Revolut Data Breach: Trusted Channel Abuse

Revolut data breach report showing customer information exposed through fraudulent government requests

A recent Revolut data breach shows how attackers can exploit trust without breaking into a bank’s core infrastructure. By using a compromised Italian government email account to submit fraudulent customer-data requests, attackers reportedly persuaded Revolut staff to disclose sensitive information linked to roughly 680 customers across several European countries. The incident exposed a second problem:…

Read More

N-able N-central RCE Vulnerability Hit Again

N-able N-central RCE Vulnerability Hit Again

An N-able N-central RCE vulnerability has forced the vendor to ship its fourth emergency hotfix in five weeks, and Huntress investigators say a customer’s server — already patched against an earlier round of flaws — was compromised a second time anyway. Tracked as CVE-2026-86218 with a maximum CVSS score of 10.0, the flaw hits a…

Read More

August 2026 Cybersecurity Roundup

August 2026 Cybersecurity Roundup: breaches at SafePal, CEVA Logistics, France's tax authority, Latvia's CSDD, and Manchester Airports, plus 5 critical CVEs.

This August 2026 Cybersecurity Roundup lands in a month when several of the biggest breaches traced back to familiar weaknesses: a compromised employee credential, an overlooked customer-facing plugin, and infrastructure monitoring that watched the wrong signals. Here’s a look at the month’s key cyberattacks and CVEs, along with our take on what they mean for…

Read More

Swiss Federal SharePoint Breach Hits 200 Accounts

The Swiss Federal SharePoint Breach compromised 200 accounts at Switzerland's national IT agency, likely via a July Patch Tuesday flaw.

The Swiss federal SharePoint breach compromised roughly 200 accounts at Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT/FOITT), the agency confirmed in early August 2026. It is the first time DIESEC’s ongoing SharePoint vulnerability coverage has connected to a confirmed, named breach inside a DACH government body — not just a vendor advisory.…

Read More

Metabase CVSS 10 SQL Injection Zero-Day Hits Admin Access

The Metabase CVSS 10 SQL injection zero-day gives attackers admin access and every connected database credential. Framework and Tally already hit.

The Metabase CVSS 10 SQL injection zero-day lets an unauthenticated attacker turn a self-hosted analytics dashboard into a master key for every database it touches. Active exploitation began August 3, 2026, and two named victims — Framework and Tally — have already confirmed customer data theft. If your organization runs Metabase for internal reporting, this…

Read More