← All issues
cybersecurityCyberBubblesupply-chain

Poisoned Software, Fake CAPTCHAs, and a City That Won't Pay

🌐  World Intel
Germany: Berlin refuses to pay hackers — but 5.79 TB may already be gone

Berlin's state government confirmed this week that hackers broke into its administrative network between August 7 and 14, stealing data from the Senate Department for Mobility, Transport, Climate Protection and Environment. The attackers posted a leak site entry on August 28 claiming they took 5.79 terabytes of data — roughly 1.5 million novels' worth of text. Berlin says it will not pay the ransom, and is still figuring out exactly what personal information was taken.

↗ The Hacker News
Australia: Two men arrested for the longest software supply chain attack spree ever

Australian federal police arrested two men from Western Australia — aged 21 and 23 — accused of running TeamPCP, a cybercrime group that spent nearly a year hiding malicious code inside popular open-source software tools. Their self-replicating worm, called Shai-Hulud, infected developers' computers, stole their login credentials, then used those credentials to poison even more software projects — a vicious cycle that compromised thousands of companies worldwide. One attack alone, targeting the AI tool LiteLLM, harvested cloud keys from more than 2,500 organizations including major tech firms.

↗ Krebs on Security
UK: Manchester Airports Group confirms hackers stole travelers' data

A data extortion group called FulcrumSec claims it stole 86 GB of data from Manchester Airports Group, which operates Manchester, London Stansted, and East Midlands airports. BleepingComputer independently confirmed at least one real traveler's record was in the stolen data, and the samples reportedly contain detailed booking, travel, and customer information — more than the airports initially admitted. If you've traveled through any of these airports, your personal details may be at risk.

↗ BleepingComputer
⚔️  Active Attacks
TerminalFix: Fake "prove you're human" boxes that install backdoors

Microsoft has spotted a new scam called TerminalFix targeting everyday website visitors. You land on a compromised site, and a fake CAPTCHA box pops up pretending to be a Cloudflare security check. It tells you to press a key combination, then paste a command into PowerShell. If you do, you've just installed a backdoor that gives attackers full remote access to your machine. This is an evolved version of a trick called ClickFix — and it's getting more sophisticated because PowerShell can run longer, more complex malicious scripts than older methods.

🛡 What to do: Never copy and paste commands into PowerShell or Terminal from a website — no legitimate CAPTCHA will ever ask you to do this. Close the tab immediately if you see such a prompt.
Chrome and Edge extensions caught secretly stealing your crypto and passwords

Researchers found multiple extensions for Google Chrome and Microsoft Edge — software add-ons you install to improve your browser — that were secretly running a malware framework in the background. The extensions stole cryptocurrency, saved passwords, and browsing history, and also pushed fake CAPTCHA popups (the ClickFix trick above) at users. The malicious extensions were available in the official stores before being caught.

🛡 What to do: Go to your browser's extensions page right now and remove any you don't recognize or no longer use. Only install extensions from developers you trust, and check user reviews before adding anything new.
🔓  New Vulnerabilities
CVE-2026-76581 WPMU DEV Dashboard (WordPress Plugin) CRITICAL 9.8

This flaw lets a complete stranger — no password needed — waltz into a WordPress website as an administrator and take it over entirely. It affects sites using the WPMU DEV Dashboard plugin with a feature called Hub Single Sign-On turned on. An attacker who knows your site uses this setup can bypass the login page and gain full control — deleting content, stealing user data, or installing more malware.

Status: Update to version 5.0.2 or later immediately. If you run a WordPress site with this plugin, this is urgent.

CVE-2026-18431 Avada Theme (WordPress) CRITICAL 9.8

Avada is one of the most popular WordPress themes in the world — and it has a serious hole. An attacker who has never visited your site before can write any file they want directly onto your web server, then run it as code. Think of it like a stranger being able to slip a note under your front door that your house then automatically reads aloud and acts on. This can lead to full server compromise.

Status: A patch is available. If your website uses the Avada theme, update it right away through your WordPress dashboard.

PaperCut NG/MF PaperCut Print Management Software CRITICAL — Actively Exploited

PaperCut is software used by offices, schools, and universities to manage printers. Attackers found two flaws they can chain together — meaning they use one bug to unlock a second, worse bug — to run any code they want on a PaperCut server without logging in at all. Hackers are actively exploiting this right now. PaperCut had to issue a second emergency patch this week after researchers found ways to bypass the first fix.

Status: Second emergency patch now available. IT teams running PaperCut should apply the latest update immediately — the first patch alone is not enough.

GHSA-7g4w-cg88-2cq2 Cosmos EVM (Blockchain Module) CRITICAL — Funds Drained

A flaw in a shared code module used by multiple blockchain networks let attackers manipulate account balances — essentially creating money from thin air or draining others' funds. Six separate blockchains were hit between August 20–25. The troubling part: Cosmos Labs knew about the flaw since April but believed it posed no real risk. They were wrong. A fix had shipped just one day before the attacks began.

Status: Patch available in v0.6.2 and v0.7.2. Blockchain operators who can't upgrade immediately are advised to halt their chain entirely.

🛠  New Tech
Android 17 adds ECH — making it harder for your internet provider to spy on your browsing

Google's upcoming Android 17 will support a technology called ECH (Encrypted Client Hello). Right now, even when you visit an HTTPS website, your internet service provider can still see which site you're connecting to — it's like sealing a letter but writing the destination on the outside of the envelope. ECH encrypts that destination too, so your ISP sees only that you're connecting somewhere, not where. This is a meaningful privacy upgrade for everyday Android users and requires no action on your part — it'll arrive with the Android 17 update.

Brave browser 1.94: Disposable email addresses built right in

The privacy-focused Brave browser released version 1.94 with a new feature called Email Aliases. When you sign up for a new app or website, Brave can generate a throwaway email address that forwards to your real inbox — so the site never learns your actual email. This protects you from spam and makes it much harder for companies to track you across different services. If the alias starts getting spam, you delete it and create a new one. No third-party service needed — it's built directly into the browser.

💡  Deep Dive
How Two Australians Poisoned the World's Software Supply Chain — And Got Caught

Imagine a criminal who breaks into a bakery and poisons the flour — not to hurt that bakery specifically, but knowing the flour will be sold to hundreds of other bakeries who will unknowingly bake it into bread for thousands of customers. That's essentially what TeamPCP did, except the flour was open-source software used by developers worldwide, and the poison was malware. This week, Australian police arrested the two men allegedly at the center of it all.

TeamPCP appeared in late 2025 with a simple but devastating playbook. They targeted software developers — people who build the apps and tools the rest of us rely on every day. First, they phished or stole developers' login credentials for code-sharing platforms like GitHub and NPM. Then they used those credentials to sneak malicious code into legitimate, trusted software packages. Any developer who downloaded that package got infected. The malware then stole that developer's credentials too — and the cycle repeated, growing larger with every turn. Their worm, Shai-Hulud, was designed to self-propagate through developer communities like wildfire through dry brush.

The scale is staggering. One attack on an AI tool called LiteLLM compromised cloud credentials from over 2,500 organizations including some of the world's biggest tech companies. TeamPCP also reportedly breached over 3,800 code repositories at GitHub after a single GitHub employee installed a compromised code extension. To grow faster, the group even ran a public hacking contest — offering $1,000 in Monero to whoever could poison the most widely-downloaded software packages, treating it as a talent recruitment drive.

The arrests came after investigators — aided by security researchers who noticed the group's leader carelessly linking his real-world identity to his hacker persona on social media — tracked the operation to two men in Western Australia. It's a reminder that even sophisticated cybercriminals make simple mistakes. For the rest of us, the takeaway is sobering: the software you use every day is built on a chain of trust that criminals are actively trying to corrupt. Keeping software updated and using tools from reputable, well-monitored sources has never mattered more.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →