CyberWire Daily - Now with extra vulnerabilities.

Episode Date: August 10, 2026

Researchers find that only a quarter of AI-generated patches are fully successful. Ransomware attacks exploit critical N-able flaw. Atlassian fixes critical flaw in Rovo AI. LexisNexis disables some s...ervices following suspicious activity. US Senate confirms Adam Cassady as cyber ambassador. Meta ordered to pay an additional $567 million in child safety case. Water sector cyberattacks expand to new states. We got your Monday Business Briefing. On our Industry Voices, Dave Bittner sits down with Mujtaba Hamid, EVP, Product and Strategy at Booz Allen Hamilton at Black Hat discussing AI Speed Cyber Defense. And scammers set sail on The Odyssey. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices, Dave Bittner sat down with Mujtaba Hamid, EVP, Product and Strategy at Booz Allen Hamilton at Black Hat USA, discussing AI Speed Cyber Defense. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading More than half of AI-generated patches are broken (CyberScoop) China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns (The Record) Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data (SecurityWeek) LexisNexis shuts down services after suspicious activity on servers (BleepingComputer) US cyber ambassador nominee Cassady confirmed in Senate (The Record) Meta Ordered to Pay $567 Million in New Mexico Child Safety Case (New York Times) New Jersey, Alabama Join States Targeted in Water Cyberattacks (Securityweek) Business Breakdown (N2K) ‘Watch The Odyssey for free online’: scam targets film fans with fake streaming sites (The Guardian) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. Maybe that's an urgent email from your CEO, or maybe it's a deep fake targeting your business. Dopple is the AI-native social engineering defense platform fighting back against impersonation and manipulation. As attackers use AI to make their tactics more sophisticated, Dopple uses it to fight back, automatically dismantling cross-channel attacks, building team resilience and providing agentic email protection. Dopple, outpacing what's next in social engineering. Learn more at doppel.com.
Starting point is 00:00:47 That's dopppeel.com. Researchers find that only a quarter of AI-generated patches are fully successful. Ransomware attacks exploit critical enable flaw. Atlassian fixes critical flaw in Robo AI. LexisNexis disables some services following suspicious activity. U.S. Senate confirms Adam Cassidy as cyber ambassador. Mehta ordered to pay an additional $567 million in child safety case. Water sector cyber attacks expand to new U.S. states.
Starting point is 00:01:36 We've got your Monday business briefing. And on our industry voices, Dave Bittner sits down with Mujahabha Hamid, EVP of Product and Strategy at Booz Allen Hamilton, at Black Hat, discussing AI Speed Cyber Defense. and scammers set sail on The Odyssey. Today is Monday, August 10th, 2026. I'm Maria Varmazes in for Dave Bittner this week, and this is your Cyberwire Intel briefing. Thank you for joining me today. Let's get started.
Starting point is 00:02:24 Researchers at OnePassword found that AI-generated security patches are still largely unreliable. When ChatGPT 5.5 and Claude Opus 4.8 were tested against six recently disclosed vulnerabilities, generating over 6,000 patches, only 26% of the patches fully fixed the vulnerability without introducing new problems or altering application behavior. More than half the time, the AI did not fix the flaw or introduced new vulnerabilities in the process. The researchers conclude that human expertise still plays an essential role in the process of fully resolving vulnerabilities and software without introducing unwanted side effects.
Starting point is 00:03:05 Microsoft has warned that a China-based cybercriminal gang is launching ransomware attacks by exploiting a critical vulnerability in Enables and Central software, which is a widely used remote monitoring and management tool. After exploiting the flaw to gain administrative access, the hackers deploy a new ransomware strain called Storm Encryptor. Enable released emergency patches earlier this month after the flaw was observed being exploited in zero-day attacks. The company then issued a second emergency.
Starting point is 00:03:35 emergency hot fix on August 6th, after attackers bypassed the first patch. A critical vulnerability in Atlassian's Rovo AI, dubbed Rovoblast, allowed attackers to use a specifically crafted link to inject malicious instructions into a victim's Rovo session without requiring a jailbreak or permission bypass. Because Rovo can access enterprise systems such as Gira, Confluence, SharePoint, Slack, and Microsoft 365, the flaw could have been used to retrieve and exfiltrate sensitive corporate data with a single click. Atlassian fixed the issue following a responsible disclosure by researchers at Veronis. Data Analytics company Lexis has taken its diligence,
Starting point is 00:04:19 Metabase API and Newsdesk services offline after detecting suspicious activity on servers managed by a third-party vendor. The company is investigating the issue and rebuilding the affected systems in a new environment before restoring service. The company has not said whether customer data was compromised. Todd Larson, who is the president of the Global Nexus Solutions Division of LexusNexis, said in a statement, our investigation is ongoing and we are working with a preeminent cybersecurity forensic firm on review and remediation. The U.S. Senate has confirmed Adam Cassidy as chief of the State Department's Bureau of Cyberspace and Digital Policy,
Starting point is 00:05:00 making him the second person to hold this position. The post had been vacant since Nathaniel Fick departed in January 2025. Cassidy, a senior official at the National Telecommunications and Information Administration, was confirmed in a 51-47 vote. The record notes that it is unclear how much influence the position still holds following a major State Department reorganization last year. A New Mexico court has ordered META to pay $567 million and make major changes to Facebook and Instagram to better protect children, bringing the company's
Starting point is 00:05:37 total liability in the case to $942 million. The ruling requires stronger age verification, limits on minors platform use, tighter controls on AI chatbot interactions, and measures to address child abuse and mental health harms. Meta plans to appeal the ruling, a company spokesperson stated, we remain confident in our record of protecting teens online and will continue to defend ourselves against claims that misrepresent the facts. As a follow-up to a story that we have been covering, New Jersey and Alabama have joined the growing list of states whose water and wastewater facilities were targeted in a cyberattack campaign linked to Iranian hackers. The campaign, which began in late July, has reportedly affected at least
Starting point is 00:06:24 12 states. New Jersey's Cape May and Woodbine water systems were targeted on July 27th, disrupting phone systems, but not water service. The same day, hackers targeted industrial control systems at Alabama's Childersburg water sewer and gas system, but water services were not disrupted. So far, affected utilities have reported limited impact, and officials continue to say that drinking water is safe. The attacks have targeted ICS devices made by Rockwell automation and may involve equipment from other major vendors. The FBI confirmed at least seven states have been targeted as of July 30th, but has not publicly provided further updates. And now it's time for our Monday business briefing. Last week's business breakdown highlights
Starting point is 00:07:11 just over a staggering $1 billion raised across 17 investments and one acquisition. For investments, Horizon 3 raised $250 million in a series E round led by night. Dragon and NEA. The U.S.-based autonomous pen testing company is now valued at $2 billion. Horizon 3 plans to use the funding to scale its GTM operations, accelerate its product roadmap, and support its entry into both Singapore and Australia. Additionally, Spur, the U.S.-based IP intelligence provider, raised $200 million from Insight partners. With the funding, the company is looking to expand investment across product development, intelligence coverage, integrations, and enterprise operations. lines. In acquisitions, Octa, the U.S.-based IAM company, acquired Permiso Security. By acquiring
Starting point is 00:08:02 the identity security platform, Octa is looking to expand its footprint beyond identity management and add core SOC capabilities through Permiso's P0 Labs. And that wraps up this week's business breakdown. For deeper analysis on major business moves shaping the cybersecurity landscape, make sure to subscribe to N2K Pro and check out thecyberwire.com. every Wednesday for the latest updates. Stick with us now. After the break, Dave Bittner sits down with Mujdaba Hamid, EVP of Product and Strategy at Booz Allen Hamilton, at Black Hat USA to discuss AI speed cyber defense. And scammer set sail on The Odyssey.
Starting point is 00:09:03 AI is making fishing attacks faster, more convincing, and harder for people to spot. And traditional security awareness and fishing training, weren't designed for this level of attack. Hoxhunt helps security teams prepare employees for the attacks they face every day, with personalized fishing training that adapts to each employee and reduces risky behavior over time. For IT and security leaders looking to strengthen their human layer of defense, without adding more manual work, visit hoxhunt.com slash cyberwire to learn more. That's H-O-X-H-U-N-T dot com slash.
Starting point is 00:09:42 Cyberwire. Recently at Black Hat USA, Dave Bittner sat down with Mujtapa Hamid, EVP of Product and Strategy at Booz Allen Hamilton, as they discussed AI Speed Cyber Defense. Here's their conversation. We talked about agentic for cybersecurity. The best innovation ideas and product ideas will also be the ones that are agent-native and grow out and scale very fast,
Starting point is 00:10:17 which means especially if you're a technology company, or your leveraging technology for your work, you will be having a lot of genetic IP that you have to develop, roll out, and scale very quickly. Well, welcome back. We are here at Black Hat 2026, and I am pleased to be joined by Mushitaabha Hamid,
Starting point is 00:10:43 who is Executive Vice President for Product and Strategy at Booz Allen Hamilton. Welcome, and thank you for joining us. Good to be here. Thanks, Dave. So we want to talk about AI today. And before we dig into some of the specifics, I would love to get your take on kind of the state of things.
Starting point is 00:11:03 Like where do we find ourselves in this moment when it comes to security professionals and enterprise folks in general in dealing with this wave of AI? Yeah. Well, I'm surprised you're starting by AI. But yeah, I think, you know, every so often, there's a new tech wave, and the tech stack gets either evolved or reshaped.
Starting point is 00:11:29 And we've been through a few of those, depending on how old you are. You know the 95 wave, and then the wave when the mobile phones, the smartphones came, and then the cloud wave. And I think we're at this, a new wave, but this wave seems to be different because it's not just that a new layer is getting added.
Starting point is 00:11:51 but potentially the whole stack will get redrawn as well. I mean, I can imagine these LLMs and that infrastructure and now we're starting to see open weight models come to life. So a new infrastructure layer is getting set up on which not just software gets built, but then applications and the whole stack gets rebuilt on that. With that, then you need a new middleware type of layer as well, which we're also starting to see, you know, be it harnesses or a genetic governance, or policy controls,
Starting point is 00:12:24 and then the apps on top. So I think this wave is a culmination of several things, but yeah, I think the stack is getting redone. But every time the stack gets redone, the prior waves are still there. You know, we still have mainframes running ATM software. And so all of those. So for cybersecurity professionals,
Starting point is 00:12:47 the complexity just expands and compounds. And I think that's what we are going through right now. So you're barely trying to keep up with what you had to worry about and suddenly a whole new redrawing of the tech stack with ginormous amounts of code getting written, vulnerabilities getting found. And so to call it, I think it's overwhelming for the industry, for the Sissos, for everyone involved.
Starting point is 00:13:16 How much do you think that this is a marriage of velocity that everything is, it seems to me, is coming so much more quickly at all the people who are trying to adjust to all of this. Yeah, and that's also another thing that to me, I don't think it's new. As technology develops every wave of technology, the velocity increases.
Starting point is 00:13:42 And here, yeah, the velocity is maybe even exponentially faster than the prior waves. and we see that in the adoption. And just in my personal experience and probably yours and others, the changes we used to see in a year or two years in terms of new tools or resources coming,
Starting point is 00:14:06 now we're seeing that in a matter of months. I grew up in a semiconductor industry when the Moore's law was fully active and we'd be very proud that every 18 months you could double the computing power. Well, the elements, and this whole wave is going much fast. than Woolrowl right now.
Starting point is 00:14:22 And how do you see the adversaries taking advantage of that? What are some of the specific things you're tracking? The things that we track as Booz Allen, given the sensitive clients that we work with, but there's a lot that we're, all of us are seeing. You know, the news coming out, the hugging face news that came out,
Starting point is 00:14:44 the wave before that when, you know, the mythos news was released. Now, you know, super patched Tuesday, with hundreds and hundreds of vulnerabilities being found. So we're all seeing and living through the impact with the pace and velocity and depth of changes. And as with all, technology, technology can be used for good or evil. And the adversaries are as smart if not smarter
Starting point is 00:15:12 and they have a lot of strong tools better than they've ever had at their disposal. and we're seeing the effects of that, honestly. And so to me, as a product manager and going through this case, we have to be in that line between hope and fear, right? Like, too much hope and too much fear, like both of them,
Starting point is 00:15:38 so you have to be in that, okay, what do you do about it? Right? Like, how do you use the tools at your disposal in a way that you can remain a tech optimist and you're out there at the front lines and you're helping the companies protect their mission systems, their crown jewels,
Starting point is 00:15:57 their operational readiness, so they can keep doing what they're doing. You alluded to the scale of an organization like Booz Allen, and I think that extends to the types of customers that you tend to work with. How do you reconcile this velocity issue, with large organizations
Starting point is 00:16:19 that have to deal with things like regulations. There's that old saying, you can't just turn a battleship on a dime. How do you align those things? There's no magic trick here. And so the position we have given who we work with in the scale, complexity, and the unique threats
Starting point is 00:16:41 and regulations that our set of customers have to work with is, one, you have to be really good at thinking in systems and being systematic and seeing patterns at scale. Second, really understanding the customer environment deeply,
Starting point is 00:17:02 be it to deploy zero trusted or to kind of do penetration testing or to kind of come up with a cyber defense. But really that stems from a deep knowledge of the environment itself. And then go execute at pace. So what we see from Booz Allen is,
Starting point is 00:17:24 yeah, we bring a lot of the commercial technology into bear as well. You have to be focused on the mission grounding, then environment knowledge, and then thinking like large-scale systems and applying that. And what are the strategies that you and your colleagues think are going to be most successful here? Are we talking about fighting AI with AI? Well, I'd be one of 500 people here talking about fighting AI with AI.
Starting point is 00:17:54 That's true. You probably have heard that a few times. Once or twice, yeah. But I think we can all say fight AI with AI. But what do we mean when we say that, right? Are you applying AI at the fringes? Are you looking at AI at the workflow level? or are you looking at AI fundamentally reimagining
Starting point is 00:18:19 how the value is provided to the customer? So, for example, given the scale sophistication and what the adversity is doing, what I believe is we need to kind of have be fighting AI with AI at all levels, right? Here, what we have from a product standpoint is the advantage of coming in with fresh ideas. And so we fundamentally are going AI native.
Starting point is 00:18:50 So we look at AI at the ground up at the core of our technology solution to fight this threat instead of if we were an incumbent or established, we would be looking at, okay, how do I start to kind of bring in AI from the fringes of my product down? But we're actually like reimagining it
Starting point is 00:19:12 from the inside out. And I believe that both approaches are needed, but our approach is also needed in order to scale at the velocity that we need right now. Help me understand that. Does that mean that the products at their core are AI-focused as opposed to having AI grafted on after the fact? Yeah, so the core of our products,
Starting point is 00:19:38 that essentially agent-egent-egetic products, So with an orchestrator, with a swarm of agents, and an agentic framework underneath, so we can be ensuring that all the agents in our product are resilient, we have immutable logs of what those agents are doing, we can move towards compliance for our agents. But essentially, we're an agentic swarm set up product portfolio. So everything starts from there,
Starting point is 00:20:10 which then gives us the ability to scale, branch off very quickly as well. So if there's an adjacent idea that comes in or a gap, we see, a lot of times it could just be a refactoring of that agent swarm, or you add a few more agents into that swarm, task them differently, and you have a full governance on it. So that's what I mean by an agent-native product approach. How do you train your own model?
Starting point is 00:20:42 on that adversary mindset and do it in such a way that it is responsible, controllable, all of those things that folks worry about. Yeah. So in terms of the models, that whole ecosystem is also evolving very fast. Gee, right? Just the news of the last few weeks has been, you know, the breakthroughs in these open-weight models
Starting point is 00:21:04 and, you know, which ecosystems, open-weight models are getting traction and how small can they be and how specialized can they be? So I believe this arc will play out. We've started out with just using models that are available, both the frontier models largely, but also some of the other specialized models. And we will continue to write that arc. Perhaps we will have some of our own models
Starting point is 00:21:31 as this open way the ecosystem rose up. But then the innovation and the technology we had to deploy is exactly what you're saying. How do you trust the models that we have? So we have a proprietary framework for our VELOC suite, which we call the VELOX Agenic Framework, which is sitting underneath all of our products. And in that is the provenance layer,
Starting point is 00:21:59 I believe compliance for agentic solutions is coming. Los Alon is one of the leaders in compliance over the decades for the federal government. so we're already proactively thinking about agentic compliance. And from that, we have a product and preview called VALox Layer 1. It's actually a proxy that sits between the agent and the LLM. And it governs everything going out and coming back. And you can deploy policy.
Starting point is 00:22:29 We have innutable logs. So the techniques we are using, our customers are interested in having access to those techniques. So we're introducing a product around that as well. Interesting. Moujtabh Hamid is Executive Vice President for Product and Strategy at Booz Allen Hamilton. Thank you so much for joining us. Thanks. That was Mujdava Hamid and Dave Bittner discussing AI Speed, Cyber Defense.
Starting point is 00:23:00 For more information on this conversation, be sure to check out our show notes. What's the one thing in business that's spreading as fast as AI? AI risk. Every new tool your team signs up for, every vendor that turns on AI features, every new integration, each one is another opportunity for something to go wrong. And most security programs weren't built to keep up with AI's pace of growth. Enter Vanta. Vanta is the number one agenetic trust platform,
Starting point is 00:23:43 trusted by more than 16,000 fast-moving companies like Ramp, Hursor, and Harvey to help them stay audit-ready. And now Vanta helps companies like yours keep. an eye on the risks that appear between audits across your vendors, your AI tools, and your entire environment. The Vanta agent works like a 24-7 GRC engineer in the background. It finds issues, drafts fixes for you, and can cut vendor assessment time by up to 50%. Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today at vanta.com slash cyber. That's v-a-t-a-com slash cyber.
Starting point is 00:24:33 Last up, tell us muse of the dangers of sailing the high seas, because if you've been waiting to see The Odyssey but can't make it to the cinema, beware of anyone offering you a convenient shortcut. The highly anticipated film is being used as bait in a wave of fake streaming scams, with criminals setting up convincing websites, complete with phony reviews and even dubbed versions tailored to a visitor's location. Victims are lured into signing up for free access, only to be asked for their bank details.
Starting point is 00:25:15 And yeah, as you might expect, there's no movie waiting on the other side. Instead, victims could end up with money stolen from their accounts, malware on their computers, and a fresh invitation to future fishing scams. Hooray! Now, while Christopher Nolan may want you to experience his epic on the, the big screen, he probably didn't have a malware download in mind for the encore. And that's the CyberWire. For links to all of today's stories, check out our daily briefing at thecyberwire.com.
Starting point is 00:25:55 We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share our rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to Cyberwire at n2K.com. And 2K's lead producer is Liz Stokes. We are mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our executive producer is Jennifer Eibin.
Starting point is 00:26:22 Peter Kielpia is our publisher. And I'm Maria Vermazes in for host, Dave Bittner, this week. Thanks for listening. We'll see you tomorrow.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.