Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: Supply Chain Attacks Hit Defence, AI-Driven Phishing Escalates

In the last 24 hours, the Australian cyber threat landscape has been dominated by a significant supply chain compromise within the Defence sector and a surge in AI-enabled social engineering campaigns targeting the FinTech and Healthcare industries. Threat actors are increasingly leveraging third-party vulnerabilities to bypass hardened perimeters, necessitating an immediate review of vendor access privileges.

Executive Summary

In the last 24 hours, the Australian cyber threat landscape has been dominated by a significant supply chain compromise within the Defence sector and a surge in AI-enabled social engineering campaigns targeting the FinTech and Healthcare industries. Threat actors are increasingly leveraging third-party vulnerabilities to bypass hardened perimeters, necessitating an immediate review of vendor access privileges.

Sector-Specific Updates

1. Government & Defence: Supply Chain Under Siege Details have emerged overnight regarding a breach targeting IKAD Engineering, a key contractor for Australian naval projects. The ransomware group known as 'J Group' has claimed responsibility, alleging they maintained undetected access for five months.

  • Impact: Potential exposure of operational data related to the Hunter Class frigate and Collins Class submarine programs. While classified technical data reportedly remains secure, the breach highlights the critical risk posed by "Tier 2" suppliers.
  • Action: Defence contractors must urgently audit all external connections and enforce strict network segmentation for third-party vendors.

2. Healthcare: Ransomware Pivot We are observing a shift in tactics by ransomware affiliates who are now targeting specialist medical units with double-extortion attacks. Following the recent incidents impacting cardiology units, threat actors are deploying new ransomware variants that specifically target PACS (Picture Archiving and Communication Systems) servers, which are often left exposed to the internet for remote diagnostics.

  • Threat Actor: Affiliates associated with the Qilin ransomware group.
  • Action: Ensure all medical imaging servers are behind VPNs and multifactor authentication (MFA) is enforced on all remote access portals.

3. SaaS & Education: API Vulnerabilities Exploited A wave of attacks targeting SaaS-based Student Management Systems has been detected in the last 24 hours. Attackers are exploiting Broken Object Level Authorization (BOLA) vulnerabilities in APIs to scrape student personal identification information (PII).

  • Target: Private education providers and EdTech platforms.
  • Action: SaaS providers must immediately run API security scans to identify authorisation flaws.

4. FinTech: The Rise of Deepfake Fraud Australian FinTech firms have reported a sharp increase in AI-driven Business Email Compromise (BEC) attempts. In the last 24 hours, several high-value transfer requests were accompanied by deepfake audio messages on WhatsApp, mimicking C-suite executives to authorise fraudulent transactions.

  • Action: Update verification protocols to require secondary, out-of-band authentication (e.g., a phone call to a known internal number) for all high-value transfers.

Emerging Technologies & IoT

  • IoT Botnets: A new variant of the Mirai botnet has been identified scanning for unpatched vulnerabilities in Australian-manufactured smart metering devices.
  • AI Systems: "Prompt injection" attacks against customer service chatbots are escalating, with attackers manipulating AI models to divulge backend system prompts and sensitive customer data.

Critical Vulnerabilities Exploited

  • Cloud Edge Gateways: Active exploitation of a zero-day vulnerability in a widely used SSL VPN appliance was observed late yesterday. This flaw allows unauthenticated remote code execution (RCE) at the network edge.
  • Web Applications: Deserialisation vulnerabilities in Java-based e-commerce platforms are being weaponised to deploy web shells.

Conclusion

The events of the last 24 hours underscore that perimeter defences are no longer sufficient. The breach of a defence contractor through a third party and the use of AI to bypass human verification in FinTech demonstrate that trust must be verified at every level—whether it is a vendor, an API call, or an executive's voice.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: Russian Sanctions, Defence Supply Chain Breaches & The Zero-Day Surge

The last 24 hours have seen a significant escalation in the Australian cyber threat landscape. The Federal Government has moved from defence to offence with landmark sanctions against Russian cybercrime infrastructure, while the private sector grapples with active zero-day exploitation across major enterprise platforms. From defence contractors to healthcare providers, no sector has been left untouched this week.

Here is your deep dive into the threats shaping the Australian cyber environment today.

Executive Summary

The last 24 hours have seen a significant escalation in the Australian cyber threat landscape. The Federal Government has moved from defence to offence with landmark sanctions against Russian cybercrime infrastructure, while the private sector grapples with active zero-day exploitation across major enterprise platforms. From defence contractors to healthcare providers, no sector has been left untouched this week.

Here is your deep dive into the threats shaping the Australian cyber environment today.


Top Story: Government Strikes Back at "Bulletproof" Hosters

In a coordinated effort with the US and UK, the Australian Government has imposed financial sanctions and travel bans on two Russian entities—Media Land LLC and ML. Cloud LLC—and their operators. These entities are accused of providing "bulletproof hosting" services that act as the backbone for ransomware gangs and phishing campaigns targeting Australian critical infrastructure.

  • Impact: This marks a shift in strategy, targeting the supply chain of cybercriminals themselves.
  • Observation: Expect potential retaliatory DDoS or low-level disruptions from pro-Russian hacktivist auxiliaries in the coming days.

Critical Vulnerability Alert: The "Zero-Day Blitz"

A flurry of critical vulnerabilities has been weaponised in the wild over the last 24 hours. Security teams must prioritise the following patches immediately:

  • Citrix NetScaler (CVE-2025-5777): Dubbed "Citrix Bleed 2," this critical flaw is being exploited by advanced threat actors to bypass authentication.
  • Fortinet FortiWeb (CVE-2025-58034 & CVE-2025-64446): Active exploitation is confirmed for these Command Injection and Authentication Bypass vulnerabilities. Attackers are executing malicious code via crafted HTTP requests.
  • Windows Kernel (CVE-2025-62215): A local Elevation of Privilege (EoP) zero-day allows attackers with low-level access to gain SYSTEM privileges. This is a key component in current ransomware kill chains.
  • Cisco ISE (CVE-2025-20337): Exploited as a zero-day to deploy custom malware.

Recommendation: Immediate patching is non-negotiable. If patching is not possible for Citrix or Fortinet appliances, isolate them from the public internet immediately.


Sector Watch

🛡️ Defence & Government

The "soft underbelly" of the defence supply chain has been exposed. IKAD Engineering, a naval contractor involved in the Hunter Class frigate and Collins Class submarine programs, confirmed a breach where threat actors maintained access for five months.

  • Threat Actor: The J Group ransomware gang.
  • Lesson: Third-party risk management is critical. Even non-classified environments can reveal sensitive operational context to adversaries.

🏥 Healthcare

Australian healthcare continues to bleed data.

  • DBG Health: The Morpheus ransomware group has claimed responsibility for a significant breach, leaking employee passport scans and patient data.
  • Spectrum Medical Imaging: Targeted by INC Ransom, exfiltrating financial and medical records.
  • Sydney Centre for Ear, Nose & Throat: Currently notifying patients of a compromised email account leading to data exposure.

🎓 Education

Western Sydney University (WSU) has confirmed a major data breach spanning from June to September 2025. Attackers accessed Tax File Numbers (TFNs) and health information, highlighting the persistence of threat actors within academic networks before detection.

💰 FinTech & SaaS

ASIC has officially declared cyber resilience a top enforcement priority for 2025. This comes as financial institutions report a surge in AI-powered phishing.

  • Emerging Tactic: Attackers are using generative AI to craft hyper-realistic phishing lures that bypass traditional "bad grammar" detection filters, specifically targeting SaaS administrators to hijack API keys.

Emerging Tech Threat: Mobile Spyware

A sophisticated commercial spyware campaign dubbed "LANDFALL" has been uncovered targeting Samsung Galaxy devices.

  • Vector: The malware exploits a zero-day in Samsung’s image-processing library (CVE-2025-21042) via malicious WhatsApp image files.
  • Target: High-value individuals in corporate and government sectors.

Actionable Advice for the Weekend

  1. Audit External Attack Surface: With the Citrix and Fortinet flaws active, scan your public-facing IP space for exposed administrative interfaces.
  2. Review Vendor Access: The IKAD Engineering breach is a reminder to audit the privileges of third-party contractors.
  3. Brief Staff on AI Phishing: Remind employees that impeccable grammar and personalisation are no longer proof of legitimacy in emails.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: Defence Supply Chain Sieged, Russian Hosts Sanctioned & Critical Fortinet Zero-Days

The Australian cyber threat landscape has intensified over the last 24 hours with significant geopolitical moves and critical infrastructure attacks. The Federal Government, in coordination with the US and UK, has officially sanctioned Russian "bulletproof" hosting providers facilitating ransomware campaigns against Australian targets. Meanwhile, the defence supply chain is under scrutiny following a confirmed breach at a major naval contractor, and network defenders are racing to patch actively exploited zero-days in Fortinet and Citrix appliances.

Here is your daily deep dive into the threats shaping our digital environment.

Executive Summary The Australian cyber threat landscape has intensified over the last 24 hours with significant geopolitical moves and critical infrastructure attacks. The Federal Government, in coordination with the US and UK, has officially sanctioned Russian "bulletproof" hosting providers facilitating ransomware campaigns against Australian targets. Meanwhile, the defence supply chain is under scrutiny following a confirmed breach at a major naval contractor, and network defenders are racing to patch actively exploited zero-days in Fortinet and Citrix appliances.

Here is your daily deep dive into the threats shaping our digital environment.

Sector Intelligence

Government & Defence: Supply Chain in the Crosshairs

The most critical update today involves IKAD Engineering, a key contractor for the Hunter Class frigate and Collins Class submarine programs. The J Group ransomware gang has claimed responsibility for a breach, alleging they maintained undetected access for five months—a "staycation in the defence supply chain"—before exfiltrating 800GB of data. While IKAD states no classified data was lost, this highlights a severe visibility gap in third-party risk management.

Simultaneously, the Australian Government has imposed sanctions on Media Land LLC and ML.Cloud, along with key individuals Aleksandr Volosovik and Kirill Zatolokin. These entities are accused of providing the backend infrastructure for ransomware groups like Qilin and Medusa, which have relentlessly targeted Australian schools and hospitals this year.

  • Threat Actor Watch: Volt Typhoon (China-nexus) continues to probe Australian critical infrastructure, specifically telecommunications and energy grids, likely for pre-positioning rather than immediate disruption.

SaaS & Cloud Providers: The Fortinet Crisis

SaaS providers and enterprises using Fortinet FortiWeb WAFs must act immediately. A critical vulnerability (CVE-2025-64446) is being actively exploited in the wild. This path traversal flaw allows unauthenticated attackers to create administrative accounts via the API, effectively handing over full control of the device.

  • Impact: Full device compromise, potential lateral movement into cloud environments.
  • Status: CISA has mandated US federal agencies patch this by today, 21 November 2025. Australian organisations should follow suit immediately.

Healthcare: Relentless Ransomware

Healthcare remains the most targeted sector in 2025, accounting for 17% of all significant cyber incidents. The sanctions against Russian hosting firms are a direct response to attacks on this sector, but operational risks remain high. Hospitals are advised to review their exposure to the Citrix NetScaler zero-day (CVE-2025-5777), which is currently being used to deploy ransomware payloads.

FinTech & DeFi: Smart Contract Failures

The decentralised finance (DeFi) sector has seen over $3.1 billion in losses this year. In the last 24 hours, analysis has surfaced regarding the Abracadabra protocol hack ($1.8m loss), caused by a state management flaw in a smart contract. For Australian FinTechs, this reinforces the need for rigorous code audits and formal verification before deployment, especially as high-speed chains like Solana gain traction.

IoT & Mobile: Commercial Spyware

A sophisticated spyware campaign dubbed "LANDFALL" has been uncovered targeting Samsung Galaxy devices. It exploits a zero-day in the image-processing library (CVE-2025-21042). The malware is delivered via malicious DNG files on WhatsApp, affecting high-profile targets in the corporate and government sectors.


Vulnerability Watch: Critical Exploits

We are tracking the following vulnerabilities actively exploited in the Australian wild:

  1. Fortinet FortiWeb (CVE-2025-64446)

    • Type: Path Traversal / Auth Bypass.
    • Severity: Critical (CVSS 9.8).
    • Action: Update to version 8.0.2+ immediately. If patching is impossible, disable the management interface on public-facing IPs.
  2. Windows Kernel (CVE-2025-62215)

    • Type: Privilege Escalation.
    • Severity: High.
    • Context: Actively used by attackers to gain SYSTEM privileges after initial foothold (often via phishing).
  3. Fortinet FortiWeb (CVE-2025-58034)

    • Type: OS Command Injection.
    • Severity: Critical.
    • Context: Often chained with the auth bypass above to execute arbitrary code.

Pen Tester’s Perspective: The Rise of "Agentic" Threats

By Lean Security

The breach of IKAD Engineering is a textbook example of why perimeter defences are insufficient. The attackers didn't just smash and grab; they dwelt. They understood the network better than the administrators.

Furthermore, we are seeing a shift towards Agentic AI in offensive operations. Automated agents are now capable of chaining vulnerabilities (like the Fortinet auth bypass followed by command injection) at machine speed, drastically reducing the "time-to-compromise."

Recommendation: Organisations must move beyond annual compliance checks.

  1. Simulate the Supply Chain Breach: Don't just test your perimeter; test your reaction when a trusted vendor is compromised.
  2. API Security: The Fortinet exploit targeted an API endpoint. Ensure your API security testing covers logic flaws and authorisation bypasses, not just standard injections.
  3. Hunt for Persistence: If you run FortiWeb, assume compromise. Check logs for new, unrecognised admin accounts created in the last 30 days.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Australia Cyber Threat Update: Bulletproof Hosting Crackdown & Critical Fortinet/Cisco Exploits

Australia faces a crackdown on bulletproof hosting and active exploitation of critical Fortinet & Cisco vulnerabilities. Learn to protect your organization from these urgent cyber threats.

Executive Summary

The Australian cyber threat landscape for the last 24 hours has been dominated by a coordinated international response to resilient cybercrime infrastructure and the escalation of attacks against edge devices. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), in conjunction with global partners (CISA, FBI, NCSC-UK), released pivotal guidance yesterday targeting "Bulletproof Hosting" providers. Meanwhile, critical vulnerabilities in Fortinet and Cisco appliances are seeing active exploitation, posing severe risks to Australian organisations relying on these perimeter defence technologies.


Top Strategic Development: Crackdown on Bulletproof Hosting

Sectors Impacted: Government, FinTech, Critical Infrastructure

In a major release on 19 November 2025, the ACSC joined international agencies to publish "Bulletproof Defense: Mitigating Risks From Bulletproof Hosting Providers." Bulletproof hosting (BPH) services are the backbone of the cybercrime economy, allowing ransomware gangs and phishing operators to host malicious content with impunity.

  • The Threat: BPH providers knowingly ignore abuse complaints and facilitate high-volume phishing campaigns and C2 (Command and Control) infrastructure.
  • Action Required: Australian network defenders and ISPs are urged to review the new guidance to identify and block traffic to and from known BPH IP ranges. This is a critical step for Government and FinTech sectors to reduce the attack surface for ransomware and fraud.

Critical Vulnerabilities Under Active Exploitation

Organisations using web application firewalls (WAFs) and secure gateways must urgently review the following exploits highlighted in the last 24 hours:

1. Fortinet FortiWeb – Critical Authentication Bypass

  • CVE: CVE-2025-64446 (CVSS 9.1)
  • Status: Active Exploitation Confirmed (Added to CISA KEV on 14 Nov 2025, widely targeted in the last 24 hours).
  • Impact: This critical vulnerability allows unauthenticated remote attackers to bypass authentication and gain administrative control over FortiWeb appliances.
  • Relevance: High risk for SaaS providers and eCommerce platforms using FortiWeb to protect customer data.
  • Recommendation: Patch immediately. If patching is not possible, restrict management interface access to trusted internal IPs only.

2. Cisco ASA & FTD – State-Sponsored Targeting

  • CVEs: CVE-2025-20333 (CVSS 9.9) and CVE-2025-20362
  • Threat Actor: Linked to UAT4356/Storm-1849 (State-sponsored activity).
  • Context: Despite patches being available, telemetry indicates approximately 48,000 appliances globally remain unpatched. Threat actors are chaining these vulnerabilities to establish persistent footholds in corporate networks.
  • Sector Risk: Government and Education networks are frequent targets for this type of espionage-focused campaign.

3. WatchGuard Firebox & IoT Risks

  • Observation: Security researchers have identified over 54,000 exposed WatchGuard Firebox devices as of mid-November 2025.
  • IoT Threat: A new botnet is aggressively recruiting end-of-life GeoVision devices.
  • Takeaway: IoT and edge security remains a weak point. Organisations with distributed branches (e.g., Healthcare clinics, retail chains) must audit their perimeter footprint for unmanaged or end-of-life devices.

Sector-Specific Threat Intelligence

  • Healthcare: Following the trend of high-impact ransomware attacks (such as the MediSecure incident earlier in the decade), the sector remains a priority target. The new BPH guidance is crucial here—blocking BPH infrastructure can prevent the initial callback of ransomware payloads often used against hospitals.
  • Education (EdTech): With the academic year wrapping up, schools and universities are facing increased phishing attempts disguised as administrative notices. The exploitation of Cisco VPN vulnerabilities is a specific vector being used to penetrate university research networks.
  • FinTech: A new alert from the ACSC (13 Nov 2025) regarding scammers impersonating police to steal cryptocurrency remains highly relevant. FinTech platforms should warn users about this social engineering tactic, which often involves "urgent" requests to move funds to "safe" wallets.

Penetration Tester’s Perspective

From an offensive security standpoint, the current environment is volatile. Attackers are moving faster than defenders can patch. The FortiWeb bypass (CVE-2025-64446) is particularly dangerous because it compromises the very device meant to secure your web applications.

During our recent engagements, we have observed that API security remains a blind spot. With the rise of AI-driven attacks, automated scripts are now capable of probing APIs for logic flaws much faster than human analysts. Ensure your APIs are not just behind a WAF, but also rigorously tested for Broken Object Level Authorisation (BOLA) and other logic vulnerabilities.


Contact us for a quote for penetration testing service or adversary simulation.

Read More
Lean Security Expert Lean Security Expert

CISA Alert: LANDFALL Spyware Hits Australian BYOD Devices

A zero-click vulnerability, CVE-2025-21042, in millions of Samsung devices is being actively exploited to install "LANDFALL," a commercial-grade spyware. This threat, now on CISA's KEV catalog , transforms an executive's personal device into a silent corporate surveillance tool, completely bypassing your MDM and EDR. For Australian organisations with BYOD policies, this is a critical, reportable data breach scenario under the NDB scheme.

Understanding the Threat: CVE-2025-21042 and the LANDFALL Spyware

For Australian CISOs and IT Directors, the enterprise perimeter no longer ends at the firewall. It ends in the pockets of your C-suite. The recent CISA alert for CVE-2025-21042 has elevated a theoretical risk into an actively exploited reality, with profound implications for Australian businesses.  

This isn't a minor consumer-grade bug. This is a supply chain-style compromise of your most trusted, high-value assets: your executive team.

What is CVE-2025-21042?

Tracked as CVE-2025-21042, this is a critical (CVSS 8.8-9.8) out-of-bounds write vulnerability in a core image processing library (libimagecodec.quram.so) on a vast range of high-end Samsung Galaxy devices.

Its primary vector is a "zero-click" exploit. This is the apex predator of vulnerabilities. An attacker simply sends a specially crafted Digital Negative (DNG) image file via a messaging app like WhatsApp. The victim does not need to open the image, click a link, or interact in any way. The device's operating system processes the image preview, triggering the vulnerability and leading to remote code execution (RCE) with system-level privileges.  

The Payload: "LANDFALL" Commercial-Grade Spyware

The vulnerability is merely the delivery mechanism. The payload, dubbed "LANDFALL," is a sophisticated, modular, commercial-grade spyware framework engineered for one purpose: total surveillance.  

Research from Palo Alto Networks' Unit 42 confirms LANDFALL grants attackers complete control. Its capabilities include:  

  • Audio Surveillance: Recording all microphone audio and phone calls, silently capturing board meetings, legal discussions, and M&A strategy sessions.  

  • Data Exfiltration: Stealing all photos, contacts, SMS messages, and call logs.  

  • Location Tracking: Continuous, real-time monitoring of the victim's movements.  

  • Stealth and Persistence: LANDFALL is designed to evade detection and maintain access even after reboots, giving attackers a persistent foothold.  

This toolkit is not the work of common criminals; it's associated with Private-Sector Offensive Actors (PSOAs)—mercenary groups that sell these capabilities to the highest bidder for corporate and state-level espionage.  

Business Impact Analysis: The Australian BYOD Liability

This vulnerability was actively exploited for at least seven months (from July 2024 to February 2025) before Samsung's patch in April 2025. On November 10, 2025, CISA added it to the Known Exploited Vulnerabilities (KEV) catalog, mandating a fix by December 1 for federal agencies—a clear signal of its severity and active threat status.  

For Australian leaders, this presents a catastrophic governance failure.

Your Executive's Pocket: The New Attack Surface

In Australia, Samsung holds over 25% of the mobile market , with over 9 million users. Many of these are the exact flagship Galaxy S22, S23, S24, and Z Fold devices targeted by this exploit.  

In a corporate BYOD (Bring Your Own Device) environment, that personal phone is a trusted endpoint. It is used to check corporate email, access the VPN, join Teams/Zoom calls, and review sensitive documents. When compromised by LANDFALL, that device becomes a vector for a devastating corporate data breach. The ACSC has long warned that BYOD introduces new risks that require careful consideration and risk management, which this exploit directly targets.  

A Corporate Data Breach on a Personal Device

The compromise of an executive's phone is not a personal matter. The exfiltration of corporate data (e.g., strategic plans, financial forecasts, client data) from that device is a clear-cut "eligible data breach" under the Office of the Australian Information Commissioner's (OAIC) Notifiable Data Breaches (NDB) scheme.  

Your organisation is legally required to assess and report this breach. This introduces severe complications:

  • Legal Liability: How can you prove what data was not taken? The "employee records exemption" does not apply to the sensitive corporate data, client PII, or market-sensitive information discussed in a board meeting recorded by the spyware.  

  • Reputational Damage: A breach originating from your C-suite's devices signals a fundamental failure of security and governance.  

  • Detection Failure: The most critical question is: How would you even know?

Why Your MDM and EDR Are Blind to This Threat

This is the gap that PSOAs and LANDFALL exploit. Australian CISOs investing in robust security stacks are being failed by a critical blind spot.

  • Mobile Device Management (MDM): MDM and Unified Endpoint Management (UEM) solutions are governance tools, not security tools. They are designed to enforce policies, push patches, and wipe lost devices. On a BYOD device, their visibility is intentionally limited by employee privacy concerns. An MDM cannot inspect an image parsing library in real-time. It can only (slowly) report if the device is patched, which is useless against a zero-day exploit.  

  • Endpoint Detection & Response (EDR): Your EDR is on the corporate laptop, not the executive's personal phone.  

  • Network Monitoring: The exploit occurs on the device itself. The exfiltrated data is siphoned off over HTTPS on non-standard ports , blending in with thousands of other app connections from a mobile device, making it invisible to traditional network firewalls.  

For seven months, this vulnerability was a zero-day. Patching was not an option. Detection was the only possible defence. Your stack was blind, and you were exposed.  

How Red Teaming Exposes This Vulnerability

A standard penetration test will check if your external-facing servers are patched. It will not tell you if you could withstand a LANDFALL-style attack.  

This threat requires an adversary-centric approach. Our red team engagements move beyond simple vulnerability scanning to simulate the tactics, techniques, and procedures (TTPs) of the PSOAs behind this attack.  

Simulating the Mobile-Originated Breach Scenario

We answer the one question your board should be asking: "Can we detect and respond to a zero-click compromise of our executive team?"

A standard pen test checks a list of known vulnerabilities. Our mobile-originated red team engagement simulates the entire attack chain:  

  1. Targeted Reconnaissance: We identify high-value targets (e.g., C-suite, finance, legal) and their specific devices, just as a real attacker would.

  2. Adversary Emulation: We emulate the TTPs of an actor like the one deploying LANDFALL, focusing on social engineering vectors and client-side exploits targeting mobile devices.  

  3. Payload & Exfiltration: We use a non-destructive, benign payload to simulate a zero-click compromise. The objective is to gain access and begin exfiltrating data.  

  4. Testing Your Detection: The real test begins now. Is your SOC blind? Does your SIEM generate an alert? Does your incident response team know how to contain a threat originating from a personal BYOD device? Can they differentiate malicious traffic from the "noise" of 300 other apps?

Our Methodology: Assume You Are Breached

Your MDM will fail to stop a zero-day. Your network perimeter will be bypassed. The battle is one of detection and response.

Our methodology provides the only realistic assessment of your resilience to this modern, mobile-first threat. We provide a clear, actionable report that moves beyond "patch this" and delivers a strategic roadmap for building resilience.

This isn't just about CVE-2025-21042. It's about the next zero-click exploit, and the one after that. Do not wait for a journalist's phone call to find out your most sensitive conversations are being auctioned by mercenaries.

Secure your enterprise. Contact Lean Security today for a confidential Red Team briefing.

Read More