Shadow AI, deepfakes, and supply chain compromise are rewriting the financial sector threat playbook
Revolut Data Leak May Trace Back to Compromised Italian Government Accounts
Attackers using a compromised Italian government PEC account impersonated law enforcement to obtain data on ~680 Revolut customers.
Revolut confirmed its systems were not breached; fraudulent data requests came from a compromised PEC mailbox tied to the Prefecture of Reggio Calabria on the pec.interno.it domain. Per the Financial Times, roughly 680 customers had identity documents, addresses, banking information, verification selfies and cryptocurrency transaction histories exposed. Researcher Korra of Duel described a 'spray and pray' operation using hundreds of crypto transaction IDs and fraudulent European Investigation Orders. Threat actor IAmNotAVillain claims six months of access and 147 GB exfiltrated from Italian law-enforcement systems, though this remains unverified.
Hackers Return $263 Million Stolen From Liquid Network
Hackers drain roughly 4,000 BTC (~$320M) from Liquid Network federation wallet, then return 3,400 BTC with ~598 BTC still outstanding.
Attackers withdrew about 4,000 Bitcoin (roughly $320 million) from the Liquid Network federation wallet, which held approximately 4,200 BTC, via the SideSwap Peg-out Authorization Key without that key being compromised. Blockstream disabled nodes and suspended transactions after disclosing the heist on Sunday. Alleged white-hat hackers returned 3,400 BTC (~$262.6M) on Monday, demanding the underlying bug be patched before releasing the remaining ~598 BTC (~$47M). The network remains paused while fixes and a safe restart are prepared.
Russian Man Extradited Over Malware Campaign Targeting Freelancers
A Russian national was extradited to the US for allegedly spreading TVRAT and DarkVNC malware to 80,000 freelance platform users via Excel attachments.
Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025, extradited on August 28, 2026, and indicted on conspiracy, computer damage, unauthorized access and aggravated identity theft charges. Prosecutors say he and co-conspirators used about 255 fake accounts on a freelance employment platform's messaging system to send macro-laden Excel attachments between June 2016 and November 2017, deploying TVRAT (TVSPY/TeamSpy) and DarkVNC remote access trojans. Thousands of victims were identified on a US-hosted C2 domain, with roughly half of the 80,000 affected users in the US; C2 infrastructure was paid for with virtual currency. If convicted he faces up to 20 years for wire fraud conspiracy plus additional terms and fines.
Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Compromised Admin Menu Editor Pro update server distributed backdoored plugin versions installing web shells and hidden admin accounts on roughly 1,500 WordPress sites.
A threat actor with root-level access to adminmenueditor.com pushed trojanized Admin Menu Editor Pro versions 2.35 and 2.36 containing includes/wp-user-consent.php, which installed a web shell and created a hidden wp_-prefixed user account. At least 230 customers and roughly 1,500 sites installed the malicious update, with several hundred more downloads possibly affected. Developer Janis Elsts took the site offline after the attacker recompromised the clean 2.36 release; version 2.34 and the free plugin are believed unaffected.
Japan’s Digital Agency Breach Exposes 240,000+ Users’ Personal Records to Hackers
Attackers exploited a patched VPN appliance flaw to breach Japan's Digital Agency shared government platform, exposing about 246,000 personal records.
Japan's Digital Agency disclosed on September 11 that attackers exploited a VPN appliance vulnerability to access the Government Solution Service (GSS), a shared IT platform across ministries, exposing roughly 246,000 personal records. The attacker was active since late May using a maintenance staffer's credentials, with suspicious activity detected June 25 and containment on July 9. Exposed data covers about 189,000 employees/public officials and 57,000 contractors; no My Number, bank, or pension data was included. The VPN flaw was medium severity with a patch already available, and the 78-day detection-to-disclosure gap has drawn scrutiny.
Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS guest analyst detonated a RedTail Linux sample from a DShield honeypot, finding process masquerading as php-fpm, monitoring-kill behavior, and a TCP listener.
A DShield honeypot captured multi-architecture RedTail Linux executables (ARM, ARM64, i686, RISC-V, x86-64) deployed via shell scripts. Dynamic analysis of the UPX-packed, statically linked x86-64 sample (SHA-256 63be5f38...d35e) in an isolated Ubuntu 24.04 VM on Proxmox showed it renamed its process via prctl(PR_SET_NAME), killed a filesystem-monitoring process, and opened a TCP listening socket while surviving processes posed as php-fpm or PostgreSQL-like workers. Differential memory images pre- and post-execution were captured from the hypervisor for forensics.
August 2026 CVE Landscape
Insikt Group catalogs 73 high-impact August 2026 CVEs (43 Very Critical), including PaperCut, Zimbra, and Metabase flaws actively exploited or weaponized.
Recorded Future's Insikt Group identified 73 high-impact vulnerabilities in August 2026, 43 rated Very Critical, spanning 45 vendors with Microsoft accounting for roughly 11%. 31 vulnerabilities surfaced via CISA's KEV catalog, with others validated via open sources, vendor telemetry, and honeypot data. New Nuclei detection templates were released for CVE-2025-62593 (Ray), CVE-2026-72898 (Metabase), and CVE-2026-9198 (IBM Langflow). The report also highlights two AI-assisted operations: UAT-10147 exploited Zimbra, AjaxPro, Nacos, and Telerik servers before using DeepAudit and PentestGPT post-compromise, while a separate Chinese-speaking actor weaponized Hermes Agent and DeepSeek in a failed attempt.
Russian man indicted for spreading malware to 80,000 freelancers
US prosecutors indicted a Russian national for infecting roughly 80,000 freelancers with TVRAT and DarkVNC malware via fake freelance-platform accounts.
Searzhudin Tamirlanovich Aktulaev, 40, was indicted in California for conspiracy, transmission of malicious code, and aggravated identity theft; he was arrested in Cyprus in May 2025 and extradited in August 2026. From June 2016 to November 2017, about 255 fake accounts on a Northern California freelance platform messaged roughly 80,000 users with malicious Excel attachments that ran macros to download malware. The campaign deployed TVRAT (also known as TeamSpy), which exploited a TeamViewer flaw, and DarkVNC via VNC Viewer, exfiltrating stolen data to US-hosted command-and-control servers. About half the victims were in the US, and stolen credentials were used for fraud.
FBI Probes Service Selling 153M+ Drivers Licenses
Dark web service Nexus sells scans of 153M+ US and Canadian drivers licenses, apparently siphoned from a breached identity verification company; FBI opened an inquiry.
A new dark web identity theft service called Nexus, advertised on the Exploit forum, offers scans of more than 153 million drivers licenses from the US and Canada, plus over 10 million ID cards and millions of travel and medical documents. The data appears to come from an ongoing breach at a major Louisiana-based identity verification company, with records growing by roughly 400,000 in 24 hours. Records include high-ranking US officials such as Defense Secretary Pete Hegseth, and timestamps suggest data was captured during car rentals and travel. The FBI's New Orleans field office has launched an official inquiry into the source of the images.
US charges 17 Iranian hackers over 31-terabyte academic data theft
US indicts 17 Iranian Mabna Institute hackers who stole 31TB of academic data from universities, companies, and agencies via spearphishing.
The US Department of Justice charged 17 alleged Mabna Institute members, adding eight defendants to the nine charged in 2018, for a 2013-2017 campaign largely conducted for Iran's Islamic Revolutionary Guard Corps. The group stole over 31TB of academic data and intellectual property from 144 US and 178 foreign universities, at least 42 US companies, and at least five federal and state agencies, compromising about 8,000 of 100,000 spearphished professor email accounts. US universities spent roughly $3.4 billion procuring the stolen data; one defendant also hacked HBO and sought about $6 million in bitcoin ransom. The State Department offers up to $10 million for information on five defendants, none of whom are in US custody.
SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
SafePal disclosed an order-tracking plug-in authorization flaw exposing names, emails, addresses and purchase details of 39,798 hardware wallet customers; no wallet credentials affected.
Hardware wallet maker SafePal disclosed that an authorization flaw in an order-tracking plug-in exposed names, email addresses, shipping addresses, phone numbers and purchase details of approximately 39,798 customers. No seed phrases, private keys, wallet credentials or financial information were exposed, and SafePal found no evidence of wallet or fund compromise. A separate configuration error left a data-cleanup process broken between September 2025 and April 2026, extending the affected order window back to March 2025. A threat actor has advertised a matching dataset on a cybercrime forum, and the company has fixed the flaw, cut data retention to 90 days, purged affected records, engaged third-party validators and taken down over 30 phishing sites.
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Metabase warns an actively exploited zero-day (CVE-2026-72898, CVSS 10.0) grants unauthenticated admin access; Framework, n8n, and Kilo Code disclosed data exposure.
Metabase disclosed a maximum-severity SQL injection affecting versions x.58 through x.63 that lets unauthenticated attackers inject SQL via the /api/session/reset_password endpoint and gain administrator access to Metabase instances. Metabase Cloud was attacked, patches were released, and CISA added CVE-2026-72898 to the KEV catalog with a federal remediation deadline of August 14, 2026. Downstream victims include Framework (customer names, IPs, addresses, phone numbers, and emails accessed), n8n (136 customer records, five with bcrypt-hashed passwords), and Kilo Code (Slack access tokens). Wiz estimates roughly 13% of cloud environments run self-hosted Metabase, with about 2,500 instances internet-accessible.