Skip to content

Trust Is Under Attack; this Time Through Developers, AI Agents & Identity Systems.

This week's threat landscape highlights a growing convergence between identity compromise, software supply-chain attacks and AI-enabled security risks. Attackers are increasingly bypassing traditional security controls by targeting the technologies organisations trust most: software development ecosystems, browser extensions, AI coding assistants, authentication systems and privileged administrative platforms.

For Australian organisations, the most immediate concern is the active exploitation of critical infrastructure and security management platforms. Vulnerabilities affecting Cisco Identity Services Engine (ISE), Cisco Secure Email Gateway, GitLab, WSO2 API Manager, Orkes Conductor and Issabel Framework are already being leveraged by attackers. In several cases, successful exploitation provides unauthenticated root-level access to systems responsible for identity management, email security and application delivery.

At the same time, AI-related threats continue to mature rapidly. Security researchers disclosed attacks against AI coding assistants, browser-based AI agents and plugin ecosystems that could allow attackers to access sensitive files, steal credentials or execute unauthorised actions using a victim's authenticated session.

The message for business leaders is clear: cyber risk now extends well beyond endpoints and servers. It increasingly includes AI agents, software dependencies, developer identities, browser extensions and cloud-integrated workflows


Executive Summary

The highest-priority threats this week centre on actively exploited enterprise infrastructure and identity systems.

Of immediate concern are Cisco ISE CVE-2026-76460 and Cisco Secure Email Gateway CVE-2026-76461, both of which are being actively exploited and can provide unauthenticated root command execution. Given the critical role these platforms play in network access control and email security, organisations should urgently patch affected systems and investigate for signs of compromise.

Australian organisations should also assess exposure to Check Point CVE-2026-91843, a critical root-level code execution vulnerability affecting management and log servers. Although exploitation has not been confirmed, the severity of the flaw and the privileged nature of these systems make rapid remediation essential.

Software supply-chain attacks remain highly active. Malicious npm packages impersonating legitimate libraries have been observed stealing system information and developer credentials while using Slack, Telegram and Ethereum-based infrastructure for command-and-control. Separately, attackers leveraged credentials obtained during a previous npm compromise to access approximately 170 private repositories belonging to CrowdSec through a former employee's still-active GitHub account.

AI security featured prominently throughout this week's reporting, with multiple vulnerabilities affecting OpenAI Codex, Docker Sandboxes and browser-integrated AI assistants. These issues demonstrate that AI tools should now be treated as privileged enterprise systems rather than simple productivity platforms.


Vulnerabilities and Active Exploitation

Several critical vulnerabilities are already under active exploitation and require immediate attention.

The most serious are Cisco ISE CVE-2026-76460 and Cisco Secure Email Gateway CVE-2026-76461, which can allow unauthenticated attackers to achieve root-level access. Because these products support identity management and email security functions, a successful compromise could undermine an organisation's broader security posture

Other actively exploited vulnerabilities include:

    • GitLab CVE-2026-85706 allowing unauthenticated arbitrary file access.
    • Orkes Conductor CVE-2026-58138 enabling unauthenticated remote code execution.
    • WSO2 API Manager CVE-2026-5430 JWT authentication bypass.
    • Issabel Framework CVE-2026-89026 authentication bypass and command execution.
    • WooCommerce Wholesale Lead Capture CVE-2026-27540 enabling unauthenticated web-shell uploads.
    • Multiple Linux kernel vulnerabilities newly added to CISA's Known Exploited Vulnerabilities catalogue. Researchers also disclosed several high-severity vulnerabilities not yet confirmed as exploited, including the Check Point management server flaw, SolarWinds ARM remote code execution vulnerabilities and sandbox escapes affecting OpenAI Codex and Docker Sandboxes.

 

What organisations should do

    • Prioritise remediation of internet-facing systems.
    • Conduct compromise hunting before declaring patching complete.
    • Restrict management interfaces to trusted networks.
    • Rotate exposed credentials, tokens and secrets.
    • Validate that attackers have not established persistence prior to remediation.

Software Supply-Chain Threats Continue to Escalate

Software supply-chain attacks remain one of the most significant enterprise risks.

Researchers identified malicious npm packages, including indexed-btree and btree-core, that impersonated legitimate software libraries and concealed malicious functionality within normal application runtime processes rather than installation scripts. This approach allows attacks to evade many traditional package security controls.

Another campaign, PhantomRaven, reportedly used more than 100 typosquatted and slopsquatted packages to harvest Git, npm and CI/CD credentials. Researchers assessed portions of the malware were likely AI-generated, reflecting the increasing role of AI in accelerating attacker development cycles.

Perhaps most concerning was the disclosure that credentials stolen during the earlier TanStack npm compromise enabled attackers to access approximately 170 private CrowdSec repositories through a dormant GitHub account belonging to a former employee. The incident highlights how a single developer compromise can create downstream impacts long after the initial attack.

What organisations should do

    • Audit software dependencies and package repositories.
    • Remove affected npm packages immediately.
    • Revoke unused developer accounts and access tokens.
    • Enforce stronger offboarding controls.
    • Restrict development workflows to approved internal repositories.

AI and Agentic Security Risks Move Into the Enterprise

AI security developments this week should serve as a wake-up call for organisations deploying agentic AI tools.

Researchers disclosed Heapjack and Overpatch, two vulnerabilities affecting OpenAI Codex that could allow malicious repositories to escape intended sandbox controls, access trusted tokens and execute commands outside authorised environments. Docker also patched vulnerabilities affecting its sandboxing technology that could enable host file access and unauthorised system interaction.

A separate attack technique, BragJack, demonstrated how malicious browser extensions can hijack AI assistants embedded within browsers. Researchers showed these attacks could potentially access emails, local files, screenshots, microphones, cameras and authenticated browser sessions.

Meanwhile, the newly disclosed Plugin4Shell vulnerability highlighted risks within AI coding ecosystems by allowing attackers to replace supposedly trusted plugins while coding assistants continued reporting approved versions as installed. The result is that AI agents may unknowingly execute malicious code with access to sensitive business systems and credentials.

What organisations should do

    • Maintain inventories of AI agents and plugins.
    • Restrict AI access to sensitive systems and data.
    • Apply least-privilege controls to AI environments.
    • Require human approval for high-impact actions.
    • Continuously monitor AI tools for unauthorised behaviour.

Malware, Espionage and Identity Threats

A joint advisory involving Australian and international authorities highlighted continued activity by North Korea-linked WaterPlum, which reportedly compromised more than 30,000 devices across 100 countries through fake recruitment campaigns and coding assessments. Stolen credentials and cryptocurrency assets reportedly resulted in losses exceeding US$10 million.

Identity-focused attacks also remain prominent. The N0va phishing campaign continues abusing legitimate device-code and OAuth authentication workflows to obtain access and refresh tokens for Microsoft and other cloud services, effectively bypassing much of the protection users typically expect from MFA.

Additional cyber espionage activity involved China-aligned FamousSparrow, Pakistan-aligned Transparent Tribe, and Iran-linked operators deploying surveillance-focused malware aimed at government, telecommunications and strategic sectors.


Data Breaches and Credential Exposure

The largest publicly disclosed breach this week involved Gyazo, where exploitation of a server vulnerability reportedly exposed approximately 23.62 million user records and metadata associated with roughly 490 million uploaded images. Exposed information may include password hashes, session identifiers, billing details, integration tokens, IP addresses and image-related metadata.

The incident serves as another reminder that identity information, API tokens and integration credentials are increasingly valuable targets for cybercriminals, particularly when they can be leveraged to gain access to downstream platforms and services.

 

Final Thoughts

This week's intelligence reinforces a theme that has become increasingly evident throughout 2026: attackers are targeting trust. They are exploiting trusted software packages, trusted identities, trusted AI assistants and trusted development workflows to gain access and establish persistence.

For Australian organisations, immediate priorities should include patching internet-facing systems, reviewing software supply-chain controls, strengthening developer identity governance, implementing AI security guardrails and removing dormant privileged accounts.

The organisations best positioned to manage cyber risk will be those that recognise cybersecurity is no longer just about protecting systems. It is about protecting the relationships of trust that connect people, software, identities and increasingly, artificial intelligence.