Cyber Dispatch™️
398 subscribers
34 photos
2 videos
51 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch
Download Telegram
Israel Top Target for Hacktivists Worldwide

· Israel hit with 16% of all hacktivist campaigns in H1 2026
· Over 1000 attacks claims recorded against Israel
· 85% of attacks by Pro-Palestine, pro-Russia and anti-Western groups

#TGITM @TheGhostITM
UAE Warns AI Is Making Cyberattacks More Complex

· AI makes attacks harder to trace and attribute
· Threats now include cybercrime and cyberwar
· Social media exploitation also rising
French Tax Authority Hacker Arrested

· 18-year-old suspected member of ZeroBytes group arrested
· Group claimed theft of data from over 600,000 people
· Stolen data includes names, tax IDs, emails, and financial info
Saudi Arabia Launches New Cyber Inspections

· Inspections target government, private, and critical infrastructure
· Aim to boost compliance and identify violations
· Focus on protecting critical infrastructure and government services
Baku to Host First International Ethical Hacking Conference

· CyberHackCon 2026 set for October 27 in Baku
· Focus on offensive security, critical infrastructure, AI threats
· Over 20 international speakers confirmed
Hackers Stealing Claude AI Tokens

· Attackers steal session data to hijack users' Claude accounts
· Victims report unusual token consumption with no activity
· OAuth keys used to create Claude Code sessions on victims' accounts
Boston Scientific Hit by Cyberattack

· Attack disrupts production, orders, and shipments
· Company may miss Q3 and full-year 2026 financial forecasts
· Significant impact on financial performance expected
Attackers are turning breach secrecy into leverage.

Bitdefender says some offer clean recovery and confidentiality for payment. Meanwhile, 55.2% of IT/security pros who experienced a breach or incident said they were asked to keep a breach quiet even when it should have been disclosed.
Stolen AI session tokens can bypass passwords and MFA.

In one 7 GB infostealer dump, Okta found 555 JWTs likely tied to AI authentication and 24 still-valid API keys for AI services.
Take your internet-exposed Alby Bitcoin wallet off the public internet first.

A critical flaw in Alby Hub v1.7.0–v1.18.5 could let attackers take over wallets that were reachable from the internet.
Google patched a new actively exploited Chrome V8 zero-day.

CVE-2026-87491 lets crafted HTML execute arbitrary code inside Chrome’s sandbox. Google has not said how it’s being weaponized or who is behind it.
New CVE-2026-67401 vulnerability in cPanel lets mail-privileged hosting accounts execute code as root.

cPanel says every supported cPanel & WHM version is affected and has released fixed builds.
Malware linked to F5 BIG-IP APM break-ins hides a PHP web shell in memory while targeted scripts can remain clean on disk.

Sophos found the implant alters what PHP sees when Apache loads those files, helping explain why file checks can miss it.
N-able says CVE-2026-86218 is being exploited in the wild. The CVSS 10.0 N-central flaw can enable pre-auth RCE.

CISA added it to KEV, while Huntress is probing a separate N-central compromise where the exploit used remains unconfirmed.
Check Point patched two critical VPN certificate flaws, CVE-2026-85102 and CVE-2026-85103, that could allow unauthenticated RCE under specific, undisclosed conditions.

Both carry CVSS 9.8 scores.
A Guardian-produced documentary at Venice reveals how Israel built AI systems to mass-generate low-ranking Hamas targets in Gaza.

Those targets were then bombed at home, at night, with full knowledge their families would die too.

The film, NAZA, features 24 Israeli military and intelligence insiders speaking anonymously.
The Iranian Revolutionary Guard sent a message to Israelis' phones saying:

"The last US radar system in the region has been destroyed. Your media and leaders are lying. Leave the country. Missiles are coming, and no shelter is safe."
Anthropic says it blocked five attempts to exploit AI models for potential bioweapons development

Artificial intelligence firm Anthropic revealed Thursday that it blocked five separate attempts to misuse its Claude models for activities that could potentially aid in the development of biological weapons.
Cyber Dispatch™️
Anthropic says it blocked five attempts to exploit AI models for potential bioweapons development Artificial intelligence firm Anthropic revealed Thursday that it blocked five separate attempts to misuse its Claude models for activities that could potentially…
The incidents involved sensitive inquiries regarding chikungunya, avian influenza, and smallpox, including a case where a military-affiliated researcher sought assistance that raised concerns about generating deadlier viral variants.

The company's report also detailed attempts to bypass platform safeguards using fraudulent accounts and virtual private networks, alongside separate queries from Yemen concerning guided rocket development.

While Anthropic cautioned that detecting such capabilities does not prove malicious intent or a guarantee of success, the findings highlight mounting security risks as advanced AI systems lower technical barriers for specialized research.
Three threat clusters exploited Cisco FMC flaws to steal credentials, deploy Cyclops Blink, and push Qilin ransomware.

Both flaws are now in CISA’s KEV catalog. Federal agencies must patch CVE-2026-20079 by September 12.
PaperCut has replaced its emergency patches for two actively exploited flaws with fully tested maintenance releases.

The flaws have been used to bypass authentication and execute arbitrary code. Versions 26.0.5, 25.0.13, and 24.1.10 include the fixes and added hardening.