Latest cyber news, threats, security, and guidelines. Stack up.

Incidents

Thu 10 Sep

Way Forward (AU charity): payments suspended after third-party CMS cyber incident

Cyber Daily (10 September 2026) reports Australian financial-hardship charity Way Forward disclosed a cyber incident at an external customer-management platform provider. In a 9 September statement the charity said payment arrangements initiated through the affected system were unavailable, clients were notified as a precaution, and creditors were asked for a temporary payment moratorium so client credit reports stay unaffected. A spokesperson later told Cyber Daily the provider’s initial analysis indicated impacted information related mostly to the provider’s own company, still subject to change while the provider investigation continues. No OAIC notice or named vendor was fetched on this pass; treat data-impact scope as provisional. Primary: Cyber Daily quoting Way Forward; company website returned a challenge page this pass.

Cyber Daily — Way Forward third-party CMS incident (10 Sep 2026)

breaches australia identity

Incidents

Thu 10 Sep

NSW Online Registry: prosecutors say ChatGPT wrote scraper for ~8,769 restricted court docs

ABC News (10 September 2026) reports a Downing Centre Local Court hearing for Christopher John Duff, 40, who has pleaded not guilty to four counts of accessing restricted data held in a computer. NSW Department of Communities and Justice discovered a breach of the NSW Online Registry (court-user login portal) in March 2025; police say cybercrime detectives investigated alleged unauthorised access to 8,769 restricted documents between January and March 2025 (AVOs, details of minors, and other DCJ forms). Prosecutors allege Duff used ChatGPT to create Python scraper-style scripts for bulk download, then sought legal advice and “coaching” from ChatGPT after his registry login was shut down and before charge — and intend to rely on ChatGPT conversation records plus forensic testimony in what is described as among the first such Australian cases. Hearing stalled on volume (~10,000+ pages of proposed exhibits). Charged April 2025 after a search warrant in Sydney’s east; on bail. Allegations unproven. Primary: ABC; wire: ACS Information Age (10 Sep).

ABC News — Duff / NSW Online Registry ChatGPT hearing (10 Sep 2026)

breaches australia ai identity

Incidents

Thu 10 Sep

PivotC2: CVE-2025-25249 FortiGate CAPWAP RCE delivers Node.js RAT (178 victims)

SOCRadar Threat Research (covered 10 September 2026 by SecurityWeek) reports active exploitation of CVE-2025-25249, a heap-based buffer overflow in the FortiOS / FortiSwitchManager cw_acd CAPWAP daemon (UDP 5246), delivering PivotC2 — a Node.js post-exploitation RAT for FortiGate with interactive shell, tunneling, scanning and config/credential harvesting. SOCRadar cites NVD CVSSv3 9.8; Fortinet advisory FG-IR-25-084. Exploitation observed since at least July 2026; ~30k targeted IPs and 178 confirmed PivotC2 sessions (majority US; two full US intrusions with data theft). Tradecraft assessed as Russian-speaking cybercrime; RAT comments suggest AI-assisted development. Affected examples: FortiOS 7.6.0–7.6.3, 7.4.0–7.4.8, 7.2.0–7.2.11, 7.0.0–7.0.17; FortiSwitchManager 7.2.0–7.2.6 and 7.0.0–7.0.5. Fixed: FortiOS 7.6.4 / 7.4.9 / 7.2.12 / 7.0.18; FortiSwitchManager 7.2.7 / 7.0.6. Distinct from desk card fortinet-fortimonitoronsight-20260909. Primary: SOCRadar; vendor: FG-IR-25-084; wire: SecurityWeek.

SOCRadar — PivotC2 / CVE-2025-25249

vulnerabilities network

Incidents

Wed 9 Sep

Gigabud Android banking trojan clones apps via Vwork work-profile (Group-IB)

Group-IB (9 September 2026) documents a Gigabud (GoldFactory) banking-trojan chain that installs a second Android app, Vwork, to create a work profile and drop a tampered banking app inside it. Work-profile isolation hides the trojan from the banking app’s malware checks on the personal profile. Confirmed on infected devices in Indonesia. Gigabud arrives as a sideloaded fake airline/tax/government app, demands Accessibility and overlay permissions, overlays fake logins and lock-screen capture, then drives taps via Accessibility under a black screen. Vwork is based on open-source Shelter but strips caller checks so other apps can create profiles, clone apps, and open them; setup is reduced to a single Chinese-language prompt. Order observed: Gigabud → Vwork within minutes → cloned banking app. Distinct from desk card mantax-otax-android-20260910. Primary: Group-IB; wire: The Hacker News (10 Sep 2026).

Group-IB — Vwork app cloning / Gigabud (9 Sep 2026)

breaches identity

Incidents

Wed 9 Sep

Surfshark: internal test server and proxy accessed after misconfiguration

Surfshark's 9 September 2026 incident report says unusual activity on an internal engineering test server was confirmed on 2 September 2026 after a human misconfiguration left the host reachable from the internet. The company contained the same day and finished remediation by 5 September. An unauthorised party accessed limited engineering material (parts of system binaries, internal service configurations, and some build-related credentials that had appeared in code history). Access was also gained to an isolated content-accessibility optimisation VPS used as a proxy with no user identities, IP addresses, encryption keys, or browsing traffic. Surfshark states no user data or production VPN services were affected, no customer action is required, and exposed secrets were rotated or retired. Primary: Surfshark blog incident report; wire: BleepingComputer (10 Sep 2026).

Surfshark — September 2026 incident report

breaches cloud identity

Incidents

Wed 9 Sep

US Treasury/DoJ: Xinbi Guarantee scam marketplace seized; $52.8M crypto frozen

US Treasury OFAC (press release sb0624) designated Xinbi Guarantee, a Chinese-language illicit marketplace supporting cyber scams, fraud, money laundering, and related crime targeting Americans, plus two supporting digital-currency entities — coordinated with DoJ Scam Center Strike Force infrastructure and wallet seizures. THN (9 September 2026) reports ~$52.8M in cryptocurrency frozen across 52 wallets and ~$12M held in two seized payment wallets; Telegram channels hosting the market dismantled. Xinbi acted as escrow between scam-center operators and vendors (pig-butchering sites, laundering, trafficking labour). Treasury notes reported use by North Korean hackers and OFAC-designated entities including Jin Bei Group and Prince Group TCO affiliates. Primary: Treasury OFAC; wire: THN (DoJ PR was 401 from this pass).

US Treasury OFAC — Xinbi Guarantee (Sep 2026)

breaches identity cloud

Incidents

Wed 9 Sep

BlueMoon kit: APT31/JungleBamboo + UTA0560 GRIMWEDGE chain Chrome/Windows 0-days

Proofpoint (9 September 2026) documents BlueMoon, chaining CVE-2026-85046 (Chrome V8 type confusion), CVE-2026-87491 (V8/WebAssembly sandbox escape; patch-gap 0-day), and CVE-2026-85880 (Windows ALPC heap overflow LPE / AppContainer escape; Microsoft September Patch Tuesday + CISA KEV). First in-the-wild use attributed to China-aligned APT31 (Violet Typhoon / Judgement Panda / JungleBamboo) from 28 August 2026; other espionage clusters rapidly reused the kit. UPDATE 15 September 2026 desk (Volexity blog 9 Sep; THN wire 15 Sep): Volexity details two China-nexus clusters using the same byte-identical exploit chain against NGOs via spearphishing through reflected XSS on a legitimate US university site. UTA0560 deploys GRIMWEDGE (obfuscated JavaScript backdoor via MSI custom actions; C2 ocr.opusaccel[.]top; recon/file/process/Run/Upload; no built-in persistence). JungleBamboo/APT31 deploys SUPERSTOMP loader then LONGTALE (aka GemStone) credential-stealing Chrome extension masquerading as Google Gemini (keylogging, cookies, screenshots, ~30s exfil). Distinct from desk cards cve-2026-85046 / cve-2026-87491 / ms-september-2026-patch-tuesday — this card is the shared kit and post-exploitation. Primary: Proofpoint; secondary: Volexity; wire: THN.

Proofpoint — BlueMoon exploit kit (9 Sep 2026)

vulnerabilities network identity

Incidents

Wed 9 Sep

Veradigm: patient PII/SSN copied via vendor API credentials; Gentlemen claim 3.5M records

BleepingComputer (9 September 2026) covers Veradigm's SEC disclosure of a third-party vendor incident: an attacker obtained vendor credentials for a Veradigm customer-services API and copied patient personal details including some Social Security numbers; clinical/medical content and the broader Veradigm network were not accessed per the filing. Veradigm says a small number of customers were affected, notified law enforcement, and is offering credit monitoring where applicable. The Gentlemen ransomware group claimed the intrusion on 5 September and listed Veradigm on its leak site, alleging about 3.5 million patient records and a leak deadline of 11 September 2026 — treat volume and attribution as actor claims pending Veradigm confirmation. Distinct from desk card sharp-office-thegentlemen-20260907 (AU Sharp Office listing). Primary: BleepingComputer (SEC filing).

BleepingComputer — Veradigm / Gentlemen (9 Sep 2026)

breaches identity cloud

Incidents

Wed 9 Sep

AdaptHealth: 4.1M people exposed after June contractor social-engineering breach

BleepingComputer (9 September 2026) reports AdaptHealth confirmed about 4.1 million people were exposed in a cyberattack discovered in July. SEC filing 2 July 2026 disclosed access to cloud business apps including patient management, document storage, and EHR portals. Company update: compromise on 5 June 2026 via social engineering of a third-party contractor's privileged account; ransomware demand around 15 June; data classes named include names, contact and demographic data, health insurance, and health information. HHS submission lists 4,115,802 individuals. Notifications and 12-month credit monitoring offered. Reporting attributes the actor to ShinyHunters; BleepingComputer could not find a current AdaptHealth listing on that group's portal. No Australian nexus identified this pass. Primary: BleepingComputer (company filings).

BleepingComputer — AdaptHealth 4.1M (9 Sep 2026)

breaches identity cloud

Incidents

Wed 9 Sep

Gellibrand Support Services (AU NDIS): Anubis ransomware leak-site listing

Ransomware.live discovered on 9 September 2026 that the Anubis ransomware group listed Gellibrand Support Services on its leak site. Gellibrand is a Victorian NDIS disability support provider (Sunshine VIC 3020 and Ballarat offices; gellibrand.org.au). Treat as a leak-site claim until the organisation or OAIC publishes a primary incident statement. No data-volume figure verified on this pass. Primary: Ransomware.live listing.

Ransomware.live — Anubis / Gellibrand (9 Sep 2026)

breaches australia

Incidents

Tue 8 Sep

Slim Spider: Brazil e-crime cluster steals crypto custody secrets and Pix-linked cloud creds

CrowdStrike (covered by The Hacker News, 8 September 2026) tracks Slim Spider, a Brazil-based e-crime cluster active against Brazilian financial institutions since at least March 2026. In a late-March 2026 multi-stage intrusion at a Brazilian financial institution, the actor targeted crypto custody assets and Pix instant-payment infrastructure: custom Bash scripts queried cloud instance metadata for temporary credentials, enumerated secrets in the cloud credential manager, used Foundry cast to derive an Ethereum wallet address from a stolen private key, and implemented cloud-native signing via OpenSSL. The actor also pivoted to Azure DevOps to run malicious pipelines that deployed implants across a managed Kubernetes cluster, including backdoors mimicking legitimate infrastructure binaries (e.g. "spi" impersonating Sistema de Pagamentos Instantâneos). Primary: CrowdStrike adversary page; wire: The Hacker News.

CrowdStrike — Slim Spider adversary page

breaches cloud identity

Incidents

Tue 8 Sep

Florida FLHSMV confirms DAVID DMV breach via stolen Plant City PD credentials

UPDATE 11 September 2026: the Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a DAVID driver-database breach after ShinyHunters claimed compromise. In a statement posted to X (status 2098239548660514979), FLHSMV said it learned of the breach on 4 September 2026, that it was quickly mitigated, and that no further breach is ongoing. Investigation found attackers used compromised credentials of a single Plant City Police Department user that had been improperly stored on the employee’s personal electronic device. FLHSMV notified the Florida Office of the Attorney General and is working with the Florida Digital Service and Florida Department of Law Enforcement; further detail withheld pending the criminal investigation. FLHSMV has not disclosed how many records were accessed and has not confirmed ShinyHunters’ claim of 200,000+ records. ShinyHunters had claimed a password-reset flaw and multi-account access (including DMV/FBI accounts) iterating DAVID record IDs from 3 September — FLHSMV’s credential finding differs from that claim. Original 8 September desk card covered the unconfirmed extortion claim with Epstein DAVID screenshot as purported proof. No Australian nexus identified. Primary: FLHSMV X statement; wire: BleepingComputer (11 Sep).

FLHSMV statement on X (4 Sep learn / posted around claim period)

breaches identity