Skip to content

Confidential Β· 05 Sep 2026

πŸ›‘οΈ Daily Cybersecurity Briefing β€” 2026-09-05 (Saturday)

Window: last 24–48h (Sep 4–5). Severity: πŸ”΄ CRITICAL Β· 🟑 HIGH Β· 🟒 MEDIUM.

Threat level GUARDEDVictims L30D 86Top actor QilinM&A L30D $94.5M

Number of the day8.8Mpeople whose email addresses, phone numbers, vehicle registrations, and airport-service records were published online by FulcrumSec after Manchester Airports Group refused to pay a ransom demand; the largest confirmed data dump from a UK aviation operator on record. SecurityWeek Β· BleepingComputer

πŸ’Ό M&A ACTIVITY

No new cybersecurity M&A deals confirmed in the Sep 4–5 weekend windowMediumCybersecuritymarket quiet; no announcements tracked via SecurityWeek, Return on Security, or Infosecurity Magazine. SecurityWeek's August roundup is expected the week of Sep 7 and may surface late-August deals. mWISE (Sep 15–17, Atlanta) is the next likely deal-announcement cluster.
L30D summary (Aug 6 – Sep 5): 12 deals tracked in August 2026; disclosed-value highlights: Visaβ†’BioCatch $2.4B (behavioural-biometrics/fraud detection, largest Aug deal); Zenity $125M Series C (AI agent governance); CyberCatch $94.5M all-cash (compliance AI, Datavault AI); Oligo Security $60M Series C (runtime/AI application security); Obsidian Security $100M+ Series D (SSPM/identity). Consolidation theme: AI governance, identity, and agentic-AI security absorb the bulk of capital; no new September deals yet. SecurityWeek M&A Tracker

⚠️ CRITICAL BREACHES & INCIDENTS

Manchester Airports Group / FulcrumSec β€” 8.8M traveller records published after ransom refusal; API credentials left in public JavaScriptCriticalTransportation & LogisticsFulcrumSec published roughly 550GB of uncompressed data (86GB compressed) on September 4 after Manchester Airports Group (MAG) declined to pay its ransom demand. The exfiltrated dataset covers parking bookings, lounge access, Fast Track purchases, and Wi-Fi sign-ups at three UK airports (Manchester, London Stansted, East Midlands), and contains email addresses, phone numbers, vehicle registrations, and postcodes for approximately 8.8 million people. Payment-card data was not accessed. Root cause: FulcrumSec extracted 86GB from MAG's Iterable marketing-automation platform using API credentials the group found embedded in publicly accessible JavaScript code on each airport's website β€” no network intrusion required. MAG disclosed the incident on August 27; FulcrumSec claimed responsibility September 1 and published September 4. UK ICO and relevant authorities have been notified. SecurityWeek Β· BleepingComputer Β· Infosecurity Magazine
McKesson / ShinyHunters β€” Sep 9 data-publication deadline 4 days out; $55M demand unanswered; no public payment or settlement signalCriticalHealthcare & Life SciencesAs of Sep 5, ShinyHunters has not published data and McKesson has not confirmed payment or resolution. The Sep 9 deadline was the group's second stated threshold (the initial September 1 negotiation window passed without McKesson engaging publicly). The 284M-record Snowflake exfiltration (attack window Aug 21–25) involved vishing β†’ Okta SSO credential theft β†’ multi-SaaS pivot, a methodology structurally identical to the Scattered Spider/UNC3944 playbook. One credible source reports the initial deadline already passed and ShinyHunters has not yet published β€” consistent with a private negotiation or deliberate delay for leverage. πŸŸ₯ The 284M-record count is ShinyHunters' own Snowflake row-count characterisation; unique-individual figure TBD. SecurityWeek Β· ExZec Cyber Β· Malwarebytes
Boston Scientific β€” day 12 recovery; Piper Sandler mid-September restoration estimate; no new network activity since Aug 25HighHealthcare & Life SciencesIndustrials & ManufacturingNo change in status since Sep 4. Cork manufacturing remains at reduced capacity; partial order processing resumed for select product lines. Mid-September is the Piper Sandler restoration estimate. Hospital procurement planners for elective cardiac procedures should continue contingency sourcing. πŸŸ₯ Server Killers attribution remains an unconfirmed hacktivist claim; no data-exfiltration scope disclosed. Boston Scientific
Rhysida / Berlin Senate β€” Sep 20 state election 15 days out; DLS data auction countdown active; election data confirmed not in exfiltrated setHighGovernment & Public SectorThe 30 BTC (~EUR 2M) auction for 5.79TB of Berlin Senate data remains live. Berlin interior administration has confirmed election-infrastructure data is not in the claimed dataset. Pre-election uncertainty continues to function as information-environment disruption regardless of data authenticity. πŸŸ₯ Data scope and sample authenticity unverified. Cybernews Β· BankInfoSecurity
EDIF S.p.A. / Aurora ransomware β€” Italian wholesale electrical-equipment distributor claimed Sep 4; attack estimated Aug 27HighIndustrials & ManufacturingAurora posted EDIF S.p.A. (Italian wholesale distributor of electrical equipment, plumbing, and lighting systems) on its DLS September 4. Exposed files reportedly include system passwords, certified email credentials, customer invoices, tax numbers, shipping records, CCTV configurations, databases, financial records, and a detailed 2024 financial report. Attack estimated August 27. πŸŸ₯ DLS claim; verify before treating as a breach. DeXpose Β· RedPacket Security
Gunra ransomware β€” Blanco & Etcheverry (Uruguay, law) and Occidental (Venezuela, insurance) claimed Sep 4MediumGunra posted two new victims on September 4: Blanco & Etcheverry, a Uruguayan law firm (~$5M revenue), and Occidental, a Venezuelan insurance company (~$157M revenue). CISA issued #StopRansomware advisory AA26-222A on Gunra in August. No data-exfiltration scope confirmed for either. πŸŸ₯ Both DLS claims; unverified. Ransomware.live/Blanco Β· Ransomware.live/Occidental Β· CISA AA26-222A
Data I/O β€” all systems operational as of Sep 4; ransomware intrusion via commercial third-party firewall; no confirmed customer or revenue impactMediumTechnology & SoftwareData I/O (semiconductor programming equipment) confirmed full system restoration by September 4 following a ransomware attack. The company attributed initial access to a vulnerability in a commercial third-party firewall product and stated the attack was not specifically targeted at Data I/O. No customer, order, or revenue losses were reported.

πŸ”“ CRITICAL VULNERABILITIES

Kestra CVE-2026-49869 (CVSS 10.0) β€” BOD 26-04 federal remediation deadline TODAY (Sep 5); unauthenticated RCE as rootCriticalAuthenticationFilter in Kestra OSS (workflow orchestration platform, widely used in AI/data pipelines) uses a suffix-match check (`endsWith("/configs")`) to whitelist the public config endpoint, allowing any path whose final segment is `/configs` to skip Basic Auth entirely. An unauthenticated attacker can create and execute arbitrary workflows and achieve RCE as root in the Kestra worker container. Affected: all versions through 1.3.20. Patched: 1.0.45 and 1.3.21. CISA added September 2 under BOD 26-04 with a 3-day FCEB deadline. FCEB organizations are required to patch today. CISA KEV Β· The Hacker News Β· AiCybr
Cisco Nexus 9000 CVE-2026-20212 (CVSS 9.8) β€” unauthenticated RCE as root; no workaround; affects Silicon One ASIC modelsCriticalTechnology & SoftwareA binding-to-unrestricted-IP vulnerability in Nexus 9000 series switches equipped with Cisco Silicon One ASIC allows an unauthenticated remote attacker to reach TCP ports 43210 and 43211 and execute code with root privileges. No workarounds; patch immediately. Advisory published September 2. Cisco PSIRT Β· The Hacker News Β· SC Media
Cisco IOS XR CVE-2026-20274 and CVE-2026-20279 (both CVSS 9.8) β€” buffer/memory issues and improper access control; 7-CVE hardening bundle released Sep 2HighTechnology & SoftwareCisco's September 2 IOS XR Security Hardening Release bundles seven CVEs across two underlying vulnerability classes. CVE-2026-20274 (CVSS 9.8) covers buffer/out-of-bounds writes and insecure default initialization; CVE-2026-20279 (CVSS 9.8) covers improper certificate validation and missing authentication for critical functions. No workarounds. Cisco Security Advisory Β· The Register
CISA Sep 2 KEV batch: 3 of 7 additions target AI/ML infrastructure β€” first KEV batch with AI components as near-majorityHighTechnology & SoftwareThe September 2 KEV batch marks a structural shift: CVE-2026-59822 (LiteLLM AI gateway, unauthenticated MCP session via arbitrary Bearer token, CVSS 8.8) and CVE-2026-48710 (Starlette/FastAPI ASGI framework underlying vLLM and LiteLLM, Host-header injection bypassing path-based auth middleware) both expose the AI-inference supply chain at the framework level. Organizations running self-hosted LLM inference pipelines should treat these as priority patches regardless of FCEB scope. CISA KEV Sep 2 Β· Yahoo/Forkast Β· P.K. Sharma
Upcoming BOD 26-04 compliance deadlines (federal) β€” Sep 9 remains the critical near-term dateMediumNetScaler/ADC CVE-2026-8452 (added Aug 26) federal deadline Sep 9; PaperCut NG/MF CVE-2026-81578 / CVE-2026-82078 federal deadline Sep 14; SonicWall SMA1000 and JFrog Artifactory trailing. Organizations outside federal scope should verify these are patched. CISA KEV Catalog

🚨 INTELLIGENCE AGENCY ALERTS & POLICY

Serbia: Citizen Lab confirms Pegasus zero-click exploit against 14 student activists and opposition politicians; iOS 18.4.1 patches the iMessage vectorHighGovernment & Public SectorCitizen Lab and SHARE Foundation confirmed September 3–4 that at least 14 people in Serbia have been targeted with Pegasus spyware and a new NoviSpy variant since early 2026, in the largest documented wave of state-adjacent surveillance against Serbian civil society on record. Targets include student-movement members, opposition MPs, and local councillors. The Pegasus delivery used a zero-click iMessage exploit; iOS 18.4.1, released in conjunction with the disclosure, patches the underlying vulnerability. Serbian intelligence (BIA) and President Vucic deny the allegations; the European Union stated the practice would be "unacceptable if confirmed." Citizen Lab attributes the tool to NSO Group. Citizen Lab / CyberScoop Β· The Cyber Express Β· Balkan Insight Β· TechTimes
No new CISA, FBI, or NSA advisories in the Sep 4–5 windowMediumGovernment & Public SectorWeekend cadence; latest active advisories are the CISA #StopRansomware: Medusa update (Aug 18–19, 500+ CI victims) and #StopRansomware: Gunra (AA26-222A). Both remain current.

🌐 THREAT ACTOR & CAMPAIGN ACTIVITY

Qilin β€” holds rank 1; YTD 546; pace unchanged at ~140 victims/monthCriticalGovernment & Public SectorNo new high-profile Qilin victims confirmed in the Sep 4–5 window beyond those already tracked. The ATF major-incident claim (Aug 26) remains under DOJ investigation. YTD: 546; L3M: 335. πŸŸ₯ The ATF claim is unverified. Ransomware.live
FulcrumSec β€” MAG data published Sep 4; credential-in-JavaScript MO is repeatable at scaleHighTransportation & LogisticsFulcrumSec's attack against Manchester Airports Group required no network intrusion: the group harvested Iterable API credentials from publicly accessible JavaScript code. This MO β€” harvesting keys from frontend JS or CDN-hosted bundles β€” requires no exploit, is undetectable by traditional network monitoring, and applies to any organisation whose marketing/analytics platform is configured with client-side credentials. FulcrumSec is now confirmed as a distinct extortion actor with at least one major publication. BleepingComputer Β· SecurityAffairs
Gunra ransomware β€” Blanco & Etcheverry, Occidental added to DLS Sep 4; CISA AA26-222A advisory activeHighGunra continues posting victims across Latin America (Uruguay, Venezuela). CISA-issued AA26-222A characterises Gunra as a double-extortion RaaS targeting law firms, financial services, and insurance. πŸŸ₯ DLS claims; unverified. CISA AA26-222A
Aurora β€” EDIF S.p.A. (Italy) claimed Sep 4MediumAurora posted the Italian wholesale-distribution firm with a broad dataset. πŸŸ₯ DLS claim; unverified. DeXpose

🌍 GEOPOLITICS

Analyst lens: how this week's cyber activity maps to state strategy. Defense Β· cyber Β· economics.
The FulcrumSec/MAG attack is the proof-of-concept that credential harvesting from public JavaScript is now a mass-scale extortion vector against large consumer-data platforms β€” no intrusion required, audit trails are minimal, and the liability is proportional to data volume, not attack sophistication.CriticalTransportation & LogisticsManchester Airports Group's Iterable API keys were embedded in publicly visible JavaScript β€” a configuration error that requires no exploit to weaponise, no network footprint to generate, and no EDR to evade. The result was 8.8 million records and the full extortion cycle in one operation. The attack pattern scales: any organisation with a marketing-automation or customer-data platform configured with client-side credentials is a structural equivalent target. For a PE portfolio holder, the risk is not in whether the company ran a secure network β€” it is in whether its customer-data platforms were audited for exposed credentials at the application layer. BleepingComputer Β· SecurityWeek
Three of seven CISA KEV additions targeting AI/ML infrastructure is a structural signal, not a coincidence β€” the exploit surface of AI deployment is now moving into the same production-vulnerability regime as the enterprise network stack.CriticalTechnology & SoftwareLiteLLM (AI gateway), Starlette/FastAPI (the ASGI framework underlying vLLM, LiteLLM, and most MCP server implementations), and Kestra (AI/data pipeline orchestrator) are all in the Sep 2 KEV batch. These are not edge components β€” they are the orchestration, inference, and integration layers that sit between enterprise applications and the large-language models they call. An unauthenticated attacker who compromises an LiteLLM gateway or Kestra orchestrator has a persistent observation point across every prompt and workflow the enterprise runs through that layer. The speed from disclosure to KEV listing (days, not weeks) confirms these vulnerabilities are being actively exploited, not just discovered. CISA KEV Sep 2 Β· Forkast
The confirmed Pegasus deployment against Serbian student protesters creates a direct precedent for European Union member-state concern and accelerates the push for binding EU spyware regulation β€” the political and legal risk to NSO Group is now European, not just Israeli.HighGovernment & Public SectorThe Serbia case follows the Predator/Pegasus findings against Greece, Hungary, Spain, and Poland β€” all EU member states β€” that have driven two years of European Parliament investigation. Serbia, though not an EU member, holds EU accession candidate status and is in active accession negotiations. The EU's "unacceptable if confirmed" statement is weaker than it sounds β€” it stops well short of sanctions or accession-pause β€” but the Citizen Lab confirmation means the evidentiary standard for stronger action is now met. The proximate risk for enterprise security teams: the same zero-click iMessage vector documented by Citizen Lab requires iOS 18.4.1 to patch; any unpatched iPhone in a high-risk-individual threat model (executive, journalist, board member) should be updated immediately. CyberScoop Β· TechTimes
The McKesson Sep 9 deadline β€” still 4 days out and unanswered publicly β€” is the clearest live test of whether US healthcare extortion has reached a scale where the payment calculus inverts: $55M may be less than the regulatory, litigation, and remediation cost of a 284M-record publication.HighHealthcare & Life SciencesThe vishing+Okta+Snowflake attack chain is now documented for McKesson. If data publishes on September 9 (or shortly after, given the initial deadline already passed), the breach notification volume, state AG actions, and civil litigation that follow will dwarf the ransom demand. If a private resolution is in progress β€” consistent with the current silence β€” it sets a $55M price floor for the next attacker targeting a major US healthcare distributor. Either outcome raises the structural ransomware-risk pricing for the entire healthcare supply chain. SecurityWeek Β· ExZec Cyber
Threat actors
1 Β· Qilin546 YTD
2 Β· The Gentlemen335 YTD
3 Β· Akira228 YTD
4 Β· DragonForce248 YTD
M&A activity
Socure β†’ Fravityβ€”
Brinqa β†’ PlexTracβ€”
Munich Re (via HSB) β†’ $575Mβ€”
Fortinet β†’ Virtue AIβ€”