Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
Washington's "economic D-Day" against Iran produced the day's headline cyber action: Treasury sanctioned four alleged Iranian hackers โ three operators and a leader of an MOIS-directed crew tied to the Mabna Institute โ for compromising and exfiltrating data from US energy, defence, healthcare, IT and financial companies since late 2023, the second action against the same network in a fortnight and part of a wider sanctions wave hitting digital assets, technology, gold, aviation and shipping. In Europe, Norway's shared government digital infrastructure (Digdir) spent Monday under a heavy DDoS attack that knocked ID-porten logins, e-signatures and agency data exchange partially offline โ its third attack this year โ while CISA published a rare public red-team advisory showing a tale of two detections: a water utility quarantined simulated spearphishing compromises within minutes while a government organisation let the same activity run undetected to domain dominance. On the breach desk, employee-benefits platform Paylogix disclosed that Akira ransomware operators stole Social Security numbers, health insurance and medical data on tens of thousands of people over five days last November, hospital operator Nutex Health told the SEC that an unauthorised party exfiltrated private information from its servers across its 28-facility network, and Georgia's Tift Regional Health System agreed to pay $1.2 million over the 2022 Hive ransomware breach that exposed 180,142 patients' data. CISA also added a Gitea code-injection flaw (CVE-2026-60004) to the KEV catalog, and SOCRadar documented AnonyMousKIT, a phishing-as-a-service platform using voice AI agents to talk stolen-iPhone owners into surrendering passcodes.
ASD's ACSC published no new advisories overnight โ the TeamCity On-Premises exploitation alert from 24 August remains its most recent and operative guidance, and Australian teams still working that alert should note the parallel international picture: Shadowserver now counts 274 compromised Zimbra instances from the CVE-2026-73570 campaign CISA KEV-listed on 21 August, a reminder that these build-and-mail-infrastructure warnings escalate fast (the ACSC's own joint advisory on Russian LAUNDRY BEAR actors phishing Zimbra users remains live guidance). The Treasury sanctions matter to Australian organisations less as direct impact than as targeting intelligence: the designated crew hit exactly the sectors Australia exports to the US alliance economy โ energy, defence contracting, healthcare, IT and finance โ and Treasury's explicit framing of MOIS direction versus personal enrichment is useful attribution texture for Australian incident-response teams assessing Iranian-state interest. The UK's proposed secret vendor-blocking powers, adapted from the Huawei regime, are the closest analogue to debates Canberra has already settled through the SOCI Act's enhanced obligations โ worth watching for how the UK handles the transparency trade-offs Australia legislated through a different door. And the CISA red-team report's central finding โ thousands of queued EDR alerts burying the real ones โ is the operational failure mode the ACSC's Essential Eight detection requirements exist to counteract.
Three threads from the past week converge today. First, the Iran file has moved from warning to action: last week's digests carried US warnings of AI-assisted attacks on Siemens PLCs in water facilities (19โ20 August) and Trump-era accusations around Minnesota water incidents; today Treasury named and sanctioned the alleged MOIS-directed operators, formalising the attribution the technical advisories implied โ with Tehran vowing consequences and the war nearing five months, expect Iranian-linked intrusion activity to remain elevated rather than taper. Second, the AI-on-offence trend that ran through last week (AI-built Weedhack sites, AI-assisted UAT-10147 rootkits, Talos' agentic-AI assessment) gained its most consumer-facing example yet: AnonyMousKIT's voice AI agents conducting passcode-phishing calls at roughly $0.10 an attempt across 506 domains โ industrialised social engineering at commodity prices, sitting alongside Mirage2FA's session-theft surge hitting some 4,500 US and EU Microsoft 365 tenants. Third, regulators are hardening supply-chain levers in parallel: the UK's vendor-related directions (25 August) extend Huawei-style blocking into MSPs, data centres and health, while New Zealand moves its own platform-regulation bill and the EU/US continue their respective regimes โ a Five Eyes-wide regulatory wave visible across digests since mid-August. Watch this week for whether the Zimbra compromise count keeps climbing toward four figures, whether the UK amendments survive House of Lords committee in September intact, and for possible follow-on Iran designations as the "economic D-Day" rolls forward.
Incident Map
Global (Macro) 2 stories
US Treasury Sanctions Four Alleged MOIS-Directed Iranian Hackers Behind Critical Infrastructure Breaches
The Treasury Department sanctioned three Iranian hackers โ Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh and Mohammad Reza Kadkhoda'i โ plus gang leader Mojtaba Ghal'eh-Kuhi, for compromising and exfiltrating data from multiple US critical-infrastructure companies since late 2023, spanning energy, defence contracting, healthcare, IT and finance. The action, announced as part of Treasury Secretary Bessent's "economic D-Day" sanctions package, follows an indictment unsealed against Mabna Institute-affiliated hackers just weeks ago and notes some members' profit-seeking extended to targeting Iranian companies themselves. Secondary-sanctions categories now cover digital assets, technology, gold, aviation and shipping; Iran has vowed consequences. **Verification:** Verified
AnonyMousKIT PhaaS Platform Uses Voice AI Agents to Phish iPhone Passcodes at Scale
SOCRadar researchers mapped AnonyMousKIT, a phishing-as-a-service platform active since early 2024 that automates unlocking stolen iPhones: 506 connected domains, 168 reseller storefronts, and recovered transcripts of 200 victim calls handled by a voice AI agent running five personas (including "Alice from Apple Support") at about $0.10 per attempt, with 90% of calls to Brazil. Impersonating Apple with correct model and IMEI details, the chain harvests device passcodes, Apple Account credentials and MFA codes โ exposing iCloud backups and Keychain passwords โ before resale. A small percentage of targets were government and corporate mailboxes. **Verification:** Verified
Government 4 stories
Massive DDoS Disrupts Norway's Shared Government Digital Infrastructure for a Second Day
A large distributed denial-of-service attack began at 03:38 CEST Monday against the infrastructure underpinning Norway's Digitalisation Agency (Digdir) shared services โ public-service logins, electronic IDs and signatures, secure digital mail and inter-agency data exchange โ leaving several services fully unavailable for periods, with ID-porten and eSignering still partially degraded. Digdir director Frode Danielsen said there is no indication of a security breach or personal-data compromise, and noted it is the third DDoS this year after June and 3 August attacks. NSM and Datatilsynet are notified; dependent platforms Altinn and Skatteetaten warned users of login failures. No attribution yet, though Norwegian media speculate about Russia. **Verification:** Verified
CISA Red Team Report: Water Utility Detected Simulated Attack in Minutes, Government Organisation Missed Domain-Wide Compromise
CISA's rare public red-team advisory (AA26-237A) describes two voluntary engagements: at a water organisation ("Organization B"), defenders triaged spearphishing alerts and quarantined workstations within 2, 10 and 20 minutes, then detected and isolated a second push reaching the OT DMZ bastion host; at a government organisation ("Organization A"), red teamers moved from internal phishing to domain-elevated privileges and sensitive business systems undetected, their alerts buried among thousands of false positives in a SOC whose staff saw but did not respond to EDR notifications. Both organisations underestimated cloud risk, lacked Conditional Access for workload identities, and had no token-revocation process. **Verification:** Verified
CISA Adds Actively Exploited Gitea Code-Injection Flaw (CVE-2026-60004) to KEV Catalog
CISA added CVE-2026-60004, a code-injection vulnerability in the Gitea self-hosted Git service, to the Known Exploited Vulnerabilities Catalog on 25 August based on evidence of active exploitation โ the sole addition that day. FCEB agencies must remediate under BOD 26-04 timelines and check for pre-patch compromise; self-hosted Gitea instances are common in small development teams and internal toolchains, making exposure reviews worthwhile well beyond US federal agencies. It follows last week's additions covering Oracle HTTP Server (CVE-2026-21962) and Zimbra (CVE-2026-73570). **Verification:** Verified
UK Seeks Powers to Secretly Block Risky Tech Suppliers Across Critical Sectors
Amendments to the UK Cyber Security and Resilience Bill, tabled Monday ahead of September's House of Lords committee stage, would let ministers issue "vendor-related directions" barring suppliers deemed critical national-security risks from serving managed service providers, data centres, digital infrastructure and the energy, water, transport and health sectors โ adapting the Huawei 5G mechanism while removing its transparency safeguards: no public designation of the vendor, no duty to give the vendor a copy of the order, and recipients can be barred from discussing it. Only the receiving company must be named, with annual reporting to Parliament on direction counts. Cybersecurity minister Liz Lloyd framed the powers as acting "before a threat materialises". **Verification:** Verified
Financial Services 1 story
Akira Ransomware Breach at Benefits Platform Paylogix Exposed SSNs, Health and Financial Data on Tens of Thousands
Employee-benefits administrator Paylogix disclosed that hackers stole files from its network between 13 and 18 November 2025, including Social Security numbers, electronic signatures, financial account details, health insurance information, medical data and passport numbers; the company was listed on the Akira ransomware leak site in January though it has not attributed the attack itself. State filings show 64,383 affected in South Carolina alone, plus 2,304 in New Hampshire and 1,102 in Vermont, with notices also filed in California, Massachusetts, New Jersey and other states โ implying a national total well above 67,000. Law-enforcement is engaged and several class actions are being organised. Akira remains among the most active ransomware families, with Google incident responders ranking it second-most-observed malware family of 2025. **Verification:** Verified **Breach:** Confirmed breach
Healthcare 2 stories
Hospital Operator Nutex Health Tells SEC Data Was Exfiltrated in Cyberattack Across Its 28-Facility Network
Nutex Health, a Nasdaq-listed for-profit hospital operator running 28 facilities across 12 states with $875 million in 2025 revenue, disclosed in an SEC filing that an unauthorised third party accessed and exfiltrated information from company servers, "including some information that may be private and/or confidential". The company engaged external forensics, activated its response plan, contained the intrusion and notified law enforcement, but has yet to determine whether patient, employee, provider or business information was affected; it reports no material operational or financial impact as of 24 August. No threat actor has claimed the attack. **Verification:** Verified **Breach:** Confirmed breach
Tift Regional Health System Pays $1.2 Million to Settle Class Action Over 2022 Hive Ransomware Breach
Georgia's Tift Regional Health System (operating as Southwell) agreed to pay $1.2 million to settle consolidated class actions over the August 2022 ransomware attack claimed by Hive, which reported stealing a terabyte of data and leaked some of it; HHS OCR breach reporting covered 180,142 individuals whose names, birth dates, Social Security numbers and medical information were potentially accessed between 11 and 17 August 2022. The litigation specifically faulted encryption and data-retention failures and notification delays โ victims waited almost a year, until 11 August 2023, to be told. **Verification:** Verified **Breach:** Confirmed breach
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| โ Tier 1 | Very High | Official / first-party |
| โ Tier 2 | High | Established cyber journalism |
| โ Tier 3 | Moderate | General tech/news media |
| โ Tier 4 | Low | Social / unverified |