top of page

The Security Brief


Your MFA Won't Stop This: The OAuth Phishing Campaign Targeting Australian Microsoft 365 Users
A sophisticated phishing-as-a-service platform has compromised more than 340 Microsoft 365 organisations across five countries — including Australia — in under six weeks. What makes this campaign particularly alarming is not its scale, but its mechanism: multi-factor authentication (MFA), the control that many organisations treat as their identity security bedrock, offers no meaningful protection against it. The campaign, attributed to a platform called EvilTokens, exploits a
6 days ago4 min read


AI Platform Under Fire: CVE-2026-33017 Exploited Within Hours of Disclosure
When a critical vulnerability in a widely-used open-source AI platform is actively exploited within twenty hours of public disclosure — with no public proof-of-concept code in circulation — it signals something more alarming than a single software flaw. It tells us that threat actors are operating with prepared, industrialised exploitation toolkits, ready to strike the moment a new target enters their crosshairs. CVE-2026-33017, a critical remote code execution (RCE) flaw in
Mar 254 min read
bottom of page