Cyber Dispatch™️
399 subscribers
34 photos
2 videos
52 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch
Download Telegram
Berlin has launched a crisis response after hackers published data stolen from the city government.

The cyberattack affected two government departments, the ransomware group Rhysida claims it stole around 5.79 TB of data from Berlin’s systems, including thousands of contracts and other documents.
Attackers hijack MikroTik routers through internet-exposed SSH. No authentication required.
A critical VMware flaw can turn local VM admin access into host code execution.

Broadcom fixed CVE-2026-59346 and an HGFS flaw in Workstation and Fusion 26H1u1. Both affect 25H2 and 26H1, with no workarounds or known exploitation.
Attackers are exploiting an unpatched Magento and Adobe Commerce ZERO-DAY to backdoor online stores.

No login required. No published CVE. No Adobe patch yet.
Attackers breached JetBrains Cadence via an unpatched TeamCity server, extracting AWS IAM credentials from a 2024 backup and accessing user data and S3 files.

JetBrains is urging users to rotate secrets and treat all Cadence executions as untrusted.
Attackers are exploiting a PaperCut authentication bypass and RCE chain against schools and universities in the U.S. and Europe.

The attacks enable credential theft, privileged account creation, registry hive collection, and Meterpreter deployment.
Attackers conceal phishing lures using invisible Unicode characters.
The creator of the C++ programming language, Bjarne Stroustrup.
Cyber Dispatch™️
The creator of the C++ programming language, Bjarne Stroustrup.
-

"Idiotic": Bjarne Stroustrup Slams AI-Coded Software as a Security Nightmare

By #TGITM — Published: September 7, 2026

In a blistering critique that has sent ripples through the developer community, Bjarne Stroustrup—the creator of the C++ programming language—has dismissed the current wave of AI-generated code as not only ineffective but dangerously insecure.

Speaking in a recent interview, Stroustrup pulled no punches, calling the idea of using natural language as a programming language "idiotic." While the tech industry races to embed large language models into every development pipeline, the legendary computer scientist warns that the output is a ticking time bomb for safety-critical systems.

"Bloated Code, More Bugs, More Holes"

Stroustrup's primary grievance lies with code quality. He argued that AI tools do not write lean, efficient code—they generate "bloated code" that introduces "more bugs, more security holes," and consumes excessive memory.

"It's hard to validate, " he stated, pointing to a fundamental flaw: unlike human-written patches, which are typically localized and traceable, AI-generated changes are opaque. "You don't actually know where it's changed. You have to try and figure that out. "

This lack of transparency, he warned, creates a validation crisis. The very experts capable of auditing this machine-written code—senior developers—are starting to retire rather than deal with the Sisyphean task of re-validating code that "changes every time you make a change in your prompts. "

The 10–20% That Matters Most

While acknowledging that AI might handle mundane or boilerplate tasks, Stroustrup made it clear where the line must be drawn.

"It's not, at least now, good at safety-critical, performance-critical code, " he said.

He conceded that AI could potentially manage "70 or 80% of the world's code," but dismissed that as irrelevant. "It's that 10 or 20% of the code that I'm interested in. And there, it's not there. "

Repeating Old Mistakes

Perhaps most damning is his observation that LLMs are merely regurgitating the past. "LLM-based code is imitating old code and getting old performance and old bugs again, " he noted. Rather than advancing software engineering, AI risks fossilizing legacy vulnerabilities and inefficiencies.

The Bottom Line

For security professionals, Stroustrup's message is clear: Do not trust AI to write critical infrastructure code. While the industry chases productivity gains, the hidden costs—memory bloat, validation debt, and unpatched vulnerabilities—may outweigh any speed benefits.

As he put it simply: "In the field I’m mostly interested in... code will still be written by humans. "

#AI #C++
@TheGhostITM
An Italian activist hosting provider has lost its domain, its PayPal account and its bank account after the Trump administration listed it as a global terrorist entity.

Its bank, the Italian Banca Etica, has publicly accused the Trump administration of using terrorism sanctions against political dissent.
🤬1
Cyber Dispatch™️
An Italian activist hosting provider has lost its domain, its PayPal account and its bank account after the Trump administration listed it as a global terrorist entity. Its bank, the Italian Banca Etica, has publicly accused the Trump administration of using…
The bank says Autistici/Inventati had banked normally since 2018, medium risk, no money-laundering flags. The OFAC listing alone forced the reclassification. Keeping the account open risked secondary sanctions cutting card payments for its other 130,000 customers and members.
😭1
Curating a GitHub repository of security toolkits while filtering emerging threats and vulnerability disclosures from 4 key intelligence channels.

Toolkits
Toolkits
News
Quotes

#CyberSecurity #InfoSec #ThreatIntelligence #GitHub
Attackers are chaining two critical MikroTik RouterOS bugs to take full control of any router with SSH exposed to the internet. Polish CERT has confirmed exploitation since at least 2 September.
Saudi Arabia - 𝗞𝗵𝗮𝗹𝗲𝗱 𝗔𝗹𝗳𝗮𝗴𝗶𝗵 𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝗶𝗻𝗴 𝗖𝗼𝗻𝘀𝘂𝗹𝘁𝗮𝗻𝗰𝘆 𝗖𝗼.

Panzer hacking group claims to have breached Khaled Alfagih Engineering Consultancy Co. and allegedly exfiltrated 22 GB of data. According to the exposed file listing, the dataset appears to include corporate and financial documents, project contracts, engineering files, certifications and other internal business records.
Preemptive Cyber Strike Targets Egyptian Port Authority and "Future of Egypt" Entity

A hacker group has claimed a major cyber breach of Egypt's port authority technical infrastructure, describing the operation as a "preemptive security strike" that "shook the regime's foundations."

The hackers stated they obtained a massive cache of sensitive data, including ship registrations, movement logs, and yacht authorizations. The group specifically named the "Future of Egypt Authority" (Mustaqbal Misr) and the "Armed Forces Land Projects Agency" as the entities responsible for authorizing yacht movements—pointing to a deliberate focus on military-linked economic bodies.

According to the group's statement, the stolen data includes visitor lists to Egyptian islands with names and nationalities, administrative documents, and footage from hacked security cameras inside offices.

The Future of Egypt Authority is a powerful military-affiliated economic entity that has rapidly expanded control over agriculture, land management, and food imports since its transformation by presidential decree in 2022. The hackers framed this operation as exposing corruption within the Egyptian regime.

The group concluded with a warning: "No one should test Egypt"—a nationalist narrative framing the breach as both a revelation and a threat.
GPT‑6 Astra clears all 48 levels of ‘I am not a robot’ CAPTCHA.
Adobe patches a Magento zero-day already exploited to deploy malware.

CVE-2026-75650 abuses Magento template processing for unauthenticated code execution. Attacks have delivered a Rust #Linux backdoor and PHP web shell.
Grindr will pay £26 million to settle U.K. claims that it shared users’ personal data, including HIV status, with third parties.

The case covers pre-2020 practices and includes no finding or admission of liability.
N-central’s 4th hotfix in five weeks fixes CVE-2026-86218, a CVSS 10.0 unauthenticated RCE flaw.

Hotfix 3 servers need updating. N-able’s incident notice reports exploitation; its release notes say it’s unconfirmed.
JSCeal V8 malware can bypass Google authentication using stolen browser cookies.

It can also modify Binance, Bybit, and Ledger traffic through a local proxy.
Security researchers have demonstrated a new electromagnetic attack that can recover audio playing through ordinary wired and wireless headphones, with intelligible speech captured from as far as 30 meters away.

The technique, called InjectEave, can also operate through walls and expose information from smart-home devices and landline phones.

The research was conducted by researchers from the Hong Kong University of Science and Technology (Guangzhou) and Hong Kong Polytechnic University.