top of page

The Security Brief


SonicWall SMA 1000 Zero-Days: Remote Access Appliances Turned Into Backdoors
Two zero-day vulnerabilities in SonicWall's SMA 1000 remote access appliances are being exploited in the wild, and attackers are using the appliances themselves as a route into corporate networks. SonicWall confirmed active exploitation on 14 July. CISA followed within days, adding both flaws to its Known Exploited Vulnerabilities catalogue and giving US federal agencies until 17 July to patch or disconnect the devices. What Happened The two flaws are CVE-2026-15409, an unaut
Jul 213 min read


CVE-2026-8451: A New NetScaler Memory Leak, Exploited Within a Day
Citrix patched a new NetScaler flaw on 30 June. Attackers were exploiting it within 24 hours. CVE-2026-8451 is a pre-authentication memory leak in the same family as CitrixBleed, the 2023 bug that fed a wave of intrusions worldwide. The gap between a vendor advisory and mass scanning is now measured in hours, not weeks. What Happened On 30 June, Citrix published bulletin CTX696604, disclosing six vulnerabilities in NetScaler ADC and NetScaler Gateway. The one drawing scrutiny
Jul 113 min read


SharePoint RCE Under Active Attack: What CVE-2026-45659 Means for On-Premises Servers
CISA has confirmed that attackers are exploiting a remote code execution flaw in Microsoft SharePoint Server, and it has told United States federal agencies to patch by 4 July. The bug, CVE-2026-45659, carries a CVSS score of 8.8 and needs nothing more than a low-privileged account to work. For any Australian organisation still running SharePoint on-premises, that deadline is worth watching just as closely. What Happened On 1 July, CISA added CVE-2026-45659 to its Known Explo
Jul 83 min read


Cisco Unified CM Under Attack: What CVE-2026-20230 Means for Your Phone System
A patch released three weeks ago has turned into a live incident. CVE-2026-20230, a flaw in Cisco Unified Communications Manager, is now being exploited in the wild, and an attacker who pulls it off lands with root on the server running an organisation's phone system. Cisco shipped the fix on 3 June. The attacks started over the weekend of 21 to 22 June. What Happened CVE-2026-20230 is a server-side request forgery weakness in Cisco Unified Communications Manager and its Sess
Jun 263 min read


FortiBleed: 75,000 Fortinet Firewalls Exposed and What It Means for Australian Networks
Roughly 75,000 Fortinet FortiGate firewalls have had their administrator credentials exposed in a dataset now circulating among researchers, and in all likelihood among criminals. These devices sit at the edge of corporate networks across 194 countries, and the credentials appear to be current. For any organisation running FortiGate as its perimeter, this is something to act on this week, not next quarter. What Happened The campaign, named FortiBleed, was first disclosed on 1
Jun 223 min read


The Instructure Breach: 275 Million Records and a Hard Look at Education's Supply Chain
ShinyHunters has claimed a breach of Instructure, the company behind the Canvas learning management system used by roughly 9,000 schools and universities worldwide. The group says it pulled personal records on 275 million students, teachers and staff, and gave Instructure until 12 May to pay or watch the data hit a public leak site. Australian institutions running Canvas are now part of that exposure picture. What Happened ShinyHunters publicly took credit for the Instructure
May 83 min read


Copy Fail (CVE-2026-31431): What the Latest Linux Privilege Escalation Means for Australian Defenders
A 732-byte Python script. That is all it takes to go from an unprivileged shell to root on almost every Linux distribution shipped since 2017. The flaw, dubbed Copy Fail and tracked as CVE-2026-31431, was disclosed on 29 April by researchers from Theori and Xint after sitting unnoticed in the Linux kernel for nine years. What Happened Copy Fail is a logic bug in the Linux kernel's authencesn AEAD cryptographic template, reachable through the AF_ALG socket interface. By chaini
May 13 min read


Critical Cisco IMC Vulnerability (CVE-2026-20093): What Australian Organisations Need to Do Now
A critical authentication bypass vulnerability in Cisco's Integrated Management Controller (IMC) has sent security teams scrambling this week, with a CVSS score of 9.8 out of 10.0 placing it firmly in the "patch immediately" category. For organisations running Cisco UCS servers — including many Australian enterprises and government agencies — the window between disclosure and exploitation is narrowing fast. What Happened Cisco disclosed CVE-2026-20093 on 3 April 2026, a criti
Apr 43 min read


Your MFA Won't Stop This: The OAuth Phishing Campaign Targeting Australian Microsoft 365 Users
A sophisticated phishing-as-a-service platform has compromised more than 340 Microsoft 365 organisations across five countries — including Australia — in under six weeks. What makes this campaign particularly alarming is not its scale, but its mechanism: multi-factor authentication (MFA), the control that many organisations treat as their identity security bedrock, offers no meaningful protection against it. The campaign, attributed to a platform called EvilTokens, exploits a
Mar 274 min read


AI Platform Under Fire: CVE-2026-33017 Exploited Within Hours of Disclosure
When a critical vulnerability in a widely-used open-source AI platform is actively exploited within twenty hours of public disclosure — with no public proof-of-concept code in circulation — it signals something more alarming than a single software flaw. It tells us that threat actors are operating with prepared, industrialised exploitation toolkits, ready to strike the moment a new target enters their crosshairs. CVE-2026-33017, a critical remote code execution (RCE) flaw in
Mar 254 min read
bottom of page