CyberWire Daily - Water you waiting for?

Episode Date: August 3, 2026

Cyberattacks hit U.S. water systems. CISA tackles open source security. China’s surveillance machine is exposed. Hotel Wi-Fi gets riskier. Healthcare and police data spill online. Fake SQLite vulner...abilities fool security databases. Monday business briefing. Our guest is Tim Starks from CyberScoop discussing the White House's quantum aspirations. AI is the hottest thing on campus. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tim Starks, Senior Reporter from CyberScoop, discussing the White House's quantum aspirations. Selected Reading Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran (The New York Times) CISA lays out new guidance for using open-source software (Help Net Security) How China Keeps Tabs on Foreigners (The New York Times) Microsoft Issues Hotel Wi-Fi Warning For Windows PC Users (Forbes) Exclusive: Partnered Health responds to Inc Ransom data breach claims (Cyber Daily) Security Flaw Placed 30 Years of DNA Evidence at Risk of Hacking (Wall Street Journal) SQLite Critical CVEs or LLM Slop? (JFrog Security Research) Details of 100,000 police staff leaked on the dark web after hack (The Times) ThreatLocker secures $190 million in a Series F round led by Elephant (N2K Pro Business Briefing) At colleges, the AI boom means everyone wants to dabble in computer science (AP News) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. AI is making fishing attacks faster, more convincing, and harder for people to spot, and traditional security awareness and fishing training weren't designed for this level of attack. Hawkshunt helps security teams prepare employees for the attacks they face every day, with personalized fishing training that adapts to each employee and reduces risky behavior over time. For IT and security leaders looking to strengthen their human layer of defense without adding more manual work, visit hoxhunt.com slash cyberwire to learn more. That's hoxhunt.com slash cyberwire. Cyber attacks hit U.S. water systems. Sisa tackles open source security.
Starting point is 00:01:09 China's surveillance machine is exposed. Hotel Wi-Fi gets a bit riskier. healthcare and police data spill online, fake SQ light vulnerabilities, full security databases. We got your Monday business briefing. Our guest is Tim Starks from CyberSoup discussing the White House's quantum aspirations. And AI is the hottest thing on campus. It's Monday, August 3, 26. I'm Dave Bittner, and this is your Cyberwire Intel briefing. Thanks for joining us here today.
Starting point is 00:02:12 Happy Monday. It's great to have you with us. Cyber attacks targeting U.S. water systems have expanded to at least seven states, with officials warning the campaign could be much broader. While no drinking water has been contaminated, hackers have targeted internet-connected industrial control systems used to manage water quality, chemical treatment, and pressure. Minnesota first disclosed the activity, and Michigan later confirmed attacks affecting multiple municipal systems, though officials said, there were no public health impacts.
Starting point is 00:02:47 Federal investigators consider Iran the leading suspect, citing an increase in Iranian cyberactivity since the U.S. and Israel's war with Iran began, but they stress the attribution remains preliminary and lacks definitive forensic proof. President Trump publicly disputed Iran's involvement, while state and federal officials continued to treat Iranian actors as the most likely source. SISA warned that water utilities of all sizes are at risk and urged operators to disconnect vulnerable controllers from the Internet. The incidents underscore long-standing concerns about the cybersecurity of aging resource-constrained critical infrastructure.
Starting point is 00:03:32 SISA has released new guidance to help federal agencies securely adopt, manage, and contribute to open-source software. The recommendations emphasize evaluating OSS before, deployment, maintaining inventories of software components, tracking dependencies, monitoring for vulnerabilities, and applying patches promptly. SISA also encourages agencies to contribute security fixes and improvements back to the open source community while ensuring sensitive information is not exposed. For software developed by federal agencies, SISA recommends planning for open source release where appropriate, following secure development practices,
Starting point is 00:04:14 and publishing supporting documentation and software bills of materials. The guidance also addresses open source AI, warning that artificial intelligence models lacking transparency into their training data and development process should be treated as proprietary software with incomplete provenance and subjected to stricter risk management before deployment. A cybersecurity researcher uncovered and unsecured Chinese surveillance platform that appears to track thousands of foreigners in Zhang Jakao, revealing the breadth of China's
Starting point is 00:04:52 monitoring capabilities beyond its own citizens. The database contained detailed personal information, including passport data, phone numbers, travel records, camera sightings, hospital visits, and social connections. It categorized individuals by nationality, religion, and other attributes, including foreign journalists, students, and residents from Hong Kong and Taiwan. Evidence reviewed by the New York Times suggests the platform was developed for the Zhang Jakao Public Security Bureau by surveillance technology firm Origin Dynamic. Researchers said the exposed system highlights China's extensive integration of surveillance data and weak privacy safeguards, with sensitive information left accessible online.
Starting point is 00:05:39 Experts warned the incident reflects a broader expansion of China's surveillance infrastructure and the risks posed by poorly secured government systems. Microsoft is warning organizations to treat hotel, airport, conference, and other public Wi-Fi networks as untrusted, following the discovery of Captive Crunch, a global cyber campaign attributed to the Russian threat group Storm 2945, a subgroup of Midnight Blizzard. Active since May, the campaign compromises hospitality network infrastructure to present fake login pages, software updates, and verification prompts that steal credentials or install malware. In some cases, attackers abuse Microsoft's legitimate device code authentication process
Starting point is 00:06:31 to gain account access without stealing passwords. Microsoft also found evidence that Android devices are being taught. targeted with malicious app downloads. The company says the attackers used artificial intelligence to support the campaign. To reduce risk, Microsoft recommends using mobile hotspots or cellular connections instead of public Wi-Fi, avoiding software updates through captive portals, adopting fishing-resistant authentication and disabling device code authentication where it is not needed. The timing is hard to miss with Black Hat and,
Starting point is 00:07:09 and DefCon just getting underway. It's a fitting reminder that in Las Vegas, not every suspicious network is part of the conference agenda. Australian healthcare provider partnered health is investigating claims by the Cyber Extortion Group Inc. Ransom that it has stolen and published data from the organization's network. The group says 11 files containing personal information were posted on its dark net leak site,
Starting point is 00:07:37 though partnered health has obtained a court injunction, restricting access to the data while investigators access its authenticity, which seems aspirational. The incident stems from a cyber attack disclosed in July that occurred on June 23rd, with additional patients and employees now believed to be affected. Partnered health has notified impacted individuals and reported the incident to Australian authorities. Security experts warns,
Starting point is 00:08:07 the breach highlights the growing cyber risks facing healthcare organizations and advise patients to be vigilant for fishing attempts and fraudulent communications using potentially stolen personal information. Researchers at the University of New Haven have identified a high-severity security vulnerability affecting DNA analysis software widely used in U.S. crime laboratories, potentially exposing digital forensic records dating back, to 1995 to undetectable tampering. The flaw could allow an attacker with access to a lab's systems to alter DNA analysis files without leaving evidence of modification, raising concerns about the
Starting point is 00:08:52 integrity of digital forensic evidence. Researchers demonstrated the attack using AI-assisted code and publicly available decryption keys, though there is no evidence the vulnerability has been exploited in real cases. After being notified, Thermo Fisher Scientific acknowledged the issue, worked with SISA, and released a software update that adds digital signatures to help verify file integrity. Experts say the findings highlight the need for stronger cybersecurity protections in forensic laboratories. Security researchers at JFrog say dozens of recently published SQ-Lite Vulnerability Advisories appear to be fabricated, likely generated by large language models, despite being assigned CVE identifiers and initially receiving high severity ratings
Starting point is 00:09:46 from the National Vulnerability Database and other sources. After analyzing six reported SQ-Lite flaws, researchers found the advisories referenced non-existent functions, incorrect line numbers, invalid proof-of-concept exploits and fixes that never existed. None of the vulnerabilities appeared on SQ Lite's official advisory page, and testing failed to reproduce the claimed issues. J-Frog warns the incident exposes weaknesses in the current CVE ecosystem, where unverified submissions can propagate through vulnerability databases and automated security tools. The researchers recommend validating high-impact CVEs. against vendor advisories, source code, and reproducible exploits before prioritizing remediation,
Starting point is 00:10:37 particularly as AI-generated content becomes more prevalent. A cyber attack in the UK's Police National Legal Database has exposed the names and contact details of roughly 100,000 police officers on the dark web, raising serious safety concerns for law enforcement personnel. Authorities believe the Hacking Group X-Fill Squad was responsible as part of a broader campaign targeting UK government agencies, including the Ministry of Defense, Home Office, National Crime Agency, and Crown Prosecution Service. The breach follows a separate attack on the Department for Education that exposed more than half a million records. Affected officers say the leak increases personal security risks, particularly for those involved in Orrador's. organized crime investigations.
Starting point is 00:11:31 Turning to our Monday business briefing, cybersecurity and AI companies announced a wave of funding and acquisition activity this past week, led by Threat Lockers $190 million Series F to expand its zero-trust platform. Other notable funding rounds included Act Security with $60 million, Aegis AI at $36 million, Harmony AI with $34 million, Hush security with 30 million, abstract with 25 million, copy site with 3 million, and Frenos with $1.5 million, with investment focused on cloud security, identity management,
Starting point is 00:12:12 AI-powered security operations, and enterprise automation. On the mergers and acquisitions front, CYERA agreed to acquire identity security startup Oasis security for $1 billion to combine data and identity protection. Leonardo DRS announced a $450 million acquisition of mission software provider RAFT, while Key Factor plans to acquire UK-based identity security firm COFID to strengthen AI trust infrastructure. VENA Solutions also announced plans to acquire Enterprise AI platform Morphio AI to enhance its AI capabilities. Be sure to check out our business briefing on our web, website that is part of CyberWire Pro.
Starting point is 00:13:01 Coming up after the break, Tim Starks from CyberScoop discusses the White House's quantum aspirations, and AI is the hottest thing on campus. Stay with us. What's the one thing in business that's spreading as fast as AI? AI risk. Every new tool your team signs up for, every vendor that turns on AI features, every new integration, each one is another opportunity for something to go wrong. And most security programs weren't built to keep up with AI's pace of growth.
Starting point is 00:13:55 Enter Vanta. Vanta is the number one agentic trust platform, trusted by more than 16,000 fast-moving companies like Ramp, Hursor, and Harvey to help them stay audit-ready. And now Vanta helps companies like yours keep an eye on the risks that appear between audits across your vendors, your AI tools, and your entire environment. The Vanta agent works like a 24-4. 47 GRC engineer in the background. It finds issues, drafts, fixes for you, and can cut vendor assessment time by up to 50%.
Starting point is 00:14:29 Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today at vanta.com slash cyber. That's V-A-N-T-A-com slash cyber. It is my pleasure to welcome back to the show. Tim Starks, he is a senior reporter at CyberScoop. Tim, welcome back. Hey, good to be back. Looking at this recent article you wrote for CyberScoop,
Starting point is 00:15:10 this is about the supply chain challenges that may loom large in the quantum race, according to some folks from the White House. What's going on here, Tim? Yeah, we got some rare comments from someone we haven't heard much from publicly named Brad Blakestack. He's the director of the National Quantum Coordination Office that is housed within the White House Office of Science and Technology Policy. If you're following me, that's a long title. But the idea is, you know, he's someone who is, you know, was supposed to coordinate all the quantum efforts that are happening on cyber.
Starting point is 00:15:48 And he talked about some of the big challenges for dealing with all the things that are happening on quantum. For cyber listeners or readers, obviously the issue of quantum computing looms large. But one of the things he said that jumped out at us was talking about how the supply chain is one of the biggest challenges here. How so? What he was saying was there's no easy way to do quantum all in one place. So there's not like one single hardware platform. There's different technologies for quantum computing, for quantum sensing. They're all completely different.
Starting point is 00:16:34 You have people who make these different components over here for this kind of quantum, for this other kind of quantum. And it ends up being so diffuse that it's hard to bring it all together and make it so that you're building everything in a unified way. You know, specifically there was the issue he was disenfranchised. discussing about that there's not just this diffuseness, but there's also just not a lot of it at all, that you have not enough quite economic demand yet or marketplace dynamics to make it so that people want to be getting into manufacturing widgets, quantum widgets, let's call them. Every time I talk about this subject, I think of, I think of, it might have been a Rick and Morty
Starting point is 00:17:17 episode where they're like, you can't just call something quantum and assume that that makes it science fiction now. Right. Right. Quantum in front of everything, but I'm kind of doing it in this conversation. Anyway, he's saying, you know, that there's not this kind of base that we have for other kinds of things, that, you know, the supply chain that can really
Starting point is 00:17:34 reliably start producing things. And that that's one of the really biggest fundamental challenges he's facing and that they're trying to address in this administration. They've had a couple executive orders on quantum in June. It was interesting to hear from him on this and how they're trying to get to the very fundamental building blocks of quantum and trying to make sure that it can be a thing that gets going at all.
Starting point is 00:17:58 Yeah. I'm curious, you know, you mentioned the funding issue. Isn't that just the kind of thing that a federal government should be able to fund that sort of pure research to get us across the finish line? Conceivably, yes, it's something that the federal government could be doing.
Starting point is 00:18:14 And he did mention one kind of role where the government could do that, where they can say, we'd like you to make the, He literally used the word widgets, so I'm not, if I used it earlier, I was not being facetious. Make these things to our specifications, and we will buy them. And so that could be a way that that could happen. He did talk about funding limitations.
Starting point is 00:18:33 You know, this administration has downsized federal government funding significantly in lots of ways and lots of places. He mentioned the ideas of things like prize challenges and other ways to kind of incentivize the market to get going. Was there any kind of call to action from him for industry? Hmm, was there? No, not really. I would say not really. It wasn't that he was, you know, saying that they shouldn't do anything, but he wasn't saying, here's a list of things we want you to do.
Starting point is 00:19:05 Yeah, more of a state of the union kind of address, perhaps. Yeah, it was really meant more to be like, these are the things where we are looking to do. You know, he talked about trying to do things to make it. So just if anything, the closest he might have come to that is saying, The U.S. needs to own this issue, if you will. One of the things that there has been a discussion about out there in the sort of think tanking community and people who research this stuff is that this is, the supply chain is not just
Starting point is 00:19:32 a U.S. diffusion problem. It's an international diffusion problem that we're relying on parts from China, from Iran. And it's not like there's one country that's dominating this. And I think if there was one kind of call, it was like the U.S. needs to dominate this. we need to be such that we're the place where this all starts, that this is the foundation of it all, and this is where other countries turn to us. So I think that would be the closest thing to a call to industry.
Starting point is 00:20:03 He really was kind of giving an overarching view of what the administration is working on on this and talking about what makes it a challenge among the things were supply chain. But we talk about encryption, of course. One of the things it was fascinating about the speeches of well to me that I didn't mention in the story is that I think when I, as a reporter cover Cyber, think about quantum computing, I think about encryption, I think about breaking encryption.
Starting point is 00:20:27 He was talking about that as important and meaningful, but also he said, candidly, we're more enthused about the economic impacts of quantum computing and other quantum technologies, that that's where they're focused on the economic gains of this, less so the national security risks. Not that he was saying that it didn't exist, but that he was,
Starting point is 00:20:48 that was a point of emphasis for the administration. That being the leader in that realm could be of great advantage to the U.S. economically? Not just that, but also that the technological advances that could be unlocked by quantum could be something that we see with things like being able to break down things from, like being able to approach pharmaceuticals, other kinds of industries, and use the advances of quantum technology to really push forward the technology. and other areas. I see. Well, watching his presentation, was your sense that it was one of optimism? Yes, it was, I would say. Obviously, a lot of people, you know, who are in this
Starting point is 00:21:30 administration talk up the president and what he's doing is unique here. I think this might be a case where that's the case. I mean, certainly quantum technology has been an emphasis for other administrations, but I don't know that we've seen this kind of high-level attention from it. And I think that that is something that he was optimistic about from the standpoint of saying, look, this is something we're really focusing on. This is something we really want to do. And I think that some credit is due to the administration for making that a big point of this. Yeah. All right. Well, Tim Starks is senior reporter at CyberScoop.
Starting point is 00:22:03 Tim, thanks so much for taking the time for us. Thank you. And finally, artificial intelligence is reshaping higher education in unexpected ways, As demand for traditional computer science degrees cools and entry-level coding jobs face pressure from AI, colleges are finding growing interest from students who never planned to study computer science in the first place. Psychology majors, musicians, biologists, and business students are adding AI minors, certificates, and courses to build what universities increasingly view as a fundamental workplace skill. schools are responding with AI literacy requirements, new interdisciplinary programs, and faster course
Starting point is 00:23:05 development, reflecting the technology's rapid evolution. Educators argue that understanding AI is becoming as essential as reading or basic math, even as they caution against over-reliance on the technology. The irony is hard to miss. AI may be writing some code that once justified a computer scientist, degree, but it's also convincing students across nearly every other discipline that they need to learn enough about it to keep up. And that's the Cyberwire. For links to all of today's stories, check out our daily briefing at the Cyberwire.com. We're recording on site at Black Hat this
Starting point is 00:23:57 Wednesday and Thursday from our podcast studio in the SpectorOps Kennel Club. If you'd like to meet the N2K Cyberwire team, make sure you stop by the studio. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to Cyberwire at N2K.com. N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Heltsman.
Starting point is 00:24:36 Our contributing host is Maria Vermazes. Our executive producer is Jennifer Ibn. Peter Kilpe is our publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.