<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 10/6/2026

SHARE

Breaches

Data breach at Denmark's population register exposes 8.8 million people

A data breach at Denmark's Central Population Register (CPR) has exposed the personal information of 8.8 million people. These include people living in Denmark, deceased people and citizens who have moved abroad. The CPR is Denmark's national register of residents, and the 10-digit CPR number it assigns to each person is used for everything from taxes and healthcare to banking. The CPR administration learned that there had been irregular activity in the system during September. READ MORE...

Hacking

Chinese Hackers Impersonate US Officials for AI Cyber Espionage

Chinese hackers impersonated US policymakers in adversary-in-the-middle (AiTM) phishing campaigns aimed at stealing credentials from artificial intelligence (AI) experts working for US think tanks, universities, and legal organizations. Researchers from Proofpoint discovered the campaign, which occurred in July, and attributed it to China-aligned threat actor TA419, according to a blog post published last week. READ MORE...


Domino's customers targeted in credential stuffing attacks

Domino's Pizza customers tell us they have received emails saying they account has been accessed by a third party. Domino's says its internal systems weren't breached, but that individual accounts were logged into using a password and email combination stolen from another online account owned by the customer. This is known as credential stuffing. Credential stuffing is an attack where criminals take usernames and passwords stolen from one website and try them on many other websites. READ MORE...

Software Updates

Citrix issues patch for third exploited flaw in NetScaler

Citrix on Saturday urged customers to immediately patch a memory-overflow vulnerability in NetScaler ADC and NetScaler Gateway, which was being exploited as a zero-day. The vulnerability, tracked as CVE-2026-88779, could lead to a denial-of-service condition on customer-managed NetScaler deployments when certain preconditions were met, the company said. Citrix noted the system could be rendered unavailable in cases where repeated attacks had taken place. READ MORE...

Malware

OpenAI agents tried to hack Wikipedia tools and flooded it with traffic

The publisher of Wikipedia said Monday that OpenAI agents attempted to hack a note-taking tool it hosts, made unauthorized edits, and sent millions of resource-intensive requests to its infrastructure, in the latest instance of OpenAI systems taking harmful and potentially dangerous actions. The objective of some of the OpenAI agents' actions, the Wikimedia Foundation said, was to use Wikipedia as a proxy for fetching data from third-party sites. READ MORE...


Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

Malicious packages published as part of a long-running NPM supply chain campaign have accumulated over 40,000 downloads, Checkmarx reports. Dubbed MALFEX and distributing malware such as the Overlord RAT and infostealers, the campaign has been ongoing since August 2023, when the threat actor published its first package. To date, the threat actor has published 12 packages, eight of which are malicious. READ MORE...

Information Security

Google pauses open source bug bounty program after rise in AI submissions

Companies like Google and Microsoft are finding much bigger numbers of vulnerabilities in their own products as a result of AI. But the same technology is leading to public reporting programs becoming overwhelmed by the mass submission of speculative, duplicated, or hallucinated findings. Now, Google's announced it has temporarily stopped accepting submissions to its open source bug bounty program, OSS VRP. READ MORE...


FBI Arrests 'Most Wanted' Developer of Ploutus ATM Malware

A Venezuelan national believed to be a leader of Tren de Aragua (TdA)'s ATM jackpotting activities and the developer of the infamous Ploutus ATM malware has been arrested. According to the US, TdA is a violent transnational criminal organization that engages in different types of trafficking, robbery, fraud, extortion, and various types of financial crimes targeting US organizations, including ATM jackpotting. READ MORE...

Exploits/Vulnerabilities

New Dell System Update flaw lets hackers gain root privileges

Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible. DSU lets enterprise IT administrators deploy BIOS, firmware, and software updates onto Linux and Windows systems on PowerEdge enterprise server infrastructure. In a Thursday security advisory, the company said the flaw (tracked as CVE-2026-86360) allows threat actors to execute code with root privileges. READ MORE...


Atlassian warns of critical file access flaw in its datacenter products

Atlassian has told its users to patch its datacenter products, pronto, to prevent attackers accessing their files. The Australian collaborationware company on Monday sent users an email that opens with the words "Action required" and points to a security bulletin that explains CVE-2026-21589. The 9.3-rated arbitrary file access vulnerability is present in the datacenter versions of its Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, and Fisheye products. READ MORE...


Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets

GitHub Copilot CLI may reveal developer secrets if it comes across instructions that tell it to do so, depending on the underlying model. The coding agent tool was flagged earlier this year for being susceptible to indirect prompt injection. That's when a model ingests text from a source other than the user that directs it to take some action outside the scope of its intended function. This is more of the same, with a twist. READ MORE...

On This Date

  • ...in 1866, the Reno gang carries out the first robbery of a moving train in the U.S., making off with over $10,000.
  • ...in 1995, Astronomers discover that the star 51 Pegasi has a planet orbiting around it, the first observed solar system outside of our own.
  • ...in 2007, Explorer and author Jason Lewis becomes the first person to complete a human-powered circumnavigation of the globe.
  • ...in 2010, the social media photo-sharing site Instagram is founded.