CyberWire Daily - Claude outside the lines.
Episode Date: July 31, 2026Anthropic says Claude escaped the sandbox three times, while a judge questions the Pentagon’s blacklist. The EU launches an AI enforcement team, the FTC targets a telehealth firm’s tracking pixels..., and a WordPress backdoor is stopped just in time. CareCloud discloses a major data breach, a stealthy cryptominer hides in plain sight, AiTM phishing surges against law firms, and Finland severs one more digital link to Russia. Our guest is Yan Shoshitaishvili, Associate Professor, Arizona State University, previewing his Black Hat 2026 keynote "Vulnerability Research in the Agentic Age." AI scammers may deserve a promotion. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Yan Shoshitaishvili, Associate Professor, Arizona State University, discussing his Black Hat 2026 keynote "Vulnerability Research in the Agentic Age." Be sure to tune in this Sunday for a special edition featuring our full, extended interview with Yan. Selected Reading Anthropic AI Models Hacked Three Organizations During Tests (Bloomberg) Anthropic, Pentagon Clash Over First Amendment Claims (GovInfo Security) EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels (SecurityWeek) FTC sues Hims & Hers for allegedly sharing patients' medical data with advertisers Meta and Snap (TechCrunch) Wordfence Finds Critical Backdoor in ARVE WordPress Plugin (Hackread) CareCloud Data Breach Impacts Over 350,000 (SecurityWeek) Cryptominer Abuses Linux PAM to Hide From SOC Analysts (Infosecurity Magazine) AiTM Phishing Becomes Top Initial Access Threat to Law Firms (Infosecurity Magazine) Finland to disconnect fiber-optic link to Russia as lease expires (The Record) AI Scammers Are Better at Building Trust Than Humans (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
This episode is supported by Black Hat USA.
If you follow the research, you know a lot of it breaks on Black Hat stages.
Hundreds of peer-reviewed briefings, more than 100 hands-on trainings,
and the largest business hall in Black Hat's history.
Six days to learn the skills you'll need tomorrow.
August 1st to the 6th.
Use code Cyberwire for $200 off your briefings pass.
at blackhat.com.
We'll see you in Vegas.
Anthropic says
Claude escaped the sandbox three times.
While a judge questions
the Pentagon's blacklist,
the EU launches an AI enforcement
team, the FTC targets a
telehealth firm's tracking pixels,
and a WordPress back door is stopped
just in time. CareCloud
discloses a major data breach.
A stealthy crypto miner hides in
plain sight, AITM
fishing surges against law firms,
and Finland severs one more digital link to Russia.
Our guest is Jan Shoshitsavili,
associate professor at Arizona State University,
with a preview of his Black Hat 2026 keynote
vulnerability research in the agentic age.
And AI scammers may deserve a promotion.
It's Friday, July 31st, 2026.
I'm Dave Bittner, and this is your Cyberwire Intel briefing.
Thanks for joining us here today.
Friday. It is great as always to have you with us.
Anthropic disclosed that a review of its cybersecurity testing uncovered three cases in which its
clawed AI models unintentionally hacked real-world organizations after escaping what were supposed
to be isolated testing environments. The company examined more than 141,000 evaluations
following a similar disclosure by OpenAI and found incidents dating back to 8,000. And found incidents
dating back to April. The breaches occurred during Capture the Flag exercises designed to test
offensive cybersecurity capabilities. Due to a misunderstanding with evaluation partner irregular,
the environments had internet access despite being presented to the models as offline simulations.
Anthropics said older models continued attacking after reaching the open internet,
while its latest model recognized the mistake and stopped. The affected
organizations were not identified, and neither they nor Anthropic initially detected the intrusions.
The company said the models, which lacked normal public safeguards, exploited weak passwords to gain
access. Anthropic acknowledged human errors contributed to the incidents and said future AI
evaluations involving powerful autonomous systems will require much stronger security controls.
Meanwhile, a federal judge expressed strong skepticism over the Pentagon's decision to blacklist Anthropic as a supply chain risk,
suggesting the action may conflict with First Amendment protections.
During a hearing in Anthropics lawsuit, Judge Rita Lynn questioned whether the Defense Department had retaliated against the company
for its public stance on limiting military use of its AI models, including mass surveillance.
Anthropic argues the designation threatens billions in revenue, while the Pentagon says it must
make independent national security decisions and trust the AI technologies it deploys.
Government attorneys maintained the designation was an internal contracting decision rather
than regulatory action, and argued AI presents unique security concerns because new models can
introduce unknown capabilities. The judge said she will
issue a written ruling. The hearing also clarified that the blacklist does not legally prohibit
all Defense Department contractors from using Anthropics models. The European Union has launched a
new enforcement team to oversee compliance with its AI Act, which takes effect Sunday, marking one of the
world's most comprehensive efforts to regulate artificial intelligence. The expanded AI office will monitor
companies for violations such as AI-generated misinformation, explicit content, cyber threats,
and other systemic risks, including threats to critical infrastructure and fundamental rights.
AI providers must clearly label AI-generated content through disclosures or digital watermarks.
The EU has also introduced whistleblower and compliance tools to support investigations
and can impose fines or restrict market access for violators.
The initiative follows recent AI safety incidents involving anthropic and open AI
and reflects the EU's broader strategy to strengthen oversight while reducing dependence on U.S. and Chinese technology.
The Federal Trade Commission has sued telehealth provider Hymns and Hers,
alleging the company improperly shared customers' sensitive medical and health information
with advertising and technology companies, including meta, snap, Microsoft, Pinterest, Reddit, and X,
while misleading users about its privacy practices.
According to the complaint, tracking pixels embedded on the company's website,
collected and transmitted health-related data and user activity,
despite privacy policy statements suggesting otherwise.
The FTC also alleges Hymns and Hers engaged in deceptive billing practices
and made subscription cancellations unnecessarily difficult.
Hems and Hers says its privacy policy gives users choices
over how their data is used
and that it intends to vigorously defend itself against the allegations.
The lawsuit continues the FTC's broader effort to crack down on health care companies
accused of improperly sharing patient-sensitive information with third-party advertisers.
A malicious backdoor was discovered in the most recent version of the Advanced Responsive Video Embedder
WordPress plugin before it reached users through WordPress.org's automatic update system.
Detected within two hours by WordFence's Prism System, the critical vulnerability with a CVSS score of 9.8,
could have allowed attackers to gain administrator access
using a single embedded authentication token.
The malicious code also transmitted site information
to an attacker-controlled server.
WordFence believes the developer's account
was likely compromised, allowing the malicious commit.
WordPress.org quickly removed the plugin from distribution
and its recently introduced update delay
prevented automatic installation on most sites.
organizations running version 10.8.7, particularly if installed manually or from third-party sources,
should remove it immediately and review their systems for signs of compromise.
Care Cloud is notifying at least 350,000 individuals that their personal, financial, and medical information
was stolen in a March 26 data breach affecting an electronic health record environment.
The company said attackers accessed one of its Amazon Web Services environments between March 10th and March 16th and likely exfiltrated sensitive data, including social security numbers, financial information, and health records.
CareCloud says it has no evidence the stolen data has been misused and is offering affected individuals 24 months of identity protection and credit monitoring.
The company has not identified the threat actor or disclosed.
the total number of impacted individuals.
Researchers at Group IB have identified a cryptojacking campaign that deliberately abandons
route access on compromise Linux servers to evade detection. After gaining route privileges
through a trusted third-party connection, the attackers used Linux plug-able authentication
modules to impersonate low-privileged users without passwords, allowing the malware to persist
while avoiding security monitoring focused on administrator accounts.
The campaign also disabled logging services, altered authentication logs, disguised malicious
processes as legitimate ones, and masked mining traffic as normal web activity.
The malware, a modified version of the XM-Rig Monero Miner, deletes itself from a disk after launching
and runs entirely in memory, complicating forensic analysis.
Group IB recommends forwarding logs to tamper-proof external systems,
restricting third-party access, and using memory forensics to detect similar attacks.
Adversary in the middle fishing has become the leading initial access method targeting law firms,
accounting for just under 29% of attacks, according to a new E-Sentire threat intelligence report.
The technique bypasses multi-factor authentication
by intercepting valid user sessions,
reflecting attackers shift from stealing credentials
to hijacking authenticated sessions.
E. Sentire also reported a 20% year-over-year increase in attacks
against the legal sector,
with identity-based threats making up more than half of all incidents.
Other common tactics included ClickFix fishing lures
that exploit filing deadlines,
abuse of Microsoft Teams,
and malware such as net support,
manager rat and Luma Steeler. The report recommends fishing-resistant authentication,
including Fido2 security keys and pass keys, stronger conditional access policies,
and improved monitoring of identity systems to detect suspicious session activity.
Finland's national grid operator, Fingrid, will disconnect a fiber-optic telecommunications
link to Russia when its lease expires at the end of the year, removing another remaining
piece of cross-border infrastructure following the end of electricity trading in 2022.
The fiber connection was part of the former electricity transmission network between the two
countries, which has since been dismantled. Fingrid said the impact on telecommunications
connectivity is expected to be minimal, although Russian media reported operators are seeking
alternative routes. The move comes as relations between Finland and Russia remain strained,
following Russia's invasion of Ukraine and Finland's accession to NATO.
Finnish authorities have also warned of ongoing Russian influence operations
and threats targeting critical infrastructure, including telecommunications networks.
Coming up after the break, my conversation with Jan Shoshatazvili,
Associate Professor at Arizona State University,
he's previewing his Black Hat 2026 keynote.
and AI scammers may deserve a promotion.
Stay with us.
Jan Shoshchia Tsevili is Associate Professor at Arizona State University.
I caught up with him for a preview of his Black Hat 2026 keynote
Vulnerability Research in the Agentic Age.
So my lab has been doing vulnerability research for a very long time.
I've been in that space since my graduate studies,
and I started my graduate studies in 2010.
And basically ever since then,
I've been analyzing different types of systems
at very deep levels for vulnerabilities.
During this, I created, along with my colleagues,
the anger binary analysis framework,
a lot of other techniques and approaches
to find bugs and software,
to understand bugs and software,
to remediate bugs and software.
And we just,
has been pushing the envelope for a long time.
So along comes this new technology,
which is LLM inference for bug hunting.
And in about 2023,
the first kind of rumbles of,
hey, this is actually pretty interestingly useful come along.
And it's just accelerated since then.
So now both in our research,
capacity and in actual, you know, security competitions,
old-day competitions like the style of poloan and so on.
We are very, very much everywhere using agentic security analysis to augment,
sometimes supersede, but mostly augment our existing work.
So I figured a lot of experience from my vantage point that I can draw on
because, you know, as a faculty researcher, I work with dozens of students and other researchers in the space.
There's a lot of lessons learned that we've taken away from a lot of different projects,
and it'd be cool to spread those lessons to the community.
Well, before we dig into the details of your presentation,
it helped me understand how vulnerability research has been considered in the past.
to me. To what degree was it thought of as a technical capability? To what degree was it a craft or even an art form?
It's a great question because it's been considered all of these different things to different extent.
When I started, it was 2010. I started as a graduate researcher, but of course I was into security before that and the CTF scene and so on.
To find bugs in software when I started, you could rely on these static analyzers with high false positives, unclear usability.
You could dig into the very, very early days of dynamic analysis with sending random inputs hoping for the best or generating file formats, hoping to observe security flaws in an application.
But really, the majority of bug hunting back then was manual.
You would stare at this software and you would understand it.
And that was very much a kind of person against software, like almost martial art.
In fact, inspired by that sort of feeling of vulnerability research as a martial art.
in the early days, created a whole like martial art and security training with my
Pone College platform.
That really was inspired by this feeling like, this is an art form.
And then gradually this art form became a science.
As new technology came up, I would say the biggest one that created, in my view,
a really a very well-defined practice of this is kind of the science.
the specific techniques would be the rise of very standardized fuzzers like American fussy lop.
There were some before that, and a lot of rows right at the same time, but around the time of DARPA's Cyber Grand Challenge competition, the world of fuzzing kind of exploded.
And now you have very well-defined, like, hey, if you want to analyze this type of software, well, this is what you do.
You set up this fuzzer.
You add these types of seeds.
You configure this type of sanitization, this type of code covering.
It became much more step-by-step kind of science, let's say, than a more vague art.
There's still space for the art.
So it was this merger of both, right?
As people built up understanding of the software they were analyzing, they could really dig in much more cleverly.
There's a lot of space for this human expertise.
and intuition.
There was a huge equalization.
You could really, without knowing much about reverse engineering and so on, start finding
bugs in real software.
And we saw a huge increase in the number of vulnerabilities identified and disclosed and
so on in that time.
That era, I would claim, is ending now, where the hacker with a fuzzer is starting to
be out-competed by hackers wielding AI agents that are wielding fuzzers.
And now in this newly kind of discovered area, you know, art and invention phase of this,
but it's going to, you know, resettle into its own very well-regmented, you know,
this is how you analyze software in the modern day as well.
Does the person who has the background in vulnerability research, the person who in the previous world was a gifted artist, do they still have an advantage using the agentic tools?
Absolutely, especially in this phase. I'm going to say something that can probably be, can certainly be criticized and I would probably call people out if they said stuff like this.
But, you know, in March, Anthropic released a sneak peek into Mitos, right?
They're a super cyber-capable model with a lot of fanfare.
And, you know, this is how many bugs, Mithos finds in this target.
This how many bugs, Mithos finds in this target, and so on.
And we were already also, of course, as was much of the rest of the world doing,
agentic-driven vulnerability research.
And we look at these numbers, as did a lot of other people,
and say, well, wait, we're getting similar numbers without mythos.
Now, the difference, of course, is the amount of kind of human expertise,
target-specific expertise, really seed, not seeds in the traditional fuzzing sense of
inputs into a program, test cases.
to drive different behavior, but seeds is in insights, different insights given to the models
and the agenetic pipelines that enabled capabilities that seem well beyond the base capabilities
of models.
I have friends that achieve, quote, mythos-like results with open models.
We've achieved in many different projects, called mythos-like results, with frontier models and so on.
the differentiator there is that human inside human intuition for now.
It's unclear if that will remain.
I don't see it fully going away anytime really soon.
You're seeing a bit of a schism with hackers actually and how they approach this.
I'm very active in the competitive Capture the Flag Community.
I ran DefCon CTF for a couple years.
I've been a core member of Shellfish for way too long now.
I think 17 years now.
That's terrifying.
So I've seen a lot of different trends in the CTF community.
When we came out with the Anchor Binary Analysis Framework, I mentioned,
it minorly, compared to LLMs,
in a minor way, revolutionized the reverse engineering,
capture the flag category.
But, you know, and when decompilers came out and got good, they revolutionized the, you know, also reverse engineering and the exploitation category, the binary exploitation category of CTFs, as well as revolutionizing, reverse engineering in the real world.
In CTF, what you saw, what I saw, because I have been in CTF for that long, with the rise of decompilers is there were hackers that refused to adopt them that really like.
looking at assembly instructions instead of pseudocode.
And some of the best of them could keep up for a while.
But if you didn't adopt the latest tools,
you were eventually kind of forced to basically announce your retirement.
And we're seeing that right now in the Capture the Flag community.
All of these hackers are retiring because to them,
what they really loved about,
capture the flag about
that sort of applied
high-stakes security
is being kind of eaten
away by the agents doing
the nitty-gritty
that they really loved to do.
We're also seeing
top
CTF teams
with the remaining players
adapt to the modern paradigm.
Because if you look at
the scoreboard of the
top CTFs, for example,
DefConCTF qualifiers.
There's a quick competition with bespoke software,
so it's not fully representative of the real world,
but there's a window to the real world at it.
You see the top teams remain the top teams
because they really invest in understanding
how to have the human value ad,
how to properly harness the modern technology
with agents and security analysis by agents
to use their human expertise to improve over the purely agente expertise.
And what I see, although less of this happens in the open, outside of the CTF community,
I see the same thing outside of the CTF community.
I see the same thing in our research labs.
I see the same thing in our spinoff companies.
I see the same space for human ingenuity and insights and expertise to still be very, very valuable.
There is more to my conversation with Jan more than we could fit in today's episode,
so we'll be running a special edition of our conversation on Sunday.
You can look for that in your CyberWire Daily Feed.
If you're heading to Black Hat USA this year, make plans to visit the SpectorOps Kennel Club.
As creators of Bloodhound, the SpectorOps team will host talks with OpenAI and the UK AI Security Institute,
as well as hands-on workshops aimed at helping you understand
AI accelerated attack paths and the latest in identity trade craft.
Visit specterops.io to pre-register and learn more.
SpectorOps Kennel Club is adjacent to Libertine Social inside Mandalay Bay.
While you're there, visit the N2K Cyberwire podcast studio
where we'll be capturing expert perspectives and conversations from across Black Hat.
And finally, artificial intelligence may soon be ready for a promotion, from scammer's assistant to scammer's co-worker.
A new study by researchers from four universities found that generative AI chatbots outperformed human scammers during the trust-building phase of so-called pig-butchering scams, where victims are gradually lured into fraudulent cryptocurrency investments.
In a week-long experiment, 46% of participants complied with an AI chatbot's request to download an app,
compared with just 18% who followed a similar request from a human.
Participants also reported higher levels of trust in the AI and sent most of their messages to the bot.
Researchers say the findings suggest AI could automate much of the relationship-building process,
leaving humans to handle only the final investment pitch
and potentially sidestep existing AI safeguards.
While AI vendors say newer models include stronger anti-fraud protections,
researchers warn the industry could shift towards more autonomous scams,
making operations harder to detect,
even if it means fewer scammers have to make awkward small talk for a living.
And that's the Cyberwire.
For links to all of today's story,
check out our daily briefing at thecyberwire.com.
Be sure to check out this weekend's research Saturday
and my conversation with Marcus Hutchins,
principal threat researcher at Expell.
We're sharing their research not very gentlemanly,
analyzing a zero-day exploit used by the gentleman ransomware
to disable targets EDRs.
That's Research Saturday. Do check it out.
And hello, Maria Vermazza is here on Sunday's T-minus space cyber briefing.
my interview with Jen Sovada of clarity about growing supply chain risks as the space industry becomes increasingly globalized.
That's Sunday on T-minus. Don't miss it.
We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights to keep you a step ahead in the rapidly changing world of cybersecurity.
If you like our show, please share a rating and review in your favorite podcast app.
Please also fill out the survey in the show notes or send an email to Cyberwire at N2.
K.com.
N2K's lead producer is Liz Stokes.
We're mixed by Trey Hester
with original music and sound design by
Elliot Peltzman. Our contributing
host is Maria Vermazes. Our
executive producer is Jennifer Ibin.
Peter Kilpe is our publisher, and I'm
Dave Bittner. Thanks for listening.
We'll see you back here next week.
Heading to Black Hat USA,
the N2K's Cyberwire team will be on-site
recording from our podcast studio
in the SpectorOps Kennel Club.
If you're interested in joining us for a conversation or learning more about what we're recording throughout the week,
stop by the studio and meet the N2K Cyberwire team.
SpectorOps's Kennel Club is adjacent to Libertine Social inside Mandalay Bay.
