IT Security Newsletter - 10/5/2026
Detained ShinyHunters hacker reportedly helping FBI track down fellow members
A suspected ShinyHunters member known as Rey has been detained in Jordan and is reportedly helping the FBI track down the rest of the group. Reuters reports that Jordanian authorities detained Saif al-Din Khader, alias Rey, last week, with two of its three sources placing the arrest on Tuesday. One source told the publication that Khader is walking investigators through his electronic devices and digital correspondence. READ MORE...
OpenAI alerts 100+ orgs that its 'misaligned models' attempted to break in - or worse
OpenAI's agents have repeatedly strayed beyond their intended scope. Two separate reports detail the activity, including one from Sam Altman's company saying it has notified more than 100 organizations about potentially problematic model activity. OpenAI, in a late Wednesday update to its ongoing Hugging Face investigation, said it has notified more than 100 organizations that "misaligned models" may have accessed their systems. READ MORE...
250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms
Healthcare organizations Clover Health Investments and AngMar Management Services are notifying more than 250,000 people that their information was stolen in separate data breaches. Jersey City, New Jersey-based Clover Health Investments was hacked in early July, after attackers used social engineering to compromise three non-managerial health plan employee accounts. The incident resulted in the theft of personally identifiable information (PII) and protected health information (PHI). READ MORE...
South Korea probes bank breaches amid suspected AI-powered attacks
South Korea's Financial Services Commission (FSC) held an emergency meeting following a series of cyberattacks targeting financial institutions in the country. During the meeting, officials confirmed a data breach at Shinhan Bank and said other cybersecurity incidents affected other South Korean banks, including Kookmin Bank. Shinhan Bank and KB Kookmin Bank are large private South Korean commercial banks, each holding more than $400 billion in assets. READ MORE...
Patient-zero drill put health facilities to the test-40% of them failed
COVID-19 made the weaknesses in our pandemic preparedness at national and global levels painfully clear. But a new study highlights that even at the first, local steps of an outbreak with pandemic-potential, we are worryingly underprepared. Health officials in New York set up a regional test of healthcare facilities to identify and respond to a patient with a mystery infection that could pose a pandemic-level threat. But things didn't go well. READ MORE...
Fortra Patches Critical Vulnerabilities in BoKS
Fortra has released patches for eight vulnerabilities in Core Privileged Access Manager (BoKS), including three critical-severity bugs. BoKS provides organizations with central management of Unix and Linux fleets, enabling policy enforcement and access control across accounts. On Thursday, the company warned that BoKS Manager deployments relying on BoKS keytab for Active Directory service account management are affected by a critical flaw leading to authentication bypass. READ MORE...
Warlock ransomware breach SharePoint in water, telecom operator attacks
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. ?Over the past two months, the threat actor appears to have focused on countries speaking Portuguese and Spanish across Europe, Africa, and Latin America. The gang emerged in June 2025 and gained notoriety after exploiting a chain of zero-day vulnerabilities in Microsoft SharePoint known as ToolShell. READ MORE...
n0n Ransomware: What You Need to Know
N0n is a newly-emerged cyber extortion gang (and yes, that's a zero, not an "o" in its first name). The group was first spotted in the middle of September 2026, and within days it had published on its dark web leak site details of what it claimed to be around a dozen victims. Since then, the tally has continued to grow. Aside from the usual threat of "pay up or we leak your data", n0n claims that it shuts down victims' networks, and destroys backups and shadow copies. READ MORE...
How RMM abuse gives attackers a way in that looks like business as usual
Huntress found attackers using legitimate remote monitoring and management (RMM) software in 45% of the endpoint-related incidents it recorded in the first quarter of 2026. The security company also ranked 11 attack tactics by how often it sees them and how much damage each can do, and RMM abuse sits farthest right on the chart, the position for tactics it sees most often. IT teams use RMM tools to manage computers from anywhere, which can be abused by attackers. READ MORE...
The US needs a real plan to defend its water systems
The summer's cyberattacks by Iranian hackers on water systems in 12 states underscored how vulnerable U.S. water systems are to foreign adversaries. A broad attack on water infrastructure could have consequences comparable to a public health crisis that impacts the country's entire population. The threat to water has long been clear. Cyber actors from China, Russia, Iran, North Korea, and ransomware groups pose critical threats to U.S. networks and critical infrastructure. READ MORE...
SWIFT Banking & Government Middleware Enables RCE
Researchers have discovered a critical vulnerability in a hardware authentication program used to access highly sensitive global government and financial systems. In cases where purely digital methods just aren't secure enough, especially careful organizations may require that users authenticate to sensitive systems with MFA hardware. After all, you wouldn't want a simple password to allow hackers into a system that facilitates financial transfers or official government business. READ MORE...
Fortinet warns that critical flaw in FortiMail is facing exploitation
Fortinet on Thursday warned of a critical path traversal vulnerability in Fortinet FortiMail, which has been exploited in the wild. The zero-day vulnerability, tracked as CVE-2026-104286, allows an unauthenticated attacker to write arbitrary files on a system through the use of specially crafted HTTP or HTTPS requests. Fortinet said it has been in touch with government authorities and other stakeholders regarding the threat, and urged customers to apply a workaround. READ MORE...
- ...in 1921, The World Series is broadcast on radio for the first time.
- ...in 1947, US President Harry S Truman delivers the first televised White House address.
- ...in 1962, the first James Bond film, "Dr. No", starring Sean Connery is released in theaters.
- ...in 1969, "Monty Python's Flying Circus" debuts on BBC One.








