π¨ ACTIVE EXPLOITATION
- UPDATE: Australia Charges Two Alleged TeamPCP Hackers Over Supply-Chain Attacks
Australia has charged two alleged TeamPCP members over global software supply-chain attacks.- Government, academic, and private-sector organizations worldwide were affected.
- Trivy, LiteLLM, Telnyx, SAP, and TanStack packages were among the targets.
- Malicious code was injected into open-source repositories and then incorporated by developers.
- The activity potentially compromised more than 1,000 organizations, stealing 500,000 credentials and at least 300GB of data.
- Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, face 14 combined charges after arrests in Western Australia.
π Coverage: bleepingcomputer.com Β· π via BleepingComputer, SecurityWeek (+2)
π₯ BREACHES & INCIDENTS
- Hackers access data of 8.7 million customers at three UK airports
Hackers accessed data belonging to 8.7 million customers of three UK airports.- Manchester Airports Group customers at Manchester, London Stansted and East Midlands airports were affected.
- Exposed data included email addresses, phone numbers, vehicle registrations and postcodes.
- Email addresses came mainly from airport Wi-Fi sign-ups.
- Vehicle registrations and other details came from car-park, lounge and fast-track bookings.
π Coverage: bbc.com Β· π via r/cybersecurity, @metacurity@infosec.exchange
π΅οΈ RESEARCH & DEEP DIVES
-
Russian-linked hackers target senior EU officials on Signal and WhatsApp
Russian-linked hackers targeted senior EU officials through Signal and WhatsApp phishing.- Senior EU officials using Signal and WhatsApp were targeted, including political, military and diplomatic figures.
- Attackers sought to hijack messaging accounts and read private and group conversations.
- Personalized spearphishing messages used malicious links, files and social engineering.
- Fake Signal support chatbots requested security codes that could link attacker-controlled devices to accounts.
π Source: politico.eu Β· π Coverage: darkreading.com Β· π via Dark Reading
-
Russian-Speaking Hackers Used Cursor AI in Intrusions Against Seven Companies
Russian-speaking hackers used Cursor AI to accelerate intrusions against at least seven companies.- Victims included companies in chemicals, manufacturing, logistics, pharmaceuticals, and title insurance.
- Aur0ra ransomware operators sought administrator accounts, credentials, and access to corporate networks.
- Hackers used Cursorβs AI agent to plan attacks and generate technical guidance.
- They bypassed Cursorβs refusals by claiming the activity was a security simulation.
- The campaign was exposed after researchers found an unauthenticated server containing 28 Cursor chat sessions.
π Coverage: reuters.com Β· π via r/cybersecurity
π CVEs & KEV
-
CVE-2026-77554 β CVSS 10.0 β A malicious actor with access to the network could exploit an Improper Input ...
-
CVE-2026-77550 β CVSS 10.0 β A malicious actor with access to the network could exploit an Improper Neutra...
-
CVE-2026-77553 β CVSS 9.9 β A malicious actor with access to the network and low privileges could exploit...
-
CVE-2026-77548 β CVSS 9.9 β A malicious actor with access to the network and low privileges could exploit...
-
CVE-2026-77547 β CVSS 9.9 β A malicious actor with access to the network and low privileges could exploit...
-
CVE-2026-77546 β CVSS 9.9 β A malicious actor with access to the network and low privileges could exploit...
-
CVE-2026-18080 β CVSS 9.8 β ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce through 1.17.8 - Un...
-
CVE-2026-77557 β CVSS 9.8 β A malicious actor with access to the network could exploit an Improper Access...
-
CVE-2026-77552 β CVSS 9.8 β A malicious actor with access to the network could exploit an Improper Input ...
-
CVE-2026-77532 β CVSS 9.6 β A malicious actor with access to an adjacent network could exploit a Buffer O...
-
CVE-2026-80204 β CVSS 9.3 β Grav before 1.0.18 Authentication Bypass via Scoped API KeyThe Grav API plugi...
-
CVE-2026-80203 β CVSS 9.3 β Grav before 1.0.18 Authentication Bypass via Scoped API KeyThe getgrav/grav-p...
-
CVE-2026-77551 β CVSS 9.0 β A malicious actor with access to the network and under certain conditions cou...
-
CVE-2026-77549 β CVSS 9.0 β A malicious actor with access to the network and under certain conditions cou...
-
CVE-2026-81579 β CVSS 8.8 β WibuKey for Windows: Kernel Driver Privilege Escalation
-
CVE-2026-81662 β CVSS 8.6 β Flowintel Alert Settings Configuration Allows Remote Code Execution via Arbit...
-
CVE-2026-15985 β CVSS 8.1 β Classified Listing - Mobile Number Verification through 1.6.0 - Unauthenticated Au...
-
CVE-2026-81743 β CVSS 7.5 β Flowintel Arbitrary Log File Path Allows Remote Code Execution via Template I...
-
CVE-2026-81659 β CVSS 7.1 β Flowintel Note PDF Export Allows Arbitrary Local File Read via Pandoc/XeLaTeX...
-
CVE-2026-81658 β CVSS 6.5 β Foreman: cross-tenant disclosure of template revisions via unauthorized audit...