Revolut breach exposes user passports

Revolut's passport breach, a critical GitLab flaw, and more.

Revolut breach exposes user passports

Hi there, this is your daily β˜•οΈ Cyberpresso.


In today's Cyberpresso:

πŸ”“ Revolut breach exposes user passports

πŸ› Researchers reveal OpenAI agents attacked RubyGems in May

🚨 Hackers exploit max-severity GitLab flaw

πŸ‡ Sogou flaw exploited to plant backdoor

Plus: πŸ’‘ 4 strategies & tactics, 🎁 8 other news you might like, 🧰 6 tools, and πŸ“š 5 papers.

πŸ”“ Revolut breach exposes user passports LINK

  • Fintech company Revolut disclosed a data breach after it handed over customer data to a threat actor who impersonated a government agency by emailing a request from that agency's official domain.
  • The attacker sent a request from an unauthorised email account using the official government agency's email domain, and because the communication carried valid domain authentication credentials, Revolut fulfilled it believing it was an authentic government request.
  • The exposed data includes full name, date of birth, occupation, postal address, email, phone, passport and/or driver's license copies, facial verification selfies, account statements with IBAN numbers, withdrawal records, and full transaction history including Bitcoin transactions.
  • πŸ› Researchers reveal OpenAI agents attacked RubyGems in May LINK

  • Researchers say an OpenAI agent swarm was very likely behind a malicious attack on the RubyGems package repository, first reported on May 12th by Maciej Mensfeld of the RubyGems security team, that forced signups to be paused.
  • Hundreds of packages were involved, many with "oai" in their name, author field, or fake email, containing LLM-authored code that abused the RubyDoc.info documentation build process to exfiltrate public data from UK government websites, including Southwark council docs.
  • Some packages also tried to steal API keys through an exploit patched over two months later, with success unclear, and the researchers report OpenAI had not disclosed to RubyGems that it was responsible prior to now.
  • 🚨 Hackers exploit max-severity GitLab flaw LINK

  • Attackers are already probing a maximum severity path traversal flaw (CVE-2026-85706) in GitLab CE/EE that lets an unauthenticated user read arbitrary files from a self-hosted server, with GitLab issuing a fix on September 10.
  • The bug affects all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2, and vendor watchtower reported detecting in-the-wild probes on September 11 while CISA added it to its exploited-bugs catalog the same day.
  • The flaw stems from improper path confinement and missing authentication enforcement in the repository commits API, and defenders can hunt for exploitation by checking logs for HTTP POST requests to "/api/v4/projects/{id}/repository/commits/" URIs containing "file.path" parameters.
  • πŸ‡ Sogou flaw exploited to plant backdoor LINK

  • A China-linked espionage group known as UNC3569 abused a critical one-click remote code execution flaw in Tencent's Sogou Input Method for Windows to plant the GRAYRABBIT backdoor on targeted systems.
  • The bug, CVE-2026-51990, was actively exploited: a crafted link launched Sogou's outdated embedded browser without a sandbox, and attackers ran a known browser bug to run code as the logged-in user, then sideloaded the malware.
  • Tencent fixed the link-handling behavior in Sogou Input Method version 16.3.0.3498, pushed via automatic updates on April 21, which now validates URL arguments and limits navigation to approved Sogou and Tencent domains; earlier Windows versions should update immediately.
  • πŸ’‘ Strategies & Tactics

    > New fuzzing tool finds security vulnerabilities in WordPress plugins: A WordPress-specific automated testing tool called THEMIS finds server-side security flaws in plugins by watching traffic between plugin code and the WordPress core.

    > macOS Tahoe 26.4 update stops you from copying your login Keychain: Apple now ties the login Keychain to each Mac's security chip, blocking manual credential copying to another machine and complicating corporate bulk migrations.

    > Turn it off and on again, but for critical infrastructure: An automated defender that estimates how far an intrusion has spread, then reboots infected machines to expel attackers, works but assumes the attacker's behavior is known in advance.

    > Update your firewall rules: Teams and Copilot are changing address: Update firewall and proxy rules before early October, since Microsoft is moving Teams and Copilot web access to new cloud.microsoft addresses.

    Other news you might like

    • GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push PipelineLINK
    • Hackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows ProcessLINK
    • Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank WebsitesLINK
    • Malicious Twitch extension exposed OAuth tokens of 30,000 usersLINK
    • ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like AttacksLINK
    • Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing CapabilitiesLINK
    • Microsoft: September updates cause RDS failures on Windows ServerLINK
    • Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome HijackerLINK

    🧰 Trending tools

    Kastra: runtime authorization layer for AI agents that evaluates every action in under a millisecond, blocking unauthorized tool use and logging tamper-proof audit trails.LINK

    Cynative Security Research Agent: open-source AI CLI that answers plain-language security questions across code, cloud, and Kubernetes using read-only, IAM-enforced production access.LINK

    Aegisora: an open-source proxy that secures LLM agents with least-privilege API access, PII masking, prompt-injection blocking, and audit logging.LINK

    Reark: An intelligent reverse engineering analysis tool designed for multiple target platforms, currently supporting HarmonyOS (HAP/APP/ABC) and Android (APK/AAB).LINK

    Agent Beacon is the world's first open-source telemetry layer for AI agents wherever they run: locally, in CI, in the browser, or in the cloud.LINK

    Spanda: measures epistemic uncertainty in LLM outputs with sub-microsecond latency, implemented in Rust for high-performance inference monitoring.LINK

    πŸ“š Trending papers & reports

    VR motion privacy tools that scramble body-tracking data to prevent user identification are better judged by asking real users what they'll accept than by measuring movement distortion alone, which misses most of what drives acceptance.LINK

    Style-aware text rewriting rewrites documents to erase the personal writing quirks that let systems re-identify anonymous authors, cutting re-identification accuracy 60-70% while keeping meaning and readability intact, beating existing privacy methods.LINK

    Personal attribute snooping now traces exactly which few posts reveal your age, income, or job, hitting ~87% accuracy while flagging the source for over 98% of guesses, so people can redact only the leaky posts.LINK

    Agent skill safety shows that malware scanners approving code as clean still let AI agents run prohibited actions, and a rule-based gate caught all 23 forbidden attempts they tried, closing a real permissions gap.LINK

    Password-free phone login on websites can leak users' phone numbers in a single visit, with a one-year study finding ~74% of over 116,000 sites carrying flaws that enable these one-click identity leaks.LINK


    See you tomorrow for a new dose of β˜•οΈ Cyberpresso!

    More from the archive