A synthesis of the significant global and Australian cyber events of April, May and June 2026, and what they mean for Australian organisations.
The second quarter of 2026 was defined by attacks on trust. Across April, May and June, the most consequential incidents did not involve attackers battering at hardened perimeters. They involved attackers walking in through the software supply chain, the identity plane, and third-party providers that their victims had every reason to trust.
Running underneath almost every story was artificial intelligence, which moved decisively from an emerging concern to an operational reality on both sides of the fight. Anthropic disclosed that a frontier model could autonomously discover and exploit previously unknown vulnerabilities, the FBI dismantled an AI-assisted phishing service blamed for 1.9 billion US dollars in losses, and by June the US government was forcing AI companies to restrict access to their most capable models. Regulators, from Australia's APRA and ASD to the Five Eyes agencies collectively, spent the quarter telling boards that this is a present business risk, not a future one.
Five interconnected themes ran through the quarter:
The connective tissue this quarter is trust. Supply chain compromise, identity abuse and third-party breaches are all attacks on relationships an organisation has chosen to rely on. Defending the perimeter is no longer the point when the adversary arrives as a trusted dependency, a valid credential or an authorised supplier. The practical work for the rest of 2026 is inventorying those trust relationships, monitoring them as if they were production infrastructure, and shrinking the blast radius when one of them fails.
These figures span very different units, from dollar losses to affected individuals to compromised devices. They are not additive. They are collected here to convey the scale and diversity of a single quarter's activity, and each is drawn out in the sections that follow.
Artificial intelligence dominated the quarter in three distinct roles: as an offensive weapon, as a defensive tool, and as a subject of urgent regulation. The three roles kept colliding.
In April, Anthropic published a technical assessment of its most capable model, Claude Mythos Preview, disclosing that during internal testing the model had autonomously discovered and exploited previously unknown vulnerabilities across every major operating system and web browser. In one documented case it chained four separate vulnerabilities to escape the security boundaries of both a browser and the underlying operating system, a level of sophistication historically associated with nation-state programmes. The model found a 27-year-old flaw in OpenBSD and a 17-year-old remote code execution flaw in FreeBSD, autonomously, in hours. Rather than release the model publicly, Anthropic launched Project Glasswing, a controlled consortium of defenders including AWS, Apple, Microsoft, Google, CrowdStrike and JPMorgan Chase, and estimated that comparable capabilities would emerge from other labs within six to eighteen months.
By June the criminal application was visible. Working with Google and Black Lotus Labs, the FBI dismantled ‘Outsider Enterprise’, a China-based phishing-as-a-service operation running since at least 2023 that combined AI with distributed phishing kits to impersonate trusted brands over the major US carriers. The operation was tied to roughly 9,000 fake sites, more than a million fraudulent URLs, the theft of over 3.8 million credit card records, and an estimated 1.9 billion US dollars in losses.
The offensive capability quickly became a governance problem. In June the US government forced Anthropic to suspend access to its two most advanced models, Fable 5 and Mythos 5, for all customers worldwide, citing a jailbreak that could turn the models toward finding software vulnerabilities. Anthropic disputed the basis for the order, describing the evidence as a narrow, non-universal jailbreak, but complied globally rather than attempt to partition access by nationality. Days later OpenAI delayed the full public release of GPT-5.6 at the US government's request, limiting access to a small group of vetted partners. Both episodes signalled that access to frontier models is now being treated as a national security control point.
Defensively, the message from every major agency was the same: adopt AI deliberately or fall behind. In June the Five Eyes cyber security agencies issued a joint statement warning that AI is accelerating the speed, scale and sophistication of attacks, shrinking the window between a vulnerability being discovered and exploited, and that this is now a core business risk and a leadership responsibility rather than a purely technical one. The UK's NCSC had already warned in early May of an AI-fuelled "patch tsunami", in which AI-driven vulnerability discovery flushes out years of accumulated technical debt faster than most security teams can absorb it.
Whether Mythos represents a genuine step change or partly reflects competitive positioning, the downstream pressure it created is real and it is not going away. The defensive implication is unglamorous but decisive: the organisations that will cope are the ones that already know what they run, can patch internet-facing systems in days rather than weeks, and prioritise perimeter systems first. Asset inventory accuracy and patch cadence, long treated as hygiene, are now the variables that determine whether an organisation stays ahead of AI-accelerated vulnerability discovery.
If one technical story defined the quarter, it was the erosion of trust in the software supply chain. Attackers repeatedly reached high-value targets not by breaking in directly, but by compromising the pipelines, packages and providers that their victims implicitly trusted.
April opened with a supply chain attack on Axios, a JavaScript library downloaded over 100 million times a week and present in roughly 80% of cloud and code environments. Attackers compromised a maintainer's account and published two backdoored versions that silently installed malware across Windows, macOS and Linux, live for about three hours before removal. Both Google and Microsoft attributed the attack to North Korean state actors, and it was accompanied by over 1,700 further malicious packages planted across developer ecosystems. Later in the month, data stolen from the private repository of application security firm Checkmarx was published, with access traced back to an earlier tampering of Trivy, a widely used open-source scanner, a clear illustration of supply chain long-tail risk surfacing weeks after the initial compromise.
May brought the moment the open-source world had been dreading. Over eight days, a group calling itself TeamPCP ran two waves of its Mini Shai-Hulud worm through the npm registry. On 11 May it hit TanStack, publishing 84 malicious versions across 42 packages reaching the 12-million-weekly-download react-router library. The method is what made it strategically important: no npm token was stolen and no maintainer was phished. Attackers hijacked TanStack's own GitHub Actions release pipeline through a misconfigured workflow, poisoned the build cache, and waited for a legitimate maintainer to merge. Every malicious package shipped with valid SLSA Build Level 3 provenance, a first in npm's history, effectively retiring "just check the signature" as a standalone defence. The worm self-propagated to more than 170 packages within hours; OpenAI disclosed that two employee devices were compromised, exposing source code and code-signing certificates. Eight days later the group returned through a compromised maintainer account and pushed 637 malicious versions across 323 packages in Alibaba's AntV ecosystem in a 22-minute automated burst.
The same pattern ran through the Australian incidents. Generation Life, Australian Clinical Labs and the Melbourne International Film Festival were all breached through third-party platforms and providers rather than their own core systems.
Treat CI/CD runners as production infrastructure, with the access controls and monitoring that implies. Implement a 24 to 72 hour cooldown before adopting new package versions, which would have caught both May waves before they spread. Audit build-pipeline workflow configurations organisation-wide, and be able to answer in minutes, not days, whether you are currently running any compromised version.
Identity was the battleground of the quarter, and one name recurred more than any other. ShinyHunters, an English-speaking group active since 2019 and closely intertwined with Scattered Spider inside the broader criminal network known as The Com, dominated the breach headlines from April through June.
The group's relevance to Australia is direct. It was behind the July 2025 Qantas breach that exposed data on roughly 5.7 million customers. In April 2026 there was a genuine law enforcement win when Tyler Buchanan, a 24-year-old operating as "Tylerb", pleaded guilty in a California federal court in connection with his role in Scattered Spider, facing sentencing in August. But as analysts noted, when individual members are arrested others fill the roles, and the operation did not slow.
April alone brought ShinyHunters breaches of Rockstar Games, Udemy and others, several traced to a shared third-party cloud access pathway. In May the group ran a sustained two-week extortion campaign against Instructure, exploiting an undisclosed flaw in the Canvas learning platform and claiming exfiltration of roughly 3.65 TB of data affecting approximately 275 million individuals across nearly 9,000 institutions. Much of the exposed data belonged to minors, which, unlike passwords or card numbers, cannot be rotated. Instructure ultimately announced it had "reached an agreement" with the attackers, language widely read as a thinly veiled confirmation of a reported 10 million US dollar payment.
The University of Technology Sydney, the University of Sydney, the University of Melbourne, RMIT, Flinders University and TasTAFE were confirmed as affected or investigating. Education Queensland, which has run its QLearn platform on Canvas since 2020, confirmed that staff and student names, email addresses and school locations were exposed, with targeted support offered to households flagged for family and domestic violence concerns given how readily school location data can be misused.
By June the group had shifted technique again, exploiting CVE-2026-35273, a critical unauthenticated remote code execution zero-day in Oracle PeopleSoft, to compromise more than 100 organisations between late May and early June. Around 68% of the victims were universities and colleges. The broader lesson of the quarter is that ShinyHunters' tradecraft, OAuth token theft from vendors, insider recruitment and zero-day exploitation, is being copied across the ecosystem faster than most organisations are adapting to it.
State-sponsored activity in Q2 shifted noticeably toward pre-positioning and disruption of critical infrastructure, rather than data theft alone.
On 7 April, six US federal agencies published a joint advisory confirming that Iranian-affiliated hackers had been compromising internet-facing industrial control systems across US water, energy and government facilities since at least March. The campaign was notable for using the vendor's own legitimate software, Rockwell's Studio 5000, to reach exposed devices with no custom malware required. Internet intelligence firm Censys identified 5,219 such controllers exposed globally, nearly 75% of them in the US, many connected via basic cellular modems at water pumping stations and remote substations.
On 23 April a broad international coalition including Australia's ACSC published a joint advisory on a significant shift in Chinese state-linked operations. Rather than routing attacks through infrastructure they control, these actors have moved to large-scale "covert networks", essentially botnets assembled from compromised home routers and Internet of Things devices, that are maintained by Chinese-linked companies and shared across multiple groups, making activity far harder to trace. The recommended response is to map and baseline edge-device traffic, particularly VPN and remote access, and enforce multi-factor authentication on all remote connections.
North Korea's operations were patient and well-resourced. Beyond the Axios supply chain attack, the regime stole approximately 578 million US dollars in April across the Drift Protocol (286 million) and KelpDAO (292 million) thefts, taking its cumulative crypto theft since 2017 past 6 billion dollars. Its fake-IT-worker operations also spread beyond the tech sector into Australian healthcare, civil engineering and customer service roles. Meanwhile the ACSC co-signed an updated advisory on a sustained Russian GRU espionage campaign against Western logistics and technology firms involved in Ukraine-related supply chains across at least 13 NATO countries.
The strategic backdrop tightened in May when CISA released CI Fortify, guidance built around isolate, sustain and recover that explicitly assumes critical infrastructure will be attacked during a crisis and must keep operating in a degraded state. "Operate degraded" has replaced "prevent breach" as the working assumption, reflecting the reality that Volt Typhoon-class actors are already pre-positioned in many environments. Australian critical infrastructure operators should read it alongside existing ASD material, because the underlying premise is one Australian regulators have pointed at for years.
Domestically, the quarter was one of unusually concentrated regulatory activity, much of it explicitly connected to the AI developments overseas.
The timing is the signal. APRA's AI letter, ASFA's SuperFCX application and the Mythos disclosure all landed in the same window, reflecting a genuine shift in how Australian regulators frame AI risk as something requiring board attention now. For APRA-regulated entities in particular, the AI letter requires a documented response, not just a read.
Ransomware and extortion activity against Australian organisations continued at a steady pace across all three months, spanning hospitality, education, construction, retail, jewellery, healthcare and local government suppliers. A representative sample is shown below.
| Organisation | Sector | Actor | Month |
|---|---|---|---|
| Genealogy SA | Community | SafePay | April |
| NSW Treasury (insider) | Government | Insider | April |
| Mastercom | Communications | INC Ransom | April |
| Generation Life | Financial services | Qilin | April |
| Goodstone Group | Hospitality | CMD Organisation | May |
| Scope Systems | IT services | Unattributed | May |
| Champion Homes | Construction | DragonForce | May |
| Gregory Jewellers | Retail | Kairos | May |
| Bluize | Hospitality IT | Qilin | May |
| Australian Clinical Labs (SunDoctors) | Healthcare | Third-party breach | June |
| Reynella East College | Education | Interlock | June |
| NSW Rural Fire Service | Emergency services | Unattributed | June |
| Southern Design RV | Retail | CMD Organisation | June |
| Melbourne International Film Festival | Arts | Third-party breach | June |
Categorising the quarter's most significant publicly reported incidents by their disclosed initial-access vector makes the central theme concrete. Where the entry point was stated, trusted third parties and the software supply chain accounted for more incidents than every other vector combined.
Several advisories issued during the quarter warrant prompt attention. Organisations should confirm their exposure to each and prioritise remediation of internet-facing systems.
| Identifier | Affected product | Issue | Status |
|---|---|---|---|
| CVE-2026-34621 | Adobe Acrobat and Reader | JavaScript processing flaw allowing code execution from a crafted PDF; exploited since November 2025 | Patch now |
| CVE-2026-4194 | cPanel / WebHost Manager | Authentication bypass actively exploited in the wild against hosting environments | Patch now |
| CVE-2026-35273 | Oracle PeopleSoft | Unauthenticated RCE zero-day used by ShinyHunters to compromise 100+ organisations | Patch now |
| FIRESTARTER | Cisco Firepower / Secure Firewall | Backdoor that survives firmware upgrades; patched devices may remain compromised | Investigate |
| FortiBleed | Fortinet firewall / VPN | Credential campaign against ~75,000 devices using brute-force against reused, leaked credentials | Investigate |
| Vidar / ClickFix | Windows endpoints | Vidar Stealer delivered via compromised Australian WordPress sites and a fake CAPTCHA that tricks users into running PowerShell | Awareness |
The Vidar campaign abuses legitimate Australian websites and asks the victim to paste a command into PowerShell as administrator, sidestepping endpoint controls because the user runs it voluntarily. The rule to socialise across every workforce is blunt: if a CAPTCHA or a website ever tells you to open PowerShell and paste a command, it is malware.
The through-line of Q2 2026 is that adversaries are working through trust relationships rather than around defences, and that AI is compressing the time available to respond. None of the priorities below are novel. What has changed is the speed at which failing to act now converts into exposure.
Signed, provenance-verified packages shipped malware this quarter. Apply the same access controls, monitoring and review discipline to build pipelines as to production systems, and introduce a 24 to 72 hour cooldown before adopting new dependency versions.
FortiBleed, the Amex insider and the PeopleSoft campaign all turned on reused, excessive or unmonitored access. Enforce phishing-resistant MFA and single sign-on, log at account and action level, and move toward just-in-time access.
A critical RCE hit 100-plus victims in under two weeks. Maintain accurate asset inventories, know your external exposure, prioritise internet-facing systems first, and patch critical flaws in days, not weeks.
Several breaches arrived through suppliers, and shadow AI is now a supervisory concern. Audit third-party integrations and the permissions they hold, and treat unsanctioned AI use as a governance issue rather than an IT one.
The Five Eyes agencies call AI a leadership responsibility. Confirm your controls hold under a real incident, and adopt AI for defence, earlier vulnerability detection and faster response, as the ISM now urges.
With the framework set to retire over two years, begin mapping your controls to enterprise IT, operational technology, cloud and agentic AI as distinct domains, and engage with the consultation on the new Essentials series.