Compiled from 52 monitored sources · 62 articles reviewed
Today’s Briefing
Extortion group FulcrumSec claims it stole 86GB from Manchester Airports Group after finding API credentials exposed in client-side JavaScript, affecting customers of Manchester, London Stansted, and East Midlands airports. Apache released patches for four critical-severity vulnerabilities in Tomcat.CVE-2026-68525, CVE-2026-65905, CVE-2026-65637, and CVE-2026-65182.covering authentication bypass, authorisation bypass, and incomplete remediation of an earlier input validation flaw across versions 9.0, 10.1, and 11.0. Google patched two critical out-of-bounds write flaws in Chrome's ANGLE component, CVE-2026-79189 and CVE-2026-79188, both rated high severity for potential remote code execution outside the sandbox.
Top Stories
- Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft
- What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree
- Halo-record: Open-source audit trails for AI agents
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.