Cyber Dispatch™️
393 subscribers
32 photos
2 videos
48 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
FBI Arrests Florida Man in $220,000 Steam Crypto Theft Case.
Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding.
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs.
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent.
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines.
Attackers are exploiting Palo Alto Networks PAN-OS flaw CVE-2026-0257 to deploy Qilin ransomware.

Some intrusions ended in rapid encryption. Others escalated to credential theft, data exfiltration, and double extortion.
Invisible text on an Android screen can hijack an AI agent and make it run commands on the PC controlling the phone.

Researchers tested 5 open-source frameworks. Every one failed at least six of seven attacks.
WordPress sites are under active attack.

Attackers are exploiting the wp2shell chain to gain unauthenticated RCE on vulnerable stock installations, with no plugins required. Public exploit code is now fueling mass scanning and web shell deployments.
SharkNinja has responded to The Hacker News story on the Shark robot vacuum flaw.

The company says it has "completely addressed" the vulnerability, but has not said when the fix shipped, whether it reissued the exposed device certificates or only rescoped the policy, or how many devices were affected.
CVE-2026-58455 chains an authentication bypass with command injection. In the standard deployment, RCE inside the application container becomes host compromise through the mounted Docker socket.
Microsoft shares manual fix for WSUS sync delays and timeouts.
Clover Health Investments Discloses Data Breach.
US seizes over 1,000 websites in FIFA World Cup piracy crackdown.
New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication.
OVH reveals semi-secret plan to fix critical Januscape bug with mass reboots – and an Australian crash-test dummy.
Europe's flagship open-source Microsoft 365 rival Nextcloud's website was hacked. The company confirmed it after publicly calling it "a normal infrastructure problem." Nextcloud uses Wordpress (ring a bell? wp2shell?).
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign.
Suno - 55,282,226 breached accounts.
Craneware confirms customer and employee data exposed in security incident.
South Korea proposes new rules for seizing self-custody crypto wallets.
Cookie Crumbles: Exploitation of CVE-2026-0257 Leads to Qilin Ransomware.