Two stories about AI are running, and both are incomplete. The tools genuinely compress work; the accounting, the calibration and the power bills are another matter. Twenty-five years ago the fibre outlasted the forecasts that paid for it, and nothing in a boom is cheaper than a confident number.
Google’s €13bn Finnish AI investment shows the race is no longer just about chips and models. It is about nuclear power, grids, cooling and construction. As data centres become industrial assets, countries with reliable, low-carbon energy will hold the decisive advantage as global AI
AI is shrinking the gap between flaw disclosure and exploitation, forcing boards to modernise security at machine speed. As agentic systems arm attackers and defenders alike, the opportunity lies in identity, cloud protection, automated response and AI governance, not apocalypse rhetoric globally.
Trellix says attackers gained unauthorised access to part of its source code repository, but has found no evidence that its release pipeline was affected or that code was exploited.
Trellix has confirmed that attackers gained unauthorised access to part of its internal source code repository, placing one of the sector’s major vendors under direct scrutiny for its own software supply chain controls. In an official statement, the company said it recently identified the compromise, moved quickly to engage leading forensic specialists, and notified law enforcement.
Trellix maintains that, based on current findings, there is no evidence its source code release or distribution processes were affected, and no indication the code has been exploited. Cyber analyst and media outlets confirms access to part of a repository. However, key details remain undisclosed, including which systems were impacted, how long the attackers had access, and who was responsible.
The concern is straightforward. Source code repositories are high value targets. They expose product logic, architecture and potential weaknesses that can be weaponised later. That includes backdoor development, evasion techniques, or broader downstream supply chain attacks. When the target is a major endpoint security and XDR provider, the implications extend well beyond a single vendor.
Why it matters
Trellix products operate deep within enterprise security environments, covering endpoint protection, detection and response, email and data security, network detection and security operations. Any exposure at the code level raises legitimate questions about long term assurance, even where no immediate tampering is identified.
Attackers are shifting focus upstream. Development environments are now a primary target set, including source code, CI/CD pipelines, developer credentials and code signing infrastructure. A breach at this layer scales risk across entire customer bases. This is no longer a contained technical issue. It is a governance, trust and systemic risk question.
For Australian organisations and global enterprises alike, this incident is a clear signal to reassess how security vendors are evaluated. That includes controls around repository access, secret management, isolated build environments, code signing integrity, update mechanisms and independent incident validation. Security vendors should not be treated as outside the threat model.
There is no immediate indication that Trellix customers are compromised based on current disclosures. That said, organisations should stay alert for further technical detail, follow any vendor guidance as it emerges, and strengthen their third party software risk frameworks. The exposure of development infrastructure is now a frontline risk, not a theoretical one.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
OpenAI's Astra can develop zero-day exploits, while a US$1 billion defence push seeks to give critical infrastructure teams the same machine-speed advantage.
US authorities have dismantled QTFY’s QScan and QTRouter platforms, exposing a China-linked service model that blended exploit trading, automated scanning and hijacked IoT devices to reach critical infrastructure while concealing where attacks began.
Australia’s cyber agency is warning that attackers are exploiting two N-able N-central authentication bypass flaws locally. For MSPs and enterprise IT teams, a trusted management console can become a route across hundreds of customer endpoints.
A record close on Wall Street and the AI names that were meant to lead it taken apart in the same session. Beijing is now drafting export controls on its own models. The labs keep finding their systems outside the box. Read one at a time, it is a normal week. Read together, something else entirely.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!