CyberWire Daily - Fake it till you exfiltrate it.

Episode Date: August 18, 2026

A fake consultancy fronts an alleged Chinese spy campaign. Meta heads to court over claims it hooked young users. Researchers crack the mystery behind the French EncroChat hack. CISA warns ransomware ...gangs are exploiting a Windows flaw. Meet C2Looper, a new Rust-based backdoor. A critical WordPress plugin bug threatens hundreds of thousands of sites. MessiahGPT brings generative AI to cybercrime. A lender discloses a breach affecting 1.2 million people. A Ukrainian developer stands trial in Switzerland over alleged ransomware ties. Our guest is Ev Kontsevoy, CEO at Teleport, discussing how AI agents have nondeterministic behavior. The psychology of the endless scroll.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today’s Industry Voices, we are joined by Ev Kontsevoy, CEO at Teleport, discussing how AI agents have nondeterministic behavior. If you enjoyed this conversation, check out the full interview here. Selected Reading A fake website and a deluge of CVs: the Australian firm embroiled in an FBI probe into alleged Chinese espionage (The Guardian) States Seek $200 Billion From Meta Over Child Social Media Addiction Claims (The New York Times) Revealed: Cyber spies used malware from GitHub to hack EncroChat cryptophone network (Computer Weekly) CISA: Windows Task Host flaw now exploited by ransomware gangs (Bleeping Computer) C2Looper Backdoor Uses GitHub for C2 (ThreatLabz) 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw (SecurityWeek) MessiahGPT Criminal AI Service Advertised on BreachForums (HackRead) Heights Finance Data Breach Impacts at Least 1.2 Million Individuals (SecurityWeek) Ukrainian software developer faces 12 years in Swiss ransomware trial (The Record from Recorded Future News) Why Can't We Stop Scrolling? (Psychology Today) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. Social engineering attacks look trustworthy, a routine request, an internal email, a familiar face on a call. But Dopple sees through the disguise. Their AI-native platform detects and disrupts attacks across every channel, trains employees to recognize deepfakes and deception, and investigates every fish to take down the campaign behind it. They fight relentlessly to protect your... your business, brand, and people. Dopple, outpacing what's next in social engineering.
Starting point is 00:00:43 Learn more at doppel.com. That's do p-p-p-el.com. Of fake consultancy, fronts an alleged Chinese spy campaign. Meta heads to court over claims it hooked young users. Researchers crack the mystery behind the French encrochat hack. Cicill warns ransomware gangs are exploiting a windows flaw. C-2 looper is a new Rust Bills. based backdoor. A critical WordPress plug-in bug threatens hundreds of thousands of sites.
Starting point is 00:01:28 Messiah GPT brings generative AI to cybercrime. A lender discloses a breach affecting 1.2 million people. A Ukrainian developer stands trial in Switzerland over alleged ransomware ties. Our guest is Ev Konsevoy, CEO at Teleport, discussing how AI agents have non-deterministic behavior. And the psychology of the endless scrolls. It's Tuesday, August 18th, 2026. I'm Dave Bittner, and this is your Cyberwire Intel briefing. Thanks for joining us here today. It's great to have you with us. The Australian Consultancy Horizon became an unwitting target in an alleged Chinese espionage operation, after criminals created a fake website impersonating the firm and used it to recruit defense,
Starting point is 00:02:41 trade, and political experts in the United States. Beginning in mid-20205, Horizon received a flood of job applications, calls, and emails from people responding to positions the company had never advertised. A year later, the fake website was seized by the FBI as part of a U.S. Department of Justice investigation into 13 websites allegedly linked to Chinese intelligence operations. According to the FBI, the sites used stolen identities, AI-generated images, and fabricated consultancy firms to recruit individuals with access to sensitive or classified information. China has denied the allegations, calling them baseless.
Starting point is 00:03:27 The case highlights growing concerns that AI and convincing online impersonation can make espionage recruitment more effective, prompting Five Eyes intelligence agencies to urge businesses and job security, to report suspicious recruiters and treat unexpected online approaches with caution. Meta faces its first federal bellwether trial over claims that Facebook and Instagram were deliberately designed to addict young users and contribute to a youth mental health crisis.
Starting point is 00:04:01 California, Colorado, Kentucky, and New Jersey alleged the company violated federal child privacy and state consumer protection laws, by promoting its platform as safe while allegedly knowing their risks. If successful, the states could seek damages approaching $200 billion. Meta denies the claims, arguing it has implemented safeguards for teens, including privacy protections and messaging restrictions, and contends it is being unfairly singled out for industry-wide challenges. The six-to-eight-eight-week trial is expected to feature test-perature.
Starting point is 00:04:40 from CEO Mark Zuckerberg and internal company documents. The outcome could influence thousands of similar lawsuits and shape future regulation of social media platforms designed for younger users. Computer Weekly reports that Czech cybersecurity firm InVAS has reverse-engineered the malware French authorities used to hack Encro chat phones back in 2020, revealing details previously protected as a national security secret. Researchers found the French implant relied on the Android bad binder vulnerability and the open source Frida toolkit.
Starting point is 00:05:22 The malware gained route access, disabled security controls, and copied messages and other data directly from infected phones, often sending them to police within seconds. Invasis also found that much of the exploit code came from publicly available tools and described the malware as technically unsophisticated and prone to failure. The findings appear to support the position that police obtained messages through device interference rather than intercepting encrypted communications in transit. British and European lawyers say the new technical evidence could have major consequences for ongoing appeals and legal challenges
Starting point is 00:06:04 concerning the admissibility and disclosure of encrochat evidence. Sessa says ransomware gangs are exploiting a high-severity Windows task host privilege escalation vulnerability that Microsoft patched in November of last year. The flaw affects Windows 11 and Windows Server 2025 and can allow a local attacker with basic user permissions to gain system privileges and take full control of an unpatched device. Sisa first added the vulnerability to its known exploited vulnerabilities catalog in April, then updated the listing Friday to confirm ransomware use.
Starting point is 00:06:45 The agency has not disclosed details about specific attacks. Z-scaler Threat Labs has identified C2 Looper, a new Rust-based malware family likely associated with ransomware operations and designed to establish an initial foothold on compromised systems. First observed in July, the malware supports remote command execution, system reconnaissance, and deployment of additional payloads. Researchers believe, with low-to-medium confidence, that is distributed through multi-stage click-fix campaigns.
Starting point is 00:07:22 C2 looper uses encrypted strings, dynamically resolves Windows APIs, and communicates with command and control servers over HTTP. A newer variant demonstrates ongoing development by replacing traditional infrastructure with GitHub-based command and control, adding new reconnaissance and file management capabilities and improving command handling.
Starting point is 00:07:47 According to Threat Labs, the malware's evolving feature set suggests it is intended to support lateral movement, data collection, and the deployment of follow-on-ne-on-examines. malware, including ransomware. Defiant has disclosed a critical vulnerability in the Forminator Forms WordPress plugin that could allow unauthenticated attackers to achieve remote code execution through arbitrary
Starting point is 00:08:13 file uploads. The flaw affects multiple versions and was recently patched. While default configurations reduce the risk, sites using custom file upload storage may be vulnerable to complete compromise through uploaded web shells. The plugin has more than 600,000 installations with an estimated 300,000 sites still running vulnerable versions. No active exploitation has been reported. Trellix has identified Messiah GPT, an AI service advertised on breach forums as an unrestricted platform for generating malware, fishing content, and other illicit material. The service offers free trial queries, paid subscriptions starting at $8 a month,
Starting point is 00:09:02 cryptocurrency payments, and no identity verification. Its operators claim the model was built without common AI safety controls and trained on unrestricted data, although Trellix could not independently verify those claims. Researchers say Messiah GPT is part of a growing underground market for criminal AI tools, alongside services such as dark GBT and apex AI, as well as stolen access to legitimate AI platforms. The report highlights how cybercriminals are increasingly commercializing AI, offering dedicated services designed to support malicious activities
Starting point is 00:09:42 while avoiding the safeguards imposed by mainstream providers. Heights Finance Holdings is notifying more than 1.2 million individuals that personal and financial information was stolen after hackers breached a third-party cloud platform used to store customer data. Exposed information includes names, social security numbers, bank account details, government IDs, and dates of birth. The company says its core loan systems were unaffected and has found no evidence the stolen data has been posted online. Heights is offering 24 months of credit monitoring and identity protection. to affected customers.
Starting point is 00:10:27 A Ukrainian software developer is on trial in Switzerland, where prosecutors are seeking a 12-year prison sentence over his alleged role in the Locker Goga, Megacortex, and Nephilim ransomware operations. Authorities accuse the 52-year-old of helping develop malware used in attacks against companies, including Stadler Rail, Creologics, and Mayor Tobler, causing an estimated 130 million Swiss francs in losses.
Starting point is 00:10:59 The defendant denies any involvement, claiming ransomware source code found on his devices came from legitimate cybersecurity consulting work and challenging the handling of digital evidence. Prosecutors also seek to confiscate 1.8 million Swiss francs in alleged criminal proceeds and expel him from Switzerland for 12 years. The multinational investigation began after ransomware attacks in 2019, and a verdict is expected in September.
Starting point is 00:11:30 Coming up after the break, my conversation with Ev Konsevoy, CEO at Teleport. We're discussing how AI agents have non-deterministic behavior. And the psychology of the endless scroll. Stay with us. Ev Konsevoy is CEO at Teleport, and in today's sponsored industry voices, segment, we discuss how AI agents have non-deterministic behavior. We are back at Black Hat 2026, and it is my pleasure to welcome Ev Konsevoy. He is the CEO at Teleport. Ev, thanks so much for joining us. Thanks for having me. So we are talking today,
Starting point is 00:12:33 I think, like a lot of conversations here at Black Hat, about some of the challenges folks are facing when it comes to integrating AI into their systems. And, specifically, AI agents, and you have this notion, the thing that you want to highlight is about how they're nondeterministic in their behavior. Unpack that for us. What are the implications? Well, nondeterministic may be a simpler word to describe that. It would be unpredictable. So you can ask an agent to do something 10 times in a row, and then there is no guarantee that it's going to do the exact same thing all 10 times. That's really what nondetermin is. deterministic means. But I also think maybe for the purpose of this conversation, it's important to draw
Starting point is 00:13:17 distinction between two types of agents. It's something that I'm hearing on the floor here all the time. Because when people talk about agents, there are agents that run on your laptop, they're basically kind of your assistant on the desktop. So that's one type of agent. But another type of agent that we're more interested in is the agent that exists in a data center, like in your cloud environment. Okay. So when you can imagine when you have next, generation systems composed of hundreds of thousands of anonymous agents running on your infrastructure. It's kind of scary to realize that their behavior is unpredictable. So that is really kind of the focus of so many conversations here in Vegas this year.
Starting point is 00:13:59 Yeah. It's funny. I heard someone quip that we finally come up with computers that aren't good at math, right? They're unpredictable. They don't always give you the right answer, right? So what are the implications of that? When you have that reality in your data centers, how does that affect how you approach things? Well, the obvious implication is that in the past, we were not afraid of our own software.
Starting point is 00:14:29 So when we were talking about data integrity, data safety, people would normally think about external actors trying to hack and break into your computing environments. And that was the focus of cybersecurity industry. How do you protect your data from outside threat or from inside threat, like your own employees? But when you put non-deterministic agents into an environment, so suddenly you have another problem to worry about, might even be a bigger one, that is, how do you protect yourself from that non-deterministic behavior? How do you make sure that an agent trying to do something that you actually asked it to do would not unexpectedly, like, damage data, for example, due to hallucinations or due to, like context changes or memory changes or maybe you swap the underlying LLM and the new version of the model is behaving slightly differently. So that now is the focus.
Starting point is 00:15:23 And so kind of going back to your question a little bit. So the implications are we need to look back at what are the best practices to secure our environment and how can we modify these practices? how can we extend them to account for this change? And probably the best place to start would be the leading framework that we've been using for many years now called zero trust. So I'm not saying it's obsolete. I'm actually, there are plenty of organizations that still are behind implementing zero trust for their environments.
Starting point is 00:15:59 But we do believe that it needs to be extended. And we're proposing a new framework that we, you could probably Google it called agent trust. So that extends zero trust principles to accommodate these new realities. Well, tell us about that. What does that involve? Zero trust for those who are not aware. So it came out from series of white papers published by Google a while ago. They're very approachable.
Starting point is 00:16:25 I invite everyone to go and read them. But if we're to summarize and make a very concise short summary, zero trust comes down to roughly three core principles. One is that you need to verify an identity. Essentially, you need to make sure that you have an identity. It could be a human or it could be machine. When they try to do something, they need to prove that they are who they claim they are. So strong authentication.
Starting point is 00:16:51 So the second principle is that you need to use minimal, you need to issue an identity minimal required privileges to do something. So which means that if your job, for example, to operate. Like, if someone is granting you access to a database, you probably shouldn't be able to see all the tables in the database. You should only be able to modify tables that need it for your particular work.
Starting point is 00:17:19 Or in a computing environments for development teams, famously developers are almost never given access to production environments. Like, they don't need that. They have staging, they have tests. Right. So basically, you need to make sure you're using minimum required privileges. And the third one, you should always operate with this assumption that you are breached, that on your internal network, like within your organization, there are bad actors out there. That's actually where the zero trust name came from. It basically means don't trust the network.
Starting point is 00:17:48 So your local network is no more secure than the big internet. So your iPhone is probably the best implementation of their principle. It's equally secure whether you're on 5G or Wi-Fi. So that's zero trust. Again, enforce identity, basically use minimum required privileges and assume breach. So that is not enough to contain agentic behavior. That is not enough to deal with non-deterministic, non-predictable behavior. So what you should do, like you need to extend first principle.
Starting point is 00:18:24 So when you say, assume that you need to authenticate, you need to extend that and you just say, you need to be constantly authenticated. What I mean by that, the agent should run inside of some kind of trusted runtime. That is continuously enforcing identity of that agent. So essentially, agents should not have access to the network by default. It should not have access to disk. By default, it basically needs to be in this completely isolated environment, like a person locked sort of for gross analogy,
Starting point is 00:18:59 like in some kind of like a crazy dark room where they cannot see anything, cannot hear anything, they can't be isolated. Okay, so that's the first thing. Okay. Like, you simply cannot have an agent run in a, like with full visibility into your environment. Sure. So the second one is that you need to bound the collective autonomy of agents. What I mean by that is you might be in a situation where you have a group of agents doing something
Starting point is 00:19:28 and each agent is actually acting correctly, but the collective behavior is misaligned with your principles. So this happens all the time because of unpredictability of agentic behavior. So if an agent gets stuck trying to complete a certain task, for whatever reason, maybe latency increased somewhere or maybe some context changes. So like what used to work before doesn't work anymore, but the agent doesn't simply fail, like a traditional software,
Starting point is 00:19:59 it will try to get really, really creative, particularly if you use the latest generation models. Right. It will start trying new things to accomplish task. And when you have a group of agents doing these new things, collectively that might lead to a massive misalignment. It makes me wonder, can you end up with an agentic version of an angry mob? Right?
Starting point is 00:20:19 Well, the paperclip story is probably a perfect example of that. Yeah. Yes. And the third one, when... So the third principle is that you need to assume that you've been breached. That needs to extend to, like you need to assume misalignment. You need to assume that even though all of your monitoring, that all of your permissions and privileges are correct,
Starting point is 00:20:42 but you still need to assume that agent is doing something it's not supposed to and it's not visible, which basically means you need to watch much, much closer what agents are doing. If I'm a security professional, how do I make the case to the powers that be, to my board of directors, to my CEO, that this is the direction we need to go? Maybe they're looking at saying, hey, we're implementing zero trust. That checks the regulatory box. But I want to go in and tell them, no, we need to be proactive to the next thing. How would I make that case?
Starting point is 00:21:18 What are your recommendations? It's almost a political question. So what we see, actually, it's maybe the inverse of that is that, so this AI boom is nothing like I've ever seen before. I was, in the earlier days, I was thinking, oh, it's going to be kind of similar to cloud migration, digital transformation. You know, like when people were moving to this cloud native architectures, everything is at S-code. But that one took many, many years, and it still may be in progress. AI is happening much faster. you would meet very traditional kind of slow-moving organizations that are conservative in their pick of technologies.
Starting point is 00:22:00 But even in those organizations, technology leaders are under immense pressure to deliver on AI promises, to get AI into production like tomorrow. Like they have the strict orders all the way from CEO or from their boards. And there are given resources. That's what we are seeing. So it is maybe a rare example where, like, I wouldn't complain as a vendor, as a practitioner in the industry, that the initiative is underfunded. So from my perspective, like folks who are implementing this, like agentics strategies in their organizations, they technically have everything they need from resources perspective. The difficulties they're facing are organizational, cultural, and signal-to-noise ratio overall in the ecosystem. because every single vendor now claims that they have a full AI solution,
Starting point is 00:22:53 which obviously is not possible because... Right. For obvious reasons, yes. But people need to take advantage of this moment where there is... The resources are being thrown at this problem because nobody wants to be left behind. Yeah, exactly. Yeah. All right, well, Ev Kuntsevoy is CEO at Teleport.
Starting point is 00:23:12 Thank you so much for joining us. Thanks for having me. And finally, Doom scrolling has... has become a near-universal habit, turning idle moments into marathon sessions of TikToks, Instagram reels, and endless feeds. While social media addiction is not officially recognized as a behavioral addiction, researchers say it shares striking similarities with gambling. Like a slot machine, the infinite scroll relies on unpredictable rewards. Most posts are forgettable, but every so often one delivers the perfect joke, video, or insight,
Starting point is 00:24:07 keeping users swiping in anticipation of the next hit. Scientists are also exploring dopamine's role, but the evidence is surprisingly mixed, suggesting the brain's response may be more complicated than commonly believed. Unlike gambling, social media offers many different rewards, from entertainment and novelty to social connection and relief from boredom, making it difficult to measure and even harder to resist. In other words, the next great post is always just one more swipe away,
Starting point is 00:24:40 which is exactly the problem. And that's the Cyberwire. For links to all of today's stories, check out our daily briefing at thecyberwire.com. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app.
Starting point is 00:25:17 Please also fill out the survey in the show notes or send an email to Cyberwire at n2K.com. N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazes. Our executive producer is Jennifer Iben. Peter Kilpe is our publisher. And I'm Dave Bittner. Thanks for listening.
Starting point is 00:25:40 We'll see you back here. tomorrow.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.