Visualização normal

Ontem — 8 de Setembro de 2026Cybersecurity News
  • ✇Cybersecurity News
  • CVE-2026-75650 (CVSS 10): Adobe Commerce Arbitrary Code Execution Exploited in the Wild Do Son
    An Adobe Commerce vulnerability, CVE-2026-75650 (CVSS 10), enables unauthenticated arbitrary code execution and is exploited in the wild. Patch now. Related Posts: September 2026 SAP Security Patch Day Fixes Critical Flaws ASUS Patches Control Center Express and Armoury Crate Flaws Public PoC Disclosed for ZcopyReaper Linux Vulnerability (CVE-2026-43502) The post CVE-2026-75650 (CVSS 10): Adobe Commerce Arbitrary Code Execution Exploited in the Wild appeared first on Daily CyberSecurity.
     
Antes de ontemCybersecurity News
  • ✇Cybersecurity News
  • StyleSmuggler: Magento Zero-Day RCE Exploited in the Wild Do Son
    StyleSmuggler, a Magento zero-day, gives unauthenticated remote code execution and is exploited in the wild. No patch yet. Mitigate now. Related Posts: CVE-2026-86218 (CVSS 10): N-central Pre-Auth RCE Exploited in the Wild MikroTrick PoC: RouterOS Admin Rights Exploited In Wild AI Agent Coordination: The Unprecedented OpenAI Breakout The post StyleSmuggler: Magento Zero-Day RCE Exploited in the Wild appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • NightmareEclipse Releases PoCs for Avast, Kaspersky, and NVIDIA Flaws Do Son
    Discover the details of three new NightmareEclipse vulnerabilities targeting Avast, Kaspersky, and NVIDIA components, lacking official vendor confirmation. Related Posts: CVE-2026-81934: Redis RCE PoC Exploit Now Public CVE-2026-78319: SAUTER Controller RCE Flaw Disclosed CVE-2026-82329 Exploited: JFrog Artifactory Admin Takeover The post NightmareEclipse Releases PoCs for Avast, Kaspersky, and NVIDIA Flaws appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Anthropic Issues Claude Security Warnings Do Son
    Anthropic is sending security warnings and deleting payment methods as info-stealing malware compromises Claude user sessions. Protect your account now. Related Posts: ToxNetV2 Botnet Integrates AI ToxicPanda 2.0 Banking Trojan Attacks Escalate Globally NPM Typosquatting Malware Targets WSL Developers The post Anthropic Issues Claude Security Warnings appeared first on Daily CyberSecurity.
     

Anthropic Issues Claude Security Warnings

Por:Do Son
31 de Agosto de 2026, 07:23

Anthropic is sending security warnings and deleting payment methods as info-stealing malware compromises Claude user sessions. Protect your account now.

Related Posts:

The post Anthropic Issues Claude Security Warnings appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • NCSC Warns of Physical Disruptions from Cyberattacks on OT Systems Do Son
    The UK NCSC warns of rising cyberattacks on operational technology, urging organizations to secure internet-exposed industrial systems against physical disruptions. Related Posts: Google Tracks Russian Cyber Espionage Clusters OpenAI Disrupts Russian Influence Campaign Promoting Fake Think Tank NIST Asks for Help Putting People First in Cybersecurity The post NCSC Warns of Physical Disruptions from Cyberattacks on OT Systems appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Fire Ant Threat Actor Targets Trusted Infrastructure Do Son
    The Fire Ant threat actor uses trusted infrastructure compromise to breach high-value targets. Discover how this group evades detection in networks. Related Posts: ValleyRAT Backdoor Spread via Signed Chinese Adware UAT-10147 Deploys SPECTRE Cross-Platform Implant Kimsuky Spear Phishing Abuses Remote Control Tools The post Fire Ant Threat Actor Targets Trusted Infrastructure appeared first on Daily CyberSecurity.
     
  • ✇Security Affairs
  • Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft Pierluigi Paganini
    Extortion group FulcrumSec claims they stole 86GB of Manchester Airports Group data after finding API credentials exposed in client-side JavaScript. Manchester Airports Group (MAG) disclosed a data breach on August 27 affecting customers of Manchester, London Stansted, and East Midlands airports. Two days later, BleepingComputer reports the extortion group FulcrumSec claimed responsibility, saying it stole roughly 86GB of data, considerably more detailed than what MAG’s original disclosure s
     

Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft

30 de Agosto de 2026, 14:21

Extortion group FulcrumSec claims they stole 86GB of Manchester Airports Group data after finding API credentials exposed in client-side JavaScript.

Manchester Airports Group (MAG) disclosed a data breach on August 27 affecting customers of Manchester, London Stansted, and East Midlands airports. Two days later, BleepingComputer reports the extortion group FulcrumSec claimed responsibility, saying it stole roughly 86GB of data, considerably more detailed than what MAG’s original disclosure suggested.

MAG’s own statement describes a relatively limited set of exposed data. It says the breach affected car park, lounge, Fast Track bookings, and airport WiFi registrations, exposing email addresses, phone numbers, vehicle registrations, and postcodes.

MAG disclosed that the data breach impacted 8.7 million customers, however, the company says most of those customers had only their email addresses exposed.

FulcrumSec tells a different story. The group shared samples with BleepingComputer that included a 21.5GB export of Manchester customer data, with personal identifiers, historical booking details, and marketing information. BleepingComputer checked one record against a real traveler’s purchase history and found matching Fast Track bookings, arrival times, terminal information, and payment amounts.

The alleged way into the system is particularly concerning. FulcrumSec says it found airport-specific Iterable API credentials inside client-side JavaScript. That code runs in users’ browsers, so anyone inspecting the website with developer tools could potentially see those credentials.

“The group claims it obtained access using airport-specific Iterable API credentials exposed in client-side JavaScript and that the stolen material includes nearly 200,000 records related to upcoming travel during the remainder of 2026.” states the report. These records allegedly contain dates, times and booking information linked to personally identifiable information. FulcrumSec says it intends to publish the stolen data and a technical account of the intrusion. If the claim is accurate, attackers did not need a highly sophisticated technique. They simply found sensitive API credentials exposed in code that the website sent directly to customers’ browsers.”

The most concerning specific claim is nearly 200,000 records tied to upcoming travel through the rest of 2026, complete with dates, times, and booking details linked to identifiable individuals. BleepingComputer couldn’t independently verify that number or the full scope of what was actually taken, and MAG declined to directly address FulcrumSec’s specific claims when asked, instead pointing to its existing statement that affected customers with upcoming bookings had already been contacted. MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, a spokesperson said, without engaging with the 86GB figure or the exposed-credentials claim directly.

FulcrumSec plans to publish the stolen data but may redact upcoming travel records because of the risk of real-world harm. UK postcodes can identify very small groups of addresses, and combined with vehicle registrations, parking dates and booking details, the data could enable highly convincing phishing messages targeting people with upcoming trips.

UK postcodes make this exposure sharper than the equivalent breach might be in the US. Unlike American ZIP codes covering broad delivery areas, a full UK postcode typically identifies a small cluster of neighboring addresses, sometimes a single property, according to the Office for National Statistics. Combined with vehicle registrations, parking dates, and specific booking references, that’s more than enough raw material for a phishing message referencing a real upcoming trip that would be very hard to distinguish from a genuine MAG communication.

Security researchers commenting on the broader incident have flagged a supply-chain angle worth watching. Airport operations increasingly run through third-party platforms for booking, parking, and loyalty services rather than systems the airport itself directly controls, and Iterable, the marketing platform whose API credentials FulcrumSec claims to have abused, is exactly that kind of outsourced dependency. This also isn’t aviation’s first bad year: a September 2025 ransomware attack on Collins Aerospace‘s check-in software had already grounded systems at Heathrow, Brussels, and Berlin, meaning UK and European aviation infrastructure has now taken two significant hits inside twelve months.

MAG says no payment card or banking data was exposed, however, travelers who recently booked parking, lounge access or Fast Track should assume more travel data may be exposed and treat messages citing real booking details with caution.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Manchester Airports Group (MAG))

  • ✇Cybersecurity News
  • TeamPCP Hackers Arrested in Joint Operation Do Son
    Discover the details of the TeamPCP hackers arrested in Australia for executing devastating open-source supply chain attacks using the Mini Shai-Hulud worm. Related Posts: FBI Seizes QScan and QTRouter Platforms Run by China State Hackers SilkParasite APT Hits Central Asian Governments With 7 RATs Operation CameraSwarm: 14,500 Dahua Cameras Compromised Across Ukraine and Russia The post TeamPCP Hackers Arrested in Joint Operation appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • macOS ClickFix Malware Exploits Polygon C2 Do Son
    A new macOS ClickFix malware campaign hides C2 servers on the blockchain. See how this macOS ClickFix malware steals crypto wallets and credentials. Related Posts: SynkLoader Malware Deploys Multi-Language Attack Tools WeedHack Malware Still Hits Minecraft Gamers via Fake Sites Cruciferra Malware Loader Uses ClickFix Lures to Kill EDR The post macOS ClickFix Malware Exploits Polygon C2 appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-71362 Exploited: Adobe Commerce Account Takeover, Details and PoC are Public Do Son
    Attackers exploit CVE-2026-71362, an unauthenticated Adobe Commerce account takeover flaw (CVSS 9.1). Details and PoC are public. Patch now. Related Posts: Critical MongoDB Security Vulnerabilities Require Immediate Patching CVE-2026-73125: Ebyte NA111-M Flaws Let Attackers Fully Compromise the Device D-Link DIR-X1860Z Flaw Lets Attackers Change the Admin Password Without Login The post CVE-2026-71362 Exploited: Adobe Commerce Account Takeover, Details and PoC are Public appeared first on Dai
     
  • ✇Cybersecurity News
  • Mercor Data Breach Targets AI Supply Chain Do Son
    Discover the details of the massive Mercor data breach exposing 4TB of recruiting data for OpenAI, Google, Meta, and Microsoft. Related Posts: Meta Settles Child Privacy Lawsuit Rapidly Exposed Git Repositories Leak Critical Cloud Secrets Take-Two Subpoenas Microsoft and Discord Over GTA VI "Cyberleek" Leaks The post Mercor Data Breach Targets AI Supply Chain appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-72137 (CVSS 9.8): Linux Kernel Flaw Enables Root Privilege Escalation, PoC Public Do Son
    A public PoC exploit targets CVE-2026-72137, a CVSS 9.8 Linux kernel double-free that enables root privilege escalation. Patch now. Related Posts: CVE-2026-19042: TeamViewer Command Injection Enables Remote Code Execution CISA Adds Six Exploited Vulnerabilities Including Citrix NetScaler Flaw Dell Cloud Disaster Recovery CVE-2026-70419 (CVSS 9.1) Allows Command Execution The post CVE-2026-72137 (CVSS 9.8): Linux Kernel Flaw Enables Root Privilege Escalation, PoC Public appeared first on Daily
     
  • ✇Cybersecurity News
  • Jewelbug APT Group Operations Combine Espionage and Fraud Do Son
    The Jewelbug APT group runs espionage alongside cryptocurrency scams. Read our report on Jewelbug APT group operations. Related Posts: Cisco Talos Discovers JWR Phishing Framework US Agencies Warn of AI-Generated Exploits Targeting Siemens S7 PLCs PATCHCORD Malware Hits Afghan Telecom in New APT36 Campaign The post Jewelbug APT Group Operations Combine Espionage and Fraud appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Cisco Talos Discovers JWR Phishing Framework Do Son
    Cisco Talos discovered the JWR phishing framework, a new PhaaS variant. Read our JWR phishing framework analysis to learn about this real-time cyber threat. Related Posts: Jewelbug APT Group Operations Combine Espionage and Fraud US Agencies Warn of AI-Generated Exploits Targeting Siemens S7 PLCs PATCHCORD Malware Hits Afghan Telecom in New APT36 Campaign The post Cisco Talos Discovers JWR Phishing Framework appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Armored Likho Still Toolkit Deploys Covert Spying Implants Do Son
    Kaspersky uncovered the Armored Likho Still Toolkit. Read our Armored Likho Still Toolkit analysis to explore the Telegram stealer and audio spying tools. Related Posts: PATCHCORD Malware Hits Afghan Telecom in New APT36 Campaign HoneyMyte CoolClient Rootkit Deploys Kernel Driver DOJ Charges 17 Iranians in Mabna Institute Cyber Theft The post Armored Likho Still Toolkit Deploys Covert Spying Implants appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Abyssos Modular RAT: Zscaler ThreatLabz Analysis Do Son
    Zscaler ThreatLabz analysts discovered the Abyssos modular RAT. This Abyssos RAT gives attackers total remote control, stealing data and credentials. Related Posts: GEEKOM Mini PC Driver Downloads Found Bundled With Backdoor Since 2024 Aeternum Blockchain Botnet Hides C2 Commands in Polygon Smart Contracts DCRat Campaign Uses SVG HTML Smuggling to Deliver DarkCrystal RAT The post Abyssos Modular RAT: Zscaler ThreatLabz Analysis appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Kimwolf Botnet Malware Upgrades DDoS and C2 Defenses Do Son
    Palo Alto Networks analyzed Kimwolf botnet malware. Read our Kimwolf botnet malware analysis to learn how it attacks Android TV boxes. Related Posts: Project CAV3RN Framework Adds DNS and Google Relays DeadLock Ransomware Employs Decentralized Infrastructure Apple Sends Mercenary Spyware Alerts to Users in 110+ Countries The post Kimwolf Botnet Malware Upgrades DDoS and C2 Defenses appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Project CAV3RN Framework Adds DNS and Google Relays Do Son
    Kaspersky analyzed the Project CAV3RN framework. Read our Project CAV3RN framework analysis to see how attackers abuse DNS and Google Apps Script. Related Posts: Kimwolf Botnet Malware Upgrades DDoS and C2 Defenses DeadLock Ransomware Employs Decentralized Infrastructure Apple Sends Mercenary Spyware Alerts to Users in 110+ Countries The post Project CAV3RN Framework Adds DNS and Google Relays appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • DeadLock Ransomware Employs Decentralized Infrastructure Do Son
    DeadLock ransomware uses blockchain nodes and Session chat. Learn how the DeadLock ransomware encryptor targets networks worldwide. Related Posts: Kimwolf Botnet Malware Upgrades DDoS and C2 Defenses Project CAV3RN Framework Adds DNS and Google Relays Apple Sends Mercenary Spyware Alerts to Users in 110+ Countries The post DeadLock Ransomware Employs Decentralized Infrastructure appeared first on Daily CyberSecurity.
     
  • ✇Firewall Daily – The Cyber Express
  • Thailand SEC Files Criminal Complaint Against Bitkub Over 2021 Cyberattack Ashish Khaitan
    Thailand's cryptocurrency exchange Bitkub has rejected allegations of fraud after the Thailand SEC filed a criminal complaint related to the company's disclosures following the Bitkub cyberattack in 2021. The case focuses on how the exchange reported the impact of the cyberattack on Bitkub to regulators, rather than on the safety of customer funds.  In response to the complaint, Bitkub stated that all customer assets currently held on its platform remain safe, fully accounted for, and protect
     

Thailand SEC Files Criminal Complaint Against Bitkub Over 2021 Cyberattack

Bitkub cyberattack

Thailand's cryptocurrency exchange Bitkub has rejected allegations of fraud after the Thailand SEC filed a criminal complaint related to the company's disclosures following the Bitkub cyberattack in 2021. The case focuses on how the exchange reported the impact of the cyberattack on Bitkub to regulators, rather than on the safety of customer funds.  In response to the complaint, Bitkub stated that all customer assets currently held on its platform remain safe, fully accounted for, and protected in accordance with applicable regulations. The company argued that the allegations stem from decisions made during the aftermath of the 2021 security breach and do not reflect fraudulent conduct. 

Thailand SEC Files Complaint Over the 2021 Bitkub Cyberattack 

On 23 July 2026, the Thailand SEC filed a criminal complaint against Bitkub Online Co., Ltd. and its former directors, Sakolkorn Sakavee and Thaweesap Rawan. The regulator alleged that the company's daily net capital reports submitted between 10 May and 30 October 2021 failed to accurately reflect the material reduction in its digital asset holdings caused by the Bitkub cyberattack.  According to the regulator, the reports did not disclose the impact of the theft on the company's asset balance. The Thailand SEC also accused the two former directors of making false entries in company documents that gave the impression that customer assets were still being held normally and that the company had not suffered any damage.  The complaint has been referred to Thailand's Economic Crime Suppression Division for further investigation. Following that process, the matter may be forwarded to prosecutors and the courts. The Thailand SEC noted that filing a criminal complaint does not represent a final determination of guilt. 

Bitkub Says Disclosure Decision was Intended to Prevent Customer Losses

Following media reports about the complaint, Bitkub published a statement on LinkedIn explaining its position on the cyberattack and the subsequent reporting decisions.  The company said the allegations relate to an incident in early May 2021, when one of its digital asset wallets was compromised by cybercriminals. Bitkub acknowledged that the breach was not disclosed at the time.  According to the company, the individual responsible for disclosure obligations deliberately withheld information about the wallet compromise. Bitkub said the decision was made to avoid triggering a "bank run," or mass withdrawals of digital assets by customers, while the company worked to replace the stolen assets.  The exchange stated:  "The decision of such individual not to disclose the incident was made with the intention to prevent a bank run—that is, a mass withdrawal of digital assets by customers upon learning of the theft—which could have rendered the Company unable to procure sufficient replacement digital assets for the customers while the recovery process was still ongoing."  Bitkub added that such a scenario could have resulted in significant customer losses and broader damage to Thailand's digital asset industry.  The company also stressed that, at the time of the Bitkub cyberattack, all of its digital asset wallet security systems complied with standards prescribed by the relevant authorities and had been audited. 

Co-founders Replaced Stolen Assets After Cyberattack on Bitkub 

Although the digital assets stolen during the cyberattack on Bitkub were never recovered, the company said its co-founders voluntarily absorbed the financial loss.  According to Bitkub, the co-founders purchased digital assets matching the same types and quantities as those stolen and transferred them to the company. As a result, the exchange said neither its customers nor the business ultimately suffered any financial loss from the incident.  In its statement, Bitkub said:  "As no bank run occurred, even though the stolen digital assets could not be recovered, the Co-Founders of the Bitkub Group voluntarily absorbed the loss by purchasing equivalent digital assets (in the same type and quantity as those stolen) and providing them to the Company. Consequently, neither the Company nor its customers suffered any financial loss from the theft." 

Thailand SEC Previously Confirmed Customer Assets Were Intact 

Bitkub also pointed to the findings of an earlier inspection conducted by the Thailand SEC after reports of the Bitkub cyberattack surfaced online. According to the company, the regulator verified that, as of 8 September 2025, all customer assets held by the exchange were safe and fully accounted for.  The company reiterated this point in its latest statement, saying:  "At the outset, for the sake of clarity and mutual understanding, the Company wishes to affirm that all customers' assets currently held by the Company are safe and fully accounted for. The Company reiterates its strict compliance with all applicable laws and regulations in safeguarding and maintaining customer assets."  Bitkub maintained that the criminal complaint relates to historical reporting practices between May and October 2021, more than five years ago, rather than to the current condition of customer assets or any ongoing security concerns.  As the investigation proceeds, the case will determine whether the company's reporting following the Bitkub cyberattack complied with regulatory requirements. For now, the complaint remains an allegation, and the legal process involving the Thailand SEC, investigators, prosecutors, and the courts has yet to reach a final conclusion. 
❌
❌