Revolut disclosed sensitive customer data after fulfilling a fraudulent information request sent from an unauthorized account operating within a real government agency’s email domain; the message passed domain-authentication checks. The exposed information included identity and contact details, identity documents, verification selfies, account statements, withdrawal records, and transaction histories including Bitcoin; no biometric facial telemetry was involved.
Why it matters
The incident did not involve malware, outsider access to Revolut’s servers, or compromised customer funds; staff processed the request, and the fraud was discovered when Revolut independently verified it with the government agency.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily
Cloud · The Hacker News
What happened
Microsoft disclosed two campaigns involving abuse of third-party email delivery infrastructure to send financial-fraud scam messages and passkey-themed social engineering to breach cloud environments. Microsoft said the first campaign sent more than one million scam emails between August 3 and 5, 2026, while masquerading as chief executive officers.
Why it matters
The campaigns distinguish use of established delivery infrastructure from the trustworthiness of the messages it carries, making that boundary relevant alongside social-engineering defenses.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily
Exploitation · The Hacker News
What happened
CISA added five security flaws affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog after reports of active exploitation in the wild. The supplied text identifies CVE-2026-42016 as affecting one of the listed products and gives it a CVSS score of 8.1; the description is truncated after stating that it involves incorrect authorization.
Why it matters
Active-exploitation cataloging makes the listed product flaws immediately relevant to exposure review, even though the supplied technical detail covers only one listed issue.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Evidence is visible. Uncertainty stays visible too.
Baitaphish separates source records from interpretations, labels AI-assisted enrichment, and avoids turning ingestion volume into unsupported claims about threats, prevalence, or risk.