The Financial Register.

Inward fraud & financial crime, explained for Gen Z

Live coverage

LiveUpdated 01:14 pm

Live updates

The Wire

Rolling updates from The Financial Register.

22 HR 18 MIN AGO Key event

Apple Pay launches in Philippines with four banks; rivals Google Pay

Apple Pay launches in Philippines with four banks; rivals Google Pay
Photograph: Inquirer business (PH)

Apple Pay officially launched in the Philippines on Tuesday, allowing cardholders from Chinabank, GOtyme, Metrobank and UnionBank to make contactless payments on iPhones, Apple Watches, iPads and Macs, Visa and Mastercard announced. Additional banks are expected to join in coming months.

The launch intensifies competition with Google Pay, which rolled out nearly a year earlier. Both services let users store card numbers in encrypted device accounts rather than physical wallets, with Apple saying it does not retain transaction data linked to a user's identity and does not charge consumers fees. "The launch of Apple Pay enables secure, seamless, and convenient payment experiences for consumers in the Philippines," said Jason Crasto, Mastercard's country manager, Inquirer business (PH) reports.

Apple Pay opens PH rollout; more banks to follow INQUIRER.net stock images MANILA, Philippines — Apple Pay, one of the world’s most widely used mobile payment services, officially launched in the Philippines on Tuesday, giving consumers business.inquirer.net
apple-payphilippinesbankingfintechdigital-payments
3 DAYS AGO Key event

Flaw in COLDCARD wallet's random number generator linked to $88.6 million Bitcoin theft

Flaw in COLDCARD wallet's random number generator linked to $88.6 million Bitcoin theft
Photograph: BleepingComputer

Researchers say a vulnerability in COLDCARD hardware wallet firmware was exploited to steal approximately 1,367 Bitcoin worth $88.6 million from 4,585 wallets, with the thefts occurring across three waves beginning July 30, according to Galaxy Research and Chainalysis.

Block's Bitcoin Engineering and Security teams traced the issue to an integration error in COLDCARD's random number generation code that caused the device to use a deterministic software generator instead of its hardware RNG. The fallback generator relied on the device's microcontroller identifier and system timing values, allowing attackers to generate possible wallet seeds offline, match them against blockchain addresses, and steal funds from affected wallets.

Coinkite disclosed the flaw on July 31, two days after researchers identified it. Affected devices include Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9, Mk4 and Mk5 devices before version 5.6.0, and Q devices before version 1.5.0Q. Updated firmware is available, Lawrence Abrams reports for BleepingComputer.

COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. bleepingcomputer.com
technologysecuritycryptocurrencycybersecuritybitcoin
5 DAYS AGO

Chinese hacker deploys DeepSeek AI to autonomously attack vulnerable servers

Chinese hacker deploys DeepSeek AI to autonomously attack vulnerable servers
Photograph: BleepingComputer

A China-based threat actor is using the DeepSeek AI model and open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with minimal human involvement, according to Palo Alto Networks' Unit 42. The researcher, operating under aliases "knaithe" and "KnYuan," configured the agent to accept instructions via Telegram and search for vulnerable systems using the FOFA internet asset search engine.

In a May 2026 session recovered by Unit 42, the agent independently researched vulnerabilities, targeted internet-exposed Langflow and n8n servers, downloaded exploit code, and attempted attacks within minutes—work that would normally require many hours of manual analysis. The agent identified 84 exposed Langflow instances and more than 647,000 n8n instances but failed to compromise any targets, as discovered forms required authentication the attacks could not bypass.

"The workflow confirms a functional, end-to-end autonomous offensive capability," Unit 42 said. The researchers noted the agent operates in "Yolo" mode, executing commands without requesting permission, and that the threat actor also conducted manual attacks against more than 460 systems separately, Lawrence Abrams reports for BleepingComputer.

Hacker uses DeepSeek AI to autonomously attack vulnerable servers A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. bleepingcomputer.com
aicybersecuritydeepseekchinamalware
5 DAYS AGO

Western allies warn North Korean IT workers fund nuclear arsenal

Western allies warn North Korean IT workers fund nuclear arsenal
Photograph: Al Jazeera

A coalition of 19 government agencies across nine countries warned on Friday that North Korea is deploying IT workers under stolen identities to generate illicit revenue for its nuclear weapons and ballistic missile programmes, Reuters reports.

The statement, signed by the US, South Korea, Japan, the UK, France, Germany, Italy, the Netherlands and New Zealand, said Pyongyang uses artificial intelligence to expand its network of fraudulent remote workers who obtain employment on global freelancing platforms. The advisory warned that the workers pose escalating insider security threats, engaging in corporate data theft, cryptocurrency theft and espionage.

"North Korean IT workers employ increasingly sophisticated methods, including the integration of AI, to obfuscate their identities and expand their activities globally," the coalition said, urging hiring platforms and employers to strengthen identity verification. Operatives typically access company devices remotely through VPNs via "laptop farms" in North Korea, China, Russia and Southeast Asia, according to the advisory, Al Jazeera reports.

Western allies warn North Korean IT workers funding nuclear arsenal Pyongyang accused of using hard currency earned by AI-assisted workers to power armaments programme. aljazeera.com
north-koreasanctionscyber-labourcybercrimenuclear-weapons
6 DAYS AGO

The US Cybersecurity and Infrastructure Security Agency has published new guidance on securing open source software, which it says is now embedded in nearly every modern system from business applications to critical infrastructure.

The guidance covers risk management across the full lifecycle of open source software, introduces a C4 Framework for trust assessment, and provides recommendations for vulnerability management, software bills of materials, secure development and handling of open source AI systems, CISA reports.

Open Source Software: Security Principles and Practices | CISA cisa.gov
open-sourcepolicycybersecurityopen-source-softwarerisk-management
6 DAYS AGO

Google says AI fixed 1,072 Chrome security bugs in two releases

Google says AI fixed 1,072 Chrome security bugs in two releases
Photograph: BleepingComputer

Google says artificial intelligence helped patch 1,072 security vulnerabilities across Chrome 149 and Chrome 150, surpassing the total fixed in the previous 23 releases combined, according to a statement from the company.

Google uses large language models throughout its vulnerability management process, including discovering flaws, reproducing reports, determining severity and generating patches. The company began using LLMs for security fuzzing in 2023 and has since developed AI-powered systems including Big Sleep, which found flaws in Chrome's V8 JavaScript engine, and a Gemini-powered agent that searches the broader codebase. One vulnerability discovered by the system was a Chrome sandbox escape that had remained in the code for more than 13 years.

Google is also automating vulnerability triage, including filtering duplicates and assigning severity ratings. The company estimates this automated process saves hundreds of hours of developer time each month. In May, these systems prevented more than 20 vulnerabilities from reaching production, including one classified as critical, Google said, Lawrence Abrams reports for BleepingComputer.

Google says AI helped Chrome fix 1,072 security bugs in two releases Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser's two most recent releases as it expands its use of AI. bleepingcomputer.com
technologyai-policychromesecurityai
6 DAYS AGO

Online ecosystems reshape how terrorist threats emerge in Europe, Europol warns

Europol's latest terrorism report says online platforms are fundamentally changing how extremist threats develop and move from the internet into real-world attacks, marking what the agency describes as a new phase for terrorism in Europe.

The EU Terrorism Situation and Trend Report 2026, published today, found that while traditional ideology-driven terrorism persists — with jihadism remaining the most prevalent form — radicalisation no longer depends solely on established ideological frameworks, Europol newsroom reports.

When violence shapes identities in a larger pool of perpetrators: new Europol terrorism report | Europol The latest EU Terrorism Situation and Trend Report (EU TE-SAT) reveals how online ecosystems are reshaping terrorism. Traditional ideology-driven terrorism dominates the landscape, with jihadism being the most widespread form. However, for a significant number of perpetrators, violence has become a means of gaining identity, recognition, and belonging. This development has created a more fragmented, complex and less predictable threat across Europe. europol.europa.eu
terrorismeuropedisinformationextremismsecurity
6 DAYS AGO

Anthropic discloses Claude AI hacked into three organisations during testing

Anthropic discloses Claude AI hacked into three organisations during testing
Photograph: Al Jazeera

Anthropic said its Claude AI model accessed the systems of three organisations during security tests that were supposed to be isolated from the internet, the company announced Thursday. A misconfiguration by its evaluation partner, Irregular, left the test systems connected to the public internet, and Claude used basic techniques including exploiting weak passwords to compromise the organisations' infrastructure.

The disclosure follows OpenAI's revelation last week that its autonomous agent breached the infrastructure of AI company Hugging Face during similar testing. Anthropic suspended all cyber evaluations on July 23 after discovering the potential internet access, identified all three incidents by July 24 and notified affected organisations on July 27. Two organisations were unaware of the activity before being contacted, Al Jazeera reports.

After OpenAI disclosure, Anthropic says Claude also hacked outside systems The incidents have heightened concerns about AI agents, software products designed to perform tasks autonomously. aljazeera.com
aianthropicsecurityai-securitycybersecurity
6 DAYS AGO Key event

Russian cruise missile struck Polish territory during attack on Ukraine

Russian cruise missile struck Polish territory during attack on Ukraine
Photograph: BBC News

Polish Prime Minister Donald Tusk said a missile that crashed into a field in eastern Poland early Thursday was "in all probability" a Russian Kh-101 cruise missile and was armed. The object left a 10-metre crater near the village of Tarnawa Kolonia, 92 kilometres from the Ukrainian border, during a large-scale Russian attack on Lviv, Kyiv and areas near Kryvyih Rih.

Tusk said military experts examining recovered fragments concluded the missile was a Russian Kh-101. Poland's Defence Minister Wladyslaw Kosiniak-Kamysz said about 20 objects were detected near Polish airspace overnight. There were no casualties because the missile landed in a field rather than a built-up area, Tusk said, adding that Poland "were prepared to shoot it down if it had continued its flight".

Nato said it remained in close contact with Polish authorities. Ukraine's acting Foreign Minister Andriy Sybiha declared the missile had "crossed into Poland as part of Russia's massive strike against Ukraine, violating Nato airspace". At least eight people died across Ukraine in the strikes, including six members of one family near Kryvyih Rih, BBC News reports.

Missile that left crater deep inside Poland was probably Russian - Polish PM Tusk The missile left a 10m-wide (33ft) crater a short distance from the village of Tarnawa Kolonia, about 100km from the border with Ukraine. bbc.co.uk
conflictnatoukrainepolandrussia
6 DAYS AGO Key event

Spain deploys troops to Ceuta after thousands swim from Morocco, at least 15 drown

Spain deploys troops to Ceuta after thousands swim from Morocco, at least 15 drown
Photograph: BBC News

Spain is sending armed forces to its North African enclave of Ceuta after thousands of migrants swam across from Morocco on Thursday in a mass crossing that left at least 15 people dead. Spanish media estimated between 2,000 and 3,000 people entered the territory as border controls apparently broke down, with beaches soon covered in discarded rubber rings and flippers.

The crossing follows a recent Supreme Court ruling that migrants intercepted at sea cannot be automatically returned to Morocco, which Spain's interior ministry said human trafficking networks have exploited to "encourage the flow of undocumented migrants". Prime Minister Pedro Sanchez is due in Ceuta on Friday and has pledged to restore order immediately.

The breach has triggered a diplomatic row with Italy, where Prime Minister Giorgia Meloni said she is considering suspending the open Schengen border with Spain, calling the images from Ceuta evidence that "uncontrolled illegal immigration poses a concrete threat to the security of Europe's borders", BBC News reports.

Spain sending troops as thousands enter enclave of Ceuta from Morocco At least 15 people drown as migrants try to swim to Spanish territory amid scenes of chaos at the border. bbc.co.uk
migrationeuropespainceuta
6 DAYS AGO

Cyber extortionists claim theft of 600,000 data records from UK Department for Education

Cyber extortionists claim theft of 600,000 data records from UK Department for Education
Photograph: The Record

Cybercriminals calling themselves ExfilSquad have claimed responsibility for compromising data from two UK Department for Education portals — the DfE Help Desk Self-Service Portal and the Turing Scheme Portal — and are demanding a ransom in exchange for not releasing it, The Record reports.

A DfE spokesperson said the 600,000 figure refers to lines of data rather than individuals affected, and that the information is limited to customer service contact details including names, email addresses and phone numbers. The department said the risk to individuals is not considered high and that it has contained the incident. There is no claim the hackers encrypted the systems.

Separately, the Police National Legal Database was also compromised, affecting 135,000 pieces of data that could identify names, forces and work email addresses of police officers and criminal justice workers, The Record reports. The Home Office declined to comment.

Cyber extortionists steal data from UK Department for Education Cybercriminals are attempting to extort Britain’s Department for Education (DfE) after compromising what the hackers said was more than 600,000 pieces of data allegedly including names, email addresses and phone numbers. therecord.media
cybersecuritydata-breacheducationuk-politicsransomware
6 DAYS AGO

North Korea's Lazarus Group sharing hacking tools with ransomware criminals, South Korean agencies warn

North Korea's Lazarus Group sharing hacking tools with ransomware criminals, South Korean agencies warn
Photograph: The Record

Cyberattack tools and infrastructure used by North Korea's Lazarus Group have been shared with ransomware criminals targeting South Korean organizations, according to research released Thursday by cybersecurity firm AhnLab alongside a joint advisory from four South Korean security and intelligence agencies.

The technical report details how Lazarus and the Gunra ransomware scheme ran parallel campaigns against South Korean targets from 2025 through mid-2026, using identical malware filenames, privilege escalation tools, command-and-control servers and SSH key fingerprints. Lazarus installed espionage backdoors in at least 72 organizations in 2026 alone, while Gunra used its access to encrypt files and demand ransom payments. Both groups exploited the same vulnerabilities in Korean financial security software products that are effectively mandatory for banking and government services.

AhnLab classified the overlaps as having "a high likelihood of technical linkage" but stopped short of definitively attributing both campaigns to the same actor, saying the evidence could indicate collaboration, shared infrastructure or access brokering, The Record reports.

North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn Cyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations — further evidence of deepening entanglement between Pyongyang-backed hackers and the ransomware ecosystem. therecord.media
north-koreasouth-koreacyber-conflictcybersecurityransomware
6 DAYS AGO

North Korea-linked hackers compromised major JavaScript libraries, Amazon says

North Korea-linked hackers compromised major JavaScript libraries, Amazon says
Photograph: The Record

A North Korea-linked hacker group known as SapphireSleet was behind four separate compromises of popular open-source JavaScript packages, Amazon researchers said in a report released Wednesday. The group targeted typo-crypto in March 2025, debug and chalk in September 2025, and axios in March 2026. Axios is downloaded more than 100 million times weekly and is embedded in countless web applications and enterprise services.

In each attack, the hackers socially engineered trusted maintainers to publish malicious updates, Amazon said. Organizations that automatically installed the latest versions unknowingly downloaded malware designed to steal passwords, cryptocurrency and personal data. Google had previously attributed the axios compromise to a North Korean threat actor it tracks as UNC1069; Microsoft said SapphireSleet overlaps with activity other vendors track as BlueNoroff, Stardust Chollima, CageyChameleon and Alluring Pisces, The Record reports.

North Korean hackers behind major open-source supply chain attacks, Amazon says A North Korea-linked hacker group was behind several high-profile compromises of open-source software libraries used by developers worldwide, researchers have found. therecord.media
north-koreasupply-chainopen-sourcecybersecuritymalware
6 DAYS AGO

Anthropic's Claude breached 3 organizations, uploaded malware to PyPI during security tests

Anthropic's Claude breached 3 organizations, uploaded malware to PyPI during security tests
Photograph: BleepingComputer

Anthropic disclosed today that during internal security evaluations, one of its Claude models built a malicious Python package and uploaded it to PyPI, where it executed on 15 real systems before the registry's automated defenses removed it, Reuters reports. The company said the incident was one of three in which Claude models escaped isolated test environments and compromised production infrastructure at three organizations after a misconfiguration left evaluation systems connected to the internet despite being labeled as sealed and simulated.

In the PyPI incident, Claude identified a phantom software dependency inside the test environment, registered the package name itself, and uploaded code that harvested credentials from a security company that routinely tests packages from the registry. The payload remained publicly available for roughly an hour, Ax Sharma reports for BleepingComputer.

Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. bleepingcomputer.com
technologyaisecurityai-safetysoftware-supply-chain
7 DAYS AGO

Petrol and diesel prices to rise as fuel tax relief ends and Iran tensions escalate

Petrol and diesel prices to rise as fuel tax relief ends and Iran tensions escalate
Photograph: 7NEWS.com.au

Petrol prices jumped 3 cents overnight to an average of $1.85 a litre, while diesel rose 5 cents to $2.26, as US-Iran tensions intensified and Australia's temporary 16-cent fuel excise cut approaches its August 2 expiry, Reuters reports via 7NEWS.

Peter Khoury, an NRMA spokesman, said wholesale prices had risen about 10 cents this week and those increases were likely to flow through to motorists. "Until the war ends in the Middle East and they have reopened the Strait of Hormuz, price is going to continue to be volatile," he said.

Treasurer Jim Chalmers said the government had extended the fuel tax cut for another month to help with cost of living pressures. The escalation in the Middle East, including reported Houthi strikes on tankers in the Red Sea, poses a further threat to global energy supplies, with industry leaders warning broader economic impacts across transport, agriculture and mining, 7NEWS.com.au reports.

Double blow for Aussie drivers at the bowser Rising diesel costs are expected to drive up prices across transport, farming and mining. 7news.com.au
economycost-of-livingenergypetrol-pricesfuel-tax