Stay Ahead of Cyber Threats with Expert Insights

Practical cybersecurity guidance, incident response expertise, and industry intelligence for Australian law firms and businesses.

The Legal Cyber Brief — monthly cyber intelligence for law firm leaders. Threats, regulatory shifts, and practical tools from the field. No fluff.

CYOODA - Newsletter

1,205 Breaches. A Record Year. And Your Sector Is a Fixture in the Top Five.

The privacy regulator just published the worst annual breach numbers since mandatory reporting began - and legal services made the most-affected list again. This fortnight: a record year the OAIC...
Read More about 1,205 Breaches. A Record Year. And Your Sector Is a Fixture in the Top Five.

‘Months, Not Years’: The Five Eyes AI Warning No Law Firm Should Scroll Past.

Your next phishing email won't have a single typo - because a machine wrote it. This fortnight: an unprecedented Five Eyes warning that AI-powered attacks are close, a professional-services firm...
Read More about ‘Months, Not Years’: The Five Eyes AI Warning No Law Firm Should Scroll Past.

68 days. That’s how long attackers are hiding in Australian networks before anyone notices.

Your device management tool just became a weapon. This fortnight: Iran-linked hackers wipe 200,000 devices using Microsoft's own admin tools, an Australian healthcare software vendor hit by ransomware this week,...
Read More about 68 days. That’s how long attackers are hiding in Australian networks before anyone notices.

Thoughts and articles by Cyooda

All
  • All
  • Cybersecurity
  • Detection Engineering
  • How To Guides
  • Ransomware Insights
  • Security Insights

Your Help Desk Is the Easiest Way Into Your Firm

Your Help Desk Is the Easiest Way Into Your Firm I'll tell you how a recent engagement actually went, because the result deserves to be uncomfortable. We were engaged to...
Read More about Your Help Desk Is the Easiest Way Into Your Firm

AI Acceptable Use Policy for Law Firms: What It Should Say | Cyooda

Your firm already has an AI policy. You just didn't write it. Right now, in the absence of anything official, every member of your staff is making their own individual...
Read More about AI Acceptable Use Policy for Law Firms: What It Should Say | Cyooda

You Just Became a Data Target. AML Tranche 2 and the Security Bill Nobody Costed.

Since 1 July, your firm has been a reporting entity under the AML/CTF regime. If you're like most of the firms I talk to, the last six months have been...
Read More about You Just Became a Data Target. AML Tranche 2 and the Security Bill Nobody Costed.

The Email That Never Arrived: Inside a Real Business Email Compromise

The picture above is thirty years old, yet its message still hold true today. Our legal and business systems are built on the assumption that we know who we're dealing...
Read More about The Email That Never Arrived: Inside a Real Business Email Compromise

Cybersecurity news from around the world

Zoom and Xerox Release Critical Security Updates Fixing Privilege Escalation and RCE Flaws

Zoom and Xerox have addressed critical security flaws in Zoom Clients for Windows and FreeFlow Core that could allow privilege escalation and remote code execution. The vulnerability impacting Zoom Clients...
Read More about Zoom and Xerox Release Critical Security Updates Fixing Privilege Escalation and RCE Flaws

Microsoft asks users to ignore certificate enrollment errors

Microsoft has asked customers this week to disregard incorrect CertificateServicesClient (CertEnroll) errors that appear after installing the July 2025 preview update and subsequent Windows 11 24H2 updates. In recent months,...
Read More about Microsoft asks users to ignore certificate enrollment errors

Microsoft August 2025 Patch Tuesday Fixes Kerberos Zero-Day Among 111 Total New Flaws

Microsoft on Tuesday rolled out fixes for a massive set of 111 security flaws across its software portfolio, including one flaw that has been disclosed as publicly known at the...
Read More about Microsoft August 2025 Patch Tuesday Fixes Kerberos Zero-Day Among 111 Total New Flaws

Fortinet Warns About FortiSIEM Vulnerability (CVE-2025-25256) With In-the-Wild Exploit Code

Fortinet is alerting customers of a critical security flaw in FortiSIEM for which it said there exists an exploit in the wild. The vulnerability, tracked as CVE-2025-25256, carries a CVSS...
Read More about Fortinet Warns About FortiSIEM Vulnerability (CVE-2025-25256) With In-the-Wild Exploit Code

Phishers Target Aviation Execs to Scam Customers

KrebsOnSecurity recently heard from a reader whose boss's email account got phished and was used to trick one of the company's customers into sending a large payment to scammers. An...
Read More about Phishers Target Aviation Execs to Scam Customers

A familiar playbook with a twist: 3AM ransomware actors dropped virtual machine with vishing and Quick Assist

Ransomware is usually a crime of opportunity.  Attackers typically strike through an easily discovered vulnerability or security weakness- unpatched Internet-facing software, vulnerable network edge devices, or exposed inbound virtual private...
Read More about A familiar playbook with a twist: 3AM ransomware actors dropped virtual machine with vishing and Quick Assist

Android gets patches for Qualcomm flaws exploited in attacks

Google has released security patches for six vulnerabilities in Android's August 2025 security update, including two Qualcomm flaws exploited in targeted attacks. The two security bugs, tracked as CVE-2025-21479 and...
Read More about Android gets patches for Qualcomm flaws exploited in attacks

Storm-2603 Exploits SharePoint Flaws to Deploy Warlock Ransomware on Unpatched Systems

Microsoft has revealed that one of the threat actors behind the active exploitation of SharePoint flaws is deploying Warlock ransomware on targeted systems. The tech giant, in an update shared...
Read More about Storm-2603 Exploits SharePoint Flaws to Deploy Warlock Ransomware on Unpatched Systems

The Legal Cyber Brief — monthly cyber intelligence for law firm leaders.

The Legal Cyber Brief
Monthly cyber intelligence for law firm leaders.