Cyber Dispatch™️
394 subscribers
33 photos
2 videos
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Judge orders Meta to pay nearly $1 billion in fines for endangering children online.
Israel is spending millions to shape how AI chatbots answer questions about Gaza, using a network of pro-Israel websites designed to influence training data and responses. The reporting says the goal is to “poison” chatbot outputs, not just sway public opinion.
3.8 Million Impacted by Unlimited Technology Systems Data Breach.
Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case.
Meta says AI model hacked third-party company during cyber testing.
Apple's Private Relay Leaks Your Real IP Address in Safari.
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild.
CIA Edited Wikipedia to Serve State Interests, Platform Co-Founder Reveals

Wikipedia co-founder Larry Sanger revealed that the CIA, global governments, and corporate PR firms systematically exploit the platform's anonymity rules to edit articles.
Cyber Support Front claims it is selling data allegedly stolen from Israeli defense contractor IMCO following a recent cyberattack. The breach reportedly includes sensitive production and product information.
A hacktivist group known as RipperSec has reportedly launched a new wave of DDoS attacks targeting an Israeli-linked export organization.
Anthropic says safety errors in its latest AI model have dropped significantly following updates, aiming to improve reliability in benign biological queries while maintaining strict safeguards on sensitive topics.
NetBlocks data shows internet connectivity in Odesa dropped sharply during recent Russian strikes on energy infrastructure, highlighting the overlap between kinetic attacks and digital disruption.
Google has open-sourced WeatherNext 2, an AI model designed to improve tropical storm forecasting, reportedly delivering earlier and more accurate predictions in testing, though it remains a research tool.
Japanese banks are ramping up AI-driven cybersecurity defenses, deploying advanced tools to detect vulnerabilities and counter increasingly sophisticated and zero-day attacks.
A cyberattack impacting IT systems at multiple North Carolina ports has exposed ongoing vulnerabilities in U.S. logistics infrastructure, with experts warning such hubs remain high-value targets due to operational complexity.
A suspected supply chain attack in Russia: threat group “Head Mare” reportedly breached TrueConf servers and distributed trojanized versions of its video conferencing software. Kaspersky says targets include energy, transport, and IT sectors.
New research demos also show CSS/HTML attack paths across Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail that can leak tokens, hijack UI actions, or lead to account takeover.
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.

The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain administrator access to the instance.
Attackers are exploiting a LoadMaster flaw for command execution.

CVE-2026-8037 lets unauthenticated attackers run arbitrary commands on affected appliances. KEVIntel logged 792 exploitation attempts from 65 IPs in 41 days.
Nearly 800 malicious npm packages are delivering a cross-platform RAT and infostealer.

The campaign targets Windows, macOS, and Linux, with WEL1DROPPER fetching platform-specific payloads and falling back to DNS TXT records when HTTPS fails.
A newly discovered WordPress pre-auth XSS affects every version.

XSS2Shell (CVE-2026-64638) can run attacker-controlled JS in a site's origin without a login. With a logged-in Administrator, one click, and required deployment conditions, it can be chained to PHP code execution.