Threat intelligence stories
Cambodia scam compounds linked to mobile banking fraud
Today
#
data protection
#
surveillance
#
biometrics
Cambodia scam compounds are being tied to a mobile banking fraud network that hit users in 21 countries, researchers say.
OPSWAT launches AI file screening engine for MetaDefender
Last week
#
firewalls
#
network security
#
cloud security
OPSWAT adds millisecond AI file screening to MetaDefender, aiming to cut false positives and speed decisions in critical infrastructure networks.
Small alert, big defense: Inside a SOC's early-morning response
Last week
#
vpns
#
ransomware
#
mfa
UK SOC spots Monday-morning conditional access failure from Germany, helps reset compromised Microsoft 365 account before attackers can strike.
Attackers shift upstream into Australia's network edge
Last week
#
firewalls
#
ddos
#
network infrastructure
Lumen says attackers are increasingly exploiting routers, VPN gateways and other edge devices in Australia, with nation-state activity and proxy networks making detection harder.
Lumen warns of malware-backed proxy networks in APAC
Last week
#
firewalls
#
vpns
#
network infrastructure
Lumen says malware-backed proxy networks are helping attackers hide in plain sight across Asia Pacific, as AI speeds up infrastructure changes.
iProov report warns of soaring iOS injection attacks
Last week
#
uc
#
data protection
#
devops
iProov warns iOS injection attacks surged 1,151% in late 2025 as generative AI fuels deepfake impersonation and identity fraud.
Microsoft 365 EvilToken campaign hits hundreds daily
Last week
#
mfa
#
cloud security
#
phishing
Microsoft warns that 10 to 15 EvilToken phishing runs are launched daily, compromising hundreds of organisations through OAuth token abuse.
Qualys warns attackers exploit flaws before disclosure
Last week
#
firewalls
#
vpns
#
network security
Qualys says attackers are exploiting flaws before disclosure as remediation backlogs swell, with edge devices facing the highest risk.
TrendAI: Evolving the cybersecurity value proposition
Last week
#
hybrid cloud
#
digital transformation
#
cloud security
TrendAI urges stronger AI governance as it shifts cybersecurity from fear-based selling to platformised risk reduction for Australian firms.
Microsoft warns of Storm-1175's rapid Medusa attacks
Last week
#
ransomware
#
cybersecurity
#
microsoft
Microsoft says Storm-1175 is exploiting newly disclosed flaws within hours, hitting organisations in the UK and elsewhere with fast-moving Medusa ransomware.
Qualys warns exploitation is outpacing manual patching
Last week
#
firewalls
#
vpns
#
network infrastructure
Qualys study says attackers are exploiting flaws before patches exist, as manual remediation lags and edge systems emerge as the highest risk.
Permiso launches sandbox for AI agent skill security
Last week
#
firewalls
#
network security
#
cloud security
Permiso launches SandyClaw sandbox to detonate AI agent skills and expose hidden runtime risks before they reach enterprise systems.
China-aligned TA416 resumes spying on EU & Mideast
Last week
#
phishing
#
email security
#
cybersecurity
China-linked TA416 returns to spying on European diplomats and later expands attacks to Middle Eastern government targets after Iran conflict.
Vulnetix named Australia's first global CVE authority
Last week
#
malware
#
digital transformation
#
cloud security
Vulnetix expands AI coding defences as Australia's first Global CVE Numbering Authority, opening vulnerability tools to developers nationwide.
Attackers turn trusted tools into cyber weapon
This month
#
malware
#
ransomware
#
advanced persistent threat protection
Attackers abuse trusted tools, remote support software and stolen SSO sessions to breach systems, ReliaQuest says.
Cloud security turns to identity, access & sovereignty
This month
#
data protection
#
hyperscale
#
pam
Executives at Docusign, BeyondTrust and Saviynt say identity, data sovereignty and tighter access controls are now shaping cloud security priorities.
Cloud security experts warn of control plane risks
This month
#
firewalls
#
data protection
#
hybrid cloud
Cloud security specialists say organisations must rethink defences as control plane exposure, swelling telemetry and fragmented tools create fresh risks.
Zscaler flags Xloader malware's tougher obfuscation
This month
#
malware
#
firewalls
#
encryption
Zscaler says Xloader malware has added layered encryption, decoy servers and new obfuscation tricks to hinder analysts.
Google links axios attack to suspected North Korean actor
This month
#
devops
#
advanced persistent threat protection
#
supply chain
Google says the axios npm supply chain attack was linked to suspected North Korean actor UNC1069, raising fears for Australian and New Zealand firms.
DeepLoad malware steals credentials via ClickFix campaign
This month
#
malware
#
firewalls
#
network infrastructure
ReliaQuest flags DeepLoad malware stealing live credentials in enterprise networks, with AI-style obfuscation, USB spread and hidden WMI persistence.