Australian Threat Intelligence Briefing: Chrome Zero-Days, Government Gaps & AI Agent Risks
In the last 24 hours, the Australian cyber threat landscape has been dominated by the discovery of an actively exploited Zero-Day in Google Chrome and the release of concerning data regarding government incident reporting. Critical vulnerabilities in SaaS platforms and the escalating weaponisation of AI agents continue to pose significant risks to local organisations.
Executive Summary
In the last 24 hours, the Australian cyber threat landscape has been dominated by the discovery of an actively exploited Zero-Day in Google Chrome and the release of concerning data regarding government incident reporting. Critical vulnerabilities in SaaS platforms and the escalating weaponisation of AI agents continue to pose significant risks to local organisations.
Critical Vulnerability Alert: Google Chrome Zero-Day (CVE-2026-2441)
Sectors Impacted: All (SaaS, Education, Government, FinTech) Google has released an emergency security update to address a high-severity Zero-Day vulnerability (CVE-2026-2441) in the Chrome browser.
- The Flaw: A Use-After-Free vulnerability within the CSS processing component.
- The Risk: Threat actors are actively exploiting this in the wild to execute arbitrary code on victim machines via crafted HTML pages.
- Action Required: Security teams must ensure all instances of Chrome are updated to version 145.0.7632.75 immediately. This also affects Chromium-based browsers used in many enterprise SaaS environments.
Government & Critical Infrastructure: The "Silent" Risk
Sectors Impacted: Government, Critical Infrastructure New data released yesterday highlights a concerning gap in our national cyber resilience. A report tabled in Parliament reveals that a significant number of Federal Government entities are failing to report cyber incidents to the Australian Signals Directorate (ASD).
- Key Insight: Despite 92% of entities claiming "Effective" compliance with the Protective Security Policy Framework (PSPF), actual technology security controls remains a weak point.
- The Threat: The lack of visibility into these "silent" breaches allows state-sponsored actors (such as the persistent Salt Typhoon group) to maintain long-term access to critical networks without detection.
Supply Chain & Third-Party Risk
Sectors Impacted: FinTech, Healthcare, eCommerce New research from BlueVoyant released on 16 February indicates that 99% of Australian organisations have been negatively impacted by a third-party or supply chain breach in the past year.
- The Trend: Attackers are bypassing hardened perimeter defences by targeting smaller, less secure vendors.
- FinTech Warning: This comes in the wake of the historic $2.5 million penalty handed down to FIIG Securities, setting a precedent that governance failures and "tick-box compliance" regarding vendor security will no longer be tolerated by regulators.
Sector-Specific Updates
- Healthcare: The sector remains on high alert following the 0APT gang's claimed attack on Epworth HealthCare. With ransomware groups increasingly using psychological pressure and data exfiltration (surgical records, billing details), data segregation is critical.
- Education/EdTech: The fallout from the Victorian Department of Education breach (impacting 665,000 students) continues to widen. We are observing an increase in phishing campaigns targeting the exposed credentials of students and staff.
- AI Systems: A new frontier of threat has emerged with "AI Agents." Vulnerabilities in platforms like Moltbook (a social media site for AI agents) and the weaponisation of tools like OpenClaw demonstrate that autonomous AI systems are becoming both targets and vectors for attack.
- SaaS & Cloud: BeyondTrust administrators should verify they have patched CVE-2026-1731, a critical pre-authentication remote code execution flaw that has seen rapid exploitation since its disclosure.
Conclusion
The events of the last 24 hours reinforce the need for "assumed breach" mentalities. From unpatched browsers to silent supply chain compromises, the perimeter is porous. Australian organisations must pivot from passive defence to active validation of their security controls.
Contact us for a quote for penetration testing service or adversary simulation.
Threat Briefing: BeyondTrust Critical RCE, Healthcare Under Siege & The $2.5M FinTech Warning
The Australian cybersecurity landscape has shifted dramatically in the last 24 hours. Security teams across the country must urgently prioritise the remediation of a critical remote code execution (RCE) vulnerability in BeyondTrust appliances, which is currently seeing active exploitation. Simultaneously, the healthcare sector faces a fresh wave of extortion attempts from the '0APT' group, and the Federal Court has handed down a landmark $2.5 million penalty to a financial services firm, setting a new precedent for board-level accountability.
Executive Summary
The Australian cybersecurity landscape has shifted dramatically in the last 24 hours. Security teams across the country must urgently prioritise the remediation of a critical remote code execution (RCE) vulnerability in BeyondTrust appliances, which is currently seeing active exploitation. Simultaneously, the healthcare sector faces a fresh wave of extortion attempts from the '0APT' group, and the Federal Court has handed down a landmark $2.5 million penalty to a financial services firm, setting a new precedent for board-level accountability.
Here is your deep dive into the threats impacting Australian organisations over the last 24 hours.
Critical Vulnerability Alert: SaaS & Remote Access
BeyondTrust Remote Support RCE (CVE-2026-1731)
- Threat Level: Critical (Active Exploitation)
- Impact: System Takeover
- Target Sectors: Government, MSPs, Enterprise
A critical pre-authentication command injection vulnerability has been discovered in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) appliances. This flaw allows unauthenticated attackers to inject malicious commands and gain SYSTEM-level access, effectively handing them the keys to the kingdom.
Intelligence: Threat actors—suspected to be state-sponsored—are actively exploiting this to deploy lateral movement tools like AdsiSearcher disguised as legitimate binaries. Given the heavy reliance on BeyondTrust by Australian Managed Service Providers (MSPs) and government agencies, the supply chain risk is severe.
Recommendation: Patch immediately. If patching is not feasible, restrict management interface access to trusted internal IPs only.
Cisco Meeting Management (CVE-2026-20098)
- Threat Level: High
- Impact: Privilege Escalation
Organisations using on-premise collaboration hardware must address a high-severity flaw in Cisco Meeting Management. Disclosed earlier this month and now seeing proof-of-concept circulation, this vulnerability allows authenticated remote attackers to elevate privileges to root.
Sector Intelligence
Healthcare: The '0APT' Ransomware Siege
The assault on Australia’s healthcare sector has intensified. Diabetes WA has been confirmed as the latest casualty, with reports indicating a significant data exfiltration event involving patient records.
This incident follows the 5 February claims by the emerging 0APT ransomware gang, who allege they have stolen 920GB of sensitive data—including surgical records—from the Epworth HealthCare group. While investigations are ongoing, these incidents highlight a ruthlessly effective pivot by adversaries towards psychological pressure tactics, leveraging sensitive health data to force rapid settlement.
FinTech: A $2.5 Million Governance Warning
In a move that should send shockwaves through Australian boardrooms, the Federal Court has ordered FIIG Securities to pay a $2.5 million penalty for failing to adequately protect client data.
This ruling, stemming from a breach that exposed client data to the dark web, reinforces that cybersecurity is no longer just an IT issue—it is a non-negotiable governance obligation. The court found FIIG’s risk management practices insufficient, a verdict that mirrors the Australian Securities and Investments Commission's (ASIC) aggressive new stance on cyber resilience.
Emerging Risk: ASIC has also flagged "Agentic AI" as a key risk for 2026. FinTechs deploying autonomous AI agents for transaction monitoring must guard against manipulation attacks where agents are tricked into authorising fraudulent transfers.
Government & Education: Access Control Failures
The Victorian Department of Education continues to manage the fallout of a significant breach affecting 1,700 schools. Intelligence suggests the initial entry point was not a zero-day exploit, but rather "ghost credentials"—valid accounts that should have been revoked. This aligns with recent ACSC data showing that identity-based attacks now outpace malware infections as the primary vector for public sector compromises.
IoT & Automotive: Privacy Probe Launched
The Australian Privacy Commissioner has launched an investigation into two major automotive manufacturers regarding "spying cars". The inquiry focuses on the unauthorised collection of driver behaviour data—including voice recordings and location history—which is allegedly being sold to third-party advertisers and insurers.
Emerging Threat Landscape
- API Security: Australia is now the region's most targeted nation for API breaches. A new report indicates that 95% of Australian organisations have experienced an API security incident in the last 12 months, with unmanaged "Shadow APIs" providing a backdoor for attackers to bypass perimeter defences.
- n8n Workflow Automation: Users of the n8n automation platform must patch CVE-2026-21858, a critical unauthenticated RCE that allows attackers to execute arbitrary code via crafted workflows.
Action Plan for CISOs
- Patch BeyondTrust and n8n appliances immediately; treat these as emergency changes.
- Review Off-Boarding Processes: The Education breach highlights the danger of dormant accounts. Audit your Active Directory for "ghost credentials" today.
- Brief the Board: Use the FIIG Securities ruling to justify budget requests for governance, risk, and compliance (GRC) tooling.
Contact us for a quote for penetration testing service or adversary simulation.
Daily Threat Briefing: Critical SaaS RCEs & Healthcare Under Siege
In the last 24 hours, the Australian cybersecurity landscape has been dominated by urgent warnings regarding remote access tools and a fresh wave of attacks targeting the healthcare sector. Of particular concern is the active exploitation of a critical vulnerability in BeyondTrust Remote Support, a tool widely used by Australian enterprises and managed service providers (MSPs). Additionally, new reports from the Australian Signals Directorate (ASD) and global bodies highlight the weaponisation of AI agents, reshaping the threat horizon for 2026.
Executive Summary
In the last 24 hours, the Australian cybersecurity landscape has been dominated by urgent warnings regarding remote access tools and a fresh wave of attacks targeting the healthcare sector. Of particular concern is the active exploitation of a critical vulnerability in BeyondTrust Remote Support, a tool widely used by Australian enterprises and managed service providers (MSPs). Additionally, new reports from the Australian Signals Directorate (ASD) and global bodies highlight the weaponisation of AI agents, reshaping the threat horizon for 2026.
1. SaaS & Remote Access: The BeyondTrust Critical RCE
Sector: SaaS, MSPs, Government
Threat Level: Critical (Active Exploitation)
The most significant development overnight is the discovery of a critical pre-authentication command injection vulnerability (CVE-2026-1731) in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) appliances.
- The Threat: Attackers are exploiting this flaw to inject malicious commands without needing credentials. This allows them to gain
SYSTEMlevel access to the appliance, effectively hijacking the "keys to the kingdom" for remote management. - Australian Impact: Given the heavy reliance on BeyondTrust by Australian MSPs and government agencies for secure remote access, this vulnerability presents a massive supply chain risk.
- Observed Activity: Security researchers have observed threat actors—likely state-sponsored—using this flaw to deploy lateral movement tools like
AdsiSearcherandSimpleHelpbinaries, renamed to blend in with legitimate processes. - Action: Organisations must patch immediately. If patching is not possible, restrict access to the management interface to trusted internal IPs only.
2. Healthcare Sector: Diabetes WA & The Data Hemorrhage
Sector: Healthcare
Threat Level: High
The assault on Australia’s healthcare sector continues, with Diabetes WA confirmed as the latest casualty in a string of high-profile breaches.
- The Incident: While details are still emerging, initial reports indicate a significant data exfiltration event. This follows a worrying trend in early 2026 where attackers are aggressively targeting patient management systems and third-party SaaS providers used by clinics.
- Context: This incident comes off the back of the massive MediSecure fallout, reinforcing that health data remains a premium commodity on the dark web. The attackers are not just encrypting data; they are leveraging sensitive health information for double-extortion schemes.
- Emerging Trend: We are seeing a shift from "smash-and-grab" ransomware to "dwell-and-leak" operations, where attackers silently exfiltrate terabytes of data over weeks before triggering alarms.
3. IoT & OT: Critical Infrastructure on High Alert
Sector: Energy, Utilities, IoT
Threat Level: High
Following a disruptive cyber attack on Poland’s energy grid earlier this week, the CISA and ACSC have issued joint warnings regarding Operational Technology (OT) vulnerabilities.
- The Vulnerability: The alert focuses on vulnerabilities in legacy Remote Terminal Units (RTUs) and Human-Machine Interfaces (HMIs) that are common in Australian water and energy utilities.
- The Attack Vector: Threat actors are utilising "living off the land" techniques—using pre-installed, legitimate administration tools—to manipulate OT controls, making detection by standard IT security tools incredibly difficult.
- Local Relevance: Australian critical infrastructure operators are urged to segregate OT networks from IT environments and enforce strict read-only access where possible.
4. AI & Emerging Tech: The Rise of Autonomous Attack Agents
Sector: All Sectors (focus on EdTech/FinTech)
Threat Level: Emerging
As discussions from Safer Internet Day 2026 conclude, a new reality is setting in: AI is no longer just a tool for drafting emails; it is an autonomous threat actor.
- AI Agents: Security firms have reported the first wild instances of "autonomous AI attack agents." These are AI-driven scripts capable of self-healing and pivoting. If an attack path is blocked, the AI agent autonomously rewrites its code or tries a different exploit chain without human intervention.
- Target: EdTech and FinTech platforms are seeing the highest volume of these attacks, likely due to the rich datasets they hold and the complex API ecosystems they rely on.
- Defence: Traditional static rules (WAFs) are failing against these adaptive threats. Behavioural analysis and "identity-first" security models are now the baseline requirement.
Actionable Intelligence for Australian CISOs
- Audit Remote Access: Immediately verify the version of any BeyondTrust appliances in your environment. Treat unpatched internet-facing instances as compromised.
- Review Third-Party Risk: For healthcare providers, demand immediate assurance from SaaS vendors regarding their data handling and breach notification processes.
- Segregate OT/IoT: Ensure your operational technology is air-gapped or strictly firewalled from your corporate network.
- Monitor for Anomalies: With AI agents in the wild, look for "impossible travel" or erratic behaviour in API traffic that standard signature-based detection might miss.
Contact us for a quote for penetration testing service or adversary simulation.
Daily Threat Briefing: Australia – 13 February 2026
The last 24 hours in the Australian cyber threat landscape have been dominated by the escalating weaponisation of Generative AI, significant regulatory enforcement in the financial sector, and critical vulnerabilities in widely used SaaS automation tools. Nation-state actors, particularly the group identified as Salt Typhoon, continue to persistently target critical infrastructure, while the healthcare and education sectors face a fresh wave of data extortion campaigns.
Executive Summary
The last 24 hours in the Australian cyber threat landscape have been dominated by the escalating weaponisation of Generative AI, significant regulatory enforcement in the financial sector, and critical vulnerabilities in widely used SaaS automation tools. Nation-state actors, particularly the group identified as Salt Typhoon, continue to persistently target critical infrastructure, while the healthcare and education sectors face a fresh wave of data extortion campaigns.
Sector-Specific Updates
Healthcare The sector remains under heavy fire. Diabetes WA has been identified as the latest victim of a cyber attack, with reports emerging of sensitive patient data exfiltration. This incident follows closely on the heels of the attack on an Adelaide women’s health clinic earlier this year. Furthermore, security researchers have flagged a disturbing trend of AI-generated deepfake advertisements impersonating leading Australian medical specialists to promote fraudulent supplements, posing a significant public health and trust risk.
FinTech & Financial Services A landmark regulatory precedent has been set. The Federal Court has ordered Fiig Securities to pay a $2.5 million penalty for cybersecurity failures that left client data exposed. This is a clear signal to the FinTech sector that inadequate cyber resilience will incur severe financial and reputational costs. Additionally, CommBank research released this week highlights that while 89% of Australians feel confident spotting scams, only 42% can actually distinguish AI-generated banking fraud, signalling a need for stronger biometric anti-spoofing measures in banking apps.
Education / EdTech The education sector is currently a primary target for ransomware groups. The Albright Institute of Language and Business has been hit by a cyber attack claimed by the threat actor KillSec, who allege to have stolen personal and business data. This incident compounds the ongoing fallout from the massive Victorian Department of Education data breach confirmed late last month, which impacted all 1,700 government schools.
Government & Critical Infrastructure A new report reveals a critical visibility gap: only 35% of federal entities fully reported cyber incidents to the Australian Signals Directorate (ASD) in the last financial year. This underreporting hampers national situational awareness. Meanwhile, intelligence reports confirm that Salt Typhoon, a sophisticated China-linked threat actor, has been actively compromising Australian critical networks by exploiting vulnerabilities in edge devices (routers and firewalls) to maintain long-term stealthy persistence.
SaaS Providers A Critical severity vulnerability (CVE-2026-21858) in the n8n workflow automation platform is being actively exploited. This Unauthenticated Remote Code Execution (RCE) flaw allows attackers to take full control of automation servers. SaaS providers and users utilising n8n for backend workflows must patch immediately. Additionally, unsecure MongoDB instances continue to be a vector for data leaks, with a new wave of automated attacks identifying exposed databases globally.
eCommerce With Valentine's Day approaching, the Australian Federal Police (AFP) and KnowBe4 have issued urgent warnings regarding "industrial-scale" romance scams powered by deepfake video and voice technology. These AI agents can hold real-time video calls, bypassing traditional "proof of life" checks used by dating and eCommerce platforms to verify user identity.
IoT (Internet of Things) The threat surface for IoT is expanding through "agentic AI". New analysis suggests that AI agents, capable of autonomous decision-making and interacting with IoT devices, are being weaponised to launch attacks at machine speed. Attackers are moving away from simple malware to "living off the land" techniques on compromised IoT edge devices to evade detection.
Technical Deep Dive: Exploited Vulnerabilities
- CVE-2026-21858 (n8n RCE): Exploitation is trivial and unauthenticated. Attackers are using this to inject malicious workflows that execute system commands, effectively turning automation servers into botnet nodes or crypto miners.
- Edge Device Compromise: Threat actors like Salt Typhoon are exploiting legacy vulnerabilities in Cisco and Fortinet edge devices to deploy custom rootkits. These rootkits survive firmware upgrades and allow traffic mirroring, enabling espionage without touching the internal endpoints.
Strategic Recommendations
Organisations must urgently pivot from passive defence to active validation. The rise of deepfakes renders standard identity verification obsolete; consider implementing challenge-response authentication for high-value transactions. For SaaS and Cloud environments, immediate patching of automation tools like n8n and rigorous review of MongoDB access controls are mandatory. Finally, government agencies must improve incident reporting pipelines to the ASD to ensure a coordinated national defence.
Contact us for a quote for penetration testing service or adversary simulation.
Daily Threat Briefing: Australia – 12 February 2026
The Australian cyber threat landscape for the last 24 hours has been dominated by a concerning breach of the national Early Warning Network (EWN) and a historic regulatory penalty in the FinTech sector. These events signal a shift from pure data theft to systemic disruption and regulatory accountability. Simultaneously, technical teams must urgently address critical vulnerabilities in AI agents and workflow automation tools that are being actively exploited in the wild.
Executive Summary
The Australian cyber threat landscape for the last 24 hours has been dominated by a concerning breach of the national Early Warning Network (EWN) and a historic regulatory penalty in the FinTech sector. These events signal a shift from pure data theft to systemic disruption and regulatory accountability. Simultaneously, technical teams must urgently address critical vulnerabilities in AI agents and workflow automation tools that are being actively exploited in the wild.
Here is your deep dive into the threats impacting Australian organisations over the last 24 hours.
Sector Spotlight
Government & Critical Infrastructure: Trust Under Fire In a disturbing development confirmed yesterday (11 February), the Early Warning Network (EWN)—used by councils and emergency services to alert Australians to disasters—suffered a security breach. Threat actors gained unauthorised access to the broadcasting portal, sending false alerts to a subset of subscribers. While EWN officials state that only "white page" data (names and addresses) was accessed, the incident highlights a critical vulnerability in our national notification infrastructure. The ability for adversaries to hijack trusted communication channels poses a severe risk to public safety and trust.
FinTech: A $2.5 Million Warning The Federal Court has handed down a landmark penalty against fixed-income specialist FIIG Securities, ordering them to pay $2.5 million for cybersecurity failures related to a 2023 breach. This is the first time civil penalties have been applied purely for cyber resilience failures under Australian Financial Services (AFS) licence obligations. The court cited a lack of multi-factor authentication (MFA) and inadequate incident response testing. Key Takeaway: For Australian FinTechs, "tick-box" compliance is dead. The ASIC 2026 Outlook, released last week, explicitly flags "Agentic AI" fraud as the next frontier, warning that autonomous AI agents could be manipulated to authorise fraudulent transactions.
Healthcare: Psychological Warfare Epworth HealthCare remains in a standoff with the 0APT ransomware gang, which claims to have exfiltrated 920GB of sensitive surgical and billing records. As of today, Epworth maintains there is "no verified evidence" of the breach, suggesting this may be a "phantom" extortion attempt—a growing tactic where gangs bluff to force a payout. This follows the MediSecure fallout, reinforcing the immense pressure on the sector.
Education: The Long Tail of Breach The Victorian Department of Education is managing the escalating fallout of a massive breach confirmed in January, now known to impact all 1,700 government schools. Additionally, Loyola College is dealing with a confirmed ransomware attack by the Interlock gang, who have leaked nearly 600GB of data, including student passports, to the dark web.
Vulnerability Watch: What to Patch Now
1. AI Systems: OpenClaw 1-Click RCE (CVE-2026-25253) A critical vulnerability has been disclosed in OpenClaw (formerly Moltbot), a popular open-source AI agent used by developers. The flaw allows unauthenticated remote code execution (RCE) via a single malicious link.
- Risk: Attackers can steal authentication tokens and hijack the AI agent to execute commands on the host machine.
- Status: Active exploitation observed. Patch immediately to version 2026.1.29 or later.
2. SaaS & Cloud: Microsoft Office Zero-Day (CVE-2026-21509) Microsoft has issued an out-of-band patch for a "Security Feature Bypass" vulnerability in Office 365 and Office 2019/2021.
- Risk: Allows attackers to bypass the "Mark of the Web" and Protected View, enabling malicious macros to run without user warning.
- Intel: This is being actively exploited by state-sponsored actor APT28 (Fancy Bear) in campaigns targeting government and critical sectors.
3. Workflow Automation: n8n RCE (CVE-2026-21858) A critical RCE vulnerability in n8n, a workflow automation tool used to glue together SaaS apps, is being targeted. If you self-host n8n, ensure it is behind a VPN or strictly authenticated, as it often holds API keys for your entire SaaS stack (Salesforce, Slack, Google Workspace).
Strategic Outlook
The events of the last 24 hours confirm that we are entering an era of "Cyberthuggery"—where disruption and psychological pressure (as seen with Epworth and EWN) are becoming as valuable to attackers as data theft. With the launch of the Essential Eight Certification service yesterday, organisations have a new mechanism to prove their resilience, but compliance must be backed by genuine defensive depth.
Contact us for a quote for penetration testing service or adversary simulation.