Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
The supply-chain beat dominates today. Coder disclosed that a malicious actor compromised its Cloudflare infrastructure and pinned unauthorised servers into the pool behind its Terraform module registry, delivering modified modules that acted as credential stealers to a subset of workspace users between 07:35 and 21:45 UTC on 31 August โ a package-level attack that targeted the exact secrets cloud and AI developers keep in their provisioner environments. On the older-but-still-exposed front, a critical, actively exploited vulnerability in Elementor Pro (CVE-2026-32475, patched 19 August) has generated roughly 200,000 blocked exploitation attempts, mostly between 19 and 23 August, with attackers uploading PHP webshells to WordPress sites โ the same pattern Wordfence has been flagging across the plugin ecosystem. HPE separately patched a critical unauthenticated buffer-overflow RCE (CVE-2026-73749) plus 23 further ArubaOS-CX flaws, none yet publicly exploited but touching the switch OS that underpins enterprise, government and university networks. On the data-exposure side, Thomson Reuters disclosed a March-June compromise of its C-Track court case-management platform affecting courts in at least 12 US states, the US Virgin Islands and Canada โ including sealed/redacted case information โ reinforcing that judicial records sitting with a commercial vendor inherit that vendor's security posture.
The operative ACSC item is unchanged from the previous cycle โ the 24 August high-rated alert on active exploitation of TeamCity On-Premise servers (CVE-2026-63077); no new ACSC alert or KEV addition landed in this window (CISA's 2 September KEV batch, incl. JFrog Artifactory and Sangoma Switchvox, was already covered). The most directly relevant Australian development today is regulatory enforcement: ACMA fined Telstra A$277,000 for repeatedly failing to perform the identity-authentication checks its own SIM-swap prevention process requires, following at least A$39,500 in losses to 15 customers and 13 further near-misses between January and October 2025 โ a concrete instance of a regulator enforcing operational processes rather than just technical layers, directly relevant to how Australian firms with identity-brokerage and MFA-reliance (the same trust assumptions behind this week's US SIM-swap-adjacent and vishing-fed breaches) are being supervised. For Australian enterprises, the Coder registry compromise is a same-week warning about AI/cloud development tooling supply chains: Australian teams self-hosting Coder or sourcing Terraform modules were inside the exposure window, and the module cache should be purged and provisioner secrets rotated regardless of the per-customer ambiguity. Elementor Pro (6M+ installs) and ArubaOS-CX are both widely deployed in Australian SMB and government/education networks respectively; the WordPress plugin should be patched to 4.2.2+ and the `/uploads/elementor/forms/` directory inspected for rogue PHP, and Australian network operators should track HPE's bulletin for AOS-CX releases. Note the quiet-notification thread: Origin Energy's ~900,000 customer data-theft (late August, from last week's window) still has no formal OAIC NDB-register listing confirmed to date.
Today consolidates two weekly through-lines rather than opening new ones. First, the software-supply-chain pattern that has run since Monday โ malicious `.git` configs, JFrog Artifactory token-forging, Gogs zero-day, and now Coder's registry being pinned into Cloudflare's pool โ has become the week's most consistent operational theme: trusted build/registry infra is being attacked at the distribution boundary, and defenders are being asked to treat artifact provenance as a first-class control. The Coder incident is a reminder that "the registry is behind Cloudflare" is not itself a supply-chain guarantee when the *attack surface sits in front of Cloudflare's routing decision* โ the attacker didn't defeat WAF, they manipulated where CDN requests terminate. Second, the AI-as-attacker and AI-tooling-attack thread from 1โ3 September (manifold.ai intelligence, aurora's cursor use, SonicWall exploitation) carries forward quietly: CVE-2026-32475 and CVE-2026-73749 are conventional flaws, but the Coder-and-manifold pairing shows AI coding tooling increasingly doubles as both the target and the tool. Geopolitically the Serbian spyware story (Pegasus + a NoviSpy variant on 14 opposition/activist targets, October elections ahead) was a full entry on 3 September and stays context โ the year's largest documented surveillance wave and a reminder that commercial spyware plus physical phone seizure remains the most reliable state instrument, and that patching mobile OS is the operative control. Week-ahead watch items: whether JFrog discloses victim-count impact and whether Coder's exposure window translates into either victim or credential-rotation guidance beyond the advisory; HPE ArubaOS-CX is unpatched-in-the-wild risk and bears watching for a KEV add.
Incident Map
Government 2 stories
Thomson Reuters Exposes US and Canadian Court Data in C-Track Case-Management Breach
Thomson Reuters publicly disclosed a separate compromise of its C-Track court case-management platform, affecting courts in at least 12 US states, the US Virgin Islands and Canada. The company detected the unauthorised activity on 30 June, with the investigation finding files were first obtained in March and access persisting into June; potentially exposed data includes names, Social Security numbers, driver's licence numbers, medical information, dates of birth and health insurance information, and at some courts confidential, redacted or sealed case information. Thomson Reuters says the breach occurred within its own environment, not the courts', has not disclosed the access vector, party responsible or a victim count, and is offering 12 months of credit monitoring; Ontario's chief justices and Montana's Supreme Court have separately confirmed involvement. Verification: Verified Breach: Confirmed breach
Australian Communications and Media Authority Fines Telstra $277K for SIM Swapping Prevention Misses
The Australian Communications and Media Authority (ACMA) has fined Telstra A$277,000 for failing to follow its own identity-authentication processes to prevent SIM swapping. ACMA said the lapses facilitated at least A$39,500 in losses to 15 customers between January and October 2025, with a further 13 attempts identified where staff failed to apply additional fraud protections; Telstra accepted court-enforceable undertakings to strengthen fraud-prevention processes and improve staff training. The fine follows ACMA's larger A$1.551 million penalty against Telstra in July 2024 for the same failure class, and brings the regulator's total SIM-swap enforcement to more than A$5 million. Verification: Verified
Healthcare 2 stories
Five Healthcare Providers Report Ransomware-Related Data Breaches
HIPAA-breach notifications published this week confirm ransomware-led compromises at five US providers: Alta Orthopaedics (California, 24,496 individuals, INC Ransom claiming 26 GB exfiltrated and leaked), Cornerstone Behavioral Healthcare (Maine, 14,830 patients, ransom declined, <10% of data encrypted), Cameron Regional Medical Center (Missouri, 60-bed acute care hospital, Anubis ransomware claiming ~500 GB), Suntree Internal Medicine (Florida, 9,810 individuals, INC Ransom) and Associated Endocrinologists (Michigan, 4,979 patients, RansomHouse). Exposed data in most cases includes names, dates of birth, Social Security numbers, health/insurance information and, at Alta, financial account and biometric data. Three of the five are attributed (INC Ransom, Anubis, RansomHouse); Cornerstone is notable for a detailed letter describing a rapid containment (<10% encryption) and a no-pay decision. Verification: Verified Breach: Confirmed breach
Multi-Million Settlement Resolves Managed Care of North America Data Breach Litigation
Dental insurer and third-party administrator Managed Care of North America (MCNA) has agreed to settle consolidated class action litigation stemming from a 2023 breach that affected around 8.9 million individuals, triggered by an unauthorised third party accessing its network between 22 February and 7 March 2023. Records included names, contact details, dates of birth, Social Security/driver's licence/Medicare IDs, and dental-care information. Under the settlement MCNA covers attorney fees up to US$6.4m plus litigation costs up to US$1.31m, funds two years of medical-data monitoring (valued ~US$179/yr per class member), and reimburses documented unreimbursed losses up to US$2,500 per member; objection/opt-out deadline is 19 October 2026 with a final fairness hearing on 16 November. Verification: Verified Breach: Confirmed breach
Global (Macro) 6 stories
Coder's Registry Infrastructure Compromised to Push Malicious Terraform Modules
Open-source cloud-development platform Coder disclosed that an unidentified actor compromised its Cloudflare infrastructure and added unauthorised IP address(es) to the pool behind its Terraform module registry (`registry.coder.com`), causing Cloudflare to route a subset of registry requests to attacker servers that delivered modified modules containing credential-stealing code (CVE-2026-82416 family per advisory GHSA-vx42-ghc9-gw65). The malicious delivery window was 07:35โ21:45 UTC on 31 August; the modules searched provisioner environment variables and secrets, cloud/AI-tooling API keys, CI/CD credentials, OIDC tokens, configured SSH keys and config-file secrets, and exfiltrated them to the lookalike domain `coder-infra[.]com`. Versions 2.37.0, 2.36.4, 2.35.7 and 2.34.9 fixed the issue; affected users are advised to rotate the listed secrets, purge module caches, and examine firewall/DNS/VPC logs for connections to `coder-infra[.]com`. Coder says refresh tokens were not passed to the provisioner and it saw no evidence of impact to its own customer data. Verification: Verified
Critical Elementor Pro Flaw Exploited to Take Over WordPress Sites
Wordfence is reporting active exploitation of CVE-2026-32475, a critical file-upload-array validation bypass in the WordPress Elementor Pro plugin (versions 4.2.1 and earlier, 6M+ installs) that lets an unauthenticated attacker upload a malicious PHP file to `/wp-content/uploads/elementor/forms/` and execute arbitrary commands. Exploitation began 19 August โ the same day Elementor shipped version 4.2.2 โ and Wordfence reports more than 190,000 blocked attempts between 19 and 23 August, delivering webshell payloads. The exploit is only possible on sites with a published Elementor Pro Form widget containing at least one File Upload field, a common configuration; administrators are urged to upgrade to 4.2.2+ immediately and inspect the forms directory for rogue PHP files. Verification: Verified
HPE Patches Critical ArubaOS-CX Remote Code Execution Flaw
Hewlett Packard Enterprise has patched CVE-2026-73749, a critical unauthenticated buffer-overflow in an ArubaOS-CX daemon that allows remote code execution with elevated privileges via crafted packets, plus 23 further flaws (CVE-2026-73750โ73782) rated up to 8.8 that include command injection through the web interface, arbitrary-file-write via an API endpoint, a predictable factory-default password and authentication-bypass issues. Affected release branches span AOS-CX 10.10 through 10.18; HPE named fixed versions (for example 10.18.1002+, 10.17.1030+ and 10.16.1060+) and said it was not aware of active exploitation or public PoCs at publication. ArubaOS-CX runs HPE enterprise network switches widely used by large businesses, government agencies, universities, healthcare organisations and service providers. Verification: Verified
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Cisco patched a critical flaw (CVE-2026-20212, CVSS 9.8) affecting ten Silicon One-based Nexus 9000 switches, alongside an IOS XR hardening release bundling seven umbrella CVEs (two rated 9.8). The flaw stems from binding to an unrestricted IP address that leaves TCP ports 43210 and 43211 reachable in the default Layer 3 VRF, allowing a remote attacker who can reach the switch address to send crafted input that executes as root, or crashes the S1HAL process and reloads the device. Cisco reports no workaround for any affected IOS XR version and said it was not aware of active exploitation as of its 2 September disclosure. Verification: Verified
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
Group-IB disclosed BraZetsu, a Python-based Windows malware framework it attributes with high confidence to the Brazilian actor Exilware and which functions as the primary technical mechanism for the actor's Initial Access Broker operation, feeding an underground "Infect Marketplace" that commercialises footholds in Iberian and Latin American environments. Group-IB describes the framework as AI-enhanced and operationally mature, with a modular architecture and stealth techniques that left some samples undetectable on VirusTotal at analysis time, and says it lets IABs conduct extensive reconnaissance on compromised systems before resale to ransomware groups and other buyers. Verification: Verified
Shai-Hulud Infostealer Expands to 469 Credential Locations
GitGuardian reports that a recent variant of the Shai-Hulud infostealer worm has expanded to scan for credentials across 469 locations in developer environments, CI/CD tooling, cloud configurations and AI tool configs โ up from 189 paths in earlier variants, with Linux coverage rising from 89 to 290 locations and new cloud-target additions including Hetzner, Alibaba Cloud and Tencent Cloud. The expansion reflects a broader shift in which attackers no longer try to break trust relationships but harvest the standing credentials already inside them, a theme consistent with the week's developer-toolchain compromise coverage. Verification: Verified
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| โ Tier 1 | Very High | Official / first-party |
| โ Tier 2 | High | Established cyber journalism |
| โ Tier 3 | Moderate | General tech/news media |
| โ Tier 4 | Low | Social / unverified |