News

The New Battleground: Identity, AI and Trusted Software

Written by Digital Frontier Partners | 12 August 2026, 4:05:24 am Z

Cybercriminals are increasingly avoiding noisy attacks and instead exploiting the technologies organisations trust every day. This week's intelligence highlights a concerning convergence of identity compromise, AI-enabled attack techniques, software supply chain intrusions and actively exploited vulnerabilities affecting enterprise platforms.

Attackers are leveraging legitimate authentication mechanisms, trusted development ecosystems and emerging AI capabilities to gain access, steal data and establish persistence while remaining difficult to detect. At the same time, several critical vulnerabilities are under active exploitation, placing internet-facing applications, remote management platforms and development environments at immediate risk.

For Australian organisations, the message is clear: traditional cyber hygiene remains essential, but boards and executives must also address identity governance, AI security controls, supply chain resilience and the growing risks associated with trusted third-party platforms.

Executive Summary

This week's highest-priority threats centre on actively exploited internet-facing systems, identity-focused attacks and software supply chain compromises.

A critical zero-day affecting self-hosted Metabase installations is being actively exploited to obtain administrator access, steal database credentials and extract connected data. At the same time, attackers are exploiting vulnerabilities in N-able N-central, Progress Kemp LoadMaster and JetBrains TeamCity, reinforcing the importance of rapid patching and post-compromise investigation.

Identity attacks continue to evolve. Threat actors associated with UNC6671 are impersonating IT support staff and contacting employees directly on their personal phones. Victims are redirected to adversary-in-the-middle phishing sites that capture credentials, MFA tokens and cloud sessions, allowing attackers to gain access to Microsoft 365, Okta and other SaaS environments before conducting data theft and extortion.

Software supply chain risks also remain elevated. Hundreds of malicious npm packages, compromised development tools and malicious extensions have been identified stealing developer credentials, repository tokens, cloud secrets and CI/CD credentials across Windows, macOS and Linux environments.

Artificial intelligence continues to create both opportunities and risks. Researchers disclosed multiple AI-related security weaknesses, including prompt injection vulnerabilities, agent hijacking techniques, coding-agent flaws and incidents where AI systems interacted with real-world systems due to inadequate testing controls and sandbox isolation.

Actively Exploited Vulnerabilities and Zero-Days

Several high-risk vulnerabilities are being actively exploited and should be treated as urgent patching priorities.

The most significant involves a critical Metabase zero-day that allows unauthenticated SQL injection, administrator access and theft of connected database information. Confirmed breaches have already occurred, demonstrating the real-world impact of delayed patching.

Meanwhile, vulnerabilities affecting N-able N-central continue to be exploited to gain administrative control of managed environments. Attackers have reportedly leveraged these flaws to execute remote-control functions and establish persistent access through Cloudflare Tunnels, creating significant risks for managed service providers and downstream customers.

Other important patching priorities include:

    • Progress Kemp LoadMaster command injection vulnerabilities.
    • JetBrains TeamCity remote code execution flaws.
    • WordPress authentication and code execution chains.
    • Gitea unauthenticated file-read vulnerabilities.
    • Critical Cisco SD-WAN and IOS XE vulnerabilities.
    • Linux privilege-escalation and container-escape flaws.

What organisations should do

    • Prioritise patching internet-facing systems.
    • Conduct compromise assessments after patching.
    • Review administrator and remote-access activity.
    • Monitor for unusual authentication behaviour.
    • Validate integrity of CI/CD environments and build pipelines.

Phishing, Social Engineering and Identity Compromise

Identity remains one of the most attractive attack vectors for cybercriminals.

This week, UNC6671 continued targeting employees in financial services, professional services, private equity and legal organisations. The group's approach relies on human trust rather than technical exploitation, with attackers impersonating help desk staff and convincing employees to authenticate through fraudulent portals that mimic legitimate services. Once access is obtained, attackers move quickly to extract sensitive information and pursue extortion opportunities.

Microsoft 365 environments remain a preferred target. Researchers observed campaigns leveraging voicemail-themed phishing emails, trusted redirect services and geographically aligned residential proxies to quietly compromise accounts and search payroll, finance and HR emails. These attacks create significant risks for payroll fraud, business email compromise and financial diversion attempts.

Device-code phishing campaigns also continue to increase. By abusing legitimate Microsoft authentication workflows, attackers can obtain OAuth tokens and establish persistent access without the need to steal passwords directly or bypass MFA through conventional means.

What organisations should do

    • Deploy phishing-resistant MFA wherever possible.
    • Restrict unnecessary device-code authentication.
    • Monitor authentication method changes.
    • Require managed and compliant devices.
    • Independently verify unsolicited support requests.

Malware and Software Supply Chain Attacks

Software supply chain attacks remain one of the most significant enterprise risks because they exploit trusted developer ecosystems and distribute compromise at scale.

This week, nearly 800 malicious npm packages were identified delivering remote access trojans and information stealers across multiple operating systems. A separate npm worm contaminated hundreds of packages and automatically spread through compromised publishing credentials, allowing attackers to harvest repository secrets, cloud credentials and development tokens.

Investigations also uncovered malicious developer extensions masquerading as legitimate tools, while package repository compromises and dependency poisoning attacks continued targeting open-source ecosystems. Organisations relying heavily on third-party software, development tools and cloud-native workflows face an elevated level of exposure.

Attackers also continued abusing trusted workflows. Fake software updates were used to deploy legitimate remote monitoring and management software, allowing attackers to maintain persistent access while avoiding traditional malware detection mechanisms.

What organisations should do

    • Audit software dependencies and extensions.
    • Rotate developer credentials and access tokens.
    • Restrict package-install scripts where possible.
    • Monitor source code repositories for suspicious activity.
    • Treat affected development environments as compromised until proven otherwise.

AI and Agent Security Risks

AI-related security issues featured prominently in this week's reporting.

Researchers demonstrated multiple ways AI assistants, browsers and autonomous agents can be manipulated through prompt injection techniques. Hidden instructions embedded in emails, webpages, repositories and collaboration platforms can influence AI systems into exposing information or performing unauthorised actions.

Atlassian's Rovo assistant was found to be vulnerable to prompt injection scenarios capable of retrieving information from Jira and Confluence environments accessible to the user. Additional flaws were disclosed in AI development frameworks, coding assistants and agent execution environments that could allow unauthorised tool invocation, secret exposure and workflow compromise.

Perhaps most concerning are reports that misconfigured AI testing environments allowed models to interact with real-world systems, access external services and perform unintended actions due to weak sandbox controls. These incidents reinforce the need for governance and strong isolation when deploying autonomous AI capabilities.

What organisations should do

    • Apply least-privilege principles to AI agents.
    • Limit access to sensitive data repositories.
    • Isolate AI testing environments.
    • Implement human approval requirements for critical actions.
    • Include AI governance within enterprise risk frameworks.

Critical Infrastructure and Data Breaches

Several incidents this week reinforce the risks posed by exposed operational technology and internet-facing infrastructure.

Attacks against water systems overseas demonstrated how publicly exposed industrial controllers can be manipulated without sophisticated exploitation techniques. In separate incidents, internet-accessible PLCs were targeted to alter operational settings and disrupt services. While these incidents occurred outside Australia, the technologies involved are widely deployed globally and remain relevant to local critical infrastructure operators.

Data breaches resulting from exploitation of vulnerable platforms also continued, with incidents involving Metabase environments and remote management systems leading to exposure of customer, account and operational information.

What organisations should do

    • Remove industrial control systems from direct internet exposure.
    • Segment operational technology environments.
    • Review remote-access pathways.
    • Replace default credentials.
    • Continuously monitor externally accessible systems.

 

Final Thoughts

This week's cyber landscape reinforces a recurring theme: attackers are targeting trust. Whether through trusted software packages, legitimate authentication platforms, familiar support processes or emerging AI capabilities, threat actors are increasingly exploiting systems designed to improve productivity and efficiency.

For Australian organisations, immediate priorities should include patching exposed systems, strengthening Microsoft 365 and identity controls, reviewing software supply chain security, governing AI adoption and ensuring critical infrastructure remains appropriately segmented. The organisations that succeed will be those that recognise trusted systems are becoming the preferred pathway for modern cyber attacks and build their security strategies accordingly.