Cyber Dispatch™️
394 subscribers
33 photos
2 videos
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Attackers are exploiting a GitLab flaw days after disclosure.

CVE-2026-19478 lets unauthenticated attackers modify or delete public projects and rewrite their data under certain conditions. watchTowr says it saw in-the-wild exploitation against its honeypots.
Attackers can weaponize Defender’s own signed driver to delete security software at boot.

BTR.sys runs from Ring 0 before Defender’s user-mode services start. Check Point showed it deleting the full Defender stack on Windows 11 25H2 with Tamper Protection enabled.
A CVSS 10.0 Entra ID flaw was exploited in the wild.

CVE-2026-69836 allows an unauthorized attacker to remotely execute code through unsafe deserialization.

Microsoft says the flaw is fully mitigated and no customer action is required. How attackers exploited it remains undisclosed.
Rust supply chain attack hits three crates, including 245 million-download arrayref.

A compromised maintainer account pushed malicious releases that pulled in typosquatted proc-macro1, whose build script fetches and runs a remote payload during compilation.
Critical NetScaler flaw can bypass authentication on certain Gateway and AAA configurations.

Citrix patched CVE-2026-19490 (CVSS 9.3). Exposure depends on the NetScaler version and configuration, with SAML required in some cases.
Attackers are exploiting a Zimbra flaw that can lead to unauthenticated RCE.

CVE-2026-73570 affects ZCS before 10.1.20 when zimbra-snmp is installed and SNMP notifications are enabled. Crafted SMTP requests may execute OS commands as the Zimbra user.
Expired Visa payment cards can be revived for real purchases.

New “Zombie Card” attack rewrites the expiry date a contactless terminal reads over NFC, while the card’s cryptography still validates.
Manic can exfiltrate data even when a phone is offline.

New Manic Android malware uses nearby infected devices as C2 relays, with four hops by default. It targets 169 apps and can capture PINs, one-time codes, messages, files, and location data.
NASA AIT-GUI could let unauthenticated attackers issue spacecraft commands.

The operator console also exposed script and sequence execution, while malicious web pages could reach command routes through cross-origin POST requests.
ToxicPanda and GoldDigger are moving beyond credential theft.

ToxicPanda 2.0 adds 167 remote commands, PIN harvesting, lock-screen credential replacement, and shell access. GoldDigger can control banking apps, view screens live, and initiate fraudulent transactions.
14 npm packages drop RedC2 4.0 on Linux.

The packages work as advertised, but also launch its RedShell beacon on import. RedC2 includes an LLM-backed agent that turns natural-language instructions into beacon commands.
40 Firefox extensions pose as Web3 products to steal wallet secrets.

They impersonate OKX, Rabby Wallet, TronLink and others, capturing recovery phrases, private keys, keyrings, credentials or clipboard data. Some began as sports or utility add-ons.
Unauthenticated attackers could turn Elementor Pro uploads into RCE.

CVE-2026-32475 lets an attacker skip the file-extension blocklist and upload PHP when a published Form widget has a File Upload field. Elementor fixed it in 4.2.2.
A Spectre attack leaked a JWT from a co-located Cloudflare Worker.

Researchers demonstrated the attack in Cloudflare’s production environment at up to 12 bits/second, 360× faster than the 2021 result. No customer data was accessed.
Russia Expands Information Warfare with Artificial Intelligence and Cyberattacks

Since the start of the war in Ukraine, Russia has shifted its focus from achieving a quick victory in the "battle of narratives" to a long-term information operation, employing state media, proxy networks, cyberattacks, and artificial intelligence in a coordinated manner.
Cyber Dispatch™️
Russia Expands Information Warfare with Artificial Intelligence and Cyberattacks Since the start of the war in Ukraine, Russia has shifted its focus from achieving a quick victory in the "battle of narratives" to a long-term information operation, employing…
Artificial intelligence has reduced the cost of information warfare operations by enabling the rapid creation of fake content, translation and localization of messages, and the generation of synthetic images and videos. Simultaneously, data theft and cyberattacks are also used to bolster propaganda efforts.

In this approach, Russia tailors its messages to specific regions and utilizes topics such as energy, migration, and the cost of supporting Ukraine to influence public opinion.
Beijing has announced a new three-year action plan to develop the humanoid robot and embodied intelligence industry. This plan focuses on strengthening production, standards, testing and certification, financing, and building a resilient supply chain.
Lawmakers Seek Review of Staff Reductions at U.S. Cybersecurity Agency

Several U.S. congressional Democrats have asked the U.S. Government Accountability Office (GAO) to investigate the impact of significant staff and budget cuts at the Cybersecurity and Infrastructure Security Agency (CISA) on the agency's ability to protect critical infrastructure.
According to a report from the National Center for Cyberspace, the messaging apps Ita and Bale collectively recorded 15 billion visits between July 7th and July 13th, 2024.

Bale, with 10.8 billion visits and 3.4 million pieces of content, and Ita, with 4.2 billion visits and 6.1 million pieces of content, registered the highest levels of activity. Viraesti also published 123,000 pieces of content.
Cyberattack on Canada's Largest Children's Hospital

SickKids, the largest children's hospital in Canada, has announced a cybersecurity incident that may have resulted in the theft of personal information of current and former employees, job applicants, and staff of some affiliated organizations.
American Senators Demand Explanation from TikTok

American senators Marsha Blackburn and Richard Blumenthal have accused TikTok of disabling certain protective features of its algorithm in A/B tests for a group of users, in order to assess the impact of safety measures on user engagement.