The Financial Register.

Inward fraud & financial crime, explained for Gen Z

Live coverage

LiveUpdated 08:26 am

Live updates

The Wire

Rolling updates from The Financial Register.

Hacking group claims theft of data from nearly 50 companies including Shell, Philips, GE

Hacking group claims theft of data from nearly 50 companies including Shell, Philips, GE
Photograph: Channel NewsAsia business

A prolific hacking group known as Cl0p claimed on Wednesday it had stolen large volumes of data from nearly 50 companies worldwide, including energy giant Shell, medical equipment maker Philips, industrial conglomerate GE and financial services firm Fiserv, according to a posting on the group's website.

Shell said it was aware of a recent "possible incident" and was investigating with security teams. Philips said it had "identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data", adding the breach did not affect customer environments. Fiserv said it had found no evidence that customer, banking, transaction or personal data had been compromised.

Reuters could not independently verify the hacking group's claims about what data was stolen or how much, Channel NewsAsia business reports.

Hacking group claims mass data theft from Shell, Philips, GE, Fiserv and dozens of others AMSTERDAM, Aug 13 : A prolific hacking group known for exploiting software vulnerabilities to attack multiple targets simultaneously claimed it had stolen large volumes of data from nearly 50 companies worldwide, including Philips, Shell, Fiserv and GE, according to a posting on the group's website.Philips sa channelnewsasia.com
cybersecuritydata-breachfiservfraud
State-ownedCNAMediacorp · state-ownedOwned through Temasek, the Singapore sovereign fund.
38 DAYS AGO Key event Share

Trump administration allows private firms to attack cybercrime groups

Trump administration allows private firms to attack cybercrime groups
Photograph: The Record

President Donald Trump signed a presidential memorandum on Wednesday allowing vetted private companies to launch offensive cyber operations against transnational criminal organizations targeting Americans, in partnership with the Justice and Homeland Security departments.

The firms will conduct attacks and surveillance on cybercriminal networks, subject to advance approval from DOJ and DHS officials. No operation will be sanctioned if it risks loss of life or rises to the level of armed attack under international law. Companies must sign contracts, undergo vetting, report regularly to federal agencies and face at least $1 million in penalties for violations.

The White House said Americans reported $20.8 billion in cyber-related losses last year through scams, ransomware and cyberattacks. Federal agencies have two months to develop operating procedures and minimum standards for participating companies, which must demonstrate technical proficiency, facility security and personnel vetting.

Cybersecurity experts questioned the lack of legal protections in the memorandum and raised concerns about potential for foreign governments to target U.S, The Record reports.

Trump taps cyber firms to go on offensive against criminals The Trump administration will allow private companies to launch attacks on cybercrime organizations, the White House announced. therecord.media
cybersecuritycybercrimepolicyfraudtrump-administration
CommercialThe RecordRecorded Future · trade pressPublished by a cybersecurity vendor that sells threat intelligence.

Telstra announces A$1 billion buyback, reports modest profit rise

Telstra announces A$1 billion buyback, reports modest profit rise
Photograph: Channel NewsAsia business

Australia's Telstra Group announced a A$1 billion share buyback on Thursday and reported annual profit of A$2.24 billion for the year ended June 30, up 3.2 per cent from the prior year. The result was slightly below analyst consensus of A$2.30 billion. Revenue in Telstra's mobile segment, which accounts for about 44 per cent of group income, grew 3.2 per cent to A$11.37 billion, driven by higher average revenue per user and mobile service revenue growth from a series of tariff increases implemented over the year.

Telstra declared a final dividend of 10.5 Australian cents per share, up from 9.5 cents last year, and forecast 2027 earnings before interest, taxes, depreciation and amortisation after leases of A$8.5 billion to A$8.8 billion. Chief Executive Vicki Brady said the company would continue investing in network resilience under its Connected Future 30 strategy. The announcement comes as Australia's telecommunications sector faces heightened scrutiny following a July software fault that triggered a nationwide outage affecting phone services, wireless payments and some rail services, Channel NewsAsia business reports.

Telstra dials up shareholder returns with A$1 billion buyback, posts modest profit rise Aug 13 : Australia's Telstra Group unveiled a A$1 billion ($705.9 million) share buyback on Thursday and reported a marginal rise in annual profit, driven by growth in its mobile business and higher customer spending.The telecom firm posted profit attributable of A$2.24 billion for the year ended June 30, up channelnewsasia.com
telstraearningsbuybackaustraliatelecoms
State-ownedCNAMediacorp · state-ownedOwned through Temasek, the Singapore sovereign fund.

More than 500 fake VPN extensions remain on Chrome Web Store

More than 500 fake VPN extensions remain on Chrome Web Store
Photograph: BleepingComputer

More than 737 fake Chrome VPN extensions impersonating Proton VPN, NordVPN, Surfshark and ExpressVPN routed users' traffic through SOCKS5 proxies operated by a single provider, researchers at application security company Socket found. The extensions were downloaded nearly 75,000 times, mainly by Russian users seeking to bypass blocked services, and were published through 40 accounts using a shared analytics account.

Socket identified three threat behaviors: 520 extensions configured Chrome to route all browser traffic through the operator's proxies; 104 extensions used DNS-over-HTTPS to hide the proxy destination; and some advertised nonexistent premium servers in Japan, Singapore, Canada, Australia and Turkey for subscription fraud. The researchers said the extensions impersonated established brands, used nonfunctional payment mechanisms and added remote configuration after approval — indicators of intentional deception.

Google removed more than 200 extensions, but over 500 remain available on the Chrome Web Store, Socket reports.

Hundreds of fake Chrome VPN extensions route traffic through a proxy More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies operated by a single provider. bleepingcomputer.com
cybersecurityconsumer-threatchrome-extensionsscamsmalware
CommercialBleepingComputerBleepingComputer LLC · trade press

Australia's smelter bailouts cost $2.5 million per job, dwarfing AI policy spending

Australia's smelter bailouts cost $2.5 million per job, dwarfing AI policy spending
Photograph: SMH business (AU)

The Albanese government has committed $2.5 billion to keep Rio Tinto's Tomago aluminium smelter operating near Newcastle, protecting 1000 jobs at a cost of $2.5 million per position, the Sydney Morning Herald reports. The figure exceeds support for other ageing industrial facilities, including a $240 million zinc and lead smelter bailout in South Australia and Tasmania, a $600 million Mount Isa copper smelter package, and a $2 billion Gladstone aluminium smelter support scheme.

The government frames the Tomago support as critical to Australia's clean energy transition, arguing that keeping smelters operational allows them to be modernised and made environmentally sustainable, securing domestic supply of materials essential to battery production. Without the bailout, the Herald notes, Australia would rely on smelters in China and other nations for these materials.

The investment contrasts sharply with the government's approach to artificial intelligence disruption, which it predicts will eventually cause major job losses. The government's AI policy relies on an office within the Prime Minister's department with no new laws or dedicated regulator, the Herald reports.

How much is a job worth? At Tomago, it’s $2.5 million in taxpayer cash The Albanese government has scarcely met an ageing industrial facility that it doesn’t think deserves vast sums of federal support. smh.com.au
government-subsidyindustrial-policypublic-spendingmanufacturingsubsidies
CommercialThe Sydney Morning HeraldNine Entertainment

Android malware duo steals card data and takes loans in victims' names

Android malware duo steals card data and takes loans in victims' names
Photograph: BleepingComputer

A combination of two Android malware tools—WindRelay and the SpyNote remote administration tool—is being used to steal payment card data and fraudulently take out loans, cybersecurity firm Group-IB reports. In an investigated incident, an attacker impersonating a bank employee called a victim, instructed them to sideload the malicious SpyNote app, then remotely installed WindRelay and used the banking app to take out a loan in the victim's name.

The attacker instructed the victim to tap their payment card against the phone and enter their PIN. WindRelay converted the phone into a fraudulent contactless reader and relayed the card's near-field communication data—including transaction-specific authentication codes—to the attacker's device in real time, allowing fraudulent purchases at genuine payment terminals. The entire fraud occurred during a 13-minute call, Group-IB said.

Group-IB identified nearly two dozen WindRelay samples between November 2025 and July 2026 communicating with four command-and-control servers, with targeting appearing focused on Czechia, Slovakia and Slovenia, Bill Toulas reports for BleepingComputer.

Android malware combo takes out loans and relays victims' credit cards A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. bleepingcomputer.com
cybersecurityfraud-scamsmalwareandroid-malwarepayment-fraud
CommercialBleepingComputerBleepingComputer LLC · trade press
39 DAYS AGO Key event Share

Hackers exploit critical SharePoint flaw hours after security code released

Hackers exploit critical SharePoint flaw hours after security code released
Photograph: BleepingComputer

Attackers are exploiting a critical Microsoft SharePoint authentication bypass vulnerability within hours of a proof-of-concept exploit being published, threat intelligence company Defused reported on Tuesday. The flaw, tracked as CVE-2026-55040, allows unauthenticated attackers to impersonate SharePoint users or administrators and access or modify files, according to cybersecurity researcher Stephen Fewer at Rapid7, who released the technical writeup and exploit code on Tuesday.

Microsoft patched the vulnerability in July 2026 updates and warned customers running SharePoint Enterprise Server 2016 and SharePoint Server 2019 to apply the fix. The U.S. Cybersecurity and Infrastructure Security Agency warned network defenders on July 15 to secure SharePoint servers and recommended blocking direct internet exposure or placing servers behind a Layer 7 reverse proxy. Shadowserver currently tracks over 8,500 Microsoft SharePoint servers exposed online, Sergiu Gatlan reports for BleepingComputer.

Hackers leverage new Microsoft SharePoint exploit in attacks Hackers have already begun using a proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday. bleepingcomputer.com
cybersecuritymicrosoftsharepointvulnerabilityexploit
CommercialBleepingComputerBleepingComputer LLC · trade press
39 DAYS AGO Key event Share

North Korean Lazarus hackers exploit Windows zero-day to target defense firms

North Korean Lazarus hackers exploit Windows zero-day to target defense firms
Photograph: BleepingComputer

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies in Europe and India as part of the Operation Dream Job campaign, BleepingComputer reports citing researchers at Check Point.

Microsoft patched the flaw this month, describing it as a use-after-free vulnerability in Windows Ancillary Function Driver for WinSock that allows attackers to escalate privileges to SYSTEM level. Lazarus incorporated an exploit for the vulnerability into a new version of the FudModule kernel-mode rootkit, which disables endpoint detection and response telemetry and interferes with security products.

Check Point found that the latest wave of Operation Dream Job, which has used fraudulent recruitment offers to target employees, also deployed a new backdoor called Troy supporting 17 commands including file exfiltration and remote process termination.

Lazarus hackers exploited Windows zero-day to target defense firms North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. bleepingcomputer.com
cybersecurityzero-dayhackingdefensemalware
CommercialBleepingComputerBleepingComputer LLC · trade press

Google says Chrome blocks 7 billion unwanted Android notifications daily

Google says Chrome blocks 7 billion unwanted Android notifications daily
Photograph: BleepingComputer

Google said its Chrome browser blocked more than 7 billion unwanted notifications daily on Android during the first quarter of 2026, as notification abuse has been increasingly used to distribute scams, malware and phishing attempts.

The company uses overlapping defense systems to catch abuse at different stages, including automatically revoking notification permissions from sites users have not recently visited and those that repeatedly trigger suspicious warnings. Chrome also limits sites classified as disruptive to 1,000 messages per minute, with excess requests returning an error, Mayank Parmar reports for BleepingComputer.

Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse Google says Chrome's anti-abuse systems reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026. bleepingcomputer.com
cybersecurityfraud-scamsmobilescams
CommercialBleepingComputerBleepingComputer LLC · trade press

NZ regulator fines online retailer $1.1m for fake customer reviews

NZ regulator fines online retailer $1.1m for fake customer reviews
Photograph: NZ Herald business

New Zealand's Commerce Commission has fined Auckland-based online retailer The TV Shop $1.1 million for publishing false customer reviews, according to the NZ Herald. The fine marks enforcement action against deceptive trading practices in e-commerce, Herald Reporters reports for NZ Herald business.

The TV Shop fined $1.1m over fake ‘customer’ reviews The company was convicted of 13 charges for breaches of the Fair Trading Act. nzherald.co.nz
consumer-protectionfair-tradingretail-fraudecommerce-fraudnz
CommercialNZ HeraldNZME

Intel raises $20 billion in upsized share offering

Intel raises $20 billion in upsized share offering
Photograph: The Straits Times

Intel raised $20 billion in an upsized share offering to fund the expansion of its chip contract manufacturing business, Reuters reports.

The US chipmaker priced the stock sale at $95 per share, representing a 2.6% discount to its previous close, after initially aiming to raise $15 billion.

Intel raised its capital expenditure forecast to $20 billion in July amid rising demand for artificial intelligence processors, and plans high-volume production using its 14A manufacturing process by 2028, The Straits Times reports.

Intel raises US$20 billion from upsized share offering Intel secures US$20 billion from an expanded share offering to fund its chip contract manufacturing business expansion amid a stock rebound. Read more at straitstimes.com. Read more at straitstimes.com. straitstimes.com
intelcapital-marketssemiconductorsmarketstechnology
CommercialThe Straits TimesSPH Media TrustReceives Singapore government funding.

Data breach costs in SE Asia jump 12 percent to record $4.12m

Data breach costs in SE Asia jump 12 percent to record $4.12m
Photograph: Inquirer business (PH)

Costs incurred by businesses across Southeast Asia due to data breaches reached a record high in 2026, jumping 12 percent to an average of $4.12 million, according to IBM's 2026 Cost of a Data Breach Report. The increase was driven partly by artificial intelligence making cyberattacks cheaper and faster to carry out, said IBM Asean general manager Catherine Lian.

Financial services firms in the region incurred the highest average breach costs at $6.53 million, followed by industrial organizations at $5.99 million and communications firms at $4.28 million. The findings were based on data from 26 organizations across the Philippines, Singapore, Indonesia, Malaysia, Thailand and Vietnam.

Organizations that extensively used AI and security automation reported a lower average breach cost of $3.66 million compared with $4.86 million among those without these tools, and contained breaches 123 days faster. Nearly three in four organizations in the region said they planned to increase investments in security tools and governance following a breach, Inquirer business (PH) reports.

Data breach costs jump in SE Asia INQUIRER.net stock images MANILA, Philippines — Costs incurred by businesses across Southeast Asia due to data breaches reached a record high in 2026, as increasingly sophisticated attacks business.inquirer.net
data-breachcybersecuritysoutheast-asia
CommercialPhilippine Daily InquirerInquirer Group
40 DAYS AGO Key event Share

US court sanctions Meta over lost evidence in Forrest scam ad case

US court sanctions Meta over lost evidence in Forrest scam ad case
Photograph: ABC business (AU)

A U.S. federal court has sanctioned Meta for failing to preserve key evidence in a lawsuit brought by Australian billionaire Andrew Forrest over scam ads, ABC News reports.

A judge found the company failed to take reasonable steps to retain data, including the final scam ads shown to victims, resulting in prejudice against Forrest.

Forrest, who is suing Meta over fake crypto and investment ads using his likeness, said the ruling gave "a glimmer of hope of correcting a huge injustice inflicted on society." Blake Kagi reports for ABC business (AU).

US court rules against Meta in Andrew Forrest scam ads case A US Federal Court has ruled against the social media giant in an ongoing legal dispute with Australian billionaire Andrew Forrest, who is suing Meta over scam ads that feature his likeness without his permission. abc.net.au
scamsmetalitigationandrew-forrest
Publicly fundedABC NewsAustralian Broadcasting Corporation · publicly fundedStatutory corporation, funded by the Commonwealth.
40 DAYS AGO Key event Share

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
Photograph: BleepingComputer

The U.S. Cybersecurity and Infrastructure Security Agency confirmed Tuesday that ransomware gangs are exploiting CVE-2026-45659, a high-severity remote code execution vulnerability in Microsoft SharePoint that allows attackers with low privileges to execute arbitrary code on unpatched servers. CISA added the flaw to its Known Exploited Vulnerabilities Catalog on July 1 and ordered federal agencies to patch within three days.

Microsoft released fixes in May for SharePoint Enterprise Server 2016, SharePoint Server 2019 and SharePoint Server Subscription Edition. The vulnerability stems from a deserialization of untrusted data weakness and "does not require significant prior knowledge of the system", Microsoft said. Internet security firm Shadowserver is tracking over 8,500 exposed SharePoint servers online, with more than 200 remaining unpatched against the flaw.

CISA has now flagged 14 actively exploited Microsoft SharePoint vulnerabilities since November 2021, with eight also used in ransomware attacks, Sergiu Gatlan reports for BleepingComputer.

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. bleepingcomputer.com
cybersecurityransomwarevulnerabilitymicrosoftcisa
CommercialBleepingComputerBleepingComputer LLC · trade press
40 DAYS AGO Key event Share

Cisco warns of firewall flaw being actively exploited to crash devices

Cisco warns of firewall flaw being actively exploited to crash devices
Photograph: BleepingComputer

Cisco has disclosed a high-severity denial-of-service vulnerability in its Secure Firewall ASA and Threat Defense software that is being actively exploited in attacks, the company said in a security advisory published today. The flaw, tracked as CVE-2026-20349 with a severity score of 8.6, can be triggered remotely without authentication by sending a crafted HTTP request to affected devices with remote access services enabled, causing them to reload and go offline.

"An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device," Cisco said. A successful attack "could allow the attacker to cause the affected device to reload, resulting in a DoS condition." Vulnerable configurations include IKEv2 Remote Access VPN, SSL VPN and Zero Trust Network Access on FTD devices. Cisco has released hot fixes for ASA versions 9.16 through 9.24 and FTD versions 7.0 through 10.0, and said there are no workarounds. The company became aware of active exploitation in August 2026 but has not disclosed who is behind the attacks or which organizations are targeted, Reuters is reporting, Lawrence Abrams reports for BleepingComputer.

Cisco warns of ASA and FTD VPN flaw exploited to crash devices Cisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software is being actively exploited in attacks to remotely crash affected devices. bleepingcomputer.com
cybersecurityvpnciscovulnerabilitydenial-of-service
CommercialBleepingComputerBleepingComputer LLC · trade press

Scamwatch warns of fake purchase callback scams targeting Australians

Scammers are sending fake messages claiming you have made a purchase of $300 to $2,000 and urging you to call a number to stop or reverse the payment, the ACCC's Scamwatch service warned on Tuesday. The messages, which arrive by text, email, app notification or calendar invitation, often impersonate payment services such as PayPal or companies including Apple, Google, Microsoft and Norton, and may include personal details such as your name, email or address to appear legitimate.

If you call the number, scammers may ask for bank or card details, request you send money claiming overpayment, install software to access your accounts, or trick you into buying gift cards. Scamwatch advises checking whether any payment is real by logging into your official account through the real website or app, rather than using contact details in the message, and not calling the number or sharing financial information or one-time codes, scamwatch.gov.au reports.

Scam alert: Fake purchase callback scams Scammers are sending fake messages that say you bought something you didn’t buy and tells you to call a phone number to stop or reverse the payment. scamwatch.gov.au
fraudscamsconsumer-protectionaccc
Not ratedscamwatch.gov.auNo ownership record held

ASIC puts car insurers on notice over premium rises far outpacing inflation

ASIC puts car insurers on notice over premium rises far outpacing inflation
Photograph: ABC business (AU)

ASIC has released a review finding that car insurance premiums rose 8 per cent in the year to July 2025, far exceeding inflation, after complaints about the product topped the corporate regulator's complaints register in 2024-25.

The watchdog examined eight brands under five insurers representing nearly three-quarters of the market and found their renewal notices did not clearly explain why premiums were rising beyond inflation. "Insurers tell us there are a range of reasons for these significant increases, but the problem is they're not explaining the reasons for those increases," ASIC commissioner Alan Kirkland said. "That's important because people need to understand how much their premium has actually gone up."

ASIC found that nearly 40 per cent of people who renewed their policy did not contact their provider or compare quotes, yet almost one in three of those who questioned their premiums ended up with a better deal. Insurers also failed to make clear in renewal notices that customers paying in instalments could save between 10 and 20 per cent by paying annually. "Loyalty doesn't pay," Mr Kirkland said, ABC business (AU) reports.

'Loyalty doesn't pay': Car insurers asked to explain soaring premiums The corporate regulator ASIC has taken aim at major car insurers, finding the companies are not explaining why customers' premiums are rising faster than inflation. abc.net.au
insurancepremiumscar-insuranceasicconsumer-complaints
Publicly fundedABC NewsAustralian Broadcasting Corporation · publicly fundedStatutory corporation, funded by the Commonwealth.

FBI, South Korea warn of Gunra ransomware targeting critical infrastructure

FBI, South Korea warn of Gunra ransomware targeting critical infrastructure
Photograph: The Record

The FBI and South Korea's National Policy Agency have warned of a ransomware gang called Gunra that is breaching critical infrastructure organizations through firewall vulnerabilities, according to a joint cybersecurity advisory released Monday. The group, which emerged in April 2025 using source code from the leaked Conti ransomware, has been exploiting two known Fortinet firewall vulnerabilities to gain access to networks in the healthcare, financial services and government sectors globally, stealing and encrypting data before demanding ransoms often exceeding $10 million.

The agencies said Gunra actors have attempted to contact victim company management directly by email to solicit payments, with limited success, The Record reports.

FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned. therecord.media
cybersecuritycritical-infrastructureransomwarelaw-enforcement
CommercialThe RecordRecorded Future · trade pressPublished by a cybersecurity vendor that sells threat intelligence.

BdThemes WordPress plugins compromised in supply-chain attack

BdThemes WordPress plugins compromised in supply-chain attack
Photograph: BleepingComputer

A threat actor compromised BdThemes' upstream infrastructure and modified a remote JSON feed to create rogue administrator accounts on WordPress sites running the company's plugins, according to security firm Defiant's Wordfence division. The attack exploited a cross-site scripting vulnerability in the Biggop Library component responsible for fetching promotional banners, allowing the attacker to inject malicious JavaScript that used legitimate administrators' sessions to create hidden admin accounts and install webshells, BleepingComputer reports.

Wordfence detected the attacks starting August 7, with evidence suggesting the campaign began as early as June 23. The affected plugins—including Element Pack, which has over 100,000 active installations—were removed from WordPress.org on August 8 pending review. The vulnerability was assigned a "medium" severity score and remains unpatched as of publication, Defiant said. Researchers traced the command-and-control infrastructure to the same attacker behind recent compromises of Advanced Responsive Video Embedder and OptinMonster.

BdThemes plugins supply-chain hack creates rogue WordPress admins A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts. bleepingcomputer.com
cybersecuritywordpresssupply-chainsupply-chain-attackmalware
CommercialBleepingComputerBleepingComputer LLC · trade press
41 DAYS AGO Key event Share

China-linked hackers exploit software flaw in ransomware supply-chain attack

China-linked hackers exploit software flaw in ransomware supply-chain attack
Photograph: The Record

Microsoft Threat Intelligence warned that Storm-1175, a financially motivated group linked to China, is exploiting a critical vulnerability in N-central, a remote monitoring tool used by managed service providers, to deploy custom ransomware called StormEncryptor across victim networks. The group began attacks on August 2, the same day the flaw in N-central was disclosed, gaining what Huntress described as "unauthenticated, 'god-mode' access" to servers that control thousands of downstream business endpoints.

A single compromised N-central server can cascade into dozens of ransomware incidents across an MSP's entire client base. Storm-1175 previously used Medusa ransomware to target healthcare, professional services and finance organisations in Australia, Britain and the United States, and has moved from initial access to full encryption in under 24 hours. N-able, which makes N-central, said it contacted a "limited number" of affected customers. Huntress found more than half of reachable N-central cloud servers across its partner base remained unpatched even after emergency fixes were issued on August 2 and August 6, The Record reports.

China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns A China-linked threat actor is believed to be exploiting a critical vulnerability affecting cybersecurity software from the company N-able. therecord.media
cybersecurityransomwaremicrosoftsupply-chain-attackvulnerability
CommercialThe RecordRecorded Future · trade pressPublished by a cybersecurity vendor that sells threat intelligence.
41 DAYS AGO Key event Share

CISA flags SonicWall SMA1000 flaws as actively exploited by ransomware gangs

CISA flags SonicWall SMA1000 flaws as actively exploited by ransomware gangs
Photograph: BleepingComputer

The U.S. Cybersecurity and Infrastructure Security Agency has confirmed that ransomware gangs are actively exploiting two vulnerabilities in SonicWall's SMA1000 enterprise VPN gateway, according to BleepingComputer. The flaws, tracked as CVE-2026-15409 and CVE-2026-15410, were patched by SonicWall in mid-July after the company warned they were being exploited in zero-day attacks.

Incident response firm Volexity previously reported that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 to deploy custom malware including KNUCKLEBALL and ROOTRUN on vulnerable VPN appliances. CISA added both flaws to its Known Exploited Vulnerabilities catalog on July 14, ordering U.S. federal agencies to patch within three days. Security watchdog Shadowserver tracks over 380 SMA1000 appliances exposed online, though some may have already been secured.

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. bleepingcomputer.com
ransomwarevulnerabilitycritical-infrastructurecybersecurityvpn
CommercialBleepingComputerBleepingComputer LLC · trade press

30% of UK manufacturers hit by cyber-attacks in past year, survey finds

30% of UK manufacturers hit by cyber-attacks in past year, survey finds
Photograph: Guardian business

Nearly a third of British manufacturers have experienced a cyber-incident in the past 12 months, according to a survey by MakeUK, a lobby group for the sector. The findings highlight growing hacking risks to companies, with attacks often leading to lost production time and increased costs, yet only half of manufacturers have a plan in place to respond to an attack.

The rise in attacks comes almost a year after JLR, Britain's largest automotive employer, was hit by a cyber-attack that forced production halts for weeks. The independent Cyber Monitoring Centre said that incident cost the UK economy at least £1.9bn, probably making it the most expensive cyber incident ever in Britain. The New York Times reported in June that Russian hackers were behind the JLR attack.

Jonathon Ellison, director of national resilience at the National Cyber Security Centre, said: "In today's landscape, no manufacturer can afford to treat cybersecurity as anything other than a business-critical priority." The UK government has said cybercrime costs the economy £14.7bn a year, with the rise of generative AI systems adding urgency to efforts to upgrade defences.

UK manufacturers face rising hacking risk as survey shows 30% were hit last year Big companies describe being under constant threat but only half have a plan in place to respond to an attack theguardian.com
cybersecurityhackingmanufacturingukdata-breach
Trust or non-profitThe GuardianScott Trust (Guardian Media Group)Trust-owned: no shareholders and no proprietor.
41 DAYS AGO Key event Share

US agency warns of critical LoadMaster flaw actively exploited in attacks

US agency warns of critical LoadMaster flaw actively exploited in attacks
Photograph: BleepingComputer

The U.S. Cybersecurity and Infrastructure Security Agency has added a critical command injection vulnerability in Progress Kemp LoadMaster to its catalog of actively exploited flaws, ordering federal agencies to patch within three days.

Tracked as CVE-2026-8037, the vulnerability allows unauthenticated attackers to execute arbitrary commands on unpatched LoadMaster appliances through unsanitized API inputs. Progress Software released patches in June for LoadMaster versions GA v7.2.63.1 and older, and LTSF v7.2.54.17 and older. Nearly 300 LoadMaster instances are exposed online, according to threat watchdog Shadowserver, though the number already patched or running as honeypots is unknown.

Kemp LoadMaster is used by over 100,000 deployments worldwide, including Amazon and the U.S. Air Force, to distribute web traffic across multiple servers. "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," CISA said. The agency urged all defenders, not just government agencies, to prioritize patching the flaw, Sergiu Gatlan reports for BleepingComputer.

Critical Progress LoadMaster flaw now actively exploited in attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. bleepingcomputer.com
cybersecurityvulnerabilitycisacritical-vulnerabilitiesus-government
CommercialBleepingComputerBleepingComputer LLC · trade press
42 DAYS AGO Key event Share

Australia's real estate agents now must report suspicious buyers under new anti-money laundering rules

Australia's real estate agents now must report suspicious buyers under new anti-money laundering rules
Photograph: SMH business (AU)

Real estate agents, accountants and lawyers came under Australia's Anti-Money Laundering and Counter-Terrorism Financing Act on July 1, requiring them to identify buyers and sellers and report suspicious activity to police. The change means cash deals with minimal identification are no longer possible.

AUSTRAC boss Brendan Thomas said the reforms will "help uncover money laundering in real estate transactions that we don't currently see". Two-thirds of the $1.2 billion in criminal assets frozen by police since 2020 is related to property, with the AFP's Criminal Assets Confiscation Taskforce having seized two Sydney penthouses in The Rocks district after they were purchased at inflated prices by organised crime figures.

Economists are split on the impact. AUSTRAC argues the rules will lower prices by removing illicit money from the market; Domain's chief economist says property values are "still driven by supply, demand and interest rates" and expects "no major impact" on average home prices, Colin Kruger reports for SMH business (AU).

What happens when crime is no longer paying for our real estate? The property sector’s money laundering restrictions have finally arrived, and it may be adding to the real estate slump. smh.com.au
fraud-scamsreal-estatemoney-launderingaustracorganised-crime
CommercialThe Sydney Morning HeraldNine Entertainment

Healthcare software firm discloses breach affecting 3.8 million patients

Healthcare software firm discloses breach affecting 3.8 million patients
Photograph: BleepingComputer

Unlimited Technology Systems, which processes financial and revenue cycle data for US specialty healthcare providers, disclosed on July 20 that hackers accessed patient files for five days in October 2025. The breach, detected on October 19, 2025, exposed personal information of 3.8 million patients, including full names, Social Security numbers, dates of birth, driver's license scans, insurance details and medical records, according to a notice filed with the U.S. Department of Health and Human Services on July 1.

The company serves 4,500 clinics and 6,500 specialty healthcare providers and processes more than $70 billion in net healthcare charges annually. The unauthorized access occurred between October 5 and October 10, 2025. No ransomware or extortion group has claimed responsibility, and Unlimited Technology Systems said it has not identified the attackers. Affected patients were offered identity monitoring services through Kroll, Bill Toulas reports for BleepingComputer.

Unlimited Technology Systems breach impacts 3.8 million people Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. bleepingcomputer.com
data-breachhealthcarecybersecuritypatient-privacy
CommercialBleepingComputerBleepingComputer LLC · trade press
42 DAYS AGO Key event Share

Metabase zero-day SQL injection flaw actively exploited in customer data thefts

Metabase zero-day SQL injection flaw actively exploited in customer data thefts
Photograph: BleepingComputer

A critical SQL injection vulnerability in Metabase versions 1.58 and above has been actively exploited to breach customer instances and steal data, Metabase disclosed on Thursday. The unauthenticated flaw gives attackers administrator access to instances, allowing them to steal credentials, read databases and export data. Metabase Cloud customers have been patched; self-hosted users must upgrade immediately to versions 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, or 0.63.5.

Laptop maker Framework confirmed attackers used the vulnerability to steal customer names, email addresses, billing and shipping addresses, phone numbers and login IP addresses. The flaw carries a CVSS score of 10.0 and has not yet been assigned a CVE identifier. Metabase advises customers to revoke user sessions, rotate database credentials, and review logs for POST requests to /api/session/reset_password followed by GET requests to /api/user/current, which indicate compromise, Mayank Parmar reports for BleepingComputer.

Metabase SQLi zero-day exploited in customer data-theft attacks A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. bleepingcomputer.com
cybersecuritydata-breachvulnerability
CommercialBleepingComputerBleepingComputer LLC · trade press
42 DAYS AGO Key event Share

New Mexico judge orders Meta to pay $567 million in kids safety case

New Mexico judge orders Meta to pay $567 million in kids safety case
Photograph: The Record

A New Mexico judge on Thursday ordered Meta to pay $567 million and overhaul how youth use its platforms, ruling the company a 'public nuisance' in a case considered the first bellwether among dozens brought against Meta by state attorneys general. Judge Bryan Biedscheid ordered $420 million of the settlement directed to a fund for treatment of New Mexico youth harmed on the platforms, with the remainder for public awareness campaigns.

The judge also prohibited Meta from sending push notifications to youth users between 10 p.m. and 7 a.m., limited youth engagement to 90 hours a month per user, and required child protection safety screens on Facebook and Instagram. In March, a jury in the same case had imposed a separate $375 million fine, finding Meta deceived users about safety and facilitated sexual exploitation of minors.

Meta said in a statement it disagrees with the ruling and plans to appeal. 'We work hard to keep people safe on our platforms and have been transparent about the challenges of identifying and removing bad actors and harmful content,' a company spokesperson said, The Record reports.

New Mexico judge orders Meta to pay $567 million in kids online safety case The money will be used to create a fund to mitigate social media harms, including by carving out $420 million for treatment for New Mexico youth who have been hurt on the platforms. therecord.media
cybersecuritydata-safetymetachild-safetylitigation
CommercialThe RecordRecorded Future · trade pressPublished by a cybersecurity vendor that sells threat intelligence.
42 DAYS AGO Key event Share

Military device maker discloses phishing attack to SEC

Military device maker discloses phishing attack to SEC
Photograph: The Record

IEH Corporation, which manufactures connectors used in military satellites, missiles and fighter jets, disclosed a cyberattack to the U.S. Securities and Exchange Commission on Thursday. An employee fell victim to a phishing attack that gave intruders access to an email inbox containing customer communications, purchase orders, engineering documentation and potentially export-controlled technical information, according to an 8-K filing.

The company discovered the breach on Tuesday and said there is no evidence data was taken from the account, though "sensitive information was accessible to the unauthorized party during the compromise period." IEH is taking corrective action to secure the mailbox and preserve evidence. As of Friday, the company said there is no indication the incident will impact its business operations, The Record reports.

Military device manufacturer discloses cyber incident to SEC IEH Corporation — which produces specialized products used in military satellites, missiles and fighter jets — said it discovered a cyberattack on Tuesday and immediately tried to contain it. therecord.media
cybersecuritybreachmilitaryphishing
CommercialThe RecordRecorded Future · trade pressPublished by a cybersecurity vendor that sells threat intelligence.

No story is present in the provided source. The text appears to be a jumbled collection of JavaScript code and library references, with no discernible news content, Education News reports.

https://news.google.com/rss/articles/CBMipgFBVV95cUxNQmJjYWJHTFgyUmdkMkoxVUF0T01iRXk1WlJTZTc0S1M4LVJzQ01RaFNPaVFXa2VYb25QbENZX0t6eWE2VTY0cGxKdTJhNkRnWXJ2MkxvUUYyWlpyZ2dKNlpBLUc5NXYzTlYzRnVvbXpGZXFVbHhjZzlaZ3dwS2JxUlRJRDNHb0lCQy1mUG1PUDVzNUJiM3dZTmk5d0JxdDFBUlF1TE1B?oc=5 news.google.com
fraud-scamsdiasporamigrationnone
Not ratednews.google.comNo ownership record held

Levi Strauss says hackers breached employee computers, accessed corporate data

Levi Strauss says hackers breached employee computers, accessed corporate data
Photograph: The Record

Levi Strauss & Co. said in a filing with the U.S. Securities and Exchange Commission on Friday that hackers accessed employee computers and exfiltrated corporate data.

The breach involved a social‑engineering attack that compromised three company‑issued devices, the filing said. Levi Strauss added that the incident did not disrupt operations and it saw no evidence that consumer data was affected.

"The company does not believe the incident has had, or is reasonably likely to have, a material impact on its business strategy, operations, financial condition, or results of operations," the filing stated.

The company did not identify the attackers, confirm ransomware involvement or report a ransom demand, and the investigation remains ongoing, The Record reports.

Levi Strauss says hackers breached employee computers, accessed corporate data Intruders exfiltrated certain corporate information after gaining access to three company-issued computers through a social engineering attack, Levi Strauss reported. therecord.media
cybersecuritycrime-justicedata-breachretail
CommercialThe RecordRecorded Future · trade pressPublished by a cybersecurity vendor that sells threat intelligence.

Load older updates

↑ Back to the latest updates