Cybersecurity News

Filters
Tag

High Alert! ACSC warns of hackers targeting Aussie orgs using TeamCity On-Premises

Matched: Australia

Australia's cyber security agency has warned that hackers are actively exploiting a vulnerability in JetBrains' TeamCity On-Premises software to target Australian organisations. The flaw, roughly a month old, allows attackers to gain unauthorised access to affected networks. The ACSC is urging organisations using the platform to apply available patches immediately to reduce their exposure.

Even connected car head units are being targeted by hackers now — experts warn in-car systems are at risk of being hijacked into a botnet

Kaspersky has identified the first malware campaign built specifically to target Android-based car head units, linking it to the MoYu Group behind the BadBox botnet. Attackers hijacked a legitimate software update channel in DoFun-manufactured devices to silently deliver malware capable of ad fraud, displaying unwanted ads, and harvesting device data. The malware runs invisibly with no user-facing interface. DoFun says the issue has since been resolved on most affected devices.

New malware targets Microsoft Teams users by posing as your company's IT helpdesk

A new backdoor malware called SynkLoader is targeting Microsoft Teams users via fake IT helpdesk messages urging victims to install a malicious "PowerShell Cleaner" hosted on Azure. Key modules include PhishLocker, which displays a fake Windows login screen to steal passwords, and Interactive Shell, enabling full remote control. Organizations are advised to treat unsolicited Teams messages with suspicion and verify requests directly with IT.

New Guidance Helps Businesses Verify Quantum-Safe Hardware Claims

The Trusted Computing Group has released guidance to help businesses verify whether trusted platform modules genuinely meet quantum-safe security requirements. The move addresses growing concerns that hardware marketed as quantum-resistant may not deliver on those claims, giving organisations clearer tools to assess and confirm the cryptographic capabilities of security hardware as quantum computing threats advance.

NIST Warns of Unique Security Risks in Multi-Cloud Environments

NIST has identified 23 unique security challenges posed by multi-cloud environments, where organizations use services from multiple cloud providers simultaneously. The risks include increased attack surfaces, complex identity management, inconsistent security policies, and difficulties in data governance. NIST is calling on the cybersecurity community to develop solutions to address these emerging threats as multi-cloud adoption continues to grow.

Fake Codex Download Uses Google Sites to Deliver macOS Malware

Attackers created fake codec download pages hosted on Google Sites to distribute macOS malware. The campaign used sponsored search results to drive traffic and employed a ClickFix-style social engineering technique, tricking users into manually running malicious commands. The use of Google's infrastructure helped bypass security warnings and lend the pages false legitimacy.

Canadian SickKids hospital hit again by cyberattacks, more data stolen

Canada's SickKids pediatric hospital suffered a cyberattack exploiting a third-party software vulnerability, exposing personal data of current and former employees and job applicants. Clinical systems and patient records were unaffected. Those impacted are being offered 24 months of free credit monitoring. The hospital was previously hit by LockBit ransomware in late 2022, marking this its latest security incident.

Private equity giant Apollo confirms data breach saw personal info stolen

Apollo Global Management confirmed a cyberattack between July 6–10, 2026, in which a threat actor used social engineering to access its cloud environment. Stolen data included names, dates of birth, contact information, addresses, and Social Security numbers. Financial data was not compromised. Apollo notified authorities, engaged forensic experts, and is offering affected individuals two years of free identity protection. No group has claimed responsibility and the data has not appeared on the dark web.

Doubloon Dredger Abuses Notion to Harvest Authentication Tokens

A threat actor dubbed Doubloon Dredger used malicious PDFs to redirect victims to fake Microsoft login pages hosted via Notion. The campaign harvested Microsoft authentication tokens, exploiting Notion's legitimate infrastructure to evade detection. The abuse of trusted platforms helped the attackers bypass security filters while capturing credentials from targeted users.

Microsoft August 2026 Windows Updates Trigger Issues on Devices Using RGB Lighting Features

Matched: health

Microsoft is investigating a Windows 11 issue where August 2026 security update KB5121003 causes games to freeze, crash, or trigger PC restarts on devices with RGB lighting hardware. The problem involves the inpoutx64 driver used by RGB peripherals and components. Affected games include ARC Raiders, MARVEL Tōkon: Fighting Souls, and THE FINALS. As a workaround, Microsoft advises disabling the driver via Registry Editor. Windows Server is unaffected.

AmnesiaStealer Gives Hackers Hidden Control of Logged-In Browsers on Macs

Matched: cryptocurrency

AmnesiaStealer is a new macOS malware spread via fake GitHub pages that trick users into running a Terminal command. Beyond stealing passwords, cookies, and keychain data, it can silently mirror an active browser session in a hidden Chromium instance, giving attackers real-time control of already-authenticated accounts. This makes MFA protections ineffective. A LaunchDaemon ensures persistence after the initial infection.

Why "I approve" can become the most dangerous button in enterprise AI

Enterprises rushing to deploy autonomous AI agents risk creating accountability gaps when humans shift from active decision-makers to passive reviewers. Approval workflows can become meaningless rituals as alert volumes rise. AI agents acting on networks need governed identities, bounded permissions, and audit trails explaining not just actions but reasoning. Multi-agent chains compound traceability problems. Organizations should expand agent autonomy gradually, like junior employees earning access, backed by proper identity and observability infrastructure.

Why most organizations are getting AI security wrong (and why it’s about to catch up with them)

Organizations are deploying AI rapidly without adequate security frameworks, creating dangerous gaps. Unlike traditional applications, AI operates as a dynamic chain of events — prompts, model responses, agent actions, data retrieval — where risks exist throughout, not at single points. Traditional security tools sit around AI rather than within it, reacting after the fact. Security decisions trail behind innovation teams, and bolt-on tools fail to address AI's cross-cutting nature. Effective AI security requires embedding controls directly into execution paths, particularly traffic flows where requests and responses are processed.

The ascent of autonomous attacks and the race to contain them

AI is enabling autonomous cyberattacks that can conduct reconnaissance, breach systems, and adapt without human input. A 2025 Jaguar Land Rover attack cost £485m in losses. Smaller businesses face growing exposure as AI scans for vulnerabilities at scale. Defenses need to shift toward continuous monitoring, strong identity controls, and AI-powered detection, supported by human expertise, to counter threats moving faster than traditional security measures.

Fake CAPTCHA Tricks Mac Users Into Installing a Backdoor That Steals Passwords and Mines Crypto

Matched: cryptocurrency

A ClickFix campaign is targeting Mac users with a fake CAPTCHA page styled as "TrustKey" that tricks victims into running a malicious Terminal command. The command fetches an AppleScript payload via Cloudflare Workers, installs a persistent LaunchAgent, and uses blockchain-based EtherHiding to locate its command server. The backdoor steals browser credentials, keychain data, and crypto wallet information, while also deploying XMRig to mine Monero. Any CAPTCHA requesting Terminal access should be treated as malicious.

Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant

An Iranian cyberattack that temporarily shut down a UK power plant has prompted warnings from security experts about vulnerabilities in critical national infrastructure. Analysts say the incident exposes inadequate defenses across key sectors and are calling for urgent investment in cybersecurity measures, improved threat intelligence sharing, and stronger regulatory frameworks to protect essential services from increasingly sophisticated state-sponsored attacks.

What airports can teach us about the power of invisible business AI

Airports appear effortless to travelers but rely on complex, invisible coordination between dozens of systems and stakeholders. Businesses face the same challenge. The article argues AI's greatest value lies not in headline-grabbing applications but in behind-the-scenes operational intelligence — connecting data sources, anticipating disruptions, and enabling adaptive responses. Like well-run airports, successful businesses will embed AI into core processes so customers simply notice that everything works.

Who really needs Forward Deployed Engineers around AI?

Major tech firms are heavily investing in Forward Deployed Engineers to help enterprises implement AI. AWS pledged $1 billion, OpenAI acquired deployment specialist Tomoro, and Microsoft announced a $3.5 billion AI delivery unit. FDEs embed within companies to bridge the gap between probabilistic AI systems and deterministic business environments. However, heavy reliance on FDEs signals AI market immaturity — as the technology matures, standardized deployment should reduce dependence on specialized human intervention.

Researchers Uncover Thousands of Leaked AWS Keys

Truffle Security researchers discovered more than 9,000 active, publicly exposed AWS key pairs on GitHub. The leaked credentials, embedded in public repositories, could allow attackers to access cloud resources and sensitive data. Many keys remained valid despite being public. The findings highlight ongoing risks from developers accidentally committing credentials to code repositories without proper secrets management practices.