Cyber Dispatch™️
380 subscribers
21 photos
1 video
50 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Researcher reveals evidence of Instagram private profiles leaking photos.
Operation Switch Off dismantles major pirate TV streaming services.
Crypto wallets received a record $158 billion in illicit funds last year.
Mandiant details how ShinyHunters abuse SSO to steal cloud data.
GlassWorm Loader Hits Open VSX via Developer Account Compromise.
Cloud storage payment scam floods inboxes with fake renewals.
الأمن الفرنسي يقتحم مقر إكس في باريس للاشتباه بتورط إيلون ماسك بالبيدوفيليا
شركة الإتصالات الفلسطينية:

انقطاع خدمة الإنترنت في شمال قطاع غزة بسبب أعمال صيانة فنية، على أن تعود الخدمة خلال ساعة واحدة.
Match, Hinge, OkCupid, and Panera Bread breached by ransomware group.
تم تسجيل فشل عالمي في عمل ChatGPT في جميع أنحاء العالم.
CVE-2025-7016

Improper Access Control vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Authentication Abuse.This issue affects QR Menu: before s1.05.12.
CVE-2025-59818

This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.
CVE-2026-1819

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Karel Electronics Industry and Trade Inc. ViPort allows Stored XSS.This issue affec...
CVE-2026-1861

Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2026-25510

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.28.5.0, an authenticated.
CVE-2026-1803

A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the component Dropbear SSH Service. This manipulation causes use of default credentials.
CVE-2026-24954

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.
CVE-2025-65875

An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2025-70841

Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuration data via direct request to /script/.env file.
CVE-2026-24665

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a stored Cross-Site Scripting (XSS) vulnerability allows authenticated.
SolarWinds Web Help Desk flaw added to CISA KEV

• CVE-2025-40551 (CVSS 9.8): unauthenticated RCE via deserialization
• Fixed in WHD v2026.1
• Federal agencies must patch by February 6