Cyber Dispatch™️
398 subscribers
34 photos
2 videos
53 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch
Download Telegram
Ukrainian Hackers Claim Access to Russian Navy Secrets — The "Ukrainian Militant" group claims its "Poseidon" operation obtained classified Russian naval documents on ~70 projects, including submarines and sonar systems.
Hackers Breach Government Data — A Chinese-speaking group exploited WordPress and ZyXEL flaws to target at least 49 organizations in 29 countries, stealing over 18,500 records.
Unpatched D-Link Router Vulnerability — A critical flaw (CVE-2026-86296) in legacy DIR-822A routers has a public exploit and no patch, allowing unauthenticated remote code execution.
New Zealand Investors' Data Exposed After Breach — Investment platform Hatch reported that a cyber intrusion at US firm DriveWealth exposed customers' personal and financial data.
Anthropic and OpenAI Seek Looser Australian AI Training Rules — Both companies asked Australia to relax copyright restrictions on using content to train AI models, proposing licensing frameworks.
California Tightens Data Center Oversight — The governor signed seven new laws requiring data centers, especially AI-related ones, to disclose energy and water consumption and land use.
Cyberattack on Munich University — Ludwig Maximilian University of Munich reported an unknown hacker accessed sensitive student data, including identity, banking, and academic records.
ShinyHunters Claims FBI Breach — The ransomware group claims to have stolen data on thousands of FBI employees; Reuters verified some data but could not confirm its origin.
US-UK Defense AI Cooperation — Britain and the US launched a new partnership to develop AI-enabled defense capabilities and autonomous systems for protecting critical infrastructure.
OpenAI Urges US to Lead Global AI Standards — OpenAI called on the US to spearhead international technical standards, model evaluation metrics, and incident reporting protocols for advanced AI.
Czech President Warns of Possible Russian Cyberattack on NATO — President Petr Pavel warned of hybrid operations, including cyberattacks and sabotage, aimed at testing NATO's cohesion.
New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control.
Adobe Patches Critical Flaws in Connect, AEM Forms.
Ofcom takes a hard look at Pornhub's Apple-powered age checks.
ChatGPT advertising system reportedly tracks users across websites.
AI agents steal 600,000 credit cards in attacks on online retailers.
Cyber Dispatch™️
AI agents steal 600,000 credit cards in attacks on online retailers.
The campaign, active since at least July 2026, has reportedly stolen more than 600,000 unexpired payment card records, deployed web skimmers, and accessed systems belonging to major retailers, travel companies, and industrial firms.
Android 17 enables certificate transparency, and breaks custom CAs.
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks.
Attackers are exploiting WordPress CVE-2026-87902 within hours of disclosure.

The attacks use pearcmd.php to write attacker-controlled PHP files to disk, but only when specific theme and server conditions are met.
Compromised MemTensor packages are pushing the sckit credential stealer through npm and PyPI.

The Go-based malware targets developer and cloud secrets, launching on memory recall in the npm plugin or as soon as the PyPI module is imported.