Latest cyber news, threats, security, and guidelines. Stack up.

Incidents

Fri 28 Aug

Pacific ABS / pacificabs.com (AU): Settra leak-site listing (ransomware.live)

Ransomware.live’s Australia country feed lists pacificabs.com (Pacific Global Solutions / PABS / Atteign LLC; professional-services activity tag) under the Settra brand — feed published date 28 August 2026, discovered on the tracker 17 September 2026 (API id cGFjaWZpY2Ficy5jb21Ac2V0dHJh). Claim text references documents and a prologue mentioning 40+ American businesses; treat as an unconfirmed extortion claim. No company website incident notice, OAIC notice, Webber Insurance list entry, or ACSC advisory was located on this 18 September 2026 04:00 Perth desk pass. Distinct from prior AU Settra desk card verve-portraits-settra-20260903. Australian operators should verify backups, MFA, and remote-access exposure until a primary notice appears.

Ransomware.live — pacificabs.com / Settra (discovered 17 Sep 2026)

australia

Incidents

Fri 28 Aug

JetBrains Cadence: TeamCity CVE-2026-63077 missed; customer data and secrets exposed

JetBrains' Cadence incident post (opened 28 August 2026, last updated 1 September 2026 12:05 CEST) confirms unauthorized access to Cadence, a JetBrains-hosted cloud-compute service for PyCharm via an optional plugin that orchestrates work with TeamCity. The Cadence host api.cadence.jetbrains.com was vulnerable to CVE-2026-63077 (desk card cve-2026-63077) and was exploited; activity from 8 August to 24 August 2026; discovered 23 August; server taken offline 24 August. Confirmed: personal data extracted (usernames, real names, emails, last-login times, last IPs); a full 2024 Cadence server backup compromised (treat credentials/config/artifacts in that backup as exposed); multiple AWS IAM users/secrets used with Cadence compromised from that backup; files in JetBrains Cadence S3 buckets accessed; possible access to source synchronized from PyCharm. JetBrains says no evidence secrets were taken from the live environment beyond the backup path, invalidated Cadence plugin access tokens, and lists IoC IPs (150.109.230.104, 43.153.227.206, 62.210.127.48, 210.247.242.190, 15.235.225.205, 152.233.30.18). Users must rotate all credentials used in Cadence executions and treat inputs/outputs as untrusted. Distinct from the On-Premises TeamCity ACSC exploitation card: this is JetBrains' own hosted Cadence service.

JetBrains Cadence incident post

tech cloud identity

Incidents

Fri 28 Aug

@7nohe/openapi-react-query-codegen: ten published versions after an abused GitHub Actions publishing workflow

Socket (28 August 2026) reports that ten versions of npm package @7nohe/openapi-react-query-codegen were published that day after a comment-triggered GitHub Actions trusted-publishing workflow was abused. An untrusted GitHub account could comment a publish trigger on a pull request and ship fork code under the repository OIDC identity. Versions named by Socket and Step Security are 0.5.4, 0.5.5, 1.6.3, 1.6.4, 2.2.1, 2.2.2, 3.0.3, 3.0.4, plus two 0.0.0-sha prerelease tags. Stable releases ran obfuscated JavaScript 3FWCvzduYZg.js via binding.gyp and/or a preinstall hook. Socket describes Mini Shai-Hulud-consistent self-propagation. Install-time code targeted cloud credentials, package-registry credentials, GitHub Actions secrets and AI-agent configuration. All ten carried valid npm provenance. Pin known-good 0.5.3, 1.6.2, 2.2.0 or 3.0.2, isolate affected hosts, then rotate tokens. This desk does not attribute the package to TeamPCP; Socket and Step Security do not name that group.

Socket (28 Aug 2026)

tech cloud identity

Vulnerabilities

Fri 28 Aug

JFrog Artifactory CVE-2026-82329: critical auth bypass; admin-token minting; CISA KEV

JFrog's 28 August 2026 advisory rates CVE-2026-82329 Critical (CVSS 3.1 9.8): under default configuration, an unauthenticated attacker with network access may obtain administrative privileges on self-managed Artifactory. watchTowr told SecurityWeek (1 Sep) and BleepingComputer / The Hacker News (2 Sep) it has seen exploitation — attackers minting admin tokens, enumerating users/groups/federated topologies, and in limited cases creating backdoor users — from a small set of IPs without evidence of mass scanning yet. watchTowr describes a 'phantom' join key on instances without an additional join key configured, abused via JFrog Access to forge administrator credentials. Self-hosted patches: 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20; JFrog says cloud was already fortified. Access tokens are independent credentials — upgrading the binary does not by itself revoke minted tokens, so rotate/revoke tokens and hunt anomalous admin activity after patching. CISA added CVE-2026-82329 to the KEV catalog on 2 September 2026. UPDATE 10–11 September 2026 (Wiz / THN): Wiz also saw CVE-2026-82329 abused in the wild alongside a separate 42018→42016 chain (15 Aug–8 Sep) that yields admin and drops Rust C2 / Groovy plugins — see desk cards cve-2026-42018 and cve-2026-42016. Distinct from cve-2026-66384.

JFrog security advisories (CVE-2026-82329, 28 Aug 2026)

vulnerabilities cloud

Advisories

Fri 28 Aug

HexMage Magecart: EtherHiding on Ethereum Sepolia to skim e-commerce checkouts

Confiant (28 August 2026; figures as of 25 August) tracks HexMage, a Magecart cluster that injects a fake Google Tag Manager block into compromised storefronts (mostly WooCommerce), loads ethers.js, and reads a Sepolia testnet contract to obtain a disposable skimmer host (EtherHiding). Confiant observed 40+ impacted sites across at least 15 countries since about April 2026; 25 storefronts mapped, including Australian site protocoffee[.]com[.]au (a blockchain-free loader variant pointing at stylerightnoww[.]com). One owner wallet (0x88361C914Bb0942da9a1b7Bb396a7513C1917aee) had deployed 144 contracts by 21 July 2026. The skimmer overlays the payment form, harvests PAN/expiry/CVV, then restores the DOM so the purchase completes. Fake-GTM detection: the injected block never fetches googletagmanager[.]com/gtm.js. Cyber Security News carried the story on 31 August. Defanged names only on this desk — not live links.

Confiant (28 Aug 2026)

tech australia

Advisories

Fri 28 Aug

TerminalFix: fake Cloudflare CAPTCHA pushes a reverse-tunnel via Windows Terminal

Microsoft Threat Intelligence (Security blog dated 28 August 2026; JSON-LD published 29 August) describes TerminalFix, a ClickFix variant that uses compromised websites and a fake Cloudflare CAPTCHA overlay to trick users into pasting a PowerShell command in Windows Terminal or PowerShell rather than the Run dialog. The command downloads a ZIP with a legitimate LockScreenContentServer.exe binary and a malicious dui70.dll for DLL sideloading. Later stages pull payloads hidden in PNG images, persist via Registry Run keys and scheduled tasks, run Active Directory reconnaissance, and deploy a Python reverse-tunnel implant that proxies TCP over an encrypted WebSocket. Microsoft says it did not observe the later hands-on-keyboard steps (privilege escalation, defence tampering, ransomware) in the analysed chain, but treats affected hosts as potential network pivot points. Distinct from the older ClickFix/Vidar WordPress campaign already on this desk. Primary: Microsoft. Secondary: The Hacker News 30 August.

Microsoft Security Blog (28 Aug 2026)

tech identity network

Incidents

Fri 28 Aug

ATF confirms cyber incident on a standalone system after Qilin listing

SecurityWeek (28 August 2026) reports the US Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a cybersecurity incident after the Qilin ransomware group listed the agency. ATF's statement, as quoted there, says the intrusion hit a standalone system that was disconnected once discovered, that the system sits apart from the ATF enterprise network, and that there is no indication the enterprise network, eForms, or any other ATF system was affected or that ATF cannot perform its missions. An investigation is underway with the Justice Department; senior DOJ officials designated the event a major incident under federal guidelines and required notifications were completed. Qilin added ATF to its leak site on 26 August; SecurityWeek says the post made no specific claims, showed no stolen-document screenshots, and did not set a leak timer. Actor claims are not treated as verified facts on this desk. ATF's press-release URL returned 403 from this pass; facts are from SecurityWeek quoting the statement.

SecurityWeek (28 Aug 2026; quotes ATF)

breaches

Incidents

Fri 28 Aug

Hasbro: employee personal and financial information accessed

Hasbro's Massachusetts consumer letter (OCABR 2026-1427, posted in the August 2026 breach-letter list) says a data security incident may have involved employee personal information after a compromised employee account. Hasbro says it disabled that account, terminated unauthorised access, and added safeguards. The letter says involved information varied and may have included name plus one or more of email, address, phone number, national ID number, or financial information. BleepingComputer, citing the Massachusetts 2026 Data Breach Notification Report, says 436 Massachusetts employees had Social Security numbers, financial-account information, credit/debit card numbers, or driver's-licence information involved. Hasbro has not published a nationwide total. Hasbro did not link this notice to its March 2026 incident. No customer impact is stated in the letter.

Hasbro MA consumer letter (2026-1427)

breaches identity

Vulnerabilities

Fri 28 Aug

GiveWP WordPress donation plugin unauthenticated RCE (CVE-2026-82222)

Patchstack (28 August 2026) and CVE-2026-82222 describe an unauthenticated PHP object injection chain in GiveWP through 4.16.7.1 that reaches remote code execution. On 4.16.5.1 and below a default install with one published donation form and an active gateway is enough. On 4.16.6–4.16.7.1 reachability narrows but a legacy give_forms post without formBuilderSettings (including draft/trashed) re-arms the chain. The plugin's give_action=user_register path ignores WordPress users_can_register, so an attacker can obtain an account even when registration is disabled. Patchstack rates CVSS 10.0. Vendor fixed in GiveWP 4.16.7.2 (27 August 2026), which breaks the chain at several layers and migrates serialized object payloads already in the database. Patch to 4.16.7.2 or later.

Patchstack advisory

vulnerabilities cloud

Incidents

Fri 28 Aug

Sharp Motor Group (Tweed Heads): third-party IT provider cyber incident; OAIC notified

Cyber Daily's 28 August 2026 report quotes a Sharp Motor Group spokesperson confirming the Tweed Heads, NSW dealership is aware that its third-party IT provider has been involved in a cyber incident. The company said it is working with independent cyber specialists and relevant authorities, has notified the OAIC, and that staff and customer privacy remain the priority. Cyber Daily reports the Storm ransomware group listed Sharp Motor Group in a 23 August leak-site post and published sample files it claims were taken (including identity documents and financial material); those actor claims and any data-volume figures are not independently confirmed in the company statement and are not treated as verified facts on this desk. Storm has also listed other Australian automotive and machinery firms this month; company responses for those other listings were not confirmed in the same report.

Cyber Daily (28 Aug 2026; quotes Sharp Motor Group)

australia retail

Incidents

Fri 28 Aug

McKesson: cybersecurity incident with third-party apps and data exfiltration

McKesson's 28 August 2026 customer notice and Form 8-K say it discovered a cybersecurity incident on 25 August 2026 affecting its information systems. The company says the investigation is in early stages and involves third-party applications plus unauthorised access and exfiltration of data. Updates are posted at mckesson.com/cybersecurity. A 29 August 2026 customer note on that page (heading: McKesson Cybersecurity Incident Investigation and Response Update) says McKesson continues to serve customers across all lines of business and accept orders, distribution centres remain operational, and shipping continues. That note does not add scope, named applications, or confirmation of actor claims. As of the 8-K filing date, McKesson had not determined the incident to be material or reasonably likely to have a material impact on financial condition or results of operations. The company has not publicly named the applications involved, the access path, or what was taken. Secondary reporting attributes claims by the ShinyHunters extortion group (including a large patient-record count and Okta/Salesforce/Snowflake access via vishing); those actor claims are not confirmed in McKesson's notice or 8-K and are not treated as verified facts on this desk.

McKesson cybersecurity notice

breaches healthcare

Vulnerabilities

Thu 27 Aug

cPanel/WHM domain parking: authenticated file create to root (CVE-2026-65643)

cPanel's 27 August 2026 advisory: an authenticated account that can add parked or addon domains can create arbitrary files on the server. Successful exploitation is code execution as root, which is the whole host, not one site. All supported cPanel/WHM versions are affected. Patched builds: 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and WP Squared 11.138.1.7. The vendor page does not publish a CVSS score and does not say it is exploited. This is not the April login bypass (CVE-2026-41940), which is already on the desk.

cPanel advisory (27 Aug 2026)

vulnerabilities cloud