Week in review

AUSCERT Week in Review for 7th Aug 2026

Greetings, A major new software supply chain attack has highlighted the growing risks facing organisations that rely on open source code. Researchers have uncovered a self-propagating malware campaign, dubbed ChainDrop, which has compromised more than 1,300 packages in the Node Package Manager (npm) ecosystem, affecting packages that collectively receive around two billion downloads each month. The attack reportedly began when a threat actor gained access to the GitHub account of the maintainer behind several widely used caching libraries, including Keyv and Cacheable. From there, the malware spread through interconnected projects, ultimately impacting packages associated with a range of technology vendors and organisations. What makes ChainDrop particularly concerning is its ability to spread automatically. Malicious code was inserted into legitimate software packages and published through trusted GitHub Actions workflows, allowing the compromised releases to appear authentic. Once an affected package was installed, a hidden pre-installation script executed automatically, downloading additional components and launching an information-stealing payload. According to security researchers, the malware is designed to collect a wide range of sensitive information, including GitHub and npm access tokens, cloud credentials, Kubernetes secrets, database credentials, and keys for services such as AWS, Azure and Google Cloud. The stolen data is then encrypted and exfiltrated, while the malware searches for new opportunities to compromise additional repositories and packages. Security experts warn that any developer workstation or CI/CD environment that installed an affected package should be considered compromised. Recommended response measures include rebuilding impacted systems, rotating exposed credentials, reviewing repositories for unauthorised changes, and strengthening dependency management controls. As investigations continue, the number of affected packages may grow, reinforcing the importance of ongoing vigilance across the software supply chain. Attackers Exploit N-able Patch Bypass Flaw on RMM Servers Date: 2026-08-04 Author: Dark Reading N-able recently disclosed that a threat actor targeted its N-central product through a patch bypass vulnerability and used the flaw to gain access to customer environments. The company, which sells security and IT management tools to managed service providers (MSPs) and internal IT teams, disclosed active exploitation over the weekend. Rails patches critical Active Storage flaw with RCE potential Date: 2026-08-01 Author: Bleeping Computer [See AUSCERT bulletin https://portal.auscert.org.au/bulletins/ASB-2026.0171.2] A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). Rails is a popular open-source web application framework written in Ruby for building websites and web apps. It uses the built-in Rails component Active Storage for handling file uploads and attachments. Rails maintainers published an advisory about the CVE-2026-66066 flaw, which received a critical severity rating. Massive ChainDrop npm supply-chain attack infects hundreds of packages Date: 2026-08-04 Author: Bleeping Computer [See AUSCERT bulletin https://portal.auscert.org.au/bulletins/ASB-2026.0172] Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. Infected packages include very popular ones such as Keyv and Cacheable, flat-cache and file-entry-cache, all caching utilities from the same maintainer. The supply-chain attack started after the threat actor compromised the GitHub account of Keyv’s maintainer, and quickly spread to packages associated with major organizations such as Deliveroo, Ornikar, OneReach, Picsart, Qlik, and ServiceTitan. Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction Date: 2026-08-01 Author: The Hacker News [See AUSCERT bulletin https://portal.auscert.org.au/bulletins/ESB-2026.8857] Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in arbitrary code execution in the context of the current user without requiring any user interaction. The update also resolves another high-severity flaw (CVE-2026-48448, CVSS score: 8.6) stemming from SQL injection that could pave the way for arbitrary file reads. New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts Date: 2026-08-05 Author: Security Week The new attack methods, named ‘Pass-ta-key’ by Palo Alto Networks, focus on Google-synced passkeys. The security firm’s researchers showed how a threat actor could use the techniques to take over accounts without needing privilege escalation or user interaction. In a Pass-ta-key attack, malware already present on a Windows machine running Chrome can examine the browser’s local synchronization database to identify which online accounts the user has protected with passkeys, along with associated usernames and encrypted credential material. ASB-2026.0171.2 – UPDATE Ruby on Rails (Active Storage): CVSS (Max): 9.5 Ruby on Rails has released security updates to address a critical vulnerability in Active Storage that could allow an attacker to perform arbitrary file reads and potentially achieve remote code execution under vulnerable image processing configurations. ASB-2026.0172 – npm packages: CVSS (Max): None A large-scale npm supply chain attack, dubbed ChainDrop, compromised hundreds of widely used npm packages. ESB-2026.9044 – Adobe Campaign Classic: CVSS (Max): 10.0 This update addresses critical vulnerabilities that could result in arbitrary code execution and arbitrary file system read. ESB-2026.9115 – Cisco Catalyst SD-WAN: CVSS (Max): 9.9 Cisco has released software updates that address these vulnerabilities. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 31st July 2026

Greetings, Organisations using JetBrains TeamCity On-Premises are being urged to patch a newly disclosed critical security vulnerability that could allow attackers to bypass authentication and execute malicious commands on affected servers. The flaw, tracked as CVE-2026-63077, impacts all versions of TeamCity On-Premises and has been rated particularly severely because it enables remote code execution with the privileges of the TeamCity server process. TeamCity Cloud customers are not affected, as mitigations have already been implemented by JetBrains. TeamCity is widely used by development teams to automate software building, testing, and deployment processes. According to JetBrains, successful exploitation of the vulnerability could expose sensitive project data, system configurations, stored credentials, and potentially compromise software build pipelines and release artifacts. These risks make the issue especially significant for organisations that rely on TeamCity as a core component of their software delivery environment. While JetBrains stated there is currently no evidence of active exploitation, the warning carries added weight given TeamCity’s history as a target for cybercriminals, including ransomware operators and state-sponsored threat actors in 2023 and 2024. Past vulnerabilities in the platform have been rapidly exploited in real-world attacks, prompting experts to recommend swift remediation whenever critical flaws are disclosed. JetBrains has already addressed the issue in TeamCity versions 2025.11.7 and 2026.1.3 and strongly recommends upgrading as soon as possible. For customers unable to immediately move to the latest releases, the company has also provided a security patch plugin for supported versions dating back to TeamCity 2017.1. Additional security measures, including restricting access through VPNs and limiting exposure of internet-facing TeamCity services, are also recommended to reduce the risk of compromise. Critical VM Escape Vulnerability Patched in VMware ESXi Date: 2026-07-29 Author: Security Week [AUSCERT has informed the affected members via Critical MSINs] [AUSCERT has published security bulletin for this – https://portal.auscert.org.au/bulletins/ESB-2026.8797/] Broadcom published a new security advisory on Wednesday, informing VMware product users that patches are available for several vulnerabilities affecting ESXi, vCenter, Workstation, and Fusion. Three of the vulnerabilities have been assigned a ‘critical’ severity rating. One of them is CVE-2026-47876, an out-of-bounds write issue in ESXi’s VMXNET3 virtual network adapter. An attacker with local admin privileges on a VM with this adapter can exploit it to execute arbitrary code on the host. CVE-2026-47876 has been described by VMware as a VM escape. Cisco warns of FMC static credential flaw exploited in zero-day attacks Date: 2026-07-29 Author: Bleeping Computer [AUSCERT has published security bulletin for this – https://portal.auscert.org.au/bulletins/ESB-2026.8812/] Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. The vulnerability is caused by static credentials for a low-privilege account built into Cisco Secure FMC Software. Cisco says an unauthenticated, remote attacker can use these credentials to log in to an affected system and access sensitive data available to the account. Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Date: 2026-07-25 Author: The Hacker News Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update. Any authenticated user who can push to a project can run it. The attacker commits a crafted Jupyter notebook and opens its commit diff, which leaks a heap pointer. Enough of those and an automated probe can locate the libraries in memory. Two more notebooks then fire the payload. No administrator rights, no CI or runner access, no victim interaction, no access to anyone else's project. US, Australia Release OT Isolation Guidance for Critical Infrastructure Date: 2026-07-29 Author: Security Week The US cybersecurity agency CISA and Australia’s Cyber Security Centre (ACSC) have published joint guidance detailing how critical infrastructure (CI) organizations can isolate vital OT and supporting systems. Aimed at boosting cyber resilience, the CI Fortify – Advice for isolating vital systems guidance also includes details on how these systems can be operated in isolation for long periods, to ensure the continuity of critical services in case of disruption or crisis. The document is designed to help OT owners, operators, and cybersecurity teams improve their preparedness, response, and recovery. Origin Energy boss confirms almost a million Australians compromised by data breach Date: 2026-07-28 Author: Cyber Daily Aussie energy supplier Origin has said it has completed its initial investigations into a cyber security incident first disclosed on 22 July. “We have now completed the initial phase of our review into Origin’s customer data security incident,” Origin CEO Frank Calabria said in a 28 July statement. “At this point in time, we believe the information of approximately 900,000 current and former customers was accessed.” ESB-2026.8651 – macOS Sequoia 15.7.8: CVSS (Max): 9.1* Apple has released security updates for macOS Sequoia 15.7.8 to address multiple security vulnerabilities. Users are advised to install the update to help protect their systems. ESB-2026.8797 – VMware Products: CVSS (Max): 7.8 Broadcom has released security updates for VMware Aria Operations to address a high-severity local privilege escalation vulnerability. ESB-2026.8812 – Cisco Secure FMC Software: CVSS (Max): 5.3 Cisco has released a security update for Secure Firewall Management Center (FMC) to address a critical static credential vulnerability that has been exploited in zero-day attacks. ESB-2026.8839 – GitLab Community & Enterprise Edition: CVSS (Max): 8.5 GitLab has released GitLab 19.2.1 patch updates for Community and Enterprise Editions to address security vulnerabilities and bug fixes. ESB-2026.8857 – Adobe Campaign Classic: CVSS (Max): 10.0 Adobe has published security updates for Adobe Campaign addressing multiple vulnerabilities. Users are advised to apply the available updates to mitigate potential security risks. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 24th July 2026

Greetings, Origin Energy has confirmed that unauthorised access to customer information has occurred, marking what is believed to be the largest publicly known cyber incident to affect an Australian energy retailer. The company, which serves more than 4.8 million customers, announced it is still investigating the extent of the breach and determining how many may have been impacted. According to Origin, the compromised information may include customers’ names, addresses, dates of birth, phone numbers, and limited banking information such as the last four digits of a credit card or the last three digits of a bank account. The company has stressed that full banking and credit card details do not appear to have been exposed. Chief Executive Frank Calabria apologised to customers, acknowledging the trust placed in the company and assuring customers that securing systems and preventing further unauthorised access remains a top priority. Origin says it will contact affected customers directly once it has confirmed who was impacted. The breach came to light after a media outlet was contacted by an alleged hacker who provided a sample of customer records. Following notification of the incident, Origin alerted authorities and informed the Australian Securities Exchange. The incident adds to a growing list of major Australian cyber security breaches in recent years, following attacks on organisations including Optus, Medibank, and Qantas. Cyber security experts are urging Origin customers to remain vigilant for suspicious emails, text messages and phone calls, as criminals often leverage stolen personal information in follow-up scams. While some customers have recently experienced delays receiving energy bills, Origin says those issues are linked to July pricing changes and are not connected to the data breach investigation. Critical ServiceNow code execution flaw now exploited in attacks Date: 2026-07-20 Author: Bleeping Computer Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. Formerly known as the Now Platform, ServiceNow AI Platform is an enterprise-grade Platform-as-a-Service (PaaS) that helps businesses integrate AI into core enterprise workflows. Cybersecurity company Searchlight Cyber, which found this critical vulnerability and reported it on April 1st, says that it allows unauthenticated threat actors to escape the sandbox and execute code remotely within the ServiceNow platform in high-complexity attacks. WordPress Core "wp2shell" RCE flaws get public exploits, patch now Date: 2026-07-18 Author: Bleeping Computer [See AUSCERT Bulletin https://portal.auscert.org.au/bulletins/ESB-2026.8154] Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. The wp2shell attack consists of two flaws, tracked as CVE-2026-63030 and CVE-2026-60137, that can be chained together to achieve pre-authentication remote code execution against WordPress installs running versions 6.9.x and 7.0.x. The flaws were discovered by Adam Kues of Searchlight Cyber, which says an unauthenticated attacker can exploit them against a default WordPress installation. Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC Date: 2026-07-21 Author: The Hacker News A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network. Microsoft credited DEVCORE researcher "splitline" with discovering and reporting the flaw. Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Date: 2026-07-22 Author: Security Week [AUSCERT has published security bulletins for these Oracle updates] Oracle has patched more than 1,400 vulnerabilities with its July 2026 Critical Patch Update (CPU), with a vast majority of the flaws likely identified by artificial intelligence. According to Oracle, the latest quarterly CPU includes 1,449 security patches, addressing 1,434 unique CVEs across 334 products. CISA orders urgent action on actively exploited Langflow RCE flaw Date: 2026-07-22 Author: Bleeping Computer The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. Tracked as CVE-2026-0770, this critical security flaw allows unauthenticated threat actors to gain remote code execution as root in low-complexity attacks. ESB-2026.8410 – Mozilla Thunderbird: CVSS (Max): 10.0* A large number of vulnerabilities was patched in Mozilla Thunderbird, with the most severe being tracked as CVE-2026-16367 for a sandbox escape due to invalid pointer in the Disability Access APIs component. ESB-2026.8355 – Tenable Security Center: CVSS (Max): 9.9 Tenable Security Center has underlying third party libraries which were found to contain vulnerabilities. Updated versions are now available from the providers, which Tenable has implemented to address potential impacts of these identified vulnerabilities. ESB-2026.8317 – Atlassian Products: CVSS (Max): 10.0 83 high severity vulnerabilities and 18 critical severity third party vulnerabilities have been fixed in new versions of Atlassian products. Some of the patched vulnerabilities include remote code execution, denial of service and improper authorization. ASB-2026.0144 – Oracle Communications: CVSS (Max): 9.8 Oracle has released a critical patch update containing 168 new security patches or Oracle Communications. Many of these vulnerabilities can be remotely exploitable without authentication over a network. It has also been exploited in the CISA KEV. ESB-2026.8151 – roundcube: CVSS (Max): 10.0 Multiple vulnerabilities in roundcube such as account takeover, cross-site scripting, SSRF bypass, information disclosure and denial of service have been fixed in a new version release. Roundcube strongly recommends patching with the latest version. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 17th July 2026

Greetings, The Office of the Australian Information Commissioner (OAIC) has concluded its preliminary inquiries into the 2025 Qantas data breach, determining that there is currently insufficient evidence to warrant a formal regulatory investigation or enforcement action against the airline. The decision follows an almost year-long review of the incident, which affected approximately 5.12 million Australians and was one of the country's most significant privacy breaches in recent years. The breach occurred when a threat actor successfully carried out a phone-based social engineering, or “vishing”, attack against an employee at an overseas third-party contact centre used by Qantas. The attacker convinced the employee they were speaking with legitimate IT support and ultimately gained access to customer information through a customer relationship management platform. Qantas detected unusual activity within days, contained the incident, revoked access to the compromised account and began its incident response process. According to the OAIC, approximately 5.67 million customer records were affected, including names, email addresses, phone numbers and Qantas Frequent Flyer details. Around 1.7 million records also contained additional information such as addresses, dates of birth, and gender. Importantly, the compromised system did not store credit card details, financial information, passwords, PINs or passport details. After examining Qantas’ privacy governance, security controls, staff training, third-party oversight arrangements and incident response processes, the OAIC concluded there was no indication the airline had failed to take reasonable steps to protect personal information or ensure compliance with privacy obligations. The regulator noted that Qantas had implemented security audits, mandatory cyber-awareness training, contractual privacy requirements for service providers and a prompt breach response program. While the OAIC has closed its preliminary inquiries, it emphasised that the decision is not an endorsement of Qantas’ practices and that future investigations remain possible if new information emerges. The report highlights the growing threat of sophisticated social engineering attacks and reinforces the importance of strong cyber security controls, employee awareness training, and rapid incident response capabilities. SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now Date: 2026-07-14 Author: Bleeping Computer [AUSCERT has contacted members about this vulnerability where possible] SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. CVE-2026-15409 is a critical (CVSS 10.0) server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface that allows a remote, unauthenticated attacker to force an appliance to make requests to unintended locations. CVE-2026-15410 is a high-severity (CVSS 7.2) post-authentication code injection flaw in the SMA1000 Appliance Management Console that could allow a remote authenticated administrator to execute arbitrary operating system commands. CISA warns admins to patch actively exploited SharePoint flaws Date: 2026-07-15 Author: Bleeping Computer The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. These security flaws (tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affect all supported self-hosted SharePoint Server versions, including SharePoint Server Subscription Edition (the latest on-premises version, which uses a "continuous update" model). Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting Date: 2026-07-14 Author: ASD ACSC Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory (CSA) builds on FBI’s Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure Public Service Announcement of the decade-plus FSB Center 16 cyber activity by providing additional tactics, techniques, and procedures (TTPs) to enable defenders to more fully understand and counter the threat. SAP warns of critical flaws in NetWeaver and Commerce Cloud Date: 2026-07-14 Author: Bleeping Computer SAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. The first critical issue patched this month is a memory corruption security issue (tracked as CVE-2026-44747) stemming from an out-of-bounds write weakness in the NetWeaver Application Server ABAP (AS ABAP), the runtime environment, application server, and development platform for core SAP enterprise software. "SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability," SAP says. "This has high impact on confidentiality, integrity, and availability of the application." RabbitMQ Vulnerability Threatens Enterprise Systems Date: 2026-07-14 Author: Security Week A vulnerability in RabbitMQ could allow attackers to obtain the broker’s confidential OAuth secret, potentially posing a serious threat to enterprises, according to cybersecurity firm Miggo. RabbitMQ is a popular open source message broker that routes, buffers, and distributes messages, enabling asynchronous communication between applications. Tracked as CVE-2026-5721 (CVSS score of 8.7), the security defect impacts an open management endpoint that returns the OAuth secret to anyone, without authentication. ESB-2026.7869 – VMware Avi Load Balancer: CVSS (Max): 9.8 Broadcom has released updates for VMware Avi Load Balancer to fix seven vulnerabilities, including a critical authentication bypass flaw (CVE-2026-47865). ESB-2026.7892 – Zoom: CVSS (Max): 9.8 Zoom has released updates to address a critical account takeover vulnerability (CVE-2026-53412) affecting Windows-based Zoom products. ESB-2026.7904 – Adobe ColdFusion: CVSS (Max): 9.9 Adobe has released security updates for ColdFusion to address multiple critical vulnerabilities, including arbitrary code execution and server-side request forgery (SSRF). ESB-2026.8009 – Splunk Enterprise: CVSS (Max): 9.8 Splunk has released security updates for Splunk Enterprise to address multiple vulnerabilities affecting Windows and Unix/Linux platforms. ASB-2026.0129 – Microsoft ESU: CVSS (Max): 9.9 Microsoft has released its July 2026 Patch Tuesday update, addressing 335 vulnerabilities across Windows, Exchange Server, and other products, including multiple critical remote code execution and privilege escalation flaws. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 10th July 2026

Greetings, The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) has issued a critical alert following a large-scale cyber campaign targeting vulnerabilities in website content management systems (CMS) across the globe, including Australia. Small and medium-sized businesses have been particularly affected, with attackers actively scanning websites for weaknesses in popular CMS platforms and plugins. According to the ACSC, malicious actors are exploiting known vulnerabilities that enable unauthenticated file uploads, remote code execution and other forms of server compromise. Their primary objective is to deploy webshells, which are malicious scripts that provide remote access and control over web servers. Once installed, webshells can be used to deface websites, steal credentials and sensitive data, distribute additional malware, or provide a foothold for broader network compromise. The campaign is exploiting vulnerabilities in a range of widely used CMS products and plugins, particularly within the WordPress ecosystem, as well as other platforms including Craft CMS, MaxSite CMS, MetInfo CMS and Joomla components. The ACSC noted that this activity highlights the growing cyber threat landscape, with advances in artificial intelligence contributing to faster identification and exploitation of newly disclosed vulnerabilities. Website owners and administrators are being urged to inspect systems for signs of compromise, review logs for suspicious activity, isolate affected servers and restore websites from known-good backups where necessary. The ACSC also recommends prioritising patching, monitoring for unauthorised file creation and restricting file access to reduce the risk of webshell deployment. Organisations should ensure all website software and plugins remain up to date and consider additional controls to detect unusual processes and limit potential movement within corporate networks. Max severity Adobe ColdFusion flaw now exploited in attacks Date: 2026-07-06 Author: Bleeping Computer [Please see AUSCERT Bulletin: https://portal.auscert.org.au/bulletins/ESB-2026.7232/] [AUSCERT has contacted affected members where applicable] Attackers are now exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, according to vulnerability intelligence company KEVIntel. ColdFusion is a commercial web app development platform designed to help build and deploy enterprise-grade websites. The CVE-2026-48282 security flaw affects ColdFusion versions 2025.9, 2023.20, and earlier, and can be exploited by attackers without privileges to gain remote code execution on unpatched systems. Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution Date: 2026-07-03 Author: Security Week Two critical vulnerabilities in the popular AI code editor Cursor could lead to remote code execution on the underlying operating system, Cato Networks reports. The security defects are tracked as CVE-2026-50548 and CVE-2026-50549 (CVSS score of 9.8) and are referred to as DuneSlide, given that they lead to remote code execution (RCE) outside of the IDE’s sandbox. According to Cato, the flaws abuse Cursor’s automatic terminal command execution inside the sandbox, which does not prompt the user for approval, and can be triggered when a victim prompts the IDE to ingest an attacker-controlled payload. BeyondTrust warns of critical flaws in remote access software Date: 2026-07-07 Author: Bleeping Computer BeyondTrust warned customers to patch two critical security flaws in its Remote Support (RS) and Privileged Remote Access (PRA) software that could allow attackers to bypass authentication. The first vulnerability, tracked as CVE-2026-40138, affects the company's RS remote desktop and assistance platform (versions 25.3.2 or earlier) and the PRA enterprise cybersecurity solution (versions 25.3.2 or earlier). This vulnerability stems from an improper authentication weakness in the authentication subsystem, and successful exploitation enables attackers without privileges to bypass access controls and access targeted appliances, including accounts with elevated privileges. Critical Gitea Flaw Under Active Exploitation, Researchers Warn Date: 2026-07-07 Author: Security Week Threat actors are exploiting a vulnerability in Gitea’s reverse-proxy authentication mechanism to access internet-accessible instances by supplying only a valid username. Specific to Gitea’s official Docker images, the critical-severity security defect is tracked as CVE-2026-20896 (CVSS score of 9.8) and can be exploited with a single HTTP header, Sysdig Sr. Director of Threat Research Michael Clark says. The issue exists because, in Gitea Docker images before 1.26.3, the default settings allow connections from any source IP address instead of enforcing an allowlist, security researcher Ali Mustafa, who was credited for finding the bug, explains. Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities Date: 2026-07-07 Author: The Hacker News A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of a new campaign. The activity involves the exploitation of now-patched, critical security flaws in the open-source email solution, such as CVE-2024-42009 (CVSS score: 9.3), to siphon credentials, followed by either the deployment of a web shell for persistent access or a known post-exploitation tool called VShell. ASB-2026.0125 – ALERT CMS and Plugins: CVSS (Max): 10.0* ACSC has published a critical alert warning of a large-scale campaign actively exploiting vulnerabilities in multiple CMS platforms to compromise websites, urging organisations to patch affected systems and check for signs of compromise. ESB-2026.7592 – IBM MQ container software: CVSS (Max): 10.0 IBM has released updates to fix multiple vulnerabilities affecting IBM MQ Operator and Queue manager container images. The update addresses security issues including Improper Privilege Management, Exposure of Sensitive Information to an Unauthorized Actor, and Improper Validation of Integrity Check Value in components such as OpenSSL, WebSphere Application Server Liberty, and Java SE. ESB-2026.7596 – ALERT Palo Alto Prisma Browser: CVSS (Max): 9.6* Palo Alto Networks has incorporated Chromium security fixes into its products. These fixes are included in Google’s Chrome 150 release, which addresses 433 security fixes, including 20 Critical vulnerabilities affecting components such as Browser, V8, ANGLE, Skia, Blink, and FileSystem. ESB-2026.7647 – ALERT Juniper Networks CTPView: CVSS (Max): 10.0 Juniper Networks has released CTPView 9.3R2-3, addressing multiple vulnerabilities. Juniper SIRT is not aware of any malicious exploitation, and no workarounds are available. ESB-2026.7681 – OpenPLC v3: CVSS (Max): 9.9 Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to the filesystem. Through the standard OpenPLC program compilation process, this may be escalated to arbitrary native code execution, potentially resulting in code execution as the OpenPLC runtime user. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 3rd July 2026

Greetings, Citrix has released patches for six vulnerabilities affecting NetScaler ADC and NetScaler Gateway appliances, but industry attention is firmly focused on CVE-2026-8451, a high-severity memory disclosure flaw that researchers say belongs to the same family of vulnerabilities as the infamous “CitrixBleed” attacks that have plagued organisations in recent years. The flaw carries a CVSS score of 8.8 and impacts NetScaler deployments configured as a SAML Identity Provider, a common setup for single sign-on environments. The vulnerability was discovered by security researchers at watchTowr while they were analysing another NetScaler issue disclosed earlier this year. According to the researchers, CVE-2026-8451 stems from insufficient input validation in the way NetScaler processes SAML authentication requests, creating an out-of-bounds memory read condition that could allow sensitive data to be exposed before authentication. In its analysis, watchTowr argued that the issue highlights a broader pattern of memory management weaknesses within NetScaler appliances. The researchers noted that similar memory disclosure vulnerabilities have repeatedly emerged in the product line, leading them to dub the latest flaw “CitrixBleed To Infinity And Beyond.” While there is currently no public evidence that CVE-2026-8451 is being actively exploited, security teams are taking the issue seriously. A closely related NetScaler vulnerability disclosed in March 2026 was exploited in the wild shortly after publication and was subsequently added to CISA’s Known Exploited Vulnerabilities catalogue. Organisations running affected NetScaler versions are strongly encouraged to apply Citrix’s latest updates as soon as possible and review vendor guidance for any additional mitigation steps. Critical SimpleHelp flaw exploited to deploy new stealer malware Date: 2026-06-29 Author: bleepingcomputer Hackers are exploiting a recently disclosed critical vulnerability (CVE-2026-48558) in SimpleHelp to deploy Djinn Stealer, a previously undocumented cross-platform information stealer targeting Windows, macOS, and Linux. The SimpleHelp platform is primarily used by managed service providers (MSPs), IT departments, helpdesks, and system administrators for remote monitoring and management (RMM). Hackers now exploit critical Oracle E-Business flaw in attacks Date: 2026-06-29 Author: Bleeping Computer [See also AUSCERT bulletin: https://portal.auscert.org.au/bulletins/ESB-2026.5874/] [AUSCERT has contacted affected members where applicable] Attackers have begun exploiting a critical vulnerability (tracked as CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial application, according to threat intelligence company Defused. This security flaw was found in the File Transmission component of EBS's Oracle Payments product and enables unauthenticated malicious actors with HTTP network access to take over vulnerable systems through low-complexity attacks. Anonymous researcher drops 0-day 'exploitarium' repo Date: 2026-06-29 Author: The Register [AUSCERT has published security bulletins for CVE-2026-55200] Not everyone is willing to follow responsible disclosure of vulns. An anonymous researcher has dumped what they say is working exploit code for zero-day vulnerabilities across 15 software products and open source projects without notifying any vendors or maintainers prior to publishing – and attackers are already exploiting at least two of these. The first is CVE-2026-55200, a critical, pre-authentication remote code execution (RCE) vulnerability in libssh2, a popular client-side C library that implements the SSH2 protocol. DirtyClone: A Linux Privilege Escalation That Leaves No Trace on DiskDirtyClone: Fourth Linux Kernel Flaw in Six Weeks Escalates to Root Date: 2026-06-27 Author: Security Affairs DirtyClone: a Linux kernel privilege escalation that silently rewrites executables in memory, leaving no disk trace. Patch now. JFrog Security Research published a working exploit walkthrough on June 25 for CVE-2026-43503 (CVSS score of 8.8), a Linux kernel privilege escalation they call DirtyClone. It’s the fourth vulnerability in the DirtyFrag family, all sharing the same root failure: file-backed memory gets treated as packet data, and an in-place network operation writes where it should have copied. CVSSIf your kernel doesn’t have the May 21 mainline patch, update now. CISA: Windows BlueHammer flaw now exploited by ransomware gangs Date: 2026-06-30 Author: Bleeping Computer CISA confirmed on Monday that ransomware gangs have begun exploiting a high-severity Microsoft Defender privilege escalation vulnerability that has previously been abused in zero-day attacks. Dubbed BlueHammer, the security flaw (CVE-2026-33825) was leaked by a security researcher known as "Nightmare Eclipse" in early April, together with proof-of-concept exploit code, in protest at how the Microsoft Security Response Center (MSRC) handles the disclosure process. ESB-2026.7189 – Apple iOS and iPadOS: CVSS (Max): 8.8* Apple has released updates for iOS and iPadOS to address multiple vulnerabilities affecting Kernel, WebKit, WebRTC, and other components, including issues that may allow unexpected system termination, cross-origin data exposure, and sensitive information disclosure. ESB-2026.7232 – Adobe ColdFusion: CVSS (Max): 10.0 Adobe has released security updates for ColdFusion versions 2025 and 2023 to address multiple critical and important vulnerabilities. These vulnerabilities could allow arbitrary code execution, privilege escalation, unauthorized file system access, and security feature bypass. ESB-2026.7296 – NetScaler ADC and NetScaler Gateway: CVSS (Max): 8.8 Multiple vulnerabilities have been identified in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). Cloud Software Group strongly recommends updating as soon as possible. ESB-2026.7324 – Splunk: CVSS (Max): 9.8 Splunk has remediated multiple Common Vulnerabilities and Exposures (CVEs) affecting third-party packages included in Python for Scientific Computing version 4.3.2 and later. ESB-2026.7358 – IBM MQ for HPE NonStop: CVSS (Max): 9.8 IBM MQ for HPE NonStop is affected by multiple OpenSSL vulnerabilities, including CVE-2026-31789. The most severe issue may lead to a heap buffer overflow when processing specially crafted X.509 certificates, potentially resulting in a crash or code execution. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 26th June 2026

Greetings, Global cyber security leaders are urging organisations to rethink their approach to risk as AI rapidly reshapes both the scale and speed of cyber attacks. In a joint statement, the Five Eyes alliance, comprising Australia, the United States, the United Kingdom, Canada and New Zealand, has warned that the impact of frontier AI models will be felt far sooner than many organisations expect. According to the advisory, these next-generation systems are poised to transform offensive and defensive cyber capabilities “within months, not years,” dramatically reducing the time between discovering and exploiting vulnerabilities. This acceleration is lowering barriers to entry for malicious actors, enabling less sophisticated attackers to launch complex, high-impact operations with increasing efficiency. Coverage from The Record reinforces this message, highlighting growing government concern that powerful AI tools can already identify and exploit software flaws at a pace that exceeds human response. In some cases, advanced models have demonstrated an ability to uncover vulnerabilities and generate exploit pathways in hours, intensifying fears that cyber defences may struggle to keep up. Despite the urgency, the Five Eyes agencies emphasise that the fundamentals of cyber security remain critical. Their guidance focuses on strengthening baseline practices such as rapid patching, reducing system exposure, improving identity controls and preparing thoroughly for inevitable breaches. They also stress that cyber risk is now a core organisational risk, rather than a purely technical issue, requiring strategy and leadership accountability. Importantly, the statement balances its warning with opportunity. While adversaries are already leveraging AI, organisations are urged to adopt the same technologies to enhance detection, improve resilience and respond more quickly to incidents. This message serves as an important reminder that AI is a present and accelerating force. Organisations that act decisively now will be better positioned to manage emerging risks, while those that delay may face growing operational, financial and reputational consequences. Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure Date: 2026-06-19 Author: Security Week A critical Splunk Enterprise vulnerability is being exploited in attacks only days after its public disclosure, and organizations have been urged to patch it immediately. The vulnerability is tracked as CVE-2026-20253 and Splunk’s advisory says it can be exploited by an unauthenticated attacker to create or truncate arbitrary files via a PostgreSQL sidecar service endpoint. “The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials,” Splunk said in its advisory. Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks Date: 2026-06-23 Author: Bleeping Computer [See AUSCERT Bulletin https://portal.auscert.org.au/bulletins/ESB-2026.6126] A high-severity SSRF vulnerability, tracked as CVE-2026-20230, in Cisco Unified Communications Manager Server is now being exploited in attacks. Cisco released security updates for the CVE-2026-20230 flaw on June 3, warning that exploitation could give attackers root privileges on the device. "A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device," warned Cisco. ASD to retire Essential Eight cyber security framework within next two years Date: 2026-06-24 Author: iTnews Its replacement reflects a changing reality for security teams. The Australian Signals Directorate intends to retire its Essential Eight guidance framework within two years, to keep up with shifting cyber security sands. Replacing Essential Eight will be a broader "Essentials" series designed to cover enterprise IT, cloud, operational technology, and potentially agentic artificial intelligence (AI) as distinct security domains. 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown Date: 2026-06-19 Author: Security Week [AUSCERT have contacted the potentially impacted members via email] Law enforcement agencies in four countries, working with Europol and private partners, have disrupted SocGholish infrastructure and cleaned up nearly 15,000 infected WordPress websites. Active since 2017 and also known as FakeUpdates, SocGholish is a malware framework injected into websites running popular content management systems, such as WordPress, Joomla, and Drupal, either via known vulnerabilities or stolen credentials. FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation Date: 2026-06-23 Author: The Hacker News A Russian-speaking initial access broker (IAB) driven by financial gain is assessed to be behind a large-scale credential-harvesting operation known as FortiBleed that has targeted over 430,000 FortiGate firewalls globally. The campaign, active since February 2026, involves collecting credential lists, searching for exposed services, brute-forcing accessible systems, and deploying bespoke sniffers on compromised firewalls. "Once deployed, these sniffers capture cleartext and hashed credentials from traffic passing through compromised devices," SOCRadar said [PDF] in a fresh report. "The actors then crack, validate, and reuse the credentials against Active Directory domains and other exposed services." ESB-2026.6227.3 – Cisco Catalyst SD-WAN Manager: CVSS (Max): 10.0 A severe vulnerability allowed an authenticated, local attacker to execute arbitrary commands as root via a crafted file into the affected system. Cisco has released updates that address this issue. ESB-2026.6871 – MISP: CVSS (Max): 9.4 This MISP update addresses two RCE vectors, an authentication hardening issue and various fixes across the controller layer. Upgrading is strongly recommended. ESB-2026.6891 – IBM MQ container software: CVSS (Max): 10.0* IBM MQ Operator and Queue Manager container images had multiple severe vulnerabilities addressed. IBM strongly recommends applying the latest container images. ESB-2026.6951 – Tenable Identity Exposure: CVSS (Max): 9.9 Several third party components of Tenable Identity Exposure were found to contain numerous vulnerabilities. Updated/patched versions have been provided by the respective vendors to address reported vulnerabilities. ESB-2026.7052 – chromium: CVSS (Max): 9.6* Execution of arbitrary code, denial of service and information disclosure were security issues recently discovered in Chromium. These issues have been addressed in version 149.0.7827.196-1~deb13u1. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 19th June 2026

Greetings, A newly uncovered data exposure incident dubbed “FortiBleed” has revealed a large number of Fortinet VPN credentials tied to organisations worldwide. The dataset contains usernames, email addresses, and plaintext passwords linked to more than 73,000 firewall devices across 194 countries, spanning industries from telecommunications and finance to government and manufacturing. The scale and sophistication of the operation suggest a highly organised campaign. Analysis indicates attackers carried out billions of login attempts against hundreds of thousands of systems, harvesting and cracking authentication data using advanced computing resources. The resulting database catalogued verified credentials as well as contextual details such as company size and industry, which is likely intended to help prioritise high-value targets. Independent researchers have validated portions of the leaked data, confirming that at least some credentials are authentic and recent. Many of the affected devices remain accessible online, amplifying the potential risk. Experts believe the information may have originated from exported Fortinet configuration files, though it is still unclear whether the exact source was a new vulnerability or previously compromised data. Despite the severity, Fortinet has stated that the leak does not stem from a newly identified flaw, but rather from a combination of past incidents and credential harvesting techniques such as brute-force attacks. Organisations who appear in the dataset are urged to immediately reset passwords linked to Fortinet VPN and administrative systems, implement multi-factor authentication, review gateway logs for any signs of suspicious activity, and keep a close watch for compromised employee credentials. Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication Date: 2026-06-13 Author: The Hacker News [See AUSCERT bulletin: https://portal.auscert.org.au/bulletins/ESB-2026.6480] Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution. The vulnerability, tracked as CVE-2026-20253, is rated 9.8 on the CVSS scoring system. "In Splunk Enterprise versions below 10.2.4 and 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint," Splunk said in an alert this week. Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks Date: 2026-06-15 Author: Bleeping Computer [See also AUSCERT bulletin: https://portal.auscert.org.au/bulletins/ESB-2026.6638/] Cisco has released security updates to address a vulnerability in the Catalyst SD-WAN Manager, tracked as CVE-2026-20262, that was exploited in attacks to escalate to root privileges. Formerly known as SD-WAN vManage, this network management software allows admins to manage up to 6,000 SD-WAN devices from a single dashboard. The now-patched zero-day security flaw affects all deployment types, regardless of device configuration, including on-prem deployments, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP). Oracle’s Second Monthly Security Updates Deliver 245 Patches Date: 2026-06-17 Author: Security Week [Please also see AUSCERT bulletin: https://portal.auscert.org.au/bulletins/ESB-2026.6735/] Oracle on Tuesday announced the release of its June 2026 Critical Security Patch Update (CSPU), the second since it began releasing monthly patches. The company still releases its quarterly Critical Patch Updates, but it recently decided to supplement them with monthly patches to address more severe vulnerabilities. The software giant said the latest round of CSPU updates delivers 245 new patches, including for Communications, E-Business Suite, Enterprise Manager, Fusion Middleware, JD Edwards, MySQL, PeopleSoft, Siebel CRM, Supply Chain, Systems, and Virtualization products. Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw Date: 2026-06-15 Author: The Hacker News [AUSCERT has shared IoCs related to CVE-2026-0257 via its MISP instance] Palo Alto Networks has revealed that it has observed "active exploitation" of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals. The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software that could be exploited by bad actors to set up VPN connections. According to the network security company, the security defect could be exploited by a bad actor to bypass security controls and initiate VPN connections. FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. Date: 2026-06-18 Author: Bleeping Computer [AUSCERT have contacted the potentially impacted members via email] A newly discovered data leak dubbed "FortiBleed" has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide. The exposed data was first discovered by security researcher Bob Diachenko, who says he found a server containing what appeared to be valid Fortinet VPN credentials, including usernames, email addresses, and plaintext passwords. ESB-2026.6674 – Firefox 152: CVSS (Max): 9.1* Mozilla released the Firefox 152 update addressing multiple security vulnerabilities. The fixes include memory safety bugs, sandbox escapes, privilege escalation vulnerabilities, and other security issues across browser components ESB-2026.6681 – Atlassian Products: CVSS (Max): 10 Atlassian has released product versions over the past month that fix 76 high-severity vulnerabilities and 24 critical-severity third-party vulnerabilities. ESB-2026.6735 – Oracle Products: CVSS (Max): 9.8* The June 2026 Critical Security Patch Update contains 245 new security patches across multiple Oracle product families. It includes Oracle PeopleSoft PeopleTools and Oracle PeopleSoft Enterprise Applications patches addressing CVE-2026-35273. ESB-2026.6778 – Cisco Identity Services Engine: CVSS (Max): 9.1 Cisco has released software updates addressing multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). These vulnerabilities could allow a remote attacker to achieve remote code execution or disclose information on affected devices. ESB-2026.6796 – NGINX: CVSS (Max): 8.1 F5 has released updates for affected products to address a vulnerability in NGINX Open Source. The issue may allow a remote unauthenticated attacker to trigger a use-after-free condition via a specially crafted HTTP/3 session, potentially leading to denial of service or code execution under certain conditions. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 12th June 2026

Greetings, Oracle has issued an urgent security advisory addressing a critical vulnerability in its widely used PeopleSoft platform, amid growing concerns that the flaw may already be exploited in real-world attacks. The vulnerability, tracked as CVE-2026-35273, affects PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 and could allow unauthenticated attackers to remotely execute code on affected systems. As PeopleSoft supports essential business functions such as HR, payroll, finance, and supply chain operations, potential impact of such a flaw is significant for large organisations globally. While Oracle has released mitigation guidance, it has yet to provide a full patch. The company has also not confirmed whether the vulnerability is being actively exploited as a zero-day, though it has strongly urged customers to follow its guidance immediately to reduce risk. Concern has been heightened by reports linking the issue to activity from the cybercriminal group ShinyHunters. The group has claimed to have targeted hundreds of PeopleSoft instances across more than 100 organisations, allegedly combining previously known flaws with zero-day vulnerabilities to access sensitive data. Security researchers have observed at least some level of exploitation, reinforcing the urgency of the situation. The education sector appears particularly affected, with institutions such as the University of Nottingham confirming data breaches linked to the campaign. This latest development highlights the ongoing risks facing enterprise software environments and highlights the importance of timely mitigation, monitoring and rapid response capabilities. Organisations relying on PeopleSoft are being advised to prioritise Oracle’s recommendations as investigations continue and more details emerge. Cisco warns of unpatched SD-WAN zero-day exploited in attacks Date: 2026-06-05 Author: Bleeping Computer [See AUSCERT bulletin https://portal.auscert.org.au/bulletins/ESB-2026.6227.2/] On Thursday, Cisco warned of a high-severity, unpatched zero-day in the Cisco Catalyst SD-WAN Manager (tracked as CVE-2026-20245) actively exploited in attacks enabling root privilege escalation. The zero-day flaw impacts all deployment types, including On-Prem Deployment, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP). CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog Date: 2026-06-06 Author: The Hacker News The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity security flaw impacting SolarWinds Serv-U multi-protocol file server software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-28318 (CVSS score: 7.5), is a denial-of-service (DoS) bug that causes the service to crash under certain conditions. CISA described it as an uncontrolled resource consumption vulnerability that results in a DoS condition. Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities Date: 2026-06-10 Author: The Hacker News [AUSCERT has published relevant security bulletins] Fortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary code execution and information disclosure. The security flaw patched by Fortinet relates to a command injection vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI. It's tracked as CVE-2026-25089 (CVSS score: 9.1). Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code Date: 2026-06-09 Author: The Hacker News [AUSCERT has contacted affected members where applicable] Veeam has released security patches to address a critical flaw in its Backup & Replication software that could result in remote code execution. Tracked as CVE-2026-44963, the vulnerability carries a CVSS score of 9.4 out of a maximum of 10.0. "A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user," Veeam said in a Tuesday advisory. Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks Date: 2026-06-10 Author: Bleeping Computer [AUSCERT has published a relevant security bulletin – https://portal.auscert.org.au/bulletins/ASB-2026.0123/] Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations. PeopleSoft is an enterprise business software suite used by large organizations to manage business operations such as human resources, payroll, finance, supply chain management, procurement, and student administration. ESB-2026.6355 – Google Chrome: CVSS (Max): 9.6* Google Chrome addresses 74 security vulnerabilities, including 17 Critical issues, and also fixes a High-severity vulnerability that is known to be actively exploited in the wild. ESB-2026.6391 – Adobe Campaign Classic: CVSS (Max): 10 Adobe has released security updates for Adobe Campaign Classic. This update addresses critical vulnerabilities that could result in arbitrary code execution. ESB-2026.6438 – Fortinet FortiSandbox: CVSS (Max): 9.1 A vulnerability in the FortiSandbox web UI involving improper neutralization of special elements used in an OS command may allow an unauthenticated attacker to execute unauthorized commands through specially crafted HTTP requests. ESB-2026.6460 – Palo Alto Products: CVSS (Max): 9.3 A vulnerability involving improper validation of credentials in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources. ESB-2026.6473 – Splunk Enterprise: CVSS (Max): 10 Splunk Enterprise updates multiple components including Go, MongoDB, aiohttp, OpenTelemetry, PostgreSQL, etcd-related binaries, Log4j, and Cloudflare CIRCL libraries to address a range of security vulnerabilities, including some with associated CVE identifiers. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 5th June 2026

Greetings, Microsoft has moved to address a significant identity security issue in its Entra ID platform, patching a flaw that could have enabled widespread privilege escalation and service account takeover across enterprise environments. The vulnerability, identified by researchers at Silverfort, centred on the “Agent ID Administrator” role. This feature was introduced to manage the lifecycle of AI agent identities within Entra ID. While the role was designed with a limited scope, researchers discovered it could be abused to take ownership of arbitrary service principals, including those unrelated to AI agents. By assigning themselves ownership and adding new credentials, attackers could effectively impersonate these service accounts and inherit their permissions, a scenario described as “full service principal takeover.” The risks associated with this flaw are substantial. Service principals often underpin critical enterprise functions such as automation workflows, API integrations, and cloud infrastructure operations. If compromised, particularly when linked to highly privileged roles or Microsoft Graph permissions, attackers could gain broad access to sensitive systems, escalate privileges further, and potentially take control of entire tenant environments. The root cause of the issue lies in a failure to properly enforce scope boundaries. Because AI agent identities are built on the same underlying architecture as standard service principals, the role’s permissions extended beyond their intended domain. This highlights a growing challenge in identity security, where new features layered on existing systems can inadvertently introduce unexpected access paths. Microsoft responded by deploying a fix across cloud environments on April 9, 2026, blocking the ability of the Agent ID Administrator role to modify non-agent service principals. The incident serves as a timely reminder that robust role scoping, continuous monitoring, and strict governance of non-human identities are essential as organisations adopt increasingly complex, AI-driven identity ecosystems. Critical Windows Netlogon RCE flaw now exploited in attacks Date: 2026-06-01 Author: Bleeping Computer [See AUSCERT bulletin https://portal.auscert.org.au/bulletins/ASB-2026.0110] The Centre for Cybersecurity Belgium (CCB), the country's national authority for cybersecurity, warned on Friday that threat actors are now exploiting a recently patched critical Windows Netlogon vulnerability in attacks. Netlogon is a remote procedure call (RPC) interface and a core Microsoft Windows Server background service that authenticates services and users on Windows domain-based networks. Microsoft patched this vulnerability (CVE-2026-41089) during the May 2026 Patch Tuesday, describing it as a stack-based buffer overflow in Windows Netlogon that allows attackers without privileges to gain remote code execution on targeted domain controllers. Critical Kirki flaw exploited to hijack WordPress admin accounts Date: 2026-06-02 Author: Bleeping Computer Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress to take over any user account, including those belonging to administrators. The attacks were detected by WordPress security firm Defiant, whose Wordfence firewall blocked over 222 attempts against its customers in the past 24 hours. The full name of the plugin is Kirki – Freeform Page Builder, Website Builder & Customizer. It is a freeform visual builder and advanced theme customizer active on more than 500,000 websites. Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks Date: 2026-05-30 Author: Bleeping Computer [See updated AUSCERT bulletin https://portal.auscert.org.au/bulletins/ESB-2026.5111.2] Palo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, in attacks attempting to breach corporate networks. The company fixed the CVE-2026-0257 flaw earlier this month, warning that it could be used to establish unauthorized VPN connections on the device. "GlobalProtect portal and gateway of Palo Alto Networks PAN-OS software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection," reads Palo Alto's advisory. Exploit Code Published for Critical Flowise RCE Vulnerability Date: 2026-05-30 Author: Security Week Obsidian Security has released technical information and proof-of-concept (PoC) code targeting a remote code execution (RCE) vulnerability in Flowise. The issue, tracked as CVE-2026-40933 (CVSS score of 9.9), was disclosed in April along with several other security defects impacting AI ecosystems that rely on Anthropic’s MCP protocol. Flowise, a popular open source platform that provides developers with a drag-and-drop interface for building LLM flows and AI agents, and which has over 52,000 GitHub stars, was flagged as one of the impacted products. ‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds Date: 2026-06-03 Author: Security Week Known denial-of-service (DoS) techniques can be chained together in a new exploit that can knock major web servers offline, Calif security researchers warn. Dubbed HTTP/2 Bomb and discovered using OpenAI’s Codex, the exploit combines a compression bomb that targets HTTP/2’s header compression scheme (HPACK) with a Slowloris-style hold that prevents the server from freeing memory. ASB-2026.0110 – Microsoft Windows: CVSS (Max): 9.8 Microsoft's May 2026 Patch Tuesday update addresses 67 vulnerabilities across supported Windows desktop and server platforms, including Windows 10, Windows 11, Windows Server 2016–2025, and Windows Admin Center. ESB-2026.5111.2 – Palo Alto PAN-OS: CVSS (Max): 7.8 A high-severity authentication bypass vulnerability, affects Palo Alto Networks' GlobalProtect VPN functionality on PAN-OS firewalls. Successful exploitation allows an unauthenticated attacker to bypass security controls and establish unauthorized VPN access. ESB-2026.6009 – IBM QRadar Investigation Assistant App: CVSS (Max): 10.0 IBM has released an update for the IBM QRadar Investigation Assistant App (AI Assistant) to address numerous vulnerabilities in bundled third-party components. ESB-2026.5923 – Chormium: CVSS (Max): 9.8 Debian has released an advisory to address a large number of security vulnerabilities in Chromium. The advisory addresses vulnerabilities that could lead to, Remote code execution, Information disclosure &Denial of service. ESB-2026.6022 – Unbound: CVSS (Max): 10 Ubuntu has released an advisory to address multiple vulnerabilities in Unbound, a widely used validating, recursive DNS resolver. The advisory backports fixes for several vulnerabilities affecting older Ubuntu LTS releases. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 29th May 2026

Greetings, Carnival Corporation, the world’s largest cruise operator, has confirmed a significant cyber security incident affecting nearly six million individuals. The breach, which occurred in April 2026, was triggered by a social engineering attack in which a threat actor deceived an employee into granting access to their account. This allowed the attacker to infiltrate a limited portion of Carnival’s IT systems and ultimately extract customer data. The company detected suspicious activity on April 14 and moved to block access, later confirming on April 22 that personal information had been copied. Carnival has since begun notifying approximately 5.99 million affected individuals. While the full scope of the compromised data varies, exposed information is believed to include names, dates of birth, email addresses, and loyalty program details. The breach has been linked to the ShinyHunters cybercrime group, which claimed responsibility and alleged it stole millions of records along with large volumes of internal corporate data. The incident highlights the ongoing effectiveness of social engineering tactics, where attackers exploit human behaviour rather than technical vulnerabilities to gain entry into systems. In response, Carnival says it has strengthened its cyber security measures and engaged external experts to support its investigation. However, for millions of customers, the breach serves as a timely reminder of the importance of vigilance in protecting personal information in an increasingly digital travel landscape. LiteSpeed cPanel Plugin 0-Day Exploited in the wild to Gain Server Root Access Date: 2026-05-22 Author: Cyber Security News [AUSCERT has identified the impacted members (where possible) and contacted them via email] LiteSpeed has disclosed and patched a critical 0‑day privilege escalation flaw in its user-end cPanel plugin that is already being actively exploited to gain root access on Linux hosting servers. The bug is tracked as CVE‑2026‑48172 and affects LiteSpeed cPanel user-end plugin versions from v2.3 up to, but not including, v2.4.5. Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code Date: 2026-05-28 Author: The Hacker News [AUSCERT has identified the impacted members (where possible) and contacted them via email] A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, that allows an authenticated user to execute arbitrary code under certain conditions. The security flaw, per Rapid7, is rated 9.4 on the CVSS scoring system. It does not have a CVE identifier. “The vulnerability allows any authenticated user to achieve remote code execution (RCE) on the server by creating a pull request with a malicious branch name that injects the –exec flag into git rebase during the ‘Rebase before merging’ merge operation,” security researcher Jonah Burgess said. Trend Micro warns of Apex One zero-day exploited in the wild Date: 2026-05-22 Author: Bleeping Computer Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows systems. Apex One is Trend Micro’s enterprise-grade endpoint security platform that protects corporate networks from a wide range of security threats, including malware, ransomware, fileless attacks, and web-based threats. Drupal: Critical SQL injection flaw now targeted in attacks Date: 2026-05-22 Author: Bleeping Computer Drupal is warning that hackers are attempting to exploit a “highly critical” SQL injection vulnerability announced earlier this week. The content management system (CMS) project published a PSA on May 18, urging administrators to reserve time for core updates that addressed an issue that threat actors might start exploiting “within hours or days.” New 7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code and Compromise Systems Date: 2026-05-26 Author: Cyber Security News A critical heap buffer overflow vulnerability has been disclosed in 7-Zip version 26.00, enabling attackers to achieve arbitrary code execution via a vtable hijack by exploiting a defect in the tool’s NTFS archive handler. Tracked as CVE-2026-48095 and assigned advisory GHSL-2026-140, the flaw resides in the CInStream::GetCuSize() function inside NtfsHandler.cpp. The function computes the NTFS compression-unit buffer size using a 32-bit shift operation: (UInt32)1 << (BlockSizeLog + CompressionUnit). ASB-2026.0111 – Microsoft SharePoint Server: CVSS (Max): 8.8 Microsoft has released a security update addressing a remote code execution vulnerability in Microsoft SharePoint Server. A deserialization of untrusted data vulnerability in Microsoft Office SharePoint allows an authenticated attacker with low privileges to exploit this flaw over the network to execute arbitrary code on the affected SharePoint server. ESB-2026.5634 – NGINX: CVSS (Max): 8.1 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only. ESB-2026.5674 – IBM QRadar SIEM: CVSS (Max): 9.8* Multiple components with known vulnerabilities were addressed in IBM QRadar SIEM 7.5.0 UP15 IF03, including an off-by-one heap buffer overflow in XML::Parser when parsing deeply nested XML files. A heap overflow in the Linux kernel NFSv4.0 replay cache caused by copying oversized LOCK denied responses into a fixed 112-byte buffer without bounds checking was also addressed. Additional fixes included a use-after-free issue in Python decompressor objects after a MemoryError, a Vim modeline sandbox bypass allowing arbitrary OS command execution when opening a crafted file, and an OpenSSH scp issue that could install downloaded files as setuid or setgid under specific conditions. ESB-2026.5737 – IBM WebSphere Application Server: CVSS (Max): 9.8 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by remote code execution and HTTP request smuggling when using the optional and separately installable Web Server Plug-ins for IBM WebSphere Application Server component. ESB-2026.5761 – Jenkins: CVSS (Max): 8.8* LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals from the configured LDAP server. These can forward to an RMI URL that causes Jenkins to deserialize attacker-controlled data, resulting in Remote Code Execution (RCE) on the Jenkins controller if deserialization “gadgets” are available on the classpath. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 22nd May 2026

Greetings, What a week it’s been! AUSCERT2026 delivered another standout chapter in Australia’s longest-running cyber security conference, bringing together practitioners, researchers, and leaders from across the globe for four days of learning, collaboration, and innovation on the Gold Coast. Celebrating its 25th year, this milestone event truly embodied its “Game On!” theme, highlighting the fast-paced, high-stakes nature of modern cyber defence and the teamwork required to succeed. The week kicked off with an expansive lineup of hands-on tutorials and workshops, spanning everything from red teaming and threat hunting to governance, AI compliance, and cloud security. These sessions created an energised environment where attendees could dive deep into technical challenges, sharpen their capabilities, and exchange insights with peers and industry experts. A highlight of the week was the keynote lineup, which once again brought big ideas and future-focused thinking to centre stage. Dr. Kawin Boonyapredee delivered a standout keynote on “Beyond Bits: Defending Data in the Quantum Age,” exploring the transformative impact of quantum computing and the urgent need to prepare cryptographic defences for the future. Meanwhile, the International CyberSecurity Challenge brought a global competitive edge to the conference, with teams from around the world competing in high-pressure scenarios that showcased emerging talent and reinforced the importance of collaboration on an international scale. This year saw Team Europe taking out the top spot, followed by Team USA and Team Oceania. Beyond the formal sessions, AUSCERT2026 thrived on its strong sense of community. Networking events, which included the welcome reception and the 25th Anniversary Gala Dinner, offered invaluable opportunities to connect, reflect, and celebrate the industry’s progress together. AUSCERT2026 sparked conversations, developed skills, and built relationships that will continue to strengthen and evolve the cyber security landscape across Australia and beyond. Here’s to another year of pushing boundaries, fostering collaboration, and staying one step ahead, because in this arena, it’s always Game On. Microsoft warns of Exchange zero-day flaw exploited in attacks Date: 2026-05-15 Author: Bleeping Computer On Thursday, Microsoft shared mitigations for a high-severity Exchange Server vulnerability exploited in attacks that allow threat actors to execute arbitrary code via cross-site scripting (XSS) while targeting Outlook on the web users. Microsoft describes this security flaw (CVE-2026-42897) as a spoofing vulnerability affecting up-to-date Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) software. Max-severity flaw in ChromaDB for AI apps allows server hijacking Date: 2026-05-19 Author: Bleeping Computer A max-severity vulnerability in the latest Python FastAPI version of the ChromaDB project allows unauthenticated attackers to run arbitrary code on exposed servers. The flaw is tracked as CVE-2026-45829 and was reported to ChromaDB on February 17. It received the maximum severity score from HiddenLayer, the company that discovered it. NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE Date: 2026-05-17 Author: The Hacker News [AUSCERT has published relevant security bulletins from individual vendors] A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck. The vulnerability, tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow in ngx_http_rewrite_module affecting NGINX versions 0.6.27 through 1.30.0. According to AI-native security company depthfirst, the vulnerability was introduced in 2008. Hackers bypass SonicWall VPN MFA due to incomplete patching Date: 2026-05-20 Author: Bleeping Computer Threat actors brute-forced VPN credentials and bypassed multi-factor authentication (MFA) on SonicWall Gen6 SSL-VPN appliances to deploy tools used in ransomware attacks. During the intrusions, the hacker took between 30 and 60 minutes to log in, do network reconnaissance, test credential reuse on internal systems, and log out. Microsoft Rolls Out Mitigations for ‘YellowKey’ BitLocker Bypass Date: 2026-05-20 Author: Security Week Microsoft on Tuesday rolled out mitigations for YellowKey, a recently disclosed zero-day vulnerability leading to BitLocker bypass. The issue, now tracked as CVE-2026-45585 (CVSS score of 6.8), can be triggered by an attacker with physical access to a system by using a USB drive containing the publicly released YellowKey exploit code and rebooting the system into recovery mode. ESB-2026.5308 – IBM MQ container software: CVSS (Max): 9.9* Multiple vulnerabilities were addressed in IBM MQ Operator and Queue manager container images. systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. ESB-2026.5387 – IBM MQ Agent: CVSS (Max): 10.0 Multiple vulnerabilities were addressed in IBM MQ Agent images. Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11. ESB-2026.5403 – Mozilla Firefox: CVSS (Max): 9.8 Firefox 151 fixes multiple high-severity vulnerabilities, including sandbox escapes, memory safety bugs with potential for code execution due to memory corruption, and several same-origin policy bypasses in DOM and networking components. The update also addresses additional issues such as privilege escalation, spoofing, information disclosure, integer overflows, mitigation bypasses, and denial-of-service vulnerabilities across multiple browser components. ESB-2026.5500 – Splunk: Splunk Enterprise CVSS (Max): 10.0 Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Splunk Enterprise versions 10.2.3, 10.0.6, 9.4.11, 9.3.12, and higher. ESB-2026.5533 – Cisco Secure Workload: CVSS (Max): 10.0 A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more