-

·
Booking.com Data Breach Enables “Reservation Hijacks” Scam
A data breach at travel giant Booking.com exposed customer reservation details including full names, addresses, booking dates, email addresses, and phone numbers. Cybersecurity firm Norton reports criminals are now conducting reservation hijacks – contacting customers posing as hotels to trick them into sending money for fake reservation issues. The company has updated reservation PINs and…
-

·
Operation PowerOFF Seizes 53 DDoS Domains, Exposes 3 Million Criminal Accounts
An international law enforcement operation involving 21 countries (including Australia, the U.S., UK, Germany, and Japan) took down 53 domains and arrested four people running commercial DDoS-for-hire services. The operation disrupted “booter” services used by over 75,000 cybercriminals, with databases containing over 3 million criminal user accounts seized. Authorities are now sending warning emails to…
-

·
Rockstar Games Hit by ShinyHunters Ransomware Attack
The notorious cybercrime group ShinyHunters has claimed responsibility for a ransomware attack on Rockstar Games (maker of GTA). The group claims to have stolen 78.6 million records from Rockstar Snowflake environment and issued a ransom deadline of April 14, 2026, threatening to publish stolen material if cryptocurrency payment demands were not met. This represents a…
-

·
Mirai Variant “Nexcorium” Exploits TBK DVRs and TP-Link Routers for DDoS Botnet
Threat actors are actively exploiting a command injection vulnerability (CVE-2024-3721) in TBK DVR-4104 and DVR-4216 devices to deploy a Mirai botnet variant called “Nexcorium.” The malware also targets end-of-life TP-Link Wi-Fi routers and Huawei HG532 devices. Once infected, devices are enrolled into a botnet capable of launching large-scale DDoS attacks over UDP, TCP, and SMTP…
-

·
$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims
Grinex, a Kyrgyzstan-incorporated cryptocurrency exchange sanctioned by the U.K. and the U.S. last year, said it is suspending operations after it blamed Western intelligence agencies for a $13.74 million hack. The exchange said it fell victim to what it described as a large-scale cyber attack that bore hallmarks of foreign intelligence agency involvement. This attack…
-

·
Cyber Invaders – Learn Cyber Security Through Play
Defend Your Network Against Cyber Threats The Australian Institute of Cyber Security is excited to launch Cyber Invaders, an interactive educational game designed to introduce students, young people, and anyone new to cyber security to the fundamental concepts of digital defence. How It Works Cyber threats are falling towards your network. Each threat has one…
-

·
Hasbro Cyberattack: Toy Giant Hit by Data Breach
Major Toy Manufacturer Suffers Cyberattack Hasbro Inc., one of the world’s largest toy manufacturers and the company behind iconic brands including Transformers, Play-Doh, Peppa Pig, Dungeons & Dragons, Monopoly, My Little Pony, and Magic: The Gathering, has disclosed a significant cyberattack that has disrupted its operations. Incident Timeline The company discovered unauthorized access to its…
-

·
Axios NPM Supply Chain Attack: Cross-Platform RAT Deployed to 100 Million Weekly Downloads
The Axios NPM Compromise: A Supply Chain Attack of Unprecedented Scale On March 31, 2026, the JavaScript ecosystem faced one of its most significant supply chain attacks when the axios npm package was compromised. With over 100 million weekly downloads and 174,000 dependent packages, axios is a foundational HTTP client library used across countless applications,…
-

·
ACSC Warns of Targeting Campaign Against Australian Code Repositories
ACSC Warns of Targeting Campaign Against Australian Code Repositories The Australian Cyber Security Centre has issued an urgent alert warning that threat actors are actively targeting online code repositories used by Australian developers and organisations. The campaign represents a significant supply chain risk that could compromise software deployed across Australian businesses and government agencies. The…
-

·
Federal Court Hits Binance Australia With $10 Million Penalty for Misclassifying Retail Investors
The Federal Court of Australia has ordered Oztures Trading Pty Ltd, operating as Binance Australia Derivatives, to pay a $10 million penalty after the Australian Securities and Investments Commission (ASIC) found the cryptocurrency exchange had misclassified more than 85 per cent of its Australian clients. Between July 2022 and April 2023, 524 retail investors were…









