CyberWire Daily - Laundry Bear gets the spin cycle.

Episode Date: July 24, 2026

Laundry Bear snuffles through unpatched Zimbra Collaboration servers. The State Department puts visa restrictions on cybercriminals. Oracle drops a record 1,449 security patches. Researchers disclose ...a critical vulnerability in OpenAI’s ChatGPT Workspace Agents. A new benchmark evaluates frontier AI model malware reverse engineering. LunchPoke uses the Notepad++ application to establish persistence. A Swiss rail manufacturer refuses to pay the ransom. Dave Bittner sits down with Maria Varmazis, host of T-Minus Space Cyber Briefing, to discuss the show's evolution into CyberWire's weekly space cyber briefing. The AI goes to space.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Dave Bittner sits down with Maria Varmazis, host of T-Minus Space Cyber Briefing, to discuss the show's evolution into CyberWire's weekly space cyber briefing. Maria shares why space cybersecurity deserves more attention, how the new format allows for deeper conversations on topics like GPS security and European space sovereignty, and why every cybersecurity professional should be paying attention to the growing role of space in cyber. You can hear part one here. Selected Reading Russian hackers exploit Zimbra zero-click flaw for email theft (Bleeping Computer) State Department imposes visa restrictions on foreign cyber scammers (The Record) Oracle drops 1,449 security patches like it's the new normal (The Register) OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider (SecurityWeek) Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models (SecurityWeek) Hackers abuse Notepad++ plugins to stealthily install malware (Bleeping Computer) Swiss train maker Stadler refuses Everest $12 million ransomware demand (The Record) If you pay a hacker's ransom, chances are that they'll come back for more (TechCrunch) NASA Puts Google’s Gemma Large Language Model in Orbit (IEEE Spectrum) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. What's the one thing in business that's spreading as fast as AI? AI risk. Every new tool your team signs up for, every vendor that turns on AI features, every new integration, each one is another opportunity for something to go wrong. And most security programs weren't built to keep up with AI's pace of growth. Enter Vanta. Vanta is the number one agentic trust.
Starting point is 00:00:36 platform, trusted by more than 16,000 fast-moving companies like Ramp, Hercer, and Harvey to help them stay audit-ready. And now Vanta helps companies like yours keep an eye on the risks that appear between audits across your vendors, your AI tools, and your entire environment. The Vanta agent works like a 24-7 GRC engineer in the background. It finds issues, drafts, fixes for you, and can cut vendor assessment time by up to 50 percent. Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today at Vanta.com slash cyber. That's V-A-T-A dot com slash cyber.
Starting point is 00:01:27 Laundrie Bear snuffles through unpatched Zimbra collaboration servers. The State Department puts visa restrictions on cybercriminals. Oracle drops a record 1,449 security patches. Researchers disclose a critical vulnerability in OpenAI's chat GPT workspace agents. A new benchmark evaluates frontier AI model malware reverse engineering. Lunchpoke uses the Notepad Plus Plus application to establish persistence. A Swiss rail manufacturer refuses to pay the ransom. And the AI goes to space.
Starting point is 00:02:16 Today is Friday, July 24th, 2026. I'm Maria Varmazes in for Dave Bittner today, and this is your Cyberwire Intel briefing. Happy Friday, everybody, and thank you for joining me. Let's dive into it. First up, SISA is warning that the Russian state-sponsored group Laundry Bear, also known as Void Blizzard, is targeting organizations using unpatched Zimbra collaboration servers. The attackers exploit CVE 2025-66-377. which is a cross-site scripting vulnerability that allows malicious JavaScript embedded in HTML emails to execute automatically when the messages are viewed, enabling theft of emails, credentials,
Starting point is 00:03:25 address books, and two-factor authentication tokens. The campaign also creates Zimber application passcodes to maintain access while bypassing multi-factor authentication. Stolen data is exfiltrated over DNS and HTTPS, and the group also used. uses adversary-in-the-middle fishing sites that impersonate Zimbra login portals. Sysa urges organizations to patch Zimbra, review indicators of compromise, investigate suspicious authentication activity, revoke unauthorized application passcodes, and adopt fishing-resistant multi-factor authentication where possible.
Starting point is 00:04:03 The State Department has announced new visa restrictions targeting individuals involved in foreign cybercrime networks, along with their immediate family members. Secretary of State Marco Rubio unveiled the policy during a visit to Southeast Asia, where industrial-scale scam centers have become a major regional concern. The restrictions apply to people responsible for or complicit in cyber-enabled crimes, including online scams and sextortion scams, and build on President Trump's executive order aimed at combating cybercrime and fraud. Rubio said that many of these operations are tied to Chinese transnational criminal groups
Starting point is 00:04:42 engaged in human trafficking, money laundering, and financial scams that cost Americans an estimated $10 billion in 2024. The administration says the new policy is intended to deter cybercriminals by limiting their ability to travel to the United States. Oracle has released a record 1,449 security patches as part of its quarterly critical patch update, reflecting both the company's extensive product portfolio and its increased use of artificial intelligence for vulnerability discovery. Security experts say that the volume is less an indication of poor code quality than a growing trend toward AI-assisted bug hunting, which is also driving larger patch releases across the industry. Oracle recently introduced
Starting point is 00:05:30 monthly critical security patch updates to deliver fixes for the most urgent vulnerabilities between its quarterly releases. Among the highest priority flaws are several critical vulnerabilities affecting Oracle Fusion Millware and Oracle Database Server, including bugs that could allow unauthenticated system compromise or remote code execution. Experts urge organizations to prioritize patching and use automated patch management tools where possible. Security researchers at Zenity Labs disclosed a now-patched critical vulnerability in OpenAI's chat GBT workspace agents, dubbed agent forger, that could have allowed attackers to create and remotely control invisible AI agents inside an organization's chat GBT workspace.
Starting point is 00:06:17 The attack relied on phishing a logged-in user into clicking a specially crafted URL that abused the agent builder's initialization process to automatically create an autonomous agent with attacker-defined instructions. If the victim already had authorized connectors, such as Gmail or Outlook, the agent could execute commands delivered by email, access sensitive data, impersonate users, and perform other actions without additional authorization prompts. Zenity reported the issue to OpenAI,
Starting point is 00:06:48 which acknowledged the vulnerability and deployed a fix within three days, preventing further exploitation of this flaw. Sentinel One has introduced a new benchmark to evaluate how well Frontier AI models handle long-term malware, reverse engineering, using its investigation of the fast 16 malware as a real-world test case. Rather than measuring isolated tasks, the benchmark assesses whether models can adapt as new evidence overturns earlier conclusions. Among the models tested, GPT 5.6 Sol was the only one to successfully complete all eight investigation stages. Researchers found that while other models
Starting point is 00:07:30 demonstrated strong technical analysis, they struggled to recover from incorrect assumptions. Sentinel 1 concluded that human reverse engineers remain essential, as even the best-performing model made significant errors and still required expert oversight. Score another one for the humans. Ukraine's CERT has identified a campaign by the UAC-0099 threat group that uses the legitimate Notepad Plus Plus application alongside a malicious plugin called LunchPoke to establish persistence on compromised systems. The attack begins with a fishing-delivered VBS script that downloads an archive containing
Starting point is 00:08:11 Notepad++, a malicious DLL disguised as a plugin, and additional malware components. When Notepad Plus Plus launches, it loads the malicious plugin, which creates scheduled tasks, extracts additional payloads and deploys the Bernie Bear. and match-boil version 2 malware loaders. CERT UA attributes the activity to UAC 0099, which is a group previously linked to providing initial access for sandworm operations. Administrators are advised to update Notep-PAD plus-plus, WynR, and 7ZIP to current versions
Starting point is 00:08:48 and monitor for suspicious scheduled tasks and malicious plug-in activity. Swiss Rail manufacturer Stadler Rail says it will not pay. a 10 million Swiss franc, or about 12.3 million U.S. dollars, ransom, after the Everest Ransomware group stole technical documents from a supplier's file-sharing platform. The company said that the breach resulted from compromised supplier credentials and did not affect Stadler's own systems, operations, or customer data. Production remains unaffected, and there has been no impact on trains in service. Stadler has filed a criminal complaint and says it will not negotiate with the attackers. This marks the company's second public extortion attempt in recent years
Starting point is 00:09:33 following a similar incident in 2020. Security experts note that paying ransoms often fails to end extortion, with many organizations later facing additional demands from the same attackers. In fact, a new proof point survey of 953 organizations found that more than one-third of companies that paid a ransomware demand were later targeted with a second extortion. attempt. The findings reinforce long-standing guidance from governments and cybersecurity experts that paying a ransom does not guarantee stolen data will be deleted or that the attacks will end. Researchers say that ransomware groups increasingly rely on repeated extortion, often retaining stolen data even after payment. Recent incidents, including breaches at Clue and change health care,
Starting point is 00:10:22 illustrate how victims can remain vulnerable despite paying, and that all underscores the risks of negotiating with cybercriminals. After the break, we're doing one of my favorite things and bending the space time continuum, just a little bit. And before Dave Bittner left for the day, he turned to the tables and interviewed me about why space cybersecurity deserves more attention. I'm a little biased, but it's a good conversation. So yeah.
Starting point is 00:10:58 And the AI goes to space. Stay with us. Now, normally, everybody, this is where host Dave Bittner would introduce his interview for the day. But since I'm filling in for him today, well, I'll just introduce myself. It's me, Maria Vermazas. And before Dave Bittner left, he sat down with me to talk about why space cybersecurity deserves more attention. Here's our conversation. All right, well, Dave, it's great to speak to you today.
Starting point is 00:11:38 Thanks for coming back on. Yeah, that's great. show. On my way out the door today, we were able to squeeze in one last conversation here, so I appreciate you taking the time, as I had to be away for the main part of the show today. But I want to take today and just sort of get an update from you of some of the goings-on with the T-minus podcast, which has really evolved over the past several months into a whole new thing. And it's pretty exciting. What would you got going on over there, Maria? Well, Dave, we relaunched T-minus, what, in mid-May?
Starting point is 00:12:15 I want to say May 17th, if I'm being really pedantic. And we went from a daily space news show and evolved into a space cyber briefing that's now weekly. And so in my mind, we've sort of camera-wise, tightened the focus, really, really gone laser-focused with the show. And when we first made this change, I was wondering, are we going to have a lot to talk about, are we going to get people who are interested in the show,
Starting point is 00:12:41 And I'm so relieved and thrilled that it's been far more successful and then my wildest dreams could have predicted, which has been just awesome. Like the feedback's been great. We've been getting so many awesome guests, and the conversations have been really fascinating. I've been learning a ton. And yes, there is more than enough going on in this niche of space cyber
Starting point is 00:13:01 that, yes, we have plenty to talk about every week, which has been really thrilling. So, yeah, I'm here kind of one, whew! Yeah. Give us some of the backstory, though. What prompted the shift to focusing on the cyber side of space? Well, it had been a good three years of covering the show, of covering the space industry as a daily show. And there was an element going on throughout a lot of my conversations
Starting point is 00:13:26 that I was noticing that the space cyber world was quickly evolving to meet the moment that it was in, but it still felt like it was a very baby little space. There were a lot of major players in it, but it wasn't being talked about as much as I was. would have expected giving the importance of what's going on there. You've got the confluence of space is not technically considered critical infrastructure, but it sort of is anyway. We are increasingly interdependent on space-based systems. We've seen space-based systems becoming disabled through
Starting point is 00:13:59 cyber attacks in the geopolitical sphere, in like the war in Ukraine, for example. It's very important. And the importance of space cyber is only getting more and more great. And I'm hearing it all the time from not just people that I interview, but just around the world. And again, in the geopolitical sphere, in the military sphere, in the commercial sphere. So the drumbeat was getting louder for the last few years. And in my conversations with people who are in that world, I think the question for me was coming up more and more again,
Starting point is 00:14:28 why aren't people talking about this more? It's so important. And then the answer eventually came, well, we should talk about it more. There you go. If nobody's talking about it, we should do that. Yeah, it's like I'll make my own podcast, with Blackjack, and, you know, that's the future I'm a quote. I'll just be a bridge.
Starting point is 00:14:44 But, yeah, we just figured we're going to do it. And so we're doing it. And it's been awesome. Well, tell me about it. What is the format of the show? The format of the show is a weekly sort of news magazine. We are every Sunday. So we're the Cyberwire Sunday show.
Starting point is 00:15:02 And that's where we take about a half an hour and focus on a space cyber topic, whether it is an interview with an expert guest or I'm having a conversation with my producer, Ethan Cook, and we're chit-chatting about more evergreen topic in the space cyber realm. One of our earlier episodes was about why GPS is so important to the global economy and why attacks against GPS are frankly really catastrophic. This is something that has been known in the military world for decades. But I think the importance of GPS, for example,
Starting point is 00:15:37 has been widely underappreciated in the broader world in terms of its importance outside of mere navigation. And we really just went into the weeds with this, and that's what I really enjoy about it, is that we can get real deep into the weeds on these real nerdy space cyber conversations in a way that we couldn't do before. And it's been a journey of discovery,
Starting point is 00:16:00 but I've been really enjoying it. And our latest conversation that Ethan and I have been doing with our second part coming out this Sunday actually is on European space sovereignty, which has been very politics wonky and it's just been really interesting. What's been the shift like for you switching from the cadence of a daily to a weekly? I mean, you know what it's like to run a daily show, Dave. That is a real intense schedule. It's a marathon, not a sprint. Truly, truly it is. So the pace has slowed down for me, but it's been a lot more deliberate.
Starting point is 00:16:41 We're able to be a lot more careful and choosy about the kind of topics that we're going to cover. We're not just trying to follow, and not that this is a bad thing, we're not just following the news, but we're going, what's really interesting to me, what's really interesting to us right now, and how can we go really deep on that? So, for example, the space sovereignty discussion that we've been having the last two weeks, we touch on my trip to NATO in the NATO cyber headquarters in December that I did, which is not something I think we would normally bring up on, you know, the daily show. And the whole reason that we're talking about it is I had been noticing in some of the news stories that I'd been reading that a lot has been coming up about the EU space law and EU Space Act and a lot of legislation in the EU specifically.
Starting point is 00:17:31 and I just got really curious about it and I wanted to know more about it and I said, Ethan, why don't you and I just kind of go real deep on the research for this? Spend some time, I think we spend like a solid month just pouring over a lot of this and that helped brief our discussion and it ended up being like hours
Starting point is 00:17:50 that we ended up having to trim down into a two episode two-parter but it's a different animal going from a daily show where you know, we're trying to get things out the door and be timely to a weekly magazine approach where we're trying to go really deep on a subject. And that's been quite a shift for me personally. But it's different and I enjoy it. Yeah. Well, good for you. I mean, it is absolutely good stuff. It just strikes me that there's a ton of crossover between cyber nerds and space nerds, right?
Starting point is 00:18:20 Oh, yeah. That chart overlaps. So. Yeah, the Venn diagram is practically a circle. Right. Right. And there are a lot of cyber folks who, are just interested in space just as a curiosity and that's great and I think that's a lot of people who listen to the show and there's an increasing cohort of cyber professionals who want to be in the space industry for a
Starting point is 00:18:42 career. It's been really interesting hearing from those folks and admittedly that is definitely a niche of a niche but I think the thing that if there's one thing people will get out of this show who are just plain old cyber folks space is coming for you. Space is coming in your job
Starting point is 00:18:58 whether or not you're going to be in this space world, space is coming to you. Space systems are coming to the world of networking if they're not already in it. So it's something that is going to be part of your realm, even if it's not going to be your specialization. It's going to be in the goo of what you do. So it's something worth maybe having on the back burner as some knowledge for you to have. And that's sort of, that's maybe not a very compelling pitch, but that's the pitch I give people. Well, I think also, you know if you're if you're a cyberwire daily listener uh i can see how taking on another daily when when t minus was a daily might be a bit much but now that it's a weekly it's a lot easier to
Starting point is 00:19:38 fit into your listening schedule yeah we're our we're your sunday show so uh you don't have to listen to us on sunday but you know we're on your sunday rotation and uh we try not to overwhelm and we go real deep on a topic per episode so it's not lots of things it's one thing uh and feel free to pick and choose which episodes are interesting to you. They're not always going to be if you listen to it this week, but miss it next week. It won't make sense. They tend to be more timeless. So I hope that helps with the digestibility. Because the funny thing about space is that even though it is such a cutting edge field, it actually moves kind of slow. Which is funny. The cyber world moves a lot more quickly, relatively speaking. So you can slow down a little bit with space stuff.
Starting point is 00:20:25 and learn about the landscape there, and you can catch up and you won't be behind. All right. Well, thank you for having me here to discuss this. Thank you for having me be a guest on my own show. Well, thanks for taking the time before you head out to chat with me about what I've been up to. I appreciate it, Dave. All right.
Starting point is 00:20:47 We'll see you soon. See you soon. If you enjoyed that conversation that Dave and I just had, and if you want to hear part one of the space sovereignty conversation on T-minus at aired last week, just check out today's show notes for more links. AI is making fishing attacks faster, more convincing, and harder for people to spot, and traditional security awareness and fishing training weren't designed for this level of attack. Hawkshunt helped security teams prepare employees for the attacks they face every day
Starting point is 00:21:30 with personalized fishing training that adapts to each employee, and reduces risky behavior over time. For IT and security leaders looking to strengthen their human layer of defense, without adding more manual work, visit hoxhunt.com slash cyberwire to learn more. That's H-O-X-H-U-N-T dot com slash cyberwire. And finally today, NASA's Jet Propulsion Laboratory has demonstrated that artificial intelligence doesn't need a warehouse full of GPUs to earn its place in orbit. researchers successfully ran Google's lightweight Gemma 3 language model
Starting point is 00:22:17 aboard loft orbital's Yam 9 satellite, where it analyzed images captured in space and answered natural language questions about what it saw. The Navi orbital system lets scientists guide image analysis with simple prompts instead of complex spacecraft commands, which is a shift that could make satellites far easier to operate. That'd be nice. And beyond convenience, onboard AI could overcome bandwidth limitations,
Starting point is 00:22:42 by sending concise text summaries instead of massive gigs of image files, speeding applications like wildfire detection. But for now, the model is safely isolated from flight control, so no chatbot is flying the spacecraft just yet. Still, this demonstration does suggest that future satellites and perhaps maybe even astronauts could someday have an AI companion that's just ready to help rather than simply admiring the view. And that is The Cyberwire. For links to all of today's stories, check out our daily briefing at thecyberwire.com. This week on Research Saturday, Dave Bittner sits down with Andre Kovovic,
Starting point is 00:23:32 security awareness specialist from ESET, as they discussed their research on frosty neighbor, fresh mischief and digital shenanigans. That's Research Saturday. Check it out. That's the Cyberwire Daily brought to you by N2K Cyberwire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your podcast app. Please also fill up a survey in the show notes or send an email to Cyberwire at N2K.com.
Starting point is 00:24:06 N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our executive producer is Jennifer Ibin. Peter Kilpe is our publisher, and I'm Maria Vermazes in for host Dave Vittner today. Thanks for listening and have a wonderful weekend. Heading to Black Hat USA, the N2K's Cyberwire team will be on-site recording from our podcast studio in the SpectorOps Kennel Club. If you're interested in joining us for a conversation or learning more about what we're recording throughout the week, stop by the studio and meet the N2K Cyberwire team.
Starting point is 00:25:08 SpectorOps's Kennel Club is a job. to libertine social inside Mandalay Bay.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.