Cyber Dispatch™️
396 subscribers
33 photos
2 videos
50 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch
Download Telegram
SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency.
Multiple Flaws in Google's Synced Passkey Implementation Allow Attackers to Take Over Your Accounts.
Microsoft denies Windows 11 is spying on desktop PCs, reveals what the service actually does.
Cyber Dispatch™️
Microsoft denies Windows 11 is spying on desktop PCs, reveals what the service actually does.
Windows 11 quietly runs a background service called Windows Health and Optimized Experiences, and yes, it starts automatically on every boot. It’s real, it’s been there for over a year, and no, it isn’t secretly recording your PC and sending it to Microsoft every 15 minutes!
Cyber Dispatch™️
Microsoft denies Windows 11 is spying on desktop PCs, reveals what the service actually does.
What it actually does is far less dramatic. The service, known internally as whesvc, watches for signs of a sluggish system and only saves diagnostic traces locally on your own machine. The data it collects doesn’t leave your PC unless you choose to file a report through the Feedback Hub.
Microsoft is trying to earn that trust back

Windows 11 became one of the most criticized versions of Windows for real reasons, and Redmond has been working to reverse that since March, when the company committed to fixing Windows 11’s quality and fundamentals.
New XCSSET variant targets macOS devs via compromised Xcode projects.
Two trojanized npm packages hid a command server’s IP address inside blank Ethereum transfers.

The NullReceiver technique avoids smart contracts and transaction data, making the attacker’s infrastructure harder for defenders to track.
A Linux kernel root exploit is now public.

The 13-year-old OVSwrap flaw (CVE-2026-64531) can let unprivileged local users gain root through Open vSwitch on affected systems.

The public PoC includes offsets for roughly 800 x86-64 kernel builds.
CVE-2026-59774, a critical Gitea flaw, lets attackers use a public repository to read any file accessible to the Gitea service account. Gitea says it could also be chained into command execution.
Kali365 turns Microsoft's real device login page into a phishing trap.

Victims enter an attacker-controlled code, which may give attackers continued access to Microsoft 365 email and files.

AnyRun records 80+ public sessions a week, with the US the main target.
Veeam, Terraform MCP, and Django patched 11 flaws exposing credentials, crossing tenant boundaries, and enabling file writes.
Cyber Dispatch™️
Veeam, Terraform MCP, and Django patched 11 flaws exposing credentials, crossing tenant boundaries, and enabling file writes.
Veeam fixed CVE-2026-58073, which can expose managed-agent credentials without authentication, and CVE-2026-58072, a file-write flaw that can lead to RCE.
HashiCorp patched CVE-2026-16498 and CVE-2026-16496, which can break tenant isolation in Terraform MCP Server, plus SSRF flaw CVE-2026-14869.
Django fixed CVE-2026-15307, a GeoDjango flaw that can write files and, on some setups, lead to code execution.
A new critical cPanel flaw could let an authenticated hosting customer run SQL as database root.

CVE-2026-58048 affects all supported cPanel & WHM versions and WP Squared. In some configurations, the compromise may reach the underlying OS.
Attackers are exploiting CVE-2026-18577 to bypass authentication, gain admin access, and abuse Take Control for lateral movement. N-able confirms limited customer compromises, and CISA has added the flaw to KEV.
DeepMind CEO Demis Hassabis Steps Down in Major Google AI Shake-Up

Demis Hassabis has resigned as chief executive of Google DeepMind to become Alphabet's chief scientist in a major leadership shake-up as Google attempts to outpace startup rivals.
Judge orders Meta to pay nearly $1 billion in fines for endangering children online.
Israel is spending millions to shape how AI chatbots answer questions about Gaza, using a network of pro-Israel websites designed to influence training data and responses. The reporting says the goal is to “poison” chatbot outputs, not just sway public opinion.
3.8 Million Impacted by Unlimited Technology Systems Data Breach.