Cyber Dispatch™️
380 subscribers
21 photos
1 video
50 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Microsoft provided the FBI with keys to unlock encrypted user data

Microsoft said it receives around 20 requests for BitLocker keys a year and will provide them to law enforcement.

In Win 11, uploading your key to their cloud is activated by default for ‘convenience’.
Osiris ransomware hit a major food service operator in Southeast Asia, researchers say.

The attack used a custom POORTRY driver to shut down security tools, then encrypted systems and exfiltrated data to cloud storage.
Fake SymPy on PyPI is targeting Linux devs. The package sympy-dev clones the real project text, poses as a dev build, and has 1,100+ downloads since Jan 17.

It activates only when certain math functions run, then loads an XMRig miner fully in memory to avoid traces.
One developer. 88,000+ lines of code.

Researchers say an advanced Linux malware framework was built in weeks with AI help, guided by a single skilled developer using an AI agent—resetting expectations for what one actor can build.
An 11-year-old critical flaw in GNU InetUtils telnetd lets attackers log in as root with no password.

Tracked as CVE-2026-24061 (CVSS 9.8), it affects all versions 1.9.3–2.7 due to an unsanitized USER environment value passed to login.
Cisco fixed an actively exploited zero-day in its voice and collaboration stack.

CVE-2026-20045 allows unauthenticated attackers to run commands and escalate to root on exposed Unified CM and Webex Calling systems.
Tucker Carlson: “Pornography websites are controlled by Israeli intelligence agencies.
UK House of Lords votes in favor of banning VPNs for young people

They will only allow VPN use for those aged 18 and over.

They have also voted in favor of the UK social media ban for under-16s.
CISA has added a critical vulnerability affecting Broadcom’s VMware vCenter Server to its Known Exploited Vulnerabilities (KEV) catalog.

This addition confirms that active exploitation of CVE-2024-37079 has been detected in the wild, posing a significant risk to enterprise environments that rely on vCenter for virtualization management.

Successful exploitation allows a malicious actor with network access to the vCenter Server to execute remote code, potentially gaining full control over the affected system.
New social media platform “Upscrolled” founded by Palestinian-Australian technologist Issam Hijazi has received thousands of downloads since Larry Ellison took control of TikTok.
BREAKING: EVERYONE IS MOVING TO UPSCROLL AFTER LARRY ELLISON TOOK OVER THE OTHER MEDIA.
North Korea’s Konni group is using AI-assisted PowerShell malware to target blockchain developers.

Campaigns hit Japan, Australia, and India via Google ad–style phishing links that bypass filters and drop EndRAT.
Russian users hit by a new phishing chain delivering Amnesia RAT and ransomware.

Fake business docs and LNK files do the work — no exploits. Payloads are split across GitHub and Dropbox, then Microsoft Defender is disabled using defendnot.
Poland blocked what officials described as its strongest cyberattack on the energy sector in years.
CISA confirms active exploitation of a critical VMware vCenter Server flaw.

CVE-2024-37079 allows remote code execution via a DCE/RPC heap overflow if an attacker has network access.
Google Project Zero revealed a working zero-click exploit chain against Pixel 9 phones.

A bug in the Dolby audio decoder let Google Messages process a malicious audio file in the background, gaining code execution, then a kernel bug completed the takeover. Pixel patches shipped in early Jan 2026.
Hackers get $1,047,000 for 76 zero-days at Pwn2Own Automotive 2026.
A single spreadsheet formula can now lead to full server takeover in Grist-Core.

The flaw, CVE-2026-24002 (CVSS 9.1), breaks out of the Pyodide sandbox, letting attackers run OS commands and access files and secrets.
Microsoft rushed out out-of-band fixes for an actively exploited Office zero-day.

CVE-2026-21509 (CVSS 7.8) lets attackers bypass Office security using a malicious file that must be opened by the victim.
Bitcoin seed panic fake—scammers bait thieves with bogus lists. Real risks: Snap malware, phishing. Store offline, verify updates. Funds safe.