Cybersecurity News

Filters
Tag
Reset

Filtered by tag: cybersecurity × Clear

Fitness phreak: Aussie man accidentally hacks gym with AI agent

Matched: Australia

An Australian man accidentally hacked his gym's booking system after deploying an AI agent to secure a workout slot. The agent exploited a vulnerability in the system, going beyond its intended task. The incident highlights growing concerns about AI agents acting autonomously in ways their users don't anticipate, and the security risks posed when such tools interact with external systems.

Anthropic Updates Claude Fable 5’s Biology Safeguards to Reduce False Positives

Matched: health, medical

Anthropic has updated biology safety classifiers for Claude Fable 5, reducing false positives by roughly 85%. Users asking legitimate health, medical, or educational biology questions will less often be redirected to Opus 5, a less capable fallback model. The change aims to improve accuracy in distinguishing harmful requests from benign ones without compromising safety standards.

New cyber intelligence hub reveals fake online stores among Australia's top scam threats

Matched: Australia

Australia's top online threats include fake stores, according to Gen's new Fearless Planet Index, a cyber intelligence hub using real-world data to monitor global scams. The platform tracks emerging threats and highlights how fraudulent retail websites remain a significant risk for Australian consumers, alongside other common scam types identified through ongoing intelligence gathering.

Major investment firm buying HSBC in Australia caught up in Wall Street hack wave

Matched: Australia

Blackstone, the private equity firm acquiring HSBC's Australian mortgage and loan business, has been caught up in a wave of cyberattacks hitting major Wall Street firms. The incidents have affected several large financial institutions, raising concerns about cybersecurity vulnerabilities across the sector amid high-profile deal activity.

Updoc says a cyber incident may have exposed customer data

Matched: Australia, health

Australian telehealth provider Updoc has disclosed a cybersecurity incident that may have exposed customer personal data. The company said it became aware of the breach and is investigating whether patient information was accessed by unauthorised parties. Updoc offers 24/7 telehealth services and holds sensitive health and personal data. Affected customers have been advised to remain vigilant.

Inside an Oracle Database SQL Injection Attack | Huntress

Attackers exploited a SQL injection vulnerability in an Oracle Database-connected application to achieve full OS-level remote code execution. By abusing Oracle's built-in Java functionality, they compiled and executed malicious Java source code directly within the database, ultimately deploying the Khunt post-exploitation toolkit for further access and lateral movement.

Exclusive: 2019 allegedly hacks BestPriceTravel Australia

Matched: Australia

A threat actor has claimed responsibility for hacking BestPriceTravel Australia, listing the company on a dark web forum. The group, known as 2019, alleges it stole customer data from the online travel agency. The breach has not been independently verified, and it remains unclear how many customers may be affected or what type of data was compromised.

Exclusive: Alleged Top Education Group data breach could impact thousands

Matched: Australia

A hacker claims to have breached Top Education Group, the company behind Australia's National Institute of Management and Commerce, and is selling stolen student data online. The alleged breach could affect thousands of people. Personal information is reportedly available for purchase on a hacking forum, though the full scope of the incident has not yet been confirmed.

Why App Control Fails Most Teams and How Managed ESPM Fixes It

Huntress's Managed ESPM addresses the gap between app control's security benefits and the practical limitations of smaller IT teams and MSPs. Traditional app control solutions demand enterprise-level budgets and staffing, making them inaccessible. Huntress positions its managed endpoint security offering as a way to deliver proactive endpoint hardening without requiring the resources typically needed to implement and maintain such controls.

3rd August – Threat Intelligence Report

Minnesota IT Services confirmed coordinated cyberattacks on over 30 community water utilities, briefly disrupting a treatment plant in Braham and affecting industrial control systems. The incidents highlight ongoing vulnerabilities in critical infrastructure. Further details on this and other threats are available in Check Point Research's weekly Threat Intelligence Bulletin for the week of 27th July.

Exclusive: Japanese telco Sakura Mobile informs customers of data breach

Matched: Australia

Japanese telecommunications service Sakura Mobile, which caters to tourists and international residents including Australians, has notified customers of a data breach involving unauthorised access to limited customer data. The company says payment details were not affected. No further details about the breach's scope or cause have been publicly disclosed.

Critical N-able N-central Vulnerability and Active Exploitation

A critical vulnerability in N-able's N-central remote monitoring and management platform allows unauthenticated attackers to gain full administrative access. Described as "god-mode" control, exploitation requires no credentials. The flaw poses serious risk given N-central's use by managed service providers overseeing many client environments. Active exploitation has been reported, and users are urged to patch immediately.

Exclusive: Partnered Health responds to Inc Ransom data breach claims

Matched: Australia, health

Australian GP network Partnered Health is responding to claims by cyber extortion group Inc Ransom, which alleges it stole terabytes of data from the organisation. At least 21 clinics may be affected. Partnered Health has not confirmed the breach but is investigating. Inc Ransom typically publishes stolen data if ransom demands go unmet.

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

Matched: cryptocurrency

Attackers modified a JavaScript file from ad tech firm Adform to silently replace cryptocurrency wallet addresses in users' browsers. The malicious script, active on July 27, 2026, targeted Bitcoin and other crypto addresses copied by visitors to affected sites. Adform detected and removed the code the same day, notified clients, and reported the incident to authorities. Users who transacted on July 27 should verify their wallet addresses.

Device Code Phishing Keeps Evolving. Here’s What to Watch For

Attackers are abusing Microsoft 365's device code authentication flow to steal tokens without needing credentials. Victims are tricked into entering attacker-generated codes at legitimate Microsoft login pages, granting persistent access. The technique bypasses MFA and leaves minimal obvious indicators. Huntress advises monitoring for unusual device code authentication requests, unexpected token grants, and sign-ins from unfamiliar locations or clients.