Connect with us

CyberSecurity

Microsoft Cloud Patches, 5,000 Hacked Dropbox Accounts, and a $1.1B Security Startup: What You Missed

Published

on

Microsoft cloud patches

The Week’s Under-the-Radar Security Stories

Some stories don’t get the headline treatment they deserve. They still matter, though. This week’s quiet-but-significant batch includes a wave of cloud patches from Microsoft, a credential-stuffing attack on Dropbox, and a cybersecurity startup hitting unicorn status.

Here’s what you need to know.

Microsoft Rolls Out Patches for Cloud Services

Microsoft has been busy behind the scenes. The company pushed out fixes for several of its cloud offerings, addressing vulnerabilities that could have given attackers a foothold in enterprise environments.

The patches cover a range of services, though Microsoft hasn’t disclosed every detail. What’s clear is that IT teams should treat these updates as priority. Cloud misconfigurations and unpatched flaws remain a top attack vector, and this is a reminder that even the biggest providers need constant upkeep.

For admins, the takeaway is straightforward: check your Microsoft cloud security dashboard, review the latest advisories, and apply the updates before they become a problem. Delaying patches in a cloud environment is a gamble, and the house usually wins.

What the Patches Target

Microsoft’s advisory points to vulnerabilities in Azure and related services. Specifics are sparse, but the company’s track record suggests these could range from privilege escalation to information disclosure. If you’re running any Microsoft cloud workload, the official security update guide is your first stop.

5,000 Dropbox Accounts Hacked via Credential Stuffing

Dropbox confirmed that attackers compromised roughly 5,000 user accounts. The method? Credential stuffing — using usernames and passwords stolen from other breaches to break into accounts where people reuse passwords.

This isn’t a breach of Dropbox’s own systems. The company says its infrastructure wasn’t compromised. Instead, the attackers leveraged the all-too-common habit of password reuse. Once they had valid credentials from elsewhere, they simply tried them on Dropbox.

Dropbox has reset passwords for affected users and is rolling out additional protections. But the incident underscores a persistent problem: credential stuffing attacks remain one of the most effective ways for hackers to get in. No fancy exploits needed, just a list of leaked passwords and a bit of patience.

How to Protect Yourself

  • Use a unique password for every account. Yes, every single one.
  • Enable two-factor authentication, especially on cloud storage and email.
  • Check haveibeenpwned.com to see if your credentials have been exposed.
  • If you’re a Dropbox user, change your password now, even if you weren’t affected.

It’s tedious, but it works. The hackers who did this weren’t geniuses — they were just counting on people to make the same mistake twice.

Guardio Hits $1.1 Billion Valuation

In brighter news, Guardio, a browser security startup, has reached a valuation of $1.1 billion. The company, which focuses on protecting consumers from phishing, malware, and malicious extensions, has been growing quietly but steadily.

Guardio’s approach is simple: a lightweight browser extension that blocks threats before they reach the user. It’s a consumer-focused product, but the underlying tech has broader implications. As more people work from home, the browser has become the new perimeter.

The Guardio funding round signals that investors see value in endpoint protection that doesn’t require a degree in cybersecurity to operate. That’s a good sign for the industry, and an even better one for users who just want to browse without getting hacked.

Why These Stories Matter

On the surface, these three items seem disconnected. A cloud patch, a credential stuffing attack, and a funding round — what’s the thread?

It’s this: security is a moving target. Microsoft’s patches show that even the giants are constantly fixing holes. The Dropbox incident shows that human behavior — password reuse, ignored 2FA — often undoes even the best technical defenses. And Guardio’s valuation shows that the market rewards products that make security accessible.

None of these stories will dominate tomorrow’s headlines. But together, they paint a picture of an industry that’s always fighting, always adapting, and always finding new ways to protect users. That’s worth paying attention to, even if it doesn’t make the front page.

Stay patched, stay vigilant, and for heaven’s sake, stop reusing your passwords.

Continue Reading

CyberSecurity

Cisco Nexus 9000 Critical Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Published

on

Cisco Nexus 9000 critical flaw

Critical Cisco Nexus 9000 Vulnerability: What You Need to Know

Cisco has released emergency patches for a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches. The vulnerability, tracked as CVE-2026-20212 with a CVSS score of 9.8, allows an unauthenticated, remote attacker to execute arbitrary code as root on affected devices.

The flaw resides in the Cisco Nexus 9000 Series switches powered by Silicon One chips. An attacker could exploit this by sending specially crafted packets to the management interface, potentially gaining full control of the switch without any credentials.

This is not a drill. With a CVSS score of 9.8, this is as severe as it gets in the networking world. The affected models include the 9364C, 9332D, 9348D, 9364D, and several others in the Nexus 9000 family.

Which Models Are Affected?

  • Nexus 9364C-GX
  • Nexus 9332D-GX2B
  • Nexus 9348D-GX2B
  • Nexus 9364D-GX2B
  • Nexus 9364D-GX2A
  • And 5 more Silicon One-based models

If you’re running any of these switches, you need to act fast. Cisco has confirmed that no workaround exists for this vulnerability. The only fix is to apply the software update.

The IOS XR Hardening Release: 7 CVEs Bundled, 2 Rated 9.8

Alongside the Nexus 9000 fix, Cisco also released a broader IOS XR hardening update that bundles seven umbrella CVEs. Two of these are rated at 9.8 critical severity, making this one of the more significant IOS XR security updates in recent memory.

The IOS XR vulnerabilities affect a wider range of devices, including the ASR 9000 Series and NCS 5500 Series routers. Cisco warns that there is no workaround for any IOS XR version, so administrators must upgrade to the patched releases immediately.

One of the 9.8-rated flaws involves a buffer overflow in the IPv6 processing stack, while the other relates to a command injection vulnerability in the CLI. Both could be exploited remotely without authentication, which is why they carry such high severity scores.

What Makes These IOS XR Vulnerabilities Dangerous?

The lack of authentication requirements is the key concern. An attacker on the network could send malformed packets to trigger the buffer overflow, or craft a malicious CLI command to inject code. In both cases, the result is the same: full compromise of the router.

Cisco’s advisory notes that these vulnerabilities are not known to be exploited in the wild yet, but that could change quickly. Given the criticality, waiting for proof of exploitation is a dangerous game.

Immediate Actions for Network Administrators

If you manage any of the affected devices, here’s your priority list:

  1. Identify affected devices: Check if your Nexus 9000 switches are Silicon One-based and on the affected model list.
  2. Review IOS XR versions: Determine if your ASR 9000 or NCS 5500 routers are running a vulnerable IOS XR release.
  3. Plan the upgrade: Cisco has provided patched versions for both the Nexus 9000 and IOS XR. Schedule maintenance windows to apply these updates.
  4. Monitor for anomalies: Until patches are applied, watch for unusual traffic patterns or unauthorized access attempts on management interfaces.

Remember, there are no workarounds. This isn’t a situation where you can apply an access control list or disable a service to mitigate risk. The only path forward is patching.

Context: Cisco’s Recent Security Track Record

This isn’t the first time Cisco has had to scramble to fix critical flaws in its networking gear. In recent years, the company has addressed multiple zero-day vulnerabilities in IOS XE and other products. The pattern is clear: network infrastructure is a prime target for attackers, and Cisco is working to stay ahead.

For more on related security issues, check out our coverage of Cisco IOS XE zero-day vulnerabilities and network switch security best practices.

The bottom line: if you’re running affected Cisco gear, treat this as an emergency. The technical details are public, and exploit code could be developed quickly. Patch now, not later.

Continue Reading

CyberSecurity

ThreatsDay: CEO Phishing Kits, 5K Dropbox Hacks, OAuth Traps, and 17 More Threats You Can’t Ignore

Published

on

CEO phishing kits

The Week in Cyber Threats: When ‘Normal’ Is the Weapon

The worst part isn’t the sophistication. It’s how ordinary these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door?

That grim reality runs through this week’s ThreatDay roundup. Attackers are weaponizing everyday tools—fake login pages, old account links, even software guides pointing to unsafe downloads. One wrong letter in a web address can be enough to hand over your credentials.

Here are the 20 stories that matter, starting with the ones that should keep you up at night.

CEO Phishing Kits: The New Gold Standard for Scammers

Cybercriminals have industrialized CEO fraud. Ready-made CEO phishing kits are now sold on dark web forums, complete with realistic email templates, fake login portals, and even call scripts for voice phishing.

These kits target executives specifically. They mimic internal communications, spoof vendor invoices, and exploit the authority that comes with a C-suite title. The result? A single click can authorize a fraudulent wire transfer or expose sensitive board documents.

Why Executives Are Easy Prey

Executives are busy. They delegate. They respond to urgency. Attackers know this. They craft emails that look like they came from a legal department or a trusted partner, often referencing real projects or meetings scraped from LinkedIn.

One security researcher noted that these kits are so polished that even trained employees hesitate before flagging them. The kits include A/B tested subject lines and pre-written responses to common questions. It’s a full-scale operation, not a hobby.

5,000 Dropbox Accounts Hacked: The Silent Data Drain

In a separate but equally alarming incident, hackers compromised over 5,000 Dropbox accounts using credential stuffing attacks. They didn’t break Dropbox’s servers—they just reused passwords leaked from other breaches.

Once inside, they searched for financial documents, personal identification, and any file that could be used for identity theft or blackmail. The attack was silent. No suspicious login alerts. No unusual activity flags. Just a quiet exfiltration of data.

How to Protect Your Cloud Storage

If you’re still using the same password for multiple sites, stop. Enable two-factor authentication immediately. Check your Dropbox account for active sessions and revoke any you don’t recognize.

Also, review your shared links. Old, forgotten links to sensitive files can remain active for years. Attackers use them as backdoors. Clean them up.

OAuth Traps: The ‘Allow’ Button That Costs Millions

OAuth is the backbone of modern app logins. You see it every time you click “Sign in with Google” or “Continue with Facebook.” But attackers have learned to weaponize this convenience.

In this week’s OAuth traps, scammers create malicious apps that request excessive permissions. When a user clicks “Allow,” the app gains access to their email, contacts, and even cloud drives. The user thinks they’re granting access to a useful tool. In reality, they’re handing over the keys to their digital life.

Spotting a Malicious OAuth Request

Before clicking “Allow,” ask yourself three questions: Do I recognize the app? Why does it need access to my contacts? Can I revoke this permission later?

Legitimate apps rarely request permissions they don’t need. If a PDF converter wants access to your Gmail, that’s a red flag. Always check the permissions screen carefully. And remember—you can revoke app access anytime from your account settings.

17 More Threats You Should Know About

Beyond the big three, this week’s roundup includes:

  • Fake IT support calls—scammers posing as helpdesk staff to reset passwords.
  • Malicious browser extensions that steal browsing history and credentials.
  • Phishing via shared documents—a link to a “shared file” that leads to a fake login page.
  • Typosquatting domains—one-letter-off URLs that mimic popular sites.
  • Fake software update prompts that install ransomware.
  • Vishing (voice phishing) targeting remote workers.
  • Smishing (SMS phishing) with fake delivery notifications.
  • QR code phishing—malicious codes placed over legitimate ones.
  • Social media impersonation of executives to trick employees.
  • Cloud misconfigurations exposing sensitive data publicly.
  • Supply chain attacks via compromised vendor software.
  • Ransomware double extortion—stealing data before encrypting it.
  • Deepfake audio used to authorize fraudulent transactions.
  • Credential harvesting via fake surveys.
  • Malvertising—malicious ads on legitimate sites.
  • Session hijacking through unsecured Wi-Fi.
  • Insider threats—disgruntled employees leaking data.

What You Can Do Right Now

You don’t need to be a security expert to protect yourself. Start with the basics: use a password manager, enable two-factor authentication everywhere, and be skeptical of unsolicited requests—even if they look legitimate.

For businesses, consider security awareness training for all employees. A well-informed team is your first line of defense. Also, audit your OAuth permissions and cloud storage settings regularly.

The threats are real, but so is your ability to defend against them. Stay alert. Stay updated. And never click “Allow” without thinking.

Continue Reading

CyberSecurity

Manchester Airports Group Data Breach: 8.8 Million Records Leaked After Ransom Refusal

Published

on

Manchester Airports Group data breach

What Happened?

The Manchester Airports Group (MAG) is dealing with a massive data breach. The attackers, a group called FulcrumSec, have leaked roughly 550 gigabytes of data. That’s a lot of information. It includes the personal details of about 8.8 million people.

MAG runs three major UK airports: Manchester, London Stansted, and East Midlands. The breach affected booking data for car parks, lounges, and Fast Track services. It also hit in-airport Wi-Fi sign-ups.

The group claims it got in using admin keys. These keys were reportedly left exposed in the frontend JavaScript of the airports’ websites. That’s a pretty basic security mistake. It’s like leaving your house key under the doormat.

The Scale of the MAG Data Leak

So, what exactly was stolen? According to data breach notification site HaveIBeenPwned, the leak includes 8.8 million email addresses and phone numbers. But it goes deeper than that.

FulcrumSec says the stolen data includes:

  • 2,482,763 purchases (bookings for parking, lounge, and fast-track products)
  • 461,433 SMS messages associated with bookings
  • 108,077 unique UK vehicle registration plates

Names, browser agent details, and residential IP addresses were also exposed. The group even claims to have grabbed the MAG platform’s configuration.

What This Means for Affected Users

If you’ve used these airports recently, there’s a chance your data is in there. The exposed information could be used for phishing attacks. Hackers might send convincing emails or texts that look like they’re from MAG. They could try to trick you into revealing more sensitive information.

Vehicle registration plates are particularly concerning. They could be used for cloning or other fraud.

Why Did FulcrumSec Leak the Data?

Simple. MAG reportedly refused to pay the ransom. The extortion group has admitted as much. They didn’t get their money, so they published the data. This is a common tactic. Many ransomware groups operate on a “name and shame” strategy. They leak stolen data to pressure victims into paying.

MAG confirmed it received a ransom demand but hasn’t shared further details. The company said its operations were not affected by the incident. That’s small comfort for the millions of people whose data is now floating around the dark web.

How Did the Attackers Get In?

FulcrumSec says they used admin keys that were left in plain sight. These keys were in the frontend JavaScript of each of the three airports’ websites. In each root domain, no less.

This is a serious oversight. Admin keys should never be exposed in client-side code. They should be stored securely on servers, protected by additional authentication measures. Leaving them in JavaScript is like writing your password on a sticky note and attaching it to your monitor.

SecurityWeek has not independently verified the attackers’ claims. But the data appears to be legitimate. HaveIBeenPwned has already parsed the dataset and added it to their database.

What Should You Do If You’re Affected?

First, don’t panic. But do take action. If you’ve used MAG airports for parking, lounges, or Fast Track, or signed up for Wi-Fi, your data might be compromised.

Here are some steps you can take:

  • Change your passwords, especially if you reuse them across multiple sites.
  • Be wary of unsolicited emails or texts asking for personal information.
  • Monitor your bank statements for any unusual activity.
  • Consider using a credit monitoring service.

This incident is a reminder of the importance of ransomware defense strategies. It also highlights the risks of data exposure through misconfigured web applications.

The Bigger Picture

This breach is part of a worrying trend. Airports and other critical infrastructure are increasingly becoming targets. Just recently, we saw 153 million driver license images offered on the dark web. And a ransomware gang claimed a data breach at Nutex Health.

The MAG data breach is a stark reminder that no organization is immune. Even those with substantial security budgets can fall victim to simple mistakes. The exposure of admin keys in frontend JavaScript is a basic error that should never happen.

For now, affected individuals should stay vigilant. The leaked data could be used for years to come. It’s not just about the immediate aftermath. It’s about the long-term risk of identity theft and fraud.

MAG has not yet commented on the full extent of the breach or what steps they’re taking to prevent future incidents. But one thing is clear: the consequences of this Manchester Airports Group data breach will be felt for a long time.

Continue Reading

Trending