Stay Ahead of Cyber Threats with Expert Insights

Practical cybersecurity guidance, incident response expertise, and industry intelligence for Australian law firms and businesses.

The Legal Cyber Brief — monthly cyber intelligence for law firm leaders. Threats, regulatory shifts, and practical tools from the field. No fluff.

CYOODA - Newsletter

1,205 Breaches. A Record Year. And Your Sector Is a Fixture in the Top Five.

The privacy regulator just published the worst annual breach numbers since mandatory reporting began - and legal services made the most-affected list again. This fortnight: a record year the OAIC...
Read More about 1,205 Breaches. A Record Year. And Your Sector Is a Fixture in the Top Five.

‘Months, Not Years’: The Five Eyes AI Warning No Law Firm Should Scroll Past.

Your next phishing email won't have a single typo - because a machine wrote it. This fortnight: an unprecedented Five Eyes warning that AI-powered attacks are close, a professional-services firm...
Read More about ‘Months, Not Years’: The Five Eyes AI Warning No Law Firm Should Scroll Past.

68 days. That’s how long attackers are hiding in Australian networks before anyone notices.

Your device management tool just became a weapon. This fortnight: Iran-linked hackers wipe 200,000 devices using Microsoft's own admin tools, an Australian healthcare software vendor hit by ransomware this week,...
Read More about 68 days. That’s how long attackers are hiding in Australian networks before anyone notices.

Thoughts and articles by Cyooda

All
  • All
  • Cybersecurity
  • Detection Engineering
  • How To Guides
  • Ransomware Insights
  • Security Insights

Your Help Desk Is the Easiest Way Into Your Firm

Your Help Desk Is the Easiest Way Into Your Firm I'll tell you how a recent engagement actually went, because the result deserves to be uncomfortable. We were engaged to...
Read More about Your Help Desk Is the Easiest Way Into Your Firm

AI Acceptable Use Policy for Law Firms: What It Should Say | Cyooda

Your firm already has an AI policy. You just didn't write it. Right now, in the absence of anything official, every member of your staff is making their own individual...
Read More about AI Acceptable Use Policy for Law Firms: What It Should Say | Cyooda

You Just Became a Data Target. AML Tranche 2 and the Security Bill Nobody Costed.

Since 1 July, your firm has been a reporting entity under the AML/CTF regime. If you're like most of the firms I talk to, the last six months have been...
Read More about You Just Became a Data Target. AML Tranche 2 and the Security Bill Nobody Costed.

The Email That Never Arrived: Inside a Real Business Email Compromise

The picture above is thirty years old, yet its message still hold true today. Our legal and business systems are built on the assumption that we know who we're dealing...
Read More about The Email That Never Arrived: Inside a Real Business Email Compromise

Cybersecurity news from around the world

Storm-2603 Exploits SharePoint Flaws to Deploy Warlock Ransomware on Unpatched Systems

Microsoft has revealed that one of the threat actors behind the active exploitation of SharePoint flaws is deploying Warlock ransomware on targeted systems. The tech giant, in an update shared...
Read More about Storm-2603 Exploits SharePoint Flaws to Deploy Warlock Ransomware on Unpatched Systems

Customer Account Takeovers: The Multi-Billion Dollar Problem You Don’t Know About

Everyone has cybersecurity stories involving family members. Here's a relatively common one. The conversation usually goes something like this: "The strangest thing happened to my streaming account. I got locked...
Read More about Customer Account Takeovers: The Multi-Billion Dollar Problem You Don’t Know About

RansomHub Went Dark April 1; Affiliates Fled to Qilin, DragonForce Claimed Control

Cybersecurity researchers have revealed that RansomHub's online infrastructure has "inexplicably" gone offline as of April 1, 2025, prompting concerns among affiliates of the ransomware-as-a-service (RaaS) operation. Singaporean cybersecurity company Group-IB...
Read More about RansomHub Went Dark April 1; Affiliates Fled to Qilin, DragonForce Claimed Control

What you should be doing when you receive an unsolicited One Time Passcode

If you receive an unsolicited One Time Passcode (OTP) for a service that you use,  either as an SMS or Email you should be concerned and act immediately! Why should...
Read More about What you should be doing when you receive an unsolicited One Time Passcode

Top targeted vulnerabilities of 2023: STOP this madness

In 2023 the top 10 targeted vulnerabilities used by threat actors to actively exploit victims were more than 10 years old! In order of CVE ranking we have: CVE-2017-0199 -...
Read More about Top targeted vulnerabilities of 2023: STOP this madness

Beware of new Ransomware Tactic

2 days ago ALPHV/BlackCat in a bid to apply further pressure to get their latest victim MeridanLink to pay, filed a compliant against them with the U.S. Securities and Exchange...
Read More about Beware of new Ransomware Tactic

DEF CON 31 – New Novel WFP filter attack for privilege escalation

I recently returned from the DEF CON 2023 conference in Las Vegas and amongst many of the briefings that I attended the talk by Ron Ben Yizhak was particularly interesting. ...
Read More about DEF CON 31 – New Novel WFP filter attack for privilege escalation

Data Privacy – It’s time to act

What is the Australian data privacy act? The Privacy Act 1988 was introduced to promote and protect the privacy of individuals and to regulate how Australian Government agencies and organisations...
Read More about Data Privacy – It’s time to act

The Legal Cyber Brief — monthly cyber intelligence for law firm leaders.

The Legal Cyber Brief
Monthly cyber intelligence for law firm leaders.