CyberWire Daily - The world's least private hackers.

Episode Date: July 27, 2026

Hackers target Thailand’s Ministry of Finance with an autonomous AI agent.A new industry alliance hopes to improve AI security. Golden Chickens lay four new malware families. GitHub and PyPI introdu...ce time-based safeguards. SourTrade malvertising builds malware directly inside a victim’s browser. Attackers target credentials of traveling corporate employees. EDR shutdown is now par for the course for leading ransomware groups. Russian threat actors exploited a Zimbra vulnerability for at least five months before it was patched. Monday business briefing. Our guest is Krishna Sai, CTO at SolarWinds, with security lessons learned from the World Cup. When the feed ends, the fun begins.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Krishna Sai, CTO at SolarWinds, discussing the security risks around the World Cup and how this affects IT teams as they try to manage the growing digital traffic sprawl surrounding the event. Selected Reading Hackers used autonomous AI agent to spy on Thailand's finance ministry (The Record) Nvidia and Tech Giants Launch AI Security Alliance (SecurityWeek) Golden Chickens malware-as-a-service resurfaces with four new families (SC Media) GitHub, PyPI add time-based defenses against supply chain attacks (Bleeping Computer) SourTrade Malvertising Campaign Secretly Builds Malware in the Browser (Infosecurity Magazine) Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials (SecurityWeek) Ransomware Groups Increasingly Deploy EDR Kill Techniques (Infosecurity Magazine) TA488 Targets Zimbra Mailservers with Half-Click Exploits IProofpoint) Endpoint security firm Glow emerges from stealth with $180 million. (N2K Pro Business Briefing) Being a Luddite Is Fun Again (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. This episode is supported by Black Hat USA. If you follow the research, you know a lot of it breaks on Black Hat stages. Hundreds of peer-reviewed briefings, more than 100 hands-on trainings, and the largest business hall in Black Hat's history. Six days to learn the skills you'll need tomorrow. August 1st to the 6th. Use code Cyberwire for $200 off your briefings pass.
Starting point is 00:00:36 at blackhat.com. We'll see you in Vegas. If you're heading to Black Hat USA this year, make plans to visit the SpectorOps Kennel Club. As creators of Bloodhound, the SpectorOps team will host talks with OpenAI and the UK AI Security Institute, as well as hands-on workshops
Starting point is 00:01:04 aimed at helping you understand AI accelerated attack paths and the latest in identity tradecraft. Visit Spectorops.io to pre-register and learn more. Spector Ops Kennel Club is adjacent to Libertine Social inside Mandalay Bay. While you're there, visit the N2K Cyberwire podcast studio, where we'll be capturing expert perspectives and conversations from across Black Hat. Packers target Thailand's Ministry of Finance. A new industry alliance hopes to improve AI security,
Starting point is 00:01:52 Golden Chickens lay four new malware families, GitHub and Pi Pi-Pai introduced time-based safeguards. Sower trade malvertising builds malware directly inside a victim's browser. Attackers target credentials of traveling corporate employees. EDR shutdown is now par for the course for leading ransomware groups.
Starting point is 00:02:12 Russian threat actors exploit a Zimbra vulnerability for at least five months before it was patched. We've got your Monday business briefing. Our guest is Krishna Sy, CTO at Solar Winds, with security lessons learned from the World Cup. And when the feed ends,
Starting point is 00:02:27 the fun begins. It's Monday, July 27th, 2026. I'm Dave Bittner, and this is your Cyberwire Intel Briefing. Thanks for joining us here today. It's great as always to have you with us. Researchers at Hunt I.O. say hackers used an autonomous artificial agent during an apparent cyber espionage campaign
Starting point is 00:03:14 targeting Thailand's Ministry of Finance. While the intrusion was underway, the attackers accidentally exposed hundreds of files on their own infrastructure, giving researchers an unusual look inside the operation. The files included malware, stolen credentials, attack scripts, AI agent logs, and evidence that multiple ministry systems had already been compromised. Hunt I.O. said the attackers relied heavily on Ermes, an open-source AI agent configured to execute to execute commands without human approval.
Starting point is 00:03:49 The agent autonomously explored the ministry's network, gathered system information, and searched for ways to escalate privileges. Although researchers found no evidence of data exfiltration, the activity appears focused on reconnaissance, credential theft, and preparing for future operations. Hunt I.O. has not attributed the campaign, but said several indicators suggest the operators were Chinese-speaking. Invidia and dozens of technology, cybersecurity, and enterprise software companies have launched the OpenSecure AI Alliance,
Starting point is 00:04:27 a new initiative focused on developing and sharing open source tools, models, and techniques to improve AI security. The effort builds on work from the Linux Foundation's Accretes Initiative and the Open Source Security Foundation. founding members include major industry players such as Microsoft, IBM, Cisco, CrowdStrike, Palo Alto Networks, and Hugging Face. The Alliance argues that open AI security tools strengthen collective cyber defense and cautions that broad restrictions on open frontier AI could undermine those efforts. Researchers say the operators behind the Golden Chickens malware-as-a-service platform have accepted. expanded their toolkit with four new malware families. According to Recorded Futures InSICT group, the new families, Tiny Egg, Chunky Chicken,
Starting point is 00:05:23 a modularized Chunky Chicken variant, and Chrome Egg Scalator reflect a significant architectural evolution. Tiny Egg acts as a lightweight back door for initial access, while Chunky Chicken adds capabilities such as browser credential theft and live browser session control, The modularized version introduces a plugin-based framework that can load 14 capabilities on demand, including key logging, screen capture, and process management.
Starting point is 00:05:55 Researchers say the move toward modular operator-controlled malware improves defense evasion, reduces detection risk, and offers customers more flexible capabilities within the malware-as-a-service ecosystem. GitHub and the Python package index, Pi Pi, have introduced new time-based safeguards designed to reduce software supply chain risk. GitHub's Dependibot now applies a default three-day delay notice before automatically recommending newly released package updates, giving security researchers and maintainers more time to identify and remove malicious packages before they're widely adopted. The delay is configurable. and GitHub continues to recommend additional protections such as dependency pinning, restricted access tokens, and limiting installation scripts. Meanwhile, Pi Pi will no longer allow maintainers to add new files to package releases more than 14 days after publication. The change is intended to prevent
Starting point is 00:07:01 attackers from compromising trusted older releases, a technique known as release poisoning, even though no confirmed Pi-Pi attacks have used that method to date. Researchers at Confiant say the Sower Trade Malvertising Campaign has adopted a new technique that builds malware directly inside a victim's browser to evade detection. Active since 2024, the operation impersonates popular trading and cryptocurrency platforms, including Trading View, Solana and Luno, to lure investors, with fake trading tips and cryptocurrency giveaways. Instead of delivering a complete malware file,
Starting point is 00:07:44 the malicious site sends assembly instructions, downloads clean components from separate infrastructure, and reconstructs the final infostealer in the browser's memory. Because no complete malware file is transmitted over the network, traditional file-based security tools are less likely to detect the attack. Researchers say the approach allows sour trade to very, the payload by victim or session, making the campaign more difficult to identify and disrupt. Researchers at ReliaQuest warn that attackers are compromising public Wi-Fi gateway appliances
Starting point is 00:08:22 used for captive portal networks to steal Microsoft 365 credentials from traveling corporate employees. Active since at least June, the campaign targets Wi-Fi systems at hotels, conference centers, and other shared venues by altering DNS settings to redirect users to attacker-controlled infrastructure. Using an adversary-in-the-middle technique, the attackers can intercept traffic and harvest login credentials, rely a quest observed victims across multiple industries, including financial services, health care, energy, and retail, suggesting broad targeting rather than a sector-specific campaign. While the activity resembles the previously reported Frost Armada operation linked to APT-28, researchers say differences in infrastructure and tactics indicate either a separate threat actor
Starting point is 00:09:16 or one reusing elements of APT-28's tradecraft. Researchers at Halcyon warned that disabling endpoint detection and response or EDR tools before encrypting systems has become standard practice. for leading ransomware groups, significantly reducing defenders' response time. The company's second quarter, 26, ransomware evolution report found that some groups, including The Gentleman, now build EDR and antivirus shutdown capabilities directly into their attack chains. Halcyon says the Gentleman has incorporated techniques from other major ransomware families to improve encryption, code obfuscation, and security tool evasion.
Starting point is 00:10:03 Although publicly claimed ransomware attacks declined 5.7% during the quarter, researchers observed increasingly sophisticated operations, including rapid attacks, greater use of artificial intelligence throughout the attack chain, and continued exploitation of enterprise edge vulnerabilities. The report concludes that ransomware is becoming faster, more automated, and more difficult to detect and contain. Proofpoint says Russia-aligned threat actor TA488 exploited a previously unknown vulnerability in Zimbra Collaboration Suite mail servers for at least five months before it was patched. The group also used a so-called half-click exploit, requiring victims only to open or preview a malicious email to trigger embedded code.
Starting point is 00:10:55 According to ProofPoint, the attacks targeted Ukrainian government organizations as well as U.S. government, defense, and scientific entities. After gaining access, TA488 deployed malware dubbed Zim Reaper to steal credentials, establish persistent access, and exfiltrate emails from compromised accounts. Researchers say the campaign relied on obfuscated JavaScript, DNS-based data exfiltration, and app-specific passwords. to maintain access. ProofPoint assesses the activity is linked to Russian intelligence and notes the Operation Unders continued targeting of webmail platforms
Starting point is 00:11:36 for cyber espionage. Turning to our Monday business briefing, cybersecurity investment remained strong last week, led by Israeli endpoint security startup glow, which emerged from stealth with $180 million to expand U.S. operations and research. Other major funding rounds included Neo with $100 million for Agentic Software Security,
Starting point is 00:12:02 risk ledger with $32.2 million for AI-enabled supply chain security, 20 with an additional $30 million for offensive cyber technology, and empirical security with $25 million for predictive vulnerability management. Smaller investments supported companies focused on security telemetry, autonomous penetration testing, identity verification, post-quantum security, deep fake detection, email security, and open-source software security. Mergers and acquisitions were also active, with Palo Alto Networks announcing plans to acquire observability provider Embrace, Aura completing its acquisition of Coria, and Veridas agreeing to merge with Fourth Line. Additional acquisitions by Ningio,
Starting point is 00:12:53 WebAsie and Amplex highlight continued industry consolidation as vendors broaden capabilities across software security, identity, training, procurement, and digital risk management. Be sure to check out our complete Cyberwire Pro business briefing. You can find that on our website. Coming up after the break, my conversation with Krishna Sy, CTO at SolarWinds. We're discussing security lessons learned from the work. World Cup. And when the feed ends, the fun begins. Stay with us. Krishna-Sai is Chief Technology Officer at Solar Winds. We recently got together to discuss some of the security lessons to be learned from the World Cup. You know, whenever there's an event
Starting point is 00:14:04 like the World Cup, it is very exciting. You have millions of people now actively involved in this. And if you think about where the lens of a modern enterprise IT teams, which has the challenge of supporting all the infrastructure and operations that goes towards making an event like this very successful, there are so many dimensions of that that happened, like folks are streaming matches, using personal devices, accessing variety of cloud services to not only, integrate and get themselves engaged with all the things that go on with a World Cup like event, responding to messages, participating in social media. There's a lot of activity that happens. All of those, of course, creates more traffic, but it also creates a lot of noise.
Starting point is 00:14:58 And, you know, when I wear my, say, security or IT ops angle, that becomes a great environment for both a lot of excitement and energy, but also creates unique challenges for the folks who have the responsibility to keep this infrastructure alive so that an event like this can be successful. So there's a lot that goes on through that where, especially when it comes to, from a security perspective, the ability to distinguish excitement from all the challenges of congestions of networks, misconfiguration, fraud, active attacks and so on. So there are a lot of positives and energies which we're all excited about, but from an operations perspective, there's a lot of new challenges for IT and ops teams as well.
Starting point is 00:15:48 You know, one of the things I was thinking about in anticipation of our call was how, because this is an event that happens every few years, does that mean that this is a team that isn't working together all the time? But then I also thought, well, maybe this is one of those situations where as soon as one event finishes, they're on the preparation schedule for the next one, even though it's a few years down the road. No, absolutely. And what happens is that when you think about what it takes to support an event like those in terms of systems and peoples and technology and processes, these are burst events,
Starting point is 00:16:29 right, like that happen and suddenly the infrastructure happened. And then we see this in other places as well, when there's a sports event, when there's a big music event as an example, our key celebrations and so on. And that's where I think the system needs to have a lot of the core characteristics that goes into being ready, so to speak, for an event like this, a plan for the next event. That includes a variety of things, which includes systems, people, processes, and so on. But IT systems, which are the infrastructure systems that need to support this, have like a few characteristics. I mean, since we're talking about the World Cup, using an analogy like that, right, you need the ability to have observability, the ability to look at the whole fields like the way Messi does, as an example.
Starting point is 00:17:19 You need agility to be able to respond, elasticity as conditions change, like Lamain Imal as an example, right? Or you need Ronaldo's like reliability and discipline where your systems and processes are matured, where you do have the ability to have an operationalize the system. You need to be able to perform a game. You need to have precision in being able to act on the right signals so that you can respond better. So I think all of these types of things that happen, of course, it's a team sport, taking another soccer analogy, which means that in your systems, you need. need to have lay it controls, have the right communication paradigms, have the right levels of security overlays, whether it's related to identity or threat vectors and so on. But I think from a system perspective, continually thinking about how the various aspects of your operations, network,
Starting point is 00:18:15 applications, cloud, identity, databases, signals, so that they all come together and form this team sport is a very, very important aspect of how we're going to be. you need to actually think and plan for events like these. What are the lessons that enterprise defenders can take from this? I think about things like resilience and availability, you know, with a major event like this, but those lessons can translate to the day-to-day of regular everyday folks. 100%, right?
Starting point is 00:18:47 Like, the core challenges have continually, if you think about IT teams, that prepare for demand spikes and, you know, address visible. gaps and not only during events like this, but just in day-to-day operations, these types of events become forcing functions where teams can elevate their maturity levels or get prepared with new tools and processes and so on. But essentially, the preparation is always the same, which is identifying key business services that you need in your day-to-day services that cannot fail, like what do you need to do to protect from a security perspective, identity, you know, for organizations, VPN access, collaboration tools, customer phasing applications, and all the day-to-day
Starting point is 00:19:36 workloads that IT and ops teams have to manage, and then be able to have a view of ensuring that you have complete visibility across the workloads that you need to manage and the service and dependencies tied to business outcomes so that you're able to put the systems and processes in place, whether that is observability tools or incident response tools or be cloud operations tools, etc, that you need to be able to tackle ongoing challenges like this. But at the end of the day, it all maps down to how teams are able to shape themselves and mature themselves to be able to map business outcomes to tried and tested methodologies
Starting point is 00:20:20 in terms of how you operationalize your IT and infrastructure across the board. Well, let's extend the metaphor to building teams itself. You know, folks have sometimes that they go out looking for superstars or I think people refer to them sometimes as unicorns when they're out there trying to find that perfect person to, higher for their team. And that extends to athletics as well. But at the same team, at the same time, rather, you need some balance there as well. Absolutely. I mean, and that's why I keep reinforcing that this is a team sport. And we say this in the soccer field all the time. The superstars
Starting point is 00:21:04 are not only the ones that actually score the goals. But, you know, oftentimes it's the assess that matter. Right. And we see, this balance across teams as well. And it's so important. That's why I think having a good understanding of what the team shape is and how your team actually comes together to tackle a business outcome, whether that is being able to respond to an event like this in terms of supporting the bandwidth requirements for streaming an event or dealing with how do you deal with fishing attacks that may increase as a result of an
Starting point is 00:21:43 event like this as part of your security team or being able to ensure that you have adequate failover when systems fail to be able to respond to them quickly, whether that is through automation or through incident response. Like all of these things essentially come together in terms of how your teams are able to shape those business outcomes and have processes and tools in place to be able to tackle them. That's Krishna Sai from Solar Winds. And finally, a week-long New York Festival called the Summer of Ludd set out to prove that meaningful community doesn't require social media, smartphones, or big tech platforms. Organized entirely through phone hotlines, posters, bookstores, and word of mouth, the event featured phone-free raves, workshops, theatrical programs,
Starting point is 00:22:56 protests and plenty of handmade gnome hats. One highlight was a mock trial of OpenAI and CEO Sam Altman, ending with participants gleefully stomping a giant cardboard smartphone because apparently the cardboard had it coming. Beneath the playful absurdity was a serious message, rebuild community through shared in-person experiences rather than algorithm-driven feeds. Organizers argued that public events, not viral posts, are the foundation of lasting social movements, while acknowledging the challenge of resisting commercialization and digital capture, the festival embraced joy over cynicism, suggesting that the most radical act in 2026 might
Starting point is 00:23:44 simply be showing up, looking around, and leaving your phone in your pocket. And that's the Cyberwire. For links to all of today's stories, check out our daily briefing at thecyberwire.com. Don't forget to check out the grumpy old geeks podcast where I contribute to a regular segment on Jason and Brian's show every week. You can find grumpy old geeks where all the fine podcasts are listed. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast.
Starting point is 00:24:28 app. Please also fill out the survey in the show notes or send an email to Cyberwire at n2k.com. N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazas. Our executive producer is Jennifer Ibin. Peter Kilpe is our publisher and I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow. Heading to Black Hat USA, the N2K Cyberwire team will be on-site recording from our podcast studio in the SpectorOps Kennel Club. If you're interested in joining us for a conversation or learning more about what we're recording throughout the week, stop by the studio and meet the N2K Cyberwire team.
Starting point is 00:25:37 SpectorOps's Kennel Club is adjacent to Libertine Social inside Mandalay Bay.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.