View all sources for this day →

The Signal

The identity and cloud items illustrate a shared boundary: authenticated or established communication channels can still be used to deliver fraudulent actions. The exploitation and ransomware items, separately, emphasize operational and legal responses to malicious activity. [1][2][3][4]

Must Know

Identity · Securityaffairs

Identity · Incident

What happened

Revolut disclosed sensitive customer data after fulfilling a fraudulent information request sent from an unauthorized account operating within a real government agency’s email domain; the message passed domain-authentication checks. [1]

The exposed information included identity and contact details, identity documents, verification selfies, account statements, withdrawal records, and transaction histories including Bitcoin; no biometric facial telemetry was involved. [1]

Why it matters

The incident did not involve malware, outsider access to Revolut’s servers, or compromised customer funds; staff processed the request, and the fraud was discovered when Revolut independently verified it with the government agency. [1]

Cloud · The Hacker News

Cloud · Identity

What happened

Microsoft disclosed two campaigns involving abuse of third-party email delivery infrastructure to send financial-fraud scam messages and passkey-themed social engineering to breach cloud environments. [2]

Microsoft said the first campaign sent more than one million scam emails between August 3 and 5, 2026, while masquerading as chief executive officers. [2]

Why it matters

The campaigns distinguish use of established delivery infrastructure from the trustworthiness of the messages it carries, making that boundary relevant alongside social-engineering defenses. [2]

Exploitation · The Hacker News

Exploitation · Vulnerability

What happened

CISA added five security flaws affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog after reports of active exploitation in the wild. [3]

The supplied text identifies CVE-2026-42016 as affecting one of the listed products and gives it a CVSS score of 8.1; the description is truncated after stating that it involves incorrect authorization. [3]

Why it matters

Active-exploitation cataloging makes the listed product flaws immediately relevant to exposure review, even though the supplied technical detail covers only one listed issue. [3]

Incident · Securityaffairs

Incident · Security

What happened

A U.S. federal court sentenced Ukrainian national Oleksii Lytvynenko to four years in prison for conspiracy to commit wire fraud tied to deploying Conti ransomware. [4]

Conti attacks affected computers and networks in 47 U.S. states, 31 foreign countries, the District of Columbia, and Puerto Rico from 2020 through 2022; the FBI estimated associated victim payouts exceeded $150 million by January 2022. [4]

Why it matters

Forensic artifacts recovered during his July 2023 arrest in County Cork, Ireland, demonstrated ongoing involvement in ransomware activity after Conti’s 2022 shutdown. [4]

Sources (4)
  1. [1] Revolut Exposed KYC Data After Fraudulent Government Email Passed Security Checks

    securityaffairs · September 12, 2026

  2. [2] Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

    the hacker news · September 13, 2026

  3. [3] CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

    the hacker news · September 12, 2026

  4. [4] Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence

    securityaffairs · September 13, 2026