Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Cyber Threat Briefing: Australia’s Digital Landscape Under Siege

As we analyse the cyber threat landscape for the last 24 hours, Australian organisations are facing a convergence of sophisticated ransomware campaigns, rapid exploitation of AI vulnerabilities, and targeted scams against individuals. The Australian Signals Directorate (ASD) and industry leaders have flagged critical developments affecting the Healthcare, SaaS, and Government sectors.

As we analyse the cyber threat landscape for the last 24 hours, Australian organisations are facing a convergence of sophisticated ransomware campaigns, rapid exploitation of AI vulnerabilities, and targeted scams against individuals. The Australian Signals Directorate (ASD) and industry leaders have flagged critical developments affecting the Healthcare, SaaS, and Government sectors.

Here is your daily deep dive into the threats shaping our digital environment.

Healthcare Sector: Ransomware Resurgence

The healthcare sector remains the prime target for financially motivated threat actors. In the last 24 hours, Epworth HealthCare has become the focus of a significant security incident. The newly emerged ransomware group, 0APT, has claimed responsibility for a breach, alleging the theft of 920GB of data, including sensitive patient databases.

While Epworth HealthCare has stated there is currently "no verified evidence" of the exfiltration, this incident highlights a disturbing trend. The ASD’s Annual Cyber Threat Report 2024-2025 revealed that ransomware incidents in healthcare have doubled year-on-year, with attackers achieving a 95% success rate in this sector—significantly higher than the national average.

Action Item: Healthcare providers must urgently review their data egress monitoring and validate backup immutability.

SaaS and Cloud: Critical Vulnerabilities Exploited

SaaS providers and organisations relying on workflow automation are under immediate threat from a critical Remote Code Execution (RCE) vulnerability.

  • n8n Workflow Automation (CVE-2026-21858): A critical vulnerability (CVSS 10.0) is being actively exploited, allowing unauthenticated attackers to execute arbitrary code and access sensitive files. Given the widespread use of n8n for integrating APIs and services, this poses a severe supply chain risk.
  • Fortinet Cloud SSO: Security teams should also be aware of active exploitation attempts targeting the FortiCloud Single Sign-On (SSO) mechanism (CVE-2025-59718). Attackers are bypassing authentication to access customer devices, emphasising the fragility of identity management systems in the cloud.

AI Systems: The 16-Minute Window

Artificial Intelligence is no longer just a tool for defenders; it is a vulnerable attack surface. A startling report released this week by Zscaler indicates that enterprise AI systems are being compromised at "machine speed."

Red team exercises revealed that 100% of tested enterprise AI systems contained critical flaws, with attackers able to compromise these systems in an average of just 16 minutes. The primary vectors include:

  • Exposed Model Endpoints: Lack of authentication allowing unauthorised queries.
  • Prompt Injection: Manipulating AI logic to bypass safety rails.
  • Insecure API Integrations: AI agents with excessive permissions writing to production systems.

FinTech & eCommerce: "Digital Arrest" Scams

The financial sector is seeing a rise in sophisticated social engineering attacks. A "Digital Arrest" scam has surfaced prominently in Sydney, where victims are coerced by fraudsters posing as officials from the Indian High Commission or federal police. These attackers use high-pressure tactics, claiming involvement in money laundering, to siphon funds via cryptocurrency and bank transfers.

For eCommerce and FinTech platforms, the risk lies in identity fraud and account takeovers (ATO), as criminals leverage stolen data from other breaches to bypass verification checks.

Government & IoT: Infrastructure Risks

The Australian Government and critical infrastructure operators continue to mitigate legacy risks that remain active. The ASD has reiterated warnings regarding WatchGuard Firebox devices (CVE-2025-14733), which are seeing continued exploitation attempts.

Furthermore, the rise of "Shadow API" vulnerabilities—unmanaged and invisible API endpoints—is creating blind spots for government agencies. These endpoints are frequently targeted to bypass access controls (IDOR vulnerabilities), leading to unauthorised data exposure.

Summary of Critical Vulnerabilities

CVE ID Severity Description Target
CVE-2026-21858 Critical (10.0) Unauthenticated RCE in n8n workflow automation. SaaS / Cloud
CVE-2025-59718 Critical Authentication Bypass in FortiCloud SSO. Cloud / NetSec
CVE-2025-14733 High Exploitation of WatchGuard Firebox devices. Network / IoT

Conclusion

The events of the last 24 hours demonstrate that speed is the adversary's greatest weapon. From the 16-minute compromise time of AI systems to the rapid weaponisation of the n8n vulnerability, Australian organisations must move from reactive patching to proactive continuous exposure management.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Australian Cyber Threat Briefing: AI Agents Hijacked and Critical RCEs Targeting Enterprise

Good morning, Australia. As we analyse the threat landscape for the last 24 hours, it is clear that 2026 is shaping up to be the year where "Agentic AI" risks move from theoretical to catastrophic. Today's briefing highlights a massive exposure in the AI ecosystem, critical zero-days continuously exploited by state-sponsored actors, and a glaring privacy failure in the Australian property sector.

Good morning, Australia. As we analyse the threat landscape for the last 24 hours, it is clear that 2026 is shaping up to be the year where "Agentic AI" risks move from theoretical to catastrophic. Today's briefing highlights a massive exposure in the AI ecosystem, critical zero-days continuously exploited by state-sponsored actors, and a glaring privacy failure in the Australian property sector.

Here is your daily deep dive into the threats mattering most to Australian organisations today.

🚨 Top Story: The "Moltbook" AI Agent Leak

Sectors Impacted: SaaS, AI, EdTech, FinTech

Over the last 24 hours, the cybersecurity community has been rocked by the exposure of Moltbook, a platform dubbed the "Reddit for AI Agents." A misconfigured database left 150,000 AI Agent API keys and login tokens publicly accessible.

  • The Threat: This is not just a data breach; it is an identity breach for autonomous systems. Attackers can use these stolen keys to hijack AI agents, forcing them to execute fraudulent transactions, exfiltrate sensitive corporate data, or launch phishing attacks from "trusted" AI accounts.
  • Why it Matters: If your organisation is integrating third-party AI agents or building "Vibe Coding" projects without rigorous security audits, you are likely exposed. This incident underscores the critical need for Non-Human Identity Management (NHIM).

🔍 Sector-Specific Threat Intelligence

Government & Critical Infrastructure

  • Operation Neusploit (APT28): Russian state-sponsored actors are actively exploiting a zero-day in Microsoft Office (CVE-2026-21509).
    • Attack Vector: Malicious RTF documents.
    • Impact: This vulnerability allows remote code execution (RCE) on unpatched systems. Despite Microsoft rushing a patch late last month, exploitation rates have surged in the last 48 hours targeting government entities and defence contractors.
    • NSW Strategy Update: On a positive note, the NSW Government has released a new cyber strategy mandating 24-hour incident reporting and a "secure-by-design" approach. We expect federal agencies to follow suit shortly.

SaaS & eCommerce (Mobile Focus)

  • React Native "Metro4Shell" (CVE-2025-11953): A critical RCE vulnerability (CVSS 9.8) in the React Native CLI is being exploited in the wild.
    • The Risk: Many Australian eCommerce and FinTech mobile apps rely on this framework. Threat actors are using this flaw to deliver base64-encoded PowerShell scripts, bypassing Defender to execute arbitrary commands.
    • Action: DevSecOps teams must verify their build pipelines and dependencies immediately.

Healthcare & Real Estate

  • Property Data Exposed: A new report from Guardian Australia has revealed that major Australian rental platforms are exposing millions of lease documents via predictable, non-authenticated URLs.
    • Relevance: While this hits Real Estate directly, the methodology (Insecure Direct Object Reference or IDOR) is rampant in Healthcare patient portals and EdTech platforms.
    • Check: Ensure your web applications enforce strict authorisation checks on every document access request. "Security through obscurity" (randomised URLs) is not security.

Enterprise & IoT

  • Ivanti EPMM Zero-Days (CVE-2026-1281 & CVE-2026-1340): CISA has set a deadline of this week for federal agencies to patch these critical code injection vulnerabilities.
    • Impact: Unauthenticated attackers can execute commands on Endpoint Manager Mobile gateways. This is a primary vector for lateral movement into IoT networks and corporate mobile fleets.

đź›  Technical Vulnerability Watchlist

CVE ID Severity Description Status
CVE-2026-21858 Critical n8n Workflow Automation RCE. Unauthenticated attackers can access sensitive files and execute code. Exploited in Wild
CVE-2026-21509 High Microsoft Office RCE. Exploited by APT28 via RTF files. Patch Immediately
CVE-2025-11953 Critical React Native CLI RCE. Impacting mobile app supply chains. Active Attacks

🛡️ Recommendations for CISOs & Security Teams

  1. Rotated AI Secrets: If your teams use Moltbook or similar "Agentic" platforms, rotate all associated API keys immediately.
  2. Hunt for RTF Files: Block .rtf attachments at the email gateway or enforce strict sandboxing until the Microsoft patch (CVE-2026-21509) is verified across your fleet.
  3. Audit Web Assets for IDOR: The rental platform leak is a wake-up call. Test your APIs to ensure that changing a document ID in the URL does not grant access to another user's data.

The speed at which AI agents are being compromised and weaponised is the defining challenge of 2026. Do not let your automated workforce become an adversary's entry point.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: AI Agents Exposed, NSW's New Cyber Mandate, and Real Estate Risks

Good morning. Here is your daily deep dive into the Australian cyber threat landscape for the last 24 hours. Today’s briefing highlights a critical security failure in the emerging "AI Agent" economy, a major shift in NSW government compliance, and new vulnerabilities targeting widely used developer tools.

Good morning. Here is your daily deep dive into the Australian cyber threat landscape for the last 24 hours. Today’s briefing highlights a critical security failure in the emerging "AI Agent" economy, a major shift in NSW government compliance, and new vulnerabilities targeting widely used developer tools.

Top Story: The "Moltbook" Breach & The Risks of 'Vibe Coding'

In a significant wake-up call for the AI and SaaS sectors, Moltbook—a social network designed exclusively for AI agents to interact—has suffered a major security breach. Security researchers at Wiz revealed that the platform inadvertently exposed the private messages, email addresses, and credentials of over 6,000 human owners.

  • The Root Cause: The breach has been attributed to "vibe coding"—the practice of rapidly assembling software using AI coding assistants without rigorous security auditing. The platform lacked basic database protections, allowing unrestricted access to sensitive agent-to-agent communications.
  • Impact: This incident underscores a critical new attack surface: Non-Human Identities (NHIs). As organisations deploy autonomous AI agents to handle tasks, these agents become prime targets for credential theft and data exfiltration.

Government & Compliance: NSW Unveils New Cyber Strategy

The New South Wales Government has released its updated Cyber Security Strategy, introducing stricter obligations for managed service providers (MSPs) and partners.

  • Key Change: Partners providing services to NSW government entities must now align with state emergency plans and adhere to a 24-hour mandatory reporting window for cyber incidents.
  • Strategic Shift: The policy moves away from "tick-box compliance" towards continuous, evidence-based risk management. For SaaS and IT providers serving the public sector, immediate visibility and incident response integration are no longer optional—they are contractual necessities.

Sector Watch

Real Estate & Property A new investigation has flagged major data leak risks across Australian real estate leasing platforms. With the rental market under pressure, these platforms hold vast amounts of PII (passports, financial statements). Vulnerabilities in their APIs and improper access controls are leaving applicants' data exposed to scraping and identity theft.

FinTech & Business Services Nikkei, the parent company of the Financial Times, confirmed a breach exposing over 17,000 employees and partners. The attack vector? Compromised internal Slack workspaces. This serves as a stark reminder for FinTech firms: collaboration tools are a critical entry point. If your Slack or Teams environment is not monitored for anomalous behaviour, you are flying blind.

Healthcare The healthcare sector remains the most aggressively targeted industry in Australia. Recent reports from the Office of the Australian Information Commissioner (OAIC) indicate a continued surge in data breach notifications. The primary vector remains credential compromise and phishing, targeting overworked staff to gain entry into patient record systems.

Vulnerability Watch

  • Notepad++ Malware Injection: The popular text editor Notepad++ has been compromised. Hackers have injected malware into the software distribution, targeting developers and IT administrators. Action: Verify checksums immediately and block unverified downloads.
  • Fortinet (CVE-2026-24858): A critical Authentication Bypass vulnerability in FortiOS, FortiManager, and FortiAnalyzer is being actively exploited. If you utilise Fortinet infrastructure, ensure you have patched to the latest January 2026 release immediately.
  • n8n Workflow Automation (CVE-2026-21858): A critical Remote Code Execution (RCE) flaw in this workflow automation tool remains a high-priority fix, especially for organisations automating backend API tasks.

Emerging Threat: DeepSeek V4 & AI Sovereignty

While the Australian government banned the DeepSeek app from official devices last year, the release of DeepSeek V4 is reigniting the debate around AI sovereignty. The low-power, high-efficiency model is gaining traction in the private sector. Security leaders must evaluate the data privacy implications of integrating non-Western AI models into their corporate stacks, particularly regarding data residency and censorship risks.


Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: AI Model Hosting Abuse & New SSO Phishing Campaigns

In the last 24 hours, the Australian cyber threat landscape has been dominated by sophisticated abuse of AI infrastructure and targeted identity attacks. A new report released today highlights how threat actors are weaponising legitimate AI hosting platforms to distribute malware, bypassing traditional perimeter defences. Simultaneously, the FinTech and SaaS sectors are facing a resurgence of human-led phishing campaigns targeting Single Sign-On (SSO) credentials.

Executive Summary

In the last 24 hours, the Australian cyber threat landscape has been dominated by sophisticated abuse of AI infrastructure and targeted identity attacks. A new report released today highlights how threat actors are weaponising legitimate AI hosting platforms to distribute malware, bypassing traditional perimeter defences. Simultaneously, the FinTech and SaaS sectors are facing a resurgence of human-led phishing campaigns targeting Single Sign-On (SSO) credentials.

This briefing covers critical developments impacting Healthcare, Education, Government, and the SaaS supply chain.


Emerging Threats & Attack Vectors

1. AI Systems: Hugging Face Weaponised for Malware Distribution

Sectors: eCommerce, Technology, General Threat Actor: Unknown / Cybercrime Groups

A significant development reported today involves the abuse of Hugging Face, a popular platform for hosting machine learning models. Researchers at Bitdefender have identified a campaign where attackers are using the platform to host and distribute a malicious Android Remote Access Trojan (RAT) disguised as a security app called "TrustBastion".

  • The Attack: Users are lured via deceptive advertisements warning of device infection. The malicious app, once installed, fetches its payload directly from a Hugging Face repository.
  • Why it Matters: By hosting malware on a trusted domain like Hugging Face, attackers can evade standard network filtering and reputation-based blocking used by many Australian enterprises. This represents a dangerous evolution in "Living off the Land" tactics, now extending to AI infrastructure.

2. SaaS & FinTech: ShinyHunters Targeting Okta SSO

Sectors: FinTech, SaaS Providers Threat Actor: ShinyHunters / SLSH Alliance

New intelligence from Silent Push indicates a large-scale, human-led phishing campaign targeting Okta Single Sign-On (SSO) accounts. Unlike automated credential stuffing, this campaign employs "vishing" (voice phishing) and real-time social engineering to bypass Multi-Factor Authentication (MFA).

  • Targets: High-value targets in FinTech (payment processors) and SaaS platforms.
  • Impact: Successful compromise allows threat actors to pivot into corporate dashboards, accessing sensitive customer data and financial systems. This is a critical alert for any organisation relying on federated identity providers.

Sector-Specific Updates

Education: Victorian Schools Targeted

Reports have surfaced regarding a cyber incident affecting Victorian schools, disrupting IT networks and raising concerns over student data privacy. This follows a trend of increasing ransomware pressure on the Australian education sector, where legacy systems often struggle to repel modern "big game hunting" tactics.

Government: NSW Overhauls Cyber Emergency Plan

In response to the escalating threat environment, the NSW Government has announced a major overhaul of its state cyber emergency plan. The new framework mandates that government agencies report incidents to Cyber Security NSW within 24 hours and introduces stricter "Crown Jewel" asset management plans. This regulatory shift underscores the need for public sector agencies to move from compliance-based security to active resilience.

Healthcare: Persistent Data Risks

The healthcare sector remains a primary target. Following a series of breaches affecting providers like Diabetes WA and DBG Health over the past year, the Australian healthcare industry is being urged to adopt "secure by design" principles. The monetisation of medical records on the dark web continues to drive ransomware activity against clinics and support organisations.


Critical Vulnerabilities (CVEs)

Penetration testers and sysadmins should prioritise the following vulnerabilities which are relevant to Australian infrastructure:

  • n8n Workflow Automation (CVE-2026-21858): A Critical unauthenticated Remote Code Execution (RCE) vulnerability in the n8n platform. As this tool is widely used by SaaS providers and internal dev teams for automation, it represents a high-risk entry point. Patch immediately.
  • Cisco Network Infrastructure: The Australian Cyber Security Centre (ACSC) and WA Cyber Security Unit have issued alerts regarding critical vulnerabilities in Cisco appliances (Reference: 20260127001). Organisations should verify their patch status for edge devices.

Recommendations

  1. Block Unsanctioned AI Repositories: Review network egress and ingress policies for AI model hosting sites (e.g., Hugging Face) if they are not required for business operations, or inspect traffic for executable anomalies.
  2. Hardening SSO: Move beyond SMS/Voice MFA. Implement FIDO2/WebAuthn hardware keys where possible to mitigate the risk of real-time phishing and vishing attacks targeting Okta users.
  3. Audit Automation Tools: specifically scan for exposed n8n instances and ensure they are behind a VPN or strictly authenticated.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Australia Cyber Threat Briefing: Network Assaults Outpace Malware & AI Privacy Shifts

The Australian cyber threat landscape has undergone a distinct shift in the last 24 hours. New intelligence released yesterday indicates that threat actors are moving away from traditional malware infections, favouring direct network-based attacks to exploit exposed edge infrastructure. As Australian organisations race to integrate AI, privacy governance is struggling to keep pace, creating new blind spots in real-time data protection.

Executive Summary The Australian cyber threat landscape has undergone a distinct shift in the last 24 hours. New intelligence released yesterday indicates that threat actors are moving away from traditional malware infections, favouring direct network-based attacks to exploit exposed edge infrastructure. As Australian organisations race to integrate AI, privacy governance is struggling to keep pace, creating new blind spots in real-time data protection.

This briefing covers the critical developments from 29–30 January 2026, focusing on a critical RCE vulnerability in automation tools, the evolving tactics targeting our Education and Healthcare sectors, and the rise of "living off the land" network assaults.


Sector-Specific Threat Intelligence

1. SaaS & Cloud Providers: The Automation Risk

  • Critical Vulnerability (Active Exploitation): A critical Remote Code Execution (RCE) vulnerability has been identified in the n8n workflow automation platform (tracked as CVE-2026-21858).
    • The Threat: With a CVSS score of 10.0, this flaw allows unauthenticated attackers to execute arbitrary code on the server.
    • Relevance: Many Australian FinTechs and SaaS startups utilise n8n for backend automation. Threat actors are actively scanning for exposed instances to gain initial access and pivot into cloud environments.
    • Action: Patch immediately to the latest version. If patching is not possible, isolate the instance behind a VPN or WAF immediately.

2. General Enterprise & Government: Network Attacks Surge

  • Breaking News: A report released yesterday highlights a significant divergence in Australia’s threat profile compared to the APAC region. While Asia continues to battle malware, Australia has seen network-based attacks outpace malware incidents by over 11 to 1 in the last quarter.
  • Analysis: Attackers are no longer relying on users clicking phishing links. Instead, they are aggressively scanning for misconfigured firewalls, exposed RDP ports, and unpatched edge devices (like the recent WatchGuard Firebox flaws).
  • Impact: Government agencies and enterprises with large, legacy footprints are prime targets for these "smash-and-grab" entry attempts.

3. Education & EdTech: The Third-Party Trap

  • Current Trend: While ransomware attacks on the Education sector have plateaued moving into 2026 (rising only 2% year-on-year), the vector has changed.
  • The Shift: Attackers are bypassing university firewalls by targeting third-party vendors—such as timetable scheduling software, HVAC management, and library systems.
  • Warning: EdTech providers must rigorously audit their API security, as they are now the preferred backdoor into major university networks.

4. Healthcare: Persistent Data Extortion

  • Ongoing Threat: Following the major breaches of 2025 (including the O&G Adelaide incident), the healthcare sector remains the primary target for double-extortion ransomware.
  • Tactic: Threat actors are increasingly using "fileless" attacks to exfiltrate patient data without triggering antivirus alarms, leveraging legitimate administrative tools (PowerShell, WMI).
  • Defence: Behavioural monitoring is critical. Static antivirus is no longer sufficient to stop these intrusions.

5. AI Systems: The "Real-Time" Governance Gap

  • Emerging Risk: With the rapid adoption of AI agents in customer service and internal data retrieval, a new vulnerability class has emerged: Contextual Data Leakage.
  • Insight: Security leaders warned yesterday that traditional "point-in-time" privacy checks are failing. AI agents often retain access to sensitive data (PII) longer than necessary or retrieve it for unauthorised users due to vague prompt permissions.
  • Recommendation: Implement "Real-time Access Control" for AI models to ensure they verify user permissions before retrieving data, not just at the login stage.

Technical Focus: Exploited Vulnerabilities

  • n8n Workflow Automation (CVE-2026-21858): [CRITICAL] Unauthenticated RCE.
  • WatchGuard Firebox (CVE-2025-14733): Continued exploitation of unpatched firewalls in the SMB sector.
  • MongoDB (CVE-2025-14847): Attackers are still hunting for unpatched MongoDB servers exposed to the internet to scrape data for extortion.

Conclusion

The events of the last 24 hours serve as a stark reminder: perimeter defence is not enough. With network scanning reaching unprecedented levels and automation tools becoming liabilities, Australian organisations must adopt a "assume breach" mentality. Ensure your edge devices are patched, your third-party vendors are vetted, and your AI systems are governed by strict real-time access controls.

Contact us for a quote for penetration testing service or adversary simulation.

Read More