Cyber Dispatch™️
380 subscribers
21 photos
1 video
50 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
China-linked UAT-8099 targets IIS servers in Asia using BadIIS SEO malware.

The group broke into vulnerable IIS servers, mainly in Thailand and Vietnam, using web shells and PowerShell. The aim remains SEO fraud, now tuned by region.
SmarterMail fixed a critical unauthenticated RCE in its email server software.

The flaw, CVE-2026-24423 (CVSS 9.3), lets attackers execute OS commands via a crafted remote server. It affects builds before 9511.
The tech giant Microsoft said it receives around 20 requests for BitLocker keys a year and will provide them to governments in response to valid court orders. But companies like Apple and Meta set up their systems so such a privacy violation isn’t possible.
Apple is testing a new iOS setting that reduces how precisely cellular networks can 📍 locate your device.

Limit Precise Location restricts location data to a broad area instead of an exact address.
A campaign targets NGOs and individuals documenting human rights abuses.

HarfangLab tracks the activity as RedKitten, using Excel files themed around deceased protesters to deliver malware.

The tooling relies on GitHub, Google Drive, and Telegram for configuration and control, with indicators suggesting parts of the code may be LLM-assisted.
DOJ releases details alleged talented hacker working for Jeffrey Epstein.
Epstein's Shadow Hacker

Jeffrey Epstein's web of influence extended into the digital underworld, according to a bombshell Justice Department document released on January 31, 2026. An FBI informant's 2017 statement claims Epstein employed a "personal hacker"—a redacted Italian cybersecurity expert from Calabria with elite skills in zero-day exploits. This revelation, part of the ongoing Epstein Files disclosures, paints a chilling picture of how the late financier allegedly weaponized cutting-edge hacking talents.

The Hacker's Profile Emerges

The document describes the individual as a master of vulnerabilities in iOS, BlackBerry, and Firefox, crafting offensive cyber tools sold to governments including the US and UK. He reportedly built Saudi Arabia's cyber surveillance program and even sold a zero-day exploit to Hezbollah for a trunk of cash, which he laundered through a California theater company. Earning six-figure sums, he shunned deals with "incompetent" Italy and Asian buyers, preferring high-stakes clients backed by billionaires like Epstein.

Online sleuths can likely pinpoint him: his firm was acquired by CrowdStrike in fall 2017, after which he rose to Vice President. Epstein provided seed money alongside two other tycoons, one tied to a Japanese firm. The informant notes his ties to "old school" European hackers, including phonetic handles like "PH," blending old-world cybercrime with modern zero-days.

Implications for Cybersecurity Elite

This isn't just tabloid fodder—it's a stark reminder of blurred lines between private hacking prowess and criminal patronage. Epstein, known for compromising elites, may have leveraged this talent for surveillance or blackmail ops, mirroring his real-world tactics.

CrowdStrike's involvement demands scrutiny. Did due diligence miss these shadows during acquisition? Post-2017, as VP, could he have influenced endpoint security tools used globally?

Broader Cybercrime Echoes

Epstein's orbit intersects with recent headlines: Empire Market's co-founder pleading guilty to decades in prison; ShinyHunters breaching Crunchbase; CISA flagging exploited flaws in Ivanti, Fortinet, and Microsoft Office. Yet none rival the intrigue of a zero-day dealer bankrolled by a sex-trafficker.

For the hacker, fallout looms. Italian authorities may reopen probes, while US agencies question Epstein-era dealings. Hezbollah cash runs evoke state-sponsored cyber bazaars, where exploits fuel asymmetric warfare.

This story underscores cybersecurity's dark side: geniuses moonlighting for the highest bidder. Victims of Epstein's network deserve full unredacted files—allegations alone erode trust.

As Pierluigi Paganini warns on SecurityAffairs, one ponders why Epstein chose such a figure. The answer likely lies in power: digital dirt as leverage.


@TheGhostsITM
New Windows Malware Uses Pulsar RAT for Live Chats While Stealing Data.
US Seizes $400 Million Linked to Helix Dark Web Crypto Mixer.
انسحاب كامل لجيش الاحتلال بعد تدمير شارع الشالية خلف سوبر ماركت المجد شارع حيفا في مدينة جنين
Researcher reveals evidence of Instagram private profiles leaking photos.
Operation Switch Off dismantles major pirate TV streaming services.
Crypto wallets received a record $158 billion in illicit funds last year.
Mandiant details how ShinyHunters abuse SSO to steal cloud data.
GlassWorm Loader Hits Open VSX via Developer Account Compromise.
Cloud storage payment scam floods inboxes with fake renewals.
الأمن الفرنسي يقتحم مقر إكس في باريس للاشتباه بتورط إيلون ماسك بالبيدوفيليا
شركة الإتصالات الفلسطينية:

انقطاع خدمة الإنترنت في شمال قطاع غزة بسبب أعمال صيانة فنية، على أن تعود الخدمة خلال ساعة واحدة.
Match, Hinge, OkCupid, and Panera Bread breached by ransomware group.
تم تسجيل فشل عالمي في عمل ChatGPT في جميع أنحاء العالم.
CVE-2025-7016

Improper Access Control vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Authentication Abuse.This issue affects QR Menu: before s1.05.12.