CyberWire Daily - Please hold while we decide.
Episode Date: August 17, 2026Internal policy conflicts hamper U.S. military AI leadership. Clop claims GE, Philips and Shell. Attackers actively probe internet-facing GeoServer instances. “The Hatman” offers millions of alleg...ed employee records for sale. ETSI begins the approval process for European cyber standards. Microsoft is still working on a patch for the ShieldBreak vulnerability. Autonomous AI systems create CPU bottlenecks. Monday business briefing. Our guest is Nick Warner, CEO at Neo.ai, on the shifting landscape around AI and agentic security. AI agents kneecap each other with self-replicating malware. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today’s Industry Voices segment, we are joined by Nick Warner, Neo.ai's CEO, discussing the shifting landscape around AI and agentic security. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading The U.S. Military Wants A.I. Dominance. Feuds and China May Thwart It. (The New York Times) Philips and GE investigating Clop ransomware data theft claims (Bleeping Computer) Attackers Probe Critical GeoServer SQL Injection Vulnerability (Hack Read) Crook hawks millions of records allegedly plundered from corporate Azure tenants (The Register) ETSI Proposes 17 Cybersecurity Standards to Support EU CRA (Infosecurity Magazine) Microsoft working on Defender patch for ShieldBreak zero-day (Bleeping Computer) Agentic AI Crunch Creates CPU Comeback (IEEE Spectrum) Corma raises $60 million in seed funding. (N2K) Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware (SecurityWeek) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
Social engineering attacks look trustworthy, a routine request, an internal email, a familiar face on a call.
But Dopple sees through the disguise.
Their AI-native platform detects and disrupts attacks across every channel,
trains employees to recognize deepfakes and deception, and investigates every fish to take down the campaign behind it.
They fight relentlessly to protect your.
your business, brand, and people.
Dopple, outpacing what's next in social engineering.
Learn more at doppel.com.
That's do p-p-p-e-l.com.
Internal policy conflicts hamper U.S. military AI leadership.
Klop claims GE, Phillips, and Shell.
Attackers actively probe internet-facing geoserver instances.
The Hatman offers millions of alleged employee records for sale.
Etsy begins the approval process for U.S.E.
European cyber standards. Microsoft is still working on a patch for the shield break vulnerability.
Autonomous AI systems create CPU bottlenecks. We've got your Monday business briefing.
Our guest is Nick Warner, CEO at Neo AI, on the shifting landscape around AI and agenic security.
And AI agents kneecap each other with self-replicating malware.
It's Monday, August 17, 26.
I'm Dave Bittner, and this is your Cyberwire Intel briefing.
Happy Monday, all. It is great to be back. My thanks to Maria Vermazes for filling in as host and the entire Cyberwire team for keeping everything running smoothly while I was enjoying some vacation time away with the family.
Here's today's stories. The New York Times argues that the United States push to achieve military leadership in artificial intelligence is being undermined by,
by internal policy conflicts, inconsistent decision-making, and the rapid pace of Chinese AI development.
A key example is the Pentagon's shifting stance toward Anthropic, whose AI tools were first banned,
then partially reinstated despite their importance for cybersecurity and offensive cyber capabilities.
The dispute stems from disagreements between Anthropic and Defense Secretary Pete Hegeseth
over limits on military use of the company's technology,
even as agencies like the NSA continue testing Anthropics' advanced mythos model.
More broadly, the Trump administration has alternated between deregulation
and tighter oversight of frontier AI models,
while sending mixed signals on export controls for advanced chips.
Security experts warn that these inconsistencies could weaken U.S. competitiveness
as China narrows the AI gap, increasing the stakes in what many view as a strategic technological race
with profound national security implications.
General Electric Phillips and Shell are investigating claims by the Klopp ransomware gang
that it breached their systems and stole sensitive data.
Phillips confirmed an attempted compromise of an internal enterprise server,
but said the incident was contained and did not.
not affect customer environments. GE and Shell acknowledge they're assessing the claims, but have not
confirmed a breach. Klopp has listed all three companies among 43 alleged victims of attacks
exploiting the critical PTC wind chill and flex PLM vulnerability. Security researchers SISA and
Germany's BSI have confirmed active exploitation of the flaw, prompting urgent patching guidance.
Klopp claims it stole sensitive corporate data, including project plans, blueprints, and backups.
The group has a history of exploiting enterprise software vulnerabilities in large-scale data theft campaigns,
targeting major organizations worldwide.
Attackers are actively probing internet-facing geo-server instances for a critical unauthenticated SQL injection vulnerability,
affecting deployments that use post-GIS 12 or later with text or JSON fields.
Publicly disclosed as a zero-day on August 12th, the flaw allows attackers to manipulate database queries
through exposed web feature services and web map service interfaces.
Under certain PostGSQL configurations, the vulnerability can lead to remote code execution on the database host.
Researchers have already observed.
widespread scanning activity, though current probes appear to be testing systems rather than
exploiting them fully. Geo Server released patched versions on August 14th and advises immediate upgrades
as no effective workaround exists. Organizations should also restrict access to exposed services,
review post-GresQL privileges, and monitor logs for suspicious requests. A threat actor known as
the Hatman claims to be selling millions of employee records, allegedly stolen from the Microsoft
Azure environments of nine major organizations, including McDonald's, Vodafone, Tata Consultancy Services,
Kindril, and HCL Technologies. According to Hudson Rock, the data appears highly likely to be authentic
and includes corporate contact information, employee IDs, organizational structures, group memberships,
details about privileged administrator accounts. While the attacker claims compromised credentials were
used, the initial access method remains unverified. Hudson Rock believes the campaign is more likely
tied to Info-Stealer malware than an Azure vulnerability. TCS said it found no evidence of a breach,
describing the exposed information as outdated basic employee data and stating that customer
systems and data were not affected. Other organizations have not confirmed the claims.
The European Telecommunications Standards Institute, Etsy, has begun the approval process for 17
cybersecurity standards that will help organizations comply with the European Union's Cyber
Resilience Act, which takes full effect in December 2027. The proposed standards establish
baseline security requirements for commercially available hardware and software sold in the EU,
including Secure-by-Default configurations, modern cryptography, software bills of materials,
and the ability to provide security updates after products are sold. The standards cover 17 product
categories, including operating systems, routers, firewalls, VPNs, browsers, password managers,
IoT devices, smart home products, and wearables.
Public consultation will continue through late 2026 with final standards expected by December.
Etsy, Sen, and Senilek are also conducting workshops to help manufacturers,
particularly small and medium-sized businesses, prepare for CRA compliance.
Microsoft has confirmed it's developing a security update for a newly disclosed
Microsoft Defender privilege escalation vulnerability known as shield break. The flaw was publicly
disclosed by security researcher Nightmare Eclipse, who claims it bypasses Microsoft's earlier
fix for the rogue planet vulnerability. A proof-of-concept exploit demonstrates that a local
attacker with limited privileges can gain system-level access on fully patched Windows 11
and Windows server systems when Microsoft Defender is enabled.
Microsoft says it is investigating the issue and preparing a security update but has not provided a release timeline.
The disclosure follows an ongoing dispute between Nightmare Eclipse and Microsoft over vulnerability reporting practices.
Several other Windows Zero Day vulnerabilities disclosed by the researcher remain unpatched,
although Microsoft has addressed some in recent Patch Tuesday updates.
Agentic AI is shifting a.m.
key infrastructure bottleneck from GPUs to CPUs, as autonomous AI systems generate large numbers
of tool calls, API requests, and sub-agents that rely heavily on traditional processors.
According to an article from the I-Triple-E, industry analysts and researchers say that while
GPUs still handle large-language model inference, CPUs manage tasks such as parsing outputs,
invoking tools, executing code, enforcing security guardrails, and tokenizing data.
As enterprises deploy thousands or even millions of AI agents, CPU demand has surged,
prompting Amazon Web Services to urge engineers to conserve CPU resources.
Researchers also found that insufficient CPU capacity can leave GPU's idle while they wait for instructions,
increasing latency.
Longer AI conversations further amplify CPU workloads because tokenization must be repeated after each tool call.
The growing demand is already influencing the hardware market with server CPU shortages,
increased investment from Intel, AMD, ARM, Qualcomm, and Invidia,
and expectations that CPU capacity will become increasingly critical for large-scale agentic AI deployments.
Turning to our Monday business briefing, cybersecurity and AI companies attracted significant investment this past week,
led by AI cybersecurity startup Korma, which raised a $60 million seed round to expand deployments already underway at Fortune 100 and Fortune 500 organizations.
Drone defense firm Aurelius Systems secured $40 million to advance its Archimedes platform and strength,
and manufacturing, while AI red-teaming company MindGuard raised $30 million to scale operations.
Actualize AI emerged from stealth with $7 million to expand its AI governance platform.
Sintaza received a strategic investment to accelerate sovereign AI development,
and insider threat startup above received funding from CrowdStrikes Investment Fund.
Mergers and acquisitions also remained active.
Visa agreed to acquire Biometric Verification Company Biocatch.
Deal purchased AI Identity Verification Startup Clarity.
Anaconda acquired AI security firm Encrypt AI, and InfoBlocks completed its acquisition of Kentik.
Blue Ally acquired giga networks.
AXAXL agreed to acquire cybersecurity consultancy SRS.
and Logicalis U.S. expanded its managed security services footprint by acquiring loyal.
Check out all of the cybersecurity business news.
That is part of our business briefing.
You can find that on our website.
It's all part of Cyberwire Pro.
Coming up after the break, my conversation with Nick Warner, CEO at Neo-AI,
on the shifting landscape around AI and agentic security.
and AI agents kneecap each other with self-replicating malware.
Stick around.
Nick Warner is CEO at Neo-AI.
In today's sponsored industry voices conversation,
we discuss the shifting landscape around AI and agentic security.
We are continuing our conversations here at Black Hat 2026,
and joining me is Nick Warner.
He is CEO at Neo.
Nick, thanks for joining us.
Happy to be here.
So obviously the hot topic on the show floor here today is AI.
But I think one of the interesting things I've noticed while walking around on the show floor is that AI has kind of infiltrated everything, right?
And so the security professionals are trying to figure out how to deal with that reality.
What's your take on that, this ubiquity of it?
Yeah, well, you know, I think we're going to see that throughout the enterprise.
And we're just at the front end of this massive software inflection point,
where today everybody's talking about the frontier AI software,
whether or not it's Claude Desktop, ChatGPT, et cetera.
But really what's happening is that all software by 2030 will be agentic.
Half of it's going to be agentic by the end of this year.
And so the problem isn't just how do we control these ultra-powerful,
almost like mini-operating system, agentic platform, desktop tools.
But what do we do about that accounting software that becomes agentic in two weeks?
That HR software that we've used and trusted and could define what normal look like with it for eight years.
And suddenly on a Wednesday, it becomes agentic.
And so I think the infiltration and the ubiquity of the AI messaging, I think, is also going to be found in all software.
And so we're really at, I think, a forefront of a very exciting, but also challenging time and security.
Well, if I'm a CISO and I see these changes happening, how do I contend with that?
Is it fair to categorize it as a type of sprawl?
It is.
And I think it's compounded also by a lot of the design customers we've had and the folks we're talking to run very large enterprises.
And so there is this prevailing question that we get asked is like, where do we begin?
And how do we possibly adopt better controls through our enterprise and do it in the way that's scalable?
And I think that that's a real problem that people are wrestling with today.
Is it fair to say that this is the number one problem we're facing in cyber these days?
I think it is.
Yeah, for sure.
Because it's, you know, you have an entire industry that was built around the premise of fundamentally there were two things.
There was software and there were humans.
And we got really good as an industry at defining what normal look like for human behavior and for software behavior.
And all of that is out the window now with AI.
Well, let's look at the broader view then.
I mean, outside of security itself, the broader enterprise environment, in your view, how is that affecting the entire ecosystem of an organization?
Well, you know, that's the challenge in, you know, my two decades plus in cybersecurity is that for better for work,
worse, we have to be reactive to what the broader IT industry is developing, introducing,
and end users are adopting. And right now, the pace and freneticism in innovation, especially
from the AI side of things, is really incredible. So I think at no other point in history
have we had this inflection point and then also compounded by the speed at which things are changing.
And so I think that's reflected in how we're using devices in our personal lives. It's certainly
being reflected in how companies are adopting new agentic software. And, you know, there's a lot of
good with it. There's also some bad and there's also some ugly. So it's a, it's a reflection
of the sign of the times. I want to touch on the leadership aspect of this. Before you were
with Neo, I want to get this right. You were leading Sentinel One's go-to-market efforts. You were with
them through their IPO. From a leadership point of view,
what is your take on this reality where we find ourselves these days?
How is someone in your position best positioned to lead this journey?
Yeah, you know, I think there's an amazing amount of funding that's coming into the cyber market.
And I think for really good reason, because we live in a digital world,
and we live in a digital world that's undergoing a revolution.
And so naturally, you're going to need some really interesting and new tech to help,
problems. But I think what's sort of lost in this is that there's a difference between having
good to great product and then building a great enduring company. And I think what you really need
is operational know-how, understanding and expertise on how to build and scale an enduring
business, to put customers at the center of what you're doing and building. And I think that that's
really going to be exacerbated today by the pace of change. So it's not enough to solve the problems
of today as we're in August, there's going to be new and different problems that we have to
solve in November in February, in July of next year. And so you really need to put the right
type of framework in place at a company to be relevant in two, three, four years, especially
with the pace of change that we see today. Tell me a little bit more about Neo itself. I mean,
how are you structuring the organization to be in a position to handle these challenges?
Yeah, you know, I think for us,
We were in stealth purposely for well over a year, which in today's sort of dog-year age, that's a long time.
There are companies I've seen out there, and they were in stealth for 60 days.
But we took a long path to market because we wanted to build the right type of core architecture.
There are some shortcuts that you can take place in terms of introducing tech, especially in a vibe coding world.
But we understood that to sell and support enterprises, we wanted all eyes and focus in terms of,
internally on building a great product.
And so at this point, we're really pivoting now
into building a great go-to-market.
And it's a great go-to-market that a lot of things
that I'm putting in structurally are about
how do we best find support and serve customers
and do that in a way that they understand
that Neo is not a company that's built to sell.
We're not here to sort of build interesting tech
that could be absorbed in a year or two.
We want to build a foundational company
and security. And so that really takes discipline. It takes structure. It takes a right type of hiring,
all of which I've been through in my two decades plus in the industry. I think it's fair to say
that obviously we're in an era of rapid change when it comes to all these things. I might even go
so far to say you're fairly volatile. As you look towards the future, towards the horizon,
do you think things are going to settle in? How long do you suspect we might have to wait?
until we get in some sort of a steady state, if ever.
I mean, well, you know, I've been in cybersecurity 25 years,
so there's no sort of stasis steady state.
It's, you know, change is constant.
But, you know, for myself, it's really what keeps things exciting, interesting.
I do think what, you know, from an AI perspective,
we're going to really start to reap some interesting benefits on tough problems that we haven't solved.
as civilizations haven't solved,
that I think we're going to start to see
some really interesting breakthroughs.
Because right now, there's sort of a hype cycle
of scare factor, rapid adoption,
not really understanding the best way to use these things
in a lot of ways.
And I think that where we will get to is a balance
of people really understanding this is really useful technology
that can help humans solve really interesting problems.
And I, you know, look, if anything, humans are smart, adaptable,
creative. And so I think that we'll be fine. We'll, we'll, we'll, we're going to adapt and adjust to this.
I think as an industry, it's going to really require a rethink of a lot of the traditional controls.
And not to take anything away from them, they were just built for a different era. And, you know,
that happens in the industry. Every 10 or so years, whether or not it's, you know, at the beginning
of the millennium, it was the internet. And then it was mobile.
And then it was cloud.
And now we're living through something that's probably bigger than all of those things wrapped up in one.
So it's a great time to be alive and it's a great time to be in the industry because the problems are numerous and very interesting that we're all trying to solve as an industry.
All right.
Nick Warner is CEO at Neo.
Nick, thanks so much for joining us.
Thanks for having me.
I enjoyed it.
And finally, Anthropics' latest research suggests,
that giving AI agents conflicting goals can produce surprisingly human workplace dynamics,
only with more malware. In one experiment, multiple clod-based agents were independently tasked
with migrating the same software project. Unaware they had company, they soon concluded
rival agents were obstructing their work and responded by disabling accounts, killing competing
processes, planting disguised malicious code, and in some cases, locking one another out entirely.
Fortunately, not every disagreement ended in a digital coup. More advanced Mythos 5 models frequently
recognized the conflict stemmed from contradictory instructions, documented their actions,
and sought human help, although they often seized control before negotiating peace. Separate experiments
found coordinated AI swarms uncovered more software vulnerabilities than isolated agents,
while identical models tended to converge on the same decisions,
even adopting consensus over correct information.
Anthropic argues these findings show that smarter AI does not automatically become more cooperative,
making agent-to-agent safety an increasingly urgent challenge.
And that's the Cyberwire.
For links to all of today's stories, check out our daily briefing at thecyberwire.com.
We'd love to know what you think of this podcast.
Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity.
If you like our show, please share a rating and review in your favorite podcast app.
Please also fill out the survey in the show notes or send an email to Cyberwire at n2K.com.
N2K's lead producer is Liz Stokes.
We're mixed by Trey Hester with original music and sound design by Elliot Peltzman.
Our contributing host is Maria Vermazes.
Our executive producer is Jennifer Ivan.
Peter Kilpe is our publisher, and I'm Dave Bittner.
Thanks for listening. We'll see you back here tomorrow.
