Cyber Security News
Start. Stay. Grow.
Curated daily. The latest hacks, breaches, and cyber trends—humanized.
Daily cyber brief
Hacking Editorial Brief — September 15, 2026
Revolut Social Engineering Attack Exposes Nearly 700 Customer Records
Fintech platform Revolut disclosed that attackers successfully social engineered company personnel into handing over private customer data for nearly 700 users. The threat actors impersonated government officials to deceive Revolut staff into providing customer IDs, addresses, and other personal details. The incident occurred over the weekend and represents a targeted social engineering campaign exploiting human rather than technical vulnerabilities. Revolut has contacted affected customers, though the full scope of data misuse and whether additional financial fraud has occurred remains under investigation. The breach highlights persistent risks in customer service and compliance workflows where impersonation tactics can bypass technical security controls.
Canadian National Pleads Guilty to Breaching 165 Companies, Exposing 100 Million Records
A 26-year-old Canadian hacker has pleaded guilty to compromising 165 companies in a campaign that began in early 2024 and exposed data linked to approximately 100 million individuals. The operation extended beyond directly targeted organizations, suggesting supply chain or third-party data aggregation as part of the broader exposure. Investigative work eventually led to identification and prosecution, though the guilty plea represents one of the larger-scale breach admissions in recent years by individual count and exposure volume. Details on the attack methodology, targeted sectors, and whether data was monetized or distributed remain limited in public reporting.
Sources: City AM · Financial Times · Times of India
Around the Web
Last Updated: N/A

Hacks + Heists
Russian-Linked Threat Actors Using AI to Exploit PaperCut NG/MF Vulnerabilities
A suspected Russian-speaking cyber actor has used artificial intelligence to devise exploits targeting recently disclosed security flaws in PaperCut N...
Read more →CISA Confirms Ransomware Gangs Abusing Microsoft SharePoint RCE Vulnerability
CISA confirmed that ransomware gangs have begun actively exploiting a high-severity Microsoft SharePoint remote code execution vulnerability since ear...
Read more →China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and ...
Read more →Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
JeetBot's Twitch extension sent OAuth tokens from nearly 31000 users to operator-controlled proxies; Firefox 85.8.7 stops the behavior.
Read more →North Korean Hackers Exploit Windows Zero-Day in Operation Dream Job
North Korean hackers have been actively exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies.
Read more →
Big Cyber
Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution
Chinese threat actors linked to UNC3569 are actively exploiting CVE-2026-51990 in Tencent's Sogou Input Method to deploy the GrayRabbit backdoor for c...
Read more →New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
Intel takes the same position on physical attacks against server memory. Cybersecurity. Intel has separately said that physical interposer attacks of ...
Read more →Passkey phishing attack, Anthropic's report, airline cyber loophole - CISO Series
Airlines compliance with new cybersecurity regulations means fewer passenger conveniences. Starting next month, airlines whose flights are canceled or...
Read more →Cybersecurity stocks get a jolt on gloomy AI warnings from CEOs of Anthropic and OpenAI
Shares of top cybersecurity names popped in pre-market trading amid fresh warnings from the biggest names in AI within the past two days. Okta (OKTA) ...
Read more →
Hard Tech
React2Shell (CVE-2025-55182)
A 10.0 critical severity vulnerablility affecting server-side use of React.js, tracked as CVE-2025-55182 in React.js and CVE-2025-66478 specifically f...
Read more →Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer
We discovered three vulnerabilities that when chained together, allow for complete remote compromise:
Read more →Check Point - Wrong Check Point (CVE-2024-24919)
Gather round, gather round - it’s time for another blogpost tearing open an SSLVPN appliance and laying bare a recent in-the-wild exploited bug. This ...
Read more →Backdoor in XZ Utils allows RCE: everything you need to know - CVE-2024-3094
Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgentl...
Read more →Loading...
The Cybersecurity Chronicles
‘The Cybersecurity Chronicles: 2024‘ pulls back the curtain on the digital threats that shaped our world last year, revealing the human stories behind the headlines. From art galleries frozen by ransomware to prison tablets hacked with a minus sign, from British Library archivists racing to protect centuries of knowledge to Spotify users meticulously curating their digital identities – these stories illuminate how cybersecurity touches every aspect of modern life.
Author Mark Nole weaves together intimate portraits of the people on all sides of the digital battlefield: the defenders working through sleepless nights to protect critical infrastructure, the victims grappling with stolen identities and lost savings, and even the attackers themselves, operating from nondescript offices with project management software and performance metrics.
Through detailed reporting and narrative storytelling, Nole reveals how 2024 became the year when cybersecurity stopped being just a technical problem and emerged as a fundamentally human challenge. Whether you’re a security professional or simply someone trying to understand our increasingly digital world, these chronicles offer an unprecedented look at how technology shapes – and sometimes betrays – our trust, our privacy, and our lives.

Stay Updated with Cyber Security News
Get the latest cybersecurity headlines, breaking news, and expert insights delivered directly to your inbox. Stay ahead of threats and informed about the digital landscape.
Join thousands of cybersecurity professionals and enthusiasts. No spam, just valuable insights.