Latest / Tech Talks With Kinsoft / Last Week in Tech – Microsoft's Agents Go GA, the Canvas Mega-Breach Escalates, and DigiCert's Cert Compromise
Transcript
- 0:00Imagine building like the ultimate completely
- 0:02impenetrable fortress. I am talking titanium
- 0:05walls, laser grids, biometric scanners that check
- 0:10your retina and your fingerprints. The whole
- 0:12nine yards. Right. The whole nine yards. You
- 0:14spend billions on the architecture and it is
- 0:16mathematically perfect. And then on day one,
- 0:19the security guard stationed at the front desk
- 0:22gets a phone call. from someone pretending to
- 0:25be, I don't know, the fire inspector. And the
- 0:27guard just casually props the titanium backdoor
- 0:30open with a brick. Wow. Yeah, it completely invalidates
- 0:33the billion -dollar laser grid, right? Because
- 0:35the technology worked flawlessly, but the overall
- 0:38system still suffered a, well, a catastrophic
- 0:41failure just because of that human element. Welcome
- 0:44to the Deep Dive. Today, we are looking at a
- 0:47recent, incredibly revealing snapshot from the
- 0:49tech landscape. It's the Tech Talks with Kinsoft
- 0:52update from May 11th, 2026. A really fascinating
- 0:56brief. It is, because this single document captures
- 1:00this terrifying paradox about where we are right
- 1:04now. You know, we are building these mathematically
- 1:06perfect digital fortresses, but we are just leaving
- 1:10those titanium doors. propped open everywhere.
- 1:13Yeah, that's exactly it. On one hand, our technology
- 1:15is becoming unbelievably autonomous and capable.
- 1:18But then on the other hand, our biggest vulnerabilities
- 1:20are still fundamentally human. It really is kind
- 1:25of the defining tension of this era we're in.
- 1:28When we analyze this Kinsoft source material,
- 1:30two major interconnected themes emerge for you
- 1:34to really think about. Right. First, we have
- 1:36the official mainstream arrival of autonomous
- 1:38AI agents. And then running totally parallel
- 1:41to that massive leap forward, we have a series
- 1:44of just catastrophic cyber breaches. Huge ones.
- 1:47Yeah. And the narrative thread tying this all
- 1:49together is that as we hand over more power to
- 1:52technology to act on our behalf, you know, the
- 1:54human gatekeepers managing these systems are
- 1:56increasingly becoming our absolute weakest link.
- 1:59Okay, let's unpack this because we have to start
- 2:01with a big announcement from Microsoft's recent
- 2:02build conference. Oh, absolutely. According to
- 2:04the Kinsoft update, Microsoft has officially
- 2:07made the, quote, agent era a reality. They announced
- 2:11that their Agent 365 platform, along with this
- 2:14entirely new agent framework and a whole stack
- 2:17of in -house AI models, has moved to general
- 2:20availability. Right. General availability is
- 2:22the key term there. Yeah. Plus they rolling out
- 2:25a new unified intelligence layer across all the
- 2:28developer tools. So we are officially out of
- 2:31the experimental sandbox here. But, you know,
- 2:33what does that actually mean for you, the listener?
- 2:35We hear words like framework and layer. all the
- 2:38time in tech we do but if we connect this to
- 2:41the bigger picture the shift to general availability
- 2:43is a massive milestone this isn't uh beta testing
- 2:47for a few select tech enthusiasts in a basement
- 2:49anymore right this is a fully supported enterprise
- 2:52-grade product rolling out to the global mainstream
- 2:54and the transition here the really important
- 2:56part is moving from conversational ai to agentic
- 3:00ai okay break that down a bit well For the last
- 3:02few years, we have basically been talking to
- 3:04incredibly smart chatbots, right? You ask a question,
- 3:08it generates some text. But an AI agent is an
- 3:12entity designed to take real independent actions
- 3:15inside your actual software ecosystem. So rather
- 3:18than just like generating a draft of an email
- 3:21that I have to manually copy and paste, the agent
- 3:24actually reads my inbox, decides an email needs
- 3:27to be sent, writes it, and literally hits the
- 3:29send button for me. that is the practical application
- 3:31yes it's doing the work yeah and to understand
- 3:35how that actually functions we have to look at
- 3:38that unified intelligence layer you mentioned
- 3:40earlier okay think of previous ai as like a brain
- 3:43trapped in a jar a brain in a drawer right it
- 3:46was really smart but it couldn't touch anything
- 3:47yeah this new unified intelligence layer acts
- 3:50like a nervous system connecting all your different
- 3:52applications it provides the digital roads for
- 3:55the agent to travel between your word processor
- 3:57your email client your corporate database. And
- 4:01the framework itself gives the AI the hands to
- 4:04actually push buttons and move files across those
- 4:07different software environments. It is honestly
- 4:09like hiring a brand new, incredibly fast, hyper
- 4:13-efficient digital employee. You bring them on
- 4:15board and suddenly you have this massive workforce
- 4:18multiplier. Oh, massive. But wait, I have to
- 4:21push back here for a second. Think about it like
- 4:23corporate credit cards. Okay. If you give a corporate
- 4:26card to a human employee, you have an HR file.
- 4:29You've done a background check. You have a manager
- 4:31actively watching their spending. Hopefully,
- 4:32yeah. Hopefully. But if we are handing out digital
- 4:36ID badges to these AI agents, you know, giving
- 4:40them access to our sensitive corporate environments,
- 4:43how do we actually govern a machine's identity
- 4:46and its access rights? Oh, the million dollar
- 4:48question. Right. Because imagine handing out
- 4:5010 ,000 corporate cards in a single second to
- 4:53invisible digital workers. Yeah. How do you even
- 4:56begin to track who's doing what? You've hit on
- 4:58the exact vulnerability the Kinsoft update explicitly
- 5:01warns about. Every single agent you deploy is
- 5:05a new non -human identity with access rights
- 5:08that absolutely must be governed. It's just a
- 5:10massive headache waiting to happen. It is. When
- 5:13an AI agent logs into a database to pull records,
- 5:16the system needs to know if that specific agent
- 5:18is authorized. If an attacker manages to hijack
- 5:22an agent or, say, trick an agent through a malicious
- 5:26prompt. Oh, wow. The attacker inherits all the
- 5:29machine's permissions. We are rapidly expanding
- 5:32our attack surface by creating thousands of these
- 5:35non -human identities that basically hold the
- 5:37keys to our digital kingdoms. Which means the
- 5:39platforms managing all these identities and all
- 5:41this access need to be incredibly. secure, like
- 5:44flawlessly secure. And that introduces a major
- 5:46structural problem. Right. Because giving AI
- 5:49new identities and deep platform access requires
- 5:52those underlying platforms to be flawless. But
- 5:55the reality of our current infrastructure is,
- 5:57well, it's anything but flawless. Which brings
- 5:59us to the architecture of the cloud itself. That
- 6:01feels like the perfect bridge to the next massive
- 6:04story in the Kinsoft update. Since we're giving
- 6:07these agents the keys to our cloud platforms,
- 6:10we really need to look at how fragile those platforms
- 6:12actually are right now. They're more fragile
- 6:14than people think. Yeah, and the nightmare scenario
- 6:17unfolded recently at Instructure. For those who
- 6:20don't know, Instructure runs Canvas, which is
- 6:22this massive learning management system used
- 6:25by countless schools and universities. Almost
- 6:27everyone in education uses it. Right. Well, the
- 6:30threat actor, a crew known as Shiny Hunters,
- 6:32managed to breach the system. And they didn't
- 6:35just quietly steal data. No, it was very loud.
- 6:38They actively defaced the Canvas login portals
- 6:41of roughly 330 different institutions. They stole
- 6:45data belonging to hundreds of millions of users.
- 6:48And the situation was so dire that a ransom deal
- 6:51was eventually struck. It's just staggering.
- 6:54This incident is being called the largest education
- 6:56sector breach on record. Unbelievable. And to
- 6:59really understand the sheer scale of the devastation
- 7:01here, we have to examine how these services are
- 7:04actually delivered. Canvas operates as a massive
- 7:07SaaS platform, software as a service. Right.
- 7:10SaaS. The central lesson here from Kinsoft is
- 7:13the terrifying scale of vendor breaches. Break
- 7:17down that scale for us a bit. Like, why is a
- 7:19SaaS breach fundamentally different from, say,
- 7:21a traditional network hack from 10 years ago?
- 7:24Well, in the past, if a university wanted a digital
- 7:27portal for its students, they bought their own
- 7:29physical servers, they installed them in a dusty
- 7:31basement on campus, and they ran the software
- 7:34locally. Okay. An attacker would have to breach
- 7:36University A's firewalls and then start completely
- 7:39from scratch to separately breach University
- 7:41B's firewalls. It was a lot of manual work for
- 7:44the hacker. Exactly. But with a multi -tenant
- 7:47sauce model, all those universities outsource
- 7:49their infrastructure to a single centralized
- 7:51vendor. Instructure is the vendor. It is essentially
- 7:55a giant apartment building where everyone shares
- 7:57the exact same foundation and the same plumbing.
- 7:59So the attacker doesn't need to break into 330
- 8:02separate university servers. They just need to
- 8:04find like one vulnerability in the master key
- 8:08system of the apartment building. You got it.
- 8:10And once that single central hub is compromised,
- 8:14the disaster cascades instantly to every single
- 8:17tenant. The economies of scale that make sauce
- 8:19so affordable and so efficient. Which is why
- 8:22everyone uses it. Right. Those same economies
- 8:24of scale also create massive single points of
- 8:27failure. It's kind of terrifying when you think
- 8:29about it. You drop one massive cloud -shaped
- 8:32basket. And 330 institutions lose hundreds of
- 8:36millions of user records. I mean, grades, personal
- 8:39information, financial data, all at the exact
- 8:41same time. And think about the ransom negotiation.
- 8:44Oh, God. How does a single vendor negotiate a
- 8:46ransom when the data belongs to hundreds of independent
- 8:49universities? The legal and logistical nightmare
- 8:52is just staggering. Seriously. So what does this
- 8:55all mean for the listener? I mean, whether you
- 8:57are a student, a professional, or running a business,
- 9:00we all rely on massive... platforms every single
- 9:04day. If the platforms holding our most sensitive
- 9:06data can be breached and held for ransom by crews
- 9:09like Shiny Hunters, is any data actually safe?
- 9:13Like, is this just the cost of doing business
- 9:16in 2026? It forces a very sobering reality check
- 9:19about vendor risk. You can have the most draconian,
- 9:23hyper -secure password policies in your own organization.
- 9:26But if your vendor's security fails, your data
- 9:29is completely exposed. Wow. It completely shifts
- 9:32the burden of trust away from your internal IT
- 9:35team and straight on to a third party. But let's
- 9:38play devil's advocate for a second. Let's say
- 9:39a university gets spooked by the campus breach
- 9:41and decides to pull all their data out of the
- 9:44cloud. They move everything back to those isolated
- 9:46servers in the campus basement. They are completely
- 9:48safe now, right? They are not. Not at all. No,
- 9:50because even offline, isolated servers still
- 9:52need to download software updates, right? To
- 9:54patch known bugs. And that exposes a completely
- 9:57different... much deeper vulnerability. Oh boy.
- 10:00Breaking into a software platform like Canvas
- 10:02is one thing, but breaking the system that tells
- 10:04the internet what software to trust in the first
- 10:07place, that is a foundational crisis. Which perfectly
- 10:10leads us to a story that might seem, I don't
- 10:13know, a little abstract at first glance, but
- 10:15is arguably the most unsettling part of this
- 10:17entire Kinsoft update. Definitely. We're talking
- 10:20about the breach at DigiCert. According to the
- 10:22source, attackers successfully manipulated DigiCert
- 10:25into issuing fraudulent code signing certificates.
- 10:28And then the attackers used those fake certificates
- 10:31to digitally sign their malware, making the malicious
- 10:34software look entirely legitimate to literally
- 10:37anyone who downloaded it. What's fascinating
- 10:40here is the underlying mechanism of Internet
- 10:42security that this attack actually exploited.
- 10:45We really need to talk about the concept of a
- 10:47trust anchor. A trust anchor. Yeah. Whenever
- 10:49your computer downloads a piece of software or,
- 10:52say, an app, your operating system does a quick
- 10:54background check before allowing it to install.
- 10:56Right. It asks, who created this file and has
- 10:59the code been tampered with since it left the
- 11:01developer's computer? It's looking for that little
- 11:03pop -up that says, like, verified publisher.
- 11:06Exactly. And the way it verifies that publisher
- 11:09is through public key cryptography. Certificate
- 11:12authorities, like DigiCert, are the organizations
- 11:15trusted by Apple, Microsoft, Google to issue
- 11:18those cryptographic certificates. Okay, so they're
- 11:21the authorities. They are the digital passport
- 11:23agencies of the internet. When DigiCert signs
- 11:26a certificate for a software developer, it is
- 11:28mathematically vouching for them. Gotcha. The
- 11:31operating system sees the DigiCert signature
- 11:33and applies a fundamental hard -coded rule. This
- 11:37file is digitally signed by a trusted anchor.
- 11:39Therefore, it is safe to run. So it's like a
- 11:42master counterfeiter. Right. But instead of just
- 11:44printing fake money in a basement and hoping
- 11:46a cashier doesn't look too closely. Right. The
- 11:48counterfeiter actually manages to trick the official
- 11:50government mint into stamping their fake money
- 11:53with a real mathematically perfect watermark.
- 11:56The money itself is fundamentally counterfeit,
- 11:59but the security features. are 100 % genuine.
- 12:01That captures the severity perfectly. By issuing
- 12:05those fraudulent certificates, DigiCert unknowingly
- 12:08gave malware a VIP pass right past the bouncers
- 12:12of every single computer security system. The
- 12:16fundamental guarantee of, is this digitally signed,
- 12:18was just completely broken. Wait, wait, you're
- 12:20losing me here. I have to push back on this.
- 12:22Sure. We are talking about DigiCert. A company
- 12:26whose entire existence is based on mathematically
- 12:29perfect billion dollar cryptography. Yes. We're
- 12:33talking about prime numbers so large that it
- 12:35would take a supercomputer like a million years
- 12:38to crack them. And you're telling me the bad
- 12:40guys bypassed all that math just by calling customer
- 12:44service and asking nicely. I know. How does a
- 12:46help desk worker even have the authority to issue
- 12:48a cryptographic certificate? It sounds totally
- 12:50absurd, but it highlights a massive blind spot
- 12:53in how we structure security. Customer support
- 12:55portals have administrative overrides. Oh, of
- 12:58course they do. Right. They're designed to help
- 13:00legitimate customers who lose their keys or need
- 13:02expedited service. The attackers didn't use some
- 13:05brilliant zero -day hacking code to break into
- 13:07DigiSearch cryptographic vaults. No code at all.
- 13:10No. The Kinsoft update explicitly states they
- 13:13used social engineering through the support portal.
- 13:16They just manipulated a human being who had authorized
- 13:19access to the tools that generate those certificates.
- 13:22So the foundational trust anchors of the entire
- 13:24Internet really were defeated by a smooth talker
- 13:28on the help desk line. They were. Honestly, it
- 13:32makes perfect sense from the attacker's perspective.
- 13:34How so? We spend billions analyzing code, patching
- 13:38servers, and configuring firewalls. But attackers
- 13:41realize that the path of least resistance is
- 13:43almost always human psychology. Yeah, why break
- 13:46the math when you can break the person? Exactly.
- 13:48Why spend months trying to crack an encryption
- 13:51algorithm when you can just convince an employee
- 13:53that you are a frantic developer facing a massive
- 13:57deadline who needs a certificate reissued immediately?
- 14:00Wow. Social engineering relies on manipulation,
- 14:03you know, creating a false sense of urgency,
- 14:05leveraging fake authority, or just exploiting
- 14:07natural human empathy to trick a person into
- 14:09bypassing all the rules. Which brings us to the
- 14:12ultimate takeaway from the Kinsoff brief, and
- 14:14the realization that the human element is sort
- 14:16of the universal bypass here. And this wasn't
- 14:19just an isolated incident at DigiCert. Not at
- 14:22all. The update heavily emphasizes recent breaches
- 14:24at the global fashion retailer Zara and at an
- 14:28NVIDIA cloud gaming partner. And the common thread,
- 14:31Kinzov calls social engineering, quote, The week's
- 14:34quiet villain. A great phrase. Let's dive into
- 14:37how these specific breaches happened. Because
- 14:39Zara and NVIDIA are massive companies with huge
- 14:42security budgets. They have multi -factor authentication,
- 14:46identity protocols that works. How does a smooth
- 14:48talker bypass all of that? The tactics are incredibly
- 14:51sophisticated, yet entirely non -technical. In
- 14:54scenarios like the NVIDIA Cloud Gaming Hartner
- 14:57breach, attackers often utilize a technique called
- 15:00MFA fatigue combined with IT impersonation. MFA
- 15:03fatigue. Yeah. So they acquire a target's username
- 15:06and password, often from an older, completely
- 15:08unrelated data leak. They try to log in, which
- 15:11triggers a multi -factor authentication request
- 15:13to the real employee's phone. The classic press
- 15:16one to approve this login notification. Yes.
- 15:19And the attacker will spam that notification
- 15:21to the employee's phone 50 times in the middle
- 15:24of the night. Oh, that's incredibly annoying.
- 15:26Right. The employee is annoyed, confused, and
- 15:29just wants their phone to stop buzzing at two
- 15:31in the morning. But they usually don't click
- 15:33approve. Good. But then the next morning, the
- 15:36attacker calls the employee, spoofing the phone.
- 15:39number so it looks like the internal IT help
- 15:42desk oh no the attacker says hey we noticed some
- 15:46weird login activity on your account last night
- 15:49we are trying to secure it but I need you to
- 15:51approve the notification I'm sending to your
- 15:53phone right now to verify your identity oh wow
- 15:56so the employee thinks they're talking to the
- 15:59good guys right I think clicking approve is securing
- 16:02their account when in reality they're letting
- 16:04the attacker straight into the network exactly
- 16:06and similar tactics are used against Exploiting
- 16:23that authority. Yes. They bypass the technical
- 16:26identity protocols by manipulating the human
- 16:28desire to be helpful or, honestly, just the human
- 16:32fear of getting in trouble with the boss. It
- 16:34is the brick. propping open the titanium door
- 16:37all over again. It really is. The laser grid
- 16:39works perfectly, but the security guard was tricked
- 16:42into turning it off. You know, if we synthesize
- 16:44everything we've discussed today, a very stark
- 16:47picture emerges. We are deploying incredibly
- 16:50advanced autonomous AI agents through platforms
- 16:54like Microsoft's Agent 365, giving them their
- 16:58own digital corporate credit cards to roam our
- 17:00networks. We are centralizing hundreds of millions
- 17:03of user records in massive SaaS infrastructures
- 17:06like Canvas, creating incredibly lucrative targets.
- 17:09The technological stakes have never been higher.
- 17:11Never. Yet despite all of this advanced technology,
- 17:14attackers are succeeding through completely low
- 17:17-tech methods. Right. using convincing phone
- 17:19calls, manipulated emails, and support portal
- 17:22trickery to bypass the strongest digital defenses
- 17:24we can possibly build. The technology isn't failing.
- 17:27The human gatekeepers are being manipulated into
- 17:29opening the doors. And the Kinsoft update ends
- 17:32with a very direct piece of advice that connects
- 17:35this right back to you, the listener. Their sign
- 17:38-off is stay patched, stay skeptical. Good advice.
- 17:42Because whether you were running a massive corporate
- 17:44IT department or you're just sitting at home
- 17:46trying to figure out if that text message from
- 17:48your bank is a phishing scam, the human element
- 17:51is the final line of defense. It absolutely is.
- 17:54Critical thinking is a required security control
- 17:57now. Knowledge is most valuable when it is understood
- 18:00and applied. We can build the most robust AI
- 18:03frameworks and secure our sauce environments
- 18:05with mathematical precision. But if we don't
- 18:08train ourselves to view our digital interactions
- 18:10with a healthy dose of that recommended skepticism,
- 18:12the technical defenses simply do not matter.
- 18:15They're useless. Pretty much. The attackers will
- 18:17always target the easiest way in. And right now,
- 18:20that is us. So to quickly recap this incredibly
- 18:23dense snapshot of our tech landscape, we are
- 18:26officially entering the era of. autonomous AI
- 18:28agents taking real actions inside our software
- 18:31nervous systems. At the same time, we are witnessing
- 18:34the terrifying single point of failure vulnerability
- 18:37of massive SaaS platforms with breaches affecting
- 18:40hundreds of millions of people at once. And underneath
- 18:44it all, the very cryptographic trust anchors
- 18:46of the internet are being bypassed, not with
- 18:49complex code, but with simple human conversation
- 18:52and psychological manipulation. It is a wild
- 18:55time to be navigating the digital world. It certainly
- 18:58is. The landscape requires a constant active
- 19:00reevaluation of where our true vulnerabilities
- 19:02actually lie. And as we wrap up today's deep
- 19:05dive, I want to leave you with a final lingering
- 19:07thought to mull over. We spent a lot of time
- 19:09talking about how easy it is to socially engineer
- 19:11a human being like the support staff at DigiCert
- 19:14or the employees at an NVIDIA partner into making
- 19:18a terrible mistake. But think about those new
- 19:20autonomous AI agents Microsoft is rolling out.
- 19:24These agents have their own digital identities,
- 19:26their own access rights, and the ability to interact
- 19:29with a broader digital ecosystem on our behalf.
- 19:32What happens when those AI agents become the
- 19:34targets of these exact same social engineering
- 19:37tricks? We know a smooth talker can manipulate
- 19:39a tired human help desk worker by creating a
- 19:42false sense of urgency. But as these AI models
- 19:45read our emails and interact with outside data,
- 19:48I mean, can you fast talk an AI into handing
- 19:51over the keys to the kingdom? That is a terrifying
- 19:53thought. That is something to think about the
- 19:55next time you authorize a digital agent to manage
- 19:57your inbox. Thank you for joining us on this
- 19:59deep dive. Stay skeptical out there, and we will
- 20:02catch you next time.