Cyber Dispatch™️
Israel and Germany sign security pact focused on 'counterterrorism' and cyber 'defense'.
Israel and Germany signed a security agreement Sunday to deepen cooperation on counterterrorism, cyber 'defense', and advanced technologies, citing threats from Iran and its allies. Israeli Benjamin Netanyahu said the pact strengthens joint efforts against groups such as Hezbollah, Hamas, and the AnsarAllah, which he said threaten both Israel and regional stability. The declaration was signed by Netanyahu and German Interior Minister Alexander Dobrindt.
MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors.
UK government exempting itself from flagship cyber law inspires little confidence.
Astaroth banking malware is now using WhatsApp as its main delivery channel in Brazil.
Researchers report a new Python-based module that steals a victim’s contact list and auto-sends malicious ZIP files, spreading the infection chat to chat.
Researchers report a new Python-based module that steals a victim’s contact list and auto-sends malicious ZIP files, spreading the infection chat to chat.
China-linked UAT-7290 targets telecoms in South Asia, now expanding into Southeastern Europe.
Cisco Talos links the group to deep recon, edge device exploits, SSH brute force, 🐧 Linux malware, and shared ORB relay infrastructure.
Cisco Talos links the group to deep recon, edge device exploits, SSH brute force, 🐧 Linux malware, and shared ORB relay infrastructure.
Europol Arrests 34 Black Axe Members in Spain Over €5.9M Fraud and Organized Crime.
Instagram’s “17 Million User Data Leak” Was Just Scraped Records from 2022.
China instructs domestic companies to stop using US and Israeli cybersecurity software citing national security concerns.
Cyber Dispatch™️
China instructs domestic companies to stop using US and Israeli cybersecurity software citing national security concerns.
Chinese authorities have instructed domestic companies to stop using cybersecurity software from around a dozen US and Israeli firms, citing national security risks, according to sources speaking with Reuters. Among the affected companies are VMware (owned by Broadcom), Palo Alto Networks, Fortinet from the US, and Israel’s Check Point Software Technologies. Officials are concerned the software could collect and transmit sensitive information abroad.
A stealthy flaw in Telegram’s mobile clients that lets attackers unmask users’ real IP addresses with a single click, even those hiding behind proxies.
Dubbed a “one-click IP leak,” the vulnerability turns seemingly innocuous username links into potent tracking weapons. The issue hinges on Telegram’s automatic proxy validation mechanism.
When users encounter a disguised proxy link, often embedded behind a username (e.g., t[.]me/proxy?server=attacker-controlled), the app pings the proxy server before adding it.
Dubbed a “one-click IP leak,” the vulnerability turns seemingly innocuous username links into potent tracking weapons. The issue hinges on Telegram’s automatic proxy validation mechanism.
When users encounter a disguised proxy link, often embedded behind a username (e.g., t[.]me/proxy?server=attacker-controlled), the app pings the proxy server before adding it.
Chinese crime groups are running pig-butchering scams like a startup.
Researchers found $2,500 turnkey kits with fake trading sites, apps, hosting, and laundering—built to scale fast, no skills needed.
Researchers found $2,500 turnkey kits with fake trading sites, apps, hosting, and laundering—built to scale fast, no skills needed.
A web skimming campaign active since January 2022 is still stealing checkout data from compromised e-commerce sites.
Researchers found Magecart-style JavaScript that hides from admins, swaps real Stripe forms with fakes, steals card and personal data, then erases itself.
Researchers found Magecart-style JavaScript that hides from admins, swaps real Stripe forms with fakes, steals card and personal data, then erases itself.
ServiceNow patched a critical AI Platform flaw enabling unauthenticated user impersonation and actions as the victim.
CVE-2025-12420 (CVSS 9.3) affects Now Assist and Virtual Agent. Fixed Oct 30. No known exploitation.
CVE-2025-12420 (CVSS 9.3) affects Now Assist and Virtual Agent. Fixed Oct 30. No known exploitation.
Malicious Chrome extension targeted MEXC users by abusing an already logged-in browser session.
It auto-created new API keys, secretly enabled withdrawals, hid that permission in the UI, and sent the keys to a Telegram bot.
Uninstalling the extension didn’t revoke 🔑 access.
It auto-created new API keys, secretly enabled withdrawals, hid that permission in the UI, and sent the keys to a Telegram bot.
Uninstalling the extension didn’t revoke 🔑 access.