A cyberattack on Manchester Airports Group exposed data of 8.7 million customers across Manchester, Stansted, and East Midlands airports. Manchester…
PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print…
Unitree G1 Humanoid Robot Flaws Allow Unauthenticated Root RCE Over Bluetooth
Security researcher Boschko has revealed two vulnerabilities in Unitree’s G1 humanoid robot that can be exploited to achieve unauthenticated remote code…
APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between…
IT Security News Hourly Summary 2026-08-28 11h : 9 posts
9 posts published in the last hour 08:31Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations 08:31Prompt Injection Attack Hijacks Claude Code Opus 5 Auto Mode to Execute Malicious Code 08:3178 arrests in bust of major Western Mediterranean smuggling…
Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations
Aurora ransomware operators are abusing SpaceX’s Cursor Agent AI tool to conduct tasks such as reconnaissance and exploitation activities
Prompt Injection Attack Hijacks Claude Code Opus 5 Auto Mode to Execute Malicious Code
A recent demonstration of prompt-injection research has revealed that Claude Code Opus 5, when running in its default Auto Mode, can be manipulated to…
78 arrests in bust of major Western Mediterranean smuggling network in Spain
The operation, conducted under a newly established Europol Taskforce within Europol’s European Centre Against Migrant Smuggling, brought together officers…
TITAN RaaS Uses AI for Data Classification, Regulatory Analysis and Automated Ransom Calculation
A newly emerged ransomware-as-a-service operation named TITAN is advertising an AI-driven extortion platform that it claims can autonomously classify…
PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers
Guardicore Labs uncovers a Ransomware detection campaign targeting MySQL servers. Attackers use Double Extortion and publish data to pressure victims.
Hundreds of WordPress Sites Hijacked to Show Fake reCAPTCHA and Steal Windows Passwords.
Hundreds of compromised WordPress websites are being used in a sophisticated malware-delivery campaign that combines browser persistence,…
Manchester Airports Group breached, millions of customers’ data stolen
Someone broke into the systems of Manchester Airports Group (MAG) and walked away with a “quantity” of customer data from three UK airports, the company…
Hackers Can Buy Corporate Executives’ Social Security Numbers for Just 25 Cents
Corporate executives’ Social Security numbers (SSNs) are being sold on dark web identity marketplaces for as little as $0.25 per record. This creates a…
IT Security News Hourly Summary 2026-08-28 10h : 9 posts
9 posts published in the last hour 07:31Threats Making WAVs – Incident Response to a Cryptomining Attack 07:31CISA Warns of Linux Kernel Privilege Escalation Vulnerability Exploited in Attacks 07:31Brazil Plans Supercomputers Built With US, Chinese Tech 07:31Go Loader Uses Anti-Sandbox…
Threats Making WAVs – Incident Response to a Cryptomining Attack
Guardicore security researchers describe and uncover a full analysis of a cryptomining attack, which hid a cryptominer inside WAV files. The report…
CISA Warns of Linux Kernel Privilege Escalation Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added a Linux kernel vulnerability, tracked as CVE-2026-53362, to its Known Exploited…
Brazil Plans Supercomputers Built With US, Chinese Tech
South America’s largest economy announces two AI supercomputers using tech from Huawei and Nvidia, in move to boost tech sovereignty
Go Loader Uses Anti-Sandbox Checks and SNOWLIGHT to Execute Fileless VShell RAT in Memory
A Windows malware campaign disguised as a graduate-school resume has been observed delivering the SNOWLIGHT stager and a fileless VShell remote-access…
Some Malicious PE Stats, (Thu, Aug 27th)
During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? A couple of…
Manchester Airports breach, ATF agency breach, clothier Carhartt breach
Manchester Airports Group suffers cyber incident ATF suffers data breach Clothing retailer Carhartt suffers data breach Get the show notes here:…
Claude Code Opus 5 Auto Mode Hijacked via Prompt Injection to Execute Malicious Code
Claude Code Opus 5 in Auto Mode can be tricked into running malicious code via a simple website summary request. In a limited lab test, the attack…
AI IR Overlay – Incident Response Specification for AI Agents
AI IR Overlay specifies containment for agents using valid credentials, with a working kill-switch contract and an admitted gap when no SOC is staffed.
IT Security News Hourly Summary 2026-08-28 09h : 5 posts
5 posts published in the last hour 06:31Leaked University Files Reveal How Russia Trains Hackers for Military Cyber Operations 06:02The Nansh0u Campaign – Hackers Arsenal Grows Stronger 06:01What 90 days and a small budget can buy in AI agent security…
Leaked University Files Reveal How Russia Trains Hackers for Military Cyber Operations
A cache of leaked internal records has exposed what appears to be a structured Russian military cyber-operator pipeline embedded inside Bauman Moscow…