Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: Australia - 17 January 2026

The Australian cyber threat landscape remains volatile this weekend following a chaotic 48 hours. Security teams across the country are currently responding to a major breach affecting the Victorian education sector and managing the fallout from critical vulnerabilities in Microsoft Windows and workflow automation tools.

Executive Summary

The Australian cyber threat landscape remains volatile this weekend following a chaotic 48 hours. Security teams across the country are currently responding to a major breach affecting the Victorian education sector and managing the fallout from critical vulnerabilities in Microsoft Windows and workflow automation tools.

For Saturday, 17 January 2026, our analysts are highlighting active exploitation of a Windows zero-day (CVE-2026-20805), a critical RCE in the n8n automation platform affecting SaaS providers, and continued data leakage risks in the healthcare sector.

Top Story: Victorian Schools Data Breach

In a significant blow to the Education/EdTech sector, the Victorian Department of Education confirmed yesterday (16 January) that a cyber attack has compromised data across 1,700 government schools. Threat actors gained unauthorised access to a database containing personal information of current and former students, including names and email addresses.

  • Impact: While passwords have been reset, the exposure of student contact details creates a long-term risk of targeted phishing and identity fraud.
  • Recommendation: Education providers must urgently review third-party access controls and enforce Multi-Factor Authentication (MFA) on all parent and student portals.

Critical Vulnerability Alerts

1. Microsoft Windows "Desktop Window Manager" Zero-Day (CVE-2026-20805)

  • Severity: Critical (Active Exploitation Confirmed)
  • Sector Impact: Government, FinTech, Corporate Enterprise
  • Details: A privilege escalation vulnerability in the Desktop Window Manager (DWM) is being actively exploited in the wild. Attackers are using this to gain 'SYSTEM' privileges on compromised workstations, often as a second stage after initial access.
  • Action: Immediate patching of the January 2026 "Patch Tuesday" updates is mandatory. Prioritise high-value workstations in finance and government networks.

2. n8n Workflow Automation RCE (CVE-2026-21858)

  • Severity: Critical (CVSS 9.8)
  • Sector Impact: SaaS Providers, FinTech, Startups
  • Details: A remote code execution (RCE) flaw in the popular n8n workflow automation tool allows unauthenticated attackers to take full control of self-hosted instances. Many Australian FinTechs use n8n to glue together APIs and backend services.
  • Action: Isolate n8n instances from the public internet immediately and apply the latest vendor patches.

Sector-Specific Intelligence

  • FinTech & Insurance: The Prosura data breach (confirmed 14 January) continues to escalate, with reports that stolen data (affecting ~300,000 customers) is now being actively traded on dark web forums. Financial institutions should be on high alert for customers being targeted by "vishing" (voice phishing) attacks using the leaked policy data to build credibility.

  • Healthcare: The "MongoBleed" vulnerability (CVE-2025-14847) remains a persistent threat. We are observing automated botnets scanning Australian IP ranges for unpatched MongoDB instances, specifically targeting eHealth applications. Attackers are exfiltrating unstructured patient data without needing authentication.

  • eCommerce: Retailers are urged to audit their session storage mechanisms. The recent Microsoft Word RCE (CVE-2026-20944) is being weaponised in phishing campaigns targeting retail employees, disguised as "Invoice" or "Order Query" attachments. Exploitation occurs simply via the Preview Pane—no click is required.

  • IoT & Edge Security: Organisations using WatchGuard Firebox devices at network edges must verify they have patched CVE-2025-14733. We have detected scanning activity originating from compromised IoT botnets attempting to exploit this flaw to breach corporate perimeters.

Analyst's Comment

The convergence of a Microsoft zero-day and a critical SaaS infrastructure flaw (n8n) creates a "perfect storm" for weekend attacks. Ransomware groups are known to accelerate operations during off-hours. We strongly advise Australian organisations to maintain heightened monitoring on outbound traffic and privileged account usage over the next 48 hours.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: Critical n8n RCE, Microsoft Zero-Days & Prosura Breach

The Australian cyber threat landscape has seen a significant surge in activity over the last 24 hours. Critical alerts have been issued for widely used workflow automation platforms and cloud infrastructure, placing SaaS providers, government agencies, and FinTech organisations on high alert.

Executive Summary

The Australian cyber threat landscape has seen a significant surge in activity over the last 24 hours. Critical alerts have been issued for widely used workflow automation platforms and cloud infrastructure, placing SaaS providers, government agencies, and FinTech organisations on high alert.

Our analysis for today highlights a critical unauthenticated Remote Code Execution (RCE) in the n8n platform, the fallout from Microsoft’s January Patch Tuesday involving actively exploited Hyper-V zero-days, and a confirmed breach affecting Australian insurance provider Prosura.


Top Priority: Critical n8n Workflow Automation RCE

Target: SaaS Providers, API Integrators, FinTech Vulnerability: CVE-2026-21858 (Critical)

The Australian Cyber Security Centre (ACSC) and global threat intelligence firms have flagged active exploitation of a critical vulnerability in the n8n workflow automation platform.

  • The Threat: CVE-2026-21858 allows unauthenticated threat actors to execute arbitrary code on the underlying server via malformed form-based workflows.
  • Impact: As n8n is often used to glue together disparate APIs and handle sensitive data pipelines (FinTech data, customer details), a compromise here effectively grants attackers the "keys to the kingdom," allowing lateral movement into connected cloud services.
  • Action: Organisations using n8n must isolate instances immediately and apply the latest hotfix.

Sector Watch: Key Incidents & Trends

FinTech & eCommerce: Prosura Data Breach

Australian rental car insurance provider Prosura has confirmed a significant cyber incident resulting in unauthorised access to customer data.

  • Details: Threat actors accessed internal IT systems, exposing driver's licences and policy documents. The attackers also utilised the compromised infrastructure to send fraudulent emails to customers.
  • Response: Prosura has paused its online self-service portal while forensic investigations continue.
  • Takeaway: This incident underscores the growing trend of "island hopping"—where attackers compromise a trusted service provider to launch phishing campaigns against its user base from a legitimate domain.

Government & Cloud Infrastructure: Microsoft Patch Tuesday Fallout

Following the January Patch Tuesday (13 Jan), security teams across the Australian Government and enterprise sectors are racing to patch eight zero-day vulnerabilities.

  • Critical Focus: CVE-2025-21333, CVE-2025-21334, and CVE-2025-21335 are actively exploited Privilege Escalation vulnerabilities in Windows Hyper-V.
  • Risk: These flaws allow an attacker with a foothold on a guest virtual machine to escape the sandbox and gain SYSTEM privileges on the host server. This is a "Code Red" risk for private cloud providers and government data centres relying on virtualised environments.

AI Systems: Open WebUI Code Injection

As AI adoption accelerates in Education and EdTech, a new vulnerability has emerged in Open WebUI (formerly Ollama WebUI), a popular self-hosted interface for LLMs.

  • Vulnerability: CVE-2025-64496 permits remote code injection via the 'Direct Connection' feature.
  • Risk: Attackers can hijack the AI interface to execute commands on the host, potentially poisoning models or exfiltrating proprietary training data.

Healthcare & IoT: WatchGuard & Trend Micro Alerts

  • Network IoT: A critical vulnerability in WatchGuard Firebox devices (CVE-2025-14733) is seeing active exploitation. Healthcare clinics using these appliances for edge security are urged to update firmware immediately to prevent perimeter breaches.
  • Security Management: Trend Micro Apex Central has patched a critical RCE (CVE-2025-69258) that allows attackers to execute code as SYSTEM without user interaction.

Threat Actor Activity

  • Medusa Ransomware: The group remains highly active in the region, recently claiming attacks on non-profits and healthcare adjacents. Their tactics continue to involve double extortion—encrypting data and threatening to leak sensitive medical records.
  • Crimson Collective: Following the Brightspeed breach, this group is showing increased aggression towards telecommunications and infrastructure targets.

Recommendations

  1. Patch n8n and Hyper-V: These are the most volatile vectors currently being exploited in the wild.
  2. Review Third-Party Risk: With the Prosura incident, verify the security posture of insurance and API partners.
  3. Secure AI Workloads: Ensure self-hosted AI tools like Open WebUI are not exposed to the public internet without strict access controls.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: Australia – 14 January 2026

The Australian cyber threat landscape for 14 January 2026 is dominated by a critical zero-day vulnerability in Microsoft Windows, actively exploited in the wild, and a confirmed breach of a major ASX-listed resource producer. The Australian Cyber Security Centre (ASD’s ACSC) has also issued fresh guidance on AI security following a surge in attacks targeting workflow automation platforms.

Executive Summary

The Australian cyber threat landscape for 14 January 2026 is dominated by a critical zero-day vulnerability in Microsoft Windows, actively exploited in the wild, and a confirmed breach of a major ASX-listed resource producer. The Australian Cyber Security Centre (ASD’s ACSC) has also issued fresh guidance on AI security following a surge in attacks targeting workflow automation platforms.

For security teams across Government, Healthcare, and SaaS, the priority today is patching the new Microsoft Desktop Window Manager flaw and auditing exposed automation tools.


Sector-Specific Threat Intelligence

Government & Critical Infrastructure

  • Microsoft Zero-Day (CVE-2026-20805): In the last 24 hours, Microsoft’s January Patch Tuesday release has highlighted CVE-2026-20805, a privilege escalation vulnerability in the Desktop Window Manager (DWM). CISA and the ACSC have confirmed this is being actively exploited. Attackers are using this to gain ‘SYSTEM’ privileges on compromised government and enterprise workstations.
  • Regis Resources Breach: Major Australian gold producer Regis Resources has confirmed a significant cyber incident. While details are emerging, this underscores the continued targeting of Australia’s critical resource sector by financially motivated ransomware groups.
  • DFAT Vulnerability: On a positive note, a critical vulnerability in the Department of Foreign Affairs and Trade (DFAT) was responsibly disclosed by ethical hackers rather than exploited by nation-states, highlighting the value of robust Vulnerability Disclosure Programmes (VDPs).

Healthcare & eCommerce

  • The "MongoBleed" Aftershocks (CVE-2025-14847): Security teams are still battling the fallout from the "MongoBleed" memory leak vulnerability. Threat actors are actively scanning for unpatched MongoDB instances in Australian healthcare providers to exfiltrate unstructured patient data (PII/PHI).
  • eCommerce Session Hijacking: Retailers using MongoDB for session storage are at high risk. We have observed scripts in the wild attempting to scrape active session tokens via this flaw, potentially allowing account takeovers without credentials.

SaaS & FinTech

  • n8n Workflow Automation RCE (CVE-2026-21858): A Critical (CVSS 9.8) Remote Code Execution vulnerability in the popular n8n workflow automation platform was flagged this week. SaaS providers and FinTechs using n8n for backend integrations (e.g., connecting CRMs to banking APIs) must isolate these instances immediately. Exploitation allows unauthenticated attackers to execute arbitrary code on the hosting server.
  • IBM API Connect Auth Bypass: FinTechs relying on IBM API Connect for open banking implementations should review CVE-2025-13915. This authentication bypass flaw is being weaponised to skip API gateway security checks.

Education & EdTech

  • University Data Retention Risks: Following the massive data breaches at the University of Sydney and Western Sydney University in late 2025, threat actors are now targeting alumni databases in EdTech platforms. The focus has shifted to extracting long-term historical data for identity theft.

IoT & AI Systems

  • AI Security Alert: The ACSC released a new publication today (14 Jan 2026) regarding AI risks for small to medium businesses. This coincides with reports of Prompt Injection attacks targeting customer service chatbots, tricking them into revealing backend API keys.
  • WatchGuard Firebox Exploits: Organisations using WatchGuard Firebox devices for edge security (common in distributed IoT networks) must patch CVE-2025-14733 immediately. Active exploitation is providing attackers with initial access to OT (Operational Technology) networks.

Vulnerability Watchlist: Top 3 to Patch Now

  1. Microsoft Windows DWM (CVE-2026-20805):

    • Type: Privilege Escalation.
    • Status: Actively Exploited.
    • Action: Apply the January 2026 Patch Tuesday update immediately.
  2. n8n Workflow Automation (CVE-2026-21858):

    • Type: Unauthenticated Remote Code Execution.
    • Status: PoC publicly available.
    • Action: Update to the latest stable release or restrict internet access to the instance.
  3. MongoDB Server (CVE-2025-14847):

    • Type: Information Disclosure (Memory Leak).
    • Status: Targeted by ransomware groups.
    • Action: Upgrade to the latest patched version and audit log files for suspicious read operations.

Recommendations

Organisations should prioritise the patching of public-facing infrastructure, particularly the n8n and WatchGuard vulnerabilities. For internal networks, the Microsoft DWM flaw represents a critical risk for lateral movement if an endpoint is compromised.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: Anubis Targets Healthcare & Critical RCE in n8n Automation

In the last 24 hours, the Australian cyber threat landscape has been dominated by a resurgence of targeted ransomware campaigns against the healthcare sector and critical vulnerability disclosures affecting widely used SaaS automation tools. The Anubis ransomware gang has claimed responsibility for breaching a Queensland medical practice, while a Critical-rated Remote Code Execution (RCE) vulnerability in the n8n workflow automation platform poses an immediate risk to SaaS providers and tech-driven enterprises.

Executive Summary

In the last 24 hours, the Australian cyber threat landscape has been dominated by a resurgence of targeted ransomware campaigns against the healthcare sector and critical vulnerability disclosures affecting widely used SaaS automation tools. The Anubis ransomware gang has claimed responsibility for breaching a Queensland medical practice, while a Critical-rated Remote Code Execution (RCE) vulnerability in the n8n workflow automation platform poses an immediate risk to SaaS providers and tech-driven enterprises.

Sector-Specific Threat Intelligence

Healthcare: Anubis Ransomware Aggression

The most concerning development overnight is the alleged compromise of Laidley Family Doctors in Queensland by the Anubis ransomware group.

  • The Incident: Anubis has listed the clinic on its dark web leak site, claiming to have exfiltrated sensitive patient data, including Medicare numbers, medical histories, and personal contact details.
  • The Actor: Anubis is employing a unique psychological pressure tactic. Their spokesperson, using the alias "Tobias Keller," poses as a journalist to "interview" victims and regulatory bodies, effectively weaponising media attention to force ransom payments.
  • Impact: This follows a pattern of Anubis targeting smaller Australian healthcare providers (such as the previous Pound Road Medical Centre incident), exploiting the often limited cyber resilience of regional medical practices.

SaaS & Cloud: Critical n8n RCE (CVE-2026-21858)

For SaaS providers and organisations relying on low-code automation, a new critical alert has been issued.

  • The Vulnerability: A Critical Unauthenticated Remote Code Execution (RCE) vulnerability (tracked as CVE-2026-21858) has been discovered in the n8n workflow automation platform.
  • The Risk: This flaw allows attackers to execute arbitrary code on the server without logging in. given n8n's role in connecting disparate APIs and databases, a compromise here could act as a supply-chain bridge into deeper corporate networks.
  • Action: Immediate patching or isolating n8n instances from the public internet is mandatory.

Education: Fallout from "Fog" Ransomware

The tertiary education sector continues to face headwinds. Following the University of Notre Dame Australia incident claimed by the Fog ransomware gang, chatter on underground forums indicates that Initial Access Brokers (IABs) are actively selling credentials for other Australian educational institutions. The market for ".edu.au" access remains lucrative due to the vast amounts of PII and research data held by these entities.

IoT & Infrastructure: WatchGuard & MongoDB Exploits

  • WatchGuard Firebox: The ASD’s ACSC has flagged active exploitation of CVE-2025-14733, a critical vulnerability in WatchGuard Firebox devices. This is being leveraged to gain initial access to corporate networks.
  • Database Leaks: Automated scanning for CVE-2025-14847 (a MongoDB server vulnerability) is spiking. Threat actors are using this to mass-exfiltrate data from misconfigured or unpatched cloud databases.

Emerging Trends & Threat Actor Behaviour

  • API Insecurity: A new industry report highlights that Australian enterprises currently face the highest frequency of API-related security incidents in the Asia-Pacific region. With FinTech and eCommerce relying heavily on API ecosystems, "Zombie APIs" (forgotten, unmonitored endpoints) are becoming the primary vector for data breaches.
  • Pro-Russia Hacktivism: The ASD has reiterated warnings regarding pro-Russia hacktivist groups shifting focus towards Australian critical infrastructure, likely in response to geopolitical stances. These attacks are typically DDoS or defacement but can mask more sophisticated intrusion attempts.

Recommendations

  1. Healthcare: Review third-party remote access policies and ensure immutable backups are in place to counter ransomware encryption.
  2. SaaS/DevOps: Audit all n8n instances immediately for CVE-2026-21858.
  3. General: Prioritise patching of edge devices (firewalls, VPNs) and conduct a discovery audit to identify and decommission unused APIs.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: Australia - 12 January 2026

The Australian cyber threat landscape for Monday, 12 January 2026, is dominated by the fallout from the "MongoBleed" vulnerability and a coordinated surge in attacks targeting the healthcare and SaaS sectors. Over the weekend, threat actors have accelerated the weaponisation of critical flaws in workflow automation tools and API gateways. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has observed intensified scanning activity, and several high-profile domestic breaches have been confirmed.

Executive Summary

The Australian cyber threat landscape for Monday, 12 January 2026, is dominated by the fallout from the "MongoBleed" vulnerability and a coordinated surge in attacks targeting the healthcare and SaaS sectors. Over the weekend, threat actors have accelerated the weaponisation of critical flaws in workflow automation tools and API gateways. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has observed intensified scanning activity, and several high-profile domestic breaches have been confirmed.

Sector-Specific Threat Analysis

1. Healthcare: Under Siege from Ransomware and API Flaws The healthcare sector remains the primary target this week.

  • Manage My Health (MMH) Update: Following the initial breach notification, the "Kazu" ransomware gang has escalated their extortion attempts, threatening to leak 400,000 patient files if a $60k ransom is not paid. Approximately 6-7% of the platform's 1.8 million users are affected, with stolen data including medical correspondence and discharge summaries.
  • Laidley Family Doctors: In a separate incident, the Queensland-based clinic has been listed on the dark web leak site of the "Anubis" ransomware gang. The group claims to have exfiltrated sensitive patient history and Medicare details.
  • IoMT Vulnerability: We are tracking active exploitation of Broken Object Level Authorization (BOLA) flaws in HL7 interface engines used to connect Internet of Medical Things (IoMT) devices. Attackers are attempting to intercept patient telemetry data directly from bedside monitors.

2. SaaS Providers: "Critical" n8n RCE & MongoBleed SaaS platforms are facing a dual threat from infrastructure and application-level vulnerabilities.

  • n8n Workflow Automation: A maximum-severity vulnerability (CVE-2026-21858, CVSS 10.0) allows unauthenticated remote code execution (RCE) in self-hosted n8n instances. Attackers are exploiting this to take full control of automation servers. A secondary authenticated RCE (CVE-2026-21877) is also being leveraged against compromised accounts.
  • "MongoBleed" (CVE-2025-14847): This unauthenticated memory leak in MongoDB servers continues to be a major vector. Threat actors are scraping server memory to extract session tokens and PII from SaaS backends without requiring login credentials.

3. FinTech: AI-Driven Vishing & Insurer Breach

  • Prosura Data Breach: Australian insurer Prosura has taken its self-service portal offline following a breach exposing customer driving licences and policy data. This incident highlights the risk of "identity aggregation" targets.
  • "DeepVoice" Campaign: A sophisticated social engineering campaign is targeting Australian neo-banks. Attackers are utilising AI-generated voice clones of C-suite executives to bypass voice biometric authentication and authorise fraudulent high-value transfers.

4. Education / EdTech: AI Supply Chain Risk

  • Langflow Exploitation: EdTech platforms utilising the Langflow AI orchestration tool are being targeted via CVE-2025-3248. This vulnerability allows unauthorised Python code injection, effectively poisoning the "AI supply chain" and granting attackers access to underlying Large Language Model (LLM) data pipelines.
  • LMS Ransomware: A new ransomware strain is targeting third-party plugins in Learning Management Systems (LMS), disrupting summer semester coursework for several tertiary institutions.

5. Government: Supply Chain & Perimeter Defence

  • DFAT Disclosure: A critical vulnerability within the Department of Foreign Affairs and Trade (DFAT) was responsibly disclosed by an ethical hacker, preventing potential diplomatic data exposure.
  • WatchGuard Firebox: Government networks remain on high alert regarding CVE-2025-14733. Active exploitation of this perimeter vulnerability is being used as a beachhead for lateral movement into secure zones.

6. IoT: Telematics Targeted

  • Netstar Australia: The telematics provider has been listed by the "Black Shrantac" ransomware group. The alleged theft of GPS fleet tracking data poses significant operational risks to logistics and transport organisations relying on real-time monitoring.

Critical Vulnerabilities to Patch Immediately

  • CVE-2026-21858: n8n Workflow Automation (Unauthenticated RCE) - CVSS 10.0
  • CVE-2025-14847: MongoDB Server ("MongoBleed") - Memory Leak
  • CVE-2025-3248: Langflow AI (Code Injection)
  • CVE-2025-14733: WatchGuard Firebox (Auth Bypass)

Recommendations Organisations are urged to prioritise patching internet-facing automation tools and databases immediately. For FinTech and Healthcare entities, reviewing API gateway configurations for BOLA vulnerabilities and implementing phishing-resistant MFA (such as FIDO2 keys) is critical to countering the current wave of AI-enhanced attacks.

Contact us for a quote for penetration testing service or adversary simulation.

Read More