Latitude Financial Forecast $100 million Loss from Data Breach

Latitude Financial released an ASX announcement forecasting it’s first half of 2023 Statutory losses to be around $100 million. This is mainly attributed to the cyber-attack and data breach it suffered in mid March which affected 14 million records containing...

Mandatory 2FA Coming to PyPI

The Python Package Index has announced that all accounts that manages at least one project will need to have two-factor authentication enabled by the end of the year. The Python Package Index is a software repository for packages created in the python programming...

Surge in Business Email Compromise

Microsoft has released the fourth edition of their threat intelligence report titled Cyber Signals. The report highlights a surge in cybercriminal activity around business email compromise. Microsoft has observed a 38% increase in cybercrime as a service (CaaC)...
Speaker at AppSec Australia Meetup

Speaker at AppSec Australia Meetup

Had a great evening speaking about Securing Software Supply Chain this evening at the AppSec Australia 🇦🇺 Meetup. The audience were very engaged with lots of great questions and follow up conversations over pizzas. The event was organised by Scott Contini and Jack...

Apple Bans Employees from using ChatGPT

 While companies are embracing AI technology and using ChatGPT, others have chosen to avoid them. Apple is one of those companies. They have restricted their employees from using ChatGPT and other artificial intelligence utilities. They have also barred their staff...

Telstra Launches Initiative to Snitch Scammers

7226(SCAM), that’s the number Telstra customers can now forward scam SMS and MMS messages. Doing that helps prevent the same scam from potentially affecting others. And in case you’re wondering, messages forwarded do not automatically turn into block. This...

Password Manager Vulnerable to Master Password Compromise

A new KeePass vulnerability has recently been disclosed which makes it possible to recover the master password even when the program is closed. The vulnerability is CVE-2023-3278 and a simple proof of concept tool has been released that can be used to dump the master...

PyPI Struggling with High Volume of Malware

The Python Package Index, also known as PyPI, is struggling to deal with the high volume of malicious users and packages. As a result, the administrators of the index temporarily suspended new user registrations and project creations. The incident notice stated that...

Apple Releases Fixes for Three Zero Days

Apple has just released software updates for its Macs, iPhones, iPads, Apple Watch, Apple TV and Safari browsers. The updates for the iPhone, Macs and iPads contains fixes for three zero day vulnerabilities. These vulnerabilities allow for code execution and also for...

New Phishing Attacks Using New .zip Top Level Domain

Cybersecurity experts are raising concerns over Google’s new .ZIP and .MOV internet domains. The .ZIP domains are already been seen to be used in phishing attacks. Google release those top-level domains recently, which means that anyone can register .zip or .mov...