Latest cyber news, threats, security, and guidelines. Stack up.

Latest

Last 3 days · one card, one id
Incident
Published 2026-08-27
Verified 2026-08-29

AFP, WAPF and FBI charge two WA men over alleged open-source supply-chain syndicate

Joint AFP, Western Australia Police Force and FBI release: two West Australian men were charged on 26 August 2026 with a combined 14 offences after Perth search warrants. Police allege a syndicate inserted malicious code into software on an open-source repository that other developers then pulled in. The AFP estimates more than 1,000 organisations globally, more than 500,000 credentials, and at least 300 GB of data, with remediation costs in the hundreds of millions of dollars. The FBI statement in that release names the group TeamPCP. The men are not named in the AFP release. The investigation continues; further arrests have not been ruled out.

Exploited in Australia?
unknown

Primary: AFP media release · ABC News (secondary)

australia supply chain

AI
Published 2026-08-27
Verified 2026-08-29

Open letter: a limited window for a global cyber-defense surge

OpenAI published an open letter, "A call for collective action on cyber defense," signed on that page by OpenAI, Anthropic, Google, Microsoft, AWS and a long listed set of other firms. The letter says there is a limited window to strengthen cyber defences; that in the coming months AI-enabled cyber attacks will become far more widespread and sophisticated as models become more capable; and that hospitals, water treatment plants and internet infrastructure are at risk. It argues status-quo security will not be enough, and calls on organisations, cybersecurity companies and governments to put cyber-capable AI in defenders' hands, starting with essential services. Dated 27 August 2026 in contemporaneous reporting; the letter page itself does not print a date.

Product
Agentic / frontier AI (cyber defense)
Exploited in Australia?
unknown

Primary: OpenAI open letter · TechCrunch (27 Aug; date stamp)

ai llm agentic

Vulnerability
Published 2026-08-27
Verified 2026-08-29

ownCloud WebDAV pre-signed URL authentication bypass (CVE-2023-49105)

ownCloud core before 10.13.1 accepts pre-signed WebDAV URLs even when the file owner has no signing-key configured (the default). If the victim username is known, an unauthenticated attacker can access, modify, or delete any of that user's files. ownCloud rates CVSS 9.8. Fixed in 10.13.1 by denying pre-signed URLs when no signing-key is set. Patch, then review access logs for unexpected WebDAV activity.

Product
ownCloud core
Versions
10.6.0 through 10.13.0
CVSS
(CVSS 3.1, ownCloud)
Exploited in Australia?
unknown
Patch to
10.13.1 or later

Primary: ownCloud advisory · Vendor: NVD · CVE: CVE-2023-49105

vulnerabilities

Vulnerability
Published 2026-08-27
Verified 2026-08-29

Linux IPv6 fragmentation out-of-bounds write (CVE-2026-53362)

Out-of-bounds write in the Linux IPv6 send path (__ip6_append_data) when the paged-allocation branch undersizes the linear skb by fraggap bytes. An unprivileged local user can trigger it with a UDPv6 socket using MSG_MORE and MSG_SPLICE_PAGES. kernel.org rates CVSS 7.8. Red Hat describes the same flaw as a privilege-escalation and container-escape path on affected kernels. Patch to 6.1.177, 6.6.144, 6.12.95, 6.18.38 or 7.1.3, or the distro kernel that carries those stable commits. Red Hat documents a temporary workaround of user.max_user_namespaces=0; that setting breaks some container workflows.

Product
Linux kernel (IPv6)
Versions
From 6.0 until 6.1.177 / 6.6.144 / 6.12.95 / 6.18.38 / 7.1.3
CVSS
(CVSS 3.1, kernel.org CNA)
Exploited in Australia?
unknown
Patch to
6.1.177 / 6.6.144 / 6.12.95 / 6.18.38 / 7.1.3 or distro equivalent

Primary: NVD · Vendor: Red Hat RHSB-2026-009 · CVE: CVE-2026-53362 · kernel.org stable commit

vulnerabilities

Vulnerability
Published 2026-08-27
Verified 2026-08-29

JFrog Artifactory Docker cache path traversal (CVE-2026-66384)

Authenticated path-limitation flaw in JFrog Artifactory: under specific remote-repository conditions a user may write outside the intended Docker cache path. NVD affected builds end before 7.146.35, and 7.161.0 through builds before 7.161.16. CVSS 5.3. Patch to 7.146.35 or 7.161.16 (or later). Treat artifact caches as part of the software supply chain, not a side appliance.

Product
JFrog Artifactory
Versions
Before 7.146.35; 7.161.0 before 7.161.16
CVSS
(CVSS 3.1, NVD)
Exploited in Australia?
unknown
Patch to
7.146.35 or 7.161.16+

Primary: JFrog security advisories · Vendor: NVD · CVE: CVE-2026-66384 · Artifactory self-managed releases

vulnerabilities supply chain

Vulnerability
Published 2026-08-27
Verified 2026-08-29

ServiceNow AI Platform unauthenticated SQL injection (CVE-2026-74820)

ServiceNow's 27 August 2026 CVE record says it remediated an unauthenticated SQL injection in the ServiceNow AI Platform that could, in certain circumstances, let an unauthenticated user run arbitrary SQL against the instance database and read or change data beyond what was intended. ServiceNow scored it 10.0 (CVSS 4.0). Hosted instances received a vendor-deployed security update; partners and self-hosted customers were given the update. ServiceNow says it is not currently aware of malicious exploitation. The same 27 August CNA batch includes CVE-2026-6876 (Now Platform sandbox escape, CVSS 4.0 8.7) and CVE-2026-18886 (AI Platform improper access control). Self-hosted operators should apply the August 2026 CVE advisory updates. Affected CNA rows include Xanadu, Yokohama, Zurich and Australia patch families listed on the CVE record.

Product
ServiceNow AI Platform (also Now Platform for CVE-2026-6876)
Versions
CNA-listed Xanadu, Yokohama, Zurich and Australia patch-family builds (see KB3152242)
CVSS
(CVSS 4.0, ServiceNow CNA)
Exploited in Australia?
unknown
Patch to
Hosted: vendor already deployed the update. Self-hosted/partners: apply August 2026 CVE advisory updates (KB3152242)

Primary: CVE-2026-74820 (ServiceNow CNA) · Vendor: ServiceNow August 2026 CVE advisory (KB3152242) · CVE: CVE-2026-74820, CVE-2026-6876, CVE-2026-18886 · CVE-2026-6876 (same-day Now Platform sandbox escape)

vulnerabilities cloud ai

Vulnerability
Published 2026-08-27
Verified 2026-08-29

PaperCut NG/MF: active exploitation; Emergency Patch Release 2 (CVE-2026-82078, CVE-2026-81578)

PaperCut Software's 27 August 2026 (AEST) security bulletin, last updated 28 August, says its response team is investigating active exploitation of PaperCut NG and PaperCut MF, with confirmed customer incidents. The advisory applies to all versions of both products. Immediate action: if the Application Server is reachable from the public internet, restrict web access to trusted addresses now. At 8:42pm AEST on 28 August, PaperCut published Emergency Patch Release 2 for NG/MF v25 and v26 (Windows, Linux and macOS), with extra hardening after work with Huntress and watchTowr. At 10:08pm AEST the same day it published Release 2 for v24 as well. Install Release 2 even if you already applied the original emergency patch. Versions before v24 should upgrade to the latest. The bulletin now lists CVE-2026-82078 (unsafe dynamic class loading in the database connector, CVSS 4.0 9.4 Critical) and CVE-2026-81578 (authentication bypass that can let an unauthenticated remote attacker modify certain system configurations, CVSS 4.0 8.8 High). Site Servers and secondary/print servers should be updated, not only the primary Application Server. Print Deploy and Mobility Print are not affected. ASD's ACSC had not published a matching PaperCut alert at last check.

Product
PaperCut NG and PaperCut MF
Versions
All versions of NG and MF
CVSS
(CVE-2026-82078, CVSS 4.0, PaperCut); 8.8 (CVE-2026-81578, CVSS 4.0)
Exploited in Australia?
unknown
Patch to
Emergency Patch Release 2 for v24, v25 and v26; restrict public web access now; upgrade pre-v24 to latest

Primary: PaperCut security bulletin (27 Aug 2026) · Vendor: PaperCut (vendor) · CVE: CVE-2026-82078, CVE-2026-81578 · CVE-2026-82078

vulnerabilities australia

Vulnerability
Published 2026-08-26
Verified 2026-08-29

Microsoft SQL Server remote code execution (CVE-2019-1068)

CISA added CVE-2019-1068 to KEV on 26 August 2026 (federal due date 29 August 2026). NVD: a remote code execution issue when SQL Server incorrectly handles processing of internal functions. Apply the Microsoft security update from the MSRC advisory. Do not invent a cumulative update number here.

Product
Microsoft SQL Server
CVSS
(CVSS 3.1, NVD)
Exploited in Australia?
unknown
Patch to
Microsoft security update (MSRC CVE-2019-1068)

Primary: Microsoft MSRC · Vendor: NVD · CVE: CVE-2019-1068 · CISA KEV addition notice

vulnerabilities

Vulnerability
Published 2026-08-26
Verified 2026-08-29

Citrix NetScaler ADC/Gateway memory overflow (CVE-2026-8452)

CISA added CVE-2026-8452 to KEV on 26 August 2026 (federal due date 29 August 2026). NVD describes a memory-overflow issue in NetScaler ADC and NetScaler Gateway that can cause unpredictable behaviour and denial of service when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Apply the fixed builds in Citrix bulletin CTX696604. This desk does not invent build numbers the bulletin page would not yield over a plain fetch.

Product
Citrix NetScaler ADC and NetScaler Gateway
Versions
Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server configurations (see CTX696604)
CVSS
(CVSS 3.1, NVD); 8.8 (CVSS 4.0, vendor CNA)
Exploited in Australia?
unknown
Patch to
Vendor fixed builds in CTX696604

Primary: Citrix CTX696604 · Vendor: NVD · CVE: CVE-2026-8452 · CISA KEV addition notice

vulnerabilities network