192.168.1.1Sampled records contained IP addresses
ThreatNoir Morning Brief — August 31
Morning Review in IT Security — August 31, 2026
The cybersecurity landscape continues to face significant threats as August concludes, with major incidents spanning airport infrastructure breaches, malicious browser extensions, AI platform hijacking, and critical WordPress vulnerabilities. Organizations and individual users alike face escalating risks from both opportunistic and sophisticated threat actors seeking to exploit unpatched systems and steal sensitive credentials.
FulcrumSec Claims Manchester Airports Hack, Theft of 86 GB of Data
The threat actor FulcrumSec has claimed responsibility for a breach targeting Manchester Airports Group, allegedly stealing 86 gigabytes of sensitive data. BleepingComputer independently validated the authenticity of the breach by confirming at least one traveler's record from the stolen samples. The exposed data extends beyond what Manchester Airports Group initially disclosed to the public, containing detailed customer information, booking records, and comprehensive travel data that poses significant privacy risks to affected passengers. Source: FulcrumSec claims Manchester Airports hack, theft of 86 GB of data
Chrome Web Store Extensions Caught Stealing Crypto, Browser Data
Security researchers have identified multiple malicious extensions distributed through the Google Chrome Web Store and Microsoft Edge that deployed a sophisticated malware framework capable of stealing cryptocurrency, sensitive user data, and browser history. The malware also injected ClickFix lures designed to deceive users into clicking malicious links. This discovery highlights the ongoing vulnerability of official browser extension marketplaces to malicious submissions despite platform security reviews. Source: Chrome Web Store extensions caught stealing crypto, browser data
Anthropic Warns Infostealer Malware Is Hijacking Claude Sessions to Drain Usage
Anthropic has issued a warning to Claude users that infostealer malware present on compromised personal computers has been stealing active Claude login sessions, enabling attackers to gain unauthorized access to user accounts and consume their API usage quotas. The malware families identified in this campaign include Acreed, Atomic Stealer, LummaC2, RedLine, StealC, and Vidar. This attack demonstrates how credential theft malware can be repurposed to target AI platform accounts and represents a growing threat to users of AI services who may not realize their sessions have been compromised. Source: Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Five critical security vulnerabilities have been disclosed in widely used WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could allow attackers to bypass authentication, take over accounts, or execute arbitrary code on affected websites. The vulnerabilities include CVE-2026-76581 with a CVSS score of 9.8, along with CVE-2026-18431, CVE-2026-19598, CVE-2026-19632, and CVE-2026-82222. These flaws pose an immediate threat to the millions of WordPress sites relying on these popular extensions and require urgent patching to prevent site compromise. Source: Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
As the day progresses, security teams should prioritize patching WordPress vulnerabilities, reviewing browser extension installations, securing Claude API credentials, and monitoring for any indicators of compromise related to the Manchester Airports breach. The convergence of these threats underscores the critical importance of maintaining robust security hygiene across infrastructure, applications, and user endpoints.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Atomic Stealer (AMOS)Infostealer malware identified by Anthropic on Macs
- VidarInfostealer malware identified by Anthropic
- LummaC2Infostealer malware identified by Anthropic
- StealCInfostealer malware identified by Anthropic
- RedLineInfostealer malware identified by Anthropic
- AcreedInfostealer malware identified by Anthropic
- Authentication bypass in WPMU DEV Dashboard plugin
- Arbitrary file write in Avada theme
- Sensitive information exposure in TranslatePress plugin
- Privilege escalation in Pods plugin
- Arbitrary command execution in GiveWP plugin