IT Security Newsletter

IT Security Newsletter - 9/14/2026

Written by Cadre | Mon, Sep 14, 2026

Revolut gave customer IDs and financial data to a government impostor

Revolut has acknowledged that it disclosed sensitive customer records to an unauthorized party. The company had accepted fraudulent information requests sent from an email address on a legitimate government agency domain, according to TechCrunch. Revolut is a London-based banking and financial platform with more than 80 million customers globally, according to the company. Revolut describes this as an external impersonation scam, not an intrusion into its systems. READ MORE...

Florida confirms DMV database breached via stolen police account

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach after the ShinyHunters extortion gang claimed to have compromised the system. The disclosure comes after the ShinyHunters extortion group claimed it breached the DAVID database and stole more than 200,000 driver records. "On September 4, 2026, FLHSMV learned of a data breach conducted by an international cybercriminal organization," the agency said. READ MORE...

Telus Warns Customers of Account Breaches

Telus, one of Canada's largest telecom providers, is notifying some customers that their accounts have been breached and their personal information has been accessed. In data breach notifications sent to customers whose consumer telecom accounts were affected, Telus said the intrusions occurred between February 2025 and June 2026. According to the company, the attacker used compromised credentials to access Telus accounts and the information they store. READ MORE...

Hackers abused Claude to extract secrets from 1.8M Android apps

Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. The AI company says that between December 2025 and August 2026, it recorded various forms of artificial intelligence misuse, including for cyber and influence operations, surveillance, scams, development of biological and conventional weapons, and model distillation. READ MORE...

Threat Actor Generates 1M Personalized Fraud Emails in 3 Days

Artificial intelligence (AI) is enabling threat actors to send unholy volumes of fraudulent emails, personalized to a degree that mass emailers of old couldn't have touched. Last month, Microsoft researchers tracked a phishing campaign in which an unattributed threat actor sent out more than one million emails in just three days. Despite the volume of content they had to juggle, the threat actor managed to target relevant accounts payable departments and lightly personalize each message. READ MORE...

State authorities warn they lack resources to address cyber threat to critical sectors

State and local governments across the U.S. are facing significant gaps in their ability to protect critical infrastructure at a time of increased threat activity. State authorities said they need additional funding, federal support and staffing in order to protect key sectors like water, energy and healthcare, according to a report from the National Association of State Chief Information Officers (NASCIO) and General Dynamics Information Technology. READ MORE...

More JFrog Artifactory bugs under attack, and all 3 have patches

JFrog Artifactory instances continue to get hit hard. Multiple attackers are exploiting three JFrog Artifactory bugs to gain administrative control over vulnerable instances - in some cases, just days after the vendor published a patch - and then using this illicit access to install malicious plugins and backdoors. Earlier this month, security researchers told The Register that miscreants began battering internet-exposed systems vulnerable to CVE-2026-82329. READ MORE...

Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems

Researchers say they have discovered thousands of malicious software packages uploaded to an online public software repository that were left by a "swarm" of OpenAI agents. According to an incident timeline published Friday by researchers Spencer Kitts, Thomas Larsen and Sydney Von Arx, the campaign began May 5 when they observed a handful of suspicious packages being uploaded to RubyGems, a public library for the Ruby programming language. READ MORE...

Why AI Is So Good at Scamming Humans

If there's one thing that AI models are remarkably good at, it's manipulation. That's according to security researcher Fred Heiding, who spoke with Dark Reading's senior news director, Rob Wright, at the Dark Reading News Desk at Black Hat USA 2026 last month. Heiding, executive director at Menlo Park Intelligence, and former US National Cyber Director Chris Inglis, spoke at the conference about their research on AI security. READ MORE...

GitLab's critical flaw is already drawing internet-wide probes

GitLab released emergency patches Thursday for two high-severity flaws in its software development platform, one of them holding the highest possible severity score, while a security firm reports that it has already seen attackers probing the internet for the flaws. The company patched the issues in new versions of both its Community Edition and Enterprise Edition, and urged those that use self-managed installations to upgrade as soon as possible. READ MORE...

  • ...in 1956, the IBM RAMAC 305 was introduced.
  • ...in 1959, the Soviet probe Luna 2 crashes onto the Moon, becoming the first man-made object to reach it.
  • ...in 1994, Major League Baseball cancels the 1994 season and the World Series.
  • ...in 2000, Microsoft introduced the last update to the OS, MS-DOS. (Version 8.0)