---
title: "The New Battleground: Identity, AI and Trusted Software"
description: Cybercriminals are evolving tactics, exploiting trusted technologies and identities. Discover essential strategies for organisations to enhance cybersecurity resilience.
image: https://digitalfrontierpartners.com.au/hubfs/AI-Generated%20Media/Images/Cybersecurity%20Brainstorming%20Session%20in%20Modern%20Office.png
---

[Skip to content](https://digitalfrontierpartners.com.au/news/the-new-battleground-identity-ai-and-trusted-software#main-content)

[![](https://digitalfrontierpartners.com.au/hs-fs/hubfs/DFP-Logo.webp?width=1200&height=342&name=DFP-Logo.webp)](https://www.digitalfrontierpartners.com.au/)

- [Services](https://digitalfrontierpartners.com.au/news/the-new-battleground-identity-ai-and-trusted-software#products)
  
  Show submenu for Services 
  
    - [Cybersecurity](https://digitalfrontierpartners.com.au/cybersecurity-services-24/7-threat-monitoring-and-response-dfp)
    - [Due Diligence](https://digitalfrontierpartners.com.au/technology-due-diligence-product-assessment-digital-frontier-partners)
    - [Enterprise AI](https://digitalfrontierpartners.com.au/enterprise-ai)
    - [Technology Advisory](https://digitalfrontierpartners.com.au/technology-advisory-services-digital-frontier-partners)
    - [Workforce Optimisation](https://digitalfrontierpartners.com.au/workforce-optimisation-ai-driven-cost-control-and-performance-dfp)
- Resources
  
  Show submenu for Resources 
  
    - [News](https://digitalfrontierpartners.com.au/news/tag/news)
    - [Case Studies](https://digitalfrontierpartners.com.au/news/tag/case-study)
    - [Research](https://digitalfrontierpartners.com.au/news/tag/research)
    - [Weekly Cyber Reports](https://digitalfrontierpartners.com.au/news/tag/weekly-cyber-reports)
- [About](https://digitalfrontierpartners.com.au/news/the-new-battleground-identity-ai-and-trusted-software#about)
  
  Show submenu for About 
  
    - [About Us](https://digitalfrontierpartners.com.au/about)
    - [Contact Us](https://digitalfrontierpartners.com.au/contact)

Open main navigation

Close main navigation

- [Services](https://digitalfrontierpartners.com.au/news/the-new-battleground-identity-ai-and-trusted-software#products)
  
  Show submenu for Services 
  
    - [Cybersecurity](https://digitalfrontierpartners.com.au/cybersecurity-services-24/7-threat-monitoring-and-response-dfp)
    - [Due Diligence](https://digitalfrontierpartners.com.au/technology-due-diligence-product-assessment-digital-frontier-partners)
    - [Enterprise AI](https://digitalfrontierpartners.com.au/enterprise-ai)
    - [Technology Advisory](https://digitalfrontierpartners.com.au/technology-advisory-services-digital-frontier-partners)
    - [Workforce Optimisation](https://digitalfrontierpartners.com.au/workforce-optimisation-ai-driven-cost-control-and-performance-dfp)
- Resources
  
  Show submenu for Resources 
  
    - [News](https://digitalfrontierpartners.com.au/news/tag/news)
    - [Case Studies](https://digitalfrontierpartners.com.au/news/tag/case-study)
    - [Research](https://digitalfrontierpartners.com.au/news/tag/research)
    - [Weekly Cyber Reports](https://digitalfrontierpartners.com.au/news/tag/weekly-cyber-reports)
- [About](https://digitalfrontierpartners.com.au/news/the-new-battleground-identity-ai-and-trusted-software#about)
  
  Show submenu for About 
  
    - [About Us](https://digitalfrontierpartners.com.au/about)
    - [Contact Us](https://digitalfrontierpartners.com.au/contact)
- [Contact us](https://digitalfrontierpartners.com.au/contact)

[Contact us](https://digitalfrontierpartners.com.au/contact)

 12 August 2026, 2:05:24 pm AEST

# The New Battleground: Identity, AI and Trusted Software

![Picture of Digital Frontier Partners](https://digitalfrontierpartners.com.au/hs-fs/hubfs/500x%20DFP%20(3).png?width=50&name=500x%20DFP%20(3).png) [Digital Frontier Partners](https://digitalfrontierpartners.com.au/news/author/digital-frontier-partners)

Cybercriminals are increasingly avoiding noisy attacks and instead exploiting the technologies organisations trust every day. This week's intelligence highlights a concerning convergence of identity compromise, AI-enabled attack techniques, software supply chain intrusions and actively exploited vulnerabilities affecting enterprise platforms.

Attackers are leveraging legitimate authentication mechanisms, trusted development ecosystems and emerging AI capabilities to gain access, steal data and establish persistence while remaining difficult to detect. At the same time, several critical vulnerabilities are under active exploitation, placing internet-facing applications, remote management platforms and development environments at immediate risk.

For Australian organisations, the message is clear: traditional cyber hygiene remains essential, but boards and executives must also address identity governance, AI security controls, supply chain resilience and the growing risks associated with trusted third-party platforms.

---

**Executive Summary**

This week's highest-priority threats centre on actively exploited internet-facing systems, identity-focused attacks and software supply chain compromises.

A critical zero-day affecting self-hosted Metabase installations is being actively exploited to obtain administrator access, steal database credentials and extract connected data. At the same time, attackers are exploiting vulnerabilities in N-able N-central, Progress Kemp LoadMaster and JetBrains TeamCity, reinforcing the importance of rapid patching and post-compromise investigation.

Identity attacks continue to evolve. Threat actors associated with UNC6671 are impersonating IT support staff and contacting employees directly on their personal phones. Victims are redirected to adversary-in-the-middle phishing sites that capture credentials, MFA tokens and cloud sessions, allowing attackers to gain access to Microsoft 365, Okta and other SaaS environments before conducting data theft and extortion.

Software supply chain risks also remain elevated. Hundreds of malicious npm packages, compromised development tools and malicious extensions have been identified stealing developer credentials, repository tokens, cloud secrets and CI/CD credentials across Windows, macOS and Linux environments.

Artificial intelligence continues to create both opportunities and risks. Researchers disclosed multiple AI-related security weaknesses, including prompt injection vulnerabilities, agent hijacking techniques, coding-agent flaws and incidents where AI systems interacted with real-world systems due to inadequate testing controls and sandbox isolation.

---

**Actively Exploited Vulnerabilities and Zero-Days**

Several high-risk vulnerabilities are being actively exploited and should be treated as urgent patching priorities.

The most significant involves a critical Metabase zero-day that allows unauthenticated SQL injection, administrator access and theft of connected database information. Confirmed breaches have already occurred, demonstrating the real-world impact of delayed patching.

Meanwhile, vulnerabilities affecting N-able N-central continue to be exploited to gain administrative control of managed environments. Attackers have reportedly leveraged these flaws to execute remote-control functions and establish persistent access through Cloudflare Tunnels, creating significant risks for managed service providers and downstream customers.

Other important patching priorities include:

**What organisations should do**

---

**Phishing, Social Engineering and Identity Compromise**

Identity remains one of the most attractive attack vectors for cybercriminals.

This week, UNC6671 continued targeting employees in financial services, professional services, private equity and legal organisations. The group's approach relies on human trust rather than technical exploitation, with attackers impersonating help desk staff and convincing employees to authenticate through fraudulent portals that mimic legitimate services. Once access is obtained, attackers move quickly to extract sensitive information and pursue extortion opportunities.

Microsoft 365 environments remain a preferred target. Researchers observed campaigns leveraging voicemail-themed phishing emails, trusted redirect services and geographically aligned residential proxies to quietly compromise accounts and search payroll, finance and HR emails. These attacks create significant risks for payroll fraud, business email compromise and financial diversion attempts.

Device-code phishing campaigns also continue to increase. By abusing legitimate Microsoft authentication workflows, attackers can obtain OAuth tokens and establish persistent access without the need to steal passwords directly or bypass MFA through conventional means. <https://dfpartners-my.sharepoint.com/personal/angeline_tan_digitalfrontierpartners_com/Documents/Microsoft%20Copilot%20Chat%20Files/cyber_threat_intel_categories%2020260809.json>

**What organisations should do**

---

**Malware and Software Supply Chain Attacks**

Software supply chain attacks remain one of the most significant enterprise risks because they exploit trusted developer ecosystems and distribute compromise at scale.

This week, nearly 800 malicious npm packages were identified delivering remote access trojans and information stealers across multiple operating systems. A separate npm worm contaminated hundreds of packages and automatically spread through compromised publishing credentials, allowing attackers to harvest repository secrets, cloud credentials and development tokens.

Investigations also uncovered malicious developer extensions masquerading as legitimate tools, while package repository compromises and dependency poisoning attacks continued targeting open-source ecosystems. Organisations relying heavily on third-party software, development tools and cloud-native workflows face an elevated level of exposure.

Attackers also continued abusing trusted workflows. Fake software updates were used to deploy legitimate remote monitoring and management software, allowing attackers to maintain persistent access while avoiding traditional malware detection mechanisms.

**What organisations should do**

---

**AI and Agent Security Risks**

AI-related security issues featured prominently in this week's reporting.

Researchers demonstrated multiple ways AI assistants, browsers and autonomous agents can be manipulated through prompt injection techniques. Hidden instructions embedded in emails, webpages, repositories and collaboration platforms can influence AI systems into exposing information or performing unauthorised actions.

Atlassian's Rovo assistant was found to be vulnerable to prompt injection scenarios capable of retrieving information from Jira and Confluence environments accessible to the user. Additional flaws were disclosed in AI development frameworks, coding assistants and agent execution environments that could allow unauthorised tool invocation, secret exposure and workflow compromise.

Perhaps most concerning are reports that misconfigured AI testing environments allowed models to interact with real-world systems, access external services and perform unintended actions due to weak sandbox controls. These incidents reinforce the need for governance and strong isolation when deploying autonomous AI capabilities.

**What organisations should do**

---

**Critical Infrastructure and Data Breaches**

Several incidents this week reinforce the risks posed by exposed operational technology and internet-facing infrastructure.

Attacks against water systems overseas demonstrated how publicly exposed industrial controllers can be manipulated without sophisticated exploitation techniques. In separate incidents, internet-accessible PLCs were targeted to alter operational settings and disrupt services. While these incidents occurred outside Australia, the technologies involved are widely deployed globally and remain relevant to local critical infrastructure operators.

Data breaches resulting from exploitation of vulnerable platforms also continued, with incidents involving Metabase environments and remote management systems leading to exposure of customer, account and operational information.

**What organisations should do**

 

**Final Thoughts**

This week's cyber landscape reinforces a recurring theme: attackers are targeting trust. Whether through trusted software packages, legitimate authentication platforms, familiar support processes or emerging AI capabilities, threat actors are increasingly exploiting systems designed to improve productivity and efficiency.

For Australian organisations, immediate priorities should include patching exposed systems, strengthening Microsoft 365 and identity controls, reviewing software supply chain security, governing AI adoption and ensuring critical infrastructure remains appropriately segmented. The organisations that succeed will be those that recognise trusted systems are becoming the preferred pathway for modern cyber attacks and build their security strategies accordingly.

 

[Weekly Cyber Reports](https://digitalfrontierpartners.com.au/news/tag/weekly-cyber-reports)

## Related posts

[![](https://digitalfrontierpartners.com.au/hs-fs/hubfs/A%20dramatic%20169%20landscape%20digital%20illustration%20showing%20a%20stormy%20cyber%20landscape.%20The%20scene%20includes%20.jpeg?height=200&name=A%20dramatic%20169%20landscape%20digital%20illustration%20showing%20a%20stormy%20cyber%20landscape.%20The%20scene%20includes%20.jpeg)](https://digitalfrontierpartners.com.au/news/the-cyber-storm-is-here-why-australia-must-act-now)

## [The Cyber Storm Is Here: Why Australia Must Act Now](https://digitalfrontierpartners.com.au/news/the-cyber-storm-is-here-why-australia-must-act-now)

 26 May 2025, 10:46:39 am AEST

[Read more](https://digitalfrontierpartners.com.au/news/the-cyber-storm-is-here-why-australia-must-act-now)

[![](https://digitalfrontierpartners.com.au/hs-fs/hubfs/AI-Generated%20Media/Images/The%20image%20depicts%20a%20modern%20corporate%20boardroom%20filled%20with%20professionals%20gathered%20around%20a%20sleek%20oval%20table%20The%20room%20is%20welllit%20featuring%20large%20windows%20that%20reveal%20a%20cityscape%20in%20the%20background%20showcasing%20tall%20buildings%20under%20a%20clear%20blue%20sky%20On%20the.png?height=200&name=The%20image%20depicts%20a%20modern%20corporate%20boardroom%20filled%20with%20professionals%20gathered%20around%20a%20sleek%20oval%20table%20The%20room%20is%20welllit%20featuring%20large%20windows%20that%20reveal%20a%20cityscape%20in%20the%20background%20showcasing%20tall%20buildings%20under%20a%20clear%20blue%20sky%20On%20the.png)](https://digitalfrontierpartners.com.au/news/why-cyber-threat-intelligence-is-crucial-for-australian-businesses)

## [Why Cyber Threat Intelligence is Crucial for Australian Businesses](https://digitalfrontierpartners.com.au/news/why-cyber-threat-intelligence-is-crucial-for-australian-businesses)

 14 October 2025, 10:43:00 am AEDT

[Read more](https://digitalfrontierpartners.com.au/news/why-cyber-threat-intelligence-is-crucial-for-australian-businesses)

[![](https://digitalfrontierpartners.com.au/hs-fs/hubfs/AI-Generated%20Media/Images/The%20image%20depicts%20a%20chaotic%20digital%20landscape%20filled%20with%20ominous%20shadows%20representing%20cyber%20threats%20In%20the%20foreground%20a%20glowing%20computer%20screen%20displays%20a%20warning%20message%20about%20SharePoint%20vulnerabilities%20with%20highlighted%20code%20snippets%20and%20alert%20symb.jpeg?height=200&name=The%20image%20depicts%20a%20chaotic%20digital%20landscape%20filled%20with%20ominous%20shadows%20representing%20cyber%20threats%20In%20the%20foreground%20a%20glowing%20computer%20screen%20displays%20a%20warning%20message%20about%20SharePoint%20vulnerabilities%20with%20highlighted%20code%20snippets%20and%20alert%20symb.jpeg)](https://digitalfrontierpartners.com.au/news/cyber-threats-escalate-australian-organisations-under-siege)

## [Cyber Threats Escalate: Australian Organisations Under Siege](https://digitalfrontierpartners.com.au/news/cyber-threats-escalate-australian-organisations-under-siege)

 28 July 2025, 11:04:14 am AEST

[Read more](https://digitalfrontierpartners.com.au/news/cyber-threats-escalate-australian-organisations-under-siege)

###### Visit Us On:

[linkedin-in icon](https://www.linkedin.com/company/digitalfrontierpartners/posts/?feedView=all) [Follow us on Facebook](https://www.youtube.com/watch?v=-BsUxioXzCk&t=6s)

---

[![](https://digitalfrontierpartners.com.au/hs-fs/hubfs/DFP-Logo.webp?width=1200&height=342&name=DFP-Logo.webp)](https://digitalfrontierpartners.com.au/)

Level 4, 350 Collins St, Melbourne VIC, Australia 3000

+61 [1800 288 817](https://www.google.com/search?q=digital+frontier+partners&oq=digital+&gs_lcrp=EgZjaHJvbWUqDwgAECMYJxjjAhiABBiKBTIPCAAQIxgnGOMCGIAEGIoFMhUIARAuGCcYrwEYxwEYgAQYigUYjgUyBggCEEUYOTIMCAMQABhDGIAEGIoFMgwIBBAAGEMYgAQYigUyBggFEEUYPDIGCAYQRRg8MgYIBxBFGDzSAQg0MzQ1ajBqN6gCALACAA&sourceid=chrome&ie=UTF-8#)

Company  

- [Home](https://digitalfrontierpartners.com.au/hp)
- [About Us](https://digitalfrontierpartners.com.au/about)
- [Careers](https://digitalfrontierpartners.zohorecruit.com.au/jobs/Careers)
- [Contact Us](https://digitalfrontierpartners.com.au/contact)

---

Resources

- [News](https://digitalfrontierpartners.com.au/news)
- [Research](https://digitalfrontierpartners.com.au/news)
- [Weekly Cyber Report](https://digitalfrontierpartners.com.au/news)
- [Case Studies](https://digitalfrontierpartners.com.au/news)

---

Policies

- [Privacy Policy](https://digitalfrontierpartners.com.au/news/privacy-policy)
- [Information Security Policy](https://digitalfrontierpartners.com.au/news/information-security-policy)
- [Quality Policy](https://digitalfrontierpartners.com.au/news/quality-policy)

Products and Services

- [Cybersecurity](https://digitalfrontierpartners.com.au/cybersecurity-services-24/7-threat-monitoring-and-response-dfp)
- [Due Diligence](https://digitalfrontierpartners.com.au/technology-due-diligence-product-assessment-digital-frontier-partners)
- [Enterprise Artificial Intelligence (AI)](https://digitalfrontierpartners.com.au/enterprise-ai)
- [Technology Advisory](https://digitalfrontierpartners.com.au/technology-advisory-services-digital-frontier-partners)
- [Workforce Optimisation](https://digitalfrontierpartners.com.au/workforce-optimisation-ai-driven-cost-control-and-performance-dfp)

---

Industries

- [Local Government](https://digitalfrontierpartners.com.au/localgovernment-cybersecurity)
- [Financial Services Cyber Security](https://digitalfrontierpartners.com.au/financialservices)
- [Financial Services Artificial Intelligence](https://digitalfrontierpartners.com.au/financial-services-artificial-intelligence)
- [Mid Market Enterprise AI](https://digitalfrontierpartners.com.au/enterprise-artificial-intelligence)
- [Aged Care Roster Optimisation](https://digitalfrontierpartners.com.au/aged-care-rostering-optimisation)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Digital Frontier Partners",
    "url" : "https://digitalfrontierpartners.com.au/news/author/digital-frontier-partners"
  },
  "dateModified" : "2026-08-12T04:05:24.513Z",
  "datePublished" : "2026-08-12T04:05:24.000Z",
  "headline" : "The New Battleground: Identity, AI and Trusted Software",
  "image" : [ "https://digitalfrontierpartners.com.au/hubfs/AI-Generated%20Media/Images/Cybersecurity%20Brainstorming%20Session%20in%20Modern%20Office.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://digitalfrontierpartners.com.au/news/the-new-battleground-identity-ai-and-trusted-software",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://digitalfrontierpartners.com.au/hubfs/DFP-Logo.webp"
    }
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://digitalfrontierpartners.com.au/#organisation",
  "@type" : "Organization",
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "AU",
    "addressLocality" : "Melbourne",
    "addressRegion" : "VIC",
    "postalCode" : "3000",
    "streetAddress" : "Level 4, 350 Collins Street"
  },
  "description" : "Digital Frontier Partners provides enterprise technology advisory, AI enablement, workforce optimisation and cybersecurity services, helping organisations align strategy, value and risk.",
  "email" : "contact@digitalfrontierpartners.com",
  "knowsAbout" : [ "Enterprise AI enablement", "Artificial intelligence strategy", "AI governance and risk", "Workforce optimisation", "Cybersecurity", "Technology due diligence", "Digital transformation" ],
  "logo" : {
    "@type" : "ImageObject",
    "contentUrl" : "https://digitalfrontierpartners.com.au/hs-fs/hubfs/DFP-Logo.webp?width=1200&height=342&name=DFP-Logo.webp",
    "height" : 342,
    "width" : 1200
  },
  "name" : "Digital Frontier Partners",
  "telephone" : "+61 1800 288 817",
  "url" : "https://digitalfrontierpartners.com.au/"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://digitalfrontierpartners.com.au/#website",
  "@type" : "WebSite",
  "inLanguage" : "en-AU",
  "name" : "Digital Frontier Partners",
  "publisher" : {
    "@id" : "https://digitalfrontierpartners.com.au/#organisation"
  },
  "url" : "https://digitalfrontierpartners.com.au/"
}
```