Cyber Dispatch™️
388 subscribers
22 photos
1 video
47 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Anonymous for Justice hacked Israeli databases, laboratories, and weapons schematics, stating it is “exposing technology used in the killing of children and women.”

The group also published large files containing documents and photos belong to Israeli officers and scientists.
Chinese hackers linked to Salt Typhoon group infiltrate US congressional staff emails.

A Chinese hacker group known as Salt Typhoon has reportedly breached email systems used by staffers for several powerful US House of Representatives committees.
Hacker group Handala claims Mossad will soon 'encounter a shock they never saw coming':

"Tonight at 6:30 PM (Occupied Territories time), Mossad will encounter a shock they never saw coming."
Cyber Dispatch™️
Hacker group Handala claims Mossad will soon 'encounter a shock they never saw coming': "Tonight at 6:30 PM (Occupied Territories time), Mossad will encounter a shock they never saw coming."
"While their officers were busy orchestrating unrest in other countries, they failed to notice that they were being watched right in their own backyard. Sometimes, when you’re so focused on destabilizing others, you become blind to the shadows following you at home.

The tables are turning, let’s see who is really in control."
Microsoft says attackers are abusing misconfigured MX routing and weak spoof protections to send phishing emails that appear internal.

Some emails use the same address in both “From” and “To,” enabling credential theft and BEC.
Cisco released patches for CVE-2026-20029 in Identity Services Engine and ISE-PIC.

The XML parsing flaw allows an authenticated admin to upload a malicious file and read restricted OS files.

A public PoC exists. Patch Now.
Active exploitation is hitting old D-Link DSL router.

CVE-2026-0625 (CVSS 9.3) allows unauthenticated remote code execution via the dnscfg.cgi endpoint.

The same DNSChanger-style abuse seen in past hijacking campaigns is resurfacing, and many affected models are end of life and no longer maintained.
Three npm pkgs posing as bitcoinjs tools found spreading NodeCordRAT.

Postinstall scripts chained a 2nd pkg to drop the payload, steal Chrome creds, API tokens, and crypto wallet seed phrases, and run commands via Discord C2 on Win/Linux/macOS.
European hotels are facing a phishing campaign abusing Booking-com cancellation emails.

Victims hit a fake site, see a fake blue screen, and are told to run a PowerShell “fix.” That installs DCRat via MSBuild.exe, sets Defender exclusions, and persists on the system.
Warning: Two Chrome extensions with 900,000+ installs were found stealing ChatGPT and DeepSeek conversations, plus all open tab URLs.

Researchers call this prompt poaching.
Another CVSS 10.0 n8n vulnerability disclosed.

Researchers found another critical flaw (CVE-2026-21858) in n8n that lets remote attackers take full control with no authentication required.

The bug abuses Content-Type handling in form webhooks to read local files, steal secrets, forge admin sessions, and achieve RCE.
Israel Warns Palestinians: Stop Posting Zionist War Crimes Footage

"We are monitoring your online activity. Publishing inciting content online is considered a terrorist crime in every sense and may lead to arrest or imprisonment. Consider this your warning."
VMware ESXi zero-days likely exploited a year before disclosure.
377,000 Impacted by Data Breach at Texas Gas Station Firm.
‘ZombieAgent’ Attack Let Researchers Take Over ChatGPT.
An investigation by Channel 12 found that about half of politically active Israeli social media accounts are bots, with many amplifying posts by PM Benjamin Netanyahu and other members of his coalition.

These bot networks rapidly like and repost pro-Israel content moments after posting to hijack platform algorithms and give the impression of a bigger reach.
Black Cat is running an SEO poisoning campaign that ranks fake software sites in search results.

The group impersonates tools like Notepad++, tricking users into installing trojanized installers that drop a backdoor stealing browser data, keystrokes, clipboard contents, and enabling remote access.
Researchers disclosed multiple critical flaws in Coolify that let authenticated users run commands as root, enabling full server compromise.

The issues span 11 CVEs rated up to 10.0 and impact 52,890 internet-exposed hosts.
Ransomware has moved past simple extortion.

Stolen data is now auctioned when ransoms fail, turning breaches into repeat revenue. Data auctions expand profits, attract more actors, and scale attacks faster.
Warning - Yet another n8n vulnerability.

n8n disclosed a CVSS 10.0 RCE flaw allowing authenticated users to execute untrusted code and fully compromise an instance.

CVE-2026-21877 affects cloud and self-hosted deployments running versions ≥0.123.0 and <1.121.3.
Forwarded from 𝐺𝑟𝑎𝑦 𝐻𝑎𝑡𝑠
Mehrdad Rahimi's Secure Phone Contact List

Mehrdad Rahimi, the leading officer of the Mossad actors inside IRAN, has used intelligence techniques, has coded all his agents and assigned a separate name for each of them, now you can see this list, more than 600 Iranian Leaders who are responsible for killing projects in IRAN, are now available for anyone to see. All the elements of the anarchists know, for months, from the origin, they've been in our intelligence trap.

https://filebin.net/zpscsip54ub013rr

#Handala