POPULARITY
AI goes to war. Iranian strikes leave AWS data unrecoverable. OpenAI discloses more model misbehavior. Researchers uncover 16 Wireshark vulnerabilities. TrustSink turns Entra authentication into a password trap. RatHat raids Android credentials. The FBI takes down a DDoS-for-hire service. A data broker loses its domains. U.S. Cyber Command names a new AI chief. Ethan Cook is joining Dave Bittner and Ben Yelin to discuss the industry-proposed and administration-opposed AI slowdown. CISA's field of schemes. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today, Ethan Cook, N2K's lead analyst, joins Dave Bittner and Ben Yelin for a discussion about the industry-proposed and administration-opposed AI slowdown, exploring the policy debate and what it could mean for the future of AI. If you enjoyed this conversation, be sure to check out the full interview on Caveat here. Selected Reading The era of AI warfare has arrived (Financial Times) Iran strikes on Amazon data centers caused permanent loss of customer data (Ars Technica) OpenAI Discloses Six New Incidents of ‘Concerning' A.I. Behavior (The New York Times) AISLE Discovers 16 CVEs in Wireshark, the World's Most Popular Network Protocol Analyzer (AISLE) TrustSink: How a Rogue External MFA Provider Steals Passwords (Varonis) RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts (Zimperium) US takes down NightmareStresser DDoS-for-hire platform (Bleeping Computer) Data Broker Radaris Loses Domains in Privacy Fight (Krebs on Security) Former NGA Executive Ronzelle Green Named USCYBERCOM Chief AI Officer (ExecutiveGov) CISA releases Cyber Decoys guide detailing tripwires, honeytokens to strengthen critical infrastructure detection and response (Industrial Cyber) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. We start with some follow-up from Gordy, who has questions about a fairground contest collecting personal information, plus an update on Joe's backpack. Joe covers the takedown of Xinbi Guarantee, an illicit marketplace allegedly providing services to scam centers, including money laundering, fake investment sites, and other tools for fraud. Maria looks at QR-code scams and a growing wave of rental scams on TikTok, where fake listings use stolen property photos, below-market prices, and upfront fees to target prospective renters. Dave explores a report on how hundreds of ads promoting AI “nudify” tools and other abusive content were able to reach users through Meta's advertising system. Our Catch of the Day comes from Tim, who received a suspicious board-position offer that appears to have scraped details directly from his LinkedIn profile—and somehow offered him a seat on the board of his own company. Resources and links to stories: U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto See a QR code parked somewhere? Don't scan it…yet! 68% of TikTok rental listings carry scam warning signs Meta Failed to Catch Hundreds of AI Child Abuse Ads. Some Included Images of Real Kids Have a Catch of the Day you'd like to share? Email it to us at hackinghumans@n2k.com.
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. We start with some follow-up on Joe's chicken coop, which apparently looks amazing—and we may even get a little into the mechanics behind it. Dave looks at the growing scam crisis in the U.S., including how victims are often targeted a second time by recovery scammers after losing money in the first scam. Joe covers a massive identity-theft operation allegedly offering more than 153 million stolen driver's license records for sale on the dark web, with investigators working to determine where the data came from. Maria explores a multimillion-dollar romance and investment scam in which a man allegedly posed as an NFL player, using fake identities, relationships, and phony investment accounts to defraud at least 26 women. Our Catch of the Day comes from a listener who clicked a suspicious Calendly link and lived to tell the tale. Resources and links to stories: Scams in the US are at a record high. Yet most victims get no help and some end up losing even more Microsoft Plugs Nearly 1,000 Security Holes Man Posing as San Francisco 49er Charged with Defrauding Over Two Dozen Women Out of More than $1.3 Million "It's hard to feel bad when it's as easy as just Googling it": Jason Kelce left stunned after fake 49er Daejon Love's alleged $1.3M+ romance scam Clicked on Phishing Link From “Calendly” Have a Catch of the Day you'd like to share? Email it to us at hackinghumans@n2k.com.
Welcome in! You've entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today's most interesting threats. Your host is Selena Larson, Proofpoint intelligence analyst and host of their podcast DISCARDED. Inspired by the residents of a building in New York's exclusive upper west side, Selena is joined by her co-hosts N2K Networks Dave Bittner and Keith Mularski, former FBI cybercrime investigator and now Chief Global Ambassador at Qintel. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. This week, Dave, Selena, and Keith explore the pros and cons of allowing select U.S. companies to conduct offensive cyber operations under strict government guardrails. They discuss what the proposed framework could mean for private-sector security researchers, how researchers have already been operating in this space for years, and where the line between defense and offense gets blurry. They also look at how adversaries such as China and Russia use proxy companies and other private-sector entities to conduct cyber operations—and consider whether giving trusted U.S. companies similar capabilities could strengthen cyber defenses or create new risks.
In this Special Episode, Maria Varmazis and Dave Bittner are joined by friend of the show, Brandon Karpf, to unpack a new bipartisan congressional investigation into the lingering presence of Chinese state-owned telecommunications companies inside U.S. internet infrastructure. The House Select Committee on China says China Mobile, China Unicom, and China Telecom remain deeply embedded in American networks even after federal regulators denied or revoked their authority to provide certain telecommunications services over national security concerns. The investigation found that restrictions imposed by the FCC limited what the companies could sell, but did not necessarily remove their equipment, network connections, or commercial relationships from the U.S. internet ecosystem. Links to stories: Stranger Pings: Chinese Telecom Companies Infiltrate U.S. Infrastructure
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. We start with some follow-up from Anne, who writes in to share how much she enjoys the show, how she used the “Shields Up” message with her coworkers, and—most importantly another chicken update! Maria covers a pair of MyChart scams that use fake medical results and bogus Medicare giveaways to steal credentials, personal information, and payment details. Joe looks at two scams—one targeting a business through a massive Amazon fraud scheme and another warning residents about fake invoices designed to steal their money. Dave explores the surprising value of simply replying to a wrong-number text, as scammers use responses to identify active phone numbers and find potential targets for increasingly sophisticated fraud campaigns. Our Catch of the Day promises a piece of a mysterious $25 million overpayment. All you have to do is reply with your phone number and your desired cut—what could possibly go wrong? Resources and links to stories: Health systems warn patients of MyChart phishing scam Woman sentenced after nearly $10M Amazon scam funds luxury lifestyle South Haven warns of invoice scam targeting residents Your polite reply to that text is worth $2 on the dark web Have a Catch of the Day you'd like to share? Email it to us at hackinghumans@n2k.com.
In this episode, Maria Varmazis and Dave Bittner from N2K Cyberwire get back together to discuss the evolution of advanced persistent threats (APTs), threat actor landscape, attribution changes, and the future of cyber espionage over the past decade. Join Dave and Maria as they explore how geopolitical factors, organizational professionalism, and emerging technologies like AI are shaping cybersecurity threats. Together, they talk about: The shift in attribution practices over the last 10 years. The role of nation states and organized crime in cyber threats. The impact of AI and emerging technologies on cyber warfare. The challenges of naming and shaming threat groups. The professionalization and organizational evolution of APT groups.
A judge rules the Trump administration illegally labeled Anthropic a national security risk. The White House moves to keep foreign technology out of U.S. power systems. OpenAI rallies a global cyber defense push as its own AI agents exploit a Linux vulnerability. Researchers uncover a new speculative-execution attack and hidden implants in Chinese-made routers. A fake voicemail campaign slips past email defenses. PaperCut faces an exploited zero-day. And ServiceNow patches three maximum-severity flaws in its AI Platform. Maria Varmazis and I look back at a decade of emerging threat actors and APTs. NSA sends out a covert save-the-date. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today, as we continue celebrating the CyberWire Daily's 10th anniversary, Maria Varmazis and Dave Bittner look back at a decade of emerging threat actors and APTs. Enjoyed the conversation? Be sure to tune in Sunday for a special edition featuring the full discussion. Selected Reading Trump Administration's Blacklisting of Anthropic Was Illegal, Judge Rules (The New York Times) White House bans foreign-made equipment for power generation over cyber backdoor concerns (The Record) Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge (SecurityWeek) A call for collective action on cyber defense (OpenAI) New type of attack can slip past the defenses in your computer's processor (MIT News) Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign (Infosecurity Magazine) OpenAI Agents Exploited Linux Kernel Flaw on Company's Own Systems (SecurityWeek) Hundreds of AI agents went rogue in OpenAI's Hugging Face hack (POLITICO) PaperCut Releases Emergency Patch for Exploited Zero-Day (SecurityWeek) ServiceNow warns of three max severity security vulnerabilities (Bleeping Computer) Chinese Implants in the Supply Chain (VulnCheck) Exclusive: NSA to host a hacker reunion in bid to rebuild secretive unit (The Record) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
This week, we're celebrating a pretty big milestone: 400 episodes of Hacking Humans! Along the way, we've shared hundreds of stories, scams, lessons, and plenty of memorable Catch of the Days—and we couldn't have made it this far without you. To everyone who has listened, written in with a story, sent us a Catch of the Day, or simply learned to be a little more suspicious of that weird text message: thank you for being part of 400 episodes of Hacking Humans. We're glad you're here to celebrate with us. And now, after 400 episodes, there's really only one thing left to do: get back to the scams. This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. Dave covers celebrity podcast impersonation scams, where fraudsters use personal details, convincing AI-generated personas, and fake production teams to build trust with potential guests. Maria looks at a rental scam that cost a San Francisco renter $18,600 after scammers copied a legitimate apartment listing, showed him the property, and convinced him they were the landlord. Joe discusses new research showing that younger people can be just as vulnerable to scams as older victims, particularly when they're navigating things like jobs, apartments, online shopping, and their first financial accounts. Our Catch of the Day comes from a scammer who apparently discovered the hard way that sometimes the scammer can get scammed. Resources and links to stories: Inside the Fake Celebrity Podcast Scam Fooling Hollywood They escaped south-east Asia's scam compounds. Then they realised they were still trapped How a ‘savvy' S.F. renter lost more than $18K in an elaborate real estate scam Jacksonville woman sues VyStar, alleges credit union failed to properly investigate $42K impersonation scam Teens targeted for scams Scammer got scammed Have a Catch of the Day you'd like to share? Email it to us at hackinghumans@n2k.com.
Medusa's reach grows. Cl0p expands its victim list. The DOJ charges 17 alleged Iranian hackers. CISA sounds the alarm on four exploited vulnerabilities. TWINLOOT hides in plain sight inside Microsoft 365. Maria Varmazis shares the latest from the space-cyber realm as Ukraine strikes Russia's satellite nerve center. The FDA considers guardrails for AI medical devices. Expired credit cards get an unexpected second life. A disgruntled contractor heads to prison. Dave Bittner sits down with Brian Vecci, Field CTO at Varonis, at Black Hat USA to discuss how AI is calling your security bluff. Highway hijinks meet high-tech hardware. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest At Black Hat USA, Dave Bittner sat down with Brian Vecci, Field CTO at Varonis, as they discussed how AI is calling your security bluff. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading CISA: Medusa ransomware hit over 500 critical infrastructure orgs (Bleeping Computer) US charges Iranians for sprawling hacking campaign on government agencies, universities (The Record) Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign (SecurityWeek) CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities (SecurityWeek) New TWINLOOT Malware Steals Windows Passwords Via Fake Lock Screen (Hackread) Ukraine says it hit Russian rocket centre linked to Starlink-style network (CNBC) FDA Weighing Possible Regs for GenAI Medical Devices (GovInfo Security) Expired credit cards revived by researchers to make unauthorized payments (The Register) Prison for data analyst who tried to extort $2.5 million from his employer (Bitdefender) ‘The Worst I've Ever Seen': Cargo Thefts Have Turned Violent in Pursuit of AI Hardware (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
In this special edition from Black Hat, Dave Bittner sits down with Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps, to explore how frontier AI models are changing the way defenders approach cybersecurity. The conversation moves beyond the hype to examine responsible AI deployment, AI red teaming, reducing noise in security workflows, and the balance between advanced models and human expertise. They also discuss OpenAI's Trusted Access for Cyber program and what it takes to give security practitioners access to powerful AI capabilities while managing the risks of misuse. Check out the full video here.
As AI products proliferate, they continue to introduce new concerns, which have subtly eroded trust in imagery and content created by space-based infrastructure. In this week's episode, host Maria Varmazis sits down with Dave Bittner and Brandon Karpf to look at Google's troubled implementation of Nano Banana 2 in Google Earth. The incident raises larger concerns regarding how AI systems are becoming deeper ingrained into everyday life despite their ability to be misused and spread misinformation. Like what you heard? Be sure to subscribe to our free Signals and Space Briefing, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space Is there a topic or person you'd like to hear on our show? You can send your questions and feedback to space@n2k.com. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.
As AI products proliferate, they continue to introduce new concerns, which have subtly eroded trust in imagery and content created by space-based infrastructure. In this week's episode, host Maria Varmazis sits down with Dave Bittner and Brandon Karpf to look at Google's troubled implementation of Nano Banana 2 in Google Earth. The incident raises larger concerns regarding how AI systems are becoming deeper ingrained into everyday life despite their ability to be misused and spread misinformation. Like what you heard? Be sure to subscribe to our free Signals and Space Briefing, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space Is there a topic or person you'd like to hear on our show? You can send your questions and feedback to space@n2k.com. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.
President Trump deputizes private-sector companies to target cybercriminals. The LiteLLM supply-chain attack exposed credentials belonging to thousands of organizations. Data-theft campaign targets misconfigured Salesforce and ServiceNow instances. Hackers deploy AI agents to breach Taiwanese government systems. CISA mandates urgent patch for actively exploited Cisco firewall vulnerability. Nightmare Eclipse publishes yet another Windows zero-day exploit. On our Industry Voices segment, Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps, discuss frontier models and the future of cyber defense. And please do not reply. Seriously. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices segment, Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps, speak with Dave Bittner at Black Hat about frontier models and the future of cyber defense, including responsible AI deployment, red teaming, reducing security noise, and the evolving role of human expertise in AI-assisted defense. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading Trump turns to private sector in offensive hacking operations memo (CyberScoop) Terabytes of credentials leaked in massive supply-chain attack (Ars Technica) "City-Forum" data-theft attacks target Salesforce, ServiceNow portals (BleepingComputer) 'Near-autonomous' AI agents attack Taiwan's nuclear safety agency (The Register) Cisco says software vulnerability could let hackers crash firewalls (Cybersecurity Dive) Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows (The Register) Sensitive Info Goes Into ‘No Reply' Emails Constantly. This Guy Sees It All (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
We got your Patch Tuesday notes. Attackers target Microsoft SharePoint vulnerability following PoC release. Cyberattack on CEVA Logistics causes ongoing supply chain disruptions. Wesco confirms data breach following extortion claims. Akira ransomware bypasses EDR in Safe Mode. California announces AI cybersecurity fund. N2K's Lead Analyst Ethan Cook shares about cyber weapons for space. Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain. And fasten your seatbelts and ignore the fake Wi-Fi. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain, including AgentBaiting, where fake AI Skills and MCP servers were used to deliver malware, and hidden instructions that can influence AI agents. If you enjoyed the conversation, be sure to check out the full interview here. Selected Reading Microsoft and Adobe Patch Tuesday, August 2026 Security Update Review (Qualys) Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack (Check Point Research) Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability CSO Online ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact (SecurityWeek) Hackers leverage new Microsoft SharePoint exploit in attacks (BleepingComputer) The CEVA Logistics data breach is having major knock-on effects across Europe - here's what we know (TechRadar) Wesco confirms security incident after ExfilSquad claims data theft (BleepingComputer) Akira Hits Safe Mode: Ransomware Rebooting Around EDR (Huntress) California Building ‘AI Cyber Defense Fund' to Protect Critical Infrastructure From Hackers (Gizmodo) Laser weapons for space? US officials see threat, opportunity (BREAKING DEFENSE) DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Poland's CERT describes winter cyberattack against heat-and-power plant. Russian military hackers target Ukrainian IT workers in fake recruitment scheme. Chinese IP connections spark security review in UK Navy drones. US and South Korea warn of “Gunra” ransomware gang with North Korean ties. OpenAI mandates strict security controls for its new cybersecurity model. Record-breaking DDoS attacks surge in H1 2026. Data-scraping AI extension returns to the Chrome Web Store. Dave Bittner sat down with Stephen Harrison, VP of Product at Abnormal AI at Black Hat USA to discuss "The Identities Your Security Stack Is Ignoring." And no pain, no gain, no authorization. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices, Dave Bittner sat down with Stephen Harrison, VP of Product at Abnormal AI at Black Hat USA to discuss "The Identities Your Security Stack Is Ignoring." If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading Hackers breached a small Polish energy plant via private APN last year (BleepingComputer) Russian military hackers pose as recruiters to target Ukrainian IT workers (The Record) Cyber vulnerability sweep picks up Royal Navy drones sending data to China (The Register) U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang (CyberScoop) OpenAI's Upcoming Astra Model Raises Autonomous Cyberattack Concerns (SecurityWeek) Cloudflare DDoS Threat Report H1 2026 (Cloudflare) Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities (SecurityWeek) AI assistant hacks gym website in first known Australian autonomous cyber attack (ABC News) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Researchers find that only a quarter of AI-generated patches are fully successful. Ransomware attacks exploit critical N-able flaw. Atlassian fixes critical flaw in Rovo AI. LexisNexis disables some services following suspicious activity. US Senate confirms Adam Cassady as cyber ambassador. Meta ordered to pay an additional $567 million in child safety case. Water sector cyberattacks expand to new states. We got your Monday Business Briefing. On our Industry Voices, Dave Bittner sits down with Mujtaba Hamid, EVP, Product and Strategy at Booz Allen Hamilton at Black Hat discussing AI Speed Cyber Defense. And scammers set sail on The Odyssey. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices, Dave Bittner sat down with Mujtaba Hamid, EVP, Product and Strategy at Booz Allen Hamilton at Black Hat USA, discussing AI Speed Cyber Defense. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading More than half of AI-generated patches are broken (CyberScoop) China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns (The Record) Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data (SecurityWeek) LexisNexis shuts down services after suspicious activity on servers (BleepingComputer) US cyber ambassador nominee Cassady confirmed in Senate (The Record) Meta Ordered to Pay $567 Million in New Mexico Child Safety Case (New York Times) New Jersey, Alabama Join States Targeted in Water Cyberattacks (Securityweek) Business Breakdown (N2K) ‘Watch The Odyssey for free online': scam targets film fans with fake streaming sites (The Guardian) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. We start with some follow-up after a listener asks Joe to finally reveal the backpack that's become a recurring character on the show—and whether it's really as airport-infeding as everyone says. Joe covers Myanmar's approval of the death penalty for convicted scammers and shares a real-world fraud case involving forged Little Debbie snack deliveries that shows scams don't always happen online. Maria explores the rise in foreclosure rescue and equity-stripping scams, where fraudsters target financially vulnerable homeowners and attempt to steal their money—or even their homes. Dave breaks down new research showing how AI-powered phone farms are making it easier than ever for scammers to automate fraud, manage hundreds of fake accounts, and scale their operations with minimal technical skill. Our Catch of the Day is on a scam-baiting exchange featuring an unforgettable tale of a supposed two-timing "Barb Johnson" that quickly spirals into absurdity. Resources and links to stories: Kitchen Sink Backpack Giant Backpack Your Backpack Got Worse On Purpose Burma approves death penalty for scammers months after FBI's $8 billion crypto crackdown Little Debbie snack fraud investigation leads to arrest of West Virginia man, who allegedly forged records for deliveries that never happened As foreclosures increase, so do warnings about some self-proclaimed 'home savers' Researchers Warn of AI-Enhanced Phone Fraud Ecosystem That Twotiming B**ch Barb Johnson Have a Catch of the Day you'd like to share? Email it to us at hackinghumans@n2k.com.
Welcome in! You've entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today's most interesting threats. Your host is Selena Larson, Proofpoint intelligence analyst and host of their podcast DISCARDED. Inspired by the residents of a building in New York's exclusive upper west side, Selena is joined by her co-hosts N2K Networks Dave Bittner and Keith Mularski, former FBI cybercrime investigator and now Chief Global Ambassador at Qintel. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. This week, Today, while Keith is off, Dave and Selena kick off a back-to-school special, exploring the cyber threats students, parents, educators, and universities should have on their radar. They examine the rise in job scams targeting university communities, discuss recent espionage activity aimed at higher education institutions in the U.S. and Canada, and look at how cybercriminals prey on younger audiences through online games, YouTube, and social media. From fake game cracks delivering information stealers to sextortion schemes targeting teens, they break down the tactics attackers are using and share practical advice for staying safe as the new school year begins. Sources: Job Scams Using Bioscience Lures Target Universities One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation
Welcome in! You've entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today's most interesting threats. Your host is Selena Larson, Proofpoint intelligence analyst and host of their podcast DISCARDED. Inspired by the residents of a building in New York's exclusive upper west side, Selena is joined by her co-hosts N2K Networks Dave Bittner and Keith Mularski, former FBI cybercrime investigator and now Chief Global Ambassador at Qintel. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. This week, Today, while Keith is off, Dave and Selena kick off a back-to-school special, exploring the cyber threats students, parents, educators, and universities should have on their radar. They examine the rise in job scams targeting university communities, discuss recent espionage activity aimed at higher education institutions in the U.S. and Canada, and look at how cybercriminals prey on younger audiences through online games, YouTube, and social media. From fake game cracks delivering information stealers to sextortion schemes targeting teens, they break down the tactics attackers are using and share practical advice for staying safe as the new school year begins. Sources: Job Scams Using Bioscience Lures Target Universities One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation
In this special edition, guest Yan Shoshitaishvili, Associate Professor, University of Arizona, joins host Dave Bittner to share a preview of his Black Hat USA 2026 keynote "Vulnerability Research in the Agentic Age." Join Yan and Dave to hear insights on the evolution of vulnerability research, the impact of AI and LLMs on cybersecurity, and the future of human expertise in the field. If you are heading to Black Hat, check out Yan's session on Thursday, August 6 at 9:15 AM.
The AI industry spent the week arguing with itself, which is honestly the healthiest thing it's done in years. One coalition led by Nvidia begged regulators not to slow down open AI models, while more than 1,100 AI workers signed another letter asking regulators to do exactly that. Anthropic warned about bioweapons, OpenAI admitted the four-hour workweek isn't happening after all, and Microsoft's Satya Nadella reminded everyone that building your entire business on someone else's AI is a fantastic way to outsource your own brain. In other words, the people selling the future still can't agree on what they're selling, except that you'd better buy it fast.Meanwhile, the AI bubble keeps demanding sacrifices. Patreon, BuzzFeed, and Uber all swung the layoff axe while insisting AI isn't replacing humans... it's just reorganizing them out of a paycheck. Nvidia is floating another three-quarters of a trillion dollars in infrastructure deals that have people muttering "AI subprime mortgage crisis," China has discovered there's money in renting your face to AI companies, and the U.S. is carving data centers out of pollution rules because apparently acid rain is a small price to pay for chatbot dominance. Add in ChatGPT suddenly refusing to imitate famous authors, researchers discovering AI coding assistants are happily installing malware if you ask nicely, and Meta launching an ad campaign about the wonders of AI that somehow forgets to mention what any of those wonders actually are.Elsewhere in Tech Hell™, eBay finally paid the price for its executives' unhinged harassment campaign involving pig masks and live insects, Elon is shopping The Boring Company while promising money won't matter in the AI utopia of 2036, and a traveler is headed to court after allegedly triggering GrapheneOS's "duress PIN" during a border search. We also hit Media Candy with Star Trek: Strange New Worlds, Silo, Blade Runner 2099 and Neuromancer, celebrate Dave Bittner's birthday, marvel at Jason's ever-growing Boneyard of dead websites, and somehow end up discussing thermal cameras, piano repair, and old-man bladder supplements. Because that's what happens when Gen X gets older - we just add more tabs instead of closing the old ones.Sponsors:DeleteMe - Get 20% off your DeleteMe plan when you go to JoinDeleteMe.com/GOG and use promo code GOG at checkout.StoryBlocks - For a limited time, they're offering 15% off any annual plan at storyblocks.com/gogPrivate Internet Access - Go to GOG.Show/vpn and sign up today. For a limited time only, you can get OUR favorite VPN for as little as $2.03 a month.SetApp - With a single monthly subscription you get 240+ apps for your Mac. Go to SetApp and get started today!!!1Password - Get a great deal on the only password manager recommended by Grumpy Old Geeks! gog.show/1passwordShow notes at https://gog.show/757Watch on YouTube at https://youtu.be/Sii_nodESkcSHOW NOTESEBay and Former Execs Will Pay $56 Million to Couple They Tormented With Bloody Pig MasksAs US weighs response to Chinese AI, industry urges against broad open-weight restrictionsAI researchers call for new tools that can slow automated model developmentOver 1,100 AI workers sign letter asking US to support tools that 'pace the frontier of automated AI development'Anthropic's Dario Amodei responds: doesn't oppose open-weight models, but fears Chinese AIAmodei Denies Anthropic Supports Open-Weight AI Ban, Warns of China RisksSam Altman said AI hasn't led to 4-hour workweeks because people are competitiveSam Altman Shuts Down Hopes of an AI-Led 4-Day Workweek Anytime SoonOpenAI Proposes 32-Hour Pilot Incentives for EmployersSatya Nadella says companies that trust one AI for everything may not survive Microsoft CEO Satya Nadella warns companies relying on one AI model may not surviveOpenAI's rogue hacking incident was a warning shot. Will it be a wake-up call to finally create AI safety regulation?Behind the Curtain: AI godfathers converge on regulationsPatreon is laying off 20 percent of its staffAI Mania Is Eviscerating Global Decision-MakingBuzzFeed Lays Off 33 Percent of Remaining Staff After Bizarre Pivot to AIUber lays off 10 percent of its customer service team in favor of using AIIn China, people are renting out their faces to AIAs SpaceX Sheds a Tesla's Worth of Value, Elon Musk Is Trying to Sell Investors on Another CompanyHow Much Charity Would It Take for People to Like Elon Musk?ChatGPT is now refusing requests to write in famous authors' stylesNvidia's $750 Billion Deals Revive Fear of AI Circular FinancingThe Trump administration is exempting data centers from pollution laws intended to prevent acid rainUS accuses American of allegedly wiping his phone using a 'duress' password during border searchMeta launches new Facebook Verified badge for actual, real humansMeta launches a storefront platform through Facebook MarketplaceMeta's pro-AI ad campaign is conspicuously light on AIIf You AI-Generate Code, Hackers Just Found a Devious Method to Install Malware Directly on Your ComputerMinions & MonstersStar Trek: Strange New WorldsBroadchurch S2SiloTed Lasso Season 4 TrailerNeuromancer — Official Teaser | Apple TVPrime Video Finally Lifts the Lid on ‘Blade Runner 2099'Star Trek: Section 31Bad Deeds by Andrew Hunter MurrayDave BittnerThe CyberWireHacking HumansCaveatControl LoopOnly Malware in the BuildingJason DeFillippoJurassic Park computers in excruciating detailWho are the Mandalorians? | Star Wars: Galaxy GuideHF96V Thermal Camera with Visual Camera & Laser Pointer, Intelligent Scene Detection, 240 * 240 Super Resolution Thermal Imaging Camera,25 Hz, 50° FOV, -4°F to 1022°F, IP54 Infrared CameraProject FarmSee Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. We start with some follow-up on Joe's chicken coop project. Dave covers a new FBI warning about scammers impersonating FBI agents and the IC3 to target fraud victims a second time with convincing deepfakes, fake websites, and recovery scams. Joe shares the story of a retired man who lost £1,800 after two scammers worked together to convince him they were protecting his Amazon account from fraud. Maria breaks down a new UN report revealing that scam networks stole up to $114 billion across Asia-Pacific in 2025 and are evolving into global criminal enterprises powered by specialization and AI. Our Catch of the Day comes from a listener who blames being left unsupervised for one of the funniest scam-baiting exchanges we've seen yet. Resources and links to stories: Fake FBI Agents Use IC3 Complaint Scams to Target Fraud Victims Amazon scam was so authentic - it got the better of me Crime gangs snare more than $88 billion in scams in Asia-Pacific, UN says Have a Catch of the Day you'd like to share? Email it to us at hackinghumans@n2k.com.
Laundry Bear snuffles through unpatched Zimbra Collaboration servers. The State Department puts visa restrictions on cybercriminals. Oracle drops a record 1,449 security patches. Researchers disclose a critical vulnerability in OpenAI's ChatGPT Workspace Agents. A new benchmark evaluates frontier AI model malware reverse engineering. LunchPoke uses the Notepad++ application to establish persistence. A Swiss rail manufacturer refuses to pay the ransom. Dave Bittner sits down with Maria Varmazis, host of T-Minus Space Cyber Briefing, to discuss the show's evolution into CyberWire's weekly space cyber briefing. The AI goes to space. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Dave Bittner sits down with Maria Varmazis, host of T-Minus Space Cyber Briefing, to discuss the show's evolution into CyberWire's weekly space cyber briefing. Maria shares why space cybersecurity deserves more attention, how the new format allows for deeper conversations on topics like GPS security and European space sovereignty, and why every cybersecurity professional should be paying attention to the growing role of space in cyber. You can hear part one here. Selected Reading Russian hackers exploit Zimbra zero-click flaw for email theft (Bleeping Computer) State Department imposes visa restrictions on foreign cyber scammers (The Record) Oracle drops 1,449 security patches like it's the new normal (The Register) OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider (SecurityWeek) Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models (SecurityWeek) Hackers abuse Notepad++ plugins to stealthily install malware (Bleeping Computer) Swiss train maker Stadler refuses Everest $12 million ransomware demand (The Record) If you pay a hacker's ransom, chances are that they'll come back for more (TechCrunch) NASA Puts Google's Gemma Large Language Model in Orbit (IEEE Spectrum) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
This week, while Maria is out hosts Dave Bittner and Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. Dave covers a phishing campaign using fake Facebook verification emails to trick users into handing over their account credentials. Joe highlights the Better Business Bureau's new Scam Tracker heat map for visualizing scam trends and discusses a global INTERPOL operation that led to thousands of arrests and hundreds of millions of dollars in seized fraudulent funds. Our Catch of the Day is on a scam-baiter who encounters a hilariously inept TikTok scam account, proving that not every scammer is a master criminal. Resources and links to stories: Phishing Attacks Targeted Facebook Users With Fake Verification Offer Heatmap Over 5,800 arrests, USD 293 million intercepted in global fraud bust These TikTok scam accounts are literally so stupid Have a Catch of the Day you'd like to share? Email it to us at hackinghumans@n2k.com.
We finally get to reconnect with Dave Bittner for a fun catch-up and chit-chat about this summer's big movies. Brian's kid discovers all of Star Wars at once.Dave BittnerThe CyberWireHacking HumansCaveatControl LoopOnly Malware in the BuildingKnockoff - Amazon Brand FilterBob Gurr: Living by DesignSupport the show at Patreon! - https://patreon.com/gogOther ways to support the show! - https://gog.show/donateJoin our Discord! - https://discord.gg/r4ZmSHBBuy some merch! - https://shop.gog.show/See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. We start with some follow-up after a listener wrote in to share their love of X Japan, joking that the show should spend less time talking about chickens and more time celebrating one of Japan's most legendary metal bands. Joe covers how millions of compromised consumer devices are fueling massive residential proxy networks that cybercriminals and nation-state actors use to disguise malicious activity online. Dave looks at a ransomware campaign using fake INTERPOL emails to pressure victims into opening malicious attachments and infecting their systems. Maria explores whether AI-powered operating systems could one day become our first line of defense against scams by detecting social engineering attacks before users ever fall for them—and what new risks that future could bring. Our catch of the day is on an unsolicited Telegram message that quickly turns into an entertaining romance scam encounter. Resources and links to stories: X Japan - Kurenai Live 1989 (Blue Blood Tour - 爆発寸前GIG) How Hackers Found a Back Door Into the American Living Room A Sneaky Back Door Lets Hackers Into Your Home. Here's How to Protect Yourself. 50.147.72.126 Fake Interpol investigation emails target small businesses with ransomware The Beginning of the End of Social Engineering Polish Frank part 1. He had me at the bush. Have a Catch of the Day you'd like to share? Email it to us at hackinghumans@n2k.com.
In this special edition of CyberWire Daily's 10th anniversary series, N2K CyberWire's Maria Varmazis and Dave Bittner discuss 10 years of vulnerabilities, zero‑days, and hardware flaws. Together they reflect on the last decade of cybersecurity vulnerabilities, exploring key shifts, landmark incidents like WannaCry and Log4Shell, and the evolving landscape shaped by hardware issues and AI. Join Maria and Dave as they discuss how these changes impacted security practices and the importance of vigilance in a rapidly interconnected world. Learn more about your ad choices. Visit megaphone.fm/adchoices
Please enjoy this encore of Hacking Humans. This week, our hosts Dave Bittner, Joe Carrigan, and Maria Varmazis (also host of the T-Minus Space Daily show) are back sharing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. We've got some follow-up from listener Kajetan, who recalled a run-in with a scammer in Paris posing as a mute fundraiser—and says he performed a "miracle" by crossing out his name, prompting the supposedly mute woman to suddenly start yelling at him. Maria has the story on how small businesses in Toronto, like the family-run Souvlaki Hut and Pippins Tea Company, were shocked to discover that thieves exploited vulnerabilities in their point of sale terminals to issue themselves thousands in fraudulent refunds—exposing serious flaws in how these machines are secured. Dave's story is on a Stanford-led study that found popular AI therapy bots, including ChatGPT and commercial mental health platforms, often respond inappropriately to serious mental health issues—fueling delusions, validating harmful thoughts, and failing to follow basic therapeutic guidelines—raising urgent concerns about their use as replacements for human therapists. Joe follows the story on a sweeping federal investigation into Minnesota's Housing Stabilization Services program, where agents raided homes and businesses tied to an alleged multi-million-dollar Medicaid fraud scheme that exploited vulnerable residents and billed taxpayers for housing support services that were never provided. Our catch of the day is on a patient scammer who spent five months building trust before claiming to send a $700K inheritance payout locked in a lawsuit—complete with a fake video of a safe and a shady tracking number—only to demand €15,000 in "customs fees," a scam the Redditor thankfully saw through before handing over any money. Complete our annual audience survey before August 31. Resources and links to stories: AI therapy bots fuel delusions and give dangerous advice, Stanford study finds ‘It was a shock': Toronto business owner says customer used point of sale terminal to issue himself $2,000 refund KARE 11 Investigates: Federal agents raid homes & businesses seizing evidence in housing fraud investigation Have a Catch of the Day you'd like to share? Email it to us at hackinghumans@n2k.com.
In this Special Edition episode, N2K CyberWire's Dave Bittner sits down with Caitlin Sarian, widely known as Cybersecurity Girl, to explore how storytelling, authenticity, and community are reshaping a more human-centered cybersecurity landscape. Recorded live at The Cyber Guild's Uniting Women in Cyber (UWIC) Event last fall, this candid conversation highlights Caitlin's unconventional path into cybersecurity and her mission to make the industry more accessible and relatable for all. Together, they explore how breaking down technical barriers can unlock new pathways into the field especially for those from nontraditional backgrounds. UWIC brings together industry leaders, practitioners, and emerging talent to advance the cybersecurity workforce through leadership, innovation, and inclusion. Join us on Oct 8 for UWIC 2026! Learn more about your ad choices. Visit megaphone.fm/adchoices
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. We start with some follow-up on an editorial examining whether AI could signal the beginning of the end for traditional social engineering, as attackers increasingly target AI systems instead of people. Dave's got the story on an FBI warning that crypto scammers are using cash couriers to collect money from victims and bypass banking safeguards. Maria's got the story on AI-powered impersonators posing as members of the rock band Sons of Legion to scam fans through fake relationships and fraudulent requests for money. Joe's got two stories: one on HSBC Australia facing a proposed $246 million penalty over alleged scam protection failures, and another on two Michigan gold scam busts that prevented victims from losing hundreds of thousands of dollars. Our catch of the day is a reflection on a past interaction where the author initially held out hope someone might reappear, but ultimately accepts they're gone and shares the story in hindsight, including their own strongly emotional reaction at the time. Resources and links to stories: The Beginning of the End of Social Engineering FBI Warns Courier Cash Pickups Are Driving Crypto Scams A Rock Band Went Viral. Then AI Scammers Moved In HSBC's Australia unit to pay $24.6 million fine over scam protection failures, court rules A Couple Was Told To Turn $250,000 Into Gold. Police Stopped The Courier Scam Video: Deputies nab suspect in attempted $700,000 gold coin scam Eric - failed bait because I'm such a b**ch - part 1 Have a Catch of the Day you'd like to share? Email it to us at hackinghumans@n2k.com.
Five Eyes warns AI could supercharge cyberattacks within months. Tata Electronics confirms breach as stolen data allegedly includes Apple and Tesla documents. Researchers publish new analysis of FortiBleed. Gizmodo breach exposes readers to ClickFix malware campaign. BootROM exploit can bypass Apple's SecureROM. Scattered Spider members plead guilty in the UK. Attackers exploit Gravity SMTP flaw to harvest secrets From WordPress sites. Executive Order accelerates federal shift to post-quantum cryptography. Dave Bittner sits down with Ellen Boehm, the Senior Vice President of IoT Strategy & Operations at Keyfactor, to discuss NIST's progress in its PQC efforts. Keeping tabs on the tab-keepers. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today Dave Bittner sits down with Ellen Boehm, the Senior Vice President of IoT Strategy & Operations at Keyfactor, to discuss NIST's progress in its PQC efforts and where more effort needs to be made to get the U.S. and its critical infrastructure quantum-ready. Selected Reading 'Five Eyes' intelligence alliance warns that new AI models pose urgent cyber risk (Reuters) Intel agencies: Frontier AI models will reshape cybersecurity faster than expected (CyberScoop) Anthropic's Mythos AI broke into almost all NSA classified systems in hours (SecurityAffairs) Tata Electronics, a major tech supplier to Apple and Tesla, confirms data breach (TechCrunch) FortiBleed campaign used custom FortiGate sniffer to steal credentials (BleepingComputer) Gizmodo readers hit with ClickFix malware prompts after account compromise (The Register) New Exploit Bypasses Apple's Boot Defenses, Affects Millions of iPhones (SecurityWeek) TFL Hackers Admit Carrying Out Cyberattack That Cost £39M (Law360) Attackers Actively Exploiting Sensitive Information Exposure Vulnerability in Gravity SMTP Plugin (Wordfence) Trump Signs Executive Order Accelerating Post-Quantum Cryptography Migration (Security Week) Madison Square Garden Made Dossier on Activists Who Opposed Facial Recognition (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Klue supply-chain attack impacts cybersecurity firms. Brand-new Prinz Eugen ransomware is surprisingly polished. ShinyHunters leak exposes sensitive data of 10,000 Council of Europe employees. Security agencies sound alarm over FortiBleed credential harvesting operation. Texas data breach affects hunting and fishing licensees. Microsoft ties Mastra AI supply chain attack to North Korean hackers. Vidar infostealer unveils new technique to defeat Chrome's encryption protections. Brazil investigates suspected hack of emergency alert system. We got your Monday business brief. On today's Industry Voices, Dave Bittner sits down with Mike Britton, CIO of Abnormal AI, as they discuss "AI-Powered Attacks Are Now a Commodity.” And not the kind of beats you want to drop. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, we are joined by Mike Britton, CIO of Abnormal AI, discussing "AI-Powered Attacks Are Now a Commodity — And Most Organizations Don't Know It Yet." If you enjoyed this conversation and want to hear the full interview, listen here. Selected Reading Klue OAuth breach victim list grows as Icarus hackers claim attack (BleepingComputer) Prinz Eugen ransomware: a deep dive into a new Go-based encryptor (ThreatDown by Malwarebytes) Council of Europe Data Breach: ShinyHunters Makes 10,000 Employees' Records Permanent (Tech Times) Global cybersecurity agencies warn of credential exposure in FortiBleed campaign targeting Fortinet firewalls, VPN gateways (Industrial Cyber) Everything's bigger and better in Texas – even data breaches (The Register) Microsoft links Mastra AI supply chain attack to North Korean hackers (BleepingComputer) Inside Vidar's ABE Bypass: From Memory Scanning to APC Injections (Gen Digital) Brazil probes emergency warning system after nationwide rogue alert (The Register) Ent emerges from stealth with $100 million in seed funding. (N2K Pro Business Briefing) Apple patches Beats Studio Buds flaw that could turn earbuds into a wiretap (Malwarebytes) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
For years, security teams had time between discovery and exploitation. Time to triage. Time to validate. Time to prioritize what to fix first. AI has compressed that window. Frontier models now discover and chain vulnerabilities faster than human analysts can confirm them, and the gap between finding and fixing is shrinking in both directions. In this episode of CyberWire-X, N2K's Dave Bittner and Federico Kirschbaum, Head of XBOW Security Lab, explore what it actually means to run autonomous offensive security, why validation workflows built for quarterly testing cycles struggle to keep up, and how practitioners are redefining what a tested application looks like when the pace of offense has fundamentally changed. Learn more about your ad choices. Visit megaphone.fm/adchoices
Traditionally, GPS jamming attacks have been confined to the ground; however, new data shows that these attacks could be moving to target signals before they even reach the ground. In this week's episode, host Maria Varmazis sits down with Dave Bittner and Brandon Karpf to discuss recent research that suggests the attack landscape for GPS attacks is expanding. If this research is accurate, these attacks represent a significant evolution for how defenders think about this critical technology. Key sources: Something is jamming GPS over Europe. Here's what we found. Chasing Lightning: Detecting, Characterizing, and Identifying a Powerful Space-Based GNSS Interference Source. EKS 5. Like what you heard? Be sure to subscribe to our free Signals and Space Briefing, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space Is there a topic or person you'd like to hear on our show? You can send your questions and feedback to space@n2k.com. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com. Learn more about your ad choices. Visit megaphone.fm/adchoices
Traditionally, GPS jamming attacks have been confined to the ground; however, new data shows that these attacks could be moving to target signals before they even reach the ground. In this week's episode, host Maria Varmazis sits down with Dave Bittner and Brandon Karpf to discuss recent research that suggests the attack landscape for GPS attacks is expanding. If this research is accurate, these attacks represent a significant evolution for how defenders think about this critical technology. Key sources: Something is jamming GPS over Europe. Here's what we found. Chasing Lightning: Detecting, Characterizing, and Identifying a Powerful Space-Based GNSS Interference Source. EKS 5. Like what you heard? Be sure to subscribe to our free Signals and Space Briefing, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space Is there a topic or person you'd like to hear on our show? You can send your questions and feedback to space@n2k.com. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com. Learn more about your ad choices. Visit megaphone.fm/adchoices
In this special edition of CyberWire Daily's 10th anniversary series, N2K CyberWire's Maria Varmazis and Dave Bittner discuss leaks, espionage and influence operations over the past 10 years. Together they reflect on a decade of cybersecurity developments, focusing on the pivotal year 2016 where a shift occurred. Join N2K as we cover the rise of nation-state cyber operations, major leaks like the Panama Papers and DNC email hacks, and the evolving landscape of cyber norms, trust, and threat perception. Learn more about your ad choices. Visit megaphone.fm/adchoices
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. This week, we have follow up on a listener-submitted trick for diverting unwanted calls to a different number, including the famous Rickroll hotline, along with a discussion about whether Joe should launch a podcast dedicated entirely to the trials and tribulations of raising backyard chickens. Maria has the story of a journalist who infiltrated a sophisticated North Korean hiring scam that uses fake job interviews, real freelance recruiters, and malware-laced coding tests to steal passwords and cryptocurrency. Dave's got a viral gas station scam warning involving screws placed in fuel pumps, and why investigators found no evidence that the alleged scheme is actually happening. Joe's first story is on a new Maryland law that gives banks and credit unions the authority to temporarily pause suspicious transactions in an effort to better protect customers from fraud and financial exploitation. On this week's Catch of the Day, a scammer serves up a blood-curdling tale involving "Dr. Prince Andrew" and a very questionable beverage choice. Resources and links to stories: I Made The World's First Self-Cooling Clothes Cools Surfaces Up To 15°F Below The Air Temperature I got inside a North Korean hiring scam. What I found reveals a troubling shift in tactics Gas pump 'screw method' scam warning is a hoax Maryland law gives banks and credit unions power to pause suspicious transactions Longevity Ready Maryland, Fraud Protections, Support for Caregivers Among Wins for Older Marylanders Dr. Prince Andrew admits to drinking blood "occasionally" Have a Catch of the Day you'd like to share? Email it to us at hackinghumans@n2k.com.
What It Takes To Be Successful in Cyber Media All links and images can be found on CISO Series Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Dave Bittner, producer and host, The CyberWire. Joining is Graham Cluley, host of Smashing Security podcast and Leo Laporte, founder of TWiT (This Week in Tech) and host of Security Now podcast. In this episode: Format follows function The decision gap Practitioner fingerprints Beyond the news cycle A huge thanks to our sponsor, Palo Alto Networks Cortex Cloud unifies code, cloud, and SOC on a single data, risk, and control plane — giving teams the context, workflows, and agentic intelligence to turn risk into resolution. Native AI agents investigate and act within enterprise guardrails, delivering real-time protection from workload to network edge. Cloud security that outpaces machine-speed threats. Learn more at paloaltonetworks.com/cortex/cloud/demo.
In large enterprise software companies, vulnerability management teams are facing unprecedented speed and scale as AI accelerates both discovery and exploitation of security issues. In this episode of CyberWire-X, N2K's Dave Bittner is joined by Adobe's Daniel Ventura, Senior Manager of the Vulnerability Operations Center, and Sangeeta Arora, Director of Vulnerability Management, to discuss how Adobe is evolving its vulnerability management strategy to keep pace with AI-driven threats. They share real world insights on prioritization, crossteam partnership, and how modern programs can balance speed with meaningful risk reduction. Learn more about your ad choices. Visit megaphone.fm/adchoices
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. This week's follow-up stories involve a puppy scam, a memorable road trip, fresh eggs, chickens, and an unexpected rat encounter. Joe examines two cases highlighting the real-world financial impact of fraud, including a vendor payment scam that cost a Maine town nearly $190,000 and a report on growing state-level fraud losses. Maria discusses a highly targeted espionage campaign that maintained access to a stock exchange executive's Outlook account, while quietly exfiltrating sensitive information. Dave explores how criminals are using AI-generated deepfakes of executives to convince employees to authorize fraudulent payments. Our Catch of the Day comes from listener Piet-Auke Boekema, who uncovered a LinkedIn scammer offering to sell cybersecurity certifications without requiring the exams. Resources and links to stories: Residents of Arizona, Nevada and Hawaii lost the most to fraud schemes. How other states compare Harpswell loses $189,199 to vendor payment scam Espionage Campaign Targeted Stock Exchange Executive for Five Months The Deepfake Boss Scam: How to Verify Requests Before It's Too Late Have a Catch of the Day you'd like to share? Email it to us at hackinghumans@n2k.com.
This week on Grumpy Old Geeks, Brian and Jason once again survey the smoldering wreckage of the tech industry and discover that the people building the future are increasingly being sued by governments, publishers, customers, employees, and occasionally reality itself. California is coming after 23andMe over its catastrophic data breach, Florida is taking a swing at OpenAI, CNN has joined the ever-growing conga line of companies suing Perplexity, and Meta somehow decided the solution to improving AI is recording employees' every mouse click while generously allowing them a whole 30-minute privacy break. Meanwhile, Google's own engineers are sharing memes about how much Google's AI tools suck, Microsoft apparently wants users addicted to its new AI assistant - first taste's free! - and Anthropic is preparing to go public with a valuation that makes even the most irrational dot-com era investor look financially responsible.The AI arms race continues producing exactly the kinds of outcomes you'd expect when venture capitalists start huffing their own press releases. Instagram's AI support bot reportedly helped hackers steal accounts because apparently "Are you sure you're the owner?" was considered an optional step. Suno raised another $400 million while fighting copyright lawsuits, Paramount+ seems to have let AI create the ugliest Star Trek thumbnail in Federation history, and Stan Lee has now been digitally resurrected because modern capitalism looked at death and said, "Nice try." Over in transportation, BYD is so confident in its self-driving technology that it's willing to pay for your accidents, while Tesla owners are discovering their old Full Self-Driving contracts may have quietly received software updates of the legal variety. Somewhere in a conference room, a lawyer just whispered, "Let's not put that in writing," ten years too late.Elsewhere, governments worldwide continue their ongoing experiment of raising children by confiscating smartphones. Malaysia has implemented a social media ban for kids under 16, Poland wants phones and smartwatches locked away at school, and Kentucky schools just collected $27 million from social media companies accused of building products as addictive as cigarettes.Dave Bittner drops by for a visit and we discuss Spotify listeners apparently preferring old music because new music keeps getting algorithmically focus-grouped into oblivion and a healthy dose of Star Wars, Downton Abbey, Derry Girls, Lego, books, gadgets, and AI-generated jazz. Add it all up and you've got another week where the only thing moving faster than technology is the legal department trying to keep up.Sponsors:DeleteMe - Get 20% off your DeleteMe plan when you go to JoinDeleteMe.com/GOG and use promo code GOG at checkout.Shopify - Sign up for your one-dollar-per-month trial today at Shopify.com/grumpyPrivate Internet Access - Go to GOG.Show/vpn and sign up today. For a limited time only, you can get OUR favorite VPN for as little as $2.03 a month.SetApp - With a single monthly subscription you get 240+ apps for your Mac. Go to SetApp and get started today!!!1Password - Get a great deal on the only password manager recommended by Grumpy Old Geeks! gog.show/1passwordShow notes at https://gog.show/749Watch on YouTube at https://youtu.be/A1sv2BEzWBkShow NotesVibe Coders are Script KiddiesDestroy the BroligarchyColorado Governor Vetoes Surveillance Pricing Ban as Public Backlash Against the Tech GrowsCalifornia sues 23andMe over 2023 data breach that affected 7 million usersFlorida sues OpenAI, Sam Altman, in first-of-its-kind lawsuit over violent incidentsMeta will reportedly let employees take 30-minute breaks from its tracking programInstagram is alerting users who were targeted by hackers during AI chatbot attacksGoogle Employees Internally Share Memes About How Its AI SucksGoogle ordered to put clearer links in AI search and let UK publishers opt outMicrosoft Wants to 'Make People Addicted' to its New AI Assistant, Internal Documents RevealMeta, other social networks will pay $27 million to settle Kentucky school district lawsuitMalaysia's under-16 social media ban carries fines up to $2.5 millionPoland wants to ban phones and smartwatches in schoolsCNN is the latest media company to sue PerplexityStill facing copyright lawsuits, AI music generator Suno raises another $400MBYD is assuming financial liability if you crash while using its self-driving techAnthropic is set to go public after filing paperwork with the SECData Center Operators Are Trying to Fix Their Water Use ProblemsTesla Owners Say Their Old FSD Contracts Were Quietly ChangedStan Lee's voice and likeness have been resurrected, thanks to AIParamount+ used AI to make the ugliest Star Trek thumbnail ever2026 World Cup Wall ChartI Am Not a Robot: My Year Using AI to Do (Almost) Everything by Joanna SternCarl's Doomsday Scenario: Dungeon Crawler Carl Book 2 by Matt DinnimanWisdom Takes Work: Learn. Apply. Repeat. by Ryan HolidayBelkin Connect 4-Port USB-C Hub - USB C Hub Multiport Adapter Dongle with 4 USB-C 3.2 Gen 2 Ports - High-Speed 10G Data Transfer for Laptop, MacBook, iPad, PC, and More - 100W PD - $32.24Dave BittnerThe CyberWireHacking HumansCaveatControl LoopOnly Malware in the BuildingThe Mandalorian Season 1Star Wars: RebelsWrapped up the Downton Abbey series rewatchBuffy and Ted Lasso star Anthony Head dies at 72Almost through the Derry Girls series.Lego Mando and Grogu set (mild spoiler)AI generated JazzThe Biggest Hits on Spotify Right Now Are a Blast From the PastSee Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. They're also joined by special guest Kieran Human, Lead Cybersecurity Engineer at ThreatLocker . Dave's story is on an FBI warning that the Silent Ransom Group is escalating its extortion tactics by combining phishing and fake IT support calls with in-person visits, where attackers may physically enter offices to plug malicious devices into company computers. Joe's story is on a listener-submitted case from Australia where attackers used a phishing email to silently install legitimate remote-access software, hijack a dental practice's email system, and launch a large-scale phishing campaign that bypassed many traditional security controls. Maria's story is on a California mother who lost $5,000 after scammers used what appeared to be her daughter's voice in a fake kidnapping call, highlighting the growing threat of AI-powered voice cloning scams. Our Catch of the Day comes from a text scam that took an unexpected turn when the recipient fired back with a response the scammer definitely wasn't prepared for. Resources and links to stories: FBI warns of in-person data theft attacks from extortion gang California Mom Loses More Than $5,000 in Voice Scam After Receiving Fake Call from Her Daughter Alleging She Was Kidnapped Have a Catch of the Day you'd like to share? Email it to us at hackinghumans@n2k.com.
In this special edition of CyberWire Daily's 10th anniversary series, N2K CyberWire's Maria Varmazis and Dave Bittner consider the tactics, trends, and turning points that shaped the threat landscape over the last decade of ransomware. Ransomware has evolved from small-scale extortion and opportunistic attacks to sprawling, sophisticated, organized crime and state-sponsored attacks. Cryptocurrency plays a pivotal role in enabling ransomware's growth by providing untraceable payment methods. Join us as we explore key incidents like WannaCry and NotPetya, the shift from street crime to organized and nation-state cyber threats, and AI's impact on the future of ransomware. Learn more about your ad choices. Visit megaphone.fm/adchoices
Iranian hackers hit LA transit. Chinese cyber operators target Middle East infrastructure. Dutch police take down a 17-million-device botnet. Researchers uncover a phishing risk in ChatGPT. Anthropic prepares its Mythos model for release. Chrome patches 22 critical bugs. Zapier fixes a dangerous vulnerability chain. ShinyHunters claims a Charter breach. A data broker who fueled scams against millions of seniors heads to prison. Maria Varmazis joins Dave Bittner for a look back at a decade of ransomware. A Google insider allegedly went from threat hunting to bet hunting. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today CyberWire hosts Maria Varmazis and Dave Bittner take a look at how ransomware has evolved over the past decade, from opportunistic attacks to today's sprawling criminal enterprises, and discuss the tactics, trends, and turning points that shaped the threat landscape. You can catch the full conversation on Sunday in the CyberWire Daily podcast feed. We hope you'll join us! Selected Reading Iranian hackers behind March's LA transport cyberattack, Gambit finds (The Jerusalem Post) Chinese Hackers Exploit Iran War to Target Maritime and Energy Firms (Infosecurity Magazine) Dutch cops wrest 17M devices from mystery botnet's clutches (The Register) ChatGPT blindly trusts browser content, turning the page into a payload (The Register) Anthropic confirms Claude Mythos-class models will roll out to the public (Bleeping Computer) Chrome 148 Update Patches 151 Vulnerabilities (SecurityWeek) Zapier fixes bug chain that researchers say risked widespread account takeover (CyberScoop) Charter Communications data breach affects 4.9 million accounts (Bleeping Computer) Man sent to prison for selling data of 7 millions elderly Americans (Bleeping Computer) US charges Google security engineer with Polymarket insider trading (Bleeping Computer) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. We start with some follow up on Joe's rental scam story, as listener Ben suggests the scammers may go the extra mile because they could keep collecting rent for months before anyone realizes the property was never theirs to rent out. Also, another listener writes in with some “Chook Psychology 101." Maria's story is on scammers targeting recent college graduates with fake student loan relief offers, job scams, and rental listings designed to steal personal information, deposits, and money through high-pressure tactics. Joe's story is on Congress pressuring major telecom companies to do more to stop the flood of scam calls and texts still reaching Americans despite billions already being blocked every year. Dave's story is on Android 17 adding new protections aimed at stopping banking scams, including stronger privacy controls and defenses against malicious calls during sensitive actions. Our Catch of the Day is on a text scam where scammers use scare tactics by sending fake messages about court dates and legal trouble. Resources and links to stories: BBB warns of scams targeting new graduates Congressional committee asks telecoms to do more to prevent scams as losses surge Android 17 to expand banking scam call and privacy protections Have a Catch of the Day you'd like to share? Email it to us at hackinghumans@n2k.com.
FOLLOW UP: This week, it seems America believes every complicated social problem can be fixed by asking, “Have you tried turning the internet off for the children?” Meanwhile, the Electronic Frontier Foundation quietly notes that the science behind social media bans might not be as clear-cut as cable-news dads screaming about dopamine loops claim. Turns out, teen anxiety may also be linked to pandemics, school shootings, climate dread, and an economy that feels like a Fallout side quest. Meanwhile, Snap Inc. and YouTube settled another lawsuit accusing their apps of turning kids into doomscrolling goblins, Meta continues to insist social media addiction isn't real while losing money in court, and former Google CEO Eric Schmidt was booed at a graduation speech after telling graduates to hop on the AI rocket ship without asking questions — exactly what a billionaire says when he already owns the rocket.In the news, Elon Musk lost another OpenAI lawsuit because apparently even juries have limits. SpaceX's IPO revealed Musk plans to power AI with enough gas turbines to recreate 1890s London smog, and Grok officially became a disclosure liability after the whole “MechaHitler” incident. Tesla robotaxis still clip fences and occasionally require humans to remotely drive the “self-driving” cars. Trump Mobile somehow shipped a gold phone that actually works — a stunning upset — before immediately leaking customer data. LinkedIn finally admitted the platform has become an AI-generated motivational swamp filled with “it's not about X, it's about Y” sludge from people named Brayden. Spotify is handing out podcast verification badges so listeners can tell real creators from algorithmic nightmare fuel. Meta laid off thousands more workers while reportedly using employee surveillance to train AI replacements. And OpenAI is giving everyone in Malta a free year of ChatGPT Plus if they complete an AI literacy course, which honestly makes Malta sound more technologically responsible than Silicon Valley.APPS & DOODADS reflect classic Gen-X paranoia, as Backblaze highlights California's constant threat of wildfires and the idea that local backups are optimistic. YouTube introduced AI deepfake detection tools, allowing creators to finally see which scam ads are using their faces to promote crypto vitamins, while X limited free users to 50 posts a day unless they pay for a blue check — proving once again that the true free speech was the subscriptions we sold along the way. Retrocodex arrived with a strong “everything your teachers confidently told you in 1987 was wrong” vibe.MEDIA CANDY opens with the eternal cry of “FUCK THE FIRETV!!!!” before Jason taps out of Good Omens after ten minutes while Brian takes the bullet for the audience. There's also chatter about Mortal Kombat 2, The Devil Wears Prada 2, Billy Corgan talking goth history with David J, and more existential dread courtesy of Dan Carlin's Common Sense.THE DARK SIDE WITH DAVE welcomes back Dave Bittner for a Mando & Grogu review, Darth Maul, and a stunning but absurdly expensive LEGO Disneyland set. There's also a guy who built a full-size Millennium Falcon “with his wife's permission,” a fan-made Star Tours film, and the Federal Trade Commission discovering that those creepy “your phone is listening to you” ad-tech companies mainly just had PowerPoint decks and confidence. Also: mechanical keyboard simulators now exist, because apparently even fake typing has become a lifestyle brand.Sponsors:DeleteMe - Get 20% off your DeleteMe plan when you go to JoinDeleteMe.com/GOG and use promo code GOG at checkout.Shopify - Sign up for your one-dollar-per-month trial today at Shopify.com/grumpyPrivate Internet Access - Go to GOG.Show/vpn and sign up today. For a limited time only, you can get OUR favorite VPN for as little as $2.03 a month.SetApp - With a single monthly subscription you get 240+ apps for your Mac. Go to SetApp and get started today!!!1Password - Get a great deal on the only password manager recommended by Grumpy Old Geeks! gog.show/1passwordShow notes at https://gog.show/747Watch on YouTube at https://youtu.be/eX5jVfewaswFOLLOW UPThe Science is Not Settled: How Weak Evidence is Fueling a National Push to Ban Social Media for YouthSnap and YouTube have reportedly settled another major social media addiction lawsuitEx-Google CEO Eric Schmidt Fails to Read Room on AI, Gets Booed into OblivionIN THE NEWSElon Musk took too long to sue OpenAI, jury unanimously agreesSpaceX IPO Filing Reveals Nearly $3 Billion Investment in Gas Turbines for AI Data Centers‘MechaHitler' Is SpaceX's Problem NowTrump Mobile Phone Beats Expectations by Actually ExistingNew crash data highlights the slow progress of Tesla's robotaxisIf You Used Insider Knowledge to Score Big on Polymarket, You May Now Be in Huge TroubleMinnesota passes prediction markets banLinkedIn doesn't want your AI slop anymoreSpotify is launching verification badges for podcasts to help listeners avoid AI slopZuckerberg Tells the Tattered Remainder of His Workers That He Won't Conduct Another a Mass Firing for at Least Seven MonthsOpenAI is offering ChatGPT Plus to citizens of Malta for a yearMassive Crypto ATM Company Bitcoin Depot Is Shutting Down as the Whole Industry Collapses‘Smoke Weed and Earn Bitcoin' With This Vape Pen in Our Increasingly Dystopian Nightmare‘Unstoppable' Crypto Exchange Halts Trading After $10 Million TheftIran Doubles Down on Bitcoin for Ships Passing Through the Straight of HormuzTrump-Linked Crypto Company Notes 'Substantial Doubt' It Can Survive Another 12 MonthsAPPS & DOODADSBackblazeYouTube's AI deepfake detection tool is now available to all creators 18 and olderX accounts are limited to 50 posts and 200 replies a day unless they pay for a blue checkmarkRetrocodexMEDIA CANDYGood Omens Season 3 - The FinaleThe Magnificent Others with Billy Corgan - David J of Bauhaus & Love & RocketsCommon Sense 326 – The Water in Which We SwimTHE DARK SIDE WITH DAVEDave BittnerThe CyberWireHacking HumansCaveatControl LoopOnly Malware in the BuildingMaul: Shadow LordRogue One: A Star Wars StoryNot Even Baby Yoda Can Save ‘Star Wars'Colorado man creates replica Millenium FalconSomeone made a Star Tours fan film.Bring Disneyland Home With This Gorgeous New Lego Set‘Creepy' Listening Tool for Targeted Ads Didn't Actually Work, FTC SaysMechanical keyboard simSee Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.
In this special edition of CyberWire Daily's 10th anniversary series, N2K CyberWire's Maria Varmazis and Dave Bittner discuss cybersecurity geopolitics and warfare that have been in the news over the past 10 years. We begin our conversation around the supply chain malware from the destructive NotPetya campaign out of Russia, then Maria and Dave highlight: Olympic Destroyer disrupting the Pyeongchang Games, CozyBear's SolarWinds espionage campaign, the Colonial Pipeline ransomware disruption, Russia's full invasion of Ukraine paired with Viasat hack, Iranian hackers attacking ICS devices at water treatment plants in Israel, and China's VoltTyphoon and SaltTyphoon intrusions in critical sectors. Join us as we reflect on the escalation from election interference and disruption, to espionage and ransomware as national security crises, to integration in kinetic war,and now expansion into space, with AI-driven defenses and NATO codifying cyber as a collective defense domain. Learn more about your ad choices. Visit megaphone.fm/adchoices
CISA orders rapid patching of actively exploited Ivanti zero-day. Canvas gets hacked during finals week. Dirty Frag is a new Linux zero-day. Researchers document a serious Claude Chrome extension bug. Meta ends Instagram encryption. PCPJack malware clean house before moving in. A new report highlights quantum-era cryptographic threats. Cloudflare announces layoffs amidst AI deployment. Sri Lankan police shut down a scam center. Maria Varmazis joins me to look back at ten years of geopolitics in cyber. Vibe coding reveals valuable data. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we're previewing a special edition of CyberWire Daily's 10th anniversary series, where N2K CyberWire's Maria Varmazis and Dave Bittner revisit a decade of cyber geopolitics and warfare. Selected Reading CISA gives feds four days to patch Ivanti flaw exploited as zero-day (Bleeping Computer) Hackers ate my homework: Educational SaaS Canvas down after cyberattack (The Register) New Linux 'Dirty Frag' zero-day gives root on all major distros (Bleeping Computer) Flaw in Claude's Chrome extension allowed ‘any' other plugin to hijack victims' AI (CyberScoop) Meta U-turns on encryption push for Instagram as DMs go plaintext (The Register) ‘PCPJack' Worm Removes TeamPCP Infections, Steals Credentials (Security Week) Quantum Risk Explained (Recorded Future) Building for the future (Cloudflare) Sri Lanka makes 37 arrests as it raids another scam centre (Bitdefender) Thousands of Vibe-Coded Apps Expose Corporate and Personal Data on the Open Web (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
13 years of podcasting has taught us nothing; companies are lying about AI layoffs while Meta destroys itself from the inside; Andreessen has zero introspection and it shows; Dune 3 looks incredible; Firefly lives again; one idiot executive staked Buffy; Adobe paid $75M for being evil; your AI passwords are garbage; Dave Bittner is here to make you feel worse about all of it.Sponsors:DeleteMe - Get 20% off your DeleteMe plan when you go to JoinDeleteMe.com/GOG and use promo code GOG at checkout.SquareSpace - go to squarespace.com/GRUMPY for a free trial. And when you're ready to launch, use code GRUMPY to save 10% off your first purchase of a website or domain.Private Internet Access - Go to GOG.Show/vpn and sign up today. For a limited time only, you can get OUR favorite VPN for as little as $2.03 a month.SetApp - With a single monthly subscription you get 240+ apps for your Mac. Go to SetApp and get started today!!!1Password - Get a great deal on the only password manager recommended by Grumpy Old Geeks! gog.show/1passwordShow notes at https://gog.show/738Watch on YouTube: https://youtu.be/pykGjOmMs5cFOLLOW UPGOG Ep 1: How to Make Money on the Internet - March 25th, 2013The ‘AI-Washing' of Job Cuts Is Corrosive and ConfusingRace on to establish globally recognised 'AI-free' logoBillionaire Marc Andreessen says he has "zero" introspection, and that the idea itself is a modern invention.Gamblers trying to win a bet on Polymarket are vowing to kill me if I don't rewrite an Iran missile storyIN THE NEWSAtlassian to cut roughly 10% jobs in pivot to AIMeta is reportedly planning to cut up to 20 percent of its staff in upcoming layoffsMeta Is Building an Encrypted Chatbot After AI Agents Went Rogue and Exposed Sensitive DataMeta Says It Is Removing End-to-End Encryption From Instagram Direct MessagesMeta is testing clickable links in Instagram captions for verified subscribersEncyclopedia Britannica sues OpenAI for copyright and trademark infringementSenators tell ByteDance to shut down Seedance 2.0 AI video app 'immediately'Things Are Suddenly Looking Incredibly Bad for Trump's Social Media CompanyTrump administration will reportedly get $10 billion for brokering the TikTok dealThe Billionaire Backlash Against a Philanthropic DreamJeff Bezos' Washington Post Now Setting Readers' Subscription Prices With Uber-Style AIAPPS & DOODADSAdobe agrees to pay settlement for making its subscriptions hard to cancelEverything you need to know to design with StitchWhat is DESIGN.md?Warning: Your AI-Generated Password Is a Major Security Risk. Here's What to Use InsteadMEDIA CANDYDune: Part Three | Official Teaser TrailerHow ‘Dune: Part Three' Is Changing the Entire ‘Dune' Franchise"Paradise" has been renewed for Season 3 at Hulu, Variety has learned.Paradise on HuluMars ExpressNathan Fillion Says ‘Firefly' Animated Series In Development With Co-Stars Set To Reprise Roles; Concept Art RevealedSarah Michelle Gellar Says a Single Executive Was Responsible for Killing the ‘Buffy' Reboot‘V For Vendetta' at 20: We Spoke to Its Director About the Increasingly Relevant Comic AdaptationTHE DARK SIDE WITH DAVEDave BittnerThe CyberWireHacking HumansCaveatControl LoopOnly Malware in the BuildingDisney's 100% Rotten Tomatoes Masterpiece Returns This Fall With Brand-New ReleaseShhh… It's zombie proof. Kia's all-electric rangeThe Last Quiet Thing by Terry GodierEvel Knievel Kings Island 1975 - Farthest Successful Jump at 133 feet70's Evel Knievel Toy Commercial IDEALEvel Knievel's 14 Greyhound Bus Jump Oct 25th 1975 HD enhanced. Epic WORLD RECORD.Craig Ferguson's Evel Knievel Story is Wild!!Being EvelWembley 50th Anniversary Evel Knievel Stunt Cycle Set – Limited Gold EditionEvel Knievel Stunt Cycle - Trail Bike EditionSee Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.