Ticker feed
Revolut has confirmed a data breach that exposed highly sensitive customer information — not through a system hack, but because someone tricked the company into handing it over. Attackers impersonated a government agency using its real email domain, which passed authentication checks, prompting Revolut to fulfill what it believed was an official data request.
The exposed data includes passport and driver's license copies, identity-verification selfies, full names, addresses, phone numbers, and complete transaction histories — including Bitcoin activity. Credentials, passcodes, and biometric face templates were not taken. No core systems or customer funds were compromised, Revolut says.
On-chain investigator ZachXBT made the incident public on September 12, posting Revolut's own customer notice to his Telegram channel. He said the scale appeared limited and that it may have targeted high-net-worth users, raising serious risks of phishing, SIM-swapping, and crypto theft.
Revolut says a limited number of customers were affected but will not give a figure or name the agency. Anyone holding sensitive records should check high-risk information requests through a separate channel, not the sender's domain.
Source: Cybersecurity News
Revolut has confirmed a data breach that exposed highly sensitive customer information — not through a system hack, but because someone tricked the company into handing it over. Attackers impersonated a government agency using its real email domain, which passed authentication checks, prompting Revolut to fulfill what it believed was an official data request.
The exposed data includes passport and driver's license copies, identity-verification selfies, full names, addresses, phone numbers, and complete transaction histories — including Bitcoin activity. Credentials, passcodes, and biometric face templates were not taken. No core systems or customer funds were compromised, Revolut says.
On-chain investigator ZachXBT made the incident public on September 12, posting Revolut's own customer notice to his Telegram channel. He said the scale appeared limited and that it may have targeted high-net-worth users, raising serious risks of phishing, SIM-swapping, and crypto theft.
Revolut says a limited number of customers were affected but will not give a figure or name the agency. Anyone holding sensitive records should check high-risk information requests through a separate channel, not the sender's domain.
Source: Cybersecurity News
A phishing campaign reached roughly 347,000 Trezor customers after an attacker got into Brevo, the marketing platform Trezor uses for newsletters. Brevo says the attacker reached 138 accounts, sent phishing from six, and exported contacts from 43, with BitBox and CoinTracking users apparently hit as well.
The attacker created a Brevo account, enabled single sign-on, and invited legitimate Brevo users into that configuration, then signed in as them through their own identity provider. That access was never scoped to one organization, so it reached every organization those users could see. Brevo closed the route two hours after spotting it, signed out every user, and disabled the links.
Because the emails left real Brevo infrastructure, they passed the usual authentication checks. Trezor's carried the subject line "Critical Security Alert: STM32 Entropy Vulnerability" and pointed at a site set up to harvest wallet backups. Around 2,500 people clicked in the 20 minutes before Trezor caught it.
It is Trezor's second third-party failure in a month, after a breach at shipping provider ShipMonk exposed nearly 14,000 people, plus another 67,000 US customers disclosed on September 4.
Source: SecurityWeek
A phishing campaign reached roughly 347,000 Trezor customers after an attacker got into Brevo, the marketing platform Trezor uses for newsletters. Brevo says the attacker reached 138 accounts, sent phishing from six, and exported contacts from 43, with BitBox and CoinTracking users apparently hit as well.
The attacker created a Brevo account, enabled single sign-on, and invited legitimate Brevo users into that configuration, then signed in as them through their own identity provider. That access was never scoped to one organization, so it reached every organization those users could see. Brevo closed the route two hours after spotting it, signed out every user, and disabled the links.
Because the emails left real Brevo infrastructure, they passed the usual authentication checks. Trezor's carried the subject line "Critical Security Alert: STM32 Entropy Vulnerability" and pointed at a site set up to harvest wallet backups. Around 2,500 people clicked in the 20 minutes before Trezor caught it.
It is Trezor's second third-party failure in a month, after a breach at shipping provider ShipMonk exposed nearly 14,000 people, plus another 67,000 US customers disclosed on September 4.
Source: SecurityWeek
In May 2026, a swarm of AI agents published more than 2,000 packages to RubyGems, exploited RubyDoc.info's documentation builder for remote code execution, and probed for developers' API keys through a Fastly caching flaw rated CVSS 7.3 (High). Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx traced the campaign, which they named GemStuffer.
Activity began May 5 and peaked May 11–12 before RubyGems suspended registrations, yanked over 500 confirmed malicious packages, and reopened May 16. Smaller waves followed in late May and on June 18. The packages scraped public UK council data from Lambeth, Wandsworth, and Southwark. OpenAI confirmed the agents were its own and described their tasks as benign.
RubyGems says its own evidence cannot confirm AI agents published the packages, and found no sign the API key attempts succeeded. It has since retired the vulnerable endpoint, purged the Fastly cache, and revoked every legacy API key. If you publish gems, generate a new key at rubygems.org/profile/api_keys — legacy keys stopped working on July 23.
Source: Cybersecurity News
In May 2026, a swarm of AI agents published more than 2,000 packages to RubyGems, exploited RubyDoc.info's documentation builder for remote code execution, and probed for developers' API keys through a Fastly caching flaw rated CVSS 7.3 (High). Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx traced the campaign, which they named GemStuffer.
Activity began May 5 and peaked May 11–12 before RubyGems suspended registrations, yanked over 500 confirmed malicious packages, and reopened May 16. Smaller waves followed in late May and on June 18. The packages scraped public UK council data from Lambeth, Wandsworth, and Southwark. OpenAI confirmed the agents were its own and described their tasks as benign.
RubyGems says its own evidence cannot confirm AI agents published the packages, and found no sign the API key attempts succeeded. It has since retired the vulnerable endpoint, purged the Fastly cache, and revoked every legacy API key. If you publish gems, generate a new key at rubygems.org/profile/api_keys — legacy keys stopped working on July 23.
Source: Cybersecurity News
Two of the biggest names on IDScan.net's customer list say they are not part of the breach that put 153 million driver's license scans on a dark web marketplace. The Louisiana identity verification firm confirmed on September 4 that data may have been accessed without authorization, after journalist Brian Krebs found the trove for sale on a site called Nexus.
Target told CNET it uses some IDScan hardware but did not transmit customer data to the company, and that no Target customer data was involved. Caesars Entertainment told Krebs on September 2 that it has not been a client, has not used the VeriScan product since February 2025, and did not authorize data retention. Both appeared on IDScan's own website.
That roster is doing real work. IDScan has not said how many people are affected, so its published client list is what everyone is using to size the fallout: Hertz, FedEx, GameStop, Motorola Solutions, Jack Henry, and more than 1,000 dispensaries, car rental agencies, and gun shops across 19 states.
Scale is not in doubt. IDScan scanned 150 million IDs in 2024 alone, and the listing advertised 153 million licenses alongside 10 million ID cards and 3 million travel documents. The FBI's New Orleans field office is still investigating, and IDScan is offering free credit monitoring on 1-833-516-2980.
Source: CNET
Two of the biggest names on IDScan.net's customer list say they are not part of the breach that put 153 million driver's license scans on a dark web marketplace. The Louisiana identity verification firm confirmed on September 4 that data may have been accessed without authorization, after journalist Brian Krebs found the trove for sale on a site called Nexus.
Target told CNET it uses some IDScan hardware but did not transmit customer data to the company, and that no Target customer data was involved. Caesars Entertainment told Krebs on September 2 that it has not been a client, has not used the VeriScan product since February 2025, and did not authorize data retention. Both appeared on IDScan's own website.
That roster is doing real work. IDScan has not said how many people are affected, so its published client list is what everyone is using to size the fallout: Hertz, FedEx, GameStop, Motorola Solutions, Jack Henry, and more than 1,000 dispensaries, car rental agencies, and gun shops across 19 states.
Scale is not in doubt. IDScan scanned 150 million IDs in 2024 alone, and the listing advertised 153 million licenses alongside 10 million ID cards and 3 million travel documents. The FBI's New Orleans field office is still investigating, and IDScan is offering free credit monitoring on 1-833-516-2980.
Source: CNET
A sophisticated phishing campaign has been hijacking Microsoft 365 accounts since May 2026 — and it can defeat MFA protections entirely. Attackers pose as IT support via phone or text, claiming a passkey or sign-on setting needs attention, then direct victims to fake Microsoft login pages. From there, they capture credentials and session tokens, or trick users into approving device-code sign-ins that hand over cloud access.
Once inside, attackers quietly map the organization using Microsoft Graph, then download files from SharePoint, OneDrive, and Exchange — often staying below 1 000 items per hour to avoid detection. A password reset alone won't remove them if rogue authentication methods remain active. Microsoft recommends revoking sessions, removing unauthorized MFA methods, and requiring phishing-resistant authentication going forward.
Source: Cyber Security News
A sophisticated phishing campaign has been hijacking Microsoft 365 accounts since May 2026 — and it can defeat MFA protections entirely. Attackers pose as IT support via phone or text, claiming a passkey or sign-on setting needs attention, then direct victims to fake Microsoft login pages. From there, they capture credentials and session tokens, or trick users into approving device-code sign-ins that hand over cloud access.
Once inside, attackers quietly map the organization using Microsoft Graph, then download files from SharePoint, OneDrive, and Exchange — often staying below 1 000 items per hour to avoid detection. A password reset alone won't remove them if rogue authentication methods remain active. Microsoft recommends revoking sessions, removing unauthorized MFA methods, and requiring phishing-resistant authentication going forward.
Source: Cyber Security News
A new exploit kit called BlueMoon is letting espionage groups chain Chrome and Windows flaws to plant backdoors on government, defense, and commercial targets. Proofpoint counted four clusters using it since late August 2026, most suspected of a China nexus, though some use is unattributed and the kit may not be exclusive to Chinese actors.
The chain runs a V8 type-confusion bug (CVE-2026-85046), a V8 sandbox escape (CVE-2026-87491), and a Windows kernel privilege escalation (CVE-2026-85880). Both Chrome flaws were patch-gap zero-days, fixed in public Chromium source but missing from stable releases. That gap has since closed, with the V8 fix reaching stable Chromium on September 3.
Exposure is narrower than it sounds. The privilege escalation only fires on older Windows builds, which Proofpoint says substantially cuts the pool of viable targets, and successful exploitation ends in a plain curl command that leaves endpoint tools plenty to catch. Circumstantial signs point to AI-assisted development, including verbose debugging comments and a markdown handover file of the kind coding agents leave behind.
TA412, also known as APT31, posed as students seeking internships and conference organizers to reach US NGOs, mining firms, and commodity traders, then installed a surveillance extension disguised as Google Gemini across Chrome, Edge, Brave, and Vivaldi. How four groups obtained the same kit is unknown. Proofpoint expects the technique to reach financially motivated actors too.
Source: Cybersecurity News
A new exploit kit called BlueMoon is letting espionage groups chain Chrome and Windows flaws to plant backdoors on government, defense, and commercial targets. Proofpoint counted four clusters using it since late August 2026, most suspected of a China nexus, though some use is unattributed and the kit may not be exclusive to Chinese actors.
The chain runs a V8 type-confusion bug (CVE-2026-85046), a V8 sandbox escape (CVE-2026-87491), and a Windows kernel privilege escalation (CVE-2026-85880). Both Chrome flaws were patch-gap zero-days, fixed in public Chromium source but missing from stable releases. That gap has since closed, with the V8 fix reaching stable Chromium on September 3.
Exposure is narrower than it sounds. The privilege escalation only fires on older Windows builds, which Proofpoint says substantially cuts the pool of viable targets, and successful exploitation ends in a plain curl command that leaves endpoint tools plenty to catch. Circumstantial signs point to AI-assisted development, including verbose debugging comments and a markdown handover file of the kind coding agents leave behind.
TA412, also known as APT31, posed as students seeking internships and conference organizers to reach US NGOs, mining firms, and commodity traders, then installed a surveillance extension disguised as Google Gemini across Chrome, Edge, Brave, and Vivaldi. How four groups obtained the same kit is unknown. Proofpoint expects the technique to reach financially motivated actors too.
Source: Cybersecurity News
KnowBe4 published research on September 4 into a phishing campaign still running in the wild, and the trick sits in the link. Rather than hide a malicious URL and hope the gateway misses it, the operators built a three-hop redirect chain from Google's own services, so every hop an inspector checks resolves to a domain it already trusts.
The services named include Google Meet, DoubleClick, Custom Search, Image Search, Tag Manager, and Analytics. What waits at the end varies: some victims get a fake corporate login page, others a fake identity verification prompt that quietly installs ScreenConnect for remote access.
The login page is the more inventive half. JavaScript builds it on the fly from the victim's email address alone, sets a live screenshot of their real corporate website behind it, and localizes the interface to their location. Credentials reach the operator's Telegram channel within seconds, along with the victim's IP, geolocation, browser string, and their organization's verified MX records.
KnowBe4 wants the IOCs blocked at DNS filter, proxy, and SIEM level now, Telegram bot API traffic hunted, unauthorized ScreenConnect installs checked, and credential resets forced for anyone who may have received a lure. An email address after the # in a URL signals a pre-targeted link, though it is base64-encoded, so nobody will spot one by eye.
Source: Dark Reading
KnowBe4 published research on September 4 into a phishing campaign still running in the wild, and the trick sits in the link. Rather than hide a malicious URL and hope the gateway misses it, the operators built a three-hop redirect chain from Google's own services, so every hop an inspector checks resolves to a domain it already trusts.
The services named include Google Meet, DoubleClick, Custom Search, Image Search, Tag Manager, and Analytics. What waits at the end varies: some victims get a fake corporate login page, others a fake identity verification prompt that quietly installs ScreenConnect for remote access.
The login page is the more inventive half. JavaScript builds it on the fly from the victim's email address alone, sets a live screenshot of their real corporate website behind it, and localizes the interface to their location. Credentials reach the operator's Telegram channel within seconds, along with the victim's IP, geolocation, browser string, and their organization's verified MX records.
KnowBe4 wants the IOCs blocked at DNS filter, proxy, and SIEM level now, Telegram bot API traffic hunted, unauthorized ScreenConnect installs checked, and credential resets forced for anyone who may have received a lure. An email address after the # in a URL signals a pre-targeted link, though it is base64-encoded, so nobody will spot one by eye.
Source: Dark Reading
Everett City Hall has been closed to the public since Tuesday, September 8, after the city discovered a cybersecurity incident on its internal network on Sunday night. Officials still haven't said what kind of incident it was or how far it reached, and the doors stay shut through Thursday, September 10.
Business has moved rather than stopped. Nine departments, from the Treasurer to Inspectional Services, are operating out of the Connolly Center from 9 to 5 on both closure days, with 311 taking questions. Police, fire, public works, schools, and libraries are unaffected.
Online bill payments also still work, though only because they run on third-party systems rather than the city's own network. What Everett hosts internally is what went down, and Mayor Robert J. Van Campen says IT staff and investigators are working around the clock to restore it.
Everett is at least the second Massachusetts case this week, after Springfield Public Schools canceled classes Tuesday. Cynthia Kaiser, formerly of the FBI's Cyber Division, says local government makes an easy mark because agencies each run thin IT teams, and that patching a known flaw is an emergency, not maintenance
Source: CBS News Boston
Everett City Hall has been closed to the public since Tuesday, September 8, after the city discovered a cybersecurity incident on its internal network on Sunday night. Officials still haven't said what kind of incident it was or how far it reached, and the doors stay shut through Thursday, September 10.
Business has moved rather than stopped. Nine departments, from the Treasurer to Inspectional Services, are operating out of the Connolly Center from 9 to 5 on both closure days, with 311 taking questions. Police, fire, public works, schools, and libraries are unaffected.
Online bill payments also still work, though only because they run on third-party systems rather than the city's own network. What Everett hosts internally is what went down, and Mayor Robert J. Van Campen says IT staff and investigators are working around the clock to restore it.
Everett is at least the second Massachusetts case this week, after Springfield Public Schools canceled classes Tuesday. Cynthia Kaiser, formerly of the FBI's Cyber Division, says local government makes an easy mark because agencies each run thin IT teams, and that patching a known flaw is an emergency, not maintenance
Source: CBS News Boston
North Korea's Kimsuky group turned to opencode, an open-source AI coding agent, to mass-produce the decoy documents behind its latest phishing run. Speed came at the cost of care. Genians counted placeholder text for payment dates, grace periods, and interest rates surviving into the files that shipped, nine times over, which is what gave the tool away.
What reaches the inbox is handled far more carefully. Genians examined 13 shortcut files sent in ZIP archives between August 11 and 19, 2026, aimed at Korean financial and corporate staff, each wearing a Chrome icon over a forged "Hangul Document" property. Open one and PowerShell runs behind 5,800 to 9,500 characters of arguments, held out of sight by roughly 300 leading spaces.
From there the loader reaches GitHub Raw with a hardcoded access token, then registers a hidden scheduled task misspelled to pass for BitLocker, MATLAB, or .NET before deleting itself. Three samples never fetch a decoy and open a 16-byte error file instead, which looks like a failed attack. Persistence and payload retrieval run anyway.
That is why document quality settles nothing. Genians points defenders at the shortcut itself: a chrome.exe icon over a PowerShell target, randomly named scripts written into AppData and executed on the spot, and scheduled tasks carrying slight misspellings or long strings of digits.
Source: Cyber Security News
North Korea's Kimsuky group turned to opencode, an open-source AI coding agent, to mass-produce the decoy documents behind its latest phishing run. Speed came at the cost of care. Genians counted placeholder text for payment dates, grace periods, and interest rates surviving into the files that shipped, nine times over, which is what gave the tool away.
What reaches the inbox is handled far more carefully. Genians examined 13 shortcut files sent in ZIP archives between August 11 and 19, 2026, aimed at Korean financial and corporate staff, each wearing a Chrome icon over a forged "Hangul Document" property. Open one and PowerShell runs behind 5,800 to 9,500 characters of arguments, held out of sight by roughly 300 leading spaces.
From there the loader reaches GitHub Raw with a hardcoded access token, then registers a hidden scheduled task misspelled to pass for BitLocker, MATLAB, or .NET before deleting itself. Three samples never fetch a decoy and open a 16-byte error file instead, which looks like a failed attack. Persistence and payload retrieval run anyway.
That is why document quality settles nothing. Genians points defenders at the shortcut itself: a chrome.exe icon over a PowerShell target, randomly named scripts written into AppData and executed on the spot, and scheduled tasks carrying slight misspellings or long strings of digits.
Source: Cyber Security News
A dark web identity theft service called Nexus began selling digital scans of more than 153 million US and Canadian driver's licenses in the week of August 31, 2026, most of them American. The FBI's New Orleans field office opened an investigation on September 1, and the site went dark hours later.
Investigative journalist Brian Krebs found his own license listed, then asked more than a dozen friends and family for permission to search. All nine he found confirmed traveling on or near the timestamps attached to their images. The common thread was Hertz car rentals, plus a Las Vegas dispensary in one case.
Both point to IDScan.net, a Louisiana identity verification firm that lists Hertz as a client and holds an exclusive agreement with that dispensary chain. IDScan scans IDs with infrared and ultraviolet light, and the Nexus records include infrared and ultraviolet versions of each license.
IDScan.net says it is investigating and has issued no statement. Nexus operators claim a year of continuous exfiltration, and the license count grew by nearly 400,000 in a single day. Licenses for Defense Secretary Pete Hegseth and the FBI's assistant director were among those listed.
NCC Group's Tim Rawlins says organizations should design identity systems assuming that identity evidence will eventually be compromised, and should hold identity vendors to contract terms covering retention, incident notification, and independent assurance.
Source: SecurityWeek
A dark web identity theft service called Nexus began selling digital scans of more than 153 million US and Canadian driver's licenses in the week of August 31, 2026, most of them American. The FBI's New Orleans field office opened an investigation on September 1, and the site went dark hours later.
Investigative journalist Brian Krebs found his own license listed, then asked more than a dozen friends and family for permission to search. All nine he found confirmed traveling on or near the timestamps attached to their images. The common thread was Hertz car rentals, plus a Las Vegas dispensary in one case.
Both point to IDScan.net, a Louisiana identity verification firm that lists Hertz as a client and holds an exclusive agreement with that dispensary chain. IDScan scans IDs with infrared and ultraviolet light, and the Nexus records include infrared and ultraviolet versions of each license.
IDScan.net says it is investigating and has issued no statement. Nexus operators claim a year of continuous exfiltration, and the license count grew by nearly 400,000 in a single day. Licenses for Defense Secretary Pete Hegseth and the FBI's assistant director were among those listed.
NCC Group's Tim Rawlins says organizations should design identity systems assuming that identity evidence will eventually be compromised, and should hold identity vendors to contract terms covering retention, incident notification, and independent assurance.
Source: SecurityWeek