CyberWire Daily - You've been disconnected.
Episode Date: July 28, 2026A senator targets legacy VPNs. Minnesota water systems come under cyberattack. A 20-year-old flaw exposes 24,000 servers. Microsoft debuts its first cybersecurity AI model. A critical VeloCloud bug is... under active attack. The Dysphoria botnet tops 200,000 devices. Apple faces a lawsuit over a fake crypto wallet. Denmark builds a cyber-resilient banking backup. Google gives threat actors yet another set of names. Our guest is John Chiappetta, Chief Revenue Officer of Xona Systems, discussing the Aviation Cybersecurity GAO report that highlights gaps in FAA network security. Hacking the admissions system in search of a fair chance. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by John Chiappetta, Chief Revenue Officer of Xona Systems, discussing the Aviation Cybersecurity GAO report that highlights gaps in FAA network security. Selected Reading Wyden Demands Two-Year Federal VPN Purge: Zero-Trust Procurement Rule Would Reshape Vendor Market (Tech Times) Several MN water facilities targeted by cyber attacks (FOX 9 Minneapolis-St. Paul) Over 24,000 exposed server BMCs leak password hash via decades-old flaw (Bleeping Computer) Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model (SecurityWeek) Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock (The Register) New Dysphoria DDoS botnet spreads to 200k devices worldwide (Bleeping Computer) Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin (Bleeping Computer) Denmark Readies Emergency Reserve Bank to Fight Cyberattacks (Global Finance Magazine) Google Adopts New Threat Actor Naming System (SecurityWeek) Rejected Cybersecurity Applicant Allegedly Hacks IIT Madras Portal: "All I Need Is A Fair Chance" (NDTV) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
This episode is supported by Black Hat USA.
If you follow the research, you know a lot of it breaks on Black Hat stages.
Hundreds of peer-reviewed briefings, more than 100 hands-on trainings,
and the largest business hall in Black Hat's history.
Six days to learn the skills you'll need tomorrow.
August 1st to the 6th.
Use code Cyberwire for $200 off your briefings pass.
at blackhat.com.
We'll see you in Vegas.
If you're heading to Black Hat USA this year,
make plans to visit the SpectorOps Kennel Club.
As creators of Bloodhound,
the SpectorOps team will host talks with OpenAI
and the UK AI Security Institute,
as well as hands-on workshops
aimed at helping you understand
AI accelerated attack paths
and the latest in identity tradecraft.
Visit Spectorops.io to pre-register
and learn more. Spector Ops Kennel Club is adjacent to Libertine Social inside Mandalay Bay.
While you're there, visit the N2K Cyberwire podcast studio where we'll be capturing expert
perspectives and conversations from across Black Hat.
As Senator targets legacy VPNs, Minnesota water systems come under cyber attack, a 20-year-old
flaw exposes 24,000 servers. Microsoft debuts its first cybersecurity AI mob,
A critical Velo Cloud bug is under active attack.
The dysphoria botnet tops 200,000 devices.
Apple faces a lawsuit over a fake crypto wallet.
Denmark builds a cyber resilient banking backup.
Google gives threat actors yet another set of names.
Our guest is John Chiapeta, chief revenue officer of Zona Systems, discussing the aviation
cybersecurity GAO report that highlights gaps in FAA network security.
and hacking the admission system in search of a fair chance.
It's Tuesday, July 28, 2026, one of my favorite days of the year.
I'm Dave Bittner, and this is your Cyberwire Intel briefing.
Thanks for joining us here today.
It's great as always to have you with us.
Senator Ron Wyden has urged SISA, the Office of Management and Budget, and NIST
to take coordinated action to eliminate legacy VPNs from federal network
within two years and require vendors to certify that their remote access products
meet zero-trust standards to remain eligible for federal contracts.
Wyden argues that repeated emergency patching of Internet-facing VPN appliances
is an unsustainable response to vulnerabilities rooted in their architecture.
His proposal calls for SISA to issue a binding operational directive mandating migration,
NIST to establish technical standards emphasizing outbound only remote access,
memory-safe programming languages, and decentralized key management,
and OMB to update procurement rules so only compliant products can be purchased by federal agencies and defense contractors.
The letter cites multiple nation-state campaigns exploiting VPN products from vendors,
including Avanti, Cisco, and Fortinette as evidence that Legacy Remedict,
Mode Access Technology has become a recurring national security risk.
While the agencies are not obligated to act, their proposal aligns with SISA's recent
zero-trust guidance and could significantly reshape the federal cybersecurity market if adopted.
At least three Minnesota cities, Plymouth, South St. Paul, and Braham are responding to cyber
attacks targeting their water facilities, prompting assistance from state authorities.
Plymouth reported attacks on water towers and lift stations.
South St. Paul said its water utility system was affected,
and Brom experienced a brief outage at its water plant before crews restored operations.
Officials believe other communities may have also been impacted,
although it remains unclear whether the incidents are connected or the work of a single threat actor.
All three cities say the effects have been limited, drinking water remains safe,
and residents can continue normal water use.
Minnesota IT Services is coordinating with local, state, and federal partners
to assess the attacks, share threat intelligence, support response and recovery efforts,
and determine the full scope of the ongoing investigation.
Researchers have identified more than 24,000 Internet-exposed servers
vulnerable to a long-standing weakness in the intelligent platform management interface, IPMI 2.0 protocol,
that can expose password hashes for offline cracking.
The flaw stems from a protocol design dating back to 2004
and affects baseboard management controllers,
which provide low-level remote server administration.
Lava researchers found that about one-third of affected systems used weak or predictable,
credentials, including default passwords, making compromise significantly easier. Because BMCs operate below
the operating system, successful attacks can provide deep control over physical servers and potentially
broader management environments. The researchers urge organizations to keep IPMI interfaces off the public
internet, rotate default BMC passwords, isolate management networks, and disable legacy
IPMI authentication to reduce exposure.
Microsoft has introduced MAI Cyber One Flash, its first AI model built specifically for cybersecurity,
designed to identify vulnerabilities in complex code.
Integrated into the company's M-Dash multi-agent platform, the model works alongside larger AI
models to improve efficiency while reducing costs by 50%.
Microsoft says testing showed the system outperformed competing cybersecurity AI models from Google, OpenAI, and Anthropic in Vulnerability Discovery.
MAI Cyber One Flash will be available through Microsoft's Project Perception Security Platform, which enters public preview on August 3rd.
Arista has confirmed active exploitation of a critical vulnerability affecting its on-premises Velo Cloud
orchestrator software. The flaw with a 10.0 CVSS rating is an unauthenticated OS command
injection vulnerability that can allow attackers to compromise the orchestrator and potentially
gain access to managed VILO cloud edge devices. Because the web interface is exposed by default,
Arista recommends restricting access to trusted management networks and blocking known malicious IP
addresses until patches are applied. SISA has added. CISA has added.
added the flaw to its known exploited vulnerabilities catalog underscoring the urgency.
The issue does not affect Arista's hosted VILO cloud service,
and patched software versions are now available for affected on-premises deployments.
Researchers have identified a botnet called dysphoria that has compromised an estimated 200,000
devices worldwide and is being used for DDoS attacks and traffic relay operations.
According to Kianjin X-Lab, the malware employs a blockchain-based command and control mechanism
using Ethereum and Solana naming services to make its infrastructure more resilient and difficult to disrupt.
Since first appearing in March, dysphoria has rapidly evolved, adding multi-chain support,
new command and control techniques, and separate variants for DDoS attacks and proxy services.
The botnet spreads by exploiting weak telnet and SSH credentials and known vulnerabilities in routers, cameras, and other IoT devices.
Researchers recommend patching firmware, changing default passwords,
disabling unnecessary remote access, and strengthening device security settings to reduce the risk of compromise.
Three Apple users have filed a lawsuit alleging they lost a combined $1.8 million,
in Bitcoin after downloading a fraudulent Sparrow Wallet application from the App Store.
The complaint claims the fake app impersonated the legitimate desktop-only cryptocurrency wallet,
tricking users into entering their recovery seed phrases,
which attackers then used to steal their funds.
The plaintiffs argue Apple failed to adequately review and remove the fraudulent app
despite prior warnings from Sparrow Wallet's developer and user reports.
Apple said it removed the impersonating apps, terminated the associated developer accounts,
and provided channels for reporting fraudulent software.
The lawsuit seeks reimbursement for the stolen cryptocurrency, damages,
and court-ordered improvements to Apple's App Store review process and fraud warnings.
In Denmark, Denmark's National Bank is developing a dormant energy bank,
an offline backup banking system designed to keep,
keep critical financial services running during a major cyber attack.
The initiative is part of the central bank's emergency preparedness for critical financial sector
activities in extreme scenarios strategy introduced in late 2025.
If a cyber attack disables a major bank or Denmark's broader banking infrastructure, the DEB
would allow businesses and consumers to continue receiving salaries, making transfers, and using
payment cards until normal operations are restored. The plan also includes a card payment
contingency system that enables retailers to accept physical cards and mobile wallets, even during
prolonged IT outages, by storing transactions offline and settling them once connectivity returns.
Currently being piloted nationwide, the offline payment capability is expected to be fully
operational at grocery stores and pharmacies by the end of this year,
strengthening Denmark's resilience against large-scale cyber disruptions.
Google Threat Intelligence Group has introduced yet another threat actor naming system
because the cybersecurity industry apparently didn't have enough aliases to keep track of already.
The company is replacing numeric identifiers with two-word cryptonyms,
pairing a memorable name with a category suffix that reflects attribution or motivation.
Under the new scheme, China's groups end in Castle,
Russia's in Relic, North Korea's in Neptune,
Iran's in Ion, and cybercrime gangs in Comet.
For example, the group long-tracked by Google as APT-44
and by everyone else under a small library of different names
will now be known as sandworm relic.
Google says the new taxonomy is intended to simplify tracking
while preserving legacy names,
mitre attack mappings, and other vendor aliases
during what is sure to be another industry-wide exercise
in cross-referencing threat actor names.
Coming up after the break,
my conversation with John Chiapeta from Zona Systems,
We're discussing the Aviation Cybersecurity GAO report that highlights gaps in FAA network security
and hacking the admissions system in search of a fair chance.
Stay with us.
John Chiapeta is Chief Revenue Officer at Zona Systems.
We recently sat down to discuss the Aviation Cybersecurity GAO report that highlights gaps in FAA network security.
Naturally, this is a very critical industry.
That is primarily what we serve at Zona.
So we are focused on critical industries, generally speaking, energy, even manufacturing.
So this certainly falls into the scope of what we focus on.
Now, when it comes to the report in itself, it's interesting from a few different perspectives.
And I think what everybody needs to factor in is these aren't new organizations.
It's not a startup which started yesterday.
So there's certain things that are inherent to them.
And some of this is the infrastructure that they have can't be refreshed or turned off or upgraded overnight.
And so a lot of these industries are facing relatively similar challenges.
Yeah, you know, when I think of aviation, it's kind of, you know, that old joke about,
you have to change the oil while the engine is running and how much harder that is.
At the same time, I think we hear lots of stories about aviation having challenges with things
like air traffic controllers and the technology that they use.
I mean, is this a case of a vertical that is just a little behind when it comes to updating
their technology?
I wouldn't use the words a little behind necessarily.
I think inherently it's an industry that's hard to.
move, right? Banking would be another one. Energy sector would be another one and that it's
institutionalized. And so, you know, you mentioned kind of change the oil while it's running.
I think that's absolutely accurate in the sense of this industry is starting to face the same
challenges every other industry is facing right now, but it's new for this industry. These challenges
did exist when a lot of this infrastructure was set up. And so, you know, it's, yes, it's a technology
piece, but it's also a culture piece. And it's, how do you get ahead of that on really both sides
at once? Well, I know you have a story to share about some work that you did with an airport authority
and some of the surprises that you found within their systems. Surprise for me, for sure. Surprise for them,
I think, as well. But this was actually driven, and it's related because a few years ago,
I want to say it was 2023. TSA came in with a number of changes.
when it came to cybersecurity, best practices, guidelines, all of that. And at the time, I was engaged
with a very large airport authority working on a very similar project to what we do right now.
So what we focus on is secure remote access. All of the organizations that we work with,
and this is no different, they have systems that they don't manufacture themselves. It helps
operate their business, but ultimately they have vendors and contractors and different.
different people who support those systems who may not be on site. And so they need remote access
into these systems. And so that was the project we were working on. And we were working with the
operation site. So very typically, we'd either work with operations or IT slash cyber teams and,
you know, the combination of the two. This was exclusively with the operation side. And they were
rather frustrated. And the frustration that they had, those individuals are tasked
with keeping things moving, keeping the systems running,
keeping people moving through the airport,
keeping everything secure.
And TSA at the time threw a bit of a wrench into that
because they said, hey, I want you to evaluate
how you're doing remote access today,
who's connecting to these networks, what's going on?
Get a better handle on that.
It's essentially the message that went out.
In that process, they were rather frustrated
because they had to do that instead of focus on
the work that they do on a daily basis, which, as we know, keeps them very busy. During that,
they found out that they were only working with a number of vendors at this specific point in time,
but when they looked at how vendors were accessing the network, there was a number, I think it was
upwards of 30 different connections that were still able to access the network, even though
they weren't dealing with those 30 different vendors. They were only dealing with a handful.
And so rather surprising to them, certainly surprising to me,
because just like you and I, we travel through the airport all the time.
We've got to jump through all kinds of hurdles.
And it's interesting to see these doors weren't locked at the time.
What do you suppose that story says about the broader situation that we find in the industry today?
Is this a typical kind of thing to find?
It is.
Less and less as the years go on.
But again, you're focused on, you know, or certainly we're focused on industries where
if we go back 15, 20 years,
they were never connected to the internet.
They were never meant to connect to the internet.
And then COVID certainly expedited that
where all of a sudden systems that were never meant
to connect to the internet in the first place,
you had to connect them because they might be supported
by a vendor who's in a different state or a different country.
And when something goes wrong,
you can't take everything offline.
You need them to connect in and fix it right now.
And so the way that different organizations
address that was relatively the same, which is leveraged what's called a VPN.
At the end of the day, that's a big long Ethernet Core, and there's a number of challenges
that come along with that.
And what they found themselves in is a situation where they didn't have best practices,
they didn't have guidelines around that.
It was very common for connections to be spun up, but then nobody comes back to the IT
team who spun up that connection to say, hey, we no longer work with that vendor.
there's no need to have that. Everybody's busy. They got another job to do right after they
complete this one and those compound over the years. So what are your recommendations for organizations
to best deal with this particular issue? It's a good question. And I wish there was a one-size-fits-all
type of approach to this. But as with anything, it's not that simple. What I would say is,
first you need to understand what is it that's all.
on that network, right?
You need to understand what's behind the doors,
what are you ultimately protecting,
and then work backwards to say, okay,
how do I do this in a way where I'm doing it proactively
and not reactively?
We hear a lot about, you know,
how do we understand the detection and monitoring piece?
Well, that piece means something already got in,
something already happened.
And so how do you look at the front doors to say,
how do I guarantee that nothing touches these systems?
The article that we're discussing actually mentioned,
NIST and the zero trust principles and guidelines that NIST produces and the recommendation to
follow that pretty tightly. I think that's fantastic. Then look at what are your high priority
resources that, you know, those are the ones that keep you up at night that need to be protected
at all cost. Who are the privileged users? And then make sure you fully understand how this maps
together. But the key thing is be proactive about the security. Do not bake that in as a
an afterthought.
That's John Chiapetta from Zona Systems.
And finally, a would-be cybersecurity student has ignited an online debate after allegedly
hacking the websites of IIT Madras and IIT Kanpur, claiming the intrusion was less about causing
damage than making a very pointed admissions appeal.
In messages shared on Reddit, the individual said he was a very important.
rejected from IIT Madrasse's Bachelor of Science in Cybersecurity program, despite paying the
application fee, submitting the required materials, and building years of cybersecurity experience.
His central plea, all I need is just a fair chance.
He also alleged that several program seats went unfilled and claimed, without independent
verification, to have accessed sensitive institutional systems after repeated attempts to report
security issues, and contact administrators went unanswered. Reports of website outages surfaced
around the same time, although any connection remains unconfirmed. The episode has divided opinion
with critics condemning the alleged hack, while others questioned whether traditional admissions processes
are overlooking practical cybersecurity talent. And that's the Cyberwire. For links to all of today's
stories, check out our daily briefing at the cyberwire.com.
We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights
that keep you a step ahead in the rapidly changing world of cybersecurity.
If you like our show, please share a rating and review in your favorite podcast app.
Please also fill out the survey and the show notes or send an email to Cyberwire at n2K.com.
N2K's lead producer is Liz Stokes.
We're mixed by Trey Hester with original music and sound design by
Elliot Peltzman. Our contributing host is Maria Vermazas. Our executive producer is Jennifer Ibin.
Peter Kilby is our publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here
tomorrow. Heading to Black Hat USA, the N2K's Cyberwire team will be on-site recording from our
podcast studio in the SpectorOps Kennel Club. If you're interested in joining us for a conversation
or learning more about what we're recording throughout the week,
stop by the studio and meet the N2K Cyberwire team.
SpectorOps's Kennel Club is adjacent to Libertine Social inside Mandalay Bay.
