Richard Chirgwin
Verified
As seen in:
Medium,
CorranCast,
The Register,
EIN News,
health.einnews.com,
iTnews,
Crikey,
NotebookReview,
CRN Australia,
LXer Linux News
and
Infosec journalist currently between gigs. Owner of Bunjaree Cottages. www.bunjareecottages.com.au - Views my own.
Is this you? As a journalist, you can create a free Muck Rack account to customize your profile, list your contact preferences, and upload a portfolio of your best work.
Claim your profile
Articles by Richard Chirgwin
Systemd adds filesystem mount tool
The developers behind Systemd, the alternative to sysvinit, have added a mount tool to their user space bootstrapper. The mount tool landed during the weekend in this merge. It gives Systemd users a systemd-mount command, letting the mount command pull in dependencies and use auto-mounting logic. Developer Lennart Poettering notes, scheduling the mount means there's time to check parent mounts, or run a file system checker. Poettering gave a much longer explanation at Reddit, here.
Queensland TMR's tech team seeking CTO
Queensland’s Department of Transport and Main Roads is looking for an executive director and chief technology officer (CTO). The CTO role is currently being held by Matt Hodder in an acting capacity, after predecessor Brett Stenson left for Brisbane City Council in August 2023 after a five-year stint. iTnews approached TMR for comment. The CTO role has four direct reports and a staff of more than 180 full-time equivalents.
NSW cyber security agency plans further local government action
Cyber Security NSW is planning industry roundtables which it hopes will bolster security in the local government sector. Local governments faced criticism in 2021, again in 2023, and in another sampling audit this year, leading the state government’s cyber security agency seek solutions for the sector, not just more point-in-time audits.
Cyber criminals gather together, researchers find
Cyber crime is not as fluid or mobile as believed, with international research identifying six hotspots that host the most malicious activity. An Australia-UK-French research team nominated Russia, Ukraine, China, the USA, Nigeria and Romania as key cyber crime host countries. Australia ranked 34 on the list. The World Cybercrime Index is designed to let law enforcement and the private sector to concentrate their efforts on “key cyber crime hubs”, co-author Dr Miranda Bruce of UNSW Canberra said.
Rust runs into trouble on Windows
The Rust programming language has a standard library on Windows that gives attackers a way to execute shell commands. Rated critical in an advisory on GitHub, the vulnerability affects the Rust standard library in version 1.77.1 and earlier.
Microsoft unleashes 157 bug fixes
Microsoft has pushed out 157 fixes for “Patch Tuesday”, including seven Chromium bugs in the Edge browser, but critical vulnerabilities are few and far between. While it only carries a CVSS score of 6.7, CVE-2024-26234 is notable because Microsoft said it has seen exploits in the wild. Discovered by Sophos’ Christopher Budd, CVE-2024-26234 is described by Microsoft as a “proxy driver spoofing vulnerability” leading to improper access control that is only locally exploitable.
NSW Electoral Commission CISO moving on
The NSW Electoral Commission (NSWEC) is seeking a chief information security officer (CISO) following the departure of Vishwanath Nair. The role description for the position of director, information security explains that the successful applicant will “provide advice” as CISO to the state’s electoral commissioner. As well as business-as-usual responsibilities, the CISO will be responsible for the NSWEC’s ongoing cyber uplift program.
3G shutdown to affect more customers' access to Triple Zero Original
More than a million phones could be impacted by 3G network shutdowns later this year, a telecommunications working group set up to monitor the closures has told communications minister Michelle Rowland. When Telstra and Optus close their 3G networks later this year, customers who haven’t updated their handsets will lose access to 3G-based services. The shutdown will also affect other applications, such as internet of things and medical alert devices.
Australian motorcycle distributor sees websites breached
ASX-listed motorcycle distributor MotorCycle Holdings has disclosed a data breach affecting customers of two of its brands. The company announced to the Australian Securities Exchange [pdf] that a threat actor “unlawfully gained access to a third-party hosted web server” that hosted websites for the Sherco and Lambretta brands.
Australian Space Agency's first CTO moves on
The Australian Space Agency’s first chief technology officer, Aude Vignelles, has announced that she is to leave her role. Vignelles joined the agency in 2019 as executive director, program and capability and was made CTO in November 2020. Announcing her decision on LinkedIn, Vignelles said it had been an “honour and a privilege” to be the agency's inaugural CTO.
HTTP2 bug plagues web servers
A common misconfiguration in popular web servers that support HTTP2 exposes them to low-effort denial-of-service attacks, according to security researcher Bartek Nowotarski. What Nowotarski calls the Continuation Flood attack is a class of vulnerabilities in HTTP2 protocol implementations.
NBN HFC users can expect a speed boost from May 1
NBN HFC customers should soon see a considerable speed boost, with NBN Co removing a speed cap that applies to its wholesale product. Until now, HFC services have been subject to a Layer 2 network management configuration that applied a maximum sustained information rate (MSIR) of 750Mbps. The purpose of this was to manage capacity in the HFC network.
IBM terminal emulator has RCE bug
IBM’s terminal emulator for Windows machines, Personal Communications (PCOM), must be patched against a critical vulnerability. The software includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege escalation. “The vulnerability allows any unprivileged user with network access to a target computer to run commands with full privileges in the context of NT AUTHORITY\SYSTEM," IBM’s advisory for CVE-2024-25029 explained.
Goodman launches $2.5 billion, 126MW data centre project
Goodman Group has re-started the planning process for a major data centre site in the Cumberland council area in Sydney. A prior approval process has been withdrawn in favour of Project Pluto, a 126MW facility. A Goodman Group spokesperson told iTnews the data centre would target “the short-term needs of cloud operators and new market entrants”.
Ivanti reboots security after troubled start to 2024
A batch of new vulnerabilities has drawn a mea culpa from Ivanti’s CEO, and a promise to embrace secure-by-design methodologies.
NBN HFC users can expect a speed boost from May 1
NBN HFC customers should soon see a considerable speed boost, with NBN Co removing a speed cap that applies to its wholesale product. Until now, HFC services have been subject to a Layer 2 network management configuration that applied a maximum sustained information rate (MSIR) of 750Mbps. The purpose of this was to manage capacity in the HFC network.
Diabetes WA reveals data breach
Diabetes WA has disclosed a data breach affecting people who engaged with its telehealth service. In a breach notice posted Tuesday, the organisation said a “third party” gained “access to the personal information of some ... contacts.” The personal information possibly exposed in the breach includes name, address, date of birth, email, phone number, marital status, Indigenous status, referring doctor, type of diabetes, and Medicare number.
UTS to pilot cyber security training to nonprofit sector
The University of Technology, Sydney (UTS) is set to run a pilot program that makes cyber security education available to Australian non-profits in Indigenous, refugee and low socio-economic communities. The university is one of 11 recipients worldwide of funding from the Kyndryl Foundation. Established in September 2023 by IBM legacy infrastructure and services spin-out Kyndryl, the foundation’s initial focus is on cyber security activities.
HSBC fined for CDR breaches
HSBC Bank has been caught out by poor data quality, leading to fines for Consumer Data Right (CDR) breaches. The fines were announced by the Australian Competition and Consumer Commission (ACCC), which issued the bank with two infringement notices. The total paid by the bank was $33,000. The infringements “related to alleged failures by HSBC to disclose complete mortgage interest rate details and accurate credit card balances in response to separate requests for this data,” the ACCC said.
HSBC fined for CDR breaches
HSBC Bank has been caught out by poor data quality, leading to fines for Consumer Data Right (CDR) breaches. The fines were announced by the Australian Competition and Consumer Commission (ACCC), which issued the bank with two infringement notices. The total paid by the bank was $33,000. The infringements “related to alleged failures by HSBC to disclose complete mortgage interest rate details and accurate credit card balances in response to separate requests for this data,” the ACCC said.
NSW Ambulance seeking decision support system
NSW Ambulance is going to market for a real time decision support system, to assist the dispatch and resourcing decisions currently made solely by humans.
Aussie Broadband sells down Superloop stake
Aussie Broadband is selling down part of its 19.9 percent stake in Superloop, after legal action to maintain the shareholding failed. The retail service provider bought the shares as part of an unsolicited takeover bid for Superloop that it made in late February. Superloop’s board turned down the offer, which valued the company at $466 million, saying it was “opportunistic and fundamentally undervalues Superloop”.
Curious engineer catches backdoor in Linux compression package
A curious Microsoft engineer has turned up a backdoor in the nearly-ubiquitous open source XZ Utils package that’s set Linux maintainers into a patching frenzy. Andres Freund, who describes himself on LinkedIn as a “PostgreSQL developer and committer”, investigated an approximately 500ms performance issue with the liblzma library. His investigation, outlined in a post to Openwall, led him to discover the backdoor, which is deployed by an obfuscated script in the build chain.
TPG Telecom, UTS test 5G signals as flood sensors
Radio signal propagation on TPG Telecom’s 5G network will be used to gather data about floods, in a trial with the University of Technology, Sydney (UTS). The university and the telco have created the 5G Network Sensing Lab to create the technology, which is being tested on the Parramatta River and Georges River. The lab opened last week with a demonstration of the technology. The prototype measures how 5G signals propagate to gather weather information like rainfall, water levels and river flows.
Senate to probe 3G network shutdown
The Australian Senate has opened an inquiry into the shutdown of Telstra’s and Optus’s 3G networks – but it is not due to make findings until after the networks are scheduled to close. The end of 3G has become contentious because some 4G handsets use 3G for Triple Zero calls, rather than voice-over-LTE (VoLTE).
Australian supermarkets, transport next for cyber exercises
Food and grocery, finance, and transport will be the next three industries to have their cyber security tested under the government’s National Cyber Security Exercise program. Cyber security coordinator Lieutenant General Michelle McGuinness.
Telstra explains why Triple Zero transfers failed
Telstra has partly attributed its March 1 Triple Zero outage to software that unexpectedly failed while medical support devices were logging into its network. During the 90-minute outage, calls had to be manually transferred to emergency services, with 148 transfers failing and one Victorian man dying of a cardiac arrest.
Gigabit NBN services boosted by flat-rate pricing
Users of NBN Co's up-to-gigabit broadband services have enjoyed less variable, faster peak-hour speeds after backhaul bandwidth charges were removed last year. The Australian Competition and Consumer Commission (ACCC) published its regular Measuring Broadband Australia (MBA) report [pdf], which showed the end of backhaul charges on plans of 100Mbps and above had the greatest impact on NBN Co's highest-speed services.
University of Canberra sets aside $30 million to kick off 10-year digital plan
The University of Canberra has launched a 10-year digital masterplan (DMP) that will fund key projects in cyber security, platform modernisation and data quality. CDO Craig Mutton launches the DMP University of Canberra After more than a year of development, the plan lays out 68 initiatives to be undertaken in the DMP’s first three years, backed by a $30 million funding commitment.
South East Water creates CISO position
Major Victorian water retailer South East Water is recruiting for a newly created chief information security office (CISO). Reporting to the chief information officer, the CISO will be tasked with building and leading a security team for the government-owned utility, which covers an area from South-East Melbourne to Gippsland. The company delivers fresh water, recycled water, and sewage services to the 1.8 million people in its catchment.
Python supply chain exploited to distribute malware
A Python coding community is undergoing a software supply-chain attack, with threat actors targeting the 170,000-strong Top.gg GitHub organisation with malware. Top.gg began life as Discord Bots, promoting the work of developers in the Discord ecosystem and hosting millions of bots.
Cyber Security NSW sees better ways to improve council security than audits
Cyber Security NSW has taken aim at the way councils' security is being assessed, seeing regular maturity and compliance audits as an ineffective way to improve security in the sector. The agency's comments came after the release of a regular audit [pdf] of a sample of councils and their cyber security postures and practices.
Government will make digital ID voluntary
The government has accepted coalition and Greens calls for its digital ID to be made explicitly voluntary, with finance minister Katy Gallagher announcing amendments to the digital ID bill that will be brought to the senate this week. The voluntary requirement was proposed earlier this month in dissenting reports to the senate committee examining the bill.
Telstra goes live with Starlink for homes
Telstra has kicked off its Starlink-powered home broadband service after months of “comprehensive testing”. The telco first announced its tie-up with Starlink in June last year, and at that time said it expected to launch services before the end of the year. The $125 a month (plus $599 for hardware) Telstra Satellite Home Internet service targets customers in the NBN Sky Muster footprint with a low-latency, high speed service.
ACMA braces for battle over 6GHz spectrum Original
The Australian Communications and Media Authority (ACMA) is gearing up for a battle between wi-fi businesses and carriers over the future of a key chunk of radio spectrum. ACMA today kicked off its next five-year planning project, publishing a draft five-year spectrum outlook, which will, among other things, determine the use of the upper 6GHz frequency band.
"Unpatchable" vulnerability found in Apple's silicon
A group of US academics has demonstrated a side-channel attack against Apple’s M-series silicon, extracting keys from constant-time encryption processes. The attack, which the researchers dubbed GoFetch, works against “data memory-dependent prefetchers” (DMPs). DMPs are a hardware optimisation technique which try to prefetch addresses found in program memory.
AWS linked to fresh $450m Sydney data centre build
A mystery $450 million 53-megawatt data centre to be built on Sydney's outskirts has links to Amazon Web Services' 'Project Echidna', suggesting that project is now worth some $750 million. iTnews first revealed the existence of 'Project Echidna' in June last year, tying it to a different $300 million, 35.2MW site in another part of Western Sydney. It appears Project Echidna's scope has either grown in size or was always anticipated to be an umbrella project for several data centre builds.
SA education system rollout stalls at high schools
South Australia’s education management system (EMS) rollout has only reached half of the state’s 900 schools but spent 70 percent of its budget spent, meaning an additional $47 million will be needed to complete the project. The project is anticipated to run three years behind the expected 2023 completion date, based on when the state's auditor general last reported [pdf] on the rollout in 2019. The final price is likely to top $169 million.
Telstra finds its next networks and technology boss
Telstra has named Shailin Sehgal as its new networks and technology boss, succeeding Nikos Katinakis who left late last year. Shailin Sehgal Telstra Sehgal is being promoted from his current position leading Telstra’s network, applications and cloud engineering team, where he worked on fixed and wireless technology, and cloud-hosted products and services, including security services.
Atlassian's Bamboo has critical SQL injection vulnerability
Atlassian’s monthly security roll-up includes a patch for a critical SQL injection vulnerability in its Bamboo data centre and server products. The critical vulnerability is CVE-2024-1597, in the PostgreSQL JBDC driver. It only affects PostgreSQL if PreferQueryMode is set to “simple”, which is not the configuration Atlassian uses.
John Holland joins Microsoft 365 Copilot early access program
A 2023 trial of ChatGPT convinced construction heavyweight John Holland Group that it could find a place in its business for AI and led to it signing on to trial Microsoft’s Copilot. John Holland said its early AI experiences had saved uses between 30 and 60 minutes a day, or as much as 10 hours per month.
Legacy spectrum licenses could return to market from 2028
Radio spectrum used for wireless broadband, rail safety, and electronic news gathering could be up for grabs after 2028. The licenses in question were issued between 2008 and 2012 for 20 years, and as expiry draws close, the Australian Communications and Media Authority needs to decide whether it’s best to renew them in part or full, or put them back on the market.
ATO farewells long-time CIO
The Australian Tax Office’s long-time head of technology, chief information officer (CIO) and second commissioner, Ramez Katf, will be leaving the agency on April 30. Ramez Katf ATO Katf has held the CIO role since 2015, and in May 2017, added second commissioner of enterprise solutions and technology to his remit. His impending departure was first reported by The Mandarin. Before joining the ATO, he had been an Accenture managing director for more than 29 years.
Queensland emergency services to get consolidated rostering
Rostering and other personnel systems covering more than 36,000 Queensland emergency services staff are to get a major uplift, under a tender released yesterday. The tender seeks a single software-as-a-service system, first for the Queensland Ambulance Service, but for eventual rollout to Queensland Fire and Emergency Services, Queensland Corrective Services, and Queensland Police.
Macquarie University hiring CISO
Macquarie University is looking for a permanent replacement for former chief information security officer (CISO) Jeremy Koster, who left in July 2023. The rule is currently held in an acting capacity by Shad Thakkar. The permanent CISO will “develop and implement Macquarie University's information technology (IT) security strategy whilst protecting the business from information security breaches and cyber environment threats", according to a recruitment advertisement.
NSW Telco Authority seeks disaster connectivity kits for communities
The NSW government is acquiring mobile systems to help provide wi-fi connectivity to communities cut off by natural disasters. The kits were a commitment made by customer service minister Jihad Dib in June 2023. Under that project, the commonwealth and NSW governments are co-funding the $3.6 million provision of community connectivity kits, that could be quickly deployed by the NSW Telco Authority to communities cut off by a natural disaster.
Epic Games lawsuit kicks off in Australia
Epic Games’ competition lawsuit against Apple and Google has finally opened in the Federal Court, with lawyers kicking off day one of an expected two weeks of opening submissions. The case follows similar ones overseas, launched after the two giants pushed the publisher of Fortnite off their app stores for using its own in-app payment system. The Australian case has been on hold awaiting the outcome of Epic’s US lawsuits.
NSW Telco Authority seeks disaster connectivity kits for communities
The NSW government is acquiring mobile systems to help provide wi-fi connectivity to communities cut off by natural disasters. The kits were a commitment made by customer service minister Jihad Dib in June 2023. Under that project, the commonwealth and NSW governments are co-funding the $3.6 million provision of community connectivity kits, that could be quickly deployed by the NSW Telco Authority to communities cut off by a natural disaster.
ACCC examines AI's influence on internet search
The Australian Competition and Consumer Commission is examining the impact of generative AI on internet search. The technology's introduction is likely the only significant change in the search landscape since the ACCC’s interim Digital Platforms Report, which found Google to be the dominant search engine in Australia due to its command of the Android operating system and its payments to Apple to be the default search on the Safari browser.
Queensland Rail is replacing its CIDO
Queensland Rail is in the process of replacing its chief information and digital officer (CIDO) following the departure of Boon Beh at the end of last year. Beh left in November 2023 after three-and-a-half years in the role, returning to Incitec Pivot as its CIO. The CIDO position is currently held by Arnaud Franjou in an interim capacity.
Show More
loading
Actions
Get in touch with Richard
Contact Richard, search articles and posts on X, monitor coverage, and track replies from one place.
Learn more about Muck Rack