Oracle reportedly cuts thousands of jobs while increasing AI investment — Headcount fell by about 21,000 in the last fiscal year as quarterly capex rose from $8.5B to $28.5B for AI infrastructure.
Cyber Dispatch™️
Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts.
As Microsoft explained, this affects all supported Windows client and server versions, including the latest Windows 11 26H1 and Windows Server 2025 releases, and it triggers erroneous alerts in the Windows Security app that prompt users to "Tap or click to turn on Microsoft Defender Antivirus."
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage.
Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE.
Cyber Dispatch™️
Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE.
HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading, file cleanup, and persistence via Windows autorun registry keys.
Cyber Dispatch™️
HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading, file cleanup, and persistence via Windows autorun registry…
The attacks typically involve the use of social engineering via messaging platforms like Telegram, WhatsApp, and Instagram to communicate with targets under the pretext of offering technical support or posing as trusted contacts, and then deliver malware dressed up as a seemingly harmless installer to trigger the infection. These applications masquerade as legitimate applications like Pictory, KeePass, and Telegram, and contain the second-stage implant.
Cyber Dispatch™️
The attacks typically involve the use of social engineering via messaging platforms like Telegram, WhatsApp, and Instagram to communicate with targets under the pretext of offering technical support or posing as trusted contacts, and then deliver malware dressed…
A notable aspect of the Python-based malware is its use of Telegram for command-and-control (C2), allowing it to list running programs, take screenshots, capture web browser data, upload/download files, turn on the microphone, copy Telegram and WhatsApp data, steal saved passwords, download additional malware, and delete files.
CVE-2026-90999: A fabricated Sentry bug report can make Seer's coding agent run attacker code.
OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training.
Four Linux kernel flaws now have public working exploits for local root.
DirtyAH6, TUNderflow, and PPPoEject require unprivileged user namespaces for an ordinary user. DiagSpill needs SCTP available but no special privileges.
DirtyAH6, TUNderflow, and PPPoEject require unprivileged user namespaces for an ordinary user. DiagSpill needs SCTP available but no special privileges.
New WordPress "Click2Shell" vulnerability can force a silent theme install from a crafted link.
Researchers chained the flaw with a separate theme bug to execute code on the server.
Researchers chained the flaw with a separate theme bug to execute code on the server.
Transparent Tribe is targeting government and defense entities in India and Afghanistan with a new Rust backdoor.
RUSTYSHADE uses private GitHub repos for encrypted C2, while post-compromise activity includes Windows and Linux file stealers.
RUSTYSHADE uses private GitHub repos for encrypted C2, while post-compromise activity includes Windows and Linux file stealers.
Azure AI Foundry flaw lets unauthorized attackers elevate privileges over the network.
The CVSS 10.0 issue stems from missing authentication for a critical function. Microsoft says it is fully mitigated, with no evidence of exploitation.
The CVSS 10.0 issue stems from missing authentication for a critical function. Microsoft says it is fully mitigated, with no evidence of exploitation.
Critical Check Point management flaw lets unauthenticated attackers run code as root.
The 9.8-rated bug (CVE-2026-91843) sits in the login path before authentication.
The 9.8-rated bug (CVE-2026-91843) sits in the login path before authentication.
Critical Docker Sandboxes flaw lets malicious guest code escape the shared workspace and read or modify files across a macOS host.
CVE-2026-77179 crosses the virtio-fs boundary with the host account’s rights.
CVE-2026-77179 crosses the virtio-fs boundary with the host account’s rights.
UAE and Saudi Arabia made up nearly half of Gulf cyberattacks in H1 2026. UAE 35%, Iran 17%, Saudi 15%. Top methods: vulnerabilities 38%, malware 31%, social engineering 27%. Government orgs were 27% of successful targets.
Turkiye busts Israel-linked 'Scam Empire' accused of defrauding victims out of $266 million
Turkish security forces have dismantled an Israel-linked fraudulent trading network accused of defrauding victims across Europe, Asia, and Africa of at least $266 million over the past two years, Turkish Justice Minister Akin Gurlek said on Friday.
Turkish security forces have dismantled an Israel-linked fraudulent trading network accused of defrauding victims across Europe, Asia, and Africa of at least $266 million over the past two years, Turkish Justice Minister Akin Gurlek said on Friday.
Cyber Dispatch™️
Turkiye busts Israel-linked 'Scam Empire' accused of defrauding victims out of $266 million Turkish security forces have dismantled an Israel-linked fraudulent trading network accused of defrauding victims across Europe, Asia, and Africa of at least $266…
The investigation targeted 42 call centers operated by 28 companies and involving 239 suspects, with coordinated dawn raids conducted at 236 locations in Istanbul and Mugla alongside Turkiye’s National Intelligence Organization (MIT) and Interpol, Middle East Eye reported.
Gurlek said investigators identified individuals linked to Israel as the companies’ principal owners and ultimate beneficiaries. The operation was connected to the international criminal network known as "Scam Empire," which allegedly used multilingual call center agents, fabricated investment profits, and overseas bank accounts and cryptocurrency wallets to defraud victims.
Gurlek said investigators identified individuals linked to Israel as the companies’ principal owners and ultimate beneficiaries. The operation was connected to the international criminal network known as "Scam Empire," which allegedly used multilingual call center agents, fabricated investment profits, and overseas bank accounts and cryptocurrency wallets to defraud victims.