IT Security Newsletter

IT Security Newsletter - 9/2/2026

Written by Cadre | Wed, Sep 2, 2026

Krebs on Security: FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the FBI today launched an official inquiry into the source of the images. READ MORE...

FBI raises alarm over deceptive phishing campaign targeting prominent people

Attackers are targeting prominent, high-profile people, their family members and acquaintances on a commercial messaging application to gain long-term access to their accounts containing sensitive data, the FBI warned in an alert Tuesday. Officials did not describe the objectives or origins of the attackers, which have more recently impersonated government officials, journalists and publicly known personalities. READ MORE...

Legacy Lenovo login opens 5,000 Dropbox accounts to attackers

Dropbox has warned around 5,000 users that attackers compromised their accounts by abusing a legacy Lenovo login integration. In an email sent to affected customers, the cloud storage biz said attackers exploited an integration that allowed users to access Dropbox using Lenovo IDs. Dropbox blamed "an issue with Lenovo's email verification process," which allowed attackers to register Lenovo IDs using Dropbox users' email addresses and then access the corresponding storage accounts. READ MORE...

Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency

Unpatched servers at a Philippine nuclear agency, a naval contractor, and other organizations allowed a cyberthreat group to breach the networks and steal information on nuclear-material processes, IT planning, personnel, and other sensitive data. and other sensitive data. Researchers from threat hunting platform Hunt.io discovered the files on an ownCloud server hosted in Amsterdam that appeared to be a hub for the attackers, hosting offensive tools and stolen data. READ MORE...

Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks

AI model testing organization METR has disclosed two attacks that happened earlier this year, including one in which an attacker stole an API key and spent three weeks consuming public-model credits worth about $600,000. METR (short for Model Evaluation and Threat Research) found no evidence that the attackers accessed sensitive information in either incident, and the org said it investigated both with security experts. READ MORE...

BGP hijack infecting networks caused by a comedy of errors that's not funny at all

Hackers carried out a supply chain attack that installed malware on networks using an unusual technique: hijacking a chunk of Internet space where cloud management software used by hosting providers, data centers, and other large infrastructure companies is updated. In a well-coordinated operation, the unknown attackers exploited weaknesses in the routing security setup of hosting provider Hetzner Online and the process for attaining valid TLS certificates. READ MORE...

Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products

Rockwell Automation on Tuesday informed customers that patches or workarounds are available for more than a dozen vulnerabilities discovered across its industrial automation products. Only one of the new advisories describes critical vulnerabilities. It covers four critical and high-severity denial-of-service (DoS) issues affecting the RSLinx Classic communications software. Exploitation can cause the RSLinx Classic service to crash, requiring a restart for recovery. READ MORE...

US charges Russian for infecting 80,000 freelancers with malware

A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware. 40-year-old Searzhudin Tamirlanovich Aktulaev was extradited to the United States after being arrested in Cyprus in May 2025. According to court documents filed in June 2021 and unsealed this week, Aktulaev allegedly infected thousands of users by exploiting an online messaging platform in phishing attacks. READ MORE...

23-Year-Old Sality P2P Botnet Disrupted

After 23 years of operation, the Sality peer-to-peer (P2P) botnet has been disrupted as part of an international law enforcement effort. First observed in 2003, Sality has been used for distributing various malware families, including information stealers, proxy services, distributed denial-of-service (DDoS) payloads, and more. For the past eight years, it mainly served the EggJagger clipjacking tool, which is believed to have stolen at least $150,000 in Bitcoin and Ethereum. READ MORE...

  • ...in 1752, Great Britain adopts the Gregorian calendar.
  • ...in 1929, film director Hal Ashby ("Harold and Maude", "Being There") is born in Ogden, UT.
  • ...in 1945, Japan formally surrenders to the Allied powers, with Foreign Minister Mamoru Shigemitsu signing the agreement aboard the battleship USS Missouri in Tokyo Bay.
  • ...in 1963, the CBS Evening News becomes US network television's first half-hour weeknight news broadcast.