Latest / Tech Talks With Kinsoft / Last Week in Tech
Transcript
- 0:00So picture this. Hackers just remotely wiped
- 0:0380 ,000 medical technology devices. And they
- 0:06did it without running a single line of malware.
- 0:08Plus, a major telecommunications giant lost an
- 0:13entire petabyte of data, all because of a forgotten
- 0:16password from over a year ago. Yeah, it is a
- 0:18staggering amount of data. And it gets worse.
- 0:20The very tools that we deploy to scan our code
- 0:23for vulnerabilities are out there actively distributing
- 0:26worms. Oh, and Google's AI is actively rewriting
- 0:30news headlines into, well, the exact opposite
- 0:32of reality. It really has. Welcome to Tech Talks
- 0:36with Ken Soft. I am so thrilled you are joining
- 0:38us today. Our mission for this episode is pretty
- 0:40clear. We are synthesizing a massive stack of
- 0:43recent tech and cybersecurity reports, incident
- 0:46analyses, and patch notes just to figure out
- 0:49exactly how the rules of the digital race are
- 0:51being entirely rewritten. And, you know, the
- 0:53overarching theme that emerges from analyzing
- 0:55all these sources is undeniable. The traditional
- 0:57perimeter is dead. Totally dead. Yeah. Today's
- 1:00threats and innovations, they just aren't happening
- 1:03at the gates anymore. They're happening inside
- 1:04the house. Inside the house. Right. Exactly.
- 1:06They're embedded deep in our software supply
- 1:09chains, our built in enterprise administration
- 1:13tools and, you know, our daily workflows. OK,
- 1:16let's unpack this, starting with how threat actors
- 1:19are. No longer really breaking in. They're just
- 1:22logging in. Right. Let's look at that massive
- 1:25incident at Stryker. They're a huge medical technology
- 1:28giant. Literally overnight, 80 ,000 employee
- 1:33devices. And we're talking corporate hardware
- 1:35and personal devices that were enrolled in their
- 1:37network. They were all remotely wiped. Just completely
- 1:39erased. Exactly. And a pro -Iran hacktivist group
- 1:43known as Handala claimed responsibility. They
- 1:46stated they stole 50 terabytes of data. Although
- 1:49I should point out that investigators from Microsoft
- 1:50Dart and Palo Alto haven't actually confirmed
- 1:53that exfiltration yet. Right, right. But the
- 1:55device wipe itself is completely undeniable.
- 1:57Absolutely. The scale of the disruption is severe.
- 1:59But the mechanism, I mean, that is what really
- 2:01demands our attention here. We've spent decades
- 2:04building these incredibly complex endpoint detection
- 2:07and response systems, you know, EDR. Just to
- 2:10catch malicious executables. Exactly. To catch
- 2:12the bad code. But like. No malware was used here.
- 2:16None at all. None? It honestly reminds me of
- 2:18a valet parking model. You know, the parking
- 2:21garage doesn't check if you actually own the
- 2:22car. Right. It only checks if you hold the digital
- 2:24ticket. So the attackers compromised a Microsoft
- 2:28Intune global administrator account. And from
- 2:31there, they just used the software's legitimate
- 2:33built -in remote wipe feature to just erase those
- 2:3880 ,000 devices. What's fascinating here is how
- 2:41this entirely redefines the trust model. How
- 2:44so? Well, Intune is a mobile device management
- 2:46platform, right? So it's designed by definition
- 2:48to have ultimate authority over the endpoints
- 2:51it manages. Because it's an admin tool. Exactly.
- 2:54Right. So by compromising that global admin identity,
- 2:56the attackers bypass the firewalls, the anomaly
- 2:59detection, and the EDR entirely. Wow. Yeah. The
- 3:02security systems just simply saw a legitimate
- 3:04administrator executing a highly privileged but
- 3:07standard command. Because it's a feature, not
- 3:09a bug. Precisely. Identity is the new perimeter.
- 3:12If you hold the keys, the system inherently trusts
- 3:16you, regardless of your intent. And we see that
- 3:18exact same principle in the Telus Digital hack,
- 3:20too. Oh, yeah. For those listening, Telus Digital
- 3:23is this massive Canadian business process outsourcer.
- 3:26They handle call centers and AI bots for major
- 3:30telecoms and financial services. A huge target.
- 3:33A massive target. one petabyte of data. One petabyte.
- 3:43It's hard to even conceptualize that much data.
- 3:45It really is. And it included FBI background
- 3:47checks and call center recordings. And how did
- 3:50they get in? By using Google Cloud Platform credentials
- 3:52that were stolen in a completely different hack,
- 3:54a breach of a company called SalesLoft way back
- 3:56in 2025. And that right there illustrates the
- 3:59incredibly long tail of these identity crises.
- 4:03Yeah, a year later. Right. A token or credential
- 4:05stolen a year ago in a totally separate incident
- 4:08just becomes the entry point for a petabyte scale
- 4:10data. a theft today. It's terrifying. And regulators
- 4:13are rapidly losing patience with this exact scenario.
- 4:17Are they stepping in? They are. In Australia,
- 4:19the Armed Forces Security Agency recently warned
- 4:22corporate boards that claiming, you know, we
- 4:25were collateral damage in a third party breach.
- 4:27That's no longer a valid defense. Interesting.
- 4:30Yeah. When basic segmentation and identity oversight
- 4:33fail, regulators are saying the responsibility
- 4:35falls squarely on the organization holding the
- 4:38data. Well, and we are seeing that long tail
- 4:40accountability play out with Singtel right now,
- 4:42too. Right. The Senate inquiries. Yeah. They
- 4:44are facing Senate inquiries over these explosive
- 4:46allegations of secret. ransom payments from a
- 4:492022 Optus breach. It just shows how the fallout
- 4:52from these identity compromises lasts for years.
- 4:55Absolutely years. But if attackers are just logging
- 4:59in using legitimate tools and stolen credentials,
- 5:02what happens when the security tools themselves
- 5:05are compromised? That is the next logical step
- 5:07for them. Right. We're seeing a shift from poisoning
- 5:09the user to poisoning the well. Let's look at
- 5:13the recent supply chain attack on the Trivy vulnerability
- 5:15scanner. Trivi is a highly foundational open
- 5:18source tool. It's everywhere. It really is. Development
- 5:21teams integrate it directly into their continuous
- 5:24integration workflows. They use it to scan containers
- 5:27and code for vulnerabilities before deployment.
- 5:30And threat actors tracked as Team PCP use stolen
- 5:34credentials to publish malicious Trivi releases
- 5:37and modify GitHub actions. Yeah. And I gotta
- 5:40say, this is what genuinely alarms me. The irony
- 5:42of it. Yes. Developers use Trivy to find the
- 5:45holes. If the tool verifying the integrity of
- 5:48your code is actually injecting the malware,
- 5:50how can any organization trust their own development
- 5:53pipeline? It's like the security guard is the
- 5:54one handing out blueprints to the bank vault.
- 5:57That's a great way to put it. And the severity
- 5:59of this incident goes far beyond just credential
- 6:01harvesting. What else did they do? Well, the
- 6:03attackers unleashed a self -propagating worm
- 6:06called Canister Worm across 47 NPM packages.
- 6:10Okay, wow. And what makes Canister Worm... incredibly
- 6:13sophisticated is its command and control infrastructure.
- 6:16It actually leverages tamper -proof smart contracts
- 6:19to spread. Wait, hold on. They are using blockchain
- 6:22infrastructure to host the malware's instructions?
- 6:25Yes. That is wild. It is. Traditionally, you
- 6:29know, if an attacker sets up a command and control
- 6:31server on a cloud provider, security researchers
- 6:34can just work with the provider to take that
- 6:36server offline. Right. Sinkholing the attack.
- 6:39Exactly. But by hosting the execution logic on
- 6:43decentralized smart contracts, the attackers
- 6:46have created this immutable distributed command
- 6:48infrastructure. You can't just call up customer
- 6:50service for the blockchain. Right. You cannot
- 6:52simply submit a takedown request to a blockchain.
- 6:55Wow. So you end up with a trusted security scanner
- 6:58acting as a distribution mechanism for a highly
- 7:01resilient worm that is deeply embedded into the
- 7:04software supply chain. It is absolute infrastructural
- 7:07rot. It really is. And speaking of foundational
- 7:10software, this leads right into the behemoth
- 7:12that was Microsoft's March 2026 patch Tuesday.
- 7:16Oh, that was a massive update. Huge. They addressed
- 7:1979 flaws, including two publicly disclosed zero
- 7:22days, one in SQL Server and one in .NET. Right.
- 7:25But there is one specific vulnerability that...
- 7:28perfectly highlights this era of compromised
- 7:31foundational tools. It's an Excel co -pilot flaw.
- 7:35Right. CVE -2626144. That's the one. And it allows
- 7:41for a zero -click information disclosure attack
- 7:44via unintended network egress. And this is so
- 7:47critical because we are integrating highly privileged
- 7:50AI agents into our most sensitive document environments.
- 7:54Yeah. Co -pilot is everywhere now. It is. And
- 7:56it has access to your emails, your financial
- 7:58models, your internal chats. So for the listener,
- 8:02how does unintended network egress actually work
- 8:05in this context? Because it sounds like a very
- 8:07polite way of saying the AI is smuggling data
- 8:09out the back door. It's essentially an advanced
- 8:11prompt injection that manipulates the AI's network
- 8:14permissions. Okay. So an attacker can embed hidden
- 8:17instructions within an Excel file. Maybe they
- 8:19use white text or they hide it in the metadata.
- 8:21Something the user wouldn't even see. Exactly.
- 8:23But when Copilot scans the doc... to summarize
- 8:26it for the user, it processes those hidden instructions.
- 8:29And then the malicious prompt commands the AI
- 8:31to gather sensitive data from the user's environment,
- 8:35append that data to a URL, and make a web request
- 8:39to an external server controlled by the attacker.
- 8:42While pretending to do something else. Right,
- 8:44under the guise of fetching a required image
- 8:46or resource. That's insidious. The user never
- 8:49clicks a malicious link. The AI agent just does
- 8:52it for them in the background. So the threat
- 8:55is basically already inside the perimeter by
- 8:57default. Exactly. And this smuggling, it doesn't
- 9:01just stop at the enterprise cloud. It extends
- 9:03all the way to the devices in our pockets in
- 9:05our homes. Let's shift to the edge frontier.
- 9:08A very active space right now. Highly active.
- 9:11We just saw Android release its massive March
- 9:132026 update. A staggering 129 fixes. Massive
- 9:18patch. It is. But here's where it gets really
- 9:20interesting. This update includes a fix for a
- 9:23zero -day vulnerability in Qualcomm GPUs. That's
- 9:26CVE -20262 -1385. And it was already being actively
- 9:31exploited in the wild. The update was so huge.
- 9:34They actually split it into a March 1st software
- 9:37patch and a March 5th hardware patch. for the
- 9:40chipsets and that distinction between the software
- 9:43and hardware patch is really critical for you
- 9:46to understand the complexity of these devices
- 9:47break that down a bit sure the operating system
- 9:50layer android that can be patched relatively
- 9:52easily but a gpu zero day involves the fundamental
- 9:56microcode that's executing on the system on a
- 9:58chip oh it's way deeper much deeper the hardware
- 10:01patch fundamentally alters how memory is allocated
- 10:04at the silicon level Yeah. And it requires deep
- 10:07coordination between Google chipset manufacturers
- 10:10like Qualcomm and device vendors like Samsung.
- 10:13And Samsung actually had to use a dual track
- 10:15approach. They did. They had to push their own
- 10:17specific security fixes alongside Google's. And
- 10:19the crazy part is. While they were patching 129
- 10:23security holes, they were simultaneously pushing
- 10:26out new ecosystem features. Right, like Wi -Fi
- 10:29sync. Yeah, Wi -Fi sync to share network credentials
- 10:32and play shorts for App Store video previews.
- 10:35It is an incredibly complex ecosystem. It's a
- 10:39lot of moving parts. But compare that to the
- 10:41devices sitting in our living rooms. While phones
- 10:43get 129 patches in a day, our home appliances
- 10:47are basically a security void. A total Wild West.
- 10:50Truly. But Australia is trying to change that.
- 10:53They're enforcing their new security standards
- 10:55for smart devices as of March 4th, 2026. And
- 10:59this is overseen by the Technology Assessment
- 11:00and Regulation Office, or TARO. And these rules,
- 11:03quite strict, they mandate the elimination of
- 11:07universal default passwords for IoT devices.
- 11:10Finally. Yeah, and manufacturers must provide
- 11:12a mechanism to report security vulnerabilities.
- 11:14Plus, crucially, they must be transparent about
- 11:17the guaranteed timeline for security updates.
- 11:20Which is great, but I have a major pushback here.
- 11:22Oh. Why explicitly exclude smartphones, laptops,
- 11:26and PCs from these rules? Doesn't that leave
- 11:28the devices holding our most sensitive personal
- 11:31data completely unregulated by this new office?
- 11:34I mean, isn't that like putting a high -tech
- 11:36biometric lock on your garden shed but leaving
- 11:39your front door wide open? I see why it looks
- 11:41that way. But if we connect this to the bigger
- 11:44picture, the exclusion makes technical sense.
- 11:47Really? How so? Well... Smartphones and laptops
- 11:50possess hardware roots of trust. And as we just
- 11:53discussed with that Android update, they have
- 11:55highly active, deeply scrutinized update ecosystems.
- 11:59Okay, that's true. The mobile ecosystem is actively
- 12:02managed by massive security teams. Exactly. The
- 12:05IoT space, however, has traditionally operated
- 12:07on bare metal Linux with hard -coded credentials
- 12:10that are flashed once at the factory and then
- 12:13completely forgotten. Oh, right. Like a smart
- 12:15fridge that never gets an update. Precisely.
- 12:17And a compromised... smart thermostat might seem
- 12:19trivial, but it acts as a persistent foothold
- 12:22to access the wider domestic network. So Tero
- 12:25is just targeting the weakest links. Right. They
- 12:27are targeting the unregulated edge of the network
- 12:30to ensure those weak links meet at least a minimum
- 12:32baseline. Okay, that makes sense. So regulators
- 12:35are enforcing baseline security on IoT. But what
- 12:38happens when government regulations actually
- 12:40mandate the creation of new vulnerabilities on
- 12:43our most secure devices? That is the regulation
- 12:45paradox we are seeing unfold right now. Exactly.
- 12:48Let's look at Brazil. They're a fast -tracking
- 12:50bill 4765 slash 2025. This legislation heavily
- 12:55mirrors the European Union's Digital Markets
- 12:58Act. Right, focusing on interoperability. Yeah,
- 13:01forcing tech companies to allow hardware and
- 13:03software interoperability to increase market
- 13:06competition. And look, market contestability
- 13:08is a standard economic goal. Regulators want
- 13:11smaller companies to be able to compete with
- 13:13massive walled gardens. Which sounds good on
- 13:16paper. It does. But when you apply this mandate.
- 13:19to highly secure digital ecosystems, the technical
- 13:23reality clashes violently with the regulatory
- 13:25intent. And we have a perfect, real -world example
- 13:28of this clash involving the Apple iPhone. We
- 13:31do. To make alternative web browsers or third
- 13:33-party app stores run as fast as Apple's made
- 13:36of apps, external developers need direct access
- 13:39to the just -in -time, or JIT, compiler. Right.
- 13:42And a JIT compiler is designed to take software
- 13:45code and compile it into machine code on the
- 13:47fly. Dynamically. Yes. dynamically to drastically
- 13:51boost performance. But to do this, it requires
- 13:54the ability to write to device memory and then
- 13:57immediately execute that memory. But wait, doesn't
- 14:00that fundamentally break the security model?
- 14:03How do you mean? Well, if you can write data
- 14:05and execute it on the fly, you bypass the core
- 14:08sandboxing that keeps a malicious app from taking
- 14:10over the phone. You've identified the exact vulnerability.
- 14:14Modern operating systems rely on a security principle
- 14:17called Write XOR Execute. Okay. It basically
- 14:20means a sector of memory can either be written
- 14:23to or it can be executed, but never both simultaneously.
- 14:26Oh, I see. The JIT compiler is the one highly
- 14:29guarded exception to this rule. And regulators
- 14:32want to open that up. Yes. By forcing Apple to
- 14:35grant third -party applications access to the
- 14:38JIT compiler for the sake of market competition,
- 14:40regulators are mandating access to the most dangerous
- 14:43engine on the device. That's terrifying. And
- 14:46we saw the fallout from this, too. Hackers recently...
- 14:48used a JIT exploit called Dark Sword to indiscriminately
- 14:52hack hundreds of millions of iPhones. Just by
- 14:54embedding the tool in infected websites. Yeah.
- 14:57Apple patched the specific exploit eventually.
- 15:00But researchers noted that the Russian hackers
- 15:02who utilized Dark Sword left the fully documented
- 15:05code online. With instructions. Yes. With English
- 15:09comments explaining how to use it for... absolutely
- 15:12anyone to deploy. It's not just about leaving
- 15:14the vault door unlashed. It's like regulators
- 15:17demanding the bank give competing tellers the
- 15:20unrestricted ability to rewrite the bank's operational
- 15:23ledger on the fly. This raises an important question
- 15:26for you as the listener to consider regarding
- 15:28the intersection of policy and security. Yeah,
- 15:30it's a huge policy issue. If a government successfully
- 15:32mandates interoperability, legally forcing a
- 15:36company to open up direct read, write and execute
- 15:39access to third parties who assumes the risk.
- 15:41If a nation state actor uses that legally mandated
- 15:44open door to launch an attack that compromises
- 15:47millions of citizens, who is responsible for
- 15:50the patch? It's a massive gray area. It is. The
- 15:53regulatory push to rapidly alter these deeply
- 15:55embedded architectures often just fails to account
- 15:58for the profound security implications. We are
- 16:01seeing these complex systems pushed to their
- 16:03absolute limits by both attackers and regulators.
- 16:07Constantly. Speaking of complex systems we are
- 16:09struggling to control, let's transition to the
- 16:12ultimate wildcard for your business and daily
- 16:14life. Artificial intelligence. Ah, AI. Yeah.
- 16:18Well, we are seeing a true... dual reality when
- 16:21it comes to ai right now we really are ai is
- 16:23simultaneously acting as an unpredictable agent
- 16:26of chaos on the consumer front and a highly deterministic
- 16:30optimized engine for enterprise efficiency let's
- 16:33look at the chaos first because this is wild
- 16:35a report from the verge detailed how google search
- 16:38is experimenting with using ai to rewrite news
- 16:41headlines directly in its traditional 10 blue
- 16:43links right So a writer published a highly critical
- 16:46review of an application. The original headline
- 16:49was, quote, I used the cheat on everything AI
- 16:51tool and it didn't help me cheat on anything.
- 16:54Which is a scathing review. Very scathing. The
- 16:56intention of the author is entirely unambiguous.
- 16:58Totally unambiguous. Yeah. But Google's AI completely
- 17:02hallucinated the context. It rewrote the headline
- 17:05in the search results to just say, quote, cheat
- 17:08on everything AI tool. Wow. It stripped all the
- 17:11context and completely inverted the truth into
- 17:14what looks like a positive endorsement. Because
- 17:16the AI is context blind. Exactly. If millions
- 17:20of people are scanning search results for accurate
- 17:22information, having an AI actively distorting
- 17:25reality on the fly is a massive problem. So what
- 17:28does this all mean? Well, it means consumer facing
- 17:31large language models are still really struggling
- 17:34with foundational comprehension. Because they
- 17:36just predict words. Right. Because they predict
- 17:38language statistically rather than actually understanding
- 17:41truth factually, they are prone to these massive
- 17:44context collapses. A mess. It is. But we have
- 17:47to contrast this consumer level chaos with what
- 17:50is happening in the enterprise space. Where things
- 17:52are a bit more controlled. Much more. In the
- 17:54enterprise space, AI is being deployed with much
- 17:57tighter parameters and specialized hardware architecture.
- 18:00OK, so like at the GTC 2026 conference, IBM and
- 18:04NVIDIA just announced an expanded collaboration
- 18:07that paints a totally different picture. Exactly.
- 18:09They are not using AI to rewrite blog posts.
- 18:12They're using AI and GPU native computing to
- 18:15literally revolutionize global supply chains.
- 18:18And the technical jump here is huge. They are
- 18:21taking IBM's Watson X dot data sequel engine,
- 18:25which is called Presto, and accelerating it using
- 18:27NVIDIA's CutEF software. Okay, so to understand
- 18:30the magnitude of this, you really have to look
- 18:32at the underlying hardware. Right. Traditional
- 18:34data processing runs on CPUs. Right. And CPUs
- 18:36execute tasks sequentially, just one instruction
- 18:39at a time. Which is fine for basic tasks, but
- 18:42they applied this to Nestle's global order -to
- 18:44-cash data mart. Which is an enormous data set.
- 18:46Enormous. This system tracks every single order,
- 18:49fulfillment, delivery, and invoice across 186
- 18:53countries. It processes massive terabytes of
- 18:56data across 44 dense tables. So running this
- 18:59on standard CPUs meant a single data refresh
- 19:01took Nestle 15 minutes. Which in global logistics
- 19:04is an eternity. It really is. But by moving to
- 19:07the NVIDIA GPU architecture, they are utilizing
- 19:10vectorized processing. Right, because GPUs have
- 19:13thousands of smaller cores. Exactly. They are
- 19:16designed to process millions of rows of data
- 19:18simultaneously in parallel. And the CutEF software
- 19:21allows Nestle to run their existing SQL queries
- 19:25on these GPUs without even having to rewrite
- 19:28the code. Which is the real game changer. Yeah.
- 19:30And the results were staggering. They reduced
- 19:33that global query runtime from 15 minutes down
- 19:36to just 3 minutes. Wow. That achieved an 83 %
- 19:40cost savings. and a 30 times overall price performance
- 19:43improvement. That is massive for a global company.
- 19:47It's unbelievable. And they aren't stopping at
- 19:49structured tabular data either. They are rolling
- 19:52out Dockling and Nematron models to ingest and
- 19:55standardize massive amounts of unstructured data.
- 19:58Like scattered PDFs. Yeah, PDFs, vendor research,
- 20:01all at an enterprise scale. It's just incredible.
- 20:03On one hand, we have AI acting like a toddler
- 20:06with a megaphone on the consumer internet, completely
- 20:08scrambling the news. And on the other hand...
- 20:10It is building a high -speed bullet train for
- 20:12global logistics, saving multinational corporations
- 20:15millions. It really perfectly encapsulates the
- 20:19dual nature of the technological landscape we
- 20:21have explored today. It does. To synthesize this
- 20:24journey for you, the perimeter you thought was
- 20:27protecting your network is completely gone. Ranish.
- 20:30Hackers are using your own legitimate administration
- 20:32tools, like Intune, to wipe your devices. The
- 20:37security scanners you trust to protect your code
- 20:39are utilizing blockchain smart contracts to distribute
- 20:43worms into your supply chain. Which is still
- 20:45crazy to me. It is. And your phone requires fundamental
- 20:48microcode patches to stay secure against active
- 20:51zero days, while regulators are just now trying
- 20:54to put baseline password rules on the Wild West
- 20:56of smart home devices. Yeah. And AI is simultaneously
- 20:59distorting the information you read and exponentially
- 21:02accelerating the supply chains you rely on. It
- 21:05is a phenomenal amount of... complexity to manage.
- 21:06You cannot just buy a firewall, check a compliance
- 21:09box and call it a day anymore. Not even close.
- 21:11You have to constantly, actively evaluate your
- 21:14identity management, the integrity of your supply
- 21:16chain and your core infrastructure, which is
- 21:19exactly why before we sign off, I strongly suggest
- 21:22that you go to www .kinsoft .com forward slide.
- 21:26old all to discuss your own security and IT needs.
- 21:30You need to ensure your business is prepared
- 21:32for the rapidly shifting digital landscape we've
- 21:34discussed today. And the team at Kinsoft can
- 21:36help you navigate this exact complexity. And
- 21:38as we wrap up this analysis, I want to leave
- 21:40you with a final thought to mull over. Lay it
- 21:42on us. We've established that the traditional
- 21:45security perimeter is dead, replaced by identity.
- 21:47We've seen that AI can seamlessly hallucinate
- 21:50and rewrite the very interfaces we interact with
- 21:53daily. Right. So as these AI agents become more
- 21:56autonomous, more embedded in our enterprise workflows,
- 21:58and as our personal credentials continue to leak
- 22:01from breaches years in the past, how long until
- 22:04you have to mathematically prove you are a human
- 22:06being to your own devices just to log in? Wow.
- 22:09That is a brilliant and genuinely chilling question
- 22:13to end on. If the system only trusts the digital
- 22:16token, the concept of proving our physical reality
- 22:18becomes the next great security frontier. Thank
- 22:21you for joining us on Tech Talks with Kinsoft.
- 22:22We will catch you next time.