Cyber Dispatch™️
402 subscribers
34 photos
2 videos
53 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch
Download Telegram
Jump Jump VPN User Data Allegedly Leaked — A 1.2GB dataset reportedly includes names, phone numbers, national IDs, payments, sessions, device details, and logs.
Israel Expands Cyber Influence in Latin America — Colombia, Ecuador, and Argentina pursue cooperation on surveillance, AI, and cybersecurity, raising privacy concerns.

#TGITM
Telegram Desktop Flaw Could Have Exposed Messages — Malicious JavaScript in bot buttons could run from exported HTML chats; patched after affecting versions 4.15.1–6.9.3.
Cisco Warns of Actively Exploited Zero-Day in Secure Email Gateway — CVE-2026-76461 allows unauthenticated root command execution via a crafted email; CISA sets a Sept. 17 deadline.
Israeli cyber firm blamed for AI hacking breaches at Anthropic, OpenAI and Meta

Cybersecurity breaches involving AI models developed by Anthropic, OpenAI and Meta resulted from flawed testing environments managed by Tel Aviv-based contractor Irregular rather than rogue autonomous behavior, according to an investigation by US publication Effort.
Cyber Dispatch™️
Israeli cyber firm blamed for AI hacking breaches at Anthropic, OpenAI and Meta Cybersecurity breaches involving AI models developed by Anthropic, OpenAI and Meta resulted from flawed testing environments managed by Tel Aviv-based contractor Irregular rather…
The investigation found that Irregular left internet connections active during simulated cybersecurity exercises, allowing AI models to access external servers, publish malicious packages and exploit vulnerabilities.

Evaluators also told the models that internet access was disabled while configuration errors left public networks accessible, and failed to establish clear boundaries defining which systems could be targeted.
Cyber Dispatch™️
The investigation found that Irregular left internet connections active during simulated cybersecurity exercises, allowing AI models to access external servers, publish malicious packages and exploit vulnerabilities. Evaluators also told the models that internet…
Some model instances were consequently able to scan external networks for up to 34 hours. “According to their own findings, Anthropic and Irregular bear all of the responsibility for the cybersecurity incidents they caused,” Effort said.

Effort found that the hacking stopped entirely after engineers instructed the models not to conduct real-world attacks, pointing instead to basic security failures and poorly controlled testing environments.
Attackers are exploiting a critical WooCommerce Wholesale Lead Capture flaw to plant PHP web shells.

Wordfence has blocked over 100,000 exploit attempts since June against CVE-2026-27540, which affects versions through 2.0.3.1.
Forged admin JWTs are being used in WSO2 API Manager exploitation attempts.

CVE-2026-5430 lets unsupported JWT algorithms bypass authentication and can lead to account takeover. Fixes are available.
KREMLIN banking malware bypasses Chromium integrity checks to install a Chrome and Edge extension that steals credentials and session tokens.

It also uses Ethereum smart contracts to rotate C2 and payload locations.
A joint U.S.-U.K.-Dutch advisory says a Windows malware campaign tracked as HEAVYGRAM, also known as CHOSEN BRICK, uses Telegram bots to spy on dissidents and journalists. According to the advisory, the malware can steal messages and passwords, record audio, capture screenshots, and exfiltrate files. The advisory links the activity to a state-linked actor, but the attribution has not been independently confirmed.
ByteDance founder Zhang Yiming is now Asia's richest person on the Bloomberg Billionaires Index, surpassing Gautam Adani.

Both around $105 billion but Zhang ranks higher.
Cyber Dispatch™️
ByteDance founder Zhang Yiming is now Asia's richest person on the Bloomberg Billionaires Index, surpassing Gautam Adani. Both around $105 billion but Zhang ranks higher.
His wealth jumped $12 billion this month after Bloomberg updated ByteDance's private valuation using BlackRock/Fidelity filings and cut its risk discount from 25% to 10% following TikTok's US resolution (Oracle/Silver Lake JV).

ByteDance's AI products (Doubao chatbot, Seedance video model) also boosted investor interest.

Zhang's fortune has grown 8x since 2019.
ISRAEL has taken over iPhone.

New iPhones will have an Israeli chip inside of them, the CX1 and all of your wireless data will pass through them.
Cyber Dispatch™️
ISRAEL has taken over iPhone. New iPhones will have an Israeli chip inside of them, the CX1 and all of your wireless data will pass through them.
C1X = cellular modem (Sub-6GHz 5G, no mmWave). N1 = Wi-Fi 7, Bluetooth 6, Thread. Both are Apple-designed.

Design: Developed with Apple's R&D center in Israel (Herzliya/Haifa).
Cyber Dispatch™️
C1X = cellular modem (Sub-6GHz 5G, no mmWave). N1 = Wi-Fi 7, Bluetooth 6, Thread. Both are Apple-designed. Design: Developed with Apple's R&D center in Israel (Herzliya/Haifa).
The Apple-Israel chip connection, by model:

· iPhone 17e / iPad Air → C1X modem + N1 wireless chip. Both developed "in close cooperation with engineers from Apple's development center in Israel".
· iPhone 18 Pro / Pro Max / Duo → C2 modem + N1 chip. Apple's Israeli R&D teams (Herzliya, Haifa) contributed to the C-series modem platform.
U.S. seizes two NightmareStresser domains tied to hundreds of thousands of DDoS attacks and attempts.

The DDoS-for-hire service was assessed to have been used worldwide since 2022.
Attackers are exploiting a critical Issabel Framework flaw.

CVE-2026-89026 uses a hard-coded JWT signing key, letting unauthenticated remote attackers forge tokens and execute OS commands as the Asterisk user. A fix is available.
From compromised VPN credentials to MQTT and Matrix C2, three threat groups are targeting Russian enterprises.

NightEagle uses GhostContainer, Toy Ghouls now fields a custom backdoor, and Kaspersky links Hacking Cat to Gorilla RAT and destructive malware.
Azerbaijan hosts cybersecurity meeting for NGOs — Experts shared practical advice on data protection, phishing, social engineering, suspicious files, and regular backups.
From “APT smartification” to “smart APT” — An analysis argues cyber defense must move beyond tools to AI-driven governance, risk management, monitoring, and automated response.