Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
The day's headline is domestic: ASD's Australian Cyber Security Centre has issued a high-rated alert on active exploitation of JetBrains TeamCity On-Premises servers inside Australia, warning that CVE-2026-63077 (CVSS 9.8) lets an unauthenticated attacker with HTTP(S) access bypass authentication and execute arbitrary operating-system commands on every On-Prem version of the CI/CD platform. In Washington, CISA added an actively exploited Oracle HTTP Server / WebLogic proxy plug-in flaw (CVE-2026-21962) to the KEV catalog โ the sole new addition on 24 August โ while Red Hat patched a critical (9.1) unauthenticated account-takeover flaw in the Keycloak identity server that has no known exploitation yet. On the incident side, ReliaQuest publicly dissected a failed ShinyHunters social-engineering attack against itself โ credential phishing via a `reliaquest.claims` lookalike domain defeated by device-trust controls โ and South Korean authorities detailed how a government-backed startup platform leaked roughly 5,000 applicants' data after an API exposed the encryption key alongside the ciphertext it protected.
The ACSC TeamCity alert is the operative action for Australian organisations this morning and outranks everything else in this digest: review environments for vulnerable TeamCity On-Premises servers, question whether build interfaces need internet exposure at all, apply vendor mitigations, and check third-party/MSP-managed instances โ the alert explicitly asks organisations to confirm their providers have patched and are monitoring, with vendor IoCs available for hunting. The alert's SMB audience tag matters because TeamCity frequently sits in small development shops rather than enterprise SOCs. Elsewhere the day offers no new OAIC notifications or APRA actions; the nearest allied regulatory signal is the FTC-side TikTok COPPA settlement coverage continuing from Friday, which lands amid Australia's own age-assurance rollout. The Keycloak flaw is worth Australian defenders' attention purely on ubiquity grounds โ open-source identity infrastructure is common across federal and state government shared services, and an unauthenticated reset-to-takeover path is the kind of bug that gets chained once public exploits appear.
Three threads from the past week converge today. First, identity and build infrastructure are under concentrated pressure: last week brought trojanised npm packages and Rust registry poisoning (digests 21โ24 August), and today adds authentication-bypass flaws at both the CI/CD layer (TeamCity, actively exploited) and the identity layer (Keycloak, patched pre-exploitation) โ the tooling that vouches for who and what ships code. Second, the attackers-are-hitting-the-defenders pattern sharpened: Health-ISAC warned about ShinyHunters targeting healthcare data-theft surface twice this month (1 and 4 August), and the gang's vishing campaign has now been turned on ReliaQuest, a firm that had publicly documented the campaign days earlier โ a reminder that publishing threat intelligence makes you a target for proof-of-work retaliation. Third, the AI-as-offensive-instrument trend rolls on: Talos' assessment that UAT-10147's Linux rootkit showed AI-assisted authorship (20โ21 August) sits alongside this week's AI-built malicious sites (Weedhack via Lovable) and AI-based crawling named in the Korean breach investigation โ AI is now cited on both sides of incidents as tool and technique. Watch this week for a possible CISA joint advisory on TeamCity if US exploitation widens, mirroring the Siemens S7 pattern from 19 August, and for Keycloak exploitation status to appear in future KEV additions if a public exploit lands.
Incident Map
Government 3 stories
ASD's ACSC Alerts on Active Exploitation of TeamCity On-Premises Servers Within Australia
ASD's ACSC has observed active exploitation of CVE-2026-63077 (Critical, CVSS 9.8) affecting all versions of JetBrains TeamCity On-Premises within Australia. An unauthenticated attacker with HTTP(S) access can bypass authentication checks and execute arbitrary operating-system commands on the CI/CD server. No specific industry or sector is being targeted. The centre advises reviewing exposure, applying vendor mitigations and IoCs, and confirming MSP-managed instances are patched and monitored. **Verification:** Verified
CISA Adds Actively Exploited Oracle HTTP Server Flaw (CVE-2026-21962) to KEV Catalog
CISA added CVE-2026-21962, an improper access-control vulnerability in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to the Known Exploited Vulnerabilities Catalog on 24 August โ the sole addition that day. Federal Civilian Executive Branch agencies must patch on the standard two-week deadline; the KEV listing confirms the flaw is being exploited in practice, making it priority patching for any organisation fronting WebLogic with OHS. Zimbra (added 21 August) remains the other recent KEV entry under active remediation. **Verification:** Verified
South Korean Government Startup Platform Leaked ~5,000 Applicants After Exposing Encryption Key via API
South Korea's Ministry of SMEs and Startups, investigating with the NIS and National Police Agency, confirmed that the Modu-ui Changup startup-support platform leaked email addresses, evaluation comments and startup-idea summaries for about 5,000 successful applicants because an API response exposed the encryption key alongside encrypted data โ which crawlers, reportedly including AI-based crawling, harvested despite privacy settings. Authorities identified 39 South Korean IP addresses accessing the data. The case is a textbook demonstration that encryption without key management is decoration. **Verification:** Verified **Breach:** Confirmed breach
Global (Macro) 1 story
Critical Keycloak Password-Reset Flaw (CVE-2026-18963) Lets Unauthenticated Attackers Take Over Any Account
Red Hat and the Keycloak project patched CVE-2026-18963 (CVSS 9.1), a weak password-recovery mechanism flaw (CWE-640) that lets an unauthenticated remote attacker take over arbitrary accounts by forcing password resets through improper state validation in the reset-credential flow. Upstream fixes shipped in Keycloak 26.7.2 (released 19 August) with RHBK builds 26.4.15 and 26.6.6 also patched; there is no evidence of exploitation or public exploit as of 24 August. Given Keycloak's role guarding enterprise single sign-on, defenders should treat patching as urgent before a weaponised chain appears. **Verification:** Verified
Retail & Entertainment & Sport 2 stories
ReliaQuest Confirms Failed ShinyHunters Data-Theft Attack After Vishing Campaign Turned on the Defender
ReliaQuest disclosed that ShinyHunters-linked attackers vishing-called employees using a lookalike `reliaquest.claims` SSO page and the name of a real security staff member; one employee surrendered credentials and approved an MFA push, granting temporary view-only access to the identity dashboard โ where device-trust controls blocked every subsequent application access. The company terminated sessions, rotated tokens and found no persistence, application access or customer-data exposure; ShinyHunters listed the firm on its leak site and conceded the access was view-only. The gang had registered `.claims` impersonation domains that ReliaQuest itself flagged days earlier. **Verification:** Verified **Breach:** Probable breach
Weedhack Malware Spreads Via Fake Minecraft Clients, With One Lookalike Site Built Using Lovable AI
McAfee Labs reports websites are still distributing the Weedhack malware family to gamers through convincing fake Minecraft client sites โ complete with branding, FAQs, install guides and links to genuine GitHub repositories โ with more than 6,300 malicious-site access attempts detected and blocked. One lookalike site was built with Lovable, an AI-powered website builder, underscoring how generative tooling lowers the cost of convincing phishing infrastructure. The multi-stage attack culminates in JAR payloads deployed on the victim's machine. **Verification:** Verified
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| โ Tier 1 | Very High | Official / first-party |
| โ Tier 2 | High | Established cyber journalism |
| โ Tier 3 | Moderate | General tech/news media |
| โ Tier 4 | Low | Social / unverified |