Cyber Dispatch™️
403 subscribers
34 photos
4 videos
56 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch
Download Telegram
Cisco says attackers are exploiting a critical SD-WAN Manager authentication bypass.

CVE-2026-76504 lets a remote attacker access the Manager API as admin without credentials. Cisco has fixes, no workaround, and log checks for suspicious activity.
Attackers are abusing ChatGPT Custom GPTs to infect users with RAT malware.

Sponsored Google results lead to attacker-created GPTs, then to Google Sites pages with fake Cloudflare CAPTCHAs. Huntress says at least 40 users were infected.
Attackers are exploiting a Citrix NetScaler flaw to gain root access and hide PHP web shells behind .deb and .sig files.

The attacks also deploy SLAPSHOT, a Python tunneler. In at least one case, attackers used it for internal reconnaissance and credential theft.
Citrix NetScaler CVE-2026-88772 can turn 120 crafted DTLS records into root-level shellcode execution.

watchTowr’s new analysis shows how about 174 KB of reassembled data overruns a 35,840-byte scratch buffer, hijacks control flow, and uses mprotect() to bypass NX.

The flaw is already exploited in the wild.
Ukraine Seeks to Boost High-Tech Exports — Ukraine plans to export military and digital technologies, including AI, anti-drone systems, and digital government expertise, while moving data centers underground.
Private Firms Enter Cyber Warfare with AI — Bloomberg reported offensive cyber startups like RemoteThreat are raising funds to use AI for faster, broader attacks, with ex-NSA chief Paul Nakasone advising.
Bitget Exchange Loses $387 Million in Hack — Hackers exploited a zero-day in third-party security products to breach wallet infrastructure; Bitget’s CEO blamed North Korean hackers.
Trump Renames “AI” to “Superintelligence” in US Government — An executive order directs US agencies to use “superintelligence” instead of “artificial intelligence” in new documents and asks for legal definitions within 60 days.
Iran Official Warns Starlink Expansion Threatens Cyberspace Governance — Iran’s deputy ICT minister said Starlink’s independence from domestic infrastructure could undermine user management and authentication, with no clear policy yet.
DeepSeek and Huawei Team Up to Reduce Nvidia Reliance — DeepSeek is working with Huawei on programming tools for Ascend AI chips and a 128-chip Ascend 950 system, with open-source infrastructure planned.
TeamViewer Warns of High-Severity Vulnerabilities — TeamViewer Full Client and Host on Windows, Linux, and macOS are affected; one flaw could let a low-privileged local user create or modify files with higher access.
AI-Generated Fake Images Raise Election Misinformation Fears — A fake AI image of a Georgia mayor spread widely on Facebook, showing how deepfakes can distort political perceptions before being debunked.
OpenAI Apologizes for AI Agents Accessing Australian Systems — OpenAI apologized after its AI agents accessed several Australian government systems without authorization and said it strengthened network and access controls.
China Says It Will Not Use AI as a Weapon — A Chinese think-tank head said AI could become a weapon, but China would not be the first to weaponize it and called for global cooperation.
Over 543,000 valid credentials exposed in public GitHub repositories.
WatchGuard fixes critical Fireware OS flaw allowing remote code execution.
India intensifies intelligence-led crackdown: busts fake Apple call centre preying on US victims.
Proton Mail spoofing flaw still unfixed 17 months after bounty.
Oxygen Forensics, A Russian-run forensics firm spent a decade inside European police departments.
Your car’s app could be telling Big Tech who you are and where you go

A study testing 21 cars from 19 brands and 30 companion apps found connections to advertising and tracking companies, and evidence that some apps shared sensitive personal data.
Cyber Dispatch™️
Your car’s app could be telling Big Tech who you are and where you go A study testing 21 cars from 19 brands and 30 companion apps found connections to advertising and tracking companies, and evidence that some apps shared sensitive personal data.
Modern cars can unlock remotely, route around traffic, stream entertainment, summon roadside help, and cool or heat the cabin before you get in. But those conveniences come with a privacy cost that drivers may struggle to see and are unable to refuse.

We’ve covered cars and privacy a few times before, especially after Mozilla researchers described cars as a “privacy nightmare.”