Section
Cybersecurity
ASX 200 infostealer infections are now a board risk
ASX 200 infostealer infections are exposing how stolen credentials and shared suppliers can turn a solid cyber score into real board risk.
Device code phishing surges as ASD warns Microsoft 365 users
Device code phishing is targeting Australian Microsoft 365 users, the ASD has warned, as Proofpoint tracks a surge in criminal toolkits and phishing-as-a-service platforms.
Google publishes Chromium exploit code before patch lands
Chromium exploit code was published before a fix was broadly available, raising short-term risk for Chrome and other browsers built on Google's engine.
GitHub breach exposes 3,800 repos in VS Code attack
GitHub breach exposed about 3,800 internal repositories after a poisoned VS Code extension hit one employee device, widening supply-chain concerns.
Claude Code sandbox bypass patched after 130 releases
Anthropic patched a Claude Code sandbox bypass affecting about 130 releases, showing how AI coding tools can expose developer workstations.
OpenAI Daybreak: CBA, Westpac test cyber defences
OpenAI Daybreak is being tested by Commonwealth Bank and Westpac, bringing agentic cyber defence tools into Australian banking workflows.
EY cyber report retracted after AI citation errors
EY pulled a cybersecurity report after GPTZero found more than 70 per cent of its 27 citations were AI-generated, invented or misattributed.
Baidam and AUSCERT sign 12-month cyber pact on threat sharing
Baidam and AUSCERT have signed a 12-month pact covering threat intelligence, incident response, phishing takedowns and training for Australian organisations.
Developer workstations are the new supply-chain weak link
Developer workstations are emerging as the new supply-chain weak link as attackers pivot from package registries to laptops, tokens and CI access.
Windows MiniPlasma exploit gives SYSTEM access as PoC goes public
A Windows proof of concept dubbed MiniPlasma has put enterprise defenders on alert after researchers said the privilege-escalation bug could still reach SYSTEM on patched machines.
Grafana says GitHub token breach led to code download, extortion attempt
Grafana says a stolen GitHub token let an attacker download its codebase and demand a ransom, with no evidence of customer-data exposure or system impact.
Infosys opens North Sydney security operations centre for ANZ clients
Infosys has opened a dedicated Global Security Operations Center in North Sydney, expanding 24/7 monitoring and incident response for ANZ customers.
Apple, Google and Microsoft push passkeys, but recovery still matters
Passkeys are becoming the default sign-in option across major platforms, but the real question in 2026 is whether recovery and cross-device portability are finally good enough for mainstream users.
Researchers say Mythos sped Apple M5 Mac exploit development
Calif says Anthropic's Mythos Preview helped build a working exploit against Apple's M5 memory protections in five days, sharpening the Mac fleet security debate.
BitLocker explained: when Windows users should turn on drive encryption in 2026
BitLocker is still worth enabling for many Windows users, but the real 2026 decision sits around recovery keys, device encryption and how much control each Windows edition gives you.
ASIC Names Mythos in Urgent Cyber Warning to Financial Sector
ASIC has issued an urgent open letter to the financial services industry naming Anthropic's Claude Mythos as a frontier AI threat capable of triggering 'system-wide domino effects', and setting out 12 action steps for firms to strengthen their cyber defences.
Budget boosts AI, but cyber gaps remain, industry warns
The 2026-27 federal budget commits billions to AI and digital infrastructure, but cybersecurity spending tilts toward large institutions while SMEs remain exposed.
CTV ad fraud surges 140 per cent as AI-powered schemes spread globally
Connected TV fraud schemes jumped 140 per cent in the March quarter, with AI-powered bot attacks and data centre traffic costing advertisers US$1.8 million per billion unprotected impressions, according to new research from DoubleVerify.
Australia's $7.5B cybersecurity market: scale vs local split
Enterprises will spend AU$7.5B on cybersecurity in 2026. Global platforms dominate yet consolidation splits the market between scale and local sovereign accountability.
Instructure reaches deal with ShinyHunters as Canvas breach hits Australian universities
The company behind the Canvas learning platform says stolen data has been returned and destroyed, but declines to say whether any payment was made.
BitLocker comes free with every Windows PC. Here is how to set it up.
Windows 11 can encrypt every byte on your hard drive using BitLocker or Device Encryption, and on new PCs it is often turned on before you reach the desktop. The Australian Signals Directorate recommends full-disk encryption for any device handling customer data, and the software is already built into Windows at no extra cost.
Stop guessing if your data leaked. Here's how to check in 60 seconds.
Seventeen billion compromised accounts sit inside Have I Been Pwned, the free Australian-built breach checker that tells you in under a minute whether your email address was exposed. Here is how it works, what else to use, and what to do after the bad news lands.
ShinyHunters claim 275 million Canvas LMS records, set 12 May leak deadline
The hacking collective ShinyHunters says it has stolen 275 million records from Instructure's Canvas learning platform, naming Australia among affected regions. The vendor has confirmed an intrusion of its Salesforce environment, the second by the same actor in eight months, with a 12 May leak deadline.
The case for end-to-end encrypted email, and the four services that actually deliver it
Three independent providers build proper end-to-end email encryption: Proton Mail, Tuta Mail, and Mailfence. Microsoft 365 with S/MIME sits beside them for compliance-bound enterprises. Everything else is metadata theatre.
Australian households need a real password manager. Two are worth using.
Browser-saved passwords leak, breached vaults like LastPass keep surfacing, and the Australian Cyber Security Centre keeps repeating the same advice. The two managers worth installing today are 1Password and Bitwarden, with Proton Pass close behind for households committed to the Proton suite.






















