Australian Monthly Threat Briefing: December 2025
As we close out 2025, the Australian cyber threat landscape has witnessed a volatile December, characterised by a sharp escalation in sector-specific ransomware campaigns and the weaponisation of critical vulnerabilities in cloud and AI infrastructure. Threat actors have aggressively targeted the "edge" of Australian networks—exploiting SaaS platforms, unpatched IoT devices, and third-party supply chains.
As we close out 2025, the Australian cyber threat landscape has witnessed a volatile December, characterised by a sharp escalation in sector-specific ransomware campaigns and the weaponisation of critical vulnerabilities in cloud and AI infrastructure. Threat actors have aggressively targeted the "edge" of Australian networks—exploiting SaaS platforms, unpatched IoT devices, and third-party supply chains.
This briefing summarises the key threats, incidents, and vulnerabilities impacting Australian organisations over the last 30 days.
Sector-Specific Threat Intelligence
Healthcare
The healthcare sector remains under immense pressure. A major audit released in mid-December revealed systemic security bypasses within NSW Health districts, highlighting a culture of non-compliance that leaves patient data exposed. Concurrently, the Point Lonsdale Medical Group in Victoria suffered a significant cyber attack, resulting in unauthorised access to sensitive patient information. These incidents underscore the critical need for strict identity management and network segmentation in medical environments.
SaaS Providers
Software-as-a-Service (SaaS) providers are facing a dual threat from infrastructure vulnerabilities and supply chain attacks. Hexicor, an IT services provider, was targeted by the KillSec ransomware gang, which exfiltrated client folders and hashed passwords. This breach serves as a stark warning for SaaS platforms to enforce rigorous third-party risk management, as attackers increasingly use service providers as a pivot point to compromise downstream clients.
FinTech
December was a particularly damaging month for the financial technology sector. Austin’s Financial Solutions fell victim to the Kairos ransomware group, which allegedly stole 147GB of data, including employee passports and payroll records. Additionally, mortgage broker Finsure confirmed a cyber incident impacting nearly 300,000 unique email addresses. Regulatory scrutiny is also intensifying, with the Commonwealth Bank facing fines for Consumer Data Right breaches, emphasising the heavy compliance burden FinTechs face alongside active criminal targeting.
Education / EdTech
Australian universities continue to be prime targets for both hacktivists and extortionists. The University of New South Wales (UNSW) Physics Department was targeted by the hacktivist group RipperSec, disrupting website operations. Meanwhile, the University of Sydney confirmed a breach of an online IT code repository, exposing the fragility of development environments. The KillSec gang has also been observed aggressively targeting EdTech platforms, exploiting the high value of student data for extortion.
Government & Defence
A critical supply chain breach hit IKAD Engineering, a key defence contractor, exposing sensitive data related to Australia’s naval and weapons programs. This incident, claimed by ransomware actors, highlights the persistent threat to the Defence Industry Security Program (DISP) members. At the local government level, Muswellbrook Shire Council suffered a severe ransomware attack by the SafePay gang, which published 175GB of internal data after negotiations failed.
IoT & Critical Infrastructure
The "edge" remains a favoured entry point. The Australian Cyber Security Centre (ACSC) issued multiple alerts regarding the active exploitation of Cisco and WatchGuard edge devices. Threat actors are chaining vulnerabilities in these internet-facing appliances to bypass authentication and gain initial access to critical infrastructure networks.
Critical Vulnerabilities: Web, Cloud, & AI
Penetration testers and defenders must prioritise the following vulnerabilities, which have seen active exploitation or high-risk disclosure in the last 30 days:
AI Systems (LangChain Prompt Injection): A core vulnerability was identified in LangChain, a framework widely used for building AI applications. This flaw allows for "prompt injection" attacks, enabling attackers to manipulate Large Language Model (LLM) outputs to exfiltrate data or execute unauthorised commands. As Australian organisations race to integrate AI, this represents a significant, often overlooked attack vector.
Web Applications (React Server Components - CVE-2025-55182): A critical Remote Code Execution (RCE) vulnerability was discovered in React Server Components. Given the ubiquity of React in modern Australian web applications, this flaw poses a severe risk, allowing attackers to take control of servers hosting vulnerable apps.
Cloud Infrastructure (Fortinet FortiCloud SSO - CVE-2025-59718 & CVE-2025-59719): Critical authentication bypass vulnerabilities were patched in FortiCloud. These flaws allow attackers to bypass Single Sign-On (SSO) protections and gain administrative access to cloud-managed security appliances. Immediate patching is mandatory.
API Security: The Vroom by YouX incident earlier this month, which exposed driver's licences via a non-password-protected database, serves as a reminder of the dangers of API misconfigurations and "Zombie APIs" that lack proper access controls.
Conclusion
December 2025 has demonstrated that no sector is immune to sophisticated cyber coercion. From the exploitation of cutting-edge AI frameworks to the brute-force compromising of unpatched edge firewalls, the threat landscape is diverse and unforgiving. Organisations must move beyond compliance-based security and adopt a proactive stance—validating their defences against these real-world adversary behaviours.
Contact us for a quote for penetration testing service or adversary simulation.
Monthly Threat Briefing: Australia – November 2025
As we approach the holiday season, the Australian cyber threat landscape has intensified, with November 2025 marking a significant surge in ransomware activity and sophisticated supply chain attacks. The Australian Signals Directorate (ASD) and private sector intelligence indicate that threat actors are increasingly capitalising on reduced staffing levels during weekends and public holidays, a trend expected to escalate as we head into December. This month’s briefing analyses critical incidents and emerging vulnerabilities across key sectors, highlighting the urgent need for robust defence mechanisms in web applications, cloud environments, and AI systems.
As we approach the holiday season, the Australian cyber threat landscape has intensified, with November 2025 marking a significant surge in ransomware activity and sophisticated supply chain attacks. The Australian Signals Directorate (ASD) and private sector intelligence indicate that threat actors are increasingly capitalising on reduced staffing levels during weekends and public holidays, a trend expected to escalate as we head into December.
This month’s briefing analyses critical incidents and emerging vulnerabilities across key sectors, highlighting the urgent need for robust defence mechanisms in web applications, cloud environments, and AI systems.
Sector-Specific Threat Intelligence
Healthcare
The healthcare sector remains a primary target for extortion. In November, the Point Lonsdale Medical Group in Victoria confirmed a cyber attack resulting in the unauthorised access of personal information. This incident follows a broader trend of ransomware groups, such as INC Ransom, aggressively targeting medical centres and allied health providers. The critical nature of patient data makes these organisations prime targets for "double extortion" tactics, where attackers encrypt data and threaten to release it publicly.
Education & EdTech
Western Sydney University continues to manage the fallout from a major data breach revealed recently, which exposed sensitive data including tax file numbers, payroll figures, and health information. Forensic investigation suggests the unauthorised access occurred between June and September 2025, but the repercussions are currently being felt across the sector. This highlights the persistent persistence of threat actors within academic networks, often undetected for months.
Government
State-sponsored espionage remains a top concern. On 24 November 2025, federal parliamentarians and staff at Parliament House were issued a strict warning to disable Wi-Fi and Bluetooth on their devices during a high-profile visit by a foreign delegation. This precautionary measure underscores the heightened risk of close-access technical attacks and data interception targeting government officials.
Additionally, the Crisis24 OnSolve CodeRED platform, used by emergency services, faced disruptions due to a cyber attack claimed by the INC ransomware gang. This attack on critical emergency notification infrastructure demonstrates the willingness of cybercriminals to endanger public safety for financial gain.
SaaS & AI Systems
November saw a notable incident involving OpenAI and analytics provider Mixpanel. OpenAI severed ties with the vendor after a security lapse exposed non-content data associated with some API users, such as email addresses and organisation IDs. While no chat logs or API keys were compromised, this incident serves as a stark reminder of third-party supply chain risks in the AI ecosystem.
Furthermore, a breach at customer success platform Gainsight reportedly impacted Salesforce customer tokens, forcing companies to rotate credentials rapidly. For SaaS providers, these events highlight the fragility of trust in interconnected cloud ecosystems.
FinTech
The Australian Cyber Security Centre (ACSC) issued alerts this month regarding scammers impersonating police to target cryptocurrency users. These sophisticated social engineering campaigns aim to steal seed phrases and wallet funds. Financial institutions are also grappling with a rise in AI-driven fraud, where deepfake voice technology is used to bypass biometric authentication in phone banking.
IoT & Automotive
Vulnerabilities in connected vehicles took centre stage with the disclosure of a flaw in Subaru’s Starlink multimedia technology (CVE-2025-xxxx), which could potentially allow third parties to access user accounts. As vehicles become increasingly software-defined, the attack surface for IoT significantly expands, necessitating rigorous penetration testing of embedded systems and APIs.
Vulnerability Spotlight: Exploited & Critical CVEs
Organisations should prioritise patching the following vulnerabilities, which have been active or critical in November 2025:
- Oracle Identity Manager (CVE-2025-61757): A critical pre-authentication Remote Code Execution (RCE) vulnerability. Security researchers have observed this being exploited as a zero-day. Immediate patching is required for all identity governance implementations.
- Microsoft WSUS (CVE-2025-59287): A critical flaw in Windows Server Update Services allows attackers to intercept and manipulate updates. This is particularly dangerous for enterprise environments relying on internal update servers.
- Node-forge (CVE-2025-12816): A high-severity vulnerability in this popular JavaScript cryptography library can allow attackers to bypass signature verifications. Developers using this package in their web applications must upgrade immediately to prevent cryptographic bypass attacks.
Strategic Recommendations
As we enter the holiday period, Australian organisations must assume that "off-hours" are target hours. We recommend:
- ** enforcing 24/7 monitoring** or managed detection and response (MDR) coverage during the holidays.
- Reviewing third-party access auditing, especially for SaaS integrations (like the OpenAI/Mixpanel case).
- Conducting adversary simulation to test resilience against ransomware encryption and data exfiltration tactics.
Contact us for a quote for penetration testing service or adversary simulation.