Cyber Dispatch™️
402 subscribers
34 photos
2 videos
53 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch
Download Telegram
BRICS agrees on Delhi Declaration

BRICS members approved the Delhi Declaration at their 18th summit, stressing stronger cooperation, global governance reform, and joint work on cybersecurity, digital infrastructure, AI, digital public infrastructure, and submarine cables.
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users.
Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution.
Nintendo warns of Switch code execution flaw via on-screen QR codes.
ClickFix attacks infecting PCs and Macs are going viral.
Thai ISP 3BB attacker had root access and hid MeshCentral for persistence.

Recovered tools sprayed passwords across 55+ internal systems and targeted subscriber login databases.
Attackers are exploiting a Cisco Secure Email Gateway vulnerability that can let a crafted email trigger command execution as root.

Cisco has released fixes, and CISA added CVE-2026-76461 to its KEV catalog.
A human attacker exploited Marimo’s pre-auth RCE and reached an SSH bastion in eight seconds.

The operator used harvested AWS credentials to fetch the private key from Secrets Manager and authenticate over SSH. No AI agent was involved.
Warning: LiteSpeed Enterprise before 6.3.7 can let low-privilege website users gain root on shared-hosting servers.

It can bypass CageFS isolation. No CVE is assigned, exploitation is unknown, and 6.3.7 may not auto-update immediately.
Exposed Vite dev servers are being scanned for cloud credentials.

Attackers are exploiting a Vite flaw to bypass file restrictions and retrieve .env files, AWS and Azure credentials, and infrastructure state.
Eclipse Ransomware Group Claims Attacks in France and US — The group says it stole about 60GB from French firm Rosello et Fils; the claims remain unverified.
Ukraine-Linked Hackers Use New Malware Against Russian Targets — Kaspersky links “Hacking Cat” to Gorilla RAT and Monkey malware for remote access and data destruction
Revolut Hit by Customer Data Leak via Fake Government Requests — The UK fintech says personal and ID data was exposed after spoofed emails from a trusted government domain.
China Calls Anthropic’s AI Slowdown Plea a Cold War Tactic — Global Times accuses the US of trying to limit China’s AI progress; Trump vows to keep America ahead.
150+ cybersecurity giants—Microsoft, Google, OpenAI, Anthropic—warn AI is supercharging cyberattacks.

Palo Alto’s Unit 42 simulated a full ransomware attack in just 25 minutes using AI: a 100x speed increase.

Zero-day production is now 100x faster than humans alone.
Amazon says its cloud infrastructure in Bahrain and the UAE is beyond saving after missile strikes. The Gulf is now rebuilding AI data centers with war-proofing: underground sites, missile interceptors, dispersal, hardened power. The cloud is no longer just IT. It’s a target.
Jump Jump VPN User Data Allegedly Leaked — A 1.2GB dataset reportedly includes names, phone numbers, national IDs, payments, sessions, device details, and logs.
Israel Expands Cyber Influence in Latin America — Colombia, Ecuador, and Argentina pursue cooperation on surveillance, AI, and cybersecurity, raising privacy concerns.

#TGITM
Telegram Desktop Flaw Could Have Exposed Messages — Malicious JavaScript in bot buttons could run from exported HTML chats; patched after affecting versions 4.15.1–6.9.3.
Cisco Warns of Actively Exploited Zero-Day in Secure Email Gateway — CVE-2026-76461 allows unauthenticated root command execution via a crafted email; CISA sets a Sept. 17 deadline.
Israeli cyber firm blamed for AI hacking breaches at Anthropic, OpenAI and Meta

Cybersecurity breaches involving AI models developed by Anthropic, OpenAI and Meta resulted from flawed testing environments managed by Tel Aviv-based contractor Irregular rather than rogue autonomous behavior, according to an investigation by US publication Effort.