Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
A quiet Monday after a heavy weekend still surfaced three genuinely fresh developments, headlined by an unauthenticated takedown of internet-exposed MikroTik routers. CERT Polska's warning, published 5 September, details attackers gaining full administrative control of RouterOS devices via SSH reachable from the internet with no authentication, with successful attacks dating to at least 2 September and fixes shipped across the 6.x, 7.x and development channels. Elastic Security Labs, meanwhile, documented four previously unreported persistent modules tied to the REVSTEALER commercial infostealer β one switches off Windows Update and Microsoft Defender before deploying a cryptocurrency miner, while the others steal wallet data and proxy attacker traffic β research freshly surfaced on 6 September after the stealer had been observed since February. And Microsoft threat researchers described a large-scale phishing campaign using invisible Unicode (ASCII-smuggling) characters to split finance-related lure words and evade email security filters, peaking at up to 2.37 million messages a day in late February and still active. The weekend's pre-captured material β the Magento StyleSmuggler zero-day, JetBrains Cadence, ClickFix-on-blockchain, OpenAI's wiki admission and the Citrix NetScaler advisory β was already covered in Friday and Sunday's digests.
No new ACSC alert landed in the SaturdayβMonday window; the operative mandated action remains the 4 September critical advisory on Citrix NetScaler ADC/Gateway, already covered in Friday's digest and still the standing instruction for Australian organisations running those appliances. The dominant Australian story today is the Vocus cable break on its Australia Singapore Cable system, which experienced a shunt fault between Perth and Singapore weeks after the second major cable on the same route β ASC's sister system β began its own cable issue. COTDR testing from the Perth landing station has pinpointed the break to Indonesian waters between Anyer and Singapore, and Vocus is coordinating marine repairs, spare materials and regulatory approvals while traffic reroutes via Australian east-coast cables and then through Japan or the United States. For Australian defenders, the event is a resilience reminder: subsea cable redundancy in the region is finite, and the same infrastructure that carries financial, government and defence traffic is both a physical and an availability risk that SD-WAN and Essential Eight posture alone cannot make up for. On the regulatory front, the Attorney-General's Department's consultation package for the Privacy Amendment (Personal Data Protection) Bill 2026 β the second wave of Privacy Act reforms β remains the defining direction of travel for Australian data-handling obligations, even as its day-to-day implications are disciplined by existing CPS 234 and NDB scheme duties.
The week's through-lines hold. Internet-exposed infrastructure remains the highest-velocity target class: today's MikroTik SSH hijack lands alongside NCSC UK's end-of-August warning on internet-exposed systems and edge devices, and extends a month in which CISA has steadily added its known-exploited catalogue entries (Chrome V8 on 4 September; seven additions on 2 September spanning LiteLLM, Starlette, Kestra, JFrog Artifactory, Sangoma Switchvox and the SonicWall SMA1000 pair). The FleetWatch-style lesson is that unauthenticated or weakly-authenticated management services on the public internet remain a first-order intrusion vector that patching cadence alone has not closed. Commercial-infaostealer-as-a-service is maturing: REVSTEALER β sold commercially since February β now ships multi-module persistence that survives its own deletion, de-fangs Microsoft's native defences and drops miners, the same commercialised-commodity trend flagged across the past week's vendor coverage. The regulatory wave continues to build: G7's post-quantum push and the USβUK scam-centre takedown memorandum (both covered this week) sit alongside Australia's second-wave Privacy Act consultation as evidence that regulators across the Five Eyes are moving from guidance to obligation. For the week ahead, watch the CISA KEV cadence for fresh edge and remote-access additions, and Adobe's 8 September security bulletin β the first scheduled opportunity for the Magento StyleSmuggler patch.
Incident Map
Global (Macro) 2 stories
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
CERT Polska published an attack warning, dated 5 September, describing how attackers are gaining full administrative control of MikroTik routers whose Secure Shell (SSH) service is reachable from the internet, with no authentication required; successful attacks date to at least 2 September and no victim count or attacker identity has yet been published. MikroTik's security update fixes the issue in RouterOS 6.49.21, 7.23.4, 7.24.2 (and 7.23.5 on the long-term channel to address a regression), with no development-channel bypass listed in the disclosure. CERT recommends immediate installation, followed by a check for unauthorised configuration changes, and notes that home devices with MikroTik's default firewall rules intact are not exposed because public access to management ports is blocked by default. The episode underscores the ongoing risk posed by internet-exposed management services on edge devices. Verification: Verified
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic Security Labs documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer sold commercially since at least February 2026, which remain on an infected machine after the stealer deletes itself. One switches off Windows Update and Microsoft Defender before running a cryptocurrency miner; the four β named ProManager, WinUpdate, SoftManager and LockAppHost β respectively steal wallet and browser-extension data, redirect cryptocurrency addresses and capture mnemonic-shaped clipboard content, run a reverse SOCKS5 proxy over an encrypted WebSocket, and deploy XMRig while suspending competitors and establishing persistence. The core stealer exfiltrates browser passwords and cookies, wallets, gaming and messaging data and files. The findings, published 2 September and freshly surfaced on 6 September, point to a commercial infostealer maturing into a persistent multi-module presence rather than a fire-and-forget credential snatcher. Verification: Verified
Financial Services 1 story
Attackers Conceal Phishing Lures Using Invisible Unicode Characters
Microsoft threat researchers described a large-scale phishing campaign using the ASCII-smuggling technique, in which invisible Unicode characters from the Tags block (U+E0000βU+E007F) are inserted inside finance-related lure words such as 'funding' to split them and evade email security filters while remaining visually intact. Microsoft's telemetry shows the high-volume phase peaked at up to 2.37 million messages a day in late February, persisted for roughly three months and dropped sharply after 15 May 2026, though the campaign remains active. The technique is already established in AI prompt-injection attacks for concealing malicious instructions; its adoption in consumer phishing signals attackers porting evasion mechanics across threat classes. Users are encouraged to examine sender identity and links in finance-related email regardless of how natural the message appears. Verification: Verified
Transport 1 story
Vocus Hit by AustraliaβSingapore Cable Break
Vocus is managing a fault on its Australia Singapore Cable (ASC) system between Perth and Singapore β weeks after the second major cable on the route, ASC's sister system, recorded its own shunt fault. COTDR testing from the Perth cable landing station has pinpointed the break to Indonesian waters between Anyer and Singapore, and Vocus is coordinating marine repairs, spare materials and regulatory approvals. Internet traffic has been rerouted via alternate paths, with network engineers reporting traffic shifting to Australian east-coast cables and then through Japan or the United States. The event is a resilience reminder for the eastern-Indic region's submarine cable infrastructure, on which Australian financial, government and cloud traffic depends, and comes as regional authorities weigh redundancy against a finite set of physical routes. Verification: Reported
Healthcare 1 story
Resource Center of Dallas Notifies 12,500 Patients About Cyber Incident
Resource Center of Dallas, an organisation providing health, wellness and advocacy services to the LGBTQIA+ community in North Texas, is notifying 12,490 individuals about a data security incident discovered earlier this year. Third-party cybersecurity professionals engaged to investigate suspicious network activity determined that certain personal and health-related information was accessed without authorisation; the organisation said it has taken steps to secure its systems and is offering affected individuals monitoring support. The incident was disclosed alongside breaches at Kern Psychiatric Health and Wellness Center, The Asthma Center, Integrative Emergency Services and Psychiatry of Texas, continuing the steady cadence of US healthcare breach notifications. Verification: Verified Breach: Confirmed breach
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| β Tier 1 | Very High | Official / first-party |
| β Tier 2 | High | Established cyber journalism |
| β Tier 3 | Moderate | General tech/news media |
| β Tier 4 | Low | Social / unverified |