Tech Talks With Kinsoft

Steven Kinnas

Tech Talks with Kinsoft is your insider pass to the ever-evolving world of technology. We break down the latest in tech news, cybersecurity trends, and emerging innovations shaping our digital future. Whether you’re a seasoned IT pro, a curious techie, or a business leader navigating digital transformation, our conversations are packed with insights, real-world takeaways, and a healthy dose of tech-savvy clarity. Hosted by the Kinsoft team with decades of industry expertise—because in tech, staying ahead isn’t optional.

  1. 6h ago

    N-able N-central – God Mode on the Management Plane, and the Hotfix That Wasn't Enough

    At the start of August 2026, attackers exploited an authentication bypass in N-able's N-central remote monitoring and management platform to obtain full administrative control of the console - and then used the product's own legitimate remote access feature to reach the machines it manages. The vendor shipped a fix. It was not enough. The six-day timeline. 1 Aug: N-able detects active exploitation of CVE-2026-18556 (CVSS 7.4 under v3.1, 8.2 under v4.0); all versions affected, hosted and on-premises. 2 Aug: hotfix 1, build 2026.3.1.7, plus a second advisory for CVE-2026-18577 - the residual bypass left by the incomplete fix (8.1 under v3.1, 8.2 under v4.0). 3 Aug: CISA adds 18577 to the Known Exploited Vulnerabilities catalogue. 4 Aug: CISA adds 18556; N-able confirms attackers obtained administrative access. 6 Aug: hotfix 2, build 2026.3.1.10 - required even if hotfix 1 was already applied. The patch-rate gap. Huntress observed 55.6% of reachable cloud N-central servers unpatched early on 3 August, falling to 13.6% overall by that afternoon - but 28.6% of reachable self-hosted servers were still unpatched. Hosted customers were fixed by the vendor; self-hosted ones had to fix themselves. The attack chain. Unauthenticated bypass to full admin ("god mode"), then abuse of the built-in Take Control remote access feature - with sessions logged under the default legitimate "MSP Support" account, so the attack looks like ordinary support work. Then domain controller reconnaissance, and persistence via a Cloudflare Tunnel (cloudflared) registered as a Windows service plus a suspicious svchost.exe in a user's Documents folder. No attribution - at all. Not formal, not suspected, not claimed. All ten published indicator IPs are Mullvad or NordVPN exit nodes. No ransomware was observed and no extortion claims have surfaced. Hunting artefacts: ui_access_control.log for the indicator IPs and the mspsupport identity; the Take Control logs under ProgramData; Windows event IDs 4102, 8192 and 8193; and any cloudflared service you did not install. Five durable lessons: give the management plane identity-provider-grade controls, including IP allow-listing and MFA on every operator account; recognise that the on-premises appliance is usually the one machine in your estate without EDR; understand that applying the vendor patch is not the same as being safe; treat remote control sessions as security events and review the out-of-hours ones weekly; and if you buy IT services, ask your provider precisely when they applied the August hotfixes. Because when a database is breached you lose data. When your management plane is breached, you lose the ability to trust anything else you are looking at - including your logs and your patch reports. Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: N-able security advisories for CVE-2026-18556 and CVE-2026-18577 (1-6 August 2026); Huntress, "N-able vulnerability exploitation" (3 August 2026); BleepingComputer; Rapid7 Emergent Threat Response for CVE-2026-18577; Horizon3.ai attack research; CISA Known Exploited Vulnerabilities catalogue additions, 3 and 4 August 2026; The Hacker News; The Register.

    N-able N-central – God Mode on the Management Plane, and the Hotfix That Wasn't Enough
  2. 2d ago

    Court Services Victoria – A Hearing-Link List, 28,600 Lines, and the Victims Nobody Can Name

    In July 2026, someone accessed the system Victorian courts use to link participants to online hearings. Not the case management system - the joining list. Four years of it, across ten regional court locations, for the Magistrates' Court and the Children's Court. This episode walks through what was confirmed, what was only claimed, and why a scheduling layer turned out to be more sensitive than the case files it pointed at. What Court Services Victoria confirmed: the incident occurred in July 2026; the data spans 2022 to 2026; ten named regional locations including Bendigo, Castlemaine, Echuca, Kerang, Kyneton, Maryborough, Mildura, Ouyen, Robinvale and Swan Hill. Exposed fields include participant names, case titles and numbers, hearing dates, times and courtrooms, plus two things not on the public record - email addresses and a description of the person's role in the matter. The Case Management System, employee data and financial data were not accessed. What was only claimed: the "more than 28,600 lines" figure comes from the threat actor, not from the organisation. CSV states it "is unable to verify the number of people and matters impacted". Lines are not people, and no affected-person count has been published. The most sensitive claim, carefully sourced: the ABC reports it understands the leaked data includes the names of parties in family violence intervention order hearings and children's court cases. CSV has not confirmed this. CSV's own support page links to The Orange Door, Safe Steps and the Victims of Crime Helpline. Also covered: why nobody has been individually notified, what CSV is offering instead (a public FAQ and a hotline on 03 9087 6116), and why your ability to notify people is a design decision you make years before a breach. Four takeaways: find your scheduling layers; treat metadata and context as data; use retention as a blast-radius control; and know whether your clients sit under the OAIC or a state regulator - CSV is a Victorian public sector body, so this one sits with OVIC under the Privacy and Data Protection Act 2014 (Vic), not the OAIC. And the uncomfortable closing question: CSV confirms this is a completely different system to its 2024 breach. What else in your organisation looks like the system you have not hardened yet? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Court Services Victoria, "Data Security Notification" and "CSV data security incident FAQs" (courts.vic.gov.au, 30 July 2026); Magistrates' Court of Victoria notification (mcv.vic.gov.au, 5 August 2026); Cyber Daily exclusive (30 July 2026); Lawyers Weekly (30 July 2026); ABC News (7 August 2026), summarised by DataBreaches.Net; Law360 Australia; Privacy and Data Protection Act 2014 (Vic); Office of the Victorian Information Commissioner.

    Court Services Victoria – A Hearing-Link List, 28,600 Lines, and the Victims Nobody Can Name
  3. 4d ago

    Last Week in Tech – Google Reshuffles Its AI Empire, Washington Writes a Rulebook It Won't Show You, and Memory Sold Out to 2030

    Your Monday roundup of the technology and security news that matters to Australian businesses, covering 3-9 August 2026. In this episode: Google's AI leadership shake-up (5 Aug). Demis Hassabis moves to Chair of Google DeepMind and Chief Scientist of Alphabet. Koray Kavukcuoglu becomes SVP of Google DeepMind reporting to Sundar Pichai, taking Gemini research and product. Jeff Dean leaves after 27 years to co-found a public benefit corporation with Sanjay Ghemawat, with Google as founding investor and cloud partner. The Gemini app is past 950 million monthly users; Gemma is past 900 million downloads. Washington's unpublished frontier-AI framework (4 Aug). Under Executive Order 14409, an NSA-led group has built a process for up to 30 days of pre-release government access to frontier models - and reportedly will not publish it. Open-weight models are excluded. Why a shrinking public evidence base means you need your own evaluation set. AMD and Palantir (3-4 Aug). AMD: revenue $11.5bn (+50%), Data Centre $6.7bn (+107%) and now 58% of the company, Q3 guided to about $13bn. Palantir: revenue $1.935bn (+93%), US commercial +149%, adjusted free cash flow $1.22bn, guidance raised to about $8.15bn. Two great quarters, two opposite market reactions, and what that says about capital intensity. Microsoft's 10-K discloses $24.1bn of OpenAI revenue, plus $6bn of accounts receivable from a single customer as at 30 June. A prompt to run your own customer-concentration numbers. Memory is being sold out to 2030. Samsung plans to cover 60-70% of its memory production capacity under five-year binding agreements with advance payments and floor prices; SK hynix has completed talks with around ten customers. What allocation-constrained supply means for your FY27 hardware budget. Meta launches Muse Code (5 Aug), and Bending Spoons agrees to buy Airtable for a $1.285bn enterprise value (4 Aug). Security round-up: the Metabase zero-day and the Framework, Tally and LexisNexis fallout; IBM Langflow and Apache Tomcat added to CISA KEV; and a preview of Friday's N-able N-central deep-dive. Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Google blog, "The next chapter of our AI momentum" (5 Aug 2026); Axios and Tech Policy Press (4 Aug 2026); White House Executive Order 14409; AMD Q2 2026 results (4 Aug 2026); Palantir Q2 2026 results (3 Aug 2026); Microsoft FY2026 Form 10-K; The Korea Herald and StorageNewsletter (2-3 Aug 2026); TechCrunch, CNBC and the Wall Street Journal (5 Aug 2026); Bending Spoons investor newsroom (4 Aug 2026); BleepingComputer, TechCrunch and The Hacker News (6-8 Aug 2026); CISA Known Exploited Vulnerabilities catalogue (3-4 Aug 2026); Huntress (1-7 Aug 2026).

    Last Week in Tech – Google Reshuffles Its AI Empire, Washington Writes a Rulebook It Won't Show You, and Memory Sold Out to 2030
  4. Aug 13

    Thirty Towns Without Water Controls – Minnesota, Rigged PLCs, and the Bug That Can't Be Patched

    Over two days in late July, a coordinated attack disrupted water and wastewater operations across more than 30 Minnesota communities — Braham's well and treatment plant shut down entirely, Plymouth disconnected cellular-connected water towers and lift stations, Maple Plain declared a local state of emergency. Drinking water quality was never affected and no boil-water advisories were issued, but the mechanism matters more than the outcome. Four days earlier CISA had expanded its advisory on Iranian-affiliated PLC targeting to cover Schneider Electric and Siemens alongside Rockwell, documented PLC project file theft for the first time, and described an FBI-observed case where malicious Add-On Instructions disabled safety shutdowns and alarms while operator displays were manipulated to show normal conditions. The central Rockwell authentication bypass (CVSS 9.8) was disclosed in February 2021, added to CISA KEV in March 2026 — and Rockwell says it cannot be fully fixed by a software patch. Censys found 5,219 internet-exposed Rockwell/Allen-Bradley hosts globally, disproportionately on cellular carrier networks, which is exactly how a small utility connects a remote water tower. Attribution: suspected, NOT formally attributed — treat nation-state headlines as speculation. Five actions for Australian businesses: inventory your control equipment and its connectivity (especially cellular routers), assume it can't be patched, segment it off the corporate network and off the internet, know and practise your manual fallback, and build an independent way to verify reality that isn't the compromised control system's own screen. Context: the ASD told Australian critical infrastructure operators on 28 July to be ready to isolate systems for three months, and the SOCI Act's eleven sectors capture far more businesses than most owners realise. Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Tenable Research Special Operations FAQ (28 July 2026, updated 31 July); Minnesota IT Services and municipal statements; StateScoop; SecurityWeek; CISA Advisory AA26-097A (updated 22 July 2026) and the Known Exploited Vulnerabilities catalogue; Censys internet exposure scanning (April 2026); Australian Signals Directorate critical infrastructure guidance (28 July 2026) via iTnews.

    Thirty Towns Without Water Controls – Minnesota, Rigged PLCs, and the Bug That Can't Be Patched
  5. Aug 11

    GO2 Health – A Veterans' Clinic, One Mailbox, and the Twelve Weeks Nobody Was Told

    A Brisbane medical practice serving thousands of veterans lost Department of Veterans' Affairs ID numbers from a single email mailbox after a phishing attack — and then took twelve weeks to tell the patients. We walk the confirmed timeline (mailbox accessed in April, discovered 24 April with same-day containment and user alerts, OAIC notified 18 May, patients notified 16 July, ABC story 21 July), what GO2 Health has confirmed was taken, and what remains genuinely unknown — including the number of people affected, which the practice has not published. The lessons transfer to any Australian business: shared mailboxes are undesigned databases holding data your secured systems never see; auto-archiving capped this breach at twelve months and is the cheapest blast-radius control there is; the 30-day OAIC assessment clock governs telling the regulator, not telling people; a two-stage notification gets you vigilance without sacrificing accuracy; and identifiers you didn't issue — DVA, Medicare, concession cards — still need a documented replacement pathway you write before the incident, not during it. Context: the OAIC recorded 1,205 notified breaches last year, 716 from malicious or criminal activity, with health providers the most affected sector at 19%. Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: ABC News (Will Murray, 21 July 2026); Cyber Daily (22 July 2026); GO2 Health company statements; The Medical Republic (OAIC spokesperson on the Notifiable Data Breaches scheme, 16 July 2026); OAIC Notifiable Data Breaches statistics.

    GO2 Health – A Veterans' Clinic, One Mailbox, and the Twelve Weeks Nobody Was Told
  6. Aug 9

    Last Week in Tech – A Record $450 Billion Day, $720 Billion of AI Capex, and the Memory Bill Landing on Your Desk

    Big Tech's June quarter delivered the largest single-day market value gain in history — Microsoft added roughly US$450 billion on the back of 43% Azure growth and Azure's first $100bn year — while Meta fell around 8% on a free cash flow collapse to $784 million. Add up the guidance and Alphabet, Amazon, Meta and Microsoft are committing roughly US$720-745 billion of capital expenditure in calendar 2026. Amazon's AWS backlog jumped from $364bn to $496bn in a quarter and Andy Jassy says there won't be enough capacity in 2026 or 2027. Also this week: SK hynix and Samsung post extraordinary memory results with Samsung tipping the chip crunch to run to 2028 — expect PC prices up as much as 8% this year, so lock FY27 hardware quotes now. Anthropic audits 141,006 evaluation runs after the OpenAI containment incident and finds three cases where its model reached the internet — neither affected organisation had detected it. EU AI Act transparency obligations (chatbot disclosure, deepfake labelling, and machine-readable AI content marking for new systems) took effect 2 August even though high-risk obligations slipped to December 2027 under the Digital Omnibus. Amgen files an 8-K over patient data taken from third-party cloud environments. Cisco Secure FMC static hard-coded credentials — CVSS 5.3 but rated High impact by Cisco because it chains with other FMC flaws — hit CISA KEV with a 1 August deadline. Plus: Australia's GovAI catalogue expands with onshore-hosting requirements, and the ASD tells critical infrastructure operators to be ready to isolate for three months. Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: CNBC, Reuters, Bloomberg and CFO Dive (Microsoft, Amazon, Meta earnings); Apple Newsroom (fiscal Q3 results, 30 July); SK hynix Newsroom and Reuters (memory results); TechCrunch (Anthropic evaluation audit, 30 July); Reuters (Altman in Washington, 29 July); Gibson Dunn and Holland & Knight (EU AI Act timing); SEC EDGAR Form 8-K and BleepingComputer (Amgen); Cisco advisory and the CISA Known Exploited Vulnerabilities catalogue (Cisco FMC); iTnews (GovAI catalogue, ASD guidance).

    Last Week in Tech – A Record $450 Billion Day, $720 Billion of AI Capex, and the Memory Bill Landing on Your Desk

About

Tech Talks with Kinsoft is your insider pass to the ever-evolving world of technology. We break down the latest in tech news, cybersecurity trends, and emerging innovations shaping our digital future. Whether you’re a seasoned IT pro, a curious techie, or a business leader navigating digital transformation, our conversations are packed with insights, real-world takeaways, and a healthy dose of tech-savvy clarity. Hosted by the Kinsoft team with decades of industry expertise—because in tech, staying ahead isn’t optional.