CyberWire Daily - The world's least private hackers.
Episode Date: July 27, 2026Hackers target Thailand’s Ministry of Finance with an autonomous AI agent.A new industry alliance hopes to improve AI security. Golden Chickens lay four new malware families. GitHub and PyPI introdu...ce time-based safeguards. SourTrade malvertising builds malware directly inside a victim’s browser. Attackers target credentials of traveling corporate employees. EDR shutdown is now par for the course for leading ransomware groups. Russian threat actors exploited a Zimbra vulnerability for at least five months before it was patched. Monday business briefing. Our guest is Krishna Sai, CTO at SolarWinds, with security lessons learned from the World Cup. When the feed ends, the fun begins. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Krishna Sai, CTO at SolarWinds, discussing the security risks around the World Cup and how this affects IT teams as they try to manage the growing digital traffic sprawl surrounding the event. Selected Reading Hackers used autonomous AI agent to spy on Thailand's finance ministry (The Record) Nvidia and Tech Giants Launch AI Security Alliance (SecurityWeek) Golden Chickens malware-as-a-service resurfaces with four new families (SC Media) GitHub, PyPI add time-based defenses against supply chain attacks (Bleeping Computer) SourTrade Malvertising Campaign Secretly Builds Malware in the Browser (Infosecurity Magazine) Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials (SecurityWeek) Ransomware Groups Increasingly Deploy EDR Kill Techniques (Infosecurity Magazine) TA488 Targets Zimbra Mailservers with Half-Click Exploits IProofpoint) Endpoint security firm Glow emerges from stealth with $180 million. (N2K Pro Business Briefing) Being a Luddite Is Fun Again (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
This episode is supported by Black Hat USA.
If you follow the research, you know a lot of it breaks on Black Hat stages.
Hundreds of peer-reviewed briefings, more than 100 hands-on trainings,
and the largest business hall in Black Hat's history.
Six days to learn the skills you'll need tomorrow.
August 1st to the 6th.
Use code Cyberwire for $200 off your briefings pass.
at blackhat.com.
We'll see you in Vegas.
If you're heading to Black Hat USA this year,
make plans to visit the SpectorOps Kennel Club.
As creators of Bloodhound,
the SpectorOps team will host talks with OpenAI
and the UK AI Security Institute,
as well as hands-on workshops
aimed at helping you understand
AI accelerated attack paths
and the latest in identity tradecraft.
Visit Spectorops.io to pre-register
and learn more. Spector Ops Kennel Club is adjacent to Libertine Social inside Mandalay Bay.
While you're there, visit the N2K Cyberwire podcast studio, where we'll be capturing expert
perspectives and conversations from across Black Hat.
Packers target Thailand's Ministry of Finance. A new industry alliance hopes to improve AI security,
Golden Chickens lay four new malware families, GitHub and Pi Pi-Pai introduced time-based
safeguards. Sower trade
malvertising builds malware directly
inside a victim's browser.
Attackers target credentials of traveling
corporate employees. EDR
shutdown is now par for the course
for leading ransomware groups.
Russian threat actors exploit a
Zimbra vulnerability for at least five months
before it was patched. We've got your
Monday business briefing. Our guest
is Krishna Sy, CTO at
Solar Winds, with security
lessons learned from the World Cup.
And when the feed ends,
the fun begins.
It's Monday, July 27th,
2026. I'm Dave Bittner, and this
is your Cyberwire Intel Briefing.
Thanks for joining us here today. It's great as always
to have you with us. Researchers at Hunt I.O.
say hackers used an autonomous artificial agent
during an apparent cyber espionage campaign
targeting Thailand's Ministry of Finance.
While the intrusion was underway,
the attackers accidentally exposed hundreds of files on their own infrastructure,
giving researchers an unusual look inside the operation.
The files included malware, stolen credentials, attack scripts, AI agent logs,
and evidence that multiple ministry systems had already been compromised.
Hunt I.O. said the attackers relied heavily on Ermes,
an open-source AI agent configured to execute to execute commands without human approval.
The agent autonomously explored the ministry's network,
gathered system information, and searched for ways to escalate privileges.
Although researchers found no evidence of data exfiltration,
the activity appears focused on reconnaissance, credential theft,
and preparing for future operations.
Hunt I.O. has not attributed the campaign,
but said several indicators suggest the operators were Chinese-speaking.
Invidia and dozens of technology, cybersecurity, and enterprise software companies have launched the OpenSecure AI Alliance,
a new initiative focused on developing and sharing open source tools, models, and techniques to improve AI security.
The effort builds on work from the Linux Foundation's Accretes Initiative and the Open Source Security Foundation.
founding members include major industry players such as Microsoft, IBM, Cisco, CrowdStrike, Palo Alto Networks, and Hugging Face.
The Alliance argues that open AI security tools strengthen collective cyber defense and cautions that broad restrictions on open frontier AI could undermine those efforts.
Researchers say the operators behind the Golden Chickens malware-as-a-service platform have accepted.
expanded their toolkit with four new malware families.
According to Recorded Futures InSICT group,
the new families, Tiny Egg, Chunky Chicken,
a modularized Chunky Chicken variant,
and Chrome Egg Scalator
reflect a significant architectural evolution.
Tiny Egg acts as a lightweight back door for initial access,
while Chunky Chicken adds capabilities
such as browser credential theft
and live browser session control,
The modularized version introduces a plugin-based framework that can load 14 capabilities on demand, including key logging, screen capture, and process management.
Researchers say the move toward modular operator-controlled malware improves defense evasion, reduces detection risk, and offers customers more flexible capabilities within the malware-as-a-service ecosystem.
GitHub and the Python package index, Pi Pi, have introduced new time-based safeguards designed to reduce software supply chain risk.
GitHub's Dependibot now applies a default three-day delay notice before automatically recommending newly released package updates,
giving security researchers and maintainers more time to identify and remove malicious packages before they're widely adopted.
The delay is configurable.
and GitHub continues to recommend additional protections such as dependency pinning, restricted access
tokens, and limiting installation scripts. Meanwhile, Pi Pi will no longer allow maintainers to add new
files to package releases more than 14 days after publication. The change is intended to prevent
attackers from compromising trusted older releases, a technique known as release poisoning,
even though no confirmed Pi-Pi attacks have used that method to date.
Researchers at Confiant say the Sower Trade Malvertising Campaign
has adopted a new technique that builds malware directly inside a victim's browser to evade detection.
Active since 2024, the operation impersonates popular trading and cryptocurrency platforms,
including Trading View, Solana and Luno, to lure investors,
with fake trading tips and cryptocurrency giveaways.
Instead of delivering a complete malware file,
the malicious site sends assembly instructions,
downloads clean components from separate infrastructure,
and reconstructs the final infostealer in the browser's memory.
Because no complete malware file is transmitted over the network,
traditional file-based security tools are less likely to detect the attack.
Researchers say the approach allows sour trade to very,
the payload by victim or session, making the campaign more difficult to identify and disrupt.
Researchers at ReliaQuest warn that attackers are compromising public Wi-Fi gateway appliances
used for captive portal networks to steal Microsoft 365 credentials from traveling corporate employees.
Active since at least June, the campaign targets Wi-Fi systems at hotels, conference centers,
and other shared venues by altering DNS settings to redirect users to attacker-controlled infrastructure.
Using an adversary-in-the-middle technique, the attackers can intercept traffic and harvest login credentials,
rely a quest observed victims across multiple industries, including financial services,
health care, energy, and retail, suggesting broad targeting rather than a sector-specific campaign.
While the activity resembles the previously reported Frost Armada operation linked to APT-28,
researchers say differences in infrastructure and tactics indicate either a separate threat actor
or one reusing elements of APT-28's tradecraft.
Researchers at Halcyon warned that disabling endpoint detection and response or EDR tools
before encrypting systems has become standard practice.
for leading ransomware groups, significantly reducing defenders' response time.
The company's second quarter, 26, ransomware evolution report found that some groups,
including The Gentleman, now build EDR and antivirus shutdown capabilities directly into their
attack chains. Halcyon says the Gentleman has incorporated techniques from other major ransomware
families to improve encryption, code obfuscation, and security tool evasion.
Although publicly claimed ransomware attacks declined 5.7% during the quarter,
researchers observed increasingly sophisticated operations,
including rapid attacks, greater use of artificial intelligence throughout the attack chain,
and continued exploitation of enterprise edge vulnerabilities.
The report concludes that ransomware is becoming faster, more automated,
and more difficult to detect and contain.
Proofpoint says Russia-aligned threat actor TA488 exploited a previously unknown vulnerability in Zimbra Collaboration Suite mail servers for at least five months before it was patched.
The group also used a so-called half-click exploit, requiring victims only to open or preview a malicious email to trigger embedded code.
According to ProofPoint, the attacks targeted Ukrainian government organizations as well as U.S. government, defense, and scientific entities.
After gaining access, TA488 deployed malware dubbed Zim Reaper to steal credentials, establish persistent access, and exfiltrate emails from compromised accounts.
Researchers say the campaign relied on obfuscated JavaScript, DNS-based data exfiltration, and app-specific passwords.
to maintain access.
ProofPoint assesses the activity
is linked to Russian intelligence
and notes the Operation Unders
continued targeting of webmail platforms
for cyber espionage.
Turning to our Monday business briefing,
cybersecurity investment remained strong last week,
led by Israeli endpoint security startup glow,
which emerged from stealth
with $180 million to expand U.S. operations
and research.
Other major funding rounds included Neo with $100 million for Agentic Software Security,
risk ledger with $32.2 million for AI-enabled supply chain security,
20 with an additional $30 million for offensive cyber technology,
and empirical security with $25 million for predictive vulnerability management.
Smaller investments supported companies focused on security telemetry,
autonomous penetration testing, identity verification, post-quantum security, deep fake detection, email security,
and open-source software security. Mergers and acquisitions were also active, with Palo Alto Networks
announcing plans to acquire observability provider Embrace, Aura completing its acquisition of Coria,
and Veridas agreeing to merge with Fourth Line. Additional acquisitions by Ningio,
WebAsie and Amplex highlight continued industry consolidation as vendors broaden capabilities
across software security, identity, training, procurement, and digital risk management.
Be sure to check out our complete Cyberwire Pro business briefing. You can find that on our website.
Coming up after the break, my conversation with Krishna Sy, CTO at SolarWinds.
We're discussing security lessons learned from the work.
World Cup. And when the feed ends, the fun begins. Stay with us.
Krishna-Sai is Chief Technology Officer at Solar Winds. We recently got together to discuss some of
the security lessons to be learned from the World Cup. You know, whenever there's an event
like the World Cup, it is very exciting. You have millions of people now actively involved
in this. And if you think about where the lens of a modern enterprise IT teams, which has the challenge
of supporting all the infrastructure and operations that goes towards making an event like this very
successful, there are so many dimensions of that that happened, like folks are streaming matches,
using personal devices, accessing variety of cloud services to not only,
integrate and get themselves engaged with all the things that go on with a World Cup like event,
responding to messages, participating in social media. There's a lot of activity that happens.
All of those, of course, creates more traffic, but it also creates a lot of noise.
And, you know, when I wear my, say, security or IT ops angle, that becomes a great
environment for both a lot of excitement and energy, but also
creates unique challenges for the folks who have the responsibility to keep this infrastructure
alive so that an event like this can be successful. So there's a lot that goes on through
that where, especially when it comes to, from a security perspective, the ability to distinguish
excitement from all the challenges of congestions of networks, misconfiguration, fraud, active
attacks and so on. So there are a lot of positives and energies which we're all excited about,
but from an operations perspective, there's a lot of new challenges for IT and ops teams as well.
You know, one of the things I was thinking about in anticipation of our call was how,
because this is an event that happens every few years, does that mean that this is a team
that isn't working together all the time? But then I also thought, well, maybe this is one of
those situations where as soon as one event finishes, they're on the preparation schedule for
the next one, even though it's a few years down the road.
No, absolutely.
And what happens is that when you think about what it takes to support an event like
those in terms of systems and peoples and technology and processes, these are burst events,
right, like that happen and suddenly the infrastructure happened.
And then we see this in other places as well, when there's a sports event,
when there's a big music event as an example, our key celebrations and so on.
And that's where I think the system needs to have a lot of the core characteristics
that goes into being ready, so to speak, for an event like this, a plan for the next event.
That includes a variety of things, which includes systems, people, processes, and so on.
But IT systems, which are the infrastructure systems that need to support this, have like a few characteristics.
I mean, since we're talking about the World Cup, using an analogy like that, right, you need the ability to have observability, the ability to look at the whole fields like the way Messi does, as an example.
You need agility to be able to respond, elasticity as conditions change, like Lamain Imal as an example, right?
Or you need Ronaldo's like reliability and discipline where your systems and processes are matured, where you do have the ability to have an operationalize the system.
You need to be able to perform a game.
You need to have precision in being able to act on the right signals so that you can respond better.
So I think all of these types of things that happen, of course, it's a team sport, taking another soccer analogy, which means that in your systems, you need.
need to have lay it controls, have the right communication paradigms, have the right levels of
security overlays, whether it's related to identity or threat vectors and so on. But I think from a
system perspective, continually thinking about how the various aspects of your operations, network,
applications, cloud, identity, databases, signals, so that they all come together and form
this team sport is a very, very important aspect of how we're going to be.
you need to actually think and plan for events like these.
What are the lessons that enterprise defenders can take from this?
I think about things like resilience and availability, you know,
with a major event like this,
but those lessons can translate to the day-to-day of regular everyday folks.
100%, right?
Like, the core challenges have continually, if you think about IT teams,
that prepare for demand spikes and, you know, address visible.
gaps and not only during events like this, but just in day-to-day operations, these types of events
become forcing functions where teams can elevate their maturity levels or get prepared with
new tools and processes and so on. But essentially, the preparation is always the same,
which is identifying key business services that you need in your day-to-day services that cannot
fail, like what do you need to do to protect from a security perspective, identity, you know,
for organizations, VPN access, collaboration tools, customer phasing applications, and all the day-to-day
workloads that IT and ops teams have to manage, and then be able to have a view of ensuring that
you have complete visibility across the workloads that you need to manage and the
service and dependencies tied to business outcomes so that you're able to put the systems and
processes in place, whether that is observability tools or incident response tools or
be cloud operations tools, etc, that you need to be able to tackle ongoing challenges like
this. But at the end of the day, it all maps down to how teams are able to shape themselves
and mature themselves to be able to map business outcomes
to tried and tested methodologies
in terms of how you operationalize your IT and infrastructure across the board.
Well, let's extend the metaphor to building teams itself.
You know, folks have sometimes that they go out looking for superstars
or I think people refer to them sometimes as unicorns
when they're out there trying to find that perfect person to,
higher for their team. And that extends to athletics as well. But at the same team, at the same
time, rather, you need some balance there as well. Absolutely. I mean, and that's why I keep
reinforcing that this is a team sport. And we say this in the soccer field all the time. The superstars
are not only the ones that actually score the goals. But, you know, oftentimes it's the
assess that matter. Right. And we see,
this balance across teams as well.
And it's so important.
That's why I think having a good understanding of what the team shape is and how your team
actually comes together to tackle a business outcome, whether that is being able to respond
to an event like this in terms of supporting the bandwidth requirements for streaming an event
or dealing with how do you deal with fishing attacks that may increase as a result of an
event like this as part of your security team or being able to ensure that you have adequate
failover when systems fail to be able to respond to them quickly, whether that is through
automation or through incident response. Like all of these things essentially come together in
terms of how your teams are able to shape those business outcomes and have processes and
tools in place to be able to tackle them.
That's Krishna Sai from Solar Winds.
And finally, a week-long New York Festival called the Summer of Ludd set out to prove that meaningful community doesn't require social media, smartphones, or big tech platforms.
Organized entirely through phone hotlines, posters, bookstores, and word of mouth, the event featured phone-free raves, workshops, theatrical programs,
protests and plenty of handmade gnome hats.
One highlight was a mock trial of OpenAI and CEO Sam Altman, ending with participants gleefully
stomping a giant cardboard smartphone because apparently the cardboard had it coming.
Beneath the playful absurdity was a serious message, rebuild community through shared in-person
experiences rather than algorithm-driven feeds.
Organizers argued that public events, not viral posts, are the foundation of lasting social movements,
while acknowledging the challenge of resisting commercialization and digital capture,
the festival embraced joy over cynicism, suggesting that the most radical act in 2026 might
simply be showing up, looking around, and leaving your phone in your pocket.
And that's the Cyberwire.
For links to all of today's stories, check out our daily briefing at thecyberwire.com.
Don't forget to check out the grumpy old geeks podcast where I contribute to a regular segment on Jason and Brian's show every week.
You can find grumpy old geeks where all the fine podcasts are listed.
We'd love to know what you think of this podcast.
Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity.
If you like our show, please share a rating and review in your favorite podcast.
app. Please also fill out the survey in the show notes or send an email to Cyberwire at
n2k.com. N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and
sound design by Elliot Peltzman. Our contributing host is Maria Vermazas. Our executive producer is
Jennifer Ibin. Peter Kilpe is our publisher and I'm Dave Bittner. Thanks for listening. We'll see
you back here tomorrow. Heading to Black Hat USA, the N2K
Cyberwire team will be on-site recording from our podcast studio in the SpectorOps Kennel Club.
If you're interested in joining us for a conversation or learning more about what we're recording
throughout the week, stop by the studio and meet the N2K Cyberwire team.
SpectorOps's Kennel Club is adjacent to Libertine Social inside Mandalay Bay.
