Latest cyber news, threats, security, and guidelines. Stack up.

Incidents

Mon 31 Aug

Softaculous/Virtualizor: BGP hijack delivered a malicious hypervisor update

Softaculous' Virtualizor incident post (31 August 2026) says IP block 162.55.80.0/24 (Hetzner space used by Softaculous services) was BGP-hijacked from about 20:57 UTC on 28 August to about 06:10 UTC on 30 August. An unauthorised announcement by AS62390 (NexonHost), transited via AS6204 (Zet.net), was more specific than Hetzner's 162.55.0.0/16 and diverted traffic, including the software-update endpoint and client-area/billing site. The attacker obtained a technically valid Let's Encrypt certificate for Virtualizor, Softaculous and related names, so diverted connections showed no certificate warning. The vendor confirmed a malicious Virtualizor update package reached a small number of installations that checked for updates during diversion; it cannot list every affected host. Known indicator: systemd unit /etc/systemd/system/java-jre-update.service. Routing has been restored. Operators should hunt that unit (and not only delete it), rotate Virtualizor API keys, and audit SSH keys, accounts and cron. The vendor shipped Virtualizor 3.2.9.9 with a mitigation tool and says package signing is coming. Other Softaculous products had no identified malicious package at the time of the post. Clients who logged into the billing site during the window should reset that password.

Virtualizor incident post (31 Aug 2026)

tech cloud

Incidents

Mon 31 Aug

Berlin confirms data theft and extortion after state-network cyberattack

Berlin's official 31 August update says the city is facing extortion after the mid-August cyberattack on its administrative network and will not pay. Forensic work confirmed data left the Senate Department for Mobility, Transport, Climate Protection and the Environment between 7 and 12 August; the scope is still being assessed and personal or other non-public data may be involved. Berlin says the affected departments were disconnected on 14 August and investigations by state police, prosecutors and federal security authorities continue. BleepingComputer reports that the Rhysida ransomware group claimed the attack and a much larger theft, but Berlin's notice does not attribute the incident or confirm the actor's volume and content claims.

Berlin.de official update (31 Aug 2026)

breaches

Incidents

Fri 28 Aug

Pacific ABS / pacificabs.com (AU): Settra leak-site listing (ransomware.live)

Ransomware.live’s Australia country feed lists pacificabs.com (Pacific Global Solutions / PABS / Atteign LLC; professional-services activity tag) under the Settra brand — feed published date 28 August 2026, discovered on the tracker 17 September 2026 (API id cGFjaWZpY2Ficy5jb21Ac2V0dHJh). Claim text references documents and a prologue mentioning 40+ American businesses; treat as an unconfirmed extortion claim. No company website incident notice, OAIC notice, Webber Insurance list entry, or ACSC advisory was located on this 18 September 2026 04:00 Perth desk pass. Distinct from prior AU Settra desk card verve-portraits-settra-20260903. Australian operators should verify backups, MFA, and remote-access exposure until a primary notice appears.

Ransomware.live — pacificabs.com / Settra (discovered 17 Sep 2026)

australia

Incidents

Fri 28 Aug

JetBrains Cadence: TeamCity CVE-2026-63077 missed; customer data and secrets exposed

JetBrains' Cadence incident post (opened 28 August 2026, last updated 1 September 2026 12:05 CEST) confirms unauthorized access to Cadence, a JetBrains-hosted cloud-compute service for PyCharm via an optional plugin that orchestrates work with TeamCity. The Cadence host api.cadence.jetbrains.com was vulnerable to CVE-2026-63077 (desk card cve-2026-63077) and was exploited; activity from 8 August to 24 August 2026; discovered 23 August; server taken offline 24 August. Confirmed: personal data extracted (usernames, real names, emails, last-login times, last IPs); a full 2024 Cadence server backup compromised (treat credentials/config/artifacts in that backup as exposed); multiple AWS IAM users/secrets used with Cadence compromised from that backup; files in JetBrains Cadence S3 buckets accessed; possible access to source synchronized from PyCharm. JetBrains says no evidence secrets were taken from the live environment beyond the backup path, invalidated Cadence plugin access tokens, and lists IoC IPs (150.109.230.104, 43.153.227.206, 62.210.127.48, 210.247.242.190, 15.235.225.205, 152.233.30.18). Users must rotate all credentials used in Cadence executions and treat inputs/outputs as untrusted. Distinct from the On-Premises TeamCity ACSC exploitation card: this is JetBrains' own hosted Cadence service.

JetBrains Cadence incident post

tech cloud identity

Incidents

Fri 28 Aug

@7nohe/openapi-react-query-codegen: ten published versions after an abused GitHub Actions publishing workflow

Socket (28 August 2026) reports that ten versions of npm package @7nohe/openapi-react-query-codegen were published that day after a comment-triggered GitHub Actions trusted-publishing workflow was abused. An untrusted GitHub account could comment a publish trigger on a pull request and ship fork code under the repository OIDC identity. Versions named by Socket and Step Security are 0.5.4, 0.5.5, 1.6.3, 1.6.4, 2.2.1, 2.2.2, 3.0.3, 3.0.4, plus two 0.0.0-sha prerelease tags. Stable releases ran obfuscated JavaScript 3FWCvzduYZg.js via binding.gyp and/or a preinstall hook. Socket describes Mini Shai-Hulud-consistent self-propagation. Install-time code targeted cloud credentials, package-registry credentials, GitHub Actions secrets and AI-agent configuration. All ten carried valid npm provenance. Pin known-good 0.5.3, 1.6.2, 2.2.0 or 3.0.2, isolate affected hosts, then rotate tokens. This desk does not attribute the package to TeamPCP; Socket and Step Security do not name that group.

Socket (28 Aug 2026)

tech cloud identity

Incidents

Fri 28 Aug

ATF confirms cyber incident on a standalone system after Qilin listing

SecurityWeek (28 August 2026) reports the US Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a cybersecurity incident after the Qilin ransomware group listed the agency. ATF's statement, as quoted there, says the intrusion hit a standalone system that was disconnected once discovered, that the system sits apart from the ATF enterprise network, and that there is no indication the enterprise network, eForms, or any other ATF system was affected or that ATF cannot perform its missions. An investigation is underway with the Justice Department; senior DOJ officials designated the event a major incident under federal guidelines and required notifications were completed. Qilin added ATF to its leak site on 26 August; SecurityWeek says the post made no specific claims, showed no stolen-document screenshots, and did not set a leak timer. Actor claims are not treated as verified facts on this desk. ATF's press-release URL returned 403 from this pass; facts are from SecurityWeek quoting the statement.

SecurityWeek (28 Aug 2026; quotes ATF)

breaches

Incidents

Fri 28 Aug

Hasbro: employee personal and financial information accessed

Hasbro's Massachusetts consumer letter (OCABR 2026-1427, posted in the August 2026 breach-letter list) says a data security incident may have involved employee personal information after a compromised employee account. Hasbro says it disabled that account, terminated unauthorised access, and added safeguards. The letter says involved information varied and may have included name plus one or more of email, address, phone number, national ID number, or financial information. BleepingComputer, citing the Massachusetts 2026 Data Breach Notification Report, says 436 Massachusetts employees had Social Security numbers, financial-account information, credit/debit card numbers, or driver's-licence information involved. Hasbro has not published a nationwide total. Hasbro did not link this notice to its March 2026 incident. No customer impact is stated in the letter.

Hasbro MA consumer letter (2026-1427)

breaches identity

Incidents

Fri 28 Aug

Sharp Motor Group (Tweed Heads): third-party IT provider cyber incident; OAIC notified

Cyber Daily's 28 August 2026 report quotes a Sharp Motor Group spokesperson confirming the Tweed Heads, NSW dealership is aware that its third-party IT provider has been involved in a cyber incident. The company said it is working with independent cyber specialists and relevant authorities, has notified the OAIC, and that staff and customer privacy remain the priority. Cyber Daily reports the Storm ransomware group listed Sharp Motor Group in a 23 August leak-site post and published sample files it claims were taken (including identity documents and financial material); those actor claims and any data-volume figures are not independently confirmed in the company statement and are not treated as verified facts on this desk. Storm has also listed other Australian automotive and machinery firms this month; company responses for those other listings were not confirmed in the same report.

Cyber Daily (28 Aug 2026; quotes Sharp Motor Group)

australia retail

Incidents

Fri 28 Aug

McKesson: cybersecurity incident with third-party apps and data exfiltration

McKesson's 28 August 2026 customer notice and Form 8-K say it discovered a cybersecurity incident on 25 August 2026 affecting its information systems. The company says the investigation is in early stages and involves third-party applications plus unauthorised access and exfiltration of data. Updates are posted at mckesson.com/cybersecurity. A 29 August 2026 customer note on that page (heading: McKesson Cybersecurity Incident Investigation and Response Update) says McKesson continues to serve customers across all lines of business and accept orders, distribution centres remain operational, and shipping continues. That note does not add scope, named applications, or confirmation of actor claims. As of the 8-K filing date, McKesson had not determined the incident to be material or reasonably likely to have a material impact on financial condition or results of operations. The company has not publicly named the applications involved, the access path, or what was taken. Secondary reporting attributes claims by the ShinyHunters extortion group (including a large patient-record count and Okta/Salesforce/Snowflake access via vishing); those actor claims are not confirmed in McKesson's notice or 8-K and are not treated as verified facts on this desk.

McKesson cybersecurity notice

breaches healthcare

Incidents

Thu 27 Aug

NSW Police charge a Sydney telco employee over alleged sale of customer data

iTnews (28 August 2026), citing an NSW Police statement, reports that a 30-year-old telecommunications employee was arrested at a police station in Sydney's west and charged over allegedly accessing customer data through his employment and selling it to criminal groups. Police allege the information was then used to commit fraud against multiple victims. Charges listed in that report are 12 counts of deal with identity info to commit an indictable offence, 12 counts of unauthorised function with intent to commit a serious offence, and 10 counts of agent corruptly receive benefit (34 offences). The arrest followed a Queensland Police referral. iTnews does not name the employer. The National Tribune reprint of the police release dates the arrest about 9.30am on Thursday 27 August 2026, refused bail to Liverpool Local Court the same day. These are allegations before a court.

iTnews (28 Aug 2026; quotes NSW Police)

australia identity

Incidents

Thu 27 Aug

Manchester Airports Group: FulcrumSec leaks ~550GB / HIBP ~8.8M emails and phones after ransom refusal

MAG’s 27 August 2026 statement said an unauthorised third party obtained customer data from car park, lounge and Fast Track bookings and in-airport Wi-Fi sign-ups at Manchester, London Stansted and East Midlands airports (emails, phones, vehicle registrations, postcodes; no bank details; operations unaffected). SecurityWeek (3 September 2026) reports the FulcrumSec extortion group published roughly 550GB of uncompressed data after MAG reportedly refused a ransom, claiming access via exposed admin keys. Have I Been Pwned, which ingested the dump, put the scale at about 8.8 million email addresses and phone numbers, with names, browser agents, purchases and vehicle plates also present. FulcrumSec claimed on the order of 2.48 million purchases in the set. MAG’s original mediacentre statement remains the operator notice; treat FulcrumSec/HIBP figures as leak-site and breach-notification telemetry refining scope.

MAG statement (27 Aug 2026)

breaches identity

Incidents

Thu 27 Aug

Alliance Distribution Services (Hachette Australia): systems disruption after unauthorised activity

Hachette Australia told ABC News that unauthorised activity on the computer systems of its distribution subsidiary Alliance Distribution Services (ADS) was believed to have occurred on 18 July 2026. As of the 27 August 2026 ABC report, Hachette said it was still restoring systems and services, could not yet confirm a timeline for a full return to normal operations, and that restoring full operations securely remained its top priority. The disruption has hit book supply to Australian bookshops and authors ahead of the busy trading period. Hachette has not publicly confirmed whether the incident involved ransomware, data theft, or another form of attack. Secondary commentary that labels the event ransomware remains unverified by the company.

ABC News (quotes Hachette)

australia supply chain