> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> InfoSec News Nuggets – 09/15/2026

[SOURCE] AboutDFIR [AUTHOR: Mary] [DATE: 15/09/2026 10:48] [LANGUAGE: EN]
Revolut Confirms Customer Data Breach Through Fake Government Requests  British fintech Revolut confirmed it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent information requests sent from a legitimate government agency’s email domain, in what the company describes as a sophisticated impersonation scam rather than a system intrusion. The exposed data included identity and contact details, dates of birth, addresses, phone numbers, copies of passports and driver’s licenses, and in some cases verification selfies, account statements, and transaction histories — though Revolut says a “limited number” of customers were affected and that funds and core systems were unaffected. The incident illustrates a distinct and harder-to-defend attack vector: rather than breaching Revolut’s own systems, the attacker exploited the trust attached to a real government email domain, meaning even properly authenticated, legitimate-looking correspondence can’t be assumed safe when handling sensitive customer data requests.      Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service  Socket’s Threat Research Team identified a cross-store browser extension called “Twitch Enhanced Viewer | JeetBot,” live on both the Chrome Web Store and Firefox Add-ons with roughly 30,000 combined users, that captures live Twitch OAuth session tokens and forwards them to proxy servers operated by a Russian-language commercial bot service. Despite marketing itself as a quality-of-life tool for ad blocking and forced 1080p playback, the extension reads the Authorization header used by Twitch’s web client to extract an account-scoped token — far more sensitive than the playback token actually needed — appending it in cleartext to a URL query parameter where it gets logged by the proxy’s own request logs. Notably, the extension hardcodes an exemption for ten Russian-language streamer channels, routing their traffic through the same proxy without attaching a token at all — evidence Socket says points to deliberate intent rather than a careless implementation bug.      Linux Kernel ZcopyReaper Vulnerability Lets Local Attackers Gain Root Privileges  Security researchers at NebuSec disclosed CVE-2026-43502, dubbed ZcopyReaper, a local privilege escalation flaw in the Linux kernel’s Reliable Datagram Sockets zero-copy send path that lets an unprivileged local attacker obtain root access with no special capabilities or reliance on user namespaces — meaning the common hardening step of disabling unprivileged user namespaces does nothing to stop it. The flaw has existed since Linux kernel version 4.17 and was demonstrated successfully on an openSUSE system, with a fix landing in Linux 7.1-rc3. NebuSec says ZcopyReaper is just one of more than 20 exploitable Linux kernel vulnerabilities its automated exploit-generation pipeline has identified and published proof-of-concept code for, underscoring how AI-assisted vulnerability research is now surfacing kernel-level flaws at a pace defenders will need new tooling to keep up with.      Human Attacker Hits Machine-Speed Exploitation of Marimo RCE  Sysdig’s Threat Research Team documented a human-operated intrusion that exploited CVE-2026-39987, the previously disclosed pre-authentication RCE flaw in Marimo’s terminal WebSocket endpoint, and moved from initial access to an authenticated SSH bastion host in just eight seconds — a speed usually associated with AI-driven attacks. The operator spent roughly four hours hand-writing and debugging a custom Python toolkit before conducting a nine-hour session of more than 850 interactive commands, harvesting AWS credentials from the compromised host and its Redis backend, then using them to pull an SSH private key from AWS Secrets Manager. Sysdig found no evidence of LLM involvement despite the attacker briefly viewing what appeared to be an LLM prompt-injection bait file, reinforcing that skilled human operators with well-prepared tooling can already match the speed of automated agents once the groundwork is laid.      CISA Flags Five Actively Exploited Bugs in Tools Your Business Probably Runs  CISA added five actively exploited vulnerabilities across JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog within a 48-hour span, spanning an artifact repository, a remote-support tool, and router firmware — three very different products all under confirmed active attack. The ScreenConnect flaw (CVE-2026-84869, CVSS 9.9) lets an attacker transfer and execute files through an active remote session without host authorization, while the two MikroTik RouterOS flaws, dubbed the MikroTrick exploit chain by CERT Polska, allow unauthenticated device takeover and were given the earliest remediation deadline of September 13. The rapid-fire pattern of additions across unrelated product categories highlights how CISA’s KEV catalog functions as a real-time signal of which vulnerabilities have moved from theoretical risk to confirmed exploitation — a distinction that matters far more than severity scores alone when prioritizing patch cycles.    The post InfoSec News Nuggets – 09/15/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
[messages.read_original_source] →