Security Insights

Threat Update
Phillip Roberts 5 August 2026

Trusted Domains, Disposable Infrastructure: Tax-Season Phishing on Vercel

Fortian has observed a sharp rise in campaigns abusing legitimate application hosting platforms - Vercel, Cloudflare Workers and Netlify - to stage credential harvesting pages and malware loaders. The platforms aren't compromised; attackers just deploy from free-tier accounts and inherit the clean domain reputation that URL filters and block lists trust. Three July campaigns are covered: an AI-generated JavaScript loader delivering LogMeIn RMM behind a fake ATO document, a UPS impersonation dropping ScreenConnect via a VBS "Flash updater", and indiscriminate ATO credential harvesting behind fake myGov notifications. Includes KQL hunting queries and indicators of compromise.

Read more →
Monthly Update
Allan Grant 31 July 2026

July Cyber Environment Update

OpenAI and Anthropic both disclosed that their own AI models escaped evaluation environments and compromised real production systems within ten days of each other, while researchers documented the first ransomware operation run start to finish by an LLM. Scattered Spider members were jailed over the Transport for London attack, ShinyHunters claimed Ernst & Young, and Russian intelligence was found hijacking IP cameras across Europe for military reconnaissance. In Australia, AML/CTF Tranche 2 brought roughly 90,000 professional services firms under the Privacy Act, and breaches hit Partnered Health, Origin Energy and several smaller operators.

Read more →
Threat Update
Phillip Roberts 28 July 2026

Nothing to Take Down: IPFS-Hosted Phishing With Runtime Brand Impersonation

A technical breakdown of a credential harvesting campaign targeting ASX-listed organisations. The kit is published to IPFS and addressed by content hash, so there is no single host to action. It builds a convincing impersonation of any target organisation at runtime from the victim's own email domain using three free public APIs, and exfiltrates harvested credentials straight into the operator's Telegram client. Includes anti-analysis techniques, attribution artefacts, detection opportunities and indicators of compromise.

Read more →
Threat Update
Fortian 24 July 2026

Q2 2026 Quarterly Cyber Threat Review

A synthesis of the significant global and Australian cyber events of April, May and June 2026. The quarter was defined by attacks on trust: frontier AI turned both weapon and regulatory flashpoint, signed npm packages shipped malware, ShinyHunters and The Com dominated the identity breach headlines, and nation-state actors shifted toward pre-positioning in critical infrastructure. Australian regulators accelerated hard, with an APRA letter on AI risk, the retirement of the Essential Eight and the Horizon 2 phase of the national strategy.

Read more →
Threat Update
Tristan Bunnage 15 July 2026

Detection of Multi-Accounting Campaigns with Machine Learning

Fortian's machine-learning approach to catching large multi-accounting campaigns that randomise usernames, user agents and residential IPs to slip past conventional detection rules - using bisecting k-means clustering over engineered features to surface a real campaign that had evaded every existing rule.

Read more →
Monthly Update
Allan Grant 1 July 2026

June Cyber Environment Update

June was defined by AI on both sides of the fight: the Five Eyes warned boards it is a present business risk, the FBI dismantled a China-based AI-powered phishing service blamed for $1.9 billion in losses, and the US forced Anthropic and OpenAI to restrict their most capable models. Identity stayed the weakest link, with ShinyHunters exploiting an Oracle PeopleSoft zero-day against 100+ organisations and FortiBleed compromising 75,000 devices. Australia moved to retire the Essential Eight, updated the ISM, and ordered Amex to overhaul access controls after an insider breach.

Read more →
Life at Fortian
Casey Wilfling 8 June 2026

Fortian Summer Internship 2026

Casey Wilfling's experience interning with Fortian's Managed Security Services team in summer 2026, covering ransomware attack analysis with Cyber Kill Chain mapping, custom Microsoft Sentinel detection engineering, and building an automated IoC extraction and STIX 2.1 conversion pipeline for multi-tenant threat intelligence distribution via Azure Logic Apps and OpenCTI.

Read more →
Monthly Update
Allan Grant 1 June 2026

May Cyber Environment Update

May was defined by the TanStack and AntV npm supply chain compromises, ShinyHunters' extortion of Instructure exposing 275 million records (including Australian universities and Queensland schools), and CISA shifting US critical infrastructure policy onto a wartime footing. Australia formally established its Cyber Incident Review Board, the Federal Budget signalled cyber spending in station-keeping mode, and ransomware groups hit hospitality, jewellery, construction, and IT services domestically.

Read more →
Life at Fortian
Jake Marchese 21 May 2026

Webinar: Understanding Adversary-in-the-Middle Attacks

Join Fortian's Jake Marchese for a webinar on 16 June 2026 covering how AiTM phishing attacks bypass MFA by stealing session tokens, with an attack demonstration and detection strategies using Microsoft Sentinel.

Read more →
Life at Fortian
Fortian 5 May 2026

Fortian at the 2026 Technology for Social Justice Conference

Fortian is proud to sponsor the Technology for Social Justice Conference, taking place 6 to 8 May 2026 at the Telstra Customer Insight Centre in Melbourne. Organised by Infoxchange, the conference brings together executives, IT leaders, and change-makers from across the for-purpose sector.

Read more →
Monthly Update
Allan Grant & Jordan Kavallaris 1 May 2026

April Cyber Environment Update

April was dominated by three converging storylines: Iranian escalation against US industrial infrastructure, North Korea's patient and precisely executed supply chain operations, and Anthropic's Claude Mythos Preview forcing a sector-wide conversation about AI-driven vulnerability discovery. Supply chain compromise ran through almost every major incident.

Read more →
Monthly Update
Allan Grant 2 April 2026

March Cyber Environment Update

Geopolitics and cybersecurity collided in March 2026 as the US-Israeli campaign against Iran opened a new chapter in state-linked cyber conflict - one that reached commercial cloud infrastructure, senior US officials, and organisations with no connection to the conflict whatsoever. Read on for Fortian's analysis of the month's key developments.

Read more →
Monthly Update
Jordan Kavallaris 5 March 2026

February Cyber Environment Update

Cyber threats struck close to home in February 2026, with a Sydney fintech exposing the driver's licences of nearly a quarter of a million Australians, a Victorian poultry processor taken offline by attackers, and 94 Australian organisations confirmed to have paid ransomware groups since mandatory disclosure commenced. Globally, Russia targeted Poland's power grid and the Winter Olympics, a Chinese state-sponsored group hijacked a trusted software update mechanism, and the US withdrawal from key international cyber organisations left international partners with fewer Western-aligned options.

Read more →
Threat Update
Phillip Roberts 11 February 2026

2025 Cyber Threats: A Frontline Perspective

Fortian’s annual Security Operations Centre report highlights the most significant cyber threat trends affecting Australian organisations in 2025, based on real incidents investigated by our SOC. This year’s findings reveal a decisive shift toward identity abuse, SaaS-driven data theft, browser-native attacks, and defence evasion through trusted infrastructure. Drawing on real-world attacker behaviour rather than theory, the report examines how these threats are playing out in practice and the defensive measures organisations should prioritise as they move into 2026.

Read more →
Monthly Update
Allan Grant 2 February 2026

January Cyber Environment Update

January 2026 highlighted how closely cyber activity continues to track broader political, economic and social pressures. State-linked cyber operations tied to conflict in Europe and domestic unrest in Iran remained prominent, while cybercriminal groups continued to demonstrate how effective social engineering and identity abuse have become, enabling large-scale data theft without the need for sophisticated technical exploits.

Read more →
Monthly Update
Allan Grant 30 November 2025

November Cyber Environment Update

November saw steady activity across Australia’s cyber landscape, including new government sanctions, emerging AI-enabled threats and several notable breaches affecting local organisations. This month’s update highlights how attackers continue to target supply chains, identity systems and high-trust service platforms.

Read more →
Monthly Update
Allan Grant 31 October 2025

October Cyber Environment Update

In October, the U.S. shutdown hampered CISA’s operations, while major incidents unfolded across F5, Qantas, and ReadyTech. On a positive note, the month also brought new policy initiatives and awareness efforts, including Cyber Security Awareness Month, the release of the ACSC’s Annual Cyber Threat Report, and the appointment of a new Ambassador for Cyber Affairs and Critical Technology.

Read more →
Advisory & Governance
Riva Antonio 27 October 2025

The Hidden Third-Party Risk: How Shadow IT Escapes Governance

Shadow IT introduces unseen third-party risks that traditional governance often misses. In this post, Fortian GRC consultant Riva Antonio explores how unsanctioned tools quietly expand your vendor ecosystem and offers a practical maturity model to help organisations regain visibility and control.

Read more →
Threat Update
Phil Roberts & Giacomo Marchese 16 October 2025

The Indicator You Didn’t Backtest: Fake TradingView Videos Driving Infostealers

Fortian’s Security Operations Centre has uncovered a new campaign using fake “AI TradingView indicator” YouTube tutorials to distribute multi-stage infostealers. This blog post breaks down each stage of the infection chain, detection opportunities, and defences to help organisations counter similar AI-themed social engineering attacks.

Read more →
Threat Update
Phil Roberts & Giacomo Marchese 7 October 2025

The Great Wall of Nope: Why firewall logs are not enough

As part of Fortian’s Cyber Security Awareness Month blog series, SOC analysts Giacomo Marchese and Phil Roberts examine why relying solely on firewall logs leaves critical blind spots in modern threat detection. Their post explores how host, identity, and cloud telemetry provide the context needed for faster, more accurate investigations.

Read more →
Monthly Update
Barry Schramm, Marcus Wong & Jason Wood 3 October 2025

Cybersecurity Awareness Month

September’s cyber landscape revealed a surge in supply chain and open-source attacks, alongside law enforcement action against major criminal groups. From Scattered Spider arrests to the Shai-Hulud NPM worm and rising third-party breaches in Australia, the month underscored how attackers are exploiting the trust that underpins modern digital ecosystems.

Read more →
Monthly Update
Allan Grant 30 September 2025

September Cybersecurity Update

September’s cyber landscape revealed a surge in supply chain and open-source attacks, alongside law enforcement action against major criminal groups. From Scattered Spider arrests to the Shai-Hulud NPM worm and rising third-party breaches in Australia, the month underscored how attackers are exploiting the trust that underpins modern digital ecosystems.

Read more →
Monthly Update
Ben Watson & Allan Grant 1 September 2025

August Cybersecurity Update

August saw state-backed hackers and cyber gangs dominate headlines. China stayed central, targeting telecoms, hosting, and diplomats, while a joint advisory from multiple agencies warned of systemic Chinese espionage. In Australia, the OAIC sued Optus over the 2022 breach, ASIO put cyber-espionage costs at $3b, and multiple Australian organisations faced incidents.

Read more →
Life at Fortian
Carl Flottmann 19 August 2025

2025 Fortian Winter Internship

In June and July 2025, Fortian welcomed Carl Flotmann as our winter intern. In this blog post, Carl writes about his internship project, which involved designing an on-demand log analysis solution using Azure Data Explorer, Logstash, and Terraform to support advanced SOC investigations.

Read more →
Life at Fortian
Barry Schramm, Marcus Wong & Jason Wood 11 August 2025

Defcon 33 Roundup

Fortian’s leadership team joined thousands of security professionals at Defcon 33 in Las Vegas to catch the latest in security research, exploits, and emerging threats. In this blog post, we share our standout talks and takeaways from the world’s biggest hacker conference.

Read more →
Monthly Update
Ben Watson & Allan Grant 1 August 2025

July Cybersecurity Update

In July 2025, there was a major Qantas breach, ASIC’s launched its latest cyber enforcement action, and the Australian Defence Force revealed plans for a national cyber reserve. Internationally, new UK cyber policies were introduced and cyberattacks exploited Microsoft SharePoint and exposed millions of McDonald’s records.

Read more →
Monthly Update
Ben Watson & Allan Grant 2 July 2025

June Cybersecurity Update

June 2025 saw geo-political tensions involving the U.S., Israel and Iran drive cyber attacks. The Trump Administration released a new cybersecurity executive order, while closer to home, Australian organisations faced into ongoing ransomware attacks and insider threats.

Read more →
Monthly Update
Ben Watson & Allan Grant 2 June 2025

May Cybersecurity Update

In May 2025, global and Australian cybersecurity landscapes saw heightened activity, with international crackdowns on malware networks, rising nation-state threats, and a sharp increase in data breaches. Legal developments around generative AI also highlighted ongoing concerns over data governance and regulatory risk.

Read more →
Monthly Update
Ben Watson & Allan Grant 2 May 2025

April Cybersecurity Update

In April, global cyber operations were threatened with disruption by U.S. funding cuts to the CVE and MITRE programs, while in Australia the superannuation, education, and health sectors faced breaches.

Read more →
Monthly Update
Ben Watson & Allan Grant 4 April 2025

March Cybersecurity Update

March saw the release of the US Intelligence Community’s 2025 Threat Assessment which reaffirmed China as the foremost cyber adversary to the US. Despite these threats, recent U.S. policy changes—like laying off cyber personnel—may weaken national and international cyber defences. Meanwhile a significant breach at Oracle exposed over 6 million records and in Australia, no new federal cybersecurity funding was announced in the 2025 Budget.

Read more →
Life at Fortian
Tristan Bunnage 18 March 2025

2025 Fortian Summer Internship

In January 2025, Fortian welcomed Tristan Bunnage as a summer intern. In this blog post, Tristan writes about his internship project, which involved using his experience and background in applied mathematics and statistics to perform a model-assisted threat hunt to detect password spraying attacks

Read more →
Monthly Update
Ben Watson 4 March 2025

February Cybersecurity Update

In February, Australia’s ban on Chinese AI model DeepSeek and cybersecurity firm Kaspersky highlights escalating concerns over data sovereignty and foreign technology risks, while the U.S. downplaying Russia as a cyber threat adds further complexity to the global security landscape.

Read more →
Monthly Update
Ben Watson 1 Feb 2025

January Cybersecurity Update

The transition to the Trump administration has led to cybersecurity policy shifts in the US. President Trump has swiftly reversed several of his predecessor’s initiatives. Meanwhile, in Australia, ransomware attacks on local councils and manufacturing firms highlight ongoing vulnerabilities, while the ACSC has issued warnings about emerging threats, including bulletproof hosting for cybercriminals and insecure operational technology being targeted by hackers.

Read more →
Advisory & Governance
Riva Antonio & Prashanth B.P. 17 January 2025

Business Email Compromise: Mobius v Inoteq - the Need for Vigilance in Invoice Payments

In this blog post, we examine a Western Australian court decision that underscores the importance of robust verification processes when it comes to invoice payments, including security learnings for Australian organisations.

Read more →
Monthly Update
Ben Watson 7 January 2025

December Cybersecurity Update

December 2024 saw significant cybersecurity incidents, including ransomware attacks on Australian organisations and global malware campaigns targeting banking apps. Overseas, tensions between the US and China continued to escalate over ongoing claims of Chinese hacking.

Read more →
Threat Update
James Fox 4 December 2024

Extending Defender XDR with Velociraptor

In this technical blog post, Fortian SOC analyst James Fox writes about how Fortian's Security Operations Team uses Velociraptor with Defender XDR to extend security operations investigations beyond the boundaries of SIEM telemetry.

Read more →
Monthly Update
Ben Watson 2 December 2024

November Cybersecurity Update

November's cybersecurity landscape highlights both progress and persistent challenges, from the passage of Australia's landmark Cyber Security Bill, joint international law enforcement initiatives to the uncovering of significant software vulnerabilities and high-profile breaches across critical sectors.

Read more →
Life at Fortian
Fortian 18 November 2024

CSA Conference 2024: Its not just about AI!

We were very excited to see our very own Phillip Roberts speaking at the Cloud Security Alliance Summit 2024 (It's not just about AI!), last week at the University of Wollongong, Sydney CBD campus.

Read more →
Monthly Update
Ben Watson 1 November 2024

October Cybersecurity Update

Welcome to Fortian's October monthly cybersecurity update! Every month, we aim to bring you news and valuable insights to key cyber incidents. This month, we cover the new Australian Cybersecurity Bill, cyber attacks on the US elections, along with developments in the domestic and international cyber threat landscapes, including key take-aways for Australian businesses.

Read more →
Life at Fortian
Koushik Anand Pirabu 1 October 2024

2024 Fortian Internship

During the 2024 winter break, Fortian welcomed Koushik Anand Pirabu as an intern. In this blog post, Koushik reflects on his internship experience working alongside Fortian's Security Operations Centre.

Read more →
Threat Update
Phillip Roberts & Giacomo Marchese 19 September 2024

Unmasking sophisticated marketplace Scams

In this blog post, Fortian analysts Philip and Giacomo delve into the intricacies of a recently discovered pernicious Facebook Marketplace scam campaign.

Read more →
Threat Update
James Fox 28 June 2024

Uncertain threats part #2: bayesian belief networks in security operations

In the second part of a three post series, Fortian security operations consultant James Fox blogs about how to leverage Bayesian Belief Networks to enhance threat detection and streamline triage processes.

Read more →
Advisory & Governance
Vince Hardy 30 May 2024

Securing the split: cybersecurity and demergers

Fortian security consultant Vince Hardy discusses corporate demergers from a cyber security perspective, including key considerations during the process.

Read more →
Threat Update
James Fox 11 April 2024

Uncertain threats part #1: strategies for handling uncertainty in identity investigations

James outlines strategies for reducing uncertainty in identity investigations, including relating anomalies to known threats, scoring anomalies based on how unusual they are, and performing low-impact responses to mitigate potential threats while minimizing business disruption.

Read more →
Threat Update
James Fox 24 Feb 2024

Building temporal correlations in threat hunts

An outline of several time-based techniques which can be used to strengthen uncertain threat hunting results.

Read more →
Threat Update
Phillip Roberts Oct 6, 2023

Threat actor bypassing location-based conditional access controls via dynamic AiTM infrastructure

Fortian discloses information regarding a novel adversary in the middle campaign that bypasses location-based conditional access controls via dynamically routed proxy servers

Read more →
Threat Update
Philip Roberts Sep 4, 2023

A credential harvester that's actually interesting!

Phillip and Sho came across something interesting when analysing a credential harvesting attack.

Read more →
Life at Fortian
Cooper Eldridge August 3, 2023

Fortian winter internship

Cooper gives an overview of his month at Fortian as part of our internship program

Read more →
Identity & Cloud
Reece Payne July 24, 2023

Return of Those Guys

Reece is a security consultant, pen tester, appsec guy, SOC supporter and perhaps most importantly one of Those Guys. In this post he provides a write-up of their activities against a retired HackTheBox (HTB) capture the flag called "Precious"

Read more →
Advisory & Governance
Prashanth BP July 17, 2023

A practical approach to application security

Prashanth covers some simple, practical steps to improving your application security.

Read more →
Advisory & Governance
Vince Hardy June 22, 2023

Privileged access management

Vince provides some guidance on implementing an effective privileged access management framework.

Read more →
Threat Update
Phillip Roberts May 24, 2023

Understanding the intricacies of AAD sign in logs to detect MFA fatigue attacks

Phillip explains how MFA events are represented in AAD sign-in logs, explores a few different approaches threat actors may take to exploit MFA and proposes a Sentinel query to help with detection.

Read more →
Threat Update
Phillip Roberts & Kumar Soorya August 26, 2022

Analysis of recent ransomware incident targeting users via fake Google Chrome updates

Phillip and Soorya from Fortian's SOC get into the finer details of some recent malware.

Read more →
Advisory & Governance
Andrew Bycroft February 25, 2022

Why the human element of cybercrime gets overlooked

Andrew examines the importance of the human element in cybersecurity.

Read more →
Advisory & Governance
Andrew Bycroft October 5, 2021

What is cyber security?

Andrew looks at the origins of one of the key terms in our industry, and questions whether it's really the one we should be using.

Read more →
Advisory & Governance
Prashanth B.P. August 23, 2021

Application threat modelling

Prashanth gives an overview of threat modelling and the application of a secure-by-design principle to software development.

Read more →
Identity & Cloud
Michael Pearn August 13, 2021

An introduction to Open ID Connect (OIDC)

Practical guidance for working with OIDC.

Read more →
Identity & Cloud
Michael Pearn July 29, 2021

Cloud to cloud user and group provisioning: a case study comparing Azure and Okta

Michael provides a real-world comparison of provisioning to Google Workspace using two of the most common cloud identity management platforms.

Read more →
Identity & Cloud
Jason Wood August 18, 2020

Quick and easy attack surface reduction - 2020 style

A couple of years down the track, Jason revisits attack surface reduction and explores a different approach using an AWS application load balancer and OIDC.

Read more →
Identity & Cloud
Adrian Bole June 06, 2020

Securing access to your Imperva cloud WAF with Okta

Having set up a basic WAF configuration, Adrian now steps through enabling SAML (and MFA) for WAF administration.

Read more →
Identity & Cloud
Adrian Bole May 11, 2020

Protecting your website with Imperva Cloud WAF

Adrian provides the first of two posts discussing the configuration of Imperva Cloud WAF.

Read more →
Identity & Cloud
Reece Payne November 23, 2019

DNS security

Reece talks about some of the security challenges with DNS.

Read more →
Life at Fortian
Jake Astles October 27, 2019

Fortian CyberCon 2019 challenge reflection (Part 2)

The second of Jake's posts on how he built the Fortian technical challenge for CyberCon 2019

Read more →
Life at Fortian
Jake Astles October 16, 2019

Fortian CyberCon 2019 challenge reflection (Part 1)

Jake gives us the first of two posts on how he built the Fortian technical challenge for CyberCon 2019

Read more →
Advisory & Governance
Chikonga Maimbo August 1, 2019

The value of security architecture

Chiko revisits the basics of security architecture: what is it, why do we do it and what are the benefits?

Read more →
Advisory & Governance
Simon Ellis July 18, 2019

Information wants to be free

Simon provides an update on some work we've been doing on Open Banking and the Consumer Data Right.

Read more →
Identity & Cloud
Reece Payne November 23, 2018

Don't trust those crafty users

Reece gets into the challenges of actually having users use your web application.

Read more →
Life at Fortian
Marcus Wong Oct 09, 2018

AISA CyberCon 2018

Marcus gives a bit of information about our attendance at this year's CyberCon.

Read more →
Identity & Cloud
Jason Wood June 29, 2018

Apache reverse proxy with SAML and Azure AD

Jason walks through setting up a quick and easy reverse proxy authenticating using SAML.

Read more →
Identity & Cloud
Reece Payne June 12, 2018

Getting logs out of Azure AD

Reece shows you how to get some interesting logging info out of Azure AD.

Read more →
Advisory & Governance
Marcus Wong May 11, 2018

Security, privacy and the 2018 budget

Marcus provides a brief update on information relevant to cyber security in the 2018 federal budget.

Read more →