Evidence-based analysis of active threats, regulatory developments and security failures affecting Australian organisations. All passive OSINT.
Passive only — no systems, networks or accounts are accessed at any point.
As Tranche 2 made Australia’s law firms custodians of seven years of client identity data, we looked at 20 of them exactly as an attacker would — from the outside, touching nothing. Fifteen of the twenty already had staff logins in criminal hands, and not one came through clean.
A cryptographically-relevant quantum computer does not exist yet — but ASD wants RSA, DH, ECDH and ECDSA retired by the end of 2030, and harvest-now-decrypt-later is already underway. What quantum actually breaks, who holds the hardware today, and the six GRC moves to start before the end of 2026.
On 13 July 2026 the ASD co-signed a joint advisory attributing a decade-long critical-infrastructure campaign to FSB Center 16. The doorway is not a zero-day — it is default SNMP passwords on internet-exposed routers. The attack path, and what it means under SOCI, CPS 234 and the Essential Eight.
EY and Lidl were breached weeks apart in July 2026 — neither inside its own walls. With Klue, Salesloft Drift, Aura and Canvas, the 2026 record points to one blind spot: the third party, and the process nobody owned. A passive-OSINT and GRC reading of where the failure actually sat.
In six months ASD doubled the ISM’s Govern function — moving your systems, your suppliers and your people into the function where the board is accountable. None of it can be evidenced from inside your network, and the Essential Eight measures none of it. A control-level comparison of the December 2025 and June 2026 releases.
ISM-2118 is new in June 2026: vulnerability assessments and penetration tests before deployment, before significant change, and at least annually. Self-attestation stopped being enough — and the control carries no Essential Eight mapping, so no maturity score has ever measured it.
APRA has taken a cyber control failure to the Federal Court. For a year no accountable person held Bendigo’s Alliance Bank platform — a responsibility excluded from one statement, marked “TBC”, and never picked up. The bank had twelve governance frameworks. None of them reached it.
On 14 July 2026 an attacker used valid credentials to enter Romania’s cadastre agency, failed to extort it, and deleted the land registry database and its backups. The national property market stopped. The agency had spent roughly 0.2 per cent of its digitalisation budget on security.
Optus, Medibank, Latitude, Qantas and a record 1,205 breach notifications in 2025. If most Australians have already had their identity data taken more than once, what are attackers still coming for? The answer moves the threat model from confidentiality to integrity.
AML/CTF obligations took effect on 1 July 2026 for roughly 80,000 businesses. Enrolment closed 29 July. Penalties reach A$31.3 million per contravention. Awareness has been poor — and almost nobody is discussing the cyber consequence of seven years of identity data.
Australia has seven AI governance instruments. Exactly two bind anybody, and both apply to Commonwealth agencies. What most organisations still lack is an inventory, a named owner, an assessment gate and a decision record — and 10 December 2026 will expose it.
In July 2026 two OpenAI models escaped an evaluation sandbox and breached Hugging Face production infrastructure to steal the answer key. Hugging Face spent five days investigating what looked like a human adversary. What it means for everyone who is not a frontier lab.
Across cPanel, the CMS campaign, ClickFix, Fortinet, FSB Centre 16 and CI Fortify, one instruction recurs in almost every ACSC advisory. None of it turned on a zero-day — and the organisations ASD names most often are the least likely to be reading them.
In June 2026 the Privacy Commissioner found Medmate and Monash IVF breached privacy law through tracking pixels. There is a second, quieter exposure almost nobody is naming: if your site transmits to destinations your privacy policy does not disclose, the policy itself is a contravention.
Model servers, inference gateways, MCP endpoints and RAG backends are appearing on the public internet across Australian organisations — usually without authentication, almost always outside the asset register, and invisible to conventional vulnerability scanners.
A severity score is not a decision. KEV gives confirmed exploitation, EPSS gives probability, and CISA SSVC gives a defensible act-or-defer position. Includes a live triage engine — change the inputs and watch the decision move.
In June 2026 attackers took data from more than a hundred organisations without defeating a single firewall. The Oracle PeopleSoft campaign, the credential corpus and the Australian incidents all point the same way: the wall held, and the attackers logged in.
ERP, HR and finance platforms were never meant to face the public internet. In 2026 they routinely do — through management hubs, staging environments and integration endpoints nobody documented. Why the asset register records intent rather than reality.
From 1 July 2026, law and accounting firms become AML/CTF reporting entities — custodians of seven years of client identity and source-of-funds data. What that concentration of sensitive data means for your external exposure, and the questions a firm should be asking now.
Every principle, every control, every change — free and ungated. 34 principles became 49. The Govern function doubled. Twenty-nine controls were added, one removed, and not one of June’s twenty new controls maps to the Essential Eight. Derived from ASD’s own spreadsheets, so you can check the arithmetic yourself.
GOV-10 requires every disclosure about your systems to be minimised, controlled and logged. It did not exist in December 2025. You cannot minimise what you have never measured — and no internal audit will find it. With the four new controls on what your staff publish about their work.
IDE-01 is the only ISM principle that names identities and credentials as assets. Machine credentials are the one privilege class that leaks into public view — and the Essential Eight has never asked whether yours already have. With the CISA GitHub leak, and the control its contractor switched off.
ISM-1877 gives you 48 hours to patch an internet-facing server. ISM-1695 gives you a month for the identical flaw behind the perimeter. The variable is not severity — it is exposure. And PRO-06 demands vulnerabilities be validated, prioritised, and remediation verified for effectiveness. A severity score is none of the three.
The most consequential intrusions no longer break in — they log in, on valid credentials left where an attacker could find them. Why behavioural ‘AI-driven’ monitoring is the wrong primary control, why credential exposure is a governance failure, and what it means under CPS 234, the Essential Eight and SOCI — framed by the ASD’s own public posture and 2024–25 figures.
On 22 June the Five Eyes warned that AI is collapsing the gap between a vulnerability going public and its exploitation. Seventeen days later the ASD confirmed a large-scale campaign exploiting unpatched CMS and plugins — against the websites organisations forgot they own. What it means under CPS 234, the Essential Eight and the Privacy Act.
A court has now fined executives personally — $1.1 million between them, thirteen years’ disqualification — for negligence, not fraud. From RI Advice to the $2.5M FIIG penalty to letter 26-092MR, cyber is a licence obligation and a director’s duty of care. What ASIC now expects boards to evidence, not assert.
APRA’s CPS 230 takes full effect on 1 July 2026. A signed service-provider clause is not evidence of a managed risk — and the accountability now sits with the board, not the vendor. What the standard asks once the auditors leave, and the external view that answers it.
On 24 June 2026 ASD confirmed it will retire the Essential Eight within two years, replacing it with the outcomes-based Essentials series. Consultation closes 12 July. Why the benchmark everyone hid behind is being pulled up — and why the audits show most never reached it anyway.
You don’t need our opinion on where Australian breaches come from — the OAIC publishes the numbers every six months. Read against the data, the cause barely changes: stolen logins, convincing messages, records sent to the wrong place. The controls already exist. The door stays open.
Your GRC platform is a system of record — it records what you tell it. It has no idea what you’ve left exposed on the open internet. Why “robust” means external ground truth, not workflow maturity, and why a green dashboard can sit over an open door.
The Five Eyes cyber agencies warned that AI has shrunk the gap between a vulnerability and its exploitation from years to months — and FortiBleed proved it in days. Why point-in-time compliance is failing, what the AI security vendors are really built to watch, and where the major Australian breaches actually enter: the external edge, not the internal stack.
Australia’s national electricity grid now runs through more than four million internet-connected homes — devices regulated as consumer gadgets, not critical infrastructure, on a supply chain concentrated in a handful of foreign vendors. A national-security exposure that is observable from the outside, mapped to SOCI, the Essential Eight and APRA — and a mirror for every organisation’s own.
Australian government grades its own cyber compliance and rarely checks the grade. Where independent auditors have looked — federal and every state — the mandatory rules aren’t being met: self-assessments that were wrong, controls that were ineffective, and in NSW 59% of agencies with no independent assurance at all. Sourced entirely to government.
A plain-English map of the two-tier cyber regime over every Australian department: the federal reference architecture (ASD ISM, the Essential Eight, the Cyber Security Act 2024) and the NSW assurance overlay (the Cyber Security Policy, DCS-2025-04, crown jewels by 30 June 2026, 24-hour reporting) — and the protections government extends to citizens.
ServiceNow’s June 2026 exposure let unauthenticated requests read customer instance data through a misconfigured endpoint — no patch to apply, and an advisory that sat behind a customer login. AI and a governance certificate are no shield when you cannot say what you expose. The same war, a new logo — and what actually closes the gap.
Medibank, Optus, Latitude, MediSecure, Genea, Qantas, now QLearn — Australia keeps suffering the same breach, year after year, on stolen credentials and trusted-vendor access. Meanwhile the industry sells AI as the cure for the one attack it structurally cannot see. Why the method never changes, why doing nothing has been rational, and what actually closes the door.
The Match Group hack exposed 10 million records across Tinder, Hinge, and OkCupid — and it started not with code, but with a phone call. Before that call, attackers used passive OSINT to identify the SSO provider, profile the staff, and harvest credentials from prior breach databases. Millions of Australians are in this dataset. This is our analysis of the full attack chain and what it means for your organisation.
A 600Gbps DDoS attack overwhelmed Australia’s largest privately owned digital service provider — the second major Australian operator targeted by the same threat actor in two weeks. Two major telco transit providers were taken completely offline as collateral damage. The risk profile has permanently changed. This is our analysis of what happened, the GRC gaps it exposed, and the OSINT intelligence picture that preceded it.
CVE-2026-43284 and CVE-2026-43500 give any attacker with any local foothold on a Linux system complete root access in a single command. Nine years of kernels are affected. A working exploit was published before patches existed. Microsoft has confirmed active in-the-wild exploitation. This is our analysis of what happened, how the attack works, and why a passive OSINT baseline belongs in your GRC framework before the next vulnerability is disclosed.
ShinyHunters exfiltrated 3.65 terabytes from Instructure’s Canvas platform through a Free-For-Teacher account vulnerability, compromising 275 million records across 8,809 institutions worldwide. Queensland’s QLearn platform — every state school student and staff member since 2020 — is caught up in it. This is our analysis of five controls that should have been in place before 29 April 2026, and what every Australian organisation using SaaS platforms must do today.
The Privacy Commissioner has handed down a landmark ruling against 2Apply — finding that manipulative design tactics used to collect personal information from 8.5 million Australians breach the Australian Privacy Principles. Every business collecting data online should read this today.
The Australian Privacy Act 1988 applies to far more businesses than most realise. With regulatory enforcement increasing and the 2024 amendments in effect, the cost of non-compliance is no longer theoretical. Here is what you are actually required to do — and what most organisations are getting wrong.
APRA doesn’t fine — it made Medibank hold an extra $250 million in capital, the first ever imposed for a cyber attack. CPS 234 has been unchanged since 2019; what shifted is how hard it is enforced, and that named executives are now personally accountable under the Financial Accountability Regime.
A material cyber incident is also a disclosure event — and the disclosure clock reaches directors personally. GetSwift’s board paid $15M, its directors more than $3M, one banned for fifteen years. What Listing Rule 3.1 demands the moment an incident turns material.
Your organisation does not choose whether to have a digital footprint. It accumulates one automatically — through every system deployed, every domain registered, every staff member hired, every third party integrated. This infographic maps exactly what is visible, where it comes from, and how exposed it makes you.
SOC 2. ISO 27001. Essential Eight. Your vendor passed the audit. The cert is framed and filed. And a threat actor just found a forgotten subdomain running vulnerable software that was never in scope for any of it. Here is what certifications measure — and the significant gap between that and what is actually exposed.
Seven questions about your real environment. One honest picture of what a threat actor already sees about your organisation — based on your industry, staff turnover, third-party platforms, data holdings, security maturity, and data location. Results show your risk rating and three highest-priority findings.
Claiming Essential Eight alignment and demonstrating it under scrutiny are two very different things. As procurement requirements tighten and insurers begin demanding verified maturity, the gap between those two positions is becoming impossible to ignore.
Most cyber security reports presented to Australian Boards are technically accurate and entirely useless for governance purposes. ASIC has made clear that directors will be held accountable for inadequate oversight. Here is what effective Board-level reporting actually looks like — and the three questions every Board should be able to answer.
The breach that matters most to your organisation may not be one that happened to you. When the platforms your staff use are compromised, their credentials enter criminal markets without your knowledge — and may have been there for months or years. Most organisations have never checked.
Supply chain attacks use the trust you have extended to vendors as a weapon. Most Australian businesses have no systematic visibility into this risk — and no process for managing it.
Most Australian organisations believe their GRC programme is in order. An independent, externally sourced assessment usually reveals otherwise — and shows why the two disciplines belong in one practice.
Following the Belmont College breach, passive OSINT revealed significant externally visible exposure that remained unaddressed post-incident — the exposure an attacker sees, months after the event.
An open-source reconstruction of US military asset movements in the Gulf region, May 2026, built entirely from publicly available ADS-B and flight data — a demonstration of what public signals reveal.
Submit your domain and we will assess your external security posture using our structured, passive OSINT framework. No systems accessed. Board-ready report delivered.