Cyber Dispatch™️
380 subscribers
21 photos
1 video
50 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Microsoft rushed out out-of-band fixes for an actively exploited Office zero-day.

CVE-2026-21509 (CVSS 7.8) lets attackers bypass Office security using a malicious file that must be opened by the victim.
Bitcoin seed panic fake—scammers bait thieves with bogus lists. Real risks: Snap malware, phishing. Store offline, verify updates. Funds safe.
Edward Snowden: "Both Apple and Android devices unfortunately are not especially good in protecting your privacy.

"Every phone, even when the screen is off you think it's doing nothing, but it's screaming 'Here I am'."

"They can see everything about you. They can see everything about what your device is doing, and they can do whatever they want with your device."
New app UpScrolled is number 1 on the US Play Store now and the most downloaded social network app after the mass censorship of TikTok.
ShinyHunters claims 2 Million Crunchbase records; company confirms breach.
Nearly 800,000 Telnet servers exposed to remote attacks.
TikTok Finalizes a Deal to Form a New American Entity.
SoundCloud - 29,815,722 breached accounts.
Turns out Google was also listening when you said nothing, thought nothing, and were just existing in your kitchen.

$68 million later, the official position is:

“We accidentally recorded private conversations. Accidentally shared them with advertisers. Super weird. Oops.”

Reminder that the smart speaker was never smart.
TikTok uninstalls are up 150% following the Larry Ellison took over the platform in the US - CNBC News.
Konni Hackers Deploy AI-Generated PowerShell Backdoor Against Blockchain Developers.
Hackers can bypass npm’s Shai-Hulud defenses via Git dependencies.
Fake Microsoft Teams Billing Phishing Alerts Reach 6,135 Users via 12,866 Emails.
Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code.
Crunchbase Confirms Data Breach After Hacking Claims.
Don't Judge a PNG by Its Header: PURELOGS Infostealer Analysis.
Cloudflare misconfiguration behind recent BGP route leak.
$6,000 “Stanley” Toolkit Sold on Russian Forums Fakes Secure URLs in Chrome.
OpenAI team invitation system exploited in sophisticated phishing scam.
Ivanti has rolled out security updates to address two security flaws impacting Ivanti Endpoint Manager Mobile (EPMM) that have been exploited in zero-day attacks.

CVE-2026-1281 (CVSS score: 9.8) - A code injection allowing attackers to achieve unauthenticated remote code execution
CVE-2026-1340 (CVSS score: 9.8) - A code injection allowing attackers to achieve unauthenticated remote code execution

They affect the following versions

EPMM 12.5.0.0 and prior, 12.6.0.0 and prior, and 12.7.0.0 and prior (Fixed in RPM 12.x.0.x)

EPMM 12.5.1.0 and prior and 12.6.1.0 and prior (Fixed in RPM 12.x.1.x)
Researchers map 175K publicly exposed Ollama LLM servers worldwide.

Tool-calling turns exposed AI into a highest-severity execution risk.