IT Security Newsletter - 9/24/2026
FBI probes cyberattack tied to third-party jobs portal
The FBI is investigating a cyberattack on its jobs portal after the cybercrime group ShinyHunters said it hacked the system and stole a vast trove of sensitive data from the bureau. "The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII)," the bureau said in a statement on Wednesday READ MORE...
Astrana Health Data Breach Impacts Private, Confidential Information
Astrana Health says private and confidential information was stolen from its servers after employees were targeted in a social engineering attack. Astrana Health is a California-based physician-centric healthcare management company that provides back-office services, including claims and billing. The incident involved the company's subsidiary Astrana Health Management, according to a filing with the US Securities and Exchange Commission (SEC). READ MORE...
Academic publisher Elsevier hit by LAPSUS$ redirect attack
Academic publishing giant Elsevier confirmed a compromise this week after students found its platform redirecting users to a cybercriminal crew's leak page. One Reddit user, a self-described nursing student, highlighted the issue on September 22, posting a screenshot of LAPSUS$'s leak site after trying to access "homework and textbooks." "Every time I try to open the Elsevier website, I am met with this," they wrote. "Anyone know anything or have any explanation? Totally creepy." READ MORE...
Ghost Service Accounts Enable M365 Data Theft in Chile
Hackers are leveraging overlooked machine accounts in Microsoft 365 (M365) to steal enterprise data from organizations in Chile. Within any organization's M365 environment, there are accounts that belong to humans, sure, but also shared functional identities and accounts for applications and automated processes. ndividuals are responsible for their own identities, but who keeps track of, maintains, and secures those nonhuman ones? READ MORE...
Ubuntu kernel CVE fixes are moving to a weekly release schedule
Ubuntu kernels will ship every week under a new release schedule from Canonical, which is merging its four-week cycle for regular Stable Release Updates (SRUs) and its two-week cycle for security fixes into a single two-week cycle. The cycles overlap, each starting a week after the one before, which is what produces a weekly release. Admins who need a kernel CVE fix sooner than the full cycle allows now have a sanctioned way to get one within a week. READ MORE...
Ukrainian ransomware developer jailed for nearly 13 years
A court in Zurich has sentenced a Ukrainian man to 12 years and nine months in prison, and banned him from Switzerland for ten years, for developing ransomware that blackmailed companies around the world. The 52-year-old man, who according to local media reports had been living in the Basel-Landschaft region but has not been named, found by the court to be the lead developer of the LockerGoga, MegaCortex, and Nefilim families of ransomware. READ MORE...
Ryuk ransomware operator sentenced to 2 years in prison
A35-year-old Armenian national was sentenced to two years in prison for his involvement in a series of Ryuk ransomware attacks while living in Ukraine and Russia in 2019 and 2020, the Justice Department said Tuesday. Karen Vardanyan was extradited from Ukraine to the United States last year and pleaded guilty to computer fraud and conspiracy to commit fraud and extortion in July. Vardanyan's sentencing also calls for about $1.2 million in restitution to victims. READ MORE...
Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios
In a summer filled with revelations about artificial intelligence's rapid development, researchers were especially alarmed by runaway bots finding their way onto the internet and, in at least one instance, coordinating there with one another. Could a swarm of AI agents take over the entire internet? It's a possibility that could be only six to 12 months away, Anthropic CEO Dario Amodei said in his essay this month calling for the industry to slow down the technology's development. READ MORE...
Hackers now exploit critical Roundcube flaw in code injection attacks
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. Roundcube Webmail is a browser-based IMAP email client used as the default mail interface by thousands of services with millions of users, and it is pre-installed with the widely used cPanel web hosting control panel. READ MORE...
- ...in 1852, Henri Giffard made the first ever powered and controlled flight in his hydrogen-filled dirigible, travelling 27 km from Paris to Elancourt.
- ...in 1893, blues singer Lemon Henry Jefferson, AKA "Blind Lemon" Jefferson, is born in Coutchman, TX.
- ...in 1948, comedian and actor Phil Hartman ("Saturday Night Live", "The Simpsons") is born in Brantford, Ontario.
- ...in 1968, TV newsmagazine "60 Minutes" debuts on CBS.








