This month in security with Tony Anscombe – October 2025 edition
04
Nov
2025

This month in security with Tony Anscombe – October 2025 edition

From the end of Windows 10 support to scams on TikTok and state-aligned hackers wielding AI, October’s headlines offer a…

Fake Solidity VSCode extension on Open VSX backdoors developers
04
Nov
2025

Fake Solidity VSCode extension on Open VSX backdoors developers

A remote access trojan dubbed SleepyDuck, and disguised as the well-known Solidity extension in the Open VSX open-source registry, uses an…

New TruffleNet BEC Campaign Leverages AWS SES Using Stolen Credentials to Compromise 800+ Hosts
04
Nov
2025

New TruffleNet BEC Campaign Leverages AWS SES Using Stolen Credentials to Compromise 800+ Hosts

Identity compromise has become one of the most significant threats facing cloud infrastructure, particularly when attackers gain access to legitimate…

Transforming Australian Insurance Operations, Customer Service and Fraud Detection with AI and ML
03
Nov
2025

Transforming Australian Insurance Operations, Customer Service and Fraud Detection with AI and ML

Australia’s insurance organisations face a perfect storm of tighter regulatory compliance requirements, increasing risk from more frequent and intense weather…

Jabber Zeus developer ‘MrICQ’ extradited to US from Italy
03
Nov
2025

Jabber Zeus developer ‘MrICQ’ extradited to US from Italy

Jabber Zeus developer ‘MrICQ’ extradited to US from Italy Pierluigi Paganini November 03, 2025 Ukrainian Yuriy Rybtsov, aka MrICQ, a…

5 things to do after discovering a cyberattack
03
Nov
2025

5 things to do after discovering a cyberattack

When every minute counts, preparation and precision can mean the difference between disruption and disaster 03 Nov 2025  •  ,…

Scores of Australian Cisco devices remain BADCANDY infected
03
Nov
2025

Scores of Australian Cisco devices remain BADCANDY infected

More than 150 Australian Cisco routers and switches remain infected with the BADCANDY webshell as of late October 2025, despite…

Cybersecurity abstract
03
Nov
2025

Prosecutors allege incident response pros used ALPHV/BlackCat to commit string of ransomware attacks

Federal prosecutors allege that three cybersecurity professionals, whose job was to help companies respond to ransomware attacks, instead carried out…

Just weeks left until Companies House ID changes: how to prepare
03
Nov
2025

Just weeks left until Companies House ID changes: how to prepare

In a mere few weeks, Companies House will bring into force one of the most significant identity verification changes in…

Malware
03
Nov
2025

SesameOp malware abuses OpenAI Assistants API in attacks

Microsoft security researchers have discovered a new backdoor malware that uses the OpenAI Assistants API as a covert command-and-control channel….

Microsoft Patch for WSUS Flaw has Broken Hotpatching on Windows Server 2025
03
Nov
2025

Microsoft Patch for WSUS Flaw has Broken Hotpatching on Windows Server 2025

In a recent setback for Windows administrators, Microsoft’s October 2025 security update addressing a critical vulnerability in Windows Server Update…

Malicious VSX Extension "SleepyDuck" Uses Ethereum to Keep Its Command Server Alive
03
Nov
2025

Malicious VSX Extension “SleepyDuck” Uses Ethereum to Keep Its Command Server Alive

Nov 03, 2025Ravie LakshmananCryptocurrency / Threat Intelligence Cybersecurity researchers have flagged a new malicious extension in the Open VSX registry…