// incident review

Cyber Digest — Sector Incident Review: Q3 2026 (to date)

Top incidents by sector and regulatory / technology / thematic changes

11 Sectors
44 Incidents
11 With 3+
Home · Reports · Cyber Digest — Sector Incident Review: Q3 2026 (to date)
📋

Executive Summary

Analysis

Q3 to date is defined by convergence, and the final week hardened it: the quarter that began with the 12-agency edge-device advisory and the Russian Zimbra zero-day closed with the FBI/DOJ takedown of the Chinese QScan/QTRouter espionage-proxy network, Iran-linked Tortoiseshell's infrastructure expansion, the first documented Android malware in car head units, and OpenAI's disruption of a Russian influence operation run through ChatGPT. The direction of travel is sustained targeting of internet and OT infrastructure, with state espionage and ransomware-scale campaigns actively contested.

The regulatory arc through the quarter runs one way: frontier-AI and platform-data law moved from debate to obligation (Illinois' Frontier AI Model Law, the EU AI Digital Omnibus, TikTok's US$400 million child-privacy settlement, ACSC frontier-AI board guidance), and the ACSC issued its most consequential Australia-priority alert of the period on active N-able exploitation. KEV and ICS advisories - including a late-month six-vulnerability add and a rare public CISA red-team report - set the operational tempo for Australian and NZ defence communities.

The human and third-party layers remained the quarter's most reliable attack surfaces: these actors use the human layer as the initial-access vector through vishing (UNC6671, Qantas' 5.7-million-record breach), Sandworm's ClickFix lures, ToxicPanda's on-device banking fraud, and third-party-supplied financial data (Paylogix, US Bank). Safety-critical transport links (CPDLC, car head units), water/OT targeting and maturing disclosure regimes (SEC 8-Ks from Boston Scientific and Nutex Health, the Dutch DPA probe) all close the quarter with the incident set more structured - not less.

Key Judgements

1

Patch-to-exploitation conveyance is the dominant technical risk through Q3 - KEV additions and ICS advisories led scores in nearly half the sectors; state espionage and ransomware infrastructure are now being contested in real time (QScan/QTRouter takedown, Akira on Paylogix).

Confidence: High
2

Chinese and Iranian state-sponsored activity is concentrated on civilian infrastructure - edge devices, IoT, defence supply chains - rather than strategic military systems; the QScan/QTRouter takedown demonstrates serious adversary-competition capacity.

Confidence: High
3

The human/third-party layer is the quarter's most reliable access vector - vishing (UNC6671, Qantas), on-device mobile bank fraud (ToxicPanda) and supplier-platform attacks (Paylogix) - demanding phishing-resistant MFA and continuous supply-chain verification.

Confidence: High
4

Frontier-AI and platform-data obligations are now binding in key jurisdictions while offensive AI capability advances; boards should treat AI governance as an audit-in-scope, board-owned item through Q4.

Confidence: High
5

Vehicle transport OT (car head units, data-link safety systems) and third-party financial infrastructure are the quarter's emerging high-consequence targets; sector-specific OT contingency planning and third-party risk review are defensible board-level asking.

Confidence: Moderate
🎯

Cross-Sector Themes

9 themes

The bottom line up front: these themes cut across every sector-specific incident below, each listing the sectors it touches.

1

State-sponsored campaigns remained the quarter's constant

Q3 is bookended by state-sponsored activity, and the close added chapters: the CISA/FBI/NSA 12-agency advisory on Russian edge-device targeting (mirrored by ACSC), the Russian Zimbra zero-day, Sandworm's ClickFix shift, the China-linked Storm-1175 StormEncryptor disclosure, and the late-August FBI/DOJ takedown of the Chinese QScan/QTRouter espionage-proxy network alongside Iran-linked Tortoiseshell's expansion. The quarter reads as sustained, coordinated targeting of internet-exposed infrastructure across Five Eyes.

🛰️ Defence🏛️ Government🌐 Global (Macro)
2

Ransomware industrialisation reached critical infrastructure

The five-eyes-plus-ROK #StopRansomware advisory on Gunra RaaS dominates the quarter, and the close added Akira's Paylogix ransomware breach (SSNs and financial data on tens of thousands, via a benefits platform) and the LockBit fourth-party claim against US Bank. Third-party-supplied benefits and financial infrastructure is now a first-class ransomware target alongside core operators.

🌐 Global (Macro)⚡ Energy & Utilities🏛️ Government
3

Internet-exposed OT and private-cellular networks are a mapped attack surface

CERT Polska's private-cellular-network intrusion into a Polish heat plant - the first documented use of that pathway into ICS - plus 4,400+ exposed Rockwell PLCs, a 12-state water campaign, and the new NSA/FBI/CISA 'active threat' advisory on AI-assisted attacks on Siemens S7 PLCs, show OT attack paths are formally mapped and actively exploited. The ACSC's OT-isolation guidance is the direct Australian response.

⚡ Energy & Utilities🏛️ Government🚚 Transport
4

Water-sector targeting is expanding state by state

The quarter's water story moved from advisory to incident: a coordinated attack disabled OT at 30+ Minnesota facilities in late July, and the campaign reached 12 US states by early August. These are the incidents behind CISA's and ACSC's OT-focused guidance and the US Senate's water-security legislation.

⚡ Energy & Utilities🏛️ Government
5

Frontier-AI governance shifted from debate to binding obligations

Illinois' Frontier AI Model Law, the EU's AI Digital Omnibus entering into force, ACSC's frontier-AI board guidance and the UK NCSC's disclosure of frontier-AI evaluation incidents all landed in the quarter. Boards now have explicit expectations, not just principles — a direct compliance signal for Australian and NZ organisations.

⚖️ Legal Services🏛️ Government🌐 Global (Macro)
6

Vishing and human-layer social engineering are the top access vectors

UNC6671's vishing wave targeting personal phones to steal SaaS data, Qantas' 5.7-million-record vishing breach, and Sandworm's ClickFix lures all converge on the same conclusion: attackers are converting people into the initial-access vector. Phishing-resistant MFA and out-of-band verification remain the quarter's highest-leverage controls.

💰 Financial Services🚚 Transport🛰️ Defence
7

Health data exposure is widening through non-breach paths

Beyond ShinyHunters' endemic healthcare targeting, the quarter added AI-platform exposure (Loma Linda's IRB dataset uploaded to an external AI service) and cross-provider disclosure (UCLA Health, dating back to 2024), plus the 3.8-million-patient Unlimited Technology Systems breach. Health and education organisations face growing governance obligations over accidental and AI-mediated exposure, not just direct theft.

🏥 Healthcare🎓 Education
8

Aviation and port infrastructure are in the crosshairs

The CISA ICS advisory on CPDLC over ATN-B1 (five CVEs affecting aviation data-link safety systems), the contained cyberattack on North Carolina Ports, and the UAE thwarting a campaign targeting aviation, energy and education all point one way: safety-critical transport operational links are now a live targeting surface.

🚚 Transport⚡ Energy & Utilities🌐 Global (Macro)
9

Supplier and third-party access is the retail and education entry point

Levi Strauss was breached via employee computers, Vincennes schools via their tech provider AME's ransomware incident, and the Q3 retail set repeatedly showed attackers entering networks through trusted vendor accounts and endpoints rather than large-scale server-side hacks. Third-party access control is the shared control across quarters.

🛍️ Retail & Entertainment & Sport🎓 Education🏗️ Construction & Property
💰

Financial Services

4 incidents
1

ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud

Zimperium documented the updated Android banking trojan ToxicPanda (TgToxic) with 167 remote commands, PIN harvesting against more than 140 banking and cryptocurrency apps, and screen-capture plus overlay-based credential phishing across 349 financial institutions in 16 countries. The updated version abuses Android accessibility services, adds fake-overlay lock-screen credential capture, and enables Android Debug Bridge via an automated click chain to unlock and shell-access the compromised device. Verification: Reported (vendor research).

Source: Zimperium · Tier 1/4 — Very High · 2026-08-19 · Score 100
2

Akira Ransomware Breach at Benefits Platform Paylogix Exposed SSNs, Health and Financial Data on Tens of Thousands

Employee-benefits administrator Paylogix disclosed that hackers stole files from its network between 13 and 18 November 2025, including Social Security numbers, electronic signatures, financial account details, health insurance information, medical data and passport numbers; the company was listed on the Akira ransomware leak site in January though it has not attributed the attack itself. State filings show 64,383 affected in South Carolina alone, plus 2,304 in New Hampshire and 1,102 in Vermont, with notices also filed in California, Massachusetts, New Jersey and other states — implying a national total well above 67,000. Law-enforcement is engaged and several class actions are being organised. Akira remains among the most active ransomware families, with Google incident responders ranking it second-most-observed malware family of 2025. Verification: Verified Breach: Confirmed breach

Source: The Record · Tier 2/4 — High · 2026-08-25 · Score 60
3

U.S. Bank Says Breach Claims Tied to Fourth-Party Incident, Denies Own Systems Hit

US Bancorp, the seventh-largest US bank, said LockBit's claim that it had been added to the gang's leak site relates to a "fourth party event that occurred outside" its environment, with no evidence its own systems, networks or data repositories were compromised. LockBit added the bank to its victims list on Thursday morning and threatened to leak data in two weeks, but provided no sample data to substantiate the claim. The episode is the second bank listed on a ransomware leak site this week. Verification: Verified (bank statement to press). Breach: Unverified claim (leak-site listing; bank disputes that its own systems were compromised, pointing to a fourth-party event).

Source: The Record · Tier 2/4 — High · 2026-08-21 · Score 60
4

"Zombie Card" Attack Can Revive Expired Visa Cards for Contactless Payments

Researchers at the University of Massachusetts Amherst demonstrated an attack that revives expired Visa contactless cards at real point-of-sale terminals by rewriting the expiry date the terminal reads over near-field communication (NFC), without breaking any of the card's cryptography. The attack requires the cardholder to be in physical possession of (or near) the expired card, a man-in-the-middle relay positioned between the card and the terminal, the account to remain open under the same primary account number, and the bank not to re-check the expiration during authorisation. Transactions succeeded at most of the five large US banks tested; the researchers also tied the same mechanism to CDCVM-flag tampering, which they described as resting on the same undetected-transaction weakness. Verification: Reported (academic research; no known live abuse reported).

Source: The Hacker News · Tier 2/4 — High · 2026-08-20 · Score 60
ThematicTop thematic change

Mobile-banking trojan escalation and ransomware on third-party platforms lead the financial-cyber quarter

The quarter's financial picture closes with ToxicPanda 2.0's on-device fraud expansion (167 remote commands, PIN harvesting across 140+ banking and crypto apps, and screen/overlay credential phishing across 349 institutions in 16 countries) leading the sector, alongside Akira's Paylogix ransomware breach exposing Social Security numbers and financial data on tens of thousands via a benefits platform, and the LockBit fourth-party claim that US Bank attributes to a third-party event. For Australian banks and fintechs the through-line is credential and custody controls on the mobile endpoint, plus third-party-supplied benefits and payment platforms becoming first-class ransomware targets.

Source: Zimperium, The Record, CyberScoop, July-August 2026

🛰️

Defence

4 incidents
1

CISA, FBI, NSA & 12 Allied Agencies Warn: Improve Router Hygiene to Protect Against Russian State-Sponsored Actors

A joint advisory (AA26-117A) from CISA, the FBI, NSA and 12 allied agencies detailed a sustained Russian state-sponsored campaign targeting network edge devices - routers, VPNs and firewalls - exploiting default credentials, legacy vulnerabilities and weak configurations to gain covert access. The advisory urges organisations replace unsupported edge devices, patch known vulnerabilities, harden management interfaces and audit logs, and was mirrored by the Australian ACSC and Cyber.gov.au for AU organisations.

Source: CISA · Tier 1/4 — Very High · 2026-07-13 · Score 100
2

FBI and DOJ Take Down QScan and QTRouter, the Chinese Espionage Proxy Network Behind QTFY

The Department of Justice announced the takedown on Wednesday of QScan (a platform that scanned and automatically infected internet-of-things devices) and QTRouter (an obfuscation network allowing attackers to make traffic appear to originate from any infected device), both run by China-based Nanjing Xinjiuwei Network Technology and used primarily by China's Ministry of State Security and the People's Liberation Army. The state-sponsored "QTFY" group behind them has since 2018 targeted the Federal Reserve, Department of Energy, DOJ, US Senate, NASA, HHS, NIH, hospitals, telecoms providers, power companies, financial institutions and defence contractors, exploiting devices in more than 130 countries; FBI Assistant Director Brett Leatherman described a complex network of hackers-for-hire and government clients in China. The seized, hard-coded domains rendered both platforms inoperable. The FBI has investigated the infrastructure since 2018, tracing a 2019 NASA intrusion to a Pulse Secure VPN flaw back to China. Verification: Verified

Source: The Record · Tier 2/4 — High · 2026-08-26 · Score 60
3

Iran-Linked Tortoiseshell Expands Infrastructure Across Europe and the Middle East

Group-IB researchers identified new infrastructure tied to Tortoiseshell, an Iranian APT active since at least 2018 that runs espionage against defence, aerospace, technology and military organisations — linked by researchers to Iran's Islamic Revolutionary Guard Corps — including two servers ("uk1" and "uk2") hosted on IP addresses in Britain and further infrastructure in Belgium, Saudi Arabia and the UAE. Group-IB also surfaced new malware samples, including a TwoStroke-like backdoor giving broad control over infected machines and a tool that establishes reverse SSH tunnels between compromised networks and attacker-controlled infrastructure, bypassing inbound protections. The combination suggests Tortoiseshell is widening both its geographic reach and its capability set, and is described as among the most active Iranian APTs of 2026. Verification: Verified

Source: The Record · Tier 2/4 — High · 2026-08-26 · Score 60
4

Leaked Source Code Formally Links Geedge Networks Gateway to China's Great Firewall

American academics presenting at USENIX Security 2026 analysed more than 100,000 files leaked from Geedge Networks last year and found source-code overlap between the company's Tiangou Secure Gateway (TSG) firewall and China's Great Firewall, confirming TSG as one of the filtering system's known traffic-censorship components. Only one of three characterised DNS injectors matched Geedge behaviour, indicating the system involves multiple vendors. The leak also exposed Geedge's export business, giving Western governments concrete visibility into the commercial proliferation of Chinese state censorship technology. Verification: Verified

Source: Risky Biz News · Tier 2/4 — High · 2026-08-21 · Score 60
ThematicTop thematic change

China-linked espionage is contested in the open: the QScan/QTRouter takedown anchors the defence quarter

The quarter closed with the US DOJ takedown of QScan/QTRouter, the Chinese espionage-proxy network behind QTFY targeting the Federal Reserve, DoE, NASA and defence contractors since 2018 - the clearest demonstration of adversaries contested at the infrastructure level - alongside Iran-linked Tortoiseshell's infrastructure expansion and leaked source code linking Geedge's gateway to China's Great Firewall. Layered on the CISA/FBI/NSA 12-agency edge-device advisory (mirrored by ACSC), the defence-industry read is that state-sponsored targeting of internet-exposed infrastructure and IoT is now a documented, contested reality directly relevant to the Australian defence-industrial base under REDSPICE.

Source: The Record, Risky Business, CISA, The Hacker News, July-August 2026

🏥

Healthcare

4 incidents
1

ShinyHunters Leaks 7.1 Million Records Claimed from Medical-Device Maker Baxter International

Baxter International, a Deerfield, Illinois-based manufacturer of renal-care, IV and infusion, surgical and patient-monitoring devices, disclosed on 13 August that it detected unauthorised activity in certain third-party applications and launched an investigation. The ShinyHunters extortion group claimed responsibility on 14 August, gave Baxter a 17 August deadline, and on 19 August released roughly 7.1 million alleged Salesforce records, some containing personally identifiable information. Baxter has not confirmed the data-theft scope, that all 7.1 million records relate to patients, or the identity of the threat actor, and maintains the incident has not affected patient services or its products. ShinyHunters is among the most active extortion groups and counts OneMedical, DentaQuest and Medtronic among prior healthcare victims. Verification: Verified Breach: Probable breach

Source: HIPAA Journal · Tier 2/4 — High · 2026-08-26 · Score 60
2

Medical-Device Maker Boston Scientific Says Cyberattack Disrupted Operations Globally

Massachusetts-based Boston Scientific, one of the world's largest medical-device manufacturers (59,000 employees, 13 manufacturing facilities, revenue over $20 billion in 2025), said a cyberattack detected on 25 August caused a network outage and "impacted access to certain operating systems and business applications, including the ability to process and ship customer orders". The company activated incident-response procedures, contracted external experts and filed with the SEC, but has yet to disclose attack type, attacker, initial-access vector, or whether data was exposed; no extortion actor has claimed the attack, and restoration timelines are unknown. Verification: Verified

Source: BleepingComputer · Tier 2/4 — High · 2026-08-26 · Score 60
3

American Addiction Centers & Octopus Pathology Disclose Hacking Incidents

American Addiction Centers and Oculus (Octopus) Pathology disclosed hacking incidents involving unauthorised access to protected health information. Both entities filed the required notifications consistent with federal and state breach-notification rules; details on record volumes and impacted individuals were limited in the early disclosures. Confidence: Confirmed breach (companies disclosed incidents to regulators). Breachability: Confirmed breach.

Source: HIPAA Journal · Tier 2/4 — High · 2026-08-18 · Score 60
4

Poland Probes MyDr Healthcare Software Breach Potentially Affecting 19 Million People

Polish authorities are investigating a cyberattack on healthcare software provider MyDr that may have exposed data belonging to nearly 19 million people and more than 12,000 medical facilities. MyDr, a privately-owned Polish company whose software connects healthcare providers to Poland's nationwide P1 e-health platform, confirmed the incident and said it had identified and removed the cause and introduced additional security measures, without detailing the vulnerability. Polish Digital Affairs Minister Krzysztof Gawkowski said the e-Health Center was replacing affected credentials as a precaution. Authorities said hackers obtained unauthorised access to historical data held through April 2024, but that it may not involve all MyDr customers or their patients; the company said it had found no evidence the data had been published. Confidence: Confirmed breach (company and Polish authorities publicly confirmed the intrusion; the 19M figure is an upper-bound estimate from authorities). Breach claim: Confirmed breach.

Source: The Record · Tier 2/4 — High · 2026-08-17 · Score 60
ThematicTop thematic change

Medical-device supply chain and ShinyHunters shape the quarter's healthcare close

The quarter ends with the healthcare picture shaped by two threads: medical-device manufacturer disruption (Boston Scientific's global operations struck late August; Baxter's roughly 7.1 million-record ShinyHunters claim) and the sustained ShinyHunters targeting of health-sector data that Health-ISAC flagged. Beneath sits Poland's MyDr clinical-software breach (19 million upper bound) and a persistent thin tail of provider and cross-provider disclosures. The through-line is clinical-software and device-supply-chain exposure, not just direct network intrusion.

Source: HIPAA Journal, BleepingComputer, The Record, July-August 2026

🎓

Education

4 incidents
1

CISA Unveils New Cybersecurity Resources for K-12 Schools and Districts

CISA released new cybersecurity resources for K-12 schools and districts, expanding its outreach to a sector that has become a frequent ransomware and data-breach target. The package includes practical guidance tailored to school IT environments and reinforces the agency's broader K-12 security initiative. Confidence: Confirmed (first-party release).

Source: CISA · Tier 1/4 — Very High · 2026-08-12 · Score 100
2

University of St. Thomas (Houston) to Compensate Data Breach Victims

The University of St. Thomas in Houston agreed to compensate victims of a data breach, following class action and regulatory scrutiny. The case reflects the growing legal and financial consequences universities face after student and staff data is compromised, alongside settlement obligations.

Source: GovTech · Tier 2/4 — High · 2026-08-06 · Score 60
3

Vincennes School District Shuts Down Servers After Tech Provider Ransomware Attack

The Vincennes Community School Corporation in Indiana took servers offline on 4 August after a ransomware attack hit its technology provider, AME, which had been targeted via one of the provider's other customers. Phones and internet at the district's building were knocked out as a precaution, although the district stated no district data had been compromised. K-12 ransomware incident mirroring the now-common attack-on-the-vendor, not-the-school pattern.

Source: WTHI-TV · Tier 3/4 — Moderate · 2026-08-04 · Score 55
4

University of Tennessee Sues Anthropic Over AI Research Patent Infringement

The University of Tennessee has filed a patent suit against Anthropic, challenging the technology's core architecture and testing what universities are owed for AI research. The case could set a precedent for other institutions asserting IP rights over AI model training data and research outputs. The lawsuit tests whether universities are entitled to compensation when their research underpins commercial AI systems.

Source: Inside Higher Ed · Tier 3/4 — Moderate · 2026-08-03 · Score 40
ThematicTop thematic change

K-12 schools are now a named government security priority as campuses stay breach-prone

CISA's K-12 cybersecurity resource package marks the sector's formal arrival as a government-priority attack surface, following a window in which schools appeared repeatedly in breach and privacy disputes. Edtech vendor dependence ran through the quarter: an edtech-provider ransomware attack knocked out a school district (Vincennes) and AI-IP litigation (Tennessee v. Anthropic) keeps vendor and student-data governance the defining educational-risk questions.

Source: CISA, GovTech, WTHI-TV, July-August 2026

🏛️

Government

4 incidents
1

CISA Adds Six Known Exploited Vulnerabilities to the KEV Catalog

CISA added six vulnerabilities to its Known Exploited Vulnerabilities Catalog on 26 August based on evidence of active exploitation: Citrix NetScaler ADC and NetScaler Gateway CVE-2026-8452 (memory buffer overflow), Microsoft SQL Server CVE-2019-1068 (remote code execution), Linux Kernel CVE-2022-0995 (out-of-bounds write), Ajax.NET Professional CVE-2021-23758 (deserialisation of untrusted data), Red Hat Libuser CVE-2015-3246 (race condition) and Red Hat Automatic Bug Reporting Tool CVE-2015-5287 (privilege escalation). US federal agencies must remediate under BOD 26-04 timelines and check for pre-patch compromise. The Citrix NetScaler addition is the standout — a recent, network-edge flaw — and all six merit review beyond the US federal enterprise. Verification: Verified

Source: CISA · Tier 1/4 — Very High · 2026-08-26 · Score 100
2

CISA Red Team Report: Water Utility Detected Simulated Attack in Minutes, Government Organisation Missed Domain-Wide Compromise

CISA's rare public red-team advisory (AA26-237A) describes two voluntary engagements: at a water organisation ("Organization B"), defenders triaged spearphishing alerts and quarantined workstations within 2, 10 and 20 minutes, then detected and isolated a second push reaching the OT DMZ bastion host; at a government organisation ("Organization A"), red teamers moved from internal phishing to domain-elevated privileges and sensitive business systems undetected, their alerts buried among thousands of false positives in a SOC whose staff saw but did not respond to EDR notifications. Both organisations underestimated cloud risk, lacked Conditional Access for workload identities, and had no token-revocation process. Verification: Verified

Source: CISA · Tier 1/4 — Very High · 2026-08-25 · Score 100
3

CISA Adds Two TrueConf Server CVEs to Known Exploited Vulnerabilities (CVE-2026-72529/72530)

CISA added TrueConf Server CVE-2026-72529 (missing authentication for critical function) and CVE-2026-72530 (code injection) to the Known Exploited Vulnerabilities catalogue on 20 August — the third consecutive day of KEV additions. The pair reflect a criminal ecosystem continuing to add internet-facing collaboration and conferencing products to its attack list. The additions start the 14-day federal remediation clock under BOD 26-04 and extend the same urgency horizon to any operator of TrueConf. Verification: Verified (official CISA feed).

Source: CISA · Tier 1/4 — Very High · 2026-08-20 · Score 100
4

ACSC Issues High-Rated Alert on Active Exploitation of N-able Slopes — Australia Priority

The Australian Cyber Security Centre (ACSC) issued a High-rated alert on 19 August warning of active exploitation in Australia of N-able and N-central remote monitoring and management (RMM) vulnerabilities tracked as CVE-2026-18556 and CVE-2026-18577. The ACSC rated the alert High and directed Australian organisations — across business, critical infrastructure and government — to assess exposure and apply mitigations. This is a direct, Australia-specific active-threat warning in an RMM product class long-targeted by Australian campaigns. Confidence: Confirmed (official ACSC alert; High rating). Breach claim: N/A (vulnerability/advisory).

Source: ACSC · Tier 1/4 — Very High · 2026-08-19 · Score 100
RegulatoryTop regulatory change

KEV-catalog velocity and a rare public red-team report close the government quarter

CISA ended August by adding six actively exploited vulnerabilities to its KEV catalogue (headlined by the Citrix NetScaler edge flaw) and publishing a rare public red-team report contrasting a water utility that detected and isolated a simulated attack in minutes against a government SOC that missed domain-wide compromise. The ACSC's high-rated N-able active-exploitation alert remains the quarter's Australia-priority anchor.

Source: CISA, ACSC, July-August 2026

Energy & Utilities

4 incidents
1

CISA Issues Multiple Siemens and Johnson Controls ICS Advisories

CISA published a batch of ICS advisories covering vulnerabilities in Siemens products — LOGO! Soft Comfort, Solid Edge, Simcenter Femap, Parasolid, Siveillance Video, Desigo DXR and PXC controllers, License Server (SLS) and RUGGEDCOM APE1808 — and the Johnson Controls Metasys building-management platform. The advisories highlight continued risk in industrial control and building-automation systems across energy and industrial environments. Confidence: Confirmed (official advisories).

Source: CISA · Tier 1/4 — Very High · 2026-08-13 · Score 100
2

CISA Urges Water and Wastewater Systems to Protect OT Against Activity Targeting PLCs

CISA issued an urgent alert urging the Water and Wastewater Systems Sector to protect operational technology (OT) environments against malicious activity specifically targeting programmable logic controllers (PLCs). The alert follows last week's coordinated cyberattack that disabled OT at 30+ Minnesota water systems (covered 30 July) and continues a wave of OT-focused guidance from CISA and the ACSC.

Source: CISA · Tier 1/4 — Very High · 2026-07-31 · Score 100
3

ACSC Urges Organisations to Isolate Vital OT and Critical Enabling Systems

In a proactive technical publication, the Australian Signals Directorate’s ACSC issued comprehensive advice outlining methods for isolating vital operational technology (OT) and core enabling networks from corporate IT networks. The ASD highlights that network isolation is the single most effective defence to contain active cyberattacks, prevent lateral movement of adversaries, and ensure critical physical services remain running.

Source: ACSC · Tier 1/4 — Very High · 2026-07-28 · Score 100
4

Poland Uncovers Second Heat Plant Cyberattack That Went Hidden for Months

CERT Polska revealed at DEF CON that an attack on a Polish combined heat and power plant supplying ~50,000 residents went unrecognised as malicious during last winter, initially blamed on a contractor error. The investigation traced the first known use of a private cellular data network as an ICS pathway: attackers moved from already-compromised wind farm firewalls to a cellular router, then across the private network to a heat plant controller still running factory-default credentials, dwelled 11 days, and disabled Siemens controllers on 29 December before wiping network equipment to destroy forensic evidence — only one legacy router's logs enabled reconstruction. CERT Polska warns the "trusted" private cellular network misconfiguration is believed widespread internationally.

Source: The Record · Tier 2/4 — High · 2026-08-11 · Score 60
TechnologyTop technology change

ICS and building-automation advisory volume is the quarter's defining OT signal, now with demonstrated impact

Siemens and Johnson Controls ICS advisories, the NSA/FBI/CISA advisory on AI-assisted targeting of Siemens S7 PLCs, Poland's heat-plant private-cellular intrusion and the 12-state water campaign together show OT advisory volume and demonstrated impact. ACSC's OT-isolation guidance is the direct Australian playbook under the SOCI Act and NZISM.

Source: CISA, ACSC, The Record, July-August 2026

🏗️

Construction & Property

4 incidents
1

CISA Advisory: Johnson Controls Simplex Incident Manager Credential Leak

CISA published ICS advisory ICSA-26-232-01 for the Johnson Controls Simplex Incident Manager (versions <= V2.01), affecting fire-alarm and incident-management systems in commercial facilities, government, transport and energy settings. Successful exploitation lets a local low-privilege attacker extract user credentials — passwords and authentication tokens — from system memory, potentially reaching the application and connected systems (CVE-2026-27875, CVSS 5.8). For building operators, the advisory is a reminder that building-automation and life-safety networks hold credentials with inherently privileged access to physical environments. Verification: Verified (official CISA advisory).

Source: CISA · Tier 1/4 — Very High · 2026-08-20 · Score 100
2

Cushman & Wakefield Data Breach Exposes Social Security Numbers

Global commercial real estate services firm Cushman & Wakefield disclosed a breach originating in late April 2026, when attackers exfiltrated files including names and Social Security numbers. The breach was reported to the California and Massachusetts attorneys-general on 7 August 2026, with affected consumers offered 24 months of Experian credit monitoring; ransomware group ShinyHunters claimed responsibility on the Tor network in May.

Source: Claim Depot / regulator notification · Tier 3/4 — Moderate · 2026-08-07 · Score 60
3

Case & Associates Properties Data Breach Exposes SSNs; Lawsuit Possible

Commercial and residential property manager Case & Associates, operating across Arkansas, Kansas, Mississippi, Missouri, Oklahoma and Texas, disclosed a data breach in which an unauthorised actor accessed its network between September 2025 and March 2026. A filing with the Texas Attorney General's Office indicated names and Social Security numbers were exposed, with notifications sent to affected individuals and attorneys investigating a potential class action.

Source: ClassAction.org · Tier 3/4 — Moderate · 2026-07-16 · Score 60
4

Sunrise Company Data Breach Exposes Personal Info; Akira Ransomware Blamed

California-based real estate developer Sunrise Company, whose portfolio spans more than 20 resort communities, reported a data breach after detecting unauthorised acquisition of files on its network on 23 April 2026. A notification submitted to the California Attorney General's Office on 28 July 2026 confirms names were exposed, while dark-web monitoring platform Ransomware.live attributes the attack to the Akira ransomware group, which claims exfiltration of 13 GB of data.

Source: ClassAction.org · Tier 3/4 — Moderate · 2026-07-29 · Score 55
ThematicTop thematic change

Property-sector breaches keep surfacing through breach-notice channels

Construction and property incidents continue to surface via breach-notice and legal channels rather than major press: Cushman & Wakefield's SSN exposure, Orova on Yost Home Improvements, ABC Supply, and late-quarter Turner Construction's salaries/bank/SSN disclosure. The pattern for quarter-end: property firms quietly accumulating disclosure obligations. (Sector supplemented by web collection.)

Source: Web collection (breach-notice aggregators), July-August 2026

🛍️

Retail & Entertainment & Sport

4 incidents
1

GTA VI Pre-Release Leaks Prompt Take-Two Subpoenas in High-Profile Data-Extortion Case

A persona calling itself "CyberLeek" published pre-release Grand Theft Auto VI gameplay footage across roughly eight days before the publisher's planned reveal, one of the year's highest-profile data-extortion incidents. Take-Two Interactive has petitioned federal courts for DMCA subpoenas against Discord, Microsoft and X (a Google petition remains pending) seeking identities, treating it like an insider-threat investigation; watermark crypto-wallet addresses indicate monetisation alongside the stated anti-corporate protest, prompting security researchers (Cynthia Kaiser, Katie Moussouris) to characterise it as a novel monetisation model for stolen pre-release content distinct from classic quiet ransom negotiations. The affected sites went offline as of Monday. Verification: Verified

Source: CyberScoop · Tier 2/4 — High · 2026-08-25 · Score 60
2

LACMA Data Breach Exposed Social Security and Medical Data

The Los Angeles County Museum of Art disclosed that a breach detected on 11 July 2025 — with the investigation completed in late February 2026 — exposed full names, dates of birth, Social Security numbers, driver's licence or government-issued IDs, partial financial account and payment-card numbers, health-insurance information and medical information (provider names, treatment and diagnosis details). LACMA says it notified law enforcement and impacted individuals, offering a year of identity-theft and fraud protection. The museum is among the largest art institutions in the western United States. The number of affected individuals has not been disclosed. Verification: Verified Breach: Confirmed breach

Source: BleepingComputer · Tier 2/4 — High · 2026-08-25 · Score 60
3

DecryptAds: New Free Service Reveals Who's Tracking You — and Ad Networks Involved

Security researcher Brian Krebs launched DecryptAds, a free service that decrypts the encrypted payloads many news sites send to advertising and tracking networks, letting users see exactly which ad networks are profiling them. The tool exposes the breadth of third-party tracking across the web.

Source: KrebsOnSecurity · Tier 2/4 — High · 2026-08-14 · Score 60
4

Levi Strauss Says Hackers Breached Employee Computers, Accessed Corporate Data

Levi Strauss & Co. disclosed that hackers breached employee computers and accessed corporate data. The denim giant joins a growing list of retail organisations targeted via employee endpoint compromise rather than server-side intrusion. The breach is under investigation; no ransomware claim has been made public.

Source: The Record · Tier 2/4 — High · 2026-08-07 · Score 60
ThematicTop thematic change

Data-extortion and supply-chain issues shape the retail-entertainment close

GTA VI pre-release leaks (Take-Two's DMCA subpoenas), the LACMA SSN/medical breach, the expired-domain streaming/malware network and SafePal's wallet-manufacturer breach together show data-extortion and supply-chain vectors alongside the ongoing endpoint entry (Levi Strauss). The consumer-data and digital-trust surfaces, not just the server-side hack, dominate the sector's incidents.

Source: CyberScoop, Infoblox, SafePal, The Record, July-August 2026

🌐

Global (Macro)

4 incidents
1

OpenAI Bans Russian ChatGPT Accounts Behind a Covert Influence Operation

OpenAI said it disrupted a covert influence campaign by banning a cluster of ChatGPT accounts originating in Russia (using VPNs) that were used to promote the "International Burke Institute", a fictitious Israeli think tank complete with plagiarised academic articles and a "sovereignty index" that praised Russia — a template for AI platform-enabled covert influence ahead of an audience's ability to verify. The action reflects platform-scale detection of AI-assisted influence operations and adds a further example of AI being turned to disinformation. Verification: Verified

Source: OpenAI · Tier 1/4 — Very High · 2026-08-26 · Score 100
2

CISA Adds Metabase SQL-Injection Flaw (CVE-2026-72898) to Known Exploited Vulnerabilities

CISA added CVE-2026-72898 — an unauthenticated SQL-injection vulnerability in the Metabase analytics/BI platform — to its Known Exploited Vulnerabilities catalogue. Exploitation lets an unauthenticated remote attacker inject arbitrary SQL into the Metabase application database, gain administrator access, change application configuration and steal stored credentials for connected databases. The addition obliges federal civilian agencies to remediate under BOD 26-04. Confidence: Confirmed (official CISA catalogue entry).

Source: CISA · Tier 1/4 — Very High · 2026-08-13 · Score 100
3

FBI, CISA and International Partners Warn of Gunra Ransomware Targeting Critical Infrastructure

A joint advisory (AA26-222A) from the FBI, CISA, DoD DC3, NSA, US Secret Service and the Republic of Korea's National Police Agency details Gunra, a ransomware-as-a-service variant derived from leaked Conti source code. Gunra first emerged April 2025, launched a structured RaaS affiliate program in early 2026, and operates a double-extortion model with a Tor-based negotiation portal and dedicated leak site. Victim sectors span healthcare, financial services, critical manufacturing, transport, government, utilities, academia, media and retail across the Americas, Europe, the Middle East, Africa and Asia-Pacific. The advisory includes patching priorities for internet-facing VPN/RDP, offline immutable backups, and network segmentation. Confidence: Confirmed (joint official advisory with IOCs).

Source: CISA · Tier 1/4 — Very High · 2026-08-10 · Score 100
4

Cryptographic Context Injection vs Grok — Data Exfiltration Via Encrypted Instructions

Mixed teams demonstrated that AI assistants remain vulnerable to a "cryptographic context injection" attack: malicious instructions embedded in the encrypted transport at the client boundary can be read by the model as legitimate context, allowing a malicious web page to steal Grok chat data (Ars Technica's Dan Goodin; tested in the context-injection paper published this week). The root problem is that LLM products do not place a trust boundary at the same layer as their users; xAI was informed in June, and the assistant was still returning data when the report went live. For AI-security teams the takeaway is concrete: separation of model-visible context from user directives is not solved by prompt bans. Verification: Reported (independent disclosure with live retest).

Source: Ars Technica · Tier 2/4 — High · 2026-08-20 · Score 60
ThematicTop thematic change

AI-enabled influence, signed-driver weaponisation and RMM exploitation define the macro quarter

August's close put AI-enabled activity at the macro fore: OpenAI's disruption of a Russian ChatGPT-influence operation, Check Point's demonstration of the Defender BTR.sys driver for kernel-level attacks, and continued patch-to-exploitation conveyance (SharePoint RCE, Metabase, the Gunra RaaS advisory) anchor the quarter's technical picture. Australia's MSPs remain directly exposed via the N-able N-central campaign that drove the quarter's hotfix cycle.

Source: OpenAI, Check Point Research, CISA, The Hacker News, July-August 2026

🚚

Transport

4 incidents
1

First Malware Family Built for Car Head Units Spreads Via Firmware Updaters

Kaspersky researchers documented a malware family infecting Android-based vehicle head unit firmware made by DoFun, spreading through the devices' own built-in updaters — the first documented case of malware with an infection chain specific to car head units. Attributed with high confidence to the MoYu Group, the multi-stage downloader enables ad fraud and recruits infected units into a residential proxy botnet. The finding extends botnet economics into vehicle-adjacent consumer hardware that sits, largely unpatched, on home networks.

Source: Kaspersky Securelist · Tier 1/4 — Very High · 2026-08-21 · Score 100
2

CISA Issues ICS Advisory on CPDLC over ATN-B1 Vulnerabilities (Five CVEs)

CISA released ICS advisory ICSA-26-219-01 covering five CVEs (CVE-2025-71409 through 71413, CVSS 7.1) affecting Controller-Pilot Data Link Communications (CPDLC) over ATN-B1. The system relies on legacy clear-text, unauthenticated radio-frequency links that allow unauthorised message injection, denial-of-service, and forced session resets in the air-traffic-control data link. CISA notes this does not constitute an unsafe aircraft condition but can degrade operational safety margins by increasing workload and delaying safety-critical instruction delivery. Reported by Armasuisse researcher Martin Strohmeier.

Source: CISA · Tier 1/4 — Very High · 2026-08-07 · Score 100
3

Qantas Tech-Support Scam (Vishing) Led to Massive Data Breach; Privacy Commissioner Clears Carrier

A tech-support vishing scam caused a massive data breach at Australian airline Qantas, with reports of 5.7 million customers' personal information leaked after a fake 'Qantas IT help' caller tricked a contact-centre agent into connecting the CRM to a data-extraction tool. The Office of the Australian Information Commissioner found Qantas did not breach the Australian Privacy Principles and declined to open a formal probe, though class actions remain in train. The incident demonstrates telephone-based social engineering of the human layer, not a technical intrusion.

Source: The Register · Tier 2/4 — High · 2026-07-16 · Score 65
4

UAE Thwarts Coordinated Cyber Attacks on Aviation, Energy and Education Sectors

The UAE Cyber Security Council said on 10 August that organised cyber attacks targeting the aviation, energy and education sectors had been detected and repelled before any systems or services were compromised. The council said the attacks included attempts to breach digital systems and infrastructure, targeting of operational accounts and data, and targeted phishing campaigns exploiting users as entry points. The announcement follows the UAE foiling a wave of sophisticated attacks on its financial sector in July, and precedes broader regional scrutiny of critical-infrastructure protection: even a thwarted campaign of this scope signals serial, sector-spanning targeting of Gulf critical infrastructure.

Source: The National · Tier 2/4 — High · 2026-08-10 · Score 60
TechnologyTop technology change

Vehicle-connected hardware and safety-critical links mark the transport close

The quarter closed with the first documented Android malware targeting car head units (Kaspersky, via legitimate DoFun firmware updaters) leading the sector's incidents, alongside the CPDLC/ATN-B1 safety-data CVEs and the aviation/port themes (Qantas' vishing breach, the UAE thwarted campaign, North Carolina Ports). Vehicle-adjacent consumer hardware and safety-critical operational links are the emerging transport targets.

Source: Kaspersky Securelist, CISA, The Register, July-August 2026