CyberWire Daily

N2K Networks

The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

  1. hace 4 h

    Who’s watching the AI watchers?

    A watchdog challenges the Trump administration’s secret frontier AI reviews. METR discloses two cyberattacks. Leaked documents reveal a Russian cyber training pipeline. Rogue ScreenConnect clients spread malware like a worm. A breach exposes appellate court records across the U.S. and Canada. Spring Ring impersonates IT support on Microsoft Teams. Plex urges users to patch, and Cisco warns of unpatched Secure Email flaws. Our guest is Rob van der Veer, Chief AI Officer at Software Improvement Group, discussing how we are not keeping up with the AI attack surface. Robocall report cards.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Rob van der Veer, Chief AI Officer at Software Improvement Group, discussing how we are not keeping up with AI attack surface. Selected Reading Trump may be forced to reveal secret rules feds use for AI safety testing (Ars Technica) Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks (The Register) 2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators (Security Affairs) Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity (Huntress) A breach at Thomson Reuters reached appellate courts in twelve US jurisdictions (Thenextweb) Spring Ring Vishing Attack Uses Fake IT Calls on Microsoft Teams to Install Malware (Hackread) Plex warns users to patch security vulnerabilities immediately (Bleeping Computer) Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities (SecurityWeek) The FCC wants consumers to rate their telecom’s anti-robocall protections (CyberScoop) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  2. hace 1 día

    Drive-by data theft.

    Nexus sells driver’s license scans on the dark web. OpenAI says its models have reached a “Critical” capability threshold. International law enforcement disrupts a decades-old botnet. AI hallucinations fuel “slop squatting.” Plus, urgent patches for Cleo Harmony and Virtualizor, a Texas healthcare breach, and a Russian national accused of targeting thousands of freelancers with remote-access malware. Maria Varmazis shares the latest space-cyber news. Our guest is Rob Allen, Chief Product Officer at Threat Locker, talking about protecting against AI in the workplace. AI threatens the government’s bug supply. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today’s Industry Voices we are joined by Rob Allen, Chief Product Officer at Threat Locker, talking about protecting against AI in the workplace. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading FBI Probes Service Selling 153M+ Drivers Licenses (Krebs on Security) OpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity Threshold (SecurityWeek) Sality botnet infrastructure dismantled in joint global takedown (Bleeping Computer) Crooks Are Learning to Love AI Hallucinations (IEEE Spectrum) MSSA Reference Architecture 2.0 (Mobile Satellite Services Association (MSSA)) Exploit Published for Fresh Cleo Harmony Vulnerability (SecurityWeek) Malicious Virtualizor Update Served via BGP Hijacking (SecurityWeek) Nutex Health Says Patient Data Stolen, Hackers Threaten Leak (Infosecurity Magazine) US charges Russian for infecting 80,000 freelancers with malware (Bleeping Computer) How AI could make it harder for governments to use hacking tools (TechCrunch) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  3. hace 2 días

    Nightmare on Windows 11.

    Nightmare Eclipse drops a Kaspersky zero-day. The Financial Stability Board warns frontier AI could threaten the global financial system. Anthropic says it has tightened security. CISA adopts a risk-based approach to patching. A new Windows infostealer hides in fake AI models. A critical vulnerability in JFrog Artifactory is kneedeep in active exploitation. North Korean workers are still landing U.S. jobs. A classic NSA codebreaking machine. Our guest is Heather Ceylan, CISO at Box, discussing if AI becomes agentic, governance could become a resilience issue. A robot vacuum sucks up evidence.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices, we are joined by Heather Ceylan, CISO at Box, discussing as AI becomes agentic, governance becomes a resilience issue. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher (SecurityAffairs) Financial Stability Board Sounds the Alarm Over Frontier AI Risks (Infosecurity Magazine) Unit 42 warns AI has shifted balance of power from defenders to attackers (CyberScoop) Improving our alignment and security practices (Anthropic) CISA vulnerability directive designed to ‘buy back time’ against hackers (Federal News Network) RevStealer malware spread through fake Claude Opus 5 download (SC Media) Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild (SecurityWeek) North Korea-linked IT Workers Are Getting Hired Inside Western Companies (SecurityAffairs) IBM Built the Cold War's Most Powerful Code Breaker for the NSA (IEEE Spectrum) Man uses robot vacuum to covertly record his wife's affair, wins divorce settlement but gets sentenced to prison for making an illegal recording — Husband lands behind bars after counter-suit over privacy rights (Tom's Hardware) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  4. hace 3 días

    Let’s kill the kill switch.

    Could an AI kill switch create more problems than it solves? A critical Rails flaw is under active attack. Malicious browser extensions steal cryptocurrency. Fire Ant targets trusted network infrastructure. Claude Code gets tricked into running attacker-controlled code. MyChart phishing scams spread malware. Two alleged sextortionists face U.S. charges. A former DIA insider walks into an FBI sting. Monday business briefing. Our guest is Tim Starks from CyberScoop discussing a controversial retail security bill. Getting local with Nigerian scammers. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tim Starks from CyberScoop as he is discussing a controversial retail security bill. Selected Reading The AI Kill Switch Act is repeating the Clipper Chip’s mistakes (CyberScoop) Critical Ruby on Rails Vulnerability in Attackers' Crosshairs (SecurityWeek) Chrome Web Store extensions caught stealing crypto, browser data (Bleeping Computer) China-linked Fire Ant Hides Inside Trusted Infrastructure (SecurityAffairs) Researcher shows how Claude Code can be tricked simply by asking it to summarize a website (The Register) Fake MyChart emails can show alarming test results, trick patients into installing malware (WMAR) Nigerians extradited to US for sextortion, deaths of two teens (Bleeping Computer) US government snitch-finder pleads guilty to leaking state secrets to foreign spies (The Register) AI safety and security company Alice raises $140 million. (N2K Pro Business Briefing) How Cyber Sleuths Tracked a Nigerian Scammer to His Doorstep (404 media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  5. hace 6 días

    The blacklist boomerang.

    A judge rules the Trump administration illegally labeled Anthropic a national security risk. The White House moves to keep foreign technology out of U.S. power systems. OpenAI rallies a global cyber defense push as its own AI agents exploit a Linux vulnerability. Researchers uncover a new speculative-execution attack and hidden implants in Chinese-made routers. A fake voicemail campaign slips past email defenses. PaperCut faces an exploited zero-day. And ServiceNow patches three maximum-severity flaws in its AI Platform. Maria Varmazis and I look back at a decade of emerging threat actors and APTs. NSA sends out a covert save-the-date. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today, as we continue celebrating the CyberWire Daily’s 10th anniversary, Maria Varmazis and Dave Bittner look back at a decade of emerging threat actors and APTs. Enjoyed the conversation? Be sure to tune in Sunday for a special edition featuring the full discussion. Selected Reading Trump Administration’s Blacklisting of Anthropic Was Illegal, Judge Rules (The New York Times) White House bans foreign-made equipment for power generation over cyber backdoor concerns (The Record) Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge (SecurityWeek) A call for collective action on cyber defense (OpenAI) New type of attack can slip past the defenses in your computer’s processor (MIT News) Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign (Infosecurity Magazine) OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems (SecurityWeek) Hundreds of AI agents went rogue in OpenAI’s Hugging Face hack (POLITICO)  PaperCut Releases Emergency Patch for Exploited Zero-Day (SecurityWeek) ServiceNow warns of three max severity security vulnerabilities (Bleeping Computer) Chinese Implants in the Supply Chain (VulnCheck) Exclusive: NSA to host a hacker reunion in bid to rebuild secretive unit (The Record) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  6. 27 ago

    Meta gets a Meta-sized bill.

    Meta settles. Australian police arrest two alleged TeamPCP members. The White House moves to shore up water utility cybersecurity. ATF reports a major cyber incident. The Navy tells sailors to lock down social media. The FBI warns of a prolific Chinese hacking operation. Bill Gates sounds the alarm on AI. A purported think tank tries to influence chatbot answers. And attackers focus less on individual vulnerabilities and more on the vendors behind them. Our guest is Tim Springston, Principal Product Manager at Semperis, on achieving hybrid identity resilience in the age of agentic AI. Meta pumps the brakes on going AI native.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today’s industry voices segment, we are joined by Tim Springston, Principal Product Manager at Semperis, discussing how to achieve hybrid identity resilience in the age of agentic AI. If you enjoyed this conversation, check out the full interview here. Selected Reading Meta agrees to pay $18 billion to settle US lawsuits over children's social media addiction (Reuters) Two Alleged ‘TeamPCP’ Hackers Arrested in Australia (Krebs on Security) White House to unveil program to protect water systems against hackers (POLITICO) DOJ firearms agency says hackers breached system containing investigation targets (The Record) US Navy tells sailors and their families: scrub your social media, enemies are watching (Bitdefender) Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI Warns (Infosecurity Magazine) Bill Gates diagnoses problems with AI, but an expert questions his prescription (ABC News) Fake US thinktank set up and funded by Israel sought to game AI for propaganda (The Guardian) SentinelOne and Tenable Find Cyber Attackers Routinely Target Edge-Device Vendor Ecosystems Rather Than Individual Vulnerabilities (SentinelOne) AI agents meant to replace Meta workers made “large-scale, disruptive actions” (Ars Technica) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Acerca de

The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

También te podría interesar