Revolut breach and Cisco email gateway 0‑day patch – what you need to know
Last week two separate cyber incidents made headlines: Cisco released an emergency patch for a zero‑day flaw in its email security gateway that was actively exploited, and Revolut confirmed that a phishing attack stole sensitive customer data. Both events highlight the ongoing risk of email‑based attacks and the need for strong security hygiene.
Cisco’s Secure Email and Web Appliance (SWE) contains a vulnerability that allowed attackers to execute code on the device without authentication. The flaw was discovered being used in the wild, prompting Cisco to issue a critical update on September 13. Organizations that run the appliance must apply the patch immediately, as the vulnerability could let hackers intercept, modify, or forward corporate email traffic, potentially exposing confidential information.
The Revolut incident involved a fraudster posing as a government agency using a legitimate‑looking email address from that agency’s domain. The attacker convinced a Revolut employee to share internal files, resulting in the exposure of customer names, email addresses and partial financial details. Revolut announced the breach on September 12 and began an internal investigation while notifying affected users.
Both cases target the same weak point: phishing emails that appear authentic. The Cisco exploit relied on malicious email content to reach vulnerable gateways, while the Revolut breach used social engineering to gain trust and extract data. Users and administrators should treat any unexpected request for credentials or internal documents with suspicion, even if the sender’s address looks legitimate.
To reduce the risk, apply Cisco’s patch without delay and verify that all email security appliances are up to date. Enable multi‑factor authentication on all accounts, especially for privileged users. Use strong, unique passwords and consider a password manager to avoid reuse. Regularly scan inbound emails with anti‑phishing tools and educate staff on how to spot a scam, such as checking sender details, hovering over links, and confirming requests through a separate channel.
ComputerScams.com offers free tools to test password strength and check if an email address has been involved in known phishing campaigns. Running these checks can alert you to compromised credentials before attackers exploit them.
If you suspect that your Revolut account or any other service has been accessed without permission, change your passwords immediately, enable two‑factor authentication, and monitor your statements for unauthorized activity. Report suspicious emails to your IT department or to the service provider’s abuse team.
Stay vigilant: the quickest way to protect yourself online is to verify any unsolicited request for personal or financial information before responding.
Source: Read the original report