CyberWire Daily - Hackers hiding in plain sight.

Episode Date: August 19, 2026

Medusa’s reach grows. Cl0p expands its victim list. The DOJ charges 17 alleged Iranian hackers. CISA sounds the alarm on four exploited vulnerabilities. TWINLOOT hides in plain sight inside Microsof...t 365. Maria Varmazis shares the latest from the space-cyber realm as Ukraine strikes Russia’s satellite nerve center. The FDA considers guardrails for AI medical devices. Expired credit cards get an unexpected second life. A disgruntled contractor heads to prison. Dave Bittner sits down with Brian Vecci, Field CTO at Varonis, at Black Hat USA to discuss how AI is calling your security bluff. Highway hijinks meet high-tech hardware. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest At Black Hat USA, Dave Bittner sat down with Brian Vecci, Field CTO at Varonis, as they discussed how AI is calling your security bluff. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading CISA: Medusa ransomware hit over 500 critical infrastructure orgs (Bleeping Computer) US charges Iranians for sprawling hacking campaign on government agencies, universities (The Record) Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign (SecurityWeek) CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities (SecurityWeek) New TWINLOOT Malware Steals Windows Passwords Via Fake Lock Screen (Hackread) Ukraine says it hit Russian rocket centre linked to Starlink-style network (CNBC) FDA Weighing Possible Regs for GenAI Medical Devices (GovInfo Security) Expired credit cards revived by researchers to make unauthorized payments (The Register) Prison for data analyst who tried to extort $2.5 million from his employer (Bitdefender) ‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI Hardware (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.   Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. Social engineering attacks look trustworthy, a routine request, an internal email, a familiar face on a call. But Dopple sees through the disguise. Their AI-native platform detects and disrupts attacks across every channel, trains employees to recognize deepfakes and deception, and investigates every fish to take down the campaign behind it. They fight relentlessly to protect your... your business, brand, and people. Dopple, outpacing what's next in social engineering.
Starting point is 00:00:43 Learn more at doppel.com. That's D-O-P-P-P-E-L.com. Medusa's reach grows. Klop expands its victim list. The DOJ charges 17 alleged Iranian hackers. Sissa sounds the alarm on four exploited vulnerabilities. Twin loot hides in plain sight inside Microsoft 365. The FDA considers guardrails for AI medical devices.
Starting point is 00:01:25 Maria Vermazas has the latest news from space. Expired credit cards get an unexpected second life. A disgruntled contractor heads to prison. Our guest is Brian Vetchy from Veronis, discussing how AI is calling your security bluff. And highway hijinks meet high-tech hardware. It's Wednesday, August 19th, 2026. I'm Dave Bittner, and this is your son.
Starting point is 00:02:01 Cyberwire Intel briefing. Thanks for joining us here today. It is great as always to have you with us. The Cybersecurity Infrastructure Security Agency, alongside the FBI and the Department of Health and Human Services, has warned that the Medusa Ransomware gang has compromised more than 500 U.S. critical infrastructure organizations since June 2021. The updated advisory marks a significant increase from the more than 300 victims reported in 2025 and highlights sectors including healthcare, defense, manufacturing, government,
Starting point is 00:02:52 information technology, and financial services. Officials urge organizations to prioritize patching vulnerabilities, segment networks to limit lateral movement, and restrict remote access from untrusted sources. Active since 2021, Medusa evolved from a closed ransomware operation into a ransomware as a service model that recruits affiliates through cybercriminal forums. Sissah also notes that Medusa is often confused with other malware families, including Medusa Locker, despite being a separate ransomware operation. The U.S. Department of Justice has charged 17 Iranian nationals for their alleged roles in a long-running hacking campaign tied to the Islamic Revolutionary Guard Corps.
Starting point is 00:03:41 prosecutors say the operation conducted through the Mabna Institute targeted U.S. government agencies, universities, companies, and United Nations organizations beginning around 2013. According to the indictment, the hackers compromised thousands of professor email accounts, stealing at least 31 terabytes of research, intellectual property, academic publications, and other sensitive data. The Justice Department says the stolen information was provided to the Iranian government and sold through online platforms in Iran. The State Department is offering up to $10 million for information on five alleged participants. Officials estimate U.S. universities spent roughly $20 million investigating and remediating the breaches,
Starting point is 00:04:31 highlighting the campaign's lasting financial and security impact. The Klopp Ransomware Group is claimed more than 40 victims in a campaign exploiting a critical remote code execution flaw in PTC's wind chill and flex PLM platforms. The vulnerability first observed in active attacks earlier this year enables unauthenticated attackers to execute arbitrary code. Security researchers say Klop affiliates deployed web shells and a custom implant capable of mapping sensitive data, decrypting credentials,
Starting point is 00:05:07 and maintaining persistent access for large-scale data theft. The gang has published the names of alleged victims, including Shell, Phillips, Fiserve, Zebra Technologies, Toast, and Ingersoll Rand, while listing the types and volumes of stolen data. None of the named companies has confirmed a significant breach, though several say they are investigating. The campaign mirrors Klop's previous mass extortion operations, targeting widely used enterprise software vulnerabilities. SISA is urging organizations to immediately patch four actively exploited vulnerabilities, affecting Microsoft, VMware, and Apple products. The flaws include critical remote code execution and authentication bypass issues in Windows Internet Key Exchange, Microsoft SharePoint, VMware V Center, and MacOS screen sharing.
Starting point is 00:06:06 Researchers have linked the Microsoft and VMware vulnerabilities to real-world attacks, while the Apple flaw has been used to gain unauthorized access and deploy cryptocurrency mining malware. All four vulnerabilities have been added to SISA's known exploited vulnerabilities catalog, with federal agencies directed to apply patches by August 21st. Researchers at Ontenew have uncovered twin loot, a Python-based malware implant that conceals its command and control traffic within legitimate Microsoft 3,000, 365 services. First observed in July of this year, the malware uses SharePoint online to exchange commands and stolen data, Microsoft Teams infrastructure for covert remote access, and the
Starting point is 00:06:55 victim's edge browser to communicate with Microsoft Graph, making malicious activity appear legitimate. The campaign begins with a fake IT support call over Teams, convincing victims to run a malicious power shell command. Twin Lute also displays a counterfeit Windows lock screen to harvest passwords and includes a persistence technique that requires no administrator privileges. Antenou found no confirmed link to a known threat group but advises organizations to closely monitor unusual activity involving Microsoft Graph, SharePoint, Teams, browser automation, and Oath applications.
Starting point is 00:07:37 Maria Vermazis is host of the T-Mindexam. space cyber podcast, and every Wednesday she joins us here with the latest news from the wild blue yonder. She files this report. Thank you, Dave. Last week, Ukraine struck Russia's progress rocket and space center in Samara, which is about 900 kilometers from Ukraine's nearest border. The Samara-based space center is home to a number of Russia's main space programs, including the launch facility for Soyuz rockets that are specifically used to launch Russia's RASVET satellite constellation. Now, it's often called Russia's alternative to Starlink.
Starting point is 00:08:19 Rasvet is Russia's planned proliferated low-earth orbit communications constellation, though there are some big differences between Rass VET and Starlink, because unlike the approximately 12,000 Starlink satellites on orbit at the moment, which have been launched over a period of years at this point, RASFET only began launching earlier this year, and having completed two launches so far, RASFET is estimated to have around 32 operational satellites in its constellation. For comparison, an average Starlink launch can put around 30 satellites into orbit in one go on a Falcon 9 rocket.
Starting point is 00:08:56 So, Ukraine damaging a key facility for both ROSFET production and launch is a noteworthy strategic move in disrupting Russia's space-based communications plans, just as those plans were quite literally getting off the ground. For the CyberWire Daily, I'm Maria Vermazzes from T-minus Space Cyber Briefing. Back to you, Dave. That's Maria Vermazze's host of the T-minus Space Cyber podcast. The U.S. Food and Drug Administration is seeking public input on how to regulate generative AI-enabled medical devices.
Starting point is 00:09:33 releasing a discussion paper that outlines potential clinical risks and regulatory considerations. The agency emphasizes it regulates medical devices, not generative AI software itself, and plans to apply a risk-based approach based on a device's intended use and technical characteristics. The paper raises questions about higher risk functions, such as AI systems that direct treatment decisions or emergency care, compared to those providing general information. Public comments are open through October 19th and will help shape future guidance. Industry experts note that generative AI introduces new challenges,
Starting point is 00:10:15 including hallucinations, model drift, data poisoning, and expanded cybersecurity risks, requiring stronger life cycle management and evaluation than traditional medical software. Researchers from the University of Massachusetts Amherst have demonstrated that some expired visa contactless credit cards can still be used for payments by exploiting a weakness in the EMV contactless protocol. Presented at USNICS Security 2026, the research shows that attackers using NFC proxy devices can alter the expiration date seen by a point-of-sale terminal, because Visa's contactless implementation does not cryptographically bind that field. As a result, some payment terminals and issuing banks may authorize transactions from expired cards,
Starting point is 00:11:11 depending on their validation process. The researchers found that MasterCard, American Express, and Discover resisted the attack under their tested configurations. The team disclosed the issue to Visa last year, but says neither Visa nor affected banks, have confirmed whether the vulnerability has been fully addressed. A former data analyst has been sentenced to two years in federal prison after attempting to extort his employer using stolen company data. Cameron Curry, a contractor at Brightly Software, abused his legitimate access after learning his contract would not be renewed.
Starting point is 00:11:52 Prosecutors said he created the online persona loot and sent more than 60 emails, demanding a $2.5 million cryptocurrency payment, threatening to leak sensitive corporate records and employee personal information. Investigators trace the campaign through email metadata and cryptocurrency accounts linked to Curry's family, leading to his arrest and conviction on six extortion-related charges. The case highlights the persistent risk posed by insider threats and underscores the importance of immediately revoking system access and closely monitoring privileged users
Starting point is 00:12:31 during employee or contractor departures. Coming up after the break, my conversation with Brian Vecchi, field CTO at Veronis. We're discussing how AI may be calling your security bluff. And highway hijinks meet high-tech hardware. Brian Vetchy is field CTO at Veronis. He and I recently got to,
Starting point is 00:13:16 together at Black Hat USA to discuss how AI is calling your security bluff. Well, welcome back to another one of our conversations here at Black Hat USA 2026. I am joined now by Brian Vecchi, who is Field CTO at Veronis. Brian, good to see you again. Good to see you, too. Well, it's been a busy Black Hat. It's been a couple days now as we're recording this. What's your overall sense as you're walking around the show floor and having the meetings
Starting point is 00:13:45 that you're having? So, yeah, I've been back-to-back with customer meetings for the most part. Okay. It's really interesting. You can, I can give you all the platitudes about, of course, everybody wants to talk about security for AI and AI for security. But I think what's actually really interesting is versus three years ago, everybody was talking about AI as the greatest information retrieval tool in the history of mankind, which it was. Okay. Which caused all sorts of data privacy and data security issues that you and I have talked about before.
Starting point is 00:14:12 Yeah. What's interesting now is now we're kind of in the agentic future, right? And everybody has been saying we're in the first inning, second inning, whatever part of the baseball metaphor you want to use. I really think we're in like the second or third inning of this AI revolution. And everybody's really worried about agents now, which are autonomous and non-deterministic and connect multiple systems and leverage multiple types of identities and can make changes. It's not just about getting information or creating things. It's about making changes, which makes them incredibly powerful and incredibly dangerous. Yeah.
Starting point is 00:14:51 Which is incredibly interesting from a security standpoint. It's interesting because just earlier today, I had a conversation with someone about this very thing. And my take was that, you know, maybe a year or two ago, people were kind of looking around at each other and going, are we really going to do this? Right. And now we're past that. It's in the Ruby mirror. like, okay, we're doing this, but I still sense a certain bit of wariness on people's minds as they, you know, okay, we're doing this, but we're all in this together, right?
Starting point is 00:15:23 I've got a stat that'll validate your read on the wariness. So in order for an agent, a single agent to be useful, it's got to be connected to data, right? Says the guy that comes from a data security vendor, but let's bear with me, right? Because if your agents aren't connected to your enterprise data, they are not valuable. They can't do anything useful. They can't leverage the context that your enterprise has, which makes them valuable, right? Only 3% of enterprise data are currently connected to AI systems. So when you say, rightfully so, that you're looking around and everybody's like,
Starting point is 00:16:00 are we really going to do this? Yeah, but the but is borne out by AI systems are only? connected to 3% of enterprise data. That is not going to be the case a year from now, five years from now, 10 years from now, 10 years from now we're going to be talking about enterprises who were able to safely deploy and leverage
Starting point is 00:16:20 AI systems, the ones that are going to get up on stage at a keynote and say we deployed 100,000 agents. They were a massive force multiplier for our workforce. They allowed us to unlock enterprise value in ways unseed since the invention of the assembly line. There are going to be
Starting point is 00:16:37 lots of other businesses that weren't able to keep up. But the ones that are going to do that, that are going to be telling those stories, are the ones that are going to be able to safely connect AI systems. And by systems, I mean models and agents and information retrieval tools and embedded AI, everything that goes into kind of a modern AI workforce to their enterprise data stores.
Starting point is 00:16:59 It's currently at 3%. It's going to dramatically increase, and it's going to be done safely for some, and it's going to be a disaster for us. I want to explore that number, though. I mean, doesn't it matter which 3%? Sure, except, like, I mean, it does, but at the same time, the whole idea of an agent is this is an autonomous system that can work at machine speed that can be a force multiplier for our employees, which means they have to connect to the same systems and data that your employees use, or else they will not be valuable. There's two sides to
Starting point is 00:17:35 this. It's how do you do that safely and make sure that, because, you know, agents are going to, because they're non-deterministic and they're going to single-mindedly, and I try not to be anthropomorphic, but that is kind of, it's how it feels. It's how it feels. Single-mindedly try to accomplish goal. Right. And they're going to do it in ways that are going to be unexpected, but the only way they're going to be truly valuable is that they can act in the same kinds of ways that employees can. And the more barriers you put in place, the more gargails you put in place for an agent or the more, the less information that an agent can access, the less valuable it's going to be. I would argue, if you're going to have an agent, why wouldn't you connect it to your entire enterprise data?
Starting point is 00:18:17 The reason is privacy and security, right? Because you don't want your agent to go rogue. You don't want it to cause a data breach. So that's the push and pull here. It's the old security trope of convenience versus security, right? It's productivity versus security. So where are we headed? in terms of having the tools and capabilities and assurances that we can pull this off? I think it's all about context. So agents are valuable because they have enterprise context. They know what your company is and does and how it works.
Starting point is 00:18:53 And they get that from all the data that they have to access. Security is the same way. So this goes back to the conversation that we've had a couple times now about I've got security for AI. I got to put guardrails in place, but I also need AI for security. I need robots to help me control and manage and protect the robots. It's all about automation, and automation is only as good as the inputs. It's like garbage in, garbage out. I used to tell a joke when I would do a keynote, and it was the easiest joke in security,
Starting point is 00:19:26 especially data security. Easiest joke to tell, always got like a nice sensible chuckle. I can reduce all of your information security risk to zero. I can do it extremely quickly. I can do it without almost any help from you. I will write a PowerShell script that deletes all your data. All of your risk goes to zero. That joke used to get a mild chuckle.
Starting point is 00:19:45 Now it gets a, wow, that's actually probable. Like an agent might do that. There's that scene in Silicon Valley where the AI goes and deletes all the code because it gets rid of all the bugs, right? So it might actually happen now. So if you're going to put automation in place to help with security, that automation needs to have the right telemetry, because telemetry is context. So when it comes to data, and that's what we're talking about here, you need to know what data you have and where it is and what's sensitive.
Starting point is 00:20:14 And that's where a lot of enterprises have stopped. There's this whole category of tools, data security posture management, that really does cloud sensitivity scanning. But discovery by itself isn't security. And I think that is what people have really come to understand in the last, I'm going to say 12 to 18 months, is that if all you do is figure out where all your sensitive data is, you don't have enough context for security. What's additionally important, not really important, is additionally important is the context of, because agents leverage identities, what do these identities actually have access to?
Starting point is 00:20:45 So now you need to understand access control. You also need to understand behavior. A really good example is if an agent touches something sensitive, that should trigger some sort of response. This agent should no longer be allowed to access. the internet, right? If an agent touches sensitive information, don't let it go out to the internet. It gets quarantined. Yeah, it should. But I would argue if an agent, why does an agent have access to something sensitive in the first place? And I had this conversation with one of our customers
Starting point is 00:21:14 a couple of days ago at the beginning of Black Hat. And what she said was, well, we don't know until the agent does something. And I think that's the wrong way to approach this. The really, the really smart organizations, the enterprises that are getting ahead of this, are, the ones that are using automation with the right telemetry, meaning they are feeding in behavior information of all identities, human and non-human identities, all accounts, including all agents. They're feeding in data classification, they're feeding in posture information, configuration information. The ability to identify a vulnerability has collapsed with Methos. It's the easiest thing in the world now, not just CVEs, but to identify posture and other configuration vulnerabilities,
Starting point is 00:21:55 but they're also feeding in access control information, and this is hard. because how someone gets access to a file in Microsoft 365 is a totally different mechanism than how someone gets access to a piece of data in an S3 bucket in an AWS environment is totally different than how someone gets access to a record inside Salesforce. And just because it's hard doesn't mean you can't do it, right?
Starting point is 00:22:18 So the hard work of security is going to be collecting and then using the right telemetry, which gives context to the automation that's going to help secure an identical future, which is a very trite way of saying, collect the right information so you can use it. Brian Vetchi is field CTO at Veronis. Brian, thanks so much for joining us.
Starting point is 00:22:37 Thank you so much. Finally, our legitimate businessman's desk reports cargo thieves appear to have read the memo on AI's booming value and skip straight to the action scenes. According to a story in Wired, investigators say two recent shipments of expensive AI data center equipment
Starting point is 00:23:16 vanished after escort vehicles were deliberately disabled, one by a rear-end collision and another by a pit-style maneuver, leaving millions of dollars in hardware missing. While the incidents remain under investigation, security experts say they reflect a broader shift in cargo theft. Criminals increasingly combined cyber-enabled fraud, stolen trucking identities, and compromised motor carrier registrations with old-fashioned deception and occasionally a little automotive choreography. As AI infrastructure drives demand for high-value servers, chips, and cooling equipment, freight companies are responding with stronger identity checks, GPS tracking, and license plate monitoring. For the industry, moving AI hardware now requires more than logistics. It increasingly
Starting point is 00:24:11 resembles protecting a rolling vault, complete with determined adversaries and ever more creative escape plans. And that's the Cyberwire. For links to all of today's stories, check out our daily briefing at the Cyberwire.com. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to Cyberwire at N2K.com. N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Peltzman.
Starting point is 00:25:06 Our contributing host is Maria Vermazas. Our executive producer is Jennifer Iben. Peter Kilpe is our publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.