rootpwn

Threat Intel

RootPwn Weekly: Airport Breach, ATF, Boston Scientific, McKesson, AI Threats, and Critical Vulnerabilities

This week’s intel reveals a massive data leak at Manchester Airports Group affecting 8.7 million passengers, a compromised ATF system, and network outages at Boston Scientific. McKesson’s 284 million‑record breach stemmed from vishing‑driven Okta takeovers. AI researchers exposed new injection techniques and a phishing‑as‑a‑service platform. Meanwhile, PaperCut, Ubiquiti, Vercel, and ServiceNow rolled out emergency fixes for CVSS 10 zero‑day flaws that could grant remote code execution.

RootPwn’s latest Threat Intelligence Bulletin brings you the week’s most critical cyber events and vulnerability alerts.

Top Attacks & Breaches

  • Manchester Airports Group – A breach exposed personal data for 8.7 million customers, including contact info, vehicle registration numbers, and details from car‑park, lounge, fast‑track, and Wi‑Fi registrations.
  • U.S. ATF – A single compromised computer housed investigation data. The agency disconnected the system after the breach; Qilin ransomware claimed responsibility and listed the target on its leak site.
  • Boston Scientific – A cyberattack triggered widespread network outages, disrupting order‑processing and shipping services worldwide. Systems began restoration on August 26.
  • McKesson – ShinyHunters used vishing to hijack Okta accounts, then accessed Salesforce and Snowflake, exfiltrating ~1 TB of data containing 284 million patient records.

AI Threats

  • Cryptographic Context Injection – Researchers demonstrated how malicious code can hide inside encrypted content, tricking AI assistants with browsing or coding capabilities into leaking user data or bypassing safety controls.
  • Amazon Kiro Prompt Injection – A crafted project file can manipulate the AI agent, exposing local data. Amazon patched the flaw in version 0.8.140.
  • AnonyMousKIT – An AI‑driven phishing‑as‑a‑service platform targets stolen iPhones, using email, SMS, WhatsApp, and synthetic voice calls to steal Apple IDs, passcodes, and 2FA tokens, enabling Activation Lock removal.

Vulnerabilities & Patches

  • PaperCut NG & MF – CVE‑2026‑81578 (auth bypass, CVSS 8.8) and CVE‑2026‑82078 (unsafe class loading, CVSS 9.4) allow unauthenticated remote code execution when chained.
  • Ubiquiti UniFi – 21 critical/high flaws, including authentication bypass, command injection, and privilege escalation (several CVSS 10.0). Full patch set released.
  • Vercel Next.js – CVE‑2026‑75604 (Windows path traversal) and a libheif AVIF image‑processing flaw can lead to unauthenticated RCE. Fixed in Next.js 15.5.24 and 16.3.3.
  • ServiceNow AI Platform – Three CVE‑2026‑18885, ‑18886, and ‑74820 (code injection, access control, SQL injection) all rated CVSS 10.0. Patches applied.

Data Breach AI Threats Zero-Day Vulnerabilities

← All news