Cyber Dispatch™️
399 subscribers
34 photos
2 videos
53 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch
Download Telegram
Four Linux kernel flaws now have public working exploits for local root.

DirtyAH6, TUNderflow, and PPPoEject require unprivileged user namespaces for an ordinary user. DiagSpill needs SCTP available but no special privileges.
New WordPress "Click2Shell" vulnerability can force a silent theme install from a crafted link.

Researchers chained the flaw with a separate theme bug to execute code on the server.
Transparent Tribe is targeting government and defense entities in India and Afghanistan with a new Rust backdoor.

RUSTYSHADE uses private GitHub repos for encrypted C2, while post-compromise activity includes Windows and Linux file stealers.
Azure AI Foundry flaw lets unauthorized attackers elevate privileges over the network.

The CVSS 10.0 issue stems from missing authentication for a critical function. Microsoft says it is fully mitigated, with no evidence of exploitation.
Critical Check Point management flaw lets unauthenticated attackers run code as root.

The 9.8-rated bug (CVE-2026-91843) sits in the login path before authentication.
Critical Docker Sandboxes flaw lets malicious guest code escape the shared workspace and read or modify files across a macOS host.

CVE-2026-77179 crosses the virtio-fs boundary with the host account’s rights.
UAE and Saudi Arabia made up nearly half of Gulf cyberattacks in H1 2026. UAE 35%, Iran 17%, Saudi 15%. Top methods: vulnerabilities 38%, malware 31%, social engineering 27%. Government orgs were 27% of successful targets.
Turkiye busts Israel-linked 'Scam Empire' accused of defrauding victims out of $266 million

Turkish security forces have dismantled an Israel-linked fraudulent trading network accused of defrauding victims across Europe, Asia, and Africa of at least $266 million over the past two years, Turkish Justice Minister Akin Gurlek said on Friday.
Cyber Dispatch™️
Turkiye busts Israel-linked 'Scam Empire' accused of defrauding victims out of $266 million Turkish security forces have dismantled an Israel-linked fraudulent trading network accused of defrauding victims across Europe, Asia, and Africa of at least $266…
The investigation targeted 42 call centers operated by 28 companies and involving 239 suspects, with coordinated dawn raids conducted at 236 locations in Istanbul and Mugla alongside Turkiye’s National Intelligence Organization (MIT) and Interpol, Middle East Eye reported.

Gurlek said investigators identified individuals linked to Israel as the companies’ principal owners and ultimate beneficiaries. The operation was connected to the international criminal network known as "Scam Empire," which allegedly used multilingual call center agents, fabricated investment profits, and overseas bank accounts and cryptocurrency wallets to defraud victims.
Cyber Dispatch™️
The investigation targeted 42 call centers operated by 28 companies and involving 239 suspects, with coordinated dawn raids conducted at 236 locations in Istanbul and Mugla alongside Turkiye’s National Intelligence Organization (MIT) and Interpol, Middle East…
Turkish officials said one alleged mastermind, identified by the initials YA, is an Israeli national who also holds Portuguese citizenship.

Turkish officials said some Israel-based fraud networks had moved operations to Turkiye to avoid detection amid worsening tensions between Ankara and Tel Aviv. According to the investigation, employees were allegedly trained to use false identities and fabricated personal backgrounds to gain victims’ trust, while Israeli citizens were reportedly prohibited from being targeted.

The Organized Crime and Corruption Reporting Project (OCCRP) has previously documented similar investment fraud operations involving call centers in Israel, Eastern Europe, and Georgia.
A hard-coded static key in SolarWinds ARM can enable unauthenticated RCE.

CVE-2026-28326 affects ARM 2026.2 and earlier and is fixed in 2026.2.1. SolarWinds did not report in-the-wild exploitation.
Attackers are exploiting a critical Orkes Conductor RCE without authentication.

Nearly 7,000 attack attempts were blocked from Sept. 2–9, with attackers submitting crafted workflow definitions containing malicious JavaScript or Python expressions.
Three Linux kernel flaws are being exploited.

One can enable local privilege escalation. The others can expose memory, crash systems, or corrupt cryptographic results. All three are now in CISA’s KEV catalog.
Nvidia CEO Jensen Huang: I’m not afraid of paying taxes. I’m just afraid of being poor.
BragJack attacks hijack AI browser agents through malicious extensions.
North Korean WaterPlum hackers infected 30,000 devices worldwide.
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang.
Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up.
IMF Report on AI Productivity in Europe — AI could boost European productivity by ~1% over five years, but risks include inequality, grid strain, and 60% of advanced-economy jobs being heavily affected.
Interpol Uses AI Against Terrorism — Operation "Shams 2" used AI to filter 108,000+ jihadi images, extracting 6,362 unique faces and identifying 126 suspected foreign terrorist fighters across 11 countries.
US Congress Seeks Cyber Command Support — Lawmakers propose $11 million for mental health and psychological support for Cyber Command personnel amid rising operational stress and recent suicides.