Cybersecurity News

Filters
Tag

Mirage2FA Phishing Kit Bypasses MFA to Hijack Microsoft 365 Sessions, Targeting 3,500+ Organizations

Matched: health

A phishing-as-a-service toolkit called Mirage2FA, linked to the group LinX Coders, has potentially compromised 4,532 Microsoft 365 accounts across 3,518 organizations in 94 countries, with 63.7% of victims in the US. The kit uses HTML, XHTML, and SVG attachments to deploy adversary-in-the-middle proxies that capture authenticated session cookies, bypassing MFA without dropping malware. Over half of 9,332 recorded compromise events involved cookie theft, making simple password resets insufficient for remediation.

Aus mutual banks are trying to balance human personal touch and AI efficiency

Matched: Australia

Australian mutual banks are working to balance AI efficiency with the personal service their customers value. Unlike larger banks, mutuals built their reputation on human connection, making the shift toward AI tools more delicate. They are exploring automation for back-end processes while preserving face-to-face and personalised interactions where customers expect them most.

Pro-nuclear lobby group says nuclear power the best solution to data centre energy demands in Australia

Matched: Australia

A pro-nuclear lobby group, Nuclear for Australia, argues that nuclear power is the best way to meet growing energy demands from AI data centres while keeping household electricity bills affordable. The non-profit contends other energy sources cannot adequately handle the load, though critics dispute this claim.

Microsoft Teams Outage Largely Mitigated After Users Lost Access to Multiple Features

Matched: health

Microsoft Teams suffered an outage on August 26, 2026, primarily affecting Asia-Pacific users who could not join or create meetings, with some unable to share screens. Microsoft attributed the disruption to maintenance activity with unintended consequences. By 7:26 a.m. IST, the company reported the issue largely mitigated and said engineers would monitor for 15–30 minutes to prevent recurrence. One-to-one calls remained functional during the incident.

Report: Australian CEOs face cyber accountability gap as AI accelerates attacks

Matched: Australia

More than half of Australian security professionals expect CEOs to lose their jobs following a major cyber breach, yet research highlights a significant gap between board-level accountability and actual operational preparedness. The disconnect is worsening as AI accelerates the pace and sophistication of attacks, raising concerns that leadership responsibility is outpacing organisations' real-world cyber defences.

Busted! Interpol-led operation targeting West African cybercrime groups nets 58 arrests

Matched: Australia, cryptocurrency

An Interpol-led operation involving 22 countries across six continents resulted in 58 arrests targeting West African cybercrime groups. Operation Jackal IV focused on dismantling romance scam and cryptocurrency fraud networks. Australia was among the participating nations. The operation also led to the identification of hundreds of additional suspects and the seizure of assets linked to the criminal organizations.

Young Aussies can’t afford financial advice, use AI tools instead

Matched: Australia

Young Australians are increasingly turning to AI tools for financial guidance due to the high cost of traditional advice, according to Webull Australia. The online broker's findings show young Aussies lead AI adoption for financial queries, reflecting a broader trend of cost-conscious consumers seeking affordable alternatives to licensed financial advisers.

Of course, this fake GTA VI ISO download is malware — testers reveal 113GB download is 99.99% empty zeroes, with a tiny virus attached

A fake GTA VI ISO circulating on torrent sites is almost entirely empty data, with testers finding 113GB of zeroes concealing a roughly 50KB malware payload. The inflated file size was designed to mimic a legitimate game release. The malicious code reportedly disables Windows Defender and other security tools via PowerShell commands. Interest in GTA VI leaks has made fans easy targets, with Rockstar's official release scheduled for November.

New Windows malware lays dormant until a custom command activates it like a sleeper agent

SLEEPWALKER is a newly discovered Windows malware implant that contains no malicious code, instead lying dormant until receiving a specially crafted network signal. Disguised as ESET's Management Agent, it evades security software entirely. Once activated, it can schedule tasks, communicate with remote systems, and execute code. Researcher Dominik Reichel believes it's likely a nation-state tool targeting specific victims, though no active campaigns or confirmed victims have been identified.

ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions

Matched: health

ToxNetV2 is a Linux botnet targeting AArch64 systems that integrates NVIDIA's NIM AI service into its controller to suggest attack commands. The controller feeds system and botnet data to the AI model, parsing structured responses into a queue of proposed actions — including shell commands, SSH access, and file operations — that human operators must approve before execution. The botnet uses a peer-to-peer structure and includes scanning, self-propagation, and 17 network-attack modules. Researchers at JOESecurity noted the malware embeds a jailbreak prompt to reduce AI refusals.

Fake Microsoft Security Scan Tells You to Remove Antivirus—Then Scammers Ask for Remote Access

Matched: cryptocurrency, health

Scammers are running fake Microsoft-branded security scan websites that display fabricated results showing poor scores and false warnings. The sites instruct visitors to uninstall their antivirus software, then collect personal and banking details through a form before redirecting victims to await a callback. Callers then request remote access to the device. Malwarebytes identified 11 related sites sharing one server, all using similar SysScan branding.

ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealer

Matched: cryptocurrency

ClickFix campaigns are delivering PavinLoader malware through fake CAPTCHA pages, software downloads, and malicious game installers that trick users into running malicious commands. The loader uses legitimate Windows tools like MSBuild to hide its activity, employs blockchain-based command-and-control via EtherHiding to obscure infrastructure, and deploys payloads including Amatera Stealer and HijackLoader to steal passwords, browser data, and cryptocurrency wallet information.

Microsoft August 2026 Update Breaks When Generating PDF/XPS Content

Matched: health

Microsoft's August 2026 .NET Framework cumulative updates are causing printing failures and PDF/XPS generation errors in WPF applications. The bug triggers a System.IO.FileFormatException when using ClearType fonts like Calibri, Cambria, Constantia, and Corbel, affecting Windows 10, 11, and Server 2012–2025. The issue stems from stricter font validation in the TrueType subsetter introduced alongside fixes for six security vulnerabilities. A temporary workaround exists but disables the security protections the update introduced.

Android car systems abused by hackers to launch new malware that pulls devices into a hidden proxy network

Kaspersky discovered Android malware targeting DoFun car head units by hijacking the TWCore update app to install malicious APKs. The multi-stage attack deploys a dropper, loader, and reverse proxy tool, with the apparent goal of building a botnet from internet-connected vehicles. Kaspersky attributed the campaign to MoYu Group, previously linked to the BadBox botnet. DoFun has since patched the vulnerabilities.

Some Mac users think they're installing OpenAI Codex, but it's actually a malware that can steal passwords in seconds

Matched: cryptocurrency

Cybercriminals are using stolen Google Ads accounts and Google Sites to impersonate OpenAI's Codex download page, targeting macOS users. The fake site avoids detection by hosting malicious content via an iFrame elsewhere. Victims are tricked into pasting Terminal commands, which install AMOS, a macOS infostealer that harvests passwords, browser data, and crypto wallet information. The Windows download button was non-functional — only the Mac payload worked.

Defining the MVC: Recover faster from cyberattacks by restoring what matters most

Organizations struggle to recover from cyberattacks not due to missing backups, but from trying to restore everything simultaneously. The Minimum Viable Company (MVC) concept offers a better approach: identifying the minimum people, processes, and technology needed to keep functioning during a crisis. Key recovery capabilities include mapping critical services, establishing a trusted foundational layer, isolating recovery assets, building clean-room recovery environments, and validating plans through realistic rehearsals.

No standing still: Zero Trust and cybersecurity

Cyberattacks are growing in speed and scale, costing businesses billions — recent incidents hit Jaguar Land Rover, WestJet, and Collins Aerospace. With public trust in data handling already low, companies need modernized security strategies. Zero Trust, built on "never trust, always verify," limits breach damage by confining access rather than relying on a single perimeter. Despite 96% of firms planning adoption, only 35% have implemented it, highlighting an urgent need for cross-industry action and consistent standards.

Report: Australia’s transport sector under-prepared for risk of cyber attack

Matched: Australia

A survey of Australia's logistics industry found fewer than half of respondents feel prepared to handle a cyber security incident, highlighting significant vulnerabilities in the transport sector. The findings suggest the industry lacks adequate readiness to defend against or respond to cyber attacks, raising concerns about potential disruptions to critical supply chain infrastructure.

9 in 10 Aussies know property scams exist – but only half can spot one

Matched: Australia

Nine in ten Australians are aware property scams exist, but only half feel confident identifying one, according to new research. The gap between awareness and detection ability has widened, raising concerns about settlement security. Experts warn fraud is becoming increasingly sophisticated, leaving buyers and sellers vulnerable despite general awareness of the risks.

ASD warns Australian TeamCity servers under attack

Matched: Australia

Australia's signals directorate has warned that JetBrains TeamCity servers in the country are being actively exploited following a critical authentication bypass vulnerability. The flaw, which allows attackers to gain administrative control without credentials, was patched in late July. Organisations running unpatched TeamCity instances are urged to update immediately.