Daily brief at 7am Melbourne. Unsubscribe any time.

Monday 22 June 2026

The Boot Key Deadline Nobody Told You About: Windows and Linux Have 48 Hours

Your PC's boot keys expire in 48 hours, Suncorp puts AI agents on insurance claims, and a fresh botnet turns thousands of D-Link routers into a criminal proxy network.

Lead story

The Boot Key Deadline Nobody Told You About: Windows and Linux Have 48 Hours

On 24 June 2026 — this Tuesday — a set of cryptographic keys that underpin the Secure Boot process on Windows and Linux machines will begin to expire. If you've never heard of this, you're not alone. But the consequences of ignoring it range from annoying (systems that won't boot after an update) to serious (machines left exposed to bootkit malware that Secure Boot was specifically designed to stop).

Here's the short version of what Secure Boot actually does. When your computer starts up, before the operating system loads, firmware checks that every piece of boot software has been signed by a trusted key. It's a chain of trust designed to ensure nobody has tampered with your boot sequence — the kind of attack that nation-state malware like BlackLotus specifically targets. The keys doing that signing have a finite lifespan, and a batch of them are hitting their expiry date right now.

Who is actually at risk? The impact varies depending on your setup. Home users running standard Windows 11 on modern hardware are likely covered by automatic updates Microsoft has been quietly pushing for months. The bigger exposure is in enterprise environments — particularly organisations running older hardware, custom Linux distributions, dual-boot configurations, or systems that have been carefully locked down and aren't receiving automatic firmware or bootloader updates. Virtualisation environments and servers are also in scope.

For Linux users, the picture is patchier. Distributions like Ubuntu, Fedora, and SUSE have issued updated shim packages (the small piece of software that bridges firmware and the bootloader), but whether those updates have actually landed on every machine in a fleet is a different question. If your Linux systems run a rolling update process, you're probably fine. If someone last touched that server in 2024, check now.

The practical risk has two flavours. First, if the expired keys are revoked as part of the transition, machines running older signed bootloaders could simply refuse to start — a business continuity problem. Second, and more concerning from a security standpoint, the window between key expiry and full revocation is exactly the gap attackers will probe. Bootkits that survive only because old keys aren't yet revoked become newly potent.

What should you do before Tuesday? Microsoft's guidance says to ensure your Windows devices have received updates from the last few months and that UEFI firmware is current. For Linux, check that your distribution's shim and GRUB packages are at their latest versions. If you manage a fleet, now is a good time to audit which machines haven't checked in for updates recently — those are your risk surface.

The Australian context: Organisations covered by the Security of Critical Infrastructure Act — utilities, financial services, health, transport — have an obligation to maintain patching and configuration hygiene on their systems. A boot-level vulnerability or misconfiguration isn't the same category of risk as an unpatched application server, but the principle is identical. If your asset register doesn't track firmware patch state, this week is a reasonable prompt to fix that.

The expiry itself is a planned, managed transition — not a zero-day. But "planned" doesn't mean "painless," and the organisations most likely to be caught off guard are the ones that have the least tolerance for unplanned downtime.

Watch for: post-deadline reports of boot failures in enterprise environments, and any threat actor attempting to exploit the transition window before revocation is fully enforced.

Also today

AryStinger Botnet Hijacks 4,000+ D-Link Routers as Criminal Proxy Fleet

A newly documented botnet called AryStinger has quietly compromised more than 4,000 end-of-life D-Link routers, turning them into a proxy network for routing malicious traffic. The routers, which no longer receive security updates from D-Link, were targeted through known unpatched vulnerabilities. Once infected, devices join a pool that bad actors can rent to disguise the origin of attacks, credential-stuffing campaigns, or fraud. The pattern mirrors earlier botnets like Volt Typhoon's SOHO router campaigns. D-Link routers remain widely deployed in Australian homes and small businesses — if you're still running an older D-Link model, this is a firm nudge to replace it.

Bleeping Computer

Trump Clears Anthropic After National Security Standoff

The Trump administration has reversed its position on Anthropic, no longer classifying the AI safety-focused lab as a national security threat. Trump said the company responded "very quickly" and "responsibly" to the administration's concerns — though the specific demands made and concessions given have not been made public. The episode is a notable demonstration of how the current US administration is using national security framing as a lever over domestic AI companies. For the broader AI ecosystem, the unresolved question is what compliance looks like — and whether this sets a precedent for similar pressure on other labs.

iTnews

Suncorp Deploys AI Agents Inside Insurance Claims — This Month

Suncorp is rolling out five AI agents into its insurance claims process as early as June 2026, making it one of the first major Australian financial services companies to move autonomous AI into a core operational workflow rather than a pilot. Each agent handles a discrete sub-process within the claims pipeline. The move is significant because insurance claims decisions carry real consumer harm potential — incorrect automated decisions can delay payouts to people who've just lost homes or vehicles. How Suncorp governs those agents, and whether affected customers know AI is in the loop, will be a test case watched closely by ASIC and the broader industry.

iTnews

Polymarket Paid Creators to Post Fake Betting Videos

A Wall Street Journal investigation has found that prediction market platform Polymarket paid social media creators to film themselves placing bets and celebrating winnings that weren't real — in many cases using near-perfect replicas of the Polymarket interface. More than 1,100 deceptive clips were identified. The creators did not disclose the commercial relationship in their posts. This is a textbook case of undisclosed paid promotion, which sits in murky territory across most jurisdictions' consumer protection and financial advertising rules. In Australia, ASIC's guidance on social media financial promotions and the ACCC's influencer disclosure rules would both be relevant if an Australian operator did the same.

The Verge

iOS 27: The AI Features Beyond Siri's Makeover

Apple's WWDC announcements focused heavily on Siri's overhaul, but TechCrunch has catalogued a broader set of AI features landing in iOS 27 that may prove more immediately useful: smarter notification summarisation, on-device writing tools across third-party apps, improved image generation, and contextual suggestions that draw on personal data without sending it to the cloud. The on-device emphasis matters — Apple is still positioning privacy as a differentiator against Google and Samsung. For Australian users, the practical question is whether features dependent on Apple Intelligence's server-side components will be geo-restricted, as some Apple Intelligence features were slow to reach non-US markets in iOS 18.

TechCrunch

Lendi Group Builds Its Own Agentic Orchestration Layer for Mortgages

Australian mortgage platform Lendi Group has rebuilt a significant chunk of its technology stack around agentic AI, including developing its own orchestration layer to coordinate multiple AI agents rather than relying on a third-party framework. The decision to build rather than buy reflects a broader pattern among larger Australian fintechs that have decided off-the-shelf AI agent frameworks don't give them enough control over reliability and compliance. Lendi handles home loans for hundreds of thousands of Australians — if an AI agent mis-sequences a loan approval step, the consumer consequences are material. The build-vs-buy debate for agentic infrastructure is now very live across Australian financial services.

iTnews

China Leads the Global Robotaxi Race, New Scorecard Finds

A new assessment of the global robotaxi industry puts Chinese operators — led by Baidu's Apollo Go and WeRide — significantly ahead of US competitors on operational scale, city coverage, and ride volume. While Waymo dominates in the US on safety reputation and premium positioning, Chinese firms have achieved the kind of mass deployment that generates training data at scale. The gap matters because robotaxi AI improves with miles driven — China's head start compounds over time. For Australian transport planners watching the space, the scorecard is a useful reality check on which technology stack is likely to be available for licensing or deployment first.

TechCrunch

NSW Police Gets $108.8M to Tackle Tech-Enabled Crime

The NSW government has allocated $108.8 million to NSW Police for upgrades to digital evidence management systems and broader technology infrastructure. The budget injection is a direct response to the explosive growth in data generated by tech-enabled crime — think encrypted messaging, crypto transactions, and surveillance footage — which has overwhelmed existing evidence handling systems. NSW Police cited soaring investigative demands as the primary driver. The investment aligns with a national pattern of state police forces playing catch-up with criminals who adopted cloud and mobile-native infrastructure years before law enforcement had the tools to investigate it at scale.

The Mandarin

NSW Hits KPMG With Its Toughest Procurement Ban Yet

New South Wales has extended its restrictions on engaging KPMG for government work, going further than the federal government's earlier pause. The state has imposed sweeping procurement controls that tighten scrutiny across all government engagements with the firm — not just new contracts. The move escalates what has become an ongoing governance reckoning with the big four consulting firms following a string of probity controversies. For IT and digital transformation programs — which have historically been heavy consumers of big-four consulting — the ban creates a real procurement headache for NSW agencies mid-project.

The Mandarin

Ubisoft Co-Founder Claude Guillemot Dies in Plane Crash

Claude Guillemot, one of the five brothers who founded Ubisoft in 1986, has died at 69 following a plane crash. Along with his siblings, Guillemot helped build what became one of the world's largest video game publishers, responsible for franchises including Assassin's Creed, Far Cry, and Rainbow Six. The company has faced a turbulent few years — shareholder pressure, failed acquisition bids, and underwhelming game launches — and was already navigating a succession and strategic reset. Guillemot's death is a loss for the industry's founding generation and adds to an already uncertain period for the company.

TechCrunch

Electric Air Taxis Are Grounded — By Lawyers, Not Physics

The electric vertical take-off and landing (eVTOL) sector's biggest obstacle right now isn't battery energy density or FAA certification — it's litigation. Joby Aviation and Archer Aviation are locked in a trade secrets lawsuit, with Joby alleging Archer was built on stolen IP. Other players in the sector face their own legal entanglements. The piece is a useful corrective to the hype cycle: the technology is closer to real than it's ever been, but the commercial launch timelines being marketed to cities and investors — including Australian ones, where both Joby and Wisk have explored opportunities — keep slipping, and the courtroom is now a meaningful variable.

The Verge

Sources consulted