<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 9/30/2026

SHARE

Top News

Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond

Agroup of Russian government hackers is refining its attacks to make it easier to eavesdrop on victims and significantly expand its targets among governments, think tanks and nonprofits around the world, with an emphasis on Ukraine, Microsoft research published Tuesday concludes. The company examined a change in the approach of a group it calls Star Blizzard, which is affiliated with the Russian Federal Security Service (FSB), and its novel malware, RedFlick. READ MORE...

Breaches

Automated AI agent used to breach cybersecurity nonprofit DIVD

The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as "loud and very, very messy." Evidence uncovered during the ongoing investigation indicates the attacker exploited a vulnerability, but the attack's purpose and impact remain unclear at this stage. DIVD is a nonprofit organization of volunteer security researchers that scans the internet for systems affected by known vulnerabilities and notifies their owners. READ MORE...

Hacking

Former US Air Force members behind million-dollar BEC scheme head to prison

Two men who ran BEC and phishing campaigns against US businesses while serving in the Air Force have been sentenced to a combined 189 months in federal prison. According to public documents and evidence presented at sentencing, Chijioke Timothy Odimegwu, 25, and Harafat Mogaji, 26, both from Delaware, spent nearly two years sending spam and phishing emails to businesses around the US to steal usernames and passwords for employee email accounts. READ MORE...

Trends

Your car's app could be telling Big Tech who you are and where you go

A study testing 21 cars from 19 brands and 30 companion apps found connections to advertising and tracking companies, and evidence that some apps shared sensitive personal data. Modern cars can unlock remotely, route around traffic, stream entertainment, summon roadside help, and cool or heat the cabin before you get in. But those conveniences come with a privacy cost that drivers may struggle to see and are unable to refuse. READ MORE...

Software Updates

TeamViewer urges users to patch severe flaws "as soon as possible"

Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. The highest-severity flaw is a remote session access control bypass (CVE-2026-92370) stemming from an improper access control weakness in TeamViewer Full Client and Host software for Windows, Linux, and macOS that could let remote threat actors perform unauthorized actions leading to remote code execution on targeted systems. READ MORE...


High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

The developers of the OpenSSL and WolfSSL open source cryptographic libraries announced patches for roughly a dozen vulnerabilities each, including high-severity flaws. Of the 14 vulnerabilities fixed in OpenSSL, one has been assigned a high severity rating. Tracked as CVE-2026-84782, it could allow a remote peer to obtain fragments of heap memory or crash applications that use Datagram TLS (DTLS), a protocol commonly found in VPNs, VoIP and IoT products. READ MORE...


Chrome, Firefox Updates Patch Over 100 Vulnerabilities

Google and Mozilla on Tuesday announced fresh Chrome and Firefox updates that address over 100 vulnerabilities. The latest Chrome release was rolled out with fixes for 32 security defects, including a critical-severity buffer overflow issue in ANGLE tracked as CVE-2026-102331 and reported by an external researcher. Google addressed 25 high-severity security weaknesses, most of which are uninitialized resource and use-after-free vulnerabilities. READ MORE...

Information Security

South Africa Seeks Help After Cyberattack Targets Air Traffic Control

The South African state-owned company that provides air traffic control (ATC) and weather operations for approximately 10% of the world's airspace discovered ransomware-linked malware in an operational technology (OT) network, according to public documents released this month. The company, Air Traffic and Navigation Services (ATNS), believes that its technical team stopped the attack, but it issued a request for quotes (RFQ) seeking cyber-forensics firms to investigate the incident. READ MORE...


OpenAI's GPT-6 Astra ran supply chain attacks despite being told not to

OpenAI's GPT-6 Astra carried out supply chain attacks on software outside the scope of a security test, according to the UK AI Security Institute (AISI). AISI tested the model before its public release. The tests ran inside a simulation, so no live systems were touched. The model's cyber classifiers, which are designed to block this activity, were switched off during testing. The model completed a supply chain attack in 29.2% of runs, compared with 6.3% for GPT-5.6 Sol and none for GPT-5.5. READ MORE...

Exploits/Vulnerabilities

AI models keep posting screenshots showing sensitive data from inside tech companies

Amid the growing concern about AI models escaping security simulations to hack websites comes word that these "superintelligent" blobs of code have no understanding of privacy or security. Researchers affiliated with Glow Security, a startup whose backers include venture capital funds Sequoia and Greenoaks, have found more than 13,000 sensitive screenshots of corporate software projects from 343 companies that were posted to public GitHub repos by AI models. READ MORE...

On This Date

  • ...in 1927, Babe Ruth hits his 60th home run of the 1927 season and with it sets a record that would stand for 34 years.
  • ...in 1954, the USS Nautilus, the world's first nuclear submarine, is commissioned by the U.S. Navy.
  • ...in 1972, Pro baseball great Roberto Clemente hits his 3,000th and final hit of his career
  • ...in 1980, the original specifications for Ethernet computer networking technologies are published by Xerox with Intel and Digital Equipment Corporation.