CyberWire Daily - The feds flip the script.

Episode Date: August 26, 2026

The U.S. disrupts a Chinese hacking operation blamed for intrusions at several sensitive government agencies.  CISA says more than 100 water systems were targeted in July. Attackers exploit a cri...tical Gitea flaw, while malicious pages masquerade as Cloudflare verification screens. Cyber insurance claims get costlier, and AI agents break out of their sandboxes. Boston Scientific battles a cyber incident. Plus, a new standard tracks AI agent activity, criminals target stolen iPhones, and an alleged money mule is charged in a $7.5 million scam. Our guest is Stephen Hilt,  Sr. Threat Researcher at TrendAI,  on the risks facing data centers.  Some breach data doesn’t quite measure up. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today’s Industry Voices, we are joined by Stephen Hilt,  Sr. Threat Researcher at TrendAI discussing the cybersecurity risks facing data centers and the thousands of internet-exposed industrial control systems that could leave them vulnerable to attack. And if you enjoyed this conversation, be sure to check out the full interview here.  If you’d like to hear more on this topic from TrendAI, you can check out this recent episode of the AI Security Brief podcast that focuses on data center security. Guest Mark Houpt, CISO at DataBank, joined hosts Johnny Hand and Dustin Childs to explain why securing the AI era starts with protecting the physical data centers that power it—and why proven security fundamentals still matter against rapidly evolving threats. AI Security Brief podcast publishes every other Thursday on the N2K CyberWire network. Subscribe today! Selected Reading China-sponsored hacking platforms seized by US, Justice Department says (Reuters)   CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks (SecurityWeek) Hackers now exploit critical Gitea flaw in code injection attacks (Bleeping Computer) Hackers abuse npm mirrors to host phishing redirect pages (Bleeping Computer) Average Cyber Insurance Losses Increase Despite Fewer Claims (Infosecurity Magazine) VMs won't contain cyber-capable agents (Trail of Bits) Boston Scientific hit by cyberattack, global operations affected (Reuters) Linux Foundation Introduces TRACE Standard for AI Runtime Evidence (Infosecurity Magazine) AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes (Bleeping Computer) Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly (The Record) Trump signs memo to help drastically boost US commercial space launches (Reuters)  A Cautionary Tale About Data Breach Claims, Verification and Carhartt (Troy Hunt) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. What's the one thing in business that's spreading as fast as AI? AI risk. Every new tool your team signs up for, every vendor that turns on AI features, every new integration, each one is an opportunity for something to go wrong. And most security programs weren't built for AI's pace of growth. Enter Vanta. Vanta is the number one agentic trust platform.
Starting point is 00:00:36 form used by over 16,000 fast-moving companies like Ramp, Hercer, and Harvey to ensure they're always audit-ready. And now Vanta is helping companies like yours watch for the risks that show up between audits across your vendors, your AI tools, and your whole environment. The Vanta agent works like a 24-7 GRC engineer in the background, finding issues, drafting fixes for you, and cutting vendor assessment time by up to 50%. Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today at vanta.com slash cyber.
Starting point is 00:01:19 That's V-A-N-T-A dot com slash cyber. The Justice Department says the U.S. has disrupted a Chinese hacking operation blamed for intrusions at several sensitive government agencies. Sessa says more than 100 water systems were targeted in July. Attackers exploit a critical Git-T-flaw, while malicious pages masquerade as cloud-flare verification screens. Cyber insurance claims get costlier, and AI agents break out of their sandboxes.
Starting point is 00:02:05 Boston Scientific battles a cyber incident. A new standard tracks AI agent activity, criminals target stolen iPhones, and an alleged money mule is charged on a $7.5 million scam. Our guest is Stephen Hilt, senior threat researcher at Trend AI, on the risks facing data centers. And some breach data doesn't quite measure up. It's Wednesday, August 26, 2026. I'm Dave Bittner, and this is your Cyberwire Intel Briefing.
Starting point is 00:02:49 Thanks for joining us here today. It is great as always to have you with us. The Justice Department says the U.S. has disrupted a Chinese hacking operation blamed for intrusions at several sensitive government agencies, including the Justice Department, NASA, the Federal Reserve, and the U.S. Senate. Authorities seize domains associated with two hacking platforms, known as Q-Scan and QT router, that were allegedly used in the campaign. The Chinese embassy in Washington did not immediately comment.
Starting point is 00:03:35 Beijing has routinely denied. responsibility for cyber attacks attributed to China. Sisa says more than 100 internet-exposed water and wastewater systems were targeted in cyber attacks in July, the first federal accounting of the recent campaign scope. The attack, linked to Iranian threat actors, targeted operational technology, often programmable logic controllers connected directly to cellular modems. At least a dozen states appear to been affected, though the attacks cause no significant disruption. SISA is using the campaign to urge critical infrastructure operators to reduce their internet-facing attack surface.
Starting point is 00:04:19 The agency recommends identifying exposed systems, removing unnecessary connections, changing default passwords, applying security updates, and routing required remote access through secure gateways with multi-factor authentication. Sisa says PLCs and other industrial control systems exposed through cellular modems or the public internet have enabled recent malicious activity against the water sector. Elsewhere, Sisa says attackers are actively exploiting a critical vulnerability in Git-T, the self-hosted software development platform. The flaw allows users with repository right access to execute arbitrary shell commands with the privileges of the GitT service account. Because GitT enables self-registration by default, an unauthenticated
Starting point is 00:05:11 attacker could register an account, create a repository, and exploit the vulnerability without existing credentials. GitT patch the flaw in a recent version. Shadow Server currently tracks nearly 5,000 internet-exposed Git-T instances, though it's unclear how many remain vulnerable. Sisa has added the flaw to its known exploited vulnerabilities catalog and ordered federal civilian agencies to remediate it by August 28th. Reported attacks have deployed cryptocurrency mining malware on unpatched servers. Threat actors are abusing NPM and its mirrors to host malicious HTML pages disguised as cloud flare verification screens. Researchers at OX security identified 24 packages using the technology. unlike traditional NPM supply chain attacks, the packages don't infect developers who install them.
Starting point is 00:06:10 Instead, attackers use NPM as storage and services such as unpackaged to render the malicious pages from legitimate domains, potentially helping them evade security controls. The pages embed Cloudflare's legitimate turnstile CAPTCHA, but obfuscated JavaScript redirects visitors, regardless of whether verification's... succeeds. Some versions retrieve encrypted destination URLs from a separate service, allowing attackers to change redirects without republishing the NPM package. Researchers warn those destinations could lead to phishing pages or malware, and that malicious files may remain accessible through mirrors even after NPM removes the original packages.
Starting point is 00:06:57 Each Wednesday, we feature the latest from our T-minus Space Cyber Podcast Team. team. Maria Vermazas is out this week, so Ethan Cook files this report. Thanks, Dave. Last Friday, President Trump signed a new memo that looks to dramatically increased support for commercial space launches. The White House signals that it wants to enable at least 1,000 launches and re-entries annually by 2030, which is a significant increase from the 178 launches conducted in 2025. The memo also directs NASA to facilitate commercial transportation to the moon and commercial robotic access to Mars. The memo called on agencies to incentivize co-development for space transportation infrastructure,
Starting point is 00:07:39 expedite permitting, and environmental reviews, and ensure necessary wireless spectrum access for space launches. Lastly, the administration tasked agencies with identifying a new federal reentry site within 90 days. For the T-minus space cyber briefing, this is producer Ethan Cook. Back to you, Dave. Be sure to check out the T-minus Space Space Space. cyber podcast wherever you get your favorite shows. Cyber insurance claims are getting more expensive for larger companies, even as fewer claims
Starting point is 00:08:11 are being filed. Chubbs' 26 Cyber Claims Report found that average claim cost in 2025 rose 22% for U.S. middle market companies and doubled for large firms. The U.K. and Europe saw similar increases of 34% and 90%. percent, respectively. Chubb attributes the rising severity largely to data breach and privacy legislation, along with higher business interruption costs. U.S. claims were substantially more expensive, reflecting significant third-party litigation
Starting point is 00:08:47 expenses not seen in the U.K. and Europe. The insurer also warns that expanding privacy laws and ransomware-related data leaks are increasing companies' litigation exposure. In the U.S., even administrative fees can be substantial. A case involving 10,000 claimants could generate more than $10 million in non-refundable fees before its merits are considered. A researcher from Trail of Bits testing GPT 5.6 cyber found the AI agent could repeatedly escape a virtual machine intended to contain it. The agent first exploited, recently disclosed host-kernal vulnerabilities, then combined flaws in a networking library. After the researcher rebuilt the environment and its dependencies from current upstream code,
Starting point is 00:09:42 the agent spent roughly 12 hours autonomously researching the attack surface and ultimately assembled a reliable escape chain involving several previously unknown vulnerabilities. The experiment suggests convention. VMs may no longer provide sufficient isolation for highly capable cyber agents. The researcher recommends minimizing attack surface, rapidly applying upstream updates, restricting network access and privileges, and closely monitoring agent activity. Firecracker proves substantially more resistant in additional testing, although the agent could still hard-lock the host through already patched Linux kernel flaws. Boston Scientific says a cybersecurity incident is disrupting global operations,
Starting point is 00:10:31 including information systems used to process and ship customer orders. The medical device maker detected the incident August 25th and brought in third-party cybersecurity specialist to investigate and contain the threat. Some business operations are expected to remain affected during recovery. Boston Scientific says it has not determined whether the incident is likely to have a material impact. The full scope and nature of the attack remain under investigation. The Linux Foundation is backing Trace, a new open standard designed to provide temper-resistance evidence of what AI agents actually do.
Starting point is 00:11:12 Developed by confidential computing vendor opaque with support from AMD, Intel, Microsoft, and Technology Innovation Institute, Trace creates hardware-backed cryptologically verifiable records of an agent's runtime environment, software, policies, data classifications, and tool use. The specification combines existing Internet standards with confidential computing technologies, including AMD's secure encrypted virtualization, to produce portable evidence that organizations can independently verify across infrastructure providers. The Linux Foundation will provide vendor-neutral governance, with technical work hosted by the Coalition for Secure AI.
Starting point is 00:11:59 Trace addresses a growing concern as autonomous agents enter production. Policies and sandbox configurations can define intended behavior, but don't necessarily prove which controls remained active or what the agent actually did. Researchers at SOC radar have uncovered Anonymous Kit, a Fishing-as-a-Service platform designed to help criminals, unlock stolen Apple devices and bypass activation lock. Active since early 2024, the service is linked to 506 domains
Starting point is 00:12:34 and 168 reseller storefronts. Anonymous kit extracts owner contact information from stolen devices and targets victims through email, SMS, WhatsApp, and AI-generated phone calls. Messages impersonate Apple, using accurate device details to convince victims. their missing iPhone has been found. Fake Apple pages then solicit device passcodes, Apple account credentials, and two-factor authentication codes. In some cases, an AI voice agent
Starting point is 00:13:07 posing as Apple support assists with a deception. Successful attacks can allow criminals to access personal data, remove devices from FindMy, and resell them. Compromised accounts could also expose iCloud backups, keychain passwords, and corporate information. A 21-year-old Indian National is facing federal charges for allegedly helping overseas scammers steal more than $7.5 million from at least nine elderly victims in New York and New Jersey. Prosecutors say J. Sunhabarthi Goswamy served as a money mule, collecting cash, gold, and gift cards from victims deceived by scammers. impersonating law enforcement or government officials.
Starting point is 00:13:57 Authorities allege Goswami received victim addresses and code words, collected the assets, and transported them for eventual transfer to India, earning about $90,000. After an earlier arrest in December 2025, prosecutors say he continued participating in the scheme. Following another arrest in August, Goswami allegedly fled to Keky, Canada and attempted to fly from Toronto to Doha.
Starting point is 00:14:28 Canadian authorities arrested him at the airport, and he is awaiting extradition to the United States. Coming up after the break, my conversation with Stephen Hilt, senior threat researcher at Trend AI, on the risks facing data centers. And some breach data doesn't quite measure up. Stay with us. AI is transforming the way organizations work. But what happens when we rely on it so much that we begin losing the human judgment and context that make good decisions possible?
Starting point is 00:15:22 I recently sat down with Johnny Hand from Trend AI, and he made an important point about what we risk when we offload too much AI. We risk our most valuable resource, which is our human context, our creativity, our ability to understand context, contextually, like in the environment, those things. Those are really hard challenges for AI to tackle. If you're trying to separate AI hype from operational reality, I think you'll really enjoy this conversation. Listen now at explore.thecyberwire.com slash trend AI. Stephen Hilt is Senior Threat Researcher at Trend AI. In today's sponsored industry voices conversation, our discussion from Black Hat about the cybersecurity risks facing data centers.
Starting point is 00:16:24 We are continuing our conversations here at Black Hat 2026, and joining me is Stephen Hilt. He is a senior threat researcher with Trend AI. Stephen, thanks so much for taking the time for us today. Thanks for having me. So I want to talk to you about the presentation that you gave.
Starting point is 00:16:40 This was at DefCon, about exposed data centers, bypass IT security, crank up the heat. Before we get into the specifics, what made you decide to take on this topic? So it's kind of an iteration of things that I've paid attention to for the last, you know, 15 years or so with exposed control systems. And I think right now is very timely, not planned, but with the
Starting point is 00:17:03 Iranian and CISO alerts and things around that about critical infrastructure being attacked, it's actually timely because this is just another avenue that needs to be addressed. Well, I do no question that data centers are in the news these days, for better, for worse, our need for them, but also communities aren't always happy when they're being built too close by. What are some of the specific vulnerabilities that you talked about in your presentation? So there are vulnerabilities that have existed.
Starting point is 00:17:35 It's just exposed building automation systems. What we were able to, what we've done, and we've done in previous research for other types of systems like exposed oil and gas, is in this case we looked at data centers, And the way we did that was we tried to triangulate where the data center is. We found some publications that helped us guide us into that direction. And then we were able to search online footprints of what's exposed within that region
Starting point is 00:18:04 and reducing it down by size and numbers, removing false positives to say the likelihood that this device belongs to that control system or to that data center. That's pretty high. So let me just back up there. So what you're saying is, correct me if I'm wrong, your goal was to figure out first where a data center is. Can you use publicly available information to figure that out? Was that the first step? Yeah, there's a lot of news articles. As you mentioned, data centers are a very hot topic right now.
Starting point is 00:18:36 So we leverage some of that information that's coming out where people and other journalists have identified where all the data centers are, specifically in our case, through this research is in the U.S. There is other listings that exist for other countries as well. Okay. So we took that and then based off of that information, started reducing and searching online footprints. Well, let's go through that process together. Can you walk us through that journey?
Starting point is 00:19:06 Yeah. It's actually we filed a patent on it a couple years ago, and it was granted. So it is called geostocking. And the reason why we want to talk about is people need to do it. So the idea would be we did it for data centers, but you should be able to do this on your locations to find things that are potentially exposed.
Starting point is 00:19:28 And in that process, we lay out how to do that for your own facilities to map around what's around it. Okay. And then you as an owner should know what that looks like your data, what looks like your systems. It's a way to help fight shadow IT and get
Starting point is 00:19:51 better at knowing what is your assets. Is this applicable to manufacturing facilities, enterprise IT? Does it matter the vertical? It does not matter. That process doesn't matter. We're just
Starting point is 00:20:07 choosing data centers in this case because of a hot topic. I think as you even mentioned earlier, they're hot topics. I like to look at data centers as the new not in my backyard. Yes, yes. You see those signs posted on social media all the time about the data center. No.
Starting point is 00:20:28 Yeah, yeah. It's the new not in my backyard. So it is a hot topic for lots of reasons, it's not just cybertext, but also if you could find where data centers are, you know, people may take interest. physically of where they are. So having that information out there, also people need to know that that information does exist, that we were able to do that.
Starting point is 00:20:51 So maybe we need to address that as well. Well, can we dig into some of the specifics that you found with the data centers? So what kind of information were you able to uncover and what are the implications of it? So nothing's out of the ordinary Backnet and Niagara, Fox, which are two building automation protocols, are easy to identify online.
Starting point is 00:21:12 Okay. If it's exposed, you can find it. How to, now what you can do with those is you can control the building. So the touch panels, how, you know, the sensors in each room telling you what temperature it is, the HVAC to the fire suppression systems, all of that is controlled through building automation protocols. So if that's exposed, then we can find that any building, we could control it remote. We could make new set points raise the temperature, hence the crank up the heat. Right.
Starting point is 00:21:48 And that doesn't apply that applies for everything, including data centers, because they have lots of cooling, lots of, you know, power requirements. All those types of things can be affected through the building automation system. And what is more striking is, in a lot of cases, when you are a tenant in a building and not the owner, It's not your building automation system. So it is the owners, not the tenants, to control. So that's where that conversation needs to be happening, is CSOs need to be talking to their facilities and say we need to make sure these things are online.
Starting point is 00:22:32 Right. The owners issued us these key fobs. The owners are timing the HVAC for these times of day, or those sorts of things. And so the example in our case is data systems. because they're ultra-critical. And, you know, if you raise the heat to data center, servers shut down and protect themselves. Right.
Starting point is 00:22:49 So, in theory, could we raise the heat up and make it look like it was never raising? Yeah. Because you can... So you can have the sensors report false information, for example, so the heat's going up, but nobody knows it? You could, yes.
Starting point is 00:23:06 Okay. And you say you could... Could you? Yes. Okay. You understand my question? Okay. We didn't do it.
Starting point is 00:23:17 Right. But it has been done in the past. I see. I see. So based on this information, what are your recommendation? What did you say to the folks in the audience, the steps they can take to mitigate these things? As always, asset inventory is very critical,
Starting point is 00:23:35 including inventory that is not necessarily your control, but controls what affects you. We need to think of like that, where we are out there profiling everything that controls and affects our day-to-day operations. What about the concerns from, say, activists? I remember a while back I interviewed somebody who worked in a controversial,
Starting point is 00:24:11 manufacturing sector. And I never really thought about it. He said one of the things as the CISO of his company was keeping an eye on the media because sometimes people came to their facilities to protest. And he had to kind of keep an eye on
Starting point is 00:24:26 if people had ill intent. It seems to me like part of what you're talking about here is if you can get this information, then people who have ill intent probably could as well and use it to their advantage. Yeah, it doesn't have to be always just, you know, as I mentioned earlier,
Starting point is 00:24:41 with everything going on as nation states. It doesn't have to be that way. It can be activists. It can be cyber criminals who have, you know, just ill intentions, not necessarily espionage or they just purely want to destroy things. And that's the whole not in my backyard kind of approach, which is we do need to pay attention to our exposed assets for those types of purposes. What do you suppose the future looks like for this?
Starting point is 00:25:09 As the information like you've discovered here and you're sharing with the folks out there, do you think we're going to see different approaches to how people handle building automation? Yeah, I hope so. The biggest thing is I want people to, much like all the other things we've been saying for the last 10, 15 years,
Starting point is 00:25:28 is we need to get these things offline, not on the internet. We need to protect them, and we need to be talking to our building owners to make sure that, they are meeting our requirements for security. Where does a typical building owner sit in this? Are they blissfully unaware that these are even possibilities?
Starting point is 00:25:52 Or are these things on their radar? I don't know. To answer you, honestly, I don't know. I guess it depends on who they're providing to is part of it. I think that would all depend on building owners, how many tenants they have. Maybe you're the only tenant, because you have a multi-floor data center.
Starting point is 00:26:11 Right, right. You may be able to talk to them better than, you know, one that has, you know, you have a small data center for your own purposes, and, you know, then you have, you know, all other tenants that you have to deal with as well. One of them is the reason why it's online. I don't.
Starting point is 00:26:33 You know, it's one of those things that every scenario is different, so you wouldn't know the exact solution. So that's why I think people need to be knowledgeable that this could happen, and they need to take actions to their own specific use cases. What are the takehomes for you? What do you hope that people walked away from your presentation learning? Yeah, that every type of asset inventory still matters. Fundamental basics still need to be applied.
Starting point is 00:27:04 It's just now we have to think that other attacks or physical. may exist, and how do we address those? All right. Well, Stephen Hilt is Senior Threat Researcher at Trend AI. Stephen, thanks so much for joining us. That's Stephen Hilt from Trend AI. You can hear more from Trend AI on the AI Security Brief podcast that publishes every other Thursday on the N2K Cyberwire Network. On a recent episode, Mark Hout from Databank,
Starting point is 00:27:34 joined host's Johnny Hand and Dustin Childs to explain why securing the AI era starts with protecting the physical data centers that power it, and why proven security fundamentals still matter against rapidly evolving threats. We'll have a link to the AI Security Brief podcast in our show notes. And finally, Troy Hunt's analysis of an alleged Carhart data breach began with an eye-catching number, nearly 25 million unique email addresses. Other reporting cited similar figures, which seemed reassuring, then the data started behaving strangely.
Starting point is 00:28:30 Using AI-assisted analysis and some decidedly old-fashioned eyeballing, Hunt found millions of synthetic records from the TPCDS benchmarking dataset mixed with apparently genuine Carhart customer data. Gibberish email domains, suspiciously uniform birth countries, and perfectly flat birth year distributions were among the giveaways. Removing benchmark data, Microsoft aliases, deactivated accounts, and test records eventually cut the total to about 12.9 million addresses. Hunt found strong evidence the remaining data genuinely originated from Carhart,
Starting point is 00:29:11 including employee addresses and Carhart-specific email sub-addresses. His larger point is that breach claims require, verification. Criminals may dump the data, analysts may count it, and suddenly, synthetic test records have acquired victims, lawyers, and a headline. Jolene, Jolene, please don't take mine. And that's the Cyberwire. For links to all of today's stories, check out our daily briefing at thecyberwire.com. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity.
Starting point is 00:30:02 If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey and the show notes or send an email to Cyberwire at N2K.com. N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazas. Our executive producer is Jennifer Ibin. Peter Kilpie is our publisher.
Starting point is 00:30:27 and I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.