Two alleged TeamPCP members were arrested in Australia, closing a supply-chain saga that ran all summer. A multi-agent AI framework conducted a near-autonomous government intrusion in Taiwan — the first publicly confirmed case of its kind. And Citrix NetScaler is under active exploitation again."

TeamPCP arrests — two Australians (aged 21 and 23) charged over supply-chain attacks hitting 1,000+ organisations, 500,000 stolen credentials, and 300GB of exfiltrated data

First confirmed near-autonomous AI cyberattack on a government — eight coordinated AI agents (Hermes + OpenClaw) conducted 12 attack waves against the Taiwanese government over four days, cracking 85 accounts and stealing 2,500+ personnel records, with suspected Chinese-language operators

Citrix NetScaler CVE-2026-8452 — pre-auth RCE under active exploitation, web shells being deployed, CISA added to KEV with a 3-day patch deadline

Mirage2FA phishing platform touched 4,532 organisations with adversary-in-the-middle attacks bypassing MFA on Microsoft 365