AI Agents, Supply-Chain Arrests, and Citrix Exploits Dominate Cybersecurity Week
Australian Federal Police, alongside the FBI, arrested two Western Australian men on August 27 for their alleged roles in TeamPCP's supply-chain attacks, which compromised over 1,000 organisations, stole 500,000 credentials, and exfiltrated 300GB of data. Separately, Dream Security researchers revealed the first publicly confirmed near-autonomous AI cyberattack, in which a multi-agent framework using Hermes and OpenClaw agents conducted 12 attack waves against the Taiwanese government over four days, cracking 85 accounts and stealing over 2,500 personnel records. A critical pre-authentication remote code execution flaw in Citrix NetScaler, tracked as CVE-2026-8452, is under active exploitation with web shells being deployed, prompting CISA to add it to its Known Exploited Vulnerabilities catalogue with a three-day patch deadline. The week also saw the Mirage2FA phishing platform bypass multi-factor authentication for Microsoft 365 users across 4,532 organisations, while print management software PaperCut urged immediate patching for an unassigned critical vulnerability. Additional incidents included a phishing-linked breach at cybersecurity firm ReliaQuest, a pro-Russian cyberattack on Manchester Airports Group, and 58 arrests in a global money-laundering operation called Operation Jackal.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in