Category: Security Alerts

HomeSecurity Alerts

Who Owns the Risk of Unmapped Factory Floor Networks?

Ask a CISO for an inventory of corporate laptops and the answer may be available within minutes. Ask the same organisation to account for every industrial controller, undocumented switch, legacy gateway and temporary wireless device operating across a factory floor,...

Continue Reading  

Third-Party Risk Management: Lessons from the Origin Energy Data Incident

The moment customer data moves beyond your immediate operational environment, governance becomes more complex. Australian and New Zealand organisations routinely rely on external providers for customer service, technology operations, cloud platforms, and specialised business processes. Those arrangements may improve efficiency,...

Continue Reading  

The Autonomous Blind Spot: Governing AI Agents in Production Environments

As artificial intelligence moves from generating content to taking action, the governance challenge changes with it. Agentic AI systems can reason across multiple steps, interact with external tools and APIs, and execute actions with reduced human involvement. Organisations are therefore...

Continue Reading  

Vulnerability Summary Reports by Cybernetic GI – July 2025

Cybernetic GI Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD). The Department of Homeland Security (DHS) National Cybersecurity and Communications Integration Center (NCCIC) /...

Continue Reading  

Log4j vulnerability: what should boards be asking?

Background The Log4Shell critical vulnerability in the widely used logging tool Log4j has caused concern beyond the cyber security community. This is because Log4j - rather than being a single piece of software - is a software component that’s used by millions of computers worldwide running online services....

Continue Reading  

Apache Log4j Vulnerability Guidance

Background Apache Log4j2 is a ubiquitous library used by millions for Java applications; the library is part of the Apache Software Foundation’s Apache Logging Services project. The vulnerability CVE-2021-44228, disclosed on December 9, 2021, allows for remote code execution against...

Continue Reading  

Alert (AA21-291A) BlackMatter Ransomware : The Dark Side Returns

Background BlackMatter is a new ransomware threat discovered at the end of July 2021. BlackMatter is ransomware-as-a-service (Raas) tool that allows  the ransomware's developers to profit from cybercriminal affiliates (i.e., BlackMatter actors) who deploy it against victims. This malware started...

Continue Reading  

FoggyWeb: SolarWinds Hackers Access Microsoft AD Servers

Background The Microsoft Threat Intelligence Center (MSTIC) has released information on the uncovering of a widespread malicious email campaign undertaken by the activity group that Microsoft tracks as NOBELIUM. Nobelium, which operates from Russia, is the name given to the threat actor behind...

Continue Reading  

CWE Top 25 Most Dangerous Software Weaknesses, 2021

Cybernetic GI Security Bulletin provides a summary of CWE Top 25 Most Dangerous Software Weaknesses in 2021. Entries may include additional information provided by organizations. This data may include identifying information, values, definitions, and related links. The patch information is...

Continue Reading  

Kaseya Ransomware Attack – 1

In 2019, Cybernetic Global Intelligence had warned about REvil. Refer to our previous blog on GandCrab ransomware: Is it back under a new REvil guise? The fourth of July celebrations in America this year were slightly different for around 1500 organizations...

Continue Reading