Threat actors stories
Existing phishing and fraud tactics are becoming faster, cheaper and harder to detect, raising the risk for large organisations, ReliaQuest said.
Boards face growing pressure to treat AI-driven cyber threats as an immediate business risk, with attackers able to exploit flaws within months.
Trusted third-party access has let attackers quietly pull large volumes of Salesforce records from enterprise systems via a Klue integration.
Public release of the Mini Shai-Hulud code means copycat attacks can now hit developers, CI/CD systems and open-source supply chains.
A single phishing email can now compromise identities, bypass multifactor authentication and hit endpoints within five minutes, Barracuda said.
Thousands of corporate devices may be exposed because many remain unpatched, unseen or missing endpoint protection, Arctic Wolf found.
Cybersecurity teams fear the release could speed up vulnerability hunting on both sides, forcing faster patching and tighter controls.
Older, internet-facing IIS servers are being singled out by China-linked hackers, with one new cluster able to persist despite partial containment.
Access to AI research and software is drawing state-backed and criminal attacks, with technology firms now the world's most targeted sector.
Nearly 100 organisations were hit in a six-week phishing spree that used GitHub repositories and Visual Studio Code tools to infect developers.
CrowdStrike said state-backed espionage and extortion are surging as AI assets inside tech groups draw hackers seeking code, models and access.
The partnership could speed up flaw detection and patching for critical software used by businesses and public sector organisations across the region.
Banks and investment firms face mounting exposure as ransomware incidents jump and more than half of vendors carry high-severity flaws.
Many firms are exposing sensitive data as shadow AI and weak controls leave them open to breaches, hallucinations and unauthorised access.
Security teams can now check exposed credentials against Okta as Flare folds threat intelligence, investigation and identity risk tools into one platform.
Canadians could soon gain stronger control over federal records as Ottawa weighs binding powers for the Privacy Commissioner and rules for AI decisions.
The extension gives Rugby Australia two more years of protection against cyber threats as sporting bodies face rising risks to data and match-day systems.
Exploited software flaws are now overtaking stolen passwords as the main breach route, sharpening pressure on security teams to patch faster.
Australian businesses face renewed ransomware pressure as INC expands quickly after LockBit and BlackCat were disrupted, researchers say.
Sydney will coordinate wider APJ growth as demand rises for earlier warning on cyber threats hitting critical infrastructure and finance.