# Archive
Browse past daily curated stories
Monday, August 31, 2026
-
1BleepingComputer generalChrome Web Store extensions caught stealing crypto, browser data
Multiple Chrome and Edge extensions were found delivering a coordinated malware framework capable of stealing cryptocurrency, browser history, and sensitive data, while also injecting ClickFix lures into victims' browsers. The campaign affected users of both Google Chrome and Microsoft Edge, representing a significant supply-chain-style threat through the browser extension ecosystem. Security teams should audit installed extensions and treat any prompting ClickFix-style copy-paste commands as a high-confidence indicator of compromise.
-
2The Hacker News generalTerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Microsoft disclosed details of TerminalFix, a new ClickFix variant that directs victims to execute malicious commands in Windows Terminal or PowerShell rather than the traditional Run dialog, deploying a reverse-tunnel backdoor via fake Cloudflare CAPTCHA pages. The shift to Terminal/PowerShell increases attack sophistication and likelihood of success against technical users who may not recognize the lure. Defenders should monitor for unexpected PowerShell or Windows Terminal invocations spawned from browser processes.
-
3The Hacker News generalFive Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Critical vulnerabilities were disclosed across five widely-used WordPress plugins and themes — WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP — with flaws including CVE-2026-76581 (CVSS 9.8), an authentication bypass enabling full site takeover, as well as additional RCE vulnerabilities reported by Wordfence and Patchstack. These flaws collectively put millions of WordPress installations at risk of unauthenticated account takeover and arbitrary code execution. WordPress administrators should apply available patches immediately and audit for signs of exploitation.
-
4BleepingComputer generalAnthropic warns infostealer malware is hijacking Claude sessions to drain usage
Anthropic warned Claude users that infostealer malware on victim machines is harvesting active Claude session tokens, allowing attackers to hijack authenticated sessions and drain paid usage allocations without needing credentials. This attack vector bypasses MFA by targeting session cookies post-authentication, a technique commonly associated with stealers like Lumma and Redline. Claude users on shared or less-secured endpoints should rotate sessions and review active login activity.
-
5BleepingComputer generalFulcrumSec claims Manchester Airports hack, theft of 86 GB of data
Threat actor FulcrumSec claims to have exfiltrated 86 GB of data from Manchester Airports Group (MAG), with BleepingComputer independently verifying at least one traveler's record from the leaked samples. The exposed data reportedly includes detailed customer, booking, and travel information that exceeds what MAG publicly disclosed in its breach notification. The verification of a real traveler record substantiates the breach claim and suggests MAG's disclosure may be incomplete.
-
6SecurityWeek generalHasbro Data Breach Exposed Employee Personal Information
Hasbro disclosed a data breach stemming from a cyberattack earlier in 2026 that exposed personal information belonging to employees. The breach follows an initial disruption period during which Hasbro did not publicly confirm data exfiltration, a pattern consistent with ransomware or targeted intrusion campaigns targeting HR and corporate data. Affected employees should monitor for identity theft and phishing using the exposed personal data.
-
7Ars Technica Security generalI asked 100 companies for my data. Some deleted it instead.
A privacy audit of 100 companies found that submitting data access or deletion requests — rights guaranteed under laws like GDPR and CCPA — frequently resulted in confusion, non-responses, or unintended deletion of accounts rather than data. The investigation exposes widespread non-compliance and operational failures in privacy request handling across industries. Security and compliance teams should treat data subject request workflows as a concrete audit target, not just a legal checkbox.
-
8BleepingComputer generalBrave browser adds email aliases to help users evade tracking
Brave browser version 1.94 introduces a built-in 'Email Aliases' feature allowing users to generate disposable email addresses at signup, reducing tracking and exposure of real email addresses to third parties. The feature is integrated natively into the browser, removing the need for third-party alias services like SimpleLogin or AnonAddy. This is a meaningful privacy enhancement for users concerned about email-based tracking and credential exposure in data breaches.
-
9Ars Technica Security generalA 12TB Steam “teraleak” spills more than a decade of lost PC gaming history
A 12TB leak of Valve internal data, referred to as a 'teraleak,' surfaced publicly and contains over a decade of unreleased or cut game content including material from Portal 2 and apparent references to a never-released Half-Life 2: Episode 3. While primarily a gaming history story, the scale of the leak raises questions about Valve's internal data security practices and source code/IP protection for a major software platform operator. Security practitioners at game studios and software companies should treat this as a case study in insider threat and long-term data retention risk.
-
10BleepingComputer generalAnthropic is cutting Claude Code's current weekly limits by 17%
Anthropic announced changes to Claude Code's weekly usage limits, framing a 25% increase to standard limits while simultaneously reducing previously elevated current limits by 17% — a net reduction for existing heavy users on Pro, Max, Team, and Enterprise plans. While not a security vulnerability, the change affects security researchers and developers relying on Claude Code for automated analysis or tooling workflows. The adjustment reflects ongoing capacity management challenges as AI coding assistant adoption scales.