Cyber Dispatch™️
399 subscribers
34 photos
2 videos
53 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch
Download Telegram
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks.
Attackers are exploiting WordPress CVE-2026-87902 within hours of disclosure.

The attacks use pearcmd.php to write attacker-controlled PHP files to disk, but only when specific theme and server conditions are met.
Compromised MemTensor packages are pushing the sckit credential stealer through npm and PyPI.

The Go-based malware targets developer and cloud secrets, launching on memory recall in the npm plugin or as soon as the PyPI module is imported.
A new cPanel flaw, CVE-2026-87899, in CalDAV/CardDAV lets any logged-in cPanel account run code as root and take full control of the server.

A second flaw, CVE-2026-87900 in WP Toolkit, lets authenticated users modify databases belonging to other accounts.
Three Chrome-Windows 0-days were exploited in one chain to escape Chrome’s sandbox and achieve remote code execution.

Chinese threat actor UTA0565 used fake sites in the attacks, with the chain ultimately deploying CLEANGULP malware.
F5’s BIG-IP APM 0-day is being exploited for unauthenticated RCE.

CVE-2026-94127 affects systems where APM acts as an OAuth authorization server. F5 has released hotfixes, and CISA added the flaw to KEV.
Next.js patched a critical ImageResponse flaw that can lead to server code execution.

"CVE-2026-94545" affects 16.2.0 through 16.3.5 on Node.js when attacker-controlled values reach generated SVG. The fix is 16.3.6.
ShinyHunters says it breached the FBI and stole data on agents and job applicants.

The FBI says it is investigating claims of unauthorized activity affecting FBIjobs[.]gov.

ShinyHunters also claims a PeopleSoft zero-day was used, but no public technical details of the flaw are available.
Check Point is warning customers about a newly disclosed Security Management Server zero-day exploited in targeted attacks in July.

CVE-2026-93616 lets an attacker who can reach the web service upload and run scripts without logging in. A fix landed Sept. 22.
Spanish PM Pedro Sánchez on AI:

The paradox is that we have these techno oligarchs investing in a technology that many of their workers say could kill and end humanity. And at the same time, these technical oligarchs are investing massively in immortality.

I think that what we need is serious regulation, responsible development of AI, and not bunkers and Mars missions for saving the techno oligarchs.
Cyber Dispatch™️
Spanish PM Pedro Sánchez on AI: The paradox is that we have these techno oligarchs investing in a technology that many of their workers say could kill and end humanity. And at the same time, these technical oligarchs are investing massively in immortality.…
Spanish PM Pedro Sánchez:

The situation of the far right is not coming from a specific content but from a specific tool, which is social media and the algorithm.

Because it is poisoning the public debate. It is contributing to dehumanize many political actors. I’m also a victim of it.
WordPress issues patch a new critical flaw (CVE-2026-87902) that requires no account and can lead to code execution on some servers.

Versions 4.7.0 through 7.1.1 are affected.
Russian drone/missile strike on Kyiv hit multiple data centers, knocking out internet for ~100,000 households.

ISPs UTELS, Pavutina, Crazy Network, and Etherlink all reported major node damage.

Hosting providers Cityhost and MiroHost lost Kyiv-based equipment, with MiroHost's local facility destroyed entirely (95% of clients unaffected on foreign servers).
Cyber Dispatch™️
Russian drone/missile strike on Kyiv hit multiple data centers, knocking out internet for ~100,000 households. ISPs UTELS, Pavutina, Crazy Network, and Etherlink all reported major node damage. Hosting providers Cityhost and MiroHost lost Kyiv-based equipment…
Providers are warning of significant price increases, saying current ~300-350 UAH rates are no longer viable given the cost of maintaining resilient infrastructure under constant attack.

Russia claimed the sites supported military communications.
A fake Cloudflare check ended with Vidar Stealer running inside a signed Microsoft process.

Researchers mapped 17,000+ infected URLs. About 3,000 still served ClickFix lures, while Polygon smart contracts let operators swap lure hosts without touching the compromised sites.
Microsoft plans $10 billion-plus Gulf investment through 2030

Microsoft plans to invest more than $10 billion across the United Arab Emirates, Saudi Arabia, Qatar and Kuwait between now and 2030, including spending on cloud and artificial intelligence infrastructure, a senior executive said on Wednesday.
Cyber Dispatch™️
Microsoft plans $10 billion-plus Gulf investment through 2030 Microsoft plans to invest more than $10 billion across the United Arab Emirates, Saudi Arabia, Qatar and Kuwait between now and 2030, including spending on cloud and artificial intelligence infrastructure…
The US technology company is making 'digital resilience' a central part of its regional strategy during the ongoing US-Israeli war on Iran. Vice Chair and President Brad Smith told Reuters that the investment reflects Microsoft's "ongoing build-out of infrastructure and also the expansion of operations in the region."

"We're sustaining all the investments we planned to make before this conflict started, and we're in fact adding to them ... It's an aggressive spending schedule," Smith said.
Cyber Dispatch™️
The US technology company is making 'digital resilience' a central part of its regional strategy during the ongoing US-Israeli war on Iran. Vice Chair and President Brad Smith told Reuters that the investment reflects Microsoft's "ongoing build-out of infrastructure…
Microsoft is also working with Gulf governments on preparedness and the protection of critical data through a digital resilience initiative.

The company also plans to invest more than $400 million in subsea and terrestrial connectivity infrastructure across West Asia by 2030. Microsoft is further expanding partnerships with national AI companies, including Abu Dhabi-based G42, in which it invested $1.5 billion for a minority stake in 2024, securing a board seat currently held by Smith. It is also working with Saudi Arabia's Humain and Qatar's Qai "in selected areas that are priorities for them," although Smith said Microsoft does not plan to make capital investments in those companies.
The US is again deploying large numbers of strategic tankers and C-17 transport aircraft to West Asia, with several flights tracked landing in Israel as a new US air bridge forms amid preparations for a potential large-scale attack on Iran, according to Flightradar24 data,
Ed Sheeran has lost nearly 500,000 Instagram followers in the past week, according to Social Blade, amid backlash over Macklemore’s removal from his Loop Tour following pro-Palestine remarks and a performance of “Hind’s Hall.”