top of page

The Security Brief


Docker's Billion-Dollar Oversight: CVE-2026-34040 Lets Attackers Slip Past Authorisation Plugins
A newly disclosed vulnerability in Docker Engine has once again shown how a single overlooked edge case can unravel an entire security control. CVE-2026-34040, rated 8.8 on the CVSS scale, allows attackers to bypass authorisation plugins with nothing more than a padded HTTP request. For any organisation running containers in production — which today means most of them — the implications are serious and immediate. What Happened Researchers at Cyera discovered that Docker's mid
7 days ago3 min read


Critical Cisco IMC Vulnerability (CVE-2026-20093): What Australian Organisations Need to Do Now
A critical authentication bypass vulnerability in Cisco's Integrated Management Controller (IMC) has sent security teams scrambling this week, with a CVSS score of 9.8 out of 10.0 placing it firmly in the "patch immediately" category. For organisations running Cisco UCS servers — including many Australian enterprises and government agencies — the window between disclosure and exploitation is narrowing fast. What Happened Cisco disclosed CVE-2026-20093 on 3 April 2026, a criti
Apr 43 min read


Your MFA Won't Stop This: The OAuth Phishing Campaign Targeting Australian Microsoft 365 Users
A sophisticated phishing-as-a-service platform has compromised more than 340 Microsoft 365 organisations across five countries — including Australia — in under six weeks. What makes this campaign particularly alarming is not its scale, but its mechanism: multi-factor authentication (MFA), the control that many organisations treat as their identity security bedrock, offers no meaningful protection against it. The campaign, attributed to a platform called EvilTokens, exploits a
Mar 274 min read
bottom of page