Cyber Dispatch™️
395 subscribers
33 photos
2 videos
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Telegram was removed from the Apple App Store worldwide.

Added back to the Apple App Store.
TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover.
CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild.
Tor launches Snowflake Android app to help users bypass censorship.
Cyber Dispatch™️
Tor launches Snowflake Android app to help users bypass censorship.
The Tor Project has announced Snowflake Volunteer, a new Android app that lets users donate a portion of their internet bandwidth to help people bypass online censorship.

The app is intended to expand the pool of volunteer-run Snowflake proxies while giving users control over battery, network, and connection usage.
The Tor Project has announced Snowflake Volunteer, a new Android app that lets users donate a portion of their internet bandwidth to help people bypass online censorship.
The app is intended to expand the pool of volunteer-run Snowflake proxies while giving users control over battery, network, and connection usage.
Cyber Dispatch™️
The Tor Project has announced Snowflake Volunteer, a new Android app that lets users donate a portion of their internet bandwidth to help people bypass online censorship. The app is intended to expand the pool of volunteer-run Snowflake proxies while giving…
The app was developed by Bloco, an Android studio based in Portugal, after the company contacted Tor’s anti-censorship team about building a standalone Snowflake volunteering tool. The idea grew from Bloco’s work with the Open Observatory of Network Interference, or OONI, where its developers saw how activists and nongovernmental organizations rely on censorship-circumvention tools to stay connected.
New DOUBLECUP ClickFix service hides malware in browser cache images.
An active npm supply chain attack has compromised at least 868 packages carrying over 2 billion monthly installs with a credential-stealing worm. Shai-Hulud is back.

It started with the compromise of the GitHub account of the maintainer behind keyv, a library with roughly 127 million weekly npm downloads.
SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access.
Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages.
SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency.
Multiple Flaws in Google's Synced Passkey Implementation Allow Attackers to Take Over Your Accounts.
Microsoft denies Windows 11 is spying on desktop PCs, reveals what the service actually does.
Cyber Dispatch™️
Microsoft denies Windows 11 is spying on desktop PCs, reveals what the service actually does.
Windows 11 quietly runs a background service called Windows Health and Optimized Experiences, and yes, it starts automatically on every boot. It’s real, it’s been there for over a year, and no, it isn’t secretly recording your PC and sending it to Microsoft every 15 minutes!
Cyber Dispatch™️
Microsoft denies Windows 11 is spying on desktop PCs, reveals what the service actually does.
What it actually does is far less dramatic. The service, known internally as whesvc, watches for signs of a sluggish system and only saves diagnostic traces locally on your own machine. The data it collects doesn’t leave your PC unless you choose to file a report through the Feedback Hub.
Microsoft is trying to earn that trust back

Windows 11 became one of the most criticized versions of Windows for real reasons, and Redmond has been working to reverse that since March, when the company committed to fixing Windows 11’s quality and fundamentals.
New XCSSET variant targets macOS devs via compromised Xcode projects.
Two trojanized npm packages hid a command server’s IP address inside blank Ethereum transfers.

The NullReceiver technique avoids smart contracts and transaction data, making the attacker’s infrastructure harder for defenders to track.
A Linux kernel root exploit is now public.

The 13-year-old OVSwrap flaw (CVE-2026-64531) can let unprivileged local users gain root through Open vSwitch on affected systems.

The public PoC includes offsets for roughly 800 x86-64 kernel builds.
CVE-2026-59774, a critical Gitea flaw, lets attackers use a public repository to read any file accessible to the Gitea service account. Gitea says it could also be chained into command execution.