Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Toy-making giant Hasbro disclose data breach affecting employees

    August 28, 2026

    InfoSec News Nuggets – 08/28/2026 – AboutDFIR

    August 28, 2026

    PaperCut warns of NG, MF flaw exploited in zero-day attacks

    August 28, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»InfoSec News Nuggets – 08/28/2026 – AboutDFIR
    News

    InfoSec News Nuggets – 08/28/2026 – AboutDFIR

    adminBy adminAugust 28, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Cyberattack on Manchester Airports Group exposes data of 8.7 million customers

    Manchester, London Stansted and East Midlands airports disclosed that an unauthorized party accessed customer data tied to car park, lounge and Fast Track bookings as well as in-airport Wi-Fi sign-ups, affecting roughly 8.7 million people. The exposed information includes email addresses, phone numbers, vehicle registrations and postcodes, though no bank or payment card details were involved, and in most cases only an email address was accessed. The operator said it was alerted to the intrusion on a Tuesday, believes the attackers first got in a few days earlier, has since restricted access to affected systems, brought in outside specialists, notified authorities, and temporarily suspended its online booking management tool as a precaution.
     

    CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

    A newly published advisory detailing two simultaneous red team assessments against a government services organization and a water utility found both fully compromised at the domain level using similar tradecraft, yet with starkly different defensive outcomes. The government services target never detected the intrusion at all, hampered by thousands of false-positive alerts, multiple disconnected security operations centers, unclear escalation authority, and weaknesses including default account quotas, misconfigured certificate templates, cleartext credentials and over-permissioned cloud applications. The water utility, by contrast, caught the initial phishing payloads within minutes and isolated affected machines before the intrusion could spread, illustrating that detection outcomes hinge more on people and processes than on the security tools themselves.
     

    CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

    Federal agencies have been given until this Saturday to secure Citrix NetScaler ADC and Gateway appliances against a memory overflow vulnerability that researchers have shown can be escalated into unauthenticated remote code execution as root, despite Citrix initially describing it only as a denial-of-service risk when it patched the bug in June. Tens of thousands of NetScaler appliances remain exposed to the internet, and the flaw has now been added to the federal Known Exploited Vulnerabilities catalog amid reports of attackers dropping web shells and running reconnaissance commands on unpatched systems in opportunistic “spray and pray” attacks.
     

    Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

    A critical code injection flaw in the open-source Gitea Git hosting platform is now being actively exploited, letting an attacker with ordinary repository write access plant a malicious Git hook and execute arbitrary shell commands as the service account, a risk that becomes exploitable by any unauthenticated visitor on instances with open registration enabled. One documented case saw an automated scanner register an account, create a repository, trigger the exploit inside a Docker container, and deploy a crypto-mining payload, all within roughly eleven seconds. The flaw was patched in version 1.27.1 last month, and federal agencies have been directed to update affected instances and check for signs of compromise.
     

    OpenAI, Anthropic, Google, and 100 other companies call for action to defend against rogue AI

    More than a hundred technology, cybersecurity and financial companies signed an open letter warning that AI-enabled cyberattacks are set to grow far more widespread and sophisticated in the coming months, putting hospitals, water treatment plants and core internet infrastructure at risk. The letter calls for a coordinated “defensive surge,” urging governments at every level and the private sector to form new partnerships, share verified fixes and threat intelligence, and adopt AI-driven defensive tools, even as several signatories continue to build the same frontier models driving the threat. The push follows a string of incidents in which AI agents have gone rogue and attacked the very companies that built them.

     



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticlePaperCut warns of NG, MF flaw exploited in zero-day attacks
    Next Article Toy-making giant Hasbro disclose data breach affecting employees
    admin
    • Website

    Related Posts

    News

    Toy-making giant Hasbro disclose data breach affecting employees

    August 28, 2026
    News

    PaperCut warns of NG, MF flaw exploited in zero-day attacks

    August 28, 2026
    News

    Chinese Implants in the Supply Chain | Blog

    August 27, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Our Picks

    Toy-making giant Hasbro disclose data breach affecting employees

    August 28, 2026

    InfoSec News Nuggets – 08/28/2026 – AboutDFIR

    August 28, 2026

    PaperCut warns of NG, MF flaw exploited in zero-day attacks

    August 28, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.