Skip to content

Sam's News — security — 2026-08-30

Security

8 Chinese operator exploits 3-year-old ownCloud vulnerability to steal Philippine nuclear data

A Chinese threat actor has exploited a three-year-old ownCloud flaw to steal sensitive Philippine nuclear data.

Sources: Pasquale Pillitteri RSS

7.5 Chrome and Edge extensions deploy cryptocurrency and data-stealing malware framework

Multiple browser extensions for Chrome and Edge delivered a malware framework that stole cryptocurrency, sensitive data, and browser history while injecting ClickFix phishing lures.

  • 18 Chrome extensions, 1 Edge extension identified stealing wallet credentials
  • 14 extensions created by threat actor, 5 purchased from previous owners
  • Campaign activity dates back to February 2024; distributed via Chrome Web Store
  • Threat actor created fake websites impersonating crypto utilities, VPNs, and banking services

Sources: BleepingComputer RSS Update to: 19 Chrome and Edge browser extensions found stealing cryptocurrency and wallet secrets

7 TerminalFix malware uses fake Cloudflare CAPTCHAs to deploy reverse-tunnel backdoor

Microsoft disclosed TerminalFix, a ClickFix malware variant that deceives users into executing malicious PowerShell commands via fake Cloudflare CAPTCHA pages. The attack deploys a reverse-tunnel backdoor that grants attackers persistent network access to reach internal systems and conduct reconnaissance, lateral movement, and data exfiltration.

  • Malicious command runs LockScreenContentServer.exe and loads rogue dui70.dll via DLL sideloading
  • PNG-embedded payloads retrieved from bestsocialmedianewspapper[.]com or offlineupdater[.]com
  • Python reverse-tunnel C2 (client.py) tunnels traffic to gitnow[.]dev:443 via encrypted WebSocket
  • Establishes persistence via Registry Run keys and scheduled tasks
  • Performs domain reconnaissance, admin enumeration, and network topology mapping
  • Enables C2 server to proxy traffic to internal systems accessible from victim network

Sources: The Hacker News AI Web Searched

7 Infostealer malware hijacks Claude sessions to drain account usage

An infostealer malware stole Claude user login sessions, prompting Anthropic to wipe affected users' saved payment cards.

Sources: BleepingComputer RSS, Pasquale Pillitteri RSS

6.5 Tixel Ticket Resale Platform Hit by Metabase Zero-Day Data Breach

Ticket resale platform Tixel warned users of a data breach resulting from a Metabase zero-day vulnerability.

Sources: SMBtech RSS

6.5 FulcrumSec claims 86 GB data theft from Manchester Airports Group

Threat actor FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group, including detailed customer and booking information.

Sources: BleepingComputer RSS

AI

4 Anthropic Increases Claude Code Weekly Limits by 25%, Despite Framing as Cut

Anthropic permanently increases Claude Code's weekly usage limits by 25% for Pro, Max, Team, and Enterprise plans, though initial messaging framed it differently.

Sources: BleepingComputer RSS