Airport breach exposes 8.7M customers

Airport data breach, PaperCut zero-day, ServiceNow flaws, and more.

Airport breach exposes 8.7M customers

Hi there, this is your daily ☕️ Cyberpresso.


In today's Cyberpresso:

✈️ Airport breach exposes 8.7M customers

🖨️ PaperCut hit by active zero-day

🛠️ ServiceNow patches 3 critical flaws

💉 Prompt injection makes Claude Code run malware

🔗 Malware hides backup server on Ethereum

Plus: 💡 6 strategies & tactics, 🎁 7 other news you might like, 🧰 6 tools, and 📚 5 papers.

✈️ Airport breach exposes 8.7M customers LINK

  • A cyberattack on Manchester Airports Group (MAG), which runs Manchester, East Midlands and London Stansted airports, stole the personal data of about 8.7 million customers, with attackers demanding a ransom that MAG says it refused to pay.
  • Most exposed data came from passengers who registered for airport WiFi, primarily email addresses, while car-park reservations, lounge bookings and fast-track access exposed vehicle registration numbers and postcodes, though no bank account or payment-card details were involved.
  • MAG says it identified the breach on Tuesday, contained it, engaged cybersecurity advisors and notified the UK Information Commissioner's Office; it warns customers to watch for phishing emails, texts and scam calls impersonating the airports or support teams.
  • 🖨️ PaperCut hit by active zero-day LINK

  • PaperCut is warning that attackers are exploiting an unspecified vulnerability in its PaperCut NG and PaperCut MF print management software, with the vendor confirming it is aware of real customer incidents involving the products.
  • The flaw is being actively exploited in the wild against the Application Server, the single "brain" of both products, and the bulletin's guidance to restrict public internet access points to a remotely exploitable bug, though PaperCut is still investigating.
  • Until fixed indicators are published, PaperCut says to restrict Application Server web access to trusted IP addresses and watch for suspicious post-exploitation activity from pc-app.exe or specific database errors in server.log.
  • 🛠️ ServiceNow patches 3 critical flaws LINK

  • ServiceNow has released patches for three maximum-severity flaws in its AI Platform, the cloud-based PaaS (formerly the Now Platform) that powers over 100,000 enterprise AI apps at 85% of Fortune 500 companies.
  • The most serious, CVE-2026-18885, is a code injection bug that lets unauthenticated attackers run arbitrary code, while the two others allow privilege escalation and reading or modifying instance data through SQL injection.
  • All three can be pulled off by unauthenticated attackers in low-complexity attacks with no user interaction; ServiceNow patched its cloud platform, told self-hosted customers to update, and said it is not aware of exploitation so far.
  • 💉 Prompt injection makes Claude Code run malware LINK

  • Researchers found that more than 100 websites host llms.txt and llms-full.txt files pointing to unregistered code packages and domains, letting attackers claim those names and make AI coding agents like Claude Code automatically install malware.
  • A stealth Israeli startup scanned 6,214 domains belonging to defense contractors, Fortune 500, and Big Tech companies, finding 8,265 of these files, of which 120 referenced unclaimed packages or domain names that anyone could register.
  • After registering a few unclaimed names, the researchers got phone-home beacons within an hour from Fortune 500 companies and startups whose coding agents, including Claude, OpenAI's Codex, and Nous Research's Hermes, executed the proof-of-concept code.
  • 🔗 Malware hides backup server on Ethereum LINK

  • A newly identified Go-based malware framework called GoCaracal, linked to the cyber-espionage group Dark Caracal, uses Ethereum smart contracts as a fallback way to recover its command-and-control server when the primary one is taken down.
  • If repeated attempts to reach its main C2 server fail, the implant queries a public Ethereum service for a replacement address stored in a custom Solidity contract named BulletproofC2, then writes the new address into memory and resumes normal off-chain communication.
  • Arctic Wolf tied the framework to a June 2026 intrusion in Venezuela delivered via Spanish-language tax-themed phishing with weaponized SVG files, and published a YARA rule plus hashes, domains, C2 addresses, and Ethereum contract indicators for threat hunting.
  • 💡 Strategies & Tactics

    > Hackers Abuse Active Directory SPN Misconfigurations for Stealthy Kerberoasting Attacks: Attackers briefly attach service labels to ordinary Windows accounts, steal crackable login tickets offline, then erase the change to evade detection, so audit user accounts for these labels and disable weak encryption.

    > Extend Amazon Bedrock Guardrails to Tool Interactions Using the Strands Agents SDK: checking tool inputs and outputs so external data and parameters can't slip through unvalidated.

    > Cleartext Credential Recovery in ServiceNow: Attackers with admin-level ServiceNow roles can modify its credential-test scripts to dump stored passwords and keys in cleartext, exposing secrets ServiceNow normally hides.

    > Inside 90 days of attacks on AI infrastructure: Attackers now target self-hosted AI tools like LiteLLM to steal model provider keys and hijack computing power, so treat internet-facing AI infrastructure as high-value production systems.

    > How Clop accessed the enterprise blueprint with no credentials: Clop exploited a flaw in Windchill engineering software to plant a stealthy implant that steals stored credentials while hiding inside trusted application activity, showing why defenders must monitor what their own software can access and decrypt.

    > AWS Shows How Hackers Can Turn Stolen Cloud Credentials Into Full-Scale Attacks: Correlate a single stolen identity's actions across cloud logs, comparing them to normal behavior, so a coordinated attack surfaces before scattered alerts miss it.

    Other news you might like

    • Unitree G1 Humanoid Robot Flaws Allow Unauthenticated Root RCE Over BluetoothLINK
    • BlueDelta Targets Defense and Diplomatic Organizations With HOOKEDGE MalwareLINK
    • Chinese Routers Sold Worldwide Contain BackdoorsLINK
    • CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix ProductsLINK
    • OpenAI’s rogue AI model incident was worse than we thoughtLINK
    • Go Loader Uses Anti-Sandbox Checks and SNOWLIGHT to Execute Fileless VShell RAT in MemoryLINK
    • Critical Next.js Vulnerabilities Enables Remote Code Execution AttacksLINK

    🧰 Trending tools

    Perfai Security: autonomously tests AI-built apps for access-control, business-logic, and prompt-injection flaws, then opens pull requests with confirmed fixes around the clock.LINK

    Halo: an API-first tool that combines NLP, visual, and audio authentication to detect deepfakes and synthetic media, helping fraud and trust teams stop synthetic media attacks.LINK

    MonoCloud for Startups: combines authentication and Cedar-based authorization for users, APIs, and AI agents, letting you control, audit, and revoke access, free for a year.LINK

    FireTail: discovers shadow AI, enforces governance policies from frameworks like OWASP, and centralizes logging to secure AI usage across all your environments.LINK

    ORGN CDE: an enterprise AI IDE that generates code privately using confidential computing, provable encryption, and zero data retention for security-conscious teams.LINK

    Playground: test your prompt injection skills against AI agents in a hands-on sandbox for exploring and understanding LLM security weaknessesLINK

    📚 Trending papers & reports

    Confidential AI on Blackwell chips can run private, encrypted large-model inference with only ~1-3% slowdown when configured right, versus the 30-40% penalty seen in default setups, making secure AI hosting nearly free.LINK

    Smart meter privacy lets utilities compute total neighborhood electricity use for grid monitoring and forecasting without ever seeing any household's individual reading, even if some meters are hacked or collude.LINK

    XRP Ledger defenses show that adding new trusted connections between nodes makes the network much harder for attackers to break by isolating the participants that hold it together.LINK

    Medical device attack testing gives hospitals a first benchmark to check whether security tools can tell real health emergencies from device faults or hacks, revealing that today's detectors miss replay attacks and small tampering almost entirely.LINK

    Web attack detection flags malicious traffic while highlighting exactly which parts of a request look suspicious, an approach that exposed mislabeled data in a popular public dataset that had been quietly blinding detection systems to real attacks.LINK


    See you tomorrow for a new dose of ☕️ Cyberpresso!

    More from the archive