Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (31 August 2026)
Published: Loading…
At a Glance
- Microsoft disclosed a TerminalFix ClickFix variant using fake Cloudflare CAPTCHAs to deploy a custom reverse-tunnel implant via Windows Terminal.
- An attacker exploited a flawed GitHub Actions workflow to publish 10 malicious versions of npm package @7nohe/openapi-react-query-codegen.
- FulcrumSec claimed theft of 86 GB of data from Manchester Airports Group, including nearly 200,000 upcoming travel bookings.
- Anthropic warned that infostealer malware including Vidar, LummaC2, StealC and RedLine is hijacking active Claude login sessions.
- Hasbro disclosed a data breach after a compromised employee account exposed customer names, contact details and financial information.
- Wordfence and Patchstack disclosed five critical WordPress plugin and theme flaws enabling site takeover or remote code execution.
Editorial Analysis
Several of today's incidents involved the theft or exposure of credentials already trusted by the target system. Anthropic warned that infostealers including Vidar, LummaC2, StealC and RedLine are being used to hijack active Claude sessions, allowing attackers to bypass authentication by taking over existing sessions rather than stealing passwords. FulcrumSec's claimed breach of Manchester Airports Group took a different route, allegedly using airport-specific API credentials exposed in client-side JavaScript to access customer and booking data. Neither case required a weakness in the underlying authentication system: access was obtained through credentials or sessions that were already trusted.
Attackers also continued to abuse legitimate distribution and delivery mechanisms. TerminalFix uses a spoofed Cloudflare CAPTCHA to direct users into Windows Terminal, rather than the Run dialog more commonly associated with ClickFix campaigns. The approach follows the same broader pattern seen in recent npm and Rust supply-chain compromises, where attackers use a trusted mechanism to deliver malicious code. In TerminalFix, that trust comes from a familiar browser security prompt; in supply-chain attacks, it comes from an established package or publishing process.
Highlights of the Day
TerminalFix Campaign Uses Fake CAPTCHAs to Deploy Reverse Tunnels
Microsoft identified a TerminalFix campaign, a ClickFix variant tricking users into pasting malicious PowerShell into Windows Terminal via fake Cloudflare CAPTCHA overlays. The attack chain combines DLL sideloading, steganographic payload delivery through PNG images, and extensive Active Directory reconnaissance. It culminates in a custom Python-based reverse tunnel that gives attackers persistent SOCKS-style proxy access into compromised networks.
Malicious npm Publish Exploited Flawed GitHub Actions Workflow
An attacker published 10 malicious versions of @7nohe/openapi-react-query-codegen by exploiting an unguarded issue_comment trigger in the package's release workflow. The pipeline checked out attacker-controlled fork code and held OIDC publishing permissions, allowing the attacker to mint npm tokens without stealing credentials. Payloads used node-gyp exploitation and a multi-layer obfuscated loader matching the Mini Shai-Hulud toolkit to download and execute a Bun runtime.
Hasbro Notifies Customers of Data Breach Involving Personal Information
Hasbro disclosed a data security incident involving a compromised employee account that allowed unauthorised access to personal information. Exposed data varied by individual and may have included names, email addresses, phone numbers, national ID numbers, or financial information. Hasbro has disabled the affected account, terminated unauthorised access, and is offering complimentary identity protection services to affected individuals.
Extortion Group Claims Theft of 86GB in Manchester Airports Breach
Extortion group FulcrumSec claimed responsibility for the Manchester Airports Group breach, alleging theft of roughly 86GB of customer data. The group says it used exposed Iterable API credentials found in client-side JavaScript to access records, including nearly 200,000 upcoming travel bookings. MAG previously disclosed that car park, lounge, Fast Track, and Wi-Fi registration data were affected, with reports suggesting 8.7 million customers impacted overall.
Anthropic Warns Infostealers Are Hijacking Claude Login Sessions
Anthropic has warned users that infostealer malware, including Vidar, LummaC2, StealC, RedLine and Acreed, is stealing active Claude login sessions from infected computers. Attackers use the stolen sessions to access accounts and consume usage without needing passwords or two-factor authentication. Anthropic is signing out affected users, removing saved payment methods, and refunding unauthorised charges.
Daily Coverage