Stay Ahead of Cyber Threats with Expert Insights

Practical cybersecurity guidance, incident response expertise, and industry intelligence for Australian law firms and businesses.

The Legal Cyber Brief — monthly cyber intelligence for law firm leaders. Threats, regulatory shifts, and practical tools from the field. No fluff.

CYOODA - Newsletter

1,205 Breaches. A Record Year. And Your Sector Is a Fixture in the Top Five.

The privacy regulator just published the worst annual breach numbers since mandatory reporting began - and legal services made the most-affected list again. This fortnight: a record year the OAIC...
Read More about 1,205 Breaches. A Record Year. And Your Sector Is a Fixture in the Top Five.

‘Months, Not Years’: The Five Eyes AI Warning No Law Firm Should Scroll Past.

Your next phishing email won't have a single typo - because a machine wrote it. This fortnight: an unprecedented Five Eyes warning that AI-powered attacks are close, a professional-services firm...
Read More about ‘Months, Not Years’: The Five Eyes AI Warning No Law Firm Should Scroll Past.

68 days. That’s how long attackers are hiding in Australian networks before anyone notices.

Your device management tool just became a weapon. This fortnight: Iran-linked hackers wipe 200,000 devices using Microsoft's own admin tools, an Australian healthcare software vendor hit by ransomware this week,...
Read More about 68 days. That’s how long attackers are hiding in Australian networks before anyone notices.

Thoughts and articles by Cyooda

All
  • All
  • Cybersecurity
  • Detection Engineering
  • How To Guides
  • Ransomware Insights
  • Security Insights

Your Help Desk Is the Easiest Way Into Your Firm

Your Help Desk Is the Easiest Way Into Your Firm I'll tell you how a recent engagement actually went, because the result deserves to be uncomfortable. We were engaged to...
Read More about Your Help Desk Is the Easiest Way Into Your Firm

AI Acceptable Use Policy for Law Firms: What It Should Say | Cyooda

Your firm already has an AI policy. You just didn't write it. Right now, in the absence of anything official, every member of your staff is making their own individual...
Read More about AI Acceptable Use Policy for Law Firms: What It Should Say | Cyooda

You Just Became a Data Target. AML Tranche 2 and the Security Bill Nobody Costed.

Since 1 July, your firm has been a reporting entity under the AML/CTF regime. If you're like most of the firms I talk to, the last six months have been...
Read More about You Just Became a Data Target. AML Tranche 2 and the Security Bill Nobody Costed.

The Email That Never Arrived: Inside a Real Business Email Compromise

The picture above is thirty years old, yet its message still hold true today. Our legal and business systems are built on the assumption that we know who we're dealing...
Read More about The Email That Never Arrived: Inside a Real Business Email Compromise

Cybersecurity news from around the world

⚡ Weekly Recap: Chrome 0-Day, AI Hacking Tools, DDR5 Bit-Flips, npm Worm & More

The security landscape now moves at a pace no patch cycle can match. Attackers aren't waiting for quarterly updates or monthly fixes-they adapt within hours, blending fresh techniques with old,...
Read More about ⚡ Weekly Recap: Chrome 0-Day, AI Hacking Tools, DDR5 Bit-Flips, npm Worm & More

Microsoft Entra ID flaw allowed hijacking any company’s tenant

A critical combination of legacy components could have allowed complete access to the Microsoft Entra ID tenant of every company in the world. The fatal mix included undocumented tokens called...
Read More about Microsoft Entra ID flaw allowed hijacking any company’s tenant

Google Fined $379 Million by French Regulator for Cookie Consent Violations

The French data protection authority has fined Google and Chinese e-commerce giant Shein $379 million (€325 million) and $175 million (€150 million), respectively, for violating cookie rules. Both companies set...
Read More about Google Fined $379 Million by French Regulator for Cookie Consent Violations

Salesloft Takes Drift Offline After OAuth Token Theft Hits Hundreds of Organizations

Salesloft on Tuesday announced that it's taking Drift temporarily offline "in the very near future," as multiple companies have been ensnared in a far-reaching supply chain attack spree targeting the...
Read More about Salesloft Takes Drift Offline After OAuth Token Theft Hits Hundreds of Organizations

Android Security Alert: Google Patches 120 Flaws, Including Two Zero-Days Under Attack

Google has shipped security updates to address 120 security flaws in its Android operating system as part of its monthly fixes for September 2025, including two issues that it said...
Read More about Android Security Alert: Google Patches 120 Flaws, Including Two Zero-Days Under Attack

Researcher to release exploit for full auth bypass on FortiWeb

A security researcher has released a partial proof of concept exploit for a vulnerability in the FortiWeb web application firewall that allows a remote attacker to bypass authentication. The flaw was...
Read More about Researcher to release exploit for full auth bypass on FortiWeb

Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors

The Dutch National Cyber Security Centre (NCSC-NL) has warned of cyber attacks exploiting a recently disclosed critical security flaw impacting Citrix NetScaler ADC products to breach organizations in the country....
Read More about Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors

Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses

An ongoing data extortion campaign targeting Salesforce customers may soon turn its attention to financial services and technology service providers, as ShinyHunters and Scattered Spider appear to be working hand...
Read More about Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses

The Legal Cyber Brief — monthly cyber intelligence for law firm leaders.

The Legal Cyber Brief
Monthly cyber intelligence for law firm leaders.