Cyber Dispatch™️
380 subscribers
21 photos
1 video
50 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Cyber Dispatch™️
Photo
This is the original image.
Data leak exposes over 200M Telegram user records.
Anthropic’s Claude Opus 4.6 AI found 500+ previously unknown high-severity flaws in open-source code.

Impacted: Ghostscript, OpenSC, CGIF. Bugs ranged from buffer overflows to memory corruption — all validated and patched.
APT Infy paused C2 ops during Iran’s Jan internet blackout — then rebuilt infrastructure as access returned.

Timing ties activity to state network controls. Latest malware uses Telegram + HTTP for dual-channel C2.
Critical RCE flaw in n8n (CVE-2026-25049, CVSS 9.4) lets authenticated users execute system commands via crafted workflow expressions.

Public webhooks exposed → remote trigger, credential theft, server takeover.
Amaranth-Dragon targeted Southeast Asian government and law enforcement networks in 2025, with links to the APT41 ecosystem.

Campaigns leveraged political lures and the WinRAR CVE-2025-8088 RCE flaw, using cloud delivery and geo-fenced infrastructure for stealth.
Microsoft warns infostealers are expanding from Windows to macOS.

Since late 2025, malvertising (Google Ads) and ClickFix lures have delivered fake DMG installers. Python-based stealers abuse native macOS tools + AppleScript to extract creds, cookies, and iCloud Keychain data.
Fake recruiter coding tests pushed poisoned npm & PyPI dependencies to developers.

Hidden packages deployed RAT access, while separate implants stole browser & crypto wallet data. One library exceeded 10,000 downloads before weaponization.
Google tracked multiple state groups using Gemini for vuln research, exploit debugging, and persona building across cyber operations.

One malware strain even generated second-stage code via the API, executed filelessly in memory.
Threat actors are actively exploiting CVE-2026-1731 (9.9) in BeyondTrust Remote Support & PRA.

Attackers extract portal data, then open WebSocket channels to trigger unauthenticated RCE.
417 exploitation sessions from 8 unique source IP addresses between February 1 and 9, 2026. An estimated 346 exploitation sessions have originated from 193.24.123[.]42, accounting for 83% of all attempts.

The malicious activity is designed to exploit CVE-2026-1281 (CVSS scores: 9.8), one of the two critical security vulnerabilities in EPMM, along with CVE-2026-1340 that could be exploited by an attacker to achieve unauthenticated remote code execution. Late last month, Ivanti acknowledged it's aware of a "very limited number of customers" who were impacted following the zero-day exploitation of the issues.
Interference with the Global Positioning System (GPS) in and around Haifa.
US used Claude AI during Maduro kidnapping operation.
Cyber Dispatch™️
US used Claude AI during Maduro kidnapping operation.
The US military actively used Anthropic’s Claude AI model during January's operation to kidnap Venezuelan President Nicolás Maduro.
Cyber Dispatch™️
US used Claude AI during Maduro kidnapping operation.
Claude was employed during the operation itself, not only in the planning stages, although the exact nature of its role has not been fully disclosed.
Newly launched social media app “UpScrolled”, has been removed from the Google Play Store.
Social media app “UpScrolled” is back online after previously being removed from the Google Play Store, with access now restored for users.
Security firms uncovered coordinated abuse of Chrome extensions across business, social, and AI tools.

From Meta ad accounts to Gmail inboxes, attackers used add-ons to scrape data, inject payloads, and persist inside sessions.
One bulletproof-hosted IP drove 346 of 417 Ivanti EPMM exploit attempts.

Activity targeted CVSS 9.8 RCE flaws, rotating 300+ user agents while scanning other enterprise platforms in parallel. Signals automated initial-access reconnaissance.
Apple shipped emergency updates after confirming exploitation of a zero-day in dyld.

The bug (CVE-2026-20700) could allow attackers to execute arbitrary code on vulnerable Apple devices.
North Korea-linked UNC1069 used deepfake Zoom calls to hack crypto firms.

Posing via Telegram, attackers lured victims into fake meetings, triggering ClickFix commands that deployed multi-stage malware on macOS & Windows to steal wallets and credentials.