28 Aug 2026
Week in review
Greetings,
The pressure on social media platforms to better protect young users is intensifying, with governments and regulators around the world taking increasingly tough measures against the technology giants.
New Zealand is the latest country to move towards restricting social media access for under 16s, with proposed legislation requiring platforms to take reasonable steps to verify users' ages. The proposal follows Australia's world-first under-16 social media restrictions and reflects growing international concern about the impact of social media on children.
Meanwhile, in the United States, Meta has agreed to pay up to US$18 billion to settle lawsuits brought by almost every US state over allegations that Facebook and Instagram harmed children and misled the public about the safety of its platforms. As part of the settlement, Meta has also agreed to introduce stronger protections for teenage users, including default time limits, overnight restrictions and limits on notifications during school hours.
While Meta has not admitted wrongdoing and the settlement does not fundamentally change its business model, the scale of the agreement signals a significant shift in expectations around platform accountability. It could also provide a template for similar action against other major platforms, with part of Meta's settlement tied to comparable commitments from competitors such as TikTok and YouTube.
The global push highlights the growing intersection of online safety, privacy, cybersecurity and regulation. As age verification and platform monitoring increase, so do concerns around protecting sensitive user data. Regulation is accelerating, and technology companies face growing expectations to build safety and security into their platforms by design.
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
Date: 2026-08-25
Author: The Hacker News
[AUSCERT has informed the potentially affected members via Critical MSINs]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. Successful exploitation of the flaw can lead to unauthorized access to the instances or modification of critical data.
Hackers breached over 270 Zimbra servers in ongoing attacks
Date: 2026-08-25
Author: Bleeping Computer
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability.
The ZCS email and collaboration suite is used by hundreds of millions of people and organizations, including thousands of businesses and hundreds of government agencies worldwide.
Synacor patched the security flaw (tracked as CVE-2026-73570), which allows unauthenticated attackers to gain code execution remotely by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled, with the release of ZCS version 10.1.20 on July 20.
Active exploitation of a software development platform within Australia
Date: 2026-08-24
Author: ASD ACSC
The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has observed active exploitation of a vulnerability affecting TeamCity On-Premises servers within Australia.
TeamCity is a Continuous Integration and Continuous Deployment (CI/CD) server to automate the processes of building, testing, and deploying software.
CVE 2026-63077 may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands.
This vulnerability affects all TeamCity On-Premises versions.
Hackers target Microsoft SharePoint RCE chain with PoC exploit
Date: 2026-08-26
Author: Bleeping Computer
Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused.
The first (tracked as CVE-2026-55040) is an authentication bypass flaw in the JWT token validation pipeline that attackers without privileges can exploit to perform operations as a SharePoint site user or administrator.
The second (CVE-2026-63520) is a vulnerability in SharePoint's Business Connectivity Services (BCS) that unauthenticated attackers can chain after successfully exploiting CVE-2026-55040 for remote code execution (RCE) on a targeted SharePoint Server.
Shop now? Banking malware campaign posing as Woolworths active in Australia
Date: 2026-08-21
Author: cyberdaily.au
Woolies and other trusted brands are being used to spread an Android Trojan that can access bank accounts, read SMSes, and even access cameras.
Security researchers have lifted the lid on an ongoing Android malware campaign active in Australia, posing as several trusted and well-known brands to spread a Remote Access Trojan (RAT) designed, among other things, to steal banking information.
According to NordVPN’s threat intelligence team, the campaign is circulating via text messages, WhatsApp, and social media, impersonating brands such as supermarket giant Woolworths and several airlines, including Emirates, Qatar Airways, and Air India.
ESB-2026.9812 – Cisco Crosswork Platform(s): CVSS (Max): 10.0
Cisco has released software updates that address vulnerabilities in Cisco Crosswork platform(s).
ESB-2026.10018 – Adobe Campaign Classic: CVSS (Max): 10.0
Adobe has released a security update that addresses critical (RCE) vulnerabilities in Adobe Campaign Classic.
ESB-2026.10087 – GitLab Community Edition (CE) and Enterprise Edition (EE): CVSS (Max): 8.7
Updated versions of GitLab Community Edition (CE) and Enterprise Edition (EE) contain important bug and security fixes. GitLab strongly recommends that all self-managed GitLab installations be upgraded.
ESB-2026.10066 – IBM QRadar SIEM: CVSS (Max): 9.8
Multiple components with known vulnerabilities were addressed in IBM QRadar SIEM updates.
ESB-2026.10159 – All-Line Equipment Company Fuel-Boss: CVSS (Max): 8.7
Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems.
Stay safe, stay patched and have a good weekend!
The AUSCERT team