Ajax football club hack exposed fan data, enabled ticket hijack

2026-03-27T01:23:31Z3a854baca1f0ea1821125233eeb9f4acc8cfae53fa4502bd0eb24f407f6e4c03
CVE-2026-33017active-exploitationai-securitybubble-platform-abusecitrix-netscalercorunacybercrime-forumsdata-breachgithub-ai-scanninginfostealerios-exploitlangflowmagentophishingpolyshellredlinesanctionsthreat-actor-operationsticket-hijackingtorg-grabbervulnerability-patchxinbi

What happened

A bundle of mid‑late March 2026 cyber incidents and advisories: CISA warns of active exploitation of a critical Langflow flaw (CVE-2026-33017) used to hijack AI workflows; Ajax Amsterdam disclosed a breach that exposed fan data and enabled ticket hijacking; PolyShell attacks are actively targeting a majority of vulnerable Magento stores; new Torg Grabber infostealer and continued abuse of no-code platforms (Bubble) are being used to phish Microsoft credentials and steal crypto wallets. Additional items include Citrix NetScaler patches with urgent remediation guidance, UK sanctions against the

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
3a854baca1f0ea1821125233eeb9f4acc8cfae53fa4502bd0eb24f407f6e4c03
Enrichment time
2026-03-27T01:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.