IT Security Newsletter

IT Security Newsletter - 9/29/2026

Written by Cadre | Tue, Sep 29, 2026

Pentagon Personnel Agency Data Breach Impacts 3 Million People

The US Defense Manpower Data Center (DMDC), which maintains personnel records for the Pentagon, has started notifying people that their personal information was exposed. According to the DMDC's notice, unauthorized users had access to one of its file-sharing servers for roughly nine months. A copy of the notification letter, dated September 18 and shared online by a recipient, says the problem was discovered in mid-July. READ MORE...

Hackers exploit SQL injection flaw to steal patient data from Polish medical software provider

Hackers stole patient data from Qbusoft, a Polish medical software maker, weeks after a breach at another provider exposed records of nearly 19 million people in the country. The data comes from Medyc, a platform the company sells to medical offices and clinics to manage patient registration, records and prescriptions. In August, attackers stole data on nearly 19 million people from MyDr, a Warsaw-based company whose software is used by about 12,000 healthcare facilities. READ MORE...

Dutch Police Arrest 'Reformed' Hacker in Shiny Hunters Investigation

Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p. READ MORE...

AI Agents Are Privileged Users, Who Is Auditing Their Access?

Enterprises spend heavily protecting the human perimeter. Security teams deploy phishing-resistant multifactor authentication (MFA), enforce rigid conditional access policies, and scrutinize every login from an unexpected IP address. Yet while we closely monitor the human employee, engineering teams are quietly granting broad production access to autonomous AI agents, which often operate as non-human identities (NHIs) backed by service accounts, API tokens, or delegated cloud permissions. READ MORE...

Kiteworks patches critical flaw, brings customer systems online

American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. Formerly known as Accellion, it operates a Private Content Network (PCN) that integrates enterprise email, file sharing, Managed File Transfer (MFT), APIs, and web forms into a single platform. Kiteworks provides services to thousands of global corporations and government agencies, and its Private Data Network has over 100 million end-users. READ MORE...

Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings

Citrix took most of the weekend to confirm that attackers were actively exploiting the newest round of NetScaler zero-days, leaving network defenders and threat hunters to react without official confirmation. Yet, behind the scenes, multiple CERTs, advisory firms, insurance providers, researchers and chatty security professionals warned their respective peers and communities of a live and serious threat. READ MORE...

Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

A newly discovered ClickFix campaign is relying on ChatGPT Custom GPTs to impersonate legitimate products and lure victims into executing malicious code on their machines. Custom GPTs are personalized versions of ChatGPT that may include specific instructions and tools. They are hosted on ChatGPT.com, and their pages feature their custom names at the top, along with the builder's profile. READ MORE...

Meta's Muse sent a Facebook Marketplace buyer to a seller's home

A Facebook Marketplace buyer arrived at a seller's apartment to collect a keyboard. The seller wasn't home and didn't know anyone was coming. Meta's AI assistant Muse had handled the conversation, shared his address, and arranged the visit without telling him. We often write about AI misalignment and how to use AI agents and browsers safely. That can sound theoretical, but this is an example of the real-world risk when an agent is allowed to act on someone's behalf. READ MORE...

The devil is still in the email - but wears a new mask

Many of today's phishing attempts are no longer betrayed by poor grammar, a sketchy URL or a crude login page. To be sure, it does still pay to look out for these red flags, but their absence doesn't make a message legitimate. Modern social engineering schemes are increasingly designed to withstand scrutiny and to provide reassurance where an attack might once have left some giveaways. By extension, email-borne threats in particular are now built to meet as little resistance as possible. READ MORE...

Apple patches CoreGraphics zero-day flaw exploited in attacks

Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. Tracked as CVE-2026-20700, this flaw stems from an out-of-bounds write weakness discovered by Meta Product Security in CoreGraphics, a framework used for two-dimensional vector graphics, image rendering, and text drawing across iOS, macOS, iPadOS, watchOS, and tvOS. READ MORE...

One Packet Can Crash OT Servers in Industrial Sectors

A newly disclosed flaw in an open source database used in industrial and Internet of Things (IoT) environments could let unauthenticated attackers crash vulnerable servers with a single specially crafted network packet. The zero-day vulnerability, tracked as CVE-2026-42542 affects TDengine, a time-series database that organizations in sectors like manufacturing, energy, automotive, and IoT use to store and analyze large volumes of data collected over time. READ MORE...

  • ...in 1942. actor Ian McShane ("Deadwood", "Lovejoy") is born in Lancashire, England.
  • ...in 1963, Les Claypool, bass player and lead singer of alternative rock band Primus, is born in Richmond, CA.
  • ...in 1966, Chevrolet introduces the Camaro, which went on to become one of the iconic "muscle cars" of the mid-20th century.
  • ...in 1988, Stacy Allison of Portland, OR becomes the first American woman to reach the summit of Mount Everest.