CyberWire Daily - Do not pass Go(ogle).
Episode Date: July 23, 2026Google gets a billion dollar fine from the EU. The White House considers sanctions against Chinese AI developers. The GAO criticizes overlap in cyber reporting regulations. The Feds warn of Iranian ag...ents targeting OT systems. Researchers disclose a high-severity Linux kernel vulnerability. Dolphin X uses AI profiling to find high-value victims. A new backdoor routes C2 through the browser. Check Point confirms a critical zero-day. A lawsuit accuses ChatGPT of unauthorized medical advice. Ben Yelin explains how political campaigns attempt to influence LLMs. Baseball benches the bots. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies talking about how "Politicians Are Trying to Change What Chatbots Say About Them." If you enjoyed this conversation, be sure to check out Ben on Caveat every week. Selected Reading Google Hit With $1 Billion Fine for Abusing Its Power in Europe (New York Times) US Eyes Sanctions on Chinese AI Firms Over Distillation (GovInfo Security) Most federal cybersecurity reporting rules are duplicative, study finds (CyberScoop) Federal agencies broaden alert on Iran-linked OT attacks (The Record) New RefluXFS Linux flaw lets attackers gain root privileges (Bleeping Computer) New Dolphin X Stealer Employs AI Profiling to Prioritize Targets (Infosecurity Magazine) New msaRAT malware uses Chrome, Edge browsers to route C2 traffic (Bleeping Computer) New Check Point Zero-Day Vulnerability Exploited in the Wild (SecurityWeek) Lawsuit Claims ChatGPT Dished Out Dangerous Health Advice (GovInfo Security) MLB bans using dugout iPads for AI-powered in-game strategy calls (Engadget) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
What's the one thing in business that's spreading as fast as AI?
AI risk.
Every new tool your team signs up for, every vendor that turns on AI features, every new integration,
each one is another opportunity for something to go wrong.
And most security programs weren't built to keep up with AI's pace of growth.
Enter Vanta.
Vanta is the number one agentic trust.
platform, trusted by more than 16,000 fast-moving companies like Ramp, Hercer, and Harvey to help
them stay audit-ready. And now Vanta helps companies like yours keep an eye on the risks that
appear between audits across your vendors, your AI tools, and your entire environment.
The Vanta agent works like a 24-7 GRC engineer in the background. It finds issues, drafts,
fixes for you, and can cut vendor assessment time by up to 50 percent.
Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust.
Get started today at Vanta.com slash cyber.
That's V-A-T-A-com slash cyber.
Google gets a billion-dollar fine from the EU.
The White House considers sanctions against Chinese AI developers, the GAO,
criticizes overlap in cyber reporting regulations. The feds warn of Iranian agents targeting OT systems.
Researchers disclose a high severity Linux kernel vulnerability. Dolphin X uses AI profiling to find high
value victims. A new backdoor routes C2 through the browser. Checkpoint confirms a critical zero day.
A lawsuit accuses chat GPT of unauthorized medical advice. Ben Yellen explains how political campaigns
attempt to influence LLMs, and baseball benches the bots.
It's Thursday, July 23rd, 26.
I'm Dave Bittner, and this is your Cyberwire Intel Briefing.
Thanks for joining us here today.
It's great as always to have you with us.
The European Union has fined Google 890 million euros,
about $1 billion, for violating the Digital Markets Act
by abusing its dominance in search,
and its Google Play App Store.
Regulators said Google unfairly prioritized its own services,
including shopping, travel, and translation,
over competing offerings in search results,
while also restricting how app developers communicate with users
and process transactions outside Google Play.
The company has 60 days to comply or face additional penalties
of up to 5% of its global revenue.
Google criticized the ruling,
arguing it will degrade products for European users.
The decision comes at a sensitive moment
as President Trump considers new tariffs on the European Union
and has previously criticized European regulators
for targeting U.S. technology companies.
It also reflects the EU's continued aggressive enforcement
of competition rules against major technology firms,
even as similar antitrust actions against Google
continue in the United States.
The Trump administration is considering sanctions against Chinese artificial intelligence developers,
accused of stealing U.S. intellectual property to build competing AI models.
Treasury Secretary Scott Bessent said the administration will investigate
whether Chinese models were trained by copying American systems,
claiming investigators have identified watermarks from U.S. large language models in several Chinese releases.
He also alleged that Chinese developers,
Developers use model distillation, training new systems on the outputs of more advanced U.S. models to replicate their capabilities at lower cost.
While Bessent didn't identify specific companies or explain how the alleged evidence was detected,
he said any firms found to have stolen U.S. technology could face sanctions.
He also suggested American companies using Chinese AI models could eventually be required to disclose that fact to customers.
The comments come amid growing U.S. scrutiny of China's rapidly advancing AI sector and ahead of planned U.S.-China AI talks expected in September.
A new Government Accountability Office report found that nearly 70% of federal cybersecurity regulations requiring written reports to government agencies overlap with other reporting requirements, creating significant duplication for organizations.
reviewing 117 regulations across 37 agencies, the GAO identified 80 rules with similar or identical
reporting obligations, particularly affecting critical infrastructure sectors.
The report highlights ongoing challenges in harmonizing cybersecurity regulations,
despite efforts launched under the Biden administration and continued into the current Trump administration.
One example is the pending cyber incident reporting,
for Critical Infrastructure Act, which could add to existing reporting requirements for sectors
such as financial services already subject to multiple agency rules. Although the Office of the
National Cyber Director and the Department of Homeland Security have made some progress, the GAO said
broader harmonization efforts have stalled, concluding that federal attempts to streamline
cybersecurity reporting have experienced delays and achieved only limited success.
Federal agencies have expanded an earlier warning about Iranian government-affiliated cyberactivity
targeting Internet-facing operational technology systems.
The updated advisory broadens the scope beyond Rockwell Automation and Alan Bradley programmable logic controllers
to include Schneider Electric, Siemens, and potentially other manufacturers.
According to Sisa, observed attacks involved malicious project file,
and manipulation of data displayed on human machine interface
and supervisory control and data acquisition systems,
resulting in operational disruptions and financial losses.
Because PLCs are widely used in critical infrastructure,
including power, water, and manufacturing,
officials from SISSA, the FBI, and the EPA warned
that the threat is likely to continue.
The agencies urged organizations to restrict direct internet access to PLCs and strengthen deployment security to reduce the risk of compromise.
Researchers at Qualus have disclosed a high-severity Linux kernel vulnerability, dubbed Reflux FS, that allows local attackers to gain root privileges by exploiting a race condition in the XFS file system.
The flaw affects multiple versions on systems using XFS with RefLink enabled,
a default configuration on many enterprise Linux distributions.
According to Qualis, attackers can overwrite protected files,
including root-owned configuration files and suid binaries,
while bypassing standard security protections.
The vulnerability has existed since 2017 and was patched on July 16,
responsible disclosure.
Qualis estimates more than 16 million systems may be affected
and recommends organizations apply vendor-provided kernel updates immediately,
as no practical mitigations or temporary workarounds are currently available.
Researchers at Veronis Threat Labs have identified a new Windows InfoSteeler
and remote access Trojan called DolphinX
that uses an AI-powered profiling system
to help cybercriminals prioritize high-value victims.
Marketinged on a cybercrime forum,
the malware targets more than 300 applications and steals sensitive data,
including cryptocurrency wallets, SSH keys, cloud tokens, DevOps credentials,
and browser logins.
Its standout feature is an AI profiler
that automatically scores infected users
based on factors such as application usage,
browsing activity and installed software.
According to Veronis, the system enables attackers managing thousands of compromised devices
to quickly identify the most valuable targets through daily rankings,
making large-scale credential theft and victim prioritization significantly more efficient.
Cisco Talos has identified a new rust-based back door dubbed MSA Rat
used by the Chaos Ransomware Group to conceal command and control communications by routing them through Chrome or Microsoft Edge.
The malware leverages the Chrome DevTools Protocol to control a headless browser session,
avoiding direct connections to attacker infrastructure and making detection more difficult.
It establishes encrypted communication using WebRTC, Cloudflare Workers, and Twilio Turn servers,
blending malicious traffic with legitimate web activity while masking the attacker's IP address.
Recent chaos attacks have begun with fishing before deploying MSA rat through a fake Windows update installer.
Cisco Talos says this browser-based communication method significantly complicates detection,
tracing, and blocking of the attacker's infrastructure.
Checkpoint has confirmed that attackers exploited a critical.
zero-day vulnerability in its security management and multi-domain management products.
The authentication bypass flaw allows attackers to obtain an administrator login token
and modify security policies and configurations.
The attacks affected a limited number of customers with internet-exposed management environments.
Checkpoint has released patches, mitigations, and indicators of compromise,
while SISA has added the vulnerability to its known exploits.
vulnerabilities catalog and ordered federal agencies to remediate it by July 25th.
A former Florida pastor has filed a lawsuit against OpenAI and CEO Sam Altman,
alleging that ChatGPT provided dangerous medical advice that contributed to a life-threatening health
crisis. The complaint claims the chatbot evolved from a general information tool
into an unauthorized medical practitioner,
diagnosing conditions, recommending treatments,
discouraging medical care,
and fostering emotional dependence.
According to the lawsuit,
ChatGPT's personalized memory features
strengthened the relationship
and encouraged the man to rely on its guidance
instead of seeking professional treatment,
causing him to delay care for symptoms,
he says, were later linked to a pulmonary embolism.
The man alleges the experience cost him his health, career, ministry, and home.
The suit also accuses OpenAI of prioritizing user engagement over safety
by failing to implement adequate safeguards against harmful medical advice.
OpenAI has not publicly responded to the allegations.
Coming up after the break, Ben Yellen explains how political campaigns attempt to influence LLMs,
and baseball benches the bots.
Stay with us.
It is always my pleasure to welcome back to the show.
Ben Yellen.
He is from the University of Maryland
Center for Cyber Health and Hazard Strategies,
but also my co-host over on the caveat podcast.
Ben, welcome back.
Good to be with you again, Dave.
We were recently talking over on the caveat podcast
about an article that caught your eye
from the folks over at the New York Times.
What's going on here, Ben?
This is about politicians trying to change
what chatbots say about them.
So we used to have search engine optimization where politicians would try and make sure that the results of a Google search were favorable to them.
And now that is extending into the AI realm where politicians are trying to manipulate chatbots into saying positive things about them.
So the hook for this story is about a Democratic candidate for the Missouri state legislature named Dustin Lloyd.
And in doing research, he figured out that AI catbots didn't really know anything about him.
There was some basic public information about who he is and what he's running for,
but the chatbot knew nothing about his policy priorities.
So he decided to expand his own website.
He put a question-and-answer section in there about his background and his goals
and his policy prescriptions.
And almost instantaneously, he found that the chatbot responses were becoming more detailed.
They were reflecting the message he wanted to put out there.
And now he's used to use.
using and hiring people who are focused on what they're calling automated engine optimization, AEO, where you are optimizing the chatbots response to people's inquiries.
And this is a new frontier. I think political campaigns used to focus on social media, search results, as I said, traditional news coverage.
Now they have to think about how AI chatbots are synthesizing information because people trust these chatbots.
They treat chatbots as a trustworthy source of political information.
So campaigns now have the incentive to do things like create Reddit posts
that are seemingly by third-party authors talking about a candidate's policy proposals
or their appealing personal characteristics and hoping that that Reddit posts gets scraped and used in a chatbot response.
The other side of this, of course, is whatever.
a candidate does, the opposition can also do.
Right, right.
So we're going to have these kind of warring optimization wars
where one candidate's trying to put positive information out there.
I could set up a website that's like,
such-and-such-and-sucks.com,
do my own question-and-answer section
and could say terrible things about my political opponent.
But this is kind of the new frontier in campaign messaging
and getting information out there
and an information ecosystem
that's already so crowded
and difficult to navigate.
Yeah.
And I guess this is, as you say,
as we see what used to be search engines
like Google are turning into AI engines,
they're not sending you to the source anymore.
They're distilling and analyzing and aggregating
and combining into an authoritative answer for you.
Right. And that's kind of the reality that these campaigns have to deal with. And it's not just that they're creating an authoritative answer. They're creating an answer that people increasingly are trusting. And I've been prone to this myself where I should know better. I should know that a chat bot's responses aren't always reliable. They're sycophants. Chatboss are trying to please me and give me the answer that I want. But I still read the response and kind of instinctually think it's trustworthy. And I think the,
these answer engine, I said automated before,
it's answer engine optimization specialists
are understanding this phenomenon very well
and realize that if you can get chatbots
to put out not just truthful or reliable information,
but a political message that reflects your candidate's priorities,
you can gain an advantage.
You just have to know how the chatbots work.
And the fact is, the chatbots search the internet
and they pull in fresh content.
They are looking for, by fresh content,
it's current events.
When we're talking about political candidates,
it's events relating to this year's midterm election
and the candidates that are running in them.
This is a form of manipulation.
I mean, I don't think this is like an earnest search
for the truth about political candidates,
but it's just another way that political campaigns
can try and optimize what people are seeing
about their favorite candidates.
And the turnaround on this is remarkably quick,
right? Yeah, I mean, they did one study here where they made a change on Wikipedia about a certain
candidate's profile, and they tested how long it would take for that change to be reflected in
a chatbot response, and the time was 12 minutes. So it happens very quickly. And this is a new,
thing. I mean, you think back to the infancy of chat GPT in 2022, where we understood at the time,
like, chat GPT's knowledge base goes up to 2020, 2021.
Right, right.
If you ask it about current events, it's just not going to know the answer.
That was four years ago.
Like, it's just crazy how quickly all this has developed.
Hmm.
And I suppose, I mean, even beyond your local political adversary, we have to worry about international adversaries here as well, and their influence.
Yeah, I mean, anybody who can manipulate chatbots could be a friend or a foe, and you could see nation-state actors like Russia or China manipulating public profile.
are creating shell websites to put out fresh information
about candidates that they disfavor,
and that's going to show up in chatbots.
It's a great way to sow disinformation,
which does mean that this could create a societal harm.
It just seems like we're moving farther and farther away from ground truth.
Yeah, I mean, there used to be a time where there were relatively easy ways
to find out the basics about a candidate and a candidate's position.
You go to your local newspaper.
They might have profiles of,
here are your state Senate candidates.
And here's what their priorities are.
We interviewed them personally.
You make a decision.
You had mentioned on our caveat podcast,
this is what the League of Women Voters used to do.
Right.
That's just not the way it is anymore.
It's harder to figure out what's actually the truth,
especially for people who don't engage in the political process
until a week before the election.
If you've never heard of this candidate,
your first impression is going to be
what's spit out by a chatbot,
when for months, everybody,
opponents and proponents,
have been trying to game
the responses of that chatbot.
Right, right.
And again, the person who has more money
can publish more webpages
that get scraped and have greater influence
and away we go.
Sure, absolutely.
And we really don't have any restrictions
on money in politics these days.
So spend as much as you want,
optimize greater than your opponent,
gain an advantage.
Political fundraisers can realize
that this is a way
that they can have a big impact.
So if they want to donate
unlimited sums of money
in a super PAC
to try and affect
what a chat bond answer is,
they're certainly going to try and do that.
Tale as old as time.
Yep.
All right.
Well, Ben Yellen is from the University
of Maryland Center for Cyber Health
and Hazard Strategies
and also my co-host on the caveat podcast.
Ben, thanks so much for joining us.
Thanks for having me, Dave.
AI is making fishing attacks faster, more convincing, and harder for people to spot,
and traditional security awareness and fishing training weren't designed for this level of attack.
Hawkshunt helped security teams prepare employees for the attacks they face every day,
with personalized fishing training that adapts to each employee and reduces risky behavior over time.
For IT and security leaders looking to strengthen their human layer of defense,
without adding more manual work,
visit hoxhunt.com slash cyberwire to learn more.
That's h-o-x-h-U-N-T.com slash cyberwire.
And finally, Major League Baseball has decided
there are still some jobs best left to humans,
at least in the dugout.
The league has issued a mid-season policy
barring teams from using generative AI on in-game tablets
to make recommendations on substitutions, pitch selection,
and other strategic decisions traditionally handled by players and coaches.
According to The Athletic, the change followed reports
that roughly a third of teams had been experimenting with custom AI-powered apps,
though no clubs were punished after MLB confirmed they had complied with the new rules.
The move partially reverses the league's gradual relaxation of tablet restrictions imposed
after the 2021 sign-stealing scandal.
While baseball has long embraced statistics and data-driven analysis,
league officials appear to have drawn the line at letting chatbots manage the game.
After all, spreadsheets may love certainty,
but baseball has always had a soft spot for gut instinct,
unpredictable moments,
and the occasionally beautifully irrational decision.
And that's the Cyberwire.
For links to all of today's stories, check out our daily briefing at thecyberwire.com.
We'd love to know what you think of this podcast.
Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity.
If you like our show, please share a rating and review in your favorite podcast app.
Please also fill out the survey in the show notes or send an email to Cyberwire at n2k.com.
N2K's lead producer is Liz Stokes.
We're mixed by Trey Hester
with original music and sound design by Elliot Peltzman.
Our contributing host is Maria Vermazis.
Our executive producer is Jennifer Ibin.
Peter Kilty is our publisher, and I'm Dave Bittner.
Thanks for listening.
We'll see you back here tomorrow.
Heading to Black Hat USA,
the N2K's Cyberwire team
will be on-site recording from our podcast studio
in the SpectorOps Kennel Club.
If you're interested in joining us for a conversation or learning more about what we're recording throughout the week,
stop by the studio and meet the N2K Cyberwire team.
SpectorOps's Kennel Club is adjacent to Libertine Social inside Mandalay Bay.
