Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
Saturday's digest is led by an actively exploited macOS screen-sharing zero-day, a government-confirmed breach of France's tax authority, and a China-linked APT adding a signed Windows rootkit to its backdoor arsenal. First, CVE-2026-65400 (CVSS 7.1) โ a flaw in macOS screen sharing's state management that lets an unauthenticated remote attacker log in without a password and run code โ is under active exploitation. The Netherlands' NCSC says it received notification of the bug being abused on multiple systems with port 5900 exposed to the internet, where attackers obtained root and planted a Monero crypto miner. Apple patched the flaw last week for macOS Tahoe, Sequoia and Sonoma; details became public at Black Hat. Second, France's tax authority (DGFiP) has confirmed a breach after a hacker using the alias ZeroBytes claimed to have obtained data on more than 600,000 people. The French Economy Ministry said an attacker used a stolen or misused identity to gain access to DGFiP systems in late June, viewing and extracting data on individuals and businesses before access was cut off; the claimed figure and data authenticity are not independently verified. Third, the HoneyMyte (Mustang Panda) APT has been observed deploying an updated CoolClient backdoor with a signed Windows kernel-mode rootkit, with confirmed victims including government entities in Myanmar, Mongolia, Pakistan and Russia, continuing a sustained China-linked espionage thread in this week's digests.
The actively exploited macOS screen-sharing flaw is the priority obligation for Australian organisations this week. CVE-2026-65400 sits on the default attack path Macs present when screen sharing is exposed โ exactly the internet-facing remote-access surface ACSC's Essential Eight and patch-prominence guidance target. The Dutch NCSC observation that attackers reached root and dropped a crypto miner on exposed systems shows real-world weaponisation within days of public disclosure, and Australian estates running macOS Tahoe, Sequoia and Sonoma with Screen Sharing enabled should treat swift patching as urgent, ideally before the 48-hour KEV-style window the ACSC and ASD advocate. The France DGFiP breach โ a state revenue authority losing data on individuals and businesses through a credential/identity compromise โ is a direct analogue to the risk profile Australian agencies and the ATO face under the Privacy Act Notifiable Data Breaches scheme and the SOCI Act, and reinforces the identity-centric breach pattern Australian defenders already see. ACSC's homepage continues to lead with frontier-AI board guidance, secure-agentic-AI adoption and CI Fortify OT isolation rather than new advisories โ no new ACSC publications this cycle. Mustang Panda's targeting of South/Southeast Asian and Russian government networks is a Five Eyes-significant development for Australian intelligence consumers tracking China-linked espionage across the Indo-Pacific.
Two structural threads from the week tighten further on Saturday. The zero-day and security-feature bypass conveyor remains the dominant operator risk. This digest's actively exploited macOS screen-sharing flaw joins a week defined by patch-to-exploitation conveyance โ the SharePoint authentication bypass, LibWeb metabase SQLi, afd.sys and VMware vCenter entries, and CISA's KEV and two-week BOD 26-04 directives โ with several of this week's bugs moving from HackerOne/PoC to active weaponisation within days. The Dutch NCSC's root-and-crypto-miner observation on internet-exposed remote-access ports is the clearest evidence yet that attackers are sweeping for immediately reachable, under-patched surfaces rather than novel TTPs. China-linked espionage continues to build momentum. Mustang Panda's signed kernel rootkit and PATCHCORD's targeting of Afghan telecoms and Indian critical infrastructure extend the week's APT arc โ JewelBug's dual state-espionage-and-crypto theft and the near-autonomous AI attack on a Taiwanese government target โ pointing to intensifying Indo-Pacific-focused collection as allied states reorient their own offensive posture (the US private-sector-hacking memo, Germany's spy-law overhaul). A separate governance thread also materialises: Apple's fresh mercenary-spyware threat notifications across 110 countries and Flock's ALPR access tightening both reflect growing pressure on surveillance and commercial-espionage data practices. Expect continued patching urgency on exposed remote-access services, sustained China-linked APT activity, and a broadening accountability debate over surveillance-data controls in the week ahead.
Incident Map
Global (Macro) 2 stories
Vulnerability Giving Attackers Full Control of Macs Is Under Active Exploitation
CVE-2026-65400 (CVSS 7.1), a flaw in the macOS screen-sharing capability's state management, lets an unauthenticated remote attacker log in without a password, view the screen and control the keyboard and mouse. The Netherlands' NCSC warned the bug is under active exploitation on multiple systems with port 5900 exposed to the internet, where attackers obtained root access and installed a Monero crypto miner. Apple patched the flaw last week for macOS Tahoe, Sequoia and Sonoma; details became public at Black Hat. **Verification: Verified** (official NCSC notification; documented in-the-wild exploitation).
CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps
Cybersecurity researchers identified a large-scale, global recruitment-themed phishing campaign using fake interview-scheduling pages and Browser-in-the-Browser windows to steal Google and Facebook credentials, and, in more advanced cases, relay multi-factor authentication prompts in real time. CTM360's RecruitTrap report logged more than 3,000 phishing URLs over two months, impersonating real recruiters for more than 50 organisations across 14 sectors, with marketing professionals the most-targeted group โ a deliberate focus given compromised marketing accounts can reach advertising platforms, social profiles and customer data. **Verification: Verified** (vendor campaign analysis).
- Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers โ Researchers detail a post-exploitation technique using the Chrome DevTools Protocol inside a running Chrome/Edge process on Windows to access cookies, saved data and authenticated sessions; requires prior code execution, placing it in a narrower post-compromise scenario. (The Hacker News, 2026-08-14)
- Unpatched GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE โ An unpatched GeoServer remote-code-execution flaw is being actively targeted, underscoring the exposed open-source analytics/geospatial surface. (The Hacker News, 2026-08-13)
- New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables โ Researchers document NatJack, a class of attack that abuses NAT table manipulation to hijack TCP sessions and spoof DNS. (The Hacker News, 2026-08-13)
- TeamPCP/LiteLLM supply-chain exposure (recurring, exec context): โ The continuing LiteLLM/Trivy credential-supply-chain exposure, covered earlier in the week, keeps evolving as researchers parse affected pipelines.
Government 3 stories
France Investigates Tax Authority Breach After Hacker Claims 600,000 Victims
France's tax authority (DGFiP) has confirmed hackers breached its information systems and extracted data on individuals and businesses. The Economy Ministry said an attacker gained unauthorised access in late June after stealing or misusing someone's identity, and could view and extract data before access was cut off. A hacker using the alias ZeroBytes claimed to have obtained data on more than 600,000 people โ names, tax identification numbers, email addresses, family circumstances and tax-status details โ though the figure and data authenticity are not independently verified. DGFiP said it will individually contact affected people, notify France's data protection authority and file a criminal complaint. It is the latest in a string of 2026 French government agency breaches (ANTS in April, the Education Ministry, and the National Bank Accounts File). **Verification: Verified** (French ministry publicly confirmed the intrusion and data extraction; the 600K victim figure is an unverified hacker claim). **Breach: Confirmed breach**
Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware
Apple sent a fresh batch of threat notifications to customers it suspects may have been targeted by mercenary spyware attacks in 110 countries, and says it has now notified customers in over 150 countries since the programme began in late 2021. The notifications typically go to people individually targeted because of who they are or what they do โ journalists, activists, politicians and diplomats. Apple does not attribute the attacks or resulting notifications to specific attackers or regions, citing the extreme cost, sophistication and worldwide nature of mercenary spyware. **Verification: Verified** (official Apple threat-notification programme).
Flock Tightens Privacy Controls Amid Scandals Over Officer Abuse
Flock Safety, a major supplier of Automatic License Plate Recognition (ALPR) technology used by thousands of US police agencies, is tightening its privacy controls and audit/assistance processes for police departments amid a series of scandals over officers misusing plate-reader data. The move reflects growing scrutiny of commercial surveillance infrastructure and the access controls law enforcement applies to location-tracking data. **Verification: Reported** (vendor policy change reported by established outlet; no regulator disclosure cited).
- Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office โ A data breach at Scotland's Prosecutor's Office is potentially widening, adding to a string of Scottish public-sector incidents. (Dark Reading, 2026-08-14)
Defence 1 story
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
The threat actor HoneyMyte, also known as Mustang Panda, has been observed deploying an updated CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious processes, files, registry objects and command-and-control information. Kaspersky identified victims in Myanmar, Mongolia, Pakistan and Russia, including confirmed government entities, with CoolClient consistently deployed as a secondary backdoor following a PlugX infection. The kernel component is installed when CoolClient has full Service Control Manager access and the SeTcbPrivilege; otherwise the implant proceeds without the driver. Kaspersky published file hashes, paths and C2 domains as indicators of compromise. **Verification: Verified** (vendor technical analysis with published IoCs).
- New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure โ Researchers detail PATCHCORD, a cyber-espionage backdoor aimed at Afghan telecom infrastructure and Indian critical-infrastructure targets, extending the week's China-linked APT arc. (The Hacker News, 2026-08-13)
Healthcare 4 stories
Boston Healthcare for the Homeless Program Breach Affects at Least 185K State Residents
A data breach at the Boston Health Care for the Homeless Program affects at least 185,000 Massachusetts residents, according to notification filings reported by HIPAA Journal. The incident is among the larger nonprofit-healthcare breaches this period and highlights how detection-sensitive provider environments can expose large populations. **Verification: Reported** (reported via notification/regulatory filings; victim-scale figures from the reporting source). **Breach: Probable breach**.
Texas Hearing Institute Ransomware Attack Affects 30,000 Patients
The Texas Hearing Institute disclosed a ransomware attack affecting approximately 30,000 patients, reported via HHS notification filings. The incident is part of a wave of smaller and mid-size provider ransomware cases, consistent with HIPAA Journal's concurrent reporting on SportsMed Family Partnerships (Florida) and Open Door health breaches. **Verification: Reported** (ransomware disclosed via notification filings). **Breach: Probable breach**.
Aesto Health Data Security Incident Affects Multiple Healthcare Provider Clients
Aesto Health, a business associate serving multiple healthcare provider clients, disclosed a data security incident. Business-associate incidents of this kind can expose data for several downstream providers at once, widening the effective blast radius beyond a single organisation and complicating notice obligations across the sector. **Verification: Reported** (vendor disclosure via HIPAA Journal). **Breach: Probable breach**.
ZOLL Medical Pays $3.5 Million to Settle Data Breach Lawsuit
ZOLL Medical has agreed to pay US$3.5 million to settle a class-action lawsuit over a prior data breach, reported by HIPAA Journal. The settlement illustrates the litigation and financial tail of healthcare data breaches, where medical-device and provider organisations face prolonged civil exposure alongside regulatory attention from HHS OCR. **Verification: Verified** (documented settlement).
Financial Services 1 story
WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud
Researchers detail WindRelay, a new Android malware that hijacks victims' devices and abuses them as Near-Field Communication (NFC) relays for contactless payment fraud. By relaying payment-card NFC signals, the malware lets attackers perform transactions using compromised phone hardware in proximity, an emerging pattern in mobile-financial fraud that targets the contactless-payments surface widely used across Australian and New Zealand banking. **Verification: Verified** (technical analysis of the malware).
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| โ Tier 1 | Very High | Official / first-party |
| โ Tier 2 | High | Established cyber journalism |
| โ Tier 3 | Moderate | General tech/news media |
| โ Tier 4 | Low | Social / unverified |