CyberPulse

CyberPulse We are leaders in the space of Governance, Risk and Compliance (GRC), security advisory, consulting and pe*******on testing.

We partner in your Cybersecurity journey!!

The download button is the whole intrusion in this one.Microsoft published research on 1 September 2026 on an active cam...
03/09/2026

The download button is the whole intrusion in this one.

Microsoft published research on 1 September 2026 on an active campaign that builds convincing copies of vendor download pages, then serves a malicious installer to whoever clicks. The impersonated list includes Microsoft Edge, Kaspersky, draw.io and Calibre. Microsoft says the affected devices it observed sit predominantly in the China-based operations of multinational organisations and with Chinese-speaking users, in healthcare, manufacturing, logistics, government and higher education.

Once the file runs, it adds sweeping Microsoft Defender exclusions, deletes the volume shadow copies you would recover from, disables the Windows Update services, then hides its persistence in scheduled tasks with names that read like ordinary IT jobs.

Blocking the file does not work either. The archive keeps its name while the hash changes on every download, so there is nothing stable to put on a list.

The control that helps is Defender Tamper Protection, because it blocks those exclusion writes even when the malware is running as SYSTEM. Worth checking whether it is on across your fleet, and whether anyone would see the alert if it fired.

What does ISO 27001 actually cost in Australia?Our 2026 cost guide puts first-year totals at $18,000 to $35,000 for orga...
02/09/2026

What does ISO 27001 actually cost in Australia?

Our 2026 cost guide puts first-year totals at $18,000 to $35,000 for organisations under 25 staff, $35,000 to $75,000 for 25 to 250 staff, and $75,000 to $150,000 or more for large or complex environments. Ongoing annual costs sit between $5,000 and $15,000 for most, and higher for complex environments. Indicative figures, not a quote.

Scope is the variable you control. A scope drawn around one product line costs less to build, less to audit and less to maintain. Existing Essential Eight or SOC 2 work is evidence you can reuse.

One warning worth repeating: a very low quote usually covers the audit fee alone, with readiness and internal audit left out.

A draft bill released on 31 August would put a fixed 72-hour clock on reporting a data breach to the Privacy Commissione...
02/09/2026

A draft bill released on 31 August would put a fixed 72-hour clock on reporting a data breach to the Privacy Commissioner. The Privacy Act currently says as soon as practicable. Consultation closes 18 September.

The detail that matters for a business: the 30-day window to assess a suspected breach is not changing, and it was never the reporting deadline. The 72 hours begin the moment someone in your organisation has reasonable grounds to believe a notifiable breach has happened. That is a judgement call, and in most businesses nobody has been told it is theirs to make.

The draft does allow an incomplete report, in writing, explaining what is missing and why. So holding off until you have the full story is the wrong instinct.

Worth doing this month: decide who makes that call, and have the report fields ready before you need them.

Attackers are aiming at people, not just systems. Business email compromise targets finance and procurement. Fake login ...
01/09/2026

Attackers are aiming at people, not just systems. Business email compromise targets finance and procurement. Fake login pages copy the Microsoft 365 sign-in screen. Spear phishing quotes a real project, because the details were public.

The tell most staff were taught to look for has gone. AI-written messages do not carry spelling errors, and synthetic voice is being used to impersonate executives on calls.

What still works: train by role rather than one generic module, run phishing simulation continuously and coach rather than punish, and set one rule for money, that any change to bank details is confirmed on a number you already held.

The print server is not usually the first thing on a patch list. This week it should be.PaperCut published an urgent sec...
01/09/2026

The print server is not usually the first thing on a patch list. This week it should be.

PaperCut published an urgent security bulletin on 27 August 2026 and says it is aware of confirmed customer incidents. On 31 August, CISA added both flaws to its Known Exploited Vulnerabilities catalog. The advisory applies to all versions of PaperCut NG and PaperCut MF.

PaperCut has also published what the attackers did once inside. They listed the domain controllers 4 minutes in. At 21 minutes and 29 seconds they had a Windows service named Remote Access Service running as LocalSystem. Six minutes later they pulled down AnyDesk. That is a foothold with remote control on it, from a printing box.

If your PaperCut Application Server can be reached from the internet, restrict it to trusted IP addresses today, then install Emergency Patch Release 2. It replaces the first emergency patch, and your site servers and secondary print servers need it as well. Anything on v23 or earlier has no patch at all.

Cyber risk is often filed as a subset of IT risk. It is worth separating them, because the filing decides who is account...
31/08/2026

Cyber risk is often filed as a subset of IT risk. It is worth separating them, because the filing decides who is accountable.

IT risk is about whether systems work: outages, failed upgrades, ageing hardware. Predictable, internally driven, and well managed by technology teams.

Cyber risk has someone on the other side of it, actively adapting to your controls. The consequences show up as financial loss, regulatory attention, failed contracts and lost customer confidence.

Merge the two and boards end up reading control counts instead of business impact. Separate them, give cyber risk a named executive owner, and report it the way you already report credit or safety risk.

Some attacks do not break in. They ask nicely, and someone helpful says yes.Microsoft published research on 28 August 20...
31/08/2026

Some attacks do not break in. They ask nicely, and someone helpful says yes.

Microsoft published research on 28 August 2026 on the TerminalFix campaign. A compromised website shows a fake Cloudflare verification box and asks the visitor to copy a command and paste it in. Older versions of this trick used the Run dialog. This one points people at Windows Terminal or PowerShell, because longer scripts run properly there.

From that single paste, a signed Microsoft binary loads a malicious DLL, a payload gets pulled out of PNG images, scheduled tasks restart it every 60 minutes, and the attacker opens a quiet tunnel out that Microsoft says looks like ordinary encrypted web traffic.

No vulnerability was exploited, so there is nothing to patch here. The controls that help are restricting what PowerShell can do for standard users, logging what it runs, and making sure staff know that no verification page ever needs a command pasted into a terminal.

Application control is one of the ASD's Essential Eight, and at Maturity Level One it has to block, not just log. That s...
31/08/2026

Application control is one of the ASD's Essential Eight, and at Maturity Level One it has to block, not just log. That step is where rollouts stall. Enforcement creates a queue: someone needs a tool that is not on the list, a vendor update changes a binary, and a decision has to be made quickly or work stops.

CyberPulse is an authorised ThreatLocker reseller, and we deliver it fully managed. We build the allowlist, ringfence what is approved, maintain the policy, and handle the approval requests day to day.

If allowlisting has stalled at your place, or you are scoping it for the first time, talk to us.

Microsoft 365 arrives with default settings, and most Australian organisations never move past them. Microsoft secures t...
30/08/2026

Microsoft 365 arrives with default settings, and most Australian organisations never move past them. Microsoft secures the platform. Identity, access and data configuration are yours.

Four changes cover most of the risk. Enforce multi-factor authentication through Conditional Access rather than the old per-user setting. Turn off legacy authentication, because SMTP, POP3 and IMAP bypass Conditional Access and MFA entirely. Cut Global Administrator back to two or three break-glass accounts. Put Microsoft Defender for Office 365 in blocking mode, and extend Safe Links and Safe Attachments to SharePoint, OneDrive and Teams.

Then export the baseline and check the tenant against it on a schedule. Configuration drift is what undoes good work six months later.

A browser extension your team approved two years ago can turn malicious without anyone touching it.Socket published rese...
30/08/2026

A browser extension your team approved two years ago can turn malicious without anyone touching it.

Socket published research on 27 August 2026 on 19 extensions in the Chrome and Edge stores that steal logins, session cookies, form data, Facebook business account tokens, LinkedIn sessions and full browser history. Fourteen were built by the attacker. Five were genuine extensions bought from their original authors. The biggest, Enable Right Click and Copy, was made by an organisation called PreppHint and had roughly 70,000 Chrome users and 10,000 on Edge before it changed owners. Existing users just received an update.

Google has pulled the Chrome version. Socket says the Edge copy was still live and serving malware when it published.

The practical step: use Chrome Enterprise or Edge policy to limit staff to an approved list of extensions, then look at what is already installed across your fleet. Most organisations have never checked.

Address

11 York Street
Sydney, NSW
2000

Opening Hours

Monday 9am - 5:30pm
Tuesday 9am - 5:30pm
Wednesday 9am - 5:30pm
Thursday 9am - 5:30pm
Friday 9am - 5:30pm

Alerts

Be the first to know and let us send you an email when CyberPulse posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share