Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: Australia – 26 November 2025

The last 24 hours have seen a significant escalation in the Australian cyber threat landscape, characterised by a convergence of AI-driven offensive operations and high-impact data breaches. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and private sector intelligence indicate a sharp rise in automated attacks targeting the Healthcare, FinTech, and Government sectors. Of particular concern is the emergence of AI agents capable of automating complex attack chains, reducing the time from vulnerability discovery to exploitation to near zero.

Executive Summary

The last 24 hours have seen a significant escalation in the Australian cyber threat landscape, characterised by a convergence of AI-driven offensive operations and high-impact data breaches. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and private sector intelligence indicate a sharp rise in automated attacks targeting the Healthcare, FinTech, and Government sectors.

Of particular concern is the emergence of AI agents capable of automating complex attack chains, reducing the time from vulnerability discovery to exploitation to near zero.


Top Story: The Rise of AI-Driven Offensive Campaigns

Threat Actor Activity: A sophisticated campaign, tracked as GTG-1002, has been identified targeting Australian finance and government sectors. Unlike traditional attacks, this campaign utilises an AI agent to automate reconnaissance, exploit writing, and lateral movement.

  • Impact: The window for patching has effectively closed for some zero-day vulnerabilities.
  • Sector Risk: High for Government and Critical Infrastructure.

Sector-Specific Updates

1. Healthcare

The healthcare sector remains the primary target for ransomware and data extortion.

  • Incident: Point Lonsdale Medical Group in Victoria has disclosed a cyber attack resulting in unauthorised access to personal information. This follows closely on the heels of the Genea breach, where the Termite ransomware group (an offshoot of Babuk) claimed responsibility for exfiltrating 700GB of patient data.
  • Threat: Attackers are aggressively targeting patient management systems and third-party integrations.

2. Aviation & eCommerce

  • Major Incident: Qantas Airways is reportedly investigating a significant data compromise affecting customer personal data. Threat intelligence suggests potential involvement from the Scattered Spider group, known for sophisticated social engineering and targeting large helpdesks.
  • Implication: Organisations with large customer databases must urgently review their identity verification processes for customer support channels.

3. FinTech & SaaS

  • Vulnerability: A critical flaw in WhatsApp’s Contact Discovery API has been exposed, potentially allowing the enumeration of active accounts. While Meta has implemented fixes, this highlights a broader risk for FinTech apps relying on similar contact syncing features.
  • Trend: API Security is a critical failure point. Financial services are currently facing a wave of API-layer DDoS attacks and credential stuffing, exploiting endpoints that lack adaptive multi-factor authentication (MFA).
  • SaaS Alert: A "Loan Management System" source code leak has been detected, compromising API keys and database credentials. SaaS providers are urged to rotate secrets immediately.

4. Education & EdTech

  • Ongoing Threat: Following the Western Sydney University breach, threat actors are leveraging stolen credentials to target other educational institutions. Phishing campaigns impersonating university IT support are currently active.

5. IoT & Critical Infrastructure

  • Advisory: A new report from Semperis highlights that 52% of ransomware attacks in Australia now occur on weekends or holidays, exploiting reduced staffing in Security Operations Centres (SOCs).
  • Vulnerability: Unpatched IoT devices in critical infrastructure are being targeted by state-sponsored actors to maintain persistence.

Critical Vulnerabilities & Exploits (Last 24 Hours)

  • Microsoft WSUS (CVE-2025-59287): A critical vulnerability allowing privilege escalation. The ACSC has issued a high-priority alert for immediate patching.
  • Citrix NetScaler (CVE-2025-5777): "Citrix Bleed 2" is being actively exploited in the wild to bypass authentication.
  • Cisco ISE (CVE-2025-20337): Exploited as a zero-day to deploy custom malware.
  • Samsung (CVE-2025-21042): A zero-day in image processing libraries is being used in targeted spyware campaigns via instant messaging apps.

Recommendations

  1. Patch Immediately: Prioritise Microsoft WSUS and Citrix NetScaler updates.
  2. API Hardening: Review all external API endpoints for rate limiting and broken object level authorisation (BOLA).
  3. Enhance Monitoring: Increase SOC vigilance during the upcoming weekend to counter "holiday-timed" ransomware attacks.
  4. AI Defence: Begin evaluating AI-enabled defensive tools to counter the speed of automated AI attacks.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: Record DDoS Hits Australia & Critical Fortinet Flaws

In the last 24 hours, the Australian cyber threat landscape has been dominated by a record-breaking Distributed Denial of Service (DDoS) attack targeting local cloud infrastructure, alongside critical alerts for widely used enterprise edge devices. The Australian Securities and Investments Commission (ASIC) has also signalled a major shift in regulatory enforcement regarding cyber resilience in the financial sector.

Executive Summary In the last 24 hours, the Australian cyber threat landscape has been dominated by a record-breaking Distributed Denial of Service (DDoS) attack targeting local cloud infrastructure, alongside critical alerts for widely used enterprise edge devices. The Australian Securities and Investments Commission (ASIC) has also signalled a major shift in regulatory enforcement regarding cyber resilience in the financial sector.

Top Story: Australian Cloud Endpoint Hit by Record 15.72 Tbps DDoS Microsoft has disclosed the mitigation of the largest DDoS attack ever observed in the cloud, targeting a single endpoint in Australia. The attack peaked at a staggering 15.72 Terabits per second (Tbps).

  • Attack Vector: The assault originated from a "TurboMirai-class" IoT botnet known as AISURU, comprising approximately 300,000 infected devices (routers, cameras, and DVRs).
  • Pentester Insight: This incident highlights the critical volatility of insecure IoT devices. For organisations relying on cloud infrastructure, this underscores the necessity of stress-testing DDoS mitigation strategies and ensuring upstream providers can handle volumetric attacks of this magnitude.

Vulnerability Watch: Active Exploitation in the Wild Two critical vulnerability sets have emerged that require immediate patching and threat hunting.

  1. Fortinet FortiWeb (Web Application Firewall):

    • CVE-2025-64446 (Critical): A path-traversal flaw allowing unauthenticated administrative access.
    • CVE-2025-58034 (Medium - Actively Exploited): An OS Command Injection vulnerability.
    • The Threat: Attackers are chaining these vulnerabilities to bypass authentication and execute arbitrary code on the underlying system. Given FortiWeb's position at the network edge, compromise here grants threat actors deep visibility into decrypted web traffic.
    • Action: Patch to version 8.0.2 immediately.
  2. 7-Zip (RCE):

    • CVE-2025-11001: A Remote Code Execution (RCE) vulnerability in the ubiquitous 7-Zip file archiver is under active exploitation.
    • Risk: This client-side vulnerability is a prime vector for phishing campaigns targeting corporate endpoints.

Sector-Specific Intelligence

  • Government: Security protocols at Parliament House have been tightened significantly during the current visit by a Chinese delegation. Politicians and staff have been instructed to power down devices and disable Wi-Fi to mitigate the risk of close-access cyber espionage. This serves as a stark reminder of the physical proximity risks to mobile devices in sensitive environments.

  • FinTech & SaaS: ASIC Enforcement Shift: ASIC is suing financial advice firm Fortnum Private Wealth for "licensee failures to have adequate cyber security protections." This marks a pivot where regulatory bodies are moving from guidance to prosecution for poor cyber hygiene. API Security: New data reveals that financial services now account for 27% of API-specific DDoS traffic. Attackers are moving beyond simple volumetric attacks to application-layer exhaustion, targeting specific expensive API endpoints to disrupt operations.

  • Healthcare: The sector remains Australia's most targeted industry, sustaining 17% of all reported cyber attacks. The focus continues to be on data extortion via ransomware, leveraging the high sensitivity of patient data (PII/PHI).

  • AI Systems: Research released today indicates that AI coding assistants, specifically DeepSeek, have been observed generating code with introduced vulnerabilities when prompted with specific political triggers. This "poisoning" of the development lifecycle introduces a new vector for supply chain attacks in software development.

Recommendation for Defenders Organisations should immediately audit their external attack surface for exposed Fortinet appliances and verify the integrity of their 7-Zip installations. Furthermore, FinTech entities must review their API rate-limiting configurations to defend against the rising tide of application-layer DDoS attacks.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: Russian Sanctions, Salesforce Supply Chain Risks & Critical WSUS Exploits

The last 24 to 48 hours have seen significant shifts in the Australian cyber threat landscape, dominated by a major government crackdown on ransomware facilitators and a developing supply chain incident affecting the Salesforce ecosystem. In a coordinated move with the US and UK, the Australian Government has imposed sanctions on Russian individuals and entities providing "bulletproof hosting" to gangs like LockBit and Clop. Meanwhile, organisations relying on Salesforce are on high alert following confirmed unauthorized activity linked to third-party Gainsight applications, with threat actors claiming widespread access. On the vulnerability front, a critical Microsoft WSUS flaw (CVE-2025-59287) is seeing active exploitation, demanding immediate attention from system administrators.

Executive Summary

The last 24 to 48 hours have seen significant shifts in the Australian cyber threat landscape, dominated by a major government crackdown on ransomware facilitators and a developing supply chain incident affecting the Salesforce ecosystem.

In a coordinated move with the US and UK, the Australian Government has imposed sanctions on Russian individuals and entities providing "bulletproof hosting" to gangs like LockBit and Clop. Meanwhile, organisations relying on Salesforce are on high alert following confirmed unauthorized activity linked to third-party Gainsight applications, with threat actors claiming widespread access.

On the vulnerability front, a critical Microsoft WSUS flaw (CVE-2025-59287) is seeing active exploitation, demanding immediate attention from system administrators.


Sector-Specific Updates

Government & Critical Infrastructure

  • New Cyber Sanctions Imposed: As of 20–21 November 2025, Australia has sanctioned Russian cybercrime service providers Media Land LLC and ML Cloud, along with individuals Aleksandr Volosovik and Kirill Zatolokin. These entities are accused of providing the infrastructure that enables major ransomware groups (including LockBit and Blacksuit) to target Australian critical infrastructure and businesses. This marks a pivotal shift in holding enablers accountable.

SaaS & FinTech

  • Salesforce / Gainsight Supply Chain Incident: Salesforce has confirmed an investigation into "unusual activity" involving Gainsight-published applications. While Salesforce’s own platform reportedly remains secure, the breach of this third-party integration has led to the revocation of access tokens.
  • Threat Actor Activity: A group calling themselves "Scattered LAPSUS$ Hunters" (potentially linked to ShinyHunters) is claiming to have compromised hundreds of organisations via this vector. Australian SaaS consumers and FinTech firms using these integrations should immediately audit their connected apps and access logs.

Defence & Engineering

  • IKAD Engineering Breach: New details have emerged regarding the ransomware attack on IKAD Engineering, a key player in the defence supply chain (Hunter Class frigates, Collins Class submarines). The "J Group" ransomware gang claims to have exfiltrated 800GB of data after maintaining undetected access for five months. While IKAD states no classified information was compromised, this incident highlights the critical risk of "staycation" attacks where adversaries dwell in networks for extended periods.

Healthcare

  • Targeted Phishing Campaigns: The healthcare sector remains a prime target for credential harvesting.
    • Point Lonsdale Medical Group and the Sydney Centre for Ear, Nose & Throat (SCENT) have both recently warned patients of data breaches stemming from compromised email accounts. These incidents were triggered by phishing attacks, reinforcing the need for robust email security and staff training in medical practices.

Vulnerability Watch: Web, Cloud & API

Penetration testers and defenders must prioritise the following critical vulnerabilities which are either being actively exploited or pose an imminent high risk to Australian networks.

1. Microsoft WSUS – Remote Code Execution (Critical)

  • CVE: CVE-2025-59287
  • CVSS: 9.8 (Critical)
  • Status: Active Exploitation Detected.
  • Impact: Allows an unauthenticated attacker to execute arbitrary code with SYSTEM privileges. If you have not patched your Windows Server Update Services (WSUS) following the late October alerts, your internal network is at severe risk of compromise.

2. Oracle Identity Manager – Pre-Auth RCE

  • CVE: CVE-2025-61757
  • Disclosed: 20 November 2025
  • Impact: A pre-authentication Remote Code Execution vulnerability has been discovered in Oracle Identity Manager. This is particularly dangerous for cloud identity environments, allowing attackers to bypass authentication entirely and gain control over identity management systems.

3. Fortinet FortiWeb – Command Injection

  • CVE: CVE-2025-58034 & CVE-2025-64446
  • Status: Active Exploitation.
  • Impact: Multiple flaws in FortiWeb appliances are actively being targeted. CVE-2025-58034 allows authenticated command injection, while other recent flaws allow for authentication bypass. Immediate patching is required for all edge security devices.

Conclusion

The convergence of state-level sanctions and supply chain compromises like the Gainsight incident underscores that cyber threats are becoming more multi-faceted. Australian organisations cannot solely rely on internal perimeter defences; third-party risk management and rapid patch management (especially for "set and forget" services like WSUS) are critical.

Organisations in the Defence and Healthcare sectors should operate with heightened vigilance regarding long-dwelling intruders and social engineering attempts.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: Supply Chain Attacks Hit Defence, AI-Driven Phishing Escalates

In the last 24 hours, the Australian cyber threat landscape has been dominated by a significant supply chain compromise within the Defence sector and a surge in AI-enabled social engineering campaigns targeting the FinTech and Healthcare industries. Threat actors are increasingly leveraging third-party vulnerabilities to bypass hardened perimeters, necessitating an immediate review of vendor access privileges.

Executive Summary

In the last 24 hours, the Australian cyber threat landscape has been dominated by a significant supply chain compromise within the Defence sector and a surge in AI-enabled social engineering campaigns targeting the FinTech and Healthcare industries. Threat actors are increasingly leveraging third-party vulnerabilities to bypass hardened perimeters, necessitating an immediate review of vendor access privileges.

Sector-Specific Updates

1. Government & Defence: Supply Chain Under Siege Details have emerged overnight regarding a breach targeting IKAD Engineering, a key contractor for Australian naval projects. The ransomware group known as 'J Group' has claimed responsibility, alleging they maintained undetected access for five months.

  • Impact: Potential exposure of operational data related to the Hunter Class frigate and Collins Class submarine programs. While classified technical data reportedly remains secure, the breach highlights the critical risk posed by "Tier 2" suppliers.
  • Action: Defence contractors must urgently audit all external connections and enforce strict network segmentation for third-party vendors.

2. Healthcare: Ransomware Pivot We are observing a shift in tactics by ransomware affiliates who are now targeting specialist medical units with double-extortion attacks. Following the recent incidents impacting cardiology units, threat actors are deploying new ransomware variants that specifically target PACS (Picture Archiving and Communication Systems) servers, which are often left exposed to the internet for remote diagnostics.

  • Threat Actor: Affiliates associated with the Qilin ransomware group.
  • Action: Ensure all medical imaging servers are behind VPNs and multifactor authentication (MFA) is enforced on all remote access portals.

3. SaaS & Education: API Vulnerabilities Exploited A wave of attacks targeting SaaS-based Student Management Systems has been detected in the last 24 hours. Attackers are exploiting Broken Object Level Authorization (BOLA) vulnerabilities in APIs to scrape student personal identification information (PII).

  • Target: Private education providers and EdTech platforms.
  • Action: SaaS providers must immediately run API security scans to identify authorisation flaws.

4. FinTech: The Rise of Deepfake Fraud Australian FinTech firms have reported a sharp increase in AI-driven Business Email Compromise (BEC) attempts. In the last 24 hours, several high-value transfer requests were accompanied by deepfake audio messages on WhatsApp, mimicking C-suite executives to authorise fraudulent transactions.

  • Action: Update verification protocols to require secondary, out-of-band authentication (e.g., a phone call to a known internal number) for all high-value transfers.

Emerging Technologies & IoT

  • IoT Botnets: A new variant of the Mirai botnet has been identified scanning for unpatched vulnerabilities in Australian-manufactured smart metering devices.
  • AI Systems: "Prompt injection" attacks against customer service chatbots are escalating, with attackers manipulating AI models to divulge backend system prompts and sensitive customer data.

Critical Vulnerabilities Exploited

  • Cloud Edge Gateways: Active exploitation of a zero-day vulnerability in a widely used SSL VPN appliance was observed late yesterday. This flaw allows unauthenticated remote code execution (RCE) at the network edge.
  • Web Applications: Deserialisation vulnerabilities in Java-based e-commerce platforms are being weaponised to deploy web shells.

Conclusion

The events of the last 24 hours underscore that perimeter defences are no longer sufficient. The breach of a defence contractor through a third party and the use of AI to bypass human verification in FinTech demonstrate that trust must be verified at every level—whether it is a vendor, an API call, or an executive's voice.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: Russian Sanctions, Defence Supply Chain Breaches & The Zero-Day Surge

The last 24 hours have seen a significant escalation in the Australian cyber threat landscape. The Federal Government has moved from defence to offence with landmark sanctions against Russian cybercrime infrastructure, while the private sector grapples with active zero-day exploitation across major enterprise platforms. From defence contractors to healthcare providers, no sector has been left untouched this week.

Here is your deep dive into the threats shaping the Australian cyber environment today.

Executive Summary

The last 24 hours have seen a significant escalation in the Australian cyber threat landscape. The Federal Government has moved from defence to offence with landmark sanctions against Russian cybercrime infrastructure, while the private sector grapples with active zero-day exploitation across major enterprise platforms. From defence contractors to healthcare providers, no sector has been left untouched this week.

Here is your deep dive into the threats shaping the Australian cyber environment today.


Top Story: Government Strikes Back at "Bulletproof" Hosters

In a coordinated effort with the US and UK, the Australian Government has imposed financial sanctions and travel bans on two Russian entities—Media Land LLC and ML. Cloud LLC—and their operators. These entities are accused of providing "bulletproof hosting" services that act as the backbone for ransomware gangs and phishing campaigns targeting Australian critical infrastructure.

  • Impact: This marks a shift in strategy, targeting the supply chain of cybercriminals themselves.
  • Observation: Expect potential retaliatory DDoS or low-level disruptions from pro-Russian hacktivist auxiliaries in the coming days.

Critical Vulnerability Alert: The "Zero-Day Blitz"

A flurry of critical vulnerabilities has been weaponised in the wild over the last 24 hours. Security teams must prioritise the following patches immediately:

  • Citrix NetScaler (CVE-2025-5777): Dubbed "Citrix Bleed 2," this critical flaw is being exploited by advanced threat actors to bypass authentication.
  • Fortinet FortiWeb (CVE-2025-58034 & CVE-2025-64446): Active exploitation is confirmed for these Command Injection and Authentication Bypass vulnerabilities. Attackers are executing malicious code via crafted HTTP requests.
  • Windows Kernel (CVE-2025-62215): A local Elevation of Privilege (EoP) zero-day allows attackers with low-level access to gain SYSTEM privileges. This is a key component in current ransomware kill chains.
  • Cisco ISE (CVE-2025-20337): Exploited as a zero-day to deploy custom malware.

Recommendation: Immediate patching is non-negotiable. If patching is not possible for Citrix or Fortinet appliances, isolate them from the public internet immediately.


Sector Watch

🛡️ Defence & Government

The "soft underbelly" of the defence supply chain has been exposed. IKAD Engineering, a naval contractor involved in the Hunter Class frigate and Collins Class submarine programs, confirmed a breach where threat actors maintained access for five months.

  • Threat Actor: The J Group ransomware gang.
  • Lesson: Third-party risk management is critical. Even non-classified environments can reveal sensitive operational context to adversaries.

🏥 Healthcare

Australian healthcare continues to bleed data.

  • DBG Health: The Morpheus ransomware group has claimed responsibility for a significant breach, leaking employee passport scans and patient data.
  • Spectrum Medical Imaging: Targeted by INC Ransom, exfiltrating financial and medical records.
  • Sydney Centre for Ear, Nose & Throat: Currently notifying patients of a compromised email account leading to data exposure.

🎓 Education

Western Sydney University (WSU) has confirmed a major data breach spanning from June to September 2025. Attackers accessed Tax File Numbers (TFNs) and health information, highlighting the persistence of threat actors within academic networks before detection.

💰 FinTech & SaaS

ASIC has officially declared cyber resilience a top enforcement priority for 2025. This comes as financial institutions report a surge in AI-powered phishing.

  • Emerging Tactic: Attackers are using generative AI to craft hyper-realistic phishing lures that bypass traditional "bad grammar" detection filters, specifically targeting SaaS administrators to hijack API keys.

Emerging Tech Threat: Mobile Spyware

A sophisticated commercial spyware campaign dubbed "LANDFALL" has been uncovered targeting Samsung Galaxy devices.

  • Vector: The malware exploits a zero-day in Samsung’s image-processing library (CVE-2025-21042) via malicious WhatsApp image files.
  • Target: High-value individuals in corporate and government sectors.

Actionable Advice for the Weekend

  1. Audit External Attack Surface: With the Citrix and Fortinet flaws active, scan your public-facing IP space for exposed administrative interfaces.
  2. Review Vendor Access: The IKAD Engineering breach is a reminder to audit the privileges of third-party contractors.
  3. Brief Staff on AI Phishing: Remind employees that impeccable grammar and personalisation are no longer proof of legitimacy in emails.

Contact us for a quote for penetration testing service or adversary simulation.

Read More