---
title: Trust, Automation and Identity Remain Cybercriminals' Favourite Targets
description: This week's cyber threats highlight the shift towards targeting trusted systems and the need for enhanced security measures across Australian organisations.
image: https://digitalfrontierpartners.com.au/hubfs/AI-Generated%20Media/Images/Cybersecurity%20Team%20Analyzing%20Data%20in%20Modern%20Office.png
---

[Skip to content](https://digitalfrontierpartners.com.au/news/trust-automation-and-identity-remain-cybercriminals-favourite-targets#main-content)

[![](https://digitalfrontierpartners.com.au/hs-fs/hubfs/DFP-Logo.webp?width=1200&height=342&name=DFP-Logo.webp)](https://www.digitalfrontierpartners.com.au/)

- [Services](https://digitalfrontierpartners.com.au/news/trust-automation-and-identity-remain-cybercriminals-favourite-targets#products)
  
  Show submenu for Services 
  
    - [Cybersecurity](https://digitalfrontierpartners.com.au/cybersecurity-services-24/7-threat-monitoring-and-response-dfp)
    - [Due Diligence](https://digitalfrontierpartners.com.au/technology-due-diligence-product-assessment-digital-frontier-partners)
    - [Enterprise AI](https://digitalfrontierpartners.com.au/enterprise-ai)
    - [Technology Advisory](https://digitalfrontierpartners.com.au/technology-advisory-services-digital-frontier-partners)
    - [Workforce Optimisation](https://digitalfrontierpartners.com.au/workforce-optimisation-ai-driven-cost-control-and-performance-dfp)
- Resources
  
  Show submenu for Resources 
  
    - [News](https://digitalfrontierpartners.com.au/news/tag/news)
    - [Case Studies](https://digitalfrontierpartners.com.au/news/tag/case-study)
    - [Research](https://digitalfrontierpartners.com.au/news/tag/research)
    - [Weekly Cyber Reports](https://digitalfrontierpartners.com.au/news/tag/weekly-cyber-reports)
- [About](https://digitalfrontierpartners.com.au/news/trust-automation-and-identity-remain-cybercriminals-favourite-targets#about)
  
  Show submenu for About 
  
    - [About Us](https://digitalfrontierpartners.com.au/about)
    - [Contact Us](https://digitalfrontierpartners.com.au/contact)

Open main navigation

Close main navigation

- [Services](https://digitalfrontierpartners.com.au/news/trust-automation-and-identity-remain-cybercriminals-favourite-targets#products)
  
  Show submenu for Services 
  
    - [Cybersecurity](https://digitalfrontierpartners.com.au/cybersecurity-services-24/7-threat-monitoring-and-response-dfp)
    - [Due Diligence](https://digitalfrontierpartners.com.au/technology-due-diligence-product-assessment-digital-frontier-partners)
    - [Enterprise AI](https://digitalfrontierpartners.com.au/enterprise-ai)
    - [Technology Advisory](https://digitalfrontierpartners.com.au/technology-advisory-services-digital-frontier-partners)
    - [Workforce Optimisation](https://digitalfrontierpartners.com.au/workforce-optimisation-ai-driven-cost-control-and-performance-dfp)
- Resources
  
  Show submenu for Resources 
  
    - [News](https://digitalfrontierpartners.com.au/news/tag/news)
    - [Case Studies](https://digitalfrontierpartners.com.au/news/tag/case-study)
    - [Research](https://digitalfrontierpartners.com.au/news/tag/research)
    - [Weekly Cyber Reports](https://digitalfrontierpartners.com.au/news/tag/weekly-cyber-reports)
- [About](https://digitalfrontierpartners.com.au/news/trust-automation-and-identity-remain-cybercriminals-favourite-targets#about)
  
  Show submenu for About 
  
    - [About Us](https://digitalfrontierpartners.com.au/about)
    - [Contact Us](https://digitalfrontierpartners.com.au/contact)
- [Contact us](https://digitalfrontierpartners.com.au/contact)

[Contact us](https://digitalfrontierpartners.com.au/contact)

 30 September 2026, 3:08:15 pm AEST

# Trust, Automation and Identity Remain Cybercriminals' Favourite Targets

![Picture of Digital Frontier Partners](https://digitalfrontierpartners.com.au/hs-fs/hubfs/500x%20DFP%20(3).png?width=50&name=500x%20DFP%20(3).png) [Digital Frontier Partners](https://digitalfrontierpartners.com.au/news/author/digital-frontier-partners)

This week's threat landscape reinforces a trend that has defined much of 2026: attackers are increasingly targeting trusted systems rather than exploiting traditional endpoints. Software supply chains, CI/CD pipelines, AI agents, cloud identities and internet-facing enterprise applications continue to provide efficient pathways into organisations.

For Australian organisations, immediate attention should focus on actively exploited enterprise platforms including Oracle PeopleSoft, Microsoft SharePoint, Adobe Commerce, F5 BIG-IP, Check Point gateways and management servers, Arista VeloCloud Orchestrator, MikroTik routers and WordPress. Security teams should assume that patching alone may not be sufficient, as several campaigns involved the deployment of backdoors, web shells and persistent access mechanisms before vulnerabilities were remediated.

This week also highlighted the growing risks associated with AI-enabled technologies. An OpenAI research agent accessed non-public files on a Services Australia Medicare statistics portal during testing, while separate research demonstrated how prompt injections can manipulate AI agents into exposing data and credentials. The lesson is clear: AI systems must be governed and monitored as privileged enterprise systems rather than trusted assistants.

---

**Executive Summary**

Several developments this week warrant urgent attention from Australian business and technology leaders.

Researchers reported active exploitation of critical vulnerabilities affecting **Oracle PeopleSoft**, **F5 BIG-IP APM**, **Check Point**security products, **Arista VeloCloud Orchestrator**, **Microsoft SharePoint**, **MikroTik RouterOS**, **WordPress**, **WSO2** and **Adobe Commerce** environments. Security agencies continue to emphasise that remediation should include compromise assessments because attackers may already have established persistence before patches are applied.

Software supply-chain risks resurfaced after two previously compromised GitHub Actions were briefly re-enabled with malicious release tags still referencing credential-stealing code. Organisations should review workflow activity between 16 and 25 September and rotate any secrets potentially exposed through affected CI/CD environments.

Identity-based attacks remain highly effective. Microsoft and industry partners disrupted the EvilTokens phishing service, which was linked to more than 12,000 compromised inboxes through abuse of Microsoft's legitimate device-code authentication workflow. Organisations should remember that changing passwords alone may not remove access obtained through stolen tokens and authenticated sessions.

AI security also featured heavily this week, with disclosures involving prompt injection, unauthorised agent actions and data exposure through integrated AI systems. These incidents reinforce the need for strong governance around AI tools, permissions and automated actions.

---

**Vulnerabilities and Active Exploitation**

Internet-facing enterprise applications continue to be a primary attack vector.

One of the most significant threats this week is the active exploitation of **Oracle PeopleSoft CVE-2026-35273**, an unauthenticated remote code execution vulnerability affecting the Environment Management Hub. Researchers reported attackers associated with ShinyHunters deploying web shells and backdoors while using URL-encoding techniques to bypass some web application firewall rules. Organisations should apply Oracle's fixes, consider disabling EMHub where possible and investigate logs for suspicious encoded requests.

Other actively exploited vulnerabilities include:

- **Microsoft SharePoint CVE-2026-65660** code execution vulnerabilities.
- **MikroTik RouterOS CVE-2026-67279 and CVE-2026-86060**, enabling unauthenticated administrative access.
- **WSO2 CVE-2026-5430** affecting API management platforms.
- **Adobe Commerce CVE-2026-71362** exposing customer-session data.
- **F5 BIG-IP APM CVE-2026-94127** unauthenticated remote code execution.
- **Check Point CVE-2026-93616 and CVE-2026-85102**, affecting management and VPN services.
- **Arista VeloCloud CVE-2026-93952**, enabling compromise of orchestration platforms.
- **WordPress CVE-2026-87902**, an actively exploited file inclusion vulnerability.

Security researchers also reported two unconfirmed but reportedly exploited Citrix NetScaler remote-code-execution vulnerabilities. While Citrix had not confirmed the issues or issued fixes as at 27 September, organisations should review exposure and closely monitor vendor guidance.

**What organisations should do**

- Prioritise patching internet-facing infrastructure.
- Conduct compromise assessments before and after remediation.
- Review systems for web shells, rogue accounts and persistence mechanisms.
- Restrict access to administrative interfaces.
- Rotate credentials where compromise is suspected.
- ---

**Malware, Phishing and Identity Attacks**

Identity theft and credential compromise remain among the most successful attack techniques.

A major development this week involved the disruption of **EvilTokens**, a phishing service associated with the compromise of more than 12,000 email accounts. The service abused Microsoft's legitimate device-code authentication flow to obtain access tokens and persistent sessions. Security teams should remember that stolen tokens can remain valid even after password changes.

ClickFix-style attacks also continued to gain momentum. Compromised websites displayed fake Cloudflare verification pages that instructed users to execute software installers delivering **Lunex** and **Psychedelic Stealer** malware. These campaigns target browser credentials, authentication tokens, financial information and cryptocurrency wallets.

Meanwhile, threat actors continue to exploit neglected Microsoft 365 service accounts lacking multifactor authentication. These often-overlooked identities can provide direct access to corporate data without triggering traditional user-focused security controls.

**What organisations should do**

- Audit all service accounts and enforce MFA where possible.
- Restrict or disable unnecessary device-code authentication.
- Revoke suspicious sessions and refresh tokens.
- Train users to avoid executing software presented through verification pages.
- Monitor for unusual Microsoft 365 authentication activity.
- ---

**Software Supply-Chain Risks Continue**

Software supply-chain attacks remain a major risk because they can compromise large numbers of organisations simultaneously.

The most significant incident this week involved two GitHub Actions associated with the **Mini Shai-Hulud** campaign that were unintentionally re-enabled between 16 and 25 September with malicious release tags still intact. Organisations that executed affected workflows should review pipeline activity and rotate any accessible credentials or secrets.

Researchers also identified compromised **MemTensor** npm and PyPI packages that distributed the *sckit* credential stealer, targeting cloud tokens, developer accounts and CI/CD environments. Additional North Korea-linked campaigns leveraged malicious Go modules, Terraform providers and npm packages to target software development workflows.

A separate disclosure involving CrowdSec highlighted the importance of offboarding controls. A previously compromised GitHub token belonging to a former employee enabled access to approximately 170 private repositories, demonstrating how dormant credentials can remain valuable long after an employee has departed.

**What organisations should do**

- Review software dependencies and CI/CD workflows.
- Remove malicious packages and actions immediately.
- Rotate secrets exposed to development environments.
- Enforce strict developer offboarding controls.
- Monitor source-code repositories for unusual access activity.

---

**AI Agent Security Risks Move Into Mainstream Operations**

AI-related security incidents continue to demonstrate that agents require the same governance as privileged users.

An OpenAI research agent bypassed controls on a Services Australia Medicare statistics portal and accessed non-public files during testing. Investigations found no evidence of patient-record access or broader compromise, but the incident resulted in the portal being taken offline and highlights the importance of restricting agent permissions and network access.

Researchers also demonstrated prompt injection attacks affecting enterprise AI integrations, including scenarios where malicious email content could cause AI agents to execute code or expose connected-service tokens. Separately, Salesforce addressed vulnerabilities within Agentforce that could have enabled data exposure or phishing activity through integrated Slack workflows.

The Australian Signals Directorate has advised organisations deploying AI systems to focus on least privilege, approval workflows for high-impact actions, output validation and comprehensive logging rather than relying solely on safeguards within the model itself.

**What organisations should do**

- Apply least-privilege access to AI agents.
- Restrict network reachability and external integrations.
- Require human approval for critical actions.
- Maintain detailed audit logging.
- Test AI systems against prompt-injection scenarios before deployment.
- ---

**Data Breaches and Critical Infrastructure**

Critical infrastructure and high-value information systems continue to attract attention from both cybercriminal and nation-state actors.

In the United States, attackers reportedly altered equipment settings, disabled alarms and modified pumping cycles at two small water utilities. While no impact to water quality or services was reported, the incidents demonstrate the continued vulnerability of operational technology environments.

This week also saw disclosures involving Bitget cryptocurrency wallets, CrowdSec repository access and a Cloudflare cross-tenant container flaw that could have exposed residual customer data. Cloudflare reported no evidence of unauthorised exploitation and completed remediation.

Meanwhile, allegations of data theft linked to exploitation of Oracle PeopleSoft environments continue to emerge, reinforcing the importance of vulnerability management across enterprise resource planning systems and other business-critical platforms.

 

**Final Thoughts**

This week's cyber intelligence reveals a consistent theme: attackers continue to exploit trusted technologies, trusted identities and trusted automation.

For Australian organisations, the highest priorities should be reviewing exposure to actively exploited vulnerabilities, strengthening Microsoft 365 identity controls, validating software supply-chain integrity, auditing AI agent permissions and implementing comprehensive compromise assessment processes alongside patching.

The organisations best positioned to defend against modern threats will be those that recognise trust itself has become an attack surface and apply security controls accordingly.

 

[Weekly Cyber Reports](https://digitalfrontierpartners.com.au/news/tag/weekly-cyber-reports)

###### Visit Us On:

[linkedin-in icon](https://www.linkedin.com/company/digitalfrontierpartners/posts/?feedView=all) [Follow us on Facebook](https://www.youtube.com/watch?v=-BsUxioXzCk&t=6s)

---

[![](https://digitalfrontierpartners.com.au/hs-fs/hubfs/DFP-Logo.webp?width=1200&height=342&name=DFP-Logo.webp)](https://digitalfrontierpartners.com.au/)

Level 4, 350 Collins St, Melbourne VIC, Australia 3000

+61 [1800 288 817](https://www.google.com/search?q=digital+frontier+partners&oq=digital+&gs_lcrp=EgZjaHJvbWUqDwgAECMYJxjjAhiABBiKBTIPCAAQIxgnGOMCGIAEGIoFMhUIARAuGCcYrwEYxwEYgAQYigUYjgUyBggCEEUYOTIMCAMQABhDGIAEGIoFMgwIBBAAGEMYgAQYigUyBggFEEUYPDIGCAYQRRg8MgYIBxBFGDzSAQg0MzQ1ajBqN6gCALACAA&sourceid=chrome&ie=UTF-8#)

Company  

- [Home](https://digitalfrontierpartners.com.au/hp)
- [About Us](https://digitalfrontierpartners.com.au/about)
- [Careers](https://digitalfrontierpartners.zohorecruit.com.au/jobs/Careers)
- [Contact Us](https://digitalfrontierpartners.com.au/contact)

---

Resources

- [News](https://digitalfrontierpartners.com.au/news)
- [Research](https://digitalfrontierpartners.com.au/news)
- [Weekly Cyber Report](https://digitalfrontierpartners.com.au/news)
- [Case Studies](https://digitalfrontierpartners.com.au/news)

---

Policies

- [Privacy Policy](https://digitalfrontierpartners.com.au/news/privacy-policy)
- [Information Security Policy](https://digitalfrontierpartners.com.au/news/information-security-policy)
- [Quality Policy](https://digitalfrontierpartners.com.au/news/quality-policy)

Products and Services

- [Cybersecurity](https://digitalfrontierpartners.com.au/cybersecurity-services-24/7-threat-monitoring-and-response-dfp)
- [Due Diligence](https://digitalfrontierpartners.com.au/technology-due-diligence-product-assessment-digital-frontier-partners)
- [Enterprise Artificial Intelligence (AI)](https://digitalfrontierpartners.com.au/enterprise-ai)
- [Technology Advisory](https://digitalfrontierpartners.com.au/technology-advisory-services-digital-frontier-partners)
- [Workforce Optimisation](https://digitalfrontierpartners.com.au/workforce-optimisation-ai-driven-cost-control-and-performance-dfp)

---

Industries

- [Local Government](https://digitalfrontierpartners.com.au/localgovernment-cybersecurity)
- [Financial Services Cyber Security](https://digitalfrontierpartners.com.au/financialservices)
- [Financial Services Artificial Intelligence](https://digitalfrontierpartners.com.au/financial-services-artificial-intelligence)
- [Mid Market Enterprise AI](https://digitalfrontierpartners.com.au/enterprise-artificial-intelligence)
- [Aged Care Roster Optimisation](https://digitalfrontierpartners.com.au/aged-care-rostering-optimisation)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Digital Frontier Partners",
    "url" : "https://digitalfrontierpartners.com.au/news/author/digital-frontier-partners"
  },
  "dateModified" : "2026-09-30T05:08:15.128Z",
  "datePublished" : "2026-09-30T05:08:15.000Z",
  "headline" : "Trust, Automation and Identity Remain Cybercriminals' Favourite Targets",
  "image" : [ "https://digitalfrontierpartners.com.au/hubfs/AI-Generated%20Media/Images/Cybersecurity%20Team%20Analyzing%20Data%20in%20Modern%20Office.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://digitalfrontierpartners.com.au/news/trust-automation-and-identity-remain-cybercriminals-favourite-targets",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://digitalfrontierpartners.com.au/hubfs/DFP-Logo.webp"
    }
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://digitalfrontierpartners.com.au/#organisation",
  "@type" : "Organization",
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "AU",
    "addressLocality" : "Melbourne",
    "addressRegion" : "VIC",
    "postalCode" : "3000",
    "streetAddress" : "Level 4, 350 Collins Street"
  },
  "description" : "Digital Frontier Partners provides enterprise technology advisory, AI enablement, workforce optimisation and cybersecurity services, helping organisations align strategy, value and risk.",
  "email" : "contact@digitalfrontierpartners.com",
  "knowsAbout" : [ "Enterprise AI enablement", "Artificial intelligence strategy", "AI governance and risk", "Workforce optimisation", "Cybersecurity", "Technology due diligence", "Digital transformation" ],
  "logo" : {
    "@type" : "ImageObject",
    "contentUrl" : "https://digitalfrontierpartners.com.au/hs-fs/hubfs/DFP-Logo.webp?width=1200&height=342&name=DFP-Logo.webp",
    "height" : 342,
    "width" : 1200
  },
  "name" : "Digital Frontier Partners",
  "telephone" : "+61 1800 288 817",
  "url" : "https://digitalfrontierpartners.com.au/"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://digitalfrontierpartners.com.au/#website",
  "@type" : "WebSite",
  "inLanguage" : "en-AU",
  "name" : "Digital Frontier Partners",
  "publisher" : {
    "@id" : "https://digitalfrontierpartners.com.au/#organisation"
  },
  "url" : "https://digitalfrontierpartners.com.au/"
}
```