TrendAI expands bug bounty to cover AI vulnerabilities

The New Frontier of Cyber Warfare: AI-Powered Zero Days For years, the cybersecurity world viewed Artificial Intelligence (AI) as a futuristic tool—either a helpful assistant or a distant threat. That illusion has shattered. We are now entering an era where AI is not just the tool being used to attack, but the primary target of … Read more

Government entities in Queensland unaware of cybersecurity vulnerabilities, audit office report finds

Queensland Government Systems Exposed: A Wake-Up Call for Cybersecurity A recent cybersecurity audit has revealed significant vulnerabilities within Queensland government systems, with auditors gaining “the highest level of access” to two entities. The findings underscore a growing concern: Australian public sector organizations are increasingly susceptible to cyberattacks, particularly those originating through third-party vendors. The Scope … Read more

Latvia’s SAB warns of Russian ICS cyber threat to European and Western critical infrastructure

Russia continues to engage in sabotage, information operations, and cyberattack preparations targeting industrial control systems (ICS) in Latvia and other Western nations. These actions, identified by the Latvian Constitution Protection Bureau (SAB) in its 2025 annual report, are intended to create uncertainty, disrupt services, and retaliate against support for Ukraine, as well as discourage future … Read more

Cisco Fixes Actively Exploited Zero-Day CVE-2026-20045 in Unified CM and Webex

Cisco Zero-Days: A Harbinger of Increased Attacks on Collaboration Tools? The recent disclosure of CVE-2026-20045, a critical zero-day vulnerability impacting Cisco’s Unified Communications and Webex Calling platforms, isn’t an isolated incident. It’s a stark reminder of a growing trend: collaboration tools are rapidly becoming prime targets for malicious actors. This vulnerability, already exploited in the … Read more

OpenAI Launches ChatGPT Health with Isolated, Encrypted Health Data Controls

The Rise of AI Health Companions: Beyond ChatGPT Health OpenAI’s launch of ChatGPT Health marks a pivotal moment, but it’s just the beginning. The integration of artificial intelligence into personal healthcare is rapidly accelerating, driven by user demand for accessible information and proactive health management. This isn’t simply about chatbots answering medical questions; it’s about … Read more

Digital finance in 2026: what to expect as pilot schemes move into real-world use

The Future of Digital Finance: Beyond Silos and Towards Interoperability Digital finance is no longer a futuristic concept; it’s rapidly becoming the norm. Stablecoins, tokenized assets, and the exploration of Central Bank Digital Currencies (CBDCs) are reshaping how we think about money and financial systems. However, the next phase – the period leading up to … Read more

Cyber attacks that occurred this year and how you can protect your data

It’s been a relentless year for cyber security, with millions of Australians seeing their personal data fall into the hands of increasingly sophisticated criminals. From healthcare providers to financial institutions and even government agencies, no sector has been immune. The fallout isn’t just personal – businesses are facing potentially crippling financial losses. <h2 class=”Typography_basesj2RP Heading_heading__VGa5B … Read more

New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory

MongoDB Vulnerability: A Harbinger of Future Database Security Challenges A recently disclosed high-severity flaw in MongoDB (CVE-2025-14847) – allowing unauthenticated read access to heap memory – isn’t just a patch-and-move-on situation. It’s a stark reminder of the evolving threat landscape facing database security, and a glimpse into challenges we’ll see amplified in the coming years. … Read more

Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens

December 22, 2025Ravie LakshmananMalware / Open Source / Supply Chain Security The Rising Tide of Malicious Packages: A Looming Threat to Software Supply Chains The recent discovery of “lotusbail,” a malicious npm package masquerading as a WhatsApp API, and a wave of compromised NuGet packages targeting the cryptocurrency ecosystem, aren’t isolated incidents. They represent a … Read more

Russia-Linked Hackers Use Microsoft 365 Device Code Phishing for Account Takeovers

The Rise of Device Code Phishing: A Glimpse into the Future of Account Takeovers A concerning trend is rapidly gaining traction in the cybersecurity landscape: device code phishing. Recent reports, including analysis by Proofpoint of the UNK_AcademicFlare campaign attributed to a Russia-aligned group, highlight a sophisticated technique for stealing Microsoft 365 credentials. This isn’t a … Read more