CyberWire Daily

N2K Networks

The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

  1. 6 hr ago

    A very real-world AI test.

    Google confirms unauthorized access by Gemini. AI’s growing power outpaces its defenses. Hackers target Colorado water utilities. Georgia weighs voting-system security. ShinyHunters hijacks Clop’s leak site. FamousSparrow spies across Latin America. CrowdSec loses source code. New npm malware slips past supply-chain defenses. Monday business briefing. Our guest is Matt Fredrikson, CEO of Gray Swan AI, discussing OpenAI's Astra. A new app warns Glassholes to ZuckOff.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Matt Fredrikson, Carnegie Mellon University Associate Professor and CEO of Gray Swan AI, discussing OpenAI's Astra and real industry risks. Selected Reading Google says Gemini breached three companies during security test (The Record) Hackers who broke into OpenAI warn the AI industry has a security problem (Washington Post) Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems (Security Week) Lawmakers mull cybersecurity concerns as they prepare for overhaul of Georgia’s voting system (Cobb Courier) Clop gets a taste of its own medicine after ShinyHunters hijack leak site (The Register) China-Linked FamousSparrow Deploys SparroWocky Backdoor in Latin America (Hackread) CrowdSec Confirms Source Code Stolen in Supply Chain Attack (Security Week) Malicious npm packages evade install-script defenses at runtime (Bleeping Computer) Physical AI security company Exein lands $270 million. (N2K Networks) ZuckOff Is a Free App That Sees Meta Glasses Before They See You (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

  2. 1 day ago

    Defending Space as Critical Infrastructure. [T-Minus: Space-Cyber Briefing]

    Space infrastructure has become an increasingly important part of everyday life, which has also made it an increasingly attractive target for exploitation. Host Maria Varmazis and Sean MacKirdy, Area Vice President for the National Security vertical at Elastic Government Solutions, sit down to discuss how space stakeholders need to reevaluate their approach to securing space systems. As space systems continue to grow more important, malicious actors are going to look to target them more often. By adopting a stronger universal framework and a consistent way to interpret data across all spacecraft, space cybersecurity practitioners will be able to standardize their practices and create more effective and timely responses. Key Sources: SPARTA v4.0 Maria Varmazis interviews Brandon Bailey about Space Attack Research and Tactic Analysis, or SPARTA matrix. Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: ⁠⁠⁠⁠⁠⁠⁠https://thecyberwire.com/newsletters/signals-and-space⁠⁠⁠⁠⁠⁠⁠ Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to ⁠⁠⁠⁠⁠⁠⁠space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: ⁠⁠⁠⁠⁠⁠⁠https://www.surveymonkey.com/r/NJYCN2P ⁠⁠⁠⁠⁠⁠⁠ T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. ⁠⁠⁠⁠⁠⁠⁠N2K⁠⁠⁠⁠⁠⁠⁠ is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at ⁠⁠⁠⁠⁠⁠⁠n2k.com⁠⁠⁠⁠⁠⁠⁠. Learn more about your ad choices. Visit megaphone.fm/adchoices

    Defending Space as Critical Infrastructure. [T-Minus: Space-Cyber Briefing]
  3. 3 days ago

    The Cisco root route.

    Cisco patches a maximum-severity vulnerability in its Identity Services Engine. Court documents describe AI as “an astonishing theft of unprecedented proportions.” Researchers chain vulnerabilities to take over employee ChatGPT accounts. Microsoft and Check Point patch vulnerabilities. Manufacturing remains ransomware’s favorite target. Hackers compromise a Japanese image-sharing service. The Settra ransomware group leverages remote management software. An Australian think-tank warns of Chinese AI-enabled surveillance in Venezuela. Maria Varmazis joins me for a look back at ten years of critical infrastructure exploits. Everything you wanted to know about AI but were afraid to prompt. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Dave Bittner and Maria Varmazis reflect on the past decade of critical infrastructure attacks, looking at major incidents like the Ukraine power grid attack and Colonial Pipeline and the lessons they’ve taught the industry about resilience and preparedness. If you enjoyed this conversation, be sure to tune in this Sunday for a special edition of the show, where Dave and Maria continue the conversation. Selected Reading Cisco drops another exploited zero-day, this time a perfect 10 (The Register) ‘Doom Loop’: OpenAI and Microsoft Admits LLMs Are Destroying the Web and Built on Theft (404 Media) AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code (SecurityWeek) Microsoft Patches 18 Vulnerabilities in AI, Cloud Products (SecurityWeek) New Check Point flaw lets hackers execute code with root privileges (Bleeping Computer) Manufacturing Accounts for 22% of all Ransomware Victims (Infosecurity Magazine) 23 Million User Records Compromised in Gyazo Data Breach (SecurityWeek) Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM (Huntress) USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech (The Register) Will A.I. Kill Us? Can It Hack My Bank Account? Your A.I. Questions Answered (New York Times) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

  4. 4 days ago

    AI is calling the shots.

    AI goes to war. Iranian strikes leave AWS data unrecoverable. OpenAI discloses more model misbehavior. Researchers uncover 16 Wireshark vulnerabilities. TrustSink turns Entra authentication into a password trap. RatHat raids Android credentials. The FBI takes down a DDoS-for-hire service. A data broker loses its domains. U.S. Cyber Command names a new AI chief. Ethan Cook is joining Dave Bittner and Ben Yelin to discuss the industry-proposed and administration-opposed AI slowdown. CISA’s field of schemes.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today, Ethan Cook, N2K’s lead analyst, joins Dave Bittner and Ben Yelin for a discussion about the industry-proposed and administration-opposed AI slowdown, exploring the policy debate and what it could mean for the future of AI. If you enjoyed this conversation, be sure to check out the full interview on Caveat here. Selected Reading The era of AI warfare has arrived (Financial Times) Iran strikes on Amazon data centers caused permanent loss of customer data (Ars Technica) OpenAI Discloses Six New Incidents of ‘Concerning' A.I. Behavior (The New York Times) AISLE Discovers 16 CVEs in Wireshark, the World’s Most Popular Network Protocol Analyzer (AISLE) TrustSink: How a Rogue External MFA Provider Steals Passwords (Varonis) RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts (Zimperium) US takes down NightmareStresser DDoS-for-hire platform (Bleeping Computer) Data Broker Radaris Loses Domains in Privacy Fight (Krebs on Security) Former NGA Executive Ronzelle Green Named USCYBERCOM Chief AI Officer (ExecutiveGov) CISA releases Cyber Decoys guide detailing tripwires, honeytokens to strengthen critical infrastructure detection and response (Industrial Cyber) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

  5. 5 days ago

    Cybercrime finds its sea legs.

    Officials investigate suspected cyberattacks on U.S.-bound oil tankers. Iranian operators deploy Chosen Brick surveillance malware. Ukraine cracks down on scam call centers. Researchers uncover two TP-Link camera zero-days. Maria Varmazis looks at weapons in space. CenterPoint Energy reports a data breach. Spain records its first breach caused by an autonomous AI agent. PhantomRaven targets developers through malicious npm packages. Illicit casinos provide cover for cybercrime. A New York healthcare provider exposes patient data. Our guest is Chad Thunberg, CISO at Yubico, on how real crypto-agility still needs a hardware root of trust. Hackers do a little Flock picking. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today Chad Thunberg, CISO at Yubico, discusses how software-only encryption is only half the answer: real crypto-agility still needs a hardware root of trust, not just a software patch. Selected Reading Coast Guard, FBI investigating after 2 oil tankers bound for US hit with cyberattacks (ABC News) US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware (SecurityWeek) Ukraine moves to crack down on scam call centers after corruption scandal (The Record) Zero-Day Flaw in TP-Link Cameras Enables Covert Eavesdropping (Infosecurity Magazine) CenterPoint Energy Discloses Data Breach Following Dark Web Claims of 7.5 Million Records Stolen (Beyond Machines) Spain gets its first taste of AI-aided cyber attack (The Register) PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting (CrowdStrike) How Money Laundering, Scams, and Espionage Hide in a Web Full of Casino Garbage (Infoblox) 280,000 Impacted by Premier Medical Group Data Breach (SecurityWeek) Meink: Space Force has deployed space control weapons to orbit (DefenseScoop) Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

  6. 6 days ago

    Pedal to the AI metal.

    The President pushes back on calls to slow AI. Microsoft lays out potential AI safety rules. Lawmakers consider the crypto Clarity Act. Florida’s Department of Highway Safety and Motor Vehicles and Japan’s Digital Agency suffer data breaches. Phishing campaigns grow increasingly difficult for email security tools to spot. New York seizes a dozen AI deepfake domains. Alleged Black Axe cybercriminals face charges. Our guest is Camille Stewart Gloster, former U.S. Deputy Cyber Director and author of the new book "The Insider You Built: How Organizations Stay in Control of Autonomous AI Agents." AI meets the long arm of the old law.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we’re joined by Camille Stewart Gloster, author of The Insider You Built: How Organizations Stay in Control of Autonomous AI Agents, and founder of CAS Strategies. We’ll discuss her new book and the broader questions it raises about AI agents. You can learn more about "The Insider You Built” here. Selected Reading Trump pushes back on Anthropic CEO's call for an AI slowdown (SC Media) Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints (SecurityWeek) Microsoft releases emergency Windows updates to fix RDS failures (Bleeping Computer) This bill could reshape crypto in America -- and it's sparking a major battle (NPR) Florida Department of Highway Safety hacked by international criminal group (WPTV) 240,000 Hit by Data Breach at Japan’s Digital Agency (SecurityWeek) VBSpam comparative review - Q3 (Virus Bulletin) New York Seizes 12 Celebrity Deepfake Websites (404 Media) Suspected Black Axe gang leaders face cybercrime charges in the US (Bleeping Computer) Ex-FTC boss Khan urges Uncle Sam to break out the handcuffs for AI CEOs, citing 1934 precedent (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

About

The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

You Might Also Like