CyberWire Daily - A nightmare on Windows street.

Episode Date: July 17, 2026

Nightmare Eclipse drops another Windows zero-day. The Gentlemen take the ransomware crown. CISA orders emergency Fortinet patching. Canada’s surveillance bill faces U.S. scrutiny. Meta’s Oversight... Board flags AI censorship bias. Commerce tops the cyber target list. An active espionage campaign hits Bangladesh’s military. The Hewlett Foundation commits $100 million to emerging tech security. And U.S. prosecutors dismantle an alleged cyber-enabled money laundering network. Our guest is Nick Stohlman, Vice President of CJIS Strategy at Imprivata, talking about CJIS readiness and the identity security challenges facing public safety agencies. Leaked source code reveals an AI mixtape. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Nick Stohlman, Vice President of CJIS Strategy at Imprivata, talking about CJIS, Criminal Justice Information Services, readiness and the identity security challenges facing public safety agencies. Selected Reading New Windows LegacyHive zero-day gives hackers admin privileges (Bleeping Computer) The Gentlemen Overtakes Qilin as Most Prolific Ransomware Threat (Infosecurity Magazine) CISA urges immediate action on actively exploited Fortinet flaws (Bleeping Computer) Senator calls on Rubio, Blanche to push back against Canadian surveillance legislation (The Record) Meta Oversight Board finds top AI models less likely to criticize repressive regimes (Reuters) Commerce faces rising AI bot activity, escalating DDoS attacks, and new fraud tactics (Akamai) From Biography to Backdoor: Tracking a DoNot (APT-C-35) Intrusion Targeting Bangladesh Military Personnel (Cyderes) Hewlett Foundation Announces New $100 Million Emerging Technology and Security Initiative (Hewlett Foundation) US charges two over laundering $43 million from investment fraud (Bleeping Computer) Hack Reveals Suno AI Music Generator Scraped YouTube, Deezer, and Genius (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. This episode is brought to you by L'Oreal Group. Beauty is a powerful force that moves us. That's why L'Oreal Group has built a business that is inclusive at its heart with 100% of its brands, championing diversity. With 25,000 professional opportunities for people under 30 worldwide and 54% of leading positions held by women, diversity is a strength that helps L'Oreal Group create
Starting point is 00:00:33 the best beauty products for all people. Visit laurel.com to learn more. This episode is supported by Black Hat USA. If you follow the research, you know a lot of it breaks on Black Hat stages. Hundreds of peer-reviewed briefings, more than 100 hands-on trainings, and the largest business hall in Black Hat's history. Six days to learn the skills you'll need tomorrow. August 1st to the 6th.
Starting point is 00:01:03 Use code Cyberwire for $200 off your briefings pass, at blackhat.com. We'll see you in Vegas. Nightmare Eclipse drops another Windows Zero Day. The gentlemen take the ransomware crown. Sisa orders emergency fortinet patching. Canada's surveillance bill faces U.S. scrutiny. Meta's oversight board flags AI censorship bias.
Starting point is 00:01:40 Commerce tops the cyber target list. An active espionage campaign hits Bangladesh's military. The Hewlett Foundation commits $100 million to emerging tech security, U.S. prosecutors dismantle an alleged cyber-enabled money laundering network. Our guest is Nick Stolman, Vice President of Seegis Strategy at Improvata, talking about Seagis readiness and the identity security challenges facing public safety agencies. And leaked source code reveals an AI mixtape. It's Friday, July 17, 26.
Starting point is 00:02:24 I'm Dave Bittner, and this is your Cyberwire Intel briefing. Thanks for joining us here today. It's great as always to have you with us. Happy Friday. A security researcher using the handle Nightmare Eclipse has released Legacy Hive, a proof-of-concept zero-day exploit that targets the Windows user profile service and enables privilege escalation on fully patched Windows systems. The vulnerability has not yet been assigned a CVE.
Starting point is 00:03:08 Unlike the researcher's earlier releases, this proof of concept has been deliberately limited. requiring additional user credentials to reduce the risk of widespread abuse. Testing by security researchers Will Dorman and Kevin Beaumont confirmed the exploit works. Dorman said it could let a standard user modify an administrator's registry Hive, potentially enabling code execution when the administrator logs in, while Beaumont published Microsoft Defender for endpoint detection queries. Legacy Hive is the latest in a series of, of Windows Zero Day disclosures from Nightmare Eclipse,
Starting point is 00:03:47 whose previous releases have prompted Microsoft patches and public legal warnings. The ransomware landscape is shifting, with The Gentleman emerging as the most active cyber extortion group between March and May of this year, according to Relya Quest. Researchers tracked 300 claimed victims linked to the group, surpassing Keelan, which recorded 289 incidents
Starting point is 00:04:13 after leading ransomware activity throughout the previous year. Across 11 major ransomware operations, RelyA Quest identified 1,368 victim claims spanning 99 countries. The report attributes the gentleman's rapid rise to aggressive affiliate recruitment, AI-assisted malware development, and a well-packaged ransomware as-a-service toolkit that lowers the barrier for new operators. The toolkit includes detailed attack playbook, and pre-configured intrusion tools that help affiliates launch attacks more efficiently. RelyAQuest expects the group's momentum to continue and recommends organization strengthen remote access controls, harden identity protections, enforce Microsoft's vulnerable driver
Starting point is 00:05:02 block list, and monitor suspicious network activity. Sessa has ordered federal agencies to urgently patch two actively exploited critical vulnerabilities in Fortinette Fortesandbox. The flaws, patched by Fortinette in April and June, allow unauthenticated remote code execution through command injection attacks that require no user interaction. Although Fortnite has not confirmed exploitation,
Starting point is 00:05:30 threat intelligence firm diffused reported attacks in June, and SISA has now added both vulnerabilities to its known exploited vulnerabilities catalog. Federal agencies must apply patches by July, 19th. Senator Ron Wyden is urging Secretary of State Marco Rubio and acting Attorney General Todd Blanche to oppose Canada's proposed Lawful Access Act, warning it could threaten U.S. national security and the privacy of American citizens. In a letter, Wyden argued the legislation could compel U.S. technology companies to secretly assist Canadian surveillance by retaining user metadata,
Starting point is 00:06:12 creating back doors and modifying systems to facilitate lawful access requests. The bill has passed Canada's House of Commons and is awaiting Senate approval. Wyden called for a review of whether the proposal could force companies like Apple and Google to disclose Americans' data and recommended using ongoing U.S.-Canada Cloud Act negotiations to prohibit such requirements. Canada's Citizen Lab has also raised constitutional. concerns about elements of the legislation. A study by META's Independent Oversight Board found that leading AI models, including those from
Starting point is 00:06:54 OpenAI and Anthropic, are significantly less likely to generate politically critical content about governments with restrictive speech laws than about more permissive countries. Across 10 models, researchers found refusals occurred 34% of the time for restrictive jurisdictions compared with 14% for permissive ones. The board warned this could introduce bias into widely used AI systems and called for greater transparency in AI training, evaluation, and human rights assessments. Akamai's latest state of the internet report says commerce has become the world's most targeted industry for cyber attacks as AI-powered shopping agents and autonomous tools reshape
Starting point is 00:07:41 online retail. By the end of 2025, AI bots accounted for nearly 48% of all commerce traffic on Akamai's network with AI training crawlers making up the majority. The report warns that attackers are increasingly exploiting AI through agent hijacking, synthetic identity fraud, and API attacks, while Layer 7 distributed denial of service attacks continue to surge, particularly against retailers. Akamai also found widespread gaps in API visibility, with most organizations unable to identify sensitive data exposure. Meanwhile, fishing and malware activity have risen sharply, fueling account takeovers and loyalty fraud as attackers industrialized cybercrime against digital commerce platforms.
Starting point is 00:08:33 Researchers at Sidaris Howler Cell uncovered an active cyber espionage campaign targeting Bangladesh's military and defense sector and attributed it with high confidence to do not, also known as APTC35. The operation begins with a spearfishing RTF document disguised as the biography of a Bangladesh Air Force officer. The document uses remote template injection to retrieve a malicious macro with server-side geofencing limiting delivery to intended regional targets. The malware executes through multiple encrypted stages before installing a DLL that establishes persistence, profiles the infected system, and communicates with command and control servers over encrypted HTTP. By interacting directly with the C2 infrastructure, researchers retrieved a live second-stage payload
Starting point is 00:09:29 confirming the campaign remains active. Matching encryption keys, infrastructure, and communication patterns, further strengthen the attribution to do not and indicate an ongoing intelligence gathering operation targeting South Asian government and military organizations. The William and Flora Hewlett Foundation has launched a $100 million emerging technology and security initiative to fund research and policy efforts through 2013
Starting point is 00:10:00 focused on the safe development of artificial intelligence, biotechnology, and quantum computing. announced at the Aspen Security Forum, the initiative will support universities, think tanks, and civil society organizations working to protect critical infrastructure, address emerging technology risks, and strengthen global governance. Building on earlier exploratory grants, the program aims to promote practical, evidence-based solutions that balance innovation with security through collaboration across government, industry, and independent organizations. On a personal note, our own research Saturday program was initially made possible by a Hewlett Foundation grant. U.S. prosecutors have charged Joying Shen and Huaget Zhang to New York residents with operating a large-scale money laundering network that allegedly moved at least $43 million in proceeds from cyber-enabled investment fraud scams between 2020 and 2022.
Starting point is 00:11:06 According to the indictment, the pair managed a network of more than a dozen associates who used approximately 140 bank accounts tied to 45 shell companies to transfer stolen funds to China. The underlying scams involved criminals building trust with victims through social media and messaging platforms before convincing them to invest in fake opportunities. If convicted of conspiracy to commit money laundering, the defendants face up. to 20 years in prison. The case highlights the continued growth of investment fraud, which the FBI says caused $8.6 billion in reported losses in 2025. Coming up after the break, my conversation with Nick Stolman from Improvada. We're talking about Seagis readiness and the identity security challenges facing public safety agencies. And leaked source code reveals an AI mixtape.
Starting point is 00:12:12 Stay with us. The Hulu original series Furious is coming to Disney Plus, starring Emmy Rossum. Furious follows FBI agent Alice Black on the hunt for a mysterious and calculating serial killer. Both walk their own paths toward justice, and as their lives start to intertwine, the line between right and wrong begins to blur. Don't miss the three-episode premiere of the Hulu original series Furious on July 27th, on Hulu on Disney Plus. This episode is brought to you by Accenture.
Starting point is 00:12:55 When your advertising operations fall out of sync, everything else follows. Spotify and Accenture are working together to reinvent the rhythm of ad sales, using automation, analytics, and smarter workflows to simplify campaign delivery and access better data across the business. The result? Less time spent on operations, more time connecting brands with the moments and fandoms that matter most. Learn more at Accenture.com.
Starting point is 00:13:20 slash Spotify. In Toronto, every arrival is a statement, and nothing says it better than this. Cadillac Optic was the number one selling luxury EV in Canada for 2025. Find your rhythm across a seamless 33-inch display and an immersive 19-speaker AKG surround audio system. This city demands agility, and Optic delivers with precision to make every drive extraordinary. Let's take the Cadillac. Find out more at Cadillac Canada.ca.
Starting point is 00:13:46 Luxury sales claim based on S&P Global Mobility Canadian New Vehicle Total Registrations for calendar year 2025 for the Cadillac definition of luxury. My name is Peter Parker, but I'm also... Spider-Man. This July... We're faced with a threat. That can be anyone. The world may have forgotten Peter Parker.
Starting point is 00:14:03 I'm just a neighbor. Friendly neighbor. But he hasn't forgotten them. Sometimes Spider-Man has to do the hard thing. That's my responsibility. Talk to Banner? I didn't know you could get that big. Spider-Man, brand-new day.
Starting point is 00:14:17 In theaters, July 31st. Nick Stolman is vice president of Seegis Strategy at Improvada. We recently sat down to talk about Seagis readiness and the identity security challenges facing public safety agencies. We really wanted to get a temperature of the water where agencies were with their CIS compliance journey. In October of 24, the FBI released a document of 400 pages or more of requirements to meet And we wanted to find out how many people had started that process and started on their journey
Starting point is 00:15:03 to find out, you know, what's the real lay of the land out there. And so we decided let's do a survey and ask agencies from multiple sizes, multiple types, and see where they're at when it comes to CIS compliance. So CIS stands for criminal justice information services. For folks who may not be familiar with that. What does it mean and why does compliance here matter? So Seagis is actually part of the FBI out of West Virginia. They employ about 3,000 different people within that section of the FBI. And their main focus is to provide and to secure access to criminal justice information databases that public safety agencies use on a daily basis. NCIC, inlets and so forth, running your criminal history, running a driver's license through D&N.
Starting point is 00:15:54 through NCIC, finding out there's any warrants on an individual or a piece of property. So all the databases of public safety access, we need to protect. And the FBI's focus is to make sure those databases are being accessed properly by the right personnel, those that have rights, and that the compliance is handled in a professional manner that we're meeting those requirements that the FBI has put out. So what are some of the challenges that public safety agencies face here to meet that compliance? Yeah, you know, it comes down to cost and bandwidth a lot of the time. I was a former undersheriff at a sheriff's office and I started my career as a drug enforcement agent.
Starting point is 00:16:40 And I always had to deal with CIS compliance as well as an end user. But from a department standpoint, there's cost to be compliant. and you have to buy the right tools, multifactor authentication tools, software, you know, and then you have to put those into practice. You have to implement them. And then you have to train, and you have to have those end users,
Starting point is 00:16:59 which is everybody at the department, making sure that they're, you know, obviously accessing the systems properly and that they're conducting themselves in a compliant manner. One of the things it really does come down to, it's not necessarily that agencies don't understand the priority of this and the necessity and need is finding the funding to buy the right, software, the right technology, and then the training and so forth. And it's a compliance,
Starting point is 00:17:23 see this compliance is not a one-fix-all. You buy a product and fix it. It's everyday practice, and it's really an agency's responsibility. It's not an IT problem. It's an agency problem. And you're only as strong and only as compliant as your weakest user. So it really takes consistent training, consistent upkeep of the system you're using. And so obviously there's a cost with that. And, you know, it has to be prioritized. And when you've got to look for fuel money for your patrol cars or buy some software, you know, you have to pick the priority there. Right.
Starting point is 00:17:58 Now, it's my understanding that the Department of Homeland Security has a proposed framework here. Is it Anchor CL? Is that correct? That's correct. They do have an initiative out there that they're working on, which, you know, is going to be able to kind of like, you know, sitting the guidelines and making it easier. and obviously when Homeland Security gets involved, you'll find that they also are a big provider of grant funding, right? So that obviously can solve twofold.
Starting point is 00:18:27 It can get compliance in a more structured manner, but it also can provide a path to financing to be able to afford that. For the public safety folks in our audience, what are your recommendations? What are the steps that you would suggest for folks to strengthen their identity security without trying to solve everything all at once. Coming from running an agency,
Starting point is 00:18:50 I would approach it like I'd do everything within the agency's jurisdiction and scope, right? It's a mission. And when you have a mission, you get the right personnel involved. I would formulate a team from command staff, end users, power users, and IT staff. And I'd evaluate our workflows and what do we really need to be compliant? Where's our weakest points? Is it password?
Starting point is 00:19:13 is that you share devices, where are we weak, what workflows are causing us, the opportunity to fall into the non-practice of compliance and become a victim. Just because your public safety agency doesn't mean you can't become a victim as well, right? So I would put a team together and make it a focus, put a timeline to it, and I would advise them, start researching what other agencies are doing, make contact with the FBI. The FBI is their friend and their partner in Cesar's Compliancy, ask for guidance from them, their state agency. You know, here in North Carolina, I would live.
Starting point is 00:19:46 I would contact the SVI, State Bureau investigations, and get their input on compliance and formulate a plan and look for a good partner. Not a vendor, I'd look for a partner. You know, again, I mentioned earlier that compliance is an ongoing everyday practice. So you need a partner. You're not buying something. It's not a transactional sale. It's a commitment.
Starting point is 00:20:07 It's a journey. And you want to find a partner that's staying ahead of the game and is connected with the Bureau, connected with the state agencies and understands the market, understands the need and the pain points, and understands where the FBI is going with future compliance concerns. Every time technology changes, for example, when we went from on-premise systems to cloud systems, that caused more compliance concerns on how you access the cloud system.
Starting point is 00:20:30 And now today we're dealing with AI, right? You hear AI through any type of vertical, any market out there. Well, it's obviously very strong and prevalent in public safety as well. So that creates new compliance concerns. So you need to find a partner that understands that and is not just trying to sell you a piece of product or a piece of software that's going to solve multi-factor authentication. That's where it starts, but it goes much further than that. It sounds to me the way you're describing it, like there is a good amount of collaboration out there among the people who are using these tools. Is there a sense of collegiality out there among those folks?
Starting point is 00:21:08 I think so. I think this is always back historically has always been on the shoulders of IT. And I think now, because the true weakness is usually through our own end users, it can't be all on IT. So you're starting to see that group of that formation of teamwork and not just within the agency, other agencies, and also other partners and vendors and also collaborating with the FBI. The FBI, again, you know, their job, they're trying to do the job and make you successful as well and make sure that you're compliant. and that you don't put your agency at risk and the citizens you serve at risk. So it takes teamwork, it takes collaboration, and it takes an understanding that we're all in this for the same mission. We want to protect those CGI databases.
Starting point is 00:21:51 We want to protect the citizens. And we want to make sure the folks are out there serving them get home at night. And there's a lot of ways that can happen where they could not get home at night if you're not practicing CIS compliance. That's Nick Stolman from Improvata. Hear that? It's your money calling. It wants a promotion. Elevate your savings with the Scotia high-interest savings account.
Starting point is 00:22:29 Always earn high regular interest rates that grow the more you save and invest. Conditions apply. Visit scotiabank.com slash h-I-SA to learn more. Scotia Bank. You're richer than you think. What's the one thing in business that's spreading as fast as AI? AI risk. Every new tool your team signs up for, every vendor that turns on AI features, every new integration, each one is another opportunity for something to go wrong.
Starting point is 00:23:02 And most security programs weren't built to keep up with AI's pace of growth. Enter Vanta. Vanta is the number one agenetic trust platform, trusted by more than 16,000 fast-moving companies like Ramp, Hursor, and Harvey to help them stay audit-ready. And now Vanta helps companies like yours keep an eye on the risks that appear between audits across your vendors, your AI tools, and your entire environment. The Vanta agent works like a 24-7 GRC engineer in the background. It finds issues, drafts fixes for you, and can cut vendor assessment time by up to 50%. Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate your security and compliance, earn and prove trust.
Starting point is 00:23:52 Get started today at vanta.com slash cyber. That's v-a-t-a-com slash cyber. And finally, a hacker has pulled back the curtain on how AI music company Suno built its models, revealing source code that allegedly shows the platform scraped millions of songs, lyrics, podcasts, and stock audio from services including YouTube music, Dizer, Genius, Pond Five, and Gimendo.
Starting point is 00:24:33 The leaked code appears to detail massive training datasets, automated scraping tools, and techniques for finding vocal tracks, while also suggesting the use of proxy infrastructure to collect content at scale. The breach reportedly exposed customer contact information and limited stripe payment data, though Suno says the incident involved outdated code was quickly contained and did not compromise full payment card numbers. The revelations add weight to ongoing copyright lawsuits accusing Suno of training on copyrighted music. It's a reminder that in AI, today's training playlist can become tomorrow's courtroom exhibit. And that's the Cyberwire. For links to all of today's stories, check out our daily briefing at the cyberwire.com. Be sure to check out this weekend's research Saturday in my conversation with
Starting point is 00:25:35 Lauren Fivison, senior threat researcher at Silent Push. The research is titled Meet Drive Surge, a new threat actor using click-fix and fake update drive-by attacks in thousands of compromised sites. That's Research Saturday. Check it out. And hello, Maria Vermazas here on Sunday's T-minus space cyber briefing or diving into Europe's push for space sovereignty, from data laws to independent launch and secure communications. T-minus producer Ethan Cook and I have a conversation on why and how Europe is urgently pursuing space sovereignty. That is on Sunday on T-minus. See you then. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show,
Starting point is 00:26:23 please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to Cyberwire at N2K.com. N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazes. Our executive producer is Jennifer Ibn,
Starting point is 00:26:46 Peter Kilpe is our publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here next week. Getting to this year's Black Hat USA, the N2K Cyberwire team will be on site recording from our podcast studio in the SpectorOps Kennel Club. If you're interested in joining us for a conversation or learning more about what we're recording throughout the week, visit sponsor.thecyberwire.com for more information. And make sure you stop by the studio and meet the N2K Cyberwire team.
Starting point is 00:27:37 We'll see you there.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.