Glasswing Blog

AI Cybersecurity Insights

Expert analysis on AI-driven security, VPN comparisons, and tools to protect your digital life.

Vulnerability

Microsoft's May 2026 Patch Tuesday: Two Critical RCE Flaws Every Australian Business Must Patch Now

Two CVSS 9.8 remote code execution flaws in Windows DNS (CVE-2026-41096) and Netlogon (CVE-2026-41089) headline May 2026 Patch Tuesday. Australian businesses must apply updates immediately.

14 May 2026 10 min read
Threats

Criminals Used AI to Build the World's First Zero-Day 2FA Bypass — What Australian Businesses Must Know

Google's Threat Intelligence Group confirmed the first AI-crafted zero-day exploit: a Python script that bypasses two-factor authentication on a popular open-source admin tool. Here's what Australian SMBs must do before the next campaign launches.

13 May 2026 11 min read
Data Breach

ShinyHunters Hacks Canvas LMS: Australian Students Hit in 275-Million-Record Breach

ShinyHunters stole 275 million records from Canvas LMS in May 2026, hitting dozens of Australian universities and state school systems during exam period. Here's what happened and what affected Australians must do now.

12 May 2026 11 min read
Malware

ClickFix Vidar Stealer: ACSC Warns Australian Businesses of WordPress Infostealer Campaign

Australia's ACSC has confirmed an active ClickFix campaign using compromised WordPress sites to deliver Vidar Stealer — an infostealer that harvests saved passwords, session cookies, and crypto wallet data. No exploit required: users are tricked into running the malware themselves.

10 May 2026 11 min read
Vulnerabilities

CVE-2026-23918: Apache HTTP/2 Double-Free Flaw Is Crashing Servers and Enabling RCE — What Australian Site Owners Must Do Now

A critical double-free in Apache HTTP Server 2.4.66's mod_http2 (CVSS 8.8) enables denial-of-service on all servers and remote code execution on Debian and Docker deployments. Australian site owners must patch to 2.4.67 or apply WAF mitigation now.

7 May 2026 11 min read
Ransomware

DragonForce Ransomware Strikes Two Australian Businesses: What SMBs Must Do Now

DragonForce ransomware struck gelato chain Gelatissimo and builder Champion Homes in April 2026, exposing staff and customer data. Here's what Australian SMBs must do before they're next.

6 May 2026 10 min read
AI Security

Five Eyes Agencies Warn Australian Businesses: Your AI Agents Are a Security Gap

Six national cybersecurity agencies — including Australia's ACSC — issued their first joint guidance on agentic AI. Here's what it means for Australian businesses using AI tools.

5 May 2026 11 min read
Linux Security

Copy Fail (CVE-2026-31431): The Nine-Year Linux Kernel Flaw That Hands Root to Any Attacker

A nine-year-old Linux kernel bug grants root in seconds with no race condition required. CISA added it to KEV. What Australian businesses and website owners must do now.

4 May 2026 11 min read
Threat Intelligence

Russian GRU (APT28) Is Targeting Logistics Firms — What Australian Businesses Must Know

ACSC and 15 allied agencies confirm Russia's GRU Unit 26165 is actively targeting logistics and tech companies. Here's what Australian organisations must do now.

3 May 2026 10 min read
Vulnerability

CVE-2026-42208: The SQL Flaw That Let Hackers Steal AI API Keys — What Australian Developers Must Do Now

A critical pre-auth SQL injection in LiteLLM's AI gateway proxy (CVSS 9.3) was exploited within 36 hours of disclosure, stealing OpenAI, Anthropic, and Bedrock credentials. Patch checklist and secrets hygiene for Australian developers.

2 May 2026 10 min read
Vulnerability

CVE-2026-41940: cPanel & WHM's Critical Authentication Bypass Is Under Active Attack in Australia

A CVSS 9.8 authentication bypass in cPanel and WHM was exploited for two months as a zero-day before the patch dropped. The ACSC confirms active exploitation in Australia — here's what to do.

1 May 2026 11 min read
Ransomware

Qilin Ransomware Is Now Australia's Most Active Threat: What Businesses Must Do in 2026

Qilin recorded 31 confirmed victims in a single week in late April 2026, making it the world's most prolific ransomware group. Multiple Australian organisations have already been hit — here's what you need to do.

29 April 2026 11 min read
Cloud Security

Vercel Breached: How a Roblox Cheat Download Exposed Cloud Secrets — and What Australian Businesses Must Do Now

A Roblox cheat download planted Lumma Stealer at a third-party vendor, bypassing MFA entirely and exposing environment variables from hundreds of Vercel customer projects.

28 April 2026 11 min read
Nation-State Threats

China-Nexus Covert Networks Are Targeting Australian Critical Infrastructure — What Businesses Must Do Now

A joint advisory from 16 agencies — including Australia's ACSC — warns China-linked groups are weaponising compromised home routers for espionage and pre-positioning attacks on critical infrastructure.

27 April 2026 10 min read
Vulnerability

CVE-2026-21858 (Ni8mare): Critical n8n Flaw Exposing 26,000+ Automation Servers to Remote Takeover

Australia's ACSC has warned of a CVSS 10.0 unauthenticated RCE vulnerability in n8n workflow automation. Over 26,000 servers remain exposed months after a patch was released.

26 April 2026 10 min read
Data Breach

NSW Treasury Insider Data Breach 2026: What Australian Organisations Must Learn

An NSW Treasury staffer was arrested after allegedly transferring 5,600 sensitive government documents to an external server. Here's what every Australian organisation must know about insider threat detection and prevention.

April 25, 2026 11 min read
Supply Chain Security

Bitwarden CLI Backdoored: The Shai-Hulud npm Supply Chain Attack and What Australian Developers Must Do

The official Bitwarden CLI npm package was compromised for 93 minutes on 22 April 2026, deploying a self-propagating worm that stole developer credentials across npm, SSH, and cloud environments.

24 April 2026 11 min read
Vulnerabilities

Microsoft SharePoint Zero-Day CVE-2026-32201: 1,370+ Servers Still Unpatched as Attackers Strike

Microsoft's April 2026 Patch Tuesday patched a SharePoint zero-day already exploited in the wild. Over 1,370 servers remain exposed globally. Here's what Australian organisations must check and do now.

April 23, 2026 10 min read
WordPress Security

31 WordPress Plugins Secretly Backdoored: The 2026 Supply Chain Attack Targeting 400,000 Sites

Attackers secretly inserted a PHP backdoor into 31 WordPress plugins in 2025, then activated it in April 2026 to inject SEO spam into 400,000 sites. A separate attack hit Smart Slider 3 Pro the same week. Here's what Australian site owners need to check and do now.

April 23, 2026 11 min read
Ransomware

The Gentlemen Ransomware: How This Fast-Rising Group Is Targeting Australian Businesses in 2026

The Gentlemen RaaS exploded from 35 to 320+ victims in six months and now deploys a 1,570-host botnet via SystemBC. Australian firms are a priority target — here's how the attacks work and what to do.

April 23, 2026 10 min read
Critical Vulnerabilities

Four Cisco SD-WAN Flaws Under Active Attack: What Australian Networks Must Patch Now

CISA added four Cisco Catalyst SD-WAN Manager CVEs to its exploit watchlist in 48 hours. Threat actor UAT-8616 is chaining them to seize full network control — Australian organisations have days to act.

April 22, 2026 9 min read
Data Breach

16 Billion Passwords Leaked: What Australians Must Do Right Now

The world's largest-ever credential dump exposes 16 billion logins harvested by infostealer malware — including Australian government portals and banking accounts. Here's what it means and exactly what to do.

April 21, 2026 10 min read
Critical Vulnerabilities

Two Windows Defender Zero-Days Still Unpatched as Attackers Exploit All Three

BlueHammer, RedSun, and UnDefend are all being actively exploited. Microsoft has patched only one. Here's what Australian organisations must do while two flaws remain open.

April 20, 2026 9 min read
Ransomware

Melbourne Financial Firm 3P Corporation Hit by Space Bears Ransomware: What Australian SMBs Must Do Now

Space Bears ransomware published 213 GB of stolen client data — including bank details and signed tax forms — from a Melbourne financial firm after the ransom deadline passed this week.

April 19, 2026 10 min read
Ransomware

Australian Hospitals Under Fire: The INC Ransom Threat Targeting Healthcare in 2026

Five Eyes agencies have confirmed INC Ransom is actively targeting Australian hospitals. Here's how the attacks work, what the ACSC advisory means, and how to protect your organisation.

April 17, 2026 10 min read
Critical Vulnerabilities

CISA Warns of 6 Actively Exploited Flaws in Fortinet, Microsoft & Adobe — What Australian Businesses Must Do Now

CISA added six critical vulnerabilities to its KEV catalogue on 14 April 2026, including a near-perfect CVSS 9.8 Fortinet SQL injection that needs no credentials to exploit. Here's what to patch right now.

April 16, 2026 9 min read
Data Breach

Booking.com Data Breach 2026: What Australians Need to Know and How to Stay Safe

Booking.com confirmed a supply chain breach on 13 April exposing traveller data. Australian users are being hit by targeted WhatsApp phishing — here's what to do right now.

April 15, 2026 9 min read
Password Security

25 Critical Vulnerabilities Found in Major Password Managers: What You Need to Know

Researchers from ETH Zurich uncovered 25 attack vectors across Bitwarden, LastPass, and Dashlane affecting 60 million users. Here's what happened and how to protect yourself.

April 15, 2026 9 min read
AI Cybersecurity

What Is Project Glasswing? Anthropic's AI Cybersecurity Initiative Explained

Everything you need to know about the largest coordinated vulnerability disclosure in history, powered by Claude Mythos.

April 8, 2026 8 min read
VPN Comparison

Best VPNs for Australia in 2026: Privacy, Speed & Value Compared

We tested NordVPN, Surfshark, and PureVPN for Australian users. Here's which one you should choose based on your needs.

April 8, 2026 10 min read
AI Security

How AI Is Finding Zero-Day Vulnerabilities Faster Than Humans

AI systems are discovering entire new classes of security flaws that human researchers missed for decades. Here's how it works.

April 8, 2026 7 min read
VPN Comparison

NordVPN vs Surfshark 2026: Which VPN Is Better?

A detailed head-to-head comparison of the two most popular VPNs on speed, security, price, and features.

April 8, 2026 9 min read