PODCAST · technology
Tech Talks With Kinsoft
by Steven Kinnas
Tech Talks with Kinsoft is your insider pass to the ever-evolving world of technology. We break down the latest in tech news, cybersecurity trends, and emerging innovations shaping our digital future. Whether you’re a seasoned IT pro, a curious techie, or a business leader navigating digital transformation, our conversations are packed with insights, real-world takeaways, and a healthy dose of tech-savvy clarity. Hosted by the Kinsoft team with decades of industry expertise—because in tech, staying ahead isn’t optional.
-
30
Last Week in Tech – The AI Capex Reckoning, AMD's Anthropic Deal, and WordPress Under Attack
The market finally asks AI to show its receipts. This week: Alphabet and Tesla beat on revenue but get hammered for record capex — the Nasdaq's worst day since April — while Intel posts its best growth since 2011; AMD and Anthropic strike a 2-gigawatt GPU deal with up to US$5B in equity; the "wp2shell" WordPress core flaws go from patch to mass exploitation in 48 hours; a 7,600-repository GitHub campaign booby-traps fake AI agent integrations — and AI coding assistants recommend them to victims; Anubis claims the Fairlife ransomware attack (unverified); and DeepSeek V4 arrives with API surge pricing. Practical takeaways for Australian businesses throughout.Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: CNBC (Alphabet/Tesla/Intel earnings, AMD–Anthropic), AMD investor relations, SecurityWeek & Rapid7 & Qualys (wp2shell), The Hacker News & BleepingComputer (FakeGit/AgentBaiting, Anubis–Fairlife), DeepSeek API reporting.
-
29
Coca-Cola's Fairlife – The Ransomware Attack That Stopped the Milk
This week's global deep-dive is about ransomware you can see on a supermarket shelf. On 16 July, Coca-Cola disclosed in a formal SEC filing that its billion-dollar dairy subsidiary Fairlife had been hit by a ransomware event that reached production-related systems — and that all US production of Fairlife products had been temporarily suspended, while Canadian lines kept running. No criminal group has claimed the attack, and whether data was stolen or a ransom demanded remains unknown. We use the incident to unpack the difference between IT and OT — office systems versus the systems that run machines — why ransomware that touches the factory floor is measured in stopped lines rather than encrypted files, what Coca-Cola's fast, formal disclosure got right, and how any business that makes, moves or sells physical things should think about segmentation, continuity and the "can we run without the computers?" question.Could your operations keep moving if ransomware reached the systems that run them? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: SEC 8-K filing (Coca-Cola); BleepingComputer; TechCrunch; Help Net Security.
-
28
Partnered Health – A GP Network Breach, 21 Clinics, and a Court Order Against Criminals
This week's Australian deep-dive is a confirmed breach at Partnered Health, the operator of more than 60 medical, skin-cancer and allied-health clinics nationwide. An intruder detected on 23 June stole personal and health information tied to 21 named clinics across five states and territories — names, dates of birth, Medicare and health-insurance numbers, and in some cases consultation notes, referral letters and pathology results. Patients were notified from around 15 July, some 22 days after detection, and the company took the unusual step of obtaining a NSW Supreme Court injunction barring use or publication of the stolen data — a tactic security experts openly question. We walk the timeline, weigh what an injunction against anonymous offshore criminals can and can't achieve, and pull out the lessons: why health data is the crown jewel of stolen identity, what a good notification looks like, and the questions every practice — and every patient — should be asking.Does your organisation hold health or identity data it couldn't afford to lose? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: ACS Information Age; SBS News; DataBreaches.net; The Cyber Express; EFTM.
-
27
Last Week in Tech – China's Open-Source Shock, TSMC's Record Quarter, and a 570-Flaw Patch Tuesday
Your Monday catch-up on the week in tech, with a security lens. China's Moonshot AI releases Kimi K3 — the largest open-weight model ever, at 2.8 trillion parameters — and chip stocks shudder in a DeepSeek-style sell-off. The AI build-out rolls on regardless: TSMC posts a record quarterly profit, up 77 per cent, and adds another 100 billion US dollars to its Arizona plans, a day after ASML lifts its full-year outlook. The first Nvidia H200 chips ship to China under new licences even as Nvidia halves its approved Asian buyer list. And a report says Meta is weighing leasing Anthropic up to 10 billion dollars of compute — early talks only, and we flag it as such. On the security desk: Microsoft's biggest-ever Patch Tuesday fixes 570 flaws including two zero-days under active attack, a separate perfect-storm SharePoint flaw (CVE-2026-58644) draws a three-day CISA patch deadline, and the US, EU and UK launch their first joint cyber-sanctions package against the Russian ransomware ecosystem.Wondering what any of this means for your patch queue or your AI plans? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Bloomberg; CNBC; Axios; SCMP; SEC filings; DigiTimes; Reuters; CNN Business; BleepingComputer; CrowdStrike; CISA; Rapid7; SecurityWeek; The Hacker News; The Record; Chainalysis.
-
26
AssuranceAmerica – One Stolen Password, Seven Million Exposed
A global breach that turned on the most ordinary failure there is — one stolen employee login. US auto insurer AssuranceAmerica has begun notifying almost seven million people that attackers used a single compromised staff credential to copy files containing names, policy details, driver's-licence numbers and — per state regulator filings — Social Security and tax ID numbers, in what's reportedly the largest exposure of American driver's-licence numbers this year. We walk the timeline from the 16 March credential theft to the 10 July notifications, weigh a nearly four-month disclosure gap and a notably lean response, and draw out the lessons: mandatory multi-factor authentication, collecting and keeping less identity data, and why how you treat people after a breach is part of security, not an afterthought.Do you know whether one stolen password could reach your crown jewels? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: BleepingComputer; TechCrunch; Cybernews; SecurityWeek; Techlicious.
-
25
Teletrac Navman – 3,000 Fleets' Live GPS Data Allegedly Up for Sale
An alleged Australian breach that turns a mundane operational tool into a physical-safety question. A criminal on a hacking forum claims to have captured a live, 48-hour feed of real-time GPS data from fleet-telematics provider Teletrac Navman — allegedly covering nearly 3,000 customer organisations across Australia and New Zealand, more than 30,000 vehicles, and thousands of named drivers, with a sample said to name councils, rail operators and a mining giant. Teletrac Navman has not confirmed the breach and the OAIC would not confirm a notification, so we hold a hard line between the seller's claims and confirmed fact — and use the story to unpack why location data is some of the most sensitive you hold, the risk of concentrating it in one shared platform, and the questions to put to your providers.Worried about the location and telematics data flowing through your business? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Cyber Daily; ACS Information Age; Daily Dark Web.
-
24
Last Week in Tech – The AI Boom's Memory-and-Power Bill, Microsoft's 4,800 Cuts, and a Perfect-10 ColdFusion Flaw
Your Monday catch-up on the week in tech, with a security lens. This week the real AI story wasn't a model — it was the physical bill coming due. Samsung posts a record quarterly profit, up nearly nineteen-fold, on AI-memory demand; SK Hynix raises around 29 billion dollars in one of the biggest-ever US share listings; and Britain's National Grid tips 1.75 billion into a US power project built to feed a single Microsoft data centre. Microsoft cuts about 4,800 jobs and overhauls Xbox as it reallocates toward AI. Europe's top court makes Google's 4.1-billion-euro Android fine final. And on the security desk: a perfect-10 Adobe ColdFusion flaw (CVE-2026-48282) is exploited within two hours of disclosure and draws an emergency CISA patch order, Accenture confirms a breach after a criminal offers stolen data for sale, and INTERPOL's Operation First Light nets 5,811 arrests and 293 million dollars.Trying to work out what all this means for your hardware budget and your patch queue? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Reuters; CNBC; Bloomberg; Samsung; TechCrunch; DataCenterDynamics; Adobe; CISA; BleepingComputer; SecurityWeek; Help Net Security; INTERPOL.
-
23
DHS HSIN – When "Unclassified" Doesn't Mean "Low Risk"
A breach at the heart of America's homeland-security apparatus - and a masterclass in why "unclassified" is not the same as "unimportant." The US Department of Homeland Security has confirmed that attackers broke into the Homeland Security Information Network, or HSIN - the platform it uses to share sensitive-but-unclassified information with thousands of federal, state, local and private-sector partners, and one currently helping coordinate security for the 2026 World Cup. Classified systems were untouched, but what the intruders took, and who they are, remains unknown. We dig into the danger of "sensitive-but-unclassified" data, why legacy collaboration systems are prime targets, and how to communicate honestly when you know attackers got in but not yet what they took.Do you know how your own data is classified - and protected accordingly? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: BleepingComputer; Nextgov/FCW; TechCrunch; PYMNTS; UpGuard.
-
22
Reynella East College – Interlock's First Australian Victim Dumps 600GB of School Data
A confronting Australian breach that puts schools squarely in the firing line. Reynella East College - a public preschool-to-Year-12 school in Adelaide's south with more than 1,900 students - took its computer systems offline for a week after a cyber security breach, and weeks later the ransomware group Interlock dumped what it claims is 610 gigabytes of stolen data on the dark web. It's Interlock's first known attack on an Australian organisation, and a review of the leak reportedly turned up passport scans of international students and staff and lists of passwords stored in plain text. We unpack how schools became fair game, why identity documents and cleartext passwords are the worst possible things to lose, and how to tell what's confirmed from what's just a criminal's claim.Worried about what's sitting in your own file shares? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Cyber Daily; Comparitech; Insurance Business Australia; EducationHQ; ransomware.live.
-
21
Last Week in Tech – Big Tech's "We'll Build It For You" Land Grab, a Cheaper Claude, and a CitrixBleed Sequel
Your Monday catch-up on the week that was in tech, with a security lens. This week: the AI giants pivot from selling software to selling people - Microsoft stands up a 2.5-billion-dollar "Frontier Company" to embed its own engineers inside your business, just two days after Amazon committed a billion to the same idea. Anthropic ships Claude Sonnet 5, a cheaper model built to run autonomous agents. Money keeps pouring into the AI plumbing, with Together AI raising 800 million and Meta reportedly building a cloud business of its own. And on the security desk: a CitrixBleed-style flaw in NetScaler is exploited within a day of its patch, researchers document the first ransomware run end-to-end by an AI agent, and a 19-year-old alleged member of Scattered Spider is extradited to the US.Trying to work out what all this means for your own tech stack and your patch queue? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: CNBC; TechCrunch; GeekWire; Anthropic; Bloomberg; Business Wire; SecurityWeek; The Hacker News; BleepingComputer; Sysdig; watchTowr; US Department of Justice.
-
20
Nissan – ShinyHunters Turn an Oracle Zero-Day into a Payroll Nightmare
The Oracle PeopleSoft campaign we've been tracking just claimed a big-name victim. Nissan has disclosed that employee data across the Americas — potentially including bank details, Social Security and national ID numbers — was stolen when the extortion crew ShinyHunters exploited a critical PeopleSoft zero-day. We break down CVE-2026-35273, the two-week window when attackers were inside before a patch even existed, why HR and ERP systems are crown-jewel targets, and the smart, concrete fraud controls Nissan put in place afterwards.Do you know what's exposed on your internet-facing enterprise apps? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: BleepingComputer; The Register; The Hacker News; Google/Mandiant.
-
19
Mackay Sugar – "The Gentlemen" Ransomware Halts Australia's Sugar Heartland
An Australian ransomware story you can taste. Mackay Sugar — the country's second-largest raw sugar producer — was hit by the ransomware crew "The Gentlemen" right at the start of the North Queensland crushing season, forcing shutdowns at two of its three mills and leaving 1,300-plus cane-farming families with nowhere to send their harvest. We unpack how an attack on IT systems becomes a physical, region-wide supply-chain problem, why critical infrastructure and agriculture are increasingly in the crosshairs, and what "operational technology" risk really means for Aussie businesses.Worried a cyber incident could stop your operations, not just leak your data? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: SecurityWeek; Cyber Daily; The Record; Mackay Sugar incident updates.
-
18
Generation Life – A Third-Party Breach Reaches the Financial Sector
Australian life-investment firm Generation Life has confirmed that some customers' personal information was caught up in a cyber attack it first disclosed back in April — an incident that came in through an external service provider and was later claimed by the Qilin ransomware group. We follow the long tail of a breach: how an April intrusion, a May leak-site listing and a late-June confirmation all belong to the same story, why third-party access is the recurring weak point, and what multi-regulator notification looks like for an APRA-regulated business.Do you know exactly what your service providers can reach? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Cyber Daily; Insurance Business Australia; Money Management.
-
17
Last Week in Tech – Anthropic vs Alibaba, OpenAI's Own Chip, and an Emergency Cisco Patch
Your Monday catch-up, with a security lens. This week: Anthropic takes an extraordinary allegation to US lawmakers, accusing Alibaba's Qwen team of the largest-ever "distillation attack" on Claude. OpenAI and Broadcom unveil "Jalapeño," OpenAI's first custom AI chip. Qualcomm spends nearly $4 billion buying Modular to chip away at Nvidia's CUDA lock-in. And CISA orders an emergency patch of an actively-exploited flaw in Cisco's phone-system software.Wondering whether that Cisco flaw affects you? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: CNBC; OpenAI; Bloomberg; CISA; BleepingComputer; The Hacker News; Help Net Security.
-
16
KDDI – One Flaw, Six ISPs, 14 Million Exposed Mailboxes
A single vulnerability in one shared platform cascaded across six Japanese internet providers, exposing up to 14.2 million email accounts. Telecoms giant KDDI has confirmed a breach of a shared email system used by KDDI, JCOM, NIFTY, BIGLOBE and others — an intrusion via a flaw in third-party software. We look at "shared-infrastructure blast radius": how concentration risk turns one weakness into millions of victims, why exposed email logins are gold for credential-stuffing, and the transparency questions KDDI has left unanswered.Do you know how many of your services depend on one shared platform? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: BleepingComputer; SecurityAffairs; The Japan Times.
-
15
NSW Rural Fire Service – Nova Ransomware Hits an Emergency Service
The NSW Rural Fire Service — the world's largest volunteer fire service — has confirmed a cyber security incident, reported as Australia's first confirmed ransomware attack on a government agency in 2026. The entry point? A single compromised account and the remote-access system behind it. The ransomware crew "Nova" claims to have stolen 300 gigabytes of data — a figure the RFS has not confirmed. We dig into the compromised-account-plus-remote-access playbook, and the very real gap between what an attacker claims and what a victim can verify.Is your remote access as locked down as you think? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Cyber Daily; Comparitech; ACS Information Age.
-
14
Last Week in Tech – SpaceX Buys Cursor for $60B, Washington Pulls Anthropic's Top Models, and the Klue Breach Spreads
Your Monday catch-up, with a security lens. This week: SpaceX makes the largest startup acquisition in history, buying AI-coding company Cursor for around $60 billion in stock — days after its own IPO. Washington uses export-control powers to force Anthropic to pull its most powerful models on national-security grounds. The Klue OAuth breach we flagged a fortnight ago balloons to nearly 200 companies, including a who's-who of security vendors. And world leaders sit down with AI's biggest names at the G7, as SoftBank pledges €45 billion for French data centres.Trying to work out what all this AI consolidation means for your own tech stack? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: CNBC; TechCrunch; Fortune; SecurityWeek; BleepingComputer; Global Banking & Finance.
-
13
Texas Parks & Wildlife – 3 Million Licences Exposed in a Vendor Breach
A clean, cautionary supply-chain story from the US. The Texas Parks and Wildlife Department disclosed that attackers breached the third-party vendor processing its hunting and fishing licences, exposing personal data — including driver's-licence and passport numbers — for more than three million people. No ransomware, no dramatic leak site; just a quiet vendor compromise leaking exactly the kind of identity documents you can't change. We dig into why government-via-vendor breaches keep happening, and why passport and licence numbers are the data attackers now want most.Do you know what your third-party vendors can see? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: SecurityWeek; KXAN.
-
12
Mackay Sugar – "The Gentlemen" Ransomware Halts Australia's Sugar Heartland
An Australian ransomware story you can taste. Mackay Sugar — the country's second-largest raw sugar producer — was hit by the ransomware crew "The Gentlemen" right at the start of the North Queensland crushing season, forcing shutdowns at two of its three mills and leaving 1,300-plus cane-farming families with nowhere to send their harvest. We unpack how an attack on IT systems becomes a physical, region-wide supply-chain problem, why critical infrastructure and agriculture are increasingly in the crosshairs, and what "operational technology" risk really means for Aussie businesses.Worried a cyber incident could stop your operations, not just leak your data? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: SecurityWeek; Cyber Daily; The Record; Mackay Sugar incident updates.
-
11
Last Week in Tech – Apple's Gemini-Powered Siri, ShinyHunters Hit PeopleSoft, and the AI-Chip Land Grab
Your Monday catch-up on the week that was in tech, with a security lens. This week: Apple finally reveals its overhauled, AI-powered Siri at WWDC 2026 — running partly on Google's Gemini models. The AI infrastructure land grab heats up as Alphabet rents out its new TPUs in a $5B Blackstone joint venture and Microsoft ships its Maia 200 accelerator. Anthropic's Claude posts eye-watering growth and formalises a $100M partner program. And on the security desk: ShinyHunters exploit an Oracle PeopleSoft flaw to hit universities, Europol dismantles a €336M crypto-laundering pipeline used by ransomware crews, CISA flags three newly exploited vulnerabilities, and a new gang called The Gentlemen climbs the ransomware rankings.Want last week's headlines turned into a plan for your own environment? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Apple Newsroom; Engadget; CNBC; NPR; TechCrunch; Tech Startups; BuildFastWithAI; Europol; Google/Mandiant; CISA.
-
10
Under Armour Breach – 72 Million Customer Accounts Exposed
In a major global incident, the Everest ransomware group claimed sportswear giant Under Armour as a victim in late 2025, alleging access to around 343GB of data — and in January 2026 a dataset containing roughly 72 million customer email addresses (about 72.7 million accounts) was published on a hacking forum. In this episode of Tech Talks with Kinsoft, we cover the data involved — names, email addresses, dates of birth, locations and purchase information — the verification by services like Have I Been Pwned, the class-action lawsuits that followed, and Under Armour's response, including that it was investigating and found no evidence its payment-processing or password systems were affected. We flag where claims are alleged rather than confirmed.Worried about brand-scale breaches and protecting customer data? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: TechCrunch; Malwarebytes.
-
9
Champion Homes Data Breach – Inside the DragonForce Ransomware Attack
Sydney home builder Champion Homes has confirmed a cyber incident after the DragonForce ransomware group claimed responsibility for an attack that saw roughly 44GB of company data stolen and leaked to the dark web. In this episode of Tech Talks with Kinsoft, we unpack what happened: the data taken — including employee payroll records, customer quotes, and tender and legal documents — how DragonForce's ransomware-as-a-service model operates, and how Champion Homes contained the incident and notified the relevant authorities while continuing to operate across the Sydney and Illawarra regions.Concerned about your own exposure to ransomware and data breaches? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Cyber Daily; Real Estate Business.
-
8
Last Week in Tech – Copilot's Billing Backlash, SoftBank's €75B France Bet, and the Klue OAuth Supply-Chain Hit
Your Monday catch-up, with a security lens. This week: GitHub Copilot switches to token-based billing and developers revolt over surprise bills, Microsoft shows off a cheaper homegrown coding model at Build, and SoftBank commits up to €75B to AI data centres in France — Europe's biggest such bet. On the breach desk: an OAuth attack on sales-intelligence firm Klue cascades into Salesforce data theft across HackerOne, Gong, OneTrust, Tanium and Huntress; Nintendo is hit by ransomware; and Oxford's careers platform is breached. The OAuth supply-chain pattern is the one to watch.Using connected SaaS apps and OAuth integrations? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: BuildFastWithAI; Medium (David Akpovi); imfounder; SharkStriker; The Hacker News.
-
7
Charter/Spectrum – ShinyHunters Vishing Breach
Charter Communications (Spectrum) confirmed in late May 2026 that it had suffered a data breach after ShinyHunters claimed to have stolen customer records; roughly 4.9 million accounts had personal details exposed (the group claimed far more from Charter's Salesforce). ShinyHunters says it used a vishing call on 1 April 2026 to trick a Charter employee into surrendering Microsoft Entra access, then reached Salesforce data. We tie it to the broader ShinyHunters Salesforce and SSO campaign and the recurring vishing playbook.Want to harden your identity provider against vishing? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Security Affairs; Techlicious.
-
6
Gelatissimo Data Breach – DragonForce and the 352GB Heist
In April 2026, the DragonForce ransomware group claimed it breached Gelatissimo, the Australian artisanal gelato franchise, and listed the company on its dark web leak site. In this episode of Tech Talks with Kinsoft, we cover what the group alleges it took — around 352GB of data, with sample screenshots showing employee payroll details, partial tax file numbers, and a visa application containing a passport number — the extortion threat to publish the data, and Gelatissimo's response, including engaging cyber security experts and notifying the OAIC and the Australian Cyber Security Centre. We flag throughout where claims are alleged rather than confirmed.Worried about ransomware and the safety of your staff and customer data? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Cyber Daily; ACS Information Age.
-
5
Last Week in Tech – Anthropic's $900B Round, AI Guardrails Stripped in Minutes, and Trellix's Source-Code Breach
Your Monday catch-up, with a security lens. This week: Anthropic is reportedly closing a $30B round at a $900B-plus valuation and projecting its first-ever quarterly operating profit — even as SpaceX filings reveal eye-watering compute bills. The politics heat up as President Trump abruptly cancels an AI executive order. A worrying safety finding shows researchers stripping the guardrails off major AI models in minutes. And on the breach desk: security vendor Trellix has attackers in its own source code, drug-delivery manufacturer West Pharmaceutical recovers from a crippling attack, and education-sector attacks jump again.Concerned your security tools themselves could be a target? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Tech Startups; BuildFastWithAI; Bloomberg; Comparitech; cm-alliance.
-
4
Carnival Corporation Breach – 6 Million Cruise Customers Exposed
On 14 April 2026, Carnival Corporation detected unauthorised activity after a bad actor used social engineering to compromise an employee account. In this episode of Tech Talks with Kinsoft, we cover the global breach that affected roughly 5,995,277 individuals — almost 6 million — the categories of data potentially involved, the timeline through to the company's customer notifications and dedicated breach webpage on 27 May 2026, and the support offered including complimentary credit monitoring. It's a reminder that human-targeted attacks remain one of the most effective ways in.Worried about social engineering and account takeover? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: News4Jax; Hoplon InfoSec.
-
3
VSP Solutions – Stormous Hits a Security-Hardware Distributor
VSP Solutions, a NSW distributor of video-security hardware (Hikvision, Axis and similar), became aware of an incident on 13 May 2026; the Stormous group listed it on 23 May claiming 40 GB+ including financial backups, email archives, staff folders and customer and client databases. VSP's position is that the affected data was historical and related-business and that current operations were unaffected. A lens on distributor and supply-chain risk and protecting archived data.Sit in someone's supply chain? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Cyber Daily.
-
2
Last Week in Tech – Google's Agentic Gemini, the Coding-Agent Gold Rush, and CISA's Own Key Leak
Your Monday catch-up, with a security lens. This week: Google goes all-in on agents at I/O 2026 with Gemini 3.5 and a new any-input video model, Gemini Omni. Three rival coding agents launch in three days as the price of frontier coding power keeps falling. SpaceX's S-1 lifts the lid on xAI's finances, and Anthropic teams up with the Gates Foundation on a $200M global-development push. On security: a CISA contractor accidentally exposes AWS GovCloud keys on a public GitHub repo, Canadian police arrest the alleged operator of a massive IoT botnet, and a Vietnamese government network is breached.Building or buying AI tools and not sure how to keep your secrets out of public repos? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Tech Startups; Medium (David Akpovi); Digital Applied; The Hacker News; cm-alliance.
-
1
Brightspeed – Crimson Collective Claims 1M+ Records
In early January 2026, fiber-broadband provider Brightspeed opened a cybersecurity investigation after a group calling itself Crimson Collective claimed via Telegram (4 January) to have stolen data on more than 1 million customers, sharing screenshots and small samples as purported proof. The claimed data included account master records — names, emails, phone numbers, billing and service addresses and account metadata — with the group alleging payment histories and masked card details may have been accessed. As of mid-January the company had not confirmed exfiltration or a production-system compromise; the claims remained unverified, and class actions followed. We cover how to assess unverified extortion claims.Unsure whether a leak claim against you is real? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: SecurityWeek; eSecurity Planet.
-
0
Goodstone Group Breach – Passport Scans Leaked in CMD Ransomware Attack
In May 2026, Tasmanian hospitality group Goodstone Group — which runs hotels, restaurants, bars and bottleshops across northern Tasmania — confirmed it was responding to a cyber incident after the CMD Organization ransomware group listed it on a dark web leak site. In this episode of Tech Talks with Kinsoft, we cover the sensitive material the attackers published as proof, including employee passport scans, a confidentiality agreement and bank reconciliation details, the roughly $1 million (9 BTC) extortion demand, and the company's response as it engaged security experts and authorities.Worried about ransomware hitting your business? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Cyber Daily.
-
-1
Last Week in Tech – AI Writes Its First Zero-Day, OpenAI's Deployment Play, and the Canvas Mega-Breach
Your Monday catch-up on the week that was, with a security lens. This week: researchers document the first known case of attackers using AI to develop a working zero-day exploit. OpenAI launches a $4B Deployment Company and buys consultancy Tomoro to get AI into enterprises faster, while SoftBank pours money into AI data centres and batteries. On the breach desk: ShinyHunters complete what's now called the largest education-sector breach on record, defacing Canvas login portals at around 330 institutions — including Harvard and Princeton — before Instructure paid up. Plus Washington turns up the heat on AI, with the Pentagon flagging a major AI lab as a supply-chain risk.Worried about AI-accelerated attacks on your own systems? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Tech Startups; Coaio; cm-alliance; SharkStriker; TechCrunch.
-
-2
McGraw Hill – 13.5M Exposed via Salesforce Misconfig
Edtech giant McGraw Hill confirmed a breach (dated around 10 April 2026, surfacing mid-April) after ShinyHunters' extortion threat; about 13.5 million accounts were exposed — emails, names, phone numbers and physical addresses — via a Salesforce misconfiguration. When negotiations failed, the group published over 100 GB of data. McGraw Hill said the exposed data was limited and did not include Social Security numbers, financial information or student data from its learning platforms. We discuss misconfiguration risk and the limits of non-sensitive data.Need a configuration and exposure review of your SaaS estate? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: BleepingComputer; The Register.
-
-3
Energy Action Breach – SafePay Ransomware Targets an Energy Giant
In early May 2026, the SafePay ransomware group listed Energy Action — an Australian firm that manages energy procurement for a large share of the country's commercial businesses — on its dark web leak site, threatening to release stolen data. In this episode of Tech Talks with Kinsoft, we cover what Energy Action does, the kind of data potentially at risk, the fact that the volume and specifics had not been confirmed, and background on SafePay, an active global threat that notably does not operate as ransomware-as-a-service. Throughout, we flag where claims are alleged rather than confirmed.Concerned about ransomware exposure in your business or supply chain? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Cyber Daily.
-
-4
Last Week in Tech – Microsoft's Agents Go GA, the Canvas Mega-Breach Escalates, and DigiCert's Cert Compromise
Your Monday catch-up, with a security lens. This week: Microsoft makes its AI agents generally available at Build, and the ShinyHunters Canvas breach escalates into what's being called the largest education-sector breach on record. On security: certificate authority DigiCert is socially engineered into issuing fraudulent code-signing certs, and Zara and an NVIDIA cloud-gaming partner are breached.Confident your staff can't be talked into handing over access? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Microsoft; The Hacker News; CNN; Comparitech; CM-Alliance.
-
-5
Medtronic – ShinyHunters Hits a Medical-Device Giant
ShinyHunters listed Medtronic on its leak site on 17 April 2026, claiming more than 9 million records; Medtronic confirmed the breach on 24 April alongside an SEC Form 8-K, stating an unauthorized party accessed data in certain corporate IT systems. Potentially affected data included names, addresses, certain medical details, billing and health-insurance information, demographics and Social Security numbers. Medtronic said it found no impact to products, patient safety, manufacturing and distribution or financial-reporting systems. We place it in ShinyHunters' wider Salesforce and SSO extortion campaign.Worried about corporate-IT and Salesforce exposure? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: SecurityWeek; Infosecurity Magazine.
-
-6
Canvas LMS Data Breach – Australian Schools and Universities Hit
In May 2026, Instructure disclosed a cyber security incident affecting Canvas, the learning management platform used widely across Australian universities, vocational providers and schools. In this episode of Tech Talks with Kinsoft, we cover the categories of data involved — names, email addresses, student ID numbers and messages between users — Instructure's statement that it found no evidence passwords, dates of birth, government IDs or financial information were taken, the scale of the impact on Australian education, and the OAIC and institutional response, including guidance for affected students and staff.Reviewing your own vendor and platform security? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: OAIC; University of Canberra.
-
-7
Last Week in Tech – OpenAI Breaks Its Microsoft Lock-In, Big Tech's $650B AI Bill, and the Salesforce Breach Wave
Your Monday catch-up, with a security lens. This week: OpenAI loosens its Microsoft exclusivity and goes live on AWS, and Big Tech's quarterly earnings push combined AI spending toward $650–700B for the year. On the breach desk: the ShinyHunters Salesforce-theft wave rolls on through Amtrak, Pitney Bowes and Vimeo, while a Hungarian media giant loses 8.5 terabytes.Worried about what's connected to your Salesforce or CRM? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: CNBC; TechCrunch; VentureBeat; Quartz; Fortune; CM-Alliance.
-
-8
France's ANTS ID Registry – 11.7M Accounts Exposed
France's ANTS (Agence nationale des titres sécurisés / France Titres), the Interior-Ministry body managing ID cards, passports, driver's licences and immigration documents, detected a security incident around 15 April 2026 on its ants.gouv.fr portal. ANTS confirmed about 11.7 million accounts were impacted (a threat actor claimed up to 19 million). Exposed data reportedly included full names, contact details, dates of birth, home addresses and civil-status information. Researchers traced it to a basic Insecure Direct Object Reference (IDOR) flaw in the ANTS API; ANTS notified the CNIL, ANSSI and the Paris prosecutor. We explain IDOR in plain terms and the identity-theft risk.Building or running citizen-facing portals and APIs? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: TechCrunch; Help Net Security.
-
-9
Gregory Jewellers Data Breach – Kairos Ransomware Claims 574GB
In April 2026, the Kairos ransomware group claimed responsibility for breaching Gregory Jewellers, an Australian family-owned luxury jewellery retailer, alleging it stole roughly 574GB of data and listing the company on its dark web leak site. In this episode of Tech Talks with Kinsoft, we cover what the attackers say they took — client personal information, internal corporate records and customer details — how Kairos has been targeting Australian organisations, and the company's response as it works with specialists and notifies authorities and affected customers.Concerned about ransomware and data theft in your business? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Cyber Daily.
-
-10
Last Week in Tech – Meta's 8,000 Job Cuts, Medtronic's Breach, and a $290M Crypto Heist
Your Monday catch-up, with a security lens. This week: Meta cuts around 8,000 jobs to fund its AI build-out. On the breach desk it's a heavy week — Medtronic confirms a breach via an SEC filing, the Everest gang leaks two US banks through a shared vendor, North Korea-linked attackers pull off a $290M crypto heist, and ADT confirms customer data was stolen.Is a shared third-party vendor a hole in your defences? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Quartz; Axios; HIPAA Journal; TechCrunch; CM-Alliance.
-
-11
ADT – ShinyHunters Vishing Breach Hits 5.5M
Home-security firm ADT detected unauthorized access around 20 April 2026; the breach became public when extortion group ShinyHunters listed ADT on its leak site on 24 April with a pay-or-leak deadline. The confirmed breach affected about 5.5 million people — emails, names, phone numbers and addresses, and in a small percentage of cases dates of birth and the last four digits of SSN/Tax IDs. The attack reportedly began with a vishing call impersonating IT support to capture Okta single-sign-on credentials, then reached the company's Salesforce data. We cover the human-layer vishing risk and SSO exposure.Concerned your help desk could be social-engineered? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: BleepingComputer; BankInfoSecurity.
-
-12
NSW Treasury Insider Breach – 5,600 Sensitive Documents Exfiltrated
In April 2026, NSW Treasury disclosed a significant insider data breach: a staffer on its commercial team allegedly exfiltrated more than 5,600 sensitive government documents to an external server. In this episode of Tech Talks with Kinsoft, we cover how internal security monitoring flagged the suspicious transfer, the involvement of NSW Police, the arrest and charges, the confidential commercial and financial information involved, and the government's coordinated response — including that the data was recovered and public services were not disrupted.Worried about insider risk and data loss in your own organisation? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: iTnews; Cyber Daily.
-
-13
Last Week in Tech – Patch Tuesday's Two Zero-Days, Rockstar's Vendor Breach, and Amazon's $11.6B Satellite Bet
Your Monday catch-up, with a security lens. This week: Microsoft's Patch Tuesday fixes 167 flaws including two zero-days, Rockstar Games is breached through a third-party vendor, Amazon bids $11.6B for a satellite operator to take on Starlink, and Snap cuts a sixth of its staff citing AI.Are you patching the flaws attackers are already using? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: BleepingComputer; Krebs on Security; Tom's Hardware; TechCrunch; CNBC; Reuters.
-
-14
Booking.com – Hotel-Partner Breach Fuels Travel Scams
Around 13 April 2026 Booking.com began notifying customers that unauthorized third parties had accessed guest reservation data — not by breaching Booking.com directly, but by compromising hotel partner accounts (researchers point to ClickFix phishing of hotel staff, attributed to a group tracked as Storm-1865). Exposed data included booking details, names, email and physical addresses and phone numbers; financial information was not accessed. Criminals quickly used the details in convincing WhatsApp and SMS phishing referencing guests' real hotel, dates and booking references. We cover third-party and supply-chain risk and how to spot these scams.Worried about partner and supply-chain access to your data? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: TechCrunch; Help Net Security.
-
-15
3P Corporation – Space Bears Claims a Melbourne Finance Firm
The Space Bears ransomware group listed Melbourne financial-services firm 3P Corporation in early April 2026 (post dated 10 April; incident said to be 7 April), claiming 200 GB+ including a database, financial documents and personal information of employees and clients. 3P disputes this — it told Cyber Daily its systems stopped the attack before data was compromised. We present both sides and how to weigh contested leak-site claims.Hold sensitive client data in a small firm? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Cyber Daily; Accountants Daily.
-
-16
Last Week in Tech – Anthropic's Exploit-Writing Model, Meta Goes Closed-Source, and a Critical Notebook RCE
Your Monday catch-up, with a security lens. This week: Anthropic gives security partners early access to a frontier model so capable it wrote 181 working exploits on its own, Meta breaks from open-source with its first proprietary model, and Amazon and OpenAI flash eye-watering AI numbers. On security: a critical flaw in a popular Python notebook tool is exploited within hours.Patching open-source tools fast enough? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Fortune; Axios; TechCrunch; CNBC; SecurityWeek; The Hacker News; Reuters.
-
-17
Foster City, California – Ransomware Halts a City
On 19 March 2026, IT staff in Foster City, California identified ransomware on the city's networks. The city declared a local state of emergency and suspended most non-emergency services while 911 and police dispatch stayed functional; phone, email and online access were disrupted and government meetings moved in-person, with phone and email restored around 29 March. Officials warned that public information may have been accessed and urged anyone who had done business with the city to change passwords. We look at why small, budget-constrained municipalities are attractive ransomware targets and what resilience steps matter.Run a small council or local-government IT shop? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: GovTech; The Record (Recorded Future News).
-
-18
Qilin's WA Spree – Esperance Metaland
Part of the same early-2026 Qilin spree: Esperance Metaland, a Western Australian regional business, was added to Qilin's leak site on 21 February 2026. With little evidence published, the episode uses it to discuss the concentrated targeting of regional WA businesses and how to assess unverified leak-site claims calmly, plus practical defences.Worried a leak-site listing might name you next? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Cyber Daily.
-
-19
Last Week in Tech – OpenAI's $122B Round, Oracle's Mass Layoffs, and a Backdoor in a Top npm Package
Your Monday catch-up, with a security lens. This week: OpenAI closes a record $122B round, Oracle makes its largest-ever job cuts to fund AI, and Google ships open models that run on your phone. On the breach desk: North Korea-linked attackers backdoor the hugely popular "axios" npm package, and Apple patches a Spotlight flaw that could expose your files.Do you actually know what open-source packages your software depends on? Visit www.kinsoft.com.au to talk through your security and IT needs.Sources: Bloomberg; CNBC; TechCrunch; Reuters; Android Authority; The Verge.
We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.
No matches for "" in this podcast's transcripts.
No topics indexed yet for this podcast.
Loading reviews...
ABOUT THIS SHOW
Tech Talks with Kinsoft is your insider pass to the ever-evolving world of technology. We break down the latest in tech news, cybersecurity trends, and emerging innovations shaping our digital future. Whether you’re a seasoned IT pro, a curious techie, or a business leader navigating digital transformation, our conversations are packed with insights, real-world takeaways, and a healthy dose of tech-savvy clarity. Hosted by the Kinsoft team with decades of industry expertise—because in tech, staying ahead isn’t optional.
HOSTED BY
Steven Kinnas
CATEGORIES
Loading similar podcasts...