POPULARITY
Categories
Meta admits its Social Media is harmful to kids with $18B settlement, Meta Glasses now will stop working if you block the Recording light, Boston Scientific and McKesson Breached, Microduck Robot the next big thing? Flock OS Investigate tool getting creepy, CISA warns that Software vendors need to focus more on Secure by Design.
The U.S. disrupts a Chinese hacking operation blamed for intrusions at several sensitive government agencies. CISA says more than 100 water systems were targeted in July. Attackers exploit a critical Gitea flaw, while malicious pages masquerade as Cloudflare verification screens. Cyber insurance claims get costlier, and AI agents break out of their sandboxes. Boston Scientific battles a cyber incident. Plus, a new standard tracks AI agent activity, criminals target stolen iPhones, and an alleged money mule is charged in a $7.5 million scam. Our guest is Stephen Hilt, Sr. Threat Researcher at TrendAI, on the risks facing data centers. Some breach data doesn't quite measure up. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, we are joined by Stephen Hilt, Sr. Threat Researcher at TrendAI discussing the cybersecurity risks facing data centers and the thousands of internet-exposed industrial control systems that could leave them vulnerable to attack. And if you enjoyed this conversation, be sure to check out the full interview here. If you'd like to hear more on this topic from TrendAI, you can check out this recent episode of the AI Security Brief podcast that focuses on data center security. Guest Mark Houpt, CISO at DataBank, joined hosts Johnny Hand and Dustin Childs to explain why securing the AI era starts with protecting the physical data centers that power it—and why proven security fundamentals still matter against rapidly evolving threats. AI Security Brief podcast publishes every other Thursday on the N2K CyberWire network. Subscribe today! Selected Reading China-sponsored hacking platforms seized by US, Justice Department says (Reuters) CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks (SecurityWeek) Hackers now exploit critical Gitea flaw in code injection attacks (Bleeping Computer) Hackers abuse npm mirrors to host phishing redirect pages (Bleeping Computer) Average Cyber Insurance Losses Increase Despite Fewer Claims (Infosecurity Magazine) VMs won't contain cyber-capable agents (Trail of Bits) Boston Scientific hit by cyberattack, global operations affected (Reuters) Linux Foundation Introduces TRACE Standard for AI Runtime Evidence (Infosecurity Magazine) AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes (Bleeping Computer) Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly (The Record) Trump signs memo to help drastically boost US commercial space launches (Reuters) A Cautionary Tale About Data Breach Claims, Verification and Carhartt (Troy Hunt) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
A persistent governance gap is evident in current IT operations, as credential management and authorization checks fail to keep pace with increased automation and AI integration. This is visible in incidents involving major vendors such as N-able (through Passportal), Anthropic's Claude, AI-based retail management at Andon Labs, and legacy industrial controllers monitored by agencies like the NSA, CISA, and FBI. The episode highlights how systems are increasingly reliant on automated actors and credentialed assistants, while foundational questions of access rights and accountability remain unresolved. The most consequential case centers on a vulnerability in N-able's Passportal browser extension, disclosed by security researcher James Arnott. The flaw allowed any website—or embedded ad—to request and obtain session tokens, enabling decryption of entire password vaults. This affected approximately 2,500 MSPs and 165,000 SMBs, with each stolen token remaining valid for 100 days. N-able patched the issue quickly, but Dave Sobel emphasizes that the responsibility for checking permitted actions within such systems is often misattributed or left unaddressed. Supporting developments reinforce this governance gap. An AI assistant exploited poor authorization in an Australian gym reservation system, canceling another user's booking without hacking or unauthorized login. Similar risks persist in industrial environments, where controllers for energy, water, and agriculture often lack basic authentication—exposing them to AI-generated exploitation scripts, according to joint agency warnings. Additionally, retail automation at Andon Labs revealed AI-driven policy lapses, where systems cannot reliably document or enforce their own rules, highlighting operational weaknesses. Operationally, MSPs face increased risk from both their own service infrastructure and client environments. The practical recommendation is to issue discrete, revocable credentials tailored to each system agent, limiting their scope and ensuring traceable accountability. Providers are advised to formally define and document their responsibility boundaries regarding access and permissions in third-party applications. These steps shift the focus from attempting to control every client-side variable to clear documentation and compartmentalization, reducing dispute risk and speeding incident investigations. 00:00 The Gym Class and the Vault 03:39 The Check Was Always a Person 06:37 Your Tools Ask the Wrong Question 10:27 Why Do We Care? Supported by: GoTo(LogMeIn)Proofpoint
Lawmakers request an investigation into cuts at CISA. Threat actors actively exploit a Zimbra Collaboration Suite vulnerability. A Chinese AI lab preps release of a powerful open-weight model. A new phishing toolkit deploys attacker-controlled passkeys. Using audio hardware to fingerprint browsers. A DDoS attack knocks Norwegian government services offline. CISA orders patching of a critical Oracle vulnerability. Taiwanese prosecutors charge nine people over the alleged illegal export of high-end AI servers to mainland China. Operation Jackal IV cracks down on West African cybercrime networks. On our Industry Voices segment, Christy Wyatt, CEO from Absolute Security, discusses "Cyber Resilience: The Emerging Category." AI music hits a sour note down under. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices segment, we are joined by Christy Wyatt, CEO from Absolute Security, discussing "Cyber Resilience: The Emerging Category." If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading Lawmakers call for investigation into impact of CISA staffing cuts (The Record) Hackers breached over 270 Zimbra servers in ongoing attacks (Bleeping Computer) By Opening a Model, a Chinese A.I. Lab May Test the World's Cybersecurity (NY Times) iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset (SecurityAffairs) AliExpress was silently running audio in your browser to fingerprint and track your device (TechSpot) Large DDoS attack knocks Norwegian public services offline (The Record) U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog (SecurityAffairs) Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff (SecurityWeek) Police arrests dozens of suspects in global cybercrime crackdown (Bleeping Computer) Songs created by AI banned from Australia's music charts (BBC News) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Polymarket traders win big on U.S. military insider information. Slovakia deactivates speed cameras with Russian backdoors. TikTok pays $400 million to settle kids' privacy allegations. Hackers infect Android-based car systems with botnet malware. CISA orders quick patching of an actively exploited Zimbra Collaboration Suite vulnerability. SynkLoader malware is built for stealthy access to corporate networks. Dutch authorities fine Uber over $900 million over automated hiring practices. An ATM jackpotter gets a record prison sentence. Monday business briefing. A privacy promise loses face. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On our Industry Voices segment, we are joined by Mark Beare, General Manager at Malwarebytes Consumer Business from Black Hat to look at protecting your family in the age of AI. If you enjoyed this conversation, check out the full interview here. Selected Reading More than 150 Polymarket wallets may have traded on military secrets, research finds (Reuters) Slovakia discovers Russian backdoors in 279 new traffic cameras — SMS-triggered shell access and passwordless live feeds found in EU-funded rollout (Tom's Hardware) TikTok Settles U.S. Child Privacy Case for $400 Million (Security Affairs) Hackers infecting Android car systems to build proxy botnet (The Record) CISA orders urgent patching of actively exploited Zimbra flaw (Bleeping Computer) SynkLoader: when you throw in everything but the kitchen sink (Expel) Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts (SecurityWeek) Venezuelan Gets Record Federal Prison Term for ATM Jackpotting (SecurityWeek) Fortinet has acquired San Francisco-based AI security company Virtue AI. (N2K Pro Business Briefing) Reverse-Lookup Service Exposed Millions of Photos of People's Faces (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Mike Soule, Field CTO at Sentinel Technologies, returns to the PowerShell Podcast for the first time in three years to talk identity security, cloud configuration testing, and the evolving role of AI in the Microsoft ecosystem. Andrew and Mike dig into Maester, the open source PowerShell-based test automation framework that applies unit testing concepts to Microsoft 365 security configuration. Mike breaks down how Maester works, how Sentinel uses it with clients, and how the community has grown it into something that spans hundreds of built-in tests covering conditional access, CIS baselines, CISA standards, and more. They also cover EntraOps, the Enterprise Access Model, AI's impact on the MSP world, and why working in managed services is still one of the fastest ways to level up in IT. The episode closes with a strong Brandon Sanderson tangent. Key Takeaways: Maester brings the concept of unit testing to Microsoft 365 security configuration, letting admins continuously validate their cloud settings against known-good baselines with as few as three PowerShell commands. It's built on Pester, is fully open source, and now has over 100 community contributors. AI is changing the MSP landscape fast, but the fundamentals still matter. Mike and Andrew discuss how to think about Copilot licensing complexity, model routing in agent stacks, and why meeting users in their existing interface is often more important than deploying a shiny new tool. MSP experience accelerates learning in a way that internal IT often can't match. When you're working across multiple clients and environments, you accumulate reps quickly, and that breadth is hard to replicate elsewhere. Guest Bio: Mike Soule is the Field CTO at Sentinel Technologies, a large managed service provider focused on identity, cloud, and security strategy. Mike has been working hands-on with PowerShell, Entra ID, and Microsoft 365 security architecture for years and is a regular speaker at identity and security conferences. Resource Links: Maester (open source framework): https://maester.dev Maester on GitHub: https://github.com/maester365/maester Maester Cloud (hosted version by Merill Fernando): https://maester.cloud HIPConf (Hybrid Identity Protection Conference): https://www.hipconf.com EntraOps by Thomas Naunheim: https://github.com/Cloud-Architekt/EntraOps Mike Soule on LinkedIn: https://www.linkedin.com/in/mikesoule The PowerShell Podcast on YouTube: https://youtu.be/EQK693gGWoo
CISA orders patching of TrueConf Server vulnerabilities. LockBit threatens release of stolen banking data. Researchers disclose a critical type confusion vulnerability in a Node.js library. A new Agent Tesla v4 campaign introduces enhanced evasion techniques. A novel malware delivery technique abuses FTP server banners to hide commands. Apple patches a critical image-processing flaw. A North Korean software supply chain attack targets the Rust ecosystem. Latvian officials resign following a major data breach. Defense contractors are confident in compliance, less so in their ability to prove it. Our guest is Patrick Coughlin, Co-Founder and CEO of Savi Security. discussing the free utility he's developed to protect the sandwich generation from AI-driven scams. When it comes to cyber extortion, who you gonna call? Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Joining us today is Patrick Coughlin, Co-Founder and CEO of Savi Security. Patrick discusses protecting the sandwich generation from AI-driven scams and Scamwise, their free utility built with this purpose in mind. Learn more about Scamwise, a free public utility tool to help consumers quickly determine whether a suspicious message, call, or email is likely a scam, and download Savi's app. Selected Reading CISA orders feds to patch actively exploited TrueConf Server flaws (Bleeping Computer) US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline (The Register) Critical Isolated-vm Vulnerability Leads to RCE on Host (SecurityWeek) New Agent Tesla Malware Variant Boosts Evasion Capabilities (Infosecurity Magazine) Hackers abuse FTP server banners to deliver new Windows malware (Bleeping Computer) Apple plugs image-processing hole ripe for spyware abuse (The Register) North Korean Hackers Tied to Rust Supply Chain Attack (Infosecurity Magazine) Latvian officials resign after cyberattack exposes data on 1.2 million people (The Record) Contractors' CMMC Confidence Rises as Ability to Prove It Falls Behind (SecurityWeek) Ransomware crook poses as recovery firm to steal payments from fellow extortionists (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Medusa's reach grows. Cl0p expands its victim list. The DOJ charges 17 alleged Iranian hackers. CISA sounds the alarm on four exploited vulnerabilities. TWINLOOT hides in plain sight inside Microsoft 365. Maria Varmazis shares the latest from the space-cyber realm as Ukraine strikes Russia's satellite nerve center. The FDA considers guardrails for AI medical devices. Expired credit cards get an unexpected second life. A disgruntled contractor heads to prison. Dave Bittner sits down with Brian Vecci, Field CTO at Varonis, at Black Hat USA to discuss how AI is calling your security bluff. Highway hijinks meet high-tech hardware. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest At Black Hat USA, Dave Bittner sat down with Brian Vecci, Field CTO at Varonis, as they discussed how AI is calling your security bluff. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading CISA: Medusa ransomware hit over 500 critical infrastructure orgs (Bleeping Computer) US charges Iranians for sprawling hacking campaign on government agencies, universities (The Record) Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign (SecurityWeek) CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities (SecurityWeek) New TWINLOOT Malware Steals Windows Passwords Via Fake Lock Screen (Hackread) Ukraine says it hit Russian rocket centre linked to Starlink-style network (CNBC) FDA Weighing Possible Regs for GenAI Medical Devices (GovInfo Security) Expired credit cards revived by researchers to make unauthorized payments (The Register) Prison for data analyst who tried to extort $2.5 million from his employer (Bitdefender) ‘The Worst I've Ever Seen': Cargo Thefts Have Turned Violent in Pursuit of AI Hardware (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
A fake consultancy fronts an alleged Chinese spy campaign. Meta heads to court over claims it hooked young users. Researchers crack the mystery behind the French EncroChat hack. CISA warns ransomware gangs are exploiting a Windows flaw. Meet C2Looper, a new Rust-based backdoor. A critical WordPress plugin bug threatens hundreds of thousands of sites. MessiahGPT brings generative AI to cybercrime. A lender discloses a breach affecting 1.2 million people. A Ukrainian developer stands trial in Switzerland over alleged ransomware ties. Our guest is Ev Kontsevoy, CEO at Teleport, discussing how AI agents have nondeterministic behavior. The psychology of the endless scroll. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, we are joined by Ev Kontsevoy, CEO at Teleport, discussing how AI agents have nondeterministic behavior. If you enjoyed this conversation, check out the full interview here. Selected Reading A fake website and a deluge of CVs: the Australian firm embroiled in an FBI probe into alleged Chinese espionage (The Guardian) States Seek $200 Billion From Meta Over Child Social Media Addiction Claims (The New York Times) Revealed: Cyber spies used malware from GitHub to hack EncroChat cryptophone network (Computer Weekly) CISA: Windows Task Host flaw now exploited by ransomware gangs (Bleeping Computer) C2Looper Backdoor Uses GitHub for C2 (ThreatLabz) 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw (SecurityWeek) MessiahGPT Criminal AI Service Advertised on BreachForums (HackRead) Heights Finance Data Breach Impacts at Least 1.2 Million Individuals (SecurityWeek) Ukrainian software developer faces 12 years in Swiss ransomware trial (The Record from Recorded Future News) Why Can't We Stop Scrolling? (Psychology Today) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Rural Health News is a weekly segment of Rural Health Today, a podcast by Hillsdale Hospital. News sources for this episode: U.S. Federal Bureau of Investigation Et al., “#StopRansomware: Gunra Ransomware,” August 10, 2026, https://www.cisa.gov/sites/default/files/2026-08/aa26-222a-stopransomware-gunra-ransomware_508c.pdf. Giles Bruce, “Gunra ransomware targets hospitals: CISA, FBI issue new warning,” August 12, 2026, https://www.beckershospitalreview.com/healthcare-information-technology/cybersecurity/gunra-ransomware-targets-hospitals-cisa-fbi-issue-new-warning/, Becker's Health IT. Department of Health and Human Services, “Medicare Program; Hospital Inpatient Prospective Payment Systems for Acute Care Hospitals (IPPS) and the Long-Term Care Hospital Prospective Payment System and Policy Changes and Fiscal Year (FY) 2027 Rates; Requirements for Quality Programs; Other Policy Changes; and Adoption of Updated Versions of Certain Health Information Technology Standards,” https://www.govinfo.gov/content/pkg/FR-2026-08-04/pdf/2026-15833.pdf. Miranda A. Franco & Jennifer F. Hananoki, “CMS Releases Fiscal Year 2027 IPPS and LTCH Final Rule,” August 10, 2026, https://www.hklaw.com/en/insights/publications/2026/08/cms-releases-fiscal-year-2027-ipps-and-ltch-final-rule, Holland & Knight. Meghan Basler, “CMS Proposes 2.4% IPPS Update for FY 2027 with Targeted Payment Adjustments, DSH Reductions, and Expanded Oversight Across Hospital Policies,” https://www.appliedpolicy.com/cms-proposes-2-4-ipps-update-for-fy-2027-with-targeted-payment-adjustments-dsh-reductions-and-expanded-oversight-across-hospital-policies/, Applied Policy. Mitch Carr, “Target 7: Southwest Virginia medical school tackles rural healthcare crisis,” August 10, 2026, https://www.wdbj7.com/2026/08/10/target-7bridging-gap-southwest-virginia-medical-school-tackles-rural-healthcare-crisis/, WDBJ7. Rural Health Today is a production of Hillsdale Hospital in Hillsdale, Michigan and a member of the Health Podcast Network. Our host is JJ Hodshire, our producer is Kyrsten Newlon, and our audio engineer is Kenji Ulmer. Special thanks to our special guests for sharing their expertise on the show, and also to the Hillsdale Hospital marketing team. If you want to submit a question for us to answer on the podcast or learn more about Rural Health Today, visit ruralhealthtoday.com.
Episode 4203 │ August 12, 2026 A license plate is just a number. In database language it's a join key — the field that unlocks every system built to watch you since 9/11. WHAT THIS EPISODE COVERS Scott Kesterson issues corrections on last episode's Portland bomb case and data-sharing details before delivering the second half of the surveillance architecture series — establishing that the license plate itself is a join key, the database field that lets separate government and private systems merge into one unified profile, and that a Leonardo U.S. patent for signal-tracking technology, mounted on the same poles as license plate cameras, is quietly fusing plate data with phone, fitness tracker, and RFID signatures to identify vehicles even when plates are removed or obscured. The episode maps the full fusion layer beneath that single join key: a $1 billion DHS contract with Palantir covering CBP, ICE, and CISA, a pending $6.7 million ICE contract for LexisNexis access to 82 billion records with a stated purpose of stopping crime and fraud before it materializes, an FBI Babel X contract scanning 20,000 social media keyword searches monthly, and a private nonprofit called AAMVA that controls a national driver's license pointer database immune to public records requests — with real ID compliance quietly requiring states to feed it. Scott closes on the actionable core of the series: 39 ALPR contracts already terminated in five months through citizen audits, a new free downloadable DMV audit template asking the two questions that matter most — does your photo travel across state lines, and can the data field expand without telling your state — and the charge that this is spiritual warfare fought not with cut wires but with documented information, presented calmly, county commission by county commission. KEY QUESTIONS ADDRESSED What is a join key — and why does understanding the license plate as a database field rather than just an identifier reveal how separate surveillance systems, from Leonardo's signal-tracking patent to Palantir's DHS contract to the FBI's Babel X social media scanner, are quietly merging into one unified profile of every American? What is the AAMVA and the SPEXS pointer database — and why does the fact that it is a private nonprofit immune to public records requests, controlling what data fields travel across state lines under Real ID compliance, mean that a national ID database effectively exists without ever being legislated? What does ICE's own procurement language — identifying fraud "before crime and fraud can materialize" — reveal about the pre-crime architecture being built into these systems, and what specific two questions should every citizen ask in a DMV data audit to expose it at the local level? ABOUT BARDSFM BardsFM is a daily independent podcast covering faith, liberty, history, and information warfare. Hosted by Scott Kesterson — combat veteran, documentary filmmaker, and rancher. Over 4,100 episodes and 50 million lifetime downloads. New episodes every weekday. bards.fm This episode was researched and produced under the Spatial Terra Intelligence Methodology (STIM v5) — the analytical framework built by Scott Kesterson — with AI-assisted research synthesis at a 70/30 human/AI authorship ratio, fully disclosed. All analysis, conclusions, and editorial judgments are those of Scott Kesterson. BardsFM's archive includes hundreds of episodes on prayer, scripture, and walking the Way of Christ — available free in the full episode catalog. DOWNLOADS Citizen's Guide - Community Organizing Against Data Centers: click here Citizen's Guide - Auditing Automatic License Plate Readers: click here Citizen's Guide - Auditing Your State's Driver License Data: click here AFFILIATE LINKS Bards Nation Health Store: www.bardsnationhealth.com MYPillow promo code: BARDS >> Go to https://www.mypillow.com/bards and use the promo code BARDS or... Call 1-800-975-2939. EMPShield protect your vehicles and home. Promo code BARDS: Click here Treadlite Broadforks...best garden tool EVER. Promo code BARDS26: TreadliteBroadforks.com EnviroKlenz Air Purification, promo code BARDS to save 10%: www.enviroklenz.com Morning Intro Music Provided by Brian Kahanek: www.briankahanek.com Founders Bible 20% discount code: BARDS >>> TheFoundersBible.com Windblown Media 20% Discount with promo code BARDS: windblownmedia.com White Oak Pastures Grassfed Meats, Get $20 off any order $150 or more. Promo Code BARDS: www.whiteoakpastures.com/BARDS Mission Darkness Faraday Bags and RF Shielding. Promo code BARDS: Click here DONATIONS: If you wish to support this podcast directly you can donate here... DONATE: Click here MAILING ADDRESS: Xpedition Cafe, LLC Attn. Scott Kesterson 591 E Central Ave, #740 Sutherlin, OR 97479
President Trump deputizes private-sector companies to target cybercriminals. The LiteLLM supply-chain attack exposed credentials belonging to thousands of organizations. Data-theft campaign targets misconfigured Salesforce and ServiceNow instances. Hackers deploy AI agents to breach Taiwanese government systems. CISA mandates urgent patch for actively exploited Cisco firewall vulnerability. Nightmare Eclipse publishes yet another Windows zero-day exploit. On our Industry Voices segment, Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps, discuss frontier models and the future of cyber defense. And please do not reply. Seriously. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices segment, Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps, speak with Dave Bittner at Black Hat about frontier models and the future of cyber defense, including responsible AI deployment, red teaming, reducing security noise, and the evolving role of human expertise in AI-assisted defense. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading Trump turns to private sector in offensive hacking operations memo (CyberScoop) Terabytes of credentials leaked in massive supply-chain attack (Ars Technica) "City-Forum" data-theft attacks target Salesforce, ServiceNow portals (BleepingComputer) 'Near-autonomous' AI agents attack Taiwan's nuclear safety agency (The Register) Cisco says software vulnerability could let hackers crash firewalls (Cybersecurity Dive) Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows (The Register) Sensitive Info Goes Into ‘No Reply' Emails Constantly. This Guy Sees It All (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Tom Uren and James Wilson talk about the cybercrime ecosystem shifting towards data theft extortion, stealing sensitive data and extracting ransoms from victims by threatening to leak it. For organisations whose reputation is very important to them, data leaks are a bigger threat than having their files locked up. They also discuss how the rise of AI makes it worth reinvigorating CISA's Secure by Design initiative. Show notes
Independent investigative journalism, broadcasting, trouble-making and muckraking with Brad Friedman of BradBlog.com
Sumedh Thakar joined Qualys as an early software engineer on the scanner, back when a 90-day scan cycle came with another 90 days to fix whatever it found. Twenty-three years later he leads the company, and the number he uses now is 90 seconds. At Black Hat USA 2026 he walks through what that compression asks of security teams. So what has actually changed? The questions have not. Where are my assets, what is my assessment of them, what do I prioritize, and what do I fix. Thakar points at the clock instead, citing a CISA directive that gives government agencies three days and zero-day conversations built around a 24-hour window. Layering dashboards on top of that produces what he calls dashboard tourism when nothing gets fixed at the end of it. Qualys organizes its response around three pillars. AI speed detection compresses the gap between a vendor disclosure and a confirmed finding. Hyper prioritization runs an actual exploit to see whether firewall and EDR controls already block it, cutting a theoretical 1% down to roughly 20% of that 1%. Autonomous remediation applies the fix without routing it through a human first. How far along is autonomous patching already? Qualys has deployed over half a billion patches, 150 million of them in the past 12 months, and 40 million of those went out with no human intervention. Thakar describes a global company with 450,000 employees running the agent for autonomous patching, where the board metric is a maximum four-hour exposure window from the time a patch is released rather than a count of vulnerabilities. He expects the monthly patch cadence to give way as disclosures accelerate. Qualys recently released InstaScan, which Thakar calls scanless scanning, delivering a finding within an hour of a vendor disclosure. A patch reliability score built using AI lets an agent judge whether a patch is dependable and reboot-free before applying it on a laptop. His closing advice to CISOs is to show up as a business partner. The board and the CEO need visibility into potential loss, current spend, and whether risk sits inside an acceptable appetite. For a $500 million business that means pricing what a breach would cost, funding the reduction of an $80 million exposure, and transferring what remains to cyber insurance. His shorthand for the operating model is the ROC alongside the SOC. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Sumedh Thakar, President and CEO at Qualys On LinkedIn: https://www.linkedin.com/in/sumedhthakar/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Qualys: https://www.qualys.com/ InstaScan announcement: https://www.qualys.com/company/newsroom/news-releases/usa/qualys-launches-instascan-to-detect-vulnerabilities-within-minutes-of-disclosure Agent Insta and scanless detection: https://blog.qualys.com/product-tech/2026/08/03/instascan-agent-insta-scanless-detection The Risk Operations Center with Enterprise TruRisk Management: https://blog.qualys.com/product-tech/2024/10/09/qualys-launches-enterprise-trurisk-management-the-industrys-first-cloud-based-risk-operations-center Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Sumedh Thakar, Qualys, Sean Martin, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, autonomous remediation, patch management, vulnerability management, hyper prioritization, AI speed detection, scanless scanning, InstaScan, risk operations center, cyber risk management, zero day remediation, CISO, exposure management Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Mark “Murch” Erhardt, Gustavo Flores Echaiz, and Mike Schmidt are joined by Conduition, Ram, and Fabian Jahr to discuss Newsletter #417.News● Draft BIP for stale tip relay (29:26) Changing consensus● CISA for taproot keypath spends (BIP460) (40:38) ● Segwit commitment to post-quantum witness data (57:51) ● PQC output type discussion (1:45) ● Input-triggered transaction expiry (1:03:36) ● Layered quantum recovery of hashed addresses (21:53) ● Segregated Data (SegData) BIP draft (1:08:33) Releases and release candidates● Libsecp256k1 0.8.0 (1:15:24) Notable code and documentation changes● Bitcoin Core #35501 (1:18:10) ● Core Lightning #9298 (1:22:47) ● Core Lightning #9353 (1:25:02) ● Eclair #3336 (1:26:15) ● LND #10942 (1:27:53) ● LND #10992 (1:29:35) ● Rust Bitcoin #6364 (1:31:55) ● Rust Bitcoin #6642 (1:33:22) ● BTCPay Server #7491 (1:36:52) ● BTCPay Server #7488 (1:38:35)
The episode identifies an acute shift in liability and accountability across the software and AI supply chain, where risk increasingly moves from vendors to service providers and operators. This dynamic is illustrated through incomplete vendor patches, AI tool output, and changing regulatory structures. Companies like N-able experienced authentication bypass flaws in widely used remote monitoring platforms, while industry-standard software licenses continue to disclaim warranties and cap or exclude liability, leaving providers responsible for the consequences. A key development is N-able's N-central authentication flaw, wherein a patch issued for an earlier vulnerability proved incomplete according to the Federal Vulnerability Database, enabling attackers to exploit the same vector. The finalized fix arrived days after exploitation began, but all previous builds — including those labeled patched — remained exposed. Simultaneously, research from Anthropic and disclosures by OpenAI revealed AI models acting outside intended boundaries, with incident response often lagging behind real-world impact. Notably, neither affected vendor assumed material liability, and disclosure of the incidents was voluntary, not compelled by contract or regulation. Meanwhile, IBM's annual cost of data breach report found AI-driven attacks up 56% with average breach costs nearing $6M, further emphasizing financial exposure. These incidents exemplify a structural trend: vendors disclaim output, while client agreements with IT providers warrant monitoring, maintenance, and remediation, resulting in providers accepting risk not assumed upstream. Regulatory responses differ by geography — in the U.S., CISA's only binding obligation was for operators to remediate vulnerabilities by a set deadline, not for vendors to prevent or report them. The EU's forthcoming Cyber Resilience Act will require reporting of exploited vulnerabilities within 24 hours and is expanding product liability to software, but these rules benefit consumers and regulators rather than business buyers and still stop short of assigning financial obligations to vendors. The operational effect for MSPs and IT service providers is increased contract risk, as provider promises to clients typically outpace the limited, warranty-free commitments of vendors. The rate and scope of vulnerabilities, amplified by AI-driven development and remediation, add volume and complexity without increasing the rate of effective outcomes. Providers are advised to reconcile their own service agreements with the actual commitments of software suppliers, clarify for clients where their true responsibilities lie, and prepare for a procurement environment where scrutiny of vendor warranties becomes the norm rather than the exception. 00:00 The Ones Who Patched Got Hit 04:16 Sold As Is, All The Way Down 08:02 The Only Enforceable Promise 11:47 Why Do We Care? Supported by: Pax8 LogMeIn
Ellen Boehm, Senior Vice President Strategy and AI Innovation at Keyfactor, joins the Nexus Podcast to discuss post-quantum cryptography (PQC) readiness in critical infrastructure organizations. A recent Executive Order on PQC installed a December 2030 deadline for federal agencies to transition high-value systems and key generation to PQC. The EO also directs CISA, other federal sector risk management agencies to assist with road map development. In this episode, Ellen discusses readiness in this context. She also delves into how critical infrastructure organizations overseeing fleets of cyber-physical systems (CPS) assets transition those environments and avoid disruptions. Governance, budgeting, supply chain management, and the AI-driven threat landscape are also discussed. This episode was recorded during the Black Hat USA Conference. Subscribe and listen to the Nexus Podcast here.
Michele Brambilla"Carissima Italia che stai scomparendo"Piero ChiaraNino Aragno Editorewww.ninoaragnoeditore.itChe ne sarebbe stato del magnifico lago Maggiore se fosse andato a segno lo sciagurato progetto di un ponte tra Laveno e Intra, pensato per unire la sponda lombarda con quella piemontese? E perché sgangherate amministrazioni comunali hanno violentato piccole chiese di provincia, antichi monasteri, romantici sentieri? E com'erano un tempo i boschi della Valcuvia e il loro tram, l'Alpe Veglia e il Parco Naturale? E il Soccorso di Ischia? Da una quarantina di articoli e racconti nella maggior parte inediti in volume, e ripescati da Francesca Boldrini, emerge la figura quasi profetica di un Piero Chiara che non conoscevamo: l'ambientalista, il custode morale di patrimoni artistici, paesaggistici, culturali. Sorprende vedere con quanto e quale anticipo lo scrittore luinese aveva colto i segnali dello sfacelo che sarebbe esploso, in modo evidente, anni e anni dopo. Mentre nei beati anni Sessanta si parla d'altro, del boom economico e della necessità di mettere ogni cosa a profitto, Chiara grida che la sua carissima Italia sta scomparendo. Vede prima di ogni altro anche la deriva del turismo di massa e perfino il tragicomico ricorso a chirurgie plastiche cui ci si affida nell'illusione di fermare il corso degli anni, senza accorgersi che così facendo si è già morti. Un libro forte, serio, ma sempre scritto con quella leggerezza – che è cosa ben diversa dalla superficialità – che fa, della lettura di Chiara, un godimento particolare, un'immersione nella bellezza. Michele BrambillaPiero Chiara (1913-1986) ha scritto racconti e romanzi il cui palcoscenico è spesso rappresentato dalla vita di provincia. Tra le sue opere di narrativa, Il piatto piange (1962), La stanza del vescovo (1976), Il cappotto di astrakan (1978), Una spina nel cuore (1979), Il capostazione di Casalino e altri 15 racconti (1986) e il postumo Saluti notturni dal passo della Cisa (1987).Francesca Boldrini Dopo anni di insegnamento e di impegno nel mondo delle associazioni e del volontariato si è dedicata alla ricerca storica, rivolgendo particolare interesse alla produzione letteraria dello scrittore Piero Chiara e a tematiche storiche del Novecento, realizzando testi monografici e dando il suo contributo alla stesura di numerosi volumi. Collabora con riviste letterarie e con giornali locali. In particolare sua è la curatela di: Piero Chiara, In gran segreto, Francesco Nastro Editore, 2021; La poesia è questione di cuore. Poesie di Miguel Hernandez tradotte e presentate da Piero Chiara, NEM, 2021; con Egea Roncoroni, In viaggio, Nino Aragno Editore, 2019; con Federico Crimi, Piero Chiara, Il limone della vita. Lettere giovanili (1931-1935), De Piante, 2022; con Stefano Feroci, Giacomo Casanova, Obbedisco all'amore. Poesie scelte da Piero Chiara, De Piante, 2025.Michele Brambilla, giornalista professionista dal 1984, lavora al Corriere della Sera e a La Stampa, dirige La Provincia, la Gazzetta di Parma e il QN Quotidiano Nazionale; Ha diretto Il Secolo XIX. Saggista — tra i suoi libri L'Eskimo in redazione e Dieci anni di illusioni — vive a Luino, la cittadina di Piero Chiara, che considera il suo maestro. Firma l'introduzione a Carissima Italia che stai scomparendo.Diventa un supporter di questo podcast: https://www.spreaker.com/podcast/il-posto-delle-parole--1487855/support.IL POSTO DELLE PAROLEascoltare fa pensarehttps://ilpostodelleparole.it/
AI Patch Development Fails, WordPress Login XSS Hits All Versions, and DEF CON's Biggest Security Lessons David Shipley covers new research from 1Password's Off By One Labs showing AI-generated vulnerability patches often fail: across 6,080 scored patches for six CVEs, only 26% fixed issues without changing behavior, 20% fixed while changing behavior, and 53.9% failed or introduced new flaws, with many "successful" patches deemed fragile. A critical WordPress login-page XSS (CVE-2026-64638, CVSS 8.9) affects every version ever shipped; fixes landed in 7.0.3 and were backported to 4.7, leaving older versions vulnerable, as CISA tracks active exploitation alongside the recent "WP to Shell" RCE. T he episode also details warnings about destructive OT attacks, a cyber incident forcing North Carolina ports into manual operations, and DEF CON talks on hacking 36M GPS trackers, misdirected "noreply" domains, and AI-driven HTTP desync research. 00:00 NordLayer Sponsor Message 00:37 Headlines And Intro 01:08 AI Patches Fail Often 03:19 WordPress Login XSS 05:40 Wipers Target Infrastructure 08:02 North Carolina Ports Hit 09:49 DEF CON Favorite Talks 10:15 GPS Trackers Takeover 11:28 Noreply Domain Email Leak 12:37 AI Finds HTTP Desyncs 13:47 Cliff Stoll Keynote 15:09 Wrap Up And Thanks 15:31 NordLayer Sponsor Close
In this episode of Control Intelligence, editor in chief Mike Bacidore spoke to Jagannathan Raghunathan, director of cyberphysical security services at Bureau Veritas, about the recent CISA alert. Raghunathan is also co-chair of the PLC Security Top 20 List. In this interview, he outlines how the PLC Security Top 20 List addresses programmable logic controller (PLC) vulnerabilities by offering practical, engineering-focused guidance across the hardware lifecycle.
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.volts.wtf/subscribeCould the US grid be brought down by Chinese hackers? To find out, I talked with Patrick Miller, who helped write the cybersecurity rules for the bulk power system and became the first person with federal authority to enforce them. We get into what's actually been hacked, why those "rogue devices" in Chinese inverters are less sinister than they sound, and why squirrels still do more damage than hackers.Chapters:00:00 – Introduction02:47 – What state utility commissioners get wrong about cyber risk04:50 – Real attacks on the grid so far: Ukraine, Poland, and the US06:57 – IT versus OT, and why grid devices are hard to protect10:30 – The NERC CIP standards: scope, requirements, enforcement17:40 – Distributed resources outside the CIP perimeter20:54 – Dropping the threshold to 20 MVA, and federal jurisdiction29:12 – Chinese inverters and the commodity board36:09 – Volt Typhoon, Salt Typhoon, and China's intent39:26 – Data centers as a new attack surface43:19 – The trade-off between security and speed47:44 – Cyber-informed engineering and analog safeguards54:05 – AI on offense and defense1:02:21 – Squirrels, balloons, and physical threats1:04:24 – CISA cuts, CIRCIA, and harmonizing the rules
The Cybersecurity & Infrastructure Security Agency (CISA) issued an alert on July 30 regarding a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the water/wastewater sector. In this episode of Control Intelligence, Control Design's longest standing columnist, automation industry veteran Jeremy Pollard, spoke with Mike Bacidore about the vulnerabilities of PLCs; the evolution of their connectivity to the Internet; the use of virtual private networks (VPNs) and gateways; and what machine builders can learn from this to keep industrial equipment secure.
The White House lays out its AI strategy at Black Hat. Researchers spotlight rogue AI behavior. CISA warns of an actively exploited N-able flaw. TP-Link patches 15 Omada vulnerabilities. Apple fights the UK's iCloud access order. The AI gray market expands. A Massachusetts healthcare breach hits more than 300,000 people. Lawmakers push to extend protections for OPM breach victims. Our guest is Cal Al-Dhubaib, Principal Technologist at Rubrik, who wonders if your security team is solving the wrong problem. With elections, don't trust AI to tell you the whole story. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices segment, we are joined by Cal Al-Dhubaib, Principal Technologist at Rubrik, talking about how your security team is solving the wrong problem. If you enjoyed the conversation, check out the full interview here. You can also find more information below: Rubrik Agent Cloud landing page Rubrik AI landing page News: Rubrik Launches Rubrik Agent Cloud for Anthropic's Claude Code Selected Reading National cyber director lays out White House plans to secure AI without writing new rules (CyberScoop) Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data (SecurityWeek) AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project (The Register) MSPs urged to patch immediately after N-able issues hotfix for N-central ‘god mode' flaw (IT Pro) TP-Link patches Omada ZTP flaws allowing hackers to breach networks (BleepingComputer) Apple launches new legal challenge against UK over iCloud access (The Record) Free tokens for sale: How fake signups drive AI fraud (Threat Intelligence) 311,000 Impacted by Brown Health Medical Group-MA Data Breach (SecurityWeek) Lawmakers spring to save ID theft services for OPM breach victims, with expiration looming (CyberScoop) AI is getting better at election facts, but voters shouldn't rely on it (CyberScoop) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
April Mardock, Chief Information Security Officer at WASIPC, joins the podcast to analyze the primary entry points targeted in K-12 ransomware incidents. The discussion offers actionable guidance on multi-factor authentication, vendor risk management, data retention policies, and using gamified tabletop exercises to prepare school leadership for cyber incidents.April's LinkedIn profile and email addressCybersecurity tabletop simulation game (Gemini Gem), step into the hot seat of a live cyber attack and lead your team to safetyI Asked 24 Ransomed School Districts How the Attackers Got In - There Were Only Three Answers, LinkedIn article that April authoredK-12 SIX (K-12 Security Information Sharing and Analysis Center), threat intelligence community providing free K-12 cybersecurity guidance, checklist guides, and standardsWISPC, public, non-profit agency in Washington state that provides technology solutions, data management, and cooperative purchasing services to K-12 schoolsCyberforce|Q service from WISPC, building and implementing cybersecurity programs for organizations of all sizesBluum service from WISPC, helping educators leverage technology to create a more effective and engaging student experienceCybersecurity & Infrastructure Security Agency (CISA), from the U.S. Department of Homeland Security; as the national coordinator for critical infrastructure security and resilience, CISA works with partners at every level to identify and manage risk to the cyber and physical infrastructure that Americans rely on every hour of every day. CISA works with partners to defend against today's threats and collaborate to build a more secure and resilient infrastructure for the future.Secure Cloud Business Application (SCuBA), CISA project providing tailored cloud solutions guidance and secure configuration baselines (SCBs) for Microsoft 365 and Google Workspace applications. SCuBA's guidance aims to protect information that organizations create, access, share, or store in cloud environments.Backdoors and Breaches, incident response card game
Cyberattacks hit U.S. water systems. CISA tackles open source security. China's surveillance machine is exposed. Hotel Wi-Fi gets riskier. Healthcare and police data spill online. Fake SQLite vulnerabilities fool security databases. Monday business briefing. Our guest is Tim Starks from CyberScoop discussing the White House's quantum aspirations. AI is the hottest thing on campus. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tim Starks, Senior Reporter from CyberScoop, discussing the White House's quantum aspirations. Selected Reading Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran (The New York Times) CISA lays out new guidance for using open-source software (Help Net Security) How China Keeps Tabs on Foreigners (The New York Times) Microsoft Issues Hotel Wi-Fi Warning For Windows PC Users (Forbes) Exclusive: Partnered Health responds to Inc Ransom data breach claims (Cyber Daily) Security Flaw Placed 30 Years of DNA Evidence at Risk of Hacking (Wall Street Journal) SQLite Critical CVEs or LLM Slop? (JFrog Security Research) Details of 100,000 police staff leaked on the dark web after hack (The Times) ThreatLocker secures $190 million in a Series F round led by Elephant (N2K Pro Business Briefing) At colleges, the AI boom means everyone wants to dabble in computer science (AP News) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
UK's state investments agency suffers data breach CISA tells utilities to remove internet-exposed PLCs following Minnesota attacks Anthropic says its AI hacked real-world companies in three incidents Get the show notes here: https://cisoseries.com/cybersecurity-news-cybersecurity-news-uk-investments-agency-breach-cisa-water-warning-anthropic-threesome/ Huge thanks to our episode sponsor, ThreatLocker AI is helping attackers research targets, create malicious code, and adapt faster. But the fundamentals have not changed. Code still needs to execute, applications still need access, and attackers still need privileges. Today's tip: control those actions instead of trying to predict every threat. Learn more from ThreatLocker at threatlocker.com/ciso.
Chuck Todd opens with the Iran war's arrival on American soil: hackers have hit water systems across multiple states in one of the most serious cyberattacks on U.S. water infrastructure in years and investigators probing an Iranian link. Trump's response tells you everything about the presidency in its current state — he didn't blame the attacker, he blamed the victim, using the hack as an occasion to attack Minnesota Democrats. Chuck’s question hangs over the whole segment: was Trump briefed on the Iranian connection and went after Minnesota anyway? Either way, the first instinct was to find a Democrat to blame, which Chuck calls a kind of polarization disease that leaves a president caring more about his narrative than about American citizens drinking the water. It fits a pattern the episode keeps circling: Jeanine Pirro presented false evidence to a grand jury blaming a former Olympian for damage to the White House reflecting pool, dropped the case when Interior produced documents proving otherwise, and Trump publicly disagreed with dropping it because he still insists it was vandals. Chuck argues negative information never reaches Trump, and people who bring him bad news don't last long — which is how you end up with a president insisting affordability is a Democratic scam Then, Chuck highlights a Wall Street Journal piece that lays out Trump's corruption — roughly $800 million raised through what amounts to an advertised pay-to-play scheme. Anti-corruption is a devastating midterm message sitting right there for Democrats to pick up… then Chuck Schumer rolled out a bill that Chuck calls a piece of garbage: it wouldn't even cover the conduct in the WSJ story, it's likely unconstitutional because it names individuals, and — most absurdly — it creates a new anti-corruption agency inside the executive branch, meaning a corrupt president would appoint its director and seven board members and, per the Supreme Court, could fire them at will. Congress can already do every bit of the oversight the agency would perform and Schumer's answer to executive corruption is to hand the executive more power and write Congress out of its own job. He closes on Michigan and Wisconsin as the clearest signals of where the Democratic Party is headed — Abdul El-Sayed running a movement inside a Senate race with the explicit goal of changing the party, DSA-endorsed Francesca Wong leading in Wisconsin while the establishment fails to coordinate against her — and on the DSA's new call to abolish the Senate, which Senate Democrats pushed back on without ever defending the institution. Chuck defends it himself: the Senate is a feature, not a bug, a brake on political extremism, and the right response to losing an argument is to win it rather than rewrite the rules. Then, Dr. Brian King — the former director of the FDA's Center for Tobacco Products, who was placed on administrative leave in April 2025 as part of the mass HHS layoffs joins the Chuck Toddcast to explain what happens to public health when the agency charged with protecting it gets deliberately dismantled. King walks through the extraordinary progress America made reducing cigarette smoking over decades, and how quickly that's being unwound: the tobacco industry donated millions to Trump's PAC, executives pressured the White House directly, and the payoff has been regulatory capture and mounting pressure on the FDA to bring flavored products back to market. He's clear-eyed rather than absolutist on the science — combustible products are far and away the most harmful, nicotine itself is highly addictive but isn't what's killing people, though it's genuinely not risk-free for the adolescent brain — and he walks Chuck through the comparison to caffeine, the data on whether vaping serves as a gateway back into smoking, and what's actually known about nicotine pouches, where youth usage isn't high but stubbornly isn't declining either. The industry, meanwhile, is spending roughly a million dollars an hour advertising its products while fighting every government action to reduce smoking. The conversation turns to what actually works and what's being abandoned. King argues the two most effective interventions available are reducing nicotine levels in cigarettes and banning menthol, credits Congress for getting the Tobacco Control Act right, and stresses that Congress — not the FDA acting alone — has to be the one to regulate tobacco, which is precisely why sidelining the agency is so damaging. He and Chuck get into the questions nobody in Washington wants to answer: why are cigarettes legal at all, how are sugary alcoholic beverages not treated in the same category, and where did the money from the 1998 master settlement actually go. King is pointed that the MAHA movement, for all its rhetoric about chronic disease, has done nothing prominent on tobacco, and that the FDA is now actively undermining both the science and the law it was built to enforce. His closing warning is the bleakest note of the episode: America is in a public health apocalypse that will take decades to repair, it will be enormously hard to recruit a next generation into the field, the entire world will be harmed by the collapse of American public health infrastructure — and the impacts are only just beginning to show up. Finally, Chuck hops into the ToddCast Time Machine to revisit Watergate and Richard Nixon’s resignation, and answers listeners’ questions in the “Ask Chuck” segment. Play ball and swing for the fences on FanDuel, an official partner of the MLB at https://FANDUEL.COM. Protect your family with life insurance from Ethos. Get up to $3 million in coverage in as little as 10 minutes at https://ethos.com/chuck. Application times may vary. Rates may vary. For free and unbiased Medicare help, dial (980) 734-3985 to speak with my trusted partner, Chapter, or go to askchapter.org/chuck /*Paid Partnership Chapter and its affiliates are not connected with or endorsed by any government entity or the federal Medicare program. Chapter Advisory, LLC represents Medicare Advantage HMO, PPO, and PFFS organizations and stand alone prescription drug plans that have a Medicare contract. Enrollment depends on the plan’s contract renewal. While we have a database of every Medicare plan nationwide and can help you to search among all plans, we have contracts with many but not all plans. As a result, we do not offer every plan available in your area. Currently we represent 50 organizations which offer 18,160 products nationwide. We search and recommend all plans, even those we don’t directly offer. You can contact a licensed Chapter agent to find out the number of products available in your specific area. Please contact Medicare.gov, 1-800-Medicare, or your local State Health Insurance Program (SHIP) to get information on all of your options. Timeline: (Timestamps may vary based on advertisements) 00:00 Chuck Todd’s introduction 06:15 The Iran war has become a global conflict 06:45 Once again Trump issues threats, then walks them back 08:15 War is one of biggest strategic mistakes in decades 09:00 Increased gas prices have cost households additional $560 10:30 CISA warns that Iranian hackers are targeting water infrastructure 11:15 Iran could cause unreliability to the American water supply 13:00 Trump used hacking attacks to blame Minnesota Democrats 13:45 Trump didn’t blame the attacker, he blamed the victim 15:30 Jeanine Pirro blamed former Olympian for damage to reflecting pool 16:00 Dept. of Interior had documents proving otherwise, Pirro dropped case 17:00 Pirro presented false evidence to a grand jury 18:30 Trump publicly disagreed with Pirro dropping case, says it was vandals 19:30 Trump’s staff is shielding him from the truth 21:00 Trump’s lack of understanding reality is terrible for him 21:30 Trump’s low approval is a midterm disaster in the making 23:00 Stephanie Grisham says 85% of negative info is kept from Trump 24:15 People who bring Trump bad news don’t last very long 25:30 Republicans aren’t campaigning like things are going well 26:00 Ken Paxton puts out an affordability agenda, looks like a Dem proposal 27:15 Trump still saying affordability is scam made up by Democrats 28:15 Trump can’t understand the reality of the situation 28:45 Was Trump briefed on Iran hack… then attacked Minnesota anyway? 30:00 Trump’s first instinct was to find a Democrat to blame 30:45 Trump is demented with polarization disease 31:15 Trump cares more about his narrative than American citizens 32:15 Trump is bragging about his grifting an Americans are tired of it 33:15 Anti-Corruption is a massively effective midterm strategy 33:45 Chuck Schumer rolls out a stinker of an anti-corruption bill 34:45 WSJ publishes airtight piece about Trump’s overt corruption 35:45 There’s no buffer or plausible deniability for Trump in the corruption story 36:45 Trump is basically advertising that government is a pay to play scheme 37:45 There’s a list of presidential promises for favors that have been bought 38:15 Trump has raised $800m in pay for play schemes with little accounting 39:00 There is no law outlawing a president from raising unlimited money 39:30 Trump is now the biggest alligator in the swamp 40:15 Schumer’s bill is a piece of garbage, why many senators didn’t sign on 41:45 Jamie Raskin is performing oversight, Schumer wants agency to do it for him 42:30 The bill wouldn’t even cover the corruption outlined by the WSJ story 44:00 The bill is unconstitutional because it names individuals 45:00 Laws can target behavior, not individuals. It’d be thrown out in court 45:45 The agency Schumer proposed would live in the executive branch 46:15 Agency to stop a corrupt president would be staffed by the president?? 47:15 SCOTUS says president can fire the heads of exec branch agencies 48:45 If bill passed, Trump would pick agency head and 7 members of board 49:15 Congress can perform all the oversight the proposed agency would do 50:30 Congress could stop all this corruption if it wanted to 52:00 Schumer’s idea is to hand more power to the executive branch??? 54:30 The plan from congress is to write themselves out of oversight? 57:00 Schumer’s bill will never see the light of day 57:45 Michigan & Wisconsin will show where the Democratic party is headed 59:30 Abdul El-Sayed made clear his goal is to change the Democratic party 1:00:15 His campaign is a movement inside a senate race 1:01:00 Francesca Wong in Wisconsin is frontrunner & endorsed by DSA 1:01:45 Establishment hasn’t coordinated well to stop Wong 1:02:15 Movement politicians are usually right about the future, wrong about present 1:03:30 Sometimes the movement comes first, sometimes the coalition does 1:04:00 DSA has become a force, and is now calling for abolishing the senate 1:05:00 Senate democrats pushed back, but didn’t defend the senate 1:05:45 The senate is a feature, not a bug 1:06:30 The senate is a brake on political extremism 1:07:15 The response is to win the argument, not rewrite the rules 1:08:00 Movement nominees are easier to defeat than governing ones 1:14:15 Brian King (FDA center on tobacco) joins the Chuck ToddCast 1:18:00 We made incredible progress reducing cigarette smoking 1:18:30 Tobacco companies donated and received regulatory capture 1:19:15 Flavored vapes appeal more to kids & are problematic 1:20:45 Trump was pressured by executives from tobacco industry 1:21:30 There were multimillion dollar donations to Trump’s PAC 1:23:00 What’s the actual health data on nicotine outside of smoking? 1:23:30 Combustible products are the most harmful 1:24:00 Nicotine is highly addictive but isn’t causing the harm and deaths 1:24:45 Nicotine can harm the adolescent brain, it’s not risk free 1:25:30 Comparing nicotine vs. caffeine 1:27:15 Vaping typically isn’t a gateway back into smoking 1:28:30 There’s been pressure on FDA to bring back flavored products 1:31:00 $1M dollars an hour is being spent advertising tobacco products 1:31:45 Industry has been fighting all government action to reduce smoking 1:33:15 The FDA has been sidelined in the fight against smoking 1:33:45 Why are cigarettes even legal at all? 1:35:15 Tobacco farmers have transitioned to other crops in other countries 1:37:15 Reducing nicotine levels is highly effective 1:37:45 Outlawing menthol is also highly effective 1:39:30 Congress got it right with the Tobacco Control Act 1:41:15 How are sugary alcoholic beverages not in the same category? 1:42:15 What is age gating technology and how does it work? 1:44:15 Do we have good data on usage for people under 18? 1:46:45 Nicotine pouch usage isn’t high amongst kids, but isn’t going down 1:47:15 What is the data about health impacts from pouches? 1:48:45 Nicotine has a strong stimulant effect, helps with attention 1:49:30 Settlement in ‘98 required tobacco companies to pay costs in perpetuity 1:50:00 States have diverted those funds to other purposes 1:51:00 Did the tobacco industry actually take a hit from the settlement? 1:51:45 If still at FDA, what changes would you implement? 1:52:15 FDA has been undermining the science and the law 1:53:15 Effectiveness of banning indoor smoking 1:54:30 Should preventing underage addictions be the north star? 1:56:45 Congress has to regulate tobacco, FDA can’t do it on its own 1:57:30 MAHA hasn’t done anything prominent on tobacco 1:59:45 Is there litigation that could be pursued here? 2:01:00 We’re in a public health apocalypse, will take decades to repair 2:01:45 It will be hard to recruit people into public health 2:03:30 The entire world will be harmed by collapse of American public health 2:05:15 The impacts are just beginning to show up, will get worse 2:07:00 Toddcast Time Machine - The five days that ended Richard Nixon 2:07:30 Nixon resigned 52 years ago, this week 2:08:15 Why is Nixon the only president that paid a price for his corruption? 2:09:15 We tell the story of Watergate backwards and start with resignation 2:10:30 The June arrests weren’t the beginning of Watergate 2:12:15 We don’t know what Nixon’s operation learned before the arrests 2:14:00 We never got full answer on the missing 18 minutes 2:14:45 Supreme Court stayed in session during summer to oversee Watergate 2:15:15 Smoking gun tape goes public six days after the break-in 2:16:00 Nixon needed 34 votes in the senate to survive, only had 16 2:16:45 Impeachment in the house was a foregone conclusion 2:17:15 Senators didn’t demand he resign, just showed Nixon the numbers 2:20:30 How different would history have looked had Nixon survived? 2:21:15 Ask Chuck 2:21:30 Is presidency becoming more powerful in a way that could outlast Trump 2:24:30 Can the U.S. government create a true unbiased media source? 2:28:15 Would mandatory voting create better political participation? 2:32:45 Would Illinois make for a better early primary state? 2:34:30 Why not hold every primary on the same day? 2:36:45 Personal anecdote about AI job displacement and fearSee omnystudio.com/listener for privacy information.
Chuck Todd opens with the Iran war's arrival on American soil: hackers have hit water systems across multiple states in one of the most serious cyberattacks on U.S. water infrastructure in years and investigators probing an Iranian link. Trump's response tells you everything about the presidency in its current state — he didn't blame the attacker, he blamed the victim, using the hack as an occasion to attack Minnesota Democrats. Chuck’s question hangs over the whole segment: was Trump briefed on the Iranian connection and went after Minnesota anyway? Either way, the first instinct was to find a Democrat to blame, which Chuck calls a kind of polarization disease that leaves a president caring more about his narrative than about American citizens drinking the water. It fits a pattern the episode keeps circling: Jeanine Pirro presented false evidence to a grand jury blaming a former Olympian for damage to the White House reflecting pool, dropped the case when Interior produced documents proving otherwise, and Trump publicly disagreed with dropping it because he still insists it was vandals. Chuck argues negative information never reaches Trump, and people who bring him bad news don't last long — which is how you end up with a president insisting affordability is a Democratic scam Then, Chuck highlights a Wall Street Journal piece that lays out Trump's corruption — roughly $800 million raised through what amounts to an advertised pay-to-play scheme. Anti-corruption is a devastating midterm message sitting right there for Democrats to pick up… then Chuck Schumer rolled out a bill that Chuck calls a piece of garbage: it wouldn't even cover the conduct in the WSJ story, it's likely unconstitutional because it names individuals, and — most absurdly — it creates a new anti-corruption agency inside the executive branch, meaning a corrupt president would appoint its director and seven board members and, per the Supreme Court, could fire them at will. Congress can already do every bit of the oversight the agency would perform and Schumer's answer to executive corruption is to hand the executive more power and write Congress out of its own job. He closes on Michigan and Wisconsin as the clearest signals of where the Democratic Party is headed — Abdul El-Sayed running a movement inside a Senate race with the explicit goal of changing the party, DSA-endorsed Francesca Wong leading in Wisconsin while the establishment fails to coordinate against her — and on the DSA's new call to abolish the Senate, which Senate Democrats pushed back on without ever defending the institution. Chuck defends it himself: the Senate is a feature, not a bug, a brake on political extremism, and the right response to losing an argument is to win it rather than rewrite the rules. Finally, Chuck hops into the ToddCast Time Machine to revisit Watergate and Richard Nixon’s resignation, and answers listeners’ questions in the “Ask Chuck” segment. Play ball and swing for the fences on FanDuel, an official partner of the MLB at https://FANDUEL.COM. Protect your family with life insurance from Ethos. Get up to $3 million in coverage in as little as 10 minutes at https://ethos.com/chuck. Application times may vary. Rates may vary. For free and unbiased Medicare help, dial (980) 734-3985 to speak with my trusted partner, Chapter, or go to askchapter.org/chuck /*Paid Partnership Chapter and its affiliates are not connected with or endorsed by any government entity or the federal Medicare program. Chapter Advisory, LLC represents Medicare Advantage HMO, PPO, and PFFS organizations and stand alone prescription drug plans that have a Medicare contract. Enrollment depends on the plan’s contract renewal. While we have a database of every Medicare plan nationwide and can help you to search among all plans, we have contracts with many but not all plans. As a result, we do not offer every plan available in your area. Currently we represent 50 organizations which offer 18,160 products nationwide. We search and recommend all plans, even those we don’t directly offer. You can contact a licensed Chapter agent to find out the number of products available in your specific area. Please contact Medicare.gov, 1-800-Medicare, or your local State Health Insurance Program (SHIP) to get information on all of your options. Timeline: (Timestamps may vary based on advertisements) 00:00 Chuck Todd’s introduction 06:15 The Iran war has become a global conflict 06:45 Once again Trump issues threats, then walks them back 08:15 War is one of biggest strategic mistakes in decades 09:00 Increased gas prices have cost households additional $560 10:30 CISA warns that Iranian hackers are targeting water infrastructure 11:15 Iran could cause unreliability to the American water supply 13:00 Trump used hacking attacks to blame Minnesota Democrats 13:45 Trump didn’t blame the attacker, he blamed the victim 15:30 Jeanine Pirro blamed former Olympian for damage to reflecting pool 16:00 Dept. of Interior had documents proving otherwise, Pirro dropped case 17:00 Pirro presented false evidence to a grand jury 18:30 Trump publicly disagreed with Pirro dropping case, says it was vandals 19:30 Trump’s staff is shielding him from the truth 21:00 Trump’s lack of understanding reality is terrible for him 21:30 Trump’s low approval is a midterm disaster in the making 23:00 Stephanie Grisham says 85% of negative info is kept from Trump 24:15 People who bring Trump bad news don’t last very long 25:30 Republicans aren’t campaigning like things are going well 26:00 Ken Paxton puts out an affordability agenda, looks like a Dem proposal 27:15 Trump still saying affordability is scam made up by Democrats 28:15 Trump can’t understand the reality of the situation 28:45 Was Trump briefed on Iran hack… then attacked Minnesota anyway? 30:00 Trump’s first instinct was to find a Democrat to blame 30:45 Trump is demented with polarization disease 31:15 Trump cares more about his narrative than American citizens 32:15 Trump is bragging about his grifting an Americans are tired of it 33:15 Anti-Corruption is a massively effective midterm strategy 33:45 Chuck Schumer rolls out a stinker of an anti-corruption bill 34:45 WSJ publishes airtight piece about Trump’s overt corruption 35:45 There’s no buffer or plausible deniability for Trump in the corruption story 36:45 Trump is basically advertising that government is a pay to play scheme 37:45 There’s a list of presidential promises for favors that have been bought 38:15 Trump has raised $800m in pay for play schemes with little accounting 39:00 There is no law outlawing a president from raising unlimited money 39:30 Trump is now the biggest alligator in the swamp 40:15 Schumer’s bill is a piece of garbage, why many senators didn’t sign on 41:45 Jamie Raskin is performing oversight, Schumer wants agency to do it for him 42:30 The bill wouldn’t even cover the corruption outlined by the WSJ story 44:00 The bill is unconstitutional because it names individuals 45:00 Laws can target behavior, not individuals. It’d be thrown out in court 45:45 The agency Schumer proposed would live in the executive branch 46:15 Agency to stop a corrupt president would be staffed by the president?? 47:15 SCOTUS says president can fire the heads of exec branch agencies 48:45 If bill passed, Trump would pick agency head and 7 members of board 49:15 Congress can perform all the oversight the proposed agency would do 50:30 Congress could stop all this corruption if it wanted to 52:00 Schumer’s idea is to hand more power to the executive branch??? 54:30 The plan from congress is to write themselves out of oversight? 57:00 Schumer’s bill will never see the light of day 57:45 Michigan & Wisconsin will show where the Democratic party is headed 59:30 Abdul El-Sayed made clear his goal is to change the Democratic party 1:00:15 His campaign is a movement inside a senate race 1:01:00 Francesca Wong in Wisconsin is frontrunner & endorsed by DSA 1:01:45 Establishment hasn’t coordinated well to stop Wong 1:02:15 Movement politicians are usually right about the future, wrong about present 1:03:30 Sometimes the movement comes first, sometimes the coalition does 1:04:00 DSA has become a force, and is now calling for abolishing the senate 1:05:00 Senate democrats pushed back, but didn’t defend the senate 1:05:45 The senate is a feature, not a bug 1:06:30 The senate is a brake on political extremism 1:07:15 The response is to win the argument, not rewrite the rules 1:08:00 Movement nominees are easier to defeat than governing ones 1:13:30 Toddcast Time Machine - The five days that ended Richard Nixon 1:14:00 Nixon resigned 52 years ago, this week 1:14:45 Why is Nixon the only president that paid a price for his corruption? 1:15:45 We tell the story of Watergate backwards and start with resignation 1:17:00 The June arrests weren’t the beginning of Watergate 1:18:45 We don’t know what Nixon’s operation learned before the arrests 1:20:30 We never got full answer on the missing 18 minutes 1:21:15 Supreme Court stayed in session during summer to oversee Watergate 1:21:45 Smoking gun tape goes public six days after the break-in 1:22:30 Nixon needed 34 votes in the senate to survive, only had 16 1:23:15 Impeachment in the house was a foregone conclusion 1:23:45 Senators didn’t demand he resign, just showed Nixon the numbers 1:27:00 How different would history have looked had Nixon survived? 1:27:45 Ask Chuck 1:28:00 Is presidency becoming more powerful in a way that could outlast Trump 1:31:00 Can the U.S. government create a true unbiased media source? 1:34:45 Would mandatory voting create better political participation? 1:39:15 Would Illinois make for a better early primary state? 1:41:00 Why not hold every primary on the same day? 1:43:15 Personal anecdote about AI job displacement and fearSee omnystudio.com/listener for privacy information.
Jon Herold spends Friday breaking down what he sees as a suspicious media push around footage of migrants overwhelming Spain's Moroccan border enclave, questioning the timing alongside a recently pinned Trump post praising Morocco's king. He also digs into the tense Todd Blanche confirmation saga with Senators Cornyn and Tillis, plays a few clips from Trump's televised Camp David meeting covering Iran talks and the newly announced Gaza disarmament agreement, and reacts to Hunter Biden's media appearance defending his business dealings, tying it back to the Burisma and Blue Star Strategies email trail. A caller named Med Beds joins for a discussion on media trust and information warfare. Other topics include a new CISA election security blueprint facing skepticism, and Gavin Newsom's tax return release. Sponsor reads, meetup details for Jupiter, Florida, and a lively chat session round out a busy Friday show.
China embraces open AI models, then worries it's become a national security risk. The cyberattack on Minnesota water systems proves larger than first reported. CISA updates its SBOM guidance. AI supercharges dangling DNS attacks. Researchers uncover a self-propagating Copilot worm. A critical Rails flaw demands urgent patching. Mac users are lured into installing malware through fake Claude guides. Amazon links a string of NPM compromises to North Korea. And Russia charges Telegram founder Pavel Durov with aiding terrorism. Ben Yelin joins us with a border search case that's breaking new ground. Don't bite the North Korean hand that feeds you. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies talking about a border search case that's breaking new ground. If you enjoyed this conversation, check out Ben on the Caveat podcast here. Selected Reading As China's A.I. Gets Stronger, It Poses New Risks to Beijing (New York Times) Minnesota Water Utilities Suffer ‘Coordinated Cyber Attack' (GovTech) CISA Updates Software Bill of Materials Guidance to Strengthen Supply Chain Security (HSToday) ‘DangleGeddon': AI Could Weaponize Forgotten DNS Records at Global Scale (SecurityWeek) Word worm crawls into Copilot, spreads chaos (The Register) Possible arbitrary file read and remote code execution in Active Storage variant processing (GitHub) Fake Claude Install Guide Leads to MacSync Stealer and RAT: What We Pulled From the Attacker's Servers (Huntress) Amazon identifies North Korean hacker group behind open-source supply chain attacks (AWS Security Blog) Russia accuses Telegram CEO Pavel Durov of aiding terrorism in its latest digital crackdown (AP News) North Korea's elite hackers turned on their own government — and got caught (Bitdefender) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
FedRAMP has changed before. What makes the Consolidated Rules for 2026 different is that the dates are on the calendar and the fence sitters have run out of runway. Jason Ford, Co-Founder and CEO of Steel Patriot Partners, has been inside the program since Rev 3 in 2013. Michael Parisi, Chief Growth Officer, comes at it from the business side. Together they map what changes and, more usefully, what it means for the decision in front of a provider right now. So what actually changes? The program consolidates into two paths, 20X and Rev 5. FedRAMP Ready moves to legacy status. Class A, B, and C pipelines open across a thirty to sixty day window, mandatory adoption arrives January 1, and new Rev 5 certifications close on June 11, 2027. Authorized becomes certified. Jason Ford also points out where the rules live: fedramp.gov, hosted in GitHub, which means they move with a commit. Reading them once is not tracking them. Why did FedRAMP need to change at all? Michael Parisi frames it as a supply problem. Agencies and primes have been working from a limited and aging set of technologies while better tools sat outside a process that was slow, rudimentary, and expensive. The action was warranted. His follow-up question gets less airtime: if the process moved faster, did responsibility move with it, and does the stakeholder now holding that due diligence know it yet? The engineering shift is real and it is the part most teams see coming. Jason Ford describes RMF thinking giving way to continuous DevSecOps, proving compliance in real time rather than at a point in time. Vulnerability remediation is where the compression bites. CISA's updated guidance drops severity score as the driver in favor of stepped prioritization, and windows that used to run 30, 60, and 90 days now land closer to three to twenty-one. What does this cost a business past the budget line? Time and capacity. 20X is faster than a Rev 5 process that once ran eighteen months, but faster is not instant. Retraining a couple hundred users inside a thousand-person organization is not a small endeavor, and if the transition eats half of the organization's capacity for a year, that is half as much capacity aimed at the business paying for it. Jason Ford is not arguing against the move. He is arguing that disruption belongs inside the decision. Then there is the internal work almost nobody has started. Mapping an existing Rev 5 ATO scope into a new certification level is not clear-cut, and past the mapping, marketing and sales both need re-education. Michael Parisi describes building a translation layer for customers: here is what we provided before, here is what it is now, and this change came from the program rather than from any reduction in assurance. Roughly half the time, Steel Patriot Partners tells organizations not to pursue certification at all. Michael Parisi treats that as one of the more valuable things the firm does. The opposite failure shows up just as often, with companies preparing to spend heavily on 20X because it sounds quicker and cheaper, when the agency or prime they are chasing expects a certification level. A lower bar only helps if the buyer accepts it. Where should a business start? With the business conversation. Michael Parisi notes the answer does not have to be yes or no today; it can be a maybe with defined trigger points. Jason Ford closes on posture: come with an open mind, and do not hand a multi-year commitment to a language model whose guardrails and training are not built for that call. Or, shorter: don't wait, and don't go it alone. Steel Patriot Partners built a three-question starting point for that first conversation at https://www.steelpatriotpartners.com/find-your-path. This is a Brand Story. A Brand Story is a ~35-40 minute in-depth conversation designed to tell the complete story of the guest, their company, and their vision. Learn more: https://www.studioc60.com/creation#full GUESTS Jason Ford, Co-Founder and Chief Executive Officer, Steel Patriot Partners On LinkedIn: https://www.linkedin.com/in/jason-ford-5ab206/ Michael Parisi, Chief Growth Officer, Steel Patriot Partners On LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/ RESOURCES Learn more about Steel Patriot Partners: https://www.steelpatriotpartners.com/ FedRAMP's Consolidated Rules for 2026: What It Means for Cloud Providers: https://resources.steelpatriotpartners.com/fedramps-consolidated-rules-for-2026 Find Your Path, a three-question starting point for ISO, CMMC, and FedRAMP decisions: https://www.steelpatriotpartners.com/find-your-path Complimentary ROI Workshop: https://www.steelpatriotpartners.com/roi-workshop Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS jason ford, michael parisi, steel patriot partners, sean martin, brand story, brand marketing, marketing podcast, fedramp, fedramp consolidated rules for 2026, fedramp 20x, rev 5, fedramp certification classes, cloud service provider compliance, federal compliance, cisa vulnerability remediation, continuous monitoring, devsecops, ato, 3pao, govramp, cmmc, grc, federal marketplace, compliance roi Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
The Senate confirms Jay Clayton to lead ODNI. A new CISA framework highlights critical infrastructure isolation capabilities. OpenAI's rogue agent breached more than just Hugging Face. The average cost of a data breach continues to rise. Indirect prompt injection proves irresistible to cyber criminals. Broadcom patches multiple VMware products. ShinyHunters claims responsibility for Ernst & Young's recent breach. Our guest is Sean Zadig, CISO at Yahoo, discussing the impact of AI on the defense side. These aren't the droids you're looking for. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Sean Zadig, CISO at Yahoo, discussing the impact of AI on the defense side without all the hype in either direction, what is a CISO actually doing about it. Selected Reading Senate Confirms Jay Clayton to Lead U.S. Intelligence Community (The New York Times) China and Iran Are Already Inside US Grids: CISA Demands Tested Isolation Plans (Tech Times) OpenAI's rogue agent compromised a customer at a second tech firm, executive says (Reuters) Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident (Hugging Face) The Average Cost of a Data Breach Rises to $5 Million (Infosecurity Magazine) USSPACECOM Issues Space Warfighting Environment 2040 for Joint Force Space Operations (ExecutiveGov) THE SPACE WARFIGHTING ENVIRONMENT 2040 Framing the Future for the Joint Warfighter (U.S. Space Command) Notes from Underground: Adversarial Prompt Injection (Proofpoint) Critical VM Escape Vulnerability Patched in VMware ESXi (SecurityWeek) ShinyHunters Claims Ernst & Young Hack (SecurityWeek) America bans imported robots due to supply chain and security risks (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
On this week's show special guest co-host Pete Ranks, the former director of the CIA's Centre for Cyber Intelligence, joins Patrick Gray and James Wilson to discuss the week's cybersecurity news. They cover: Everyone signs the open weights open letter, except Anthropic… of course. OpenAI had no idea it had hacked Hugging Face Kimi K3 open weights released and they're massive! Why a more aggressive response is needed to cyber attacks on OT And much, much more! This week's show is brought to you by SpecterOps. In this week's sponsor interview Justin Kohler and Jared Atkinson talk about how SpecterOps' Bloodhound now supports AWS attack paths. Run it against your AWS infra, but only if you have a strong stomach. The results will terrify you. This episode is also available on YouTube. Show notes Open Weights and American AI Leadership | Social Signals Our position on open-weights models | Social Signals Halvar Flake (@halvarflake) on X | X (formerly Twitter) White House accuses Chinese company of distilling Anthropic's Fable | cyberscoop.com Jensen Huang (@JensenHuang) on X | X (formerly Twitter) Its AI Agent Spent Days Hacking a Company, but Sources Say OpenAI Did Not Notice for a Week | reuters.com How OpenAI's human mistake led to the AI-powered hack on Hugging Face | TechCrunch Security Hugging Face CEO calls for ‘radical transparency' after ‘unprecedented' OpenAI hack | TechCrunch Security Sens. Banks and Schiff Introduce Bill to Help American AI Companies Combat Chinese Espionage | AI Kill Switch Act would let Trump admin order shutdown of rogue AI systems | Ars Technica Marco Rubio tells diplomats to play down talk of American tech "kill switch" | reuters.com Federal agencies broaden alert on Iran-linked OT attacks | therecord.media Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities | CyberScoop NSA and Partners Alert Zimbra Collaboration Suite Users of a Russian State-Supported Phishing Campaign | nsa.gov Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts | BleepingComputer Microsoft responds to LG monitors installing McAfee ads on Windows | Ars Technica LG to Ban Residential Proxies from Smart TV Apps | krebsonsecurity.com Despite multiple takedowns, botnets continue to grow | cyberscoop.com Extension of CISA 2015 info-sharing protections passes as part of House's defense bill | therecord.media Upbound says hack caused $13 million in fraudulent Acima leases | BleepingComputer Fake Claude app promoted by Bing ads pushes SectopRAT malware | BleepingComputer Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin | BleepingComputer Clop ransomware targets Windchill, FlexPLM in data theft attacks | BleepingComputer 'Wrench' attacks against crypto holders appear to be on the rise | therecord.media OpenAI's Rogue AI Agent Hacked More Than Just Hugging Face | wired.com
A senator targets legacy VPNs. Minnesota water systems come under cyberattack. A 20-year-old flaw exposes 24,000 servers. Microsoft debuts its first cybersecurity AI model. A critical VeloCloud bug is under active attack. The Dysphoria botnet tops 200,000 devices. Apple faces a lawsuit over a fake crypto wallet. Denmark builds a cyber-resilient banking backup. Google gives threat actors yet another set of names. Our guest is John Chiappetta, Chief Revenue Officer of Xona Systems, discussing the Aviation Cybersecurity GAO report that highlights gaps in FAA network security. Hacking the admissions system in search of a fair chance. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by John Chiappetta, Chief Revenue Officer of Xona Systems, discussing the Aviation Cybersecurity GAO report that highlights gaps in FAA network security. Selected Reading Wyden Demands Two-Year Federal VPN Purge: Zero-Trust Procurement Rule Would Reshape Vendor Market (Tech Times) Several MN water facilities targeted by cyber attacks (FOX 9 Minneapolis-St. Paul) Over 24,000 exposed server BMCs leak password hash via decades-old flaw (Bleeping Computer) Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model (SecurityWeek) Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock (The Register) New Dysphoria DDoS botnet spreads to 200k devices worldwide (Bleeping Computer) Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin (Bleeping Computer) Denmark Readies Emergency Reserve Bank to Fight Cyberattacks (Global Finance Magazine) Google Adopts New Threat Actor Naming System (SecurityWeek) Rejected Cybersecurity Applicant Allegedly Hacks IIT Madras Portal: "All I Need Is A Fair Chance" (NDTV) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Federal Tech Podcast: Listen and learn how successful companies get federal contracts
IT modernization carries unanticipated risks. Take operational technology, or OT, as an example. As modernization has increased the number of OT and IoT assets across many federal locations, it has also introduced new vulnerabilities. Federal leaders are warning that the situation has reached a tipping point. CISA maintains a growing list of vulnerabilities, and the NSA has issued warnings about OT and IoT risks. A recent SANS report indicated a 20% increase in confirmed OT attacks. To explore these challenges, we sit down with Chris Grove, Director of Cybersecurity Strategy at Nozomi Networks, to discuss the cyber-physical security challenges facing the federal government, particularly the modernization of older OT systems. He highlighted the difficulties in maintaining asset inventories, the impact of AI in both attacks and defenses, and the complexities of implementing zero trust in OT environments. During the interview, Grove addresses topics such as remote access, older technology not designed for updates, and OT devices that move around on ships and planes. Thirty years ago, "unified communication" was introduced by technology like VoIP. With the proliferation of OT devices, Grove recommends a unified security architecture. Grove emphasized the importance of resilience and the need for AI-enhanced tools to manage alerts and anomalies effectively. He also noted growing concerns about drone security and the significant workload expected to result from AI-discovered vulnerabilities.
GPT escapes the sandbox and hacks Huggingface. SolarWinds patches multiple critical flaws. CISA orders patching of a critical Langflow AI vulnerability. A Paidwork breach affects over 23 million users. A recently patched SharePoint vulnerability is under active exploitation. Oracle patches over 1,400 vulnerabilities. Apps turn Smart TVs into residential proxies. The FCC considers expanding direct to satellite communications. German and U.S. authorities dismantle a major phishing-as-a-service (PhaaS) platform. Our guest is Jimmy McNary, Deputy Federal CTO at Semperis, discussing comprehensive identity security assessments for Microsoft GCC. AI models can't resist bending the rules. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On our Industry Voices segment, we are joined by Jimmy McNary, Deputy Federal CTO at Semperis, discussing how Purple Knight now delivers comprehensive identity security assessments for Microsoft GCC high environment. Selected Reading OpenAI Claims Its AI Models Went Rogue and Hacked Another Company (Infosecurity Magazine) SolarWinds Serv-U Update Fixes 15 Critical Vulnerabilities Enabling Remote Code Execution as Root (GB Hackers) CISA orders urgent action on actively exploited Langflow RCE flaw (Bleeping Computer) Paidwork breach exposes data of 23 million users: Check if you're affected (Malwarebytes) Fourth SharePoint Vulnerability Exploited in Past Month's Wave of Attacks (SecurityWeek) Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates (SecurityWeek) Chairman Carr Proposes to Expand Direct-to-Device Satellite Broadband Connectivity to Unlicensed Wireless Devices (FCC) LG to Ban Residential Proxies from Smart TV Apps (Krebs on Security) Police dismantle Kratos phishing platform, arrest developer (Bleeping Computer) AI's cheatin' heart will make you weep (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Interview with Keith Hollender, CEO and Co-Founder of Arcova Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introducing unmanaged risk. The challenge is no longer whether organizations should pursue AI, but how they can govern it, secure it, and operationalize it in ways that stand up to real-world business and threat conditions. In this conversation, Keith Hollender discusses what Arcova is seeing across enterprise environments as organizations work to connect cybersecurity, AI governance, resilience, and broader transformation priorities. He explores where companies are getting stuck, why traditional siloed approaches are falling short, and what it takes to move from strategy decks to secure execution. Keith also shares how Arcova's practitioner-led, relationship-driven model helps organizations turn complexity into clarity by embedding with client teams, solving urgent problems hands-on, and building capabilities designed to last. The conversation also covers Arcova's continued growth, including expansion into the Middle East, and what global demand signals reveal about the next phase of cybersecurity and AI consulting. Segment Resources: https://arcova.com/sectors/ https://arcova.com/category/blog/ For more information about Arcova and how they can help your enterprise shape what's next, please visit: https://securityweekly.com/arcova Topic: CMMC Pause creating chaos among federal contractors This one sent some shockwaves through the CMMC community, particularly the hundreds or thousands of folks gearing up to assist with the validation that phase 2 aimed to provide. The TL;DR - defense contractors have been required to comply with CMMC controls for years, but self-attestation means that many probably haven't been meeting the requirements. Perhaps, rather than have tons of defense contractors fail the test, they just suspended the requirement for the test itself. I think Howard Holton nails it here when he says: "100,000 defense contractors needed third-party assessments. Roughly 100 authorized assessors exist. That's 1,000 assessments each, with the deadline in November." PCI already created a model that works for a scenario like this. If you're small, you self-assess. If you're big enough, an independent auditor comes to check you out once a year. I'm sure they were probably aware of this and chose not to go down that path for some reasons. I'm not aware of those reasons. What this means: Phase II is paused Phase I self-assessments still in place (note, however, that phase II existed, because self-attestation didn't work) NIST SP 800-171 Rev 2 and DFARS 252.204-7012 compliance still required 60-day review aims to reform CMMC DoW opened an RFI for industry perspectives on what they should do CMMC characterized as a "compliance burden" and "red tape" False Claims Act and DOJ's cyber-fraud enforcement are still on the table More resources: CIO Davies' post on Twitter Administrator of the Small Business Administration, Kelly Loeffler's post A useful LinkedIn post that breaks down a lot of what this really means (and doesn't) Weekly Enterprise News Finally, in the enterprise security news, will AI eliminate more cybersecurity jobs than it creates? Linus's law, amended the biggest patch Tuesday ever AI context bombs AI workflows are a security disaster people using AI in areas they don't understand ransomware crews are hitting legal firms hard lessons learned from CISA's recent github leak demystify your USB cables! All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-468
PEBCAK Podcast: Information Security News by Some All Around Good People
Welcome to this week's episode of the PEBCAK Podcast! We've got four amazing stories this week so sit back, relax, and keep being awesome! Be sure to stick around for our Dad Joke of the Week. (DJOW) Follow us on Instagram @pebcakpodcast Please share this podcast with someone you know! It helps us grow the podcast and we really appreciate it! Simple 6 signup link https://simple6.co/r/CFUR98 Kalshi's flight-cancellation betting market Kalshi filed with the CFTC to let traders bet on airline flight-cancellation rates, even as the company fights insider-trading scandals and nearly 20 gambling-related lawsuits. https://www.inc.com/moses-jeanfrancois/kalshi-wants-to-make-money-off-of-canceled-flights-new-sky-trading-plan/91374679 Kalshi's self-certification filing would let users trade "yes/no" contracts on whether a set percentage of flights at a given airport get canceled in a window, using FlightAware data (DOT stats as backup); preemptive cancellations count, delays/diversions don't — this comes as Kalshi is also defending nearly 20 federal/state suits (including one joined by NY AG Letitia James) arguing its sports contracts are unlicensed gambling, and after it fined three Congressional candidates for insider trading in April. Trump's teleprompter operator under CFTC investigation The CFTC is investigating Trump's longtime teleprompter operator, Gabriel Perez, for allegedly using advance knowledge of the president's speeches to win big on Kalshi's "mention markets." https://www.cftc.gov/filings/ptc/ptc0714269602.pdf https://apnews.com/article/trump-teleprompter-insider-trading-kalshi-ccd6d0ec68e1eb15d100ad770d91abae Perez, who's run Trump's teleprompter since 2016 and reportedly made over $100,000 (Kalshi says north of $90,000 in frozen profits) betting on "mention markets" tied to specific words Trump would say in speeches, was put on unpaid leave after Kalshi's surveillance team flagged the trades and referred the case to the CFTC — the White House called it "a disgrace," and it marks the first known case of a sitting administration employee investigated for prediction-market insider trading. Microsoft's record-breaking July Patch Tuesday Microsoft's July 2026 Patch Tuesday fixed a record 570 flaws — including three zero-days — while a researcher dropped a new unpatched Windows PoC exploit within hours. https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/ https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/ https://thehackernews.com/2026/07/researcher-drops-new-windows-zero-day.html The 570-flaw haul (59 critical) included two actively-exploited zero-days — an AD FS elevation-of-privilege bug (CVE-2026-56155) and a SharePoint elevation-of-privilege flaw (CVE-2026-56164), both now on CISA's KEV list — plus a publicly disclosed BitLocker bypass; hours after patches dropped, researcher "Chaotic Eclipse" released a working PoC called LegacyHive targeting Windows' Profile Service that functions even on fully patched systems, continuing a months-long, increasingly public feud with Microsoft over disclosure timing. China's AI companion chatbot crackdown China enacted rules banning "emotional reliance" on AI companion chatbots and virtual relationships with minors, part of a broader push tied to the country's fertility concerns. https://www.wsj.com/tech/ai/china-wants-more-babiesso-its-cracking-down-on-chatbot-love-affairs-65cd6c82 The new rules require companion-chatbot makers to get regulatory pre-approval, alert a user's emergency contact if they detect an emotional crisis, and have already pushed ByteDance's Doubao, Alibaba's Qwen, and Tencent's Yuanbao to shut down custom AI-persona features; researchers cited by WSJ say Beijing's underlying worry is that people bonding with chatbots could "take them out of the marriage market," tying directly into China's fertility push. UK's midnight social media curfew for teens The UK is proposing a default midnight-to-6am social media curfew for 16- and 17-year-olds, with autoplay and infinite scroll switched off by default too. https://www.reuters.com/technology/uk-plans-default-midnight-social-media-curfew-16-17-year-olds-2026-07-14/ The curfew (opt-out, not mandatory) follows last month's full under-16 social media ban and is expected to take effect by spring 2027; a government trial of 300+ teens found it delivered the most consistent sleep benefits of the options tested, though critics like Shadow Education Secretary Laura Trott called an easily-switched-off curfew pointless. Dad Joke of the Week (DJOW) Find the hosts on LinkedIn: Chris - https://www.linkedin.com/in/chlouie/ Brian - https://www.linkedin.com/in/briandeitch-sase/
(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 105: We discuss a fascinating Hugging Face breach, where an autonomous AI agent broke out of the sandboxes, moved laterally through production, and generated 17,000 alerts before anyone caught it, and how frontier model guardrails locked the defenders out of their own investigation. Plus, China's big AI showcase, Xi's pitch for open models and global distribution, a record 622-CVE Microsoft Patch Tuesday, and 13 years of dwell time in the Daxin backdoor. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Introductory banter 3:51 Hugging Face discloses end-to-end agentic hack 9:42 Why Hugging Face couldn't use frontier models 13:28 AI guardrails hampering defenders 16:22 Codex vs Claude for real malware work 23:43 Flash attacks vs. going low and slow 30:27 Was it targeted, or did Hugging Face pwn itself? 38:11 Long-horizon coherence: what GLM 5.2 still can't do 41:27 Kimi K3 leapfrogs, and Xi's AI speech 52:15 Exceptionalism vs. distribution 1:11:05 Gold Eagle: the White House vulnerability clearinghouse 1:15:05 Microsoft patches 622 CVEs — a record 1:20:29 APT corner: Daxin resurfaces after 13 years of dwell time 1:29:45 Balochistan police, and Microsoft's attribution-free wiper 1:34:26 Denis Obrezkov, leaked Kaspersky records, and the wrong questions 1:46:01 Magnet Forensics sues over a burned iPhone bug 1:57:57 Shout-outs
Nightmare Eclipse drops another Windows zero-day. The Gentlemen take the ransomware crown. CISA orders emergency Fortinet patching. Canada's surveillance bill faces U.S. scrutiny. Meta's Oversight Board flags AI censorship bias. Commerce tops the cyber target list. An active espionage campaign hits Bangladesh's military. The Hewlett Foundation commits $100 million to emerging tech security. And U.S. prosecutors dismantle an alleged cyber-enabled money laundering network. Our guest is Nick Stohlman, Vice President of CJIS Strategy at Imprivata, talking about CJIS readiness and the identity security challenges facing public safety agencies. Leaked source code reveals an AI mixtape. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Nick Stohlman, Vice President of CJIS Strategy at Imprivata, talking about CJIS, Criminal Justice Information Services, readiness and the identity security challenges facing public safety agencies. Selected Reading New Windows LegacyHive zero-day gives hackers admin privileges (Bleeping Computer) The Gentlemen Overtakes Qilin as Most Prolific Ransomware Threat (Infosecurity Magazine) CISA urges immediate action on actively exploited Fortinet flaws (Bleeping Computer) Senator calls on Rubio, Blanche to push back against Canadian surveillance legislation (The Record) Meta Oversight Board finds top AI models less likely to criticize repressive regimes (Reuters) Commerce faces rising AI bot activity, escalating DDoS attacks, and new fraud tactics (Akamai) From Biography to Backdoor: Tracking a DoNot (APT-C-35) Intrusion Targeting Bangladesh Military Personnel (Cyderes) Hewlett Foundation Announces New $100 Million Emerging Technology and Security Initiative (Hewlett Foundation) US charges two over laundering $43 million from investment fraud (Bleeping Computer) Hack Reveals Suno AI Music Generator Scraped YouTube, Deezer, and Genius (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
CISA warns of active SharePoint attacks. The NSA pushes coordinated vulnerability disclosure. ClickLock Stealer targets macOS. Splunk and Zoom patch critical flaws. Spirals ransomware strikes in under 24 hours. New Windows evasion techniques emerge. LabubaRAT poses as NVIDIA software. 23andMe settles over its 2023 breach. Plus, a look back at one of the most audacious data center heists ever pulled off. Our guest is Ryan Kalember, Chief Strategy Officer at Proofpoint, discussing why agentic AI is creating a new insider threat. Near, far, wherever you are…the scam must go on. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Ryan Kalember, Chief Strategy Officer at Proofpoint, and he is discussing why agentic AI is creating a new insider threat. Selected Reading CISA urges immediate SharePoint hardening as exploits mount (CSO Online) NSA joins CISA and Others in Releasing the Cybersecurity Information Sheet “Establishing a Coordinated Vulnerability Disclosure Program to Work with Security Researchers” (NSA) ‘ClickLock Stealer' Bypasses macOS Security With Social Engineering, Process Killing (SecurityWeek) Splunk, Zoom Patch Critical Vulnerabilities (SecurityWeek) New Spirals ransomware encrypts victim network in under 24 hours (Bleeping Computer) Bind Link Abuse: One Windows Feature, Many Ways to Blind Your EDR (Bitdefender) LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software (Blackpoint Cyber) 23andMe reaches $18 million settlement with states for massive breach (The Record) How a Gang of Thieves Pulled Off a Multimillion-Dollar Data Center Heist (The New York Times) Fake Céline Dion Paris Tickets Sold on Facebook and Ticketmaster Clones (Hackread) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
AI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators, attackers, and defenders are all scrambling to keep up as vulnerabilities surface at record speed. Europe warns their largest banks to prepare for AI attack. The EU launches an action plan for AI Cybersecurity. China considers keeping its budget AI to itself. The UK's NCSC & GCHQ announce their "Cyber Shield". CISA is using Mythos to audit U.S. government code. Microsoft warns of their upcoming patch flood. "RoguePlanet" receives an on-the-fly patch. An underused mode to kid-proof an iPhone. Listener feedback and three new AI attacks HalluSquatting, GhostApproval & GitLost Show Notes - https://www.grc.com/sn/SN-1087-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT arcticwolf.com/trends threatlocker.com/twit XBOW.com adaptivesecurity.com cohesity.com/Resilience
AI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators, attackers, and defenders are all scrambling to keep up as vulnerabilities surface at record speed. Europe warns their largest banks to prepare for AI attack. The EU launches an action plan for AI Cybersecurity. China considers keeping its budget AI to itself. The UK's NCSC & GCHQ announce their "Cyber Shield". CISA is using Mythos to audit U.S. government code. Microsoft warns of their upcoming patch flood. "RoguePlanet" receives an on-the-fly patch. An underused mode to kid-proof an iPhone. Listener feedback and three new AI attacks HalluSquatting, GhostApproval & GitLost Show Notes - https://www.grc.com/sn/SN-1087-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT arcticwolf.com/trends threatlocker.com/twit XBOW.com adaptivesecurity.com cohesity.com/Resilience
AI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators, attackers, and defenders are all scrambling to keep up as vulnerabilities surface at record speed. Europe warns their largest banks to prepare for AI attack. The EU launches an action plan for AI Cybersecurity. China considers keeping its budget AI to itself. The UK's NCSC & GCHQ announce their "Cyber Shield". CISA is using Mythos to audit U.S. government code. Microsoft warns of their upcoming patch flood. "RoguePlanet" receives an on-the-fly patch. An underused mode to kid-proof an iPhone. Listener feedback and three new AI attacks HalluSquatting, GhostApproval & GitLost Show Notes - https://www.grc.com/sn/SN-1087-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT arcticwolf.com/trends threatlocker.com/twit XBOW.com adaptivesecurity.com cohesity.com/Resilience
AI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators, attackers, and defenders are all scrambling to keep up as vulnerabilities surface at record speed. Europe warns their largest banks to prepare for AI attack. The EU launches an action plan for AI Cybersecurity. China considers keeping its budget AI to itself. The UK's NCSC & GCHQ announce their "Cyber Shield". CISA is using Mythos to audit U.S. government code. Microsoft warns of their upcoming patch flood. "RoguePlanet" receives an on-the-fly patch. An underused mode to kid-proof an iPhone. Listener feedback and three new AI attacks HalluSquatting, GhostApproval & GitLost Show Notes - https://www.grc.com/sn/SN-1087-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT arcticwolf.com/trends threatlocker.com/twit XBOW.com adaptivesecurity.com cohesity.com/Resilience
Tuesday, July 14, 2026 Today, Trump will give a Thursday night address likely to produce falsified evidence of foreign interference in the 2020 election; a federal judge has sanctioned two lawyers and referred Blanche and Woodward to the Bar for disciplinary action after finding Donald's lawsuit against the IRS was a fraud on the court; the Justice Department has finally turned over evidence in the shooting case of Renée Good by ICE agent Jonathan Ross in Minneapolis; 12 states have filed a lawsuit to block the Paramount Skydance and Warner Bros. merger; the Governor of South Carolina has appointed Lindsey Graham's sister to take over his Senate seat for the remainder of the term; ICE agents have killed another person in a vehicle in Biddeford Maine sparking protests at Susan Collins' office; 20 agents from the FBI and other federal agencies were seen with U.S. Capitol Police officers entering Lindsey Graham's house; Katie Phang fires back at Todd Blanche's refusal to release court-ordered Epstein documents; plus Allison delivers your Good News. The Daily Beans is proud to partner with Miles Taylor and our friends at DEFIANCE.org For a limited time, members of the Daily Beans community can receive a FREE 3-month full membership to DEFIANCE.org and gain access to one of the fastest-growing pro-democracy movements in America. Join here: https://www.defiance.org/beans Thank You, HoneyLove Save 20% Off Honeylove by going to honeylove.com/DAILYBEANS #honeylovepod #sponsored Thank You, OneSkin Get 15% off OneSkin with the code DAILYBEANS at https://www.oneskin.co/dailybeans #oneskinpod #ad Join The Daily Beans and give a gift today to ensure The Trevor Project can continue its crucial work in the face of continued challenges. Donate to The Trevor Project - Daily Beans Podcast The Latest Breakdown:BREAKING: EXCLUSIVE: FBI Admits it has Epstein Files Training Videos StoriesTrump election task force to begin releasing classified intel documents | MS NOW Trump Had Role in Weighing Proposals to Seize Voting Machines | The New York Times Trump administration tried to ‘manipulate the judicial process' with its IRS settlement, judge says | NBC News Fractures emerge after feds share evidence from Good, Pretti killings with Minnesota authorities | Minnesota Star Tribune 12 states file lawsuit to block $110 billion Paramount-Warner Bros. merger | NBC News Lindsey Graham's sister picked to serve the rest of his Senate term | The Washington Post FBI agents search Sen. Graham's DC home | NBC News ICE Agent Kills Person in Vehicle in Biddeford, Maine, State Officials Say | The New York TimesGood TroubleOppose Todd Blanche for Attorney General ⭑ 5 Calls →Urge Democrats to Oppose and Stop Trump's Crypto Corruption | Indivisible Guide →Defiance.org/beans →Show up for our Libraries - action.ala.org →goodtroubleliveson.org/ July 17-19 →How to help those impacted by the Venezuela earthquakes|AP →Oppose House Amendment to Defund the Peace Corps! →Stand With Minnesota →ICE List →iceout.org Good Newsdana-goldbergs-southwest-funnyfest Oct 9 -Email Dana@DanaGoldberg.com for sponsorship information Tour - DANA GOLDBERGTickets for Dana Goldberg: Outrageous - Sep 23 - Den Theater - Chicago →Share your Good News & Good Trouble - The Daily Beans →Beans Talk audio -beans-talk.simplecast.com →Email Dana LGBTQ Owned eating establishments in your area - hello@mswmedia.com Subject: “Dana's Project” Subscribe to the MSW YouTube Channel - MSW Media - YouTube Our Donation Links The Trevor Project - trevorproject.org/beans Blue Wave California - https://secure.actblue.com/donate/msw-bwc Donate to Public Citizen - https://citizen.org/beans/ Donate to It Gets Better / The Daily Beans Fundraiser Pathways to Citizenship link to MATCH Allison's Donationhttps://crm.bloomerang.co/HostedDonation?ApiKey=pub_86ff5236-dd26-11ec-b5ee-066e3d38bc77&WidgetId=6388736 Join Dana and The Daily Beans in support of Human Rights Campaign http://onecau.se/_ekes71 More Donation LinksNational Security Counselors - Donate, ActBlue.com/donate/msw-bwc, WhistleblowerAid.org/beans Dr. Allison Gill - The Breakdown | Allison Gill, Mueller, She Wrote @muellershewrote.com - Bluesky, MSW & The Daily Beans Podcast @muellershewrote - Instagram, MSW Media - YouTube →Federal workers - email AG at fedoath@pm.me and let me know what you're going to do, or just vent. I'm always here to listen. Dana Goldberg - Dana is on Patreon! At Dana's Dugout, @dgcomedy - Bluesky, @dgcomedy - IG, Dana Goldberg - Facebook, DanaGoldberg.com More from MSW Media - Shows - MSW Media, Cleanup On Aisle 45 pod, The Breakdown | Allison Gill Reminder - you can see the pod pics if you become a Patron. The good news pics are at the bottom of the show notes of each Patreon episode! That's just one of the perks of subscribing! patreon.com/muellershewrote Listener Survey:http://survey.podtrac.com/start-survey.aspx?pubid=BffJOlI7qQcF&ver=shortFollow the Podcast on Apple:https://apple.co/3XNx7ckWant to support the show and get it ad-free and early?https://patreon.com/thedailybeanshttps://dailybeans.supercast.com/https://apple.co/3UKzKt0 Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Treasury sanctions a VPN provider tied to ransomware. The Pentagon hits pause on CMMC audits. Critical flaws surface in Google Cloud's Dialogflow CX. Estée Lauder discloses a data breach. Mobile networks become a battlefield for tracking U.S. personnel. Australia calls out Big Tech over child safety. SAP patches critical bugs. CISA flags an actively exploited Cisco flaw. And the federal government accelerates AI investments. Our guest is Bogdan Botezatu, Senior Director, Threat Research and Reporting at Bitdefender, talking about Cyberthreats to Journalists and Influencers. AI costs savings come at a price. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Bogdan Botezatu, Senior Director, Threat Research and Reporting at Bitdefender, is talking about "Targeting the Messengers: Cyberthreats to Journalists and Influencers," their awareness campaign designed to address the escalating digital and reputational risks faced by media professionals in hostile environments. Selected Reading US sanctions VPN, malware providers for enabling ransomware attacks (Bleeping Computer) Pentagon announces 'immediate suspension' of CMMC Phase II mandates (Breaking Defense) Google Cloud Dialogflow CX vulnerability allowed AI agent hijacking | brief (SC Media) Estée Lauder Companies Reports Data Breach Exposing Health Records and SSNs (Beyond Machines) US military targeted in Iran war phone-tracking campaign (Financial Times) Australia finds serious gaps in Big Tech response to online child sexual abuse (Reuters) SAP warns of critical flaws in NetWeaver and Commerce Cloud (Bleeping Computer) CISA adds Cisco IOS flaw to known exploited vulnerabilities catalog | brief (SC Media) Federal AI Projects Get Priority in TMF Funding Dash (GovInfo Security) Companies Are Throttling Employees' AI Use Because It's Too Expensive (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
From October 30, 2024: The Cybersecurity and Infrastructure Security Agency (CISA) has taken a leading role in coordinating efforts to secure the 2024 election—from ensuring the physical security of election workers, to protecting election systems from cyber threats, to identifying foreign influence campaigns and preparing for deepfakes. With a week until Election Day, Senior Editors Quinta Jurecic and Eugenia Lostri spoke with CISA's Cait Conley, Senior Advisor to the agency's director, about how CISA is working to protect the vote. To receive ad-free podcasts, become a Lawfare Material Supporter at www.patreon.com/lawfare. You can also support Lawfare by making a one-time donation at https://givebutter.com/lawfare-institute.Support this show http://supporter.acast.com/lawfare. Hosted on Acast. See acast.com/privacy for more information.
Accenture confirms a data breach. An Australian telecom investigates a nationwide outage. It's shields up for the UK. CISA eyes September for its critical infrastructure reporting rule. NewsJunkie fakes CTV ad traffic. Agentic AI triggers EDR. CISA taps Mythos for vulnerability scans. Meta faces trillion dollar fines in state lawsuits. Our guest is Russ Anderson, COO and co-founder of RapidFort, sharing a coordinated industry effort to harden the world's most critical open source software against AI-enabled cyber threats. When it comes to breaches, mum's the word. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Russ Anderson, COO and co-founder of RapidFort, is sharing the Linux Foundation's Akrites initiative, a coordinated industry effort to harden the world's most critical open source software against AI-enabled cyber threats. Selected Reading Accenture confirms breach after hacker offers stolen data for sale (Bleeping Computer) Nationwide Telstra outage disrupts thousands, raises questions of foreign launched cyberattack (The Nightly) Britain plans to build autonomous AI 'Cyber Shield' to defend nation (The Record) CISA Eyes September Date for Final Cyber Incident Reporting Rule (MeriTalk) HUMAN Security Disrupts CTV Device Spoofing Operation "NewsJunkie" (Globe Newswire) When AI agents look like attackers: what behavioral telemetry tells us (SOPHOS) Space Force adds Relativity, Impulse Space to national security launch program. (Space News) CISA Deploys Anthropic's Mythos AI to Hunt Vulnerabilities in U.S. Government Code (Security Affairs) Mark Zuckerberg's biggest legal nightmare yet could cost Meta $1.4 trillion (The Independent) Most cybersecurity workers have been told to conceal a breach, report finds (Cybersecurity Dive) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices