Cyber Dispatch™️
380 subscribers
21 photos
1 video
50 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Jordanian pleads guilty to selling access to 50 corporate networks
UK govt. warns about ongoing Russian hacktivist group attacks.
Fake ad blocker extension crashes the browser for ClickFix attacks.
MX Linux 25.1 brings back switchable init systems.
OpenAI's ChatGPT Atlas browser is testing actions feature.
Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading.
RansomHouse Claims Data Breach at Major Apple Contractor Luxshare.
CrowdStrike shareholders lose battle to recoup losses from 2024 outage.
Evelyn Stealer Malware Abuses VS Code Extensions to Steal Developer Credentials and Crypto.
VoidLink Signals the Start of a New Era in AI-Generated Malware.
Firefox joins Chrome and Edge as sleeper extensions spy on users.
Windows 11 shutdown bug forces Microsoft into out-of-band damage control.
Ingram Micro says ransomware attack affected 42,000 people.
Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over $12 Billion.
SmarterMail flaw is under active attack within 48 hours of patching.

The bug lets attackers bypass auth, reset the admin password, then abuse built-in admin features to run OS commands as SYSTEM.

Activity points to patch reverse-engineering.
After X opened up its algorithm, users discovered that those criticizing Israel were massively censored and had their reach reduced by 90%.

The entire algorithm is now based on whether or not the user criticizes Israel.
Fortinet confirms active exploitation of CVE-2025-59718 / 59719, allowing FortiGate FortiCloud SSO bypass — even on fully patched devices.

Attackers abuse crafted SAML logins to gain admin access, add persistent accounts, enable VPN, and steal configs. Disabling FortiCloud SSO is advised.
Attackers are abusing trusted IT tools, not deploying malware.

A new campaign steals email logins, then installs legitimate RMM software for silent, long-term access.
Because the tools are signed and allowed, many security controls don’t trigger.
Email is still the easiest way in.

In Google Workspace, BEC attacks often carry no links or malware, so native defenses miss them. One compromised inbox can expose years of sensitive email and files.
Fortinet FortiGate under automated SSO abuse.

Attackers exploit CVE-2025-59718/59719 to add admin users, enable VPN access, and export firewall configs within seconds, per Arctic Wolf.
RCE flaws found in widely used AI Python libraries.

Researchers report bugs in Apple FlexTok, NVIDIA NeMo, and Salesforce Uni2TS that trigger when malicious model metadata is loaded.

These tools power popular AI models. Patches are out, no active exploitation seen yet.