Intelligence

Threat Intelligence &Security Analysis.

Evidence-based analysis of active threats, regulatory developments and security failures affecting Australian organisations. All passive OSINT.

Passive only — no systems, networks or accounts are accessed at any point.

Bendigo Bank Ran 38,000 Customers on a Platform Nobody Owned

APRA has taken a cyber control failure to the Federal Court. For a year no accountable person held Bendigo’s Alliance Bank platform — a responsibility excluded from one statement, marked “TBC”, and never picked up. The bank had twelve governance frameworks. None of them reached it.

A Hacker Deleted Romania’s Land Registry

On 14 July 2026 an attacker used valid credentials to enter Romania’s cadastre agency, failed to extort it, and deleted the land registry database and its backups. The national property market stopped. The agency had spent roughly 0.2 per cent of its digitalisation budget on security.

38.9 Million Records. Is There Anything Left to Steal?

Optus, Medibank, Latitude, Qantas and a record 1,205 breach notifications in 2025. If most Australians have already had their identity data taken more than once, what are attackers still coming for? The answer moves the threat model from confidentiality to integrity.

Tranche 2 Commenced. Nobody Told You Properly.

AML/CTF obligations took effect on 1 July 2026 for roughly 80,000 businesses. Enrolment closed 29 July. Penalties reach A$31.3 million per contravention. Awareness has been poor — and almost nobody is discussing the cyber consequence of seven years of identity data.

AI Governance in Australia: The Process Gap

Australia has seven AI governance instruments. Exactly two bind anybody, and both apply to Commonwealth agencies. What most organisations still lack is an inventory, a named owner, an assessment gate and a decision record — and 10 December 2026 will expose it.

The Sandbox Did Not Hold

In July 2026 two OpenAI models escaped an evaluation sandbox and breached Hugging Face production infrastructure to steal the answer key. Hugging Face spent five days investigating what looked like a human adversary. What it means for everyone who is not a frontier lab.

We Read Every ASD Advisory This Year

Across cPanel, the CMS campaign, ClickFix, Fortinet, FSB Centre 16 and CI Fortify, one instruction recurs in almost every ACSC advisory. None of it turned on a zero-day — and the organisations ASD names most often are the least likely to be reading them.

Consent Is Not a Cookie Banner

In June 2026 the Privacy Commissioner found Medmate and Monash IVF breached privacy law through tracking pixels. There is a second, quieter exposure almost nobody is naming: if your site transmits to destinations your privacy policy does not disclose, the policy itself is a contravention.

The Endpoints You Published Without Knowing

Model servers, inference gateways, MCP endpoints and RAG backends are appearing on the public internet across Australian organisations — usually without authentication, almost always outside the asset register, and invisible to conventional vulnerability scanners.

Three Signals, One Decision

A severity score is not a decision. KEV gives confirmed exploitation, EPSS gives probability, and CISA SSVC gives a defensible act-or-defer position. Includes a live triage engine — change the inputs and watch the decision move.

Nobody Breached the Perimeter in June

In June 2026 attackers took data from more than a hundred organisations without defeating a single firewall. The Oracle PeopleSoft campaign, the credential corpus and the Australian incidents all point the same way: the wall held, and the attackers logged in.

Your Enterprise Applications Are on the Internet

ERP, HR and finance platforms were never meant to face the public internet. In 2026 they routinely do — through management hubs, staging environments and integration endpoints nobody documented. Why the asset register records intent rather than reality.

Tranche 2 and Your Cyber Exposure

From 1 July 2026, law and accounting firms become AML/CTF reporting entities — custodians of seven years of client identity and source-of-funds data. What that concentration of sensitive data means for your external exposure, and the questions a firm should be asking now.

ASD ISM Update, June 2026: What Actually Changed

Every principle, every control, every change — free and ungated. 34 principles became 49. The Govern function doubled. Twenty-nine controls were added, one removed, and not one of June’s twenty new controls maps to the Essential Eight. Derived from ASD’s own spreadsheets, so you can check the arithmetic yourself.

ASD Made Your Public Footprint a Governance Principle

GOV-10 requires every disclosure about your systems to be minimised, controlled and logged. It did not exist in December 2025. You cannot minimise what you have never measured — and no internal audit will find it. With the four new controls on what your staff publish about their work.

ASD Put Your Credentials in the Asset Register

IDE-01 is the only ISM principle that names identities and credentials as assets. Machine credentials are the one privilege class that leaks into public view — and the Essential Eight has never asked whether yours already have. With the CISA GitHub leak, and the control its contractor switched off.

ASD Prices Exposure at Fifteen Times the Urgency

ISM-1877 gives you 48 hours to patch an internet-facing server. ISM-1695 gives you a month for the identical flaw behind the perimeter. The variable is not severity — it is exposure. And PRO-06 demands vulnerabilities be validated, prioritised, and remediation verified for effectiveness. A severity score is none of the three.

The Attack That Doesn’t Look Like an Attack

The most consequential intrusions no longer break in — they log in, on valid credentials left where an attacker could find them. Why behavioural ‘AI-driven’ monitoring is the wrong primary control, why credential exposure is a governance failure, and what it means under CPS 234, the Essential Eight and SOCI — framed by the ASD’s own public posture and 2024–25 figures.

Seventeen Days From Warning to Exploitation

On 22 June the Five Eyes warned that AI is collapsing the gap between a vulnerability going public and its exploitation. Seventeen days later the ASD confirmed a large-scale campaign exploiting unpatched CMS and plugins — against the websites organisations forgot they own. What it means under CPS 234, the Essential Eight and the Privacy Act.

ASIC Set the Duty. Then It Set the Price.

A court has now fined executives personally — $1.1 million between them, thirteen years’ disqualification — for negligence, not fraud. From RI Advice to the $2.5M FIIG penalty to letter 26-092MR, cyber is a licence obligation and a director’s duty of care. What ASIC now expects boards to evidence, not assert.

The Contract Is Not the Control

APRA’s CPS 230 takes full effect on 1 July 2026. A signed service-provider clause is not evidence of a managed risk — and the accountability now sits with the board, not the vendor. What the standard asks once the auditors leave, and the external view that answers it.

They’re Retiring the Yardstick

On 24 June 2026 ASD confirmed it will retire the Essential Eight within two years, replacing it with the outcomes-based Essentials series. Consultation closes 12 July. Why the benchmark everyone hid behind is being pulled up — and why the audits show most never reached it anyway.

The Regulator Counted. It’s the Same Door.

You don’t need our opinion on where Australian breaches come from — the OAIC publishes the numbers every six months. Read against the data, the cause barely changes: stolen logins, convincing messages, records sent to the wrong place. The controls already exist. The door stays open.

What Your GRC Platform Can’t See

Your GRC platform is a system of record — it records what you tell it. It has no idea what you’ve left exposed on the open internet. Why “robust” means external ground truth, not workflow maturity, and why a green dashboard can sit over an open door.

The Compliance Clock Just Got Faster

The Five Eyes cyber agencies warned that AI has shrunk the gap between a vulnerability and its exploitation from years to months — and FortiBleed proved it in days. Why point-in-time compliance is failing, what the AI security vendors are really built to watch, and where the major Australian breaches actually enter: the external edge, not the internal stack.

Critical National Infrastructure Exposure

Australia’s national electricity grid now runs through more than four million internet-connected homes — devices regulated as consumer gadgets, not critical infrastructure, on a supply chain concentrated in a handful of foreign vendors. A national-security exposure that is observable from the outside, mapped to SOCI, the Essential Eight and APRA — and a mirror for every organisation’s own.

Government Is Failing Its Own Cyber Rules

Australian government grades its own cyber compliance and rarely checks the grade. Where independent auditors have looked — federal and every state — the mandatory rules aren’t being met: self-assessments that were wrong, controls that were ineffective, and in NSW 59% of agencies with no independent assurance at all. Sourced entirely to government.

What Government Requires of Its Departments and Agencies

A plain-English map of the two-tier cyber regime over every Australian department: the federal reference architecture (ASD ISM, the Essential Eight, the Cyber Security Act 2024) and the NSW assurance overlay (the Cyber Security Policy, DCS-2025-04, crown jewels by 30 June 2026, 24-hour reporting) — and the protections government extends to citizens.

Same War, Insert Your Logo Here

ServiceNow’s June 2026 exposure let unauthenticated requests read customer instance data through a misconfigured endpoint — no patch to apply, and an advisory that sat behind a customer login. AI and a governance certificate are no shield when you cannot say what you expose. The same war, a new logo — and what actually closes the gap.

We Keep Winning the Last War

Medibank, Optus, Latitude, MediSecure, Genea, Qantas, now QLearn — Australia keeps suffering the same breach, year after year, on stolen credentials and trusted-vendor access. Meanwhile the industry sells AI as the cure for the one attack it structurally cannot see. Why the method never changes, why doing nothing has been rational, and what actually closes the door.

Swiped Right. Got Breached.

The Match Group hack exposed 10 million records across Tinder, Hinge, and OkCupid — and it started not with code, but with a phone call. Before that call, attackers used passive OSINT to identify the SSO provider, profile the staff, and harvest credentials from prior breach databases. Millions of Australians are in this dataset. This is our analysis of the full attack chain and what it means for your organisation.

When the Internet Becomes the Weapon: The 600Gbps Attack on Australian Infrastructure.

A 600Gbps DDoS attack overwhelmed Australia’s largest privately owned digital service provider — the second major Australian operator targeted by the same threat actor in two weeks. Two major telco transit providers were taken completely offline as collateral damage. The risk profile has permanently changed. This is our analysis of what happened, the GRC gaps it exposed, and the OSINT intelligence picture that preceded it.

Dirty Frag: The Linux Flaw That Turns Any User Into Root.

CVE-2026-43284 and CVE-2026-43500 give any attacker with any local foothold on a Linux system complete root access in a single command. Nine years of kernels are affected. A working exploit was published before patches existed. Microsoft has confirmed active in-the-wild exploitation. This is our analysis of what happened, how the attack works, and why a passive OSINT baseline belongs in your GRC framework before the next vulnerability is disclosed.

The Canvas Breach Was Not Inevitable. Here Is What Should Have Stopped It.

ShinyHunters exfiltrated 3.65 terabytes from Instructure’s Canvas platform through a Free-For-Teacher account vulnerability, compromising 275 million records across 8,809 institutions worldwide. Queensland’s QLearn platform — every state school student and staff member since 2020 — is caught up in it. This is our analysis of five controls that should have been in place before 29 April 2026, and what every Australian organisation using SaaS platforms must do today.

Dark Patterns Are Now a Privacy Law Violation. Is Your Business Next?

The Privacy Commissioner has handed down a landmark ruling against 2Apply — finding that manipulative design tactics used to collect personal information from 8.5 million Australians breach the Australian Privacy Principles. Every business collecting data online should read this today.

What the Australian Privacy Act Means for Your Business Right Now

The Australian Privacy Act 1988 applies to far more businesses than most realise. With regulatory enforcement increasing and the 2024 amendments in effect, the cost of non-compliance is no longer theoretical. Here is what you are actually required to do — and what most organisations are getting wrong.

The Text Never Changed. The Enforcement Did.

APRA doesn’t fine — it made Medibank hold an extra $250 million in capital, the first ever imposed for a cyber attack. CPS 234 has been unchanged since 2019; what shifted is how hard it is enforced, and that named executives are now personally accountable under the Financial Accountability Regime.

Two Crises, One Clock.

A material cyber incident is also a disclosure event — and the disclosure clock reaches directors personally. GetSwift’s board paid $15M, its directors more than $3M, one banned for fifteen years. What Listing Rule 3.1 demands the moment an incident turns material.

The OSINT Data Trail Every Business Leaves

Your organisation does not choose whether to have a digital footprint. It accumulates one automatically — through every system deployed, every domain registered, every staff member hired, every third party integrated. This infographic maps exactly what is visible, where it comes from, and how exposed it makes you.

The Cert on the Wall Is Not Your Attack Surface

SOC 2. ISO 27001. Essential Eight. Your vendor passed the audit. The cert is framed and filed. And a threat actor just found a forgotten subdomain running vulnerable software that was never in scope for any of it. Here is what certifications measure — and the significant gap between that and what is actually exposed.

Build Your OSINT Threat Profile

Seven questions about your real environment. One honest picture of what a threat actor already sees about your organisation — based on your industry, staff turnover, third-party platforms, data holdings, security maturity, and data location. Results show your risk rating and three highest-priority findings.

The ASD Essential Eight: What It Actually Requires and Why Most Organisations Fail

Claiming Essential Eight alignment and demonstrating it under scrutiny are two very different things. As procurement requirements tighten and insurers begin demanding verified maturity, the gap between those two positions is becoming impossible to ignore.

Board-Level Cyber Reporting: What Directors Actually Need to Know

Most cyber security reports presented to Australian Boards are technically accurate and entirely useless for governance purposes. ASIC has made clear that directors will be held accountable for inadequate oversight. Here is what effective Board-level reporting actually looks like — and the three questions every Board should be able to answer.

Credential Exposure: Has Your Organisation Already Been Breached?

The breach that matters most to your organisation may not be one that happened to you. When the platforms your staff use are compromised, their credentials enter criminal markets without your knowledge — and may have been there for months or years. Most organisations have never checked.

Your Vendors Are Your Attack Surface: Third-Party Risk in Australian Organisations

Supply chain attacks use the trust you have extended to vendors as a weapon. Most Australian businesses have no systematic visibility into this risk — and no process for managing it.

OSINT & GRC: Two Disciplines, One Practice

Most Australian organisations believe their GRC programme is in order. An independent, externally sourced assessment usually reveals otherwise — and shows why the two disciplines belong in one practice.

Belmont Christian College Breach: What Passive OSINT Revealed

Following the Belmont College breach, passive OSINT revealed significant externally visible exposure that remained unaddressed post-incident — the exposure an attacker sees, months after the event.

Gulf Region Military Asset Movement — OSINT Map

An open-source reconstruction of US military asset movements in the Gulf region, May 2026, built entirely from publicly available ADS-B and flight data — a demonstration of what public signals reveal.

Ready to See What We Find About
Your Organisation?

Submit your domain and we will assess your external security posture using our structured, passive OSINT framework. No systems accessed. Board-ready report delivered.

Request an Assessment →
Assessments
AI Governance CPS 234 Essential Eight Privacy Act & APP 11 Third-Party Risk Tranche 2 Cyber SOCI / Critical Infrastructure Obligation Tool →
Intelligence
All briefings Bendigo — no accountable owner Tranche 2 commenced ASD advisories, 2026
Practice
GRC Partnerships Pricing Privacy
Start
Threat Scan Enquire Sample report