The Signal
Concrete exposure through a malicious browser extension and an impersonation incident merits priority over broader platform and research announcements. The reporting platform and AI benchmark are separate practitioner developments: one concerns a binding reporting channel, while the other concerns evaluation of models used in security work. [1][2][3][4]
Must Know
Identity · The Hacker News
What happened
A malicious cross-store Twitch browser extension leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. [1]
The extension is named “Twitch Enhanced Viewer | JeetBot” and lists HISHIMIRO/jeetbot.cc as its developer. [1]
Why it matters
Because the exposure described sits in an extension rather than the Twitch service, the item highlights the security boundary created when account tokens are handled by third-party browser software. [1]
Identity · Helpnetsecurity
What happened
Someone impersonating a government agency and using an address on that agency’s domain obtained sensitive records from Revolut; the bank confirmed the incident on September 12. [2]
Revolut said a limited number of customers were affected and that it contacted them directly. [2]
Why it matters
The supplied facts distinguish the domain used in an impersonation from the identity of the agency being impersonated, a boundary relevant to assessing responsibility for the disclosure. [2]
Exploitation · Helpnetsecurity
What happened
ENISA switched on the Cyber Resilience Act’s Single Reporting Platform on 11 September 2026, when the law’s reporting obligations began binding manufacturers. [3]
ENISA built the platform and operates it day to day under Article 16(1) of the Cyber Resilience Act. [3]
Why it matters
Its practitioner relevance is administrative and legal: a reporting channel is now operated alongside obligations that the source says became binding on manufacturers. [3]
AI & Agents · Helpnetsecurity
What happened
AWS’ Deception Benchmark measures whether AI models can distinguish genuine security vulnerabilities from code that appears risky but is safe. [4]
AWS is making the benchmark publicly available so researchers can use its dataset and evaluation process without repeating the cost of generating and refining samples. [4]
Why it matters
Security teams use AI for vulnerability triage, penetration testing, threat modeling, incident response, and code review. [4]
Also Worth Knowing
Incident · Helpnetsecurity
What happened
A ManageEngine survey of 700 IT and cybersecurity leaders in the US and Canada found that cybersecurity attention often rises after an incident, then recedes as organizations return to existing priorities and practices. [5]
Because every respondent had experienced an incident, the survey describes a post-incident pattern within that population rather than a prevalence estimate for all organizations. [5]
AI & Agents · Helpnetsecurity
What happened
Dataminr announced Dataminr Advanced for Corporate Security, which it says delivers agentic AI capabilities for protecting people, sites, and operations before risks escalate. [6]
The announcement describes product positioning and named capabilities; it does not by itself establish how the offering performs in deployment. [6]
AI & Agents · The Hacker News
What happened
The source states that vulnerability discovery is becoming faster and operating at greater scale, while defenders must determine which findings warrant action. [7]
The source’s framing separates discovery volume from the decision about which findings deserve action. [7]