Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Malicious npm packages evade install-script defenses at runtime

    September 20, 2026

    Researchers escape OpenAI Codex sandbox to run commands on host

    September 20, 2026

    Microsoft Teams will let admins block custom file extensions

    September 20, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»InfoSec News Nuggets – 09/15/2026 – AboutDFIR
    News

    InfoSec News Nuggets – 09/15/2026 – AboutDFIR

    adminBy adminSeptember 15, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Revolut Confirms Customer Data Breach Through Fake Government Requests 

    British fintech Revolut confirmed it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent information requests sent from a legitimate government agency’s email domain, in what the company describes as a sophisticated impersonation scam rather than a system intrusion. The exposed data included identity and contact details, dates of birth, addresses, phone numbers, copies of passports and driver’s licenses, and in some cases verification selfies, account statements, and transaction histories — though Revolut says a “limited number” of customers were affected and that funds and core systems were unaffected. The incident illustrates a distinct and harder-to-defend attack vector: rather than breaching Revolut’s own systems, the attacker exploited the trust attached to a real government email domain, meaning even properly authenticated, legitimate-looking correspondence can’t be assumed safe when handling sensitive customer data requests. 

     

     

    Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service 

    Socket’s Threat Research Team identified a cross-store browser extension called “Twitch Enhanced Viewer | JeetBot,” live on both the Chrome Web Store and Firefox Add-ons with roughly 30,000 combined users, that captures live Twitch OAuth session tokens and forwards them to proxy servers operated by a Russian-language commercial bot service. Despite marketing itself as a quality-of-life tool for ad blocking and forced 1080p playback, the extension reads the Authorization header used by Twitch’s web client to extract an account-scoped token — far more sensitive than the playback token actually needed — appending it in cleartext to a URL query parameter where it gets logged by the proxy’s own request logs. Notably, the extension hardcodes an exemption for ten Russian-language streamer channels, routing their traffic through the same proxy without attaching a token at all — evidence Socket says points to deliberate intent rather than a careless implementation bug. 

     

     

    Linux Kernel ZcopyReaper Vulnerability Lets Local Attackers Gain Root Privileges 

    Security researchers at NebuSec disclosed CVE-2026-43502, dubbed ZcopyReaper, a local privilege escalation flaw in the Linux kernel’s Reliable Datagram Sockets zero-copy send path that lets an unprivileged local attacker obtain root access with no special capabilities or reliance on user namespaces — meaning the common hardening step of disabling unprivileged user namespaces does nothing to stop it. The flaw has existed since Linux kernel version 4.17 and was demonstrated successfully on an openSUSE system, with a fix landing in Linux 7.1-rc3. NebuSec says ZcopyReaper is just one of more than 20 exploitable Linux kernel vulnerabilities its automated exploit-generation pipeline has identified and published proof-of-concept code for, underscoring how AI-assisted vulnerability research is now surfacing kernel-level flaws at a pace defenders will need new tooling to keep up with. 

     

     

    Human Attacker Hits Machine-Speed Exploitation of Marimo RCE 

    Sysdig’s Threat Research Team documented a human-operated intrusion that exploited CVE-2026-39987, the previously disclosed pre-authentication RCE flaw in Marimo’s terminal WebSocket endpoint, and moved from initial access to an authenticated SSH bastion host in just eight seconds — a speed usually associated with AI-driven attacks. The operator spent roughly four hours hand-writing and debugging a custom Python toolkit before conducting a nine-hour session of more than 850 interactive commands, harvesting AWS credentials from the compromised host and its Redis backend, then using them to pull an SSH private key from AWS Secrets Manager. Sysdig found no evidence of LLM involvement despite the attacker briefly viewing what appeared to be an LLM prompt-injection bait file, reinforcing that skilled human operators with well-prepared tooling can already match the speed of automated agents once the groundwork is laid. 

     

     

    CISA Flags Five Actively Exploited Bugs in Tools Your Business Probably Runs 

    CISA added five actively exploited vulnerabilities across JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog within a 48-hour span, spanning an artifact repository, a remote-support tool, and router firmware — three very different products all under confirmed active attack. The ScreenConnect flaw (CVE-2026-84869, CVSS 9.9) lets an attacker transfer and execute files through an active remote session without host authorization, while the two MikroTik RouterOS flaws, dubbed the MikroTrick exploit chain by CERT Polska, allow unauthenticated device takeover and were given the earliest remediation deadline of September 13. The rapid-fire pattern of additions across unrelated product categories highlights how CISA’s KEV catalog functions as a real-time signal of which vulnerabilities have moved from theoretical risk to confirmed exploitation — a distinction that matters far more than severity scores alone when prioritizing patch cycles. 

     



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleSuspected Black Axe gang leaders face cybercrime charges in the US
    Next Article BambooToken malware controls Windows and Linux systems via MQTT
    admin
    • Website

    Related Posts

    News

    Malicious npm packages evade install-script defenses at runtime

    September 20, 2026
    News

    Researchers escape OpenAI Codex sandbox to run commands on host

    September 20, 2026
    News

    Microsoft Teams will let admins block custom file extensions

    September 20, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Our Picks

    Malicious npm packages evade install-script defenses at runtime

    September 20, 2026

    Researchers escape OpenAI Codex sandbox to run commands on host

    September 20, 2026

    Microsoft Teams will let admins block custom file extensions

    September 20, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.