If you just remember one thing from this briefing…
The fortnight's largest breach hit systems nobody was watching hardest: car parking, Wi-Fi and lounge bookings, not flight operations.
Manchester Airports Group's backend booking platform gave up 8.7 million customer records across three
airports; the data was published on 2 September after MAG refused to pay. Ask your team: do our "ancillary"
customer platforms get the same assurance testing as operational systems, or less.
Priority1–2 Sep
SonicWall SMA1000 zero-day chain gives unauthenticated code execution on remote-access gateways
SonicWall confirmed active exploitation of two chained SMA1000 flaws on 1 September: CVE-2026-83548, an
unauthenticated SSRF (CVSS 10.0), and CVE-2026-83549, an OS command injection, together giving remote
code execution. Both reached the CISA KEV catalogue the next day — the third exploited SMA1000 zero-day
since December.
So what: SMA1000 units terminate VPN and remote-maintenance access across many
estates. Treat any internet-facing unit as compromised until patched.
Priority28 Aug
Manchester Airports Group breach exposes 8.7 million customer records, then gets published
An unauthorised third party accessed a backend system handling car park, lounge, Fast Track and Wi-Fi
bookings across Manchester, Stansted and East Midlands airports. MAG refused the ransom; FulcrumSec
published roughly 640GB of the data on 2 September, including emails, phone numbers and vehicle
registrations. Payment data and operations were unaffected.
So what: ancillary customer platforms now carry the same regulatory exposure as
core systems. Confirm they receive equivalent testing and monitoring.
Watch2 Sep
Storm ransomware group lists Boeing and Airbus supplier Star Aviation
Storm, a ransomware group active since August, listed Kentucky supplier Star Aviation Inc on its leak
site on 2 September, claiming theft of technical schematics and employee ID data — one of roughly 44 to
48 victims claimed since it surfaced, amid intensifying extortion focus on aviation suppliers.
So what: check what schematics or engineering data your tier-2/3 suppliers hold, and
whether contracts require prompt breach notification.
Watch1 Sep
Zelensky warns Russian airspace unsafe as GNSS jamming intensifies
On 1 September President Zelensky warned airlines that Russian airspace is no longer safe, citing GPS
jamming severe enough to make aircraft disappear from radar, alongside expanding drone and air-defence
activity. It follows August's confirmed growth of Baltic spoofing infrastructure and EASA's revised
Safety Information Bulletin.
So what: reassess routing and diversion planning near Russian and Baltic airspace;
confirm crews hold current GNSS-denied procedures.