Weekly Threat Briefing Lean Security Expert Weekly Threat Briefing Lean Security Expert

Weekly Threat Briefing: Zero-Days Hit Apple & SolarWinds, NSW Health Under Pressure

This week in Australian cyber security, the threat landscape is dominated by critical zero-day exploitations affecting widely used infrastructure. Federal agencies and private sector organisations are on high alert following CISA’s inclusion of new vulnerabilities in the Known Exploited Vulnerabilities (KEV) catalogue. Locally, the healthcare sector remains under intense scrutiny following the release of a concerning audit of NSW Health’s cyber posture, while SaaS and AI-driven threats continue to evolve.

Executive Summary

This week in Australian cyber security, the threat landscape is dominated by critical zero-day exploitations affecting widely used infrastructure. Federal agencies and private sector organisations are on high alert following CISA’s inclusion of new vulnerabilities in the Known Exploited Vulnerabilities (KEV) catalogue. Locally, the healthcare sector remains under intense scrutiny following the release of a concerning audit of NSW Health’s cyber posture, while SaaS and AI-driven threats continue to evolve.

Sector Spotlight

Healthcare: Systemic Risks Exposed

The Australian healthcare sector is facing a "sustained cyber risk" environment. Following the recent audit tabled in NSW Parliament, which identified systemic non-compliance with cyber security controls across NSW Health, industry experts are warning that the sector remains critically exposed.

  • Key Insight: A January 2026 report by Gallagher highlighted that Australian health service providers lodged over 200 data breach notifications in the past 12 months.
  • Threat Vector: The convergence of IT and OT (Operational Technology) in hospitals, combined with legacy systems, makes clinical operations a prime target for ransomware. The audit revealed that many Local Health Districts (LHDs) are struggling to meet the NSW Government’s mandatory Cyber Security Policy (CSP) requirements.

Government & Critical Infrastructure

Federal agencies are urged to prioritise patching immediately following the detection of active exploitation of SolarWinds and Apple vulnerabilities.

  • SolarWinds Web Help Desk (WHD): The US cyber security agency (CISA) has warned that CVE-2025-40536 (CVSS 8.1), a security control bypass, is being exploited in the wild. This flaw allows unauthenticated attackers to access restricted functionality, potentially leading to Remote Code Execution (RCE). Australian government bodies using WHD for IT service management must assume compromise if unpatched.
  • Supply Chain Risks: The "PolarEdge" botnet, which compromised thousands of Cisco routers globally earlier this year, remains a persistent threat to critical infrastructure edge devices.

SaaS & Tech Providers

The SaaS landscape is grappling with "Shadow AI" and API vulnerabilities.

  • Apple Zero-Day: A new buffer overflow vulnerability in Apple systems, tracked as CVE-2026-20700, has been patched after being exploited in highly sophisticated attacks. This serves as a reminder that even the most secure ecosystems are vulnerable to targeted zero-day campaigns.
  • Shadow AI: With the rapid adoption of AI agents in the enterprise, organisations are struggling to govern "Shadow AI"—unauthorised AI tools used by employees. Vendors like Okta have released new governance tools this week to help CISOs detect these hidden risks, which often bypass traditional DLP (Data Loss Prevention) controls.

Vulnerability Watch: The "Must-Patch" List

Our penetration testing team has identified the following vulnerabilities as high-priority for Australian organisations this week:

  1. Apple Core Systems (CVE-2026-20700)

    • Type: Buffer Overflow
    • Status: Exploited in the wild.
    • Impact: Arbitrary code execution on iOS and macOS devices.
    • Action: Update to the latest OS versions immediately.
  2. SolarWinds Web Help Desk (CVE-2025-40536)

    • Type: Authentication Bypass
    • Status: Exploited in the wild (Zero-day).
    • Impact: Allows attackers to create internal proxy users and pivot to RCE.
    • Action: Apply the latest hotfix or isolate the WHD instance from the internet.
  3. Notepad++ (CVE-2025-15556)

    • Type: Update Integrity Verification
    • Status: Active exploitation attempts observed.
    • Impact: Attackers can compromise the update mechanism to deliver malware.
    • Action: Verify the authenticity of all open-source tool updates.

Emerging Threat: The AI Attack Surface

As we move further into 2026, "AI-driven ransomware" is becoming a tangible reality. Reports this week suggest that threat actors are increasingly using LLMs to automate the generation of phishing campaigns that are indistinguishable from legitimate internal communications. For the Education and FinTech sectors, this means the "human firewall" is being tested like never before.

Recommendation: Review your email security gateways and conduct fresh adversary simulation exercises that mimic these AI-enhanced social engineering tactics.


Contact us for a quote for penetration testing service or adversary simulation.

Read More
Weekly Threat Briefing Lean Security Expert Weekly Threat Briefing Lean Security Expert

Weekly Threat Briefing: Australia's Cyber Landscape (2–8 February 2026)

The first week of February 2026 has seen a distinct escalation in targeted campaigns against Australian critical infrastructure and services. This week’s intelligence highlights a sophisticated pivot by threat actors towards human-led attacks on identity systems (SSO) and a resurgence of high-impact ransomware claims in the healthcare sector. Furthermore, critical vulnerabilities in widely used SaaS and collaboration tools demand immediate attention from security teams across the region.

Executive Summary

The first week of February 2026 has seen a distinct escalation in targeted campaigns against Australian critical infrastructure and services. This week’s intelligence highlights a sophisticated pivot by threat actors towards human-led attacks on identity systems (SSO) and a resurgence of high-impact ransomware claims in the healthcare sector. Furthermore, critical vulnerabilities in widely used SaaS and collaboration tools demand immediate attention from security teams across the region.

Here is your deep dive into the threats impacting Australian organisations over the last 7 days.

Sector Spotlight

Healthcare: Ransomware Resurgence

The Australian healthcare sector remains in the crosshairs. On 5 February 2026, the Epworth HealthCare group was named as a victim by the emerging 0APT ransomware gang. The group claims to have exfiltrated 920GB of sensitive data, including surgical records and billing details. While Epworth has stated there is currently "no verified evidence" of the breach, this incident underscores the psychological pressure tactics increasingly used by adversaries to force negotiations. This follows closely on the heels of the MediSecure fallout, reinforcing the need for robust data segregation in medical environments.

Government & Education: Data Privacy Fallout

Public sector transparency is being tested this week. Fairfield City Council (NSW) formally published a data breach notification on 5 February 2026 regarding a cyber incident that occurred in late 2025. The investigation confirmed that unauthorised access led to the exposure of staff and resident information.

Simultaneously, the Victorian Department of Education is managing the aftermath of a major breach confirmed in January 2026, which impacted 1,700 schools. The sheer scale of these incidents highlights the "long-tail" effect of breaches in the public sector, where notification and remediation often lag behind the initial compromise.

SaaS & Cloud: Identity Under Siege

A new threat alliance dubbed "SLSH" (linking tactics from Scattered Spider, LAPSUS$, and ShinyHunters) has been observed targeting high-value enterprises, including Australian FinTechs. Their modus operandi involves human-led voice phishing (vishing) to bypass Multi-Factor Authentication (MFA) on Okta SSO instances. Unlike automated bots, these attackers speak fluent English and socially engineer helpdesk staff to reset credentials, granting them administrative access to cloud environments.

FinTech & AI: The "Agentic" Threat

On 4 February 2026, the Australian Securities and Investments Commission (ASIC) released its outlook for the year, explicitly flagging "Agentic AI" as a key risk. While not a traditional exploit, the unmonitored deployment of autonomous AI agents in FinTech is creating new attack surfaces—specifically, the risk of AI agents being manipulated to authorise fraudulent transactions or leak proprietary financial models.

Critical Vulnerabilities Explored

Security teams should prioritise the following vulnerabilities disclosed or actively exploited this week:

  • Microsoft Office & 365 (CVE-2026-21509): A critical vulnerability is being actively exploited in the wild. This flaw allows attackers to bypass Object Linking and Embedding (OLE) security protections. If a user opens a crafted Office file, the attacker can execute arbitrary code. Patch immediately.
  • Cisco Meeting Management (CVE-2026-20098): Disclosed on 4 February 2026, this high-severity flaw allows an authenticated, remote attacker to upload arbitrary files and elevate privileges to root. This is particularly dangerous for organisations relying on on-premise collaboration hardware.
  • Notepad++ Supply Chain Attack: It was confirmed this week that a state-sponsored actor compromised the update infrastructure of the open-source editor Notepad++. Users who updated between June and December 2025 may have received a malicious binary. Security teams must verify the hash integrity of all developer tools installed in their environments.

Emerging Tactics: "Living off the Identity"

The shift from "Living off the Land" to "Living off the Identity" is the defining trend of early 2026. The SLSH campaign demonstrates that technical controls (like standard MFA) are insufficient against determined human adversaries.

  • Recommendation: Australian organisations should enforce FIDO2 hardware keys for privileged accounts and implement "number matching" for MFA to reduce fatigue attacks.

Conclusion

As we move further into 2026, the barrier between "technical" and "social" attacks is dissolving. Whether it is a ransomware group coercing a hospital or a vishing crew tricking a FinTech helpdesk, the human element remains the most critical vulnerability.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Weekly Threat Briefing Lean Security Expert Weekly Threat Briefing Lean Security Expert

Weekly Threat Briefing: Critical Zero-Days and Nation-State Shifts Targeting Australia

The last seven days (26 January – 02 February 2026) have been defined by a resurgence in high-criticality infrastructure vulnerabilities and evolving nation-state tradecraft. For Australian organisations, the immediate priority is addressing active exploitation of Ivanti Endpoint Manager Mobile (EPMM) zero-days and critical patches for Cisco network infrastructure. Simultaneously, the threat landscape is shifting with reports of North Korean APT groups restructuring their operations, while the healthcare sector faces renewed warnings regarding IT/OT convergence risks.

Executive Summary

The last seven days (26 January – 02 February 2026) have been defined by a resurgence in high-criticality infrastructure vulnerabilities and evolving nation-state tradecraft. For Australian organisations, the immediate priority is addressing active exploitation of Ivanti Endpoint Manager Mobile (EPMM) zero-days and critical patches for Cisco network infrastructure. Simultaneously, the threat landscape is shifting with reports of North Korean APT groups restructuring their operations, while the healthcare sector faces renewed warnings regarding IT/OT convergence risks.


Top Priority: Exploited Vulnerabilities

1. Ivanti Endpoint Manager Mobile (EPMM) Zero-Days

Date Detected: 30 January 2026 Sector Impact: Government, SaaS, Enterprise Late last week, Ivanti issued an urgent warning regarding the active exploitation of zero-day vulnerabilities in its Endpoint Manager Mobile (EPMM). Threat actors are leveraging these flaws to bypass authentication and execute arbitrary code on mobile management gateways. Given the widespread use of Ivanti in Australian government and enterprise environments, this represents a critical risk.

  • Action: Immediate patching is required. Security teams should hunt for indicators of compromise (IoCs) in gateway logs dating back to mid-January.

2. Cisco Network Infrastructure Vulnerabilities

Date Released: 27 January 2026 Sector Impact: All Sectors (Critical Infrastructure focus) Cisco released a major security advisory on Tuesday addressing multiple critical vulnerabilities in its IOS XE software. Exploitation allows unauthenticated remote attackers to gain administrative control over network devices. With Australian critical infrastructure heavily reliant on Cisco backbones, these vulnerabilities are a prime target for initial access brokers.


Sector-Specific Threat Intelligence

Healthcare: The IT/OT "Cascade" Effect

A new report released on 27 January 2026 by Trellix highlights a dangerous trend affecting the healthcare sector: the "cascading" effect of cyber attacks moving from administrative IT systems into Operational Technology (OT) and patient care workflows.

  • Analysis: Australian healthcare providers are increasingly digitising patient systems. The report indicates that 75% of recent threats originated in non-clinical environments (e.g., email phishing) before laterally moving to impact medical devices.
  • Recommendation: Network segmentation between clinical OT and administrative IT is no longer optional—it is a patient safety imperative.

Government: BEC and Social Engineering

A significant incident surfaced this week involving a $3.5 million loss from a government agency due to a sophisticated Business Email Compromise (BEC) attack. The perpetrators impersonated a construction contractor, leveraging deepfake-enhanced social engineering to authorise fraudulent payments.

  • Takeaway: Technical controls (like MFA) must be supplemented with strict procedural verification for high-value transactions.

SaaS & Cloud: Salesforce Ecosystem Risks

Reports have emerged regarding a targeted campaign against Salesforce environments. While not a direct breach of Salesforce's core infrastructure, attackers are successfully harvesting high-privilege credentials via sophisticated phishing campaigns targeting Australian SaaS administrators.

  • Risk: Once inside, attackers are exfiltrating customer databases and manipulating API integrations to maintain persistence.

FinTech & AI: The Implementation Trap

As Australian FinTechs rush to integrate AI-driven customer service agents, new research from Cyber Daily (30 January) warns of "AI implementation risks." Early audits suggest that many of these AI systems suffer from prompt injection vulnerabilities, allowing attackers to manipulate banking chatbots into disclosing sensitive user data or bypassing fraud checks.


Threat Actor Focus: North Korean APT Evolution

Intelligence surfacing on 30 January indicates a strategic shift within the infamous North Korean hacking ecosystem (often linked to the Lazarus Group). The group appears to be "dividing to conquer," splitting into smaller, specialised cells.

  • New Tactics: One cell is focusing exclusively on cryptocurrency theft to fund state activities, while another is dedicated to supply chain espionage against the defence and education sectors.
  • Relevance: Australian universities and defence contractors should anticipate highly targeted spear-phishing campaigns tailored to their specific research and development projects.

Recommendations for the Week Ahead

  1. Patch Immediately: Prioritise Ivanti EPMM and Cisco IOS XE updates.
  2. Review BEC Procedures: Verify payment details offline for all transactions over $10,000.
  3. Segregate OT Networks: Ensure clinical devices in healthcare settings are isolated from email and internet-facing segments.
  4. Audit AI Models: If you are deploying LLMs in customer-facing roles, conduct adversarial testing for prompt injection flaws.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Weekly Threat Briefing Lean Security Expert Weekly Threat Briefing Lean Security Expert

Weekly Threat Briefing: Automation Platforms Under Siege & The Rise of AI Jailbreaks (11 Jan 2026)

Welcome to this week's threat briefing. As we settle into 2026, the Australian cyber landscape is already heating up with critical exploits targeting the very automation tools that drive our efficiency. From unauthenticated remote code execution in popular workflow platforms to the industrialisation of AI jailbreaking, this week has highlighted that "set and forget" is no longer a viable security strategy.

Welcome to this week's threat briefing. As we settle into 2026, the Australian cyber landscape is already heating up with critical exploits targeting the very automation tools that drive our efficiency. From unauthenticated remote code execution in popular workflow platforms to the industrialisation of AI jailbreaking, this week has highlighted that "set and forget" is no longer a viable security strategy.

Here is your deep dive into the threats shaping the last 7 days.

Critical Vulnerability Spotlight: The n8n RCE

The most alarming development this week (8 Jan 2026) is the discovery of a critical unauthenticated Remote Code Execution (RCE) vulnerability in the n8n workflow automation platform (tracked as CVE-2026-21858).

  • The Risk: n8n is widely used by SaaS providers and tech-forward organisations to glue together APIs and services. This vulnerability allows an attacker to execute arbitrary code on the host server without needing to log in.
  • Impact: For organisations using n8n to orchestrate sensitive data flows (e.g., connecting CRM data to billing systems), a compromise here effectively hands over the keys to your entire API ecosystem.
  • Action: If you run self-hosted instances of n8n, patch immediately. Isolate these instances from the public internet where possible.

Sector-Specific Threat Analysis

SaaS & APIs: The Gateway Under Fire

Following the n8n disclosure, the IBM API Connect platform also came under scrutiny this week. On 6 January, warnings were issued regarding a critical vulnerability (CVE-2025-13915) that is now being actively probed.

  • Observation: We are seeing a shift where attackers are moving away from brute-forcing front doors and instead targeting the "middleware" and API gateways that manage trust.
  • Advice: Review your API gateway logs for anomalous traffic patterns, specifically inspecting for injection attempts in header fields.

Retail & FinTech: The Initial Access Bazaar

A new report released this week by Cyble on the ANZ Threat Landscape has revealed a disturbing trend for 2026: Retail organisations now account for 34% of all Initial Access Broker (IAB) sales, followed closely by the Banking, Financial Services, and Insurance (BFSI) sector.

  • The Threat: Cybercriminals are not just stealing credit cards; they are selling "footholds" into corporate networks.
  • Actor Profile: The threat group "Warlock" has been identified as a key player, leveraging unpatched on-premises SharePoint vulnerabilities to establish persistence before selling access to ransomware affiliates.

Healthcare: Data Rich, Security Poor

While no massive new breach was declared this specific week, intelligence indicates that the Morpheus ransomware group is actively re-tooling to target healthcare interoperability standards (like FHIR APIs). The digitisation of patient records remains a double-edged sword; ensure your third-party integrations are strictly scoped.

Government: The Scam Relocation

The Australian Cyber Security Centre (ACSC) and regional partners have tracked a significant movement of organised scam syndicates. As of 5 January, intelligence suggests these groups are relocating operations from Myanmar to Cambodia (specifically Malai province).

  • Relevance: Expect a new wave of highly sophisticated, socially engineered "pig butchering" scams targeting Australian government employees and contractors. These often begin via innocuous messages on encrypted messaging apps.

Emerging Tech: AI Systems & The "Storm"

The intersection of AI and cybersecurity is no longer theoretical. The threat actor tracked as Storm-2139 continues to demonstrate capability in "AI Jailbreaking".

  • Method: By compromising Azure OpenAI accounts via stolen credentials, they are modifying guardrails to generate illicit content and bypass safety filters.
  • Corporate Risk: If your organisation relies on "wrapper" applications around LLMs, be aware that attackers are actively looking for prompt injection vulnerabilities to manipulate your AI's output or exfiltrate data.

IoT & Infrastructure: WatchGuard Exploitation

Finally, reports from late December into this week confirm active exploitation of WatchGuard Firebox devices (CVE-2025-14733). These edge devices are often the first line of defence; if unpatched, they become the attacker's beachhead.

Summary & Recommendations

The theme for January 2026 is clear: Interconnectivity is the vulnerability. Whether it is an automation tool like n8n, an API gateway, or a third-party vendor access point, the "glue" holding your stack together is under attack.

Immediate Priorities:

  1. Patch n8n and IBM API Connect instances immediately.
  2. Audit specific egress traffic from your automation servers—they should only talk to known endpoints.
  3. Refresh anti-phishing training for staff regarding "relationship" scams (pig butchering), particularly in government and defence sectors.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Weekly Threat Briefing Lean Security Expert Weekly Threat Briefing Lean Security Expert

Weekly Threat Briefing: Australia’s Cyber Landscape (29 Dec 2025 – 4 Jan 2026)

As we settle into 2026, the Australian cyber threat landscape shows no signs of slowing down. The transition from December 2025 to January 2026 has been characterised by a volatile mix of critical infrastructure vulnerabilities and aggressive ransomware campaigns targeting the "edge" of corporate networks. This week, we have observed a sharp escalation in the exploitation of database and API vulnerabilities, alongside targeted attacks on the healthcare and education sectors.

Introduction

As we settle into 2026, the Australian cyber threat landscape shows no signs of slowing down. The transition from December 2025 to January 2026 has been characterised by a volatile mix of critical infrastructure vulnerabilities and aggressive ransomware campaigns targeting the "edge" of corporate networks. This week, we have observed a sharp escalation in the exploitation of database and API vulnerabilities, alongside targeted attacks on the healthcare and education sectors.

This briefing provides a deep dive into the most significant cyber threats, incidents, and vulnerabilities impacting Australian organisations over the last 7 days.

Sector-Specific Threat Intelligence

  • Healthcare: A Critical Target The healthcare sector remains under immense pressure. Following a challenging December, we have seen reports of a cyber attack affecting the Point Lonsdale Medical Group in Victoria, resulting in unauthorised access to sensitive patient information. This incident follows a major audit released in late 2025 which revealed systemic security bypasses within NSW Health districts, highlighting a culture of non-compliance that continues to leave patient data exposed. Threat actors are increasingly weaponising these gaps to extort providers.

  • SaaS & Cloud Providers: The "MongoBleed" Crisis The most critical technical threat of the week is the "MongoBleed" vulnerability (CVE-2025-14847) affecting MongoDB servers. Despite a patch being available since late December, reports indicate that nearly 95% of exposed instances remain unpatched. Attackers are actively exploiting this to dump server memory and harvest credentials. Additionally, the supply chain risk to SaaS providers was underscored by the Hexicor breach. The KillSec ransomware gang targeted the IT services provider, exfiltrating client folders and hashed passwords, demonstrating how attackers use SaaS platforms as a pivot point to compromise downstream clients.

  • FinTech: Ransomware and API Risks The financial sector faces dual threats from extortion and infrastructure flaws. Austin's Financial Solutions has fallen victim to the Kairos ransomware group, which allegedly stole and published 147GB of data, including employee passports and payroll records. Simultaneously, a critical vulnerability in IBM API Connect (CVE-2025-13915)—widely used by FinTechs to manage APIs for AI services—has been disclosed. This flaw allows authentication bypass, potentially giving attackers unauthorised access to sensitive banking APIs without valid credentials.

  • Education / EdTech: Universities in the Crosshairs Australian universities continue to be prime targets. The University of New South Wales (UNSW) Physics Department was recently targeted by the hacktivist group RipperSec, causing service disruptions. Meanwhile, a breach at the University of Sydney involving an online IT code repository has exposed the fragility of development environments. The KillSec gang has also been observed pivoting to EdTech platforms, exploiting the high value of student data for extortion.

  • Government & Critical Infrastructure Local government is not immune, with Muswellbrook Shire Council suffering a severe ransomware attack by the SafePay gang, leading to the publication of 175GB of internal data. At the network edge, critical vulnerabilities in WatchGuard Firebox (CVE-2025-14733) and Fortinet devices are being actively exploited to gain initial access to government and infrastructure networks.

  • eCommerce & Retail As the festive season wraps up, scammers have ramped up activity targeting Australian consumers. A wave of fake Australia Post delivery messages and QR code scams has been intercepted, designed to steal personal and financial information. On the corporate side, Australian jeweller BECKS confirmed a cyber incident following claims by the SafePay ransomware group.

Vulnerability Spotlight: Web, API, and AI

  • MongoBleed (CVE-2025-14847): A high-severity information disclosure flaw in MongoDB.

    • Risk: Allows unauthenticated attackers to read server memory, potentially exposing cleartext credentials and tokens.
    • Action: Patch immediately to the latest version (v8.0.17+).
  • IBM API Connect (CVE-2025-13915): CVSS 9.8 (Critical).

    • Risk: Authentication bypass in the API gateway. This is particularly dangerous for organisations rushing to deploy AI services, as it breaks the assumption that the gateway enforces identity.
    • Action: Apply the patch for versions 10.0.8.x and 10.0.11.0 immediately.
  • AI Weaponisation: We are observing a trend where threat actors use AI to "hyper-personalise" phishing campaigns and create "polymorphic" malware that changes its code to evade detection. Defenders must look beyond static signatures and focus on behavioural analysis.

Conclusion

The first week of 2026 serves as a stark reminder that basic hygiene—patching databases like MongoDB and securing network edges—remains the most effective defence against sophisticated adversaries. Organisations must also rigorously audit their third-party SaaS and API dependencies to mitigate supply chain risks.

Contact us for a quote for penetration testing service or adversary simulation.

Read More