// daily digest ยท 2026-08-19
Wednesday·19 August 2026

Cyber Digest

A daily roundup of key cybersecurity developments across sectors

11 stories5 sectors8 sourcesAU/NZ watchlist active

Executive Summary

A functional Wednesday led by an active-exploitation alert on Australian soil, the latest Microsoft Copilot Personal flaws, and a fresh spike in AI-agent and cloud-credential attacks. First, the Australian Cyber Security Centre (ACSC) issued a High-rated alert on 19 August for active exploitation in Australia of N-able and N-central remote monitoring and management (RMM) platform vulnerabilities, tracked as CVE-2026-18556 and CVE-2026-18577, urging organisations to assess exposure and apply mitigations. This is a direct and rare AU-first active-threat warning and reinforces the RMM supply-chain theme running through the year. Second, Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal โ€” collectively "CoSnitch" (CVE-2026-24301) โ€” that let a single click on a crafted link silently exfiltrate data from connected apps; the flaws turn on an undocumented `autorun=1` URL parameter Copilot itself surfaced during testing, and Microsoft shipped patches on 18 August. Third, CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalogue on 18 August covering Microsoft Internet Key Exchange (IKE), Broadcom VMware vCenter, Microsoft SharePoint and Apple macOS, with the catalogue's MLflow SSRF entry updated on 19 August โ€” the third straight adult cyber-news day anchored by CISA patch prioritisation.

The ACSC's active-exploitation alert for N-able/N-central is the standout Australian development and should be treated as priority remediation for any local organisation running remote-monitoring software. RMM tools have been a defining attack vector in Australian-targeted intrusions throughout 2026, and this is the clearest active-exploitation warning to Australian organisations in the cycle. It sits alongside the ASD ISM and Essential Eight patching obligations โ€” under APRA CPS 234, regulated financial firms holding N-able/N-central in scope face a direct compliance imperative to assess exposure promptly. The deepfake-scam warning from ASIC, which surfaced in this cycle, continues the AU regulatory focus on AI-enabled fraud and identity theft against Australian consumers and investors, reinforcing the OAIC Notifiable Data Breaches scheme and ACSC guidance on AI-assisted social engineering. The CoSnitch findings on consumer AI assistants are directly relevant to Australian individuals and the growing Base-layer of agentic AI tools in local enterprises, while the week's US RMM/KEV activity is a Five Eyes signal Australian defenders should monitor as BOD 26-04-style prioritisation continues.

3
Government
4
Global (Macro)
1
Healthcare
2
Financial Services
1
Transport

Incident Map

(static view)
CriticalSevereElevatedGuardeddarker = more incidents
Australia
3
United States
3
Germany
1
United Kingdom
1

Pan-regional / not map-pinned: ๐ŸŒ Global: 3

4 countries ยท 11 stories ยท click a country for its stories. Interactive map loads on the hosted site.

๐ŸŽฏ Geo-attribution: 8/11 stories located directly from text (73%).

๐ŸŽฏ Geo-attribution: 8/11 stories located directly from text (73%).

Government 3 stories

1

ACSC Issues High-Rated Alert on Active Exploitation of N-able Slopes โ€” Australia Priority

The Australian Cyber Security Centre (ACSC) issued a High-rated alert on 19 August warning of active exploitation in Australia of N-able and N-central remote monitoring and management (RMM) vulnerabilities tracked as CVE-2026-18556 and CVE-2026-18577. The ACSC rated the alert High and directed Australian organisations โ€” across business, critical infrastructure and government โ€” to assess exposure and apply mitigations. This is a direct, Australia-specific active-threat warning in an RMM product class long-targeted by Australian campaigns. **Verification: Verified** (official ACSC alert; High rating).

ACSCโ— Tier 1/4 โ€” Official / First-party2026-08-19
2

Berlin Cuts Two State Ministries Off Government Network After Security Breach

Berlin cut two state ministries off the German government network following a security breach, in an operation actors reportedly linked to the supply-chain issue affecting the government network. The move is the latest in a wave of German and European government-network incidents this year, and illustrates the operational trade-off between availability and containment when a breach is detected in shared government infrastructure. **Verification: Reported** (outlet-reported incident; government confirmed network separation). **Breach: Probable breach**

The Recordโ— Tier 2/4 โ€” Established cyber journalism2026-08-18
3

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue on 18 August: Microsoft Internet Key Exchange (IKE) service extensions (CVE-2026-33824), Broadcom VMware vCenter path traversal (CVE-2026-59310), Microsoft SharePoint weak authentication (CVE-2026-55040) and Apple macOS improper authentication (CVE-2026-65400). The additions carry a two-week federal remediation obligation under BOD 26-04 and signal confirmed exploitation in the wild across Windows, VMware, SharePoint and macOS. A further MLflow SSRF entry was added on 19 August (CVE-2026-64849). **Verification: Verified** (official CISA KEV entries).

CISAโ— Tier 1/4 โ€” Official / First-party (vulnerability feed)2026-08-18

Global (Macro) 4 stories

1

Microsoft Copilot Personal Flaws Let One Click Exfiltrate Data From Connected Apps โ€” CoSnitch

Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal that could allow a single click on a crafted link to silently exfiltrate data from connected apps and other information available to the victim's Copilot session. The flaws, collectively named **CoSnitch** (CVE-2026-24301), turn in part on an undocumented `autorun=1` URL parameter that Copilot itself surfaced during testing; the researchers reported the issue to Microsoft in December 2025 and patches shipped 18 August. The group found no evidence of in-the-wild exploitation. **Verification: Verified** (vendor-researched disclosure, patch published).

The Hacker Newsโ— Tier 2/4 โ€” Established cyber journalism2026-08-18
2

Critical GitLab GraphQL Flaw Lets Unauthenticated Attackers Delete Public Projects

GitLab patched a critical vulnerability in its GraphQL API that could allow an unauthenticated attacker to delete public projects, disclosed with a zero-click angle. The flaw, reported on 17 August, adds to a busy week of critical web-application findings and reinforces GitLab's position as a high-value, internet-facing target. **Verification: Verified** (vendor advisory; reported by multiple outlets).

The Hacker Newsโ— Tier 2/4 โ€” Established cyber journalism2026-08-17
3

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

Researchers documented a single threat actor continuously scraping both Salesforce and ServiceNow web portals since 2025, harvesting data exposed in those customer-facing SaaS platforms. The finding underscores the pivot to **SaaS-scraping as a low-friction mass-compromise technique**, where public/waters surfaces on widely used enterprise platforms are mined at scale rather than exploited by a single breach. **Verification: Reported** (researcher-identified campaign; no single exclusive newscaster). **Breach: Unverified claim** (attributed scraping activity).

The Hacker Newsโ— Tier 2/4 โ€” Established cyber journalism2026-08-18
4

Medusa Ransomware Tallying Hundreds of New Victims; CISA Updates Tactics

CISA identified more than 200 victims of the Medusa ransomware operation over the last year and updated its advisory on the group's tactics, techniques and procedures. The updated advisory reflects a continuing and high-volume Ransomware-as-a-Service targeting pattern and gives defenders fresh detection guidance, in line with CISA's ongoing KEV and advisory cadence. **Verification: Verified** (CISA/agency advisory reported by the outlet). **Breach: Confirmed breach** (multiple victim entities per advisory).

CyberScoopโ— Tier 2/4 โ€” Established cyber journalism2026-08-18

Healthcare 1 story

1

American Addiction Centers & Octopus Pathology Disclose Hacking Incidents

American Addiction Centers and Oculus (Octopus) Pathology disclosed hacking incidents involving unauthorised access to protected health information. Both entities filed the required notifications consistent with federal and state breach-notification rules; details on record volumes and impacted individuals were limited in the early disclosures. **Verification: Verified** (companies disclosed incidents to regulators). **Breach: Confirmed breach**

HIPAA Journalโ— Tier 2/4 โ€” Established cyber journalism2026-08-18

Financial Services 2 stories

1

ASIC Warns of Deepfake Scam Surge Against Australian Consumers

The Australian Securities and Investments Commission (ASIC) warned of a surge in deepfake-related scams targeting Australian consumers and investors, including authorised-transaction and high-stream fake celebrity/authority models. The warning reinforces the OAIC and ACSC standing guidance on AI-enabled fraud and identity theft, and flags the growing consumer exposure to AI-generated visual content. **Verification: Verified** (Australian regulator public warning).

Finextraโ— Tier 2/4 โ€” Established cyber journalism2026-08-17
2

ANZ Warns of Troubling 'Scam-Coaching' Trend

Australian bank ANZ warned of a "scam-coaching" trend, in which fraudsters coach victims to lie to their bank to subvert scam-prevention controls โ€” a variant of social-engineering designed to defeat the very protections banks and regulators have deployed. The warning is directly relevant to the OAIC Notifiable Data Breach scheme's anti-fraud regime and to the industry's escalating fight against authorised-push-payment scams. **Verification: Verified** (Australian bank warning).

Finextraโ— Tier 2/4 โ€” Established cyber journalism2026-08-17

Transport 1 story

1

Six Arrested as UK Police Target Cargo Theft Costing ยฃ70m+ a Year

UK police arrested six people in an operation targeting cargo and freight theft โ€” a logistics-side physical-cyber overlap that moves goods loss into the supply-chain risk picture. The arrests underscore the convergence of organised freight crime with digital coordination of supply chains used by Australian and global shippers. **Verification: Verified** (police action-reported).

FreightWavesโ— Tier 3/4 โ€” Moderate / General news2026-08-18

Analytics

Sector distribution

Government
3
Global (Macro)
4
Healthcare
1
Financial Services
2
Transport
1

Source breakdown

The Hacker News
3
Finextra
2
ACSC
1
The Record
1
CISA
1
CyberScoop
1
HIPAA Journal
1
FreightWaves
1
11stories
Government 3
Global (Macro) 4
Healthcare 1
Financial Services 2
Transport 1

Source Reliability Index

TierLabelDescription
โ— Tier 1Very HighOfficial / first-party
โ— Tier 2HighEstablished cyber journalism
โ— Tier 3ModerateGeneral tech/news media
โ— Tier 4LowSocial / unverified