The CyberWire Daily Podcast 7.28.26
Ep 2602 | 7.28.26

You've been disconnected.

Transcript

A senator targets legacy VPNs. Minnesota water systems come under cyberattack. A 20-year-old flaw exposes 24,000 servers. Microsoft debuts its first cybersecurity AI model. A critical VeloCloud bug is under active attack. The Dysphoria botnet tops 200,000 devices. Apple faces a lawsuit over a fake crypto wallet. Denmark builds a cyber-resilient banking backup. Google gives threat actors yet another set of names. Our guest is John Chiappetta, Chief Revenue Officer of Xona Systems, discussing the Aviation Cybersecurity GAO report that highlights gaps in FAA network security. Hacking the admissions system in search of a fair chance.

Today is Tuesday July 28th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

A Senator looks to eliminate legacy VPNs from federal networks. 

Sen. Ron Wyden has urged CISA, the Office of Management and Budget, and NIST to take coordinated action to eliminate legacy VPNs from federal networks within two years and require vendors to certify that their remote access products meet zero-trust standards to remain eligible for federal contracts. Wyden argues that repeated emergency patching of internet-facing VPN appliances is an unsustainable response to vulnerabilities rooted in their architecture. His proposal calls for CISA to issue a Binding Operational Directive mandating migration, NIST to establish technical standards emphasizing outbound-only remote access, memory-safe programming languages, and decentralized key management, and OMB to update procurement rules so only compliant products can be purchased by federal agencies and defense contractors. The letter cites multiple nation-state campaigns exploiting VPN products from vendors including Ivanti, Cisco, and Fortinet as evidence that legacy remote access technology has become a recurring national security risk. While the agencies are not obligated to act, the proposal aligns with CISA’s recent zero-trust guidance and could significantly reshape the federal cybersecurity market if adopted.

Multiple Minnesota water facilities suffer cyber attacks. 

At least three Minnesota cities, Plymouth, South St. Paul, and Braham, are responding to cyberattacks targeting their water facilities, prompting assistance from state authorities. Plymouth reported attacks on water towers and lift stations, South St. Paul said its water utility system was affected, and Braham experienced a brief outage at its water plant before crews restored operations. Officials believe other communities may also have been impacted, although it remains unclear whether the incidents are connected or the work of a single threat actor. All three cities say the effects have been limited, drinking water remains safe, and residents can continue normal water use. Minnesota IT Services (MNIT) is coordinating with local, state, and federal partners to assess the attacks, share threat intelligence, support response and recovery efforts, and determine the full scope of the ongoing investigation.

A decades-old bug affects over 24,000 internet-exposed servers. 

Researchers have identified more than 24,000 internet-exposed servers vulnerable to a long-standing weakness in the Intelligent Platform Management Interface (IPMI) 2.0 protocol that can expose password hashes for offline cracking. The flaw, tracked as CVE-2013-4786, stems from a protocol design dating back to 2004 and affects Baseboard Management Controllers (BMCs), which provide low-level remote server administration. Lava researchers found that about one-third of affected systems used weak or predictable credentials, including default passwords, making compromise significantly easier. Because BMCs operate below the operating system, successful attacks can provide deep control over physical servers and potentially broader management environments. The researchers urge organizations to keep IPMI interfaces off the public internet, rotate default BMC passwords, isolate management networks, and disable legacy IPMI authentication to reduce exposure.

Microsoft unveils its first AI model built specifically for cybersecurity. 

Microsoft has introduced MAI-Cyber-1-Flash, its first AI model built specifically for cybersecurity, designed to identify vulnerabilities in complex code. Integrated into the company’s MDASH multi-agent platform, the model works alongside larger AI models to improve efficiency while reducing costs by 50%. Microsoft says testing showed the system outperformed competing cybersecurity AI models from Google, OpenAI, and Anthropic in vulnerability discovery. MAI-Cyber-1-Flash will be available through Microsoft’s Project Perception security platform, which enters public preview on August 3.

A critical VeloCloud Orchestrator bug is under active exploitation. 

Arista has confirmed active exploitation of a critical vulnerability, CVE-2026-16812, affecting its on-premises VeloCloud Orchestrator software. The flaw, rated CVSS 10.0, is an unauthenticated OS command injection vulnerability that can allow attackers to compromise the orchestrator and potentially gain access to managed VeloCloud Edge devices. Because the web interface is exposed by default, Arista recommends restricting access to trusted management networks and blocking known malicious IP addresses until patches are applied. The Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, underscoring its urgency. The issue does not affect Arista’s hosted VeloCloud service, and patched software versions are now available for affected on-premises deployments.

Dysphoria botnet controls over 200,000 devices. 

Researchers have identified a botnet called Dysphoria that has compromised an estimated 200,000 devices worldwide and is being used for distributed denial-of-service (DDoS) attacks and traffic relay operations. According to QiAnXin XLab, the malware employs a blockchain-based command-and-control mechanism, using Ethereum and Solana naming services to make its infrastructure more resilient and difficult to disrupt. Since first appearing in March, Dysphoria has rapidly evolved, adding multi-chain support, new command-and-control techniques, and separate variants for DDoS attacks and proxy services. The botnet spreads by exploiting weak Telnet and SSH credentials and known vulnerabilities in routers, cameras, and other Internet of Things devices. Researchers recommend patching firmware, changing default passwords, disabling unnecessary remote access, and strengthening device security settings to reduce the risk of compromise.

A lawsuit claims Apple allowed a fraudulent crypto app in the App Store. 

Three Apple users have filed a lawsuit alleging they lost a combined $1.8 million in Bitcoin after downloading a fraudulent Sparrow Wallet application from the App Store. The complaint claims the fake app impersonated the legitimate desktop-only cryptocurrency wallet, tricking users into entering their recovery seed phrases, which attackers then used to steal their funds. The plaintiffs argue Apple failed to adequately review and remove the fraudulent app despite prior warnings from Sparrow Wallet’s developer and user reports. Apple said it removed the impersonating apps, terminated the associated developer accounts, and provides channels for reporting fraudulent software. The lawsuit seeks reimbursement for the stolen cryptocurrency, damages, and court-ordered improvements to Apple’s App Store review process and fraud warnings.

Denmark seeks to secure financial services against cyber attacks. 

In Denmark, Danmarks Nationalbank is developing a Dormant Emergency Bank (DEB), an offline backup banking system designed to keep critical financial services running during a major cyberattack. The initiative is part of the central bank’s Emergency Preparedness for Critical Financial Sector Activities in Extreme Scenarios strategy, introduced in late 2025. If a cyberattack disables a major bank or Denmark’s broader banking infrastructure, the DEB would allow businesses and consumers to continue receiving salaries, making transfers, and using payment cards until normal operations are restored. The plan also includes a Card Payment Contingency system that enables retailers to accept physical cards and mobile wallets even during prolonged IT outages by storing transactions offline and settling them once connectivity returns. Currently being piloted nationwide, the offline payment capability is expected to be fully operational at grocery stores and pharmacies by the end of 2026, strengthening Denmark’s resilience against large-scale cyber disruptions.

Google introduces yet another threat actor naming system. 

Google Threat Intelligence Group has introduced yet another threat actor naming system, because the cybersecurity industry apparently didn’t have enough aliases to keep track of already. The company is replacing numeric identifiers with two-word cryptonyms, pairing a memorable name with a category suffix that reflects attribution or motivation. Under the new scheme, China’s groups end in “Castle,” Russia’s in “Relic,” North Korea’s in “Neptune,” Iran’s in “Ion,” and cybercrime gangs in “Comet.” For example, the group long tracked by Google as APT44, and by everyone else under a small library of different names, will now be known as “Sandworm Relic.” Google says the new taxonomy is intended to simplify tracking, while preserving legacy names, MITRE ATT&CK mappings, and other vendor aliases during what is sure to be another industry-wide exercise in cross-referencing threat actor names.

 

Hacking the admissions system in search of a fair chance. 

A would-be cybersecurity student has ignited an online debate after allegedly hacking the websites of IIT Madras and IIT Kanpur, claiming the intrusion was less about causing damage than making a very pointed admissions appeal. In messages shared on Reddit, the individual said he was rejected from IIT Madras’ Bachelor of Science in Cyber Security program despite paying the application fee, submitting the required materials, and building years of cybersecurity experience. His central plea: “All I need is just a fair chance.” He also alleged that several program seats went unfilled and claimed, without independent verification, to have accessed sensitive institutional systems after repeated attempts to report security issues and contact administrators went unanswered. Reports of website outages surfaced around the same time, though any connection remains unconfirmed. The episode has divided opinion, with critics condemning the alleged hack while others questioned whether traditional admissions processes are overlooking practical cybersecurity talent.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

 

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.