Cyber Dispatch™️
403 subscribers
34 photos
4 videos
56 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch
Download Telegram
TeamViewer Warns of High-Severity Vulnerabilities — TeamViewer Full Client and Host on Windows, Linux, and macOS are affected; one flaw could let a low-privileged local user create or modify files with higher access.
AI-Generated Fake Images Raise Election Misinformation Fears — A fake AI image of a Georgia mayor spread widely on Facebook, showing how deepfakes can distort political perceptions before being debunked.
OpenAI Apologizes for AI Agents Accessing Australian Systems — OpenAI apologized after its AI agents accessed several Australian government systems without authorization and said it strengthened network and access controls.
China Says It Will Not Use AI as a Weapon — A Chinese think-tank head said AI could become a weapon, but China would not be the first to weaponize it and called for global cooperation.
Over 543,000 valid credentials exposed in public GitHub repositories.
WatchGuard fixes critical Fireware OS flaw allowing remote code execution.
India intensifies intelligence-led crackdown: busts fake Apple call centre preying on US victims.
Proton Mail spoofing flaw still unfixed 17 months after bounty.
Oxygen Forensics, A Russian-run forensics firm spent a decade inside European police departments.
Your car’s app could be telling Big Tech who you are and where you go

A study testing 21 cars from 19 brands and 30 companion apps found connections to advertising and tracking companies, and evidence that some apps shared sensitive personal data.
Cyber Dispatch™️
Your car’s app could be telling Big Tech who you are and where you go A study testing 21 cars from 19 brands and 30 companion apps found connections to advertising and tracking companies, and evidence that some apps shared sensitive personal data.
Modern cars can unlock remotely, route around traffic, stream entertainment, summon roadside help, and cool or heat the cabin before you get in. But those conveniences come with a privacy cost that drivers may struggle to see and are unable to refuse.

We’ve covered cars and privacy a few times before, especially after Mozilla researchers described cars as a “privacy nightmare.”
Chinese hackers impersonated U.S. AI experts and former officials in phishing emails targeting people working on AI policy, regulation and export controls, according to Proofpoint.

The hackers sent fake collaboration offers that led to password-stealing websites. Fewer than 10 people were targeted.

Proofpoint said the campaign appeared focused on gathering intelligence about U.S. AI policymaking rather than simply stealing technology.
Pentagon unveils AI-powered 'Autonomous Warfare Command,' taps Elon Musk for key role.
Andy Burnham’s government is looking for a British alternative to U.S. tech firm Palantir for major NHS and Ministry of Defence contracts as part of its “Buy British” push.

Ministers are considering using a break clause in Palantir’s £330mn NHS data-platform contract next March, possibly giving the company a temporary extension while a UK replacement is developed.

Officials are also examining alternatives for Palantir’s £240.6mn MoD contract, although some warn replacing its technology could be risky.
Attackers are exploiting a critical FortiMail flaw that allows unauthenticated arbitrary file writes.

CISA added "CVE-2026-104286" to KEV. Fortinet published IOCs and workarounds, with fixes still pending for some versions.
Police arrested a 16-year-old suspected of running KillSec.

Authorities took over the #ransomware group’s leak site and shut down five servers. The probe covers about 1,000 suspected attacks worldwide, with about 500 identified as successful so far.
AI agents hacked the hackers, stealing email addresses from security research org.
Cyber Dispatch™️
AI agents hacked the hackers, stealing email addresses from security research org.
AI agents hacked the hackers - the Dutch Institute for Vulnerability Disclosure (DIVD) - via two zero-day bugs in its Zammad support platform, abusing the flaws to hijack sessions, run code remotely as the local zammad user, and escalate privileges to root.

The chained exploits took just seconds to move from session hijacking to root access, and on Thursday, the nonprofit bug hunting organization said the miscreants stole data belonging to its volunteer security researchers, including DIVD email addresses and potentially other contact details.
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks.
Russian hacking group Star Blizzard expands phishing operations with new malware technique.
WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory.