Skip to content

Trust Is the New Attack Surface

For years, cybersecurity teams focused on patching vulnerabilities, hardening internet-facing systems and preventing malware infections. While those priorities remain critical, this week’s threat landscape highlights a significant shift: attackers are increasingly targeting trust itself. Whether through trusted software, connected applications, AI assistants or human interactions, threat actors are finding success by abusing the relationships organisations rely on every day.

For Australian organisations, the message is clear. Traditional security controls remain essential, but organisations must now pay equal attention to identity governance, third-party integrations, developer ecosystems and user-driven attack paths.

Critical Vulnerabilities Demand Immediate Attention

Several actively exploited vulnerabilities emerged this week, affecting technologies commonly deployed across Australian enterprises.

Microsoft SharePoint Server remains under active attack, with threat actors exploiting vulnerabilities that enable remote code execution, privilege escalation and persistence. Organisations running on-premises SharePoint should prioritise patching, threat hunting and reviewing internet exposure immediately.

At the network edge, SonicWall SMA 1000 appliances are being targeted through chained zero-day vulnerabilities capable of delivering root-level access and facilitating ransomware deployment. Similarly, critical vulnerabilities affecting Fortinet FortiSandbox devices have now joined the list of actively exploited flaws, reinforcing the ongoing focus attackers place on perimeter infrastructure.

Web-facing platforms are also under pressure. A newly disclosed unauthenticated WordPress remote code execution chain, known as “wp2shell”, now has publicly available exploit code, significantly increasing the likelihood of opportunistic attacks against unpatched websites. Meanwhile, a critical 7-Zip vulnerability and the OpenSSL “HollowByte” denial-of-service issue demonstrate that even widely trusted software components can quickly become business risks when patching is delayed.

The common theme is simple: exposed systems continue to provide attackers with some of the fastest paths to compromise.

Identity Attacks Continue to Outpace Exploits

While vulnerabilities attracted considerable attention, the most concerning trend remains the rise of identity-based attacks.

Threat actors linked to ShinyHunters and Scattered Spider continue to gain access to Salesforce environments not through platform vulnerabilities, but by manipulating users and abusing OAuth trust relationships. Attackers are convincing victims to authorise malicious connected applications, compromising third-party integrations and exploiting overly permissive access permissions.

This approach is particularly relevant for Australian organisations given the attention generated by previous breaches involving trusted service providers and customer service channels. The lesson is increasingly clear: securing SaaS platforms requires more than protecting user passwords. Organisations must also govern the applications, integrations and tokens that operate within those environments.

Adding to this challenge, researchers highlighted techniques capable of validating stolen credentials within Microsoft Entra environments while reducing visibility through traditional sign-in monitoring. These developments further demonstrate how attackers are adapting their methods to evade established detection controls.

Social Engineering Remains the Leading Entry Point

Many of this week’s most active malware campaigns relied on social engineering rather than software vulnerabilities.

The continued rise of ClickFix-based attacks highlights how effective user manipulation remains. Rather than exploiting systems directly, attackers convince users to copy, paste and execute malicious commands disguised as troubleshooting steps or verification processes. Once executed, these commands can deploy credential stealers, remote access tools and data theft malware.

The ACR Stealer campaign demonstrates this approach at scale, targeting Microsoft 365 credentials, browser passwords, session tokens and cloud-stored documents. Similar tactics are appearing across both Windows and macOS environments, including the emergence of the ClickLock infostealer, which uses deceptive techniques to pressure users into revealing their system passwords.

These campaigns reinforce an important reality: multifactor authentication alone is not enough when attackers can convince legitimate users to perform the malicious action themselves.

Supply Chain Risks Continue to Expand

The software supply chain remains one of the most attractive targets for attackers seeking broad impact.

This week saw multiple malicious npm package campaigns affecting developers and software teams. Some packages delivered remote access trojans, others deployed botnet loaders, while several leveraged trusted developer workflows to gain persistence and access to sensitive environments.

Developer tools themselves are also becoming attack surfaces. Security researchers identified weaknesses in AI-assisted coding platforms, including Cursor and Claude-related integrations, that could allow attackers to execute code, manipulate AI-driven workflows or trigger unauthorised actions through malicious repositories, browser extensions or crafted prompts.

For businesses embracing AI-powered development tools, governance must evolve as quickly as adoption. Untrusted repositories, overly permissive extensions and unrestricted AI integrations can introduce risks that traditional security controls were never designed to detect.

AI Infrastructure Is Becoming a Target

As organisations accelerate AI adoption, attackers are following closely behind.

A newly observed botnet dubbed NadMesh is actively scanning internet-exposed AI services such as Ollama, Langflow and other AI platforms to harvest cloud credentials, Kubernetes tokens and configuration data. Rather than targeting the AI systems themselves, attackers are looking for privileged access that can be leveraged elsewhere across the environment.

At the same time, emerging research into AI agents and automation platforms highlights growing concerns around prompt manipulation, excessive permissions and unauthorised actions performed by trusted AI systems. As AI becomes more deeply integrated into daily business operations, governance and monitoring will become just as important as functionality.

Key Takeaways for Australian Organisations

The most effective security investments this week are not necessarily new technologies, but disciplined execution of existing controls:

  • Prioritise patching of internet-facing systems, particularly SharePoint, SonicWall, Fortinet and WordPress environments.
  • Review OAuth applications and third-party SaaS integrations to ensure access remains appropriately governed.
  • Strengthen monitoring for token theft, suspicious connected apps and unusual authentication activity.
  • Educate staff about ClickFix-style attacks and reinforce that users should never execute commands from unsolicited sources.
  • Tighten software supply chain controls, including package management, repository trust and AI-assisted development tools.
  • Review security controls around AI services, cloud credentials and internet-exposed AI infrastructure.
  • Validate helpdesk, customer service and administrative verification procedures to reduce social engineering exposure.

Final Thought

This week’s threat intelligence demonstrates that attackers are increasingly succeeding by exploiting trust rather than technology alone. Whether through SaaS integrations, AI assistants, developer tools, social engineering or trusted software components, the modern attack surface is no longer limited to vulnerable systems.

The organisations best positioned to defend themselves will be those that treat identity, trust relationships and third-party access with the same urgency traditionally reserved for critical vulnerabilities