Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
A busy Tuesday after the quiet Monday โ the weekend and Monday publication cycle delivered two major confirmed breaches, a fresh nation-state cyber operation, and the first concrete EU Cyber Resilience Act standards. First, Polish authorities are investigating a cyberattack on healthcare software provider MyDr that may have exposed data belonging to nearly 19 million people and more than 12,000 medical facilities. MyDr, whose software connects providers to Poland's nationwide P1 e-health platform, confirmed the incident and said it had removed the cause; Polish Digital Affairs Minister Krzysztof Gawkowski said the e-Health Center was replacing affected credentials as a precaution. The company said it had found no evidence the data had been published, and authorities said the unauthorised access reached historical data held through April 2024. Second, US debt-consolidation lender Heights Finance disclosed a breach of a third-party cloud platform that exposed personal and financial data on about 734,828 customers โ including Social Security numbers, tax IDs, driver's licence numbers, bank account and routing numbers โ after a hacker gained access in May. The company told Texas regulators on Friday and published a customer warning; it said the intrusion was limited to the cloud platform and did not affect its loan-management systems. Third, Ukraine's military intelligence (HUR) claimed it disrupted Russia's largest online marketplace, Wildberries, in a cyber operation run with the Cyber Corps hacker group, amplifying the impact of drone strikes on the company's warehouses; the claims could not be independently verified.
The EU Cyber Resilience Act standards published this week are the most strategically relevant development for Australian organisations, alongside the ASIC deepfake-scam warning. The European Telecommunications Standards Institute (ETSI) released 17 draft cybersecurity standards that vendors must follow to sell products in the EU when the CRA enters effect next year โ covering minimum security features such as updatability, software bills of materials (SBOMs) and modern cryptography. Australian organisations that buy or build on EU-market hardware and software will inherit these baseline requirements, and the standards align closely with the ASD's Essential Eight and ISM configuration-and-patching guidance; local product vendors exporting to Europe should treat the draft standards (in public comment until November) as a forward compliance signal. Separately, ASIC has warned of a surge in deepfake scams targeting Australian consumers and investors โ a direct AU regulatory alert that reinforces the OAIC and ACSC's standing guidance on AI-enabled fraud and identity theft, and connects to the week's broader theme of AI being weaponised for social engineering. The MyDr breach is a reminder for Australian healthcare providers of the concentration risk in third-party clinical software and the importance of the OAIC Notifiable Data Breaches scheme and APRA CPS 234 for health and financial data; the Heights Finance and SafePal incidents underscore the identity-integrity and supply-chain exposure Australian financial-services and fintech firms face from cloud and third-party platforms.
Two threads from the past seven days frame this Tuesday, grounded in the digests of the past week. The EU Cyber Resilience Act is moving from policy to enforceable standards, marking a regulatory wave that has been building all month. The ETSI draft standards (17 August) are the final step before the CRA enters effect next year, following a week that saw the EU publish its upcoming cybersecurity standards and continued Five Eyes regulatory convergence on AI-agent security, data protection and critical-infrastructure resilience. Australian and New Zealand organisations should read this as a signal that baseline product-security requirements are becoming a market-access condition, not just a compliance exercise. Nation-state cyber operations against economic and logistics targets continue to escalate. Ukraine's HUR claimed a disruptive cyber operation against Wildberries, Russia's largest online marketplace, amplifying drone strikes on its warehouses โ the latest in a sustained pattern of Ukraine targeting Russian economic infrastructure, and a reminder of the growing overlap between cyber and kinetic warfare. This connects to the week's China-linked espionage momentum (Mustang Panda's signed kernel rootkit, JewelBug's dual operations, PATCHCORD's targeting) and the allied response, including the White House's reported move to let private security firms conduct offensive cyber operations against overseas criminals. The patch-to-exploitation conveyor remains the defining operator risk. CISA added Ray-Project's Ray code-injection flaw (CVE-2025-62593) to its Known Exploited Vulnerabilities catalogue on 17 August with a 20 August remediation deadline, continuing the week's pattern of KEV additions (Cisco ASA/FTD, Windows WinSock, Metabase) and the two-week BOD 26-04 federal patch directive. For defenders, the message is unchanged: internet-facing AI/ML orchestration platforms and cloud data stores are high-priority patch and monitoring targets.
Incident Map
Healthcare 3 stories
Poland Probes MyDr Healthcare Software Breach Potentially Affecting 19 Million People
Polish authorities are investigating a cyberattack on healthcare software provider MyDr that may have exposed data belonging to nearly 19 million people and more than 12,000 medical facilities. MyDr, a privately-owned Polish company whose software connects healthcare providers to Poland's nationwide P1 e-health platform, confirmed the incident and said it had identified and removed the cause and introduced additional security measures, without detailing the vulnerability. Polish Digital Affairs Minister Krzysztof Gawkowski said the e-Health Center was replacing affected credentials as a precaution. Authorities said hackers obtained unauthorised access to historical data held through April 2024, but that it may not involve all MyDr customers or their patients; the company said it had found no evidence the data had been published. **Verification: Verified** (company and Polish authorities publicly confirmed the intrusion; the 19M figure is an upper-bound estimate from authorities). **Breach: Confirmed breach**
Beverly Hills Plastic Surgeon Confirms Data Theft/Extortion Incident
Terry J. Dubrow, MD, a Beverly Hills, California-based plastic surgeon, notified the California Attorney General about a security incident in which an individual claimed to have breached its computer systems and copied sensitive patient information. An investigation confirmed unauthorised access to parts of its network starting 16 January 2026, with files copied; on 27 July the practice confirmed patients' personal information had been obtained, including names, patient-chart data, referring-physician information, and potentially contact details, Social Security numbers, driver's licence or state ID numbers, birth dates and prescription information. **Verification: Verified** (practice notified the state regulator and confirmed the data theft). **Breach: Confirmed breach**
Vishing Attack Gives Threat Actor Access to Quantum Health Network
Quantum Health, a Dublin, Ohio-based healthcare navigation and care coordination company, disclosed a cybersecurity incident identified in May 2026 that began with a vishing attempt. An attacker called a Quantum Health user on 29 May and tricked them into providing network access; between 29 May and 1 June the unauthorised third party accessed the network and acquired files, and on 1 June Quantum Health experienced a network disruption affecting internal and external systems. The threat group was not named and no ransomware group appears to have claimed responsibility. **Verification: Verified** (company disclosed the incident and traced it to the vishing call). **Breach: Confirmed breach**
Financial Services 1 story
Nearly 750,000 Had Financial Info, SSNs Leaked in South Carolina Loan Company Breach
Cybercriminals breached the cloud system of debt-consolidation loan company Heights Finance in May, stealing financial and personal data on about 734,828 customers. The company, which operates dozens of personal loan companies across Alabama, Tennessee, Georgia, Texas and South Carolina, published a customer warning and told Texas regulators on Friday. Stolen information includes contact details, bank account and routing numbers, and government IDs including Social Security numbers, tax IDs, driver's licence numbers or state IDs, plus personal information shared during customer-service interactions. Heights Finance said the breach was discovered on 7 May when a hacker gained access to a cloud-based platform hosted by a third party, and that the intrusion was limited to that platform and did not affect its loan-management systems. **Verification: Verified** (company published a warning and notified regulators; the 734,828 figure is from the company's Texas filing). **Breach: Confirmed breach**
Retail & Entertainment & Sport 1 story
SafePal Crypto Hardware Wallet Maker Confirms Breach Affecting Nearly 40,000 Customers
Crypto hardware wallet company SafePal confirmed a data breach, telling users that nearly 40,000 customers had information stolen during a recent security incident. The company said the incident impacted information from people who placed orders between 2 March 2025 and 11 April 2026, including names, email addresses, shipping addresses, phone numbers and purchase details. SafePal said it identified a flaw in the order-tracking function for a plug-in associated with customer order information that, under certain conditions, allowed unauthorised access to another customer's order information; the issue has been remediated. SafePal is the third hardware wallet manufacturer attacked in the last month, after Trezor and Coinkite dealt with incidents affecting thousands of customers. The company reiterated that all wallets, seed phrases and private keys remain secure. **Verification: Verified** (company disclosed the incident in a blog post). **Breach: Confirmed breach**
Government 1 story
CISA Adds Ray-Project Ray Code Injection Flaw to Known Exploited Vulnerabilities
CISA added CVE-2025-62593, a code-injection vulnerability in Ray-Project's Ray distributed-computing framework, to its Known Exploited Vulnerabilities catalogue on 17 August, with a remediation due date of 20 August. Ray is widely used for AI/ML orchestration and distributed workloads, and the addition signals confirmed exploitation in the wild. The add continues a week of KEV activity (Cisco ASA/FTD, Windows WinSock, Metabase) and reinforces the two-week BOD 26-04 federal patch directive. **Verification: Verified** (official CISA KEV catalogue entry).
Global (Macro) 2 stories
Ukraine Says Cyberattack Hit Russian E-Commerce Giant Wildberries Amid Drone Strikes
Ukraine's military intelligence (HUR) claimed it disrupted the operations of Russia's largest online marketplace, Wildberries, in a cyberattack intended to amplify the impact of drone strikes on the company's infrastructure. The operation was reportedly carried out with the Cyber Corps hacker group and caused "widespread disruption" affecting customer service, contact centres and payment infrastructure, despite the target's "strong security measures". HUR said it targeted Wildberries because of its role in Russia's logistics network and in financing the war against Ukraine; the claims could not be independently verified. **Verification: Unverified** (single source โ HUR statement; no independent confirmation).
EU Publishes Draft Cyber Resilience Act Standards for Product Vendors
The European Telecommunications Standards Institute (ETSI) released 17 draft cybersecurity standards that vendors must follow to sell products in the EU when the Cyber Resilience Act enters effect next year. The standards cover 17 core technologies across major product categories and describe minimum security features each must implement to be CRA-compliant, including the ability to update products after sale, shipping with a software bill of materials (SBOM), and using modern cryptography. The standards are interim drafts in a public-comments phase until November, with final versions expected by December, a year before CRA compliance. **Verification: Verified** (official ETSI publication reported by established cyber outlet).
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| โ Tier 1 | Very High | Official / first-party |
| โ Tier 2 | High | Established cyber journalism |
| โ Tier 3 | Moderate | General tech/news media |
| โ Tier 4 | Low | Social / unverified |