Cyber Dispatch™️
394 subscribers
32 photos
2 videos
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts.
Adobe Patches Critical ColdFusion Vulnerabilities.
Cyberattack at KFC Japan impacting online orders and deliveries.
7 Severe Vulnerabilities Patched in VMware Avi Load Balancer.
BlackRock assets rise to RECORD $15.3 trillion — FT

$192 billion of capital in the second quarter ALONE
🤯1
FortiSandbox CVE-2026-59835 exposes sandbox VNC sessions without authentication.
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now.

An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, that were known to be defective but remained signed by the software company anyway.
Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws.
Microsoft patched a SharePoint flaw after attackers had already exploited it as a zero-day.

CVE-2026-58644 affects every supported on-premises SharePoint version and can lead to remote code execution.

CISA has now added it to KEV.
Two Scattered Spider hackers have been sentenced to 5.5 years each for the £29 million TfL attack.

The intrusion left 148 systems inoperable, disrupted Dial-a-Ride and payment services, and forced all 27,000 employees into the office for password resets.
Hidden Infrastructure Exposed: ANY.RUN Reveals Hijacked Gov Websites Delivering Malware.

ANY.RUN's latest threat investigation uncovered previously undocumented backdoors and relationships behind the active PhantomEnigma campaign.
😱1
CVE-2026-53412 affects the Desktop Client, VDI Client, and Meeting SDK.
South Korea making its own security-centric AI model.
New OkoBot framework deploys 20 payloads to steal data, crypto.
Coca-Cola says Fairlife ransomware attack halts US dairy production.
Australian regulator declines to find Qantas responsible for 5.67 million customer data exposure.
Daxin malware resurfaces with new backdoor targeting Taiwan manufacturer.
🤔1
‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing.
China 'just erased' US AI lead — Axios

Moonshot AI drops Kimi K3 — an open-weight model that BEATS Anthropic's Opus 4.8 on several benchmarks

And it's ~40% cheaper
wp2shell now has two CVEs, and a working proof-of-concept is public.

> CVE-2026-63030 breaks REST batch routing
> CVE-2026-60137 injects SQL

Chained, they give an anonymous attacker code execution on affected WordPress sites.
OpenSSL quietly fixed HollowByte, a flaw where an 11-byte TLS request can reserve up to 131 KB of server memory per connection.

On the glibc systems researchers tested, that memory remained frozen until restart.