Tech & Security Intelligence
Every week we round up the IT & cybersecurity news that actually matters to New Zealand businesses — short, plain-English, and worth three minutes.
PaperCut ships two emergency patches in eighteen hours after its print servers come under live attack. Commvault finds a third of ANZ ransomware victims paid and a third of those got nothing back. Windows 11 24H2 Home and Pro has six weeks of security updates left, and One NZ and 2degrees propose merging their mobile towers.
The NCSC's Q2 report shows losses down 52% but the hard incidents climbing. CISA confirms four flaws are already being exploited, including a critical SharePoint bypass, Microsoft's Exchange Web Services opt-out closes at the end of August, and a one-click Copilot flaw is patched after the AI was talked into explaining it.
Microsoft's August update fixes around 400 flaws, one of them a Windows zero-day already used by North Korean hackers. The NZSIS names espionage against Kiwi companies as a growing threat, Copilot changes web address on 18 August, and the NCSC tells businesses to vet the suppliers holding their data.
Attackers are taking over the remote-management software that runs business PCs — and the first patch didn't hold. Microsoft starts rolling out cross-tenant email recall, the Biometric Privacy Code grace period closes, and scammers begin cold-calling New Zealanders as the NCSC.
Attackers are stealing Microsoft 365 accounts through Microsoft's own real login page, passkeys become the default sign-in on 1 September as SMS codes head for retirement, NZ scam numbers jump again, and 85% of Kiwi firms back themselves to survive an outage while only 39% have tested it.
A pre-auth WordPress Core flaw chain is already being exploited, ransomware groups multiply to 146 with mid-sized firms most targeted, two Microsoft 365 deadlines quietly break old scripts and office scanners, and NZ's biometric privacy rules stop being optional on 3 August.
NZ scams keep climbing through 2026 (fake shops, tech-support cons and "scam-yourself" tricks), a perfect-10 zero-day hits SonicWall remote-access boxes under active attack, Microsoft makes Copilot a permanent part of its business plans, and the Privacy Commissioner's verdict on our health-data breaches lands.
Netsafe turns AI on the scammers with a platform that wastes their time, three web-app flaws (one in an AI tool) come under active attack, Microsoft 365 starts watermarking AI-generated video and audio, and why NZ's cyber laws are about to grow real teeth.
Tax-refund scams jump 44% as refund season peaks, an actively-exploited SharePoint Server flaw to patch now, Microsoft 365 adds built-in email security (and a price rise) from 1 July, and why infostealers now walk straight past MFA.
Microsoft warns of a hotel-phishing scam that slips past email filters, unveils its always-on "Scout" AI agent, NZ's cyber agency reports losses up 76%, and the government signals tougher cyber rules with director liability.
Google's scam advisory warns QR-code "quishing" is bypassing MFA, Copilot Cowork goes live on Anthropic's Claude, NZ widens its anti-scam net, and a new Privacy Act rule on indirect data collection.
Microsoft's biggest-ever Patch Tuesday, FIFA-themed fake-job phishing, a 1 July Microsoft 365 price rise, and a Deloitte study showing AI is paying off for Kiwi business.
The Canvas breach hits NZ universities, Microsoft prices AI for small business, the NCSC warns of an AI “vulnerability storm”, and the Privacy Commissioner pushes for big fines.
QR-code scams surge in NZ, CERT NZ joins the NCSC, Microsoft 365 security & price changes, and a new Privacy Act rule.
A new issue every week. Want it in your inbox?