CyberWire Daily

N2K Networks

The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

  1. 2h ago

    The pay system needs a patch.

    Military cyber personnel face pay cuts. A critical RCE threatens banking and government authentication systems. Dell patches a critical update flaw. A missed patch costs Accenture an FBI contract. Hackers hijack a fashion retailer’s push notifications. Insurers brace for rogue AI claims. Hackers breach a supertanker’s propulsion system. Denmark suffers a massive population data breach. And Japan extradites a suspected Qilin ransomware operator. Our guest is Steve Ryan, Founder and CEO of Trinity Cyber, on surviving first contact from a Frontier AI-enabled cyber threat. There’s no honor among Gentlemen.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On our Industry Voices segment, we are joined by Steve Ryan, Founder and CEO of Trinity Cyber, talking about surviving first contact from a Frontier AI-enabled cyber threat. If you enjoyed this conversation, check out the full interview here. Selected Reading The Pentagon’s new cyber mastery incentive model promised a ‘new era.’ Troops are bracing for pay cuts. (DefenseScoop) Critical CVE-2026-18397: Remote Code Execution Vulnerability in Thales SConnect Threatens SWIFT Banking and Government Authentication Systems (Rescana) Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access (Security Affairs) FBI Drops Accenture Contractor After Sensitive Data Breach (Security Affairs) Asos customers receive ‘hack’ notification threatening to leak data (The Guardian) Insurance claims to test Altman and Amodei liability for ‘rogue’ AI (Financial Times) Hackers Breached Propulsion System of US-Bound Oil Tanker (Bloomberg) 8.8 Million Impacted by Data Breach at Denmark’s Central Person Register (SecurityWeek) World's Largest Ransomware Group Qilin Member Arrested in Japan (The Chosun Daily) Ransomware Affiliate Double-Crosses RaaS Operator to Steal Victim Funds (Infosecurity Magazine) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

  2. 1d ago

    A new AI task force takes shape.

    The President launches a new federal AI task force. South Korea investigates financial sector data leaks. AI slop overwhelms a Google bug bounty program. Citrix patches an exploited zero-day. Stealthy malware hides inside Asian email security appliances. Apple tightens macOS privacy around AI agents. Attackers exploit a critical Rejetto File Server flaw. The Senate advances healthcare cybersecurity legislation. Monday business briefing. Our guest is Jared Shepard, CEO of Hypori, with insights on how the military is adopting AI technologies. A real good password…isnt’. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Jared Shepard, CEO of Hypori, sharing how he sees the military and DoW adopting AI technologies. Selected Reading Trump names national intelligence director Jay Clayton to lead a new federal AI task force (AP News) South Korean president orders probe into data leaks across financial industry (Reuters) Google freezes open-source bug bounty program amid flood of invalid AI slop submissions — product flaw submissions halted until 2027 as maintainers drown in hallucinations (Tom's Hardware) Citrix patches NetScaler SAML zero-day exploited in attacks (Bleeping Computer) New Linux malware mimics network edge appliances to evade detection (SC Media) Apple changes full-disk access permissions to curb abuse from AI agents (Ars Technica) Exploitation Hits Rejetto HFS Vulnerability Discovered by AI (SecurityWeek) Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity (SecurityWeek) Island raises $400 million in a Series F round. (N2K Pro Business Briefing) CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

  3. 2d ago

    Earth’s expanding attack surface. [T-Minus: Space-Cyber Briefing]

    As space infrastructure expands, so too does the need for cybersecurity expertise beyond securing traditional spacecraft. Host Maria Varmazis speaks with ⁠Milenk Starcevic⁠, Head of Cybersecurity at ⁠Vision Space⁠, and ⁠Andrzej “Andy” Olchawa⁠, Senior Cybersecurity Engineer also at Vision Space, about the growing space cybersecurity field. They discuss the role of compliance and auditing, how cybersecurity professional can develop space-specific skills, and how emerging capabilities are expanding the attack surface. Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: ⁠⁠⁠⁠⁠⁠⁠⁠⁠https://thecyberwire.com/newsletters/signals-and-space⁠⁠⁠⁠⁠⁠⁠⁠⁠ Key Sources: ⁠The Spacecraft Hacker's Handbook.⁠ Space cybersecurity starts on the ground. Hack the Box. Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to ⁠⁠⁠⁠⁠⁠⁠⁠⁠space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: ⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.surveymonkey.com/r/NJYCN2P ⁠⁠⁠⁠⁠⁠⁠⁠⁠ T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. ⁠⁠⁠⁠⁠⁠⁠⁠⁠N2K⁠⁠⁠⁠⁠⁠⁠⁠⁠ is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at ⁠⁠⁠⁠⁠⁠⁠⁠⁠n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠. Learn more about your ad choices. Visit megaphone.fm/adchoices

    Earth’s expanding attack surface. [T-Minus: Space-Cyber Briefing]
  4. 4d ago

    A rough week for safety.

    OpenAI fires safety researchers for mishandling sensitive information. CISA looks to secure the next 250. Dell patches six critical flaws, while attackers exploit a FortiMail zero-day. Warlock ransomware expands its reach, and Star Blizzard scales up its phishing. Researchers map maritime GPS spoofing. An alleged Iranian hacker is extradited to the U.S., and law enforcement takes down KillSec. Our guests are John Kindervag and Dr. Chase Cunningham, discussing their new book "Cyber Resilience at Machine Speed: The Zero Trust Model for the AI Era". Clippy’s back, and this time he wants your wallet.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by John Kindervag, along with Dr. Chase Cunningham, discussing their book "Cyber Resilience at Machine Speed: The Zero Trust Model for the AI Era". Selected Reading Disinformation, Defense and Democracy: A Look as This Year’s Election Security (Security Magazine) CISA launches ‘Securing the Next 250’ campaign to strengthen critical infrastructure cybersecurity and resilience (Industrial Cyber) Dell asks admins to patch max severity CSM flaws as soon as possible (Bleeping Computer) Fortinet warns of critical FortiMail flaw exploited in zero-day attacks (Bleeping Computer) Chinese ransomware group Warlock targets Spanish- and Portuguese-speaking countries (SC Media) Russian FSB-linked hackers scale up phishing attacks against Ukraine supporters (The Record) 367,000-Ship Study Finds Global GPS Spoofing, Red Sea Activity Before Grounding (Hackread) In Rare Move, Alleged Iranian State Hacker Extradited to US (SecurityWeek) Police Target KillSec Ransomware Group with Arrests and Seizures (Infosecurity Magazine) Crypto Scammers Hijack Microsoft's Official X Account  (SecurityWeek) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

  5. 5d ago

    The Pentagon’s roll call.

    A Pentagon breach exposes data on millions. ShinyHunters goes dark. MI5 warns universities about Chinese espionage. AI agents find creative ways around their guardrails. A fake Zoom installer delivers macOS malware. Cisco patches an actively exploited SD-WAN flaw. OpenAI disrupts a “distillation attack.” Cyber Command confronts operator burnout. Treasury targets alleged ATM jackpotters. Our guest is Etay Maor, Vice President of Threat Intelligence at Cato Networks, with a reminder that your network isn't a recycling bin. Prophecy as a service. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Etay Maor, Vice President of Threat Intelligence at Cato Networks, sharing his views on how your network isn't a recycling bin. Selected Reading Hackers stole millions of US military personnel records during months-long data breach (TechCrunch) ShinyHunters website goes offline after FBI deadline expires (Reuters) MI5 Warns Over 100 Academics Helped China's Espionage Plans (Infosecurity Magazine) Rogue Agents Investigation (Asymmetric Security) CloudSyncD: macOS backdoor hidden in a fake Zoom installer (Jamf) Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability (SecurityWeek) Irony alert: OpenAI whines that Chinese model stole its special IP that it stole from everybody else (The Register) After reports on suicide deaths, Pentagon puts Cyber Command on notice (The Record) Treasury Blacklists Most-Wanted ATM Malware Developer and His Network (SecurityWeek) Chatbots as oracles: How AI is giving new life to the ancient practice of seeking answers from inscrutable sources (The Conversation) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

  6. 6d ago

    The guardrails go to court.

    AI companies sign a voluntary accord aimed at addressing safety concerns. Cybercriminals abuse the CustomGPT feature as part of a ClickFix campaign. The FBI is urging members of ShinyHunters to come forward. A fraud campaign turns stolen credentials into job scams. Maria Varmazis joins us for her space cyber story. The WaterISAC confronts persistent weaknesses. AI gives SOC teams more time at the expense of training. Two U.S. Air Force members get federal prison time over a business email compromise scheme. Our guest is Dan Ohlemeier, Senior Solutions Architect for Ready1 at Semperis, discussing crisis orchestration. That is one big pile of technical debt. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today’s Industry Voices we are joined by Dan Ohlemeier, Senior Solutions Architect for Ready1 at Semperis, discussing crisis orchestration: the unsung hero of successful cyber incident response. If you enjoyed this conversation, tune into the full interview here. Selected Reading Trump says top tech firms have signed accord to 'self-police' AI development (NPR) OpenAI Ignored Employees’ Warnings About Safely Testing A.I. Models (The New York Times) OpenAI Gets Sued Over the Hugging Face Hack (WIRED) Attackers Combine ChatGPT Feature Abuse With ClickFix to Deliver Trojan Malware (Infosecurity Magazine) ShinyHunters Defiant After FBI Calls on Members to Come Forward (SecurityWeek) From EDU Account Takeover to Job Scam Abuse: West African Fraud Actors Target Universities (Proofpoint) SpaceX's Starship returns early to Earth after reaching orbit for the first time (AP News)  WaterISAC reckons with range of threats after summer of cyberattacks (CyberScoop) AI Boosts SOC Analyst Capacity but Limits Skill Development (Infosecurity Magazine) US Air Force members given over 6 years in prison for cyber theft of more than $2 million (The Record) AI Finds a Way: The Jurassic Park Problem (Securonix) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

  7. Sep 29

    Astra, la vista, baby.

    OpenAI holds back its newest model over safety concerns. Kiteworks lifts its precautionary shutdown. Apple patches an exploited zero-day. Japanese rail operators disclose cyberattacks. An Anthropic authentication flaw opens the door to account takeover. Thousands of Supabase databases leak data. NeedyMantis targets telecoms and governments. A Vietnamese national faces charges in a multimillion-dollar crypto laundering scheme. James Winebrenner, CEO of Elisity, is sharing barriers to compliance and challenges for manufacturers as the EU Cyber Resilience Act is implemented. If you’re hoping for credit, be careful what you share. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest James Winebrenner, CEO of Elisity, is sharing barriers to compliance and challenges for manufacturers as the EU Cyber Resilience Act (EU CRA) is implemented. Selected Reading OpenAI Says It Will Not Release Newest Astra A.I. Model Over Safety Concerns (The New York Times) Florida asks for order to halt ChatGPT development (Axios) Kiteworks Urges Customers to Restart Systems After Shutdown Notice (Infosecurity Magazine) Apple patches CoreGraphics zero-day flaw exploited in attacks (Bleeping Computer) Japanese Railway Operators Hit with Weekend Cyber Attacks (Infosecurity Magazine) Cycode Uncovers Account Takeover in Anthropic's MCP Python SDK (Cycode) Everything Everywhere: Systemic Data Exposure in Supabase Apps (UpGuard) Daemon Tools Hackers' NeedyMantis Malware Dissected by Microsoft (SecurityWeek) Vietnamese man charged in $16 million 'pig butchering' crypto scam (Bleeping Computer) Did Anthropic’s A.I. Really Make a Scientific Discovery on Its Own? (The New York Times) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

4.8
out of 5
1,020 Ratings

About

The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

You Might Also Like