Australian Cyber Threat Briefing: Surging Ransomware, AI Exploits, and Critical API Vulnerabilities
As of 17 March 2026, the Australian cyber threat landscape is escalating at an unprecedented pace, driven by highly sophisticated threat actors exploiting novel vulnerabilities across cloud, AI, and API environments. As a senior penetration tester, I spend my days simulating these exact adversary behaviours to uncover weaknesses before they are weaponised. Over the last 24 hours, we have observed a significant uptick in targeted attacks against critical Australian sectors, compounded by the rapid exploitation of newly disclosed Common Vulnerabilities and Exposures (CVEs).
As of 17 March 2026, the Australian cyber threat landscape is escalating at an unprecedented pace, driven by highly sophisticated threat actors exploiting novel vulnerabilities across cloud, AI, and API environments. As a senior penetration tester, I spend my days simulating these exact adversary behaviours to uncover weaknesses before they are weaponised. Over the last 24 hours, we have observed a significant uptick in targeted attacks against critical Australian sectors, compounded by the rapid exploitation of newly disclosed Common Vulnerabilities and Exposures (CVEs).
Here is your daily threat briefing and deep dive into the current risks impacting Australian organisations.
Sector Threat Analysis
Healthcare Healthcare remains the most targeted industry in Australia for both IT and Operational Technology (OT) attacks. We are tracking a joint advisory from the Australian Cyber Security Centre (ACSC) regarding the INC Ransom group, which operates a Ransomware-as-a-Service (RaaS) model and has breached at least 11 Australian organisations recently. Furthermore, the Aeromedical Society of Australasia is currently managing an incident following claims by the LockBit ransomware gang. Threat actors are increasingly using legitimate administrative tools like 7-Zip and rclone to blend into regular network traffic before executing double-extortion campaigns.
FinTech The FinTech sector has been severely impacted by a massive data breach at the alternative lending platform 'youX'. Threat actors exfiltrated 141 GB of highly sensitive data, exposing over 600,000 loan applications—including Australian driver's licences, income details, and residential addresses. This breach was linked to a misconfigured MongoDB Atlas cluster (leveraging CVE-2025-14847) and highlights severe third-party risk management (TPRM) blind spots. Additionally, in a landmark ruling, the Federal Court imposed an AUD$2.5 million penalty on FIIG Securities for cybersecurity governance failures, signalling a shift in regulatory enforcement by ASIC.
SaaS Providers & Government A major supply chain attack has surfaced involving a global legal intelligence SaaS provider, LexisNexis. A threat actor tracked as 'FulcrumSec' successfully breached the provider's AWS environment. This incident has had an immediate flow-on effect, exposing highly sensitive data belonging to Australian law firms and federal government agencies.
eCommerce & Retail Disruptions in digital retail continue to cascade. The Kairos ransomware group recently compromised the Seagrass Boutique Hospitality Group, demonstrating how vulnerabilities in corporate networks can threaten point-of-sale (POS) systems and consumer-facing commerce. Moreover, data from a major Australian poultry processor, Hazeldenes, was published to a dark web leak site following a disruptive attack.
Education / EdTech The Victorian Department of Education is managing the fallout from a major breach impacting 1,700 government schools. New phishing campaigns are actively impersonating the department to target the exposed personal information of current and former students.
IoT (Internet of Things) With the Australian Government's new Cyber Security Rules 2025 for smart devices now in full effect, the regulatory stakes are at an all-time high. On the tactical front, the ACSC has issued critical warnings regarding state-sponsored exploitation of maximum-severity zero-day vulnerabilities in Cisco Catalyst SD-WAN controllers.
Deep Dive: Exploited Vulnerabilities in Web Apps, APIs, Cloud, and AI Systems
Our adversary simulation engagements heavily leverage the convergence of AI, API, and cloud vulnerabilities. Key exploits active in the wild over the last 24 hours include:
- Cloud & Web Applications ("React2Shell"): The SaaS provider breach mentioned above was facilitated by CVE-2025-55182, a critical Unsafe Deserialization vulnerability in React Server Components. The ACSC has warned that this allows unauthenticated Remote Code Execution (RCE) in modern web applications using specific webpack and turbopack packages.
- API & SaaS Automation ("Ni8mare"): A critical RCE vulnerability (CVE-2026-21858, CVSS 10.0) in the popular n8n workflow automation tool is being actively exploited. Attackers are abusing this flaw to execute arbitrary code on underlying servers. Furthermore, CVE-2026-24423 (SmarterMail API) is actively being exploited by ransomware operators due to a missing authentication flaw. According to the latest 2026 API ThreatStats Report, APIs now account for 17% of all published vulnerabilities, with a 36% overlap between AI vulnerabilities and API security flaws.
- AI Developer Tools (Claude Code RCE): Check Point Research recently disclosed critical vulnerabilities (CVE-2025-59536 / CVE-2026-21852) in Anthropic's Claude Code command-line tool. Attackers can achieve RCE and exfiltrate API tokens via malicious project configurations (such as Hooks and Model Context Protocol servers) the moment a developer clones an untrusted repository—requiring zero user interaction.
- AI Frameworks: CVE-2026-25130 is a critical command injection vulnerability affecting the Cybersecurity AI (CAI) framework. Attackers can bypass human-in-the-loop safety mechanisms and achieve RCE by injecting malicious arguments into the pre-approved
find_file()tool. - IoT & Infrastructure: The ACSC has flagged CVE-2026-20127, a critical authentication bypass in Cisco SD-WAN controllers. Threat actors are exploiting this to add rogue peers and establish long-term root persistence within corporate infrastructure.
The Penetration Tester’s Perspective
The barriers to entry for cybercriminals have plummeted. Threat actors are leveraging generative AI to create bespoke malware and automate reconnaissance. However, the most successful breaches we analyse—and replicate during our red team engagements—still stem from fundamental misconfigurations: exposed API endpoints, unsafe deserialization, bypassed multi-factor authentication (MFA) via session hijacking, and vulnerable third-party SaaS integrations.
To defend against these threats, Australian organisations must move beyond compliance-based checklists. You must proactively validate your external attack surface, secure your AI pipelines, and implement runtime enforcement for APIs to detect logic abuse in real-time.
Contact us for a quote for penetration testing service or adversary simulation.
Daily Australian Cyber Threat Briefing: Escalating AI Exploits, Ransomware, and Cloud Breaches
As a senior penetration tester actively analysing adversary behaviour and responding to frontline incidents, I am tracking an exceptionally volatile threat landscape across Australia today, 16 March 2026. Over the past 24 hours, the window between vulnerability disclosure and active exploitation has collapsed from weeks to mere hours. We are observing threat actors aggressively weaponising artificial intelligence, exploiting cloud misconfigurations, and capitalising on critical zero-day vulnerabilities to bypass traditional perimeter defences. With Australia’s mandatory ransomware reporting laws in full enforcement and the new Cyber Security (Security Standards for Smart Devices) Rules 2025 officially active this month, the stakes for Australian organisations have never been higher.
As a senior penetration tester actively analysing adversary behaviour and responding to frontline incidents, I am tracking an exceptionally volatile threat landscape across Australia today, 16 March 2026. Over the past 24 hours, the window between vulnerability disclosure and active exploitation has collapsed from weeks to mere hours. We are observing threat actors aggressively weaponising artificial intelligence, exploiting cloud misconfigurations, and capitalising on critical zero-day vulnerabilities to bypass traditional perimeter defences. With Australia’s mandatory ransomware reporting laws in full enforcement and the new Cyber Security (Security Standards for Smart Devices) Rules 2025 officially active this month, the stakes for Australian organisations have never been higher.
Below is your intelligence briefing on current and emerging cyber threats, prominent threat actors, and new vulnerabilities impacting key Australian sectors.
Sector Threat Analysis
Healthcare & IoT The Australian healthcare sector remains under intense siege from double-extortion ransomware syndicates. Over the last 24 hours, intelligence confirmed that the emerging '0APT' gang and 'Termite' group are actively targeting legacy medical endpoints. Furthermore, a joint advisory from the Australian Cyber Security Centre (ACSC) recently highlighted the INC Ransom group’s aggressive targeting of health networks, using administrative tools like 7-Zip and rclone to stealthily exfiltrate patient data. Adversaries are heavily leveraging unpatched Internet of Things (IoT) devices for initial access. Fortunately, the new mandatory smart device security standards explicitly banning universal default passwords are now actively being enforced nationwide, mitigating severe botnet risks.
SaaS Providers & Government Supply chain vulnerabilities are currently at the forefront of our telemetry. We are tracking the fallout of a major cloud data breach involving global legal intelligence SaaS provider LexisNexis, executed by the threat actor 'FulcrumSec'. This breach compromised an AWS environment, exposing sensitive data tied to federal government agencies and top-tier law firms. Concurrently, the ACSC has issued critical alerts regarding the active, state-sponsored exploitation of Cisco Catalyst SD-WAN controllers (CVE-2026-20127). Attackers are leveraging this authentication bypass to embed persistent backdoors directly into government and enterprise edge networks.
FinTech & eCommerce The financial and retail sectors are facing cascading disruptions. Threat actors have recently published stolen data from major Australian poultry processor Hazeldenes on the dark web, while the Kairos ransomware group disrupted consumer-facing commerce and point-of-sale (POS) systems at the Seagrass Boutique Hospitality Group. In the FinTech space, platform youX suffered a catastrophic data breach, exposing 141 gigabytes of borrower profiles and driver's licences due to a cloud-hosted MongoDB Atlas misconfiguration. Adding to the pressure, ASIC has recently imposed a landmark AUD 2.5 million penalty on a financial services licensee for poor cybersecurity governance, proving that proactive cyber resilience is now a strict regulatory mandate.
Education / EdTech Higher education institutions and EdTech vendors are battling highly sophisticated pre-authentication exploits. We are actively tracking threat actors targeting CVE-2026-1731, a critical Remote Code Execution (RCE) vulnerability in BeyondTrust remote support software. Institutions relying on unsupported, legacy technology lacking modern Zero-Trust architectures and Multi-Factor Authentication (MFA) are providing an open door for initial access brokers.
Exploited Vulnerabilities: Web Apps, APIs, Cloud & AI
Web Applications & APIs Adversaries are deploying automated scripts to map undocumented Shadow APIs, scraping backend databases by exploiting business logic flaws. Additionally, 'FulcrumSec' heavily relied on "React2Shell," a critical vulnerability in an unpatched web application, to breach SaaS environments.
Cloud Deployments Identity has become the new perimeter. We are seeing a surge in identity-driven cloud attacks, specifically targeting misconfigured Azure Entra ID conditional access policies to bypass MFA via Adversary-in-the-Middle (AiTM) phishing kits. The youX MongoDB incident perfectly exemplifies the devastating real-world impact of publicly exposed database clusters and poor Cloud Security Posture Management (CSPM).
AI Systems The convergence of AI and APIs has introduced complex new attack vectors. Most notably, we are tracking the active exploitation of CVE-2026-21858 ("Ni8mare"), a CVSS 10.0 unauthenticated RCE vulnerability in the n8n workflow automation platform—a tool heavily relied upon by SaaS providers to orchestrate APIs and AI agents. Threat actors are also increasingly using AI-powered voice cloning to execute complex payment fraud against Australian businesses. However, as highlighted by recent threat reports, the most immediate AI risk remains internal: staff inadvertently spilling sensitive corporate data and intellectual property into public-facing generative AI models.
Conclusion
As penetration testers, we simulate these exact attack paths daily to uncover critical security gaps. Baseline compliance is no longer sufficient; Australian organisations must adopt an "assume breach" mentality. Ensure your cloud architectures are hardened, your external attack surfaces are monitored, and your incident response plans are rigorously tested.
Contact us for a quote for penetration testing service or adversary simulation.
Australian Daily Threat Briefing: AI Exploits, Ransomware Resurgence, and Zero-Day Fallout
As a senior penetration tester actively analysing adversary behaviour and responding to frontline incidents, I am tracking a highly volatile threat landscape across Australia today. Over the past 24 hours, the window between vulnerability disclosure and active exploitation has collapsed to mere days. We are seeing threat actors rapidly weaponising artificial intelligence, exploiting cloud misconfigurations, and capitalising on critical zero-day vulnerabilities.
As a senior penetration tester actively analysing adversary behaviour and responding to frontline incidents, I am tracking a highly volatile threat landscape across Australia today. Over the past 24 hours, the window between vulnerability disclosure and active exploitation has collapsed to mere days. We are seeing threat actors rapidly weaponising artificial intelligence, exploiting cloud misconfigurations, and capitalising on critical zero-day vulnerabilities.
Here is your deep dive into the threats and exploits impacting Australian organisations today.
Sector Threat Analysis
Healthcare The healthcare sector remains under intense siege. A joint advisory issued on 12 March 2026 by the Australian Cyber Security Centre (ACSC) and international partners warned of escalating attacks by the INC Ransom group. Operating a Ransomware-as-a-Service (RaaS) model, this group has breached at least 11 Australian organisations, heavily targeting healthcare. Threat actors are using legitimate administrative tools like 7-Zip and rclone to blend into normal network traffic before deploying double-extortion tactics. Concurrently, emerging ransomware operators like 0APT and Termite are increasingly applying psychological pressure, threatening to release highly sensitive patient management data to force payments.
SaaS Providers & Government Threat intelligence over the last 24 hours confirmed a major cloud data breach involving a global legal intelligence SaaS provider. A threat actor tracked as 'FulcrumSec' breached the provider's AWS environment by exploiting "React2Shell," a critical vulnerability in an unpatched web application. This supply chain attack has had an immediate flow-on effect, exposing highly sensitive data belonging to Australian law firms and federal government agencies.
eCommerce & Retail Digital retail and physical supply chains are facing cascading disruptions. Just yesterday, 12 March 2026, data stolen from major Australian poultry processor Hazeldenes in a disruptive February attack was published to a dark web leak site. Similarly, the Kairos ransomware group recently hit the Seagrass Boutique Hospitality Group, underscoring how deeply these cyber threats can disrupt point-of-sale (POS) systems and consumer-facing commerce.
FinTech The FinTech sector has been rocked by the massive data breach at alternative lending platform 'youX', which exposed over 600,000 loan applications. Threat actors exfiltrated 141 GB of sensitive data by exploiting a misconfigured MongoDB Atlas cluster linked to the recently disclosed MongoDB Server Leak vulnerability (CVE-2025-14847). Adding to the industry's pressure, the Australian Securities and Investments Commission (ASIC) recently handed down a landmark AUD 2.5 million penalty to FIIG Securities for historical cybersecurity governance failures—proving that proactive cyber resilience is now a strictly enforced regulatory expectation.
Education / EdTech In the education sector, attackers are increasingly bypassing basic Multi-Factor Authentication (MFA) on university and EdTech portals. We are observing a spike in Adversary-in-the-Middle (AiTM) session hijacking, heavily facilitated by the proliferation of low-cost Phishing-as-a-Service (PHaaS) frameworks. Meanwhile, the Victorian Department of Education continues to manage the fallout from a major data breach impacting 1,700 schools, with new phishing campaigns actively impersonating the department.
IoT (Internet of Things) With the Australian Government's new Cyber Security (Security Standards for Smart Devices) Rules 2025 officially commencing earlier this month, the regulatory stakes for IoT have never been higher. On the tactical front, the ACSC has issued urgent warnings regarding the active, state-sponsored exploitation of maximum-severity zero-day vulnerabilities in Cisco SD-WAN controllers (including CVE-2026-20127). Adversaries are leveraging authentication bypass flaws to add rogue peers and establish long-term, root-level persistence in networking environments.
Vulnerability & Technology Deep Dive
- Web Applications & Cloud Environments: The newly weaponised "React2Shell" vulnerability and the MongoDB Server Leak (CVE-2025-14847) are currently the primary vectors for high-impact cloud data exfiltration. Organisations must audit their cloud perimeters and database configurations immediately.
- AI Systems: AI is no longer just a buzzword; it is a dual-use weapon. We are tracking a sophisticated pivot towards AI-enabled API exploitation. The Model Context Protocol (MCP) is emerging as a critical new attack surface, widening the "blast radius" of compromised AI systems. Furthermore, generative AI is actively being used for real-time network mapping and generating deepfake voice clones to bypass payment verification processes in Australian businesses.
Summary
The speed at which adversaries are moving from initial access to full domain compromise and data exfiltration demands a proactive, intelligence-led defence strategy. Relying on basic compliance and outdated MFA is no longer sufficient to secure Australian operations.
Contact us for a quote for penetration testing service or adversary simulation.
Australian Cyber Threat Briefing: AI Weaponisation, API Exploits, and Sector-Wide Targeting
Welcome to today’s daily threat briefing for 13 March 2026. As a senior penetration tester actively analysing adversary behaviour and responding to frontline incidents, I am tracking a highly volatile threat landscape across Australia. The window between vulnerability disclosure and active exploitation has collapsed from weeks to mere days. Over the past 24 hours, we have seen threat actors rapidly weaponising artificial intelligence, exploiting cloud misconfigurations, and capitalising on critical zero-day vulnerabilities.
Welcome to today’s daily threat briefing for 13 March 2026. As a senior penetration tester actively analysing adversary behaviour and responding to frontline incidents, I am tracking a highly volatile threat landscape across Australia. The window between vulnerability disclosure and active exploitation has collapsed from weeks to mere days. Over the past 24 hours, we have seen threat actors rapidly weaponising artificial intelligence, exploiting cloud misconfigurations, and capitalising on critical zero-day vulnerabilities.
Furthermore, with the Australian Government's mandatory ransomware reporting laws in full enforcement and the new Cyber Security (Security Standards for Smart Devices) Rules 2025 officially commencing on 4 March 2026, the regulatory stakes for Australian organisations have never been higher.
Sector Threat Analysis
Healthcare & IoT The healthcare sector remains under intense siege from ransomware syndicates. Recent operations by the 'Termite' ransomware group and the emerging '0APT' gang have severely impacted Australian health networks, with the latter claiming the exfiltration of over 920 GB of highly sensitive patient data from providers like Epworth HealthCare. Adversaries frequently gain an initial foothold by exploiting unpatched, legacy medical Internet of Things (IoT) endpoints. Fortunately, Australia’s mandatory cybersecurity standards for consumer smart devices are now actively enforced, outright banning universal default passwords and mandating vulnerability reporting to help neutralise IoT botnet risks.
SaaS Providers & Government Supply chain vulnerabilities continue to undermine Australian data sovereignty. In the past 24 hours, threat intelligence confirmed a major cloud data breach involving a global legal intelligence SaaS provider, severely impacting Australian law firms and federal government agencies. The threat actor, 'FulcrumSec', breached the provider's AWS environment by exploiting "React2Shell," a critical vulnerability in an unpatched web application. Simultaneously, the Australian Signals Directorate (ASD) and Five Eyes partners have issued urgent warnings regarding the active, state-sponsored exploitation of a maximum-severity zero-day in Cisco SD-WAN controllers (CVE-2026-20127). The advanced threat actor UAT-8616 is leveraging this flaw to plant persistent backdoors directly into government and enterprise edge networks.
FinTech FinTech platforms are experiencing aggressive targeting for data theft. The Australian alternative lending platform 'youX' recently suffered a massive breach exposing over 444,000 loan applications. This compromise was traced back to a severe MongoDB server misconfiguration (CVE-2025-14847). Adding to the pressure, the Australian Securities and Investments Commission (ASIC) recently handed down a landmark AUD 2.5 million penalty to a financial services firm for historical cybersecurity governance failures—proving that proactive cyber resilience is now a strictly enforced regulatory expectation, even in the absence of direct consumer harm.
Education/EdTech Educational institutions and supporting platforms remain highly lucrative targets for extortion. The 'KillSec' ransomware group has actively claimed breaches against the Australian educational support platform Thanks For the Help (TFTH) and the Albright Institute. Attackers are increasingly bypassing basic Multi-Factor Authentication (MFA) on university and EdTech portals using Adversary-in-the-Middle (AiTM) session hijacking, heavily facilitated by the proliferation of low-cost Phishing-as-a-Service (PHaaS) frameworks.
eCommerce Digital retail and supply chains are facing cascading disruptions from double-extortion campaigns. Most notably, data stolen from major Australian poultry processor Hazeldenes in a disruptive February attack was published to a dark web leak site just yesterday, 12 March 2026. Similarly, the Kairos ransomware group recently targeted the Seagrass Boutique Hospitality Group, underscoring how deeply cyber threats can disrupt physical supply chains, point-of-sale systems, and consumer-facing commerce.
Technology Vulnerabilities Focus
- Web Applications & APIs: Threat actors are aggressively scanning for and exploiting vulnerabilities like the newly weaponised "React2Shell" to compromise web applications. Furthermore, unauthenticated API endpoints and authentication bypass flaws remain prime targets for initial access and privilege escalation.
- Cloud Systems: Data leaks from unsecured cloud storage (e.g., MongoDB servers, AWS S3 buckets) continue to be low-hanging fruit for attackers, bypassing traditional perimeter defences entirely.
- AI Systems: We are witnessing an AI cyber arms race. Threat actors are deploying autonomous "agentic" malware and highly convincing AI-generated social engineering lures. Conversely, a major internal risk involves staff accidentally spilling sensitive, classified commercial data into public, unvetted Generative AI tools, violating corporate data governance policies.
To stay ahead of these rapidly evolving threats, organisations must adopt a proactive, offensive security posture. Relying on compliance alone is no longer sufficient; continuous testing of your web applications, APIs, cloud environments, and staff resilience is critical to ensure operational survivability.
Contact us for a quote for penetration testing service or adversary simulation.
Daily Cyber Threat Briefing: AI-Driven Exploitation and API Abuse Surge Across Australia
Welcome to today’s cyber threat briefing for 11 March 2026. As a senior penetration tester analysing the latest adversary behaviour, I am tracking a highly volatile threat landscape across Australia. Over the past 24 hours, our telemetry and incident response data reveal that the window between vulnerability disclosure and active exploitation has collapsed from weeks to mere days. Threat actors are rapidly weaponising artificial intelligence, exploiting misconfigured cloud environments, and capitalising on critical API vulnerabilities.
Welcome to today’s cyber threat briefing for 11 March 2026. As a senior penetration tester analysing the latest adversary behaviour, I am tracking a highly volatile threat landscape across Australia. Over the past 24 hours, our telemetry and incident response data reveal that the window between vulnerability disclosure and active exploitation has collapsed from weeks to mere days. Threat actors are rapidly weaponising artificial intelligence, exploiting misconfigured cloud environments, and capitalising on critical API vulnerabilities.
Regulatory Context Before diving into technical specifics, Australian organisations must recognise a monumental shift in the compliance baseline. The Australian Securities and Investments Commission (ASIC) recently handed down a landmark AUD 2.5 million penalty to an Australian financial services firm for cybersecurity governance failures—proving that cyber resilience is now a strictly enforced regulatory expectation, even without widespread consumer harm. Additionally, as of 4 March 2026, Australia’s mandatory cybersecurity standards for consumer smart devices officially commenced, outright banning universal default passwords and mandating vulnerability reporting to mitigate the risk of IoT botnets.
Sector Threat Analysis
- Healthcare & IoT: The medical sector remains under intense siege from ransomware syndicates. The Australian Cyber Security Centre (ACSC) recently issued a joint advisory regarding the INC Ransom group, which is aggressively targeting health networks across Australia and the Pacific. Adversaries continue to exploit unpatched Internet of Things (IoT) medical devices as an initial foothold, allowing them to move laterally and exfiltrate highly sensitive patient data undetected.
- SaaS Providers & Government: Supply chain vulnerabilities are taking centre stage following a major cloud data breach involving a global legal intelligence SaaS provider, which exposed sensitive client data across multiple Australian federal agencies. Simultaneously, the ACSC has issued critical alerts regarding active, state-sponsored exploitation of Cisco Catalyst SD-WAN controllers (CVE-2026-20127); attackers are using an authentication bypass to embed persistent backdoors directly into government and enterprise edge networks.
- FinTech: The financial technology sector is experiencing aggressive targeting for data theft. Recent breaches, including an incident involving a compromised MongoDB cloud cluster, have exposed hundreds of thousands of customer loan applications.
- eCommerce: Digital retailers are facing cascading disruptions from double-extortion campaigns. Attackers are exploiting logic flaws in inventory and payment gateways, while simultaneously using automated AI tools to execute highly convincing social engineering attacks against eCommerce supply chain partners.
- Education / EdTech: Educational institutions remain prime targets. Threat actors and Initial Access Brokers (IABs) are heavily leveraging AI-driven Phishing-as-a-Service (PHaaS) frameworks to execute Adversary-in-the-Middle (AiTM) attacks. This allows them to seamlessly bypass standard Multi-Factor Authentication (MFA) and harvest the VPN credentials of university staff and students.
Exploited Vulnerabilities: Web Applications, APIs, Cloud, and AI Systems From an offensive security perspective, the techniques leveraged in the last 24 hours highlight a severe maturation in adversary capabilities:
- Web Applications: Attackers are using AI-assisted tools to scan for unpatched public-facing applications at unprecedented speeds. Recent global threat intelligence confirms that over 50% of successfully exploited web vulnerabilities now require zero authentication, highlighting a critical lapse in basic cyber hygiene.
- APIs: We are tracking widespread abuse of Broken Object Level Authorisation (BOLA) vulnerabilities within B2B APIs. These flaws allow unauthorised users to manipulate API requests, bypassing traditional web application firewalls to exfiltrate cross-tenant data.
- Cloud: Cloud exploitation is moving away from credential brute-forcing toward the targeting of third-party software vulnerabilities and misconfigured IAM roles. The exploitation window for these cloud-based vulnerabilities is now measured in days.
- AI Systems: The attack surface for embedded AI tooling is expanding drastically. We are observing active exploitation of integrations like the Model Context Protocol (MCP), where malicious tools can silently collect and exfiltrate a user's entire chat history. Furthermore, "Shadow AI" data exfiltration and prompt injection attacks are heavily utilised to manipulate customer-facing AI agents, leaking backend system prompts and internal routing data.
Conclusion The speed at which adversaries are operationalising exploits means that Australian businesses can no longer rely on static, point-in-time security assessments. Moving beyond baseline compliance to adopt a proactive, "assume breach" mentality is imperative.
Contact us for a quote for penetration testing service or adversary simulation.