๐ฅ BREACHES & INCIDENTS
-
Hackers Claim Sale of 75M Revolut User Records, Company Denies New Breach
Hackers claim to sell 75 million Revolut user records, but Revolut denies a new breach.- Applies to Revolut fintech platform users, potentially over 75 million records
- Data allegedly includes partial card data, emails, names, phone numbers, addresses, device info, and hashed credentials
- Samples show bcrypt or argon2id password hashes and metadata on device models and OS
- Seller offers dataset for around $500 on cybercrime forum, suspiciously low price
- Revolut states no evidence of new breach and ongoing investigation; data may be aggregated from multiple sources
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
-
Houston City College Data Breach Exposes 832k Student Records in ShinyHunters Extortion
Houston City College suffered a data breach exposing 832,000 student records by ShinyHunters.- Applies to Houston City College students and alumni, approx. 832,000 individuals affected
- Exposed data includes names, emails, phone numbers, addresses, DOB, gender, citizenship, and academic records
- Attack linked to ShinyHunters group using cyber extortion with pay-or-leak tactics
- Attackers gained unauthorized access via misconfigured databases or weak credentials
- Stolen data published on underground forums after ransom demands were refused
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ต๏ธ RESEARCH & DEEP DIVES
-
CVE-2026-10702 Firefox JIT Flaw Allows Code Execution via Malicious Webpage Visit
CVE-2026-10702
A Firefox JIT vulnerability enables arbitrary code execution by visiting a malicious webpage.- Applies to Firefox versions 147 through 151.0.2 and Tor Browser releases using these versions
- Vulnerability in Firefox's JIT compiler allows arbitrary code execution in the renderer process
- Triggered by simply visiting a malicious webpage without additional user interaction
- Exploit reclaims freed memory, corrupts objects, and redirects WebAssembly to execute shellcode
- Nebula Security released exploit code and demonstrated use in a browser-to-kernel ARM64 Android chain
๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
AsyncAPI npm Packages Targeted in Supply Chain Attack Stealing Dev Credentials
Attackers republished compromised AsyncAPI npm packages that steal developer API credentials.- Targets developers and automated build systems using AsyncAPI npm packages
- Five AsyncAPI package versions republished with hidden loaders activating on import
- Malware called Miasma steals GitHub, npm, cloud, container, and AI service credentials
- Attack exploited weak GitHub Actions workflow to push poisoned commits and releases
- Payload fetches encrypted modules from IPFS and persists via sync.js on multiple OS
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ ADVISORIES
- Critical VM Escape and Other Vulnerabilities Patched in VMware ESXi and Related Products
VMware patched critical VM escape and other vulnerabilities in ESXi, vCenter, Workstation, and Fusion.- Applies to VMware ESXi, vCenter, Workstation, and Fusion products
- Critical VM escape vulnerability (
CVE-2026-47876) in ESXi VMXNET3 adapter allows code execution on host - Critical vCenter flaws include authentication bypass (
CVE-2026-59309) and remote code execution (CVE-2026-59310) - High-severity ESXi, Workstation, Fusion flaw (
CVE-2026-41703) enables info leak or DoS via VM deployment permissions - Low-severity ESXi issue (
CVE-2026-41709) allows admin actions without logging - Exploitation requires local admin or network access depending on vulnerability
๐ Coverage: securityweek.com ยท ๐ Original: securityweek.com ยท ๐ via SecurityWeek
๐ CVEs & KEV
- CVE-2026-14270 โ CVSS 8.8 โ Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooComm...
- CVE-2026-12895 โ CVSS โ โ SQL Injection in Frappe's ERPNextSQL injection in Frappe's ERPNext, versions ...