Cyber Dispatch™️
389 subscribers
22 photos
1 video
47 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
AdonisJS users are being advised to patch a critical flaw in adonisjs/bodyparser.

CVE-2026-21440 (CVSS 9.2) allows arbitrary file writes via path traversal when upload filenames aren’t explicitly sanitized.
Popular workflow automation platform n8n disclosed a critical flaw that lets authenticated users with workflow edit rights execute OS commands on the host.

Tracked as CVE-2025-68668, the issue carries a CVSS score of 9.9.
Chinese-speaking attackers hijacked a SonicWall VPN to escape VMware ESXi guest VMs.

Huntress stopped it before ransomware, but the chain abused 3 VMware zero-days now on CISA’s KEV list.
CISA closed 10 Emergency Directives issued between 2019–2024.

The required security actions for risks such as SolarWinds, Microsoft Exchange, and VMware were completed or are now enforced under Binding Operational Directive 22-01.
Handala hackers post Mossad 'secure phone' footage syncing Iran rioters with USA cell numbers.
Iranians have succeeded in disrupting Musk’s Starlink internet technology.
Hacker leaks 200,000 user + employee records from Israeli hosting provider Infocenters Ltd

Target: Infocenters Ltd (Hosting, Cloud Services, Data Centers, IT Solutions)

Leaked data includes:

1. Individual Demographic Data

Full names (Hebrew + English)
Previous family names
CodeAlias names used
Place of birth (Israel/Lithuania)
Year of birth (1928–1943)
Current age (2024-based)

2. Contact & Identification Data

Email addresses (http://gov.il, http://ac.il, http://net.il, gmail, etc.)
Physical addresses
Phone numbers
City & postal codes

3. Historical Data

WWII-era records
Europol says Spanish police arrested 34 suspects linked to Black Axe, a Nigeria-origin crime syndicate.

The 🕵️‍♂️ group is tied to cyber fraud, trafficking, and violent crime worldwide. Investigators estimate €5.93M in fraud losses, with cash and bank funds seized in Spain.
Trend Micro patched a critical flaw in on-prem Apex Central for Windows that can lead to SYSTEM-level code execution.

CVE-2025-69258 (CVSS 9.8) allows a remote, unauthenticated attacker with endpoint access to load a malicious DLL via MsgReceiver.exe.

On-prem builds below 7190 are affected.
Russian state-linked APT28 targeted Turkish energy and nuclear staff, a European think tank, and organizations in North Macedonia and Uzbekistan.

Fake Microsoft, Google, and VPN login pages harvested credentials, then redirected victims to real sites to stay hidden.
Israel and Germany sign security pact focused on 'counterterrorism' and cyber 'defense'.
Cyber Dispatch™️
Israel and Germany sign security pact focused on 'counterterrorism' and cyber 'defense'.
Israel and Germany signed a security agreement Sunday to deepen cooperation on counterterrorism, cyber 'defense', and advanced technologies, citing threats from Iran and its allies. Israeli Benjamin Netanyahu said the pact strengthens joint efforts against groups such as Hezbollah, Hamas, and the AnsarAllah, which he said threaten both Israel and regional stability. The declaration was signed by Netanyahu and German Interior Minister Alexander Dobrindt.
Malaysia and Indonesia block X over failure to curb deepfake smut.
MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors.
UK government exempting itself from flagship cyber law inspires little confidence.
Texas court blocks Samsung from tracking TV viewing, then vacates order.
Ireland recalls almost 13,000 passports over missing 'IRL' code.
Illinois man charged with hacking Snapchat accounts to steal nude photos.
Astaroth banking malware is now using WhatsApp as its main delivery channel in Brazil.

Researchers report a new Python-based module that steals a victim’s contact list and auto-sends malicious ZIP files, spreading the infection chat to chat.
China-linked UAT-7290 targets telecoms in South Asia, now expanding into Southeastern Europe.

Cisco Talos links the group to deep recon, edge device exploits, SSH brute force, 🐧 Linux malware, and shared ORB relay infrastructure.
Europol Arrests 34 Black Axe Members in Spain Over €5.9M Fraud and Organized Crime.