Back Technadu Weekly Cybersecurity Roundup: Trust Opens the Door, Evidence Closes It
Impersonation remains a reliable tool for scammers, as seen this week in the Revolut breach and scams targeting farmers.
While bug hunters struggle to find safe harbor for reporting vulnerabilities, one bug hunter allegedly built malware to generate his own bounty claims, bringing more challenges for the already struggling ethical hackers.
Revolut Data Breach Exposes Customer IDs After Fraudulent Government Requests
Revolut confirmed that an unauthorized party obtained sensitive customer information after submitting fraudulent information requests through an email address on a legitimate government agency domain. The exposed records could include birth dates, addresses, phone numbers, passports, driver’s licenses, verification selfies, account statements, and transaction histories, while Revolut said its systems and customer funds were unaffected. The fintech said only a limited number of customers were affected, although it has not disclosed the exact figure, identified the government agency, or said whether the incident was confined to a particular country.
Spain Records Its First Reported Data Breach Executed Through an AI Agent
Spain’s data protection authority has received its first notification of a breach allegedly executed through an AI agent. The agent successfully logged in and autonomously searched the application for vulnerabilities. It then found a weakness that enabled access to invoices and modification of personal data. The AEPD says the important shift is the agent chaining multiple attack stages together toward an objective. The agency cautions that the information currently comes from the affected organization and remains under analysis. The AEPD has not disclosed the affected organization or the number of people impacted.
Researchers Use Claude to Chain Flaws and Reach OpenAI's Internal Code Repository
Three security researchers used Anthropic's Claude to help build an exploit chain that compromised an OpenAI employee's ChatGPT account and provided access to internal development resources. The research began with a remote-code-execution flaw affecting the libheif image-processing library used by Discourse, the platform behind OpenAI's developer forum, before an authentication weakness enabled the researchers to obtain tokens associated with an employee account. That access extended to OpenAI's private Monorepo, where the researchers demonstrated their reach by submitting a benign pull request without accessing or exposing sensitive source code.
Black Axe Leaders Brought From South Africa to U.S. After Years-Long Extradition Fight
Five alleged Black Axe leaders have been extradited from South Africa to face U.S. federal charges. Their arrests in South Africa date back to 2021, making their transfer a years-long cross-border enforcement effort. The group ran romance scams and advance-fee schemes targeting U.S. victims from Cape Town. Some victims were allegedly threatened with exposure of sensitive photographs when they hesitated to pay. The defendants also laundered proceeds from business email compromise schemes. U.S. and South African authorities, Interpol, and several enforcement agencies contributed to bringing the five defendants to the U.S.
Ransomware Hits More Manufacturers as New Groups Rapidly Replace Disrupted Operators
Manufacturing recorded 1,183 disclosed ransomware victims between January and July 2026, up 39.7% from the same period last year. Nearly half of those incidents came from groups that were absent from its dataset in 2023 and 2024. The number of groups targeting manufacturers rose from 55 in 2023 to 91 in seven months of 2026. The Gentlemen first appeared in the dataset in September 2025 but recorded 142 manufacturing victims in the first seven months of 2026, second only to Qilin’s 178. The U.S. recorded 412 manufacturing ransomware victims in the first seven months of 2026, compared with 443 a year earlier. Europe rose from 199 to 369 victims, while the rest of the world increased from 205 to 402. The figures show that disruption of established ransomware groups has not prevented new operators from rapidly taking their place.
Scammers Impersonate Farm Equipment Sellers to Steal Thousands From Farmers
The FTC is warning scammers claiming to sell tractors and other farm equipment to farmers. They send convincing purchase agreements and invoices before requesting thousands of dollars by wire transfer. They may also schedule delivery, giving buyers another reason to believe the transaction is legitimate. The equipment never arrives, and scammers either disappear or invent excuses for the delay. The FTC advises buyers to independently verify sellers and avoid payment methods that are difficult to reverse. Fake listings can appear on social media or through paid results impersonating genuine businesses.
FBI Seizes NightmareStresser DDoS-for-Hire Domains
The FBI seized domains associated with NightmareStresser, which the Justice Department describes as one of the world's longest-running DDoS-for-hire services. Customers paid the service to overwhelm targeted systems and disrupt internet access. The action was carried out by the FBI's Anchorage Field Office with Canada's RCMP as part of Operation PowerOFF, an ongoing international effort involving law enforcement agencies from several countries to dismantle DDoS-for-hire infrastructure worldwide. Over eight years, related U.S. enforcement efforts have resulted in more than 100 booter-service domains being seized and 12 defendants charged. Authorities are also targeting the administrators and users of these services.
Bug Bounty Hunter Allegedly Used AI-Built Malware to Create His Own Bounty Opportunities
Recent research says a bug bounty hunter developed and distributed the PhantomRaven information stealer through malicious npm packages. The malware collected system details and CI/CD environment variables that could expose credentials and authentication tokens. CrowdStrike assesses with high confidence that its JavaScript code was generated using an LLM. The operator compromised company systems and then used the access to pursue bug bounty rewards. The hunter claims to have collected bounties from at least nine organizations through established disclosure platforms.
Phone After International Trip Uncovers CSAM, Oregon Man Gets 40 Years
Jayson Setera, 51, of Newberg, Oregon, was sentenced to 40 years in federal prison after being convicted of possessing and transporting child sexual abuse material (CSAM). Law enforcement searched his cellphone after his international flight landed at Newark Liberty International Airport in January 2024, finding approximately 170 photographs and eight videos, including material involving prepubescent minors. The phone also contained messages soliciting CSAM and referring to the sexual abuse of young children, while payment records showed money sent to people who provided the material. Homeland Security Investigations and Customs and Border Protection conducted the investigation under the DOJ’s Project Safe Childhood initiative.
Brevo Attack Uses Compromised Cloudflare Key to Push Malware Through 100,000+ Websites
Attackers used a compromised Cloudflare API key to inject malicious code into Brevo services and scripts embedded on customer websites. The malicious Cloudflare Worker operated for roughly five and a half hours on September 14. Visitors could see a fake Cloudflare verification page instructing them to run a command that installed malware. On affected WordPress sites, the code also attempted to install a malicious plugin when an administrator was logged in. Security firm Sansec estimates that more than 100,000 websites were exposed through the affected Brevo components. Brevo removed the malicious Worker and revoked the compromised credentials.
When Your Device Becomes Evidence Against You
For manufacturers, taking down major ransomware groups is proving to be only part of the battle. On the enforcement side, authorities closed in on several offenders this week, from the extradition of alleged Black Axe leaders to the NightmareStresser DDoS takedown.
The phone used to solicit and exchange child sexual abuse material became the very evidence that exposed the crime, ending in a 40-year prison sentence.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
