GreenCyber

GreenCyber / Light reading / Week ending 16 August 2026

The Global Threat Summary, week ending 16 August 2026

The week the flaws arrived already in use. In almost every serious item, somebody was exploiting the weakness before the rest of the world was told it existed.

Global Threat Summary

Last week the story was fixes that did not hold. This week the flaws arrived already in use. In almost every serious item of the past seven days, somebody was exploiting the weakness before the rest of the world was told it existed, or from the same hour it was told.

Start with Windows. Microsoft's August update was very large, and one flaw inside it had been used against real organisations since early July. The group behind it is North Korean, the way in was a message about a job, and the payload was built for a single purpose: to switch off the security monitoring that was supposed to notice. This is the fourth time in four years that the same group has used a previously unknown flaw in the same Windows component to install the same tool. There is a comfort that circulates in boardrooms, offered sincerely by people doing their jobs well, which is that endpoint detection is deployed across the estate. That control is worth the money most days. This particular tool exists so that on the day that matters, it is not.

The same week produced a flaw with no fix at all. A researcher published a working exploit for a Microsoft Defender weakness whose July repair turned out to be walkable around, and there was still no patch when the week closed. Separately, another researcher posted an unpatched flaw in a widely used mapping platform straight to a social media account with no coordination, and scanning for vulnerable systems began the same afternoon. For a leadership team the practical consequence is the same in both cases. There are weeks when patching is not the answer available, and the organisations that cope are the ones that decided in advance what they would do instead.

Then the pattern that is now two weeks old and worth naming out loud. Last week it was an artificial intelligence platform holding every credential it had been given. This week it is a business intelligence tool holding every database password it had been given, taken over by a single request that required no login at all. Neither product holds much data of its own. Both hold connections. Neither is usually bought through procurement, and neither tends to appear on an asset register, because the register was built from what the organisation purchased rather than from what it runs.

The industrial finding of the week is the one most likely to change a budget. The leading specialist firm in operational technology security counted a record quarter of ransomware against industrial organisations, up twelve per cent, with manufacturing taking roughly two thirds of it. In the same quarter it observed no case at all of an attacker reaching into a control system. Plants stopped anyway, because the ordinary corporate systems the plant depends on were encrypted and that was enough. The consequence is real and the mechanism is dull..... and the dull mechanism is the one that is not being funded.

Extortion, meanwhile, has stopped choosing targets and started choosing software. One criminal group listed more than forty organisations in a single day off a single widely deployed enterprise product. An oil major and a trailer manufacturer in regional New South Wales were selected by the same query. Being too small to be interesting was never a security position. It was a guess about the attacker's intentions, and the attacker did not have intentions about anyone in particular.

Two things about disclosure sit against each other and both are worth a minute. An Australian listed retailer told its market it was investigating an incident on the same afternoon it took systems offline, while the investigation was days old and the outcome unknown. Four other Australian businesses appeared last week only as entries on criminal leak sites, and none of them has said anything at all. Across the same seven days, not one company listed in the United States told its market about a material cybersecurity incident. That absence is genuine and it was found by going and looking, which is the only way an absence is ever found.

Three things worth a leadership meeting

One. The industrial threat is not shaped the way the spending assumes. A record quarter of attacks on industrial organisations produced no instance of anyone manipulating a control system, and production stopped regardless. If the operational technology programme is built around an attacker reaching the plant, it is aimed slightly to the left of what is happening.

Two. Three of the week's most serious flaws were in use before they were public, and one had no fix when the week ended. Severity ratings are produced before anyone knows whether a flaw is being used, and the most urgent item of the week was not rated critical. Anything known to be exploited should jump the queue whatever its rating says, and there needs to be a decision already made about what happens when there is nothing to install.

Three. On Wednesday 19 August, more than fifty Australian organisations, fifteen of them superannuation funds, rehearse a coordinated attack together, on purpose. It is the fourth year they have done it. Very few other sectors anywhere have an equivalent, and the reason it is worth a leadership meeting is not what those funds learn. It is the question of who would organise the same thing for your own sector, and what it would cost.

Three questions to put to the executive team

  • If production stopped tomorrow because our office systems were encrypted, and nobody ever touched the plant or the machinery, whose plan covers that, and has anyone written down which corporate systems production silently depends on?
  • What do we run whose whole value is that it connects to everything else, who gave it those credentials, and which single person could tell us this week every piece of software we expose to the internet?
  • When did we last rehearse an incident with the organisations we depend on in the room, rather than alone, and if we have never done it, who would we ask?

Cross sectoral, the items that reach every industry

Nine items last week reached organisations regardless of what they do. They are set out here, ahead of the industry breakdown, because a reader who scans only their own sector would otherwise miss them.

Exploited before it was disclosed

Windows afd.sys, CVE-2026-68820, exploited by Lazarus since early July. Cross sectoral. [Confirmed]

  • A use after free in the Windows Ancillary Function Driver for WinSock, the kernel driver behind Windows networking, allowing an attacker already running code on a machine to elevate to SYSTEM. Fixed in Microsoft's 11 August release and added to CISA's Known Exploited Vulnerabilities catalogue the same day. Microsoft rated it important, not critical.
  • Three zero days were addressed in that release. CVE-2026-68820 was the only one with evidence of use. The other two, CVE-2026-62832 and CVE-2026-72971, were publicly disclosed without it. The exploited one carries the lower severity label, which is the practical point for anyone ordering a patch queue.
  • Check Point Research published on the same day that the North Korean group tracked as Lazarus had been exploiting it since early July, inside a fresh wave of Operation Dream Job, the long running fake recruiter campaign. The payload is FudModule, a kernel rootkit built to degrade security telemetry by removing or interfering with callbacks, filters and event tracing. This is the fourth time since 2022 that the group has used a zero day in this one driver to install this one rootkit.
  • The named targets are defence contractors, aerospace engineers and aviation professionals in France, Germany, India and Brazil. That is Check Point's own reporting and no other researcher has independently confirmed the target set. [Reported]
  • No CVSS score is used here. One source gives 7.0 and Microsoft's own label is important. The primary record is the vendor severity and the catalogue entry, and the count of exploited flaws in the release, which is one.

Sources: CISA Known Exploited Vulnerabilities catalogue, version 2026.08.14, pulled directly; Microsoft security advisory, 11 August 2026; Check Point Research, 11 August 2026; BleepingComputer; The Hacker News; SecurityWeek; SecurityAffairs; Help Net Security; Tenable.

Metabase, CVE-2026-72898, CVSS 10.0, a three day federal deadline. Cross sectoral. [Confirmed]

  • An unauthenticated SQL injection in the password reset endpoint of Metabase, the widely used self hosted business intelligence platform. A single crafted request to `/api/session/reset_password` yields administrator control of the instance, and with it every database credential and connection string the tool holds.
  • Dated context, and not last week's news: Metabase disclosed on 6 August. The in window event is the catalogue addition on 11 August with a remediation deadline of 14 August, which is the moment a known risk became a deadline. That deadline binds United States federal agencies and nobody else. It remains the clearest published opinion available on how fast this needs to be gone.
  • Bishop Fox published the technical research. Metabase's own advisory is the primary vendor record.
  • This is the second week running that the most serious item in the software estate has had the same shape, following IBM Langflow. Neither product holds much data of its own and both hold credentials to everything they connect to. Naming the pattern is the finding. [Assessment]
  • Patching does not rotate a credential. Administrator control of a reporting platform yields service accounts and connection strings that remain valid after the fix is applied, that work from anywhere, and whose use looks normal in a log because they are meant to be used.

Sources: CISA Known Exploited Vulnerabilities catalogue, version 2026.08.14, pulled directly; Metabase security advisory, 6 August 2026; Bishop Fox research; The Hacker News; GBHackers; IONIX; runZero.

GeoServer, GHSA-mqjf-5f49-2fjh, published with no patch and scanned within hours. Cross sectoral. [Reported]

  • On 12 August at 10:46 UTC a researcher posted details of an SQL injection in GeoServer's `jsonArrayContains` filter function to a social media account, with no coordinated disclosure and no patch available. GeoServer is the open source platform organisations use to publish and serve geospatial data, and it is frequently internet facing by design.
  • Rated CVSS 9.8, reaching remote code execution under common PostGIS and Oracle JDBC configurations. Fixed versions landed afterwards in 3.0.1, 2.28.5 and 2.27.6. There is no CVE identifier at the time of writing, only the GitHub security advisory, so any number circulating as a CVE for this is wrong.
  • Exploitation attempts were observed within hours, hundreds of them from a small pool of addresses. What has been observed is scanning and probing for vulnerable instances. No named organisation has been confirmed compromised, and the two are routinely blurred in coverage.
  • The published research describes the flaw as a regression of CVE-2023-25158, fixed in 2023 and returned for this one function. That is a different risk class from a new flaw. Almost every organisation has a process for something newly announced and nothing at all that asks whether something previously closed has quietly reopened, because closed things generate no alerts.
  • No exposure count appears here. See the closing note.

Sources: GitHub security advisory GHSA-mqjf-5f49-2fjh, primary; Hadrian research, 12 August 2026; The Hacker News; SecurityWeek; SecurityAffairs; Field Effect.

ShieldBreak, a public exploit for a Defender flaw with no fix in the window. Cross sectoral. [Reported]

  • On 12 August a researcher using the name Nightmare Eclipse published ShieldBreak, a working exploit chain that bypasses Microsoft's July fix for CVE-2026-50656, a Microsoft Defender privilege escalation flaw known as RoguePlanet. It takes an attacker who already has local code execution to SYSTEM on fully current Windows 11 25H2 and Windows Server 2025.
  • There was no patch at the close of the window. Reporting dated 17 August, after the window, indicates Microsoft is working on one. That changes the position from no fix exists to a fix is coming, and it does not change what an organisation does this week.
  • The reported one hundred per cent success rate is the researcher's own claim about their own exploit and has not been independently measured. [Claimed]
  • The researcher published after what is reported as a legal threat from Microsoft. Microsoft has not confirmed it, it is not inside quotation marks anywhere in this document, and it is not stated here as fact. [Reported]
  • This is a privilege escalation and not remote code execution. Nobody is getting into an organisation with it. That distinction is what separates a useful briefing from a frightening one, and it also explains the answer, which is compensating controls and constraining where unknown code can run at all.

Sources: BleepingComputer; SecurityWeek; The Hacker News; SecurityAffairs; Arctic Wolf; Tanium; iTnews. No primary vendor advisory existed at the close of the window.

Cisco ASA and FTD, CVE-2026-20349, added to the exploited catalogue. Cross sectoral. [Confirmed]

  • An unauthenticated attacker can crash the firewall through the SSL VPN. CVSS 8.6. Cisco's advisory and the catalogue addition are both dated 11 August, and there is no workaround.
  • The impact is denial of service only, which is why it sits here as a deadline rather than as a featured story. A firewall that reboots on demand is still an availability event for every remote worker behind it.
  • Three vulnerabilities entered the catalogue in the window, all on 11 August: this one, the Windows afd.sys flaw and Metabase. Counted from the catalogue itself, version 2026.08.14, which holds 1,665 entries. A quiet week by count and a loud one by severity.

Sources: CISA Known Exploited Vulnerabilities catalogue, version 2026.08.14, pulled directly; Cisco security advisory, 11 August 2026.

Supply chain and build infrastructure

LiteLLM, a forty minute window in March reconstructed at scale in August. Cross sectoral. [Assessment]

  • CloudSEK published research on 11 August reconstructing the scale of the LiteLLM supply chain compromise. The group it tracks as TeamPCP is described as having compromised the Trivy security scanner used inside LiteLLM's own build pipeline, remained about twenty days, and on 24 March published backdoored LiteLLM packages 1.82.7 and 1.82.8 to PyPI. The packages were live for roughly forty minutes.
  • CloudSEK assesses that this was long enough for automated build systems to pull them into approximately 434,000 CI/CD pipelines across more than 2,500 organisations, harvesting credentials as they went. Those figures are CloudSEK's own and no independent party has reproduced them.
  • The figures diverge across sources and the divergence is itself the content. The Hacker News reports more than 2,100 organisations, StepSecurity counts 78,330 secrets from 2,186 organisations, and BreachHistory maps 2,488 firms. No clean number is presented here because there is not one.
  • The research names specific multinational organisations as high confidence matches. Those names are not reproduced in this document. They are one research firm's assessment, none of the named organisations has confirmed anything, and a list of that kind travels further than the caveat attached to it. [Assessment]
  • Window discipline. The compromise was March, the FBI FLASH advisory FLASH-20260702-01 on the same campaign was July, and the only in window event is the publication of the scale on 11 August. The question it leaves is not about artificial intelligence at all. It is whether an organisation knows what its build pipelines pull in, and whether the credentials those pipelines hold have been rotated since March.

Sources: CloudSEK research, 11 August 2026; FBI FLASH advisory FLASH-20260702-01, July 2026; SecurityWeek; The Hacker News; StepSecurity; Cyber Daily; Unite.AI.

Extortion and the leak site economy

Cl0p listed more than forty organisations in a single day, off one enterprise product. Cross sectoral. [Claimed]

  • Cl0p ran a mass extortion wave through the window tied to Oracle E-Business Suite, listing more than forty victims on 12 August alone. Named on the leak site were Philips, General Electric, Tristar and Shell, with Zebra added on 13 August and the Australian trailer manufacturer Midland on 12 August.
  • Shell said on 14 August that it was aware of a potential incident and was investigating. That is a company confirming it is looking, which is not a company confirming what happened, and it is the only element of this wave above Claimed. [Confirmed]
  • Every claim about what was taken comes from the criminal group describing its own work. Extortion groups inflate, relist old victims and name organisations they never reached. Midland has confirmed nothing. Cl0p's claimed volumes are not reproduced here, because a size in gigabytes from an extortion group adds nothing except the impression of precision.
  • Cl0p's own message, printed alongside the list, is the clearest statement available of what a leak site listing actually is:

This is the list of companies that did not reach to us. To avoid publication contact us before your name is revealed.

  • That is a negotiating position published in public and aimed at the companies that have not replied. It is not a breach report, and the difference matters most in the first hour of somebody finding their own name on it.

Sources: Cyber Daily exclusive; RansomLook and Ransomware.live leak site data, pulled directly; Shell's own statement, 14 August 2026; SecurityWeek; BlackFog; Paubox; TechRadar.

Ninety nine listings in seven days, and one group took more than a quarter of them. Cross sectoral. [Claimed]

  • Leak site tracking recorded 99 listings across the window. Qilin was dominant with 28, The Gentlemen 18, DireWolf 6 and LockBit5 5. Counted directly from the RansomLook API rather than read about.
  • Every one of those is a claim by an interested party. The count measures publishing activity by criminal groups, not confirmed compromises, and it undercounts every organisation that paid quietly and never appeared.
  • Ransomware.live was unreachable during the initial sweep and reachable later in the run. Where it was consulted it carries the same Australian listings, which means the individual listings do not rest on a single aggregator. A second aggregator confirms that a listing exists, and confirms nothing about whether anything was taken.
  • Reported on 13 August, the Akira group was observed disabling endpoint protection by rebooting machines into Safe Mode, stealing data and then failing to encrypt. It is a useful counterexample to the assumption that a ransomware incident means encryption, and to the assumption that no encryption means no loss. [Reported]

Sources: RansomLook API, pulled directly; Ransomware.live; BleepingComputer; SecurityWeek.

Two absences, both counted rather than assumed

Nothing filed, nothing issued. Cross sectoral. [Confirmed]

  • Not one company listed in the United States disclosed a material cybersecurity incident to its market in the window. The SEC EDGAR full text search for 8-K Item 1.05 filings between 10 and 16 August returns zero. The same query across a wider range returns eleven hits across July, so the zero is a real result rather than a broken query.
  • Australia's ACSC published no alert or advisory in the window, for the third week running. Its two live critical alerts still date from 9 July and 18 June, and its two live advisories from 23 July and 14 July.
  • Neither absence is a reason to relax and neither is a finding about risk. They are findings about the record, and they become more interesting the longer they hold.
  • One gap is stated rather than hidden. The AusCERT Week in Review of 14 August could not be retrieved at the usual path. It is treated as not retrieved, which is not the same as absent, and nothing in this document depends on it.

Sources: SEC EDGAR full text search, run directly; ASD's ACSC alerts and advisories feeds, pulled directly.

The week for a security leader

Manufacturing and industrial operations

A record industrial quarter in which nobody touched a control system [Reported]

  • Dragos published its industrial ransomware analysis for the second quarter of 2026 on 10 August. It records 1,140 incidents against industrial organisations worldwide, up twelve per cent from 1,020 in the first quarter. Manufacturing took 747 of them, sixty five per cent of the total. Construction 176, equipment manufacturing 114, food and beverage 70. North America recorded 514. Australia and New Zealand recorded 19.
  • The finding underneath the counts, in the report's own terms: Dragos observed no case in the quarter in which a ransomware operator reached stage two of the industrial control system kill chain or directly manipulated a control system. Encrypting the information technology systems and the virtualisation that support the plant was sufficient to stop the plant.
  • The methodology caveat travels with the numbers and comes from Dragos rather than from us. The counts are built from publicly disclosed victims and criminal leak site postings, which undercounts organisations that pay quietly and overcounts groups that inflate. It is a well constructed sample and not a census.
  • The commercial point is worth stating plainly, because it runs against the interest of the firm that published it. The leading specialist in industrial security looked across a record quarter and did not find a single case of the scenario that sells industrial security assessments. It published that anyway, with its method and its limits attached. [Assessment]

Sources: Dragos industrial ransomware analysis, Q2 2026, published 10 August 2026; Help Net Security; Cyber Daily; SecurityBrief AU; Security Journal UK.

Sixteen ICS advisories in seven days, against four the week before [Confirmed]

  • Counted directly from CISA's industrial control system advisory feed. Sixteen advisories across the window, fifteen of them published on 13 August alone, plus one on 12 August and one update on 11 August. The whole of the previous week produced four.
  • The 13 August batch includes AVEVA Enterprise SCADA, Johnson Controls Metasys and Airwall, Hitachi Energy APM Edge, ANDRITZ HIPASE-250, Siemens Desigo building controllers alongside several other Siemens products, a Haiwell industrial internet of things cloud gateway for human machine interfaces, and one medical device.
  • None of those vendors did anything wrong by appearing. A published advisory is a vendor and a government agency telling the world where to look, which is the system working as designed.
  • The list is not exotic. It is the equipment that runs buildings, plants, substations and sites, most of it specified years ago, installed by a contractor and not thought about since. A spike in advisory volume is not itself a crisis. The risk is the time it takes an organisation to determine which of these products it actually operates, which in most industrial businesses is measured in weeks. [Assessment]
  • AVEVA Enterprise SCADA is the one to localise on in this region, since it turns up in Australian energy, water and mining, and it is a primary government record rather than vendor marketing.

Sources: CISA industrial control system advisory feed, pulled directly and counted.

Mackay Sugar, mills stopped without anyone reaching the mill [Reported]

  • Dated context, carried because the analysis is the in window event. Mackay Sugar, Australia's second largest raw sugar producer, disclosed a cybersecurity incident on 10 June. Milling and cane haulage stopped at two of its three Queensland mills. The group calling itself The Gentlemen claimed responsibility on 15 June by listing the company. [Claimed]
  • Dragos's analysis, published in the window, found no evidence that the actor reached the industrial control systems or directly manipulated operational technology. Its assessment, offered at low confidence and labelled as such in the report, is that this primarily affected enterprise information technology, with milling halted either by the disruption itself or as a precautionary containment decision.
  • The uncertainty is the useful part rather than a weakness in the reporting. A well made containment decision looks identical, from outside, to a successful attack on production. The plant is stopped either way, and only one of those two events is something an attacker achieved.
  • The company has confirmed nothing beyond its own June disclosure and has not been approached by us. Nothing here is a comment on the decisions it made.

Sources: Dragos industrial ransomware analysis, Q2 2026; Mackay Sugar's own disclosure, 10 June 2026; Cyber Daily; SecurityBrief AU.

Also reaching this sector: the Cl0p wave in the cross sectoral section above, which listed a mid sized trailer manufacturer alongside an oil major and an industrial conglomerate, and the LiteLLM item, because industrial firms run build pipelines like everybody else.

Energy and utilities

Shell confirms it is investigating a potential incident [Confirmed]

  • Shell said on 14 August that it was aware of a potential incident and was investigating, after appearing on Cl0p's leak site during the Oracle E-Business Suite wave. It has confirmed an investigation and nothing further.
  • No data set, volume or impact has been confirmed by the company. Everything else circulating about it originates with the extortion group. [Claimed]
  • Two of the industrial advisories published on 13 August land directly in this sector. AVEVA Enterprise SCADA is used across energy, water and mining, and Hitachi Energy APM Edge sits in asset performance management for utilities.

Sources: Shell's own statement, 14 August 2026; CISA industrial control system advisory feed; Cyber Daily; SecurityWeek.

Also reaching this sector: every item in the cross sectoral section above, and the industrial quarter analysis in the manufacturing section, whose central finding is that production stops through corporate systems rather than through control systems.

Telecommunications and critical infrastructure

Two subsea cable systems into Perth faulted inside a protection zone, cause not established [Confirmed]

  • SUBCO's INDIGO West, which runs between Perth and Singapore, and INDIGO Central, which runs between Perth and Sydney, suffered shunt faults in close succession over the weekend of 8 and 9 August. A shunt fault means the outer insulation has been damaged and seawater has reached the interior. Both faults sit inside Australia's declared submarine cable protection zone off Perth.
  • Window discipline. The faults themselves fall in the previous window. The in window events are the Australian Federal Police confirming it has a report in front of it and the story becoming public on 10 and 11 August.
  • The AFP's statement, in full:

The AFP has received a report of crime in relation to this matter. This report is currently being assessed based on the information provided. Further comment will be made at an appropriate time.

  • No cause has been established, nothing has been attributed to any vessel or to deliberate action, and no vessel is named in this document. SUBCO's founder raised concern publicly about vessel activity near the location and timing, asked the AFP to look at it, and was explicit that it could be a coincidence. That is an operator asking for an investigation rather than announcing a conclusion. Shunt faults are routinely caused by anchors and fishing gear worldwide, and that explanation remains available. [Reported]
  • The board question survives whatever the cause turns out to be. Two paths failed close together inside one corridor. Redundancy is bought on the assumption that two things fail independently, and physical infrastructure has a habit of converging into one trench, one duct, one landing station or one stretch of seabed while the network diagram still shows two.

Sources: Australian Federal Police statement, primary; SUBCO's own account; iTnews; Converge Digest; Marine Insight; Tom's Hardware; Reuters syndication.

Also reaching this sector: the Cisco ASA and FTD catalogue addition in the cross sectoral section above, since a firewall that can be crashed without authentication is an availability problem for any operator of remote access.

Financial services

Operation Honey Bee, an entire sector rehearsing a coordinated attack [Confirmed]

  • The Gateway Network Governance Body announced Operation Honey Bee 2026, reported on 12 August and scheduled for Wednesday 19 August. This is a planned exercise. No fund has been attacked, and any reading of it as an incident is wrong.
  • More than fifty participants, including fifteen superannuation funds, administrators, gateway providers, the sector's regulators and industry and government stakeholders. Fourth year of the exercise and the largest to date, facilitated by an external risk advisory firm rather than run in house. Participant numbers vary slightly between outlets and these are GNGB's own.
  • The design is the part worth a director's attention. Most organisations that rehearse at all rehearse alone, which is the one scenario in which everybody else is available to help. Honey Bee tests what an ecosystem does when several members are hit at once and have to share information and coordinate recovery while each is having its own worst day.
  • GNGB's chief executive Michelle Bower stated the purpose:

By working together, participants can strengthen the resilience of the superannuation ecosystem and help protect Australians' retirement savings.

  • It follows APRA's position after the 2025 attacks on the sector that coordination across the industry protects more than any single fund can protect alone. [Reported]

Sources: Gateway Network Governance Body announcement, primary; iTnews; Super Review; ASFA; Financial Newswire; Proactive Investors; Cyber Daily.

Two consumer cryptocurrency platforms disclosed customer data losses [Reported]

  • Trezor disclosed a breach affecting approximately 14,000 customers, reported on 13 August. SafePal disclosed one affecting 39,798 customers, reported on 16 August. Both are smaller than the week's featured items and are carried here because the pattern in this segment is consistent rather than because either count is large.
  • Flagged as lighter. Neither has the independent corroboration that would carry a featured item, and neither company's own notification has been read directly for this document.
  • The material risk in this segment is rarely the platform balance. It is that a customer list with contact details becomes the raw material for the next round of targeted approaches, which is the same mechanism seen in the technology section this week. [Assessment]

Sources: BleepingComputer; SecurityAffairs; Help Net Security.

Also reaching this sector: every item in the cross sectoral section above. The business intelligence platform item in particular, since finance functions are where reporting tools are most often stood up outside procurement.

Retail and consumer

Nick Scali told the market on the afternoon it took systems offline [Confirmed]

  • Furniture retailer Nick Scali Limited filed an ASX announcement at 4:32pm on Friday 14 August saying it was investigating a security incident. It is the primary record, it is the company's own words, and it is short.
  • What the announcement says. The company took certain systems offline. Sales orders and deliveries are still being completed, with response times to customers slower than normal. The company does not have evidence of unauthorised access to its customer data. It has notified the Australian Cyber Security Centre and the Australian Federal Police.
  • That is the whole of the confirmed record. No group has claimed the incident on any leak site as at the close of the window. Other material is circulating, some of which may prove correct, and none of it is the company's own account. This document carries the filing and nothing else, and it says nothing about data, actor or dwell time.
  • The governable detail is the timing rather than the incident. The company filed on the afternoon it took systems down, while the investigation was days old, rather than at the end of it. Somebody held the authority to make that call and held it before the week began. [Assessment]

Sources: Nick Scali Limited ASX announcement, 14 August 2026, primary; Cyber Daily; Inside Retail; Capital Brief; TipRanks; Reuters via TradingView.

Two Australian online retailers appeared on leak sites and have said nothing [Claimed]

  • Ollie's Place Kidswear, an online children's clothing retailer, was listed by the group calling itself The Gentlemen on 14 August. Oz Hair and Beauty, an online beauty retailer, was listed by the group calling itself Xpl0itrs in the days that followed.
  • Both are listings on extortion sites and nothing more. Neither company has confirmed anything, no reputable outlet has stood either up independently, and nothing is asserted here about what was taken from either.
  • The pattern rather than the companies is the reason they are recorded. Two online retailers and a construction consultancy, in one week, from three unrelated groups, is the actual shape of the mid market threat picture, and it is not the shape the news reports. [Assessment]

Sources: RansomLook and Ransomware.live leak site data, pulled directly.

Also reaching this sector: the Cl0p wave in the cross sectoral section above, and the leak site volume item, which puts these two listings inside a total of 99 for the week.

Technology and software

RingCentral, 1.6 million records analysed, and the data is itself a phishing kit [Reported]

  • Have I Been Pwned analysed the dumped archive on 13 August and counted 1.6 million unique email addresses, each accompanied by a full name, a telephone number and a physical address.
  • The initial access was voice phishing an employee, which is the same technique behind the coordinated campaign against financial firms reported the previous week.
  • The consequence is circular and worth naming. A data set of names, numbers and addresses is precisely the material required to make the next voice phishing call convincing. The output of this incident is an input to the next one. [Assessment]

Sources: Have I Been Pwned, 13 August 2026; BleepingComputer; The Hacker News.

VMware vCenter, CVE-2026-59310, compromised hosts counted by one researcher [Reported]

  • An unauthenticated path traversal leading to code execution, CVSS 9.8. Disclosed on 29 July, so the in window element is the reporting on 13 August rather than the flaw itself.
  • QUIRSO reports 361 compromised addresses across 47 countries as at 7 August, with attackers installing reverse SSH for persistence. That is a single research source and the figure has not been independently reproduced. [Assessment]
  • Persistence installed through a virtualisation management plane survives the patching of the flaw that allowed it. Applying the fix is the beginning of the work here rather than the end of it.

Sources: QUIRSO research; Broadcom advisory, 29 July 2026; SecurityWeek; The Hacker News.

Shorter notes from the software estate [Reported]

  • SAP Commerce Cloud. A maximum severity flaw is reported as under active attack, reported 14 August. Flagged as lighter pending a primary vendor record.
  • Apple issued a further round of mercenary spyware Threat Notifications on 13 August. Apple does not name the operators or the targets, and the notification round is the whole of the public record.
  • Threema was disrupted by a large scale distributed denial of service attack on 16 August. Availability only, with no claim of data loss by anybody.
  • Zebra Technologies was listed by Cl0p on 13 August as part of the Oracle wave covered in the cross sectoral section. Listed, not confirmed. [Claimed]

Sources: SecurityWeek; BleepingComputer; Apple's own notification programme; SecurityAffairs; RansomLook leak site data.

Also reaching this sector: the business intelligence and geospatial platform items in the cross sectoral section above, and the LiteLLM build pipeline item, which lands harder on software organisations than on anybody else.

Government and defence

Royal Navy patrol vessel cameras were sending heartbeat traffic to an address in China [Reported]

  • A routine cyber vulnerability assessment found that cameras fitted to the Royal Navy's K3 Scout autonomous patrol vessels had been sending automated heartbeat signals to an IP address in China for around five months. Reported 10 August.
  • The cameras carried documentation certifying them as compliant with United States restrictions on Chinese made military electronics. The manufacturer, Kraken, said the cameras came from a third party supplier and were represented as compliant, and has not named the supplier or the components.
  • Heartbeat traffic is a device stating that it is still alive. It is not evidence of data leaving, and the Ministry of Defence has said it found no evidence that any of its data or systems were accessed or transmitted. Anyone describing this as exfiltration from a warship has invented it. [Confirmed]
  • The remediation was to disconnect the cameras from the internet, which closed the path and degraded the capability at the same time. That trade is the honest cost of finding this late rather than at procurement.
  • The story is provenance and paperwork, and it reaches any organisation that has ever accepted a compliance certificate as proof of where a component came from. Devices of this class are bought as equipment rather than as computers, certified on documentation rather than tested, and placed on networks nobody monitors for outbound traffic. [Assessment]

Sources: Ministry of Defence statement; Kraken's own statement; The Register, 10 August 2026; DroneXL; Army Recognition; Defence Blog; eSecurity Planet.

Also reaching this sector: the Windows afd.sys item in the cross sectoral section above, whose named targets are defence contractors, aerospace engineers and aviation professionals, and whose selection method was individual technical staff approached about work in their own field.

Professional services

3-Point Australia listed by the group calling itself Storm [Claimed]

  • 3-Point Australia, a project management and construction consultancy, was listed on 14 August with a claimed attack date of 13 August.
  • The listing is confirmed as a listing, taken directly from leak site data. The company has confirmed nothing and no second outlet has stood it up. Nothing is asserted here about what was taken.
  • Professional services firms hold client material without holding client liability for it in any way a client can see, which is what makes a listing in this sector propagate into other organisations' risk registers within days. [Assessment]

Sources: RansomLook and Ransomware.live leak site data, pulled directly.

Also reaching this sector: the business intelligence platform item in the cross sectoral section above, since consultancies run reporting tools wired into client data, and the leak site volume item.

Healthcare

There was no healthcare incident in the window. The sector is named rather than dropped because an empty sector is information, and because two items still reach it. Philips was named on Cl0p's leak site during the Oracle E-Business Suite wave, which is a claim by an extortion group and nothing more, and the batch of industrial advisories published on 13 August includes one medical device. The largest United States health data breach reported this year is not carried here. See the closing note.

Transport and logistics

There was nothing in this sector in the window. No incident, no advisory of its own and no disclosure. Tristar was named on the Cl0p leak site as part of the wave recorded in the cross sectoral section, which is a claim and not a confirmed event, and that is the whole of the sector's week.

Circulating, and not carried

  • Every exposure count. GreyNoise and the Shadowserver country level figures were both unreachable on this run. There is therefore no mass scanning against targeted read and no Australian exposure number anywhere in this document, for the Windows, Metabase or GeoServer items. A missing figure costs a sentence and a wrong one costs the document.
  • The Metabase host count. A commercial threat intelligence firm published an assessment on 8 August putting roughly eleven thousand hosts as probable self hosted deployments, with somewhat over four thousand likely running vulnerable versions. It is a real 2026 figure from a named firm and it is out on the same basis as last week's exploitation attempt figure for Kemp LoadMaster: a single commercial telemetry number with no visible methodology sits at Assessment and does not get promoted because it is convenient. It also carries no national breakdown, which is the number anyone asking the question actually wants.
  • **The five companies said to have lost customer data before the Metabase disclosure.** Traceable to disclosure reporting, but the companies are not named and no primary source names them.
  • The August Patch Tuesday total. Outlets counted the release at 398, 400, 421 and 751 depending on what each chose to include. No total is presented here as agreed fact. The count that is consistent everywhere is the number of flaws in the release already being used, which is one.
  • Cl0p's own claim of close to fifty companies, and its claimed data volumes for individual victims. Unverified figures from an interested party. The figure used above is more than forty listings on 12 August, which independent reporting stands up.
  • The named victim list in the LiteLLM research. Held back deliberately. One research firm's high confidence matches, none confirmed by the organisations named, in a document that gets forwarded.
  • Any theory about the Perth cables. Vessel identification and ship tracking material is circulating and none of it is carried here, not even to be dismissed, because repeating a claim in order to knock it down is still repeating it. No cause has been established.
  • The largest United States health data breach reported this year. DentaQuest, between 15 million and 23.4 million people. Access was in May, discovery on 20 May and notifications from 17 July. The mid August coverage is coverage, not news, and it is out of window.
  • Black Hat research into artificial intelligence coding agent harnesses, covering Claude Code, Gemini CLI and OpenAI Codex, one flaw rated 10.0 by Google. Published 6 August, which is the previous window. Strong material for a governance deep dive and the wrong week to run it as news.
  • The unnamed Australian kidswear brand reported on 17 August as investigating hacker claims. Out of window, very likely the same company as one of the listings recorded above, and not confirmed. We are not the ones to confirm it.
  • Phone cracking technology and NSW Police, reported 17 August. Out of window, and a surveillance and civil liberties story rather than a threat item.
  • A vendor programme announcement on small business protection, recorded so it is not mistaken for something missed. It is not a threat item.
  • Kaspersky is not cited anywhere in this document, consistent with the ASD posture. Nothing in the week required it.
  • New Zealand produced nothing in the window. Not thin, empty. The most recent NCSC New Zealand publication is third party data handling guidance dated 4 August, which is out of window and is guidance rather than an incident.

Start a conversation

Want this every week?

It goes out to the organisations we work with. Ask and you are on the list, and there is nothing else attached to it.

  • Every enquiry is read by a senior leader. There is no sales sequence behind this form.
  • Nothing is resold to you and no vendor introduction is waiting at the other end.
  • A first conversation is a conversation, not a scoping call with a proposal attached.

It reaches a senior leader, not a queue. If you would rather write directly, advisory@greencyber.ai.