Progress Software Tells ShareFile Customers: Shut It Down Now
Progress Software has issued an urgent directive to ShareFile customers running on-premises Storage Zone Controllers, telling them to take the Windows servers offline immediately. The company confirmed it is responding to a "credible external security threat" and has proactively disabled access to affected accounts. Progress hasn't disclosed what the vulnerability is or whether it's being actively exploited, which is a red flag in itself — the company learned harsh lessons from the MOVEit breach in 2023 and appears to be moving faster this time. ShareFile is widely used in legal, financial services, and healthcare sectors. Australian organisations using ShareFile's managed file transfer capabilities should confirm their deployment model with their vendors immediately.
The Hacker News ↗Vishing Attacks Are Hijacking Microsoft 365 Accounts Via Fake Passkey Enrolment
A threat actor tracked as O-UNC-066 is running a sophisticated voice phishing campaign against Microsoft 365 users. Victims receive a phone call impersonating a security alert, then get directed to a fake Microsoft Entra ID page that captures their credentials and tricks them into enrolling the attacker's passkey — effectively handing over persistent, phishing-resistant access. Okta researchers who discovered the campaign note it's targeting organisations across multiple sectors and is explicitly designed to circumvent MFA. The passkey enrolment angle is clever: it turns a next-gen authentication method into an access vector by inserting the attack at the moment of enrolment rather than authentication. M365 admins should audit recent passkey enrolments and lock down who can register new credentials.
The Hacker News ↗Europe Passes Chat Control 2.0 — Mandatory Message Scanning Is Now Law
The European Parliament has passed Chat Control 2.0, requiring companies including Google, Meta, and Microsoft to scan users' private messages for child sexual abuse material. Privacy advocates have fought the law for years, arguing that any system capable of scanning encrypted messages fundamentally breaks end-to-end encryption — you can't build a backdoor only good guys can use. Supporters argue the status quo lets CSAM circulate freely behind the shield of encryption. The law now applies to platforms operating in the EU, meaning Australian users of those platforms may see policy changes as companies try to build globally consistent implementations. Expect legal challenges immediately, and watch how Apple — already in a fight with OpenAI — responds given its strong privacy positioning.
The Record ↗HalluSquatting: Researchers Turn AI Hallucinations Into a Malware Delivery Channel
Researchers have demonstrated a technique called "adversarial hallucination squatting" — or HalluSquatting — that exploits the tendency of AI assistants to confidently recommend non-existent package names. The attack works by registering the fake package names that popular AI coding assistants frequently hallucinate, then stuffing them with malware. When a developer asks an AI for help and it suggests a package that doesn't exist, an attacker who pre-registered that name gets code execution on the developer's machine. It's a new flavour of typosquatting that requires no typo — just a predictably wrong AI. The technique has been demonstrated against multiple popular AI assistants and achieves remote code execution. This is a genuine supply chain risk for any team using AI-assisted coding without package verification discipline.
SecurityWeek ↗SK Hynix Raises $26.5 Billion in the Biggest Foreign IPO in US History
South Korean memory chipmaker SK Hynix opened on Wall Street at $170 per share on Friday, raising $26.5 billion and shattering Alibaba's record for the largest US debut by a foreign company. The AI boom's insatiable appetite for high-bandwidth memory — the specialised RAM that makes Nvidia's GPUs sing — has turned SK Hynix into one of the most strategically critical companies in the global chip stack. US officials used the debut to press SK Hynix and Samsung to build domestic American fabs. The trillion-dollar valuation and Wall Street reception underline just how much the AI infrastructure story is really a memory story. For Australian superannuation funds with US equity exposure, SK Hynix is now a name that matters.
TechCrunch ↗GigaWiper: The Swiss Army Knife of Destructive Malware
Microsoft has detailed GigaWiper, a modular Windows backdoor that bundles at least three distinct malware families into a single package: a standalone wiper, ransomware-grade encryption, and a multi-pass data destruction command. The modular design means attackers can switch objectives mid-intrusion — start with reconnaissance, pivot to encryption for ransom leverage, then trigger the wiper if negotiations fail or they simply want to cover tracks. SecurityWeek and The Register both covered the disclosure, noting it represents a meaningful step up in destructive capability from typical ransomware tooling. The combination approach is particularly nasty for incident responders, who may face simultaneous recovery and negotiation decisions with no clean path through either.
SecurityWeek ↗Free Android VPN Apps Are Leaking the Traffic They Promise to Protect
A study testing 281 of the most popular free VPN apps on the Google Play Store found widespread, basic failures: 29 apps leak user traffic outside the VPN tunnel entirely, and many transmit unencrypted data or embed tracking SDKs. The apps flagged with at least one problem have been installed more than 2.4 billion times combined. The failures aren't sophisticated — they're sloppy implementations of fundamentals. This matters particularly for users in high-risk environments who believe a free VPN is protecting their traffic. In Australia, where free VPN use spiked after various geo-blocking discussions, this finding is a direct consumer warning: the free VPN you installed is quite possibly doing the opposite of what you think.
The Hacker News ↗EU Threatens Meta With Fines Over Autoplay and Infinite Scroll
The European Commission has formally told Meta that autoplay video, infinite scroll, push notifications, and its personalised recommendation algorithms breach the Digital Services Act — and that fines are coming if the company doesn't make changes. The DSA requires platforms to assess and mitigate risks of "addictive design" on minors, and the Commission has decided Meta has failed that test. Meta will almost certainly challenge the ruling, but the regulatory pressure is real. Australia is watching closely: the Online Safety Act's Basic Online Safety Expectations and the ongoing reform of age assurance rules put Australian regulators on a parallel track, and EU enforcement precedents tend to inform what ACMA considers politically achievable domestically.
TechCrunch ↗CBA Cuts 176 Technology and Engineering Roles
Commonwealth Bank of Australia is cutting 176 technology and engineering positions, the bank confirmed to iTnews. CBA pushed back on suggestions the roles are being offshored, but offered little detail on where the work goes instead. The cuts land at an interesting moment: CBA has been one of the more aggressive Australian financial institutions in publicising its AI investments, and headcount reductions in engineering during an AI buildout tend to tell a story about where productivity gains are actually landing. Whether this is AI-driven efficiency, cost discipline ahead of a softer economic period, or both is worth watching. It's also a significant development for Australia's tech employment market, where financial services engineering roles carry real weight.
iTnews ↗Ransomware Negotiator Who Betrayed His Own Clients Gets 70 Months
Angelo Martino, a former ransomware negotiator at DigitalMint, has been sentenced to 70 months in federal prison after prosecutors established he was secretly feeding confidential victim information to the BlackCat/AlphV gang he was supposed to be negotiating against. Martino and two co-conspirators helped extort a combined $75.3 million from five US-based victims. He is the third security professional sentenced in relation to ransomware conspiracy charges in recent months, a pattern that signals US prosecutors are actively pursuing insider collusion as a category, not just treating it as an oddity. The case is a sharp reminder that incident response — including negotiation — creates privileged access that can be catastrophically abused.
CyberScoop ↗Patreon Partners With Cloudflare to Block AI Crawlers From Creator Content
Patreon has partnered with Cloudflare to block AI training crawlers from scraping creator content, with CEO Jack Conte drawing a hard line: "Creators deserve credit, compensation, and consent. If that's not on the table, the crawlers can stay the fuck off Patreon." The move follows similar actions from other platforms and reflects growing creator-economy pressure on AI labs to negotiate data licensing rather than scrape freely. Cloudflare's AI crawler blocking tools have been increasingly adopted by publishers and platforms globally, including several Australian media organisations that have quietly deployed them over the past year. Whether this constitutes meaningful protection or a speed bump that determined crawlers route around remains an open question.
404 Media ↗