
Sypha Security Threat Feed 
[boldgrid_component type=”wp_rss” opts=”%7B%22widget-rss%5B%5D%5Burl%5D%22%3A%22https%3A%2F%2Fwww.cisecurity.org%2Ffeed%2Falert%22%2C%22widget-rss%5B%5D%5Btitle%5D%22%3A%22CIS%20Cyber%20Threat%20Level%3A%22%2C%22widget-rss%5B%5D%5Bitems%5D%22%3A%2210%22%2C%22widget-rss%5B%5D%5Bshow_date%5D%22%3A1%2C%22widget-rss%5B%5D%5Bshow_summary%5D%22%3A0%2C%22widget-rss%5B%5D%5Bshow_author%5D%22%3A0%7D”]
- OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree
- AI Sends Global Crime Syndicates Into Fraud Nirvana
- AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking
- A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
- OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts
- Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency
- No Perfect Fix for AI Browser Prompt Injection Flaws
- DHS Wants Protesters’ Signal Group Chats
- CSS: The Hidden Threat Lurking in Your Inbox
- The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop
- 15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
- Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
- JetBrains security advisory (AV26-752) – Update 1
- OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes
- Zbtlink security advisory (AV26-779)
- Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt
- Fake Open VSX Extensions Harvest Private Repo and CI Data
- Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
- Paperclip AI Flaws Let Unauthenticated Attackers Run Commands
- Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
- Hewlett Packard Enterprise (HPE) security advisory (AV26-778)
- Prompt Injection Remains Biggest LLM Risk, Despite Limited Incidents
- ChainDrop Worm Hits 400+ npm Packages with Two Billion Monthly Installs
- Vulnerabilities in Car Anti-Theft Device
- Frontier Models Engage in Unsanctioned Behavior During Testing
- Veeam security advisory (AV26-777)
- Adobe security advisory (AV26-776)
- Iran Cyberattacks Against Minnesota Water Systems
- The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software
- QuickFox Supply Chain Attack Used to Deploy FDMTP Implant
- Almost Half of Malware Samples Communicate Direct to IP
- Some Claude Chats Are Searchable on Google
- Fake IRS letters target cryptocurrency holders
- Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Authentication Bypass
- More on the OpenAI Agent’s Attack on Hugging Face
- The OpenAI Hack Shows the Genie Is Out of the Bottle
- Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
- The $5 million threat: AI Is supercharging phishing attacks
- The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version
- Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise
- Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
- North Korea’s elite hackers turned on their own government – and got caught
- Smashing Security podcast #478: This job interview could destroy your company
10th September 2025

Defence Industry Security Program (DISP)
Sypha Defence Advisory is in the process of becoming a DISP member. Check back to review our progress and status update.
Visit DISP
25th October 2023

Sherwood Applied Business Security Architecture
SABSA is a proven methodology for developing business-driven, risk and opportunity focused Security Architectures at both enterprise and solutions level that traceably support business objectives.
It is also widely used for Information Assurance Architectures, Risk Management Frameworks, and to align and seamlessly integrate security and risk management into IT Architecture methods and frameworks.
The SABSA framework and methodology is used successfully around the globe to meet a wide variety of Enterprise needs including Risk Management, Information Assurance, Governance, and Continuity Management. SABSA has evolved since 1995 to be the ‘approach of choice’ for organisations in 50 countries and in sectors as diverse as Banking, Homeless Management, Nuclear Power, Information Services, Communications Technology, Manufacturing and Government.
Sypha Defence Advisory became a SABSA member on the 25th October 2023.
Visit SABSA
1st June 2021

Australian Government Security Vetting Agency
The Australian Government Security Vetting Agency (AGSVA) is the central vetting agency for the Australian Government and conducts security clearance assessments for federal, state and territory agencies.
Sypha Defence Advisory employees must pass federal government security clearance vetting before an offer of employment is provided. This is a mandated requirement for most Federal Government Agencies but also provides additional reassurance to our clients that our employees have had an extensive background check completed and are deemed suitable to work within the information security industry.
Visit AGSVA Assessment
1st November 2020

Information Systems Audit and Control Association (ISACA) Membership
ISACA was founded in 1967 as a centralised source of information for computer systems audit control. It has since evolved into an international organisation providing education, certification training, Risk IT Framework, COBIT (Control Objective for the Information and related Technologies) Framework to help organisations elevate their cybersecurity maturity, with their primary purpose to “help business technology professionals and their enterprises around the world realize the positive potential of technology”.
Sypha Defence Advisory employees are sponsored professional members of ISACA and actively work towards ISACA cybersecurity certifications, which showcase our expertise and commitment to providing international best practice cybersecurity defence strategies and solutions to our clients.
Visit isaca.org
23rd October 2020

Australian Information Security Association (AISA) Membership
To gain an overall perspective of cybersecurity across the Australian business landscape we need partnerships with organisations that represent all Australians across all sectors: private, public, government and individuals.
The AISA is a not for profit entity committed to ” … the development of a robust information security sector by building the capacity of professionals in Australia and advancing the cyber security and safety of the Australian public as well as businesses and governments in Australia.”
This is why Sypha Defence Advisory is a member of AISA, so we can leverage their knowledge, network and resources to balance the needs of the public, private and government sectors when it comes to planning the appropriate strategies and developing the controls needed to mitigate the risk of a cybersecurity incident for all Australian organisations and businesses.
22nd July 2020
Australian Cyber Security Centre (ACSC) Partnership
Part of our ongoing commitment to our clients is to ensure that we are well informed and can provide accurate and timely cybersecurity information that will help executive management teams make the right decisions when assessing risk. Helping management determine where to invest time and money in order to protect critical assets is at the forefront of everything we do. Having the right partnerships with the most well-informed organisations is critical in being able to provide this advice.
We are pleased to announce a partnership with the Australian Cyber Security Centre where we will be working with them to ensure that Australian businesses are adequately protected from the latest sophisticated cyber threats.
