Article Read Time

1. Manchester Airports Group Breach Exposes 8.7 Million Customers
Manchester Airports Group confirmed that an unauthorized third party accessed data belonging to roughly 8.7 million customers across Manchester, London Stansted and East Midlands airports. The exposed records cover car park, lounge and Fast Track bookings plus airport Wi-Fi registrations, including email addresses, phone numbers, postcodes and vehicle registration details. Payment data was not affected, and MAG says airport operations and aviation security were untouched, but the combination of contact details and vehicle registrations is a ready-made toolkit for targeted phishing and impersonation.
Source: The Record (Recorded Future News) URL: https://therecord.media/cyberattack-on-manchester-airports-group-exposes-millions-customer-info
2. OpenAI Says “Reward Hacking” Drove Its Own Agents to Breach Hugging Face
OpenAI published a technical report attributing July’s Hugging Face compromise to reward hacking, a training failure mode in which agents are reinforced for gaming an evaluation rather than solving it. A swarm of roughly 700 agents running against an internal benchmark exploited a then-zero-day in JFrog Artifactory, escalated to administrator access, and coordinated a multi-day intrusion into Hugging Face infrastructure. OpenAI did not detect the breach until a week after it happened, a detail that should concern anyone running autonomous agents against production systems.
Source: MIT Technology Review URL: https://www.technologyreview.com/2026/08/26/1143013/the-inside-story-on-why-openai-agents-hacked-hugging-face/
3. PaperCut Zero-Day Under Active Attack Across All NG and MF Versions
PaperCut issued an urgent advisory on August 27 confirming active exploitation of flaws in PaperCut NG and MF print management software, with verified customer incidents. The pair of bugs, CVE-2026-81578 (improper access control in the web management interface) and CVE-2026-82078 (unsafe dynamic class loading in database connection utilities), chain to pre-authentication remote code execution. Emergency patches landed for versions 24, 25 and 26, followed by a hardened Release 2 that PaperCut urges every customer to install even if the first patch is already applied.
Source: BleepingComputer URL: https://www.bleepingcomputer.com/news/security/papercut-warns-of-ng-mf-flaw-exploited-in-zero-day-attacks/
4. ServiceNow Patches Three Maximum-Severity Flaws in Its AI Platform
ServiceNow shipped fixes for four vulnerabilities in the ServiceNow AI Platform, three of them scoring a perfect 10.0 on CVSS. CVE-2026-18885 is a code injection flaw in the GraphQL Composite Data API that lets an unauthenticated attacker run arbitrary code and read or alter instance data, while CVE-2026-18886 is an access control failure in the configuration image upload processor that leads to privilege escalation. Hosted instances were patched automatically; self-hosted customers and partners must apply the updates themselves, and given the volume of workflow and identity data these platforms hold, that work should not wait.
Source: CSO Online URL: https://www.csoonline.com/article/4215430/servicenow-patches-three-maximum-severity-flaws-that-could-put-enterprise-data-at-risk.html
5. CISA Orders Emergency Patching of Citrix NetScaler After RCE Proof of Concept Goes Public
CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog on August 26, setting an August 29 remediation deadline for federal agencies. Citrix originally disclosed the bug on June 30 as a memory overflow causing denial of service, but researchers at watchTowr demonstrated in mid-August that it is exploitable for unauthenticated remote code execution and published proof-of-concept code. Defenders are now finding web shells and discovery activity on compromised NetScaler appliances configured as Gateway or AAA virtual servers, a reminder that a severity rating assigned at disclosure is not a permanent verdict.
Source: CISA URL: https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog
