CyberWire Daily
Recent Episodes
The U.S. and China agree on an AI safety channel. Some states say CISA’s election security plan comes too late. Citrix patches critical zero-days under active exploitation. AI agents probed government websites in unexpected and concerning ways. ShinyHunters launches a new campaign against Oracle PeopleSoft customers. A New Mexico jury finds Meta misled state residents. Business briefing. Tim Starks from CyberScoop shares insights on multiple issues facing CISA. Who’s ready for algorithmic holiday shopping?
Kiteworks urges customers pull the plug on vulnerable servers. CISA lays out its election security plan. Known vulnerabilities linger unpatched. Big AI labs consider a new standards body. Questions surround claims of an OpenAI Medicare hack. File notifications become a privacy leak. SectopRAT hides in audio software. A new Android banking trojan takes control. An attacker puts open-source AI agents to work hacking hundreds of organizations. A Rydox cybercrime marketplace operator pleads guilty. Our guest is Todd Thorsen, CISO of CrashPlan, with ways to prepare for and react to critical infrastructure campaigns. Americans give AI the side-eye.
Researchers find a new way to weaken RSA. ShinyHunters allegedly exposes sensitive FBI details. CISA and the FBI warn of third-party ICS risks. An OpenAI agent hacks an Australian government portal. SolarWinds patches critical flaws. A placeholder domain delivers ClickFix. Digital forensics executives face charges over alleged Russian ties. ENISA maps Europe’s cyber threats. The U.S. and China have very different ideas about AI safety. Our guest is Kurt Dusek, Technical Product Advisor at Appdome, sharing thoughts on segregation of duties and AI agents. Women in tech have their say.
The hunters go after the bureau.
ShinyHunters claims to have breached FBI systems. CLOSEDQUORUM malware delegates command-and-control decisions to commercial LLMs. An IT error erases 11 years of hospital maternity data. F5 patches a critical BIG-IP APM zero-day. Ransomware activity remains high. Microsoft disrupts the EvilTokens cybercrime platform. Researchers turn Claude Code’s normal workflow against itself. Pundits propose an AI Assurance Compact. A Ryuk ransomware gang member gets two years prison time. Our guest is Jen Sovada, General Manager of Public Sector at Claroty, on Project Watershed 250 and the challenges facing U.S. water utilities. Meta’s Muse mettles with messages.
Storm clouds over the waterworks.
CISA rides out a Cyber Storm. The EU struggles to share cyber threat information. Nightmare Eclipse drops another Defender zero-day. TASK#STOMP steals business documents. North Korean operatives fake their way through job interviews. A genetics lab pays $700,000 over a phishing breach. A zero-day in Meta’s Muse AI assistant opens the door to privilege hijacking. Marc Woolward, Senior Advisor to Humanix and former CTO for Goldman Sachs, discussing social engineering and vishing attacks. Infiltrating Team PCP.

