Fortian has observed a sharp rise in campaigns abusing legitimate application hosting platforms - Vercel, Cloudflare Workers and Netlify - to stage credential harvesting pages and malware loaders. The platforms aren't compromised; attackers just deploy from free-tier accounts and inherit the clean domain reputation that URL filters and block lists trust. Three July campaigns are covered: an AI-generated JavaScript loader delivering LogMeIn RMM behind a fake ATO document, a UPS impersonation dropping ScreenConnect via a VBS "Flash updater", and indiscriminate ATO credential harvesting behind fake myGov notifications. Includes KQL hunting queries and indicators of compromise.
Read more →OpenAI and Anthropic both disclosed that their own AI models escaped evaluation environments and compromised real production systems within ten days of each other, while researchers documented the first ransomware operation run start to finish by an LLM. Scattered Spider members were jailed over the Transport for London attack, ShinyHunters claimed Ernst & Young, and Russian intelligence was found hijacking IP cameras across Europe for military reconnaissance. In Australia, AML/CTF Tranche 2 brought roughly 90,000 professional services firms under the Privacy Act, and breaches hit Partnered Health, Origin Energy and several smaller operators.
Read more →A technical breakdown of a credential harvesting campaign targeting ASX-listed organisations. The kit is published to IPFS and addressed by content hash, so there is no single host to action. It builds a convincing impersonation of any target organisation at runtime from the victim's own email domain using three free public APIs, and exfiltrates harvested credentials straight into the operator's Telegram client. Includes anti-analysis techniques, attribution artefacts, detection opportunities and indicators of compromise.
Read more →A synthesis of the significant global and Australian cyber events of April, May and June 2026. The quarter was defined by attacks on trust: frontier AI turned both weapon and regulatory flashpoint, signed npm packages shipped malware, ShinyHunters and The Com dominated the identity breach headlines, and nation-state actors shifted toward pre-positioning in critical infrastructure. Australian regulators accelerated hard, with an APRA letter on AI risk, the retirement of the Essential Eight and the Horizon 2 phase of the national strategy.
Read more →Fortian's machine-learning approach to catching large multi-accounting campaigns that randomise usernames, user agents and residential IPs to slip past conventional detection rules - using bisecting k-means clustering over engineered features to surface a real campaign that had evaded every existing rule.
Read more →June was defined by AI on both sides of the fight: the Five Eyes warned boards it is a present business risk, the FBI dismantled a China-based AI-powered phishing service blamed for $1.9 billion in losses, and the US forced Anthropic and OpenAI to restrict their most capable models. Identity stayed the weakest link, with ShinyHunters exploiting an Oracle PeopleSoft zero-day against 100+ organisations and FortiBleed compromising 75,000 devices. Australia moved to retire the Essential Eight, updated the ISM, and ordered Amex to overhaul access controls after an insider breach.
Read more →Casey Wilfling's experience interning with Fortian's Managed Security Services team in summer 2026, covering ransomware attack analysis with Cyber Kill Chain mapping, custom Microsoft Sentinel detection engineering, and building an automated IoC extraction and STIX 2.1 conversion pipeline for multi-tenant threat intelligence distribution via Azure Logic Apps and OpenCTI.
Read more →May was defined by the TanStack and AntV npm supply chain compromises, ShinyHunters' extortion of Instructure exposing 275 million records (including Australian universities and Queensland schools), and CISA shifting US critical infrastructure policy onto a wartime footing. Australia formally established its Cyber Incident Review Board, the Federal Budget signalled cyber spending in station-keeping mode, and ransomware groups hit hospitality, jewellery, construction, and IT services domestically.
Read more →Join Fortian's Jake Marchese for a webinar on 16 June 2026 covering how AiTM phishing attacks bypass MFA by stealing session tokens, with an attack demonstration and detection strategies using Microsoft Sentinel.
Read more →Fortian is proud to sponsor the Technology for Social Justice Conference, taking place 6 to 8 May 2026 at the Telstra Customer Insight Centre in Melbourne. Organised by Infoxchange, the conference brings together executives, IT leaders, and change-makers from across the for-purpose sector.
Read more →April was dominated by three converging storylines: Iranian escalation against US industrial infrastructure, North Korea's patient and precisely executed supply chain operations, and Anthropic's Claude Mythos Preview forcing a sector-wide conversation about AI-driven vulnerability discovery. Supply chain compromise ran through almost every major incident.
Read more →Geopolitics and cybersecurity collided in March 2026 as the US-Israeli campaign against Iran opened a new chapter in state-linked cyber conflict - one that reached commercial cloud infrastructure, senior US officials, and organisations with no connection to the conflict whatsoever. Read on for Fortian's analysis of the month's key developments.
Read more →Cyber threats struck close to home in February 2026, with a Sydney fintech exposing the driver's licences of nearly a quarter of a million Australians, a Victorian poultry processor taken offline by attackers, and 94 Australian organisations confirmed to have paid ransomware groups since mandatory disclosure commenced. Globally, Russia targeted Poland's power grid and the Winter Olympics, a Chinese state-sponsored group hijacked a trusted software update mechanism, and the US withdrawal from key international cyber organisations left international partners with fewer Western-aligned options.
Read more →Fortian’s annual Security Operations Centre report highlights the most significant cyber threat trends affecting Australian organisations in 2025, based on real incidents investigated by our SOC. This year’s findings reveal a decisive shift toward identity abuse, SaaS-driven data theft, browser-native attacks, and defence evasion through trusted infrastructure. Drawing on real-world attacker behaviour rather than theory, the report examines how these threats are playing out in practice and the defensive measures organisations should prioritise as they move into 2026.
Read more →January 2026 highlighted how closely cyber activity continues to track broader political, economic and social pressures. State-linked cyber operations tied to conflict in Europe and domestic unrest in Iran remained prominent, while cybercriminal groups continued to demonstrate how effective social engineering and identity abuse have become, enabling large-scale data theft without the need for sophisticated technical exploits.
Read more →November saw steady activity across Australia’s cyber landscape, including new government sanctions, emerging AI-enabled threats and several notable breaches affecting local organisations. This month’s update highlights how attackers continue to target supply chains, identity systems and high-trust service platforms.
Read more →In October, the U.S. shutdown hampered CISA’s operations, while major incidents unfolded across F5, Qantas, and ReadyTech. On a positive note, the month also brought new policy initiatives and awareness efforts, including Cyber Security Awareness Month, the release of the ACSC’s Annual Cyber Threat Report, and the appointment of a new Ambassador for Cyber Affairs and Critical Technology.
Read more →Shadow IT introduces unseen third-party risks that traditional governance often misses. In this post, Fortian GRC consultant Riva Antonio explores how unsanctioned tools quietly expand your vendor ecosystem and offers a practical maturity model to help organisations regain visibility and control.
Read more →Fortian’s Security Operations Centre has uncovered a new campaign using fake “AI TradingView indicator” YouTube tutorials to distribute multi-stage infostealers. This blog post breaks down each stage of the infection chain, detection opportunities, and defences to help organisations counter similar AI-themed social engineering attacks.
Read more →As part of Fortian’s Cyber Security Awareness Month blog series, SOC analysts Giacomo Marchese and Phil Roberts examine why relying solely on firewall logs leaves critical blind spots in modern threat detection. Their post explores how host, identity, and cloud telemetry provide the context needed for faster, more accurate investigations.
Read more →September’s cyber landscape revealed a surge in supply chain and open-source attacks, alongside law enforcement action against major criminal groups. From Scattered Spider arrests to the Shai-Hulud NPM worm and rising third-party breaches in Australia, the month underscored how attackers are exploiting the trust that underpins modern digital ecosystems.
Read more →September’s cyber landscape revealed a surge in supply chain and open-source attacks, alongside law enforcement action against major criminal groups. From Scattered Spider arrests to the Shai-Hulud NPM worm and rising third-party breaches in Australia, the month underscored how attackers are exploiting the trust that underpins modern digital ecosystems.
Read more →August saw state-backed hackers and cyber gangs dominate headlines. China stayed central, targeting telecoms, hosting, and diplomats, while a joint advisory from multiple agencies warned of systemic Chinese espionage. In Australia, the OAIC sued Optus over the 2022 breach, ASIO put cyber-espionage costs at $3b, and multiple Australian organisations faced incidents.
Read more →In June and July 2025, Fortian welcomed Carl Flotmann as our winter intern. In this blog post, Carl writes about his internship project, which involved designing an on-demand log analysis solution using Azure Data Explorer, Logstash, and Terraform to support advanced SOC investigations.
Read more →Fortian’s leadership team joined thousands of security professionals at Defcon 33 in Las Vegas to catch the latest in security research, exploits, and emerging threats. In this blog post, we share our standout talks and takeaways from the world’s biggest hacker conference.
Read more →In July 2025, there was a major Qantas breach, ASIC’s launched its latest cyber enforcement action, and the Australian Defence Force revealed plans for a national cyber reserve. Internationally, new UK cyber policies were introduced and cyberattacks exploited Microsoft SharePoint and exposed millions of McDonald’s records.
Read more →June 2025 saw geo-political tensions involving the U.S., Israel and Iran drive cyber attacks. The Trump Administration released a new cybersecurity executive order, while closer to home, Australian organisations faced into ongoing ransomware attacks and insider threats.
Read more →In May 2025, global and Australian cybersecurity landscapes saw heightened activity, with international crackdowns on malware networks, rising nation-state threats, and a sharp increase in data breaches. Legal developments around generative AI also highlighted ongoing concerns over data governance and regulatory risk.
Read more →In April, global cyber operations were threatened with disruption by U.S. funding cuts to the CVE and MITRE programs, while in Australia the superannuation, education, and health sectors faced breaches.
Read more →March saw the release of the US Intelligence Community’s 2025 Threat Assessment which reaffirmed China as the foremost cyber adversary to the US. Despite these threats, recent U.S. policy changes—like laying off cyber personnel—may weaken national and international cyber defences. Meanwhile a significant breach at Oracle exposed over 6 million records and in Australia, no new federal cybersecurity funding was announced in the 2025 Budget.
Read more →In January 2025, Fortian welcomed Tristan Bunnage as a summer intern. In this blog post, Tristan writes about his internship project, which involved using his experience and background in applied mathematics and statistics to perform a model-assisted threat hunt to detect password spraying attacks
Read more →In February, Australia’s ban on Chinese AI model DeepSeek and cybersecurity firm Kaspersky highlights escalating concerns over data sovereignty and foreign technology risks, while the U.S. downplaying Russia as a cyber threat adds further complexity to the global security landscape.
Read more →The transition to the Trump administration has led to cybersecurity policy shifts in the US. President Trump has swiftly reversed several of his predecessor’s initiatives. Meanwhile, in Australia, ransomware attacks on local councils and manufacturing firms highlight ongoing vulnerabilities, while the ACSC has issued warnings about emerging threats, including bulletproof hosting for cybercriminals and insecure operational technology being targeted by hackers.
Read more →In this blog post, we examine a Western Australian court decision that underscores the importance of robust verification processes when it comes to invoice payments, including security learnings for Australian organisations.
Read more →December 2024 saw significant cybersecurity incidents, including ransomware attacks on Australian organisations and global malware campaigns targeting banking apps. Overseas, tensions between the US and China continued to escalate over ongoing claims of Chinese hacking.
Read more →In this technical blog post, Fortian SOC analyst James Fox writes about how Fortian's Security Operations Team uses Velociraptor with Defender XDR to extend security operations investigations beyond the boundaries of SIEM telemetry.
Read more →November's cybersecurity landscape highlights both progress and persistent challenges, from the passage of Australia's landmark Cyber Security Bill, joint international law enforcement initiatives to the uncovering of significant software vulnerabilities and high-profile breaches across critical sectors.
Read more →We were very excited to see our very own Phillip Roberts speaking at the Cloud Security Alliance Summit 2024 (It's not just about AI!), last week at the University of Wollongong, Sydney CBD campus.
Read more →Welcome to Fortian's October monthly cybersecurity update! Every month, we aim to bring you news and valuable insights to key cyber incidents. This month, we cover the new Australian Cybersecurity Bill, cyber attacks on the US elections, along with developments in the domestic and international cyber threat landscapes, including key take-aways for Australian businesses.
Read more →During the 2024 winter break, Fortian welcomed Koushik Anand Pirabu as an intern. In this blog post, Koushik reflects on his internship experience working alongside Fortian's Security Operations Centre.
Read more →In this blog post, Fortian analysts Philip and Giacomo delve into the intricacies of a recently discovered pernicious Facebook Marketplace scam campaign.
Read more →In the second part of a three post series, Fortian security operations consultant James Fox blogs about how to leverage Bayesian Belief Networks to enhance threat detection and streamline triage processes.
Read more →Fortian security consultant Vince Hardy discusses corporate demergers from a cyber security perspective, including key considerations during the process.
Read more →James outlines strategies for reducing uncertainty in identity investigations, including relating anomalies to known threats, scoring anomalies based on how unusual they are, and performing low-impact responses to mitigate potential threats while minimizing business disruption.
Read more →An outline of several time-based techniques which can be used to strengthen uncertain threat hunting results.
Read more →Fortian discloses information regarding a novel adversary in the middle campaign that bypasses location-based conditional access controls via dynamically routed proxy servers
Read more →Phillip and Sho came across something interesting when analysing a credential harvesting attack.
Read more →Cooper gives an overview of his month at Fortian as part of our internship program
Read more →Reece is a security consultant, pen tester, appsec guy, SOC supporter and perhaps most importantly one of Those Guys. In this post he provides a write-up of their activities against a retired HackTheBox (HTB) capture the flag called "Precious"
Read more →Prashanth covers some simple, practical steps to improving your application security.
Read more →Vince provides some guidance on implementing an effective privileged access management framework.
Read more →Phillip explains how MFA events are represented in AAD sign-in logs, explores a few different approaches threat actors may take to exploit MFA and proposes a Sentinel query to help with detection.
Read more →Phillip and Soorya from Fortian's SOC get into the finer details of some recent malware.
Read more →Andrew examines the importance of the human element in cybersecurity.
Read more →Andrew looks at the origins of one of the key terms in our industry, and questions whether it's really the one we should be using.
Read more →Prashanth gives an overview of threat modelling and the application of a secure-by-design principle to software development.
Read more →Practical guidance for working with OIDC.
Read more →Michael provides a real-world comparison of provisioning to Google Workspace using two of the most common cloud identity management platforms.
Read more →A couple of years down the track, Jason revisits attack surface reduction and explores a different approach using an AWS application load balancer and OIDC.
Read more →Having set up a basic WAF configuration, Adrian now steps through enabling SAML (and MFA) for WAF administration.
Read more →Adrian provides the first of two posts discussing the configuration of Imperva Cloud WAF.
Read more →Reece talks about some of the security challenges with DNS.
Read more →The second of Jake's posts on how he built the Fortian technical challenge for CyberCon 2019
Read more →Jake gives us the first of two posts on how he built the Fortian technical challenge for CyberCon 2019
Read more →Chiko revisits the basics of security architecture: what is it, why do we do it and what are the benefits?
Read more →Simon provides an update on some work we've been doing on Open Banking and the Consumer Data Right.
Read more →Reece gets into the challenges of actually having users use your web application.
Read more →Marcus gives a bit of information about our attendance at this year's CyberCon.
Read more →Jason walks through setting up a quick and easy reverse proxy authenticating using SAML.
Read more →Reece shows you how to get some interesting logging info out of Azure AD.
Read more →Marcus provides a brief update on information relevant to cyber security in the 2018 federal budget.
Read more →No posts in this category yet.