Cyber Dispatch™️
386 subscribers
22 photos
1 video
47 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Researchers linked three malicious browser extension campaigns to one Chinese threat actor.

Over 8.8 million users across Chrome, Edge, and Firefox were affected over seven years, with some extensions lying dormant for years before turning malicious.
Knownsec Data Breach: A Trove of Espionage Tradecraft with an Insider Narrative.
NYC mayoral inauguration bans Flipper Zero, Raspberry Pi devices.
Yesterday evening someone leaked PlaySation 5 ROM keys online. Emulation nerds are going schizo because this could mean we have PlayStation 5 emulation technology,
IBM Warns of Critical API Connect Bug Allowing Remote Authentication Bypass.
Disney will pay $10 million to settle children's data privacy lawsuit.
CVE-2025-14733: WatchGuard Firebox iked Out of Bounds Write Vulnerability Exploited in the Wild.
Everest Ransomware Leaks 1TB of Stolen ASUS Data.
RondoDox botnet exploits React2Shell flaw to breach Next.js servers.
Hackers drain $3.9M from Unleash Protocol after multisig hijack.
CVE-2025-43530: Exploiting a private API for VoiceOver [on macOS].
Trust Wallet Chrome Extension Hack Drains $8.5M via Shai-Hulud Supply Chain Attack.
Hacker Claims European Space Agency Breach, Selling 200GB of Data.
Researchers uncovered phishing sent through Google Cloud’s built-in email feature. Emails came from google[.]com, not spoofed domains, making them harder to spot.

Clicks passed through Google-hosted pages before stealing Microsoft login credentials.
A former Coinbase support agent was arrested in India after hackers bribed contractors to steal customer data.

The breach exposed 69,461 users and led to a $20M ransom demand. Coinbase cut ties with involved vendors and says more arrests are coming.
A botnet called RondoDox has been quietly expanding for nine months, now abusing React2Shell (CVSS 10.0) to compromise Next.js servers and IoT devices.

As of December 2025, the activity has been observed leveraging the recently disclosed React2Shell (CVE-2025-55182, CVSS score: 10.0) flaw as an initial access vector.
Hacker group Handala releases former Israeli minister Ayelet Shaked’s WhatsApp chats.
The hacker group Handala announced the release of former Israeli minister Ayelet Shaked’s WhatsApp conversations, with deep access to senior political circles. The group framed the leak as both transparency and a warning, asserting its influence reaches the highest levels of authority.
A German hacker known as "Martha Root" dressed as a pink Power Ranger and deleted a white supremacist dating website live onstage.
UPDATE | Handala hacker group announces bounty on 15 Israeli intelligence officers.
1