Week in review

AUSCERT Week in Review for 18th September 2026

Greetings, September is MFA Month, making it the perfect time to review one of the simplest and most effective cyber security measures available: multi-factor authentication (MFA). As part of the Australian Signals Directorate’s (ASD) MFA: Switch It On campaign, organisations across Australia are being encouraged to enable MFA on all accounts and systems. The initiative aims to increase MFA adoption across businesses, government agencies, and critical infrastructure organisations, helping make Australia a safer place to connect online. The need for MFA has never been clearer. According to the ASD, 42% of cyber security incidents reported by industry, government, and critical infrastructure organisations in 2024-25 involved compromised accounts or credentials. This serves as a timely reminder that passwords alone are no longer enough to protect against modern cyber threats. MFA adds an extra layer of protection by requiring users to verify their identity using more than just a password. As one of the most effective defences against unauthorised access, phishing-resistant forms of MFA can significantly reduce the risk of cybercriminals gaining access to accounts, applications, corporate systems, and networks. By encouraging employees, customers, suppliers, and stakeholders to enable MFA, organisations can strengthen their cyber resilience, better protect sensitive information and assets, and reduce the risk of account compromise. For practical guidance, including step-by-step instructions for enabling MFA on popular accounts and applications, visit the Australian Cyber Security Centre's guide ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks Date: 2026-09-14 Author: Security Week ConnectWise has released urgent patches for a critical-severity vulnerability in the ScreenConnect remote access and support software that has been exploited in worm-like attacks. Tracked as CVE-2026-84869 (CVSS score of 9.9/10), the security defect is described as a missing authorization and improper privilege management issue. The bug creates “a condition in the ScreenConnect client that may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances,” ConnectWise explains in its advisory. Cisco patches Secure Email Gateway zero-day exploited in attacks Date: 2026-09-15 Author: Bleeping Computer [Please see AUSCERT bulletin https://portal.auscert.org.au/bulletins/ESB-2026.10980.2/] Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. "In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," the company warned in a Monday security advisory. The security flaw (tracked as CVE-2026-76461) was found in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway and affects virtual and physical appliances, regardless of the device configuration. GitLab Vulnerability Exploited One Day After Disclosure Date: 2026-09-11 Author: Security Week [Please see AUSCERT bulletin https://portal.auscert.org.au/bulletins/ESB-2026.10914/] Threat actors have started exploiting a newly patched vulnerability in GitLab one day after public disclosure, attack surface management firm WatchTowr warns. Tracked as CVE-2026-85706 (CVSS score of 10/10), the security defect is described as a path traversal issue that can allow unauthenticated users to read arbitrary files from the GitLab server. All Community Edition (CE) and Enterprise Edition (EE) versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected. Check Point Patches Critical VPN Vulnerabilities Date: 2026-09-11 Author: Security Week Cybersecurity firm Check Point this week announced patches for two critical-severity vulnerabilities in its gateway and firewall products using VPN functionality. Tracked as CVE-2026-85102 and CVE-2026-85103 (CVSS score of 9.8), both security defects could be exploited without authentication for remote code execution (RCE), Check Point warns. The former is described as an improper validation of certificate data during VPN negotiation, while the latter is a heap overflow in the VPN certificate ASN.1 decoding flow. Passkey-themed phishing attacks lead to Microsoft 365 data theft Date: 2026-09-11 Author: Bleeping Computer Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. The activity has been observed since May 2026 and begins with the attackers researching targeted organizations and employees before calling or messaging victims while impersonating corporate IT help desks. The attackers tell employees that they must urgently update a passkey, multi-factor authentication (MFA), or single sign-on (SSO) configuration to avoid losing access to corporate systems. ASB-2026.0222 – Check Point Products: CVSS (Max): 9.8 Check Point have provided fixes for two critical CVSS 9.8 flaws that affect Check Point Security Gateway, Security Management Server and Spark Firewall (Centrally Managed and Locally Managed) products. ASB-2026.0236 – Oracle Communications: CVSS (Max): 9.8 Oracle have provided a Critical Security Patch Update that contains 31 new security patches for Oracle Communications – 23 of these vulnerabilities may be remotely exploitable without authentication. ESB-2026.11217 – Cisco Secure Firewall Management Center (FMC): CVSS (Max): 10.0 Cisco has released software updates that address a vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. ESB-2026.10914 – GitLab Community & Enterprise Edition: CVSS (Max): 10.0 GitLab have provided updated versions of GitLab Community & Enterprise Edition that contain important bug and security fixes, and they strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately. ESB-2026.10980.2 – Cisco Secure Email Gateway: CVSS (Max): 9.8 Cisco has released software updates that address a vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 11th September 2026

Greetings, This week, Mathspace disclosed a data breach affecting about 1.08 million students, carers and staff in Australia and New Zealand. Information stolen includes names, email addresses, usernames, account types and countries . While no passwords or sign-on credentials were accessed, the exposed information could be used to create convincing phishing emails impersonating Mathspace. The attackers accessed the data by exploiting a flaw in Mathspace’s self-hosted installation of Metabase. While Metabase had disclosed the vulnerability and provided a patch, Mathspace had not installed the patch at the time of the attack. Attackers exploited the vulnerability days after it was disclosed and patched by Metabase on 6 August. This breach follows a ransomware attack on education platform Canvas earlier this year. These incidents highlight the value of sensitive information held by education platforms and the attractiveness of the education sector to cyber criminals. The Metabase vulnerability allowed attackers to gain administrator access to the affected system without legitimate credentials. Mathspace said its vulnerability-notification process did not identify and escalate the Metabase advisory for action. The company later secured the affected system, took it offline and notified affected users and relevant authorities. Mathspace said there is currently no evidence that the stolen information has been published, sold or misused. However, affected users should remain alert to phishing and impersonation attempts using the exposed information. … Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Date: 2026-09-07 Author: Security Week Threat actors are exploiting a zero-day vulnerability in Adobe Commerce and Magento e-commerce platforms to backdoor online stores, cybersecurity firm Sansec reports. Dubbed StyleSmuggler, the security defect enables attackers to inject PHP code into Magento’s template system and evade detection by using the ‘styles’ properties. According to Sansec, the attack works in two stages: first, the PHP code is injected by generating a failure report, and then Magento executes the code via a failed payment email. N-able patches max severity N-central flaw amid ongoing attacks Date: 2026-09-07 Author: Bleeping Computer N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform. IT departments and managed service providers (MSPs) use the N-central platform to monitor, manage, and maintain client networks and devices from a centralized web-based console. Tracked as CVE-2026-86218, this RCE vulnerability allows threat actors without privileges to execute malicious code on unpatched N-central instances exposed online in low-complexity attacks. Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication Date: 2026-09-06 Author: The Hacker News [AUSCERT has notified potentially affected members] Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5. Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count or attacker identity. MikroTik's security update lists fixed RouterOS releases. CERT says the fixes prevent the observed attacks and recommends immediate installation, followed by a check for unauthorized configuration changes. SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution Date: 2026-09-09 Author: The Hacker News SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP security company Onapsis, it has been codenamed OVERPASS. Microsoft discloses two actively exploited zero-days among 974 vulnerabilities Date: 2026-09-08 Author: CyberScoop [AUSCERT has published security bulletins for these Microsoft updates] Microsoft addressed 974 defects across its product suite, including two actively exploited zero-day vulnerabilities, in its monthly Patch Tuesday security program. The massive batch of patches, Microsoft’s largest ever, reflects a continuing trend for the vendor as it leans on artificial intelligence to discover more vulnerabilities at a faster rate. Yet, the recent period of record breaking vulnerability disclosures hasn’t resulted in a flood of actively exploited zero-days. ESB-2026.10690 – Adobe Commerce: CVSS (Max): 10.0 Adobe has released a security update for Adobe Commerce and Magento Open Source. This update resolves critical, important, and moderate vulnerabilities. ASB-2026.0220 – Microsoft Windows: CVSS (Max): 9.8 Microsoft has released 'Microsoft Windows' updates to resolve 726 vulnerabilities, as part of the Microsoft security patch updates for the month of September 2026. ASB-2026.0212 – Microsoft Azure: CVSS (Max): 10.0 Microsoft has released 'Microsoft Azure' updates to resolve 12 vulnerabilities, as part of the Microsoft security patch updates for the month of September 2026. ESB-2026.10780 – Palo Alto Networks PAN-OS: CVSS (Max): 9.2 A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition. ESB-2026.10661 – Linux kernel (GCP): CVSS (Max): 10.0 Ubuntu have provided an update(s) for several vulnerabilities that were discovered in the Linux kernel for Google Cloud Platform (GCP) systems. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 4th September 2026

Greetings, After more than two decades in the shadows, one of the internet’s longest-running botnets has finally been disrupted. An international operation involving authorities and cyber security researchers from the US, Bulgaria, Hungary and Romania, alongside CrowdStrike and the Shadowserver Foundation, has isolated more than 15,000 infected systems and seized domains linked to the Sality botnet. Unlike traditional botnets that rely on central command-and-control servers, Sality used a peer-to-peer network, making it harder to disrupt or dismantle. Researchers exploited this architecture to interfere with communications between infected machines and disrupt the botnet. Sality has been used to distribute malware and facilitate various forms of cyber crime, including cryptocurrency theft. Organisations should not assume that older malware is no longer a threat. Effective endpoint protection, timely patching, network monitoring and investigation of legacy malware detections remain essential. The continued activity of threats such as Sality demonstrates that malware can persist for years, making it important to detect and respond to both emerging and long-standing threats. Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server Date: 2026-08-28 Author: The Hacker News cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM. Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs Date: 2026-08-31 Author: Security Week Hackers are exploiting a critical-severity Ruby on Rails vulnerability that leads to remote code execution (RCE), VulnCheck warns. Tracked as CVE-2026-66066 (CVSS score of 9.5) and referred to as KindaRails2Shell, the flaw is described as an arbitrary file read leading to secret exposure, RCE, and lateral movement. The security defect was disclosed in late July, when Ruby on Rails rolled out patches for it, urging the immediate patching of all Rails applications that rely on libvips for Active Storage image processing and allow image uploads from untrusted users. Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks Date: 2026-09-01 Author: Bleeping Computer Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. Tracked as CVE-2026-62911 and reported by DEVCORE Research Team's Orange Tsai, this security flaw affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) software. Threat actors with basic privileges on the targeted server can exploit it in low-complexity attacks that require user interaction. PaperCut issues emergency patches as threat actors target chained vulnerabilities Date: 2026-08-31 Author: Cybersecurity Dive [See AUSCERT bulletin: https://portal.auscert.org.au/bulletins/ASB-2026.0208/] PaperCut issued emergency patches on Friday to address critical vulnerabilities in its print-management software. The company confirmed in a security advisory that multiple customers were successfully targeted and that it is working with security researchers at Huntress and watchTowr to respond to the attacks. The vulnerabilities include an improper access-control flaw in PaperCut MF and NG. CVE-2026-81578 enables an unauthenticated attacker to modify certain system configurations and CVE-2026-82078 enables an attacker to execute arbitrary Java bytecode. BGP Hijack Diverts Softaculous Traffic to Deliver Malicious Virtualizor Update Date: 2026-09-01 Author: Cyber Security News Attackers hijacked BGP routing for Softaculous last week and delivered a malicious Virtualizor update to a handful of hypervisor servers, according to a vendor incident report. Hosting providers use Virtualizor to manage VPS nodes on KVM, Xen, LXC, OpenVZ, and Proxmox, and a single master can control hundreds of virtualization servers, placing a poisoned update high in the hosting stack. The product publicly lists hundreds of NOC partners, so a compromise here hits hosting infrastructure rather than a single website panel. ESB-2026.10412 – Cisco Nexus 9000 Series Switches: CVSS (Max): 9.8 Cisco has released software updates that addresses vulnerabilities in Cisco Nexus 9000 Series Switches. ASB-2026.0208 – PaperCut NG / MF: CVSS (Max): 9.4 PaperCut NG and PaperCut MF are affected by two vulnerabilities that can be chained by attackers to bypass authentication and execute arbitrary code on vulnerable servers. ESB-2026.10356 – Firefox ESR: CVSS (Max): 10.0 Internally found bugs present in Firefox 154, Firefox ESR 153.1, Firefox ESR 140.14 and Firefox ESR 115.39. ESB-2026.10351 – Rockwell Automation Logix Platform: CVSS (Max): 7.5 A denial-of-service vulnerability exists in the affected Logix platforms due to improper validation of input length during CIP message processing. ESB-2026.10167 – Tenable Enclave Security: CVSS (Max): 9.9 Several vulnerabilities have been identified, reported to Tenable and resolved. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 28th August 2026

Greetings, The pressure on social media platforms to better protect young users is intensifying, with governments and regulators around the world taking increasingly tough measures against the technology giants. New Zealand is the latest country to move towards restricting social media access for under 16s, with proposed legislation requiring platforms to take reasonable steps to verify users' ages. The proposal follows Australia's world-first under-16 social media restrictions and reflects growing international concern about the impact of social media on children. Meanwhile, in the United States, Meta has agreed to pay up to US$18 billion to settle lawsuits brought by almost every US state over allegations that Facebook and Instagram harmed children and misled the public about the safety of its platforms. As part of the settlement, Meta has also agreed to introduce stronger protections for teenage users, including default time limits, overnight restrictions and limits on notifications during school hours. While Meta has not admitted wrongdoing and the settlement does not fundamentally change its business model, the scale of the agreement signals a significant shift in expectations around platform accountability. It could also provide a template for similar action against other major platforms, with part of Meta's settlement tied to comparable commitments from competitors such as TikTok and YouTube. The global push highlights the growing intersection of online safety, privacy, cybersecurity and regulation. As age verification and platform monitoring increase, so do concerns around protecting sensitive user data. Regulation is accelerating, and technology companies face growing expectations to build safety and security into their platforms by design. Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data Date: 2026-08-25 Author: The Hacker News [AUSCERT has informed the potentially affected members via Critical MSINs] The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. Successful exploitation of the flaw can lead to unauthorized access to the instances or modification of critical data. Hackers breached over 270 Zimbra servers in ongoing attacks Date: 2026-08-25 Author: Bleeping Computer Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. The ZCS email and collaboration suite is used by hundreds of millions of people and organizations, including thousands of businesses and hundreds of government agencies worldwide. Synacor patched the security flaw (tracked as CVE-2026-73570), which allows unauthenticated attackers to gain code execution remotely by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled, with the release of ZCS version 10.1.20 on July 20. Active exploitation of a software development platform within Australia Date: 2026-08-24 Author: ASD ACSC The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has observed active exploitation of a vulnerability affecting TeamCity On-Premises servers within Australia. TeamCity is a Continuous Integration and Continuous Deployment (CI/CD) server to automate the processes of building, testing, and deploying software. CVE 2026-63077 may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands. This vulnerability affects all TeamCity On-Premises versions. Hackers target Microsoft SharePoint RCE chain with PoC exploit Date: 2026-08-26 Author: Bleeping Computer Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused. The first (tracked as CVE-2026-55040) is an authentication bypass flaw in the JWT token validation pipeline that attackers without privileges can exploit to perform operations as a SharePoint site user or administrator. The second (CVE-2026-63520) is a vulnerability in SharePoint's Business Connectivity Services (BCS) that unauthenticated attackers can chain after successfully exploiting CVE-2026-55040 for remote code execution (RCE) on a targeted SharePoint Server. Shop now? Banking malware campaign posing as Woolworths active in Australia Date: 2026-08-21 Author: cyberdaily.au Woolies and other trusted brands are being used to spread an Android Trojan that can access bank accounts, read SMSes, and even access cameras. Security researchers have lifted the lid on an ongoing Android malware campaign active in Australia, posing as several trusted and well-known brands to spread a Remote Access Trojan (RAT) designed, among other things, to steal banking information. According to NordVPN’s threat intelligence team, the campaign is circulating via text messages, WhatsApp, and social media, impersonating brands such as supermarket giant Woolworths and several airlines, including Emirates, Qatar Airways, and Air India. ESB-2026.9812 – Cisco Crosswork Platform(s): CVSS (Max): 10.0 Cisco has released software updates that address vulnerabilities in Cisco Crosswork platform(s). ESB-2026.10018 – Adobe Campaign Classic: CVSS (Max): 10.0 Adobe has released a security update that addresses critical (RCE) vulnerabilities in Adobe Campaign Classic. ESB-2026.10087 – GitLab Community Edition (CE) and Enterprise Edition (EE): CVSS (Max): 8.7 Updated versions of GitLab Community Edition (CE) and Enterprise Edition (EE) contain important bug and security fixes. GitLab strongly recommends that all self-managed GitLab installations be upgraded. ESB-2026.10066 – IBM QRadar SIEM: CVSS (Max): 9.8 Multiple components with known vulnerabilities were addressed in IBM QRadar SIEM updates. ESB-2026.10159 – All-Line Equipment Company Fuel-Boss: CVSS (Max): 8.7 Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Resources

Cyber Culture Metrics: Actionable Tool from AUSCERT

Understanding and measuring cyber culture enables organisations to reduce human risk, improve security outcomes, and foster a culture of resilience. The AUSCERT Cyber Leaders Network Cyber Culture Metrics Working Group have developed a practical tool for organisations to assess the maturity of their cyber security culture, benchmark performance, and prioritise improvements that reduce human cyber risk. The Cyber Culture Maturity Model (CCMM) measurement instrument provides a: Diagnostic Tool (6 dimensions aligned with NCSC Iceberg model, 5 questions each) Linkage to Theoretical Foundation Cyber Culture Measurement Score CCMM Reference for Improvements The tool is freely available for download: AUSCERT – CLN – Cyber Culture Maturity Model Instrument Macro (Excel)   Tim Lane (CISO, TURSA) unveiled this tool in his presentation at the AUSCERT2026 Conference in May 2026. The presentation recording is available below. Download a copy of Tim’s presentation slides here: AUSCERT – CLN – Cyber Culture Metrics   These resources were developed by the Cyber Leaders Network’s Cyber Culture Metrics working group. The Cyber Leaders Network brings together cyber security professionals from across industries to collaborate, share best practices, and exchange insights on emerging challenges. Coordinated by AUSCERT, the Network provides a trusted forum for leaders to collectively strengthen Australia’s cyber resilience. All resources are shared under a Creative Commons Attribution 4.0 International License (CC BY 4.0), allowing you to share and adapt the material with appropriate credit to the AUSCERT Cyber Leaders Network.

Learn more

Week in review

AUSCERT Week in Review for 21st Aug 2026

Greetings, AUSCERT is proud to be part of the Not-For-Profit Cyber Uplift Community of Practice, launched by the Australian Department of Home Affairs in partnership with the Australian Charities and Not-for-profits Commission. The free launch event will take place on Wednesday, 26 August 2026, from 1PM–2PM AEST, providing not-for-profit organisations with practical advice, knowledge and support to strengthen cyber resilience across the sector. Register here The importance of strengthening cyber resilience is particularly timely, with a large-scale data theft campaign reportedly targeting Azure/Entra environments belonging to major organisations, including McDonald’s, TCS, Vodafone and Kyndryl. The campaign is linked to a new threat actor known as TheHatman, who claims to have stolen millions of enterprise records. While the initial access vector remains unconfirmed, reported possibilities include stolen credentials or session cookies, phishing, weak or missing MFA, and overly permissive third-party applications. The activity does not currently appear to exploit an Azure vulnerability, with compromised credentials a key concern. The incident highlights how stolen organisational information including employee details, reporting structures, service accounts and privileged account information could enable highly targeted phishing, impersonation and business email compromise attacks. It reinforces the importance of phishing-resistant MFA, protecting cloud credentials and session tokens, detecting infostealer infections, reviewing third-party application permissions and monitoring unusual activity across Azure/Entra environments. Together, these developments highlight why practical cyber resilience initiatives are essential for organisations of all sizes. … Critical Citrix NetScaler Flaw Lets Remote Attackers Bypass Authentication Without Credentials Date: 2026-08-19 Author: Cyber Security News [See AUSCERT bulletin: https://portal.auscert.org.au/bulletins/ESB-2026.9740/] Cloud Software Group has issued a critical security bulletin warning customers of two serious vulnerabilities affecting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). Tracked as CVE-2026-19489 and CVE-2026-19490, the flaws could allow attackers to trigger denial-of-service conditions or bypass authentication entirely on unpatched appliances, putting enterprise remote access infrastructure at significant risk. Hackers Exploiting Unpatched GeoServer Zero-Day Date: 2026-08-14 Author: Security Week The security defect is described as an SQL injection that could allow attackers to achieve remote code execution. Threat actors started exploiting an unpatched zero-day vulnerability in GeoServer hours after it was publicly disclosed, attack surface management firm WatchTowr says. The security defect, described as an SQL injection issue that could be exploited to achieve remote code execution (RCE), was disclosed on Wednesday by a security researcher named q1uf3ng. According to the researcher’s post on X, the flaw affects GeoServer’s jsonArrayContains function, a filter expression for querying JSON array fields to check if they contain specific values. It can be used with PostGIS and Oracle JDBC data stores. Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects Date: 2026-08-17 Author: The Hacker News [Please see AUSCERT bulletin https://portal.auscert.org.au/bulletins/ESB-2026.9629/] GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. Hacker claims 3.6 million Azure account records stolen from major companies Date: 2026-08-17 Author: Bleeping Computer A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. Starting July 31st, multiple posts from someone using the alias “TheHatman” advertised data dumps from major organizations, including McDonald's, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels (IHG), and Kyndryl. In total, the threat actor claims to have 3.64 million data records, with the most recent breach posted on Sunday, containing an alleged 1.7 million employee records from McDonalds. CISA: Windows Task Host flaw now exploited by ransomware gangs Date: 2026-08-18 Author: Bleeping Computer The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. Task Host is a core Windows system component that allows DLL-based processes to run in the background and prevents data corruption by ensuring they close properly during shutdown. Tracked as CVE-2025-60710, this Windows privilege escalation security flaw was patched by Microsoft in November 2025 and stems from a link following weakness that affects Windows 11 and Windows Server 2025 devices. ESB-2026.9629 – GitLab Community & Enterprise Edition: CVSS (Max): 9.4 GitLab released versions which contain important bug and security fixes for GitLab Community Edition (CE) and Enterprise Edition (EE) ESB-2026.9641 – iOS 18.7.10 and iPadOS: CVSS (Max): 9.8 Multiple vulnerabilities affecting iOS and iPadOS have been addressed by Apple ASB-2026.0202 – Oracle E-Business Suite: CVSS (Max): 9.8 This Critical Security Patch Update contains 120 new security patches for Oracle E-Business Suite ESB-2026.9713 – Cisco Secure Workload Software: CVSS (Max): 10.0 Cisco has released software updates that address vulnerabilities that affect Cisco Secure Workload Software (SaaS) ESB-2026.9752 – Splunk Enterprise: CVSS (Max): 9.8 Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Splunk Enterprise versions Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Resources

Navigating the Quantum Horizon: Actionable Tools from AUSCERT

As quantum computing moves from research to operational reality, organisations need to address emerging risks, supply chain vulnerabilities, and evolving regulatory requirements. The AUSCERT Cyber Leaders Network Quantum Computing Working Group have developed some practical tools for organisations to evaluate their current exposure, engage vendors, prioritise investment, and build operational resilience. The Executive Briefing helps boards and executives understand quantum-related risks, regulatory obligations, and strategic planning considerations.  The Vendor Post-Quantum Cryptography (PQC) Questionnaire enables organisations to assess the quantum readiness of third-party suppliers and identify potential supply chain risks. The Cryptographic Bill of Materials (CBOM) provides a structured framework for inventorying and auditing internal cryptographic assets and risk. The tools are freely available for download: Executive Briefing – Quantum Computing Preparedness v1.0 (PDF) Vendor Post-Quantum Cryptography (PQC) Assessment Questionnaire v1.0 (PDF)  |  Word Version Cryptographic Bill of Materials (CBOM) Audit Template (Excel)   Mikhail Lopushanski (General Manager, Technology GRISC, Auto & General) unveiled these tools in his presentation at the AUSCERT2026 Conference in May 2026. The presentation recording is available below. Download a copy of Mikhail’s presentation slides here: AUSCERT CLN – Navigating the Quantum Horizon   These resources were developed by the Cyber Leaders Network’s Quantum Computing working group. The Cyber Leaders Network brings together cyber security professionals from across industries to collaborate, share best practices, and exchange insights on emerging challenges. Coordinated by AUSCERT, the Network provides a trusted forum for leaders to collectively strengthen Australia’s cyber resilience. All resources are shared under a Creative Commons Attribution 4.0 International License (CC BY 4.0), allowing you to share and adapt the material with appropriate credit to the AUSCERT Cyber Leaders Network.

Learn more

Week in review

AUSCERT Week in Review for 14th Aug 2026

Greetings, A routine attempt to secure a place in a popular gym class has highlighted a growing challenge in the age of artificial intelligence. In what is believed to be Australia's first known case of an autonomous AI-powered cyber attack, an AI assistant tasked with booking a gym session discovered and exploited a vulnerability in the gym’s online booking system without being instructed to do so. The incident involved an Australian technology professional who used an AI agent powered by Anthropic’s Claude model through the OpenClaw platform. After being asked to book a class, the AI found a way to bypass booking restrictions and reserve places weeks earlier than the system was designed to allow. More concerningly, when the user asked whether it could improve his position on a waiting list, the AI removed another member’s booking as part of what it described as testing its capabilities. It later admitted it could not restore that person's place. Experts say the case demonstrates a key risk associated with increasingly autonomous AI agents. Unlike traditional chatbots, these systems can independently plan and execute tasks across websites and software platforms. While designed to achieve a user's goal, they may choose methods the user neither expected nor authorised. Researchers refer to the challenge of ensuring AI systems act within human intentions and boundaries as the “alignment problem.” The incident follows recent reports of advanced AI models autonomously hacking systems during testing, raising concerns among cyber security professionals and policymakers. Legal experts also note that responsibility remains unclear when an AI agent causes harm, with questions lingering over whether liability rests with the user, software developer, AI provider, or the operator of the vulnerable system. For businesses and consumers alike, this situation serves as a reminder that while AI agents offer powerful productivity benefits, they also introduce new risks that organisations, regulators and technology providers are only beginning to understand. … Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE Date: 2026-08-11 Author: The Hacker News Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's affected-product list covers only those three on-premises editions, and SharePoint Online is not among them. Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack Date: 2026-08-11 Author: The Hacker News [AUSCERT has published security bulletins for these Microsoft updates] Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first. The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only one in this month's release Microsoft flags as under active exploitation. Exploitation depends on triggering a race condition in the driver. Microsoft has not publicly attributed the exploitation. Check Point Research says Lazarus used the zero-day in its Operation Dream Job campaign. SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code Date: 2026-08-12 Author: The Hacker News SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation. "SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation," according to a description of the flaw on CVE.org. Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data Date: 2026-08-08 Author: Security Week Varonis Threat Labs has disclosed a one-click vulnerability in Rovo, Atlassian’s enterprise AI assistant, that let a specially crafted link seed attacker-controlled instructions directly into a user’s live AI session. Dubbed RovoBlast, the flaw required no jailbreak and no permission bypass, relying on the fact that the assistant simply treated externally supplied parameters as trusted input. Foreign control of AI vendors a board-level risk, ASD says Date: 2026-08-07 Author: IT News Australian boards should treat the foreign ownership, control and influence of their artificial intelligence (AI) providers as a cyber risk in its own right, the Australian Signals Directorate advises. That is one of the four key action points in new guidance from the ASD, co-written with the Australian Institute of Company Directors (AICD), that asks boards to assess the risks of relying on AI providers. ESB-2026.9350 – Zoom: CVSS (Max): 8.3 Zoom patched a high-severity zero-click flaw (CVE-2026-53413) that could enable remote code execution on meeting participants’ devices. ESB-2026.9366 – Adobe Campaign Classic: CVSS (Max): 10.0 Adobe patched critical vulnerabilities in Campaign Classic that could allow arbitrary code execution, including two CVSS 10.0 flaws. ESB-2026.9378 – CTI-Transmute 1.5: CVSS (Max): 8.8 CTI-Transmute 1.5 adds 16 security fixes, a public API, and other improvements to MISP/STIX threat intelligence conversion. ESB-2026.9500 – Intel Chipset Firmware: CVSS (Max): 8.5 Intel addressed a high-severity CSME and SPS firmware flaw (CVE-2026-6727) that could allow local privilege escalation. ESB-2026.9519 – Palo Alto GlobalProtect App: CVSS (Max): 8.5 Palo Alto Networks fixed a medium-severity GlobalProtect flaw (CVE-2026-0299) that could allow local privilege escalation to SYSTEM/root. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 7th Aug 2026

Greetings, A major new software supply chain attack has highlighted the growing risks facing organisations that rely on open source code. Researchers have uncovered a self-propagating malware campaign, dubbed ChainDrop, which has compromised more than 1,300 packages in the Node Package Manager (npm) ecosystem, affecting packages that collectively receive around two billion downloads each month. The attack reportedly began when a threat actor gained access to the GitHub account of the maintainer behind several widely used caching libraries, including Keyv and Cacheable. From there, the malware spread through interconnected projects, ultimately impacting packages associated with a range of technology vendors and organisations. What makes ChainDrop particularly concerning is its ability to spread automatically. Malicious code was inserted into legitimate software packages and published through trusted GitHub Actions workflows, allowing the compromised releases to appear authentic. Once an affected package was installed, a hidden pre-installation script executed automatically, downloading additional components and launching an information-stealing payload. According to security researchers, the malware is designed to collect a wide range of sensitive information, including GitHub and npm access tokens, cloud credentials, Kubernetes secrets, database credentials, and keys for services such as AWS, Azure and Google Cloud. The stolen data is then encrypted and exfiltrated, while the malware searches for new opportunities to compromise additional repositories and packages. Security experts warn that any developer workstation or CI/CD environment that installed an affected package should be considered compromised. Recommended response measures include rebuilding impacted systems, rotating exposed credentials, reviewing repositories for unauthorised changes, and strengthening dependency management controls. As investigations continue, the number of affected packages may grow, reinforcing the importance of ongoing vigilance across the software supply chain. Attackers Exploit N-able Patch Bypass Flaw on RMM Servers Date: 2026-08-04 Author: Dark Reading N-able recently disclosed that a threat actor targeted its N-central product through a patch bypass vulnerability and used the flaw to gain access to customer environments. The company, which sells security and IT management tools to managed service providers (MSPs) and internal IT teams, disclosed active exploitation over the weekend. Rails patches critical Active Storage flaw with RCE potential Date: 2026-08-01 Author: Bleeping Computer [See AUSCERT bulletin https://portal.auscert.org.au/bulletins/ASB-2026.0171.2] A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). Rails is a popular open-source web application framework written in Ruby for building websites and web apps. It uses the built-in Rails component Active Storage for handling file uploads and attachments. Rails maintainers published an advisory about the CVE-2026-66066 flaw, which received a critical severity rating. Massive ChainDrop npm supply-chain attack infects hundreds of packages Date: 2026-08-04 Author: Bleeping Computer [See AUSCERT bulletin https://portal.auscert.org.au/bulletins/ASB-2026.0172] Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. Infected packages include very popular ones such as Keyv and Cacheable, flat-cache and file-entry-cache, all caching utilities from the same maintainer. The supply-chain attack started after the threat actor compromised the GitHub account of Keyv’s maintainer, and quickly spread to packages associated with major organizations such as Deliveroo, Ornikar, OneReach, Picsart, Qlik, and ServiceTitan. Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction Date: 2026-08-01 Author: The Hacker News [See AUSCERT bulletin https://portal.auscert.org.au/bulletins/ESB-2026.8857] Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in arbitrary code execution in the context of the current user without requiring any user interaction. The update also resolves another high-severity flaw (CVE-2026-48448, CVSS score: 8.6) stemming from SQL injection that could pave the way for arbitrary file reads. New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts Date: 2026-08-05 Author: Security Week The new attack methods, named ‘Pass-ta-key’ by Palo Alto Networks, focus on Google-synced passkeys. The security firm’s researchers showed how a threat actor could use the techniques to take over accounts without needing privilege escalation or user interaction. In a Pass-ta-key attack, malware already present on a Windows machine running Chrome can examine the browser’s local synchronization database to identify which online accounts the user has protected with passkeys, along with associated usernames and encrypted credential material. ASB-2026.0171.2 – UPDATE Ruby on Rails (Active Storage): CVSS (Max): 9.5 Ruby on Rails has released security updates to address a critical vulnerability in Active Storage that could allow an attacker to perform arbitrary file reads and potentially achieve remote code execution under vulnerable image processing configurations. ASB-2026.0172 – npm packages: CVSS (Max): None A large-scale npm supply chain attack, dubbed ChainDrop, compromised hundreds of widely used npm packages. ESB-2026.9044 – Adobe Campaign Classic: CVSS (Max): 10.0 This update addresses critical vulnerabilities that could result in arbitrary code execution and arbitrary file system read. ESB-2026.9115 – Cisco Catalyst SD-WAN: CVSS (Max): 9.9 Cisco has released software updates that address these vulnerabilities. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more