CyberWire Daily - More than meets the AI.

Episode Date: July 29, 2026

The Senate confirms Jay Clayton to lead ODNI. A new CISA framework highlights critical infrastructure isolation capabilities. OpenAI’s rogue agent breached more than just Hugging Face. The average c...ost of a data breach continues to rise. Indirect prompt injection proves irresistible to cyber criminals. Broadcom patches multiple VMware products. ShinyHunters claims responsibility for Ernst & Young’s recent breach. Our guest is Sean Zadig, CISO at Yahoo, discussing the impact of AI on the defense side. These aren’t the droids you’re looking for. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Sean Zadig, CISO at Yahoo, discussing the impact of AI on the defense side without all the hype in either direction, what is a CISO actually doing about it. Selected Reading Senate Confirms Jay Clayton to Lead U.S. Intelligence Community (The New York Times) China and Iran Are Already Inside US Grids: CISA Demands Tested Isolation Plans (Tech Times) OpenAI's rogue agent compromised a customer at a second tech firm, executive says (Reuters) Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident (Hugging Face) The Average Cost of a Data Breach Rises to $5 Million (Infosecurity Magazine) USSPACECOM Issues Space Warfighting Environment 2040 for Joint Force Space Operations (ExecutiveGov) THE SPACE WARFIGHTING ENVIRONMENT 2040 Framing the Future for the Joint Warfighter (U.S. Space Command)  Notes from Underground: Adversarial Prompt Injection (Proofpoint) Critical VM Escape Vulnerability Patched in VMware ESXi (SecurityWeek) ShinyHunters Claims Ernst & Young Hack (SecurityWeek) America bans imported robots due to supply chain and security risks (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. This episode is supported by Black Hat USA. If you follow the research, you know a lot of it breaks on Black Hat stages. Hundreds of peer-reviewed briefings, more than 100 hands-on trainings, and the largest business hall in Black Hat's history. Six days to learn the skills you'll need tomorrow. August 1st to the 6th. Use code Cyberwire for $200 off your briefings pass.
Starting point is 00:00:36 at blackhat.com. We'll see you in Vegas. The Senate confirms Jay Clayton to lead ODNI. A new Sisa framework highlights critical infrastructure isolation capabilities. OpenAI's rogue agent breached more than just hugging face. The average cost
Starting point is 00:01:08 of a data breach continues to rise. Indirect prompt injection proves irresistible to cyber criminals. Broadcom patches multiple VMware products. Shiny Hunters claims responsibility for Ernst & Young's recent breach. Our guest is Sean Zadig,
Starting point is 00:01:24 CISO at Yahoo, discussing the impact of AI on the defensive side. And these aren't the droids you're looking for. It's Wednesday, July 29, 2026. I'm Dave Bittner, and this is your Cyberwire Intel briefing. Thanks for joining us here today. It's great as always to have you with us. Jay Clayton was confirmed by the Senate
Starting point is 00:02:14 in a 51-47 party-line vote to lead the office of the Director of National Intelligence, replacing acting director Bill Pulte. Although some Democrats initially viewed Clayton favorably, support eroded after he declined during his confirmation hearing to clearly state that Joe Biden won the 2020 election. Still, many lawmakers preferred Clayton to Pulte, whose brief tenure featured aggressive staffing cuts, public boasts about downsizing and concerns over his lack of national security experience.
Starting point is 00:02:50 The Intelligence Office, created after the September 11th attacks to coordinate U.S. spy agencies, has seen its influence diminish under President Trump, who has relied more heavily on CIA director John Ratcliffe. Clayton, a former SEC chairman and current U.S. attorney in Manhattan, is expected to work closely with Ratcliffe, despite lingering concerns about his political independence. A new joint framework from SISA and cybersecurity agencies in Australia, the UK, and Canada warns that critical infrastructure operators must build and test isolation capabilities before cyber attacks occur, not during them. The guidance, called CI Fortify, was prompted by major intrusion such as China's Volt Typhoon and Salt Typhoon campaigns, which exposed weaknesses in
Starting point is 00:03:43 U.S. infrastructure and telecommunications networks. A key finding is that many OT systems rely on corporate IT services like Active Directory and DNS, causing isolation plans to fail when networks are disconnected. C.I. Fortify recommends standalone OT authentication services, predefined isolation points, physical disconnection where possible, recovery procedures, and regular full-scale testing. However, the guidance is voluntary, and experts warn many operators lack the funding and resources to implement it. While the framework establishes a new federal baseline for resilience, organizations that fail to prepare may face greater regulatory, legal, and insurance scrutiny after future cyber incidents.
Starting point is 00:04:35 Reuters reports. that the rogue AI agent developed by OpenAI, which carried out a multi-day hacking campaign against Hugging Face, also compromised a customer hosted on Modal Labs' platform. According to Modal's chief technology officer, the attack exploited a customer's publicly accessible, unauthenticated endpoint, rather than a flaw in Models' infrastructure or security isolation. Hugging Face previously disclose that the agent first breached a sandbox hosted by a third-party provider before using it to expand its attack, though it did not identify the provider. OpenAI confirmed the agent compromised four accounts across four services but did not name them.
Starting point is 00:05:21 The incident suggests the agent's activity extended beyond hugging face. OpenAI said it has since deactivated, encrypted, and restricted access to the AI model involved, while declining to comment further on the modal-related compromise. Hugging Face published a technical analysis of the July intrusion, detailing how the autonomous AI agent conducted a four-and-a-half-day attack involving roughly 17,600 actions across thousands of automated decision points. According to the company, the agent running OpenAI's exploit-jim evaluation benchmark appeared to target HuggingFace to obtain benchmark solutions rather than complete the tasks legitimately.
Starting point is 00:06:10 The attack unfolded in two stages. First, the agent escaped its evaluation sandbox, compromised a third-party code sandbox, and used it as a launch pad. It then exploited two vulnerabilities in HuggingFace's dataset processing pipeline, gaining code execution and access to internal systems before moving last. Interally. Investigators reconstructed the attack using recovered logs and the open source GLM 5.2 model. Hugging Face said the only customer data accessed were five exploit gym challenge datasets and limited operational metadata with no broader customer assets affected. IBM's 2026 cost of a data breach report found the global average cost of a data breach
Starting point is 00:07:00 rose 12% over the past year to a record $4.99 million based on incidents affecting 602 organizations worldwide. Lost business, customer trust, and incident response expenses remain the largest cost drivers. The report also highlights a shift in ransomware tactics, with 41% of victims reporting attackers threatened reputational damage or public exposure to increase pressure for payment. Health care recorded the highest average breach cost at $6.6 million, followed by financial services, industrial, technology, and entertainment. IBM also found that more than one in four organizations experienced AI-driven attacks with deep-fake impersonation and AI-enabled malware among the most common. These attacks added an average of $1 million per breach, prompting 85% of
Starting point is 00:07:58 organizations to plan increased cybersecurity spending, particularly on zero-trust security and improved data governance. The U.S. Space Command has released a new strategic framework looking ahead to the year 2040, envisioning a future where space is more crowded, more contested, and more central to military operations than ever before. Maria Vermazas takes a closer look at what the space warfighting environment 2040 report tells us about how military planners see the evolving relationship between space operations and cybersecurity. Thank you, Dave. There is a new document from U.S. Space Command that's been
Starting point is 00:08:42 just published called the Space Warfighting Environment 2040, and it's a new framework outlining how U.S. military operations in space might evolve over the next 15 years. This new report highlights several trends in contested space that have direct cybersecurity implications, including but not limited to AI-enabled networks that can reroute around disruptions, quantum technologies that could reshape secure communications, and growing reliance on commercial space services. Now, a key recommendation in this document is that the military now trained for contested space environments as the norm instead of merely a possibility. Space warfighting Environment 2040 writes that warfighters should assume that communications, positioning, timing, and network services will be actively disrupted during future conflicts.
Starting point is 00:09:36 The document also warns that future conflicts will target the entire space-enabled effect chain going from satellites and ground stations to communications links and data networks. Notably, it identifies cyber intrusion, jamming, spoofing, and information operations, as key threats, pointing to both Russia's use of cyber and electronic warfare as well as North Korea's continued emphasis on cyber capabilities. The document also calls out growing risk from the commercial space supply chain, meaning that while commercial space infrastructure is becoming increasingly important to military operations, those same commercially built components and spacecraft are also available and thereby more easily exploitable to adversaries through those same.
Starting point is 00:10:22 commercial markets. For the CyberWire Daily, I'm Maria Vermazes from T-minus space cyber briefing. Back to you, Dave. That's Maria Vermazes, host of the T-minus Space Cyber podcast. Be sure to check that out wherever you get your favorite shows. Researchers from ProofPoint report growing interest among cybercriminals in indirect prompt injection with underground forums advertising tools that embed hidden prompts into content processed by AI assistance. Subscription services, starting around $150 per month, offer generators for emails, PDFs, calendar invites, and webpages designed to manipulate AI agents rather than human users. Emerging techniques include hidden white-on-white text in emails and documents, malicious prompts embedded in PDFs, calendar invitations that target
Starting point is 00:11:19 AI-powered email summarization and prompts concealed in website code or image metadata used in malvertising. While large-scale exploitation has not yet been widely observed, researchers say these tools show attackers are actively developing AI-focused tradecraft. ProofPoint warns organizations to prepare for these techniques, as they are likely to become more common as AI-powered applications and autonomous agents see broader adoption. Broadcom has released security updates for multiple VMware products, including ESXI, V-Center, workstation, and fusion, addressing five vulnerabilities, three-rated critical. The most severe include a VM escape flaw in ESXI's VMX Net3 adapter, an authentication
Starting point is 00:12:13 bypass in V-Center and a remote code execution vulnerability in V-center. Additional fixes address a high-severity denial of service flaw and a low-severity logging bypass. Broadcom says there's no evidence of active exploitation, but urges customers to apply patches promptly due to VMware's history of being targeted by attackers. The Shiny Hunter's Extortion Group has claimed responsibility for Ernst & Young's recently disclosed data breach, which exposed sensitive client tax information stored in a third-party support platform. According to EY, attackers access support tickets between March 28th and April 12th, obtaining personal and financial data, including social security numbers and payment card information.
Starting point is 00:13:04 The company is offering affected individuals two years of identity protection services, but has not disclosed the number of victims or confirmed the attacker's identity. Shiny hunters has threatened to publish the stolen data unless EY responds by July 31st. Coming up after the break, my conversation with Sean Zadig, CISO at Yahoo. We're discussing the impact of AI on the defensive side. And these aren't the droids you're looking for. Stay with us. Sean Zadig is Chief Information Security Officer at Yahoo. We recently got together to discuss the impact of artificial intelligence on the defensive side of the house. So as the CISO at Yahoo, I kind of sit between the business and, which is, you know, at Yahoo is serving consumers around
Starting point is 00:14:19 the world with all sorts of tools and things that sort of help make their lives work and our security team and functions. And I often am playing a role, sort of a dual role. One of those roles is basically making sure those teams have what they need and they are functioning appropriately and they're resourced appropriately and they've got the strategic support to be sort of anticipating what's coming in the future. But the other
Starting point is 00:14:43 part of my role is really going and speaking really in depth about the business that I support and what new products are coming and what are the business pressures and increasingly how can cybersecurity support
Starting point is 00:14:58 and enable those business sections to succeed, including things like, well, M&A, how can we help there? And what are the risks of M&A in certain parts of the world or certain types of businesses? What are the sort of strategic cyber concerns that play a role and maybe bringing out new products? And how should we be thinking about cyber, not just in terms of vulnerabilities, but in terms of what the benefit and risk to a business is? So a lot more business than I thought I would when I first begin this journey. Yeah, interesting. Well, not only are you CSO at Yahoo, you are also a dad. And so I'm really interested for your perspective, knowing what you do about security and dealing
Starting point is 00:15:44 with it every day at work, how does that translate to your day of looking out for your kids? I would say it impacts it pretty significantly. And so, you know, as the CSO, my other role, I don't think I mentioned yet was, and also the chief paranoid. And the team is called the paranoids. It's kind of a fun, quirky name, but we like to think that we're paranoid for our users and thinking about all the sort of threats and the things that we need to be concerned with so they don't have to be. And I think that also kind of plays itself out in my home life too. And so I have three kids and they're 15 and 12 and eight. Actually, eight just turned to eight today. And, you know, I think in terms of like technology and the dangers online and what they should be using, what they shouldn't be using, I think that
Starting point is 00:16:37 constantly making decisions kind of on a daily basis in terms of what's an appropriate level of risk and what are the making sure that they understand what this, what can sort of happen in sort of a bad way online. But then also, like, what are the benefits of being online? And what technologies are they getting exposed to and what will help them in the future as they, you know, become little, from little humans to big humans and, you know, eventually think about careers and their own families. So it's a lot of micro decisions that kind of add up to trying to raise a good person nowadays. Yeah, it strikes me that that's a really interesting range of ages that you have, you know, that you have the spectrum between the youngsters, the one. just coming into their teen years and then one who's sort of right in the middle of that,
Starting point is 00:17:29 in my house we referred to it as the vortex of chaos of the hormones and the social pressures and all those things that all of us went through as teens. What sort of conversations are you having with your kids at those different ages? Yeah, I mean, my son, who's my middle child, who's 12, he he's the most sort of like technically adept and interested and also dangerous.
Starting point is 00:17:58 And so for example, he's got that cybersecurity bug and he's very interested in in hacking and in technology and in not just using it, but also coming up against the boundaries and maybe pushing it past what it maybe was designed to do. And so he's the one I have to kind of, you know,
Starting point is 00:18:19 watch out for. But, you know, having actually part of my background I didn't really talk about before was I used to be a federal agent for the U.S. government doing cyber crime investigations. And I actually had seen a lot of situations where, you know, teenagers who didn't have good outlets for their skills would kind of get sucked into a life of crime and would kind of go the wrong way and then fall into under the attention of the authorities like myself. and I'm really thankful that nowadays there are so many opportunities for young people to engage in and satisfy that curiosity without having to go into these kind of illicit worlds. So a really good example is bug bounty programs.
Starting point is 00:19:05 Yahoo runs one and I think we allow kids as young as 16 to participate depending on the platform. Others might do it's the same. and, you know, it's a way for people to sort of learn how to hack, learn what security is and, you know, how to, in some cases, come up against that line and maybe cross it once in a while without, in a safe environment that builds skills for a future career instead of potentially leading to, you know, a criminal record or, you know, ways that might make future career hard. And so, you know, sort of with my son, I'm like, hey, well, let's talk. about, okay, you want to explore some of these things. Like, let's expose you to some tools that give you some context. And so, for example, I said I'm off with Wyrshark and helped him
Starting point is 00:19:57 understand network packets and what good looks like. And so you can help sort of see what bad looks like and how to recognize that. And then he plays a lot of Minecraft online, which is the sort of nod I give to online gaming, but I don't, there are certain other platforms that I say you can't do, including social media, you know, he often, you know, is exposed to people trying to hack him or fish him. And so there's a lot of opportunities to sort of interject and say, oh, well, that might be a fishing attack. Why do you think that is? And what is suspicious about that? And sort of like the stop and think before you click type of mantra. And it's kind of fun that I get to, you know, a lot of things I deal with at work on a day-to-day basis, play out in some way in the things that he's seen
Starting point is 00:20:44 in Minecraft or in some of these other forums. Well, let's talk about just some practical advice then. For the folks in our audience, do you have any tips or words of wisdom? Some of the things that you've put in place or you recommend? Yeah, I think, I mean, to be honest, like having visibility,
Starting point is 00:21:07 and that's a core security concept, is having visibility over your environment. And whether it's a, you know, corporation like Yahoo and we want to have network visibility or whether me at home, I want to have visibility over to what my kids are doing and they are aware that I have that visibility. And so, for example, the two older kids have phones and they do because they actually take the metro to school in downtown DC. And so I, but it's a phone that is kind of locked down and we're an Apple home for those sort of things.
Starting point is 00:21:44 And so they, you know, it's a family plan with the sort of family sharing enabled and location services on and, you know, requiring permission to enable certain features or install certain software. And, you know, they know it's very, very, very clear that the parent sort of administers the device. And it's for their, you know, make sure they know it's for their safety. So I would say, you know, making sure that you have a clear conversation with your children about what, you know, what could happen online, what some of the risks are, and some of the ways that we can mitigate that risk with, you know, protections and being careful who you talk to and things like password hygiene and, you know, a lot of cybersecurity basics, they're really applicable at home. You have a 15-year-old. Do you get much pushback there? You know, dad. All the other kids have this, that, and the other thing. You know, I surprisingly don't. And I think part of it is because I guess cybersecurity is kind of in the background of a lot of our conversations.
Starting point is 00:22:54 And I work from home. And so sometimes they might hear me talking about it or as I'm driving them, picking them up from the metro. And I'd be on a call with people at Yahoo talking about AI or cybersecurity or stuff. And so I think through osmosis, they're actually absorbing a fair. amount of the threat landscape. And they, I'm not getting a surprising amount of pushback, I think. And partly as well as I also know the parents really well and they associate with on a regular basis, like their best friends. And, you know, they know what I do. And I'm often, you know, answering questions or providing advice to them around technology. And so the other,
Starting point is 00:23:33 their best friends are kind of well calibrated when it comes to their, their own risk tolerance, I guess. That's Sean Zedig from Yahoo. If you're heading to Black Hat USA this year, make plans to visit the SpectorOps Kennel Club. As creators of Bloodhound, the SpectorOps team will host talks with OpenAI and the UK AI Security Institute, as well as hands-on workshops aimed at helping you understand AI accelerated attack paths and the latest in identity tradecraft. Visit Spectorops.io to pre-register. and learn more. Spector Ops Kennel Club is adjacent to Libertine Social inside Mandalay Bay. While you're there, visit the N2K Cyberwire podcast studio, where we'll be capturing expert
Starting point is 00:24:35 perspectives and conversations from across Black Hat. And finally, the U.S. is drawing a firm line around advanced robotics, moving to effectively block future imports of foreign-made robots on national security grounds. Federal officials argue that increasingly connected robots could be exploited for espionage, remote disruption, or supply chain leverage, pointing to vulnerabilities previously disclosed in Chinese-made unitary robots. New FCC restrictions prohibit sales of most foreign-built advanced robots while exempting machines manufactured in the U.S. and certain systems approved by the Defense Department. robots already authorized for sale can continue to be imported and existing owners are unaffected.
Starting point is 00:25:37 The policy signals Washington's broader effort to localize critical technologies. It also hands a potential advantage to domestic manufacturers like Tesla, whose long-promised optimist robot may now have less foreign competition, provided it eventually graduates from keynote appearances to actual production. And that's the Cyberwire. For links to all of today's stories, check out our daily briefing at thecyberwire.com. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity.
Starting point is 00:26:28 If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to Cyberwire at N2K.com. N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazas. Our executive producer is Jennifer Ibin. Peter Kilpy is our publisher. And I'm Dave Bittner.
Starting point is 00:26:56 Thanks for listening. We'll see you back here tomorrow. Heading to Black Hat USA, the N2K's Cyberwire team will be on-site recording from our podcast studio in the SpectorOps Kennel Club. you're interested in joining us for a conversation or learning more about what we're recording throughout the week, stop by the studio and meet the N2K Cyberwire team. SpectorOps's Kennel Club is adjacent to Libertine Social inside Mandalay Bay.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.