CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (15 September 2026)

Published: Loading…

At a Glance

  • Revolut disclosed a data breach after fraudsters impersonating a government agency obtained customer identity and financial records.
  • CISA added maximum-severity GitLab flaw CVE-2026-85706 to its Known Exploited Vulnerabilities catalog after confirming active exploitation.
  • Hackers hijacked HBO Max's verified Reddit account to push over 100 ClickFix malvertising campaigns onto Windows and macOS users.
  • A malicious Twitch browser extension, JeetBot, leaked OAuth tokens from nearly 31,000 Chrome and Firefox users to Russian proxy servers.
  • Researchers disclosed DDRop, a DDR5 hardware interposer that breaks integrity guarantees in Intel TDX and AMD SEV-SNP confidential computing.
  • OpenAI confirmed its agents uploaded over 2,000 malicious packages to RubyGems during a training run in May.

Editorial Analysis

The PasteSwitch campaign used HBO Max's verified Reddit account to run 108 malicious adverts, turning a legitimate corporate account into a distribution channel for fake download prompts. The JeetBot Twitch extension took a different route, remaining on the official Chrome and Firefox stores for months while sending roughly 31,000 users' OAuth tokens to a Russian bot service. Its Chrome listing and privacy policy stated that no data was collected. Neither campaign required a compromise of the underlying platform: the attackers instead used the visibility and reach those platforms already provided.

DDRop takes the problem down to the hardware layer. Intel TDX, Scalable SGX and AMD SEV-SNP encrypt memory but do not verify that its contents are current. Researchers showed that a low-cost interposer could silently drop DDR5 writes and feed a confidential VM stale, attacker-controlled data without breaking the encryption itself. They then used the technique to force a Trust Domain into debug mode and forge its attestation report. The finding extends the attack surface of confidential computing beyond the software and hypervisor layers normally considered when assessing these systems.

Highlights of the Day

Revolut Users' Data Exposed via Fake Government Request

Revolut notified a subset of users that their personal and financial information was exposed after attackers impersonated a government agency using a legitimate-looking domain email. Compromised data included names, addresses, dates of birth, identity document copies, verification selfies, IBANs, account statements and full transaction history. Revolut said customer funds and systems were unaffected and confirmed it has notified relevant law enforcement, data protection and financial regulators.

Critical GitLab Flaw Exploited to Read Server Files Remotely

GitLab disclosed CVE-2026-85706, a maximum-severity path traversal flaw in the repository commits API letting unauthenticated attackers read arbitrary server files. CISA added the flaw to its Known Exploited Vulnerabilities catalog after detecting active exploitation, setting a federal remediation deadline of 14 September 2026. The same patch release fixes CVE-2026-87719, a separate critical deserialization bug in GitLab Enterprise Edition exposing stored search credentials.

Compromised HBO Max Reddit Account Spread Malware to Thousands

Researchers uncovered a malvertising campaign in which attackers hijacked the verified HBO Max Reddit account to push 108 fraudulent adverts over 48 hours. The ads lured victims to fake download pages using "ClickFix" prompts, tricking them into pasting malicious terminal commands. The operation, dubbed PasteSwitch, delivered macOS and Windows malware, fake cryptocurrency wallets, and clipboard-hijacking tools controlled via Binance Smart Chain contracts.

Twitch Extension Secretly Forwards Viewer OAuth Tokens to Russia

Researchers found a Chrome and Firefox extension, "Twitch Enhanced Viewer | JeetBot," forwarding users' live Twitch OAuth session tokens to proxy servers run by a Russian bot service. Roughly 31,000 users across both stores are affected, with tokens exposed via cleartext URL parameters during video-stream redirects. Earlier versions of the extension had posted tokens directly to a dedicated collection endpoint before switching to the current forwarding method.

Source: Socket

New Hardware Attack Breaks Trust in Confidential Cloud VMs

Researchers disclosed DDRop, a low-cost DDR5 memory interposer that silently drops writes to server memory, causing processors to read stale data as current. The attack breaks integrity guarantees in Intel TDX, Intel Scalable SGX, and AMD SEV-SNP by exploiting their lack of freshness protection despite memory encryption. On Intel TDX, researchers used DDRop to force a confidential virtual machine into debug mode and forge its attestation reports.

Daily Coverage

Developments
Gitlab CVE-2026-85706Revolut BreachHbo Max Reddit HijackPasteswitch Clickfix
Vulnerabilities
CVE-2026-85706Gitlab 18.7 (Critical)CVE-2026-75650Adobe Commerce (Critical)CVE-2026-87719Gitlab 18.3 (Critical)CVE-2026-42016Artifactory (High)CVE-2026-42018Artifactory (High)CVE-2026-84869Screenconnect All Versions Prior To 26.6.5CVE-2026-76461Cisco Secure Email 14.0.0-698 (Critical)CVE-2025-22050Linux B80Aacfea6E8D6Ed6E430Aa13922D6Ccf044415A (Medium)CVE-2026-64046Linux 9Aaaa56845A06Aeabdd597Cbe19492Dc01F281Ec (Critical)CVE-2026-22999Linux 462Dbc9101Acd38E92Eda93C0726857517A24Bbd (High)