SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers

Infosec stories

Flux result 60894680 31c6 4f6d abcb c183535ef82d

Barracuda spots 7 million device code phishing attacks

Today
#
mfa
#
cloud security
#
phishing
Barracuda links surge in device code phishing attacks to EvilTokens kit as criminals exploit Microsoft 365 logins and bypass multifactor checks.
Jerome

VPN vulnerabilities don't have to become breaches

Today
#
firewalls
#
vpns
#
ransomware
Unpatched VPN gateways are leaving organisations open to ransomware and outages, as modern Zero Trust access cuts off the exposed front door.
Flux result fca4a0e6 784b 40b9 b3fe f49b2f8f1ebf

CrowdStrike launches AI security coalition with partners

Today
#
cloud security
#
application security
#
devsecops
CrowdStrike unveils AI security coalition with Accenture, EY, IBM Cybersecurity Services, Kroll and OpenAI to spot and fix code flaws faster.
Flux result f5d018a7 4220 4dc5 8456 e0cf4c8f98ca

DTEX warns Telegram & WhatsApp AI agents risk exfiltration

Today
#
virtualisation
#
physical security
#
dlp
DTEX warns that AI agents controlled via Telegram and WhatsApp can quietly access files, expose credentials and exfiltrate data from endpoints.
660

Coro promotes Benjamin Morrell to security strategy role

Today
#
firewalls
#
data analytics
#
digital transformation
Coro elevates Benjamin Morrell to Vice President of Security Strategy as it ties product design more closely to internal operations and AI-led protection.
Flux result 5328c3ec 5dc0 4730 a648 7e6dd6dfe965

Apricorn launches 32TB offline encrypted desktop drive

Yesterday
#
storage
#
data protection
#
dr
Apricorn broadens its Aegis Padlock DT FIPS line with a 32TB hardware-encrypted desktop drive for offline backups and sensitive data.
Flux result eb8495d1 df1f 429c ba7a 7f3428bce440

Thrive launches Abacode compliance services after deal

Yesterday
#
data protection
#
dr
#
socs
Thrive widens post-Abacode push with managed compliance service for firms facing tougher rules and cyber risk.
Flux result f8c260c6 c417 4abd 8bb0 37e6377be18a

Anthropic & OpenAI split on cyber AI release strategy

Yesterday
#
devops
#
hyperscale
#
cloud security
Anthropic and OpenAI take rival paths on AI cyber tools, as one keeps access tightly restricted while the other widens vetted user access.
Email attachment20260423 2733349 yqpri8

Everywhen issues six checks to spot unsafe websites

Yesterday
#
malware
#
endpoint protection
#
phishing
Everywhen warns businesses and consumers to check web addresses, padlocks and browser alerts as fake sites fuel rising cyber fraud risk.
Flux result c47fc794 21dd 4fb9 9c40 8c1333595464

Lineaje survey finds AI code confidence outpaces visibility

Yesterday
#
digital transformation
#
application security
#
devsecops
Lineaje survey flags a widening governance gap as most firms use AI-generated code, yet few can fully see or track it.
Flux result 18a4dde7 e4cb 4d02 9c37 a89119ec2b8b

One-third of FIFA World Cup partners lack email protection

Yesterday
#
gaming
#
data protection
#
mfa
Proofpoint warns that 36% of FIFA World Cup 2026 commercial partners still lack the strongest DMARC settings, leaving fans exposed to spoofed emails.
Flux result b0e7cc49 91ef 4484 ba46 cdb3c997b1bf

Claude Code can leak secrets in public npm packages

Yesterday
#
data protection
#
application security
#
devsecops
Check Point says Anthropic's Claude Code can quietly stash credentials in .claude/settings.local.json, which may be published in public npm packages.
Check point

Check Point teams with Google Cloud on AI agent security

Yesterday
#
firewalls
#
data protection
#
digital transformation
Check Point and Google Cloud add governance and live monitoring to enterprise AI agents as firms race to secure autonomous workflows.
Flux result dd4e24eb d611 436e 8eee 5f94a368885c

LevelBlue warns of GhostOps risk from rogue AI agents

Yesterday
#
data protection
#
digital transformation
#
cloud security
LevelBlue says unsanctioned AI agents are slipping into enterprise systems, creating a hidden governance and security blind spot for businesses.
Flux result 301972a1 9b2e 48b8 a9aa 9e092af5bfea

Rubrik launches Google Cloud tools for AI governance

Yesterday
#
storage
#
data protection
#
dr
Rubrik adds Google Cloud controls for AI agents and Cloud SQL backups as enterprises race to govern autonomous systems and protect data.
Flux result d3a1a349 04e0 45e3 a295 960dbbd7d347

Check Point tops Miercom hybrid mesh security benchmark

Yesterday
#
firewalls
#
ransomware
#
hybrid cloud
Check Point claims fourth straight win in Miercom hybrid mesh security test, scoring 99.8% and beating rivals on phishing and malware blocking.
Flux result 98c90454 e22b 40d3 87b0 b943c20a210c

Zscaler joins Anthropic Project Glasswing on cyber AI

2 days ago
#
firewalls
#
vpns
#
network security
Zscaler joins Anthropic's Project Glasswing to test Claude Mythos Preview in software scans, as the firm pushes zero trust against AI-driven attacks.
Flux result ba26dffd 2c48 4e83 87b5 365314843884

ServiceNow completes USD $7.75 billion Armis acquisition

2 days ago
#
firewalls
#
digital transformation
#
cloud security
ServiceNow bolsters cyber security push with Armis buyout, adding real-time asset visibility and deepening its platform after Veza.
Flux result ad42d32c 7135 4932 a4cb b35aca0c1391

HackerOne launches h1 Validation to tackle AI flaws

2 days ago
#
devops
#
digital transformation
#
application security
HackerOne unveils h1 Validation as vulnerability reports surge 76% and AI tools speed up discovery, leaving firms struggling to triage real threats.
Flux result ebf65211 8555 4f44 8fa9 1d2df642919d

CIS launches AI security guides for models & agents

2 days ago
#
digital transformation
#
application security
#
physical security
CIS, Astrix and Cequence publish AI security guides for large language models, autonomous agents and MCP environments.