Weekly review

ThreatNoir Morning Brief — August 31

2026-08-31Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — August 31, 2026

The cybersecurity landscape continues to face significant threats as August concludes, with major incidents spanning airport infrastructure breaches, malicious browser extensions, AI platform hijacking, and critical WordPress vulnerabilities. Organizations and individual users alike face escalating risks from both opportunistic and sophisticated threat actors seeking to exploit unpatched systems and steal sensitive credentials.

FulcrumSec Claims Manchester Airports Hack, Theft of 86 GB of Data

The threat actor FulcrumSec has claimed responsibility for a breach targeting Manchester Airports Group, allegedly stealing 86 gigabytes of sensitive data. BleepingComputer independently validated the authenticity of the breach by confirming at least one traveler's record from the stolen samples. The exposed data extends beyond what Manchester Airports Group initially disclosed to the public, containing detailed customer information, booking records, and comprehensive travel data that poses significant privacy risks to affected passengers. Source: FulcrumSec claims Manchester Airports hack, theft of 86 GB of data

Chrome Web Store Extensions Caught Stealing Crypto, Browser Data

Security researchers have identified multiple malicious extensions distributed through the Google Chrome Web Store and Microsoft Edge that deployed a sophisticated malware framework capable of stealing cryptocurrency, sensitive user data, and browser history. The malware also injected ClickFix lures designed to deceive users into clicking malicious links. This discovery highlights the ongoing vulnerability of official browser extension marketplaces to malicious submissions despite platform security reviews. Source: Chrome Web Store extensions caught stealing crypto, browser data

Anthropic Warns Infostealer Malware Is Hijacking Claude Sessions to Drain Usage

Anthropic has issued a warning to Claude users that infostealer malware present on compromised personal computers has been stealing active Claude login sessions, enabling attackers to gain unauthorized access to user accounts and consume their API usage quotas. The malware families identified in this campaign include Acreed, Atomic Stealer, LummaC2, RedLine, StealC, and Vidar. This attack demonstrates how credential theft malware can be repurposed to target AI platform accounts and represents a growing threat to users of AI services who may not realize their sessions have been compromised. Source: Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Five critical security vulnerabilities have been disclosed in widely used WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could allow attackers to bypass authentication, take over accounts, or execute arbitrary code on affected websites. The vulnerabilities include CVE-2026-76581 with a CVSS score of 9.8, along with CVE-2026-18431, CVE-2026-19598, CVE-2026-19632, and CVE-2026-82222. These flaws pose an immediate threat to the millions of WordPress sites relying on these popular extensions and require urgent patching to prevent site compromise. Source: Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

As the day progresses, security teams should prioritize patching WordPress vulnerabilities, reviewing browser extension installations, securing Claude API credentials, and monitoring for any indicators of compromise related to the Manchester Airports breach. The convergence of these threats underscores the critical importance of maintaining robust security hygiene across infrastructure, applications, and user endpoints.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
Malware6
  • Atomic Stealer (AMOS)
    Infostealer malware identified by Anthropic on Macs
  • Vidar
    Infostealer malware identified by Anthropic
  • LummaC2
    Infostealer malware identified by Anthropic
  • StealC
    Infostealer malware identified by Anthropic
  • RedLine
    Infostealer malware identified by Anthropic
  • Acreed
    Infostealer malware identified by Anthropic