Manchester Airports Group - 8.7 Million Travellers, and the API Keys Sitting in Plain Sight
Manchester Airports Group – 8.7 Million Travellers, and the API Keys Sitting in Plain SightA deep-dive into the largest known customer data breach at a British airport operator — and the claimed entry vector any…
Quest Apartment Hotels - 1.5 Million Guest Records, and the Attacker Who Never Touched Quest's Systems
Quest Apartment Hotels – 1.5 Million Guest Records, and the Attacker Who Never Touched Quest's SystemsA deep-dive into Australia's biggest hospitality breach of 2026 — and the vendor-ecosystem attack pattern behind it.On Monday 17 August…
Last Week in Tech - Nvidia Doubles, Meta Pays $18 Billion, and the Musk-Altman Feud Reaches Your Code Editor
Last Week in Tech – Nvidia Doubles, Meta Pays $18 Billion, and the Musk–Altman Feud Reaches Your Code EditorYour Monday roundup of the technology and security stories that mattered to Australian businesses in the week…
Metabase - The Reporting Tool That Held Every Key, and the Five Companies That Found Out
A deep-dive on CVE-2026-72898, the unauthenticated SQL injection zero-day exploited against Metabase Cloud in early August 2026.Two corrections to our roundup of 17 August, made on air. A CVE has since been assigned - CVE-2026-72898,…
Bendigo Bank - 1,598 Accounts, One Password, and the $8 Million Bill That Arrived Three Years Later
On 11 August 2026, Bendigo and Adelaide Bank accepted a proposed $8 million penalty over a March 2023 cyber attack on Service One Alliance Bank. The court documents contain a sentence worth reading twice: at…
Last Week in Tech - Nvidia Turns GPUs Into an Asset Class, the AI Price War Breaks Out, and an AI Agent Goes to War
Your Monday roundup of the technology and security stories that mattered to Australian businesses in the week of 10-16 August 2026.Nvidia's $500bn financing platforms (10 Aug). MOUs with Apollo, BlackRock, Blackstone, Brookfield, Goldman Sachs and…
N-able N-central – God Mode on the Management Plane, and the Hotfix That Wasn't Enough
At the start of August 2026, attackers exploited an authentication bypass in N-able's N-central remote monitoring and management platform to obtain full administrative control of the console - and then used the product's own legitimate…
Court Services Victoria – A Hearing-Link List, 28,600 Lines, and the Victims Nobody Can Name
In July 2026, someone accessed the system Victorian courts use to link participants to online hearings. Not the case management system - the joining list. Four years of it, across ten regional court locations, for…
Last Week in Tech – Google Reshuffles Its AI Empire, Washington Writes a Rulebook It Won't Show You, and Memory Sold Out to 2030
Your Monday roundup of the technology and security news that matters to Australian businesses, covering 3-9 August 2026.In this episode:Google's AI leadership shake-up (5 Aug). Demis Hassabis moves to Chair of Google DeepMind and Chief…
Thirty Towns Without Water Controls – Minnesota, Rigged PLCs, and the Bug That Can't Be Patched
Over two days in late July, a coordinated attack disrupted water and wastewater operations across more than 30 Minnesota communities — Braham's well and treatment plant shut down entirely, Plymouth disconnected cellular-connected water towers and…
GO2 Health – A Veterans' Clinic, One Mailbox, and the Twelve Weeks Nobody Was Told
A Brisbane medical practice serving thousands of veterans lost Department of Veterans' Affairs ID numbers from a single email mailbox after a phishing attack — and then took twelve weeks to tell the patients. We…
Last Week in Tech – A Record $450 Billion Day, $720 Billion of AI Capex, and the Memory Bill Landing on Your Desk
Big Tech's June quarter delivered the largest single-day market value gain in history — Microsoft added roughly US$450 billion on the back of 43% Azure growth and Azure's first $100bn year — while Meta fell…
SonicWall SMA1000 – Zero-Days at the Edge, Stolen MFA Seeds, and a Password Called admin:admin
Two SonicWall SMA1000 flaws — an unauthenticated SSRF rated a perfect 10.0 (CVE-2026-15409) and a path-traversal-to-root bug (CVE-2026-15410) — were exploited as zero-days from at least 22 June, three weeks before the 14 July patches.…
Lifeline Australia – A Serial Hacker, Doctored Data, and the Charity Sector's Security Gap
Australia's best-known crisis-support charity confirmed a breach after a serial hacker known as "2019" dumped 10,000+ staff and volunteer records on an underground forum — for free. We cover the timeline (forum post 11 July,…
Last Week in Tech – Claude Opus 5, a Patchless Java Zero-Day, and EY's Support-Desk Breach
Frontier AI gets cheaper from two directions this week: Anthropic's Claude Opus 5 lands at unchanged pricing with state-of-the-art benchmarks, while Moonshot AI drops the largest open-weight model ever (Kimi K3, ~2.8T parameters) — big…
When the Hacker Was the AI – How OpenAI's Own Models Breached Hugging Face
The industry's long-predicted "agentic attacker" arrived — and it was wearing a lab coat. Hugging Face disclosed a breach of its production infrastructure by an autonomous AI agent: a malicious dataset exploited two code-execution flaws,…
Origin Energy – A 3:40am Email, an Extortionist Called "John Doe", and Millions of Customers in Limbo
Australia's largest energy retailer confirmed unauthorised access to customer data after an extortionist calling themselves "John Doe" took the story to journalists first. We walk through the timeline — the 3:40am customer emails, the ASX…
Last Week in Tech – The AI Capex Reckoning, AMD's Anthropic Deal, and WordPress Under Attack
The market finally asks AI to show its receipts. This week: Alphabet and Tesla beat on revenue but get hammered for record capex — the Nasdaq's worst day since April — while Intel posts its…
Coca-Cola's Fairlife – The Ransomware Attack That Stopped the Milk
This week's global deep-dive is about ransomware you can see on a supermarket shelf. On 16 July, Coca-Cola disclosed in a formal SEC filing that its billion-dollar dairy subsidiary Fairlife had been hit by a…
Partnered Health – A GP Network Breach, 21 Clinics, and a Court Order Against Criminals
This week's Australian deep-dive is a confirmed breach at Partnered Health, the operator of more than 60 medical, skin-cancer and allied-health clinics nationwide. An intruder detected on 23 June stole personal and health information tied…