An Impostor Used a Real Government Email to Get Revolut’s Customer Records

A fraudulent request from a genuine government email domain persuaded Revolut to disclose sensitive customer records. The failure was in verifying who had authority to ask.
Vulnerabilities, defensive security, architecture and operational security.

A fraudulent request from a genuine government email domain persuaded Revolut to disclose sensitive customer records. The failure was in verifying who had authority to ask.

Surfshark says an internet-reachable engineering test server was accessed by an unauthorised party. It reports no user-data or VPN-service impact, but the incident exposed an important security gap.

Cryptographic workload identities cannot prove which process asked for them if an attacker controls the node making that claim. Unit 42 demonstrated the risk in SPIFFE/SPIRE.

A working app can still expose a key to private systems. Anthropic describes a 1.8 million-APK credential hunt in Claude-assisted criminal operations, while separate cases show how quickly stolen tokens can become wider access.

A million-plus email campaign combined fake executive approval, a forged ServiceNow invoice and an invented forwarded conversation to seek nearly $50,000 transfers.

Check Point used a shared internal package service to pass hidden tasks between separate ChatGPT accounts. In its demonstration, the victim saw a normal answer while Gmail data crossed the boundary.

Florida identified one compromised police login, improperly stored on an employee's personal device, as the route into its systems. The claimed scale of exposure remains unconfirmed.

Ivanti disclosed eight remote-code-execution flaws in Neurons for ITSM, two requiring no login. Cloud tenants were patched in August, but on-premises administrators must apply the right September patch.

Gen Digital traced a GRAYRABBIT intrusion to a crafted Sogou Input Method link. The link opened a six-year-old browser engine with its sandbox disabled, allowing an old JavaScript exploit to run.

Wiz observed attackers chaining two Artifactory flaws for administrator access and using a third flaw separately. Some intrusions left persistent accounts, malicious plugins and Rust backdoors.