# Threat Intel Brief — August 31, 2026
TL;DR
- Critical WordPress vulnerabilities disclosed in five popular plugins/themes enable authentication bypass and remote code execution; CVE-2026-76581 (CVSS 9.8) affects WPMU DEV Dashboard, while CVE-2026-82222 (CVSS 10.0) enables RCE in GiveWP via PHP object injection.
- TerminalFix campaign deploys reverse-tunnel backdoors via fake Cloudflare CAPTCHAs, tricking users into executing multi-line PowerShell scripts that establish persistent network access and Active Directory reconnaissance capabilities.
- Browser extension supply chain attack compromised 19 Chrome/Edge extensions (70,000+ Chrome users affected) to steal cryptocurrency wallets, credentials, and deploy ClickFix social engineering lures.
- FulcrumSec extortion group claims theft of 86 GB from Manchester Airports Group affecting 8.7 million customers; breach exploited exposed API credentials in client-side JavaScript.
- Three critical CERT.BE advisories urge immediate patching of WatchGuard Fireware OS, PaperCut, and ServiceNow platforms; specific CVE details not yet publicly disclosed.
Critical Threats
WordPress Plugin and Theme Vulnerabilities Enable Complete Site Takeover
What happened: Security researchers disclosed five critical vulnerabilities in widely deployed WordPress plugins and themes. CVE-2026-76581 (CVSS 9.8) in WPMU DEV Dashboard ≤5.0.1 enables authentication bypass on sites with Hub SSO enabled. CVE-2026-18431 in Avada theme ≤7.16 with Fusion Builder ≤3.16 permits arbitrary PHP file upload and execution. CVE-2026-19632 in TranslatePress ≤3.3.1 exposes password reset tokens for admin takeover. CVE-2026-19598 in Pods ≤3.3.9 allows privilege escalation to administrator. CVE-2026-82222 (CVSS 10.0) in GiveWP ≤4.16.7.1 enables remote code execution via PHP object injection on sites with active donation forms.
Impact: All five vulnerabilities allow unauthenticated attackers to achieve complete site compromise. Given the significant install base of these plugins across the WordPress ecosystem, hundreds of thousands of sites are potentially vulnerable. Successful exploitation enables attackers to steal customer data, inject malicious content, deploy webshells, pivot to internal networks, or use compromised sites for malware distribution and phishing campaigns.
Recommendations:
- Immediate (0-24h): Update WPMU DEV Dashboard to >5.0.1, Avada theme to >7.16 and Fusion Builder to >3.16, TranslatePress to >3.3.1, Pods to >3.3.9, and GiveWP to >4.16.7.1. Audit administrator accounts for unauthorized access and review WordPress admin activity logs for suspicious logins.
- 24-72h: Scan web servers for unauthorized PHP files in wp-content/uploads and theme directories. Review web server access logs for POST requests to vulnerable plugin endpoints. For GiveWP sites, examine donation form submissions for anomalous serialized data and scan for webshells.
- This week: Deploy WordPress firewall rules blocking unauthenticated access to vulnerable plugin endpoints. Implement file integrity monitoring for WordPress core and plugin directories.
TerminalFix Campaign Deploys Reverse-Tunnel Backdoors
What happened: Microsoft Threat Intelligence disclosed an active campaign using fake Cloudflare CAPTCHA pages on compromised websites to trick users into executing malicious PowerShell commands. Unlike traditional ClickFix attacks, TerminalFix directs victims to Windows Terminal or PowerShell to execute complex multi-line scripts. The attack chain uses DLL sideloading (LockScreenContentServer.exe loading malicious dui70.dll), steganographic payload concealment in PNG images, and deploys a Python-based reverse WebSocket tunnel providing SOCKS-style TCP proxy access to internal networks.
Impact: Compromised hosts become network pivot points enabling attackers to proxy arbitrary TCP traffic, perform extensive Active Directory reconnaissance (domain trusts, admin enumeration, user/computer searches), and reach internal systems. The reverse-tunnel capability creates pathways for privilege escalation, security control bypass, data exfiltration, and ransomware deployment. The campaign's AD-focused reconnaissance indicates intent to exploit enterprise network access for lateral movement and credential theft.
Recommendations:
- Immediate (0-24h): Enable PowerShell script block logging (Event ID 4104) and monitor for obfuscated or encoded commands. Block known malicious domains: bestsocialmedianewspapper[.]com, offlineupdater[.]com, gitnow[.]dev.
- 24-72h: Restrict PowerShell and Windows Run dialog execution for standard users via AppLocker or Application Control for Windows. Monitor for DLL sideloading indicators, specifically LockScreenContentServer.exe loading suspicious dui70.dll from C:\ProgramData.
- This week: Train users to recognize fake CAPTCHA prompts requesting PowerShell command execution. Monitor for unusual outbound WebSocket connections to port 443 and Python-based processes establishing reverse tunnels from workstations.
Malicious Browser Extensions Steal Cryptocurrency and Credentials
What happened: Security researchers identified 19 malicious Chrome and Edge extensions that deployed a modular malware framework via updates after legitimate extensions were acquired or compromised. The campaign, active since early 2024, affected over 70,000 Chrome users and 10,000 Edge users. The malware steals credentials across all websites, drains cryptocurrency wallets (EVM, Solana, Tron), hijacks sessions on major exchanges (Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit), and injects ClickFix social engineering attacks. The framework uses encrypted WebSocket command-and-control, removes Content Security Policy headers, and injects scripts into all visited sites.
Impact: Users with installed extensions face complete credential compromise, cryptocurrency wallet draining, and session hijacking on financial platforms. The modular framework is extensible, suggesting additional payloads may be deployed. Organizations must audit browser extensions, force password resets for affected users, and monitor for lateral movement from compromised credentials.
Recommendations:
- Immediate (0-24h): Audit all Chrome and Edge browser extensions against published lists of malicious extension IDs; uninstall matches and quarantine affected endpoints. Force password resets for users who had malicious extensions installed, prioritizing cryptocurrency exchange accounts and corporate SSO credentials.
- 24-72h: Review authentication logs and SIEM for anomalous logins from affected user accounts since early 2024. Block published C2 domains at perimeter firewalls and DNS filtering; monitor for WebSocket connections to unknown external hosts from browser processes.
- This week: Implement browser extension allowlisting via Group Policy (Chrome) or Intune (Edge) to prevent installation of unapproved extensions. Educate users on risks of third-party extensions.
Critical Vulnerabilities in Enterprise Platforms Require Urgent Patching
What happened: CERT.BE issued three urgent advisories warning of critical vulnerabilities in WatchGuard Fireware OS, PaperCut print management software, and ServiceNow platforms. Specific CVE identifiers and technical details have not been publicly disclosed in available advisories, but the urgency of the warnings suggests high exploitability or potential active targeting.
Impact: WatchGuard firewalls are widely deployed network perimeter devices; compromise can enable lateral movement, traffic interception, and complete network breach. PaperCut is extensively used in enterprise and education sectors for print management. ServiceNow platforms handle IT service management, security operations, and business workflows across major organizations. Critical vulnerabilities in these platforms could enable unauthorized access, data exposure, or service disruption.
Recommendations:
- Immediate (0-24h): Check vendor security bulletins for WatchGuard (watchguard.com/support/security-advisories), PaperCut (papercut.com/kb/Main/Security-Bulletins), and ServiceNow (HI portal and Now Support) for specific CVE details and patch availability. Inventory all instances and current patch levels.
- 24-72h: Apply vendor-provided patches immediately for all identified instances, prioritizing internet-facing and production systems. Review application logs and network traffic for suspicious authentication attempts or unusual activity.
- This week: If immediate patching is not possible, implement network segmentation to isolate vulnerable systems from untrusted networks. Restrict management interface access to trusted networks only until patching is complete.
Threat Actor Activity
FulcrumSec Data Extortion Campaign
FulcrumSec, a financially motivated data-extortion group active since 2025, claims to have stolen 86 GB of data from Manchester Airports Group (MAG), the UK's largest airport operator. BleepingComputer validated the breach, confirming stolen data includes detailed customer information, booking records, and travel details affecting approximately 8.7 million customers across Manchester, London Stansted, and East Midlands airports.
The group gained initial access through exposed Iterable API credentials found in client-side JavaScript code on MAG websites. Unlike ransomware operators, FulcrumSec specializes in data theft and extortion through threatened publication rather than encryption. MAG reportedly refused to pay the ransom demand. The group has previously targeted LexisNexis, Novo Nordisk, Global Schools Group, and Avnet, demonstrating a pattern of opportunistic attacks against organizations with valuable customer databases.
Defensive focus: Organizations should implement automated scanning for exposed API credentials and secrets in client-side JavaScript and publicly accessible code repositories. Deploy API gateway monitoring with rate limiting and anomalous data access detection to identify bulk data exfiltration attempts. Enforce principle of least privilege for API credentials, ensuring customer-facing applications use read-only tokens with minimal scope and short expiration windows.
Anthropic Claude Session Hijacking via Infostealers
Anthropic warned that infostealer malware on compromised PCs is stealing active Claude login sessions, enabling attackers to access accounts and consume user API quotas and usage credits. This represents an evolution of credential theft targeting AI platform access, where attackers leverage stolen session tokens to abuse cloud-based AI services at victim expense.
Geopolitical Context
UK Critical Infrastructure Targeting
The Manchester Airports Group breach represents the largest known customer data breach affecting a British airport operator. The incident demonstrates the vulnerability of civilian aviation infrastructure to non-state cybercriminal actors and will likely prompt regulatory scrutiny from the UK Information Commissioner's Office under UK GDPR provisions. The exposure of granular travel data—including booking references, vehicle registrations, and UK postcodes—creates downstream risks for affected customers and may accelerate policy discussions regarding mandatory security standards for critical infrastructure operators, particularly concerning API security and credential management.
European Network Security Coordination
CERT.BE's urgent advisories on WatchGuard, PaperCut, and ServiceNow vulnerabilities reflect Belgium's role as a key NATO and EU institutional hub, where network security infrastructure protection is paramount. Belgium hosts NATO headquarters and EU institutions, making its network infrastructure a persistent target for espionage operations. The emphasis on urgent remediation may indicate awareness of active exploitation or credible threat intelligence. The advisories will likely prompt coordinated responses from other EU member state CERTs and ENISA (European Union Agency for Cybersecurity).
Recommended Actions
Immediate (0-24 hours)
1. Update vulnerable WordPress plugins/themes: WPMU DEV Dashboard, Avada/Fusion Builder, TranslatePress, Pods, and GiveWP to latest versions 2. Audit all Chrome and Edge browser extensions; remove any matching published malicious extension lists 3. Check WatchGuard, PaperCut, and ServiceNow vendor security bulletins for patch availability and apply immediately 4. Enable PowerShell script block logging and monitor for obfuscated commands 5. Block TerminalFix campaign domains: bestsocialmedianewspapper[.]com, offlineupdater[.]com, gitnow[.]devWithin 24-72 hours
1. Force password resets for users affected by malicious browser extensions, prioritizing cryptocurrency and SSO accounts 2. Scan web servers for unauthorized PHP files in WordPress installations 3. Review authentication logs for anomalous logins from affected accounts since early 2024 4. Implement API gateway monitoring with rate limiting and anomalous data access detection 5. Restrict PowerShell execution for standard users via AppLocker or Application ControlThis week
1. Deploy WordPress firewall rules blocking unauthenticated access to vulnerable plugin endpoints 2. Implement browser extension allowlisting via Group Policy or Intune 3. Train users to recognize fake CAPTCHA prompts requesting PowerShell command execution 4. Scan for exposed API credentials in client-side JavaScript and public code repositories 5. Monitor for DLL sideloading indicators and unusual WebSocket connections from workstationsWatch List
- WordPress ecosystem: Monitor for proof-of-concept exploits targeting CVE-2026-76581, CVE-2026-18431, CVE-2026-19632, CVE-2026-19598, and CVE-2026-82222; expect exploitation attempts within days of PoC publication
- TerminalFix evolution: Watch for additional fake CAPTCHA campaigns and variants targeting other platforms beyond Windows Terminal/PowerShell
- Browser extension supply chain: Anticipate additional malicious extension discoveries as researchers audit Chrome Web Store and Edge add-ons store
- FulcrumSec data publication: Monitor for potential release of Manchester Airports Group data and copycat attacks targeting aviation sector API credentials
- Enterprise platform CVEs: Watch for public disclosure of specific CVE identifiers for WatchGuard, PaperCut, and ServiceNow vulnerabilities referenced in CERT.BE advisories
Sources
- BleepingComputer: FulcrumSec claims Manchester Airports hack, theft of 86 GB of data — https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/
- BleepingComputer: Anthropic warns infostealer malware is hijacking Claude sessions to drain usage — https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/
- BleepingComputer: Chrome Web Store extensions caught stealing crypto, browser data — https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/
- The Hacker News: TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor — https://thehackernews.com/2026/08/terminalfix-uses-fake-cloudflare.html
- The Hacker News: Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE — https://thehackernews.com/2026/08/five-critical-wordpress-plugin-and.html
- Microsoft Security: TerminalFix campaign deploys a reverse tunnel through multistage intrusion — https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/
- CERT.BE (Belgium): Warning: Multiple Vulnerabilities in WatchGuard Fireware OS, Patch Immediately! — https://ccb.belgium.be/advisories/warning-multiple-vulnerabilities-watchguard-fireware-os-patch-immediately
- CERT.BE (Belgium): Warning: Critical and High vulnerability in PaperCut, Patch Immediately! — https://ccb.belgium.be/advisories/warning-critical-and-high-vulnerability-papercut-patch-immediately
- CERT.BE (Belgium): Warning: Critical Vulnerabilities in ServiceNow platforms, Patch Immediately! — https://ccb.belgium.be/advisories/warning-critical-vulnerabilities-servicenow-platforms-patch-immediately
