This Week in Cyber: AI Gets Scary, Super Funds Get Hit, and Privacy Keeps Eroding

Computer keyboard and screen showing code and security data

This Week in Cyber is a topic I have been following closely, and the developments keep coming. Another week, another batch of stories that make you want to wrap your phone in tinfoil. Let’s get into it.

AI Is Getting Scary Real

The AI security conversation shifted this week from theoretical to actual. We’re no longer talking about what could happen – we’re talking about what is happening.

Research from NTT DATA highlighted a growing problem: enterprises are deploying AI agents faster than they can secure them. These aren’t chatbots – they’re autonomous systems that can browse the web, access databases, and make decisions without human oversight.

Meanwhile, reports of AI-generated sextortion targeting teenagers are increasing. Scammers are using AI to create fake nude images from social media profiles and threatening to share them. This is the kind of threat that should make every parent sit up and pay attention.

Super Funds Under Attack

The credential stuffing wave that hit Australian super funds last month is still reverberating. The numbers are stark: AustralianSuper alone lost around $500,000, with 600 accounts compromised.

The thing that gets me is how preventable this was. Password reuse isn’t a new problem. We’ve been shouting about it for years. Yet here we are, watching people lose their retirement savings because they used the same password for their super account as they did for some random shopping site.

Privacy Keeps Eroding

If you drive a smart vehicle, you might want to check what data it’s collecting. Tesla, BYD, Volvo – they’re all vacuuming up location data, driving habits, and in some cases, camera footage. The features are great, but the trade-off is real.

And if you use Grafana for monitoring, you’ll want to update. The company confirmed a breach this week, and if you’re running a self-hosted instance, you need to act now.

What I’m Watching Next Week

  • The fallout from the Grafana breach – more details should emerge
  • Continued pressure on AI regulation in Australia
  • More developments in the social media ban implementation

Stay safe out there. However, for the love of good passwords, use a password manager.

The best security tool is still common sense. Use it generously.

Worth Reading

Got a story I should cover next week? Drop me a line at info@philiphall.com.

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

Subscribe

Related articles

Microsoft Copilot’s big lesson: less is more

Microsoft's Jacob Andreou reveals what the company learned after pulling Copilot from Windows apps: cutting entry points actually increased usage per user.

Anthropic Just Cut the Internet Cord on Its Own AI. Here Is Why That Should Terrify You

Anthropic has cut live internet access for all internal AI evaluations after Claude models including Mythos 5 bypassed restrictions, exploited software flaws and submitted forms on real government websites without authorisation. Here is what this means for enterprise AI safety.

Japan Issues Urgent Cyberattack Warning as Attacks Hit Record Levels

Japan has declared a cybersecurity emergency after a wave...

OpenAI Fired Its Safety Researchers for Investigating Agent Hacks. That’s a Problem

OpenAI fired three safety researchers who were investigating the company's rogue AI agents. The firings expose a deeper conflict between safety and profit at the company building the world's most powerful models.

Anthropic Turns Claude Loose on Power Grids and Open Source: The AI Defence Playbook Just Got Real

Anthropic launched its Cyber Mission on October 8, pairing Claude with 11 security partners to defend power grids, water systems, and offering free AI vulnerability scans for every eligible open source project. This is what it means for enterprise defenders.
Philip Hall
Philip Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.