Cyber Dispatch™️
393 subscribers
32 photos
2 videos
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Craneware confirms customer and employee data exposed in security incident.
South Korea proposes new rules for seizing self-custody crypto wallets.
Cookie Crumbles: Exploitation of CVE-2026-0257 Leads to Qilin Ransomware.
Hackers steal $23.7 million in crypto from Ostium in off-chain attack.
Healthcare giant Abbott probes two cyber incidents amid extortion claims.
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch.
LG Monitors Spotted Installing Adware-Like App on Windows PCs.
Paidwork breach exposes data of 23 million users: Check if you’re affected.
Greedy ransomware crews return for seconds after victims cough up first extortion payments.
Critical SharePoint RCE flaw exploited to steal machine keys.
Cisco's open-weight bug busters take on Google and OpenAI.
A cyberattack targeting Tidewater Telecom disrupted internet service for at least 23 towns in Maine's midcoast region on Sunday, affecting municipal governments and residents, as reported by Statescoop.
Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia.
Cisco Launches Low-Cost AI Models for Source Code Security.
Ostium trading platform loses $23.75 million in off-chain exploit.
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities.
The Hidden CCS2 Attack Surface on EV Chargers.
Windmill servers are under active attack.

Experts say attackers are exploiting CVE-2026-29059 to read arbitrary server files without logging in. On some systems, the same flaw can lead to superadmin access and code execution.
An attacker does not need the reviewer’s broader Azure DevOps permissions.

In tests, one hidden PR comment steered the reviewer’s AI coding agent into other projects and leaked data the attacker could not access directly.
Russian Hacker Used Gemini to Manage a Botnet

Trend Micro announced that a Russian hacker used Gemini CLI to manage a small botnet, delegating a significant portion of the technical tasks, including code writing, debugging, command execution, and even transferring the command and control (C2) server, to this AI tool.
Qualys researchers have disclosed a high-severity vulnerability in Ubuntu’s snap-confine component that allows an unprivileged local user to gain root access. Tracked as CVE-2026-8933, the flaw can give an attacker complete administrative control of an affected computer.