The Week in 60 Seconds
Security & Exploitation
Softaculous address-space hijack
What happened
Attackers conducted a supply-chain attack by hijacking Internet address space used by Softaculous, whose software manages Web applications and virtualized environments. [1]
The attackers exploited weaknesses in Hetzner Online’s routing-security setup and the process for obtaining valid TLS certificates. [1]
Why it matters
Softaculous used the hijacked IP addresses to deliver updates and host a client and billing site, creating exposure for users relying on those services. [1]
SonicWall SMA 1000 exploitation and fixes
What happened
SonicWall SMA 1000 appliances are affected by CVE-2026-83548 and CVE-2026-83549, which SonicWall disclosed as patched vulnerabilities already actively exploited in the wild. [2]
Rapid7 characterized the pair as a max-severity pre-authentication server-side request forgery flaw and a high-severity OS command injection flaw that can be chained for unauthenticated remote-code execution. [2]
Why it matters
CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog, while SonicWall did not disclose the number of affected customers or the first known exploitation date. [2]
AI & Agent Security
Coding-agent package-installation research
What happened
The researchers registered some unclaimed names and hosted packages that caused machines executing them to contact the researchers’ server. [5]
The researchers’ beacon recorded parent processes and indicated that coding agents, including Claude, OpenAI’s Codex, and Nous Research’s Hermes, were involved in the observed installs. [5]
Why it matters
Researcher Alon Hertz characterized the trust model as broken, saying agents treat vendor documentation as ground truth and that human supervisors do not question it. [5]
Coding-agent data at an inference honeypot
What happened
An internet-exposed inference honeypot was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide “free” LLM backends. [6]
The honeypot received a real coding-agent session containing history, filesystem output, working paths, and the agent’s local tool manifest. [6]
Why it matters
The honeypot did not request or cause tool execution; the exposed request showed what a malicious operator in that position could do. [6]
Reported AI-supported espionage campaign
What happened
Hunt.io documented a China-linked campaign using commercial AI models in live cyberespionage operations against government, education, political-archive and industrial targets across Asia. [7]
The models did not independently compromise systems; they helped automate scanning, credential testing, exploitation, webshell deployment, data collection and reporting within attacker-built infrastructure. [7]
Why it matters
Hunt.io said the activity is the second campaign in two months in which commercial AI coding tools were embedded as operational components of live nation-state intrusions. [7]
Cloud & Platform
Manchester Airports Group exposure update
What happened
MAG confirmed a breach of customer information in a third-party database involving parking, lounge, Fast Track and airport Wi‑Fi data; it said airport operations, passenger safety and aviation security were unaffected. [4]
MAG said attackers took email addresses, phone numbers, vehicle registration details and postcodes, while payment-card data was not accessed. [4]
Why it matters
The reported data can link a person to an airport, booking type, vehicle, location and contact number, making fraud attempts more convincing. [4]
FalconFlank investigation and configuration
What happened
The FalconFlank zero-day affects CrowdStrike’s Falcon endpoint security platform and is described as a privilege-escalation vulnerability abusing Falcon’s Microsoft Office malicious-macro remediation feature. [3]
The reported proof of concept works on fully updated Windows 11 25H2 and Windows Server 2025 systems when Falcon is running Phase 3 - Optimal Protection with malicious macro removal enabled. [3]
Why it matters
The affected Falcon feature inspects Microsoft Office documents and removes potentially harmful macro code to help prevent malicious code or other payloads from executing when documents are opened. [3]
Heimdall's Read
What Changed
Manchester Airports Group exposure update
Reported August 30, 2026
MAG said 8.7 million customers were impacted, but most had only email addresses exposed, and that no payment-card or banking data was exposed. [8]
BleepingComputer checked one supplied record against a real traveler’s purchase history and found matching Fast Track bookings, arrival times, terminal information, and payment amounts. [8]
Reported September 4, 2026
Have I Been Pwned reported approximately 8.8 million compromised email addresses and phone numbers, alongside names, IP addresses, browser user-agent details, geographic information, purchases and vehicle registration plates. [4]
Watch Next Week
Softaculous address-space hijack
Watch
The supplied evidence does not identify the attackers, affected user count, malware behavior, or remediation and compromise-check guidance. [1]
Coding-agent package-installation research
Watch
Anthropic, OpenAI, and Nous Research had not responded to requests for comment by publication time, so the evidence does not establish their explanations or the relevant configuration differences. [5]
Manchester Airports Group exposure update
Watch
FulcrumSec claimed responsibility, said it leaked the data after MAG refused a ransom demand, and alleged access through administrator keys exposed in frontend JavaScript on all three airport websites; MAG had not confirmed that access method and SecurityWeek had not independently verified it. [4]
SonicWall SMA 1000 exploitation and fixes
Watch
SonicWall urged customers to contact technical support to review indicators of compromise and hunt for potential compromise; if signs are detected, it advised reimaging or redeploying the appliance, changing user and administrator passwords, and resetting tokens. [2]