CyberWire Daily - Please hack responsibly.
Episode Date: August 13, 2026President Trump deputizes private-sector companies to target cybercriminals. The LiteLLM supply-chain attack exposed credentials belonging to thousands of organizations. Data-theft campaign targets mi...sconfigured Salesforce and ServiceNow instances. Hackers deploy AI agents to breach Taiwanese government systems. CISA mandates urgent patch for actively exploited Cisco firewall vulnerability. Nightmare Eclipse publishes yet another Windows zero-day exploit. On our Industry Voices segment, Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps, discuss frontier models and the future of cyber defense. And please do not reply. Seriously. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices segment, Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps, speak with Dave Bittner at Black Hat about frontier models and the future of cyber defense, including responsible AI deployment, red teaming, reducing security noise, and the evolving role of human expertise in AI-assisted defense. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading Trump turns to private sector in offensive hacking operations memo (CyberScoop) Terabytes of credentials leaked in massive supply-chain attack (Ars Technica) "City-Forum" data-theft attacks target Salesforce, ServiceNow portals (BleepingComputer) 'Near-autonomous' AI agents attack Taiwan's nuclear safety agency (The Register) Cisco says software vulnerability could let hackers crash firewalls (Cybersecurity Dive) Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows (The Register) Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
Maybe that's an urgent email from your CEO, or maybe it's a deep fake targeting your business.
Doppel is the AI-native social engineering defense platform fighting back against impersonation and manipulation.
As attackers use AI to make their tactics more sophisticated, Doppel uses it to fight back,
automatically dismantling cross-channel attacks, building team resilience, and providing agentic
email protection.
Dopple, outpacing what's next in social engineering.
Learn more at doppel.com.
That's do pp-p-el.com.
President Trump deputizes private sector companies to target cybercriminals.
The light L-L-L-L-M supply chain attack exposed credentials belonging to thousands of organizations.
Data theft campaign targets misconfigured.
Salesforce and Service Now instances.
Hackers deploy AI agents to breach Taiwanese government systems.
SISA mandates urgent patch for actively exploited Cisco firewall vulnerability.
Nightmare Eclipse publishes yet another Windows Zero Day Exploit.
On our industry voices segment today, Clint Gibler, Cyber Lead at OpenAI, and Robbie Winchester,
chief global professional services officer at SpectorOps, discuss frontier models and the future of cyber defense.
And please do not reply.
Seriously.
Today is Thursday, August 13th, 2026.
I'm Maria Varmazes, and this is your Cyberwire Intel briefing.
Thank you for joining me today.
Let's dive in.
President Trump has signed a national security memorandum
establishing a framework that allows private sector companies
to assist federal law enforcement in offensive hacking operations
against transnational criminal organizations.
Under this directive of federal,
federal coordination center will oversee participating companies as they conduct cyber surveillance
and effects operations against these groups. The program requires strict vetting, adherence to
existing laws such as the Computer Fraud and Abuse Act, and oversight to evaluate companies' technical
proficiency. While some cyber experts welcome this as a significant shift in U.S. cyber policy that
stop short of a full hackback authorization. Others caution that it sets a risky precedent by expanding
private sector involvement in offensive cybersecurity operations. A supply chain attack on open source
AI library Light LLM exposed terabytes worth of credentials and other secrets belonging to thousands of
organizations. The incident took place in March 26 when the team PCP criminal group inserted malicious
code into the light LLM Python packages on Pi Pi, which were live for about 40 minutes.
The full impact of the attack was unclear at the time, but researchers at Cloud S-EK and Hudson Rock
have now obtained a copy of the data stolen during the attack. The researchers say that the breach
compromised over 434,000 CI-CD pipelines across nearly 2,500 organizations, including
Microsoft, Amazon, Cisco, Samsung, and Salesforce.
The exposed data includes active database passwords, API keys, SSH keys, cloud credentials,
Kubernetes Secrets, package publishing credentials, and more.
The researchers advise affected organizations to immediately audit their environments
and rotate all accessible credentials, assuming that they were exposed.
An ongoing data theft campaign dubbed City Forum is targeting organizations worldwide by exploiting
misconfigured Salesforce and Service Now portals.
According to researchers at RICO, the attacks use custom tools to enumerate in steel-exposed
records without needing to exploit underlying software vulnerabilities.
RICO explains, the attacker reaches Salesforce Lightning web runtime sites through the UI API,
a data layer we have not seen any public tool or write-up about, and it hammers a native
ServiceNow service portal search endpoint.
The attacks have targeted telecoms, banks, and financial,
firms, enterprise software vendors, and public sector portals.
Administrators are advised to review guest user sharing rules, disable unnecessary public APIs,
and enact strict authentication controls on search portals.
Suspected China-linked hackers launched what researchers call a near-autonomous cyber attack targeting
Taiwan.
Using publicly available AI agents like Hermes and OpenClaw, the attackers built a platform
that deployed up to eight agents simultaneously.
Over four days, these agents mapped 21 government systems, research vulnerabilities, and
autonomously adapted their tactics when blocked.
The attack successfully compromised at least 85 accounts, stole thousands of personnel records,
and expanded to hit Taiwan's nuclear safety agency and at least seven energy companies.
Cisco has issued patches for an actively exploited vulnerability affecting its secure
firewall adaptive security appliance and secure firewall threat defense operating systems.
The flaw, which is caused by improper error handling during HTTP request processing,
allows unauthenticated remote attackers to crash the firewalls by sending error-riddled
requests leading to denial of service. The U.S. cybersecurity and infrastructure security agency,
better known as SISA, has added the flaw to its known exploited vulnerabilities catalog and ordered
federal agencies to apply fixes by tomorrow, August 14th.
In what's become a monthly occurrence, Nightmare Eclipse, a disgruntled researcher with an apparent
grudge against Microsoft, published a new Windows Zero Day Exploit hours after Microsoft released
its patch Tuesday updates. The exploit allows attackers to gain system privileges on up-to-date
Windows 10, Windows 11, and Windows server systems. Security researcher Kevin Beaumont confirmed
that the exploit works and published detections and hunting queries to help organizations
protect themselves until a patch is available.
Now stick with us. After the break, Dave Bittner is joined at Black Hat by Clint Gibler of
Open AI and Robbie Winchester of Spectre Offs to explore frontier models and the future of cyber defense.
And please do not reply seriously.
AI is making fishing attacks faster, more convincing, and harder for.
people to spot and traditional security awareness and fishing training weren't designed for this
level of attack.
Hoxhunt helped security teams prepare employees for the attacks they face every day, with personalized
fishing training that adapts to each employee and reduces risky behavior over time.
For IT and security leaders looking to strengthen their human layer of defense, without adding
more manual work, visit Hoxhunt.com slash Cyberwire to learn more.
That's h-O-X-H-U-N-T.com slash cyberwire.
On our industry voices segment today, Dave Bittner talks with Clint Gibler,
cyber lead at OpenAI, and Robbie Winchester,
chief global professional services officer at SpectorOps,
all about frontier models and the future of cyber defense.
Here's their conversation.
To kick things off, before we dig into the real meat of our conversation here today,
Can we just kind of do a level set when it comes to where we think we stand
when it comes to our journey with tools like chat GPT and OpenAI and the large language models?
What do you think we are in that journey?
Yeah, I think a few years ago, say, chat GPT 3.5, it was an interesting idea,
and there were sort of the glimmers of something practically useful and valuable there.
But I think today across many domains, whether it's coding, knowledge work or other things,
it is, at least for me, actively, very, very helpful, surprisingly.
Yeah.
And we see it continuing to improve.
How about you? What do you think?
Yeah, I think we're kind of an interesting place where there's this breadth of capability and advancement
within the models and what LLMs can do in the accuracy and the kind of integrations that exist.
And it's also at the same time kind of tangentially related to your question,
and there's a kind of learning how to adapt and adopt
and what is the right way to use this.
And there's, I think, a lot of the base of,
I'm going to use this as a magic answer machine,
you know, the kind of stereotypical you ask questions,
you get a response.
But that's also only the real surface level of the utility of,
you know, how can you integrate and use different capabilities
and make, you know, kind of full-featured projects, things,
and go beyond, like, replacing Google search.
And so I'm interested and excited to kind of,
to see that shift. I think we're living that right now where everyone knows I can ask chat GPT
instead of Google and get a question response, but not everyone knows how can I go and leverage
something like Codex and do a project and what are these different like next generation kind of
things and what does that future look like, which is exciting. Yeah, just quick for the audience.
Let me see a show of hands. How many of you are using these kinds of tools on a daily basis,
would you say? Pretty much everybody, at least once a week, everybody else. Now, keep your hands up.
How about a year ago? Would you say you were using them daily a year ago? Maybe half.
So we can see how these have become part of our everyday use for so many people. And obviously,
this is a room full of folks who are a little biased towards that kind of use. But it is interesting
to see how people are coming to depend on it in their everyday lives. People, you wouldn't expect
to be calling on that.
I want to ask you about the trusted access for cyber program,
which is giving vetted people access to these frontier models.
Describe that for us and why that's an important part
of how you are presenting these tools.
With regards to many of the things we do at OpenAI,
it's useful to understand it from sort of a key point of view
or a key frame of reference,
and that is how do we maximally support and augment defenders
while giving ideally minimal capabilities for attackers.
So how do we protect the world
rather than giving potentially very capable cyber models
to attackers?
And specifically, so we have our mainline models,
such as 5.6 sole,
that are very capable at a number of defensive tasks,
whether that's looking for bugs and source code,
to analyzing logs,
to taking a look at malware,
as was shown earlier today,
so many different things.
and in the capability spectrum from, you know, identifying and fixing vulnerabilities
all the way to, say, generating exploits, which has a higher attacker uplift.
The earlier things on that spectrum, we went as broadly available to as many defenders as possible.
But there are some trusted companies or some trusted individuals that do get a lot of value from a broader range,
including more offensive capabilities, such as for AI red teams,
mean or pen testing, which does have defender uplift, but sort of commensurately higher attack
or uplift.
So basically, the trusted access program is our ability to give the most capable cyber models
to defenders so that they can help secure both companies and their customers.
And how do you calibrate that?
And is there any collaboration among the leading providers of these sorts of tools with all
the frontier models?
is there, collusion is the wrong word, but is there,
collaboration.
Collaboration.
Thank you, thank you.
Yeah, I did, I did.
But I guess, you know, there's a certain sense that I think some people have
that those frontier models, the experimental ones, we might be playing with fire a little bit.
So we need to be careful that we don't get burned.
How do you calibrate what's ready for the general public versus what we need to keep an eye on
to make sure that it's ready?
It's a good question.
So I think there's a lot of new developments with Frontier Model capabilities that, you know,
we're all figuring this out for the first time together.
And so there is the Frontier Model Foundation where all of the Foundation labs as well as other government organizations and, say,
NVIDIA and other companies where we're getting together to determine, you know,
what should our policies be more broadly?
So it's not just a single company making decisions in isolation.
All of us, speaking for at least one foundation lab,
we think very carefully about what we can do
to empower and augment defenders,
ideally maximally augmenting defenders
while giving minimal attacker uplift.
So there's many different sort of nuances
and small choices that you can make there,
but I think all of the labs, to my knowledge,
I have friends at all of them.
And I think people are very earnestly doing what they can
to help secure the world as quickly as possible,
given increasingly capable open source models.
I do also think to kind of piggyback on that,
part of the challenge of this is if you look at,
and kind of from the SpectreOps coming from more of an offensive security,
like adversary perspective,
how can this be used intentionally in a way to demonstrate what bad looks like
so that it doesn't happen inadvertently?
If you look at the history of red teaming, penetration testing, anything,
you are doing things that would, you go into a penetration test,
you are performing illegal actions against a company
that is only okay because they said it's okay.
But under any other circumstances,
a bunch of, you know, my group of testers,
if they did it one week later,
they would be committing a crime.
It's because we've agreed to go and do this adversarial thing
under these specific circumstances that there's merit.
And the reason why you do that is because there's concept
and there's reality,
and you can have a perspective of what is this going to look like,
but once the rubber meets the road,
you actually can then kind of unpack that and see.
And I think a lot of the challenge is figuring out what are those kind of intentional, unintentional, you know, dealing with fire.
Like fire has many use cases that you may not think about in the first place.
And some of those may be more dangerous than you realized.
And so you can't conceptualize every bit of that.
So having that, I think, like from our perspective, having the ability to work with a, you know, less restrictive model to be able to identify maybe use cases, issues, concerns, considerations in an authorized way for the benefit.
of the company and the providers is much better than you find out about it the first time
online.
Yeah, and like with many things, fire being a good example,
sort of fire can both keep you warm and cook your food, also burn down your house.
And if you are an enterprise that has many, many potential, say you have different scanners
and it's like you have 10,000 maybe vulnerabilities, if you can dynamically prove some subset of
those are actually exploitable, that helps you prioritize where
the real risk is.
So again, our cyber capable models can work with SpectreOps and others to, yeah,
just try to fix the most important things faster.
Well, for the security leaders here with us today,
what is your advice for the responsible deployment of these tools within their own enterprises?
From what you've learned, any tips, tricks, words of wisdom?
Sure.
So there's a number of security controls that you can use with Codex, for example.
So rather than running it in full access mode that allows it to just do anything without prompting you,
there's also an auto mode, which essentially has another model running to evaluate the tool calls and actions that it is taking so that it isn't doing something potentially dangerous.
You can also provide a custom policy for that.
You're like, hey, in our environment, here's the set of things that we believe are safe and trustworthy.
Also, depending on the use case, you can use the right model for the job.
For example, if you are scanning your network or trying to identify potential vulnerabilities,
you can use perhaps a mainline model that will refuse to actually exploit it.
However, if you are trying to actually prove something as exploitable,
then perhaps you could use a more cyber-focused model.
Yeah, and there is a number of additional security controls that we are working on and rolling out soon.
I would take kind of a more, maybe more abstract taking a step back.
The biggest thing from kind of like my perspective is there are elements like what Clint talked about that are very much kind of related to the specifics of an LLM deployment and you would want to like make sure it's there.
But also there are elements that are no different than any other application or no other piece of software being deployed.
And yes, there's a lot of capability, but like why are you deploying it?
What access does it need?
Who needs to have that access?
What are all the features?
There's a lot of elements where you can inadvertently, if you inadvertently are provisioning too much access, you're having a whole.
over permissions, you're having it too broadly deployed.
There's nothing inherent about the LLM or the model or the capability there that is wrong
necessarily, but you're creating fertile ground for something that you probably don't want
to have happen happen.
So it's, I think, a little bit of like, think about, in essence, this, there's, at a base
level, this is another application that is going to be deployed for a purpose, albeit a more
broad and kind of interesting, nuanced purpose.
But it is an application you're deploying for a purpose.
There should be an understanding of what you're deployed.
how it is deployed, where it is managed,
what are the identities you're there,
what potential new and interesting attack paths.
You know, if you, deploying a agentic tool to your sock
is potentially great,
but that also now potentially opens up an opportunity
for something else to take over your environment.
And so that doesn't mean that you shouldn't do it,
but you should have that perspective of holistically,
like, what am I adding,
and what is this kind of new landscape
rather than just adding a feature in, and again, any application has cost, everything has risk,
making sure you're conceptualizing more of a complete view and not just focusing on.
I think this can make solving a problem easier and not maybe what's the second or third order
effect.
That was Clint Gibler, Cyber Lead at OpenAI, and Robbie Winchester, Chief Global Professional Services
Officer at SpectorOps, discussing frontier models and the future of cyber defense.
If you want to listen to the full conversation, make sure to check out our special edition coming out this Sunday, wherever you get your favorite podcasts.
What's the one thing in business that's spreading as fast as AI? AI risk.
Every new tool your team signs up for, every vendor that turns on AI features, every new integration, each one is another opportunity for something to go wrong.
And most security programs weren't built to keep up with AI's pace of
growth. Enter Vanta. Vanta is the number one agentic trust platform, trusted by more than
16,000 fast-moving companies like Ramp, Hurser, and Harvey to help them stay audit-ready.
And now Vanta helps companies like yours keep an eye on the risks that appear between
audits across your vendors, your AI tools, and your entire environment.
The Vanta agent works like a 24-7 GRC engineer in the background. It finds issues,
drafts fixes for you and can cut vendor assessment time by up to 50%. Whether you're a fast-growing
startup or a global enterprise, Vanta is here to help you automate your security and compliance
and earn and prove trust. Get started today at vanta.com slash cyber. That's V-A-N-T-A-com slash cyber.
And finally today, please do not reply.
Seriously. A report by WIRE details how two security researchers purchased inexpensive
placeholder domains such as noreply.net and deleted user.com and configured them to receive
incoming emails. Doing so revealed a widespread data leakage problem as they began receiving
hundreds of thousands of misdirected automated emails from various companies. The messages
has included sensitive internal communications, human resources documents, hotel bookings, corporate
secrets, and my favorite, confirmation of people's pizza orders. Pepperoni with cheese, please.
And that's The Cyberwire. For links to all of today's stories, check out our daily briefing at
thecyberwire.com. We'd love to know what you think of this podcast. Your feedback ensures we
deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity.
security. If you like the show, please share a rating and review in your podcast app.
Please also fill up the survey and the show notes or send an email to Cyberwire at
N2K.com. N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music
and sound design by Elliot Heltzman. Our executive producer is Jennifer Ibin, Peter Kilpe
is our publisher, and I'm Maria Vermazas in for host Dave Bittner this week. Thank you for
listening. We'll see you tomorrow.
