Visualização normal

Hoje — 8 de Setembro de 2026Stream principal
  • ✇Cybersecurity News
  • CVE-2026-75650 (CVSS 10): Adobe Commerce Arbitrary Code Execution Exploited in the Wild Do Son
    An Adobe Commerce vulnerability, CVE-2026-75650 (CVSS 10), enables unauthenticated arbitrary code execution and is exploited in the wild. Patch now. Related Posts: September 2026 SAP Security Patch Day Fixes Critical Flaws ASUS Patches Control Center Express and Armoury Crate Flaws Public PoC Disclosed for ZcopyReaper Linux Vulnerability (CVE-2026-43502) The post CVE-2026-75650 (CVSS 10): Adobe Commerce Arbitrary Code Execution Exploited in the Wild appeared first on Daily CyberSecurity.
     
Antes de ontemStream principal
  • ✇Cybersecurity News
  • StyleSmuggler: Magento Zero-Day RCE Exploited in the Wild Do Son
    StyleSmuggler, a Magento zero-day, gives unauthenticated remote code execution and is exploited in the wild. No patch yet. Mitigate now. Related Posts: CVE-2026-86218 (CVSS 10): N-central Pre-Auth RCE Exploited in the Wild MikroTrick PoC: RouterOS Admin Rights Exploited In Wild AI Agent Coordination: The Unprecedented OpenAI Breakout The post StyleSmuggler: Magento Zero-Day RCE Exploited in the Wild appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • NightmareEclipse Releases PoCs for Avast, Kaspersky, and NVIDIA Flaws Do Son
    Discover the details of three new NightmareEclipse vulnerabilities targeting Avast, Kaspersky, and NVIDIA components, lacking official vendor confirmation. Related Posts: CVE-2026-81934: Redis RCE PoC Exploit Now Public CVE-2026-78319: SAUTER Controller RCE Flaw Disclosed CVE-2026-82329 Exploited: JFrog Artifactory Admin Takeover The post NightmareEclipse Releases PoCs for Avast, Kaspersky, and NVIDIA Flaws appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Anthropic Issues Claude Security Warnings Do Son
    Anthropic is sending security warnings and deleting payment methods as info-stealing malware compromises Claude user sessions. Protect your account now. Related Posts: ToxNetV2 Botnet Integrates AI ToxicPanda 2.0 Banking Trojan Attacks Escalate Globally NPM Typosquatting Malware Targets WSL Developers The post Anthropic Issues Claude Security Warnings appeared first on Daily CyberSecurity.
     

Anthropic Issues Claude Security Warnings

Por:Do Son
31 de Agosto de 2026, 07:23

Anthropic is sending security warnings and deleting payment methods as info-stealing malware compromises Claude user sessions. Protect your account now.

Related Posts:

The post Anthropic Issues Claude Security Warnings appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • NCSC Warns of Physical Disruptions from Cyberattacks on OT Systems Do Son
    The UK NCSC warns of rising cyberattacks on operational technology, urging organizations to secure internet-exposed industrial systems against physical disruptions. Related Posts: Google Tracks Russian Cyber Espionage Clusters OpenAI Disrupts Russian Influence Campaign Promoting Fake Think Tank NIST Asks for Help Putting People First in Cybersecurity The post NCSC Warns of Physical Disruptions from Cyberattacks on OT Systems appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Fire Ant Threat Actor Targets Trusted Infrastructure Do Son
    The Fire Ant threat actor uses trusted infrastructure compromise to breach high-value targets. Discover how this group evades detection in networks. Related Posts: ValleyRAT Backdoor Spread via Signed Chinese Adware UAT-10147 Deploys SPECTRE Cross-Platform Implant Kimsuky Spear Phishing Abuses Remote Control Tools The post Fire Ant Threat Actor Targets Trusted Infrastructure appeared first on Daily CyberSecurity.
     
  • ✇Security Affairs
  • Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft Pierluigi Paganini
    Extortion group FulcrumSec claims they stole 86GB of Manchester Airports Group data after finding API credentials exposed in client-side JavaScript. Manchester Airports Group (MAG) disclosed a data breach on August 27 affecting customers of Manchester, London Stansted, and East Midlands airports. Two days later, BleepingComputer reports the extortion group FulcrumSec claimed responsibility, saying it stole roughly 86GB of data, considerably more detailed than what MAG’s original disclosure s
     

Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft

30 de Agosto de 2026, 14:21

Extortion group FulcrumSec claims they stole 86GB of Manchester Airports Group data after finding API credentials exposed in client-side JavaScript.

Manchester Airports Group (MAG) disclosed a data breach on August 27 affecting customers of Manchester, London Stansted, and East Midlands airports. Two days later, BleepingComputer reports the extortion group FulcrumSec claimed responsibility, saying it stole roughly 86GB of data, considerably more detailed than what MAG’s original disclosure suggested.

MAG’s own statement describes a relatively limited set of exposed data. It says the breach affected car park, lounge, Fast Track bookings, and airport WiFi registrations, exposing email addresses, phone numbers, vehicle registrations, and postcodes.

MAG disclosed that the data breach impacted 8.7 million customers, however, the company says most of those customers had only their email addresses exposed.

FulcrumSec tells a different story. The group shared samples with BleepingComputer that included a 21.5GB export of Manchester customer data, with personal identifiers, historical booking details, and marketing information. BleepingComputer checked one record against a real traveler’s purchase history and found matching Fast Track bookings, arrival times, terminal information, and payment amounts.

The alleged way into the system is particularly concerning. FulcrumSec says it found airport-specific Iterable API credentials inside client-side JavaScript. That code runs in users’ browsers, so anyone inspecting the website with developer tools could potentially see those credentials.

“The group claims it obtained access using airport-specific Iterable API credentials exposed in client-side JavaScript and that the stolen material includes nearly 200,000 records related to upcoming travel during the remainder of 2026.” states the report. These records allegedly contain dates, times and booking information linked to personally identifiable information. FulcrumSec says it intends to publish the stolen data and a technical account of the intrusion. If the claim is accurate, attackers did not need a highly sophisticated technique. They simply found sensitive API credentials exposed in code that the website sent directly to customers’ browsers.”

The most concerning specific claim is nearly 200,000 records tied to upcoming travel through the rest of 2026, complete with dates, times, and booking details linked to identifiable individuals. BleepingComputer couldn’t independently verify that number or the full scope of what was actually taken, and MAG declined to directly address FulcrumSec’s specific claims when asked, instead pointing to its existing statement that affected customers with upcoming bookings had already been contacted. MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, a spokesperson said, without engaging with the 86GB figure or the exposed-credentials claim directly.

FulcrumSec plans to publish the stolen data but may redact upcoming travel records because of the risk of real-world harm. UK postcodes can identify very small groups of addresses, and combined with vehicle registrations, parking dates and booking details, the data could enable highly convincing phishing messages targeting people with upcoming trips.

UK postcodes make this exposure sharper than the equivalent breach might be in the US. Unlike American ZIP codes covering broad delivery areas, a full UK postcode typically identifies a small cluster of neighboring addresses, sometimes a single property, according to the Office for National Statistics. Combined with vehicle registrations, parking dates, and specific booking references, that’s more than enough raw material for a phishing message referencing a real upcoming trip that would be very hard to distinguish from a genuine MAG communication.

Security researchers commenting on the broader incident have flagged a supply-chain angle worth watching. Airport operations increasingly run through third-party platforms for booking, parking, and loyalty services rather than systems the airport itself directly controls, and Iterable, the marketing platform whose API credentials FulcrumSec claims to have abused, is exactly that kind of outsourced dependency. This also isn’t aviation’s first bad year: a September 2025 ransomware attack on Collins Aerospace‘s check-in software had already grounded systems at Heathrow, Brussels, and Berlin, meaning UK and European aviation infrastructure has now taken two significant hits inside twelve months.

MAG says no payment card or banking data was exposed, however, travelers who recently booked parking, lounge access or Fast Track should assume more travel data may be exposed and treat messages citing real booking details with caution.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Manchester Airports Group (MAG))

  • ✇Cybersecurity News
  • TeamPCP Hackers Arrested in Joint Operation Do Son
    Discover the details of the TeamPCP hackers arrested in Australia for executing devastating open-source supply chain attacks using the Mini Shai-Hulud worm. Related Posts: FBI Seizes QScan and QTRouter Platforms Run by China State Hackers SilkParasite APT Hits Central Asian Governments With 7 RATs Operation CameraSwarm: 14,500 Dahua Cameras Compromised Across Ukraine and Russia The post TeamPCP Hackers Arrested in Joint Operation appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • macOS ClickFix Malware Exploits Polygon C2 Do Son
    A new macOS ClickFix malware campaign hides C2 servers on the blockchain. See how this macOS ClickFix malware steals crypto wallets and credentials. Related Posts: SynkLoader Malware Deploys Multi-Language Attack Tools WeedHack Malware Still Hits Minecraft Gamers via Fake Sites Cruciferra Malware Loader Uses ClickFix Lures to Kill EDR The post macOS ClickFix Malware Exploits Polygon C2 appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-71362 Exploited: Adobe Commerce Account Takeover, Details and PoC are Public Do Son
    Attackers exploit CVE-2026-71362, an unauthenticated Adobe Commerce account takeover flaw (CVSS 9.1). Details and PoC are public. Patch now. Related Posts: Critical MongoDB Security Vulnerabilities Require Immediate Patching CVE-2026-73125: Ebyte NA111-M Flaws Let Attackers Fully Compromise the Device D-Link DIR-X1860Z Flaw Lets Attackers Change the Admin Password Without Login The post CVE-2026-71362 Exploited: Adobe Commerce Account Takeover, Details and PoC are Public appeared first on Dai
     
  • ✇Cybersecurity News
  • Mercor Data Breach Targets AI Supply Chain Do Son
    Discover the details of the massive Mercor data breach exposing 4TB of recruiting data for OpenAI, Google, Meta, and Microsoft. Related Posts: Meta Settles Child Privacy Lawsuit Rapidly Exposed Git Repositories Leak Critical Cloud Secrets Take-Two Subpoenas Microsoft and Discord Over GTA VI "Cyberleek" Leaks The post Mercor Data Breach Targets AI Supply Chain appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-72137 (CVSS 9.8): Linux Kernel Flaw Enables Root Privilege Escalation, PoC Public Do Son
    A public PoC exploit targets CVE-2026-72137, a CVSS 9.8 Linux kernel double-free that enables root privilege escalation. Patch now. Related Posts: CVE-2026-19042: TeamViewer Command Injection Enables Remote Code Execution CISA Adds Six Exploited Vulnerabilities Including Citrix NetScaler Flaw Dell Cloud Disaster Recovery CVE-2026-70419 (CVSS 9.1) Allows Command Execution The post CVE-2026-72137 (CVSS 9.8): Linux Kernel Flaw Enables Root Privilege Escalation, PoC Public appeared first on Daily
     
  • ✇Technical Information Security Content & Discussion
  • /r/netsec's Q3 2026 Information Security Hiring Thread /u/netsec_burn
    Overview If you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company. We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education. Please reserve top level comments for those posting open positions. Rules & Guidelines Include the company name in the post
     

/r/netsec's Q3 2026 Information Security Hiring Thread

Overview

If you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.

We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.

Please reserve top level comments for those posting open positions.

Rules & Guidelines

Include the company name in the post. If you want to be topsykret, go recruit elsewhere. Include the geographic location of the position along with the availability of relocation assistance or remote work.

  • If you are a third party recruiter, you must disclose this in your posting.
  • Please be thorough and upfront with the position details.
  • Use of non-hr'd (realistic) requirements is encouraged.
  • While it's fine to link to the position on your companies website, provide the important details in the comment.
  • Mention if applicants should apply officially through HR, or directly through you.
  • Please clearly list citizenship, visa, and security clearance requirements.

You can see an example of acceptable posts by perusing past hiring threads.

Feedback

Feedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)

submitted by /u/netsec_burn
[link] [comments]
  • ✇Technical Information Security Content & Discussion
  • r/netsec monthly discussion & tool thread /u/albinowax
    Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links. Rules & Guidelines Always maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary. Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely. If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely. Avoid use o
     

r/netsec monthly discussion & tool thread

Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.

Rules & Guidelines

  • Always maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.
  • Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.
  • If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.
  • Avoid use of memes. If you have something to say, say it with real words.
  • All discussions and questions should directly relate to netsec.
  • No tech support is to be requested or provided on r/netsec.

As always, the content & discussion guidelines should also be observed on r/netsec.

Feedback

Feedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.

submitted by /u/albinowax
[link] [comments]

Minimus is shutting down after raising $51M, Twistlock founders returning cash to investors

Twistlock founders Ben Bernstein, Dima Stopel and John Morello are shutting down their newest startup Minimus. They raised 51 million in seed funding from YL Ventures and Mayfield and had around 60 employees a few months ago. The pitch was stripped down container images that cut out most CVEs before they ever shipped but commercial traction never caught up to the technical story. Customers get a 60 day window before the registry goes fully offline on October 22 and remaining cash is going back to investors. Founder pedigree and funding clearly do not guarantee product market fit. Anyone else surprised this one did not make it?

submitted by /u/DakPrescottQBDraw
[link] [comments]
❌
❌