Phishing

Application Security
Five Critical WordPress Flaws Enable Site Takeover and RCE
Five critical vulnerabilities in WPMU DEV Dashboard, Avada Theme, TranslatePress, Pods, and GiveWP allow authentication bypass, privilege escalation, and RCE.
Application Security
Anthropic Warns Infostealer Malware Hijacking Claude Sessions
Anthropic warns Vidar, Lumma, StealC, RedLine, and AMOS malware are stealing Claude session tokens, enabling attackers to drain user credits fraudulently.
CVE Vulnerability Alerts
FulcrumSec Claims 86GB Manchester Airports Data Breach
FulcrumSec claims theft of 86 gigabytes from Manchester Airports Group, exposing booking data for 8.7 million customers from a third-party database breach.
Cybersecurity
Berlin Refuses Rhysida Ransom as Group Claims 5.7TB Data Theft
Rhysida ransomware group demanded 30 bitcoin for 5.7 terabytes of Berlin state data, but Governing Mayor Kai Wegner flatly refused to negotiate or pay.
CVE Vulnerability Alerts
Two Nigerians Extradited to US for Sextortion That Killed Two Teens
Adebola Adekunle and Mudasiru Olawale were extradited from Nigeria on August 31 to face charges in sextortion schemes that killed two U.S. teens.
Application Security
AI Research Org METR Loses $600K in Credits to Dual Breach Attacks
METR disclosed two incidents where attackers stole API keys and consumed $600,000 in AI credits through fail-open authentication and targeted probing.
Application Security
WatchGuard Patches Five Critical RCE Flaws in Fireware and Dimension
WatchGuard patched five CVSS 9.3 buffer overflow and privilege escalation flaws enabling unauthenticated remote code execution in Fireware and Dimension.
Cybersecurity
Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass
U.S. and South Korean intelligence agencies warn Gunra ransomware exploits Fortinet firewall flaws alongside a previously undocumented MFA bypass technique.
Cybersecurity
Sandworm Fake Job Interview Campaign Targets Ukrainian IT Workers
CERT-UA attributes a Sandworm-linked UAC-0145 social engineering campaign using fake job interviews and trojanized WireGuard VPN clients against Ukraine.
Cybersecurity
CSS Attacks Break Webmail Boundaries to Capture Passwords, Tokens
PortSwigger researcher Gareth Heyes showed email-borne CSS attacks that capture passwords and steal tokens in Outlook, Gmail, Yahoo, and other webmail services.