Cyber Dispatch™️
398 subscribers
34 photos
2 videos
53 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch
Download Telegram
Attackers are exploiting flaws in Zyxel GS1900 switches and Veeam Agent for Windows.

Zyxel’s bug can run OS commands from the LAN without authentication. Veeam’s can give a local attacker SYSTEM control.
Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto.
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR.
Garrity’s Anthropic CVE tracker maintains a list of vulnerabilities credited to the Anthropic team and/or Project Glasswing and also checks these CVEs against the company's known exploited vulnerabilities index "to get a better read on the real Glasswing ‘danger factor.’"

As of Monday, the CVE count is 225, and just one, a critical SQL injection bug in Ghost (CVE-2026-26980), has been exploited in the wild.
AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft.
US Investigation Into Binance Over Iran-Linked Transactions — Federal prosecutors are examining whether Binance failed to prevent transactions linked to Iran, potentially violating US sanctions.
DeepSeek to Report on AI Risks at UN Security Council — The Chinese AI startup will brief the UN Security Council on AI dangers and security implications, alongside OpenAI and Anthropic.
Banks Worried About AI-Driven Shopping Security — International banks warn that AI agents used for online purchases could increase fraud, scams, and privacy violations.
American Concerns Over AI Safety — A Reuters/Ipsos poll found 73% of Americans believe AI companies are not doing enough to prevent serious harm from the technology.
Cyberattacks on US Energy Ships Continue — A US LNG carrier bound for Italy was diverted to Spain after control and monitoring system disruptions, marking the third such cyber incident in recent weeks.
Ukrainian Hackers Claim Access to Russian Navy Secrets — The "Ukrainian Militant" group claims its "Poseidon" operation obtained classified Russian naval documents on ~70 projects, including submarines and sonar systems.
Hackers Breach Government Data — A Chinese-speaking group exploited WordPress and ZyXEL flaws to target at least 49 organizations in 29 countries, stealing over 18,500 records.
Unpatched D-Link Router Vulnerability — A critical flaw (CVE-2026-86296) in legacy DIR-822A routers has a public exploit and no patch, allowing unauthenticated remote code execution.
New Zealand Investors' Data Exposed After Breach — Investment platform Hatch reported that a cyber intrusion at US firm DriveWealth exposed customers' personal and financial data.
Anthropic and OpenAI Seek Looser Australian AI Training Rules — Both companies asked Australia to relax copyright restrictions on using content to train AI models, proposing licensing frameworks.
California Tightens Data Center Oversight — The governor signed seven new laws requiring data centers, especially AI-related ones, to disclose energy and water consumption and land use.
Cyberattack on Munich University — Ludwig Maximilian University of Munich reported an unknown hacker accessed sensitive student data, including identity, banking, and academic records.
ShinyHunters Claims FBI Breach — The ransomware group claims to have stolen data on thousands of FBI employees; Reuters verified some data but could not confirm its origin.
US-UK Defense AI Cooperation — Britain and the US launched a new partnership to develop AI-enabled defense capabilities and autonomous systems for protecting critical infrastructure.
OpenAI Urges US to Lead Global AI Standards — OpenAI called on the US to spearhead international technical standards, model evaluation metrics, and incident reporting protocols for advanced AI.
Czech President Warns of Possible Russian Cyberattack on NATO — President Petr Pavel warned of hybrid operations, including cyberattacks and sabotage, aimed at testing NATO's cohesion.