Cyber Dispatch™️
402 subscribers
34 photos
2 videos
53 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch
Download Telegram
Anthropic: AI Misuse Is Entering a New Phase: From Cybercrime to Surveillance, Propaganda and Weapons.
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent.
FBI cyber leader details bureau’s first unclassified cyber strategy.
Mexico seizes cartel-linked crypto mining farm

Police found a hidden crypto mining farm in Sierra Norte de Puebla, seizing about 300 GPUs, power equipment, and 8 satellite antennas, with suspected electricity theft and drug cartel links.
UNESCO unveils new AI governance tools

At the 4th Global Forum on Ethics of AI in Riyadh, UNESCO launched tools including RAM 2.0 to assess countries’ AI readiness and a toolkit for AI’s environmental impact.
UK and U.S. cooperate on AI and fusion energy

At the Global Fusion Summit in London, the two countries signed agreements, including one between UKAEA and Princeton Plasma Physics Lab to combine AI, supercomputing, and fusion research.
Google hires Israeli chip team to develop AI chip

Google has formed a team in Israel, led by former Hailo CEO Guy Kaminitz and including a former Nvidia manager, to build on-device AI chips for robots and autonomous systems.

#TGITM
Windows hit via Tencent software flaw

A critical vulnerability in Tencent’s Sogou Input Method was actively exploited for one-click malware execution, installing GrayRabbit malware; Tencent fixed it in version 16.3.0.3498, but its embedded browser engine remains outdated.
NSA undergoes major reorganization into five mission centers

The NSA is restructuring into five mission centers covering China, cybersecurity, AI, combat support, and global intelligence, aiming to speed intelligence delivery to military forces by January.
EU mandates 24-hour disclosure of crypto wallet vulnerabilities

Under the Cyber Resilience Act, crypto wallet makers must report exploited vulnerabilities to ENISA and CSIRTs within 24 hours, with full reports in 72 hours and final reports in 14 days.
South Korea enacts new law against strategic technology espionage

The new law expands espionage crimes from North Korea to all foreign countries, imposing at least 3 years in prison and targeting chips, displays, batteries, and AI technologies.
BRICS agrees on Delhi Declaration

BRICS members approved the Delhi Declaration at their 18th summit, stressing stronger cooperation, global governance reform, and joint work on cybersecurity, digital infrastructure, AI, digital public infrastructure, and submarine cables.
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users.
Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution.
Nintendo warns of Switch code execution flaw via on-screen QR codes.
ClickFix attacks infecting PCs and Macs are going viral.
Thai ISP 3BB attacker had root access and hid MeshCentral for persistence.

Recovered tools sprayed passwords across 55+ internal systems and targeted subscriber login databases.
Attackers are exploiting a Cisco Secure Email Gateway vulnerability that can let a crafted email trigger command execution as root.

Cisco has released fixes, and CISA added CVE-2026-76461 to its KEV catalog.
A human attacker exploited Marimo’s pre-auth RCE and reached an SSH bastion in eight seconds.

The operator used harvested AWS credentials to fetch the private key from Secrets Manager and authenticate over SSH. No AI agent was involved.
Warning: LiteSpeed Enterprise before 6.3.7 can let low-privilege website users gain root on shared-hosting servers.

It can bypass CageFS isolation. No CVE is assigned, exploitation is unknown, and 6.3.7 may not auto-update immediately.
Exposed Vite dev servers are being scanned for cloud credentials.

Attackers are exploiting a Vite flaw to bypass file restrictions and retrieve .env files, AWS and Azure credentials, and infrastructure state.