Cyber Dispatch™️
403 subscribers
34 photos
4 videos
56 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch
Download Telegram
Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data.
Cyber Dispatch™️
Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data.
The Pentagon is informing more than 2 million current and former military members that their personnel records storing sensitive personal information were stolen over a monthslong compromise of one of its networks. The breach is the second one in recent months to expose sensitive government information.

The records, according to one notification letter posted to Reddit, included Social Security numbers, names, addresses, sex, race, and occupational specialty. This last category could be particularly valuable to foreign adversaries because it could help their intelligence agencies in identifying high-value military personnel. Starting last October, hackers gained access to a system operated by the Defense Manpower Data Center, which collates Department of Defense personnel records. The Pentagon says that the breach compromised the records of 2.8 million living individuals.
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline.
Huawei and Qualcomm Announce Broad Patent License Agreement.
Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions.
More than 25 years after the fat PlayStation 2 launched, a dev known as DiscoStarslayer has managed to pull firmware out of the stubborn SPC970 MechaCon chip responsible for authorizing discs and handling most of the console's security.

In a Bluesky post, the dev credited Libby, the collaborator who found an exploit that made the extraction possible. According to the dump tool's docs, that exploit told the chip that an incoming batch of settings data would be empty, and sent more data than it had room for. Before this, in an effort covering some four years, there had been struggles with a slower method of stripping the chip's packaging and reading its contents, which produced only rough dumps.
Cyber Dispatch™️
More than 25 years after the fat PlayStation 2 launched, a dev known as DiscoStarslayer has managed to pull firmware out of the stubborn SPC970 MechaCon chip responsible for authorizing discs and handling most of the console's security. In a Bluesky post…
Everything has been pushed to GitHub alongside 22 firmware images covering fat PS2s from the Japan-only SCPH-15000 of 2000 to the 39000-series models of 2002. They also cover the Namco System 246 and 256 arcade boards that used the same chip. These early machines were some of the final unread parts of the PS2 after the 2003 "Dragon" MechaCon was dumped in 2021.
Attackers are targeting a Rejetto HFS flaw that enables forged admin sessions and remote code execution.

CVE-2026-61500 affects HFS 3.0.0–3.2.0. VulnCheck detected exploitation attempts against vulnerable U.S. hosts after a public PoC was released.
Citrix has patched a new NetScaler zero-day exploited in targeted attacks.

CVE-2026-88779 affects certain SAML-configured deployments & can cause denial-of-service, with repeated triggering potentially leaving services unavailable.
OpenAI CEO Sam Altman on AI

We believe that the world should accept some bad things happening for the benefits of this technology and people having the agency.
ShinyHunters Suspect Detained in Jordan, Assisting FBI

By TGITM

A member of the ShinyHunters extortion collective, operating under the handle "Rey," has reportedly been taken into custody in Jordan and is now cooperating with the FBI to help identify and locate remaining members of the group.

Jordanian officials detained Rey — identified as Saif al-Din Khader — earlier this week, with sources confirming his arrest took place on Tuesday.

Those familiar with the matter say Khader is actively assisting the FBI and other international law enforcement bodies in tracking down fellow members.

According to one source, Khader is guiding investigators through his devices and digital correspondence to help pinpoint his alleged accomplices.

"His cooperation is essential to the ongoing effort to bring these hackers to justice," the source stated.

The reported detention arrives as the FBI intensifies its pursuit of ShinyHunters following the group's cyberattack on the bureau itself.

In September, ShinyHunters claimed it compromised FBI systems by exploiting an alleged Oracle PeopleSoft zero-day flaw, then moved laterally into FBI-managed AWS GovCloud environments.

The attackers claimed to have exfiltrated between 2TB and 3TB of data, including records tied to current and former FBI personnel, job applicants, medical and psychiatric information, and internal service records.

The FBI previously acknowledged it was investigating reports of unauthorized activity but did not confirm any data exfiltration.

Following the FBI breach, Dutch police arrested a 24-year-old man from Amsterdam on September 15 as part of the ShinyHunters investigation.

The suspect was identified as Pepijn van der Stap, who previously operated under the alias "Umbreon."

After that arrest, the FBI issued a public warning to other ShinyHunters members, urging them to surrender voluntarily, noting that investigators were still working to identify those involved.

"Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left," said Brett Leatherman, Assistant Director of the FBI Cyber Division.

"The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."

The group's primary spokesperson continued communicating with media outlets after van der Stap's arrest, indicating that individual was not the one running that messaging account.

On Tuesday — the same day Khader was reportedly detained — early signs of disruption emerged within the ShinyHunters operation.

An alleged ShinyHunters affiliate who had previously reached out to media regarding the FBI attack and a recent Clop ransomware data breach abruptly closed their online messaging account.

Shortly after, the ShinyHunters data leak site went dark, and the group's main representative also ceased responding to inquiries from journalists.

It remains unclear whether the sudden silence and shutdown of ShinyHunters-linked infrastructure are directly tied to Khader's reported detention.

However, by Thursday, a new ShinyHunters data leak site was back online, suggesting other members are still running the extortion operation.

The ShinyHunters gang has long been a persistent threat to law enforcement, carrying out large-scale data theft and extortion campaigns against organizations around the world.

In recent years, the group has focused heavily on Salesforce and other cloud SaaS environments, with campaigns linked to breaches at Google, Cisco, and PornHub.

The group typically compromises third-party integration firms and leverages stolen authentication tokens to access connected SaaS platforms and extract customer data.
ShinyHunters was also responsible for a massive data-theft attack on Instructure Canvas in May that triggered significant platform outages. The company ultimately reached a "deal" with the threat actors to prevent the stolen data from being published online.

Over the years, multiple arrests have been tied to the ShinyHunters name, including suspects connected to Snowflake data-theft attacks, breaches at PowerSchool, and the operation of the Breached v2 hacking forum.

Who is Rey?

The threat actor known as Rey has been associated with numerous data theft and extortion attacks over the past two years.

In January 2025, Rey was one of four threat actors who claimed responsibility for a breach of Telefónica's internal Jira ticketing system, in which approximately 2.3GB of documents, tickets, and other data were allegedly stolen.

Rey and two of the other attackers were members of the then-emerging HellCat ransomware operation.

The actor was later linked to a broader series of attacks targeting Jira servers at organizations worldwide.

In February 2025, Orange confirmed that its Romanian operations were hit by a cyberattack after Rey leaked approximately 6.5GB of stolen data. Rey stated at the time that he was a member of HellCat but had carried out the Orange breach independently.

Rey was subsequently linked to the ShinyHunters extortion group and was seen holding administrative privileges in Telegram channels run by "Scattered Lapsus$ Hunters."

Scattered Lapsus$ Hunters first appeared in 2025 and claimed to be composed of former members of the Lapsus$, Scattered Spider, and ShinyHunters cybercrime groups.

The collective claimed responsibility for the September 2025 cyberattack on Jaguar Land Rover that forced the automaker to halt production for weeks and ultimately cost the company more than $220 million.

Rey was also connected to an earlier March 2025 breach of Jaguar Land Rover, in which the actor leaked gigabytes of data, including Jira issues, source code, employee information, and development logs.

In November 2025, Rey's real identity — Saif Al-Din Khader — was confirmed after analysis of infostealer logs and direct communication over Signal.

Khader stated he was trying to distance himself from Scattered Lapsus$ Hunters and claimed he had been cooperating with law enforcement since at least June.

"I'm already cooperating with law enforcement," Khader stated. "In fact, I have been talking to them since at least June. I have told them nearly everything. I haven't really done anything like breaching into a corp or extortion related since September."

Those claims could not be independently verified.

#TGITM
Microsoft ranked the UAE sixth and Israel second among countries facing the highest levels of recorded cyberattacks between January and June 2026.
Robotics startup Safeworld raised more than $12 million to test the safety of AI-powered robots in simulated human environments.
Ukrainian officials warned of Russian-linked attacks targeting iPhones used by military personnel and government employees.
Microsoft, the UAE Cybersecurity Council, and Core42 are deploying AI-powered cybersecurity capabilities for UAE government institutions.
ClickFix has a new trick... the malicious payload is already sitting in your browser cache before you paste the command.

Compromised sites preload scripts disguised as PNGs, letting pasted commands bypass Windows Run's ~260-character limit and launch a multi-stage malware chain.
Exchange admins should review this now.

CVE-2026-96940 can allow an authenticated attacker to access other users’ mailboxes and read emails and attachments within the same organization.
Cling hides C2 commands in STUN traffic as threat actors were observed attempting to exploit Realtek Jungle SDK flaw CVE-2021-35394. A subset of that activity delivered the botnet.
Azerbaijan, Türkiye, and Uzbekistan held their first joint cyber exercise, “Power of Unity 2026,” in Karabakh, focusing on cyberattacks, drone threats, and disinformation.
NEC plans to connect its operations centers in Japan, the United States, and Europe to provide round-the-clock global cyber-threat monitoring from July 2027.