CyberWire Daily - Water you waiting for?
Episode Date: August 3, 2026Cyberattacks hit U.S. water systems. CISA tackles open source security. China’s surveillance machine is exposed. Hotel Wi-Fi gets riskier. Healthcare and police data spill online. Fake SQLite vulner...abilities fool security databases. Monday business briefing. Our guest is Tim Starks from CyberScoop discussing the White House's quantum aspirations. AI is the hottest thing on campus. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tim Starks, Senior Reporter from CyberScoop, discussing the White House's quantum aspirations. Selected Reading Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran (The New York Times) CISA lays out new guidance for using open-source software (Help Net Security) How China Keeps Tabs on Foreigners (The New York Times) Microsoft Issues Hotel Wi-Fi Warning For Windows PC Users (Forbes) Exclusive: Partnered Health responds to Inc Ransom data breach claims (Cyber Daily) Security Flaw Placed 30 Years of DNA Evidence at Risk of Hacking (Wall Street Journal) SQLite Critical CVEs or LLM Slop? (JFrog Security Research) Details of 100,000 police staff leaked on the dark web after hack (The Times) ThreatLocker secures $190 million in a Series F round led by Elephant (N2K Pro Business Briefing) At colleges, the AI boom means everyone wants to dabble in computer science (AP News) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
AI is making fishing attacks faster, more convincing, and harder for people to spot,
and traditional security awareness and fishing training weren't designed for this level of attack.
Hawkshunt helps security teams prepare employees for the attacks they face every day,
with personalized fishing training that adapts to each employee and reduces risky behavior over time.
For IT and security leaders looking to strengthen their human layer of defense without adding more manual work, visit hoxhunt.com slash cyberwire to learn more.
That's hoxhunt.com slash cyberwire.
Cyber attacks hit U.S. water systems. Sisa tackles open source security.
China's surveillance machine is exposed. Hotel Wi-Fi gets a bit riskier.
healthcare and police data spill online, fake SQ light vulnerabilities, full security databases.
We got your Monday business briefing.
Our guest is Tim Starks from CyberSoup discussing the White House's quantum aspirations.
And AI is the hottest thing on campus.
It's Monday, August 3, 26.
I'm Dave Bittner, and this is your Cyberwire Intel briefing.
Thanks for joining us here today.
Happy Monday.
It's great to have you with us.
Cyber attacks targeting U.S. water systems have expanded to at least seven states, with officials
warning the campaign could be much broader. While no drinking water has been contaminated,
hackers have targeted internet-connected industrial control systems used to manage water quality,
chemical treatment, and pressure. Minnesota first disclosed the activity, and Michigan later
confirmed attacks affecting multiple municipal systems, though officials said,
there were no public health impacts.
Federal investigators consider Iran the leading suspect, citing an increase in Iranian cyberactivity
since the U.S. and Israel's war with Iran began, but they stress the attribution remains preliminary
and lacks definitive forensic proof. President Trump publicly disputed Iran's involvement,
while state and federal officials continued to treat Iranian actors as the most likely source.
SISA warned that water utilities of all sizes are at risk
and urged operators to disconnect vulnerable controllers from the Internet.
The incidents underscore long-standing concerns
about the cybersecurity of aging resource-constrained critical infrastructure.
SISA has released new guidance to help federal agencies securely adopt,
manage, and contribute to open-source software.
The recommendations emphasize evaluating OSS before,
deployment, maintaining inventories of software components, tracking dependencies, monitoring for
vulnerabilities, and applying patches promptly. SISA also encourages agencies to contribute
security fixes and improvements back to the open source community while ensuring sensitive
information is not exposed. For software developed by federal agencies, SISA recommends
planning for open source release where appropriate, following secure development practices,
and publishing supporting documentation and software bills of materials.
The guidance also addresses open source AI,
warning that artificial intelligence models lacking transparency
into their training data and development process
should be treated as proprietary software with incomplete provenance
and subjected to stricter risk management before deployment.
A cybersecurity researcher uncovered and unsecured Chinese surveillance
platform that appears to track thousands of foreigners in Zhang Jakao, revealing the breadth of China's
monitoring capabilities beyond its own citizens. The database contained detailed personal information,
including passport data, phone numbers, travel records, camera sightings, hospital visits, and social
connections. It categorized individuals by nationality, religion, and other attributes,
including foreign journalists, students, and residents from Hong Kong and Taiwan.
Evidence reviewed by the New York Times suggests the platform was developed for the
Zhang Jakao Public Security Bureau by surveillance technology firm Origin Dynamic.
Researchers said the exposed system highlights China's extensive integration of surveillance data
and weak privacy safeguards, with sensitive information left accessible online.
Experts warned the incident reflects a broader expansion of China's surveillance infrastructure
and the risks posed by poorly secured government systems.
Microsoft is warning organizations to treat hotel, airport, conference, and other public Wi-Fi networks as untrusted,
following the discovery of Captive Crunch, a global cyber campaign attributed to the Russian threat group Storm 2945,
a subgroup of Midnight Blizzard.
Active since May, the campaign compromises hospitality network infrastructure to present fake login pages,
software updates, and verification prompts that steal credentials or install malware.
In some cases, attackers abuse Microsoft's legitimate device code authentication process
to gain account access without stealing passwords.
Microsoft also found evidence that Android devices are being taught.
targeted with malicious app downloads.
The company says the attackers used artificial intelligence to support the campaign.
To reduce risk, Microsoft recommends using mobile hotspots or cellular connections
instead of public Wi-Fi, avoiding software updates through captive portals,
adopting fishing-resistant authentication and disabling device code authentication where it is not needed.
The timing is hard to miss with Black Hat and,
and DefCon just getting underway.
It's a fitting reminder that in Las Vegas,
not every suspicious network is part of the conference agenda.
Australian healthcare provider partnered health
is investigating claims by the Cyber Extortion Group Inc. Ransom
that it has stolen and published data from the organization's network.
The group says 11 files containing personal information
were posted on its dark net leak site,
though partnered health has obtained a court injunction,
restricting access to the data while investigators access its authenticity,
which seems aspirational.
The incident stems from a cyber attack disclosed in July that occurred on June 23rd,
with additional patients and employees now believed to be affected.
Partnered health has notified impacted individuals
and reported the incident to Australian authorities.
Security experts warns,
the breach highlights the growing cyber risks facing healthcare organizations
and advise patients to be vigilant for fishing attempts and fraudulent communications
using potentially stolen personal information.
Researchers at the University of New Haven have identified a high-severity security vulnerability
affecting DNA analysis software widely used in U.S. crime laboratories,
potentially exposing digital forensic records dating back,
to 1995 to undetectable tampering. The flaw could allow an attacker with access to a lab's systems
to alter DNA analysis files without leaving evidence of modification, raising concerns about the
integrity of digital forensic evidence. Researchers demonstrated the attack using AI-assisted code
and publicly available decryption keys, though there is no evidence the vulnerability has
been exploited in real cases. After being notified, Thermo Fisher Scientific acknowledged the issue,
worked with SISA, and released a software update that adds digital signatures to help verify
file integrity. Experts say the findings highlight the need for stronger cybersecurity protections
in forensic laboratories. Security researchers at JFrog say dozens of recently published
SQ-Lite Vulnerability Advisories appear to be fabricated, likely generated by large language
models, despite being assigned CVE identifiers and initially receiving high severity ratings
from the National Vulnerability Database and other sources. After analyzing six reported
SQ-Lite flaws, researchers found the advisories referenced non-existent functions, incorrect line numbers,
invalid proof-of-concept exploits and fixes that never existed. None of the vulnerabilities
appeared on SQ Lite's official advisory page, and testing failed to reproduce the claimed issues.
J-Frog warns the incident exposes weaknesses in the current CVE ecosystem, where unverified
submissions can propagate through vulnerability databases and automated security tools.
The researchers recommend validating high-impact CVEs.
against vendor advisories, source code, and reproducible exploits before prioritizing remediation,
particularly as AI-generated content becomes more prevalent.
A cyber attack in the UK's Police National Legal Database has exposed the names and contact
details of roughly 100,000 police officers on the dark web, raising serious safety concerns
for law enforcement personnel.
Authorities believe the Hacking Group X-Fill Squad was responsible as part of a broader campaign targeting UK government agencies, including the Ministry of Defense, Home Office, National Crime Agency, and Crown Prosecution Service.
The breach follows a separate attack on the Department for Education that exposed more than half a million records.
Affected officers say the leak increases personal security risks, particularly for those involved in Orrador's.
organized crime investigations.
Turning to our Monday business briefing,
cybersecurity and AI companies announced a wave of funding
and acquisition activity this past week,
led by Threat Lockers $190 million Series F to expand its zero-trust platform.
Other notable funding rounds included Act Security with $60 million,
Aegis AI at $36 million, Harmony AI with $34 million,
Hush security with 30 million, abstract with 25 million, copy site with 3 million, and
Frenos with $1.5 million, with investment focused on cloud security, identity management,
AI-powered security operations, and enterprise automation.
On the mergers and acquisitions front, CYERA agreed to acquire identity security startup
Oasis security for $1 billion to combine data and identity protection.
Leonardo DRS announced a $450 million acquisition of mission software provider RAFT,
while Key Factor plans to acquire UK-based identity security firm COFID to strengthen AI trust infrastructure.
VENA Solutions also announced plans to acquire Enterprise AI platform Morphio AI to enhance its AI capabilities.
Be sure to check out our business briefing on our web,
website that is part of CyberWire Pro.
Coming up after the break, Tim Starks from CyberScoop discusses the White House's quantum aspirations,
and AI is the hottest thing on campus.
Stay with us.
What's the one thing in business that's spreading as fast as AI?
AI risk.
Every new tool your team signs up for, every vendor that turns on AI features, every new integration,
each one is another opportunity for something to go wrong.
And most security programs weren't built to keep up with AI's pace of growth.
Enter Vanta.
Vanta is the number one agentic trust platform,
trusted by more than 16,000 fast-moving companies like Ramp, Hursor, and Harvey to help them stay audit-ready.
And now Vanta helps companies like yours keep an eye on the risks that appear between audits
across your vendors, your AI tools, and your entire environment.
The Vanta agent works like a 24-4.
47 GRC engineer in the background.
It finds issues, drafts, fixes for you, and can cut vendor assessment time by up to 50%.
Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust.
Get started today at vanta.com slash cyber.
That's V-A-N-T-A-com slash cyber.
It is my pleasure to welcome back to the show.
Tim Starks, he is a senior reporter at CyberScoop.
Tim, welcome back.
Hey, good to be back.
Looking at this recent article you wrote for CyberScoop,
this is about the supply chain challenges that may loom large in the quantum race,
according to some folks from the White House.
What's going on here, Tim?
Yeah, we got some rare comments from someone we haven't heard much from publicly
named Brad Blakestack.
He's the director of the National Quantum Coordination Office that is housed within the White House Office of Science and Technology Policy.
If you're following me, that's a long title.
But the idea is, you know, he's someone who is, you know, was supposed to coordinate all the quantum efforts that are happening on cyber.
And he talked about some of the big challenges for dealing with all the things that are happening on quantum.
For cyber listeners or readers, obviously the issue of quantum computing looms large.
But one of the things he said that jumped out at us was talking about how the supply chain is one of the biggest challenges here.
How so?
What he was saying was there's no easy way to do quantum all in one place.
So there's not like one single hardware platform.
There's different technologies for quantum computing, for quantum sensing.
They're all completely different.
You have people who make these different components over here for this kind of quantum,
for this other kind of quantum.
And it ends up being so diffuse that it's hard to bring it all together and make it so that you're building everything in a unified way.
You know, specifically there was the issue he was disenfranchised.
discussing about that there's not just this diffuseness, but there's also just not a lot of it at all,
that you have not enough quite economic demand yet or marketplace dynamics to make it so that
people want to be getting into manufacturing widgets, quantum widgets, let's call them.
Every time I talk about this subject, I think of, I think of, it might have been a Rick and Morty
episode where they're like, you can't just call something quantum and assume that that makes it
science fiction now.
Right.
Right.
Quantum in front of everything, but I'm kind of doing it in this
conversation.
Anyway, he's saying, you know, that there's not this kind of base that we have
for other kinds of things, that, you know, the supply chain that can really
reliably start producing things.
And that that's one of the really biggest fundamental challenges he's facing and that
they're trying to address in this administration.
They've had a couple executive orders on quantum in June.
It was interesting to hear from him on this and how they're trying to get to
the very fundamental building blocks of quantum
and trying to make sure that it can be a thing
that gets going at all.
Yeah. I'm curious, you know,
you mentioned the funding issue.
Isn't that just the kind of thing
that a federal government should be able to fund
that sort of pure research
to get us across the finish line?
Conceivably, yes, it's something
that the federal government could be doing.
And he did mention one kind of role
where the government could do that,
where they can say,
we'd like you to make the,
He literally used the word widgets, so I'm not, if I used it earlier, I was not being facetious.
Make these things to our specifications, and we will buy them.
And so that could be a way that that could happen.
He did talk about funding limitations.
You know, this administration has downsized federal government funding significantly in lots of ways and lots of places.
He mentioned the ideas of things like prize challenges and other ways to kind of incentivize the market to get going.
Was there any kind of call to action from him for industry?
Hmm, was there?
No, not really.
I would say not really.
It wasn't that he was, you know, saying that they shouldn't do anything,
but he wasn't saying, here's a list of things we want you to do.
Yeah, more of a state of the union kind of address, perhaps.
Yeah, it was really meant more to be like,
these are the things where we are looking to do.
You know, he talked about trying to do things to make it.
So just if anything, the closest he might have come to that is saying,
The U.S. needs to own this issue, if you will.
One of the things that there has been a discussion about out there in the sort of think tanking
community and people who research this stuff is that this is, the supply chain is not just
a U.S. diffusion problem.
It's an international diffusion problem that we're relying on parts from China, from Iran.
And it's not like there's one country that's dominating this.
And I think if there was one kind of call, it was like the U.S. needs to dominate this.
we need to be such that we're the place where this all starts,
that this is the foundation of it all,
and this is where other countries turn to us.
So I think that would be the closest thing to a call to industry.
He really was kind of giving an overarching view of what the administration is working on on this
and talking about what makes it a challenge among the things were supply chain.
But we talk about encryption, of course.
One of the things it was fascinating about the speeches of well to me that I didn't mention in the story
is that I think when I, as a reporter cover Cyber,
think about quantum computing,
I think about encryption,
I think about breaking encryption.
He was talking about that as important and meaningful,
but also he said,
candidly, we're more enthused about the economic impacts
of quantum computing and other quantum technologies,
that that's where they're focused on the economic gains of this,
less so the national security risks.
Not that he was saying that it didn't exist,
but that he was,
that was a point of emphasis for the administration.
That being the leader in that realm could be of great advantage to the U.S. economically?
Not just that, but also that the technological advances that could be unlocked by quantum
could be something that we see with things like being able to break down things from,
like being able to approach pharmaceuticals, other kinds of industries,
and use the advances of quantum technology to really push forward the technology.
and other areas. I see. Well, watching his presentation, was your sense that it was one of
optimism? Yes, it was, I would say. Obviously, a lot of people, you know, who are in this
administration talk up the president and what he's doing is unique here. I think this might be a
case where that's the case. I mean, certainly quantum technology has been an emphasis for other
administrations, but I don't know that we've seen this kind of high-level attention from it. And I think
that that is something that he was optimistic about from the standpoint of saying,
look, this is something we're really focusing on. This is something we really want to do.
And I think that some credit is due to the administration for making that a big point of this.
Yeah.
All right. Well, Tim Starks is senior reporter at CyberScoop.
Tim, thanks so much for taking the time for us.
Thank you.
And finally, artificial intelligence is reshaping higher education in unexpected ways,
As demand for traditional computer science degrees cools and entry-level coding jobs face pressure from AI,
colleges are finding growing interest from students who never planned to study computer science in the first place.
Psychology majors, musicians, biologists, and business students are adding AI minors, certificates,
and courses to build what universities increasingly view as a fundamental workplace skill.
schools are responding with AI literacy requirements, new interdisciplinary programs, and faster course
development, reflecting the technology's rapid evolution.
Educators argue that understanding AI is becoming as essential as reading or basic math,
even as they caution against over-reliance on the technology.
The irony is hard to miss.
AI may be writing some code that once justified a computer scientist,
degree, but it's also convincing students across nearly every other discipline that they need
to learn enough about it to keep up. And that's the Cyberwire. For links to all of today's stories,
check out our daily briefing at the Cyberwire.com. We're recording on site at Black Hat this
Wednesday and Thursday from our podcast studio in the SpectorOps Kennel Club. If you'd like to
meet the N2K Cyberwire team, make sure you stop by the studio.
We'd love to know what you think of this podcast.
Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity.
If you like our show, please share a rating and review in your favorite podcast app.
Please also fill out the survey in the show notes or send an email to Cyberwire at N2K.com.
N2K's lead producer is Liz Stokes.
We're mixed by Trey Hester with original music and sound design by Elliot Heltsman.
Our contributing host is Maria Vermazes.
Our executive producer is Jennifer Ibn.
Peter Kilpe is our publisher, and I'm Dave Bittner.
Thanks for listening.
We'll see you back here tomorrow.
