
Tech Talks With Kinsoft
di Steven Kinnas
Last Week in Tech - The Biggest Patch Tuesday Ever, a 10.0 With No Patch to Apply, and Oracle's $664 Billion Round Trip
Last Week in Tech for Monday 14 September 2026, covering 7 to 13 September. Microsoft's largest Patch Tuesday ever (8 Sep): around 970 CVEs — 974 per Microsoft's own release note, 964 per Tenable, 966 per BleepingComputer. Two were already being exploited, both Windows privilege escalation, both CVSS v3.1 7.8: CVE-2026-85880 (ALPC heap buffer overflow) and CVE-2026-81963 (Windows Update Stack link-following), per Tenable the first Update Stack flaw ever caught being exploited. Both are local escalation, not initial access. ZDI's Dustin Childs rates Exchange CVE-2026-55007 (8.1, malicious Visio attachment) the month's most important patch, and calls Windows DNS Server CVE-2026-69730 (9.8) the spiritual successor to SigRed. September's Windows Server updates break Remote Desktop Services — test first. Magento and Adobe Commerce "StyleSmuggler": CVE-2026-75650, CVSS v3.1 10.0, unauthenticated RCE. Exploited from 4 Sep, disclosed by Sansec 5 Sep, patched 7 Sep (APSB26-146), added to CISA KEV 8 Sep. A Magento-written log file is poisoned with PHP, then executed when Magento renders the standard Payment Transaction Failed Reminder email — nobody needs to open it. Sansec's first victim ran 2.4.6-p15 with July and August updates applied, the current patch level for that line; Disrex Group confirmed two more, one on 2.4.8 running Sansec's own protection product. Patching does not remove an installed backdoor — any store online between 4 Sep and patching needs a compromise assessment, a session flush, and rotation of the encryption key, admin passwords and all env.php credentials. Ten CVEs into CISA KEV in three days, almost all edge devices. 9 Sep: Cisco Secure Firewall Management Center auth bypass to root, CVE-2026-20079 (10.0), with Cisco confirming exploitation from August; Citrix NetScaler auth bypass CVE-2026-19490 (9.3); Fortinet heap overflow CVE-2025-25249 (7.3), linked by SOCRadar to a PivotC2 campaign that infected 178 devices. 10 Sep: MikroTik RouterOS CVE-2026-67277 and CVE-2026-86060 — CERT Polska warned of full administrative takeover via internet-exposed SSH without authentication, calling it MikroTrick. Zero-day status unverified. Oracle Q1 FY2027 (10 Sep): revenue US$19.3bn (+30%), cloud US$11.6bn (+62%), infrastructure US$7.4bn (+121%), backlog US$664bn against roughly US$640bn expected, with 300,000+ GPUs delivered. On 11 Sep shares rose as much as 7.8% intraday, then reversed to close around 2% down. S&P estimates roughly half the backlog is tied to OpenAI, calculated against the prior US$638bn figure; Moody's has flagged counterparty risk. Apple (9 Sep): the iPhone Duo foldable starts at US$1,999, on sale 23 October. iPhone 18 Pro from US$1,199 and Pro Max from US$1,299 ship in 65+ countries from 18 September. All run the A20 Pro, Apple's first 2nm chip. There is no standard iPhone 18 this cycle — the affordable models move to spring 2027, pushing mid-tier fleet refreshes out two quarters. The AI cost gap: DeepSeek's V4.1-Flash (10 Sep) has MIT-licensed open weights at US$0.15 per million input tokens and US$0.60 per million output off-peak, though its benchmarks are vendor-published and not independently reproduced. The Information reported on 6 September that Anthropic has signed compute agreements worth up to US$517bn — an estimated maximum across many deals, not published by Anthropic. Coming up: Wednesday, a Sydney edtech breach affecting over a million people. Friday, the developer-tools vendor that missed its own patch. Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Microsoft Security Update Guide; Tenable; BleepingComputer; Sansec; Adobe APSB26-146; Disrex Group; CISA KEV catalogue; CERT Polska; Oracle investor relations; The Information.
153 Million Driver's Licences - The Scanner at the Front Desk, and the Shop That Sold What It Saw
A dark web shop, 153 million driver's licence scans, an FBI investigation, and the scanner at your front desk. What was found. On 1 September, KrebsOnSecurity reported a dark web service called "Nexus" advertising more than 153 million US and Canadian driver's licence scans, plus 10 million+ ID cards, 3 million+ travel documents and 579,000+ medical cards. Records contained six images per document — front and back in normal, infrared and ultraviolet light — with date and time stamps. The listing appeared on a Russian-language forum on 31 August. The FBI's New Orleans field office opened an investigation the day Krebs published and confirmed it publicly to Reuters on 2 September. The Nexus site went offline hours after publication. Four class actions were filed on 2 September in the US District Court for the Eastern District of Louisiana. The important qualifier. The lawsuits name identity-verification vendor IDScan.net, but the company has NOT confirmed a breach. It says it is working to validate the information, has not reached conclusions on the nature or scope of any incident, and has secured systems, preserved logs, engaged outside counsel and forensics, and contacted law enforcement. Krebs's evidence is correlative: he found his own licence and nine of a dozen consenting volunteers' licences, and every timestamp matched a moment the person handed a licence to a business — usually a car rental counter. IDScan.net's documentation describes infrared and ultraviolet document scanning, matching the image types in the dump. Compelling, but not proven. A correction worth noting. Early coverage listed brands from IDScan.net's public customer page. Caesars Entertainment stated on 2 September that it has not been a client, stopped using the relevant product in February 2025, had no active accounts at the time, and did not authorise data retention. Also unknown: when collection began (the "over a year" claim comes from the seller's own advertisement), and whether the dataset still circulates. There is no legitimate service where an individual can check exposure. What Australian businesses should do. If you photograph or scan customer ID — real estate, recruitment, RTOs, conveyancing, gyms, venues, car hire, AML checks — this is your risk profile. Four questions: (1) Do you still hold documents you no longer need? Australian Privacy Principle 11.2 requires destruction or de-identification once the permitted purpose has passed. (2) If you use a third-party verification product, where is the image stored, for how long, and what do your contract terms actually say about retention, deletion on termination, sub-processors and breach notification? (3) Could you record a verification event instead of keeping an image? (4) If your ID store were breached tomorrow, could you say how many documents, whose, and how old? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: KrebsOnSecurity; Reuters; BleepingComputer; SecurityWeek; CSO Online; TIME; OAIC (Australian Privacy Principle 11).
PaperCut - 9:42 on a Thursday, Three Emergency Patches, and the Bug the Founder Wrote Himself
A Melbourne software company, a print server, and three emergency patches in six days. The company. PaperCut Software International, founded 1998 by Chris Dance and Matt Doran, headquartered in Melbourne with offices in Portland and London. Privately held, still founder-led. PaperCut's own figure: around 100 million users across more than 70,000 organisations. The timeline. 27 August, 9:42am AEST — an education-sector customer reports a compromised PaperCut MF server; a second organisation reports similar activity at 5:05pm, and its logs allow the full chain to be reconstructed. PaperCut declares a P0 and publishes an advisory deliberately stripped of technical detail. 28 August, 2:10am — Emergency Patch Release 1 for versions 25 and 26; version 24 later that day; CVEs assigned; Emergency Patch Release 2 the same day after watchTowr and Huntress bypass the first fix. 29 August — Defused honeypots see the attacks pivot to database-table dumping. 31 August — both CVEs added to the CISA Known Exploited Vulnerabilities catalogue with a 14 September federal deadline; a Metasploit module is published. 1 September — Emergency Patch Release 3, fixing two regressions and adding hardening. Install it even if you patched earlier. The vulnerabilities. CVE-2026-81578, authentication bypass in the web management interface (CWE-306), 8.8 High under CVSS v4.0. CVE-2026-82078, unsafe dynamic class loading in the database connector (CWE-470), 9.4 Critical under CVSS v4.0. Chained, they give unauthenticated remote code execution: an Apache Tapestry routing quirk lets an attacker display a public page while invoking an admin component, rewrite the external user-lookup settings, and abuse the bundled Apache Derby driver to reach an attacker-controlled H2 database whose initialisation parameter creates a JavaScript-backed trigger that spawns a process. What is not known. No attribution by anyone — not PaperCut, not Huntress, not watchTowr, not CISA. No ransomware gang has claimed it. No victim count, record count or data-category list has been published. Shadowserver tracked 800+ internet-exposed servers as at 1 September; that is an exposure count, not a compromise count. What to do. Patch to Emergency Patch Release 3. Assume compromise if the server was internet-facing and unpatched after 26 August — patching does not evict an existing intruder. Hunt PaperCut's indicators: suspicious activity from pc-app.exe, missing or truncated server.log, and the "no suitable driver found for jdbc:no:x" and "Database error looking up cardID" errors. There are no published network indicators. Then ask why a print server was internet-facing at all. Also timely: the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, released for consultation around 1 September, proposes a hard 72-hour notification deadline to the Information Commissioner. Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: PaperCut security bulletin and Chris Dance's incident blog; Rapid7; BleepingComputer; Cyber Daily; SecurityWeek; CISA Known Exploited Vulnerabilities catalogue; iTnews.
Last Week in Tech - Nvidia Buys Hugging Face, GPT-6 Crosses the Cyber Line, and Seven Exploited Flaws in a Day
Last Week in Tech for Monday 7 September 2026, covering 30 August to 6 September. Nvidia to acquire Hugging Face for US$12.93bn. Confirmed by Nvidia on 3 September, expected to close in the first half of 2027 subject to regulatory approval. Nvidia states the platform serves 18 million+ developers, 3 million+ models and 200,000+ companies, and has committed that Nvidia compute will not be required to build on or deploy through it. OpenAI ships GPT-6 "Astra" (3 September). OpenAI says it is the first model to meet the Critical cybersecurity threshold under its own Preparedness Framework — 100% on ExploitBench versus 78.5% for the prior model, and 39% versus 5.5% on a fresh-vulnerability variant. OpenAI says the model found and disclosed two previously unknown zero-days during evaluation. The shipped model refuses advanced offensive tasks. Separately, OpenAI committed US$1bn in subsidised defensive AI access for critical infrastructure, government, nonprofits and open-source maintainers; eligibility, subsidy level and post-subsidy pricing are not yet disclosed. Broadcom Q3 FY2026 (2 September). Revenue US$29.59bn, up 86% year on year; free cash flow US$13.67bn. CEO Hock Tan, quoted in the release, put AI semiconductor revenue at US$16.7bn, up 221% year on year, with Q4 expected at US$21.7bn. Longer-range AI revenue projections circulating this week came from earnings-call commentary, not the written release. CISA adds seven exploited flaws in one day (2 September). Four sit in AI and DevOps infrastructure — Kestra, JFrog Artifactory, Berri LiteLLM and Starlette. Microsoft reports attackers harvesting LiteLLM database tables for provider API keys and proxy-issued virtual keys, and advises monitoring AI workloads according to their control-plane role. Also on the list: Sangoma Switchvox (CVSS v4.0 9.3), a VoIP platform sold to SMBs, patched 14 July, first seen exploited 30 August. Fixed version 8.4.0.2. Elementor Pro under mass exploitation. Critical arbitrary file upload patched 19 August in version 4.2.2. Wordfence has blocked over 190,000 exploit attempts, and roughly two-thirds of Elementor's 10 million installations were still vulnerable as at 4 September. Indicator of compromise: any .php file under /wp-content/uploads/elementor/forms/. Chrome's sixth zero-day of 2026. V8 type confusion, fix shipped 3 September, added to CISA KEV 4 September. Fixed builds 152.0.7977.82/.83. Relaunch Chrome. Coming up: Wednesday, the PaperCut zero-day chain. Friday, 153 million driver's licence scans on the dark web. Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: NVIDIA newsroom; OpenAI; SecurityWeek; Broadcom investor relations; CISA KEV catalogue; Microsoft Security Blog; The Hacker News; Wordfence; BleepingComputer.
Manchester Airports Group - 8.7 Million Travellers, and the API Keys Sitting in Plain Sight
Manchester Airports Group – 8.7 Million Travellers, and the API Keys Sitting in Plain Sight A deep-dive into the largest known customer data breach at a British airport operator — and the claimed entry vector any developer could have spotted. On 27 August 2026, Manchester Airports Group (MAG) — operator of Manchester, London Stansted and East Midlands airports — disclosed that an unauthorised third party had stolen customer data from its commercial systems: car park bookings, lounges, Fast Track and Wi-Fi sign-ups. Roughly 8.7 million customers were affected. For most, the exposure was an email address; parking, lounge and Fast Track customers also lost phone numbers, UK postcodes and vehicle registration plates. No payment data was held in the affected system, and no airport operational systems were touched — flights ran normally. On 30 August, extortion group FulcrumSec claimed the attack to BleepingComputer: ~86GB stolen, entry via API credentials for third-party marketing platform Iterable allegedly exposed in client-side JavaScript, plus ~200,000 records about upcoming travel. Those claims are unverified — but BleepingComputer independently validated sample data against one traveller's real purchase history, and the samples were far richer than MAG's disclosure: booking references, prices, parking dates and historical spend. In this episode: - The confirmed facts versus the criminal's claims — and why the distinction matters - MAG's response: containment, ICO notification within UK GDPR's 72-hour window, suspending Manage My Booking, and contacting every affected customer - Why postcode + number plate + parking dates is near-perfect phishing bait - Four lessons for Australian businesses: your marketing SaaS stack is attack surface; never ship API keys in client-side code; data minimisation decided this breach's severity years in advance; and assume the true scope is worse than your first assessment Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: BleepingComputer (27 and 30 Aug 2026); Infosecurity Magazine (27 Aug 2026); Security Affairs (30 Aug 2026); MAG data-security incident page; TTG Media (28 Aug 2026, ICO confirmation).
Quest Apartment Hotels - 1.5 Million Guest Records, and the Attacker Who Never Touched Quest's Systems
Quest Apartment Hotels – 1.5 Million Guest Records, and the Attacker Who Never Touched Quest's Systems A deep-dive into Australia's biggest hospitality breach of 2026 — and the vendor-ecosystem attack pattern behind it. On Monday 17 August 2026, Quest Apartment Hotels — 160+ properties, founded in Melbourne in 1988, majority-owned since 2017 (and fully since 2022) by Singapore's The Ascott Limited — identified unauthorised access to a database system. The entry point wasn't Quest's own network: the company says access arose "from a vulnerability through a third-party service provider" holding Quest guest data. Two days later, on 19 August, Quest disclosed publicly and emailed affected guests under the signature of Ascott Australasia managing director David Mansfield. What was taken: records predating June 2025 — full names, email addresses and contact details, street addresses in some records, and a small number of dates of birth. No financial or payment card data. Quest hasn't published a number; ACS Information Age reports more than 1.5 million records were potentially involved. What we don't know: the vendor's identity, the specific vulnerability (no CVE published), and how the attacker got in — Quest has declined to answer. No threat actor has claimed responsibility and no ransom demand is public. The response: containment and remediation completed before disclosure; OAIC, ACSC and other authorities notified; external cyber and privacy advisers engaged; all affected guests contacted. In this episode: Why the vendor ecosystem is now the preferred way in — and how this breach follows Origin Energy, Partnered Health and Lifeline in a bruising winter for Australian data holders - The phishing second wave: why names + contact details + dates of birth are "the raw ingredients for convincing phishing and identity fraud" (Kash Sharma, BlueVoyant) - Five lessons for Australian businesses: map the vendors that touch your customer data; treat data retention as attack surface; know your Notifiable Data Breaches obligations; contract for security before the incident; and warn customers about branded scams that follow Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: ABC News (19 Aug 2026); Information Age / ACS (19–20 Aug 2026); The Register (19 Aug 2026); Cyber Daily (20 Aug 2026); SmartCompany; Australian Cyber Security Magazine; Quest Apartment Hotels statement; 7NEWS.
Last Week in Tech - Nvidia Doubles, Meta Pays $18 Billion, and the Musk-Altman Feud Reaches Your Code Editor
Last Week in Tech – Nvidia Doubles, Meta Pays $18 Billion, and the Musk–Altman Feud Reaches Your Code Editor Your Monday roundup of the technology and security stories that mattered to Australian businesses in the week of 24–30 August 2026. In this episode: Nvidia's record quarter (26 Aug). Revenue US$96.2bn, up 106% year-on-year; data centre US$89bn (~93% of the company); Q3 guided to ~US$108bn and CFO Colette Kress forecasting ~70% growth for fiscal 2028. What an accelerating AI capex cycle means for your cloud pricing and FY27 budget. - Meta's teen-harm settlement (26 Aug). Up to ~US$17bn — Meta itself puts it at ~US$18bn over ten years, ~US$12.7bn guaranteed — settling the multistate lawsuit filed by 33 state attorneys-general, without a finding of liability, but with enforceable product changes: two-hour daily limits and a midnight–6am curfew for under-18s, likes hidden by default on children's accounts, cosmetic filters banned for minors, most school-hours notifications off. A template for how Australia's under-16 social media ban could be enforced, and a warning on design-liability risk. - OpenAI to cut Cursor off (29 Aug). After SpaceX's US$60bn acquisition of Cursor-maker Anysphere closed on 14 Aug, OpenAI proposed ending model access on 12 November, citing its litigation history with Elon Musk's companies. Cursor says OpenAI models are ~5% of traffic. Concentration risk in AI dev tooling: know which models your tools depend on. - Alibaba's Wan 3.0 (24 Aug). Document-to-video AI at ~US$6 per 30-second clip — and the data-sovereignty question to ask before marketing uploads anything. - Security round. Citrix NetScaler CVE-2026-8452 (8.8 CVSS v4.0) — disclosed in June as denial-of-service, reclassified to unauthenticated RCE, added to CISA's KEV on 26 Aug with web shells found on compromised appliances; Zimbra CVE-2026-73570 (8.9 CVSS v3.1) — single-email command injection, 270+ servers confirmed compromised, ~8,200 still unpatched; and Boston Scientific's still-unattributed cyberattack halting order shipping and manufacturing worldwide. Coming up: Wednesday, the Quest Apartment Hotels breach. Friday, Manchester Airports Group in full. Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: CNBC, Fortune and Kiplinger on Nvidia Q2 FY2027 results (26 Aug 2026); CNN Business, Bloomberg and Al Jazeera on the Meta settlement (26–27 Aug 2026); CNBC and the OpenAI blog on Cursor model access (29 Aug 2026); Seeking Alpha on the SpaceX–Anysphere close (14 Aug 2026); Dataconomy and Winbuzzer on Alibaba Wan 3.0 (24–25 Aug 2026); Help Net Security, SecurityWeek, BleepingComputer and CISA KEV on Citrix CVE-2026-8452; The Hacker News, runZero, Shadowserver and CCB Belgium on Zimbra CVE-2026-73570; TechCrunch, The Register and BleepingComputer on Boston Scientific (26 Aug 2026).
Metabase - The Reporting Tool That Held Every Key, and the Five Companies That Found Out
A deep-dive on CVE-2026-72898, the unauthenticated SQL injection zero-day exploited against Metabase Cloud in early August 2026. Two corrections to our roundup of 17 August, made on air. A CVE has since been assigned - CVE-2026-72898, added to CISA's Known Exploited Vulnerabilities catalogue on 11 August and rated 10.0 under both CVSS v3.1 and v4.0. And LexisNexis has explicitly ruled out any connection between its service outage and this flaw: the similarly-named Nexis Metabase API is an unrelated product, and LexisNexis is not a Metabase Cloud customer. The timeline. 2 Aug: attacker active in Kilo Code's instance for about four hours. 3 Aug: broader attack on Metabase Cloud; Metabase detects, blocks and patches the same day. 6 Aug: public advisory; Framework notified, and notifies its own customers. 8 Aug: a researcher publishes a proof-of-concept lab. 10 Aug: CVE assigned; public exploits go open-source; Checkly and Wiz publish. 11 Aug: added to CISA KEV with a 14 August deadline; a second Metabase advisory covers further flaws; ShinyHunters lists Metabase on its leak site. The vulnerability. An unauthenticated POST to /api/session/reset_password. Four individually correct behaviours chain together: Clojure's merge not stripping attacker-supplied keys when authentication fails; JSON keywordisation; HoneySQL's raw keyword, a deliberate feature that bypasses parameterisation; and a lookup that compiles the result into unparameterised SQL. The result is blind SQL injection against the application database, leading to a forged administrator session. As Checkly put it, no password was stolen. The patch is a three-line type check. Exposure. Dataminr's 8 August scan found roughly 11,000 probable self-hosted instances, 4,309 likely vulnerable, and over 97% of fingerprinted hosts on an affected branch unpatched. Five victims disclosed, all Metabase Cloud tenants, all of whom published their own post-mortems: Framework Computer (names, emails, login IPs, addresses, phone numbers; VAT and EIN for business customers), Tally (emails and hashed passwords), n8n (136 records, plus a separately-discovered 2023 plaintext password bug), Kilo Code and Anaconda (names, emails, billing addresses, user prompts, later Slack access tokens), and Checkly (26 minutes of read-only warehouse queries exposing plaintext credentials hard-coded into check configurations). Metabase has never said how many tenants were affected. Attribution: unconfirmed. ShinyHunters listed Metabase on 11 August, but Dataminr assessed the listing as a placeholder with no scope named. Metabase has named nobody. Treat it as a claim. Check your own instance. In application or ingress logs, look for a POST to /api/session/reset_password returning HTTP 400 immediately followed by a GET to /api/user/current returning HTTP 200. That pattern indicates likely compromise. Five lessons. One: your BI tool is a production system holding a key ring - audit what it stores and scope those service accounts to read-only. Two: internet-facing auth endpoints on internal tools are an unforced error. Three: using the managed version is not the same as not being affected. Four: rotate sessions and downstream credentials, not just passwords - there was no malware, and both survive a patch. Five: use the secrets store, not free-text config fields. Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: NVD and CVE.org; CISA KEV; Metabase advisories GHSA-vwf4-m7j8-wcjf and GHSA-r495-55cx-fjh7; Wiz; Bishop Fox; Dataminr; BleepingComputer; and disclosures by Checkly, n8n, Kilo Code, Framework and Tally.
Bendigo Bank - 1,598 Accounts, One Password, and the $8 Million Bill That Arrived Three Years Later
On 11 August 2026, Bendigo and Adelaide Bank accepted a proposed $8 million penalty over a March 2023 cyber attack on Service One Alliance Bank. The court documents contain a sentence worth reading twice: at the time the attack began, 1,598 customer accounts were protected by the password 123456. The timeline. 2020: penetration testing identifies security weaknesses in the Alliance Bank environment. Not remediated. October 2022: a threat actor attempts brute-force login attacks and fails; the board is told the bank is at a critical point of needing further investment in resourcing and capability. No substantive review is undertaken. March 2023: an unidentified attacker brute-forces approximately 257 customer accounts. 10 August 2026: APRA files an Originating Application in the Federal Court. 11 August 2026: APRA announces publicly and Bendigo lodges an ASX announcement accepting the proposed penalty. The numbers - all official, from APRA, the Federal Court filing and Bendigo's ASX announcement, none of them threat-actor claims: 257 accounts accessed; 286 unauthorised transactions; 87 customers affected by a transaction; approximately $490,000 misappropriated; about $140,000 unrecoverable; all customers fully reimbursed; 1,598 accounts using 123456; an $8m proposed penalty; and about $2.6m in additional legal costs. The three named control weaknesses: password settings permitting very weak passwords; multiple accounts protected by identical passwords; and system design that enabled the attacker to identify valid customer IDs - account enumeration. The regulatory angle. This is not an OAIC or Notifiable Data Breaches matter, because no bulk personal information was taken. The regulator is APRA and the instrument is the Banking Executive Accountability Regime. All four admitted failures are governance failures: inadequate authentication controls, no systematic testing programme, accountable persons' responsibilities not covering the Alliance Bank IT system, and inadequate information security governance. Attribution: none. APRA and the court documents describe an unidentified threat actor. No group claimed it, no data was published, no ransomware was involved. Five lessons. One: a penetration test you don't remediate is worse than no penetration test - it is a dated written record that you were told. Two: treat a failed attack as a real incident; October 2022 was a rehearsal nobody reviewed. Three: password policy isn't solved because you assume it is - go and measure it, and make MFA default rather than optional. Four: account enumeration is a vulnerability, not a UX detail - identical responses and identical timing, whether or not the account exists. Five: outsourced, white-labelled or subsidiary IT still carries your accountability, so put a person's name, not a team's, against every system your customers touch. The penalty is roughly 16 times the amount stolen. It isn't for the loss; it's for the three years between the finding and the fix. Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: APRA media release, Bendigo and Adelaide Bank admits breaching its BEAR obligations, 11 August 2026; APRA Originating Application, Federal Court of Australia, stamped and redacted, 10 August 2026; Bendigo and Adelaide Bank ASX announcement, 11 August 2026; Information Age (Australian Computer Society), 12 August 2026; Cyber Daily, 11 August 2026; FST Media; Lawyerly; Mortgage Professional Australia.
Last Week in Tech - Nvidia Turns GPUs Into an Asset Class, the AI Price War Breaks Out, and an AI Agent Goes to War
Your Monday roundup of the technology and security stories that mattered to Australian businesses in the week of 10-16 August 2026. Nvidia's $500bn financing platforms (10 Aug). MOUs with Apollo, BlackRock, Blackstone, Brookfield, Goldman Sachs and KKR to mobilise third-party capital for AI compute. Why an MOU is not a contract, and the reported - but not company-confirmed - 25% loan backstop. The AI price war (11-14 Aug). Gemini 3.7 Flash three weeks after 3.6 at half the price; GPT-5.6 Luna cut ~80%; Claude Opus 5 at $5/$25 with the Sonnet 5 price rise cancelled; DeepSeek raising prices sharply. What to do about your existing vendor agreement - and why introductory pricing that expires at end-2026 isn't a 2027 budget line. The near-autonomous AI agent attack on Taiwan (12 Aug). Open-source agent frameworks, guardrails bypassed by claiming authorised pen-testing, and an operation that expanded its own scope. Plus OpenAI's Daybreak Blue and Red tiers, and 51 US House Democrats asking questions. The chip money wave (10-13 Aug). TSMC's record July (+44.7% YoY), Intel's upsized $20bn raise, Cisco's $9.3bn of AI infrastructure orders, Applied Materials' record quarter - and why beating expectations still moved three of these share prices down. IBM and OpenAI (13 Aug), Gemini past 1bn users, and Anthropic watermarking Claude output worldwide - the first clearly visible case of EU AI Act compliance being exported globally by default. Security round. August Patch Tuesday (~400 CVEs, one exploited zero-day, CVE-2026-68820, attributed to Lazarus a day later); VMware vCenter CVE-2026-59310 exploited five days after disclosure with 361 victims in 47 countries; SAP Commerce Cloud CVE-2026-58231 exploited three days after patch day; Cisco ASA/FTD CVE-2026-20349; Adobe Commerce CVE-2026-71362 exploited within hours; unpatched GeoServer and Windows Defender ShieldBreak zero-days with no CVE at all; and macOS Screen Sharing CVE-2026-65400 being used to plant Monero miners on internet-exposed Macs. Incidents: the Ceva Logistics breach rippling to Steam, ING, Bol, De Bijenkorf and Ajax; and ransomware taking out doors and HVAC - not clinical systems - at Manitoba's largest hospital. Coming up: Wednesday, the Bendigo Bank cyber penalty. Friday, the Metabase zero-day in full. Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Nvidia newsroom, CNBC, Bloomberg, TechCrunch, Reuters, VentureBeat, Financial Times, Dream Group research, CyberScoop, The Register, CNN, OpenAI, The Hill, TSMC and Intel investor relations, Cisco, Applied Materials, IBM newsroom, Ars Technica, Axios, SecurityWeek, BleepingComputer, The Hacker News, Zero Day Initiative, Tenable, Rapid7, CISA, Onapsis, Dutch NCSC, The Record, CBC.