Ajax football club hack exposed fan data, enabled ticket hijack
2026-03-27T07:23:26Z•a962f2c8bac680c2273252729f87c628111de781abaa4028c55c174318172c76
AI securityBubble platform abuseCVE-2026-33017Citrix NetScalerCorunaLangflowLeakBaseMagentoPolyShellRedLineTikTok for BusinessTorg GrabberXinbiactive exploitationcredential theftdata breachiOS exploitsinfostealerpaid-AI-accountspatch nowphishingsanctionssupply-chainticket hijackunderground markets
What happened
Multiple active cyber incidents and trends: CISA warns of a critical, actively exploited Langflow vulnerability (CVE-2026-33017) that lets attackers hijack AI workflows. Dutch club Ajax suffered a breach exposing a few hundred fans’ data and enabling ticket hijacks. The UK sanctioned the Xinbi marketplace for selling stolen data and equipment to scam networks. Phishing campaigns target TikTok for Business and Microsoft accounts (abusing Bubble no-code apps to evade detectors). New infostealers are active — Torg Grabber targets hundreds of crypto-wallet extensions, and RedLine infrastructure is
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- a962f2c8bac680c2273252729f87c628111de781abaa4028c55c174318172c76
- Enrichment time
- 2026-03-27T07:23:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.