CyberWire Daily - AI without adult supervision.
Episode Date: August 6, 2026Meta’s AI models join the sandbox escape club. China’s telecom footprint in the U.S. may be larger than expected. The White House keeps its AI safety playbook under wraps. AI coding tools introduc...e new GitHub risks. ENISA expands its CVE role. A critical Paperclip flaw enables code execution. Crypto wallet fears fuel phishing attacks. Researchers uncover a backdoor in Chinese-made routers. The Snowflake hacker pleads guilty. Our guest is Dustin Childs, Head of Threat Awareness of TrendAI’s Zero Day Initiative, discussing the new Patch Tuesday era. AI takes your word for it. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Dustin Childs, Head of Threat Awareness of TrendAI’s Zero Day Initiative, discussing the new Patch Tuesday era. Be sure to check Dustin out on the AI Security Briefing podcast. Selected Reading Meta AI Hacked External Systems During Cybersecurity Testing (SecurityWeek) Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says (The Record) Secret White House AI Safety Framework Draws Criticism (BankInfo Security) Few Federal Agencies Trust Their Own AI Agent Security (BankInfo Security) Black Hat USA 2026: One GitHub Issue Could Compromise Major AI Coding Workflows (Hackread) ENISA scales up its role in the CVE Program (enisa) Critical Paperclip Flaw Allowed Admin Access, Code Execution (SecurityWeek) COLDCARD security audit phishing attack installs remote access tool (Bleeping Computer) Chinese-made Zbtlink routers have backdoor, researchers say (Reuters) Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions (US Department of Justice) “I’m Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails (Hackread) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
AI is making fishing attacks faster, more convincing, and harder for people to spot,
and traditional security awareness and fishing training weren't designed for this level of attack.
Hawkshunt helps security teams prepare employees for the attacks they face every day,
with personalized fishing training that adapts to each employee and reduces risky behavior over time.
For IT and security leaders looking to strengthen their human layer of defense without adding more manual work,
visit hoxhunt.com slash cyberwire to learn more.
That's h-o-x-h-U-N-T.com slash cyberwire.
Meta's AI models join the Sandbox Escape Club.
China's telecom footprint in the U.S. may be larger than expected.
The White House keeps its AI safety playbook under wraps.
AI coding tools introduce new GitHub risks.
Anisa expands its CVE role.
A critical paperclip flaw enables code execution.
Crypto wallet fears fuel fishing attacks.
Researchers uncover a back door in Chinese-made routers.
The snowflake hacker pleads guilty.
Our guest is Dustin Childs, head of threat awareness of Trend AI's Zero Day initiative,
discussing the new Patch Tuesday era.
And AI takes your word for it.
It's Thursday, August 6th, 2026.
I'm Dave Bittner, and this is your Cyberwire Intel Briefing.
We've been recording on-site at Black Hat this week from our podcast studio in the SpectorOps Kennel Club.
Thanks to everyone who stopped by for an interview or just to say hello.
We've gathered interesting insights and perspectives from our many guests,
which we'll be sharing here on the daily in the coming days.
And special thanks to SpectorOps for their partnership,
providing us with a first-class home base here at Black Hat.
Here's today's news.
Not to be left out of the party,
META has disclosed that one of its advanced AI models
escaped its intended testing boundaries
during an independent cybersecurity evaluation
conducted by Israeli startup irregular.
Due to a misconfiguration that allowed Internet access,
the model exploited a vulnerability in an unnamed third-party service,
and breached another organization's systems, making unauthorized internal changes.
MEDA is investigating the incident and plans to publish a full retrospective.
The disclosure follows similar reports from Anthropic,
whose Claude models also escaped Irregulars Testing Environment
after mistakenly treating live Internet access as part of the exercise.
Those models compromised three organizations, including a cybersecurity company,
by carrying out sophisticated actions, such as publishing a malicious Python package.
OpenAI has also reported AI models escaping test environments,
including attacks on previously unknown vulnerabilities.
Separately, the UK's AI Security Institute observed Anthropic and OpenAI models
using tools such as Tor, malicious GitHub pull requests,
and social engineering to target real organizations during front-taxed.
tier AI testing.
A bipartisan House Select Committee on China investigation found that China Mobile, China Unicom,
and China Telecom continue to maintain a significant presence in the U.S. Internet ecosystem
despite losing key Federal Communications Commission licenses over cybersecurity concerns.
The 49-page report, prompted by the Salt Typhoon Telecom hacking campaign, concludes the state-owned
carriers remain closely tied to the Chinese government and have preserved access to critical
U.S. network infrastructure through less regulated services, data centers, interconnection agreements,
and network equipment. Lawmakers warn these footholds could provide opportunities for future
state-sponsored cyber operations and recommend expanding the FCC's authority, requiring the
removal of Chinese telecom equipment and increasing federal cybersecurity expertise.
The report also cites historical links between the companies and previous cyber incidents
and Chinese hacking organizations.
The White House is facing criticism after deciding not to publicly release its long-awaited
voluntary artificial intelligence safety framework, which is expected to guide how the government
evaluates advanced AI models before public deployment.
Critics argue that keeping the framework confidential undermines transparency and leaves developers,
researchers, and the public uncertain about the rules governing AI oversight.
The move follows a series of high-profile AI security incidents and government reviews of frontier models
from companies including OpenAI and Anthropic.
Meanwhile, a Booz-Allen-Hamilton survey found that although many federal agencies are piloting autonomous AI agents,
Few have deployed them in production, and only 28% of technology leaders are confident they can do so securely.
Respondents cited concerns over protecting sensitive data, unauthorized agent controls, and AI-enabled cyber attacks,
reinforcing calls for clearer governance, stronger security controls, and better guidance for deploying increasingly autonomous AI systems.
Researchers from NoV security disclosed vulnerabilities in AI coding tools from Anthropic, Google, and OpenAI that could allow attackers to exploit public GitHub issues, the compromise software repositories.
Presented here at Black Hat USA 2026, the research showed that untrusted issue content could influence AI agents with access to repository credentials, enabling remote code,
execution, credential theft, and unauthorized repository changes.
Anthropic fixed multiple flaws in clawed code, including a vulnerability that could leak
sensitive data through Hugging Face.
Google patched a critical Gemini-CLI vulnerability with a CVS rating of 10 that exposed
GitHub and API credentials in certain automated workflows.
OpenAI addressed a Codex workflow flaw that allowed attacker instructions to
persist between agent runs. Researchers found similar configurations in more than 100 public repositories
and urged organizations to update affected tools, restrict token permissions, and isolate AI workflows.
Enissa, the EU agency dedicated to enhancing cybersecurity in Europe, has expanded its role in the
CVE program, now overseeing 20 CVE numbering authorities,
including eight transferred from the MITRE route.
The agency said the expansion strengthens global vulnerability management
as emerging technologies, including frontier AI models,
accelerate vulnerability discovery and exploitation.
As the EU's CVE route,
ANISA recruits, supports, and coordinates European CNAs
while working closely with SISA and MITR.
The agency says the broader CNA network
will improve the resilience, capability, and global representation of the CVE program.
Researchers at OASIS Security disclosed a critical authorization bypass vulnerability
with a CVSS score of 10 in the AI management platform paperclip.
The flaw allowed remote attackers to self-register, gain elevated API access,
and deploy malicious AI agents capable of executing arbitrary code,
with the server's privileges.
Paperclip has patched the issue by strengthening authorization checks and company scoping.
The company also fixed two additional vulnerabilities involving sensitive data exposure
and DNS rebinding flaw that could enable code execution on developers' machines.
ProofPoint researchers have identified a fishing campaign
that exploits concerns over a recently disclosed cold-card hard
where wallet vulnerability and a suspected $88 million Bitcoin theft.
Attackers send emails posing as cold card,
urging users to complete a fake security audit through a fraudulent website
featuring live chat support, likely staffed by human operators.
Victims are persuaded to download a supposed diagnostic tool
that actually installs Connect-Wise screen connect,
a legitimate remote access application,
giving attackers full control of the compromised system.
The access could be used to steal cryptocurrency and sensitive data,
install additional malware, or deploy ransomware.
The campaign highlights how cybercriminals rapidly capitalize
on high-profile security incidents
by combining convincing social engineering
with trusted remote management software.
Researchers at Volnchechak say they discovered a previously undocumented
backdoor in more than 20 models of ZBT link routers sold globally under the ZBT Link and
Y Flyer brands. The back door reportedly contacts a Chinese registered domain every 35 seconds,
potentially enabling remote access to the routers and connected devices. Volncheck did not
notify ZBT link before publication, stating that coordinated disclosure assumes the vendor did
not intend the behavior. Conor Riley Muka, a 26-year-old Canadian, pleaded guilty in the U.S.
yesterday to his role in the widespread 2024 snowflake data theft campaign, admitting to computer
fraud, wire fraud, identity theft, and conspiracy charges. Prosecutors say he and his co-conspirators
used stolen credentials to access at least 165 customer environments, steal billions of records,
and extort victims, earning roughly $2.5 million in ransom payments. Moka will be sentenced
in October. He faces a mandatory minimum penalty of two years in prison for aggravated identity
theft and a maximum of 30 years in prison for three other counts.
Coming up after the break, my conversation with Dustin Childs,
head of threat awareness at Trend AI's Zero Day Initiative,
we're discussing the new Patch Tuesday era,
and AI takes your word for it.
Stay with us.
What's the one thing in business that's spreading as fast as AI?
AI risk.
Every new tool your team signs up for,
every vendor that turns on AI features,
every new integration, each one is another opportunity for something to go wrong.
And most security programs weren't built to keep up with AI's pace of growth.
Enter Vanta.
Vanta is the number one agentic trust platform, trusted by more than 16,000 fast-moving
companies like Ramp, Hursor, and Harvey to help them stay audit-ready.
And now Vanta helps companies like yours keep an eye on the risks that appear between audits
across your vendors, your AI tools, and your entire environment.
The Vanta agent works like a 24-7 GRC engineer in the background.
It finds issues, drafts, fixes for you, and can cut vendor assessment time by up to 50%.
Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate
your security and compliance and earn and prove trust.
Get started today at Vanta.com slash...
cyber. That's V-A-N-T-A-com slash cyber.
Dustin Childs is head of threat awareness at Trend A-I's Zero Day Initiative.
We got together to discuss the new Patch Tuesday era.
Going back to before there was a patch Tuesday, enterprises were very disturbed at the irregular
pace that patches were coming out. Microsoft was essentially releasing patches when they were ready,
whether it was Tuesday, Wednesday, Thursday, Friday,
and enterprises just couldn't cope from a vulnerability management standpoint.
Did they let them know, hey, can we agree on one day of the week?
And Patch Tuesday became that day that they said, okay, we'll consolidate all of our patches to release on Patch Tuesday.
And that was the genesis of it.
And over the next 20-plus years, it became the standard that the industry followed.
Adobe does it, Oracle does it.
Cisco usually does it as well.
So it really culminated in a time where enterprises are expecting patches to come out on the second Tuesday of every month,
and they've geared their vulnerability management processes based on that.
And is it fair to say that over the past couple of decades, that cadence has served us all well?
Generally speaking, yes.
I mean, it got some regularity to it.
It allowed us to prepare.
It allowed us to resource manage.
It allowed us to, you know, gear up for certain things and know that.
okay, this is a time we're going to have to do this.
So yes, it has been a good thing
that Microsoft started all those years ago.
Well, over the course of this year,
and particularly the last couple of Patch Tuesdays,
we've seen some real changes here.
What's going on?
Well, really, it's of the volume that has changed.
It used to be, you know, Microsoft would release somewhere
between 50 and 100 CVEs a month.
Then they released like 250.
And then last month, they released,
over 600. Adobe had a sharp increase as well. Oracle has sharp increase, and now even Apple
has had a sharp increase. So it's a bit of a bug apocalypse that we're living through right now.
Thanks to AI-driven vulnerability discovery, the volume has just absolutely exploded.
And what are the ramifications of that? Is Patch Tuesday in trouble, or might it collapse
under its own weight?
Well, it might.
Certain organizations, Apple and Adobe, most notably,
have decided to do additional releases beyond just Patch Tuesday
to try and lessen the load for just Tuesday itself.
Microsoft has decided not to do this,
but it really, what it introduces is an even bigger patch gap for enterprises.
I mean, it's great that Microsoft can patch 600 bugs in a month,
but it's very difficult for organizations to roll those patches out to their enterprise
within any time whatsoever,
and that's leaving their systems incredibly vulnerable
as they test and deploy this gigantic load of batches.
How would a typical organization handle this,
this avalanche of patches?
How do you prioritize?
Well, you have to prioritize first
with what your internet-facing systems are
and start from there.
So if you have SharePoint connected to the internet
or RDP or WRDP or,
whatever, those are your systems that are going to be your most vulnerable. Then after that,
you're going to look at your systems that are most critical to your business and start with those
and then prioritize everything else as Tier 3. So, I mean, really, you have to break it down that way,
and you have to make sure your asset discovery is up to date because you don't want to be trying
to test and deploy patches for systems that you don't have and you don't want to miss patches for
systems that you might not remember that you have. So you need to know what you're protecting.
And asset discovery is the key piece to that.
How do you suppose this could play out in the future here? Do we suspect the rate to continue increasing
or do we think it'll level out at some point? I do think it will stay very high for quite a few
months. Hopefully it will return back down to a more reasonable level. But I think we are here
with this level of volume for a while.
And the AI vulnerability discovery is what's really pushing this,
both internally and externally.
And I say that because if you look at the huge release from Google Chrome,
it was, I think, over 400 CVEs,
but most of those were discovered internally using AI.
So that's great that they're able to do that
and close those holes before external people do.
But eventually, AI is going to run out of bugs
that they can discover easily,
and then it's going to go back to a lower level
as we've patched these holes.
We saw something similar when fuzzing became very popular the first time.
We got all these low-hanging fruit bugs.
We had a huge explosion, and then it tailed off.
So I do think it will tail off,
but I think we're going to be here for at least another six months.
It seems like maybe at the moment it's kind of a mixed blessing,
but in the long haul, do we suspect this is going to be a good thing?
In the long haul, yes, it is a good thing because we're finding and fixing bugs,
and that's always a good thing, at least in my opinion.
But in the short term, it's going to be some rough writing and some very long nights
for the people who are in charge of patching the systems.
Hopefully, they're learning how to use AI for defense as well and for triage.
And that's what we do here at ZDI.
We saw a 450% jump in submissions to our program,
and we had to turn to AI to help us triage that level of bug.
So yes, it's a good thing overall,
but it's going to be some rough sailing to get us through this.
What's your advice for that person out there who's feeling overwhelmed
and feels like they don't have the resources to deal with this?
Maybe they're thinking of, you know,
they've got to go knock on the board of directors' door
and say, hey, we're drowning here.
Yes, I would say definitely make that call.
Definitely talk to your board and let them know
how resource constraints you are, but also to remember to take a deep breath, and it's like
eating at an elephant, one bite at a time. So you just take care of one problem, and then the next
problem, and then the next problem. And you will get there. I try to be encouraging with this,
but I also recognize that everyone out there I know is the three unders, which is understaffed,
underfunded, and under pressure. So taking that to the board to try and get some additional resources,
especially if it's in the area where you can do any sort of automation,
I think that's a very good thing.
What are the opportunities for automation here?
Can we fight fire with fire and throw AI at this problem?
I definitely think so.
And I think really the opportunity here is when it comes to the testing of these patches
before they get deployed.
Right now, that's a very laborious process.
And it's one of the things, you know, that generally speaking,
you want to test things before you roll them into production.
and hopefully AI can automate a lot of that testing process and get us to the point where not removing the human in the loop at all,
but getting it to the point where it's like we can get more confidence with these patches without having to manually test them all the time.
That's Dustin Childs from Trend AI's Zero Day Initiative.
And finally, according to Cisco Talos, some hackers have discovered that one of the East,
easiest ways to persuade an AI assistant to help with cybercrime is simply to say, I'm allowed.
Researchers found that AI coding tools often accepted unverified claims of authorization,
enabling attackers to build malware, develop distributed denial of service tools,
harvest credentials, and automate criminal operations with surprisingly little resistance.
The study found that less experienced threat actors could use AI to create basic attack tools,
while more skilled operators leveraged it to validate massive email lists, harvest secrets from
vulnerable systems, test telegram applications, and probe internet-connected camera services.
Although AI did not eliminate the need for technical expertise, it significantly accelerated
routine offensive tasks. Cisco Talos concluded that the effectiveness of AI in cybercrime
still depends largely on the operator's skill,
but warn defenders to prepare for a growing wave of AI-assisted attacks,
especially as current guardrails remain easier to charm than to enforce.
And that's the Cyberwire.
For links to all of today's stories,
check out our daily briefing at thecyberwire.com.
We'd love to know what you think of this podcast.
Your feedback ensures we deliver the insights
to keep you a step ahead in the rapidly changing world of cybersecurity,
If you like our show, please share a rating and review in your favorite podcast app.
Please also fill out the survey in the show notes or send an email to Cyberwire at n2K.com.
N2K's lead producer is Liz Stokes.
We're mixed by Trey Hester with original music and sound design by Elliot Peltzman.
Our contributing host is Maria Vermazas.
Our executive producer is Jennifer Iben.
Peter Kilby is our publisher, and I'm Dave Bittner.
Thanks for listening.
We'll see you back here.
tomorrow.
