Secret CISO 9/13: Revolut Leaks Passports, GitLab CVSS 10 Hit Fast, MikroTik KEV, BlueMoon Spreads
Revolut confirms it handed over passports and Bitcoin histories to a fake government request, GitLab’s CVSS 10 path traversal sees in-the-wild probes within a day, CISA flags two MikroTik RouterOS bugs as exploited, and an exploit kit jumps between spy crews.
Today’s theme: security controls fail most reliably at the seam between “process” and “authority.” If your workflow treats an inbox, a token, or a government email domain like truth, attackers will happily cosplay as truth.
Today's Top 5
- Revolut hands over passports: A fake government request slipped through and triggered a high-octane data disclosure. The scary part is what the package enables next, not what leaked. ([radiousa.com](https://radiousa.com/2026/09/12/revolut-confirms-sensitive-customer-data-breach-falling-for-fake-government-requests/?utm_source=openai))
- GitLab CVSS 10 probed fast: A critical GitLab path traversal bug saw in-the-wild activity about a day after patches dropped. If you run GitLab internet-facing, assume you are in the race already. ([securityweek.com](https://www.securityweek.com/gitlab-vulnerability-exploited-one-day-after-disclosure/))
- MikroTik added to KEV: CISA tagged two RouterOS bugs as actively exploited. If you have MikroTik on the edge, this is a weekend patching story, not a Monday one. ([content.govdelivery.com](https://content.govdelivery.com/accounts/USDHSCISA/bulletins/4298cb9))
- BlueMoon jumps between spy crews: Proofpoint describes an exploit kit that moved across multiple espionage clusters in days. It is a glimpse of the coming “shared exploit supply chain.” ([techradar.com](https://www.techradar.com/pro/security/multiple-hacking-groups-found-using-the-same-chrome-malware-in-the-same-week-so-what-does-it-mean?utm_source=openai))
- Cisco FMC exploited in the wild: Talos-linked reporting says ransomware and state-linked activity both abused FMC flaws. One foothold, many post-exploitation playbooks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/amp/))
Now, the receipts and the parts you can act on.
Data Breaches

- Revolut confirms sensitive customer data disclosed after fake government requests: Revolut told Reuters it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. Revolut says systems and customer funds were unaffected, and it alerted regulators and law enforcement after detection. Source: Reuters (republished) ([radiousa.com](https://radiousa.com/2026/09/12/revolut-confirms-sensitive-customer-data-breach-falling-for-fake-government-requests/?utm_source=openai))
- Trezor phishing wave after Brevo incident hits 347,000 addresses: Trezor says phishing emails were sent to roughly 347,000 opt-in newsletter addresses after an incident at its email provider Brevo, and about 2,500 users clicked before takedown. Expect more follow-on lures because the list is now “validated.” Source: BleepingComputer ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-phishing-attacks-after-brevo-breach/))
- Imperial Healthcare Solutions listed by Qilin on leak site (unverified claim): The Qilin ransomware crew listed Imperial Healthcare Solutions on its leak site on September 12, 2026, per reporting and tracker references. Treat as an extortion signal until the victim confirms, but hunt for Qilin TTPs anyway. Source: RecentBreach.es ([recentbreaches.com](https://recentbreaches.com/breach/imperial-healthcare-solutions-qilin-2026-09?utm_source=openai))
Security Research

- GitLab CVE-2026-85706 exploited one day after disclosure: SecurityWeek reports WatchTowr observed in-the-wild probing for a critical GitLab path traversal that can read arbitrary files via a single unauthenticated HTTP request. If you cannot patch immediately, reduce exposure and review access logs for suspicious repository API paths. Source: SecurityWeek ([securityweek.com](https://www.securityweek.com/gitlab-vulnerability-exploited-one-day-after-disclosure/))
- CISA KEV adds two MikroTik RouterOS CVEs: CISA added CVE-2026-67277 and CVE-2026-86060 to KEV based on evidence of active exploitation. For most orgs this translates to “assume compromise” checks on exposed devices, not just patching. Source: CISA bulletin ([content.govdelivery.com](https://content.govdelivery.com/accounts/USDHSCISA/bulletins/4298cb9))
- Cisco FMC flaws used by ransomware and state-linked clusters: BleepingComputer summarizes Talos findings that CVE-2026-20079 (auth bypass) and CVE-2026-20316 (static credential) were exploited by multiple clusters, including activity that deployed Qilin ransomware in some cases. If FMC is in your environment, treat it like a tier-0 asset. Source: BleepingComputer ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/amp/))
- BlueMoon exploit kit turns patch-gap into capability sharing: Malwarebytes details an exploit kit called BlueMoon that chains Chrome and Windows flaws into real-world attacks, with researchers noting how quickly weaponization follows public fixes. The operational lesson is simple: patch velocity is now an intrusion-prevention control. Source: Malwarebytes ([malwarebytes.com](https://www.malwarebytes.com/blog/bugs/2026/09/bluemoon-exploit-kit-turns-chrome-and-windows-flaws-into-attacks?utm_source=openai))
- MantaxOtax Android malware mixes ransomware with spyware: Zimperium research, covered by Infosecurity Magazine, describes MantaxOtax as Android malware with both encryption and data theft behavior. Mobile threats are borrowing enterprise pressure tactics, with fewer IR playbooks and worse visibility. Source: Infosecurity Magazine ([infosecurity-magazine.com](https://www.infosecurity-magazine.com/news/mantaxotax-android-malware/?utm_source=openai))
- Phishing lures use sexual misconduct claims to push Zoho Assist as a RAT: Cofense reports emails impersonating university leadership and using sensitive allegations to drive clicks, delivering an abused but legitimate remote access tool. The move here is policy plus controls: block unauthorized remote tools and alert on fresh installs. Source: Cofense ([cofense.com](https://cofense.com/blog/false-allegations%2C-real-threats-sexual-misconduct-claims-used-as-phishing-lures?utm_source=openai))
Top CVEs
- CVE-2026-85706: Critical GitLab CE/EE path traversal that allows unauthenticated arbitrary file reads in affected versions. Exploitation attempts were observed rapidly after patch disclosure, so patching is table stakes and exposure reduction buys time only. Source ([securityweek.com](https://www.securityweek.com/gitlab-vulnerability-exploited-one-day-after-disclosure/))
- CVE-2026-67277: MikroTik RouterOS missing authentication for a critical function, added to CISA KEV with evidence of active exploitation. If RouterOS is exposed, validate configuration integrity and rotate credentials after remediation. Source ([content.govdelivery.com](https://content.govdelivery.com/accounts/USDHSCISA/bulletins/4298cb9))
- CVE-2026-86060: MikroTik RouterOS command argument delimiter handling issue, also added to CISA KEV as actively exploited. Prioritize internet-facing routers and any that front management networks. Source ([content.govdelivery.com](https://content.govdelivery.com/accounts/USDHSCISA/bulletins/4298cb9))
- CVE-2026-20079: Cisco Secure Firewall Management Center authentication bypass (CVSS 10.0) that enables unauthorized access in the management plane. Talos-linked reporting ties exploitation to multiple clusters and downstream actions like web shells and credential theft. Source ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2?utm_source=openai))
- CVE-2026-20316: Cisco FMC static credential vulnerability, exploited alongside other FMC weaknesses in the wild. Even when “just” a login weakness, the blast radius is massive because FMC governs firewall policy and visibility. Source ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/amp/))
Podcasts & Talks

- Risky Business #849: Risky Business Podcast: A fresh episode drop with the usual mix of industry news and opinion, good listening for security leaders because it tracks how policy and vendor narratives are shifting this quarter. Listen: Risky Business ([risky.biz](https://www.risky.biz/risky-business/))
- SANS Stormcast (Friday, September 11th, 2026): The daily briefing format is useful for CISOs who want a fast gut-check on what defenders are actually seeing, not just what vendors are selling. Listen: Podscan ([podscan.fm](https://www.podscan.fm/podcasts/sans-internet-stormcenter-daily-cyber-security-podcast-stormcast?utm_source=openai))
Final Words
Revolut’s incident is the reminder nobody wants: sometimes the “exploit” is your compliance workflow. You can patch CVEs all day and still leak the crown jewels because someone sent the right email from the right domain.
GitLab and MikroTik show the other side of the coin. Attackers do not wait for your change window. They wait for your disclosure and your lag.
If this edition helped, forward it to one colleague who owns identity workflows, not just firewalls. If you’re reading this on the web because someone forwarded it, subscribe free at secretciso.org.
Stay vigilant, stay informed, and see you in the next edition of Secret CISO!