Security News

Record Data Breaches Highlight Australia's Network Security Gap

iTnews · 21 Sept 2026
Key Takeaway Small businesses should ensure network access policies are updated promptly whenever new devices or locations connect, and should close off exposed management services and unpatched systems before attackers, human or AI-driven, can find them.

Australia recorded 1,205 notifiable data breaches in 2025, the highest total since mandatory reporting began and an 8% rise on the previous year, according to the Office of the Australian Information Commissioner. The Australian Signals Directorate's Cyber Security Centre has separately warned that threat actors are targeting internet-facing network devices, exploiting exposed management services, weak configurations and known vulnerabilities to steal network information and credentials.

Industry commentary suggests Australia is lagging behind other parts of the Asia Pacific and Japan region, where network and security teams have converged, treating the network as part of security from the outset rather than as a separate function. The concern is that attackers are moving faster than traditional processes can keep up with. Initiatives such as Project Glasswing, built on an Anthropic AI model, illustrate how quickly AI can be used to identify vulnerabilities, and a July 2026 incident involving Hugging Face showed autonomous AI agents recovering exposed credentials and exploiting vulnerabilities to expand access within internal systems.

The practical risk is that gaps open whenever a device connects from a new location or a policy fails to keep pace, sometimes leaving businesses unable to say with confidence who or what has access to their network. These are the kinds of windows attackers have already shown they can exploit.

Summarised by CISO AI from iTnews. We link back to every original so you can read it yourself.