IT Security Newsletter

IT Security Newsletter - 9/10/2026

Written by Cadre | Thu, Sep 10, 2026

Anthropic reveals fourth likely crime committed by its AI

Amid industry soul-searching¹ about the possibility of AI improving itself to the point that it kills everyone, Anthropic has revealed yet another incident that would qualify as a crime if perpetrated by a person. The AI biz published "an alignment assessment" detailing four times Claude models accessed third-party systems without authorization. The company has already reported three of the incidents. Evidence of the fourth was lurking in a session transcript dating back to January 2026. READ MORE...

4.1 Million Impacted by AdaptHealth Data Breach

More than 4.1 million individuals had their personal, health, and insurance information stolen in a data breach at healthcare company AdaptHealth. Operating over 680 facilities across the US, AdaptHealth describes itself as a network of medical equipment companies that provides patients with healthcare solutions and medical equipment. The company was hacked in early June, when a threat actor gained access to its cloud-based applications. READ MORE...

Veradigm warns of patient data breach after ransomware gang claims attack

Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. The company says the incident did not cause operational disruptions but affected a small number of customers. Formerly known as Allscripts Healthcare Solutions, Veradigm is a Chicago-based healthcare technology company that supplies medical practices with software. READ MORE...

Cybercriminals are building phishing pages that exist only inside victims' browsers

A phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside their own browser, according to researchers at Barracuda. "Instead of delivering a phishing page from a web server, the malicious content is assembled inside the victim's browser using a blob URL - a temporary browser-generated URL that points to content stored locally in memory rather than on a website," researchers explained. READ MORE...

Chinese espionage groups swarm to exploit triple-link chain of zero-days

Proofpoint researchers have spotted at least four state-aligned threat groups chain a trio of zero-day vulnerabilities to conduct espionage on various targets of interest to China's government since late August. The Chinese espionage group that Proofpoint tracks as TA412, also known as Violet Typhoon and APT31, struck first, exploiting the chain of vulnerabilities Aug. 28. At least three additional espionage threat groups followed suit. READ MORE...

Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories

Major chipmakers AMD, Arm, and Nvidia published new security advisories on Tuesday to notify customers of vulnerabilities recently discovered in their products. AMD announced fixes for CVE-2026-43603, a NULL pointer dereference flaw in its Linux GPU kernel driver that could lead to system crashes and a denial-of-service (DoS) condition. The company credited Maxime Rossi Bellom and Ramtine Tofighi Shirazi from SecMate for reporting the security defect. READ MORE...

More than 100,000 fake stores are out to steal your card details

Researchers at German cybersecurity company Nebty have identified "DoppelCart," a cluster of almost 119,000 domains linked to copied online stores. The researchers describe it as the largest publicly documented fake-shop network by associated domain count. They found 118,787 .shop domains in the cluster, representing 2.72% of the .shop top-level domain (TLD) population they examined. The operation copies legitimate retailers' product catalogs, descriptions, branding, and images. READ MORE...

Mythos Vulnerability Firehose Hits a Human Bottleneck

A new analysis of public data from Anthropic's Project Glasswing has highlighted a significant gap between the number of vulnerability findings generated by its Claude frontier model and those that ultimately prove to be real, serious, and worth fixing. The distinction matters because it suggests that the bottleneck in vulnerability research may increasingly lie in validating new flaws and coordinating their remediation rather than in discovering them. READ MORE...

Four groups caught using the same Chrome and Windows exploit kit

A nearly identical exploit kit that targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows is being actively used by at least four hacking groups, some of which have ties to the Chinese government. Researchers from security firm Proofpoint said Wednesday that BlueMoon, the name they gave to the kit, chains three vulnerabilities together so the attackers using it can install malware of their choice. READ MORE...

  • ...in 1813, the U.S. defeats the British Fleet at the Battle of Lake Erie during the War of 1812.
  • ...in 1941, scientist and popular science writer Stephen Jay Gould ("The Mismeasure of Man", "The Panda's Thumb") is born in Queens, NY.
  • ...in 1963, major league baseball pitcher Randy Johnson is born in Walnut Creek, CA.
  • ...in 2008, CERN's Large Hadron Collider is powered up in Geneva, Switzerland. It is the most complex experimental facility ever built.