#NSBCS.145 - From the desk of the CEO: The AI Apocalypse Can Wait. Cyber Can’t.

 

You could be forgiven for thinking that everything we know about cyber is about to change. AI-powered attacks. Autonomous SOCs. Agentic security. AI versus AI. The end of traditional security operations. Depending on what you read, we’re either standing at the beginning of a new golden age of cyber defence or staring down an AI apocalypse.

Maybe we are. But I think we need to keep some perspective.

AI is most certainly going to change how we defend our businesses, how attackers operate and how quickly both sides can move. It is already doing that. I’m excited about what it can do, and I think we should be embracing that. Many organisations already are.

But after more than 20 plus years working in and around cyber security, my guess based on my own lived experiences across thousands of cyber incidents, is that a significant number of Australian businesses still aren’t consistently doing the cyber fundamentals well. Not even close to well, and certainly not consistently.

Not because businesses don’t care, but because cyber is hard. Technology environments are complicated. Businesses change constantly. People come and go. Technical debt accumulates. There is always another priority competing for attention.

No amount of AI fixes all of that.

The fundamentals might sound simple. Doing them properly, consistently and at scale is anything but.

So yes, AI can help us detect threats faster. It can analyse enormous amounts of information, automate repetitive work and help our people make better decisions. We should absolutely take advantage of that.

But AI doesn’t magically fix poor identity hygiene. It doesn’t give you instant visibility of assets you don’t know exist. It doesn’t patch systems that have been sitting on a vulnerability list for six months. And it doesn’t create an effective incident response capability if nobody has ever practised what happens when things go wrong. It can certainly help (and this help will get better), but you still need to do the work. AI has accelerated the cyber journey. It hasn’t created a shortcut that skips the necessity of sequence and execution.

So perhaps the question for business leaders shouldn’t only be, “What are we doing about AI?” but also remembering we need to pay attention to the “Are we consistently doing the things we already know matter?” Do we understand our environment? Do we know where our biggest risks are? Are the controls we’ve invested in actually working? Can we see when something goes wrong? Are we ready to respond when it does?

For me, that is where Cyber Confidence starts.

AI will increasingly help us exert our cyber muscle faster. Just don’t confuse acceleration with skipping the work.

Cyber is still cyber, the work still needs to be done.


What we read this week

  • Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details - Attackers began exploiting CVE-2026-21589 (CVSS 9.3), a critical arbitrary file access flaw in Atlassian's self-hosted Data Center products, within two hours of watchTowr publishing details. Affected products include Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Crucible and Fisheye; Atlassian Cloud is patched. The bug lies in how Atlassian resolves web-resource paths, letting an unauthenticated attacker read files in the web application root with a single request. On Crowd and Jira, attackers can read crowd.properties, use the stored credentials to gain admin access and create rogue administrator accounts. Previdian logged 15 exploitation attempts from three IPs in Japan and the United States (U.S.), and expects mass scanning to follow.

  • Teenager Suspected of Leading KillSec Ransomware Group as Law Enforcement Seizes Servers and Leak Sites - On 30 September 2026, Operation KillSwitch, a German-led international investigation, took down the KillSec cybercrime group's dark web leak site and secured at least 110 terabytes of stolen data. Active since around 2024, KillSec broke into organisations through software vulnerabilities and poorly secured access points, especially cloud storage, copied sensitive data, then threatened to publish it unless victims paid. Investigators link the group to around 1,000 suspected attacks, of which about 500 have so far been identified as successful, a figure that may change. The group also used artificial intelligence (AI) to build its infrastructure and pick targets. Its suspected main operator is 16, and an alleged developer was a minor during some offences. Police made three provisional arrests, searched eight properties in Greece, Romania, Spain and the United Kingdom (UK), took control of five central servers and domains, and are tracing cryptocurrency proceeds.

  • Fortinet Warns that Critical Flaw in FortiMail is Facing Exploitation - On 1 October, Fortinet warned that a critical path traversal zero-day in FortiMail, tracked as CVE-2026-104286, is being exploited in the wild. The flaw lets an unauthenticated attacker write arbitrary files to a system using crafted HTTP or HTTPS requests. According to watchTowr, placing a file can let attackers run commands on the device, giving full access to the mail gateway, stored mail, credentials and connected systems. Fortinet, whose own researcher discovered the bug, has not said when a patch will be available or when attacks began. It urges customers to disable identity-based encryption support or, alternatively, restrict the management interface to trusted private networks. The zero-day follows other Fortinet issues, including exploited FortiSandbox flaws and a Cybersecurity and Infrastructure Security Agency (CISA) warning in June after thousands of firewall and VPN credentials were compromised.

  • Denmark Says Attackers Accessed CPR Data For 8.8 Million People via Company Account - Unauthorised parties used a private company's lawful lookup access to Denmark's Central Person Register (CPR) to retrieve names, addresses and personal identification numbers for about 8.8 million people, the digitalisation ministry said on 5 October. The activity ran for about 10 days in September, using mass automated lookups to identify valid CPR numbers, and was spotted by a register employee on 2 October. Access has been cut, the data protection authority Datatilsynet were notified and police are investigating. It remains unclear how the company's systems were accessed, who was responsible, or whether the data has been used, with residents urged to watch for targeted phishing and set a credit warning on borger.dk.

  • Anthropic Opens Its Most Powerful AI Models to More Security Teams - Anthropic is expanding its Cyber Verification Program (CVP), which gives vetted cyber security professionals access to its most powerful models with fewer safeguards. It follows Project Glasswing, whose partners found at least 129,000 verified software vulnerabilities between April and July, while Anthropic's own open-source scanning found 5,500 more by October. More than 33,000 have been rated critical or high severity, and Anthropic expects the true impact is at least five times higher, as the figures come from a limited partner survey. The revamped CVP merges Glasswing, which offered Claude Mythos to organisations securing critical software, with the original CVP. It has three tiers, all including Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1: Defence, for incident response and malware analysis; Red Team, for authorised penetration testing by organisations only; and Specialised, the least restricted, for a small group testing safety-critical systems such as power grids, vetted alongside the U.S. government.