Select Page

Australian Information
and Cyber Security Awareness

Australian focus with a bit of New Zealand, vendor neutral, no vendor press releases, advertisement free.

Please follow the Source link to the original article to support the content owner. We've only provide a brief summary with metadata to assist in categorisation.

YouTube player

 





Featured

Latest

AU Info and Cyber Security News Last Week 2023-11-27

Australian Cyber News Last Week – November 27th, 2023: Well, that was a busy week. The Australian government’s release of the 2023-2030 Australian Cyber Security Strategy. I wrote up the TissuePath breach and followed down a rabbit hole of Core Desktop and AlphV (Black Cat). Optus CEO resigns, Changes to the SOCI act, Federal whole-of-government zero trust target, scale back of Metadata retention, and two-year delay on banning ransomware payments.

Australian InfoSec Incidents and Audits Issues

Incident: Football Australia data breach reportedly exposes contracts, passports, and ticket information | ABC News Australia

Australian Football Breach, 1 February 2024: Football Australia data breach reportedly exposes contracts, passports, and ticket information. Plain-text digital “keys” in the publicly accessible code, access to 127 digital storage containers.

Incident: Australian travel agency Inspiring Vacations, exposes customer data after leaving database publicly accessible

Australian Travel Agency Breach, 11 January 2024: Melbourne travel agency Inspiring Vacations, exposes customer data after leaving database publicly accessible. The leaked data, includes passport images, travel visa certificates, travel itineraries, and partial credit card numbers.

Incident: The Iconic promises refunds after a spate of fraudulent transactions on customer accounts | ABC News Australia

Australian Retail Breach, 09 January 2024: Australian retailer The Iconic, promises refunds after a spate of fraudulent transactions on customer accounts. While not directly hacked, the unauthorised third party used a technique known as ‘credential stuffing’.

Incident: Yakult Australia targeted in cyber attack, employee files published on dark web | ABC News Australia

Australian Manufacturer Ransomware Privacy Breach, 28 December 2023: Yakult Australia targeted in cyber attack, employee files published on dark web. 95 gigabytes of data including passports, medical assessments, salaries, and performance reviews.

Loading

Australian Info & Cyber Security News

Information Security Memes