Threat actors stories
A surge in non-human identities is leaving businesses more exposed, with privileged access risks now stretching beyond staff to AI agents and machine accounts.
Affected organisations may still face unauthorised access after patching, as researchers found attackers using scripts and reverse shells on NetScaler devices.
Data theft is now driving ransom demands, with average payments rising and attackers increasingly targeting senior staff at exposed companies.
Manufacturers, hospitals and service firms face escalating extortion threats as organised crime drives most attacks across Australasia.
AI is speeding up attacks by finding existing weaknesses, leaving organisations and SMEs exposed to faster, cheaper intrusions.
Attackers are exploiting AI faster than many defences can respond, prompting a shift to continuous testing for hidden exposures.
Surveyed firms are struggling to spot when autonomous tools stray from approved tasks, as 48% of security leaders now rank them as their biggest insider threat.
Attackers are exploiting AI tools to speed intrusions and drain cloud resources, pushing defenders towards machine-speed security operations.
Criminals are increasingly using AI for ransomware and credential theft, while flaws in test models are exposing production systems and data.
Smaller companies are facing cyber losses almost equal to their resilience spending, as attacks cost an average USD $52,000 a year.
Nearly half of security leaders now rank AI agents above external hackers and malicious insiders, according to Exabeam's survey.
With most operators exposed to basic flaws, the paper warns telecom networks could face the same low-effort intrusions seen in US water systems.
Security teams in Australia and New Zealand face hidden fraud and malware risks from gambling sites that can mask illegal deposits and scam withdrawals.
Defenders now have minutes, not hours, as attackers use agentic AI to automate credential theft, scanning and extortion across live operations.
Patch management teams face a record burden as Microsoft's latest monthly release spans 999 flaws, including two under active attack.
Analysts will save hours of manual research as structured intelligence on threat actors, malware and CVEs is added to Searchlight Threat.
A major coordinated attack on UK battery storage could cost the grid GBP £2 billion to GBP £10 billion within five years, Centrii says.
Regulated security teams get auditable AI assistance as Corelight's new tools aim to speed triage without losing traceability.
Businesses have almost no time to patch flaws now, as ESET says the median gap between disclosure and exploitation fell to zero days in 2026.
Australian businesses face faster, cheaper attacks as the ASD urges tighter control of privileged access and AI identities.