Revolut breached and more - Sept 20, 2026

Featured

Revolut has revealed they were victim of a data breach

The attacker impersonated a government agency, and tricked Revolut into disclosing customer financial information and passport data

This Week’s Updates

Breaches

Japan's Digital Agency confirms a VPN flaw exposed roughly 246,000 personnel records of government employees

CenterPoint Energy confirms customer personal information was stolen after an attacker leaked data allegedly taken from the utility

Admin Menu Editor Pro's developer confirms a compromised update server pushed a backdoored WordPress plugin update to roughly 1,500 sites

Brevo confirms attackers stole a Cloudflare API key and used it to inject ClickFix malware scripts into its site and customer-embedded JavaScript

Gyazo confirms a server vulnerability let hackers steal 23.6 million user records from the image-sharing platform

Vulnerabilities

Hackers exploit a critical Tencent Sogou Input Method flaw tracked as CVE-2026-51990 to deploy the GrayRabbit backdoor

CISA warns hackers are now exploiting GitLab's patched max-severity path traversal flaw, CVE-2026-85706

Cisco patches a critical Secure Email Gateway zero-day that attackers were already exploiting to execute commands as root

CISA warns ransomware gangs have joined attacks exploiting a critical VMware vCenter RCE flaw patched in July

Hackers actively exploit a patched WooCommerce Wholesale Lead Capture plugin flaw, CVE-2026-27540, to upload PHP backdoors to WordPress sites

Acronis discloses a high-severity, actively exploited Linux privilege escalation flaw in its cPanel, WHM, and Plesk backup plugin

Google patches an actively exploited Android zero-day among 110 flaws fixed in its September Pixel security update

CISA warns a critical ConnectWise ScreenConnect vulnerability is now being actively exploited in attacks

Cisco releases patches for a max-severity Identity Services Engine zero-day that attackers are actively exploiting

Check Point patches a critical flaw that let attackers execute code with root privileges on its management systems

Researcher's BragJack attacks earn two CVEs and over $20,000 in bounties after hijacking AI agents in five browsers, since patched by Google and Microsoft

Next
Next

Microsoft Released September 2026 Software Updates