24 July 2026
ASD advisory
zimbra mail servers under active attack.
A joint advisory on the group tracked as LAUNDRY BEAR exploiting Zimbra Collaboration Suite. Mail servers are a favourite target because they hold everything, and because plenty of businesses run one that nobody has logged into for maintenance in a year.
What this means for you
If you self host mail rather than using Microsoft 365 or Google Workspace, this is one to check today. Also worth asking whether you would even know if your mail server had been compromised, because access to email is access to password resets for everything else.
Read the ASD advisory
14 July 2026
ASD advisory
russian state actors, persistent and ongoing.
A joint advisory covering sustained malicious activity by Russian state sponsored actors. Related advisories over the same period cover phishing campaigns and the exploitation of network devices by the same category of actor.
What this means for you
State actors are not coming for your business directly. They are coming for the firewall, router or VPN appliance at your edge, because compromised small business infrastructure is useful cover for going after someone bigger. Your gear becomes their launchpad, and you find out when someone else's investigators come knocking.
Read the ASD advisory
9 July 2026
ASD alert · Critical
large scale campaign hitting website platforms.
ASD rated this one critical and flagged it specifically for small and medium businesses. Attackers are running a broad campaign against known vulnerabilities in web content management systems, the software behind most business websites.
What this means for you
If your site runs on WordPress, and most do, this is aimed squarely at you. Campaigns like this are automated and indiscriminate, so being small is not protection. An unpatched plugin nobody has thought about since the site was built is the usual way in, and the first sign is often a customer telling you your site is serving malware.
Read the ASD alert
27 May 2026
ASD guidance
using ai without opening a new front door.
ASD published guidance on where organisations can sensibly use AI to strengthen security, and the risks that come with it. Companion material this year covers agentic AI in cyber defence and the effect frontier models are having on the threat landscape.
What this means for you
Your staff are already pasting company information into AI tools, whether or not anyone approved it. Worth having a position on which tools are acceptable and what must never go into them, before it becomes a question your insurer or a customer asks you.
Read the ASD guidance
7 May 2026
ASD advisory
clickfix: when your own staff are the exploit.
Attackers are compromising WordPress sites to serve a social engineering trick known as ClickFix, which persuades the visitor to run a command themselves under the guise of fixing a problem. It has been observed targeting Australian networks and delivering information stealing malware.
What this means for you
No patch fixes this one, because nothing is being exploited except the person at the keyboard. The defence is monitoring that catches the malware after the click, and staff who know that no legitimate website ever asks you to paste something into a terminal or a Run box.
Read the ASD advisory
1 May 2026
ASD alert · Critical
the hosting control panel problem.
ASD reported active exploitation in Australia of a critical authentication bypass in cPanel and WebHost Manager, the control panel behind a very large share of small business web hosting. The flaw allowed unauthenticated remote attackers in, with patches released at the end of April.
What this means for you
Most businesses have no idea whether their hosting runs cPanel, because the website was built by someone else years ago. That is the point. Your attack surface includes systems you have never logged into and suppliers you have half forgotten, which is exactly what continuous scanning is for.
Read the ASD alert
24 April 2026
ASD advisory
your old router may already be working for someone else.
An advisory on China-nexus actors building covert networks out of compromised devices, and the shift in tactics behind it. The devices being recruited are ordinary ones: routers, cameras, network appliances sitting in ordinary businesses.
What this means for you
The forgotten device is the risk. An out of support router in a back office, a camera system installed by a contractor five years ago, anything nobody has patched because nobody remembers it exists. Asset discovery is not paperwork, it is the only way you find these.
Read the ASD advisory
6 March 2026
ASD advisory
inc ransom is operating in australian networks.
A joint advisory on the INC Ransom group and its affiliate network, and the threat they pose to networks in Australia, New Zealand and the Pacific islands.
What this means for you
Affiliate models do not select targets by value, they select by reachability. Unpatched remote access and accounts without multi factor authentication are the usual entry. If you cannot say today which of your systems are reachable from the internet, that is the gap to close first.
Read the ASD advisory
12 February 2026
ASD report
the essential eight bar keeps moving.
The 2025 Commonwealth Cyber Security Posture Report sets out how federal agencies are tracking against the Essential Eight. Worth reading even if you are nowhere near government, because agency expectations flow downhill into supplier contracts.
What this means for you
If you sell to government, or to anyone who does, Essential Eight maturity is heading for your contracts whether you went looking for it or not. Knowing your current level before a customer asks beats working it out mid tender.
Read the ASD report
Source material published by the Australian Signals Directorate at cyber.gov.au, licensed under Creative Commons Attribution 4.0. The summaries and commentary on this page are ours. For the official wording, technical detail and indicators, always go to the ASD advisory itself.