Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: AI Agents Exposed, NSW's New Cyber Mandate, and Real Estate Risks

Good morning. Here is your daily deep dive into the Australian cyber threat landscape for the last 24 hours. Today’s briefing highlights a critical security failure in the emerging "AI Agent" economy, a major shift in NSW government compliance, and new vulnerabilities targeting widely used developer tools.

Good morning. Here is your daily deep dive into the Australian cyber threat landscape for the last 24 hours. Today’s briefing highlights a critical security failure in the emerging "AI Agent" economy, a major shift in NSW government compliance, and new vulnerabilities targeting widely used developer tools.

Top Story: The "Moltbook" Breach & The Risks of 'Vibe Coding'

In a significant wake-up call for the AI and SaaS sectors, Moltbook—a social network designed exclusively for AI agents to interact—has suffered a major security breach. Security researchers at Wiz revealed that the platform inadvertently exposed the private messages, email addresses, and credentials of over 6,000 human owners.

  • The Root Cause: The breach has been attributed to "vibe coding"—the practice of rapidly assembling software using AI coding assistants without rigorous security auditing. The platform lacked basic database protections, allowing unrestricted access to sensitive agent-to-agent communications.
  • Impact: This incident underscores a critical new attack surface: Non-Human Identities (NHIs). As organisations deploy autonomous AI agents to handle tasks, these agents become prime targets for credential theft and data exfiltration.

Government & Compliance: NSW Unveils New Cyber Strategy

The New South Wales Government has released its updated Cyber Security Strategy, introducing stricter obligations for managed service providers (MSPs) and partners.

  • Key Change: Partners providing services to NSW government entities must now align with state emergency plans and adhere to a 24-hour mandatory reporting window for cyber incidents.
  • Strategic Shift: The policy moves away from "tick-box compliance" towards continuous, evidence-based risk management. For SaaS and IT providers serving the public sector, immediate visibility and incident response integration are no longer optional—they are contractual necessities.

Sector Watch

Real Estate & Property A new investigation has flagged major data leak risks across Australian real estate leasing platforms. With the rental market under pressure, these platforms hold vast amounts of PII (passports, financial statements). Vulnerabilities in their APIs and improper access controls are leaving applicants' data exposed to scraping and identity theft.

FinTech & Business Services Nikkei, the parent company of the Financial Times, confirmed a breach exposing over 17,000 employees and partners. The attack vector? Compromised internal Slack workspaces. This serves as a stark reminder for FinTech firms: collaboration tools are a critical entry point. If your Slack or Teams environment is not monitored for anomalous behaviour, you are flying blind.

Healthcare The healthcare sector remains the most aggressively targeted industry in Australia. Recent reports from the Office of the Australian Information Commissioner (OAIC) indicate a continued surge in data breach notifications. The primary vector remains credential compromise and phishing, targeting overworked staff to gain entry into patient record systems.

Vulnerability Watch

  • Notepad++ Malware Injection: The popular text editor Notepad++ has been compromised. Hackers have injected malware into the software distribution, targeting developers and IT administrators. Action: Verify checksums immediately and block unverified downloads.
  • Fortinet (CVE-2026-24858): A critical Authentication Bypass vulnerability in FortiOS, FortiManager, and FortiAnalyzer is being actively exploited. If you utilise Fortinet infrastructure, ensure you have patched to the latest January 2026 release immediately.
  • n8n Workflow Automation (CVE-2026-21858): A critical Remote Code Execution (RCE) flaw in this workflow automation tool remains a high-priority fix, especially for organisations automating backend API tasks.

Emerging Threat: DeepSeek V4 & AI Sovereignty

While the Australian government banned the DeepSeek app from official devices last year, the release of DeepSeek V4 is reigniting the debate around AI sovereignty. The low-power, high-efficiency model is gaining traction in the private sector. Security leaders must evaluate the data privacy implications of integrating non-Western AI models into their corporate stacks, particularly regarding data residency and censorship risks.


Contact us for a quote for penetration testing service or adversary simulation.

Read More
Weekly Threat Briefing Lean Security Expert Weekly Threat Briefing Lean Security Expert

Weekly Threat Briefing: Critical Zero-Days and Nation-State Shifts Targeting Australia

The last seven days (26 January – 02 February 2026) have been defined by a resurgence in high-criticality infrastructure vulnerabilities and evolving nation-state tradecraft. For Australian organisations, the immediate priority is addressing active exploitation of Ivanti Endpoint Manager Mobile (EPMM) zero-days and critical patches for Cisco network infrastructure. Simultaneously, the threat landscape is shifting with reports of North Korean APT groups restructuring their operations, while the healthcare sector faces renewed warnings regarding IT/OT convergence risks.

Executive Summary

The last seven days (26 January – 02 February 2026) have been defined by a resurgence in high-criticality infrastructure vulnerabilities and evolving nation-state tradecraft. For Australian organisations, the immediate priority is addressing active exploitation of Ivanti Endpoint Manager Mobile (EPMM) zero-days and critical patches for Cisco network infrastructure. Simultaneously, the threat landscape is shifting with reports of North Korean APT groups restructuring their operations, while the healthcare sector faces renewed warnings regarding IT/OT convergence risks.


Top Priority: Exploited Vulnerabilities

1. Ivanti Endpoint Manager Mobile (EPMM) Zero-Days

Date Detected: 30 January 2026 Sector Impact: Government, SaaS, Enterprise Late last week, Ivanti issued an urgent warning regarding the active exploitation of zero-day vulnerabilities in its Endpoint Manager Mobile (EPMM). Threat actors are leveraging these flaws to bypass authentication and execute arbitrary code on mobile management gateways. Given the widespread use of Ivanti in Australian government and enterprise environments, this represents a critical risk.

  • Action: Immediate patching is required. Security teams should hunt for indicators of compromise (IoCs) in gateway logs dating back to mid-January.

2. Cisco Network Infrastructure Vulnerabilities

Date Released: 27 January 2026 Sector Impact: All Sectors (Critical Infrastructure focus) Cisco released a major security advisory on Tuesday addressing multiple critical vulnerabilities in its IOS XE software. Exploitation allows unauthenticated remote attackers to gain administrative control over network devices. With Australian critical infrastructure heavily reliant on Cisco backbones, these vulnerabilities are a prime target for initial access brokers.


Sector-Specific Threat Intelligence

Healthcare: The IT/OT "Cascade" Effect

A new report released on 27 January 2026 by Trellix highlights a dangerous trend affecting the healthcare sector: the "cascading" effect of cyber attacks moving from administrative IT systems into Operational Technology (OT) and patient care workflows.

  • Analysis: Australian healthcare providers are increasingly digitising patient systems. The report indicates that 75% of recent threats originated in non-clinical environments (e.g., email phishing) before laterally moving to impact medical devices.
  • Recommendation: Network segmentation between clinical OT and administrative IT is no longer optional—it is a patient safety imperative.

Government: BEC and Social Engineering

A significant incident surfaced this week involving a $3.5 million loss from a government agency due to a sophisticated Business Email Compromise (BEC) attack. The perpetrators impersonated a construction contractor, leveraging deepfake-enhanced social engineering to authorise fraudulent payments.

  • Takeaway: Technical controls (like MFA) must be supplemented with strict procedural verification for high-value transactions.

SaaS & Cloud: Salesforce Ecosystem Risks

Reports have emerged regarding a targeted campaign against Salesforce environments. While not a direct breach of Salesforce's core infrastructure, attackers are successfully harvesting high-privilege credentials via sophisticated phishing campaigns targeting Australian SaaS administrators.

  • Risk: Once inside, attackers are exfiltrating customer databases and manipulating API integrations to maintain persistence.

FinTech & AI: The Implementation Trap

As Australian FinTechs rush to integrate AI-driven customer service agents, new research from Cyber Daily (30 January) warns of "AI implementation risks." Early audits suggest that many of these AI systems suffer from prompt injection vulnerabilities, allowing attackers to manipulate banking chatbots into disclosing sensitive user data or bypassing fraud checks.


Threat Actor Focus: North Korean APT Evolution

Intelligence surfacing on 30 January indicates a strategic shift within the infamous North Korean hacking ecosystem (often linked to the Lazarus Group). The group appears to be "dividing to conquer," splitting into smaller, specialised cells.

  • New Tactics: One cell is focusing exclusively on cryptocurrency theft to fund state activities, while another is dedicated to supply chain espionage against the defence and education sectors.
  • Relevance: Australian universities and defence contractors should anticipate highly targeted spear-phishing campaigns tailored to their specific research and development projects.

Recommendations for the Week Ahead

  1. Patch Immediately: Prioritise Ivanti EPMM and Cisco IOS XE updates.
  2. Review BEC Procedures: Verify payment details offline for all transactions over $10,000.
  3. Segregate OT Networks: Ensure clinical devices in healthcare settings are isolated from email and internet-facing segments.
  4. Audit AI Models: If you are deploying LLMs in customer-facing roles, conduct adversarial testing for prompt injection flaws.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: AI Model Hosting Abuse & New SSO Phishing Campaigns

In the last 24 hours, the Australian cyber threat landscape has been dominated by sophisticated abuse of AI infrastructure and targeted identity attacks. A new report released today highlights how threat actors are weaponising legitimate AI hosting platforms to distribute malware, bypassing traditional perimeter defences. Simultaneously, the FinTech and SaaS sectors are facing a resurgence of human-led phishing campaigns targeting Single Sign-On (SSO) credentials.

Executive Summary

In the last 24 hours, the Australian cyber threat landscape has been dominated by sophisticated abuse of AI infrastructure and targeted identity attacks. A new report released today highlights how threat actors are weaponising legitimate AI hosting platforms to distribute malware, bypassing traditional perimeter defences. Simultaneously, the FinTech and SaaS sectors are facing a resurgence of human-led phishing campaigns targeting Single Sign-On (SSO) credentials.

This briefing covers critical developments impacting Healthcare, Education, Government, and the SaaS supply chain.


Emerging Threats & Attack Vectors

1. AI Systems: Hugging Face Weaponised for Malware Distribution

Sectors: eCommerce, Technology, General Threat Actor: Unknown / Cybercrime Groups

A significant development reported today involves the abuse of Hugging Face, a popular platform for hosting machine learning models. Researchers at Bitdefender have identified a campaign where attackers are using the platform to host and distribute a malicious Android Remote Access Trojan (RAT) disguised as a security app called "TrustBastion".

  • The Attack: Users are lured via deceptive advertisements warning of device infection. The malicious app, once installed, fetches its payload directly from a Hugging Face repository.
  • Why it Matters: By hosting malware on a trusted domain like Hugging Face, attackers can evade standard network filtering and reputation-based blocking used by many Australian enterprises. This represents a dangerous evolution in "Living off the Land" tactics, now extending to AI infrastructure.

2. SaaS & FinTech: ShinyHunters Targeting Okta SSO

Sectors: FinTech, SaaS Providers Threat Actor: ShinyHunters / SLSH Alliance

New intelligence from Silent Push indicates a large-scale, human-led phishing campaign targeting Okta Single Sign-On (SSO) accounts. Unlike automated credential stuffing, this campaign employs "vishing" (voice phishing) and real-time social engineering to bypass Multi-Factor Authentication (MFA).

  • Targets: High-value targets in FinTech (payment processors) and SaaS platforms.
  • Impact: Successful compromise allows threat actors to pivot into corporate dashboards, accessing sensitive customer data and financial systems. This is a critical alert for any organisation relying on federated identity providers.

Sector-Specific Updates

Education: Victorian Schools Targeted

Reports have surfaced regarding a cyber incident affecting Victorian schools, disrupting IT networks and raising concerns over student data privacy. This follows a trend of increasing ransomware pressure on the Australian education sector, where legacy systems often struggle to repel modern "big game hunting" tactics.

Government: NSW Overhauls Cyber Emergency Plan

In response to the escalating threat environment, the NSW Government has announced a major overhaul of its state cyber emergency plan. The new framework mandates that government agencies report incidents to Cyber Security NSW within 24 hours and introduces stricter "Crown Jewel" asset management plans. This regulatory shift underscores the need for public sector agencies to move from compliance-based security to active resilience.

Healthcare: Persistent Data Risks

The healthcare sector remains a primary target. Following a series of breaches affecting providers like Diabetes WA and DBG Health over the past year, the Australian healthcare industry is being urged to adopt "secure by design" principles. The monetisation of medical records on the dark web continues to drive ransomware activity against clinics and support organisations.


Critical Vulnerabilities (CVEs)

Penetration testers and sysadmins should prioritise the following vulnerabilities which are relevant to Australian infrastructure:

  • n8n Workflow Automation (CVE-2026-21858): A Critical unauthenticated Remote Code Execution (RCE) vulnerability in the n8n platform. As this tool is widely used by SaaS providers and internal dev teams for automation, it represents a high-risk entry point. Patch immediately.
  • Cisco Network Infrastructure: The Australian Cyber Security Centre (ACSC) and WA Cyber Security Unit have issued alerts regarding critical vulnerabilities in Cisco appliances (Reference: 20260127001). Organisations should verify their patch status for edge devices.

Recommendations

  1. Block Unsanctioned AI Repositories: Review network egress and ingress policies for AI model hosting sites (e.g., Hugging Face) if they are not required for business operations, or inspect traffic for executable anomalies.
  2. Hardening SSO: Move beyond SMS/Voice MFA. Implement FIDO2/WebAuthn hardware keys where possible to mitigate the risk of real-time phishing and vishing attacks targeting Okta users.
  3. Audit Automation Tools: specifically scan for exposed n8n instances and ensure they are behind a VPN or strictly authenticated.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Australia Cyber Threat Briefing: Network Assaults Outpace Malware & AI Privacy Shifts

The Australian cyber threat landscape has undergone a distinct shift in the last 24 hours. New intelligence released yesterday indicates that threat actors are moving away from traditional malware infections, favouring direct network-based attacks to exploit exposed edge infrastructure. As Australian organisations race to integrate AI, privacy governance is struggling to keep pace, creating new blind spots in real-time data protection.

Executive Summary The Australian cyber threat landscape has undergone a distinct shift in the last 24 hours. New intelligence released yesterday indicates that threat actors are moving away from traditional malware infections, favouring direct network-based attacks to exploit exposed edge infrastructure. As Australian organisations race to integrate AI, privacy governance is struggling to keep pace, creating new blind spots in real-time data protection.

This briefing covers the critical developments from 29–30 January 2026, focusing on a critical RCE vulnerability in automation tools, the evolving tactics targeting our Education and Healthcare sectors, and the rise of "living off the land" network assaults.


Sector-Specific Threat Intelligence

1. SaaS & Cloud Providers: The Automation Risk

  • Critical Vulnerability (Active Exploitation): A critical Remote Code Execution (RCE) vulnerability has been identified in the n8n workflow automation platform (tracked as CVE-2026-21858).
    • The Threat: With a CVSS score of 10.0, this flaw allows unauthenticated attackers to execute arbitrary code on the server.
    • Relevance: Many Australian FinTechs and SaaS startups utilise n8n for backend automation. Threat actors are actively scanning for exposed instances to gain initial access and pivot into cloud environments.
    • Action: Patch immediately to the latest version. If patching is not possible, isolate the instance behind a VPN or WAF immediately.

2. General Enterprise & Government: Network Attacks Surge

  • Breaking News: A report released yesterday highlights a significant divergence in Australia’s threat profile compared to the APAC region. While Asia continues to battle malware, Australia has seen network-based attacks outpace malware incidents by over 11 to 1 in the last quarter.
  • Analysis: Attackers are no longer relying on users clicking phishing links. Instead, they are aggressively scanning for misconfigured firewalls, exposed RDP ports, and unpatched edge devices (like the recent WatchGuard Firebox flaws).
  • Impact: Government agencies and enterprises with large, legacy footprints are prime targets for these "smash-and-grab" entry attempts.

3. Education & EdTech: The Third-Party Trap

  • Current Trend: While ransomware attacks on the Education sector have plateaued moving into 2026 (rising only 2% year-on-year), the vector has changed.
  • The Shift: Attackers are bypassing university firewalls by targeting third-party vendors—such as timetable scheduling software, HVAC management, and library systems.
  • Warning: EdTech providers must rigorously audit their API security, as they are now the preferred backdoor into major university networks.

4. Healthcare: Persistent Data Extortion

  • Ongoing Threat: Following the major breaches of 2025 (including the O&G Adelaide incident), the healthcare sector remains the primary target for double-extortion ransomware.
  • Tactic: Threat actors are increasingly using "fileless" attacks to exfiltrate patient data without triggering antivirus alarms, leveraging legitimate administrative tools (PowerShell, WMI).
  • Defence: Behavioural monitoring is critical. Static antivirus is no longer sufficient to stop these intrusions.

5. AI Systems: The "Real-Time" Governance Gap

  • Emerging Risk: With the rapid adoption of AI agents in customer service and internal data retrieval, a new vulnerability class has emerged: Contextual Data Leakage.
  • Insight: Security leaders warned yesterday that traditional "point-in-time" privacy checks are failing. AI agents often retain access to sensitive data (PII) longer than necessary or retrieve it for unauthorised users due to vague prompt permissions.
  • Recommendation: Implement "Real-time Access Control" for AI models to ensure they verify user permissions before retrieving data, not just at the login stage.

Technical Focus: Exploited Vulnerabilities

  • n8n Workflow Automation (CVE-2026-21858): [CRITICAL] Unauthenticated RCE.
  • WatchGuard Firebox (CVE-2025-14733): Continued exploitation of unpatched firewalls in the SMB sector.
  • MongoDB (CVE-2025-14847): Attackers are still hunting for unpatched MongoDB servers exposed to the internet to scrape data for extortion.

Conclusion

The events of the last 24 hours serve as a stark reminder: perimeter defence is not enough. With network scanning reaching unprecedented levels and automation tools becoming liabilities, Australian organisations must adopt a "assume breach" mentality. Ensure your edge devices are patched, your third-party vendors are vetted, and your AI systems are governed by strict real-time access controls.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: NSW Gov Strategy Launch, Vic Schools Breached & Critical AI Flawsc

Welcome to today's threat briefing. As we approach the end of January, the Australian cyber landscape is seeing significant shifts in government policy and active exploitation of education and financial sectors. Below is a deep dive into the critical threats, incidents, and vulnerabilities observed over the last 24 hours.

Welcome to today's threat briefing. As we approach the end of January, the Australian cyber landscape is seeing significant shifts in government policy and active exploitation of education and financial sectors. Below is a deep dive into the critical threats, incidents, and vulnerabilities observed over the last 24 hours.

Top Story: NSW Government Launches 2026–2028 Cyber Strategy

Just announced today, the New South Wales Government has officially launched its Cyber Security Strategy 2026–2028. This new framework marks a pivotal shift in how the state manages digital risks, introducing a mandatory 24-hour reporting window for cyber incidents—a significantly tighter timeframe designed to improve visibility and rapid response.

Key Takeaways for Gov & Enterprise:

  • Supply Chain Focus: The strategy explicitly targets third-party supply chain risks, a vector that has plagued Australian organisations over the last year.
  • Critical Infrastructure (CI): Enhanced obligations for CI operators to ensure resilience against nation-state actors.
  • Strategic Shift: Moving from a compliance-heavy model to a "resilience-first" approach, integrating identity support and faster intelligence sharing.

Sector Intelligence

1. Education & EdTech: Victorian Department of Education Breach

The Victorian Department of Education has confirmed a major data breach impacting over 1,700 government schools.

  • The Incident: An unauthorised third party accessed a database containing student names, school details, and email addresses with encrypted passwords.
  • Impact: While the department states no "sensitive" family details were accessed, the exposure of student identities creates a long-term risk of targeted phishing and identity fraud.
  • SaaS Risk: This incident highlights the fragility of centralised databases in the EdTech sector. Administrators should enforce immediate password rotations and review third-party access logs.

2. FinTech & Insurance: Prosura Data Leak

In a severe blow to the financial services sector, Australian car rental insurer Prosura has suffered a breach exposing approximately 300,000 customers.

  • Status: Threat actors have released 98 million lines of data on dark web forums.
  • Data Exposed: Customer names, policy details, and travel destinations.
  • Advisory: Financial institutions should be on high alert for social engineering attacks leveraging this fresh dataset to bypass identity verification checks.

3. Healthcare: Ransomware Success Rate at 95%

Recent reports from the Australian Signals Directorate (ASD) indicate a worrying trend for 2026: ransomware attacks on healthcare providers have doubled, with a 95% success rate for attackers once they gain initial access.

  • Threat Actor: The BianLian group remains highly active, targeting Australian critical infrastructure and healthcare with exfiltration-based extortion (threatening data release rather than just encryption).

Vulnerability Watch: Web, Cloud & AI

The last 24 hours have highlighted critical vulnerabilities that penetration testers and SysAdmins must address immediately.

Web Application & APIs

  • React Server Components (CVE-2026-23864): A High-Severity Denial of Service (DoS) vulnerability was disclosed on 26 January. This follows the critical RCE (CVE-2025-55182) from late last year.

    • Risk: Attackers can crash server-side rendering processes, taking down high-traffic React applications.
    • Action: Upgrade react-server-dom-webpack and related packages immediately.
  • n8n Workflow Automation (CVE-2026-21858): A Critical Unauthenticated RCE exists in the popular workflow automation tool n8n.

    • Risk: This is a "game over" bug for SaaS providers using n8n for backend orchestration. It allows full server takeover without credentials.
    • Action: Patch or isolate instances behind a VPN immediately.

Cloud & AI Systems

  • AI Cloud Misconfigurations: New research released yesterday details how "Agentic AI" deployments are introducing massive cloud risks. Specific incidents involving VyroAI and Chattee showed that misconfigured Cloud (Elasticsearch/Kafka) instances linked to AI models exposed millions of chat logs.
    • Attack Vector: Attackers are not attacking the AI model itself, but the infrastructure (Vector DBs, RAG pipelines) surrounding it.
    • Advisory: Ensure all AI-related data stores are not public-facing and enforce strict IAM roles.

Threat Actor Profile: The Rise of "Agentic AI" Attacks

We are observing a shift in 2026 where threat actors are utilising AI Agents to automate the exploitation of APIs. These autonomous agents can chain vulnerabilities (e.g., finding an exposed API endpoint, testing for BOLA/IDOR, and exfiltrating data) at a speed human teams cannot match.

Defensive Strategy: Traditional rate limiting is no longer sufficient. Organisations must implement behavioural analysis on API gateways to detect non-human traffic patterns that mimic legitimate user flows.


Contact us for a quote for penetration testing service or adversary simulation.

Read More