Matthew Miller, Author at Techbest - Top Tech Reviews In Australia - Page 15 of 174

AI Agents Stealthily Emerge as Leading Users in Companies, Leaving Organisations Unprepared


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

AI Agents: The Emerging Power User in Enterprises | TechBest

Brief Overview

  • AI agents are increasingly being adopted in organizations, frequently lacking appropriate governance.
  • These agents manage sensitive information and demand rigorous access controls.
  • Machine identities surpass human identities, complicating security management.
  • Organizations face security risks from AI agents with excessive permissions.
  • New standards such as MCP heighten the number of connections requiring secure oversight.
  • Contemporary identity security must progress to encompass AI agents.
  • Palo Alto Networks’ Idira aids in managing access across various identity types.

The Growth of AI Agents in Organizations

AI agents are swiftly becoming a fundamental part of the enterprise identity framework. However, numerous organizations are implementing them more quickly than they can regulate, leading to significant blind spots regarding the access capabilities of these agents, the systems they can connect to, and how that access is managed.

AI agents are becoming vital in organizations, with governance challenges.

As AI agents increasingly engage with sensitive information and automate operational workflows on behalf of users, they are being integrated into customer service, software development, and knowledge management. The primary security concern is not just what these agents are capable of, but whether organizations truly grasp and govern the privileges they have been assigned.

A New Category of Privileged Identity

Many organizations still wrongly interpret AI agents as simple software applications. In reality, they function as digital workers, capable of retrieving data, initiating workflows, and interfacing with critical business applications. Whether linked to internal knowledge repositories or customer-centric platforms, these agents frequently handle extremely sensitive data. Nevertheless, distinct ownership and visibility of how these permissions are utilized remain significantly inadequate.

This issue arises at a moment when the overall identity landscape already faces considerable pressure. Palo Alto Networks’ 2026 Identity Security Landscape Report revealed that machine identities now exceed human identities by a ratio of 109 to 1 in Australia, with both machine and AI agent identities anticipated to surge in the upcoming year. As organizations expand their AI initiatives, they are adding a vast, intricate layer of non-human users that necessitate the same visibility, governance, and accountability that have traditionally been applied to human employees.

The Broadening Attack Surface

AI agents are not intrinsically risky; the danger arises when organizations assign enterprise-level privileges before implementing enterprise-level controls. Our research shows that Australian organizations estimate around 40% of AI agents and 41% of machine identities already have access to organizational data, including vital business systems.

An AI agent with excessive permissions presents an attractive target for cybercriminals. If breached, manipulated, or misused, it turns into a trusted entryway into the organization, enabling malicious actors to navigate laterally through networks, remove data, or interrupt essential operations.

This issue is compounded by emerging standards like the Model Context Protocol (MCP). While MCP is beneficial for scaling agentic AI by establishing a consistent method for agents to communicate with databases and enterprise applications, it concurrently amplifies the number of credentials, permissions, and trust relations that are active throughout the network.

Each new link between an AI agent and a business system generates an access route that must be protected. As organizations develop these interconnected AI ecosystems, insight into who or what possesses access to critical systems becomes as critical as securing the AI models themselves.

Advancing Governance for the Agentic Age

To reduce these risks, contemporary identity security principles must be broadened to encompass all identity types, including human, machine, and agentic.

This necessitates a thorough strategy: identifying and cataloging all AI identities, implementing lifecycle management, enforcing stringent least-privilege access, and consistently monitoring for unusual activity. It additionally involves ensuring human oversight for compliance and guaranteeing that access can be immediately revoked if an agent is compromised or decommissioned.

As AI agents become deeply integrated into everyday operations, traditional identity tools will become insufficient. Organizations need advanced identity security platforms that extend governance beyond typical human users. The industry is experiencing a profound transformation: transitioning from managing only human access to governing every single identity operating within the enterprise from a centralized control framework.

To assist organizations in navigating this transition, Palo Alto Networks has recently introduced Idira. By merging privileged access management with capabilities for machine and agentic identity security, Idira offers a unified platform to discover, secure, and govern access across all identity types.

AI agents are swiftly becoming the most interconnected and privileged entities within the enterprise. As Australian organizations continue to expand agentic AI, strong governance will shift from being an obstacle to becoming the ultimate facilitator of security, trust, and innovation.

Conclusion

As AI agents become increasingly integrated into enterprise practices, they introduce new challenges for identity management and security. Organizations must tackle the governance of these agents to avert security incidents and maintain compliance. The emergence of AI agents requires a transformation in identity security strategies, with platforms like Palo Alto Networks’ Idira offering the essential tools for managing an array of identity types.

Q: What are AI agents and how are they utilized in organizations?

A: AI agents are software applications that carry out automated functions and interact with data and systems. In organizations, they are employed for customer service, software development, and knowledge management, among various other activities.

Q: Why do AI agents present a security concern?

A: AI agents create a security concern when they are given excessive privileges without adequate controls, rendering them potential targets for attackers aiming to exploit their access to confidential data and systems.

Q: What is the Model Context Protocol (MCP) and what impact does it have on AI agents?

A: The MCP is a protocol that streamlines interactions between AI agents and enterprise applications. While it aids in the scalability of AI deployment, it also complicates the management of credentials and access routes.

Q: How can organizations enhance governance for AI agents?

A: Organizations can strengthen governance by cataloging AI identities, managing their lifecycles, enforcing least-privilege access, and scrutinizing for anomalies, ensuring human oversight and quick response to security incidents.

Q: What is Palo Alto Networks’ Idira, and how does it assist with AI agent governance?

A: Idira is a solution from Palo Alto Networks that merges privileged access management with machine and agentic identity security features, providing a cohesive approach for discovering, securing, and managing access for all identity types.

New Cybersecurity Leader Named at JB Hi-Fi Group


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

New Cyber Security Leader at JB Hi-Fi Group

Quick Overview

  • Kanchana Devi has been appointed as the leader of group cyber security at JB Hi-Fi Group.
  • Devi has a robust background with the University of Melbourne and Accenture.
  • Devi’s goal is to improve cyber resilience and foster secure innovation.
  • JB Hi-Fi Group comprises JB Hi-Fi, The Good Guys, and e&s.
  • Former cyber security head Daniel Eastley is now the CISO at the Country Fire Authority in Victoria.

Overview

In a calculated initiative to strengthen its cybersecurity framework, JB Hi-Fi Group has revealed the appointment of Kanchana Devi as the leader of group cyber security. This follows the exit of Daniel Eastley in April, who has transitioned to a key position at the Country Fire Authority in Victoria.

Kanchana Devi’s Path

Kanchana Devi shared her excitement about joining JB Hi-Fi Group in her latest LinkedIn update. She is keen to partner with diverse teams within the group to boost cyber resilience and secure business functions, while also promoting safe innovation in the contemporary digital landscape.

Devi’s considerable experience encompasses her recent position at the University of Melbourne and a noteworthy 13-year tenure at Accenture, where she refined her skills in cyber security and digital transformation.

Retail Footprint of JB Hi-Fi Group

JB Hi-Fi Group is a prominent name in the retail domain, featuring well-known brands like JB Hi-Fi, The Good Guys, and e&s. The group’s dedication to enhancing its cybersecurity measures is underscored by Devi’s appointment, with the aim of safeguarding their extensive customer base and business operations.

New Position for Daniel Eastley

Daniel Eastley, who previously occupied a leadership role at JB Hi-Fi Group, now assumes the role of Chief Information Security Officer (CISO) at the Country Fire Authority in Victoria. His time at the Australian Red Cross Lifeblood equipped him with invaluable insights into infrastructure and security, which he now applies in the fire authority.

New cyber security leader announced by JB Hi-Fi Group

Conclusion

Kanchana Devi’s appointment as head of group cyber security at JB Hi-Fi Group signifies an important advancement in reinforcing the company’s cyber resilience. Her extensive background from earlier roles and her vision for secure innovation are in line with the group’s goals of protecting its operations and customer information.

Q: Who is the newly appointed head of group cyber security at JB Hi-Fi Group?

A: Kanchana Devi has taken on the role of the new head of group cyber security.

Q: What expertise does Kanchana Devi bring to JB Hi-Fi Group?

A: Devi brings extensive expertise stemming from her positions at the University of Melbourne and Accenture.

Q: Which brands are part of the JB Hi-Fi Group?

A: The JB Hi-Fi Group consists of JB Hi-Fi, The Good Guys, and e&s.

Q: What is Daniel Eastley’s new position following his departure from JB Hi-Fi Group?

A: Daniel Eastley is now the Chief Information Security Officer at the Country Fire Authority in Victoria.

Alinta Energy Implements State-of-the-Art AI for Improved Executive Insights


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Alinta Energy’s AI-Driven System for Executive Decision Support

Brief Overview

  • Alinta Energy has introduced AISE, a system using AI for executive insights.
  • AISE links executives to data and documents, improving decision processes.
  • The system was created in partnership with Databricks.
  • AISE analyzes 500 data metrics and more than 9000 documents.
  • Each insight features a confidence score for better guidance.
  • AISE is fully implemented and growing within Alinta Energy.

Overview of Alinta Energy’s AI Project

Alinta Energy, a prominent electricity generator and retailer, has rolled out an advanced AI system intended to aid its executive team in making well-informed choices. This initiative signifies a substantial leap in the firm’s application of technology to optimize and enhance strategic decision-making procedures.

The Alinta Intelligent Strategic Engine (AISE)

Launched at the Databricks’ Data + AI Summit in the U.S., the Alinta Intelligent Strategic Engine, known as AISE, is the result of a joint effort between Alinta’s CEO and CIO. As stated by Brad Walker, the general manager of data and AI, AISE was developed within a four-week timeframe, utilizing around 70 person-days of labor.

Capabilities of the System

AISE combines 500 structured data metrics and over 9000 documents, including board papers and strategic presentations. The system uses a supervising agent to interpret executive requests and present relevant insights, each paired with a confidence score to guide decision-making.

AISE’s Influence on Decision-Making

By offering a confidence score, AISE assists executives in assessing the reliability of the insights gathered. This functionality is vital in ensuring decisions are rooted in robust data, minimizing risks associated with strategic initiatives. The system is structured to help executives make decisions with varying degrees of certainty, from highly confident to more cautious insights.

Upcoming Developments

AISE is presently in active use, with ambitions to broaden its functionality across Alinta Energy’s diverse business divisions. This ongoing enhancement aims to deepen the integration of AI within the company’s operations, solidifying its commitment to utilizing technology for business advancements.

Conclusion

The implementation of the AISE system by Alinta Energy signifies a crucial stride towards embedding AI in executive decision-making. By leveraging data-driven insights, the organization positions itself at the forefront of technological progress in the energy industry.

Questions & Answers

Q: What does AISE stand for?

A: AISE refers to Alinta Intelligent Strategic Engine, an AI system tailored to provide data-driven insights for executive decision-making.

Q: In what way does AISE operate?

A: AISE employs a multi-agent framework to process data metrics and documents, delivering insights with a confidence score to assist executive decisions.

Q: What advantages does AISE offer Alinta Energy?

A: AISE advances decision-making by delivering trustworthy insights, mitigating risks, and enhancing the efficiency of strategic planning.

Q: Is AISE exclusive to Alinta Energy?

A: At present, AISE has been specifically designed for Alinta Energy, though similar systems might be investigated by other organizations in the future.

Q: How was AISE created?

A: AISE was developed in collaboration with Databricks over a four-week period, involving approximately 70 person-days of effort.

Q: What future enhancements are anticipated for AISE?

A: Alinta Energy intends to broaden AISE’s functionalities throughout its business units, further integrating AI into its operations.

Medical Clinic Consortium Partnered Health Experiences Data Breach


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Partnered Health Data Breach: Essential Information

Brief Overview

  • Data breach at Partnered Health impacts 21 clinics.
  • Confidential personal and medical information has been compromised.
  • Legal restraining order secured to avoid data exploitation.
  • Possible scam risks targeting those impacted.
  • Bupa intends to purchase Partnered Health for $450 million.

Details of the Breach

On June 23, Partnered Health, based in Adelaide, disclosed a major data breach involving 21 of its general practitioner clinics. The incident led to the unauthorized access of sensitive personal and medical details, including names, addresses, contact numbers, Medicare, private health insurance, and Veteran Card identifiers.

Incident of data breach at Partnered Health clinic

Medical data and treatment records were allegedly accessed during the breach. Nevertheless, Partnered Health has not provided technical details about the attack or the complete scope of the compromised data.

Legal Actions and Security Protocols

Following the breach, Partnered Health secured a court injunction from the Supreme Court of New South Wales to block the use or release of the stolen data. The organization has also cautioned its customers to remain alert to potential scams arising from the inappropriate use of their personal information.

Corporate News

In light of the data breach, health insurance and medical service operator Bupa has announced plans to acquire Partnered Health for $450 million. This acquisition is awaiting approval from the Australian Competition and Consumer Commission and the Foreign Investment Review Board.

Conclusion

Partnered Health has faced a significant data breach impacting 21 clinics, with personal and medical information being compromised. Legal measures are underway to deter the misuse of data, while Bupa is set to make a substantial acquisition of the organization.

Questions & Answers

Q: What type of information was compromised in the breach?

A: The breach involved names, addresses, contact numbers, Medicare, private health insurance, Veteran Card identifiers, and medical data.

Q: How many clinics were impacted by the data breach?

A: The breach affected a total of 21 clinics.

Q: What legal actions has Partnered Health implemented?

A: Partnered Health has secured an injunction from the Supreme Court of New South Wales to prevent the misuse of the stolen information.

Q: What should individuals affected be mindful of?

A: Affected individuals should be wary of scams that might leverage their compromised data.

Q: Who is in the process of acquiring Partnered Health?

A: Bupa is in the process of acquiring Partnered Health for $450 million, pending regulatory approvals.

Hard lines, wider nets: the Indo-Pacific week in seven moves


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Taiwan moved missiles, ASEAN reopened a door to Myanmar, Beijing built an AI institution, and the South China Sea argument turned ten without getting any safer.

Review: Razer Seiren V3 Pro – The Premier Hybrid Microphone for Streamers, Creators, and Presenters


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Concise Overview

  • Razer Seiren V3 Pro caters to creators, streamers, and presenters.
  • Features hybrid connectivity through USB-C and XLR ports.
  • Equipped with an integrated shock absorber and pop filter.
  • Showcases Razer Chroma RGB lighting for visual feedback.
  • Supports sophisticated audio processing via Razer Synapse software.
  • Retailing at AU$429.95, perfect for both novices and experts.

A Stunning, Practical Design

The Razer Seiren V3 Pro captivates immediately with its robust construction, made from premium zinc unibody. This weight guarantees stability when paired with a boom arm, preventing issues commonly seen with lighter microphones.

Unboxing Razer Seiren V3 Pro – The Complete Package

The package contains the microphone, a mini adjustable arm mount, a solid base, a cable, stickers, and an information booklet. The mic’s onboard bracket accommodates a standard thread for seamless transitions to a boom arm.

Subtle Features That Truly Perform

Razer’s aesthetics combine sleek professionalism with its distinctive flair. The built-in cover serves as a shock absorber and pop filter, removing the necessity for an external foam sock. The outer filter cover can be detached for a minimalist look.

Razer Seiren V3 Pro – Sleek and Subtle Design

The microphone incorporates Razer Chroma RGB lighting, featuring a discreet light ring at the base that changes color based on gain levels, providing real-time visual cues. It turns red when muted, clearly indicating the status.

Intelligent, Tactile Controls

The Razer Seiren V3 Pro shines in usability with a tap-to-mute sensor on top, removing the noise of physical button presses. A dedicated gain dial and headphone jack for zero-latency monitoring can be found at the bottom.

Smart Controls on Razer Seiren V3 Pro

Adaptability: The Power of Dual USB-C & XLR

The dual connectivity of USB-C and XLR enables the microphone to evolve with its user. The included USB cable comes with a USB-A to USB-C adapter for straightforward plug-and-play setup. For the best outcomes, the XLR connection is advisable.

Hybrid Connectivity of Razer Seiren V3 Pro

Utilizing both USB and XLR connections unlocks the microphone’s full capability, with USB powering the audio processing and RGB lighting. The setup requires two USB slots, one for the microphone and another for the mixer when using XLR.

Clear, Sharp, Studio-Quality Sound

The Razer Seiren V3 Pro provides outstanding audio quality with its 30mm dynamic capsule, delivering a warm, rich broadcast tone. It effectively isolates voice and diminishes background noise, reducing post-production work.

Razer Synapse Software with Razer Seiren V3 Pro

Razer Synapse software elevates the user experience with features like 32-Bit Float Support, AI noise reduction, and onboard DSP effects, further enhancing sound quality and performance.

Concluding Thoughts

The Razer Seiren V3 Pro stands as a versatile microphone suited for both beginners and professionals. With its USB and XLR functionalities, sturdy build, and advanced audio features, it presents remarkable value at AU$429.95.

Advanced Features of Razer Seiren V3 Pro in Synapse

Its elegant design, coupled with exceptional audio performance, makes it a worthwhile investment for anyone looking to elevate their audio setup.

Overview

The Razer Seiren V3 Pro is a remarkable addition to Razer’s offerings, tailored for creators, streamers, and presenters. Its hybrid connectivity, sturdy design, and superior sound quality render it ideal for a variety of professional uses. With advanced features available through Razer Synapse, it offers versatility and control, ensuring users can achieve broadcast-quality audio effortlessly.

Q: What makes the Razer Seiren V3 Pro appropriate for both novices and experts?

A: Its dual USB-C and XLR connectivity enables easy setup and scalability, making it perfect for beginners starting with USB and professionals moving to XLR setups.

Q: How does the Razer Seiren V3 Pro manage background noise?

A: The microphone boasts a dynamic capsule that efficiently isolates voice and minimizes background noise, supplemented by DSP features available through Razer Synapse.

Q: Is the Razer Seiren V3 Pro compatible with both PC and Mac?

A: Yes, it is compatible with both PC and Mac systems, due to its USB-C connection and the included USB-A to USB-C adapter.

Q: What advantages does using Razer Synapse with the microphone provide?

A: Razer Synapse grants access to advanced audio processing features including 32-Bit Float Support, AI noise reduction, and various DSP effects, enhancing audio quality and user control.

Q: Does the Razer Seiren V3 Pro come with an XLR cable?

A: No, the XLR cable is not included and must be purchased separately if you choose to use an XLR setup.

Q: How does the Razer Chroma RGB lighting improve the user experience?

A: The RGB lighting provides real-time visual indications of gain levels and mute status, offering an intuitive way to oversee audio settings during usage.

Colonial First State Names New Executive for Data and AI Group


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Colonial First State Appoints New Executive for Data and AI

Overview

  • Colonial First State designates Sid Baidwan as the Group Executive of Data and AI.
  • Baidwan formerly worked as Chief AI Officer at Smartgroup and directed AI transitions at Suncorp.
  • His responsibilities will center on advancing AI and data strategy for the benefit of members, advisers, and employees.
  • Australia’s superannuation framework is on track to become the second-largest globally.
  • Baidwan intends to utilize AI to enhance wealth accumulation and retirement transitions.

Sid Baidwan’s Role

Colonial First State names new executive for data and AI

Image credit: LinkedIn.

Colonial First State has named Sid Baidwan as its Group Executive of Data and AI. Baidwan joined the company in June, bringing in experience from his prior position as Chief AI Officer at Smartgroup and having undertaken AI transformation at Suncorp.

Leading AI Initiatives at CFS

Baidwan’s appointment was initially alluded to in a LinkedIn update in May and has now been officially confirmed. A representative from Colonial First State (CFS) mentioned that Baidwan is anticipated to lead the organization’s AI and data strategy, aiming to convert AI capabilities into real value for members, advisers, and employees.

With extensive knowledge in both technical engineering and commercial strategy, Baidwan’s position is viewed as critical to enhancing the organization’s technological prowess. His leadership is expected to foster innovation within Australia’s expanding superannuation industry.

Overview of Australia’s Superannuation

In a LinkedIn message, Baidwan conveyed his enthusiasm for spearheading AI and data projects at CFS. He underscored the forthcoming expansion of Australia’s superannuation system, which is expected to grow into the second-largest retirement savings reservoir worldwide. This expansion, along with an ageing demographic, offers both challenges and prospects that Baidwan aims to tackle through AI-focused innovations.

Data and AI are anticipated to play an essential part in transforming the superannuation structure, facilitating enhanced services for advisers and clients, and promoting wealth growth along with secure retirement transitions.

Conclusion

With Sid Baidwan at the forefront, Colonial First State stands ready to harness AI and data strategies to improve its services and respond to the increasing demands of Australia’s superannuation landscape. His guidance signifies a major advance towards innovative solutions that aim to better meet the needs of advisers and clients while ensuring a smooth transition to retirement.

Q&A

Q: What role has Sid Baidwan been appointed to at Colonial First State?

A: Sid Baidwan has been appointed as the Group Executive of Data and AI at Colonial First State.

Q: What prior positions did Baidwan hold?

A: Baidwan was the Chief AI Officer at Smartgroup and also oversaw AI changes at Suncorp.

Q: What will be Baidwan’s primary objective in his new position?

A: His primary objective will be to enhance Colonial First State’s AI and data strategy to generate value for members, advisers, and employees.

Q: Why is the data and AI role important for CFS?

A: Data and AI are vital for advancing the superannuation system and improving service, wealth growth, and retirement security.

Q: How is Australia’s superannuation system expected to evolve?

A: It is anticipated to become the globe’s second-largest retirement savings pool, offering avenues for innovation.

Q: What opportunities does Baidwan perceive in the superannuation field?

A: Baidwan sees opportunities for innovation through AI to enhance support for advisers and clients and to facilitate wealth growth and secure retirement transitions.

Notorious 1990s Hacker Taken into Custody for €100 Million Monthly Fraud Operation


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Infamous 1990s Hacker Apprehended in Enormous Fraud Scheme

Brief Overview

  • Ehud Tenenbaum, aka The Analyzer, indicted for a €100 million-a-month scam.
  • Operation managed 20 call centers and hired over 700 staff.
  • Operation Sunflower utilized celebrity endorsements in deceptive advertisements.
  • Tenenbaum has a track record of prominent cyber offenses dating back to the late 1990s.
  • Five more suspects detained across Europe.

The Capture of Ehud Tenenbaum

Infamous 1990s hacker arrested over €100 million-a-month fraud network

The infamous hacker of the 1990s, Ehud Tenenbaum, also referred to as The Analyzer, was taken into custody by Dutch law enforcement. Tenenbaum, aged 46, is accused of being involved in a sprawling investment fraud operation that reportedly yielded over €100 million (A$164 million) every month. The scheme incorporated 20 call centers and employed more than 700 individuals.

Operation Sunflower Revealed

Known as Operation Sunflower, the fraud ring deployed misleading advertisements featuring prominent Dutch and Belgian personalities to exploit victims. Most victims lost over €10,000 ($16,371) each. The deceitful operation ran for a minimum of four years before it was dismantled in July.

International Arrests and Extradition

Tenenbaum was apprehended on May 26 at a Polish airport upon arrival from Dubai and was later extradited to the Netherlands. Alongside Tenenbaum, five other individuals were arrested in Poland, Cyprus, Greece, and Belgium, with Dutch officials indicating there may be additional arrests.

A Legacy of Cyber Offenses

Early Hacking Ventures

Tenenbaum’s cybercriminal journey commenced in the late 1990s. In 2001, he confessed to infiltrating systems belonging to the US Air Force, Navy, Pentagon, NASA, Massachusetts Institute of Technology (MIT), and Israel’s Knesset. The FBI’s Solar Sunrise investigation into these incursions even reached the White House, initially raising fears of state-sponsored cyber attacks.

Credit Card Fraud and Financial Crimes

In 2008, Tenenbaum faced allegations in Canada and the US connected to a credit card fraud operation totaling US$1.5 million ($2.15 million). He accepted a plea deal resulting in a time-served sentence, a US$503,000 fine, and three years of probation after his extradition to the US.

In 2013, Tenenbaum was arrested again in Israel for suspected money laundering, with large amounts of foreign currency being funneled into Israel from known criminals. The resolution of this legal situation remains uncertain.

Conclusion

Ehud Tenenbaum, well-known for his hacking activities in the 1990s, has been arrested for participating in a vast fraud operation producing over €100 million monthly. Recognized for his expertise in cyber crime, Tenenbaum’s background includes breaching significant governmental systems, as well as engagement in credit card fraud and money laundering.

Q: Who is Ehud Tenenbaum?

A: Ehud Tenenbaum, known as The Analyzer, is a prominent hacker from the 1990s, recently apprehended for his role in a large-scale fraud operation.

Q: What was Operation Sunflower?

A: Operation Sunflower was a fraudulent scheme that operated 20 call centers and hired over 700 staff, employing fake celebrity endorsements to deceive victims out of substantial sums of money.

Q: What other offenses has Tenenbaum been associated with?

A: Tenenbaum has a background of cyber offenses, including hacking US government systems in the late 1990s and facing credit card fraud charges in 2008.

Q: How was Tenenbaum captured?

A: Tenenbaum was apprehended at a Polish airport after he arrived from Dubai and was extradited to the Netherlands as part of a wider investigation by Dutch authorities.

Q: What legal actions have been taken against Tenenbaum in the past?

A: Tenenbaum has encountered several legal actions, including an 18-month sentence for hacking, a plea agreement for credit card fraud, and an uncertain resolution for a money laundering accusation in 2013.

Telstra’s Network Affected by Unlogged Time Change


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Quick Overview

  • Telstra is experiencing a nationwide mobile service disruption due to unlogged configuration alterations and obsolete firmware.
  • An undocumented modification raised a server’s time authority status, resulting in interruptions.
  • The outdated GPS card reset the network’s clock to 2006, causing errors in customer devices.
  • Telstra has received 8,000 requests for compensation, with $100,000 already disbursed.
  • Telstra has partnered with Technology Audit Partners for a comprehensive investigation.

Understanding the Outage

The recent mobile network outage at Telstra is linked to a combination of an unlogged configuration modification and an overlooked firmware update on its Symmetricom SSU-2000 Network Time Synchronisation System. This detail emerged during a senate inquiry, revealing additional complexity to the initial assessment of the problem.

Telstra network affected by a timekeeping malfunction

Telstra initially identified a node tasked with timekeeping in its mobile network as the source of the disruption. Accurate timekeeping is vital for mobile networks, structured into various layers or “stratums.” Telstra utilizes the Network Time Protocol (NTP), relying on atomic clocks at Stratum 0 as the primary time source.

Clarifying the Timekeeping Issue

In Telstra’s standard network configuration, the SSU-2000 occupies Stratum 3 in the time hierarchy. However, a failure to connect with Stratum 2 servers led to an undocumented rise to Stratum 1. This adjustment permitted the unit to rely on its onboard GPS card for timekeeping, which had not been updated due to its prior inactivity.

Public records indicate that the SSU-2000 is roughly 24 years old, with GPS cards using a legacy time counter that resets every 1024 weeks. This caused the internal clock to revert to November 2006, resulting in devices showing incorrect dates and potentially interfering with secure communications.

Compensation and Inquiry

Michael Ackland, Telstra’s CFO, mentioned that the company has handled about 8,000 compensation requests, with $100,000 already compensated. Bigger claims are still being evaluated. CEO Vicki Brady confirmed the engagement of Technology Audit Partners to carry out a thorough examination of the incident.

Conclusion

The Telstra network disruption highlights the crucial need for maintaining up-to-date system configurations and documentation. As Telstra manages customer compensations and ongoing investigations, this event serves as a reminder of the complex interdependencies in telecommunications networks.

Common Questions

Q: What led to the Telstra network disruption?

A: The disruption resulted from an unlogged configuration change coupled with an outdated firmware update on a timekeeping unit.

Q: In what way did the timekeeping problem impact customers?

A: Customers faced incorrect device times, which could have disrupted secure communications and network access.

Q: What actions is Telstra taking to resolve the issue?

A: Telstra has brought in Technology Audit Partners for a comprehensive investigation and is processing compensation claims from those affected.

Q: How much compensation has Telstra disbursed to date?

A: Telstra has issued around $100,000 in compensation, with larger claims still under consideration.

Q: What function does the SSU-2000 serve in Telstra’s network?

A: The SSU-2000 is integral to Telstra’s timekeeping framework, typically situated at Stratum 3 in the network time structure.

Q: Why was the GPS card not updated?

A: The GPS card was not updated because it was not in active use; its significance grew after the server’s undocumented rise to Stratum 1.

Qantas Avoids Formal OAIC Inquiry Regarding 2025 Vishing Event


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Qantas Avoids OAIC Investigation Following 2025 Vishing Breach

Brief Overview

  • Qantas will not undergo an official OAIC inquiry regarding the June 2025 data breach.
  • Initial investigations by the OAIC revealed that Qantas implemented sufficient measures to handle the breach.
  • The breach impacted the personal and frequent flyer details of 5.12 million Australians.
  • The data was compromised via a social engineering method identified as vishing.
  • The OAIC may still choose to initiate a formal investigation later on.

Qantas Tackles Data Breach Issues

Qantas avoids OAIC inquiry for 2025 data breach

Summary of the June 2025 Breach

In June 2025, Qantas faced a major data breach that unveiled the personal and frequent flyer data of roughly 5.12 million Australians. This incident was linked to cyber attacks from groups referred to as Scattered Spider, Lapsus$, and ShinyHunters. The event raised alarms regarding the airline’s data protection protocols.

OAIC’s Initial Findings

The Office of the Australian Information Commissioner (OAIC), under the leadership of Privacy Commissioner Carly Kind, carried out initial inquiries into the breach. They assessed whether Qantas contravened Australian Privacy Principles 1, 8, and 11, which relate to the handling, overseas disclosure, and security of personal data. The findings suggested that Qantas had implemented proper measures to manage the breach, including containing the issue and swiftly notifying the public.

Understanding the Vishing Technique

The breach was carried out utilizing a technique known as vishing, a variety of social engineering where perpetrators mimic trusted organizations to gather information. In this scenario, the attacker impersonated “Qantas IT help” and deceived a call center representative into employing a customized version of Salesforce’s Data Loader tool, enabling the mass extraction of customer data.

Future Considerations for Qantas

Although the OAIC has opted not to initiate a formal investigation at this time, this determination is not definitive. The regulatory body holds the authority to pursue a formal inquiry should new information emerge or if Qantas does not maintain adequate data protection standards going forward. This situation underscores the persistent cyber threats encountered by organizations and the critical need for strong security protocols.

Conclusion

Qantas has evaded an immediate formal investigation from the OAIC concerning the data breach in June 2025, which affected millions of Australians. The preliminary investigations by the OAIC established that Qantas handled the breach properly, though the possibility of future inquiries persists. This episode emphasizes the threats posed by vishing attacks and the importance of rigorous data protection measures within the aviation sector.

Q: What triggered the data breach at Qantas?

A: The breach was instigated by a vishing attack, where an adversary impersonated “Qantas IT help” and manipulated a call center agent into utilizing a tailored Salesforce tool for data extraction.

Q: How many Australians were impacted by the Qantas data breach?

A: Approximately 5.12 million Australians had their personal and frequent flyer information compromised during the breach.

Q: Did the OAIC find Qantas guilty of violating any privacy principles?

A: The OAIC’s initial inquiries did not find Qantas in violation of Australian Privacy Principles 1, 8, and 11, as the airline took measures to manage and contain the breach.

Q: Is the OAIC able to conduct a formal investigation in the future?

A: Yes, the OAIC maintains the authority to initiate a formal investigation if deemed necessary, based on new information or future compliance concerns.

Q: How did Qantas respond to the data breach?

A: Qantas acted swiftly to contain the breach and communicated the incident to the public, thereby reducing potential risks to their customers.

Q: What is vishing and why is it a threat?

A: Vishing is a social engineering tactic where assailants leverage voice communication to impersonate trusted figures and acquire sensitive information. It is a threat because it manipulates human trust, potentially resulting in major data breaches.