Latest / Tech Talks With Kinsoft / Last Week in Tech – OpenAI Retires GPT-4o, China-Linked Telco Espionage, and an Ivanti Zero-Day Hits Brussels
Transcript
- 0:00Imagine waking up tomorrow, grabbing your coffee,
- 0:02opening your laptop, and discovering that the
- 0:05digital foundation your entire company runs on
- 0:07has just, well, vanished. Right. Just completely
- 0:12gone. Exactly. It hasn't been hacked. It isn't
- 0:15temporarily down for maintenance. It is just
- 0:18gone, erased. And today we're looking at a week
- 0:21where that exact scenario actually played out
- 0:24for thousands of businesses globally. We are
- 0:27unpacking why the cybersecurity perimeters we
- 0:30blindly trust to protect our workflows are cracking
- 0:34right down the middle. Yeah, and it forces a
- 0:36total recalibration of how we approach enterprise
- 0:38architecture. I mean, we operate under this illusion
- 0:40of permanence. We deploy a tool, we build our
- 0:43defenses, and we just assume that because we
- 0:45paid for them or, you know, because they have
- 0:47a big shiny vendor logo on them, that the ground
- 0:50beneath us is solid. Right, but it's not. Not
- 0:52at all. The telemetry we are seeing right now
- 0:54proves that the ground is completely fluid. Which
- 0:56brings us to today's deep dive. We are tearing
- 0:59into a really dense, incredibly revealing update
- 1:02from Kinsoft Tech Talks. And this is dated February
- 1:0616th, 2026. The mission today is to examine a
- 1:11chilling theme hidden in this week's tech news,
- 1:13which is the severe systemic danger of the misplaced
- 1:17trust we put into our digital infrastructure.
- 1:19Oh, absolutely. And nowhere is that infrastructure
- 1:21evaporating faster than in the realm of artificial
- 1:24intelligence. So the Kinsoft update kicks off
- 1:28with OpenAI initiating this massive, unceremonious
- 1:31house cleaning. They retired GPT -4 .0, GPT -4
- 1:34.1, the 04 Mini, and the original GPT -5 models
- 1:37from the chat GPT API, essentially forced everyone
- 1:40onto GPT -5 .2 overnight. Yeah. And on the surface,
- 1:43if you are just, I don't know, a casual user
- 1:45asking a chatbot to write a grocery list, you
- 1:47probably didn't even notice. Right. You just
- 1:49open the app and it works. Exactly. But in the
- 1:51enterprise environment, deprecating models like
- 1:53that is an architectural earthquake. It's a huge
- 1:55deal. Okay. Let's unpack this because if you
- 1:57were building a modern business, you don't just
- 1:59plug an AI model into your workflow. You weave
- 2:02it into the very fabric of your operations. You
- 2:04really do. You spend months engineering prompts,
- 2:07tuning system instructions. You know, formatting
- 2:10JSON parsers to handle the exact latency, the
- 2:14token limits, and the specific hallucination
- 2:16quirks of, say, GPT -4 .0. Building your critical
- 2:20business infrastructure directly on top of a
- 2:23specific hard -coded AI model like that is essentially
- 2:26like building a massive corporate skyscraper
- 2:28on a rented foundation. That is a great way to
- 2:31put it. Right. Because the landlord can legally
- 2:33swap the concrete out for gravel while you sleep.
- 2:36You wake up. And your customer service platform
- 2:38is suddenly throwing 500 level air codes because
- 2:41the API endpoint you rely on simply no longer
- 2:44exists. Yeah. And the Kinsoft report highlights
- 2:46a fascinating and, well, somewhat terrifying
- 2:49data point regarding exactly that. They noted
- 2:51that leading up to the deprecation, barely a
- 2:53tenth of a percent of users were still hitting
- 2:55the GPT -40 endpoints daily. A tenth of a percent.
- 2:58I mean, that sounds small. It does sound small,
- 3:00right? But in the context of OpenAI's massive
- 3:03global user base, a tenth of a percent is still.
- 3:07thousands of enterprise applications, automated
- 3:09scripts, and customer -facing interfaces all
- 3:12breaking at the exact same time. Exactly. Thousands
- 3:15of IT teams having the worst morning of their
- 3:17lives. And the failure here isn't on OpenAI,
- 3:20right? It's an enterprise architecture failure.
- 3:23When you hardwire a complex system to a single
- 3:26model version, you are over -optimizing for the
- 3:29present. and just totally ignoring the reality
- 3:31of cloud infrastructure. You're betting your
- 3:34uptime on an external vendor's deprecation schedule.
- 3:37But what is the alternative? I mean, if an engineering
- 3:39team spends six months getting the tone and formatting
- 3:42of GPT -40 exactly right for an automated legal
- 3:45review tool, they can't just flip a switch to
- 3:48GPT -5 .2. No, of course not. The output drift
- 3:51alone would break the downstream processing.
- 3:53The JSON structures might change. The verbosity
- 3:55changes. You can't just, you know, swap the API
- 3:58key and go to lunch. Right, which is why you
- 4:00don't hardwire it in the first place. You implement
- 4:02an AI abstraction layer. Okay, an abstraction
- 4:04layer. Tell me more about that. So, you need
- 4:06middleware that acts as a translator between
- 4:09your core application and the LOM vendor. Instead
- 4:12of your app asking GPT -4o directly to analyze
- 4:15a document, your app asks your internal gateway.
- 4:19That gateway handles the routing, the prompt
- 4:21translation, and the error handling. Oh, I see.
- 4:24Yeah, so if a model gets deprecated, you just
- 4:26update the abstraction layer to map to the new
- 4:28model, and your core application never knows
- 4:30the difference. The lesson here is that you simply
- 4:33cannot trust your tools to remain static. The
- 4:36infrastructure will be deprecated right out from
- 4:38under you. The deprecation of those AI hodls
- 4:41absolutely proves that trusting external vendors
- 4:44for stability is a massive operational risk.
- 4:46But that transitions us to an even more critical
- 4:49question. Which is? What happens when we apply
- 4:51that exact same blind trust to our own internal
- 4:54perimeters? I mean, if an AI tool you choose
- 4:56to trust can vanish, what happens when a security
- 4:58wall you have to trust gets shattered from the
- 5:00outside? Yeah, and this is where the Kinsoft
- 5:02update shifts from a discussion about operational
- 5:05resilience into a genuine crisis of cybersecurity.
- 5:08It gets really dark, really fast. It does. The
- 5:12report details this relentless wave of attacks
- 5:14targeting edge devices, and specifically, they
- 5:18highlight critical zero -day vulnerabilities
- 5:20in Avanti's Endpoint Manager Mobile. And just
- 5:23to underscore the severity of this for anyone
- 5:25listening, Avanti Endpoint Manager Mobile isn't
- 5:28just some peripheral, nice -to -have tool. Not
- 5:31at all. For an enterprise, an MDM, a mobile device
- 5:35management server, is the absolute keys to the
- 5:38kingdom. It has administrative access to every
- 5:40company phone, tablet, and remote device in the
- 5:43fleet. It can wipe them. It can install apps.
- 5:46It tracks them. It's the nerve center. Exactly.
- 5:48And attackers use these Ivanti Zero Days to breach
- 5:51the European Commission and parts of the Dutch
- 5:53government. What does this all mean for the rest
- 5:56of us if massive government bodies are getting
- 5:58caught with their digital pants down? I mean,
- 6:01if highly funded organizations with sprawling
- 6:04security operation centers are getting breached
- 6:06straight through their edge perimeters, how is
- 6:08a mid -sized financial firm so to stand a chance?
- 6:11Well, what's fascinating here is the specific
- 6:13metric that the Kinsoft report focuses on regarding
- 6:16the European Commission breach. Brussels publicly
- 6:18stated that they detected and contained their
- 6:21incursion within about nine hours. Wait, OK,
- 6:23I have to push back. hard on that being framed
- 6:25as a positive outcome. Nine hours. I know. I
- 6:29know how it sounds. In an enterprise network,
- 6:31an attacker with hyper -privileged access from
- 6:34an MDM server can do an unbelievable amount of
- 6:38damage in nine hours. That isn't a silver lining.
- 6:42To me, that illustrates how terrifyingly fast
- 6:44an entire network can be compromised once a trusted
- 6:48edge device is broken. I totally hear that. And
- 6:50you're not wrong, but you have to look at it
- 6:52through the lens of modern threat architecture.
- 6:55Yes, nine hours is enough time to do damage,
- 6:57but you are comparing it to a hypothetical scenario
- 6:59of absolute prevention. Right. And that scenario
- 7:02just no longer exists. The days of the perfect,
- 7:05unbreachable firewall are over. So you're saying
- 7:07the perimeter is entirely porous now. Basically,
- 7:10yes. The perimeter is just a filter. It stops
- 7:12the automated noise, the low level stuff. But
- 7:14against a determined, well -resourced adversary
- 7:17wielding a zero day exploit, the wall will fail.
- 7:20It's just a matter of when. Exactly. And the
- 7:24historical dwell time for threat actors inside
- 7:27a network used to be measured in months, sometimes
- 7:30even a year. If an attacker has administrative
- 7:33access for a month, they map your active directory,
- 7:36they execute Kerberosting attacks to harvest
- 7:39service account credentials, they move laterally
- 7:42to your backup servers, and they plant these
- 7:45deep, deep persistence mechanisms. Yeah, they
- 7:48just dig in like a tick. Exactly. By the time
- 7:50you spot them, you don't just... have to kick
- 7:52them out. You have to rebuild your entire domain
- 7:54from scratch. Because they've poisoned the well
- 7:56completely. Precisely. So by containing the breach
- 7:59in nine hours, Brussels operated on an assumed
- 8:02breach mentality. They didn't just trust their
- 8:05Ivanti server to keep attackers out. They actively
- 8:08monitored the internal network traffic for anomalous
- 8:11behavior, assuming the firewall had already failed.
- 8:13Oh, I get it. So the nine hours is a win because
- 8:16it's not a month. Right. Nine hours means they
- 8:18stopped the lateral movement before the attackers
- 8:20could cement a permanent foothold. Fast detection
- 8:23is really the only viable defense mechanism we
- 8:25have left. That makes the next section of the
- 8:28Kinsoft report even more alarming to me. Because
- 8:31Brussels had a loud nine -hour firefight. They
- 8:34saw the anomaly, they responded, they contained
- 8:36it. But the update immediately contrasts that
- 8:39active defense with attackers who are playing
- 8:42a much quieter long -term game. Oh yeah, a very
- 8:44different kind of threat. We are moving from
- 8:46edge devices into the core of the telecommunications
- 8:50sector. The telco infrastructure breaches. This
- 8:53completely redefines the scale of the problem.
- 8:55It really does. The report details a campaign
- 8:58by a threat group known as UNC 388A6. And just
- 9:02to be completely clear with you listening, the
- 9:04source material explicitly notes that this is
- 9:06a China -linked espionage group. We are simply
- 9:09reporting the facts and the attribution exactly
- 9:11as they were documented in the Kinsloft update.
- 9:14We aren't taking any political stance here, just
- 9:16examining the mechanics of the attack. Right,
- 9:18keeping it focused on the tech. Exactly. So this
- 9:21group successfully compromised all four of Singapore's
- 9:24major telecommunications companies in a highly
- 9:26sophisticated, really long -running campaign.
- 9:29And the Kinsloft report places that... right
- 9:31alongside another major telco incident. The Dutch
- 9:34provider Odido disclosed a breach exposing the
- 9:37personal data of 6 .2 million customers. But
- 9:41these two incidents represent fundamentally different
- 9:45threat models, don't they? I mean, they don't
- 9:46even belong in the same category of attack. The
- 9:49Odido breach, exposing 6 .2 million records,
- 9:52is a massive data exfiltration event. It's horrible
- 9:56for privacy, but architecturally, it's a smash
- 9:58and grab. Yeah, it's noisy. Right. You back a
- 10:01truck up, blow the vault doors, scoop up the
- 10:03data, and trigger every single alarm in the building
- 10:05as you drive away. It is obvious, but compromising
- 10:08the core infrastructure of all four major telcos
- 10:11in Singapore. That isn't a bank heist. No, it's
- 10:14not. If we connect this to the bigger picture,
- 10:16you really have to understand why telcos are
- 10:18the ultimate target. They aren't just holding
- 10:20customer data. They are the physical pipes of
- 10:22the digital economy. Right. It's not breaking
- 10:24into the bank. It is compromising the city's
- 10:27entire water supply. You don't need to pick the
- 10:29locks on individual houses if you completely
- 10:31control the reservoir feeding the pipes. That's
- 10:33a perfect analogy. If you are sitting inside
- 10:35the telco infrastructure. You have access to
- 10:38the metadata, the routing tables, and potentially
- 10:40the SMS multi -factor authentication tokens of
- 10:43every single citizen and enterprise. utilizing
- 10:47that network. And this is where the how becomes
- 10:49so critical, especially compared to the Brussels
- 10:51incident. UNC 3886 didn't just phish an employee
- 10:56and log into an admin portal. They use specialized
- 10:58malware designed specifically for virtualized
- 11:01environments. They were deploying root kits that
- 11:03sit at the hypervisor level. We're below the
- 11:06operating system. Exactly. Below the OS. When
- 11:09malware is sitting on the ESXi hypervisor, the
- 11:12virtual machines running on top of it and the
- 11:14standard endpoint detection and response tools
- 11:16running inside those virtual machines literally
- 11:19cannot see it. Because they're looking inside
- 11:21the house, but the foundation is rigged. Yes.
- 11:23The antivirus thinks the system is clean because
- 11:25the underlying foundation of the server itself
- 11:27is compromised. This is why the assumed breach
- 11:30model is so incredibly difficult to execute perfectly.
- 11:33If your monitoring tools are running on a compromised
- 11:36hypervisor, they are just lying to you. That
- 11:38is terrifying. It is. This invisible threat allows
- 11:42state -sponsored actors to map critical infrastructure
- 11:45and prepare for future sabotage without ever
- 11:48tripping a single alarm. So we have hypervisor
- 11:51-level rootkits compromising national telcos
- 11:53and zero -days ripping through government -edged
- 11:56devices. For a lot of IT professionals listening
- 11:58to this, it's easy to feel a sense of detachment.
- 12:01You might think, you know, I don't run a national
- 12:05telecommunications grid and I'm not the European
- 12:06Commission. These ultra -sophisticated attacks
- 12:09don't apply to my daily operations. But Kinsoft
- 12:12does not let us off the hook there. Not even
- 12:15slightly. They bring the threat directly to the
- 12:17absolute most mundane everyday tool in the corporate
- 12:20arsenal. Yep, email. They warn that severe threats
- 12:23are walking straight through the front door of
- 12:25our trusted environment. The report highlights
- 12:28a malicious outlook at him. We were talking about
- 12:30email plugins. And this wasn't some sketchy executable
- 12:33file downloaded from a dark web forum. This malicious
- 12:36add -in was hosted and distributed directly through
- 12:39the official Microsoft store. And before it was
- 12:42finally detected and pulled, it was used to successfully
- 12:44compromise roughly 4 ,000 Microsoft Enterprise
- 12:47accounts. Which is just a catastrophic number.
- 12:50I mean, an Enterprise Microsoft account isn't
- 12:52just access to someone's inbox. It is the identity
- 12:55plane for the user. It's everything. It grants
- 12:57access to their SharePoint architecture, their
- 12:59Teams communications, internal financial documents,
- 13:03and potentially the whole corporate directory.
- 13:06Here's where it gets really interesting. How
- 13:08on earth does a piece of malware just bypass
- 13:10Microsoft's security and sit proudly in the official
- 13:14store? We are all conditioned from day one in
- 13:17corporate IT to trust the ecosystem. Right, the
- 13:20blue checkmark mentality. Yes. If Microsoft puts
- 13:23a checkmark next to an add -in on their official
- 13:25marketplace, we just assume it has been rigorously
- 13:28reverse -engineered, sandboxed, and purified
- 13:31by a team of elite cybersecurity engineers. But
- 13:34the Kinsoft report is incredibly explicit here.
- 13:37Proof that an application came from an official
- 13:39store is absolutely not the same thing as proof
- 13:41that it is safe. And this raises an important
- 13:43question about the psychology of enterprise security.
- 13:46How so? Well, we have this desperate desire to
- 13:49outsource our critical thinking. IT administrators
- 13:52are overworked. They're exhausted. So they rely
- 13:54on the platform owner, Microsoft, Google, Apple
- 13:57to do the vetting for them. But Fred actors understand
- 14:01exactly how the marketplace automated scanning
- 14:03works. They know the blind spots. Exactly. Microsoft
- 14:07scanners are looking for traditional malware
- 14:09signatures. They are looking for code that tries
- 14:12to inject malicious payloads into memory. or
- 14:16establish illicit command and control connections.
- 14:19But a malicious Outlook add -in doesn't need
- 14:21to do any of that, does it? No, not at all. It
- 14:23just uses standard, legitimate Microsoft APIs
- 14:26to ask the user for permission. It requests an
- 14:29OAuth token. Okay, let's drill into that, because
- 14:32the mechanism here is why this is so successful.
- 14:35When an employee clicks Accept, on one of these
- 14:38shiny, official -looking add -ins, they aren't
- 14:40giving the attacker their password. No, and honestly,
- 14:43the attacker doesn't even want their password.
- 14:45Why not? Because if they steal a password, they
- 14:47still have to bypass your multi -factor authentication.
- 14:49Ah, right, the MFA prompt. Exactly. Instead,
- 14:53the add -in asks for an OAuth token. You can
- 14:56think of an OAuth token like a digital hotel
- 14:59keycard. When you check into a hotel, you prove
- 15:02your identity at the front desk once. That's
- 15:04your password and your MFA. The desk verifies
- 15:07you, and they give you a keycard. From that point
- 15:09on, you just tap the card to open your door.
- 15:12You don't show your passport to the door every
- 15:14single time you want to get into your room. And
- 15:16these malicious add -ins are essentially tricking
- 15:19the user into handing a master keycard directly
- 15:22to the attacker. Precisely. The user clicks accept
- 15:25on a prompt that says something harmless, like
- 15:27allow this app to read your emails and access
- 15:29your files. Microsoft generates the oath token
- 15:32and hands it straight to the add -in. Game over.
- 15:34Yeah. The attacker now has persistent programmatic
- 15:37access to the user's entire Microsoft 365 environment.
- 15:41They don't need to hack the network perimeter.
- 15:43They don't need to defeat your MFA. They've been
- 15:46legally handed the keys by an employee who simply
- 15:49trusted the official Microsoft Store logo. Threat
- 15:52actors are totally weaponizing our misplaced
- 15:54trust in these ecosystems. Man, we have covered
- 15:57a massive amount of ground today, and the implications
- 16:00of this Kinsoft update are heavy. We've seen
- 16:02core AI models vanish without warning, forcing
- 16:06enterprises into these panicked architectural
- 16:08scrambles. We've watched critical zero -day exploits
- 16:11tear down the edge defenses of the European Commission.
- 16:14We've examined hypervisor -level espionage living
- 16:17silently inside foundational telco infrastructure.
- 16:21we've unpacked how malicious actors are legally
- 16:23bypassing MFA by poisoning trusted software marketplaces
- 16:27with oath token harvesters. It paints a very
- 16:30stark picture of the modern threat landscape
- 16:32for sure. But the Kinsoft Tech Talks update doesn't
- 16:35just leave the listener drowning in paranoia.
- 16:37There's a very concrete through line here. Internet
- 16:40facing edge devices and trusted ecosystem add
- 16:42-ins are the primary vectors where attackers
- 16:44are finding the most success right now. And it's
- 16:47precisely because they are the areas where organizations
- 16:49mistakenly assume the vendor has already solved
- 16:52the security problem. For you listening, if you
- 16:55are an IT director, a security architect, or
- 16:58a business owner trying to operationalize this
- 17:00intelligence, here is your concrete action plan.
- 17:03First, you have to assume breach. You cannot
- 17:05just rely on your firewalls or your MDM servers,
- 17:08as we saw with Brussels. Your survival depends
- 17:11entirely on how fast you can detect lateral movement
- 17:13inside your network. Are you actively hunting
- 17:16for anomalous Kerberos tickets or unusual Active
- 17:19Directory queries right now? If not, you need
- 17:23to be. Second, you must aggressively lock down
- 17:26user consent for enterprise applications. You
- 17:28simply cannot allow standard employees to grant
- 17:31OOOTH permissions to third -party add -ins, regardless
- 17:34of whether they come from the official Microsoft
- 17:36or Google store. You have to take that power
- 17:38away. You do. You have to implement administrative
- 17:40workflows, where every single requested integration
- 17:43is audited for permission scopes before the token
- 17:46is granted. And finally, regarding your workflows,
- 17:49stop hardwiring your operations to specific external
- 17:52models. models. Whether it is an LLM or a cloud
- 17:55API, build abstraction layers. Do not tie your
- 17:59skyscraper to a rented foundation that will inevitably
- 18:01shift. And as the Kinsoft report notes, if you
- 18:05are sitting there wondering exactly what your
- 18:06attack surface looks like right now, you cannot
- 18:09protect an environment you haven't fully mapped.
- 18:12They advise visiting kinsoft .com .au if you
- 18:15need comprehensive help assessing your exposure
- 18:17to these exact vectors. Yeah, and the host of
- 18:19the Kinsoft update signed off with a phrase that
- 18:21serves as the the perfect operating principle
- 18:23for this entire discussion. They said, stay patched,
- 18:26stay skeptical. It really is the only way forward.
- 18:29But looking at everything we've unpacked today,
- 18:31from the ephemeral nature of our AI tools to
- 18:32the deeply compromised state of hypervisors and
- 18:35official marketplaces, it forces a fundamental
- 18:37reevaluation of how we do business. We naturally
- 18:40want bedrock. We want to designate our firewalls
- 18:43and our software vendors as safe so we can stop
- 18:45worrying about them and just, you know, focus
- 18:48on our actual work. But the telemetry proves
- 18:50that safety is a total... Right. And I want to
- 18:52leave you with a final lingering thought to chew
- 18:54on regarding that illusion of safety. If the
- 18:58AI endpoints we build upon can just disappear,
- 19:01if the governmental perimeters we trust are breached
- 19:04in hours, and if the official stores we rely
- 19:07on are actively weaponized, well, is the very
- 19:10concept of trusting your IT infrastructure an
- 19:13outdated vulnerability? Moving forward, should
- 19:16enterprises completely abandon the idea of building
- 19:19a secure, unbreachable environment and instead
- 19:21design their operations assuming that the network
- 19:24is already compromised? If the spy is already
- 19:26living in the ceiling, how do you change the
- 19:29way you do business on the floor? That is the
- 19:31defining architectural question of the next decade.
- 19:33If you can't trust the foundation, you have to
- 19:36build resilience into every single transaction.
- 19:39Thank you so much for joining us for this deep
- 19:40dive into the Kinsoft intelligence. We hope it
- 19:43gave you the clarity to rethink your architecture,
- 19:45maybe a few aha moments about how these mechanisms
- 19:47actually work, and plenty to strategize over.
- 19:50Keep questioning your assumptions, keep exploring
- 19:52your networks, and we'll see you next time.