Unknown parties know where you stayed last summer, down under, across 120 Quest properties
Quest, an Australian aparthotel chain, has confirmed a data security incident that exposed personal information of its guests. The breach, which was identified on Monday, August 17, 2026, stemmed from a vulnerability in a third-party service provider's database system.
The company stated that the compromised data pertains to records created before June 2025. Information exposed includes guests' full names, email addresses, and other contact details. A limited number of entries also contained dates of birth. Quest operates over 120 properties across Australia, New Zealand, and Fiji, and the incident could affect both domestic and international visitors who booked stays through its own channels or third-party travel sites like Expedia, Wotif, and Booking.com.
Upon discovering the unauthorized access, Quest immediately took steps to contain the incident and has since implemented remediation measures. The company has initiated forensic investigations and engaged external cybersecurity and privacy advisors. All affected guests have reportedly been notified of the breach.
Quest has not publicly identified the third-party service provider responsible for the vulnerability, nor has it disclosed the specific method of the breach or the total number of customers impacted. The extent of the lost data, particularly how far back the records go, also remains undisclosed. The nature of the exposed data, including names, contact details, and dates of birth, could potentially be used for identity fraud attempts.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.