Cyber Dispatch™️
376 subscribers
21 photos
1 video
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Critical WordPress Plugin Vulnerability Exploited in Widespread Attacks.
Ukraine Joins EU Cybersecurity Reserve for Emergency Support
 Artificial Intelligence Set to Transform Cyber Warfare Landscape.
Surge in Cyberattacks Targets Medical Technology Companies.
Anthropic May Introduce Identity Verification for Claude Users.
That WhatsApp file from a trusted contact may not be safe.

A new VBS malware campaign is spreading through WhatsApp Desktop/Web and installing ManageEngine Endpoint Central for remote access on Windows PCs.
A 1997 parser bug is still haunting Squid.

Squidbleed (CVE-2026-47729) can leak another user’s cleartext HTTP request through a shared Squid proxy, including credentials or session tokens.
A fake Node.js download was the start of a real malware chain.

Elastic researchers found a new #malvertising campaign using Google Ads to deliver OXLOADER, a previously unreported loader that drops CastleStealer.

The payload was staged through Storj and built to avoid analysis.
Canada’s spy service got a court order to remotely clean malware-infected devices.

CSIS used its threat reduction powers to neutralize two foreign-run botnets operating through Canadian servers, SOHO routers, cameras, TVs, and other IoT gear.

The ruling stayed secret for more than 2 years.
The critical NGINX flaws now have a clearer technical path.

CVE-2026-42530 comes down to an HTTP/3 lifetime mismatch that can leave a freed stream pointer treated as valid.

CVE-2026-42055 lets oversized HPACK data write past its buffer, causing unauthenticated worker crashes.
New macOS ClickFix attack silently mounts DMGs to push infostealer.
Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents.
Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks.
2 Scattered Spider-Linked Hackers Plead Guilty Over £39M TfL Cyberattack.
GIGABYTE confirms UEFI password bypass possible, calls it a design issue.
🫡31🤓1
Anyone can be a hacker, not just skinny white dudes in hoodies.

@HackersQuote
🤣31👏1
Japanese telco exposes 14.2 million managed email credentials.
Petro alleges U.S.–Israeli cyber units interfered in elections after right-wing candidate narrowly wins Colombian presidency.