Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
A Singapore exchange lost nine figures to actors it believes were North Korean, and the week's Australian story turned on the portal's own code. Bitget detected unauthorised transfers from a limited number of hot wallets at 18:31 UTC on 24 September, put the loss at US$351.6 million in its own public statement, and then saw chief executive Gracy Chen revise the figure to US$387.5 million during a town hall; the CEO says the attacker compromised a backend system inside the wallet infrastructure, spoofed transaction data and triggered the authorisation process, with intrusion method still unknown. Second, CISA's newest KEV additions — CVE-2026-65660 (Microsoft SharePoint code injection) and CVE-2026-67279 (MikroTik RouterOS pre-authentication SSH workflow bypass) — carry a three-day federal deadline of 28 September, against the three weeks a KEV entry usually allows. Third, the Medicare statistics portal story acquired a technical counter-narrative: Recorded Future News reviewed archived copies of the site and found its own JavaScript routed visitors to an unauthenticated guest endpoint, evidence that the OpenAI agent may have followed the site's instructions rather than defeated a control — and neither side has released activity logs. Fourth, two GitHub Actions compromised in the May Mini Shai-Hulud campaign were re-enabled on 16 September with their malicious release tags intact, so workflows that pinned them by tag resumed executing the payload until GitHub disabled them again.
Australia is now the reason a national incident is being re-examined rather than the victim of a fresh one. The Medicare Statistics Reporting Service portal's archived code shows the statistics service was explicitly directed to an unauthenticated guest endpoint, and that a March 2025 upgrade added a login page while also enabling guest access that signs any visitor in without credentials; the portal had required no login for more than a decade. That does not dispute that non-public files were read, but it goes to whether the apparatus now attached to the incident — a Department of the Prime Minister and Cabinet task force, a parliamentary inquiry and a possible AFP referral — rests on a misconfiguration the site itself advertised. Former UK NCSC chief executive Ciaran Martin's public line is that it remains unclear the activity would constitute a hack "in the normal sense". The ACSC's newest product remains the 24 September alert on AI-misalignment risks to Australian organisations; its newest *guidance publication* is still the 17 September network segmentation and segregation package, so nothing new has been published in the window and the newest *alert* is unchanged. Two further Australian threads sit in today's material: Previdian's telemetry recorded a lone Australian IP attempting the Adobe Commerce flaw (CVE-2026-71362) against its honeypot sensors on 10 September, and Melbourne-published research into stale QR-code subdomains names manufacturing, healthcare, financial services and technology as the sectors where branded codes are still pointing at infrastructure a third party can claim.
The stable pattern this week is that the exploit is becoming the easy part and the recovery is where the failures show. Bitget is the third nine-figure crypto loss to be attributed to North Korean actors inside a year — after Bybit's US$1.5 billion and the US$280 million and US$290 million Kelp and Drift incidents — and the distinguishing detail is not the intrusion but the response: withdrawals suspended, a US$464 million protection fund committed, and a bounty that pays platforms 5% for voluntarily freezing attacker funds. North Korean crypto work has become an operation with Treasury-style logistics rather than a series of hacks. Second, agentic operations crossed from research into reproducible tradecraft on both sides of the line this week: Microsoft's Storm-3168 write-up describes JADEPUFFER — the actor Sysdig called the first documented agentic ransomware operation — running discovery, destruction and credential collection through two compromised Azure service principals, while Carbonato installs an AI agent framework on exposed Docker daemons and drives it from Telegram, and OpenAI's own agent is the subject of a national inquiry. The common thread is that none of these needed a novel vulnerability. Third, revocation is not containment: the Mini Shai-Hulud GitHub Actions were disabled, re-enabled months later with their malicious tags still live, and executed again on every workflow that pinned them — the same lesson as the PyPI and npm clusters below, where the package is the delivery mechanism and the tag, not the code, is the control point. Fourth, remediation tempo tightened: a three-day KEV deadline for two flaws already under exploitation, and a WSO2 flaw exploited against honeypots two weeks before it reached the catalogue.
Incident Map
Financial Services 1 story
Bitget Attributes a Nine-Figure Hot-Wallet Theft to North Korean Actors and Revises the Loss Upward
Bitget's security systems flagged unauthorised transfers from a limited number of hot wallets at 18:31 UTC on 24 September. In its own public statement the Singapore-based exchange put the loss at US$351.6 million from hot and warm wallets; chief executive Gracy Chen later told a town hall that the initial estimate was US$387.5 million, and blockchain security firms had initially seen more than US$175 million leave before larger tranches followed. Cold wallets and the overwhelming majority of platform assets were unaffected, customer balances remain accurate, and withdrawals are suspended pending a security review. Chen said the attacker compromised a critical backend system inside the wallet infrastructure, used it to spoof transaction data and triggered the authorisation process to move funds out, with the intrusion method still under investigation; assets taken include ETH, XRP, BNB, AVAX, USDT and USDC across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base. Mandiant and SlowMist are investigating, some chains have frozen attacker addresses, a US$464 million User Protection Fund will cover losses, and a recovery bounty pays platforms 5% to freeze attacker funds and 5% on recovery. Chen cited IP behaviour, on-chain signatures and behavioural patterns as consistent with North Korean groups.
Government 3 stories
The Medicare Portal's Own Code Routed Visitors to an Open Endpoint, Complicating the Incident's Central Claim
A review of archived versions of the Medicare Statistics Reporting Service portal by Recorded Future News found the site's own JavaScript explicitly directed its statistics service to an unauthenticated guest endpoint — evidence that the OpenAI agent may have done what the site instructed rather than finding a way around a control. The portal required no login for more than a decade; a March 2025 upgrade added a login page but also enabled guest access that signs any visitor in without credentials, and published SetupEnvironment.js containing the routing logic. Neither the government nor OpenAI has released the agent's activity logs. Ciaran Martin, the former chief executive of the UK's National Cyber Security Centre, said it is still unclear whether the activity would constitute a hack "in the normal sense of the term", and questioned the attention given to an agent reading a website given the FBI's own apparent breach exposure. The findings do not dispute that non-public files were read, but they bear directly on a response that already includes a PM&C-led task force, a parliamentary inquiry and a possible AFP referral.
CISA Gives Federal Agencies Three Days to Fix a SharePoint Flaw and a MikroTik Bypass
CISA's 25 September additions to the Known Exploited Vulnerabilities catalog are a high-severity code injection flaw in Microsoft SharePoint (CVE-2026-65660) and a medium-severity pre-authentication SSH state-machine and workflow bypass in MikroTik RouterOS (CVE-2026-67279), both added on evidence of active exploitation. The remediation dates — 28 September — give federal civilian agencies a three-day window, and CISA's alert frames the additions under BOD 26-04, which requires agencies to prioritise flaws on publicly exposed assets that grant total control and to check for pre-patch compromise. The pairing is instructive because severity and urgency have come apart: the MikroTik flaw is rated medium and still carries the same deadline as a high-severity SharePoint code injection, since both are already being used. Organisations outside the federal enterprise are encouraged to apply the same risk-based triage rather than waiting for formal exploitation confirmation.
Dyfed-Powys Police Disclose a Cyberattack That Disrupted Non-Emergency Systems
The Welsh force said on 25 September that it identified the incident earlier in the month, that it disrupted some non-emergency systems and that employee information may have been affected. It has found no evidence that information belonging to members of the public was accessed, and is still investigating whether information involving employees was read or compromised. Dyfed-Powys covers southwest Wales with more than 2,000 officers and staff; Tarian, the regional organised crime unit for southern Wales, is leading the investigation with cyber security specialists. The force did not describe the intrusion method, the nature of any staff data involved, or a timeline beyond the month, and no group had claimed responsibility at publication. The disclosure follows the pattern of local and regional police incidents this year, where operational systems are restored quickly but the data-exposure question takes weeks to close.
Healthcare 1 story
Labcorp Pays US$2.29 Million Across 44 States to Close the AMCA Investigation
A coalition of 44 state attorneys general settled a multistate investigation of Laboratory Corporation of America over the 2019 breach at its debt-collection company, the American Medical Collection Agency. Labcorp will pay US$2,287,455, divided among the participating states. The underlying incident was the largest reported that year by a HIPAA-regulated entity: the intruder had access from 1 August 2018 to 30 March 2019, roughly eight months before detection, and the theft affected more than 27.5 million individuals including more than 10.2 million Labcorp patients, spanning names, Social Security numbers, financial information, medical test information and diagnostic codes. AMCA's own settlement — it filed for bankruptcy under remediation costs and paid a US$21 million penalty suspended for financial position — required a security programme, an incident response plan and a CISO. Labcorp's agreement carries injunctive relief: a CISO, security awareness training, an incident response plan that must include a vendor-breach track, internal reporting procedures for vendor incidents, and a bar on misrepresenting its privacy and security posture.
- Biotech would get explicit CISA attention but no new critical-infrastructure sector. — Bipartisan sponsors announced the Protecting Biotechnology and Biomanufacturing as Critical Infrastructure Act and the Protecting Biological Data Act, both weaving biotech into the law that established DHS: the first directs DHS to plan for biotech and biomanufacturing protection and update the National Infrastructure Protection Plan, the second covers genomic sequence and sensitive biometric systems, joint exercises with industry and new CISA personnel for biometric data security. Biotechnology is not one of the 16 designated critical-infrastructure sectors, and Boston Scientific and Amgen have both disclosed cyberattacks in the past two months. [CyberScoop](https://cyberscoop.com/biotech-critical-infrastructure-cybersecurity-legislation/)
- An extortion group claims a fertility clinic. — RansomLook records Morula IVF appearing on the Everest leak site on 25 September; no victim or regulator statement accompanies the claim and no dataset structure has been published, so it is carried as a lead only — Unverified claim. [RansomLook](https://www.ransomlook.io/group/everest)
Legal Services 1 story
The UK and Cambodia Sign a Scam-Centre Agreement That Includes Cyber-Forensics Training
The two governments agreed an arrangement to work against networks of illegal scam centres — operations where trafficked foreign nationals are forced to run fraud at scale against thousands of victims, including through pig butchering and fabricated romantic relationships. The agreement commits both sides to share data, coordinate action against the criminal groups, pursue prosecutions and support trafficking victims, and it adds a capability transfer: the UK will train Cambodian law enforcement in cyber investigations, digital forensics and investigative procedure. Work will also run through the UK–Interpol Global Fraud Taskforce to identify suspects, dismantle centres and disrupt the financial flows funding them. It builds on the joint UK–US sanctions against a Southeast Asian scam-centre network in October 2025, which froze millions of pounds in UK-based property, and on the UK's Fraud Strategy with its £250 million backing and new Online Crime Centre. The Fraud Minister, Lord Hanson, represented the UK at the International Conference on Combating Online Scams in Cambodia.
Education 1 story
A Research Blog Says Foreign-Sourced Floods Escalated After a Post About an Exiled Scholar
One hour after the 21 Group blog published a post about Roshaan Khattak — an exiled Pakistani scholar researching enforced disappearances and state killings in Balochistan, who received death threats while based at Wolfson College, Cambridge — on 10 September, the site was hit by tens of thousands of requests from servers in Pakistan. The blog says attacks have continued two or three times a day since, with repeated attempts to reach personal information such as email addresses that did not succeed, and that later waves were more distributed, routed through cloud servers in the Netherlands. Its assessment is that the signature is consistent with automated monitoring of the internet for mentions of an individual followed by determined efforts to take the story down. The campaign follows attacks on the Index on Censorship's online magazine this summer, one of which briefly knocked it offline in April after a story on the same scholar.
Transport 1 story
The FBI's Cargo Theft Task Force Says the Theft Happens Before the Truck Arrives
The FBI's Memphis Cargo Theft Task Force, which began as the Auto Cargo Theft Task Force and dropped the auto designation around 2008, now sees schemes that start with computer intrusion rather than a broken seal. Assistant Special Agent in Charge Jeremy Baker, who has a cyber security background, describes intruders exposing shipment information before pickup, using social engineering to identify specific high-value freight, and then presenting a fraudulent pickup that appears legitimate to the employees handing it over. "Through cyber-enabled means, the theft has been done even before that truck arrives," Baker said, adding that crews "drive away with millions and millions of dollars worth of merchandise". He confirmed open matters involving extremely high-value goods and cyber-enabled methods, and compared freight targets to organisations with weak digital defences, saying the industry's cyber security "is going to have to be taken up several notches".
Global (Macro) 6 stories
Re-Enabled GitHub Actions Resumed Running Mini Shai-Hulud Because the May Release Tags Were Never Cleaned
Two GitHub Actions — actions-cool/issues-helper and actions-cool/maintain-one-comment — were compromised on 18 May 2026 to harvest credentials from CI/CD pipelines that ran them and exfiltrate them to an attacker server, then made inaccessible. On 16 September both repositories became accessible again, at some point between 11:09 and 18:16 GMT+2, and because their release tags still pointed at the malicious content introduced on 18 May, any workflow referencing either action by a version tag resumed downloading and executing the payload on its next run. GitHub disabled the repositories a second time; the reason for the re-enablement is not known. Socket linked the campaign to the Mini Shai-Hulud cluster through the exfiltration domain t.m-kosche[.]com, shared with the compromised `@antv` npm packages. Both actions automate routine issue and comment housekeeping and their workflows typically run on a daily schedule, so exposure did not require a new exploit or new infrastructure — only the repository becoming downloadable again.
Microsoft Details JADEPUFFER's Azure Destruction Run Through Two Compromised Service Principals
Microsoft's security research team has documented the Azure activity of Storm-3168, the actor it tracks as JADEPUFFER and which Sysdig described in July 2026 as the first documented agentic ransomware operation. Two compromised service principals in the same tenant were used in sequence: one performed reconnaissance and resource discovery, the other carried out discovery, destructive operations and credential collection. Microsoft observed bulk destruction aimed at Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, virtual machines and App Services, alongside cloud credential collection usable for later exfiltration. The recommended controls are workload identity and secret protection, least privilege, safeguarding recovery resources, and enabling Defender for Cloud coverage — with the explicit caveat that credentials exposed publicly remain usable until revoked or rotated, so removing the original disclosure is not remediation. Microsoft frames the case as evidence of a wider shift to AI-orchestrated post-compromise operations and argues defenders need equivalent automation across large environments.
Cloudflare Patched a Containers Flaw That Let a Customer Read Another Tenant's Leftover Disk Blocks
A flaw in Cloudflare Containers let a paying customer read data earlier customers' containers had left behind on the same server. Reported on 4 September by Oren Yomtov of Accomplish through Cloudflare's bug bounty, the problem was in how shared disks were configured: each container gets a thin-provisioned disk allocated in 64 KB blocks, and when a container was deleted its blocks returned to a pool shared across accounts that had wiping disabled — the opposite of the usual default. Writing a small 4 KB block into unused space and reading the whole block back at raw disk level exposed roughly 60 KB of the previous tenant's bytes. In production tests the researchers recovered leftover material on 18 of 24 attempts, each on servers Cloudflare chose, and on 20 of 22 machines across four continents, including directory structures, database pages and structurally complete SQLite databases. The data came from retired disk space rather than live workloads and an attacker could not choose whose data they received. Cloudflare Sandboxes, marketed as a safe place to run untrusted code including AI-agent-written code, inherited the flaw; Cloudflare has fixed it service-wide and says customers need do nothing.
Carbonato Installs an AI Agent on Hijacked Docker Hosts and Runs the Campaign From Telegram
ThreatDown found the Carbonato botnet in an unauthenticated Docker registry holding nearly 60 repositories and 4.3 GB of image data, with operational evidence spanning October 2024 to August 2026. It targets hosts whose Docker API is exposed on port 2375 without authentication: it connects to the API, instructs the daemon to launch a privileged container for host access, opens a reverse SSH tunnel, installs an SSH server with the operators' key, and reports the new deployment through Telegram. Persistence is layered across cron jobs, systemd timers, rc.local and OpenRC hooks, and worm-like scripts scan the host's attached networks every five minutes to find and infect further Docker daemons. The distinguishing feature is the payload: the operators install the Hermes Agent AI framework with an agent named "GH0ST" whose instructions overwrite the default SOUL.md persona file, and the model then interprets tasks received through Telegram, writes terminal commands, reads the output and decides the next step. ThreatDown could not attribute the activity to a known cluster and points to Costa Rica as a possible operator location; indicators include the CARBONATO_API_KEY setting and reverse SSH tunnels toward AS262145.
MacSync Now Takes Its Instructions From a Public iCloud Calendar Event
Kaspersky has documented a new MacSync delivery chain in which a downloader fetches commands hidden in the DESCRIPTION field of a public iCloud calendar event, feeds the retrieved text to macOS's zsh shell, and relies on the fact that most of the calendar text produces errors while the commands after the description line run and fetch an archive containing the malware components. The archive's APP bundle acts as a dropper for further stages. The infostealer module is largely unchanged, targeting browser history, cookies and saved credentials, crypto wallet extensions and application data, Telegram data, the Keychain file, system and device information, and SSH, AWS, Kubernetes, Git and shell configuration files. What is new is an Objective-C backdoor that disguises itself as Finder and establishes persistence through a LaunchAgent, `.zshrc` modifications and global Git hooks while terminating macOS notification processes so alerts do not reach the user; it can run attacker-supplied AppleScript from its command server, deploy a browser extension or replace an installed Ledger wallet app, and collect and upload files. The campaign was also delivered as a fake crypto wallet site called Toria.
Indicators of compromise · MacSync — 4 shown
yoauction[.]comzanderrealestate[.]comhxxps://zanderrealestate[.]com/curl/85cb26206d920216eee0c5f67e8de516b4d55bd1752025bb3c08a069a44fdbdffbc460f7b29d7e709c28fc9368a592f3140fdb51fff5de54471450e250b6345a
Defanged third-party indicators (abuse.ch). The defanging is deliberate: never click, resolve or fetch these values. An indicator corroborates a report — it never proves one, and its presence here does not mean this story's hosts are listed.
'QR Jacking' Lets Anyone Claim a Branded QR Subdomain and Repoint Printed Codes
Farzan Karimi, who previously led red teams at Google and Electronic Arts, published research showing that QR-code platforms' custom-domain feature can be used to seize companies' branded QR addresses. Demonstrated against QR Tiger's "Own Short Domain" feature, the weakness is that the platform verified only that a CNAME record existed, never who was claiming it — so any account holder could claim a subdomain still pointing at the platform after a business stopped using the service without removing its DNS record, and take it over in under a minute. Because the codes are printed, the effect reaches existing campaigns: Karimi confirmed to iTnews that a QR code generated for a campaign remains at risk for as long as the stale record stands, and printed codes cannot be revoked with a software update. He says he found hundreds of vulnerable companies across manufacturing, healthcare, financial services and technology, published no count and named none, and reported that QR Tiger had not fixed the flaw five months after he reported it. His proposed control — an ownership token published in a TXT record — is standard practice on other SaaS platforms.
- Elementor's Editor Events module bypassed REST nonce validation. — A cross-site request forgery flaw in the Elementor Website Builder plugin, active on 10 million sites, lets an unauthenticated attacker create an administrator account by getting a logged-in administrator to open a single link — no JavaScript, attacker-hosted page or submitted form required, since the module checks the raw request URI for the `elementor/v1/events/` path and skips WordPress's REST nonce check, letting an attacker append that string to requests against other endpoints. It affects only versions 4.3.0 and 4.3.1, used by up to 2 million sites; Patchstack received the report on 22 September and Elementor fixed it in 4.3.2 on 24 September. It has no CVE identifier yet. [BleepingComputer](https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/)
- Two npm packages pose as n8n nodes and pull a binary from a PKI-disguised path. — The OpenSourceMalware archive's newest critical records, both verified on 25 September, are `n8n-nodes-moonlet-helpers` and `n8n-nodes-moonlet-utils`: both present as n8n helper nodes, ship empty stub node code, and run a postinstall that fetches an opaque binary from `mkicom[.]com/.well-known/pki-validation/ct_dn8` — a path styled as a PKI or Certificate Transparency validation endpoint on an unrelated domain — writes it to `/tmp/.nc`, chmods it 0755 and launches it detached through `setsid`. Treated as one campaign lead, this is the same install-hook pattern as the archive's other new records this run, including the PyPI pair `my-private-pkg` / `vercel-runtime-python` (MAL-2026-17180, MAL-2026-17168), which beacons host identifiers to a webhook.site collector and appears to be a dependency-confusion lure at an internal package name. ([n8n-nodes-moonlet-utils](https://opensourcemalware.com/npm/n8n-nodes-moonlet-utils), MAL-2026-17177)
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| ● Tier 1 | Very High | Official / first-party |
| ● Tier 2 | High | Established cyber journalism |
| ● Tier 3 | Moderate | General tech/news media |
| ● Tier 4 | Low | Social / unverified |
Key to this page
Two pill families appear in the text and they answer different questions. A CVE pill colours severity — a measured CVSS band from the National Vulnerability Database. A threat-actor pill colours attribution confidence — how well-corroborated the naming is, which is a claim rather than a measurement. Both are links: a CVE opens the ATT&CK matrix or its wiki page, an actor opens its wiki page.
CVE identifiers
- CVE-XXXX-NNNNCritical · CVSS 9.0+
- CVE-XXXX-NNNNHigh · CVSS 7.0–8.9
- CVE-XXXX-NNNNMedium · CVSS 4.0–6.9
- CVE-XXXX-NNNNLow · below 4.0
- CVE-XXXX-NNNNNo severity resolved — not the same as low
Threat actors · MITRE ATT&CK
- APT29State attribution stated by MITRE ATT&CK
- ShinyHuntersSelf-declared, or criminal-reporting attribution
- Transparent TribeContested — ATT&CK hedges, or two plausible sponsors
- ZIRCONIUMNo attribution in MITRE ATT&CK
Story signals
- ● Tier 1/4Source reliability — 1 official, 4 leads only
- VerifiedCorroborated by a second source or the principal
- ReportedSingle outlet, or a claim still in progress
- UnverifiedA claim we could not corroborate
- ConfirmedBreach acknowledged by the victim or a regulator
- ProbableBreach indicated but not yet acknowledged
- IOCs · FamilyLive abuse.ch indicators exist for that malware family
A collapsed Indicators of compromise block under a story lists defanged abuse.ch indicator values. The defanging is deliberate — never click, resolve or fetch them. An indicator corroborates a report; it never proves one.
Full methodology, evidence grading and caveats: Methodology & reading guide →