Cyber Dispatch™️
395 subscribers
33 photos
2 videos
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Mozilla rolls out ad blocking to Firefox for iOS.
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells.
Claude Mythos only model to complete full cyber kill chain, experts say.
New PackClient RAT sold on Telegram.
TikTok all public endpoints reversed engineered. Scraped 5.94 billion TikTok videos and 3.23 billion profiles in 3 weeks.
Legacy Lenovo login opens 5,000 Dropbox accounts to attackers.
Most people assume that once their phone is locked, their photos are protected from anyone who picks up the device. However, a behavior discovered Jose Rodriguez shows that photos may be accessible during an incoming WhatsApp video call, even while the phone remains locked.
Cyber Dispatch™️
Most people assume that once their phone is locked, their photos are protected from anyone who picks up the device. However, a behavior discovered Jose Rodriguez shows that photos may be accessible during an incoming WhatsApp video call, even while the phone…
Fortunately, there is a simple mitigation you can apply today:

Open Settings on your Android device.
Go to Apps -> WhatsApp -> Permissions.
Select Photos and Videos.
Change the permission from full access to Limited access.
Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs.
Cisco searched for IOS XR bugs and found so many it rolled them into an update release.
HPE patches critical ArubaOS-CX remote code execution flaw.
Pegasus and NoviSpy Used Against Serbian Protesters.

#TGITM
SpaceXAI apologizes for outage that affected Grok and other 'compute partners'.
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory.
Cyber Dispatch™️
Pegasus and NoviSpy Used Against Serbian Protesters. #TGITM
Pegasus infected a Serbian student movement member’s iPhone through a zero-click iMessage exploit.

#TGITM
A critical Cisco Nexus 9000 flaw lets unauthenticated remote attackers run code as root.

CVE-2026-20212 leaves TCP ports 43210 and 43211 reachable in the default Layer 3 VRF on 10 switch models.
An RMM phishing campaign first tied to Canada spans 46 countries.

ANYRUN linked 601 cases to the operation, with 45% of observed activity associated with the U.S. Fake tax, shipping, and invoice lures trick targets into installing legitimate RMM software.
Thomson Reuters C-Track court software breach may have exposed SSNs and sealed court data.
Attackers are abusing signed Node.js binaries to run malware.