Share on social
Sep 3, 2026
Lorem ipsum

Top Story This Week:
FulcrumSec Claims Responsibility for Manchester Airport Group Breach
Threat group FulcrumSec has published roughly 550GB of data it claims to have stolen from Manchester Airports Group (MAG), which operates the UK's Manchester, Stansted and East Midlands airports.
According to FulcrumSec, initial access came from admin keys for customer engagement platform Iterable, found sitting in plain sight in the frontend JavaScript of all three MAG websites. The group added that unlike the group's previous breaches at Arup Group and Novo Nordisk, where credentials were buried in obscure subdomains, these keys were on the sites' root domains and visible to anyone who right-clicked "inspect" in their browser. MAG has not confirmed the specific attack vector.
The claimed extortion is more than 8.7 million customer profiles, 1.2 billion marketing events, 2.5 million historical bookings, and over 461,000 SMS messages containing vehicle and booking details in plain text. The group says it holds data on 191,000 future bookings, including travel schedules and vehicle information, and claims some affected individuals are public figures, politicians and military personnel. (Read more on Infosecurity Magazine)
Why it Matters
Booking, parking and loyalty services at most airports run on outsourced platforms rather than in-house systems, and Iterable is exactly that kind of third-party dependency. But if FulcrumSec's claims are to be believed, the initial access came down to MAG's websites exposing the credentials.
Anything sent to a customer's browser can be inspected by anyone who knows where to look. When an admin-level credential ends up hidden in that code, it transforms an ordinary, public-facing website into a direct route into sensitive systems, no sophisticated exploit required.
Part of why these kinds of issues persist is that most organizations don't have a clear enough picture of their own external attack surface. They have visibility over their websites, but may not be able to say with confidence what those sites expose, what they connect to, or what an attacker could do with access they find.
This gap is widening because modern attack surfaces are no longer just traditional infrastructure. They include APIs, cloud services, third-party integrations, stray credentials, and forgotten functionality left over from old projects. Some of the most consequential exposures may not look like conventional vulnerabilities at all.
What this Means for Practitioners
Not hardcoding credentials is good security hygiene that most developers already know. But the hard part is verifying that the rule has genuinely held up across hundreds or even thousands of apps, domains, APIs, and integrations, many of which may have been built or modified by different teams over time.
To close that gap, organizations need to regularly assess their external assets from an attacker's perspective. That means going beyond routine CVE scanning to actively hunt for exposed credentials, forgotten or undocumented APIs, and unintended admin access that shouldn't be reachable from the outside.
When an exposure is found, the next step is understanding what it actually enables. Not all exposures are equal. Access to analytics data is a very different risk from admin-level access to customer records. Prioritize fixing the exposures with a realistic, exploitable attack path, and then verify. Don't just assume they've actually been closed.
What this Means for Security Leaders
Ask your security teams a direct question: do we know what we're exposing, not just what we own?
Confirm that your teams maintain a complete, current view of the external attack surface that extends beyond traditional asset inventories to cover the APIs, integrations, and forgotten systems that often fall outside standard tracking.
Asset discovery is only step one. The organization needs to understand what those assets expose, and how a seemingly low-risk application might connect through to something far more sensitive.
Speed matters too. How quickly can the team move from spotting an exposure to actually closing it? External attack surfaces don't stay still, new applications go live, infrastructure shifts, and third-party tools get bolted on constantly.
The goal is an ongoing process for finding, understanding, and fixing these exposures continuously, so attackers don't get there first.
Discover More
The Need for Attack Surface Management in Modern Enterprises
Modern enterprises face shifting and expanding digital ecosystems. Attack surface management helps security teams outpace threat actors, provide continuous visibility, and control over the assets attackers are most likely to exploit. In this blog we discuss the ongoing need for modern enterprises to implement Attack Surface Management tools and the many benefits of doing so. Read more.
How can Continuous Asset Discovery Prevent Security Blindspots
The traditional approach - scanning periodically - leaves too much room for error. By the time an organization identifies an exposed asset, it may already be compromised. In this blog we discuss why periodic scanning can leave your digital assets exposed and how continuous asset discovery closes the window of exposure. Read more.
Detection covers compromised third-party credentials in circulation, supplier data appearing in leaks and ransomware disclosures, and attacker activity naming your vendors across forums, marketplaces, and closed channels. Ransomware File Explorer goes further: it unpacks leak-site file trees so you can see whether a supplier, or an acquisition target, has been hit by a ransomware attack that hasn't been disclosed, and whether your files are in the leaked data. You learn a dependency is at risk from evidence, not from the vendor's disclosure timeline.
Attackers conduct reconnaissance and discuss their targets on hidden parts of the internet before they strike: registering lookalike infrastructure, trading credentials, discussing targets. Searchlight surfaces that activity as it forms and maps it to your organization, so your team acts while a threat is still being assembled, not after it has launched.
The risk is identified where it lives: on your own infrastructure. Discovery identifies the third-party software running on your surface, down to product and version, and validates what's genuinely exploitable, so supplier risk is assessed from your side of the relationship, with no access to the vendor's environment required.
CTEM is about continuously managing exposure. PTEM operationalizes and evolves this by incorporating adversary-informed threat intelligence and real-time attacker insight, shifting from continuous validation to active prediction and prevention of attacks before they are launched.






