CyberWire Daily

Daily briefing on cyber security news and threats.

Episodes (40)

Software Development

You can’t secure what you can’t see.

An OT cyber coalition urges CISA to establish baseline security requirements. Another OpenAI safety worker resigns. Maryland lawmakers seek funding for Cyber Command’s mental health initiatives. Hackers compromised country-code domain registries for TLS certs. The FBI and French authorities shut down alleged CSAM AI deepfake websites. Ransomware recovery firm CEO indicted for secretly paying attackers. MATCHBOIL keeps simmering. Apollo software pioneer Margaret Hamilton dies. On today’s Industry

27 min

Series: CyberWire Daily

Software Development

The door into SonicWall.

SonicWall issues emergency patches. European wind and solar sites are exposed online. South Korea warns of AI-powered attacks on banks. Maria Varmazis unpacks the EU’s new Space Threat Response Architecture. Google patches dozens of high-severity Chrome flaws. Researchers uncover an SSRF vulnerability in Harbor. AI reshapes vulnerability management. Wikimedia says OpenAI agents repeatedly broke its rules. Pwn2Own kicks off in Ireland. Our guest is Derek Holt, CEO of Digital.ai, who says AI has k

23 min

Series: CyberWire Daily

Software Development

The pay system needs a patch.

Military cyber personnel face pay cuts. A critical RCE threatens banking and government authentication systems. Dell patches a critical update flaw. A missed patch costs Accenture an FBI contract. Hackers hijack a fashion retailer’s push notifications. Insurers brace for rogue AI claims. Hackers breach a supertanker’s propulsion system. Denmark suffers a massive population data breach. And Japan extradites a suspected Qilin ransomware operator. Our guest is Steve Ryan, Founder and CEO of Trinity

32 min

Series: CyberWire Daily

Software Development

A new AI task force takes shape.

The President launches a new federal AI task force. South Korea investigates financial sector data leaks. AI slop overwhelms a Google bug bounty program. Citrix patches an exploited zero-day. Stealthy malware hides inside Asian email security appliances. Apple tightens macOS privacy around AI agents. Attackers exploit a critical Rejetto File Server flaw. The Senate advances healthcare cybersecurity legislation. Monday business briefing. Our guest is Jared Shepard, CEO of Hypori, with insights on

29 min

Series: CyberWire Daily

Software Development

Earth’s expanding attack surface. [T-Minus: Space-Cyber Briefing]

As space infrastructure expands, so too does the need for cybersecurity expertise beyond securing traditional spacecraft. Host Maria Varmazis speaks with ⁠Milenk Starcevic⁠, Head of Cybersecurity at ⁠Vision Space⁠, and ⁠Andrzej “Andy” Olchawa⁠, Senior Cybersecurity Engineer also at Vision Space, about the growing space cybersecurity field. They discuss the role of compliance and auditing, how cybersecurity professional can develop space-specific skills, and how emerging capabilities are expandin

16 min

Series: CyberWire Daily

Software Development

Play to win, pay to lose. [Research Saturday]

Today we are joined by Jean-Pierre Mouton, Senior Threat Intelligence Consultant at GuidePoint Security, discussing their work on "How Play Achieves Encryption." Play ransomware, also known as PlayCrypt, continues to target organizations across multiple sectors using a consistent double-extortion playbook that combines data theft with widespread encryption. A recent investigation details how the group gained access through a SonicWall VPN, moved laterally using tools such as Mimikatz and PsExec,

23 min

Series: CyberWire Daily

Software Development

The Pentagon’s roll call.

A Pentagon breach exposes data on millions. ShinyHunters goes dark. MI5 warns universities about Chinese espionage. AI agents find creative ways around their guardrails. A fake Zoom installer delivers macOS malware. Cisco patches an actively exploited SD-WAN flaw. OpenAI disrupts a “distillation attack.” Cyber Command confronts operator burnout. Treasury targets alleged ATM jackpotters. Our guest is Etay Maor, Vice President of Threat Intelligence at Cato Networks, with a reminder that your netw

26 min

Series: CyberWire Daily

Software Development

A rough week for safety.

OpenAI fires safety researchers for mishandling sensitive information. CISA looks to secure the next 250. Dell patches six critical flaws, while attackers exploit a FortiMail zero-day. Warlock ransomware expands its reach, and Star Blizzard scales up its phishing. Researchers map maritime GPS spoofing. An alleged Iranian hacker is extradited to the U.S., and law enforcement takes down KillSec. Our guests are John Kindervag and Dr. Chase Cunningham, discussing their new book "Cyber Resilience at

31 min

Series: CyberWire Daily

Software Development

The guardrails go to court.

AI companies sign a voluntary accord aimed at addressing safety concerns. Cybercriminals abuse the CustomGPT feature as part of a ClickFix campaign. The FBI is urging members of ShinyHunters to come forward. A fraud campaign turns stolen credentials into job scams. Maria Varmazis joins us for her space cyber story. The WaterISAC confronts persistent weaknesses. AI gives SOC teams more time at the expense of training. Two U.S. Air Force members get federal prison time over a business email compro

32 min

Series: CyberWire Daily

Software Development

Astra, la vista, baby.

OpenAI holds back its newest model over safety concerns. Kiteworks lifts its precautionary shutdown. Apple patches an exploited zero-day. Japanese rail operators disclose cyberattacks. An Anthropic authentication flaw opens the door to account takeover. Thousands of Supabase databases leak data. NeedyMantis targets telecoms and governments. A Vietnamese national faces charges in a multimillion-dollar crypto laundering scheme. James Winebrenner, CEO of Elisity, is sharing barriers to compliance a

26 min

Series: CyberWire Daily

Software Development

The AI hotline.

The U.S. and China agree on an AI safety channel. Some states say CISA’s election security plan comes too late. Citrix patches critical zero-days under active exploitation. AI agents probed government websites in unexpected and concerning ways. ShinyHunters launches a new campaign against Oracle PeopleSoft customers. A New Mexico jury finds Meta misled state residents. Business briefing. Tim Starks from CyberScoop shares insights on multiple issues facing CISA. Who’s ready for algorithmic holida

23 min

Series: CyberWire Daily

Software Development

Space cybersecurity starts on the ground. [T-Minus: Space-Cyber Briefing]

Though spacecraft are important, space cybersecurity extends well beyond these assets touching ground stations, mission-control assets, and other critical components. Host Maria Varmazis speaks with Milenk Starcevic, cybersecurity lead at Vision Space, and Andrzej “Andy” Olchawa, a space-focused offensive security professional, about the broader space cybersecurity attack surface. By considering all aspects of a space mission, both in orbit and on the ground, cybersecurity professionals can bett

21 min

Series: CyberWire Daily

Software Development

The Insider You Built with author Camille Stewart Gloster. [Special Edition]

On this special edition podcast, N2K CyberWire's Dave Bittner spoke with Camille Stewart Gloster⁠. Camille is the author of The Insider You Built: How Organizations Stay in Control of Autonomous AI Agents, and founder of⁠ CAS Strategies⁠. Dave and Camille discuss her new book and the broader questions it raises about AI agents. Listen in as Camille Stewart Gloster discusses the implications of autonomous AI agents, focusing on authority, accountability, and risk management in organizations. She

21 min

Series: CyberWire Daily

Software Development

An apple a day, a phish away. [Research Saturday]

Today we are joined by Ensar Seker, VP of Research and CISO at SOCRadar, discussing their work on "Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain." An investigation into AnonyMousKIT reveals an AI-powered Phishing-as-a-Service platform designed to steal Apple credentials and disable Activation Lock on stolen devices. The platform uses email, SMS, WhatsApp, and AI-driven voice calls to impersonate Apple Support, with researchers uncovering a broader ecosystem spanning 506 domains, 168 store

24 min

Series: CyberWire Daily

Software Development

The hunters go after the bureau.

ShinyHunters claims to have breached FBI systems. CLOSEDQUORUM malware delegates command-and-control decisions to commercial LLMs. An IT error erases 11 years of hospital maternity data. F5 patches a critical BIG-IP APM zero-day. Ransomware activity remains high. Microsoft disrupts the EvilTokens cybercrime platform. Researchers turn Claude Code’s normal workflow against itself. Pundits propose an AI Assurance Compact. A Ryuk ransomware gang member gets two years prison time. Our guest is Jen So

28 min

Series: CyberWire Daily

Software Development

No factoring necessary.

Researchers find a new way to weaken RSA. ShinyHunters allegedly exposes sensitive FBI details. CISA and the FBI warn of third-party ICS risks. An OpenAI agent hacks an Australian government portal. SolarWinds patches critical flaws. A placeholder domain delivers ClickFix. Digital forensics executives face charges over alleged Russian ties. ENISA maps Europe’s cyber threats. The U.S. and China have very different ideas about AI safety. Our guest is Kurt Dusek, Technical Product Advisor at Appdom

29 min

Series: CyberWire Daily

Software Development

The hunters go after the bureau.

ShinyHunters claims to have breached FBI systems. CLOSEDQUORUM malware delegates command-and-control decisions to commercial LLMs. An IT error erases 11 years of hospital maternity data. F5 patches a critical BIG-IP APM zero-day. Ransomware activity remains high. Microsoft disrupts the EvilTokens cybercrime platform. Researchers turn Claude Code’s normal workflow against itself. Pundits propose an AI Assurance Compact. A Ryuk ransomware gang member gets two years prison time. Our guest is Jen So

28 min

Series: CyberWire Daily

Software Development

Storm clouds over the waterworks.

CISA rides out a Cyber Storm. The EU struggles to share cyber threat information. Nightmare Eclipse drops another Defender zero-day. TASK#STOMP steals business documents. North Korean operatives fake their way through job interviews. A genetics lab pays $700,000 over a phishing breach. A zero-day in Meta’s Muse AI assistant opens the door to privilege hijacking. Marc Woolward, Senior Advisor to Humanix and former CTO for Goldman Sachs, discussing social engineering and vishing attacks. Infiltrat

27 min

Series: CyberWire Daily

Software Development

A very real-world AI test.

Google confirms unauthorized access by Gemini. AI’s growing power outpaces its defenses. Hackers target Colorado water utilities. Georgia weighs voting-system security. ShinyHunters hijacks Clop’s leak site. FamousSparrow spies across Latin America. CrowdSec loses source code. New npm malware slips past supply-chain defenses. Monday business briefing. Our guest is Matt Fredrikson, CEO of Gray Swan AI, discussing OpenAI's Astra. A new app warns Glassholes to ZuckOff. Remember to leave us a 5-star

29 min

Series: CyberWire Daily

Software Development

Defending Space as Critical Infrastructure. [T-Minus: Space-Cyber Briefing]

Space infrastructure has become an increasingly important part of everyday life, which has also made it an increasingly attractive target for exploitation. Host Maria Varmazis and Sean MacKirdy, Area Vice President for the National Security vertical at Elastic Government Solutions, sit down to discuss how space stakeholders need to reevaluate their approach to securing space systems. As space systems continue to grow more important, malicious actors are going to look to target them more often. B

26 min

Series: CyberWire Daily

Software Development

CyberWire Daily at 10: Critical infrastructure attacks over the last 10 years. [Special Edition]

In this Special Edition episode, Maria Varmazis⁠ and ⁠Dave Bittner⁠ from N2K Cyberwire get back together to reflect on the past decade of critical infrastructure attacks, evolving threats, and lessons learned from incidents like the Ukraine power grid attack and Colonial Pipeline ransomware. They discuss how these events have shaped current cybersecurity practices and the importance of resilience and preparedness. Join Maria and Dave as they discuss: The critical infrastructure evolution over th

43 min

Series: CyberWire Daily

Software Development

All about that proxy. [Research Saturday]

Today we are joined by Dr. Renée Burton, VP of Threat Intelligence at Infoblox, discussing their work on Lurking Lizard, "Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real." The research uncovers Lurking Lizard, a threat actor that has operated since at least 2022 by using fake software installers, VPNs, and lookalike domains to secretly turn victims’ devices into residential proxy nodes. Researchers identified more than 230 related domains and connected seemingly separate campai

25 min

Series: CyberWire Daily

Software Development

The Cisco root route.

Cisco patches a maximum-severity vulnerability in its Identity Services Engine. Court documents describe AI as “an astonishing theft of unprecedented proportions.” Researchers chain vulnerabilities to take over employee ChatGPT accounts. Microsoft and Check Point patch vulnerabilities. Manufacturing remains ransomware’s favorite target. Hackers compromise a Japanese image-sharing service. The Settra ransomware group leverages remote management software. An Australian think-tank warns of Chinese

28 min

Series: CyberWire Daily

Software Development

AI is calling the shots.

AI goes to war. Iranian strikes leave AWS data unrecoverable. OpenAI discloses more model misbehavior. Researchers uncover 16 Wireshark vulnerabilities. TrustSink turns Entra authentication into a password trap. RatHat raids Android credentials. The FBI takes down a DDoS-for-hire service. A data broker loses its domains. U.S. Cyber Command names a new AI chief. Ethan Cook is joining Dave Bittner and Ben Yelin to discuss the industry-proposed and administration-opposed AI slowdown. CISA’s field o

29 min

Series: CyberWire Daily

Software Development

Cybercrime finds its sea legs.

Officials investigate suspected cyberattacks on U.S.-bound oil tankers. Iranian operators deploy Chosen Brick surveillance malware. Ukraine cracks down on scam call centers. Researchers uncover two TP-Link camera zero-days. Maria Varmazis looks at weapons in space. CenterPoint Energy reports a data breach. Spain records its first breach caused by an autonomous AI agent. PhantomRaven targets developers through malicious npm packages. Illicit casinos provide cover for cybercrime. A New York health

29 min

Series: CyberWire Daily

Software Development

Pedal to the AI metal.

The President pushes back on calls to slow AI. Microsoft lays out potential AI safety rules. Lawmakers consider the crypto Clarity Act. Florida’s Department of Highway Safety and Motor Vehicles and Japan’s Digital Agency suffer data breaches. Phishing campaigns grow increasingly difficult for email security tools to spot. New York seizes a dozen AI deepfake domains. Alleged Black Axe cybercriminals face charges. Our guest is Camille Stewart Gloster, former U.S. Deputy Cyber Director and author o

28 min

Series: CyberWire Daily

Software Development

Bigfoot in the neural network.

NSA preps a major restructuring. Anthropic’s CEO calls for an AI slowdown. China acknowledges AI risks. RubyGems got swarmed by AI agents. A maximum-severity GitLab vulnerability is under active exploitation. Direct Send abuse makes phishing emails appear legit. A British fintech firm leaks sensitive customer info. LinkedIn wins a legal dispute over browser extension scanning. Monday business briefing. Our guest is Tim Starks, senior reporter at CyberScoop, sharing government leaders’ outlook fo

27 min

Series: CyberWire Daily

Software Development

Space's cybersecurity policy problem. [T-Minus: Space-Cyber Briefing]

As space becomes increasingly connected and autonomous, effective cybersecurity policy is struggling to keep pace. Host Maria Varmazis and ⁠⁠⁠Dr. Mac McGuire sit down to discuss the limitations of current approaches for managing space cyber risks and what the industry is lacking. The two discuss how the space incidents have the potential to significant impact astronauts by disrupting oxygen systems, thermal regulation, and telemetry. Like what you heard? Be sure to subscribe to our free Signals

22 min

Series: CyberWire Daily

Software Development

A beast by any other name. [Research Saturday]

Today we are joined by Brigid O Gorman, Senior Intelligence Analyst on Symantec Threat Hunter team, discussing their work on “GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses." GodDamn ransomware, the latest rebrand from the Hyadina group behind Monster and Beast, is using increasingly sophisticated techniques to evade defenses. In a recent attack, the threat actors used AnyDesk for remote access, a broad credential-harvesting toolkit, and the PoisonX malicious

23 min

Series: CyberWire Daily

Software Development

You might want to watch what you say.

WeWorm has China’s attention. Calls for an AI slowdown continue. OpenAI calls for mandatory AI regulation. Anthropic disrupts Russian cyberespionage. The EU’s 24 hour reporting requirement goes into effect. GitLab and Check Point patch critical vulnerabilities. IDScan confirms theft of IDs. Microsoft tracks a cloud intrusion campaign. Our guest is Kevin E. Greene, Chief Cybersecurity Technologist, Public Sector at BeyondTrust, discussing the role of privilege disruption in cyber resiliency. Watc

29 min

Series: CyberWire Daily

Software Development

Making cybercrime more difficult.

The FBI lays out its new Cyber Strategy. CISA plans a federal cyber overhaul. Anthropic discloses another unauthorized AI intrusion. Treasury sanctions a Chinese-language cybercrime marketplace. Another Microsoft Defender zero-day emerges. Gigabud banking malware gets stealthier. Chinese espionage groups deploy the BlueMoon exploit kit. Lawmakers target hack-for-hire firms. A U.S. designation forces an Italian technology collective to shut down. Ben Yelin discusses how private AI chatbot convers

28 min

Series: CyberWire Daily

Software Development

Clear your calendar, it’s Patch Tuesday.

Patch Tuesday is a doozy. The Feds warn China-based AI companies are distilling U.S. AI models. A new ClickFix campaign goes straight for the browser. Smart TVs get nosy. Hackers gift themselves a $47 million bug bounty. An Ohio man gets 15 years in federal prison for cyberstalking and sextortion. Andy Hornegold, Chief Security Technologist from Intruder, discusses what makes up a reliable AI pentests and the benefits and risks that come with AI-enabled security. Putting AI at the head of the cl

30 min

Series: CyberWire Daily

Software Development

Worming its way through WeChat.

Researchers build a self-propagating attack against WeChat. Threat actors move toward multi-agent AI frameworks. N-able issues an emergency patch for a maximum-severity bug under active exploitation. MikroTik patches multiple RouterOS vulnerabilities. China accesses restricted American technology through subsidiaries and overseas partners. An active phishing campaign abuses legitimate Google services to make malicious links appear trustworthy. Australians may soon be able to disable the algorith

30 min

Series: CyberWire Daily

Software Development

This call may be monitored. [Special Edition]

In this Special Episode, Maria Varmazis and Dave Bittner are joined by friend of the show, Brandon Karpf, to unpack a new bipartisan congressional investigation into the lingering presence of Chinese state-owned telecommunications companies inside U.S. internet infrastructure. The House Select Committee on China says China Mobile, China Unicom, and China Telecom remain deeply embedded in American networks even after federal regulators denied or revoked their authority to provide certain telecomm

38 min

Series: CyberWire Daily

Software Development

When hackers control the clock. [T-Minus: Space-Cyber Briefing]

The accurate timing data from spacecraft has become an invaluable tool for nearly every critical infrastructure sector and a greater target for malicious actors. Host Maria Varmazis and ⁠Andy Davis⁠, Global Research Director at the NCC Group, discuss the importance of timing in space. The two look at how timing systems have continued to grow more important in everyday life and why attackers have begun to increasingly exploit these critical services. Key sources: GPS: A backbone for critical infr

23 min

Series: CyberWire Daily

Software Development

RMM-ber this ransomware. [Research Saturday]

Ismael Valenzuela, Vice President of Labs, Threat Research and Intelligence at Arctic Wolf, sits down with Dave to discuss their work tracking Anubis. Arctic Wolf Labs details a series of 2026 Anubis ransomware intrusions, revealing affiliates using stolen VPN credentials and exploiting CitrixBleed 2 to gain initial access. Attackers then blended into legitimate IT activity by deploying RMM tools, using RDP and PsExec for lateral movement, stealing credentials, and establishing tunnels and proxi

19 min

Series: CyberWire Daily

Software Development

What the Flock?

The G7 and CISA prepare for the quantum threat. Nightmare Eclipse drops a CrowdStrike zero-day. The White House’s offensive hacking plan raises legal questions. CISA offers a playbook for communicating through cyber incidents. OpenAI puts a billion dollars behind AI-powered defense. Researchers uncover a serious PostgreSQL flaw. Google patches an exploited Chrome zero-day. Broadcom fixes VMware vulnerabilities. Attackers target a WordPress plugin flaw. Lawmakers tell license plate surveillance c

31 min

Series: CyberWire Daily

Software Development

Who’s watching the AI watchers?

A watchdog challenges the Trump administration’s secret frontier AI reviews. METR discloses two cyberattacks. Leaked documents reveal a Russian cyber training pipeline. Rogue ScreenConnect clients spread malware like a worm. A breach exposes appellate court records across the U.S. and Canada. Spring Ring impersonates IT support on Microsoft Teams. Plex urges users to patch, and Cisco warns of unpatched Secure Email flaws. Our guest is Rob van der Veer, Chief AI Officer at Software Improvement Gr

24 min

Series: CyberWire Daily

Software Development

Drive-by data theft.

Nexus sells driver’s license scans on the dark web. OpenAI says its models have reached a “Critical” capability threshold. International law enforcement disrupts a decades-old botnet. AI hallucinations fuel “slop squatting.” Plus, urgent patches for Cleo Harmony and Virtualizor, a Texas healthcare breach, and a Russian national accused of targeting thousands of freelancers with remote-access malware. Maria Varmazis shares the latest space-cyber news. Our guest is Rob Allen, Chief Product Officer

30 min

Series: CyberWire Daily

Software Development

Nightmare on Windows 11.

Nightmare Eclipse drops a Kaspersky zero-day. The Financial Stability Board warns frontier AI could threaten the global financial system. Anthropic says it has tightened security. CISA adopts a risk-based approach to patching. A new Windows infostealer hides in fake AI models. A critical vulnerability in JFrog Artifactory is kneedeep in active exploitation. North Korean workers are still landing U.S. jobs. A classic NSA codebreaking machine. Our guest is Heather Ceylan, CISO at Box, discussing i

27 min

Series: CyberWire Daily