Cyber Dispatch™️
393 subscribers
32 photos
2 videos
48 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs.
Microsoft builds a bouncer to keep bots out of Teams meetings.
Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input.
WhatsApp will soon enable the use of "username" so users can connect without sharing their phone numbers.
The Trump administration wants U.S. intelligence agencies to create a single master database of all foreign espionage targets—including suspected spies, intelligence officers, #hackers, criminal groups, and potential CIA recruits.
Amazon fined $2.25M for withholding evidence from fraud victims.
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware.
Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery.
Massive Password Spray Campaign Targeting Azure CLI.
Quebec water treatment plant attack gains access to control pumps and chlorine dosing.
RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS.
Norway plans to restrict AI use for students aged 6–13, shifting focus back to traditional learning tools amid concerns about developmental impact.
Poland warns Russia may be influencing AI outputs by flooding the internet with disinformation, highlighting a new front in hybrid warfare.
Reports suggest Claude Code may use hidden markers to identify certain users, raising new transparency and privacy concerns in AI tooling.
The U.S. lifts export restrictions on Anthropic’s advanced AI models after new security measures, restoring access for global users.
OECD releases a roadmap for AI in public governance, emphasizing citizen engagement and efficiency—but warns AI is not a standalone solution to democratic challenges.
The U.S. offers up to $10M for intel on hackers tied to Russian groups UNC5792 and UNC4221, linked to phishing attacks targeting Signal and WhatsApp users, including officials.
A former NSO executive is reportedly behind a new cyber project, signaling the next wave of offensive cyber tools as geopolitical tensions increasingly shift into digital battlegrounds.
90+ spoofed software domains are pushing AsyncRAT through ScreenConnect.

Kaspersky says the sites mimic OBS Studio, Bandicam, DNS Jumper, and DS4Windows, then use SEO to surface in Google and Bing.
PureLogs Stealer now hides behind Blogger pages and a fake PDF JavaScript file.

Experts say VEIL#DROP uses PowerShell, dynamic Blogspot URLs, fileless .NET loading, and Microsoft-signed LOLBins to evade detection.
Two Cursor vulnerabilities could let hidden prompt-injection instructions escape the editor’s terminal sandbox and run commands on a developer’s machine.

Tracked as CVE-2026-50548 and CVE-2026-50549, they affect versions before 3.0.