• John Hammond
  • Posts
  • Cybersecurity Shenanigans #028: Fake feds trick Revolut, five AI browsers get hijacked (Claude included 😬), and GitLab scores a 10 (not in a good way)

Cybersecurity Shenanigans #028: Fake feds trick Revolut, five AI browsers get hijacked (Claude included 😬), and GitLab scores a 10 (not in a good way)

Here's this month's cybersecurity scoop.

👋 Hey friend,

Is there something in the water this month? Because it feels like everybody is getting got. 👀

A fintech company fell for an email that looked official. Five AI browsers proved to be “hijackable” by a plain old browser extension. And a GitLab vulnerability earned a 10 severity score. And we’re only halfway through September. 🫣

Let’s dig in. And as always, thank you for being here! 💙

— JH

News & Commentary

Revolut Got Social-Engineered by a Fake Government Agency, and Customers' Passports Paid the Price ✈️

Revolut just disclosed a doozy: a "sophisticated impersonation operation" straight up tricked them into handing over customer data. We're talking passport and driver's license copies, ID-verification selfies (yikes 😅), full transaction histories including Bitcoin activity, IBANs — basically a starter kit for building a very convincing fake….you.

Here’s what happened. Someone got their hands on an email account sitting on a legitimate government agency's domain and used it to send what looked like a totally valid legal request. Domain authentication checked out, so Revolut treated it as real and handed the stuff over. And there’s the problem: Domain authentication tells you the email came from the right mail server. It does not tell you whether the account sending it should be trusted. Those are two very different things.

Revolut's saying, probably correctly, that this wasn't a breach of their core systems or app, and funds are safe. Not super comforting though, right? If your passport scan and your entire crypto transaction history are floating around out there, "your account wasn't hacked" doesn't really land that great. ZachXBT and folks in the crypto community are already flagging that this looks targeted at high-net-worth users specifically — which, of course it does. 😅 That's exactly the crowd that gets hammered with SIM-swapping, extortion, and "hi, this is definitely your bank" calls.

Takeaway here: Authenticated does not mean authorized. If you're the one fielding "urgent" requests from official-looking domains, verify it out-of-band before you send anything. Pick up the phone, call a known number. And if you're a Revolut customer, just assume your KYC docs are out there now and keep your guard up for phishing that knows way too much about you.

One Extension to Hijack Them All: Chrome, Comet, Edge, Opera Neon, and Yes, Even Claude 🤖

I think this one is gonna hit close to home for all of us. 😅

Researchers at Forever Security just proved that a plain browser extension with permission to tweak web pages could hijack the AI assistants that live in five different Chromium-based products: Gemini Live in Chrome, Perplexity's Comet, Microsoft Edge, Opera Neon, and yep, Claude in Chrome.

It takes into account how AI setups work. Each one has a “body” of sorts living in your browser. It can see the screen, open files, use your camera, etc. Then you have its “brain,” which lives on the company’s servers and tells the “body” what to do. The “body” is only supposed to take orders from one trusted page — think gemini.google.com, perplexity.ai, etc. An extension isn’t supposed to be able to command that body at all. It can kinda mess with web pages, sure, but not talk to the AI directly.

So Forever Security just…kinda took over the trusted page instead. With two permissions that ad blockers use all the time, they got their extension to inject code into that trusted page and start issuing commands as if they were the vendor.

Of all the impacted assistants, Perplexity’s Comet took the biggest hit. Perplexity built Comet as a fully AI-driven browser, so once hijacked, the agent could read any file on your machine, extract your browsing history, take screenshots, and even act as you. In Perplexity’s defense, they’d actually locked down extensions on their main page……but they left a test address wide open. Oops. 😅

None of this has shown up in an actual attack in the wild, and every method here needs the attacker to already have you install their extension. But the bigger point stands: Stuffing an AI agent into the browser reopens a door browsers have spent years trying to keep shut, letting a low-privilege extension reach into a high-privilege part of the system.

Takeaway: Update Chrome to 143.0.7499.192+ and Edge to 150.0.4078.48+ if you haven't already, and if you're running Comet, Opera Neon, or Claude in Chrome, just make sure you're current and actually look at what extensions you've got installed. Including that ad blocker you forgot about 10 tabs ago.

GitLab Has a Scary 10 CVE and Hackers Aren't Waiting Around ⚠️

This week, CISA added a GitLab flaw to its Known Exploited Vulnerabilities (KEV) catalog, which is basically the "we're not speculating anymore, this is actively being used" list. Federal agencies had until Monday to patch. That's how you know it's bad.

The bug, CVE-2026-85706, is a path traversal issue. Basically, GitLab wasn't properly checking who you were or where you were allowed to put files, which meant unauthenticated attackers could reach into files they had zero business touching. They released a patch on September 10, so if you're on a vulnerable version, please go patch — this CVE earned a 10 severity score. 😅 

And people are already poking at it. watchTowr said their analysts were seeing in-the-wild probes for vulnerable GitLab servers, warning attackers could use this to "read local files and configs to obtain credentials, secrets, and sensitive information" — so yeah, the exact stuff you really don't want strangers reading off your dev environment.

GitLab also quietly fixed a second one in the same update, CVE-2026-87719, which could leak sensitive info from Enterprise Edition servers. Less flashy, still worth knowing about.

Takeaway: if you're running a self-managed GitLab instance, patch to the fixed version now, not after your next planning meeting. Given the track record, "we'll get to it" is exactly how these turn into headlines.

Email being clipped?

Here’s some actually helpful advice: You can view the email in your browser: https://johnhammond.beehiiv.com/p/cybersecurity-shenanigans-028.

(And as always, thanks for nothing, Clippy. 💙)

Latest Content

// Recently, I got a message under embargo: "We deanonymized Team PCP." 👀 For 5 days in March 2026, one stolen token let this hacker group poison 5 software ecosystems — including a package downloaded 95 million times a month. In this video, we recreate the entire investigation and unmask the person behind the cat avatar. 🐱

// What if exploring open directories on the internet felt like playing Minecraft? Dimensions instead of IPs, mobs instead of files, weapons instead of tools. I don't play Minecraft or know how to mod it, so I had AI build it during a livestream. 😅

// A standard user. A privilege escalation bug in the Steam client. Full system access on Windows. 😅 I dig into the proof-of-concept and use some AI-assisted research to show exactly how it works.

Just Hacking Training News 🤓

September Course Release

Brandon Keath brings us the first of many courses in our Coding for Cybersecurity series: Python Fundamentals. No programming experience required!

20% off course launch discount expires Midnight ET September 30

This course aims to help you build confidence in the fundamentals while connecting each concept to real cybersecurity tasks such as log analysis, command-line tools, data parsing, reporting, and safe automation. Confidence will help you code more; coding more will help you understand different parts of programming and how they work. Course includes:

1️⃣ Python from the Ground Up (Start from absolute zero!)
2️⃣ Your First Cybersecurity Scripts
3️⃣ Using AI to Learn and Build Faster
4️⃣ Python Hands-on Cybersecurity Projects

Price = $50 $40 with 20% Launch Discount

Have fun and learn by doing with useful projects!

Blue Team Con Freebies

JHT had a blast at Blue Team Con in Chicago last weekend. Thanks for everyone that stopped by to “Hack a Drug Lord’s Smart Toilet”! Missed it? We gotchu!

Both free mini-workshops AKA Extended Upskill Challenges created for the IoT Village this year AND the 2 from last year are all FREE online! They are NameYourPrice with a $0 minimum, so anything you can contribute helps us to deliver great content to the community.

Labor Day ALL Month

20% Off Courses w/ Code LABOR20
Exp Midnight ET Sept 30

Save on Suggested Courses

❤️ Red Team

❤️ Web App Pentesting Jr Analyst
❤️ API Hacking
❤️ Phishing for Red Teams
❤️ Windows Malware Dev - 1 of 6
❤️ Mastering AD Security Vol 1
❤️ Dark Web & Cybercrime Investigations
❤️ Beginner Level OSINT
❤️ Hardware Hacking 101 w/ Kit!

Blue Team 💙

💙 AI Cyber Defense Ops
💙 Constructing Defense 2026 with AI Teaching Assistant
💙 ConDef Lite (DIY Version)
💙 SOC Analyst 101
💙 SIEMless Threat Hunting
💙 Incident Response 101
💙 Ease Me into Cryptography
💙 Script-Based Malware Analysis

Courses in Production: AI Hacking Part 1: Anatomy of an LLM, Cyber Threat Intelligence L1, Networking for Pentesters, Jr Network Pentester and more!

Happy Hacking!