Gridware Logo

November Cyber Recap

By Ahmed Khanji Updated 2 December 2025 3 min read

in 𝕏
November Cyber Recap

November Recap

A lot of the activity stayed underneath the surface, which made the month feel quieter than it actually was. It wasn’t intense, but it wasn’t slow either. It just took a closer look to see where the movement was.

Australian organisations continued to show strong confidence in their cyber posture, even though the incidents across the month didn’t quite match that confidence. A few cases showed how easily an organisation can feel secure on paper while older systems and missed exposures sit in the background. The pattern was clear in Aussie businesses still overconfident with their cyber defences, where small gaps carried more weight than expected.

Another issue that kept surfacing this month was the number of older Cisco IOS XE devices still carrying the BADCANDY implant. The ACSC noted more than 150 routers and switches still affected across the country. These devices sit quietly at the edge of networks, which explains how the implant stayed in place long after patches were released.

Telecom infrastructure also drew attention this month. ASIO confirmed probing linked to Salt Typhoon, which didn’t lead to outages but showed that interest in these networks hasn’t gone away.

On the development side, Shai Hulud 2.0 drew attention for how quickly it spread. Over 25,000 public packages were affected after malicious versions were published to widely used repositories. Because so many teams rely on the same open-source components, the impact reached much further than it first appeared.

Harvard’s vishing breach

The university confirmed that a voice phishing call led to access inside its Alumni Affairs and Development systems. The attacker gained access to names, contact details, mailing addresses, class years, event attendance and donor records. The affected data didn’t include financial information or passwords, but it was still detailed enough to support targeted follow up attacks.

London council’s service disruption

Three London councils moved into emergency arrangements after a cyber incident disrupted their shared IT environment. Phone lines and council services went offline during the recovery, which created noticeable delays and showed how fast critical infrastructure feels the impact of an attack.

Asahi Group’s data exposure

In Japan, Asahi Group confirmed that personal information belonging to roughly 1.5 million people had been accessed. The details included names, contact information and internal business records related to customers, staff and family contacts. The company also reported logistical and administrative delays while systems were restored, which added operational strain on top of the exposure itself.

Heading Into December

December usually brings a different feel to cyber activity. Teams are smaller, projects slow down and a lot of environments stay running with less attention than usual. Managed Security Support is available for organisations that want a bit more confidence heading into the break.

Ahmed Khanji

Ahmed Khanji

CEO, Gridware

Ahmed Khanji is the CEO of Gridware, a leading cybersecurity consultancy based in Sydney, Australia. He is recognised for his insights into offensive security and emerging technologies such as blockchain, and often contributes to broader cybersecurity conversations across the country. With an extensive background as a security advisor to major Australian enterprises, Ahmed helps organisations navigate the evolving threat landscape with clarity and confidence.