Daily brief at 7am Melbourne. Unsubscribe any time.

Thursday 3 September 2026

The Ransomware Gang That Left an 80-Page Security Audit Behind

An AI-orchestrated ransomware attack that concluded with an 80-page security audit for the victim is the clearest sign yet that autonomous threat actors have arrived.

Lead story

The Ransomware Gang That Left an 80-Page Security Audit Behind

A ransomware attack documented this week did something no human crew has bothered to do before: after encrypting the victim's files and exfiltrating data, the AI agents behind the operation compiled and delivered an 80-page security audit detailing exactly how they got in, what they found, and what the victim should fix. Adding insult to injury, as The Register put it — but also raising a genuinely unsettling question about what autonomous attackers look like at scale.

The attack was carried out entirely by AI agents, from initial reconnaissance through lateral movement, encryption, and exfiltration. No human operator appears to have been hands-on-keyboard at any stage. The audit left behind was almost certainly a byproduct of the agents' own internal logging and reasoning — not a deliberate taunt — but the effect is the same: a more thorough post-incident report than most organisations produce for themselves.

Why this matters more than another ransomware headline

We've covered AI-assisted attacks before — tools that speed up phishing, help script exploits, summarise recon data. This is different. This is an agentic loop that executed every phase of an intrusion without human direction. That changes the economics of ransomware fundamentally. Human operators are a bottleneck: they sleep, they make mistakes under pressure, they can only run so many campaigns simultaneously. Remove that bottleneck and the volume ceiling lifts dramatically.

It also changes the defender's problem. Traditional threat intelligence relies partly on recognising human patterns — the tools a group favours, the hours they work, the mistakes they make when tired. AI agents don't have off-hours and they don't get sloppy at 3am.

The timing is notable

This comes the day after OpenAI's Astra model crossed what the company calls the "critical" cybersecurity threshold — capable of independently finding and exploiting zero-days across hardened systems. Google simultaneously announced Gemini 3.8 Flash Cyber and its Fairwind Program, giving priority defenders early access to a purpose-built security model. Anthropic unveiled Enterprise Frontier Safeguards. All three major frontier labs, on the same day, are making dual-use cyber capability moves.

That's not a coincidence. The labs know what's coming — their own red-teaming has shown it — and they're racing to put defensive tools in defenders' hands before offensive uses proliferate. The question is whether the gap between offensive availability and defensive adoption is wide enough for incidents like this week's ransomware attack to become routine.

What to watch

Attribution of AI-agent attacks is already harder than attribution of human-operated intrusions. Expect incident responders to start pushing for "agent fingerprinting" — ways to identify which model or framework ran an attack — the same way they fingerprint malware families today. Whether that's technically feasible at the speed agentic attacks move is an open question.

Australian organisations running unpatched perimeter devices — and there are plenty, based on ACSC's annual threat report data — are precisely the kind of soft targets autonomous agents optimise for. The patch-now message hasn't changed. But the urgency has.

Also today

153 Million Drivers Licences Are Now a Dark Web Product

A new identity-theft service appeared on dark web markets this week offering digital scans of more than 153 million US and Canadian drivers licences. Krebs on Security traced the source to a widely-used identity-verification company based in Louisiana — the kind of firm that collects licence scans when you rent a car, verify your age, or open a financial account. The FBI's New Orleans field office is investigating. The breach is unfolding in real time, with individuals confirming their own licences are available for purchase. It's a stark reminder that every scan you hand to a third-party verifier is only as safe as that company's security posture — and most people never know who those companies are.

Krebs on Security

SonicWall SMA 1000 Zero-Days Chained for Unauthenticated RCE — Attacks Already Underway

SonicWall has patched two zero-day vulnerabilities in its SMA 1000 series VPN appliances — CVE-2026-83548 (CVSS 10.0, pre-auth SSRF) and CVE-2026-83549 — that attackers are already chaining to achieve unauthenticated remote code execution. Third-party security operations centres monitoring affected customers say further attacks are described as "almost certain." SonicWall edge devices have been a recurring target in 2026, with earlier zero-days exploited over the northern hemisphere summer. SMA 1000 appliances are widely deployed in Australian enterprise and government environments as remote-access gateways; the ACSC has previously flagged SonicWall vulnerabilities in its advisories. Patch immediately.

The Hacker News

BGP Hijack Poisoned Virtualizor's Update Pipeline With a Root-Level Backdoor

Attackers used a Border Gateway Protocol hijack to divert update traffic from hosting-control-panel vendor Softaculous, then served a malicious Virtualizor package that installed persistent root access on affected hypervisors. One hosting provider confirmed five of 34 checked servers were compromised. The attackers used a technically valid TLS certificate for Softaculous domains — meaning HTTPS gave users false reassurance the update was legitimate. The incident is a textbook example of why software update integrity needs to go beyond transport-layer encryption. Hosting providers running Virtualizor should audit all hypervisors from the affected window (from approximately 28 August) and treat any flagged systems as fully compromised.

Ars Technica

Google, Anthropic, and OpenAI All Made Cyber AI Moves on the Same Day

In what reads like a coordinated industry moment, all three major frontier AI labs announced cybersecurity-focused moves on Wednesday. Google unveiled Gemini 3.8 Flash Cyber — its most capable security-focused model — and a new "Fairwind Program" giving governments, healthcare providers, and telcos early access. Anthropic released Enterprise Frontier Safeguards, combining zero data retention with automated misuse monitoring for enterprise Claude deployments. And OpenAI's Astra model was confirmed to have crossed the company's "critical" cybersecurity threshold, capable of independently finding and exploiting zero-days. The simultaneous announcements suggest the labs are acutely aware of the dual-use risk their models pose — and are trying to get defensive tools to defenders before the offensive uses proliferate.

The Hacker News

Malicious .git Configs Can Trick AI Coding Agents Into Running Attacker Code

Manifold Security disclosed eight vulnerabilities across seven popular command-line AI coding agents — including Claude, Codex, and Cursor — where a repository's Git configuration can name a shell command that the agent executes on the developer's local machine, outside its sandbox and without asking permission. Four of the eight flaws remained unpatched at the time of publication. The attack requires the malicious repo to reach the developer's machine, which could happen via dependency confusion, a compromised open-source package, or simply cloning a repo from an untrusted source. Developers using AI coding agents on work machines should treat this as a supply-chain risk equivalent to running arbitrary scripts from npm.

The Hacker News

Researchers Used Claude to Port an ICS Exploit Across PLC Hardware in Hours

Forescout's Vedere Labs used Anthropic's Claude to adapt a working pre-authentication RCE exploit — originally targeting one WAGO programmable logic controller model — to run on a different PLC model, executing attacker-supplied ARM shellcode on live hardware. The underlying vulnerability (CVE-2021-31886) is five years old, but the research shows that AI dramatically lowers the skill barrier for porting industrial control system exploits across hardware variants. PLCs sit at the heart of manufacturing, utilities, and critical infrastructure. Australian critical infrastructure operators governed under the SOCI Act should factor AI-assisted exploit development into their threat models when assessing OT network exposure.

The Hacker News

23-Year-Old Sality Botnet Finally Put Down

US and European authorities, working alongside CrowdStrike and the Shadowserver Foundation, disrupted the Sality botnet on 31 August — a peer-to-peer malware network that has been running, in various forms, since 2003. Authorities turned Sality's own architecture against it: by manipulating peer lists and sinkholing payload URLs, they cut infected machines off from operator commands without needing to touch each endpoint. Sality once counted millions of infected nodes; its persistence across two decades makes it a case study in how resilient decentralised malware architectures can be. The takedown is a meaningful win, though operators behind the network are not reported to have been charged.

The Record

GeoNetwork RCE Chain Threatens Government Geoportal Backends Worldwide

Two vulnerabilities in GeoNetwork — the open-source geospatial metadata platform used behind many government and agency web portals — can be chained to achieve unauthenticated remote code execution. Fixes shipped in versions 4.4.12 and 4.2.17 in July, but full vulnerability details were only published on 31 August, meaning the patch-to-disclosure window has now closed. GeoNetwork originated at the UN and is widely deployed across national mapping agencies, environmental departments, and local government. Several Australian government agencies use GeoNetwork-backed geoportals; administrators should confirm they are running patched versions immediately given the public availability of vulnerability details.

The Hacker News

UK Moves to Ban High-Risk Tech Suppliers From Critical Infrastructure

Late amendments to the UK's Cyber Security and Resilience Bill would give ministers explicit power to block high-risk technology vendors from supplying critical infrastructure — a significant expansion of the framework that already governs telecoms suppliers like Huawei. The move comes as supply chain attacks have intensified globally. Separately, the Bill has drawn criticism for placing security obligations on AI users rather than the vendors building AI systems, with ministers rejecting proposed "emergency shutdown" powers and mandatory red lines in favour of voluntary safeguards. Australia is watching closely: the SOCI Act's third-party risk provisions are broadly comparable, but stop short of similar ministerial supply-chain exclusion powers.

SecurityWeek

Google's Ad Exchange Gets a Pass — But the Antitrust Fight Isn't Over

A US federal court ruled that Google will not be required to sell its ad exchange business, despite the court having already found that Google acted illegally to monopolise the online advertising market. The Department of Justice had pushed for a structural break-up; instead the remedy is expected to be more limited behavioural remedies. It's a significant win for Google — a forced divestiture of the ad exchange would have been one of the most consequential tech antitrust remedies in decades. The ruling doesn't end the case, and Google still faces separate antitrust proceedings in Europe and ongoing scrutiny of its search dominance. Publishers — including Australian media — reliant on the ad tech ecosystem will be watching remedy negotiations carefully.

Ars Technica

Texas Police Used AI to Write the Report Documenting Their AI-Assisted Hunt for an Abortion Patient

A Texas police department used an AI tool to draft the official report documenting an investigation in which officers used Flock Safety's automated licence plate reader network to locate a woman suspected of having an abortion. The case layers two controversial AI surveillance uses on top of each other: AI-powered vehicle tracking to conduct the investigation, and AI-generated prose to document it. Civil liberties advocates argue the combination makes accountability harder — AI-drafted reports can obscure officer decision-making in ways that handwritten accounts cannot. The story has no direct Australian parallel yet, but Australian police agencies are expanding automated number plate recognition networks and beginning to pilot AI report-writing tools.

404 Media

Aesto Health Breach: 9.5 Million Patient Records Leaked From December Attack

Healthcare data company Aesto notified US federal regulators this week that a cyberattack last December exposed sensitive health information belonging to more than 9.5 million people. The nine-month gap between the incident and public notification — while within some regulatory windows — illustrates the chronic lag between breach occurrence and disclosure that leaves patients unable to protect themselves. Healthcare remains the sector most targeted by ransomware and data theft globally. Under Australia's Notifiable Data Breaches scheme, entities covered by the Privacy Act must notify the OAIC and affected individuals "as soon as practicable" — a standard that regulators have increasingly interpreted as weeks, not months.

The Record

Sources consulted