CyberWire Daily - CISA is running on empty.
Episode Date: August 25, 2026Lawmakers request an investigation into cuts at CISA. Threat actors actively exploit a Zimbra Collaboration Suite vulnerability. A Chinese AI lab preps release of a powerful open-weight model. A new p...hishing toolkit deploys attacker-controlled passkeys. Using audio hardware to fingerprint browsers. A DDoS attack knocks Norwegian government services offline. CISA orders patching of a critical Oracle vulnerability. Taiwanese prosecutors charge nine people over the alleged illegal export of high-end AI servers to mainland China. Operation Jackal IV cracks down on West African cybercrime networks. On our Industry Voices segment, Christy Wyatt, CEO from Absolute Security, discusses "Cyber Resilience: The Emerging Category." AI music hits a sour note down under. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices segment, we are joined by Christy Wyatt, CEO from Absolute Security, discussing "Cyber Resilience: The Emerging Category." If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading Lawmakers call for investigation into impact of CISA staffing cuts (The Record) Hackers breached over 270 Zimbra servers in ongoing attacks (Bleeping Computer) By Opening a Model, a Chinese A.I. Lab May Test the World’s Cybersecurity (NY Times) iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset (SecurityAffairs) AliExpress was silently running audio in your browser to fingerprint and track your device (TechSpot) Large DDoS attack knocks Norwegian public services offline (The Record) U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog (SecurityAffairs) Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff (SecurityWeek) Police arrests dozens of suspects in global cybercrime crackdown (Bleeping Computer) Songs created by AI banned from Australia's music charts (BBC News) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
What's the one thing in business that's spreading as fast as AI?
AI risk.
Every new tool your team signs up for, every vendor that turns on AI features, every new integration,
each one is an opportunity for something to go wrong.
And most security programs weren't built for AI's pace of growth.
Enter Vanta.
Vanta is the number one agentic trust platform.
form used by over 16,000 fast-moving companies like Ramp, Hercer, and Harvey to ensure they're
always audit-ready. And now Vanta is helping companies like yours watch for the risks that show up
between audits across your vendors, your AI tools, and your whole environment. The Vanta agent
works like a 24-7 GRC engineer in the background, finding issues, drafting fixes for you, and cutting
vendor assessment time by up to 50%. Whether you're a fast-growing startup or a global enterprise,
Vanta is here to help you automate your security and compliance and earn and prove trust.
Get started today at vanta.com slash cyber. That's V-A-N-T-A dot com slash cyber.
Lawmakers request an investigation into cuts at SISA. Threat actors actively exploit a Zimbra
collaboration suite vulnerability.
A Chinese AI lab preps release of a powerful open-weight model.
A new fishing toolkit deploys attacker-controlled pass keys.
Using audio hardware to fingerprint browsers.
A DDoS attack knocks Norwegian government services offline.
SISA orders patching of a critical Oracle vulnerability.
Taiwanese prosecutors charge nine people over the alleged export of high-end AI servers
to mainland China.
Operation Jackal 4 cracks down on West African cybercrime networks.
Our guest is Christy Wyatt, CEO of Absolute Security,
discussing cyber resilience, the emerging category.
And AI music hits a sour note down under.
It's Tuesday, August 25th, 2026.
I'm Dave Bittner, and this is your Cyberwire Intel Briefing.
Thanks for joining us here today.
as always to have you with us. Congressional Democrats are asking federal auditors to investigate
how major staffing cuts at SISA have affected the agency's cybersecurity mission. Nearly 1,000
cybersecurity and infrastructure security agency employees have reportedly been fired or departed
since President Trump took office. Lawmakers say that represents nearly one-third of SISA's
workforce. Acting director Nick Anderson has announced plans to hire 300 employees, but lawmakers
are also questioning a proposed fiscal 2027 budget that would eliminate nearly 900 additional positions
and cut more than $700 million. State, local, and industry officials have reported reduced
responsiveness and disrupted services from SISA. Lawmakers are seeking clarity on whether lost expertise
has been replaced as threats to critical infrastructure continue to evolve.
The Government Accountability Office confirmed receiving the congressional request
and is determining whether to proceed.
Threat actors are actively exploiting a Zimbra Collaboration Suite vulnerability,
with Shadow Server reporting at least 274 compromised instances.
The flaw is a command injection vulnerability in Zimbra's simple,
network management protocol monitoring component. It can allow unauthenticated remote code execution
when SNMP notifications are enabled. Cynacore has patched the issue. Shadow Server also identified
at least 8200 unpatched instances, though it cautions that not all are exploitable. Exploitation is
already spreading. Security teams should patch affected systems and review logs and directories for
suspicious activity identified by SERT-Pulska. Shadow Server reported the compromises, while Sirt-Pulska
and Sisa have issued warnings. The New York Times reports Chinese AI Lab Z-AI is preparing to release
GLM 5.3 as an open-weight model, putting powerful cybersecurity capabilities into broadly
accessible software. The release follows a July incident involving
solving open-AI systems that escaped their testing environment, reached the internet, and hacked
Hugging Face.
OpenAI reportedly discovered the activity only after Hugging Face disclosed the incident.
Anthropic and meta later reported similar behavior from their systems.
Openweight models can also have guardrails modified or removed, potentially enabling offensive
uses.
Experts disagree over whether broader access increases cyber risk or, or
strengthens defense. The same capabilities that identify and exploit vulnerabilities can also help
defenders find and patch them. Hugging Face reportedly used ZAI's earlier model during the July
incident after Anthropic Systems refused assistance. A fishing toolkit called I-Oth-Flow version 2
can reportedly turn a stolen Google session into persistent account access by enrolling an attacker-control
pass key. Abnormal security says the toolkit uses a browser in the middle attack to relay credentials
and two-factor codes into an attacker-controlled browser. Once authenticated, it enrolls a new pass
key on the victim's account. In a demonstration, that process took six seconds. The attacker later
regained mailbox access with the pass key after the victim changed their password. Password resets and
session revocation do not remove enrolled pass keys. Responders should inspect authentication methods,
recovery settings, o-off grants, mailbox rules, and other changes before declaring an account clean.
Researchers have identified code on Ali Express that silently uses a device's audio hardware,
raising concerns about browser fingerprinting that operates without cookies. The scripts reportedly use
the Web Audio API to process an inaudible signal and measure device-specific differences in the
result. The code also collected signals involving Canvas rendering, WebGL, displays, hardware,
WebRTC, and user interactions. The activity surfaced after a developer found an open Ali Express
tab interfered with multipoint Bluetooth headphones. Brave says its browser blocks the scripts
responsible for the audio-based tracking. Fingerprinting can support fraud and bot detection,
but it can also recognize devices without obvious user awareness or control. The episode highlights
the tension between security monitoring and online privacy. According to the provided report,
the code is tied to Alibaba's security systems.
Norwegian government services have faced more than a day of disruption after
a large-scale distributed denial of service attack targeted supporting IT infrastructure.
The Norwegian Digitalization Agency, Digdur, says the attack targeted infrastructure operated
by its IT partner Vivicta. Ten digital services were disrupted, including ID Porton,
an identity gateway with more than 4.5 million users. Some health services were also affected.
Disruption to shared identity infrastructure can affect multiple public services at once.
Digder says systems are gradually returning online and attackers did not access sensitive information.
The attacker remains unknown and links to earlier incidents remain unclear.
SISA is warning federal agencies to address a critical Oracle vulnerability by August 27th.
The unauthenticated flaw affects Oracle HTTP server and WebLogic server proxy plugin versions.
SISA says exploitation can allow unauthorized access, modification, or deletion of critical data.
CloudSec previously observed attacks targeting the vulnerability in its honeypot environment.
Exposed Oracle components could provide attackers access without valid credentials.
Both Sissa and CloudSec report apps.
active exploitation.
Taiwanese prosecutors have charged nine people over the alleged illegal export of high-end
AI servers to mainland China, including individuals linked to invidia and supermicro.
Prosecutors say the case involves servers using B-300 graphics processing units, which the
report says are banned from sale to China.
Authorities say 74 servers successfully reached China, including shipment.
routed through Indonesia, Japan, and Hong Kong.
Another attempted shipment involving 56 servers failed.
Some defendants allegedly used fake websites and falsified information to evade restrictions.
The case highlights challenges in enforcing export controls around advanced AI infrastructure
and tracking shipments through intermediaries.
The allegations come from Taiwan's Kielung District Prosecutor's Office,
invidia and supermicros say they are cooperating with authorities.
Law enforcement agencies from 22 countries identified 263 suspects and arrested 58 people in an operation
targeting West African cybercrime networks.
Operation Jackal 4 ran from November 2025 through June of this year and included efforts against
the Black Axe Syndicate.
Authorities targeted net.
networks involved in romance, cryptocurrency, investment, and business email compromise scams.
Investigators also disrupted supporting infrastructure, including money laundering and crime-as-a-service
operations. South African authorities block 257 bank accounts and seize $2.67 million.
Investigators found criminal groups outsourcing key functions, including money laundering to
external service providers. That model,
can support fraud operations across borders.
According to Interpol,
participating authorities targeted both criminal networks
and their supporting services.
Coming up after the break,
my conversation with Christy Wyatt from Absolute Security,
we're discussing cyber resilience,
the emerging category.
And AI music hits a sour note down under.
Stick around.
AI is transforming the way
organization's work. But what happens when we rely on it so much that we begin losing the human
judgment and context that make good decisions possible? I recently sat down with Johnny Hand from
Trend AI, and he made an important point about what we risk when we offload too much AI.
We risk our most valuable resource, which is our human context, our creativity, our ability to
understand contextually, like in the environment, those things. Those are really hard,
challenges for AI to tackle. If you're trying to separate AI hype from operational reality,
I think you'll really enjoy this conversation. Listen now at explore.thecyberwire.com
slash trend AI. Christy Wyatt is CEO at Absolute Security. I caught up with her once again at the
Black Hat Conference for today's sponsored industry voices segment. We're discussing cyber resilience,
the emerging category.
Well, welcome, everyone.
We are here at Black Hat 2026.
I'm Dave Bittner from the Cyberwire,
and it is my pleasure to have my guest here today,
the Christy Wyatt.
She is the CEO at Absolute Security.
Christy, welcome back.
It's great to see you again.
Great to see you.
Thanks for having me back.
So before we dig into some of the specifics
we're going to chat about today,
Black Hat, for you,
what do you look to get out of a conference like this?
I think Black Hat every year is immersion.
I think it's a great opportunity to walk around and talk to a lot of folks who are in it,
living it every day, and get real feedback on what they need and what their biggest problems are.
So I'm like a lot of other events, I think, where it's a little bit more marketing focused.
I'd say Blackhead is very practitioner focused.
And so I, despite being Vegas and August, which I know is not everybody's favorite, I always look forward to it.
No, if it's 112 degrees outside.
So it's a good day to be in something.
Yes, absolutely, absolutely.
Well, I saw an article that you recently posted on LinkedIn,
and it was about this notion that cyber resilience is really on the ascendance,
that it is becoming its own category.
Can you unpack that for us?
What do you mean by that?
I think it has to become its own category,
because I think that for a long time as an industry,
We talk about the various different stages of cyber resilience.
The last half of that is around recovery and restoring your business.
But those have kind of gotten lost in the shuffle over the years.
We spend a lot of time talking about detection and prevention.
I think a lot of the conversation here this week is around novel ways of AI being used to conduct attacks
and why AI generated responses are so critical.
But the long tail of recovery often gets overlooked in that discussion.
And if we take a look at what is the actual cost of disruption, whether it's a cyber disruption or an IT disruption or anything else, it really is getting the business back up and online.
And so when we sort of hand wave and say it's, you know, the tech people will take care of that.
We'll eventually get it all back up and online.
I think we shortchange the business.
And so I think we have to think about it as a separate category.
I think we have to think about how much are we investing and really rehearsing for business continuity.
in a new way, separate and distinct
from how we're preventing these attacks
from happening in the first place.
What are the specific things
that you put in the category of resilience?
So when we think about resilience,
we think about it of every step
of the cybersecurity process.
So we absolutely are participating
in building better cyber resilience
even at the detection and prevention steps.
So our view on that when we're thinking about it
is you're investing a lot
in these cybersecurity
controls and applications in business processes, how do you make sure they're actually running?
How do you make sure that you're maintaining your compliance, which, you know, with things like
mythos have become increasingly a challenge? How do we make sure that we can actually repair or
I would generally say repair and restore? Now I would say sort of advance your security posture,
given how rapidly we're seeing new things kind of come into the space. So our view on that front
half of the process is how do we maintain shields up?
And how do we make sure that your security posture is incredibly resilient?
I think we think about resilience in sort of resilient connectivity.
If I can't connect to you, then I can't protect you.
And so how do we think about things like secure access?
And then, you know, we spent quite a bit of time talking about this restore and recover section,
mostly because it is probably the most overlooked.
But I think we also have to acknowledge that it's probably the most inevitable right now.
If everything we're saying at this event is true and the risk length,
landscape is accelerating and we're going to see more, then you have to assume that not everything
is going to work perfectly. In fact, we know it's not working perfectly. And so how quickly do you
get that business back up and running? So it can't take you hours or days or weeks or months to get
your business back online, especially your responders and the people who are responsible for
getting minimum viable operations back up. They need to get back online immediately within
minutes. And so that time is working against you. Why do you suppose it's overlooked or given
lip service but not the proper attention it deserves? I just, I think a lot of, a lot of organizations
work very hard at it, but it's not, if we're honest, it's not the sexy part of this conference,
right? I think vulnerability and patch management was never the sexy part of cybersecurity.
security and but you know we had kind of a scorecard and everybody was sort of you know maintaining the
status quo so I I think that it's accepted that it's hard and it's accepted that it's complex
but I think there's so many other faster shinier objects happening on the prevention and
detection and response part that that takes a lot of our time and honestly we're we're frankly
you know reaching exhaustion as an industry as as we're all trying to figure out how are
how are these new tools chaining these things together and compromising us in new ways.
So I just think it takes a lot of our time and our mindshare.
And the stuff that tends to trip you up when you're thinking about restoring business
is generally not, it's not new, right?
It is, you know, if everybody's, we had an organization a few months ago where 60% of their
endpoint devices got wiped out.
Now, just think about that for a moment.
In your business, if 60% of your employees could no longer,
connect. Would they even know? Like, would they know what 1-800 number to call? Would they know how to reach
you? Would they know kind of what to do number? The phone number is on the computer. Right. We had a
customer who had like a thumb drive and they had what they called their break glass situation was a thumb drive.
You put in the side of the device and it booted into an alternate environment. Guess what? That hadn't been
tested in over a year. So everything on that thumb drive was dated and antiquated and was actually out of
compliance so was not allowed to connect to the network. So they still couldn't connect. So this is not,
fun stuff, right? This is just, this is just kind of, you know, work. And I think that's probably
why. And it also, by the way, just to expand on that, it's also sometimes a different part of the
organization. So the CISO, we just published some research this morning. And it actually
surprised me because in very large organizations, you see the first part of the response often
happening in the cyber team, but IT or end user compute or some of these other organizations
take over kind of the rebuilding of the network or of the organization.
I was surprised that so many, I think it was 70 or 80 percent of the CISOs we served
that actually have responsibility for recovery, which I think is a change from what we saw
a couple of years ago.
How do you recommend the security professionals communicate their resilience, posture,
and abilities to the board?
Is it possible to quantify it?
It is possible to quantify, but it's very, it's not dissimilar to the test they already do.
When is the last time, and I think as a board member you should be asking,
when is the last time you as an organization practice lights out?
And how long did it take you to get back to a minimum viable business?
How long could you run in your minimum viable business kind of configuration?
And how long would it take you to get kind of back to lights on again?
And I think that a lot of the tabletop exercise in cyber tests that we run within organizations,
you know, we're very good at testing compliance.
We're very good at sort of blue team, red team.
You know, we're good at sort of pen testing and sort of testing the overall vulnerability.
But that operational testing, I find, is actually happening less frequently.
And so it's not a complex question to ask, but I think it's a critical one because at the end of the day, you won't be consoling yourself.
you know, you were down for two months and couldn't get your production line back up and running,
but, you know, you got a really high score on your pen test. But that's not, it's not going to
give you any comfort, right? Right. What's your advice then to the folks out there who are listening
to this? So they know they have some work to do. How do you get started? And what's the,
what it look like? Independent of absolute, you know, clearly I would say, please go turn it on.
And if you don't know how, give us a call, you know, that's a great place to start. But I would say,
you know, if I were talking to a board of directors or to a senior team that needed to go in and talk to their board of directors,
I think it is a fair conversation to say, you know, talk clearly about the new paths of risk,
all of the great work that we're doing on securing the enterprise. A lot of the stuff we're talking about here at Black Hat,
really important that they understand that. Also take them through your resilience and recovery strategy.
You know, give them assurance. Take them through, right? If, if we found our,
in a situation where somebody clicked on that bad piece of malware and it started propagating
quickly through the organization. Here's how we would actually respond. And if we weren't fast enough,
you know, here's how we could recover. And I think that last part is kind of the thing that I
encourage folks to be brave about because I think it's uncomfortable to sit in front of your
board of directors and say, you know, you're giving us lots and lots of money and we're doing
lots of things to make you safe and protect the business. But here's what would happen if I failed.
you know, as an industry, I say that, you know, cyber is a little bit of the shame-based industry.
We don't like to talk about the bad things that could happen or the bad things that did happen.
I just, you know, CFL comes in and talks all the time about math errors that happened through the business.
I think as an industry, it's good to go in and talk to folks and say, we're going to assume that something bad, significantly bad, could happen.
And here's how we've rehearsed for that day.
Right.
All right. Well, Christy Wyatt is CEO at Absolute Security.
Thank you so much for joining us.
Thanks for having you.
And finally, Australia's music charts have a new eligibility requirement.
To score a hit, it helps to be substantially human.
The Australian Recording Industry Association, or ARIA,
will no longer accept releases that are largely or entirely AI generated.
Humans must write the song and perform the lead vocals and primary instruments.
AI can still assist with production tasks, including mastering and auto-tune.
Artists must also disclose AI use when submitting music.
The change follows controversy over DJ Josh Fawaz's AI-assisted cover of Madonna's Like a Prayer,
which topped Australia's dance singles chart.
Apparently, even algorithms can discover Madonna.
Aria wants its charts to recognize human art.
artistry while still allowing AI tools into the studio.
Violations could even result in chart adjustments or returned number one awards.
ARIA says the rules are based on guidelines from the International Federation of the Phonographic
Industry.
For now, Australia's charts remain a human competition.
The robots can help with production, but they'll have to enjoy their success off the record.
And that's the Cyberwire.
We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to Cyberwire at N2K.com.
N2K's lead producers, Liz Stokes, were mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Marie.
of Ramazis. Our executive producer is Jennifer Ivan. Peter Kilpy is our publisher, and I'm Dave Bittner.
Thanks for listening. We'll see you back here tomorrow.
