Cybersecurity News

Filters
Tag

Faulty towers: Quest hotel chain discloses third-party customer data breach

Matched: Australia

Australian hotel apartment chain Quest has disclosed a data breach affecting customer information, including names, email addresses, and dates of birth. The breach originated from a third-party supplier rather than Quest's own systems. Affected customers have been notified and warned to remain vigilant against potential phishing attempts and scams that may exploit the compromised data.

ACSC warns of active exploitation targeting N-able N-central in Australia

Matched: Australia

The ACSC has issued a high-priority alert warning of active exploitation of vulnerabilities in N-able N-central, a remote monitoring and management platform, targeting Australian organisations. The centre is urging affected users to apply patches and mitigations immediately. N-able N-central is widely used by managed service providers, meaning exploitation could have downstream impacts on multiple client organisations.

No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns

Matched: cryptocurrency

A platform called "Kriminal" offers an AI service with no content restrictions, marketed toward cybercriminals. Accessible via cryptocurrency, it provides social engineering scripts, offensive hacking tools, and open-source intelligence scanning. Despite official terms prohibiting illegal use, researchers warn the guardrail-free system meaningfully lowers the barrier for cybercrime, enabling even unskilled actors to conduct sophisticated attacks.

ASD warns of Australian attacks on N-able N-central RMM

Matched: Australia

Australia's signals directorate has warned of active attacks exploiting a critical authentication bypass vulnerability in N-able's N-central remote monitoring and management software. The flaw effectively grants attackers administrator-level access without credentials. Organisations using the platform are urged to apply available patches immediately, as the software's privileged network access makes it a high-value target.

What Is a Website Attack Surface? A Beginner’s Guide to Reducing Risk

A website's attack surface includes all exposed components that could be exploited, such as login pages, contact forms, plugins, APIs, and forgotten staging sites or backups. Every added feature introduces new elements requiring management and potential vulnerability. Reducing risk involves identifying and minimizing these exposed components to limit opportunities for attackers to compromise the site.

Comcast is adding motion detection to millions of routers, and I’m worried it’s a privacy nightmare

Comcast is rolling out motion-detection capabilities to its Xfinity routers using WiFi signals to sense movement in homes. The feature, which doesn't require cameras, works by analyzing wireless signal disruptions. Many customers are concerned about privacy, particularly around who can access the data and how it's stored. Comcast says the feature is opt-in and data stays local, but critics remain skeptical.

Experts manage to hack Microsoft Copilot by continually asking it questions about itself

Researchers discovered they could manipulate Microsoft Copilot by persistently questioning it about its own nature and system instructions. Through repeated probing, the AI revealed internal configurations it was meant to keep hidden. The findings highlight concerns that AI assistants can be socially engineered into bypassing safeguards, raising questions about whether current security measures are sufficient for enterprise deployment.

Microsoft smothers malware by tracking behavior instead of blocking domains

Microsoft has shifted its malware defense strategy from blocking malicious domains to tracking behavioral patterns. Because attackers can rapidly automate new domains to replace blocked ones, domain-blocking proves ineffective. By monitoring how malware behaves rather than where it connects, Microsoft aims to identify and neutralize threats more reliably, staying ahead of attackers who exploit the limitations of domain-based defenses.

Hackers Actively Exploiting macOS’s Built-in Screen Sharing Service Vulnerability in the Wild

Matched: cryptocurrency

Hackers are exploiting a flaw in macOS's built-in Screen Sharing service to gain root-level access to devices. Attackers are using the remote-access feature to place files, alter system settings, and deploy cryptocurrency mining malware. The threat is notable because Screen Sharing ships enabled on many Macs, giving attackers a widely available entry point on a limited number of targeted systems.

Bluesky reveals recent outage was caused by major DDoS attack

Bluesky experienced a significant outage caused by a distributed denial-of-service (DDoS) attack, the company confirmed. The attack overwhelmed its systems, disrupting access for users. Iranian state-backed threat actors claimed responsibility, though Bluesky has not verified that claim. The platform has since restored service and is working to strengthen its defenses against future attacks.

AI needs rules and rails: Why governance must move beyond policy

As AI adoption accelerates, organizations need more than high-level policy — they need practical operational guardrails. Governance must translate abstract principles into enforceable standards covering data use, model accountability, and risk management. Without structured frameworks embedded into workflows, AI systems risk drifting from business objectives, creating compliance gaps and unintended consequences. Effective governance requires collaboration across technical, legal, and business teams.

SMEs aren’t too small to target for cybercriminals, they’re too exposed to ignore

Small and medium-sized businesses are increasingly targeted by cybercriminals due to weaker security defenses compared to larger organizations. Despite holding valuable data and often serving as supply chain entry points to bigger companies, many SMEs underestimate their risk exposure. Limited budgets and IT resources leave them vulnerable, making them attractive, easy targets rather than overlooked ones.

US charges 17 Iranian nationals over “massive cyber theft campaign”

Matched: Australia

The US Justice Department has charged 17 Iranians linked to a company called Emennet Pasargad over a large-scale cyber theft campaign targeting academics worldwide, including in Australia. The hackers allegedly stole research, credentials, and other sensitive data. Several of those charged are also accused of previous interference in US elections.

Australia & Thailand to strengthen cooperation on fighting cybercrime

Matched: Australia

Australia and Thailand have agreed to strengthen cooperation on combating cybercrime and transnational crime, following talks between Prime Minister Anthony Albanese and Thai PM Anutin Charnvirakul. The two leaders released a joint statement outlining their commitment to deeper collaboration on cross-border criminal activity, reflecting shared security concerns in the region.

ASIC warns scammers are using AI to create deepfake investment scam networks

Matched: Australia

Australia's financial regulator ASIC has warned that scammers are using AI to build networks of fake investment websites, making online searches an unreliable verification method. The deepfake sites mimic legitimate businesses and can include fabricated celebrity endorsements. ASIC urged Australians to independently verify investment opportunities through official registers rather than relying on search results.

'The attacks we found only scratch the surface of what is possible': Experts say so-called 'Proactive SIM' cards can hijack smartphones, IoT devices and even EV chargers

Researchers warn that "Proactive SIM" cards can exploit a decades-old telecom standard to execute commands on host devices without user interaction. The vulnerability affects smartphones, IoT devices, and EV chargers. Because the SIM sits inside the device and communicates directly with its processor, a compromised or malicious card can run code invisibly, and researchers say discovered attacks likely represent only a fraction of what's possible.

'This technology turns every router into a potential means for surveillance': Report claims Wi-Fi devices could 'quietly identify' people with nearly 100% accuracy

Researchers have demonstrated that standard Wi-Fi routers can identify individuals with nearly 100% accuracy by analyzing how their bodies disrupt wireless signals. Tested on 197 people, the technique requires no cameras or wearables. Privacy advocates warn this could enable covert mass surveillance through existing infrastructure, as virtually any Wi-Fi network could potentially be used to silently identify people.