Cyber Dispatch™️
380 subscribers
21 photos
1 video
50 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Microsoft built a scanner to detect backdoors in open-weight LLMs 🧠 using 3 behavioral signals.

It flags trigger attention spikes, memorized poisoning data leaks, and fuzzy trigger activation—no retraining required. Built to scan open models at scale.
China-linked Amaranth-Dragon targeted Southeast Asian government and law enforcement networks in 2025, with links to the APT41 ecosystem.

Campaigns leveraged political lures and the WinRAR CVE-2025-8088 RCE flaw, using cloud delivery and geo-fenced infrastructure for stealth.
🕸️ Exposed C2 server showed a complete BYOB botnet in the open 🧠

Droppers, loaders, and RATs for Windows, Linux, and macOS were publicly accessible, revealing a multi-stage chain for evasion, persistence, and control. Crypto miners were also hosted.
eScan antivirus delivered a malicious update after its update system was compromised.

During a two-hour window, attackers swapped a trusted file to stop updates and 🛠️ cleanup. The malware hid by faking update status and downloading more payloads.
Hackers compromise NGINX servers to redirect user traffic.
A high-severity RCE flaw in OpenClaw lets attackers take over the local agent with a single click.

A crafted link can steal a gateway token via unvalidated WebSocket origins, enabling full command execution even on localhost-only setups through the user’s browser.
Researchers detect active exploitation of a critical React Native CLI flaw.

CVE-2025-11953 allows unauthenticated OS command execution on exposed Metro dev servers, with attacks deploying PowerShell and a Rust payload.
Experts at CTM360 report brand impersonation has become a scaled fraud operation.

Its findings show 30,000+ fake fashion stores across 80+ countries, using ads and real payment flows before disappearing.
China-linked Lotus Blossom compromised Notepad++ hosting infrastructure to hijack update traffic and deliver the Chrysalis backdoor, Rapid7 reports.
The average cost to mine a single Bitcoin is now over $90,000. The price of Bitcoin has collapsed to $67,000. Everyone mining Bitcoin at the moment is losing a fortune.
👍3
خطأ بشري في بورصة كورية: موظف Bithumb حول المستخدمين إلى مليونيرات في لحظة

تسبب موظف مبتدئ في بورصة العملات الرقمية الكورية Bithumb عن طريق الخطأ في حالة من الفوضى غير المألوفة، بعد أن نقل 2000 بيتكوين لمئات المستخدمين بدلاً من مكافأة ضئيلة بقيمة 2000 وون كوري (حوالي 1.5 دولار). وفقًا لتقرير في The Korea Times، حدث الخطأ بسبب إدخال وحدة الدفع كـ BTC بدلاً من KRW. ونتيجة لذلك، أصبح العديد من المستخدمين مليونيرات في لحظة وسارعوا إلى بيع البيتكوين الذي حصلوا عليه، مما تسبب في موجة مبيعات مفاجئة وذعر داخل البورصة.
Spain's Deputy Prime Minister Yolanda Díaz:

"I have left X. That network is a place of hate.

We are not vassals of Elon Musk or Trump."
Researchers find 341 malicious ClawHub skills targeting OpenClaw users via fake install steps.

The skills deploy Atomic Stealer on macOS and keylogging malware on Windows, abusing OpenClaw’s open marketplace model.
A supply chain attack spread malware via trusted VS Code extensions on Open VSX.

Attackers hijacked a real developer account and pushed GlassWorm through four existing tools.

22,000+ installs happened before removal.
Russia-linked APT28 exploited a newly disclosed Microsoft Office flaw within days of disclosure.

CVE-2026-21509 was used via malicious RTF files, with geo-fenced delivery targeting Ukraine, Slovakia, and Romania.
Mozilla will add 1-click Firefox setting to fully disable generative AI features.

With Firefox 148, users can block all current and future AI features or manage them individually, keeping AI strictly opt-in as browsers add more automation.
SATOSHI NAKAMOTO WALLET JUST BECAME ACTIVE AGAIN!

SOMEONE TRANSFERRED IN 2,565 $BTC AFTER 15 YEARS OF DORMANCY.

SO SATOSHI IS ALIVE AND BUYING BITCOIN?
Almost 1.4M users reportedly affected in Betterment breach.
Spain's Ministry of Science shuts down systems after breach claims.
Russian group APT28 (aka Fancy Bear or UAC-0001) has launched a sophisticated espionage campaign targeting European military and government entities.