Today on CISO Series…
- Super Cyber Friday:”Hacking our Comfort with Autonomous Agents”
- Join us LIVE on YouTube forDepartment of Know
In today’s cybersecurity news…
Manchester Airports Group suffers cyber incident
The operator of Manchester airport, London Stansted, and East Midlands airports, announced a breach that involves the theft of customer data relating to car park, lounge and Fast Track bookings, as well as in-airport Wi-Fi sign-ups. Specifically, the stolen data includes customers’ email addresses, phone numbers, vehicle registration numbers and postcodes. MAG said “neither it nor the affected system held customers’ bank or payment details.” It stressed also that passenger safety and aviation security had not been compromised and that airport operations remained unaffected. Its online booking service has been temporarily suspended as a precaution. No mention of the group responsible has yet been made.
ATF suffers data breach
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed that it recently experienced a cyberattack, calling the breach a “major incident.” The agency which operates within the Department of Justice, which itself has been suffering a series of intrusions, appeared on the leak site of the Qilin ransomware gang on Wednesday. A spokesperson for the ATF told Recorded Future News the issue “involved a standalone computer system containing information about targets of ATF investigations,” which was not connected to any other ATF systems, including any case management systems.”
Clothing retailer Carhartt suffers data breach
Sensitive data from nearly 13 million accounts stolen from the company earlier this month, has now been published by the ShinyHunters extortion group, according to Have I Been Pwned. Representatives from Carhartt have not yet confirmed the claims made by ShinyHunters, which the attack, which occurred on August 13 and which involved more than 50GB of documents containing a wide range of customer, employee, and corporate data. The group released an archive of the allegedly stolen records on its dark web after the company refused to pay up.
Microsoft delivers fix for Windows 11 crashes, gaming issues
This fix is in regard to system crashes and gaming issues on Windows 11 devices that return “EXCEPTION_ACCESS_VIOLATION” errors. “While it was initially believed that the August 2026 updates may be behind these problems,Microsoftlater blamed them on peripherals with built-in RGB lighting,” adding that such lighting devices “may install drivers or code components with file names similar to inpoutx64.” In addition to the rollout already underway, a driver block will also be included in the September 2026 Windows security updates and future releases.
Big thanks to our sponsor,ThreatDown
Australia arrests 2 alleged TeamPCP members
Two men, both in their early twenties, have been arrested and charged by Australian authorities in relation to their alleged affiliation with the cybercrime syndicate that is believed to “have caused financial losses totaling hundreds of millions of dollars.” In short, TeamPCP compromised major software supply chains and developer security tools to siphon over 500,000 corporate credentials from compromised CI/CD pipelines,” transforming corporate software pipelines into data-harvesting networks.
Three 10.0 Ubiquiti security flaws fixed
The company, which manufactures wireless and wired data communication products, has patched 22 critical vulnerabilities, three of which were rated 10 out of 10, have CVE numbers and would have allowed a hacker to access privileges on the device or application. (CVE-2026-77537, CVE-2026-77550 and CVE-2026-77554). All but one of these vulnerabilities affect theUbiquiti Inc.UniFi line of products. The company “did not immediately respond to a request for comment about whether it had seen any of the exploits used in the wild before they were patched.”
CISA adds six exploited flaws to KEV
Cybersecurity and Infrastructure Security Agencyon Wednesday added six flaws to its Known Exploited Vulnerabilities catalog, “including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation.” Also included, a remote code execution vulnerability in Microsoft SQL Server, an out-of-bounds memory write vulnerability in Linux Kernel, a privilege escalation vulnerability in Red Hat Automatic Bug Reporting Tool (ABRT) and a deserialization of untrusted data vulnerability inAjax.NETProfessional (AjaxPro). A link with additional details is available in the show notes to this episode.
Unexpected chat between OpenAI agents led to Hugging Face hack
According to reports published byOpenAIand independent AI research firm METR regarding the infamous HuggingFace hack, “more than 1,200 AI agents within OpenAI started unexpectedly communicating, it led to a large group banding together in order to hack into Hugging Face.” Describing the scale of this action as “extraordinarily complex,” the report says “a total of 1,206 AI agents that were meant to be kept isolated from one another began communicating. They did so by sending more than 70,000 messages on an “unsanctioned message board,” which enabled more than 700 agents take part in a collective effort to attack Hugging Face. “As for why the agents began communicating in the first place when they were not supposed to, METR found that the communicating agents had “unintentionally been given an impossible task,” forcing the agents to cheat in order to resolve its command.
Spotify,Apple Podcasts,YouTube,RSS link,Amazon Music, add as anAlexa Skill, or search “Cybersecurity Headlines” on your favorite podcast app.