Today’s Menu (30-second skim)

  • Revolut says scammers used fake government requests to get customer data: Criminals tricked their way into sensitive customer information, which can make future scams sound very real.
  • Crypto customers got phishing emails after an email provider breach: A trusted email system was abused to send fake crypto security alerts that tried to steal wallet backup words.
  • Chrome fixed a security bug attackers were already using: Google patched Chrome after attackers were already using a browser bug, so restarting after updates matters.

1) Revolut says scammers used fake government requests to get customer data

Revolut says scammers used fake government requests to get customer data story image

What happened (plain English): Revolut said an unauthorized person got some customer information by sending fake information requests from a real government email domain. That made the request look more believable, like a letter with an official-looking return address. The exposed information could include names, birthdays, addresses, phone numbers, email addresses, ID documents, verification selfies, account statements, and transaction history. Revolut said only a limited number of customers were affected. The company also said customer funds and Revolut systems were not affected, and it blocked the email address, contacted affected customers, and alerted officials.

Why it matters to you: The danger is not just what was taken today, but how it can be used tomorrow. If a scammer already knows your birthday, address, or recent banking history, a fake bank call can sound much more convincing. One realistic trick is a caller saying, “We see a suspicious transfer from your Revolut account,” then asking you to move money to a “safe” account. Another is a text that includes real personal details and pushes you to click a link to “verify” your identity.

How to protect yourself (do this):

  • If you get a message about a bank problem, do not use the phone number or link in the message. Open the bank app or use the number on your card.
  • Be extra suspicious of anyone who already knows your birthday, address, or part of your account history. That does not prove they are legitimate.
  • Turn on transaction alerts and review recent bank activity for small test charges or unfamiliar transfers.
  • If your ID document was exposed, watch for credit checks or new accounts you did not start.

Published: 2026-09-12

Source: TechCrunch


2) Crypto customers got phishing emails after an email provider breach

Crypto customers got phishing emails after an email provider breach story image

What happened (plain English): An attacker broke into Brevo, an email marketing service used by cryptocurrency companies and other businesses. Brevo said 138 customer accounts were accessed, 6 accounts were used to send phishing emails, and contacts were exported from 43 accounts. People who used companies like Trezor, CoinTracking, and BitBox received scam emails that looked like urgent security warnings. One fake Trezor email tried to scare people into downloading an app and entering their wallet backup words. In plain terms, the scam came through a familiar-looking newsletter path, which made it feel more trustworthy than a random spam message.

Why it matters to you: A familiar sender name is not a safety guarantee. A scam email can come from a list you really joined, or from a company tool the business really uses. One abuse scenario is a fake “your wallet is at risk” message that sends you to a lookalike site. Another is a fake app that asks for your recovery words, which can let thieves drain a crypto wallet permanently.

How to protect yourself (do this):

  • Never type crypto recovery words, seed phrases, or backup words into a website or app because an email told you to.
  • Treat urgent wallet warnings as suspicious until you confirm them on the company’s official website or support page.
  • Use bookmarks for financial and crypto sites instead of clicking email links.
  • If you clicked a link but did not enter secrets, close it, update your device, and watch for follow-up scam messages.

Published: 2026-09-11

Source: Malwarebytes


3) Chrome fixed a security bug attackers were already using

Chrome fixed a security bug attackers were already using story image

What happened (plain English): Google released a Chrome update that fixed 230 security problems. One of those problems was already being used by attackers. The bug, called CVE-2026-87491, affected V8, the part of Chrome that runs JavaScript on websites. JavaScript is the code many websites use to make pages interactive, like buttons, menus, and forms. A malicious web page could use the bug to run code inside Chrome’s sandbox, and CISA added the bug to its Known Exploited Vulnerabilities list on September 9.

Why it matters to you: This is the kind of issue where a bad web page can be dangerous if your browser is behind on updates. You do not have to be a hacker or do anything fancy to be at risk. One realistic scenario is clicking a link from a fake delivery text and landing on a booby-trapped page. Another is tapping a scary ad or social post that rushes you to “check your account” before your browser has been restarted and fully updated.

How to protect yourself (do this):

  • In Chrome, go to More > Help > About Google Chrome, let it update, then relaunch the browser.
  • Do the same update check for Edge, Brave, Opera, or Vivaldi if you use one of those.
  • Do not postpone browser restarts for days. The update often does not fully protect you until the browser restarts.
  • Be careful with links in unexpected texts, emails, ads, and social posts, especially when they push urgency.

Published: 2026-09-09

Source: The Hacker News


Grandma’s Firewall

Grandma's Firewall

This week’s simple rule: If a warning arrives by message, check it from a separate path. Do not trust the link, app, or phone number that came inside the warning.

Two scripts you can steal:

  • “Thanks for the heads-up. I’m going to check from my own app or bookmark before I do anything.”
  • “I don’t enter passwords, banking details, ID information, or recovery words from a message link. I’ll contact the company through its official site.”

Top rated products