BleepingComputer (8 September 2026) reports Sophos analysis of a Linux rootkit targeting F5 BIG-IP APM environments that intercepts PHP loading and injects a fileless web shell in memory so on-disk PHP files stay unchanged. ESET tracks the family as PoisonedRefresh. Sophos describes a separate installer/propagation stage that tampers with Apache /usr/sbin/httpd, SELinux policy, and persistence across BIG-IP upgrade images; the second stage uses RC4 string hiding, hooks __libc_start_main and apr_dso_load, and injects into APM webtop scripts such as apm_css.php3, full_wt.php3, and webtop_popup_css.php3. The web shell accepts magic requests, eval()s decrypted content, and returns HTTP 201 disguised as text/css; a password-protected local UNIX socket can spawn Bash without a TCP listener. Sophos says the payload was likely deployed after exploitation of CVE-2025-53521 (critical RCE that F5 reclassified from DoS in March). Shadowserver reportedly tracked about 795 internet-exposed BIG-IP APM endpoints still vulnerable to that CVE at time of writing. Hunt: Apache workers reading /proc/self/maps, changing libphp memory protections, creating /run/bigtlog.pipe, launching /bin/bash, unusual POSTs to targeted .php3 paths, or HTTP 201 + text/css responses. Wire: BleepingComputer; research: Sophos / ESET.
BleepingComputer — BIG-IP APM PoisonedRefresh rootkit (8 Sep 2026)
breaches network cloud identity
BleepingComputer exclusive (8 September 2026): Kinryū Labs found an internet-reachable Elasticsearch cluster named "pax-info" (Viettel-assigned IP space, Hanoi) holding Advance Passenger Information System (APIS) data — 210,318,069 passenger and 10,465,631 crew records (220,783,700 entries, ~107 GB across 29 indices) spanning January 2017 to April 2026. Fields included names, dates of birth, sex, nationalities, passport/travel-document numbers and expiry, issuing countries, plus flight numbers/dates, airlines, origin/destination/transit airports, seats, baggage refs, and scheduled/estimated/actual times. Sample records reviewed included Korean, Chinese, Canadian, and New Zealand nationalities among others; many international carriers across Asia-Pacific, Europe, and the Middle East appear, so travellers who flew to/from/through Vietnam may be affected (counts are travel records, not unique people). Access path: open internet returned HTTP 401, but a cloud-based path reached the cluster which then accepted default credentials (FOFA saw the host/port from Oct 2022; exposure duration via the second path unknown). Kinryū reported to Vietnamese authorities, airlines, and national CERTs from 3 June 2026; access remediated 8 June 2026 after Singapore Airlines security helped coordinate containment. No ransom notes or sales listings found; without server logs, prior copying cannot be ruled out. Operator organisation not confirmed. Kinryū expects a fuller technical write-up on its blog later this week. Primary wire: BleepingComputer; researcher: Kinryū Labs.
BleepingComputer — Vietnam-linked APIS leak (8 Sep 2026)
breaches australia cloud identity
Sophos analysis (published ~7 September 2026; THN 9 September) describes malware on compromised F5 BIG-IP Access Policy Manager appliances that injects a PHP web shell into memory when Apache loads APM webtop scripts apm_css.php3, full_wt.php3 or webtop_popup_css.php3 — so on-disk file hashes can look clean. F5 previously tracked related activity as malware family c05d5254 and warned those three scripts can be modified or hold in-memory-only shells (IoC list from March). Defenders must not rely on disk-only webshell scans; compare runtime/Apache memory and hunt the F5 IoCs. Related CVE context in wires includes CVE-2025-53521 in some coverage. Watchlist: F5. Primary research: Sophos; wire: THN; vendor IoC context: F5.
Sophos — in-memory PHP web server rootkit (BIG-IP APM)
vulnerabilities network
CloudSEK (7 September 2026) details BigBear 2.0, an Evilginx2-based phishing-as-a-service panel targeting Microsoft 365 with an "offy" phishlet. Researchers obtained admin access to the operator panel (alias "General Boss"): 42 VPS nodes over the campaign lifecycle (many on Vultr/The Constant Company), geo-matched residential proxies, Telegram exfiltration bots for at least five affiliates, and cookie replay after victims complete MFA. Panel telemetry cited by CloudSEK: 5,137 credential records (474 complete MFA-bypassed authentications, 1,032 plaintext passwords, 4,148 session cookies) across 3,331 unique victim IPs in 40+ countries; BleepingComputer notes 258 organisations with at least one completed MFA-bypass compromise (461 in the broader targeting set). Custom JS can weaken phishing-resistant MFA (FIDO2/WebAuthn) toward weaker methods. Operation still active at publish time. Primary: CloudSEK blog; wire: BleepingComputer (7 Sep 2026).
CloudSEK — Tracking BigBear 2.0 Evilginx2 PhaaS (7 Sep 2026)
breaches identity cloud
Cyber Daily (9 September 2026) quotes a Sharp Office spokesperson confirming a cyber incident affecting some parts of its systems: the Broadmeadow office-technology supplier engaged external responders, contained and restored business systems (operational at time of quote), and said it notified the Australian Cyber Security Centre. The Gentlemen ransomware group had listed Sharp Office (sharpoffice.com.au) claiming a data publish window; ransomware.live shows discovered 2026-09-07. Investigation ongoing; no public headcount or OAIC notice fetched this pass. Distinct from earlier Sharp Motor Group third-party incident. Primary: Cyber Daily with company confirmation; listing: ransomware.live AUS.
Cyber Daily — Sharp Office confirms incident (9 Sep 2026)
breaches australia
Mathspace's incident blog (published 5 September 2026, updated 6 September 2026) says attackers exploited a security vulnerability in its self-hosted Metabase internal-reporting install, obtaining administrator access without a legitimate login. Metabase published a critical advisory and patches on 6 August 2026; Mathspace says its vulnerability-notification process did not escalate that advisory, and it only updated on 29 August after a later Metabase notice. Unauthorised access dated from 10 August 2026 AEST; data was downloaded from the Australian reporting database on 27 August; Mathspace confirmed the historical access on 3 September. About 1,079,819 people in Australia and New Zealand were affected (students, parents/guardians, school staff, and Mathspace staff). Exported fields included user ID, username, names, email, country, time zone, user type, email-verification status, and last-active / last-login / date-joined. Passwords, SSO tokens, API credentials, academic records and school-link tables were not exposed. School notifications began 4 September. Mathspace notified the OAIC, ASD's ACSC, NZ OPC, NZ NCSC, and Australian state/territory education departments. The timeline matches Metabase CVE-2026-72898 (GHSA-vwf4-m7j8-wcjf); Mathspace's post does not name the CVE. Primary: Mathspace incident blog.
Mathspace incident blog (updated 6 Sep 2026)
breaches australia cloud
Trezor's blog (original 13 August 2026; updated 4 September 2026) says ShipMonk, a shipping provider, suffered unauthorized access. On 2 September 2026 Trezor was told the breach also held order data from prior cooperation (November 2019–August 2021) that ShipMonk had repeatedly assured in writing had been deleted. That tranche affects about 67,000 further US customers with full exposure of name, email, phone, shipping address and order number; all were emailed from privacy@satoshilabs.com. Hardware wallets are not affected; phishing and physical-security risk rise for exposed addresses. Earlier August disclosures covered customers who ordered to US/UK/Sweden/Colombia/Brazil/Italy/Portugal between 10 May and 8 August 2026 (about 11,742 in the original summary, with later August clarifications). Reporting ties ShipMonk's break-in to exploitation of Metabase CVE-2026-72898 (CVSS 10.0 SQLi) and names ShinyHunters as a claimed extortion actor — treat that attribution as third-party reporting, not a Trezor confirmation. Primary: Trezor blog update. UPDATE 11 September 2026: Trezor’s Brevo blog says on 9 September 2026 Brevo (newsletter platform) had a security incident affecting 120 Brevo accounts; an unauthorised actor sent mail from customer accounts including Trezor’s. About 347,000 opt-in newsletter addresses were exposed for further phishing risk; no other Trezor systems were touched and the Brevo account was suspended. Phishing used subject “Critical Security Alert: STM32 Entropy Vulnerability,” linking to a fake app that asked for wallet backups. Trezor took the phishing domain down at DNS within ~20 minutes, limiting clicks to about 2,500 people, and notified customers. Do not enter seed phrases from email links. Primary Brevo post: trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider; wire: BleepingComputer (11 Sep).
Trezor blog — ShipMonk incident (updated 4 Sep 2026)
breaches identity cloud
Arctic Wolf Pack Alert (3 September 2026) tracks PREY-0058: executives (directors/VPs) are cold-called by actors impersonating internal IT/help desk and steered to authentication-themed lure domains (assignpasskey.com, mfaregister.com, nowsso.com, oskeysetup.com, oursso.com, passkey-mfa.com, passkeydeploy.com, registermymfa.com, setpasskey.com and org-specific subdomains). An operator-gated AiTM Microsoft 365 login harvests credentials and MFA approvals; stolen sessions are replayed via residential proxies (notably NodeMaven, often same geo/ASN as the victim). Post-access discovery hits SharePoint/Entra (SearchQueryPerformed with contentclass:STS_Site/STS_Web and indexdocid pagination), then bulk exfil from SharePoint, OneDrive, Exchange, and Box — no endpoint malware or network lateral movement observed. Overlaps GTIG UNC6671 tradecraft; related extortion brands cited include BlackFile, Pink, Helix, Cinder, and Redact (affiliate/rebrands, not a single proven identity). Targets primarily US construction/engineering, healthcare/pharma, real estate, finance, professional services. Defences: phishing-resistant MFA (FIDO2/device-bound passkeys), Conditional Access (device compliance; block proxy/hosting ASN), Continuous Access Evaluation, tighten SharePoint scope, train staff that IT will not cold-call for passkey enrolment. Wire: The Hacker News (7 Sep 2026). Distinct from BigBear Evilginx2 PhaaS already on desk.
Arctic Wolf Pack Alert — PREY-0058 (3 Sep 2026)
breaches identity cloud
iTnews (3 September 2026) reports the Australian Communications and Media Authority fined Telstra $277,000 for not applying required identity-authentication processes to prevent SIM-swapping fraud. ACMA said the fraud caused at least $39,500 in losses to 15 customers between January and October 2025, with 13 further attempts where agents failed to add fraud protections or to act on risk signals; ACMA member Samantha Yorke said frontline staff did not follow Telstra's own processes. SIM swaps let attackers move a victim's number onto their own SIM and intercept MFA codes and other mobile traffic. ACMA accepted court-enforceable undertakings for stronger fraud prevention and staff training. Context in the same report: a larger $1.551 million Telstra penalty in July 2024 for related ID-authentication failures, and more than $5 million in ACMA telco fines to date on mobile-number fraud. Watchlist relevance: Telstra.
iTnews (3 Sep 2026)
australia identity
Ransomware.live’s Australia country feed (observed 4 September 2026) lists Victorian photography business Verve Portraits (verveportraits.com.au) under the Settra brand, discovered 3 September 2026 with an estimated attack date of 13 August 2026. No company statement, OAIC notice, or ACSC advisory was located on this pass, so treat the listing as an unconfirmed extortion claim until a primary notice appears. Australian operators in professional services should still verify backups, MFA, and remote-access exposure.
Ransomware.live Australia (listing observed 4 Sep 2026)
australia
UPDATE 14 September 2026: Cyber Daily’s Penfold Motors exclusive states machinery management specialist Macquarrie recently confirmed it is responding to a cyber security incident at a third-party supplier — elevating the earlier ransomware.live Storm listing (discovered 3 September 2026; estimated attack 1 September) from leak-site-only to company-acknowledged supplier compromise. No separate Macquarrie customer-notification text, OAIC entry, or ACSC advisory was fetched beyond that Cyber Daily confirmation. Same Storm wave as Penfold Motors and other Australian automotive/farm-machinery dealers. UPDATE 15 Sep 2026: Cyber Daily names Auto-IT as the third-party software firm whose customer environments were hit via abused RMM (see auto-it-storm-20260915). Primary confirmation wire: Cyber Daily (14 Sep); listing context: ransomware.live AUS.
Cyber Daily — Macquarrie confirmation in Penfold/Storm piece (14 Sep 2026)
australia ot ics
BleepingComputer (3 September 2026) reports France’s CNIL fined Hôpital privé de la Loire (HPL, Ramsay Santé group, Saint-Étienne) €500,000 for GDPR security and notification failures after a summer 2025 intrusion into the electronic patient record system exposed sensitive data of 524,867 patients plus 202,246 trusted third parties (about 727,000 people). CNIL findings cited include external physician access without VPN or multi-factor authentication, overly broad access once an account was compromised, lack of near-real-time monitoring that let exfiltration run for days, and failure to directly notify the trusted-third-party cohort (Articles 32 and 34 GDPR). A teen using the alias “Marak” claimed the path began with one doctor’s account and tried to sell the data; reporting says it was neither sold nor published. HPL strengthened controls during proceedings. Practitioners: remote clinical access needs MFA and VPN; least privilege on EPR; detection that catches multi-day bulk extract; notify every category of affected individual.
BleepingComputer (3 Sep 2026)
breaches identity