Cyber Dispatch™️
393 subscribers
32 photos
2 videos
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Cisco's open-weight bug busters take on Google and OpenAI.
A cyberattack targeting Tidewater Telecom disrupted internet service for at least 23 towns in Maine's midcoast region on Sunday, affecting municipal governments and residents, as reported by Statescoop.
Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia.
Cisco Launches Low-Cost AI Models for Source Code Security.
Ostium trading platform loses $23.75 million in off-chain exploit.
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities.
The Hidden CCS2 Attack Surface on EV Chargers.
Windmill servers are under active attack.

Experts say attackers are exploiting CVE-2026-29059 to read arbitrary server files without logging in. On some systems, the same flaw can lead to superadmin access and code execution.
An attacker does not need the reviewer’s broader Azure DevOps permissions.

In tests, one hidden PR comment steered the reviewer’s AI coding agent into other projects and leaked data the attacker could not access directly.
Russian Hacker Used Gemini to Manage a Botnet

Trend Micro announced that a Russian hacker used Gemini CLI to manage a small botnet, delegating a significant portion of the technical tasks, including code writing, debugging, command execution, and even transferring the command and control (C2) server, to this AI tool.
Qualys researchers have disclosed a high-severity vulnerability in Ubuntu’s snap-confine component that allows an unprivileged local user to gain root access. Tracked as CVE-2026-8933, the flaw can give an attacker complete administrative control of an affected computer.
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks.
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge.
Microsoft 365 outage affects Teams, SharePoint and other services.
EU fines Google $1 billion for search, app store antitrust violations.
Hackers abuse Notepad++ plugins to stealthily install malware.
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers.
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild.
Millions of California-bought cars can be hijacked via Bluetooth.
Year-long Russian attacks infect users as soon as they look at an email.
New Dolphin X infostealer uses AI to identify high-value victims.