24 Jul 2026

Week in review

Greetings,

Origin Energy has confirmed that unauthorised access to customer information has occurred, marking what is believed to be the largest publicly known cyber incident to affect an Australian energy retailer. The company, which serves more than 4.8 million customers, announced it is still investigating the extent of the breach and determining how many may have been impacted.

According to Origin, the compromised information may include customers’ names, addresses, dates of birth, phone numbers, and limited banking information such as the last four digits of a credit card or the last three digits of a bank account. The company has stressed that full banking and credit card details do not appear to have been exposed.

Chief Executive Frank Calabria apologised to customers, acknowledging the trust placed in the company and assuring customers that securing systems and preventing further unauthorised access remains a top priority. Origin says it will contact affected customers directly once it has confirmed who was impacted.

The breach came to light after a media outlet was contacted by an alleged hacker who provided a sample of customer records. Following notification of the incident, Origin alerted authorities and informed the Australian Securities Exchange.

The incident adds to a growing list of major Australian cyber security breaches in recent years, following attacks on organisations including Optus, Medibank, and Qantas. Cyber security experts are urging Origin customers to remain vigilant for suspicious emails, text messages and phone calls, as criminals often leverage stolen personal information in follow-up scams.

While some customers have recently experienced delays receiving energy bills, Origin says those issues are linked to July pricing changes and are not connected to the data breach investigation.


Critical ServiceNow code execution flaw now exploited in attacks
Date: 2026-07-20
Author: Bleeping Computer

Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.
Formerly known as the Now Platform, ServiceNow AI Platform is an enterprise-grade Platform-as-a-Service (PaaS) that helps businesses integrate AI into core enterprise workflows.
Cybersecurity company Searchlight Cyber, which found this critical vulnerability and reported it on April 1st, says that it allows unauthenticated threat actors to escape the sandbox and execute code remotely within the ServiceNow platform in high-complexity attacks.

WordPress Core "wp2shell" RCE flaws get public exploits, patch now
Date: 2026-07-18
Author: Bleeping Computer

[See AUSCERT Bulletin https://portal.auscert.org.au/bulletins/ESB-2026.8154]
Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately.
The wp2shell attack consists of two flaws, tracked as CVE-2026-63030 and CVE-2026-60137, that can be chained together to achieve pre-authentication remote code execution against WordPress installs running versions 6.9.x and 7.0.x.
The flaws were discovered by Adam Kues of Searchlight Cyber, which says an unauthenticated attacker can exploit them against a default WordPress installation.

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
Date: 2026-07-21
Author: The Hacker News

A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr.
The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network. Microsoft credited DEVCORE researcher "splitline" with discovering and reporting the flaw.

Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates
Date: 2026-07-22
Author: Security Week

[AUSCERT has published security bulletins for these Oracle updates]
Oracle has patched more than 1,400 vulnerabilities with its July 2026 Critical Patch Update (CPU), with a vast majority of the flaws likely identified by artificial intelligence.
According to Oracle, the latest quarterly CPU includes 1,449 security patches, addressing 1,434 unique CVEs across 334 products.

CISA orders urgent action on actively exploited Langflow RCE flaw
Date: 2026-07-22
Author: Bleeping Computer

The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents.
Tracked as CVE-2026-0770, this critical security flaw allows unauthenticated threat actors to gain remote code execution as root in low-complexity attacks.


ESB-2026.8410 – Mozilla Thunderbird: CVSS (Max): 10.0*

A large number of vulnerabilities was patched in Mozilla Thunderbird, with the most severe being tracked as CVE-2026-16367 for a sandbox escape due to invalid pointer in the Disability Access APIs component.

ESB-2026.8355 – Tenable Security Center: CVSS (Max): 9.9

Tenable Security Center has underlying third party libraries which were found to contain vulnerabilities. Updated versions are now available from the providers, which Tenable has implemented to address potential impacts of these identified vulnerabilities.

ESB-2026.8317 – Atlassian Products: CVSS (Max): 10.0

83 high severity vulnerabilities and 18 critical severity third party vulnerabilities have been fixed in new versions of Atlassian products. Some of the patched vulnerabilities include remote code execution, denial of service and improper authorization.

ASB-2026.0144 – Oracle Communications: CVSS (Max): 9.8

Oracle has released a critical patch update containing 168 new security patches or Oracle Communications. Many of these vulnerabilities can be remotely exploitable without authentication over a network. It has also been exploited in the CISA KEV.

ESB-2026.8151 – roundcube: CVSS (Max): 10.0

Multiple vulnerabilities in roundcube such as account takeover, cross-site scripting, SSRF bypass, information disclosure and denial of service have been fixed in a new version release. Roundcube strongly recommends patching with the latest version.


Stay safe, stay patched and have a good weekend!

The AUSCERT team