Cyber Dispatch™️
394 subscribers
33 photos
2 videos
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Multiple X users are reporting a wave of unsolicited password reset requests, with some receiving dozens in a short period.
𝗠𝗮𝗻𝗰𝗵𝗲𝘀𝘁𝗲𝗿 𝗔𝗶𝗿𝗽𝗼𝗿𝘁𝘀 𝗚𝗿𝗼𝘂𝗽

FulcrumSec Goes Public With Manchester Airports Group Breach Claim, Alleging 8.67 Million Customer Profiles Exposed.
Nearly 22,000 Microsoft Exchange servers still miss the fix for a critical vulnerability that gets attackers into mailboxes without a password, Shadowserver says.

The proof-of-concept exploit code is publicly available and easy to abuse.
CrowdStrike and NVIDIA have built two AI security models together, one to attack and one to defend.

The pair were tested against each other on a digital twin of NVIDIA's own infrastructure.

CrowdStrike says both run on NVIDIA Nemotron, trained on Falcon telemetry and 15 years of its incident-response data.
Defense Secretary Pete Hegseth’s driver’s license has leaked. A new dark-web service is selling scans of his and 153M+ U.S. and Canadian driver’s licenses.

Timestamps on the scans match victims’ visits to Hertz rental counters and cannabis dispensaries. Evidence points to idscan[.]net, an ID-verification vendor used by Hertz, Target, FedEx and 1,000+ dispensaries.

#TGITM
Sony's PlayStation arm says it may stop responding to customers who harass staff and consider legal or criminal action.

Its new policy cites customer demands like forced kneeling apologies, uninvited office visits and repeated demands.
IDScan publicly names the brands that feed driver’s licenses into its systems:

Hertz, FedEx, Target, GameStop, Caesars, Motorola Solutions, Jack Henry, LendingUSA, MRI Software, Waste Management, Polaris, Rouses Market, Circa Casino, Planet 13 and the US Coast Guard Academy.

These are the suspected sources of the 153M scans now selling on the dark web.
Microsoft will turn memory integrity on by default on more Windows 11 PCs from October 13, and it can slow games.

Tom's Hardware measured games up to 15% slower with VBS and memory integrity on in 2023 and a since-deleted 2022 Microsoft post acknowledged a frame-rate cost in some games.

Microsoft will start switching Memory Integrity (HVCI) on by default across eligible Windows 11 PCs, delivered through ordinary quality updates.

Only verified kernel-mode code will load, blocking unsigned rootkits and raising the bar on driver-based kernel attacks.
Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556).
Mozilla rolls out ad blocking to Firefox for iOS.
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells.
Claude Mythos only model to complete full cyber kill chain, experts say.
New PackClient RAT sold on Telegram.
TikTok all public endpoints reversed engineered. Scraped 5.94 billion TikTok videos and 3.23 billion profiles in 3 weeks.
Legacy Lenovo login opens 5,000 Dropbox accounts to attackers.
Most people assume that once their phone is locked, their photos are protected from anyone who picks up the device. However, a behavior discovered Jose Rodriguez shows that photos may be accessible during an incoming WhatsApp video call, even while the phone remains locked.
Cyber Dispatch™️
Most people assume that once their phone is locked, their photos are protected from anyone who picks up the device. However, a behavior discovered Jose Rodriguez shows that photos may be accessible during an incoming WhatsApp video call, even while the phone…
Fortunately, there is a simple mitigation you can apply today:

Open Settings on your Android device.
Go to Apps -> WhatsApp -> Permissions.
Select Photos and Videos.
Change the permission from full access to Limited access.