CyberWire Daily - Now with extra vulnerabilities.
Episode Date: August 10, 2026Researchers find that only a quarter of AI-generated patches are fully successful. Ransomware attacks exploit critical N-able flaw. Atlassian fixes critical flaw in Rovo AI. LexisNexis disables some s...ervices following suspicious activity. US Senate confirms Adam Cassady as cyber ambassador. Meta ordered to pay an additional $567 million in child safety case. Water sector cyberattacks expand to new states. We got your Monday Business Briefing. On our Industry Voices, Dave Bittner sits down with Mujtaba Hamid, EVP, Product and Strategy at Booz Allen Hamilton at Black Hat discussing AI Speed Cyber Defense. And scammers set sail on The Odyssey. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices, Dave Bittner sat down with Mujtaba Hamid, EVP, Product and Strategy at Booz Allen Hamilton at Black Hat USA, discussing AI Speed Cyber Defense. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading More than half of AI-generated patches are broken (CyberScoop) China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns (The Record) Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data (SecurityWeek) LexisNexis shuts down services after suspicious activity on servers (BleepingComputer) US cyber ambassador nominee Cassady confirmed in Senate (The Record) Meta Ordered to Pay $567 Million in New Mexico Child Safety Case (New York Times) New Jersey, Alabama Join States Targeted in Water Cyberattacks (Securityweek) Business Breakdown (N2K) ‘Watch The Odyssey for free online’: scam targets film fans with fake streaming sites (The Guardian) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
Maybe that's an urgent email from your CEO, or maybe it's a deep fake targeting your business.
Dopple is the AI-native social engineering defense platform fighting back against impersonation and manipulation.
As attackers use AI to make their tactics more sophisticated,
Dopple uses it to fight back, automatically dismantling cross-channel attacks,
building team resilience and providing agentic email protection.
Dopple, outpacing what's next in social engineering.
Learn more at doppel.com.
That's dopppeel.com.
Researchers find that only a quarter of AI-generated patches are fully successful.
Ransomware attacks exploit critical enable flaw.
Atlassian fixes critical flaw in Robo AI.
LexisNexis disables some services following suspicious activity.
U.S. Senate confirms Adam Cassidy as cyber ambassador.
Mehta ordered to pay an additional $567 million in child safety case.
Water sector cyber attacks expand to new U.S. states.
We've got your Monday business briefing.
And on our industry voices, Dave Bittner sits down with Mujahabha Hamid,
EVP of Product and Strategy at Booz Allen Hamilton, at Black Hat, discussing AI Speed Cyber Defense.
and scammers set sail on The Odyssey.
Today is Monday, August 10th, 2026.
I'm Maria Varmazes in for Dave Bittner this week,
and this is your Cyberwire Intel briefing.
Thank you for joining me today. Let's get started.
Researchers at OnePassword found that AI-generated security patches
are still largely unreliable.
When ChatGPT 5.5 and Claude Opus 4.8 were tested against six recently disclosed
vulnerabilities, generating over 6,000 patches, only 26% of the patches fully fixed the vulnerability
without introducing new problems or altering application behavior. More than half the time,
the AI did not fix the flaw or introduced new vulnerabilities in the process. The researchers
conclude that human expertise still plays an essential role in the process of fully resolving
vulnerabilities and software without introducing unwanted side effects.
Microsoft has warned that a China-based cybercriminal gang is launching ransomware attacks
by exploiting a critical vulnerability in Enables and Central software,
which is a widely used remote monitoring and management tool.
After exploiting the flaw to gain administrative access,
the hackers deploy a new ransomware strain called Storm Encryptor.
Enable released emergency patches earlier this month
after the flaw was observed being exploited in zero-day attacks.
The company then issued a second emergency.
emergency hot fix on August 6th, after attackers bypassed the first patch.
A critical vulnerability in Atlassian's Rovo AI, dubbed Rovoblast, allowed attackers to use a
specifically crafted link to inject malicious instructions into a victim's Rovo session without
requiring a jailbreak or permission bypass. Because Rovo can access enterprise systems such as
Gira, Confluence, SharePoint, Slack, and Microsoft 365, the flaw could have been used to retrieve
and exfiltrate sensitive corporate data with a single click.
Atlassian fixed the issue following a responsible disclosure by researchers at Veronis.
Data Analytics company Lexis has taken its diligence,
Metabase API and Newsdesk services offline after detecting suspicious activity on servers
managed by a third-party vendor.
The company is investigating the issue and rebuilding the affected systems
in a new environment before restoring service.
The company has not said whether customer data was compromised.
Todd Larson, who is the president of the Global Nexus Solutions Division of LexusNexis,
said in a statement, our investigation is ongoing and we are working with a preeminent cybersecurity forensic firm on review and remediation.
The U.S. Senate has confirmed Adam Cassidy as chief of the State Department's Bureau of Cyberspace and Digital Policy,
making him the second person to hold this position.
The post had been vacant since Nathaniel Fick departed in January 2025.
Cassidy, a senior official at the National Telecommunications and Information Administration,
was confirmed in a 51-47 vote.
The record notes that it is unclear how much influence the position still holds
following a major State Department reorganization last year.
A New Mexico court has ordered META to pay $567 million
and make major changes to Facebook and Instagram to better protect children, bringing the company's
total liability in the case to $942 million.
The ruling requires stronger age verification, limits on minors platform use, tighter controls on
AI chatbot interactions, and measures to address child abuse and mental health harms.
Meta plans to appeal the ruling, a company spokesperson stated, we remain confident in our record of
protecting teens online and will continue to defend ourselves against claims that misrepresent the
facts. As a follow-up to a story that we have been covering, New Jersey and Alabama have joined the
growing list of states whose water and wastewater facilities were targeted in a cyberattack campaign
linked to Iranian hackers. The campaign, which began in late July, has reportedly affected at least
12 states. New Jersey's Cape May and Woodbine water systems were targeted on July 27th,
disrupting phone systems, but not water service. The same day, hackers targeted industrial
control systems at Alabama's Childersburg water sewer and gas system, but water services were not
disrupted. So far, affected utilities have reported limited impact, and officials continue to
say that drinking water is safe. The attacks have targeted ICS devices made by Rockwell
automation and may involve equipment from other major vendors. The FBI confirmed at least
seven states have been targeted as of July 30th, but has not publicly provided further updates.
And now it's time for our Monday business briefing. Last week's business breakdown highlights
just over a staggering $1 billion raised across 17 investments and one acquisition. For investments,
Horizon 3 raised $250 million in a series E round led by night.
Dragon and NEA. The U.S.-based autonomous pen testing company is now valued at $2 billion. Horizon 3 plans to use
the funding to scale its GTM operations, accelerate its product roadmap, and support its entry into
both Singapore and Australia. Additionally, Spur, the U.S.-based IP intelligence provider, raised $200
million from Insight partners. With the funding, the company is looking to expand investment across
product development, intelligence coverage, integrations, and enterprise operations.
lines. In acquisitions, Octa, the U.S.-based IAM company, acquired Permiso Security. By acquiring
the identity security platform, Octa is looking to expand its footprint beyond identity management
and add core SOC capabilities through Permiso's P0 Labs. And that wraps up this week's
business breakdown. For deeper analysis on major business moves shaping the cybersecurity landscape,
make sure to subscribe to N2K Pro and check out thecyberwire.com.
every Wednesday for the latest updates.
Stick with us now. After the break, Dave Bittner sits down with Mujdaba Hamid,
EVP of Product and Strategy at Booz Allen Hamilton, at Black Hat USA to discuss AI speed cyber defense.
And scammer set sail on The Odyssey.
AI is making fishing attacks faster, more convincing, and harder for people to spot.
And traditional security awareness and fishing training,
weren't designed for this level of attack.
Hoxhunt helps security teams prepare employees for the attacks they face every day,
with personalized fishing training that adapts to each employee and reduces risky behavior over time.
For IT and security leaders looking to strengthen their human layer of defense,
without adding more manual work, visit hoxhunt.com slash cyberwire to learn more.
That's H-O-X-H-U-N-T dot com slash.
Cyberwire.
Recently at Black Hat USA, Dave Bittner sat down with Mujtapa Hamid,
EVP of Product and Strategy at Booz Allen Hamilton,
as they discussed AI Speed Cyber Defense.
Here's their conversation.
We talked about agentic for cybersecurity.
The best innovation ideas and product ideas will also be the ones that are agent-native
and grow out and scale very fast,
which means especially if you're a technology company,
or your leveraging technology for your work,
you will be having a lot of genetic IP
that you have to develop,
roll out, and scale very quickly.
Well, welcome back.
We are here at Black Hat 2026,
and I am pleased to be joined by Mushitaabha Hamid,
who is Executive Vice President for Product and Strategy
at Booz Allen Hamilton.
Welcome, and thank you for joining us.
Good to be here.
Thanks, Dave.
So we want to talk about AI today.
And before we dig into some of the specifics,
I would love to get your take on kind of the state of things.
Like where do we find ourselves in this moment
when it comes to security professionals and enterprise folks in general
in dealing with this wave of AI?
Yeah.
Well, I'm surprised you're starting by AI.
But yeah, I think, you know,
every so often, there's a new tech wave,
and the tech stack gets either evolved or reshaped.
And we've been through a few of those,
depending on how old you are.
You know the 95 wave,
and then the wave when the mobile phones, the smartphones came,
and then the cloud wave.
And I think we're at this, a new wave,
but this wave seems to be different
because it's not just that a new layer is getting added.
but potentially the whole stack will get redrawn as well.
I mean, I can imagine these LLMs and that infrastructure
and now we're starting to see open weight models come to life.
So a new infrastructure layer is getting set up on which not just software gets built,
but then applications and the whole stack gets rebuilt on that.
With that, then you need a new middleware type of layer as well,
which we're also starting to see, you know, be it harnesses or a genetic governance,
or policy controls,
and then the apps on top.
So I think this wave is a culmination of several things,
but yeah, I think the stack is getting redone.
But every time the stack gets redone,
the prior waves are still there.
You know, we still have mainframes running ATM software.
And so all of those.
So for cybersecurity professionals,
the complexity just expands and compounds.
And I think that's what we are going through right now.
So you're barely trying to keep up with what you had to worry about
and suddenly a whole new redrawing of the tech stack
with ginormous amounts of code getting written,
vulnerabilities getting found.
And so to call it, I think it's overwhelming for the industry,
for the Sissos, for everyone involved.
How much do you think that this is a marriage
of velocity that everything is, it seems to me,
is coming so much more quickly at all the people
who are trying to adjust to all of this.
Yeah, and that's also another thing that to me,
I don't think it's new.
As technology develops every wave of technology,
the velocity increases.
And here, yeah, the velocity is maybe even exponentially faster
than the prior waves.
and we see that in the adoption.
And just in my personal experience
and probably yours and others,
the changes we used to see
in a year or two years in terms of new tools
or resources coming,
now we're seeing that in a matter of months.
I grew up in a semiconductor industry
when the Moore's law was fully active
and we'd be very proud that every 18 months
you could double the computing power.
Well, the elements,
and this whole wave is going much fast.
than Woolrowl right now.
And how do you see the adversaries
taking advantage of that?
What are some of the specific things you're tracking?
The things that we track as Booz Allen,
given the sensitive clients that we work with,
but there's a lot that we're, all of us are seeing.
You know, the news coming out,
the hugging face news that came out,
the wave before that when, you know,
the mythos news was released.
Now, you know, super patched Tuesday,
with hundreds and hundreds of vulnerabilities being found.
So we're all seeing and living through the impact
with the pace and velocity and depth of changes.
And as with all, technology, technology can be used for good or evil.
And the adversaries are as smart if not smarter
and they have a lot of strong tools
better than they've ever had at their disposal.
and we're seeing the effects of that, honestly.
And so to me, as a product manager
and going through this case,
we have to be in that line between hope and fear, right?
Like, too much hope and too much fear,
like both of them,
so you have to be in that, okay, what do you do about it?
Right?
Like, how do you use the tools at your disposal
in a way that you can remain a tech optimist
and you're out there at the front lines
and you're helping the companies
protect their mission systems,
their crown jewels,
their operational readiness,
so they can keep doing what they're doing.
You alluded to the scale of an organization
like Booz Allen,
and I think that extends to the types of customers
that you tend to work with.
How do you reconcile this velocity issue,
with large organizations
that have to deal with things like regulations.
There's that old saying,
you can't just turn a battleship on a dime.
How do you align those things?
There's no magic trick here.
And so the position we have given
who we work with in the scale,
complexity, and the unique threats
and regulations that our set of customers
have to work with is,
one, you have to be really good
at thinking in systems
and being systematic
and seeing patterns at scale.
Second, really understanding
the customer environment deeply,
be it to deploy zero trusted
or to kind of do
penetration testing or
to kind of come up with a cyber defense.
But really that stems
from a deep knowledge of the environment itself.
And then go execute at pace.
So what we see from Booz Allen is,
yeah, we bring a lot of the commercial technology into bear as well.
You have to be focused on the mission grounding,
then environment knowledge,
and then thinking like large-scale systems and applying that.
And what are the strategies that you and your colleagues think
are going to be most successful here?
Are we talking about fighting AI with AI?
Well, I'd be one of 500 people here talking about fighting AI with AI.
That's true.
You probably have heard that a few times.
Once or twice, yeah.
But I think we can all say fight AI with AI.
But what do we mean when we say that, right?
Are you applying AI at the fringes?
Are you looking at AI at the workflow level?
or are you looking at AI fundamentally reimagining
how the value is provided to the customer?
So, for example, given the scale sophistication
and what the adversity is doing,
what I believe is we need to kind of have
be fighting AI with AI at all levels, right?
Here, what we have from a product standpoint is
the advantage of coming in with fresh ideas.
And so we fundamentally are going AI native.
So we look at AI at the ground up
at the core of our technology solution
to fight this threat instead of
if we were an incumbent or established,
we would be looking at, okay,
how do I start to kind of bring in AI
from the fringes of my product down?
But we're actually like reimagining it
from the inside out.
And I believe that both approaches are needed,
but our approach is also needed
in order to scale at the velocity that we need right now.
Help me understand that.
Does that mean that the products at their core
are AI-focused as opposed to having AI grafted on after the fact?
Yeah, so the core of our products,
that essentially agent-egent-egetic products,
So with an orchestrator, with a swarm of agents,
and an agentic framework underneath,
so we can be ensuring that all the agents in our product are resilient,
we have immutable logs of what those agents are doing,
we can move towards compliance for our agents.
But essentially, we're an agentic swarm set up product portfolio.
So everything starts from there,
which then gives us the ability to scale,
branch off very quickly as well.
So if there's an adjacent idea that comes in or a gap, we see,
a lot of times it could just be a refactoring of that agent swarm,
or you add a few more agents into that swarm,
task them differently, and you have a full governance on it.
So that's what I mean by an agent-native product approach.
How do you train your own model?
on that adversary mindset
and do it in such a way that it is responsible,
controllable, all of those things that folks worry about.
Yeah. So in terms of the models,
that whole ecosystem is also evolving very fast.
Gee, right?
Just the news of the last few weeks has been,
you know, the breakthroughs in these open-weight models
and, you know, which ecosystems, open-weight models are getting traction
and how small can they be and how specialized can they be?
So I believe this arc will play out.
We've started out with just using models that are available,
both the frontier models largely,
but also some of the other specialized models.
And we will continue to write that arc.
Perhaps we will have some of our own models
as this open way the ecosystem rose up.
But then the innovation and the technology we had to deploy
is exactly what you're saying.
How do you trust the models that we have?
So we have a proprietary framework for our VELOC suite,
which we call the VELOX Agenic Framework,
which is sitting underneath all of our products.
And in that is the provenance layer,
I believe compliance for agentic solutions is coming.
Los Alon is one of the leaders in compliance over the decades
for the federal government.
so we're already proactively thinking about agentic compliance.
And from that, we have a product and preview called VALox Layer 1.
It's actually a proxy that sits between the agent and the LLM.
And it governs everything going out and coming back.
And you can deploy policy.
We have innutable logs.
So the techniques we are using, our customers are interested in having access to those techniques.
So we're introducing a product around that as well.
Interesting.
Moujtabh Hamid is Executive Vice President for Product and Strategy at Booz Allen Hamilton.
Thank you so much for joining us.
Thanks.
That was Mujdava Hamid and Dave Bittner discussing AI Speed, Cyber Defense.
For more information on this conversation, be sure to check out our show notes.
What's the one thing in business that's spreading as fast as AI?
AI risk.
Every new tool your team signs up for, every vendor that turns on AI features, every new integration,
each one is another opportunity for something to go wrong.
And most security programs weren't built to keep up with AI's pace of growth.
Enter Vanta.
Vanta is the number one agenetic trust platform,
trusted by more than 16,000 fast-moving companies like Ramp, Hursor, and Harvey to help them stay audit-ready.
And now Vanta helps companies like yours keep.
an eye on the risks that appear between audits across your vendors, your AI tools, and your entire environment.
The Vanta agent works like a 24-7 GRC engineer in the background.
It finds issues, drafts fixes for you, and can cut vendor assessment time by up to 50%.
Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust.
Get started today at vanta.com slash cyber.
That's v-a-t-a-com slash cyber.
Last up, tell us muse of the dangers of sailing the high seas,
because if you've been waiting to see The Odyssey but can't make it to the cinema,
beware of anyone offering you a convenient shortcut.
The highly anticipated film is being used as bait in a wave of fake streaming scams,
with criminals setting up convincing websites,
complete with phony reviews and even dubbed versions tailored to a visitor's location.
Victims are lured into signing up for free access,
only to be asked for their bank details.
And yeah, as you might expect, there's no movie waiting on the other side.
Instead, victims could end up with money stolen from their accounts, malware on their computers,
and a fresh invitation to future fishing scams.
Hooray!
Now, while Christopher Nolan may want you to experience his epic on the,
the big screen, he probably didn't have a malware download in mind for the encore.
And that's the CyberWire.
For links to all of today's stories, check out our daily briefing at thecyberwire.com.
We'd love to know what you think of this podcast.
Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing
world of cybersecurity.
If you like our show, please share our rating and review in your podcast app.
Please also fill out the survey in the show notes or send an email to Cyberwire at n2K.com.
And 2K's lead producer is Liz Stokes.
We are mixed by Trey Hester with original music and sound design by Elliot Peltzman.
Our executive producer is Jennifer Eibin.
Peter Kielpia is our publisher.
And I'm Maria Vermazes in for host, Dave Bittner, this week.
Thanks for listening.
We'll see you tomorrow.
