GreenCyber

GreenCyber / Light reading / Week ending 23 August 2026

The Global Threat Summary, week ending 23 August 2026

Almost nothing serious this week happened inside the organisation it happened to. Four of the five stories are about a system the victim did not run.

Global Threat Summary

In one line: almost nothing serious this week happened inside the organisation it happened to.

Australia's cyber agency issued its first alert since 9 July, and it was not about a product most boards have heard of. It was about the console a managed service provider uses to run its customers' computers. ASD said it had seen those systems being targeted in Australia and told organisations to go and ask their IT provider whether the patch had been applied. That is an unusually blunt instruction from a government agency, and it is blunt because for most organisations there is nothing else to do. The machine at risk is not yours. The decision about it is not yours either.

The same shape turned up four more times in seven days, each time a little further away. An Australian online retailer told its customers that the data published about them was held by a third party provider it has not named. An Australian accommodation group with more than a hundred properties across Australia, New Zealand and Fiji said the same thing about a different provider it has not named either. Both disclosed quickly, both notified the regulators, and neither could tell a customer whose systems actually failed. Then a large American bank, listed on a criminal site, investigated and said the matter related to an event at a fourth party. Not its supplier. Its supplier's supplier. Very few organisations maintain a register that reaches the third party. Almost none reach past it, and this week the risk did.

The second thing worth a director's attention is that the week's numbers moved, and they moved in the same direction. A health technology company that told regulators in March that a breach had affected around three hundred and fifty thousand people filed an updated figure this week of more than three and three quarter million. Microsoft published a maximum severity flaw in the identity service most Australian organisations sign in through, marked it as being exploited, and corrected that the following day to say it never had been. A widely read criminal leak site, read by researchers and journalists and quoted into board papers, published dozens of entries this week that were not victims at all. In each case the first number travelled widely and the correction travelled less far. Any organisation that made a decision on the first version and never went back is holding a number that has since been withdrawn.

Third, and shortest. Software makers released fixes this week and attackers were using the same flaws within days. One development platform was patched on the Monday and was being exploited by the Thursday. A virtualisation product was attacked five days after an emergency patch. A mail platform came with a three day deadline attached. Three days is not a warning about the future. It is the current interval, and any patch cycle measured in months is a decision to arrive after the attacker rather than a schedule.

The last thing is quieter and it is genuinely good news, which this document rarely carries. Australia opened recruitment into a new Defence Cyber Reserve Force, built in twelve months, with a new entry pathway that recognises industry experience rather than requiring people to start again. Every board that has sat through an incident has asked afterwards where the people are supposed to come from. This is the first structural answer in a while, and the people it wants are already sitting in Australian businesses.

Three things worth a leadership meeting

One. The supplier question has a layer underneath it, and almost no register goes that deep. This week an organisation was told its customers' data was at risk because of an incident at a company its own supplier had contracted. Third party risk management, as most organisations practise it, is a questionnaire sent to the companies you pay. It does not reach the companies they pay, and it produces no answer at all to the only question a customer asks, which is whose systems failed.

Two. The first number published about an incident is routinely wrong, and it is usually wrong low. One victim count moved by more than a factor of ten between March and this week. A maximum severity flaw was recorded as under attack and then recorded as never having been. Nobody behaved badly in either case, and both were corrected in public by the organisation that got it wrong, which is the system working. The governance failure is not theirs. It is downstream, in every organisation that acted on the first figure and never scheduled a moment to look again.

Three. Three days from public fix to active attack is now the planning number. Not the exception, not the worst case, the middle of this week's range. An organisation that patches monthly has decided, in advance and usually without noticing, that it will be exposed for roughly four weeks each time. That may be an acceptable decision. It is not currently a decision anybody has been asked to make out loud.

Three questions to put to the executive team

  • Who operates the system that can reach every one of our computers, is it a company we pay or a company they pay, and when did we last see evidence rather than assurance that they had patched it?
  • If a supplier we have never heard of lost our customers' data this week, who here would find out, how would they find out, and what could we honestly tell a customer about whose systems failed?
  • Name the last incident number this business acted on, ours or somebody else's. Who has looked at it since, and if it has changed, what did we change back?

Cross sectoral, the items that reach every industry

Eight items last week reached organisations regardless of what they do. They are set out here, ahead of the industry breakdown, because a reader who scans only their own sector would otherwise miss them.

Exploited, and confirmed as exploited

N-able N-central, CVE-2026-18556 and CVE-2026-18577, ASD says it is being targeted in Australia. Cross sectoral. [Confirmed]

  • ASD's ACSC published a HIGH ALERT at 2:44pm Australian eastern time on Wednesday 19 August. Its own words: "ASD's ACSC has observed the targeting of vulnerabilities affecting the N-able N-central product within Australia." Note the wording. The alert is titled active exploitation and the body says observed targeting, and the distinction is preserved here rather than tidied. ASD rates a high alert as requiring action within 48 hours, with generally no mitigating factors available and impact widespread among customers.
  • N-able N-central is a remote monitoring and management platform. Managed service providers and large enterprise IT departments use it to discover, manage, automate and secure endpoints. Administrative control of the console is the level of access a provider's own engineers hold across every machine they manage. Both flaws are authentication bypass through an alternate path, and the second exists because the fix for the first was incomplete, which CISA's catalogue entry states in its own text.
  • Dated context, and it is what makes this a story this week rather than a restatement. The flaws, the patches and the first observed exploitation are early August. N-able patched on 1 August and released Hotfix 2 on 6 August. CISA added the two entries on 4 and 3 August. What is in window is the Australian government saying, in its own name, that this is being targeted here.
  • Scoring, because it is not agreed and the disagreement is useful. N-able's own CVSS 4.0 score is 8.2 for both. NVD's independent CVSS 3.1 assessment is 7.4 for CVE-2026-18556 and 8.1 for CVE-2026-18577. EPSS as at 23 August puts CVE-2026-18577 at 4.10 per cent and CVE-2026-18556 at 0.49 per cent, which is not a contradiction of the catalogue listing and is covered below.
  • The attacker behaviour is worth naming precisely because it is not a vulnerability problem. Where exploitation has been examined, the attacker used N-central's built in Take Control feature to reach the machines downstream and registered a Cloudflare tunnel for persistence, which connects outbound and therefore needs no inbound firewall rule and no listening port. That is Huntress, Rapid7 and Arctic Wolf reporting, not ASD, and ASD names neither technique. [Reported]

Sources: ASD's ACSC alert, 19 August 2026, primary and read directly; CISA Known Exploited Vulnerabilities catalogue, version 2026.08.21, pulled directly; NVD records for both CVEs, pulled directly; FIRST EPSS API, scores as at 23 August 2026, pulled directly; N-able security advisory; Huntress; Rapid7; Arctic Wolf; The Register; SecurityWeek; The Hacker News; Help Net Security; Cyber Daily.

GitLab, CVE-2026-19478, patched on the Monday and exploited by the Thursday. Cross sectoral. [Reported]

  • GitLab released fixed versions on 17 August, out of its normal twice monthly patch schedule, for a GraphQL code injection flaw that allows an unauthenticated attacker to modify or delete public projects and user data. Affected versions are 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6 and 19.2 before 19.2.4. GitLab's own CVSS score is 9.4.
  • Public reporting of in the wild exploitation followed on 20 August, three days after the fix. GitLab.com and GitLab Dedicated were already patched, so this lands on self managed installations only.
  • The whole story sits inside the window, which is rare and is why it is the cleanest available answer to the question of why a monthly patch cycle is not a patch cycle. It needs no decoration.
  • Self managed GitLab usually holds the source code, the pipeline credentials and the deployment keys in one place, so the consequence is not the repository, it is what the repository can reach. No named victim organisation has been confirmed by anyone.
  • EPSS as at 23 August is 1.94 per cent. The flaw was reported through GitLab's own bug bounty programme, which is worth one line: it was found by somebody who was paid to look and chose to report it.

Sources: GitLab security release, 17 August 2026, primary; NVD record, pulled directly; FIRST EPSS API, 23 August 2026; Horizon3 technical analysis; SecurityWeek; The Hacker News; GovInfoSecurity; eSecurity Planet; Field Effect.

VMware vCenter, CVE-2026-59310, a China nexus assessment and Babuk derived ransomware. Cross sectoral. [Reported]

  • CISA added the path traversal flaw to the exploited catalogue on 18 August with a three day remediation deadline of 21 August. Broadcom's fix is dated 29 July, so the vulnerability is dated context and the catalogue listing is the in window event that turns a vendor report into a confirmed exploited entry.
  • German incident response firm QUIRSO reports a coordinated global campaign, with compromised systems beginning to contact attacker infrastructure on 3 August, five days after the emergency patch. The chain runs through unauthenticated code execution to cron based execution, payload staging, single sign on account creation, persistence, discovery, ESXi access and finally ransomware built from the leaked Babuk code.
  • QUIRSO assesses with moderate confidence that the operator is a Chinese speaking actor working in the UTC plus eight time zone, on the basis of Chinese language artefacts in attacker created scripts, apparent reuse of research from a Chinese security publication and repeated use of Chinese language tooling. That is one firm's assessment in its own hedged words and no independent party has reproduced it. [Assessment]
  • The figures, 361 addresses across 47 countries, come from the same single source. The Hacker News, Infosecurity Magazine, Dark Reading and BleepingComputer all cover QUIRSO rather than confirming it independently, and that difference is stated rather than blurred. QUIRSO's own reading is that the ransomware may not have been the primary objective, which is a firm arguing against the more saleable version of its own finding.
  • Persistence installed through a virtualisation management plane survives the patching of the flaw that allowed it. Applying the fix is the beginning of the work here and not the end of it. EPSS as at 23 August is 2.40 per cent.

Sources: CISA Known Exploited Vulnerabilities catalogue, version 2026.08.21, pulled directly; Broadcom advisory, 29 July 2026; QUIRSO research, August 2026; FIRST EPSS API, 23 August 2026; The Hacker News; Infosecurity Magazine; Dark Reading; BleepingComputer.

Zimbra, CVE-2026-73570, a national CERT warning and a three day federal deadline. Cross sectoral. [Reported]

  • CERT Polska reported on 17 August that the flaw was being actively exploited, urging immediate version checks and compromise reviews. A national CERT saying it is seeing exploitation is a primary record and it is the strongest element here.
  • It is a pre authentication OS command injection in Zimbra Collaboration's SNMP notification handling, allowing an unauthenticated attacker to execute commands as the zimbra user on the mail server. It affects Zimbra Collaboration before 10.1.20 only where the zimbra-snmp package is installed and SNMP notifications are enabled, which is a real limiting condition and is stated rather than dropped. CVSS 8.9.
  • CISA added it to the exploited catalogue on 21 August with a remediation deadline of 24 August, which is today. That deadline binds United States federal agencies and nobody else, and it remains the clearest published opinion available on how fast this needs to be gone.
  • The patch has existed since 20 July, in version 10.1.20. This is a month old fix reaching a national CERT alert and a federal deadline, and the interval is the finding rather than the flaw.
  • Australian relevance, stated carefully. ASD published an advisory on 23 July about Russian state supported actors phishing users of Zimbra Collaboration Suite. That is a different issue from this one and the two are not connected by anybody. What they share is the product, which has now drawn an Australian government advisory and an actively exploited catalogue entry inside five weeks. [Assessment]

Sources: CERT Polska, 17 August 2026; CISA Known Exploited Vulnerabilities catalogue, version 2026.08.21, pulled directly; Zimbra release notes for 10.1.20; ASD's ACSC advisory, 23 July 2026, pulled directly; SecurityWeek; The Hacker News; Security Affairs.

Ten entries on the exploited catalogue in seven days, and two of them are machine learning infrastructure. Cross sectoral. [Confirmed]

  • Counted directly from the catalogue, version 2026.08.21, which holds 1,674 entries. Ten additions across five separate days inside the window, against three the week before. Ray on 17 August. Microsoft IKE, VMware vCenter, Microsoft SharePoint and Apple macOS on 18 August. MLflow on 19 August. Two TrueConf Server flaws on 20 August. Zimbra on 21 August.
  • Two of the ten are machine learning infrastructure rather than conventional enterprise software. Ray, CVE-2025-62593, is a code injection flaw in the distributed computing framework, and it is a 2025 identifier reaching the exploited list now. MLflow, CVE-2026-64849, is a server side request forgery that reaches internal and cloud metadata services. Both are tools data science teams install themselves, and neither is usually on an asset register, because the register was built from what the organisation purchased.
  • The one to look at first is not the one with the headline. CVE-2026-33824, a double free in Microsoft's Internet Key Exchange service extensions enabling remote code execution, carries an EPSS score of 77.90 per cent as at 23 August and sits in the 99.6th percentile. Nothing else in the week's set is close, and the highest severity item of the week sits at 1.37 per cent.
  • Ten is a count and a count needs a baseline. Three weeks of observation is not a baseline. The honest statement is that this week was heavier than last week, not that exploitation is accelerating. [Assessment]
  • Also in the set and worth a line each: Apple macOS CVE-2026-65400, an authentication bypass allowing an attacker on the network to authenticate to Screen Sharing without valid credentials, and Microsoft SharePoint CVE-2026-55040, a weak authentication flaw allowing a security feature bypass over a network. Both carried three day federal deadlines of 21 August.

Sources: CISA Known Exploited Vulnerabilities catalogue, version 2026.08.21, pulled directly and counted; FIRST EPSS API, scores as at 23 August 2026, pulled directly.

Maximum severity, and a record that corrected itself

Microsoft Entra ID, CVE-2026-69836, CVSS 10.0, and the exploitation flag that was withdrawn. Cross sectoral. [Confirmed]

  • Microsoft published the flaw on 20 August. It is a deserialisation of untrusted data in Entra ID allowing an unauthorised attacker to execute code over a network, with no authentication and no user interaction. CVSS 3.1 base score 10.0, the maximum possible, on vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Entra ID is the identity service behind Microsoft 365, Azure and a long tail of third party applications that sign in through it.
  • The bulletin was read directly on 24 August rather than through any article about it. It records Exploited: No, Publicly disclosed: No, and an exploitability assessment of Exploitation Less Likely. Revision 1.1, dated 21 August, states its reason in Microsoft's own words: "Corrected Exploited to No. This vulnerability was not exploited in the wild. This is an informational change only."
  • The disagreement in the coverage is real and it is the useful part. For roughly a day the authoritative vendor record indicated exploitation, several outlets published on that basis, and the correction arrived afterwards. Nobody fabricated anything. Every outlet that ran with exploited in the wild was reading the vendor. For a board the signal is not who was wrong, it is that the primary record moved and the first version travelled further than the second. [Assessment]
  • There is nothing for a customer to do, which is genuinely unusual and worth saying out loud. Microsoft's own answer, verbatim: "This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency." The CVE exists because Microsoft chose to publish a cloud service flaw that it had already fixed and was under no obligation to disclose.
  • The scores disagree with each other and that is worth carrying rather than resolving. Base score 10.0, temporal score 8.7, exploit code maturity recorded as unproven, and EPSS as at 23 August of 1.37 per cent. A number that reads as the worst possible thing and a number that reads as unlikely, describing the same flaw on the same day, measuring different questions.

Sources: Microsoft Security Response Center bulletin for CVE-2026-69836, pulled directly from the MSRC API on 24 August 2026, including full revision history; NVD record, pulled directly; FIRST EPSS API, 23 August 2026; Help Net Security; The Register; Cybersecurity Dive; The Hacker News.

Reading the threat data itself

Dozens of this week's leak site entries are not victims, they are somebody's vulnerability scan. Cross sectoral. [Confirmed]

  • The RansomLook API was pulled directly on 24 August. Of the hundred most recent records, 48 are attributed to the group calling itself The Gentlemen, and 46 of those 48 are plainly not organisations. They carry titles such as `RCSSTI {{7*7}} ${7*7} <%=7*7%> {{config}}`, `XSSPROBE`, `PROBEDIR`, `../RCTRAV` and a run of `TRAVA` through `TRAVF`. Those are server side template injection probes, cross site scripting probes and path traversal payloads, fired at the leak site itself and scraped back out as though they were victim names. Two of the 48 read like organisations, and both sit inside the same burst, so even those cannot be separated with confidence.
  • The timing settles it. Forty seven of the 48 landed on 22 August between 03:00:35 and 04:48:28 UTC, which is 47 entries inside 108 minutes, arriving in clusters roughly twelve minutes apart. That is a scanning cadence. It is not how a criminal group publishes victims.
  • It is not one site and it is not one group. The same hundred records include an entry from another group titled `Test` with the description "test test test", a post from a fourth group that is a message to security researchers rather than an extortion demand, and another that was edited on 23 August to remove a client's name. Leak site data is a mutable, adversarial, unvalidated feed that happens to be published in a machine readable form, and the machine readable form is what makes it look like data.
  • A correction to our own record, made here rather than quietly. This document reported a total of 99 listings for the previous window from this same endpoint. That endpoint returns the hundred most recent records rather than a window, so 99 was a cap artefact and not a count, and it should not be relied on. This run has visibility of 21 to 23 August only and therefore publishes no weekly total at all.
  • Nobody is at fault for this and that is the point worth carrying to a board. Every feed, dashboard and vendor report reading this class of source has the same problem, most have not looked, and victim counts from these aggregators are quoted into board papers, insurance submissions and press coverage every week. Ask where a ransomware number came from before it is used to make a decision. [Assessment]

Sources: RansomLook API, pulled directly on 24 August 2026, with listing titles and timestamps quoted verbatim from the returned records.

Two absences, both counted rather than assumed

Nothing filed, and no exposure number available anywhere. Cross sectoral. [Confirmed]

  • Not one company listed in the United States disclosed a material cybersecurity incident to its market in the window. The SEC EDGAR full text search for 8-K Item 1.05 filings between 17 and 23 August returns zero. The same query across 1 July to 23 August returns eleven, so the zero is a real result rather than a broken query. That is the second week running.
  • GreyNoise and the Shadowserver country level exposure counts were both unreachable on this run, for the third week running. The community endpoints that remain open answer questions about a single address and not about a vulnerability, and the tagging and statistics interfaces both refused. There is therefore no mass scanning against targeted read anywhere in this document and no Australian exposure number for the N-able, GitLab, vCenter, Zimbra or Entra ID items.
  • That absent sentence is the one that lands hardest with a board, which is precisely why no substitute is offered for it. A weaker source with a convenient number would read the same on the page and mean something different. The number is unavailable and it is said plainly.
  • Neither absence is a finding about risk. They are findings about the record, and they become more interesting the longer they hold.

Sources: SEC EDGAR full text search, run directly against the search index on 24 August 2026; GreyNoise and Shadowserver endpoints, attempted directly and recorded as unreachable.

The week for a security leader

Retail, hospitality and consumer

Oz Hair and Beauty, two million records, and a provider it will not name [Confirmed]

  • The Australian online beauty retailer confirmed an incident to Cyber Daily on 18 August. Its own words: "We are aware of a claim made online regarding data relating to our company. As soon as we became aware, we instructed our IT provider to commence an investigation. Our investigation to date indicates the claim relates to data held by a third-party provider." The provider is not named by the company, by the attacker or by anyone reporting it.
  • Have I Been Pwned loaded the set on 19 August at 03:15 UTC and verified it. The precise count is 1,988,331 unique email addresses, which most coverage rounds to two million. The data classes Have I Been Pwned records are email addresses, names, phone numbers, geographic locations and purchases, and that is the whole of the independently verified list.
  • Accuracy nuance that is easy to lose. Cyber Daily's reporting, reading the attacker's own claim, adds home addresses and the last four digits of active gift cards and puts the record count near 2.1 million. Those elements are not in the Have I Been Pwned record and are carried here as the attacker's claim rather than as verified content. [Claimed]
  • Neither the company nor anybody else has called this ransomware. It is an extortion and publication case with no encryption reported. The group calling itself xpl0itrs launched on 12 June 2026 and listed the company on 15 August, which is the previous window. The in window events are the confirmation and the independent load of the data.
  • A published data set of names, phone numbers, suburbs and purchase histories is the raw material for the next round of targeted approaches against those customers. That consequence outlasts the incident by years and it does not appear in any breach notification. [Assessment]

Sources: Oz Hair and Beauty statement to Cyber Daily, 18 August 2026; Have I Been Pwned breach record, pulled directly from the API on 24 August 2026; The Cyber Express; Inside Retail; ransomware.live listing record.

Quest Apartment Hotels, a database reached through a supplier, and no number at all [Confirmed]

  • Quest identified unauthorised access on Monday 17 August and disclosed on 19 August. Its own words: "On Monday, 17 August 2026, we identified unauthorised access to a database system arising from a vulnerability through a third-party service provider." David Mansfield, Managing Director for Australasia at parent company The Ascott Limited, added: "We are very sorry this has happened and for any concern it may cause."
  • The records predate June 2025 and hold names, email addresses and other contact details, with a small number carrying dates of birth. There is no public indication that payment card details or passwords were exposed. Quest notified the Office of the Australian Information Commissioner and the Australian Cyber Security Centre, engaged external cybersecurity and privacy advisers, and says forensic investigation is complete and the incident contained.
  • No record count exists in the confirmed record. Neither Quest nor the ABC nor The Register carries a number. Figures are circulating from lighter outlets and none is carried here, which is covered in the closing note.
  • Quest runs more than 120 properties across Australia, New Zealand and Fiji, serving a corporate travel population. The genuinely trans Tasman element of this week's local picture sits here rather than in a regulatory footnote.
  • Two Australian organisations, two different sectors, two different unnamed suppliers, disclosed inside 48 hours. Both disclosed quickly, both notified the regulators properly, and neither could tell a customer whose systems failed. That is a fair observation about how third party disclosure works rather than a criticism of either company, because there is currently no mechanism that would let either of them answer it. [Assessment]

Sources: Quest Apartment Hotels statement, 19 August 2026; ABC News, 19 August 2026; The Register, 19 August 2026; Cyber Daily; SmartCompany; Information Age; Australian Cyber Security Magazine.

An Android banking trojan wearing the Woolworths name, in Scam Awareness Week [Reported]

  • Cyber Daily reported on 21 August on an Android remote access trojan campaign active in Australia, spreading by text message, WhatsApp and social media while impersonating trusted brands including Woolworths and the airlines Emirates, Qatar Airways and Air India. The pretexts are job openings, tax refunds and flight deals.
  • The malware can reach banking applications, read SMS messages and access the camera, which means a one time code delivered by text is not a second factor on a device running it.
  • The research is NordVPN's threat intelligence team, which reports more than 100 discrete domains, registration on disposable extensions including .cc and .lol, and Cloudflare used as cover. Flagged as lighter: one vendor research source reported by one Australian outlet, and the vendor is a consumer VPN company. That is a reason to attribute it openly rather than a reason to discard it, and its figures are not promoted past an assessment. [Assessment]
  • Window discipline. The campaign has been running since August 2025, so the campaign is not new. What is in window is the publication.
  • Woolworths is being impersonated, not breached, and that distinction has to survive into any restatement of this item. Scam Awareness Week runs 24 to 28 August, which is the week this document lands in, and this is unusually useful material for an employee population.

Sources: NordVPN threat intelligence research; Cyber Daily, 21 August 2026.

Shorter notes from retail and consumer [Reported]

  • Nick Scali. Last week's Australian listed disclosure has developed rather than repeated. Systems are coming back online with sales and deliveries slower than normal. Reporting states that a ransom was demanded and that the company engaged an intermediary to communicate with the attackers, and that some customer delivery addresses were obtained but not financial details. None of that is confirmed by the company, and it sits against the chief executive's reported statement that there was no evidence of unauthorised access to customer data. Both positions are named, neither is resolved here, and nothing is built on the unconfirmed part. [Reported]
  • Ramsey Bros. The Storm group published a listing on 17 August naming the South Australian farm machinery dealer, which has operated on the Eyre Peninsula for 70 years across six dealerships. The group threatens full publication on 4 September. Listed, not confirmed by the company, reported by one outlet reading a criminal's own site. It is a dealership holding customer, parts and service records rather than an operator of anything industrial, and the agriculture and critical infrastructure framing is not reached for here. [Claimed]

Sources: Nick Scali Limited ASX announcement of 14 August 2026, previous window, for the confirmed record; Inside Retail; Capital Brief; SmartCompany; Cyber Daily, 20 August 2026; RansomLook leak site data.

Also reaching this sector: every item in the cross sectoral section above. The N-able item in particular, since retailers and franchise networks are the part of the market most likely to have outsourced IT entirely, and the leak site item, which is what a listing like the Ramsey Bros one actually is.

Healthcare

CareCloud, a March breach that grew from 350,000 people to 3.75 million this week [Confirmed]

  • CareCloud filed an updated breach report with the United States Department of Health and Human Services on Monday 17 August, confirming more than 3.75 million individuals affected. The company had originally reported the same incident at around 350,000. That is the fifth largest United States health data breach reported this year.
  • The incident itself is dated context. An unauthorised third party accessed one of CareCloud's Amazon Web Services storage environments between 10 and 16 March 2026, a window of six days. The in window event is the corrected figure reaching the regulator.
  • The data reported taken includes names, addresses, dates of birth, social security numbers, driver licence and government identification numbers, financial account and card numbers, and medical and health insurance information. That combination supports identity fraud rather than nuisance contact, which is a different order of harm from a marketing list.
  • CareCloud is a New Jersey company providing electronic health record storage to tens of thousands of healthcare professionals, and processing patient and payment data on behalf of hospitals and practices. Not one of the 3.75 million people has a relationship with it. They have a relationship with their doctor.
  • The number is the finding for anyone with a governance role. A figure was reported to a regulator in March, was relied on by every practice that read it, and moved by more than a factor of ten five months later. Nobody appears to have behaved badly. Establishing scope accurately takes months and the interim figure is published anyway, because the alternative is publishing nothing. [Assessment]

Sources: CareCloud filing with the United States Department of Health and Human Services, 17 August 2026; TechCrunch, 19 August 2026; The Record; HIPAA Journal; IT Pro; Malwarebytes.

Also reaching this sector: every item in the cross sectoral section above, particularly the N-able item, since medical practices are among the heaviest users of outsourced IT management, and the machine learning entries on the exploited catalogue, which land wherever clinical analytics has been stood up outside procurement.

Financial services

U.S. Bank, listed by LockBit, and an incident at a fourth party [Confirmed]

  • LockBit 5 listed the bank on its leak site in the middle of the week, with reporting following on 20 and 21 August, and set a deadline in early September. Outlets differ on the exact deadline date and no single date is asserted here. The group published no sample files, no file count and no detail about affected systems, customers or employees.
  • U.S. Bank investigated and issued a statement, which is the confirmed record and is worth reading in full: "We have investigated this matter and the available evidence indicates that the claim regarding a potential cyber incident is related to a fourth party event that occurred outside of our environment. At this time, there is no evidence that our systems, networks or data repositories were compromised."
  • Fourth party is the term to take away. It means a contractor to one of the bank's own suppliers. The bank declined to name either the third or the fourth party. Reporting notes that a different vendor, Fidelity National Information Services, was the route of a previous third party incident affecting the bank, and that is a separate earlier matter and not this one. It is recorded here only so the two are not merged by somebody reading quickly.
  • Everything the criminal group has said about this remains a claim by an interested party with nothing published to support it. Everything the bank has said is a statement it is accountable for. Those are different classes of evidence and the gap between them is the whole story. [Claimed]
  • Almost no third party risk programme extends to the fourth party, and no standard questionnaire asks a supplier to enumerate its own subcontractors in a form the customer can audit. This is the first time this year that a significant institution has used the term in a public statement about its own incident, and it is likely to appear in a regulator's language next. [Assessment]

Sources: U.S. Bank statement, 20 August 2026; The Register, 20 August 2026, updated 21 August; The Record, 21 August 2026; Cybernews; RansomLook leak site data.

Shorter notes from financial services [Claimed]

  • BOK Financial was posted by the group calling itself ShinyHunters on 22 August with a stated deadline of 24 August. Listed, not confirmed, no company statement located, nothing asserted here about what was taken.
  • One group posted fourteen separate listings inside a single minute on 22 August, several of them financial services and microfinance organisations across Asia and the Americas, each tagged with a dollar figure presented as claimed revenue. A revenue figure attached to a victim name by an extortion group is a pricing signal about the ransom, not a measure of anything taken.
  • No Australian or New Zealand financial institution appears in the records retrieved. With only three days visible in this run, that is not evidence of absence.

Sources: RansomLook API, pulled directly on 24 August 2026.

Also reaching this sector: every item in the cross sectoral section above. The Entra ID item in particular, since financial services is the sector most likely to have federated a long tail of third party applications into one identity provider, and the leak site item, which governs how any listing in this section should be read.

Technology and software

Alation confirmed a cyberattack and has explained nothing [Confirmed]

  • Alation confirmed on 20 August that it had discovered unauthorised activity in one of its systems and was investigating. That confirmation followed customer facing disruption on 18 August, which the company described at the time as degraded availability and said it had resolved within an hour.
  • The company has not disclosed the attack method, the cause, whether customer data was accessed or taken, or how many customers are affected. What is confirmed is that there was an attack and that an investigation is running. Everything else about it is currently unknown rather than withheld.
  • Alation says it serves more than 500 global companies including around half of the Fortune 1000. It is a data catalogue and governance platform, which means its function is to know where an organisation's most sensitive data lives and who may use it. It holds the map rather than the territory. [Assessment]
  • This is the third week running in which the most consequential software item has had the same shape: a product bought for connection or oversight rather than for storage, holding credentials and knowledge about everything else. Naming the pattern is the finding, and the practical question is which of these an organisation runs and who authorised the access they hold.
  • No group has claimed it, no data has appeared, and nothing here should be read as a statement that customer data was affected.

Sources: Alation statement, 20 August 2026; TechCrunch, 20 August 2026; eSecurity Planet; Cybersecurity Dive; Techzine.

Kingston Technology is investigating a claim by the Everest group [Claimed]

  • Cyber Daily reported on 21 August that the memory and storage manufacturer is investigating claims by the Everest group, disclosed on the group's leak site on 20 August, of roughly 138.5GB across 9,438 files.
  • The group describes the material as marketing content drawn from Asia Pacific operations, naming markets including Taiwan, Japan, Korea, Thailand, Vietnam, India, Australia, New Zealand, Malaysia and Singapore.
  • Everest is a Russian speaking operation active since 2021 with a history of listing hardware manufacturers. The volume and the file count are the group's own figures and neither has been verified by anyone.
  • The company has confirmed that it is investigating and has confirmed nothing else. Being a manufacturer of components does not make this an industrial or operational technology incident, and the claim concerns marketing files.
  • Australia and New Zealand appear in the claimed scope, which is why it is carried at all rather than left out as a routine listing.

Sources: Cyber Daily, 21 August 2026; RansomLook and ransomware.live leak site data.

Also reaching this sector: every item in the cross sectoral section above. The GitLab item lands harder here than anywhere else, since self managed instances concentrate source code, pipeline credentials and deployment keys, and the Ray and MLflow catalogue entries reach any organisation running its own machine learning infrastructure.

Government and defence

Australia opens recruitment into a Defence Cyber Reserve Force [Confirmed]

  • Defence announced on 21 August that it is recruiting experienced cyber professionals into a new Cyber Reserve Force, drawing specialist expertise from industry, government and academia. The primary record is Defence's own media release.
  • The named areas are cyber operations, artificial intelligence, network engineering, cloud security, digital forensics, incident response, threat intelligence and cyber strategy. The stated purpose is specialist advice, technical expertise, operational support and the ability to surge cyber capability rapidly.
  • It was stood up in twelve months and is an outcome of the review of the Australian Defence Force Reserve. A new entry pathway recognises existing skills, experience and demonstrated capability rather than requiring experienced people to start again, and the first direct entry member has been appointed.
  • It is not a threat item and it is carried deliberately. It speaks to the workforce question every Australian board asks after an incident, which is where the people are going to come from, and the people it is recruiting are currently employed in Australian businesses.

Sources: Australian Department of Defence media release, 21 August 2026, primary; Cyber Daily; Defence Connect; Mirage News.

One state owned defence manufacturer listed, and nothing confirmed [Claimed]

  • Itaguaí Construções Navais, the Brazilian state owned naval construction company, was listed by LockBit 5 on 22 August. Taken directly from leak site data.
  • The company has confirmed nothing, no second outlet has stood it up, and nothing is asserted here about what was taken or whether anything was.
  • It is recorded because a state owned defence shipbuilder appearing on an extortion site is a category of listing worth knowing about, and because leaving it out would make this sector look emptier than it was.

Sources: RansomLook API, pulled directly on 24 August 2026.

Also reaching this sector: every item in the cross sectoral section above, particularly the N-able item, since ASD's alert is addressed to government as well as to business and states explicitly that no specific sector is being singled out.

Professional services

Consultancies and law firms across several countries, all of it claimed [Claimed]

  • Turner and Townsend, the international construction and infrastructure consultancy, was listed on 21 August by the group calling itself Coinbase Cartel. Klasko Immigration Law Partners, a United States family law practice and two accounting firms were listed by the same group on 22 August.
  • All of these are listings on extortion sites and nothing more. No company has confirmed anything, no reputable outlet has stood any of them up independently, and nothing is asserted here about what was taken from any of them.
  • A distinction worth drawing after the leak site item above. A bare title in a feed can be anything. A named organisation with a sector label and a description is a different quality of record, still unverified, still a claim by a criminal, and worth reporting as existing while asserting nothing about its content. [Assessment]
  • Professional services firms hold client material without holding client liability for it in any way a client can see, which is what makes a listing in this sector propagate into other organisations' risk registers within days, regardless of whether it turns out to be true.

Sources: RansomLook API, pulled directly on 24 August 2026.

Also reaching this sector: every item in the cross sectoral section above. The Alation item in particular, since consultancies run data catalogues and reporting platforms wired into client information, and the leak site item, which is the correct lens for everything in this section.

Energy and utilities

One claim, and it is the whole of the sector's week [Claimed]

  • Vietnam Electricity, the country's largest power utility, was listed on 22 August by the group calling itself Emperador. Taken directly from leak site data. The company has confirmed nothing and no outlet has stood it up.
  • No energy or utility incident was disclosed by any organisation anywhere in the window, and no sector specific advisory was issued. That is the honest position and it is not dressed up.
  • The exposure that does reach this sector this week is not an energy story at all. It is the virtualisation management layer, since a great many utilities run historians, engineering workstations and business systems as virtual machines, and the hypervisor management plane is the shortest path to all of them at once. No utility victim has been named in that campaign by anyone. [Assessment]

Sources: RansomLook API, pulled directly on 24 August 2026; CISA industrial control system advisory feed, pulled directly and counted.

Also reaching this sector: every item in the cross sectoral section above, particularly the vCenter item for the reason given, and the N-able item, since utilities in the mid market outsource IT management as readily as anybody else.

Manufacturing and operational technology

This sector is reported empty, and the emptiness is the entry. No operational technology or industrial control incident was disclosed anywhere in the window. No manufacturer confirmed an attack on production. The heading is kept rather than dropped, because an absent heading reads as an oversight and a heading saying nothing happened is information.

Three industrial advisories in seven days, against fifteen in a single day the week before [Confirmed]

  • Counted directly from CISA's industrial control system advisory feed. Three advisories in the window: CISA's own Malcolm tool and Siemens Simcenter Nastran on 18 August, and Johnson Controls Simplex Incident Manager on 20 August. The previous window produced sixteen, fifteen of them on 13 August alone.
  • The only one of the three touching life safety, the Johnson Controls Simplex Incident Manager advisory, is a credential storage weakness that is not remotely exploitable, requires local access and low privileges already held, and carries no known exploitation. Siemens Simcenter Nastran is engineering simulation software and Malcolm is a network traffic analysis tool. None of the three is a story and none is presented as one.
  • An advisory is not an incident. A quiet advisory week means vendors and CISA published less, which is a fact about the publication stream and not a fact about what happened in anybody's plant.
  • The differentiator sits out one week. That is preferable to inflating a local access credential storage weakness into an operational technology warning, which is exactly the move this document exists not to make.

Sources: CISA industrial control system advisory feed, pulled directly and counted for both windows.

Dated context, clearly labelled: the Monterrey water utility intrusion, published 6 May 2026 [Reported]

This is May material and it is not this week's news. It is carried here, in this section only, because a board reading an empty operational technology section is better served by knowing what the current reference point is than by a blank space, and because the question it answers is being asked now.

  • Dragos published analysis on 6 May 2026 of an intrusion at a water utility in Monterrey, Mexico, in which the attacker used artificial intelligence assistance during the intrusion. The attacker reached the corporate network and attempted to pivot toward the control environment.
  • Dragos is careful about what it did and did not find, and its own position is that the attempts were unsuccessful and that it observed no further evidence that the adversary had breached the operational technology environment. Anyone describing this as an artificial intelligence attack that reached a water control system has gone past what the research says.
  • It remains, at the time of writing, the clearest published account available of artificial intelligence assistance inside a real intrusion against an industrial organisation. That is why it is the reference point, and it is also a comment on how few such accounts exist. [Assessment]
  • The useful board framing is the one Dragos's own finding supports. The interesting question is not whether an attacker can reason about a control system. It is that the corporate network was the route, the corporate network is always the route, and that was true before anybody used a language model.
  • Nothing in this item is in window and nothing in it should be restated as current. The date goes in the first line of any retelling.

Sources: Dragos analysis, published 6 May 2026, out of window and labelled as such throughout.

Also reaching this sector: every item in the cross sectoral section above. The N-able item most of all, since a remote monitoring platform with administrative reach into every managed endpoint is the established route from a corporate network into the engineering workstations that sit beside a plant, and the vCenter item for the same reason at the virtualisation layer.

Transport and logistics

There was nothing in this sector in the window. No incident was disclosed, no advisory was issued specific to it, and no operator anywhere confirmed an attack. The heading is kept rather than dropped so that its emptiness is visible.

One extortion listing touches the sector and it is the whole of its week. An Argentine long distance coach operator appeared on 22 August among the fourteen listings that one group posted inside a single minute, described in the group's own words and tagged with a claimed revenue figure. It is a claim by a criminal, nothing has been confirmed by the company, and it is recorded as existing rather than as having happened. [Claimed]

Sources: RansomLook API, pulled directly on 24 August 2026.

Also reaching this sector: every item in the cross sectoral section above. Transport and logistics operators buy managed IT, run virtualisation and authenticate through the same identity services as everybody else, and the absence of a sector specific incident this week says nothing about their exposure to any of it.

Circulating, and not carried

  • Every exposure count, for the third week running. GreyNoise and the Shadowserver country level figures were both attempted directly on this run and neither returned usable data. There is therefore no mass scanning against targeted read and no Australian exposure number anywhere in this document. A missing figure costs a sentence. A wrong one costs the document.
  • Any weekly leak site total. The endpoint used returns the hundred most recent records rather than a window, so this run has visibility of 21 to 23 August only. No total is published, and the total published from this source for the previous window should be read as a cap rather than a count.
  • A record count for Quest Apartment Hotels. A figure above a million is circulating from lighter outlets. Neither the company, the ABC nor The Register carries a number, and no primary source supports one. Quest has not disclosed how many people are affected, and that is the accurate statement.
  • Home addresses and gift card digits in the Oz Hair and Beauty set. Reported by one outlet reading the attacker's own claim. The independently verified record lists five data classes and those are not among them, so they are carried as the attacker's claim inside the item and are not stated as fact.
  • The Nick Scali ransom demand, the intermediary and the delivery addresses. Reported rather than confirmed, and sitting against the chief executive's reported statement that there was no evidence of unauthorised access to customer data. The intermediary thread is the most interesting item in the local week and it is also the least stood up. It is stated once inside the item and nothing is built on it.
  • Levi Strauss. Corporate data taken through social engineering of three employee devices, disclosed to the United States Securities and Exchange Commission on 7 August under Item 8.01, other events, rather than under Item 1.05, material cybersecurity incident. That choice of item is genuinely interesting as a materiality judgement made in public. It is out of window by more than a fortnight and it is not run as news.
  • MyDr, Poland. A national medical records platform, with claims of data on nearly nineteen million people and 2.5 terabytes held. Announced by Poland's Ministry of Digital Affairs on 12 August, which is the previous window. The scale is real and the timing is not ours.
  • Craneware. A healthcare software vendor breach disclosed by regulatory filing to the London Stock Exchange on 20 July. Out of window, recorded here only because it surfaces alongside this week's healthcare material and could be mistaken for it.
  • The North Carolina Ports Authority attack. 4 August, well outside the window, and noted only so nobody reaches for it as this week's transport item.
  • **One extortion listing carrying an insurer's name that also belongs to a New Zealand company.** The listing gives no country, no domain and no detail sufficient to establish which organisation is meant. It is not carried as an Australian or New Zealand item because it has not been established as one, and naming a company on that basis would be worse than saying nothing.
  • Every claimed data volume and revenue figure from an extortion group. Several appear in the records pulled this week. A size in gigabytes or a dollar figure from a criminal adds nothing except the impression of precision, and the revenue figures in particular are a pricing signal about a ransom rather than a measurement of anything.
  • Shell and the Oracle E-Business Suite extortion wave. Previous window. Not run as news and noted so it is not reached for.
  • New Zealand produced nothing in the window. Not thin, empty. The NCSC New Zealand publication record carries no in window incident or advisory. The only New Zealand connection this week is that Quest Apartment Hotels operates properties there and Kingston Technology appears in a claimed scope naming it. Where this document says Australia and New Zealand, that is Australian material with a New Zealand footnote, and it is not presented as more.
  • Kaspersky is not cited anywhere in this document, consistent with the ASD posture. Nothing in the week required it.

Start a conversation

Want this every week?

It goes out to the organisations we work with. Ask and you are on the list, and there is nothing else attached to it.

  • Every enquiry is read by a senior leader. There is no sales sequence behind this form.
  • Nothing is resold to you and no vendor introduction is waiting at the other end.
  • A first conversation is a conversation, not a scoping call with a proposal attached.

It reaches a senior leader, not a queue. If you would rather write directly, advisory@greencyber.ai.