Insider threats stories
Most fake hires are exposed only after getting system access, leaving companies vulnerable for days and often weeks before a fraud is spotted.
Nearly one in 10 AI security alerts in retail involved systems exposing protected customer data to users without access, research found.
Manufacturers, hospitals and service firms face escalating extortion threats as organised crime drives most attacks across Australasia.
Access approvals can now be handled in Google Chat, as Keeper brings privileged requests and just-in-time elevation into Workspace workflows.
Security teams can now trace risky browser activity by staff and AI agents, as Citrix adds visual session records and policy guidance.
Surveyed firms are struggling to spot when autonomous tools stray from approved tasks, as 48% of security leaders now rank them as their biggest insider threat.
Autonomous systems are now creating fresh avenues for code theft, remote execution and runaway cloud spending, Mandiant says.
Nearly half of security leaders now rank AI agents above external hackers and malicious insiders, according to Exabeam's survey.
User behaviour remains IT's biggest vulnerability, with 65% of professionals saying password sharing is the worst security lapse.
Investigators could gain a fuller view of insider risk as Proofpoint links Microsoft 365 messages and files with AI interactions.
Smaller firms face mounting pressure to prove cyber compliance as Pistachio adds Hugin's technology to reach audit-ready customers across Europe.
Trusted employees and AI agents are now seen as prime insider risks, with deepfake fraud and hidden access gaps worsening the threat.
Security teams can now trace blocked cloud requests faster, as Google Cloud rolls out policy intelligence for VPC Service Controls to cut investigation time.
Businesses using personal AI agents in the workplace now face tighter access checks, as Ping aims to stop unsanctioned actions and improve audit trails.
Businesses face broader email risk as Abnormal adds outbound data-loss controls and adaptive phishing training to its security platform.
Hidden AI risks are already widespread in workplaces, with Mimecast saying users are driving shadow tools and most exposure still starts with people.
Singapore regulators are pressing firms to stop using identity numbers for authentication as leaked telecom records can fuel years of impersonation fraud.
Only 20% of Australian organisations say they fully understand AI cyber risks, leaving boards exposed as phishing and deepfakes grow more credible.
Australian security chiefs are facing heavier AI oversight as breach costs climb and most say staff use of generative tools could expose data.
Australian firms are leaving staff and contractors with excessive access, making insider incidents harder to spot, report and contain.