Security news.
Today's security brief highlights a range of active threats, including data breaches at major entities like Manchester Airports and McKesson, and ongoing malware campaigns targeting browser extensions and AI platforms. Several critical vulnerabilities in popular software, including WordPress plugins and PaperCut, also require immediate attention from developers and IT teams.
FulcrumSec Claims Manchester Airports Hack, 86 GB Data Theft
FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group, with samples revealing detailed customer, booking, and travel information beyond initial disclosures.
Anthropic Warns of Infostealer Malware Hijacking Claude Sessions
Anthropic is cautioning Claude users about infostealer malware on their PCs stealing active Claude login sessions, enabling attackers to access accounts and consume AI usage.
Chrome Web Store Extensions Caught Stealing Crypto, Browser Data
Multiple extensions for Google Chrome and Microsoft Edge were found distributing a malware framework that deployed modules to steal cryptocurrency, sensitive data, browser history, and inject ClickFix lures.
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Microsoft revealed details of TerminalFix, a new ClickFix variant using fake Cloudflare CAPTCHAs to trick users into running malicious commands in Windows Terminal or PowerShell, establishing a reverse tunnel.
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Multiple critical security flaws, including CVE-2026-76581 with a CVSS score of 9.8, were disclosed in WordPress plugins and themes like WPMU DEV Dashboard, Avada, and GiveWP, potentially leading to authentication bypass, account takeover, and arbitrary code execution.
McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft
Healthcare and pharmaceutical distributor McKesson disclosed a cyber incident after the ShinyHunters extortion group claimed to have stolen 284 million patient data records.
PaperCut Releases Second Emergency Patch for Exploited Flaws
PaperCut issued a second emergency security update for two actively exploited vulnerabilities in its NG and MF print management software, addressing new bypasses discovered after the initial fixes.
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA added CVE-2023-49105 (ownCloud Improper Authentication), CVE-2026-53362 (Linux Kernel Unspecified Vulnerability), and CVE-2026-66384 (JFrog Artifactory Improper Limitation of a Pathname) to its KEV Catalog due to active exploitation.