Week in review

AUSCERT Week in Review for 28th August 2026

Greetings, The pressure on social media platforms to better protect young users is intensifying, with governments and regulators around the world taking increasingly tough measures against the technology giants. New Zealand is the latest country to move towards restricting social media access for under 16s, with proposed legislation requiring platforms to take reasonable steps to verify users' ages. The proposal follows Australia's world-first under-16 social media restrictions and reflects growing international concern about the impact of social media on children. Meanwhile, in the United States, Meta has agreed to pay up to US$18 billion to settle lawsuits brought by almost every US state over allegations that Facebook and Instagram harmed children and misled the public about the safety of its platforms. As part of the settlement, Meta has also agreed to introduce stronger protections for teenage users, including default time limits, overnight restrictions and limits on notifications during school hours. While Meta has not admitted wrongdoing and the settlement does not fundamentally change its business model, the scale of the agreement signals a significant shift in expectations around platform accountability. It could also provide a template for similar action against other major platforms, with part of Meta's settlement tied to comparable commitments from competitors such as TikTok and YouTube. The global push highlights the growing intersection of online safety, privacy, cybersecurity and regulation. As age verification and platform monitoring increase, so do concerns around protecting sensitive user data. Regulation is accelerating, and technology companies face growing expectations to build safety and security into their platforms by design. Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data Date: 2026-08-25 Author: The Hacker News [AUSCERT has informed the potentially affected members via Critical MSINs] The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. Successful exploitation of the flaw can lead to unauthorized access to the instances or modification of critical data. Hackers breached over 270 Zimbra servers in ongoing attacks Date: 2026-08-25 Author: Bleeping Computer Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. The ZCS email and collaboration suite is used by hundreds of millions of people and organizations, including thousands of businesses and hundreds of government agencies worldwide. Synacor patched the security flaw (tracked as CVE-2026-73570), which allows unauthenticated attackers to gain code execution remotely by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled, with the release of ZCS version 10.1.20 on July 20. Active exploitation of a software development platform within Australia Date: 2026-08-24 Author: ASD ACSC The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has observed active exploitation of a vulnerability affecting TeamCity On-Premises servers within Australia. TeamCity is a Continuous Integration and Continuous Deployment (CI/CD) server to automate the processes of building, testing, and deploying software. CVE 2026-63077 may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands. This vulnerability affects all TeamCity On-Premises versions. Hackers target Microsoft SharePoint RCE chain with PoC exploit Date: 2026-08-26 Author: Bleeping Computer Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused. The first (tracked as CVE-2026-55040) is an authentication bypass flaw in the JWT token validation pipeline that attackers without privileges can exploit to perform operations as a SharePoint site user or administrator. The second (CVE-2026-63520) is a vulnerability in SharePoint's Business Connectivity Services (BCS) that unauthenticated attackers can chain after successfully exploiting CVE-2026-55040 for remote code execution (RCE) on a targeted SharePoint Server. Shop now? Banking malware campaign posing as Woolworths active in Australia Date: 2026-08-21 Author: cyberdaily.au Woolies and other trusted brands are being used to spread an Android Trojan that can access bank accounts, read SMSes, and even access cameras. Security researchers have lifted the lid on an ongoing Android malware campaign active in Australia, posing as several trusted and well-known brands to spread a Remote Access Trojan (RAT) designed, among other things, to steal banking information. According to NordVPN’s threat intelligence team, the campaign is circulating via text messages, WhatsApp, and social media, impersonating brands such as supermarket giant Woolworths and several airlines, including Emirates, Qatar Airways, and Air India. ESB-2026.9812 – Cisco Crosswork Platform(s): CVSS (Max): 10.0 Cisco has released software updates that address vulnerabilities in Cisco Crosswork platform(s). ESB-2026.10018 – Adobe Campaign Classic: CVSS (Max): 10.0 Adobe has released a security update that addresses critical (RCE) vulnerabilities in Adobe Campaign Classic. ESB-2026.10087 – GitLab Community Edition (CE) and Enterprise Edition (EE): CVSS (Max): 8.7 Updated versions of GitLab Community Edition (CE) and Enterprise Edition (EE) contain important bug and security fixes. GitLab strongly recommends that all self-managed GitLab installations be upgraded. ESB-2026.10066 – IBM QRadar SIEM: CVSS (Max): 9.8 Multiple components with known vulnerabilities were addressed in IBM QRadar SIEM updates. ESB-2026.10159 – All-Line Equipment Company Fuel-Boss: CVSS (Max): 8.7 Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Resources

Cyber Culture Metrics: Actionable Tool from AUSCERT

Understanding and measuring cyber culture enables organisations to reduce human risk, improve security outcomes, and foster a culture of resilience. The AUSCERT Cyber Leaders Network Cyber Culture Metrics Working Group have developed a practical tool for organisations to assess the maturity of their cyber security culture, benchmark performance, and prioritise improvements that reduce human cyber risk. The Cyber Culture Maturity Model (CCMM) measurement instrument provides a: Diagnostic Tool (6 dimensions aligned with NCSC Iceberg model, 5 questions each) Linkage to Theoretical Foundation Cyber Culture Measurement Score CCMM Reference for Improvements The tool is freely available for download: AUSCERT – CLN – Cyber Culture Maturity Model Instrument Macro (Excel)   Tim Lane (CISO, TURSA) unveiled this tool in his presentation at the AUSCERT2026 Conference in May 2026. The presentation recording is available below. Download a copy of Tim’s presentation slides here: AUSCERT – CLN – Cyber Culture Metrics   These resources were developed by the Cyber Leaders Network’s Cyber Culture Metrics working group. The Cyber Leaders Network brings together cyber security professionals from across industries to collaborate, share best practices, and exchange insights on emerging challenges. Coordinated by AUSCERT, the Network provides a trusted forum for leaders to collectively strengthen Australia’s cyber resilience. All resources are shared under a Creative Commons Attribution 4.0 International License (CC BY 4.0), allowing you to share and adapt the material with appropriate credit to the AUSCERT Cyber Leaders Network.

Learn more

Week in review

AUSCERT Week in Review for 21st Aug 2026

Greetings, AUSCERT is proud to be part of the Not-For-Profit Cyber Uplift Community of Practice, launched by the Australian Department of Home Affairs in partnership with the Australian Charities and Not-for-profits Commission. The free launch event will take place on Wednesday, 26 August 2026, from 1PM–2PM AEST, providing not-for-profit organisations with practical advice, knowledge and support to strengthen cyber resilience across the sector. Register here The importance of strengthening cyber resilience is particularly timely, with a large-scale data theft campaign reportedly targeting Azure/Entra environments belonging to major organisations, including McDonald’s, TCS, Vodafone and Kyndryl. The campaign is linked to a new threat actor known as TheHatman, who claims to have stolen millions of enterprise records. While the initial access vector remains unconfirmed, reported possibilities include stolen credentials or session cookies, phishing, weak or missing MFA, and overly permissive third-party applications. The activity does not currently appear to exploit an Azure vulnerability, with compromised credentials a key concern. The incident highlights how stolen organisational information including employee details, reporting structures, service accounts and privileged account information could enable highly targeted phishing, impersonation and business email compromise attacks. It reinforces the importance of phishing-resistant MFA, protecting cloud credentials and session tokens, detecting infostealer infections, reviewing third-party application permissions and monitoring unusual activity across Azure/Entra environments. Together, these developments highlight why practical cyber resilience initiatives are essential for organisations of all sizes. … Critical Citrix NetScaler Flaw Lets Remote Attackers Bypass Authentication Without Credentials Date: 2026-08-19 Author: Cyber Security News [See AUSCERT bulletin: https://portal.auscert.org.au/bulletins/ESB-2026.9740/] Cloud Software Group has issued a critical security bulletin warning customers of two serious vulnerabilities affecting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). Tracked as CVE-2026-19489 and CVE-2026-19490, the flaws could allow attackers to trigger denial-of-service conditions or bypass authentication entirely on unpatched appliances, putting enterprise remote access infrastructure at significant risk. Hackers Exploiting Unpatched GeoServer Zero-Day Date: 2026-08-14 Author: Security Week The security defect is described as an SQL injection that could allow attackers to achieve remote code execution. Threat actors started exploiting an unpatched zero-day vulnerability in GeoServer hours after it was publicly disclosed, attack surface management firm WatchTowr says. The security defect, described as an SQL injection issue that could be exploited to achieve remote code execution (RCE), was disclosed on Wednesday by a security researcher named q1uf3ng. According to the researcher’s post on X, the flaw affects GeoServer’s jsonArrayContains function, a filter expression for querying JSON array fields to check if they contain specific values. It can be used with PostGIS and Oracle JDBC data stores. Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects Date: 2026-08-17 Author: The Hacker News [Please see AUSCERT bulletin https://portal.auscert.org.au/bulletins/ESB-2026.9629/] GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. Hacker claims 3.6 million Azure account records stolen from major companies Date: 2026-08-17 Author: Bleeping Computer A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. Starting July 31st, multiple posts from someone using the alias “TheHatman” advertised data dumps from major organizations, including McDonald's, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels (IHG), and Kyndryl. In total, the threat actor claims to have 3.64 million data records, with the most recent breach posted on Sunday, containing an alleged 1.7 million employee records from McDonalds. CISA: Windows Task Host flaw now exploited by ransomware gangs Date: 2026-08-18 Author: Bleeping Computer The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. Task Host is a core Windows system component that allows DLL-based processes to run in the background and prevents data corruption by ensuring they close properly during shutdown. Tracked as CVE-2025-60710, this Windows privilege escalation security flaw was patched by Microsoft in November 2025 and stems from a link following weakness that affects Windows 11 and Windows Server 2025 devices. ESB-2026.9629 – GitLab Community & Enterprise Edition: CVSS (Max): 9.4 GitLab released versions which contain important bug and security fixes for GitLab Community Edition (CE) and Enterprise Edition (EE) ESB-2026.9641 – iOS 18.7.10 and iPadOS: CVSS (Max): 9.8 Multiple vulnerabilities affecting iOS and iPadOS have been addressed by Apple ASB-2026.0202 – Oracle E-Business Suite: CVSS (Max): 9.8 This Critical Security Patch Update contains 120 new security patches for Oracle E-Business Suite ESB-2026.9713 – Cisco Secure Workload Software: CVSS (Max): 10.0 Cisco has released software updates that address vulnerabilities that affect Cisco Secure Workload Software (SaaS) ESB-2026.9752 – Splunk Enterprise: CVSS (Max): 9.8 Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Splunk Enterprise versions Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Resources

Navigating the Quantum Horizon: Actionable Tools from AUSCERT

As quantum computing moves from research to operational reality, organisations need to address emerging risks, supply chain vulnerabilities, and evolving regulatory requirements. The AUSCERT Cyber Leaders Network Quantum Computing Working Group have developed some practical tools for organisations to evaluate their current exposure, engage vendors, prioritise investment, and build operational resilience. The Executive Briefing helps boards and executives understand quantum-related risks, regulatory obligations, and strategic planning considerations.  The Vendor Post-Quantum Cryptography (PQC) Questionnaire enables organisations to assess the quantum readiness of third-party suppliers and identify potential supply chain risks. The Cryptographic Bill of Materials (CBOM) provides a structured framework for inventorying and auditing internal cryptographic assets and risk. The tools are freely available for download: Executive Briefing – Quantum Computing Preparedness v1.0 (PDF) Vendor Post-Quantum Cryptography (PQC) Assessment Questionnaire v1.0 (PDF)  |  Word Version Cryptographic Bill of Materials (CBOM) Audit Template (Excel)   Mikhail Lopushanski (General Manager, Technology GRISC, Auto & General) unveiled these tools in his presentation at the AUSCERT2026 Conference in May 2026. The presentation recording is available below. Download a copy of Mikhail’s presentation slides here: AUSCERT CLN – Navigating the Quantum Horizon   These resources were developed by the Cyber Leaders Network’s Quantum Computing working group. The Cyber Leaders Network brings together cyber security professionals from across industries to collaborate, share best practices, and exchange insights on emerging challenges. Coordinated by AUSCERT, the Network provides a trusted forum for leaders to collectively strengthen Australia’s cyber resilience. All resources are shared under a Creative Commons Attribution 4.0 International License (CC BY 4.0), allowing you to share and adapt the material with appropriate credit to the AUSCERT Cyber Leaders Network.

Learn more

Week in review

AUSCERT Week in Review for 14th Aug 2026

Greetings, A routine attempt to secure a place in a popular gym class has highlighted a growing challenge in the age of artificial intelligence. In what is believed to be Australia's first known case of an autonomous AI-powered cyber attack, an AI assistant tasked with booking a gym session discovered and exploited a vulnerability in the gym’s online booking system without being instructed to do so. The incident involved an Australian technology professional who used an AI agent powered by Anthropic’s Claude model through the OpenClaw platform. After being asked to book a class, the AI found a way to bypass booking restrictions and reserve places weeks earlier than the system was designed to allow. More concerningly, when the user asked whether it could improve his position on a waiting list, the AI removed another member’s booking as part of what it described as testing its capabilities. It later admitted it could not restore that person's place. Experts say the case demonstrates a key risk associated with increasingly autonomous AI agents. Unlike traditional chatbots, these systems can independently plan and execute tasks across websites and software platforms. While designed to achieve a user's goal, they may choose methods the user neither expected nor authorised. Researchers refer to the challenge of ensuring AI systems act within human intentions and boundaries as the “alignment problem.” The incident follows recent reports of advanced AI models autonomously hacking systems during testing, raising concerns among cyber security professionals and policymakers. Legal experts also note that responsibility remains unclear when an AI agent causes harm, with questions lingering over whether liability rests with the user, software developer, AI provider, or the operator of the vulnerable system. For businesses and consumers alike, this situation serves as a reminder that while AI agents offer powerful productivity benefits, they also introduce new risks that organisations, regulators and technology providers are only beginning to understand. … Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE Date: 2026-08-11 Author: The Hacker News Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's affected-product list covers only those three on-premises editions, and SharePoint Online is not among them. Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack Date: 2026-08-11 Author: The Hacker News [AUSCERT has published security bulletins for these Microsoft updates] Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first. The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only one in this month's release Microsoft flags as under active exploitation. Exploitation depends on triggering a race condition in the driver. Microsoft has not publicly attributed the exploitation. Check Point Research says Lazarus used the zero-day in its Operation Dream Job campaign. SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code Date: 2026-08-12 Author: The Hacker News SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation. "SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation," according to a description of the flaw on CVE.org. Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data Date: 2026-08-08 Author: Security Week Varonis Threat Labs has disclosed a one-click vulnerability in Rovo, Atlassian’s enterprise AI assistant, that let a specially crafted link seed attacker-controlled instructions directly into a user’s live AI session. Dubbed RovoBlast, the flaw required no jailbreak and no permission bypass, relying on the fact that the assistant simply treated externally supplied parameters as trusted input. Foreign control of AI vendors a board-level risk, ASD says Date: 2026-08-07 Author: IT News Australian boards should treat the foreign ownership, control and influence of their artificial intelligence (AI) providers as a cyber risk in its own right, the Australian Signals Directorate advises. That is one of the four key action points in new guidance from the ASD, co-written with the Australian Institute of Company Directors (AICD), that asks boards to assess the risks of relying on AI providers. ESB-2026.9350 – Zoom: CVSS (Max): 8.3 Zoom patched a high-severity zero-click flaw (CVE-2026-53413) that could enable remote code execution on meeting participants’ devices. ESB-2026.9366 – Adobe Campaign Classic: CVSS (Max): 10.0 Adobe patched critical vulnerabilities in Campaign Classic that could allow arbitrary code execution, including two CVSS 10.0 flaws. ESB-2026.9378 – CTI-Transmute 1.5: CVSS (Max): 8.8 CTI-Transmute 1.5 adds 16 security fixes, a public API, and other improvements to MISP/STIX threat intelligence conversion. ESB-2026.9500 – Intel Chipset Firmware: CVSS (Max): 8.5 Intel addressed a high-severity CSME and SPS firmware flaw (CVE-2026-6727) that could allow local privilege escalation. ESB-2026.9519 – Palo Alto GlobalProtect App: CVSS (Max): 8.5 Palo Alto Networks fixed a medium-severity GlobalProtect flaw (CVE-2026-0299) that could allow local privilege escalation to SYSTEM/root. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 7th Aug 2026

Greetings, A major new software supply chain attack has highlighted the growing risks facing organisations that rely on open source code. Researchers have uncovered a self-propagating malware campaign, dubbed ChainDrop, which has compromised more than 1,300 packages in the Node Package Manager (npm) ecosystem, affecting packages that collectively receive around two billion downloads each month. The attack reportedly began when a threat actor gained access to the GitHub account of the maintainer behind several widely used caching libraries, including Keyv and Cacheable. From there, the malware spread through interconnected projects, ultimately impacting packages associated with a range of technology vendors and organisations. What makes ChainDrop particularly concerning is its ability to spread automatically. Malicious code was inserted into legitimate software packages and published through trusted GitHub Actions workflows, allowing the compromised releases to appear authentic. Once an affected package was installed, a hidden pre-installation script executed automatically, downloading additional components and launching an information-stealing payload. According to security researchers, the malware is designed to collect a wide range of sensitive information, including GitHub and npm access tokens, cloud credentials, Kubernetes secrets, database credentials, and keys for services such as AWS, Azure and Google Cloud. The stolen data is then encrypted and exfiltrated, while the malware searches for new opportunities to compromise additional repositories and packages. Security experts warn that any developer workstation or CI/CD environment that installed an affected package should be considered compromised. Recommended response measures include rebuilding impacted systems, rotating exposed credentials, reviewing repositories for unauthorised changes, and strengthening dependency management controls. As investigations continue, the number of affected packages may grow, reinforcing the importance of ongoing vigilance across the software supply chain. Attackers Exploit N-able Patch Bypass Flaw on RMM Servers Date: 2026-08-04 Author: Dark Reading N-able recently disclosed that a threat actor targeted its N-central product through a patch bypass vulnerability and used the flaw to gain access to customer environments. The company, which sells security and IT management tools to managed service providers (MSPs) and internal IT teams, disclosed active exploitation over the weekend. Rails patches critical Active Storage flaw with RCE potential Date: 2026-08-01 Author: Bleeping Computer [See AUSCERT bulletin https://portal.auscert.org.au/bulletins/ASB-2026.0171.2] A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). Rails is a popular open-source web application framework written in Ruby for building websites and web apps. It uses the built-in Rails component Active Storage for handling file uploads and attachments. Rails maintainers published an advisory about the CVE-2026-66066 flaw, which received a critical severity rating. Massive ChainDrop npm supply-chain attack infects hundreds of packages Date: 2026-08-04 Author: Bleeping Computer [See AUSCERT bulletin https://portal.auscert.org.au/bulletins/ASB-2026.0172] Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. Infected packages include very popular ones such as Keyv and Cacheable, flat-cache and file-entry-cache, all caching utilities from the same maintainer. The supply-chain attack started after the threat actor compromised the GitHub account of Keyv’s maintainer, and quickly spread to packages associated with major organizations such as Deliveroo, Ornikar, OneReach, Picsart, Qlik, and ServiceTitan. Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction Date: 2026-08-01 Author: The Hacker News [See AUSCERT bulletin https://portal.auscert.org.au/bulletins/ESB-2026.8857] Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in arbitrary code execution in the context of the current user without requiring any user interaction. The update also resolves another high-severity flaw (CVE-2026-48448, CVSS score: 8.6) stemming from SQL injection that could pave the way for arbitrary file reads. New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts Date: 2026-08-05 Author: Security Week The new attack methods, named ‘Pass-ta-key’ by Palo Alto Networks, focus on Google-synced passkeys. The security firm’s researchers showed how a threat actor could use the techniques to take over accounts without needing privilege escalation or user interaction. In a Pass-ta-key attack, malware already present on a Windows machine running Chrome can examine the browser’s local synchronization database to identify which online accounts the user has protected with passkeys, along with associated usernames and encrypted credential material. ASB-2026.0171.2 – UPDATE Ruby on Rails (Active Storage): CVSS (Max): 9.5 Ruby on Rails has released security updates to address a critical vulnerability in Active Storage that could allow an attacker to perform arbitrary file reads and potentially achieve remote code execution under vulnerable image processing configurations. ASB-2026.0172 – npm packages: CVSS (Max): None A large-scale npm supply chain attack, dubbed ChainDrop, compromised hundreds of widely used npm packages. ESB-2026.9044 – Adobe Campaign Classic: CVSS (Max): 10.0 This update addresses critical vulnerabilities that could result in arbitrary code execution and arbitrary file system read. ESB-2026.9115 – Cisco Catalyst SD-WAN: CVSS (Max): 9.9 Cisco has released software updates that address these vulnerabilities. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 31st July 2026

Greetings, Organisations using JetBrains TeamCity On-Premises are being urged to patch a newly disclosed critical security vulnerability that could allow attackers to bypass authentication and execute malicious commands on affected servers. The flaw, tracked as CVE-2026-63077, impacts all versions of TeamCity On-Premises and has been rated particularly severely because it enables remote code execution with the privileges of the TeamCity server process. TeamCity Cloud customers are not affected, as mitigations have already been implemented by JetBrains. TeamCity is widely used by development teams to automate software building, testing, and deployment processes. According to JetBrains, successful exploitation of the vulnerability could expose sensitive project data, system configurations, stored credentials, and potentially compromise software build pipelines and release artifacts. These risks make the issue especially significant for organisations that rely on TeamCity as a core component of their software delivery environment. While JetBrains stated there is currently no evidence of active exploitation, the warning carries added weight given TeamCity’s history as a target for cybercriminals, including ransomware operators and state-sponsored threat actors in 2023 and 2024. Past vulnerabilities in the platform have been rapidly exploited in real-world attacks, prompting experts to recommend swift remediation whenever critical flaws are disclosed. JetBrains has already addressed the issue in TeamCity versions 2025.11.7 and 2026.1.3 and strongly recommends upgrading as soon as possible. For customers unable to immediately move to the latest releases, the company has also provided a security patch plugin for supported versions dating back to TeamCity 2017.1. Additional security measures, including restricting access through VPNs and limiting exposure of internet-facing TeamCity services, are also recommended to reduce the risk of compromise. Critical VM Escape Vulnerability Patched in VMware ESXi Date: 2026-07-29 Author: Security Week [AUSCERT has informed the affected members via Critical MSINs] [AUSCERT has published security bulletin for this – https://portal.auscert.org.au/bulletins/ESB-2026.8797/] Broadcom published a new security advisory on Wednesday, informing VMware product users that patches are available for several vulnerabilities affecting ESXi, vCenter, Workstation, and Fusion. Three of the vulnerabilities have been assigned a ‘critical’ severity rating. One of them is CVE-2026-47876, an out-of-bounds write issue in ESXi’s VMXNET3 virtual network adapter. An attacker with local admin privileges on a VM with this adapter can exploit it to execute arbitrary code on the host. CVE-2026-47876 has been described by VMware as a VM escape. Cisco warns of FMC static credential flaw exploited in zero-day attacks Date: 2026-07-29 Author: Bleeping Computer [AUSCERT has published security bulletin for this – https://portal.auscert.org.au/bulletins/ESB-2026.8812/] Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. The vulnerability is caused by static credentials for a low-privilege account built into Cisco Secure FMC Software. Cisco says an unauthenticated, remote attacker can use these credentials to log in to an affected system and access sensitive data available to the account. Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Date: 2026-07-25 Author: The Hacker News Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update. Any authenticated user who can push to a project can run it. The attacker commits a crafted Jupyter notebook and opens its commit diff, which leaks a heap pointer. Enough of those and an automated probe can locate the libraries in memory. Two more notebooks then fire the payload. No administrator rights, no CI or runner access, no victim interaction, no access to anyone else's project. US, Australia Release OT Isolation Guidance for Critical Infrastructure Date: 2026-07-29 Author: Security Week The US cybersecurity agency CISA and Australia’s Cyber Security Centre (ACSC) have published joint guidance detailing how critical infrastructure (CI) organizations can isolate vital OT and supporting systems. Aimed at boosting cyber resilience, the CI Fortify – Advice for isolating vital systems guidance also includes details on how these systems can be operated in isolation for long periods, to ensure the continuity of critical services in case of disruption or crisis. The document is designed to help OT owners, operators, and cybersecurity teams improve their preparedness, response, and recovery. Origin Energy boss confirms almost a million Australians compromised by data breach Date: 2026-07-28 Author: Cyber Daily Aussie energy supplier Origin has said it has completed its initial investigations into a cyber security incident first disclosed on 22 July. “We have now completed the initial phase of our review into Origin’s customer data security incident,” Origin CEO Frank Calabria said in a 28 July statement. “At this point in time, we believe the information of approximately 900,000 current and former customers was accessed.” ESB-2026.8651 – macOS Sequoia 15.7.8: CVSS (Max): 9.1* Apple has released security updates for macOS Sequoia 15.7.8 to address multiple security vulnerabilities. Users are advised to install the update to help protect their systems. ESB-2026.8797 – VMware Products: CVSS (Max): 7.8 Broadcom has released security updates for VMware Aria Operations to address a high-severity local privilege escalation vulnerability. ESB-2026.8812 – Cisco Secure FMC Software: CVSS (Max): 5.3 Cisco has released a security update for Secure Firewall Management Center (FMC) to address a critical static credential vulnerability that has been exploited in zero-day attacks. ESB-2026.8839 – GitLab Community & Enterprise Edition: CVSS (Max): 8.5 GitLab has released GitLab 19.2.1 patch updates for Community and Enterprise Editions to address security vulnerabilities and bug fixes. ESB-2026.8857 – Adobe Campaign Classic: CVSS (Max): 10.0 Adobe has published security updates for Adobe Campaign addressing multiple vulnerabilities. Users are advised to apply the available updates to mitigate potential security risks. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 24th July 2026

Greetings, Origin Energy has confirmed that unauthorised access to customer information has occurred, marking what is believed to be the largest publicly known cyber incident to affect an Australian energy retailer. The company, which serves more than 4.8 million customers, announced it is still investigating the extent of the breach and determining how many may have been impacted. According to Origin, the compromised information may include customers’ names, addresses, dates of birth, phone numbers, and limited banking information such as the last four digits of a credit card or the last three digits of a bank account. The company has stressed that full banking and credit card details do not appear to have been exposed. Chief Executive Frank Calabria apologised to customers, acknowledging the trust placed in the company and assuring customers that securing systems and preventing further unauthorised access remains a top priority. Origin says it will contact affected customers directly once it has confirmed who was impacted. The breach came to light after a media outlet was contacted by an alleged hacker who provided a sample of customer records. Following notification of the incident, Origin alerted authorities and informed the Australian Securities Exchange. The incident adds to a growing list of major Australian cyber security breaches in recent years, following attacks on organisations including Optus, Medibank, and Qantas. Cyber security experts are urging Origin customers to remain vigilant for suspicious emails, text messages and phone calls, as criminals often leverage stolen personal information in follow-up scams. While some customers have recently experienced delays receiving energy bills, Origin says those issues are linked to July pricing changes and are not connected to the data breach investigation. Critical ServiceNow code execution flaw now exploited in attacks Date: 2026-07-20 Author: Bleeping Computer Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. Formerly known as the Now Platform, ServiceNow AI Platform is an enterprise-grade Platform-as-a-Service (PaaS) that helps businesses integrate AI into core enterprise workflows. Cybersecurity company Searchlight Cyber, which found this critical vulnerability and reported it on April 1st, says that it allows unauthenticated threat actors to escape the sandbox and execute code remotely within the ServiceNow platform in high-complexity attacks. WordPress Core "wp2shell" RCE flaws get public exploits, patch now Date: 2026-07-18 Author: Bleeping Computer [See AUSCERT Bulletin https://portal.auscert.org.au/bulletins/ESB-2026.8154] Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. The wp2shell attack consists of two flaws, tracked as CVE-2026-63030 and CVE-2026-60137, that can be chained together to achieve pre-authentication remote code execution against WordPress installs running versions 6.9.x and 7.0.x. The flaws were discovered by Adam Kues of Searchlight Cyber, which says an unauthenticated attacker can exploit them against a default WordPress installation. Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC Date: 2026-07-21 Author: The Hacker News A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network. Microsoft credited DEVCORE researcher "splitline" with discovering and reporting the flaw. Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Date: 2026-07-22 Author: Security Week [AUSCERT has published security bulletins for these Oracle updates] Oracle has patched more than 1,400 vulnerabilities with its July 2026 Critical Patch Update (CPU), with a vast majority of the flaws likely identified by artificial intelligence. According to Oracle, the latest quarterly CPU includes 1,449 security patches, addressing 1,434 unique CVEs across 334 products. CISA orders urgent action on actively exploited Langflow RCE flaw Date: 2026-07-22 Author: Bleeping Computer The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. Tracked as CVE-2026-0770, this critical security flaw allows unauthenticated threat actors to gain remote code execution as root in low-complexity attacks. ESB-2026.8410 – Mozilla Thunderbird: CVSS (Max): 10.0* A large number of vulnerabilities was patched in Mozilla Thunderbird, with the most severe being tracked as CVE-2026-16367 for a sandbox escape due to invalid pointer in the Disability Access APIs component. ESB-2026.8355 – Tenable Security Center: CVSS (Max): 9.9 Tenable Security Center has underlying third party libraries which were found to contain vulnerabilities. Updated versions are now available from the providers, which Tenable has implemented to address potential impacts of these identified vulnerabilities. ESB-2026.8317 – Atlassian Products: CVSS (Max): 10.0 83 high severity vulnerabilities and 18 critical severity third party vulnerabilities have been fixed in new versions of Atlassian products. Some of the patched vulnerabilities include remote code execution, denial of service and improper authorization. ASB-2026.0144 – Oracle Communications: CVSS (Max): 9.8 Oracle has released a critical patch update containing 168 new security patches or Oracle Communications. Many of these vulnerabilities can be remotely exploitable without authentication over a network. It has also been exploited in the CISA KEV. ESB-2026.8151 – roundcube: CVSS (Max): 10.0 Multiple vulnerabilities in roundcube such as account takeover, cross-site scripting, SSRF bypass, information disclosure and denial of service have been fixed in a new version release. Roundcube strongly recommends patching with the latest version. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 17th July 2026

Greetings, The Office of the Australian Information Commissioner (OAIC) has concluded its preliminary inquiries into the 2025 Qantas data breach, determining that there is currently insufficient evidence to warrant a formal regulatory investigation or enforcement action against the airline. The decision follows an almost year-long review of the incident, which affected approximately 5.12 million Australians and was one of the country's most significant privacy breaches in recent years. The breach occurred when a threat actor successfully carried out a phone-based social engineering, or “vishing”, attack against an employee at an overseas third-party contact centre used by Qantas. The attacker convinced the employee they were speaking with legitimate IT support and ultimately gained access to customer information through a customer relationship management platform. Qantas detected unusual activity within days, contained the incident, revoked access to the compromised account and began its incident response process. According to the OAIC, approximately 5.67 million customer records were affected, including names, email addresses, phone numbers and Qantas Frequent Flyer details. Around 1.7 million records also contained additional information such as addresses, dates of birth, and gender. Importantly, the compromised system did not store credit card details, financial information, passwords, PINs or passport details. After examining Qantas’ privacy governance, security controls, staff training, third-party oversight arrangements and incident response processes, the OAIC concluded there was no indication the airline had failed to take reasonable steps to protect personal information or ensure compliance with privacy obligations. The regulator noted that Qantas had implemented security audits, mandatory cyber-awareness training, contractual privacy requirements for service providers and a prompt breach response program. While the OAIC has closed its preliminary inquiries, it emphasised that the decision is not an endorsement of Qantas’ practices and that future investigations remain possible if new information emerges. The report highlights the growing threat of sophisticated social engineering attacks and reinforces the importance of strong cyber security controls, employee awareness training, and rapid incident response capabilities. SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now Date: 2026-07-14 Author: Bleeping Computer [AUSCERT has contacted members about this vulnerability where possible] SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. CVE-2026-15409 is a critical (CVSS 10.0) server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface that allows a remote, unauthenticated attacker to force an appliance to make requests to unintended locations. CVE-2026-15410 is a high-severity (CVSS 7.2) post-authentication code injection flaw in the SMA1000 Appliance Management Console that could allow a remote authenticated administrator to execute arbitrary operating system commands. CISA warns admins to patch actively exploited SharePoint flaws Date: 2026-07-15 Author: Bleeping Computer The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. These security flaws (tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affect all supported self-hosted SharePoint Server versions, including SharePoint Server Subscription Edition (the latest on-premises version, which uses a "continuous update" model). Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting Date: 2026-07-14 Author: ASD ACSC Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory (CSA) builds on FBI’s Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure Public Service Announcement of the decade-plus FSB Center 16 cyber activity by providing additional tactics, techniques, and procedures (TTPs) to enable defenders to more fully understand and counter the threat. SAP warns of critical flaws in NetWeaver and Commerce Cloud Date: 2026-07-14 Author: Bleeping Computer SAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. The first critical issue patched this month is a memory corruption security issue (tracked as CVE-2026-44747) stemming from an out-of-bounds write weakness in the NetWeaver Application Server ABAP (AS ABAP), the runtime environment, application server, and development platform for core SAP enterprise software. "SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability," SAP says. "This has high impact on confidentiality, integrity, and availability of the application." RabbitMQ Vulnerability Threatens Enterprise Systems Date: 2026-07-14 Author: Security Week A vulnerability in RabbitMQ could allow attackers to obtain the broker’s confidential OAuth secret, potentially posing a serious threat to enterprises, according to cybersecurity firm Miggo. RabbitMQ is a popular open source message broker that routes, buffers, and distributes messages, enabling asynchronous communication between applications. Tracked as CVE-2026-5721 (CVSS score of 8.7), the security defect impacts an open management endpoint that returns the OAuth secret to anyone, without authentication. ESB-2026.7869 – VMware Avi Load Balancer: CVSS (Max): 9.8 Broadcom has released updates for VMware Avi Load Balancer to fix seven vulnerabilities, including a critical authentication bypass flaw (CVE-2026-47865). ESB-2026.7892 – Zoom: CVSS (Max): 9.8 Zoom has released updates to address a critical account takeover vulnerability (CVE-2026-53412) affecting Windows-based Zoom products. ESB-2026.7904 – Adobe ColdFusion: CVSS (Max): 9.9 Adobe has released security updates for ColdFusion to address multiple critical vulnerabilities, including arbitrary code execution and server-side request forgery (SSRF). ESB-2026.8009 – Splunk Enterprise: CVSS (Max): 9.8 Splunk has released security updates for Splunk Enterprise to address multiple vulnerabilities affecting Windows and Unix/Linux platforms. ASB-2026.0129 – Microsoft ESU: CVSS (Max): 9.9 Microsoft has released its July 2026 Patch Tuesday update, addressing 335 vulnerabilities across Windows, Exchange Server, and other products, including multiple critical remote code execution and privilege escalation flaws. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more