CyberWire Daily
N2K Networks
0
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
ตอน
-
Storm clouds over the waterworks. 22.09.2026 27นาทีCISA rides out a Cyber Storm. The EU struggles to share cyber threat information. Nightmare Eclipse drops another Defender zero-day. TASK#STOMP steals business documents. North Korean operatives fake their way through job interviews. A genetics lab pays $700,000 over a phishing breach. A zero-day in Meta’s Muse AI assistant opens the door to privilege hijacking. Marc Woolward, Senior Advisor to Humanix and former CTO for Goldman Sachs, discussing social engineering and vishing attacks. Infiltrating Team PCP. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Marc Woolward, former CTO for Goldman Sachs and Senior Advisor to Humanix, discussing social engineering/vishing attacks and how ShinyHunters continues to use this method on other industries. Selected Reading CISA’s Cyber Storm X tests cybersecurity preparedness across transportation, water and wastewater sectors (Industrial Cyber) Another worry for water systems: infostealer exposure (CyberScoop) Poor data sharing undermining EU cyber defences, auditors say (Reuters) New TASK#STOMP Windows Backdoor Enables Continuous Document Theft (Hackread) New Windows Defender zero-day blocks Microsoft antivirus updates (Bleeping Computer) Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme (SecurityWeek) Ambry Genetics Pays $700K HIPAA Fine in Phishing Breach (GovInfo Security) Meta Muse AI app flaw lets local malware redirect dictation traffic (The Register) An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices -
A very real-world AI test. 21.09.2026 29นาทีGoogle confirms unauthorized access by Gemini. AI’s growing power outpaces its defenses. Hackers target Colorado water utilities. Georgia weighs voting-system security. ShinyHunters hijacks Clop’s leak site. FamousSparrow spies across Latin America. CrowdSec loses source code. New npm malware slips past supply-chain defenses. Monday business briefing. Our guest is Matt Fredrikson, CEO of Gray Swan AI, discussing OpenAI's Astra. A new app warns Glassholes to ZuckOff. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Matt Fredrikson, Carnegie Mellon University Associate Professor and CEO of Gray Swan AI, discussing OpenAI's Astra and real industry risks. Selected Reading Google says Gemini breached three companies during security test (The Record) Hackers who broke into OpenAI warn the AI industry has a security problem (Washington Post) Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems (Security Week) Lawmakers mull cybersecurity concerns as they prepare for overhaul of Georgia’s voting system (Cobb Courier) Clop gets a taste of its own medicine after ShinyHunters hijack leak site (The Register) China-Linked FamousSparrow Deploys SparroWocky Backdoor in Latin America (Hackread) CrowdSec Confirms Source Code Stolen in Supply Chain Attack (Security Week) Malicious npm packages evade install-script defenses at runtime (Bleeping Computer) Physical AI security company Exein lands $270 million. (N2K Networks) ZuckOff Is a Free App That Sees Meta Glasses Before They See You (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices -
CyberWire Daily at 10: Critical infrastructure attacks over the last 10 years. [Special Edition] 20.09.2026 43นาทีIn this Special Edition episode, Maria Varmazis and Dave Bittner from N2K Cyberwire get back together to reflect on the past decade of critical infrastructure attacks, evolving threats, and lessons learned from incidents like the Ukraine power grid attack and Colonial Pipeline ransomware. They discuss how these events have shaped current cybersecurity practices and the importance of resilience and preparedness. Join Maria and Dave as they discuss: The critical infrastructure evolution over the past 10 years. Notable cyber attacks including the Ukraine power grid, NotPetya, and the Colonial Pipeline. The shift from traditional ransomware attacks to attacks on infrastructure. The emergence of space and satellite communications as targets. Lessons learned and the future outlook for cybersecurity resilience. Learn more about your ad choices. Visit megaphone.fm/adchoices -
Defending Space as Critical Infrastructure. [T-Minus: Space-Cyber Briefing] 20.09.2026 26นาทีSpace infrastructure has become an increasingly important part of everyday life, which has also made it an increasingly attractive target for exploitation. Host Maria Varmazis and Sean MacKirdy, Area Vice President for the National Security vertical at Elastic Government Solutions, sit down to discuss how space stakeholders need to reevaluate their approach to securing space systems. As space systems continue to grow more important, malicious actors are going to look to target them more often. By adopting a stronger universal framework and a consistent way to interpret data across all spacecraft, space cybersecurity practitioners will be able to standardize their practices and create more effective and timely responses. Key Sources: SPARTA v4.0 Maria Varmazis interviews Brandon Bailey about Space Attack Research and Tactic Analysis, or SPARTA matrix. Like what you heard? Be sure to subscribe to our free Signals and Space Briefing, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to [email protected]. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com. Learn more about your ad choices. Visit megaphone.fm/adchoices -
All about that proxy. [Research Saturday] 19.09.2026 25นาทีToday we are joined by Dr. Renée Burton, VP of Threat Intelligence at Infoblox, discussing their work on Lurking Lizard, "Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real." The research uncovers Lurking Lizard, a threat actor that has operated since at least 2022 by using fake software installers, VPNs, and lookalike domains to secretly turn victims’ devices into residential proxy nodes. Researchers identified more than 230 related domains and connected seemingly separate campaigns—including fake 7-Zip, downloader tools, and WireVPN—through shared infrastructure, tracking URLs, deployment patterns, and APIs. The investigation suggests the actor runs an end-to-end proxy operation, recruiting compromised devices and then monetizing their bandwidth through proxy services and fake review sites, with WireVPN appearing to be the latest evolution of the campaign. The research and executive brief can be found here: Fake Installers, Fake Reviews, Fake Services - Real Proxies, Real Victims Learn more about your ad choices. Visit megaphone.fm/adchoices -
The Cisco root route. 18.09.2026 28นาทีCisco patches a maximum-severity vulnerability in its Identity Services Engine. Court documents describe AI as “an astonishing theft of unprecedented proportions.” Researchers chain vulnerabilities to take over employee ChatGPT accounts. Microsoft and Check Point patch vulnerabilities. Manufacturing remains ransomware’s favorite target. Hackers compromise a Japanese image-sharing service. The Settra ransomware group leverages remote management software. An Australian think-tank warns of Chinese AI-enabled surveillance in Venezuela. Maria Varmazis joins me for a look back at ten years of critical infrastructure exploits. Everything you wanted to know about AI but were afraid to prompt. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Dave Bittner and Maria Varmazis reflect on the past decade of critical infrastructure attacks, looking at major incidents like the Ukraine power grid attack and Colonial Pipeline and the lessons they’ve taught the industry about resilience and preparedness. If you enjoyed this conversation, be sure to tune in this Sunday for a special edition of the show, where Dave and Maria continue the conversation. Selected Reading Cisco drops another exploited zero-day, this time a perfect 10 (The Register) ‘Doom Loop’: OpenAI and Microsoft Admits LLMs Are Destroying the Web and Built on Theft (404 Media) AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code (SecurityWeek) Microsoft Patches 18 Vulnerabilities in AI, Cloud Products (SecurityWeek) New Check Point flaw lets hackers execute code with root privileges (Bleeping Computer) Manufacturing Accounts for 22% of all Ransomware Victims (Infosecurity Magazine) 23 Million User Records Compromised in Gyazo Data Breach (SecurityWeek) Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM (Huntress) USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech (The Register) Will A.I. Kill Us? Can It Hack My Bank Account? Your A.I. Questions Answered (New York Times) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices -
AI is calling the shots. 17.09.2026 29นาทีAI goes to war. Iranian strikes leave AWS data unrecoverable. OpenAI discloses more model misbehavior. Researchers uncover 16 Wireshark vulnerabilities. TrustSink turns Entra authentication into a password trap. RatHat raids Android credentials. The FBI takes down a DDoS-for-hire service. A data broker loses its domains. U.S. Cyber Command names a new AI chief. Ethan Cook is joining Dave Bittner and Ben Yelin to discuss the industry-proposed and administration-opposed AI slowdown. CISA’s field of schemes. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today, Ethan Cook, N2K’s lead analyst, joins Dave Bittner and Ben Yelin for a discussion about the industry-proposed and administration-opposed AI slowdown, exploring the policy debate and what it could mean for the future of AI. If you enjoyed this conversation, be sure to check out the full interview on Caveat here. Selected Reading The era of AI warfare has arrived (Financial Times) Iran strikes on Amazon data centers caused permanent loss of customer data (Ars Technica) OpenAI Discloses Six New Incidents of ‘Concerning' A.I. Behavior (The New York Times) AISLE Discovers 16 CVEs in Wireshark, the World’s Most Popular Network Protocol Analyzer (AISLE) TrustSink: How a Rogue External MFA Provider Steals Passwords (Varonis) RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts (Zimperium) US takes down NightmareStresser DDoS-for-hire platform (Bleeping Computer) Data Broker Radaris Loses Domains in Privacy Fight (Krebs on Security) Former NGA Executive Ronzelle Green Named USCYBERCOM Chief AI Officer (ExecutiveGov) CISA releases Cyber Decoys guide detailing tripwires, honeytokens to strengthen critical infrastructure detection and response (Industrial Cyber) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices -
Cybercrime finds its sea legs. 16.09.2026 29นาทีOfficials investigate suspected cyberattacks on U.S.-bound oil tankers. Iranian operators deploy Chosen Brick surveillance malware. Ukraine cracks down on scam call centers. Researchers uncover two TP-Link camera zero-days. Maria Varmazis looks at weapons in space. CenterPoint Energy reports a data breach. Spain records its first breach caused by an autonomous AI agent. PhantomRaven targets developers through malicious npm packages. Illicit casinos provide cover for cybercrime. A New York healthcare provider exposes patient data. Our guest is Chad Thunberg, CISO at Yubico, on how real crypto-agility still needs a hardware root of trust. Hackers do a little Flock picking. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today Chad Thunberg, CISO at Yubico, discusses how software-only encryption is only half the answer: real crypto-agility still needs a hardware root of trust, not just a software patch. Selected Reading Coast Guard, FBI investigating after 2 oil tankers bound for US hit with cyberattacks (ABC News) US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware (SecurityWeek) Ukraine moves to crack down on scam call centers after corruption scandal (The Record) Zero-Day Flaw in TP-Link Cameras Enables Covert Eavesdropping (Infosecurity Magazine) CenterPoint Energy Discloses Data Breach Following Dark Web Claims of 7.5 Million Records Stolen (Beyond Machines) Spain gets its first taste of AI-aided cyber attack (The Register) PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting (CrowdStrike) How Money Laundering, Scams, and Espionage Hide in a Web Full of Casino Garbage (Infoblox) 280,000 Impacted by Premier Medical Group Data Breach (SecurityWeek) Meink: Space Force has deployed space control weapons to orbit (DefenseScoop) Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices -
Pedal to the AI metal. 15.09.2026 28นาทีThe President pushes back on calls to slow AI. Microsoft lays out potential AI safety rules. Lawmakers consider the crypto Clarity Act. Florida’s Department of Highway Safety and Motor Vehicles and Japan’s Digital Agency suffer data breaches. Phishing campaigns grow increasingly difficult for email security tools to spot. New York seizes a dozen AI deepfake domains. Alleged Black Axe cybercriminals face charges. Our guest is Camille Stewart Gloster, former U.S. Deputy Cyber Director and author of the new book "The Insider You Built: How Organizations Stay in Control of Autonomous AI Agents." AI meets the long arm of the old law. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we’re joined by Camille Stewart Gloster, author of The Insider You Built: How Organizations Stay in Control of Autonomous AI Agents, and founder of CAS Strategies. We’ll discuss her new book and the broader questions it raises about AI agents. You can learn more about "The Insider You Built” here. Selected Reading Trump pushes back on Anthropic CEO's call for an AI slowdown (SC Media) Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints (SecurityWeek) Microsoft releases emergency Windows updates to fix RDS failures (Bleeping Computer) This bill could reshape crypto in America -- and it's sparking a major battle (NPR) Florida Department of Highway Safety hacked by international criminal group (WPTV) 240,000 Hit by Data Breach at Japan’s Digital Agency (SecurityWeek) VBSpam comparative review - Q3 (Virus Bulletin) New York Seizes 12 Celebrity Deepfake Websites (404 Media) Suspected Black Axe gang leaders face cybercrime charges in the US (Bleeping Computer) Ex-FTC boss Khan urges Uncle Sam to break out the handcuffs for AI CEOs, citing 1934 precedent (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices -
Bigfoot in the neural network. 14.09.2026 27นาทีNSA preps a major restructuring. Anthropic’s CEO calls for an AI slowdown. China acknowledges AI risks. RubyGems got swarmed by AI agents. A maximum-severity GitLab vulnerability is under active exploitation. Direct Send abuse makes phishing emails appear legit. A British fintech firm leaks sensitive customer info. LinkedIn wins a legal dispute over browser extension scanning. Monday business briefing. Our guest is Tim Starks, senior reporter at CyberScoop, sharing government leaders’ outlook for cybersecurity and AI at the Billington Cybersecurity Summit. Finding Bigfoot in the neural network. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest We are joined by Tim Starks, senior reporter at CyberScoop, sharing government leaders’ outlook for cybersecurity and AI at the Billington Cybersecurity Summit. You can read Tim’s coverage here. Selected Reading National Security Agency launches historic restructuring (The Washington Post) Anthropic CEO Calls for an AI Slowdown. Is It Possible? (SecurityAffairs) China’s spy agency warns of AI risk to national security (Financial Times) OpenAI Agent Swarm Hacks RubyGems Package Manager (Infosecurity Magazine) CISA: Hackers now exploit max severity GitLab flaw in attacks (Bleeping Computer) Direct Send: How Attackers Weaponize Your Infrastructure Against You (KnowBe4) Revolut discloses data breach exposing financial info, passports (Bleeping Computer) LinkedIn beats "BrowserGate" lawsuits over scanning users' Chrome extensions (Ars Technica) NVIDIA to acquire Hugging Face for $12.9 billion. (N2K Pro Business Briefing) Sentient AI's Bigfoot Era Could Arrive at Any Moment (Gizmodo) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices -
Space's cybersecurity policy problem. [T-Minus: Space-Cyber Briefing] 13.09.2026 22นาทีAs space becomes increasingly connected and autonomous, effective cybersecurity policy is struggling to keep pace. Host Maria Varmazis and Dr. Mac McGuire sit down to discuss the limitations of current approaches for managing space cyber risks and what the industry is lacking. The two discuss how the space incidents have the potential to significant impact astronauts by disrupting oxygen systems, thermal regulation, and telemetry. Like what you heard? Be sure to subscribe to our free Signals and Space Briefing, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to [email protected]. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com. Learn more about your ad choices. Visit megaphone.fm/adchoices -
A beast by any other name. [Research Saturday] 12.09.2026 23นาทีToday we are joined by Brigid O Gorman, Senior Intelligence Analyst on Symantec Threat Hunter team, discussing their work on “GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses." GodDamn ransomware, the latest rebrand from the Hyadina group behind Monster and Beast, is using increasingly sophisticated techniques to evade defenses. In a recent attack, the threat actors used AnyDesk for remote access, a broad credential-harvesting toolkit, and the PoisonX malicious kernel driver to disable endpoint security before deploying the ransomware. The activity highlights Hyadina’s continued development of its ransomware operations and an escalation in its defense-evasion capabilities. The research and executive brief can be found here: GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses Learn more about your ad choices. Visit megaphone.fm/adchoices -
You might want to watch what you say. 11.09.2026 29นาทีWeWorm has China’s attention. Calls for an AI slowdown continue. OpenAI calls for mandatory AI regulation. Anthropic disrupts Russian cyberespionage. The EU’s 24 hour reporting requirement goes into effect. GitLab and Check Point patch critical vulnerabilities. IDScan confirms theft of IDs. Microsoft tracks a cloud intrusion campaign. Our guest is Kevin E. Greene, Chief Cybersecurity Technologist, Public Sector at BeyondTrust, discussing the role of privilege disruption in cyber resiliency. Watch what you say. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Kevin E Greene, Chief Cybersecurity Technologist, Public Sector at BeyondTrust, discussing the role of privilege disruption in cyber resiliency. Selected Reading For China, a Mock A.I. Attack on WeChat Signals a Dangerous New Era (The New York Times) This Is Really Bad (The New York Times) OpenAI Calls for Mandatory National AI Safety Rules (BankInfo Security) Anthropic caught Russia-linked spies using Claude in hacking operations (The Record) EU's Cyber Resilience Act starts the 24-hour vulnerability clock (The Register) GitLab urges users to patch max severity path traversal flaw (Bleeping Computer) Check Point Patches Critical VPN Vulnerabilities (SecurityWeek) ID verification giant IDScan confirms data breach with more than 150 million driver's licenses stolen (TechCrunch) Passkey-themed social engineering leads to identity and cloud compromise (Microsoft Security Blog) Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices -
Making cybercrime more difficult. 10.09.2026 28นาทีThe FBI lays out its new Cyber Strategy. CISA plans a federal cyber overhaul. Anthropic discloses another unauthorized AI intrusion. Treasury sanctions a Chinese-language cybercrime marketplace. Another Microsoft Defender zero-day emerges. Gigabud banking malware gets stealthier. Chinese espionage groups deploy the BlueMoon exploit kit. Lawmakers target hack-for-hire firms. A U.S. designation forces an Italian technology collective to shut down. Ben Yelin discusses how private AI chatbot conversations are increasingly being used as evidence in court cases. When proofs meet prompts. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Dave Bittner sits down with Caveat cohost and University of Maryland Center for Cyber, Health, and Hazard Strategies expert Ben Yelin to discuss how private AI chatbot conversations are increasingly being used as evidence in criminal and civil court cases, raising new questions about privacy, legal protections, and what users should expect from their supposedly private AI interactions. Want to hear the full conversation? Be sure to check out Caveat for the full discussion and more on the latest issues in privacy, surveillance, cybersecurity law, and policy. Selected Reading FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors (Infosecurity Magazine) CISA Unveils Plan for Follow-On Integrated Cyber Assessment Support Contract (GovCon Wire) Widened Scan Turns Up Fourth Rogue Claude Cyber Incident (SecurityWeek) US sanctions Xinbi Guarantee over cyber scams and money laundering (Metacurity) New 'ShieldCrash' Zero-Day Exploit Targets Microsoft Defender (SecurityWeek) Gigabud banking trojan uses app cloning to evade fraud detection (SC Media) Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits (The Register) Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms (TechCrunch) Italian tech collective Autistici/Inventati shuts down after US terrorist designation (The Record) OpenAI Navier-Stokes Proof: $1 Million AI Math Controversy Explained (The CyberSec Guru) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices -
Clear your calendar, it’s Patch Tuesday. 09.09.2026 30นาทีPatch Tuesday is a doozy. The Feds warn China-based AI companies are distilling U.S. AI models. A new ClickFix campaign goes straight for the browser. Smart TVs get nosy. Hackers gift themselves a $47 million bug bounty. An Ohio man gets 15 years in federal prison for cyberstalking and sextortion. Andy Hornegold, Chief Security Technologist from Intruder, discusses what makes up a reliable AI pentests and the benefits and risks that come with AI-enabled security. Putting AI at the head of the class. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Andy Hornegold, Chief Security Technologist from Intruder, discussing what makes up a reliable AI pentests and the benefits and risks that come with AI-enabled security. Selected Reading Microsoft Patch Tuesday Fixes 966 Vulnerabilities, Including 2 Exploited 0-Days (Hackread) Ivanti Patches Critical Flaws Across Enterprise Security Products (SecurityWeek) Chrome 153 Patches Seventh Zero-Day of 2026 (SecurityWeek) Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day (SecurityWeek) ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws (SecurityWeek) CISA, NSA and FBI Warn Chinese AI Firms Are Targeting U.S. AI Models at Industrial Scale (HSToday) Europe's push for space sovereignty. (N2K Networks) History for European spaceflight: Isar Aerospace reaches orbit and deploys payloads on second flight (Isar Aerospace) ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 (Talos Intelligence) LG TVs caught spying even when offline or on standby (The Verge) 'White hat' hackers take $47 million bounty after $320 million crypto theft (The Record) Man gets 15 years for extorting women with AI-generated porn videos (Bleeping Computer) Alpha School’s AI teaching model is expanding. Does it work? (Scientific American) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices -
Worming its way through WeChat. 08.09.2026 30นาทีResearchers build a self-propagating attack against WeChat. Threat actors move toward multi-agent AI frameworks. N-able issues an emergency patch for a maximum-severity bug under active exploitation. MikroTik patches multiple RouterOS vulnerabilities. China accesses restricted American technology through subsidiaries and overseas partners. An active phishing campaign abuses legitimate Google services to make malicious links appear trustworthy. Australians may soon be able to disable the algorithm. Monday business briefing. Jason Lancaster, Chief Investigations Officer at SpyCloud, discusses how AI is affecting shifting cybercrime from traditional investigations to agentic AI at scale. Electromagnetic eavesdropping gets personal. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Jason Lancaster, Chief Investigations Officer at SpyCloud, discussing how AI is affecting shifting cybercrime from traditional investigations to agentic AI at scale. Selected Reading A.I. Models Built a Computer Worm That Could Rapidly Hack WeChat Accounts (The New York Times) Hackers build AI frameworks for widescale credential theft (Bleeping Computer) N-able Issues Emergency Hotfix for Maximum-Severity Unauthenticated RCE in N-central (Beyond Machines) MikroTik Patches Critical Flaws Chained to Hack Routers (SecurityWeek) How a Blacklisted Chinese Tech Giant Kept Buying America’s Best A.I. Chips (The New York Times) Bypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a Trust Proxy (KnowBe4) ‘Global reckoning for big tech’: Australia to force social media platforms to allow users to opt out of algorithms (The Guardian) Socure raises $156 million and acquires agentic AI platform Fravity. (N2K Pro Business Briefing) New attack eavesdrops on headphone audio from 30 meters away (CyberInsider) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices -
This call may be monitored. [Special Edition] 07.09.2026 38นาทีIn this Special Episode, Maria Varmazis and Dave Bittner are joined by friend of the show, Brandon Karpf, to unpack a new bipartisan congressional investigation into the lingering presence of Chinese state-owned telecommunications companies inside U.S. internet infrastructure. The House Select Committee on China says China Mobile, China Unicom, and China Telecom remain deeply embedded in American networks even after federal regulators denied or revoked their authority to provide certain telecommunications services over national security concerns. The investigation found that restrictions imposed by the FCC limited what the companies could sell, but did not necessarily remove their equipment, network connections, or commercial relationships from the U.S. internet ecosystem. Links to stories: Stranger Pings: Chinese Telecom Companies Infiltrate U.S. Infrastructure Learn more about your ad choices. Visit megaphone.fm/adchoices -
When hackers control the clock. [T-Minus: Space-Cyber Briefing] 06.09.2026 23นาทีThe accurate timing data from spacecraft has become an invaluable tool for nearly every critical infrastructure sector and a greater target for malicious actors. Host Maria Varmazis and Andy Davis, Global Research Director at the NCC Group, discuss the importance of timing in space. The two look at how timing systems have continued to grow more important in everyday life and why attackers have begun to increasingly exploit these critical services. Key sources: GPS: A backbone for critical infrastructure. Spoofing ships, jamming drones: how GPS manipulation confuses and compromises. Like what you heard? Be sure to subscribe to our free Signals and Space Briefing, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to [email protected]. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com. Learn more about your ad choices. Visit megaphone.fm/adchoices -
RMM-ber this ransomware. [Research Saturday] 05.09.2026 19นาทีIsmael Valenzuela, Vice President of Labs, Threat Research and Intelligence at Arctic Wolf, sits down with Dave to discuss their work tracking Anubis. Arctic Wolf Labs details a series of 2026 Anubis ransomware intrusions, revealing affiliates using stolen VPN credentials and exploiting CitrixBleed 2 to gain initial access. Attackers then blended into legitimate IT activity by deploying RMM tools, using RDP and PsExec for lateral movement, stealing credentials, and establishing tunnels and proxies for persistence and exfiltration. The research highlights a repeatable attack chain defenders can disrupt before encryption, from suspicious remote access and unauthorized RMM deployment to credential theft, security-tool tampering, and ransomware execution. The research and executive brief can be found here: From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks Learn more about your ad choices. Visit megaphone.fm/adchoices -
What the Flock? 04.09.2026 31นาทีThe G7 and CISA prepare for the quantum threat. Nightmare Eclipse drops a CrowdStrike zero-day. The White House’s offensive hacking plan raises legal questions. CISA offers a playbook for communicating through cyber incidents. OpenAI puts a billion dollars behind AI-powered defense. Researchers uncover a serious PostgreSQL flaw. Google patches an exploited Chrome zero-day. Broadcom fixes VMware vulnerabilities. Attackers target a WordPress plugin flaw. Lawmakers tell license plate surveillance cameras to “Flock off.” Our guest is Kevin Gosschalk, Founder and CEO of Arkose Labs, discussing his new book, After Bots, which questions the old assumption that automated traffic is inherently malicious. Camouflage for the algorithmic age. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Kevin Gosschalk, Founder and CEO of Arkose Labs, joins us to discuss his new book, After Bots, and why the old assumption that automated traffic is inherently malicious no longer works. Selected Reading G7 urges organizations to prepare for quantum cyber threats (The Record) Analysts: Trump Cyber Program Could Cost Firms Legal Shields (BankInfo Security) Communicating Under Pressure: Best Practices for Service Providers (IC3) OpenAI Pledges $1bn to Bring its AI Cybersecurity Tools to Essential S (Infosecurity Magazine) 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover (SecurityWeek) Google warns of new Chrome zero-day flaw exploited in attacks (Bleeping Computer) VMware Workstation and Fusion Updates Patch Critical Vulnerability (SecurityWeek) Critical Elementor Pro flaw exploited to take over WordPress sites (Bleeping Computer) Flock Cameras Face Removal Nationwide Under New Bill (Newsweek) Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC (The Register) This 'Digital Camouflage' Shirt Confuses AI-Powered Surveillance Cameras (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
ยอดนิยมใน
พอดแคสต์นี้ปรากฏในชาร์ตพอดแคสต์ของประเทศเหล่านี้ด้วย
-
เนปาล
-
ซิมบับเว
-
จาเมกา
-
สโลวีเนีย
-
บอสเนียและเฮอร์เซโกวีนา
-
คูเวต
-
เลบานอน
-
อาร์เจนตินา
-
ศรีลังกา
-
เอสโตเนีย
-
เซียร์ราลีโอน
-
คีร์กีซสถาน
-
โอมาน
-
เปรู
-
โมซัมบิก
-
มอริเชียส
-
กาตาร์
-
คอสตาริกา
-
เซนต์วินเซนต์และเกรนาดีนส์
-
ไซปรัส
-
สาธารณรัฐโดมินิกัน
-
เอกวาดอร์
-
ลิทัวเนีย
-
ฮังการี
-
บัลแกเรีย
-
กรีซ
-
มองโกเลีย
-
ฮอนดูรัส
-
มอนเตเนโกร
-
แคเมอรูน
-
เคนยา
-
โรมาเนีย
-
เซเนกัล
-
ลัตเวีย
-
กานา
-
ตรินิแดดและโตเบโก
-
บรูไน
-
อินเดีย
-
กัวเตมาลา