Stay Ahead of Cyber Threats with Expert Insights

Practical cybersecurity guidance, incident response expertise, and industry intelligence for Australian law firms and businesses.

The Legal Cyber Brief — monthly cyber intelligence for law firm leaders. Threats, regulatory shifts, and practical tools from the field. No fluff.

CYOODA - Newsletter

‘Months, Not Years’: The Five Eyes AI Warning No Law Firm Should Scroll Past.

Your next phishing email won't have a single typo - because a machine wrote it. This fortnight: an unprecedented Five Eyes warning that AI-powered attacks are close, a professional-services firm...
Read More about ‘Months, Not Years’: The Five Eyes AI Warning No Law Firm Should Scroll Past.

68 days. That’s how long attackers are hiding in Australian networks before anyone notices.

Your device management tool just became a weapon. This fortnight: Iran-linked hackers wipe 200,000 devices using Microsoft's own admin tools, an Australian healthcare software vendor hit by ransomware this week,...
Read More about 68 days. That’s how long attackers are hiding in Australian networks before anyone notices.

Lexis Nexis Breaches – and your data maybe in the dump

Your legal research tool just became a threat vector. This fortnight: a breach that hits law firms at the supply chain, Australia's first Federal Court cyber penalty, an elite school...
Read More about Lexis Nexis Breaches – and your data maybe in the dump

Thoughts and articles by Cyooda

All
  • All
  • Cybersecurity
  • Detection Engineering
  • How To Guides
  • Ransomware Insights
  • Security Insights

Your Help Desk Is the Easiest Way Into Your Firm

Your Help Desk Is the Easiest Way Into Your Firm I'll tell you how a recent engagement actually went, because the result deserves to be uncomfortable. We were engaged to...
Read More about Your Help Desk Is the Easiest Way Into Your Firm

AI Acceptable Use Policy for Law Firms: What It Should Say | Cyooda

Your firm already has an AI policy. You just didn't write it. Right now, in the absence of anything official, every member of your staff is making their own individual...
Read More about AI Acceptable Use Policy for Law Firms: What It Should Say | Cyooda

You Just Became a Data Target. AML Tranche 2 and the Security Bill Nobody Costed.

Since 1 July, your firm has been a reporting entity under the AML/CTF regime. If you're like most of the firms I talk to, the last six months have been...
Read More about You Just Became a Data Target. AML Tranche 2 and the Security Bill Nobody Costed.

The Email That Never Arrived: Inside a Real Business Email Compromise

The picture above is thirty years old, yet its message still hold true today. Our legal and business systems are built on the assumption that we know who we're dealing...
Read More about The Email That Never Arrived: Inside a Real Business Email Compromise

Cybersecurity news from around the world

UK fines LastPass over 2022 data breach impacting 1.6 million users

The UK Information Commissioner's Office (ICO) fined the LastPass password management firm £1.2 million for failing to implement security measures that allowed an attacker to steal personal information and encrypted...
Read More about UK fines LastPass over 2022 data breach impacting 1.6 million users

MS Teams Guest Access Can Remove Defender Protection When Users Join External Tenants

Cybersecurity researchers have shed light on a cross-tenant blind spot that allows attackers to bypass Microsoft Defender for Office 365 protections via the guest access feature in Teams. "When users...
Read More about MS Teams Guest Access Can Remove Defender Protection When Users Join External Tenants

OpenAI discloses API customer data breach via Mixpanel vendor hack

OpenAI is notifying some ChatGPT API customers that limited identifying information was exposed following a breach at its third-party analytics provider Mixpanel. Mixpanel offers event analytics that OpenAI uses to...
Read More about OpenAI discloses API customer data breach via Mixpanel vendor hack

ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access

A recently patched security flaw in Microsoft Windows Server Update Services (WSUS) has been exploited by threat actors to distribute malware known as ShadowPad. "The attacker targeted Windows Servers with...
Read More about ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access

 Google Sues China-Based Hackers Behind $1 Billion Lighthouse Phishing Platform

Google has filed a civil lawsuit in the U.S. District Court for the Southern District of New York (SDNY) against China-based hackers who are behind a massive Phishing-as-a-Service (PhaaS) platform...
Read More about  Google Sues China-Based Hackers Behind $1 Billion Lighthouse Phishing Platform

Hackers exploited Citrix, Cisco ISE flaws in zero-day attacks

An advanced threat actor exploited the critical vulnerabilities "Citrix Bleed 2" (CVE-2025-5777) in NetScaler ADC and Gateway, and CVE-2025-20337 affecting Cisco Identity Service Engine (ISE) as zero-days to deploy custom malware. Amazon's...
Read More about Hackers exploited Citrix, Cisco ISE flaws in zero-day attacks

GlobalLogic warns 10,000 employees of data theft after Oracle breach

GlobalLogic, a provider of digital engineering services part of the Hitachi group, is notifying over 10,000 current and former employees that their data was stolen in an Oracle E-Business Suite...
Read More about GlobalLogic warns 10,000 employees of data theft after Oracle breach

CISA orders feds to patch Windows Server WSUS flaw used in attacks

The Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. government agencies to patch a critical-severity Windows Server Update Services (WSUS) vulnerability after adding it to its catalog of security flaws...
Read More about CISA orders feds to patch Windows Server WSUS flaw used in attacks

The Legal Cyber Brief — monthly cyber intelligence for law firm leaders.

The Legal Cyber Brief
Monthly cyber intelligence for law firm leaders.