CyberWire Daily - Apple has a message for you.

Episode Date: August 14, 2026

Apple sends out threat notifications to users targeted by spyware. Trivy, not LiteLLM, was the original source of the 2,500-organization supply chain attack. French tax authority confirms data breach.... Chinese hack-for-hire group conducts espionage and cybercrime simultaneously. Ukrainian police shut down 94 scam call centers. Former data analyst jailed for insider extortion plot. New macOS malware spreads via ClickFix. Today we are joined by Tom Kellermann, VP of AI Security at TrendAI, discussing the machine-speed war for financial control. And the glitch in the surveillance matrix. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tom Kellermann, VP of AI Security at TrendAI, discussing the machine-speed war for financial control. If you want to learn more on this topic, check out the article here. You can also check out Tom on the AI Security Brief here. Selected Reading If Apple sends you a push notification alerting you to a spyware attack, take it seriously (TechCrunch) Trivy, Not LiteLLM Behind the 2,500 Org Compromise (SecurityWeek) France investigates tax authority breach after hacker claims 600,000 victims (The Record) Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side (Symantec) AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers (Jamf) Ukraine shuts down 94 fraudulent call centers, seize millions in cash (BleepingComputer) This 'adversarial' pattern can prevent surveillance cameras from detecting you (TechCrunch) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. Maybe that's an urgent email from your CEO, or maybe it's a deep fake targeting your business. Dopple is the AI-native social engineering defense platform fighting back against impersonation and manipulation. As attackers use AI to make their tactics more sophisticated, Dopple uses it to fight back, automatically dismantling cross-channel attacks, building team resilience, and providing agentic email protection. Dopple, outpacing what's next in social engineering. Learn more at doppel.com.
Starting point is 00:00:47 That's do p-p-p-el.com. Apple sends out threat notifications to users targeted by spyware. Trivi, not Light L-LM, was the original source of the 2,500 organization supply chain attack. French tax authority confirms data breach. Chinese Hack for Hire Group conducts espionage and cybercrime simultaneously. Ukrainian police shut down 94 scam call centers. Former data analyst jailed for insider extortion plot. New macOS malware spreads via click fix.
Starting point is 00:01:36 Today we are joined by Tom Kellerman, VP of AI security at Trend AI, discussing the machine speed war for financial control. and the glitch in the surveillance matrix. Today is Friday, August 14, 2026. I'm Maria Varmazes, and this is your Cyberwire Intel briefing. Happy Friday, everybody. Thank you for joining me. Let's get started. Apple yesterday sent out threat notifications to users in 110 countries, warning them that their devices may have been targeted by mercenary spyware, often used by governments.
Starting point is 00:02:36 The alerts will now appear on devices. lock screens as well as being delivered to users' email addresses and on their Apple account pages. Apple recommends that users who have been targeted or believe they may be targeted enable lockdown mode on their devices, which is an extreme protection that reduces the attack surface by limiting many of the devices' functionalities. The company also advises targeted users to seek expert help, such as security assistance provided by the digital security helpline at the nonprofit Access Now. Researchers at SOC radar say the supply chain attack that compromised over 2,500 organizations
Starting point is 00:03:15 was primarily driven by a malicious build of Aqua Securities Trivy Scanner, rather than the light LLM package as initially suspected. Data shows that 95% of the affected entities were exposed to the malware days before the poisoned light LLM packages were published. The trivia attack is also attributed to the Team PCP threat actor and led to the Light LLM attack, but Sok Radar says the Light LLM compromise was the closing act, not the whole play.
Starting point is 00:03:47 Sok Radar explains that attackers hijacked the trusted trivia security scanner in Light LLM's build pipeline, used it to publish two poisoned light LLM releases to Pai-Pi, then relied on a Python startup file to run a credential stealer on every host that installed them. Francis Tacks Authority, which is the Directorate Generate of Public Finances
Starting point is 00:04:11 disclosed that it sustained a data breach in late June after an attacker used stolen credentials to gain access to its IT systems. Officials haven't confirmed details of what was stolen, but said that the intrusion allowed the attacker to view and extract data belonging to individuals and businesses. The incident was made public
Starting point is 00:04:31 after a hacker under the alias Zerobytes claimed to have stolen data on over 600,000 individuals, including names, tax IDs, and email addresses, family circumstances, and details about tax status. French authorities are investigating these claims and will share more information in the future. Symantec has published a report on Jewelbug, which is a China-based Hackers for Hire Group that conducts financially motivated cryptocurrency fraud, alongside espionage campaigns targeting foreign governments and militaries. The threat actor, which is linked to a registered contractor in Hunan province, uses the same control panel to conduct both criminal and nation-state espionage operations.
Starting point is 00:05:18 Semantic notes that this pairing is the signature of a hack-for-hire entity that is running for-profit crime on the side. Ukrainian authorities, in collaboration with international law enforcement, shut down 94 fraudulent call centers across the country following 411 police raids. police seized over $2 million in cash, a kilogram of gold, luxury vehicles, and thousands of computers and phones. The scammers posed as bank officers, brokers, and law enforcement to trick victims into making fake investments, installing malware or paying phony fees. Police are analyzing the seized equipment, which will likely lead to more arrests and the identification of the ringleaders. Cameron Curry, a 27-year-old data analyst contractor,
Starting point is 00:06:08 has been sentenced to two years in prison in North Carolina for orchestrating an insider extortion attack against Brightly Software. Between August and December 2023, Curry exploited his access to steal sensitive corporate information and then threatened to expose the data, report the company to the SEC, or encourage lawsuits.
Starting point is 00:06:30 After demanding a $2.5 million ransom, he ultimately extorted just $7,540, and 92 cents exactly. Jamp Threat Labs has discovered a new strain of macOS malware named Amnesia Steeler, which is a multi-range rust-based InfoSteeler distributed via ClickFix attacks on GitHub. Once installed, the malware harvests sensitive data from the keychain, browsers, Apple Notes, and Telegram. Amnesia Steeler differentiates itself from other MacOS malware like Atomic or MacSync by using a builder-driven configuration,
Starting point is 00:07:09 deploying OS-specific logic to exploit-patched Mac OS bypasses, and muting the host system to conceal the noise of background file exfiltration. Stay with us now after the break when Dave Bittner sits down with Tom Kellerman, VP of AI Security at Trend AI, to discuss the machine speed war for financial control.
Starting point is 00:07:39 And the glitch in the surveillance matrix. Stick with us. AI is making fishing attacks faster, more convincing, and harder for people to spot, and traditional security awareness and fishing training weren't designed for this level of attack. Hawkshunt helped security teams prepare employees for the attacks they face every day, with personalized fishing training that adapts to each employee and reduces risky behavior over time. For IT and security leaders looking to strengthen their human layer of defense, without adding more manual work,
Starting point is 00:08:23 visit hoxhunt.com slash cyberwire to learn more. That's h-o-x-h-U-N-T.com slash cyberwire. Tom Kellerman is the VP of AI Security at Trend AI and also occasional guest on the AI Security Briefing podcast. And he recently sat down with Dave Bittner to discuss the machine speed war for financial control. Here is their conversation. Well, in the beginning of my career,
Starting point is 00:08:59 I worked at the World Bank and IMF on the Treasury Security team decades ago, and I've always been fascinated by the level of security in the financial sector. And many people in the world deem the financial sector to be the most secure. And so understanding their biggest challenges in cyber is a poignant example of how we can learn from them and hopefully evolve our own defenses. Well, let's dig into some of the findings here together. I guess top of the list, what you just mentioned, are they indeed the most secure?
Starting point is 00:09:31 I would say the financial sector, coupled with the defense industrial base, are the most secure, but they're being targeted by the most sophisticated adversaries out there. And the financial sector is not just targeted by cybercrime cartels, but they're targeted by EPP threat actors that work to offset economic sanctions imposed by the West. Well, let's dig into some of the information that you all gathered here. What are some of the things that stood out to you? Well, one, most of the institutions that we spoke to acknowledge that they're suffering a siege of AI weaponized attacks, and they're grappling with that. This was compounded by the fact that they're recognizing that adversaries today are attempting to maintain positions in the systems, permanent persistence, by leveraging counter-incident response or fighting back against the defenders when the defenders are reacting to them.
Starting point is 00:10:22 And sometimes it escalates to even suffering destructive attacks, like wipers being deployed or ransomware in Apatia style. And then last but not least, I would say that they noticed that adversaries were attempting to steal non-public market information. They were targeting their market strategies. They were targeting information they may have about mergers and acquisitions and investment strategies written large. When it comes to being able to fight these threats,
Starting point is 00:10:49 How are the financial organizations resourced? Are they feeling as though they have the budgets they need? No, most of the Sissos would love more additional budgets. They're not receiving them, and thus they're employing AI to automate and orchestrate their security. However, securing the AI itself and ensuring that the guardrails aren't broken or jailbroken, for that matter, is highly problematic in today's world,
Starting point is 00:11:17 particularly when the Russian cybercrime cartels and spies specialize in jailbreaking models. And it's the Russian cybercrime cartels who are really targeting the financial sector the majority of the time, coupled with the North Koreans who are directly benefiting from tech transfer from the Russian allies. One of the things that caught my eye was your inclusion of steganography as something that was worth mentioning here. What's going on there? Yeah, you know, you're saying a really, resurgence of steganography. For those who don't know, you know, steganography essentially began during the Greeks, back when the Greeks ruled the world. You could hide a message in a painting, and the same is true for steganography.
Starting point is 00:12:03 What's making it more problematic now, though, is that steganography is being used for dynamic C2 and for the deployment of capabilities that are on sleep cycles. And the main reason why it's seeing such a resurgence isn't just because of the Russian cyber queries have embraced it, but that invisible prompt injection allows for it to be created much easier within static image files or video files. Oh, interesting. So the cost of being able to create this stuff has gone way down, presumably because of AI. Exactly right. Yeah. Let's talk about rats. Part of the report digs into that, and this is a persistent problem. It is very much a persistent problem. These adversaries that are targeting the financial sector do not want to leave the infrastructure that they've compromised.
Starting point is 00:12:48 They want to continue to pillage the environment, and then they want to use that environment to attack its customers through island hopping attacks. And so many of the most elite cybercrime crews out there are deploying a myriad of different rats. These rats are highly capable. They allow for everything from continuous key logging to surveillance platforms. one such rat X-form is probably the most sophisticated that we've seen. It is a modular architecture that allows you to do ransomware attacks, distributed denial of service, hidden virtual network computing, lateral movement,
Starting point is 00:13:22 crypto-supvoid hijacking, etc., etc. And most importantly, this one little rat for 500 bucks can actually allow you to deploy stagonography to maintain persistence on these systems. Wow. Who seems to be behind these things these days? Are there particular groups that you're tracking? Yeah, there's three groups that are probably the most active in targeting U.S. financial institutions.
Starting point is 00:13:45 You've got Fin 7, otherwise known as Carbon Spider, probably the most prolific. We've heard about them from years. They've moved from their tools of Carbonac and Dice Loader to Monoto. They're now deploying a Python-based frat called Anubis Stactore, which allows them to do memory and memory injection of additional modules and leave almost no fingerprints behind. They're highly prolific. You've got a new group, a fairly new group called Voie Ballard, otherwise known as Rocket Hack.
Starting point is 00:14:14 They were a mercenary for hire Russian group that is now acting as a cyber militia for the regime. And they are deploying things like Droid Watchers, Fireware, which allows them to compromise transactions in real time, facilitate, you know, wire transfer fraud, account takeover, etc. But most importantly, they are actually providing the benefits of these funds to help offset these. economic sanctions that were imposed against Russia. This is actually a significant day to be talking about this because the Senate's about to pass the piece of legislation in honor of Senator Lindsey Graham to increase sanctions against the oligarchs. And so as a result, you're going to see an increased level of attacks from these groups
Starting point is 00:14:54 against financial institutions to offset those sanctions. And then last for not least, you know, Lazarus Group, North Korea is basically most elite financially motivated cyber crew. It's the crew that's been supporting their members. missile program for years through the theft of cryptocurrency. And they're doing something quite interesting in terms of how they maintain dynamics C2. They're using blockchain-based CNC resolution, otherwise known as ether hiding, to store malware stages on the Ethereum network, making takedowns highly problematic.
Starting point is 00:15:25 And I do want to touch on this point. With AI, we constantly talk about reconnaissance and delivery. We constantly talk about, you know, zero-day tsunamis, et cetera, et cetera. But I think we need to pay more attention to how AI enables greater persistence. And one such example was a discovery by our threat team at Trend AI of a group called Band Campo, where he jail broke Gemini, and then he created a dynamic C2 that was both deployable, but could be rotated within five to six minutes of time on average, making IOC detection nearly impossible.
Starting point is 00:16:03 Well, speaking of speed, you know, I think velocity is something that is on everybody's minds these days. I hear practically on a daily basis that everyone needs to shift to be able to defend at machine speed. In this context, what does that mean for the financial sector? That's a great point. Look, orchestration and automation of things like attack path mapping, threat hunting, understanding knowledge graph relationships to, you know, map connections across assets and identities and events in real time is an imperative. You need to have that ground truth, that situation awareness facilitated and empowered by AI. I think virtual patching is here to stay or vulnerability shielding as otherwise known.
Starting point is 00:16:50 Vulnerable systems have to be shielded from the surge of zero days that are manifesting. And we pride ourselves on that capability coupled with the zero day initiative that we've been funding for two decades now as the original bug bounty program. Things like blast radius calculation, I mean, understanding how far an attacker could be from a single compromised asset, understanding that in real time, things like prompt injection prevention, you know, being able to make sure the instructions leveraged by attackers are blocked, particularly if they're malicious or if they're invisible prompts. Deep fake identification, I think, is very much important because they're using deep fake technology
Starting point is 00:17:29 to facilitate business email compromise, as well as reverse business email compromise, when they actually have already hijacked the account of a trusted user in the institution, and then they're leveraging transactions that way. And then I think things like writing style analysis to prevent business email compromise should also be something that should be empowered. But lastly, I think managed detection response services
Starting point is 00:17:53 should be deployed on Agentech XDR or Genetic SIM systems now. The older legacy capabilities out there, just not keeping up. That was Tom Kellerman and Dave Bittner discussing the Machine Speed War for Financial Control. If you enjoyed this chat, be sure to check out the AI Security Brief wherever you get your podcast. And finally, security researcher Bill Sweringen has unveiled no recognition, which is a project that uses reinforcement learning to generate adversarial patterns that make people and objects invisible to AI surveillance systems. After roughly 31 million tests over the past year, the system produced computer-generated designs that successfully scramble the object and facial detection algorithms
Starting point is 00:18:57 used by technologies like flock license plate readers, axon body cameras, and Clearview AI, without blocking the actual video recording. At DefCon last week, in fact, Sweringen successfully demonstrated the concept by covering a Toyota Yaris in one of the patterns, to evade a flock camera. Now, we should say that the patterns aren't exactly subtle, so you would be trading digital invisibility at the cost of real-world conspicuousness. But that's the trade-off.
Starting point is 00:19:45 And that is The Cyberwire. For links to all of today's stories, check out our daily briefing at thecyberwire.com. Be sure to check out Research Saturday, where we are joined by Ian Golden, senior lead information security engineer, and Mike Porka, principal information security engineer from Lumen's Black Lotus Labs,
Starting point is 00:20:05 discussing their research entitled Expanded JDIIOTE and SoHo Botnet enables rapid vulnerability exploitation. Now that is on Research Saturday. Check it out. And this Sunday on the T-minus space cyber briefing, that's my show. I'll be sitting down with Brandon Karp and Dave Fitner to unpack Google Earth's latest, shall we say, experiment with AI. and what it would have meant for the future of satellite imagery.
Starting point is 00:20:33 Make sure to tune in on Sunday for the full conversation. Also be sure to tune into a special edition this Sunday, where Dave Vittner sits down with Clint Gibler, who is the cyber lead at OpenAI, and Robbie Winchester, chief global professional services officer at SpectorOps, where they all discuss frontier models and the future of cyber defense.
Starting point is 00:20:54 You can find that episode wherever you get your favorite podcasts. As always, we would love to know you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill up the survey in the show notes or send an email to Cyberwire at N2K.com. N2K's lead producer is Liz Stokes. We are mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our executive producer is Jennifer Eibin, Peter Kilpey as our publisher,
Starting point is 00:21:27 and I have been your host this week, Maria Varmauses. I'm sitting in for Dave Bittner, who will be back next week. Thank you so much. We'll see you next week.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.