Latest cyber news, threats, security, and guidelines. Stack up.

Vulnerabilities

Thu 16 Jul

Microsoft SharePoint (CVE-2026-58644)

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability. Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.

NVD

vulnerabilities

Vulnerabilities

Wed 15 Jul

F5 BIG-IP HTTP/2 TMM memory exhaustion (CVE-2026-59762)

F5 CNA advisory K000162231 (NVD published 15 July 2026) says that when an HTTP/2 profile is configured on a virtual server, undisclosed requests can raise TMM memory until the process restarts. That is a data-plane denial of service; F5 says there is no control-plane exposure. F5 scores it 8.7 (CVSS 4.0) and 7.5 (CVSS 3.1). Affected classic BIG-IP: 21.1.0 before 21.1.0.1, 21.0.0 before 21.0.0.3, 17.5.0 before 17.5.1.8, 17.1.0 before 17.1.3.4. Also BIG-IP Next for Kubernetes 2.3 before 2.3.2 and 2.0 before 2.2.3, Next CNF 2.3 before 2.3.2 / 2.0 before 2.2.3 / 1.1 before 1.4.3, and Next SPK 1.7 before 1.7.18 (NVD also lists Next SPK 1.9.0 as affected with no upper bound). Not in CISA KEV at last check. The NVD record does not state in-the-wild exploitation.

F5 K000162231

vulnerabilities network

Vulnerabilities

Tue 14 Jul

Sangoma Switchvox unauthenticated SQLi to RCE exploited (CVE-2026-9586); CISA KEV

Horizon3 published on 1 September 2026 that Defused Cyber honeypots saw valid in-the-wild exploitation of CVE-2026-9586 on 30 August 2026 (attacker IP 176.65.148.184 in the published honeypot traffic). The flaw is an unauthenticated SQL injection in Sangoma Switchvox SMB Edition: the /pa PhoneAppsHandler.pm endpoint concatenates the PhoneIP field from an XML body into a PostgreSQL query, which Horizon3 says can be turned into remote code execution as the database superuser. Sangoma released Switchvox 8.4.0.2 on 14 July 2026. Horizon3 reported the issues in April; Security Risk Advisors independently reported them in May and published on 17 July. GitHub CVE advisory (17 July) rates it Critical 9.3. The CNA record cites Switchvox SMB Edition 8.3 (build 104997); Horizon3 notes Sangoma 8.4.0.2 release notes also mention 8.2.2.1 — upgrade to 8.4.0.2 rather than assuming an older build is safe. Horizon3 cites about 4,000 internet-exposed Switchvox devices on Shodan, mostly in the United States. CISA added CVE-2026-9586 to the KEV catalog on 2 September 2026. Restrict /pa to trusted phone networks until patched. IoC path if SSH is available: /var/log/switchvox/db-quirks.log.

Sangoma Switchvox 8.4.0.2 release notes (14 Jul 2026)

vulnerabilities network

AI

Thu 9 Jul

OpenAI GPT-5.6 family: Sol, Terra, and Luna

OpenAI launched GPT-5.6 for general availability on 9 July 2026: Sol (flagship), Terra (balanced), and Luna (cost-efficient), across ChatGPT, Codex, and the API. The company describes layered safeguards for biology and cybersecurity, with extra defensive capability behind a verified Trusted Access programme. A 21 August 2026 update on the same page cut GPT-5.6 Sol API and credit pricing by over 20 percent for three months.

OpenAI

ai llm model

Vulnerabilities

Wed 8 Jul

Juniper SRX/MX flowd crash from malformed TCP (CVE-2026-57023)

Juniper's 8 July 2026 security bulletin (JSA110083): an improper validation issue in the TCP proxy plugin of Junos OS on SRX Series and MX Series with SPC3 lets an unauthenticated, network-based attacker cause a complete denial of service. When TCP proxy is in use (ALGs, Advanced Anti-Malware, ICAP or UTM), a TCP packet with a specifically malformed header crashes flowd, causing a full service outage until the process restarts. CVSS 3.1 is 7.5; CVSS 4.0 is 8.7. Affected: 23.4 before 23.4R2-S7, 24.2 before 24.2R2-S4, 24.4 before 24.4R2-S3, 25.2 before 25.2R2. Not before 23.4R1. Juniper SIRT says it is not aware of malicious exploitation; the issue was seen during production usage. No workaround. This was part of Juniper's 8 July 2026 bulletin round (Canadian Centre for Cyber Security AV26-675).

Juniper JSA110083 (CVE-2026-57023)

vulnerabilities network

Incidents

Mon 8 Jun

UWA Callista student system: credentials exposed, unauthorised access on 28 May

The University of Western Australia's own notice says that on 28 May 2026, UWA IT identified unauthorised external access to Callista, the university's Student Information Management System, after system access credentials were unintentionally exposed online. UWA says it secured the system and removed the vulnerability. Exposed fields, on that notice, include name, UWA student ID, UWA staff ID if applicable, home and mobile numbers, date of birth (day and month only), personal email, postcode, and enrolment status as at 2 April 2026, for some prospective students, current students and recent graduates. UWA says financial details were not involved, that it found no evidence of malicious use, and that it emailed affected people on 8 June 2026. UWA password resets were not required. ASD's ACSC had not published a matching alert at last check.

UWA Callista notice

breaches australia

Incidents

Thu 7 May

Instructure Canvas: Free-For-Teacher path, ShinyHunters claim, AU campuses offline

Instructure detected unauthorised activity in Canvas on 29 April 2026 and a second access on 7 May 2026 that changed pages some students and teachers saw after login. The vendor says both used a Free-For-Teacher account path, took Canvas into maintenance, remediated the privilege-escalation routes, and permanently discontinued Free-For-Teacher. Fields named on the vendor FAQ include usernames, email addresses, course names, enrolment information, and messages; Instructure says core learning data (course content, submissions, credentials) was not compromised, and the US Education Department FSA alert (12 May, updated 29 May) repeats that there is no evidence passwords, dates of birth, government identifiers, or financial information were exposed. ShinyHunters claimed the campaign; Instructure later said it reached an agreement with the unauthorised actor, that data was returned with shred logs, and that customers should not engage the actor. SMH (13 May) put the haul at roughly 3.65 TB across 8809 institutions worldwide, including at least 122 in Australia; Trend Micro separately counted 122 Australian institutions among 8809. Patch posture for customers: rotate Canvas integrations, LTI tools, SSO connectors, and API keys; review logs for 25 April–8 May 2026.

Instructure Security Incident Update & FAQs

australia cloud identity

Advisories

Thu 7 May

ClickFix via compromised WordPress sites distributing Vidar Stealer

ASD's ACSC has observed ClickFix social-engineering activity using compromised WordPress sites to distribute Vidar Stealer against Australian infrastructure. Treat unexpected 'paste this command' prompts as hostile. This is social engineering, not an AI-stack flaw.

ASD's ACSC advisory

australia social engineering

Vulnerabilities

Fri 1 May

cPanel/WHM authentication bypass, exploited in Australia

ASD's ACSC is aware of active exploitation in Australia of a critical authentication-bypass in cPanel/WHM that can lead to control-panel access and remote code execution. The vendor and the ACSC advisory body identify the issue as CVE-2026-41940 (ACSC listing text also used CVE-2026-4194). Affects versions after 11.40. Vendor patches were published from 28 April 2026; ACSC noted patches as of 30 April 2026.

ASD's ACSC advisory

vulnerabilities australia

Advisories

Fri 1 May

Five Eyes guidance: careful adoption of agentic AI

On 1 May 2026 ASD's ACSC, with CISA, NSA, and the other Five Eyes cyber centres, published guidance on LLM-based agentic AI. The agencies say agents that plan and act are a different risk than a chatbot. Adopt incrementally, keep them on low-risk tasks, enforce least privilege, and require a human for high-impact actions. Treat this inside existing cyber programmes, not as a side hobby.

ASD's ACSC guidance

ai llm agentic australia

Vulnerabilities

Fri 27 Mar

Langflow path traversal to arbitrary file write and RCE (CVE-2026-5027)

Tenable's advisory says Langflow's POST /api/v2/files endpoint does not sanitise multipart filenames, allowing a logged-in attacker to use path traversal to write files outside the upload directory. The CNA rates it 8.8 (CVSS 3.1). Exploit-DB published a working exploit on 31 August for Langflow 1.8.4 and earlier that uses the default auto-login path, writes a cron file and reaches remote code execution; active-exploitation reporting also appeared on the wire. Upgrade to Langflow 1.9.0 or later. Disabling auto-login and restricting network access reduce exposure but do not fix the underlying arbitrary file write.

Tenable Research TRA-2026-26

tech ai

Advisories

Sun 1 Mar

Exploitation of Cisco SD-WAN appliances (joint advisory)

ASD's ACSC, with Five Eyes partners, published mitigations for ongoing exploitation of Cisco SD-WAN, including CVE-2026-20127, CVE-2026-20128 and CVE-2026-20122. Patch, hunt, and follow Cisco's hardening guidance.

ASD's ACSC advisory

vulnerabilities australia network