← Latest brief

Security news.

·Afternoon Brief

Today's security brief highlights a range of active threats, including data breaches at major entities like Manchester Airports and McKesson, and ongoing malware campaigns targeting browser extensions and AI platforms. Several critical vulnerabilities in popular software, including WordPress plugins and PaperCut, also require immediate attention from developers and IT teams.

BLEEPINGBREACH
Aug 30READ

FulcrumSec Claims Manchester Airports Hack, 86 GB Data Theft

FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group, with samples revealing detailed customer, booking, and travel information beyond initial disclosures.

BLEEPINGBREACH
Aug 30READ

Anthropic Warns of Infostealer Malware Hijacking Claude Sessions

Anthropic is cautioning Claude users about infostealer malware on their PCs stealing active Claude login sessions, enabling attackers to access accounts and consume AI usage.

BLEEPINGBREACH
Aug 30READ

Chrome Web Store Extensions Caught Stealing Crypto, Browser Data

Multiple extensions for Google Chrome and Microsoft Edge were found distributing a malware framework that deployed modules to steal cryptocurrency, sensitive data, browser history, and inject ClickFix lures.

THNMALWARE
Aug 30READ

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

Microsoft revealed details of TerminalFix, a new ClickFix variant using fake Cloudflare CAPTCHAs to trick users into running malicious commands in Windows Terminal or PowerShell, establishing a reverse tunnel.

THNRCE
Aug 29READ

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Multiple critical security flaws, including CVE-2026-76581 with a CVSS score of 9.8, were disclosed in WordPress plugins and themes like WPMU DEV Dashboard, Avada, and GiveWP, potentially leading to authentication bypass, account takeover, and arbitrary code execution.

BLEEPINGBREACH
Aug 28READ

McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft

Healthcare and pharmaceutical distributor McKesson disclosed a cyber incident after the ShinyHunters extortion group claimed to have stolen 284 million patient data records.

BLEEPINGEXPLOIT
Aug 28READ

PaperCut Releases Second Emergency Patch for Exploited Flaws

PaperCut issued a second emergency security update for two actively exploited vulnerabilities in its NG and MF print management software, addressing new bypasses discovered after the initial fixes.

CISAKEV
Aug 27READ

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA added CVE-2023-49105 (ownCloud Improper Authentication), CVE-2026-53362 (Linux Kernel Unspecified Vulnerability), and CVE-2026-66384 (JFrog Artifactory Improper Limitation of a Pathname) to its KEV Catalog due to active exploitation.

Generated twice daily from public security RSS feeds. Informational only.