Cyber Dispatch™️
380 subscribers
21 photos
1 video
50 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
CVE-2026-1819

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Karel Electronics Industry and Trade Inc. ViPort allows Stored XSS.This issue affec...
CVE-2026-1861

Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2026-25510

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.28.5.0, an authenticated.
CVE-2026-1803

A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the component Dropbear SSH Service. This manipulation causes use of default credentials.
CVE-2026-24954

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.
CVE-2025-65875

An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2025-70841

Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuration data via direct request to /script/.env file.
CVE-2026-24665

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a stored Cross-Site Scripting (XSS) vulnerability allows authenticated.
SolarWinds Web Help Desk flaw added to CISA KEV

• CVE-2025-40551 (CVSS 9.8): unauthenticated RCE via deserialization
• Fixed in WHD v2026.1
• Federal agencies must patch by February 6
Hackers are delivering AsyncRAT via IPFS-hosted VHD files in DEAD#VAX.

Phishing emails mount fake PDF drives that run obfuscated scripts and in-memory shellcode inside trusted Windows processes—minimal disk trace.

Fileless
IPFS
Process injection
Microsoft built a scanner to detect backdoors in open-weight LLMs 🧠 using 3 behavioral signals.

It flags trigger attention spikes, memorized poisoning data leaks, and fuzzy trigger activation—no retraining required. Built to scan open models at scale.
China-linked Amaranth-Dragon targeted Southeast Asian government and law enforcement networks in 2025, with links to the APT41 ecosystem.

Campaigns leveraged political lures and the WinRAR CVE-2025-8088 RCE flaw, using cloud delivery and geo-fenced infrastructure for stealth.
🕸️ Exposed C2 server showed a complete BYOB botnet in the open 🧠

Droppers, loaders, and RATs for Windows, Linux, and macOS were publicly accessible, revealing a multi-stage chain for evasion, persistence, and control. Crypto miners were also hosted.
eScan antivirus delivered a malicious update after its update system was compromised.

During a two-hour window, attackers swapped a trusted file to stop updates and 🛠️ cleanup. The malware hid by faking update status and downloading more payloads.
Hackers compromise NGINX servers to redirect user traffic.
A high-severity RCE flaw in OpenClaw lets attackers take over the local agent with a single click.

A crafted link can steal a gateway token via unvalidated WebSocket origins, enabling full command execution even on localhost-only setups through the user’s browser.
Researchers detect active exploitation of a critical React Native CLI flaw.

CVE-2025-11953 allows unauthenticated OS command execution on exposed Metro dev servers, with attacks deploying PowerShell and a Rust payload.
Experts at CTM360 report brand impersonation has become a scaled fraud operation.

Its findings show 30,000+ fake fashion stores across 80+ countries, using ads and real payment flows before disappearing.
China-linked Lotus Blossom compromised Notepad++ hosting infrastructure to hijack update traffic and deliver the Chrysalis backdoor, Rapid7 reports.
The average cost to mine a single Bitcoin is now over $90,000. The price of Bitcoin has collapsed to $67,000. Everyone mining Bitcoin at the moment is losing a fortune.
👍3
خطأ بشري في بورصة كورية: موظف Bithumb حول المستخدمين إلى مليونيرات في لحظة

تسبب موظف مبتدئ في بورصة العملات الرقمية الكورية Bithumb عن طريق الخطأ في حالة من الفوضى غير المألوفة، بعد أن نقل 2000 بيتكوين لمئات المستخدمين بدلاً من مكافأة ضئيلة بقيمة 2000 وون كوري (حوالي 1.5 دولار). وفقًا لتقرير في The Korea Times، حدث الخطأ بسبب إدخال وحدة الدفع كـ BTC بدلاً من KRW. ونتيجة لذلك، أصبح العديد من المستخدمين مليونيرات في لحظة وسارعوا إلى بيع البيتكوين الذي حصلوا عليه، مما تسبب في موجة مبيعات مفاجئة وذعر داخل البورصة.