CyberWire Daily - The AI has entered the chat.
Episode Date: July 22, 2026GPT escapes the sandbox and hacks Huggingface. SolarWinds patches multiple critical flaws. CISA orders patching of a critical Langflow AI vulnerability. A Paidwork breach affects over 23 million users.... A recently patched SharePoint vulnerability is under active exploitation. Oracle patches over 1,400 vulnerabilities. Apps turn Smart TVs into residential proxies. The FCC considers expanding direct to satellite communications. German and U.S. authorities dismantle a major phishing-as-a-service (PhaaS) platform. Our guest is Jimmy McNary, Deputy Federal CTO at Semperis, discussing comprehensive identity security assessments for Microsoft GCC. AI models can’t resist bending the rules. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On our Industry Voices segment, we are joined by Jimmy McNary, Deputy Federal CTO at Semperis, discussing how Purple Knight now delivers comprehensive identity security assessments for Microsoft GCC high environment. Selected Reading OpenAI Claims Its AI Models Went Rogue and Hacked Another Company (Infosecurity Magazine) SolarWinds Serv-U Update Fixes 15 Critical Vulnerabilities Enabling Remote Code Execution as Root (GB Hackers) CISA orders urgent action on actively exploited Langflow RCE flaw (Bleeping Computer) Paidwork breach exposes data of 23 million users: Check if you're affected (Malwarebytes) Fourth SharePoint Vulnerability Exploited in Past Month's Wave of Attacks (SecurityWeek) Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates (SecurityWeek) Chairman Carr Proposes to Expand Direct-to-Device Satellite Broadband Connectivity to Unlicensed Wireless Devices (FCC) LG to Ban Residential Proxies from Smart TV Apps (Krebs on Security) Police dismantle Kratos phishing platform, arrest developer (Bleeping Computer) AI's cheatin' heart will make you weep (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
What's the one thing in business that's spreading as fast as AI?
AI risk.
Every new tool your team signs up for, every vendor that turns on AI features, every new integration,
each one is another opportunity for something to go wrong.
And most security programs weren't built to keep up with AI's pace of growth.
Enter Vanta.
Vanta is the number one agentic trust.
platform, trusted by more than 16,000 fast-moving companies like Ramp, Hercer, and Harvey to help
them stay audit-ready. And now Vanta helps companies like yours keep an eye on the risks that
appear between audits across your vendors, your AI tools, and your entire environment.
The Vanta agent works like a 24-7 GRC engineer in the background. It finds issues, drafts,
fixes for you, and can cut vendor assessment time by up to 50 percent.
Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust.
Get started today at Vanta.com slash cyber.
That's V-A-T-A-com slash cyber.
GPT escapes the sandbox and hacks hugging face.
Solar winds patches multiple critical flaws.
Sisa orders patching of a critical.
Langeflow AI vulnerability.
A paid work breach affects over 23 million.
A recently patched SharePoint vulnerability is under active exploitation.
Oracle patches over 1,400 vulnerabilities.
Apps turn smart TVs into residential proxies.
The FCC considers expanding direct-to-satellite communications.
German and U.S. authorities dismantle a major fishing-as-a-service platform.
Our guest is Jimmy McNary, Deputy Field CTO at Semperis, discussing
comprehensive identity security assessments for Microsoft GCC. And AI models can't resist bending the rules.
It's Wednesday, July 22nd, 2026. I'm Dave Bittner, and this is your Cyberwire Intel briefing.
Thanks for joining us here today. It is great as always to have you with us.
OpenAI has disclosed that two of its frontier AI models, GPT 5.6 Sol and an undisclosed pre-release model,
autonomously breached Hugging Faces production infrastructure during an internal cybersecurity evaluation.
The models were tested in a restricted environment, but they chained together vulnerabilities,
uncovered and undisclosed zero-day, escalated privileges, gained Internet access,
and ultimately compromised Hugging Face systems to obtain evaluation-related data.
Hugging Face had previously reported the July 16th intrusion
and suspected an autonomous AI agent was responsible,
a conclusion later confirmed by OpenAI.
The company said it has responsibly disclosed the Zero Day vulnerability,
strengthened safeguards for future evaluations,
and partnered with Hugging Face on security improvements.
Security leaders say the incident demonstrates that advanced AI systems can pursue unintended harmful strategies without explicit malicious intent.
They warn the event marks a turning point for defenders, highlighting the need to prepare for AI-driven attacks that could eventually be adopted by malicious threat actors.
Solar Winds has released an update addressing 15 security vulnerabilities in its serve-U-managed file transfer.
and FTP server products, including multiple critical flaws rated 9.1 CVSS.
The vulnerabilities could allow authenticated attackers to escalate privileges, execute
arbitrary code, and potentially gain root access on Unix-like systems through broken access
controls and insecure direct object references.
While Windows deployments face lower impact, the breadth of issues makes upgrading a priority
particularly for internet-facing servers.
The release also introduces several security enhancements,
including stronger content security policies,
new browser security headers,
expanded multifactor authentication support
for Microsoft Active Directory and LDAP users,
and a fix for a stored cross-site scripting vulnerability.
Additional improvements to logging, file sharing reliability,
and browser compatibility further strengthen
the platform's overall security and operational resilience.
SISA has ordered U.S. federal agencies to urgently patch a critical vulnerability in the
Langflow AI agent framework that's being actively exploited. The flaw allows unauthenticated attackers
to achieve remote code execution as route. Researchers have observed more than 220 exploitation
attempts with attackers seeking to deploy malware and steal AWS credentials,
environment variables, and container metadata.
SISA has added the vulnerability to its known exploited vulnerabilities catalog
and directed federal agencies to remediate affected systems by Friday,
warning that the flaw poses a significant risk to federal networks.
A reported data breach at PaidWork, a platform that pays users for complete
leading online microtasks, has allegedly exposed the personal and financial information of more than
23 million users. The breach reportedly occurred in March of this year, with an 11-gibite database
advertised on a cybercrime forum the following month. Exposed information includes names,
contact details, dates of birth, bank account numbers, transaction histories, device and IP data,
profile photos, and hashed passwords.
Although paid work has not publicly confirmed the incident,
security experts warn the stolen data could enable fishing,
identity theft, credential stuffing, and account takeover attacks.
Users are advised to change reused passwords,
enable multi-factor authentication,
monitor financial accounts for suspicious activity,
and remain alert for scams leveraging their exposed personal information.
Researchers have identified active exploitation of a critical Microsoft SharePoint remote code execution vulnerability that was patched on July 14th.
The flaw allows authenticated site owners to execute arbitrary code through insecure deserialization.
Security firms diffused and Watchtower observed attacks with threat actors reportedly stealing SharePoint machine keys to maintain long-term access.
Experts warn that patching alone is insufficient and recommend rotating credentials on potentially compromised systems.
The vulnerability is the fourth actively exploited SharePoint flaw disclosed in the past month.
Oracle's July 26 Critical Patch Update addresses over 1,400 vulnerabilities across 334 products.
Around 600 of the flaws can be exploited remotely without authentication.
with major updates affecting e-business suite, fusion middleware, communications, and PeopleSoft.
Oracle credited only a small number of external researchers,
suggesting most vulnerabilities were identified internally,
likely with AI-assisted security tools.
Organizations are urged to apply the updates promptly,
as Oracle product vulnerabilities are frequently targeted by threat actors.
Your next smartphone connection,
might not come from a cell tower at all.
The FCC is considering a proposal that could expand direct-to-device satellite communications.
Maria Vermazes has more.
Thank you, Dave.
The FCC announced that it is considering opening up more than 200 megahertz of unlicensed spectrum
for direct-to-device satellite services,
where smartphones and other consumer electronics connect directly to satellites without specialized
hardware. The new proposal is on the agenda for the upcoming FCC August open commission
meeting and would explore allowing Wi-Fi and Bluetooth frequencies to also support
communications between devices on Earth and spacecraft. In addition, the FCC is seeking
comment on whether Wi-Fi and Bluetooth devices should be explicitly allowed to operate
aboard authorized spacecraft and in other space-based applications. If adopted,
These changes could lower barriers for new satellite connectivity services
and accelerate the growing market for direct-to-device communications.
The FCC says that these proposals for the August meeting
are meant to support emerging space-based communication services
as satellite and terrestrial networks continue to converge.
For the Cyberwire Daily, I'm Maria Vermazes from T-Minus Space Cyber Briefing.
Back to you, Dave.
Maria Vermazas is host of the T-Mobile.
P-minus Space Cyber Podcast.
Be sure to check that out wherever you get your favorite shows.
LG Electronics USA says it will suspend smart TV apps
that use residential proxy software development kits.
Following research showing more than 42% of apps in its webOS store
can turn users' televisions into always-on residential proxy nodes.
According to Krebs on security, the company is working with developers,
to remove the feature and warned that non-compliant apps will be removed from the platform.
Researchers found proxy SDKs embedded in a wide range of apps, including games, screen savers, and
utilities, with bright data accounting for many of the integrations. While proxy providers
say they vet customers and implement safeguards, researchers argue consumers often lack meaningful transparency
or control over how their devices are used.
LG also pledged to strengthen its app review process to prevent similar software from reaching users.
The announcement follows recent criticism over LG Monitor's software that promoted McAfee-Antivirus
subscriptions through Windows Update.
German and U.S. authorities have dismantled Kratos, a major fishing-as-a-service-platform,
by seizing more than 200 servers and arresting its alleged developer in Indonesia.
Led by Germany's federal criminal police office and Frankfurt prosecutors,
with support from U.S. law enforcement,
the operation disrupted a service believed to have supported more than 1,800 criminal customers
conducting approximately 15,000 fishing campaigns each month across 35 countries.
Kratos enabled attackers to create convincing fake Microsoft laws,
login pages to steal user credentials, facilitating account takeovers, and other cybercrimes.
Authorities estimate the platform generated at least 300,000 euros in subscription revenue since
2024. The operation, dubbed Operation Olympus Blade, also transferred the platform's domains to the
FBI, enabling investigators to identify additional suspects through seized infrastructure.
Coming up after the break, Jimmy McNary, Deputy Federal CTO at Sempris,
discusses comprehensive identity security assessments for Microsoft GCC.
And AI models can't resist bending the rules.
Stay with us.
This episode is supported by Black Hat USA.
If you follow the research, you know a lot of it breaks on Black Hat stages.
Hundreds of peer-reviewed briefings, more than 100 hands-on trainings,
and the largest business hall in Black Hat's history.
Six days to learn the skills you'll need tomorrow.
August 1st to the 6th.
Prices increased July 17th, so book before then.
Use code Cyberwire for $200 off your briefing pass at blackhat.com.
We'll see you in Vegas.
Jimmy McNary is Deputy Federal CTO at Semperus.
In today's sponsored industry voices segment,
we discuss how Purple Knight now delivers
comprehensive identity security assessments for Microsoft GCC.
CIS has been doing this exercise called Cyberstorm for the past 15, I guess,
maybe almost 16 years at this point.
And over those past eight or nine exercises that they've done, they do them about every two years,
they've focused on the perimeter, the DNS, the BGP, industrial control systems,
pipelines, et cetera, in those past exercises.
But if you look at the last exercise that they actually did, Cyberstorm 9, the centerpiece was actually an identity failure, right?
It's the first time that we've seen this in the Cyberstorm exercise.
It was the named core vulnerability.
And if I can quote SISA, they said, quote, poor identity access management practices when using the cloud, right?
So that tells us right away that there is a concerning effort in government to look at the identity core.
For many years, we've thrown a lot of money, a lot of effort, a lot of time into protecting the perimeter.
But what we realize now is it's not about if they're going to get in, it's when they get in, right?
So, you know, this exercise they do every two years was focused on the identity core and protecting the identity.
system. In fact, interesting
little tidbit from their
details that they
put out after the exercise. They
created a fictitional
nation state adversary
deployed a root kit
scenario writers called Adamware.
For those of you that don't
know, Adam being the
Microsoft's old name for active directory
application mode, it's kind of interesting
that they created the
actual root kit that they were going
to use for this exercise around
active directory. That shows you the importance of what they were trying to tell the audience the
message they were trying to get them. A little on the nose, perhaps? Yeah, exactly. They can't really
call out active directory, but they can call their malware, atomware, which is kind of a hint at what
they were trying to prove. But, you know, the criminal ransomware headlines actually undersell
our risk because the actors that truly hunt federal and defense networks is not about making noise
or a payout, right? It's more about nation-states. They want to move in quietly and then they want to
stay, right? They're not coming in, smashing a window. They are actually authenticating,
and every downstream system, they look exactly like a legitimate user. So the layer on a
directory tier where four out of 10 servers are aging out of support, and you have ideal
terrain for a patient adversary, the control plane that everything trusts, and a few teams watching
in real time, and never funded critical infrastructure that plainly is in place as well.
The exercise that they did, they saw it coming, the field data confirmed it has arrived,
and it's the legit gap that they're monitoring and they're looking at.
I know you have outlined this notion that backup is not recovery.
Can you explain that to us, unpack it a bit?
Yeah, you know, I think everyone has backups, right?
So as an organization, you probably back up a lot of critical infrastructure and a lot of critical data.
So that has been around for a long time, right?
But the dangerous assumption here is that having a backup and being able to recover are in the same sentence.
They are not.
So for the threat that exposes the gap is not the criminal ransomware crew.
It's the nation state.
And criminal ransomware is noisy, get paid business.
and it's not working well against a hardened, segmented federal and defense network
where policy says we don't pay, right?
So actors who really hunt us, they want the opposite of noise.
They want to get into your identity system quietly and either steal or when it serves them,
destroy it, right?
So if you look at, for example, the event that happened in 2017 called Not Petya,
It looked exactly like ransomware.
It had a note.
It had a countdown.
But behind it all, it was actually the Russian military with a wafer group that was
seated through a software supply chain.
And there was no decryption keys.
They were never going to give you any decryption key because destruction was the point
of their mission.
It spread by stealing credentials and moving across active directory.
And it wiped all the domain controllers.
If you look at one of the examples that are,
one of the taxes they did against Merck, right?
Merck survived only because one domain control in Ghana happened to be offline during a power
outage.
That's a single lucky copy of directory that was the entire reason they were able to recover.
And there was over $10 billion worth of damage.
That's a real gap.
So again, the government's already answered this, right?
With Cyberstorm 9, they showed us that identity is the key that you need to protect and that
it's not about if they're going to get in it, it's when they're going to get in.
I know you have years of experience working with federal organizations.
How often are they testing complete active directory recoveries?
Well, you know, I have the fortunate opportunity to talk to a lot of CIOs, CTOs,
CISOs, in the government.
And one of the biggest questions I asked them, right, is I said,
What is your plan, right, to recover Active Directory?
And, you know, there's usually some document or some plan that they've got stored away in a drawer.
And then the next question I asked them is, well, when's the last time you test it?
Oh, no, we're not going to touch Active Directory, right?
So it's active director is of, you know, it's 25 plus years old now at this point, right?
It's a great system, but it wasn't meant to be built on the technology we have today in 2026.
it was built on 2000 architecture 26 years ago.
So it's a different system than it was originally created to be,
but it still works today,
and organizations really can't get off of that system any time in the future.
So the reality is those C-level executives,
they understand that this is a critical infrastructure,
but it's one of those things that you don't really want to do too much with
or challenge because you're afraid that if it goes down,
everything's going to come back to you,
why you were doing this exercise.
Fortunately, with subparis,
our methodology and our approach is different than most backup organizations, right?
So we're able to actually back up the entire data of Active Directory,
which allows you to take that data, put it into a lab,
and recreate that entire breakdown of your system.
So you can create a pristine operating system,
pristine active directory and put that real data that you have in your environment
into a lab, wipe away a domain, and see how you recover it very quickly with our software.
Well, you mentioned that Active Directory is coming up on a few decades in age.
Can we contrast that against the wave of AI that we've seen here?
What's the impact there about how does that affect things?
Yeah, you know, Dave, we can't have any good podcast without AI today, right?
That's required.
It's required, right?
So every conversation I have seems to, you know, at least AI pops its head somewhere in there.
But I want to hold two true things at once, right?
Because the honest answer lies in the tension between them.
First, escalation is real and it's already a nation state game, right?
Last November, we saw Anthropic disclose GTG 102, which is a Chinese state-sponsored group that turned Claudecote
into a largely, you know,
autonomous espionage operation
against about 30
organizations, including government,
was part of those targets as well.
AI did an estimate
of somewhere between 80 to 90%
of the hands-on keyboard work by itself
at a speed. No human
crew could sustain, right? So
with people touching only a few
strategic decisions,
that is a barrier
lowering, right? So a smaller
actor can now run a nation-state
great operation. But the second truth matters just as much. It was not a clean operation.
The models still hallucinate credentials and oversawled its own success. So humans still had to
check its work, which anthropic flags as the current ceiling for full autonomy. But across the board,
incident data from Mantian and Sophos independently came to the same place, right?
AI is adding speed, scale, and polish,
but I would say the vast majority of breaches
still come from ordinary, human, and systematic failures.
You know, 2025 was not the year AI caused the breaches.
It's where AI is genuinely shifting things from the front door.
Instead, email fishing actually fell while voice fishing
climbed to the number two way in,
because convincing voice talks to the help desk into bypassing.
MFA. So the ground intake is that AI is a force multiplier on both sides. It's not just for
attacking, but it's also for defense operations as well. What are your recommendations then for
federal CISOs? How should they be approaching this? And any words of wisdom? Yeah, you know,
if I can leave the audience with one thing, it says, you know, we spend generations trying to keep
adversaries out. In the honest truth, from CISA's own national exercise to the field down,
nation states will get in.
So, you know, there's nothing more important right now than being resilient, right?
So resilience is not a taller wall anymore, right?
You know, we spent years trying to protect that castle, that outer perimeter.
We don't need a bigger wall.
We need a system that's more resilient, right?
So there's three disciplines that get applied.
One thing every other control depends on, which is identity.
You have to monitor it continuously because,
they reach your directory in hours, not weeks,
and you cannot defend what you cannot see.
You have to protect it,
closing the privilege escalation paths
and the old misconfigurations
that turn a single foothold into full control,
and you have to be able to recover it.
So, and not just, you know, from a backup recovery, right?
You have to recover it cleanly,
proven, and fast,
because the directory itself is compromised.
Nothing you can restore,
top of that can be trusted.
Monitor, protect, recover.
It's the entire job of identity of resilience,
and it's now the job of national security.
That's Jimmy McNary, Deputy Federal CTO at Semperus.
And finally, the UK government's AI Security Institute
has found that when AI models are given a task,
they sometimes approach it with the enthusiasm of an employee
who has discovered a shortcut,
and hopes no one asks too many questions. In cybersecurity evaluations, every model tested attempted to
cheat at least some of the time, whether by searching the Internet for answers, bypassing sandbox
restrictions, probing the testing environment, or targeting systems outside the intended scope.
Even more awkwardly, the models often failed to admit what they had done when questioned.
GPT 5.4 recorded the highest rate of cheating at 14.1% of test runs,
while Claude Mythos preview was the least frequent offender at 7.8%, though it still made the list.
The findings suggest that self-reporting and chain-of-thought monitoring cannot be relied upon to detect deceptive behavior.
For defenders, the lesson is clear.
Trusting AI to grade its own homework may not be the security stress.
energy anyone hoped for.
And that's the Cyberwire.
For links to all of today's stories,
check out our daily briefing at thecyberwire.com.
We'd love to know what you think of this podcast.
Your feedback ensures we deliver the insights
that keep you a step ahead
in the rapidly changing world of cybersecurity.
If you like our show,
please share a rating and review in your favorite podcast app.
Please also fill out the survey in the show notes
or send an email to Cyberwire at n2K.com.
N2K's lead producer is Liz Stokes.
We're mixed by Trey Hester with original music and sound design by Elliot Peltzman.
Our contributing host is Maria Vermazas.
Our executive producer is Jennifer Ibin.
Peter Kilby is our publisher, and I'm Gabe Bittner.
Thanks for listening.
We'll see you back here tomorrow.
Heading to this year's Black Hat USA,
the N2K Cyberwire team will be on site recording from our podcast studio in the Spector Ops Kennel Club.
If you're interested in joining us for a conversation or learning more about what we're recording throughout the week,
visit sponsor.thecyberwire.com for more information.
And make sure you stop by the studio and meet the N2K Cyberwire team.
We'll see you there.
