Cyber Dispatch™️
390 subscribers
32 photos
2 videos
48 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Researchers disclosed VoidLink, a modular Linux malware built for long-term, stealthy cloud access.

It detects AWS, Azure, GCP, Docker, and Kubernetes, adapts its behavior, steals credentials, and enables lateral movement using rootkit-style techniques 🧩
Check Point says CVE-2025-37164 is being mass-exploited to spread the RondoDox botnet, with 40,000+ attacks on Jan 7.

The activity targeted government, finance, and industrial sectors, prompting same-day KEV inclusion.
A China-linked group targeted U.S. government and policy entities using Venezuela-themed phishing lures.

The campaign delivered the LOTUSLITE backdoor via DLL side-loading. No confirmed compromises.
A China-linked threat actor has targeted North American critical infrastructure.

Tracked as UAT-8837, the group seeks initial access to high-value networks, then maps Active Directory and steals credentials using mostly open-source tools.

Talos says a Sitecore zero-day was recently exploited to gain entry.
A WordPress plugin with 40,000+ active installs is being actively exploited.

CVE-2026-23550 (CVSS 10.0) in Modular DS allows unauthenticated attackers to gain admin access by bypassing authentication through a flawed routing mechanism.
Cisco fixed a CVSS 10.0 RCE in AsyncOS after it was exploited as a zero-day by the China-nexus APT UAT-9686.

The flaw enables root-level command execution through the Spam Quarantine feature when it is exposed to the internet.
Researchers disclosed a one-click Copilot attack that enables silent data exfiltration.

A legitimate Copilot URL injects hidden instructions, bypasses safeguards, and can keep exfiltrating data even after the chat is closed.
GootLoader now uses 500–1,000 ZIP files glued together!

The broken ZIP won’t open in WinRAR or 7-Zip, but Windows Explorer still opens it and runs the JavaScript malware. Each download is different, so file hashes don’t match.
Researchers uncovered 5 malicious Chrome extensions masquerading as HR/ERP tools like Workday and NetSuite.

They exfiltrate auth cookies and suppress access to security and admin pages via DOM manipulation.
Hacker Nicholas Moore, 24, pleaded guilty to infiltrating U.S. government systems, including the Supreme Court's filing portal. Using stolen login credentials, he accessed sensitive personal data from victims at the Supreme Court, AmeriCorps, and the Department of Veterans Affairs. Notably, Moore brazenly posted the stolen information—including names, addresses, and even prescribed medications—to his Instagram account, @ihackthegovernment. He now faces up to a year in prison and a $100,000 fine for the breaches.
Palo Alto Networks patched a high-severity DoS flaw in GlobalProtect.

CVE-2026-0227 (CVSS 7.7) lets unauthenticated attackers repeatedly crash firewalls into maintenance mode.
Researchers null-routed traffic to 550+ AISURU/Kimwolf C2 nodes since early Oct 2025.

Kimwolf has compromised 2M+ Android devices—mostly unsanctioned TV boxes via exposed ADB—and resold them as residential proxies.
Microsoft’s first Patch Tuesday of 2026 fixes 114 Windows flaws, including one exploited in the wild.

CVE-2026-20805 is a local info-leak in Desktop Window Manager that can expose memory addresses and weaken ASLR.
A fake Chrome ad blocker crashes the browser on purpose, then tricks users into running attacker commands.

Huntress calls it CrashFix, an evolved ClickFix tactic linked to the KongTuke traffic distribution system for reuse in follow-on attacks.
Malware Analysis: LummaC2/Vidar Infostealer Disguised as XAPK Viewer on Uptodown.
Credential-stealing Chrome extensions target enterprise HR platforms.
German cops add Black Basta boss to EU most-wanted list.
Toll of Monroe University hack exceeds 320K.
Malicious GhostPoster browser extensions found with 840,000 installs.
Mandiant releases rainbow table that cracks weak admin password in 12 hours.
750,000 Impacted by Data Breach at Canadian Investment Watchdog.