
Tech Talks With Kinsoft
by Steven Kinnas
Last Week in Tech – Apple's Gemini-Powered Siri, ShinyHunters Hit PeopleSoft, and the AI-Chip Land Grab
Your Monday catch-up on the week that was in tech, with a security lens. This week: Apple finally reveals its overhauled, AI-powered Siri at WWDC 2026 — running partly on Google's Gemini models. The AI infrastructure land grab heats up as Alphabet rents out its new TPUs in a $5B Blackstone joint venture and Microsoft ships its Maia 200 accelerator. Anthropic's Claude posts eye-watering growth and formalises a $100M partner program. And on the security desk: ShinyHunters exploit an Oracle PeopleSoft flaw to hit universities, Europol dismantles a €336M crypto-laundering pipeline used by ransomware crews, CISA flags three newly exploited vulnerabilities, and a new gang called The Gentlemen climbs the ransomware rankings. Want last week's headlines turned into a plan for your own environment? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Apple Newsroom; Engadget; CNBC; NPR; TechCrunch; Tech Startups; BuildFastWithAI; Europol; Google/Mandiant; CISA.Under Armour Breach – 72 Million Customer Accounts Exposed
In a major global incident, the Everest ransomware group claimed sportswear giant Under Armour as a victim in late 2025, alleging access to around 343GB of data — and in January 2026 a dataset containing roughly 72 million customer email addresses (about 72.7 million accounts) was published on a hacking forum. In this episode of Tech Talks with Kinsoft, we cover the data involved — names, email addresses, dates of birth, locations and purchase information — the verification by services like Have I Been Pwned, the class-action lawsuits that followed, and Under Armour's response, including that it was investigating and found no evidence its payment-processing or password systems were affected. We flag where claims are alleged rather than confirmed. Worried about brand-scale breaches and protecting customer data? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: TechCrunch; Malwarebytes.Champion Homes Data Breach – Inside the DragonForce Ransomware Attack
Sydney home builder Champion Homes has confirmed a cyber incident after the DragonForce ransomware group claimed responsibility for an attack that saw roughly 44GB of company data stolen and leaked to the dark web. In this episode of Tech Talks with Kinsoft, we unpack what happened: the data taken — including employee payroll records, customer quotes, and tender and legal documents — how DragonForce's ransomware-as-a-service model operates, and how Champion Homes contained the incident and notified the relevant authorities while continuing to operate across the Sydney and Illawarra regions. Concerned about your own exposure to ransomware and data breaches? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Cyber Daily; Real Estate Business.Last Week in Tech – Copilot's Billing Backlash, SoftBank's €75B France Bet, and the Klue OAuth Supply-Chain Hit
Your Monday catch-up, with a security lens. This week: GitHub Copilot switches to token-based billing and developers revolt over surprise bills, Microsoft shows off a cheaper homegrown coding model at Build, and SoftBank commits up to €75B to AI data centres in France — Europe's biggest such bet. On the breach desk: an OAuth attack on sales-intelligence firm Klue cascades into Salesforce data theft across HackerOne, Gong, OneTrust, Tanium and Huntress; Nintendo is hit by ransomware; and Oxford's careers platform is breached. The OAuth supply-chain pattern is the one to watch. Using connected SaaS apps and OAuth integrations? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: BuildFastWithAI; Medium (David Akpovi); imfounder; SharkStriker; The Hacker News.Charter/Spectrum – ShinyHunters Vishing Breach
Charter Communications (Spectrum) confirmed in late May 2026 that it had suffered a data breach after ShinyHunters claimed to have stolen customer records; roughly 4.9 million accounts had personal details exposed (the group claimed far more from Charter's Salesforce). ShinyHunters says it used a vishing call on 1 April 2026 to trick a Charter employee into surrendering Microsoft Entra access, then reached Salesforce data. We tie it to the broader ShinyHunters Salesforce and SSO campaign and the recurring vishing playbook. Want to harden your identity provider against vishing? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Security Affairs; Techlicious.Gelatissimo Data Breach – DragonForce and the 352GB Heist
In April 2026, the DragonForce ransomware group claimed it breached Gelatissimo, the Australian artisanal gelato franchise, and listed the company on its dark web leak site. In this episode of Tech Talks with Kinsoft, we cover what the group alleges it took — around 352GB of data, with sample screenshots showing employee payroll details, partial tax file numbers, and a visa application containing a passport number — the extortion threat to publish the data, and Gelatissimo's response, including engaging cyber security experts and notifying the OAIC and the Australian Cyber Security Centre. We flag throughout where claims are alleged rather than confirmed. Worried about ransomware and the safety of your staff and customer data? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Cyber Daily; ACS Information Age.Last Week in Tech – Anthropic's $900B Round, AI Guardrails Stripped in Minutes, and Trellix's Source-Code Breach
Your Monday catch-up, with a security lens. This week: Anthropic is reportedly closing a $30B round at a $900B-plus valuation and projecting its first-ever quarterly operating profit — even as SpaceX filings reveal eye-watering compute bills. The politics heat up as President Trump abruptly cancels an AI executive order. A worrying safety finding shows researchers stripping the guardrails off major AI models in minutes. And on the breach desk: security vendor Trellix has attackers in its own source code, drug-delivery manufacturer West Pharmaceutical recovers from a crippling attack, and education-sector attacks jump again. Concerned your security tools themselves could be a target? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Tech Startups; BuildFastWithAI; Bloomberg; Comparitech; cm-alliance.Carnival Corporation Breach – 6 Million Cruise Customers Exposed
On 14 April 2026, Carnival Corporation detected unauthorised activity after a bad actor used social engineering to compromise an employee account. In this episode of Tech Talks with Kinsoft, we cover the global breach that affected roughly 5,995,277 individuals — almost 6 million — the categories of data potentially involved, the timeline through to the company's customer notifications and dedicated breach webpage on 27 May 2026, and the support offered including complimentary credit monitoring. It's a reminder that human-targeted attacks remain one of the most effective ways in. Worried about social engineering and account takeover? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: News4Jax; Hoplon InfoSec.VSP Solutions – Stormous Hits a Security-Hardware Distributor
VSP Solutions, a NSW distributor of video-security hardware (Hikvision, Axis and similar), became aware of an incident on 13 May 2026; the Stormous group listed it on 23 May claiming 40 GB+ including financial backups, email archives, staff folders and customer and client databases. VSP's position is that the affected data was historical and related-business and that current operations were unaffected. A lens on distributor and supply-chain risk and protecting archived data. Sit in someone's supply chain? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Cyber Daily.Last Week in Tech – Google's Agentic Gemini, the Coding-Agent Gold Rush, and CISA's Own Key Leak
Your Monday catch-up, with a security lens. This week: Google goes all-in on agents at I/O 2026 with Gemini 3.5 and a new any-input video model, Gemini Omni. Three rival coding agents launch in three days as the price of frontier coding power keeps falling. SpaceX's S-1 lifts the lid on xAI's finances, and Anthropic teams up with the Gates Foundation on a $200M global-development push. On security: a CISA contractor accidentally exposes AWS GovCloud keys on a public GitHub repo, Canadian police arrest the alleged operator of a massive IoT botnet, and a Vietnamese government network is breached. Building or buying AI tools and not sure how to keep your secrets out of public repos? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Tech Startups; Medium (David Akpovi); Digital Applied; The Hacker News; cm-alliance.