Strengthening Superannuation Security: Why Phishing-Resistant Authentication Can No Longer Wait
We recently reviewed an article from SecurityBrief covering the 2025 superannuation cyber incidents, along with updates relating to APRA’s CPS 230 operational risk standard. We believe this is an important topic for our audience, particularly as it highlights how credential theft continues to put Australians’ retirement savings at risk. With cyber threats evolving and regulatory […]
Android Malware “PromptSpy” Uses Generative AI to Stay Hidden on Devices
We recently reviewed new research from ESET, which has identified an Android malware family dubbed PromptSpy. According to ESET researcher Lukáš Štefanko, this appears to be the first observed Android malware sample using generative AI to maintain persistence on infected devices. The discovery is notable not because AI is controlling the entire attack, but because […]
Healthcare Leads OT Targeting in Australia
We recently reviewed new research from Nozomi Networks Labs examining operational technology (OT) and internet-connected environments across 2025. The findings are particularly relevant for Australian organisations operating critical systems — especially in healthcare and manufacturing. According to the report, healthcare services was the most targeted industry in Australia for OT and connected environments in 2025, […]
Okta SSO Vishing Campaign Linked to ShinyHunters: What Organisations Should Understand
We recently came across reporting from SecurityWeek about a large-scale cybercrime campaign linked to the ShinyHunters group. Given the number of well-known organisations mentioned and the techniques involved, we believe this is an important development to share — particularly for businesses relying on single sign-on (SSO) and multi-factor authentication (MFA) platforms. According to security firm […]
Hundreds of Chrome Extensions Found Leaking Data — Why This Matters for Your Organisation
We recently came across an article published by SecurityWeek discussing new research into malicious Chrome extensions. It immediately caught our attention — not because browser extensions are new, but because of the scale involved. More than 300 Chrome extensions were found leaking browser data, spying on users, or outright stealing sensitive information. Given how widely […]
Part 2: Securing ICS for the Future — From Resilience to Continuous Validation
If replacing aging industrial systems is unrealistic in the short term, how should organisations respond? The answer emerging across experts is clear: resilience must become operational, continuous, and identity-driven. Trevor Dearing of Illumio suggests going beyond resilience toward “anti-fragility” — systems that improve after stress rather than merely surviving it. Identity as the Core Control […]
Part 1: Industrial Control Systems in 2026 — Built for Reliability, Targeted for Disruption
Industrial Control Systems (ICS) power the infrastructure we depend on every day — electricity, water, transport, manufacturing, and increasingly, smart cities. Many of these systems were engineered for safety and uptime long before cybersecurity became a primary design consideration. They were built to operate reliably for decades. And they have. The challenge is that today’s […]
Cyber Attacks Are Getting Quieter — And Harder to Detect
When many people think about cybercrime, they picture ransomware headlines: locked systems, ransom demands, and public disruption. But the latest Red Report from Picus Security shows a different and more subtle reality. In 2025, 80% of the most commonly observed attack techniques were designed to remain hidden after initial access. Instead of loudly encrypting data, […]
Cyber Safe Business Advisory Bulletin -Origin Energy Confirms Customer Data Breach – What Businesses
Date: 23 July 2026 Prepared by: Cyber Safe Business (CSB) Cyber Security Alert Origin Energy has confirmed that a cybersecurity incident resulted in the unauthorised access and disclosure of customer data. The company stated it is continuing to investigate the incident and determine the total number of affected customers. According to Origin Energy, information potentially exposed may include: Customer names Residential addresses Dates of […]
Smartphones Are Now Central to Digital Investigations — and the Pressure Is Growing
Smartphones have quietly become one of the most important sources of evidence in modern investigations. According to a new global survey from Cellebrite, mobile devices are now cited in 97% of criminal investigations, making them the single most relied-upon source of digital evidence. That figure represents a sharp rise from 73% in 2024, reflecting how […]