Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
Friday's digest is led by an actively exploited SharePoint authentication-bypass, a landmark US reorientation of offensive cyber to the private sector, and Germany's largest postwar spy-law overhaul. First, CVE-2026-55040 (CVSS 9.1) โ a Microsoft SharePoint security-feature bypass allowing impersonation that lets an attacker disclose and modify files โ is being exploited in the wild by threat actors following Rapid7's release of a proof-of-concept this week. Microsoft patched the flaw in July; it is now the fifth SharePoint bug exploited this year, and Defused Cyber reports live exploitation. Separately, CISA has added CVE-2026-72898, an unauthenticated SQL-injection flaw in Metabase with administrator-access reach, to its Known Exploited Vulnerabilities catalogue. Second, President Trump has signed a national security memorandum authorising vetted private-sector companies to conduct offensive cyber operations against foreign criminal syndicates โ a significant reorientation of US cyber-crime policy that delegates government offensive action to commercial firms and carries wide Five Eyes and civil-liberties implications. Third, Germany's cabinet approved legislation giving its intelligence agencies powers to hack foreign systems, sabotage adversaries' supply chains and feed disinformation to extremists inside Germany โ the biggest overhaul of the country's spy laws of the postwar era. The week's AI-threat thread continues in parallel, with CyberScoop reporting that "mid-tier" AI models have become dramatically more capable at offensive hacking.
The Germany spy-law overhaul and the US offensive-cyber memo are the stories Australian and New Zealand officials will be watching most closely this week. The delegation of offensive cyber action to the private sector in the US challenges assumptions that state-conducted covert action is the exclusive domain of government agencies like ASD, and raises questions about how Five Eyes allies โ including AU โ approach public-private boundaries in offensive operations, an area where ACSC has historically drawn a clear line. The actively exploited SharePoint flaw (CVE-2026-55040) is a direct and urgent obligation for Australian organisations running Microsoft estates: an impersonation bug that discloses and modifies files on an internet-exposed SharePoint instance is precisely the scenario that triggers Australian Privacy Act Notifiable Data Breaches obligations and Essential Eight patching discipline, and the rapid PoC-to-exploitation cycle underscores why ACSC's patch-prominence guidance matters. CISA's addition of the unauthenticated Metabase SQL-injection flaw to its KEV catalogue is relevant to Australian teams using open-source analytics stacks, where an administrator-access chain via a BI tool is a documented TA style. ACSC's homepage continues to lead with frontier-AI board guidance and secure-agentic-AI adoption rather than new advisories โ no new ACSC publications this cycle โ maintaining the regulatory posture it has held all week.
Two structural themes tighten as the week ends. Offensive cyber capability is being re-nationalised and commercialised at the state level. Germany's cabinet-approved spy-law overhaul โ moving beyond surveillance into active hacking, supply-chain sabotage and domestic disinformation โ follows the US memo authorising vetted private firms to run offensive operations against foreign criminals, both sharpening the same geopolitical arc the week began with: the Taiwan near-autonomous AI attack and Frontier AI threat warnings. The pattern is a coordinated expansion of the offensive envelope across Western and allied states in the face of an increasingly assertive APT threat, with cyber diplomacy shifting from defence and deterrence toward active, sometimes delegated, engagement. Patch-to-exploitation conveyance remains the dominant operator risk. The SharePoint impersonation bug went from July Patch Tuesday disclosure to exploited-in-the-wild within weeks of a public PoC, the Metabase SQLi flaw joined the same rapid KEV conveyor this cycle, and the week's earlier `afd.sys` and VMware vCenter exploitation show internet-exposed Microsoft, web and management surfaces as the primary attack surface rather than novel TTPs โ the same pattern that drove CISA's KEV and two-week BOD 26-04 remediation directives all week. AI-offensive capability continues to feature: the CyberScoop finding that mid-tier models have "dramatically better" hacking ability sustains the AI-weaponisation thread from Tuesday's near-autonomous-attack disclosure, pointing to a coming week where AI-accelerated vulnerability discovery and automation remain front and centre. Expect patching urgency, offensive-posture diplomacy and AI-enabled threat to dominate the week ahead.
Incident Map
Global (Macro) 4 stories
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Threat actors have begun exploiting CVE-2026-55040 (CVSS 9.1), a critical security-feature bypass in Microsoft SharePoint stemming from weak authentication that allows impersonation and lets an attacker disclose files and modify data. Microsoft patched the flaw in July 2026; Defused Cyber reports attackers are exploiting it using a Rapid7 proof-of-concept released earlier this week. It is the fifth SharePoint vulnerability exploited this year after CVE-2026-45659, CVE-2026-56164, CVE-2026-58644 and CVE-2026-50522. **Verification: Verified** (vendor disclosure; documented in-the-wild exploitation).
CISA Adds Metabase SQL-Injection Flaw (CVE-2026-72898) to Known Exploited Vulnerabilities
CISA added CVE-2026-72898 โ an unauthenticated SQL-injection vulnerability in the Metabase analytics/BI platform โ to its Known Exploited Vulnerabilities catalogue. Exploitation lets an unauthenticated remote attacker inject arbitrary SQL into the Metabase application database, gain administrator access, change application configuration and steal stored credentials for connected databases. The addition obliges federal civilian agencies to remediate under BOD 26-04. **Verification: Verified** (official CISA catalogue entry).
New Mirai Variant Adds Stealth Capabilities to Notorious Botnet Code
Researchers have documented a new Mirai variant that extends the notorious DDoS botnet code with hardened stealth: encrypted communications with command-and-control servers and a built-in "sniffer" that scans for default access credentials. The additions reflect modern botnet operators' shift toward evading detection and harvesting credentials as they build and extend IoT botnets. **Verification: Verified** (technical analysis of the variant).
AI's 'Middle Class' Has Gotten Dramatically Better at Hacking
CyberScoop reports that mid-tier AI models have become dramatically more capable at offensive hacking, closing the gap with frontier models and broadening the pool of actors who can leverage AI for attacks. The finding extends the week's AI-weaponisation thread, following the disclosed near-autonomous AI attack on a Taiwanese government target, and reinforces concerns about AI lowering the barrier to effective cyber exploitation. **Verification: Reported** (research/analysis; no specific live victim disclosure).
- JewelBug APT Balances State Espionage & Cryptocurrency Theft โ Researchers detail the JewelBug APT, which combines state espionage with cryptocurrency theft, a blend of nation-state intelligence gathering and financially motivated operations. (Dark Reading, 2026-08-13)
Government 2 stories
Trump Signs Memo Authorising Private-Sector Offensive Operations Against Foreign Criminals
President Trump signed a national security memorandum authorising vetted private companies to conduct offensive hacking against foreign criminal syndicates. The memo reorients US cyber-crime policy by delegating government offensive action to commercial firms, a significant shift with wide implications for the public-private boundary in offensive cyber operations, civil liberties and the cyber-security industry. **Verification: Verified** (official memorandum reported by multiple outlets).
Germany Moves to Give Spy Agencies Hacking and Sabotage Powers
Germany's cabinet approved legislation that would let its intelligence agencies hack foreign systems, sabotage adversaries' supply chains and feed false information to extremists inside Germany โ described as the biggest overhaul of the country's spy laws of the postwar era. The proposal marks a dramatic expansion of German offensive intelligence powers beyond traditional surveillance. **Verification: Verified** (official cabinet decision).
Transport 1 story
Uber Freight Confirms Cyber Incident After Hackers Claim Nearly 1 Million Files
Uber Freight confirmed a cyber incident after hackers claimed to have obtained nearly one million files. The company told FreightWaves it contained the intrusion and engaged federal law enforcement, but has not confirmed whether the hackers' purported files are authentic or disclosed what information may be involved. The incident hits a critical logistics and supply-chain freight platform. **Verification: Reported** (victim confirmed the incident; data authenticity not yet confirmed). **Breach: Probable breach**
Healthcare 1 story
Five HIPAA-Regulated Entities Announce Data Breaches; Two Settlements Reached
HIPAA Journal reports five healthcare entities announced data breaches from HHS and state notification filings, alongside settlements between providers (including OnePoint Patient Care and Clay-Platte Family Medicine) over prior breach-related lawsuits. The batch is a steady reminder that smaller and mid-size providers remain the breach-prone tail of the healthcare sector, often lacking resources for the patching and alert-hygiene basics regulators expect. **Verification: Verified** (regulator/legal filings).
Energy & Utilities 1 story
CISA Issues Multiple Siemens and Johnson Controls ICS Advisories
CISA published a batch of ICS advisories covering vulnerabilities in Siemens products โ LOGO! Soft Comfort, Solid Edge, Simcenter Femap, Parasolid, Siveillance Video, Desigo DXR and PXC controllers, License Server (SLS) and RUGGEDCOM APE1808 โ and the Johnson Controls Metasys building-management platform. The advisories highlight continued risk in industrial control and building-automation systems across energy and industrial environments. **Verification: Verified** (official advisories).
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| โ Tier 1 | Very High | Official / first-party |
| โ Tier 2 | High | Established cyber journalism |
| โ Tier 3 | Moderate | General tech/news media |
| โ Tier 4 | Low | Social / unverified |