The Week in 60 Seconds

Reported exploitation and exposure issues span routing and certificate processes, appliance vulnerabilities, endpoint-security configuration, and a third-party airport database; the airport responsibility claim remains unconfirmed rather than established. [1][2][3][4]

AI-related evidence combines research observations of coding agents interacting with researcher-controlled infrastructure with a reported espionage campaign where commercial models assisted attacker-built operations rather than independently compromising systems. [5][6][7]

Priority should separate reported active exploitation from research demonstrations and supplier investigations: SonicWall disclosed exploitation in the wild, while CrowdStrike said it was actively investigating a reported proof of concept. [2][3]

Security & Exploitation

Softaculous address-space hijack

What happened

Attackers conducted a supply-chain attack by hijacking Internet address space used by Softaculous, whose software manages Web applications and virtualized environments. [1]

The attackers exploited weaknesses in Hetzner Online’s routing-security setup and the process for obtaining valid TLS certificates. [1]

Why it matters

Softaculous used the hijacked IP addresses to deliver updates and host a client and billing site, creating exposure for users relying on those services. [1]

SonicWall SMA 1000 exploitation and fixes

What happened

SonicWall SMA 1000 appliances are affected by CVE-2026-83548 and CVE-2026-83549, which SonicWall disclosed as patched vulnerabilities already actively exploited in the wild. [2]

Rapid7 characterized the pair as a max-severity pre-authentication server-side request forgery flaw and a high-severity OS command injection flaw that can be chained for unauthenticated remote-code execution. [2]

Why it matters

CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog, while SonicWall did not disclose the number of affected customers or the first known exploitation date. [2]

AI & Agent Security

Coding-agent package-installation research

What happened

The researchers registered some unclaimed names and hosted packages that caused machines executing them to contact the researchers’ server. [5]

The researchers’ beacon recorded parent processes and indicated that coding agents, including Claude, OpenAI’s Codex, and Nous Research’s Hermes, were involved in the observed installs. [5]

Why it matters

Researcher Alon Hertz characterized the trust model as broken, saying agents treat vendor documentation as ground truth and that human supervisors do not question it. [5]

Coding-agent data at an inference honeypot

What happened

An internet-exposed inference honeypot was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide “free” LLM backends. [6]

The honeypot received a real coding-agent session containing history, filesystem output, working paths, and the agent’s local tool manifest. [6]

Why it matters

The honeypot did not request or cause tool execution; the exposed request showed what a malicious operator in that position could do. [6]

Reported AI-supported espionage campaign

What happened

Hunt.io documented a China-linked campaign using commercial AI models in live cyberespionage operations against government, education, political-archive and industrial targets across Asia. [7]

The models did not independently compromise systems; they helped automate scanning, credential testing, exploitation, webshell deployment, data collection and reporting within attacker-built infrastructure. [7]

Why it matters

Hunt.io said the activity is the second campaign in two months in which commercial AI coding tools were embedded as operational components of live nation-state intrusions. [7]

Cloud & Platform

Manchester Airports Group exposure update

What happened

MAG confirmed a breach of customer information in a third-party database involving parking, lounge, Fast Track and airport Wi‑Fi data; it said airport operations, passenger safety and aviation security were unaffected. [4]

MAG said attackers took email addresses, phone numbers, vehicle registration details and postcodes, while payment-card data was not accessed. [4]

Why it matters

The reported data can link a person to an airport, booking type, vehicle, location and contact number, making fraud attempts more convincing. [4]

FalconFlank investigation and configuration

What happened

The FalconFlank zero-day affects CrowdStrike’s Falcon endpoint security platform and is described as a privilege-escalation vulnerability abusing Falcon’s Microsoft Office malicious-macro remediation feature. [3]

The reported proof of concept works on fully updated Windows 11 25H2 and Windows Server 2025 systems when Falcon is running Phase 3 - Optimal Protection with malicious macro removal enabled. [3]

Why it matters

The affected Falcon feature inspects Microsoft Office documents and removes potentially harmful macro code to help prevent malicious code or other payloads from executing when documents are opened. [3]

Heimdall's Read

These distinct research observations identify a bounded exposure concern for coding-agent workflows: untrusted package sources and model backends can expose execution context or create external contact. [5][6]

Both researcher observations place coding agents at researcher-controlled infrastructure: package execution produced external contact in one, while an exposed inference endpoint received a session containing local context in the other. [5][6]

What Changed

Manchester Airports Group exposure update

Reported August 30, 2026

MAG said 8.7 million customers were impacted, but most had only email addresses exposed, and that no payment-card or banking data was exposed. [8]

BleepingComputer checked one supplied record against a real traveler’s purchase history and found matching Fast Track bookings, arrival times, terminal information, and payment amounts. [8]

Reported September 4, 2026

Have I Been Pwned reported approximately 8.8 million compromised email addresses and phone numbers, alongside names, IP addresses, browser user-agent details, geographic information, purchases and vehicle registration plates. [4]

The later HIBP-processed dataset adds reported evidence after MAG’s earlier estimate and a checked traveler record; because the denominators differ, it does not establish an increase in unique victims. [8][4]

Watch Next Week

Softaculous address-space hijack

Watch

The supplied evidence does not identify the attackers, affected user count, malware behavior, or remediation and compromise-check guidance. [1]

Coding-agent package-installation research

Watch

Anthropic, OpenAI, and Nous Research had not responded to requests for comment by publication time, so the evidence does not establish their explanations or the relevant configuration differences. [5]

Manchester Airports Group exposure update

Watch

FulcrumSec claimed responsibility, said it leaked the data after MAG refused a ransom demand, and alleged access through administrator keys exposed in frontend JavaScript on all three airport websites; MAG had not confirmed that access method and SecurityWeek had not independently verified it. [4]

SonicWall SMA 1000 exploitation and fixes

Watch

SonicWall urged customers to contact technical support to review indicators of compromise and hunt for potential compromise; if signs are detected, it advised reimaging or redeploying the appliance, changing user and administrator passwords, and resetting tokens. [2]

Sources (8)
  1. [1] BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

    arstechnica security · September 2, 2026

  2. [2] Attackers exploit zero-days in consistently besieged SonicWall product

    cyberscoop · September 3, 2026

  3. [3] Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC

    theregister security · September 3, 2026

  4. [4] Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People

    securityaffairs · September 4, 2026

  5. [5] AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks

    schneier blog · September 4, 2026

  6. [6] The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)

    sans isc diary · August 31, 2026

  7. [7] Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign

    securityaffairs · September 4, 2026

  8. [8] Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft

    securityaffairs · August 30, 2026

Heimdall Weekly · 2026-08-29 – 2026-09-04 · Baitaphish