Cybersecurity News
Filters
Fake Refund Scam Hits Shopify Shop App Users
Scammers are targeting users of Shopify's Shop app with fake refund schemes. The scam operates directly within the app, contacting users with fraudulent refund offers. The campaign has been active for several months. Users are advised to be cautious of unsolicited refund messages received through the platform and to verify any communications through official Shopify channels.
The State of Ransomware Q2 2026
Ransomware activity in Q2 2026 shows signs of shifting dynamics, according to Check Point Research. While dominant ransomware-as-a-service operations continue leading the space, the previously consolidating landscape is beginning to fragment. Established groups maintain their dominance, but emerging players are increasingly challenging the concentration of power that has defined the ransomware ecosystem over the past year.
'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft
Matched: cryptocurrency
Researchers have identified a threat actor dubbed "Jewelbug," a hackers-for-hire group conducting both state-sponsored espionage and cryptocurrency theft through the same infrastructure. The dual-purpose operation — mixing intelligence gathering with financial crime — is unusual, suggesting the group serves government clients while simultaneously running independent profit-driven attacks, blurring the line between nation-state and cybercriminal activity.
Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto
Matched: cryptocurrency
Phantom Stealer is a credential-stealing malware that conceals malicious code inside PNG image files to avoid detection. Once executed on Windows systems, it harvests passwords, browser cookies, cryptocurrency wallet data, and other sensitive information. The malware has been used in campaigns targeting users across multiple countries.
De Stefano & Co expands into Melbourne as Victorian defence sector grows
Matched: Australia
Defence security advisory firm De Stefano & Co has opened a Melbourne office, its second in Australia, to capitalise on growing demand across Victoria's defence, aerospace, cyber security, and manufacturing sectors.
CBA bolsters AI investment as business lending sees major growth
Matched: Australia
CBA reported strong full-year results with business lending growing nearly twice as fast as home lending. The bank also announced increased investment in artificial intelligence as part of its broader strategy. No specific figures were provided in the headline details, but the results signal a notable shift in lending momentum toward commercial customers.
Superannuation peak body calls for advice reform as Aussies increasingly turn to AI over experts
Matched: Australia
Australia's superannuation peak body is calling for financial advice reform after a survey found more than a third of Australians have turned to AI chatbots for superannuation guidance. High costs are driving people away from professional advisers. The body warns this trend poses risks, as AI tools may not provide accurate or personalised financial advice, and is urging reforms to make expert advice more affordable and accessible.
Australia to make tech companies pay more outlets for content
Matched: Australia
Australia plans to update its media bargaining law to require tech companies to pay more news outlets for their content. The changes aim to expand the scope of existing legislation, ensuring a broader range of publishers can negotiate payment deals with platforms like Google and Meta. The move follows ongoing disputes over fair compensation for news content online.
Guide to Cybersecurity Budget Planning: How Much + How To | Huntress
Cybersecurity budget planning requires balancing protection needs against available resources. Businesses should assess risks, inventory assets, and prioritize spending on the most critical vulnerabilities. Common budget factors include tools, staff training, incident response, and compliance. Experts generally recommend allocating 10-15% of IT budgets to security, though this varies by industry, size, and risk exposure.
Akira Hits Safe Mode: Ransomware Rebooting Around EDR
An Akira ransomware affiliate attempted to bypass endpoint detection by rebooting a victim's system into Safe Mode, which prevents most security tools from loading. The tactic backfired when Safe Mode also blocked their own ransomware from executing properly. Researchers documented the full attack chain, highlighting how threat actors are adapting techniques against modern EDR solutions, sometimes with self-defeating results.
One in three ANZ organisations still pay ransomware demands, Commvault research says
Matched: Australia
One in three organisations in Australia and New Zealand still pay ransomware demands, according to Commvault research, despite uncertainty about whether data will be recovered or operations restored. The findings highlight ongoing vulnerabilities and suggest many organisations lack confidence in their ability to recover without meeting attackers' demands.
Most lenders are using AI, yet only 3% are data ready
Matched: Australia
A study has found that while most Australian lenders are actively implementing AI, only 3% have the data infrastructure needed to support it effectively. The findings highlight a significant gap between adoption ambition and operational readiness, raising concerns that lenders are deploying AI tools without the foundational data quality and governance required for reliable outcomes.
Report: Australia’s tech workforce shrinks for the first time on record
Matched: Australia
Australia's tech workforce has shrunk for the first time on record, according to the ACS Digital Pulse 2026 Report. While the sector continues contributing to economic growth, the decline in worker numbers is flagged as a significant risk. The report warns that without reversing the trend, the industry's capacity to grow and meet demand could be seriously undermined.
Equinix launches Managed Solutions in Australia
Matched: Australia
Equinix has launched Equinix Managed Solutions (EMS) in Australia, providing managed private cloud and infrastructure services. The offering targets organisations facing long hardware delivery times and rising equipment costs, allowing them to outsource infrastructure management. The service aims to help businesses scale without the complexity of managing physical infrastructure themselves.
Recorded Future’s Insikt Group reports 44% rise in high-impact CVEs in July
Matched: Australia
Recorded Future's Insikt Group recorded an 85 high-impact CVEs in July 2026, a 44% rise from the previous period. The report highlights vulnerabilities that organisations in Australia and New Zealand should prioritise for remediation, reflecting a growing threat landscape requiring urgent attention from security teams.
Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack
North Korean hackers linked to Operation Dream Job have been targeting aerospace and defense companies worldwide since early 2026, using fake job offers as lures. Victims receive malicious PDF files requiring a modified viewer that executes embedded malware. Check Point Research identified the campaign as exploiting a zero-day vulnerability, continuing a long-running North Korean strategy of disguising cyberattacks as recruitment outreach.
How to Create a Secure WordPress Staging Site: Beginner’s Guide
A WordPress staging site lets you test updates and changes before they go live, reducing the risk of breaking your site for visitors. However, staging sites copy sensitive data like admin accounts, customer records, and API keys, making security essential. The article guides beginners through creating a staging environment while ensuring it remains protected from exposure or exploitation.
Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
Matched: cryptocurrency
Researchers created a fake crypto startup and hired three suspected North Korean IT workers to study their tactics. Every company device was monitored. The operation revealed red flags hiring teams can watch for: one worker claimed to live in Texas but submitted a California driver's license and a New York bank account, exposing the inconsistencies North Korean operatives typically display during onboarding.
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Matched: health
South Korean and US cybersecurity agencies have warned about Gunra ransomware targeting critical infrastructure globally, including healthcare, financial services, government, and nonprofit sectors. The attacks exploit vulnerabilities in Fortinet and Schneider Electric systems. Gunra follows a ransomware-as-a-service model and represents a continuing trend of sophisticated ransomware variants threatening essential services worldwide.
Super sector to test cyber resilience in fourth annual Operation Honey Bee exercise
Matched: Australia
More than 50 participants from Australia's superannuation sector will take part in the fourth annual Operation Honey Bee exercise, simulating a major cyberattack to test coordination between funds, service providers, regulators, and government agencies.
