Search this show’s transcripts

CyberWire Daily

en us
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
More details
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
Sources and links

Episodes

Page 1 · 50 per page
Published 2026-09-15

Pedal to the AI metal.

28 min Transcript
View

The President pushes back on calls to slow AI. Microsoft lays out potential AI safety rules. Lawmakers consider the crypto Clarity Act. Florida’s Department of Highway Safety and Motor Vehicles and Japan’s Digital Agency suffer data breaches. Phishing campaigns grow increasingly difficult for email security tools to spot. New York seizes a dozen AI deepfake domains. Alleged Black Axe cybercriminals face charges. Our guest is Camille Stewart Gloster, former U.S. Deputy Cyber Director and author of the new book "The Insider You Built: How Organizations Stay in Control of Autonomous AI Agents." AI meets the long arm of the old law. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we’re joined by Camille Stewart Gloster, author of The Insider You Built: How Organizations Stay in Control of Autonomous AI Agents, and founder of CAS Strategies. We’ll discuss her new book and the broader questions it raises about AI agents. You can learn more about "The Insider You Built” here.

Selected Reading

Trump pushes back on Anthropic CEO's call for an AI slowdown (SC Media)

Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints (SecurityWeek)

Microsoft releases emergency Windows updates to fix RDS failures (Bleeping Computer)

This bill could reshape crypto in America -- and it's sparking a major battle (NPR)

Florida Department of Highway Safety hacked by international criminal group (WPTV)

240,000 Hit by Data Breach at Japan’s Digital Agency (SecurityWeek)

VBSpam comparative review - Q3 (Virus Bulletin)

New York Seizes 12 Celebrity Deepfake Websites (404 Media)

Suspected Black Axe gang leaders face cybercrime charges in the US (Bleeping Computer)

Ex-FTC boss Khan urges Uncle Sam to break out the handcuffs for AI CEOs, citing 1934 precedent (The Register)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

The President pushes back on calls to slow AI. Microsoft lays out potential AI safety rules. Lawmakers consider the crypto Clarity Act. Florida’s Department of Highway Safety and Motor Vehicles and Japan’s Digital Agency suffer data breaches. Phishing campaigns grow increasingly difficult for email security tools to spot. New York seizes a dozen AI deepfake domains. Alleged Black Axe cybercriminals face charges. Our guest is Camille Stewart Gloster, former U.S. Deputy Cyber Director and author of the new book "The Insider You Built: How Organizations Stay in Control of Autonomous AI Agents." AI meets the long arm of the old law. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we’re joined by Camille Stewart Gloster, author of The Insider You Built: How Organizations Stay in Control of Autonomous AI Agents, and founder of CAS Strategies. We’ll discuss her new book and the broader questions it raises about AI agents. You can learn more about "The Insider You Built” here.

Selected Reading

Trump pushes back on Anthropic CEO's call for an AI slowdown (SC Media)

Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints (SecurityWeek)

Microsoft releases emergency Windows updates to fix RDS failures (Bleeping Computer)

This bill could reshape crypto in America -- and it's sparking a major battle (NPR)

Florida Department of Highway Safety hacked by international criminal group (WPTV)

240,000 Hit by Data Breach at Japan’s Digital Agency (SecurityWeek)

VBSpam comparative review - Q3 (Virus Bulletin)

New York Seizes 12 Celebrity Deepfake Websites (404 Media)

Suspected Black Axe gang leaders face cybercrime charges in the US (Bleeping Computer)

Ex-FTC boss Khan urges Uncle Sam to break out the handcuffs for AI CEOs, citing 1934 precedent (The Register)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-09-14

Bigfoot in the neural network.

27 min Transcript
View

NSA preps a major restructuring. Anthropic’s CEO calls for an AI slowdown. China acknowledges AI risks. RubyGems got swarmed by AI agents.  A maximum-severity GitLab vulnerability is under active exploitation. Direct Send abuse makes phishing emails appear legit. A British fintech firm leaks sensitive customer info. LinkedIn wins a legal dispute over browser extension scanning. Monday business briefing. Our guest is Tim Starks, senior reporter at CyberScoop, sharing government leaders’ outlook for cybersecurity and AI at the Billington Cybersecurity Summit. Finding Bigfoot in the neural network.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

We are joined by Tim Starks, senior reporter at CyberScoop, sharing government leaders’ outlook for cybersecurity and AI at the Billington Cybersecurity Summit. You can read Tim’s coverage here


Selected Reading

National Security Agency launches historic restructuring (The Washington Post)

Anthropic CEO Calls for an AI Slowdown. Is It Possible? (SecurityAffairs)

China’s spy agency warns of AI risk to national security (Financial Times)

OpenAI Agent Swarm Hacks RubyGems Package Manager (Infosecurity Magazine)

CISA: Hackers now exploit max severity GitLab flaw in attacks (Bleeping Computer)

Direct Send: How Attackers Weaponize Your Infrastructure Against You (KnowBe4)

Revolut discloses data breach exposing financial info, passports (Bleeping Computer)

LinkedIn beats "BrowserGate" lawsuits over scanning users' Chrome extensions (Ars Technica)

NVIDIA to acquire Hugging Face for $12.9 billion. (N2K Pro Business Briefing)

Sentient AI's Bigfoot Era Could Arrive at Any Moment (Gizmodo)


Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.  


Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

NSA preps a major restructuring. Anthropic’s CEO calls for an AI slowdown. China acknowledges AI risks. RubyGems got swarmed by AI agents.  A maximum-severity GitLab vulnerability is under active exploitation. Direct Send abuse makes phishing emails appear legit. A British fintech firm leaks sensitive customer info. LinkedIn wins a legal dispute over browser extension scanning. Monday business briefing. Our guest is Tim Starks, senior reporter at CyberScoop, sharing government leaders’ outlook for cybersecurity and AI at the Billington Cybersecurity Summit. Finding Bigfoot in the neural network.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

We are joined by Tim Starks, senior reporter at CyberScoop, sharing government leaders’ outlook for cybersecurity and AI at the Billington Cybersecurity Summit. You can read Tim’s coverage here


Selected Reading

National Security Agency launches historic restructuring (The Washington Post)

Anthropic CEO Calls for an AI Slowdown. Is It Possible? (SecurityAffairs)

China’s spy agency warns of AI risk to national security (Financial Times)

OpenAI Agent Swarm Hacks RubyGems Package Manager (Infosecurity Magazine)

CISA: Hackers now exploit max severity GitLab flaw in attacks (Bleeping Computer)

Direct Send: How Attackers Weaponize Your Infrastructure Against You (KnowBe4)

Revolut discloses data breach exposing financial info, passports (Bleeping Computer)

LinkedIn beats "BrowserGate" lawsuits over scanning users' Chrome extensions (Ars Technica)

NVIDIA to acquire Hugging Face for $12.9 billion. (N2K Pro Business Briefing)

Sentient AI's Bigfoot Era Could Arrive at Any Moment (Gizmodo)


Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.  


Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

As space becomes increasingly connected and autonomous, effective cybersecurity policy is struggling to keep pace.

Host Maria Varmazis and ⁠⁠⁠Dr. Mac McGuire sit down to discuss the limitations of current approaches for managing space cyber risks and what the industry is lacking. The two discuss how the space incidents have the potential to significant impact astronauts by disrupting oxygen systems, thermal regulation, and telemetry.

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: ⁠⁠⁠⁠⁠⁠https://thecyberwire.com/newsletters/signals-and-space⁠⁠⁠⁠⁠⁠

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to ⁠⁠⁠⁠⁠⁠space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: ⁠⁠⁠⁠⁠⁠https://www.surveymonkey.com/r/NJYCN2P ⁠⁠⁠⁠⁠⁠

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. ⁠⁠⁠⁠⁠⁠N2K⁠⁠⁠⁠⁠⁠ is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at ⁠⁠⁠⁠⁠⁠n2k.com⁠⁠⁠⁠⁠⁠.

More description

As space becomes increasingly connected and autonomous, effective cybersecurity policy is struggling to keep pace.

Host Maria Varmazis and ⁠⁠⁠Dr. Mac McGuire sit down to discuss the limitations of current approaches for managing space cyber risks and what the industry is lacking. The two discuss how the space incidents have the potential to significant impact astronauts by disrupting oxygen systems, thermal regulation, and telemetry.

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: ⁠⁠⁠⁠⁠⁠https://thecyberwire.com/newsletters/signals-and-space⁠⁠⁠⁠⁠⁠

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to ⁠⁠⁠⁠⁠⁠space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: ⁠⁠⁠⁠⁠⁠https://www.surveymonkey.com/r/NJYCN2P ⁠⁠⁠⁠⁠⁠

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. ⁠⁠⁠⁠⁠⁠N2K⁠⁠⁠⁠⁠⁠ is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at ⁠⁠⁠⁠⁠⁠n2k.com⁠⁠⁠⁠⁠⁠.

Extract Knowledge
Listen elsewhere
Published 2026-09-12

A beast by any other name. [Research Saturday]

23 min Transcript
View

Today we are joined by Brigid O Gorman, Senior Intelligence Analyst on Symantec Threat Hunter team, discussing their work on “GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses." GodDamn ransomware, the latest rebrand from the Hyadina group behind Monster and Beast, is using increasingly sophisticated techniques to evade defenses.

In a recent attack, the threat actors used AnyDesk for remote access, a broad credential-harvesting toolkit, and the PoisonX malicious kernel driver to disable endpoint security before deploying the ransomware. The activity highlights Hyadina’s continued development of its ransomware operations and an escalation in its defense-evasion capabilities.

The research and executive brief can be found here:

More description

Today we are joined by Brigid O Gorman, Senior Intelligence Analyst on Symantec Threat Hunter team, discussing their work on “GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses." GodDamn ransomware, the latest rebrand from the Hyadina group behind Monster and Beast, is using increasingly sophisticated techniques to evade defenses.

In a recent attack, the threat actors used AnyDesk for remote access, a broad credential-harvesting toolkit, and the PoisonX malicious kernel driver to disable endpoint security before deploying the ransomware. The activity highlights Hyadina’s continued development of its ransomware operations and an escalation in its defense-evasion capabilities.

The research and executive brief can be found here:

Published 2026-09-11

You might want to watch what you say.

29 min Transcript
View

WeWorm has China’s attention. Calls for an AI slowdown continue. OpenAI calls for mandatory AI regulation. Anthropic disrupts Russian cyberespionage. The EU’s 24 hour reporting requirement goes into effect. GitLab and Check Point patch critical vulnerabilities. IDScan confirms theft of IDs. Microsoft tracks a cloud intrusion campaign. Our guest is Kevin E. Greene, Chief Cybersecurity Technologist, Public Sector at BeyondTrust, discussing the role of privilege disruption in cyber resiliency. Watch what you say. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Today we are joined by Kevin E Greene, Chief Cybersecurity Technologist, Public Sector at BeyondTrust, discussing the role of privilege disruption in cyber resiliency.


Selected Reading

For China, a Mock A.I. Attack on WeChat Signals a Dangerous New Era (The New York Times)

This Is Really Bad (The New York Times)

OpenAI Calls for Mandatory National AI Safety Rules (BankInfo Security)

Anthropic caught Russia-linked spies using Claude in hacking operations (The Record)

EU's Cyber Resilience Act starts the 24-hour vulnerability clock (The Register)

GitLab urges users to patch max severity path traversal flaw (Bleeping Computer)

Check Point Patches Critical VPN Vulnerabilities (SecurityWeek)

ID verification giant IDScan confirms data breach with more than 150 million driver's licenses stolen (TechCrunch)

Passkey-themed social engineering leads to identity and cloud compromise (Microsoft Security Blog)

Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent (The Register)


Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.  


Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

WeWorm has China’s attention. Calls for an AI slowdown continue. OpenAI calls for mandatory AI regulation. Anthropic disrupts Russian cyberespionage. The EU’s 24 hour reporting requirement goes into effect. GitLab and Check Point patch critical vulnerabilities. IDScan confirms theft of IDs. Microsoft tracks a cloud intrusion campaign. Our guest is Kevin E. Greene, Chief Cybersecurity Technologist, Public Sector at BeyondTrust, discussing the role of privilege disruption in cyber resiliency. Watch what you say. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Today we are joined by Kevin E Greene, Chief Cybersecurity Technologist, Public Sector at BeyondTrust, discussing the role of privilege disruption in cyber resiliency.


Selected Reading

For China, a Mock A.I. Attack on WeChat Signals a Dangerous New Era (The New York Times)

This Is Really Bad (The New York Times)

OpenAI Calls for Mandatory National AI Safety Rules (BankInfo Security)

Anthropic caught Russia-linked spies using Claude in hacking operations (The Record)

EU's Cyber Resilience Act starts the 24-hour vulnerability clock (The Register)

GitLab urges users to patch max severity path traversal flaw (Bleeping Computer)

Check Point Patches Critical VPN Vulnerabilities (SecurityWeek)

ID verification giant IDScan confirms data breach with more than 150 million driver's licenses stolen (TechCrunch)

Passkey-themed social engineering leads to identity and cloud compromise (Microsoft Security Blog)

Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent (The Register)


Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.  


Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-09-10

Making cybercrime more difficult.

28 min Transcript
View

The FBI lays out its new Cyber Strategy. CISA plans a federal cyber overhaul. Anthropic discloses another unauthorized AI intrusion. Treasury sanctions a Chinese-language cybercrime marketplace. Another Microsoft Defender zero-day emerges. Gigabud banking malware gets stealthier. Chinese espionage groups deploy the BlueMoon exploit kit. Lawmakers target hack-for-hire firms. A U.S. designation forces an Italian technology collective to shut down. Ben Yelin discusses how private AI chatbot conversations are increasingly being used as evidence in court cases. When proofs meet prompts. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Dave Bittner sits down with Caveat cohost and University of Maryland Center for Cyber, Health, and Hazard Strategies expert Ben Yelin to discuss how private AI chatbot conversations are increasingly being used as evidence in criminal and civil court cases, raising new questions about privacy, legal protections, and what users should expect from their supposedly private AI interactions.

Want to hear the full conversation? Be sure to check out Caveat for the full discussion and more on the latest issues in privacy, surveillance, cybersecurity law, and policy.

Selected Reading

FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors (Infosecurity Magazine)

CISA Unveils Plan for Follow-On Integrated Cyber Assessment Support Contract (GovCon Wire)

Widened Scan Turns Up Fourth Rogue Claude Cyber Incident (SecurityWeek)

US sanctions Xinbi Guarantee over cyber scams and money laundering (Metacurity)

New 'ShieldCrash' Zero-Day Exploit Targets Microsoft Defender (SecurityWeek)

Gigabud banking trojan uses app cloning to evade fraud detection (SC Media)

Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits (The Register)

Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms (TechCrunch)

Italian tech collective Autistici/Inventati shuts down after US terrorist designation (The Record)

OpenAI Navier-Stokes Proof: $1 Million AI Math Controversy Explained (The CyberSec Guru)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

The FBI lays out its new Cyber Strategy. CISA plans a federal cyber overhaul. Anthropic discloses another unauthorized AI intrusion. Treasury sanctions a Chinese-language cybercrime marketplace. Another Microsoft Defender zero-day emerges. Gigabud banking malware gets stealthier. Chinese espionage groups deploy the BlueMoon exploit kit. Lawmakers target hack-for-hire firms. A U.S. designation forces an Italian technology collective to shut down. Ben Yelin discusses how private AI chatbot conversations are increasingly being used as evidence in court cases. When proofs meet prompts. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Dave Bittner sits down with Caveat cohost and University of Maryland Center for Cyber, Health, and Hazard Strategies expert Ben Yelin to discuss how private AI chatbot conversations are increasingly being used as evidence in criminal and civil court cases, raising new questions about privacy, legal protections, and what users should expect from their supposedly private AI interactions.

Want to hear the full conversation? Be sure to check out Caveat for the full discussion and more on the latest issues in privacy, surveillance, cybersecurity law, and policy.

Selected Reading

FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors (Infosecurity Magazine)

CISA Unveils Plan for Follow-On Integrated Cyber Assessment Support Contract (GovCon Wire)

Widened Scan Turns Up Fourth Rogue Claude Cyber Incident (SecurityWeek)

US sanctions Xinbi Guarantee over cyber scams and money laundering (Metacurity)

New 'ShieldCrash' Zero-Day Exploit Targets Microsoft Defender (SecurityWeek)

Gigabud banking trojan uses app cloning to evade fraud detection (SC Media)

Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits (The Register)

Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms (TechCrunch)

Italian tech collective Autistici/Inventati shuts down after US terrorist designation (The Record)

OpenAI Navier-Stokes Proof: $1 Million AI Math Controversy Explained (The CyberSec Guru)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-09-09

Clear your calendar, it’s Patch Tuesday.

30 min Transcript
View

Patch Tuesday is a doozy. The Feds warn China-based AI companies are distilling U.S. AI models. A new ClickFix campaign goes straight for the browser. Smart TVs get nosy. Hackers gift themselves a $47 million bug bounty. An Ohio man gets 15 years in federal prison for cyberstalking and sextortion. Andy Hornegold, Chief Security Technologist from Intruder, discusses what makes up a reliable AI pentests and the benefits and risks that come with AI-enabled security. Putting AI at the head of the class. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Andy Hornegold, Chief Security Technologist from Intruder, discussing what makes up a reliable AI pentests and the benefits and risks that come with AI-enabled security.

Selected Reading

Microsoft Patch Tuesday Fixes 966 Vulnerabilities, Including 2 Exploited 0-Days (Hackread)

Ivanti Patches Critical Flaws Across Enterprise Security Products (SecurityWeek)

Chrome 153 Patches Seventh Zero-Day of 2026 (SecurityWeek)

Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day (SecurityWeek)

ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws (SecurityWeek)

CISA, NSA and FBI Warn Chinese AI Firms Are Targeting U.S. AI Models at Industrial Scale (HSToday)

Europe's push for space sovereignty. (N2K Networks)

History for European spaceflight: Isar Aerospace reaches orbit and deploys payloads on second flight (Isar Aerospace)

ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 (Talos Intelligence)

LG TVs caught spying even when offline or on standby (The Verge)

'White hat' hackers take $47 million bounty after $320 million crypto theft (The Record)

Man gets 15 years for extorting women with AI-generated porn videos (Bleeping Computer)

Alpha School’s AI teaching model is expanding. Does it work? (Scientific American)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Patch Tuesday is a doozy. The Feds warn China-based AI companies are distilling U.S. AI models. A new ClickFix campaign goes straight for the browser. Smart TVs get nosy. Hackers gift themselves a $47 million bug bounty. An Ohio man gets 15 years in federal prison for cyberstalking and sextortion. Andy Hornegold, Chief Security Technologist from Intruder, discusses what makes up a reliable AI pentests and the benefits and risks that come with AI-enabled security. Putting AI at the head of the class. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Andy Hornegold, Chief Security Technologist from Intruder, discussing what makes up a reliable AI pentests and the benefits and risks that come with AI-enabled security.

Selected Reading

Microsoft Patch Tuesday Fixes 966 Vulnerabilities, Including 2 Exploited 0-Days (Hackread)

Ivanti Patches Critical Flaws Across Enterprise Security Products (SecurityWeek)

Chrome 153 Patches Seventh Zero-Day of 2026 (SecurityWeek)

Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day (SecurityWeek)

ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws (SecurityWeek)

CISA, NSA and FBI Warn Chinese AI Firms Are Targeting U.S. AI Models at Industrial Scale (HSToday)

Europe's push for space sovereignty. (N2K Networks)

History for European spaceflight: Isar Aerospace reaches orbit and deploys payloads on second flight (Isar Aerospace)

ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 (Talos Intelligence)

LG TVs caught spying even when offline or on standby (The Verge)

'White hat' hackers take $47 million bounty after $320 million crypto theft (The Record)

Man gets 15 years for extorting women with AI-generated porn videos (Bleeping Computer)

Alpha School’s AI teaching model is expanding. Does it work? (Scientific American)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-09-08

Worming its way through WeChat.

30 min Transcript
View

Researchers build a self-propagating attack against WeChat. Threat actors move toward multi-agent AI frameworks. N-able issues an emergency patch for a maximum-severity bug under active exploitation. MikroTik patches multiple RouterOS vulnerabilities. China accesses restricted American technology through subsidiaries and overseas partners. An active phishing campaign abuses legitimate Google services to make malicious links appear trustworthy. Australians may soon be able to disable the algorithm. Monday business briefing. Jason Lancaster, Chief Investigations Officer at SpyCloud, discusses how AI is affecting shifting cybercrime from traditional investigations to agentic AI at scale. Electromagnetic eavesdropping gets personal.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Jason Lancaster, Chief Investigations Officer at SpyCloud, discussing how AI is affecting shifting cybercrime from traditional investigations to agentic AI at scale.

Selected Reading

A.I. Models Built a Computer Worm That Could Rapidly Hack WeChat Accounts (The New York Times)

Hackers build AI frameworks for widescale credential theft (Bleeping Computer)

N-able Issues Emergency Hotfix for Maximum-Severity Unauthenticated RCE in N-central (Beyond Machines)

MikroTik Patches Critical Flaws Chained to Hack Routers (SecurityWeek)

How a Blacklisted Chinese Tech Giant Kept Buying America’s Best A.I. Chips (The New York Times)

Bypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a Trust Proxy (KnowBe4)

‘Global reckoning for big tech’: Australia to force social media platforms to allow users to opt out of algorithms (The Guardian)

Socure raises $156 million and acquires agentic AI platform Fravity. (N2K Pro Business Briefing)

New attack eavesdrops on headphone audio from 30 meters away (CyberInsider)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Researchers build a self-propagating attack against WeChat. Threat actors move toward multi-agent AI frameworks. N-able issues an emergency patch for a maximum-severity bug under active exploitation. MikroTik patches multiple RouterOS vulnerabilities. China accesses restricted American technology through subsidiaries and overseas partners. An active phishing campaign abuses legitimate Google services to make malicious links appear trustworthy. Australians may soon be able to disable the algorithm. Monday business briefing. Jason Lancaster, Chief Investigations Officer at SpyCloud, discusses how AI is affecting shifting cybercrime from traditional investigations to agentic AI at scale. Electromagnetic eavesdropping gets personal.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Jason Lancaster, Chief Investigations Officer at SpyCloud, discussing how AI is affecting shifting cybercrime from traditional investigations to agentic AI at scale.

Selected Reading

A.I. Models Built a Computer Worm That Could Rapidly Hack WeChat Accounts (The New York Times)

Hackers build AI frameworks for widescale credential theft (Bleeping Computer)

N-able Issues Emergency Hotfix for Maximum-Severity Unauthenticated RCE in N-central (Beyond Machines)

MikroTik Patches Critical Flaws Chained to Hack Routers (SecurityWeek)

How a Blacklisted Chinese Tech Giant Kept Buying America’s Best A.I. Chips (The New York Times)

Bypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a Trust Proxy (KnowBe4)

‘Global reckoning for big tech’: Australia to force social media platforms to allow users to opt out of algorithms (The Guardian)

Socure raises $156 million and acquires agentic AI platform Fravity. (N2K Pro Business Briefing)

New attack eavesdrops on headphone audio from 30 meters away (CyberInsider)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-09-07

This call may be monitored. [Special Edition]

38 min Transcript
View

In this Special Episode, Maria Varmazis and Dave Bittner are joined by friend of the show, Brandon Karpf, to unpack a new bipartisan congressional investigation into the lingering presence of Chinese state-owned telecommunications companies inside U.S. internet infrastructure.

The House Select Committee on China says China Mobile, China Unicom, and China Telecom remain deeply embedded in American networks even after federal regulators denied or revoked their authority to provide certain telecommunications services over national security concerns. The investigation found that restrictions imposed by the FCC limited what the companies could sell, but did not necessarily remove their equipment, network connections, or commercial relationships from the U.S. internet ecosystem.

Links to stories:

More description

In this Special Episode, Maria Varmazis and Dave Bittner are joined by friend of the show, Brandon Karpf, to unpack a new bipartisan congressional investigation into the lingering presence of Chinese state-owned telecommunications companies inside U.S. internet infrastructure.

The House Select Committee on China says China Mobile, China Unicom, and China Telecom remain deeply embedded in American networks even after federal regulators denied or revoked their authority to provide certain telecommunications services over national security concerns. The investigation found that restrictions imposed by the FCC limited what the companies could sell, but did not necessarily remove their equipment, network connections, or commercial relationships from the U.S. internet ecosystem.

Links to stories:

The accurate timing data from spacecraft has become an invaluable tool for nearly every critical infrastructure sector and a greater target for malicious actors.

Host Maria Varmazis and Andy Davis⁠, Global Research Director at the NCC Group, discuss the importance of timing in space. The two look at how timing systems have continued to grow more important in everyday life and why attackers have begun to increasingly exploit these critical services.

Key sources:

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: ⁠⁠⁠⁠⁠https://thecyberwire.com/newsletters/signals-and-space⁠⁠⁠⁠⁠

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to ⁠⁠⁠⁠⁠space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: ⁠⁠⁠⁠⁠https://www.surveymonkey.com/r/NJYCN2P ⁠⁠⁠⁠⁠

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. ⁠⁠⁠⁠⁠N2K⁠⁠⁠⁠⁠ is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at ⁠⁠⁠⁠⁠n2k.com⁠⁠⁠⁠⁠.

More description

The accurate timing data from spacecraft has become an invaluable tool for nearly every critical infrastructure sector and a greater target for malicious actors.

Host Maria Varmazis and Andy Davis⁠, Global Research Director at the NCC Group, discuss the importance of timing in space. The two look at how timing systems have continued to grow more important in everyday life and why attackers have begun to increasingly exploit these critical services.

Key sources:

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: ⁠⁠⁠⁠⁠https://thecyberwire.com/newsletters/signals-and-space⁠⁠⁠⁠⁠

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to ⁠⁠⁠⁠⁠space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: ⁠⁠⁠⁠⁠https://www.surveymonkey.com/r/NJYCN2P ⁠⁠⁠⁠⁠

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. ⁠⁠⁠⁠⁠N2K⁠⁠⁠⁠⁠ is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at ⁠⁠⁠⁠⁠n2k.com⁠⁠⁠⁠⁠.

Extract Knowledge
Listen elsewhere
Published 2026-09-05

RMM-ber this ransomware. [Research Saturday]

19 min Transcript
View

Ismael Valenzuela, Vice President of Labs, Threat Research and Intelligence at Arctic Wolf, sits down with Dave to discuss their work tracking Anubis. Arctic Wolf Labs details a series of 2026 Anubis ransomware intrusions, revealing affiliates using stolen VPN credentials and exploiting CitrixBleed 2 to gain initial access.

Attackers then blended into legitimate IT activity by deploying RMM tools, using RDP and PsExec for lateral movement, stealing credentials, and establishing tunnels and proxies for persistence and exfiltration. The research highlights a repeatable attack chain defenders can disrupt before encryption, from suspicious remote access and unauthorized RMM deployment to credential theft, security-tool tampering, and ransomware execution.


The research and executive brief can be found here:

More description

Ismael Valenzuela, Vice President of Labs, Threat Research and Intelligence at Arctic Wolf, sits down with Dave to discuss their work tracking Anubis. Arctic Wolf Labs details a series of 2026 Anubis ransomware intrusions, revealing affiliates using stolen VPN credentials and exploiting CitrixBleed 2 to gain initial access.

Attackers then blended into legitimate IT activity by deploying RMM tools, using RDP and PsExec for lateral movement, stealing credentials, and establishing tunnels and proxies for persistence and exfiltration. The research highlights a repeatable attack chain defenders can disrupt before encryption, from suspicious remote access and unauthorized RMM deployment to credential theft, security-tool tampering, and ransomware execution.


The research and executive brief can be found here:

Published 2026-09-04

What the Flock?

31 min Transcript
View

The G7 and CISA prepare for the quantum threat. Nightmare Eclipse drops a CrowdStrike zero-day. The White House’s offensive hacking plan raises legal questions. CISA offers a playbook for communicating through cyber incidents. OpenAI puts a billion dollars behind AI-powered defense. Researchers uncover a serious PostgreSQL flaw. Google patches an exploited Chrome zero-day. Broadcom fixes VMware vulnerabilities. Attackers target a WordPress plugin flaw. Lawmakers tell license plate surveillance cameras to “Flock off.”  Our guest is Kevin Gosschalk, Founder and CEO of Arkose Labs, discussing his new book, After Bots, which questions the old assumption that automated traffic is inherently malicious. Camouflage for the algorithmic age. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Kevin Gosschalk, Founder and CEO of Arkose Labs, joins us to discuss his new book, After Bots, and why the old assumption that automated traffic is inherently malicious no longer works.

Selected Reading

G7 urges organizations to prepare for quantum cyber threats (The Record)

Analysts: Trump Cyber Program Could Cost Firms Legal Shields (BankInfo Security)

Communicating Under Pressure: Best Practices for Service Providers (IC3)

OpenAI Pledges $1bn to Bring its AI Cybersecurity Tools to Essential S (Infosecurity Magazine)

12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover (SecurityWeek)

Google warns of new Chrome zero-day flaw exploited in attacks (Bleeping Computer)

VMware Workstation and Fusion Updates Patch Critical Vulnerability (SecurityWeek)

Critical Elementor Pro flaw exploited to take over WordPress sites (Bleeping Computer)

Flock Cameras Face Removal Nationwide Under New Bill (Newsweek)

Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC (The Register) 

This 'Digital Camouflage' Shirt Confuses AI-Powered Surveillance Cameras (404 Media)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

The G7 and CISA prepare for the quantum threat. Nightmare Eclipse drops a CrowdStrike zero-day. The White House’s offensive hacking plan raises legal questions. CISA offers a playbook for communicating through cyber incidents. OpenAI puts a billion dollars behind AI-powered defense. Researchers uncover a serious PostgreSQL flaw. Google patches an exploited Chrome zero-day. Broadcom fixes VMware vulnerabilities. Attackers target a WordPress plugin flaw. Lawmakers tell license plate surveillance cameras to “Flock off.”  Our guest is Kevin Gosschalk, Founder and CEO of Arkose Labs, discussing his new book, After Bots, which questions the old assumption that automated traffic is inherently malicious. Camouflage for the algorithmic age. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Kevin Gosschalk, Founder and CEO of Arkose Labs, joins us to discuss his new book, After Bots, and why the old assumption that automated traffic is inherently malicious no longer works.

Selected Reading

G7 urges organizations to prepare for quantum cyber threats (The Record)

Analysts: Trump Cyber Program Could Cost Firms Legal Shields (BankInfo Security)

Communicating Under Pressure: Best Practices for Service Providers (IC3)

OpenAI Pledges $1bn to Bring its AI Cybersecurity Tools to Essential S (Infosecurity Magazine)

12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover (SecurityWeek)

Google warns of new Chrome zero-day flaw exploited in attacks (Bleeping Computer)

VMware Workstation and Fusion Updates Patch Critical Vulnerability (SecurityWeek)

Critical Elementor Pro flaw exploited to take over WordPress sites (Bleeping Computer)

Flock Cameras Face Removal Nationwide Under New Bill (Newsweek)

Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC (The Register) 

This 'Digital Camouflage' Shirt Confuses AI-Powered Surveillance Cameras (404 Media)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-09-03

Who’s watching the AI watchers?

24 min Transcript
View

A watchdog challenges the Trump administration’s secret frontier AI reviews. METR discloses two cyberattacks. Leaked documents reveal a Russian cyber training pipeline. Rogue ScreenConnect clients spread malware like a worm. A breach exposes appellate court records across the U.S. and Canada. Spring Ring impersonates IT support on Microsoft Teams. Plex urges users to patch, and Cisco warns of unpatched Secure Email flaws. Our guest is Rob van der Veer, Chief AI Officer at Software Improvement Group, discussing how we are not keeping up with the AI attack surface. Robocall report cards. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Rob van der Veer, Chief AI Officer at Software Improvement Group, discussing how we are not keeping up with AI attack surface.

Selected Reading

Trump may be forced to reveal secret rules feds use for AI safety testing (Ars Technica)

Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks (The Register)

2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators (Security Affairs)

Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity (Huntress)

A breach at Thomson Reuters reached appellate courts in twelve US jurisdictions (Thenextweb)

Spring Ring Vishing Attack Uses Fake IT Calls on Microsoft Teams to Install Malware (Hackread)

Plex warns users to patch security vulnerabilities immediately (Bleeping Computer)

Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities (SecurityWeek)

The FCC wants consumers to rate their telecom’s anti-robocall protections (CyberScoop)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

A watchdog challenges the Trump administration’s secret frontier AI reviews. METR discloses two cyberattacks. Leaked documents reveal a Russian cyber training pipeline. Rogue ScreenConnect clients spread malware like a worm. A breach exposes appellate court records across the U.S. and Canada. Spring Ring impersonates IT support on Microsoft Teams. Plex urges users to patch, and Cisco warns of unpatched Secure Email flaws. Our guest is Rob van der Veer, Chief AI Officer at Software Improvement Group, discussing how we are not keeping up with the AI attack surface. Robocall report cards. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Rob van der Veer, Chief AI Officer at Software Improvement Group, discussing how we are not keeping up with AI attack surface.

Selected Reading

Trump may be forced to reveal secret rules feds use for AI safety testing (Ars Technica)

Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks (The Register)

2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators (Security Affairs)

Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity (Huntress)

A breach at Thomson Reuters reached appellate courts in twelve US jurisdictions (Thenextweb)

Spring Ring Vishing Attack Uses Fake IT Calls on Microsoft Teams to Install Malware (Hackread)

Plex warns users to patch security vulnerabilities immediately (Bleeping Computer)

Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities (SecurityWeek)

The FCC wants consumers to rate their telecom’s anti-robocall protections (CyberScoop)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-09-02

Drive-by data theft.

30 min Transcript
View

Nexus sells driver’s license scans on the dark web. OpenAI says its models have reached a “Critical” capability threshold. International law enforcement disrupts a decades-old botnet. AI hallucinations fuel “slop squatting.” Plus, urgent patches for Cleo Harmony and Virtualizor, a Texas healthcare breach, and a Russian national accused of targeting thousands of freelancers with remote-access malware. Maria Varmazis shares the latest space-cyber news. Our guest is Rob Allen, Chief Product Officer at Threat Locker, talking about protecting against AI in the workplace. AI threatens the government’s bug supply.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On today’s Industry Voices we are joined by Rob Allen, Chief Product Officer at Threat Locker, talking about protecting against AI in the workplace. If you enjoyed this conversation, be sure to check out the full interview here.

Selected Reading

FBI Probes Service Selling 153M+ Drivers Licenses (Krebs on Security)

OpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity Threshold (SecurityWeek)

Sality botnet infrastructure dismantled in joint global takedown (Bleeping Computer)

Crooks Are Learning to Love AI Hallucinations (IEEE Spectrum)

MSSA Reference Architecture 2.0 (Mobile Satellite Services Association (MSSA))

Exploit Published for Fresh Cleo Harmony Vulnerability (SecurityWeek)

Malicious Virtualizor Update Served via BGP Hijacking (SecurityWeek)

Nutex Health Says Patient Data Stolen, Hackers Threaten Leak (Infosecurity Magazine)

US charges Russian for infecting 80,000 freelancers with malware (Bleeping Computer)

How AI could make it harder for governments to use hacking tools (TechCrunch)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Nexus sells driver’s license scans on the dark web. OpenAI says its models have reached a “Critical” capability threshold. International law enforcement disrupts a decades-old botnet. AI hallucinations fuel “slop squatting.” Plus, urgent patches for Cleo Harmony and Virtualizor, a Texas healthcare breach, and a Russian national accused of targeting thousands of freelancers with remote-access malware. Maria Varmazis shares the latest space-cyber news. Our guest is Rob Allen, Chief Product Officer at Threat Locker, talking about protecting against AI in the workplace. AI threatens the government’s bug supply.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On today’s Industry Voices we are joined by Rob Allen, Chief Product Officer at Threat Locker, talking about protecting against AI in the workplace. If you enjoyed this conversation, be sure to check out the full interview here.

Selected Reading

FBI Probes Service Selling 153M+ Drivers Licenses (Krebs on Security)

OpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity Threshold (SecurityWeek)

Sality botnet infrastructure dismantled in joint global takedown (Bleeping Computer)

Crooks Are Learning to Love AI Hallucinations (IEEE Spectrum)

MSSA Reference Architecture 2.0 (Mobile Satellite Services Association (MSSA))

Exploit Published for Fresh Cleo Harmony Vulnerability (SecurityWeek)

Malicious Virtualizor Update Served via BGP Hijacking (SecurityWeek)

Nutex Health Says Patient Data Stolen, Hackers Threaten Leak (Infosecurity Magazine)

US charges Russian for infecting 80,000 freelancers with malware (Bleeping Computer)

How AI could make it harder for governments to use hacking tools (TechCrunch)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-09-01

Nightmare on Windows 11.

27 min Transcript
View

Nightmare Eclipse drops a Kaspersky zero-day. The Financial Stability Board warns frontier AI could threaten the global financial system. Anthropic says it has tightened security. CISA adopts a risk-based approach to patching. A new Windows infostealer hides in fake AI models. A critical vulnerability in JFrog Artifactory is kneedeep in active exploitation. North Korean workers are still landing U.S. jobs. A classic NSA codebreaking machine. Our guest is Heather Ceylan, CISO at Box, discussing if AI becomes agentic, governance could become a resilience issue. A robot vacuum sucks up evidence. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today on our Industry Voices, we are joined by Heather Ceylan, CISO at Box, discussing as AI becomes agentic, governance becomes a resilience issue. If you enjoyed this conversation, be sure to check out the full interview here.

Selected Reading

Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher (SecurityAffairs)

Financial Stability Board Sounds the Alarm Over Frontier AI Risks (Infosecurity Magazine)

Unit 42 warns AI has shifted balance of power from defenders to attackers (CyberScoop)

Improving our alignment and security practices (Anthropic)

CISA vulnerability directive designed to ‘buy back time’ against hackers (Federal News Network)

RevStealer malware spread through fake Claude Opus 5 download (SC Media)

Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild (SecurityWeek)

North Korea-linked IT Workers Are Getting Hired Inside Western Companies (SecurityAffairs)

IBM Built the Cold War's Most Powerful Code Breaker for the NSA (IEEE Spectrum)

Man uses robot vacuum to covertly record his wife's affair, wins divorce settlement but gets sentenced to prison for making an illegal recording — Husband lands behind bars after counter-suit over privacy rights (Tom's Hardware)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Nightmare Eclipse drops a Kaspersky zero-day. The Financial Stability Board warns frontier AI could threaten the global financial system. Anthropic says it has tightened security. CISA adopts a risk-based approach to patching. A new Windows infostealer hides in fake AI models. A critical vulnerability in JFrog Artifactory is kneedeep in active exploitation. North Korean workers are still landing U.S. jobs. A classic NSA codebreaking machine. Our guest is Heather Ceylan, CISO at Box, discussing if AI becomes agentic, governance could become a resilience issue. A robot vacuum sucks up evidence. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today on our Industry Voices, we are joined by Heather Ceylan, CISO at Box, discussing as AI becomes agentic, governance becomes a resilience issue. If you enjoyed this conversation, be sure to check out the full interview here.

Selected Reading

Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher (SecurityAffairs)

Financial Stability Board Sounds the Alarm Over Frontier AI Risks (Infosecurity Magazine)

Unit 42 warns AI has shifted balance of power from defenders to attackers (CyberScoop)

Improving our alignment and security practices (Anthropic)

CISA vulnerability directive designed to ‘buy back time’ against hackers (Federal News Network)

RevStealer malware spread through fake Claude Opus 5 download (SC Media)

Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild (SecurityWeek)

North Korea-linked IT Workers Are Getting Hired Inside Western Companies (SecurityAffairs)

IBM Built the Cold War's Most Powerful Code Breaker for the NSA (IEEE Spectrum)

Man uses robot vacuum to covertly record his wife's affair, wins divorce settlement but gets sentenced to prison for making an illegal recording — Husband lands behind bars after counter-suit over privacy rights (Tom's Hardware)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-08-31

Let’s kill the kill switch.

27 min Transcript
View

Could an AI kill switch create more problems than it solves? A critical Rails flaw is under active attack. Malicious browser extensions steal cryptocurrency. Fire Ant targets trusted network infrastructure. Claude Code gets tricked into running attacker-controlled code. MyChart phishing scams spread malware. Two alleged sextortionists face U.S. charges. A former DIA insider walks into an FBI sting. Monday business briefing. Our guest is Tim Starks from CyberScoop discussing a controversial retail security bill. Getting local with Nigerian scammers.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Tim Starks from CyberScoop as he is discussing a controversial retail security bill.

Selected Reading

The AI Kill Switch Act is repeating the Clipper Chip’s mistakes (CyberScoop)

Critical Ruby on Rails Vulnerability in Attackers' Crosshairs (SecurityWeek)

Chrome Web Store extensions caught stealing crypto, browser data (Bleeping Computer)

China-linked Fire Ant Hides Inside Trusted Infrastructure (SecurityAffairs)

Researcher shows how Claude Code can be tricked simply by asking it to summarize a website (The Register)

Fake MyChart emails can show alarming test results, trick patients into installing malware (WMAR)

Nigerians extradited to US for sextortion, deaths of two teens (Bleeping Computer)

US government snitch-finder pleads guilty to leaking state secrets to foreign spies (The Register)

AI safety and security company Alice raises $140 million. (N2K Pro Business Briefing)

How Cyber Sleuths Tracked a Nigerian Scammer to His Doorstep (404 media)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Could an AI kill switch create more problems than it solves? A critical Rails flaw is under active attack. Malicious browser extensions steal cryptocurrency. Fire Ant targets trusted network infrastructure. Claude Code gets tricked into running attacker-controlled code. MyChart phishing scams spread malware. Two alleged sextortionists face U.S. charges. A former DIA insider walks into an FBI sting. Monday business briefing. Our guest is Tim Starks from CyberScoop discussing a controversial retail security bill. Getting local with Nigerian scammers.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Tim Starks from CyberScoop as he is discussing a controversial retail security bill.

Selected Reading

The AI Kill Switch Act is repeating the Clipper Chip’s mistakes (CyberScoop)

Critical Ruby on Rails Vulnerability in Attackers' Crosshairs (SecurityWeek)

Chrome Web Store extensions caught stealing crypto, browser data (Bleeping Computer)

China-linked Fire Ant Hides Inside Trusted Infrastructure (SecurityAffairs)

Researcher shows how Claude Code can be tricked simply by asking it to summarize a website (The Register)

Fake MyChart emails can show alarming test results, trick patients into installing malware (WMAR)

Nigerians extradited to US for sextortion, deaths of two teens (Bleeping Computer)

US government snitch-finder pleads guilty to leaking state secrets to foreign spies (The Register)

AI safety and security company Alice raises $140 million. (N2K Pro Business Briefing)

How Cyber Sleuths Tracked a Nigerian Scammer to His Doorstep (404 media)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

In this episode, Maria Varmazis and Dave Bittner from N2K Cyberwire get back together to discuss the evolution of advanced persistent threats (APTs), threat actor landscape, attribution changes, and the future of cyber espionage over the past decade. Join Dave and Maria as they explore how geopolitical factors, organizational professionalism, and emerging technologies like AI are shaping cybersecurity threats.

Together, they talk about:

  • The shift in attribution practices over the last 10 years.
  • The role of nation states and organized crime in cyber threats.
  • The impact of AI and emerging technologies on cyber warfare.
  • The challenges of naming and shaming threat groups.
  • The professionalization and organizational evolution of APT groups.
More description

In this episode, Maria Varmazis and Dave Bittner from N2K Cyberwire get back together to discuss the evolution of advanced persistent threats (APTs), threat actor landscape, attribution changes, and the future of cyber espionage over the past decade. Join Dave and Maria as they explore how geopolitical factors, organizational professionalism, and emerging technologies like AI are shaping cybersecurity threats.

Together, they talk about:

  • The shift in attribution practices over the last 10 years.
  • The role of nation states and organized crime in cyber threats.
  • The impact of AI and emerging technologies on cyber warfare.
  • The challenges of naming and shaming threat groups.
  • The professionalization and organizational evolution of APT groups.
Published 2026-08-29

Who let the AI hack? [Research Saturday]

23 min Transcript
View

Today we are joined by Crystal Morin, Senior Cybersecurity Strategist, and Michael Clark, Senior Director of Threat Research, at Sysdig, sharing their work on "LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools." The Sysdig Threat Research Team observed an attacker abusing an exposed, unauthenticated Ollama server as the “brain” for an automated offensive security tool.

The AI-powered framework can fingerprint services, identify vulnerabilities, craft exploits, extract credentials, and orchestrate attacks toward command execution, with researchers capturing the tool while it was still under active development. The activity highlights how LLMjacking is evolving from simply stealing AI compute for profit into using stolen model capacity to build increasingly autonomous offensive capabilities.

The research and executive brief can be found here:

More description

Today we are joined by Crystal Morin, Senior Cybersecurity Strategist, and Michael Clark, Senior Director of Threat Research, at Sysdig, sharing their work on "LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools." The Sysdig Threat Research Team observed an attacker abusing an exposed, unauthenticated Ollama server as the “brain” for an automated offensive security tool.

The AI-powered framework can fingerprint services, identify vulnerabilities, craft exploits, extract credentials, and orchestrate attacks toward command execution, with researchers capturing the tool while it was still under active development. The activity highlights how LLMjacking is evolving from simply stealing AI compute for profit into using stolen model capacity to build increasingly autonomous offensive capabilities.

The research and executive brief can be found here:

Published 2026-08-28

The blacklist boomerang.

29 min Transcript
View

A judge rules the Trump administration illegally labeled Anthropic a national security risk. The White House moves to keep foreign technology out of U.S. power systems. OpenAI rallies a global cyber defense push as its own AI agents exploit a Linux vulnerability. Researchers uncover a new speculative-execution attack and hidden implants in Chinese-made routers. A fake voicemail campaign slips past email defenses. PaperCut faces an exploited zero-day. And ServiceNow patches three maximum-severity flaws in its AI Platform. Maria Varmazis and I look back at a decade of emerging threat actors and APTs. NSA sends out a covert save-the-date.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today, as we continue celebrating the CyberWire Daily’s 10th anniversary, Maria Varmazis and Dave Bittner look back at a decade of emerging threat actors and APTs. Enjoyed the conversation? Be sure to tune in Sunday for a special edition featuring the full discussion.

Selected Reading

Trump Administration’s Blacklisting of Anthropic Was Illegal, Judge Rules (The New York Times)

White House bans foreign-made equipment for power generation over cyber backdoor concerns (The Record)

Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge (SecurityWeek)

A call for collective action on cyber defense (OpenAI)

New type of attack can slip past the defenses in your computer’s processor (MIT News)

Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign (Infosecurity Magazine)

OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems (SecurityWeek)

Hundreds of AI agents went rogue in OpenAI’s Hugging Face hack (POLITICO) 

PaperCut Releases Emergency Patch for Exploited Zero-Day (SecurityWeek)

ServiceNow warns of three max severity security vulnerabilities (Bleeping Computer)

Chinese Implants in the Supply Chain (VulnCheck)

Exclusive: NSA to host a hacker reunion in bid to rebuild secretive unit (The Record)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

A judge rules the Trump administration illegally labeled Anthropic a national security risk. The White House moves to keep foreign technology out of U.S. power systems. OpenAI rallies a global cyber defense push as its own AI agents exploit a Linux vulnerability. Researchers uncover a new speculative-execution attack and hidden implants in Chinese-made routers. A fake voicemail campaign slips past email defenses. PaperCut faces an exploited zero-day. And ServiceNow patches three maximum-severity flaws in its AI Platform. Maria Varmazis and I look back at a decade of emerging threat actors and APTs. NSA sends out a covert save-the-date.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today, as we continue celebrating the CyberWire Daily’s 10th anniversary, Maria Varmazis and Dave Bittner look back at a decade of emerging threat actors and APTs. Enjoyed the conversation? Be sure to tune in Sunday for a special edition featuring the full discussion.

Selected Reading

Trump Administration’s Blacklisting of Anthropic Was Illegal, Judge Rules (The New York Times)

White House bans foreign-made equipment for power generation over cyber backdoor concerns (The Record)

Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge (SecurityWeek)

A call for collective action on cyber defense (OpenAI)

New type of attack can slip past the defenses in your computer’s processor (MIT News)

Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign (Infosecurity Magazine)

OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems (SecurityWeek)

Hundreds of AI agents went rogue in OpenAI’s Hugging Face hack (POLITICO) 

PaperCut Releases Emergency Patch for Exploited Zero-Day (SecurityWeek)

ServiceNow warns of three max severity security vulnerabilities (Bleeping Computer)

Chinese Implants in the Supply Chain (VulnCheck)

Exclusive: NSA to host a hacker reunion in bid to rebuild secretive unit (The Record)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-08-27

Meta gets a Meta-sized bill.

31 min Transcript
View

Meta settles. Australian police arrest two alleged TeamPCP members. The White House moves to shore up water utility cybersecurity. ATF reports a major cyber incident. The Navy tells sailors to lock down social media. The FBI warns of a prolific Chinese hacking operation. Bill Gates sounds the alarm on AI. A purported think tank tries to influence chatbot answers. And attackers focus less on individual vulnerabilities and more on the vendors behind them. Our guest is Tim Springston, Principal Product Manager at Semperis, on achieving hybrid identity resilience in the age of agentic AI. Meta pumps the brakes on going AI native. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On today’s industry voices segment, we are joined by Tim Springston, Principal Product Manager at Semperis, discussing how to achieve hybrid identity resilience in the age of agentic AI. If you enjoyed this conversation, check out the full interview here.

Selected Reading

Meta agrees to pay $18 billion to settle US lawsuits over children's social media addiction (Reuters)

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia (Krebs on Security)

White House to unveil program to protect water systems against hackers (POLITICO)

DOJ firearms agency says hackers breached system containing investigation targets (The Record)

US Navy tells sailors and their families: scrub your social media, enemies are watching (Bitdefender)

Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI Warns (Infosecurity Magazine)

Bill Gates diagnoses problems with AI, but an expert questions his prescription (ABC News)

Fake US thinktank set up and funded by Israel sought to game AI for propaganda (The Guardian)

SentinelOne and Tenable Find Cyber Attackers Routinely Target Edge-Device Vendor Ecosystems Rather Than Individual Vulnerabilities (SentinelOne)

AI agents meant to replace Meta workers made “large-scale, disruptive actions” (Ars Technica)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Meta settles. Australian police arrest two alleged TeamPCP members. The White House moves to shore up water utility cybersecurity. ATF reports a major cyber incident. The Navy tells sailors to lock down social media. The FBI warns of a prolific Chinese hacking operation. Bill Gates sounds the alarm on AI. A purported think tank tries to influence chatbot answers. And attackers focus less on individual vulnerabilities and more on the vendors behind them. Our guest is Tim Springston, Principal Product Manager at Semperis, on achieving hybrid identity resilience in the age of agentic AI. Meta pumps the brakes on going AI native. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On today’s industry voices segment, we are joined by Tim Springston, Principal Product Manager at Semperis, discussing how to achieve hybrid identity resilience in the age of agentic AI. If you enjoyed this conversation, check out the full interview here.

Selected Reading

Meta agrees to pay $18 billion to settle US lawsuits over children's social media addiction (Reuters)

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia (Krebs on Security)

White House to unveil program to protect water systems against hackers (POLITICO)

DOJ firearms agency says hackers breached system containing investigation targets (The Record)

US Navy tells sailors and their families: scrub your social media, enemies are watching (Bitdefender)

Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI Warns (Infosecurity Magazine)

Bill Gates diagnoses problems with AI, but an expert questions his prescription (ABC News)

Fake US thinktank set up and funded by Israel sought to game AI for propaganda (The Guardian)

SentinelOne and Tenable Find Cyber Attackers Routinely Target Edge-Device Vendor Ecosystems Rather Than Individual Vulnerabilities (SentinelOne)

AI agents meant to replace Meta workers made “large-scale, disruptive actions” (Ars Technica)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-08-26

The feds flip the script.

32 min Transcript
View

The U.S. disrupts a Chinese hacking operation blamed for intrusions at several sensitive government agencies.  CISA says more than 100 water systems were targeted in July. Attackers exploit a critical Gitea flaw, while malicious pages masquerade as Cloudflare verification screens. Cyber insurance claims get costlier, and AI agents break out of their sandboxes. Boston Scientific battles a cyber incident. Plus, a new standard tracks AI agent activity, criminals target stolen iPhones, and an alleged money mule is charged in a $7.5 million scam. Our guest is Stephen Hilt,  Sr. Threat Researcher at TrendAI,  on the risks facing data centers.  Some breach data doesn’t quite measure up.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On today’s Industry Voices, we are joined by Stephen Hilt,  Sr. Threat Researcher at TrendAI discussing the cybersecurity risks facing data centers and the thousands of internet-exposed industrial control systems that could leave them vulnerable to attack. And if you enjoyed this conversation, be sure to check out the full interview here. 

If you’d like to hear more on this topic from TrendAI, you can check out this recent episode of the AI Security Brief podcast that focuses on data center security. Guest Mark Houpt, CISO at DataBank, joined hosts Johnny Hand and Dustin Childs to explain why securing the AI era starts with protecting the physical data centers that power it—and why proven security fundamentals still matter against rapidly evolving threats. AI Security Brief podcast publishes every other Thursday on the N2K CyberWire network. Subscribe today!

Selected Reading

China-sponsored hacking platforms seized by US, Justice Department says (Reuters)  

CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks (SecurityWeek)

Hackers now exploit critical Gitea flaw in code injection attacks (Bleeping Computer)

Hackers abuse npm mirrors to host phishing redirect pages (Bleeping Computer)

Average Cyber Insurance Losses Increase Despite Fewer Claims (Infosecurity Magazine)

VMs won't contain cyber-capable agents (Trail of Bits)

Boston Scientific hit by cyberattack, global operations affected (Reuters)

Linux Foundation Introduces TRACE Standard for AI Runtime Evidence (Infosecurity Magazine)

AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes (Bleeping Computer)

Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly (The Record)

Trump signs memo to help drastically boost US commercial space launches (Reuters) 

A Cautionary Tale About Data Breach Claims, Verification and Carhartt (Troy Hunt)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

The U.S. disrupts a Chinese hacking operation blamed for intrusions at several sensitive government agencies.  CISA says more than 100 water systems were targeted in July. Attackers exploit a critical Gitea flaw, while malicious pages masquerade as Cloudflare verification screens. Cyber insurance claims get costlier, and AI agents break out of their sandboxes. Boston Scientific battles a cyber incident. Plus, a new standard tracks AI agent activity, criminals target stolen iPhones, and an alleged money mule is charged in a $7.5 million scam. Our guest is Stephen Hilt,  Sr. Threat Researcher at TrendAI,  on the risks facing data centers.  Some breach data doesn’t quite measure up.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On today’s Industry Voices, we are joined by Stephen Hilt,  Sr. Threat Researcher at TrendAI discussing the cybersecurity risks facing data centers and the thousands of internet-exposed industrial control systems that could leave them vulnerable to attack. And if you enjoyed this conversation, be sure to check out the full interview here. 

If you’d like to hear more on this topic from TrendAI, you can check out this recent episode of the AI Security Brief podcast that focuses on data center security. Guest Mark Houpt, CISO at DataBank, joined hosts Johnny Hand and Dustin Childs to explain why securing the AI era starts with protecting the physical data centers that power it—and why proven security fundamentals still matter against rapidly evolving threats. AI Security Brief podcast publishes every other Thursday on the N2K CyberWire network. Subscribe today!

Selected Reading

China-sponsored hacking platforms seized by US, Justice Department says (Reuters)  

CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks (SecurityWeek)

Hackers now exploit critical Gitea flaw in code injection attacks (Bleeping Computer)

Hackers abuse npm mirrors to host phishing redirect pages (Bleeping Computer)

Average Cyber Insurance Losses Increase Despite Fewer Claims (Infosecurity Magazine)

VMs won't contain cyber-capable agents (Trail of Bits)

Boston Scientific hit by cyberattack, global operations affected (Reuters)

Linux Foundation Introduces TRACE Standard for AI Runtime Evidence (Infosecurity Magazine)

AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes (Bleeping Computer)

Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly (The Record)

Trump signs memo to help drastically boost US commercial space launches (Reuters) 

A Cautionary Tale About Data Breach Claims, Verification and Carhartt (Troy Hunt)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-08-25

CISA is running on empty.

28 min Transcript
View

Lawmakers request an investigation into cuts at CISA. Threat actors actively exploit a Zimbra Collaboration Suite vulnerability. A Chinese AI lab preps release of a powerful open-weight model. A new phishing toolkit deploys attacker-controlled passkeys. Using audio hardware to fingerprint browsers. A DDoS attack knocks Norwegian government services offline. CISA orders patching of a critical Oracle vulnerability. Taiwanese prosecutors charge nine people over the alleged illegal export of high-end AI servers to mainland China. Operation Jackal IV cracks down on West African cybercrime networks. On our Industry Voices segment, Christy Wyatt, CEO from Absolute Security, discusses "Cyber Resilience: The Emerging Category." AI music hits a sour note down under.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today on our Industry Voices segment, we are joined by Christy Wyatt, CEO from Absolute Security, discussing "Cyber Resilience: The Emerging Category." If you enjoyed this conversation, be sure to check out the full interview here.

Selected Reading

Lawmakers call for investigation into impact of CISA staffing cuts (The Record)

Hackers breached over 270 Zimbra servers in ongoing attacks (Bleeping Computer)

By Opening a Model, a Chinese A.I. Lab May Test the World’s Cybersecurity (NY Times)

iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset (SecurityAffairs)

AliExpress was silently running audio in your browser to fingerprint and track your device (TechSpot)

Large DDoS attack knocks Norwegian public services offline (The Record)

U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog (SecurityAffairs)

Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff (SecurityWeek)

Police arrests dozens of suspects in global cybercrime crackdown (Bleeping Computer)

Songs created by AI banned from Australia's music charts (BBC News)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Lawmakers request an investigation into cuts at CISA. Threat actors actively exploit a Zimbra Collaboration Suite vulnerability. A Chinese AI lab preps release of a powerful open-weight model. A new phishing toolkit deploys attacker-controlled passkeys. Using audio hardware to fingerprint browsers. A DDoS attack knocks Norwegian government services offline. CISA orders patching of a critical Oracle vulnerability. Taiwanese prosecutors charge nine people over the alleged illegal export of high-end AI servers to mainland China. Operation Jackal IV cracks down on West African cybercrime networks. On our Industry Voices segment, Christy Wyatt, CEO from Absolute Security, discusses "Cyber Resilience: The Emerging Category." AI music hits a sour note down under.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today on our Industry Voices segment, we are joined by Christy Wyatt, CEO from Absolute Security, discussing "Cyber Resilience: The Emerging Category." If you enjoyed this conversation, be sure to check out the full interview here.

Selected Reading

Lawmakers call for investigation into impact of CISA staffing cuts (The Record)

Hackers breached over 270 Zimbra servers in ongoing attacks (Bleeping Computer)

By Opening a Model, a Chinese A.I. Lab May Test the World’s Cybersecurity (NY Times)

iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset (SecurityAffairs)

AliExpress was silently running audio in your browser to fingerprint and track your device (TechSpot)

Large DDoS attack knocks Norwegian public services offline (The Record)

U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog (SecurityAffairs)

Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff (SecurityWeek)

Police arrests dozens of suspects in global cybercrime crackdown (Bleeping Computer)

Songs created by AI banned from Australia's music charts (BBC News)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-08-24

The odds were classified.

30 min Transcript
View

Polymarket traders win big on U.S. military insider information. Slovakia deactivates speed cameras with Russian backdoors. TikTok pays $400 million to settle kids' privacy allegations. Hackers infect Android-based car systems with botnet malware. CISA orders quick patching of an actively exploited Zimbra Collaboration Suite vulnerability. SynkLoader malware is built for stealthy access to corporate networks. Dutch authorities fine Uber over $900 million over automated hiring practices. An ATM jackpotter gets a record prison sentence. Monday business briefing. A privacy promise loses face. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On our Industry Voices segment, we are joined by Mark Beare, General Manager at Malwarebytes Consumer Business from Black Hat to look at protecting your family in the age of AI. If you enjoyed this conversation, check out the full interview here.

Selected Reading

More than 150 Polymarket wallets may have traded on military secrets, research finds (Reuters)

Slovakia discovers Russian backdoors in 279 new traffic cameras — SMS-triggered shell access and passwordless live feeds found in EU-funded rollout (Tom's Hardware)

TikTok Settles U.S. Child Privacy Case for $400 Million (Security Affairs)

Hackers infecting Android car systems to build proxy botnet (The Record)

CISA orders urgent patching of actively exploited Zimbra flaw (Bleeping Computer)

SynkLoader: when you throw in everything but the kitchen sink (Expel)

Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts (SecurityWeek)

Venezuelan Gets Record Federal Prison Term for ATM Jackpotting (SecurityWeek)

Fortinet has acquired San Francisco-based AI security company Virtue AI. (N2K Pro Business Briefing)

Reverse-Lookup Service Exposed Millions of Photos of People’s Faces (WIRED)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Polymarket traders win big on U.S. military insider information. Slovakia deactivates speed cameras with Russian backdoors. TikTok pays $400 million to settle kids' privacy allegations. Hackers infect Android-based car systems with botnet malware. CISA orders quick patching of an actively exploited Zimbra Collaboration Suite vulnerability. SynkLoader malware is built for stealthy access to corporate networks. Dutch authorities fine Uber over $900 million over automated hiring practices. An ATM jackpotter gets a record prison sentence. Monday business briefing. A privacy promise loses face. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On our Industry Voices segment, we are joined by Mark Beare, General Manager at Malwarebytes Consumer Business from Black Hat to look at protecting your family in the age of AI. If you enjoyed this conversation, check out the full interview here.

Selected Reading

More than 150 Polymarket wallets may have traded on military secrets, research finds (Reuters)

Slovakia discovers Russian backdoors in 279 new traffic cameras — SMS-triggered shell access and passwordless live feeds found in EU-funded rollout (Tom's Hardware)

TikTok Settles U.S. Child Privacy Case for $400 Million (Security Affairs)

Hackers infecting Android car systems to build proxy botnet (The Record)

CISA orders urgent patching of actively exploited Zimbra flaw (Bleeping Computer)

SynkLoader: when you throw in everything but the kitchen sink (Expel)

Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts (SecurityWeek)

Venezuelan Gets Record Federal Prison Term for ATM Jackpotting (SecurityWeek)

Fortinet has acquired San Francisco-based AI security company Virtue AI. (N2K Pro Business Briefing)

Reverse-Lookup Service Exposed Millions of Photos of People’s Faces (WIRED)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

As space infrastructure has continued to expand, developing secure space systems has become just as important as launching the spacecraft themselves.

In this week's episode, host Maria Varmazis sits down with Filip Rezabek, co-founder and CTO of Space Computer, to talk about some of the technologies being created to secure space infrastructure in orbit. The two discuss the importance of establishing a chain of trust in space and the challenges of securing hardware against supply chain attacks.

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: ⁠⁠⁠https://thecyberwire.com/newsletters/signals-and-space⁠⁠⁠

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to ⁠⁠⁠space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: ⁠⁠⁠https://www.surveymonkey.com/r/NJYCN2P ⁠⁠⁠

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. ⁠⁠⁠N2K⁠⁠⁠ is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at ⁠⁠⁠n2k.com⁠⁠⁠.

More description

As space infrastructure has continued to expand, developing secure space systems has become just as important as launching the spacecraft themselves.

In this week's episode, host Maria Varmazis sits down with Filip Rezabek, co-founder and CTO of Space Computer, to talk about some of the technologies being created to secure space infrastructure in orbit. The two discuss the importance of establishing a chain of trust in space and the challenges of securing hardware against supply chain attacks.

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: ⁠⁠⁠https://thecyberwire.com/newsletters/signals-and-space⁠⁠⁠

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to ⁠⁠⁠space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: ⁠⁠⁠https://www.surveymonkey.com/r/NJYCN2P ⁠⁠⁠

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. ⁠⁠⁠N2K⁠⁠⁠ is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at ⁠⁠⁠n2k.com⁠⁠⁠.

Extract Knowledge
Listen elsewhere
Published 2026-08-22

A RAT in the spreadsheet. [Research Saturday]

29 min Transcript
View

Today we are joined by Aaron Beardslee, Manager of Threat Research at Securonix, discussing "Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation." Securonix researchers have identified an evolved version of the SHEETCREEP espionage campaign, using a diplomatic-themed ISO phishing lure to deliver a C# remote access trojan targeting Indian diplomatic interests.

The malware abuses the Google Sheets API as a stealthy command-and-control channel, with researchers identifying 91 active victim tabs, including a high-confidence target in Pakistan. The campaign, assessed with moderate confidence as linked to Pakistan-aligned APT36, has added XOR-obfuscated configurations and other anti-analysis techniques to evade detection and maintain persistent access.

The research and executive brief can be found here:

More description

Today we are joined by Aaron Beardslee, Manager of Threat Research at Securonix, discussing "Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation." Securonix researchers have identified an evolved version of the SHEETCREEP espionage campaign, using a diplomatic-themed ISO phishing lure to deliver a C# remote access trojan targeting Indian diplomatic interests.

The malware abuses the Google Sheets API as a stealthy command-and-control channel, with researchers identifying 91 active victim tabs, including a high-confidence target in Pakistan. The campaign, assessed with moderate confidence as linked to Pakistan-aligned APT36, has added XOR-obfuscated configurations and other anti-analysis techniques to evade detection and maintain persistent access.

The research and executive brief can be found here:

Published 2026-08-21

The guest nobody invited.

31 min Transcript
View

CISA orders patching of TrueConf Server vulnerabilities. LockBit threatens release of stolen banking data. Researchers disclose a critical type confusion vulnerability in a Node.js library. A new Agent Tesla v4 campaign introduces enhanced evasion techniques. A novel malware delivery technique abuses FTP server banners to hide commands. Apple patches a critical image-processing flaw. A North Korean software supply chain attack targets the Rust ecosystem. Latvian officials resign following a major data breach. Defense contractors are confident in compliance, less so in their ability to prove it. Our guest is Patrick Coughlin, Co-Founder and CEO of Savi Security. discussing the free utility he’s developed to protect the sandwich generation from AI-driven scams. When it comes to cyber extortion, who you gonna call? 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Joining us today is Patrick Coughlin, Co-Founder and CEO of Savi Security. Patrick discusses protecting the sandwich generation from AI-driven scams and Scamwise, their free utility built with this purpose in mind. Learn more about Scamwise, a free public utility tool to help consumers quickly determine whether a suspicious message, call, or email is likely a scam, and download Savi’s app.

Selected Reading

CISA orders feds to patch actively exploited TrueConf Server flaws (Bleeping Computer)

US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline (The Register)

Critical Isolated-vm Vulnerability Leads to RCE on Host (SecurityWeek)

New Agent Tesla Malware Variant Boosts Evasion Capabilities (Infosecurity Magazine)

Hackers abuse FTP server banners to deliver new Windows malware (Bleeping Computer)

Apple plugs image-processing hole ripe for spyware abuse (The Register)

North Korean Hackers Tied to Rust Supply Chain Attack (Infosecurity Magazine)

Latvian officials resign after cyberattack exposes data on 1.2 million people (The Record)

Contractors' CMMC Confidence Rises as Ability to Prove It Falls Behind (SecurityWeek)

Ransomware crook poses as recovery firm to steal payments from fellow extortionists (The Register)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

CISA orders patching of TrueConf Server vulnerabilities. LockBit threatens release of stolen banking data. Researchers disclose a critical type confusion vulnerability in a Node.js library. A new Agent Tesla v4 campaign introduces enhanced evasion techniques. A novel malware delivery technique abuses FTP server banners to hide commands. Apple patches a critical image-processing flaw. A North Korean software supply chain attack targets the Rust ecosystem. Latvian officials resign following a major data breach. Defense contractors are confident in compliance, less so in their ability to prove it. Our guest is Patrick Coughlin, Co-Founder and CEO of Savi Security. discussing the free utility he’s developed to protect the sandwich generation from AI-driven scams. When it comes to cyber extortion, who you gonna call? 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Joining us today is Patrick Coughlin, Co-Founder and CEO of Savi Security. Patrick discusses protecting the sandwich generation from AI-driven scams and Scamwise, their free utility built with this purpose in mind. Learn more about Scamwise, a free public utility tool to help consumers quickly determine whether a suspicious message, call, or email is likely a scam, and download Savi’s app.

Selected Reading

CISA orders feds to patch actively exploited TrueConf Server flaws (Bleeping Computer)

US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline (The Register)

Critical Isolated-vm Vulnerability Leads to RCE on Host (SecurityWeek)

New Agent Tesla Malware Variant Boosts Evasion Capabilities (Infosecurity Magazine)

Hackers abuse FTP server banners to deliver new Windows malware (Bleeping Computer)

Apple plugs image-processing hole ripe for spyware abuse (The Register)

North Korean Hackers Tied to Rust Supply Chain Attack (Infosecurity Magazine)

Latvian officials resign after cyberattack exposes data on 1.2 million people (The Record)

Contractors' CMMC Confidence Rises as Ability to Prove It Falls Behind (SecurityWeek)

Ransomware crook poses as recovery firm to steal payments from fellow extortionists (The Register)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-08-20

The robots have gone bananas.

31 min Transcript
View

Federal agencies warn of an active campaign targeting critical infrastructure. Citrix races to patch critical NetScaler flaws. More than 50,000 exposed Stripe API keys raise fraud concerns. Black Hat and DEF CON attendees are targeted in a new social engineering campaign. Atlassian, Splunk, and Cisco fix hundreds of vulnerabilities. A new Android banking trojan adds an unusual twist. A healthcare breach impacts 3.8 million people. SilkParasite expands cyberespionage in Central Asia. And CISA eyes a major overhaul of federal cyber software procurement. Our guest is Chris Wallis, founder and CEO of Intruder, on how AI agents killed the annual pentest and are reshaping exposure management. AI powered robots find bananas quite appealing. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

On our Industry Voices segment, Intruder’s Founder and CEO Chris Wallis joined Dave at Black Hat to discuss why the annual pentest Is dead and how AI agents are reshaping exposure management. If you enjoyed this conversation, be sure to check out the full interview here.


Selected Reading

NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology (The Record)

Citrix urges admins to patch new NetScaler flaws as soon as possible (Bleeping Computer)

50,000 Stripe Secrets Leaked in Public Code (SecurityAffairs)

Black Hat/DEF CON attendees targeted in malware scheme with Google Doc lure (SC World)

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities (SecurityWeek)

Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities (SecurityWeek)

New Manic Android malware can exfiltrate data through nearby devices (Bleeping Computer)

EHR Vendor Notifying 3.8 Million Patients of Data Theft Hack (GovInfo Security)

SilkParasite: Tracking a China-Nexus APT Across Central Asia (Bitdefender)

CISA contemplates whether to hire security software buying help (Washington Technology)

I Saw the Future of AI in a Robot That Can Learn on the Spot (WIRED)


Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.  


Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Federal agencies warn of an active campaign targeting critical infrastructure. Citrix races to patch critical NetScaler flaws. More than 50,000 exposed Stripe API keys raise fraud concerns. Black Hat and DEF CON attendees are targeted in a new social engineering campaign. Atlassian, Splunk, and Cisco fix hundreds of vulnerabilities. A new Android banking trojan adds an unusual twist. A healthcare breach impacts 3.8 million people. SilkParasite expands cyberespionage in Central Asia. And CISA eyes a major overhaul of federal cyber software procurement. Our guest is Chris Wallis, founder and CEO of Intruder, on how AI agents killed the annual pentest and are reshaping exposure management. AI powered robots find bananas quite appealing. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

On our Industry Voices segment, Intruder’s Founder and CEO Chris Wallis joined Dave at Black Hat to discuss why the annual pentest Is dead and how AI agents are reshaping exposure management. If you enjoyed this conversation, be sure to check out the full interview here.


Selected Reading

NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology (The Record)

Citrix urges admins to patch new NetScaler flaws as soon as possible (Bleeping Computer)

50,000 Stripe Secrets Leaked in Public Code (SecurityAffairs)

Black Hat/DEF CON attendees targeted in malware scheme with Google Doc lure (SC World)

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities (SecurityWeek)

Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities (SecurityWeek)

New Manic Android malware can exfiltrate data through nearby devices (Bleeping Computer)

EHR Vendor Notifying 3.8 Million Patients of Data Theft Hack (GovInfo Security)

SilkParasite: Tracking a China-Nexus APT Across Central Asia (Bitdefender)

CISA contemplates whether to hire security software buying help (Washington Technology)

I Saw the Future of AI in a Robot That Can Learn on the Spot (WIRED)


Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.  


Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-08-19

Hackers hiding in plain sight.

28 min Transcript
View

Medusa’s reach grows. Cl0p expands its victim list. The DOJ charges 17 alleged Iranian hackers. CISA sounds the alarm on four exploited vulnerabilities. TWINLOOT hides in plain sight inside Microsoft 365. Maria Varmazis shares the latest from the space-cyber realm as Ukraine strikes Russia’s satellite nerve center. The FDA considers guardrails for AI medical devices. Expired credit cards get an unexpected second life. A disgruntled contractor heads to prison. Dave Bittner sits down with Brian Vecci, Field CTO at Varonis, at Black Hat USA to discuss how AI is calling your security bluff. Highway hijinks meet high-tech hardware.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

At Black Hat USA, Dave Bittner sat down with Brian Vecci, Field CTO at Varonis, as they discussed how AI is calling your security bluff. If you enjoyed this conversation, be sure to check out the full interview here.


Selected Reading

CISA: Medusa ransomware hit over 500 critical infrastructure orgs (Bleeping Computer)

US charges Iranians for sprawling hacking campaign on government agencies, universities (The Record)

Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign (SecurityWeek)

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities (SecurityWeek)

New TWINLOOT Malware Steals Windows Passwords Via Fake Lock Screen (Hackread)

Ukraine says it hit Russian rocket centre linked to Starlink-style network (CNBC)

FDA Weighing Possible Regs for GenAI Medical Devices (GovInfo Security)

Expired credit cards revived by researchers to make unauthorized payments (The Register)

Prison for data analyst who tried to extort $2.5 million from his employer (Bitdefender)

‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI Hardware (WIRED)


Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.  


Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Medusa’s reach grows. Cl0p expands its victim list. The DOJ charges 17 alleged Iranian hackers. CISA sounds the alarm on four exploited vulnerabilities. TWINLOOT hides in plain sight inside Microsoft 365. Maria Varmazis shares the latest from the space-cyber realm as Ukraine strikes Russia’s satellite nerve center. The FDA considers guardrails for AI medical devices. Expired credit cards get an unexpected second life. A disgruntled contractor heads to prison. Dave Bittner sits down with Brian Vecci, Field CTO at Varonis, at Black Hat USA to discuss how AI is calling your security bluff. Highway hijinks meet high-tech hardware.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

At Black Hat USA, Dave Bittner sat down with Brian Vecci, Field CTO at Varonis, as they discussed how AI is calling your security bluff. If you enjoyed this conversation, be sure to check out the full interview here.


Selected Reading

CISA: Medusa ransomware hit over 500 critical infrastructure orgs (Bleeping Computer)

US charges Iranians for sprawling hacking campaign on government agencies, universities (The Record)

Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign (SecurityWeek)

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities (SecurityWeek)

New TWINLOOT Malware Steals Windows Passwords Via Fake Lock Screen (Hackread)

Ukraine says it hit Russian rocket centre linked to Starlink-style network (CNBC)

FDA Weighing Possible Regs for GenAI Medical Devices (GovInfo Security)

Expired credit cards revived by researchers to make unauthorized payments (The Register)

Prison for data analyst who tried to extort $2.5 million from his employer (Bitdefender)

‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI Hardware (WIRED)


Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.  


Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-08-18

Fake it till you exfiltrate it.

28 min Transcript
View

A fake consultancy fronts an alleged Chinese spy campaign. Meta heads to court over claims it hooked young users. Researchers crack the mystery behind the French EncroChat hack. CISA warns ransomware gangs are exploiting a Windows flaw. Meet C2Looper, a new Rust-based backdoor. A critical WordPress plugin bug threatens hundreds of thousands of sites. MessiahGPT brings generative AI to cybercrime. A lender discloses a breach affecting 1.2 million people. A Ukrainian developer stands trial in Switzerland over alleged ransomware ties. Our guest is Ev Kontsevoy, CEO at Teleport, discussing how AI agents have nondeterministic behavior. The psychology of the endless scroll. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On today’s Industry Voices, we are joined by Ev Kontsevoy, CEO at Teleport, discussing how AI agents have nondeterministic behavior. If you enjoyed this conversation, check out the full interview here.

Selected Reading

A fake website and a deluge of CVs: the Australian firm embroiled in an FBI probe into alleged Chinese espionage (The Guardian)

States Seek $200 Billion From Meta Over Child Social Media Addiction Claims (The New York Times)

Revealed: Cyber spies used malware from GitHub to hack EncroChat cryptophone network (Computer Weekly)

CISA: Windows Task Host flaw now exploited by ransomware gangs (Bleeping Computer)

C2Looper Backdoor Uses GitHub for C2 (ThreatLabz)

300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw (SecurityWeek)

MessiahGPT Criminal AI Service Advertised on BreachForums (HackRead)

Heights Finance Data Breach Impacts at Least 1.2 Million Individuals (SecurityWeek)

Ukrainian software developer faces 12 years in Swiss ransomware trial (The Record from Recorded Future News)

Why Can't We Stop Scrolling? (Psychology Today)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

A fake consultancy fronts an alleged Chinese spy campaign. Meta heads to court over claims it hooked young users. Researchers crack the mystery behind the French EncroChat hack. CISA warns ransomware gangs are exploiting a Windows flaw. Meet C2Looper, a new Rust-based backdoor. A critical WordPress plugin bug threatens hundreds of thousands of sites. MessiahGPT brings generative AI to cybercrime. A lender discloses a breach affecting 1.2 million people. A Ukrainian developer stands trial in Switzerland over alleged ransomware ties. Our guest is Ev Kontsevoy, CEO at Teleport, discussing how AI agents have nondeterministic behavior. The psychology of the endless scroll. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On today’s Industry Voices, we are joined by Ev Kontsevoy, CEO at Teleport, discussing how AI agents have nondeterministic behavior. If you enjoyed this conversation, check out the full interview here.

Selected Reading

A fake website and a deluge of CVs: the Australian firm embroiled in an FBI probe into alleged Chinese espionage (The Guardian)

States Seek $200 Billion From Meta Over Child Social Media Addiction Claims (The New York Times)

Revealed: Cyber spies used malware from GitHub to hack EncroChat cryptophone network (Computer Weekly)

CISA: Windows Task Host flaw now exploited by ransomware gangs (Bleeping Computer)

C2Looper Backdoor Uses GitHub for C2 (ThreatLabz)

300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw (SecurityWeek)

MessiahGPT Criminal AI Service Advertised on BreachForums (HackRead)

Heights Finance Data Breach Impacts at Least 1.2 Million Individuals (SecurityWeek)

Ukrainian software developer faces 12 years in Swiss ransomware trial (The Record from Recorded Future News)

Why Can't We Stop Scrolling? (Psychology Today)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-08-17

Please hold while we decide.

28 min Transcript
View

Internal policy conflicts hamper U.S. military AI leadership. Clop claims GE, Philips and Shell. Attackers actively probe internet-facing GeoServer instances. “The Hatman” offers millions of alleged employee records for sale. ETSI begins the approval process for European cyber standards. Microsoft is still working on a patch for the ShieldBreak vulnerability. Autonomous AI systems create CPU bottlenecks. Monday business briefing. Our guest is Nick Warner, CEO at Neo.ai, on the shifting landscape around AI and agentic security. AI agents kneecap each other with self-replicating malware.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On today’s Industry Voices segment, we are joined by Nick Warner, Neo.ai's CEO, discussing the shifting landscape around AI and agentic security. If you enjoyed this conversation, be sure to check out the full interview here.

Selected Reading

The U.S. Military Wants A.I. Dominance. Feuds and China May Thwart It. (The New York Times)

Philips and GE investigating Clop ransomware data theft claims (Bleeping Computer)

Attackers Probe Critical GeoServer SQL Injection Vulnerability (Hack Read)

Crook hawks millions of records allegedly plundered from corporate Azure tenants (The Register)

ETSI Proposes 17 Cybersecurity Standards to Support EU CRA (Infosecurity Magazine)

Microsoft working on Defender patch for ShieldBreak zero-day (Bleeping Computer)

Agentic AI Crunch Creates CPU Comeback (IEEE Spectrum)

Corma raises $60 million in seed funding. (N2K)

Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware (SecurityWeek)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Internal policy conflicts hamper U.S. military AI leadership. Clop claims GE, Philips and Shell. Attackers actively probe internet-facing GeoServer instances. “The Hatman” offers millions of alleged employee records for sale. ETSI begins the approval process for European cyber standards. Microsoft is still working on a patch for the ShieldBreak vulnerability. Autonomous AI systems create CPU bottlenecks. Monday business briefing. Our guest is Nick Warner, CEO at Neo.ai, on the shifting landscape around AI and agentic security. AI agents kneecap each other with self-replicating malware.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On today’s Industry Voices segment, we are joined by Nick Warner, Neo.ai's CEO, discussing the shifting landscape around AI and agentic security. If you enjoyed this conversation, be sure to check out the full interview here.

Selected Reading

The U.S. Military Wants A.I. Dominance. Feuds and China May Thwart It. (The New York Times)

Philips and GE investigating Clop ransomware data theft claims (Bleeping Computer)

Attackers Probe Critical GeoServer SQL Injection Vulnerability (Hack Read)

Crook hawks millions of records allegedly plundered from corporate Azure tenants (The Register)

ETSI Proposes 17 Cybersecurity Standards to Support EU CRA (Infosecurity Magazine)

Microsoft working on Defender patch for ShieldBreak zero-day (Bleeping Computer)

Agentic AI Crunch Creates CPU Comeback (IEEE Spectrum)

Corma raises $60 million in seed funding. (N2K)

Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware (SecurityWeek)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

In this special edition from Black Hat, Dave Bittner sits down with ⁠Clint Gibler⁠, Cyber Lead at ⁠OpenAI⁠, and ⁠Robby Winchester⁠, Chief Global Professional Services Officer at ⁠SpecterOps⁠, to explore how frontier AI models are changing the way defenders approach cybersecurity.

The conversation moves beyond the hype to examine responsible AI deployment, AI red teaming, reducing noise in security workflows, and the balance between advanced models and human expertise. They also discuss OpenAI’s Trusted Access for Cyber program and what it takes to give security practitioners access to powerful AI capabilities while managing the risks of misuse.

Check out the full video here.

More description

In this special edition from Black Hat, Dave Bittner sits down with ⁠Clint Gibler⁠, Cyber Lead at ⁠OpenAI⁠, and ⁠Robby Winchester⁠, Chief Global Professional Services Officer at ⁠SpecterOps⁠, to explore how frontier AI models are changing the way defenders approach cybersecurity.

The conversation moves beyond the hype to examine responsible AI deployment, AI red teaming, reducing noise in security workflows, and the balance between advanced models and human expertise. They also discuss OpenAI’s Trusted Access for Cyber program and what it takes to give security practitioners access to powerful AI capabilities while managing the risks of misuse.

Check out the full video here.

As AI products proliferate, they continue to introduce new concerns, which have subtly eroded trust in imagery and content created by space-based infrastructure.

In this week's episode, host Maria Varmazis sits down with ⁠⁠⁠Dave Bittner and Brandon Karpf to look at Google's troubled implementation of Nano Banana 2 in Google Earth. The incident raises larger concerns regarding how AI systems are becoming deeper ingrained into everyday life despite their ability to be misused and spread misinformation.

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: ⁠⁠https://thecyberwire.com/newsletters/signals-and-space⁠⁠

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to ⁠⁠space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: ⁠⁠https://www.surveymonkey.com/r/NJYCN2P ⁠⁠

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. ⁠⁠N2K⁠⁠ is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at ⁠⁠n2k.com⁠⁠.

More description

As AI products proliferate, they continue to introduce new concerns, which have subtly eroded trust in imagery and content created by space-based infrastructure.

In this week's episode, host Maria Varmazis sits down with ⁠⁠⁠Dave Bittner and Brandon Karpf to look at Google's troubled implementation of Nano Banana 2 in Google Earth. The incident raises larger concerns regarding how AI systems are becoming deeper ingrained into everyday life despite their ability to be misused and spread misinformation.

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: ⁠⁠https://thecyberwire.com/newsletters/signals-and-space⁠⁠

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to ⁠⁠space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: ⁠⁠https://www.surveymonkey.com/r/NJYCN2P ⁠⁠

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. ⁠⁠N2K⁠⁠ is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at ⁠⁠n2k.com⁠⁠.

Extract Knowledge
Listen elsewhere

Today we are joined by Ian Goldin, Senior Lead Information Security Engineer, and Mike Horka, Principal Information Security Engineer, from Lumen's Black Lotus Labs, discussing their research entitled "Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation." Black Lotus Labs has uncovered a major resurgence of the JDY botnet, a China-nexus reconnaissance network now comprising more than 1,500 compromised SOHO and IoT devices.

The botnet uses these devices to conduct targeted scanning and fingerprinting, helping threat actors rapidly identify vulnerable infrastructure—sometimes within hours of a new vulnerability disclosure—and appears to have a particular focus on U.S. military-related networks. The research highlights how compromised routers and IoT devices can be turned into distributed reconnaissance infrastructure that evades traditional IP-based defenses and supports follow-on exploitation.

The research and executive brief can be found here:

More description

Today we are joined by Ian Goldin, Senior Lead Information Security Engineer, and Mike Horka, Principal Information Security Engineer, from Lumen's Black Lotus Labs, discussing their research entitled "Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation." Black Lotus Labs has uncovered a major resurgence of the JDY botnet, a China-nexus reconnaissance network now comprising more than 1,500 compromised SOHO and IoT devices.

The botnet uses these devices to conduct targeted scanning and fingerprinting, helping threat actors rapidly identify vulnerable infrastructure—sometimes within hours of a new vulnerability disclosure—and appears to have a particular focus on U.S. military-related networks. The research highlights how compromised routers and IoT devices can be turned into distributed reconnaissance infrastructure that evades traditional IP-based defenses and supports follow-on exploitation.

The research and executive brief can be found here:

Published 2026-08-14

Apple has a message for you.

22 min Transcript
View

Apple sends out threat notifications to users targeted by spyware. Trivy, not LiteLLM, was the original source of the 2,500-organization supply chain attack. French tax authority confirms data breach. Chinese hack-for-hire group conducts espionage and cybercrime simultaneously. Ukrainian police shut down 94 scam call centers. Former data analyst jailed for insider extortion plot. New macOS malware spreads via ClickFix. Today we are joined by Tom Kellermann, VP of AI Security at TrendAI, discussing the machine-speed war for financial control. And the glitch in the surveillance matrix.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Tom Kellermann, VP of AI Security at TrendAI, discussing the machine-speed war for financial control. If you want to learn more on this topic, check out the article here. You can also check out Tom on the AI Security Brief here.

Selected Reading

If Apple sends you a push notification alerting you to a spyware attack, take it seriously (TechCrunch)

Trivy, Not LiteLLM Behind the 2,500 Org Compromise (SecurityWeek)

France investigates tax authority breach after hacker claims 600,000 victims (The Record)

Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side (Symantec)

AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers (Jamf)

Ukraine shuts down 94 fraudulent call centers, seize millions in cash (BleepingComputer)

This 'adversarial' pattern can prevent surveillance cameras from detecting you (TechCrunch)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Apple sends out threat notifications to users targeted by spyware. Trivy, not LiteLLM, was the original source of the 2,500-organization supply chain attack. French tax authority confirms data breach. Chinese hack-for-hire group conducts espionage and cybercrime simultaneously. Ukrainian police shut down 94 scam call centers. Former data analyst jailed for insider extortion plot. New macOS malware spreads via ClickFix. Today we are joined by Tom Kellermann, VP of AI Security at TrendAI, discussing the machine-speed war for financial control. And the glitch in the surveillance matrix.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Tom Kellermann, VP of AI Security at TrendAI, discussing the machine-speed war for financial control. If you want to learn more on this topic, check out the article here. You can also check out Tom on the AI Security Brief here.

Selected Reading

If Apple sends you a push notification alerting you to a spyware attack, take it seriously (TechCrunch)

Trivy, Not LiteLLM Behind the 2,500 Org Compromise (SecurityWeek)

France investigates tax authority breach after hacker claims 600,000 victims (The Record)

Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side (Symantec)

AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers (Jamf)

Ukraine shuts down 94 fraudulent call centers, seize millions in cash (BleepingComputer)

This 'adversarial' pattern can prevent surveillance cameras from detecting you (TechCrunch)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-08-13

Please hack responsibly.

24 min Transcript
View

President Trump deputizes private-sector companies to target cybercriminals. The LiteLLM supply-chain attack exposed credentials belonging to thousands of organizations. Data-theft campaign targets misconfigured Salesforce and ServiceNow instances. Hackers deploy AI agents to breach Taiwanese government systems. CISA mandates urgent patch for actively exploited Cisco firewall vulnerability. Nightmare Eclipse publishes yet another Windows zero-day exploit. On our Industry Voices segment, Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps, discuss frontier models and the future of cyber defense. And please do not reply. Seriously.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today on our Industry Voices segment, Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps, speak with Dave Bittner at Black Hat about frontier models and the future of cyber defense, including responsible AI deployment, red teaming, reducing security noise, and the evolving role of human expertise in AI-assisted defense. If you enjoyed this conversation, be sure to check out the full interview here.

Selected Reading

Trump turns to private sector in offensive hacking operations memo (CyberScoop)

Terabytes of credentials leaked in massive supply-chain attack (Ars Technica)

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals (BleepingComputer)

'Near-autonomous' AI agents attack Taiwan's nuclear safety agency (The Register)

Cisco says software vulnerability could let hackers crash firewalls (Cybersecurity Dive)

Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows (The Register)

Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All (WIRED)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

President Trump deputizes private-sector companies to target cybercriminals. The LiteLLM supply-chain attack exposed credentials belonging to thousands of organizations. Data-theft campaign targets misconfigured Salesforce and ServiceNow instances. Hackers deploy AI agents to breach Taiwanese government systems. CISA mandates urgent patch for actively exploited Cisco firewall vulnerability. Nightmare Eclipse publishes yet another Windows zero-day exploit. On our Industry Voices segment, Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps, discuss frontier models and the future of cyber defense. And please do not reply. Seriously.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today on our Industry Voices segment, Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps, speak with Dave Bittner at Black Hat about frontier models and the future of cyber defense, including responsible AI deployment, red teaming, reducing security noise, and the evolving role of human expertise in AI-assisted defense. If you enjoyed this conversation, be sure to check out the full interview here.

Selected Reading

Trump turns to private sector in offensive hacking operations memo (CyberScoop)

Terabytes of credentials leaked in massive supply-chain attack (Ars Technica)

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals (BleepingComputer)

'Near-autonomous' AI agents attack Taiwan's nuclear safety agency (The Register)

Cisco says software vulnerability could let hackers crash firewalls (Cybersecurity Dive)

Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows (The Register)

Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All (WIRED)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-08-12

A flurry of fixes.

26 min Transcript
View

We got your Patch Tuesday notes. Attackers target Microsoft SharePoint vulnerability following PoC release. Cyberattack on CEVA Logistics causes ongoing supply chain disruptions. Wesco confirms data breach following extortion claims. Akira ransomware bypasses EDR in Safe Mode. California announces AI cybersecurity fund. N2K’s Lead Analyst Ethan Cook shares about cyber weapons for space. Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain. And fasten your seatbelts and ignore the fake Wi-Fi.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On today’s Industry Voices, Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain, including AgentBaiting, where fake AI Skills and MCP servers were used to deliver malware, and hidden instructions that can influence AI agents. If you enjoyed the conversation, be sure to check out the full interview here.

Selected Reading

Microsoft and Adobe Patch Tuesday, August 2026 Security Update Review (Qualys)

Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack (Check Point Research)

Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability CSO Online

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact (SecurityWeek)

Hackers leverage new Microsoft SharePoint exploit in attacks (BleepingComputer)

The CEVA Logistics data breach is having major knock-on effects across Europe - here's what we know (TechRadar)

Wesco confirms security incident after ExfilSquad claims data theft (BleepingComputer)

Akira Hits Safe Mode: Ransomware Rebooting Around EDR (Huntress)

California Building ‘AI Cyber Defense Fund’ to Protect Critical Infrastructure From Hackers (Gizmodo)

Laser weapons for space? US officials see threat, opportunity (BREAKING DEFENSE) 

DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi (The Register)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

We got your Patch Tuesday notes. Attackers target Microsoft SharePoint vulnerability following PoC release. Cyberattack on CEVA Logistics causes ongoing supply chain disruptions. Wesco confirms data breach following extortion claims. Akira ransomware bypasses EDR in Safe Mode. California announces AI cybersecurity fund. N2K’s Lead Analyst Ethan Cook shares about cyber weapons for space. Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain. And fasten your seatbelts and ignore the fake Wi-Fi.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On today’s Industry Voices, Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain, including AgentBaiting, where fake AI Skills and MCP servers were used to deliver malware, and hidden instructions that can influence AI agents. If you enjoyed the conversation, be sure to check out the full interview here.

Selected Reading

Microsoft and Adobe Patch Tuesday, August 2026 Security Update Review (Qualys)

Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack (Check Point Research)

Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability CSO Online

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact (SecurityWeek)

Hackers leverage new Microsoft SharePoint exploit in attacks (BleepingComputer)

The CEVA Logistics data breach is having major knock-on effects across Europe - here's what we know (TechRadar)

Wesco confirms security incident after ExfilSquad claims data theft (BleepingComputer)

Akira Hits Safe Mode: Ransomware Rebooting Around EDR (Huntress)

California Building ‘AI Cyber Defense Fund’ to Protect Critical Infrastructure From Hackers (Gizmodo)

Laser weapons for space? US officials see threat, opportunity (BREAKING DEFENSE) 

DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi (The Register)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-08-11

A private route to public risk.

20 min Transcript
View

Poland’s CERT describes winter cyberattack against heat-and-power plant. Russian military hackers target Ukrainian IT workers in fake recruitment scheme. Chinese IP connections spark security review in UK Navy drones. US and South Korea warn of “Gunra” ransomware gang with North Korean ties. OpenAI mandates strict security controls for its new cybersecurity model. Record-breaking DDoS attacks surge in H1 2026. Data-scraping AI extension returns to the Chrome Web Store. Dave Bittner sat down with Stephen Harrison, VP of Product at Abnormal AI at Black Hat USA to discuss "The Identities Your Security Stack Is Ignoring." And no pain, no gain, no authorization.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today on our Industry Voices, Dave Bittner sat down with Stephen Harrison, VP of Product at Abnormal AI at Black Hat USA to discuss "The Identities Your Security Stack Is Ignoring." If you enjoyed this conversation, be sure to check out the full interview here.

Selected Reading

Hackers breached a small Polish energy plant via private APN last year (BleepingComputer)

Russian military hackers pose as recruiters to target Ukrainian IT workers (The Record)

Cyber vulnerability sweep picks up Royal Navy drones sending data to China (The Register)

U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang (CyberScoop)

OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns (SecurityWeek)

Cloudflare DDoS Threat Report H1 2026 (Cloudflare)

Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities (SecurityWeek)

AI assistant hacks gym website in first known Australian autonomous cyber attack (ABC News)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Poland’s CERT describes winter cyberattack against heat-and-power plant. Russian military hackers target Ukrainian IT workers in fake recruitment scheme. Chinese IP connections spark security review in UK Navy drones. US and South Korea warn of “Gunra” ransomware gang with North Korean ties. OpenAI mandates strict security controls for its new cybersecurity model. Record-breaking DDoS attacks surge in H1 2026. Data-scraping AI extension returns to the Chrome Web Store. Dave Bittner sat down with Stephen Harrison, VP of Product at Abnormal AI at Black Hat USA to discuss "The Identities Your Security Stack Is Ignoring." And no pain, no gain, no authorization.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today on our Industry Voices, Dave Bittner sat down with Stephen Harrison, VP of Product at Abnormal AI at Black Hat USA to discuss "The Identities Your Security Stack Is Ignoring." If you enjoyed this conversation, be sure to check out the full interview here.

Selected Reading

Hackers breached a small Polish energy plant via private APN last year (BleepingComputer)

Russian military hackers pose as recruiters to target Ukrainian IT workers (The Record)

Cyber vulnerability sweep picks up Royal Navy drones sending data to China (The Register)

U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang (CyberScoop)

OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns (SecurityWeek)

Cloudflare DDoS Threat Report H1 2026 (Cloudflare)

Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities (SecurityWeek)

AI assistant hacks gym website in first known Australian autonomous cyber attack (ABC News)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-08-10

Now with extra vulnerabilities.

27 min Transcript
View

Researchers find that only a quarter of AI-generated patches are fully successful. Ransomware attacks exploit critical N-able flaw. Atlassian fixes critical flaw in Rovo AI. LexisNexis disables some services following suspicious activity. US Senate confirms Adam Cassady as cyber ambassador. Meta ordered to pay an additional $567 million in child safety case. Water sector cyberattacks expand to new states. We got your Monday Business Briefing. On our Industry Voices, Dave Bittner sits down with Mujtaba Hamid, EVP, Product and Strategy at Booz Allen Hamilton at Black Hat discussing AI Speed Cyber Defense. And scammers set sail on The Odyssey.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today on our Industry Voices, Dave Bittner sat down with Mujtaba Hamid, EVP, Product and Strategy at Booz Allen Hamilton at Black Hat USA, discussing AI Speed Cyber Defense. If you enjoyed this conversation, be sure to check out the full interview here.

Selected Reading

More than half of AI-generated patches are broken (CyberScoop)

China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns (The Record)

Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data (SecurityWeek)

LexisNexis shuts down services after suspicious activity on servers (BleepingComputer)

US cyber ambassador nominee Cassady confirmed in Senate (The Record)

Meta Ordered to Pay $567 Million in New Mexico Child Safety Case (New York Times)

New Jersey, Alabama Join States Targeted in Water Cyberattacks (Securityweek)

Business Breakdown (N2K)

‘Watch The Odyssey for free online’: scam targets film fans with fake streaming sites (The Guardian)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Researchers find that only a quarter of AI-generated patches are fully successful. Ransomware attacks exploit critical N-able flaw. Atlassian fixes critical flaw in Rovo AI. LexisNexis disables some services following suspicious activity. US Senate confirms Adam Cassady as cyber ambassador. Meta ordered to pay an additional $567 million in child safety case. Water sector cyberattacks expand to new states. We got your Monday Business Briefing. On our Industry Voices, Dave Bittner sits down with Mujtaba Hamid, EVP, Product and Strategy at Booz Allen Hamilton at Black Hat discussing AI Speed Cyber Defense. And scammers set sail on The Odyssey.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today on our Industry Voices, Dave Bittner sat down with Mujtaba Hamid, EVP, Product and Strategy at Booz Allen Hamilton at Black Hat USA, discussing AI Speed Cyber Defense. If you enjoyed this conversation, be sure to check out the full interview here.

Selected Reading

More than half of AI-generated patches are broken (CyberScoop)

China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns (The Record)

Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data (SecurityWeek)

LexisNexis shuts down services after suspicious activity on servers (BleepingComputer)

US cyber ambassador nominee Cassady confirmed in Senate (The Record)

Meta Ordered to Pay $567 Million in New Mexico Child Safety Case (New York Times)

New Jersey, Alabama Join States Targeted in Water Cyberattacks (Securityweek)

Business Breakdown (N2K)

‘Watch The Odyssey for free online’: scam targets film fans with fake streaming sites (The Guardian)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

As commercial space activity accelerates, satellite manufacturers are rethinking how spacecraft are designed, built, and secured.

In this week's episode, host Maria Varmazis sits down with Jason Roberson, an Industry Value Expert for Aerospace & Defense at Dassault Systems, to discuss how AI, automation, and digital engineering are transforming the space industry's product lifecycle. From digital twins and AI-assisted design to the future of in-space maintenance, Jason explores how these technologies are accelerating innovation while reshaping manufacturing. At the same time, the conversation examines the growing cybersecurity challenges that accompany this transformation and why building secure-by-design principles into space systems will be critical.

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: ⁠https://thecyberwire.com/newsletters/signals-and-space⁠

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to ⁠space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: ⁠https://www.surveymonkey.com/r/NJYCN2P ⁠

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. ⁠N2K⁠ is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at ⁠n2k.com⁠.

More description

As commercial space activity accelerates, satellite manufacturers are rethinking how spacecraft are designed, built, and secured.

In this week's episode, host Maria Varmazis sits down with Jason Roberson, an Industry Value Expert for Aerospace & Defense at Dassault Systems, to discuss how AI, automation, and digital engineering are transforming the space industry's product lifecycle. From digital twins and AI-assisted design to the future of in-space maintenance, Jason explores how these technologies are accelerating innovation while reshaping manufacturing. At the same time, the conversation examines the growing cybersecurity challenges that accompany this transformation and why building secure-by-design principles into space systems will be critical.

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: ⁠https://thecyberwire.com/newsletters/signals-and-space⁠

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to ⁠space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: ⁠https://www.surveymonkey.com/r/NJYCN2P ⁠

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. ⁠N2K⁠ is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at ⁠n2k.com⁠.

Extract Knowledge
Listen elsewhere
Published 2026-08-08

A little help from your search engine. [Research Saturday]

19 min Transcript
View

Today we are joined by Brian Hussey, SVP of Howler Cell Threat Services at Cyderes, discussing their work on "Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer." Howler Cell identified an SEO poisoning campaign targeting people searching for Claude Code installation guides, using a fake Anthropic page and a ClickFix lure to trick victims into running a malicious MSHTA command.

The attack uses a six-stage, largely fileless chain that employs an MP3/HTA polyglot, PowerShell obfuscation, AMSI bypasses, per-victim infrastructure, and in-memory execution to evade detection. The final payload is a .NET infostealer that steals credentials, while Anthropic and the legitimate Claude Code installation process were not compromised.

The research and executive brief can be found here:

More description

Today we are joined by Brian Hussey, SVP of Howler Cell Threat Services at Cyderes, discussing their work on "Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer." Howler Cell identified an SEO poisoning campaign targeting people searching for Claude Code installation guides, using a fake Anthropic page and a ClickFix lure to trick victims into running a malicious MSHTA command.

The attack uses a six-stage, largely fileless chain that employs an MP3/HTA polyglot, PowerShell obfuscation, AMSI bypasses, per-victim infrastructure, and in-memory execution to evade detection. The final payload is a .NET infostealer that steals credentials, while Anthropic and the legitimate Claude Code installation process were not compromised.

The research and executive brief can be found here:

Published 2026-08-07

Ring around the ransom.

24 min Transcript
View

Vishing attacks target hedge funds. Metabase Cloud breached by zero-day flaw. Cyberattack disrupts North Carolina Ports operations. The Chinese government has launched a security review of Palo Alto Networks products. US defense supplier breached by phishing attack. Healthcare software provider breach affected 3.8 million people. New macOS malware spreads via ClickFix attacks. Microsoft and Apple issue new security updates. Cryptography expert says new AI cryptanalysis results show promise, but not an AES breakthrough. James Turgal, Optiv Security’s vice president, cyber risk, strategy and board relations, is discussing how Iranian operators and their proxies appear to pursue disruption. And a Kentucky Fried Chicken order doxxes Chinese spyware operator.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined  by James Turgal, Optiv Security’s vice president, cyber risk, strategy and board relations, discussing how Iranian operators and their proxies appear to pursue disruption by exploiting poorly secured operational technology in sectors such as water, energy, healthcare, and transportation.

Selected Reading

Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group (BleepingComputer)

Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments (GTIG)

Cyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigate (The Record)

China launches cybersecurity review into Palo Alto Networks products (Reuters)

Attacker phished way into US defense supplier's Microsoft 365 account (The Register)

Unlimited Technology Systems Data Breach Affects 3.8 Million Patients (HIPAA Journal)

Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam (Huntress)

China-linked LightSpy spyware caught targeting victims in 13 countries, including the US (TechCrunch)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Vishing attacks target hedge funds. Metabase Cloud breached by zero-day flaw. Cyberattack disrupts North Carolina Ports operations. The Chinese government has launched a security review of Palo Alto Networks products. US defense supplier breached by phishing attack. Healthcare software provider breach affected 3.8 million people. New macOS malware spreads via ClickFix attacks. Microsoft and Apple issue new security updates. Cryptography expert says new AI cryptanalysis results show promise, but not an AES breakthrough. James Turgal, Optiv Security’s vice president, cyber risk, strategy and board relations, is discussing how Iranian operators and their proxies appear to pursue disruption. And a Kentucky Fried Chicken order doxxes Chinese spyware operator.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined  by James Turgal, Optiv Security’s vice president, cyber risk, strategy and board relations, discussing how Iranian operators and their proxies appear to pursue disruption by exploiting poorly secured operational technology in sectors such as water, energy, healthcare, and transportation.

Selected Reading

Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group (BleepingComputer)

Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments (GTIG)

Cyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigate (The Record)

China launches cybersecurity review into Palo Alto Networks products (Reuters)

Attacker phished way into US defense supplier's Microsoft 365 account (The Register)

Unlimited Technology Systems Data Breach Affects 3.8 Million Patients (HIPAA Journal)

Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam (Huntress)

China-linked LightSpy spyware caught targeting victims in 13 countries, including the US (TechCrunch)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-08-06

AI without adult supervision.

25 min Transcript
View

Meta’s AI models join the sandbox escape club. China’s telecom footprint in the U.S. may be larger than expected. The White House keeps its AI safety playbook under wraps. AI coding tools introduce new GitHub risks. ENISA expands its CVE role. A critical Paperclip flaw enables code execution. Crypto wallet fears fuel phishing attacks. Researchers uncover a backdoor in Chinese-made routers. The Snowflake hacker pleads guilty. Our guest is Dustin Childs, Head of Threat Awareness of TrendAI’s Zero Day Initiative, discussing the new Patch Tuesday era. AI takes your word for it. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Dustin Childs, Head of Threat Awareness of TrendAI’s Zero Day Initiative, discussing the new Patch Tuesday era. Be sure to check Dustin out on the AI Security Briefing podcast.

Selected Reading

Meta AI Hacked External Systems During Cybersecurity Testing (SecurityWeek)

Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says (The Record)

Secret White House AI Safety Framework Draws Criticism (BankInfo Security)

Few Federal Agencies Trust Their Own AI Agent Security (BankInfo Security)

Black Hat USA 2026: One GitHub Issue Could Compromise Major AI Coding Workflows (Hackread)

ENISA scales up its role in the CVE Program (enisa)

Critical Paperclip Flaw Allowed Admin Access, Code Execution (SecurityWeek)

COLDCARD security audit phishing attack installs remote access tool (Bleeping Computer)

Chinese-made Zbtlink routers have backdoor, researchers say (Reuters)

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions (US Department of Justice)

“I’m Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails (Hackread)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Meta’s AI models join the sandbox escape club. China’s telecom footprint in the U.S. may be larger than expected. The White House keeps its AI safety playbook under wraps. AI coding tools introduce new GitHub risks. ENISA expands its CVE role. A critical Paperclip flaw enables code execution. Crypto wallet fears fuel phishing attacks. Researchers uncover a backdoor in Chinese-made routers. The Snowflake hacker pleads guilty. Our guest is Dustin Childs, Head of Threat Awareness of TrendAI’s Zero Day Initiative, discussing the new Patch Tuesday era. AI takes your word for it. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Dustin Childs, Head of Threat Awareness of TrendAI’s Zero Day Initiative, discussing the new Patch Tuesday era. Be sure to check Dustin out on the AI Security Briefing podcast.

Selected Reading

Meta AI Hacked External Systems During Cybersecurity Testing (SecurityWeek)

Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says (The Record)

Secret White House AI Safety Framework Draws Criticism (BankInfo Security)

Few Federal Agencies Trust Their Own AI Agent Security (BankInfo Security)

Black Hat USA 2026: One GitHub Issue Could Compromise Major AI Coding Workflows (Hackread)

ENISA scales up its role in the CVE Program (enisa)

Critical Paperclip Flaw Allowed Admin Access, Code Execution (SecurityWeek)

COLDCARD security audit phishing attack installs remote access tool (Bleeping Computer)

Chinese-made Zbtlink routers have backdoor, researchers say (Reuters)

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions (US Department of Justice)

“I’m Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails (Hackread)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-08-05

SAFE and sound.

35 min Transcript
View

The White House lays out its AI strategy at Black Hat. Researchers spotlight rogue AI behavior. CISA warns of an actively exploited N-able flaw. TP-Link patches 15 Omada vulnerabilities. Apple fights the UK’s iCloud access order. The AI gray market expands. A Massachusetts healthcare breach hits more than 300,000 people. Lawmakers push to extend protections for OPM breach victims. Our guest is  Cal Al-Dhubaib, Principal Technologist at Rubrik, who wonders if your security team is solving the wrong problem. With elections, don’t trust AI to tell you the whole story.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On today’s Industry Voices segment, we are joined by Cal Al-Dhubaib, Principal Technologist at Rubrik, talking about how your security team is solving the wrong problem. If you enjoyed the conversation, check out the full interview here. You can also find more information below:

  • Rubrik Agent Cloud landing page

  • Rubrik AI landing page

  • News: Rubrik Launches Rubrik Agent Cloud for Anthropic's Claude Code

    Selected Reading

    National cyber director lays out White House plans to secure AI without writing new rules (CyberScoop)

    Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data (SecurityWeek)

    AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project (The Register)

    MSPs urged to patch immediately after N-able issues hotfix for N-central ‘god mode’ flaw (IT Pro)

    TP-Link patches Omada ZTP flaws allowing hackers to breach networks (BleepingComputer)

    Apple launches new legal challenge against UK over iCloud access (The Record)

    Free tokens for sale: How fake signups drive AI fraud (Threat Intelligence)

    311,000 Impacted by Brown Health Medical Group-MA Data Breach (SecurityWeek)

    Lawmakers spring to save ID theft services for OPM breach victims, with expiration looming (CyberScoop)

    AI is getting better at election facts, but voters shouldn’t rely on it (CyberScoop)

    Share your feedback.

    What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

    Want to hear your company in the show?

    N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

    The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  • More description

    The White House lays out its AI strategy at Black Hat. Researchers spotlight rogue AI behavior. CISA warns of an actively exploited N-able flaw. TP-Link patches 15 Omada vulnerabilities. Apple fights the UK’s iCloud access order. The AI gray market expands. A Massachusetts healthcare breach hits more than 300,000 people. Lawmakers push to extend protections for OPM breach victims. Our guest is  Cal Al-Dhubaib, Principal Technologist at Rubrik, who wonders if your security team is solving the wrong problem. With elections, don’t trust AI to tell you the whole story.

    Remember to leave us a 5-star rating and review in your favorite podcast app.

    Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

    CyberWire Guest

    On today’s Industry Voices segment, we are joined by Cal Al-Dhubaib, Principal Technologist at Rubrik, talking about how your security team is solving the wrong problem. If you enjoyed the conversation, check out the full interview here. You can also find more information below:

  • Rubrik Agent Cloud landing page

  • Rubrik AI landing page

  • News: Rubrik Launches Rubrik Agent Cloud for Anthropic's Claude Code

    Selected Reading

    National cyber director lays out White House plans to secure AI without writing new rules (CyberScoop)

    Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data (SecurityWeek)

    AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project (The Register)

    MSPs urged to patch immediately after N-able issues hotfix for N-central ‘god mode’ flaw (IT Pro)

    TP-Link patches Omada ZTP flaws allowing hackers to breach networks (BleepingComputer)

    Apple launches new legal challenge against UK over iCloud access (The Record)

    Free tokens for sale: How fake signups drive AI fraud (Threat Intelligence)

    311,000 Impacted by Brown Health Medical Group-MA Data Breach (SecurityWeek)

    Lawmakers spring to save ID theft services for OPM breach victims, with expiration looming (CyberScoop)

    AI is getting better at election facts, but voters shouldn’t rely on it (CyberScoop)

    Share your feedback.

    What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

    Want to hear your company in the show?

    N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

    The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  • Published 2026-08-04

    NPM? Not my problem.

    29 min Transcript
    View

    New Shai-Hulud campaign compromises popular npm packages. Easterly says small municipalities shouldn’t have to fend for themselves. Chinese threat groups accelerate exploits. Samsung bans smart TV apps with residential proxies. Hackers breach a Liechtenstein banking database. Swiss government IT agency hit in suspected SharePoint Attack. Microsoft’s bug bounty program awards record payouts. Researchers expose privilege boundary flaw in AI-driven CI/CD workflows. Roberta Anderson, Air Force veteran and CISO at Onterris is sharing her "Breaking the Firewall" book. And, bug hunting turns into bug sorting. 

    Remember to leave us a 5-star rating and review in your favorite podcast app.

    Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

    CyberWire Guest

    Today we are joined by Roberta Anderson, Air Force veteran and CISO at Onterris, sharing her "Breaking the Firewall" book.

    Selected Reading

    Keyv and friends compromised in npm supply chain attack (Aikido)

    Small Towns Shouldn’t Have to Defend America’s Water Supply From Iran (The New York Times)

    China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day (Infosecurity Magazine)

    Samsung bans smart TV apps that share users' internet connections with strangers (TechCrunch)

    Liechtenstein says hackers access information on 31,000 legal entities (Reuters)

    Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected (The Record) 

    Microsoft Bounty Program year in review More than $20 million awarded in our biggest year yet (Microsoft Security Response Center)

    I'll Just Call You: Agent-to-Agent Privilege Boundary Failures in CI/CD on Google's ADK Repository (Pillar Security) 

    Apple struggles to keep pace with AI ‘bug’ hunters (Financial Times)

    Share your feedback.

    What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

    Want to hear your company in the show?

    N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

    The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

    More description

    New Shai-Hulud campaign compromises popular npm packages. Easterly says small municipalities shouldn’t have to fend for themselves. Chinese threat groups accelerate exploits. Samsung bans smart TV apps with residential proxies. Hackers breach a Liechtenstein banking database. Swiss government IT agency hit in suspected SharePoint Attack. Microsoft’s bug bounty program awards record payouts. Researchers expose privilege boundary flaw in AI-driven CI/CD workflows. Roberta Anderson, Air Force veteran and CISO at Onterris is sharing her "Breaking the Firewall" book. And, bug hunting turns into bug sorting. 

    Remember to leave us a 5-star rating and review in your favorite podcast app.

    Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

    CyberWire Guest

    Today we are joined by Roberta Anderson, Air Force veteran and CISO at Onterris, sharing her "Breaking the Firewall" book.

    Selected Reading

    Keyv and friends compromised in npm supply chain attack (Aikido)

    Small Towns Shouldn’t Have to Defend America’s Water Supply From Iran (The New York Times)

    China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day (Infosecurity Magazine)

    Samsung bans smart TV apps that share users' internet connections with strangers (TechCrunch)

    Liechtenstein says hackers access information on 31,000 legal entities (Reuters)

    Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected (The Record) 

    Microsoft Bounty Program year in review More than $20 million awarded in our biggest year yet (Microsoft Security Response Center)

    I'll Just Call You: Agent-to-Agent Privilege Boundary Failures in CI/CD on Google's ADK Repository (Pillar Security) 

    Apple struggles to keep pace with AI ‘bug’ hunters (Financial Times)

    Share your feedback.

    What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

    Want to hear your company in the show?

    N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

    The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

    Published 2026-08-03

    Water you waiting for?

    26 min Transcript
    View

    Cyberattacks hit U.S. water systems. CISA tackles open source security. China’s surveillance machine is exposed. Hotel Wi-Fi gets riskier. Healthcare and police data spill online. Fake SQLite vulnerabilities fool security databases. Monday business briefing. Our guest is Tim Starks from CyberScoop discussing the White House's quantum aspirations. AI is the hottest thing on campus.

    Remember to leave us a 5-star rating and review in your favorite podcast app.

    Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

    CyberWire Guest

    Today we are joined by Tim Starks, Senior Reporter from CyberScoop, discussing the White House's quantum aspirations.

    Selected Reading

    Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran (The New York Times)

    CISA lays out new guidance for using open-source software (Help Net Security)

    How China Keeps Tabs on Foreigners (The New York Times)

    Microsoft Issues Hotel Wi-Fi Warning For Windows PC Users (Forbes)

    Exclusive: Partnered Health responds to Inc Ransom data breach claims (Cyber Daily)

    Security Flaw Placed 30 Years of DNA Evidence at Risk of Hacking (Wall Street Journal)

    SQLite Critical CVEs or LLM Slop? (JFrog Security Research)

    Details of 100,000 police staff leaked on the dark web after hack (The Times)

    ThreatLocker secures $190 million in a Series F round led by Elephant (N2K Pro Business Briefing)

    At colleges, the AI boom means everyone wants to dabble in computer science (AP News)

    Share your feedback.

    What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

    Want to hear your company in the show?

    N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

    The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

    More description

    Cyberattacks hit U.S. water systems. CISA tackles open source security. China’s surveillance machine is exposed. Hotel Wi-Fi gets riskier. Healthcare and police data spill online. Fake SQLite vulnerabilities fool security databases. Monday business briefing. Our guest is Tim Starks from CyberScoop discussing the White House's quantum aspirations. AI is the hottest thing on campus.

    Remember to leave us a 5-star rating and review in your favorite podcast app.

    Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

    CyberWire Guest

    Today we are joined by Tim Starks, Senior Reporter from CyberScoop, discussing the White House's quantum aspirations.

    Selected Reading

    Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran (The New York Times)

    CISA lays out new guidance for using open-source software (Help Net Security)

    How China Keeps Tabs on Foreigners (The New York Times)

    Microsoft Issues Hotel Wi-Fi Warning For Windows PC Users (Forbes)

    Exclusive: Partnered Health responds to Inc Ransom data breach claims (Cyber Daily)

    Security Flaw Placed 30 Years of DNA Evidence at Risk of Hacking (Wall Street Journal)

    SQLite Critical CVEs or LLM Slop? (JFrog Security Research)

    Details of 100,000 police staff leaked on the dark web after hack (The Times)

    ThreatLocker secures $190 million in a Series F round led by Elephant (N2K Pro Business Briefing)

    At colleges, the AI boom means everyone wants to dabble in computer science (AP News)

    Share your feedback.

    What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

    Want to hear your company in the show?

    N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

    The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

    In this special edition, guest Yan Shoshitaishvili, Associate Professor, University of Arizona, joins host ⁠Dave Bittner⁠ to share a preview of his Black Hat USA 2026 keynote "Vulnerability Research in the Agentic Age."

    Join Yan and Dave to hear insights on the evolution of vulnerability research, the impact of AI and LLMs on cybersecurity, and the future of human expertise in the field.

    If you are heading to Black Hat, check out Yan's session on Thursday, August 6 at 9:15 AM.

    More description

    In this special edition, guest Yan Shoshitaishvili, Associate Professor, University of Arizona, joins host ⁠Dave Bittner⁠ to share a preview of his Black Hat USA 2026 keynote "Vulnerability Research in the Agentic Age."

    Join Yan and Dave to hear insights on the evolution of vulnerability research, the impact of AI and LLMs on cybersecurity, and the future of human expertise in the field.

    If you are heading to Black Hat, check out Yan's session on Thursday, August 6 at 9:15 AM.

    As the space ecosystem continues to expand, the sector has become increasingly filled with new suppliers, manufacturers, and operators. However, while this development has led to the introduction of new technologies, it has also greatly expanded space's cyberattack surface.

    In this week's episode, host Maria Varmazis sits down with Jen Sovada, General Manager of Public Sector at Claroty. During the conversation, the two explore how vulnerabilities within the space supply chain can impact mission assurance. They discuss how the expanding space supply chain ecosystem has expanded the attack surface.

    Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space

    Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P

    T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.

    More description

    As the space ecosystem continues to expand, the sector has become increasingly filled with new suppliers, manufacturers, and operators. However, while this development has led to the introduction of new technologies, it has also greatly expanded space's cyberattack surface.

    In this week's episode, host Maria Varmazis sits down with Jen Sovada, General Manager of Public Sector at Claroty. During the conversation, the two explore how vulnerabilities within the space supply chain can impact mission assurance. They discuss how the expanding space supply chain ecosystem has expanded the attack surface.

    Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space

    Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P

    T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.

    Extract Knowledge
    Listen elsewhere
    Published 2026-08-01

    The driver's seat to ransomware. [Research Saturday]

    23 min Transcript
    View

    This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs." Researchers examine how the Gentlemen ransomware group used a previously unknown zero-day vulnerability in a legacy Windows driver to disable endpoint detection and response (EDR) tools before deploying ransomware. The report details the group's advanced bring-your-own-vulnerable-driver (BYOVD) techniques, which bypass multiple Windows security protections to gain kernel-level access and terminate protected security software. It also outlines defensive measures organizations can take, including enabling Windows Defender Application Control (WDAC), virtualization-based security (VBS), and vulnerable driver blocklists to reduce the risk of similar attacks.

    The research and executive brief can be found here:

    More description

    This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs." Researchers examine how the Gentlemen ransomware group used a previously unknown zero-day vulnerability in a legacy Windows driver to disable endpoint detection and response (EDR) tools before deploying ransomware. The report details the group's advanced bring-your-own-vulnerable-driver (BYOVD) techniques, which bypass multiple Windows security protections to gain kernel-level access and terminate protected security software. It also outlines defensive measures organizations can take, including enabling Windows Defender Application Control (WDAC), virtualization-based security (VBS), and vulnerable driver blocklists to reduce the risk of similar attacks.

    The research and executive brief can be found here:

    Published 2026-07-31

    Claude outside the lines.

    30 min Transcript
    View

    Anthropic says Claude escaped the sandbox three times, while a judge questions the Pentagon’s blacklist. The EU launches an AI enforcement team, the FTC targets a telehealth firm’s tracking pixels, and a WordPress backdoor is stopped just in time. CareCloud discloses a major data breach, a stealthy cryptominer hides in plain sight, AiTM phishing surges against law firms, and Finland severs one more digital link to Russia. Our guest is Yan Shoshitaishvili, Associate Professor, Arizona State University, previewing his Black Hat 2026 keynote "Vulnerability Research in the Agentic Age." AI scammers may deserve a promotion.

    Remember to leave us a 5-star rating and review in your favorite podcast app.

    Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

    CyberWire Guest

    Today we are joined by Yan Shoshitaishvili, Associate Professor, Arizona State University, discussing his Black Hat 2026 keynote "Vulnerability Research in the Agentic Age." Be sure to tune in this Sunday for a special edition featuring our full, extended interview with Yan.

    Selected Reading

    Anthropic AI Models Hacked Three Organizations During Tests (Bloomberg)

    Anthropic, Pentagon Clash Over First Amendment Claims (GovInfo Security)

    EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels (SecurityWeek)

    FTC sues Hims & Hers for allegedly sharing patients' medical data with advertisers Meta and Snap (TechCrunch)

    Wordfence Finds Critical Backdoor in ARVE WordPress Plugin (Hackread)

    CareCloud Data Breach Impacts Over 350,000 (SecurityWeek)

    Cryptominer Abuses Linux PAM to Hide From SOC Analysts (Infosecurity Magazine)

    AiTM Phishing Becomes Top Initial Access Threat to Law Firms (Infosecurity Magazine)

    Finland to disconnect fiber-optic link to Russia as lease expires (The Record)

    AI Scammers Are Better at Building Trust Than Humans (WIRED)

    Share your feedback.

    What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

    Want to hear your company in the show?

    N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

    The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

    More description

    Anthropic says Claude escaped the sandbox three times, while a judge questions the Pentagon’s blacklist. The EU launches an AI enforcement team, the FTC targets a telehealth firm’s tracking pixels, and a WordPress backdoor is stopped just in time. CareCloud discloses a major data breach, a stealthy cryptominer hides in plain sight, AiTM phishing surges against law firms, and Finland severs one more digital link to Russia. Our guest is Yan Shoshitaishvili, Associate Professor, Arizona State University, previewing his Black Hat 2026 keynote "Vulnerability Research in the Agentic Age." AI scammers may deserve a promotion.

    Remember to leave us a 5-star rating and review in your favorite podcast app.

    Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

    CyberWire Guest

    Today we are joined by Yan Shoshitaishvili, Associate Professor, Arizona State University, discussing his Black Hat 2026 keynote "Vulnerability Research in the Agentic Age." Be sure to tune in this Sunday for a special edition featuring our full, extended interview with Yan.

    Selected Reading

    Anthropic AI Models Hacked Three Organizations During Tests (Bloomberg)

    Anthropic, Pentagon Clash Over First Amendment Claims (GovInfo Security)

    EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels (SecurityWeek)

    FTC sues Hims & Hers for allegedly sharing patients' medical data with advertisers Meta and Snap (TechCrunch)

    Wordfence Finds Critical Backdoor in ARVE WordPress Plugin (Hackread)

    CareCloud Data Breach Impacts Over 350,000 (SecurityWeek)

    Cryptominer Abuses Linux PAM to Hide From SOC Analysts (Infosecurity Magazine)

    AiTM Phishing Becomes Top Initial Access Threat to Law Firms (Infosecurity Magazine)

    Finland to disconnect fiber-optic link to Russia as lease expires (The Record)

    AI Scammers Are Better at Building Trust Than Humans (WIRED)

    Share your feedback.

    What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

    Want to hear your company in the show?

    N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

    The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

    Published 2026-07-30

    Building a great firewall around AI.

    25 min Transcript
    View

    China embraces open AI models, then worries it’s become a national security risk. The cyberattack on Minnesota water systems proves larger than first reported. CISA updates its SBOM guidance. AI supercharges dangling DNS attacks. Researchers uncover a self-propagating Copilot worm. A critical Rails flaw demands urgent patching. Mac users are lured into installing malware through fake Claude guides. Amazon links a string of NPM compromises to North Korea. And Russia charges Telegram founder Pavel Durov with aiding terrorism. Ben Yelin joins us with a border search case that’s breaking new ground. Don’t bite the North Korean hand that feeds you.

    Remember to leave us a 5-star rating and review in your favorite podcast app.

    Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

    CyberWire Guest

    Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies talking about a border search case that’s breaking new ground. If you enjoyed this conversation, check out Ben on the Caveat podcast here. 

    Selected Reading

    As China’s A.I. Gets Stronger, It Poses New Risks to Beijing (New York Times)

    Minnesota Water Utilities Suffer ‘Coordinated Cyber Attack’ (GovTech)

    CISA Updates Software Bill of Materials Guidance to Strengthen Supply Chain Security (HSToday)

    ‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale (SecurityWeek)

    Word worm crawls into Copilot, spreads chaos (The Register)

    Possible arbitrary file read and remote code execution in Active Storage variant processing (GitHub)

    Fake Claude Install Guide Leads to MacSync Stealer and RAT: What We Pulled From the Attacker's Servers (Huntress)

    Amazon identifies North Korean hacker group behind open-source supply chain attacks (AWS Security Blog)

    Russia accuses Telegram CEO Pavel Durov of aiding terrorism in its latest digital crackdown (AP News)

    North Korea's elite hackers turned on their own government — and got caught (Bitdefender)

    Share your feedback.

    What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

    Want to hear your company in the show?

    N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

    The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

    More description

    China embraces open AI models, then worries it’s become a national security risk. The cyberattack on Minnesota water systems proves larger than first reported. CISA updates its SBOM guidance. AI supercharges dangling DNS attacks. Researchers uncover a self-propagating Copilot worm. A critical Rails flaw demands urgent patching. Mac users are lured into installing malware through fake Claude guides. Amazon links a string of NPM compromises to North Korea. And Russia charges Telegram founder Pavel Durov with aiding terrorism. Ben Yelin joins us with a border search case that’s breaking new ground. Don’t bite the North Korean hand that feeds you.

    Remember to leave us a 5-star rating and review in your favorite podcast app.

    Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

    CyberWire Guest

    Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies talking about a border search case that’s breaking new ground. If you enjoyed this conversation, check out Ben on the Caveat podcast here. 

    Selected Reading

    As China’s A.I. Gets Stronger, It Poses New Risks to Beijing (New York Times)

    Minnesota Water Utilities Suffer ‘Coordinated Cyber Attack’ (GovTech)

    CISA Updates Software Bill of Materials Guidance to Strengthen Supply Chain Security (HSToday)

    ‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale (SecurityWeek)

    Word worm crawls into Copilot, spreads chaos (The Register)

    Possible arbitrary file read and remote code execution in Active Storage variant processing (GitHub)

    Fake Claude Install Guide Leads to MacSync Stealer and RAT: What We Pulled From the Attacker's Servers (Huntress)

    Amazon identifies North Korean hacker group behind open-source supply chain attacks (AWS Security Blog)

    Russia accuses Telegram CEO Pavel Durov of aiding terrorism in its latest digital crackdown (AP News)

    North Korea's elite hackers turned on their own government — and got caught (Bitdefender)

    Share your feedback.

    What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

    Want to hear your company in the show?

    N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

    The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

    Show details
    Episodes
    3784
    Transcripts
    67
    2% coverage
    Missing transcripts
    3717
    With chapters
    0