CyberWire Daily - The blacklist boomerang.
Episode Date: August 28, 2026A judge rules the Trump administration illegally labeled Anthropic a national security risk. The White House moves to keep foreign technology out of U.S. power systems. OpenAI rallies a global cyber d...efense push as its own AI agents exploit a Linux vulnerability. Researchers uncover a new speculative-execution attack and hidden implants in Chinese-made routers. A fake voicemail campaign slips past email defenses. PaperCut faces an exploited zero-day. And ServiceNow patches three maximum-severity flaws in its AI Platform. Maria Varmazis and I look back at a decade of emerging threat actors and APTs. NSA sends out a covert save-the-date. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today, as we continue celebrating the CyberWire Daily’s 10th anniversary, Maria Varmazis and Dave Bittner look back at a decade of emerging threat actors and APTs. Enjoyed the conversation? Be sure to tune in Sunday for a special edition featuring the full discussion. Selected Reading Trump Administration’s Blacklisting of Anthropic Was Illegal, Judge Rules (The New York Times) White House bans foreign-made equipment for power generation over cyber backdoor concerns (The Record) Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge (SecurityWeek) A call for collective action on cyber defense (OpenAI) New type of attack can slip past the defenses in your computer’s processor (MIT News) Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign (Infosecurity Magazine) OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems (SecurityWeek) Hundreds of AI agents went rogue in OpenAI’s Hugging Face hack (POLITICO) PaperCut Releases Emergency Patch for Exploited Zero-Day (SecurityWeek) ServiceNow warns of three max severity security vulnerabilities (Bleeping Computer) Chinese Implants in the Supply Chain (VulnCheck) Exclusive: NSA to host a hacker reunion in bid to rebuild secretive unit (The Record) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
What's the one thing in business that's spreading as fast as AI?
AI risk.
Every new tool your team signs up for, every vendor that turns on AI features, every new integration, each one is an opportunity for something to go wrong.
And most security programs weren't built for AI's pace of growth.
Enter Vanta.
Vanta is the number one agenic trust platform.
form used by over 16,000 fast-moving companies like Ramp, Hercer, and Harvey to ensure they're
always audit-ready. And now Vanta is helping companies like yours watch for the risks that show up
between audits across your vendors, your AI tools, and your whole environment. The Vanta agent
works like a 24-7 GRC engineer in the background, finding issues, drafting fixes for you, and cutting
vendor assessment time by up to 50%. Whether you're a fast-growing startup or a global enterprise,
Vanta is here to help you automate your security and compliance and earn and prove trust.
Get started today at vanta.com slash cyber. That's V-A-N-T-A dot com slash cyber.
A judge rules the Trump administration illegally labeled Anthropica national security risk.
The White House moves to keep foreign technology.
out of U.S. power systems. Open AI rallies a global cyber defense push as its own AI agents exploit
a Linux vulnerability. The researchers uncover a new speculative execution attack and hidden implants
in Chinese-made routers. A fake voicemail campaign slips past email defenses. Paper cut faces an
exploited zero-day. Service now patches three maximum severity flaws in its AI platform.
Maria Vermazas and I look back at a decade of emerging threat actors and
APTs and NSA sends out a covert save the date.
It's Friday, August 28, 2026. I'm Dave Bittner, and this is your Cyberwire Intel briefing.
Thanks for joining us here today. Happy Friday. It is great to have you with us.
A federal judge has ruled that the Trump administration acted illegally when it designated AI
company Anthropic a national security risk and effectively barred it.
from federal work. Judge Rita Lynn said the government retaliated against Anthropic for constitutionally
protected speech after the company publicly objected to uses of its technology for mass surveillance
of Americans and autonomous lethal weapons. The dispute grew out of a $200 million dollar Pentagon contract
with a defense department arguing that a private company couldn't dictate government policy.
Defense Secretary Pete Hegseth subsequently labeled Anthropic a supply chain risk,
preventing military contractors and suppliers from doing business with the company.
Judge Lynn found little evidence supporting claims that Anthropic could sabotage its technology
during wartime, concluding that officials instead wanted to make an example of the company for criticizing the government.
Anthropic welcomed the decision and said it remains committed to working with Washington.
Washington on national security.
The Trump administration has issued an executive order
banning the acquisition or installation of certain foreign-made technology
used to operate the U.S. bulk power systems, citing cybersecurity and supply chain risks.
The order warns that equipment controlling high-voltage transmission lines,
substations, generating stations, and other critical infrastructure
could contain digital back doors, enabling foreign governments to remotely interfere with operations.
The defense, commerce, and energy departments will review transactions,
identify potentially risky equipment already in use, and develop plans to isolate,
monitor, or replace it. Officials also have 120 days to establish regulations
and identify countries warranting particular scrutiny.
The move follows a series of cyber incidents targeting,
critical infrastructure in the U.S. and abroad, amid growing warnings that AI could make
attacks on energy, water, and other essential systems easier to conduct and more sophisticated.
Nearly 130 organizations across cybersecurity, technology, finance, and other industries
are calling for a coordinated global push to strengthen cyber defenses as artificial intelligence
makes attacks more capable and widespread.
The initiative, led by OpenAI and backed by companies including Microsoft, Google, Cisco,
Crowdstrike, and Anthropic warns that existing vulnerabilities,
misconfigurations, and weak authentication leave critical infrastructure increasingly exposed.
But the group says AI can also give defenders powerful new tools for identifying and fixing weaknesses.
organizations are urged to prioritize their highest risk vulnerabilities,
continuously test defenses, and share proven threat intelligence.
Governments are asked to fund under-resourced critical infrastructure
and coordinate internationally, while AI developers are encouraged to provide defensive tools and support.
OpenAI is also offering subsidized access to its daybreak cyber models
and AI-assisted security testing programs.
Separately, OpenAI says some of its AI agents exploited a known Linux kernel vulnerability in July,
escalating privileges inside the company's own environment.
The agents identified the weakness, retrieved and customized a public exploit,
gained root access to an underlying worker node, and moved laterally through the connected environment.
The incident was separate from agents hacking, hugging face, and exploiting a J-Frog artificial,
factory zero day. SISA has since added both vulnerabilities to its known exploited vulnerabilities
catalog recommending organizations patch by August 30th.
Researchers at MIT have identified a new class of speculative execution attacks that can
bypass protections designed to stop specter-style data theft. The technique called Tontau
exploits a tiny timing gap between when processors clear their
branch prediction machinery and when those predictions are actually used. The researchers developed
an interrupt injection technique that precisely triggers routine processor interrupts during that window,
contaminating the prediction machinery again. Test produced mispredictions on multiple generations
of Intel and AMD processors and defeated several existing defenses. On an AMD system running a
current Linux kernel, the researchers demonstrated an exploit capable of reading protected memory
and in some attempts extracting the system's root password hash file. AMD has released a mitigation
available through operating system updates. The researchers say Intel defenses may require
different approaches because some fixes could inadvertently make attacks more reliable.
A two-month fishing campaign sent more than 26,000 malicious.
voicemail-themed emails to over 5,500 organizations, according to email security vendor Inki.
The operation used SVG attachments to conceal obfuscated JavaScript and evade email defenses.
The attackers disguise the attachments as text files, even though SVGs can execute JavaScript.
Once opened, the code reconstructed hidden strings and contacted a remote endpoint.
The message also impersonated recipient's own domains and frequently personalized subject lines
using part of the recipient's email address.
Despite the campaign relying largely on a single template, Microsoft's native spam filtering
classified 75% of the messages as not spam, according to Inky.
Researchers characterize the campaign as broad spray fishing rather than targeted spearfishing,
combining familiar voicemail lures, internal sender impersonation, and SVG smuggling to slip executable browser content past defenses.
Papercut is warning customers that attackers are exploiting a zero-day vulnerability in its NG and MF print management products.
The company released emergency patches and recommends restricting application servers from Internet access.
Papercutt says confirmed customer incidents include a suspicious file and deleted or truncated logs,
potentially indicating attempts to hide activity.
Huntress says the vulnerability could allow an unauthenticated attacker to manipulate trusted
configuration and execute arbitrary Java code.
Roughly 1,000 papercut instances remain exposed to the internet.
Service Now has patched three maximum severity vulnerability.
vulnerabilities in its AI platform that could allow unauthenticated attackers to execute code,
escalate privileges, or access and modify data through SQL injection. The flaws can be exploited
in low-complexity attacks without user interaction. Service now also fixed a high-severity
sandbox escape vulnerability that could enable remote code execution. The company says it hasn't
observed malicious exploitation and is urging customers with self-hosted instances to promptly update.
Researchers at Volnchek say they found two previously undocumented implants embedded in firmware
on ZBT-made routers sold under multiple brands worldwide.
Dark Lantern exposes an unauthenticated internet-accessible backdoor capable of executing commands as root,
while Speaking Stone phones home to command and control infrastructure and can execute commands,
hijack DNS, steal ISP credentials, and establish reverse SSH tunnels.
Researchers identified 203 internet-facing dark lantern devices across 22 countries.
After registering an abandoned Speaking Stone backup domain,
Volncheck received beacons from 392 devices,
almost all in China.
The implants were discovered on an $88 router sold in the U.S. under the Deep Orange brand.
Volnchek traced the underlying ZBT hardware to numerous white-labeled products internationally,
although it cautions that not every ZBT-derived device contains the implants.
Coming up after the break, my conversation with Maria Vermazas,
looking back at a decade of emerging threat actors and APTs,
and NSA sends out a covert save the date.
Stay with us.
AI is transforming the way organizations work,
but what happens when we rely on it so much
that we begin losing the human judgment and context
that make good decisions possible?
I recently sat down with Johnny Hand from Trend AI,
and he made an important point about what we risk
when we offload too much AI.
We risk our most valuable resource,
which is our human context, our creativity, our ability to understand
contextually, like in the environment, those things.
Those are really hard challenges for AI to tackle.
If you're trying to separate AI hype from operational reality,
I think you'll really enjoy this conversation.
Listen now at explore.
TheCyberwire.com slash trend AI.
As we celebrate our 10th anniversary this year at the Cyberwire Daily,
Maria Vermazas and I have been looking back at a decade of activities and interesting topics.
Here's the latest.
As you look back on the last 10 years, what do you think about changes in the threat actor landscape?
Just super high level.
Well, I mean, I think it was about 10 years ago that this public attribution of nation-state activity became a lot more common.
and the APTs became recognizable brands rather than mysterious anonymous attackers.
And I think we saw that governments and vendors and researchers all became more willing to publicly attribute these campaigns.
And then we also saw the emergence of coordinated public advisories in international cooperation.
So, you know, to me, my education on this is I was getting started on the cyberwire and getting up to speed and had the good fortune of having folks around me who knew a lot more than I did and had a lot more experience with these things.
How could you not love the bears? Fancy bear, posy bear, right? There's Russian APTs. What a great way. It's kind of like learning you're not.
nursery rhymes, you know.
What, they're, there's the three bear, you know, they're cuddly, they're soft.
How dangerous could they possibly be?
Right.
So that was my intro to all this.
Yeah.
I'm curious as the two really interesting things you mentioned, one is about how attribution
changed from we don't do that to, oh yeah, we're going to attribute now.
So I wanted to ask you about that.
And then I, well, let's get into that one first.
Because that to me, over the last 10 years, is just a, a,
seismic change. I remember when that was considered a super no-no. You just do not attribute.
And now I think there's, correct me if I'm wrong, you would know better than I would, but it seems
like there's no hesitation to do that now. What do you think? What's your read on that?
Well, some organizations still don't do attribution. I think like Dregos, you know, the industrial
control or the organization that helps protect industrial control systems, they kind of have it
is a policy that they don't do attribution.
They don't think it matters.
I guess what I wonder is how much of this is marketing, right?
Because when we go to the RSA conference and we see vendors who have big giant superhero-looking statues of the APTs,
it becomes a way to help market your defenses against them.
The adversary isn't a big, blurry, fuzzy blob on the other side of the world.
No, that's fancy bear.
No, that's, you know, so now we have the blizzards.
And for a while, they had names based on their countries.
You know, famously, the joke around the office was if there was ever a Canadian one,
it would be apologetic beaver.
Yeah, you kind of understand from the, the,
the Infosec company marketing team point of view, that they're probably relieved they don't have
to try and market a CVE or, you know, some script kitty's terrible elite speak name. Like we have
fancy bear or whatever we can use it. For them, the job is easier now. There's still plenty of that.
There's no shortage of elite speak and, you know, you've heard me complain more than once that
that no one thought that someone in the world would have to pronounce this name when they named it.
and unfortunately, you know, sometimes that burden falls on me
to try to figure out how to pronounce a string of letters and numbers.
I often come to you.
Because you have, don't I?
You have more experience.
I was porched in those fires, it's true.
Yes, you're much better at decoding.
Maria, what do you think they're going at here?
Most of the time, you get there before I do.
My spidey nerd sense is, you know, tingling.
Right.
Like this kind of thing.
Yeah, I mean, a lot of the times it wasn't meant to be read out loud.
That's very true.
It's just the fact somebody thought of it at three in the morning and was like, that sounds cool.
Yeah, yeah.
I was doing an interview just earlier today about this malware group called Goddamn.
That's the name of the group.
God damn.
We're going to get in trouble.
Someone's going to yell at us for saying that on this show.
Well, when we mention them on the Daily Podcast because it's a family show, we refer to them as the gosh darn ransomware group.
Right.
Which, you know, doesn't give them quite the street cred that they have.
have with their real name. But the person I was talking with today, the researcher, we both
agreed that maybe it's gotten to the point where these groups are just trying to punk us because
they know we have to say these names out loud. And I wonder, you know, how soon are we going to
just get the most, I don't know, disgusting vulgar names just because somebody, again, somebody has
to say it out loud. Yeah, somebody is going to be at a board meeting saying, so we got poned by this
bleep-de-bleep group. Right. You know, it's just, yeah. Yeah. Yeah. Yeah. Yeah.
What do you think has led to not just attribution, but also this coordinated naming and shaming?
I mean, is this all coming from, you know, federal governments doing a fantastic job with the private sector?
Like, what do you attribute to this?
I think it's a big part of it.
I think there's been better intelligence sharing over the years between, well, amongst government organizations, but also between the government and the private sector.
I also think we've got much better confidence in attribution than we ever did.
We know what to look for.
We know the signs of one organization or another.
So I guess the kind of table stakes when it comes to attribution has gotten much more routine.
And I think more than ever people see strategic value in exposing these adversary operations publicly.
They see it.
And I don't think they always felt that way.
I think it was spy versus spy tradecraft.
I won't say there was honor among thieves,
but there were things that were not spoken of
because you wanted to keep your cards close to your vest, I suspect.
Yeah, no, I could see that.
And I'm wondering if you noticed a shift over the last 10 years
of when stories were less about really tactical level,
this specific thing has happened,
this is what you need to do to mitigate,
versus there is a set of actions
that is now happening based on this nation-state group
or that sponsored group or, you know,
we're talking much more strategically out loud now.
Have you been noticed, you sort of touched on that.
I'm just wondering if you've been noticing that becoming,
I don't know if it's the majority of what you're seeing now
or just more of it.
I'm just curious if you've noticed a shift.
I would maybe a way to categorize
is that we have definitely seen the professionalization of APT operations over the past 10 years or so.
And so, you know, it's an interesting question to ask.
Have the attackers become dramatically better or have they simply become more disciplined?
I would say it's a bit of both, but a lot of the innovations have been organizational rather than purely technical.
They're running like a business.
They have marketing teams.
There's the hardcore coders who are getting this stuff done, but there's a whole business side to this now.
They're teams.
They're not just individuals, even just for the commercial ransomware operators.
So I think mature software development practices, we're seeing those outside, I'm sorry, mature software development practices,
we're seeing those both inside and outside of espionage operations.
Dave, I know I've been taking your brain about this.
So I'll leave you with one last question, and this is the looking-ahead question.
I wonder where you think the next threats, the next APTs, the next threat actor groups,
where are those going to come from?
Is it going to still be nation states, or are we moving past that or evolving into something worse?
Well, I think it's probably going to be more of the same for the next few years.
I think the APTs are going to adapt to new technologies,
and of course the big new technology is agentic AI.
Oh, I tried not to bring it up in that.
Oh, sorry.
Wow, we were so close.
So close.
So close.
So the last question.
I ruined it.
And I think that's largely a velocity issue, right?
Stuff's just going to come at us faster and more consistently with more vigor.
So the defenders are going to have to run at a higher speed.
But I think the defenders are going to continue to do what they do.
They're going to improve the collaboration.
They're going to improve the visibility.
And hopefully these AI systems will do a better job of blocking and tackling along the way.
But I think in the end, this contest between the attackers and the defenders,
it's really about continuous adaptation rather than decisive victories.
It is cat and mouse, right?
and I don't think it's not going to end anytime soon.
I think the players around the world are going to continue this blend between espionage and
statecraft and doing things for profit.
I mean, look at North Korea, right?
They have an incentive to make money that's different from a lot of the other nation states.
So they're kind of an edge case.
But there are plenty of nations out there who could use a few more bucks in their coffers.
And this is a pretty easy way to come out.
the big rich nations of the world.
I think that blending is going to continue.
Yeah.
Yeah.
Yeah.
Well, anything else do you want to leave the audience with Dave?
Or should we close out?
I think it just this notion that while the tools are evolving,
that the fundamentals of espionage, of trust and resilience,
those are the things that continue to define the landscape.
And I think that's what the future holds for us.
I don't think that's going to change.
So will it evolve, for sure.
But I think we've got a pretty good idea
where we're headed now when it comes to these things.
I hope. I hope. We'll see, right?
Here's hoping.
Well, Dave Bittner, the host of the CyberWire Daily.
Thank you, as always, for talking with me.
And again, congratulations on a wonderful 10 years.
No, thank you. The pleasure is mine, as always.
And finally, the NSA is throwing a reunion for alumni of tailored access operations,
its famously secretive hacking unit, and the homecoming has a practical purpose, recruitment.
Hundreds of former TAO hackers, developers, and analysts have been invited back to Fort Meade for a tour,
some nostalgia, and a pitch to return.
The unit, recently reorganized again, has seen years of turnover.
compounded by broader workforce cuts.
The reunion itself has been organized with unusual openness
for an organization once nicknamed the NSA inside the NSA.
Alumni gathered in an invitation-only signal chat
called terminated async operations,
swapping inside jokes and carefully unclassified memories.
That setup has raised a few eyebrows among former members
who note that operational security officers
may not find the arrangement quite as charming.
Still, many alumni retain active clearances and specialized skills.
For an agency trying to rebuild elite offensive capabilities,
the old class roster may be a very efficient recruiting database.
And that's the Cyberwire.
For links to all of today's stories,
check out our daily briefing at thecyberwire.com.
Be sure to check out this weekend's research Saturday,
and my conversation with Crystal Moran,
senior cybersecurity strategist, and Michael Clark, senior director of threat research at SISTIG.
The research is titled LLM Jacking Evolved.
Attackers are using stolen AI compute to build offensive agentic tools.
That's Research Saturday. Do check it out.
And hello, Maria Vermazza is here.
On Sunday's T-minus space cyber briefing, I'm speaking with Nick Cohen of the Aerospace Corporation
about all of the space cyber activities that took place at this year's depth
That is Sunday on T-minus. Don't miss it.
We'd love to know what you think of this podcast.
Your feedback ensures we deliver the insights
that keep you a step ahead in the rapidly changing world of cybersecurity.
If you like our show,
please share a rating and review in your favorite podcast app.
Please also fill out the survey and the show notes
or send an email to Cyberwire at n2K.com.
N2K's lead producer is Liz Stokes.
We're mixed by Trey Hester with original music and sound design
by Elliot Pelksman. Our contributing host is Maria Vermazis. Our executive producer is Jennifer Ibin.
Peter Kilpe is our publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here
next week.
