Daily Threat Briefing

Australian Cyber Threat Briefing: Critical RCEs and Ransomware Targeting SaaS & Education

Australian Cyber Threat Briefing: Critical RCEs and Ransomware Targeting SaaS & Education

As we wrap up the year, the Australian cyber threat landscape has intensified significantly over the last 24 hours. Critical vulnerabilities in widely used network appliances and targeted ransomware campaigns against key sectors—specifically Education, Healthcare, and SaaS providers—demand immediate attention from security teams.

Daily Threat Briefing: Critical WatchGuard Exploits & Holiday Ransomware Spikes – 24 December 2025

Daily Threat Briefing: Critical WatchGuard Exploits & Holiday Ransomware Spikes – 24 December 2025

As we head into the Christmas break, the Australian cyber threat landscape has escalated significantly over the last 24 hours. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD's ACSC) has issued a critical alert regarding active exploitation of WatchGuard Firebox devices. This comes alongside a surge in ransomware activity targeting the education and government sectors, with threat actors looking to capitalise on reduced staffing levels during the holiday period.

Daily Threat Briefing: React2Shell Crisis & Aussie Healthcare Under Fire

Daily Threat Briefing: React2Shell Crisis & Aussie Healthcare Under Fire

The last 24 hours have been critical for Australian cyber defenders. A new maximum-severity vulnerability in the React framework, dubbed "React2Shell," is being actively exploited by state-sponsored actors, sending shockwaves through the SaaS and FinTech sectors. Simultaneously, the Australian healthcare and education sectors are grappling with fresh ransomware extortion attempts and significant data leaks.

Daily Threat Briefing: Critical Cisco & React Zero-Days + NSW Health Risks

Daily Threat Briefing: Critical Cisco & React Zero-Days + NSW Health Risks

As we kick off the week leading into the holiday season, Australian security teams face a heightened threat landscape. Over the weekend, active exploitation of maximum-severity vulnerabilities in Cisco infrastructure and modern web frameworks has been confirmed. Additionally, fresh reports highlight significant cyber risks within the NSW healthcare sector and a major data breach impacting the tertiary education sector.

Daily Threat Briefing: Australia - 20 December 2025

Daily Threat Briefing: Australia - 20 December 2025

The Australian cyber threat landscape has seen significant volatility in the last 24 hours. The primary focus for security teams today is the catastrophic "React2Shell" vulnerability (CVE-2025-55182), which is actively being exploited to deploy cryptocurrency miners and backdoors across Australian cloud environments. Simultaneously, the healthcare and education sectors are under heavy fire, with a major breach disclosed by the University of Sydney and a confirmed ransomware attack on fertility provider Genea.

Australian Cyber Threat Briefing: Healthcare Security Gaps & Critical SaaS Vulnerabilities

Australian Cyber Threat Briefing: Healthcare Security Gaps & Critical SaaS Vulnerabilities

The last 24 hours have exposed significant fragility in Australia’s Healthcare and Education sectors, with a major audit revealing systemic security bypasses in NSW Health and a fresh data breach hitting the University of Sydney. Globally, critical vulnerabilities in Fortinet’s cloud infrastructure and React server components are demanding immediate patching cycles. This briefing summarises the key threats, incidents, and vulnerabilities impacting Australian organisations today.

Daily Threat Briefing: React2Shell Exploits Surge & Uni Sydney Breach

Daily Threat Briefing: React2Shell Exploits Surge & Uni Sydney Breach

As we approach the holiday shutdown period, the Australian cyber threat landscape has intensified significantly over the last 24 hours. The standout threat is the rapid weaponisation of the React2Shell (CVE-2025-55182) vulnerability, which is currently being exploited in the wild by state-sponsored actors and botnets alike. Additionally, the University of Sydney has confirmed a data breach impacting historical records, reminding the Education sector that non-production environments remain a critical risk vector.

Australian Threat Briefing: React2Shell Escalation, Critical Fortinet Flaws & AI Supply Chain Risks

Australian Threat Briefing: React2Shell Escalation, Critical Fortinet Flaws & AI Supply Chain Risks

In the last 24 hours, the Australian cybersecurity landscape has been dominated by the rapid escalation of the "React2Shell" (CVE-2025-55182) campaign and critical alerts regarding Fortinet authentication bypasses. Threat actors, particularly those with a Chinese nexus, are actively exploiting these vulnerabilities across the SaaS and Government sectors. Additionally, high-profile supply chain incidents impacting major AI providers like OpenAI highlight the growing fragility of the artificial intelligence ecosystem.

Daily Threat Briefing: React Critical RCE, Healthcare Under Fire, and New AI Risks

Daily Threat Briefing: React Critical RCE, Healthcare Under Fire, and New AI Risks

In the last 24 hours, the Australian cyber landscape has been dominated by urgent warnings regarding a maximum-severity vulnerability in the React framework, fresh ransomware concerns targeting Queensland healthcare providers, and significant developments in AI security governance. The Australian Cyber Security Centre (ACSC) and global partners continue to highlight the aggressive targeting of critical infrastructure by state-sponsored and opportunistic threat actors.

Urgent: Critical React & Fortinet Flaws Exploit Australian Networks

Urgent: Critical React & Fortinet Flaws Exploit Australian Networks

The Australian cyber threat landscape has intensified significantly over the last 24 hours. The Australian Cyber Security Centre (ACSC) and global intelligence firms have issued urgent alerts regarding a perfect storm of critical vulnerabilities. Foremost among these is "React2Shell"—a CVSS 10.0 vulnerability in the React framework—and a severe authentication bypass in Fortinet appliances. Simultaneously, ransomware groups are aggressively targeting Australian organisations, with confirmed breaches in the FinTech and Healthcare sectors. The Chaos and Qilin ransomware gangs have claimed responsibility for major data exfiltration events, highlighting the persistent threat to sensitive personally identifiable information (PII) and financial records.