Australian Monthly Threat Briefing: December 2025
As we close out 2025, the Australian cyber threat landscape has witnessed a volatile December, characterised by a sharp escalation in sector-specific ransomware campaigns and the weaponisation of critical vulnerabilities in cloud and AI infrastructure. Threat actors have aggressively targeted the "edge" of Australian networks—exploiting SaaS platforms, unpatched IoT devices, and third-party supply chains.
As we close out 2025, the Australian cyber threat landscape has witnessed a volatile December, characterised by a sharp escalation in sector-specific ransomware campaigns and the weaponisation of critical vulnerabilities in cloud and AI infrastructure. Threat actors have aggressively targeted the "edge" of Australian networks—exploiting SaaS platforms, unpatched IoT devices, and third-party supply chains.
This briefing summarises the key threats, incidents, and vulnerabilities impacting Australian organisations over the last 30 days.
Sector-Specific Threat Intelligence
Healthcare
The healthcare sector remains under immense pressure. A major audit released in mid-December revealed systemic security bypasses within NSW Health districts, highlighting a culture of non-compliance that leaves patient data exposed. Concurrently, the Point Lonsdale Medical Group in Victoria suffered a significant cyber attack, resulting in unauthorised access to sensitive patient information. These incidents underscore the critical need for strict identity management and network segmentation in medical environments.
SaaS Providers
Software-as-a-Service (SaaS) providers are facing a dual threat from infrastructure vulnerabilities and supply chain attacks. Hexicor, an IT services provider, was targeted by the KillSec ransomware gang, which exfiltrated client folders and hashed passwords. This breach serves as a stark warning for SaaS platforms to enforce rigorous third-party risk management, as attackers increasingly use service providers as a pivot point to compromise downstream clients.
FinTech
December was a particularly damaging month for the financial technology sector. Austin’s Financial Solutions fell victim to the Kairos ransomware group, which allegedly stole 147GB of data, including employee passports and payroll records. Additionally, mortgage broker Finsure confirmed a cyber incident impacting nearly 300,000 unique email addresses. Regulatory scrutiny is also intensifying, with the Commonwealth Bank facing fines for Consumer Data Right breaches, emphasising the heavy compliance burden FinTechs face alongside active criminal targeting.
Education / EdTech
Australian universities continue to be prime targets for both hacktivists and extortionists. The University of New South Wales (UNSW) Physics Department was targeted by the hacktivist group RipperSec, disrupting website operations. Meanwhile, the University of Sydney confirmed a breach of an online IT code repository, exposing the fragility of development environments. The KillSec gang has also been observed aggressively targeting EdTech platforms, exploiting the high value of student data for extortion.
Government & Defence
A critical supply chain breach hit IKAD Engineering, a key defence contractor, exposing sensitive data related to Australia’s naval and weapons programs. This incident, claimed by ransomware actors, highlights the persistent threat to the Defence Industry Security Program (DISP) members. At the local government level, Muswellbrook Shire Council suffered a severe ransomware attack by the SafePay gang, which published 175GB of internal data after negotiations failed.
IoT & Critical Infrastructure
The "edge" remains a favoured entry point. The Australian Cyber Security Centre (ACSC) issued multiple alerts regarding the active exploitation of Cisco and WatchGuard edge devices. Threat actors are chaining vulnerabilities in these internet-facing appliances to bypass authentication and gain initial access to critical infrastructure networks.
Critical Vulnerabilities: Web, Cloud, & AI
Penetration testers and defenders must prioritise the following vulnerabilities, which have seen active exploitation or high-risk disclosure in the last 30 days:
AI Systems (LangChain Prompt Injection): A core vulnerability was identified in LangChain, a framework widely used for building AI applications. This flaw allows for "prompt injection" attacks, enabling attackers to manipulate Large Language Model (LLM) outputs to exfiltrate data or execute unauthorised commands. As Australian organisations race to integrate AI, this represents a significant, often overlooked attack vector.
Web Applications (React Server Components - CVE-2025-55182): A critical Remote Code Execution (RCE) vulnerability was discovered in React Server Components. Given the ubiquity of React in modern Australian web applications, this flaw poses a severe risk, allowing attackers to take control of servers hosting vulnerable apps.
Cloud Infrastructure (Fortinet FortiCloud SSO - CVE-2025-59718 & CVE-2025-59719): Critical authentication bypass vulnerabilities were patched in FortiCloud. These flaws allow attackers to bypass Single Sign-On (SSO) protections and gain administrative access to cloud-managed security appliances. Immediate patching is mandatory.
API Security: The Vroom by YouX incident earlier this month, which exposed driver's licences via a non-password-protected database, serves as a reminder of the dangers of API misconfigurations and "Zombie APIs" that lack proper access controls.
Conclusion
December 2025 has demonstrated that no sector is immune to sophisticated cyber coercion. From the exploitation of cutting-edge AI frameworks to the brute-force compromising of unpatched edge firewalls, the threat landscape is diverse and unforgiving. Organisations must move beyond compliance-based security and adopt a proactive stance—validating their defences against these real-world adversary behaviours.
Contact us for a quote for penetration testing service or adversary simulation.
Daily Threat Briefing: Australia – 31 December 2025
As we close out 2025, the Australian cyber threat landscape remains volatile. The last 24 hours have been dominated by the rapid exploitation of the "MongoBleed" vulnerability, with the Australian Cyber Security Centre (ACSC) and global agencies issuing urgent warnings. Simultaneously, the education sector is grappling with fresh data breaches, and critical infrastructure supply chains remain under siege from ransomware syndicates.
Executive Summary
As we close out 2025, the Australian cyber threat landscape remains volatile. The last 24 hours have been dominated by the rapid exploitation of the "MongoBleed" vulnerability, with the Australian Cyber Security Centre (ACSC) and global agencies issuing urgent warnings. Simultaneously, the education sector is grappling with fresh data breaches, and critical infrastructure supply chains remain under siege from ransomware syndicates.
Below is a deep dive into the threats impacting Australian organisations today.
Sector-Specific Threat Intelligence
SaaS & Cloud Providers
- The "MongoBleed" Crisis (CVE-2025-14847): A critical unauthenticated memory-read vulnerability in MongoDB servers is being actively exploited globally. Attackers are weaponising this flaw to read uninitialized memory, potentially scraping API keys, session tokens, and credentials without logging in. Australian SaaS providers utilising MongoDB for backend data storage are at high risk. The ACSC has observed active scanning against local IP addresses.
- React Framework Exploitation: The "React2Shell" vulnerabilities (CVE-2025-55182 & CVE-2025-66478) continue to plague developers. Over 500 Australian organisations remain vulnerable to this Remote Code Execution (RCE) flaw, which Chinese-affiliated threat actors are using to compromise web applications via crafted HTTP requests.
Education & EdTech
- University of Sydney Data Breach: Reports have confirmed a significant breach impacting over 13,000 individuals, including staff, students, and alumni. This incident follows a broader trend of targeted attacks against the tertiary education sector this month.
- RipperSec Activity: The hacktivist group RipperSec has been observed targeting Australian university networks with DDoS attacks and defacement campaigns, likely exploiting unpatched edge devices during the holiday shut-down period.
Healthcare
- Rhysida Ransomware Fallout: The Rhysida group continues to pressure the Australian healthcare sector. Following the attack on a Queensland medical centre earlier this month, the group is threatening to auction sensitive patient data—including pathology reports and health summaries—if ransoms are not paid. This highlights the critical need for network segmentation in medical environments.
- General Threat: With 102 breaches reported in the last six months alone, healthcare remains the number one target for data extortion in Australia.
IoT & Critical Infrastructure
- Netstar Australia Incident: A cyber attack on the technology and GPS tracking firm Netstar has raised concerns regarding fleet management and IoT supply chains. Disruption to IoT telemetry data can have cascading effects on logistics and transport sectors.
- Edge Device Targeting: The WatchGuard Firebox zero-day (CVE-2025-14733) is being ruthlessly exploited. Threat actors are using this RCE vulnerability to gain initial access to corporate networks, bypassing perimeter defences.
Government & Defence
- Supply Chain Risks: The breach of defence contractor IKAD Engineering, resulting in the exfiltration of 800GB of data, serves as a stark warning. Threat actors are increasingly pivoting from third-party suppliers to primary targets.
- Local Council Ransomware: The SafePay ransomware gang has escalated its double-extortion tactics, recently publishing 175GB of data stolen from the Muswellbrook Shire Council.
Critical Vulnerabilities Exploited in the Wild
Penetration testers and defenders must prioritise the following vulnerabilities, which are currently seeing active exploitation in the Australian region:
MongoDB Server (CVE-2025-14847) - "MongoBleed"
- Type: Information Disclosure / Memory Leak
- Impact: Allows unauthenticated attackers to read sensitive data (tokens, keys) from memory.
- Action: Patch immediately to the latest fixed release or restrict internet access to the database port.
WatchGuard Firebox (CVE-2025-14733)
- Type: Remote Code Execution (RCE)
- Impact: Unauthenticated remote takeover of the firewall appliance.
- Action: Apply the latest Fireware OS patch or implement strict access control lists (ACLs) for management interfaces.
React Server Components (CVE-2025-55182)
- Type: Remote Code Execution
- Impact: Allows attackers to execute arbitrary code on the server via malformed "Flight" protocol payloads.
- Action: Update React and Next.js frameworks to non-vulnerable versions immediately.
Active Threat Actors
- Rhysida: Financially motivated ransomware-as-a-service (RaaS). Known for double-extortion and targeting the healthcare sector.
- KillSec: Recently active against Australian IT service providers, focusing on stealing credentials and client data.
- SafePay: A ransomware group targeting local government and public sector entities, using data publication as leverage.
Contact us for a quote for penetration testing service or adversary simulation.
Daily Threat Briefing: MongoBleed Critical Alert, Sydney Uni Breach & SaaS Risks
The last 24 hours have been dominated by urgent warnings from the Australian Cyber Security Centre (ACSC) regarding a massive global exploitation campaign targeting database infrastructure. As we approach the New Year, threat actors are capitalising on skeleton staff schedules to launch high-impact attacks. Today's briefing highlights a critical MongoDB vulnerability, a significant data breach in the Australian education sector, and ongoing pressure on SaaS supply chains.
Executive Summary
The last 24 hours have been dominated by urgent warnings from the Australian Cyber Security Centre (ACSC) regarding a massive global exploitation campaign targeting database infrastructure. As we approach the New Year, threat actors are capitalising on skeleton staff schedules to launch high-impact attacks. Today's briefing highlights a critical MongoDB vulnerability, a significant data breach in the Australian education sector, and ongoing pressure on SaaS supply chains.
Top Story: 'MongoBleed' (CVE-2025-14847) Exploited in the Wild
The most pressing threat for Australian organisations today is the active exploitation of CVE-2025-14847, dubbed "MongoBleed".
- The Threat: A critical vulnerability in MongoDB servers (specifically handling zlib-compressed messages) allows unauthenticated remote attackers to read memory fragments from the database.
- Impact: This flaw can leak sensitive data, including authentication credentials, session keys, and customer PII, without requiring a valid login.
- Status: The ACSC and CISA issued alerts late yesterday (29 December) confirming active global exploitation. Proof-of-concept code is public, and automated scanning is widespread.
- Action: All organisations using MongoDB, particularly within FinTech and eCommerce environments where customer databases are central, must patch immediately or disable zlib compression as a temporary mitigation.
Sector Watch
Education / EdTech
- University of Sydney Data Breach: Reports have confirmed a significant cyber incident affecting the University of Sydney. Threat actors successfully exfiltrated the personal data of approximately 13,000 individuals, including staff, alumni, and donors. This incident underscores the vulnerability of the education sector to data theft, particularly during holiday shutdowns when monitoring may be reduced.
Healthcare
- Global Supply Chain Risks: Following the confirmation of a cyber attack on a major NHS England provider, Australian healthcare organisations are urged to review their third-party risk exposure. The interconnected nature of modern digital health systems means that a breach in a software supplier can have cascading effects on patient data privacy and hospital operations locally.
SaaS & Government
- Supply Chain Fallout: The ripple effects of the recent BeyondTrust breach continue to surface. With attackers having exploited zero-day vulnerabilities (CVE-2024-12356/12686) to compromise Remote Support SaaS instances, government agencies and SaaS providers using privileged access management tools must rigorously audit their access logs.
- WatchGuard & Fortinet Alerts: The ACSC has reiterated warnings for WatchGuard Firebox (CVE-2025-14733) and Fortinet products. These critical vulnerabilities are currently being leveraged by adversaries to gain initial access to corporate networks, bypassing perimeter defences.
IoT & Infrastructure
- Edge Device Targeting: Adversaries are increasingly targeting unpatched edge devices. The WatchGuard vulnerability mentioned above is a prime example of threat actors focusing on IoT and network appliances that often lack the robust endpoint protection found on servers and workstations.
Technical Analysis: The Rise of Unauthenticated Data Leaks
The emergence of "MongoBleed" represents a shift towards vulnerabilities that allow data exfiltration without full system compromise (RCE). By reading server memory, attackers can silently harvest credentials to stage more complex attacks later.
- Vector: Network-based, unauthenticated.
- Mitigation: Upgrade to the latest MongoDB release immediately. If patching is not feasible today, network segmentation and disabling compression are critical interim steps.
Contact us for a quote for penetration testing service or adversary simulation.
Daily Threat Briefing: Australia – 29 December 2025
The last 24 hours have seen a surge in targeted activity against the Australian Education and IoT sectors, with critical infrastructure devices remaining a primary entry point for threat actors. The Australian Cyber Security Centre (ACSC) has flagged active exploitation of new vulnerabilities in network edge devices, while the 'KillSec' and 'Medusa' ransomware gangs have claimed significant breaches in local organisations.
Executive Summary
The last 24 hours have seen a surge in targeted activity against the Australian Education and IoT sectors, with critical infrastructure devices remaining a primary entry point for threat actors. The Australian Cyber Security Centre (ACSC) has flagged active exploitation of new vulnerabilities in network edge devices, while the 'KillSec' and 'Medusa' ransomware gangs have claimed significant breaches in local organisations.
Today's briefing highlights critical flaws in AI development frameworks and widespread attacks on educational institutions, underscoring the need for urgent patching and heightened vigilance across all sectors.
Top Critical Vulnerabilities
- WatchGuard Firebox (CVE-2025-14733): The ACSC has issued a critical alert regarding this vulnerability, which is currently being actively exploited in the wild. Attackers are using this flaw to gain unauthorised access to corporate networks. Immediate patching is non-negotiable.
- React Server Components (CVE-2025-55182): A critical severity vulnerability has been discovered in React Server Components, a popular web development framework. This flaw could allow remote code execution (RCE) on servers hosting modern web applications.
- LangChain Prompt Injection (AI Security): A core vulnerability has been identified in LangChain, a widely used framework for building AI applications. This flaw allows for prompt injection attacks that can lead to data exposure, posing a significant risk to SaaS providers integrating LLMs.
- Fortinet FortiCloud SSO (CVE-2025-59718 & CVE-2025-59719): Critical authentication bypass vulnerabilities continue to be targeted. These allow attackers to bypass login protections on the FortiCloud Single Sign-On service.
Sector-Specific Threat Intelligence
Education & EdTech The education sector is currently under siege. Waverley Christian College has confirmed a cyber incident after the Fog ransomware group claimed to have exfiltrated 5GB of data. Simultaneously, the KillSec ransomware gang has claimed a breach of the Australian educational support platform "Thanks For the Help" (TFTH). These incidents highlight the vulnerability of student data and the aggressive targeting of schools and their third-party providers.
Government Following the recent ransomware incident affecting Muswellbrook Shire Council, the SafePay ransomware gang has reportedly published 175GB of stolen data, intensifying the pressure on local government bodies to review their data resiliency and backup strategies. Additionally, the ACSC is monitoring a rise in "impersonation scams" where cybercriminals pose as Australian Federal Police to target cryptocurrency wallets.
Healthcare Harbour Town Doctors has reportedly suffered a patient data breach. With the healthcare sector accounting for a significant portion of all Australian breaches this year, this incident serves as a stark reminder of the value of medical records on the dark web. Medical practices are urged to audit their access logs and secure third-party remote access points immediately.
SaaS & IoT Netstar Australia, a technology and GPS firm, has suffered an alleged cyber attack, potentially impacting fleet management and IoT tracking services. This supply chain risk reinforces the importance of securing IoT endpoints. Meanwhile, the discovery of the LangChain vulnerability puts SaaS providers utilising AI features on high alert; developers must validate inputs rigorously to prevent prompt injection.
FinTech Austin’s Financial Solutions is dealing with the fallout of a claimed breach by the Kairos ransomware group, involving sensitive financial data and employee records. The Commonwealth Bank (CommBank) has also faced regulatory scrutiny, being fined over breaches of Consumer Data Right rules, emphasising the dual pressure of security threats and compliance mandates in the FinTech space.
Adversary Watch
- KillSec: Aggressively targeting Australian EdTech and service providers.
- Medusa: Claimed responsibility for a massive data theft (over 800GB) from Ainsworth Game Technology, showing a pivot towards high-revenue commercial targets.
- Pro-Russia Hacktivists: Continue to conduct opportunistic DDoS and defamation attacks against critical infrastructure, as noted in recent joint advisories.
Recommendation Organisations across Australia must prioritise patching WatchGuard and Fortinet devices immediately. Education and Healthcare providers should review their third-party risk management frameworks and ensure offline backups are immutable.
Contact us for a quote for penetration testing service or adversary simulation.
Weekly Threat Briefing: Australia (21 December – 28 December 2025)
As we close out 2025, the Australian cyber threat landscape remains volatile. This week (21–28 December 2025) has been defined by a significant ransomware attack on critical telematics infrastructure, continued fallout from defence supply chain compromises, and a "Perfect 10" severity vulnerability in a widely used web framework. Threat actors are aggressively targeting the convergence of IoT and critical infrastructure, while the Education and FinTech sectors face renewed pressure from data extortion groups. Below is your detailed briefing on the threats impacting Australian organisations this week.
Executive Summary
As we close out 2025, the Australian cyber threat landscape remains volatile. This week (21–28 December 2025) has been defined by a significant ransomware attack on critical telematics infrastructure, continued fallout from defence supply chain compromises, and a "Perfect 10" severity vulnerability in a widely used web framework.
Threat actors are aggressively targeting the convergence of IoT and critical infrastructure, while the Education and FinTech sectors face renewed pressure from data extortion groups. Below is your detailed briefing on the threats impacting Australian organisations this week.
Sector Intelligence
Government & Critical Infrastructure: The Netstar Incident
The most significant incident this week involves Netstar Australia, a Melbourne-based GPS and telematics provider heavily used by government and critical infrastructure operators. On 22 December 2025, the Black Shrantac ransomware group listed Netstar on its dark web leak site, claiming to have exfiltrated 800GB of data.
- Impact: Netstar provides fleet tracking for essential services. The compromise of real-time location data and customer databases poses a severe physical security risk.
- Threat Actor: Black Shrantac is a relatively new group (first detected September 2025). This is their first major Australian victim, signalling a shift towards targeting operational technology (OT) and IoT intermediaries.
- Defence Fallout: The sector is also managing the ongoing impact of the IKAD Engineering breach (reported earlier in December), where the J Group gang stole sensitive data related to the Hunter Class frigate program. These incidents highlight a critical weakness in the Australian defence and government supply chain.
Education: University of Sydney Breach
The University of Sydney is managing a serious data breach notified to staff and students on 18 December 2025, with containment efforts continuing this week.
- Vector: Unauthorised access to an online IT code library.
- Data Exposed: Historical data belonging to 13,000 staff, donors, and alumni.
- Analysis: This incident underscores the risk of "shadow IT" and forgotten repositories. Educational institutions remain high-value targets due to the vast amounts of PII and intellectual property they hold.
Healthcare: Ransomware Persistence
The healthcare sector remains the top target for data breaches in Australia.
- Point Lonsdale Medical Group (PLMG): Recently disclosed a cyber attack compromising patient information.
- Trend: Ransomware groups are moving away from pure encryption to "extortion-only" attacks, threatening to release sensitive medical records if payment is not made. With the Antidot Banker malware also circulating, healthcare apps on employee devices are at increased risk of credential theft.
FinTech & SaaS: Wealth Management Targeted
- Austin’s Financial Solutions: The Kairos ransomware group claimed responsibility for a breach this week, allegedly stealing 147GB of data, including employee passports and payroll records.
- SaaS Risk: FinTech platforms are on high alert due to the React2Shell vulnerability (see below), which allows attackers to execute code on servers running modern web applications.
Technical Spotlight: Critical Vulnerabilities
Security teams must prioritise the following exploited vulnerabilities identified this week:
1. React2Shell (CVE-2025-55182)
- Severity: Critical (CVSS 10.0)
- Target: Web Applications & SaaS
- Details: A remote code execution (RCE) vulnerability in React Server Components (versions 19.0 – 19.2.0).
- Risk: This flaw allows unauthenticated attackers to execute arbitrary code by sending a malicious payload to the server. It is being actively exploited by Chinese state-sponsored actors and cybercriminal syndicates to compromise Next.js applications commonly used in FinTech and eCommerce.
- Action: Patch immediately to version 19.2.1 or later.
2. WatchGuard Firebox (CVE-2025-14733)
- Severity: Critical
- Target: Network Edge / IoT
- Alert Date: 22 December 2025 (ASD ACSC Alert)
- Details: Active exploitation of a vulnerability in WatchGuard Firebox devices.
- Action: Apply emergency firmware updates. This is a primary vector for initial access into corporate networks.
3. Fortinet Cloud SSO Bypass (CVE-2025-59718)
- Severity: Critical
- Target: Cloud Management
- Details: An authentication bypass vulnerability in FortiCloud SSO.
- Risk: Allows attackers to gain administrative access to cloud-managed security appliances, effectively turning security tools into backdoors.
4. n8n Workflow Automation (CVE-2025-68613)
- Severity: Critical (CVSS 9.9)
- Target: AI Systems & Automation
- Details: RCE via expression injection in the n8n workflow tool.
- Relevance: As organisations rush to adopt AI automation, tools like n8n are becoming critical single points of failure. An attacker can use this to steal API keys and pivot into connected internal systems.
AI Security Watch
The rapid integration of AI into government systems is raising alarms. Reports this week indicate the Department of Home Affairs is deploying AI on sensitive data, coinciding with new warnings about Prompt Injection attacks. The exploitation of the n8n vulnerability (CVE-2025-68613) demonstrates that the infrastructure supporting AI agents is currently a softer target than the models themselves.
Recommendations for the Week Ahead
- Audit Supply Chain Access: In light of the Netstar and IKAD breaches, review all third-party vendors who have physical or digital access to your infrastructure.
- Patch React Environments: If your organisation uses Next.js or React Server Components, verify that the patch for CVE-2025-55182 has been applied. This is a "drop everything" patch.
- Secure Code Repositories: The University of Sydney incident serves as a reminder to scan public and private code repositories for hardcoded credentials and sensitive historical data.
Contact us for a quote for penetration testing service or adversary simulation.