CyberWire Daily

N2K Networks

The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

  1. 8h ago

    NPM? Not my problem.

    New Shai-Hulud campaign compromises popular npm packages. Easterly says small municipalities shouldn’t have to fend for themselves. Chinese threat groups accelerate exploits. Samsung bans smart TV apps with residential proxies. Hackers breach a Liechtenstein banking database. Swiss government IT agency hit in suspected SharePoint Attack. Microsoft’s bug bounty program awards record payouts. Researchers expose privilege boundary flaw in AI-driven CI/CD workflows. Roberta Anderson, Air Force veteran and CISO at Onterris is sharing her "Breaking the Firewall" book. And, bug hunting turns into bug sorting.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Roberta Anderson, Air Force veteran and CISO at Onterris, sharing her "Breaking the Firewall" book. Selected Reading Keyv and friends compromised in npm supply chain attack (Aikido) Small Towns Shouldn’t Have to Defend America’s Water Supply From Iran (The New York Times) China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day (Infosecurity Magazine) Samsung bans smart TV apps that share users' internet connections with strangers (TechCrunch) Liechtenstein says hackers access information on 31,000 legal entities (Reuters) Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected (The Record)  Microsoft Bounty Program year in review More than $20 million awarded in our biggest year yet (Microsoft Security Response Center) I'll Just Call You: Agent-to-Agent Privilege Boundary Failures in CI/CD on Google's ADK Repository (Pillar Security)  Apple struggles to keep pace with AI ‘bug’ hunters (Financial Times) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  2. 1d ago

    Water you waiting for?

    Cyberattacks hit U.S. water systems. CISA tackles open source security. China’s surveillance machine is exposed. Hotel Wi-Fi gets riskier. Healthcare and police data spill online. Fake SQLite vulnerabilities fool security databases. Monday business briefing. Our guest is Tim Starks from CyberScoop discussing the White House's quantum aspirations. AI is the hottest thing on campus. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tim Starks, Senior Reporter from CyberScoop, discussing the White House's quantum aspirations. Selected Reading Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran (The New York Times) CISA lays out new guidance for using open-source software (Help Net Security) How China Keeps Tabs on Foreigners (The New York Times) Microsoft Issues Hotel Wi-Fi Warning For Windows PC Users (Forbes) Exclusive: Partnered Health responds to Inc Ransom data breach claims (Cyber Daily) Security Flaw Placed 30 Years of DNA Evidence at Risk of Hacking (Wall Street Journal) SQLite Critical CVEs or LLM Slop? (JFrog Security Research) Details of 100,000 police staff leaked on the dark web after hack (The Times) ThreatLocker secures $190 million in a Series F round led by Elephant (N2K Pro Business Briefing) At colleges, the AI boom means everyone wants to dabble in computer science (AP News) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  3. 4d ago

    Claude outside the lines.

    Anthropic says Claude escaped the sandbox three times, while a judge questions the Pentagon’s blacklist. The EU launches an AI enforcement team, the FTC targets a telehealth firm’s tracking pixels, and a WordPress backdoor is stopped just in time. CareCloud discloses a major data breach, a stealthy cryptominer hides in plain sight, AiTM phishing surges against law firms, and Finland severs one more digital link to Russia. Our guest is Yan Shoshitaishvili, Associate Professor, Arizona State University, previewing his Black Hat 2026 keynote "Vulnerability Research in the Agentic Age." AI scammers may deserve a promotion. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Yan Shoshitaishvili, Associate Professor, Arizona State University, discussing his Black Hat 2026 keynote "Vulnerability Research in the Agentic Age." Be sure to tune in this Sunday for a special edition featuring our full, extended interview with Yan. Selected Reading Anthropic AI Models Hacked Three Organizations During Tests (Bloomberg) Anthropic, Pentagon Clash Over First Amendment Claims (GovInfo Security) EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels (SecurityWeek) FTC sues Hims & Hers for allegedly sharing patients' medical data with advertisers Meta and Snap (TechCrunch) Wordfence Finds Critical Backdoor in ARVE WordPress Plugin (Hackread) CareCloud Data Breach Impacts Over 350,000 (SecurityWeek) Cryptominer Abuses Linux PAM to Hide From SOC Analysts (Infosecurity Magazine) AiTM Phishing Becomes Top Initial Access Threat to Law Firms (Infosecurity Magazine) Finland to disconnect fiber-optic link to Russia as lease expires (The Record) AI Scammers Are Better at Building Trust Than Humans (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  4. 5d ago

    Building a great firewall around AI.

    China embraces open AI models, then worries it’s become a national security risk. The cyberattack on Minnesota water systems proves larger than first reported. CISA updates its SBOM guidance. AI supercharges dangling DNS attacks. Researchers uncover a self-propagating Copilot worm. A critical Rails flaw demands urgent patching. Mac users are lured into installing malware through fake Claude guides. Amazon links a string of NPM compromises to North Korea. And Russia charges Telegram founder Pavel Durov with aiding terrorism. Ben Yelin joins us with a border search case that’s breaking new ground. Don’t bite the North Korean hand that feeds you. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies talking about a border search case that’s breaking new ground. If you enjoyed this conversation, check out Ben on the Caveat podcast here.  Selected Reading As China’s A.I. Gets Stronger, It Poses New Risks to Beijing (New York Times) Minnesota Water Utilities Suffer ‘Coordinated Cyber Attack’ (GovTech) CISA Updates Software Bill of Materials Guidance to Strengthen Supply Chain Security (HSToday) ‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale (SecurityWeek) Word worm crawls into Copilot, spreads chaos (The Register) Possible arbitrary file read and remote code execution in Active Storage variant processing (GitHub) Fake Claude Install Guide Leads to MacSync Stealer and RAT: What We Pulled From the Attacker's Servers (Huntress) Amazon identifies North Korean hacker group behind open-source supply chain attacks (AWS Security Blog) Russia accuses Telegram CEO Pavel Durov of aiding terrorism in its latest digital crackdown (AP News) North Korea's elite hackers turned on their own government — and got caught (Bitdefender) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

  5. 6d ago

    More than meets the AI.

    The Senate confirms Jay Clayton to lead ODNI. A new CISA framework highlights critical infrastructure isolation capabilities. OpenAI’s rogue agent breached more than just Hugging Face. The average cost of a data breach continues to rise. Indirect prompt injection proves irresistible to cyber criminals. Broadcom patches multiple VMware products. ShinyHunters claims responsibility for Ernst & Young’s recent breach. Our guest is Sean Zadig, CISO at Yahoo, discussing the impact of AI on the defense side. These aren’t the droids you’re looking for. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Sean Zadig, CISO at Yahoo, discussing the impact of AI on the defense side without all the hype in either direction, what is a CISO actually doing about it. Selected Reading Senate Confirms Jay Clayton to Lead U.S. Intelligence Community (The New York Times) China and Iran Are Already Inside US Grids: CISA Demands Tested Isolation Plans (Tech Times) OpenAI's rogue agent compromised a customer at a second tech firm, executive says (Reuters) Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident (Hugging Face) The Average Cost of a Data Breach Rises to $5 Million (Infosecurity Magazine) USSPACECOM Issues Space Warfighting Environment 2040 for Joint Force Space Operations (ExecutiveGov) THE SPACE WARFIGHTING ENVIRONMENT 2040 Framing the Future for the Joint Warfighter (U.S. Space Command)  Notes from Underground: Adversarial Prompt Injection (Proofpoint) Critical VM Escape Vulnerability Patched in VMware ESXi (SecurityWeek) ShinyHunters Claims Ernst & Young Hack (SecurityWeek) America bans imported robots due to supply chain and security risks (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

4.8
out of 5
1,014 Ratings

About

The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

You Might Also Like