Cyber Dispatch™️
Open in Telegram
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch. #CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Show moreThe country is not specifiedThe category is not specified
390
Subscribers
No data24 hours
+47 days
+830 days
Posts Archive
Corporate America is hedging ahead of the 2026 midterms.
Companies that built close ties with Trump—especially big tech—fear Democratic-led investigations if the party wins the House.
The new Twitter is here. “Twitter. now” service launch begins today — and usernames are now available.
A startup in Virginia just launched a social network called Twitter and it has NOTHING to do with Elon Musk.
The blue bird is back, tweets and retweets are back, and it costs $20 to get through the door.
Repost from ᴛʜᴇ ɢʜᴏꜱᴛ ɪɴ ᴛʜᴇ ᴍᴀᴄʜɪɴᴇ
Two people linked to TeamPCP were reportedly arrested in Australia today. TeamPCP is believed to be behind a string of major supply-chain attacks that sent shockwaves through the cybersecurity community.
Repost from ᴛʜᴇ ɢʜᴏꜱᴛ ɪɴ ᴛʜᴇ ᴍᴀᴄʜɪɴᴇ
- Cross-platform alias persistence: Handles and identity fragments were reportedly retained across HackerOne, GitHub, Hugging Face, TikTok, Steam, and Telegram.
- Infrastructure exposure: A domain reportedly associated with malicious command-and-control activity was publicly linked from developer-facing profiles.
- Weak identity separation: A possible real name, initials, aliases, and related account data were sufficiently connected to enable further OSINT pivots.
- Historical timeline overlap: Steam VAC-ban dates and account interactions reportedly aligned across multiple identities.
- Visual-identity reuse: The same distinctive cat avatar reportedly appeared on Steam and Telegram accounts associated with the wider TeamPCP ecosystem.
- Public-record exposure: A business reportedly operated under the name OPSEC EXPRESS created an additional real-world attribution surface. Corporate records are routinely useful when they can be correlated with online identifiers, financial activity, communications, or infrastructure evidence.
Analytical Takeaway
This case demonstrates that operational security fails cumulatively. An individual does not need to expose a home address, leave a real IP address in a server log, or publish a direct confession to become attributable. Small artifacts—an old Steam ban, a contact comment, a reused profile image, a domain on a public developer profile, or a social-media video—can persist for years and later become critical evidence.
The central mistake was treating individual accounts as isolated identities. They were not isolated. The reported evidence indicates that each platform preserved a fragment of the same operational history. Once one fragment was linked to a real-world identity, the remaining artifacts could be examined as part of a single pattern.
For cyber-intelligence teams, the lesson is equally practical: prioritize pivots that establish independent corroboration. A username is a lead, not a conclusion. Confidence grows when a handle is supported by shared infrastructure, time-based correlations, platform relationships, visual markers, and verifiable public records.
#TGITM @TheGhostITM
Repost from ᴛʜᴇ ɢʜᴏꜱᴛ ɪɴ ᴛʜᴇ ᴍᴀᴄʜɪɴᴇ
Case Study: How Reused Digital Identity Exposed an Alleged TeamPCP Member
By Yara Tabet (The Ghost In The Machine)
Executive Assessment
The reported arrest of Ruben Thomson in Western Australia illustrates a common failure in hacking OPSEC: identity reuse across platforms with radically different levels of visibility. The reported attribution was not built around a zero-day, a covert implant, or a single leaked identifier. It emerged from publicly accessible traces that, when correlated, connected a long-standing online persona to an alleged TeamPCP member.
The core failure was poor compartmentalization. Handles, infrastructure references, historical account activity, profile imagery, and social-media content allegedly overlapped for years. Any one artifact would have been weak evidence. Together, they created an attribution chain that was difficult to dismiss.
Scope and Attribution Caveat
This assessment is based on publicly reported material and open-source observations. It does not independently establish guilt or validate all claims of group membership. The reference to Thomson’s reported arrest and alleged connection to TeamPCP should be read as an attribution assessment pending the outcome of judicial proceedings.
Initial Identity Pivot
The investigation reportedly began with the handle DeadCatx3, which was associated with a HackerOne profile connected to the name Ruben Thomson. The account was significant because it created an initial bridge between a real-world identity and an established online alias.
Researchers then identified what appeared to be an associated Hugging Face account using initials consistent with the same name. That profile reportedly referenced masscan[.]cloud. The domain had been identified publicly as command-and-control infrastructure associated with the Mini Shai-Hulud npm worm activity. The same domain was also reportedly present on the DeadCatx3 GitHub profile.
This overlap mattered because it was not merely a reused username. It connected a named identity, developer-platform profiles, and infrastructure allegedly tied to a malware campaign. The evidentiary value came from convergence: distinct services independently pointing toward the same operational ecosystem.
Social-Media and Steam Correlation
Once Ruben Thomson became a working lead, investigators and researchers reportedly pivoted through account-linked data and open-source records. This led to a TikTok account using the name yolosolo17.
The account reportedly contained a single video, published in March 2017, showing a Steam profile named YolocrownZ. The footage showed that the account had received a VAC ban 175 days earlier. This places the likely ban date at approximately September 13, 2016.
Further Steam research reportedly identified an account called Ellis that had also received a VAC ban on September 13, 2016. Public Steam-profile interactions and comments reportedly established a relationship between the Ellis and YolocrownZ identities.
This is a valuable example of timestamp-based correlation. A shared ban date does not identify a person on its own, but it becomes meaningful when aligned with connected accounts, relationships, alias reuse, and the wider attribution record.
The Avatar Link
The strongest and most memorable pivot was visual rather than technical. A distinctive cat avatar appeared on a Steam profile associated with the identity chain. The same image was reportedly reused by the PCPsh Telegram account linked publicly to TeamPCP.
Reverse-image searches reportedly produced few or no unrelated uses of the image. This gave the avatar limited but useful attribution value. Profile pictures are generally weak indicators because they can be copied, but their value rises when they appear consistently across accounts that also share timelines, contacts, aliases, and operational context.
The cat image did not prove identity. It corroborated an identity chain that was already supported by multiple independent sources.
OPSEC Failures Identified
Apple using Israeli designed 'C2 modem' chips for its upcoming iPhone 18 devices, with top advanced Taiwanese/US manufactured A20, Qualcomm, Image sensors (Sony Japan), and other Radios, charging, PMIC.
A malicious Amazon Kiro workspace can leak sensitive local data.
After opening the workspace, sending any message to the agent can trigger repository-controlled instructions that send local data to an external server. Amazon fixed the flaw in Kiro 0.8.140.
Proton is currently experiencing a major outage affecting Proton's services due to a cooling failure in their Frankfurt datacenter.
Nvidia has agreed to buy Hugging Face for $12.9B, The Information reports. Neither company has confirmed.
Two TeamPCP members, Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, have been arrested in Perth, Australia. The group is known for its npm supply chain attacks, including the Shai-Hulud worm.
OpenAI has published its full post-mortem on their AI breakout and compromise of Hugging Face. Carried out by its own models, with no human directing them.
Agents stuck on evaluation tasks turned an internal Artifactory server into a covert message board, escaped the sandbox via SSRF, then chained two Hugging Face zero-days into code execution on dozens of production servers.
OpenAI calls it a "warning shot" for loss of control.
ISRAEL FUNDED ‘FAKE THINK TANK’ to influence AI chatbots — Guardian
The ‘Hanover Institute’ published 124 reports and 560,000+ words in just nine days, presenting pro-Israel arguments as ‘research’
The campaign allegedly aims to get AI systems to cite Israel-friendly narratives.
US - 𝗞𝗶𝗻𝗴𝘀𝘁𝗼𝗻 𝗧𝗲𝗰𝗵𝗻𝗼𝗹𝗼𝗴𝘆
Everest hacking group claims to have breached Kingston Technology, allegedly exfiltrating 138.49 GB of data comprising 9,438 files related to internal marketing, product, retail, e-commerce and commercial operations across APAC markets.
Qatar - 𝗕𝗹𝗮𝗰𝗸 𝗖𝗮𝘁 𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝗶𝗻𝗴 & 𝗖𝗼𝗻𝘀𝘁𝗿𝘂𝗰𝘁𝗶𝗼𝗻
Qilin hacking group claims to have breached Black Cat Engineering & Construction.
The Uwais al-Qarani Hacker Group claims responsibility for a cyberattack on Israel's power grid, targeting critical infrastructure and sending a message of resistance.
#TGITM @TheGhostITM
نشر وثائق عن تعاون شركة Novamill مع الصناعات العسكرية التابعة للاحتلال الإسرائيلي
نشرت جبهة الإسناد السيبراني أجزاءً من وثائق داخلية لشركة Novamill Systems، بتبيّن تفاصيل تعاون الشركة في مجال القطع الصناعية والتكنولوجيا مع الصناعات العسكرية والفضائية التابعة للاحتلال الإسرائيلي.
بتشمل الوثائق عقودًا، واتفاقيات تعاون، وتقارير فنية مرتبطة بشركات، منها Elbit Systems وRafael والصناعات الجوية الإسرائيلية (IAI).
ومن بين الوثائق المنشورة مخططات هندسية، ومعلومات عن القطع، وتفاصيل عن أوجه التعاون التقني كمان.
Documents Released on Novamill’s Cooperation with Israeli Military Industries
The Cyber Isnaad Front has released portions of internal documents from Novamill Systems. The documents reportedly show details of the company’s cooperation in industrial components and technology with Israeli military and aerospace industries.
The documents include contracts, cooperation agreements, and technical reports related to companies including Elbit Systems, Rafael, and Israel Aerospace Industries (IAI).
The released materials also include engineering designs, information on components, and details of technical cooperation.
#TGITM @TheGhostITM
