Latest cyber news, threats, security, and guidelines. Stack up.

Incidents

Tue 1 Sep

Datadog: password-spraying against AWS root console at 150+ organisations

Datadog Security Research describes a password-spraying campaign against AWS root-user console logins at more than 150 organisations between 24 July and 23 August 2026. The median number of failed attempts per organisation was two; some saw as many as eight. The AWS root console requires the account email, so the campaign implies the operators had (or guessed) those addresses. This desk records failed attempts as reported; no successful authentications are stated in the Datadog write-up as loaded. Coverage on 1 September 2026 (Cyber Security News) likewise says researchers did not identify successful authentications. Organisations should review CloudTrail for unusual root ConsoleLogin failures and keep root use exceptional.

Datadog Security Labs

tech cloud identity ai

Vulnerabilities

Mon 31 Aug

GeoNetwork: unauthenticated RCE chain (CVE-2026-63219 + CVE-2026-58400) on government geoportals

GeoNetwork (OSGeo geospatial metadata catalog used behind many government and agency geoportals, including European INSPIRE backends) published advisories on 31 August 2026 for two flaws that chain to unauthenticated remote code execution. CVE-2026-63219 (CVSS 8.6 per The Hacker News citing the project) is a missing authorisation check on the formatter upload endpoint that lets an anonymous attacker write arbitrary .xsl or .zip formatter files. CVE-2026-58400 (CVSS 9.1 per the same reporting) is an unsafe Saxon XSLT configuration in the formatter engine that can call Runtime.exec / ProcessBuilder as the GeoNetwork process user once a malicious stylesheet is loaded. Fixes shipped earlier in 4.4.12 and 4.2.17 (8 July 2026); all 4.4.x through 4.4.11 and 4.2.x through 4.2.16 are affected. Vendor/project mitigations until patch: block write methods to /geonetwork/srv/api/formatters at the reverse proxy. Ethiack (Rafael Castilho) reported the chain and said it fingerprinted 121 internet-exposed affected instances across 39 countries, about 89% government/military/agency-related (exposure estimate, not confirmed compromises). The Hacker News (2 September) found no CISA KEV entry and no public in-wild exploitation reporting at disclosure. Primary advisories: GitHub GHSA-mh22-prqr-vf42 and GHSA-x898-729x-cc3r.

GeoNetwork GHSA-mh22 (upload)

vulnerabilities network australia

Incidents

Mon 31 Aug

Socket: 13 malicious Packagist themes push iOS WebKit-to-kernel spyware and wallet theft

Socket's 31 August 2026 research describes 13 malicious Composer theme packages on Packagist across five vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms) that inject JavaScript into Vietnamese movie and comic streaming sites. On mobile visitors the code runs gambling and ad-fraud redirects; on unpatched iPhones it loads a FUNNULL-hosted WebKit-to-kernel exploit chain. Socket says the renderer stages weaponise CVE-2025-31277 and CVE-2025-43529 (both on CISA KEV), then escape to the kernel; Apple told Socket the kernel escape was already fixed in iOS and macOS 26.1. A 12 August 2026 redeployment added keychain theft of crypto-wallet seeds and mnemonics for Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet and OKX, targeting iOS 18.4 through 18.6.x. Site operators should remove themes from those namespaces, rotate credentials, and audit shipped scripts; keep iPhones current past the listed builds.

Socket (31 Aug 2026)

tech supply chain

Incidents

Mon 31 Aug

Huntress: phishing abuses Faronics Deploy to chain ScreenConnect remote access

Huntress published on 31 August 2026 that phishing actors abused the legitimate Faronics Deploy endpoint-management platform between 21 July and 20 August 2026, with more than 457 endpoints encountering Faronics-themed lures (invoices, tax documents and similar). Victims were steered to download a signed Faronics Deploy installer disguised as an Adobe document or plugin; once enrolled in an attacker-controlled deployment, operators used Faronics remote script execution (PowerShell via curl, mshta or msiexec) to install ConnectWise ScreenConnect as a second remote-access channel. Huntress notified Faronics on 5 August 2026; Huntress says Faronics added anti-abuse controls and contacted affected organisations, and observed activity drop sharply from 21 August. Defenders should inspect C:\ProgramData\Faronics\Logs\ScriptRunner.log and unexpected ScreenConnect installs, and report suspected abuse to support@faronics.com.

Huntress (31 Aug 2026)

breaches identity

Incidents

Mon 31 Aug

METR: two 2026 security incidents; no sensitive eval data believed accessed

METR's 31 August 2026 security update describes two incidents in which external actors tried to gain unauthorised access. It believes no sensitive information was accessed in either case, and it is not attributing the events; the post is about human attackers, not AI agents breaking evaluations. In March 2026 a researcher with no sensitive-access privileges ran a vibe-coded app on a personal public EC2 instance behind Google authentication that held an API key for METR's public-models account; a fail-open bug silently disabled auth. METR assesses the attacker found the host via recently registered sites or certificate-transparency lists, prompted an agent for the key, added an SSH key, and burned credits for about three weeks. Accrued usage would have been worth about US$600,000 if the unnamed model provider had not given the credits free. In May 2026 attackers probed public infrastructure (credential stuffing, OAuth grants, phishing staff). METR had inadvertently exposed a read-only SQL mechanism on a public transcript viewer that could have reached unpublished eval data, including some sensitive model output that should not have been in that database; attackers probed the endpoint but METR says there is no evidence they found the issue or accessed non-public data. Distinct from desk cards anthropic-eval-containment-20260831 and anthropic-claude-infostealer-20260830.

METR security update (31 Aug 2026)

ai cloud

Incidents

Mon 31 Aug

Aesto Health: 9.54 million people on HHS portal after Dec 2025 AWS infrastructure incident

Aesto Health (Birmingham, Alabama), which provides healthcare data migration and archiving for covered-entity clients, posted a June 2026 notice: it discovered a network security incident on or about 18 December 2025 affecting a limited portion of its Amazon Web Services infrastructure. On 26 May 2026 the investigation determined that PII and PHI belonging to patients of various clients may have been accessed or acquired between about 2 and 18 December 2025, including names, dates of birth, medical information, driver's licence numbers, financial account numbers, health insurance information, taxpayer identification numbers, other government IDs, and Social Security numbers (elements varied; SSNs for a limited number of people). The US HHS portal lists 9,540,683 individuals; SecurityWeek (1 September) says HHS added the company on Monday 31 August 2026. At least two dozen provider clients across several states were affected. The company says it has no evidence of identity theft or financial fraud tied to the incident. No Australia link is reported.

Aesto Health notice (June 2026)

breaches cloud

Incidents

Mon 31 Aug

Softaculous/Virtualizor: BGP hijack delivered a malicious hypervisor update

Softaculous' Virtualizor incident post (31 August 2026) says IP block 162.55.80.0/24 (Hetzner space used by Softaculous services) was BGP-hijacked from about 20:57 UTC on 28 August to about 06:10 UTC on 30 August. An unauthorised announcement by AS62390 (NexonHost), transited via AS6204 (Zet.net), was more specific than Hetzner's 162.55.0.0/16 and diverted traffic, including the software-update endpoint and client-area/billing site. The attacker obtained a technically valid Let's Encrypt certificate for Virtualizor, Softaculous and related names, so diverted connections showed no certificate warning. The vendor confirmed a malicious Virtualizor update package reached a small number of installations that checked for updates during diversion; it cannot list every affected host. Known indicator: systemd unit /etc/systemd/system/java-jre-update.service. Routing has been restored. Operators should hunt that unit (and not only delete it), rotate Virtualizor API keys, and audit SSH keys, accounts and cron. The vendor shipped Virtualizor 3.2.9.9 with a mitigation tool and says package signing is coming. Other Softaculous products had no identified malicious package at the time of the post. Clients who logged into the billing site during the window should reset that password.

Virtualizor incident post (31 Aug 2026)

tech cloud

Incidents

Mon 31 Aug

Berlin confirms data theft and extortion after state-network cyberattack

Berlin's official 31 August update says the city is facing extortion after the mid-August cyberattack on its administrative network and will not pay. Forensic work confirmed data left the Senate Department for Mobility, Transport, Climate Protection and the Environment between 7 and 12 August; the scope is still being assessed and personal or other non-public data may be involved. Berlin says the affected departments were disconnected on 14 August and investigations by state police, prosecutors and federal security authorities continue. BleepingComputer reports that the Rhysida ransomware group claimed the attack and a much larger theft, but Berlin's notice does not attribute the incident or confirm the actor's volume and content claims.

Berlin.de official update (31 Aug 2026)

breaches

Advisories

Mon 31 Aug

Gryxa: AI-built Windows toolkit watches defender cleanup and fights back

ReliaQuest Threat Research describes Gryxa, a financially motivated Windows toolkit ReliaQuest assesses was substantially built with a commercial AI coding agent (AI co-author metadata on most commits in the actor's public repo). Delivery is likely an invoice-themed 19 MB SFX (invoice_<10 digits>.exe). After the visible RMM implant is removed, a surviving component collects Windows logs and host artefacts and uploads them so the operator sees the remediation. If the actor's relay is unreachable for two consecutive five-minute checks, Gryxa disables Defender and listed EDR; at three failures it attempts a silent uninstall. ReliaQuest's analysis of the actor console listed 324 hosts (69 reporting online at the time of writing); not every listed host is a confirmed victim. Credential theft targets Chromium saved logins (including App-Bound Encryption bypass paths in code) and flags wallet extensions. IoCs (defanged): wirbe[.]com, seczio[.]com, gryxa[.]com, sevrz[.]com and related hosts in ReliaQuest's table. Cyber Security News 31 August. Do not invent CVSS.

ReliaQuest (Gryxa threat spotlight)

ai identity

Vulnerabilities

Mon 31 Aug

Microsoft UFO Mobile MCP unauthenticated Android control (CVE-2026-73296)

Cyber Security News (31 August 2026) reports CVE-2026-73296 in Microsoft's open-source UFO automation framework: Mobile Model Context Protocol servers (data collection on TCP 8020, action on TCP 8021) accepted MCP requests without authentication when bound for remote access (0.0.0.0). Default bind is localhost. An exposed action server can tap, swipe, type, launch apps and drive a connected Android device or emulator over ADB; the data server can return screenshots and UI hierarchy. CSN cites GitHub advisory GHSA-24fq-m9rr-g3mm (CWE-306 / CWE-862) and a CVSS of 9.4; that GitHub advisory URL returned 404 this pass, so the score is not confirmed from GitHub and is not copied into the CVSS field. Microsoft's fix is UFO 3.0.8, which adds mandatory bearer-token auth via UFO_MCP_API_KEY and is described as refusing startup if the key is missing. Until patched, keep Mobile MCP on localhost and block 8020/8021. Wire source until the GHSA page is readable.

Cyber Security News (31 Aug 2026)

vulnerabilities ai

Advisories

Sun 30 Aug

Fire Ant: China-nexus actor hijacks Cisco IOS XR, TACACS (TacTap) and Linux management hosts

Sygnia's 30 August 2026 report (The Hacker News 31 August) says Fire Ant, first reported in 2025 and assessed to overlap UNC3886, remained active into 2026 and expanded from hypervisors into trusted infrastructure: Cisco IOS XR routers, TACACS authentication, and Linux management hosts. Router implants (including a masqueraded grub-rommon service launching /usr/bin/acpid) suppressed selected syslog, hid CLI output, and supported GRE tunnels. On the tunnel far-end, BridgeAgent persisted as zabbix_agent.service (filename zabbix_agent, not the legitimate zabbix_agentd) — a Zabbix-name masquerade, not a Zabbix product CVE. TacTap injects /lib/libseconfd.so into tac_plus to steal credentials to /var/log/.tacplus.acct (XOR 0xEF). Sygnia also describes Medusa-related Linux access, custom SSH backdoors, and REPTILE-like packet-triggered implants. Treat routers, TACACS and jump hosts as first-class forensic assets. Primary: Sygnia.

Sygnia (30 Aug 2026)

tech network

Advisories

Sun 30 Aug

Anthropic: infostealers hijacking Claude sessions to drain usage

On 30 August 2026 BleepingComputer reported Anthropic emails to affected Claude users: infostealer malware on already-compromised PCs stole active Claude login sessions, then used those sessions to access accounts and consume usage (including usage that appeared to refill then drain). Anthropic is signing affected users out, removing saved payment methods, and refunding charges it identifies as unauthorised. Anthropic says it has no reason to believe the malware was installed through Claude. It has identified Vidar, LummaC2, StealC, RedLine and Acreed on Windows, and Atomic Stealer (AMOS) on a small number of Macs. Signing out stops the stolen session; it does not remove the malware. No CVSS. No public Anthropic advisory page at the time of writing; desk source is BleepingComputer quoting the company email.

BleepingComputer (30 Aug 2026)

ai identity