Latest / Tech Talks With Kinsoft / Non-Production Does Not Mean Non-Critical: The Uni Sydney Hack
Transcript
- 0:00Hello and welcome back to Tech Talks with Ken
- 0:01Soft. I'm your host. And I have to be honest,
- 0:03looking at the stack of reports we have for this
- 0:05week, it's been a pretty heavy one. Volatile
- 0:08is the right word. Yeah. It really feels like
- 0:11a convergence of, I don't know, several different
- 0:13storm fronts hitting all at once. Exactly. I
- 0:15mean, we're seeing accidental exposure, malicious
- 0:18extortion, and critical code vulnerabilities
- 0:20all landing in the same, what, seven -day window?
- 0:23All at once. And we aren't talking about minor
- 0:26glitches here. We're looking at a massive data
- 0:29breach at one of our oldest universities, a really
- 0:32disturbing ransomware attack on a fertility provider.
- 0:35And then this red alert vulnerability in the
- 0:39code that powers a huge chunk of the modern web.
- 0:42OK, let's unpack this because, you know, it's
- 0:44not just about hackers and hoodies. Well, it's
- 0:47about the files we forgot we saved. That's exactly
- 0:49it. And what stands out to me looking at these
- 0:51collectively is that the root causes aren't what
- 0:55people expect. We always think about the Mission
- 0:57Impossible style hacks. Right. The Hollywood
- 1:00version of cybercrime. Precisely. But the theme
- 1:03emerging from this week is silent failures. It's
- 1:07about the test environments we thought were invisible,
- 1:10the bad habits we've let slide because we're
- 1:12just too busy. That concept of silent failures
- 1:14is really unsettling. It suggests the danger
- 1:17is already inside the house. So let's get into
- 1:19it. We have to start with the incident that really
- 1:22hit the headlines on December 18th, the University
- 1:24of Sydney. Yeah, this is a textbook case of what
- 1:27we call a non -production failure. Okay, set
- 1:29the scene for us. What exactly went wrong? So
- 1:32on December 18th, 2025... The university sends
- 1:35out a notification about unauthorized access.
- 1:38Now, usually you hear university breach. You're
- 1:40thinking student database, financial system.
- 1:42The crown jewels. The crown jewels. But the intruders
- 1:45didn't break down the front door. They found
- 1:47a window open in an online IT code library. A
- 1:53code library. So for those who aren't developers,
- 1:55that's like a workspace, right? A place to store
- 1:57code and test things out. Correct. It's a development
- 1:59environment. A digital workshop. It's meant for
- 2:02building and testing, not for secure storage.
- 2:06But, and this is the critical oversight, they
- 2:08found data files just sitting inside that library.
- 2:11Real data. Oh, very real data. The report from
- 2:16Lean Security points to this as a major DevSecOps
- 2:19failure. The specific issue is using production
- 2:23data. Actual people's information. Yes. Using
- 2:26actual people's information inside a non -production
- 2:29environment. I want to pause on that because
- 2:31I feel like this happens way more than anyone
- 2:34admits. I mean, developers need realistic data
- 2:37to test if their code works, so they just grab
- 2:39a copy of the live database. It is incredibly
- 2:41common and it is incredibly dangerous. It's like
- 2:43building a practice vault for a bank to train
- 2:46your security guards, but then you fill it with
- 2:48real stacks of cash just to see if they fit.
- 2:50Oh, OK. But the problem is because it's a practice
- 2:52fault, you don't put the same armed guards or
- 2:55long systems on it. That makes perfect sense.
- 2:57You assume nobody is looking at the practice
- 2:59fault. But clearly someone was. What was the
- 3:02scale of the exposure here? The numbers are pretty
- 3:06significant. You're looking at personal information
- 3:08for about 10 ,000 current staff and affiliates.
- 3:11And that's just the current payroll. Right. Add
- 3:13to that around 12 ,500 former staff members and
- 3:18then another 5 ,000 alumni and students. And
- 3:20what kind of data are we talking about? Names,
- 3:22dates of birth, phone numbers, home addresses,
- 3:25job titles, the works. I noticed something interesting
- 3:28in the timeline of that data. The university
- 3:30said these were historical extracts. The staff
- 3:34data was from 2018. Student data went back to
- 3:372010. Why is data that old just sitting there?
- 3:41That is the million dollar question. It just
- 3:43points to a failure in data retention policies.
- 3:45In these huge organizations, you often get these
- 3:48zombie data sets. Zombie data. Yeah. You know,
- 3:51a project started in 2018. The devs pulled a
- 3:53data set to test it. The project finished. But
- 3:56nobody ever went back to delete the test file.
- 3:58So it's just digital hoarding, basically. Essentially.
- 4:00And while the university has purged those data
- 4:03sets now and is working with the NSW Privacy
- 4:05Commissioner, the damage is in the exposure.
- 4:07Your date of birth hasn't changed since 2018.
- 4:10Good point. It really highlights that data sprawl
- 4:12is a massive liability. You just can't protect
- 4:15what you don't remember you have. Exactly. And
- 4:18this isn't their first issue with this kind of
- 4:20peripheral exposure. Remember back in September
- 4:232023, the breach with the international applicants.
- 4:26Through a third party provider, right? Yeah,
- 4:28it shows a pattern. The edge of the network is
- 4:30often softer than the core. Speaking of soft
- 4:33edges, we need to shift gears because while the
- 4:36Unisydney story is about oversight. An accident,
- 4:40really? The situation in the health care sector
- 4:42is much darker. This is aggressive extortion.
- 4:46It is. The health care sector is, I mean, it's
- 4:48under siege right now. And the emotional stakes
- 4:50are just incredibly high. We have to talk about
- 4:52Jania. They're a leading fertility service provider.
- 4:55Just days after the university news, reports
- 4:58concerned they were hit by the termite ransomware
- 5:00gang. Termite is a nasty group. They don't just
- 5:03lock up files. They steal them. They claim to
- 5:06have taken 700 gigabytes of data. OK, let's just
- 5:09stop there. 700 gigabytes. In the context of
- 5:13a fertility clinic, I mean, that is heavy. That's
- 5:15medical histories, diagnostic results. It's maximum
- 5:18leverage. Ransomware groups, they operate like
- 5:21businesses. They know if they steal designs for
- 5:24a new toaster, nobody really cares. But if they
- 5:26steal fertility data, the panic is immediate.
- 5:30The patients are going to pressure the organization
- 5:32to pay. It's sickening. And it wasn't just Genia.
- 5:36We saw Harbortown Doctors in Queensland pop up
- 5:38on the Rosita leak site in the same week. It
- 5:41feels like the whole sector is just bleeding.
- 5:43It is. But here's where we need to look at the
- 5:45why. It's easy to just blame the hackers, but
- 5:48I found a report, an audit from NSW Health that
- 5:51was released around the same time, and it sheds
- 5:53some light on why these places are so. This was
- 5:57the audit that talked about the normalization
- 5:58of noncompliance, right? That's the exact phrase,
- 6:01normalization of noncompliance. Which sounds
- 6:03like corporate speak for everyone's breaking
- 6:05the rules. It is, but it explains the motivation.
- 6:08The audit found that clinicians, doctors, nurses
- 6:11were routinely sharing passwords. They were using
- 6:13personal devices to handle patient data. Okay,
- 6:16let me play devil's advocate. These are doctors.
- 6:18They are under insane time pressure. If the security
- 6:21system makes you log in with a 20 -character
- 6:23password every time you move to a new room, isn't
- 6:26the security system the problem? That is a very
- 6:28valid point, and it's the core of the tension.
- 6:31The audit explicitly mentions time pressure.
- 6:35Clinicians aren't malicious. They're just trying
- 6:37to care for patients. If security gets in the
- 6:40way of patient care, security gets bypassed.
- 6:43It's just human nature. So you have the IT department
- 6:45building this fortress. But the people inside
- 6:48keep leaving the side door open because the main
- 6:50drawbridge takes too long to lower. That's it.
- 6:53But from an attacker's view, they don't care
- 6:55why the password was shared. They just care that
- 6:57it was. If we connect this to the bigger picture,
- 7:00we aren't just fighting hackers. We are fighting
- 7:03our own bad habits, our own workflow issues.
- 7:06That's a tough reality. The solution isn't just
- 7:09buy more software. It's fix the process. Precisely.
- 7:13But while human error is a huge factor there,
- 7:15there is a third storm front we have to talk
- 7:18about. And this one has nothing to do with bad
- 7:20habits. It's a pure technical failure in the
- 7:23bedrock of the Internet. You're talking about
- 7:24React 2 .0. I am. The name sounds almost playful,
- 7:27but I'm gathering the severity is anything but.
- 7:29It's catastrophic. The technical name is CVE
- 7:32-2025 -55182. But let's stick with React 2 .0.
- 7:37Please. So for the listeners. Maybe a business
- 7:40owner who is coding every day. What is this?
- 7:42Okay. Modern websites, they're not just static
- 7:44pages anymore. They're complex applications.
- 7:47They're built using frameworks. Think of it like
- 7:49the pre -built chassis and engine of a car. React
- 7:52and Next .js are two of the most popular frameworks
- 7:54in the world. They're everywhere. Startups, e
- 7:57-commerce, enterprises. Absolutely everywhere.
- 7:59And React 2 .0 is a vulnerability inside these
- 8:02frameworks. It's rated a CVSS 10 .0. A perfect
- 8:0510. That's rarely good news. It's the worst possible
- 8:08score. It means critical. And the reason it's
- 8:11a 10 is that it allows for remote code execution
- 8:14or RCE without authentication. Without authentication
- 8:18are the two scary words there. It means the attacker
- 8:21doesn't need to steal a password. They don't
- 8:24need to trick a doctor into clicking a link.
- 8:26They can just send a special request to your
- 8:28website and the server runs their command. It's
- 8:30not picking the lock. It's dissolving the door.
- 8:33And are we seeing this actually being used or
- 8:35is this still just theoretical? Oh, it is very
- 8:38much in the wild. Intelligence reports are suggesting
- 8:41China nexus groups are already all over this.
- 8:44We're seeing names like Earthlomia and Jackpot
- 8:47Panda. Jackpot Panda. I'm guessing they aren't
- 8:50looking for bamboo. No, they're using this exploit
- 8:54to plant back doors and deploy crypto miners.
- 8:56So you could have a perfectly secure network,
- 8:59trained staff. Great passwords. But because your
- 9:02website was built on React three years ago and
- 9:04you forgot to patch it, Dragpot Panda is mining
- 9:07Bitcoin on your servers. Or stealing your customer
- 9:10database. It's a supply chain risk. You didn't
- 9:12write the bad code, but you're running it. It
- 9:15reminds me a bit of that INET situation from
- 9:17the sitting duck source. Not the same method,
- 9:19obviously, but the scale of the blind spot. That's
- 9:22a great parallel. With iNet, you had 280 ,000
- 9:26customers exposed because of stolen employee
- 9:28credentials. Legitimate access used wrongly.
- 9:31With React to Shell, it's a flaw in the system
- 9:34itself. But both end in massive uninvited access.
- 9:38So let's just recap the volatility of this week.
- 9:41We've got zombie data leaking from universities.
- 9:42We have overworked health care staff bypassing
- 9:45security. And we have a foundational code vulnerability
- 9:48that just lets attackers walk right in. It feels...
- 9:52It can be. But the goal here isn't just to admire
- 9:55the problem. We need to distill this into action.
- 9:58And based on these three very distinct failures,
- 10:00we can actually draw a pretty clear map of what
- 10:03to do. Let's do it. If I'm a CTO listening to
- 10:05this or even just a business owner, what's my
- 10:08Monday morning to -do list? Okay, step one. This
- 10:10comes right from the University of Sydney incident.
- 10:12You have to inventory everything. And I don't
- 10:14mean sending an email asking what servers do
- 10:16we have. You mean automated discovery. Yes. You
- 10:19need tools that scan your network for everything
- 10:22connected to it. You cannot protect what you
- 10:24don't know exists. You have to find those forgotten
- 10:27code libraries, those test servers from 2018.
- 10:30The shadow IP problem. Find it and kill it if
- 10:33you don't need it. Yeah. Okay, what's step two?
- 10:35This is for the developers. No prod and non -prod.
- 10:38It's the golden rule that was broken at the uni.
- 10:40Never use real customer data for testing. Period.
- 10:44But the developers always say, we need real data
- 10:46to catch the edge cases. Then they need to use
- 10:48synthetic data or masked data. There are tools
- 10:51that take real data and just scramble the personal
- 10:53info, change the names, the addresses, but keep
- 10:57the structure. There's no excuse in 2026 for
- 10:59having real names in a test environment. Right.
- 11:02Okay. Step three. MFA is non -negotiable. Multi
- 11:05-factor authentication. This hits the healthcare
- 11:07and the INET issues. If a doctor writes a password
- 11:10on a sticky note, that's bad. But if the system
- 11:13also requires a thumbprint or a code from a phone,
- 11:16that sticky note is useless to a hacker. It stops
- 11:18credential theft. Patch. Immediately. If you
- 11:21use modern JavaScript frameworks, you need to
- 11:23check your version. Now. If it's vulnerable,
- 11:26patch it today. Don't wait for your quarterly
- 11:28maintenance window. A CVSS 10 is an open door.
- 11:32I want to pivot just for a second to the individual
- 11:34listener. We have a lot of people listening who
- 11:36might actually be in that Uni of Sydney data
- 11:38set or a patient at Genia. If I'm listening and
- 11:42I think, oh, that's me, what should I do? First,
- 11:45don't panic. But you have to be hypervigilant.
- 11:48The university noted there's no evidence yet
- 11:50of publication, but that can change at any moment.
- 11:53It's the phishing risk, isn't it? It's huge.
- 11:55If I'm a scammer and I know your name, your address,
- 11:58and that you worked at Sydney Uni as a professor
- 12:00of biology in 2018, I can write a very convincing
- 12:02email to you. Dear professor, regarding your
- 12:05pension. Exactly. So look at every single email
- 12:07with suspicion. And there's one other piece of
- 12:10advice the university gave, which I think is
- 12:11brilliant. Do not... post about the breach on
- 12:14social media really why is that people usually
- 12:17vent on twitter or linkedin straight away because
- 12:20it paints a target on your back if you post i
- 12:22can't believe i'm caught up in this hack you
- 12:25are basically signaling to scammers hello i am
- 12:29a victim and i am emotional and confused right
- 12:31now you are inviting them to target you that
- 12:34is solid advice Silence is safety in that regard.
- 12:37It really is. You know, we started this expecting
- 12:40to talk about high -tech cyber warfare. But when
- 12:43you boil it all down, deleting old files, not
- 12:46sharing passwords, and patching software, it's
- 12:49pretty basic hygiene. It is. But as this week
- 12:52proves, if you ignore the basics, the consequences
- 12:55are catastrophic. Well, we are just about out
- 12:57of time. But before we go, I want to leave our
- 12:59listeners with one last thought. Give us something
- 13:01to chew on. Okay. We worry a lot about the sophisticated
- 13:04threats. We worry about AI hackers and state
- 13:07-sponsored groups like Jackpot Panda, and we
- 13:09should. But I want to ask everyone listening,
- 13:12are you ignoring the boring risks to chase the
- 13:15exciting ones? Because this week proves that
- 13:17your biggest threat might not be some super virus.
- 13:19It might be a test file from 2018 that you just
- 13:22forgot to delete. The boring stuff will get you
- 13:24every time. That's the thought for the week.
- 13:26It really will. Well, thank you all for tuning
- 13:28in to this edition of Tech Talks with Ken Soft.
- 13:31Pleasure to be here. If all this talk of React
- 13:332 Shell and DevSecOps has you worrying about
- 13:36your own business's safety, or if you're suddenly
- 13:39remembering a test server you haven't checked
- 13:41in three years, You don't have to figure it out
- 13:43alone. Absolutely not. Security is a team sport.
- 13:46If you need help auditing your systems or securing
- 13:49your IT infrastructure, reach out to the professionals.
- 13:51Head over to www .kinsoft .com .au. That's www
- 13:55.kinsoft .com .au to discuss your security and
- 13:59IT needs. They can help you find those silent
- 14:01failures before the bad guys do. Stay safe out
- 14:04there. Catch you next time.