CyberWire Daily - A nightmare on Windows street.
Episode Date: July 17, 2026Nightmare Eclipse drops another Windows zero-day. The Gentlemen take the ransomware crown. CISA orders emergency Fortinet patching. Canada’s surveillance bill faces U.S. scrutiny. Meta’s Oversight... Board flags AI censorship bias. Commerce tops the cyber target list. An active espionage campaign hits Bangladesh’s military. The Hewlett Foundation commits $100 million to emerging tech security. And U.S. prosecutors dismantle an alleged cyber-enabled money laundering network. Our guest is Nick Stohlman, Vice President of CJIS Strategy at Imprivata, talking about CJIS readiness and the identity security challenges facing public safety agencies. Leaked source code reveals an AI mixtape. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Nick Stohlman, Vice President of CJIS Strategy at Imprivata, talking about CJIS, Criminal Justice Information Services, readiness and the identity security challenges facing public safety agencies. Selected Reading New Windows LegacyHive zero-day gives hackers admin privileges (Bleeping Computer) The Gentlemen Overtakes Qilin as Most Prolific Ransomware Threat (Infosecurity Magazine) CISA urges immediate action on actively exploited Fortinet flaws (Bleeping Computer) Senator calls on Rubio, Blanche to push back against Canadian surveillance legislation (The Record) Meta Oversight Board finds top AI models less likely to criticize repressive regimes (Reuters) Commerce faces rising AI bot activity, escalating DDoS attacks, and new fraud tactics (Akamai) From Biography to Backdoor: Tracking a DoNot (APT-C-35) Intrusion Targeting Bangladesh Military Personnel (Cyderes) Hewlett Foundation Announces New $100 Million Emerging Technology and Security Initiative (Hewlett Foundation) US charges two over laundering $43 million from investment fraud (Bleeping Computer) Hack Reveals Suno AI Music Generator Scraped YouTube, Deezer, and Genius (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
This episode is brought to you by L'Oreal Group.
Beauty is a powerful force that moves us.
That's why L'Oreal Group has built a business that is inclusive at its heart
with 100% of its brands, championing diversity.
With 25,000 professional opportunities for people under 30 worldwide
and 54% of leading positions held by women,
diversity is a strength that helps L'Oreal Group create
the best beauty products for all people.
Visit laurel.com to learn more.
This episode is supported by Black Hat USA.
If you follow the research, you know a lot of it breaks on Black Hat stages.
Hundreds of peer-reviewed briefings, more than 100 hands-on trainings,
and the largest business hall in Black Hat's history.
Six days to learn the skills you'll need tomorrow.
August 1st to the 6th.
Use code Cyberwire for $200 off your briefings pass,
at blackhat.com.
We'll see you in Vegas.
Nightmare Eclipse drops another Windows Zero Day.
The gentlemen take the ransomware crown.
Sisa orders emergency fortinet patching.
Canada's surveillance bill faces U.S. scrutiny.
Meta's oversight board flags AI censorship bias.
Commerce tops the cyber target list.
An active espionage campaign hits Bangladesh's military.
The Hewlett Foundation commits $100 million to emerging tech security,
U.S. prosecutors dismantle an alleged cyber-enabled money laundering network.
Our guest is Nick Stolman, Vice President of Seegis Strategy at Improvata,
talking about Seagis readiness and the identity security challenges facing public safety agencies.
And leaked source code reveals an AI mixtape.
It's Friday, July 17, 26.
I'm Dave Bittner, and this is your Cyberwire Intel briefing.
Thanks for joining us here today.
It's great as always to have you with us.
Happy Friday.
A security researcher using the handle Nightmare Eclipse has released Legacy Hive,
a proof-of-concept zero-day exploit that targets the Windows user profile service
and enables privilege escalation on fully patched Windows systems.
The vulnerability has not yet been assigned a CVE.
Unlike the researcher's earlier releases, this proof of concept has been deliberately limited.
requiring additional user credentials to reduce the risk of widespread abuse.
Testing by security researchers Will Dorman and Kevin Beaumont confirmed the exploit works.
Dorman said it could let a standard user modify an administrator's registry Hive,
potentially enabling code execution when the administrator logs in,
while Beaumont published Microsoft Defender for endpoint detection queries.
Legacy Hive is the latest in a series of,
of Windows Zero Day disclosures from Nightmare Eclipse,
whose previous releases have prompted Microsoft patches
and public legal warnings.
The ransomware landscape is shifting,
with The Gentleman emerging as the most active cyber extortion group
between March and May of this year,
according to Relya Quest.
Researchers tracked 300 claimed victims linked to the group,
surpassing Keelan, which recorded 289 incidents
after leading ransomware activity throughout the previous year.
Across 11 major ransomware operations, RelyA Quest identified 1,368 victim claims spanning 99 countries.
The report attributes the gentleman's rapid rise to aggressive affiliate recruitment,
AI-assisted malware development, and a well-packaged ransomware as-a-service toolkit that lowers the barrier for new operators.
The toolkit includes detailed attack playbook,
and pre-configured intrusion tools that help affiliates launch attacks more efficiently.
RelyAQuest expects the group's momentum to continue and recommends organization strengthen
remote access controls, harden identity protections, enforce Microsoft's vulnerable driver
block list, and monitor suspicious network activity.
Sessa has ordered federal agencies to urgently patch two actively exploited critical vulnerabilities
in Fortinette Fortesandbox.
The flaws, patched by Fortinette in April and June,
allow unauthenticated remote code execution
through command injection attacks
that require no user interaction.
Although Fortnite has not confirmed exploitation,
threat intelligence firm diffused reported attacks in June,
and SISA has now added both vulnerabilities
to its known exploited vulnerabilities catalog.
Federal agencies must apply patches by July,
19th. Senator Ron Wyden is urging Secretary of State Marco Rubio and acting Attorney General Todd Blanche
to oppose Canada's proposed Lawful Access Act, warning it could threaten U.S. national security
and the privacy of American citizens. In a letter, Wyden argued the legislation could compel
U.S. technology companies to secretly assist Canadian surveillance by retaining user metadata,
creating back doors and modifying systems to facilitate lawful access requests.
The bill has passed Canada's House of Commons and is awaiting Senate approval.
Wyden called for a review of whether the proposal could force companies like Apple and Google
to disclose Americans' data and recommended using ongoing U.S.-Canada Cloud Act negotiations
to prohibit such requirements.
Canada's Citizen Lab has also raised constitutional.
concerns about elements of the legislation.
A study by META's Independent Oversight Board found that leading AI models, including those from
OpenAI and Anthropic, are significantly less likely to generate politically critical content
about governments with restrictive speech laws than about more permissive countries.
Across 10 models, researchers found refusals occurred 34% of the time for restrictive
jurisdictions compared with 14% for permissive ones.
The board warned this could introduce bias into widely used AI systems and called for greater
transparency in AI training, evaluation, and human rights assessments.
Akamai's latest state of the internet report says commerce has become the world's most
targeted industry for cyber attacks as AI-powered shopping agents and autonomous tools reshape
online retail. By the end of 2025, AI bots accounted for nearly 48% of all commerce traffic
on Akamai's network with AI training crawlers making up the majority. The report warns that
attackers are increasingly exploiting AI through agent hijacking, synthetic identity fraud,
and API attacks, while Layer 7 distributed denial of service attacks continue to surge,
particularly against retailers.
Akamai also found widespread gaps in API visibility, with most organizations unable to identify
sensitive data exposure. Meanwhile, fishing and malware activity have risen sharply, fueling account
takeovers and loyalty fraud as attackers industrialized cybercrime against digital commerce platforms.
Researchers at Sidaris Howler Cell uncovered an active cyber espionage campaign
targeting Bangladesh's military and defense sector and attributed it with high confidence to
do not, also known as APTC35. The operation begins with a spearfishing RTF document disguised as the
biography of a Bangladesh Air Force officer. The document uses remote template injection to retrieve
a malicious macro with server-side geofencing limiting delivery to intended regional targets.
The malware executes through multiple encrypted stages before installing a DLL that establishes persistence,
profiles the infected system, and communicates with command and control servers over encrypted HTTP.
By interacting directly with the C2 infrastructure, researchers retrieved a live second-stage payload
confirming the campaign remains active.
Matching encryption keys, infrastructure, and communication patterns,
further strengthen the attribution to do not
and indicate an ongoing intelligence gathering operation
targeting South Asian government and military organizations.
The William and Flora Hewlett Foundation
has launched a $100 million emerging technology and security initiative
to fund research and policy efforts through 2013
focused on the safe development of artificial intelligence,
biotechnology, and quantum computing.
announced at the Aspen Security Forum, the initiative will support universities, think tanks, and civil society organizations working to protect critical infrastructure, address emerging technology risks, and strengthen global governance.
Building on earlier exploratory grants, the program aims to promote practical, evidence-based solutions that balance innovation with security through collaboration across government, industry, and independent organizations.
On a personal note, our own research Saturday program was initially made possible by a Hewlett Foundation grant.
U.S. prosecutors have charged Joying Shen and Huaget Zhang to New York residents
with operating a large-scale money laundering network that allegedly moved at least $43 million in proceeds
from cyber-enabled investment fraud scams between 2020 and 2022.
According to the indictment, the pair managed a network of more than a dozen associates who used approximately 140 bank accounts tied to 45 shell companies to transfer stolen funds to China.
The underlying scams involved criminals building trust with victims through social media and messaging platforms before convincing them to invest in fake opportunities.
If convicted of conspiracy to commit money laundering, the defendants face up.
to 20 years in prison. The case highlights the continued growth of investment fraud, which the FBI
says caused $8.6 billion in reported losses in 2025.
Coming up after the break, my conversation with Nick Stolman from Improvada. We're talking
about Seagis readiness and the identity security challenges facing public safety agencies.
And leaked source code reveals an AI mixtape.
Stay with us.
The Hulu original series Furious is coming to Disney Plus, starring Emmy Rossum.
Furious follows FBI agent Alice Black on the hunt for a mysterious and calculating serial killer.
Both walk their own paths toward justice, and as their lives start to intertwine,
the line between right and wrong begins to blur.
Don't miss the three-episode premiere of the Hulu original series Furious on July 27th,
on Hulu on Disney Plus.
This episode is brought to you by Accenture.
When your advertising operations fall out of sync, everything else follows.
Spotify and Accenture are working together to reinvent the rhythm of ad sales,
using automation, analytics, and smarter workflows to simplify campaign delivery
and access better data across the business.
The result?
Less time spent on operations, more time connecting brands with the moments and fandoms
that matter most.
Learn more at Accenture.com.
slash Spotify.
In Toronto, every arrival is a statement, and nothing says it better than this.
Cadillac Optic was the number one selling luxury EV in Canada for 2025.
Find your rhythm across a seamless 33-inch display and an immersive 19-speaker AKG surround
audio system.
This city demands agility, and Optic delivers with precision to make every drive extraordinary.
Let's take the Cadillac.
Find out more at Cadillac Canada.ca.
Luxury sales claim based on S&P Global Mobility Canadian New Vehicle Total Registrations
for calendar year 2025 for the Cadillac definition of luxury.
My name is Peter Parker, but I'm also...
Spider-Man.
This July...
We're faced with a threat.
That can be anyone.
The world may have forgotten Peter Parker.
I'm just a neighbor.
Friendly neighbor.
But he hasn't forgotten them.
Sometimes Spider-Man has to do the hard thing.
That's my responsibility.
Talk to Banner?
I didn't know you could get that big.
Spider-Man, brand-new day.
In theaters, July 31st.
Nick Stolman is vice president of Seegis Strategy at Improvada.
We recently sat down to talk about Seagis readiness
and the identity security challenges facing public safety agencies.
We really wanted to get a temperature of the water where agencies were
with their CIS compliance journey.
In October of 24, the FBI released a document of 400 pages or more of requirements to meet
And we wanted to find out how many people had started that process and started on their journey
to find out, you know, what's the real lay of the land out there. And so we decided let's do a
survey and ask agencies from multiple sizes, multiple types, and see where they're at when it
comes to CIS compliance. So CIS stands for criminal justice information services. For folks who may not
be familiar with that. What does it mean and why does compliance here matter? So Seagis is actually
part of the FBI out of West Virginia. They employ about 3,000 different people within that section
of the FBI. And their main focus is to provide and to secure access to criminal justice information
databases that public safety agencies use on a daily basis. NCIC, inlets and so forth, running your
criminal history, running a driver's license through D&N.
through NCIC, finding out there's any warrants on an individual or a piece of property.
So all the databases of public safety access, we need to protect.
And the FBI's focus is to make sure those databases are being accessed properly by the right
personnel, those that have rights, and that the compliance is handled in a professional
manner that we're meeting those requirements that the FBI has put out.
So what are some of the challenges that public safety agencies face here to meet that compliance?
Yeah, you know, it comes down to cost and bandwidth a lot of the time.
I was a former undersheriff at a sheriff's office and I started my career as a drug enforcement agent.
And I always had to deal with CIS compliance as well as an end user.
But from a department standpoint, there's cost to be compliant.
and you have to buy the right tools,
multifactor authentication tools, software, you know,
and then you have to put those into practice.
You have to implement them.
And then you have to train,
and you have to have those end users,
which is everybody at the department,
making sure that they're, you know,
obviously accessing the systems properly
and that they're conducting themselves in a compliant manner.
One of the things it really does come down to,
it's not necessarily that agencies don't understand the priority of this
and the necessity and need is finding the funding to buy the right,
software, the right technology, and then the training and so forth. And it's a compliance,
see this compliance is not a one-fix-all. You buy a product and fix it. It's everyday practice,
and it's really an agency's responsibility. It's not an IT problem. It's an agency problem.
And you're only as strong and only as compliant as your weakest user. So it really takes
consistent training, consistent upkeep of the system you're using. And so obviously there's
a cost with that. And, you know, it has to be prioritized.
And when you've got to look for fuel money for your patrol cars or buy some software,
you know, you have to pick the priority there.
Right.
Now, it's my understanding that the Department of Homeland Security has a proposed framework here.
Is it Anchor CL? Is that correct?
That's correct. They do have an initiative out there that they're working on,
which, you know, is going to be able to kind of like, you know, sitting the guidelines
and making it easier.
and obviously when Homeland Security gets involved,
you'll find that they also are a big provider of grant funding, right?
So that obviously can solve twofold.
It can get compliance in a more structured manner,
but it also can provide a path to financing to be able to afford that.
For the public safety folks in our audience,
what are your recommendations?
What are the steps that you would suggest
for folks to strengthen their identity security
without trying to solve everything all at once.
Coming from running an agency,
I would approach it like I'd do everything within the agency's jurisdiction
and scope, right?
It's a mission.
And when you have a mission, you get the right personnel involved.
I would formulate a team from command staff, end users, power users, and IT staff.
And I'd evaluate our workflows and what do we really need to be compliant?
Where's our weakest points?
Is it password?
is that you share devices, where are we weak, what workflows are causing us, the opportunity
to fall into the non-practice of compliance and become a victim.
Just because your public safety agency doesn't mean you can't become a victim as well, right?
So I would put a team together and make it a focus, put a timeline to it, and I would advise
them, start researching what other agencies are doing, make contact with the FBI.
The FBI is their friend and their partner in Cesar's Compliancy, ask for guidance from them,
their state agency.
You know, here in North Carolina, I would live.
I would contact the SVI, State Bureau investigations,
and get their input on compliance and formulate a plan and look for a good partner.
Not a vendor, I'd look for a partner.
You know, again, I mentioned earlier that compliance is an ongoing everyday practice.
So you need a partner.
You're not buying something.
It's not a transactional sale.
It's a commitment.
It's a journey.
And you want to find a partner that's staying ahead of the game and is connected with the Bureau,
connected with the state agencies and understands the market,
understands the need and the pain points,
and understands where the FBI is going with future compliance concerns.
Every time technology changes, for example,
when we went from on-premise systems to cloud systems,
that caused more compliance concerns on how you access the cloud system.
And now today we're dealing with AI, right?
You hear AI through any type of vertical, any market out there.
Well, it's obviously very strong and prevalent in public safety as well.
So that creates new compliance concerns.
So you need to find a partner that understands that and is not just trying to sell you a piece of product or a piece of software that's going to solve multi-factor authentication.
That's where it starts, but it goes much further than that.
It sounds to me the way you're describing it, like there is a good amount of collaboration out there among the people who are using these tools.
Is there a sense of collegiality out there among those folks?
I think so.
I think this is always back historically has always been on the shoulders of IT.
And I think now, because the true weakness is usually through our own end users, it can't be all on IT.
So you're starting to see that group of that formation of teamwork and not just within the agency, other agencies, and also other partners and vendors and also collaborating with the FBI.
The FBI, again, you know, their job, they're trying to do the job and make you successful as well and make sure that you're compliant.
and that you don't put your agency at risk and the citizens you serve at risk.
So it takes teamwork, it takes collaboration, and it takes an understanding that we're all in this for the same mission.
We want to protect those CGI databases.
We want to protect the citizens.
And we want to make sure the folks are out there serving them get home at night.
And there's a lot of ways that can happen where they could not get home at night if you're not practicing CIS compliance.
That's Nick Stolman from Improvata.
Hear that?
It's your money calling.
It wants a promotion.
Elevate your savings with the Scotia high-interest savings account.
Always earn high regular interest rates that grow the more you save and invest.
Conditions apply.
Visit scotiabank.com slash h-I-SA to learn more.
Scotia Bank.
You're richer than you think.
What's the one thing in business that's spreading as fast as AI?
AI risk.
Every new tool your team signs up for, every vendor that turns on AI features, every new integration, each one is another opportunity for something to go wrong.
And most security programs weren't built to keep up with AI's pace of growth.
Enter Vanta.
Vanta is the number one agenetic trust platform, trusted by more than 16,000 fast-moving companies like Ramp, Hursor, and Harvey to help them stay audit-ready.
And now Vanta helps companies like yours keep an eye on the risks that appear between audits across your vendors, your AI tools, and your entire environment.
The Vanta agent works like a 24-7 GRC engineer in the background.
It finds issues, drafts fixes for you, and can cut vendor assessment time by up to 50%.
Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate your security and compliance,
earn and prove trust.
Get started today at vanta.com slash cyber.
That's v-a-t-a-com slash cyber.
And finally, a hacker has pulled back the curtain
on how AI music company Suno built its models,
revealing source code that allegedly shows
the platform scraped millions of songs,
lyrics, podcasts, and stock audio
from services including YouTube music, Dizer, Genius, Pond Five, and Gimendo.
The leaked code appears to detail massive training datasets, automated scraping tools, and techniques for finding vocal tracks,
while also suggesting the use of proxy infrastructure to collect content at scale.
The breach reportedly exposed customer contact information and limited stripe payment data,
though Suno says the incident involved outdated code was quickly contained and did not compromise full payment card numbers.
The revelations add weight to ongoing copyright lawsuits accusing Suno of training on copyrighted music.
It's a reminder that in AI, today's training playlist can become tomorrow's courtroom exhibit.
And that's the Cyberwire. For links to all of today's stories, check out our daily briefing at the
cyberwire.com. Be sure to check out this weekend's research Saturday in my conversation with
Lauren Fivison, senior threat researcher at Silent Push. The research is titled Meet Drive Surge,
a new threat actor using click-fix and fake update drive-by attacks in thousands of compromised sites.
That's Research Saturday. Check it out. And hello, Maria Vermazas here on Sunday's T-minus
space cyber briefing or diving into Europe's push for space sovereignty, from data laws to
independent launch and secure communications. T-minus producer Ethan Cook and I have a conversation
on why and how Europe is urgently pursuing space sovereignty. That is on Sunday on T-minus. See you
then. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights
that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show,
please share a rating and review in your favorite podcast app.
Please also fill out the survey in the show notes
or send an email to Cyberwire at N2K.com.
N2K's lead producer is Liz Stokes.
We're mixed by Trey Hester
with original music and sound design by Elliot Peltzman.
Our contributing host is Maria Vermazes.
Our executive producer is Jennifer Ibn,
Peter Kilpe is our publisher,
and I'm Dave Bittner.
Thanks for listening.
We'll see you back here next week.
Getting to this year's Black Hat USA, the N2K Cyberwire team will be on site recording from our podcast studio in the SpectorOps Kennel Club.
If you're interested in joining us for a conversation or learning more about what we're recording throughout the week,
visit sponsor.thecyberwire.com for more information.
And make sure you stop by the studio and meet the N2K Cyberwire team.
We'll see you there.
