This week’s cyber threat landscape reinforces a growing reality: attackers are increasingly combining active vulnerability exploitation, software supply chain compromise, sophisticated social engineering and AI-assisted operations to accelerate intrusions. In several reported incidents, compromise moved from initial access to credential theft and cloud-key exposure within hours rather than days or weeks.
For Australian organisations, the most urgent risks involve internet-facing infrastructure, particularly routers, VPN appliances, development platforms, e-commerce environments and remote management services. At the same time, threat actors continue to exploit trust in collaboration platforms such as Microsoft Teams, trusted software updates and legitimate remote administration tools.
The message for business leaders is clear: patching remains essential, but it is no longer enough. Organisations must assume compromise may have occurred before remediation and embed threat hunting, credential rotation and rapid incident response into vulnerability management processes.
Executive Summary
This week’s highest-priority threats centre on actively exploited vulnerabilities affecting internet-facing systems. The most significant include the MikroTrick campaign targeting exposed MikroTik RouterOS devices, actively exploited SonicWall SMA 1000 vulnerabilities, JFrog Artifactory authentication bypass, Langflow remote code execution vulnerabilities and ongoing exploitation of PaperCut environments.
E-commerce organisations face particular risk from an unpatched Magento and Adobe Commerce zero-day known as StyleSmuggler, which reportedly enables unauthenticated code execution and installation of persistent backdoors. With no official fix available at publication, affected organisations should consider temporary mitigation measures and closely monitor affected environments.
Software supply chain attacks remain highly effective. This week saw a compromise of Coder’s registry infrastructure that distributed malicious Terraform modules designed to steal cloud, AI, SSH and CI/CD credentials, while a separate BGP hijacking incident delivered trojanised Virtualizor software updates containing persistent access mechanisms.
Artificial intelligence continues to reshape offensive operations. Researchers reported an enterprise compromise that progressed to cloud-key theft in less than ten hours using coordinated AI agents, while ransomware operators increasingly use AI coding tools to accelerate reconnaissance, privilege escalation and lateral movement
Vulnerabilities and Active Exploitation
Attackers remain heavily focused on internet-facing systems that provide access to enterprise environments.
Of particular concern is the MikroTrick campaign, which targets exposed MikroTik RouterOS SSH services and enables unauthenticated administrative access. Organisations operating MikroTik devices should upgrade immediately and review systems for evidence of unauthorised accounts, SSH keys, scripts and configuration changes.
Security teams should also prioritise remediation of:
Australian organisations should also take note of reported exploitation attempts against Citrix NetScaler CVE-2026-19490, including activity reportedly originating from Australian IP infrastructure.
The compromise of JetBrains' Cadence environment through TeamCity CVE-2026-63077 further demonstrates the business impact of delayed patching, particularly within software development and CI/CD environments.
What organisations should do
Malware, Ransomware and Botnets
This week saw continued growth in malware campaigns abusing trusted tools and services.
The REVSTEALER malware ecosystem remains active, targeting cryptocurrency wallets, browser data and sensitive credentials. The malware is commonly distributed through fake AI applications, pirated software and game cheats, while deploying persistence mechanisms that disable security controls and evade detection.
Large-scale ClickFix and EtherHiding campaigns continue to compromise websites and abuse blockchain infrastructure for command-and-control communications. More than 5,400 compromised websites were reportedly observed distributing malicious PowerShell instructions disguised as CAPTCHA verification prompts.
Threat actors also continue to exploit software supply chains as an infection vector. Malicious Terraform modules, trojanised software updates and compromised development environments remain attractive because they provide access to large numbers of downstream victims simultaneously.
Meanwhile, law enforcement achieved a notable success by disrupting the long-running Sality botnet infrastructure. However, systems already infected still require remediation and rebuilding.
Phishing, Social Engineering and Credential Theft
Social engineering remains one of the most effective attack techniques because it targets people rather than technology.
The Spring Ring campaign leveraged external Microsoft Teams accounts to impersonate IT support staff and persuade employees to install remote-management software, approve Quick Assist sessions or execute malicious PowerShell commands. More than 150 employees across multiple organisations were reportedly targeted.
ClickFix and TerminalFix-style attacks continue to evolve. Rather than relying on malicious attachments, attackers present fake verification prompts instructing users to execute commands themselves, effectively turning victims into the deployment mechanism.
Researchers also observed large-scale phishing campaigns using invisible Unicode characters embedded within finance-related terms to evade detection systems. These campaigns reportedly reached volumes exceeding two million emails per day.
What organisations should do
Data Breaches and Supply Chain Attacks
Supply chain compromise remains one of the most significant business risks facing organisations.
A compromise of Coder's Cloudflare infrastructure enabled attackers to distribute malicious Terraform modules designed to steal credentials from cloud environments, development platforms, AI services and CI/CD pipelines. Organisations that downloaded affected modules should review exposure and rotate credentials immediately
A separate BGP hijacking incident redirected software update traffic and delivered a trojanised Virtualizor package that installed persistent access mechanisms and unauthorised accounts. The incident highlights the importance of verifying software integrity and maintaining robust software provenance controls.
Additionally, the JetBrains Cadence breach exposed a backup containing potentially sensitive source code, credentials and cloud secrets, reinforcing the importance of securing development environments and associated backup repositories
AI-Enabled Cyber Threats and Agentic Security Risks
AI continues to transform both cyber defence and cyber offence.
This week’s reporting highlighted the growing capability of autonomous and semi-autonomous agents to conduct reconnaissance, credential discovery and cloud compromise at machine speed. Unit 42 researchers reported an enterprise intrusion in which coordinated agents progressed from exposed infrastructure to cloud-key theft in under ten hours.
Researchers also identified risks associated with AI coding tools and agent platforms. Malicious Git configurations were reportedly capable of causing coding assistants to execute commands outside intended sandbox environments, creating new avenues for compromise.
Meanwhile, ransomware groups are increasingly adopting AI-assisted tools to accelerate privilege escalation, lateral movement and target analysis, reducing the time required to move from initial compromise to business impact.
What organisations should do
Final Thoughts
This week's intelligence reinforces a consistent theme throughout 2026: speed matters. Threat actors are exploiting vulnerabilities rapidly, compromising trusted supply chains and increasingly using AI to compress attack timelines.
For Australian organisations, the immediate priorities should be identifying exposed edge infrastructure, remediating actively exploited vulnerabilities, rotating exposed credentials, reviewing software supply chain dependencies and implementing stronger controls around AI-enabled systems.
The organisations best positioned to manage cyber risk are those that assume compromise can occur before a patch is deployed and build resilience through proactive monitoring, rapid detection and disciplined incident response.