Press "Enter" to skip to content

OSINT / CyberSec report 01.09.2026 00:06

1. FulcrumSec claimed responsibility for a data breach at Manchester Airports Group involving the theft of 86 GB of sensitive customer and travel information (https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/).

2. Five critical vulnerabilities in WordPress plugins and themes including WPMU DEV Dashboard and Avada allow for site takeover or remote code execution (https://thehackernews.com/2026/08/five-critical-wordpress-plugin-and.html).

3. Anthropic warned that infostealer malware is actively hijacking active Claude sessions to gain unauthorized account access and consume usage (https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/).

4. Microsoft disclosed a new ClickFix variant called TerminalFix that tricks users into executing malicious commands via Windows Terminal or PowerShell (https://thehackernews.com/2026/08/terminalfix-uses-fake-cloudflare.html).

5. Multiple malicious extensions on the Chrome Web Store were identified deploying a framework to steal cryptocurrency, browser history, and sensitive user data (https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/).

6. The U.S. Department of Justice clarified that several U.S. agencies were targeted but not necessarily victims of recent hacking attempts attributed to Chinese actors (https://thehackernews.com/2026/08/doj-corrects-china-hacking-claim-says.html).

7. Two Nigerian men were extradited to the United States to face charges related to sextortion schemes linked to the deaths of two minors (https://www.bleepingcomputer.com/news/security/nigerians-charged-US-over-sextortion-deaths-of-us-teens/).

8. Berlin authorities officially refused to pay a ransom demand following a cyberattack that resulted in the theft of data from the city state network (https://www.reddit.com/r/cybersecurity/comments/1w1x7yt/berlin_refuses_to_pay_hackers_who_stole_data_from/).

9. Security researchers discovered three backdoor surveillance implants hidden within the firmware of Chinese-manufactured routers sold globally (https://www.reddit.com/r/cybersecurity/comments/1w1qs4p/security_researchers_find_surveillance_implants/).

10. Microsoft advised users to ignore erroneous security alerts stating that Defender Antivirus is turned off following the installation of recent updates (https://www.bleepingcomputer.com/news/microsoft/microsoft-asks-users-to-ignore-antivirus-is-turned-off-errors/).

11. A privilege escalation technique was identified allowing movement from IIS AppPool to NT Authority SYSTEM via the AD CS RPC endpoint (https://www.reddit.com/r/netsec/comments/1w36tcq/privilege_escalation_from_iis_apppool_to_nt/).

12. Two zero-day vulnerabilities were discovered in Shopify plugins (https://www.reddit.com/r/cybersecurity/comments/1w1oyy2/i_found_two_shopify_plugin_zerodays_in_a_bathtub/).

Be First to Comment

    Leave a Reply

    Your email address will not be published. Required fields are marked *