CyberWire Daily - The odds were classified.
Episode Date: August 24, 2026Polymarket traders win big on U.S. military insider information. Slovakia deactivates speed cameras with Russian backdoors. TikTok pays $400 million to settle kids' privacy allegations. Hackers infect... Android-based car systems with botnet malware. CISA orders quick patching of an actively exploited Zimbra Collaboration Suite vulnerability. SynkLoader malware is built for stealthy access to corporate networks. Dutch authorities fine Uber over $900 million over automated hiring practices. An ATM jackpotter gets a record prison sentence. Monday business briefing. A privacy promise loses face. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On our Industry Voices segment, we are joined by Mark Beare, General Manager at Malwarebytes Consumer Business from Black Hat to look at protecting your family in the age of AI. If you enjoyed this conversation, check out the full interview here. Selected Reading More than 150 Polymarket wallets may have traded on military secrets, research finds (Reuters) Slovakia discovers Russian backdoors in 279 new traffic cameras — SMS-triggered shell access and passwordless live feeds found in EU-funded rollout (Tom's Hardware) TikTok Settles U.S. Child Privacy Case for $400 Million (Security Affairs) Hackers infecting Android car systems to build proxy botnet (The Record) CISA orders urgent patching of actively exploited Zimbra flaw (Bleeping Computer) SynkLoader: when you throw in everything but the kitchen sink (Expel) Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts (SecurityWeek) Venezuelan Gets Record Federal Prison Term for ATM Jackpotting (SecurityWeek) Fortinet has acquired San Francisco-based AI security company Virtue AI. (N2K Pro Business Briefing) Reverse-Lookup Service Exposed Millions of Photos of People’s Faces (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
Holly Market traders win big on U.S. military insider information.
Slovakia deactivates speed cameras with Russian backdoors.
TikTok pays $400 million to settle kids' privacy allegations.
Hackers infect Android-based car systems with botnet malware.
Sisa orders quick patching of an actively exploited Zimbab Collaboration Suite vulnerability.
Syncloader malware is built for stealthy access to corporate networks.
Dutch authorities find Uber over $900 million over automated hiring practices.
An ATM jackpotter gets a record prison sentence.
We got your Monday business briefing.
Our guest is Mark Baer, general manager at Malwarebytes consumer business,
looking at protecting your family in the age of AI.
And a privacy promise loses face.
It's Monday, August 24th, 2026. I'm Dave Bittner, and this is your Cyberwire Intel Briefing.
Thanks for joining us here today. It's great as always to have you with us.
More than 150 polymarket international wallets may have traded using inside U.S. military information,
potentially broadcasting sensitive signals to outside observers. Reuters reports.
The Anti-Corruption Data Collective, or ACDC, identified 152 highly successful wallets trading military and defense markets.
Together, they made $8 million with an average win rate of 97.2%.
ACDC cautions that these patterns can have other explanations, including luck.
Researchers also found signs that large traders and automated bots copied some suspicious wager,
public blockchain transactions can make unusual betting activity visible in real time.
If suspicious trades reflect non-public military information,
copycat activity could amplify those signals and increase potential national security risks.
ACDC argues stronger identity requirements and restrictions on certain prediction markets may be needed.
Slovakia has deactivated 279 news.
installed speed cameras after its National Security Service identified multiple security
vulnerabilities, including SMS-activated Russian backdoors.
The NBU found hard-coded Russian phone numbers that could reportedly trigger shell and network
access by sending an SMS.
Researchers also found ineffective secure boot protections.
The camera's web portals exposed live streams to anyone with a device IP.
without requiring a password.
The cameras are thought to be rebranded Russian models.
Compromised traffic infrastructure could create security risks beyond traffic enforcement,
remote administrative access and exposed camera feeds could provide unauthorized parties with visibility or control.
Slovakia's interior ministry has deactivated the cameras pending an independent audit.
TikTok will pay $400 million.
to settle a 2024 U.S. government lawsuit
alleging violations of children's online privacy protections.
The Justice Department and Federal Trade Commission
accused TikTok of knowingly allowing children under 13
to create accounts and unlawfully collecting information
from children using kids' mode.
TikTok will pay $300 million immediately,
with another $100 million due
after a court vacates an earlier consent,
decree involving musical.ly.
The settlement reinforces the legal obligations companies face when handling children's
personal information.
The Justice Department also acknowledged TikTok's subsequent changes to privacy practices,
age controls, parental oversight, ownership, management, and compliance.
According to the Justice Department, the agreement represents one of the largest
recoveries obtained in a children's online privacy protection act case.
Hackers are infecting Android-based car systems with malware designed to expand a botnet and route
other people's internet traffic through the vehicles. Kaspersky found the malware on
DoFUN head units, computers controlling functions including navigation, music, and Bluetooth.
Attackers reportedly abused TW Core, a legitimate system.
application to silently install malware called JAR service. One observed module turns
compromised devices into reverse proxies, making routed traffic appear to originate from
the vehicle's connection. Automotive computers represent another class of internet-connected
devices that attackers can potentially recruit for fraud and traffic routing. Kasperski
says DoFund subsequently fix the security issues. According to Kasperski, the
The campaign is attributed with high confidence to MOU Group, linked to the bad box operation.
SISA has ordered federal civilian agencies to patch an actively exploited Zimbra Collaboration Suite vulnerability immediately.
Today is the deadline.
The command injection flaw affects the simple network management protocol, or SNMP, notification component when notifications are enabled.
Zimbra patched the issue.
issue in a recent version, SertPulska, first reported active exploitation.
Shadow Server later identified more than 270 compromised Zimbra instances while searching for
exploitation artifacts. Successful exploitation can let an unauthenticated attacker execute operating
system commands as the Zimbra user. Experts recommend reviewing logs and files for evidence
of compromise. Researchers at Expell have unconsed.
covered Sinkloader, a new malware family delivered through Microsoft Teams fishing and built
for stealthy hands-on access to corporate networks. The attack begins with someone posing as an
IT help desk employee and convincing a user to install a malicious MSI package. Syncloader then
executes components largely in-memory and bridges Python, PowerShell, C-sharp, and C-plus-plus. Researchers observed
modules for system profiling, persistence, and remote command execution, network tunneling,
and screen control. Other modules display a fake Windows lock screen to steal login credentials.
The combination of stolen credentials and network tunneling could let attackers access internal
and external systems through the victim's machine, potentially reducing signs of unusual
login locations. Researchers assess with low-to-medium confidence,
that the toolkit may be associated with ransomware operators or an initial access broker.
Dutch data protection authorities have fined Uber about $964 million over automated driver suspensions.
The regulator says Uber violated the General Data Protection Regulation, GDPR,
by allowing software to suspend driver accounts, sometimes permanently, without human review.
It also says Uber failed to properly inform drivers about automated decision-making.
The violations allegedly occurred from 2018 through 2022.
Automated decisions affecting people's livelihoods remain subject to European privacy protections.
Uber disputes the findings and says it will appeal.
A Venezuelan National has received an eight-year federal prison sentence
for participating in an ATM jackpotting scheme responsible for millions of dollars in losses.
The Justice Department says 27-year-old Juan Manuel Govai Agiero pleaded guilty to bank fraud, bank
burglary, and cyber-enabled fraud charges.
The court held him responsible for more than $3.5 million in losses.
ATM jackpotting typically involves accessing a machine, connecting a laptop, and installing malware,
that commands the ATM to dispense its cash.
Malware-enabled jackpotting remains a significant threat to financial infrastructure.
The FBI reported roughly 1900 attacks since 2020,
with losses exceeding $20 million just last year.
Turning to our Monday business briefing,
cybersecurity and AI companies announced several new funding rounds
and acquisitions in the past week,
with investment spanning data security,
AI governance, penetration testing, and critical infrastructure protection.
Prevalent AI led the funding announcements with a $22 million growth investment,
followed by Expander at $7.5 million,
Cytics at $7 million,
and neuromorphic labs at $5.1 million.
Top Hat Security also announced an undisclosed Series A.
On the acquisition front, Dinah Trace agreed to acquire AI
observability company arise for $915 million.
Data Vault AI agreed to acquire Cybercatch holdings for $94.5 million.
Fortinette acquired Virtue AI, while Cribble acquired technology assets from Radiant Securities
AI SOC product.
The activity shows investors and established vendors directing capital toward AI security,
governance, observability, and broader enterprise risk capabilities.
Be sure to check out our complete business briefing that's on our website, part of Cyberwire Pro.
Coming up after the break, my conversation with Mark Baer, general manager at Malwarebyte's consumer business,
and a privacy promise loses space.
AI is transforming the way organizations work, but what happens when we rely on it so much that we begin
losing the human judgment and context that make good decisions possible.
I recently sat down with Johnny Hand from Trend AI, and he made an important point about what we
risk when we offload too much AI.
We risk our most valuable resource, which is our human context, our creativity, our ability
to understand contextually, like in the environment, those things.
Those are really hard challenges for AI to tackle.
If you're trying to separate AI hype from.
operational reality, I think you'll really enjoy this conversation.
Listen now at explore.thecyberwire.com slash trend AI.
Mark Baer is general manager at Malwarebyte's consumer business.
I caught up with him at the Black Hat Conference for a look at protecting your family in the age
of AI.
We are continuing our conversations here at Black Hat 2026.
And joining me now is Mark Bear.
who is general manager for Malwarebytes consumer business.
Mark, welcome.
Hi. Hi, Dave.
So I'm particularly interested in your insights for where we are with AI
from the unique view that you all have at Malwarebytes
into the consumer side of things.
What can you share from that side of it?
I think it's often not talked about in the consumer side,
especially at conferences like this because it's all very B2B-I-intated.
Right.
There's this kind of convergence happen
and now where people have a lot of information
leaked about them online.
They've data breaches, they have data brokers,
they have all these different things
where you can find their email address
and look up their password.
And then that, in combination with AI,
to be able to create really personalized messages
and personalized scams at volume and at scale
is kind of something that I think everyone sees coming.
And I think consumers are starting to feel it now.
So for us, what we see is scams kind of booming.
I could create a very compelling scam.
If I know your name and I know your wife's name or a friend or where you grew up,
I can create a very, very interesting message to send you,
and I can do that to you and I can do it to 10,000 other people all in a minute
burning some tokens.
But, yeah, it's really affecting consumers a lot.
And consumers really just don't have anybody to turn for help for these types of things.
Like if you work at a company, you have an IT team.
Right.
You hand your laptop if you do something wrong or you say, I click this link.
I put my credentials in, how can you help me?
And you go somewhere and get that help.
And as a consumer, it's really hard to find that help.
And that's what we're trying to do is be that voice
and offer solutions out there.
Is it every step along the way of these scams
that's being accelerated here?
In other words, like the gathering of the information,
the crafting of the fishing email, the execution,
has this made all of those faster?
It's become a professional thing.
There's like companies that will sell SaaS software for doing scams or doing info stealing.
It's like if you go back to the 2000s or the 2010s, you had spear fishing.
Right.
And you would invest a lot of time or they would invest a lot of time
in actually researching a potential victim and going after that victim
because they were maybe wealthy or they were a good target.
You don't need people to be wealthy or a good target now
because there's just so many people out there with information leads.
and all you need to do is take $10 from 50,000 people,
this is $50,000 from one person.
And so I think that is really creating that real change in the dynamic
where I think a lot of consumers often think, like, why do I matter?
I'm a teacher, I'm a firefighter, I'm not that important,
why would anyone want to go after me?
And it's not about who you are, it's about you being, you know, a part of an audience.
And what we might consider to be a small amount,
to us, it might be a much larger amount
to someone on the other side of the world,
or even as you say in the aggregate, it adds up.
Yeah, exchange rates, some places
where these bad actors are operating
that are places that the US government
can't necessarily go after,
$10 goes a lot further.
And so, yeah, I think that's the interesting thing as well
is that these scams and fishing attacks
are getting so good and effective
that you're actually also seeing
them by advertising to create a funnel to get people in to these scam flows.
And so actually, ad blocking is another big thing that we're kind of like talk about a lot
at Nullabites because it used to be about just like turning off ads because you don't like them.
Now it's actually become a good security posture because you could search for a brand
or you could search for something on Google and someone might go and buy the top ad spot
and put a fake website there and then play on that brand trust and get people to go over
and think they're going to actually even
even to our own website. We've seen
scammers go and create a malwarebytes.com
or mailbox.com or malbass.com
and it looks really much like us
and they will try and sell our software
on a fake website and then buy that top rank on Google
to try to get those people to live it in.
Help me understand the spectrum of
defensive opportunities
that companies like malware bytes
are able to provide to consumers.
What is it encompassed?
Yeah, it's a lot more than it used to be.
Back in the 2000s, the only device you really had was your PC.
Everything was done there.
And so that's where the origins of our company came from.
It's we would protect your computer and protected from malware and viruses.
And then as the world has now gotten a lot more complicated,
people have a lot more connected devices.
We've had to extend a lot more to protect those devices as well.
So for us now, mobile security is a really big thing.
text filtering, coal filtering, ad blocking, fishing protection as well,
those things are now a big part of what we do,
even though we're very renowned for the antivirus story
that really got us to where we are today,
as well as data broker removal,
and a lot of it's also awareness.
They're trying to just make people aware that you are vulnerable
because you have a lot of information about you online,
and a lot of people don't know how to find out what information is available
about them online.
How has AI affected your business itself?
In other words, the availability of those tools on your side
to be able to use them to help you do the things you do better
to protect the folks out there?
It is actually a big help.
We have found it historically malware, definition writing,
and research was a very manual profession.
And so if you wanted to understand and reverse engineer
a bunch of different files.
It would take a lot of people.
And so you can only really process
as many things that you have the team to do so.
And now with AI,
you can actually write some really compelling
tools to just do that at mass.
It's really helpful for doing
first round screening on fishing links,
just give a quick sense of likelihood of being
a scam or a fishing site
or an infest dealer site.
So it's been really helpful for us
to try to stay ahead.
Because the really interesting
dynamic that I don't think
to talk about either is like there was obviously that
crowd strike incident that caused a lot of
machines to get bricked and so our
industry is very careful in how
we deploy our software and
build it and so we can't just go
vibe code or antivirus
and ship it because it has
kernel of access to the Windows machine
and so if you have any bugs in there
that can be very very bad
and so we'll be very careful how we
build our software and make sure the security
and the quality is very, very high.
But bad actors don't care.
You can create a piece of malware
and try to distribute it,
and if it doesn't work great,
build another one.
And so the rate of progress
that you can build these things
is just so high now.
And there's also a lot of models
that have been put out there,
the open source models,
that even old versions
that they can just use on their device
and just keep building new versions of malware.
A lot of the new LMs now
have built safeguards in place
to stop them from doing bad.
things, but the old ones don't. And so we're just seeing the volume just become a really big
factor. I think a lot of companies here at the conference are dealing with that too. Like, how do you
stay ahead when the volume is so high of threats coming out, breaches are coming out? You've got
like a lot of different companies that do the screening of your vulnerabilities that come in,
like Hacker 1. I know they're drowning in reported vulnerabilities now. So there's just so much more
noise to fight through AI. I can certainly help there.
How is it different on the consumer side?
In other words, I can imagine you have to walk that line
where you're protecting an individual,
but you have to be careful also not to overwhelm them.
That's probably the biggest challenge, to be honest.
You know, consumers, not if you wake up and think about cyber security
and they get out bed.
Right.
They don't say, I'm not going to buy I don't need their protection today or VPN.
And they often are doing it after something to come wrong.
And that's tough because a lot of these things, like if you've been fooled into a scam, your money's gone.
There's not a lot you can do about it.
And so the remediation is not as great.
And so it's really about awareness and making it easy to follow, right?
Like if you, I don't think it's ever a good thing to try to ask someone to do all of the things they need to do to get more secure in one day or in one sitting
and try to drip, feed it and make it getting easier.
So for us, we have this tool that's across all of our products,
trusted advisor, where we give someone a security score.
And that makes it just really easy to understand what their posture is.
And then there's just a list of tips of like, how do you increase your score?
And we're just trying to make it very, very easy.
Like our tagline is really around making cyber security room imagine for humans.
Humans are the biggest part of it.
Right.
And people are flawed.
They're busy.
They've got things to do.
Anything else they'd rather be doing than installing an antivist products.
And so we want to try and make that really easy for them.
So there really is an educational component to all this as well, not just the same.
technology. Totally. I think
education is big. I think there's also a lot of
shame now of what's happening.
People get scammed
and they feel stupid or they feel like
that shouldn't have happened and they don't want to talk about
it. Right. There's
so many conversations I have where I'm like, oh,
scams are happening a lot and they're like, actually that happened to me.
Yep. And they're like, they never
tell anyone that story.
It's fake shops where you
think you're buying something that's not actually going to get delivered to you.
So I think
we have to take the shame out of it.
I like having more awareness that it's happening,
that they're professional people doing these games,
and they're very, very good at it.
And if we can help with the awareness and education,
that should help people feel less shame
and hopefully talk about it more,
and then they can increase their concern
when they look at something.
They're more suspicious at things
versus just trusting everything they put on.
Where do you suppose we're headed with this stuff?
Is this a, you know, a future where that...
you know, that agentic personality is always looking over our shoulder to keep us out of trouble?
Or what would we do?
I think these AI tools can be a great companion for people.
Like, if you have, you know, securing yourself takes work, right?
Like, hey, I want to go and unsubscribe from every email I've ever signed up for,
delete all my old account.
So if a breach happens to that company, I'm not in that breach.
That takes so much work and time to do those things.
Change all your passwords, make them all secure, right?
And so if we can move in a way where AI is able to securely operate on our behalf,
it can do all that front work, right?
You're asking about complexity or challenges.
If you can make it easy, if like cyber security companies can use your AI that you pay for
that you get for free to do things that are better secure you,
that can be an amazing step in the right direction because that is, as you said,
like a big challenge.
People just don't want to make time for this stuff and let AI do it.
So I'm optimistic about that.
that. I think that can help a lot. Mark Baer is general manager with malware bites consumer business.
Mark, thanks so much for taking the time for us. Thanks, don't.
And finally, clarity check tells users its reverse image search is private and secure.
Security researcher Jeremiah Fowler found the company had apparently left more than 9 million
image files accessible online. Privacy, it seems, had encountered a configuration
issue. Fowler discovered roughly 450 gigabytes of profile pictures, screenshots, and other images,
including photographs of children in an unsecured Amazon S3 bucket. The files sat in folders
labeled faces and profiles. A URL in Clarity Check's publicly available website code provided
access without authentication. Fowler also found misconfigured APIs that could reveal potential
email addresses, physical addresses, and phone numbers, simply by manipulating website URLs.
Clarity check secured both issues after a wired contacted the company. It disputes describing the data
as publicly exposed, arguing that access required knowledge of a specific unindexed URL. The company
also says there's no evidence of malicious access. Facial images are particularly sensitive,
passwords can be changed. Faces are somewhat less cooperative. Fowler warns exposed photographs could
potentially be harvested for AI training, impersonation, or scams. Faces, it seems, still have
limited reset options. And that's the Cyberwire. For links to all of today's stories,
check out our daily briefing at thecyberwire.com. We'd love to know what you think of this podcast, your
feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of
cybersecurity. If you like our show, please share a rating and review in your favorite podcast app.
Please also fill out the survey in the show notes or send an email to Cyberwire at N2K.com.
N2K's lead producers, Liz Stokes, were mixed by Trey Hester with original music and sound design by
Elliot Peltzman. Our contributing host is Maria Vermazas. Our executive producer is Jennifer Ibin,
Peter Kilby is our publisher, and I'm Dave Bittner.
Thanks for listening.
We'll see you back here tomorrow.
