Daily brief at 7am Melbourne. Unsubscribe any time.

Friday 26 June 2026

Pre-Positioned and Patient: Nation-State Actors Are Already Inside Australian Critical Infrastructure

Nation-state hackers have already burrowed into Australian critical infrastructure — and they're waiting for the right moment to flip the switch.

Lead story

Pre-Positioned and Patient: Nation-State Actors Are Already Inside Australian Critical Infrastructure

Australian spy agencies have confirmed what defenders have long feared: nation-state actors have successfully compromised critical infrastructure networks with the explicit goal of being able to "cripple" them at a moment of geopolitical choosing. The disclosure, reported by The Register, comes with an unusually specific detail — Australian intelligence services had to contact foreign counterparts to warn them that one adversary operation had already been discovered, effectively burning the intrusion before it could be used.

That detail matters. It suggests Australian signals intelligence identified the operation early enough to neutralise it diplomatically, rather than waiting for an incident response call. It's a rare example of offensive intelligence being used to defuse a threat rather than simply attribute it after the fact.

The phrase "cripple it at a time of their choosing" is the key framing here. This isn't espionage for intelligence gathering. It's pre-positioning — planting persistent access inside power, water, communications, or transport systems so that when diplomatic or military tensions spike, the attacker already has a loaded weapon inside the perimeter. Think of it as the cyber equivalent of pre-deploying forces close to a border.

Australia is not alone in facing this. The US Cybersecurity and Infrastructure Security Agency (CISA) has spent the last two years warning about exactly this pattern from Chinese-linked group Volt Typhoon, which embedded itself inside US critical infrastructure networks — not to steal data, but to sit and wait. The Five Eyes alliance issued a joint advisory on this very threat pattern last year. What's new here is an Australian official confirmation that it isn't theoretical.

For Australian organisations operating under the Security of Critical Infrastructure (SOCI) Act, this is the scenario the legislation was designed to address. The 2022 amendments significantly expanded SOCI's scope to cover 11 sectors — from electricity and water to data storage and higher education — and introduced mandatory incident reporting and risk management obligations. The question worth asking now is whether those obligations are producing the kind of network visibility needed to find pre-positioned implants, not just respond to active attacks.

Finding this kind of access requires more than a good EDR deployment. Pre-positioned threats tend to be low-and-slow — minimal command-and-control traffic, careful use of living-off-the-land techniques, long dwell times. Detection typically requires network-level telemetry and threat hunting, not just alert triage.

The Home Affairs secretary's comments, published separately in The Mandarin, offer a glimpse at how the government is thinking about this: emphasis on clarity of purpose, fast-moving teams, and cross-agency coordination. That's the right instinct. But coordination frameworks only work if the underlying visibility exists in the first place.

Watch for whether this disclosure triggers any updated guidance from the Australian Signals Directorate (ASD) or new SOCI compliance posture expectations from the Department of Home Affairs. Given the current regulatory environment and the recent overhaul of the Essential Eight, the timing of this disclosure feels less like a coincidence and more like groundwork for something.

Also today

Cisco SD-WAN Zero-Day Was Being Exploited Two Months Before the Patch Dropped

Mandiant has detailed how threat actors exploited CVE-2026-20245 in Cisco Catalyst SD-WAN — rated CVSS 7.8 — for roughly two months before Cisco publicly disclosed and patched it. The attackers used rogue peering to connect to victim SD-WAN devices and establish root-level access, creating persistent admin accounts. It's the seventh Cisco SD-WAN vulnerability exploited in 2026 alone, which at this point stops looking like a coincidence and starts looking like a targeting pattern. Cisco SD-WAN is widely deployed by Australian enterprises and government agencies, making this a relevant patching priority regardless of whether a local compromise has been identified.

SecurityWeek

"Gaslight" macOS Malware Is Designed to Fool Your AI Analysis Tools

A newly discovered Rust-based macOS implant and infostealer — dubbed Gaslight — embeds prompt injection strings and fake debugging output directly inside the binary. The goal isn't to evade traditional antivirus; it's to confuse AI-assisted malware analysis platforms into aborting or mischaracterising their analysis. It's a clever second-order attack: the malware doesn't just hide from defenders, it actively tries to manipulate the tools defenders are increasingly relying on. The technique represents a meaningful evolution in evasion tradecraft, and will likely be adopted more broadly once the approach proves reliable in the wild.

The Hacker News

Shopify's Order-Tracking App Weaponised for Callback Phishing

Threat actors are injecting fake purchase receipts into the order histories of Shopify's "Shop" app, tricking users into calling fraudulent support numbers. From there, victims are socially engineered into handing over credentials or installing remote access tools. It's a callback phishing variant that exploits the inherent trust users have in post-purchase tracking notifications — the kind of message people open immediately. Shopify has a large merchant and customer base in Australia, and the attack is notable because it abuses a legitimate, trusted app channel rather than a spoofed email, making it harder to catch with standard email filtering.

Bleeping Computer

Popular Chrome Ad Blocker with 10 Million Users Has Hidden Script Injection Capability

Security researchers at Island found that "Adblock for YouTube," a Chrome extension with over 10 million installs and a Featured badge from Google, contains the ability to execute arbitrary JavaScript on any page a user visits. The capability appears dormant — it hasn't been observed being triggered — but its presence in a widely trusted, Google-badged extension is a significant supply chain risk. Users have no way to know it's there without source analysis. Australian organisations that manage Chrome deployments via policy should audit installed extensions, particularly those with broad permissions granted on the basis of a Featured badge.

The Hacker News

Anthropic Says Alibaba Used 25,000 Accounts to Clone Claude in Massive Distillation Attack

Anthropic has filed legal action alleging that Alibaba systematically extracted Claude's capabilities through what it's calling the largest model distillation attack ever attempted against the company. The alleged operation involved 25,000 fake accounts generating 28.8 million exchanges to mine Claude's outputs for use in training a competing model. Anthropic is seeking sanctions and framing the action as a deliberate defiance of both its terms of service and US export restrictions. It's a significant escalation in the IP and competitive intelligence dimensions of the AI race — and raises questions about what adequate terms-of-service enforcement actually looks like at scale.

Ars Technica

A German Court Just Made Google Liable for Its AI Search Summaries

A German court has ruled that Google is legally responsible for the accuracy of AI-generated summaries in its search results. The court rejected Google's defences — including arguments that users know AI can be wrong and can verify claims themselves — finding that the summaries are an expression of Google's own business activities. Schneier on Security frames this as the latest chapter in a decades-long battle over internet publishing liability, with AI now forcing a fundamental re-examination of platform versus publisher status. Australia's online safety and consumer protection frameworks could face similar pressure as AI-generated content becomes embedded in mainstream products.

Schneier on Security

New Research Explains Exactly Why LLMs Keep Falling for Prompt Injection

A research paper highlighted by Bruce Schneier finds that large language models learn to recognise the style and texture of different instruction blocks — not just the structural tags delineating them. This means role-based security architecture (system prompt vs. user prompt vs. tool output) doesn't actually survive into the model's internal representations. In plain terms: the thing most AI security architectures rely on to separate trusted instructions from untrusted user input doesn't work the way we assumed. The finding has direct implications for anyone building agentic AI systems where prompt injection is a live threat vector.

Schneier on Security

NAB's Security Operations Rethink: Fewer Alert-Jockeys, More Data Engineers

National Australia Bank is reshaping its security operations function by prioritising hires with data engineering and software development skills over traditional security analyst profiles. The shift reflects a broader industry trend toward treating security operations as a data problem — building pipelines, automating detection logic, and moving away from manual alert triage. NAB's approach signals that major Australian financial institutions are investing in long-term SecOps capability rather than headcount-based scaling, a model that could influence how other APRA-regulated entities think about their own security workforce strategy.

iTnews

Microsoft Quietly Extends Free Windows 10 Security Updates to October 2027

Microsoft has extended its free Extended Security Updates programme for Windows 10 consumers by an additional year, pushing the deadline to October 2027. The move is quiet — no major announcement, just updated documentation — and affects the roughly quarter of PCs still running Windows 10. For IT administrators, this provides breathing room but shouldn't be treated as an invitation to delay migration planning. The extension applies to the consumer ESU programme; enterprise ESU pricing arrangements remain separate. Australian government entities operating Windows 10 fleets under ASD guidance should check whether updated timelines affect their current refresh plans.

Bleeping Computer

IBM Claims World's First Sub-1 Nanometre Chip Technology

IBM has announced what it claims is the world's first sub-1 nanometre transistor technology, using a "nanostack" design that stacks atomically thin semiconductor materials vertically rather than shrinking traditional silicon. The announcement is a research milestone rather than an imminent product — commercial production at this node is years away — but it signals that the theoretical limits of Moore's Law have more runway than many expected. For AI infrastructure planners, the long-term implication is continued performance-per-watt improvements in the chips that will underpin the next generation of data centre compute.

Ars Technica

Apple and Xbox Raise Prices as the RAM Crisis Goes Mainstream

Apple has raised prices across its MacBook and iPad lines — in some cases by hundreds of dollars — blaming surging memory chip costs. Microsoft followed within hours, announcing Xbox console price increases for August citing storage and memory components now costing more than 2.5 times previous levels. The RAM shortage, dubbed "RAMageddon" in some corners, is cascading across consumer hardware in a way that affects anyone buying or refreshing devices. For Australian IT procurement teams mid-cycle, this is a meaningful signal to bring forward purchase decisions or lock in current pricing before further increases arrive.

Ars Technica

Sources consulted