<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 9/28/2026

SHARE

Breaches

DC Health Agency Exposes 400,000 Beneficiary Records

The District of Columbia Department of Health Care Finance (DHCF) is notifying nearly 400,000 people that their personal information was potentially compromised in a data breach. According to the agency, the incident impacts Medicaid and the DC Healthcare Alliance beneficiaries who enrolled between 2023 and 2026. The data breach was not the result of hacking. Instead, DHCF discovered in July that its website contained hidden personal information accessible to unauthorized individuals. READ MORE...

Hacking

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims. Cameron John Wagenius, 22, was stationed at a U.S. Army base in South Korea when he adopted the cybercriminal persona "Kiberphant0m." READ MORE...

Trends

80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking

The summer of 2026 taught the security industry a new phrase: the stolen AI login. In late August, as BleepingComputer reported, Anthropic responded to infostealer-driven hijacking of Claude sessions by signing users out, wiping saved payment methods, and refunding charges it identified as unauthorized. That is the supply side. SOCRadar's AI Identity Exposure Report goes after the demand side: the enterprises whose employees are the credentials being sold. READ MORE...


AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment

In 1983, WarGames imagined a teenager accessing military systems and nearly triggering a nuclear conflict. The cultural impact was immediate. Congress held hearings, policymakers questioned whether such a scenario was possible, and concerns about computer security entered the mainstream. Recent disclosures from OpenAI and Anthropic described cybersecurity agents reaching beyond the boundaries of the test environments designed to contain them. READ MORE...

Information Security

Is that vibe coded app safe? 5 checks before you download

AI platforms are transforming many industries. But perhaps none more so than software development. "Vibe coding" was only coined as a term in February 2025. Yet just a few months later, one report suggested 84% of developers were using or planning to use AI tools for work. On paper, it's obvious why they are doing so. AI does the heavy lifting, allowing the developer to let their creativity flourish. But in so doing, vibe coding tools also lower the barriers to entry for novices. READ MORE...

Exploits/Vulnerabilities

"Drunk" AI is terrible at keeping secrets

AI models taught to write like drunk people became easier to jailbreak and more likely to leak secrets shared in confidence. That is the finding of UNSW Sydney researchers Anudeex Shetty, Aditya Joshi and Salil Kanhere, published in their paper "In Vino Veritas and Vulnerabilities." "The key research question from the natural language processing (NLP) side for me was, how do we get LLMs drunk?" said Aditya Joshi, a senior lecturer at the UNSW School of Computer Science and Engineering. READ MORE...


Quantum random numbers can pass the tests and still leak clues to attackers

The European Telecommunications Standards Institute's (ETSI) technical report, ETSI TR 104 171, offers guidance on building and evaluating quantum random number generators (QRNGs). It focuses on weaknesses in the devices and their supporting systems that could make the numbers they produce less secure. A QRNG measures a quantum process and turns the raw results into usable random numbers. Cryptographic systems rely on unpredictable numbers to generate keys and perform other security functions. READ MORE...


Elementor WordPress flaw lets attackers create admin accounts

A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. Threat actors can exploit the flaw by tricking a logged-in administrator into opening a malicious link, causing the victim's authenticated session to perform a REST API action permitted by their account. On default installations, the result is the creation of an administrator account under the control of the attacker. READ MORE...


Certainties in life: Death, taxes, and critical Citrix vulns under attack

Death and taxes are said to be the only certainties in life. Perhaps it's time to add attackers targeting newly discovered critical flaws in Citrix's NetScaler application delivery controller and gateway products to that grim list. On Sunday, the company published a bulletin warning of eight CVEs, the worst of which - CVE-2026-88771 and CVE-2026-88772 - are rated critical with 9.5 CVSS scores. READ MORE...

On This Date

  • ...in 1867, the US takes control of Midway Island.
  • ...in 1924, a team of US Army aviators completes the first ever aerial circumnavigation of the world, covering 27,553 miles in 175 days.
  • ...in 1959, Explorer VI, the U.S. satellite, takes the first video pictures of Earth.
  • ...in 2008, SpaceX launches the first private spacecraft, Falcon 1.