
thecybersecguru

Malicious `SKILL.md` Files Are Becoming an AI Agent Supply-Chain Problem
A reported Claude-related malware incident highlights a nasty attack chain:
A user followed an AI-provided download link and was reportedly infected. After wiping the machine, they discovered a malicious `SKILL.md` that could potentially reintroduce the payload and target credentials when restored and loaded by an AI coding agent.
The interesting part isn't simply "AI gave someone a bad link."
It's the persistence and trust boundary.
AI coding agents can read instruction files, access project files, execute commands and interact with external services. A poisoned skill can therefore turn trusted agent capabilities into an attack primitive.
Recent research has demonstrated malicious Skills capable of credential theft, data exfiltration, malware delivery and even execution through dynamic context before the model sees the rendered skill content.
This raises an important question for defenders:
Should `SKILL.md`, `CLAUDE.md`, `AGENTS.md`, hooks and similar AI instruction files now be treated as software supply-chain artifacts rather than documentation?
My technical breakdown covers the reported attack, poisoned Skills, reinfection through restored configuration, credential theft risks and practical detection/response steps:
https://thecybersecguru.com/news/laude-malware-attack-malicious-download-skill-md/
#InfoSec #CyberSecurity #AI #ClaudeCode #AIAgents #Malware #PromptInjection #SupplyChainSecurity
🚨 Click2Shell: Critical WordPress RCE chain
A malicious link can trigger an authenticated WordPress admin’s browser to silently install a theme, load its functions.php, abuse an insecure AJAX handler, and reach remote code execution.
The Core flaw is patched in WordPress 7.1.1, but vulnerable third-party themes can still complete the chain.
Full technical breakdown + PoC analysis:
https://thecybersecguru.com/news/click2shell-wordpress-vulnerability-rce/

🚨 Cisco ISE CVE-2026-76460 is being actively exploited.
A CVSS 10.0 authentication bypass lets unauthenticated remote attackers send a crafted API request and gain unauthorized access to Cisco ISE/ISE-PIC.
Cisco warns successful exploitation can lead to root-level command execution, while attackers may be able to erase evidence of compromise.
🔎 Hunt ISE Kong access logs for suspicious usernames.
⚠️ No workaround is available.
🛠️ Patch releases are available.
Technical breakdown, IOCs, affected versions & remediation:
https://thecybersecguru.com/news/cisco-ise-cve-2026-76460-authentication-bypass/
🚨 PaperCut NG/MF is being actively exploited in a pre-auth RCE chain.
Two vulnerabilities are chained:
🔴 CVE-2026-81578 — Tapestry authentication bypass
🔴 CVE-2026-82078 — unsafe Java class loading
The result: unauthenticated configuration manipulation → Java bytecode execution → SYSTEM-level RCE.
Attackers have been observed dropping `Udydn.class`, abusing `jdbc:derby:memory:pwn`, executing discovery commands, and deleting logs to cover their tracks.
Worse: the first emergency patch was bypassed. Release 2 is required.
Technical breakdown + IOCs + Sigma/YARA + triage guidance:
https://thecybersecguru.com/news/papercut-cve-2026-81578-cve-2026-82078-pre-auth-rce-analysis/
#InfoSec #CVE #ThreatIntel #DFIR #IOC #BlueTeam #PaperCut #RCE
🚨 Reported 12TB Valve Data Leak: Old Steam2 Infrastructure Exposed?
A massive ~12TB archive allegedly linked to Valve’s legacy Steam2 content infrastructure has surfaced, reportedly containing historical data dating back to 2003–2013.
Researchers are reportedly finding:
• Portal 2 beta/development builds
• A claimed 2009-era Portal 2 build
• F-Stop development assets
• Legacy Valve game content
• Potentially unreleased or abandoned development material
From an infosec perspective, the interesting part isn't just the game content. It raises questions around legacy infrastructure, abandoned repositories, historical content servers, data retention, and the long-term exposure of forgotten assets.
There are also claims about **Half-Life 3 / Episode Three**, but those remain unverified.
Important: there is currently **no confirmed evidence that this represents a recent compromise of Valve's production infrastructure**. The provenance and authenticity of the complete archive still need to be established.
🔎 Technical breakdown and what is actually known:
https://thecybersecguru.com/news/valve-12tb-leak-portal-2-beta-f-stop-steam2/
#InfoSec #CyberSecurity #DataLeak #DataBreach #Valve #Steam #Steam2 #GameSecurity #DigitalForensics #ThreatIntelligence #OSINT #DataExposure #LegacySystems #IncidentResponse
🚨 Mini Shai-Hulud is back in npm.
`@7nohe/openapi-react-query-codegen` was compromised with 10 malicious releases on Aug. 28.
The interesting part: this wasn't a stolen npm password.
An attacker abused a GitHub Actions `issue_comment` workflow that could be triggered with `npm publish`, checked out attacker-controlled fork code, and used the workflow's OIDC identity to publish under the legitimate package.
Even worse, the malicious releases carried valid npm provenance.
The payload can execute during installation and target:
• GitHub / CI credentials
• npm, PyPI & RubyGems tokens
• AWS / Azure / GCP credentials
• developer & AI coding-tool configs
• GitHub Actions workflows
• package publishing access
• SSH infrastructure
Affected versions include:
`0.5.4` `0.5.5`
`1.6.3` `1.6.4`
`2.2.1` `2.2.2`
`3.0.3` `3.0.4`
Also two malicious `0.0.0-` prereleases.
Known-good versions:
`0.5.3` · `1.6.2` · `2.2.0` · `3.0.2`
The bigger lesson: provenance can prove that an artifact came through a trusted workflow. It cannot prove that the source fed into that workflow was trustworthy.
I've documented the complete attack chain, execution triggers, credential harvesting, persistence, propagation mechanisms, hashes, filenames and IoCs:
https://thecybersecguru.com/news/openapi-react-query-codegen-npm-compromise-mini-shai-hulud/
#InfoSec #CyberSecurity #npm #SupplyChainSecurity #DevSecOps #GitHubActions #Malware #ThreatIntelligence #AppSec
🚨 BREAKING: TeamPCP hackers charged in Australia
Two alleged TeamPCP members face 14 charges over a major **software supply chain attack linked to Trivy, Checkmarx KICS and LiteLLM.
The campaign potentially exposed 1,000+ organizations, 500,000+ credentials and 300GB+ of data.
The attack chain is wild: Trivy → stolen CI/CD credentials → KICS → LiteLLM → cloud, Kubernetes & AI secrets.
Full technical breakdown: https://thecybersecguru.com/news/teampcp-hackers-charged-australia-trivy-litellm-supply-chain-attacks/
#InfoSec #CyberSecurity #TeamPCP #SupplyChain #Trivy #LiteLLM #CI_CD #DevSecOps
🚨 Critical GitLab GraphQL vulnerability: CVE-2026-19478
GitLab has released an out-of-band security patch for a CVSS 9.4 critical vulnerability affecting self-managed CE/EE installations.
Under certain conditions, an unauthenticated remote attacker could use a malicious GraphQL directive to modify or delete public projects and user data.
Affected branches include:
• 18.2 → before 18.11.11
• 19.0 → before 19.0.8
• 19.1 → before 19.1.6
• 19.2 → before 19.2.4
GitLab also fixed CVE-2026-19650 (CVSS 7.1), a GraphQL multiplex-query CSRF issue that could allow unauthenticated mutation execution via GET requests under certain conditions.
🔧 Patch releases: 19.2.4 | 19.1.6 | 19.0.8 | 18.11.11
No public PoC or confirmed exploitation is currently disclosed but given the unauthenticated network attack surface and CVSS 9.4 rating, self-managed GitLab administrators should patch immediately.
Full technical breakdown:
https://thecybersecguru.com/news/cve-2026-19478-gitlab-graphql-vulnerability/
#GitLab #CVE202619478 #CVE202619650 #GraphQL #CyberSecurity #InfoSec #Vulnerability #AppSec #DevSecOps #GitLabSecurity
GitHub experiencing widespread outage, API errors reach ~20%
GitHub is currently experiencing a widespread service disruption affecting multiple core services.
GitHub reports approximately 20% error rates across web experiences and API traffic, while archive downloads and raw repository content are seeing around 50% errors**.
Affected services include:
* GitHub API
* GitHub Actions
* Pull Requests
* Issues
* Webhooks
* GitHub Copilot
* SAML/OIDC authentication
* SCIM and Team Sync
* Repository downloads and much more
The incident began at approximately 13:40 UTC on August 17, 2026, and GitHub says it is continuing to investigate while applying mitigations.
There is currently no indication that this is a cyberattack. The root cause has not yet been publicly confirmed.
Full incident coverage and timeline:
https://thecybersecguru.com/news/github-outage-api-errors-20-percent/
#GitHub #GitHubOutage #GitHubDown #GitHubAPI #GitHubActions #GitHubCopilot #DevOps #CyberSecurity #Infosec #OpenSource
🔥 VMware vCenter → ESXi → Ransomware
A suspected China-nexus actor reportedly weaponized CVE-2026-59310 just 5 days after disclosure.
The campaign hit an estimated 361 IPs across 47 countries and ultimately deployed Babuk-derived ransomware against ESXi hosts.
The interesting part is the attack chain:
vCenter compromise → root access → persistence → credential theft → ESXi lateral movement → VMFS encryption
I broke down the full chain, including the attacker’s persistence and ESXi ransomware deployment:
👉 https://thecybersecguru.com/news/vmware-vcenter-cve-2026-59310-babuk-esxi-ransomware/
#infosec #cybersecurity #VMware #vCenter #ESXi #ransomware #CVE202659310
Mistral AI source code allegedly offered for sale on a cybercrime forum.
A threat actor using the handle “mrwho” claims to have compromised Mistral AI and obtained source code, internal development projects and web application code.
The samples reportedly include a 339-file project listing and “webstral” code.
The claims remain unverified, and no customer data exposure has been established.
Technical breakdown: https://thecybersecguru.com/news/mistral-ai-source-code-leak-2026/
Apple’s privacy model deserves a closer look.
A review of Apple’s privacy disclosures raises questions around:
• First-party behavioral profiling and targeted advertising
• The data signals used for Device Trust Scores
• Long-term retention of transaction and download data
• iCloud sharing metadata exposure
• The practical limits of account deletion
• Differences between Apple’s privacy messaging and its underlying data-processing practices
Apple has made significant investments in security and encryption, but security from external attackers and privacy from the service provider are not the same thing.
We broke down the policies and the technical privacy implications:
https://thecybersecguru.com/analysis/apple-privacy-paradox-policy-analysis/
RE: https://thecybersecguru.com/news/recommended-url-slug-nextjs-rce-avif-libheif-cve-2026-75604/
🚨 CRITICAL Next.js RCE Alert!
A malicious AVIF/HEIC image can trigger unauthenticated Remote Code Execution through the Next.js Image Optimization API.
The chain runs through:
Next.js → sharp → libvips → libheif
🔴 GHSA-2xp9-vwfh-vxw4
🔴 GHSA-g89c-p67h-r497
🔴 CVE-2026-75604
🔴 libheif heap buffer overflow
🔴 Windows-hosted Next.js RCE
The deep dive breaks down the `iden`/`auxl` ISOBMFF attack chain, duplicate Alpha planes, `scale_nearest_neighbor()`, the heap overflow and remediation.
🔗 https://thecybersecguru.com/news/nextjs-rce-avif-libheif-cve-2026-75604/
#InfoSec #CyberSecurity #NextJS #RCE #AppSec #AVIF #libheif #CVE #Vulnerability #WebSecurity
Linux kernel security had a rough week.
4 kernel flaws now have public root exploits, while CISA added 3 more Linux kernel vulnerabilities to its KEV catalog due to active exploitation.
The four publicly exploited flaws:
• DirtyAH6
• TUNderflow
• PPPoEject
• DiagSpill
The interesting part: the four bugs were discovered using an AI-assisted vulnerability hunting approach.
Technical breakdown, affected versions, exploitation requirements, and mitigations:
https://thecybersecguru.com/news/linux-kernel-vulnerabilities-2026-public-exploits-cisa-kev/
🚨 Critical Tutor LMS vulnerability: CVE-2026-78175
A critical vulnerability in Tutor LMS can chain broken access control → PHP object injection → arbitrary file write → remote code execution.
Affected: Tutor LMS ≤ 4.0.7
Severity: CVSS 8.8
Potential impact: 100,000+ WordPress sites
Fixed: Tutor LMS 4.0.8
The issue is particularly concerning because a low-privileged subscriber account can reach the vulnerable withdrawal-account functionality.
Administrators should update to 4.0.8 or later and review logs, user accounts, and /wp-content/uploads/ for suspicious PHP files.
Technical breakdown:
https://thecybersecguru.com/news/cve-2026-78175-tutor-lms-rce/
#infosec #cybersecurity #WordPress #TutorLMS #CVE #RCE #AppSec
🚨 CVE-2026-80521: Linux kernel container escape
A public exploit chains an AF_UNIX socket garbage-collector use-after-free into host-level code execution from an unprivileged container.
The bug involves a race in the SCC garbage collector that leaves a freed unix_vertex reachable through a stale scc_entry pointer.
The PoC reportedly works against Ubuntu 26.04 and defeats several kernel hardening mechanisms.
Ubuntu 22.04, 24.04 and 26.04 are currently listed as affected in the article's September 23 update.
Technical breakdown + exploit chain: https://thecybersecguru.com/news/cve-2026-80521-ubuntu-kernel-container-escape/
#Linux #Cybersecurity #ContainerSecurity #Docker #Kubernetes #CVE

🚨 Swiss Bitcoin Pay has CONFIRMED a security breach.
A malicious user gained access to its internal systems, with customer emails, Bitcoin addresses, IBANs, transaction history and hashed passwords potentially exposed.
Swiss Bitcoin Pay has shut down its servers while investigating. It says user funds are safe and owed funds will be returned.
But the bigger security question is the “non-custodial” claim. The company says incoming Lightning payments are temporarily batched into on-chain UTXOs, creating a period where funds are held on its infrastructure.
I break down the breach, exposed data, Lightning architecture, custody implications and what affected users should do:
🔗 https://thecybersecguru.com/news/swiss-bitcoin-pay-breach/
#infosec #cybersecurity #databreach #bitcoin #cryptosecurity

🚨 Chat Control 2.0 hits another major EU trilogue on September 29.
The debate is centered on some serious infosec questions:
🔐 End-to-end encryption
📱 Private message scanning
⚖️ Detection orders
🪪 Mandatory age verification
🇪🇺 Chat Control 1.0 vs 2.0
The Council, Parliament and Commission still have fundamentally different positions.
Here’s the technical breakdown of what’s actually being negotiated 👇
https://thecybersecguru.com/news/chat-control-2-0-september-29-trilogue/
🚨 GTA VI LEAK: Cyberleek vs. Rockstar
A group calling itself Cyberleek has published alleged GTA VI gameplay footage and an extensive **Leonida map**, reportedly revealing details including:
• Possible 6-star wanted system
• New stamina/combat mechanics
• Vehicle storage & fuel systems
• Previously unseen locations across the map
But the more interesting (or not so much) part is the response.
Rockstar/Take-Two are reportedly issuing DMCA takedowns at near-real-time speed, with gameplay videos and screenshots disappearing shortly after being reposted.
Cyberleek is now threatening to release more GTA VI material and claims the leak is part of a broader campaign against digital game ownership.
We break down the leak, the alleged map, the takedown campaign and Cyberleek's manifesto:
https://thecybersecguru.com/news/cyberleek-gta-6-leak-gameplay-map-dmca/
#GTA6 #GTAVI #Cyberleek #RockstarGames #DataLeak #GamingSecurity #CyberSecurity #InfoSec
🚨 CRITICAL: CVE-2026-72898 is an actively exploited Metabase SQL injection.
A CVSS 10.0, unauthenticated Metabase vulnerability can let remote attackers exploit the password-reset flow, gain administrator access, and potentially expose credentials and data from connected databases.
No credentials. No user interaction.
I broke down the CVE-2026-72898 exploit chain, affected Metabase versions, attack impact, detection indicators, and mitigation steps:
🔗 https://thecybersecguru.com/exploits/cve-2026-72898-metabase-sql-injection/
If you run self-hosted Metabase, this is one to patch immediately.
#CVE202672898 #Metabase #SQLInjection #InfoSec #CyberSecurity #ZeroDay #VulnerabilityManagement #AppSec #ThreatIntel
🚨 Ledger data breach claim
A cybercrime forum seller is allegedly offering 471,000 Ledger customer records for $20,000.
The claimed dataset includes:
• Email addresses
• Names
• Physical addresses
• Phone numbers
⚠️ The data has not been independently verified and may potentially include recycled data from the 2020 Ledger breach.
We break down the listing, what may actually be at risk, and what Ledger users should know:
https://thecybersecguru.com/news/ledger-data-breach-2026-471000-customer-records/
🚨 T-MOBILE HACKED?**
An alleged 2026 T-Mobile customer database has surfaced on an underground forum.
But the sample raises serious red flags: it reportedly contains **Verizon Wireless records** and fields that look more like a broad consumer-data compilation than a genuine T-Mobile subscriber database.
No confirmed record count.
No proof of intrusion.
No independent confirmation.
No T-Mobile disclosure matching the claim.
So what is it: a fresh breach, recycled data, broker-sourced information, or simply a scam?
We break down the listing, sample schema, seller profile, and the evidence behind the claim 👇
🔗 https://thecybersecguru.com/news/t-mobile-hacked-2026-customer-database-dark-web/
#infosec #cybersecurity #TMobile #DataBreach #DarkWeb #ThreatIntel
🚨 New X Account Takeover Exploit Reportedly Active: Live Footage Surfaces
Multiple reports are now circulating that threat actors are using a new technique to take over X accounts, with video footage appearing to show an account being compromised in real time.
⚠️ Important: The exploit is NOT independently confirmed yet. The underlying attack vector, affected X component, and whether this is an actual X-side vulnerability remain unknown.
The footage + rapidly emerging reports should be noted closely.
I’ve documented the evidence, what the video appears to show, what we do and don't know, and the technical possibilities behind the reported attack:
🔗 https://thecybersecguru.com/news/x-account-takeover-exploit-threat-actors-live-footage/
#CyberSecurity #InfoSec #X #AccountTakeover #ThreatIntel #Hacking #CyberAttack #Security
🚨 Critical WordPress vulnerabilities!
CVE-2026-15748 affects Forminator Forms and can allow unauthenticated arbitrary file uploads leading to RCE on vulnerable configurations. Versions ≤ 1.56.1 are affected; 1.56.2 is patched.
CVE-2026-15826 affects User Profile Builder and enables unauthenticated authentication bypass via type confusion, potentially resulting in administrator takeover. Versions ≤ 3.16.4 are affected.
Both carry CVSS 9.8 Critical.
I've broken down the exploit chains, IoCs, detection queries, WAF rules, and hardening recommendations here:
https://thecybersecguru.com/news/cve-2026-15748-forminator-rce-cve-2026-15826-user-profile-builder/
#WordPress #CVE #InfoSec #CyberSecurity #RCE #DFIR #BlueTeam
🚨 3 ServiceNow vulnerabilities just received CVSS 10.0 ratings.
The scary part: all three are rated unauthenticated, network-reachable and low-complexity.
• CVE-2026-18885 → Code injection / arbitrary code execution
• CVE-2026-18886 → Improper access control / privilege escalation
• CVE-2026-74820 → SQL injection / arbitrary SQL execution
No privileges. No user interaction.
A fourth flaw, CVE-2026-6876 (CVSS 8.7), is a sandbox escape enabling arbitrary code execution.
ServiceNow has released fixes. Here's the technical breakdown, affected versions and patch details:
https://thecybersecguru.com/news/servicenow-cve-2026-18885-18886-74820-cvss-10/
#InfoSec #ServiceNow #CVE #CVE2026 #CyberSecurity #RCE #SQLInjection
Cisco FMC CVE-2026-20324 is a critical sftunnel vulnerability with a CVSS score of 9.9.
The flaw involves missing authorization (CWE-862) and can allow an attacker controlling or hijacking a registered sftunnel peer to write arbitrary files and execute commands as root on Secure Firewall Management Center.
The important part: this isn't a typical unauthenticated internet-facing RCE. Exploitation requires valid peer context, but compromise of FMC could have significant downstream impact because it centrally manages Cisco Secure Firewall Threat Defense devices.
Cisco reports no known exploitation and no workaround. Fixed releases should be applied as soon as possible.
Technical breakdown + detection and remediation guidance:
https://thecybersecguru.com/news/cishttps://thecybersecguru.com/news/cisco-fmc-cve-2026-20324-sftunnel-root-rce/co-fmc-cve-2026-20324-sftunnel-root-rce/
A legacy CDN domain has been re-registered and now has wildcard DNS covering `*.wpengine.netdna-ssl.com`.
`netdna-ssl.com` was part of the old MaxCDN/WP Engine infrastructure, and thousands of legacy references still exist.
The current TLS configuration prevents the deeper hostnames from serving content, but a valid wildcard certificate could turn this into a serious supply-chain risk.
Full analysis:
https://thecybersecguru.com/news/netdna-ssl-com-takeover-supply-chain-risk/
🚨 Your Wi-Fi router could potentially identify you without your phone.
Researchers at Karlsruhe Institute of Technology demonstrated BFId, an identity-inference attack using **Wi-Fi Beamforming Feedback Information (BFI).
No camera. No smartphone. No wearable. You don't even need to connect to the network.
The study tested 197 people and reported 99.5% identification accuracy, including across different perspectives and walking styles.
Even with Wi-Fi disabled on your own phone, nearby Wi-Fi devices can still generate signals that interact with your body.
This doesn't mean every router can instantly identify strangers, but it exposes a serious Wi-Fi sensing privacy threat: wireless infrastructure could potentially become an invisible surveillance layer.
🔗 https://thecybersecguru.com/news/bfid-wifi-identity-inference/
🚨 Gyazo breach: 23.62M accounts affected, with metadata tied to 490M+ images reportedly exposed.
The exposed data reportedly includes:
• Email addresses & usernames
• Password hashes
• Session IDs
• Device IDs
• X integration tokens
• OCR text
• IP addresses & EXIF data
• Gyazo image IDs
The OCR + image-ID exposure is particularly concerning for screenshots containing credentials, API keys, internal infrastructure details, or sensitive corporate information.
Full technical breakdown:
https://thecybersecguru.com/news/gyazo-breach-23-million-users-490-million-images/
#InfoSec #CyberSecurity #DataBreach #Gyazo #ThreatIntel #Privacy
🚨 Iran-linked hackers reportedly forced a UK power generator offline for four days in a significant critical infrastructure cyberattack.
The wider UK power grid was not affected, but the incident raises serious questions around OT/ICS security, remote access, and the growing targeting of energy infrastructure by state-linked threat actors.
The technical intrusion path has not yet been publicly disclosed.
Full breakdown:
https://thecybersecguru.com/news/iran-linked-hackers-uk-power-plant-cyberattack/
#Cybersecurity #Infosec #CyberAttack #ThreatIntel #CriticalInfrastructure #OTSecurity #ICS #Iran #UK #EnergySecurity

IPv4 subnetting still trips people up in CCNA exams.
So I put together a practical cheat sheet covering:
• CIDR & subnet masks
• RFC 1918 private IP ranges
• APIPA & special addresses
• The “Magic Number” method
• Network, broadcast & usable ranges
• /25 through /32 quick reference
Example: 192.168.10.33/27 → Network: 192.168.10.32 | Broadcast: 192.168.10.63
If you're studying CCNA or brushing up on networking, this is worth bookmarking.
🔗 https://thecybersecguru.com/ccna-101/ipv4-subnetting-cheat-sheet/
#CCNA #Networking #Cybersecurity #InfoSec #Subnetting #Cisco

🚨 TELUS data breach: attackers reportedly accessed consumer accounts for 16 months using compromised credentials.
The intrusion reportedly lasted from February 2025 to June 2026, exposing names, account numbers, billing addresses, phone numbers, email addresses, payment-card last four digits, service details and payment history.
The unusual part? The stolen account information was allegedly used to contact customers and persuade them to switch their services to competitors. Some customers also had unauthorized service changes.
TELUS has not disclosed the number of affected accounts.
Full breakdown:
https://thecybersecguru.com/news/telus-data-breach-2026-customer-accounts/

🚨 Google Gemini just escaped its sandbox and hacked 3 REAL companies.
During an AI security test, Gemini got unintended internet access, found/guessed credentials, and gained access to real systems.
It only stopped after realizing the targets were real.
The scary part isn't that Gemini stopped.
It's that the sandbox let it get there in the first place.
Full breakdown:
https://thecybersecguru.com/news/google-gemini-hacked-three-companies/
🚨 Brevo supply-chain attack: 100,000+ WordPress sites potentially exposed.
Attackers reportedly abused a stolen, long-lived Cloudflare API key to modify Brevo’s edge infrastructure and inject malicious JavaScript.
The payload could:
• Target logged-in WordPress admins via CSRF/session riding
• Upload and activate a malicious plugin
• Install a persistent PHP backdoor
• Show ClickFix overlays to ordinary visitors
• Deliver infostealers such as Lumma/Vidar
The attack window: Sept. 14, 2026, 16:05–20:13 UTC.
Technical breakdown + IoCs:
https://thecybersecguru.com/news/brevo-supply-chain-attack-wordpress-backdoor/
#InfoSec #CyberSecurity #WordPress #Brevo #Cloudflare #SupplyChainAttack #Malware
🚨 Could this be another Log4Shell?
A newly reported Log4j2 deserialization flaw can bypass `FilteredObjectInputStream` protections through `java.rmi.MarshalledObject`, potentially opening the door to RCE, DoS and malicious log injection under the right conditions.
With Log4j2 still deeply embedded across Java environments, this one deserves attention.
How serious do you think this could become?
🔗 https://thecybersecguru.com/news/log4j2-deserialization-vulnerability-rce/
#Log4j2 #Log4j #Java #InfoSec #CyberSecurity #RCE #Deserialization
🚨 8.7 Million Airport Customers Hit by Cyberattack
Manchester Airports Group (MAG) has confirmed a cyberattack affecting customer data linked to Manchester, Stansted, and East Midlands airports.
Exposed data includes:
• Email addresses
• Phone numbers
• Vehicle registration numbers
• Postcodes
The affected data is tied to airport Wi-Fi registrations, car parking, lounge, and Fast Track bookings.
MAG says payment/banking information was not stored in the affected system, and airport operations, passenger safety, and aviation security were not compromised.
The bigger concern now is the potential for targeted phishing, impersonation, and social-engineering attacks using the stolen customer information.
Full technical breakdown and what affected customers should watch for:
https://thecybersecguru.com/news/manchester-airports-group-cyber-attack-8-7-million-customers/
#InfoSec #CyberSecurity #DataBreach #CyberAttack #ThreatIntelligence #Phishing #SocialEngineering


























