
Notas del episodio
Last Week in Tech for the week of 14 to 20 September 2026. Recorded after the fact to fill a missed slot; later developments are flagged.
Cisco: two exploited zero-days. CVE-2026-76461 (14 Sep), Secure Email Gateway: unauthenticated SQL injection in email parsing, root via a crafted email, no user interaction. Cisco: CVSS v3.1 9.8. Fixed in 15.5.5-014, 16.0.4-302, 16.5.0-780. CVE-2026-76460 (16 Sep), Identity Services Engine: API authentication bypass to root, CVSS v3.1 10.0, no workaround beyond restricting access; ISE 3.0 is end-of-life. Both added to CISA KEV on disclosure.
Brevo supply-chain attack (14 Sep). A long-lived Cloudflare API key hard-coded in Brevo's source code was used to deploy a Worker injecting script into Brevo sites and customer-embedded JavaScript. Live for roughly 4–5.5 hours; Sansec estimates 100,000+ sites. Visitors saw a fake "verify you are human" ClickFix page; WordPress sites with Brevo widgets were targeted with a backdoor plugin. Check WordPress sites for unknown plugins.
AWS permanent data loss (15 Sep). AWS says data held only in its Bahrain region (me-south-1), or only in one UAE availability zone, cannot be recovered after damage from strikes beginning in March. Revisit single-region backup and DR plans.
Salesforce Koa (Dreamforce, 15–17 Sep). Salesforce's own CRM reasoning model, built on Nvidia Nemotron with synthetic data; US regions only at first. Later: on 24 Sep Zenity Labs disclosed "SalesBleed", three since-fixed Agentforce flaws.
AI pacing. OpenAI published a misalignment disclosure framework and six incident reports (16 Sep). Ursula von der Leyen said the EU will invite leading labs to discuss how to "pace the frontier".
Australia's Privacy Act overhaul. Consultation on the Attorney-General's Department's exposure draft closed 18 Sep. Proposals include a broader personal information definition, a "fair and reasonable" test, a right to erasure on large platforms, and a 72-hour deadline to notify the OAIC of an eligible breach. The small-business exemption stays; no new direct right to sue.
Visit www.kinsoft.com.au to talk through your security and IT needs.
Sources: Rapid7; Help Net Security; The Hacker News; The Register; Triskele Labs; Cisco advisories; SecurityWeek; Sansec; Brevo post-mortem; AWS Health Dashboard; InfoQ; Salesforce; Nvidia; The Register (SalesBleed); OpenAI; Axios; TNW; Attorney-General's Department; Allens.
