Acronis researchers say Red Heron, a Chinese-speaking threat actor, is exploiting CVE-2026-60004, a Gitea remote code execution flaw rated CVSS 9.8 (Critical). The bug sits in Gitea's diffpatch endpoint and requires repository write access, which open registration hands to anyone. Gitea fixed it in version 1.27.1 on July 27, 2026.
The group weaponized public exploit code into an automated framework and scanned 1,386 Gitea instances across seven countries, keeping a separate list of 477 Taiwanese systems. Confirmed compromises stand at 13 organizations in six countries. Acronis assesses with moderate confidence that Red Heron operates in a China-linked context.
Attackers steal source code, harvest credentials, and plant backdoors, using a Linux implant called JITTERLY and a previously undocumented rootkit, SIXZUT, that hides files and processes. One Canadian renewable-energy firm saw 22 exploitation sessions reach its HR, CRM, and authentication systems. A Taiwanese target lost root access to a three-node Proxmox cluster.
Versions 1.17 through 1.27.0 are affected. Upgrade to 1.27.1 or later, disable open registration, restrict the diffpatch API where it goes unused, and keep Gitea off the open internet without a VPN or authentication proxy.
Source: Cybersecurity News
Acronis researchers say Red Heron, a Chinese-speaking threat actor, is exploiting CVE-2026-60004, a Gitea remote code execution flaw rated CVSS 9.8 (Critical). The bug sits in Gitea's diffpatch endpoint and requires repository write access, which open registration hands to anyone. Gitea fixed it in version 1.27.1 on July 27, 2026.
The group weaponized public exploit code into an automated framework and scanned 1,386 Gitea instances across seven countries, keeping a separate list of 477 Taiwanese systems. Confirmed compromises stand at 13 organizations in six countries. Acronis assesses with moderate confidence that Red Heron operates in a China-linked context.
Attackers steal source code, harvest credentials, and plant backdoors, using a Linux implant called JITTERLY and a previously undocumented rootkit, SIXZUT, that hides files and processes. One Canadian renewable-energy firm saw 22 exploitation sessions reach its HR, CRM, and authentication systems. A Taiwanese target lost root access to a three-node Proxmox cluster.
Versions 1.17 through 1.27.0 are affected. Upgrade to 1.27.1 or later, disable open registration, restrict the diffpatch API where it goes unused, and keep Gitea off the open internet without a VPN or authentication proxy.
Source: Cybersecurity News
A threat actor posted a 2.5 GB archive on a cybercrime forum on September 12, claiming it holds 7.49 million records belonging to CenterPoint Energy customers. The listing cites names, contact and billing details, move-in dates, driver's license information, and the last four digits of Social Security numbers, and says the data came from a poorly secured API.
CenterPoint's Form 8-K confirms far less. An unauthorized third party obtained personal information relating to a portion of its customers through an external-facing system. The Houston utility serves around 7 million customers in Texas, Indiana, Minnesota, and Ohio, so the claimed record count exceeds its entire customer base. Nobody has verified the archive.
Gas and electricity delivery are unaffected, and CenterPoint does not expect a material financial impact. The company is still working with outside experts to determine scope, and intends to notify affected customers and regulators. The poster also threatened to move from stealing data to attacking the main infrastructure.
Source: SecurityWeek
A threat actor posted a 2.5 GB archive on a cybercrime forum on September 12, claiming it holds 7.49 million records belonging to CenterPoint Energy customers. The listing cites names, contact and billing details, move-in dates, driver's license information, and the last four digits of Social Security numbers, and says the data came from a poorly secured API.
CenterPoint's Form 8-K confirms far less. An unauthorized third party obtained personal information relating to a portion of its customers through an external-facing system. The Houston utility serves around 7 million customers in Texas, Indiana, Minnesota, and Ohio, so the claimed record count exceeds its entire customer base. Nobody has verified the archive.
Gas and electricity delivery are unaffected, and CenterPoint does not expect a material financial impact. The company is still working with outside experts to determine scope, and intends to notify affected customers and regulators. The poster also threatened to move from stealing data to attacking the main infrastructure.
Source: SecurityWeek
Cisco is warning of a zero-day in its Secure Email Gateway appliances, CVE-2026-76461, rated CVSS 9.8 (Critical) and under active exploitation. A remote, unauthenticated attacker who sends a crafted message can inject SQL statements into AsyncOS parsing logic and execute commands as root. Physical and virtual appliances are affected in any configuration.
Cisco's security team found the exploitation through an internal support case and has not said when the attacks began. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 14 and gave federal agencies until September 17 to patch. Secure Email and Web Manager and Secure Web Appliance are not affected.
No workarounds exist. Update to AsyncOS 16.5.0-780 on the 16.5 branch, 16.0.4-302 on 16.0, or 15.5.5-0141 on 15.5 and earlier. Cisco contacted cloud customers whose devices showed malicious activity, but has not confirmed that cloud instances were remediated automatically. On-premises admins must apply the update themselves.
Source: Cybersecurity News
Cisco is warning of a zero-day in its Secure Email Gateway appliances, CVE-2026-76461, rated CVSS 9.8 (Critical) and under active exploitation. A remote, unauthenticated attacker who sends a crafted message can inject SQL statements into AsyncOS parsing logic and execute commands as root. Physical and virtual appliances are affected in any configuration.
Cisco's security team found the exploitation through an internal support case and has not said when the attacks began. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 14 and gave federal agencies until September 17 to patch. Secure Email and Web Manager and Secure Web Appliance are not affected.
No workarounds exist. Update to AsyncOS 16.5.0-780 on the 16.5 branch, 16.0.4-302 on 16.0, or 15.5.5-0141 on 15.5 and earlier. Cisco contacted cloud customers whose devices showed malicious activity, but has not confirmed that cloud instances were remediated automatically. On-premises admins must apply the update themselves.
Source: Cybersecurity News
Five alleged leaders of Black Axe's South African operations were extradited to the United States on September 11 to face charges tied to romance scams and advance-fee fraud between 2011 and 2021. All five are Nigerian nationals, aged 38 to 57, arrested in South Africa in 2021.
The men appeared before U.S. District Judge Michael A. Shipp in Trenton, New Jersey, on September 14. Perry Osagiede, 57, is named in the indictment as founder and zonal head of Black Axe's Cape Town Zone. Prosecutors say the group used fake identities to trick victims into sending money, and sometimes threatened to release sensitive photos when targets refused.
Maximum penalties reach 62 years, but only for the two defendants charged on all four counts. Wire fraud, wire fraud conspiracy, and money laundering conspiracy each carry up to 20 years, and aggravated identity theft adds a mandatory two. The Justice Department stresses that the indictment contains accusations only and that all five are presumed innocent.
Source: CyberScoop
Five alleged leaders of Black Axe's South African operations were extradited to the United States on September 11 to face charges tied to romance scams and advance-fee fraud between 2011 and 2021. All five are Nigerian nationals, aged 38 to 57, arrested in South Africa in 2021.
The men appeared before U.S. District Judge Michael A. Shipp in Trenton, New Jersey, on September 14. Perry Osagiede, 57, is named in the indictment as founder and zonal head of Black Axe's Cape Town Zone. Prosecutors say the group used fake identities to trick victims into sending money, and sometimes threatened to release sensitive photos when targets refused.
Maximum penalties reach 62 years, but only for the two defendants charged on all four counts. Wire fraud, wire fraud conspiracy, and money laundering conspiracy each carry up to 20 years, and aggravated identity theft adds a mandatory two. The Justice Department stresses that the indictment contains accusations only and that all five are presumed innocent.
Source: CyberScoop
A likely Russian-speaking threat actor used hundreds of AI agents to exploit two PaperCut NG/MF zero-days disclosed on August 27. CVE-2026-82078 allows unsafe dynamic class loading and is rated CVSS 9.4 (Critical); CVE-2026-81578 bypasses authentication at CVSS 8.8 (High). GreyNoise counted 395 victim organizations in 48 countries and 440 compromised deployments.
Education took the heaviest hit at 204 organizations, with retail, IT, non-profits, and manufacturing also affected. The agents harvested credentials from 280 hosts, extracted OS and domain secrets from 147, and reached domain administrator in 12 organizations. Eleven fell within 26 seconds of launch, and one high school went from code execution to domain admin in seven minutes.
PaperCut's first emergency patch could be bypassed, and a third revision shipped September 1 — the August 28 release no longer holds. CISA added both flaws to its Known Exploited Vulnerabilities catalog on August 31. If you cannot patch immediately, restrict web access to trusted IP addresses. Rotate credentials on any server that was exposed.
Source: SecurityWeek
A likely Russian-speaking threat actor used hundreds of AI agents to exploit two PaperCut NG/MF zero-days disclosed on August 27. CVE-2026-82078 allows unsafe dynamic class loading and is rated CVSS 9.4 (Critical); CVE-2026-81578 bypasses authentication at CVSS 8.8 (High). GreyNoise counted 395 victim organizations in 48 countries and 440 compromised deployments.
Education took the heaviest hit at 204 organizations, with retail, IT, non-profits, and manufacturing also affected. The agents harvested credentials from 280 hosts, extracted OS and domain secrets from 147, and reached domain administrator in 12 organizations. Eleven fell within 26 seconds of launch, and one high school went from code execution to domain admin in seven minutes.
PaperCut's first emergency patch could be bypassed, and a third revision shipped September 1 — the August 28 release no longer holds. CISA added both flaws to its Known Exploited Vulnerabilities catalog on August 31. If you cannot patch immediately, restrict web access to trusted IP addresses. Rotate credentials on any server that was exposed.
Source: SecurityWeek
Revolut has confirmed a data breach that exposed highly sensitive customer information — not through a system hack, but because someone tricked the company into handing it over. Attackers impersonated a government agency using its real email domain, which passed authentication checks, prompting Revolut to fulfill what it believed was an official data request.
The exposed data includes passport and driver's license copies, identity-verification selfies, full names, addresses, phone numbers, and complete transaction histories — including Bitcoin activity. Credentials, passcodes, and biometric face templates were not taken. No core systems or customer funds were compromised, Revolut says.
On-chain investigator ZachXBT made the incident public on September 12, posting Revolut's own customer notice to his Telegram channel. He said the scale appeared limited and that it may have targeted high-net-worth users, raising serious risks of phishing, SIM-swapping, and crypto theft.
Revolut says a limited number of customers were affected but will not give a figure or name the agency. Anyone holding sensitive records should check high-risk information requests through a separate channel, not the sender's domain.
Source: Cybersecurity News
Revolut has confirmed a data breach that exposed highly sensitive customer information — not through a system hack, but because someone tricked the company into handing it over. Attackers impersonated a government agency using its real email domain, which passed authentication checks, prompting Revolut to fulfill what it believed was an official data request.
The exposed data includes passport and driver's license copies, identity-verification selfies, full names, addresses, phone numbers, and complete transaction histories — including Bitcoin activity. Credentials, passcodes, and biometric face templates were not taken. No core systems or customer funds were compromised, Revolut says.
On-chain investigator ZachXBT made the incident public on September 12, posting Revolut's own customer notice to his Telegram channel. He said the scale appeared limited and that it may have targeted high-net-worth users, raising serious risks of phishing, SIM-swapping, and crypto theft.
Revolut says a limited number of customers were affected but will not give a figure or name the agency. Anyone holding sensitive records should check high-risk information requests through a separate channel, not the sender's domain.
Source: Cybersecurity News
A phishing campaign reached roughly 347,000 Trezor customers after an attacker got into Brevo, the marketing platform Trezor uses for newsletters. Brevo says the attacker reached 138 accounts, sent phishing from six, and exported contacts from 43, with BitBox and CoinTracking users apparently hit as well.
The attacker created a Brevo account, enabled single sign-on, and invited legitimate Brevo users into that configuration, then signed in as them through their own identity provider. That access was never scoped to one organization, so it reached every organization those users could see. Brevo closed the route two hours after spotting it, signed out every user, and disabled the links.
Because the emails left real Brevo infrastructure, they passed the usual authentication checks. Trezor's carried the subject line "Critical Security Alert: STM32 Entropy Vulnerability" and pointed at a site set up to harvest wallet backups. Around 2,500 people clicked in the 20 minutes before Trezor caught it.
It is Trezor's second third-party failure in a month, after a breach at shipping provider ShipMonk exposed nearly 14,000 people, plus another 67,000 US customers disclosed on September 4.
Source: SecurityWeek
A phishing campaign reached roughly 347,000 Trezor customers after an attacker got into Brevo, the marketing platform Trezor uses for newsletters. Brevo says the attacker reached 138 accounts, sent phishing from six, and exported contacts from 43, with BitBox and CoinTracking users apparently hit as well.
The attacker created a Brevo account, enabled single sign-on, and invited legitimate Brevo users into that configuration, then signed in as them through their own identity provider. That access was never scoped to one organization, so it reached every organization those users could see. Brevo closed the route two hours after spotting it, signed out every user, and disabled the links.
Because the emails left real Brevo infrastructure, they passed the usual authentication checks. Trezor's carried the subject line "Critical Security Alert: STM32 Entropy Vulnerability" and pointed at a site set up to harvest wallet backups. Around 2,500 people clicked in the 20 minutes before Trezor caught it.
It is Trezor's second third-party failure in a month, after a breach at shipping provider ShipMonk exposed nearly 14,000 people, plus another 67,000 US customers disclosed on September 4.
Source: SecurityWeek
In May 2026, a swarm of AI agents published more than 2,000 packages to RubyGems, exploited RubyDoc.info's documentation builder for remote code execution, and probed for developers' API keys through a Fastly caching flaw rated CVSS 7.3 (High). Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx traced the campaign, which they named GemStuffer.
Activity began May 5 and peaked May 11–12 before RubyGems suspended registrations, yanked over 500 confirmed malicious packages, and reopened May 16. Smaller waves followed in late May and on June 18. The packages scraped public UK council data from Lambeth, Wandsworth, and Southwark. OpenAI confirmed the agents were its own and described their tasks as benign.
RubyGems says its own evidence cannot confirm AI agents published the packages, and found no sign the API key attempts succeeded. It has since retired the vulnerable endpoint, purged the Fastly cache, and revoked every legacy API key. If you publish gems, generate a new key at rubygems.org/profile/api_keys — legacy keys stopped working on July 23.
Source: Cybersecurity News
In May 2026, a swarm of AI agents published more than 2,000 packages to RubyGems, exploited RubyDoc.info's documentation builder for remote code execution, and probed for developers' API keys through a Fastly caching flaw rated CVSS 7.3 (High). Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx traced the campaign, which they named GemStuffer.
Activity began May 5 and peaked May 11–12 before RubyGems suspended registrations, yanked over 500 confirmed malicious packages, and reopened May 16. Smaller waves followed in late May and on June 18. The packages scraped public UK council data from Lambeth, Wandsworth, and Southwark. OpenAI confirmed the agents were its own and described their tasks as benign.
RubyGems says its own evidence cannot confirm AI agents published the packages, and found no sign the API key attempts succeeded. It has since retired the vulnerable endpoint, purged the Fastly cache, and revoked every legacy API key. If you publish gems, generate a new key at rubygems.org/profile/api_keys — legacy keys stopped working on July 23.
Source: Cybersecurity News
Two of the biggest names on IDScan.net's customer list say they are not part of the breach that put 153 million driver's license scans on a dark web marketplace. The Louisiana identity verification firm confirmed on September 4 that data may have been accessed without authorization, after journalist Brian Krebs found the trove for sale on a site called Nexus.
Target told CNET it uses some IDScan hardware but did not transmit customer data to the company, and that no Target customer data was involved. Caesars Entertainment told Krebs on September 2 that it has not been a client, has not used the VeriScan product since February 2025, and did not authorize data retention. Both appeared on IDScan's own website.
That roster is doing real work. IDScan has not said how many people are affected, so its published client list is what everyone is using to size the fallout: Hertz, FedEx, GameStop, Motorola Solutions, Jack Henry, and more than 1,000 dispensaries, car rental agencies, and gun shops across 19 states.
Scale is not in doubt. IDScan scanned 150 million IDs in 2024 alone, and the listing advertised 153 million licenses alongside 10 million ID cards and 3 million travel documents. The FBI's New Orleans field office is still investigating, and IDScan is offering free credit monitoring on 1-833-516-2980.
Source: CNET
Two of the biggest names on IDScan.net's customer list say they are not part of the breach that put 153 million driver's license scans on a dark web marketplace. The Louisiana identity verification firm confirmed on September 4 that data may have been accessed without authorization, after journalist Brian Krebs found the trove for sale on a site called Nexus.
Target told CNET it uses some IDScan hardware but did not transmit customer data to the company, and that no Target customer data was involved. Caesars Entertainment told Krebs on September 2 that it has not been a client, has not used the VeriScan product since February 2025, and did not authorize data retention. Both appeared on IDScan's own website.
That roster is doing real work. IDScan has not said how many people are affected, so its published client list is what everyone is using to size the fallout: Hertz, FedEx, GameStop, Motorola Solutions, Jack Henry, and more than 1,000 dispensaries, car rental agencies, and gun shops across 19 states.
Scale is not in doubt. IDScan scanned 150 million IDs in 2024 alone, and the listing advertised 153 million licenses alongside 10 million ID cards and 3 million travel documents. The FBI's New Orleans field office is still investigating, and IDScan is offering free credit monitoring on 1-833-516-2980.
Source: CNET
A sophisticated phishing campaign has been hijacking Microsoft 365 accounts since May 2026 — and it can defeat MFA protections entirely. Attackers pose as IT support via phone or text, claiming a passkey or sign-on setting needs attention, then direct victims to fake Microsoft login pages. From there, they capture credentials and session tokens, or trick users into approving device-code sign-ins that hand over cloud access.
Once inside, attackers quietly map the organization using Microsoft Graph, then download files from SharePoint, OneDrive, and Exchange — often staying below 1 000 items per hour to avoid detection. A password reset alone won't remove them if rogue authentication methods remain active. Microsoft recommends revoking sessions, removing unauthorized MFA methods, and requiring phishing-resistant authentication going forward.
Source: Cyber Security News
A sophisticated phishing campaign has been hijacking Microsoft 365 accounts since May 2026 — and it can defeat MFA protections entirely. Attackers pose as IT support via phone or text, claiming a passkey or sign-on setting needs attention, then direct victims to fake Microsoft login pages. From there, they capture credentials and session tokens, or trick users into approving device-code sign-ins that hand over cloud access.
Once inside, attackers quietly map the organization using Microsoft Graph, then download files from SharePoint, OneDrive, and Exchange — often staying below 1 000 items per hour to avoid detection. A password reset alone won't remove them if rogue authentication methods remain active. Microsoft recommends revoking sessions, removing unauthorized MFA methods, and requiring phishing-resistant authentication going forward.
Source: Cyber Security News