Monthly Threat Briefing: Australia – November 2025

Monthly Threat Briefing: Australia – November 2025

As we approach the holiday season, the Australian cyber threat landscape has intensified, with November 2025 marking a significant surge in ransomware activity and sophisticated supply chain attacks. The Australian Signals Directorate (ASD) and private sector intelligence indicate that threat actors are increasingly capitalising on reduced staffing levels during weekends and public holidays, a trend expected to escalate as we head into December. This month’s briefing analyses critical incidents and emerging vulnerabilities across key sectors, highlighting the urgent need for robust defence mechanisms in web applications, cloud environments, and AI systems.

Australian Cyber Threat Briefing: Record DDoS, SaaS Supply Chain Risks, and Holiday Scams

Australian Cyber Threat Briefing: Record DDoS, SaaS Supply Chain Risks, and Holiday Scams

As we enter December, the Australian cyber threat landscape has escalated sharply. In the last 24 hours, security teams across the nation have faced a convergence of sophisticated state-sponsored activity, record-breaking DDoS attacks, and targeted supply chain compromises. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and global intelligence feeds indicate a critical surge in threats targeting SaaS environments and healthcare infrastructure. This briefing covers the most significant threats, threat actors, and vulnerabilities identified over the weekend and into today, specifically tailored for Australian organisations.

Daily Threat Briefing: Australia’s Holiday Cyber Surge & Critical Sector Alerts

Daily Threat Briefing: Australia’s Holiday Cyber Surge & Critical Sector Alerts

As we wrap up the Black Friday weekend and move into the holiday season, the Australian cyber threat landscape has seen a significant escalation in activity over the last 24 hours. Our deep dive into the latest intelligence reveals a coordinated surge in campaigns targeting the government, healthcare, and retail sectors. Advanced Persistent Threats (APTs) and opportunistic criminal gangs are leveraging AI-driven automation to exploit new vulnerabilities in web applications and APIs. Click to get a more detailed breakdown of the critical threats, exploited vulnerabilities, and active threat actors impacting Australian organisations today.

Australian Weekly Threat Briefing: Defence Supply Chain Breached & SaaS Under Siege

Australian Weekly Threat Briefing: Defence Supply Chain Breached & SaaS Under Siege

This week has seen a significant escalation in cyber activity targeting Australian critical infrastructure and supply chains. The most alarming development is a confirmed breach of a major Defence contractor, potentially exposing sensitive naval data. Simultaneously, a sophisticated campaign by the "Scattered Lapsus$ Hunters" group is aggressively targeting SaaS platforms, with Qantas and Zendesk users in the crosshairs. As we approach the holiday season, a new report warns that ransomware operators are leveraging Generative AI to time attacks for weekends and public holidays, specifically targeting periods of reduced staffing in Security Operations Centres (SOCs).

Daily Threat Briefing: AI-Driven Phishing & The Machine Identity Crisis

Daily Threat Briefing: AI-Driven Phishing & The Machine Identity Crisis


In the last 24 hours, the Australian cyber threat landscape has been dominated by the rapid weaponisation of Generative AI and the escalation of "non-human" identity compromises. Following the patterns identified earlier this year in the ACSC's Annual Cyber Threat Report, we are seeing a shift from traditional credential stuffing to sophisticated, AI-enhanced social engineering and API-based attacks. Today's briefing highlights a coordinated campaign targeting the Healthcare and FinTech sectors, leveraging deepfake technology to bypass biometric verification. Additionally, new intelligence suggests state-sponsored actors are actively exploiting "shadow AI" implementations in Government supply chains.

Australia’s Cyber Siege: Healthcare Ransomware, API Exploits, and the Holiday Scam Surge

Australia’s Cyber Siege: Healthcare Ransomware, API Exploits, and the Holiday Scam Surge

The last 24 hours have underscored a critical reality for Australian CISOs and security teams: the separation between "sector-specific" threats is vanishing. From the 15.72 Tbps DDoS attack aimed at Australian infrastructure to the targeted ransomware campaigns crippling regional healthcare, the tempo of operations is accelerating as we approach the holiday season. As a penetration testing team, we are closely monitoring active exploitation in the wild. Below is your deep-dive briefing on the threats shaping the Australian landscape today.

SessionReaper & BFCM: Why Penetration Testing Services Are Critical (CVE-2025-54236)

SessionReaper & BFCM: Why Penetration Testing Services Are Critical (CVE-2025-54236)

A critical vulnerability in Adobe Commerce and Magento (CVE-2025-54236), dubbed "SessionReaper," is being ruthlessly exploited by threat actors using AI-driven tools to automate attacks at machine speed. With the Australian holiday trading season in full swing, this unauthenticated remote code execution (RCE) flaw poses an immediate existential threat to retail and B2B organizations. This alert outlines the mechanics of the attack, the role of AI in its weaponization, and the urgent defensive actions required to prevent a catastrophic data breach.

Daily Threat Briefing: Australia – 26 November 2025

Daily Threat Briefing: Australia – 26 November 2025

The last 24 hours have seen a significant escalation in the Australian cyber threat landscape, characterised by a convergence of AI-driven offensive operations and high-impact data breaches. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and private sector intelligence indicate a sharp rise in automated attacks targeting the Healthcare, FinTech, and Government sectors. Of particular concern is the emergence of AI agents capable of automating complex attack chains, reducing the time from vulnerability discovery to exploitation to near zero.

Daily Threat Briefing: Record DDoS Hits Australia & Critical Fortinet Flaws

Daily Threat Briefing: Record DDoS Hits Australia & Critical Fortinet Flaws

In the last 24 hours, the Australian cyber threat landscape has been dominated by a record-breaking Distributed Denial of Service (DDoS) attack targeting local cloud infrastructure, alongside critical alerts for widely used enterprise edge devices. The Australian Securities and Investments Commission (ASIC) has also signalled a major shift in regulatory enforcement regarding cyber resilience in the financial sector.

Daily Threat Briefing: Russian Sanctions, Salesforce Supply Chain Risks & Critical WSUS Exploits

Daily Threat Briefing: Russian Sanctions, Salesforce Supply Chain Risks & Critical WSUS Exploits

The last 24 to 48 hours have seen significant shifts in the Australian cyber threat landscape, dominated by a major government crackdown on ransomware facilitators and a developing supply chain incident affecting the Salesforce ecosystem. In a coordinated move with the US and UK, the Australian Government has imposed sanctions on Russian individuals and entities providing "bulletproof hosting" to gangs like LockBit and Clop. Meanwhile, organisations relying on Salesforce are on high alert following confirmed unauthorized activity linked to third-party Gainsight applications, with threat actors claiming widespread access. On the vulnerability front, a critical Microsoft WSUS flaw (CVE-2025-59287) is seeing active exploitation, demanding immediate attention from system administrators.