Infosec stories
Phishing emails can still slip into Microsoft 365 mailboxes when attackers leave the SMTP envelope sender blank, ReliaQuest has found.
Businesses risk being misled into revealing information unless phone systems can verify caller identity across increasingly complex cloud-linked networks.
Criminal access to thousands of Microsoft accounts was cut off after the companies shared threat data through the Global Signal Exchange.
Australian firms could face faster breaches as model-driven attackers shrink exploit times to hours, making containment and zero trust vital.
By probing its own production code, Tanium is aiming to catch flaws before attackers can exploit software used by thousands of organisations.
The stealer's use of typosquatted npm packages has raised fears that bug bounty channels are being abused to monetise stolen developer data.
Downstream AI alerts in Australia and New Zealand are rising as agents and MCP links create fresh routes for sensitive data leakage.
The sector faces mounting breach and compliance risk as unmanaged devices, shared logins and stale access undermine campus defences.
A second straight top ranking underlines growing demand for firewall tools that span cloud and on-premise systems without separate stacks.
User behaviour remains IT's biggest vulnerability, with 65% of professionals saying password sharing is the worst security lapse.
Companies selling software into the bloc now have 24 hours to flag exploited flaws, with fines reaching EUR €15 million for delays.
Growing alert volumes are pushing Indian security teams to use AI for faster, context-led decisions instead of more monitoring.
Investigators will get a fuller audit trail as the software links Microsoft 365 activity and AI prompts with emails, files and logs.
Trust from Asia Pacific security practitioners was reinforced as SonicWall won two CybersecAsia awards and joined the Hall of Fame.
The ranking bolsters its pitch that enterprises need centralised controls as AI adoption widens attack surfaces across cloud and on-premise networks.
Businesses have almost no time to patch flaws now, as ESET says the median gap between disclosure and exploitation fell to zero days in 2026.
The hire deepens Thrive's push into cybersecurity as customers seek outside help with threat detection, response and risk management.
Funding will help expand quantum-safe cybersecurity deployments as India races to build domestic defences against future quantum threats.
Australian firms could get a clearer view of AI-driven attack paths as ThreatCanary rolls out a platform blending asset discovery, API checks and offensive testing.
APIs are now a major attack surface, making shared context between developers and SecOps vital to spot real threats and avoid false alarms.