Cyber Dispatch™️
393 subscribers
32 photos
2 videos
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
According to the Cyber Security Task Force, the Australian Cyber Security Centre has issued a warning about the active exploitation of a critical vulnerability, CVE-2026-63077, in the TeamCity platform developed by JetBrains.
A Marimo notebook can launch MCP commands before cells run.

CVE-2026-75149 triggers when a crafted notebook is opened in edit mode. It affects versions before 0.23.15.
Marimo fixed it in 0.23.15.
WhatsApp now supports multiple passkeys per account.

Users can now use phishing-resistant passkeys across iOS and Android. It’s also adding full passwords for two-step verification and more context for unknown Android calls.

WhatsApp says 1 billion+ people already use them.
E4del and PINHOLE RATs hide commands in FTP banners.

The campaigns turn FTP server welcome messages into dead drop resolvers to fetch commands or C2 details.

PINHOLE also uses Pinterest and SurveyMonkey for C2 resolution.
Attackers are actively exploiting a CVSS 10.0 Oracle WebLogic flaw

CVE-2026-21962 can let unauthenticated attackers access or modify critical data in Oracle HTTP Server and WebLogic Server Proxy Plug-in via HTTP.
Cyber Dispatch™️
Yemeni Cyberattack on the Zionist Regime's Power Grid The hacking group "Uways al-Qarani" (أويس القرني) claimed in a statement that it carried out a cyber operation against the Zionist regime's electricity infrastructure. The group stated that in this operation…
Why would a Yemeni cyber group call itself “Uways al-Qarani”? Because names matter. It invokes a revered Yemeni Islamic figure, signaling identity, legitimacy, and ideological purpose—turning cyber ops into part of a wider resistance, not just technical disruption.
A large-scale DDoS attack has targeted the shared infrastructure of Norway's digital government services since Monday, causing disruptions to some public services.
Cyber Dispatch™️
A large-scale DDoS attack has targeted the shared infrastructure of Norway's digital government services since Monday, causing disruptions to some public services.
Systems such as government login, digital identification, electronic signatures, and tax services have experienced outages, slowdowns, or login issues. Norwegian officials have stated that some services are now stable, and there is no evidence of breaches or theft of personal information.
Peru and the Israeli regime are seeking to deepen cooperation in the field of cybersecurity.
Memory chips from the Chinese company CXMT, which previously struggled to reach speeds of 6400 MT/s, have now achieved a speed of 9000 MT/s in DDR5 kits.
New details emerge about the cyberattack on an American oil tanker in Gibraltar.
Cyber Dispatch™️
New details emerge about the cyberattack on an American oil tanker in Gibraltar.
Following reports about the cyberattack on the oil tanker "VL Prosperity" in the Strait of Gibraltar, Captain Mamdouh bin Jaber Al-Saqt, a seasoned Saudi captain, has revealed more details about the incident.

According to Al-Saqt, the oil tanker was targeted by a cyberattack on the night of August 7, 2026. The attackers disrupted the operation of critical parts of the ship by interfering with the engine control systems and fuel tanks. Communication with the vessel was also down for approximately 30 hours.
Researchers have warned about a security vulnerability in NVIDIA NemoClaw that, under certain circumstances, allows an attacker to access a local Ollama instance by redirecting a user to a malicious website, even without authentication.
Meta agrees to $17.1 billion settlement over alleged harms to children.
GTA 6 leak hype abused to distribute Vidar infostealer malware.
Carhartt data breach affects 12.9M, half of what ShinyHunters claimed.
Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges.

The first (tracked as CVE-2026-77537) lets unauthenticated attackers compromise unpatched devices by exploiting an improper input validation weakness in the UniFi Protect Application video surveillance management platform.

Ubiquiti also addressed a CRLF injection flaw (CVE-2026-77550) that remote attackers without privileges can exploit to bypass authentication on UniFi OS devices or instances.
Cyber Dispatch™️
Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges. The first (tracked as CVE-2026-77537) lets unauthenticated attackers compromise unpatched devices by exploiting…
"A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running CRLF Injection to bypass authentication to such UniFi OS devices or instances," it explained.

The third maximum severity vulnerability patched today is a command injection security flaw (CVE-2026-77554) stemming from improper input validation in the UniFi Talk Application Voice over IP (VoIP) phone system.
OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation.
Adobe and Nvidia Patch Dozens of Vulnerabilities.
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes.