Weekly Threat Briefing: Critical Zero-Days and Nation-State Shifts Targeting Australia
Executive Summary
The last seven days (26 January – 02 February 2026) have been defined by a resurgence in high-criticality infrastructure vulnerabilities and evolving nation-state tradecraft. For Australian organisations, the immediate priority is addressing active exploitation of Ivanti Endpoint Manager Mobile (EPMM) zero-days and critical patches for Cisco network infrastructure. Simultaneously, the threat landscape is shifting with reports of North Korean APT groups restructuring their operations, while the healthcare sector faces renewed warnings regarding IT/OT convergence risks.
Top Priority: Exploited Vulnerabilities
1. Ivanti Endpoint Manager Mobile (EPMM) Zero-Days
Date Detected: 30 January 2026 Sector Impact: Government, SaaS, Enterprise Late last week, Ivanti issued an urgent warning regarding the active exploitation of zero-day vulnerabilities in its Endpoint Manager Mobile (EPMM). Threat actors are leveraging these flaws to bypass authentication and execute arbitrary code on mobile management gateways. Given the widespread use of Ivanti in Australian government and enterprise environments, this represents a critical risk.
- Action: Immediate patching is required. Security teams should hunt for indicators of compromise (IoCs) in gateway logs dating back to mid-January.
2. Cisco Network Infrastructure Vulnerabilities
Date Released: 27 January 2026 Sector Impact: All Sectors (Critical Infrastructure focus) Cisco released a major security advisory on Tuesday addressing multiple critical vulnerabilities in its IOS XE software. Exploitation allows unauthenticated remote attackers to gain administrative control over network devices. With Australian critical infrastructure heavily reliant on Cisco backbones, these vulnerabilities are a prime target for initial access brokers.
Sector-Specific Threat Intelligence
Healthcare: The IT/OT "Cascade" Effect
A new report released on 27 January 2026 by Trellix highlights a dangerous trend affecting the healthcare sector: the "cascading" effect of cyber attacks moving from administrative IT systems into Operational Technology (OT) and patient care workflows.
- Analysis: Australian healthcare providers are increasingly digitising patient systems. The report indicates that 75% of recent threats originated in non-clinical environments (e.g., email phishing) before laterally moving to impact medical devices.
- Recommendation: Network segmentation between clinical OT and administrative IT is no longer optional—it is a patient safety imperative.
Government: BEC and Social Engineering
A significant incident surfaced this week involving a $3.5 million loss from a government agency due to a sophisticated Business Email Compromise (BEC) attack. The perpetrators impersonated a construction contractor, leveraging deepfake-enhanced social engineering to authorise fraudulent payments.
- Takeaway: Technical controls (like MFA) must be supplemented with strict procedural verification for high-value transactions.
SaaS & Cloud: Salesforce Ecosystem Risks
Reports have emerged regarding a targeted campaign against Salesforce environments. While not a direct breach of Salesforce's core infrastructure, attackers are successfully harvesting high-privilege credentials via sophisticated phishing campaigns targeting Australian SaaS administrators.
- Risk: Once inside, attackers are exfiltrating customer databases and manipulating API integrations to maintain persistence.
FinTech & AI: The Implementation Trap
As Australian FinTechs rush to integrate AI-driven customer service agents, new research from Cyber Daily (30 January) warns of "AI implementation risks." Early audits suggest that many of these AI systems suffer from prompt injection vulnerabilities, allowing attackers to manipulate banking chatbots into disclosing sensitive user data or bypassing fraud checks.
Threat Actor Focus: North Korean APT Evolution
Intelligence surfacing on 30 January indicates a strategic shift within the infamous North Korean hacking ecosystem (often linked to the Lazarus Group). The group appears to be "dividing to conquer," splitting into smaller, specialised cells.
- New Tactics: One cell is focusing exclusively on cryptocurrency theft to fund state activities, while another is dedicated to supply chain espionage against the defence and education sectors.
- Relevance: Australian universities and defence contractors should anticipate highly targeted spear-phishing campaigns tailored to their specific research and development projects.
Recommendations for the Week Ahead
- Patch Immediately: Prioritise Ivanti EPMM and Cisco IOS XE updates.
- Review BEC Procedures: Verify payment details offline for all transactions over $10,000.
- Segregate OT Networks: Ensure clinical devices in healthcare settings are isolated from email and internet-facing segments.
- Audit AI Models: If you are deploying LLMs in customer-facing roles, conduct adversarial testing for prompt injection flaws.
Contact us for a quote for penetration testing service or adversary simulation.