Latest cyber news, threats, security, and guidelines. Stack up.

Incident
Published 2026-09-17
Verified 2026-09-19

US Coast Guard/FBI board two Texas-bound oil tankers after voyage cyberattacks (VL Prosperity)

SecurityWeek (17 September 2026), citing CBS News / US officials, reports that US Coast Guard and FBI personnel boarded two Texas-bound oil tankers last month after cyberattacks disrupted the vessels en route to the United States. Named ship: Liberian-flagged crude tanker VL Prosperity (left Egypt 1 August en route to Galveston per vessel-tracking cited by CBS). Iran’s Mehr News Agency (20 August) alleged an 7 August Strait of Gibraltar intrusion affecting engine-room systems (coolant/fuel/engine speed), navigation/cargo, and ~30 hours of lost communications — US Coast Guard has not publicly attributed the incident to Iran. A Coast Guard cyber / law-enforcement / FBI Cyber Action Team boarded VL Prosperity the day after Mehr’s report and spent four days aboard; Wall Street Journal reported the second ship boarded 24 August after Gulf of Mexico arrival. Rear Adm. Amy Grable (Coast Guard Cyber Command) told CBS investigators found evidence of a malicious cyber actor on IT/onboard systems and that the tanker was not judged unsafe to operate; ~40–50 similar Cyber Protection Team boardings in the past year. Investigators still assessing whether the two tanker incidents are connected or state-linked. Wire-primary until a Coast Guard/FBI primary release is posted. OT/maritime relevance for AU shippers and ports.

Product
Maritime vessel IT/OT (engine-room / navigation / cargo / SATCOM — as alleged in open reporting; not a product CVE)
Versions
n/a
Exploited in Australia?
unknown
Patch to
Maritime operators: segment vessel IT/OT, restrict remote/SATCOM admin paths, monitor engine/navigation anomaly alarms, rehearse cyber boarding/forensics with flag-state guidance

Primary: SecurityWeek — oil tanker cyberattacks / CG–FBI boardings (17 Sep 2026)

tech ot ics network

Incident
Published 2026-09-17
Verified 2026-09-19

FBI seizes NightmareStresser DDoS-for-hire domains (Operation PowerOFF)

BleepingComputer (17 September 2026) reports the US FBI seized nightmare-stresser[.]com and nightmarestresser[.]org used by NightmareStresser, a long-running DDoS-for-hire (booter) service. FBI Cyber Division said that since 2022 the service was used to launch hundreds of thousands of actual or attempted DDoS attacks worldwide. Seizure banners cite Operation PowerOFF, the international law-enforcement effort against DDoS-as-a-service infrastructure. Historical context: Searchlight Cyber (2023) previously assessed ~566k registered users and up to ~200 Gbps multi-layer attacks; DOJ had seized nightmarestresser[.]com once before in December 2022 with related arrests. Primary wire: BleepingComputer quoting FBI Cyber Division / PowerOFF seizure banner (FBI press index 403 from this pass; no separate DoJ HTML confirmed).

Product
NightmareStresser (DDoS-for-hire / booter)
Versions
n/a (law-enforcement infrastructure seizure)
Exploited in Australia?
unknown
Patch to
Defenders: expect residual copycat booters; keep DDoS playbooks current; report booter solicitation; no product patch

Primary: BleepingComputer — FBI seizes NightmareStresser (17 Sep 2026) · THN — NightmareStresser domain seizures (17 Sep 2026)

tech network

Incident
Published 2026-09-16
Verified 2026-09-19

Gyazo (Helpfeel): ~23.62M user records + ~490M image metadata exposed after upload-server RCE

Helpfeel Inc. notice (16 September 2026 JST; Kyoto) confirms unauthorised access to Gyazo’s image-sharing service. On 11 September 2026 a third party exploited a vulnerability in Gyazo’s image upload server to run arbitrary commands; Helpfeel says it blocked access routes by early 12 September and remediated the flaw. Confirmed disclosure: ~23.62 million user-related records (fields vary — may include name/nickname, email, password hash, user/device/session IDs, X/Twitter token, Google SSO email, profile/language, registration/last-login, plan and billing status without card numbers) and ~490 million image metadata records primarily for images registered in/before January 2019 (~14.4% of image-related data), plus ~2.4 million further metadata records via filtering. Metadata includes values used to build Gyazo image URLs (upload IP, User-Agent, EXIF location, OCR text, titles, source URLs, hashed passphrases for private images); Helpfeel temporarily disabled access to files whose records were exposed and cannot rule out that some private images were viewed. UPDATE 18 Sep 2026 (BleepingComputer): Gyazo service temporarily suspended for preventive maintenance while recovery continues; Helpfeel/Cosense not confirmed impacted beyond Gyazo; users being notified; no evidence of data deletion from this incident. No payment-card data confirmed disclosed. Users: change Gyazo passwords and any reused passwords; report filed with Japan’s Personal Information Protection Commission. Primary: Helpfeel corp notice; wires: THN 17 Sep / BleepingComputer 18 Sep.

Product
Gyazo (Helpfeel Inc. image-sharing / screenshot service)
Versions
n/a (SaaS incident; upload-server vulnerability remediated per vendor)
Exploited in Australia?
unknown
Patch to
Gyazo users: change password and any reused passwords; watch phishing; treat old image URLs as potentially enumerable if metadata leaked; expect service downtime while Gyazo remains suspended for maintenance; operators using Gyazo embeds: plan alternate screenshot/CDN delivery

Primary: Helpfeel — Gyazo unauthorised access notice (16 Sep 2026) · Vendor: Helpfeel Inc. — Gyazo breach notice · BleepingComputer — Gyazo 23.6M records / service suspended (18 Sep 2026)

breaches cloud identity

Incident
Published 2026-09-16
Verified 2026-09-19

Thorndale Foundation (AU): Qilin leak-site listing (ransomware.live)

Ransomware.live’s Australia country feed lists Thorndale Foundation (www.thorndale.com.au — Western Sydney disability support not-for-profit) under the Qilin brand — published and discovered 16 September 2026 on the feed. The organisation homepage loaded on this pass with no visible cyber-incident notice; no OAIC notice, Webber Insurance list entry, or ACSC advisory was located, so treat the listing as an unconfirmed extortion claim until a primary notice appears. Distinct from reddrop-group-qilin-20260916 (same brand, different victim). Australian disability and community-service providers should verify backups, MFA, and remote-access exposure.

Exploited in Australia?
unknown

Primary: Ransomware.live Australia (Thorndale Foundation / Qilin; discovered 16 Sep 2026) · Vendor: Thorndale Foundation (org site — no incident notice found this pass) · Webber Insurance AU breaches list (no matching notice found this pass)

australia

Incident
Published 2026-09-16
Verified 2026-09-19

Reddrop Group (AU): Qilin leak-site listing (ransomware.live)

Ransomware.live’s Australia country feed lists Reddrop Group (www.reddrop.com.au — NSW supermarket group, ~18 stores) under the Qilin brand — published and discovered 16 September 2026 on the feed. The company homepage loaded on this pass with no visible cyber-incident notice; no OAIC notice, Webber Insurance list entry, or ACSC advisory was located, so treat the listing as an unconfirmed extortion claim until a primary notice appears. Distinct from other AU Qilin listings on this desk. Australian retail operators should verify backups, MFA, and remote-access exposure.

Exploited in Australia?
unknown

Primary: Ransomware.live Australia (Reddrop Group / Qilin; discovered 16 Sep 2026) · Vendor: Reddrop Group (company site — no incident notice found this pass) · Webber Insurance AU breaches list (no matching notice found this pass)

australia

Incident
Published 2026-09-16
Verified 2026-09-19

Leisure Coast Kitchens (AU): Kairos leak-site listing (ransomware.live)

Ransomware.live’s Australia country feed lists Leisure Coast Kitchens (AU retail / bespoke kitchens, laundries and bathrooms) under the Kairos brand — published 16 September 2026, discovered 16 September 2026 on the feed. No company website incident notice, OAIC notice, Webber Insurance list entry, or ACSC advisory was located on this 17 September 2026 10:00 Perth desk pass, so treat the listing as an unconfirmed extortion claim until a primary notice appears. Kairos is tracked as a data-extortion (theft-focused) brand. Distinct from other AU Kairos listings on this desk. Australian retail and trade businesses should verify backups, MFA, and remote-access exposure.

Exploited in Australia?
unknown

Primary: Ransomware.live Australia (Leisure Coast Kitchens / Kairos; discovered 16 Sep 2026) · Webber Insurance AU breaches list (no matching notice found this pass)

australia

Incident
Published 2026-09-16
Verified 2026-09-19

Mandiant: attacker hijacks AI coding-assistant session, spreads Shai-Hulud across ~100 repos

Mandiant AI Risk and Resilience Report 2026 (Google Cloud; wired by The Hacker News 16 September) case study: after compromising a SaaS provider, an attacker hijacked an active AI coding-assistant session on a developer workstation. The assistant recommended a poisoned external package; once accepted, the attacker used the session to install an infostealer via a poisoned PyPI package, harvest GitHub OAuth tokens, and deploy the self-propagating Shai-Hulud worm across about 100 internal repositories (secret theft and programmatic exfiltration). Distinct from earlier Keyv-linked npm worm / Mini Shai-Hulud supply-chain desk notes. Defenders: treat AI assistant tool-install prompts as high-risk; constrain package installs; rotate GitHub tokens; audit recent repo automation. Primary: Mandiant/Google Cloud report.

Product
AI coding assistants; developer workstations; GitHub / PyPI supply chain
Exploited in Australia?
unknown
Patch to
Revoke exposed GitHub OAuth/tokens; remove Shai-Hulud artefacts; constrain AI assistant install capabilities; rebuild from known-good

Primary: Mandiant AI Risk and Resilience Report 2026 (Google Cloud) · Vendor: Google Cloud / Mandiant · The Hacker News — Shai-Hulud AI session (16 Sep 2026)

ai cloud identity

Incident
Published 2026-09-16
Verified 2026-09-19

Premier Medical Group (NY): ~282,075 patients notified after June 2026 file access

Premier Medical Group of the Hudson Valley P.C. published a Notice of Data Security Incident: after disruption of some IT systems, investigation found an unauthorized party accessed certain files on 14 June 2026; on 14 July 2026 PMG determined files may have included patient names, contact information, dates of birth, health insurance information, provider names, internal patient IDs, dates of service, medication information, and treatment/diagnostic information. Law enforcement notified; enhanced safeguards and staff training cited. SecurityWeek (16 September 2026) reports HHS breach portal listing 282,075 individuals and that no ransomware/extortion group claim was seen. How the attack occurred not disclosed. Primary: company notice; wire: SecurityWeek.

Product
Premier Medical Group patient/IT systems (Hudson Valley, NY)
Exploited in Australia?
unknown
Patch to
Patients: review provider/insurer statements for unrecognized services; PMG incident line 888-650-4197 (ET business hours per notice)

Primary: Premier Medical Group — Notice of Data Security Incident · Vendor: Premier Medical Group (company) · SecurityWeek — 280,000 impacted (16 Sep 2026)

breaches healthcare

Incident
Published 2026-09-15
Verified 2026-09-19

GhostCode: eSentire TRU documents M365 device-code phishing kit (MFA bypass in ~78s)

eSentire Threat Response Unit blog (published 15 September 2026; dateCreated 10 Sep) details GhostCode, a novel OAuth 2.0 device-authorization phishing kit that hijacks Microsoft 365 accounts after the victim completes legitimate MFA on Microsoft's real sign-in page. Observed chain: Salesforce contact-form lure as procurement staff, sales follow-up, NDA pretext, then a WeTransfer link to a password-gated HTML attachment with AES-256-GCM ciphertext and triple-layer HTML obfuscation; a Cloudflare Turnstile gate filters scanners before the device-code page. Kit requests a user_code using the Microsoft Authentication Broker application ID, presents a polished fake document portal, and captures tokens once the victim approves the attacker's device. eSentire describes Primary Refresh Token capture and, in one intrusion, nine successful API calls and three device registrations in about 78 seconds, with residential proxies matched to victim geography. Distinct from password-stealing kits; MFA does not stop the flow because the victim authenticates Microsoft directly. Defenders: restrict or block device-code grant where unused, alert on Authentication Broker device registrations, treat unexpected WeTransfer/NDA procurement mail as high-risk, review Entra ID sign-in and device logs. Primary: eSentire TRU; wire: Cyber Security News 16 Sep.

Product
Microsoft 365 / Entra ID — OAuth 2.0 device authorization grant (Authentication Broker client)
Versions
n/a (phishing kit abusing legitimate Microsoft device-code flow; not a Microsoft product CVE)
Exploited in Australia?
unknown
Patch to
Entra ID: disable device-code flow if unused; Conditional Access / risk alerts on Authentication Broker and new device registrations; user awareness on WeTransfer NDA lures; revoke tokens / remove rogue devices on suspicion

Primary: eSentire TRU — GhostCode device-code phishing kit (15 Sep 2026) · Vendor: eSentire — GhostCode analysis · Cyber Security News — GhostCode / M365 MFA bypass wire (16 Sep 2026)

tech identity cloud

Incident
Published 2026-09-15
Verified 2026-09-19

Auto-IT (AU): confirms Storm ransomware hit a small number of customer environments via third-party RMM

Cyber Daily exclusive (15 September 2026) names Australian dealer-management software firm Auto-IT as the third-party IT supplier behind the recent Storm ransomware wave against Australian car dealerships and machinery suppliers. Auto-IT told Cyber Daily a small number of customer environments were affected via unauthorised use of a third-party remote monitoring and management (RMM) tool; customers were named on a dark-web listing site with claims of accessed business data. Company says the incident is contained, customer environments remain secure and fully operational, forensic specialists were engaged, and it is working with the Australian Cyber Security Centre and impacted customers. Cyber Daily links the wave (listings from about 18 August) to dealers including Westco Motors Cairns, Ramsey Bros, Penfold Motors, Sharp Motor Group, Agrimac, and Macquarrie — several of which already have desk cards noting an unnamed third-party supplier. Primary: Cyber Daily with Auto-IT quotes; related desk cards: penfold-motors-storm-20260914, macquarrie-storm-20260903.

Product
Auto-IT dealer management / customer environments (third-party RMM abused)
Exploited in Australia?
yes
Patch to
Auto-IT customers: follow vendor incident guidance; review RMM access, rotate credentials, confirm forensic containment; report via ACSC if impacted

Primary: Cyber Daily — Auto-IT confirms Storm / customer environments (15 Sep 2026) · Webber Insurance AU data-breaches list (Auto-IT / Storm entry)

australia

Incident
Published 2026-09-15
Verified 2026-09-19

Admin Menu Editor Pro: compromised update channel backdoors ~1,500 WordPress sites (versions 2.35/2.36)

Developer Janis Elsts (adminmenueditor.com) reports that on 14 September 2026 an attacker gained access to the plugin's distribution site and pushed malicious Admin Menu Editor Pro updates. Version 2.35 (available ~06:00–13:00 UTC) dropped includes/wp-user-consent.php (web shell) and created a hidden wp_-prefixed user; a same-day clean 2.36 push was also compromised while the attacker retained access. Update-server logs: ~230 customers, malicious build installed on at least 1,500 sites (multiple sites per customer); several hundred more downloads in the window may be affected. Free Admin Menu Editor and 2.34 believed clean. IoCs per developer: includes/wp-user-consent.php under admin-menu-editor-pro; new /wp-content/object-cache/; wp_ users hidden from the dashboard; wp_ocache* options. Remediation: restore from a backup before 14 Sep 2026, or remove the plugin, delete /wp-content/object-cache/, and purge the listed DB artefacts; site sales/updates offline pending rebuild. Primary: developer incident notice; wire: BleepingComputer 15 Sep.

Product
Admin Menu Editor Pro (WordPress premium plugin)
Versions
Malicious 2.35 and compromised 2.36; 2.34 and free edition believed clean
Exploited in Australia?
unknown
Patch to
Do not run 2.35/2.36 from the compromised channel; restore pre-14 Sep backup or remove plugin + object-cache dir + wp_ / wp_ocache* artefacts per developer guidance; wait for rebuilt distribution

Primary: Admin Menu Editor — developer incident notice (site offline; 14 Sep 2026) · Vendor: adminmenueditor.com (maintainer) · BleepingComputer — Admin Menu Editor Pro supply-chain backdoor (15 Sep 2026)

breaches cloud

Incident
Published 2026-09-15
Verified 2026-09-19

CenterPoint Energy (US utility): SEC filing confirms customer personal data stolen via external-facing system

BleepingComputer (15 September 2026) reports Houston-based utility CenterPoint Energy confirmed in an SEC filing that an unauthorized third party obtained personal information for a portion of its customers through an external-facing system. A threat actor alias “4d722e4d656f77” told BleepingComputer they exfiltrated about 7.49 million customer records (names, phones, service/billing addresses, account numbers, billing amounts, partial SSNs) by iterating IDs on a public API alleged to lack rate limiting/WAF. CenterPoint says electric and gas services were not impacted and does not expect a material business effect; it activated IR, engaged third-party experts, hardened systems, and notified law enforcement/regulators. Class-action complaints filed in US federal courts allege the incident window was about 17 August–1 September 2026. Company has not publicly matched the actor’s record count or data-type claims in the SEC text cited by the wire. Primary wire: BleepingComputer; company confirmation: SEC filing as cited there.

Product
CenterPoint Energy customer-facing / external systems (public API per actor claim)
Exploited in Australia?
unknown
Patch to
Utility customers: monitor for phishing/identity misuse; CenterPoint says services unaffected — follow company notices for affected individuals

Primary: BleepingComputer — CenterPoint Energy confirms customer data stolen (15 Sep 2026) · Vendor: CenterPoint Energy (company site) · SecurityWeek — CenterPoint confirms breach after leak (15 Sep 2026)

breaches ot ics

Incident
Published 2026-09-15
Verified 2026-09-19

US: five alleged Black Axe leaders extradited on cyber-enabled fraud / money-laundering charges

BleepingComputer (15 September 2026) reports five alleged leaders of the Black Axe cybercrime syndicate — Perry Osagiede, Franklyn Osagiede, Osariemen Clement, Collins Otughwor, and Musa Mudashiru — were extradited to the United States to face wire fraud and money-laundering charges. Prosecutors allege a Cape Town–based internet fraud campaign (about 2011–2021) using romance and advance-fee scams, aliases, dating sites, and VoIP numbers to target US victims, including coercion via threats to publish sensitive photos. US Attorney’s Office for the District of New Jersey press release linked from the wire: “Five Prominent Black Axe Members Extradited for Conspiring to Engage in Internet Scams and Money Laundering.” Law-enforcement action / charging story; not a fresh organisational data-breach notice. Primary: DOJ USAO-NJ PR; wire: BleepingComputer.

Exploited in Australia?
unknown

Primary: DOJ USAO-NJ — Black Axe members extradited (linked 15 Sep 2026 wire) · BleepingComputer (15 Sep 2026)

breaches

Incident
Published 2026-09-14
Verified 2026-09-19

Spain AEPD: first notified personal-data breach allegedly run by an AI agent (LLM)

Spain’s Agencia Española de Protección de Datos (AEPD) blog (14 September 2026; Francisco Pérez Bes) reports the agency’s first notification of a personal-data breach in which the incident was allegedly executed by an AI agent using a known large language model. Per the notifier: the agent searched generic files for vulnerabilities, successfully logged in, then autonomously hunted application flaws, modified personal data, and accessed invoices. AEPD stresses the claim is from the organisation’s notification and still requires analysis; use of a given model does not imply the provider’s model or infrastructure was compromised or purpose-built for crime. Framing: shift from AI-assisted attacker tools (phishing copy, vuln search) toward agentic chaining of attack phases at machine speed — with implications for identity/credential controls, detection, and response timing. National Cryptologic Center (CCN) paradigm-shift context noted in wire coverage. Primary: AEPD blog; secondary: BleepingComputer 16 Sep 2026.

Product
AI agent / LLM used as offensive automation (incident notification; not a product CVE)
Versions
n/a
Exploited in Australia?
unknown
Patch to
Operators: treat agentic offence as faster/adaptive; tighten identity, API keys, and least privilege; accelerate detect/contain playbooks beyond manual-attack assumptions (per AEPD framing)

Primary: AEPD — primera notificación brecha por agente de IA (14 Sep 2026) · Vendor: AEPD blog (Spanish DPA) · BleepingComputer — Spain AEPD first AI-powered breach report (16 Sep 2026)

ai identity

Incident
Published 2026-09-14
Verified 2026-09-19

Brevo: stolen Cloudflare API key → edge Worker ClickFix on customer embeds (~5.5h)

Brevo status write-up (and BleepingComputer 17 September 2026) confirms that on 14 September 2026 an attacker used a compromised long-lived Cloudflare API key (hardcoded in Brevo application source; first misuse indicated late August) to deploy a Cloudflare Worker that rewrote responses at the CDN edge for about five and a half hours (approx. 16:07–20:30 UTC). Affected: brevo.com, sendinblue.com, login/account/my/onboarding.brevo.com, sibforms.com, plus Brevo forms script, Conversations widget, and SDK loader that customers embed. The Worker stripped CSP and served a fake Cloudflare “verify you are human” ClickFix lure (Win+R / Ctrl+V / Enter) downloading malware on Windows; on WordPress sites with a logged-in admin, Sansec/Bleeping also report attempted silent install of a malicious “Web Media Optimizer” plugin backdoor. Not affected per Brevo: app.brevo.com, API, email delivery, and customer account data held in Brevo. Remediation: Worker/routes/hostnames removed, key revoked, hardcoded credential removed, Vault + Cloudflare audit alerting planned. Distinct from Brevo’s earlier 9–10 September SSO boundary incident (Trezor phishing wave). Primary: Brevo status write-up; wire: BleepingComputer; Sansec first flagged customer-site impact (up to ~100k sites cited).

Product
Brevo (Sendinblue) marketing platform — Cloudflare CDN / embedded forms, Conversations widget, SDK loader
Versions
n/a (CDN-edge Worker rewrite; origin files unmodified). Customer WordPress sites embedding affected widgets during the window were at risk.
Exploited in Australia?
unknown
Patch to
If you embed Brevo forms/Conversations/SDK: confirm scripts are clean; WordPress admins who visited affected pages during the window should audit plugins (esp. unexpected “Web Media Optimizer” / must-use copies), rotate admin sessions, and scan for backdoors. Prefer integrity checks on third-party embeds; treat ClickFix clipboard lures as malware.

Primary: Brevo status — Cloudflare Worker ClickFix write-up (14 Sep 2026 incident) · Vendor: Brevo (status write-up) · BleepingComputer — Brevo supply-chain ClickFix (17 Sep 2026)

breaches cloud

Incident
Published 2026-09-14
Verified 2026-09-19

Spain AEPD: first notified personal-data breach allegedly executed by an AI agent

Spain's Agencia Española de Protección de Datos (AEPD) blog (14 September 2026; wired by BleepingComputer and SecurityWeek 16 September) says it received the first notification of a personal-data breach in which the incident was allegedly executed by an AI agent using a known large language model. Per the affected organisation's notification (not yet independently verified by AEPD): the agent searched generic files for flaws, completed a successful login, then autonomously probed the application, modified personal data, and accessed invoices. AEPD stresses the report is from the notifier and must be analysed; use of a named model does not imply the model provider was compromised or that the tool was purpose-built for crime. Relevance for defenders: treat agentic chaining (goal → tools → adapt) as a qualitative speed/scale shift for risk analysis, credential/API hygiene, and detection/containment timing — not only for Spanish controllers. Primary: AEPD blog; wires: BleepingComputer, SecurityWeek.

Product
AI agent / LLM-orchestrated attack path against an unspecified controller (notification stage)
Exploited in Australia?
unknown
Patch to
Review IR playbooks for agent-speed chaining; harden credentials/API keys/tokens; shorten detection and containment loops; do not treat AEPD's notice as verified attribution until the agency completes analysis

Primary: AEPD — first notified breach allegedly via AI agent (14 Sep 2026) · Vendor: AEPD (Spanish Data Protection Agency) · BleepingComputer — Spain AEPD AI-agent breach notice (16 Sep 2026)

ai identity

Incident
Published 2026-09-14
Verified 2026-09-19

Alchin Long Group (AU): The Gentlemen leak-site listing (ransomware.live)

Ransomware.live’s Australia country feed lists Sydney-based hardware conglomerate Alchin Long Group (alchinlong.com; Doric/Cowdroy/Colonial Castings and related brands) under the The Gentlemen brand — published 14 September 2026, discovered 15 September 2026 on the feed. No company statement, OAIC notice, Webber Insurance list entry, or ACSC advisory was located on this 16 September 2026 desk pass, so treat the listing as an unconfirmed extortion claim until a primary notice appears. Distinct from desk card sharp-office-thegentlemen-20260907 (same brand, different victim). Australian manufacturers and hardware suppliers should verify backups, MFA, and remote-access exposure.

Exploited in Australia?
unknown

Primary: Ransomware.live Australia (Alchin Long Group / The Gentlemen; discovered 15 Sep 2026) · Vendor: Alchin Long Group (company site — no incident notice found this pass) · Webber Insurance AU breaches list (no matching notice found this pass)

australia

Incident
Published 2026-09-14
Verified 2026-09-19

Penfold Motors (Vic): Storm ransomware via third-party software; customers notified

Cyber Daily (14 September 2026) reports Victorian dealership Penfold Motors (Peter Warren Automotive Group; six Vic sites) is contacting customers after Storm ransomware operators listed the firm (listing dated 17 August; early leak post mis-attributed a similarly named UK organisation before correction). Company statement dated 7 September: contained incident involving an external software provider that stored some Penfold data; systems restored and dealerships operating; investigation with the provider and forensic specialists ongoing. Impact described as basic contact details plus vehicle and servicing information (VINs and tax invoices appeared in published samples per Cyber Daily); Penfold said there was no evidence identity documents or bank-account data were involved, and that it notified the Australian Cyber Security Centre and the Office of the Australian Information Commissioner. Cyber Daily also notes Sharp Motor Group and Macquarrie as other recent Australian automotive/machinery victims tied to third-party supplier incidents in the same Storm wave (Macquarrie desk card updated separately). UPDATE 15 Sep 2026: Cyber Daily names Auto-IT as that third-party software firm (see auto-it-storm-20260915). Primary: Cyber Daily exclusive with company quotes.

Exploited in Australia?
yes

Primary: Cyber Daily — Penfold Motors / Storm (14 Sep 2026) · Webber Insurance AU data-breaches list (September 2026 entry)

breaches australia

Incident
Published 2026-09-14
Verified 2026-09-19

HBO Max Reddit account hijacked for 108 ClickFix ads (PasteSwitch stealers)

BleepingComputer (14 September 2026) reports that the verified Reddit account u/hbomax was hijacked and used to run about 108 malicious advertisements over roughly 48 hours. Ads used ClickFix social engineering (victims paste commands into Windows Run/PowerShell or macOS Terminal) and redirected to lookalike sites (including hbomaxx[.]us). Hudson Rock and ADAMnetworks link the activity to a broader campaign they call PasteSwitch delivering information stealers, loaders, crypto clippers, and fake wallets on Windows and macOS; one macOS chain referenced “AMOS helper” persistence under a .com.apple.accountsd-style directory. Some ads impersonated HBO Max; others pushed fake AI/developer/macOS utilities. BleepingComputer said HBO / Warner Bros. Discovery had not responded at publication. Distinct from prior desk ClickFix/EtherHiding cards. Primary/wire: BleepingComputer.

Product
n/a (Reddit advertising / social engineering; Windows and macOS endpoints)
Versions
n/a
Exploited in Australia?
unknown
Patch to
Treat unexpected Run/Terminal paste prompts as hostile; verify streaming-app installs from official stores; revoke sessions if you interacted with u/hbomax ads in the window

Primary: BleepingComputer — HBO Max Reddit ClickFix (14 Sep 2026)

breaches identity

Incident
Published 2026-09-14
Verified 2026-09-19

3BB (Thailand ISP): Hunt.io finds MeshCentral backdoor, RADIUS targeting

Hunt.io (14 September 2026; The Hacker News same day) describes an intrusion against 3BB, a major Thai broadband provider. Researchers captured an attacker-operated server still live on 3 June 2026 that held tooling run from inside 3BB’s network, a MeshCentral deployment reporting to www.ayuthayatech[.]com under device group TH-3BB (agents with root), cleanup scripts that preserved MeshCentral, SSH password spraying against 55+ internal hosts, probes of agent.3bb.co[.]th, and scripts aimed at copying RADIUS subscriber credential databases (targeted; Hunt.io does not state confirmed exfiltration). The same cache held a complete exploit for FortiGate SSL-VPN CVE-2024-21762 aimed at mail.3bb.co[.]th and a valid 3BB VPN certificate plus Jasmine-network sessions (shared infrastructure; Jasmine breach not confirmed). Primary: Hunt.io; secondary: THN.

Product
3BB broadband network (FortiGate SSL-VPN; MeshCentral; RADIUS)
Versions
FortiGate firmware affected by CVE-2024-21762 reported on targeted gateway; MeshCentral abused as living-off-the-land C2
Exploited in Australia?
unknown
Patch to
ISPs/enterprises: patch FortiGate SSL-VPN (CVE-2024-21762 class); hunt unauthorized MeshCentral/RMM; rotate RADIUS and VPN credentials if similar tooling seen

Primary: Hunt.io — 3BB FortiGate / MeshCentral intrusion (14 Sep 2026) · CVE: CVE-2024-21762 · The Hacker News (14 Sep 2026)

breaches network identity

Incident
Published 2026-09-14
Verified 2026-09-19

Telus warns customers of multi-month account breaches via stolen credentials

SecurityWeek (14 September 2026) reports Telus is notifying some Canadian consumer telecom customers that attackers accessed their accounts between February 2025 and June 2026 using compromised credentials. Accessed data included names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details, and payment history. Telus says the stolen account information was used to push customers toward competitors and, in some cases, to make unauthorised service changes. Impacted credentials were reset and enhanced monitoring applied; Vancouver Police were notified and complimentary identity-theft protection offered. Headcount and exact credential source were not published; the description is consistent with credential stuffing or other account takeover using third-party credentials, which Telus has not explicitly confirmed. Distinct from the March Telus Digital / ShinyHunters incident. Primary/wire: SecurityWeek pending a public Telus notice URL.

Product
Telus consumer telecom accounts (Canada)
Versions
n/a (credential-based account takeover; not a product CVE)
Exploited in Australia?
unknown
Patch to
n/a for other operators: force password resets on suspected ATO, monitor SIM/port and plan-change abuse, offer identity monitoring where appropriate

Primary: SecurityWeek — Telus account breaches (14 Sep 2026)

breaches identity