Cybersecurity News
Filters
Australia’s eSafety Commissioner sues Telegram over terror content
Matched: Australia
Australia's eSafety Commissioner is suing Telegram after a year-long investigation found the platform failed to comply with the Online Safety Act. The regulator alleges Telegram did not adequately respond to requests for information about how it handles terrorist and violent extremist content on its platform.
Musk's X says Australia social media ban crackdown undermines international law
Matched: Australia
X has criticised Australia's proposed social media restrictions, arguing they undermine international law. The company took particular aim at the country's eSafety Commissioner, pushing back against regulatory efforts to enforce content and age-based restrictions on platforms. Australia has been pursuing stricter online safety measures, including a ban on social media for children under 16.
Reverse Engineering the Six Stages of MacSync Stealer and RAT
Researchers reverse-engineered MacSync, a six-stage macOS malware combining stealer and remote access trojan capabilities. The sample was recovered from attacker infrastructure after the compromised host went offline. Analysis traced its execution chain across all six stages, revealing how it exfiltrates data and maintains remote access on infected machines.
Introducing Huntress Webhooks. Get Real-Time Security Alerts.
Huntress has launched a webhooks feature that delivers real-time security alerts directly to tools like Slack, PSA platforms, or SIEMs. Unlike polling-based methods, webhooks push incident and escalation notifications instantly. The feature is designed for quick setup, giving security teams faster visibility into threats without manual checking or delays.
ANZ SMEs adopt AI widely, but trust lags, Arctic Wolf report finds
Matched: Australia
Australian and New Zealand small and midsize businesses are rapidly adopting AI, but trust in the technology remains limited, particularly for autonomous cybersecurity decision-making, according to a report by Arctic Wolf. While uptake is high, many SMEs prefer human oversight when it comes to security, reflecting broader concerns about reliability and accountability in AI-driven systems.
Credential Stuffing Campaign Hits SonicWall | Huntress SOC Tracking
Huntress's SOC is tracking an active credential stuffing campaign targeting SonicWall devices that has compromised dozens of organizations since July 25. Attackers are using previously leaked credentials to gain unauthorized access. Affected organizations span multiple sectors. Huntress recommends enabling multi-factor authentication, reviewing VPN access logs, and resetting credentials on all SonicWall devices as precautionary measures.
Amazon's Leo proposes satellite constellation for direct-to-phone service
Matched: Australia
Amazon's Project Kuiper has proposed a satellite constellation called Leo to provide direct-to-smartphone connectivity, competing with SpaceX's Starlink and AST SpaceMobile in the growing direct-to-device market. Amazon has partnered with Australian broadband provider NBN Co as part of the initiative.
ASD to critical infrastructure ops: be ready to isolate systems for three months
Matched: Australia
Australia's Australian Signals Directorate has issued new technical guidance urging critical infrastructure operators to prepare for the possibility of isolating their systems for up to three months following a cyberattack. The advice targets essential services sectors and focuses on building resilience and recovery capabilities to maintain operations even when disconnected from broader networks.
27th July – Threat Intelligence Report
Nichirei, a Japanese frozen-food and logistics company, suffered a ransomware attack disrupting shipping operations and affecting around 5,000 customers, with KFC Japan warning of possible shortages. Personal data theft was confirmed. The incident is among several attacks and breaches covered in Check Point Research's Threat Intelligence Bulletin for the week of 27th July.
What Our AI SOC Analyst Can Do (and What We Won’t Let It Do)
Huntress has introduced an AI SOC analyst called Athena that can autonomously investigate security threats and take actions, but operates within boundaries defined by human analysts. The system is designed to handle routine security operations work while keeping humans in control of key decisions, illustrating how the company is approaching governance around agentic AI in cybersecurity contexts.
CMMC Updates: DoW Pause and Huntress Hits 50% of Requirements
The Department of Defense paused CMMC Phase II deadlines in July, but core compliance obligations under NIST SP 800-171 remain unchanged. Huntress Managed ISPM now covers 55 of 110 required controls, reaching 50% coverage. The pause affects enforcement timelines, not underlying requirements, so compliance work continues without interruption.
Employee Spotlight: Andrew Schlemmer
Andrew Schlemmer, a Channel Account Manager, was personally affected by cybercrime, an experience that shaped his professional mission. He now works to make enterprise-grade security solutions accessible and attainable for businesses of all sizes, using his firsthand understanding of cyber threats to drive his commitment to helping organizations better protect themselves.
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
A malvertising campaign discovered in late July used a fake Claude AI artifact hosted on Anthropic's legitimate domain to trick users into downloading malware. The attack, dubbed FakeAgent, infected 29 organizations with SectopRAT, an information-stealing trojan capable of harvesting credentials and sensitive data. The campaign exploited user trust in the authentic Claude domain to bypass suspicion.
How the LSHIY Password-Spraying Attack Abuses OAuth’s ROPC Grant
Researchers tracked a large automated password-spraying campaign targeting Azure CLI that exploited OAuth's Resource Owner Password Credentials grant, a deprecated flow still supported by many systems. Attackers used it to avoid modern authentication defenses like MFA prompts and conditional access policies. The campaign, dubbed LSHIY, highlights risks of legacy OAuth flows remaining enabled, and researchers recommend disabling ROPC grants where possible.
LG to Ban Residential Proxies from Smart TV Apps
LG Electronics USA plans to suspend smart TV apps that turn televisions into residential proxy nodes, following research revealing that over 42% of apps on its webOS store allow third parties to route internet traffic through users' TVs without their knowledge. The announcement comes less than a month after that research was published.
Macquarie Government launches Microsoft Azure practice for state and federal agencies
Matched: Australia
Macquarie Government has launched a Microsoft Azure practice offering cloud, security, and AI services to Australian federal and state government agencies. The move marks the first time the company has consolidated its Azure capabilities into a dedicated practice, aiming to help public sector clients adopt and manage Microsoft cloud technologies more effectively.
What Are Initial Access Brokers?
Initial access brokers are cybercriminals who specialize in breaking into corporate networks and selling that access to other attackers, such as ransomware groups, rather than exploiting it themselves. They typically gain entry through stolen credentials, phishing, or unpatched vulnerabilities. This division of labor has made cybercrime more efficient and increased the scale of attacks on businesses.
Veeam appoints Philip Goldie as Vice President for Australia and New Zealand
Matched: Australia
Veeam has appointed Philip Goldie as Vice President for Australia and New Zealand. The appointment comes as the company highlights increasing enterprise focus on AI adoption and the data risks that accompany it. Goldie is expected to lead Veeam's regional strategy as demand grows for data protection and resilience solutions in the ANZ market.
How We Cut Noise Before It Hits the Analyst
Huntress uses AI-driven triage to filter out low-priority alerts before they reach human analysts. By automating the sorting of incoming signals, the system reduces noise and lets analysts focus on genuine threats. This approach is designed to improve response times and reduce alert fatigue, making security operations more efficient without overwhelming staff with false positives or routine notifications.
20th July – Threat Intelligence Report
Ernst & Young disclosed a data breach via a compromised third-party IT support platform, potentially exposing client documents and tax information in support tickets. The report also covers other notable attacks and breaches from the week of 20th July, with full details available in Check Point Research's Threat Intelligence Bulletin.
