Secret CISO 9/16: 8.8M Manchester Airports Records Leaked, $780M Revolut Bitcoin Extortion, CenterPoint Energy's 7.49M Customer Claim, WSO2 CVSS 9.8 Exploited
FulcrumSec dumps 8.8 million Manchester Airports records after MAG refuses to pay. Revolut's hacker escalates to a $780M Bitcoin demand, blackmailing named crypto execs. CenterPoint Energy confirms a breach, and WSO2's CVSS 9.8 flaw is under active attack.
Two extortion victims made the opposite bet this week. Manchester Airports called FulcrumSec's bluff and watched 8.8 million records land on a leak site anyway; Revolut's hacker just raised the stakes to $780 million in Bitcoin and started naming names. Neither story is close to over.
Today's Top 5
- Airport Data Dumped: FulcrumSec stopped waiting after Manchester Airports Group refused its ransom. What landed on the leak site was bigger than the airport operator first admitted to.
- $780M Bitcoin Demand: Revolut's hacker isn't negotiating quietly anymore. Named crypto industry veterans are getting direct threats, and their passports are already public.
- Utility Giant Confirms Breach: CenterPoint Energy keeps the lights on for 7 million Texans. A hacker claims to have walked out with nearly all of their records.
- Admin Tokens, Forged: A CVSS 9.8 bug in WSO2's API gateway lets attackers mint their own administrator credentials, and honeypots are already catching it happening.
- Spyware With a Fake MRI Scan: Iranian state hackers spent days building trust with journalists before sending one file. Three governments just put a name to the malware behind it.
Full stories, CVEs, and today's listening are below. Let's dig in.
Data Breaches

- FulcrumSec Publishes 8.8 Million Manchester Airports Records After Ransom Refusal: The extortion group broke in through admin API keys left exposed in the frontend JavaScript of all three of Manchester Airports Group's airport websites. MAG refused to pay, so FulcrumSec published roughly 549GB of data spanning Manchester, London Stansted, and East Midlands airports, including emails, phone numbers, postcodes, vehicle registrations, and future travel bookings. Have I Been Pwned confirmed 8.8 million people are affected, more than the airport group first disclosed. Source: Cybernews.
- Revolut Hacker Escalates to $780 Million Bitcoin Extortion, Targets Named Crypto Executives: The threat actor behind Revolut's breach is now demanding 10,000 Bitcoin and has started publishing passports and selfies of high-profile victims, including Gamdom CEO Felix Romer and former Mt. Gox chief Mark Karpeles. The original access reportedly traces to a five-month social engineering campaign that tricked Revolut's Lithuanian banking arm with a forged European Investigation Order routed through a compromised Italian government email account. Source: GovInfoSecurity.
- CenterPoint Energy Confirms Breach as Hacker Claims 7.49 Million Customer Records: The Houston utility told the SEC that an unauthorized party pulled personal data through an external-facing system after a dark web post surfaced claiming a haul of 7.49 million records, including names, billing addresses, payment details, and the last four digits of customers' Social Security numbers. CenterPoint hasn't confirmed the exact figure but says electric and gas delivery were never disrupted. Source: The Register.
- Chaos Ransomware Claims 402GB Haul From HVAC Filter Maker Glasfloss: The Chaos group says it exfiltrated corporate, financial, and employee data from the Texas air-filtration manufacturer, including accounting contracts and ESOP records. The listing surfaced on the group's leak site on September 14, with no public confirmation yet from Glasfloss on scope or customer notification. Source: Ransomware.live.
Security Research

- Mass Scanners Are Draining Cloud Credentials From Exposed Vite Dev Servers: F5 Labs tracked an automated campaign abusing CVE-2026-39364, a query-parameter bypass in Vite's development server, to pull .env files, AWS keys, Azure tokens, and Terraform state from internet-facing instances. The honeynet logged more than 800 grouped attacks and roughly 32,000 raw requests in a single month, all reaching files that Vite's own security settings are supposed to block. Source: The Hacker News.
- Gigabud Banking Trojan Clones Your Bank App Into a Hidden Work Profile: Group-IB found the Android malware pairing with Vwork, a weaponized fork of an open-source app-cloning tool, to duplicate a victim's real banking app inside an isolated Android work profile invisible to fraud checks. Operators wait, clone the app, then transact from the clone so the bank sees an unfamiliar device with no malware history. Indonesia alone saw roughly 1,469 compromised devices and $960,000 in losses between February and July. Source: The Hacker News.
- UK, US, and Netherlands Jointly Name Iranian Spyware Used on Journalists: Chosen Brick is a persistent Windows implant that harvests contacts, emails, and social media messages, and can capture screens and microphone audio. Operators impersonate people a target already knows on WhatsApp and Telegram, spend days building rapport, and have used lures as specific as fake MRI results to get a malicious file opened. Data on past victims has since turned up on pro-Iranian leak sites. Source: NCSC.
- Sandworm's Cyclops Blink Malware Resurfaces as an x86-64 Linux Implant: Researchers identified a rebuilt version of the Russia-linked botnet malware running on Cisco Secure Firewall Management Center appliances compromised via this week's rooting campaign, now able to actively scan internal networks and sniff packets. The new variant drops the original's PowerPC firmware tricks for generic Linux persistence, making it portable to a much wider range of network appliances. Source: Dark Reading.
Top CVEs
- CVE-2026-5430: A JWT algorithm-mismatch flaw in WSO2 API Manager and API Control Plane (CVSS 9.8) lets attackers craft tokens using an unsupported signing algorithm that the gateway wrongly accepts, forging administrator privileges for full account takeover. WatchTowr's honeypots caught in-the-wild forged admin tokens arriving on September 13. Source.
- CVE-2026-81963 and CVE-2026-85880: Two actively exploited Windows zero-days patched in September's Patch Tuesday. CVE-2026-81963 lets a low-privileged local attacker reach SYSTEM through the Windows Update Stack with no user interaction; CVE-2026-85880 is a heap overflow in Windows ALPC that lets an attacker who already has code execution escape a container and reach SYSTEM. Both are now in CISA's KEV catalog. Source.
- CVE-2026-83548 and CVE-2026-83549: SonicWall disclosed two SMA1000 appliance flaws that can be chained for unauthenticated remote code execution and confirmed active exploitation in the wild. The bugs sit on internet-facing secure access gateways, giving attackers a direct path from the public internet into the internal network. Source.
- CVE-2026-27540: An unrestricted file upload flaw (CVSS 9.8) in the WooCommerce Wholesale Lead Capture plugin lets unauthenticated attackers override its allowed file-type list and upload PHP web shells for full remote code execution. Wordfence has now blocked more than 100,000 exploit attempts against the flaw, with fresh attempts still landing daily on sites that never applied February's patch. Source.
Podcasts & Talks

- SANS ISC Stormcast, September 16: MacOS Traffic, a Cisco Zero-Day, and Locking Down AD and API Tokens. The Internet Storm Center's daily five-minute briefing covers unusual traffic patterns showing up from macOS 27 devices, the latest on an actively exploited Cisco zero-day, and practical steps for protecting Active Directory and API tokens from the kind of credential abuse driving several of today's breaches. A fast way to start the day informed. Listen: https://isc.sans.edu/podcastdetail/10096.
Final Words
The theme today is what happens after the first headline. Manchester Airports and Revolut were both breach stories a week or two ago. Today they're extortion stories, and the numbers only went up: 8.8 million records instead of an estimate, $780 million instead of a vague ransom demand. Assume every unresolved extortion case on your radar is still writing its second chapter.
CenterPoint Energy is a reminder that critical infrastructure providers are still just companies running APIs, and an API without rate limiting is an open door regardless of how many power plants sit behind it. Pair that with WSO2's forged admin tokens and the WooCommerce plugin still eating 100,000 exploit attempts months after a patch shipped, and the pattern is the same everywhere: authentication and access control keep breaking in the most basic ways, not the exotic ones.
If you found today's edition valuable, forward it to a colleague or friend who should see it. And if this email was forwarded to you, or you're reading it on the web, subscribe free at secretciso.org to get Secret CISO in your inbox every morning.
Stay vigilant, stay informed, and see you in the next edition of Secret CISO!