Cythera

Hacking for Heroes

We think that organisations who are working hard to help the community and vulnerable groups are Heroes!
Talk to an expert

Hacking for Heroes Programme

Our goal is to strengthen the security posture of community-focused groups, ensuring they can protect the sensitive information they handle and continue their vital work without disruption.

What is the Hacking for Heroes programme?

As part of Bastion Security Group, Cythera has officially launched Hacking for Heroes programme in 2026. Across Australia and New Zealand, the program donates $160,000 (splint evenly between AU and NZ) worth of cybersecurity consultancy annually to not-for-profit organisations. Our goal is to strengthen the security posture of community-focused groups, ensuring they can protect the sensitive information they handle and continue their vital work without disruption.

Why are we doing this?

Often not a week goes by without a data breach or ransomware attack popping up in the news. Cythera would like to help not-for-profit organisations identify and provide guidance on how to fix security issues, so they are less likely to be involved in a security event that could negatively impact what they do. We think that this is particularly important as community organisations often hold information on behalf of vulnerable people.

Who should apply?

We welcome applications from not-for-profit organisations that handle sensitive information or operate in high-trust environments. If your organisation provides essential services and could benefit from enhanced cybersecurity but lacks the internal resources, this programme is for you.

Application process

The application process is simple and focused on impact. We want to understand what you do, how you help, and how better security could support your mission.

  1. Complete our short expression of interest form
  2. If shortlisted, we’ll follow up with a call to learn more
  3. Final applicants will be selected based on need, alignment and impact potential.

Key dates

Expressions of interest for the 2026 programme are now open.

  • Applications open: 12th August - 28th August 2026
  • Short listing of applicants: 31st August - 4th September 2026
  • Final interviews: 7th - 11th September 2026
  • Successful applicants contacted: 11th September 2026
  • Engagements underway: September - February 2026

Cyber security news

Latest advisories

Stay ahead of emerging threats with our expert blog posts, research, and industry updates.
Silverstripe - Host Header Injection
Silverstripe CMS is affected by a Host Header Injection flaw, which can be exploited to manipulate password reset workflows, potentially redirecting or compromising user data.
FarCry Core Framework - Multiple Issues
FarCry Core contains multiple vulnerabilities that could let unauthenticated users upload arbitrary files and execute remote code on the hosting server.
Silverstripe – Cross-Site Scripting (XSS) Vulnerability
With local organisation admin credentials, an attacker can exploit the API to create, delete, or revert virtual machine snapshots in other organisations’ Virtual Data Centres (VDCs), breaching isolation boundaries.