elections.
Abin warning: A report by the Brazilian Intelligence Agency (Abin), titled “Threats to the 2026 Electoral Process,” explicitly warned of right-wing influencers based in the U.S. running paid electoral propaganda for Flávio Bolsonaro on X.
Microsoft Report: Rise in Cyberattacks Against the Zionist Regime

According to Microsoft’s annual report, the Zionist regime (Israel) was the world’s second most-targeted entity for cyberattacks in the first half of 2026, accounting for 7.6% of recorded attacks.

· The United States ranked first with 25.5%, while Ukraine and Taiwan placed after the Zionist regime.

· Microsoft claims that 39% of one tracked cyber threat cluster’s activity targeted the Zionist regime. The United States followed at 23%, and the UAE at 9%.

· The report says this activity included cyber espionage, disruption attempts, and destructive attacks. Attackers used methods such as phishing, credential theft, and exploitation of vulnerabilities.

The findings highlight how geopolitical tensions continue to shape the global cyber threat landscape, attackers increasingly targeting government, defense, critical infrastructure, and technology sectors. Microsoft’s telemetry indicates that attackers are combining espionage with disruptive operations, aiming to gather intelligence, weaken response capacity, and create psychological impact.

The report also points to a growing use of credential theft and vulnerability exploitation — techniques that make it easier for attackers to get their first foothold inside a system and then carry out more damaging attacks from there.

#CyberAttack #CyberWar #Iran #ZionistRegime #Microsoft #TGITM @TheGhostITM
U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog.
Dell patches critical vulnerabilities in container storage modules.
Frontline Education breach exposes school district employee data.
Warlock ransomware breach SharePoint in water, telecom operator attacks.
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign.
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers.
OpenAI alerts 100+ orgs that its 'misaligned models' attempted to break in - or worse.
EU urged to strengthen risk assessment for critical infrastructure vendors.
OpenAI's wandering AI agents earn it a California subpoena.
Californian accused of shipping $300M worth of Nvidia chips to China without Uncle Sam’s approval.
US sanctions Tren de Aragua gang members in ATM hacks crackdown.
Convincing Free Mobile phishing emails appear after data breach.
OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling.
Dell asks admins to patch max severity CSM flaws as soon as possible.
An Iranian national who was indicted in the United States for hacking hundreds of organizations was extradited from Montenegro this week.

Acting on an FBI-issued arrest warrant, Montenegrin authorities arrested the individual—a dual citizen of Turkey and Iran—on June 25.

The suspect is accused of taking part in numerous cyberattacks against US organizations beginning in 2013. The attacks caused more than $3.4 billion in losses.

Montenegrin authorities did not identify the individual by name, but gave his initials, A.B., and said he is 40 years old.

According to the indictment, the suspects launched attacks against 144 universities in the US and 178 abroad, 42 private companies in the US and 11 abroad, five US government agencies, and at least two NGOs.

The individuals stole over 31 terabytes of scientific resources, including academic data and intellectual property, as well as employee email accounts. The stolen information was given to the Iranian government and sold to Iranian universities.

The US government is offering rewards of up to $10 million for information on five of the Iranian hackers: Mesri, Galekuhi, Kahzadian, Fayaz, and Ballojeh.

Extraditions of Iranian hackers to face trial in the US are extremely rare, because hackers usually operate from inside Iran and avoid traveling to jurisdictions with US extradition treaties.

#TGITM @TheGhostITM
Antino turns Outlook and OneDrive into command-and-control channels.

China-nexus UAT-11587 is using the Rust backdoor in spear-phishing attacks targeting government and policy organizations across Asia.
GitLab has patched a critical 9.9-rated flaw in its self-hosted AI Gateway that could let low-privileged Duo Agent users escape the prompt sandbox and execute commands on the underlying server.

Affected self-hosted deployments should update immediately.
Operation KillSwitch Dismantles KillSec Ransomware Gang; 16-Year-Old Alleged Leader Arrested

ALICANTE, Spain — An international law enforcement operation has dismantled the KillSec ransomware group and arrested a 16-year-old suspected of running it, authorities said. The teen was taken into custody in Alicante, Spain, and identified as the group’s main administrator and operator.

The operation, led by German police in Hamburg, involved authorities from Belgium, the United States, Finland, Greece, the Netherlands, Spain, Switzerland, the United Kingdom, Europol, and Eurojust. Two other suspects were arrested: one in the United Kingdom, identified as Dutch national Fouad Eltibrizi, and one in Romania.

As part of the takedown, investigators seized KillSec’s dark web leak site, replacing it with a law enforcement seizure notice. Five central servers were brought under police control, including the group’s main server and infrastructure used to store stolen data. At least 110 terabytes of stolen data were secured to prevent further unauthorized access.

The investigation covers approximately 1,000 suspected attacks worldwide, with about 500 identified as successful so far. At least 70 attacks have been linked to organizations in Germany, including 18 cases connected to Hamburg.

KillSec launched its ransomware-as-a-service platform in June 2024, charging affiliates a $250 entry fee and allowing them to keep 88% of successful ransom payments. The group exploited software vulnerabilities and poorly secured edge devices to breach corporate systems, steal sensitive data, and extort victims through its leak site. Investigators also found that members used artificial intelligence to help build and maintain their ransomware infrastructure.

Authorities said the probe remains ongoing. Victims and organizations that may have been affected are encouraged to contact law enforcement.

#TGITM @TheGhostITM