Threats Affecting Australia
View all threats affecting or targeting Australia. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Australia
Click on any threat for detailed analysis and mitigation recommendations
Fake CAPTCHA, Real Business: Traffic Distribution for Hire 0 A sophisticated traffic distribution system has been operating for over 14 months, using more than 12,700 structurally similar fake CAPTCHA PDFs hosted on Webflow's CDN. The operation begins with search engine optimization, where victims searching for legitimate content encounter malicious PDFs through Google searches. These documents contain fake CAPTCHA panels that route users through a custom Elixir/Phoenix traffic distribution system employing IP filtering, bot detection, and geographic targeting. The infrastructure sorts visitors and redirects qualifying traffic to three distinct endpoints: Legion Loader distribution, a TDS reseller gate, and premium-SMS subscription scams targeting Spanish-speaking users. Non-qualifying traffic is monetized through search-arbitrage advertising. The operation primarily targets English-speaking countries and has recently been surfaced by AI assistants including Google Gemini and Claude, expanding its reach beyond traditional search engines. MediumMalware Join the discussion | AlienVault OTX General | 08/05/2026, 14:36:07 UTC Added: 08/06/2026, 08:56:14 UTC |
Phishing service spoofs RingCentral to steal Microsoft 365 accounts 0 The Greatness phishing-as-a-service (PhaaS) platform targets Microsoft 365 accounts using advanced phishing techniques including adversary-in-the-middle and device-code phishing. It spoofs RingCentral emails to bypass email security filters by exploiting whitelisting and safe-sender list trust. Post-compromise, attackers access Microsoft 365 data and services via stolen authentication tokens. The platform is sold to cybercriminals and has been active since at least mid-2022, targeting users in multiple countries. Researchers recommend auditing safe-sender lists and monitoring suspicious MFA-approved sign-ins. Join the discussion | Bleeping Computer | 08/04/2026, 21:45:36 UTC Added: 08/04/2026, 22:02:01 UTC |
ZDI-26-523: Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution VulnerabilityCVE-2026-15679 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face PyTorch Image Models. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-15679. Join the discussion | Zero Day Initiative | 07/30/2026, 05:00:00 UTC Added: 07/31/2026, 01:36:50 UTC |
ZDI-26-453: GIMP HDR File Parsing Integer Overflow Remote Code Execution VulnerabilityCVE-2026-18300 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18300. Join the discussion | Zero Day Initiative | 07/29/2026, 05:00:00 UTC Added: 07/30/2026, 15:59:04 UTC |
ZDI-26-454: GIMP PSD File Parsing Integer Overflow Remote Code Execution VulnerabilityCVE-2026-18301 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18301. Join the discussion | Zero Day Initiative | 07/29/2026, 05:00:00 UTC Added: 07/30/2026, 15:59:04 UTC |
ZDI-26-455: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityCVE-2026-18302 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18302. Join the discussion | Zero Day Initiative | 07/29/2026, 05:00:00 UTC Added: 07/30/2026, 15:59:04 UTC |
ZDI-26-456: GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityCVE-2026-18303 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18303. Join the discussion | Zero Day Initiative | 07/29/2026, 05:00:00 UTC Added: 07/30/2026, 15:59:04 UTC |
ZDI-26-457: GIMP TIF File Parsing Integer Overflow Remote Code Execution VulnerabilityCVE-2026-18304 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18304. Join the discussion | Zero Day Initiative | 07/29/2026, 05:00:00 UTC Added: 07/30/2026, 15:59:04 UTC |
ZDI-26-458: GIMP TIF File Parsing Integer Overflow Remote Code Execution VulnerabilityCVE-2026-18305 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18305. Join the discussion | Zero Day Initiative | 07/29/2026, 05:00:00 UTC Added: 07/30/2026, 15:59:04 UTC |
ZDI-26-459: GIMP SGI File Parsing Integer Overflow Remote Code Execution VulnerabilityCVE-2026-18306 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18306. Join the discussion | Zero Day Initiative | 07/29/2026, 05:00:00 UTC Added: 07/30/2026, 15:59:04 UTC |
Showing 1 to 10 of 20 results