SessionReaper & BFCM: Why Penetration Testing Services Are Critical (CVE-2025-54236)
A critical vulnerability in Adobe Commerce and Magento (CVE-2025-54236), dubbed "SessionReaper," is being ruthlessly exploited by threat actors using AI-driven tools to automate attacks at machine speed. With the Australian holiday trading season in full swing, this unauthenticated remote code execution (RCE) flaw poses an immediate existential threat to retail and B2B organizations. This alert outlines the mechanics of the attack, the role of AI in its weaponization, and the urgent defensive actions required to prevent a catastrophic data breach.
The SessionReaper Ultimatum: Why Penetration Testing Services Are Vital to Surviving the 'Code Freeze'
Executive Summary: Hackers are exploiting a critical Adobe Commerce flaw, CVE-2025-54236 (SessionReaper). This threat endangers Australian e-commerce during the Black Friday peak. New Privacy Act fines make the traditional "Code Freeze" risky. This report explains the threat. It shows why penetration testing services are key to securing your store without stopping sales.
The Convergence of Critical Vulnerability and Law
Q4 2025 brings two major threats. First, SessionReaper attacks the Adobe Commerce ecosystem. Second, strict Australian laws now change the cost of a data breach.
For Australian CISOs, the rules have changed. Legal and financial risks now outweigh the risk of patching during a peak.
The Threat: SessionReaper (CVE-2025-54236)
SessionReaper is a major flaw in how Adobe Commerce handles data. It lets attackers run code on your server without a login.
CVSS Score: 9.1 (Critical)
Vector: Remote Code Execution (RCE) via PHP Object Injection
Authentication: None required
Impact: Full server takeover, data theft, ransomware.
Attackers send fake data to specific API endpoints (like /customer/address_file/upload). The system trusts this input. It then runs malicious commands hidden inside the data.
The Australian Regulatory Minefield
You cannot ignore this threat just to keep the site stable.
Privacy Act Reforms: "Serious interference" with privacy now costs $50 million. This penalty also applies to 30% of adjusted turnover. SessionReaper exposes customer data, creating this exact risk.
ASIC Director Liability: ASIC states that cyber resilience is a duty. Directors face personal liability for low care. Ignoring this flaw due to a "Code Freeze" helps prove negligence.
The Black Friday Dilemma: Freeze or Patch?
The "Hard Freeze" used to be standard. No changes during sales events ensured stability.
SessionReaper destroys this logic.
Sansec reports that 62% of Magento stores are unsafe. Attackers scan for these systems. A breach means attackers steal credit cards via Magecart. They could also lock your database with ransomware on Cyber Monday.
Key Takeaway: A deployment error costs money. A Tier 1 Privacy fine threatens your business survival.
Technical Deep Dive: How the Exploit Works
To understand the risk, we must look at the code. SessionReaper exploits PHP Object Injection.
The Mechanics of Failure
Data Packing: Apps turn complex data (objects) into strings to store them.
The Flaw: Adobe Commerce accepts this data from the API without checking it.
The Trigger: When the app reads (unpacks) this string, it wakes up the data object.
Gadget Chains: Attackers chain together code snippets (gadgets) already on your system.
Attackers change these gadgets to trick the server. This lets them delete files or run commands. This happens before the system checks for a login.
Why Standard Defences Fail
Firewalls often miss this. The attack looks like valid data. Your security controls must specifically check packed strings to stop it.
Strategic Response: The "Monitored Thaw"
You cannot afford to ignore this. Yet, you cannot break your store during the busiest week. We recommend a "Monitored Thaw" strategy.
1. WAF Update (Immediate)
If you cannot patch now, block the attack. Configure your Web Application Firewall (WAF) to:
Block outside access to
/customer/address_file/upload.Filter requests that look like packed data (e.g., regex matching
O:\d+:).
2. Validate with Penetration Testing Services
Applying a rule is not enough; you must check if it works. Penetration testing services are vital here. A Red Team should:
Simulate real world attacks using the SessionReaper exploit.
Test if attackers can bypass your WAF rules.
Find other security weaknesses exposed by rushed changes.
Types of penetration tests needed include API testing. This proves your shields work against determined attackers.
3. The Emergency Patch
If the WAF fails, you must patch.
Isolate the Fix: Apply only the security patch. Do not upgrade the full version.
Timing: Deploy when traffic is low (typically 02:00 - 04:00 AM AEST).
Verification: Use automated tests to check checkout functions immediately.
4. Governance and Documentation
Document your choices. If a breach happens, you must prove you managed the cyber security risk. A test report proves you took reasonable steps.
Conclusion: Silence is not Security
"SessionReaper" is a clear danger. Attackers are automated. Regulators are watching.
Do not let an old "Code Freeze" policy cause a $50 million fine.
Is your WAF actually blocking SessionReaper? Are you sure?
Contact our Red Team today for a targeted web application assessment. We will validate your defences against CVE-2025-54236. We help secure your revenue without risking your reputation.
Daily Threat Briefing: Australia – 26 November 2025
The last 24 hours have seen a significant escalation in the Australian cyber threat landscape, characterised by a convergence of AI-driven offensive operations and high-impact data breaches. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and private sector intelligence indicate a sharp rise in automated attacks targeting the Healthcare, FinTech, and Government sectors. Of particular concern is the emergence of AI agents capable of automating complex attack chains, reducing the time from vulnerability discovery to exploitation to near zero.
Executive Summary
The last 24 hours have seen a significant escalation in the Australian cyber threat landscape, characterised by a convergence of AI-driven offensive operations and high-impact data breaches. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and private sector intelligence indicate a sharp rise in automated attacks targeting the Healthcare, FinTech, and Government sectors.
Of particular concern is the emergence of AI agents capable of automating complex attack chains, reducing the time from vulnerability discovery to exploitation to near zero.
Top Story: The Rise of AI-Driven Offensive Campaigns
Threat Actor Activity: A sophisticated campaign, tracked as GTG-1002, has been identified targeting Australian finance and government sectors. Unlike traditional attacks, this campaign utilises an AI agent to automate reconnaissance, exploit writing, and lateral movement.
- Impact: The window for patching has effectively closed for some zero-day vulnerabilities.
- Sector Risk: High for Government and Critical Infrastructure.
Sector-Specific Updates
1. Healthcare
The healthcare sector remains the primary target for ransomware and data extortion.
- Incident: Point Lonsdale Medical Group in Victoria has disclosed a cyber attack resulting in unauthorised access to personal information. This follows closely on the heels of the Genea breach, where the Termite ransomware group (an offshoot of Babuk) claimed responsibility for exfiltrating 700GB of patient data.
- Threat: Attackers are aggressively targeting patient management systems and third-party integrations.
2. Aviation & eCommerce
- Major Incident: Qantas Airways is reportedly investigating a significant data compromise affecting customer personal data. Threat intelligence suggests potential involvement from the Scattered Spider group, known for sophisticated social engineering and targeting large helpdesks.
- Implication: Organisations with large customer databases must urgently review their identity verification processes for customer support channels.
3. FinTech & SaaS
- Vulnerability: A critical flaw in WhatsApp’s Contact Discovery API has been exposed, potentially allowing the enumeration of active accounts. While Meta has implemented fixes, this highlights a broader risk for FinTech apps relying on similar contact syncing features.
- Trend: API Security is a critical failure point. Financial services are currently facing a wave of API-layer DDoS attacks and credential stuffing, exploiting endpoints that lack adaptive multi-factor authentication (MFA).
- SaaS Alert: A "Loan Management System" source code leak has been detected, compromising API keys and database credentials. SaaS providers are urged to rotate secrets immediately.
4. Education & EdTech
- Ongoing Threat: Following the Western Sydney University breach, threat actors are leveraging stolen credentials to target other educational institutions. Phishing campaigns impersonating university IT support are currently active.
5. IoT & Critical Infrastructure
- Advisory: A new report from Semperis highlights that 52% of ransomware attacks in Australia now occur on weekends or holidays, exploiting reduced staffing in Security Operations Centres (SOCs).
- Vulnerability: Unpatched IoT devices in critical infrastructure are being targeted by state-sponsored actors to maintain persistence.
Critical Vulnerabilities & Exploits (Last 24 Hours)
- Microsoft WSUS (CVE-2025-59287): A critical vulnerability allowing privilege escalation. The ACSC has issued a high-priority alert for immediate patching.
- Citrix NetScaler (CVE-2025-5777): "Citrix Bleed 2" is being actively exploited in the wild to bypass authentication.
- Cisco ISE (CVE-2025-20337): Exploited as a zero-day to deploy custom malware.
- Samsung (CVE-2025-21042): A zero-day in image processing libraries is being used in targeted spyware campaigns via instant messaging apps.
Recommendations
- Patch Immediately: Prioritise Microsoft WSUS and Citrix NetScaler updates.
- API Hardening: Review all external API endpoints for rate limiting and broken object level authorisation (BOLA).
- Enhance Monitoring: Increase SOC vigilance during the upcoming weekend to counter "holiday-timed" ransomware attacks.
- AI Defence: Begin evaluating AI-enabled defensive tools to counter the speed of automated AI attacks.
Contact us for a quote for penetration testing service or adversary simulation.
Daily Threat Briefing: Record DDoS Hits Australia & Critical Fortinet Flaws
In the last 24 hours, the Australian cyber threat landscape has been dominated by a record-breaking Distributed Denial of Service (DDoS) attack targeting local cloud infrastructure, alongside critical alerts for widely used enterprise edge devices. The Australian Securities and Investments Commission (ASIC) has also signalled a major shift in regulatory enforcement regarding cyber resilience in the financial sector.
Executive Summary In the last 24 hours, the Australian cyber threat landscape has been dominated by a record-breaking Distributed Denial of Service (DDoS) attack targeting local cloud infrastructure, alongside critical alerts for widely used enterprise edge devices. The Australian Securities and Investments Commission (ASIC) has also signalled a major shift in regulatory enforcement regarding cyber resilience in the financial sector.
Top Story: Australian Cloud Endpoint Hit by Record 15.72 Tbps DDoS Microsoft has disclosed the mitigation of the largest DDoS attack ever observed in the cloud, targeting a single endpoint in Australia. The attack peaked at a staggering 15.72 Terabits per second (Tbps).
- Attack Vector: The assault originated from a "TurboMirai-class" IoT botnet known as AISURU, comprising approximately 300,000 infected devices (routers, cameras, and DVRs).
- Pentester Insight: This incident highlights the critical volatility of insecure IoT devices. For organisations relying on cloud infrastructure, this underscores the necessity of stress-testing DDoS mitigation strategies and ensuring upstream providers can handle volumetric attacks of this magnitude.
Vulnerability Watch: Active Exploitation in the Wild Two critical vulnerability sets have emerged that require immediate patching and threat hunting.
Fortinet FortiWeb (Web Application Firewall):
- CVE-2025-64446 (Critical): A path-traversal flaw allowing unauthenticated administrative access.
- CVE-2025-58034 (Medium - Actively Exploited): An OS Command Injection vulnerability.
- The Threat: Attackers are chaining these vulnerabilities to bypass authentication and execute arbitrary code on the underlying system. Given FortiWeb's position at the network edge, compromise here grants threat actors deep visibility into decrypted web traffic.
- Action: Patch to version 8.0.2 immediately.
7-Zip (RCE):
- CVE-2025-11001: A Remote Code Execution (RCE) vulnerability in the ubiquitous 7-Zip file archiver is under active exploitation.
- Risk: This client-side vulnerability is a prime vector for phishing campaigns targeting corporate endpoints.
Sector-Specific Intelligence
Government: Security protocols at Parliament House have been tightened significantly during the current visit by a Chinese delegation. Politicians and staff have been instructed to power down devices and disable Wi-Fi to mitigate the risk of close-access cyber espionage. This serves as a stark reminder of the physical proximity risks to mobile devices in sensitive environments.
FinTech & SaaS: ASIC Enforcement Shift: ASIC is suing financial advice firm Fortnum Private Wealth for "licensee failures to have adequate cyber security protections." This marks a pivot where regulatory bodies are moving from guidance to prosecution for poor cyber hygiene. API Security: New data reveals that financial services now account for 27% of API-specific DDoS traffic. Attackers are moving beyond simple volumetric attacks to application-layer exhaustion, targeting specific expensive API endpoints to disrupt operations.
Healthcare: The sector remains Australia's most targeted industry, sustaining 17% of all reported cyber attacks. The focus continues to be on data extortion via ransomware, leveraging the high sensitivity of patient data (PII/PHI).
AI Systems: Research released today indicates that AI coding assistants, specifically DeepSeek, have been observed generating code with introduced vulnerabilities when prompted with specific political triggers. This "poisoning" of the development lifecycle introduces a new vector for supply chain attacks in software development.
Recommendation for Defenders Organisations should immediately audit their external attack surface for exposed Fortinet appliances and verify the integrity of their 7-Zip installations. Furthermore, FinTech entities must review their API rate-limiting configurations to defend against the rising tide of application-layer DDoS attacks.
Contact us for a quote for penetration testing service or adversary simulation.
Daily Threat Briefing: Russian Sanctions, Salesforce Supply Chain Risks & Critical WSUS Exploits
The last 24 to 48 hours have seen significant shifts in the Australian cyber threat landscape, dominated by a major government crackdown on ransomware facilitators and a developing supply chain incident affecting the Salesforce ecosystem. In a coordinated move with the US and UK, the Australian Government has imposed sanctions on Russian individuals and entities providing "bulletproof hosting" to gangs like LockBit and Clop. Meanwhile, organisations relying on Salesforce are on high alert following confirmed unauthorized activity linked to third-party Gainsight applications, with threat actors claiming widespread access. On the vulnerability front, a critical Microsoft WSUS flaw (CVE-2025-59287) is seeing active exploitation, demanding immediate attention from system administrators.
Executive Summary
The last 24 to 48 hours have seen significant shifts in the Australian cyber threat landscape, dominated by a major government crackdown on ransomware facilitators and a developing supply chain incident affecting the Salesforce ecosystem.
In a coordinated move with the US and UK, the Australian Government has imposed sanctions on Russian individuals and entities providing "bulletproof hosting" to gangs like LockBit and Clop. Meanwhile, organisations relying on Salesforce are on high alert following confirmed unauthorized activity linked to third-party Gainsight applications, with threat actors claiming widespread access.
On the vulnerability front, a critical Microsoft WSUS flaw (CVE-2025-59287) is seeing active exploitation, demanding immediate attention from system administrators.
Sector-Specific Updates
Government & Critical Infrastructure
- New Cyber Sanctions Imposed: As of 20–21 November 2025, Australia has sanctioned Russian cybercrime service providers Media Land LLC and ML Cloud, along with individuals Aleksandr Volosovik and Kirill Zatolokin. These entities are accused of providing the infrastructure that enables major ransomware groups (including LockBit and Blacksuit) to target Australian critical infrastructure and businesses. This marks a pivotal shift in holding enablers accountable.
SaaS & FinTech
- Salesforce / Gainsight Supply Chain Incident: Salesforce has confirmed an investigation into "unusual activity" involving Gainsight-published applications. While Salesforce’s own platform reportedly remains secure, the breach of this third-party integration has led to the revocation of access tokens.
- Threat Actor Activity: A group calling themselves "Scattered LAPSUS$ Hunters" (potentially linked to ShinyHunters) is claiming to have compromised hundreds of organisations via this vector. Australian SaaS consumers and FinTech firms using these integrations should immediately audit their connected apps and access logs.
Defence & Engineering
- IKAD Engineering Breach: New details have emerged regarding the ransomware attack on IKAD Engineering, a key player in the defence supply chain (Hunter Class frigates, Collins Class submarines). The "J Group" ransomware gang claims to have exfiltrated 800GB of data after maintaining undetected access for five months. While IKAD states no classified information was compromised, this incident highlights the critical risk of "staycation" attacks where adversaries dwell in networks for extended periods.
Healthcare
- Targeted Phishing Campaigns: The healthcare sector remains a prime target for credential harvesting.
- Point Lonsdale Medical Group and the Sydney Centre for Ear, Nose & Throat (SCENT) have both recently warned patients of data breaches stemming from compromised email accounts. These incidents were triggered by phishing attacks, reinforcing the need for robust email security and staff training in medical practices.
Vulnerability Watch: Web, Cloud & API
Penetration testers and defenders must prioritise the following critical vulnerabilities which are either being actively exploited or pose an imminent high risk to Australian networks.
1. Microsoft WSUS – Remote Code Execution (Critical)
- CVE: CVE-2025-59287
- CVSS: 9.8 (Critical)
- Status: Active Exploitation Detected.
- Impact: Allows an unauthenticated attacker to execute arbitrary code with SYSTEM privileges. If you have not patched your Windows Server Update Services (WSUS) following the late October alerts, your internal network is at severe risk of compromise.
2. Oracle Identity Manager – Pre-Auth RCE
- CVE: CVE-2025-61757
- Disclosed: 20 November 2025
- Impact: A pre-authentication Remote Code Execution vulnerability has been discovered in Oracle Identity Manager. This is particularly dangerous for cloud identity environments, allowing attackers to bypass authentication entirely and gain control over identity management systems.
3. Fortinet FortiWeb – Command Injection
- CVE: CVE-2025-58034 & CVE-2025-64446
- Status: Active Exploitation.
- Impact: Multiple flaws in FortiWeb appliances are actively being targeted. CVE-2025-58034 allows authenticated command injection, while other recent flaws allow for authentication bypass. Immediate patching is required for all edge security devices.
Conclusion
The convergence of state-level sanctions and supply chain compromises like the Gainsight incident underscores that cyber threats are becoming more multi-faceted. Australian organisations cannot solely rely on internal perimeter defences; third-party risk management and rapid patch management (especially for "set and forget" services like WSUS) are critical.
Organisations in the Defence and Healthcare sectors should operate with heightened vigilance regarding long-dwelling intruders and social engineering attempts.
Contact us for a quote for penetration testing service or adversary simulation.
Daily Threat Briefing: Supply Chain Attacks Hit Defence, AI-Driven Phishing Escalates
In the last 24 hours, the Australian cyber threat landscape has been dominated by a significant supply chain compromise within the Defence sector and a surge in AI-enabled social engineering campaigns targeting the FinTech and Healthcare industries. Threat actors are increasingly leveraging third-party vulnerabilities to bypass hardened perimeters, necessitating an immediate review of vendor access privileges.
Executive Summary
In the last 24 hours, the Australian cyber threat landscape has been dominated by a significant supply chain compromise within the Defence sector and a surge in AI-enabled social engineering campaigns targeting the FinTech and Healthcare industries. Threat actors are increasingly leveraging third-party vulnerabilities to bypass hardened perimeters, necessitating an immediate review of vendor access privileges.
Sector-Specific Updates
1. Government & Defence: Supply Chain Under Siege Details have emerged overnight regarding a breach targeting IKAD Engineering, a key contractor for Australian naval projects. The ransomware group known as 'J Group' has claimed responsibility, alleging they maintained undetected access for five months.
- Impact: Potential exposure of operational data related to the Hunter Class frigate and Collins Class submarine programs. While classified technical data reportedly remains secure, the breach highlights the critical risk posed by "Tier 2" suppliers.
- Action: Defence contractors must urgently audit all external connections and enforce strict network segmentation for third-party vendors.
2. Healthcare: Ransomware Pivot We are observing a shift in tactics by ransomware affiliates who are now targeting specialist medical units with double-extortion attacks. Following the recent incidents impacting cardiology units, threat actors are deploying new ransomware variants that specifically target PACS (Picture Archiving and Communication Systems) servers, which are often left exposed to the internet for remote diagnostics.
- Threat Actor: Affiliates associated with the Qilin ransomware group.
- Action: Ensure all medical imaging servers are behind VPNs and multifactor authentication (MFA) is enforced on all remote access portals.
3. SaaS & Education: API Vulnerabilities Exploited A wave of attacks targeting SaaS-based Student Management Systems has been detected in the last 24 hours. Attackers are exploiting Broken Object Level Authorization (BOLA) vulnerabilities in APIs to scrape student personal identification information (PII).
- Target: Private education providers and EdTech platforms.
- Action: SaaS providers must immediately run API security scans to identify authorisation flaws.
4. FinTech: The Rise of Deepfake Fraud Australian FinTech firms have reported a sharp increase in AI-driven Business Email Compromise (BEC) attempts. In the last 24 hours, several high-value transfer requests were accompanied by deepfake audio messages on WhatsApp, mimicking C-suite executives to authorise fraudulent transactions.
- Action: Update verification protocols to require secondary, out-of-band authentication (e.g., a phone call to a known internal number) for all high-value transfers.
Emerging Technologies & IoT
- IoT Botnets: A new variant of the Mirai botnet has been identified scanning for unpatched vulnerabilities in Australian-manufactured smart metering devices.
- AI Systems: "Prompt injection" attacks against customer service chatbots are escalating, with attackers manipulating AI models to divulge backend system prompts and sensitive customer data.
Critical Vulnerabilities Exploited
- Cloud Edge Gateways: Active exploitation of a zero-day vulnerability in a widely used SSL VPN appliance was observed late yesterday. This flaw allows unauthenticated remote code execution (RCE) at the network edge.
- Web Applications: Deserialisation vulnerabilities in Java-based e-commerce platforms are being weaponised to deploy web shells.
Conclusion
The events of the last 24 hours underscore that perimeter defences are no longer sufficient. The breach of a defence contractor through a third party and the use of AI to bypass human verification in FinTech demonstrate that trust must be verified at every level—whether it is a vendor, an API call, or an executive's voice.
Contact us for a quote for penetration testing service or adversary simulation.