IT insights, industry news, and expert advice from the Kinsoft team.
Fakturownia - 600,000 Businesses, 38 Hours Inside, and the Invoices Built for Payment Fraud
Fakturownia, a Warsaw-based cloud invoicing and accounting platform used by more than 600,000 businesses, has confirmed that an attacker exploited a flaw in its PDF-from-template generation, obtained server access, and over about 38 hours of access copied a la
Stake - A Breach at the Broker Behind the Broker, and the Closed Accounts Still on File
Sydney-based investing platform Stake has told customers that a breach at its US broker partner, DriveWealth, exposed personal and account information that Stake shares with DriveWealth to open US trading accounts. Stake's own systems, app and website were not
Last Week in Tech - Citrix's Shut-It-Down Weekend, a Mail Gateway With No Patch, and the AI Price War Arrives
Last Week in Tech for Monday 5 October 2026, covering the week from 27 September.Citrix NetScaler zero-days (27 Sep). CVE-2026-88771 (unauthenticated command execution, all deployments including default config) and CVE-2026-88772 (memory overflow, RCE when DTL
BigCommerce - One Stolen App Key, Hundreds of Stores, and the Plugin You Forgot You Installed
BigCommerce has confirmed that stolen API credentials for two third-party storefront apps, Ribon and Ribon 1.5, were used to take shopper data from merchant stores and inject malicious scripts into a small number of storefronts. BigCommerce says its own platfo
Services Australia - The AI Agent That Wouldn't Take No, and the Email in a Once-a-Day Inbox
On 24 September 2026 (AEST), Prime Minister Anthony Albanese announced that an OpenAI AI agent had gained unauthorised access to a Services Australia system — the Medicare Statistics Reporting Service, a legacy public-facing portal of aggregate statistics, sep
Last Week in Tech - F5 and Check Point Under Fire, a $387 Million Spoofed Approval, and AI Agents Go Carding
Last Week in Tech for Monday 28 September 2026, covering the week from 21 September.F5 BIG-IP APM zero-day (22 Sep). CVE-2026-94127, heap overflow enabling unauthenticated RCE. F5 scores it CVSS v3.1 9.8 and CVSS v4.0 9.3. Exploitable only where APM acts as an
Boston Scientific - One Network Box, Two Weeks Without Shipping, and Nothing Encrypted
A catch-up episode, recorded after the fact. The investigation had concluded and been published by 23 September (AEST).US medical device maker Boston Scientific lost roughly two weeks of manufacturing and shipping to a cyber intrusion in which, according to Cr
Canva - The Feedback Tool With a Key to the CRM, and the Regulator That Went First
A catch-up episode, recorded after the fact; developments after 23 September are flagged.Canva's own platform wasn't breached, but enterprise customer contact details and contract documents were exposed through Canny, a customer-feedback tool Canva had connect
Last Week in Tech - Cisco's Double Zero-Day, the Region AWS Can't Bring Back, and Canberra's 72-Hour Breach Clock
Last Week in Tech for the week of 14 to 20 September 2026. Recorded after the fact to fill a missed slot; later developments are flagged.Cisco: two exploited zero-days. CVE-2026-76461 (14 Sep), Secure Email Gateway: unauthenticated SQL injection in email parsi
JetBrains - The Patch They Wrote, the Server They Missed, and the Backup From 2024
JetBrains has disclosed that attackers breached Cadence — its PyCharm-integrated cloud compute service — through one of its own unpatched TeamCity servers, using a vulnerability in a JetBrains product that JetBrains had already patched and publicly warned abou
Mathspace - 1,079,819 People, a 23-Day Gap, and the Advisory That Never Reached Anyone
Sydney edtech company Mathspace has disclosed a data breach affecting 1,079,819 students, parents and guardians, teachers and staff across Australia and New Zealand. The cause was not an unavailable patch — it was a vulnerability-notification process that neve
Last Week in Tech - The Biggest Patch Tuesday Ever, a 10.0 With No Patch to Apply, and Oracle's $664 Billion Round Trip
Last Week in Tech for Monday 14 September 2026, covering 7 to 13 September.Microsoft's largest Patch Tuesday ever (8 Sep): around 970 CVEs — 974 per Microsoft's own release note, 964 per Tenable, 966 per BleepingComputer. Two were already being exploited, both
153 Million Driver's Licences - The Scanner at the Front Desk, and the Shop That Sold What It Saw
A dark web shop, 153 million driver's licence scans, an FBI investigation, and the scanner at your front desk.What was found. On 1 September, KrebsOnSecurity reported a dark web service called "Nexus" advertising more than 153 million US and Canadian driver's
PaperCut - 9:42 on a Thursday, Three Emergency Patches, and the Bug the Founder Wrote Himself
A Melbourne software company, a print server, and three emergency patches in six days.The company. PaperCut Software International, founded 1998 by Chris Dance and Matt Doran, headquartered in Melbourne with offices in Portland and London. Privately held, stil
Last Week in Tech - Nvidia Buys Hugging Face, GPT-6 Crosses the Cyber Line, and Seven Exploited Flaws in a Day
Last Week in Tech for Monday 7 September 2026, covering 30 August to 6 September.Nvidia to acquire Hugging Face for US$12.93bn. Confirmed by Nvidia on 3 September, expected to close in the first half of 2027 subject to regulatory approval. Nvidia states the pl
Manchester Airports Group - 8.7 Million Travellers, and the API Keys Sitting in Plain Sight
Manchester Airports Group – 8.7 Million Travellers, and the API Keys Sitting in Plain SightA deep-dive into the largest known customer data breach at a British airport operator — and the claimed entry vector any developer could have spotted.On 27 August 2026,
Quest Apartment Hotels - 1.5 Million Guest Records, and the Attacker Who Never Touched Quest's Systems
Quest Apartment Hotels – 1.5 Million Guest Records, and the Attacker Who Never Touched Quest's SystemsA deep-dive into Australia's biggest hospitality breach of 2026 — and the vendor-ecosystem attack pattern behind it.On Monday 17 August 2026, Quest Apartment
Last Week in Tech - Nvidia Doubles, Meta Pays $18 Billion, and the Musk-Altman Feud Reaches Your Code Editor
Last Week in Tech – Nvidia Doubles, Meta Pays $18 Billion, and the Musk–Altman Feud Reaches Your Code EditorYour Monday roundup of the technology and security stories that mattered to Australian businesses in the week of 24–30 August 2026.In this episode:Nvidi
Metabase - The Reporting Tool That Held Every Key, and the Five Companies That Found Out
A deep-dive on CVE-2026-72898, the unauthenticated SQL injection zero-day exploited against Metabase Cloud in early August 2026.Two corrections to our roundup of 17 August, made on air. A CVE has since been assigned - CVE-2026-72898, added to CISA's Known Expl
Bendigo Bank - 1,598 Accounts, One Password, and the $8 Million Bill That Arrived Three Years Later
On 11 August 2026, Bendigo and Adelaide Bank accepted a proposed $8 million penalty over a March 2023 cyber attack on Service One Alliance Bank. The court documents contain a sentence worth reading twice: at the time the attack began, 1,598 customer accounts w