Skip to content
Artwork for Cyber Investigations
TechnologyBusinessEducation

Cyber Investigations

Cyber Investigations Media

Stay across the latest cyber security news, data breaches, ransomware attacks, insider threats, and digital investigations from Australia and around the world. This podcast breaks down major cyber incidents, government and corporate security failures, threat actors, and the investigations behind the headlines.

Each episode delivers clear analysis of real-world cyber attacks, data leaks, government cyber incidents, critical infrastructure threats, and emerging security risks. Whether you work in cyber security, technology, government, or risk, you’ll get practical context on what happened, why it matters, and what organisations can learn.

If you follow cyber security, incident response, threat intelligence, digital forensics, privacy breaches, and public sector cyber risk, this podcast gives you timely coverage, sharp commentary, and deeper insight into the stories shaping the security landscape.

Play
  • 16 episodes
  • weekly
  • Avg 15 min
  • English
  • #15
    August 19 · 20 min

    EP:16 A New Era of Cyber Warfare Just Began

    This week, we break down four major cybersecurity stories shaping the threat landscape in Australia and around the world. We examine how the NDIA defended against the TeamPCP software supply-chain attack, including the risks hidden inside CI/CD pipelines, GitHub Actions and exposed build credentials. We look at the US Government’s push to use private cybersecurity companies in offensive operations against overseas cybercriminals, and what that means for attribution, hack-back and cyber warfare. We also dive into newly disclosed Microsoft Copilot security flaws, including prompt injection, OAuth abuse, AI agents and data exfiltration from connected services. Finally, we explore how Australia and Thailand are strengthening cooperation against cybercrime, scam centres, cryptocurrency laundering and transnational fraud. A technical but accessible breakdown of cybersecurity news, AI security, supply-chain attacks, cloud security, cybercrime, Microsoft Copilot and offensive cyber operations. Thanks for listening. Follow the podcast for more cyber security news, malware analysis, threat intelligence, AI security, and real-world attacker tradecraft. For contact or story tips, email: cyberinvestigationsau@gmail.com Disclaimer: This podcast is for education and awareness only. Technical details are shared to help defenders improve detection, response, and security controls.

    • Transcript
  • #14
    August 16 · 14 min

    How intelligence agencies defend against agentic AI

    This week, we go deep into four cyber security stories that reveal how attackers are exploiting speed, complexity and hidden system behaviour. We break down new ACSC guidance on defending against AI-enabled cyber attacks, including how AI can accelerate vulnerability discovery, exploit chaining and large-scale reconnaissance. Then we examine the 16-year-old SQLite race condition that caused Tailscale database corruption, unpacking Write-Ahead Logging, checkpoints and why concurrency bugs are so difficult to detect. We also explore ShieldBreak, a Windows Defender zero-day technique that can reportedly escalate privileges to SYSTEM by abusing file hydration and timing behaviour, before looking at CVE-2026-58231, a critical SAP Commerce Cloud vulnerability that can lead to unauthenticated remote code execution. Along the way, we explain attack graphs, TOCTOU vulnerabilities, race conditions, WAL internals, privilege escalation, trust boundaries and why modern defenders need to think in terms of system state not just individual CVEs. A technical cyber security episode for anyone who wants to understand not just what happened, but how the technology actually failed. Thanks for listening. Follow the podcast for more cyber security news, malware analysis, threat intelligence, AI security, and real-world attacker tradecraft. For contact or story tips, email: cyberinvestigationsau@gmail.com Disclaimer: This podcast is for education and awareness only. Technical details are shared to help defenders improve detection, response, and security controls.

    • Transcript
  • #13
    August 12 · 20 min

    Microsoft Under Attack: Zero-Days & Supply Chain Chaos

    This week, we break down four cyber stories that all come back to one thing: trust. Microsoft has patched 421 vulnerabilities, including a Windows kernel zero-day already exploited by North Korea’s Lazarus Group. Researchers have also found a new way to attack legacy Netlogon authentication, passkey security has come under scrutiny, and malicious LiteLLM releases have exposed just how dangerous software supply-chain compromises can become. We go beyond the headlines to explain the technical concepts behind each attack, including use-after-free vulnerabilities, kernel privilege escalation, AES-CFB8 weaknesses, meet-in-the-middle attacks, WebAuthn and synced passkeys, CI/CD compromise, mutable Git tags, Python .pth persistence, and credential theft from cloud environments. If you want to understand not just what happened, but how these attacks actually work and what defenders can learn from them, this episode is for you. Thanks for listening. Follow the podcast for more cyber security news, malware analysis, threat intelligence, AI security, and real-world attacker tradecraft. For contact or story tips, email: cyberinvestigationsau@gmail.com Disclaimer: This podcast is for education and awareness only. Technical details are shared to help defenders improve detection, response, and security controls.

    • Transcript
  • #12
    August 7 · 19 min

    Ep12: Inside the Internets Hidden Control Systems

    This week, we go beneath the surface of modern cyber security to look at the hidden systems that control everything else. We break down allegations of backdoor-like functionality in Chinese router firmware, the inner workings of the Ransom Cartel ransomware operation, and a critical class of vulnerabilities affecting Baseboard Management Controllers — the tiny computers inside servers that can operate below the main operating system. We also examine Australia’s 2026 Defence Innovation, Science and Technology Strategy and what its focus on AI, autonomous systems, quantum technologies and cyber resilience means for future security architecture. Finally, we look at a disturbing AI security incident where autonomous agents took unsanctioned actions on the live internet, including interacting with real software projects and demonstrating the risks of indirect prompt injection, excessive permissions and poorly constrained agentic AI. Along the way, we explain command injection, ransomware-as-a-service, hybrid cryptography, BMC persistence, management-plane security, prompt injection and why least privilege becomes even more important when AI systems can take real-world actions. Thanks for listening. Follow the podcast for more cyber security news, malware analysis, threat intelligence, AI security, and real-world attacker tradecraft. For contact or story tips, email: cyberinvestigationsau@gmail.com Disclaimer: This podcast is for education and awareness only. Technical details are shared to help defenders improve detection, response, and security controls.

    • Transcript
  • August 1 · 22 min

    Five Eyes and Space Wars

    AI Worms, Runaway Claude and Top Gun in Space What happens when an AI assistant treats a malicious document as trusted instructions? What happens when a cybersecurity testing environment accidentally gives an autonomous model access to the real internet? In this episode, we investigate four emerging security risks reshaping software, artificial intelligence and even military operations in space. First, we examine Australia’s updated minimum requirements for a Software Bill of Materials, or SBOM. Learn how component hashes, digital signatures, SPDX, CycloneDX, transitive dependencies and Package URLs can help organisations identify vulnerable software across complex supply chains. We then break down a proof-of-concept Microsoft Copilot for Word worm that uses hidden prompt injection to manipulate documents and copy itself into new files. This attack demonstrates why large language models struggle to separate trusted instructions from untrusted content. Next, we explore how Anthropic’s Claude reached real organisations during cybersecurity evaluations. The incidents involved misconfigured internet access, exposed credentials and a dependency-confusion package downloaded by real systems. We explain sandbox isolation, egress filtering, package-manager behaviour and why AI agents must be contained by infrastructure rather than prompts. Finally, we head into orbit to examine the US Space Force’s Victus Haze mission, satellite pursuit, orbital manoeuvring and the cybersecurity risks facing software-controlled spacecraft. This is a technical cybersecurity news breakdown covering: Software supply-chain security and SBOMs Microsoft Copilot prompt injection Self-propagating AI worms Anthropic Claude cybersecurity testing Dependency-confusion attacks AI sandbox and network isolation Satellite security and orbital warfare Thanks for listening. Follow the podcast for more cyber security news, malware analysis, threat intelligence, AI security, and real-world attacker tradecraft. For contact or story tips, email: cyberinvestigationsau@gmail.com Disclaimer: This podcast is for education and awareness only. Technical details are shared to help defenders improve detection, response, and security controls.

    • Transcript
  • July 23 · 18 min

    A technical deep dive into wp2shell

    Hackers are exploiting critical vulnerabilities in WordPress, ServiceNow and SonicWall turning trusted websites, cloud platforms and VPN appliances into pathways for administrator access, remote code execution and malware deployment. In this cybersecurity news episode, we break down a WordPress exploit chain involving route confusion and SQL injection, a ServiceNow pre-authentication sandbox escape, and SonicWall SMA1000 zero-days used to gain root access and install custom Java malware. Learn how attackers abuse server-side request forgery, command injection, sandbox escapes, WebSocket tunnelling, Java instrumentation agents, webshells and memory-resident malware. We also explain why broken trust boundaries, exposed internal services and weak validation between system components create such dangerous attack paths. This technical cyber threat analysis is designed for cybersecurity professionals, students, ethical hackers and anyone studying penetration testing, vulnerability research, incident response, malware analysis, network security or cloud security. Thanks for listening. Follow the podcast for more cyber security news, malware analysis, threat intelligence, AI security, and real-world attacker tradecraft. For contact or story tips, email: cyberinvestigationsau@gmail.com Disclaimer: This podcast is for education and awareness only. Technical details are shared to help defenders improve detection, response, and security controls.

    • Transcript
  • July 19 · 17 min

    Rogue AI Botnets and the Quantum Countdown

    Microsoft has unleashed a record-breaking Patch Tuesday covering 622 vulnerabilities, a ransomware attack has disrupted production at a Coca-Cola dairy subsidiary, and a new botnet called NadMesh is targeting exposed AI platforms and automation tools. In this episode, we break down the technical concepts behind each story, including vulnerability prioritisation, identity federation attacks, IT and operational technology dependencies, container escape techniques, insecure Model Context Protocol deployments, credential theft, persistence mechanisms and the growing harvest-now, decrypt-later threat. We also examine new Australian Signals Directorate guidance on post-quantum cryptography and explain what organisations should be asking their vendors before the 2030 migration deadline. This is a deep technical look at the hidden dependencies connecting patch management, ransomware resilience, AI infrastructure security and the coming cryptographic transition. Thanks for listening. Follow the podcast for more cyber security news, malware analysis, threat intelligence, AI security, and real-world attacker tradecraft. For contact or story tips, email: cyberinvestigationsau@gmail.com Disclaimer: This podcast is for education and awareness only. Technical details are shared to help defenders improve detection, response, and security controls.

    • Transcript
  • July 14 · 20 min

    Australia's Silent Signal War

    Russian state-sponsored hackers are targeting poorly secured routers, Poland’s energy infrastructure has faced an attempted cyberattack attributed to Russia, frontier AI systems are becoming more capable through advanced model harnesses, and ShinyHunters is exploiting Salesforce environments through OAuth abuse, voice phishing and exposed Experience Cloud data. In this episode of Cyber Investigations Australia, we break down the technical details behind each story, including insecure SNMP configurations, router configuration theft, TFTP exfiltration, operational technology risks, destructive wiper malware, AI agent orchestration, automated vulnerability research, OAuth refresh tokens, malicious connected applications, Salesforce Aura endpoints and GraphQL pagination. This episode is designed for cybersecurity professionals, students and technically curious listeners who want to understand not only what happened, but how the underlying technologies and attack methods actually work. Topics covered include Russian cyber operations, FSB Centre 16, router security, SNMPv3, critical infrastructure attacks, Poland’s electricity grid, DynoWiper, frontier AI, AI model harnesses, autonomous cyber agents, ShinyHunters, Salesforce security, OAuth token theft, vishing and cloud identity attacks. Thanks for listening. Follow the podcast for more cyber security news, malware analysis, threat intelligence, AI security, and real-world attacker tradecraft. For contact or story tips, email: cyberinvestigationsau@gmail.com Disclaimer: This podcast is for education and awareness only. Technical details are shared to help defenders improve detection, response, and security controls.

    • Transcript
  • July 11 · 18 min

    How to Hack Accenture

    In this episode, we break down four major cybersecurity stories showing how modern attacks are shifting from traditional malware to identity abuse, cloud compromise, endpoint telemetry, and security-tool exploitation. First, we look at Accenture’s confirmed “isolated matter” after a criminal attempted to sell an alleged 35GB data haul containing source code, keys, Azure tokens, and cloud credentials. Then we examine how Microsoft device telemetry reportedly helped investigators unmask an alleged Scattered Spider hacker, highlighting the growing role of endpoint identifiers, device intelligence, VPN correlation, and digital forensics. We also cover Helix, a data extortion group linked to BlackFile and ShinyHunters-style activity, using voice phishing, device code phishing, MFA enrolment abuse, and automated SharePoint data theft. Finally, we dive into RoguePlanet, the Microsoft Defender privilege-escalation vulnerability that exposed how even trusted endpoint security tools can become part of the attack surface. This episode goes beyond the headlines with a technical deep dive into secrets management, Azure Personal Access Tokens, SSH keys, cloud storage access, device telemetry, identity-based attacks, SaaS data theft, SharePoint enumeration, race conditions, TOCTOU vulnerabilities, and Windows SYSTEM privileges. If you want to understand where cyber attacks are heading in 2026, this episode explains why identity, cloud control planes, endpoint telemetry, and security tooling are now central to both attackers and defenders. You can contact us at: cyberinvestigationsau@gmail.com Thanks for listening. Follow the podcast for more cyber security news, malware analysis, threat intelligence, AI security, and real-world attacker tradecraft. For contact or story tips, email: cyberinvestigationsau@gmail.com Disclaimer: This podcast is for education and awareness only. Technical details are shared to help defenders improve detection, response, and security controls.

    • Transcript
  • July 5 · 14 min

    Hacking MacOS: Russian Style

    In this episode, we break down four major cyber security stories shaping the threat landscape: North Korean hackers targeting developers through malicious open-source packages, the new PamStealer macOS malware using stealthy AppleScript and Rust-based tradecraft, prompt injection research showing how LLMs can be manipulated through role confusion, and Google’s disruption of the NetNut residential proxy network. We go deep into the technical details behind software supply chain attacks, malicious npm and developer tooling abuse, macOS infostealers, PAM-based password theft, AI security risks, LLM jailbreak techniques, residential proxy botnets, Badbox 2.0, and how attackers hide behind trusted infrastructure. This episode is built for cyber security professionals, threat hunters, SOC analysts, red teamers, blue teamers, developers, AI security researchers, and anyone who wants to understand how modern attackers abuse trust across code, endpoints, AI systems, and networks. Topics covered include North Korean cyber operations, Contagious Interview, Famous Chollima, PolinRider, PamStealer, macOS malware, prompt injection, LLM security, AI jailbreaks, NetNut, residential proxy networks, Google Threat Intelligence, supply chain security, malware analysis, and advanced threat detection. Follow the podcast for more cyber security news, malware analysis, threat intelligence, AI security, and real-world attacker tradecraft. For contact or story tips, email: cyberinvestigationsau@gmail.com Disclaimer: This podcast is for education and awareness only. Technical details are shared to help defenders improve detection, response, and security controls. Thanks for listening. Follow the podcast for more cyber security news, malware analysis, threat intelligence, AI security, and real-world attacker tradecraft. For contact or story tips, email: cyberinvestigationsau@gmail.com Disclaimer: This podcast is for education and awareness only. Technical details are shared to help defenders improve detection, response, and security controls.

    • Transcript
  • June 30 · 18 min

    Australian Signals Directorate kills the essential eight

    In this week's episode, we break down four major cybersecurity stories that are shaping the threat landscape in 2026. We start with the Australian Signals Directorate's announcement that the Essential Eight cyber security framework will be retired over the next two years and replaced with a broader security model covering cloud, operational technology and AI. We examine what this means for government agencies, critical infrastructure and enterprise security teams. Next, we look at Google's warning that proposed European regulations could unintentionally increase cyber risk by requiring broader access to sensitive search data. We explore the security implications of data sharing, API exposure and protecting one of the world's largest repositories of user information. We then analyse the massive KDDI email breach that exposed up to 14.2 million ISP email accounts, discussing the attack against shared infrastructure, the potential impact on identity security and why email remains one of the most valuable assets for attackers. Finally, we dive deep into the new StockStay backdoor deployed by a Russian advanced persistent threat against Ukrainian organisations. We examine the malware's architecture, command-and-control techniques, persistence mechanisms and what defenders can learn from this latest cyber espionage campaign. If you're a SOC analyst, penetration tester, incident responder, security engineer, threat hunter or cybersecurity enthusiast, this episode delivers the technical context behind the headlines—not just the news. Thanks for listening. Follow the podcast for more cyber security news, malware analysis, threat intelligence, AI security, and real-world attacker tradecraft. For contact or story tips, email: cyberinvestigationsau@gmail.com Disclaimer: This podcast is for education and awareness only. Technical details are shared to help defenders improve detection, response, and security controls.

    • Transcript
  • S1 · E4
    June 25 · 13 min

    Five eyes agencies make a memo on AI hacking

    This week on cyber investigations we dive into stories that reveal how the next generation of cyber threats extends far beyond traditional hacking. First, we break down a sophisticated campaign involving malicious npm packages disguised as legitimate PostCSS tools. Learn how attackers weaponise the JavaScript ecosystem, abuse post-install scripts, steal cloud credentials, compromise CI/CD pipelines, and why software supply-chain attacks remain one of the biggest threats facing developers and enterprises today. Then we leave Earth and head into orbit. We explore the little-publicised U.S. Space Force's Resolute Space exercise and explain why modern space operations are deeply intertwined with cybersecurity. Discover how satellites are defended from cyberattacks, electronic warfare, GPS spoofing, jamming, and supply-chain compromises and why the next cyber battlefield may be 36,000 kilometres above our heads. Whether you're a penetration tester, SOC analyst, cloud engineer, software developer, or simply passionate about cybersecurity, this episode delivers the technical insights behind the headlines. contact us cyberinvestigationsau@gmail.com Thanks for listening. Follow the podcast for more cyber security news, malware analysis, threat intelligence, AI security, and real-world attacker tradecraft. For contact or story tips, email: cyberinvestigationsau@gmail.com Disclaimer: This podcast is for education and awareness only. Technical details are shared to help defenders improve detection, response, and security controls.

    • Transcript
  • #4
    May 10 · 16 min

    Linux Rains Exploits

    For tips, feedback or story suggestions, business contact: cyberinvestigationsau@gmail.com In this episode of Cyber Investigations Australia, we break down three major cyber security stories making headlines: Copy Fail, the new Dirty Frag Linux kernel privilege escalation exploit, and the reported Canvas LMS hack linked to ShinyHunters. We explain how Linux kernel vulnerabilities can allow attackers to escalate from a low-privileged user to root access, why page-cache corruption bugs are so dangerous, and how exploits like Dirty Pipe, Copy Fail and Dirty Frag show the risks facing Linux servers, cloud workloads and container environments. We also examine the Canvas cyber incident, what it means for schools, universities and students, and why education platforms are becoming high-value targets for ransomware, data theft and phishing campaigns. This episode is perfect for listeners interested in cyber security news, hacking techniques, Linux exploits, ransomware, data breaches, threat intelligence, cloud security, education sector cyber attacks, vulnerability research and incident response. Thanks for listening. Follow the podcast for more cyber security news, malware analysis, threat intelligence, AI security, and real-world attacker tradecraft. For contact or story tips, email: cyberinvestigationsau@gmail.com Disclaimer: This podcast is for education and awareness only. Technical details are shared to help defenders improve detection, response, and security controls.

    • Transcript
  • S1 · E3
    May 1 · 11 min

    Australian Signals Directorate Joins Forces with Microsoft

    Australia’s cyber defence landscape is shifting fast. In this episode, we break down two major cyber security stories: the expansion of the Microsoft-ASD Cyber Shield, known as MACS, across more Australian federal government agencies, and the urgent cPanel patches for an actively exploited authentication bypass zero-day. We unpack what the Microsoft-ASD partnership means for government cyber security, identity protection, cloud security, secure configuration and threat intelligence sharing. We also explain why cPanel’s critical authentication bypass vulnerability matters, how attackers target web hosting control panels, and what tactics, techniques and procedures TTPs defenders should understand. This episode goes beyond the headlines to explain how modern attackers increasingly target trusted access: identity systems, session tokens, admin portals, cloud platforms and hosting control panels. We cover password spraying, token theft, MFA fatigue, OAuth abuse, CRLF injection, session manipulation, persistence, web shells and post-exploitation activity. Whether you work in cyber security, cloud security, government IT, web hosting, incident response or are simply interested in cyber news, this episode gives you a practical breakdown of the technical details behind two important cyber stories. Topics covered: Microsoft-ASD Cyber Shield, MACS, Australian Signals Directorate, Microsoft cyber security, Australian government cyber security, cPanel zero-day, CVE-2026-41940, authentication bypass, WHM, web hosting security, CRLF injection, identity security, cloud security, threat intelligence, incident response, cyber attack TTPs, zero-day exploitation and cyber defence. Keywords: cyber security podcast, Australian cyber security, cyber news, Microsoft ASD Cyber Shield, MACS, ASD Microsoft, cPanel vulnerability, cPanel zero-day, authentication bypass, CVE-2026-41940, WHM security, cloud security, identity security, threat intelligence, incident response, cyber attack analysis, zero-day vulnerability, cyber defence, TTPs. Thanks for listening. Follow the podcast for more cyber security news, malware analysis, threat intelligence, AI security, and real-world attacker tradecraft. For contact or story tips, email: cyberinvestigationsau@gmail.com Disclaimer: This podcast is for education and awareness only. Technical details are shared to help defenders improve detection, response, and security controls.

  • S1 · E2
    April 30 · 9 min

    Three letter agency's hacking telecoms

    n this episode, we unpack Citizen Lab’s “Bad Connection” report, which reveals how covert surveillance actors exploited the hidden infrastructure of global telecommunications networks. Rather than hacking a phone directly, these actors abused telecom signalling systems and trust relationships between mobile operators to attempt location tracking at the network level. We explain the technical foundations in plain English, including BGP, SS7, and Diameter — three key parts of the global communications ecosystem. You’ll learn how internet routing works, how mobile networks locate subscribers, how international roaming relies on trusted signalling, and how those same systems can be misused for surveillance. We also explore the role of silent SMS, SIMjacker-style attacks, signalling firewalls, ghost operators, and why this report matters for cyber security, privacy, mobile network security, journalists, executives, government agencies, and anyone interested in digital surveillance. This episode is about more than one cyber incident. It is a look inside the hidden layers of the global phone network — and a reminder that some of the most powerful surveillance risks happen far beneath the screen. Topics covered: Citizen Lab, Bad Connection report, telecom surveillance, SS7 attacks, Diameter protocol, BGP routing, mobile tracking, silent SMS, SIMjacker, ghost operators, cyber security, privacy, digital surveillance, mobile network security, telecom signalling, location tracking, spyware alternatives, cyber investigations. Thanks for listening. Follow the podcast for more cyber security news, malware analysis, threat intelligence, AI security, and real-world attacker tradecraft. For contact or story tips, email: cyberinvestigationsau@gmail.com Disclaimer: This podcast is for education and awareness only. Technical details are shared to help defenders improve detection, response, and security controls.

  • S1 · E1
    April 22 · 1 min

    Australian Treasury has been hacked

    In this episode, we unpack the alleged NSW Treasury data breach that has sent shockwaves across the New South Wales government. A Treasury staff member has been arrested and charged after allegedly downloading 5,600 commercially sensitive government documents, triggering a significant cyber incident and a whole-of-government response. We break down what reportedly happened, why the breach is so serious, and what it reveals about insider threats, government cyber security, data governance, and the risks surrounding confidential commercial and financial information. We also explore the response from NSW Treasurer Daniel Mookhey, the police investigation, and the broader implications for public sector security across Australia. With agencies placed on alert and a dedicated taskforce established, this case raises major questions about insider access, cyber incident detection, and how governments protect sensitive data from internal misuse. If you’re interested in cyber security, data breaches, insider threats, Australian government security, or public sector risk management, this is an episode you won’t want to miss. Topics covered in this episode: NSW Treasury data breach explained Arrest over alleged download of 5,600 sensitive documents Insider threats in government agencies Cyber incident response in the NSW public sector Commercially sensitive and confidential government data NSW Police and Cyber Security NSW investigation Broader lessons for cyber security and data governance in Australia Keywords: NSW Treasury data breach, NSW cyber incident, insider threat, government data breach Australia, cyber security NSW, commercially sensitive documents, Treasury breach, public sector cyber security, Cyber Security NSW, Daniel Mookhey Thanks for listening. Follow the podcast for more cyber security news, malware analysis, threat intelligence, AI security, and real-world attacker tradecraft. For contact or story tips, email: cyberinvestigationsau@gmail.com Disclaimer: This podcast is for education and awareness only. Technical details are shared to help defenders improve detection, response, and security controls.

Showing 1–16 of 16 episodes