Progress Software disabled access to ShareFile accounts using on-premises Storage Zone Controllers due to a credible security threat, while a massive campaign dubbed FortiBleed has compromised roughly half of all internet-facing Fortinet firewalls globally.
NATO's 2026 Ankara summit placed AI security at the heart of alliance planning, raising urgent questions about autonomous systems, supply chain integrity, and the accountability of military AI as adversaries accelerate their own programmes.
SK Hynix has priced the biggest foreign listing in American history at $149 a share. The memory war we have tracked for a fortnight now has a market price. It reads as a verdict on who controls the inference economy.
Cyber Update: ASD Signals End of Essential Eight Era
ASD is preparing to retire the Essential Eight within two years, replacing it with a broader Essentials series for enterprise IT, cloud and operational technology. The shift marks a move from checklist maturity to defensible cyber architectures built for modern attack conditions in Australia today.
The Australian Signals Directorate is preparing to move beyond the Essential Eight, with a broader “Essentials” cyber security series expected to replace the framework over the next two years.
The change reflects a more complex operating environment for Australian organisations. Essential Eight remains one of the country’s most important cyber baselines, but it was built for a different phase of enterprise technology. Today, security teams are defending cloud platforms, SaaS environments, operational technology, identity systems, third-party services and automated workflows.
Chris Horlyck, head of cyber security resilience at the ACSC, told iTnews the Essential Eight would remain a “live document” during the transition. He said ASD would likely begin deprecating the framework in 12 months, before retiring it as a whole within 24 months.
The structural issue is cloud. As Horlyck put it: “Essential Eight started before cloud.” He added that organisations without cloud today would be operating with “a really surprising architecture”.
ASD has opened consultation on Essentials for enterprise IT through the ACSC Partner Portal, with feedback due by 12 July 2026. The new model is expected to cover enterprise IT, cloud and operational technology, with agentic AI also under consideration.
Why It Matters
This is not a retreat from Essential Eight discipline. It is a shift from checklist maturity to defensible architecture.
ASD says the new Essentials series will provide “prioritised, threat-informed mitigations” and give organisations more flexibility in how they implement cyber security.
For boards, CISOs and risk teams, the message is direct. Existing Essential Eight work still matters, but it now needs to sit inside a broader model of layered defence, secure design, identity assurance and protection of critical assets.
Horlyck’s reassurance is important: investment under the Essential Eight remains “relevant under the Essentials”.
The next test is whether Australian organisations can turn maturity scores into security outcomes that survive modern attacks.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
Anthropic has signed a landmark 20-year, $19 billion lease with TeraWulf for the "Justified Data" campus in Hawesville, Kentucky. The 401-megawatt AI data centre, built on a former aluminium smelting site, is expected to come online in late 2027.
What keeps cyber analysts awake at night is persistent memory in AI agents storing enterprise IP on US servers with no residency or automatic deletion. It bypasses 30-day rules. DTA's AGT.2 requires retention and purge governance but many businesses remain unaware of the privacy and forensic risks.
At midyear, the AI race has become a contest for global power. Energy, chips, cybersecurity, capital markets and state intervention now shape who controls the inference economy, who pays for it, and who is left exposed in the next industrial order of machines, markets and sovereignty to come ahead.
Anthropic has cracked the door on Mythos, its most powerful AI model, but Australia’s biggest banks and critical infrastructure players are still waiting in line, managing fast escalating cyber risks without direct access to the tool built to expose them.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!