CyberWire Daily - More than meets the AI.
Episode Date: July 29, 2026The Senate confirms Jay Clayton to lead ODNI. A new CISA framework highlights critical infrastructure isolation capabilities. OpenAI’s rogue agent breached more than just Hugging Face. The average c...ost of a data breach continues to rise. Indirect prompt injection proves irresistible to cyber criminals. Broadcom patches multiple VMware products. ShinyHunters claims responsibility for Ernst & Young’s recent breach. Our guest is Sean Zadig, CISO at Yahoo, discussing the impact of AI on the defense side. These aren’t the droids you’re looking for. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Sean Zadig, CISO at Yahoo, discussing the impact of AI on the defense side without all the hype in either direction, what is a CISO actually doing about it. Selected Reading Senate Confirms Jay Clayton to Lead U.S. Intelligence Community (The New York Times) China and Iran Are Already Inside US Grids: CISA Demands Tested Isolation Plans (Tech Times) OpenAI's rogue agent compromised a customer at a second tech firm, executive says (Reuters) Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident (Hugging Face) The Average Cost of a Data Breach Rises to $5 Million (Infosecurity Magazine) USSPACECOM Issues Space Warfighting Environment 2040 for Joint Force Space Operations (ExecutiveGov) THE SPACE WARFIGHTING ENVIRONMENT 2040 Framing the Future for the Joint Warfighter (U.S. Space Command) Notes from Underground: Adversarial Prompt Injection (Proofpoint) Critical VM Escape Vulnerability Patched in VMware ESXi (SecurityWeek) ShinyHunters Claims Ernst & Young Hack (SecurityWeek) America bans imported robots due to supply chain and security risks (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
This episode is supported by Black Hat USA.
If you follow the research, you know a lot of it breaks on Black Hat stages.
Hundreds of peer-reviewed briefings, more than 100 hands-on trainings,
and the largest business hall in Black Hat's history.
Six days to learn the skills you'll need tomorrow.
August 1st to the 6th.
Use code Cyberwire for $200 off your briefings pass.
at blackhat.com.
We'll see you in Vegas.
The Senate confirms
Jay Clayton to lead ODNI.
A new Sisa framework highlights
critical infrastructure isolation capabilities.
OpenAI's rogue agent breached more than just
hugging face. The average cost
of a data breach continues to rise.
Indirect prompt injection
proves irresistible to cyber criminals.
Broadcom patches multiple
VMware products.
Shiny Hunters claims responsibility
for Ernst & Young's recent breach.
Our guest is Sean Zadig,
CISO at Yahoo,
discussing the impact of AI on the defensive side.
And these aren't the droids you're looking for.
It's Wednesday, July 29, 2026.
I'm Dave Bittner, and this is your Cyberwire Intel briefing.
Thanks for joining us here today.
It's great as always to have you with us.
Jay Clayton was confirmed by the Senate
in a 51-47 party-line vote to lead the office of the Director of National Intelligence,
replacing acting director Bill Pulte.
Although some Democrats initially viewed Clayton favorably,
support eroded after he declined during his confirmation hearing
to clearly state that Joe Biden won the 2020 election.
Still, many lawmakers preferred Clayton to Pulte,
whose brief tenure featured aggressive staffing cuts,
public boasts about downsizing and concerns over his lack of national security experience.
The Intelligence Office, created after the September 11th attacks to coordinate U.S. spy agencies,
has seen its influence diminish under President Trump, who has relied more heavily on CIA director John Ratcliffe.
Clayton, a former SEC chairman and current U.S. attorney in Manhattan,
is expected to work closely with Ratcliffe, despite lingering concerns about his political independence.
A new joint framework from SISA and cybersecurity agencies in Australia, the UK, and Canada
warns that critical infrastructure operators must build and test isolation capabilities before
cyber attacks occur, not during them. The guidance, called CI Fortify, was prompted by major
intrusion such as China's Volt Typhoon and Salt Typhoon campaigns, which exposed weaknesses in
U.S. infrastructure and telecommunications networks. A key finding is that many OT systems rely on
corporate IT services like Active Directory and DNS, causing isolation plans to fail when networks are
disconnected. C.I. Fortify recommends standalone OT authentication services, predefined isolation points,
physical disconnection where possible, recovery procedures, and regular full-scale testing.
However, the guidance is voluntary, and experts warn many operators lack the funding and resources
to implement it. While the framework establishes a new federal baseline for resilience,
organizations that fail to prepare may face greater regulatory, legal, and insurance scrutiny
after future cyber incidents.
Reuters reports.
that the rogue AI agent developed by OpenAI, which carried out a multi-day hacking campaign against
Hugging Face, also compromised a customer hosted on Modal Labs' platform. According to Modal's
chief technology officer, the attack exploited a customer's publicly accessible, unauthenticated
endpoint, rather than a flaw in Models' infrastructure or security isolation. Hugging Face previously
disclose that the agent first breached a sandbox hosted by a third-party provider
before using it to expand its attack, though it did not identify the provider.
OpenAI confirmed the agent compromised four accounts across four services but did not name them.
The incident suggests the agent's activity extended beyond hugging face.
OpenAI said it has since deactivated, encrypted, and restricted access to the AI model involved,
while declining to comment further on the modal-related compromise.
Hugging Face published a technical analysis of the July intrusion,
detailing how the autonomous AI agent conducted a four-and-a-half-day attack
involving roughly 17,600 actions across thousands of automated decision points.
According to the company, the agent running OpenAI's exploit-jim evaluation benchmark
appeared to target HuggingFace to obtain benchmark solutions rather than complete the tasks legitimately.
The attack unfolded in two stages.
First, the agent escaped its evaluation sandbox, compromised a third-party code sandbox, and used it as a launch pad.
It then exploited two vulnerabilities in HuggingFace's dataset processing pipeline,
gaining code execution and access to internal systems before moving last.
Interally. Investigators reconstructed the attack using recovered logs and the open source
GLM 5.2 model. Hugging Face said the only customer data accessed were five exploit gym challenge
datasets and limited operational metadata with no broader customer assets affected.
IBM's 2026 cost of a data breach report found the global average cost of a data breach
rose 12% over the past year to a record $4.99 million based on incidents affecting 602 organizations worldwide.
Lost business, customer trust, and incident response expenses remain the largest cost drivers.
The report also highlights a shift in ransomware tactics, with 41% of victims reporting attackers
threatened reputational damage or public exposure to increase pressure for payment.
Health care recorded the highest average breach cost at $6.6 million, followed by financial
services, industrial, technology, and entertainment. IBM also found that more than one in four
organizations experienced AI-driven attacks with deep-fake impersonation and AI-enabled malware
among the most common. These attacks added an average of $1 million per breach, prompting 85% of
organizations to plan increased cybersecurity spending, particularly on zero-trust security and improved
data governance.
The U.S. Space Command has released a new strategic framework looking ahead to the year 2040,
envisioning a future where space is more crowded, more contested, and more central to military
operations than ever before.
Maria Vermazas takes a closer look at what the space warfighting environment 2040
report tells us about how military planners see the evolving relationship between space operations
and cybersecurity. Thank you, Dave. There is a new document from U.S. Space Command that's been
just published called the Space Warfighting Environment 2040, and it's a new framework outlining
how U.S. military operations in space might evolve over the next 15 years. This new report highlights
several trends in contested space that have direct cybersecurity implications, including but not
limited to AI-enabled networks that can reroute around disruptions, quantum technologies that
could reshape secure communications, and growing reliance on commercial space services.
Now, a key recommendation in this document is that the military now trained for contested space
environments as the norm instead of merely a possibility.
Space warfighting Environment 2040 writes that warfighters should assume that communications, positioning, timing, and network services will be actively disrupted during future conflicts.
The document also warns that future conflicts will target the entire space-enabled effect chain going from satellites and ground stations to communications links and data networks.
Notably, it identifies cyber intrusion, jamming, spoofing, and information operations,
as key threats, pointing to both Russia's use of cyber and electronic warfare as well as
North Korea's continued emphasis on cyber capabilities.
The document also calls out growing risk from the commercial space supply chain, meaning
that while commercial space infrastructure is becoming increasingly important to military
operations, those same commercially built components and spacecraft are also available
and thereby more easily exploitable to adversaries through those same.
commercial markets. For the CyberWire Daily, I'm Maria Vermazes from T-minus space cyber briefing. Back to you, Dave.
That's Maria Vermazes, host of the T-minus Space Cyber podcast. Be sure to check that out wherever you
get your favorite shows. Researchers from ProofPoint report growing interest among cybercriminals
in indirect prompt injection with underground forums advertising tools that embed hidden prompts into
content processed by AI assistance. Subscription services, starting around $150 per month,
offer generators for emails, PDFs, calendar invites, and webpages designed to manipulate
AI agents rather than human users. Emerging techniques include hidden white-on-white text
in emails and documents, malicious prompts embedded in PDFs, calendar invitations that target
AI-powered email summarization and prompts concealed in website code or image metadata used in
malvertising. While large-scale exploitation has not yet been widely observed, researchers say these
tools show attackers are actively developing AI-focused tradecraft. ProofPoint warns organizations
to prepare for these techniques, as they are likely to become more common as AI-powered
applications and autonomous agents see broader adoption.
Broadcom has released security updates for multiple VMware products, including ESXI, V-Center,
workstation, and fusion, addressing five vulnerabilities, three-rated critical.
The most severe include a VM escape flaw in ESXI's VMX Net3 adapter, an authentication
bypass in V-Center and a remote code execution vulnerability in V-center.
Additional fixes address a high-severity denial of service flaw and a low-severity logging bypass.
Broadcom says there's no evidence of active exploitation, but urges customers to apply patches
promptly due to VMware's history of being targeted by attackers.
The Shiny Hunter's Extortion Group has claimed responsibility for Ernst & Young's
recently disclosed data breach, which exposed sensitive client tax information stored in a third-party
support platform. According to EY, attackers access support tickets between March 28th and April 12th,
obtaining personal and financial data, including social security numbers and payment card information.
The company is offering affected individuals two years of identity protection services,
but has not disclosed the number of victims or confirmed the attacker's
identity. Shiny hunters has threatened to publish the stolen data unless EY responds by July 31st.
Coming up after the break, my conversation with Sean Zadig, CISO at Yahoo. We're discussing the
impact of AI on the defensive side. And these aren't the droids you're looking for. Stay with us.
Sean Zadig is Chief Information Security Officer at Yahoo. We recently got together to discuss the
impact of artificial intelligence on the defensive side of the house. So as the CISO at Yahoo,
I kind of sit between the business and, which is, you know, at Yahoo is serving consumers around
the world with all sorts of tools and things that sort of help make their lives work and our security
team and functions. And I often am playing a role, sort of a dual role. One of those roles is
basically making sure those teams
have what they need and they
are functioning appropriately and they're
resourced appropriately and they've got the strategic
support to be sort of anticipating
what's coming in the future. But the other
part of my role is really going
and speaking really
in depth about
the business that I support and
what new products are coming and what are the
business pressures and increasingly
how can
cybersecurity support
and enable those business
sections to succeed, including things like, well, M&A, how can we help there? And what are the risks
of M&A in certain parts of the world or certain types of businesses? What are the sort of
strategic cyber concerns that play a role and maybe bringing out new products? And how should
we be thinking about cyber, not just in terms of vulnerabilities, but in terms of what the
benefit and risk to a business is? So a lot more business than I thought I would when I first
begin this journey. Yeah, interesting. Well, not only are you CSO at Yahoo, you are also a dad.
And so I'm really interested for your perspective, knowing what you do about security and dealing
with it every day at work, how does that translate to your day of looking out for your kids?
I would say it impacts it pretty significantly. And so, you know, as the CSO, my other role, I don't think
I mentioned yet was, and also the chief paranoid. And the team is called the paranoids. It's kind of
a fun, quirky name, but we like to think that we're paranoid for our users and thinking about all the
sort of threats and the things that we need to be concerned with so they don't have to be. And I think
that also kind of plays itself out in my home life too. And so I have three kids and they're 15 and 12 and
eight. Actually, eight just turned to eight today. And, you know, I think in terms of like technology
and the dangers online and what they should be using, what they shouldn't be using, I think that
constantly making decisions kind of on a daily basis in terms of what's an appropriate
level of risk and what are the making sure that they understand what this, what can sort of
happen in sort of a bad way online. But then also, like, what are the benefits of being online?
And what technologies are they getting exposed to and what will help them in the future as they, you know, become little, from little humans to big humans and, you know, eventually think about careers and their own families.
So it's a lot of micro decisions that kind of add up to trying to raise a good person nowadays.
Yeah, it strikes me that that's a really interesting range of ages that you have, you know, that you have the spectrum between the youngsters, the one.
just coming into their teen years
and then one who's sort of right in the middle of that,
in my house we referred to it as the vortex of chaos
of the hormones and the social pressures
and all those things that all of us went through as teens.
What sort of conversations are you having with your kids
at those different ages?
Yeah, I mean, my son, who's my middle child, who's 12,
he he's the most sort of like technically
adept and interested and also dangerous.
And so for example,
he's got that cybersecurity bug
and he's very interested in
in hacking and in technology
and in not just using it,
but also coming up against the boundaries
and maybe pushing it past what it maybe was designed to do.
And so he's the one I have to kind of, you know,
watch out for.
But, you know, having actually part of my background I didn't really talk about before was I used to be a federal agent for the U.S. government doing cyber crime investigations.
And I actually had seen a lot of situations where, you know, teenagers who didn't have good outlets for their skills would kind of get sucked into a life of crime and would kind of go the wrong way and then fall into under the attention of the authorities like myself.
and I'm really thankful that nowadays
there are so many opportunities for young people
to engage in and satisfy that curiosity
without having to go into these kind of illicit worlds.
So a really good example is bug bounty programs.
Yahoo runs one and
I think we allow kids as young as 16 to participate
depending on the platform.
Others might do it's the same.
and, you know, it's a way for people to sort of learn how to hack, learn what security is and, you know, how to, in some cases, come up against that line and maybe cross it once in a while without, in a safe environment that builds skills for a future career instead of potentially leading to, you know, a criminal record or, you know, ways that might make future career hard.
And so, you know, sort of with my son, I'm like, hey, well, let's talk.
about, okay, you want to explore some of these things. Like, let's expose you to some tools
that give you some context. And so, for example, I said I'm off with Wyrshark and helped him
understand network packets and what good looks like. And so you can help sort of see what bad
looks like and how to recognize that. And then he plays a lot of Minecraft online, which is the
sort of nod I give to online gaming, but I don't, there are certain other platforms that I say you can't
do, including social media, you know, he often, you know, is exposed to people trying to hack him
or fish him. And so there's a lot of opportunities to sort of interject and say, oh, well, that might
be a fishing attack. Why do you think that is? And what is suspicious about that? And sort of like the
stop and think before you click type of mantra. And it's kind of fun that I get to, you know, a lot of
things I deal with at work on a day-to-day basis, play out in some way in the things that he's seen
in Minecraft or in some of these other
forums.
Well, let's talk about just some practical advice then.
For the folks in our audience,
do you have any tips or words of wisdom?
Some of the things that you've put in place or you recommend?
Yeah, I think, I mean, to be honest,
like having visibility,
and that's a core security concept,
is having visibility over your environment.
And whether it's a, you know,
corporation like Yahoo and we want to have network visibility or whether me at home,
I want to have visibility over to what my kids are doing and they are aware that I have that
visibility. And so, for example, the two older kids have phones and they do because they actually
take the metro to school in downtown DC. And so I, but it's a phone that is kind of locked down
and we're an Apple home for those sort of things.
And so they, you know, it's a family plan with the sort of family sharing enabled and location services on and, you know, requiring permission to enable certain features or install certain software.
And, you know, they know it's very, very, very clear that the parent sort of administers the device.
And it's for their, you know, make sure they know it's for their safety.
So I would say, you know, making sure that you have a clear conversation with your children about what, you know, what could happen online, what some of the risks are, and some of the ways that we can mitigate that risk with, you know, protections and being careful who you talk to and things like password hygiene and, you know, a lot of cybersecurity basics, they're really applicable at home.
You have a 15-year-old. Do you get much pushback there? You know, dad.
All the other kids have this, that, and the other thing.
You know, I surprisingly don't.
And I think part of it is because I guess cybersecurity is kind of in the background of a lot of our conversations.
And I work from home.
And so sometimes they might hear me talking about it or as I'm driving them, picking them up from the metro.
And I'd be on a call with people at Yahoo talking about AI or cybersecurity or stuff.
And so I think through osmosis, they're actually absorbing a fair.
amount of the threat landscape. And they, I'm not getting a surprising amount of pushback,
I think. And partly as well as I also know the parents really well and they associate with
on a regular basis, like their best friends. And, you know, they know what I do. And I'm often,
you know, answering questions or providing advice to them around technology. And so the other,
their best friends are kind of well calibrated when it comes to their, their own risk tolerance, I guess.
That's Sean Zedig from Yahoo.
If you're heading to Black Hat USA this year, make plans to visit the SpectorOps Kennel Club.
As creators of Bloodhound, the SpectorOps team will host talks with OpenAI and the UK AI Security Institute,
as well as hands-on workshops aimed at helping you understand AI accelerated attack paths and the latest in identity tradecraft.
Visit Spectorops.io to pre-register.
and learn more. Spector Ops Kennel Club is adjacent to Libertine Social inside Mandalay Bay.
While you're there, visit the N2K Cyberwire podcast studio, where we'll be capturing expert
perspectives and conversations from across Black Hat. And finally, the U.S. is drawing a firm
line around advanced robotics, moving to effectively block future imports of foreign-made robots
on national security grounds.
Federal officials argue that increasingly connected robots could be exploited for espionage,
remote disruption, or supply chain leverage, pointing to vulnerabilities previously disclosed in
Chinese-made unitary robots. New FCC restrictions prohibit sales of most foreign-built advanced robots
while exempting machines manufactured in the U.S. and certain systems approved by the Defense Department.
robots already authorized for sale can continue to be imported and existing owners are unaffected.
The policy signals Washington's broader effort to localize critical technologies.
It also hands a potential advantage to domestic manufacturers like Tesla,
whose long-promised optimist robot may now have less foreign competition,
provided it eventually graduates from keynote appearances to actual production.
And that's the Cyberwire.
For links to all of today's stories, check out our daily briefing at thecyberwire.com.
We'd love to know what you think of this podcast.
Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity.
If you like our show, please share a rating and review in your favorite podcast app.
Please also fill out the survey in the show notes or send an email to Cyberwire at N2K.com.
N2K's lead producer is Liz Stokes.
We're mixed by Trey Hester with original music and sound design by Elliot Peltzman.
Our contributing host is Maria Vermazas.
Our executive producer is Jennifer Ibin.
Peter Kilpy is our publisher.
And I'm Dave Bittner.
Thanks for listening.
We'll see you back here tomorrow.
Heading to Black Hat USA, the N2K's Cyberwire team will be on-site recording from our podcast studio in the SpectorOps Kennel Club.
you're interested in joining us for a conversation or learning more about what we're recording
throughout the week, stop by the studio and meet the N2K Cyberwire team. SpectorOps's
Kennel Club is adjacent to Libertine Social inside Mandalay Bay.
