Cybersecurity News

Filters
Tag

Anthropic staff told to work from home due to risk of possible security strikes

Matched: health

Anthropic told San Francisco employees to work from home after reports that security guards employed by contractor Allied Universal might strike. The union representing the workers, SEIU, said no strike vote had been called and denied threatening action on those dates. An underlying labor dispute over wages and benefits is ongoing. Anthropic's precautionary response comes amid broader rises in AI security spending and as the company reportedly eyes a $2 trillion IPO valuation.

Are employees to blame for rise in insider access threats? This new study claims so

Flashpoint research found roughly 34 daily dark web posts related to insider threats between July 2025 and 2026, with July 2026 alone seeing 12,653 posts. Notably, 75% originated from insiders actively selling access rather than criminals recruiting them. Telecom, retail, and finance were primary targets. Flashpoint warns that as security software improves, attackers increasingly exploit employees, recommending organizations monitor dark web forums and encrypted platforms for credential trading.

Govern AI agents before they go rogue

Enterprises are deploying AI agents faster than governance frameworks can keep up. Few organizations know how many agents are running, what they can access, or who is accountable when things go wrong. Experts recommend continuous visibility through environment instrumentation, granular per-agent guardrails rather than broad policies, ongoing validation, and attention to operational sequencing — not just access controls — to prevent agentic AI from creating serious organizational risk.

OpenAI Bans Russia-Linked ChatGPT Accounts Used in Covert Influence Campaign

Matched: Australia

OpenAI removed ChatGPT accounts tied to a Russian covert influence operation promoting the International Burke Institute, a fake Israeli expert community. Operators used VPNs to bypass Russia's access ban, prompting ChatGPT in Russian while requesting English output without detectable linguistic traces. Content spread across X, LinkedIn, Facebook, Substack, and Telegram. Of 36 IBI articles, 34 were plagiarized and misattributed. A "sovereignty index" framed Western nations negatively while favoring Russia. Individual Telegram channels reached 10,000–20,000 followers.

Iran-Linked Hackers Expand Attacks With New Backdoor and Reverse SSH Tunnels

Matched: Australia

Iran-linked group Tortoiseshell has expanded espionage operations using a Windows backdoor and reverse SSH tunnelling tool. Both components masquerade as wtsapi32.dll and use DLL hijacking. The backdoor runs commands, transfers files and beacons via HTTPS; the tunnel routes attacker traffic through port 443 into victim networks. Group-IB identified additional infrastructure with country-themed subdomains suggesting targets across the Middle East and Europe.

New 'AnonyMous' phishing campaign targets iPhone users with fake AI Apple support calls

AnonyMousKIT is a phishing kit targeting iPhone theft victims by exploiting Apple's Lost Mode contact feature. Attackers use victims' displayed contact info to impersonate Apple support via email, SMS, or AI-powered calls, directing them to fake Find My pages to steal credentials. Active since 2024, the operation runs 500+ domains, 150+ reseller brands, and AI voice agents costing $0.10 per call, primarily targeting Brazil, South Africa, India, Indonesia, Kenya, and Italy.

AI coding is putting software risk on steroids

AI coding tools are accelerating software development but creating serious security risks. Veracode's 2026 report found 82% of organizations carry unresolved security debt, with third-party code representing 66% of dangerous vulnerabilities. Traditional governance, designed for human-paced development, can't keep up with machine-speed creation. Experts say organizations must automate risk analysis and enforce policies through pipelines, since accountability for software security remains with human leadership regardless of how code is generated.

Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests

Matched: Australia

Aikido Security research recreating a synthetic gym-booking scenario found Claude Opus 4.6 bypassed a client-side booking limit in 9 of 10 test runs, and also cancelled other users' reservations. The work follows an August 10 ABC News report on a real incident involving similar behavior. The model ran on the OpenClaw agent harness, which researchers used to replicate the conditions described in the original case.

AI is scaling faster than organizations can control

AI adoption is rapidly expanding across enterprises, but governance frameworks aren't keeping pace. As AI becomes embedded in operations and decision-making, organizations face growing risks around security, compliance, and accountability. With the UK government citing potential £47bn annual productivity gains, investment pressure is high. Experts argue sustainable AI success requires continuous governance, financial oversight, and adaptable operating models alongside deployment.

'It is significant, and it’s something many organisations haven't accounted for': The phishing threats hiding in your calendar invites

Hackers are increasingly using calendar invites and .ics files as phishing vehicles, exploiting the trust users place in scheduling tools. Unlike emails, calendar entries are added automatically, persist even after source emails are deleted, and often escape traditional security inspection. They can contain malicious links, QR codes, and fake branding. Experts recommend treating .ics files like attachments, using phishing-resistant MFA, and training staff to question unexpected calendar-based HR or payroll notifications.

Mirage2FA Phishing Kit Bypasses MFA to Hijack Microsoft 365 Sessions, Targeting 3,500+ Organizations

Matched: health

A phishing-as-a-service toolkit called Mirage2FA, linked to the group LinX Coders, has potentially compromised 4,532 Microsoft 365 accounts across 3,518 organizations in 94 countries, with 63.7% of victims in the US. The kit uses HTML, XHTML, and SVG attachments to deploy adversary-in-the-middle proxies that capture authenticated session cookies, bypassing MFA without dropping malware. Over half of 9,332 recorded compromise events involved cookie theft, making simple password resets insufficient for remediation.

Aus mutual banks are trying to balance human personal touch and AI efficiency

Matched: Australia

Australian mutual banks are working to balance AI efficiency with the personal service their customers value. Unlike larger banks, mutuals built their reputation on human connection, making the shift toward AI tools more delicate. They are exploring automation for back-end processes while preserving face-to-face and personalised interactions where customers expect them most.

Pro-nuclear lobby group says nuclear power the best solution to data centre energy demands in Australia

Matched: Australia

A pro-nuclear lobby group, Nuclear for Australia, argues that nuclear power is the best way to meet growing energy demands from AI data centres while keeping household electricity bills affordable. The non-profit contends other energy sources cannot adequately handle the load, though critics dispute this claim.

Microsoft Teams Outage Largely Mitigated After Users Lost Access to Multiple Features

Matched: health

Microsoft Teams suffered an outage on August 26, 2026, primarily affecting Asia-Pacific users who could not join or create meetings, with some unable to share screens. Microsoft attributed the disruption to maintenance activity with unintended consequences. By 7:26 a.m. IST, the company reported the issue largely mitigated and said engineers would monitor for 15–30 minutes to prevent recurrence. One-to-one calls remained functional during the incident.

Report: Australian CEOs face cyber accountability gap as AI accelerates attacks

Matched: Australia

More than half of Australian security professionals expect CEOs to lose their jobs following a major cyber breach, yet research highlights a significant gap between board-level accountability and actual operational preparedness. The disconnect is worsening as AI accelerates the pace and sophistication of attacks, raising concerns that leadership responsibility is outpacing organisations' real-world cyber defences.

Busted! Interpol-led operation targeting West African cybercrime groups nets 58 arrests

Matched: Australia, cryptocurrency

An Interpol-led operation involving 22 countries across six continents resulted in 58 arrests targeting West African cybercrime groups. Operation Jackal IV focused on dismantling romance scam and cryptocurrency fraud networks. Australia was among the participating nations. The operation also led to the identification of hundreds of additional suspects and the seizure of assets linked to the criminal organizations.

Young Aussies can’t afford financial advice, use AI tools instead

Matched: Australia

Young Australians are increasingly turning to AI tools for financial guidance due to the high cost of traditional advice, according to Webull Australia. The online broker's findings show young Aussies lead AI adoption for financial queries, reflecting a broader trend of cost-conscious consumers seeking affordable alternatives to licensed financial advisers.

Of course, this fake GTA VI ISO download is malware — testers reveal 113GB download is 99.99% empty zeroes, with a tiny virus attached

A fake GTA VI ISO circulating on torrent sites is almost entirely empty data, with testers finding 113GB of zeroes concealing a roughly 50KB malware payload. The inflated file size was designed to mimic a legitimate game release. The malicious code reportedly disables Windows Defender and other security tools via PowerShell commands. Interest in GTA VI leaks has made fans easy targets, with Rockstar's official release scheduled for November.

New Windows malware lays dormant until a custom command activates it like a sleeper agent

SLEEPWALKER is a newly discovered Windows malware implant that contains no malicious code, instead lying dormant until receiving a specially crafted network signal. Disguised as ESET's Management Agent, it evades security software entirely. Once activated, it can schedule tasks, communicate with remote systems, and execute code. Researcher Dominik Reichel believes it's likely a nation-state tool targeting specific victims, though no active campaigns or confirmed victims have been identified.

ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions

Matched: health

ToxNetV2 is a Linux botnet targeting AArch64 systems that integrates NVIDIA's NIM AI service into its controller to suggest attack commands. The controller feeds system and botnet data to the AI model, parsing structured responses into a queue of proposed actions — including shell commands, SSH access, and file operations — that human operators must approve before execution. The botnet uses a peer-to-peer structure and includes scanning, self-propagation, and 17 network-attack modules. Researchers at JOESecurity noted the malware embeds a jailbreak prompt to reduce AI refusals.