OpenAI Deploys GPT-5.5-Cyber to Hunt and Patch Open-Source Bugs
OpenAI launched 'Daybreak' — a security initiative pairing its new GPT-5.5-Cyber model with human experts to find and fix vulnerabilities in widely-used open-source software. The companion 'Patch the Planet' programme, run with Trail of Bits, produced hundreds of discovered bugs, 64 pull requests, and 51 issues filed across 19 projects in its first week alone. The initiative is a direct shot across Anthropic's bow — Anthropic's Claude Mythos model was recently credited with helping discover the Squidbleed vulnerability — and positions OpenAI as a proactive force in the security ecosystem rather than just a capability provider. Open-source software underpins much of Australia's public and private digital infrastructure, so the downstream patch benefits are real.
OpenAI Blog ↗Klue Hack Widens: HackerOne, Huntress, Recorded Future Among Victims
The breach at Klue — a competitive intelligence SaaS platform — has now claimed a notably awkward list of victims: HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium have all disclosed impact. The attacker group, dubbed Icarus, is believed to have exploited Salesforce-linked integrations rather than breaking directly into Klue's core systems. That's the key detail — the blast radius of a SaaS integration compromise is determined by which downstream apps trusted the compromised platform's data pipes. The irony of security vendors being breached via their sales intelligence tooling will not be lost on anyone. Australian security teams using similar RevOps integrations should audit what data their CRM-connected tools can actually access.
SecurityWeek ↗Fake IT Worker Threat Expands Beyond Tech Into Australian Healthcare
The North Korea-linked 'fake IT worker' scheme — where operatives pose as remote contractors to gain paid employment and insider access — is spreading beyond the Australian technology sector into healthcare organisations, according to new reporting from iTnews. Healthcare's combination of rich personal data, often under-resourced security teams, and reliance on contract staff makes it an attractive target. The scheme typically involves fabricated LinkedIn profiles, stolen identities, and referrals from unwitting co-conspirators. Australian organisations onboarding remote contractors should be checking for suspicious patterns: reluctance to appear on video, requests to redirect pay to third parties, and unusually broad access requests early in tenure.
iTnews ↗Squidbleed: A 29-Year-Old Squid Proxy Bug That Leaks Your HTTP Traffic
Researchers at Calif.io have disclosed 'Squidbleed' — a heap over-read vulnerability baked into Squid proxy software since 1997, when a developer made a change to FTP parsing. The bug lets any user sharing a proxy read another user's cleartext HTTP request, including any credentials or session tokens riding along with it. It's been compared to Heartbleed in mechanism — a memory leak that exposes adjacent data — and it sits in Squid's default configuration. Squid is widely deployed in enterprise networks, ISPs, and government environments for caching and content filtering. The bug was found with assistance from Anthropic's Claude Mythos Preview, which is becoming an interesting pattern in recent vulnerability discovery.
The Hacker News ↗ShapedPlugin's WordPress Pro Plugins Backdoored in Supply Chain Hit
Attackers compromised the build and distribution pipeline of ShapedPlugin — a developer of popular commercial WordPress plugins — and pushed backdoored versions through the official licensed update channel. Because the malicious update came through a legitimate, trusted source, site owners who had purchased valid licences received the backdoor without any obvious warning signs. Wordfence's analysis confirms the payload was injected at the vendor level, not at the WordPress.org repository. This is the subtler and more dangerous kind of supply chain attack: it targets the premium, paid update path that many operators specifically trust over public repositories. WordPress powers a significant proportion of Australian business and government websites.
The Hacker News ↗Tata Electronics Confirms Data Breach at Apple and Tesla Supplier
Tata Electronics — a major supplier to both Apple and Tesla — has confirmed a data breach, with limited details disclosed so far. The incident is particularly sensitive given Tata's expanding role in global technology supply chains, including iPhone assembly work that has been ramping up as Apple diversifies manufacturing away from China. The breach is a reminder that supply chain cyber risk doesn't stop at software; hardware and manufacturing suppliers hold sensitive production, logistics, and personnel data that can be operationally valuable to nation-state actors. Australian Apple and Tesla customers aren't directly affected, but the incident underscores the complexity of critical supplier risk under frameworks like Australia's SOCI Act third-party provisions.
TechCrunch ↗Trump Signs Executive Orders to Accelerate Post-Quantum Encryption Migration
President Trump signed two executive orders mandating that US federal agencies fast-track their migration to post-quantum cryptography standards, while also directing investment in the domestic quantum computing industry. The orders set hard deadlines for agencies to inventory systems still relying on classical encryption and begin transitioning to NIST-approved post-quantum algorithms. The move puts formal policy muscle behind what has largely been voluntary guidance. Australia's own post-quantum migration posture — guided by the ASD — has been progressing but without equivalent legislative urgency. As a Five Eyes partner and significant US technology consumer, Australian government and financial services operators face pressure to align their own timelines or risk interoperability gaps with US counterparts.
CyberScoop ↗Canada's Spy Agency Got a Court Warrant to Remotely Disinfect Botnet Devices
In a legal first, Canada's Security Intelligence Service obtained a Federal Court warrant allowing it to remotely access and neutralise two foreign-operated botnets — reaching directly into infected home routers and IoT devices sitting on Canadian soil without their owners' knowledge or consent. The ruling, made public last week, marks the first time CSIS has used its 'threat reduction' powers in this way. It's a significant precedent: governments actively disinfecting civilian devices is a power most democracies have been cautious about codifying. Australia's ASD has analogous powers under the SOCI Act for critical infrastructure, but there's no equivalent mechanism yet for civilian endpoint remediation — a gap worth watching as botnet proliferation accelerates.
The Hacker News ↗DifyTap: Four Auth-Bypass Flaws Let Attackers Read Other Users' AI Chats
Security researchers at Zafran Security have disclosed four vulnerabilities — collectively dubbed DifyTap — in Dify, an open-source agentic workflow platform with more than 146,000 GitHub stars. The flaws allow an attacker to read AI conversation logs from other tenants' applications without needing to authenticate. In a multi-tenant SaaS context, that's a serious data leakage risk: a competitor, or simply a curious bad actor, could passively harvest conversations happening in adjacent accounts. Dify is widely used for building production AI applications, and its popularity means the exposed attack surface is substantial. Patches should be applied immediately for any self-hosted deployments.
The Hacker News ↗Brazil's Emergency Alert System Sent 'Misanthropy' to Millions of Phones
Brazil's Civil Defense Alert system — the platform designed to warn residents about floods and landslides — was apparently compromised early Saturday, sending at least a dozen unauthorised alerts across the country. The word 'misanthropy' was blasted to devices nationwide. Brazilian authorities are investigating what they suspect was a cyberattack on the alert platform. Emergency alert systems are high-value targets precisely because they carry inherent public trust — people are conditioned to act on them. Australia operates the Emergency Alert system through ACMA-regulated telcos, and the incident is a timely reminder that the integrity of public warning infrastructure needs to be treated as critical security real estate.
The Record ↗AMD Reinstates Memory Encryption After Users Accused It of Forcing Chip Upgrades
AMD reversed a controversial decision to remove Transparent Memory Encryption (TME) from its consumer-grade CPUs after significant user backlash. Critics had interpreted the move as a deliberate attempt to push security-conscious buyers toward more expensive enterprise-tier chips — essentially making a security feature a paid upsell. AMD's reversal came quickly, suggesting the reputational pressure was real. TME matters because it encrypts data sitting in RAM, protecting against cold-boot attacks and certain hypervisor-based threats. For researchers and developers building systems that handle sensitive data on consumer hardware — a scenario increasingly common in AI development workflows — the reinstatement is practically significant.
Ars Technica ↗