LastPass suffers second data breach this year

LastPass revealed that attackers had stolen customer vault data. Fortunately the stolen vaults had been encrypted using the customer’s master key, which is never known to LastPass. However the attackers might attempt to brute force the passwords to gain access...

Behind the scenes of Optus response’s to their data breach

The Australian Financial Review wrote an article providing a behind the scenes look at how the Optus data breach unfolded for the company and their CEO. This was the first of a number of major data breaches which eventually lead to changes to the Australian Privacy...

End-to-end Encryption Coming to Gmail

Google recently announced that it will be adding end-to-end encryption to Gmail on the web for its workspace users. Once enabled, it will ensure that any sensitive data delivered as part of the email’s body and attachments cannot be decrypted by Google. Users...

Malicious Cybersecurity SDK released to Developers

Threat actors have released a trojanised python package pretending to be the legitimate SDK for the trusted cybersecurity firm SentinelOne. The malware offers the expected functionality, allowing easy access to the SentinelOne API. However it has been trojanised to...

Facebook Post Phishing Attack on the Rise

A new phishing campaign is utilising facebook posts in its attack chain. This approach is used to trick victims into giving away their account credentials and personally identifiable information or PII. The post claims to be from facebook’s “Page...