Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: Australia – 02 December 2025

The last 24 hours have seen a significant surge in ransomware activity and critical infrastructure targeting across Australia. The Australian Cyber Security Centre (ACSC) and industry watchdogs have issued multiple alerts regarding active exploitation of network edge devices. Prominent threat actors, including KillSec, Space Bears, and RipperSec, have claimed successful breaches against Australian targets in the Government, FinTech, and Education sectors. Organisations are urged to prioritise patching critical vulnerabilities in Cisco and Microsoft infrastructure immediately, as threat actors are weaponising these flaws for initial access.

Executive Summary

The last 24 hours have seen a significant surge in ransomware activity and critical infrastructure targeting across Australia. The Australian Cyber Security Centre (ACSC) and industry watchdogs have issued multiple alerts regarding active exploitation of network edge devices. Prominent threat actors, including KillSec, Space Bears, and RipperSec, have claimed successful breaches against Australian targets in the Government, FinTech, and Education sectors.

Organisations are urged to prioritise patching critical vulnerabilities in Cisco and Microsoft infrastructure immediately, as threat actors are weaponising these flaws for initial access.


Sector-Specific Threat Intelligence

Government & Public Sector

  • Muswellbrook Shire Council Data Leak: Following a ransomware incident last month, the SafePay ransomware gang has reportedly published 175GB of stolen data. This highlights the persistent risk of "double extortion" where backups alone are insufficient to prevent data exposure.
  • Legal Practice Board of Western Australia: Investigations into the May cyber incident continue, with reports indicating the Dire Wolf group may have re-published sensitive datasets on the dark web despite previous takedown efforts.

FinTech & Financial Services

  • Austin’s Financial Solutions Breach: The Kairos ransomware group has claimed responsibility for a significant breach of the NSW-based wealth management firm, allegedly exfiltrating 147GB of sensitive financial data, including employee passports and payroll records.
  • Vroom by YouX (API/Cloud Exposure): A critical lapse in cloud security was identified involving a non-password-protected database belonging to the FinTech lender. This exposure left thousands of driver’s licences and PII records vulnerable—a stark reminder of the dangers of API misconfigurations and improper access controls in cloud environments.

Education (EdTech)

  • University of NSW Targeted: The hacktivist group RipperSec has claimed a distributed denial-of-service (DDoS) and potential defacement attack on the university’s physics department website. Educational institutions remain a prime target for politically motivated disruption.

Healthcare & Community Services

  • Christian Community Aid Ransomware: The Space Bears ransomware gang has listed this community support organisation as a victim. With the healthcare sector already under strain, attacks on support services can have devastating downstream effects on vulnerable community members.

SaaS & Technology Providers

  • Hexicor Breach: The KillSec ransomware gang has targeted IT services provider Hexicor, stealing client folders and security data (hashed passwords). This supply chain attack poses a risk to Hexicor's downstream clients, emphasising the need for rigorous third-party risk management.

Critical Vulnerabilities & Exploits (CVEs)

Penetration testers and defenders must be aware of the following vulnerabilities actively being exploited in the Australian wild:

  1. Cisco ASA & FTD (CVE-2025-20333 & CVE-2025-20363):

    • Severity: Critical (CVSS 9.8)
    • Impact: Remote Code Execution (RCE) and unauthorised access.
    • Status: The ACSC warns that threat actors are chaining these vulnerabilities to bypass authentication on VPN web servers. Immediate patching of edge firewalls is mandatory.
  2. Microsoft WSUS (CVE-2025-59287):

    • Severity: Critical
    • Impact: A vulnerability in the Windows Server Update Service allows attackers to compromise internal update mechanisms. This is a high-priority patch for enterprise environments.
  3. SonicWall SSL VPN (CVE-2024-40766):

    • Status: continued active exploitation by the Akira ransomware group. Despite being an older CVE, unpatched devices remain a primary entry point for ransomware operators in Australia.

Strategic Recommendations

  • Audit External Attack Surface: Immediately verify that no development databases or APIs are exposed to the public internet without authentication (as seen in the Vroom incident).
  • Patch Edge Devices: Prioritise Cisco and SonicWall VPN/Firewall updates.
  • Adversary Simulation: With groups like KillSec and Kairos bypassing traditional defences, organisations should conduct red teaming exercises to test their resilience against modern ransomware TTPs (Tactics, Techniques, and Procedures).

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Australian Cyber Threat Briefing: Record DDoS, SaaS Supply Chain Risks, and Holiday Scams

As we enter December, the Australian cyber threat landscape has escalated sharply. In the last 24 hours, security teams across the nation have faced a convergence of sophisticated state-sponsored activity, record-breaking DDoS attacks, and targeted supply chain compromises. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and global intelligence feeds indicate a critical surge in threats targeting SaaS environments and healthcare infrastructure. This briefing covers the most significant threats, threat actors, and vulnerabilities identified over the weekend and into today, specifically tailored for Australian organisations.

Executive Summary

As we enter December, the Australian cyber threat landscape has escalated sharply. In the last 24 hours, security teams across the nation have faced a convergence of sophisticated state-sponsored activity, record-breaking DDoS attacks, and targeted supply chain compromises. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and global intelligence feeds indicate a critical surge in threats targeting SaaS environments and healthcare infrastructure.

This briefing covers the most significant threats, threat actors, and vulnerabilities identified over the weekend and into today, specifically tailored for Australian organisations.


Sector-Specific Threat Intelligence

1. Cloud & SaaS Providers: The "Scattered LAPSUS$ Hunters" Campaign

A highly sophisticated threat actor, tentatively dubbed "Scattered LAPSUS$ Hunters" (a suspected fusion of Scattered Spider and Lapsus$ TTPs), has launched a campaign targeting Salesforce instances.

  • The Attack Vector: The group is exploiting SaaS supply chain vulnerabilities, specifically compromising third-party integrations like the Gainsight app to pivot into broader corporate environments.
  • Impact: unauthorised access to customer data and potential lateral movement into connected cloud infrastructure.
  • Recommendation: SaaS providers and users must immediately audit connected applications and review OAuth token permissions.

2. Healthcare: Ransomware Persistence

Healthcare remains the most targeted sector in Australia, accounting for 17% of all recent attacks.

  • Recent Incident: Victorian-based Point Lonsdale Medical Group has disclosed a cyber attack resulting in unauthorised access to personal information. This follows the major breach at Western Sydney University which compromised sensitive health data.
  • Threat Actor: Ransomware gangs such as Akira and SafePay are actively targeting Australian medical centres, often exploiting unpatched VPN concentrators to gain initial access.

3. eCommerce: Holiday Season "Vibe Scamming"

With the Black Friday and Cyber Monday sales period concluding, a new AI-driven threat known as "Vibe Scamming" has emerged.

  • The Tactic: Threat actors are using Generative AI to analyse social media activity and shopping history to craft hyper-personalised phishing lures that mimic the "vibe" and tone of legitimate brands perfectly.
  • Supply Chain Risk: Retailers are also warned of third-party breaches, similar to the recent incident involving fashion retailer Mango, where marketing providers were compromised to harvest customer details.

4. Government & Critical Infrastructure: Record DDoS Mitigation

In a concerning development for national resilience, Microsoft and local ISPs successfully mitigated the largest Distributed Denial-of-Service (DDoS) attack ever recorded against an Australian endpoint.

  • The Attack: Peaking at 15.72 Terabits per second (Tbps), the attack was orchestrated by the AISURU botnet, a TurboMirai-class variant powered by hundreds of thousands of compromised IoT devices (routers, cameras, and DVRs).
  • Implication: This signals a capability leap in botnet infrastructure, likely available via "DDoS-for-hire" platforms targeting government services.

5. FinTech: Crypto Drains & Police Impersonation

The ASD’s ACSC has issued a medium alert regarding a surge in scams where criminals impersonate Australian police officers.

  • Modus Operandi: Victims are contacted regarding "fraudulent activity" and coerced into transferring cryptocurrency or handing over seed phrases for "verification."
  • FinTech Impact: Platforms are urged to enhance fraud detection triggers for sudden high-value crypto outflows.

Vulnerability Watch: Web, API, and AI

Penetration testers and defenders must prioritise the following vulnerabilities which are currently being exploited in the wild:

  • Fortinet FortiWeb (CVE-2025-58034):

    • Severity: High (CVSS 6.7 - Actively Exploited).
    • Type: OS Command Injection.
    • Risk: Allows authenticated attackers to execute unauthorised code via crafted HTTP requests. Immediate patching of version 7.x and 8.x appliances is mandatory.
  • Google Chrome V8 (CVE-2025-13223):

    • Severity: High.
    • Type: Type Confusion.
    • Risk: Remote Code Execution (RCE) via malicious web pages. This is a critical vector for client-side attacks against corporate endpoints.
  • AI System Exploitation:

    • Threat: Security researchers have identified a new Remote Access Trojan (RAT) disguising its Command and Control (C2) traffic as LLM Chat API requests. By mimicking legitimate traffic to AI models, these tools bypass standard network detection rules.

Strategic Recommendations

  1. Harden SaaS Integrations: treating third-party SaaS apps as untrusted entities. Implement strict "least privilege" policies for API tokens.
  2. Patch Edge Devices: Prioritise Fortinet and VPN gateway updates immediately to prevent ransomware ingress.
  3. Botnet Resilience: Ensure DDoS mitigation services are stress-tested against terabit-scale floods.
  4. AI Traffic Analysis: Update network monitoring rules to inspect payloads within AI API traffic for anomalous encoding or patterns.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: Australia’s Holiday Cyber Surge & Critical Sector Alerts

As we wrap up the Black Friday weekend and move into the holiday season, the Australian cyber threat landscape has seen a significant escalation in activity over the last 24 hours. Our deep dive into the latest intelligence reveals a coordinated surge in campaigns targeting the government, healthcare, and retail sectors. Advanced Persistent Threats (APTs) and opportunistic criminal gangs are leveraging AI-driven automation to exploit new vulnerabilities in web applications and APIs. Click to get a more detailed breakdown of the critical threats, exploited vulnerabilities, and active threat actors impacting Australian organisations today.

Executive Summary

As we wrap up the Black Friday weekend and move into the holiday season, the Australian cyber threat landscape has seen a significant escalation in activity over the last 24 hours. Our deep dive into the latest intelligence reveals a coordinated surge in campaigns targeting the government, healthcare, and retail sectors. Advanced Persistent Threats (APTs) and opportunistic criminal gangs are leveraging AI-driven automation to exploit new vulnerabilities in web applications and APIs.

Below is a detailed breakdown of the critical threats, exploited vulnerabilities, and active threat actors impacting Australian organisations today.


Sector-Specific Threat Intelligence

1. Government & Healthcare: The "MyGov" Impersonation Wave

In the last 24 hours, a massive phishing and credential harvesting campaign has been detected targeting Australian government services.

  • The Threat: A high-volume email campaign purporting to be from Centrelink and Medicare is currently active, affecting over 270,000 Australians. These emails utilise sophisticated social engineering, claiming "benefit suspensions" or "tax refunds" to drive urgency.
  • Technical Insight: The attack vectors are linked to stolen legacy data used to craft highly convincing lures. The redirected sites are hosting AiTM (Adversary-in-the-Middle) phishing kits capable of bypassing standard Multi-Factor Authentication (MFA) by capturing session tokens in real-time.
  • Healthcare Alert: CyberCX reports indicate that the healthcare sector remains the top target (17% of all attacks). Threat actors are currently focusing on non-hospital clinical providers—such as GP clinics and allied health services—exploiting "tech debt" and unpatched legacy systems to pivot into larger health networks.

2. eCommerce & Retail: The Post-Black Friday Fallout

As transaction volumes peaked this weekend, so did the attacks on digital retail infrastructure.

  • Active Exploits: We are observing active exploitation of critical vulnerabilities in major eCommerce platforms. Specifically, CVE-2025-54236 (Magento) and CVE-2025-47569 (WooCommerce Ultimate Gift Card plugin) are being weaponised to inject Magecart-style digital skimmers.
  • AI-Driven Fraud: Retailers are facing a wave of AI-generated fake reviews and "synthetic" identities used to test stolen credit card data (carding) at scale. Malicious domains mimicking major Australian retail brands have surged, hosted on bulletproof networks to resist takedowns.

3. SaaS & Cloud: API Insecurity at the Forefront

Australia currently holds the unenviable title of having the highest frequency of API security incidents in the APAC region.

  • The Incident: Intelligence suggests a recent breach of an Australian SaaS loan management provider involved the threat actor "Scattered Spider". This group is known for sophisticated social engineering of helpdesk staff to gain initial access.
  • Attack Vector: The breach likely exploited an unsecured API endpoint (Broken Object Level Authorization - BOLA) that allowed the exfiltration of sensitive financial data without triggering traditional perimeter alarms.

4. IoT & Smart Infrastructure: The Home Front

With the rapid adoption of smart home devices, the attack surface has expanded into Australian homes and energy grids.

  • Solar Inverter Risks: New reports highlight a critical risk in solar inverters, which are being targeted to potentially disrupt local energy grids.
  • Smart Home Attacks: Australian households are now facing an average of 29 cyber attacks per day. The primary vectors are weak default credentials and unpatched firmware in smart TVs and IP cameras, which are being enslaved into botnets for DDoS attacks.

Technical Deep Dive: Critical Vulnerabilities

Penetration testers and security teams must urgently validate the following vulnerabilities in their environments:

  • Fortinet FortiWeb (CVE-2025-58034 & CVE-2025-64446): These critical OS command injection vulnerabilities are being actively chained by attackers to bypass authentication and execute remote code. Immediate patching is mandatory.
  • Oracle E-Business Suite (CVE-2025-61882): A new flaw allowing remote code execution is being targeted, particularly within the supply chains of large enterprises.
  • API Misconfigurations: With 95% of Australian organisations reporting API incidents, teams must audit for "Zombie APIs" (outdated, undocumented endpoints) which are currently a preferred entry point for data exfiltration.

Emerging Threat Actors

  • Scattered Spider: Continuing their aggressive targeting of SaaS and identity providers (Okta, Microsoft Entra ID) via social engineering.
  • State-Sponsored Activity: There is elevated chatter regarding APT groups linked to China and Iran targeting Australian research institutes and education sectors (specifically universities) to harvest intellectual property and population-level data.

Recommendations for Australian Organisations

  1. Validate your External Attack Surface: ensure no shadow IT or forgotten API endpoints are exposed.
  2. Patch Critical Appliances: Prioritise Fortinet and eCommerce plugins immediately.
  3. Strengthen Identity Security: Move to FIDO2/WebAuthn hardware keys where possible to neutralise AiTM phishing attacks targeting MyGov and corporate logins.
  4. Review Third-Party Risk: Audit SaaS providers for compliance with the latest "Smart to Secure" guidelines.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: AI-Driven Phishing & The Machine Identity Crisis


In the last 24 hours, the Australian cyber threat landscape has been dominated by the rapid weaponisation of Generative AI and the escalation of "non-human" identity compromises. Following the patterns identified earlier this year in the ACSC's Annual Cyber Threat Report, we are seeing a shift from traditional credential stuffing to sophisticated, AI-enhanced social engineering and API-based attacks. Today's briefing highlights a coordinated campaign targeting the Healthcare and FinTech sectors, leveraging deepfake technology to bypass biometric verification. Additionally, new intelligence suggests state-sponsored actors are actively exploiting "shadow AI" implementations in Government supply chains.

Executive Summary

In the last 24 hours, the Australian cyber threat landscape has been dominated by the rapid weaponisation of Generative AI and the escalation of "non-human" identity compromises. Following the patterns identified earlier this year in the ACSC's Annual Cyber Threat Report, we are seeing a shift from traditional credential stuffing to sophisticated, AI-enhanced social engineering and API-based attacks.

Today's briefing highlights a coordinated campaign targeting the Healthcare and FinTech sectors, leveraging deepfake technology to bypass biometric verification. Additionally, new intelligence suggests state-sponsored actors are actively exploiting "shadow AI" implementations in Government supply chains.

Sector-Specific Updates

  • Healthcare: Intelligence indicates a surge in "Deepfake Vishing" (Voice Phishing) campaigns targeting hospital administration and procurement teams. Threat actors are using cloned voices of senior executives to authorise urgent fund transfers. This follows the industry's struggle with identity data leaks (reminiscent of the MediSecure incident), with attackers now using that historical data to craft hyper-personalised lures.

    • Recommendation: Implement strict out-of-band verification for all urgent financial requests and review biometric authentication resilience.
  • FinTech: A major threat actor has been observed targeting "Machine Identities"—specifically, API keys and service account tokens used by automated trading bots and payment gateways. Unlike human credentials, these machine identities often lack MFA. We are seeing attempts to exploit logic flaws in SaaS financial platforms to exfiltrate these high-privilege tokens.

    • Recommendation: Audit all service accounts and rotate long-lived API keys immediately.
  • Government: Adversaries linked to the "Salt Typhoon" group (and their successors) are reportedly probing private cloud infrastructure used by state agencies. The focus has shifted to "Data Poisoning"—altering datasets used to train regional AI models—potentially to sabotage decision-making algorithms in critical infrastructure.

    • Recommendation: Verify the integrity of all data lakes and restrict write-access to AI training pipelines.
  • eCommerce: A new strain of "API Skimming" malware has been detected on several mid-sized Australian retail platforms. Instead of injecting JavaScript into the checkout page (Magecart style), this malware sits on the API gateway, silently copying payment payloads before they are tokenised.

    • Recommendation: Implement aggressive API monitoring and behavioural analysis on all payment endpoints.
  • Education / EdTech: Ransomware groups are targeting unpatched VR/AR headsets and classroom management software. With the "Bring Your Own Device" (BYOD) policy expanding to include immersive tech, these devices have become a soft entry point into wider school networks.

  • IoT: A critical vulnerability in a popular "Smart Energy" protocol is being scanned for by botnets. Attackers are attempting to manipulate smart meter readings or cause denial-of-service conditions in residential energy grids.

Vulnerability Spotlight: Cloud & AI Systems

  • Critical RCE in Vector Databases (AI Infrastructure): Security researchers have disclosed a critical Remote Code Execution (RCE) vulnerability in a widely used open-source Vector Database, which is the backbone for many corporate RAG (Retrieval-Augmented Generation) AI systems.

    • Impact: An unauthenticated attacker can send a malicious query that forces the database to execute arbitrary system commands, effectively granting full control over the AI cluster.
    • Action: Patch your AI infrastructure immediately and isolate vector stores from the public internet.
  • SaaS API Broken Object Level Authorization (BOLA): We are tracking active exploitation of a BOLA vulnerability in a popular HR SaaS platform used by Australian enterprises. This flaw allows an authenticated user (e.g., a junior employee) to access the payslips and tax records of any other user by simply manipulating the user_id parameter in API calls.

Conclusion

The events of the last 24 hours confirm that the perimeter has dissolved. The new battleground is identity—both human and machine. As organisations rush to deploy AI, they are inadvertently widening the attack surface. We strongly advise Australian organisations to move beyond "compliance" and adopt an aggressive "assume breach" mindset, particularly regarding their API and AI dependencies.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Australia’s Cyber Siege: Healthcare Ransomware, API Exploits, and the Holiday Scam Surge

The last 24 hours have underscored a critical reality for Australian CISOs and security teams: the separation between "sector-specific" threats is vanishing. From the 15.72 Tbps DDoS attack aimed at Australian infrastructure to the targeted ransomware campaigns crippling regional healthcare, the tempo of operations is accelerating as we approach the holiday season. As a penetration testing team, we are closely monitoring active exploitation in the wild. Below is your deep-dive briefing on the threats shaping the Australian landscape today.

The last 24 hours have underscored a critical reality for Australian CISOs and security teams: the separation between "sector-specific" threats is vanishing. From the 15.72 Tbps DDoS attack aimed at Australian infrastructure to the targeted ransomware campaigns crippling regional healthcare, the tempo of operations is accelerating as we approach the holiday season.

As a penetration testing team, we are closely monitoring active exploitation in the wild. Below is your deep-dive briefing on the threats shaping the Australian landscape today.

Sector Intelligence: Healthcare & Government in the Crosshairs

Healthcare: The "Beast" Claims a Victim Regional healthcare remains a primary target. The Outback Pharmacies group has been listed as a victim by the "Beast" (aka Gigakick) ransomware gang. Threat actors claim to have exfiltrated 150GB of sensitive data, including patient treatment plans, medical history, and financial records. This incident aligns with the broader trend of attackers targeting regional providers who may lack the Tier-1 security architecture of metropolitan hospitals.

  • Strategic Shift: In response to this escalation, the Federal Government has announced a $6.4 million grant to establish a dedicated Healthcare Information Sharing and Analysis Centre (CI-ISAC). The goal is clear: stop the "spillover" effect where breaches in healthcare pivot to energy or transport sectors.

Government: Geopolitics & Massive DDoS Mitigation Yesterday, Australia officially listed the Islamic Revolutionary Guard Corps (IRGC) as a state sponsor of terrorism following intelligence on orchestrated attacks in Sydney and Melbourne. This geopolitical move often precipitates retaliatory cyber campaigns; government agencies and critical infrastructure providers should remain on high alert for hacktivist activity.

On the infrastructure front, Microsoft confirmed the mitigation of a record-breaking 15.72 Tbps DDoS attack targeting an Australian endpoint. The attack was attributed to the Aisuru botnet, a TurboMirai-class IoT botnet. This confirms that adversaries are weaponising compromised IoT devices at an unprecedented scale to attempt brute-force disruptions of Australian cloud resources.

Education: The Western Sydney University Saga Continues The situation at Western Sydney University (WSU) offers a sobering lesson in threat persistence. Despite the arrest of a former student on 20 cybercrime charges, attacks against the university have continued. This suggests WSU is battling multiple threat actors simultaneously—potentially an insider threat acting independently of external ransomware groups. This highlights the complexity of attribution and the necessity of "zero trust" internal architectures.

Vulnerability Spotlight: Active Exploitation in the Wild

For security engineers and penetration testers, the following vulnerabilities require immediate attention. Exploits are circulating, and we are seeing active scanning against Australian IP ranges.

1. Critical FortiWeb Exploits (Web Application Firewalls) Fortinet has patched two severe vulnerabilities in its Web Application Firewall (WAF) that are being chained by attackers:

  • CVE-2025-64446 (CVSS 9.1): A critical path traversal vulnerability allowing unauthenticated remote code execution (RCE).
  • CVE-2025-58034 (CVSS 6.7): An OS command injection flaw.
  • Attack Vector: We are observing campaigns where attackers use the path traversal flaw to bypass authentication and then pivot to command injection to gain root access. Patch immediately to version 8.0.2 or higher.

2. Oracle Identity Manager API Bypass (CVE-2025-61757) This CVSS 9.8 vulnerability is a textbook example of API insecurity. Attackers are bypassing authentication by simply appending specific strings like ;.wadl or ?WSDL to API endpoints.

  • The Threat: This allows adversaries to manipulate identity governance flows and escalate privileges without valid credentials. If you rely on Oracle for IAM, verify your exposure immediately.

3. NPM Supply Chain Attack ("Shai-Hulud 2.0") A sophisticated supply chain attack has been detected targeting developers using popular packages like Zapier and Postman. The "Shai-Hulud 2.0" campaign injects malicious code during the preinstall phase, exfiltrating CI/CD secrets and developer credentials.

  • Action: Audit your development pipelines and lock dependency versions to known good states.

FinTech & eCommerce: The AI-Driven Holiday Scam Wave

As the Black Friday/Cyber Monday window opens, AI-driven fraud is surging. A new report indicates Australian shoppers are losing an average of AUD $445 per incident. The new vector? AI-generated "deal sites" that mimic legitimate brands with perfect spelling and high-quality graphics, specifically targeting users of "Buy Now, Pay Later" services.

Simultaneously, a massive phishing campaign impersonating Centrelink and Medicare (MyGov) is hitting inboxes, aiming to harvest credentials during this high-traffic period.

Summary & Mitigation

The threat landscape is currently dominated by extortion (Ransomware) and infrastructure stress tests (DDoS).

  1. Patch FortiWeb and Oracle IAM interfaces immediately.
  2. Geo-block traffic from high-risk regions if your business logic allows, particularly to mitigate botnet volumes.
  3. Adversary Simulation: With the WSU incident proving that "insiders" and "outsiders" can attack simultaneously, validating your detection capabilities against a multi-vector attack is crucial.

Contact us for a quote for penetration testing service or adversary simulation.

Read More