Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
A research-heavy Tuesday with one significant Australian data breach and a cluster of first-party vendor disclosures โ but no fresh headline zero-day or new major breach by a named enterprise. The standout is Mathspace, the Sydney-founded online maths learning platform, which confirmed that attackers exploited a critical Metabase SQL-injection vulnerability in its self-hosted reporting instance and downloaded personal information belonging to 1,079,819 students, parents and school staff across Australia and New Zealand, with access dating to 10 August and the data exfiltrated on 27 August. N-able shipped emergency Hotfix 4 for a maximum-severity, unauthenticated remote code execution flaw (CVE-2026-86218) in its N-central RMM platform, which Huntress has flagged as a potential zero-day amid active attacks on the product. Berlin is investigating a second data leak from its government network after hackers published stolen log-in credentials, extending the mid-August Rhysida ransomware compromise of two Berlin ministries. The identity-phishing theme was unusually strong: researchers documented BigBear 2.0, a phishing-as-a-service platform that bypassed multi-factor authentication at 258 organisations, and a separate fake-IT-helpdesk vishing extortion cluster (tracked as PREY-0058, aligned with UNC6671) targeting senior executives, alongside a PEEP browser-based backdoor toolkit. Sunday and Friday digests already carried the Magento StyleSmuggler zero-day, the MikroTik hijack, REVSTEALER and the Citrix NetScaler advisory โ these recurrences are suppressed here, not repeated as fresh entries.
The defining Australian story is Mathspace. Founded in Sydney in 2010 and used by more than 3,432 Australian schools, the platform disclosed that on 3 September it confirmed unauthorised access to a self-hosted Metabase internal reporting system โ a critical SQL-injection vulnerability that granted administrator access without a legitimate login. Access began 10 August, the Australian reporting database was downloaded on 27 August, and the platform states the total affected is 1,079,819 people (students, parents or guardians and school staff), with only Australia and New Zealand individuals impacted. Mathspace says no academic records, passwords or hashes, authentication tokens, SSO credentials or API credentials were exposed, though for schools with identifiable email domains attackers may be able to link accounts. This squarely engages the OAIC Notifiable Data Breaches scheme โ a breach involving over a million Australian residents is presumptively likely to cause serious harm and drive notification duties โ and the incident links to a broader Metabase / ShinyHunters data-theft campaign that has separately hit Trezor, Framework and Tally over the past month, making the Mathspace disclosure a canary for Australian organisations running exposed Metabase instances. Elsewhere, no new ACSC alert landed in the window; the operative mandatory instruction for Australian organisations remains the 4 September critical advisory on Citrix NetScaler ADC and Gateway, and the Attorney-General's Department's second wave of Privacy Act reforms (Personal Data Protection Bill 2026 consultation) continues as the standing regulatory direction.
The through-line of the last few days is that stolen data and abused remote-access and identity tooling โ not novel code โ are driving the highest-impact stories. Berlin's second leak is a ransomware/data-exposure story: Rhysida, a chronically financially motivated group that Germany's federal cyber security agency (BSI) the same week links to a campaign resembling Microsoft's 'fake-CAPTCHA'/'TerminalFix' intrusions (LoremIpsumLoader/AxolotLoader), published data in the vast majority of named-victim cases, so a fresh Berlin publish should be read as part of an established extortion cadence rather than a one-off. The convergence is around identity and MFA: BigBear 2.0's Evilginx2-based AITM cookie replay and PREY-0058's helpdesk-vishing-token-theft both monetise the same weakness through phishing-as-a-service panels, geolocation of residential proxies and FIDO2 circumvention โ a shift from brute-forcing to session hijack. Legitimate software, including remote-agent RMM/remote-access tooling trusted by MSPs, remains a persistent weaponisation target: N-able's flagged zero-day and ConnectWise's unpatched file-transfer flaw both target holes in the agent tooling trusted to hundreds of organisations, carrying on the internet-exposed-infrastructure theme (MikroTik, M365 edge, KEV additions) that has run through the past week's digests. For the week ahead, watch the CISA KEV cadence and the Metabase campaign for additional victim announcements, and Adobe's Magento security bulletin (the first scheduled patch window for StyleSmuggler).
Incident Map
Education 1 story
Mathspace Discloses Data Breach Affecting Over 1,079,819 People
Mathspace, a Sydney-founded online maths learning platform used by thousands of schools across Australia, New Zealand, the United States and the United Kingdom, disclosed over the weekend that unknown attackers exploited a critical Metabase SQL-injection vulnerability in its self-hosted reporting environment to obtain administrator access without a legitimate login and download personal information on students, parents or guardians and school staff from its Australian reporting database. Mathspace says access began on 10 August, the data was downloaded on 27 August, the breach was confirmed on 3 September, and a total of 1,079,819 people were affected โ students, staff and parents combined โ with only people in Australia and New Zealand impacted. The company states that no academic records, passwords or hashes, authentication tokens, SSO credentials or API credentials were exposed, but warns that for schools with identifiable email domains attackers may be able to link accounts to schools, and advises affected users to watch for account-related phishing or password-reset activity. The incident is part of a Metabase campaign that has also compromised Trezor, Framework and Tally, with the (ShinyHunters-linked) threat actor pursuing multiple Metabase victims. Verification: Verified Breach: Confirmed breach
Healthcare 1 story
Luminis Health Working to Restore Systems After Cyberattack
Luminis Health, a nonprofit health system in Maryland that includes Anne Arundel Medical Center and Doctors Community Medical Center, announced on 4 September that it suffered a cyberattack affecting both hospitals. The facilities still care for patients although some appointments are rescheduled, and the phone system and MyChart patient portal are presently offline; third-party cybersecurity and legal experts are investigating and safely restoring systems. Luminis has not yet determined whether patient data was exposed or stolen, and as of reporting no ransomware or data-extortion group claimed responsibility โ at this stage the event is a system-disruption incident pending a breach determination. The publication also summarises three smaller US healthcare breach notifications (Texas orthopedic surgeon Jeffrey Reuben M.D.; Well Child of Tennessee/Mississippi school-based health provider; Horizon Eye Care in New Jersey). Verification: Verified (data-breach extent under investigation)
Government 1 story
Berlin Investigates New Data Leak After Hackers Publish Stolen Login Credentials
German authorities are investigating another trove of data stolen from Berlin's government network after hackers published stolen login credentials and other information over the weekend, following a cyberattack discovered in mid-August that compromised two city ministries responsible for urban development and housing, and for transport, mobility, climate and the environment. Berlin's data protection authority says a large volume of data was stolen and published, including personal information about public employees and potentially Berlin residents (names, addresses, dates of birth, bank details, email, telephone numbers, correspondence with agencies and submitted documents). Berlin has said it will not pay the attackers, and the governing mayor described a 'very serious crime'. The piece is framed against the recurring Rhysida-attributed breach of around 5.79 terabytes and a BSI warning the same week about a campaign resembling the TerminalFix pattern, with the same financially motivated cybercrime cluster publishing data in the vast majority of named-victim cases. Verification: Verified Breach: Confirmed breach
Transport 1 story
CargoNet Reports $31.8M in Labour Day Freight Theft as Criminals Breach Trusted Freight Accounts
Fraud-intelligence firm Verisk CargoNet warned ahead of the US Labour Day holiday that cargo theft in the annual seven-day windows has climbed 70% over five years (273 incidents recorded 2021โ2025, with estimated commodity value of approximately $31.8 million), and highlighted a growing identity-based scheme: criminals gain access to trusted freight channels by compromising carrier accounts, email systems, business phones or compliance platforms, then alter delivery instructions after a legitimate carrier has taken possession โ bypassing safeguards focused only on carrier selection. CargoNet says California, Texas and Illinois account for nearly half of incidents and estimates cargo losses exceed $359 million in the first half of 2026. The item is a fraud-and-identity data point driven by account/credential compromise rather than malware. Verification: Reported
Global (Macro) 4 stories
N-able Patches Max-Severity N-central Flaw Amid Ongoing Attacks
N-able released an emergency Hotfix 4 for a maximum-severity, unauthenticated remote code execution vulnerability (CVE-2026-86218) in its N-central remote monitoring and management (RMM) platform, which MSPs and IT teams use to manage client networks. The vendor said it has no confirmation the flaw was exploited, but Huntress has flagged it as a potential zero-day and was unable to rule it out in a customer incident because logs on the compromised N-central server had rotated; the fix arrives amid active attacks on the product and follows a prior authentication-bypass pair (CVE-2026-86206/CVE-2026-86207). Shadowserver tracking indicates close to 1,500 N-central instances remain internet-exposed, concentrated in North America and Europe. Organisations running on-premises N-central should apply 2026.3 Hotfix 4 immediately. Verification: Verified
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
Security researcher SOCRadar detailed a sophisticated Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension ('Smart Bookmarks') in the Chrome/Edge profiles. It requires prior administrative or code-execution access, but once present it injects the extension by forging Chromium's own Secure Preferences integrity values โ bypassing Web Store checks and user prompts โ and pairs it with a native-messaging bridge that reaches host-level command execution and file management. PEEP polls its C2 server over plaintext HTTP every 30 seconds, exfiltrates browsing history, active-tab metadata and session cookies, and supports remote access, credential threatens, session hijacking and web-page modification. It is built on the open-source RedExt red-teaming framework and remains unattributed, though it contains Chinese-language artefacts in its source. As a post-compromise framework with no initial-access vector of its own, its lesson for defenders is that an attacker who reaches a host must be assumed to be able to weaponise the browser itself. Verification: Verified
BigBear Microsoft 365 Phishing Service Bypassed MFA at 258 Organisations
Cybersecurity company CloudSEK reports (having gained administrator access to the service's own control panel) that a phishing-as-a-service platform it calls BigBear 2.0 has been used to bypass multi-factor authentication at 258 organisations, exfiltrating 5,137 Microsoft 365 records โ 474 complete MFA-bypassed authentications, 1,032 plaintext passwords and 4,148 session cookies โ across 3,331 unique victim IPs in more than 40 countries, with the 258 distinct organisations seeing at least one completed MFA-bypass compromise. The framework uses an Evilginx2-based adversary-in-the-middle proxy between the victim and Microsoft to capture passwords and authenticated session cookies for session hijack, uses custom JavaScript to interfere with FIDO2/WebAuthn and force weaker methods, and routes via geo-matched residential proxies so Microsoft's authentication servers do not flag the activity. The multi-user panel is leased to at least five affiliate operators. CloudSEK says it notified law enforcement and organisations and offers remediation advice (revoke sessions, enforce FIDO2, use conditional access). Verification: Verified
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion
Threat hunters (Arctic Wolf, tracking the cluster as PREY-0058) have described a data-theft and extortion operation targeting Microsoft 365 and other Software-as-a-Service offerings through IT help-desk vishing, adversary-in-the-middle (AITM) token theft and residential-proxy sign-ins, singling out directors, vice-presidents and other executive staff. The activity shares significant tradecraft with a group Mandiant tracks as UNC6671, and Arctic Wolf connects the data-extortion operator 'Cinder' as a plausible rebrand or continuation of prior Pink, noting the labels cover a set of affiliates rather than a single proven actor. Attack chains begin with the phone calls impersonating internal IT or help desk and directing the target to an authentication-themed lure domain (assignpasskey[.]com, mfaregister[.]com, nowsso[.]com, oursso[.]com, passkey-mfa[.]com, oskeysetup[.]com), harvesting login and MFA approval via an operator-controlled M365 login flow and captures tokens used later for exfiltration and extortion. The episode reinforces the busy MFA-bypass phishing week. Verification: Reported
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| โ Tier 1 | Very High | Official / first-party |
| โ Tier 2 | High | Established cyber journalism |
| โ Tier 3 | Moderate | General tech/news media |
| โ Tier 4 | Low | Social / unverified |