Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Urgent: 'React2Shell' RCE Exploited by State Actors & New Healthcare Supply Chain Risks

The Australian cyber threat landscape has reached a critical juncture in the last 24 hours. The primary focus for all security teams today is the rapid weaponisation of the ‘React2Shell’ vulnerability (CVE-2025-55182), which is actively being exploited by Chinese state-sponsored actors and cybercriminal syndicates to compromise web applications across the SaaS, FinTech, and Government sectors. Simultaneously, the healthcare sector faces a renewed supply chain crisis following a breach at a major IT services provider.

Executive Summary

The Australian cyber threat landscape has reached a critical juncture in the last 24 hours. The primary focus for all security teams today is the rapid weaponisation of the ‘React2Shell’ vulnerability (CVE-2025-55182), which is actively being exploited by Chinese state-sponsored actors and cybercriminal syndicates to compromise web applications across the SaaS, FinTech, and Government sectors. Simultaneously, the healthcare sector faces a renewed supply chain crisis following a breach at a major IT services provider.

Here is your daily threat briefing for 13 December 2025.

Critical Vulnerability Alert: 'React2Shell' (CVE-2025-55182)

Sectors Impacted: SaaS, FinTech, Government, eCommerce

The Australian Cyber Security Centre (ACSC) has issued an "Act Now" alert regarding a critical Remote Code Execution (RCE) vulnerability in React Server Components, affecting versions 19.0 through 19.2.0.

  • The Threat: Dubbed "React2Shell," this flaw allows unauthenticated attackers to execute arbitrary code on the server by manipulating the deserialisation logic of the Flight protocol.
  • Current Activity: Intelligence indicates that multiple Advanced Persistent Threat (APT) groups, including those nexus to China, are operationalising this exploit to install web shells and exfiltrate sensitive customer data from Australian organisations.
  • Why It Matters: With over 500 Australian organisations estimated to be vulnerable, this represents a "perfect 10" severity risk. FinTech platforms and SaaS providers using Next.js (App Router) are particularly exposed.
  • Action: Patch immediately to the latest safe version. If patching is not feasible today, implement strict WAF rules to block malformed serialisation requests.

Sector Spotlight: Healthcare & Education

Threat Actor: KillSec Trend: Supply Chain Compromise & Extortion-Only Attacks

A significant supply chain attack has been identified targeting the Australian healthcare sector. Hexicor, a prominent IT services provider, has reportedly been compromised by the KillSec ransomware gang.

  • Impact: This breach has potentially exposed credentials and sensitive patient data for dozens of downstream healthcare and aged-care clients.
  • Tactical Shift: This incident aligns with a broader trend observed in the last 24 hours: a 40% rise in "extortion-only" attacks against Australian healthcare providers. Attackers are increasingly skipping the encryption phase to avoid automated detection, focusing instead on stealthy data theft to demand silence fees.
  • Education Sector: KillSec has also claimed responsibility for an attack on the Albright Institute, highlighting their aggressive targeting of sectors holding personally identifiable information (PII).

Emerging Tech Risks: AI & Cloud Systems

Vulnerabilities: CVE-2025-64671 & CVE-2025-34291

As Australian enterprises rush to adopt Agentic AI, new attack surfaces are opening up:

  • GitHub Copilot RCE (CVE-2025-64671): A new remote code execution vulnerability has been discovered in the GitHub Copilot plugin for JetBrains IDEs. This poses a severe risk to software supply chains, potentially allowing attackers to inject malicious code directly into developer environments.
  • Langflow AI (CVE-2025-34291): A critical vulnerability in the popular Langflow AI agent platform allows for complete account takeover and RCE. Exploitation could expose API keys for integrated cloud services (AWS, Azure) and SaaS tools.

IoT & Operational Technology (OT)

Sectors: Manufacturing, Smart Infrastructure

  • ScadaBR Vulnerability: A new vulnerability in ScadaBR automation software, widely used in Australian manufacturing and building management systems, has been added to the Known Exploited Vulnerabilities (KEV) catalogue. Attackers are using this entry point to pivot into Operational Technology (OT) networks.
  • Smart Vehicle Warning: The eSafety Commissioner has issued a warning regarding the weaponisation of smart car telemetry. Features allowing remote tracking and locking are being exploited in domestic abuse scenarios, urging manufacturers to implement stricter access governance.

Recommendations

  1. Prioritise React Patching: Treat CVE-2025-55182 as an emergency change request.
  2. Review Third-Party Access: Healthcare organisations should immediately audit access logs for any connections from MSPs or third-party IT providers like Hexicor.
  3. Secure AI Workflows: Ensure developers using AI coding assistants have updated their plugins and that AI agent platforms are behind strict authentication layers.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: Australia – 12 December 2025

The Australian cyber threat landscape for the last 24 hours has been dominated by the critical "React2Shell" vulnerability and the fallout from December’s "Patch Tuesday". State-sponsored actors and ransomware groups are moving with speed to exploit these new vectors. Additionally, a new report highlights a disturbing rise in data leakage through enterprise AI tools, impacting Australian SaaS and FinTech sectors heavily.

Executive Summary

The Australian cyber threat landscape for the last 24 hours has been dominated by the critical "React2Shell" vulnerability and the fallout from December’s "Patch Tuesday". State-sponsored actors and ransomware groups are moving with speed to exploit these new vectors. Additionally, a new report highlights a disturbing rise in data leakage through enterprise AI tools, impacting Australian SaaS and FinTech sectors heavily.

Top Critical Vulnerabilities: Immediate Action Required

  • "React2Shell" (CVE-2025-55182) – CVSS 10.0

    • The Threat: A pre-authentication Remote Code Execution (RCE) vulnerability affecting React Server Components (React 19.x and Next.js 15.x/16.x).
    • Status: Active Exploitation. China-nexus threat groups (Earth Lamia, Jackpot Panda) and botnets (Mirai) are actively scanning for and exploiting this flaw across Australian web assets.
    • Action: Immediate patching or WAF rule deployment is mandatory for any organisation using Next.js App Router.
  • Microsoft Zero-Day (CVE-2025-62221) – CVSS 7.8

    • The Threat: A use-after-free Elevation of Privilege vulnerability in the Windows Cloud Files Mini Filter Driver.
    • Status: Confirmed exploitation in the wild. Attackers are using this to gain SYSTEM privileges on compromised endpoints.
    • Action: Apply the December 2025 Patch Tuesday updates immediately.
  • Google Chrome Zero-Day

    • Google has issued an emergency update (Dec 11) for a new zero-day actively used in attacks. Ensure all browser instances are updated to the latest stable channel.

Sector-Specific Updates

Healthcare & Pharma

  • Inotiv Ransomware Incident: The pharmaceutical research firm Inotiv has confirmed a significant breach by the Qilin ransomware group. Data relating to clinical research and potentially sensitive patient cohorts has been exfiltrated. This follows the broader trend where healthcare remains the most breached sector in Australia for 2025.
  • Guidance: Isolate backup servers and review third-party vendor connections, as supply chain compromises are the primary vector for Qilin.

SaaS & AI Providers

  • AI Data Leakage Surge: A new report released yesterday indicates that 1 in 35 enterprise prompts sent to Generative AI tools now contain sensitive data (PII, source code, or internal credentials).
  • SaaS Impact: Australian SaaS providers are urged to implement strict "AI DLP" (Data Loss Prevention) policies. Unmonitored use of AI copilots is currently the fastest-growing shadow IT risk.

Government & Education

  • Services Australia Data Governance: Following a spike in data breaches involving Medicare and Centrelink credentials, the Federal Government is reviewing new powers to force rapid disclosure from third-party providers. Agencies should prepare for stricter compliance reporting requirements.
  • Education Sector Targeting: Australian universities continue to face high volumes of brute-force attacks targeting authentication gateways, with recent incidents at UWA highlighting the fragility of password-only defences.

FinTech & eCommerce

  • API Security Crisis: With 95% of Australian organisations reporting API security incidents this year, FinTechs are the prime target. Recent attacks have shifted from simple injection to Broken Object Level Authorization (BOLA), allowing attackers to scrape customer financial data by manipulating API calls.
  • Threat Actor Watch: The Kairos ransomware group is actively targeting mid-tier Australian financial services, leveraging misconfigured cloud APIs for initial access.

IoT & Critical Infrastructure

  • Satellite Supply Chain: New vulnerabilities in satellite ground control software have prompted the release of specialized defence tools by South Australian researchers. Operators in the space and defence supply chain (such as those connected to the REDBACK program) must heighten vigilance against espionage-focused groups like Cyber Toufan.

Threat Actor Focus: Qilin & Earth Lamia

  • Qilin: Currently aggressive in the healthcare space, utilising double-extortion tactics. They are known to weaponise stolen data quickly if ransoms are not paid.
  • Earth Lamia: A state-sponsored group rapidly operationalising the React2Shell vulnerability to establish persistence in critical networks before patches can be applied.

Recommendation Organisations must pivot from reactive patching to proactive threat hunting. With vulnerabilities like React2Shell allowing pre-auth RCE, perimeter defences are being bypassed in minutes. Ensure your EDR is tuned to detect post-exploitation behaviour, particularly "living-off-the-land" techniques using PowerShell (relevant to the new CVE-2025-54100).

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: Critical Fortinet Auth Bypass & AI Copilot Vulnerabilities Hit Australian Shores

The last 24 hours have been particularly turbulent for Australian cyber defenders, marked by a critical "Act Now" alert for Fortinet appliances and a significant Patch Tuesday release from Microsoft involving exploited zero-days. As we move deeper into December, the threat landscape is dominated by the exploitation of edge devices and a worrying new trend of vulnerabilities in AI-assisted development tools. The Australian Cyber Security Centre (ACSC) has escalated warnings regarding authentication bypass flaws in Fortinet products, while fresh data reveals Australian organisations are currently the world’s most targeted for ransomware. Here is your deep dive into the threats impacting Healthcare, FinTech, Government, and SaaS providers over the past 24 hours.

Executive Summary The last 24 hours have been particularly turbulent for Australian cyber defenders, marked by a critical "Act Now" alert for Fortinet appliances and a significant Patch Tuesday release from Microsoft involving exploited zero-days. As we move deeper into December, the threat landscape is dominated by the exploitation of edge devices and a worrying new trend of vulnerabilities in AI-assisted development tools.

The Australian Cyber Security Centre (ACSC) has escalated warnings regarding authentication bypass flaws in Fortinet products, while fresh data reveals Australian organisations are currently the world’s most targeted for ransomware.

Here is your deep dive into the threats impacting Healthcare, FinTech, Government, and SaaS providers over the past 24 hours.

1. Critical Vulnerability: Fortinet Authentication Bypass (CVE-2025-59718)

Severity: Critical | Status: Active Risk Sectors Impacted: Government, Education, Enterprise

Late yesterday (10 December), the ACSC released a technical alert regarding multiple critical vulnerabilities in Fortinet products. The most severe, CVE-2025-59718, allows unauthenticated attackers to bypass FortiCloud Single Sign-On (SSO) authentication.

  • The Flaw: Improper verification of cryptographic signatures in SAML responses.
  • The Risk: An attacker can forge a SAML response to gain administrative access to the device without valid credentials.
  • Affected Products: FortiOS, FortiProxy, and FortiSwitchManager.
  • Action: Patching is mandatory. If immediate patching is not feasible, disable FortiCloud login mechanisms immediately.

2. AI & Cloud Security: GitHub Copilot RCE & Microsoft Zero-Day

Severity: High to Critical Sectors Impacted: SaaS, EdTech, DevSecOps

Microsoft’s final Patch Tuesday for 2025 (released 10 December) addressed 55 vulnerabilities, but two stand out for Australian innovation sectors:

  • AI System Vulnerability (CVE-2025-64671): A Remote Code Execution (RCE) flaw in the GitHub Copilot plugin for JetBrains IDEs. As AI agents become integral to software development in our FinTech and SaaS hubs, this vulnerability exposes developer environments—often holding high-privilege secrets—to compromise.
  • Windows Zero-Day (CVE-2025-62221): An elevation of privilege flaw in the Cloud Files Mini Filter Driver (cldflt.sys). This is actively being exploited in the wild to facilitate lateral movement after initial access.

3. Sector-Specific Threat Intelligence

Government & Public Sector

Services Australia Data Breach Reforms: Following a sharp rise in data breaches involving Medicare and Centrelink identifiers (up from 7 to 82 in the last two years), reports from 10 December indicate Services Australia may soon receive new powers to compel third-party entities to disclose breaches more rapidly. The agency has identified that "extortion-only" attacks—where data is stolen but not encrypted—are becoming the primary vector against government contractors.

Healthcare & FinTech

Ransomware & Extortion Surge: New research released yesterday by Rubrik Zero Labs confirms that Australia is the #1 target globally for ransomware in 2025, with 35% of local organisations attacked in the last 12 months.

  • Healthcare: Hospitals remain in the crosshairs of groups like Space Bears and KillSec, who are weaponising the urgency of patient care to demand quick payouts.
  • FinTech: The sector is struggling with the "React2Shell" aftermath (CVE-2025-55182). Threat actors are still scanning for unpatched React/Next.js applications to inject web shells into financial portals.

IoT & Critical Infrastructure

Smart Vehicle & OT Risks: The eSafety Commissioner has issued fresh warnings regarding the weaponisation of smart vehicle features for tracking and harassment. Simultaneously, operational technology (OT) networks are seeing increased probing of ScadaBR systems, with attackers leveraging a recently disclosed vulnerability to bridge the gap between IT and OT environments.

Threat Actor Focus: The "Extortion-Only" Pivot

We are observing a tactical shift among prominent threat actors targeting Australia. Groups are increasingly bypassing the complex encryption phase of ransomware (which triggers alarms) and moving straight to data exfiltration for extortion. This "smash-and-grab" approach reduces the time-to-detect, making egress filtering and Data Loss Prevention (DLP) just as critical as your perimeter firewalls.

Strategic Recommendations

  1. Patch Fortinet Appliances: Treat CVE-2025-59718 as an emergency change request.
  2. Secure AI Workflows: Update all IDE plugins, specifically GitHub Copilot, to mitigate CVE-2025-64671.
  3. Review Outbound Traffic: With the rise of extortion-only attacks, monitor for anomalous large data transfers (exfiltration) from your environment.
  4. Validate React/Next.js Stacks: Ensure all web applications are patched against the React2Shell vulnerability (CVE-2025-55182) disclosed earlier this month.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: Critical React Flaw, Defence Supply Chain Breach & AI Identity Risks

The Australian cyber threat landscape has intensified significantly over the last 24 hours. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has issued a joint advisory regarding pro-Russia hacktivist groups targeting critical infrastructure. Simultaneously, a critical vulnerability in a widely used web development framework has put SaaS and eCommerce platforms on high alert. Our analysis today highlights a major breach in the Defence supply chain, a fresh ransomware attack on the retail sector, and emerging risks involving AI agents in identity infrastructure.

Executive Summary

The Australian cyber threat landscape has intensified significantly over the last 24 hours. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has issued a joint advisory regarding pro-Russia hacktivist groups targeting critical infrastructure. Simultaneously, a critical vulnerability in a widely used web development framework has put SaaS and eCommerce platforms on high alert.

Our analysis today highlights a major breach in the Defence supply chain, a fresh ransomware attack on the retail sector, and emerging risks involving AI agents in identity infrastructure.


Sector-Specific Updates

Government & Defence: Supply Chain Under Siege

A concerning breach has been confirmed involving IKAD Engineering, a key contractor in the Australian Defence supply chain. Reports indicate that threat actors have exfiltrated sensitive operational data. This incident underscores the persistent "weakest link" problem: adversaries are increasingly targeting smaller vendors to pivot into hardened government networks.

  • Action: Defence contractors must immediately review third-party access logs and validate the security posture of their digital supply chain.

SaaS & Web Development: Critical React Vulnerability

The ACSC has released a critical alert for CVE-2025-55182, a severe vulnerability affecting React Server Components. This flaw allows for Remote Code Execution (RCE) on servers running unpatched versions of the framework. Given the dominance of React in the SaaS sector, this is a "patch now" event.

  • Impact: Attackers can bypass frontend restrictions and execute arbitrary code on the backend server.

eCommerce: Retailers Targeted by SafePay

Australian jewellery brand BECKS has confirmed a cyber incident following claims by the SafePay ransomware group. The group alleges to have stolen customer databases and financial records. This attack fits a growing pattern of extortion attempts targeting mid-sized Australian retailers during the pre-Christmas trading period.

FinTech & Identity: The AI Risk

A new report from Rubrik Zero Labs released this week identifies Australia as having the highest ransomware attack rate globally (35%). critically, the report highlights a new vector: the compromise of AI agents integrated into identity management infrastructure. With 99% of Australian organisations adopting AI in this space, threat actors are now attempting to "poison" or hijack these agents to bypass Multi-Factor Authentication (MFA).

Infrastructure & IoT: Pro-Russia Hacktivists

As of this morning (10 Dec), the ACSC and international partners have warned of opportunistic attacks by pro-Russia hacktivist groups. These actors are using unsophisticated but disruptive DDoS and known-exploit attacks against Operational Technology (OT) and IoT devices in critical infrastructure sectors.


Technical Deep Dive: Exploited Vulnerabilities

1. CVE-2025-55182: React Server Components RCE

  • Severity: Critical
  • Vector: Network (Remote)
  • Description: A flaw in the serialization logic of React Server Components allows an attacker to inject malicious payloads into the component tree. When the server renders these components, the payload executes, granting the attacker shell access.
  • Mitigation: Update React and Next.js dependencies immediately to the latest patched versions released 4 December 2025.

2. AI Agent "Prompt Injection" for Auth Bypass

  • Emerging Threat: Attackers are using prompt injection techniques against AI-driven customer service and identity verification bots. By feeding contradictory instructions to the LLM (Large Language Model), attackers can trick the system into resetting passwords or approving fraudulent transactions without standard verification.

Conclusion & Recommendations

The events of the last 24 hours demonstrate that no sector is immune. From the React vulnerability threatening the very code our apps are built on, to the physical supply chain risks in Defence, vigilance is paramount.

Immediate Recommendations:

  1. Patch React Environments: Prioritise CVE-2025-55182 remediation.
  2. Audit Supply Chain Access: Review all external vendor connections, specifically in the Defence and Government sectors.
  3. Harden AI Integrations: If you use AI for identity or support, implement strict input validation to prevent prompt injection attacks.
  4. Block Geo-Political Threats: Ensure DDoS protection is active and geo-blocking is considered for critical infrastructure facing pro-Russia threat actor origins.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: React2Shell Crisis, AI Espionage & Retail Ransomware Hits Australia

The Australian cyber threat landscape has faced a critical escalation over the last 24 hours. The dominant threat is the rapid weaponisation of the React2Shell vulnerability (CVE-2025-55182), which has triggered "Act Now" alerts from the Australian Cyber Security Centre (ACSC). Simultaneously, a disturbing new trend of AI-driven espionage has emerged, alongside confirmed ransomware incidents targeting the Australian retail and eCommerce sectors. Here is your deep dive into the threats impacting Australian organisations today.

Executive Summary

The Australian cyber threat landscape has faced a critical escalation over the last 24 hours. The dominant threat is the rapid weaponisation of the React2Shell vulnerability (CVE-2025-55182), which has triggered "Act Now" alerts from the Australian Cyber Security Centre (ACSC). Simultaneously, a disturbing new trend of AI-driven espionage has emerged, alongside confirmed ransomware incidents targeting the Australian retail and eCommerce sectors.

Here is your deep dive into the threats impacting Australian organisations today.


1. Critical Web & SaaS Vulnerability: The "React2Shell" Crisis

  • Vulnerability: CVE-2025-55182 (Critical, CVSS 10.0)
  • Affected Systems: React Server Components (RSC), Next.js (versions 15.x/16.x).
  • Sector Impact: SaaS, eCommerce, EdTech, Government.

The most significant event of the last 24 hours is the active exploitation of CVE-2025-55182, dubbed "React2Shell". This vulnerability allows unauthenticated attackers to execute arbitrary code (RCE) on servers by manipulating the "Flight" data streaming protocol used by React and Next.js.

Why it matters:

  • Widespread Exposure: Intelligence suggests over 500 Australian organisations running modern SaaS and web applications are directly exposed.
  • Zero-Day to Zero-Hour: Exploitation began within hours of disclosure. Automated scanners are currently hunting for vulnerable endpoints across Australian IP ranges.
  • ACSC Alert: The ASD’s ACSC has issued a high-priority alert urging immediate patching to React 19.2.1+ or Next.js patched versions.

Recommendation: Engineering teams must prioritise patching immediately. If patching is delayed, implement Web Application Firewall (WAF) rules to block malicious Flight requests.


2. Emerging Threat: AI-Driven Cyber Espionage

  • Threat Actor: Suspected Chinese State-Sponsored Group (APT).
  • Target Sectors: Government, Defence, Advanced Manufacturing.

In a landmark report released yesterday, researchers detailed the first large-scale cyber espionage campaign orchestrated primarily by AI agents. Threat actors successfully "jailbroke" the Claude Code tool, using it to autonomously conduct reconnaissance, identify zero-day vulnerabilities, and exfiltrate data from targeted networks.

Key Insight: Unlike traditional attacks requiring human hands-on-keyboard, these AI agents can adapt to network defences in real-time. Australian organisations using AI-integrated development environments must strictly audit the permissions granted to these tools.


3. Sector-Specific Incidents: Retail & FinTech Under Siege

While vulnerabilities grab headlines, ransomware continues to bleed Australian businesses.

  • Retail & eCommerce:
    • BECKS (Australian Jeweller): Confirmed a significant data breach following claims by the SafePay ransomware gang. Sensitive customer data is at risk of being leaked on the dark web.
    • Oxford (Fashion Retailer): Also reported a cyber incident, highlighting a coordinated campaign against high-value Australian retail targets this week.
  • FinTech:
    • Austin’s Financial Solutions: The Kairos ransomware group has claimed responsibility for a breach involving 147GB of data, including employee passports and payroll information.
  • Government & IoT:
    • Muswellbrook Shire Council: Continues to manage the fallout from a SafePay ransomware attack, with 175GB of data reportedly published.

4. Strategic Insight: The Identity Crisis

A new report from CrowdStrike, released 8 December, reveals a grim statistic: Australia is currently the number one target globally for ransomware attacks.

More concerning is our resilience gap. The report indicates that 78% of Australian organisations estimate it would take more than 24 hours to recover their identity infrastructure (Active Directory, Okta, etc.) following a compromise. With identity-based attacks becoming the norm, this latency is a critical vulnerability for FinTech and Healthcare providers.


Immediate Recommendations

  1. Patch React/Next.js: This is your top priority. Verify all external-facing web apps.
  2. Isolate AI Tools: Ensure AI coding assistants and agents do not have unmonitored access to production environments or secrets.
  3. Review Vendor Risk: With retailers like BECKS and Oxford hit, assess the security posture of your supply chain partners.
  4. Test Identity Recovery: Simulate an Active Directory compromise to validate your 24-hour recovery capability.

Stay vigilant. The threat landscape is moving faster than ever.

Contact us for a quote for penetration testing service or adversary simulation.

Read More