Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Becoming a trusted business partner: 5 partnership strategies for Australian MSPs

A reliable service desk earns confidence. A trusted business partner earns a place in decisions about risk, growth and continuity. For Australian MSPs, that distinction matters because clients increasingly need more than a list of tools. They need clear advice about which risks to address, which outcomes to prioritise and how technology supports the business. Australian Cyber Security Centre guidance encourages organizations to scrutinize the cybersecurity measures used in outsourced ICT services.

Vulnerability Assessments in an Agentic World: Step-by-Step Guide

An old package or a misconfigured cloud storage bucket can be identified by a legacy scanner, but it does not account for the unique risk profile of autonomous systems. It cannot confirm that an AI agent with access to your production environment can chain together a CRM read, an email send and a production write using inherited credentials. Your agents are dynamic: they plan, call tools, and act across multiple environments, and some may retain context or long-term memory beyond the original request.

Skynet Comes Online - The 443 Podcast - Episode 386

This week, dive into OpenAI's and METR's analysis of the rogue OpenAI agents that hacked Hugging Face back in July. We go over the full attack timeline discussing the multiple message boards the agents created and the ultimate goal of their attack against Hugging Face and trust us, its as crazy as it gets. Before that, we discuss a recent dark web service that popped up selling 153 million stolen drivers licenses before discussing a research post into a malware implant discovered in inexpensive Chinese routers.

How to Evaluate and Choose the Best Compliance Software in 2026

Choosing compliance software in 2026? Every platform on your shortlist says the same three things: automation, AI, and audit-ready. What none of them show you in a demo is whether the tool keeps you ready all year or leaves you scrambling every audit season. This video walks through five criteria that separate the two, and the exact question to ask a vendor on each one.

Telegram Zero-Day: Malicious Sticker Crash Explained

On 6 September 2026, researchers publicly described a Telegram zero-day crash. A group owner said a chat they own became unreachable: opening it crashed official clients on iOS, Android, Desktop and Web. A second researcher posted a short recording of a script sending one specially prepared sticker into a test chat. The harm is availability, not account takeover. If the sticker stays in chat history, the crash can happen again every time someone opens that conversation.

How Far Can Prompt Injection Reach in Agentic Coding Assistants?

The blast radius of a prompt injection against your coding assistant was set weeks ago, by whoever built the dev environment image. Same assistant, same model, same injected sentence: on a laptop it collects every repository, SSH key and cloud login the developer holds; on a provisioned dev box it collects an organization token plus whatever the image left behind; on a CI runner it collects a deployment credential and a network path to production. Three environments, three incidents, one payload.

How The Sack Company Solved "Click Happy" Employees & Reduced Risk Scores with KnowBe4

The Sack Company implemented KnowBe4 to eliminate "click happy" employee behavior and streamline phishing campaign management across its family of companies. By leveraging KnowBe4’s AI Defense Agents (AIDA) and gamified phishing security awareness training, The Sack Company reduced organizational risk scores while saving 50 to 60 hours per week in IT monitoring time. KEY HIGHLIGHTS & RESULTS: TIMESTAMPS / CHAPTERS.

Automatic Key Exchange: faster, post-quantum secure origin handshakes for 45 billion daily connections (and counting)

Every time Cloudflare opens a new TLS 1.3 connection to an origin server, we have to make a guess: the protocol requires us to commit to a key agreement algorithm in the very first packet we send, before the origin has told us anything about itself or what it can support. If we guess right, the handshake completes in one round trip. Guess wrong, and the origin replies with a HelloRetryRequest, we start over, and the connection costs two round trips.