Cyber Dispatch™️
The blackout prevents independent verification of structural damage and battlefield developments in Gaza, Lebanon, and Iran. Experts warn the measures function to shield state actors from accountability under the guise of security. Adversaries with native…
The restrictions are more about avoiding embarrassment than actual security concerns. Researchers are now turning to Chinese and European satellite systems, though advocates caution that political motivations are driving these information limitations in support of an unpopular war.
Three new critical ServiceNow flaws score a maximum CVSS 10.0 and require no authentication.
They can enable arbitrary code execution, privilege escalation, or arbitrary SQL against an instance. ServiceNow says it is not aware of exploitation.
They can enable arbitrary code execution, privilege escalation, or arbitrary SQL against an instance. ServiceNow says it is not aware of exploitation.
A new critical cPanel flaw could let one hosting customer take root control of an entire server.
CVE-2026-65643 affects all supported cPanel & WHM versions. The account must be able to add parked or addon domains, which can be abused to create arbitrary server files and ultimately execute code as root.
CVE-2026-65643 affects all supported cPanel & WHM versions. The account must be able to add parked or addon domains, which can be abused to create arbitrary server files and ultimately execute code as root.
PaperCut zero-day is under active exploitation.
The flaw affects all PaperCut NG and MF versions, with confirmed customer incidents. Emergency patches are available for v25 and v26. The exploit method and attackers remain unknown.
The flaw affects all PaperCut NG and MF versions, with confirmed customer incidents. Emergency patches are available for v25 and v26. The exploit method and attackers remain unknown.
APT28-linked HOOKEDGE targets European governments and diplomats through Word lures.
The batch backdoor abuses webhook[.]site for C2 and data exfiltration, while high-value targets receive a faster second stage.
The batch backdoor abuses webhook[.]site for C2 and data exfiltration, while high-value targets receive a faster second stage.
A malicious Amazon Kiro workspace can leak sensitive local data.
After opening the workspace, sending any message to the agent can trigger repository-controlled instructions that send local data to an external server. Amazon fixed the flaw in Kiro 0.8.140.
After opening the workspace, sending any message to the agent can trigger repository-controlled instructions that send local data to an external server. Amazon fixed the flaw in Kiro 0.8.140.
US-Israel space defense ties are deepening. IAI, ELTA, RAFAEL, and ELBIT are co-developing with US contractors on Arrow 2/3, David's Sling, and potential Golden Dome integration—a space-based missile defense architecture for US homeland protection. The Arrow system, jointly developed with the US Missile Defense Agency, already intercepts ballistic threats in exo-atmospheric space. Golden Dome requirements include directed energy, high-power microwaves, satellite constellations, and AI-driven radar detection. A new 10-year Israel-NASA agreement covers scientific space collaboration from Artemis to the ULTRASAT telescope. The lines between science, defense, and surveillance are blurring.
New US federal indictment: Prosecutors in Northern California allege that Ruben Ian Thomson, also known as “TeamPCP,” hacked several companies, stole sensitive data and demanded ransom payments.
The full 8-page filing is below.
The full 8-page filing is below.
Stripe and Advent have abandoned their pursuit of PayPal, Bloomberg reports, citing people familiar with the matter.
Their $ 60.50-a-share offer valued PayPal at just over $ 53bn, roughly 15% of the ~$360bn the company commanded in 2021. Reuters reported in July that PayPal's board still considered it inadequate.
Their $ 60.50-a-share offer valued PayPal at just over $ 53bn, roughly 15% of the ~$360bn the company commanded in 2021. Reuters reported in July that PayPal's board still considered it inadequate.
Excessive use of social media is linked to an increased risk of depression.
A study conducted over 11 years with 183,000 adults found that individuals who spend at least 150 minutes per day on social media are more likely to experience depression.
A study conducted over 11 years with 183,000 adults found that individuals who spend at least 150 minutes per day on social media are more likely to experience depression.
ShinyHunters claims a U.S.-based financial technology.
🇺🇸 Jack Henry & Associates - A U.S.-based financial technology company providing core banking, payment processing, digital banking, and other technology services to banks and credit unions.
🇺🇸 Jack Henry & Associates - A U.S.-based financial technology company providing core banking, payment processing, digital banking, and other technology services to banks and credit unions.
Critical CVE-2026-73125 impacts Ebyte NE2-D11 devices
A critical missing-authentication vulnerability in the Ebyte NE2-D11 web management interface could allow a remote, unauthenticated attacker to access administrative functionality.
CVE-2026-73125 carries a CVSS 3.1 score of 9.8 and requires no privileges or user interaction. Successful exploitation could allow attackers to:
• Access sensitive configuration data
• Modify device settings
• Disrupt device availability
Affected firmware: FW-9167-0-11
A critical missing-authentication vulnerability in the Ebyte NE2-D11 web management interface could allow a remote, unauthenticated attacker to access administrative functionality.
CVE-2026-73125 carries a CVSS 3.1 score of 9.8 and requires no privileges or user interaction. Successful exploitation could allow attackers to:
• Access sensitive configuration data
• Modify device settings
• Disrupt device availability
Affected firmware: FW-9167-0-11
The Google engineer accused of making $1.2M on Polymarket insider trading says he was just gambling, not swapping, which places him outside of US commodities law.
Michele Spagnuolo's lawyers filed to dismiss on Wednesday. They aren't denying the trades, they argue Polymarket bets aren't swaps under the Commodity Exchange Act, putting a Switzerland-based gambler outside US jurisdiction.
Michele Spagnuolo's lawyers filed to dismiss on Wednesday. They aren't denying the trades, they argue Polymarket bets aren't swaps under the Commodity Exchange Act, putting a Switzerland-based gambler outside US jurisdiction.