State-sponsored actors are inside critical infrastructure networks, and they're not using malware. They're using valid credentials, dumped directly from Active Directory. The latest intelligence on Volt Typhoon confirms that identity is the new perimeter. For Australian CISOs, this isn't just a technical problem—it's a board-level risk with direct implications under the SOCI Act. We break down the technical chain of a credential dumping attack, from LSASS memory scraping to domain dominance, and present the data on why a Zero Trust architecture is no longer optional. https://lnkd.in/gY8bv62U #CyberSecurityAU #ActiveDirectory #ZeroTrust #CriticalInfrastructure
Lean Security
Computer and Network Security
Surry Hills, New South Wales 28 followers
Expert penetration testing and cybersecurity services for Australian businesses.
About us
In a world where online security is not just a feature but a necessity, Lean Security provides the innovative and reliable cyber security services your business needs to operate with confidence. Headquartered in Sydney and serving the international business community, we specialise in protecting your most critical digital assets from the ground up. The life of your business depends on the quality of the security you use. It's not a matter of 'if' a threat will emerge, but 'when'. Our mission is to be the trusted partner that navigates you through the complex digital landscape, ensuring your applications and data remain secure at all times. Our Approach We believe that effective security is never one-size-fits-all. Our team of experienced professionals takes a meticulous and collaborative approach. We listen to your vision, understand your specific needs, and build customised security plans and policies that provide robust, long-lasting protection. Partner with Lean Security for dedicated security solutions that are guaranteed to be effective and reliable. Contact us today to discuss your security needs or visit our website to learn more. www.leansecurity.com.au
- Website
-
https://www.leansecurity.com.au/
External link for Lean Security
- Industry
- Computer and Network Security
- Company size
- 2-10 employees
- Headquarters
- Surry Hills, New South Wales
- Type
- Privately Held
- Founded
- 2015
Locations
-
Primary
Get directions
81-83 Campbell St
Surry Hills, New South Wales 2010, AU
Updates
-
Annual pentests are creating a dangerous illusion of security for Australian financial boards. A single API change deployed this afternoon can completely invalidate a security report from last month. The recent Change Healthcare breach serves as a stark reminder of how a single initial access vector can lead to catastrophic impact. For Australian financial services organisations running agile CI/CD pipelines, the attack surface is evolving daily, not yearly. CISOs can no longer rely on point-in-time assurance. The conversation with the board must shift to data-driven, continuous security metrics. The critical metric? Mean Time to Remediate (MTTR). PTaaS models are designed to crush this metric, integrating security directly into the development lifecycle. Our latest briefing breaks down the data-driven case for shifting to a PTaaS model to manage board expectations effectively. https://lnkd.in/gViNEXR3 #Cybersecurity #PTaaS #FinancialServices #Australia #CISO
-
The recent wave of breaches targeting customers on major SaaS platforms wasn't a platform failure. It was a predictable exploit of a common, silent vulnerability: cloud misconfiguration. For CISOs, this is the critical gap between security policy and operational reality. Your board wants assurance, not incident reports. How can you prove your organisation's SaaS environment isn't the next headline? We deconstructed the exact attack path—from initial credential theft to mass data exfiltration—and outlined the specific penetration testing techniques that would have flagged the risk months ago. Find the full technical breakdown in the comments below. https://lnkd.in/dPq8FyxM #Cybersecurity #CloudSecurity #CISO #PenetrationTesting #RiskManagement
-
Attention CISOs and Security Leaders: The Australian cyber threat landscape is evolving rapidly. Over the past 24 hours, Lean Security has observed a significant escalation in threat actor activity, specifically weaponizing AI, exploiting insecure APIs, and targeting unpatched cloud environments. Our latest Threat Intelligence Briefing breaks down the most pressing risks across critical Australian sectors: Agentic AI and Shadow AI Risks: FinTech and government sectors are facing a new frontier of risk. Threat actors are utilizing malicious prompt injections against autonomous AI agents and deploying advanced deepfakes to bypass biometric controls and scale Business Email Compromise campaigns. Cloud and Supply Chain Vulnerabilities: SaaS providers and eCommerce organizations are experiencing cascading risks from unpatched backend configurations and third-party vendor integrations, leading to severe data exposure across government and private entities. Ransomware and API Exploits: The aggressive expansion of Ransomware-as-a-Service groups continues to plague healthcare, while EdTech platforms are seeing targeted exploitation of authorization flaws in student-facing APIs to silently drain backend databases. Legacy IoT Weaponization: Following the enforcement of the Cyber Security Act 2024, attackers are utilizing AI-driven scanning tools to rapidly fingerprint legacy smart devices, turning unpatched routers and cameras into infrastructure for botnet operations. Traditional perimeter defense is no longer sufficient. Maintaining resilience against modern adversaries requires continuous exposure validation, strict API governance, and AI-specific security protocols. We highly encourage you to view the full article on our website for the detailed, sector-by-sector analysis and technical insights into these emerging vulnerabilities. To proactively secure your infrastructure against these threats, contact Lean Security today for a tailored quote on our penetration testing and adversary simulation services. https://lnkd.in/g3agKcEa #CyberSecurity #ThreatIntelligence #Australia #CloudSecurity #InformationSecurity
-
Attention Australian CISOs and Security Leaders: The cyber threat landscape is experiencing a dramatic escalation. In our latest daily threat briefing from Lean Security, we are tracking a significant pivot toward AI-accelerated exploits, weaponized supply chains, and persistent cloud governance failures targeting local networks. Here is a summary of the critical intelligence impacting key sectors right now: FinTech and SaaS: AI security has shifted from theory to active exploitation. APRA and ASIC are warning of systemic risks following unauthorized access to frontier AI vulnerability models and multi-stage supply chain attacks poisoning AI proxy layers. Government and eCommerce: The ACSC reiterates that cloud misconfigurations, specifically excessive IAM permissions and unmanaged identities, remain the primary enablers of costly data breaches and third-party compromises. Education and Enterprise Web Applications: Immediate action is required for critical vulnerabilities in ASP.NET Core and Apache ActiveMQ. Threat actors are also aggressively extracting cryptographic secrets and API keys from developer code repositories to initiate novel supply-chain attacks. Healthcare and Critical Infrastructure: Ransomware continues to ruthlessly disrupt community health services. Simultaneously, state-sponsored actors are actively compromising IoT edge devices to obfuscate targeted attacks against Australian infrastructure, exacerbated by severe vulnerabilities in networking equipment. The velocity of these attacks proves that static defenses are no longer sufficient. Proactive validation of your cloud environments, API endpoints, and third-party AI integrations is essential. We highly encourage you to view the full article on our website for the detailed analysis of these emerging threats. While on our site, you can also reach out to Lean Security to request a quote for comprehensive penetration testing or adversary simulation to ensure your organization's defenses are prepared for these modern attack vectors. https://lnkd.in/g7S2P6g2 #CyberSecurity #ThreatIntel #Australia #RiskManagement #InfoSec
-
In our Weekly Threat Intelligence Briefing for the week ending 26 April 2026, Lean Security examines the aggressive industrialization of cybercrime across the Australian threat landscape. Recent industry data reveals a critical resilience gap: while most ANZ organizations feel confident in their threat detection capabilities, over 70 percent lack a tested incident response or business continuity plan. Today, detection is merely table stakes. Resilience is the true differentiator. Our senior penetration testing team has observed adversaries shifting away from traditional perimeter attacks. Instead, threat actors are focusing on four key areas: First, complex API integrations and web applications are being heavily targeted. Missing authorizations and path traversal flaws are allowing low-privileged users to escalate access and execute arbitrary code. Second, unpatched IoT edge devices are increasingly being exploited. Threat actors are leveraging these vulnerable perimeters to deploy botnets and disguise the origins of state-sponsored attacks. Third, SaaS providers and cloud supply chains are under siege. Adversaries are actively compromising authentication tokens to infiltrate online code repositories, modify public packages, and scan for cryptographic secrets. Finally, the rapid integration of Artificial Intelligence is vastly expanding the attack surface. While defensive AI models are proving highly effective at discovering zero-day vulnerabilities, the unauthorized use of Shadow AI by employees is exposing organizations to significant data leakage and prompt injection risks. With the FinTech sector facing multi-million dollar regulatory penalties for data breaches and healthcare remaining a prime target for aggressive ransomware syndicates, organizations must shift from a purely defensive posture to proactive validation. We strongly encourage you to view the full article on our website for a detailed analysis of these sector-specific threats, prominent actors, and a complete breakdown of newly exploited vulnerabilities. Contact Lean Security today for a quote on our penetration testing and adversary simulation services to ensure your external assets, internal APIs, and cloud configurations are rigorously tested and secure. https://lnkd.in/gQDegZt2 #CyberSecurity #ThreatIntel #CyberResilience #Australia #PenetrationTesting
-
Attention Australian C-suite and Security Leaders: The cyber threat landscape is shifting at an unprecedented pace. Over the past 24 hours, Lean Security has observed significant disruptions across the region driven by an escalating AI vulnerability storm, critical insider threats, and severe zero-day exploits. Our latest Daily Threat Briefing breaks down the most pressing threats and vulnerabilities impacting Australian industries today. Key highlights from our analysis include: Escalating AI Threats: AI tools are autonomously discovering software flaws and drastically compressing exploit timelines. Furthermore, AI infrastructure itself is increasingly becoming a primary target for threat actors. Supply Chain and Insider Risks: We are seeing a surge in third-party SaaS supply chain breaches and severe insider threat incidents impacting both government entities and the FinTech sector. Sector-Specific Sieges: Healthcare continues to face unprecedented ransomware demands targeting legacy systems, while the EdTech and eCommerce sectors battle sophisticated credential stuffing and phishing campaigns. Active Exploits in the Wild: Critical vulnerabilities, including pre-authentication API bypasses and severe code injections, are being actively exploited in Fortinet FortiClient EMS, Apache ActiveMQ, and Microsoft Defender. Edge devices are also being targeted by persistent malware that survives firmware upgrades. Reactive security measures are no longer sufficient against AI-powered offensive operations. Defending your organization requires robust network segmentation, rigorous API gateway protections, and continuous auditing of cloud integrations. We highly encourage you to read the full article on our website for a detailed sector-by-sector analysis and comprehensive mitigation strategies. While on our site, you can also contact our team for a quote on our professional penetration testing and adversary simulation services to proactively harden your defenses. https://lnkd.in/g7FWWnbP #CyberSecurity #ThreatIntel #Australia #CISO #InfoSec
-
The window between vulnerability disclosure and active exploitation has collapsed from weeks to mere hours. For C-level executives and security professionals, staying ahead of this rapidly industrializing cybercrime landscape is critical to protecting organizational assets and sensitive data. In our newest daily threat briefing from Lean Security, we examine the volatile Australian cybersecurity environment and the active risks you need to address today. Here is a summary of the most critical threats identified: 1. AI-Driven Exploitation: Autonomous frontier AI models are now successfully identifying zero-day vulnerabilities in compiled binary code, drastically lowering the barrier to entry for threat actors and effectively ending security by obscurity. 2. Supply Chain Persistence: Government and enterprise cloud networks are being targeted by advanced persistence malware, such as FIRESTARTER, allowing attackers to maintain access long after initial vulnerabilities are patched. 3. API Vulnerabilities: FinTech, eCommerce, and Healthcare platforms are battling automated botnets and ransomware groups. These actors are actively exploiting unauthenticated APIs and interconnected SaaS platforms to exfiltrate data and launch double-extortion campaigns. 4. Infrastructure and IoT Exploits: Threat actors are bypassing legacy defenses by chaining newly disclosed Windows zero-days and exploiting smart infrastructure to pivot directly into broader operational networks. Defending against these complex, AI-amplified campaigns requires an assume breach mentality and continuous validation of your security posture. We highly encourage you to view the full article on our website for a detailed analysis of these threat actors, critical vulnerabilities, and mitigation strategies. If your organization needs to validate its defenses, contact the Lean Security team today to request a quote for our penetration testing or adversary simulation services. https://lnkd.in/gEHY9H4e Tags: #CyberSecurity #ThreatIntel #Australia #CISO #PenetrationTesting
-
The Australian cyber threat landscape is shifting rapidly. We are seeing a critical escalation from isolated endpoint compromises to systemic supply chain and identity-based attacks. In our latest threat intelligence briefing at Lean Security, we analyze the active vulnerabilities targeting Australian organizations. Threat actors are aggressively capitalizing on complex API integrations, unpatched cloud infrastructure, and the hasty deployment of artificial intelligence technologies. Our analysis highlights critical risks across several key sectors. In FinTech and eCommerce, attackers are exploiting third-party trust mechanisms and poorly secured APIs. Healthcare and Government entities are facing aggressive Ransomware-as-a-Service campaigns and the downstream impacts of global SaaS supply chain breaches. Meanwhile, critical infrastructure and IoT networks are seeing active exploitation of SD-WAN vulnerabilities by advanced persistent threats. Furthermore, the rush to deploy generative AI is introducing novel data governance risks, such as prompt injection and malicious extensions, which has prompted tighter regulatory obligations under the SOCI Act. Adopting frontier technologies without rigorous security validation leaves your organization highly exposed. Defensive postures must shift from reactive monitoring to continuous security testing and proactive threat hunting. We explicitly encourage you to view the full article on our website for the detailed analysis, vulnerability breakdowns, and strategic guidance. Contact Lean Security today for a quote on our penetration testing and adversary simulation services to ensure your networks are secure. https://lnkd.in/gWyzpAF3 #CyberSecurity #ThreatIntelligence #Australia #CISO #PenetrationTesting
-
The Australian cyber threat landscape is evolving at an unprecedented pace. Our latest threat intelligence briefing from Lean Security reveals that the window between vulnerability disclosure and active exploitation has collapsed to mere hours. We are tracking several highly volatile shifts currently impacting critical sectors across the country: Healthcare and SaaS: Providers are facing aggressive ransomware campaigns, with attackers exploiting poorly secured APIs to move laterally and execute downstream supply-chain attacks. FinTech and eCommerce: API sprawl is the dominant threat vector. Adversaries are actively hunting unauthenticated REST APIs and utilizing automated botnets to bypass frontend applications and harvest sensitive consumer data. Government and Education: High-security environments remain highly vulnerable to third-party cloud breaches. Furthermore, the rapid, insecure integration of externally accessible AI APIs is leading to direct data exposure and poisoned deployment pipelines. Cloud and AI Systems: The weaponization of artificial intelligence has fundamentally shifted cyber warfare. Frontier AI models are industrializing zero-day discovery, while misconfigured cloud IAM roles and legacy IoT devices continue to provide easy paths for privilege escalation. As adversaries industrialize their attack chains, routine vulnerability scanning is no longer enough. Organizations must adopt an assume-breach architecture and engage in continuous, offensive security testing to uncover critical blind spots. Please read the full article on our website for the detailed analysis of these emerging attack vectors and sector-specific threats. If you need to validate your current security posture, contact Lean Security today to request a quote for our expert penetration testing and adversary simulation services. https://lnkd.in/giU7u9jC #CyberSecurity #ThreatIntel #Australia #InfoSec #PenetrationTesting