Cyber Dispatch™️
393 subscribers
32 photos
2 videos
48 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
A new Linux kernel exploit (CVE-2026-46331) gets root without modifying a single file on disk.

It poisons the cached copy of /bin/su in memory. The binary on disk stays untouched. File-integrity checks come back clean.
Shai-Hulud-linked malware has moved beyond npm.

Researchers found 23 malicious npm packages and a related Go module tied to Verana Blockchain.
Forescout says CVE-2025-67038 was exploited as a zero-day.

The Lantronix flaw was used against honeypots.
LastPass Customer Data Leak Through a Third-Party Company

LastPass customer data has been exposed following a security incident involving Klue, one of the company's external suppliers.
Development of the world's first intelligent microscope with the help of artificial intelligence

Chinese researchers have developed the first AI-equipped transmission electron microscope named Aeye-1. This technology can automatically perform sample preparation, imaging, and data analysis.
OpenAI unveiled its new family of artificial intelligence models

OpenAI has unveiled its new family of AI models named Sol, Terra, and Luna. These models have been developed for advanced applications, general use, and fast, cost-effective processing.
Ukraine reports an organized cyberattack to steal messenger accounts

According to the Ukrainian Security Service, a cyber operation attributed to Russian intelligence agents used fake support messages to access messenger accounts of officials, military personnel, and activists in Ukraine, Europe, and the United States.
LastPass Customer Data Leak Through a Third-Party Company

LastPass customer data has been exposed following a security incident involving Klue, one of the company's external suppliers.
CVE-2026-55200 now has public PoC code.

The libssh2 flaw lets a malicious SSH server trigger memory corruption in a connecting client.

No credentials
No user interaction
Affected through libssh2 1.11.1
Aubrey Cottle, an hacker from Oshawa, has been sentenced to 18 months after he admitted his involvement in a 2021 website defacement attack on the Republican Party of Texas (also called GOP/Grand Old Party). The sentencing was delivered by Justice Joseph Di Luca on Friday in a Newmarket courtroom.
Cyber Dispatch™️
Aubrey Cottle, an hacker from Oshawa, has been sentenced to 18 months after he admitted his involvement in a 2021 website defacement attack on the Republican Party of Texas (also called GOP/Grand Old Party). The sentencing was delivered by Justice Joseph Di…
This is crazy—an ex-Anon. A clown act more often than not. Once you’re exposed, you’re no longer a shadow; you become a public figure, reduced to performing stunts for attention. For other ex-Anons, do not perform publicity stunts. Disappear. Go underground. Stay quiet for a long time. When you return, do it clean—with no ties to the past. Cut off all contact with former associates. Build new channels, new identities, and new discipline.
Within the Anonymous collective, members are not typically referred to as “Anonymous” individually, but as “Anons.” The term applies broadly to participants, whether they are activists or hacktivists.
Experts say DCloud Uni-App templates are being used to run fake crypto exchanges, WhatsApp phishing, gambling scams, and wallet drainers.
Microsoft removed 119 Edge extensions hiding malware in images and fonts.

Up to 2.6 MILLION installs. They posed as ad blockers, VPNs, translators, and video downloaders.
The Russian Foreign Ministry announced that the country's responsible agencies are fully prepared to counter potential cyber threats from Ukraine, especially during the Russian Duma elections.
Tens of thousands of FortiGate firewalls have been exploited

Reports indicate the identification of tens of thousands of FortiGate devices with valid access credentials; this is referred to as the "FortiBleed" campaign.
Security researchers have announced that attackers have started exploiting a critical vulnerability in Oracle E-Business Suite; a weakness that could lead to full takeover of vulnerable systems.

This vulnerability, identified as CVE-2026-46817, was patched by Oracle in May 2026, but reports indicate that some organizations have not yet applied the necessary security updates.
New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials.
Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs.
Microsoft builds a bouncer to keep bots out of Teams meetings.
Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input.