Tech Talks With Kinsoft

Steven Kinnas

Tech Talks with Kinsoft is your insider pass to the ever-evolving world of technology. We break down the latest in tech news, cybersecurity trends, and emerging innovations shaping our digital future. Whether you’re a seasoned IT pro, a curious techie, or a business leader navigating digital transformation, our conversations are packed with insights, real-world takeaways, and a healthy dose of tech-savvy clarity. Hosted by the Kinsoft team with decades of industry expertise—because in tech, staying ahead isn’t optional.

  1. 4 days ago

    Manchester Airports Group - 8.7 Million Travellers, and the API Keys Sitting in Plain Sight

    Manchester Airports Group – 8.7 Million Travellers, and the API Keys Sitting in Plain Sight A deep-dive into the largest known customer data breach at a British airport operator — and the claimed entry vector any developer could have spotted. On 27 August 2026, Manchester Airports Group (MAG) — operator of Manchester, London Stansted and East Midlands airports — disclosed that an unauthorised third party had stolen customer data from its commercial systems: car park bookings, lounges, Fast Track and Wi-Fi sign-ups. Roughly 8.7 million customers were affected. For most, the exposure was an email address; parking, lounge and Fast Track customers also lost phone numbers, UK postcodes and vehicle registration plates. No payment data was held in the affected system, and no airport operational systems were touched — flights ran normally. On 30 August, extortion group FulcrumSec claimed the attack to BleepingComputer: ~86GB stolen, entry via API credentials for third-party marketing platform Iterable allegedly exposed in client-side JavaScript, plus ~200,000 records about upcoming travel. Those claims are unverified — but BleepingComputer independently validated sample data against one traveller's real purchase history, and the samples were far richer than MAG's disclosure: booking references, prices, parking dates and historical spend. In this episode: - The confirmed facts versus the criminal's claims — and why the distinction matters - MAG's response: containment, ICO notification within UK GDPR's 72-hour window, suspending Manage My Booking, and contacting every affected customer - Why postcode + number plate + parking dates is near-perfect phishing bait - Four lessons for Australian businesses: your marketing SaaS stack is attack surface; never ship API keys in client-side code; data minimisation decided this breach's severity years in advance; and assume the true scope is worse than your first assessment Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: BleepingComputer (27 and 30 Aug 2026); Infosecurity Magazine (27 Aug 2026); Security Affairs (30 Aug 2026); MAG data-security incident page; TTG Media (28 Aug 2026, ICO confirmation).

    Manchester Airports Group - 8.7 Million Travellers, and the API Keys Sitting in Plain Sight
  2. 6 days ago

    Quest Apartment Hotels - 1.5 Million Guest Records, and the Attacker Who Never Touched Quest's Systems

    Quest Apartment Hotels – 1.5 Million Guest Records, and the Attacker Who Never Touched Quest's Systems A deep-dive into Australia's biggest hospitality breach of 2026 — and the vendor-ecosystem attack pattern behind it. On Monday 17 August 2026, Quest Apartment Hotels — 160+ properties, founded in Melbourne in 1988, majority-owned since 2017 (and fully since 2022) by Singapore's The Ascott Limited — identified unauthorised access to a database system. The entry point wasn't Quest's own network: the company says access arose "from a vulnerability through a third-party service provider" holding Quest guest data. Two days later, on 19 August, Quest disclosed publicly and emailed affected guests under the signature of Ascott Australasia managing director David Mansfield. What was taken: records predating June 2025 — full names, email addresses and contact details, street addresses in some records, and a small number of dates of birth. No financial or payment card data. Quest hasn't published a number; ACS Information Age reports more than 1.5 million records were potentially involved. What we don't know: the vendor's identity, the specific vulnerability (no CVE published), and how the attacker got in — Quest has declined to answer. No threat actor has claimed responsibility and no ransom demand is public. The response: containment and remediation completed before disclosure; OAIC, ACSC and other authorities notified; external cyber and privacy advisers engaged; all affected guests contacted. In this episode: Why the vendor ecosystem is now the preferred way in — and how this breach follows Origin Energy, Partnered Health and Lifeline in a bruising winter for Australian data holders- The phishing second wave: why names + contact details + dates of birth are "the raw ingredients for convincing phishing and identity fraud" (Kash Sharma, BlueVoyant)- Five lessons for Australian businesses: map the vendors that touch your customer data; treat data retention as attack surface; know your Notifiable Data Breaches obligations; contract for security before the incident; and warn customers about branded scams that followVisit www.kinsoft.com.au to talk through your security and IT needs. Sources: ABC News (19 Aug 2026); Information Age / ACS (19–20 Aug 2026); The Register (19 Aug 2026); Cyber Daily (20 Aug 2026); SmartCompany; Australian Cyber Security Magazine; Quest Apartment Hotels statement; 7NEWS.

    Quest Apartment Hotels - 1.5 Million Guest Records, and the Attacker Who Never Touched Quest's Systems
  3. 30 Aug

    Last Week in Tech - Nvidia Doubles, Meta Pays $18 Billion, and the Musk-Altman Feud Reaches Your Code Editor

    Last Week in Tech – Nvidia Doubles, Meta Pays $18 Billion, and the Musk–Altman Feud Reaches Your Code Editor Your Monday roundup of the technology and security stories that mattered to Australian businesses in the week of 24–30 August 2026. In this episode: Nvidia's record quarter (26 Aug). Revenue US$96.2bn, up 106% year-on-year; data centre US$89bn (~93% of the company); Q3 guided to ~US$108bn and CFO Colette Kress forecasting ~70% growth for fiscal 2028. What an accelerating AI capex cycle means for your cloud pricing and FY27 budget.- Meta's teen-harm settlement (26 Aug). Up to ~US$17bn — Meta itself puts it at ~US$18bn over ten years, ~US$12.7bn guaranteed — settling the multistate lawsuit filed by 33 state attorneys-general, without a finding of liability, but with enforceable product changes: two-hour daily limits and a midnight–6am curfew for under-18s, likes hidden by default on children's accounts, cosmetic filters banned for minors, most school-hours notifications off. A template for how Australia's under-16 social media ban could be enforced, and a warning on design-liability risk.- OpenAI to cut Cursor off (29 Aug). After SpaceX's US$60bn acquisition of Cursor-maker Anysphere closed on 14 Aug, OpenAI proposed ending model access on 12 November, citing its litigation history with Elon Musk's companies. Cursor says OpenAI models are ~5% of traffic. Concentration risk in AI dev tooling: know which models your tools depend on.- Alibaba's Wan 3.0 (24 Aug). Document-to-video AI at ~US$6 per 30-second clip — and the data-sovereignty question to ask before marketing uploads anything.- Security round. Citrix NetScaler CVE-2026-8452 (8.8 CVSS v4.0) — disclosed in June as denial-of-service, reclassified to unauthenticated RCE, added to CISA's KEV on 26 Aug with web shells found on compromised appliances; Zimbra CVE-2026-73570 (8.9 CVSS v3.1) — single-email command injection, 270+ servers confirmed compromised, ~8,200 still unpatched; and Boston Scientific's still-unattributed cyberattack halting order shipping and manufacturing worldwide.Coming up: Wednesday, the Quest Apartment Hotels breach. Friday, Manchester Airports Group in full. Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: CNBC, Fortune and Kiplinger on Nvidia Q2 FY2027 results (26 Aug 2026); CNN Business, Bloomberg and Al Jazeera on the Meta settlement (26–27 Aug 2026); CNBC and the OpenAI blog on Cursor model access (29 Aug 2026); Seeking Alpha on the SpaceX–Anysphere close (14 Aug 2026); Dataconomy and Winbuzzer on Alibaba Wan 3.0 (24–25 Aug 2026); Help Net Security, SecurityWeek, BleepingComputer and CISA KEV on Citrix CVE-2026-8452; The Hacker News, runZero, Shadowserver and CCB Belgium on Zimbra CVE-2026-73570; TechCrunch, The Register and BleepingComputer on Boston Scientific (26 Aug 2026).

    Last Week in Tech - Nvidia Doubles, Meta Pays $18 Billion, and the Musk-Altman Feud Reaches Your Code Editor
  4. 27 Aug

    Metabase - The Reporting Tool That Held Every Key, and the Five Companies That Found Out

    A deep-dive on CVE-2026-72898, the unauthenticated SQL injection zero-day exploited against Metabase Cloud in early August 2026. Two corrections to our roundup of 17 August, made on air. A CVE has since been assigned - CVE-2026-72898, added to CISA's Known Exploited Vulnerabilities catalogue on 11 August and rated 10.0 under both CVSS v3.1 and v4.0. And LexisNexis has explicitly ruled out any connection between its service outage and this flaw: the similarly-named Nexis Metabase API is an unrelated product, and LexisNexis is not a Metabase Cloud customer. The timeline. 2 Aug: attacker active in Kilo Code's instance for about four hours. 3 Aug: broader attack on Metabase Cloud; Metabase detects, blocks and patches the same day. 6 Aug: public advisory; Framework notified, and notifies its own customers. 8 Aug: a researcher publishes a proof-of-concept lab. 10 Aug: CVE assigned; public exploits go open-source; Checkly and Wiz publish. 11 Aug: added to CISA KEV with a 14 August deadline; a second Metabase advisory covers further flaws; ShinyHunters lists Metabase on its leak site. The vulnerability. An unauthenticated POST to /api/session/reset_password. Four individually correct behaviours chain together: Clojure's merge not stripping attacker-supplied keys when authentication fails; JSON keywordisation; HoneySQL's raw keyword, a deliberate feature that bypasses parameterisation; and a lookup that compiles the result into unparameterised SQL. The result is blind SQL injection against the application database, leading to a forged administrator session. As Checkly put it, no password was stolen. The patch is a three-line type check. Exposure. Dataminr's 8 August scan found roughly 11,000 probable self-hosted instances, 4,309 likely vulnerable, and over 97% of fingerprinted hosts on an affected branch unpatched. Five victims disclosed, all Metabase Cloud tenants, all of whom published their own post-mortems: Framework Computer (names, emails, login IPs, addresses, phone numbers; VAT and EIN for business customers), Tally (emails and hashed passwords), n8n (136 records, plus a separately-discovered 2023 plaintext password bug), Kilo Code and Anaconda (names, emails, billing addresses, user prompts, later Slack access tokens), and Checkly (26 minutes of read-only warehouse queries exposing plaintext credentials hard-coded into check configurations). Metabase has never said how many tenants were affected. Attribution: unconfirmed. ShinyHunters listed Metabase on 11 August, but Dataminr assessed the listing as a placeholder with no scope named. Metabase has named nobody. Treat it as a claim. Check your own instance. In application or ingress logs, look for a POST to /api/session/reset_password returning HTTP 400 immediately followed by a GET to /api/user/current returning HTTP 200. That pattern indicates likely compromise. Five lessons. One: your BI tool is a production system holding a key ring - audit what it stores and scope those service accounts to read-only. Two: internet-facing auth endpoints on internal tools are an unforced error. Three: using the managed version is not the same as not being affected. Four: rotate sessions and downstream credentials, not just passwords - there was no malware, and both survive a patch. Five: use the secrets store, not free-text config fields. Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: NVD and CVE.org; CISA KEV; Metabase advisories GHSA-vwf4-m7j8-wcjf and GHSA-r495-55cx-fjh7; Wiz; Bishop Fox; Dataminr; BleepingComputer; and disclosures by Checkly, n8n, Kilo Code, Framework and Tally.

    Metabase - The Reporting Tool That Held Every Key, and the Five Companies That Found Out
  5. 25 Aug

    Bendigo Bank - 1,598 Accounts, One Password, and the $8 Million Bill That Arrived Three Years Later

    On 11 August 2026, Bendigo and Adelaide Bank accepted a proposed $8 million penalty over a March 2023 cyber attack on Service One Alliance Bank. The court documents contain a sentence worth reading twice: at the time the attack began, 1,598 customer accounts were protected by the password 123456. The timeline. 2020: penetration testing identifies security weaknesses in the Alliance Bank environment. Not remediated. October 2022: a threat actor attempts brute-force login attacks and fails; the board is told the bank is at a critical point of needing further investment in resourcing and capability. No substantive review is undertaken. March 2023: an unidentified attacker brute-forces approximately 257 customer accounts. 10 August 2026: APRA files an Originating Application in the Federal Court. 11 August 2026: APRA announces publicly and Bendigo lodges an ASX announcement accepting the proposed penalty. The numbers - all official, from APRA, the Federal Court filing and Bendigo's ASX announcement, none of them threat-actor claims: 257 accounts accessed; 286 unauthorised transactions; 87 customers affected by a transaction; approximately $490,000 misappropriated; about $140,000 unrecoverable; all customers fully reimbursed; 1,598 accounts using 123456; an $8m proposed penalty; and about $2.6m in additional legal costs. The three named control weaknesses: password settings permitting very weak passwords; multiple accounts protected by identical passwords; and system design that enabled the attacker to identify valid customer IDs - account enumeration. The regulatory angle. This is not an OAIC or Notifiable Data Breaches matter, because no bulk personal information was taken. The regulator is APRA and the instrument is the Banking Executive Accountability Regime. All four admitted failures are governance failures: inadequate authentication controls, no systematic testing programme, accountable persons' responsibilities not covering the Alliance Bank IT system, and inadequate information security governance. Attribution: none. APRA and the court documents describe an unidentified threat actor. No group claimed it, no data was published, no ransomware was involved. Five lessons. One: a penetration test you don't remediate is worse than no penetration test - it is a dated written record that you were told. Two: treat a failed attack as a real incident; October 2022 was a rehearsal nobody reviewed. Three: password policy isn't solved because you assume it is - go and measure it, and make MFA default rather than optional. Four: account enumeration is a vulnerability, not a UX detail - identical responses and identical timing, whether or not the account exists. Five: outsourced, white-labelled or subsidiary IT still carries your accountability, so put a person's name, not a team's, against every system your customers touch. The penalty is roughly 16 times the amount stolen. It isn't for the loss; it's for the three years between the finding and the fix. Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: APRA media release, Bendigo and Adelaide Bank admits breaching its BEAR obligations, 11 August 2026; APRA Originating Application, Federal Court of Australia, stamped and redacted, 10 August 2026; Bendigo and Adelaide Bank ASX announcement, 11 August 2026; Information Age (Australian Computer Society), 12 August 2026; Cyber Daily, 11 August 2026; FST Media; Lawyerly; Mortgage Professional Australia.

    Bendigo Bank - 1,598 Accounts, One Password, and the $8 Million Bill That Arrived Three Years Later
  6. 23 Aug

    Last Week in Tech - Nvidia Turns GPUs Into an Asset Class, the AI Price War Breaks Out, and an AI Agent Goes to War

    Your Monday roundup of the technology and security stories that mattered to Australian businesses in the week of 10-16 August 2026. Nvidia's $500bn financing platforms (10 Aug). MOUs with Apollo, BlackRock, Blackstone, Brookfield, Goldman Sachs and KKR to mobilise third-party capital for AI compute. Why an MOU is not a contract, and the reported - but not company-confirmed - 25% loan backstop. The AI price war (11-14 Aug). Gemini 3.7 Flash three weeks after 3.6 at half the price; GPT-5.6 Luna cut ~80%; Claude Opus 5 at $5/$25 with the Sonnet 5 price rise cancelled; DeepSeek raising prices sharply. What to do about your existing vendor agreement - and why introductory pricing that expires at end-2026 isn't a 2027 budget line. The near-autonomous AI agent attack on Taiwan (12 Aug). Open-source agent frameworks, guardrails bypassed by claiming authorised pen-testing, and an operation that expanded its own scope. Plus OpenAI's Daybreak Blue and Red tiers, and 51 US House Democrats asking questions. The chip money wave (10-13 Aug). TSMC's record July (+44.7% YoY), Intel's upsized $20bn raise, Cisco's $9.3bn of AI infrastructure orders, Applied Materials' record quarter - and why beating expectations still moved three of these share prices down. IBM and OpenAI (13 Aug), Gemini past 1bn users, and Anthropic watermarking Claude output worldwide - the first clearly visible case of EU AI Act compliance being exported globally by default. Security round. August Patch Tuesday (~400 CVEs, one exploited zero-day, CVE-2026-68820, attributed to Lazarus a day later); VMware vCenter CVE-2026-59310 exploited five days after disclosure with 361 victims in 47 countries; SAP Commerce Cloud CVE-2026-58231 exploited three days after patch day; Cisco ASA/FTD CVE-2026-20349; Adobe Commerce CVE-2026-71362 exploited within hours; unpatched GeoServer and Windows Defender ShieldBreak zero-days with no CVE at all; and macOS Screen Sharing CVE-2026-65400 being used to plant Monero miners on internet-exposed Macs. Incidents: the Ceva Logistics breach rippling to Steam, ING, Bol, De Bijenkorf and Ajax; and ransomware taking out doors and HVAC - not clinical systems - at Manitoba's largest hospital. Coming up: Wednesday, the Bendigo Bank cyber penalty. Friday, the Metabase zero-day in full. Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Nvidia newsroom, CNBC, Bloomberg, TechCrunch, Reuters, VentureBeat, Financial Times, Dream Group research, CyberScoop, The Register, CNN, OpenAI, The Hill, TSMC and Intel investor relations, Cisco, Applied Materials, IBM newsroom, Ars Technica, Axios, SecurityWeek, BleepingComputer, The Hacker News, Zero Day Initiative, Tenable, Rapid7, CISA, Onapsis, Dutch NCSC, The Record, CBC.

    Last Week in Tech - Nvidia Turns GPUs Into an Asset Class, the AI Price War Breaks Out, and an AI Agent Goes to War
  7. 20 Aug

    N-able N-central – God Mode on the Management Plane, and the Hotfix That Wasn't Enough

    At the start of August 2026, attackers exploited an authentication bypass in N-able's N-central remote monitoring and management platform to obtain full administrative control of the console - and then used the product's own legitimate remote access feature to reach the machines it manages. The vendor shipped a fix. It was not enough. The six-day timeline. 1 Aug: N-able detects active exploitation of CVE-2026-18556 (CVSS 7.4 under v3.1, 8.2 under v4.0); all versions affected, hosted and on-premises. 2 Aug: hotfix 1, build 2026.3.1.7, plus a second advisory for CVE-2026-18577 - the residual bypass left by the incomplete fix (8.1 under v3.1, 8.2 under v4.0). 3 Aug: CISA adds 18577 to the Known Exploited Vulnerabilities catalogue. 4 Aug: CISA adds 18556; N-able confirms attackers obtained administrative access. 6 Aug: hotfix 2, build 2026.3.1.10 - required even if hotfix 1 was already applied. The patch-rate gap. Huntress observed 55.6% of reachable cloud N-central servers unpatched early on 3 August, falling to 13.6% overall by that afternoon - but 28.6% of reachable self-hosted servers were still unpatched. Hosted customers were fixed by the vendor; self-hosted ones had to fix themselves. The attack chain. Unauthenticated bypass to full admin ("god mode"), then abuse of the built-in Take Control remote access feature - with sessions logged under the default legitimate "MSP Support" account, so the attack looks like ordinary support work. Then domain controller reconnaissance, and persistence via a Cloudflare Tunnel (cloudflared) registered as a Windows service plus a suspicious svchost.exe in a user's Documents folder. No attribution - at all. Not formal, not suspected, not claimed. All ten published indicator IPs are Mullvad or NordVPN exit nodes. No ransomware was observed and no extortion claims have surfaced. Hunting artefacts: ui_access_control.log for the indicator IPs and the mspsupport identity; the Take Control logs under ProgramData; Windows event IDs 4102, 8192 and 8193; and any cloudflared service you did not install. Five durable lessons: give the management plane identity-provider-grade controls, including IP allow-listing and MFA on every operator account; recognise that the on-premises appliance is usually the one machine in your estate without EDR; understand that applying the vendor patch is not the same as being safe; treat remote control sessions as security events and review the out-of-hours ones weekly; and if you buy IT services, ask your provider precisely when they applied the August hotfixes. Because when a database is breached you lose data. When your management plane is breached, you lose the ability to trust anything else you are looking at - including your logs and your patch reports. Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: N-able security advisories for CVE-2026-18556 and CVE-2026-18577 (1-6 August 2026); Huntress, "N-able vulnerability exploitation" (3 August 2026); BleepingComputer; Rapid7 Emergent Threat Response for CVE-2026-18577; Horizon3.ai attack research; CISA Known Exploited Vulnerabilities catalogue additions, 3 and 4 August 2026; The Hacker News; The Register.

    N-able N-central – God Mode on the Management Plane, and the Hotfix That Wasn't Enough
  8. 18 Aug

    Court Services Victoria – A Hearing-Link List, 28,600 Lines, and the Victims Nobody Can Name

    In July 2026, someone accessed the system Victorian courts use to link participants to online hearings. Not the case management system - the joining list. Four years of it, across ten regional court locations, for the Magistrates' Court and the Children's Court. This episode walks through what was confirmed, what was only claimed, and why a scheduling layer turned out to be more sensitive than the case files it pointed at. What Court Services Victoria confirmed: the incident occurred in July 2026; the data spans 2022 to 2026; ten named regional locations including Bendigo, Castlemaine, Echuca, Kerang, Kyneton, Maryborough, Mildura, Ouyen, Robinvale and Swan Hill. Exposed fields include participant names, case titles and numbers, hearing dates, times and courtrooms, plus two things not on the public record - email addresses and a description of the person's role in the matter. The Case Management System, employee data and financial data were not accessed. What was only claimed: the "more than 28,600 lines" figure comes from the threat actor, not from the organisation. CSV states it "is unable to verify the number of people and matters impacted". Lines are not people, and no affected-person count has been published. The most sensitive claim, carefully sourced: the ABC reports it understands the leaked data includes the names of parties in family violence intervention order hearings and children's court cases. CSV has not confirmed this. CSV's own support page links to The Orange Door, Safe Steps and the Victims of Crime Helpline. Also covered: why nobody has been individually notified, what CSV is offering instead (a public FAQ and a hotline on 03 9087 6116), and why your ability to notify people is a design decision you make years before a breach. Four takeaways: find your scheduling layers; treat metadata and context as data; use retention as a blast-radius control; and know whether your clients sit under the OAIC or a state regulator - CSV is a Victorian public sector body, so this one sits with OVIC under the Privacy and Data Protection Act 2014 (Vic), not the OAIC. And the uncomfortable closing question: CSV confirms this is a completely different system to its 2024 breach. What else in your organisation looks like the system you have not hardened yet? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Court Services Victoria, "Data Security Notification" and "CSV data security incident FAQs" (courts.vic.gov.au, 30 July 2026); Magistrates' Court of Victoria notification (mcv.vic.gov.au, 5 August 2026); Cyber Daily exclusive (30 July 2026); Lawyers Weekly (30 July 2026); ABC News (7 August 2026), summarised by DataBreaches.Net; Law360 Australia; Privacy and Data Protection Act 2014 (Vic); Office of the Victorian Information Commissioner.

    Court Services Victoria – A Hearing-Link List, 28,600 Lines, and the Victims Nobody Can Name

About

Tech Talks with Kinsoft is your insider pass to the ever-evolving world of technology. We break down the latest in tech news, cybersecurity trends, and emerging innovations shaping our digital future. Whether you’re a seasoned IT pro, a curious techie, or a business leader navigating digital transformation, our conversations are packed with insights, real-world takeaways, and a healthy dose of tech-savvy clarity. Hosted by the Kinsoft team with decades of industry expertise—because in tech, staying ahead isn’t optional.