• FluTrackers.com Inc. does not provide medical advice. Information on this web site is collected from various internet resources, and the FluTrackers board of directors makes no warranty to the safety, efficacy, correctness or completeness of the information posted on this site by any author or poster. The information collated here is for instructional and/or discussion purposes only and is NOT intended to diagnose or treat any disease, illness, or other medical condition. Every individual reader or poster should seek advice from their personal physician/healthcare practitioner before considering or using any interventions that are discussed on this website. By continuing to access this website you agree to consult your personal physican before using any interventions posted on this website, and you agree to hold harmless FluTrackers.com Inc., the board of directors, the members, and all authors and posters for any effects from use of any medication, supplement, vitamin or other substance, device, intervention, etc. mentioned in posts on this website, or other internet venues referenced in posts on this website.
  • We are not asking for any donations. Do not donate to any entity who says they are raising funds for us.

Cyber Incidents - International 2026-27

UK

Criminals publish data of 8.7m people after airports hack​

9 hours ago
Criminal hackers have posted the personal data of nearly nine million people online after breaching three UK airports.
Hackers extorted Manchester Airports Group (MAG) for an undisclosed amount but failed to get their ransom paid.

Customers of Manchester, London Stansted and East Midlands airports are being warned of secondary attacks as the data is now available to other criminals.
continued: https://www.bbc.com/news/articles/c74k39g3ee5o
 
Preparing for the Post-Quantum Era: A Call to Action

Published on Thursday 3 September 2026

We, the G7 Cybersecurity Working Group, recognize the growing threat that

quantum computing poses to public-key cryptography, and the security of

both public and private organizations. Although the exact timeline is uncer-

tain, several recent advances suggest an anticipation of the development

of quantum computers able to break widely used public-key cryptography

mechanisms and threaten the security of digital infrastructures.

To address these risks, we must reframe the quantum threat from a distant

future problem to a near‑term threat that demands action across all sectors,

not just critical infrastructure. Post-quantum cryptography (PQC) is a new

field of cryptography, designed to be resistant to both classical and quan-

tum cryptographic attacks, that can safeguard organizations from both the

conventional cyber threat and the quantum threat. For this reason, govern-

ments and organizations should begin their PQC transition as soon as pos-

sible to avoid exposure to quantum risks and to provide a level of long-term

protection of confidential data.

We acknowledge that transitioning to PQC is not a problem for individual

organizations to solve in isolation, but rather a collective transition that can

only be achieved with early engagement, coordinated planning, and infor-

med decision‑making across the public and private sectors.

This publication aims to highlight some of the risks that can be posed by

cryptographically relevant quantum computers (CRQCs)1 and to reaffirm our

collective efforts to addressing this threat. It identifies five priority areas for

PQC migration and highlights initiatives that G7 countries have advanced,

in whole or in part, to encourage timely measures today and inspire other

countries to take similar actions.

Continued: https://oos.cloudgouv-eu-west-1.out...cab3ce84648792434b5b944d73797f0e10c61bdbe8ca2
 

ICS ADVISORY​

IXON VPN Client​

Release Date September 03, 2026
Alert Code ICSA-26-246-02

Summary​

Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges.

The following versions of IXON VPN Client are affected:


  • VPN Client <1.4.7 (CVE-2026-75925)

CVSSVendorEquipmentVulnerabilities
v3 9.6IXONIXON VPN ClientImproper Neutralization of CRLF Sequences ('CRLF Injection')

Background​

  • Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy, Information Technology, Water and Wastewater
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: Netherlands
 
ICS ADVISORY

OPCFoundation OPC UA LocalDiscoveryServer (LDS)​

Release Date September 03, 2026
Alert Code ICSA-26-246-01

Summary​

Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands.

The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected:

  • UA-LDS-Installers <1.04.420 (CVE-2026-77477)

CVSSVendorEquipmentVulnerabilities
v3 4.6OPCFoundationOPCFoundation OPC UA LocalDiscoveryServer (LDS)Execution with Unnecessary Privileges

Background​

  • Critical Infrastructure Sectors: Chemical, Energy, Food and Agriculture, Water and Wastewater, Critical Manufacturing
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: United States


 

Tycon Systems TPDIN-Monitor-WEB2 (Update A)​

Last Revised September 03, 2026
Alert Code ICSA-26-202-01

Summary​

Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.

The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected:


  • TPDIN-Monitor-WEB2 <2.4.5 (CVE-2026-61884, CVE-2026-55985)

CVSSVendorEquipmentVulnerabilities
v3 9.8Tycon SystemsTycon Systems TPDIN-Monitor-WEB2Missing Authentication for Critical Function, Cleartext Storage of Sensitive Information

Background​

  • Critical Infrastructure Sectors: Critical Manufacturing
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: United States

Vulnerabilities:​

Continued: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-01
 

Rockwell Automation ControlFLASH​

Release Date September 03, 2026
Alert Code ICSA-26-246-03

Summary​

Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.

The following versions of Rockwell Automation ControlFLASH are affected:

  • ControlFLASH <=V15.07 (CVE-2026-12663)

CVSSVendorEquipmentVulnerabilities
v3 7.3Rockwell AutomationRockwell Automation ControlFLASHMissing Authentication for Critical Function

Background​

  • Critical Infrastructure Sectors: Critical Manufacturing, Energy, Water and Wastewater
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: United States

Vulnerabilities​

Continued: https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-03
 
Back
Top Bottom