Search this show’s transcripts

CyberWire Daily

en us
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
More details
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
Sources and links

Episodes

Page 2 · 50 per page
Published 2026-07-29

More than meets the AI.

29 min Transcript
View

The Senate confirms Jay Clayton to lead ODNI. A new CISA framework highlights critical infrastructure isolation capabilities. OpenAI’s rogue agent breached more than just Hugging Face. The average cost of a data breach continues to rise. Indirect prompt injection proves irresistible to cyber criminals. Broadcom patches multiple VMware products. ShinyHunters claims responsibility for Ernst & Young’s recent breach. Our guest is Sean Zadig, CISO at Yahoo, discussing the impact of AI on the defense side. These aren’t the droids you’re looking for.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Sean Zadig, CISO at Yahoo, discussing the impact of AI on the defense side without all the hype in either direction, what is a CISO actually doing about it.

Selected Reading

Senate Confirms Jay Clayton to Lead U.S. Intelligence Community (The New York Times)

China and Iran Are Already Inside US Grids: CISA Demands Tested Isolation Plans (Tech Times)

OpenAI's rogue agent compromised a customer at a second tech firm, executive says (Reuters)

Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident (Hugging Face)

The Average Cost of a Data Breach Rises to $5 Million (Infosecurity Magazine)

USSPACECOM Issues Space Warfighting Environment 2040 for Joint Force Space Operations (ExecutiveGov)

THE SPACE WARFIGHTING ENVIRONMENT 2040 Framing the Future for the Joint Warfighter (U.S. Space Command) 

Notes from Underground: Adversarial Prompt Injection (Proofpoint)

Critical VM Escape Vulnerability Patched in VMware ESXi (SecurityWeek)

ShinyHunters Claims Ernst & Young Hack (SecurityWeek)

America bans imported robots due to supply chain and security risks (The Register)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

The Senate confirms Jay Clayton to lead ODNI. A new CISA framework highlights critical infrastructure isolation capabilities. OpenAI’s rogue agent breached more than just Hugging Face. The average cost of a data breach continues to rise. Indirect prompt injection proves irresistible to cyber criminals. Broadcom patches multiple VMware products. ShinyHunters claims responsibility for Ernst & Young’s recent breach. Our guest is Sean Zadig, CISO at Yahoo, discussing the impact of AI on the defense side. These aren’t the droids you’re looking for.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Sean Zadig, CISO at Yahoo, discussing the impact of AI on the defense side without all the hype in either direction, what is a CISO actually doing about it.

Selected Reading

Senate Confirms Jay Clayton to Lead U.S. Intelligence Community (The New York Times)

China and Iran Are Already Inside US Grids: CISA Demands Tested Isolation Plans (Tech Times)

OpenAI's rogue agent compromised a customer at a second tech firm, executive says (Reuters)

Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident (Hugging Face)

The Average Cost of a Data Breach Rises to $5 Million (Infosecurity Magazine)

USSPACECOM Issues Space Warfighting Environment 2040 for Joint Force Space Operations (ExecutiveGov)

THE SPACE WARFIGHTING ENVIRONMENT 2040 Framing the Future for the Joint Warfighter (U.S. Space Command) 

Notes from Underground: Adversarial Prompt Injection (Proofpoint)

Critical VM Escape Vulnerability Patched in VMware ESXi (SecurityWeek)

ShinyHunters Claims Ernst & Young Hack (SecurityWeek)

America bans imported robots due to supply chain and security risks (The Register)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-07-28

You've been disconnected.

26 min Transcript
View

A senator targets legacy VPNs. Minnesota water systems come under cyberattack. A 20-year-old flaw exposes 24,000 servers. Microsoft debuts its first cybersecurity AI model. A critical VeloCloud bug is under active attack. The Dysphoria botnet tops 200,000 devices. Apple faces a lawsuit over a fake crypto wallet. Denmark builds a cyber-resilient banking backup. Google gives threat actors yet another set of names. Our guest is John Chiappetta, Chief Revenue Officer of Xona Systems, discussing the Aviation Cybersecurity GAO report that highlights gaps in FAA network security. Hacking the admissions system in search of a fair chance. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by John Chiappetta, Chief Revenue Officer of Xona Systems, discussing the Aviation Cybersecurity GAO report that highlights gaps in FAA network security.

Selected Reading

Wyden Demands Two-Year Federal VPN Purge: Zero-Trust Procurement Rule Would Reshape Vendor Market (Tech Times)

Several MN water facilities targeted by cyber attacks (FOX 9 Minneapolis-St. Paul)

Over 24,000 exposed server BMCs leak password hash via decades-old flaw (Bleeping Computer)

Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model (SecurityWeek)

Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock (The Register)

New Dysphoria DDoS botnet spreads to 200k devices worldwide (Bleeping Computer)

Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin (Bleeping Computer)

Denmark Readies Emergency Reserve Bank to Fight Cyberattacks (Global Finance Magazine)

Google Adopts New Threat Actor Naming System (SecurityWeek)

Rejected Cybersecurity Applicant Allegedly Hacks IIT Madras Portal: "All I Need Is A Fair Chance" (NDTV)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

A senator targets legacy VPNs. Minnesota water systems come under cyberattack. A 20-year-old flaw exposes 24,000 servers. Microsoft debuts its first cybersecurity AI model. A critical VeloCloud bug is under active attack. The Dysphoria botnet tops 200,000 devices. Apple faces a lawsuit over a fake crypto wallet. Denmark builds a cyber-resilient banking backup. Google gives threat actors yet another set of names. Our guest is John Chiappetta, Chief Revenue Officer of Xona Systems, discussing the Aviation Cybersecurity GAO report that highlights gaps in FAA network security. Hacking the admissions system in search of a fair chance. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by John Chiappetta, Chief Revenue Officer of Xona Systems, discussing the Aviation Cybersecurity GAO report that highlights gaps in FAA network security.

Selected Reading

Wyden Demands Two-Year Federal VPN Purge: Zero-Trust Procurement Rule Would Reshape Vendor Market (Tech Times)

Several MN water facilities targeted by cyber attacks (FOX 9 Minneapolis-St. Paul)

Over 24,000 exposed server BMCs leak password hash via decades-old flaw (Bleeping Computer)

Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model (SecurityWeek)

Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock (The Register)

New Dysphoria DDoS botnet spreads to 200k devices worldwide (Bleeping Computer)

Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin (Bleeping Computer)

Denmark Readies Emergency Reserve Bank to Fight Cyberattacks (Global Finance Magazine)

Google Adopts New Threat Actor Naming System (SecurityWeek)

Rejected Cybersecurity Applicant Allegedly Hacks IIT Madras Portal: "All I Need Is A Fair Chance" (NDTV)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-07-27

The world's least private hackers.

27 min Transcript
View

Hackers target Thailand’s Ministry of Finance with an autonomous AI agent.A new industry alliance hopes to improve AI security. Golden Chickens lay four new malware families. GitHub and PyPI introduce time-based safeguards. SourTrade malvertising builds malware directly inside a victim’s browser. Attackers target credentials of traveling corporate employees. EDR shutdown is now par for the course for leading ransomware groups. Russian threat actors exploited a Zimbra vulnerability for at least five months before it was patched. Monday business briefing. Our guest is Krishna Sai, CTO at SolarWinds, with security lessons learned from the World Cup. When the feed ends, the fun begins. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Krishna Sai, CTO at SolarWinds, discussing the security risks around the World Cup and how this affects IT teams as they try to manage the growing digital traffic sprawl surrounding the event.

Selected Reading

Hackers used autonomous AI agent to spy on Thailand's finance ministry (The Record)

Nvidia and Tech Giants Launch AI Security Alliance (SecurityWeek)

Golden Chickens malware-as-a-service resurfaces with four new families (SC Media)

GitHub, PyPI add time-based defenses against supply chain attacks (Bleeping Computer)

SourTrade Malvertising Campaign Secretly Builds Malware in the Browser (Infosecurity Magazine)

Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials (SecurityWeek)

Ransomware Groups Increasingly Deploy EDR Kill Techniques (Infosecurity Magazine)

TA488 Targets Zimbra Mailservers with Half-Click Exploits IProofpoint)

Endpoint security firm Glow emerges from stealth with $180 million. (N2K Pro Business Briefing)

Being a Luddite Is Fun Again (404 Media)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Hackers target Thailand’s Ministry of Finance with an autonomous AI agent.A new industry alliance hopes to improve AI security. Golden Chickens lay four new malware families. GitHub and PyPI introduce time-based safeguards. SourTrade malvertising builds malware directly inside a victim’s browser. Attackers target credentials of traveling corporate employees. EDR shutdown is now par for the course for leading ransomware groups. Russian threat actors exploited a Zimbra vulnerability for at least five months before it was patched. Monday business briefing. Our guest is Krishna Sai, CTO at SolarWinds, with security lessons learned from the World Cup. When the feed ends, the fun begins. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Krishna Sai, CTO at SolarWinds, discussing the security risks around the World Cup and how this affects IT teams as they try to manage the growing digital traffic sprawl surrounding the event.

Selected Reading

Hackers used autonomous AI agent to spy on Thailand's finance ministry (The Record)

Nvidia and Tech Giants Launch AI Security Alliance (SecurityWeek)

Golden Chickens malware-as-a-service resurfaces with four new families (SC Media)

GitHub, PyPI add time-based defenses against supply chain attacks (Bleeping Computer)

SourTrade Malvertising Campaign Secretly Builds Malware in the Browser (Infosecurity Magazine)

Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials (SecurityWeek)

Ransomware Groups Increasingly Deploy EDR Kill Techniques (Infosecurity Magazine)

TA488 Targets Zimbra Mailservers with Half-Click Exploits IProofpoint)

Endpoint security firm Glow emerges from stealth with $180 million. (N2K Pro Business Briefing)

Being a Luddite Is Fun Again (404 Media)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

As space becomes an increasingly important part of global communications, national security, and critical infrastructure, European governments are confronting a difficulty: How much control do they need over their own space capabilities?

In this week’s episode, host Maria Varmazis sits down with producer Ethan Cook⁠⁠⁠ to examine the growing push for European space sovereignty and the challenges standing in the way. The conversation explores how supply-chain dependencies can undermine national and regional independence, even when satellites and launch systems are built domestically. Additionally, the two also discuss the trade-offs between complete self-sufficiency and maintaining resilient, diversified international partnerships.

Key sources:

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.

More description

As space becomes an increasingly important part of global communications, national security, and critical infrastructure, European governments are confronting a difficulty: How much control do they need over their own space capabilities?

In this week’s episode, host Maria Varmazis sits down with producer Ethan Cook⁠⁠⁠ to examine the growing push for European space sovereignty and the challenges standing in the way. The conversation explores how supply-chain dependencies can undermine national and regional independence, even when satellites and launch systems are built domestically. Additionally, the two also discuss the trade-offs between complete self-sufficiency and maintaining resilient, diversified international partnerships.

Key sources:

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.

Extract Knowledge
Listen elsewhere
Published 2026-07-25

Cold lures, hot targets. [Research Saturday]

17 min Transcript
View

This week, we are joined by Ondrej Kubovič, Security Awareness Specialist from ESET, discussing their work on "FrostyNeighbor: Fresh mischief and digital shenanigans." Ondrej walks us through ESET's latest research into FrostyNeighbor, a long-running Belarus-aligned cyberespionage group that has continued to target Ukrainian government organizations with increasingly sophisticated spearphishing campaigns.

We discuss how the group uses malicious PDF lures, server-side victim validation, and an updated JavaScript-based malware chain to selectively deploy espionage tools, demonstrating its ongoing efforts to evade detection while compromising high-value targets across Eastern Europe.

The research and executive brief can be found here:

More description

This week, we are joined by Ondrej Kubovič, Security Awareness Specialist from ESET, discussing their work on "FrostyNeighbor: Fresh mischief and digital shenanigans." Ondrej walks us through ESET's latest research into FrostyNeighbor, a long-running Belarus-aligned cyberespionage group that has continued to target Ukrainian government organizations with increasingly sophisticated spearphishing campaigns.

We discuss how the group uses malicious PDF lures, server-side victim validation, and an updated JavaScript-based malware chain to selectively deploy espionage tools, demonstrating its ongoing efforts to evade detection while compromising high-value targets across Eastern Europe.

The research and executive brief can be found here:

Published 2026-07-24

Laundry Bear gets the spin cycle.

26 min Transcript
View

Laundry Bear snuffles through unpatched Zimbra Collaboration servers. The State Department puts visa restrictions on cybercriminals. Oracle drops a record 1,449 security patches. Researchers disclose a critical vulnerability in OpenAI’s ChatGPT Workspace Agents. A new benchmark evaluates frontier AI model malware reverse engineering. LunchPoke uses the Notepad++ application to establish persistence. A Swiss rail manufacturer refuses to pay the ransom. Dave Bittner sits down with Maria Varmazis, host of T-Minus Space Cyber Briefing, to discuss the show's evolution into CyberWire's weekly space cyber briefing. The AI goes to space. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Dave Bittner sits down with Maria Varmazis, host of T-Minus Space Cyber Briefing, to discuss the show's evolution into CyberWire's weekly space cyber briefing. Maria shares why space cybersecurity deserves more attention, how the new format allows for deeper conversations on topics like GPS security and European space sovereignty, and why every cybersecurity professional should be paying attention to the growing role of space in cyber. You can hear part one here.

Selected Reading

Russian hackers exploit Zimbra zero-click flaw for email theft (Bleeping Computer)

State Department imposes visa restrictions on foreign cyber scammers (The Record)

Oracle drops 1,449 security patches like it's the new normal (The Register)

OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider (SecurityWeek)

Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models (SecurityWeek)

Hackers abuse Notepad++ plugins to stealthily install malware (Bleeping Computer)

Swiss train maker Stadler refuses Everest $12 million ransomware demand (The Record)

If you pay a hacker's ransom, chances are that they'll come back for more (TechCrunch)

NASA Puts Google’s Gemma Large Language Model in Orbit (IEEE Spectrum)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Laundry Bear snuffles through unpatched Zimbra Collaboration servers. The State Department puts visa restrictions on cybercriminals. Oracle drops a record 1,449 security patches. Researchers disclose a critical vulnerability in OpenAI’s ChatGPT Workspace Agents. A new benchmark evaluates frontier AI model malware reverse engineering. LunchPoke uses the Notepad++ application to establish persistence. A Swiss rail manufacturer refuses to pay the ransom. Dave Bittner sits down with Maria Varmazis, host of T-Minus Space Cyber Briefing, to discuss the show's evolution into CyberWire's weekly space cyber briefing. The AI goes to space. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Dave Bittner sits down with Maria Varmazis, host of T-Minus Space Cyber Briefing, to discuss the show's evolution into CyberWire's weekly space cyber briefing. Maria shares why space cybersecurity deserves more attention, how the new format allows for deeper conversations on topics like GPS security and European space sovereignty, and why every cybersecurity professional should be paying attention to the growing role of space in cyber. You can hear part one here.

Selected Reading

Russian hackers exploit Zimbra zero-click flaw for email theft (Bleeping Computer)

State Department imposes visa restrictions on foreign cyber scammers (The Record)

Oracle drops 1,449 security patches like it's the new normal (The Register)

OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider (SecurityWeek)

Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models (SecurityWeek)

Hackers abuse Notepad++ plugins to stealthily install malware (Bleeping Computer)

Swiss train maker Stadler refuses Everest $12 million ransomware demand (The Record)

If you pay a hacker's ransom, chances are that they'll come back for more (TechCrunch)

NASA Puts Google’s Gemma Large Language Model in Orbit (IEEE Spectrum)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-07-23

Do not pass Go(ogle).

26 min Transcript
View

Google gets a billion dollar fine from the EU. The White House considers sanctions against Chinese AI developers. The GAO criticizes overlap in cyber reporting regulations. The Feds warn of Iranian agents targeting OT systems. Researchers disclose a high-severity Linux kernel vulnerability. Dolphin X uses AI profiling to find high-value victims. A new backdoor routes C2 through the browser. Check Point confirms a critical zero-day. A lawsuit accuses ChatGPT of unauthorized medical advice. Ben Yelin explains how political campaigns attempt to influence LLMs. Baseball benches the bots.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies talking about how "Politicians Are Trying to Change What Chatbots Say About Them." If you enjoyed this conversation, be sure to check out Ben on Caveat every week.

Selected Reading

Google Hit With $1 Billion Fine for Abusing Its Power in Europe (New York Times)

US Eyes Sanctions on Chinese AI Firms Over Distillation (GovInfo Security)

Most federal cybersecurity reporting rules are duplicative, study finds (CyberScoop)

Federal agencies broaden alert on Iran-linked OT attacks (The Record)

New RefluXFS Linux flaw lets attackers gain root privileges (Bleeping Computer)

New Dolphin X Stealer Employs AI Profiling to Prioritize Targets (Infosecurity Magazine)

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic (Bleeping Computer)

New Check Point Zero-Day Vulnerability Exploited in the Wild (SecurityWeek)

Lawsuit Claims ChatGPT Dished Out Dangerous Health Advice (GovInfo Security)

MLB bans using dugout iPads for AI-powered in-game strategy calls (Engadget)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Google gets a billion dollar fine from the EU. The White House considers sanctions against Chinese AI developers. The GAO criticizes overlap in cyber reporting regulations. The Feds warn of Iranian agents targeting OT systems. Researchers disclose a high-severity Linux kernel vulnerability. Dolphin X uses AI profiling to find high-value victims. A new backdoor routes C2 through the browser. Check Point confirms a critical zero-day. A lawsuit accuses ChatGPT of unauthorized medical advice. Ben Yelin explains how political campaigns attempt to influence LLMs. Baseball benches the bots.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies talking about how "Politicians Are Trying to Change What Chatbots Say About Them." If you enjoyed this conversation, be sure to check out Ben on Caveat every week.

Selected Reading

Google Hit With $1 Billion Fine for Abusing Its Power in Europe (New York Times)

US Eyes Sanctions on Chinese AI Firms Over Distillation (GovInfo Security)

Most federal cybersecurity reporting rules are duplicative, study finds (CyberScoop)

Federal agencies broaden alert on Iran-linked OT attacks (The Record)

New RefluXFS Linux flaw lets attackers gain root privileges (Bleeping Computer)

New Dolphin X Stealer Employs AI Profiling to Prioritize Targets (Infosecurity Magazine)

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic (Bleeping Computer)

New Check Point Zero-Day Vulnerability Exploited in the Wild (SecurityWeek)

Lawsuit Claims ChatGPT Dished Out Dangerous Health Advice (GovInfo Security)

MLB bans using dugout iPads for AI-powered in-game strategy calls (Engadget)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-07-22

The AI has entered the chat.

29 min Transcript
View

GPT escapes the sandbox and hacks Huggingface. SolarWinds patches multiple critical flaws. CISA orders patching of a critical Langflow AI vulnerability. A Paidwork breach affects over 23 million users. A recently patched SharePoint vulnerability is under active exploitation. Oracle patches over 1,400 vulnerabilities. Apps turn Smart TVs into residential proxies. The FCC considers expanding direct to satellite communications. German and U.S. authorities dismantle a major phishing-as-a-service (PhaaS) platform. Our guest is Jimmy McNary, Deputy Federal CTO at Semperis, discussing comprehensive identity security assessments for Microsoft GCC. AI models can’t resist bending the rules.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On our Industry Voices segment, we are joined by Jimmy McNary, Deputy Federal CTO at Semperis, discussing how Purple Knight now delivers comprehensive identity security assessments for Microsoft GCC high environment.

Selected Reading

OpenAI Claims Its AI Models Went Rogue and Hacked Another Company (Infosecurity Magazine)

SolarWinds Serv-U Update Fixes 15 Critical Vulnerabilities Enabling Remote Code Execution as Root (GB Hackers)

CISA orders urgent action on actively exploited Langflow RCE flaw (Bleeping Computer)

Paidwork breach exposes data of 23 million users: Check if you're affected (Malwarebytes)

Fourth SharePoint Vulnerability Exploited in Past Month's Wave of Attacks (SecurityWeek)

Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates (SecurityWeek)

Chairman Carr Proposes to Expand Direct-to-Device Satellite Broadband Connectivity to Unlicensed Wireless Devices (FCC)

LG to Ban Residential Proxies from Smart TV Apps (Krebs on Security)

Police dismantle Kratos phishing platform, arrest developer (Bleeping Computer)

AI's cheatin' heart will make you weep (The Register)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

GPT escapes the sandbox and hacks Huggingface. SolarWinds patches multiple critical flaws. CISA orders patching of a critical Langflow AI vulnerability. A Paidwork breach affects over 23 million users. A recently patched SharePoint vulnerability is under active exploitation. Oracle patches over 1,400 vulnerabilities. Apps turn Smart TVs into residential proxies. The FCC considers expanding direct to satellite communications. German and U.S. authorities dismantle a major phishing-as-a-service (PhaaS) platform. Our guest is Jimmy McNary, Deputy Federal CTO at Semperis, discussing comprehensive identity security assessments for Microsoft GCC. AI models can’t resist bending the rules.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On our Industry Voices segment, we are joined by Jimmy McNary, Deputy Federal CTO at Semperis, discussing how Purple Knight now delivers comprehensive identity security assessments for Microsoft GCC high environment.

Selected Reading

OpenAI Claims Its AI Models Went Rogue and Hacked Another Company (Infosecurity Magazine)

SolarWinds Serv-U Update Fixes 15 Critical Vulnerabilities Enabling Remote Code Execution as Root (GB Hackers)

CISA orders urgent action on actively exploited Langflow RCE flaw (Bleeping Computer)

Paidwork breach exposes data of 23 million users: Check if you're affected (Malwarebytes)

Fourth SharePoint Vulnerability Exploited in Past Month's Wave of Attacks (SecurityWeek)

Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates (SecurityWeek)

Chairman Carr Proposes to Expand Direct-to-Device Satellite Broadband Connectivity to Unlicensed Wireless Devices (FCC)

LG to Ban Residential Proxies from Smart TV Apps (Krebs on Security)

Police dismantle Kratos phishing platform, arrest developer (Bleeping Computer)

AI's cheatin' heart will make you weep (The Register)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-07-21

The defense against the AI arts.

25 min Transcript
View

Trump's latest AI leader resigns. The Army burns through its AI tokens. Scammers impersonate IC3 personnel.HollowGraph malware uses a compromised Microsoft 365 calendar for C2. Qilin ransomware targets a critical Palo Alto Networks flaw. A North Korean campaign targets Web3 and cryptocurrency professionals through fake job recruitment scams. Zimbra patches multiple critical bugs. Shadow AI creates regulatory headaches. Hackers wipe Romania’s land registry database. Our guest is Errol Weiss, Chief Security Officer at Health-ISAC, setting the record straight on ransomware trends. Patching the automotive security system you didn’t know you had. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we have Errol Weiss, Chief Security Officer at Health-ISAC, joining us to discuss ransomware trends in the healthcare industry. We also discuss findings from the Health-ISAC 2026 CISO Benchmarking Report and Health-ISAC's 2nd Quarter Heartbeat Report, which examine the current threat landscape facing the health sector.

Selected Reading

Trump's latest AI czar has already resigned (TechCrunch)

The Army Is Burning Through Its AI Tokens (WIRED)

Fake FBI Agents Use IC3 Complaints to Target Scam Victims (Hackread)

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication (SecurityWeek)

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang (Bleeping Computer)

Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros (Infosecurity Magazine)

Zimbra Update Patches Critical Vulnerabilities (SecurityWeek)

Shadow AI Is Rewriting Cyber Disclosure Risk (BankInfoSecurity)

Risky Bulletin: Hacker wipes Romania's entire land registry database (Risky.Biz)

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now (WIRED)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Trump's latest AI leader resigns. The Army burns through its AI tokens. Scammers impersonate IC3 personnel.HollowGraph malware uses a compromised Microsoft 365 calendar for C2. Qilin ransomware targets a critical Palo Alto Networks flaw. A North Korean campaign targets Web3 and cryptocurrency professionals through fake job recruitment scams. Zimbra patches multiple critical bugs. Shadow AI creates regulatory headaches. Hackers wipe Romania’s land registry database. Our guest is Errol Weiss, Chief Security Officer at Health-ISAC, setting the record straight on ransomware trends. Patching the automotive security system you didn’t know you had. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we have Errol Weiss, Chief Security Officer at Health-ISAC, joining us to discuss ransomware trends in the healthcare industry. We also discuss findings from the Health-ISAC 2026 CISO Benchmarking Report and Health-ISAC's 2nd Quarter Heartbeat Report, which examine the current threat landscape facing the health sector.

Selected Reading

Trump's latest AI czar has already resigned (TechCrunch)

The Army Is Burning Through Its AI Tokens (WIRED)

Fake FBI Agents Use IC3 Complaints to Target Scam Victims (Hackread)

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication (SecurityWeek)

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang (Bleeping Computer)

Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros (Infosecurity Magazine)

Zimbra Update Patches Critical Vulnerabilities (SecurityWeek)

Shadow AI Is Rewriting Cyber Disclosure Risk (BankInfoSecurity)

Risky Bulletin: Hacker wipes Romania's entire land registry database (Risky.Biz)

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now (WIRED)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Published 2026-07-20

Behind the friendly face.

29 min
View

Hugging Face reports an autonomous AI-powered breach. Ernst & Young discloses a client data breach. Attackers are actively exploiting a critical ServiceNow flaw. Ransomware gangs sharpen their tactics against law firms. Capital One open-sources an AI security tool. Text salting fools AI email filters. Hidden gambling apps slip into Apple’s App Store. And federal agents arrest a Florida man accused of spreading malware through video games. Monday business briefing. Tim Starks from CyberScoop discusses election integrity. Fake feathers lead to faulty findings.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Tim Starks from CyberScoop discussing election integrity and the Trump administration’s waning influence. You can read more here

Selected Reading

AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign (Security Affairs)

Ernst & Young Data Breach Affects Personal, Financial Information (SecurityWeek)

Critical ServiceNow code execution flaw now exploited in attacks (Bleeping Computer)

How ransomware tactics against law firms are changing (Wisconsin Law Journal)

Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool (SecurityWeek)

AI spam filters are getting suckered by old-school text salting (The Register)

Investigation reveals dozens of disguised gambling apps on the App Store in Brazil (9to5Mac)

FBI Arrests Florida Man in $220,000 Steam Crypto Theft Case (Hackread)

Israeli identity management startup Oak emerges from stealth with $60 million in seed funding. (N2K Pro Business Briefing)

AI-altered images on birdwatching forums putting research at risk | AI (artificial intelligence) (The Guardian)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Hugging Face reports an autonomous AI-powered breach. Ernst & Young discloses a client data breach. Attackers are actively exploiting a critical ServiceNow flaw. Ransomware gangs sharpen their tactics against law firms. Capital One open-sources an AI security tool. Text salting fools AI email filters. Hidden gambling apps slip into Apple’s App Store. And federal agents arrest a Florida man accused of spreading malware through video games. Monday business briefing. Tim Starks from CyberScoop discusses election integrity. Fake feathers lead to faulty findings.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Tim Starks from CyberScoop discussing election integrity and the Trump administration’s waning influence. You can read more here

Selected Reading

AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign (Security Affairs)

Ernst & Young Data Breach Affects Personal, Financial Information (SecurityWeek)

Critical ServiceNow code execution flaw now exploited in attacks (Bleeping Computer)

How ransomware tactics against law firms are changing (Wisconsin Law Journal)

Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool (SecurityWeek)

AI spam filters are getting suckered by old-school text salting (The Register)

Investigation reveals dozens of disguised gambling apps on the App Store in Brazil (9to5Mac)

FBI Arrests Florida Man in $220,000 Steam Crypto Theft Case (Hackread)

Israeli identity management startup Oak emerges from stealth with $60 million in seed funding. (N2K Pro Business Briefing)

AI-altered images on birdwatching forums putting research at risk | AI (artificial intelligence) (The Guardian)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere

As space becomes an increasingly critical part of modern infrastructure, governments are reevaluating decades of policy to ensure reliable, secure, and independent access to the systems they are increasingly relying on.

In this week’s episode, host Maria Varmazis sits down with producer Ethan Cook to explore Europe's evolving space strategy and how it is increasingly prioritizing space sovereignty. During the conversation, they examine the EU's proposed Space Act and how it aims to improve the region's space security, sustainability, and reliability for years to come.⁠⁠⁠

Key sources:

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.


More description

As space becomes an increasingly critical part of modern infrastructure, governments are reevaluating decades of policy to ensure reliable, secure, and independent access to the systems they are increasingly relying on.

In this week’s episode, host Maria Varmazis sits down with producer Ethan Cook to explore Europe's evolving space strategy and how it is increasingly prioritizing space sovereignty. During the conversation, they examine the EU's proposed Space Act and how it aims to improve the region's space security, sustainability, and reliability for years to come.⁠⁠⁠

Key sources:

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.


Extract Knowledge
Listen elsewhere

Lauren Fievisohn, Ph.D, Senior Threat Researcher from Silent Push, is sharing their work on "Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites." Silent Push researchers have identified a newly named threat actor, DriveSurge, which has compromised thousands of legitimate websites and uses ClickFix and fake browser update lures to distribute malware at scale through a pay-per-install operation.

The group leverages a traffic distribution system called zTDS to silently redirect visitors from trusted websites to malicious payloads, while employing sophisticated infrastructure, obfuscation, and fingerprinting techniques to evade detection. The report also details how DriveSurge targets both Windows and macOS users and provides defenders with eight infrastructure fingerprints to help identify and disrupt the campaign.

The research and executive brief can be found here:

More description

Lauren Fievisohn, Ph.D, Senior Threat Researcher from Silent Push, is sharing their work on "Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites." Silent Push researchers have identified a newly named threat actor, DriveSurge, which has compromised thousands of legitimate websites and uses ClickFix and fake browser update lures to distribute malware at scale through a pay-per-install operation.

The group leverages a traffic distribution system called zTDS to silently redirect visitors from trusted websites to malicious payloads, while employing sophisticated infrastructure, obfuscation, and fingerprinting techniques to evade detection. The report also details how DriveSurge targets both Windows and macOS users and provides defenders with eight infrastructure fingerprints to help identify and disrupt the campaign.

The research and executive brief can be found here:

Extract Knowledge
Listen elsewhere
Published 2026-07-17

A nightmare on Windows street.

25 min
View

Nightmare Eclipse drops another Windows zero-day. The Gentlemen take the ransomware crown. CISA orders emergency Fortinet patching. Canada’s surveillance bill faces U.S. scrutiny. Meta’s Oversight Board flags AI censorship bias. Commerce tops the cyber target list. An active espionage campaign hits Bangladesh’s military. The Hewlett Foundation commits $100 million to emerging tech security. And U.S. prosecutors dismantle an alleged cyber-enabled money laundering network. Our guest is Nick Stohlman, Vice President of CJIS Strategy at Imprivata, talking about CJIS readiness and the identity security challenges facing public safety agencies. Leaked source code reveals an AI mixtape.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Nick Stohlman, Vice President of CJIS Strategy at Imprivata, talking about CJIS, Criminal Justice Information Services, readiness and the identity security challenges facing public safety agencies.

Selected Reading

New Windows LegacyHive zero-day gives hackers admin privileges (Bleeping Computer)

The Gentlemen Overtakes Qilin as Most Prolific Ransomware Threat (Infosecurity Magazine)

CISA urges immediate action on actively exploited Fortinet flaws (Bleeping Computer)

Senator calls on Rubio, Blanche to push back against Canadian surveillance legislation (The Record)

Meta Oversight Board finds top AI models less likely to criticize repressive regimes (Reuters)

Commerce faces rising AI bot activity, escalating DDoS attacks, and new fraud tactics (Akamai)

From Biography to Backdoor: Tracking a DoNot (APT-C-35) Intrusion Targeting Bangladesh Military Personnel (Cyderes)

Hewlett Foundation Announces New $100 Million Emerging Technology and Security Initiative (Hewlett Foundation)

US charges two over laundering $43 million from investment fraud (Bleeping Computer)

Hack Reveals Suno AI Music Generator Scraped YouTube, Deezer, and Genius (404 Media)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Nightmare Eclipse drops another Windows zero-day. The Gentlemen take the ransomware crown. CISA orders emergency Fortinet patching. Canada’s surveillance bill faces U.S. scrutiny. Meta’s Oversight Board flags AI censorship bias. Commerce tops the cyber target list. An active espionage campaign hits Bangladesh’s military. The Hewlett Foundation commits $100 million to emerging tech security. And U.S. prosecutors dismantle an alleged cyber-enabled money laundering network. Our guest is Nick Stohlman, Vice President of CJIS Strategy at Imprivata, talking about CJIS readiness and the identity security challenges facing public safety agencies. Leaked source code reveals an AI mixtape.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Nick Stohlman, Vice President of CJIS Strategy at Imprivata, talking about CJIS, Criminal Justice Information Services, readiness and the identity security challenges facing public safety agencies.

Selected Reading

New Windows LegacyHive zero-day gives hackers admin privileges (Bleeping Computer)

The Gentlemen Overtakes Qilin as Most Prolific Ransomware Threat (Infosecurity Magazine)

CISA urges immediate action on actively exploited Fortinet flaws (Bleeping Computer)

Senator calls on Rubio, Blanche to push back against Canadian surveillance legislation (The Record)

Meta Oversight Board finds top AI models less likely to criticize repressive regimes (Reuters)

Commerce faces rising AI bot activity, escalating DDoS attacks, and new fraud tactics (Akamai)

From Biography to Backdoor: Tracking a DoNot (APT-C-35) Intrusion Targeting Bangladesh Military Personnel (Cyderes)

Hewlett Foundation Announces New $100 Million Emerging Technology and Security Initiative (Hewlett Foundation)

US charges two over laundering $43 million from investment fraud (Bleeping Computer)

Hack Reveals Suno AI Music Generator Scraped YouTube, Deezer, and Genius (404 Media)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2026-07-16

For hackers, sharing is caring.

30 min
View

CISA warns of active SharePoint attacks. The NSA pushes coordinated vulnerability disclosure. ClickLock Stealer targets macOS. Splunk and Zoom patch critical flaws. Spirals ransomware strikes in under 24 hours. New Windows evasion techniques emerge. LabubaRAT poses as NVIDIA software. 23andMe settles over its 2023 breach. Plus, a look back at one of the most audacious data center heists ever pulled off. Our guest is Ryan Kalember, Chief Strategy Officer at Proofpoint, discussing why agentic AI is creating a new insider threat. Near, far, wherever you are…the scam must go on.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Ryan Kalember, Chief Strategy Officer at Proofpoint, and he is discussing why agentic AI is creating a new insider threat.

Selected Reading

CISA urges immediate SharePoint hardening as exploits mount (CSO Online)

NSA joins CISA and Others in Releasing the Cybersecurity Information Sheet “Establishing a Coordinated Vulnerability Disclosure Program to Work with Security Researchers” (NSA)

‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing (SecurityWeek)

Splunk, Zoom Patch Critical Vulnerabilities (SecurityWeek)

New Spirals ransomware encrypts victim network in under 24 hours (Bleeping Computer)

Bind Link Abuse: One Windows Feature, Many Ways to Blind Your EDR (Bitdefender)

LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software (Blackpoint Cyber)

23andMe reaches $18 million settlement with states for massive breach (The Record)

How a Gang of Thieves Pulled Off a Multimillion-Dollar Data Center Heist (The New York Times)

Fake Céline Dion Paris Tickets Sold on Facebook and Ticketmaster Clones (Hackread)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

CISA warns of active SharePoint attacks. The NSA pushes coordinated vulnerability disclosure. ClickLock Stealer targets macOS. Splunk and Zoom patch critical flaws. Spirals ransomware strikes in under 24 hours. New Windows evasion techniques emerge. LabubaRAT poses as NVIDIA software. 23andMe settles over its 2023 breach. Plus, a look back at one of the most audacious data center heists ever pulled off. Our guest is Ryan Kalember, Chief Strategy Officer at Proofpoint, discussing why agentic AI is creating a new insider threat. Near, far, wherever you are…the scam must go on.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Ryan Kalember, Chief Strategy Officer at Proofpoint, and he is discussing why agentic AI is creating a new insider threat.

Selected Reading

CISA urges immediate SharePoint hardening as exploits mount (CSO Online)

NSA joins CISA and Others in Releasing the Cybersecurity Information Sheet “Establishing a Coordinated Vulnerability Disclosure Program to Work with Security Researchers” (NSA)

‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing (SecurityWeek)

Splunk, Zoom Patch Critical Vulnerabilities (SecurityWeek)

New Spirals ransomware encrypts victim network in under 24 hours (Bleeping Computer)

Bind Link Abuse: One Windows Feature, Many Ways to Blind Your EDR (Bitdefender)

LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software (Blackpoint Cyber)

23andMe reaches $18 million settlement with states for massive breach (The Record)

How a Gang of Thieves Pulled Off a Multimillion-Dollar Data Center Heist (The New York Times)

Fake Céline Dion Paris Tickets Sold on Facebook and Ticketmaster Clones (Hackread)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2026-07-15

Patchapalooza packs a punch.

28 min
View

Patch Tuesday. SonicWall urges immediate patching of actively exploited vulnerabilities.  The White House launches an AI-backed vulnerability clearinghouse. The Air Force contends with widespread cybersecurity quarantines. The UK and EU blame Russia for last year’s cyberattack on Poland’s power grid. Meta faces accusations of AI-assisted layoffs. NATO allies collaborate in space. The Pentagon offers paid cyber apprenticeships. Spanish police dismantle a cybercrime and money-laundering network. Our guest is Clark Frogley, Global Head of Fraud at Quantexa and former FBI agent, discussing the fraud-as-a-service economy and what banks are missing. Grok Build users data is cloudy with a chance of uploads. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Clark Frogley, Global Head of Fraud at Quantexa and former FBI agent, as he is discussing the fraud-as-a-service economy and what banks are missing.

Selected Reading

Microsoft Patches a Record 570 Security Flaws (Krebs on Security)

Adobe Patches Critical ColdFusion Vulnerabilities (SecurityWeek)

Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow (SecurityWeek)

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell (SecurityWeek)

Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates (SecurityWeek)

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now (Bleeping Computer)

White House announces ‘Gold Eagle’ AI clearinghouse for cyber vulnerabilities (Nextgov/FCW)

Air Force network lockouts hit troops and civilians (Federal News Network)

NATO Allies join forces to develop high-end space capabilities (NATO)

EU and UK officially blame Russian spies for cyberattack on Poland's power grid (The Register)

Meta used AI to target workers with medical conditions for layoffs, lawsuit claims (Reuters)

Pentagon opens application window for paid cyber apprenticeships (DefenseScoop)

Spanish Police take down €140 million cyber fraud ring, arrest four (Bleeping Computer)

Musk promises purge after Grok Build caught sending entire repos to the cloud (The Register)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Patch Tuesday. SonicWall urges immediate patching of actively exploited vulnerabilities.  The White House launches an AI-backed vulnerability clearinghouse. The Air Force contends with widespread cybersecurity quarantines. The UK and EU blame Russia for last year’s cyberattack on Poland’s power grid. Meta faces accusations of AI-assisted layoffs. NATO allies collaborate in space. The Pentagon offers paid cyber apprenticeships. Spanish police dismantle a cybercrime and money-laundering network. Our guest is Clark Frogley, Global Head of Fraud at Quantexa and former FBI agent, discussing the fraud-as-a-service economy and what banks are missing. Grok Build users data is cloudy with a chance of uploads. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Clark Frogley, Global Head of Fraud at Quantexa and former FBI agent, as he is discussing the fraud-as-a-service economy and what banks are missing.

Selected Reading

Microsoft Patches a Record 570 Security Flaws (Krebs on Security)

Adobe Patches Critical ColdFusion Vulnerabilities (SecurityWeek)

Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow (SecurityWeek)

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell (SecurityWeek)

Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates (SecurityWeek)

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now (Bleeping Computer)

White House announces ‘Gold Eagle’ AI clearinghouse for cyber vulnerabilities (Nextgov/FCW)

Air Force network lockouts hit troops and civilians (Federal News Network)

NATO Allies join forces to develop high-end space capabilities (NATO)

EU and UK officially blame Russian spies for cyberattack on Poland's power grid (The Register)

Meta used AI to target workers with medical conditions for layoffs, lawsuit claims (Reuters)

Pentagon opens application window for paid cyber apprenticeships (DefenseScoop)

Spanish Police take down €140 million cyber fraud ring, arrest four (Bleeping Computer)

Musk promises purge after Grok Build caught sending entire repos to the cloud (The Register)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2026-07-14

The ransomware toll road.

26 min
View

Treasury sanctions a VPN provider tied to ransomware. The Pentagon hits pause on CMMC audits. Critical flaws surface in Google Cloud’s Dialogflow CX. Estée Lauder discloses a data breach. Mobile networks become a battlefield for tracking U.S. personnel. Australia calls out Big Tech over child safety. SAP patches critical bugs. CISA flags an actively exploited Cisco flaw. And the federal government accelerates AI investments. Our guest is Bogdan Botezatu, Senior Director, Threat Research and Reporting at Bitdefender, talking about Cyberthreats to Journalists and Influencers. AI costs savings come at a price.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Bogdan Botezatu, Senior Director, Threat Research and Reporting at Bitdefender, is talking about "Targeting the Messengers: Cyberthreats to Journalists and Influencers," their awareness campaign designed to address the escalating digital and reputational risks faced by media professionals in hostile environments.

Selected Reading

US sanctions VPN, malware providers for enabling ransomware attacks (Bleeping Computer)

Pentagon announces 'immediate suspension' of CMMC Phase II mandates (Breaking Defense)

Google Cloud Dialogflow CX vulnerability allowed AI agent hijacking | brief  (SC Media)

Estée Lauder Companies Reports Data Breach Exposing Health Records and SSNs (Beyond Machines)

US military targeted in Iran war phone-tracking campaign (Financial Times)

Australia finds serious gaps in Big Tech response to online child sexual abuse (Reuters)

SAP warns of critical flaws in NetWeaver and Commerce Cloud (Bleeping Computer)

CISA adds Cisco IOS flaw to known exploited vulnerabilities catalog | brief (SC Media)

Federal AI Projects Get Priority in TMF Funding Dash (GovInfo Security)

Companies Are Throttling Employees’ AI Use Because It’s Too Expensive (404 Media)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Treasury sanctions a VPN provider tied to ransomware. The Pentagon hits pause on CMMC audits. Critical flaws surface in Google Cloud’s Dialogflow CX. Estée Lauder discloses a data breach. Mobile networks become a battlefield for tracking U.S. personnel. Australia calls out Big Tech over child safety. SAP patches critical bugs. CISA flags an actively exploited Cisco flaw. And the federal government accelerates AI investments. Our guest is Bogdan Botezatu, Senior Director, Threat Research and Reporting at Bitdefender, talking about Cyberthreats to Journalists and Influencers. AI costs savings come at a price.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Bogdan Botezatu, Senior Director, Threat Research and Reporting at Bitdefender, is talking about "Targeting the Messengers: Cyberthreats to Journalists and Influencers," their awareness campaign designed to address the escalating digital and reputational risks faced by media professionals in hostile environments.

Selected Reading

US sanctions VPN, malware providers for enabling ransomware attacks (Bleeping Computer)

Pentagon announces 'immediate suspension' of CMMC Phase II mandates (Breaking Defense)

Google Cloud Dialogflow CX vulnerability allowed AI agent hijacking | brief  (SC Media)

Estée Lauder Companies Reports Data Breach Exposing Health Records and SSNs (Beyond Machines)

US military targeted in Iran war phone-tracking campaign (Financial Times)

Australia finds serious gaps in Big Tech response to online child sexual abuse (Reuters)

SAP warns of critical flaws in NetWeaver and Commerce Cloud (Bleeping Computer)

CISA adds Cisco IOS flaw to known exploited vulnerabilities catalog | brief (SC Media)

Federal AI Projects Get Priority in TMF Funding Dash (GovInfo Security)

Companies Are Throttling Employees’ AI Use Because It’s Too Expensive (404 Media)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2026-07-13

State of the router.

26 min
View

The U.S. and its allies warn of Russian cyber threats targeting critical infrastructure as Europe rolls out new sanctions. Apple sues OpenAI over alleged trade secret theft. Progress investigates a potential ShareFile security incident, Zimbra patches a critical flaw, and researchers uncover the new CrashStealer macOS malware. Plus, the EPA tests water utility resilience, scammers clone trusted news sites, and our Monday business briefing. Our guest is Brandon Karpf, from NTT, discussing the 11th Japan-U.S. Cyber Dialogue. Californians smash that delete button.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Brandon Karpf, friend of the show discussing the 11th Japan-U.S. Cyber Dialogue.

Selected Reading

US and allies warn of Russian critical infrastructure attacks (Bleeping Computer)

EU sanctions Russian GRU military hackers over cyberattacks (Bleeping Computer)

OpenAI Hardware Biz Built with Apple Secrets, Apple Says (Gov Infosecurity)

Progress Software Warns of External Security Threat to ShareFile (Infosecurity Magazine)

Zimbra Patches Critical Code Execution Vulnerability (SecurityWeek)

When Hackers Cut the Internet, Will the Water Still Flow? (BankInfo Security)

‘A very good clone’: news stories faked to lure victims to scam investment sites (The Guardian)

CrashStealer: C++ macOS infostealer posing as crash reporter (Jamf)

Business Briefing for 07.08.26  (N2K Pro Business Briefing)

322,000 Californians sign up to have data brokers delete their personal information (Mercury News)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

The U.S. and its allies warn of Russian cyber threats targeting critical infrastructure as Europe rolls out new sanctions. Apple sues OpenAI over alleged trade secret theft. Progress investigates a potential ShareFile security incident, Zimbra patches a critical flaw, and researchers uncover the new CrashStealer macOS malware. Plus, the EPA tests water utility resilience, scammers clone trusted news sites, and our Monday business briefing. Our guest is Brandon Karpf, from NTT, discussing the 11th Japan-U.S. Cyber Dialogue. Californians smash that delete button.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Brandon Karpf, friend of the show discussing the 11th Japan-U.S. Cyber Dialogue.

Selected Reading

US and allies warn of Russian critical infrastructure attacks (Bleeping Computer)

EU sanctions Russian GRU military hackers over cyberattacks (Bleeping Computer)

OpenAI Hardware Biz Built with Apple Secrets, Apple Says (Gov Infosecurity)

Progress Software Warns of External Security Threat to ShareFile (Infosecurity Magazine)

Zimbra Patches Critical Code Execution Vulnerability (SecurityWeek)

When Hackers Cut the Internet, Will the Water Still Flow? (BankInfo Security)

‘A very good clone’: news stories faked to lure victims to scam investment sites (The Guardian)

CrashStealer: C++ macOS infostealer posing as crash reporter (Jamf)

Business Briefing for 07.08.26  (N2K Pro Business Briefing)

322,000 Californians sign up to have data brokers delete their personal information (Mercury News)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere

As the world prepares itself for quantum computing, governments and private space enterprises alike are looking to get ahead of the technology and manage the rapidly-accelerating risks.

In this week’s episode, host Maria Varmazis sits down with ⁠⁠⁠Eddy Zervigon, CEO of Quantum XChange to discuss the impacts that the post-quantum world will have impact on the space sector. During the conversation, they explore what stakeholders are doing to prepare themselves for Q-day and what a post-quantum world could look like.

Key sources:

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.

More description

As the world prepares itself for quantum computing, governments and private space enterprises alike are looking to get ahead of the technology and manage the rapidly-accelerating risks.

In this week’s episode, host Maria Varmazis sits down with ⁠⁠⁠Eddy Zervigon, CEO of Quantum XChange to discuss the impacts that the post-quantum world will have impact on the space sector. During the conversation, they explore what stakeholders are doing to prepare themselves for Q-day and what a post-quantum world could look like.

Key sources:

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.

Extract Knowledge
Listen elsewhere
Published 2026-07-11

Conti-versal opinions. [Research Saturday]

29 min
View

Today we are joined by Geoff White, host of Cyber Hack and BBC journalist, taking a deep dive into the Conti ransomware gang. Geoff explores an in-depth investigation into the notorious Conti ransomware gang, drawing from thousands of leaked internal messages to reveal how the group operated behind the scenes.

The research uncovers surprising internal debates over targeting healthcare organizations, the fallout from accidentally exposing sensitive Saudi royal family data, and frantic efforts to free an arrested gang member. It also offers a rare look at Conti leader Vitaliy Kovalev through newly uncovered video footage, providing an unprecedented glimpse into one of cybercrime's most influential figures.

More description

Today we are joined by Geoff White, host of Cyber Hack and BBC journalist, taking a deep dive into the Conti ransomware gang. Geoff explores an in-depth investigation into the notorious Conti ransomware gang, drawing from thousands of leaked internal messages to reveal how the group operated behind the scenes.

The research uncovers surprising internal debates over targeting healthcare organizations, the fallout from accidentally exposing sensitive Saudi royal family data, and frantic efforts to free an arrested gang member. It also offers a rare look at Conti leader Vitaliy Kovalev through newly uncovered video footage, providing an unprecedented glimpse into one of cybercrime's most influential figures.

Extract Knowledge
Listen elsewhere
Published 2026-07-10

GoshDarn it, that’s advanced.

25 min
View

Researchers track ransomware they say is getting GoshDarn sophisticated. Zimbra patches a critical vulnerability affecting its Classic Web Client. A sophisticated vishing campaign targeting Microsoft 365 accounts. GigaWiper combines espionage capabilities with multiple destructive payloads. The EU sues member states over lax cybersecurity. The NSA revives TAO. A Puerto Rican agency exposes roughly a million Social Security numbers. A former ransomware negotiator heads to prison for assisting BlackCat. Our guest is Maxim Zavodchik, Senior Director of AI Security Research at Akamai, with insights on the upcoming MCP specification. Bad Wifi leaves a trophy up for grabs. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

We are joined by Maxim Zavodchik, Senior Director of AI Security Research at Akamai sharing insights on new security risks that can arise from upcoming MCP specification.

Selected Reading

New Ransomware Exploits Malicious Driver to Remove Cybersecurity Protections (Infosecurity Magazine)

Zimbra urges customers to patch critical web client XSS flaw (Bleeping Computer)

Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers (SecurityWeek)

GigaWiper Combines Multiple Malware for System-Level Sabotage (SecurityWeek)

Commission preliminarily finds the addictive design of Instagram and Facebook in breach of the Digital Services Act (European Commision)

European Patience With Cybersecurity Laggards Snaps (BankInfoSecurity)

NSA revives 'Tailored Access Operations' name for elite hacking unit (The Record)

A Puerto Rico Government Agency Exposed 1 Million Social Security Numbers (ProPublica)

Third US Security Expert Sentenced to Prison for Helping Ransomware Gang (SecurityWeek)

Thief posed as Wi-Fi fixing hero, then stole priceless trophy (The Register)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Researchers track ransomware they say is getting GoshDarn sophisticated. Zimbra patches a critical vulnerability affecting its Classic Web Client. A sophisticated vishing campaign targeting Microsoft 365 accounts. GigaWiper combines espionage capabilities with multiple destructive payloads. The EU sues member states over lax cybersecurity. The NSA revives TAO. A Puerto Rican agency exposes roughly a million Social Security numbers. A former ransomware negotiator heads to prison for assisting BlackCat. Our guest is Maxim Zavodchik, Senior Director of AI Security Research at Akamai, with insights on the upcoming MCP specification. Bad Wifi leaves a trophy up for grabs. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

We are joined by Maxim Zavodchik, Senior Director of AI Security Research at Akamai sharing insights on new security risks that can arise from upcoming MCP specification.

Selected Reading

New Ransomware Exploits Malicious Driver to Remove Cybersecurity Protections (Infosecurity Magazine)

Zimbra urges customers to patch critical web client XSS flaw (Bleeping Computer)

Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers (SecurityWeek)

GigaWiper Combines Multiple Malware for System-Level Sabotage (SecurityWeek)

Commission preliminarily finds the addictive design of Instagram and Facebook in breach of the Digital Services Act (European Commision)

European Patience With Cybersecurity Laggards Snaps (BankInfoSecurity)

NSA revives 'Tailored Access Operations' name for elite hacking unit (The Record)

A Puerto Rico Government Agency Exposed 1 Million Social Security Numbers (ProPublica)

Third US Security Expert Sentenced to Prison for Helping Ransomware Gang (SecurityWeek)

Thief posed as Wi-Fi fixing hero, then stole priceless trophy (The Register)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2026-07-09

Who you gonna call?

24 min
View

GhostApproval puts AI coding assistants under the microscope. Microsoft fixes the RoguePlanet zero-day. More than 70 cybersecurity firms back a new AI Charter. An Ohio county may have paid a $1 million ransom. AssuranceAmerica discloses a breach affecting nearly seven million people. Australia bricks thousands of broadband routers. Israeli fintech Nayax reports a cyber incident. KDDI confirms a massive telecom data breach. A global anti-fraud operation leads to thousands of arrests. Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies explains the EU Cloud and AI Development Act. Slopfix fights fire with fire. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies discussing the EU Cloud and AI Development Act.

Selected Reading

GhostApproval Flaw Hits Six Major AI Coding Assistants (Infosecurity Magazine)

Microsoft Patches RoguePlanet Defender Zero-Day That Grants SYSTEM Access (Daily CyberSecurity)

New AI Security Charter Backed by Over 70 Cyber Firms  (Infosecurity Magazine)

County Government Reportedly Paid $1 Million to Cyber Extortion Group (SecurityWeek)

AssuranceAmerica data breach exposes records of 6.9 million drivers (Bleeping Computer)

Aussie gov't tells volunteers to throw out thousands of functioning test routers (Ars Technica)

Nayax shares slide after fintech company reveals cloud security breach (Ctech)

12 Million Impacted by Data Breach at Japanese Telco KDDI (SecurityWeek)

Chinese-Funded Interpol Cybercrime Crackdown Leads to 5,800 Arrests (Infosecurity Magazine)

'Slopfix' software team charges $10,000 a week to delete AI-generated code bloat — ironically, the team uses AI agents to trim messy repositories by up to 65% (Tom's Hardware)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

GhostApproval puts AI coding assistants under the microscope. Microsoft fixes the RoguePlanet zero-day. More than 70 cybersecurity firms back a new AI Charter. An Ohio county may have paid a $1 million ransom. AssuranceAmerica discloses a breach affecting nearly seven million people. Australia bricks thousands of broadband routers. Israeli fintech Nayax reports a cyber incident. KDDI confirms a massive telecom data breach. A global anti-fraud operation leads to thousands of arrests. Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies explains the EU Cloud and AI Development Act. Slopfix fights fire with fire. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies discussing the EU Cloud and AI Development Act.

Selected Reading

GhostApproval Flaw Hits Six Major AI Coding Assistants (Infosecurity Magazine)

Microsoft Patches RoguePlanet Defender Zero-Day That Grants SYSTEM Access (Daily CyberSecurity)

New AI Security Charter Backed by Over 70 Cyber Firms  (Infosecurity Magazine)

County Government Reportedly Paid $1 Million to Cyber Extortion Group (SecurityWeek)

AssuranceAmerica data breach exposes records of 6.9 million drivers (Bleeping Computer)

Aussie gov't tells volunteers to throw out thousands of functioning test routers (Ars Technica)

Nayax shares slide after fintech company reveals cloud security breach (Ctech)

12 Million Impacted by Data Breach at Japanese Telco KDDI (SecurityWeek)

Chinese-Funded Interpol Cybercrime Crackdown Leads to 5,800 Arrests (Infosecurity Magazine)

'Slopfix' software team charges $10,000 a week to delete AI-generated code bloat — ironically, the team uses AI agents to trim messy repositories by up to 65% (Tom's Hardware)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2026-07-08

Azure you concerned?

26 min
View

Accenture confirms a data breach. An Australian telecom investigates a nationwide outage. It’s shields up for the UK. CISA eyes September for its critical infrastructure reporting rule. NewsJunkie fakes CTV ad traffic. Agentic AI triggers EDR. CISA taps Mythos for vulnerability scans. Meta faces trillion dollar fines in state lawsuits. Our guest is Russ Anderson, COO and co-founder of RapidFort, sharing a coordinated industry effort to harden the world’s most critical open source software against AI-enabled cyber threats. When it comes to breaches, mum’s the word. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Russ Anderson, COO and co-founder of RapidFort, is sharing the Linux Foundation's Akrites initiative, a coordinated industry effort to harden the world’s most critical open source software against AI-enabled cyber threats.

Selected Reading

Accenture confirms breach after hacker offers stolen data for sale (Bleeping Computer)

Nationwide Telstra outage disrupts thousands, raises questions of foreign launched cyberattack (The Nightly)

Britain plans to build autonomous AI 'Cyber Shield' to defend nation (The Record)

CISA Eyes September Date for Final Cyber Incident Reporting Rule (MeriTalk)

HUMAN Security Disrupts CTV Device Spoofing Operation "NewsJunkie" (Globe Newswire)

When AI agents look like attackers: what behavioral telemetry tells us (SOPHOS)

Space Force adds Relativity, Impulse Space to national security launch program. (Space News) 

CISA Deploys Anthropic’s Mythos AI to Hunt Vulnerabilities in U.S. Government Code (Security Affairs)

Mark Zuckerberg’s biggest legal nightmare yet could cost Meta $1.4 trillion (The Independent)

Most cybersecurity workers have been told to conceal a breach, report finds (Cybersecurity Dive)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Accenture confirms a data breach. An Australian telecom investigates a nationwide outage. It’s shields up for the UK. CISA eyes September for its critical infrastructure reporting rule. NewsJunkie fakes CTV ad traffic. Agentic AI triggers EDR. CISA taps Mythos for vulnerability scans. Meta faces trillion dollar fines in state lawsuits. Our guest is Russ Anderson, COO and co-founder of RapidFort, sharing a coordinated industry effort to harden the world’s most critical open source software against AI-enabled cyber threats. When it comes to breaches, mum’s the word. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Russ Anderson, COO and co-founder of RapidFort, is sharing the Linux Foundation's Akrites initiative, a coordinated industry effort to harden the world’s most critical open source software against AI-enabled cyber threats.

Selected Reading

Accenture confirms breach after hacker offers stolen data for sale (Bleeping Computer)

Nationwide Telstra outage disrupts thousands, raises questions of foreign launched cyberattack (The Nightly)

Britain plans to build autonomous AI 'Cyber Shield' to defend nation (The Record)

CISA Eyes September Date for Final Cyber Incident Reporting Rule (MeriTalk)

HUMAN Security Disrupts CTV Device Spoofing Operation "NewsJunkie" (Globe Newswire)

When AI agents look like attackers: what behavioral telemetry tells us (SOPHOS)

Space Force adds Relativity, Impulse Space to national security launch program. (Space News) 

CISA Deploys Anthropic’s Mythos AI to Hunt Vulnerabilities in U.S. Government Code (Security Affairs)

Mark Zuckerberg’s biggest legal nightmare yet could cost Meta $1.4 trillion (The Independent)

Most cybersecurity workers have been told to conceal a breach, report finds (Cybersecurity Dive)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2026-07-07

Welcome home, hacker.

27 min
View

CERT/CC warns of an unpatched Tenda router backdoor. Adobe races to patch an actively exploited ColdFusion flaw. Canada pulls back the curtain on offensive cyber operations. Anthropic quietly removes hidden tracking from Claude Code. Chinese AI gains momentum as U.S. providers sweeten the deal. U.S. cloud firms challenge South Korea’s new security rules. Microsoft’s device telemetry helps unmask an alleged Scattered Spider hacker. And Spanish police arrest an alleged pro-Russia hacktivist.Orla Daly, CIO at Skillsoft, discusses if AI is already bypassing its own guardrails and why most organizations aren't ready. The stochastic parrot is back, and it’s tired of being misquoted.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Orla Daly, CIO at Skillsoft, discusses if AI is already bypassing its own guardrails and why most organizations aren't ready.

Selected Reading

Hidden Tenda Router Backdoor Grants Admin Access, No Patch Available (Security Affairs)

Hackers Exploit Maximum Severity Adobe ColdFusion Flaw (Infosecurity Magazine)

Canadian spy agency says it hacked drug traffickers, extremists, and a ransomware gang last year (TechCrunch)

Secret Claude tracker shocks users after Anthropic’s anti-surveillance stance (Ars Technica)

Chinese AI models are gaining ground with U.S. companies as OpenAI, Anthropic costs surge (CNBC)

AI Giants Are Handing Out Tons of Free Computing Power to Grab Startup Share (Wall Street Journal)

U.S. Big Tech raises concerns over Seoul's proposed cloud security rules (Korea JoongAng Daily)

Microsoft device telemetry key to unmasking alleged Scattered Spider hacker (iTnews)

Spain collars alleged pro-Russia hacktivist after FBI tip-off (The Register)

What Emily Bender Really Meant by "Stochastic Parrots" (IEEE Spectrum)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

CERT/CC warns of an unpatched Tenda router backdoor. Adobe races to patch an actively exploited ColdFusion flaw. Canada pulls back the curtain on offensive cyber operations. Anthropic quietly removes hidden tracking from Claude Code. Chinese AI gains momentum as U.S. providers sweeten the deal. U.S. cloud firms challenge South Korea’s new security rules. Microsoft’s device telemetry helps unmask an alleged Scattered Spider hacker. And Spanish police arrest an alleged pro-Russia hacktivist.Orla Daly, CIO at Skillsoft, discusses if AI is already bypassing its own guardrails and why most organizations aren't ready. The stochastic parrot is back, and it’s tired of being misquoted.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Orla Daly, CIO at Skillsoft, discusses if AI is already bypassing its own guardrails and why most organizations aren't ready.

Selected Reading

Hidden Tenda Router Backdoor Grants Admin Access, No Patch Available (Security Affairs)

Hackers Exploit Maximum Severity Adobe ColdFusion Flaw (Infosecurity Magazine)

Canadian spy agency says it hacked drug traffickers, extremists, and a ransomware gang last year (TechCrunch)

Secret Claude tracker shocks users after Anthropic’s anti-surveillance stance (Ars Technica)

Chinese AI models are gaining ground with U.S. companies as OpenAI, Anthropic costs surge (CNBC)

AI Giants Are Handing Out Tons of Free Computing Power to Grab Startup Share (Wall Street Journal)

U.S. Big Tech raises concerns over Seoul's proposed cloud security rules (Korea JoongAng Daily)

Microsoft device telemetry key to unmasking alleged Scattered Spider hacker (iTnews)

Spain collars alleged pro-Russia hacktivist after FBI tip-off (The Register)

What Emily Bender Really Meant by "Stochastic Parrots" (IEEE Spectrum)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2026-07-06

NetNut gets cracked.

28 min
View

The FBI disrupts a major residential proxy service. Attackers exploit Fortinet firewalls to target UK officials. European lawmakers call for a spyware investigation. A new macOS infostealer masquerades as a clipboard manager. Prompt injection campaigns targeting AI agents through malicious websites and SEO poisoning. Researchers trick Claude into remote code execution. AI’s strain on the power grid is complicated. Monday business briefing. Our guest is Gabi Reish, VP Product, Threat Intelligence & Exposure Management at Bitsight, sharing insights on how cybercriminal activity is shifting. Anime and AI meet adolescent antics. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Gabi Reish, VP Product, Threat Intelligence & Exposure Management at Bitsight, sharing insights on how cybercriminal activity is shifting. You can learn more here.

Selected Reading

FBI Seizes NetNut Domains as Google Disrupts 2M Device Proxy Network (HackRead)

Russian hackers steal government logins (The Telegraph)

Lawmaker Probing Pegasus Spyware Infected Using Same Malware (BankInfo Security)

PamStealer: a Rust-based macOS infostealer that validates credentials through PAM (Jamf)

Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments (SecurityWeek)

Red teamers turned Claude Desktop into a double agent to do their evil bidding (The Register)

How Data Centers Grid Instability Threatens Reliability (IEEE Spectrum)

Quantifind has secured $200 million in a funding round led by Summit Partners. (N2K Pro Business Briefing) 

Japanese teen arrested for cyberattack that unsubscribed over 46,000 anime accounts (The Straits Times)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

The FBI disrupts a major residential proxy service. Attackers exploit Fortinet firewalls to target UK officials. European lawmakers call for a spyware investigation. A new macOS infostealer masquerades as a clipboard manager. Prompt injection campaigns targeting AI agents through malicious websites and SEO poisoning. Researchers trick Claude into remote code execution. AI’s strain on the power grid is complicated. Monday business briefing. Our guest is Gabi Reish, VP Product, Threat Intelligence & Exposure Management at Bitsight, sharing insights on how cybercriminal activity is shifting. Anime and AI meet adolescent antics. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Gabi Reish, VP Product, Threat Intelligence & Exposure Management at Bitsight, sharing insights on how cybercriminal activity is shifting. You can learn more here.

Selected Reading

FBI Seizes NetNut Domains as Google Disrupts 2M Device Proxy Network (HackRead)

Russian hackers steal government logins (The Telegraph)

Lawmaker Probing Pegasus Spyware Infected Using Same Malware (BankInfo Security)

PamStealer: a Rust-based macOS infostealer that validates credentials through PAM (Jamf)

Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments (SecurityWeek)

Red teamers turned Claude Desktop into a double agent to do their evil bidding (The Register)

How Data Centers Grid Instability Threatens Reliability (IEEE Spectrum)

Quantifind has secured $200 million in a funding round led by Summit Partners. (N2K Pro Business Briefing) 

Japanese teen arrested for cyberattack that unsubscribed over 46,000 anime accounts (The Straits Times)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere

Over the past two decades, the space industry has changed dramatically, evolving from a largely government led effort to one that is now rooted in private enterprises driving growth and innovation.

In this week’s episode, host Maria Varmazis sits down with ⁠⁠⁠Damian DiPippa, CEO of Auria Space, to discuss how the commercialization of the space industry is driving new changes. During the conversation, they explore the future of command and control, cyber resilience, and the growing partnership between commercial and national security space.

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.

More description

Over the past two decades, the space industry has changed dramatically, evolving from a largely government led effort to one that is now rooted in private enterprises driving growth and innovation.

In this week’s episode, host Maria Varmazis sits down with ⁠⁠⁠Damian DiPippa, CEO of Auria Space, to discuss how the commercialization of the space industry is driving new changes. During the conversation, they explore the future of command and control, cyber resilience, and the growing partnership between commercial and national security space.

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.

Extract Knowledge
Listen elsewhere

While we take a break this 4th of July weekend, please enjoy this encore of AI Security Brief.

Your enterprise AI strategy isn’t as far along as you think. The reality for most organizations today is that AI is disrupting existing processes more than it’s delivering outcomes… so far. And according to Dr. Grace Trinidad, Research Director at IDC, that’s how it should be.

In this episode, host Johnny Hand sits down with Dr. Grace to discuss how AI adoption follows the same pattern as almost every major digital transformation, and why this disruption phase we’re in is messy, yet critically important. 

What we cover:

  • How history demonstrates that automation across industries created disruption well before delivering value

  • Why your AI adoption strategy is much more than simple tool deployment

  • What business and technology leaders need to consider as they integrate AI into operational workflows

  • How token consumption and AI FinOps are the emerging security and cost risk

  • How AI ontologies will be the next real business differentiator

Why stick around: 

If you’ve been wondering if your organization’s AI adoption strategy is ahead of the curve, Dr. Grace will give you a much clearer picture of where you really stand.

Episode resources:

About AI Security Brief

AI Security Brief is where security and technology leaders come to get ahead. Join us for real conversations on the AI trends, threats, and decisions that can't wait.

About TrendAI

TrendAI™ empowers organizations to lead the future of AI with proactive security designed to inspire innovation and eliminate risk. TrendAI™. AI Fearlessly.

More description

While we take a break this 4th of July weekend, please enjoy this encore of AI Security Brief.

Your enterprise AI strategy isn’t as far along as you think. The reality for most organizations today is that AI is disrupting existing processes more than it’s delivering outcomes… so far. And according to Dr. Grace Trinidad, Research Director at IDC, that’s how it should be.

In this episode, host Johnny Hand sits down with Dr. Grace to discuss how AI adoption follows the same pattern as almost every major digital transformation, and why this disruption phase we’re in is messy, yet critically important. 

What we cover:

  • How history demonstrates that automation across industries created disruption well before delivering value

  • Why your AI adoption strategy is much more than simple tool deployment

  • What business and technology leaders need to consider as they integrate AI into operational workflows

  • How token consumption and AI FinOps are the emerging security and cost risk

  • How AI ontologies will be the next real business differentiator

Why stick around: 

If you’ve been wondering if your organization’s AI adoption strategy is ahead of the curve, Dr. Grace will give you a much clearer picture of where you really stand.

Episode resources:

About AI Security Brief

AI Security Brief is where security and technology leaders come to get ahead. Join us for real conversations on the AI trends, threats, and decisions that can't wait.

About TrendAI

TrendAI™ empowers organizations to lead the future of AI with proactive security designed to inspire innovation and eliminate risk. TrendAI™. AI Fearlessly.

Extract Knowledge
Listen elsewhere

In this special edition of CyberWire Daily’s 10th anniversary series, N2K CyberWire's Maria Varmazis and Dave Bittner discuss 10 years of vulnerabilities, zero‑days, and hardware flaws. Together they reflect on the last decade of cybersecurity vulnerabilities, exploring key shifts, landmark incidents like WannaCry and Log4Shell, and the evolving landscape shaped by hardware issues and AI.

Join Maria and Dave as they discuss how these changes impacted security practices and the importance of vigilance in a rapidly interconnected world.

More description

In this special edition of CyberWire Daily’s 10th anniversary series, N2K CyberWire's Maria Varmazis and Dave Bittner discuss 10 years of vulnerabilities, zero‑days, and hardware flaws. Together they reflect on the last decade of cybersecurity vulnerabilities, exploring key shifts, landmark incidents like WannaCry and Log4Shell, and the evolving landscape shaped by hardware issues and AI.

Join Maria and Dave as they discuss how these changes impacted security practices and the importance of vigilance in a rapidly interconnected world.

Extract Knowledge
Listen elsewhere
Published 2026-07-02

The people's AI?

27 min
View

OpenAI considers an equity plan to share AI wealth with the public. Cisco confirms active exploitation of its unified CM platform. Researchers discover autonomous ransomware. The Vect ransomware operation partners with TeamPCP. The FortiBleed credential-harvesting campaign is linked to ransomware attacks. Veil#Drop stealthily deploys the PureLog Stealer. Scammers target small businesses with fake law enforcement emails. Apple’s Hide My Email feature…doesn’t. An alleged Scattered Spider member is extradited to the United States. Our guest is Ben Yelin, Dave's Caveat cohost, on the Supreme Court’s geofence warrants ruling. Microsoft’s quantum claims leave physicists in two states at once.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies discussing the Supreme Court ruling on geofence warrants. If you enjoyed this conversation, you can check out Ben on Caveat.

Selected Reading

OpenAI in talks to give Trump administration a 5% stake in the company, FT reports (CNN Business)

Cisco finally confirms attackers exploiting Unified CM flaw (Bleeping Computer)

Sysdig Details JADEPUFFER, the First Documented Agentic Ransomware Operation (HackRead)

Vect and TeamPCP partner for ransomware campaigns (Sophos)

FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks (SecurityWeek)

VEIL#DROP: Blogspot-Hosted PowerShell Loader (Secureonix)

Fake Interpol investigation emails target small businesses with ransomware (Bitdefender)

Apple ‘Hide My Email’ Vulnerability Reveals Peoples’ Real Email Addresses (404 Media)

Alleged Member of Criminal Cyber Hacking Group “Scattered Spider” Arrested in Finland and Extradited to the United States (U.S. Department of Justice, Office of Public Affairs)

Is there a new quantum processor or is Microsoft lying? (Mathew Ingram)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

OpenAI considers an equity plan to share AI wealth with the public. Cisco confirms active exploitation of its unified CM platform. Researchers discover autonomous ransomware. The Vect ransomware operation partners with TeamPCP. The FortiBleed credential-harvesting campaign is linked to ransomware attacks. Veil#Drop stealthily deploys the PureLog Stealer. Scammers target small businesses with fake law enforcement emails. Apple’s Hide My Email feature…doesn’t. An alleged Scattered Spider member is extradited to the United States. Our guest is Ben Yelin, Dave's Caveat cohost, on the Supreme Court’s geofence warrants ruling. Microsoft’s quantum claims leave physicists in two states at once.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies discussing the Supreme Court ruling on geofence warrants. If you enjoyed this conversation, you can check out Ben on Caveat.

Selected Reading

OpenAI in talks to give Trump administration a 5% stake in the company, FT reports (CNN Business)

Cisco finally confirms attackers exploiting Unified CM flaw (Bleeping Computer)

Sysdig Details JADEPUFFER, the First Documented Agentic Ransomware Operation (HackRead)

Vect and TeamPCP partner for ransomware campaigns (Sophos)

FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks (SecurityWeek)

VEIL#DROP: Blogspot-Hosted PowerShell Loader (Secureonix)

Fake Interpol investigation emails target small businesses with ransomware (Bitdefender)

Apple ‘Hide My Email’ Vulnerability Reveals Peoples’ Real Email Addresses (404 Media)

Alleged Member of Criminal Cyber Hacking Group “Scattered Spider” Arrested in Finland and Extradited to the United States (U.S. Department of Justice, Office of Public Affairs)

Is there a new quantum processor or is Microsoft lying? (Mathew Ingram)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2026-07-01

The AI lock comes off.

30 min
View

The US restores exports of Anthropic’s most advanced AI models. Adobe and Citrix rush out critical patches. RustDuck emerges as a fast-evolving DDoS threat. The Gentlemen raise the stakes with a new EDR-killing exploit. Rocket lab bets big on Iridium. Researchers unveil browser-only ransomware. New Zealand faces questions about its cyber readiness. Iran’s long-running cyber espionage campaign is back in the spotlight. Our guest is Donald Codling, CISO and senior advisor to REGO on cybersecurity and data privacy matters, to discuss the importance of tying security by design to psychological safety and digital trust. VIP backstage access, courtesy of Claude.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Donald Codling, CISO and senior advisor to REGO on cybersecurity and data privacy matters, to discuss the importance of tying security by design to psychological safety and digital trust.

Selected Reading

Fable and Mythos: Anthropic says US lifts export ban on its advanced AI tools (BBC)

Adobe patches seven max severity ColdFusion, Campaign flaws (Bleeping Computer)

RustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow (SecurityAffairs)

Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack (SecurityWeek)

Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs (Expel)

Rocket Lab to Acquire Iridium in Historic Deal, Creating A Fully Vertically Integrated Space Powerhouse Primed for Growth (Globe Newswire)

Ransomware that runs inside your browser tab, where antivirus cannot see it (Suriq)

Three major cybehttps://suriq.io/blog/browser-only-ransomware-file-system-accessrattacks have raised alarms about New Zealand's security (RNZ)

Arrest of Iranian Hacker Spotlights Iran’s Movement into Economic Espionage and IP Theft (Zero Day)

Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival (WIRED)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

The US restores exports of Anthropic’s most advanced AI models. Adobe and Citrix rush out critical patches. RustDuck emerges as a fast-evolving DDoS threat. The Gentlemen raise the stakes with a new EDR-killing exploit. Rocket lab bets big on Iridium. Researchers unveil browser-only ransomware. New Zealand faces questions about its cyber readiness. Iran’s long-running cyber espionage campaign is back in the spotlight. Our guest is Donald Codling, CISO and senior advisor to REGO on cybersecurity and data privacy matters, to discuss the importance of tying security by design to psychological safety and digital trust. VIP backstage access, courtesy of Claude.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Donald Codling, CISO and senior advisor to REGO on cybersecurity and data privacy matters, to discuss the importance of tying security by design to psychological safety and digital trust.

Selected Reading

Fable and Mythos: Anthropic says US lifts export ban on its advanced AI tools (BBC)

Adobe patches seven max severity ColdFusion, Campaign flaws (Bleeping Computer)

RustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow (SecurityAffairs)

Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack (SecurityWeek)

Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs (Expel)

Rocket Lab to Acquire Iridium in Historic Deal, Creating A Fully Vertically Integrated Space Powerhouse Primed for Growth (Globe Newswire)

Ransomware that runs inside your browser tab, where antivirus cannot see it (Suriq)

Three major cybehttps://suriq.io/blog/browser-only-ransomware-file-system-accessrattacks have raised alarms about New Zealand's security (RNZ)

Arrest of Iranian Hacker Spotlights Iran’s Movement into Economic Espionage and IP Theft (Zero Day)

Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival (WIRED)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2026-06-30

The court draws a privacy line.

24 min
View

The Supreme Court limits geofence warrants. DHS moves to expand CISA. The State Department offers $10 million for Russian hackers. A legal theory could reshape EU-U.S. data sharing. Plus, cyberattacks hit D.C. housing, Oracle and SimpleHelp flaws face active exploitation, malware lingers on Japanese military networks, and stolen Apple supplier data surfaces online. John Cannava, CIO at Ping Identity, discusses how identity threats don't go on holiday. The Secret Service dial down the risk on BYOD. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by John Cannava, CIO at Ping Identity, as he discusses how identity threats don't go on holiday: how attackers take advantage of these high-traffic moments to blend in with normal user behavior, and what needs to change to better protect fans of major events like this summer's World Cup, and identity threats in travel at large.

Selected Reading

Supreme Court says police need a warrant to obtain Google location data (Washington Post)

DHS Eyes 600 New Cybersecurity Hires, New Director for CISA (BankInfo Security)

US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp (The Record)

US Supreme Court just blew up EU-US Data Transfers (NOYB)

DC Housing Authority hit by cyberattack, website down (WJLA)

Exploitation of Recent Oracle E-Business Suite Vulnerability Begins (SecurityWeek)

USB drives carrying China-linked malware infected Japanese military networks for nearly a year (Bitdefender)

A forged login key unlocks SimpleHelp servers, and a new stealer is raiding cloud and AI credentials (SURIQ)

Apple iPhone 18 Pro supplier list, parts and photos exposed in Tata data leak (Reuters)

Even the Secret Service won't use company-issued phones (The Register)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

The Supreme Court limits geofence warrants. DHS moves to expand CISA. The State Department offers $10 million for Russian hackers. A legal theory could reshape EU-U.S. data sharing. Plus, cyberattacks hit D.C. housing, Oracle and SimpleHelp flaws face active exploitation, malware lingers on Japanese military networks, and stolen Apple supplier data surfaces online. John Cannava, CIO at Ping Identity, discusses how identity threats don't go on holiday. The Secret Service dial down the risk on BYOD. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by John Cannava, CIO at Ping Identity, as he discusses how identity threats don't go on holiday: how attackers take advantage of these high-traffic moments to blend in with normal user behavior, and what needs to change to better protect fans of major events like this summer's World Cup, and identity threats in travel at large.

Selected Reading

Supreme Court says police need a warrant to obtain Google location data (Washington Post)

DHS Eyes 600 New Cybersecurity Hires, New Director for CISA (BankInfo Security)

US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp (The Record)

US Supreme Court just blew up EU-US Data Transfers (NOYB)

DC Housing Authority hit by cyberattack, website down (WJLA)

Exploitation of Recent Oracle E-Business Suite Vulnerability Begins (SecurityWeek)

USB drives carrying China-linked malware infected Japanese military networks for nearly a year (Bitdefender)

A forged login key unlocks SimpleHelp servers, and a new stealer is raiding cloud and AI credentials (SURIQ)

Apple iPhone 18 Pro supplier list, parts and photos exposed in Tata data leak (Reuters)

Even the Secret Service won't use company-issued phones (The Register)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2026-06-29

AI behind the velvet rope.

28 min
View

The White House keeps frontier AI models on a short leash. Russian threat actors increasingly target secure messaging platforms. DirtyClone is a high-severity Linux kernel privilege escalation flaw. An investigation claims federal websites are violating privacy rules. Microsoft dismantles a sophisticated malicious browser extension campaign. Setting up a GitHub repository could trick AI coding agents into executing malicious payloads. The DOJ shuts down illegal World Cup streamers. An Anonymous-linked hacker gets 18 months for website defacement. Monday business briefing. Dylan Sandlin, Program Manager for Digital and Cybersecurity Content at the National Association of Corporate Directors (NACD), discusses cyber risk as a board concern. In healthcare AI, patient privacy needs a second opinion.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Dylan Sandlin, Program Manager for Digital and Cybersecurity Content at the National Association of Corporate Directors (NACD), discussing cyber risk as a board concern. If you're interested in learning more about NACD, be sure to check out their Director’s Handbook on Cyber-Risk Oversight.

Selected Reading

Washington pushes AI into an export-control era as rivals rush to fill the gap (Metacurity)

FBI and CISA Warn Russian Hackers Stealing Verification Codes and Account PINs From Signal Users (GB Hackers)

'DirtyClone' Linux Kernel Vulnerability Leads to Root Access (SecurityWeek)

‘It’s dangerous and it’s going to erode trust’: redesign of US government websites stokes surveillance fears | Trump administration (The Guardian)

StegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two Years (SecurityAffairs) 

Clean GitHub repo tricks AI coding agents into running malware (Bleeping Computer)

US seizes hundreds of FIFA World Cup illegal streaming domains (Bleeping Computer)

Anonymous-Linked Hacktivist Aubrey Cottle Jailed Over Texas GOP Cyberattack (Hackread)

Accenture acquires Dragos, runZero, and NetRise for more than $4 billion. (N2K Pro Business Briefing)

Medical diagnosis AIs can be tricked into telling whose data trained them (The Register)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.  

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

The White House keeps frontier AI models on a short leash. Russian threat actors increasingly target secure messaging platforms. DirtyClone is a high-severity Linux kernel privilege escalation flaw. An investigation claims federal websites are violating privacy rules. Microsoft dismantles a sophisticated malicious browser extension campaign. Setting up a GitHub repository could trick AI coding agents into executing malicious payloads. The DOJ shuts down illegal World Cup streamers. An Anonymous-linked hacker gets 18 months for website defacement. Monday business briefing. Dylan Sandlin, Program Manager for Digital and Cybersecurity Content at the National Association of Corporate Directors (NACD), discusses cyber risk as a board concern. In healthcare AI, patient privacy needs a second opinion.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Dylan Sandlin, Program Manager for Digital and Cybersecurity Content at the National Association of Corporate Directors (NACD), discussing cyber risk as a board concern. If you're interested in learning more about NACD, be sure to check out their Director’s Handbook on Cyber-Risk Oversight.

Selected Reading

Washington pushes AI into an export-control era as rivals rush to fill the gap (Metacurity)

FBI and CISA Warn Russian Hackers Stealing Verification Codes and Account PINs From Signal Users (GB Hackers)

'DirtyClone' Linux Kernel Vulnerability Leads to Root Access (SecurityWeek)

‘It’s dangerous and it’s going to erode trust’: redesign of US government websites stokes surveillance fears | Trump administration (The Guardian)

StegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two Years (SecurityAffairs) 

Clean GitHub repo tricks AI coding agents into running malware (Bleeping Computer)

US seizes hundreds of FIFA World Cup illegal streaming domains (Bleeping Computer)

Anonymous-Linked Hacktivist Aubrey Cottle Jailed Over Texas GOP Cyberattack (Hackread)

Accenture acquires Dragos, runZero, and NetRise for more than $4 billion. (N2K Pro Business Briefing)

Medical diagnosis AIs can be tricked into telling whose data trained them (The Register)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.  

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere

In this Special Edition episode, N2K CyberWire's Dave Bittner sits down with Caitlin Sarian, widely known as Cybersecurity Girl, to explore how storytelling, authenticity, and community are reshaping a more human-centered cybersecurity landscape.

Recorded live at The Cyber Guild's Uniting Women in Cyber (UWIC) Event last fall, this candid conversation highlights Caitlin’s unconventional path into cybersecurity and her mission to make the industry more accessible and relatable for all. 

Together, they explore how breaking down technical barriers can unlock new pathways into the field especially for those from nontraditional backgrounds.

UWIC brings together industry leaders, practitioners, and emerging talent to advance the cybersecurity workforce through leadership, innovation, and inclusion. Join us on Oct 8 for UWIC 2026

More description

In this Special Edition episode, N2K CyberWire's Dave Bittner sits down with Caitlin Sarian, widely known as Cybersecurity Girl, to explore how storytelling, authenticity, and community are reshaping a more human-centered cybersecurity landscape.

Recorded live at The Cyber Guild's Uniting Women in Cyber (UWIC) Event last fall, this candid conversation highlights Caitlin’s unconventional path into cybersecurity and her mission to make the industry more accessible and relatable for all. 

Together, they explore how breaking down technical barriers can unlock new pathways into the field especially for those from nontraditional backgrounds.

UWIC brings together industry leaders, practitioners, and emerging talent to advance the cybersecurity workforce through leadership, innovation, and inclusion. Join us on Oct 8 for UWIC 2026

Extract Knowledge
Listen elsewhere

Despite the space sector seeing greater investment and attention year-over-year, the sector still remains bound by an outdated and ineffective supply chain, especially in the United States.

In this week’s episode, host Maria Varmazis sits down with Doug Anderson, Partner at PwC, and Steve Jordan-Tomaszewski, Vice President of the Space Systems Division at AIA, to dive into PwC’s recent study looking at the sector’s supply chain limitations. During the conversation, they examine the supply chain’s base risks and bottlenecks, and what strategies can be utilized to address these concerns.

Key sources:

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.

More description

Despite the space sector seeing greater investment and attention year-over-year, the sector still remains bound by an outdated and ineffective supply chain, especially in the United States.

In this week’s episode, host Maria Varmazis sits down with Doug Anderson, Partner at PwC, and Steve Jordan-Tomaszewski, Vice President of the Space Systems Division at AIA, to dive into PwC’s recent study looking at the sector’s supply chain limitations. During the conversation, they examine the supply chain’s base risks and bottlenecks, and what strategies can be utilized to address these concerns.

Key sources:

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.

Extract Knowledge
Listen elsewhere
Published 2026-06-27

More bark than byte. [Research Saturday]

24 min
View

This week we are joined by Daniel Schwalbe, Chief Information Security Officer & Head of Investigations at DomainTools, discussing their work on "ZionSiphon OT Malware First Attempts? Psyops? Both?" Researchers at DomainTools take a closer look at ZionSiphon, a purported operational technology malware sample targeting the water sector, and find that despite its alarming appearance, it lacks many of the capabilities needed to function as a credible cyber-physical weapon.

They break down the malware's architecture, its operational shortcomings, and why it may be more of a prototype or proof of concept than a deployable threat. With heightened concern surrounding attacks on critical infrastructure amid the ongoing U.S.-Iran conflict, the research offers timely insight into separating genuine OT threats from overhyped malware.

The research and executive brief can be found here:

More description

This week we are joined by Daniel Schwalbe, Chief Information Security Officer & Head of Investigations at DomainTools, discussing their work on "ZionSiphon OT Malware First Attempts? Psyops? Both?" Researchers at DomainTools take a closer look at ZionSiphon, a purported operational technology malware sample targeting the water sector, and find that despite its alarming appearance, it lacks many of the capabilities needed to function as a credible cyber-physical weapon.

They break down the malware's architecture, its operational shortcomings, and why it may be more of a prototype or proof of concept than a deployable threat. With heightened concern surrounding attacks on critical infrastructure amid the ongoing U.S.-Iran conflict, the research offers timely insight into separating genuine OT threats from overhyped malware.

The research and executive brief can be found here:

Extract Knowledge
Listen elsewhere
Published 2026-06-26

Factory reset required.

25 min
View

Tata Electronics and Bajaj Auto continue recovery from cyberattacks. FCC tightens undersea cable rules to bolster national security. CISA warns of actively exploited PTC vulnerability. Gamaredon expands toolkit, hides behind legitimate services. Iran-linked hackers turn public warning systems into psychological weapons. Threat actors target critical infrastructure across Southeast Asia. DCloud framework behind global scam economy. Polish police disrupt SIM-swapping gang. French statistics agency reports cyberattack affecting nearly 13,000 staff. Our guest is Michael Fanning, CISO at Splunk, discussing how AI doesn’t create problems, it exposes them. And an open-book exam for hackers.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Michael Fanning, CISO at Splunk, discussing how AI doesn’t create problems, it exposes them.

Selected Reading

Apple supplier Tata tightens internal controls after data breach, sources say (Reuters) 

Bajaj Auto resumes normal operations as cyberattack probe continues (Storyboard18) 

FCC passes new cybersecurity rules for emergency systems, undersea cables (CyberScoop)

U.S. CISA adds Cisco and PTC Windchill and FlexPLM flaws to its Known Exploited Vulnerabilities catalog (SecurityAffairs) 

Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances (ESET) 

A Cyber-Psychological Operation: Iran-Linked Attackers Target Warning Systems (Claroty) 

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure (Unit 42)

From San Pedro to Salinas: How a Chinese Framework “DCloud Uni-App” Powers a Global Scam Economy (Infoblox)

Poland busts SIM-swapping gang tied to millions in crypto theft (BleepingComputer)

France's statistics department reports cyberattack on staff data (Reuters)

UK school’s network left wide open for invasion, student found (The Register)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Tata Electronics and Bajaj Auto continue recovery from cyberattacks. FCC tightens undersea cable rules to bolster national security. CISA warns of actively exploited PTC vulnerability. Gamaredon expands toolkit, hides behind legitimate services. Iran-linked hackers turn public warning systems into psychological weapons. Threat actors target critical infrastructure across Southeast Asia. DCloud framework behind global scam economy. Polish police disrupt SIM-swapping gang. French statistics agency reports cyberattack affecting nearly 13,000 staff. Our guest is Michael Fanning, CISO at Splunk, discussing how AI doesn’t create problems, it exposes them. And an open-book exam for hackers.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Michael Fanning, CISO at Splunk, discussing how AI doesn’t create problems, it exposes them.

Selected Reading

Apple supplier Tata tightens internal controls after data breach, sources say (Reuters) 

Bajaj Auto resumes normal operations as cyberattack probe continues (Storyboard18) 

FCC passes new cybersecurity rules for emergency systems, undersea cables (CyberScoop)

U.S. CISA adds Cisco and PTC Windchill and FlexPLM flaws to its Known Exploited Vulnerabilities catalog (SecurityAffairs) 

Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances (ESET) 

A Cyber-Psychological Operation: Iran-Linked Attackers Target Warning Systems (Claroty) 

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure (Unit 42)

From San Pedro to Salinas: How a Chinese Framework “DCloud Uni-App” Powers a Global Scam Economy (Infoblox)

Poland busts SIM-swapping gang tied to millions in crypto theft (BleepingComputer)

France's statistics department reports cyberattack on staff data (Reuters)

UK school’s network left wide open for invasion, student found (The Register)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2026-06-25

Gone with the command.

25 min
View

International operation disrupts Amadey and StealC malware infrastructure. Australian spy chief warns nation-state hackers are prepositioning for future sabotage. Stealthy new backdoor may be tied to initial access broker. Researchers uncover "Cordyceps" supply chain flaw. Iran-linked MuddyWater disguises espionage as ransomware attack. Cal Water says Handala's hacking claims were overstated. Report says Russia continued using Cellebrite phone-cracking tools after the ban. Chinese cybersecurity firm unveils AI tools to rival Anthropic's Mythos. DraftKings hacker is sentenced to eighteen months. Our guest is Erich Kron, CISO Advisor at KnowBe4, sharing the details of the CAPY program. And more Than Meets the Eye-P.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Erich Kron, CISO Advisor at KnowBe4, sharing the details of the CAPY (Cyber Awareness Program for You) program that offers free cybersecurity training for families.

Selected Reading

Three ‘cybercrime as a service’ operations undercut by Microsoft, law enforcement (The Record)

Scaling cybercrime disruption through innovation and AI (Microsoft)

Nation-state actors cracked critical Australian infrastructure to ‘cripple it at a time of their choosing’ (The Register) 

Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker (Security.com)

Cordyceps: The Silent Parasite Consuming Your Supply Chain (Novee) 

Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Cyber Espionage (Infosecurity Magazine)

Cal Water Finds No Evidence of OT Activity After Hackers Claimed They Could Disrupt Water Supply (SecurityWeek)

Russia used Cellebrite phone-hacking tool to crack down on dissident after firm cut off country (The Record)

China’s 360 says it has developed tools to match Anthropic’s Mythos (Reuters)

DraftKings hacker 'Snoopy' sentenced to 18 months in prison (BleepingComputer)

Nearly Half of LG Smart TV Apps Contain Residential Proxy SDKs (Spur Intelligence)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

International operation disrupts Amadey and StealC malware infrastructure. Australian spy chief warns nation-state hackers are prepositioning for future sabotage. Stealthy new backdoor may be tied to initial access broker. Researchers uncover "Cordyceps" supply chain flaw. Iran-linked MuddyWater disguises espionage as ransomware attack. Cal Water says Handala's hacking claims were overstated. Report says Russia continued using Cellebrite phone-cracking tools after the ban. Chinese cybersecurity firm unveils AI tools to rival Anthropic's Mythos. DraftKings hacker is sentenced to eighteen months. Our guest is Erich Kron, CISO Advisor at KnowBe4, sharing the details of the CAPY program. And more Than Meets the Eye-P.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Erich Kron, CISO Advisor at KnowBe4, sharing the details of the CAPY (Cyber Awareness Program for You) program that offers free cybersecurity training for families.

Selected Reading

Three ‘cybercrime as a service’ operations undercut by Microsoft, law enforcement (The Record)

Scaling cybercrime disruption through innovation and AI (Microsoft)

Nation-state actors cracked critical Australian infrastructure to ‘cripple it at a time of their choosing’ (The Register) 

Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker (Security.com)

Cordyceps: The Silent Parasite Consuming Your Supply Chain (Novee) 

Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Cyber Espionage (Infosecurity Magazine)

Cal Water Finds No Evidence of OT Activity After Hackers Claimed They Could Disrupt Water Supply (SecurityWeek)

Russia used Cellebrite phone-hacking tool to crack down on dissident after firm cut off country (The Record)

China’s 360 says it has developed tools to match Anthropic’s Mythos (Reuters)

DraftKings hacker 'Snoopy' sentenced to 18 months in prison (BleepingComputer)

Nearly Half of LG Smart TV Apps Contain Residential Proxy SDKs (Spur Intelligence)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2026-06-24

Klue me in on the breach.

28 min
View

LastPass says Klue breach affected customer information, but passwords remain secure. Attackers begin exploiting Cisco Unified CM vulnerability. CISA flags actively exploited Ubiquiti and Lantronix flaws, urges rapid patching. DifyTap flaws could expose private AI conversations across tenants. Researchers find AI plugin registry let unofficial tools masquerade as trusted software. xpl0itrs launches leak site, signaling shift toward full-service cyber extortion. Ransomware attack hits Indian auto giant Bajaj Auto. U.S. presses Meta to submit AI models for national security reviews. Alleged criminal marketplace administrator extradited to the US. U.S. expands sanctions against Cambodian scam network tied to cyber fraud operations. On today’s Industry Voices segment, we are joined by Mike Masciulli, Managing Director, Migration Products and Services at Semperis, discussing RC4 and AD Migration: The Break Scenarios Hiding in Your Source Domain. And a lesson in access control.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On today’s Industry Voices segment, we are joined by Mike Masciulli, Managing Director, Migration Products and Services at Semperis, discussing RC4 and AD Migration: The Break Scenarios Hiding in Your Source Domain. If you enjoyed this conversation, check out the full interview here.

Selected Reading

Password manager maker LastPass says hackers stole customer support case data during Klue breach (TechCrunch)

Klue says hackers stole credential from 2022 that led to customer data breaches (TechCrunch)

Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks (BleepingComputer)

U.S. CISA adds Ubiquiti UniFi OS and Lantronix EDS5000 plugin flaws to its Known Exploited Vulnerabilities catalog (SecurityAffairs) 

DifyTap: Zafran discovers how attackers can silently wiretap AI data across tenants on a platform powering 1M+ apps  (Zafran) 

23 ClawHub Plugins Squat Official Org Scopes (Manifold Security) 

Cyber Intel Brief: xpl0itrs Leak Site Launch (Dataminr) 

Indian auto giant Bajaj Auto hit by ransomware incident (The Record) 

U.S. Presses Meta to Agree to A.I. Reviews as Security Concerns Rise (NY Times)

Algerian Man Extradited to US for Running Cybercrime Marketplaces (SecurityWeek)

US adds sanctions against accused Cambodian scammers Prince Group (Reuters)

Ushering in the Next Frontier of Quantum Innovation (The White House) 

Meta Exposed Data Internally From Its Controversial Employee-Tracking Program (WIRED) 

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

LastPass says Klue breach affected customer information, but passwords remain secure. Attackers begin exploiting Cisco Unified CM vulnerability. CISA flags actively exploited Ubiquiti and Lantronix flaws, urges rapid patching. DifyTap flaws could expose private AI conversations across tenants. Researchers find AI plugin registry let unofficial tools masquerade as trusted software. xpl0itrs launches leak site, signaling shift toward full-service cyber extortion. Ransomware attack hits Indian auto giant Bajaj Auto. U.S. presses Meta to submit AI models for national security reviews. Alleged criminal marketplace administrator extradited to the US. U.S. expands sanctions against Cambodian scam network tied to cyber fraud operations. On today’s Industry Voices segment, we are joined by Mike Masciulli, Managing Director, Migration Products and Services at Semperis, discussing RC4 and AD Migration: The Break Scenarios Hiding in Your Source Domain. And a lesson in access control.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On today’s Industry Voices segment, we are joined by Mike Masciulli, Managing Director, Migration Products and Services at Semperis, discussing RC4 and AD Migration: The Break Scenarios Hiding in Your Source Domain. If you enjoyed this conversation, check out the full interview here.

Selected Reading

Password manager maker LastPass says hackers stole customer support case data during Klue breach (TechCrunch)

Klue says hackers stole credential from 2022 that led to customer data breaches (TechCrunch)

Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks (BleepingComputer)

U.S. CISA adds Ubiquiti UniFi OS and Lantronix EDS5000 plugin flaws to its Known Exploited Vulnerabilities catalog (SecurityAffairs) 

DifyTap: Zafran discovers how attackers can silently wiretap AI data across tenants on a platform powering 1M+ apps  (Zafran) 

23 ClawHub Plugins Squat Official Org Scopes (Manifold Security) 

Cyber Intel Brief: xpl0itrs Leak Site Launch (Dataminr) 

Indian auto giant Bajaj Auto hit by ransomware incident (The Record) 

U.S. Presses Meta to Agree to A.I. Reviews as Security Concerns Rise (NY Times)

Algerian Man Extradited to US for Running Cybercrime Marketplaces (SecurityWeek)

US adds sanctions against accused Cambodian scammers Prince Group (Reuters)

Ushering in the Next Frontier of Quantum Innovation (The White House) 

Meta Exposed Data Internally From Its Controversial Employee-Tracking Program (WIRED) 

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2026-06-23

All eyes on AI.

24 min
View

Five Eyes warns AI could supercharge cyberattacks within months. Tata Electronics confirms breach as stolen data allegedly includes Apple and Tesla documents. Researchers publish new analysis of FortiBleed. Gizmodo breach exposes readers to ClickFix malware campaign. BootROM exploit can bypass Apple's SecureROM. Scattered Spider members plead guilty in the UK. Attackers exploit Gravity SMTP flaw to harvest secrets From WordPress sites. Executive Order accelerates federal shift to post-quantum cryptography. Dave Bittner sits down with Ellen Boehm, the Senior Vice President of IoT Strategy & Operations at Keyfactor, to discuss NIST's progress in its PQC efforts. Keeping tabs on the tab-keepers.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today Dave Bittner sits down with Ellen Boehm, the Senior Vice President of IoT Strategy & Operations at Keyfactor, to discuss NIST's progress in its PQC efforts and where more effort needs to be made to get the U.S. and its critical infrastructure quantum-ready.

Selected Reading

'Five Eyes' intelligence alliance warns that new AI models pose urgent cyber risk (Reuters)

Intel agencies: Frontier AI models will reshape cybersecurity faster than expected (CyberScoop)

Anthropic's Mythos AI broke into almost all NSA classified systems in hours (SecurityAffairs) 

Tata Electronics, a major tech supplier to Apple and Tesla, confirms data breach (TechCrunch)

FortiBleed campaign used custom FortiGate sniffer to steal credentials (BleepingComputer)

Gizmodo readers hit with ClickFix malware prompts after account compromise (The Register)

New Exploit Bypasses Apple's Boot Defenses, Affects Millions of iPhones (SecurityWeek)

TFL Hackers Admit Carrying Out Cyberattack That Cost £39M (Law360)

Attackers Actively Exploiting Sensitive Information Exposure Vulnerability in Gravity SMTP Plugin (Wordfence) 

Trump Signs Executive Order Accelerating Post-Quantum Cryptography Migration (Security Week)

Madison Square Garden Made Dossier on Activists Who Opposed Facial Recognition (404 Media)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Five Eyes warns AI could supercharge cyberattacks within months. Tata Electronics confirms breach as stolen data allegedly includes Apple and Tesla documents. Researchers publish new analysis of FortiBleed. Gizmodo breach exposes readers to ClickFix malware campaign. BootROM exploit can bypass Apple's SecureROM. Scattered Spider members plead guilty in the UK. Attackers exploit Gravity SMTP flaw to harvest secrets From WordPress sites. Executive Order accelerates federal shift to post-quantum cryptography. Dave Bittner sits down with Ellen Boehm, the Senior Vice President of IoT Strategy & Operations at Keyfactor, to discuss NIST's progress in its PQC efforts. Keeping tabs on the tab-keepers.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today Dave Bittner sits down with Ellen Boehm, the Senior Vice President of IoT Strategy & Operations at Keyfactor, to discuss NIST's progress in its PQC efforts and where more effort needs to be made to get the U.S. and its critical infrastructure quantum-ready.

Selected Reading

'Five Eyes' intelligence alliance warns that new AI models pose urgent cyber risk (Reuters)

Intel agencies: Frontier AI models will reshape cybersecurity faster than expected (CyberScoop)

Anthropic's Mythos AI broke into almost all NSA classified systems in hours (SecurityAffairs) 

Tata Electronics, a major tech supplier to Apple and Tesla, confirms data breach (TechCrunch)

FortiBleed campaign used custom FortiGate sniffer to steal credentials (BleepingComputer)

Gizmodo readers hit with ClickFix malware prompts after account compromise (The Register)

New Exploit Bypasses Apple's Boot Defenses, Affects Millions of iPhones (SecurityWeek)

TFL Hackers Admit Carrying Out Cyberattack That Cost £39M (Law360)

Attackers Actively Exploiting Sensitive Information Exposure Vulnerability in Gravity SMTP Plugin (Wordfence) 

Trump Signs Executive Order Accelerating Post-Quantum Cryptography Migration (Security Week)

Madison Square Garden Made Dossier on Activists Who Opposed Facial Recognition (404 Media)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2026-06-22

The Klue is in the data trail.

29 min
View

Klue supply-chain attack impacts cybersecurity firms. Brand-new Prinz Eugen ransomware is surprisingly polished. ShinyHunters leak exposes sensitive data of 10,000 Council of Europe employees. Security agencies sound alarm over FortiBleed credential harvesting operation. Texas data breach affects hunting and fishing licensees. Microsoft ties Mastra AI supply chain attack to North Korean hackers. Vidar infostealer unveils new technique to defeat Chrome's encryption protections. Brazil investigates suspected hack of emergency alert system. We got your Monday business brief. On today’s Industry Voices, Dave Bittner sits down with Mike Britton, CIO of Abnormal AI, as they discuss "AI-Powered Attacks Are Now a Commodity.” And not the kind of beats you want to drop.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On today’s Industry Voices, we are joined by Mike Britton, CIO of Abnormal AI, discussing "AI-Powered Attacks Are Now a Commodity — And Most Organizations Don't Know It Yet." If you enjoyed this conversation and want to hear the full interview, listen here.

Selected Reading

Klue OAuth breach victim list grows as Icarus hackers claim attack (BleepingComputer)

Prinz Eugen ransomware: a deep dive into a new Go-based encryptor (ThreatDown)

Council of Europe Data Breach: ShinyHunters Makes 10,000 Employees' Records Permanent (Tech Times)

Global cybersecurity agencies warn of credential exposure in FortiBleed campaign targeting Fortinet firewalls, VPN gateways (Industrial Cyber)

Everything's bigger and better in Texas – even data breaches (The Register)

Microsoft links Mastra AI supply chain attack to North Korean hackers (BleepingComputer)

Inside Vidar’s ABE Bypass: From Memory Scanning to APC Injections (Gen Digital)

Brazil probes emergency warning system after nationwide rogue alert (The Register)

Ent emerges from stealth with $100 million in seed funding. (N2K Pro Business Briefing) 

Apple patches Beats Studio Buds flaw that could turn earbuds into a wiretap (Malwarebytes)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Klue supply-chain attack impacts cybersecurity firms. Brand-new Prinz Eugen ransomware is surprisingly polished. ShinyHunters leak exposes sensitive data of 10,000 Council of Europe employees. Security agencies sound alarm over FortiBleed credential harvesting operation. Texas data breach affects hunting and fishing licensees. Microsoft ties Mastra AI supply chain attack to North Korean hackers. Vidar infostealer unveils new technique to defeat Chrome's encryption protections. Brazil investigates suspected hack of emergency alert system. We got your Monday business brief. On today’s Industry Voices, Dave Bittner sits down with Mike Britton, CIO of Abnormal AI, as they discuss "AI-Powered Attacks Are Now a Commodity.” And not the kind of beats you want to drop.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On today’s Industry Voices, we are joined by Mike Britton, CIO of Abnormal AI, discussing "AI-Powered Attacks Are Now a Commodity — And Most Organizations Don't Know It Yet." If you enjoyed this conversation and want to hear the full interview, listen here.

Selected Reading

Klue OAuth breach victim list grows as Icarus hackers claim attack (BleepingComputer)

Prinz Eugen ransomware: a deep dive into a new Go-based encryptor (ThreatDown)

Council of Europe Data Breach: ShinyHunters Makes 10,000 Employees' Records Permanent (Tech Times)

Global cybersecurity agencies warn of credential exposure in FortiBleed campaign targeting Fortinet firewalls, VPN gateways (Industrial Cyber)

Everything's bigger and better in Texas – even data breaches (The Register)

Microsoft links Mastra AI supply chain attack to North Korean hackers (BleepingComputer)

Inside Vidar’s ABE Bypass: From Memory Scanning to APC Injections (Gen Digital)

Brazil probes emergency warning system after nationwide rogue alert (The Register)

Ent emerges from stealth with $100 million in seed funding. (N2K Pro Business Briefing) 

Apple patches Beats Studio Buds flaw that could turn earbuds into a wiretap (Malwarebytes)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere

Traditionally, GPS jamming attacks have been confined to the ground; however, new data shows that these attacks could be moving to target signals before they even reach the ground.

In this week’s episode, host Maria Varmazis sits down with Dave Bittner and Brandon Karpf to discuss recent research that suggests the attack landscape for GPS attacks is expanding. If this research is accurate, these attacks represent a significant evolution for how defenders think about this critical technology.

Key sources:

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space 

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P 

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.

More description

Traditionally, GPS jamming attacks have been confined to the ground; however, new data shows that these attacks could be moving to target signals before they even reach the ground.

In this week’s episode, host Maria Varmazis sits down with Dave Bittner and Brandon Karpf to discuss recent research that suggests the attack landscape for GPS attacks is expanding. If this research is accurate, these attacks represent a significant evolution for how defenders think about this critical technology.

Key sources:

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space 

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P 

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.

Extract Knowledge
Listen elsewhere

For years, security teams had time between discovery and exploitation. Time to triage. Time to validate. Time to prioritize what to fix first. AI has compressed that window. Frontier models now discover and chain vulnerabilities faster than human analysts can confirm them, and the gap between finding and fixing is shrinking in both directions.

In this episode of CyberWire-X, N2K’s ⁠Dave Bittner⁠ and Federico Kirschbaum, Head of XBOW Security Lab, explore what it actually means to run autonomous offensive security, why validation workflows built for quarterly testing cycles struggle to keep up, and how practitioners are redefining what a tested application looks like when the pace of offense has fundamentally changed.

More description

For years, security teams had time between discovery and exploitation. Time to triage. Time to validate. Time to prioritize what to fix first. AI has compressed that window. Frontier models now discover and chain vulnerabilities faster than human analysts can confirm them, and the gap between finding and fixing is shrinking in both directions.

In this episode of CyberWire-X, N2K’s ⁠Dave Bittner⁠ and Federico Kirschbaum, Head of XBOW Security Lab, explore what it actually means to run autonomous offensive security, why validation workflows built for quarterly testing cycles struggle to keep up, and how practitioners are redefining what a tested application looks like when the pace of offense has fundamentally changed.

Extract Knowledge
Listen elsewhere

This week, we are joined by Tom Kellermann, Trend Micro's VP of AI Security and Threat Research, discussing their work on "Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud." Researchers from Trend Micro's MDR team uncovered the full operation behind Banana RAT, a sophisticated banking trojan they track as SHADOW-WATER-063, by analyzing both attacker infrastructure and infected victim systems.

The malware uses fileless PowerShell execution, layered obfuscation, and remote-control capabilities to steal credentials, manipulate banking sessions, intercept Pix QR code payments, and facilitate financial fraud targeting Brazilian banks. The campaign appears to be operated by a Brazilian Portuguese-speaking cybercriminal group with ties to the broader Tetrade banking malware ecosystem and may be evolving toward a malware-as-a-service model.

The research and executive brief can be found here:

More description

This week, we are joined by Tom Kellermann, Trend Micro's VP of AI Security and Threat Research, discussing their work on "Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud." Researchers from Trend Micro's MDR team uncovered the full operation behind Banana RAT, a sophisticated banking trojan they track as SHADOW-WATER-063, by analyzing both attacker infrastructure and infected victim systems.

The malware uses fileless PowerShell execution, layered obfuscation, and remote-control capabilities to steal credentials, manipulate banking sessions, intercept Pix QR code payments, and facilitate financial fraud targeting Brazilian banks. The campaign appears to be operated by a Brazilian Portuguese-speaking cybercriminal group with ties to the broader Tetrade banking malware ecosystem and may be evolving toward a malware-as-a-service model.

The research and executive brief can be found here:

Extract Knowledge
Listen elsewhere

In this special edition of CyberWire Daily’s 10th anniversary series, N2K CyberWire's Maria Varmazis and Dave Bittner discuss leaks, espionage and influence operations over the past 10 years.

Together they reflect on a decade of cybersecurity developments, focusing on the pivotal year 2016 where a shift occurred.

Join N2K as we cover the rise of nation-state cyber operations, major leaks like the Panama Papers and DNC email hacks, and the evolving landscape of cyber norms, trust, and threat perception.

More description

In this special edition of CyberWire Daily’s 10th anniversary series, N2K CyberWire's Maria Varmazis and Dave Bittner discuss leaks, espionage and influence operations over the past 10 years.

Together they reflect on a decade of cybersecurity developments, focusing on the pivotal year 2016 where a shift occurred.

Join N2K as we cover the rise of nation-state cyber operations, major leaks like the Panama Papers and DNC email hacks, and the evolving landscape of cyber norms, trust, and threat perception.

Extract Knowledge
Listen elsewhere
Published 2026-06-18

The botnet browser blues.

25 min
View

International law enforcement disrupts the SocGholish botnet. The UK’s cyber chief says cybersecurity is a contest, not a risk register. Ukraine joins the EU’s cyber reserve. The Gentlemen gang sharpens its ransomware toolkit. A WordPress supply chain attack spreads malware. Critical patches land from F5, Atlassian, and Splunk. Agentjacking targets AI coding assistants. And Kodak confirms a breach claimed by ShinyHunters. Our guest is Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies on the failure of FISA section 702 to reauthorize. Criminal coders face automation anxiety.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies, and coh-host of Caveat, as he discusses the failure of FISA section 702 to reauthorize.

Selected Reading

Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp (Bleeping Computer)

Hostile States Behind 75% of Cyber-Attacks on UK CNI, NCSC Warns (Infosecurity Magazine)

Cyberspace Locked in a Nation-State Contest, Says NCSC CEO (BankInfo Security)

EU grants Ukraine access to cybersecurity reserve for major attacks (The Record)

Killing me gently: Inside Gentlemen’s EDR killer framework (ESET)

ShapedPlugin update flow hacked to infect WordPress sites (Bleeping Computer)

F5 issues out-of-band patches for critical NGINX vulnerabilities (Bleeping Computer)

Atlassian, Splunk Patch Critical Vulnerabilities (SecurityWeek)

Agentjacking: Researchers Show How One Fake Bug Report Can Hijack AI Coding Agents (HackRead)

Kodak Admits Data Breach After ShinyHunters Hack Claims (SecurityWeek)

Cybercriminals Are Worried About AI Taking Their Jobs Too (Infosecurity Magazine)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

International law enforcement disrupts the SocGholish botnet. The UK’s cyber chief says cybersecurity is a contest, not a risk register. Ukraine joins the EU’s cyber reserve. The Gentlemen gang sharpens its ransomware toolkit. A WordPress supply chain attack spreads malware. Critical patches land from F5, Atlassian, and Splunk. Agentjacking targets AI coding assistants. And Kodak confirms a breach claimed by ShinyHunters. Our guest is Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies on the failure of FISA section 702 to reauthorize. Criminal coders face automation anxiety.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies, and coh-host of Caveat, as he discusses the failure of FISA section 702 to reauthorize.

Selected Reading

Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp (Bleeping Computer)

Hostile States Behind 75% of Cyber-Attacks on UK CNI, NCSC Warns (Infosecurity Magazine)

Cyberspace Locked in a Nation-State Contest, Says NCSC CEO (BankInfo Security)

EU grants Ukraine access to cybersecurity reserve for major attacks (The Record)

Killing me gently: Inside Gentlemen’s EDR killer framework (ESET)

ShapedPlugin update flow hacked to infect WordPress sites (Bleeping Computer)

F5 issues out-of-band patches for critical NGINX vulnerabilities (Bleeping Computer)

Atlassian, Splunk Patch Critical Vulnerabilities (SecurityWeek)

Agentjacking: Researchers Show How One Fake Bug Report Can Hijack AI Coding Agents (HackRead)

Kodak Admits Data Breach After ShinyHunters Hack Claims (SecurityWeek)

Cybercriminals Are Worried About AI Taking Their Jobs Too (Infosecurity Magazine)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2026-06-17

The nominee in limbo.

31 min
View

President Trump halts a key intelligence nomination. The FBI warns of a new Microsoft 365 phishing threat. France cuts ties with Palantir. A new Android banking trojan emerges. Fortinet firewalls come under attack. CISA orders emergency Joomla patching. Plus, Madison Square Garden data leaks and malware hidden in Steam wallpapers. Our guest is Christy Wyatt, CEO from Absolute Security, discussing their new ebook. The DOJ claims pollution is mission-critical. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today’s Industry Voices we are joined by Christy Wyatt, CEO from Absolute Security, discussing their ebook. If you enjoyed this conversation, check out the full interview here.

Selected Reading

President Trump calls to delay nomination of intel pick Jay Clayton (NPR)

Warner warns of CISA cuts, staffing gaps in letter to acting chief (The Record)

French spies drop AI giant Palantir over US overreliance fears (The Local)

Rokarolla : Android Banker with Complete Device Takeover Capabilities (Zimperium)

FortiBleed: 75,000 Fortinet Firewalls Compromised: Global Enterprises Exposed – Claim Your Ethical Disclosure (InfoStealers)

CISA orders feds to patch max severity Joomla plugin flaw by Friday (Bleeping Computer)

Hackers Publish Knicks and Madison Square Garden Data Online (404 Media)

Gamers beware: malicious wallpapers on Steam found stealing accounts (Securelist)

DHS S&T Highlights New SPARTA Resources for Defending Spacecraft Against Cyberattacks (ExecutiveGov)

DOJ Lawyers Argue xAI Is ‘Vital’ for National Security in NAACP Lawsuit (WIRED)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

President Trump halts a key intelligence nomination. The FBI warns of a new Microsoft 365 phishing threat. France cuts ties with Palantir. A new Android banking trojan emerges. Fortinet firewalls come under attack. CISA orders emergency Joomla patching. Plus, Madison Square Garden data leaks and malware hidden in Steam wallpapers. Our guest is Christy Wyatt, CEO from Absolute Security, discussing their new ebook. The DOJ claims pollution is mission-critical. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today’s Industry Voices we are joined by Christy Wyatt, CEO from Absolute Security, discussing their ebook. If you enjoyed this conversation, check out the full interview here.

Selected Reading

President Trump calls to delay nomination of intel pick Jay Clayton (NPR)

Warner warns of CISA cuts, staffing gaps in letter to acting chief (The Record)

French spies drop AI giant Palantir over US overreliance fears (The Local)

Rokarolla : Android Banker with Complete Device Takeover Capabilities (Zimperium)

FortiBleed: 75,000 Fortinet Firewalls Compromised: Global Enterprises Exposed – Claim Your Ethical Disclosure (InfoStealers)

CISA orders feds to patch max severity Joomla plugin flaw by Friday (Bleeping Computer)

Hackers Publish Knicks and Madison Square Garden Data Online (404 Media)

Gamers beware: malicious wallpapers on Steam found stealing accounts (Securelist)

DHS S&T Highlights New SPARTA Resources for Defending Spacecraft Against Cyberattacks (ExecutiveGov)

DOJ Lawyers Argue xAI Is ‘Vital’ for National Security in NAACP Lawsuit (WIRED)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2026-06-16

No Mythos of escape.

31 min
View

Emergency talks fail to free Anthropic’s Fable 5. Trump moves to strengthen national security systems. Microsoft patches a critical Copilot flaw. ShinyHunters weaponize a PeopleSoft zero-day. DragonForce hides in Microsoft Teams for months. Plus, Amos Stealer targets Macs, CISA issues a three-day patch deadline, Delta avoids penalties, and researchers show just how easy it is to manipulate AI search. Our guest is Mike Fey, Co-Founder & CEO at Island, discussing the architectural differences between network and modern SASE. Consulting meets confabulation.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On today’s Industry Voices, we are joined by Mike Fey, Co-Founder & CEO at Island, discussing the architectural differences between network and modern SASE. If you enjoyed this conversation, check out the full interview here

Selected Reading

Anthropic Is Still at Odds With the White House Over Claude Fable 5 (WIRED)

Feds freaked over Fable 5 after simple 'fix this code' prompt, not jailbreak, says researcher (The Register)

White House Issues Memo to Bolster NSS Cybersecurity (SecurityWeek)

Microsoft Patches Critical SearchLeak Vulnerability in Copilot Enterprise (Beyond Machines)

ShinyHunters Hits Universities Via Oracle Zero-Day (GovInfo Security)

DragonForce Ransomware Exploited Microsoft Teams to Hide Attack (Infosecurity Magazine)

Inside Amos Stealer: How This Threat Targets macOS Credentials and Keychains (CyberProof)

CISA warns of another cPanel plugin flaw exploited in attacks (Bleeping Computer)

US closes probe into 2024 Delta Air Lines meltdown sparked by CrowdStrike outage (Reuters)

It Is Trivially Easy to Use Reddit to Manipulate AI Search, Research Suggests (404 Media)

KPMG pulls report on AI usage due to apparent hallucinations (TechCrunch)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Emergency talks fail to free Anthropic’s Fable 5. Trump moves to strengthen national security systems. Microsoft patches a critical Copilot flaw. ShinyHunters weaponize a PeopleSoft zero-day. DragonForce hides in Microsoft Teams for months. Plus, Amos Stealer targets Macs, CISA issues a three-day patch deadline, Delta avoids penalties, and researchers show just how easy it is to manipulate AI search. Our guest is Mike Fey, Co-Founder & CEO at Island, discussing the architectural differences between network and modern SASE. Consulting meets confabulation.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

On today’s Industry Voices, we are joined by Mike Fey, Co-Founder & CEO at Island, discussing the architectural differences between network and modern SASE. If you enjoyed this conversation, check out the full interview here

Selected Reading

Anthropic Is Still at Odds With the White House Over Claude Fable 5 (WIRED)

Feds freaked over Fable 5 after simple 'fix this code' prompt, not jailbreak, says researcher (The Register)

White House Issues Memo to Bolster NSS Cybersecurity (SecurityWeek)

Microsoft Patches Critical SearchLeak Vulnerability in Copilot Enterprise (Beyond Machines)

ShinyHunters Hits Universities Via Oracle Zero-Day (GovInfo Security)

DragonForce Ransomware Exploited Microsoft Teams to Hide Attack (Infosecurity Magazine)

Inside Amos Stealer: How This Threat Targets macOS Credentials and Keychains (CyberProof)

CISA warns of another cPanel plugin flaw exploited in attacks (Bleeping Computer)

US closes probe into 2024 Delta Air Lines meltdown sparked by CrowdStrike outage (Reuters)

It Is Trivially Easy to Use Reddit to Manipulate AI Search, Research Suggests (404 Media)

KPMG pulls report on AI usage due to apparent hallucinations (TechCrunch)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2026-06-15

The fable ends before it begins.

29 min
View

Anthropic pulls Fable 5. OpenAI faces a multistate probe. Handala targets a California water utility. ShinyHunters claims another victim. The FBI and Google take down a major phishing platform. The latest cybersecurity business news. Our guest is Bogdan Botezatu,  Senior Director, Threat Research and Reporting at Bitdefender, discussing a rampant global transportation smishing campaign. A deepfake detective has doubts. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today, Bogdan Botezatu,  Senior Director, Threat Research and Reporting at Bitdefender, is discussing a rampant global transportation smishing campaign. You can read more about Operation Road Trap here.

Selected Reading

Anthropic disables access to Fable 5 and Mythos 5 to comply with government directive (CNBC)

Cyber leaders defend Anthropic's banned model (Axios)

State Attorneys General Are Investigating OpenAI (The New York Times)

Handala Hacking Group Claims Breach of California Water Service (Hackread)

Maine Takes Breach Reporting Portal Offline After Fake Entries (Infosecurity Magazine)

Warner introduces bill to restore MS-ISAC funding, bolster critical infrastructure cyber defense (Industry Cyber)

Infinite Campus data breach affects 137,000 school staff accounts (Bleeping Computer)

FBI, Google Dismantle 'Outsider Enterprise' Phishing Service (SecurityWeek)

Ex-school district employee jailed for hacks on former employer (Bleeping Computer)

Cyera raises $600 million in a Series G round led by Evolution Equity Partners. (N2K Pro Business Briefing)

In Age of AI, World’s Leading Deepfake Expert No Longer Trusts His Own Eyes (The New York Times)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

More description

Anthropic pulls Fable 5. OpenAI faces a multistate probe. Handala targets a California water utility. ShinyHunters claims another victim. The FBI and Google take down a major phishing platform. The latest cybersecurity business news. Our guest is Bogdan Botezatu,  Senior Director, Threat Research and Reporting at Bitdefender, discussing a rampant global transportation smishing campaign. A deepfake detective has doubts. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Today, Bogdan Botezatu,  Senior Director, Threat Research and Reporting at Bitdefender, is discussing a rampant global transportation smishing campaign. You can read more about Operation Road Trap here.

Selected Reading

Anthropic disables access to Fable 5 and Mythos 5 to comply with government directive (CNBC)

Cyber leaders defend Anthropic's banned model (Axios)

State Attorneys General Are Investigating OpenAI (The New York Times)

Handala Hacking Group Claims Breach of California Water Service (Hackread)

Maine Takes Breach Reporting Portal Offline After Fake Entries (Infosecurity Magazine)

Warner introduces bill to restore MS-ISAC funding, bolster critical infrastructure cyber defense (Industry Cyber)

Infinite Campus data breach affects 137,000 school staff accounts (Bleeping Computer)

FBI, Google Dismantle 'Outsider Enterprise' Phishing Service (SecurityWeek)

Ex-school district employee jailed for hacks on former employer (Bleeping Computer)

Cyera raises $600 million in a Series G round led by Evolution Equity Partners. (N2K Pro Business Briefing)

In Age of AI, World’s Leading Deepfake Expert No Longer Trusts His Own Eyes (The New York Times)

Share your feedback.

What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.

Want to hear your company in the show?

N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Extract Knowledge
Listen elsewhere

For years, space cybersecurity has been a long sought after goal, but due to operational constraints, it was largely unfeasible.

In this week’s episode, host Maria Varmazis sits down with journalist Shaun Waterman to discuss his recent article “The Newest Space Race is Cyber.” As space has increasingly become a critical infrastructure component, industry leaders and security agencies alike have begun to launch new initiatives to improve capabilities both on the ground and in orbit.

Key sources:

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: ⁠https://thecyberwire.com/newsletters/signals-and-space⁠ 

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to ⁠space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: ⁠https://www.surveymonkey.com/r/NJYCN2P⁠ 

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. ⁠N2K⁠ is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.

More description

For years, space cybersecurity has been a long sought after goal, but due to operational constraints, it was largely unfeasible.

In this week’s episode, host Maria Varmazis sits down with journalist Shaun Waterman to discuss his recent article “The Newest Space Race is Cyber.” As space has increasingly become a critical infrastructure component, industry leaders and security agencies alike have begun to launch new initiatives to improve capabilities both on the ground and in orbit.

Key sources:

Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: ⁠https://thecyberwire.com/newsletters/signals-and-space⁠ 

Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to ⁠space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: ⁠https://www.surveymonkey.com/r/NJYCN2P⁠ 

T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. ⁠N2K⁠ is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.

Extract Knowledge
Listen elsewhere

In large enterprise software companies, vulnerability management teams are facing unprecedented speed and scale as AI accelerates both discovery and exploitation of security issues. In this episode of CyberWire-X, N2K’s Dave Bittner is joined by Adobe’s Daniel Ventura, Senior Manager of the Vulnerability Operations Center, and Sangeeta Arora, Director of Vulnerability Management, to discuss how Adobe is evolving its vulnerability management strategy to keep pace with AI-driven threats. They share real world insights on prioritization, crossteam partnership, and how modern programs can balance speed with meaningful risk reduction.

More description

In large enterprise software companies, vulnerability management teams are facing unprecedented speed and scale as AI accelerates both discovery and exploitation of security issues. In this episode of CyberWire-X, N2K’s Dave Bittner is joined by Adobe’s Daniel Ventura, Senior Manager of the Vulnerability Operations Center, and Sangeeta Arora, Director of Vulnerability Management, to discuss how Adobe is evolving its vulnerability management strategy to keep pace with AI-driven threats. They share real world insights on prioritization, crossteam partnership, and how modern programs can balance speed with meaningful risk reduction.

Extract Knowledge
Listen elsewhere

Martin Zugec, Technical Solutions Director at Bitdefender, discussing their work on "FamousSparrow APT Targets Azerbaijani Oil and Gas Industry." Bitdefender researchers uncovered a sustained cyber espionage campaign by the China-linked FamousSparrow group targeting an Azerbaijani oil and gas company, highlighting the growing focus on critical energy infrastructure in the South Caucasus. The attackers repeatedly exploited the same vulnerable Microsoft Exchange server over multiple months, deploying evolving versions of Deed RAT and Terndoor malware through sophisticated DLL sideloading techniques designed to evade detection and maintain persistence. The operation underscores FamousSparrow's adaptability and persistence, demonstrating how advanced threat actors continually refine their tooling and return to compromised environments until vulnerabilities are fully remediated and access is cut off.

The research and executive brief can be found here:

More description

Martin Zugec, Technical Solutions Director at Bitdefender, discussing their work on "FamousSparrow APT Targets Azerbaijani Oil and Gas Industry." Bitdefender researchers uncovered a sustained cyber espionage campaign by the China-linked FamousSparrow group targeting an Azerbaijani oil and gas company, highlighting the growing focus on critical energy infrastructure in the South Caucasus. The attackers repeatedly exploited the same vulnerable Microsoft Exchange server over multiple months, deploying evolving versions of Deed RAT and Terndoor malware through sophisticated DLL sideloading techniques designed to evade detection and maintain persistence. The operation underscores FamousSparrow's adaptability and persistence, demonstrating how advanced threat actors continually refine their tooling and return to compromised environments until vulnerabilities are fully remediated and access is cut off.

The research and executive brief can be found here:

Extract Knowledge
Listen elsewhere
Show details
Episodes
3784
Transcripts
67
2% coverage
Missing transcripts
3717
With chapters
0