CyberWire Daily - A private route to public risk.
Episode Date: August 11, 2026Poland’s CERT describes winter cyberattack against heat-and-power plant. Russian military hackers target Ukrainian IT workers in fake recruitment scheme. Chinese IP connections spark security review... in UK Navy drones. US and South Korea warn of “Gunra” ransomware gang with North Korean ties. OpenAI mandates strict security controls for its new cybersecurity model. Record-breaking DDoS attacks surge in H1 2026. Data-scraping AI extension returns to the Chrome Web Store. Dave Bittner sat down with Stephen Harrison, VP of Product at Abnormal AI at Black Hat USA to discuss "The Identities Your Security Stack Is Ignoring." And no pain, no gain, no authorization. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices, Dave Bittner sat down with Stephen Harrison, VP of Product at Abnormal AI at Black Hat USA to discuss "The Identities Your Security Stack Is Ignoring." If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading Hackers breached a small Polish energy plant via private APN last year (BleepingComputer) Russian military hackers pose as recruiters to target Ukrainian IT workers (The Record) Cyber vulnerability sweep picks up Royal Navy drones sending data to China (The Register) U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang (CyberScoop) OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns (SecurityWeek) Cloudflare DDoS Threat Report H1 2026 (Cloudflare) Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities (SecurityWeek) AI assistant hacks gym website in first known Australian autonomous cyber attack (ABC News) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
Maybe that's an urgent email from your CEO, or maybe it's a deep fake targeting your business.
Dopple is the AI-native social engineering defense platform fighting back against impersonation and manipulation.
As attackers use AI to make their tactics more sophisticated, Dopple uses it to fight back,
automatically dismantling cross-channel attacks, building team resilience, and providing agentic
email protection.
Dopple, outpacing what's next in social engineering.
Learn more at doppel.com.
That's do pp-p-el.com.
Poland's cert describes winter cyber attack against heat and power plant.
Russian military hackers target Ukrainian IT workers and fake recruitment scheme.
Chinese IP connections spark security review in U.S.
UK Navy drones.
U.S. and South Korea warn of Gunrah Ransomware Gang with North Korean ties.
Open AI mandates strict security controls for its new cybersecurity model.
Record-breaking DDoS attacks surge in H1, 2026.
Data scraping AI extension returns to the Chrome Web Store.
Dave Bittner sat down with Stephen Harrison, VP of Product at Abnormal AI at Black Hat USA,
to discuss the identities your security stack is ignoring.
and no pain, no gain, no authorization.
Today is Tuesday, August 11th, 2026.
I'm Maria Varmazes, and this is your Cyberwire Intel Briefing.
Thank you for joining me. Let's get started.
Poland's computer emergency response team has disclosed that hackers breached a Polish
combined heat and power plant by exploiting a misconfigured private access point name or APN network.
The attackers initially compromised a wind farm's firewall,
and then tunneled into the shared APN to locate an exposed controller at the power plant,
secured only by default credentials.
They then used this access to get into the plant's OT network,
temporarily shutting down a steam turbine and water treatment system.
Polish authorities quickly restored the systems before there was any impact to the public,
but said that this marks the first known real-world cyber attack
using a private APN for lateral movement into an OT network.
The attack took place on December 29, 2025, the same day that hackers tied to Russia's Electrum APT,
targeted dozens of heat and power facilities across Poland.
Though the attacks failed to cause significant disruptions, experts emphasized that the hackers
tried to cut off heat from civilian populations in the dead of winter.
Hackers linked to sandworm, which is a threat actor attributed to Russia's GRU military intelligence agency,
are posing as recruiters to target Ukrainian IT workers,
all this according to Ukraine's computer emergency response team.
The campaign has been active since at least May
and involves hackers finding potential victims on legitimate job sites,
conducting fake interviews on telegram and Zoom,
and eventually tricking candidates into downloading a malicious VPN app called SOPRA VPN.
This app, disguised as a legitimate tool needed for a technical interview assignment,
executes covert malicious commands on the victim's device.
A UK cybersecurity assessment found that cameras aboard Royal Navy drone boats
were contacting Chinese IP addresses.
The issues were discovered on cameras on crack in unmanned surface vessel subsystems
and involved non-sensitive heartbeat communications
rather than operational imagery or sensitive intelligence.
The UK's Ministry of Defense disconnected the cameras from the internet
and emphasized that no classified systems were breached.
Still, the discovery has heightened ongoing security concerns about Chinese-made components embedded in Western military hardware.
US and South Korean cybersecurity agencies have issued a joint alert regarding Gunra, which is an expanding ransomware as-a-service group targeting critical infrastructure sectors globally.
Built on leaked Conti ransomware code, Gunra has been recruiting ethical hackers and pen-testers to serve as initial access brokers in exchange for a cut of,
of the ransom profits.
Notably, researchers have found overlaps
between Gunra's operations
and those of North Korean state-sponsored hackers,
suggesting collaboration or shared infrastructure
between the cybercriminal gang and nation-state actors.
Open AI has paused internal development of projects
that lack sufficient security controls
after determining that its upcoming AI model Astra
demonstrates a significant jump in cybersecurity capabilities.
Astra has met OpenAI's critical
risk threshold, surpassing the high rating of previous models like GPT 5.6 sole, because it can
autonomously develop zero-day exploits against real-world systems and execute end-to-end cyber
attacks based solely on high-level objectives. The company has mandated isolated testing
environments, enhanced model weight predictions, and strict network restrictions for all projects
involving Astra.
Cloudflare's DDoS threat report for the first half of 2026 highlights a sixfold increase
in attacks exceeding one terabit per second, which skyrocketed from 130 incidents in Q1
to more than 800 in Q2.
While the vast majority of DDoS attacks remain relatively small in less than 10 minutes,
attackers are increasingly weaponizing DNS-based amplification and flood techniques.
The researchers also note,
that these smaller attacks can still overwhelm most websites.
A popular Chrome extension called AI Sidebar with DeepSeek, Chat, GPT, Claude, and more
has returned to the Chrome Web Store and resumed malicious activities.
The app was initially banned by Google in January 26 for secretly scraping users' AI conversations.
Although the developers temporarily removed the chat stealing behavior, most likely so they could get back into the store,
a recent update slyly introduced a new monetization scheme.
The extension now hijacks, update, and uninstall events
to force open affiliate links for an AI video generation platform.
Security firm NetScope discovered this deceptive behavior
and advises organizations to remove the extension.
Now stick with us after the break,
as Dave Bittner recently sat down at Black Hat USA with Stephen Harrison,
VP of Product at Abnormal AI,
to discuss the identities your security stack is ignoring.
And no pain, no gain, no authorization.
AI is making fishing attacks faster, more convincing, and harder for people to spot,
and traditional security awareness and fishing training weren't designed for this level of attack.
Hawkshunt helped security teams prepare employees for the attacks they face every day,
with personalized fishing training that adapts to each employee and reduces risky behavior.
over time. For IT and security leaders looking to strengthen their human layer of defense,
without adding more manual work, visit hoxhunt.com slash cyberwire to learn more. That's H-O-X-Hun-T.com
slash cyberwire. At Black Hat USA, Dave Bittner sat down with Stephen Harrison, VP of Product
at Normal AI to discuss the identities your security stack is ignoring. Here's their conversation.
We are continuing our time here at Black Hat 2026, and joining me here today is Stephen Harrison, who's VP of Product at Abnormal AI.
Welcome back. Nice to see you.
Thank you for having me.
Let's dig in, and I want to start off with a little bit of level setting with you, which is, as you're walking around the Black Hat experience this year, the show floor, the meetings, what's your sense in terms of where we are?
How would you describe the state of the industry at this moment?
I think it's a pivotal point right now.
It sounds like fearmongering or something like this or existentialism.
Okay.
But if you look at like Nvidia's Jensen's posts from like 10 days ago
and you think about like the open AI or open source stuff versus closed source things
and how AI is sort of infiltrating everything, everywhere, all at once,
It's very prevalent across all messaging.
It continues to be for the last two years,
but I think with the recent events across Open AI and Hugging Faze
or the anthropic examples or a stew of other similar things
that have happened this year,
the industry is responding that aggressively.
So what does that mean for the security folks out there
in terms of the specific pain coins that they're experiencing?
It means you're getting a lot of conflicting messaging.
from everywhere.
That's at its core, I think.
It means you have to do more or less.
You need to rethink your partnerships and frameworks
in a way that works best for your company's appetite for risk.
Some companies are all about, like, empowering employees to do whatever
and bring in new technologies to innovate
because they see the cost of not innovating
really worse than the risk of taking this approach.
And so what is the advice that you're giving to those folks to try to get this under control?
Take a deep breath.
First.
First, first.
I think that's sound advice.
Take any breath.
Don't panic, as the book says.
Sure.
Sure, the good book.
And really adapt your controls.
They're not new.
We're talking about least privilege.
We're talking about reducing your scope of impact.
And when we talk about buzzwords like zero trust.
Really what we're talking about is controlling the scope of impact for an identity
and really try to understand what guardrails meet your company's risk appetite.
And that's going to be a challenge for some companies.
And I see a lot of CSOs or cohorts or friends over the years who are coming to me now
and they're saying, you know, it's really stressful when we're like we want to pause and slow down and think about this carefully.
and the industry really isn't
affording them the luxury.
Right?
And so instead of trying to fight the tide, as it were,
really we need to find a way to flow with it
in a very controlled way
so that we're enabling transformation
and not just blocking it
or dropping gates and fences
and saying stop everything until I'm comfortable
with moving forward.
That would be a very arrogant ego to state that to their company.
And really, it's adapting to saying, where can we take risks?
What tradeoffs can we take?
Can we put in compensating controls for those areas so that the company can reach its goals?
And we're not holding it back.
To what degree does the traditional notion of identity, at least as we've defined,
find it in cyber, does it still apply?
Traditionally, like a non-person account attestations, you would essentially say,
Johnny over here, you have this scope of permissions, your employees have these scopes of
permissions.
These seem accurate from our logs and what you access day to day, and we're going to
maintain those.
But now introducing an abstraction of autonomous workloads and AI-Agentic workloads,
we need to be very certain that we maintain the same level.
of governance for attestation
and that when we introduce these
new tools that
were not bringing
in scope creep as it were
meaning the agent has more permissions
than the person
who created it
was entitled to.
That permission drift
is probably one of the largest
control risks
out there right now, I would say.
What about Shadow AI?
Knowing what's in your
what's in your world.
I think this is really paramount to any organization
understanding what AI or software.
I don't want to lump them together,
but let's talk about AI because that's the bigger risk here.
Right.
And it has actually more potential, I guess.
So that's probably why we should care about it.
Shadow AI entering the environment is not just a risk
to like maybe Johnny uploads sensitive information
to an AI chat.
There's compounded cost risks there.
tools entering your environment,
missing data processing addendums,
all these non-sexy governance,
risk and compliance workflows
still have to be performed.
And if you don't have a solution
where you can actually monitor and see
what shadow AI is coming into your environment,
you're just sort of like burying your head in the sand.
You're saying,
ignorance is bliss if I don't know about it.
And this is a real thing that Seasel is
They say, you know, if I know about it, I have to do something about it.
Right, right.
If I don't know about it, I don't have to do something about it.
I have this blissful ignorance that I can legally defend myself with, right?
Right.
But, I mean, then ignorance and negligence sort of become hand in hand there, right?
And it's, I would challenge CISOs as a former Cizzo to really change their mindset there
and really just go head first into the unknown.
and really try to catalog and understand what's entering your environment.
Stephen Harrison is VP of Product at Abnormal AI.
Stephen, thank you so much for taking the time for us.
Thank you so much for having.
If you want to learn more, be sure to check out all the links in our show notes.
What's the one thing in business that's spreading as fast as AI?
AI risk.
Every new tool your team signs up for, every vendor that turns on AI features,
every new integration, each one is another opportunity for something to go wrong.
And most security programs weren't built to keep up with AI's pace of growth.
Enter Vanta.
Vanta is the number one agenetic trust platform, trusted by more than 16,000 fast-moving
companies like Ramp, Hurser, and Harvey to help them stay audit-ready.
And now Vanta helps companies like yours keep an eye on the risks that appear between
audits across your vendors, your AI tools, and your entire environment.
The Vanta agent works like a 24-7 GRC engineer in the background.
It finds issues, drafts, fixes for you, and can cut vendor assessment time by up to 50%.
Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate
your security and compliance and earn and prove trust.
Get started today at vanta.com slash cyber.
That's v-a-t-a-com slash cyber.
And lastly today, a Melbourne man inadvertently hacked his gym's booking system
after asking his AI personal assistant to secure a spot in a popular class.
The agent, which was powered by Anthropics Claude via OpenClaw software,
analyzed the Jim's API, discovered it lacked basic authorization checks,
and exploited the vulnerability to book classes months before the allowed window.
Additionally, when the user asked if he could be moved higher up on the waitlist,
the AI canceled the reservation of the person in the number one spot as a test,
then bumped the person in the number three spot to make room for its user.
The AI was unable to add the members back to the wait list and apologized.
for not being more careful.
Wow.
And that's the Cyberwire.
For links to all of today's stories,
check out our daily briefing at thecyberwire.com.
We'd love to know what you think of this podcast.
Your feedback ensures we deliver the insights
that keep you a step ahead
in the rapidly changing world of cybersecurity.
If you like our show,
please share a rating and review in your podcast app.
Please also fill out the survey and the show notes
or send an email to Cyberwire at N2K.com.
N2K's lead producer is Liz Stokes.
We are mixed by Trey Hester
with original music and sound design by Elliot Peltzman.
Our executive producer is Jennifer Ivan,
Peter Kilpey is our publisher,
and I'm Maria Vermazas in for Dave Bittner this week.
Thanks for listening. We'll see you tomorrow.
