Cyber Dispatch™️
395 subscribers
33 photos
2 videos
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Cyber Dispatch™️
ServiceNow Patches 3 Critical Code Injection Vulnerabilities.
The first of the critical bugs, tracked as CVE-2026-18885, allows an attacker to execute arbitrary code in the ServiceNow platform under certain circumstances.

An attacker could exploit the weakness to gain access to and potentially modify arbitrary data, ServiceNow notes in its advisory.

The second critical defect, CVE-2026-18886, is described as an improper access control issue. It could allow an attacker to create or modify arbitrary data and elevate their privileges.

Tracked as CVE-2026-74820, the third critical vulnerability is an SQL injection flaw that allows an attacker to execute arbitrary SQL statements against the underlying ServiceNow database.
Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs.
California moves to exempt Linux from new age-verification law.
Boston Scientific Still Recovering From Cyberattack.
French authorities exposed Mossad-linked Israeli firm BlackCore interfering in elections across Europe, Scotland, Africa, and New York.

Fake accounts, AI bots and smear campaigns—used to push voters toward right-wing, pro-Israel candidates.
Aurora ransomware operators gave Cursor AI credentials or an existing route into victim networks.

The agent handled exploitation tasks against 10 targets, including network scanning, privilege checks, NTLM relay attempts, and certificate attacks.
If you have a Gmail account, you need to read this.

Google's AI now scans your emails and attachments, bank statements, tax files, medical letters, all of it. It turned on by default, and there's a class-action lawsuit over how.

Here are 5 moves to shut it off, the switch is hidden in two places:

1. The Main Switch

This is the main setting Google shows you, but it's not the only one.
Gmail (Desktop):
⚙️ Settings → See all settings → Smart features and personalization → Uncheck "Turn on smart features in Gmail, Chat, and Meet" → Save Changes.

2. The Hidden Switch

Turning off the first setting isn't enough. Most people stop there.
On the same settings page: Google Workspace smart features → Manage Workspace smart feature settings → Turn off both checkboxes → Save.
Both settings need to be turned off.

3. Your Phone

The settings don't always sync between devices, so check the Gmail app separately.
Gmail app → Menu (☰) → Settings → Select your account → Turn off "Smart features and personalization" → Confirm.

4. Delete Gemini History

If you've used Gemini before, your chats may be saved, and some could be reviewed by humans.
Go to http://myactivity.google.com/product/gemini
→ Turn off Gemini Apps Activity → Delete Activity → All Time.
This removes your past Gemini chat history and stops future conversations from being saved.

5. Move Sensitive Emails

Turning off Gmail's smart features helps, but for truly private emails, consider using a separate service.
For medical, legal, or financial emails, use a free Tuta Mail account. It offers end-to-end encryption and doesn't use AI to scan your emails.

Keep Gmail for newsletters, promotions, and less sensitive messages - if you must.

#Tuta
Flock CEO says Americans must "compromise" on their privacy.
Recently, OpenAI shipped a plugin that lets ChatGPT read your Mac's Messages app, search it, and draft and send replies.

However, this feature essentially renders Apple's end-to-end encryption obsolete, because your messages are now sitting on OpenAI's servers in plaintext. The plugin needs Full Disk Access, Contacts and Automation. If you have Messages in iCloud switched on, that's potentially years of history, attachments and identities, plus every SMS 2FA code your iPhone forwards to your Mac.

OpenAI says it runs locally and doesn't build an index. Local execution isn't the same as local processing. The moment ChatGPT summarises a thread or drafts a reply using a hosted model, that content leaves the machine.

In 2025 a US court ordered OpenAI to preserve ChatGPT conversations for the NYT case, including ones people had deleted. Under the CLOUD Act, data in OpenAI's control is reachable by US legal process wherever it's stored, and they can be barred from telling you it happened.

Governments have spent a decade demanding a backdoor into iMessage and getting refused. This one installs itself, for free, with a toggle.

If you've enabled it, everyone who has ever texted you is in it, and none of them know.
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis.
9.5 Million Impacted by Aesto Health Data Breach.
Five Venezuelans plead guilty to ATM jackpotting attacks in US.
Major Cyber Attacks in August 2026: US, Israel and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk.
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set.
Suspected Chinese actor targets Philippine nuclear and naval entities using known vulnerabilities.
TELEGRAM'S GRAM WALLET BEGINS LIMITED ROLLOUT

Pavel Durov has announced that Gram Wallet is now accessible to a limited group of users, with access expected to gradually expand across Telegram's massive user base over the coming weeks.

The wallet experience shown inside Telegram allows users to send GRAM directly through chats — effectively making transferring digital assets feel similar to sending a message.
Multiple X users are reporting a wave of unsolicited password reset requests, with some receiving dozens in a short period.
𝗠𝗮𝗻𝗰𝗵𝗲𝘀𝘁𝗲𝗿 𝗔𝗶𝗿𝗽𝗼𝗿𝘁𝘀 𝗚𝗿𝗼𝘂𝗽

FulcrumSec Goes Public With Manchester Airports Group Breach Claim, Alleging 8.67 Million Customer Profiles Exposed.
Nearly 22,000 Microsoft Exchange servers still miss the fix for a critical vulnerability that gets attackers into mailboxes without a password, Shadowserver says.

The proof-of-concept exploit code is publicly available and easy to abuse.
CrowdStrike and NVIDIA have built two AI security models together, one to attack and one to defend.

The pair were tested against each other on a digital twin of NVIDIA's own infrastructure.

CrowdStrike says both run on NVIDIA Nemotron, trained on Falcon telemetry and 15 years of its incident-response data.
Defense Secretary Pete Hegseth’s driver’s license has leaked. A new dark-web service is selling scans of his and 153M+ U.S. and Canadian driver’s licenses.

Timestamps on the scans match victims’ visits to Hertz rental counters and cannabis dispensaries. Evidence points to idscan[.]net, an ID-verification vendor used by Hertz, Target, FedEx and 1,000+ dispensaries.

#TGITM