Cyber Dispatch™️
386 subscribers
22 photos
1 video
47 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Malicious extensions in Chrome Web store steal user credentials.
Nomani investment scams rose 62% in 2025, ESET says.

Campaigns now run on YouTube as well as Facebook, pushing fake returns with AI-made videos.
64,000+ scam URLs were blocked this year.
From a land under siege, we light a candle this Christmas. It is a small flame against a great darkness, a whisper of hope that refuses to be silenced. Our celebration is an act of steadfast faith. May your holidays be filled with true peace.

25/12/25
Fortinet confirms active exploitation of a FortiOS SSL VPN flaw that bypasses 2FA.

CVE-2020-12812 lets attackers log in by changing the case of a username when LDAP is misconfigured.

The bug can allow admin or VPN access without second-factor checks.
CISA added a Digiever NVR bug to its exploited list after confirmed attacks.

CVE-2023-52163 allows remote code execution through command injection once logged in.

Researchers link it to Mirai and ShadowV2 botnets. The device is end-of-life and unpatched.
A new MacSync malware variant hit macOS via a signed and notarized app, letting it bypass Apple Gatekeeper.

The fake messaging installer ran like a legitimate app until Apple revoked the certificate.
Google will finally allow you to change your @ gmail .com address.
CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution.
Fake MAS Windows activation domain used to spread PowerShell malware.
Ten former Samsung employees arrested for industrial espionage charges for giving China chipmaker 10nm tech — executives and researchers allegedly leaked DRAM technology to China-based CXMT, resulting in trillions of losses in Korean Won.
Eurostar Accused Researchers of Blackmail for Reporting AI Chatbot Flaws.
US shuts down phisherfolk’s $14.6M password-hoarding platform.
MongoDB warns admins to patch severe RCE flaw immediately.
Evasive Panda APT poisons DNS requests to deliver MgBot.
New MacSync macOS Stealer Uses Signed App to Bypass Apple Gatekeeper.
''NHS Warns of PoC Exploit for 7-Zip Symbolic Link–Based RCE Vulnerability''.
Spotify cracks down on unlawful scraping of 86 million songs.
Utair - 401,400 breached accounts.
Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection.
Trust Wallet confirms extension hack led to $7 million crypto theft.
Mark Zuckerberg and Meta are lobbying the Canadian government to implement mandatory digital IDs, pushing for regulations that would require age verification at the app store level.