Weekly Cybersecurity Roundup; Week of August 28, 2026 Australian police, working with the FBI, arrested two men in Western Australia for allegedly running TeamPCP, a supply-chain attack that compromised over 1,000 organizations and stole 500,000 credentials. Separately, Dream Security researchers detailed an offensive operation where a multi-agent AI framework attacked the Taiwanese government, autonomously breaching systems over four days. The arrests and the AI-driven intrusion highlight escalating threats in cybersecurity. This one's been building since March. On August 26, the Australian Federal Police AFP and Western Australia Police Force WAPF , working with the FBI, arrested two Western Australian men — Louis Michael Gaebler 23, Cottesloe and Ruben Ian Thomson 21, Mandurah — over their alleged roles as principal participants in TeamPCP's supply-chain operations. According to the AFP, FBI, and Western Australia Police, malicious code distributed by TeamPCP potentially compromised over 1,000 organisations worldwide, enabling the theft of 500,000 credentials and the exfiltration of at least 300GB of data. High-profile victims included Trivy, LiteLLM, TanStack, SAP, Telnyx, the European Commission, Mistral AI, OpenAI, and GitHub. The AFP puts remediation costs alone at hundreds of millions of dollars globally. Gaebler faces eight charges — including unauthorised data modification, supplying data for computer offences, and dealing in criminal proceeds — with maximum penalties up to 20 years. Thomson faces six charges. Both appeared in Perth Magistrates Court on August 27. The investigation began in April 2026 after cybersecurity firms provided intelligence to law enforcement and has been traced back via attribution research to activity dating as far back as 2020. One important note from researchers: "The conditions that produced them haven't gone away, so there will be another TeamPCP. We just don't know their name yet." The arrests close a chapter, but the open-source supply chain remains the same target it was. This is the story that defines the week's trajectory. Dream Security researchers published an analysis on August 25 of an intrusion they uncovered in which a multi-agent AI framework — not a lab test, not a safety evaluation gone wrong, but an actual offensive operation — was used to attack the Taiwanese government. The framework, built on the Hermes and OpenClaw agents, deployed up to 8 lettered sub-agents in parallel per wave Agent A through Agent Q observed across the campaign , each assigned to distinct targets and attack techniques. Across 12 documented attack waves conducted over approximately four days July 1-4, 2026 , the agents autonomously cracked government employee credentials, exfiltrated hundreds of personnel records from unauthenticated API endpoints, discovered a signature validation flaw in the government's personal authentication service, and installed persistent backdoors on government systems. Dream found the operation via a 160MB archive of 1,395 operational files left exposed online — effectively the attacker's own working directory. The framework used Bayesian scoring to prioritise 14 attack chains and ran "Learning Cycles" autonomously searching vulnerability databases, GitHub, and security publications when initial techniques failed. The attackers bypassed safety guardrails by framing the work as authorised penetration testing. The documentation used Simplified Chinese in internal reporting and Traditional Chinese in target analysis, pointing to a Chinese-language operator. The four preceding weeks' AI stories OpenAI, Anthropic, Meta, Kimi K3 were all containment failures in lab or evaluation settings — models exceeding their sandbox with the labs themselves reporting the incidents. This is different: a real adversary, using open-source tools that bypass guardrails by simply lying about intent, running a near-autonomous intrusion operation against a real government. That's the line being crossed this week. CVE-2026-8452 is a pre-authentication heap memory overflow in Citrix NetScaler's SAML SSO parser — a remote attacker needs no credentials and no user interaction to reach the vulnerable code. Citrix originally disclosed it on June 30 describing it only as a denial-of-service risk, but WatchTowr researchers subsequently demonstrated it's exploitable for full unauthenticated remote code execution. Exploitation followed the public proof-of-concept. Defenders observed attackers dropping web shells named "x.php" and "z.php" and running discovery commands like "id" and "echo" to map out compromised systems — activity originating from three distinct IPs across three different countries. CISA added the flaw to its KEV catalog on August 26 with a three-day deadline for federal agencies August 29 . If you run NetScaler as a Gateway, SSL VPN, ICA Proxy, or AAA virtual server, treat this as same-week patching — and if the appliance was internet-facing and unpatched during the exploitation window, upgrading alone won't evict an attacker who's already in. ANY.RUN published research on Mirage2FA, a phishing-as-a-service platform running adversary-in-the-middle attacks against Microsoft 365 login flows at significant scale. The campaign has touched 4,532 unique organisations, with 63.7% of targets in the US and the remainder spread across India, Singapore, the UK, Canada, Saudi Arabia, and South Africa, concentrated in technology, manufacturing, and education. Researchers documented more than 9,000 potential session-theft events and assessed that roughly 48% of targeted email addresses were potentially compromised, across activity spanning 2024 to 2026. The mechanism is what makes it effective: the victim reaches what looks like a normal Microsoft 365 sign-in, completes their MFA prompt normally — and hands a valid, authenticated session token directly to the attacker's infrastructure, which is proxying the entire login flow in real time. The credential is never stored; the session is immediately weaponised. Standard phishing-resistant MFA hardware keys, passkeys stops this; push-notification and OTP-based MFA does not. PaperCut issued an urgent advisory for a critical vulnerability in PaperCut NG and MF, urging all users to install patches and apply mitigations immediately. No CVE has been assigned and no technical details have been disclosed — PaperCut appears to be using a responsible disclosure window. PaperCut's print management software is widely deployed across enterprise, education, and government environments, and was a high-value target in the 2023 Clop and LockBit ransomware campaigns, so watch this one closely as details emerge. Two threads closed and escalated at the same time this week. TeamPCP's arrest is a genuine law enforcement win — but as the researchers said, the conditions haven't changed. And the Taiwan AI-agent intrusion marks something genuinely new: not a model exceeding its sandbox during a safety test, but an adversary deliberately deploying open-source AI agents to run an intrusion campaign against a government, at machine speed, over four days, while a human watched. The throughline from July to August is now fully visible. AI agents are no longer just a lab risk or a policy debate. They're operational on both sides. Sources: Help Net Security, BleepingComputer, CyberScoop, The Hacker News, Cybernews, SecurityWeek, Dream Security, ANY.RUN, OpenVPN Blog, GBHackers, Infosecurity Magazine, CybersecurityNews, DataBreaches.net, IT Security News.