Meta’s Muse is more than a chatbot. It is a digital worker that can read email, make purchases across the web, and act after users close the app. Wall Street sees a return on Meta’s vast AI spending. Cybersecurity experts see a more urgent question: should it hold the keys to our digital lives yet?
Dell’s US$95 billion AI-server backlog and US$74 billion revenue outlook show the AI boom moving beyond a few cloud giants into enterprise, sovereign and neocloud infrastructure procurement.
Meta has come back to the consumer, and it has come back armed. Muse reads inboxes, drives a browser, books travel and pays. Meta has not led with intelligence. It has led with containment. A model that says the wrong thing is an embarrassment. An agent that does the wrong thing is now an incident.
12th December 2025 Cyber Update: Melbourne Broker ThinkMarkets Hit by Chaos Ransomware
Melbourne-based broker ThinkMarkets has been hit by the Chaos ransomware group, which stole 512GB of data. The breach includes employee passports and customer KYC records, posing a major risk to the Australian financial services firm and its clients worldwide.
Cyber News Centre's cyber update for 12th December 2025: Melbourne-headquartered online trading broker ThinkMarkets has become the latest Australian financial services firm to be targeted by a ransomware attack, with the emerging Chaos group claiming to have stolen a significant volume of sensitive data.
ThinkMarkets is a multi-regulated online brokerage firm established in 2010, with headquarters in Melbourne and London. The company provides CFD trading services across forex, stocks, and cryptocurrencies to clients in over 165 countries and holds 10 regulatory licenses, including from the Australian Securities and Investment Commission (ASIC).
The Update and Why It Matters
Update: The Chaos ransomware group listed ThinkMarkets on its dark web leak site earlier this week, claiming to have exfiltrated 512 gigabytes of data from the Australian broker. The threat actors have reportedly published the data online after ransom negotiations failed. The compromised information is extensive, containing highly sensitive corporate and personal records. According to security researchers who have viewed the data, the leak includes internal human resources files, details of customer disputes, legal advice, and confidential trading information.
Most alarmingly, the breach exposed scans of employee passports and know-your-customer (KYC) verification documents for a number of the firm’s clients. The Chaos group, first observed in February 2025, is a relatively new ransomware-as-a-service (RaaS) operation actively recruiting affiliates on Russian-speaking forums. The group employs a double-extortion model, threatening to publish stolen data if ransom demands, which have been as high as $300,000 in previous attacks, are not met. ThinkMarkets has not yet issued a public statement on the incident.
Why it Matters: This attack on an ASIC-regulated broker highlights the significant and growing threat to Australia’s financial services sector. The exfiltration of passport scans and KYC documents creates a severe risk of identity theft and financial fraud for both employees and clients of ThinkMarkets. For Australian investors, it is a stark reminder that even regulated financial entities are vulnerable to sophisticated cyber attacks.
The incident also underscores the operational risk posed by emerging RaaS groups like Chaos, which can quickly scale their attacks and cause widespread damage. The breach serves as a critical warning for the entire financial supply chain, demonstrating that robust security measures are essential to protect sensitive client data and maintain trust in the digital economy.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
OpenAI's Astra can develop zero-day exploits, while a US$1 billion defence push seeks to give critical infrastructure teams the same machine-speed advantage.
US authorities have dismantled QTFY’s QScan and QTRouter platforms, exposing a China-linked service model that blended exploit trading, automated scanning and hijacked IoT devices to reach critical infrastructure while concealing where attacks began.
Australia’s cyber agency is warning that attackers are exploiting two N-able N-central authentication bypass flaws locally. For MSPs and enterprise IT teams, a trusted management console can become a route across hundreds of customer endpoints.
A record close on Wall Street and the AI names that were meant to lead it taken apart in the same session. Beijing is now drafting export controls on its own models. The labs keep finding their systems outside the box. Read one at a time, it is a normal week. Read together, something else entirely.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!