CyberWire Daily - The odds were classified.

Episode Date: August 24, 2026

Polymarket traders win big on U.S. military insider information. Slovakia deactivates speed cameras with Russian backdoors. TikTok pays $400 million to settle kids' privacy allegations. Hackers infect... Android-based car systems with botnet malware. CISA orders quick patching of an actively exploited Zimbra Collaboration Suite vulnerability. SynkLoader malware is built for stealthy access to corporate networks. Dutch authorities fine Uber over $900 million over automated hiring practices. An ATM jackpotter gets a record prison sentence. Monday business briefing. A privacy promise loses face.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On our Industry Voices segment, we are joined by Mark Beare, General Manager at Malwarebytes Consumer Business from Black Hat to look at protecting your family in the age of AI. If you enjoyed this conversation, check out the full interview here. Selected Reading More than 150 Polymarket wallets may have traded on military secrets, research finds (Reuters) Slovakia discovers Russian backdoors in 279 new traffic cameras — SMS-triggered shell access and passwordless live feeds found in EU-funded rollout (Tom's Hardware) TikTok Settles U.S. Child Privacy Case for $400 Million (Security Affairs) Hackers infecting Android car systems to build proxy botnet (The Record) CISA orders urgent patching of actively exploited Zimbra flaw (Bleeping Computer) SynkLoader: when you throw in everything but the kitchen sink (Expel) Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts (SecurityWeek) Venezuelan Gets Record Federal Prison Term for ATM Jackpotting (SecurityWeek) Fortinet has acquired San Francisco-based AI security company Virtue AI. (N2K Pro Business Briefing) Reverse-Lookup Service Exposed Millions of Photos of People’s Faces (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. Holly Market traders win big on U.S. military insider information. Slovakia deactivates speed cameras with Russian backdoors. TikTok pays $400 million to settle kids' privacy allegations. Hackers infect Android-based car systems with botnet malware. Sisa orders quick patching of an actively exploited Zimbab Collaboration Suite vulnerability. Syncloader malware is built for stealthy access to corporate networks. Dutch authorities find Uber over $900 million over automated hiring practices.
Starting point is 00:00:52 An ATM jackpotter gets a record prison sentence. We got your Monday business briefing. Our guest is Mark Baer, general manager at Malwarebytes consumer business, looking at protecting your family in the age of AI. And a privacy promise loses face. It's Monday, August 24th, 2026. I'm Dave Bittner, and this is your Cyberwire Intel Briefing. Thanks for joining us here today. It's great as always to have you with us. More than 150 polymarket international wallets may have traded using inside U.S. military information,
Starting point is 00:01:53 potentially broadcasting sensitive signals to outside observers. Reuters reports. The Anti-Corruption Data Collective, or ACDC, identified 152 highly successful wallets trading military and defense markets. Together, they made $8 million with an average win rate of 97.2%. ACDC cautions that these patterns can have other explanations, including luck. Researchers also found signs that large traders and automated bots copied some suspicious wager, public blockchain transactions can make unusual betting activity visible in real time. If suspicious trades reflect non-public military information, copycat activity could amplify those signals and increase potential national security risks.
Starting point is 00:02:46 ACDC argues stronger identity requirements and restrictions on certain prediction markets may be needed. Slovakia has deactivated 279 news. installed speed cameras after its National Security Service identified multiple security vulnerabilities, including SMS-activated Russian backdoors. The NBU found hard-coded Russian phone numbers that could reportedly trigger shell and network access by sending an SMS. Researchers also found ineffective secure boot protections. The camera's web portals exposed live streams to anyone with a device IP.
Starting point is 00:03:28 without requiring a password. The cameras are thought to be rebranded Russian models. Compromised traffic infrastructure could create security risks beyond traffic enforcement, remote administrative access and exposed camera feeds could provide unauthorized parties with visibility or control. Slovakia's interior ministry has deactivated the cameras pending an independent audit. TikTok will pay $400 million. to settle a 2024 U.S. government lawsuit alleging violations of children's online privacy protections.
Starting point is 00:04:07 The Justice Department and Federal Trade Commission accused TikTok of knowingly allowing children under 13 to create accounts and unlawfully collecting information from children using kids' mode. TikTok will pay $300 million immediately, with another $100 million due after a court vacates an earlier consent, decree involving musical.ly.
Starting point is 00:04:32 The settlement reinforces the legal obligations companies face when handling children's personal information. The Justice Department also acknowledged TikTok's subsequent changes to privacy practices, age controls, parental oversight, ownership, management, and compliance. According to the Justice Department, the agreement represents one of the largest recoveries obtained in a children's online privacy protection act case. Hackers are infecting Android-based car systems with malware designed to expand a botnet and route other people's internet traffic through the vehicles. Kaspersky found the malware on
Starting point is 00:05:14 DoFUN head units, computers controlling functions including navigation, music, and Bluetooth. Attackers reportedly abused TW Core, a legitimate system. application to silently install malware called JAR service. One observed module turns compromised devices into reverse proxies, making routed traffic appear to originate from the vehicle's connection. Automotive computers represent another class of internet-connected devices that attackers can potentially recruit for fraud and traffic routing. Kasperski says DoFund subsequently fix the security issues. According to Kasperski, the The campaign is attributed with high confidence to MOU Group, linked to the bad box operation.
Starting point is 00:06:04 SISA has ordered federal civilian agencies to patch an actively exploited Zimbra Collaboration Suite vulnerability immediately. Today is the deadline. The command injection flaw affects the simple network management protocol, or SNMP, notification component when notifications are enabled. Zimbra patched the issue. issue in a recent version, SertPulska, first reported active exploitation. Shadow Server later identified more than 270 compromised Zimbra instances while searching for exploitation artifacts. Successful exploitation can let an unauthenticated attacker execute operating system commands as the Zimbra user. Experts recommend reviewing logs and files for evidence
Starting point is 00:06:51 of compromise. Researchers at Expell have unconsed. covered Sinkloader, a new malware family delivered through Microsoft Teams fishing and built for stealthy hands-on access to corporate networks. The attack begins with someone posing as an IT help desk employee and convincing a user to install a malicious MSI package. Syncloader then executes components largely in-memory and bridges Python, PowerShell, C-sharp, and C-plus-plus. Researchers observed modules for system profiling, persistence, and remote command execution, network tunneling, and screen control. Other modules display a fake Windows lock screen to steal login credentials. The combination of stolen credentials and network tunneling could let attackers access internal
Starting point is 00:07:44 and external systems through the victim's machine, potentially reducing signs of unusual login locations. Researchers assess with low-to-medium confidence, that the toolkit may be associated with ransomware operators or an initial access broker. Dutch data protection authorities have fined Uber about $964 million over automated driver suspensions. The regulator says Uber violated the General Data Protection Regulation, GDPR, by allowing software to suspend driver accounts, sometimes permanently, without human review. It also says Uber failed to properly inform drivers about automated decision-making. The violations allegedly occurred from 2018 through 2022.
Starting point is 00:08:35 Automated decisions affecting people's livelihoods remain subject to European privacy protections. Uber disputes the findings and says it will appeal. A Venezuelan National has received an eight-year federal prison sentence for participating in an ATM jackpotting scheme responsible for millions of dollars in losses. The Justice Department says 27-year-old Juan Manuel Govai Agiero pleaded guilty to bank fraud, bank burglary, and cyber-enabled fraud charges. The court held him responsible for more than $3.5 million in losses. ATM jackpotting typically involves accessing a machine, connecting a laptop, and installing malware,
Starting point is 00:09:20 that commands the ATM to dispense its cash. Malware-enabled jackpotting remains a significant threat to financial infrastructure. The FBI reported roughly 1900 attacks since 2020, with losses exceeding $20 million just last year. Turning to our Monday business briefing, cybersecurity and AI companies announced several new funding rounds and acquisitions in the past week, with investment spanning data security,
Starting point is 00:09:50 AI governance, penetration testing, and critical infrastructure protection. Prevalent AI led the funding announcements with a $22 million growth investment, followed by Expander at $7.5 million, Cytics at $7 million, and neuromorphic labs at $5.1 million. Top Hat Security also announced an undisclosed Series A. On the acquisition front, Dinah Trace agreed to acquire AI observability company arise for $915 million.
Starting point is 00:10:26 Data Vault AI agreed to acquire Cybercatch holdings for $94.5 million. Fortinette acquired Virtue AI, while Cribble acquired technology assets from Radiant Securities AI SOC product. The activity shows investors and established vendors directing capital toward AI security, governance, observability, and broader enterprise risk capabilities. Be sure to check out our complete business briefing that's on our website, part of Cyberwire Pro. Coming up after the break, my conversation with Mark Baer, general manager at Malwarebyte's consumer business, and a privacy promise loses space.
Starting point is 00:11:33 AI is transforming the way organizations work, but what happens when we rely on it so much that we begin losing the human judgment and context that make good decisions possible. I recently sat down with Johnny Hand from Trend AI, and he made an important point about what we risk when we offload too much AI. We risk our most valuable resource, which is our human context, our creativity, our ability to understand contextually, like in the environment, those things. Those are really hard challenges for AI to tackle. If you're trying to separate AI hype from.
Starting point is 00:12:10 operational reality, I think you'll really enjoy this conversation. Listen now at explore.thecyberwire.com slash trend AI. Mark Baer is general manager at Malwarebyte's consumer business. I caught up with him at the Black Hat Conference for a look at protecting your family in the age of AI. We are continuing our conversations here at Black Hat 2026. And joining me now is Mark Bear. who is general manager for Malwarebytes consumer business.
Starting point is 00:12:56 Mark, welcome. Hi. Hi, Dave. So I'm particularly interested in your insights for where we are with AI from the unique view that you all have at Malwarebytes into the consumer side of things. What can you share from that side of it? I think it's often not talked about in the consumer side, especially at conferences like this because it's all very B2B-I-intated.
Starting point is 00:13:20 Right. There's this kind of convergence happen and now where people have a lot of information leaked about them online. They've data breaches, they have data brokers, they have all these different things where you can find their email address and look up their password.
Starting point is 00:13:34 And then that, in combination with AI, to be able to create really personalized messages and personalized scams at volume and at scale is kind of something that I think everyone sees coming. And I think consumers are starting to feel it now. So for us, what we see is scams kind of booming. I could create a very compelling scam. If I know your name and I know your wife's name or a friend or where you grew up,
Starting point is 00:13:58 I can create a very, very interesting message to send you, and I can do that to you and I can do it to 10,000 other people all in a minute burning some tokens. But, yeah, it's really affecting consumers a lot. And consumers really just don't have anybody to turn for help for these types of things. Like if you work at a company, you have an IT team. Right. You hand your laptop if you do something wrong or you say, I click this link.
Starting point is 00:14:21 I put my credentials in, how can you help me? And you go somewhere and get that help. And as a consumer, it's really hard to find that help. And that's what we're trying to do is be that voice and offer solutions out there. Is it every step along the way of these scams that's being accelerated here? In other words, like the gathering of the information,
Starting point is 00:14:39 the crafting of the fishing email, the execution, has this made all of those faster? It's become a professional thing. There's like companies that will sell SaaS software for doing scams or doing info stealing. It's like if you go back to the 2000s or the 2010s, you had spear fishing. Right. And you would invest a lot of time or they would invest a lot of time in actually researching a potential victim and going after that victim
Starting point is 00:15:07 because they were maybe wealthy or they were a good target. You don't need people to be wealthy or a good target now because there's just so many people out there with information leads. and all you need to do is take $10 from 50,000 people, this is $50,000 from one person. And so I think that is really creating that real change in the dynamic where I think a lot of consumers often think, like, why do I matter? I'm a teacher, I'm a firefighter, I'm not that important,
Starting point is 00:15:35 why would anyone want to go after me? And it's not about who you are, it's about you being, you know, a part of an audience. And what we might consider to be a small amount, to us, it might be a much larger amount to someone on the other side of the world, or even as you say in the aggregate, it adds up. Yeah, exchange rates, some places where these bad actors are operating
Starting point is 00:15:58 that are places that the US government can't necessarily go after, $10 goes a lot further. And so, yeah, I think that's the interesting thing as well is that these scams and fishing attacks are getting so good and effective that you're actually also seeing them by advertising to create a funnel to get people in to these scam flows.
Starting point is 00:16:24 And so actually, ad blocking is another big thing that we're kind of like talk about a lot at Nullabites because it used to be about just like turning off ads because you don't like them. Now it's actually become a good security posture because you could search for a brand or you could search for something on Google and someone might go and buy the top ad spot and put a fake website there and then play on that brand trust and get people to go over and think they're going to actually even even to our own website. We've seen scammers go and create a malwarebytes.com
Starting point is 00:16:53 or mailbox.com or malbass.com and it looks really much like us and they will try and sell our software on a fake website and then buy that top rank on Google to try to get those people to live it in. Help me understand the spectrum of defensive opportunities that companies like malware bytes
Starting point is 00:17:13 are able to provide to consumers. What is it encompassed? Yeah, it's a lot more than it used to be. Back in the 2000s, the only device you really had was your PC. Everything was done there. And so that's where the origins of our company came from. It's we would protect your computer and protected from malware and viruses. And then as the world has now gotten a lot more complicated,
Starting point is 00:17:36 people have a lot more connected devices. We've had to extend a lot more to protect those devices as well. So for us now, mobile security is a really big thing. text filtering, coal filtering, ad blocking, fishing protection as well, those things are now a big part of what we do, even though we're very renowned for the antivirus story that really got us to where we are today, as well as data broker removal,
Starting point is 00:18:03 and a lot of it's also awareness. They're trying to just make people aware that you are vulnerable because you have a lot of information about you online, and a lot of people don't know how to find out what information is available about them online. How has AI affected your business itself? In other words, the availability of those tools on your side to be able to use them to help you do the things you do better
Starting point is 00:18:29 to protect the folks out there? It is actually a big help. We have found it historically malware, definition writing, and research was a very manual profession. And so if you wanted to understand and reverse engineer a bunch of different files. It would take a lot of people. And so you can only really process
Starting point is 00:18:48 as many things that you have the team to do so. And now with AI, you can actually write some really compelling tools to just do that at mass. It's really helpful for doing first round screening on fishing links, just give a quick sense of likelihood of being a scam or a fishing site
Starting point is 00:19:05 or an infest dealer site. So it's been really helpful for us to try to stay ahead. Because the really interesting dynamic that I don't think to talk about either is like there was obviously that crowd strike incident that caused a lot of machines to get bricked and so our
Starting point is 00:19:21 industry is very careful in how we deploy our software and build it and so we can't just go vibe code or antivirus and ship it because it has kernel of access to the Windows machine and so if you have any bugs in there that can be very very bad
Starting point is 00:19:37 and so we'll be very careful how we build our software and make sure the security and the quality is very, very high. But bad actors don't care. You can create a piece of malware and try to distribute it, and if it doesn't work great, build another one.
Starting point is 00:19:52 And so the rate of progress that you can build these things is just so high now. And there's also a lot of models that have been put out there, the open source models, that even old versions that they can just use on their device
Starting point is 00:20:05 and just keep building new versions of malware. A lot of the new LMs now have built safeguards in place to stop them from doing bad. things, but the old ones don't. And so we're just seeing the volume just become a really big factor. I think a lot of companies here at the conference are dealing with that too. Like, how do you stay ahead when the volume is so high of threats coming out, breaches are coming out? You've got like a lot of different companies that do the screening of your vulnerabilities that come in,
Starting point is 00:20:31 like Hacker 1. I know they're drowning in reported vulnerabilities now. So there's just so much more noise to fight through AI. I can certainly help there. How is it different on the consumer side? In other words, I can imagine you have to walk that line where you're protecting an individual, but you have to be careful also not to overwhelm them. That's probably the biggest challenge, to be honest. You know, consumers, not if you wake up and think about cyber security
Starting point is 00:21:01 and they get out bed. Right. They don't say, I'm not going to buy I don't need their protection today or VPN. And they often are doing it after something to come wrong. And that's tough because a lot of these things, like if you've been fooled into a scam, your money's gone. There's not a lot you can do about it. And so the remediation is not as great. And so it's really about awareness and making it easy to follow, right?
Starting point is 00:21:24 Like if you, I don't think it's ever a good thing to try to ask someone to do all of the things they need to do to get more secure in one day or in one sitting and try to drip, feed it and make it getting easier. So for us, we have this tool that's across all of our products, trusted advisor, where we give someone a security score. And that makes it just really easy to understand what their posture is. And then there's just a list of tips of like, how do you increase your score? And we're just trying to make it very, very easy. Like our tagline is really around making cyber security room imagine for humans.
Starting point is 00:21:56 Humans are the biggest part of it. Right. And people are flawed. They're busy. They've got things to do. Anything else they'd rather be doing than installing an antivist products. And so we want to try and make that really easy for them. So there really is an educational component to all this as well, not just the same.
Starting point is 00:22:10 technology. Totally. I think education is big. I think there's also a lot of shame now of what's happening. People get scammed and they feel stupid or they feel like that shouldn't have happened and they don't want to talk about it. Right. There's so many conversations I have where I'm like, oh,
Starting point is 00:22:26 scams are happening a lot and they're like, actually that happened to me. Yep. And they're like, they never tell anyone that story. It's fake shops where you think you're buying something that's not actually going to get delivered to you. So I think we have to take the shame out of it. I like having more awareness that it's happening,
Starting point is 00:22:43 that they're professional people doing these games, and they're very, very good at it. And if we can help with the awareness and education, that should help people feel less shame and hopefully talk about it more, and then they can increase their concern when they look at something. They're more suspicious at things
Starting point is 00:23:02 versus just trusting everything they put on. Where do you suppose we're headed with this stuff? Is this a, you know, a future where that... you know, that agentic personality is always looking over our shoulder to keep us out of trouble? Or what would we do? I think these AI tools can be a great companion for people. Like, if you have, you know, securing yourself takes work, right? Like, hey, I want to go and unsubscribe from every email I've ever signed up for,
Starting point is 00:23:29 delete all my old account. So if a breach happens to that company, I'm not in that breach. That takes so much work and time to do those things. Change all your passwords, make them all secure, right? And so if we can move in a way where AI is able to securely operate on our behalf, it can do all that front work, right? You're asking about complexity or challenges. If you can make it easy, if like cyber security companies can use your AI that you pay for
Starting point is 00:23:57 that you get for free to do things that are better secure you, that can be an amazing step in the right direction because that is, as you said, like a big challenge. People just don't want to make time for this stuff and let AI do it. So I'm optimistic about that. that. I think that can help a lot. Mark Baer is general manager with malware bites consumer business. Mark, thanks so much for taking the time for us. Thanks, don't. And finally, clarity check tells users its reverse image search is private and secure.
Starting point is 00:24:43 Security researcher Jeremiah Fowler found the company had apparently left more than 9 million image files accessible online. Privacy, it seems, had encountered a configuration issue. Fowler discovered roughly 450 gigabytes of profile pictures, screenshots, and other images, including photographs of children in an unsecured Amazon S3 bucket. The files sat in folders labeled faces and profiles. A URL in Clarity Check's publicly available website code provided access without authentication. Fowler also found misconfigured APIs that could reveal potential email addresses, physical addresses, and phone numbers, simply by manipulating website URLs. Clarity check secured both issues after a wired contacted the company. It disputes describing the data
Starting point is 00:25:38 as publicly exposed, arguing that access required knowledge of a specific unindexed URL. The company also says there's no evidence of malicious access. Facial images are particularly sensitive, passwords can be changed. Faces are somewhat less cooperative. Fowler warns exposed photographs could potentially be harvested for AI training, impersonation, or scams. Faces, it seems, still have limited reset options. And that's the Cyberwire. For links to all of today's stories, check out our daily briefing at thecyberwire.com. We'd love to know what you think of this podcast, your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app.
Starting point is 00:26:45 Please also fill out the survey in the show notes or send an email to Cyberwire at N2K.com. N2K's lead producers, Liz Stokes, were mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazas. Our executive producer is Jennifer Ibin, Peter Kilby is our publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.