Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: Defence Supply Chain Sieged, Russian Hosts Sanctioned & Critical Fortinet Zero-Days

The Australian cyber threat landscape has intensified over the last 24 hours with significant geopolitical moves and critical infrastructure attacks. The Federal Government, in coordination with the US and UK, has officially sanctioned Russian "bulletproof" hosting providers facilitating ransomware campaigns against Australian targets. Meanwhile, the defence supply chain is under scrutiny following a confirmed breach at a major naval contractor, and network defenders are racing to patch actively exploited zero-days in Fortinet and Citrix appliances.

Here is your daily deep dive into the threats shaping our digital environment.

Executive Summary The Australian cyber threat landscape has intensified over the last 24 hours with significant geopolitical moves and critical infrastructure attacks. The Federal Government, in coordination with the US and UK, has officially sanctioned Russian "bulletproof" hosting providers facilitating ransomware campaigns against Australian targets. Meanwhile, the defence supply chain is under scrutiny following a confirmed breach at a major naval contractor, and network defenders are racing to patch actively exploited zero-days in Fortinet and Citrix appliances.

Here is your daily deep dive into the threats shaping our digital environment.

Sector Intelligence

Government & Defence: Supply Chain in the Crosshairs

The most critical update today involves IKAD Engineering, a key contractor for the Hunter Class frigate and Collins Class submarine programs. The J Group ransomware gang has claimed responsibility for a breach, alleging they maintained undetected access for five months—a "staycation in the defence supply chain"—before exfiltrating 800GB of data. While IKAD states no classified data was lost, this highlights a severe visibility gap in third-party risk management.

Simultaneously, the Australian Government has imposed sanctions on Media Land LLC and ML.Cloud, along with key individuals Aleksandr Volosovik and Kirill Zatolokin. These entities are accused of providing the backend infrastructure for ransomware groups like Qilin and Medusa, which have relentlessly targeted Australian schools and hospitals this year.

  • Threat Actor Watch: Volt Typhoon (China-nexus) continues to probe Australian critical infrastructure, specifically telecommunications and energy grids, likely for pre-positioning rather than immediate disruption.

SaaS & Cloud Providers: The Fortinet Crisis

SaaS providers and enterprises using Fortinet FortiWeb WAFs must act immediately. A critical vulnerability (CVE-2025-64446) is being actively exploited in the wild. This path traversal flaw allows unauthenticated attackers to create administrative accounts via the API, effectively handing over full control of the device.

  • Impact: Full device compromise, potential lateral movement into cloud environments.
  • Status: CISA has mandated US federal agencies patch this by today, 21 November 2025. Australian organisations should follow suit immediately.

Healthcare: Relentless Ransomware

Healthcare remains the most targeted sector in 2025, accounting for 17% of all significant cyber incidents. The sanctions against Russian hosting firms are a direct response to attacks on this sector, but operational risks remain high. Hospitals are advised to review their exposure to the Citrix NetScaler zero-day (CVE-2025-5777), which is currently being used to deploy ransomware payloads.

FinTech & DeFi: Smart Contract Failures

The decentralised finance (DeFi) sector has seen over $3.1 billion in losses this year. In the last 24 hours, analysis has surfaced regarding the Abracadabra protocol hack ($1.8m loss), caused by a state management flaw in a smart contract. For Australian FinTechs, this reinforces the need for rigorous code audits and formal verification before deployment, especially as high-speed chains like Solana gain traction.

IoT & Mobile: Commercial Spyware

A sophisticated spyware campaign dubbed "LANDFALL" has been uncovered targeting Samsung Galaxy devices. It exploits a zero-day in the image-processing library (CVE-2025-21042). The malware is delivered via malicious DNG files on WhatsApp, affecting high-profile targets in the corporate and government sectors.


Vulnerability Watch: Critical Exploits

We are tracking the following vulnerabilities actively exploited in the Australian wild:

  1. Fortinet FortiWeb (CVE-2025-64446)

    • Type: Path Traversal / Auth Bypass.
    • Severity: Critical (CVSS 9.8).
    • Action: Update to version 8.0.2+ immediately. If patching is impossible, disable the management interface on public-facing IPs.
  2. Windows Kernel (CVE-2025-62215)

    • Type: Privilege Escalation.
    • Severity: High.
    • Context: Actively used by attackers to gain SYSTEM privileges after initial foothold (often via phishing).
  3. Fortinet FortiWeb (CVE-2025-58034)

    • Type: OS Command Injection.
    • Severity: Critical.
    • Context: Often chained with the auth bypass above to execute arbitrary code.

Pen Tester’s Perspective: The Rise of "Agentic" Threats

By Lean Security

The breach of IKAD Engineering is a textbook example of why perimeter defences are insufficient. The attackers didn't just smash and grab; they dwelt. They understood the network better than the administrators.

Furthermore, we are seeing a shift towards Agentic AI in offensive operations. Automated agents are now capable of chaining vulnerabilities (like the Fortinet auth bypass followed by command injection) at machine speed, drastically reducing the "time-to-compromise."

Recommendation: Organisations must move beyond annual compliance checks.

  1. Simulate the Supply Chain Breach: Don't just test your perimeter; test your reaction when a trusted vendor is compromised.
  2. API Security: The Fortinet exploit targeted an API endpoint. Ensure your API security testing covers logic flaws and authorisation bypasses, not just standard injections.
  3. Hunt for Persistence: If you run FortiWeb, assume compromise. Check logs for new, unrecognised admin accounts created in the last 30 days.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Australia Cyber Threat Update: Bulletproof Hosting Crackdown & Critical Fortinet/Cisco Exploits

Australia faces a crackdown on bulletproof hosting and active exploitation of critical Fortinet & Cisco vulnerabilities. Learn to protect your organization from these urgent cyber threats.

Executive Summary

The Australian cyber threat landscape for the last 24 hours has been dominated by a coordinated international response to resilient cybercrime infrastructure and the escalation of attacks against edge devices. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), in conjunction with global partners (CISA, FBI, NCSC-UK), released pivotal guidance yesterday targeting "Bulletproof Hosting" providers. Meanwhile, critical vulnerabilities in Fortinet and Cisco appliances are seeing active exploitation, posing severe risks to Australian organisations relying on these perimeter defence technologies.


Top Strategic Development: Crackdown on Bulletproof Hosting

Sectors Impacted: Government, FinTech, Critical Infrastructure

In a major release on 19 November 2025, the ACSC joined international agencies to publish "Bulletproof Defense: Mitigating Risks From Bulletproof Hosting Providers." Bulletproof hosting (BPH) services are the backbone of the cybercrime economy, allowing ransomware gangs and phishing operators to host malicious content with impunity.

  • The Threat: BPH providers knowingly ignore abuse complaints and facilitate high-volume phishing campaigns and C2 (Command and Control) infrastructure.
  • Action Required: Australian network defenders and ISPs are urged to review the new guidance to identify and block traffic to and from known BPH IP ranges. This is a critical step for Government and FinTech sectors to reduce the attack surface for ransomware and fraud.

Critical Vulnerabilities Under Active Exploitation

Organisations using web application firewalls (WAFs) and secure gateways must urgently review the following exploits highlighted in the last 24 hours:

1. Fortinet FortiWeb – Critical Authentication Bypass

  • CVE: CVE-2025-64446 (CVSS 9.1)
  • Status: Active Exploitation Confirmed (Added to CISA KEV on 14 Nov 2025, widely targeted in the last 24 hours).
  • Impact: This critical vulnerability allows unauthenticated remote attackers to bypass authentication and gain administrative control over FortiWeb appliances.
  • Relevance: High risk for SaaS providers and eCommerce platforms using FortiWeb to protect customer data.
  • Recommendation: Patch immediately. If patching is not possible, restrict management interface access to trusted internal IPs only.

2. Cisco ASA & FTD – State-Sponsored Targeting

  • CVEs: CVE-2025-20333 (CVSS 9.9) and CVE-2025-20362
  • Threat Actor: Linked to UAT4356/Storm-1849 (State-sponsored activity).
  • Context: Despite patches being available, telemetry indicates approximately 48,000 appliances globally remain unpatched. Threat actors are chaining these vulnerabilities to establish persistent footholds in corporate networks.
  • Sector Risk: Government and Education networks are frequent targets for this type of espionage-focused campaign.

3. WatchGuard Firebox & IoT Risks

  • Observation: Security researchers have identified over 54,000 exposed WatchGuard Firebox devices as of mid-November 2025.
  • IoT Threat: A new botnet is aggressively recruiting end-of-life GeoVision devices.
  • Takeaway: IoT and edge security remains a weak point. Organisations with distributed branches (e.g., Healthcare clinics, retail chains) must audit their perimeter footprint for unmanaged or end-of-life devices.

Sector-Specific Threat Intelligence

  • Healthcare: Following the trend of high-impact ransomware attacks (such as the MediSecure incident earlier in the decade), the sector remains a priority target. The new BPH guidance is crucial here—blocking BPH infrastructure can prevent the initial callback of ransomware payloads often used against hospitals.
  • Education (EdTech): With the academic year wrapping up, schools and universities are facing increased phishing attempts disguised as administrative notices. The exploitation of Cisco VPN vulnerabilities is a specific vector being used to penetrate university research networks.
  • FinTech: A new alert from the ACSC (13 Nov 2025) regarding scammers impersonating police to steal cryptocurrency remains highly relevant. FinTech platforms should warn users about this social engineering tactic, which often involves "urgent" requests to move funds to "safe" wallets.

Penetration Tester’s Perspective

From an offensive security standpoint, the current environment is volatile. Attackers are moving faster than defenders can patch. The FortiWeb bypass (CVE-2025-64446) is particularly dangerous because it compromises the very device meant to secure your web applications.

During our recent engagements, we have observed that API security remains a blind spot. With the rise of AI-driven attacks, automated scripts are now capable of probing APIs for logic flaws much faster than human analysts. Ensure your APIs are not just behind a WAF, but also rigorously tested for Broken Object Level Authorisation (BOLA) and other logic vulnerabilities.


Contact us for a quote for penetration testing service or adversary simulation.

Read More