Skip to content
Artwork for CyberWire Daily
NewsDaily NewsTech NewsTechnology

CyberWire Daily

N2K Networks

The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

Play
  • 51 episodes
  • daily
  • Avg 27 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • S10 · E438
    August 22 · 29 min

    A RAT in the spreadsheet. [Research Saturday]

    Today we are joined by Aaron Beardslee, Manager of Threat Research at Securonix, discussing "Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation." Securonix researchers have identified an evolved version of the SHEETCREEP espionage campaign, using a diplomatic-themed ISO phishing lure to deliver a C# remote access trojan targeting Indian diplomatic interests. The malware abuses the Google Sheets API as a stealthy command-and-control channel, with researchers identifying 91 active victim tabs, including a high-confidence target in Pakistan. The campaign, assessed with moderate confidence as linked to Pakistan-aligned APT36, has added XOR-obfuscated configurations and other anti-analysis techniques to evade detection and maintain persistent access. The research and executive brief can be found here: ⁠Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation

  • S11 · E2620
    August 21 · 31 min

    The guest nobody invited.

    CISA orders patching of TrueConf Server vulnerabilities. LockBit threatens release of stolen banking data. Researchers disclose a critical type confusion vulnerability in a Node.js library. A new Agent Tesla v4 campaign introduces enhanced evasion techniques. A novel malware delivery technique abuses FTP server banners to hide commands. Apple patches a critical image-processing flaw. A North Korean software supply chain attack targets the Rust ecosystem. Latvian officials resign following a major data breach. Defense contractors are confident in compliance, less so in their ability to prove it. Our guest is Patrick Coughlin, Co-Founder and CEO of Savi Security. discussing the free utility he’s developed to protect the sandwich generation from AI-driven scams. When it comes to cyber extortion, who you gonna call? Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Joining us today is Patrick Coughlin, Co-Founder and CEO of Savi Security. Patrick discusses protecting the sandwich generation from AI-driven scams and Scamwise, their free utility built with this purpose in mind. Learn more about Scamwise, a free public utility tool to help consumers quickly determine whether a suspicious message, call, or email is likely a scam, and download Savi’s app. Selected Reading CISA orders feds to patch actively exploited TrueConf Server flaws (Bleeping Computer) US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline (The Register) Critical Isolated-vm Vulnerability Leads to RCE on Host (SecurityWeek) New Agent Tesla Malware Variant Boosts Evasion Capabilities (Infosecurity Magazine) Hackers abuse FTP server banners to deliver new Windows malware (Bleeping Computer) Apple plugs image-processing hole ripe for spyware abuse (The Register) North Korean Hackers Tied to Rust Supply Chain Attack (Infosecurity Magazine) Latvian officials resign after cyberattack exposes data on 1.2 million people (The Record) Contractors' CMMC Confidence Rises as Ability to Prove It Falls Behind (SecurityWeek) Ransomware crook poses as recovery firm to steal payments from fellow extortionists (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  • S11 · E2619
    August 20 · 31 min

    The robots have gone bananas.

    Federal agencies warn of an active campaign targeting critical infrastructure. Citrix races to patch critical NetScaler flaws. More than 50,000 exposed Stripe API keys raise fraud concerns. Black Hat and DEF CON attendees are targeted in a new social engineering campaign. Atlassian, Splunk, and Cisco fix hundreds of vulnerabilities. A new Android banking trojan adds an unusual twist. A healthcare breach impacts 3.8 million people. SilkParasite expands cyberespionage in Central Asia. And CISA eyes a major overhaul of federal cyber software procurement. Our guest is Chris Wallis, founder and CEO of Intruder, on how AI agents killed the annual pentest and are reshaping exposure management. AI powered robots find bananas quite appealing. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On our Industry Voices segment, Intruder’s Founder and CEO Chris Wallis joined Dave at Black Hat to discuss why the annual pentest Is dead and how AI agents are reshaping exposure management. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology (The Record) Citrix urges admins to patch new NetScaler flaws as soon as possible (Bleeping Computer) 50,000 Stripe Secrets Leaked in Public Code (SecurityAffairs) Black Hat/DEF CON attendees targeted in malware scheme with Google Doc lure (SC World) Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities (SecurityWeek) Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities (SecurityWeek) New Manic Android malware can exfiltrate data through nearby devices (Bleeping Computer) EHR Vendor Notifying 3.8 Million Patients of Data Theft Hack (GovInfo Security) SilkParasite: Tracking a China-Nexus APT Across Central Asia (Bitdefender) CISA contemplates whether to hire security software buying help (Washington Technology) I Saw the Future of AI in a Robot That Can Learn on the Spot (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  • S11 · E2618
    August 19 · 28 min

    Hackers hiding in plain sight.

    Medusa’s reach grows. Cl0p expands its victim list. The DOJ charges 17 alleged Iranian hackers. CISA sounds the alarm on four exploited vulnerabilities. TWINLOOT hides in plain sight inside Microsoft 365. Maria Varmazis shares the latest from the space-cyber realm as Ukraine strikes Russia’s satellite nerve center. The FDA considers guardrails for AI medical devices. Expired credit cards get an unexpected second life. A disgruntled contractor heads to prison. Dave Bittner sits down with Brian Vecci, Field CTO at Varonis, at Black Hat USA to discuss how AI is calling your security bluff. Highway hijinks meet high-tech hardware. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest At Black Hat USA, Dave Bittner sat down with Brian Vecci, Field CTO at Varonis, as they discussed how AI is calling your security bluff. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading CISA: Medusa ransomware hit over 500 critical infrastructure orgs (Bleeping Computer) US charges Iranians for sprawling hacking campaign on government agencies, universities (The Record) Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign (SecurityWeek) CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities (SecurityWeek) New TWINLOOT Malware Steals Windows Passwords Via Fake Lock Screen (Hackread) Ukraine says it hit Russian rocket centre linked to Starlink-style network (CNBC) FDA Weighing Possible Regs for GenAI Medical Devices (GovInfo Security) Expired credit cards revived by researchers to make unauthorized payments (The Register) Prison for data analyst who tried to extort $2.5 million from his employer (Bitdefender) ‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI Hardware (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  • S11 · E2617
    August 18 · 28 min

    Fake it till you exfiltrate it.

    A fake consultancy fronts an alleged Chinese spy campaign. Meta heads to court over claims it hooked young users. Researchers crack the mystery behind the French EncroChat hack. CISA warns ransomware gangs are exploiting a Windows flaw. Meet C2Looper, a new Rust-based backdoor. A critical WordPress plugin bug threatens hundreds of thousands of sites. MessiahGPT brings generative AI to cybercrime. A lender discloses a breach affecting 1.2 million people. A Ukrainian developer stands trial in Switzerland over alleged ransomware ties. Our guest is Ev Kontsevoy, CEO at Teleport, discussing how AI agents have nondeterministic behavior. The psychology of the endless scroll. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today’s Industry Voices, we are joined by Ev Kontsevoy, CEO at Teleport, discussing how AI agents have nondeterministic behavior. If you enjoyed this conversation, check out the full interview here. Selected Reading A fake website and a deluge of CVs: the Australian firm embroiled in an FBI probe into alleged Chinese espionage (The Guardian) States Seek $200 Billion From Meta Over Child Social Media Addiction Claims (The New York Times) Revealed: Cyber spies used malware from GitHub to hack EncroChat cryptophone network (Computer Weekly) CISA: Windows Task Host flaw now exploited by ransomware gangs (Bleeping Computer) C2Looper Backdoor Uses GitHub for C2 (ThreatLabz) 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw (SecurityWeek) MessiahGPT Criminal AI Service Advertised on BreachForums (HackRead) Heights Finance Data Breach Impacts at Least 1.2 Million Individuals (SecurityWeek) Ukrainian software developer faces 12 years in Swiss ransomware trial (The Record from Recorded Future News) Why Can't We Stop Scrolling? (Psychology Today) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  • S11 · E2616
    August 17 · 28 min

    Please hold while we decide.

    Internal policy conflicts hamper U.S. military AI leadership. Clop claims GE, Philips and Shell. Attackers actively probe internet-facing GeoServer instances. “The Hatman” offers millions of alleged employee records for sale. ETSI begins the approval process for European cyber standards. Microsoft is still working on a patch for the ShieldBreak vulnerability. Autonomous AI systems create CPU bottlenecks. Monday business briefing. Our guest is Nick Warner, CEO at Neo.ai, on the shifting landscape around AI and agentic security. AI agents kneecap each other with self-replicating malware. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today’s Industry Voices segment, we are joined by Nick Warner, Neo.ai's CEO, discussing the shifting landscape around AI and agentic security. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading The U.S. Military Wants A.I. Dominance. Feuds and China May Thwart It. (The New York Times) Philips and GE investigating Clop ransomware data theft claims (Bleeping Computer) Attackers Probe Critical GeoServer SQL Injection Vulnerability (Hack Read) Crook hawks millions of records allegedly plundered from corporate Azure tenants (The Register) ETSI Proposes 17 Cybersecurity Standards to Support EU CRA (Infosecurity Magazine) Microsoft working on Defender patch for ShieldBreak zero-day (Bleeping Computer) Agentic AI Crunch Creates CPU Comeback (IEEE Spectrum) Corma raises $60 million in seed funding. (N2K) Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware (SecurityWeek) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  • S11 · E103
    August 16 · 28 min

    Frontier models and the future of cyber defense. [Special Edition]

    In this special edition from Black Hat, Dave Bittner sits down with ⁠Clint Gibler⁠, Cyber Lead at ⁠OpenAI⁠, and ⁠Robby Winchester⁠, Chief Global Professional Services Officer at ⁠SpecterOps⁠, to explore how frontier AI models are changing the way defenders approach cybersecurity. The conversation moves beyond the hype to examine responsible AI deployment, AI red teaming, reducing noise in security workflows, and the balance between advanced models and human expertise. They also discuss OpenAI’s Trusted Access for Cyber program and what it takes to give security practitioners access to powerful AI capabilities while managing the risks of misuse. Check out the full video here.

  • S2 · E720
    August 16 · 21 min

    AI, misinformation, and the future of cybersecurity. [T-Minus: Space-Cyber Briefing]

    As AI products proliferate, they continue to introduce new concerns, which have subtly eroded trust in imagery and content created by space-based infrastructure. In this week's episode, host Maria Varmazis sits down with ⁠⁠⁠Dave Bittner and Brandon Karpf to look at Google's troubled implementation of Nano Banana 2 in Google Earth. The incident raises larger concerns regarding how AI systems are becoming deeper ingrained into everyday life despite their ability to be misused and spread misinformation. Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: ⁠⁠https://thecyberwire.com/newsletters/signals-and-space⁠⁠ Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to ⁠⁠space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: ⁠⁠https://www.surveymonkey.com/r/NJYCN2P ⁠⁠ T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. ⁠⁠N2K⁠⁠ is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at ⁠⁠n2k.com⁠⁠.

  • S10 · E436
    August 15 · 27 min

    The botnet that scouts before it strikes. [Research Saturday]

    Today we are joined by Ian Goldin, Senior Lead Information Security Engineer, and Mike Horka, Principal Information Security Engineer, from Lumen's Black Lotus Labs, discussing their research entitled "Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation." Black Lotus Labs has uncovered a major resurgence of the JDY botnet, a China-nexus reconnaissance network now comprising more than 1,500 compromised SOHO and IoT devices. The botnet uses these devices to conduct targeted scanning and fingerprinting, helping threat actors rapidly identify vulnerable infrastructure—sometimes within hours of a new vulnerability disclosure—and appears to have a particular focus on U.S. military-related networks. The research highlights how compromised routers and IoT devices can be turned into distributed reconnaissance infrastructure that evades traditional IP-based defenses and supports follow-on exploitation. The research and executive brief can be found here: Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation

  • S11 · E2615
    August 14 · 22 min

    Apple has a message for you.

    Apple sends out threat notifications to users targeted by spyware. Trivy, not LiteLLM, was the original source of the 2,500-organization supply chain attack. French tax authority confirms data breach. Chinese hack-for-hire group conducts espionage and cybercrime simultaneously. Ukrainian police shut down 94 scam call centers. Former data analyst jailed for insider extortion plot. New macOS malware spreads via ClickFix. Today we are joined by Tom Kellermann, VP of AI Security at TrendAI, discussing the machine-speed war for financial control. And the glitch in the surveillance matrix. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tom Kellermann, VP of AI Security at TrendAI, discussing the machine-speed war for financial control. If you want to learn more on this topic, check out the article here. You can also check out Tom on the AI Security Brief here. Selected Reading If Apple sends you a push notification alerting you to a spyware attack, take it seriously (TechCrunch) Trivy, Not LiteLLM Behind the 2,500 Org Compromise (SecurityWeek) France investigates tax authority breach after hacker claims 600,000 victims (The Record) Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side (Symantec) AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers (Jamf) Ukraine shuts down 94 fraudulent call centers, seize millions in cash (BleepingComputer) This 'adversarial' pattern can prevent surveillance cameras from detecting you (TechCrunch) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  • S11 · E2614
    August 13 · 24 min

    Please hack responsibly.

    President Trump deputizes private-sector companies to target cybercriminals. The LiteLLM supply-chain attack exposed credentials belonging to thousands of organizations. Data-theft campaign targets misconfigured Salesforce and ServiceNow instances. Hackers deploy AI agents to breach Taiwanese government systems. CISA mandates urgent patch for actively exploited Cisco firewall vulnerability. Nightmare Eclipse publishes yet another Windows zero-day exploit. On our Industry Voices segment, Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps, discuss frontier models and the future of cyber defense. And please do not reply. Seriously. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices segment, Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps, speak with Dave Bittner at Black Hat about frontier models and the future of cyber defense, including responsible AI deployment, red teaming, reducing security noise, and the evolving role of human expertise in AI-assisted defense. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading Trump turns to private sector in offensive hacking operations memo (CyberScoop) Terabytes of credentials leaked in massive supply-chain attack (Ars Technica) "City-Forum" data-theft attacks target Salesforce, ServiceNow portals (BleepingComputer) 'Near-autonomous' AI agents attack Taiwan's nuclear safety agency (The Register) Cisco says software vulnerability could let hackers crash firewalls (Cybersecurity Dive) Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows (The Register) Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  • S11 · E2613
    August 12 · 26 min

    A flurry of fixes.

    We got your Patch Tuesday notes. Attackers target Microsoft SharePoint vulnerability following PoC release. Cyberattack on CEVA Logistics causes ongoing supply chain disruptions. Wesco confirms data breach following extortion claims. Akira ransomware bypasses EDR in Safe Mode. California announces AI cybersecurity fund. N2K’s Lead Analyst Ethan Cook shares about cyber weapons for space. Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain. And fasten your seatbelts and ignore the fake Wi-Fi. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today’s Industry Voices, Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain, including AgentBaiting, where fake AI Skills and MCP servers were used to deliver malware, and hidden instructions that can influence AI agents. If you enjoyed the conversation, be sure to check out the full interview here. Selected Reading Microsoft and Adobe Patch Tuesday, August 2026 Security Update Review (Qualys) Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack (Check Point Research) Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability CSO Online ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact (SecurityWeek) Hackers leverage new Microsoft SharePoint exploit in attacks (BleepingComputer) The CEVA Logistics data breach is having major knock-on effects across Europe - here's what we know (TechRadar) Wesco confirms security incident after ExfilSquad claims data theft (BleepingComputer) Akira Hits Safe Mode: Ransomware Rebooting Around EDR (Huntress) California Building ‘AI Cyber Defense Fund’ to Protect Critical Infrastructure From Hackers (Gizmodo) Laser weapons for space? US officials see threat, opportunity (BREAKING DEFENSE) DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  • S11 · E2612
    August 11 · 20 min

    A private route to public risk.

    Poland’s CERT describes winter cyberattack against heat-and-power plant. Russian military hackers target Ukrainian IT workers in fake recruitment scheme. Chinese IP connections spark security review in UK Navy drones. US and South Korea warn of “Gunra” ransomware gang with North Korean ties. OpenAI mandates strict security controls for its new cybersecurity model. Record-breaking DDoS attacks surge in H1 2026. Data-scraping AI extension returns to the Chrome Web Store. Dave Bittner sat down with Stephen Harrison, VP of Product at Abnormal AI at Black Hat USA to discuss "The Identities Your Security Stack Is Ignoring." And no pain, no gain, no authorization. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices, Dave Bittner sat down with Stephen Harrison, VP of Product at Abnormal AI at Black Hat USA to discuss "The Identities Your Security Stack Is Ignoring." If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading Hackers breached a small Polish energy plant via private APN last year (BleepingComputer) Russian military hackers pose as recruiters to target Ukrainian IT workers (The Record) Cyber vulnerability sweep picks up Royal Navy drones sending data to China (The Register) U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang (CyberScoop) OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns (SecurityWeek) Cloudflare DDoS Threat Report H1 2026 (Cloudflare) Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities (SecurityWeek) AI assistant hacks gym website in first known Australian autonomous cyber attack (ABC News) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  • S11 · E2611
    August 10 · 27 min

    Now with extra vulnerabilities.

    Researchers find that only a quarter of AI-generated patches are fully successful. Ransomware attacks exploit critical N-able flaw. Atlassian fixes critical flaw in Rovo AI. LexisNexis disables some services following suspicious activity. US Senate confirms Adam Cassady as cyber ambassador. Meta ordered to pay an additional $567 million in child safety case. Water sector cyberattacks expand to new states. We got your Monday Business Briefing. On our Industry Voices, Dave Bittner sits down with Mujtaba Hamid, EVP, Product and Strategy at Booz Allen Hamilton at Black Hat discussing AI Speed Cyber Defense. And scammers set sail on The Odyssey. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices, Dave Bittner sat down with Mujtaba Hamid, EVP, Product and Strategy at Booz Allen Hamilton at Black Hat USA, discussing AI Speed Cyber Defense. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading More than half of AI-generated patches are broken (CyberScoop) China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns (The Record) Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data (SecurityWeek) LexisNexis shuts down services after suspicious activity on servers (BleepingComputer) US cyber ambassador nominee Cassady confirmed in Senate (The Record) Meta Ordered to Pay $567 Million in New Mexico Child Safety Case (New York Times) New Jersey, Alabama Join States Targeted in Water Cyberattacks (Securityweek) Business Breakdown (N2K) ‘Watch The Odyssey for free online’: scam targets film fans with fake streaming sites (The Guardian) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  • S2 · E719
    August 9 · 22 min

    Designing space systems for the AI era. [T-Minus: Space-Cyber Briefing]

    As commercial space activity accelerates, satellite manufacturers are rethinking how spacecraft are designed, built, and secured. In this week's episode, host Maria Varmazis sits down with Jason Roberson, an Industry Value Expert for Aerospace & Defense at Dassault Systems, to discuss how AI, automation, and digital engineering are transforming the space industry's product lifecycle. From digital twins and AI-assisted design to the future of in-space maintenance, Jason explores how these technologies are accelerating innovation while reshaping manufacturing. At the same time, the conversation examines the growing cybersecurity challenges that accompany this transformation and why building secure-by-design principles into space systems will be critical. Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: ⁠https://thecyberwire.com/newsletters/signals-and-space⁠ Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to ⁠space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: ⁠https://www.surveymonkey.com/r/NJYCN2P ⁠ T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. ⁠N2K⁠ is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at ⁠n2k.com⁠.

  • S10 · E436
    August 8 · 19 min

    A little help from your search engine. [Research Saturday]

    Today we are joined by Brian Hussey, SVP of Howler Cell Threat Services at Cyderes, discussing their work on "Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer." Howler Cell identified an SEO poisoning campaign targeting people searching for Claude Code installation guides, using a fake Anthropic page and a ClickFix lure to trick victims into running a malicious MSHTA command. The attack uses a six-stage, largely fileless chain that employs an MP3/HTA polyglot, PowerShell obfuscation, AMSI bypasses, per-victim infrastructure, and in-memory execution to evade detection. The final payload is a .NET infostealer that steals credentials, while Anthropic and the legitimate Claude Code installation process were not compromised. The research and executive brief can be found here: Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer

  • S11 · E2610
    August 7 · 24 min

    Ring around the ransom.

    Vishing attacks target hedge funds. Metabase Cloud breached by zero-day flaw. Cyberattack disrupts North Carolina Ports operations. The Chinese government has launched a security review of Palo Alto Networks products. US defense supplier breached by phishing attack. Healthcare software provider breach affected 3.8 million people. New macOS malware spreads via ClickFix attacks. Microsoft and Apple issue new security updates. Cryptography expert says new AI cryptanalysis results show promise, but not an AES breakthrough. James Turgal, Optiv Security’s vice president, cyber risk, strategy and board relations, is discussing how Iranian operators and their proxies appear to pursue disruption. And a Kentucky Fried Chicken order doxxes Chinese spyware operator. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by James Turgal, Optiv Security’s vice president, cyber risk, strategy and board relations, discussing how Iranian operators and their proxies appear to pursue disruption by exploiting poorly secured operational technology in sectors such as water, energy, healthcare, and transportation. Selected Reading Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group (BleepingComputer) Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments (GTIG) Cyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigate (The Record) China launches cybersecurity review into Palo Alto Networks products (Reuters) Attacker phished way into US defense supplier's Microsoft 365 account (The Register) Unlimited Technology Systems Data Breach Affects 3.8 Million Patients (HIPAA Journal) Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam (Huntress) China-linked LightSpy spyware caught targeting victims in 13 countries, including the US (TechCrunch) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  • S11 · E2609
    August 6 · 25 min

    AI without adult supervision.

    Meta’s AI models join the sandbox escape club. China’s telecom footprint in the U.S. may be larger than expected. The White House keeps its AI safety playbook under wraps. AI coding tools introduce new GitHub risks. ENISA expands its CVE role. A critical Paperclip flaw enables code execution. Crypto wallet fears fuel phishing attacks. Researchers uncover a backdoor in Chinese-made routers. The Snowflake hacker pleads guilty. Our guest is Dustin Childs, Head of Threat Awareness of TrendAI’s Zero Day Initiative, discussing the new Patch Tuesday era. AI takes your word for it. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Dustin Childs, Head of Threat Awareness of TrendAI’s Zero Day Initiative, discussing the new Patch Tuesday era. Be sure to check Dustin out on the AI Security Briefing podcast. Selected Reading Meta AI Hacked External Systems During Cybersecurity Testing (SecurityWeek) Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says (The Record) Secret White House AI Safety Framework Draws Criticism (BankInfo Security) Few Federal Agencies Trust Their Own AI Agent Security (BankInfo Security) Black Hat USA 2026: One GitHub Issue Could Compromise Major AI Coding Workflows (Hackread) ENISA scales up its role in the CVE Program (enisa) Critical Paperclip Flaw Allowed Admin Access, Code Execution (SecurityWeek) COLDCARD security audit phishing attack installs remote access tool (Bleeping Computer) Chinese-made Zbtlink routers have backdoor, researchers say (Reuters) Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions (US Department of Justice) “I’m Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails (Hackread) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  • S11 · E2608
    August 5 · 35 min

    SAFE and sound.

    The White House lays out its AI strategy at Black Hat. Researchers spotlight rogue AI behavior. CISA warns of an actively exploited N-able flaw. TP-Link patches 15 Omada vulnerabilities. Apple fights the UK’s iCloud access order. The AI gray market expands. A Massachusetts healthcare breach hits more than 300,000 people. Lawmakers push to extend protections for OPM breach victims. Our guest is Cal Al-Dhubaib, Principal Technologist at Rubrik, who wonders if your security team is solving the wrong problem. With elections, don’t trust AI to tell you the whole story. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today’s Industry Voices segment, we are joined by Cal Al-Dhubaib, Principal Technologist at Rubrik, talking about how your security team is solving the wrong problem. If you enjoyed the conversation, check out the full interview here. You can also find more information below: Rubrik Agent Cloud landing page Rubrik AI landing page News: Rubrik Launches Rubrik Agent Cloud for Anthropic's Claude Code Selected Reading National cyber director lays out White House plans to secure AI without writing new rules (CyberScoop) Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data (SecurityWeek) AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project (The Register) MSPs urged to patch immediately after N-able issues hotfix for N-central ‘god mode’ flaw (IT Pro) TP-Link patches Omada ZTP flaws allowing hackers to breach networks (BleepingComputer) Apple launches new legal challenge against UK over iCloud access (The Record) Free tokens for sale: How fake signups drive AI fraud (Threat Intelligence) 311,000 Impacted by Brown Health Medical Group-MA Data Breach (SecurityWeek) Lawmakers spring to save ID theft services for OPM breach victims, with expiration looming (CyberScoop) AI is getting better at election facts, but voters shouldn’t rely on it (CyberScoop) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  • S11 · E2607
    August 4 · 29 min

    NPM? Not my problem.

    New Shai-Hulud campaign compromises popular npm packages. Easterly says small municipalities shouldn’t have to fend for themselves. Chinese threat groups accelerate exploits. Samsung bans smart TV apps with residential proxies. Hackers breach a Liechtenstein banking database. Swiss government IT agency hit in suspected SharePoint Attack. Microsoft’s bug bounty program awards record payouts. Researchers expose privilege boundary flaw in AI-driven CI/CD workflows. Roberta Anderson, Air Force veteran and CISO at Onterris is sharing her "Breaking the Firewall" book. And, bug hunting turns into bug sorting. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Roberta Anderson, Air Force veteran and CISO at Onterris, sharing her "Breaking the Firewall" book. Selected Reading Keyv and friends compromised in npm supply chain attack (Aikido) Small Towns Shouldn’t Have to Defend America’s Water Supply From Iran (The New York Times) China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day (Infosecurity Magazine) Samsung bans smart TV apps that share users' internet connections with strangers (TechCrunch) Liechtenstein says hackers access information on 31,000 legal entities (Reuters) Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected (The Record) Microsoft Bounty Program year in review More than $20 million awarded in our biggest year yet (Microsoft Security Response Center) I'll Just Call You: Agent-to-Agent Privilege Boundary Failures in CI/CD on Google's ADK Repository (Pillar Security) Apple struggles to keep pace with AI ‘bug’ hunters (Financial Times) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Showing 21–40 of 51 episodes