Australian Monthly Threat Briefing: December 2025
As we close out 2025, the Australian cyber threat landscape has witnessed a volatile December, characterised by a sharp escalation in sector-specific ransomware campaigns and the weaponisation of critical vulnerabilities in cloud and AI infrastructure. Threat actors have aggressively targeted the "edge" of Australian networks—exploiting SaaS platforms, unpatched IoT devices, and third-party supply chains.
This briefing summarises the key threats, incidents, and vulnerabilities impacting Australian organisations over the last 30 days.
Sector-Specific Threat Intelligence
Healthcare
The healthcare sector remains under immense pressure. A major audit released in mid-December revealed systemic security bypasses within NSW Health districts, highlighting a culture of non-compliance that leaves patient data exposed. Concurrently, the Point Lonsdale Medical Group in Victoria suffered a significant cyber attack, resulting in unauthorised access to sensitive patient information. These incidents underscore the critical need for strict identity management and network segmentation in medical environments.
SaaS Providers
Software-as-a-Service (SaaS) providers are facing a dual threat from infrastructure vulnerabilities and supply chain attacks. Hexicor, an IT services provider, was targeted by the KillSec ransomware gang, which exfiltrated client folders and hashed passwords. This breach serves as a stark warning for SaaS platforms to enforce rigorous third-party risk management, as attackers increasingly use service providers as a pivot point to compromise downstream clients.
FinTech
December was a particularly damaging month for the financial technology sector. Austin’s Financial Solutions fell victim to the Kairos ransomware group, which allegedly stole 147GB of data, including employee passports and payroll records. Additionally, mortgage broker Finsure confirmed a cyber incident impacting nearly 300,000 unique email addresses. Regulatory scrutiny is also intensifying, with the Commonwealth Bank facing fines for Consumer Data Right breaches, emphasising the heavy compliance burden FinTechs face alongside active criminal targeting.
Education / EdTech
Australian universities continue to be prime targets for both hacktivists and extortionists. The University of New South Wales (UNSW) Physics Department was targeted by the hacktivist group RipperSec, disrupting website operations. Meanwhile, the University of Sydney confirmed a breach of an online IT code repository, exposing the fragility of development environments. The KillSec gang has also been observed aggressively targeting EdTech platforms, exploiting the high value of student data for extortion.
Government & Defence
A critical supply chain breach hit IKAD Engineering, a key defence contractor, exposing sensitive data related to Australia’s naval and weapons programs. This incident, claimed by ransomware actors, highlights the persistent threat to the Defence Industry Security Program (DISP) members. At the local government level, Muswellbrook Shire Council suffered a severe ransomware attack by the SafePay gang, which published 175GB of internal data after negotiations failed.
IoT & Critical Infrastructure
The "edge" remains a favoured entry point. The Australian Cyber Security Centre (ACSC) issued multiple alerts regarding the active exploitation of Cisco and WatchGuard edge devices. Threat actors are chaining vulnerabilities in these internet-facing appliances to bypass authentication and gain initial access to critical infrastructure networks.
Critical Vulnerabilities: Web, Cloud, & AI
Penetration testers and defenders must prioritise the following vulnerabilities, which have seen active exploitation or high-risk disclosure in the last 30 days:
AI Systems (LangChain Prompt Injection): A core vulnerability was identified in LangChain, a framework widely used for building AI applications. This flaw allows for "prompt injection" attacks, enabling attackers to manipulate Large Language Model (LLM) outputs to exfiltrate data or execute unauthorised commands. As Australian organisations race to integrate AI, this represents a significant, often overlooked attack vector.
Web Applications (React Server Components - CVE-2025-55182): A critical Remote Code Execution (RCE) vulnerability was discovered in React Server Components. Given the ubiquity of React in modern Australian web applications, this flaw poses a severe risk, allowing attackers to take control of servers hosting vulnerable apps.
Cloud Infrastructure (Fortinet FortiCloud SSO - CVE-2025-59718 & CVE-2025-59719): Critical authentication bypass vulnerabilities were patched in FortiCloud. These flaws allow attackers to bypass Single Sign-On (SSO) protections and gain administrative access to cloud-managed security appliances. Immediate patching is mandatory.
API Security: The Vroom by YouX incident earlier this month, which exposed driver's licences via a non-password-protected database, serves as a reminder of the dangers of API misconfigurations and "Zombie APIs" that lack proper access controls.
Conclusion
December 2025 has demonstrated that no sector is immune to sophisticated cyber coercion. From the exploitation of cutting-edge AI frameworks to the brute-force compromising of unpatched edge firewalls, the threat landscape is diverse and unforgiving. Organisations must move beyond compliance-based security and adopt a proactive stance—validating their defences against these real-world adversary behaviours.
Contact us for a quote for penetration testing service or adversary simulation.