Most people assume that once their phone is locked, their photos are protected from anyone who picks up the device. However, a behavior discovered Jose Rodriguez shows that photos may be accessible during an incoming WhatsApp video call, even while the phone remains locked.
Cyber Dispatch™️
Most people assume that once their phone is locked, their photos are protected from anyone who picks up the device. However, a behavior discovered Jose Rodriguez shows that photos may be accessible during an incoming WhatsApp video call, even while the phone…
Fortunately, there is a simple mitigation you can apply today:
Open Settings on your Android device.
Go to Apps -> WhatsApp -> Permissions.
Select Photos and Videos.
Change the permission from full access to Limited access.
Open Settings on your Android device.
Go to Apps -> WhatsApp -> Permissions.
Select Photos and Videos.
Change the permission from full access to Limited access.
Cyber Dispatch™️
Most people assume that once their phone is locked, their photos are protected from anyone who picks up the device. However, a behavior discovered Jose Rodriguez shows that photos may be accessible during an incoming WhatsApp video call, even while the phone…
Discovery
This issue was discovered by Jose Rodriguez and has already been reported to both Meta and Google. According to the Jose, it works on current Android versions.
This issue was discovered by Jose Rodriguez and has already been reported to both Meta and Google. According to the Jose, it works on current Android versions.
Cisco searched for IOS XR bugs and found so many it rolled them into an update release.
SpaceXAI apologizes for outage that affected Grok and other 'compute partners'.
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory.
Cyber Dispatch™️
Pegasus and NoviSpy Used Against Serbian Protesters. #TGITM
Pegasus infected a Serbian student movement member’s iPhone through a zero-click iMessage exploit.
#TGITM
#TGITM
A critical Cisco Nexus 9000 flaw lets unauthenticated remote attackers run code as root.
CVE-2026-20212 leaves TCP ports 43210 and 43211 reachable in the default Layer 3 VRF on 10 switch models.
CVE-2026-20212 leaves TCP ports 43210 and 43211 reachable in the default Layer 3 VRF on 10 switch models.
An RMM phishing campaign first tied to Canada spans 46 countries.
ANYRUN linked 601 cases to the operation, with 45% of observed activity associated with the U.S. Fake tax, shipping, and invoice lures trick targets into installing legitimate RMM software.
ANYRUN linked 601 cases to the operation, with 45% of observed activity associated with the U.S. Fake tax, shipping, and invoice lures trick targets into installing legitimate RMM software.
Thomson Reuters C-Track court software breach may have exposed SSNs and sealed court data.
Attackers are exploiting LiteLLM, Artifactory, and Switchvox flaws.
The attacks deploy crypto miners and reverse shells, mint admin tokens, and harvest API keys. CISA added seven exploited vulnerabilities to its KEV catalog.
The attacks deploy crypto miners and reverse shells, mint admin tokens, and harvest API keys. CISA added seven exploited vulnerabilities to its KEV catalog.
A major breach at Nordic/Benelux IT supplier Dustin has led it to take systems offline. Webshops are down, and orders and deliveries have stopped.
Attackers are exploiting a Chrome V8 zero-day.
CVE-2026-85046 allows arbitrary code execution inside the browser sandbox via a crafted HTML page. Google fixed it in Chrome 152.0.7977.82/.83.
CVE-2026-85046 allows arbitrary code execution inside the browser sandbox via a crafted HTML page. Google fixed it in Chrome 152.0.7977.82/.83.
Tails 7.12 is out as the first release under the project’s new two-week cadence, bringing Tor Browser 15.0.21, Electrum 4.8.1, and updated firmware.
US military disables ad trackers on devices amid location-data targeting concerns
US military officials have said they disabled advertising trackers on a range of phones and computers, according to letters released on Friday by US Senator Ron Wyden and statements provided to Reuters. The move follows reports that commercially available location data had been used to target US forces in West Asia.
US military officials have said they disabled advertising trackers on a range of phones and computers, according to letters released on Friday by US Senator Ron Wyden and statements provided to Reuters. The move follows reports that commercially available location data had been used to target US forces in West Asia.