Cyber Dispatch™️
390 subscribers
24 photos
2 videos
48 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
A stealthy flaw in Telegram’s mobile clients that lets attackers unmask users’ real IP addresses with a single click, even those hiding behind proxies.

Dubbed a “one-click IP leak,” the vulnerability turns seemingly innocuous username links into potent tracking weapons. The issue hinges on Telegram’s automatic proxy validation mechanism.

When users encounter a disguised proxy link, often embedded behind a username (e.g., t[.]me/proxy?server=attacker-controlled), the app pings the proxy server before adding it.
Chinese crime groups are running pig-butchering scams like a startup.

Researchers found $2,500 turnkey kits with fake trading sites, apps, hosting, and laundering—built to scale fast, no skills needed.
A web skimming campaign active since January 2022 is still stealing checkout data from compromised e-commerce sites.

Researchers found Magecart-style JavaScript that hides from admins, swaps real Stripe forms with fakes, steals card and personal data, then erases itself.
ServiceNow patched a critical AI Platform flaw enabling unauthenticated user impersonation and actions as the victim.

CVE-2025-12420 (CVSS 9.3) affects Now Assist and Virtual Agent. Fixed Oct 30. No known exploitation.
Malicious Chrome extension targeted MEXC users by abusing an already logged-in browser session.

It auto-created new API keys, secretly enabled withdrawals, hid that permission in the UI, and sent the keys to a Telegram bot.

Uninstalling the extension didn’t revoke 🔑 access.
Microsoft’s first Patch Tuesday of 2026 fixes 114 Windows flaws, including one exploited in the wild.

CVE-2026-20805 is a local info-leak in Desktop Window Manager that can expose memory addresses and weaken ASLR.
CISA confirms active exploitation of a Gogs flaw now added to the KEV list.

CVE-2025-8110 (CVSS 8.7) abuses symlink handling to write outside repositories, enabling code execution. Around 700 exposed instances are already compromised.
Researchers uncovered SHADOW#REACTOR, a multi-stage campaign delivering Remcos RAT.

It starts with an obfuscated VBS launcher, moves through PowerShell, and rebuilds fragmented text payloads in memory. The defining trait is text-only stagers and LOLBin abuse to reduce detection.
Node.js fixed a DoS bug where apps crash instead of throwing a catchable error.

🧩 CVE-2025-59466 impacts Next.js, React Server Components, and most APM tools via AsyncLocalStorage. When async_hooks is enabled, deep recursion can force a hard process exit, dropping services.
Attackers uploaded fake n8n community nodes to npm to steal OAuth tokens from live workflows.

The packages mimicked real integrations, ran with full n8n access, decrypted credentials during execution, and exfiltrated them.

Eight were removed, but activity appears ongoing.
Researchers disclosed VoidLink, a modular Linux malware built for long-term, stealthy cloud access.

It detects AWS, Azure, GCP, Docker, and Kubernetes, adapts its behavior, steals credentials, and enables lateral movement using rootkit-style techniques 🧩
Check Point says CVE-2025-37164 is being mass-exploited to spread the RondoDox botnet, with 40,000+ attacks on Jan 7.

The activity targeted government, finance, and industrial sectors, prompting same-day KEV inclusion.
A China-linked group targeted U.S. government and policy entities using Venezuela-themed phishing lures.

The campaign delivered the LOTUSLITE backdoor via DLL side-loading. No confirmed compromises.
A China-linked threat actor has targeted North American critical infrastructure.

Tracked as UAT-8837, the group seeks initial access to high-value networks, then maps Active Directory and steals credentials using mostly open-source tools.

Talos says a Sitecore zero-day was recently exploited to gain entry.
A WordPress plugin with 40,000+ active installs is being actively exploited.

CVE-2026-23550 (CVSS 10.0) in Modular DS allows unauthenticated attackers to gain admin access by bypassing authentication through a flawed routing mechanism.
Cisco fixed a CVSS 10.0 RCE in AsyncOS after it was exploited as a zero-day by the China-nexus APT UAT-9686.

The flaw enables root-level command execution through the Spam Quarantine feature when it is exposed to the internet.
Researchers disclosed a one-click Copilot attack that enables silent data exfiltration.

A legitimate Copilot URL injects hidden instructions, bypasses safeguards, and can keep exfiltrating data even after the chat is closed.
GootLoader now uses 500–1,000 ZIP files glued together!

The broken ZIP won’t open in WinRAR or 7-Zip, but Windows Explorer still opens it and runs the JavaScript malware. Each download is different, so file hashes don’t match.
Researchers uncovered 5 malicious Chrome extensions masquerading as HR/ERP tools like Workday and NetSuite.

They exfiltrate auth cookies and suppress access to security and admin pages via DOM manipulation.
Hacker Nicholas Moore, 24, pleaded guilty to infiltrating U.S. government systems, including the Supreme Court's filing portal. Using stolen login credentials, he accessed sensitive personal data from victims at the Supreme Court, AmeriCorps, and the Department of Veterans Affairs. Notably, Moore brazenly posted the stolen information—including names, addresses, and even prescribed medications—to his Instagram account, @ihackthegovernment. He now faces up to a year in prison and a $100,000 fine for the breaches.
Palo Alto Networks patched a high-severity DoS flaw in GlobalProtect.

CVE-2026-0227 (CVSS 7.7) lets unauthenticated attackers repeatedly crash firewalls into maintenance mode.