Latest cyber news, threats, security, and guidelines. Stack up.

Vulnerabilities

Tue 25 Aug

Gitea CVE-2026-60004: Red Heron campaign compromises 13 orgs (Acronis TRU)

Gitea GHSA-rcr6-4jqh-j84m / CVE-2026-60004 (28 July 2026 advisory; CISA KEV 25 August 2026): diffpatch API can let a user with repository write access (including self-registered users on open instances) run commands as the Gitea service account. Affected 1.17 through versions before 1.27.1; patch to 1.27.1+. UPDATE 14 September 2026: The Hacker News cites Acronis Threat Research Unit attributing a China-linked cluster (moderate confidence) tracked as Red Heron that weaponised CVE-2026-60004 from ~29 July 2026, scanning 1,386 Gitea instances across seven countries (plus a 477-instance Taiwan dataset) and confirming compromises at 13 organisations in Canada (2), Argentina (1), Taiwan (4), the US (4), Qatar (1), and Sri Lanka (1). Campaign progressed from repository theft to credentials, persistence, and lateral movement (including root on a three-node Proxmox cluster). Tooling includes C++ Linux implant JITTERLY (30+ commands; overlaps AdaptixC2) and LD_PRELOAD rootkit SIXZUT. Primary remains Gitea advisory; secondary: THN / Acronis TRU reporting. Distinct from generic KEV listing alone.

Gitea advisory GHSA-rcr6-4jqh-j84m / CVE-2026-60004

vulnerabilities source control

Vulnerabilities

Mon 24 Aug

TeamCity On-Premises unauthenticated RCE (CVE-2026-63077), exploited in Australia

Unauthenticated remote code execution in JetBrains TeamCity On-Premises via the agent polling protocol. ASD's ACSC observed active exploitation against On-Premises servers in Australia. All On-Premises versions are affected. TeamCity Cloud is not. Patch to 2025.11.7 or 2026.1.3, or apply the vendor security patch plugin if you cannot upgrade.

ASD's ACSC advisory

vulnerabilities australia

Vulnerabilities

Mon 24 Aug

Zscaler Client Connector unauthenticated RCE (CVE-2026-59568)

Zscaler's 24 August 2026 CVE record describes multiple Client Connector flaws that allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context. Zscaler scored it 9.1 (CVSS 3.1). The CNA points administrators to the 2026 Client Connector app release summary for fixed builds. Affected version strings in that record include Windows before 4.6.0.457 / 4.7.0.317 / 4.8.0.232 / 4.9.0.372, macOS before 4.5.2.312 / 4.7.0.292 / 4.8.0.191, Linux before 3.7.2.64 / 4.2.1.64, Android and ChromeOS before 4.2, and iOS before 4.5.1. Confirm the exact build from the vendor release summary before declaring a fleet patched. Zscaler's release summary also lists CVE-2026-59564 (auth bypass to the portal), CVE-2026-59567 (local privilege escalation) and CVE-2026-59565 (local/kernel denial of service). Not in CISA KEV at last check.

CVE-2026-59568 (Zscaler CNA)

vulnerabilities network cloud

Vulnerabilities

Mon 24 Aug

Oracle HTTP Server / WebLogic proxy plug-in access control (CVE-2026-21962)

Oracle Critical Patch Update (January 2026) lists CVE-2026-21962 in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS. Supported affected versions: 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. NVD rates CVSS 10.0. Unauthenticated network access via HTTP. Apply the January 2026 CPU for the plug-in builds you run.

Oracle CPU January 2026

vulnerabilities

Incidents

Fri 21 Aug

Origin Energy: unauthorised access affecting about 900,000 customers

Origin Energy confirmed unauthorised access to personal information of approximately 900,000 current and former customers in July 2026. Categories include name, address, date of birth, contact phone, account details, and partial payment data (last four digits of a credit card or last three of a bank account). On 21 August 2026 Origin said a completed review found about 60 customers had full bank account numbers accessed, about 100 had an ID document number accessed (number only, no scans), and about 15,000 had government concession-scheme numbers accessed. Origin told ABC the alleged attacker had not publicly leaked customer data. The company is working with ASD's ACSC, the National Office of Cyber Security, AFP and OAIC; a criminal investigation continues. Earlier reporting linked the incident to a former Accenture Manila call-centre worker; Accenture declined to comment to ABC.

ABC News (quotes Origin 21 Aug update)

breaches australia

Vulnerabilities

Fri 21 Aug

Zimbra Collaboration Suite SNMP command injection (CVE-2026-73570)

Unauthenticated OS command injection in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. NVD: crafted SMTP requests can run commands as the zimbra user. CERT Polska reported active exploitation. Patch to 10.1.20. If you cannot upgrade, remove zimbra-snmp / disable snmp_notify and hunt per CERT Polska.

Zimbra Security Advisories

vulnerabilities email

Incidents

Thu 20 Aug

Oz Hair and Beauty: unauthorised access to the online order platform

Oz Hair and Beauty's official statement says its online purchase and order platform was briefly accessed by an unauthorised third party. Limited personal information of some customers who purchased before August 2026 was involved: full name, email and/or mobile, and purchase data (currency, total spend, purchase location, customer creation date). The company says credit cards, passwords, payment information and invoice details were not accessed. It reported the incident to ACSC, OAIC and New Zealand's Office of the Privacy Commissioner. Customers not emailed by 22 August 2026 were, on that statement, not identified as impacted on the investigation to date. The company has not published a count of affected records.

Oz Hair and Beauty statement

breaches australia

Vulnerabilities

Thu 20 Aug

TrueConf Server missing authentication on port 4307 (CVE-2026-72529)

Kaspersky ICS CERT (KLCERT-26-057): an unauthenticated attacker with network access to TrueConf Server on TCP 4307 can call an undocumented function and run an arbitrary script. Affects 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and earlier than 5.3. NVD CVSS 9.8. Related CVE-2026-72530 is a code-injection issue in the same product line. Patch to the fixed builds and do not expose 4307 to the internet.

Kaspersky ICS CERT KLCERT-26-057

vulnerabilities

Vulnerabilities

Wed 19 Aug

NetScaler ADC/Gateway CVE-2026-19490 on CISA KEV (due 2026-09-12); exploited since 3 Sep

Cloud Software Group bulletin CTX696939 (19 August 2026, Critical) covers an authentication bypass using an alternate path in customer-managed NetScaler ADC and NetScaler Gateway. CVSS v4.0 9.3. It applies when the appliance is a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server; on some later 14.1/13.1 builds only when a SAML action is also configured. Not Citrix-managed cloud. No workaround. Patch to 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS, or 13.1-37.277 FIPS/NDcPP, as applicable. Secure Private Access Hybrid using customer-managed NetScaler also needs those builds. BleepingComputer (4 September 2026) reports Previdian honeypot sensors saw requests matching a public PoC on 3 September from three source IPs geolocated to Australia, the United States and Germany — evidence of exploitation attempts, not confirmed successful compromise of production systems. The Centre for Cybersecurity Belgium also warned of exploitation attempts the same week. Citrix’s August bulletin had not yet flagged active exploitation. WA SOC advisory 20260907003 (7 September 2026, TLP:CLEAR) covers CVE-2026-19490 at CVSS 9.3 for the same build floors, and reports no exploitation on Western Australian Government networks at the time of writing. Distinct from CVE-2026-8452 on this desk. NEW 9–10 September 2026: CISA added CVE-2026-19490 to the Known Exploited Vulnerabilities catalog on 9 September 2026 (due 12 September 2026 for FCEB under BOD 26-04, including forensic triage requirements). SecurityWeek (10 September) summarises ongoing exploitation since at least 3 September after a public PoC, matching earlier Previdian sensor notes. Patch floors unchanged: 14.1-73.32 / 13.1-63.21 and FIPS mates.

Citrix CTX696939

vulnerabilities network australia

Vulnerabilities

Wed 19 Aug

NetScaler ADC/Gateway memory overflow (CVE-2026-19489)

Same CTX696939 bulletin: memory overflow that can cause unpredictable behaviour or denial of service when SIP ALG is enabled on a Large Scale NAT (LSN) group. CVSS v4.0 8.8. Customer-managed NetScaler ADC and Gateway only. No workaround. Same patched builds as CVE-2026-19490: 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS, or 13.1-37.277 FIPS/NDcPP. Distinct from the earlier CVE-2026-8452 memory-overflow card.

Citrix CTX696939

vulnerabilities network

Incidents

Wed 19 Aug

Quest Apartment Hotels: unauthorised access via a third-party provider

Quest identified unauthorised access on 17 August 2026 to a database through a vulnerability at a third-party service provider. Its statement says the incident is contained. Records involved are from before June 2025 and primarily names, email addresses and/or other contact details, with a small number of dates of birth. The company statement does not list payment card data and does not publish a count of affected records. Quest said it notified the OAIC and ACSC. Magazine reporting that put the figure around 1.5 million is secondary and unconfirmed by Quest.

Quest official statement

breaches supply chain australia

Vulnerabilities

Wed 19 Aug

N-able N-central authentication bypass, exploited in Australia

CVE-2026-18556 and CVE-2026-18577 are authentication-bypass issues in N-able N-central that may allow unauthorised access through an alternate path. ASD's ACSC has observed targeting of the product in Australia. Affects current versions including 2026.3. Vendor Hotfix 2 (build 2026.3.1.10, 6 August 2026) supersedes Hotfix 1. Review whether the console needs to face the internet.

ASD's ACSC advisory

vulnerabilities australia