TCSR Weekly Roundup: Chained Vulnerabilities, AI Session Hijacking, and Global Data Breaches
This week's security roundup covers critical PaperCut and WordPress flaws, AI session hijacking, and major breaches affecting healthcare and aviation.
Welcome to this week's TCSR roundup. As organizations navigate an increasingly complex threat landscape, keeping an eye on software vulnerabilities, emerging AI-related threats, and high-profile data breaches is essential. This week, we look at critical flaws in print management and CMS platforms, new session-hijacking techniques targeting AI tools, and a series of major organizational breaches.
Critical Flaws in PaperCut and WordPress Plugins
Recent disclosures highlight the ongoing risk of unpatched software components. Attackers are now chaining two separate PaperCut vulnerabilities to achieve remote code execution (RCE) without requiring authentication. Meanwhile, five critical flaws discovered in popular WordPress plugins and themes are allowing malicious actors to perform complete site takeovers and execute arbitrary code.
How TCSR helps: Regularly scanning your external attack surface for outdated software, known CVEs, and exposed management interfaces is critical to preventing these types of entry-point exploits.
AI Platforms Targeted by Hijacking and Resource Abuse
As artificial intelligence tools become integrated into daily workflows, they are increasingly targeted by threat actors. Anthropic has warned that info-stealing malware is actively hijacking active Claude sessions to drain usage limits. Concurrently, Anthropic is reducing Claude Code's weekly limits by 17%. In another AI infrastructure development, hundreds of OpenAI agents reportedly accessed Hugging Face servers in an uncoordinated influx, emphasizing the need for robust API and bot management. These evolving AI-related threats are driving a major surge in offensive security investments.
Public and Private Sectors Hit by Major Data Breaches
A wave of data breaches has impacted multiple industries this week. In the healthcare sector, McKesson disclosed a breach after the ShinyHunters group claimed to have stolen patient data. In aviation, FulcrumSec claimed responsibility for a hack on Manchester Airports, allegedly stealing 86 GB of data. Additionally, toy manufacturer Hasbro confirmed a breach exposing employee personal information, a US federal agency confirmed a compromise following ransomware group claims, and the city of Berlin publicly refused to pay ransom demands after hackers exfiltrated data from its state network.
Deceptive Tactics: Fake CAPTCHAs and Malicious Extensions
Malicious actors are employing sophisticated social engineering to bypass standard security boundaries. A campaign dubbed TerminalFix is using fake Cloudflare CAPTCHA prompts to trick users into executing commands that install a reverse-tunnel backdoor on their systems. Furthermore, several malicious extensions were discovered on the Chrome Web Store, designed to steal cryptocurrency and sensitive browser data directly from unsuspecting users.
Blockchain Exploits and Privacy Enhancements
In the decentralized space, a vulnerability in the Cosmos Ethereum Virtual Machine (EVM) was actively exploited. The exploit occurred after Cosmos Labs became aware that every blockchain running the EVM was susceptible to the flaw. On the defensive side, the Brave browser has introduced a new feature allowing users to generate email aliases, helping individuals protect their identities and evade online tracking.
What This Means for You
Modern threat actors are highly adept at finding the weakest links in your defense, whether through chained software vulnerabilities, third-party browser extensions, or social engineering tactics like fake CAPTCHAs. To protect your organization, ensure that all public-facing assets are continuously monitored. Keeping track of exposed files, verifying TLS configurations, and securing HTTP headers are foundational steps to reducing your digital footprint and keeping opportunistic attackers at bay.
Sources
- More Details Emerge on Exploited PaperCut Vulnerabilities — SecurityWeek
- ISC Stormcast For Monday, August 31st, 2026 https://isc.sans.edu/podcastdetail/10074, (Mon, Aug 31st) — SANS Internet Storm Center
- FulcrumSec claims Manchester Airports hack, theft of 86 GB of data — BleepingComputer
- Anthropic warns infostealer malware is hijacking Claude sessions to drain usage — BleepingComputer
- Chrome Web Store extensions caught stealing crypto, browser data — BleepingComputer
- TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor — The Hacker News
- YARA-X 1.20.0 Release, (Sun, Aug 30th) — SANS Internet Storm Center
- Anthropic is cutting Claude Code's current weekly limits by 17% — BleepingComputer
- Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE — The Hacker News
- Brave browser adds email aliases to help users evade tracking — BleepingComputer