Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Revolut inadvertently provided customer data to fraudsters who impersonated government officials and exploited the company's internal data request procedures. The social engineering attack bypassed technical security controls by targeting human-operated support workflows.
Vulncheck argues that the AI-driven explosion in vulnerability discovery — with 35,853 CVEs published in the first half of 2026, a 49% increase year-over-year — has fundamentally changed the exposure management problem. Only 495 CVEs were catalogued as exploited in the wild during that same period, while 116 were already listed in CISA's Known Exploited Vulnerabilities catalog.
Malwarebytes reports that Revolut provided customer identification and financial data through a government data request system, raising concerns about bulk financial data access by state entities and customer privacy protections.
Unit 42 published research on a new behavioral clustering methodology for detecting compromised cloud identities, using machine learning to group service account behaviors into profiles for anomaly detection.
Broadcom published 13 key cybersecurity statistics for 2026, revealing ransomware as the costliest attack type and supply chain attacks doubling year-over-year across all industry sectors.
Microsoft's September 2026 cumulative updates are causing Remote Desktop Services failures on Windows Server systems, disrupting enterprise remote administration workflows. The issue affects multiple Windows Server versions and stems from changes to the RDS authentication stack in the latest patch cycle.