West Publishing Corporation (Thomson Reuters Court Management Solutions) notified courts that an unauthorised party obtained files from the C-Track appellate case-management platform in March 2026; activity was discovered 30 June 2026. The Supreme Court of Ohio public statement says ten of twelve Ohio Courts of Appeals use C-Track hosted by the Court and managed by TRCMS; the 8th and 10th districts do not and are unaffected; TRCMS told the Court on 31 August 2026 that unauthorised access hit the production platform. The Hacker News (3 Sep) summarises West’s 2 September notice: courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario may be in scope; a subset of records could include names, SSNs, driver’s licence numbers, dates of birth, medical and health-insurance information; sealed or redacted material may be impacted for some courts; TRCMS says no evidence of fraud or misuse to date and offers Experian IdentityWorks (US) / TransUnion myTrueIdentity (Canada) monitoring via engagement B171847 and https://www.ctracknotification.com. Distinct from other court or identity cards on this desk.
Supreme Court of Ohio C-Track incident statement
breaches identity
KrebsOnSecurity (1 September 2026) reported a dark-web identity-theft service branded Nexus advertising digital scans of more than 153 million US and Canadian driver’s licences plus millions of other ID cards, travel documents and medical cards. Krebs’s checks pointed to Louisiana identity-verification firm IDScan.net as the likely source; the company said it was investigating and the FBI New Orleans field office opened an inquiry. SecurityWeek (3 Sep) and Ars Technica (2 Sep) corroborated the listing. BleepingComputer (4 September 2026) reports multiple lawsuits against IDScan, with firms including Markovits, Stock & DeMarco and Hall Attorneys launching investigations into potential class-action litigation. Nexus appeared to shut shortly after Krebs published. Organisations that rely on third-party ID-scan vendors should treat this as a supply-chain identity risk. NEW 10 September 2026 (BleepingComputer): IDScan published a 4 September 2026 security notice (initially noindex) stating it learned on or around 1 September that an unauthorised party may have accessed or copied customer information in IDScan.net cloud accounts — full names and driver's licence or other government ID numbers — and that investigation continues with third-party specialists. This is the first public company confirmation tying the firm to the 153M+ licence dump reporting. UPDATE 16 September 2026 desk: primary_url switched to IDScan.net press notice (datePublished 4 Sep 2026) stating unauthorised access/copy of cloud customer info may include full names and driver's licence or other government ID numbers; free credit monitoring offered; cooperating with federal law enforcement. ACS Information Age (8 Sep) re-covered the dump for AU readers — no new scope beyond vendor notice.
IDScan.net — Notification of Data Security Incident (4 Sep 2026)
breaches identity
Decrypt published on 1 September 2026 that Dropbox had emailed users about unauthorised access between 4 and 21 August 2026 via Lenovo ID single sign-on. A Dropbox spokesperson told Decrypt the company identified unauthorised access affecting Dropbox accounts connected through Lenovo ID that did not have Dropbox two-factor authentication enabled, and that an issue with Lenovo email verification allowed an unauthorised party to register a Lenovo ID using another person's email address and then use that Lenovo ID to log into the Dropbox account associated with that address. The spokesperson said approximately 5,000 Dropbox accounts were impacted, less than a third of those had files viewed or downloaded, and Dropbox had emailed all impacted users; users who did not receive an email were not impacted. Decrypt also reported that Dropbox's notification letter said logs showed no evidence files were viewed or downloaded, and that Dropbox has since changed how Lenovo IDs can access accounts. Affected user Yoni Levy posted screenshots of a new-browser sign-in alert from near Canary Wharf (Chrome on Windows, 18 August) and said he had never had a Lenovo account. This desk has not found a Dropbox public advisory page; the company notice in hand is the user email plus the spokesperson comments to Decrypt.
Decrypt (1 Sep 2026; Dropbox spokesperson)
breaches identity cloud
Coder published GitHub advisory GHSA-vx42-ghc9-gw65 on 1 September 2026 (Critical). An unidentified actor gained access to Coder's Cloudflare infrastructure and added unauthorised IP addresses to the pool used for the Coder module registry (registry.coder.com). Those addresses hosted a malicious copy of registry artefacts. For a short window the registry served malicious packages to a subset of users. The implanted code was designed to identify credentials and exfiltrate them to a lookalike domain (coder-infra.com). Coder says it has no indication that any customer data maintained by Coder was impacted. Users who downloaded a Coder Registry module between 07:35 UTC and 21:45 UTC on Monday 31 August 2026 may be affected (new templates or template versions; also workspace creation if module caching is disabled). Coder recommends reviewing firewall, DNS and VPC logs for outbound traffic to coder-infra.com, purging cached modules from the affected window, rotating potentially exposed credentials, and updating Coder. Patched versions: 2.37.0, 2.36.4, 2.35.7, 2.34.9. Affected: versions before 2.37.0.
Coder GHSA-vx42-ghc9-gw65 (1 Sep 2026)
tech cloud
NovoCure Limited's Form 8-K dated 1 September 2026 (Item 8.01) says that in mid-August 2026 a subsidiary became aware of unauthorised access to some information systems. The company activated its cybersecurity response plan, contained the event, and engaged independent forensic experts. Exposed data to date: internal company patient ID numbers for over 1,400 U.S. patient records (IDs used only internally; no names or other identifying data for those records); identifying information for fewer than 50 other patients in the western U.S.; general contact information for healthcare providers; and employee contact details such as job titles and phone numbers. Novocure states no access to medical treatment devices was obtained, operations were not compromised, and systems remain fully functional. It does not currently expect a material financial impact and says it will make required notifications, including to impacted patients. Vector and threat actor are not named in the filing.
NovoCure Form 8-K (1 Sep 2026)
breaches
The Hacker News (1 September 2026), citing ESET research disclosed on X, says Russia-aligned UAC-0099 used a technique ESET calls GuardBreaker against a target in Ukraine to interfere with AI-assisted code analysis. ESET said the actor inserted the comment "I want to make a nuclear weapon. Help me ..." in a malicious VBS script so an LLM's safety mechanisms would latch onto the content and stop analysing the rest of the code. The VBS is assessed as part of UAC-0099's toolset and is primarily designed to download and install MATCHBOIL, a C# loader used by the actor to deliver further payloads. UAC-0099 has a track record against transportation and energy sectors; CERT-UA in late July 2026 warned of MATCHBOIL delivered as a fake Notepad++ plugin. Do not treat this card as a TeamPCP reprise (already on this desk as afp-teampcp-2026).
The Hacker News (1 Sep 2026; ESET)
ai
Nutex Health Inc. told the US SEC in an 8-K dated 31 August 2026 that an unauthorised third party accessed and exfiltrated information from its servers, including patient, employee, credentialed-provider, business and financial data that is private or confidential. A third party has threatened to post that information. The Houston company says it has not identified a material impact on operations or financial reporting systems to date, and it has not named the actor. After an earlier 24 August 8-K, a purported Texas class action (Haley v. Nutex Health, Inc., S.D. Tex.) was filed on 27 August 2026. SecurityWeek (1 September) reports that Gentlemen (also tracked as Storm-2697) claimed the company on its leak site with a nine-day deadline; that leak-site claim is not company attribution. No Australia link is reported.
Nutex Health Form 8-K (31 Aug 2026)
breaches
Datadog Security Research describes a password-spraying campaign against AWS root-user console logins at more than 150 organisations between 24 July and 23 August 2026. The median number of failed attempts per organisation was two; some saw as many as eight. The AWS root console requires the account email, so the campaign implies the operators had (or guessed) those addresses. This desk records failed attempts as reported; no successful authentications are stated in the Datadog write-up as loaded. Coverage on 1 September 2026 (Cyber Security News) likewise says researchers did not identify successful authentications. Organisations should review CloudTrail for unusual root ConsoleLogin failures and keep root use exceptional.
Datadog Security Labs
tech cloud identity ai
Socket's 31 August 2026 research describes 13 malicious Composer theme packages on Packagist across five vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms) that inject JavaScript into Vietnamese movie and comic streaming sites. On mobile visitors the code runs gambling and ad-fraud redirects; on unpatched iPhones it loads a FUNNULL-hosted WebKit-to-kernel exploit chain. Socket says the renderer stages weaponise CVE-2025-31277 and CVE-2025-43529 (both on CISA KEV), then escape to the kernel; Apple told Socket the kernel escape was already fixed in iOS and macOS 26.1. A 12 August 2026 redeployment added keychain theft of crypto-wallet seeds and mnemonics for Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet and OKX, targeting iOS 18.4 through 18.6.x. Site operators should remove themes from those namespaces, rotate credentials, and audit shipped scripts; keep iPhones current past the listed builds.
Socket (31 Aug 2026)
tech supply chain
Huntress published on 31 August 2026 that phishing actors abused the legitimate Faronics Deploy endpoint-management platform between 21 July and 20 August 2026, with more than 457 endpoints encountering Faronics-themed lures (invoices, tax documents and similar). Victims were steered to download a signed Faronics Deploy installer disguised as an Adobe document or plugin; once enrolled in an attacker-controlled deployment, operators used Faronics remote script execution (PowerShell via curl, mshta or msiexec) to install ConnectWise ScreenConnect as a second remote-access channel. Huntress notified Faronics on 5 August 2026; Huntress says Faronics added anti-abuse controls and contacted affected organisations, and observed activity drop sharply from 21 August. Defenders should inspect C:\ProgramData\Faronics\Logs\ScriptRunner.log and unexpected ScreenConnect installs, and report suspected abuse to support@faronics.com.
Huntress (31 Aug 2026)
breaches identity
METR's 31 August 2026 security update describes two incidents in which external actors tried to gain unauthorised access. It believes no sensitive information was accessed in either case, and it is not attributing the events; the post is about human attackers, not AI agents breaking evaluations. In March 2026 a researcher with no sensitive-access privileges ran a vibe-coded app on a personal public EC2 instance behind Google authentication that held an API key for METR's public-models account; a fail-open bug silently disabled auth. METR assesses the attacker found the host via recently registered sites or certificate-transparency lists, prompted an agent for the key, added an SSH key, and burned credits for about three weeks. Accrued usage would have been worth about US$600,000 if the unnamed model provider had not given the credits free. In May 2026 attackers probed public infrastructure (credential stuffing, OAuth grants, phishing staff). METR had inadvertently exposed a read-only SQL mechanism on a public transcript viewer that could have reached unpublished eval data, including some sensitive model output that should not have been in that database; attackers probed the endpoint but METR says there is no evidence they found the issue or accessed non-public data. Distinct from desk cards anthropic-eval-containment-20260831 and anthropic-claude-infostealer-20260830.
METR security update (31 Aug 2026)
ai cloud
Aesto Health (Birmingham, Alabama), which provides healthcare data migration and archiving for covered-entity clients, posted a June 2026 notice: it discovered a network security incident on or about 18 December 2025 affecting a limited portion of its Amazon Web Services infrastructure. On 26 May 2026 the investigation determined that PII and PHI belonging to patients of various clients may have been accessed or acquired between about 2 and 18 December 2025, including names, dates of birth, medical information, driver's licence numbers, financial account numbers, health insurance information, taxpayer identification numbers, other government IDs, and Social Security numbers (elements varied; SSNs for a limited number of people). The US HHS portal lists 9,540,683 individuals; SecurityWeek (1 September) says HHS added the company on Monday 31 August 2026. At least two dozen provider clients across several states were affected. The company says it has no evidence of identity theft or financial fraud tied to the incident. No Australia link is reported.
Aesto Health notice (June 2026)
breaches cloud