> TODAY'S SUMMARY (1 articles)
Today's cybersecurity news highlights several key trends and threats impacting Australian organizations. The September 2026 review from Australian Cyber Aware emphasizes increasing incidents of data breaches, particularly involving personal data and critical infrastructure. There is a notable rise in AI-driven attacks, exploiting vulnerabilities in automated systems. Fraud schemes are becoming more sophisticated, often targeting financial institutions and individuals alike. Additionally, compliance with evolving privacy regulations remains a challenge for many organizations, necessitating enhanced governance frameworks. Overall, the landscape is characterized by heightened risk and the need for robust cybersecurity measures.
|
// AI-powered summary generated at 08:00
Jaguar Land Rover has reported a 25% drop in volume sales in the three months up to September 30, largely due to the impact of the ongoing cyber incident
Never rely on just a password, however strong it may be. Multi-factor authentication is essential for anyone who wants to protect their online accounts from intruders.
As the go-to cybersecurity expert for your friends and family, you’ll want to be ready for those “I clicked a suspicious link — now what?” messages. Share this quick guide to help them know exactly what to do next.
Unit 42 discovers ClickFix phishing kits, commoditizing social engineering. This kit presents a lowered barrier for inexperienced cybercriminals.
The post The ClickFix Factory: First Exposure of IUAM ClickFix Generator appeared first on Unit 42.
North Korean hackers have stolen over $2bn in cryptocurrency already this year, says Elliptic
Join Cellebrite’s 30-minute Autumn 2025 Release webinar to explore the latest digital forensics innovations, new tools, and expert insights — register now to save your spot!
Two 17-year-olds have been arrested following a cyber-attack on the Kido nursery group
Corrected Article links in the Security Updates table. This is an informational change only.
How organisations can improve their ability to both detect and discover cyber threats.
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Allegra. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2025-11466.
This vulnerability allows remote attackers to bypass authentication on Wondershare Repairit. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.4. The following CVEs are assigned: CVE-2025-10644.
You’ve trained the model, packaged it on Red Hat OpenShift AI, and it’s ready to work. The next move is exposing it through an API so people and applications can use it. At that moment, your model stops being an internal experiment and becomes a front-door service. And like any front door, somebody...
This vulnerability allows remote attackers to bypass authentication on affected installations of Wondershare Repairit. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.1. The following CVEs are assigned: CVE-2025-10643.
Pro-Partner a reçu un e-mail de ransomware anonyme, l'entreprise a signalé l'incident à la police et a activé ses mécanismes de sécurité pour renforcer ses protections. L'enquête est en cours et les principaux systèmes n'ont pas été compromis. Pro-Partner va coopérer avec la police pour élucider l'i...
Madeira USA LLC suffered a security incident involving unauthorized access to certain servers within its network, resulting in potential exposure of personal information. The incident occurred on October 8, 2025, and was discovered on the same day. Madeira has taken steps to enhance its security mea...
Cloud breaches are rising. This step-by-step guide from Unit 42 shows how to investigate, contain and recover from cloud-based attacks.
The post Responding to Cloud Incidents: A Step-by-Step Guide From the 2025 Unit 42 Global Incident Response Report appeared first on Unit 42.
A cybercriminal group that used voice phishing attacks to siphon more than a billion records from Salesforce customers earlier this year has launched a website that threatens to publish data stolen from dozens of Fortune 500 firms if they refuse to pay a ransom. The group also claimed responsibility...
Privacy laws are only as strong as their enforcement. In California, the state’s privacy agency recently issued its largest-ever fine for violation of the state’s privacy law—and all because of a consumer complaint.
The state’s  privacy law, the California Consumer Privacy Act or CCPA, requires many...
The California Privacy Protection Agency (CPPA) issued a record fine earlier this month to Tractor Supply, the country’s self-proclaimed largest “rural lifestyle” retailer, for apparently ducking its responsibilities under the California Consumer Privacy Act. Under that law, companies are required t...
Microsoft Copilot, not so much Employees could be opening up to OpenAI in ways that put sensitive data at risk. According to a study by security biz LayerX, a large number of corporate users paste Personally Identifiable Information (PII) or Payment Card Industry (PCI) numbers right into ChatGPT, ev...