Plural Cyber’s cover photo
Plural Cyber

Plural Cyber

Computer and Network Security

Auckland, AUK 593 followers

Committed to building and nurturing a cyber resilient New Zealand

About us

A team of cyber security experts, helping businesses build cyber resilience and manage their cyber security risk. At Plural, we understand that in today’s digital landscape, cyber threats are constantly evolving. That's why we provide tailored advisory services and comprehensive managed security services designed to fortify your business against these threats. With Plural, you gain a partner dedicated to safeguarding your business through proactive cyber security services and contextualised risk management.

Website
https://www.plural.co.nz
Industry
Computer and Network Security
Company size
2-10 employees
Headquarters
Auckland, AUK
Type
Privately Held

Employees at Plural Cyber

View 14 employees at Plural Cyber

or

By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.

See all employees

Locations

Updates

  • Plural Cyber reposted this

    SCAM ALERT 📢 Compromised websites serving ClickFix malware lure ClickFix is a type of social engineering technique that presents visitors to compromised websites with fake CAPTCHA or Cloudflare Turnstile challenges that instruct them to paste commands into Run, PowerShell, Terminal, or similar tools, leading to malware installation on their device.  ClickFix campaigns commonly use (but aren’t limited to) compromised WordPress sites to deliver their malware. Read the full alert here 👉 https://lnkd.in/eMr3swYi

    • No alternative text description for this image
  • NCSC NZ's Q1 2026 Cyber Security Insights Report was released today. While overall incident volumes remained relatively stable, the quarter saw a notable increase in both the severity of incidents and the financial losses experienced by New Zealanders. 🟣 By the numbers ▪️1,164 cyber security incidents reported (+3% from Q4 2025). ▪️77 incidents required specialist NCSC technical support. ▪️3 incidents categorised as C2 ("Highly Significant") – the first C2 incidents reported since 2021/22. ▪️$5.6 million in direct financial losses reported (+76% from Q4 2025). ▪️Individuals accounted for $5.2 million of reported losses. ▪️42 incidents caused losses exceeding $10,000, representing 97% of all reported financial loss. 🟣 Threat signals ▪️Phishing and credential harvesting remained the most common incident type with 437 reported incidents. ▪️Scams and fraud were the second most reported category, accounting for approximately $3.8 million in losses. ▪️Several significant incidents involved unauthorised access to sensitive customer and patient information. ▪️Thousands of New Zealanders were impacted by the three highly significant C2 incidents. 🟣 Key observations ▪️The concentration of financial losses in a small number of incidents highlights the importance of early detection and rapid response. ▪️Sensitive data remains a prime target for cyber criminals and nation-state actors alike. ▪️Credential theft continues to be one of the most effective pathways for compromise. ▪️ The impact of cyber incidents increasingly extends beyond IT systems to operational disruption, privacy obligations, regulatory scrutiny, and reputational damage. 🟣 Priorities for resilience ▪️ Strengthen identity and access management controls. ▪️ Improve phishing resistance through technical controls and user awareness. ▪️ Protect sensitive data through classification, access controls, monitoring, and encryption. ▪️ Maintain tested incident response and crisis management plans. ▪️ Focus on operational resilience, not just compliance. The report also includes an interesting discussion on the implications of emerging Frontier AI models and the opportunities and risks they may present for cyber defenders and threat actors alike. 🔗 Read the full report here: https://lnkd.in/eN5zXJhV

    • No alternative text description for this image
  • Plural Cyber reposted this

    Frontier AI technologies are the most advanced and cutting-edge AI models available. Check out the NCSC’s practical guidance for New Zealand government agencies below. Although aimed at government entities this publication can be useful for all organisations. The guide includes how to act now to prepare for the implications of Frontier AI and ensure strong cyber security readiness in this new era of artificial intelligence. These models represent an anticipated step change in capability, enabling significantly more powerful automation, reasoning and decision making than previous generations of AI. The same models that strengthen cyber defence can be exploited by malicious actors to conduct harmful cyber activities at a greater scale than seen before. This guidance outlines the actions that New Zealand organisations should treat as an immediate priority to effectively strengthen their cyber security posture. https://lnkd.in/eYmXZzEV

    • No alternative text description for this image
  • Plural Cyber reposted this

    International education technology provider Instructure has reported a cyber security incident. Instructure provides a learning management system called Canvas to education institutions in more than 100 countries, including some here in Australia. A threat actor claims to have accessed a Canvas database holding personally identifiable information of students and staff from around the world. My team is coordinating efforts to respond and understand what Australian data may be impacted. We are in the early stages of assessing the impacts, and I will share further updates as we gain a better understanding of the incident. If you think you may be impacted by this breach, the best way you can protect yourself is to not respond to unsolicited contact. Criminals use personal information from data breaches to trick victims into revealing further information that can be used to access your accounts elsewhere, including with financial institutions.

    • No alternative text description for this image
  • Plural Cyber reposted this

    ❗ ALERT ❗ We are aware of an active vulnerability affecting the cPanel/ WebHost Manager products. The vulnerability is an authentication bypass, which can allow unauthenticated remote attackers to gain access to the control panel, as well as conduct remote code execution (RCE). We recommend organisations review their networks for vulnerable instances and apply patches as soon as practical. Read the full alert 👉 https://lnkd.in/gJYMUdx8

    • No alternative text description for this image
  • Plural Cyber reposted this

    ❗ ALERT ❗ New FIRESTARTER malware affecting certain Cisco products Our international partners, the US Cybersecurity and Infrastructure Security Agency (CISA) and the UK's National Cyber Security Centre (NCSC) have identified new malware targeting Cisco Firepower and Secure Firewall products running Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software. This discovery means organisations need to take additional steps to protect their networks. CISA advises that the malicious activity likely began before or early 2024. Australian organisations should check their devices for this newly identified malware and apply patches. Note, if a device was previously compromised, the malware may have persisted through patching of previous CVEs. Read the full alert here 👉 https://lnkd.in/gun__DxG

    • No alternative text description for this image
  • Plural Cyber reposted this

    ❗ UPDATED ALERT ❗ We are aware of increased targeting of online code repositories. This alert is relevant to all Australians and organisations, including organisation leaders, that maintain online code repositories, publish public software packages, or use third party packages or software sourced from online repositories. In particular, the compromise of trusted software packages presents a significant and ongoing risk for organisations. These packages are often widely used and embedded as dependencies within other software, increasing the potential impact when vulnerabilities are identified. To manage this risk effectively, organisations must be able to rapidly identify which software packages - and which versions - are installed across their environments. This information should be accurately collected, maintained, and readily accessible. Read the updated alert 👉 https://lnkd.in/gv-ugJJ8

    • No alternative text description for this image
  • Plural Cyber reposted this

    ❗ ALERT ❗ We are aware of malicious cyber threat actors targeting Cisco SD-WANs of organisations, globally. These actors exploited a Cisco Catalyst SD-WAN controller authentication bypass vulnerability, CVE-2026-20127. After exploitation of this vulnerability the malicious actors add a rogue peer, and eventually gain root access to establish long-term persistence in SD-WANs. Along with our international partners National Security Agency, Cybersecurity and Infrastructure Security Agency, Communications Security Establishment Canada | Centre de la sécurité des télécommunications Canada, National Cyber Security Centre and National Cyber Security Centre we have released a Cisco SD-WAN Threat Hunt Guide (the Hunt Guide) based on investigative data, to support network defenders’ detection of and response to the malicious actors’ threat activity. Read the full alert and the Hunt Guide 👉 https://lnkd.in/gCBeKgbB

    • No alternative text description for this image

Similar pages