Cyber Dispatch™️
386 subscribers
22 photos
1 video
47 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Spotify music library scraped by pirate activist group and made available as a torrent.

Includes 86M audio files, now circulating in bulk torrents totaling ~300 terabytes.

Spotify is "actively investigating the incident."
INTERPOL led a cybercrime sweep across Africa. 574 arrests and $3M recovered after targeting BEC, extortion, and ransomware in 19 countries.

Separately, a Ukrainian Nefilim ransomware affiliate pleaded guilty in the U.S.
Purdue University tested deepfake detectors where they actually break: real, compressed social media video.

Not clean demos. Not lab data.

The benchmark shows why false-acceptance rate matters more than accuracy when camera feeds drive access and trust.
A critical RCE flaw (CVSS 9.9) was found in the n8n workflow automation platform.

CVE-2025-68613 lets authenticated users execute arbitrary code, enabling full instance takeover, data access, and system-level actions.

More than 103k exposed instances are observed globally.
A malicious WhatsApp API package on npm quietly hands attackers full account access.

56,000+ downloads later, “lotusbail” is intercepting every message and secretly linking attacker devices during login.
Vivaldi, a browser company from Iceland and Norway. We make a browser for all major platforms that's big on privacy and customization. Employee-owned, user-focused, and built for people who want actual control over their browsing 🧰
A truly decentralized Signal alternative messenger app with default E2EE, onion-routed messaging, no phone number or email required, and fully open source clients and servers https://alternativeto.net/software/session/about/ #session
Spearphishing Campaign Abuses npm Registry to Target U.S. and Allied Manufacturing and Healthcare Organizations
Медицинская лаборатория Гемотест (Gemotest) - 6,341,495 breached accounts.
WebRAT malware spread via fake vulnerability exploits on GitHub.
Microsoft rushes an out-of-band update for Message Queuing bug.
Ransomware Hits Romanian Water Authority, 1000 Systems Knocked Offline
CVE-2025-7771: Exploiting a Signed Kernel Driver in a Red Team Operation.
Malicious extensions in Chrome Web store steal user credentials.
Nomani investment scams rose 62% in 2025, ESET says.

Campaigns now run on YouTube as well as Facebook, pushing fake returns with AI-made videos.
64,000+ scam URLs were blocked this year.
From a land under siege, we light a candle this Christmas. It is a small flame against a great darkness, a whisper of hope that refuses to be silenced. Our celebration is an act of steadfast faith. May your holidays be filled with true peace.

25/12/25
Fortinet confirms active exploitation of a FortiOS SSL VPN flaw that bypasses 2FA.

CVE-2020-12812 lets attackers log in by changing the case of a username when LDAP is misconfigured.

The bug can allow admin or VPN access without second-factor checks.
CISA added a Digiever NVR bug to its exploited list after confirmed attacks.

CVE-2023-52163 allows remote code execution through command injection once logged in.

Researchers link it to Mirai and ShadowV2 botnets. The device is end-of-life and unpatched.
A new MacSync malware variant hit macOS via a signed and notarized app, letting it bypass Apple Gatekeeper.

The fake messaging installer ran like a legitimate app until Apple revoked the certificate.
Google will finally allow you to change your @ gmail .com address.
CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution.