25 Sep 2026

Week in review

Greetings,

In June this year an AI agent operated by US-based artificial intelligence company OpenAI gained unauthorised access to Medicare’s statistics portal and three other government systems, state and federal, while researching publicly available information on medicine spending. The incident was reported by OpenAI to the Australian government via email in September.

After encountering access restrictions, the AI agent attempted alternative methods and accessed both public and non-public information within the Medicare Statistics Reporting Service portal. There is currently no evidence that personal Medicare information was accessed or that the broader Services Australia network was compromised. The Australian Signals Directorate is assisting with a forensic investigation.

The incident highlights emerging cyber security challenges as AI agents become increasingly capable of independently navigating systems and adapting their behaviour when encountering restrictions.

For organisations, it reinforces the importance of strong access controls, continuous monitoring and logging, and appropriate guardrails and human oversight when deploying AI agents. As agentic AI capabilities evolve, security and incident response processes will need to evolve alongside them.


Australian Medicare data portal "infiltrated" by OpenAI agent
Date: 2026-09-24
Author: iTnews

An OpenAI agent has accessed “public and non-public files” from a “Medicare statistics reporting portal”, Australian Prime Minister Anthony Albanese said.
Speaking at the United Nations meeting in New York, Albanese said the AI agent had “infiltrated” and “gained unauthorised access” to the data portal in June.
While the portal is “public-facing”, according to Albanese, it appears not all of the data files that it holds are for general consumption.
“The AI agent accessed both public and non-public files,” Albanese said.

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Date: 2026-09-23
Author: The Hacker News

[AUSCERT has informed the affected members via Critical MSINs]
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication.
The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at least September 2, one day before MikroTik shipped patches in RouterOS 6.49.21, 7.23.4, and 7.24.2.

F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
Date: 2026-09-23
Author: Bleeping Computer

[AUSCERT has informed the affected members via Critical MSINs]
F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks.
BIG-IP APM (short for Access Policy Manager) is the company's centralized access management proxy solution that helps admins secure access to their organizations' networks, applications, cloud, and application programming interfaces (APIs).
Tracked as CVE-2026-94127, the flaw affects instances configured as an OAuth Authorization Server when a BIG-IP APM access policy and an OAuth profile are configured on a virtual server.

BigCommerce Data Stolen via Ribon Apps Hack
Date: 2026-09-22
Author: Security Week

Enterprise eCommerce platform BigCommerce fell victim to a supply chain attack that led to customer data theft.
BigCommerce is a SaaS provider that enables merchants to build and manage online stores. It hosts the stores, provides backend tools, and handles server security.
Late last week, the company started notifying merchants that customer data was stolen after hackers compromised a BigCommerce application key held by Ribon, a storefront and shopping experience optimization app developed by Fastr-owned Be A Part Of.

Hacked? Qantas investigating WhatsApp phishing reports
Date: 2026-09-21
Author: cyberdaily.com.au

The Flying Kangaroo and a Sydney hotel warn customers not to share payment details following suspicious messages targeting Qantas Hotels customers.
Australia’s national carrier is once again investigating a possible security breach after some of its customers were targeted by WhatsApp phishing messages.
“We’re investigating reports of phishing attempts targeting some Qantas Hotels customers.
“If you receive a suspicious WhatsApp message claiming to be from a hotel, you should ignore the message. Qantas Hotels and our accommodation partners will never ask you to verify your booking or provide personal details via WhatsApp.


ESB-2026.11491 – F5 – BIG-IP APM: CVSS (Max): 9.8

F5 have provided fixes for a vulnerability – when a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE).

ESB-2026.11529 – Ubuntu – Linux kernel: CVSS (Max): 10.0

Ubuntu have provided fixes for security issues, discovered in the Linux kernel that could possibly allow an attacker to compromise the system/subsystems.

ESB-2026.11379 – Debian – chromium: CVSS (Max): 9.8

Debian have provided fixes for security issues that were discovered in Chromium, which could result in the execution of arbitrary code, denial of service, or information disclosure.

ESB-2026.11479 – Siemens SIPLUS and SIMATIC Products: CVSS (Max): 7.8

Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions.

ESB-2026.11583 – GitLab Community Edition (CE) and Enterprise Edition (EE): CVSS (Max): 9.9

Updated versions for GitLab Community Edition (CE) and Enterprise Edition (EE) were released on September 23, 2026. These versions contain important bug and security fixes, and Gitlab strongly
recommend that all self-managed GitLab installations be upgraded to one of these versions immediately.


Stay safe, stay patched and have a good weekend!

The AUSCERT team