Cyber Dispatch™️
398 subscribers
34 photos
2 videos
51 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch
Download Telegram
Check Point patched two critical VPN certificate flaws, CVE-2026-85102 and CVE-2026-85103, that could allow unauthenticated RCE under specific, undisclosed conditions.

Both carry CVSS 9.8 scores.
A Guardian-produced documentary at Venice reveals how Israel built AI systems to mass-generate low-ranking Hamas targets in Gaza.

Those targets were then bombed at home, at night, with full knowledge their families would die too.

The film, NAZA, features 24 Israeli military and intelligence insiders speaking anonymously.
The Iranian Revolutionary Guard sent a message to Israelis' phones saying:

"The last US radar system in the region has been destroyed. Your media and leaders are lying. Leave the country. Missiles are coming, and no shelter is safe."
Anthropic says it blocked five attempts to exploit AI models for potential bioweapons development

Artificial intelligence firm Anthropic revealed Thursday that it blocked five separate attempts to misuse its Claude models for activities that could potentially aid in the development of biological weapons.
Cyber Dispatch™️
Anthropic says it blocked five attempts to exploit AI models for potential bioweapons development Artificial intelligence firm Anthropic revealed Thursday that it blocked five separate attempts to misuse its Claude models for activities that could potentially…
The incidents involved sensitive inquiries regarding chikungunya, avian influenza, and smallpox, including a case where a military-affiliated researcher sought assistance that raised concerns about generating deadlier viral variants.

The company's report also detailed attempts to bypass platform safeguards using fraudulent accounts and virtual private networks, alongside separate queries from Yemen concerning guided rocket development.

While Anthropic cautioned that detecting such capabilities does not prove malicious intent or a guarantee of success, the findings highlight mounting security risks as advanced AI systems lower technical barriers for specialized research.
Three threat clusters exploited Cisco FMC flaws to steal credentials, deploy Cyclops Blink, and push Qilin ransomware.

Both flaws are now in CISA’s KEV catalog. Federal agencies must patch CVE-2026-20079 by September 12.
PaperCut has replaced its emergency patches for two actively exploited flaws with fully tested maintenance releases.

The flaws have been used to bypass authentication and execute arbitrary code. Versions 26.0.5, 25.0.13, and 24.1.10 include the fixes and added hardening.
A crafted Sogou Input Method link led to GRAYRABBIT malware.

China-linked UNC3569 abused Sogou’s sgbiz: handler to open a malicious page in its built-in Chromium 80 browser, then exploited CVE-2021-38003 to run code with the logged-in user’s privileges.
Attackers chained two JFrog Artifactory flaws to gain admin control and plant backdoors.

Only unupdated self-hosted servers were open to that chain. A separate critical auth bypass also drew 406,000 exploitation attempts in one day.
Kash Patel wanted FBI staff to run an influence campaign on X by replying to Epstein tweets with bureau stats.

He then asked his spokesman to reply to IfindRetards' post, saying it had gotten 277k responses.

His spokesman corrected him: it had 277k views and just 400 replies. He also warned that engaging "would look bad on you."
Universal Music Group and ElevenLabs are building an AI platform that will let fans remix, mash up and reinterpret songs from UMG artists.

It's the first major-label deal for ElevenLabs, a company known for AI voice cloning. The companies also promise "personalized vocal experiences," without saying what that means

In May, UMG announced a similar AI covers and remix feature with Spotify.
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims.

Indonesian operators distribute the malware through malicious APKs hosted outside Google Play, targeting users with phishing and social engineering messages.

After installation, the malware requests permission to use the Accessibility service, which gives it extensive control over compromised devices.
They put tracking in your OS
They put tracking in your car
They put tracking in your watch
They put tracking in your phone
They put tracking in your comms
They put tracking in your browser

@CyberDispatch
Houthis Used Claude Code to Develop Missile Guidance Software: Anthropic