Australia-first cyber desk

Sources, not vibes.

Alerts, exploited vulns, and breach reporting with the original link attached. Weighted to Australia. Nothing here is invented; if a live feed dies, you get a labelled placeholder and the layout still holds.

Australia

ACSC / OAIC / AU press
2026-05-01

ACSC critical alert: cPanel/WHM CVE-2026-4194

ACSC assessed CVE-2026-4194 in cPanel/WebHost Manager as critical (CVSS 4.0 9.3). Hosting and MSP operators should treat internet-facing WHM as urgent. Listed on cyber.gov.au alerts.

australia vulnerabilitiesASD's ACSC

2026-03-01

Exploitation of Cisco SD-WAN appliances (joint advisory)

ASD's ACSC, with Five Eyes partners, published mitigations for ongoing exploitation of Cisco SD-WAN, including CVE-2026-20127, CVE-2026-20128 and CVE-2026-20122. Patch, hunt, and follow Cisco's hardening guide.

australia vulnerabilitiesASD's ACSC

2026-01-15

OAIC: 2025 notifiable data breaches hit a record 1,205

OAIC received 1,205 NDB notifications in 2025, up 8% on 2024. Malicious activity remained the main cause. Health service providers were the most commonly affected sector. Date on the media release was not stamped in the fetch; treat as OAIC 2026 publication covering 2025 stats.

breaches australia au-complianceOAIC

Vulnerabilities

KEV + ACSC

CISA KEV last pulled: 2026-08-26T11:12:20Z catalog 2026.08.25

2026-08-25

CISA KEV: Gitea code injection CVE-2026-60004

Added 25 August 2026. Gitea code injection via the diffpatch API for users with repository write access. Apply vendor mitigations; KEV due date 28 August 2026 for US FCEB.

vulnerabilities ai-techCISA KEV

2026-08-25

CISA KEV catalog (live feed used by this desk)

CISA catalog version 2026.08.25, 1676 known-exploited CVE records at last successful fetch. This POC stores recent KEV additions locally when the feed is reachable.

vulnerabilitiesCISA

2026-08-25

CISA KEV: CVE-2026-60004 Gitea Gitea

Gitea Code Injection Vulnerability. Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account. Required action: apply vendor mitigations. Source: CISA KEV 2026-08-25.

vulnerabilities ai-techCISA KEV

2026-08-24

CISA KEV: CVE-2026-21962 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability. Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data. Required action: apply vendor mitigations. Source: CISA KEV 2026-08-24.

vulnerabilitiesCISA KEV

2026-08-21

CISA KEV: CVE-2026-73570 Synacor Zimbra Collaboration Suite (ZCS)

Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability. Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user. Required action: apply vendor mitigations. Source: CISA KEV 2026-08-21.

vulnerabilitiesCISA KEV

2026-08-20

CISA KEV: CVE-2026-72530 TrueConf Server

TrueConf Server Code Injection Vulnerability. TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system. Required action: apply vendor mitigations. Source: CISA KEV 2026-08-20.

vulnerabilitiesCISA KEV

2026-08-20

CISA KEV: CVE-2026-72529 TrueConf Server

TrueConf Server Missing Authentication for Critical Function Vulnerability. TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script. Required action: apply vendor mitigations. Source: CISA KEV 2026-08-20.

vulnerabilitiesCISA KEV

Breaches

NDB / reported incidents
2026-01-15

OAIC: 2025 notifiable data breaches hit a record 1,205

OAIC received 1,205 NDB notifications in 2025, up 8% on 2024. Malicious activity remained the main cause. Health service providers were the most commonly affected sector. Date on the media release was not stamped in the fetch; treat as OAIC 2026 publication covering 2025 stats.

breaches australia au-complianceOAIC

AI and tech

tooling in KEV
2026-08-25

CISA KEV: Gitea code injection CVE-2026-60004

Added 25 August 2026. Gitea code injection via the diffpatch API for users with repository write access. Apply vendor mitigations; KEV due date 28 August 2026 for US FCEB.

vulnerabilities ai-techCISA KEV

2026-08-25

CISA KEV: CVE-2026-60004 Gitea Gitea

Gitea Code Injection Vulnerability. Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account. Required action: apply vendor mitigations. Source: CISA KEV 2026-08-25.

vulnerabilities ai-techCISA KEV

2026-08-19

CISA KEV: CVE-2026-64849 MLflow MLflow

MLflow Server-Side Request Forgery Vulnerability. MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body. Required action: apply vendor mitigations. Source: CISA KEV 2026-08-19.

vulnerabilities ai-techCISA KEV

2026-08-04

CISA KEV: IBM Langflow code injection CVE-2026-9198

Langflow default deployments: unauthenticated code injection leading to RCE, added to KEV 4 August 2026. Do not internet-expose unauthenticated AI workflow UIs.

vulnerabilities ai-techCISA KEV