Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: DeepSeek Ban, Healthcare Ransomware, and Edge Exploits

The last 24 hours in the Australian cyber security landscape have been dominated by significant government action against AI platforms and a confusing ransomware situation in the healthcare sector. On 6 February 2026, the Australian Government officially banned DeepSeek from government devices, citing national security concerns and severe vulnerabilities in the model’s safety guardrails. Simultaneously, the healthcare sector is on high alert as conflicting reports emerge regarding a massive data theft at a major Victorian provider.

Executive Summary The last 24 hours in the Australian cyber security landscape have been dominated by significant government action against AI platforms and a confusing ransomware situation in the healthcare sector. On 6 February 2026, the Australian Government officially banned DeepSeek from government devices, citing national security concerns and severe vulnerabilities in the model’s safety guardrails. Simultaneously, the healthcare sector is on high alert as conflicting reports emerge regarding a massive data theft at a major Victorian provider.

Here is your daily deep dive into the threats impacting Australian organisations today.

Government & AI Systems: The DeepSeek Ban

Sectors: Government, EdTech, SaaS Threat Level: Critical

Following advice from intelligence agencies, the Australian Government has mandated the removal of DeepSeek products from all federal systems as of yesterday.

  • The Vulnerability: Security researchers have demonstrated that the DeepSeek-R1 model is highly susceptible to adversarial manipulation. Independent analysis revealed the model failed 58% of jailbreak attempts and 86% of prompt injection tests, allowing it to generate harmful content, including malware code and disinformation, despite built-in safety filters.
  • Impact: This ban highlights the growing risk of Shadow AI in government and enterprise environments. Agencies and SaaS providers integrating similar LLMs must immediately review their "guardrail" implementations.
  • Action: Organisations should audit their networks for unauthorised use of DeepSeek and other non-compliant AI tools.

Healthcare: The 0APT Ransomware Mystery

Sectors: Healthcare, Privacy Threat Level: High

A new threat group, 0APT, has claimed responsibility for stealing 920GB of sensitive data from Epworth HealthCare, one of Victoria’s largest private hospital groups.

  • The Incident: The threat actors allege they have exfiltrated patient databases, surgical records, and billing details (including USD and AUD transactions).
  • The Conflict: In a statement released yesterday, Epworth HealthCare denied any evidence of a direct breach, suggesting the claim may relate to a third-party vendor. This "supply chain uncertainty" is a classic tactic used by ransomware groups to induce panic and force negotiations.
  • Observation: This incident underscores the critical need for third-party risk management (TPRM). Even if your perimeter is secure, your data remains vulnerable in the hands of vendors.

Infrastructure & IoT: Browser and Edge Exploits

Sectors: All (Corporate IT), IoT Threat Level: High

Microsoft and Ivanti have both been in the spotlight over the last 48 hours with critical updates.

  • Microsoft Edge (Chromium): On 5 February 2026, Microsoft released an emergency update for Edge to address CVE-2025-13223 and CVE-2025-10585. Both vulnerabilities are confirmed to be exploited in the wild. These memory corruption flaws allow remote attackers to execute arbitrary code via a crafted HTML page.
  • Ivanti Connect Secure: Organisations are still struggling to patch CVE-2025-0282, a critical stack-based buffer overflow in Ivanti VPN appliances. Exploitation allows unauthenticated remote code execution (RCE). Australian organisations with edge devices must verify their integrity immediately using the external Integrity Checker Tool (ICT).

SaaS & Web Applications: n8n Workflow Automation

Sectors: SaaS, FinTech Threat Level: Critical

A critical vulnerability (CVE-2026-21858) in the popular workflow automation platform n8n is being actively targeted.

  • The Flaw: This is an unauthenticated RCE vulnerability. Attackers can execute arbitrary code on the underlying server by manipulating form-based workflows.
  • Relevance: As FinTech and SaaS providers increasingly rely on "no-code/low-code" automation tools like n8n to connect APIs, these platforms become high-value targets for initial access.

Technical Takeaway

The common thread in the last 24 hours is input validation failure—whether it is the prompt injection attacks bypassing AI guardrails in DeepSeek, or the buffer overflows in Edge and Ivanti. Traditional WAFs are struggling to catch semantic attacks against LLMs.

Recommendation: Move beyond signature-based detection. Implement rigorous behavioural analysis for your APIs and AI interfaces to detect anomalous inputs before they process.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: Australia - 06 February 2026

In the last 24 hours, the Australian cyber threat landscape has been dominated by significant escalations in the Education and Healthcare sectors, alongside critical supply chain compromises affecting widely used software. Of particular concern is the shift in threat actor tactics towards "disruption over data theft," as highlighted by intelligence warnings regarding state-sponsored "cyberthugs." Today’s briefing analyses these developments to help your organisation stay resilient.

Executive Summary

In the last 24 hours, the Australian cyber threat landscape has been dominated by significant escalations in the Education and Healthcare sectors, alongside critical supply chain compromises affecting widely used software. Of particular concern is the shift in threat actor tactics towards "disruption over data theft," as highlighted by intelligence warnings regarding state-sponsored "cyberthugs." Today’s briefing analyses these developments to help your organisation stay resilient.

Sector-Specific Updates

  • Education & EdTech The Victorian Department of Education has confirmed a major data breach impacting all 1,700 government schools. Unauthorised third-party access in January 2026 exposed the personal information of current and former students, marking one of the largest sector-specific breaches in recent history. Simultaneously, Loyola College is managing the fallout of a ransomware attack by the Interlock gang, who have leaked nearly 600GB of data, including passports and financial records, to the dark web.

  • Healthcare Epworth HealthCare is currently investigating claims by a ransomware group alleging the theft of 920GB of sensitive data. While Epworth has stated there is currently "no evidence" of the breach, this discrepancy often precedes the release of proof-of-concept data by extortionists. Across the Tasman, Manage My Health released a critical update today (06 Feb) regarding their recent breach; the platform’s compromised feature has been secured following unauthorised access, though investigations remain active.

  • SaaS & Software Supply Chain A sophisticated supply chain attack targeting Notepad++ has been uncovered. State-sponsored actors compromised the open-source editor's update infrastructure (specifically the WinGUp updater) between June and December 2025 to deliver malicious binaries. Organisations using unverified repositories or older versions are at high risk. Additionally, a critical vulnerability in the n8n workflow automation platform (CVE-2026-21858) is being actively exploited, allowing unauthenticated remote code execution (RCE).

  • eCommerce & Insurance Australian insurance provider Prosura has temporarily shut down key online services after detecting unauthorised internal access. Attackers used this access to send fraudulent emails to customers regarding policies, likely a precursor to a targeted phishing or invoice fraud campaign.

  • Government & Critical Infrastructure Intelligence warnings issued in the last 24 hours highlight a strategic pivot by state-sponsored actors (linked to groups like Vault Typhoon) from espionage to "cyberthuggery"—aiming for mass disruption of public services rather than just data exfiltration. This follows the Australian Government's decisive ban on the DeepSeek AI model from government devices due to data privacy concerns.

Technical Focus: Vulnerabilities in Web, Cloud, and AI

  • n8n Workflow Automation RCE (CVE-2026-21858):

    • Severity: Critical
    • Vector: Unauthenticated Remote Code Execution.
    • Impact: Attackers can execute arbitrary code on the host server without credentials. This is particularly dangerous for SaaS providers integrating n8n for backend automation.
    • Action: Patch immediately to the latest stable release and restrict public access to workflow endpoints.
  • AI Infrastructure Hijacking:

    • New reports indicate cybercriminals are increasingly hijacking legitimate AI hosting services to deploy malicious models or crack password hashes using rented GPU power. This "model poisoning" and resource theft represents a growing vector for AI-driven platforms.
  • WatchGuard Firebox (CVE-2025-14733):

    • Active exploitation continues against unpatched WatchGuard appliances. Ensure firmware is updated to prevent perimeter compromise.

Strategic Recommendations

  1. Verify Software Integrity: in light of the Notepad++ incident, enforce hash verification for all software updates and audit developer tools within your environment.
  2. Education Sector Alert: Schools and EdTech providers should immediately review third-party access logs and enforce MFA on all administrative accounts.
  3. Threat Hunting: Scan for indicators of compromise related to the n8n RCE if your organisation utilises workflow automation tools.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Cyber Threat Briefing: Australia’s Digital Landscape Under Siege

As we analyse the cyber threat landscape for the last 24 hours, Australian organisations are facing a convergence of sophisticated ransomware campaigns, rapid exploitation of AI vulnerabilities, and targeted scams against individuals. The Australian Signals Directorate (ASD) and industry leaders have flagged critical developments affecting the Healthcare, SaaS, and Government sectors.

As we analyse the cyber threat landscape for the last 24 hours, Australian organisations are facing a convergence of sophisticated ransomware campaigns, rapid exploitation of AI vulnerabilities, and targeted scams against individuals. The Australian Signals Directorate (ASD) and industry leaders have flagged critical developments affecting the Healthcare, SaaS, and Government sectors.

Here is your daily deep dive into the threats shaping our digital environment.

Healthcare Sector: Ransomware Resurgence

The healthcare sector remains the prime target for financially motivated threat actors. In the last 24 hours, Epworth HealthCare has become the focus of a significant security incident. The newly emerged ransomware group, 0APT, has claimed responsibility for a breach, alleging the theft of 920GB of data, including sensitive patient databases.

While Epworth HealthCare has stated there is currently "no verified evidence" of the exfiltration, this incident highlights a disturbing trend. The ASD’s Annual Cyber Threat Report 2024-2025 revealed that ransomware incidents in healthcare have doubled year-on-year, with attackers achieving a 95% success rate in this sector—significantly higher than the national average.

Action Item: Healthcare providers must urgently review their data egress monitoring and validate backup immutability.

SaaS and Cloud: Critical Vulnerabilities Exploited

SaaS providers and organisations relying on workflow automation are under immediate threat from a critical Remote Code Execution (RCE) vulnerability.

  • n8n Workflow Automation (CVE-2026-21858): A critical vulnerability (CVSS 10.0) is being actively exploited, allowing unauthenticated attackers to execute arbitrary code and access sensitive files. Given the widespread use of n8n for integrating APIs and services, this poses a severe supply chain risk.
  • Fortinet Cloud SSO: Security teams should also be aware of active exploitation attempts targeting the FortiCloud Single Sign-On (SSO) mechanism (CVE-2025-59718). Attackers are bypassing authentication to access customer devices, emphasising the fragility of identity management systems in the cloud.

AI Systems: The 16-Minute Window

Artificial Intelligence is no longer just a tool for defenders; it is a vulnerable attack surface. A startling report released this week by Zscaler indicates that enterprise AI systems are being compromised at "machine speed."

Red team exercises revealed that 100% of tested enterprise AI systems contained critical flaws, with attackers able to compromise these systems in an average of just 16 minutes. The primary vectors include:

  • Exposed Model Endpoints: Lack of authentication allowing unauthorised queries.
  • Prompt Injection: Manipulating AI logic to bypass safety rails.
  • Insecure API Integrations: AI agents with excessive permissions writing to production systems.

FinTech & eCommerce: "Digital Arrest" Scams

The financial sector is seeing a rise in sophisticated social engineering attacks. A "Digital Arrest" scam has surfaced prominently in Sydney, where victims are coerced by fraudsters posing as officials from the Indian High Commission or federal police. These attackers use high-pressure tactics, claiming involvement in money laundering, to siphon funds via cryptocurrency and bank transfers.

For eCommerce and FinTech platforms, the risk lies in identity fraud and account takeovers (ATO), as criminals leverage stolen data from other breaches to bypass verification checks.

Government & IoT: Infrastructure Risks

The Australian Government and critical infrastructure operators continue to mitigate legacy risks that remain active. The ASD has reiterated warnings regarding WatchGuard Firebox devices (CVE-2025-14733), which are seeing continued exploitation attempts.

Furthermore, the rise of "Shadow API" vulnerabilities—unmanaged and invisible API endpoints—is creating blind spots for government agencies. These endpoints are frequently targeted to bypass access controls (IDOR vulnerabilities), leading to unauthorised data exposure.

Summary of Critical Vulnerabilities

CVE ID Severity Description Target
CVE-2026-21858 Critical (10.0) Unauthenticated RCE in n8n workflow automation. SaaS / Cloud
CVE-2025-59718 Critical Authentication Bypass in FortiCloud SSO. Cloud / NetSec
CVE-2025-14733 High Exploitation of WatchGuard Firebox devices. Network / IoT

Conclusion

The events of the last 24 hours demonstrate that speed is the adversary's greatest weapon. From the 16-minute compromise time of AI systems to the rapid weaponisation of the n8n vulnerability, Australian organisations must move from reactive patching to proactive continuous exposure management.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Australian Cyber Threat Briefing: AI Agents Hijacked and Critical RCEs Targeting Enterprise

Good morning, Australia. As we analyse the threat landscape for the last 24 hours, it is clear that 2026 is shaping up to be the year where "Agentic AI" risks move from theoretical to catastrophic. Today's briefing highlights a massive exposure in the AI ecosystem, critical zero-days continuously exploited by state-sponsored actors, and a glaring privacy failure in the Australian property sector.

Good morning, Australia. As we analyse the threat landscape for the last 24 hours, it is clear that 2026 is shaping up to be the year where "Agentic AI" risks move from theoretical to catastrophic. Today's briefing highlights a massive exposure in the AI ecosystem, critical zero-days continuously exploited by state-sponsored actors, and a glaring privacy failure in the Australian property sector.

Here is your daily deep dive into the threats mattering most to Australian organisations today.

🚨 Top Story: The "Moltbook" AI Agent Leak

Sectors Impacted: SaaS, AI, EdTech, FinTech

Over the last 24 hours, the cybersecurity community has been rocked by the exposure of Moltbook, a platform dubbed the "Reddit for AI Agents." A misconfigured database left 150,000 AI Agent API keys and login tokens publicly accessible.

  • The Threat: This is not just a data breach; it is an identity breach for autonomous systems. Attackers can use these stolen keys to hijack AI agents, forcing them to execute fraudulent transactions, exfiltrate sensitive corporate data, or launch phishing attacks from "trusted" AI accounts.
  • Why it Matters: If your organisation is integrating third-party AI agents or building "Vibe Coding" projects without rigorous security audits, you are likely exposed. This incident underscores the critical need for Non-Human Identity Management (NHIM).

🔍 Sector-Specific Threat Intelligence

Government & Critical Infrastructure

  • Operation Neusploit (APT28): Russian state-sponsored actors are actively exploiting a zero-day in Microsoft Office (CVE-2026-21509).
    • Attack Vector: Malicious RTF documents.
    • Impact: This vulnerability allows remote code execution (RCE) on unpatched systems. Despite Microsoft rushing a patch late last month, exploitation rates have surged in the last 48 hours targeting government entities and defence contractors.
    • NSW Strategy Update: On a positive note, the NSW Government has released a new cyber strategy mandating 24-hour incident reporting and a "secure-by-design" approach. We expect federal agencies to follow suit shortly.

SaaS & eCommerce (Mobile Focus)

  • React Native "Metro4Shell" (CVE-2025-11953): A critical RCE vulnerability (CVSS 9.8) in the React Native CLI is being exploited in the wild.
    • The Risk: Many Australian eCommerce and FinTech mobile apps rely on this framework. Threat actors are using this flaw to deliver base64-encoded PowerShell scripts, bypassing Defender to execute arbitrary commands.
    • Action: DevSecOps teams must verify their build pipelines and dependencies immediately.

Healthcare & Real Estate

  • Property Data Exposed: A new report from Guardian Australia has revealed that major Australian rental platforms are exposing millions of lease documents via predictable, non-authenticated URLs.
    • Relevance: While this hits Real Estate directly, the methodology (Insecure Direct Object Reference or IDOR) is rampant in Healthcare patient portals and EdTech platforms.
    • Check: Ensure your web applications enforce strict authorisation checks on every document access request. "Security through obscurity" (randomised URLs) is not security.

Enterprise & IoT

  • Ivanti EPMM Zero-Days (CVE-2026-1281 & CVE-2026-1340): CISA has set a deadline of this week for federal agencies to patch these critical code injection vulnerabilities.
    • Impact: Unauthenticated attackers can execute commands on Endpoint Manager Mobile gateways. This is a primary vector for lateral movement into IoT networks and corporate mobile fleets.

🛠 Technical Vulnerability Watchlist

CVE ID Severity Description Status
CVE-2026-21858 Critical n8n Workflow Automation RCE. Unauthenticated attackers can access sensitive files and execute code. Exploited in Wild
CVE-2026-21509 High Microsoft Office RCE. Exploited by APT28 via RTF files. Patch Immediately
CVE-2025-11953 Critical React Native CLI RCE. Impacting mobile app supply chains. Active Attacks

🛡️ Recommendations for CISOs & Security Teams

  1. Rotated AI Secrets: If your teams use Moltbook or similar "Agentic" platforms, rotate all associated API keys immediately.
  2. Hunt for RTF Files: Block .rtf attachments at the email gateway or enforce strict sandboxing until the Microsoft patch (CVE-2026-21509) is verified across your fleet.
  3. Audit Web Assets for IDOR: The rental platform leak is a wake-up call. Test your APIs to ensure that changing a document ID in the URL does not grant access to another user's data.

The speed at which AI agents are being compromised and weaponised is the defining challenge of 2026. Do not let your automated workforce become an adversary's entry point.

Contact us for a quote for penetration testing service or adversary simulation.

Read More
Daily Threat Briefing Lean Security Expert Daily Threat Briefing Lean Security Expert

Daily Threat Briefing: AI Agents Exposed, NSW's New Cyber Mandate, and Real Estate Risks

Good morning. Here is your daily deep dive into the Australian cyber threat landscape for the last 24 hours. Today’s briefing highlights a critical security failure in the emerging "AI Agent" economy, a major shift in NSW government compliance, and new vulnerabilities targeting widely used developer tools.

Good morning. Here is your daily deep dive into the Australian cyber threat landscape for the last 24 hours. Today’s briefing highlights a critical security failure in the emerging "AI Agent" economy, a major shift in NSW government compliance, and new vulnerabilities targeting widely used developer tools.

Top Story: The "Moltbook" Breach & The Risks of 'Vibe Coding'

In a significant wake-up call for the AI and SaaS sectors, Moltbook—a social network designed exclusively for AI agents to interact—has suffered a major security breach. Security researchers at Wiz revealed that the platform inadvertently exposed the private messages, email addresses, and credentials of over 6,000 human owners.

  • The Root Cause: The breach has been attributed to "vibe coding"—the practice of rapidly assembling software using AI coding assistants without rigorous security auditing. The platform lacked basic database protections, allowing unrestricted access to sensitive agent-to-agent communications.
  • Impact: This incident underscores a critical new attack surface: Non-Human Identities (NHIs). As organisations deploy autonomous AI agents to handle tasks, these agents become prime targets for credential theft and data exfiltration.

Government & Compliance: NSW Unveils New Cyber Strategy

The New South Wales Government has released its updated Cyber Security Strategy, introducing stricter obligations for managed service providers (MSPs) and partners.

  • Key Change: Partners providing services to NSW government entities must now align with state emergency plans and adhere to a 24-hour mandatory reporting window for cyber incidents.
  • Strategic Shift: The policy moves away from "tick-box compliance" towards continuous, evidence-based risk management. For SaaS and IT providers serving the public sector, immediate visibility and incident response integration are no longer optional—they are contractual necessities.

Sector Watch

Real Estate & Property A new investigation has flagged major data leak risks across Australian real estate leasing platforms. With the rental market under pressure, these platforms hold vast amounts of PII (passports, financial statements). Vulnerabilities in their APIs and improper access controls are leaving applicants' data exposed to scraping and identity theft.

FinTech & Business Services Nikkei, the parent company of the Financial Times, confirmed a breach exposing over 17,000 employees and partners. The attack vector? Compromised internal Slack workspaces. This serves as a stark reminder for FinTech firms: collaboration tools are a critical entry point. If your Slack or Teams environment is not monitored for anomalous behaviour, you are flying blind.

Healthcare The healthcare sector remains the most aggressively targeted industry in Australia. Recent reports from the Office of the Australian Information Commissioner (OAIC) indicate a continued surge in data breach notifications. The primary vector remains credential compromise and phishing, targeting overworked staff to gain entry into patient record systems.

Vulnerability Watch

  • Notepad++ Malware Injection: The popular text editor Notepad++ has been compromised. Hackers have injected malware into the software distribution, targeting developers and IT administrators. Action: Verify checksums immediately and block unverified downloads.
  • Fortinet (CVE-2026-24858): A critical Authentication Bypass vulnerability in FortiOS, FortiManager, and FortiAnalyzer is being actively exploited. If you utilise Fortinet infrastructure, ensure you have patched to the latest January 2026 release immediately.
  • n8n Workflow Automation (CVE-2026-21858): A critical Remote Code Execution (RCE) flaw in this workflow automation tool remains a high-priority fix, especially for organisations automating backend API tasks.

Emerging Threat: DeepSeek V4 & AI Sovereignty

While the Australian government banned the DeepSeek app from official devices last year, the release of DeepSeek V4 is reigniting the debate around AI sovereignty. The low-power, high-efficiency model is gaining traction in the private sector. Security leaders must evaluate the data privacy implications of integrating non-Western AI models into their corporate stacks, particularly regarding data residency and censorship risks.


Contact us for a quote for penetration testing service or adversary simulation.

Read More