Matthew Miller, Author at Techbest - Top Tech Reviews In Australia - Page 4 of 187

Researcher Cautions: Neglected QR Code Subdomains Prone to Takeover


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Abandoned QR Code Subdomains: A Security Concern

Brief Overview

  • Neglected QR code subdomains are susceptible to hijacking by malicious actors.
  • Weakness identified in custom domain functionalities of QR code providers.
  • QR Tiger’s “Own Short Domain” feature misused in the investigation.
  • Businesses from multiple industries were found at risk.
  • Immediate action required for better DNS record administration.

Grasping the QR Code Vulnerability

Security expert Farzan Karimi has exposed a major vulnerability impacting QR code subdomains, demonstrating how attackers can manipulate custom domain functionalities to send users to harmful websites. This dilemma affects organizations utilizing QR codes as branded URLs, putting them at significant security risk.

Neglected QR code subdomains vulnerable to hijacking

The Study Results

Karimi’s research used QR Tiger’s “Own Short Domain” functionality, which permits organizations to generate custom QR code web addresses. Unfortunately, a flaw in the system’s validation allows any QR Tiger user to take control of an unassigned subdomain, potentially leading legitimate users to malicious pages.

Consequences for Enterprises

The investigation uncovered numerous vulnerable organizations in sectors like manufacturing, healthcare, financial services, and technology. This vulnerability emphasizes the necessity for proper DNS record management, as outdated entries leave firms open to such hijacking threats.

Recommended Countermeasures

To address this vulnerability, Karimi proposes adopting a unique ownership token in a TXT record, a strategy already prevalent among SaaS solutions. This measure would significantly enhance the security of custom QR code domains.

Final Thoughts

While the method of attack, referred to as “QR Jacking,” uncovers substantial security weaknesses, it also serves as a crucial reminder for businesses to uphold strict DNS record management. Organizations must stay alert to defend their digital assets and maintain customer confidence.

Overview

Karimi’s investigation brings to light a vital vulnerability in QR code subdomains, enabling attackers to redirect users to harmful sites. The problem, which arises from inadequate DNS record management, impacts many businesses, leading to a demand for enhanced security protocols.

FAQs

Q: What makes QR code subdomains vulnerable?

A: The vulnerability is caused by issues in the custom domain features of QR code providers, allowing for subdomain hijacking in cases of poor DNS record management.

Q: How does the QR Jacking method function?

A: Attackers can seize unregistered subdomains via QR Tiger’s “Own Short Domain” feature, redirecting users scanning the QR code to harmful websites.

Q: Which industries are impacted by this vulnerability?

A: The vulnerability affects businesses across manufacturing, healthcare, financial services, and technology sectors.

Q: What actions can companies take to reduce this risk?

A: Companies should implement unique ownership tokens in TXT records and ensure active management of DNS records to thwart hijacking attempts.

Q: How fast can an attacker takeover a QR code subdomain?

A: The study indicates that the entire takeover process can be completed in less than one minute.

Q: Is this vulnerability limited to QR Tiger?

A: Although QR Tiger was featured in the research, similar vulnerabilities may be present in other QR code providers.

Meta Unveils Muse Charm: A Small Gadget for Managing Your AI Assistant


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Muse Charm: Transforming AI Interaction

Quick Overview

  • Meta presents the Muse Charm, a compact gadget for AI engagement.
  • Muse is capable of executing multi-step digital tasks on its own.
  • The Charm features a tactile, screen-less interface.
  • Extensive software partnerships augment Muse’s functionalities.
  • Now available in North America, while the Australian launch is forthcoming.
Meta's Muse Charm device for AI engagement

What is Meta Muse and its significance?

Meta’s Muse goes beyond the conventional chatbot by providing a personal AI assistant capable of independently performing intricate digital tasks. Unlike traditional text-driven AI, Muse executes real-life computing functions, including web exploration and email organization, all leveraging its cloud-based Muse Spark system.

Engaging through specialized hardware instead of a screen

The Muse Charm pioneers a fresh method for AI interaction. This portable device, featuring a compact display, dual cameras, and biometric verification, promotes voice-first interaction, eliminating the visual distractions typically associated with smartphones.

Extensive ecosystem connectors and its own email account

Muse’s capabilities are reinforced by a wide range of software connections. Through collaborations with leading retail and productivity platforms, Muse can manage tasks from shopping to organizing meetings, all via a specific email address.

Making the cloud agent more accessible

Meta’s approach of providing a free tier for Muse’s cloud-based features allows for wider access to autonomous agents. This approach contrasts with competitors who usually reserve such functionalities for paid tiers.

The wait for Australia

Even with its promising technology, Australian users must remain patient for Muse’s domestic release. Currently accessible in North America, the Muse Charm’s launch in Australia depends on compliance with regulations and compatibility requirements.

Conclusion

Meta’s Muse Charm marks a change in AI interaction, delivering a simplified, hardware-oriented method for managing digital tasks. While North America has early access, Australian consumers look forward to its debut, likely priced between A$150 to A$200.

Q: What is the Muse Charm?

A: The Muse Charm is a pocket-sized device from Meta created to enable direct interaction with its AI assistant, Muse, without the necessity for a smartphone.

Q: How is Muse different from other AI systems?

A: Muse can carry out sophisticated digital tasks independently, surpassing the abilities of conventional text-based AI systems, utilizing its cloud-based Muse Spark architecture.

Q: What are the primary features of the Muse Charm?

A: The Muse Charm includes a small display, dual cameras, a fingerprint scanner, and standalone cellular connectivity for an enhanced AI interaction journey.

Q: What integrations does Muse support?

A: Muse connects with leading retail platforms such as Shopify, Walmart, and travel services like Expedia, thereby boosting its task execution abilities.

Q: Is the Muse Charm sold in Australia?

A: At present, the Muse Charm is offered in North America, with its availability in Australia dependent on the completion of regulatory and compatibility assessments.

Q: How is Meta promoting accessibility for Muse?

A: Meta provides a free tier for Muse’s cloud services, enhancing accessibility for everyday users to autonomous agents.

AGL Creates Advanced AI Agent to Improve Security Architecture Assessments


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Brief Overview

  • AGL has created an AI agent to facilitate the automation of preliminary drafts for security architecture review documents.
  • The AI agent utilizes internal Confluence documents and PDFs, employing threat modeling frameworks.
  • AGL is assessing AI features in current vendor tools against its risk criteria, concentrating on model implementation, data storage, processing, and sovereignty.
AGL creates AI for security architecture evaluations

Image credit: AGL

AGL’s Innovative AI Project

AGL has advanced in technological development by creating an AI agent that streamlines the security architecture review process. This AI agent is programmed to automatically draft initial versions of review documents, thus expediting the workflow for the security architecture team. This initiative was presented by Yaso Addanki, Head of Architecture for Security and Corporate Technology, during an IBM session at Gartner’s IT Symposium/Xpo.

Functionality of the AI Agent

The AI agent harnesses internal resources like Confluence documents and PDFs, utilizing threat modeling frameworks to formulate its outputs. This technology assists security architects in rapidly reviewing, refreshing, and providing essential feedback to business units, thus improving project implementation timelines. The automation introduced by the AI agent aims to simplify processes, allowing the team to concentrate more on strategic initiatives.

Prospective Developments for Solution Architects

While currently utilized by the security architecture team, there are intentions to broaden the tool’s application to solution architects. This initiative seeks to “shift left,” enabling solution architects to incorporate necessary security controls earlier in the development cycle, thereby embedding security more intrinsically into the project lifecycle.

Thorough AI Risk Evaluations

AGL is adopting a cautious stance towards AI integration, examining the incorporation of AI features within existing vendor tools. The company is carefully evaluating these tools against its risk tolerance and security benchmarks. Important factors include understanding where AI models are deployed, how data is managed and processed, and addressing data sovereignty issues. This thorough evaluation guarantees that AI tools conform to AGL’s rigorous security and risk management standards.

Conclusion

AGL’s introduction of an AI agent signifies a notable advancement in improving their security architecture review workflow. By automating initial drafts, the AI agent enhances efficiency and allows security teams to prioritize more strategic tasks. The company’s proactive approach to AI integration and risk evaluation underscores its dedication to incorporating state-of-the-art technology while upholding stringent security protocols.

Q&A Segment

Q: What is the main role of AGL’s AI agent?

A: Its main role is to automate the generation of initial drafts for security architecture review documents, optimizing the review process.

Q: In what way does the AI agent create its outputs?

A: The agent utilizes internal Confluence documents and PDFs, employing threat modeling frameworks to formulate its outputs.

Q: Who is currently utilizing the AI agent?

A: It is presently employed by AGL’s security architecture team to enhance their workflow productivity.

Q: Are there future plans regarding the AI agent?

A: Yes, plans exist to expand its application to solution architects to facilitate the integration of security controls earlier in the project lifecycle.

Q: How is AGL evaluating the risks of incorporating AI features into existing tools?

A: AGL is scrutinizing these tools against its risk appetite, taking into account aspects such as model deployment, data management, and processing, alongside data sovereignty considerations.

Q: Why is grasping data sovereignty critical for AGL?

A: Understanding data sovereignty is vital to ensure adherence to regulations and to safeguard data integrity and privacy.

Vocus Launches Aspirational Fibre Link Initiative Bridging Brisbane and Darwin


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Quick Read

  • Vocus unveils a fresh fibre cable initiative interlinking Brisbane, Townsville, and Darwin.
  • This venture is integrated within the Australian Digital Infrastructure Platform (ADIP) and covers nearly 4000km.
  • Expected to wrap up by 2030, this follows the Sydney-Melbourne connection.
  • Queensland and the Northern Territory are set to emerge as vital data centre hubs.
  • The project seeks to improve connectivity between Australia, Asia, and the United States.

Vocus’ Aspiring Fibre Connection Venture

Vocus is initiating an innovative scheme to create a long-distance fibre cable linking Brisbane, Townsville, and Darwin. This project forms a crucial part of the Australian Digital Infrastructure Platform (ADIP), aimed at enhancing Australia’s digital connectivity.

Vocus plans fibre connection between Brisbane and Darwin

Image credit: Vocus

Growth of the Australian Digital Infrastructure Platform

The fibre connection, spanning around 4000km, will connect to the current Sydney-Melbourne line. UGL has been selected as the development partner for this first segment. The new extension highlights Vocus’ resolve to improve digital infrastructure throughout Australia.

Significance of the Connection

This initiative places Queensland and the Northern Territory as central data centre locations. These areas are expected to act as portals, enhancing Australia’s ties with Asia and the United States. The connection is predicted to cater to the growing demand for network connectivity fueled by AI and digital services.

Schedule and Future Prospects

Vocus has started route planning, technical design, and client engagement processes. The fibre connection between Brisbane, Townsville, and Darwin is anticipated to be active by 2030. This timeline coincides with the broader ambitions of the Australian Digital Infrastructure Platform.

Conclusion

Vocus’ upcoming fibre connection represents a revolutionary project that will strengthen digital connectivity among key Australian cities and international markets. By 2030, this initiative will establish Northern Australia as an influential entity in the global data exchange framework.

Q: What is the aim of Vocus’ new fibre connection project?

A: The project seeks to enhance digital connectivity throughout Australia, linking Brisbane, Townsville, and Darwin, and associating Australia with Asia and the United States.

Q: What does the Australian Digital Infrastructure Platform entail?

A: The Australian Digital Infrastructure Platform (ADIP) is a Vocus initiative aimed at broadening and improving Australia’s digital infrastructure through projects like the fibre connection.

Q: When will the fibre connection be operational?

A: The fibre connection is anticipated to be service-ready by 2030.

Q: What impact will this project have on the area?

A: The project will position Queensland and the Northern Territory as pivotal data centre zones, facilitating enhanced data exchanges with Asia and the United States.

Q: Who is the development partner for the fibre connection?

A: UGL is the designated development partner for the initial Sydney-Melbourne link, part of the wider ADIP initiative.

Q: Which sectors will benefit from the fibre connection?

A: Sectors that depend on AI, cloud computing, and digital services will gain from the improved connectivity offered by the fibre connection.

State of Security Breakfast Event Reaches Sydney


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Quick Overview

  • The State of Security Breakfast Event is set to take place in Sydney on November 25.
  • The emphasis will be on Zero Trust, Data Security & AI Governance, along with Centralising Security Information.
  • Leading security and tech executives will engage in discussions about significant cyber security issues.
  • Participants will have chances for discussions and networking.
  • Top industry speakers and panels will be featured at the event.

Cyber Security Issues in Today’s Businesses

The technology environment is swiftly changing, and cyber security teams face increasingly intricate setups. The rise in data volume, broader attack surfaces, and the quick adoption of AI technologies are transforming security strategies in organizations. As companies evolve, security personnel are responsible for strengthening identity and access controls, protecting sensitive information, and enhancing visibility across various systems.

State of Security Breakfast Event in Sydney

The Impact of AI on Cyber Security

The swift integration of AI brings forth new issues in data governance, security, and ethical utilization. As AI becomes more embedded in businesses, security leaders must address the protection of sensitive data across cloud services and AI frameworks while ensuring ethical and transparent data usage.

Key Topics at the State of Security Breakfast

Zero Trust

The initial panel will explore the transition from theoretical Zero Trust models to real-world applications. Topics will include identity management, segmentation, and continuous verification, along with the essential architectural and cultural transformations required to implement Zero Trust in hybrid settings.

Data Security & AI Governance

The convergence of data security and AI will be a primary focus. As the role of AI in organizations grows, specialists will share tactics for safeguarding sensitive data within AI models and automated processes while upholding accountability and oversight.

Centralising Security Information

Amid rising amounts of security data, businesses are looking into methods to centralize this information to improve visibility and response abilities. Panelists will discuss strategies, such as SIEM, data lakes, and other approaches to efficiently handle security alerts and signals.

Event Information and Registration

The TechBest State of Security Breakfast Roadshow will be held on November 25 from 7:45am to 11:00am at the Establishment Ballroom, 252 George St, Sydney NSW 2000. The event will showcase notable speakers, including Velvet-Belle Templeman, Deputy General Manager at TechBest, with additional speakers to be revealed. Register now to engage in discussions with industry leaders and peers.

Conclusion

The State of Security Breakfast Event in Sydney is essential for security and technology leaders. The event will tackle urgent cyber security challenges, including AI integration, Zero Trust strategies, and data protection. Participants will benefit from insights shared by expert panels and have the chance to network and converse with industry peers.

Q: What topics will the State of Security Breakfast Event cover?

A: The event will concentrate on Zero Trust, Data Security & AI Governance, and Centralising Security Information.

Q: When and where will the event take place?

A: It is set for November 25 at the Establishment Ballroom, 252 George St, Sydney NSW 2000.

Q: Who are the speakers at the event?

A: The agenda includes Velvet-Belle Templeman, Deputy General Manager at TechBest, and additional industry authorities.

Q: What opportunities are available for participants?

A: Participants can engage in panel discussions and network with fellow security and tech professionals.

Q: How can I sign up for the event?

A: You can sign up online at techbest.com.au.

ATO Culture Limits Aspiring AI Advancements


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Quick Overview

  • The ATO is prudently incorporating agentic AI, concentrating on re-engineering, automation, and machine learning for the majority of its operations.
  • Copilot Chat is widely accessible, yet its agentic capabilities are disabled due to concerns regarding data sensitivity.
  • The ATO has moved from a ‘human in the loop’ model to a ‘human at the helm’ framework to uphold accountability for AI outputs.
ATO culture limits AI ambitions

ATO’s Cautious Stance on AI

The Australian Taxation Office (ATO) is adopting a careful approach to agentic AI, shaped by its internal ethos, risk tolerance, and the sensitivity of its data assets. While preliminary architectural frameworks are progressing, the ATO posits that agentic AI might only be required for a limited portion of a comprehensive process. Assistant Commissioner Jimmy Tzimopoulos pointed out at Gartner’s IT Symposium that re-engineering processes, automation, and machine learning can fulfill most scenarios.

Restricted Role of Agentic AI

Tzimopoulos remarked that while agentic AI can address numerous situations, it doesn’t imply it should be universally implemented. The ATO discerns that the majority of requirements can be satisfied through process re-engineering and business automation, with agentic AI assuming a minimal role.

AI Learning Environment

The ATO is fostering a safe learning environment to explore the capabilities and limitations of agentic AI. Although Copilot Chat is available to a large number of personnel, its agentic features are inactive due to the ATO’s emphasis on comprehending its application with sensitive information.

Culture and Risk Management

Designing for the agentic domain reflects the ATO’s cautious nature, motivated by its risk-averse culture and obligation to manage a significant data repository. Tzimopoulos highlighted the necessity of aligning AI deployment with the organisational culture.

Ensuring Human Accountability in AI

The ATO has transitioned from a ‘human in the loop’ to a ‘human at the helm’ strategy to reinforce accountability in AI-generated outcomes. This shift underscores the requirement for human supervision to ensure that decisions correspond with the organisation’s obligations.

Forensic Analysis and AI

Tzimopoulos foresees an increase in demand for “IT forensic accountants” capable of assessing the real costs of AI services. This role entails evaluating financial models and discerning the worth of AI processes within a business framework.

Recap

The ATO’s deliberate method of integrating agentic AI is indicative of its culture and the delicate nature of its data holdings. By prioritizing process re-engineering and automation, the ATO guarantees that AI adoption is in line with its risk management protocols. The transition to ‘human at the helm’ emphasizes the significance of accountability in AI-led processes.

Q: What makes the ATO cautious about implementing agentic AI?

A: The ATO’s cautious approach stems from its risk-averse culture, data sensitivity, and the conviction that numerous processes can be managed through alternatives like re-engineering and automation.

Q: What is the function of Copilot Chat within the ATO?

A: Copilot Chat is broadly available to employees, but its agentic functionalities are turned off until the ATO comprehensively understands how to manage sensitive data with this technology.

Q: How does the ATO maintain accountability in AI processes?

A: The ATO has embraced a ‘human at the helm’ methodology to guarantee clear human oversight and responsibility for AI-generated outcomes.

Q: Who are “IT forensic accountants” and what is their relevance?

A: IT forensic accountants are anticipated to assess the authentic costs and value of AI services, assisting organisations in comprehending the financial ramifications of AI implementations.

SOUNDPEATS Air5 Pro Review


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

SOUNDPEATS Air5 Pro 55dB Adaptive Hybrid Active Noise Cancelling Wireless Earbuds, Qualcomm Snapdragon Sound, aptX™ Lossless, LDAC LE Hi-Res Audio, 6 Mics AI CVC 8.0 Call, BT 5.4, Find Earphones

New Malware Takes Charge of Commercial AI Models: Talos


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Emerging malware enables AI models to take control: Talos

Quick Overview

  • Emerging malware, CLOSEDQUORUM, employs AI models for strategic decisions.
  • Aims at Windows platforms to acquire credentials and additional data.
  • Evades standard tracing techniques, complicating its blockade.
  • Signifies a transition towards automated offensive tactics.
  • Increasing occurrence of AI-enabled malware in cybersecurity risks.

AI Models Steering Malware Operations

Cisco Talos cybersecurity analysts have identified an innovative malware variant called CLOSEDQUORUM, indicating a major transformation in the execution of cyber-attacks. In contrast to conventional malware that depends on human controllers, CLOSEDQUORUM implements commercial AI models to execute tactical moves on compromised Microsoft Windows systems.

Operational Mechanism of CLOSEDQUORUM

Upon installation, CLOSEDQUORUM connects with as many as four AI models, including DeepSeek, AliBaba’s Qwen, Mistral, and Google Gemini. These models, which are typically utilized by legitimate software, are responsible for determining the malware’s subsequent action from four possible options: steal, inject, persist, or move. This methodology removes the necessity for an attacker-operated server, rendering it tougher for defenders to trace and mitigate the malware.

Features and Constraints

This malware can extract Windows authentication details, duplicate saved passwords from widely-used browsers such as Chrome, Edge, and Firefox, and gather cryptocurrency wallet information. It is also capable of injecting code into processes and achieving persistence through Windows’ system configurations. However, the “move” feature in the malware is not yet executed in the version reviewed by Talos.

Prospective Trends in AI-Driven Malware

Talos indicates that the creator of CLOSEDQUORUM may provide tailored versions of the malware containing buyer-specific API keys and Discord webhooks. This phenomenon is part of a larger trend towards automated offensive strategies, with related AI-driven malware like PromptLock and SesameOp already recorded by other experts.

Conclusion

CLOSEDQUORUM exemplifies a pioneering form of AI-enhanced malware that delegates authority to AI models, underscoring a shift towards automation in cyber-offenses. While it primarily serves as a proof of concept, its presence foreshadows a potential escalation in AI-assisted threats.

Questions & Answers

Q: What is CLOSEDQUORUM?

A: CLOSEDQUORUM is a credential-extracting malware targeting Windows that utilizes AI models for automated decision-making.

Q: How does CLOSEDQUORUM evade detection?

A: It interfaces with commonly utilized AI endpoints instead of being run from attacker-operated servers, making tracing more difficult.

Q: What actions can CLOSEDQUORUM carry out?

A: It can acquire credentials, inject code, maintain persistence, but the “move” feature is currently inoperative.

Q: Why is CLOSEDQUORUM important?

A: It illustrates a transition towards automated, AI-enabled cyber-offenses, introducing new challenges for cybersecurity.

Q: Is CLOSEDQUORUM the first instance of this kind?

A: While distinct, it is part of the wider class of AI-assisted malware like PromptLock and SesameOp.

Q: What measures can businesses take to defend against AI-driven malware?

A: Businesses are advised to enhance their cybersecurity protocols, monitor for atypical network behaviors, and stay alert to emerging threats.

ASD Warns About DPRK Employment Scams, Effects on Australia Indeterminate


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Brief Overview

  • ASD, in collaboration with Japan, Germany, and the US, alerts about North Korean group WaterPlum masquerading as recruiters to infiltrate IT professionals with malware.
  • WaterPlum has compromised more than 30,000 devices worldwide, siphoning off $15.4 million from over 7000 cryptocurrency wallets for the DPRK.
  • The MSMT report projects that North Korea could earn up to US$800 million in 2025 by employing thousands of overseas workers, including IT professionals using stolen identities.
ASD alerts on DPRK job scams, unclear impact in Australia

North Korean Cyber Threats in Recruitment

The Australian Signals Directorate (ASD) has partnered with Japan, Germany, and the United States to warn the international community about North Korean cyber operatives posing as recruiters. Known as WaterPlum or Contagious Interview, these operatives seek to entrap IT professionals by presenting fake job opportunities, all while aiming to infect their systems with malware.

Global Consequences of WaterPlum

WaterPlum has effectively compromised over 30,000 devices in more than 100 nations. Through these breached systems, they have pilfered from around 7000 cryptocurrency wallets, transferring an estimated $15.4 million to the Democratic People’s Republic of Korea (DPRK).

ASD’s Position on Australian Impact

Although ASD has released this warning, it is still uncertain whether individuals or organizations in Australia have been affected directly. Nonetheless, ASD advises Australians and businesses to take this advisory seriously, highlighting the worldwide threat posed by DPRK cyber operatives.

North Korean Strategy for Overseas Labor

Before the WaterPlum alert, the Multilateral Sanctions Monitoring Team (MSMT) documented North Korea’s exploitation of overseas labor, including IT professionals operating under stolen identities. This strategy reportedly netted between US$450 million and US$800 million in 2025 by sending tens of thousands of workers abroad.

Difficult Conditions and Subcontracting Trends

North Korean IT workers, often subjected to challenging conditions, reportedly generate the highest revenue per individual compared to other labor categories. The DPRK government seizes a considerable share of their earnings, occasionally leaving them in debt. Notably, some of these workers have started subcontracting their assignments to cheaper labor markets.

Conclusion

The ASD’s alert regarding WaterPlum reflects the changing tactics of North Korean cyber actors targeting IT professionals internationally. While the direct effects on Australia remain unclear, the broader ramifications of such cyber threats and employment frauds are evident. Both individuals and businesses need to remain alert and informed to safeguard against these sophisticated schemes.

Q: What is WaterPlum?

A: WaterPlum, also known as Contagious Interview, is a North Korean cyber group impersonating recruiters to target IT professionals with malware.

Q: How many devices have been compromised by WaterPlum?

A: WaterPlum has compromised over 30,000 devices across more than 100 nations.

Q: How much has WaterPlum stolen via cryptocurrency wallets?

A: WaterPlum has stolen approximately $15.4 million from over 7000 cryptocurrency wallets.

Q: What is the function of the Multilateral Sanctions Monitoring Team (MSMT) in this scenario?

A: MSMT monitors North Korea’s utilization of overseas labor to finance its regime, reporting on employment frauds and associated activities.

Q: How does North Korea profit from overseas IT workers?

A: North Korea leverages overseas IT workers to generate significant income, with the government taking a large portion of their earnings.

Q: What actions should Australian individuals and businesses take in light of the advisory?

A: They should review the advisory to mitigate risks related to DPRK cyber actors attempting to breach networks and steal data.

Insufficient Data Exchange Undermining EU Cybersecurity Measures


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Brief Overview

  • Efforts for cyber defence in the European Union are hindered by insufficient data exchange among member nations.
  • The EU has allocated €1.4 billion ($2.25 billion) towards enhancing cybersecurity.
  • The deficit in information exchange is referred to as the “Achilles heel” of EU cybersecurity.
  • A major ransomware incident in 2025 went unreported by the impacted countries.
  • National security regulations are obstructing cross-border information exchange.
  • No significant cybersecurity event has been documented since 2016.
  • France, Ireland, the Netherlands, and Spain are facing legal measures due to non-adherence to EU information-sharing regulations.

EU’s Cybersecurity Funding and Obstacles

The European Union is making substantial investments in its cybersecurity framework, with a current budget of €1.4 billion aimed at bolstering its cyber defences. Nevertheless, a report from the European Court of Auditors indicates that these initiatives are being weakened by a pronounced lack of information sharing among the member states.

The Critical Weakness: Insufficient Information Exchange

The report points out that poor data sharing is the “Achilles heel” of the EU’s cybersecurity framework. A prompt and actionable flow of information is essential for an effective response to cyber threats, which is currently lacking. This shortcoming diminishes the overall effectiveness of the EU’s cybersecurity systems and protocols.

Unreported Cyber Events

In September 2025, a ransomware attack struck a technology provider servicing the aviation sector, disrupting major airports throughout Europe, such as those in London, Brussels, Berlin, and Dublin. Alarmingly, none of the impacted nations informed the EU cybersecurity agency or other member states, showcasing the gaping hole in information exchange.

Obstacles to Information Exchange

Legislation pertaining to national security in individual nations is identified as a major hindrance to effective cross-border information sharing. This legal backdrop frequently obstructs the necessary communication between countries when incidents arise.

Legal Proceedings and Non-compliance

In spite of EU regulations demanding information sharing, no EU country has reported a “large-scale” cybersecurity event since 2016. The European Commission has recently referred France, Ireland, the Netherlands, and Spain to the EU Court of Justice for not aligning their national legislation with EU directives regarding cybersecurity information sharing.

Conclusion

The European Union’s commitment to cybersecurity is laudable, yet ineffective information exchange among member states undermines its cyber defences. The absence of timely and actionable information jeopardizes the EU’s capacity to address cyber threats, presenting a significant danger to its collective security.

Q: Why is exchanging information essential for EU cybersecurity?

A: Information exchange is crucial as it enables timely reactions to cyber challenges, thereby improving the overall efficiency of cybersecurity strategies.

Q: What are the repercussions of failing to share information about cyber events?

A: The lack of information sharing can result in disjointed responses, heightened vulnerability, and extended recovery from cyber issues.

Q: In what way are national security laws impacting information sharing?

A: National security laws frequently limit the flow of information across borders, obstructing collaborative efforts to counter cyber threats.

Q: What measures is the EU implementing against non-compliant member nations?

A: The EU has initiated legal actions against states that have not modified their legislation to align with EU directives on cybersecurity information sharing.

Q: Have there been any enhancements in EU cybersecurity measures?

A: Although significant investments and some improvement in cooperation have been made, the lack of information sharing continues to be a pressing concern.

Q: What was the consequence of the ransomware incident in 2025?

A: The incident caused disruptions at major European airports, underlining the repercussions of insufficient information sharing.