President Trump deputizes private-sector companies to target cybercriminals.
The LiteLLM supply-chain attack exposed credentials belonging to thousands of organizations. CISA mandates urgent patch for actively exploited Cisco firewall vulnerability.
The LiteLLM supply-chain attack exposed credentials belonging to thousands of organizations. CISA mandates urgent patch for actively exploited Cisco firewall vulnerability.
Attackers aren't just using AI to steal data; they're using it to fight back while you investigate them in real time. And once an adversary is inside, why would they ever want to leave? That's the unsettling reality Tom Kellermann, VP of AI Security and Threat Research at TrendAI, lays out in this episode. And the numbers prove it. According to a 2026 TrendAI survey of 46 financial-sector CISOs, more than 60% of respondents experienced counter-incident response, where adversaries actively disrupt live investigations. In addition, nearly 90% of these leaders reported more AI-enabled attacks year over year. Tom joins Johnny Hand and Dustin Childs to explain why the threats that hit banks first tend to hit everyone else next, and what defenders can do about it.
This week, Ben and Ethan discuss two major stories. The first looks deeper into the Supreme Court's recent ruling on the Chatrie case and the long-term impacts this decision could have on privacy within the nation. The second dives into another court case decision, which exposes social media companies to greater liability for allegedly addictive design features on their platforms and those features impacts on users.
This week, while Dave is out, hosts Maria Varmazis and Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. Maria and Joe are joined by friend of the show Michele Kellerman. We start with some follow-up on the chicken coop, where the big news is that the chicks have officially hatched. Maria covers how AI is fueling a growing share of cybercrime in Africa as scammers use increasingly sophisticated digital tools to target victims. Michele looks at a multi-step gold bar scam targeting older New Yorkers, where criminals first compromise victims' devices and information before posing as government or law enforcement officials to steal their money. Joe breaks down the Fun Coffee crypto investment scam, which promised enormous returns before the platform suddenly shut down, leaving victims with more than HK$104 million in reported losses. Our Catch of the Day comes from Reddit, with another scam that proves if an offer sounds too good to be true, it probably comes with a very suspicious backstory.
We got your Patch Tuesday notes. Attackers target Microsoft SharePoint vulnerability following PoC release. Cyberattack on CEVA Logistics causes ongoing supply chain disruptions. Wesco confirms data breach following extortion claims. Akira ransomware bypasses EDR in Safe Mode. California announces AI cybersecurity fund. N2K’s Lead Analyst Ethan Cook shares about cyber weapons for space. Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain. And fasten your seatbelts and ignore the fake Wi-Fi.
Michael Leland, Field CTO at Island joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices at Black Hat USA 2026. He discusses the emerging risks in the AI supply chain, why AI agents introduce new challenges around trust and governance, and what organizations can do to securely adopt agentic AI without slowing innovation.
Visa and Deel both acquire identity verification companies.
Attackers target SharePoint vulnerability following PoC release. Business news: Visa and Deel both acquire identity verification companies.
In this episode of the Microsoft Threat Intelligence Podcast, Microsoft Threat Intelligence Director Elliot Volkman is joined by Microsoft Principal Threat Intelligence Analyst Crane Hassold to explore how phishing and social engineering attacks are changing beyond email. They discuss the rise of QR code phishing, Microsoft Teams scams, SMS-based attacks, and why attackers continue to follow wherever people communicate. Crane also shares practical security recommendations for organizations and explains how Microsoft's disruption of the Tycoon2FA phishing-as-a-service platform led to a dramatic decline in malicious activity while reshaping the broader phishing landscape.
Kelly O'Dwyer Manuel has been building analyst relations (AR) programs for a long time, and her first question is always the same when starting from scratch: what are you actually trying to accomplish? She joins Gianna and Andy T to talk through what AR looks like for a small team with a small budget, why most companies pay for analyst relationships before they are ready, and what a first year program should realistically look like.
Poland’s CERT describes winter cyberattack against heat-and-power plant. Russian military hackers target Ukrainian IT workers in fake recruitment scheme. Chinese IP connections spark security review in UK Navy drones. US and South Korea warn of “Gunra” ransomware gang with North Korean ties. OpenAI mandates strict security controls for its new cybersecurity model. Record-breaking DDoS attacks surge in H1 2026. Data-scraping AI extension returns to the Chrome Web Store. Dave Bittner sat down with Stephen Harrison, VP of Product at Abnormal AI at Black Hat USA to discuss "The Identities Your Security Stack Is Ignoring." And no pain, no gain, no authorization.
Stephen Harrison, VP of Product at Abnormal AI joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices interview at Black Hat USA 2026. He explains why AI agents and service accounts are creating a new identity challenge for security teams, how shadow AI is expanding the attack surface through unmanaged OAuth permissions, and why organizations need to understand what "normal" looks like for every identity in their environment.
US and South Korea warn of "Gunra" ransomware gang with North Korean ties. Chinese IP connections spark security review in UK Navy drones.
On this episode of #IMM, Christine and Madison sit down with Byron Tau as he transitions from the Associated Press to ProPublica.
For decades, Cuban intelligence has been seen as a force that punches above its weight. Shaped during the Cold War through cooperation with the Soviet Union, its intelligence officers received extensive training by the KGB. But where does Cuba’s spy service stand today, especially as it faces pressure from Washington? Retired FBI special agent Peter J. Lapp, who wrote Queen of Cuba, came in to discuss Havana’s capabilities, the Americans who spied for Cuba, and the Cubans who spied for us.
Researchers find that only a quarter of AI-generated patches are fully successful. Ransomware attacks exploit critical N-able flaw. Atlassian fixes critical flaw in Rovo AI. LexisNexis disables some services following suspicious activity. US Senate confirms Adam Cassady as cyber ambassador. Meta ordered to pay an additional $567 million in child safety case. Water sector cyberattacks expand to new states. We got your Monday Business Briefing. On our Industry Voices, Dave Bittner sits down with Mujtaba Hamid, EVP, Product and Strategy at Booz Allen Hamilton at Black Hat discussing AI Speed Cyber Defense. And scammers set sail on The Odyssey.
Mujtaba Hamid, EVP of Product and Strategy at Booz Allen Hamilton joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices at Black Hat USA 2026. He explains how AI is compressing the timeline from vulnerability discovery to exploitation, why traditional human-paced security operations can no longer keep up, and how AI-native defensive systems can help organizations detect, adapt, and respond at machine speed.
Ransomware attacks exploit critical N-able flaw. LexisNexis disables some services following suspicious activity.
As commercial space activity accelerates, satellite manufacturers are rethinking how spacecraft are designed, built, and secured. In this week's episode, host Maria Varmazis sits down with Jason Roberson, an Industry Value Expert for Aerospace & Defense at Dassault Systems, to discuss how AI, automation, and digital engineering are transforming the space industry's product lifecycle. From digital twins and AI-assisted design to the future of in-space maintenance, Jason explores how these technologies are accelerating innovation while reshaping manufacturing. At the same time, the conversation examines the growing cybersecurity challenges that accompany this transformation and why building secure-by-design principles into space systems will be critical.
This week on T-Minus: Space-Cyber Briefing: we look at how artificial intelligence (AI) is impacting the space sector and introducing new cybersecurity challenges that manufacturers have not fully realized.
Today we are joined by Brian Hussey, SVP of Howler Cell Threat Services at Cyderes, discussing their work on "Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer." Howler Cell identified an SEO poisoning campaign targeting people searching for Claude Code installation guides, using a fake Anthropic page and a ClickFix lure to trick victims into running a malicious MSHTA command. The attack uses a six-stage, largely fileless chain that employs an MP3/HTA polyglot, PowerShell obfuscation, AMSI bypasses, per-victim infrastructure, and in-memory execution to evade detection. The final payload is a .NET infostealer that steals credentials, while Anthropic and the legitimate Claude Code installation process were not compromised.
Vishing attacks target hedge funds. CISA warns of cyberattacks targeting PLCs in the water sector.
Vishing attacks target hedge funds. Metabase Cloud breached by zero-day flaw. Cyberattack disrupts North Carolina Ports operations. The Chinese government has launched a security review of Palo Alto Networks products. US defense supplier breached by phishing attack. Healthcare software provider breach affected 3.8 million people. New macOS malware spreads via ClickFix attacks. Microsoft and Apple issue new security updates. Cryptography expert says new AI cryptanalysis results show promise, but not an AES breakthrough. James Turgal, Optiv Security’s vice president, cyber risk, strategy and board relations, is discussing how Iranian operators and their proxies appear to pursue disruption. And a Kentucky Fried Chicken order doxxes Chinese spyware operator.
Cyberattack disrupts North Carolina Ports operations. Metabase Cloud breached by zero-day flaw.
Meta’s AI models join the sandbox escape club. China’s telecom footprint in the U.S. may be larger than expected. The White House keeps its AI safety playbook under wraps. AI coding tools introduce new GitHub risks. ENISA expands its CVE role. A critical Paperclip flaw enables code execution. Crypto wallet fears fuel phishing attacks. Researchers uncover a backdoor in Chinese-made routers. The Snowflake hacker pleads guilty. Our guest is Dustin Childs, Head of Threat Awareness of TrendAI’s Zero Day Initiative, discussing the new Patch Tuesday era. AI takes your word for it.
US water system cyberattacks continue to grow.
Researchers identify backdoor in Chinese-made routers. Snowflake hacker pleads guilty.
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. We start with some follow-up after a listener asks Joe to finally reveal the backpack that's become a recurring character on the show—and whether it's really as airport-infeding as everyone says. Joe covers Myanmar's approval of the death penalty for convicted scammers and shares a real-world fraud case involving forged Little Debbie snack deliveries that shows scams don't always happen online. Maria explores the rise in foreclosure rescue and equity-stripping scams, where fraudsters target financially vulnerable homeowners and attempt to steal their money—or even their homes. Dave breaks down new research showing how AI-powered phone farms are making it easier than ever for scammers to automate fraud, manage hundreds of fake accounts, and scale their operations with minimal technical skill. Our Catch of the Day is on a scam-baiting exchange featuring an unforgettable tale of a supposed two-timing "Barb Johnson" that quickly spirals into absurdity.
This week, Ben and Ethan discuss two major stories. The first involves an incident where a police officer was abusing his access to Flock camera databases to track a former partner's movement. The second looks at recent research that found that Chinese military research units have been accessing US frontier AI models to train their own models through a process called model distillation.
The White House lays out its AI strategy at Black Hat. Researchers spotlight rogue AI behavior. CISA warns of an actively exploited N-able flaw. TP-Link patches 15 Omada vulnerabilities. Apple fights the UK’s iCloud access order. The AI gray market expands. A Massachusetts healthcare breach hits more than 300,000 people. Lawmakers push to extend protections for OPM breach victims. Our guest is Cal Al-Dhubaib, Principal Technologist at Rubrik, who wonders if your security team is solving the wrong problem. With elections, don’t trust AI to tell you the whole story.
Enterprise security has long been built to detect malicious actors, but AI agents are changing the rules. Cal Al-Dhubaib, Principal Technologist at Rubrik, joins Dave Bittner to explain why organizations need to shift from identifying suspicious intrusions to recognizing when trusted AI systems begin behaving outside their intended purpose. The conversation explores why behavioral monitoring, rather than traditional indicators of compromise, may become the foundation of AI security.
Spur secures $200 million in funding from Insight Partners. Okta has agreed to acquire identity security platform Permiso Security.
Apple files new legal challenge against UK’s iCloud access mandate. Business news: Okta to acquire Permiso Security.
Jake Milstein ran newsrooms at CBS, NBC, Fox, and ABC affiliates for 25 years. He has five Emmys and strong feelings about the phrase "in today's evolving threat landscape." It turns out 25 years of writing for people with a remote in their hand is excellent training for cybersecurity marketing. He sits down with Gianna and Charles on CyberCMO Confidential to talk about why "learn more" is a moron tease, what writing a broadcast tease has to do with your website copy, and why he now writes two versions of every press release. One for journalists. One for the LLMs that are doing the reading anyway. Gianna finally presents Jake with his very own handmade Cybersecurity Marketing Society award, which he has been lobbying for throughout the episode.
New Shai-Hulud campaign compromises popular npm packages. Easterly says small municipalities shouldn’t have to fend for themselves. Chinese threat groups accelerate exploits. Samsung bans smart TV apps with residential proxies. Hackers breach a Liechtenstein banking database. Swiss government IT agency hit in suspected SharePoint Attack. Microsoft’s bug bounty program awards record payouts. Researchers expose privilege boundary flaw in AI-driven CI/CD workflows. Roberta Anderson, Air Force veteran and CISO at Onterris is sharing her "Breaking the Firewall" book. And, bug hunting turns into bug sorting.
Samsung bans smart TV apps with residential proxy code. Liechtenstein discloses breach of its Register of Beneficial Owners.
In Cold War Britain, a secret propaganda department saw its list of targets and tactics widen. Personnel inside the Information Research Department went beyond forgeries, fakes, and plants, conducting bold impersonations to smear critics and stoke tensions among foes. The team, which consisted of refugees, ex-journalists, and even daughters of aristocrats, hatched a slew of audacious operations across Europe, Africa, and the Caribbean. They also had their own internal dramas. Author Rory Cormac pored over thousands of recently declassified files to uncover and chronicle their work in his book Fakers: A Top-Secret Tale of Phantoms and Forgeries on the Disinformation Front Line.
Welcome in! You’ve entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today’s most interesting threats. Your host is Selena Larson, Proofpoint intelligence analyst and host of their podcast DISCARDED. Inspired by the residents of a building in New York’s exclusive upper west side, Selena is joined by her co-hosts N2K Networks Dave Bittner and Keith Mularski, former FBI cybercrime investigator and now Chief Global Ambassador at Qintel. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. This week, Today, while Keith is off, Dave and Selena kick off a back-to-school special, exploring the cyber threats students, parents, educators, and universities should have on their radar. They examine the rise in job scams targeting university communities, discuss recent espionage activity aimed at higher education institutions in the U.S. and Canada, and look at how cybercriminals prey on younger audiences through online games, YouTube, and social media. From fake game cracks delivering information stealers to sextortion schemes targeting teens, they break down the tactics attackers are using and share practical advice for staying safe as the new school year begins.
Cyberattacks hit U.S. water systems. CISA tackles open source security. China’s surveillance machine is exposed. Hotel Wi-Fi gets riskier. Healthcare and police data spill online. Fake SQLite vulnerabilities fool security databases. Monday business briefing. Our guest is Tim Starks from CyberScoop discussing the White House's quantum aspirations. AI is the hottest thing on campus.
Russian espionage group tied to hotel WiFi hijacking campaign. INC ransomware gang claims credit for Australian healthcare provider hack.