Cyber Dispatch™️
393 subscribers
32 photos
2 videos
48 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
EU Approves 348-Satellite IRIS² Network

Europe’s planned satellite constellation will provide secure communications for government, defense, and emergency services.
TONTOU Attack Bypasses Spectre Defenses

Researchers demonstrated a technique that can circumvent some Spectre v2 protections on AMD and Intel processors.
IBM Gives AI Security Tools to Universities

IBM and Red Hat will provide free vulnerability-analysis services to U.S. universities and nonprofit organizations.
Newcastle University confirms data breach after ExfilSquad claims 440k records.
Nikita Bier is stepping down as X’s head of product after roughly a year in the role, but will remain as an adviser. The move comes amid continued leadership changes at the platform—watching closely for who takes over product.
Levi Strauss discloses data breach after social engineering attack on employees.
North Carolina Ports confirms cyberattack disrupting operations.
UK Naval Drones Found Transmitting Data Signals to China

A routine cyber audit by the UK Ministry of Defense revealed that cameras on Kraken Technology naval drones were transmitting signals to an internet address in China
Anthropic now invisibly marks Claude-generated content worldwide, following new EU AI Act transparency rules effective August 2026.

Supported Claude models embed machine-readable watermarks directly into text, which can survive copy-pasting.

Generated images/files can carry signed C2PA provenance metadata.
ICYMI: One click from a logged-in WordPress admin can trigger a chain from pre-auth XSS to PHP code execution.

CVE-2026-64638 affects all WordPress versions, and the login-page XSS itself requires no authentication.
Mozilla revoked the Firefox and Thunderbird Linux signing key after an unencrypted copy was accidentally committed to a private repo.

No unauthorized access was found, but older downloads can stop verifying and some Firefox RPM updates may fail.
A malicious SIM can take over the modem from inside the device.

Researchers found 9 of 26 tested phones and cellular modules accept RUN AT commands from the SIM, including 6 of the 8 modules. On one commercial EV charger, they chained the interface to code execution.
Gunra ransomware breaches networks, steals data, and destroys backups.

Attacks have exploited Fortinet FortiOS/FortiProxy and Schneider Electric PowerLogic P5 flaws for initial access, before encrypting databases, NAS systems, and other key assets.
Historical reminder: In 2013, documents disclosed by Edward Snowden revealed a 2009 NSA–Israel SIGINT-sharing memorandum. The arrangement allowed Israel to receive raw, unminimized intelligence—including transcripts, emails, voice communications, and metadata—that could contain Americans’ communications. Although privacy guidelines were included, the memorandum stated that they were not legally binding.
1
FAA has hired 2,000+ gamers to train as air traffic controllers after targeting gaming skills like multitasking, quick decision-making, and problem-solving.

The April campaign helped the FAA reach 94% of its hiring goal, with another 2,000+ candidates in the pipeline.
North Korean hackers have been exploiting a newly patched Windows zero-day vulnerability to take over victims’ systems, Check Point reports.

Attributed to the infamous Lazarus Group APT, the attacks represent a continuation of the long-running Operation Dream Job campaign targeting job seekers with fake work opportunities at well-known companies. North Korean hackers have been mounting fake job attack variations regularly.
Cisco warns of ASA and FTD VPN flaw exploited to crash devices.
421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one.
Spain's national police have arrested a cybercriminal who allegedly made 38 attempts to impersonate 30 individuals to obtain digital certificates. The suspect is accused of using sophisticated techniques, including deepfake technology and forged documents, to bypass identity verification processes. The investigation was complicated by the suspect's use of numerous devices and stolen identities, with further coverage provided by The Register.
Signal adds an extra layer of security to make sure you're actually chatting with the right person.