Cyber Dispatch™️
380 subscribers
21 photos
1 video
50 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
TikTok uninstalls are up 150% following the Larry Ellison took over the platform in the US - CNBC News.
Konni Hackers Deploy AI-Generated PowerShell Backdoor Against Blockchain Developers.
Hackers can bypass npm’s Shai-Hulud defenses via Git dependencies.
Fake Microsoft Teams Billing Phishing Alerts Reach 6,135 Users via 12,866 Emails.
Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code.
Crunchbase Confirms Data Breach After Hacking Claims.
Don't Judge a PNG by Its Header: PURELOGS Infostealer Analysis.
Cloudflare misconfiguration behind recent BGP route leak.
$6,000 “Stanley” Toolkit Sold on Russian Forums Fakes Secure URLs in Chrome.
OpenAI team invitation system exploited in sophisticated phishing scam.
Ivanti has rolled out security updates to address two security flaws impacting Ivanti Endpoint Manager Mobile (EPMM) that have been exploited in zero-day attacks.

CVE-2026-1281 (CVSS score: 9.8) - A code injection allowing attackers to achieve unauthenticated remote code execution
CVE-2026-1340 (CVSS score: 9.8) - A code injection allowing attackers to achieve unauthenticated remote code execution

They affect the following versions

EPMM 12.5.0.0 and prior, 12.6.0.0 and prior, and 12.7.0.0 and prior (Fixed in RPM 12.x.0.x)

EPMM 12.5.1.0 and prior and 12.6.1.0 and prior (Fixed in RPM 12.x.1.x)
Researchers map 175K publicly exposed Ollama LLM servers worldwide.

Tool-calling turns exposed AI into a highest-severity execution risk.
Google dismantles IPIDEA, a major residential proxy network.

GTIG says 550+ threat groups used it this month to hide espionage, cybercrime, and password-spray attacks by routing traffic through hijacked home devices worldwide.
Apple buys 'secretive' Israeli AI start-up Q.ai in reported $1.6 billion deal

Apple has acquired the Israeli AI start-up Q.ai in a deal reportedly worth $1.6 billion, making it the second largest acquisition in the company’s history. According to The Financial Times, Q.ai is a “secretive” firm known for technology that can interpret “silent speech” through facial expressions. Sources say the deal could value the start-up at nearly $2 billion.
Cyber Dispatch™️
Apple buys 'secretive' Israeli AI start-up Q.ai in reported $1.6 billion deal Apple has acquired the Israeli AI start-up Q.ai in a deal reportedly worth $1.6 billion, making it the second largest acquisition in the company’s history. According to The Financial…
The purchase reflects Apple’s push to strengthen its AI capabilities after recent setbacks and delays in rolling out the full features of Apple Intelligence.

Q.ai’s technology is already being used in smart headphones and glasses to detect subtle facial micro-movements, allowing users to control devices with minimal physical action. The acquisition comes as Apple seeks to close the gap in the AI race, alongside recent partnerships integrating Google’s Gemini system and OpenAI’s ChatGPT into its software ecosystem.
Watering Hole Attack Targets EmEditor Users With Information-Stealing Malware.
U.S. Immigration and Customs Enforcement has increased its use of Israeli surveillance technology, including phone-hacking and data-extraction tools, enabling the tracking and identification of protesters.
China-linked UAT-8099 targets IIS servers in Asia using BadIIS SEO malware.

The group broke into vulnerable IIS servers, mainly in Thailand and Vietnam, using web shells and PowerShell. The aim remains SEO fraud, now tuned by region.
SmarterMail fixed a critical unauthenticated RCE in its email server software.

The flaw, CVE-2026-24423 (CVSS 9.3), lets attackers execute OS commands via a crafted remote server. It affects builds before 9511.
The tech giant Microsoft said it receives around 20 requests for BitLocker keys a year and will provide them to governments in response to valid court orders. But companies like Apple and Meta set up their systems so such a privacy violation isn’t possible.
Apple is testing a new iOS setting that reduces how precisely cellular networks can 📍 locate your device.

Limit Precise Location restricts location data to a broad area instead of an exact address.