POPULARITY
Categories
Nexus sells driver's license scans on the dark web. OpenAI says its models have reached a “Critical” capability threshold. International law enforcement disrupts a decades-old botnet. AI hallucinations fuel “slop squatting.” Plus, urgent patches for Cleo Harmony and Virtualizor, a Texas healthcare breach, and a Russian national accused of targeting thousands of freelancers with remote-access malware. Maria Varmazis shares the latest space-cyber news. Our guest is Rob Allen, Chief Product Officer at Threat Locker, talking about protecting against AI in the workplace. AI threatens the government's bug supply. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices we are joined by Rob Allen, Chief Product Officer at Threat Locker, talking about protecting against AI in the workplace. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading FBI Probes Service Selling 153M+ Drivers Licenses (Krebs on Security) OpenAI's Astra Becomes First Model to Cross Critical Cybersecurity Threshold (SecurityWeek) Sality botnet infrastructure dismantled in joint global takedown (Bleeping Computer) Crooks Are Learning to Love AI Hallucinations (IEEE Spectrum) MSSA Reference Architecture 2.0 (Mobile Satellite Services Association (MSSA)) Exploit Published for Fresh Cleo Harmony Vulnerability (SecurityWeek) Malicious Virtualizor Update Served via BGP Hijacking (SecurityWeek) Nutex Health Says Patient Data Stolen, Hackers Threaten Leak (Infosecurity Magazine) US charges Russian for infecting 80,000 freelancers with malware (Bleeping Computer) How AI could make it harder for governments to use hacking tools (TechCrunch) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Nightmare Eclipse drops a Kaspersky zero-day. The Financial Stability Board warns frontier AI could threaten the global financial system. Anthropic says it has tightened security. CISA adopts a risk-based approach to patching. A new Windows infostealer hides in fake AI models. A critical vulnerability in JFrog Artifactory is kneedeep in active exploitation. North Korean workers are still landing U.S. jobs. A classic NSA codebreaking machine. Our guest is Heather Ceylan, CISO at Box, discussing if AI becomes agentic, governance could become a resilience issue. A robot vacuum sucks up evidence. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices, we are joined by Heather Ceylan, CISO at Box, discussing as AI becomes agentic, governance becomes a resilience issue. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher (SecurityAffairs) Financial Stability Board Sounds the Alarm Over Frontier AI Risks (Infosecurity Magazine) Unit 42 warns AI has shifted balance of power from defenders to attackers (CyberScoop) Improving our alignment and security practices (Anthropic) CISA vulnerability directive designed to ‘buy back time' against hackers (Federal News Network) RevStealer malware spread through fake Claude Opus 5 download (SC Media) Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild (SecurityWeek) North Korea-linked IT Workers Are Getting Hired Inside Western Companies (SecurityAffairs) IBM Built the Cold War's Most Powerful Code Breaker for the NSA (IEEE Spectrum) Man uses robot vacuum to covertly record his wife's affair, wins divorce settlement but gets sentenced to prison for making an illegal recording — Husband lands behind bars after counter-suit over privacy rights (Tom's Hardware) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Could an AI kill switch create more problems than it solves? A critical Rails flaw is under active attack. Malicious browser extensions steal cryptocurrency. Fire Ant targets trusted network infrastructure. Claude Code gets tricked into running attacker-controlled code. MyChart phishing scams spread malware. Two alleged sextortionists face U.S. charges. A former DIA insider walks into an FBI sting. Monday business briefing. Our guest is Tim Starks from CyberScoop discussing a controversial retail security bill. Getting local with Nigerian scammers. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tim Starks from CyberScoop as he is discussing a controversial retail security bill. Selected Reading The AI Kill Switch Act is repeating the Clipper Chip's mistakes (CyberScoop) Critical Ruby on Rails Vulnerability in Attackers' Crosshairs (SecurityWeek) Chrome Web Store extensions caught stealing crypto, browser data (Bleeping Computer) China-linked Fire Ant Hides Inside Trusted Infrastructure (SecurityAffairs) Researcher shows how Claude Code can be tricked simply by asking it to summarize a website (The Register) Fake MyChart emails can show alarming test results, trick patients into installing malware (WMAR) Nigerians extradited to US for sextortion, deaths of two teens (Bleeping Computer) US government snitch-finder pleads guilty to leaking state secrets to foreign spies (The Register) AI safety and security company Alice raises $140 million. (N2K Pro Business Briefing) How Cyber Sleuths Tracked a Nigerian Scammer to His Doorstep (404 media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
In this episode, Maria Varmazis and Dave Bittner from N2K Cyberwire get back together to discuss the evolution of advanced persistent threats (APTs), threat actor landscape, attribution changes, and the future of cyber espionage over the past decade. Join Dave and Maria as they explore how geopolitical factors, organizational professionalism, and emerging technologies like AI are shaping cybersecurity threats. Together, they talk about: The shift in attribution practices over the last 10 years. The role of nation states and organized crime in cyber threats. The impact of AI and emerging technologies on cyber warfare. The challenges of naming and shaming threat groups. The professionalization and organizational evolution of APT groups.
A judge rules the Trump administration illegally labeled Anthropic a national security risk. The White House moves to keep foreign technology out of U.S. power systems. OpenAI rallies a global cyber defense push as its own AI agents exploit a Linux vulnerability. Researchers uncover a new speculative-execution attack and hidden implants in Chinese-made routers. A fake voicemail campaign slips past email defenses. PaperCut faces an exploited zero-day. And ServiceNow patches three maximum-severity flaws in its AI Platform. Maria Varmazis and I look back at a decade of emerging threat actors and APTs. NSA sends out a covert save-the-date. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today, as we continue celebrating the CyberWire Daily's 10th anniversary, Maria Varmazis and Dave Bittner look back at a decade of emerging threat actors and APTs. Enjoyed the conversation? Be sure to tune in Sunday for a special edition featuring the full discussion. Selected Reading Trump Administration's Blacklisting of Anthropic Was Illegal, Judge Rules (The New York Times) White House bans foreign-made equipment for power generation over cyber backdoor concerns (The Record) Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge (SecurityWeek) A call for collective action on cyber defense (OpenAI) New type of attack can slip past the defenses in your computer's processor (MIT News) Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign (Infosecurity Magazine) OpenAI Agents Exploited Linux Kernel Flaw on Company's Own Systems (SecurityWeek) Hundreds of AI agents went rogue in OpenAI's Hugging Face hack (POLITICO) PaperCut Releases Emergency Patch for Exploited Zero-Day (SecurityWeek) ServiceNow warns of three max severity security vulnerabilities (Bleeping Computer) Chinese Implants in the Supply Chain (VulnCheck) Exclusive: NSA to host a hacker reunion in bid to rebuild secretive unit (The Record) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Meta settles. Australian police arrest two alleged TeamPCP members. The White House moves to shore up water utility cybersecurity. ATF reports a major cyber incident. The Navy tells sailors to lock down social media. The FBI warns of a prolific Chinese hacking operation. Bill Gates sounds the alarm on AI. A purported think tank tries to influence chatbot answers. And attackers focus less on individual vulnerabilities and more on the vendors behind them. Our guest is Tim Springston, Principal Product Manager at Semperis, on achieving hybrid identity resilience in the age of agentic AI. Meta pumps the brakes on going AI native. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's industry voices segment, we are joined by Tim Springston, Principal Product Manager at Semperis, discussing how to achieve hybrid identity resilience in the age of agentic AI. If you enjoyed this conversation, check out the full interview here. Selected Reading Meta agrees to pay $18 billion to settle US lawsuits over children's social media addiction (Reuters) Two Alleged ‘TeamPCP' Hackers Arrested in Australia (Krebs on Security) White House to unveil program to protect water systems against hackers (POLITICO) DOJ firearms agency says hackers breached system containing investigation targets (The Record) US Navy tells sailors and their families: scrub your social media, enemies are watching (Bitdefender) Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI Warns (Infosecurity Magazine) Bill Gates diagnoses problems with AI, but an expert questions his prescription (ABC News) Fake US thinktank set up and funded by Israel sought to game AI for propaganda (The Guardian) SentinelOne and Tenable Find Cyber Attackers Routinely Target Edge-Device Vendor Ecosystems Rather Than Individual Vulnerabilities (SentinelOne) AI agents meant to replace Meta workers made “large-scale, disruptive actions” (Ars Technica) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
The U.S. disrupts a Chinese hacking operation blamed for intrusions at several sensitive government agencies. CISA says more than 100 water systems were targeted in July. Attackers exploit a critical Gitea flaw, while malicious pages masquerade as Cloudflare verification screens. Cyber insurance claims get costlier, and AI agents break out of their sandboxes. Boston Scientific battles a cyber incident. Plus, a new standard tracks AI agent activity, criminals target stolen iPhones, and an alleged money mule is charged in a $7.5 million scam. Our guest is Stephen Hilt, Sr. Threat Researcher at TrendAI, on the risks facing data centers. Some breach data doesn't quite measure up. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, we are joined by Stephen Hilt, Sr. Threat Researcher at TrendAI discussing the cybersecurity risks facing data centers and the thousands of internet-exposed industrial control systems that could leave them vulnerable to attack. And if you enjoyed this conversation, be sure to check out the full interview here. If you'd like to hear more on this topic from TrendAI, you can check out this recent episode of the AI Security Brief podcast that focuses on data center security. Guest Mark Houpt, CISO at DataBank, joined hosts Johnny Hand and Dustin Childs to explain why securing the AI era starts with protecting the physical data centers that power it—and why proven security fundamentals still matter against rapidly evolving threats. AI Security Brief podcast publishes every other Thursday on the N2K CyberWire network. Subscribe today! Selected Reading China-sponsored hacking platforms seized by US, Justice Department says (Reuters) CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks (SecurityWeek) Hackers now exploit critical Gitea flaw in code injection attacks (Bleeping Computer) Hackers abuse npm mirrors to host phishing redirect pages (Bleeping Computer) Average Cyber Insurance Losses Increase Despite Fewer Claims (Infosecurity Magazine) VMs won't contain cyber-capable agents (Trail of Bits) Boston Scientific hit by cyberattack, global operations affected (Reuters) Linux Foundation Introduces TRACE Standard for AI Runtime Evidence (Infosecurity Magazine) AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes (Bleeping Computer) Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly (The Record) Trump signs memo to help drastically boost US commercial space launches (Reuters) A Cautionary Tale About Data Breach Claims, Verification and Carhartt (Troy Hunt) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Lawmakers request an investigation into cuts at CISA. Threat actors actively exploit a Zimbra Collaboration Suite vulnerability. A Chinese AI lab preps release of a powerful open-weight model. A new phishing toolkit deploys attacker-controlled passkeys. Using audio hardware to fingerprint browsers. A DDoS attack knocks Norwegian government services offline. CISA orders patching of a critical Oracle vulnerability. Taiwanese prosecutors charge nine people over the alleged illegal export of high-end AI servers to mainland China. Operation Jackal IV cracks down on West African cybercrime networks. On our Industry Voices segment, Christy Wyatt, CEO from Absolute Security, discusses "Cyber Resilience: The Emerging Category." AI music hits a sour note down under. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices segment, we are joined by Christy Wyatt, CEO from Absolute Security, discussing "Cyber Resilience: The Emerging Category." If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading Lawmakers call for investigation into impact of CISA staffing cuts (The Record) Hackers breached over 270 Zimbra servers in ongoing attacks (Bleeping Computer) By Opening a Model, a Chinese A.I. Lab May Test the World's Cybersecurity (NY Times) iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset (SecurityAffairs) AliExpress was silently running audio in your browser to fingerprint and track your device (TechSpot) Large DDoS attack knocks Norwegian public services offline (The Record) U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog (SecurityAffairs) Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff (SecurityWeek) Police arrests dozens of suspects in global cybercrime crackdown (Bleeping Computer) Songs created by AI banned from Australia's music charts (BBC News) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Polymarket traders win big on U.S. military insider information. Slovakia deactivates speed cameras with Russian backdoors. TikTok pays $400 million to settle kids' privacy allegations. Hackers infect Android-based car systems with botnet malware. CISA orders quick patching of an actively exploited Zimbra Collaboration Suite vulnerability. SynkLoader malware is built for stealthy access to corporate networks. Dutch authorities fine Uber over $900 million over automated hiring practices. An ATM jackpotter gets a record prison sentence. Monday business briefing. A privacy promise loses face. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On our Industry Voices segment, we are joined by Mark Beare, General Manager at Malwarebytes Consumer Business from Black Hat to look at protecting your family in the age of AI. If you enjoyed this conversation, check out the full interview here. Selected Reading More than 150 Polymarket wallets may have traded on military secrets, research finds (Reuters) Slovakia discovers Russian backdoors in 279 new traffic cameras — SMS-triggered shell access and passwordless live feeds found in EU-funded rollout (Tom's Hardware) TikTok Settles U.S. Child Privacy Case for $400 Million (Security Affairs) Hackers infecting Android car systems to build proxy botnet (The Record) CISA orders urgent patching of actively exploited Zimbra flaw (Bleeping Computer) SynkLoader: when you throw in everything but the kitchen sink (Expel) Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts (SecurityWeek) Venezuelan Gets Record Federal Prison Term for ATM Jackpotting (SecurityWeek) Fortinet has acquired San Francisco-based AI security company Virtue AI. (N2K Pro Business Briefing) Reverse-Lookup Service Exposed Millions of Photos of People's Faces (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
CISA orders patching of TrueConf Server vulnerabilities. LockBit threatens release of stolen banking data. Researchers disclose a critical type confusion vulnerability in a Node.js library. A new Agent Tesla v4 campaign introduces enhanced evasion techniques. A novel malware delivery technique abuses FTP server banners to hide commands. Apple patches a critical image-processing flaw. A North Korean software supply chain attack targets the Rust ecosystem. Latvian officials resign following a major data breach. Defense contractors are confident in compliance, less so in their ability to prove it. Our guest is Patrick Coughlin, Co-Founder and CEO of Savi Security. discussing the free utility he's developed to protect the sandwich generation from AI-driven scams. When it comes to cyber extortion, who you gonna call? Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Joining us today is Patrick Coughlin, Co-Founder and CEO of Savi Security. Patrick discusses protecting the sandwich generation from AI-driven scams and Scamwise, their free utility built with this purpose in mind. Learn more about Scamwise, a free public utility tool to help consumers quickly determine whether a suspicious message, call, or email is likely a scam, and download Savi's app. Selected Reading CISA orders feds to patch actively exploited TrueConf Server flaws (Bleeping Computer) US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline (The Register) Critical Isolated-vm Vulnerability Leads to RCE on Host (SecurityWeek) New Agent Tesla Malware Variant Boosts Evasion Capabilities (Infosecurity Magazine) Hackers abuse FTP server banners to deliver new Windows malware (Bleeping Computer) Apple plugs image-processing hole ripe for spyware abuse (The Register) North Korean Hackers Tied to Rust Supply Chain Attack (Infosecurity Magazine) Latvian officials resign after cyberattack exposes data on 1.2 million people (The Record) Contractors' CMMC Confidence Rises as Ability to Prove It Falls Behind (SecurityWeek) Ransomware crook poses as recovery firm to steal payments from fellow extortionists (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Federal agencies warn of an active campaign targeting critical infrastructure. Citrix races to patch critical NetScaler flaws. More than 50,000 exposed Stripe API keys raise fraud concerns. Black Hat and DEF CON attendees are targeted in a new social engineering campaign. Atlassian, Splunk, and Cisco fix hundreds of vulnerabilities. A new Android banking trojan adds an unusual twist. A healthcare breach impacts 3.8 million people. SilkParasite expands cyberespionage in Central Asia. And CISA eyes a major overhaul of federal cyber software procurement. Our guest is Chris Wallis, founder and CEO of Intruder, on how AI agents killed the annual pentest and are reshaping exposure management. AI powered robots find bananas quite appealing. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On our Industry Voices segment, Intruder's Founder and CEO Chris Wallis joined Dave at Black Hat to discuss why the annual pentest Is dead and how AI agents are reshaping exposure management. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology (The Record) Citrix urges admins to patch new NetScaler flaws as soon as possible (Bleeping Computer) 50,000 Stripe Secrets Leaked in Public Code (SecurityAffairs) Black Hat/DEF CON attendees targeted in malware scheme with Google Doc lure (SC World) Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities (SecurityWeek) Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities (SecurityWeek) New Manic Android malware can exfiltrate data through nearby devices (Bleeping Computer) EHR Vendor Notifying 3.8 Million Patients of Data Theft Hack (GovInfo Security) SilkParasite: Tracking a China-Nexus APT Across Central Asia (Bitdefender) CISA contemplates whether to hire security software buying help (Washington Technology) I Saw the Future of AI in a Robot That Can Learn on the Spot (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Medusa's reach grows. Cl0p expands its victim list. The DOJ charges 17 alleged Iranian hackers. CISA sounds the alarm on four exploited vulnerabilities. TWINLOOT hides in plain sight inside Microsoft 365. Maria Varmazis shares the latest from the space-cyber realm as Ukraine strikes Russia's satellite nerve center. The FDA considers guardrails for AI medical devices. Expired credit cards get an unexpected second life. A disgruntled contractor heads to prison. Dave Bittner sits down with Brian Vecci, Field CTO at Varonis, at Black Hat USA to discuss how AI is calling your security bluff. Highway hijinks meet high-tech hardware. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest At Black Hat USA, Dave Bittner sat down with Brian Vecci, Field CTO at Varonis, as they discussed how AI is calling your security bluff. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading CISA: Medusa ransomware hit over 500 critical infrastructure orgs (Bleeping Computer) US charges Iranians for sprawling hacking campaign on government agencies, universities (The Record) Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign (SecurityWeek) CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities (SecurityWeek) New TWINLOOT Malware Steals Windows Passwords Via Fake Lock Screen (Hackread) Ukraine says it hit Russian rocket centre linked to Starlink-style network (CNBC) FDA Weighing Possible Regs for GenAI Medical Devices (GovInfo Security) Expired credit cards revived by researchers to make unauthorized payments (The Register) Prison for data analyst who tried to extort $2.5 million from his employer (Bitdefender) ‘The Worst I've Ever Seen': Cargo Thefts Have Turned Violent in Pursuit of AI Hardware (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
A fake consultancy fronts an alleged Chinese spy campaign. Meta heads to court over claims it hooked young users. Researchers crack the mystery behind the French EncroChat hack. CISA warns ransomware gangs are exploiting a Windows flaw. Meet C2Looper, a new Rust-based backdoor. A critical WordPress plugin bug threatens hundreds of thousands of sites. MessiahGPT brings generative AI to cybercrime. A lender discloses a breach affecting 1.2 million people. A Ukrainian developer stands trial in Switzerland over alleged ransomware ties. Our guest is Ev Kontsevoy, CEO at Teleport, discussing how AI agents have nondeterministic behavior. The psychology of the endless scroll. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, we are joined by Ev Kontsevoy, CEO at Teleport, discussing how AI agents have nondeterministic behavior. If you enjoyed this conversation, check out the full interview here. Selected Reading A fake website and a deluge of CVs: the Australian firm embroiled in an FBI probe into alleged Chinese espionage (The Guardian) States Seek $200 Billion From Meta Over Child Social Media Addiction Claims (The New York Times) Revealed: Cyber spies used malware from GitHub to hack EncroChat cryptophone network (Computer Weekly) CISA: Windows Task Host flaw now exploited by ransomware gangs (Bleeping Computer) C2Looper Backdoor Uses GitHub for C2 (ThreatLabz) 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw (SecurityWeek) MessiahGPT Criminal AI Service Advertised on BreachForums (HackRead) Heights Finance Data Breach Impacts at Least 1.2 Million Individuals (SecurityWeek) Ukrainian software developer faces 12 years in Swiss ransomware trial (The Record from Recorded Future News) Why Can't We Stop Scrolling? (Psychology Today) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Internal policy conflicts hamper U.S. military AI leadership. Clop claims GE, Philips and Shell. Attackers actively probe internet-facing GeoServer instances. “The Hatman” offers millions of alleged employee records for sale. ETSI begins the approval process for European cyber standards. Microsoft is still working on a patch for the ShieldBreak vulnerability. Autonomous AI systems create CPU bottlenecks. Monday business briefing. Our guest is Nick Warner, CEO at Neo.ai, on the shifting landscape around AI and agentic security. AI agents kneecap each other with self-replicating malware. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices segment, we are joined by Nick Warner, Neo.ai's CEO, discussing the shifting landscape around AI and agentic security. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading The U.S. Military Wants A.I. Dominance. Feuds and China May Thwart It. (The New York Times) Philips and GE investigating Clop ransomware data theft claims (Bleeping Computer) Attackers Probe Critical GeoServer SQL Injection Vulnerability (Hack Read) Crook hawks millions of records allegedly plundered from corporate Azure tenants (The Register) ETSI Proposes 17 Cybersecurity Standards to Support EU CRA (Infosecurity Magazine) Microsoft working on Defender patch for ShieldBreak zero-day (Bleeping Computer) Agentic AI Crunch Creates CPU Comeback (IEEE Spectrum) Corma raises $60 million in seed funding. (N2K) Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware (SecurityWeek) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Apple sends out threat notifications to users targeted by spyware. Trivy, not LiteLLM, was the original source of the 2,500-organization supply chain attack. French tax authority confirms data breach. Chinese hack-for-hire group conducts espionage and cybercrime simultaneously. Ukrainian police shut down 94 scam call centers. Former data analyst jailed for insider extortion plot. New macOS malware spreads via ClickFix. Today we are joined by Tom Kellermann, VP of AI Security at TrendAI, discussing the machine-speed war for financial control. And the glitch in the surveillance matrix. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tom Kellermann, VP of AI Security at TrendAI, discussing the machine-speed war for financial control. If you want to learn more on this topic, check out the article here. You can also check out Tom on the AI Security Brief here. Selected Reading If Apple sends you a push notification alerting you to a spyware attack, take it seriously (TechCrunch) Trivy, Not LiteLLM Behind the 2,500 Org Compromise (SecurityWeek) France investigates tax authority breach after hacker claims 600,000 victims (The Record) Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side (Symantec) AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers (Jamf) Ukraine shuts down 94 fraudulent call centers, seize millions in cash (BleepingComputer) This 'adversarial' pattern can prevent surveillance cameras from detecting you (TechCrunch) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
President Trump deputizes private-sector companies to target cybercriminals. The LiteLLM supply-chain attack exposed credentials belonging to thousands of organizations. Data-theft campaign targets misconfigured Salesforce and ServiceNow instances. Hackers deploy AI agents to breach Taiwanese government systems. CISA mandates urgent patch for actively exploited Cisco firewall vulnerability. Nightmare Eclipse publishes yet another Windows zero-day exploit. On our Industry Voices segment, Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps, discuss frontier models and the future of cyber defense. And please do not reply. Seriously. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices segment, Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps, speak with Dave Bittner at Black Hat about frontier models and the future of cyber defense, including responsible AI deployment, red teaming, reducing security noise, and the evolving role of human expertise in AI-assisted defense. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading Trump turns to private sector in offensive hacking operations memo (CyberScoop) Terabytes of credentials leaked in massive supply-chain attack (Ars Technica) "City-Forum" data-theft attacks target Salesforce, ServiceNow portals (BleepingComputer) 'Near-autonomous' AI agents attack Taiwan's nuclear safety agency (The Register) Cisco says software vulnerability could let hackers crash firewalls (Cybersecurity Dive) Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows (The Register) Sensitive Info Goes Into ‘No Reply' Emails Constantly. This Guy Sees It All (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
We got your Patch Tuesday notes. Attackers target Microsoft SharePoint vulnerability following PoC release. Cyberattack on CEVA Logistics causes ongoing supply chain disruptions. Wesco confirms data breach following extortion claims. Akira ransomware bypasses EDR in Safe Mode. California announces AI cybersecurity fund. N2K's Lead Analyst Ethan Cook shares about cyber weapons for space. Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain. And fasten your seatbelts and ignore the fake Wi-Fi. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain, including AgentBaiting, where fake AI Skills and MCP servers were used to deliver malware, and hidden instructions that can influence AI agents. If you enjoyed the conversation, be sure to check out the full interview here. Selected Reading Microsoft and Adobe Patch Tuesday, August 2026 Security Update Review (Qualys) Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack (Check Point Research) Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability CSO Online ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact (SecurityWeek) Hackers leverage new Microsoft SharePoint exploit in attacks (BleepingComputer) The CEVA Logistics data breach is having major knock-on effects across Europe - here's what we know (TechRadar) Wesco confirms security incident after ExfilSquad claims data theft (BleepingComputer) Akira Hits Safe Mode: Ransomware Rebooting Around EDR (Huntress) California Building ‘AI Cyber Defense Fund' to Protect Critical Infrastructure From Hackers (Gizmodo) Laser weapons for space? US officials see threat, opportunity (BREAKING DEFENSE) DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Poland's CERT describes winter cyberattack against heat-and-power plant. Russian military hackers target Ukrainian IT workers in fake recruitment scheme. Chinese IP connections spark security review in UK Navy drones. US and South Korea warn of “Gunra” ransomware gang with North Korean ties. OpenAI mandates strict security controls for its new cybersecurity model. Record-breaking DDoS attacks surge in H1 2026. Data-scraping AI extension returns to the Chrome Web Store. Dave Bittner sat down with Stephen Harrison, VP of Product at Abnormal AI at Black Hat USA to discuss "The Identities Your Security Stack Is Ignoring." And no pain, no gain, no authorization. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices, Dave Bittner sat down with Stephen Harrison, VP of Product at Abnormal AI at Black Hat USA to discuss "The Identities Your Security Stack Is Ignoring." If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading Hackers breached a small Polish energy plant via private APN last year (BleepingComputer) Russian military hackers pose as recruiters to target Ukrainian IT workers (The Record) Cyber vulnerability sweep picks up Royal Navy drones sending data to China (The Register) U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang (CyberScoop) OpenAI's Upcoming Astra Model Raises Autonomous Cyberattack Concerns (SecurityWeek) Cloudflare DDoS Threat Report H1 2026 (Cloudflare) Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities (SecurityWeek) AI assistant hacks gym website in first known Australian autonomous cyber attack (ABC News) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Researchers find that only a quarter of AI-generated patches are fully successful. Ransomware attacks exploit critical N-able flaw. Atlassian fixes critical flaw in Rovo AI. LexisNexis disables some services following suspicious activity. US Senate confirms Adam Cassady as cyber ambassador. Meta ordered to pay an additional $567 million in child safety case. Water sector cyberattacks expand to new states. We got your Monday Business Briefing. On our Industry Voices, Dave Bittner sits down with Mujtaba Hamid, EVP, Product and Strategy at Booz Allen Hamilton at Black Hat discussing AI Speed Cyber Defense. And scammers set sail on The Odyssey. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices, Dave Bittner sat down with Mujtaba Hamid, EVP, Product and Strategy at Booz Allen Hamilton at Black Hat USA, discussing AI Speed Cyber Defense. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading More than half of AI-generated patches are broken (CyberScoop) China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns (The Record) Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data (SecurityWeek) LexisNexis shuts down services after suspicious activity on servers (BleepingComputer) US cyber ambassador nominee Cassady confirmed in Senate (The Record) Meta Ordered to Pay $567 Million in New Mexico Child Safety Case (New York Times) New Jersey, Alabama Join States Targeted in Water Cyberattacks (Securityweek) Business Breakdown (N2K) ‘Watch The Odyssey for free online': scam targets film fans with fake streaming sites (The Guardian) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Vishing attacks target hedge funds. Metabase Cloud breached by zero-day flaw. Cyberattack disrupts North Carolina Ports operations. The Chinese government has launched a security review of Palo Alto Networks products. US defense supplier breached by phishing attack. Healthcare software provider breach affected 3.8 million people. New macOS malware spreads via ClickFix attacks. Microsoft and Apple issue new security updates. Cryptography expert says new AI cryptanalysis results show promise, but not an AES breakthrough. James Turgal, Optiv Security's vice president, cyber risk, strategy and board relations, is discussing how Iranian operators and their proxies appear to pursue disruption. And a Kentucky Fried Chicken order doxxes Chinese spyware operator. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by James Turgal, Optiv Security's vice president, cyber risk, strategy and board relations, discussing how Iranian operators and their proxies appear to pursue disruption by exploiting poorly secured operational technology in sectors such as water, energy, healthcare, and transportation. Selected Reading Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group (BleepingComputer) Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments (GTIG) Cyberattack on North Carolina Ports ‘contained' as Coast Guard, state officials investigate (The Record) China launches cybersecurity review into Palo Alto Networks products (Reuters) Attacker phished way into US defense supplier's Microsoft 365 account (The Register) Unlimited Technology Systems Data Breach Affects 3.8 Million Patients (HIPAA Journal) Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam (Huntress) China-linked LightSpy spyware caught targeting victims in 13 countries, including the US (TechCrunch) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Meta's AI models join the sandbox escape club. China's telecom footprint in the U.S. may be larger than expected. The White House keeps its AI safety playbook under wraps. AI coding tools introduce new GitHub risks. ENISA expands its CVE role. A critical Paperclip flaw enables code execution. Crypto wallet fears fuel phishing attacks. Researchers uncover a backdoor in Chinese-made routers. The Snowflake hacker pleads guilty. Our guest is Dustin Childs, Head of Threat Awareness of TrendAI's Zero Day Initiative, discussing the new Patch Tuesday era. AI takes your word for it. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Dustin Childs, Head of Threat Awareness of TrendAI's Zero Day Initiative, discussing the new Patch Tuesday era. Be sure to check Dustin out on the AI Security Briefing podcast. Selected Reading Meta AI Hacked External Systems During Cybersecurity Testing (SecurityWeek) Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says (The Record) Secret White House AI Safety Framework Draws Criticism (BankInfo Security) Few Federal Agencies Trust Their Own AI Agent Security (BankInfo Security) Black Hat USA 2026: One GitHub Issue Could Compromise Major AI Coding Workflows (Hackread) ENISA scales up its role in the CVE Program (enisa) Critical Paperclip Flaw Allowed Admin Access, Code Execution (SecurityWeek) COLDCARD security audit phishing attack installs remote access tool (Bleeping Computer) Chinese-made Zbtlink routers have backdoor, researchers say (Reuters) Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions (US Department of Justice) “I'm Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails (Hackread) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
The White House lays out its AI strategy at Black Hat. Researchers spotlight rogue AI behavior. CISA warns of an actively exploited N-able flaw. TP-Link patches 15 Omada vulnerabilities. Apple fights the UK's iCloud access order. The AI gray market expands. A Massachusetts healthcare breach hits more than 300,000 people. Lawmakers push to extend protections for OPM breach victims. Our guest is Cal Al-Dhubaib, Principal Technologist at Rubrik, who wonders if your security team is solving the wrong problem. With elections, don't trust AI to tell you the whole story. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices segment, we are joined by Cal Al-Dhubaib, Principal Technologist at Rubrik, talking about how your security team is solving the wrong problem. If you enjoyed the conversation, check out the full interview here. You can also find more information below: Rubrik Agent Cloud landing page Rubrik AI landing page News: Rubrik Launches Rubrik Agent Cloud for Anthropic's Claude Code Selected Reading National cyber director lays out White House plans to secure AI without writing new rules (CyberScoop) Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data (SecurityWeek) AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project (The Register) MSPs urged to patch immediately after N-able issues hotfix for N-central ‘god mode' flaw (IT Pro) TP-Link patches Omada ZTP flaws allowing hackers to breach networks (BleepingComputer) Apple launches new legal challenge against UK over iCloud access (The Record) Free tokens for sale: How fake signups drive AI fraud (Threat Intelligence) 311,000 Impacted by Brown Health Medical Group-MA Data Breach (SecurityWeek) Lawmakers spring to save ID theft services for OPM breach victims, with expiration looming (CyberScoop) AI is getting better at election facts, but voters shouldn't rely on it (CyberScoop) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
New Shai-Hulud campaign compromises popular npm packages. Easterly says small municipalities shouldn't have to fend for themselves. Chinese threat groups accelerate exploits. Samsung bans smart TV apps with residential proxies. Hackers breach a Liechtenstein banking database. Swiss government IT agency hit in suspected SharePoint Attack. Microsoft's bug bounty program awards record payouts. Researchers expose privilege boundary flaw in AI-driven CI/CD workflows. Roberta Anderson, Air Force veteran and CISO at Onterris is sharing her "Breaking the Firewall" book. And, bug hunting turns into bug sorting. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Roberta Anderson, Air Force veteran and CISO at Onterris, sharing her "Breaking the Firewall" book. Selected Reading Keyv and friends compromised in npm supply chain attack (Aikido) Small Towns Shouldn't Have to Defend America's Water Supply From Iran (The New York Times) China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day (Infosecurity Magazine) Samsung bans smart TV apps that share users' internet connections with strangers (TechCrunch) Liechtenstein says hackers access information on 31,000 legal entities (Reuters) Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected (The Record) Microsoft Bounty Program year in review More than $20 million awarded in our biggest year yet (Microsoft Security Response Center) I'll Just Call You: Agent-to-Agent Privilege Boundary Failures in CI/CD on Google's ADK Repository (Pillar Security) Apple struggles to keep pace with AI ‘bug' hunters (Financial Times) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Cyberattacks hit U.S. water systems. CISA tackles open source security. China's surveillance machine is exposed. Hotel Wi-Fi gets riskier. Healthcare and police data spill online. Fake SQLite vulnerabilities fool security databases. Monday business briefing. Our guest is Tim Starks from CyberScoop discussing the White House's quantum aspirations. AI is the hottest thing on campus. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tim Starks, Senior Reporter from CyberScoop, discussing the White House's quantum aspirations. Selected Reading Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran (The New York Times) CISA lays out new guidance for using open-source software (Help Net Security) How China Keeps Tabs on Foreigners (The New York Times) Microsoft Issues Hotel Wi-Fi Warning For Windows PC Users (Forbes) Exclusive: Partnered Health responds to Inc Ransom data breach claims (Cyber Daily) Security Flaw Placed 30 Years of DNA Evidence at Risk of Hacking (Wall Street Journal) SQLite Critical CVEs or LLM Slop? (JFrog Security Research) Details of 100,000 police staff leaked on the dark web after hack (The Times) ThreatLocker secures $190 million in a Series F round led by Elephant (N2K Pro Business Briefing) At colleges, the AI boom means everyone wants to dabble in computer science (AP News) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Anthropic says Claude escaped the sandbox three times, while a judge questions the Pentagon's blacklist. The EU launches an AI enforcement team, the FTC targets a telehealth firm's tracking pixels, and a WordPress backdoor is stopped just in time. CareCloud discloses a major data breach, a stealthy cryptominer hides in plain sight, AiTM phishing surges against law firms, and Finland severs one more digital link to Russia. Our guest is Yan Shoshitaishvili, Associate Professor, Arizona State University, previewing his Black Hat 2026 keynote "Vulnerability Research in the Agentic Age." AI scammers may deserve a promotion. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Yan Shoshitaishvili, Associate Professor, Arizona State University, discussing his Black Hat 2026 keynote "Vulnerability Research in the Agentic Age." Be sure to tune in this Sunday for a special edition featuring our full, extended interview with Yan. Selected Reading Anthropic AI Models Hacked Three Organizations During Tests (Bloomberg) Anthropic, Pentagon Clash Over First Amendment Claims (GovInfo Security) EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels (SecurityWeek) FTC sues Hims & Hers for allegedly sharing patients' medical data with advertisers Meta and Snap (TechCrunch) Wordfence Finds Critical Backdoor in ARVE WordPress Plugin (Hackread) CareCloud Data Breach Impacts Over 350,000 (SecurityWeek) Cryptominer Abuses Linux PAM to Hide From SOC Analysts (Infosecurity Magazine) AiTM Phishing Becomes Top Initial Access Threat to Law Firms (Infosecurity Magazine) Finland to disconnect fiber-optic link to Russia as lease expires (The Record) AI Scammers Are Better at Building Trust Than Humans (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
China embraces open AI models, then worries it's become a national security risk. The cyberattack on Minnesota water systems proves larger than first reported. CISA updates its SBOM guidance. AI supercharges dangling DNS attacks. Researchers uncover a self-propagating Copilot worm. A critical Rails flaw demands urgent patching. Mac users are lured into installing malware through fake Claude guides. Amazon links a string of NPM compromises to North Korea. And Russia charges Telegram founder Pavel Durov with aiding terrorism. Ben Yelin joins us with a border search case that's breaking new ground. Don't bite the North Korean hand that feeds you. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies talking about a border search case that's breaking new ground. If you enjoyed this conversation, check out Ben on the Caveat podcast here. Selected Reading As China's A.I. Gets Stronger, It Poses New Risks to Beijing (New York Times) Minnesota Water Utilities Suffer ‘Coordinated Cyber Attack' (GovTech) CISA Updates Software Bill of Materials Guidance to Strengthen Supply Chain Security (HSToday) ‘DangleGeddon': AI Could Weaponize Forgotten DNS Records at Global Scale (SecurityWeek) Word worm crawls into Copilot, spreads chaos (The Register) Possible arbitrary file read and remote code execution in Active Storage variant processing (GitHub) Fake Claude Install Guide Leads to MacSync Stealer and RAT: What We Pulled From the Attacker's Servers (Huntress) Amazon identifies North Korean hacker group behind open-source supply chain attacks (AWS Security Blog) Russia accuses Telegram CEO Pavel Durov of aiding terrorism in its latest digital crackdown (AP News) North Korea's elite hackers turned on their own government — and got caught (Bitdefender) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
The Senate confirms Jay Clayton to lead ODNI. A new CISA framework highlights critical infrastructure isolation capabilities. OpenAI's rogue agent breached more than just Hugging Face. The average cost of a data breach continues to rise. Indirect prompt injection proves irresistible to cyber criminals. Broadcom patches multiple VMware products. ShinyHunters claims responsibility for Ernst & Young's recent breach. Our guest is Sean Zadig, CISO at Yahoo, discussing the impact of AI on the defense side. These aren't the droids you're looking for. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Sean Zadig, CISO at Yahoo, discussing the impact of AI on the defense side without all the hype in either direction, what is a CISO actually doing about it. Selected Reading Senate Confirms Jay Clayton to Lead U.S. Intelligence Community (The New York Times) China and Iran Are Already Inside US Grids: CISA Demands Tested Isolation Plans (Tech Times) OpenAI's rogue agent compromised a customer at a second tech firm, executive says (Reuters) Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident (Hugging Face) The Average Cost of a Data Breach Rises to $5 Million (Infosecurity Magazine) USSPACECOM Issues Space Warfighting Environment 2040 for Joint Force Space Operations (ExecutiveGov) THE SPACE WARFIGHTING ENVIRONMENT 2040 Framing the Future for the Joint Warfighter (U.S. Space Command) Notes from Underground: Adversarial Prompt Injection (Proofpoint) Critical VM Escape Vulnerability Patched in VMware ESXi (SecurityWeek) ShinyHunters Claims Ernst & Young Hack (SecurityWeek) America bans imported robots due to supply chain and security risks (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
A senator targets legacy VPNs. Minnesota water systems come under cyberattack. A 20-year-old flaw exposes 24,000 servers. Microsoft debuts its first cybersecurity AI model. A critical VeloCloud bug is under active attack. The Dysphoria botnet tops 200,000 devices. Apple faces a lawsuit over a fake crypto wallet. Denmark builds a cyber-resilient banking backup. Google gives threat actors yet another set of names. Our guest is John Chiappetta, Chief Revenue Officer of Xona Systems, discussing the Aviation Cybersecurity GAO report that highlights gaps in FAA network security. Hacking the admissions system in search of a fair chance. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by John Chiappetta, Chief Revenue Officer of Xona Systems, discussing the Aviation Cybersecurity GAO report that highlights gaps in FAA network security. Selected Reading Wyden Demands Two-Year Federal VPN Purge: Zero-Trust Procurement Rule Would Reshape Vendor Market (Tech Times) Several MN water facilities targeted by cyber attacks (FOX 9 Minneapolis-St. Paul) Over 24,000 exposed server BMCs leak password hash via decades-old flaw (Bleeping Computer) Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model (SecurityWeek) Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock (The Register) New Dysphoria DDoS botnet spreads to 200k devices worldwide (Bleeping Computer) Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin (Bleeping Computer) Denmark Readies Emergency Reserve Bank to Fight Cyberattacks (Global Finance Magazine) Google Adopts New Threat Actor Naming System (SecurityWeek) Rejected Cybersecurity Applicant Allegedly Hacks IIT Madras Portal: "All I Need Is A Fair Chance" (NDTV) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Hackers target Thailand's Ministry of Finance with an autonomous AI agent.A new industry alliance hopes to improve AI security. Golden Chickens lay four new malware families. GitHub and PyPI introduce time-based safeguards. SourTrade malvertising builds malware directly inside a victim's browser. Attackers target credentials of traveling corporate employees. EDR shutdown is now par for the course for leading ransomware groups. Russian threat actors exploited a Zimbra vulnerability for at least five months before it was patched. Monday business briefing. Our guest is Krishna Sai, CTO at SolarWinds, with security lessons learned from the World Cup. When the feed ends, the fun begins. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Krishna Sai, CTO at SolarWinds, discussing the security risks around the World Cup and how this affects IT teams as they try to manage the growing digital traffic sprawl surrounding the event. Selected Reading Hackers used autonomous AI agent to spy on Thailand's finance ministry (The Record) Nvidia and Tech Giants Launch AI Security Alliance (SecurityWeek) Golden Chickens malware-as-a-service resurfaces with four new families (SC Media) GitHub, PyPI add time-based defenses against supply chain attacks (Bleeping Computer) SourTrade Malvertising Campaign Secretly Builds Malware in the Browser (Infosecurity Magazine) Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials (SecurityWeek) Ransomware Groups Increasingly Deploy EDR Kill Techniques (Infosecurity Magazine) TA488 Targets Zimbra Mailservers with Half-Click Exploits IProofpoint) Endpoint security firm Glow emerges from stealth with $180 million. (N2K Pro Business Briefing) Being a Luddite Is Fun Again (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Laundry Bear snuffles through unpatched Zimbra Collaboration servers. The State Department puts visa restrictions on cybercriminals. Oracle drops a record 1,449 security patches. Researchers disclose a critical vulnerability in OpenAI's ChatGPT Workspace Agents. A new benchmark evaluates frontier AI model malware reverse engineering. LunchPoke uses the Notepad++ application to establish persistence. A Swiss rail manufacturer refuses to pay the ransom. Dave Bittner sits down with Maria Varmazis, host of T-Minus Space Cyber Briefing, to discuss the show's evolution into CyberWire's weekly space cyber briefing. The AI goes to space. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Dave Bittner sits down with Maria Varmazis, host of T-Minus Space Cyber Briefing, to discuss the show's evolution into CyberWire's weekly space cyber briefing. Maria shares why space cybersecurity deserves more attention, how the new format allows for deeper conversations on topics like GPS security and European space sovereignty, and why every cybersecurity professional should be paying attention to the growing role of space in cyber. You can hear part one here. Selected Reading Russian hackers exploit Zimbra zero-click flaw for email theft (Bleeping Computer) State Department imposes visa restrictions on foreign cyber scammers (The Record) Oracle drops 1,449 security patches like it's the new normal (The Register) OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider (SecurityWeek) Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models (SecurityWeek) Hackers abuse Notepad++ plugins to stealthily install malware (Bleeping Computer) Swiss train maker Stadler refuses Everest $12 million ransomware demand (The Record) If you pay a hacker's ransom, chances are that they'll come back for more (TechCrunch) NASA Puts Google's Gemma Large Language Model in Orbit (IEEE Spectrum) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Google gets a billion dollar fine from the EU. The White House considers sanctions against Chinese AI developers. The GAO criticizes overlap in cyber reporting regulations. The Feds warn of Iranian agents targeting OT systems. Researchers disclose a high-severity Linux kernel vulnerability. Dolphin X uses AI profiling to find high-value victims. A new backdoor routes C2 through the browser. Check Point confirms a critical zero-day. A lawsuit accuses ChatGPT of unauthorized medical advice. Ben Yelin explains how political campaigns attempt to influence LLMs. Baseball benches the bots. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies talking about how "Politicians Are Trying to Change What Chatbots Say About Them." If you enjoyed this conversation, be sure to check out Ben on Caveat every week. Selected Reading Google Hit With $1 Billion Fine for Abusing Its Power in Europe (New York Times) US Eyes Sanctions on Chinese AI Firms Over Distillation (GovInfo Security) Most federal cybersecurity reporting rules are duplicative, study finds (CyberScoop) Federal agencies broaden alert on Iran-linked OT attacks (The Record) New RefluXFS Linux flaw lets attackers gain root privileges (Bleeping Computer) New Dolphin X Stealer Employs AI Profiling to Prioritize Targets (Infosecurity Magazine) New msaRAT malware uses Chrome, Edge browsers to route C2 traffic (Bleeping Computer) New Check Point Zero-Day Vulnerability Exploited in the Wild (SecurityWeek) Lawsuit Claims ChatGPT Dished Out Dangerous Health Advice (GovInfo Security) MLB bans using dugout iPads for AI-powered in-game strategy calls (Engadget) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
GPT escapes the sandbox and hacks Huggingface. SolarWinds patches multiple critical flaws. CISA orders patching of a critical Langflow AI vulnerability. A Paidwork breach affects over 23 million users. A recently patched SharePoint vulnerability is under active exploitation. Oracle patches over 1,400 vulnerabilities. Apps turn Smart TVs into residential proxies. The FCC considers expanding direct to satellite communications. German and U.S. authorities dismantle a major phishing-as-a-service (PhaaS) platform. Our guest is Jimmy McNary, Deputy Federal CTO at Semperis, discussing comprehensive identity security assessments for Microsoft GCC. AI models can't resist bending the rules. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On our Industry Voices segment, we are joined by Jimmy McNary, Deputy Federal CTO at Semperis, discussing how Purple Knight now delivers comprehensive identity security assessments for Microsoft GCC high environment. Selected Reading OpenAI Claims Its AI Models Went Rogue and Hacked Another Company (Infosecurity Magazine) SolarWinds Serv-U Update Fixes 15 Critical Vulnerabilities Enabling Remote Code Execution as Root (GB Hackers) CISA orders urgent action on actively exploited Langflow RCE flaw (Bleeping Computer) Paidwork breach exposes data of 23 million users: Check if you're affected (Malwarebytes) Fourth SharePoint Vulnerability Exploited in Past Month's Wave of Attacks (SecurityWeek) Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates (SecurityWeek) Chairman Carr Proposes to Expand Direct-to-Device Satellite Broadband Connectivity to Unlicensed Wireless Devices (FCC) LG to Ban Residential Proxies from Smart TV Apps (Krebs on Security) Police dismantle Kratos phishing platform, arrest developer (Bleeping Computer) AI's cheatin' heart will make you weep (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Trump's latest AI leader resigns. The Army burns through its AI tokens. Scammers impersonate IC3 personnel.HollowGraph malware uses a compromised Microsoft 365 calendar for C2. Qilin ransomware targets a critical Palo Alto Networks flaw. A North Korean campaign targets Web3 and cryptocurrency professionals through fake job recruitment scams. Zimbra patches multiple critical bugs. Shadow AI creates regulatory headaches. Hackers wipe Romania's land registry database. Our guest is Errol Weiss, Chief Security Officer at Health-ISAC, setting the record straight on ransomware trends. Patching the automotive security system you didn't know you had. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we have Errol Weiss, Chief Security Officer at Health-ISAC, joining us to discuss ransomware trends in the healthcare industry. We also discuss findings from the Health-ISAC 2026 CISO Benchmarking Report and Health-ISAC's 2nd Quarter Heartbeat Report, which examine the current threat landscape facing the health sector. Selected Reading Trump's latest AI czar has already resigned (TechCrunch) The Army Is Burning Through Its AI Tokens (WIRED) Fake FBI Agents Use IC3 Complaints to Target Scam Victims (Hackread) New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication (SecurityWeek) Critical Palo Alto VPN bug now exploited by Qilin ransomware gang (Bleeping Computer) Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros (Infosecurity Magazine) Zimbra Update Patches Critical Vulnerabilities (SecurityWeek) Shadow AI Is Rewriting Cyber Disclosure Risk (BankInfoSecurity) Risky Bulletin: Hacker wipes Romania's entire land registry database (Risky.Biz) A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Hugging Face reports an autonomous AI-powered breach. Ernst & Young discloses a client data breach. Attackers are actively exploiting a critical ServiceNow flaw. Ransomware gangs sharpen their tactics against law firms. Capital One open-sources an AI security tool. Text salting fools AI email filters. Hidden gambling apps slip into Apple's App Store. And federal agents arrest a Florida man accused of spreading malware through video games. Monday business briefing. Tim Starks from CyberScoop discusses election integrity. Fake feathers lead to faulty findings. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tim Starks from CyberScoop discussing election integrity and the Trump administration's waning influence. You can read more here. Selected Reading AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign (Security Affairs) Ernst & Young Data Breach Affects Personal, Financial Information (SecurityWeek) Critical ServiceNow code execution flaw now exploited in attacks (Bleeping Computer) How ransomware tactics against law firms are changing (Wisconsin Law Journal) Capital One Open Sources AI-Powered ‘VulnHunter' Security Tool (SecurityWeek) AI spam filters are getting suckered by old-school text salting (The Register) Investigation reveals dozens of disguised gambling apps on the App Store in Brazil (9to5Mac) FBI Arrests Florida Man in $220,000 Steam Crypto Theft Case (Hackread) Israeli identity management startup Oak emerges from stealth with $60 million in seed funding. (N2K Pro Business Briefing) AI-altered images on birdwatching forums putting research at risk | AI (artificial intelligence) (The Guardian) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Nightmare Eclipse drops another Windows zero-day. The Gentlemen take the ransomware crown. CISA orders emergency Fortinet patching. Canada's surveillance bill faces U.S. scrutiny. Meta's Oversight Board flags AI censorship bias. Commerce tops the cyber target list. An active espionage campaign hits Bangladesh's military. The Hewlett Foundation commits $100 million to emerging tech security. And U.S. prosecutors dismantle an alleged cyber-enabled money laundering network. Our guest is Nick Stohlman, Vice President of CJIS Strategy at Imprivata, talking about CJIS readiness and the identity security challenges facing public safety agencies. Leaked source code reveals an AI mixtape. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Nick Stohlman, Vice President of CJIS Strategy at Imprivata, talking about CJIS, Criminal Justice Information Services, readiness and the identity security challenges facing public safety agencies. Selected Reading New Windows LegacyHive zero-day gives hackers admin privileges (Bleeping Computer) The Gentlemen Overtakes Qilin as Most Prolific Ransomware Threat (Infosecurity Magazine) CISA urges immediate action on actively exploited Fortinet flaws (Bleeping Computer) Senator calls on Rubio, Blanche to push back against Canadian surveillance legislation (The Record) Meta Oversight Board finds top AI models less likely to criticize repressive regimes (Reuters) Commerce faces rising AI bot activity, escalating DDoS attacks, and new fraud tactics (Akamai) From Biography to Backdoor: Tracking a DoNot (APT-C-35) Intrusion Targeting Bangladesh Military Personnel (Cyderes) Hewlett Foundation Announces New $100 Million Emerging Technology and Security Initiative (Hewlett Foundation) US charges two over laundering $43 million from investment fraud (Bleeping Computer) Hack Reveals Suno AI Music Generator Scraped YouTube, Deezer, and Genius (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
CISA warns of active SharePoint attacks. The NSA pushes coordinated vulnerability disclosure. ClickLock Stealer targets macOS. Splunk and Zoom patch critical flaws. Spirals ransomware strikes in under 24 hours. New Windows evasion techniques emerge. LabubaRAT poses as NVIDIA software. 23andMe settles over its 2023 breach. Plus, a look back at one of the most audacious data center heists ever pulled off. Our guest is Ryan Kalember, Chief Strategy Officer at Proofpoint, discussing why agentic AI is creating a new insider threat. Near, far, wherever you are…the scam must go on. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Ryan Kalember, Chief Strategy Officer at Proofpoint, and he is discussing why agentic AI is creating a new insider threat. Selected Reading CISA urges immediate SharePoint hardening as exploits mount (CSO Online) NSA joins CISA and Others in Releasing the Cybersecurity Information Sheet “Establishing a Coordinated Vulnerability Disclosure Program to Work with Security Researchers” (NSA) ‘ClickLock Stealer' Bypasses macOS Security With Social Engineering, Process Killing (SecurityWeek) Splunk, Zoom Patch Critical Vulnerabilities (SecurityWeek) New Spirals ransomware encrypts victim network in under 24 hours (Bleeping Computer) Bind Link Abuse: One Windows Feature, Many Ways to Blind Your EDR (Bitdefender) LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software (Blackpoint Cyber) 23andMe reaches $18 million settlement with states for massive breach (The Record) How a Gang of Thieves Pulled Off a Multimillion-Dollar Data Center Heist (The New York Times) Fake Céline Dion Paris Tickets Sold on Facebook and Ticketmaster Clones (Hackread) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Patch Tuesday. SonicWall urges immediate patching of actively exploited vulnerabilities. The White House launches an AI-backed vulnerability clearinghouse. The Air Force contends with widespread cybersecurity quarantines. The UK and EU blame Russia for last year's cyberattack on Poland's power grid. Meta faces accusations of AI-assisted layoffs. NATO allies collaborate in space. The Pentagon offers paid cyber apprenticeships. Spanish police dismantle a cybercrime and money-laundering network. Our guest is Clark Frogley, Global Head of Fraud at Quantexa and former FBI agent, discussing the fraud-as-a-service economy and what banks are missing. Grok Build users data is cloudy with a chance of uploads. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Clark Frogley, Global Head of Fraud at Quantexa and former FBI agent, as he is discussing the fraud-as-a-service economy and what banks are missing. Selected Reading Microsoft Patches a Record 570 Security Flaws (Krebs on Security) Adobe Patches Critical ColdFusion Vulnerabilities (SecurityWeek) Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow (SecurityWeek) ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell (SecurityWeek) Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates (SecurityWeek) SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now (Bleeping Computer) White House announces ‘Gold Eagle' AI clearinghouse for cyber vulnerabilities (Nextgov/FCW) Air Force network lockouts hit troops and civilians (Federal News Network) NATO Allies join forces to develop high-end space capabilities (NATO) EU and UK officially blame Russian spies for cyberattack on Poland's power grid (The Register) Meta used AI to target workers with medical conditions for layoffs, lawsuit claims (Reuters) Pentagon opens application window for paid cyber apprenticeships (DefenseScoop) Spanish Police take down €140 million cyber fraud ring, arrest four (Bleeping Computer) Musk promises purge after Grok Build caught sending entire repos to the cloud (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Treasury sanctions a VPN provider tied to ransomware. The Pentagon hits pause on CMMC audits. Critical flaws surface in Google Cloud's Dialogflow CX. Estée Lauder discloses a data breach. Mobile networks become a battlefield for tracking U.S. personnel. Australia calls out Big Tech over child safety. SAP patches critical bugs. CISA flags an actively exploited Cisco flaw. And the federal government accelerates AI investments. Our guest is Bogdan Botezatu, Senior Director, Threat Research and Reporting at Bitdefender, talking about Cyberthreats to Journalists and Influencers. AI costs savings come at a price. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Bogdan Botezatu, Senior Director, Threat Research and Reporting at Bitdefender, is talking about "Targeting the Messengers: Cyberthreats to Journalists and Influencers," their awareness campaign designed to address the escalating digital and reputational risks faced by media professionals in hostile environments. Selected Reading US sanctions VPN, malware providers for enabling ransomware attacks (Bleeping Computer) Pentagon announces 'immediate suspension' of CMMC Phase II mandates (Breaking Defense) Google Cloud Dialogflow CX vulnerability allowed AI agent hijacking | brief (SC Media) Estée Lauder Companies Reports Data Breach Exposing Health Records and SSNs (Beyond Machines) US military targeted in Iran war phone-tracking campaign (Financial Times) Australia finds serious gaps in Big Tech response to online child sexual abuse (Reuters) SAP warns of critical flaws in NetWeaver and Commerce Cloud (Bleeping Computer) CISA adds Cisco IOS flaw to known exploited vulnerabilities catalog | brief (SC Media) Federal AI Projects Get Priority in TMF Funding Dash (GovInfo Security) Companies Are Throttling Employees' AI Use Because It's Too Expensive (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
The U.S. and its allies warn of Russian cyber threats targeting critical infrastructure as Europe rolls out new sanctions. Apple sues OpenAI over alleged trade secret theft. Progress investigates a potential ShareFile security incident, Zimbra patches a critical flaw, and researchers uncover the new CrashStealer macOS malware. Plus, the EPA tests water utility resilience, scammers clone trusted news sites, and our Monday business briefing. Our guest is Brandon Karpf, from NTT, discussing the 11th Japan-U.S. Cyber Dialogue. Californians smash that delete button. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Brandon Karpf, friend of the show discussing the 11th Japan-U.S. Cyber Dialogue. Selected Reading US and allies warn of Russian critical infrastructure attacks (Bleeping Computer) EU sanctions Russian GRU military hackers over cyberattacks (Bleeping Computer) OpenAI Hardware Biz Built with Apple Secrets, Apple Says (Gov Infosecurity) Progress Software Warns of External Security Threat to ShareFile (Infosecurity Magazine) Zimbra Patches Critical Code Execution Vulnerability (SecurityWeek) When Hackers Cut the Internet, Will the Water Still Flow? (BankInfo Security) ‘A very good clone': news stories faked to lure victims to scam investment sites (The Guardian) CrashStealer: C++ macOS infostealer posing as crash reporter (Jamf) Business Briefing for 07.08.26 (N2K Pro Business Briefing) 322,000 Californians sign up to have data brokers delete their personal information (Mercury News) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Researchers track ransomware they say is getting GoshDarn sophisticated. Zimbra patches a critical vulnerability affecting its Classic Web Client. A sophisticated vishing campaign targeting Microsoft 365 accounts. GigaWiper combines espionage capabilities with multiple destructive payloads. The EU sues member states over lax cybersecurity. The NSA revives TAO. A Puerto Rican agency exposes roughly a million Social Security numbers. A former ransomware negotiator heads to prison for assisting BlackCat. Our guest is Maxim Zavodchik, Senior Director of AI Security Research at Akamai, with insights on the upcoming MCP specification. Bad Wifi leaves a trophy up for grabs. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest We are joined by Maxim Zavodchik, Senior Director of AI Security Research at Akamai sharing insights on new security risks that can arise from upcoming MCP specification. Selected Reading New Ransomware Exploits Malicious Driver to Remove Cybersecurity Protections (Infosecurity Magazine) Zimbra urges customers to patch critical web client XSS flaw (Bleeping Computer) Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers (SecurityWeek) GigaWiper Combines Multiple Malware for System-Level Sabotage (SecurityWeek) Commission preliminarily finds the addictive design of Instagram and Facebook in breach of the Digital Services Act (European Commision) European Patience With Cybersecurity Laggards Snaps (BankInfoSecurity) NSA revives 'Tailored Access Operations' name for elite hacking unit (The Record) A Puerto Rico Government Agency Exposed 1 Million Social Security Numbers (ProPublica) Third US Security Expert Sentenced to Prison for Helping Ransomware Gang (SecurityWeek) Thief posed as Wi-Fi fixing hero, then stole priceless trophy (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
GhostApproval puts AI coding assistants under the microscope. Microsoft fixes the RoguePlanet zero-day. More than 70 cybersecurity firms back a new AI Charter. An Ohio county may have paid a $1 million ransom. AssuranceAmerica discloses a breach affecting nearly seven million people. Australia bricks thousands of broadband routers. Israeli fintech Nayax reports a cyber incident. KDDI confirms a massive telecom data breach. A global anti-fraud operation leads to thousands of arrests. Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies explains the EU Cloud and AI Development Act. Slopfix fights fire with fire. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies discussing the EU Cloud and AI Development Act. Selected Reading GhostApproval Flaw Hits Six Major AI Coding Assistants (Infosecurity Magazine) Microsoft Patches RoguePlanet Defender Zero-Day That Grants SYSTEM Access (Daily CyberSecurity) New AI Security Charter Backed by Over 70 Cyber Firms (Infosecurity Magazine) County Government Reportedly Paid $1 Million to Cyber Extortion Group (SecurityWeek) AssuranceAmerica data breach exposes records of 6.9 million drivers (Bleeping Computer) Aussie gov't tells volunteers to throw out thousands of functioning test routers (Ars Technica) Nayax shares slide after fintech company reveals cloud security breach (Ctech) 12 Million Impacted by Data Breach at Japanese Telco KDDI (SecurityWeek) Chinese-Funded Interpol Cybercrime Crackdown Leads to 5,800 Arrests (Infosecurity Magazine) 'Slopfix' software team charges $10,000 a week to delete AI-generated code bloat — ironically, the team uses AI agents to trim messy repositories by up to 65% (Tom's Hardware) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Accenture confirms a data breach. An Australian telecom investigates a nationwide outage. It's shields up for the UK. CISA eyes September for its critical infrastructure reporting rule. NewsJunkie fakes CTV ad traffic. Agentic AI triggers EDR. CISA taps Mythos for vulnerability scans. Meta faces trillion dollar fines in state lawsuits. Our guest is Russ Anderson, COO and co-founder of RapidFort, sharing a coordinated industry effort to harden the world's most critical open source software against AI-enabled cyber threats. When it comes to breaches, mum's the word. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Russ Anderson, COO and co-founder of RapidFort, is sharing the Linux Foundation's Akrites initiative, a coordinated industry effort to harden the world's most critical open source software against AI-enabled cyber threats. Selected Reading Accenture confirms breach after hacker offers stolen data for sale (Bleeping Computer) Nationwide Telstra outage disrupts thousands, raises questions of foreign launched cyberattack (The Nightly) Britain plans to build autonomous AI 'Cyber Shield' to defend nation (The Record) CISA Eyes September Date for Final Cyber Incident Reporting Rule (MeriTalk) HUMAN Security Disrupts CTV Device Spoofing Operation "NewsJunkie" (Globe Newswire) When AI agents look like attackers: what behavioral telemetry tells us (SOPHOS) Space Force adds Relativity, Impulse Space to national security launch program. (Space News) CISA Deploys Anthropic's Mythos AI to Hunt Vulnerabilities in U.S. Government Code (Security Affairs) Mark Zuckerberg's biggest legal nightmare yet could cost Meta $1.4 trillion (The Independent) Most cybersecurity workers have been told to conceal a breach, report finds (Cybersecurity Dive) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
CERT/CC warns of an unpatched Tenda router backdoor. Adobe races to patch an actively exploited ColdFusion flaw. Canada pulls back the curtain on offensive cyber operations. Anthropic quietly removes hidden tracking from Claude Code. Chinese AI gains momentum as U.S. providers sweeten the deal. U.S. cloud firms challenge South Korea's new security rules. Microsoft's device telemetry helps unmask an alleged Scattered Spider hacker. And Spanish police arrest an alleged pro-Russia hacktivist.Orla Daly, CIO at Skillsoft, discusses if AI is already bypassing its own guardrails and why most organizations aren't ready. The stochastic parrot is back, and it's tired of being misquoted. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Orla Daly, CIO at Skillsoft, discusses if AI is already bypassing its own guardrails and why most organizations aren't ready. Selected Reading Hidden Tenda Router Backdoor Grants Admin Access, No Patch Available (Security Affairs) Hackers Exploit Maximum Severity Adobe ColdFusion Flaw (Infosecurity Magazine) Canadian spy agency says it hacked drug traffickers, extremists, and a ransomware gang last year (TechCrunch) Secret Claude tracker shocks users after Anthropic's anti-surveillance stance (Ars Technica) Chinese AI models are gaining ground with U.S. companies as OpenAI, Anthropic costs surge (CNBC) AI Giants Are Handing Out Tons of Free Computing Power to Grab Startup Share (Wall Street Journal) U.S. Big Tech raises concerns over Seoul's proposed cloud security rules (Korea JoongAng Daily) Microsoft device telemetry key to unmasking alleged Scattered Spider hacker (iTnews) Spain collars alleged pro-Russia hacktivist after FBI tip-off (The Register) What Emily Bender Really Meant by "Stochastic Parrots" (IEEE Spectrum) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
The FBI disrupts a major residential proxy service. Attackers exploit Fortinet firewalls to target UK officials. European lawmakers call for a spyware investigation. A new macOS infostealer masquerades as a clipboard manager. Prompt injection campaigns targeting AI agents through malicious websites and SEO poisoning. Researchers trick Claude into remote code execution. AI's strain on the power grid is complicated. Monday business briefing. Our guest is Gabi Reish, VP Product, Threat Intelligence & Exposure Management at Bitsight, sharing insights on how cybercriminal activity is shifting. Anime and AI meet adolescent antics. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Gabi Reish, VP Product, Threat Intelligence & Exposure Management at Bitsight, sharing insights on how cybercriminal activity is shifting. You can learn more here. Selected Reading FBI Seizes NetNut Domains as Google Disrupts 2M Device Proxy Network (HackRead) Russian hackers steal government logins (The Telegraph) Lawmaker Probing Pegasus Spyware Infected Using Same Malware (BankInfo Security) PamStealer: a Rust-based macOS infostealer that validates credentials through PAM (Jamf) Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments (SecurityWeek) Red teamers turned Claude Desktop into a double agent to do their evil bidding (The Register) How Data Centers Grid Instability Threatens Reliability (IEEE Spectrum) Quantifind has secured $200 million in a funding round led by Summit Partners. (N2K Pro Business Briefing) Japanese teen arrested for cyberattack that unsubscribed over 46,000 anime accounts (The Straits Times) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
In this special edition of CyberWire Daily's 10th anniversary series, N2K CyberWire's Maria Varmazis and Dave Bittner discuss 10 years of vulnerabilities, zero‑days, and hardware flaws. Together they reflect on the last decade of cybersecurity vulnerabilities, exploring key shifts, landmark incidents like WannaCry and Log4Shell, and the evolving landscape shaped by hardware issues and AI. Join Maria and Dave as they discuss how these changes impacted security practices and the importance of vigilance in a rapidly interconnected world. Learn more about your ad choices. Visit megaphone.fm/adchoices
OpenAI considers an equity plan to share AI wealth with the public. Cisco confirms active exploitation of its unified CM platform. Researchers discover autonomous ransomware. The Vect ransomware operation partners with TeamPCP. The FortiBleed credential-harvesting campaign is linked to ransomware attacks. Veil#Drop stealthily deploys the PureLog Stealer. Scammers target small businesses with fake law enforcement emails. Apple's Hide My Email feature…doesn't. An alleged Scattered Spider member is extradited to the United States. Our guest is Ben Yelin, Dave's Caveat cohost, on the Supreme Court's geofence warrants ruling. Microsoft's quantum claims leave physicists in two states at once. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies discussing the Supreme Court ruling on geofence warrants. If you enjoyed this conversation, you can check out Ben on Caveat. Selected Reading OpenAI in talks to give Trump administration a 5% stake in the company, FT reports (CNN Business) Cisco finally confirms attackers exploiting Unified CM flaw (Bleeping Computer) Sysdig Details JADEPUFFER, the First Documented Agentic Ransomware Operation (HackRead) Vect and TeamPCP partner for ransomware campaigns (Sophos) FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks (SecurityWeek) VEIL#DROP: Blogspot-Hosted PowerShell Loader (Secureonix) Fake Interpol investigation emails target small businesses with ransomware (Bitdefender) Apple ‘Hide My Email' Vulnerability Reveals Peoples' Real Email Addresses (404 Media) Alleged Member of Criminal Cyber Hacking Group “Scattered Spider” Arrested in Finland and Extradited to the United States (U.S. Department of Justice, Office of Public Affairs) Is there a new quantum processor or is Microsoft lying? (Mathew Ingram) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
The US restores exports of Anthropic's most advanced AI models. Adobe and Citrix rush out critical patches. RustDuck emerges as a fast-evolving DDoS threat. The Gentlemen raise the stakes with a new EDR-killing exploit. Rocket lab bets big on Iridium. Researchers unveil browser-only ransomware. New Zealand faces questions about its cyber readiness. Iran's long-running cyber espionage campaign is back in the spotlight. Our guest is Donald Codling, CISO and senior advisor to REGO on cybersecurity and data privacy matters, to discuss the importance of tying security by design to psychological safety and digital trust. VIP backstage access, courtesy of Claude. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Donald Codling, CISO and senior advisor to REGO on cybersecurity and data privacy matters, to discuss the importance of tying security by design to psychological safety and digital trust. Selected Reading Fable and Mythos: Anthropic says US lifts export ban on its advanced AI tools (BBC) Adobe patches seven max severity ColdFusion, Campaign flaws (Bleeping Computer) RustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow (SecurityAffairs) Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb' Attack (SecurityWeek) Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs (Expel) Rocket Lab to Acquire Iridium in Historic Deal, Creating A Fully Vertically Integrated Space Powerhouse Primed for Growth (Globe Newswire) Ransomware that runs inside your browser tab, where antivirus cannot see it (Suriq) Three major cybehttps://suriq.io/blog/browser-only-ransomware-file-system-accessrattacks have raised alarms about New Zealand's security (RNZ) Arrest of Iranian Hacker Spotlights Iran's Movement into Economic Espionage and IP Theft (Zero Day) Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
The Supreme Court limits geofence warrants. DHS moves to expand CISA. The State Department offers $10 million for Russian hackers. A legal theory could reshape EU-U.S. data sharing. Plus, cyberattacks hit D.C. housing, Oracle and SimpleHelp flaws face active exploitation, malware lingers on Japanese military networks, and stolen Apple supplier data surfaces online. John Cannava, CIO at Ping Identity, discusses how identity threats don't go on holiday. The Secret Service dial down the risk on BYOD. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by John Cannava, CIO at Ping Identity, as he discusses how identity threats don't go on holiday: how attackers take advantage of these high-traffic moments to blend in with normal user behavior, and what needs to change to better protect fans of major events like this summer's World Cup, and identity threats in travel at large. Selected Reading Supreme Court says police need a warrant to obtain Google location data (Washington Post) DHS Eyes 600 New Cybersecurity Hires, New Director for CISA (BankInfo Security) US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp (The Record) US Supreme Court just blew up EU-US Data Transfers (NOYB) DC Housing Authority hit by cyberattack, website down (WJLA) Exploitation of Recent Oracle E-Business Suite Vulnerability Begins (SecurityWeek) USB drives carrying China-linked malware infected Japanese military networks for nearly a year (Bitdefender) A forged login key unlocks SimpleHelp servers, and a new stealer is raiding cloud and AI credentials (SURIQ) Apple iPhone 18 Pro supplier list, parts and photos exposed in Tata data leak (Reuters) Even the Secret Service won't use company-issued phones (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
The White House keeps frontier AI models on a short leash. Russian threat actors increasingly target secure messaging platforms. DirtyClone is a high-severity Linux kernel privilege escalation flaw. An investigation claims federal websites are violating privacy rules. Microsoft dismantles a sophisticated malicious browser extension campaign. Setting up a GitHub repository could trick AI coding agents into executing malicious payloads. The DOJ shuts down illegal World Cup streamers. An Anonymous-linked hacker gets 18 months for website defacement. Monday business briefing. Dylan Sandlin, Program Manager for Digital and Cybersecurity Content at the National Association of Corporate Directors (NACD), discusses cyber risk as a board concern. In healthcare AI, patient privacy needs a second opinion. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Dylan Sandlin, Program Manager for Digital and Cybersecurity Content at the National Association of Corporate Directors (NACD), discussing cyber risk as a board concern. If you're interested in learning more about NACD, be sure to check out their Director's Handbook on Cyber-Risk Oversight. Selected Reading Washington pushes AI into an export-control era as rivals rush to fill the gap (Metacurity) FBI and CISA Warn Russian Hackers Stealing Verification Codes and Account PINs From Signal Users (GB Hackers) 'DirtyClone' Linux Kernel Vulnerability Leads to Root Access (SecurityWeek) ‘It's dangerous and it's going to erode trust': redesign of US government websites stokes surveillance fears | Trump administration (The Guardian) StegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two Years (SecurityAffairs) Clean GitHub repo tricks AI coding agents into running malware (Bleeping Computer) US seizes hundreds of FIFA World Cup illegal streaming domains (Bleeping Computer) Anonymous-Linked Hacktivist Aubrey Cottle Jailed Over Texas GOP Cyberattack (Hackread) Accenture acquires Dragos, runZero, and NetRise for more than $4 billion. (N2K Pro Business Briefing) Medical diagnosis AIs can be tricked into telling whose data trained them (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Tata Electronics and Bajaj Auto continue recovery from cyberattacks. FCC tightens undersea cable rules to bolster national security. CISA warns of actively exploited PTC vulnerability. Gamaredon expands toolkit, hides behind legitimate services. Iran-linked hackers turn public warning systems into psychological weapons. Threat actors target critical infrastructure across Southeast Asia. DCloud framework behind global scam economy. Polish police disrupt SIM-swapping gang. French statistics agency reports cyberattack affecting nearly 13,000 staff. Our guest is Michael Fanning, CISO at Splunk, discussing how AI doesn't create problems, it exposes them. And an open-book exam for hackers. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Michael Fanning, CISO at Splunk, discussing how AI doesn't create problems, it exposes them. Selected Reading Apple supplier Tata tightens internal controls after data breach, sources say (Reuters) Bajaj Auto resumes normal operations as cyberattack probe continues (Storyboard18) FCC passes new cybersecurity rules for emergency systems, undersea cables (CyberScoop) U.S. CISA adds Cisco and PTC Windchill and FlexPLM flaws to its Known Exploited Vulnerabilities catalog (SecurityAffairs) Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances (ESET) A Cyber-Psychological Operation: Iran-Linked Attackers Target Warning Systems (Claroty) CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure (Unit 42) From San Pedro to Salinas: How a Chinese Framework “DCloud Uni-App” Powers a Global Scam Economy (Infoblox) Poland busts SIM-swapping gang tied to millions in crypto theft (BleepingComputer) France's statistics department reports cyberattack on staff data (Reuters) UK school's network left wide open for invasion, student found (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices