STRATQUAD
CYBER THREAT INTELLIGENCE BRIEF
Daily Brief · 31 August 2026 · 24h windowRISKLOW
StratQuad CTI Daily Brief, 31 August 2026

Compiled from 52 monitored sources · 62 articles reviewed

Today’s Briefing

Extortion group FulcrumSec claims it stole 86GB from Manchester Airports Group after finding API credentials exposed in client-side JavaScript, affecting customers of Manchester, London Stansted, and East Midlands airports. Apache released patches for four critical-severity vulnerabilities in Tomcat.CVE-2026-68525, CVE-2026-65905, CVE-2026-65637, and CVE-2026-65182.covering authentication bypass, authorisation bypass, and incomplete remediation of an earlier input validation flaw across versions 9.0, 10.1, and 11.0. Google patched two critical out-of-bounds write flaws in Chrome's ANGLE component, CVE-2026-79189 and CVE-2026-79188, both rated high severity for potential remote code execution outside the sandbox.

Top Stories

  1. Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft
  2. What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree
  3. Halo-record: Open-source audit trails for AI agents

Full brief available to subscribers

The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.

All briefs