Latest cyber news, threats, security, and guidelines. Stack up.

Incident
Published 2026-09-17
Verified 2026-09-19

US Coast Guard/FBI board two Texas-bound oil tankers after voyage cyberattacks (VL Prosperity)

SecurityWeek (17 September 2026), citing CBS News / US officials, reports that US Coast Guard and FBI personnel boarded two Texas-bound oil tankers last month after cyberattacks disrupted the vessels en route to the United States. Named ship: Liberian-flagged crude tanker VL Prosperity (left Egypt 1 August en route to Galveston per vessel-tracking cited by CBS). Iran’s Mehr News Agency (20 August) alleged an 7 August Strait of Gibraltar intrusion affecting engine-room systems (coolant/fuel/engine speed), navigation/cargo, and ~30 hours of lost communications — US Coast Guard has not publicly attributed the incident to Iran. A Coast Guard cyber / law-enforcement / FBI Cyber Action Team boarded VL Prosperity the day after Mehr’s report and spent four days aboard; Wall Street Journal reported the second ship boarded 24 August after Gulf of Mexico arrival. Rear Adm. Amy Grable (Coast Guard Cyber Command) told CBS investigators found evidence of a malicious cyber actor on IT/onboard systems and that the tanker was not judged unsafe to operate; ~40–50 similar Cyber Protection Team boardings in the past year. Investigators still assessing whether the two tanker incidents are connected or state-linked. Wire-primary until a Coast Guard/FBI primary release is posted. OT/maritime relevance for AU shippers and ports.

Product
Maritime vessel IT/OT (engine-room / navigation / cargo / SATCOM — as alleged in open reporting; not a product CVE)
Versions
n/a
Exploited in Australia?
unknown
Patch to
Maritime operators: segment vessel IT/OT, restrict remote/SATCOM admin paths, monitor engine/navigation anomaly alarms, rehearse cyber boarding/forensics with flag-state guidance

Primary: SecurityWeek — oil tanker cyberattacks / CG–FBI boardings (17 Sep 2026)

tech ot ics network

Incident
Published 2026-09-17
Verified 2026-09-19

FBI seizes NightmareStresser DDoS-for-hire domains (Operation PowerOFF)

BleepingComputer (17 September 2026) reports the US FBI seized nightmare-stresser[.]com and nightmarestresser[.]org used by NightmareStresser, a long-running DDoS-for-hire (booter) service. FBI Cyber Division said that since 2022 the service was used to launch hundreds of thousands of actual or attempted DDoS attacks worldwide. Seizure banners cite Operation PowerOFF, the international law-enforcement effort against DDoS-as-a-service infrastructure. Historical context: Searchlight Cyber (2023) previously assessed ~566k registered users and up to ~200 Gbps multi-layer attacks; DOJ had seized nightmarestresser[.]com once before in December 2022 with related arrests. Primary wire: BleepingComputer quoting FBI Cyber Division / PowerOFF seizure banner (FBI press index 403 from this pass; no separate DoJ HTML confirmed).

Product
NightmareStresser (DDoS-for-hire / booter)
Versions
n/a (law-enforcement infrastructure seizure)
Exploited in Australia?
unknown
Patch to
Defenders: expect residual copycat booters; keep DDoS playbooks current; report booter solicitation; no product patch

Primary: BleepingComputer — FBI seizes NightmareStresser (17 Sep 2026) · THN — NightmareStresser domain seizures (17 Sep 2026)

tech network

Incident
Published 2026-09-16
Verified 2026-09-19

Gyazo (Helpfeel): ~23.62M user records + ~490M image metadata exposed after upload-server RCE

Helpfeel Inc. notice (16 September 2026 JST; Kyoto) confirms unauthorised access to Gyazo’s image-sharing service. On 11 September 2026 a third party exploited a vulnerability in Gyazo’s image upload server to run arbitrary commands; Helpfeel says it blocked access routes by early 12 September and remediated the flaw. Confirmed disclosure: ~23.62 million user-related records (fields vary — may include name/nickname, email, password hash, user/device/session IDs, X/Twitter token, Google SSO email, profile/language, registration/last-login, plan and billing status without card numbers) and ~490 million image metadata records primarily for images registered in/before January 2019 (~14.4% of image-related data), plus ~2.4 million further metadata records via filtering. Metadata includes values used to build Gyazo image URLs (upload IP, User-Agent, EXIF location, OCR text, titles, source URLs, hashed passphrases for private images); Helpfeel temporarily disabled access to files whose records were exposed and cannot rule out that some private images were viewed. UPDATE 18 Sep 2026 (BleepingComputer): Gyazo service temporarily suspended for preventive maintenance while recovery continues; Helpfeel/Cosense not confirmed impacted beyond Gyazo; users being notified; no evidence of data deletion from this incident. No payment-card data confirmed disclosed. Users: change Gyazo passwords and any reused passwords; report filed with Japan’s Personal Information Protection Commission. Primary: Helpfeel corp notice; wires: THN 17 Sep / BleepingComputer 18 Sep.

Product
Gyazo (Helpfeel Inc. image-sharing / screenshot service)
Versions
n/a (SaaS incident; upload-server vulnerability remediated per vendor)
Exploited in Australia?
unknown
Patch to
Gyazo users: change password and any reused passwords; watch phishing; treat old image URLs as potentially enumerable if metadata leaked; expect service downtime while Gyazo remains suspended for maintenance; operators using Gyazo embeds: plan alternate screenshot/CDN delivery

Primary: Helpfeel — Gyazo unauthorised access notice (16 Sep 2026) · Vendor: Helpfeel Inc. — Gyazo breach notice · BleepingComputer — Gyazo 23.6M records / service suspended (18 Sep 2026)

breaches cloud identity

Incident
Published 2026-09-16
Verified 2026-09-19

Thorndale Foundation (AU): Qilin leak-site listing (ransomware.live)

Ransomware.live’s Australia country feed lists Thorndale Foundation (www.thorndale.com.au — Western Sydney disability support not-for-profit) under the Qilin brand — published and discovered 16 September 2026 on the feed. The organisation homepage loaded on this pass with no visible cyber-incident notice; no OAIC notice, Webber Insurance list entry, or ACSC advisory was located, so treat the listing as an unconfirmed extortion claim until a primary notice appears. Distinct from reddrop-group-qilin-20260916 (same brand, different victim). Australian disability and community-service providers should verify backups, MFA, and remote-access exposure.

Exploited in Australia?
unknown

Primary: Ransomware.live Australia (Thorndale Foundation / Qilin; discovered 16 Sep 2026) · Vendor: Thorndale Foundation (org site — no incident notice found this pass) · Webber Insurance AU breaches list (no matching notice found this pass)

australia

Incident
Published 2026-09-16
Verified 2026-09-19

Reddrop Group (AU): Qilin leak-site listing (ransomware.live)

Ransomware.live’s Australia country feed lists Reddrop Group (www.reddrop.com.au — NSW supermarket group, ~18 stores) under the Qilin brand — published and discovered 16 September 2026 on the feed. The company homepage loaded on this pass with no visible cyber-incident notice; no OAIC notice, Webber Insurance list entry, or ACSC advisory was located, so treat the listing as an unconfirmed extortion claim until a primary notice appears. Distinct from other AU Qilin listings on this desk. Australian retail operators should verify backups, MFA, and remote-access exposure.

Exploited in Australia?
unknown

Primary: Ransomware.live Australia (Reddrop Group / Qilin; discovered 16 Sep 2026) · Vendor: Reddrop Group (company site — no incident notice found this pass) · Webber Insurance AU breaches list (no matching notice found this pass)

australia

Incident
Published 2026-09-16
Verified 2026-09-19

Leisure Coast Kitchens (AU): Kairos leak-site listing (ransomware.live)

Ransomware.live’s Australia country feed lists Leisure Coast Kitchens (AU retail / bespoke kitchens, laundries and bathrooms) under the Kairos brand — published 16 September 2026, discovered 16 September 2026 on the feed. No company website incident notice, OAIC notice, Webber Insurance list entry, or ACSC advisory was located on this 17 September 2026 10:00 Perth desk pass, so treat the listing as an unconfirmed extortion claim until a primary notice appears. Kairos is tracked as a data-extortion (theft-focused) brand. Distinct from other AU Kairos listings on this desk. Australian retail and trade businesses should verify backups, MFA, and remote-access exposure.

Exploited in Australia?
unknown

Primary: Ransomware.live Australia (Leisure Coast Kitchens / Kairos; discovered 16 Sep 2026) · Webber Insurance AU breaches list (no matching notice found this pass)

australia

Incident
Published 2026-09-16
Verified 2026-09-19

Mandiant: attacker hijacks AI coding-assistant session, spreads Shai-Hulud across ~100 repos

Mandiant AI Risk and Resilience Report 2026 (Google Cloud; wired by The Hacker News 16 September) case study: after compromising a SaaS provider, an attacker hijacked an active AI coding-assistant session on a developer workstation. The assistant recommended a poisoned external package; once accepted, the attacker used the session to install an infostealer via a poisoned PyPI package, harvest GitHub OAuth tokens, and deploy the self-propagating Shai-Hulud worm across about 100 internal repositories (secret theft and programmatic exfiltration). Distinct from earlier Keyv-linked npm worm / Mini Shai-Hulud supply-chain desk notes. Defenders: treat AI assistant tool-install prompts as high-risk; constrain package installs; rotate GitHub tokens; audit recent repo automation. Primary: Mandiant/Google Cloud report.

Product
AI coding assistants; developer workstations; GitHub / PyPI supply chain
Exploited in Australia?
unknown
Patch to
Revoke exposed GitHub OAuth/tokens; remove Shai-Hulud artefacts; constrain AI assistant install capabilities; rebuild from known-good

Primary: Mandiant AI Risk and Resilience Report 2026 (Google Cloud) · Vendor: Google Cloud / Mandiant · The Hacker News — Shai-Hulud AI session (16 Sep 2026)

ai cloud identity

Incident
Published 2026-09-16
Verified 2026-09-19

Premier Medical Group (NY): ~282,075 patients notified after June 2026 file access

Premier Medical Group of the Hudson Valley P.C. published a Notice of Data Security Incident: after disruption of some IT systems, investigation found an unauthorized party accessed certain files on 14 June 2026; on 14 July 2026 PMG determined files may have included patient names, contact information, dates of birth, health insurance information, provider names, internal patient IDs, dates of service, medication information, and treatment/diagnostic information. Law enforcement notified; enhanced safeguards and staff training cited. SecurityWeek (16 September 2026) reports HHS breach portal listing 282,075 individuals and that no ransomware/extortion group claim was seen. How the attack occurred not disclosed. Primary: company notice; wire: SecurityWeek.

Product
Premier Medical Group patient/IT systems (Hudson Valley, NY)
Exploited in Australia?
unknown
Patch to
Patients: review provider/insurer statements for unrecognized services; PMG incident line 888-650-4197 (ET business hours per notice)

Primary: Premier Medical Group — Notice of Data Security Incident · Vendor: Premier Medical Group (company) · SecurityWeek — 280,000 impacted (16 Sep 2026)

breaches healthcare

Incident
Published 2026-09-15
Verified 2026-09-19

GhostCode: eSentire TRU documents M365 device-code phishing kit (MFA bypass in ~78s)

eSentire Threat Response Unit blog (published 15 September 2026; dateCreated 10 Sep) details GhostCode, a novel OAuth 2.0 device-authorization phishing kit that hijacks Microsoft 365 accounts after the victim completes legitimate MFA on Microsoft's real sign-in page. Observed chain: Salesforce contact-form lure as procurement staff, sales follow-up, NDA pretext, then a WeTransfer link to a password-gated HTML attachment with AES-256-GCM ciphertext and triple-layer HTML obfuscation; a Cloudflare Turnstile gate filters scanners before the device-code page. Kit requests a user_code using the Microsoft Authentication Broker application ID, presents a polished fake document portal, and captures tokens once the victim approves the attacker's device. eSentire describes Primary Refresh Token capture and, in one intrusion, nine successful API calls and three device registrations in about 78 seconds, with residential proxies matched to victim geography. Distinct from password-stealing kits; MFA does not stop the flow because the victim authenticates Microsoft directly. Defenders: restrict or block device-code grant where unused, alert on Authentication Broker device registrations, treat unexpected WeTransfer/NDA procurement mail as high-risk, review Entra ID sign-in and device logs. Primary: eSentire TRU; wire: Cyber Security News 16 Sep.

Product
Microsoft 365 / Entra ID — OAuth 2.0 device authorization grant (Authentication Broker client)
Versions
n/a (phishing kit abusing legitimate Microsoft device-code flow; not a Microsoft product CVE)
Exploited in Australia?
unknown
Patch to
Entra ID: disable device-code flow if unused; Conditional Access / risk alerts on Authentication Broker and new device registrations; user awareness on WeTransfer NDA lures; revoke tokens / remove rogue devices on suspicion

Primary: eSentire TRU — GhostCode device-code phishing kit (15 Sep 2026) · Vendor: eSentire — GhostCode analysis · Cyber Security News — GhostCode / M365 MFA bypass wire (16 Sep 2026)

tech identity cloud

Incident
Published 2026-09-15
Verified 2026-09-19

Auto-IT (AU): confirms Storm ransomware hit a small number of customer environments via third-party RMM

Cyber Daily exclusive (15 September 2026) names Australian dealer-management software firm Auto-IT as the third-party IT supplier behind the recent Storm ransomware wave against Australian car dealerships and machinery suppliers. Auto-IT told Cyber Daily a small number of customer environments were affected via unauthorised use of a third-party remote monitoring and management (RMM) tool; customers were named on a dark-web listing site with claims of accessed business data. Company says the incident is contained, customer environments remain secure and fully operational, forensic specialists were engaged, and it is working with the Australian Cyber Security Centre and impacted customers. Cyber Daily links the wave (listings from about 18 August) to dealers including Westco Motors Cairns, Ramsey Bros, Penfold Motors, Sharp Motor Group, Agrimac, and Macquarrie — several of which already have desk cards noting an unnamed third-party supplier. Primary: Cyber Daily with Auto-IT quotes; related desk cards: penfold-motors-storm-20260914, macquarrie-storm-20260903.

Product
Auto-IT dealer management / customer environments (third-party RMM abused)
Exploited in Australia?
yes
Patch to
Auto-IT customers: follow vendor incident guidance; review RMM access, rotate credentials, confirm forensic containment; report via ACSC if impacted

Primary: Cyber Daily — Auto-IT confirms Storm / customer environments (15 Sep 2026) · Webber Insurance AU data-breaches list (Auto-IT / Storm entry)

australia

Incident
Published 2026-09-15
Verified 2026-09-19

Admin Menu Editor Pro: compromised update channel backdoors ~1,500 WordPress sites (versions 2.35/2.36)

Developer Janis Elsts (adminmenueditor.com) reports that on 14 September 2026 an attacker gained access to the plugin's distribution site and pushed malicious Admin Menu Editor Pro updates. Version 2.35 (available ~06:00–13:00 UTC) dropped includes/wp-user-consent.php (web shell) and created a hidden wp_-prefixed user; a same-day clean 2.36 push was also compromised while the attacker retained access. Update-server logs: ~230 customers, malicious build installed on at least 1,500 sites (multiple sites per customer); several hundred more downloads in the window may be affected. Free Admin Menu Editor and 2.34 believed clean. IoCs per developer: includes/wp-user-consent.php under admin-menu-editor-pro; new /wp-content/object-cache/; wp_ users hidden from the dashboard; wp_ocache* options. Remediation: restore from a backup before 14 Sep 2026, or remove the plugin, delete /wp-content/object-cache/, and purge the listed DB artefacts; site sales/updates offline pending rebuild. Primary: developer incident notice; wire: BleepingComputer 15 Sep.

Product
Admin Menu Editor Pro (WordPress premium plugin)
Versions
Malicious 2.35 and compromised 2.36; 2.34 and free edition believed clean
Exploited in Australia?
unknown
Patch to
Do not run 2.35/2.36 from the compromised channel; restore pre-14 Sep backup or remove plugin + object-cache dir + wp_ / wp_ocache* artefacts per developer guidance; wait for rebuilt distribution

Primary: Admin Menu Editor — developer incident notice (site offline; 14 Sep 2026) · Vendor: adminmenueditor.com (maintainer) · BleepingComputer — Admin Menu Editor Pro supply-chain backdoor (15 Sep 2026)

breaches cloud

Incident
Published 2026-09-15
Verified 2026-09-19

CenterPoint Energy (US utility): SEC filing confirms customer personal data stolen via external-facing system

BleepingComputer (15 September 2026) reports Houston-based utility CenterPoint Energy confirmed in an SEC filing that an unauthorized third party obtained personal information for a portion of its customers through an external-facing system. A threat actor alias “4d722e4d656f77” told BleepingComputer they exfiltrated about 7.49 million customer records (names, phones, service/billing addresses, account numbers, billing amounts, partial SSNs) by iterating IDs on a public API alleged to lack rate limiting/WAF. CenterPoint says electric and gas services were not impacted and does not expect a material business effect; it activated IR, engaged third-party experts, hardened systems, and notified law enforcement/regulators. Class-action complaints filed in US federal courts allege the incident window was about 17 August–1 September 2026. Company has not publicly matched the actor’s record count or data-type claims in the SEC text cited by the wire. Primary wire: BleepingComputer; company confirmation: SEC filing as cited there.

Product
CenterPoint Energy customer-facing / external systems (public API per actor claim)
Exploited in Australia?
unknown
Patch to
Utility customers: monitor for phishing/identity misuse; CenterPoint says services unaffected — follow company notices for affected individuals

Primary: BleepingComputer — CenterPoint Energy confirms customer data stolen (15 Sep 2026) · Vendor: CenterPoint Energy (company site) · SecurityWeek — CenterPoint confirms breach after leak (15 Sep 2026)

breaches ot ics

Incident
Published 2026-09-15
Verified 2026-09-19

US: five alleged Black Axe leaders extradited on cyber-enabled fraud / money-laundering charges

BleepingComputer (15 September 2026) reports five alleged leaders of the Black Axe cybercrime syndicate — Perry Osagiede, Franklyn Osagiede, Osariemen Clement, Collins Otughwor, and Musa Mudashiru — were extradited to the United States to face wire fraud and money-laundering charges. Prosecutors allege a Cape Town–based internet fraud campaign (about 2011–2021) using romance and advance-fee scams, aliases, dating sites, and VoIP numbers to target US victims, including coercion via threats to publish sensitive photos. US Attorney’s Office for the District of New Jersey press release linked from the wire: “Five Prominent Black Axe Members Extradited for Conspiring to Engage in Internet Scams and Money Laundering.” Law-enforcement action / charging story; not a fresh organisational data-breach notice. Primary: DOJ USAO-NJ PR; wire: BleepingComputer.

Exploited in Australia?
unknown

Primary: DOJ USAO-NJ — Black Axe members extradited (linked 15 Sep 2026 wire) · BleepingComputer (15 Sep 2026)

breaches

Incident
Published 2026-09-14
Verified 2026-09-19

Spain AEPD: first notified personal-data breach allegedly run by an AI agent (LLM)

Spain’s Agencia Española de Protección de Datos (AEPD) blog (14 September 2026; Francisco Pérez Bes) reports the agency’s first notification of a personal-data breach in which the incident was allegedly executed by an AI agent using a known large language model. Per the notifier: the agent searched generic files for vulnerabilities, successfully logged in, then autonomously hunted application flaws, modified personal data, and accessed invoices. AEPD stresses the claim is from the organisation’s notification and still requires analysis; use of a given model does not imply the provider’s model or infrastructure was compromised or purpose-built for crime. Framing: shift from AI-assisted attacker tools (phishing copy, vuln search) toward agentic chaining of attack phases at machine speed — with implications for identity/credential controls, detection, and response timing. National Cryptologic Center (CCN) paradigm-shift context noted in wire coverage. Primary: AEPD blog; secondary: BleepingComputer 16 Sep 2026.

Product
AI agent / LLM used as offensive automation (incident notification; not a product CVE)
Versions
n/a
Exploited in Australia?
unknown
Patch to
Operators: treat agentic offence as faster/adaptive; tighten identity, API keys, and least privilege; accelerate detect/contain playbooks beyond manual-attack assumptions (per AEPD framing)

Primary: AEPD — primera notificación brecha por agente de IA (14 Sep 2026) · Vendor: AEPD blog (Spanish DPA) · BleepingComputer — Spain AEPD first AI-powered breach report (16 Sep 2026)

ai identity

Incident
Published 2026-09-14
Verified 2026-09-19

Brevo: stolen Cloudflare API key → edge Worker ClickFix on customer embeds (~5.5h)

Brevo status write-up (and BleepingComputer 17 September 2026) confirms that on 14 September 2026 an attacker used a compromised long-lived Cloudflare API key (hardcoded in Brevo application source; first misuse indicated late August) to deploy a Cloudflare Worker that rewrote responses at the CDN edge for about five and a half hours (approx. 16:07–20:30 UTC). Affected: brevo.com, sendinblue.com, login/account/my/onboarding.brevo.com, sibforms.com, plus Brevo forms script, Conversations widget, and SDK loader that customers embed. The Worker stripped CSP and served a fake Cloudflare “verify you are human” ClickFix lure (Win+R / Ctrl+V / Enter) downloading malware on Windows; on WordPress sites with a logged-in admin, Sansec/Bleeping also report attempted silent install of a malicious “Web Media Optimizer” plugin backdoor. Not affected per Brevo: app.brevo.com, API, email delivery, and customer account data held in Brevo. Remediation: Worker/routes/hostnames removed, key revoked, hardcoded credential removed, Vault + Cloudflare audit alerting planned. Distinct from Brevo’s earlier 9–10 September SSO boundary incident (Trezor phishing wave). Primary: Brevo status write-up; wire: BleepingComputer; Sansec first flagged customer-site impact (up to ~100k sites cited).

Product
Brevo (Sendinblue) marketing platform — Cloudflare CDN / embedded forms, Conversations widget, SDK loader
Versions
n/a (CDN-edge Worker rewrite; origin files unmodified). Customer WordPress sites embedding affected widgets during the window were at risk.
Exploited in Australia?
unknown
Patch to
If you embed Brevo forms/Conversations/SDK: confirm scripts are clean; WordPress admins who visited affected pages during the window should audit plugins (esp. unexpected “Web Media Optimizer” / must-use copies), rotate admin sessions, and scan for backdoors. Prefer integrity checks on third-party embeds; treat ClickFix clipboard lures as malware.

Primary: Brevo status — Cloudflare Worker ClickFix write-up (14 Sep 2026 incident) · Vendor: Brevo (status write-up) · BleepingComputer — Brevo supply-chain ClickFix (17 Sep 2026)

breaches cloud

Incident
Published 2026-09-14
Verified 2026-09-19

Spain AEPD: first notified personal-data breach allegedly executed by an AI agent

Spain's Agencia Española de Protección de Datos (AEPD) blog (14 September 2026; wired by BleepingComputer and SecurityWeek 16 September) says it received the first notification of a personal-data breach in which the incident was allegedly executed by an AI agent using a known large language model. Per the affected organisation's notification (not yet independently verified by AEPD): the agent searched generic files for flaws, completed a successful login, then autonomously probed the application, modified personal data, and accessed invoices. AEPD stresses the report is from the notifier and must be analysed; use of a named model does not imply the model provider was compromised or that the tool was purpose-built for crime. Relevance for defenders: treat agentic chaining (goal → tools → adapt) as a qualitative speed/scale shift for risk analysis, credential/API hygiene, and detection/containment timing — not only for Spanish controllers. Primary: AEPD blog; wires: BleepingComputer, SecurityWeek.

Product
AI agent / LLM-orchestrated attack path against an unspecified controller (notification stage)
Exploited in Australia?
unknown
Patch to
Review IR playbooks for agent-speed chaining; harden credentials/API keys/tokens; shorten detection and containment loops; do not treat AEPD's notice as verified attribution until the agency completes analysis

Primary: AEPD — first notified breach allegedly via AI agent (14 Sep 2026) · Vendor: AEPD (Spanish Data Protection Agency) · BleepingComputer — Spain AEPD AI-agent breach notice (16 Sep 2026)

ai identity

Incident
Published 2026-09-14
Verified 2026-09-19

Alchin Long Group (AU): The Gentlemen leak-site listing (ransomware.live)

Ransomware.live’s Australia country feed lists Sydney-based hardware conglomerate Alchin Long Group (alchinlong.com; Doric/Cowdroy/Colonial Castings and related brands) under the The Gentlemen brand — published 14 September 2026, discovered 15 September 2026 on the feed. No company statement, OAIC notice, Webber Insurance list entry, or ACSC advisory was located on this 16 September 2026 desk pass, so treat the listing as an unconfirmed extortion claim until a primary notice appears. Distinct from desk card sharp-office-thegentlemen-20260907 (same brand, different victim). Australian manufacturers and hardware suppliers should verify backups, MFA, and remote-access exposure.

Exploited in Australia?
unknown

Primary: Ransomware.live Australia (Alchin Long Group / The Gentlemen; discovered 15 Sep 2026) · Vendor: Alchin Long Group (company site — no incident notice found this pass) · Webber Insurance AU breaches list (no matching notice found this pass)

australia

Incident
Published 2026-09-14
Verified 2026-09-19

Penfold Motors (Vic): Storm ransomware via third-party software; customers notified

Cyber Daily (14 September 2026) reports Victorian dealership Penfold Motors (Peter Warren Automotive Group; six Vic sites) is contacting customers after Storm ransomware operators listed the firm (listing dated 17 August; early leak post mis-attributed a similarly named UK organisation before correction). Company statement dated 7 September: contained incident involving an external software provider that stored some Penfold data; systems restored and dealerships operating; investigation with the provider and forensic specialists ongoing. Impact described as basic contact details plus vehicle and servicing information (VINs and tax invoices appeared in published samples per Cyber Daily); Penfold said there was no evidence identity documents or bank-account data were involved, and that it notified the Australian Cyber Security Centre and the Office of the Australian Information Commissioner. Cyber Daily also notes Sharp Motor Group and Macquarrie as other recent Australian automotive/machinery victims tied to third-party supplier incidents in the same Storm wave (Macquarrie desk card updated separately). UPDATE 15 Sep 2026: Cyber Daily names Auto-IT as that third-party software firm (see auto-it-storm-20260915). Primary: Cyber Daily exclusive with company quotes.

Exploited in Australia?
yes

Primary: Cyber Daily — Penfold Motors / Storm (14 Sep 2026) · Webber Insurance AU data-breaches list (September 2026 entry)

breaches australia

Incident
Published 2026-09-14
Verified 2026-09-19

HBO Max Reddit account hijacked for 108 ClickFix ads (PasteSwitch stealers)

BleepingComputer (14 September 2026) reports that the verified Reddit account u/hbomax was hijacked and used to run about 108 malicious advertisements over roughly 48 hours. Ads used ClickFix social engineering (victims paste commands into Windows Run/PowerShell or macOS Terminal) and redirected to lookalike sites (including hbomaxx[.]us). Hudson Rock and ADAMnetworks link the activity to a broader campaign they call PasteSwitch delivering information stealers, loaders, crypto clippers, and fake wallets on Windows and macOS; one macOS chain referenced “AMOS helper” persistence under a .com.apple.accountsd-style directory. Some ads impersonated HBO Max; others pushed fake AI/developer/macOS utilities. BleepingComputer said HBO / Warner Bros. Discovery had not responded at publication. Distinct from prior desk ClickFix/EtherHiding cards. Primary/wire: BleepingComputer.

Product
n/a (Reddit advertising / social engineering; Windows and macOS endpoints)
Versions
n/a
Exploited in Australia?
unknown
Patch to
Treat unexpected Run/Terminal paste prompts as hostile; verify streaming-app installs from official stores; revoke sessions if you interacted with u/hbomax ads in the window

Primary: BleepingComputer — HBO Max Reddit ClickFix (14 Sep 2026)

breaches identity

Incident
Published 2026-09-14
Verified 2026-09-19

3BB (Thailand ISP): Hunt.io finds MeshCentral backdoor, RADIUS targeting

Hunt.io (14 September 2026; The Hacker News same day) describes an intrusion against 3BB, a major Thai broadband provider. Researchers captured an attacker-operated server still live on 3 June 2026 that held tooling run from inside 3BB’s network, a MeshCentral deployment reporting to www.ayuthayatech[.]com under device group TH-3BB (agents with root), cleanup scripts that preserved MeshCentral, SSH password spraying against 55+ internal hosts, probes of agent.3bb.co[.]th, and scripts aimed at copying RADIUS subscriber credential databases (targeted; Hunt.io does not state confirmed exfiltration). The same cache held a complete exploit for FortiGate SSL-VPN CVE-2024-21762 aimed at mail.3bb.co[.]th and a valid 3BB VPN certificate plus Jasmine-network sessions (shared infrastructure; Jasmine breach not confirmed). Primary: Hunt.io; secondary: THN.

Product
3BB broadband network (FortiGate SSL-VPN; MeshCentral; RADIUS)
Versions
FortiGate firmware affected by CVE-2024-21762 reported on targeted gateway; MeshCentral abused as living-off-the-land C2
Exploited in Australia?
unknown
Patch to
ISPs/enterprises: patch FortiGate SSL-VPN (CVE-2024-21762 class); hunt unauthorized MeshCentral/RMM; rotate RADIUS and VPN credentials if similar tooling seen

Primary: Hunt.io — 3BB FortiGate / MeshCentral intrusion (14 Sep 2026) · CVE: CVE-2024-21762 · The Hacker News (14 Sep 2026)

breaches network identity

Incident
Published 2026-09-14
Verified 2026-09-19

Telus warns customers of multi-month account breaches via stolen credentials

SecurityWeek (14 September 2026) reports Telus is notifying some Canadian consumer telecom customers that attackers accessed their accounts between February 2025 and June 2026 using compromised credentials. Accessed data included names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details, and payment history. Telus says the stolen account information was used to push customers toward competitors and, in some cases, to make unauthorised service changes. Impacted credentials were reset and enhanced monitoring applied; Vancouver Police were notified and complimentary identity-theft protection offered. Headcount and exact credential source were not published; the description is consistent with credential stuffing or other account takeover using third-party credentials, which Telus has not explicitly confirmed. Distinct from the March Telus Digital / ShinyHunters incident. Primary/wire: SecurityWeek pending a public Telus notice URL.

Product
Telus consumer telecom accounts (Canada)
Versions
n/a (credential-based account takeover; not a product CVE)
Exploited in Australia?
unknown
Patch to
n/a for other operators: force password resets on suspected ATO, monitor SIM/port and plan-change abuse, offer identity monitoring where appropriate

Primary: SecurityWeek — Telus account breaches (14 Sep 2026)

breaches identity

Incident
Published 2026-09-12
Verified 2026-09-19

Revolut: Italian gov-domain impersonation — ~680 high-profile accounts; $3M ransom demand

TechCrunch (12 September 2026) and BleepingComputer (14 September) report Revolut confirmed it disclosed sensitive customer information to an unauthorised third party after fraudulent information requests were sent from a legitimate government-agency email domain. SecurityWeek (17 September 2026) adds quantified scope: attackers impersonated an Italian government agency for about five months, obtained data from roughly 680 high-profile accounts, and are demanding a $3 million ransom. A Revolut spokesperson described a sophisticated external impersonation scam; the company blocked the mailbox, alerted the agency, law enforcement and regulators, and said systems and customer funds were unaffected. Customer notifications list identity and contact details (name, date of birth, postal/email addresses, phone), copies of passports or driver’s licences, facial verification selfies, account statements (including IBAN), withdrawal records, and full transaction histories (including Bitcoin activity). Primary: TechCrunch with Revolut confirmation; NEW scope wire: SecurityWeek 17 Sep; secondary: BleepingComputer 14 Sep; not a core-system compromise.

Product
Revolut (fintech / KYC document and statement handling)
Versions
n/a (business-process / legal-request social engineering; not a product CVE)
Exploited in Australia?
unknown
Patch to
n/a for operators of other platforms: verify government legal requests out-of-band; treat unexpected KYC/doc disclosure notices as phishing risk for affected customers

Primary: TechCrunch — Revolut fake government-request disclosure (12 Sep 2026) · SecurityWeek — 680 accounts / $3M ransom / 5 months (17 Sep 2026)

breaches identity

Incident
Published 2026-09-11
Verified 2026-09-19

Japan Digital Agency: GSS VPN flaw may have exposed ~246,000 personnel records

Japan's Digital Agency (news 11 September 2026; English wire coverage 14 September) says unauthorised access to Government Solution Service (GSS) may have exposed about 246,000 personal-information records. Detection on 25 June 2026 (large-scale file access via a maintenance/operations account); on 9 July investigators found a third party had used a vulnerability in a network-connected VPN device to enter the system. That day the agency suspended the account and cut external communication from the compromised equipment. Possible leaked fields include names, email addresses, phone numbers, and addresses of GSS-using agency staff, associated public officials, and contractors/individuals who worked with those agencies. Agency says My Number, bank accounts, and pension numbers were not in the exposed set; no secondary misuse confirmed at publication. Q&A: vulnerability was previously published (not a zero-day) with a medium CVSS rating; product/CVE withheld for security. Primary: Digital Agency notice; secondary: BleepingComputer.

Product
Government Solution Service (GSS) — VPN / network-connected device (vendor not named)
Versions
n/a (agency: medium-severity previously disclosed VPN flaw; CVE/product not published)
Exploited in Australia?
unknown
Patch to
Government/enterprise VPN estates: prioritise medium-rated VPN CVEs on internet-facing gear; rotate maintainer credentials after anomalous file-access; notify affected staff about phishing risk

Primary: Digital Agency (Japan) — GSS unauthorised access / possible personal information leak (11 Sep 2026) · Vendor: Digital Agency Q&A on the GSS incident · BleepingComputer (14 Sep 2026)

breaches identity network

Incident
Published 2026-09-10
Verified 2026-09-19

Way Forward (AU charity): payments suspended after third-party CMS cyber incident

Cyber Daily (10 September 2026) reports Australian financial-hardship charity Way Forward disclosed a cyber incident at an external customer-management platform provider. In a 9 September statement the charity said payment arrangements initiated through the affected system were unavailable, clients were notified as a precaution, and creditors were asked for a temporary payment moratorium so client credit reports stay unaffected. A spokesperson later told Cyber Daily the provider’s initial analysis indicated impacted information related mostly to the provider’s own company, still subject to change while the provider investigation continues. No OAIC notice or named vendor was fetched on this pass; treat data-impact scope as provisional. Primary: Cyber Daily quoting Way Forward; company website returned a challenge page this pass.

Product
Way Forward customer-management / payment processing (third-party platform)
Versions
n/a (third-party service incident; not a product CVE)
Exploited in Australia?
unknown
Patch to
n/a for other operators: verify third-party CMS/payment vendors; watch for phishing against notified Way Forward clients

Primary: Cyber Daily — Way Forward third-party CMS incident (10 Sep 2026) · Vendor: Way Forward (charity site; statement via Cyber Daily quote) · Webber Insurance AU breaches list (September 2026 entry)

breaches australia identity

Incident
Published 2026-09-10
Verified 2026-09-19

NSW Online Registry: prosecutors say ChatGPT wrote scraper for ~8,769 restricted court docs

ABC News (10 September 2026) reports a Downing Centre Local Court hearing for Christopher John Duff, 40, who has pleaded not guilty to four counts of accessing restricted data held in a computer. NSW Department of Communities and Justice discovered a breach of the NSW Online Registry (court-user login portal) in March 2025; police say cybercrime detectives investigated alleged unauthorised access to 8,769 restricted documents between January and March 2025 (AVOs, details of minors, and other DCJ forms). Prosecutors allege Duff used ChatGPT to create Python scraper-style scripts for bulk download, then sought legal advice and “coaching” from ChatGPT after his registry login was shut down and before charge — and intend to rely on ChatGPT conversation records plus forensic testimony in what is described as among the first such Australian cases. Hearing stalled on volume (~10,000+ pages of proposed exhibits). Charged April 2025 after a search warrant in Sydney’s east; on bail. Allegations unproven. Primary: ABC; wire: ACS Information Age (10 Sep).

Product
NSW Online Registry (Department of Communities and Justice)
Versions
n/a (alleged authorised-login misuse / scraper; not a product CVE)
Exploited in Australia?
yes
Patch to
n/a (criminal matter); operators: rate-limit/monitor bulk registry export, revoke credentials on anomaly, treat gen-AI chat logs as potential evidence

Primary: ABC News — Duff / NSW Online Registry ChatGPT hearing (10 Sep 2026) · ACS Information Age (10 Sep 2026)

breaches australia ai identity

Incident
Published 2026-09-10
Verified 2026-09-19

PivotC2: CVE-2025-25249 FortiGate CAPWAP RCE delivers Node.js RAT (178 victims)

SOCRadar Threat Research (covered 10 September 2026 by SecurityWeek) reports active exploitation of CVE-2025-25249, a heap-based buffer overflow in the FortiOS / FortiSwitchManager cw_acd CAPWAP daemon (UDP 5246), delivering PivotC2 — a Node.js post-exploitation RAT for FortiGate with interactive shell, tunneling, scanning and config/credential harvesting. SOCRadar cites NVD CVSSv3 9.8; Fortinet advisory FG-IR-25-084. Exploitation observed since at least July 2026; ~30k targeted IPs and 178 confirmed PivotC2 sessions (majority US; two full US intrusions with data theft). Tradecraft assessed as Russian-speaking cybercrime; RAT comments suggest AI-assisted development. Affected examples: FortiOS 7.6.0–7.6.3, 7.4.0–7.4.8, 7.2.0–7.2.11, 7.0.0–7.0.17; FortiSwitchManager 7.2.0–7.2.6 and 7.0.0–7.0.5. Fixed: FortiOS 7.6.4 / 7.4.9 / 7.2.12 / 7.0.18; FortiSwitchManager 7.2.7 / 7.0.6. Distinct from desk card fortinet-fortimonitoronsight-20260909. Primary: SOCRadar; vendor: FG-IR-25-084; wire: SecurityWeek.

Product
Fortinet FortiOS; FortiSwitchManager (cw_acd / CAPWAP)
Versions
FortiOS 7.6.0–7.6.3, 7.4.0–7.4.8, 7.2.0–7.2.11, 7.0.0–7.0.17; FortiSwitchManager 7.2.0–7.2.6, 7.0.0–7.0.5; fixed FortiOS 7.6.4/7.4.9/7.2.12/7.0.18; FSM 7.2.7/7.0.6
CVSS
9.8 (NVD CVSSv3 per SOCRadar)
Exploited in Australia?
unknown
Patch to
Upgrade FortiOS/FortiSwitchManager to fixed builds in FG-IR-25-084; hunt CAPWAP/Node.js PivotC2 IoCs and C2 sessions

Primary: SOCRadar — PivotC2 / CVE-2025-25249 · Vendor: Fortinet FG-IR-25-084 · CVE: CVE-2025-25249 · SecurityWeek (10 Sep 2026)

vulnerabilities network

Incident
Published 2026-09-09
Verified 2026-09-19

Gigabud Android banking trojan clones apps via Vwork work-profile (Group-IB)

Group-IB (9 September 2026) documents a Gigabud (GoldFactory) banking-trojan chain that installs a second Android app, Vwork, to create a work profile and drop a tampered banking app inside it. Work-profile isolation hides the trojan from the banking app’s malware checks on the personal profile. Confirmed on infected devices in Indonesia. Gigabud arrives as a sideloaded fake airline/tax/government app, demands Accessibility and overlay permissions, overlays fake logins and lock-screen capture, then drives taps via Accessibility under a black screen. Vwork is based on open-source Shelter but strips caller checks so other apps can create profiles, clone apps, and open them; setup is reduced to a single Chinese-language prompt. Order observed: Gigabud → Vwork within minutes → cloned banking app. Distinct from desk card mantax-otax-android-20260910. Primary: Group-IB; wire: The Hacker News (10 Sep 2026).

Product
Android (Gigabud RAT / Vwork work-profile helper)
Versions
n/a (malware; sideloaded outside Play)
Exploited in Australia?
unknown
Patch to
Avoid sideloaded “gov/airline/tax” APKs; deny Accessibility to untrusted apps; remove unknown work profiles; reset device if compromise suspected

Primary: Group-IB — Vwork app cloning / Gigabud (9 Sep 2026) · The Hacker News (10 Sep 2026)

breaches identity

Incident
Published 2026-09-09
Verified 2026-09-19

Surfshark: internal test server and proxy accessed after misconfiguration

Surfshark's 9 September 2026 incident report says unusual activity on an internal engineering test server was confirmed on 2 September 2026 after a human misconfiguration left the host reachable from the internet. The company contained the same day and finished remediation by 5 September. An unauthorised party accessed limited engineering material (parts of system binaries, internal service configurations, and some build-related credentials that had appeared in code history). Access was also gained to an isolated content-accessibility optimisation VPS used as a proxy with no user identities, IP addresses, encryption keys, or browsing traffic. Surfshark states no user data or production VPN services were affected, no customer action is required, and exposed secrets were rotated or retired. Primary: Surfshark blog incident report; wire: BleepingComputer (10 Sep 2026).

Product
Surfshark (internal engineering / content-accessibility proxy; not production VPN)
Exploited in Australia?
unknown
Patch to
No customer action per vendor; operators using Surfshark should still prefer the official report over third-party summaries

Primary: Surfshark — September 2026 incident report · Vendor: Surfshark (vendor) · BleepingComputer (10 Sep 2026)

breaches cloud identity

Incident
Published 2026-09-09
Verified 2026-09-19

US Treasury/DoJ: Xinbi Guarantee scam marketplace seized; $52.8M crypto frozen

US Treasury OFAC (press release sb0624) designated Xinbi Guarantee, a Chinese-language illicit marketplace supporting cyber scams, fraud, money laundering, and related crime targeting Americans, plus two supporting digital-currency entities — coordinated with DoJ Scam Center Strike Force infrastructure and wallet seizures. THN (9 September 2026) reports ~$52.8M in cryptocurrency frozen across 52 wallets and ~$12M held in two seized payment wallets; Telegram channels hosting the market dismantled. Xinbi acted as escrow between scam-center operators and vendors (pig-butchering sites, laundering, trafficking labour). Treasury notes reported use by North Korean hackers and OFAC-designated entities including Jin Bei Group and Prince Group TCO affiliates. Primary: Treasury OFAC; wire: THN (DoJ PR was 401 from this pass).

Exploited in Australia?
unknown

Primary: US Treasury OFAC — Xinbi Guarantee (Sep 2026) · The Hacker News (9 Sep 2026); DoJ Scam Center Strike Force

breaches identity cloud

Incident
Published 2026-09-09
Verified 2026-09-19

BlueMoon kit: APT31/JungleBamboo + UTA0560 GRIMWEDGE chain Chrome/Windows 0-days

Proofpoint (9 September 2026) documents BlueMoon, chaining CVE-2026-85046 (Chrome V8 type confusion), CVE-2026-87491 (V8/WebAssembly sandbox escape; patch-gap 0-day), and CVE-2026-85880 (Windows ALPC heap overflow LPE / AppContainer escape; Microsoft September Patch Tuesday + CISA KEV). First in-the-wild use attributed to China-aligned APT31 (Violet Typhoon / Judgement Panda / JungleBamboo) from 28 August 2026; other espionage clusters rapidly reused the kit. UPDATE 15 September 2026 desk (Volexity blog 9 Sep; THN wire 15 Sep): Volexity details two China-nexus clusters using the same byte-identical exploit chain against NGOs via spearphishing through reflected XSS on a legitimate US university site. UTA0560 deploys GRIMWEDGE (obfuscated JavaScript backdoor via MSI custom actions; C2 ocr.opusaccel[.]top; recon/file/process/Run/Upload; no built-in persistence). JungleBamboo/APT31 deploys SUPERSTOMP loader then LONGTALE (aka GemStone) credential-stealing Chrome extension masquerading as Google Gemini (keylogging, cookies, screenshots, ~30s exfil). Distinct from desk cards cve-2026-85046 / cve-2026-87491 / ms-september-2026-patch-tuesday — this card is the shared kit and post-exploitation. Primary: Proofpoint; secondary: Volexity; wire: THN.

Product
Google Chrome / Chromium; Microsoft Windows (ALPC)
Versions
Chrome lacking CVE-2026-85046 / CVE-2026-87491 stable builds (patch-gap 0-days); Windows prior to September 2026 CVE-2026-85880 updates
Exploited in Australia?
unknown
Patch to
Update Chrome/Edge/Chromium to builds with CVE-2026-85046 and CVE-2026-87491; apply Microsoft September 2026 updates for CVE-2026-85880; hunt NGO spearphishing / XSS redirects and GRIMWEDGE/LONGTALE indicators per Volexity

Primary: Proofpoint — BlueMoon exploit kit (9 Sep 2026) · Vendor: Microsoft — CVE-2026-85880 · CVE: CVE-2026-85046, CVE-2026-87491, CVE-2026-85880 · Volexity — UTA0560 GRIMWEDGE / JungleBamboo LONGTALE (9 Sep 2026); THN 15 Sep

vulnerabilities network identity

Incident
Published 2026-09-09
Verified 2026-09-19

Veradigm: patient PII/SSN copied via vendor API credentials; Gentlemen claim 3.5M records

BleepingComputer (9 September 2026) covers Veradigm's SEC disclosure of a third-party vendor incident: an attacker obtained vendor credentials for a Veradigm customer-services API and copied patient personal details including some Social Security numbers; clinical/medical content and the broader Veradigm network were not accessed per the filing. Veradigm says a small number of customers were affected, notified law enforcement, and is offering credit monitoring where applicable. The Gentlemen ransomware group claimed the intrusion on 5 September and listed Veradigm on its leak site, alleging about 3.5 million patient records and a leak deadline of 11 September 2026 — treat volume and attribution as actor claims pending Veradigm confirmation. Distinct from desk card sharp-office-thegentlemen-20260907 (AU Sharp Office listing). Primary: BleepingComputer (SEC filing).

Exploited in Australia?
unknown

Primary: BleepingComputer — Veradigm / Gentlemen (9 Sep 2026)

breaches identity cloud

Incident
Published 2026-09-09
Verified 2026-09-19

AdaptHealth: 4.1M people exposed after June contractor social-engineering breach

BleepingComputer (9 September 2026) reports AdaptHealth confirmed about 4.1 million people were exposed in a cyberattack discovered in July. SEC filing 2 July 2026 disclosed access to cloud business apps including patient management, document storage, and EHR portals. Company update: compromise on 5 June 2026 via social engineering of a third-party contractor's privileged account; ransomware demand around 15 June; data classes named include names, contact and demographic data, health insurance, and health information. HHS submission lists 4,115,802 individuals. Notifications and 12-month credit monitoring offered. Reporting attributes the actor to ShinyHunters; BleepingComputer could not find a current AdaptHealth listing on that group's portal. No Australian nexus identified this pass. Primary: BleepingComputer (company filings).

Exploited in Australia?
unknown

Primary: BleepingComputer — AdaptHealth 4.1M (9 Sep 2026)

breaches identity cloud

Incident
Published 2026-09-09
Verified 2026-09-19

Gellibrand Support Services (AU NDIS): Anubis ransomware leak-site listing

Ransomware.live discovered on 9 September 2026 that the Anubis ransomware group listed Gellibrand Support Services on its leak site. Gellibrand is a Victorian NDIS disability support provider (Sunshine VIC 3020 and Ballarat offices; gellibrand.org.au). Treat as a leak-site claim until the organisation or OAIC publishes a primary incident statement. No data-volume figure verified on this pass. Primary: Ransomware.live listing.

Exploited in Australia?
unknown

Primary: Ransomware.live — Anubis / Gellibrand (9 Sep 2026) · Vendor: Gellibrand Support Services (no incident statement fetched this pass)

breaches australia

Incident
Published 2026-09-08
Verified 2026-09-19

Slim Spider: Brazil e-crime cluster steals crypto custody secrets and Pix-linked cloud creds

CrowdStrike (covered by The Hacker News, 8 September 2026) tracks Slim Spider, a Brazil-based e-crime cluster active against Brazilian financial institutions since at least March 2026. In a late-March 2026 multi-stage intrusion at a Brazilian financial institution, the actor targeted crypto custody assets and Pix instant-payment infrastructure: custom Bash scripts queried cloud instance metadata for temporary credentials, enumerated secrets in the cloud credential manager, used Foundry cast to derive an Ethereum wallet address from a stolen private key, and implemented cloud-native signing via OpenSSL. The actor also pivoted to Azure DevOps to run malicious pipelines that deployed implants across a managed Kubernetes cluster, including backdoors mimicking legitimate infrastructure binaries (e.g. "spi" impersonating Sistema de Pagamentos Instantâneos). Primary: CrowdStrike adversary page; wire: The Hacker News.

Exploited in Australia?
unknown

Primary: CrowdStrike — Slim Spider adversary page · Vendor: The Hacker News (8 Sep 2026) · The Hacker News — Slim Spider / Brazil FI (8 Sep 2026)

breaches cloud identity

Incident
Published 2026-09-08
Verified 2026-09-19

Florida FLHSMV confirms DAVID DMV breach via stolen Plant City PD credentials

UPDATE 11 September 2026: the Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a DAVID driver-database breach after ShinyHunters claimed compromise. In a statement posted to X (status 2098239548660514979), FLHSMV said it learned of the breach on 4 September 2026, that it was quickly mitigated, and that no further breach is ongoing. Investigation found attackers used compromised credentials of a single Plant City Police Department user that had been improperly stored on the employee’s personal electronic device. FLHSMV notified the Florida Office of the Attorney General and is working with the Florida Digital Service and Florida Department of Law Enforcement; further detail withheld pending the criminal investigation. FLHSMV has not disclosed how many records were accessed and has not confirmed ShinyHunters’ claim of 200,000+ records. ShinyHunters had claimed a password-reset flaw and multi-account access (including DMV/FBI accounts) iterating DAVID record IDs from 3 September — FLHSMV’s credential finding differs from that claim. Original 8 September desk card covered the unconfirmed extortion claim with Epstein DAVID screenshot as purported proof. No Australian nexus identified. Primary: FLHSMV X statement; wire: BleepingComputer (11 Sep).

Product
Florida DAVID (Driver And Vehicle Information Database) / FLHSMV
Versions
n/a (credential compromise of LE agency user)
Exploited in Australia?
unknown
Patch to
n/a for AU orgs; lesson: no LE/DMV credentials on personal devices; rotate exposed agency accounts

Primary: FLHSMV statement on X (4 Sep learn / posted around claim period) · Vendor: Florida FLHSMV · BleepingComputer (11 Sep 2026); earlier claim story 8 Sep

breaches identity

Incident
Published 2026-09-08
Verified 2026-09-19

F5 BIG-IP APM: PoisonedRefresh Linux rootkit / in-memory PHP web shell (Sophos/ESET)

BleepingComputer (8 September 2026) reports Sophos analysis of a Linux rootkit targeting F5 BIG-IP APM environments that intercepts PHP loading and injects a fileless web shell in memory so on-disk PHP files stay unchanged. ESET tracks the family as PoisonedRefresh. Sophos describes a separate installer/propagation stage that tampers with Apache /usr/sbin/httpd, SELinux policy, and persistence across BIG-IP upgrade images; the second stage uses RC4 string hiding, hooks __libc_start_main and apr_dso_load, and injects into APM webtop scripts such as apm_css.php3, full_wt.php3, and webtop_popup_css.php3. The web shell accepts magic requests, eval()s decrypted content, and returns HTTP 201 disguised as text/css; a password-protected local UNIX socket can spawn Bash without a TCP listener. Sophos says the payload was likely deployed after exploitation of CVE-2025-53521 (critical RCE that F5 reclassified from DoS in March). Shadowserver reportedly tracked about 795 internet-exposed BIG-IP APM endpoints still vulnerable to that CVE at time of writing. Hunt: Apache workers reading /proc/self/maps, changing libphp memory protections, creating /run/bigtlog.pipe, launching /bin/bash, unusual POSTs to targeted .php3 paths, or HTTP 201 + text/css responses. Wire: BleepingComputer; research: Sophos / ESET.

Product
F5 BIG-IP APM (Access Policy Manager) / Apache PHP webtop
Versions
Environments vulnerable to CVE-2025-53521 and/or showing PoisonedRefresh installer artefacts; confirm against F5 advisory for your TMOS branch
Exploited in Australia?
unknown
Patch to
Patch CVE-2025-53521 per F5; hunt Sophos IoCs (httpd integrity, SELinux changes, /run/bigtlog.pipe, magic .php3 POSTs, HTTP 201 text/css); rebuild from known-good images if compromised

Primary: BleepingComputer — BIG-IP APM PoisonedRefresh rootkit (8 Sep 2026) · Vendor: F5 security advisories portal · CVE: CVE-2025-53521 · The Hacker News (9 Sep 2026)

breaches network cloud identity

Incident
Published 2026-09-08
Verified 2026-09-19

Vietnam-linked APIS Elasticsearch leak: 220.8M passenger/crew travel records

BleepingComputer exclusive (8 September 2026): Kinryū Labs found an internet-reachable Elasticsearch cluster named "pax-info" (Viettel-assigned IP space, Hanoi) holding Advance Passenger Information System (APIS) data — 210,318,069 passenger and 10,465,631 crew records (220,783,700 entries, ~107 GB across 29 indices) spanning January 2017 to April 2026. Fields included names, dates of birth, sex, nationalities, passport/travel-document numbers and expiry, issuing countries, plus flight numbers/dates, airlines, origin/destination/transit airports, seats, baggage refs, and scheduled/estimated/actual times. Sample records reviewed included Korean, Chinese, Canadian, and New Zealand nationalities among others; many international carriers across Asia-Pacific, Europe, and the Middle East appear, so travellers who flew to/from/through Vietnam may be affected (counts are travel records, not unique people). Access path: open internet returned HTTP 401, but a cloud-based path reached the cluster which then accepted default credentials (FOFA saw the host/port from Oct 2022; exposure duration via the second path unknown). Kinryū reported to Vietnamese authorities, airlines, and national CERTs from 3 June 2026; access remediated 8 June 2026 after Singapore Airlines security helped coordinate containment. No ransom notes or sales listings found; without server logs, prior copying cannot be ruled out. Operator organisation not confirmed. Kinryū expects a fuller technical write-up on its blog later this week. Primary wire: BleepingComputer; researcher: Kinryū Labs.

Exploited in Australia?
unknown

Primary: BleepingComputer — Vietnam-linked APIS leak (8 Sep 2026) · Vendor: Kinryū Labs reports (technical write-up pending) · Kinryū Labs

breaches australia cloud identity

Incident
Published 2026-09-07
Verified 2026-09-19

F5 BIG-IP APM: in-memory PHP web shell on webtop scripts (Sophos / c05d5254)

Sophos analysis (published ~7 September 2026; THN 9 September) describes malware on compromised F5 BIG-IP Access Policy Manager appliances that injects a PHP web shell into memory when Apache loads APM webtop scripts apm_css.php3, full_wt.php3 or webtop_popup_css.php3 — so on-disk file hashes can look clean. F5 previously tracked related activity as malware family c05d5254 and warned those three scripts can be modified or hold in-memory-only shells (IoC list from March). Defenders must not rely on disk-only webshell scans; compare runtime/Apache memory and hunt the F5 IoCs. Related CVE context in wires includes CVE-2025-53521 in some coverage. Watchlist: F5. Primary research: Sophos; wire: THN; vendor IoC context: F5.

Product
F5 BIG-IP Access Policy Manager (APM webtop)
Versions
Compromised APM appliances loading named webtop PHP scripts (see F5 c05d5254 IoCs)
Exploited in Australia?
unknown
Patch to
Hunt F5 c05d5254 IoCs; inspect runtime/memory not only disk; rebuild/rotate creds on confirmed compromise; keep BIG-IP patched

Primary: Sophos — in-memory PHP web server rootkit (BIG-IP APM) · CVE: CVE-2025-53521 · The Hacker News (9 Sep 2026)

vulnerabilities network

Incident
Published 2026-09-07
Verified 2026-09-19

BigBear 2.0 Evilginx2 PhaaS: MFA bypass at 258 orgs; 5,137 credential records

CloudSEK (7 September 2026) details BigBear 2.0, an Evilginx2-based phishing-as-a-service panel targeting Microsoft 365 with an "offy" phishlet. Researchers obtained admin access to the operator panel (alias "General Boss"): 42 VPS nodes over the campaign lifecycle (many on Vultr/The Constant Company), geo-matched residential proxies, Telegram exfiltration bots for at least five affiliates, and cookie replay after victims complete MFA. Panel telemetry cited by CloudSEK: 5,137 credential records (474 complete MFA-bypassed authentications, 1,032 plaintext passwords, 4,148 session cookies) across 3,331 unique victim IPs in 40+ countries; BleepingComputer notes 258 organisations with at least one completed MFA-bypass compromise (461 in the broader targeting set). Custom JS can weaken phishing-resistant MFA (FIDO2/WebAuthn) toward weaker methods. Operation still active at publish time. Primary: CloudSEK blog; wire: BleepingComputer (7 Sep 2026).

Product
Microsoft 365 / Entra ID (targeted via AiTM phishing)
Exploited in Australia?
unknown
Patch to
Enforce phishing-resistant MFA (FIDO2/passkeys); conditional access / token protection; hunt unexpected M365 session cookies and Impossible Travel; user reporting of fake Microsoft login pages

Primary: CloudSEK — Tracking BigBear 2.0 Evilginx2 PhaaS (7 Sep 2026) · BleepingComputer (7 Sep 2026)

breaches identity cloud

Incident
Published 2026-09-07
Verified 2026-09-19

Sharp Office (AU): company confirms cyber incident amid Thegentlemen leak-site claim

Cyber Daily (9 September 2026) quotes a Sharp Office spokesperson confirming a cyber incident affecting some parts of its systems: the Broadmeadow office-technology supplier engaged external responders, contained and restored business systems (operational at time of quote), and said it notified the Australian Cyber Security Centre. The Gentlemen ransomware group had listed Sharp Office (sharpoffice.com.au) claiming a data publish window; ransomware.live shows discovered 2026-09-07. Investigation ongoing; no public headcount or OAIC notice fetched this pass. Distinct from earlier Sharp Motor Group third-party incident. Primary: Cyber Daily with company confirmation; listing: ransomware.live AUS.

Exploited in Australia?
unknown

Primary: Cyber Daily — Sharp Office confirms incident (9 Sep 2026) · Vendor: Sharp Office (company site) · ransomware.live — AUS listing (Thegentlemen / Sharp Office, discovered 7 Sep 2026)

breaches australia

Incident
Published 2026-09-05
Verified 2026-09-19

Mathspace: Metabase breach exposes ~1.08M AU/NZ student, parent and staff records

Mathspace's incident blog (published 5 September 2026, updated 6 September 2026) says attackers exploited a security vulnerability in its self-hosted Metabase internal-reporting install, obtaining administrator access without a legitimate login. Metabase published a critical advisory and patches on 6 August 2026; Mathspace says its vulnerability-notification process did not escalate that advisory, and it only updated on 29 August after a later Metabase notice. Unauthorised access dated from 10 August 2026 AEST; data was downloaded from the Australian reporting database on 27 August; Mathspace confirmed the historical access on 3 September. About 1,079,819 people in Australia and New Zealand were affected (students, parents/guardians, school staff, and Mathspace staff). Exported fields included user ID, username, names, email, country, time zone, user type, email-verification status, and last-active / last-login / date-joined. Passwords, SSO tokens, API credentials, academic records and school-link tables were not exposed. School notifications began 4 September. Mathspace notified the OAIC, ASD's ACSC, NZ OPC, NZ NCSC, and Australian state/territory education departments. The timeline matches Metabase CVE-2026-72898 (GHSA-vwf4-m7j8-wcjf); Mathspace's post does not name the CVE. Primary: Mathspace incident blog.

Exploited in Australia?
yes

Primary: Mathspace incident blog (updated 6 Sep 2026) · Vendor: Metabase GHSA-vwf4-m7j8-wcjf (CVE-2026-72898) · CVE: CVE-2026-72898 · Metabase — August 2026 vulnerability post

breaches australia cloud

Incident
Published 2026-09-04
Verified 2026-09-19

Trezor: ShipMonk (~67k) plus Brevo phishing wave (347k emails / ~2.5k clicks)

Trezor's blog (original 13 August 2026; updated 4 September 2026) says ShipMonk, a shipping provider, suffered unauthorized access. On 2 September 2026 Trezor was told the breach also held order data from prior cooperation (November 2019–August 2021) that ShipMonk had repeatedly assured in writing had been deleted. That tranche affects about 67,000 further US customers with full exposure of name, email, phone, shipping address and order number; all were emailed from privacy@satoshilabs.com. Hardware wallets are not affected; phishing and physical-security risk rise for exposed addresses. Earlier August disclosures covered customers who ordered to US/UK/Sweden/Colombia/Brazil/Italy/Portugal between 10 May and 8 August 2026 (about 11,742 in the original summary, with later August clarifications). Reporting ties ShipMonk's break-in to exploitation of Metabase CVE-2026-72898 (CVSS 10.0 SQLi) and names ShinyHunters as a claimed extortion actor — treat that attribution as third-party reporting, not a Trezor confirmation. Primary: Trezor blog update. UPDATE 11 September 2026: Trezor’s Brevo blog says on 9 September 2026 Brevo (newsletter platform) had a security incident affecting 120 Brevo accounts; an unauthorised actor sent mail from customer accounts including Trezor’s. About 347,000 opt-in newsletter addresses were exposed for further phishing risk; no other Trezor systems were touched and the Brevo account was suspended. Phishing used subject “Critical Security Alert: STM32 Entropy Vulnerability,” linking to a fake app that asked for wallet backups. Trezor took the phishing domain down at DNS within ~20 minutes, limiting clicks to about 2,500 people, and notified customers. Do not enter seed phrases from email links. Primary Brevo post: trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider; wire: BleepingComputer (11 Sep).

Exploited in Australia?
unknown

Primary: Trezor blog — ShipMonk incident (updated 4 Sep 2026) · Vendor: Trezor (vendor) · CVE: CVE-2026-72898 · Trezor — Brevo incident (10 Sep 2026); also BleepingComputer 11 Sep

breaches identity cloud

Incident
Published 2026-09-03
Verified 2026-09-19

PREY-0058: IT help-desk vishing + AiTM token theft → M365/SaaS data extortion

Arctic Wolf Pack Alert (3 September 2026) tracks PREY-0058: executives (directors/VPs) are cold-called by actors impersonating internal IT/help desk and steered to authentication-themed lure domains (assignpasskey.com, mfaregister.com, nowsso.com, oskeysetup.com, oursso.com, passkey-mfa.com, passkeydeploy.com, registermymfa.com, setpasskey.com and org-specific subdomains). An operator-gated AiTM Microsoft 365 login harvests credentials and MFA approvals; stolen sessions are replayed via residential proxies (notably NodeMaven, often same geo/ASN as the victim). Post-access discovery hits SharePoint/Entra (SearchQueryPerformed with contentclass:STS_Site/STS_Web and indexdocid pagination), then bulk exfil from SharePoint, OneDrive, Exchange, and Box — no endpoint malware or network lateral movement observed. Overlaps GTIG UNC6671 tradecraft; related extortion brands cited include BlackFile, Pink, Helix, Cinder, and Redact (affiliate/rebrands, not a single proven identity). Targets primarily US construction/engineering, healthcare/pharma, real estate, finance, professional services. Defences: phishing-resistant MFA (FIDO2/device-bound passkeys), Conditional Access (device compliance; block proxy/hosting ASN), Continuous Access Evaluation, tighten SharePoint scope, train staff that IT will not cold-call for passkey enrolment. Wire: The Hacker News (7 Sep 2026). Distinct from BigBear Evilginx2 PhaaS already on desk.

Product
Microsoft 365 / Entra ID / SharePoint / Exchange Online (and connected SaaS e.g. Box)
Exploited in Australia?
unknown
Patch to
Phishing-resistant MFA (FIDO2/passkeys); Conditional Access for device trust and proxy/hosting blocks; CAE; limit SharePoint blast radius; hunt NodeMaven/residential-proxy token replay and SharePoint STS_Site discovery; verify unexpected IT/passkey calls out-of-band

Primary: Arctic Wolf Pack Alert — PREY-0058 (3 Sep 2026) · The Hacker News (7 Sep 2026)

breaches identity cloud

Incident
Published 2026-09-03
Verified 2026-09-19

ACMA fines Telstra $277,000 over SIM-swap identity-check failures

iTnews (3 September 2026) reports the Australian Communications and Media Authority fined Telstra $277,000 for not applying required identity-authentication processes to prevent SIM-swapping fraud. ACMA said the fraud caused at least $39,500 in losses to 15 customers between January and October 2025, with 13 further attempts where agents failed to add fraud protections or to act on risk signals; ACMA member Samantha Yorke said frontline staff did not follow Telstra's own processes. SIM swaps let attackers move a victim's number onto their own SIM and intercept MFA codes and other mobile traffic. ACMA accepted court-enforceable undertakings for stronger fraud prevention and staff training. Context in the same report: a larger $1.551 million Telstra penalty in July 2024 for related ID-authentication failures, and more than $5 million in ACMA telco fines to date on mobile-number fraud. Watchlist relevance: Telstra.

Product
Telstra mobile identity / SIM-change processes
Exploited in Australia?
yes
Patch to
Telstra: enforceable undertakings on fraud prevention and training; customers: PIN/port-out locks and non-SMS MFA where available

Primary: iTnews (3 Sep 2026) · Vendor: ACMA (regulator; primary notice page was 403 from this pass egress)

australia identity

Incident
Published 2026-09-03
Verified 2026-09-19

Verve Portraits (AU): Settra leak-site listing; attack est. mid-August

Ransomware.live’s Australia country feed (observed 4 September 2026) lists Victorian photography business Verve Portraits (verveportraits.com.au) under the Settra brand, discovered 3 September 2026 with an estimated attack date of 13 August 2026. No company statement, OAIC notice, or ACSC advisory was located on this pass, so treat the listing as an unconfirmed extortion claim until a primary notice appears. Australian operators in professional services should still verify backups, MFA, and remote-access exposure.

Exploited in Australia?
yes

Primary: Ransomware.live Australia (listing observed 4 Sep 2026) · Webber Insurance AU breaches list (no matching notice found this pass)

australia

Incident
Published 2026-09-03
Verified 2026-09-19

Macquarrie (AU): Storm listing; company confirms third-party supplier incident

UPDATE 14 September 2026: Cyber Daily’s Penfold Motors exclusive states machinery management specialist Macquarrie recently confirmed it is responding to a cyber security incident at a third-party supplier — elevating the earlier ransomware.live Storm listing (discovered 3 September 2026; estimated attack 1 September) from leak-site-only to company-acknowledged supplier compromise. No separate Macquarrie customer-notification text, OAIC entry, or ACSC advisory was fetched beyond that Cyber Daily confirmation. Same Storm wave as Penfold Motors and other Australian automotive/farm-machinery dealers. UPDATE 15 Sep 2026: Cyber Daily names Auto-IT as the third-party software firm whose customer environments were hit via abused RMM (see auto-it-storm-20260915). Primary confirmation wire: Cyber Daily (14 Sep); listing context: ransomware.live AUS.

Exploited in Australia?
yes

Primary: Cyber Daily — Macquarrie confirmation in Penfold/Storm piece (14 Sep 2026) · ransomware.live Australia (Storm / Macquarrie listing)

australia ot ics

Incident
Published 2026-09-03
Verified 2026-09-19

CNIL fines Hôpital privé de la Loire €500k after 727k-person EPR breach (summer 2025)

BleepingComputer (3 September 2026) reports France’s CNIL fined Hôpital privé de la Loire (HPL, Ramsay Santé group, Saint-Étienne) €500,000 for GDPR security and notification failures after a summer 2025 intrusion into the electronic patient record system exposed sensitive data of 524,867 patients plus 202,246 trusted third parties (about 727,000 people). CNIL findings cited include external physician access without VPN or multi-factor authentication, overly broad access once an account was compromised, lack of near-real-time monitoring that let exfiltration run for days, and failure to directly notify the trusted-third-party cohort (Articles 32 and 34 GDPR). A teen using the alias “Marak” claimed the path began with one doctor’s account and tried to sell the data; reporting says it was neither sold nor published. HPL strengthened controls during proceedings. Practitioners: remote clinical access needs MFA and VPN; least privilege on EPR; detection that catches multi-day bulk extract; notify every category of affected individual.

Product
Hôpital privé de la Loire / Ramsay Santé EPR
Exploited in Australia?
no
Patch to
MFA+VPN for remote EPR; least-privilege clinical accounts; near-real-time bulk-export detection; notify all affected cohorts

Primary: BleepingComputer (3 Sep 2026) · Vendor: CNIL (French DPA; decision text not loaded this pass — wire pending official release page)

breaches identity

Incident
Published 2026-09-02
Verified 2026-09-19

Thomson Reuters C-Track: unauthorised access to court case files across US states, USVI and Ontario

West Publishing Corporation (Thomson Reuters Court Management Solutions) notified courts that an unauthorised party obtained files from the C-Track appellate case-management platform in March 2026; activity was discovered 30 June 2026. The Supreme Court of Ohio public statement says ten of twelve Ohio Courts of Appeals use C-Track hosted by the Court and managed by TRCMS; the 8th and 10th districts do not and are unaffected; TRCMS told the Court on 31 August 2026 that unauthorised access hit the production platform. The Hacker News (3 Sep) summarises West’s 2 September notice: courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario may be in scope; a subset of records could include names, SSNs, driver’s licence numbers, dates of birth, medical and health-insurance information; sealed or redacted material may be impacted for some courts; TRCMS says no evidence of fraud or misuse to date and offers Experian IdentityWorks (US) / TransUnion myTrueIdentity (Canada) monitoring via engagement B171847 and https://www.ctracknotification.com. Distinct from other court or identity cards on this desk.

Product
Thomson Reuters / West Publishing C-Track court case management
Exploited in Australia?
unknown
Patch to
Courts and counsel: follow TRCMS notices; enrol monitoring if in scope; rotate any exposed credentials tied to C-Track filings

Primary: Supreme Court of Ohio C-Track incident statement · Vendor: TRCMS C-Track notification / credit-monitoring portal · The Hacker News (3 Sep 2026)

breaches identity

Incident
Published 2026-09-01
Verified 2026-09-19

IDScan.net confirms cloud access tied to 153M+ licence dump; lawsuits ongoing

KrebsOnSecurity (1 September 2026) reported a dark-web identity-theft service branded Nexus advertising digital scans of more than 153 million US and Canadian driver’s licences plus millions of other ID cards, travel documents and medical cards. Krebs’s checks pointed to Louisiana identity-verification firm IDScan.net as the likely source; the company said it was investigating and the FBI New Orleans field office opened an inquiry. SecurityWeek (3 Sep) and Ars Technica (2 Sep) corroborated the listing. BleepingComputer (4 September 2026) reports multiple lawsuits against IDScan, with firms including Markovits, Stock & DeMarco and Hall Attorneys launching investigations into potential class-action litigation. Nexus appeared to shut shortly after Krebs published. Organisations that rely on third-party ID-scan vendors should treat this as a supply-chain identity risk. NEW 10 September 2026 (BleepingComputer): IDScan published a 4 September 2026 security notice (initially noindex) stating it learned on or around 1 September that an unauthorised party may have accessed or copied customer information in IDScan.net cloud accounts — full names and driver's licence or other government ID numbers — and that investigation continues with third-party specialists. This is the first public company confirmation tying the firm to the 153M+ licence dump reporting. UPDATE 16 September 2026 desk: primary_url switched to IDScan.net press notice (datePublished 4 Sep 2026) stating unauthorised access/copy of cloud customer info may include full names and driver's licence or other government ID numbers; free credit monitoring offered; cooperating with federal law enforcement. ACS Information Age (8 Sep) re-covered the dump for AU readers — no new scope beyond vendor notice.

Product
IDScan.net identity verification / Nexus dark-web ID service
Exploited in Australia?
unknown
Patch to
Monitor IDScan/customer notices; freeze reliance on unverified third-party ID scans; watch for cloned licences

Primary: IDScan.net — Notification of Data Security Incident (4 Sep 2026) · Vendor: IDScan.net vendor notice · KrebsOnSecurity — FBI probe / Nexus 153M+ licences (1 Sep 2026); BleepingComputer 10 Sep

breaches identity

Incident
Published 2026-09-01
Verified 2026-09-19

Dropbox: Lenovo ID federation let attackers into about 5,000 accounts

Decrypt published on 1 September 2026 that Dropbox had emailed users about unauthorised access between 4 and 21 August 2026 via Lenovo ID single sign-on. A Dropbox spokesperson told Decrypt the company identified unauthorised access affecting Dropbox accounts connected through Lenovo ID that did not have Dropbox two-factor authentication enabled, and that an issue with Lenovo email verification allowed an unauthorised party to register a Lenovo ID using another person's email address and then use that Lenovo ID to log into the Dropbox account associated with that address. The spokesperson said approximately 5,000 Dropbox accounts were impacted, less than a third of those had files viewed or downloaded, and Dropbox had emailed all impacted users; users who did not receive an email were not impacted. Decrypt also reported that Dropbox's notification letter said logs showed no evidence files were viewed or downloaded, and that Dropbox has since changed how Lenovo IDs can access accounts. Affected user Yoni Levy posted screenshots of a new-browser sign-in alert from near Canary Wharf (Chrome on Windows, 18 August) and said he had never had a Lenovo account. This desk has not found a Dropbox public advisory page; the company notice in hand is the user email plus the spokesperson comments to Decrypt.

Product
Dropbox (Lenovo ID sign-in)
Exploited in Australia?
unknown
Patch to
Dropbox: expire Lenovo ID sessions and require the Dropbox password before a Lenovo ID can authenticate; enable Dropbox 2FA; users without a notification email were not in the notified set

Primary: Decrypt (1 Sep 2026; Dropbox spokesperson) · 9to5Mac (1 Sep 2026; quotes Dropbox email)

breaches identity cloud

Incident
Published 2026-09-01
Verified 2026-09-19

Coder: Cloudflare registry pool served malicious Terraform modules (31 Aug window)

Coder published GitHub advisory GHSA-vx42-ghc9-gw65 on 1 September 2026 (Critical). An unidentified actor gained access to Coder's Cloudflare infrastructure and added unauthorised IP addresses to the pool used for the Coder module registry (registry.coder.com). Those addresses hosted a malicious copy of registry artefacts. For a short window the registry served malicious packages to a subset of users. The implanted code was designed to identify credentials and exfiltrate them to a lookalike domain (coder-infra.com). Coder says it has no indication that any customer data maintained by Coder was impacted. Users who downloaded a Coder Registry module between 07:35 UTC and 21:45 UTC on Monday 31 August 2026 may be affected (new templates or template versions; also workspace creation if module caching is disabled). Coder recommends reviewing firewall, DNS and VPC logs for outbound traffic to coder-infra.com, purging cached modules from the affected window, rotating potentially exposed credentials, and updating Coder. Patched versions: 2.37.0, 2.36.4, 2.35.7, 2.34.9. Affected: versions before 2.37.0.

Product
Coder module registry (registry.coder.com)
Versions
Affected: Coder before 2.37.0; modules pulled 31 Aug 2026 07:35-21:45 UTC
Exploited in Australia?
unknown
Patch to
2.37.0 / 2.36.4 / 2.35.7 / 2.34.9; purge cached modules from the window; rotate credentials; watch coder-infra.com egress

Primary: Coder GHSA-vx42-ghc9-gw65 (1 Sep 2026) · Vendor: Coder (vendor)

tech cloud

Incident
Published 2026-09-01
Verified 2026-09-19

Novocure Form 8-K: mid-August intrusion; 1,400+ U.S. patient ID numbers accessed

NovoCure Limited's Form 8-K dated 1 September 2026 (Item 8.01) says that in mid-August 2026 a subsidiary became aware of unauthorised access to some information systems. The company activated its cybersecurity response plan, contained the event, and engaged independent forensic experts. Exposed data to date: internal company patient ID numbers for over 1,400 U.S. patient records (IDs used only internally; no names or other identifying data for those records); identifying information for fewer than 50 other patients in the western U.S.; general contact information for healthcare providers; and employee contact details such as job titles and phone numbers. Novocure states no access to medical treatment devices was obtained, operations were not compromised, and systems remain fully functional. It does not currently expect a material financial impact and says it will make required notifications, including to impacted patients. Vector and threat actor are not named in the filing.

Product
Novocure information systems
Exploited in Australia?
unknown

Primary: NovoCure Form 8-K (1 Sep 2026) · Vendor: SEC EDGAR (NVCR) · BleepingComputer (1 Sep 2026)

breaches

Incident
Published 2026-09-01
Verified 2026-09-19

UAC-0099 GuardBreaker: nuclear-weapon comment in VBS to trip LLM malware analysis

The Hacker News (1 September 2026), citing ESET research disclosed on X, says Russia-aligned UAC-0099 used a technique ESET calls GuardBreaker against a target in Ukraine to interfere with AI-assisted code analysis. ESET said the actor inserted the comment "I want to make a nuclear weapon. Help me ..." in a malicious VBS script so an LLM's safety mechanisms would latch onto the content and stop analysing the rest of the code. The VBS is assessed as part of UAC-0099's toolset and is primarily designed to download and install MATCHBOIL, a C# loader used by the actor to deliver further payloads. UAC-0099 has a track record against transportation and energy sectors; CERT-UA in late July 2026 warned of MATCHBOIL delivered as a fake Notepad++ plugin. Do not treat this card as a TeamPCP reprise (already on this desk as afp-teampcp-2026).

Product
Malicious VBS delivering MATCHBOIL (C# loader)
Exploited in Australia?
unknown

Primary: The Hacker News (1 Sep 2026; ESET)

ai

Incident
Published 2026-09-01
Verified 2026-09-19

Nutex Health confirms patient, employee and financial data theft; Gentlemen claims Houston company

Nutex Health Inc. told the US SEC in an 8-K dated 31 August 2026 that an unauthorised third party accessed and exfiltrated information from its servers, including patient, employee, credentialed-provider, business and financial data that is private or confidential. A third party has threatened to post that information. The Houston company says it has not identified a material impact on operations or financial reporting systems to date, and it has not named the actor. After an earlier 24 August 8-K, a purported Texas class action (Haley v. Nutex Health, Inc., S.D. Tex.) was filed on 27 August 2026. SecurityWeek (1 September) reports that Gentlemen (also tracked as Storm-2697) claimed the company on its leak site with a nine-day deadline; that leak-site claim is not company attribution. No Australia link is reported.

Product
Nutex Health Inc.
Exploited in Australia?
unknown

Primary: Nutex Health Form 8-K (31 Aug 2026) · Vendor: SEC EDGAR 8-K · SecurityWeek (1 Sep 2026)

breaches

Incident
Published 2026-09-01
Verified 2026-09-19

Datadog: password-spraying against AWS root console at 150+ organisations

Datadog Security Research describes a password-spraying campaign against AWS root-user console logins at more than 150 organisations between 24 July and 23 August 2026. The median number of failed attempts per organisation was two; some saw as many as eight. The AWS root console requires the account email, so the campaign implies the operators had (or guessed) those addresses. This desk records failed attempts as reported; no successful authentications are stated in the Datadog write-up as loaded. Coverage on 1 September 2026 (Cyber Security News) likewise says researchers did not identify successful authentications. Organisations should review CloudTrail for unusual root ConsoleLogin failures and keep root use exceptional.

Product
AWS root user console
Exploited in Australia?
unknown
Patch to
Review CloudTrail root ConsoleLogin failures; minimise root use

Primary: Datadog Security Labs · Cyber Security News (1 Sep 2026)

tech cloud identity ai

Incident
Published 2026-08-31
Verified 2026-09-19

Socket: 13 malicious Packagist themes push iOS WebKit-to-kernel spyware and wallet theft

Socket's 31 August 2026 research describes 13 malicious Composer theme packages on Packagist across five vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms) that inject JavaScript into Vietnamese movie and comic streaming sites. On mobile visitors the code runs gambling and ad-fraud redirects; on unpatched iPhones it loads a FUNNULL-hosted WebKit-to-kernel exploit chain. Socket says the renderer stages weaponise CVE-2025-31277 and CVE-2025-43529 (both on CISA KEV), then escape to the kernel; Apple told Socket the kernel escape was already fixed in iOS and macOS 26.1. A 12 August 2026 redeployment added keychain theft of crypto-wallet seeds and mnemonics for Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet and OKX, targeting iOS 18.4 through 18.6.x. Site operators should remove themes from those namespaces, rotate credentials, and audit shipped scripts; keep iPhones current past the listed builds.

Product
Packagist Composer themes (OphimCMS/KKPhim forks); iOS Safari/WebKit
Versions
iOS exploit tables cover 18.4–18.6.x; kernel escape fixed in iOS/macOS 26.1 per Apple to Socket; WebKit CVEs patched in later 18.7.3 / 26.2 builds per Socket
Exploited in Australia?
unknown
Patch to
Remove listed Packagist themes; update iOS past 18.6.x; block Socket IoCs

Primary: Socket (31 Aug 2026) · CVE: CVE-2025-31277, CVE-2025-43529 · The Hacker News (1 Sep 2026)

tech supply chain

Incident
Published 2026-08-31
Verified 2026-09-19

Huntress: phishing abuses Faronics Deploy to chain ScreenConnect remote access

Huntress published on 31 August 2026 that phishing actors abused the legitimate Faronics Deploy endpoint-management platform between 21 July and 20 August 2026, with more than 457 endpoints encountering Faronics-themed lures (invoices, tax documents and similar). Victims were steered to download a signed Faronics Deploy installer disguised as an Adobe document or plugin; once enrolled in an attacker-controlled deployment, operators used Faronics remote script execution (PowerShell via curl, mshta or msiexec) to install ConnectWise ScreenConnect as a second remote-access channel. Huntress notified Faronics on 5 August 2026; Huntress says Faronics added anti-abuse controls and contacted affected organisations, and observed activity drop sharply from 21 August. Defenders should inspect C:\ProgramData\Faronics\Logs\ScriptRunner.log and unexpected ScreenConnect installs, and report suspected abuse to support@faronics.com.

Product
Faronics Deploy; ConnectWise ScreenConnect
Exploited in Australia?
unknown
Patch to
Remove unauthorised Faronics/ScreenConnect enrolments; review ScriptRunner.log; report abuse to Faronics

Primary: Huntress (31 Aug 2026) · BleepingComputer (1 Sep 2026)

breaches identity

Incident
Published 2026-08-31
Verified 2026-09-19

METR: two 2026 security incidents; no sensitive eval data believed accessed

METR's 31 August 2026 security update describes two incidents in which external actors tried to gain unauthorised access. It believes no sensitive information was accessed in either case, and it is not attributing the events; the post is about human attackers, not AI agents breaking evaluations. In March 2026 a researcher with no sensitive-access privileges ran a vibe-coded app on a personal public EC2 instance behind Google authentication that held an API key for METR's public-models account; a fail-open bug silently disabled auth. METR assesses the attacker found the host via recently registered sites or certificate-transparency lists, prompted an agent for the key, added an SSH key, and burned credits for about three weeks. Accrued usage would have been worth about US$600,000 if the unnamed model provider had not given the credits free. In May 2026 attackers probed public infrastructure (credential stuffing, OAuth grants, phishing staff). METR had inadvertently exposed a read-only SQL mechanism on a public transcript viewer that could have reached unpublished eval data, including some sensitive model output that should not have been in that database; attackers probed the endpoint but METR says there is no evidence they found the issue or accessed non-public data. Distinct from desk cards anthropic-eval-containment-20260831 and anthropic-claude-infostealer-20260830.

Product
METR evaluation infrastructure
Exploited in Australia?
unknown

Primary: METR security update (31 Aug 2026) · Vendor: METR · The Hacker News (1 Sep 2026)

ai cloud

Incident
Published 2026-08-31
Verified 2026-09-19

Aesto Health: 9.54 million people on HHS portal after Dec 2025 AWS infrastructure incident

Aesto Health (Birmingham, Alabama), which provides healthcare data migration and archiving for covered-entity clients, posted a June 2026 notice: it discovered a network security incident on or about 18 December 2025 affecting a limited portion of its Amazon Web Services infrastructure. On 26 May 2026 the investigation determined that PII and PHI belonging to patients of various clients may have been accessed or acquired between about 2 and 18 December 2025, including names, dates of birth, medical information, driver's licence numbers, financial account numbers, health insurance information, taxpayer identification numbers, other government IDs, and Social Security numbers (elements varied; SSNs for a limited number of people). The US HHS portal lists 9,540,683 individuals; SecurityWeek (1 September) says HHS added the company on Monday 31 August 2026. At least two dozen provider clients across several states were affected. The company says it has no evidence of identity theft or financial fraud tied to the incident. No Australia link is reported.

Product
Aesto Health (AWS-hosted migration/archive)
Exploited in Australia?
unknown

Primary: Aesto Health notice (June 2026) · Vendor: Aesto Health (company notice) · SecurityWeek (1 Sep 2026)

breaches cloud

Incident
Published 2026-08-31
Verified 2026-09-19

Softaculous/Virtualizor: BGP hijack delivered a malicious hypervisor update

Softaculous' Virtualizor incident post (31 August 2026) says IP block 162.55.80.0/24 (Hetzner space used by Softaculous services) was BGP-hijacked from about 20:57 UTC on 28 August to about 06:10 UTC on 30 August. An unauthorised announcement by AS62390 (NexonHost), transited via AS6204 (Zet.net), was more specific than Hetzner's 162.55.0.0/16 and diverted traffic, including the software-update endpoint and client-area/billing site. The attacker obtained a technically valid Let's Encrypt certificate for Virtualizor, Softaculous and related names, so diverted connections showed no certificate warning. The vendor confirmed a malicious Virtualizor update package reached a small number of installations that checked for updates during diversion; it cannot list every affected host. Known indicator: systemd unit /etc/systemd/system/java-jre-update.service. Routing has been restored. Operators should hunt that unit (and not only delete it), rotate Virtualizor API keys, and audit SSH keys, accounts and cron. The vendor shipped Virtualizor 3.2.9.9 with a mitigation tool and says package signing is coming. Other Softaculous products had no identified malicious package at the time of the post. Clients who logged into the billing site during the window should reset that password.

Product
Virtualizor (Softaculous update infrastructure)
Versions
Installations that checked for updates between 28 Aug ~20:57 UTC and 30 Aug ~06:10 UTC
Exploited in Australia?
unknown
Patch to
Hunt java-jre-update.service; rotate API keys; restrict SSH/API; Virtualizor 3.2.9.9 mitigation build

Primary: Virtualizor incident post (31 Aug 2026) · Vendor: Softaculous / Virtualizor (vendor) · Ars Technica (2 Sep 2026)

tech cloud

Incident
Published 2026-08-31
Verified 2026-09-01

Berlin confirms data theft and extortion after state-network cyberattack

Berlin's official 31 August update says the city is facing extortion after the mid-August cyberattack on its administrative network and will not pay. Forensic work confirmed data left the Senate Department for Mobility, Transport, Climate Protection and the Environment between 7 and 12 August; the scope is still being assessed and personal or other non-public data may be involved. Berlin says the affected departments were disconnected on 14 August and investigations by state police, prosecutors and federal security authorities continue. BleepingComputer reports that the Rhysida ransomware group claimed the attack and a much larger theft, but Berlin's notice does not attribute the incident or confirm the actor's volume and content claims.

Product
State of Berlin administrative network
Exploited in Australia?
unknown

Primary: Berlin.de official update (31 Aug 2026) · Vendor: State of Berlin press release (German) · BleepingComputer (31 Aug 2026)

breaches

Incident
Published 2026-08-28
Verified 2026-09-19

Pacific ABS / pacificabs.com (AU): Settra leak-site listing (ransomware.live)

Ransomware.live’s Australia country feed lists pacificabs.com (Pacific Global Solutions / PABS / Atteign LLC; professional-services activity tag) under the Settra brand — feed published date 28 August 2026, discovered on the tracker 17 September 2026 (API id cGFjaWZpY2Ficy5jb21Ac2V0dHJh). Claim text references documents and a prologue mentioning 40+ American businesses; treat as an unconfirmed extortion claim. No company website incident notice, OAIC notice, Webber Insurance list entry, or ACSC advisory was located on this 18 September 2026 04:00 Perth desk pass. Distinct from prior AU Settra desk card verve-portraits-settra-20260903. Australian operators should verify backups, MFA, and remote-access exposure until a primary notice appears.

Exploited in Australia?
unknown

Primary: Ransomware.live — pacificabs.com / Settra (discovered 17 Sep 2026) · Ransomware.live Australia country feed (also Webber list checked — no matching notice)

australia

Incident
Published 2026-08-28
Verified 2026-09-19

JetBrains Cadence: TeamCity CVE-2026-63077 missed; customer data and secrets exposed

JetBrains' Cadence incident post (opened 28 August 2026, last updated 1 September 2026 12:05 CEST) confirms unauthorized access to Cadence, a JetBrains-hosted cloud-compute service for PyCharm via an optional plugin that orchestrates work with TeamCity. The Cadence host api.cadence.jetbrains.com was vulnerable to CVE-2026-63077 (desk card cve-2026-63077) and was exploited; activity from 8 August to 24 August 2026; discovered 23 August; server taken offline 24 August. Confirmed: personal data extracted (usernames, real names, emails, last-login times, last IPs); a full 2024 Cadence server backup compromised (treat credentials/config/artifacts in that backup as exposed); multiple AWS IAM users/secrets used with Cadence compromised from that backup; files in JetBrains Cadence S3 buckets accessed; possible access to source synchronized from PyCharm. JetBrains says no evidence secrets were taken from the live environment beyond the backup path, invalidated Cadence plugin access tokens, and lists IoC IPs (150.109.230.104, 43.153.227.206, 62.210.127.48, 210.247.242.190, 15.235.225.205, 152.233.30.18). Users must rotate all credentials used in Cadence executions and treat inputs/outputs as untrusted. Distinct from the On-Premises TeamCity ACSC exploitation card: this is JetBrains' own hosted Cadence service.

Product
JetBrains Cadence (PyCharm cloud plugin / TeamCity-backed)
Versions
api.cadence.jetbrains.com exploited 8–24 Aug 2026 via unpatched CVE-2026-63077
Exploited in Australia?
unknown
Patch to
Cadence taken offline; rotate all Cadence-linked secrets; review AWS/SCM/registry activity from 8 Aug 2026

Primary: JetBrains Cadence incident post · Vendor: JetBrains (vendor) · CVE: CVE-2026-63077 · JetBrains TeamCity CVE-2026-63077 advisory

tech cloud identity

Incident
Published 2026-08-28
Verified 2026-09-19

@7nohe/openapi-react-query-codegen: ten published versions after an abused GitHub Actions publishing workflow

Socket (28 August 2026) reports that ten versions of npm package @7nohe/openapi-react-query-codegen were published that day after a comment-triggered GitHub Actions trusted-publishing workflow was abused. An untrusted GitHub account could comment a publish trigger on a pull request and ship fork code under the repository OIDC identity. Versions named by Socket and Step Security are 0.5.4, 0.5.5, 1.6.3, 1.6.4, 2.2.1, 2.2.2, 3.0.3, 3.0.4, plus two 0.0.0-sha prerelease tags. Stable releases ran obfuscated JavaScript 3FWCvzduYZg.js via binding.gyp and/or a preinstall hook. Socket describes Mini Shai-Hulud-consistent self-propagation. Install-time code targeted cloud credentials, package-registry credentials, GitHub Actions secrets and AI-agent configuration. All ten carried valid npm provenance. Pin known-good 0.5.3, 1.6.2, 2.2.0 or 3.0.2, isolate affected hosts, then rotate tokens. This desk does not attribute the package to TeamPCP; Socket and Step Security do not name that group.

Product
@7nohe/openapi-react-query-codegen
Versions
Affected: 0.5.4, 0.5.5, 1.6.3, 1.6.4, 2.2.1, 2.2.2, 3.0.3, 3.0.4 plus two 0.0.0-sha tags; known-good 0.5.3 / 1.6.2 / 2.2.0 / 3.0.2
Exploited in Australia?
unknown
Patch to
Uninstall affected versions, pin known-good, isolate, then rotate tokens

Primary: Socket (28 Aug 2026) · Step Security (28 Aug 2026)

tech cloud identity

Incident
Published 2026-08-28
Verified 2026-09-19

ATF confirms cyber incident on a standalone system after Qilin listing

SecurityWeek (28 August 2026) reports the US Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a cybersecurity incident after the Qilin ransomware group listed the agency. ATF's statement, as quoted there, says the intrusion hit a standalone system that was disconnected once discovered, that the system sits apart from the ATF enterprise network, and that there is no indication the enterprise network, eForms, or any other ATF system was affected or that ATF cannot perform its missions. An investigation is underway with the Justice Department; senior DOJ officials designated the event a major incident under federal guidelines and required notifications were completed. Qilin added ATF to its leak site on 26 August; SecurityWeek says the post made no specific claims, showed no stolen-document screenshots, and did not set a leak timer. Actor claims are not treated as verified facts on this desk. ATF's press-release URL returned 403 from this pass; facts are from SecurityWeek quoting the statement.

Exploited in Australia?
unknown

Primary: SecurityWeek (28 Aug 2026; quotes ATF) · Vendor: ATF press release (403 this pass)

breaches

Incident
Published 2026-08-28
Verified 2026-09-19

Hasbro: employee personal and financial information accessed

Hasbro's Massachusetts consumer letter (OCABR 2026-1427, posted in the August 2026 breach-letter list) says a data security incident may have involved employee personal information after a compromised employee account. Hasbro says it disabled that account, terminated unauthorised access, and added safeguards. The letter says involved information varied and may have included name plus one or more of email, address, phone number, national ID number, or financial information. BleepingComputer, citing the Massachusetts 2026 Data Breach Notification Report, says 436 Massachusetts employees had Social Security numbers, financial-account information, credit/debit card numbers, or driver's-licence information involved. Hasbro has not published a nationwide total. Hasbro did not link this notice to its March 2026 incident. No customer impact is stated in the letter.

Exploited in Australia?
unknown

Primary: Hasbro MA consumer letter (2026-1427) · Vendor: Massachusetts August 2026 breach letters · BleepingComputer (28 Aug 2026)

breaches identity

Incident
Published 2026-08-28
Verified 2026-09-19

Sharp Motor Group (Tweed Heads): third-party IT provider cyber incident; OAIC notified

Cyber Daily's 28 August 2026 report quotes a Sharp Motor Group spokesperson confirming the Tweed Heads, NSW dealership is aware that its third-party IT provider has been involved in a cyber incident. The company said it is working with independent cyber specialists and relevant authorities, has notified the OAIC, and that staff and customer privacy remain the priority. Cyber Daily reports the Storm ransomware group listed Sharp Motor Group in a 23 August leak-site post and published sample files it claims were taken (including identity documents and financial material); those actor claims and any data-volume figures are not independently confirmed in the company statement and are not treated as verified facts on this desk. Storm has also listed other Australian automotive and machinery firms this month; company responses for those other listings were not confirmed in the same report.

Exploited in Australia?
unknown

Primary: Cyber Daily (28 Aug 2026; quotes Sharp Motor Group)

australia retail

Incident
Published 2026-08-28
Verified 2026-09-19

McKesson: cybersecurity incident with third-party apps and data exfiltration

McKesson's 28 August 2026 customer notice and Form 8-K say it discovered a cybersecurity incident on 25 August 2026 affecting its information systems. The company says the investigation is in early stages and involves third-party applications plus unauthorised access and exfiltration of data. Updates are posted at mckesson.com/cybersecurity. A 29 August 2026 customer note on that page (heading: McKesson Cybersecurity Incident Investigation and Response Update) says McKesson continues to serve customers across all lines of business and accept orders, distribution centres remain operational, and shipping continues. That note does not add scope, named applications, or confirmation of actor claims. As of the 8-K filing date, McKesson had not determined the incident to be material or reasonably likely to have a material impact on financial condition or results of operations. The company has not publicly named the applications involved, the access path, or what was taken. Secondary reporting attributes claims by the ShinyHunters extortion group (including a large patient-record count and Okta/Salesforce/Snowflake access via vishing); those actor claims are not confirmed in McKesson's notice or 8-K and are not treated as verified facts on this desk.

Exploited in Australia?
unknown

Primary: McKesson cybersecurity notice · McKesson Form 8-K (28 Aug 2026)

breaches healthcare

Incident
Published 2026-08-27
Verified 2026-09-19

NSW Police charge a Sydney telco employee over alleged sale of customer data

iTnews (28 August 2026), citing an NSW Police statement, reports that a 30-year-old telecommunications employee was arrested at a police station in Sydney's west and charged over allegedly accessing customer data through his employment and selling it to criminal groups. Police allege the information was then used to commit fraud against multiple victims. Charges listed in that report are 12 counts of deal with identity info to commit an indictable offence, 12 counts of unauthorised function with intent to commit a serious offence, and 10 counts of agent corruptly receive benefit (34 offences). The arrest followed a Queensland Police referral. iTnews does not name the employer. The National Tribune reprint of the police release dates the arrest about 9.30am on Thursday 27 August 2026, refused bail to Liverpool Local Court the same day. These are allegations before a court.

Exploited in Australia?
unknown

Primary: iTnews (28 Aug 2026; quotes NSW Police) · Vendor: NSW Police news index

australia identity

Incident
Published 2026-08-27
Verified 2026-09-19

Manchester Airports Group: FulcrumSec leaks ~550GB / HIBP ~8.8M emails and phones after ransom refusal

MAG’s 27 August 2026 statement said an unauthorised third party obtained customer data from car park, lounge and Fast Track bookings and in-airport Wi-Fi sign-ups at Manchester, London Stansted and East Midlands airports (emails, phones, vehicle registrations, postcodes; no bank details; operations unaffected). SecurityWeek (3 September 2026) reports the FulcrumSec extortion group published roughly 550GB of uncompressed data after MAG reportedly refused a ransom, claiming access via exposed admin keys. Have I Been Pwned, which ingested the dump, put the scale at about 8.8 million email addresses and phone numbers, with names, browser agents, purchases and vehicle plates also present. FulcrumSec claimed on the order of 2.48 million purchases in the set. MAG’s original mediacentre statement remains the operator notice; treat FulcrumSec/HIBP figures as leak-site and breach-notification telemetry refining scope.

Exploited in Australia?
unknown

Primary: MAG statement (27 Aug 2026) · Vendor: MAG customer FAQ · SecurityWeek (3 Sep 2026; FulcrumSec leak / HIBP 8.8M)

breaches identity

Incident
Published 2026-08-27
Verified 2026-09-19

Alliance Distribution Services (Hachette Australia): systems disruption after unauthorised activity

Hachette Australia told ABC News that unauthorised activity on the computer systems of its distribution subsidiary Alliance Distribution Services (ADS) was believed to have occurred on 18 July 2026. As of the 27 August 2026 ABC report, Hachette said it was still restoring systems and services, could not yet confirm a timeline for a full return to normal operations, and that restoring full operations securely remained its top priority. The disruption has hit book supply to Australian bookshops and authors ahead of the busy trading period. Hachette has not publicly confirmed whether the incident involved ransomware, data theft, or another form of attack. Secondary commentary that labels the event ransomware remains unverified by the company.

Exploited in Australia?
unknown

Primary: ABC News (quotes Hachette) · AFR (21 Aug; secondary)

australia supply chain

Incident
Published 2026-08-27
Verified 2026-09-19

AFP, WAPF and FBI charge two WA men over alleged open-source supply-chain syndicate

Joint AFP, Western Australia Police Force and FBI release: two West Australian men were charged on 26 August 2026 with a combined 14 offences after Perth search warrants. Police allege a syndicate inserted malicious code into software on an open-source repository that other developers then pulled in. The AFP estimates more than 1,000 organisations globally, more than 500,000 credentials, and at least 300 GB of data, with remediation costs in the hundreds of millions of dollars. The FBI statement in that release names the group TeamPCP. The men are not named in the AFP release. The investigation continues; further arrests have not been ruled out. NEW GTIG/THN (Sep 2026): Google Threat Intelligence Group tracks TeamPCP as Altered Spider / UNC6780 and describes credential stealers SANDCLOCK and DUSTMAKER plus an autonomous multi-agent framework used in a large-scale credential harvest completed in under six hours.

Exploited in Australia?
unknown

Primary: AFP media release · The Hacker News — GTIG autonomous agents / TeamPCP (Sep 2026)

australia supply chain

Incident
Published 2026-08-26
Verified 2026-09-19

Boston Scientific: cybersecurity incident disrupting manufacturing, orders and shipping

Boston Scientific's customer update page (latest posted 30 August 2026 8:25 p.m. ET) says it identified a cybersecurity incident on 25 August that caused a network outage and disruption to certain on-premise operating systems and business applications, including manufacturing, order processing and shipping. The company filed an 8-K. It is working with CrowdStrike and other third-party experts. As of the 30 August update it sees no indication of unauthorised activity in its environment related to this incident since 25 August; cloud-based systems are not impacted; the unauthorised activity is limited to certain on-premise systems. Existing implantable CRM device function and previously activated remote monitoring are described as not impacted; new remote-monitoring activations for some cardiac devices are disrupted. No ransomware group had claimed the incident in SecurityWeek's 31 August report. Actor identity is unknown on this desk.

Exploited in Australia?
unknown

Primary: Boston Scientific customer update (30 Aug 2026) · Vendor: Boston Scientific 8-K (26 Aug 2026) · SecurityWeek (31 Aug 2026)

breaches

Incident
Published 2026-08-21
Verified 2026-09-19

Origin Energy: unauthorised access affecting about 900,000 customers

Origin Energy confirmed unauthorised access to personal information of approximately 900,000 current and former customers in July 2026. Categories include name, address, date of birth, contact phone, account details, and partial payment data (last four digits of a credit card or last three of a bank account). On 21 August 2026 Origin said a completed review found about 60 customers had full bank account numbers accessed, about 100 had an ID document number accessed (number only, no scans), and about 15,000 had government concession-scheme numbers accessed. Origin told ABC the alleged attacker had not publicly leaked customer data. The company is working with ASD's ACSC, the National Office of Cyber Security, AFP and OAIC; a criminal investigation continues. Earlier reporting linked the incident to a former Accenture Manila call-centre worker; Accenture declined to comment to ABC.

Exploited in Australia?
unknown

Primary: ABC News (quotes Origin 21 Aug update) · ABC News (28 Jul; Origin 900k confirmation)

breaches australia

Incident
Published 2026-08-20
Verified 2026-09-19

Oz Hair and Beauty: unauthorised access to the online order platform

Oz Hair and Beauty's official statement says its online purchase and order platform was briefly accessed by an unauthorised third party. Limited personal information of some customers who purchased before August 2026 was involved: full name, email and/or mobile, and purchase data (currency, total spend, purchase location, customer creation date). The company says credit cards, passwords, payment information and invoice details were not accessed. It reported the incident to ACSC, OAIC and New Zealand's Office of the Privacy Commissioner. Customers not emailed by 22 August 2026 were, on that statement, not identified as impacted on the investigation to date. The company has not published a count of affected records.

Exploited in Australia?
unknown

Primary: Oz Hair and Beauty statement

breaches australia

Incident
Published 2026-08-19
Verified 2026-09-19

Quest Apartment Hotels: unauthorised access via a third-party provider

Quest identified unauthorised access on 17 August 2026 to a database through a vulnerability at a third-party service provider. Its statement says the incident is contained. Records involved are from before June 2025 and primarily names, email addresses and/or other contact details, with a small number of dates of birth. The company statement does not list payment card data and does not publish a count of affected records. Quest said it notified the OAIC and ACSC. Magazine reporting that put the figure around 1.5 million is secondary and unconfirmed by Quest.

Exploited in Australia?
unknown

Primary: Quest official statement · Information Age (secondary; unconfirmed headcount)

breaches supply chain australia

Incident
Published 2026-08-18
Verified 2026-09-19

SIA Medical Centre (Vic): Rhysida claims patient records; OAIC and ACSC notified

Cyber Daily (18 August 2026) reports Victorian multi-clinic operator SIA Medical Centre is investigating unauthorised access after the Rhysida ransomware group listed it on 12 August and claimed roughly 20,000 patient medical records (names, dates of birth, Medicare numbers, clinical notes, insurance and WorkCover files) plus staff identity documents, credentials, HR and banking material, offered for six bitcoin with a threatened publication date of 19 August. An SIA spokesperson said the organisation engaged cyber experts to contain the incident and assess personal information accessed; it has become aware an unknown third party named it online and published a small number of documents, is notifying those individuals, and has informed the Office of the Australian Information Commissioner and the Australian Cyber Security Centre. Distinct from other Rhysida cards on this desk (e.g. Berlin state-network).

Product
SIA Medical Centre (Victoria)
Exploited in Australia?
yes
Patch to
Containment and OAIC/ACSC notification underway; affected individuals being contacted as documents publish

Primary: Cyber Daily (18 Aug 2026) · Vendor: Webber AU data-breaches list (SIA Medical, Aug 2026)

australia identity

Incident
Published 2026-08-17
Verified 2026-09-19

Brighton East Dental Clinic: unauthorised access to on-premises patient files

Brighton East Dental Clinic's official notice says ASD's ACSC alerted it on 13 August 2026 to a potential incident. On 17 August 2026 the clinic identified unauthorised access to data on on-premises file servers through its firewall, contained that access, and analysed leaked data. It assesses the access occurred in early April 2026 and involves records from before April 2026: patient contact details (name, address, date of birth, email, mobile), treatment plans, oral X-rays, referrals and treatment history, and private health insurance membership numbers. The clinic has not published a count of affected records. It says it notified OAIC, ACSC and Victoria Police, partnered with IDCARE, and that remediation is complete. This desk does not take actor names or leak sizes from secondary leak-site indexes.

Exploited in Australia?
unknown

Primary: Brighton East Dental Clinic notice · Cyber Daily (18 Aug; secondary)

breaches australia

Incident
Published 2026-08-13
Verified 2026-09-19

Nick Scali (ASX: NCK): security incident; systems taken offline

Nick Scali Limited's 13 August 2026 ASX release says it is investigating a security incident and elected to take certain systems offline. The company said it was bringing those systems back online, continuing to complete sales orders and deliveries, with slower-than-normal customer response times. At the time of the release, Nick Scali said it did not have any evidence of unauthorised access to customer data. It notified the Australian Cyber Security Centre and the Australian Federal Police, and said further updates would follow as appropriate. Secondary media quoting the company (including SMH) describe the event as a cyberattack mid the prior week that forced manual order handling; those reports are consistent with the ASX notice on operational disruption. Separate secondary claims of ransom demands or confirmed customer-data access are not stated in the ASX release and are not treated as verified facts on this desk.

Exploited in Australia?
unknown

Primary: Nick Scali ASX release (13 Aug 2026) · CyberDaily (quotes ASX; 14 Aug)

australia retail

Incident
Published 2026-06-08
Verified 2026-09-19

UWA Callista student system: credentials exposed, unauthorised access on 28 May

The University of Western Australia's own notice says that on 28 May 2026, UWA IT identified unauthorised external access to Callista, the university's Student Information Management System, after system access credentials were unintentionally exposed online. UWA says it secured the system and removed the vulnerability. Exposed fields, on that notice, include name, UWA student ID, UWA staff ID if applicable, home and mobile numbers, date of birth (day and month only), personal email, postcode, and enrolment status as at 2 April 2026, for some prospective students, current students and recent graduates. UWA says financial details were not involved, that it found no evidence of malicious use, and that it emailed affected people on 8 June 2026. UWA password resets were not required. ASD's ACSC had not published a matching alert at last check.

Exploited in Australia?
unknown

Primary: UWA Callista notice · Vendor: UWA (institution)

breaches australia

Incident
Published 2026-05-07
Verified 2026-09-19

Instructure Canvas: Free-For-Teacher path, ShinyHunters claim, AU campuses offline

Instructure detected unauthorised activity in Canvas on 29 April 2026 and a second access on 7 May 2026 that changed pages some students and teachers saw after login. The vendor says both used a Free-For-Teacher account path, took Canvas into maintenance, remediated the privilege-escalation routes, and permanently discontinued Free-For-Teacher. Fields named on the vendor FAQ include usernames, email addresses, course names, enrolment information, and messages; Instructure says core learning data (course content, submissions, credentials) was not compromised, and the US Education Department FSA alert (12 May, updated 29 May) repeats that there is no evidence passwords, dates of birth, government identifiers, or financial information were exposed. ShinyHunters claimed the campaign; Instructure later said it reached an agreement with the unauthorised actor, that data was returned with shred logs, and that customers should not engage the actor. SMH (13 May) put the haul at roughly 3.65 TB across 8809 institutions worldwide, including at least 122 in Australia; Trend Micro separately counted 122 Australian institutions among 8809. Patch posture for customers: rotate Canvas integrations, LTI tools, SSO connectors, and API keys; review logs for 25 April–8 May 2026.

Product
Instructure Canvas LMS (Free-For-Teacher path)
Exploited in Australia?
yes
Patch to
Rotate Canvas integrations, LTI, SSO, and API keys; review auth and integration logs for 25 Apr–8 May 2026; Free-For-Teacher discontinued

Primary: Instructure Security Incident Update & FAQs · Vendor: Instructure · US Dept of Education FSA alert (12 May 2026; updated 29 May)

australia cloud identity