Cyber Dispatch™️
403 subscribers
34 photos
4 videos
56 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch
Download Telegram
Operation KillSwitch Dismantles KillSec Ransomware Gang; 16-Year-Old Alleged Leader Arrested

ALICANTE, Spain — An international law enforcement operation has dismantled the KillSec ransomware group and arrested a 16-year-old suspected of running it, authorities said. The teen was taken into custody in Alicante, Spain, and identified as the group’s main administrator and operator.

The operation, led by German police in Hamburg, involved authorities from Belgium, the United States, Finland, Greece, the Netherlands, Spain, Switzerland, the United Kingdom, Europol, and Eurojust. Two other suspects were arrested: one in the United Kingdom, identified as Dutch national Fouad Eltibrizi, and one in Romania.

As part of the takedown, investigators seized KillSec’s dark web leak site, replacing it with a law enforcement seizure notice. Five central servers were brought under police control, including the group’s main server and infrastructure used to store stolen data. At least 110 terabytes of stolen data were secured to prevent further unauthorized access.

The investigation covers approximately 1,000 suspected attacks worldwide, with about 500 identified as successful so far. At least 70 attacks have been linked to organizations in Germany, including 18 cases connected to Hamburg.

KillSec launched its ransomware-as-a-service platform in June 2024, charging affiliates a $250 entry fee and allowing them to keep 88% of successful ransom payments. The group exploited software vulnerabilities and poorly secured edge devices to breach corporate systems, steal sensitive data, and extort victims through its leak site. Investigators also found that members used artificial intelligence to help build and maintain their ransomware infrastructure.

Authorities said the probe remains ongoing. Victims and organizations that may have been affected are encouraged to contact law enforcement.

#TGITM @TheGhostITM
UN Security Council to Examine Emerging Technology Threats — On October 29, 2026, the council is expected to discuss how AI, cyberattacks, and autonomous technologies affect international peace and security.
Apple Strengthens Mac Security Against AI Risks — Apple plans stricter controls for Full Disk Access to prevent third-party software and AI agents from freely accessing sensitive user data.
GitLab Patches Critical AI Gateway Vulnerability — GitLab fixed a 9.9-severity flaw that could have allowed authorized users to execute arbitrary commands on self-hosted servers.
Taiwanese Foreign Minister to Visit Arizona — The visit aims to strengthen economic and semiconductor cooperation with U.S. officials and technology companies.
OpenAI Fires Three Researchers Over Confidentiality Violations — The employees were dismissed after an internal investigation found that they improperly shared sensitive company information with an independent AI-safety organization.
Google Introduces Mandatory Android Developer Identity Verification — Developers will have to verify their identities before broadly distributing apps, while unverified sideloaded apps may face a 24-hour installation delay.
U.K. Orders Universities to Halt Cooperation With Chinese Research Institute — The government acted after intelligence warnings that the institute’s projects could support Chinese intelligence and military capabilities.
India Warns Cyberattacks Could Trigger a Global Economic Crisis — India’s central bank governor cautioned that a major cyberattack, war, or technical failure could disrupt financial systems and damage the world economy.
Trump Reportedly Consulted Grok About Maduro’s Arrest — Reports claim Donald Trump asked Grok to predict Venezuelan public reaction to the possible removal and arrest of Nicolás Maduro.
Google Supports AI Education in U.S. Universities — The Google Foundation is funding pilot programs to expand AI skills, faculty training, career guidance, and AI curricula across 30 American universities.
Artificial intelligence is becoming an increasingly powerful tool in modern warfare.
In Gaza, Israel has used the technology in surveillance to identify, monitor and analyse Palestinians
Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data.
Cyber Dispatch™️
Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data.
The Pentagon is informing more than 2 million current and former military members that their personnel records storing sensitive personal information were stolen over a monthslong compromise of one of its networks. The breach is the second one in recent months to expose sensitive government information.

The records, according to one notification letter posted to Reddit, included Social Security numbers, names, addresses, sex, race, and occupational specialty. This last category could be particularly valuable to foreign adversaries because it could help their intelligence agencies in identifying high-value military personnel. Starting last October, hackers gained access to a system operated by the Defense Manpower Data Center, which collates Department of Defense personnel records. The Pentagon says that the breach compromised the records of 2.8 million living individuals.
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline.
Huawei and Qualcomm Announce Broad Patent License Agreement.
Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions.
More than 25 years after the fat PlayStation 2 launched, a dev known as DiscoStarslayer has managed to pull firmware out of the stubborn SPC970 MechaCon chip responsible for authorizing discs and handling most of the console's security.

In a Bluesky post, the dev credited Libby, the collaborator who found an exploit that made the extraction possible. According to the dump tool's docs, that exploit told the chip that an incoming batch of settings data would be empty, and sent more data than it had room for. Before this, in an effort covering some four years, there had been struggles with a slower method of stripping the chip's packaging and reading its contents, which produced only rough dumps.
Cyber Dispatch™️
More than 25 years after the fat PlayStation 2 launched, a dev known as DiscoStarslayer has managed to pull firmware out of the stubborn SPC970 MechaCon chip responsible for authorizing discs and handling most of the console's security. In a Bluesky post…
Everything has been pushed to GitHub alongside 22 firmware images covering fat PS2s from the Japan-only SCPH-15000 of 2000 to the 39000-series models of 2002. They also cover the Namco System 246 and 256 arcade boards that used the same chip. These early machines were some of the final unread parts of the PS2 after the 2003 "Dragon" MechaCon was dumped in 2021.
Attackers are targeting a Rejetto HFS flaw that enables forged admin sessions and remote code execution.

CVE-2026-61500 affects HFS 3.0.0–3.2.0. VulnCheck detected exploitation attempts against vulnerable U.S. hosts after a public PoC was released.
Citrix has patched a new NetScaler zero-day exploited in targeted attacks.

CVE-2026-88779 affects certain SAML-configured deployments & can cause denial-of-service, with repeated triggering potentially leaving services unavailable.