IT Security Newsletter - 9/25/2026
'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
Vulnerabilities in Salesforce Agentforce, collectively dubbed "Salesbleed" by researchers, could expose customers' internal data and, worse, allow attackers to phish employees from within trusted company channels. As so often happens with powerful, interconnected AI platforms that excite customers and investors, security and visibility remain hard problems to solve. READ MORE...
Russia's Hybrid Cyber-Physical War in Europe Heats Up
Russia continues to ramp up hybrid, asymmetric efforts to target its adversaries across Europe in both virtual and physical space, in support of its invasion of Ukraine, which began in February 2022. That's according to Recorded Future, which found that the activity stops short of a kinetic, boots-on-the-ground invasion, instead involving a number of psychological, cyber, and physical tactics intended to test enemy defenses, degrade critical infrastructure, and foster fear. READ MORE...
Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges
Law enforcement has arrested two leaders of a Russian-owned phone hacking company used by Kremlin agencies who allegedly masked its foreign ownership from the U.S. Defense Department, Department of Homeland Security and others to win millions of dollars worth of contracts, the Justice Department announced Wednesday. Lee Reiber, CEO of Oxygen Forensics, was arrested in his home state and Oleg Davydov, one of five Russian nationals whom [allegedly] controlled the company was arrested in London. READ MORE...
Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs
A crook has been using three open source AI harnesses to target hundreds of online retailers and other companies, swiping more than 600,000 credit card records and installing card-stealing skimmers - and all at trivial cost. AI security company Gambit recovered the human operator's staging server, and used that access to reconstruct the data-theft campaign, whose victims include a Fortune 500 company, a major US airline, a large US industrial supplies distributor, and a US fashion retailer. READ MORE...
North Korea Suspected in $351 Million Bitget Crypto Heist
Cryptocurrency exchange Bitget says the hackers who stole roughly $351.6 million in digital assets from its systems used techniques that closely resemble those of known North Korean threat actors. "Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations," Bitget CEO Gracy Chen said in a Friday post on X. READ MORE...
New Carbonato malware uses AI agents to hijack exposed Docker hosts
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. The malware features worm-like capabilities and was discovered in an unauthenticated Docker registry that contained nearly 60 repositories and 4.3 GB of image data. Researchers at enterprise security company ThreatDown retrieved operational evidence spanning October 2024 to August 2026. READ MORE...
MacSync info-stealing malware hides malicious commands in an iCloud calendar
A new MacSync variant targets Mac users with an infostealer and persistent backdoor designed to steal credentials, crypto wallet data, and files, according to Kaspersky. Researchers found the malware spreading through a crypto wallet app called Toria, which had its own website and was promoted on X and Telegram. MacSync is a family of Mac malware that emerged in 2025 as Mac.c and was later renamed. READ MORE...
Rydox marketplace admin pleads guilty, faces 22 years in prison
A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. Kosovo law enforcement and Albania's Special Anti-Corruption Body (SPAK) arrested 28-year-old Ardit Kutleshi and two other Rydox administrators (Jetmir Kutleshi and Shpend Sokoli) in December 2024. READ MORE...
Fake payroll desktop apps hand attackers a route to company paychecks
An attacker has been offering "desktop apps" for three large US payroll and HR platforms that have never released one, Allure Security have found. Anyone who runs the installer gets a copy of ScreenConnect, a legitimate remote access tool, configured to let the attacker control the computer without the user knowing. According to Ryan Merritt, Director of Security Research at Allure Security, all three providers deliver their products as web applications accessed through a browser. READ MORE...
Windows, Linux, Android File Notification Systems Leak User Activity
Researchers at Graz University of Technology in Austria show that the file-change notification features built into Linux, Android, Windows, and macOS can be abused to monitor other users on the same system, from the rhythm of their typing to the websites they visit. Linux, Windows, macOS, and Android let applications ask to be alerted when files are created, modified, or deleted. Text editors, file managers, sync clients, and antivirus products are among the programs that use this capability. READ MORE...
- ...in 1911, ground is broken in Boston, MA for Fenway Park.
- ...in 1930, writer and illustrator Shel Silverstein ("The Giving Tree", "Where the Sidewalk Ends") is born in Chicago, IL.
- ...in 1951, actor Mark Hamill, best known as Luke Skywalker in "Star Wars", (as well as the voice of the Joker on "Batman: The Animated Series") is born in Oakland, CA.
- ...in 1956, TAT-1, the first transatlantic telephone cable system is inaugurated, stretching between Scotland and Newfoundland.






