Cybersecurity News
Filters
Australia hikes levy for tech giants that fail to strike local news deals
Matched: Australia
Australia will increase a levy on large technology companies that fail to reach commercial deals with local news outlets to pay for journalism. The charge will be calculated based on advertising revenue rather than total revenue, narrowing its scope. The move is designed to pressure platforms like Google and Meta into negotiating fair compensation agreements with Australian news publishers.
Why App Control Fails Most Teams and How Managed ESPM Fixes It
Huntress's Managed ESPM addresses the gap between app control's security benefits and the practical limitations of smaller IT teams and MSPs. Traditional app control solutions demand enterprise-level budgets and staffing, making them inaccessible. Huntress positions its managed endpoint security offering as a way to deliver proactive endpoint hardening without requiring the resources typically needed to implement and maintain such controls.
3rd August – Threat Intelligence Report
Minnesota IT Services confirmed coordinated cyberattacks on over 30 community water utilities, briefly disrupting a treatment plant in Braham and affecting industrial control systems. The incidents highlight ongoing vulnerabilities in critical infrastructure. Further details on this and other threats are available in Check Point Research's weekly Threat Intelligence Bulletin for the week of 27th July.
Exclusive: Japanese telco Sakura Mobile informs customers of data breach
Matched: Australia
Japanese telecommunications service Sakura Mobile, which caters to tourists and international residents including Australians, has notified customers of a data breach involving unauthorised access to limited customer data. The company says payment details were not affected. No further details about the breach's scope or cause have been publicly disclosed.
Critical N-able N-central Vulnerability and Active Exploitation
A critical vulnerability in N-able's N-central remote monitoring and management platform allows unauthenticated attackers to gain full administrative access. Described as "god-mode" control, exploitation requires no credentials. The flaw poses serious risk given N-central's use by managed service providers overseeing many client environments. Active exploitation has been reported, and users are urged to patch immediately.
Exclusive: Partnered Health responds to Inc Ransom data breach claims
Matched: Australia, health
Australian GP network Partnered Health is responding to claims by cyber extortion group Inc Ransom, which alleges it stole terabytes of data from the organisation. At least 21 clinics may be affected. Partnered Health has not confirmed the breach but is investigating. Inc Ransom typically publishes stolen data if ransom demands go unmet.
Hackers Turned a Trusted Advertising Platform Into a Crypto-Stealer Delivery Network
Matched: cryptocurrency
Adform, an ad tech firm serving ~14,000 businesses, suffered a supply chain attack where hackers hijacked a widely used JavaScript file within its infrastructure to distribute cryptocurrency-stealing malware. Researcher Kevin Beaumont uncovered the breach, which exploited the platform's trusted ad-serving network to reach victims. Adform holds nearly 30% of the demand-side platform market, amplifying the attack's potential reach.
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Matched: cryptocurrency
Attackers modified a JavaScript file from ad tech firm Adform to silently replace cryptocurrency wallet addresses in users' browsers. The malicious script, active on July 27, 2026, targeted Bitcoin and other crypto addresses copied by visitors to affected sites. Adform detected and removed the code the same day, notified clients, and reported the incident to authorities. Users who transacted on July 27 should verify their wallet addresses.
FBI And Allies Warn of North Korean IT Workers Using Stolen Identities
Matched: Australia
The FBI, U.S. State Department, and allied nations including Japan, Canada, Germany, Australia, the UK, and South Korea have jointly warned that North Korean IT workers are infiltrating private companies using stolen identities, forged documents, and proxy networks. The advisory urges firms worldwide to strengthen hiring verification processes to detect and prevent such infiltration.
Device Code Phishing Keeps Evolving. Here’s What to Watch For
Attackers are abusing Microsoft 365's device code authentication flow to steal tokens without needing credentials. Victims are tricked into entering attacker-generated codes at legitimate Microsoft login pages, granting persistent access. The technique bypasses MFA and leaves minimal obvious indicators. Huntress advises monitoring for unusual device code authentication requests, unexpected token grants, and sign-ins from unfamiliar locations or clients.
North Korean EtherHiding Campaign Targets Crypto Wallets and Developer Credentials
Matched: cryptocurrency
North Korean hackers are using fake macOS update screens to deploy malware targeting cryptocurrency wallets, browser data, and developer credentials. The campaign uses a ClickFix-style lure that makes browser pages appear broken, prompting users to run malicious commands. Entry points include routine web searches, making the attack difficult to detect.
Report: Nearly half of Australians experienced cyber crime in 2025
Matched: Australia
Nearly half of Australians were affected by cybercrime in 2025, though overall victimisation rates fell slightly from the previous year, according to the Australian Cybercrime Survey. Online scams continued to rise despite the broader decline. Underreporting remains a significant concern, with most incidents never flagged to authorities, limiting the ability to fully assess the scale of the problem.
ASPI launches AI and Security Program to tackle national security challenges
Matched: Australia
Australia's Strategic Policy Institute has launched an AI and Security Program to research how artificial intelligence affects national security. The program will focus on cyber threats, critical infrastructure protection, defence sector AI adoption, and international AI governance frameworks.
ACMA takes Optus to Federal Court over September 2025 Triple Zero outage
Matched: Australia
Australia's communications regulator ACMA has launched Federal Court action against Optus over its handling of a September 2025 network outage, alleging the telco breached legal obligations related to Triple Zero emergency call access during the disruption.
Huntress hits an inflection point
Huntress CEO Kyle Hanslovan says the cybersecurity firm is at a strategic turning point, scaling its research-driven approach while integrating AI with human oversight to counter faster, automated threats. The company is also expanding its partner network to extend protection to more small and mid-sized businesses increasingly targeted by sophisticated cyberattacks.
Incident Response Plans: What to Include & Why They Matter
Organizations need incident response plans to minimize damage during cyberattacks. Key components include defined roles, communication protocols, detection and containment procedures, recovery steps, and post-incident analysis. Without a plan, response times slow and costs rise. Huntress helps by providing threat detection, guided remediation, and support that keeps businesses prepared before, during, and after security incidents.
$250M ARR Was Never the Goal. It Came From Staying True to Our Mission.
Huntress CEO Kyle Hanslovan says reaching $250M ARR was a byproduct of staying focused on the company's core mission: protecting small and mid-sized businesses often overlooked by the cybersecurity industry. He credits the milestone to consistency of purpose rather than chasing revenue targets, and emphasizes that the mission to defend the "99%" remains the company's top priority going forward.
Hacker Summer Camp: What First-Timers Actually Need to Know | Huntress
Annual Las Vegas security conferences DEF CON, Black Hat, and BSides attract thousands of cybersecurity professionals. First-timers should plan ahead: book hotels early, wear comfortable shoes, stay hydrated, and budget carefully. Operationally, use burner devices or hardened gear on the network, avoid ATMs on the strip, and expect crowds and long lines. Engage with the community, attend talks early, and explore villages and side events for hands-on experience.
Melbourne start-up Maincode announces widespread access to Matilda AI coding agent
Matched: Australia
Melbourne start-up Maincode has opened its AI coding agent Matilda to wider beta access. The Australian-made chat model and coding agent was previously in limited release before the company announced broader community availability. Maincode is based in Melbourne.
ACMA takes Optus to court over 2025 Triple Zero failures
Matched: Australia
Australia's communications regulator ACMA is taking Optus to court, alleging the telco breached its emergency call obligations more than 1,000 times during a network outage in September 2025. The action centres on failures to connect customers to Triple Zero during the disruption.
