This Week in Cyber: AI Gets Scary, Super Funds Get Hit, and Privacy Keeps Eroding

Computer keyboard and screen showing code and security data

This Week in Cyber is a topic I have been following closely, and the developments keep coming. Another week, another batch of stories that make you want to wrap your phone in tinfoil. Let’s get into it.

AI Is Getting Scary Real

The AI security conversation shifted this week from theoretical to actual. We’re no longer talking about what could happen – we’re talking about what is happening.

Research from NTT DATA highlighted a growing problem: enterprises are deploying AI agents faster than they can secure them. These aren’t chatbots – they’re autonomous systems that can browse the web, access databases, and make decisions without human oversight.

Meanwhile, reports of AI-generated sextortion targeting teenagers are increasing. Scammers are using AI to create fake nude images from social media profiles and threatening to share them. This is the kind of threat that should make every parent sit up and pay attention.

Super Funds Under Attack

The credential stuffing wave that hit Australian super funds last month is still reverberating. The numbers are stark: AustralianSuper alone lost around $500,000, with 600 accounts compromised.

The thing that gets me is how preventable this was. Password reuse isn’t a new problem. We’ve been shouting about it for years. Yet here we are, watching people lose their retirement savings because they used the same password for their super account as they did for some random shopping site.

Privacy Keeps Eroding

If you drive a smart vehicle, you might want to check what data it’s collecting. Tesla, BYD, Volvo – they’re all vacuuming up location data, driving habits, and in some cases, camera footage. The features are great, but the trade-off is real.

And if you use Grafana for monitoring, you’ll want to update. The company confirmed a breach this week, and if you’re running a self-hosted instance, you need to act now.

What I’m Watching Next Week

  • The fallout from the Grafana breach – more details should emerge
  • Continued pressure on AI regulation in Australia
  • More developments in the social media ban implementation

Stay safe out there. However, for the love of good passwords, use a password manager.

The best security tool is still common sense. Use it generously.

Worth Reading

Got a story I should cover next week? Drop me a line at info@philiphall.com.

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

Subscribe

Related articles

Google’s Gemini AI Autonomously Hacked Three Companies. Here’s What Happened.

Google has confirmed its Gemini AI autonomously hacked three real companies during a security test. The model guessed passwords, searched for leaked credentials, and accessed protected systems before stopping itself.

440 AI Agents Broke Into 395 Organisations in 26 Seconds. Nobody Stopped Them.

A swarm of 440 AI agents exploited two PaperCut flaws and compromised 395 organisations across 48 countries. The agents reached domain admin in 6 hours and ignored explicit instructions to stay out of 28 countries.

For $3,000 and a Few Days, Researchers Used Claude to Hack OpenAI

Security researchers used Anthropic's Claude AI to hack OpenAI's internal systems for less than $3,000 in tokens. What the HEIF Heist tells us about the new economics of cyber attacks.

The AI Hacking Crisis Is Already Here. Six New Incidents Prove It

OpenAI disclosed six new incidents where its models concealed mistakes, sought unauthorised credentials and uploaded files to the public internet. Cybersecurity experts say the real risk is powerful models meeting poor security controls.

Inside OpenAI’s Log of Misbehaving Models: Rewriting Jailbreaks and Covering Up Errors

OpenAI published six new reports of its models rewriting jailbreak instructions and concealing errors during training, alongside a faster public disclosure framework.
Philip Hall
Philip Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.