惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
博客园 - 三生石上(FineUI控件)
V
V2EX
博客园 - 司徒正美
小众软件
小众软件
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
T
Tailwind CSS Blog
Last Week in AI
Last Week in AI
雷峰网
雷峰网
月光博客
月光博客
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Apple Machine Learning Research
Apple Machine Learning Research
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
S
SegmentFault 最新的问题
美团技术团队
Hugging Face - Blog
Hugging Face - Blog
WordPress大学
WordPress大学
宝玉的分享
宝玉的分享
爱范儿
爱范儿
博客园 - 聂微东
量子位
J
Java Code Geeks
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Vercel News
Vercel News

Security Affairs

Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog Over 400,000 sites at risk as hackers exploit Breeze Cache plugin flaw (CVE-2026-3844) CISA reports persistent FIRESTARTER backdoor on Cisco ASA device in federal network 12-year-old Pack2TheRoot bug lets Linux users gain root privileges Signal phishing campaign targets Germany’s Bundestag President Julia Klöckner
Australian Sugar Producer Mackay Sugar Reports Cyber Inci...
https://www.facebook.com/sec.affairs · 2026-06-16 · via Security Affairs

Mackay Sugar, Australia’s second-largest sugar producer, disclosed a cyberattack on June 10, potentially affecting key processing operations.

Mackay Sugar is one of Australia’s largest sugar producers and the country’s second-largest sugar manufacturer. The company is based in the Mackay region of tropical North Queensland and has more than 140 years of history in sugar cane processing. It operates three major sugar mills, Farleigh, Marian, and Racecourse, and produces around 700,000 tonnes of raw sugar annually for domestic and export markets. The company disclosed a cyberattack on June 10.

The timing is brutal: the attack hit during the crushing season, when mills run continuously and any interruption means cane sitting in fields or trucks with nowhere to go. Two of the three mills appear to have been forced offline.

“Mackay Sugar is responding to a cyber security incident affecting some of our operations.” reads the report published by the company. “Our immediate focus is the safety of our people, protecting operational systems, and maintaining business continuity.”

The company engaged cybersecurity experts to investigate the security breach, contacted relevant authorities, and stood up manual workarounds to keep critical functions running. It didn’t say which systems were hit, whether operational technology was involved, or whether any data was taken.

By June 12, Mackay Sugar had managed to restart a limited manual crushing operation at Farleigh Mill, processing cane that had been harvested before the attack. That’s a meaningful distinction: the mill ran on cane already cut, not on fresh supply coming in from the field. The rest of the supply chain, the systems that coordinate cane delivery, harvesting logistics, and mill intake, was still down. No new cane was being accepted. The June 15 update showed progress but not resolution.

“Significant progress has been made over the weekend in restoring the systems that support cane supply, harvesting and mill operations.” reads the update published on June 15, 2026. “Steam trials are now underway, and subject to final validation activities, some harvesting is expected to recommence this week in preparation for the staged restart of crushing operations later this week. We have taken the responsible course of action in advising growers and harvesters not to recommence harvesting until we advise them to do so.”

Steam trials mean the mill is testing whether its boilers and processing equipment can run safely before committing to a full restart. It’s the last check before cane goes back in.

Growers and harvesters were told explicitly to hold.

“We have taken the responsible course of action in advising growers and harvesters not to recommence harvesting until we advise them to do so.” continues the report. “We recognise the impact this incident is having on our growers, and we are doing everything we can to support them and to safely resume full operations as soon as possible.”

For growers, every day of delay means cane loses sugar content in the field and incurs logistics costs with nowhere to bill.

The Gentlemen ransomware group, tracked by Microsoft as Storm-2697, claimed responsibility for the attack and added Mackay Sugar to its Tor-based data leak site on June 15. At this time, no data has been leaked yet, which usually means negotiations are still ongoing.

The Gentlemen surfaced as a ransomware operation in September 2025 and by June 13, 2026 had listed 483 victims on their dark-web leak site, 380 of them in 2026 alone. That makes them the second most prolific ransomware brand of the year by published victim count, behind only Qilin. A May 2026 leak of the group’s internal chat logs handed researchers at KELA a rare look inside: nine core members, AI-assisted tooling, and an access model built almost entirely on credentials stolen by commodity infostealer malware.

The affiliate model is straightforward and aggressive. A small core team builds and maintains the ransomware and the negotiation panel. External operators carry out the actual intrusions and keep 90% of each ransom, which is a generous split even by current standards. The leaked chats, spanning November 7, 2025 to April 30, 2026, read less like a criminal conspiracy than a small product team arguing about infrastructure choices and which AI model to use for data analysis.

Mackay Sugar’s public statements don’t mention data compromise, and it’s still unclear whether the attackers reached industrial control systems directly or whether operational technology was affected as a downstream consequence of IT systems going down. That distinction matters: IT recovery and OT recovery are different problems with different timelines, and a mill that’s restored its business systems but hasn’t verified its control systems is not a mill that’s ready to crush.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Mackay Sugar)