The CyberWire Daily Podcast 7.27.26
Ep 2601 | 7.27.26

The world's least private hackers.

Transcript

Hackers target Thailand’s Ministry of Finance with an autonomous AI agent.A new industry alliance hopes to improve AI security. Golden Chickens lay four new malware families. GitHub and PyPI introduce time-based safeguards. SourTrade malvertising builds malware directly inside a victim’s browser. Attackers target credentials of traveling corporate employees. EDR shutdown is now par for the course for leading ransomware groups. Russian threat actors exploited a Zimbra vulnerability for at least five months before it was patched. Monday business briefing. Our guest is Krishna Sai, CTO at SolarWinds, with security lessons learned from the World Cup. When the feed ends, the fun begins.

Today is Monday July 27th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

Hackers target Thailand’s Ministry of Finance with an autonomous AI agent.

Researchers at Hunt.io say hackers used an autonomous artificial intelligence agent during an apparent cyber-espionage campaign targeting Thailand’s Ministry of Finance. While the intrusion was underway, the attackers accidentally exposed hundreds of files on their own infrastructure, giving researchers an unusual look inside the operation. The files included malware, stolen credentials, attack scripts, AI agent logs, and evidence that multiple ministry systems had already been compromised. Hunt.io said the attackers relied heavily on Hermes, an open-source AI agent configured to execute commands without human approval. The agent autonomously explored the ministry’s network, gathered system information, and searched for ways to escalate privileges. Although researchers found no evidence of data exfiltration, the activity appeared focused on reconnaissance, credential theft, and preparing for future operations. Hunt.io has not attributed the campaign, but said several indicators suggest the operators were Chinese-speaking.

A new industry alliance hopes to improve AI security. 

Nvidia and dozens of technology, cybersecurity, and enterprise software companies have launched the Open Secure AI Alliance, a new initiative focused on developing and sharing open source tools, models, and techniques to improve AI security. The effort builds on work from the Linux Foundation’s Akrites initiative and the Open Source Security Foundation, or OpenSSF. Founding members include major industry players such as Microsoft, IBM, Cisco, CrowdStrike, Palo Alto Networks, and Hugging Face. Contributions range from Nvidia’s new NOOA project for tracing and auditing AI agent behavior, to Microsoft’s MDASH framework for AI-assisted vulnerability discovery, IBM and Red Hat’s Lightwell supply chain security project, and HPE’s zero-trust identity framework for AI agents. The alliance argues that open AI security tools strengthen collective cyber defense and cautions that broad restrictions on open frontier AI could undermine those efforts.

Golden Chickens lay four new malware families. 

Researchers say the operators behind the Golden Chickens malware-as-a-service, or MaaS, platform have expanded their toolkit with four new malware families, despite years of public scrutiny. According to Recorded Future’s Insikt Group, the new families, TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator, reflect a significant architectural evolution. TinyEgg acts as a lightweight backdoor for initial access, while ChonkyChicken adds capabilities such as browser credential theft and live browser session control. The modularized version introduces a plugin-based framework that can load 14 capabilities on demand, including keylogging, screen capture, and process management. Researchers say the move toward modular, operator-controlled malware improves defense evasion, reduces detection risk, and offers customers more flexible capabilities within the malware-as-a-service ecosystem.

GitHub and PyPI introduce time-based safeguards. 

GitHub and the Python Package Index, or PyPI, have introduced new time-based safeguards designed to reduce software supply chain risk. GitHub’s Dependabot now applies a default three-day delay before automatically recommending newly released package updates, giving security researchers and maintainers more time to identify and remove malicious packages before they are widely adopted. The delay is configurable, and GitHub continues to recommend additional protections such as dependency pinning, restricted access tokens, and limiting installation scripts. Meanwhile, PyPI will no longer allow maintainers to add new files to package releases more than 14 days after publication. The change is intended to prevent attackers from compromising trusted older releases, a technique known as release poisoning, even though no confirmed PyPI attacks have used that method to date.

SourTrade malvertising builds malware directly inside a victim’s browser. 

Researchers at Confiant say the SourTrade malvertising campaign has adopted a new technique that builds malware directly inside a victim’s browser to evade detection. Active since 2024, the operation impersonates popular trading and cryptocurrency platforms, including TradingView, Solana, and Luno, to lure investors with fake trading tips and cryptocurrency giveaways. Instead of delivering a complete malware file, the malicious site sends assembly instructions, downloads clean components from separate infrastructure, and reconstructs the final infostealer in the browser’s memory. Because no complete malware file is transmitted over the network, traditional file-based security tools are less likely to detect the attack. Researchers say the approach allows SourTrade to vary the payload by victim or session, making the campaign more difficult to identify and disrupt.

Attackers target credentials of traveling corporate employees. 

Researchers at ReliaQuest warn that attackers are compromising public Wi-Fi gateway appliances used for captive portal networks to steal Microsoft 365 credentials from traveling corporate employees. Active since at least June 2026, the campaign targets Wi-Fi systems at hotels, conference centers, and other shared venues by altering DNS settings to redirect users to attacker-controlled infrastructure. Using an adversary-in-the-middle, or AitM, technique, the attackers can intercept traffic and harvest login credentials. ReliaQuest observed victims across multiple industries, including financial services, healthcare, energy, and retail, suggesting broad targeting rather than a sector-specific campaign. While the activity resembles the previously reported FrostArmada operation linked to APT28, researchers say differences in infrastructure and tactics indicate either a separate threat actor or one reusing elements of APT28’s tradecraft.

EDR shutdown is now par for the course for leading ransomware groups. 

Researchers at Halcyon warn that disabling endpoint detection and response, or EDR, tools before encrypting systems has become standard practice for leading ransomware groups, significantly reducing defenders’ response time. The company’s Q2 2026 Ransomware Evolution Report found that some groups, including The Gentlemen, now build EDR and antivirus shutdown capabilities directly into their attack chains. Halcyon says The Gentlemen has incorporated techniques from other major ransomware families to improve encryption, code obfuscation, and security tool evasion. Although publicly claimed ransomware attacks declined 5.7% during the quarter, researchers observed increasingly sophisticated operations, including rapid attacks, greater use of artificial intelligence throughout the attack chain, and continued exploitation of enterprise edge vulnerabilities. The report concludes that ransomware is becoming faster, more automated, and more difficult to detect and contain.

Russian threat actors exploited a Zimbra vulnerability for at least five months before it was patched. 

Proofpoint says Russia-aligned threat actor TA488 exploited a previously unknown vulnerability in Zimbra Collaboration Suite mail servers for at least five months before it was patched as CVE-2025-66376. The group used a so-called half-click exploit, requiring victims only to open or preview a malicious email to trigger embedded code. According to Proofpoint, the attacks targeted Ukrainian government organizations as well as U.S. government, defense, and scientific entities. After gaining access, TA488 deployed malware dubbed ZimReaper to steal credentials, establish persistent access, and exfiltrate emails from compromised accounts. Researchers say the campaign relied on obfuscated JavaScript, DNS-based data exfiltration, and app-specific passwords to maintain access. Proofpoint assesses the activity is linked to Russian intelligence and notes the operation underscores continued targeting of webmail platforms for cyber espionage.

Monday business briefing. 

Cybersecurity investment remained strong this week, led by Israeli endpoint security startup Glow, which emerged from stealth with $180 million to expand U.S. operations and research. Other major funding rounds included Neo with $100 million for agentic software security, Risk Ledger with $32.2 million for AI-enabled supply chain security, Twenty with an additional $30 million for offensive cyber technology, and Empirical Security with $25 million for predictive vulnerability management. Smaller investments supported companies focused on security telemetry, autonomous penetration testing, identity verification, post-quantum security, deepfake detection, email security, and open-source software security. Mergers and acquisitions were also active, with Palo Alto Networks announcing plans to acquire observability provider Embrace, Aura completing its acquisition of Qoria, and Veridas agreeing to merge with Fourthline. Additional acquisitions by NINJIO, Webacy, and Amplix highlight continued industry consolidation as vendors broaden capabilities across software security, identity, training, procurement, and digital risk management.

 

When the feed ends, the fun begins. 

A week-long New York festival called the “Summer of Ludd” set out to prove that meaningful community doesn’t require social media, smartphones, or Big Tech platforms. Organized entirely through phone hotlines, posters, bookstores, and word of mouth, the event featured phone-free raves, workshops, theatrical protests, and plenty of handmade gnome hats. One highlight was a mock trial of OpenAI and CEO Sam Altman, ending with participants gleefully stomping a giant cardboard smartphone, because apparently cardboard had it coming. Beneath the playful absurdity was a serious message: rebuild community through shared, in-person experiences rather than algorithm-driven feeds. Organizers argued that public events, not viral posts, are the foundation of lasting social movements. While acknowledging the challenge of resisting commercialization and digital capture, the festival embraced joy over cynicism, suggesting that the most radical act in 2026 might simply be showing up, looking around, and leaving your phone in your pocket.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

 

And that’s the CyberWire Daily, brought to you by N2K CyberWire.

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.