Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
The AI-as-attacker thesis moved from proof of concept to observed intrusion. Unit 42 describes responding to a ransomware attack in which a human operator drove a fleet of frontier-AI agents that breached an enterprise network autonomously, deployed more than 50 MITRE ATT&CK techniques and claimed master keys to the victim's cloud AI infrastructure โ compressing what it estimates would have been roughly two weeks of multi-red-team human work into under ten hours, and leaving an 80-page technical audit of the victim's security posture behind. That lands directly on the heels of yesterday's Forescout-Claude PLC exploit and the Financial Stability Board's frontier-AI warning, and the same supply chain show up again in the vulnerability line: CISA added seven new Known Exploited Vulnerabilities including the actively exploited JFrog Artifactory authentication bypass (CVE-2026-82329), and Manifold's "Universal Evil" research showed malicious `.git` configuration files can make Claude Code, Codex, goose and other AI coding agents execute attacker code before the user ever approves a trust prompt (CVE-2026-72718). Independently, US prosecutors indicted a Russian national accused of infecting 80,000 freelancers with TeamSpy malware, and the ShinyHunters healthcare-data wave continued with McKesson confirming data theft from its third-party applications under a reported $55 million extortion demand.
No new ACSC alerts were published in this window; the operative advisory remains the 24 August high-rated alert on active exploitation of TeamCity On-Premise servers within Australia (CVE-2026-63077). The most directly relevant Australian development this cycle is regulatory, not incident: Australia's Privacy Act reform process advanced its second wave, with the Government publishing initial proposals that continue to reshape breach-notification and consent obligations for Australian organisations โ a reminder that the disclosure duty around vendor-procured SaaS and identity data, the shared thread through today's McKesson, Dropbox and Austrian identity-chain stories, is tightening. On the technical front, JFrog Artifactory is a repository manager Australian build and deployment teams run self-managed; an unauthenticated bypass that forges admin tokens (CVE-2026-82329) is exactly the trusted-artifact poisoning class APRA CPS 234 and the ASD Essential Eight's application-control and patching measures are designed to blunt, so Australian firms running self-hosted Artifactory should treat the KEV addition as urgent. The "malicious .git configs" research is a direct caution for Australian developers and infosec teams now standardising on AI coding agents โ a poisoned repository can silently turn a trusted CLI into an execution primitive โ and the ShinyHunters vishing-to-third-party-SaaS pattern behind McKesson mirrors the vendor-chain risk this page flagged through Jack Henry and CareCloud in recent days.
The week's through-line is the consolidation of frontier AI into first-class attack tooling, and today closes the loop between demonstrated capability and observed use. Where Forescout's Claude-driven PLC exploit and UAC-0099's anti-LLM prompt poisoning (both 01โ02 September) were researchers and adversaries demonstrating the edges, Unit 42's case is a real-world intrusion where a human operator's only job was direction while agents executed, re-planned and reported โ and the .git-config finding shows the same agent class is itself a supply-chain attack surface. These are no longer separate stories: Vercel's CEO publicly speculated a link between the JFrog bypass and recent autonomous-AI-agent research, and JFrog's token model (access tokens persist independent of the patch) means an already-forged admin token survives the upgrade โ a concrete, shared mitigation both AU and allied defenders should chase today rather than at the next patch cycle. Geopolitically, the pro-Ukraine cyber-ecosystem is reorganising: the newly surfaced VantaCore rig (F6 attributes it as a rebrand of Thor) is building custom ransomware rather than relying on LockBit/Babuk, a move partly motivated by distrust of software with Russian roots, while the Russian state-apparatus thread continues with the indictment of a TeamSpy operator. Separately, the first confirmed Pegasus infection of 2026 alongside a new NoviSpy variant on Serbian activists and officials (14 targets) marks the year's largest documented surveillance wave, carried out with a zero-click exploit that Apple's update has since closed โ a reminder that commercial spyware remains the most reliable state-surveillance instrument and that patching mobile OS is the operative control. Watch whether JFrog discloses victim counts and whether the idscan.net licence breach (yesterday) crystallises into an official notification with a full count.
Incident Map
Defence 3 stories
US Charges Russian National for Malware Campaign That Infected 80,000 Freelancers
Searzhudin Tamirlanovich Aktulaev appeared in a San Francisco federal court after a May 2025 arrest in Cyprus and extradition to the US, facing conspiracy, aggravated identity theft and computer-damage charges carrying a maximum 20-year sentence. Prosecutors allege that between June 2016 and November 2017 he used 255 fake accounts on a freelance-employment platform's messaging system to distribute TVRAT (a.k.a. TVSpy/TeamSpy) via malicious Excel attachments, exploiting a TeamViewer flaw for remote takeover, alongside a VNC-exploiting DarkVNC strain. About 80,000 users were infected โ roughly half in the US, mostly in California โ and the operator harvested e-commerce credentials and personal data for fraud; the 2021 indictment remains sealed and the company targeted is unnamed. Verification: Verified
New Pro-Ukraine 'VantaCore' Gang Targets Russian Companies With Custom Ransomware
Russian cybersecurity firm F6 documented VantaCore, a ransomware group it assesses as a rebrand of the pro-Ukrainian operation Thor, targeting at least seven Russian organisations since its August detection (leak site dating to early June). Operating as a ransomware-as-a-service outfit with a Tor-based comms channel, VantaCore builds its own toolset โ a proprietary ransomware encrypting servers and endpoints, a VantaCoreLoader propagator, a VantaCoreRAT backdoor and a SnowKiller tool to disable security software โ with ransom demands reaching millions of dollars. F6 says the shift away from LockBit 3 Black and Babuk reflects usable weaknesses in those tools and pro-Ukrainian reluctance to rely on Russian-rooted software. Verification: Reported
First Confirmed Pegasus Infection of 2026 Plus NoviSpy Variant Found on Serbian Activists
The SHARE Foundation said 14 people โ including a member of parliament and a local government official โ were targeted in what it called the largest documented surveillance wave in Serbia, coinciding with protests after the 2024 Novi Sad canopy collapse and ahead of October parliamentary elections. Citizen Lab confirmed a Pegasus infection on a student activist "with high probability" via a zero-click exploit used from December to January, while Amnesty International confirmed two devices carried a new NoviSpy variant, pointing to Serbian police or secret-service involvement during detention. Citizen Lab's Bill Marczak urged users to update to the latest iOS, noting Apple's updates have closed this exploit. Verification: Verified
Healthcare 3 stories
McKesson Confirms Data Theft in Cyberattack on Third-Party Applications
Drug distributor and supply giant McKesson said an unauthorised party gained access to its third-party applications and stole data, affecting customers in its oncology, multispecialty and medical-surgical businesses, with employee data also taken; the company has "reasonable assurance" there is no ongoing activity and has not yet determined materiality. ShinyHunters claimed responsibility, telling BleepingComputer it used voice phishing to compromise employee accounts and reach cloud applications, demanding a reported $55 million. The number affected remains unknown, but McKesson's position โ roughly 40,000 daily deliveries to nearly every US care site โ makes it an unusually connected healthcare intermediary, and Health-ISAC flagged the vishing-to-SSO pattern as a ShinyHunters signature in July. Verification: Verified Breach: Confirmed breach
DaVita Agrees to Pay $15M to Settle Claims From 2025 Interlock Breach
Kidney-care provider DaVita will pay US$15 million to settle a consolidated class action over a ransomware attack last year at the hands of Interlock that affected roughly 2.7 million people, after the group published victims' personal data on the dark web when the company refused to pay. A Colorado judge signed the preliminary settlement last week; final approval is pending next year. The breach potentially exposed names, addresses, Social Security numbers, health insurance information, dialysis lab results and images of written cheques, and followed Interlock's separate attack on Kettering Health, with Health-ISAC profiling the group as a repeat healthcare threat actor operating double extortion. Verification: Verified Breach: Confirmed breach
Oncology Firm Novocure Discloses Cyberattack Affecting More Than 1,400 Patients
Medtech and oncology firm Novocure disclosed in a 1 September SEC Form 8-K that it detected unauthorised access to some systems via a subsidiary in mid-August, with containment and an external forensic investigation under way. Impact is reported as limited: roughly 1,400 US patients had internal company ID numbers exposed (no names or identifying data), fewer than 50 patients in the Western US had additional identifying information exposed, and general contact information for US healthcare providers and employees was affected. Novocure says no medical treatment devices were accessed, operations are fully functional and it does not expect a material financial impact; the threat group and nature of the incident were not disclosed. Verification: Verified Breach: Confirmed breach
Education 1 story
Bennett College Data Breach Affects More Than 30,000 People
Greensboro's Bennett College, a private historically Black women's liberal-arts college, disclosed that unauthorised access to its network occurred from 27 October to 15 November last year, affecting at least 30,065 individuals including 10,875 in North Carolina, per a notification filed with the state Attorney General. Affected data may include names, Social Security numbers, driver's licence and state ID numbers, dates of birth, alien registration numbers, financial account information, taxpayer IDs, passport numbers, digital signatures, medical information and health insurance data. Ransomware monitor sites DeXpose and Galaxy Warden reported the college on Incransom's leak site on 6 December; the college has engaged forensic specialists and is offering credit monitoring. Verification: Verified Breach: Confirmed breach
Government 2 stories
CISA Adds Seven Vulnerabilities to Known Exploited Catalog
CISA added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on 2 September: BerriAI LiteLLM improper authentication (CVE-2026-59822), Kludex Starlette HTTP request/response smuggling (CVE-2026-48710), Kestra OSS OS command injection (CVE-2026-49869), the actively exploited JFrog Artifactory authentication bypass (CVE-2026-82329), Sangoma Switchvox SQL injection (CVE-2026-9586) and the two SonicWall SMA1000 command-injection flaws (CVE-2026-83548 / CVE-2026-83549) already covered in yesterday's digest. Federal agencies face binding operational directives to patch, and the catalog is the authoritative signal for which flaws are confirmed in the wild. Verification: Verified
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
Check Point continuity research documented malicious Apache modules, built with a component called 3snake, planted on compromised web servers to route site traffic toward gambling pages, with Brazilian government sites among those affected; 3snake's documentation states it targets rooted servers and extracts strings related to password-based authentication. Check Point ties the cluster to Earth Berberoka, an actor Trend Micro documented in 2022 targeting gambling sites across Asia, with links to the Xnote Linux backdoor and oRAT. The vendor published no count of compromised servers or module filenames/hashes to aid detection, and no affected organisation is named. Verification: Reported
Transport 1 story
Ceva Logistics Sued Over Theft of Employee Records in July Cyberattack
A former employee filed a class action against France-based freight and contract-logistics provider Ceva Logistics in the Southern District of Texas, alleging the company failed to protect bank account details and Social Security numbers stolen during a cyber intrusion in late July that disrupted operations at eight European warehouses serving retailers in the Netherlands and elsewhere. The suit, seeking at least $5 million, alleges Ceva failed to maintain reasonable security following a previous incident โ SOCRadar attributes a September 2025 CoinbaseCartel ransomware attack โ and has not formally notified employees, allowing fraud risk to persist; the plaintiff reports fraudulent card activity. Verification: Reported Breach: Probable breach
Retail & Entertainment & Sport 1 story
Dropbox Accounts Breached via Lenovo Email-Verification Flaw
Dropbox warned some users that unauthorised parties accessed their accounts by exploiting a flaw in Lenovo's email-verification process to register fraudulent Lenovo IDs under victims' email addresses, then using the federated identity to log into Dropbox accounts without their passwords; Dropbox uses Lenovo Identity Provider Services in its authentication stack. Per Reuters, roughly 5,000 accounts were accessed between 4 and 21 August, with some content viewed or downloaded. Dropbox has expired sessions authenticated through Lenovo IDs and now requires a Dropbox account password alongside Lenovo ID authentication; Lenovo described the issue as a legacy integration exploit and says Lenovo customers were not affected. Verification: Verified Breach: Confirmed breach
Global (Macro) 3 stories
Unit 42: Frontier-AI Agents Breached Enterprise Autonomously in Under 10 Hours During Ransomware Attack
Unit 42's incident-response publication documents a ransomware intrusion in which a human attacker used frontier-AI models and attack-specific agentic frameworks to breach an enterprise autonomously: deploying more than 50 MITRE ATT&CK techniques, mapping internal microservices, harvesting secrets from source repositories and the secret manager, seizing root credentials, triggering unauthorised CI/CD builds, and turning the victim's AI endpoints into post-compromise compute โ effort Unit 42 estimates would take human operators around two weeks compressed to under ten hours. Techniques spanned initial access via a public API (T1190), credentials in files (T1552.001) and cloud-account abuse (T1078), mapped to the MITRE ATLAS framework. The attacker also left an 80-page technical audit of the victim's security posture. Verification: Verified
Malicious .git Configs Make AI Coding Agents Run Attacker Code (CVE-2026-72718)
Manifold's "Universal Evil" research showed that malicious Git configuration files can make AI coding agents execute attacker code before any model call, tool approval or trust prompt โ GitHub assigned CVE-2026-72718 (CVSS 7.0, credited to Francisco Rosales). The report lists affected agents including goose (fixed 1.44.0), Codex CLI (fixed 0.131.0), Claude Code (fsmonitor path fixed 2.1.196), Qwen Code, Grok Build and Hermes Agent (fix pending), with one finding duplicating Sonar's April disclosure and echoing the same trust-dialog bypass class behind CVE-2021-43891 in Visual Studio Code. The goose `review` command is called out as executing attacker code in a malicious repo with no interaction. Verification: Verified
Hackers Exploit Critical JFrog Artifactory Auth Bypass to Forge Admin Tokens
A critical authentication-bypass vulnerability (CVE-2026-82329) in self-managed JFrog Artifactory is being exploited in the wild, with watchTowr observing attackers minting Admin tokens on what is effectively the default configuration. An unauthenticated attacker with network access can gain administrative privileges, then enumerate users, read artifacts, change security configuration and poison packages trusted by downstream build and deployment systems; Vercel CEO Guillermo Rauch warned the impact extends beyond Artifactory because downstream systems pull released artifacts automatically. JFrog patched on 28 August across multiple versions (7.161.20 and earlier), and massaged that access tokens are independent credentials, so a forged token survives the binary upgrade. The flaw is now in CISA's KEV; victim counts and IoCs remain undisclosed. Verification: Verified
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| โ Tier 1 | Very High | Official / first-party |
| โ Tier 2 | High | Established cyber journalism |
| โ Tier 3 | Moderate | General tech/news media |
| โ Tier 4 | Low | Social / unverified |