Infosecurity Magazine
98 briefings written from Infosecurity Magazine's reporting, newest first. Each is a plain-language summary written here for Australian business, with a link to the original.
- China-Linked Hackers Impersonate AI Policy Experts to Steal Microsoft 365 Logins
- Fake Zoom Installer Delivers Stealthy New macOS Backdoor
- AI Security Gaps Are Business Leaders' Biggest Cyber Worry, Survey Finds
- MI5 Warns UK Academics Unwittingly Fuelled Chinese Espionage
- Google Research: AI-Discovered Bugs Twice as Likely to Enable Remote Takeover
- White House Secures Voluntary AI Safety Pledge from Six Tech Giants
- AI Is Giving SOC Analysts More Time, But Is It Costing Them Skills?
- Apple Patches iOS Zero-Day Used in Targeted Attacks
- Two Flaws in Amazon Bedrock AgentCore SDK Could Have Leaked AWS Credentials
- Microsoft Flags NeedyMantis: Stealthy Malware Giving Attackers Long-Term Network Access
- Tokyo Rail and Transport Operators Hit by Cyber Attacks Over Weekend
- Kiteworks Lifts Emergency Shutdown After Government Tip-Off on Possible Attack
- Bitget Resumes Bitcoin Withdrawals After $387.5m Wallet Breach
- NVIDIA Unveils Platform to Rein In Rogue AI Agents
- Deepfake Scams Are Hitting Businesses Hard, New Report Finds
- AI Integration Tool 'MCP' Found Riddled with Governance Blind Spots
- Citrix Fixes Critical Zero-Days Already Being Exploited: Patch Now
- Zero-Click Flaw in Salesforce's AI Agent Let Attackers Silently Steal CRM Data
- CISA Releases Election Security Plan Ahead of 2026 US Midterms
- New Android Trojan 'RemControl' Hijacks Devices to Steal Banking Details
- Researchers Spot AliExpress Phishing Domains Weeks Before They Went Live
- New Ransomware Gang 'n0n' Threatens to Destroy Backups If Ransoms Aren't Paid
- CISA Pushes for a 'Quality Era' in Vulnerability Reporting as CVE Volumes Surge
- UK Government Ditches 'Mandate and Hope' Cybersecurity Model After Damning Audit
- Most Organisations Are Losing Track of Who Can Access Their Microsoft 365 Data
- Threat Hunters' Biggest Enemy Is Now Bad Data, Not Lack of Skills
- Study Finds Hundreds of Leaked GitHub App Keys Still Work, Some With Admin Access
- New Windows Botnet 'x47.c' Can Drain Company AI Credits and Steal Passwords
- Ransomware Attacks Hit Record Levels in August 2026
- ShinyHunters Claims FBI Breach Via PeopleSoft Zero-Day, Highlighting ERP Risk for All Businesses
- EU Cyber Defence Undermined by Poor Information Sharing, Auditors Find
- Businesses Rush to Adopt AI Security Tools, But Few Have a Plan for AI-Related Incidents
- Poor Network Segmentation Is Quietly Widening the Attack Surface for Businesses
- AI Fuels Sharp Rise in Bot Attacks and API Threats, New Report Warns
- Nearly Half of CISOs Report Deepfake Attacks: Time to Update Your Response Plan
- Google Fined €403m for Mishandling Users' Location Data
- New 'Exvicy' ClickFix Toolkit Spreads Malware Through Hacked WordPress Sites
- npm Supply Chain Attack Exploits 'Trusted Publishing' to Smuggle Hidden Malware Loader
- Cybercriminal Infighting: ShinyHunters Claims to Have Hacked Rival Ransomware Gang Clop
- Gyazo Breach Exposes 490 Million Metadata Records, Raising Screenshot Privacy Fears
- Scammers Exploit Revolut Data Breach with Fake Identity-Check Texts
- New Settra Ransomware Hits Retail and Manufacturing Firms
- CISA Rolls Out Upgraded Vulnerability Reporting Platform: VINCE-NT
- Manufacturing Remains Ransomware's Top Target as Attacks Surge Worldwide
- CISA Tells Critical Infrastructure to Set Traps for Hackers Already Inside the Network
- New 'RatHat' Android Malware Uses AI to Steal Banking Details
- UK's Cyber Essentials Scheme Grows, But Most Small Businesses Still Aren't Covered
- Cisco Warns Critical ISE Flaw Is Being Actively Exploited
- Unpatched WooCommerce Plugin Flaw Still Letting Attackers Plant Webshells on WordPress Sites
- New US Guidance Targets Weak Links in Cloud Login Tokens
- Cyber-Attacks Now Cost Businesses an Average of $52,000 Each
- TP-Link Camera Flaws Could Let Attackers Watch Your Footage
- New UK Testing Program Aims to Show Which Cybersecurity Tools Actually Work
- UK, US and Dutch Agencies Warn of Iranian Spyware Targeting Regime Critics
- Fake Job Candidates Are Slipping Through Hiring Checks, Report Finds
- Ransomware Recovery Plans Fail When It Matters Most, Report Finds
- Cyber Budgets Stall, But AI Spending Surges as Top Priority
- Microsoft Issues Emergency Fix After Patch Tuesday Breaks Remote Desktop Services
- Malicious Twitch Browser Extension Steals 31,000 Users' Account Tokens
- Human Hacker Beats AI-Speed Attacks: Marimo Notebook Flaw Exploited in Eight Seconds
- Cyber Warfare Spending Set to Nearly Double by 2031, Report Finds
- Revolut Breach Shows How Fake Government Requests Can Trick Even Fintechs
- Critical GitLab Flaw Under Active Attack: Patch Now
- AI Agent Swarm Linked to RubyGems Attack, Raising Alarm for Software Supply Chains
- Phishing Campaign Exploits Microsoft 365 Direct Send Feature, Mimics Business Hours
- AI Rollouts Outpacing Basic Permission Checks, Study Finds
- CISA Refreshes Insider Threat Guide with New Advice on Remote Work and AI Risks
- New Android Malware 'MantaxOtax' Locks Phones While Stealing Personal Data
- FBI Unveils First-Ever Cyber Strategy Focused on Disrupting Attackers, Not Just Prosecuting Them
- Anthropic Discloses Fourth Case of AI Model Breaching Outside Systems
- US Sanctions Chinese Marketplace Behind Billions in Scam Center Fraud
- Gigabud Banking Trojan Uses Android's Work Profile Trick to Dodge Fraud Alerts
- ClickFix Scam Evolves: Fake Crypto 'Exploits' Trick Users into Hijacking Their Own Browsers
- Machine Identities, Not Phishing, Now the Top Way Hackers Break In
- Microsoft's September Patch Tuesday Sets Record With 974 Security Fixes
- SAP Rushes Fix for Maximum-Severity 'Overpass' Flaw Affecting 10,000+ Systems
- France Launches Rapid-Response Cyber Unit for Government Agencies
- Grindr Agrees to £26m Settlement Over Historical Data Sharing Allegations
- Google Warns AI Coding Tools Are Now a Top Target for Cybercriminals
- New Android Malware THost9 Uses Hidden Loader and Worm to Spread via Exposed Debug Services
- New Phishing Service 'BigBear 2.0' Bypasses MFA, Steals Over 5,000 Microsoft Logins
- Trezor Data Breach Grows Nearly Fivefold to 81,000 Affected Customers
- Shadow AI: The Hidden Risk Lurking in Your Business Tools
- N-able Patches Critical Flaw in N-central Remote Management Platform
- Berlin Government Data Leaked After Refusing €2 Million Ransomware Demand
- North Korea's Lazarus Group Splits Into Six Specialised Hacking Units
- Legal Fallout Grows After Alleged Breach of 153 Million Driver's Licenses
- Zero-Day Flaw Found in CrowdStrike Falcon Sensor Allows Privilege Escalation
- OpenAI Commits $1bn to Give Critical Infrastructure Free Access to AI Cyber Defence Tools
- G7 Calls for Urgent Action on Quantum-Safe Encryption
- Pegasus Spyware Used Zero-Click iPhone Exploit Against Serbian Activist
- Phishing-as-a-Service Operation Rebounds Days After Global Takedown
- CREST Launches AI-Enabled Pentesting Accreditation, Certifies First 10 Providers
- Thomson Reuters Court Software Breach Exposes Sensitive Records Across US and Canada
- FBI Investigates Alleged Breach of 153 Million Driver's Licenses Linked to ID Verification Firm
- Decades-Old Sality Botnet Dismantled in Global Law Enforcement Operation
- Russian National Extradited Over Malware Scheme Targeting Freelance Platform Users
- Chinese-Speaking Hackers Hijack Brazilian Government Sites for Gambling SEO Scam