Weekly Threat Briefing Lean Security Expert Weekly Threat Briefing Lean Security Expert

Weekly Threat Briefing: Critical Zero-Days and Nation-State Shifts Targeting Australia

The last seven days (26 January – 02 February 2026) have been defined by a resurgence in high-criticality infrastructure vulnerabilities and evolving nation-state tradecraft. For Australian organisations, the immediate priority is addressing active exploitation of Ivanti Endpoint Manager Mobile (EPMM) zero-days and critical patches for Cisco network infrastructure. Simultaneously, the threat landscape is shifting with reports of North Korean APT groups restructuring their operations, while the healthcare sector faces renewed warnings regarding IT/OT convergence risks.

Executive Summary

The last seven days (26 January – 02 February 2026) have been defined by a resurgence in high-criticality infrastructure vulnerabilities and evolving nation-state tradecraft. For Australian organisations, the immediate priority is addressing active exploitation of Ivanti Endpoint Manager Mobile (EPMM) zero-days and critical patches for Cisco network infrastructure. Simultaneously, the threat landscape is shifting with reports of North Korean APT groups restructuring their operations, while the healthcare sector faces renewed warnings regarding IT/OT convergence risks.


Top Priority: Exploited Vulnerabilities

1. Ivanti Endpoint Manager Mobile (EPMM) Zero-Days

Date Detected: 30 January 2026 Sector Impact: Government, SaaS, Enterprise Late last week, Ivanti issued an urgent warning regarding the active exploitation of zero-day vulnerabilities in its Endpoint Manager Mobile (EPMM). Threat actors are leveraging these flaws to bypass authentication and execute arbitrary code on mobile management gateways. Given the widespread use of Ivanti in Australian government and enterprise environments, this represents a critical risk.

  • Action: Immediate patching is required. Security teams should hunt for indicators of compromise (IoCs) in gateway logs dating back to mid-January.

2. Cisco Network Infrastructure Vulnerabilities

Date Released: 27 January 2026 Sector Impact: All Sectors (Critical Infrastructure focus) Cisco released a major security advisory on Tuesday addressing multiple critical vulnerabilities in its IOS XE software. Exploitation allows unauthenticated remote attackers to gain administrative control over network devices. With Australian critical infrastructure heavily reliant on Cisco backbones, these vulnerabilities are a prime target for initial access brokers.


Sector-Specific Threat Intelligence

Healthcare: The IT/OT "Cascade" Effect

A new report released on 27 January 2026 by Trellix highlights a dangerous trend affecting the healthcare sector: the "cascading" effect of cyber attacks moving from administrative IT systems into Operational Technology (OT) and patient care workflows.

  • Analysis: Australian healthcare providers are increasingly digitising patient systems. The report indicates that 75% of recent threats originated in non-clinical environments (e.g., email phishing) before laterally moving to impact medical devices.
  • Recommendation: Network segmentation between clinical OT and administrative IT is no longer optional—it is a patient safety imperative.

Government: BEC and Social Engineering

A significant incident surfaced this week involving a $3.5 million loss from a government agency due to a sophisticated Business Email Compromise (BEC) attack. The perpetrators impersonated a construction contractor, leveraging deepfake-enhanced social engineering to authorise fraudulent payments.

  • Takeaway: Technical controls (like MFA) must be supplemented with strict procedural verification for high-value transactions.

SaaS & Cloud: Salesforce Ecosystem Risks

Reports have emerged regarding a targeted campaign against Salesforce environments. While not a direct breach of Salesforce's core infrastructure, attackers are successfully harvesting high-privilege credentials via sophisticated phishing campaigns targeting Australian SaaS administrators.

  • Risk: Once inside, attackers are exfiltrating customer databases and manipulating API integrations to maintain persistence.

FinTech & AI: The Implementation Trap

As Australian FinTechs rush to integrate AI-driven customer service agents, new research from Cyber Daily (30 January) warns of "AI implementation risks." Early audits suggest that many of these AI systems suffer from prompt injection vulnerabilities, allowing attackers to manipulate banking chatbots into disclosing sensitive user data or bypassing fraud checks.


Threat Actor Focus: North Korean APT Evolution

Intelligence surfacing on 30 January indicates a strategic shift within the infamous North Korean hacking ecosystem (often linked to the Lazarus Group). The group appears to be "dividing to conquer," splitting into smaller, specialised cells.

  • New Tactics: One cell is focusing exclusively on cryptocurrency theft to fund state activities, while another is dedicated to supply chain espionage against the defence and education sectors.
  • Relevance: Australian universities and defence contractors should anticipate highly targeted spear-phishing campaigns tailored to their specific research and development projects.

Recommendations for the Week Ahead

  1. Patch Immediately: Prioritise Ivanti EPMM and Cisco IOS XE updates.
  2. Review BEC Procedures: Verify payment details offline for all transactions over $10,000.
  3. Segregate OT Networks: Ensure clinical devices in healthcare settings are isolated from email and internet-facing segments.
  4. Audit AI Models: If you are deploying LLMs in customer-facing roles, conduct adversarial testing for prompt injection flaws.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: AI Model Hosting Abuse & New SSO Phishing Campaigns

In the last 24 hours, the Australian cyber threat landscape has been dominated by sophisticated abuse of AI infrastructure and targeted identity attacks. A new report released today highlights how threat actors are weaponising legitimate AI hosting platforms to distribute malware, bypassing traditional perimeter defences. Simultaneously, the FinTech and SaaS sectors are facing a resurgence of human-led phishing campaigns targeting Single Sign-On (SSO) credentials.

Executive Summary

In the last 24 hours, the Australian cyber threat landscape has been dominated by sophisticated abuse of AI infrastructure and targeted identity attacks. A new report released today highlights how threat actors are weaponising legitimate AI hosting platforms to distribute malware, bypassing traditional perimeter defences. Simultaneously, the FinTech and SaaS sectors are facing a resurgence of human-led phishing campaigns targeting Single Sign-On (SSO) credentials.

This briefing covers critical developments impacting Healthcare, Education, Government, and the SaaS supply chain.


Emerging Threats & Attack Vectors

1. AI Systems: Hugging Face Weaponised for Malware Distribution

Sectors: eCommerce, Technology, General Threat Actor: Unknown / Cybercrime Groups

A significant development reported today involves the abuse of Hugging Face, a popular platform for hosting machine learning models. Researchers at Bitdefender have identified a campaign where attackers are using the platform to host and distribute a malicious Android Remote Access Trojan (RAT) disguised as a security app called "TrustBastion".

  • The Attack: Users are lured via deceptive advertisements warning of device infection. The malicious app, once installed, fetches its payload directly from a Hugging Face repository.
  • Why it Matters: By hosting malware on a trusted domain like Hugging Face, attackers can evade standard network filtering and reputation-based blocking used by many Australian enterprises. This represents a dangerous evolution in "Living off the Land" tactics, now extending to AI infrastructure.

2. SaaS & FinTech: ShinyHunters Targeting Okta SSO

Sectors: FinTech, SaaS Providers Threat Actor: ShinyHunters / SLSH Alliance

New intelligence from Silent Push indicates a large-scale, human-led phishing campaign targeting Okta Single Sign-On (SSO) accounts. Unlike automated credential stuffing, this campaign employs "vishing" (voice phishing) and real-time social engineering to bypass Multi-Factor Authentication (MFA).

  • Targets: High-value targets in FinTech (payment processors) and SaaS platforms.
  • Impact: Successful compromise allows threat actors to pivot into corporate dashboards, accessing sensitive customer data and financial systems. This is a critical alert for any organisation relying on federated identity providers.

Sector-Specific Updates

Education: Victorian Schools Targeted

Reports have surfaced regarding a cyber incident affecting Victorian schools, disrupting IT networks and raising concerns over student data privacy. This follows a trend of increasing ransomware pressure on the Australian education sector, where legacy systems often struggle to repel modern "big game hunting" tactics.

Government: NSW Overhauls Cyber Emergency Plan

In response to the escalating threat environment, the NSW Government has announced a major overhaul of its state cyber emergency plan. The new framework mandates that government agencies report incidents to Cyber Security NSW within 24 hours and introduces stricter "Crown Jewel" asset management plans. This regulatory shift underscores the need for public sector agencies to move from compliance-based security to active resilience.

Healthcare: Persistent Data Risks

The healthcare sector remains a primary target. Following a series of breaches affecting providers like Diabetes WA and DBG Health over the past year, the Australian healthcare industry is being urged to adopt "secure by design" principles. The monetisation of medical records on the dark web continues to drive ransomware activity against clinics and support organisations.


Critical Vulnerabilities (CVEs)

Penetration testers and sysadmins should prioritise the following vulnerabilities which are relevant to Australian infrastructure:

  • n8n Workflow Automation (CVE-2026-21858): A Critical unauthenticated Remote Code Execution (RCE) vulnerability in the n8n platform. As this tool is widely used by SaaS providers and internal dev teams for automation, it represents a high-risk entry point. Patch immediately.
  • Cisco Network Infrastructure: The Australian Cyber Security Centre (ACSC) and WA Cyber Security Unit have issued alerts regarding critical vulnerabilities in Cisco appliances (Reference: 20260127001). Organisations should verify their patch status for edge devices.

Recommendations

  1. Block Unsanctioned AI Repositories: Review network egress and ingress policies for AI model hosting sites (e.g., Hugging Face) if they are not required for business operations, or inspect traffic for executable anomalies.
  2. Hardening SSO: Move beyond SMS/Voice MFA. Implement FIDO2/WebAuthn hardware keys where possible to mitigate the risk of real-time phishing and vishing attacks targeting Okta users.
  3. Audit Automation Tools: specifically scan for exposed n8n instances and ensure they are behind a VPN or strictly authenticated.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Australia Cyber Threat Briefing: Network Assaults Outpace Malware & AI Privacy Shifts

The Australian cyber threat landscape has undergone a distinct shift in the last 24 hours. New intelligence released yesterday indicates that threat actors are moving away from traditional malware infections, favouring direct network-based attacks to exploit exposed edge infrastructure. As Australian organisations race to integrate AI, privacy governance is struggling to keep pace, creating new blind spots in real-time data protection.

Executive Summary The Australian cyber threat landscape has undergone a distinct shift in the last 24 hours. New intelligence released yesterday indicates that threat actors are moving away from traditional malware infections, favouring direct network-based attacks to exploit exposed edge infrastructure. As Australian organisations race to integrate AI, privacy governance is struggling to keep pace, creating new blind spots in real-time data protection.

This briefing covers the critical developments from 29–30 January 2026, focusing on a critical RCE vulnerability in automation tools, the evolving tactics targeting our Education and Healthcare sectors, and the rise of "living off the land" network assaults.


Sector-Specific Threat Intelligence

1. SaaS & Cloud Providers: The Automation Risk

  • Critical Vulnerability (Active Exploitation): A critical Remote Code Execution (RCE) vulnerability has been identified in the n8n workflow automation platform (tracked as CVE-2026-21858).
    • The Threat: With a CVSS score of 10.0, this flaw allows unauthenticated attackers to execute arbitrary code on the server.
    • Relevance: Many Australian FinTechs and SaaS startups utilise n8n for backend automation. Threat actors are actively scanning for exposed instances to gain initial access and pivot into cloud environments.
    • Action: Patch immediately to the latest version. If patching is not possible, isolate the instance behind a VPN or WAF immediately.

2. General Enterprise & Government: Network Attacks Surge

  • Breaking News: A report released yesterday highlights a significant divergence in Australia’s threat profile compared to the APAC region. While Asia continues to battle malware, Australia has seen network-based attacks outpace malware incidents by over 11 to 1 in the last quarter.
  • Analysis: Attackers are no longer relying on users clicking phishing links. Instead, they are aggressively scanning for misconfigured firewalls, exposed RDP ports, and unpatched edge devices (like the recent WatchGuard Firebox flaws).
  • Impact: Government agencies and enterprises with large, legacy footprints are prime targets for these "smash-and-grab" entry attempts.

3. Education & EdTech: The Third-Party Trap

  • Current Trend: While ransomware attacks on the Education sector have plateaued moving into 2026 (rising only 2% year-on-year), the vector has changed.
  • The Shift: Attackers are bypassing university firewalls by targeting third-party vendors—such as timetable scheduling software, HVAC management, and library systems.
  • Warning: EdTech providers must rigorously audit their API security, as they are now the preferred backdoor into major university networks.

4. Healthcare: Persistent Data Extortion

  • Ongoing Threat: Following the major breaches of 2025 (including the O&G Adelaide incident), the healthcare sector remains the primary target for double-extortion ransomware.
  • Tactic: Threat actors are increasingly using "fileless" attacks to exfiltrate patient data without triggering antivirus alarms, leveraging legitimate administrative tools (PowerShell, WMI).
  • Defence: Behavioural monitoring is critical. Static antivirus is no longer sufficient to stop these intrusions.

5. AI Systems: The "Real-Time" Governance Gap

  • Emerging Risk: With the rapid adoption of AI agents in customer service and internal data retrieval, a new vulnerability class has emerged: Contextual Data Leakage.
  • Insight: Security leaders warned yesterday that traditional "point-in-time" privacy checks are failing. AI agents often retain access to sensitive data (PII) longer than necessary or retrieve it for unauthorised users due to vague prompt permissions.
  • Recommendation: Implement "Real-time Access Control" for AI models to ensure they verify user permissions before retrieving data, not just at the login stage.

Technical Focus: Exploited Vulnerabilities

  • n8n Workflow Automation (CVE-2026-21858): [CRITICAL] Unauthenticated RCE.
  • WatchGuard Firebox (CVE-2025-14733): Continued exploitation of unpatched firewalls in the SMB sector.
  • MongoDB (CVE-2025-14847): Attackers are still hunting for unpatched MongoDB servers exposed to the internet to scrape data for extortion.

Conclusion

The events of the last 24 hours serve as a stark reminder: perimeter defence is not enough. With network scanning reaching unprecedented levels and automation tools becoming liabilities, Australian organisations must adopt a "assume breach" mentality. Ensure your edge devices are patched, your third-party vendors are vetted, and your AI systems are governed by strict real-time access controls.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: NSW Gov Strategy Launch, Vic Schools Breached & Critical AI Flawsc

Welcome to today's threat briefing. As we approach the end of January, the Australian cyber landscape is seeing significant shifts in government policy and active exploitation of education and financial sectors. Below is a deep dive into the critical threats, incidents, and vulnerabilities observed over the last 24 hours.

Welcome to today's threat briefing. As we approach the end of January, the Australian cyber landscape is seeing significant shifts in government policy and active exploitation of education and financial sectors. Below is a deep dive into the critical threats, incidents, and vulnerabilities observed over the last 24 hours.

Top Story: NSW Government Launches 2026–2028 Cyber Strategy

Just announced today, the New South Wales Government has officially launched its Cyber Security Strategy 2026–2028. This new framework marks a pivotal shift in how the state manages digital risks, introducing a mandatory 24-hour reporting window for cyber incidents—a significantly tighter timeframe designed to improve visibility and rapid response.

Key Takeaways for Gov & Enterprise:

  • Supply Chain Focus: The strategy explicitly targets third-party supply chain risks, a vector that has plagued Australian organisations over the last year.
  • Critical Infrastructure (CI): Enhanced obligations for CI operators to ensure resilience against nation-state actors.
  • Strategic Shift: Moving from a compliance-heavy model to a "resilience-first" approach, integrating identity support and faster intelligence sharing.

Sector Intelligence

1. Education & EdTech: Victorian Department of Education Breach

The Victorian Department of Education has confirmed a major data breach impacting over 1,700 government schools.

  • The Incident: An unauthorised third party accessed a database containing student names, school details, and email addresses with encrypted passwords.
  • Impact: While the department states no "sensitive" family details were accessed, the exposure of student identities creates a long-term risk of targeted phishing and identity fraud.
  • SaaS Risk: This incident highlights the fragility of centralised databases in the EdTech sector. Administrators should enforce immediate password rotations and review third-party access logs.

2. FinTech & Insurance: Prosura Data Leak

In a severe blow to the financial services sector, Australian car rental insurer Prosura has suffered a breach exposing approximately 300,000 customers.

  • Status: Threat actors have released 98 million lines of data on dark web forums.
  • Data Exposed: Customer names, policy details, and travel destinations.
  • Advisory: Financial institutions should be on high alert for social engineering attacks leveraging this fresh dataset to bypass identity verification checks.

3. Healthcare: Ransomware Success Rate at 95%

Recent reports from the Australian Signals Directorate (ASD) indicate a worrying trend for 2026: ransomware attacks on healthcare providers have doubled, with a 95% success rate for attackers once they gain initial access.

  • Threat Actor: The BianLian group remains highly active, targeting Australian critical infrastructure and healthcare with exfiltration-based extortion (threatening data release rather than just encryption).

Vulnerability Watch: Web, Cloud & AI

The last 24 hours have highlighted critical vulnerabilities that penetration testers and SysAdmins must address immediately.

Web Application & APIs

  • React Server Components (CVE-2026-23864): A High-Severity Denial of Service (DoS) vulnerability was disclosed on 26 January. This follows the critical RCE (CVE-2025-55182) from late last year.

    • Risk: Attackers can crash server-side rendering processes, taking down high-traffic React applications.
    • Action: Upgrade react-server-dom-webpack and related packages immediately.
  • n8n Workflow Automation (CVE-2026-21858): A Critical Unauthenticated RCE exists in the popular workflow automation tool n8n.

    • Risk: This is a "game over" bug for SaaS providers using n8n for backend orchestration. It allows full server takeover without credentials.
    • Action: Patch or isolate instances behind a VPN immediately.

Cloud & AI Systems

  • AI Cloud Misconfigurations: New research released yesterday details how "Agentic AI" deployments are introducing massive cloud risks. Specific incidents involving VyroAI and Chattee showed that misconfigured Cloud (Elasticsearch/Kafka) instances linked to AI models exposed millions of chat logs.
    • Attack Vector: Attackers are not attacking the AI model itself, but the infrastructure (Vector DBs, RAG pipelines) surrounding it.
    • Advisory: Ensure all AI-related data stores are not public-facing and enforce strict IAM roles.

Threat Actor Profile: The Rise of "Agentic AI" Attacks

We are observing a shift in 2026 where threat actors are utilising AI Agents to automate the exploitation of APIs. These autonomous agents can chain vulnerabilities (e.g., finding an exposed API endpoint, testing for BOLA/IDOR, and exfiltrating data) at a speed human teams cannot match.

Defensive Strategy: Traditional rate limiting is no longer sufficient. Organisations must implement behavioural analysis on API gateways to detect non-human traffic patterns that mimic legitimate user flows.


Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: Australia – 28 January 2026

The Australian cyber threat landscape over the last 24 hours has been dominated by a significant data breach within the Victorian education sector and the emergency disclosure of critical vulnerabilities affecting widespread enterprise tools. Threat actors are actively exploiting zero-day vulnerabilities in Microsoft Office and Zoom, while a new supply chain attack targeting developers using AI tools has been uncovered. Australian organisations, particularly in Government, Education, and FinTech, must prioritise patching and threat hunting immediately.

Executive Summary

The Australian cyber threat landscape over the last 24 hours has been dominated by a significant data breach within the Victorian education sector and the emergency disclosure of critical vulnerabilities affecting widespread enterprise tools. Threat actors are actively exploiting zero-day vulnerabilities in Microsoft Office and Zoom, while a new supply chain attack targeting developers using AI tools has been uncovered. Australian organisations, particularly in Government, Education, and FinTech, must prioritise patching and threat hunting immediately.

Local Impact: Victorian Education Sector Breach

Victorian Department of Education Hit by Major Data Breach A significant incident has been confirmed involving the Victorian Department of Education, impacting approximately 1,700 government schools. Unauthorised third-party access has compromised the personal information of current and former students.

  • Impact: Loss of PII (Personally Identifiable Information) creating heightened risk of identity theft and targeted phishing scams against students and families.
  • Action: Educational institutions should be on high alert for follow-on social engineering attacks. Parents and staff should be warned to scrutinise unsolicited communications purportedly from the Department or schools.

Critical Vulnerabilities & Global Threats

1. Microsoft Office Zero-Day (CVE-2026-21509)

  • Severity: Critical
  • Status: Active Exploitation / Emergency Patch Issued (27 Jan 2026)
  • Details: A remote code execution (RCE) vulnerability in Microsoft Office is being actively exploited in the wild. The flaw allows attackers to execute arbitrary code via specially crafted documents, often delivered via phishing emails.
  • Recommendation: Apply the emergency patch immediately. Ensure EDR solutions are tuned to detect abnormal Office process behaviour.

2. Zoom Node Multimedia Routers RCE (CVE-2026-22844)

  • Severity: Critical
  • Details: A command injection flaw in Zoom Node Multimedia Routers (used in Meeting Connector and Hybrid deployments) allows for remote code execution.
  • Relevance: High for organisations hosting on-premise or hybrid Zoom infrastructure.
  • Recommendation: Update to version 5.2.1716.0 or later immediately.

3. Fortinet SSO Authentication Bypass (CVE-2025-59718/59719 Variant)

  • Status: Active Exploitation of Patched Devices
  • Details: Threat intelligence indicates active exploitation of a FortiCloud SSO authentication bypass, even on devices believed to be fully patched. Attackers are using crafted SAML messages to create persistent accounts and enable VPN access.
  • Recommendation: Review audit logs for suspicious SAML assertions and anomalous VPN logins. Consider temporarily disabling SSO if suspicious activity is detected until further vendor guidance is clarified.

Emerging Trends: AI & Supply Chain Attacks

Malicious VS Code AI Extensions Cybersecurity researchers have identified two malicious Visual Studio Code extensions masquerading as AI coding assistants: "ChatGPT - 中文版" and "ChatGPT - ChatMoss".

  • Threat: These extensions, with over 1.5 million combined installs, contain backdoor functionality that siphons source code and developer environment data to servers located in China.
  • Sector Risk: High for SaaS Providers, FinTech, and DevOps teams where proprietary code is the crown jewel.
  • Action: Audit developer environments for these extensions immediately and block their IDs (whensunset.chatgpt-china, zhukunpeng.chat-moss).

Sector-Specific Intelligence

  • Healthcare: The Australian Signals Directorate (ASD) continues to report a surge in ransomware targeting healthcare providers, with incidents doubling compared to the previous period. Threat actors are leveraging the chaos of recent breaches to launch extortion campaigns.
  • Government: The NSW Government is rolling out a new framework to make AI risk assessments less subjective. Agencies deploying AI tools must now undergo rigorous testing for bias and security vulnerabilities before deployment.
  • IoT: With the exploitation of edge devices like Fortigate and Zoom routers, organisations must treat IoT and edge appliances as high-risk entry points. Ensure strict network segmentation is in place to prevent lateral movement.

Analyst’s Take

The breach in Victoria serves as a stark reminder that the education sector remains a soft target with high-value data. However, the technical sophistication seen in the Fortinet bypass and the malicious VS Code extensions indicates that threat actors are moving deeper into the supply chain and infrastructure layer. Defensive teams must look beyond the perimeter and scrutinise the tools their developers and remote workforce rely on daily.

Contact us for a quote for penetration testing service or adversary simulation.

Read More