Cyber Dispatch™️
380 subscribers
21 photos
1 video
50 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
VoidLink Signals the Start of a New Era in AI-Generated Malware.
Firefox joins Chrome and Edge as sleeper extensions spy on users.
Windows 11 shutdown bug forces Microsoft into out-of-band damage control.
Ingram Micro says ransomware attack affected 42,000 people.
Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over $12 Billion.
SmarterMail flaw is under active attack within 48 hours of patching.

The bug lets attackers bypass auth, reset the admin password, then abuse built-in admin features to run OS commands as SYSTEM.

Activity points to patch reverse-engineering.
After X opened up its algorithm, users discovered that those criticizing Israel were massively censored and had their reach reduced by 90%.

The entire algorithm is now based on whether or not the user criticizes Israel.
Fortinet confirms active exploitation of CVE-2025-59718 / 59719, allowing FortiGate FortiCloud SSO bypass — even on fully patched devices.

Attackers abuse crafted SAML logins to gain admin access, add persistent accounts, enable VPN, and steal configs. Disabling FortiCloud SSO is advised.
Attackers are abusing trusted IT tools, not deploying malware.

A new campaign steals email logins, then installs legitimate RMM software for silent, long-term access.
Because the tools are signed and allowed, many security controls don’t trigger.
Email is still the easiest way in.

In Google Workspace, BEC attacks often carry no links or malware, so native defenses miss them. One compromised inbox can expose years of sensitive email and files.
Fortinet FortiGate under automated SSO abuse.

Attackers exploit CVE-2025-59718/59719 to add admin users, enable VPN access, and export firewall configs within seconds, per Arctic Wolf.
RCE flaws found in widely used AI Python libraries.

Researchers report bugs in Apple FlexTok, NVIDIA NeMo, and Salesforce Uni2TS that trigger when malicious model metadata is loaded.

These tools power popular AI models. Patches are out, no active exploitation seen yet.
Spain’s court probe into the hacking of the prime minister’s phone with Pegasus spyware has collapsed after Government of Israel refused to cooperate.

By blocking judicial assistance, Israel effectively shielded NSO Group, whose Pegasus spyware has been used to target politicians, journalists, and activists worldwide
TikTok updated its Privacy Policy and it goes far beyond basic app data.

The policy explicitly says TikTok may collect or infer sensitive personal data, including your:

Citizenship or immigration status
Religious beliefs
Mental and physical health information
Race or ethnic origin
Precise geolocation
Gender identity (including trans or non-binary)
Sexual orientation.

TikTok says this data can be provided directly, inferred from your activity, or processed “as permitted by law” and with user consent.
Microsoft provided the FBI with keys to unlock encrypted user data

Microsoft said it receives around 20 requests for BitLocker keys a year and will provide them to law enforcement.

In Win 11, uploading your key to their cloud is activated by default for ‘convenience’.
Osiris ransomware hit a major food service operator in Southeast Asia, researchers say.

The attack used a custom POORTRY driver to shut down security tools, then encrypted systems and exfiltrated data to cloud storage.
Fake SymPy on PyPI is targeting Linux devs. The package sympy-dev clones the real project text, poses as a dev build, and has 1,100+ downloads since Jan 17.

It activates only when certain math functions run, then loads an XMRig miner fully in memory to avoid traces.
One developer. 88,000+ lines of code.

Researchers say an advanced Linux malware framework was built in weeks with AI help, guided by a single skilled developer using an AI agent—resetting expectations for what one actor can build.
An 11-year-old critical flaw in GNU InetUtils telnetd lets attackers log in as root with no password.

Tracked as CVE-2026-24061 (CVSS 9.8), it affects all versions 1.9.3–2.7 due to an unsanitized USER environment value passed to login.
Cisco fixed an actively exploited zero-day in its voice and collaboration stack.

CVE-2026-20045 allows unauthenticated attackers to run commands and escalate to root on exposed Unified CM and Webex Calling systems.
Tucker Carlson: “Pornography websites are controlled by Israeli intelligence agencies.