☀️ Good morning. Here's everything that happened in cybersecurity yesterday, in under 5 minutes.

Sunday was the day the attacker's toolkit stopped looking technical. Manchester Airports Group confirmed a thief walked off with data on roughly 8.7 million customers, most of it just email addresses harvested from airport Wi-Fi sign-ups, which is precisely the fuel a convincing phishing lure runs on. Microsoft detailed TerminalFix, a ClickFix variant that stops using the cramped Run box and asks victims to paste into Windows Terminal or PowerShell instead, ending in a reverse-tunnel backdoor. SOCRadar's disclosure of AnonyMousKIT showed rented AI voice agents phoning theft victims as "Apple Support" at about ten cents a call to talk them out of their passcodes. New CDT polling found two-thirds of British adults would not trust any government, current or future, with a key to their encrypted chats. And overnight, OpenAI began showing ads to free ChatGPT users selected from whatever they just typed into the box.

🔥 Top Stories

01 — Manchester Airports Group Breach Exposes Data on 8.7 Million Customers

Data Breach

Manchester Airports Group, the UK's largest airport operator, confirmed that an unauthorised third party stole customer data covering roughly 8.7 million people across Manchester, London Stansted and East Midlands airports. The records came from car park, lounge and Fast Track bookings plus in-airport Wi-Fi registrations, and include email addresses, phone numbers, vehicle registrations and postcodes. MAG was explicit that payment data was not involved: neither the company nor the accessed system holds customers' bank or card details. The great majority of affected people had only their email address exposed.

The "mostly emails, no bank details" framing is doing a lot of work, and it anchors readers on the wrong risk. An 8.7 million-record list of verified addresses, each tied to a named airport and a service the person actually used, is a phishing supply chain. Wi-Fi captive-portal data usually lives in a marketing platform rather than the core booking system, so it rarely gets the retention discipline payment infrastructure does. Cards can be reissued in days; an email tied to real travel behaviour is a durable targeting asset. Treat any message referencing your Manchester, Stansted or East Midlands booking, parking or Wi-Fi registration as hostile until proven otherwise, and never follow a link in one to "re-verify" anything.

02 — Microsoft Says ClickFix Now Points Victims at PowerShell, Not the Run Box

Malware & Threat Intel

Microsoft Threat Intelligence disclosed TerminalFix, a ClickFix variant whose only real change is the destination. A fake Cloudflare CAPTCHA on a compromised site quietly copies an attacker-supplied command to the clipboard, then tells the visitor to open Windows Terminal or PowerShell, paste, and press Enter. In Microsoft's words, directing users to a full command environment rather than the single-line Run dialog increases the likelihood that complex, multi-line scripts execute successfully. The chain ends in DLL sideloading, reconnaissance, persistence, and a custom reverse-tunnel backdoor that turns the machine into a foothold on the internal network.

That escalation is the story. Earlier ClickFix variants usually dropped an infostealer and stopped; TerminalFix uses the same throwaway social engineering as the front door to a full intrusion. Because the upgrade is behavioural rather than technical, there is no patch to apply. The one rule that defeats it at step one: no legitimate website ever asks you to open a terminal and paste a command. For defenders, alert when a browser process spawns a terminal, restrict PowerShell and Run dialog execution for standard users via AppLocker, Application Control or Group Policy, enable the Windows Terminal multi-line paste warning, and watch for unexpected outbound tunnels.

03 — Rented AI Voice Agents Pose as Apple Support to Strip Activation Lock

Phishing & AI

SOCRadar's Threat Research Unit disclosed AnonyMousKIT, a credit-metered phishing-as-a-service platform built for one job: stripping Apple's Activation Lock from lost and stolen iPhones so they can be resold. Lures run across five billed channels from a single victim record, including email at 1.50 credits, a recorded voice call at 1 credit, and an AI voice agent at 2 credits. Every channel funnels toward the same three asks, in order: the device passcode, the Apple ID credentials, then a live 2FA code. Messages cite the handset's internal Apple model identifier and its live Find My status, both pulled from the stolen device itself.

The economics are the point. SOCRadar recovered 200 call records tied to the AI voice channel, made between August 31, 2025 and May 30, 2026, using five configured personas that all resolve to one "Alice from Apple Support" identity in English, Spanish and Portuguese, at a total platform cost of $19.24, or roughly 9.6 cents per call. The "unlock tools" on the panel are mostly decoration: 5,649 of 6,092 targeted devices, 92.7 percent, run A12 silicon or newer that current bypasses cannot touch, so the owner becomes the target instead. Apple never calls, texts or emails asking for your passcode, password or 2FA code; hang up and report it. Enterprises should move high-value Apple IDs to FIDO2 hardware keys, which cannot be read aloud to a caller.

04 — Two-Thirds of Brits Don't Trust Any Government With Their Encrypted Chats

Policy & Government

Polling by Public First for the Center for Democracy & Technology, covering 2,000 UK adults surveyed April 20 to 27, 2026, with a margin of error of plus or minus 2.2 points, found two-thirds would not hand either the current government or any future one the power to reach their encrypted messages. The distrust runs broader than party lines: 93 percent said they have a right to private conversations online, and 89 percent said nobody should access their personal messages without a court order. CDT funded the work and openly favours strong encryption, so read the framing accordingly; the underlying numbers still stand on their own.

The context is live law, not hypothetical debate. The Investigatory Powers Act 2016 lets the Home Secretary issue a secret Technical Capability Notice ordering a company to remove "electronic protection," and the Online Safety Act 2023 gives Ofcom power to require "accredited technology" to scan for child sexual abuse material, which critics argue can only work in practice through client-side scanning. Apple withdrew Advanced Data Protection for UK users in early 2025 after a secret notice and challenged the order at the Investigatory Powers Tribunal in July 2026, yet 55 percent of those polled had not heard about that notice until the survey described it. For security teams: get vendors' end-to-end encryption commitments in writing, know which jurisdictions can compel them to change defaults, and plan for a provider shipping weaker protection in one country than another.

05 — Free ChatGPT Users Now See Ads Picked From What They Just Asked

AI & Privacy

OpenAI has begun serving ads to free-tier ChatGPT users, selected from the content of the conversation in progress plus rough location and device type. Ask the assistant to help pick a mattress and an ad may appear alongside the answer, chosen because of what you just typed. What ChatGPT remembers about a user from earlier chats is not part of the targeting signal, at least not currently.

The privacy question is narrower than it first appears and more important for it. This is not profile-based advertising built on stored history; it is real-time inference on the text a user is actively typing, which means the prompt itself is now commercially interesting. For anyone using a free consumer account for work, that reframes the input box: prompts about a vendor evaluation, a legal problem or a health issue are signals, not just queries. If your organisation has staff on free-tier assistants, this is the moment to restate which categories of information never go into a consumer AI account.

📊 By The Numbers

  • 8.7 million — Manchester Airports Group customers whose data was stolen across three UK airports, most of them email addresses from Wi-Fi sign-ups and bookings.

  • 92.7 percent — Share of AnonyMousKIT's targeted devices, 5,649 of 6,092, running Apple A12 silicon or newer, which current technical bypasses cannot defeat. So the operators target the owner instead.

  • $19.24 — Total platform cost of the 200 AI voice calls SOCRadar recovered, roughly 9.6 cents per impersonation attempt.

  • 93 percent — UK adults in the CDT and Public First poll of 2,000 people who said they have a right to private conversations online; 89 percent said no access without a court order.

  • 274 — Internet-facing Zimbra servers Shadowserver has confirmed compromised via CVE-2026-73570, a reminder that the unpatched edge is still the cheapest way in.

⚡ The Signal

Not one of yesterday's four biggest stories required an exploit. TerminalFix ships no vulnerability; it borrows the trust users place in a terminal window they opened themselves. AnonyMousKIT gave up on cracking A12 silicon and rented a voice instead, at a dime a call, because the passcode is cheaper to ask for than to break. The Manchester Airports Group records are worth stealing precisely because they make the next ask sound legitimate. The pattern is not new, but the pricing is: social engineering has become an infrastructure purchase with published rates, credit bundles and customer support.

That changes what "the attack surface" means on a defender's diagram. If the entry point is a person's willingness to comply with a plausible instruction, then the controls that matter are the ones that survive a convinced user. Phishing-resistant hardware keys work against AnonyMousKIT not because they detect the lure but because a FIDO2 key cannot be read aloud into a phone. Blocking a browser from spawning a terminal works against TerminalFix not because it identifies the CAPTCHA as fake but because it breaks the chain after the user has already been persuaded. Assume the persuasion succeeds, then ask what still holds.

The encryption polling lands in the same frame. Two-thirds of British adults refusing any government a key to their messages is, at bottom, a statement about what happens to a trusted channel once a legitimate access path exists inside it. Every story above is a variation on that theme: a trusted interface, whether Apple Support, a Cloudflare CAPTCHA, an airport's Wi-Fi portal or an assistant's answer box, is worth more to an attacker than any single flaw. The 274 compromised Zimbra servers are the reminder that the old way in is still open too. Patch the edge, and then go work on the interfaces.

🔍 What You May Have Missed

📅 What to Watch

  • Zimbra CVE-2026-73570 Exploitation — Shadowserver's count of compromised internet-facing instances stood at 274 and mass-exploitation numbers rarely fall. If you run Zimbra, confirm the patch is applied rather than merely scheduled.

  • Manchester Airports Group Fallout — Watch for whether MAG or the ICO names the threat actor, and whether the exposed scope grows beyond email as investigators review the stolen set. Early samples suggest more detail for some customers than "mostly emails" implies.

  • Building a Secure AI Strategy for the Enterprise — Dark Reading virtual event on October 8. Worth a calendar hold if you are drafting AI usage policy this quarter.

  • Securing Cloud Assets in the Age of AI — Dark Reading virtual event on November 12, focused on what enterprises need to know about cloud asset security as AI workloads spread.

Stay sharp. Stay ahead.

Till next time,

The CyberSignal Team