Ransomware.live’s Australia country feed lists pacificabs.com (Pacific Global Solutions / PABS / Atteign LLC; professional-services activity tag) under the Settra brand — feed published date 28 August 2026, discovered on the tracker 17 September 2026 (API id cGFjaWZpY2Ficy5jb21Ac2V0dHJh). Claim text references documents and a prologue mentioning 40+ American businesses; treat as an unconfirmed extortion claim. No company website incident notice, OAIC notice, Webber Insurance list entry, or ACSC advisory was located on this 18 September 2026 04:00 Perth desk pass. Distinct from prior AU Settra desk card verve-portraits-settra-20260903. Australian operators should verify backups, MFA, and remote-access exposure until a primary notice appears.
JetBrains' Cadence incident post (opened 28 August 2026, last updated 1 September 2026 12:05 CEST) confirms unauthorized access to Cadence, a JetBrains-hosted cloud-compute service for PyCharm via an optional plugin that orchestrates work with TeamCity. The Cadence host api.cadence.jetbrains.com was vulnerable to CVE-2026-63077 (desk card cve-2026-63077) and was exploited; activity from 8 August to 24 August 2026; discovered 23 August; server taken offline 24 August. Confirmed: personal data extracted (usernames, real names, emails, last-login times, last IPs); a full 2024 Cadence server backup compromised (treat credentials/config/artifacts in that backup as exposed); multiple AWS IAM users/secrets used with Cadence compromised from that backup; files in JetBrains Cadence S3 buckets accessed; possible access to source synchronized from PyCharm. JetBrains says no evidence secrets were taken from the live environment beyond the backup path, invalidated Cadence plugin access tokens, and lists IoC IPs (150.109.230.104, 43.153.227.206, 62.210.127.48, 210.247.242.190, 15.235.225.205, 152.233.30.18). Users must rotate all credentials used in Cadence executions and treat inputs/outputs as untrusted. Distinct from the On-Premises TeamCity ACSC exploitation card: this is JetBrains' own hosted Cadence service.
Socket (28 August 2026) reports that ten versions of npm package @7nohe/openapi-react-query-codegen were published that day after a comment-triggered GitHub Actions trusted-publishing workflow was abused. An untrusted GitHub account could comment a publish trigger on a pull request and ship fork code under the repository OIDC identity. Versions named by Socket and Step Security are 0.5.4, 0.5.5, 1.6.3, 1.6.4, 2.2.1, 2.2.2, 3.0.3, 3.0.4, plus two 0.0.0-sha prerelease tags. Stable releases ran obfuscated JavaScript 3FWCvzduYZg.js via binding.gyp and/or a preinstall hook. Socket describes Mini Shai-Hulud-consistent self-propagation. Install-time code targeted cloud credentials, package-registry credentials, GitHub Actions secrets and AI-agent configuration. All ten carried valid npm provenance. Pin known-good 0.5.3, 1.6.2, 2.2.0 or 3.0.2, isolate affected hosts, then rotate tokens. This desk does not attribute the package to TeamPCP; Socket and Step Security do not name that group.
JFrog's 28 August 2026 advisory rates CVE-2026-82329 Critical (CVSS 3.1 9.8): under default configuration, an unauthenticated attacker with network access may obtain administrative privileges on self-managed Artifactory. watchTowr told SecurityWeek (1 Sep) and BleepingComputer / The Hacker News (2 Sep) it has seen exploitation — attackers minting admin tokens, enumerating users/groups/federated topologies, and in limited cases creating backdoor users — from a small set of IPs without evidence of mass scanning yet. watchTowr describes a 'phantom' join key on instances without an additional join key configured, abused via JFrog Access to forge administrator credentials. Self-hosted patches: 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20; JFrog says cloud was already fortified. Access tokens are independent credentials — upgrading the binary does not by itself revoke minted tokens, so rotate/revoke tokens and hunt anomalous admin activity after patching. CISA added CVE-2026-82329 to the KEV catalog on 2 September 2026. UPDATE 10–11 September 2026 (Wiz / THN): Wiz also saw CVE-2026-82329 abused in the wild alongside a separate 42018→42016 chain (15 Aug–8 Sep) that yields admin and drops Rust C2 / Groovy plugins — see desk cards cve-2026-42018 and cve-2026-42016. Distinct from cve-2026-66384.
JFrog security advisories (CVE-2026-82329, 28 Aug 2026)
Confiant (28 August 2026; figures as of 25 August) tracks HexMage, a Magecart cluster that injects a fake Google Tag Manager block into compromised storefronts (mostly WooCommerce), loads ethers.js, and reads a Sepolia testnet contract to obtain a disposable skimmer host (EtherHiding). Confiant observed 40+ impacted sites across at least 15 countries since about April 2026; 25 storefronts mapped, including Australian site protocoffee[.]com[.]au (a blockchain-free loader variant pointing at stylerightnoww[.]com). One owner wallet (0x88361C914Bb0942da9a1b7Bb396a7513C1917aee) had deployed 144 contracts by 21 July 2026. The skimmer overlays the payment form, harvests PAN/expiry/CVV, then restores the DOM so the purchase completes. Fake-GTM detection: the injected block never fetches googletagmanager[.]com/gtm.js. Cyber Security News carried the story on 31 August. Defanged names only on this desk — not live links.
Microsoft Threat Intelligence (Security blog dated 28 August 2026; JSON-LD published 29 August) describes TerminalFix, a ClickFix variant that uses compromised websites and a fake Cloudflare CAPTCHA overlay to trick users into pasting a PowerShell command in Windows Terminal or PowerShell rather than the Run dialog. The command downloads a ZIP with a legitimate LockScreenContentServer.exe binary and a malicious dui70.dll for DLL sideloading. Later stages pull payloads hidden in PNG images, persist via Registry Run keys and scheduled tasks, run Active Directory reconnaissance, and deploy a Python reverse-tunnel implant that proxies TCP over an encrypted WebSocket. Microsoft says it did not observe the later hands-on-keyboard steps (privilege escalation, defence tampering, ransomware) in the analysed chain, but treats affected hosts as potential network pivot points. Distinct from the older ClickFix/Vidar WordPress campaign already on this desk. Primary: Microsoft. Secondary: The Hacker News 30 August.
SecurityWeek (28 August 2026) reports the US Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a cybersecurity incident after the Qilin ransomware group listed the agency. ATF's statement, as quoted there, says the intrusion hit a standalone system that was disconnected once discovered, that the system sits apart from the ATF enterprise network, and that there is no indication the enterprise network, eForms, or any other ATF system was affected or that ATF cannot perform its missions. An investigation is underway with the Justice Department; senior DOJ officials designated the event a major incident under federal guidelines and required notifications were completed. Qilin added ATF to its leak site on 26 August; SecurityWeek says the post made no specific claims, showed no stolen-document screenshots, and did not set a leak timer. Actor claims are not treated as verified facts on this desk. ATF's press-release URL returned 403 from this pass; facts are from SecurityWeek quoting the statement.
Hasbro's Massachusetts consumer letter (OCABR 2026-1427, posted in the August 2026 breach-letter list) says a data security incident may have involved employee personal information after a compromised employee account. Hasbro says it disabled that account, terminated unauthorised access, and added safeguards. The letter says involved information varied and may have included name plus one or more of email, address, phone number, national ID number, or financial information. BleepingComputer, citing the Massachusetts 2026 Data Breach Notification Report, says 436 Massachusetts employees had Social Security numbers, financial-account information, credit/debit card numbers, or driver's-licence information involved. Hasbro has not published a nationwide total. Hasbro did not link this notice to its March 2026 incident. No customer impact is stated in the letter.
Patchstack (28 August 2026) and CVE-2026-82222 describe an unauthenticated PHP object injection chain in GiveWP through 4.16.7.1 that reaches remote code execution. On 4.16.5.1 and below a default install with one published donation form and an active gateway is enough. On 4.16.6–4.16.7.1 reachability narrows but a legacy give_forms post without formBuilderSettings (including draft/trashed) re-arms the chain. The plugin's give_action=user_register path ignores WordPress users_can_register, so an attacker can obtain an account even when registration is disabled. Patchstack rates CVSS 10.0. Vendor fixed in GiveWP 4.16.7.2 (27 August 2026), which breaks the chain at several layers and migrates serialized object payloads already in the database. Patch to 4.16.7.2 or later.
Cyber Daily's 28 August 2026 report quotes a Sharp Motor Group spokesperson confirming the Tweed Heads, NSW dealership is aware that its third-party IT provider has been involved in a cyber incident. The company said it is working with independent cyber specialists and relevant authorities, has notified the OAIC, and that staff and customer privacy remain the priority. Cyber Daily reports the Storm ransomware group listed Sharp Motor Group in a 23 August leak-site post and published sample files it claims were taken (including identity documents and financial material); those actor claims and any data-volume figures are not independently confirmed in the company statement and are not treated as verified facts on this desk. Storm has also listed other Australian automotive and machinery firms this month; company responses for those other listings were not confirmed in the same report.
Cyber Daily (28 Aug 2026; quotes Sharp Motor Group)
McKesson's 28 August 2026 customer notice and Form 8-K say it discovered a cybersecurity incident on 25 August 2026 affecting its information systems. The company says the investigation is in early stages and involves third-party applications plus unauthorised access and exfiltration of data. Updates are posted at mckesson.com/cybersecurity. A 29 August 2026 customer note on that page (heading: McKesson Cybersecurity Incident Investigation and Response Update) says McKesson continues to serve customers across all lines of business and accept orders, distribution centres remain operational, and shipping continues. That note does not add scope, named applications, or confirmation of actor claims. As of the 8-K filing date, McKesson had not determined the incident to be material or reasonably likely to have a material impact on financial condition or results of operations. The company has not publicly named the applications involved, the access path, or what was taken. Secondary reporting attributes claims by the ShinyHunters extortion group (including a large patient-record count and Okta/Salesforce/Snowflake access via vishing); those actor claims are not confirmed in McKesson's notice or 8-K and are not treated as verified facts on this desk.
cPanel's 27 August 2026 advisory: an authenticated account that can add parked or addon domains can create arbitrary files on the server. Successful exploitation is code execution as root, which is the whole host, not one site. All supported cPanel/WHM versions are affected. Patched builds: 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and WP Squared 11.138.1.7. The vendor page does not publish a CVSS score and does not say it is exploited. This is not the April login bypass (CVE-2026-41940), which is already on the desk.