<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 10/2/2026

SHARE

Top News

Autonomous AI agents tried to hack US, Canadian government websites

Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. The failed breach attempts targeted a website under the U.S. Department of Education and Library and Archives Canada. However, the collected data shows no evidence of access to non-public information. The AI agents appeared tasked with data retrieval operations, but their activity also included failed "rudimentary hacking attempts." READ MORE...


Crypto Scammers Hijack Microsoft's Official X Account

Microsoft has confirmed that its official X account was taken over on Thursday and used to amplify a Clippy-themed cryptocurrency account. According to The Verge, the company's account, which has more than 13 million followers, started following the crypto account and shared one of its messages. Microsoft's profile picture was also replaced with an image of Clippy, the animated paperclip assistant that shipped with older versions of Office. READ MORE...

Hacking

AI agents hacked the hackers, stealing email addresses from security research org

AI agents hacked the hackers - the Dutch Institute for Vulnerability Disclosure (DIVD) - via two zero-day bugs in its Zammad support platform, abusing the flaws to hijack sessions, run code remotely as the local zammad user, and escalate privileges to root. The chained exploits took just seconds to move from session hijacking to root access, and on Thursday, the nonprofit bug hunting organization said the miscreants stole data belonging to its volunteer security researchers. READ MORE...


Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

The Warlock ransomware group continues to target SharePoint servers in attacks against critical infrastructure, government, and education entities, Symantec reports. Warlock is believed to be operated by a China-based hacking group tracked as Longlegs and Storm-2603, which has been linked to malicious operations such as CL-CRI-1040, CamoFei, and ChamelGang. Last year, the Chinese state-sponsored groups Linen Typhoon and Violet Typhoon were seen exploiting two SharePoint vulnerabilities. READ MORE...

Software Updates

Dell asks admins to patch max severity CSM flaws as soon as possible

Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments. CSM supports Dell's primary storage platforms (PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT), and it extends the capabilities of the standard Container Storage Interface (CSI) drivers for Kubernetes. Dell said that both critical security flaws were found in the Dell CSM Authorization security module. READ MORE...

Information Security

Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members

Authorities arrested the alleged leader and two additional members of KillSec, a data extortion group primarily run by teenagers that successfully compromised about 500 organizations since 2024, Europol and the Justice Department said Thursday. Investigators said the alleged leader of the group is 16 years old, but declined to name them. One of the group's accused members, Fouad Eltibrizi, was arrested Wednesday in the United Kingdom and awaits extradition to the United States. READ MORE...


Fake xStocks, Pendle, and other sites bait crypto users with rewards votes

We found 70 websites that impersonate legitimate crypto projects that invite visitors to vote on the date of an upcoming rewards distribution. The pages copy the look of the real sites closely, and on most of them the offer is small and believable: Cast a vote, and as an active voter you get a 1.25x boost when the rewards are paid out. However, the vote is fake and clicking the Vote now button opens a wallet connection prompt. READ MORE...

Exploits/Vulnerabilities

Microsoft catches hackers exploiting Zimbra bug before disclosure

Attackers were poking at a critical Zimbra mail server bug weeks before it was publicly disclosed, and then moved on to steal credentials, raid mailboxes, and take deeper control of compromised systems. Microsoft Threat Intelligence said it tracked exploitation of CVE-2026-73570, an unauthenticated command injection vulnerability in Zimbra Collaboration Suite that gives attackers a potentially easy route into exposed mail servers. READ MORE...


Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)

Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its email security gateway. Fortinet says the flaw has been reported to be exploited in the wild, and urges customers to apply the workaround it shared until fixes are available. The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog the same day. READ MORE...

On This Date

  • ...in 1950, Charles Schulz's comic strip "Peanuts" first appears. By the late 1960s, it would run in over 2,600 newspapers worldwide.
  • ...in 1951, English musician and actor Sting is born in Wallsend, Northumberland.
  • ...in 1959, screenwriter Rod Serling's dark sci-fi/horror anthology series "The Twilight Zone" debuts on CBS.
  • ...in 1967, Thurgood Marshall is sworn in as the first African-American justice of United States Supreme Court.