The CyberWire Daily Podcast 7.29.26
Ep 2603 | 7.29.26

More than meets the AI.

Transcript

The Senate confirms Jay Clayton to lead ODNI. A new CISA framework highlights critical infrastructure isolation capabilities. OpenAI’s rogue agent breached more than just Hugging Face. The average cost of a data breach continues to rise. Indirect prompt injection proves irresistible to cyber criminals. Broadcom patches multiple VMware products. ShinyHunters claims responsibility for Ernst & Young’s recent breach. Our guest is Sean Zadig, CISO at Yahoo, discussing the impact of AI on the defense side. These aren’t the droids you’re looking for.

Today is Wednesday July 29th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

The Senate confirms Jay Clayton to lead ODNI. 

Jay Clayton was confirmed by the Senate in a 51 to 47 party-line vote to lead the Office of the Director of National Intelligence, replacing acting director Bill Pulte. Although some Democrats initially viewed Clayton favorably, support eroded after he declined during his confirmation hearing to clearly state that Joe Biden won the 2020 election. Still, many lawmakers preferred Clayton to Pulte, whose brief tenure featured aggressive staffing cuts, public boasts about downsizing, and concerns over his lack of national security experience. The intelligence office, created after the September 11 attacks to coordinate U.S. spy agencies, has seen its influence diminish under President Trump, who has relied more heavily on CIA Director John Ratcliffe. Clayton, a former SEC chairman and current U.S. attorney in Manhattan, is expected to work closely with Ratcliffe despite lingering concerns about his political independence.

A new CISA framework highlights critical infrastructure isolation capabilities. 

A new joint framework from CISA and cybersecurity agencies in Australia, the UK, and Canada warns that critical infrastructure operators must build and test isolation capabilities before cyberattacks occur, not during them. The guidance, called CI Fortify, was prompted by major intrusions such as China’s Volt Typhoon and Salt Typhoon campaigns, which exposed weaknesses in U.S. infrastructure and telecommunications networks. A key finding is that many operational technology (OT) systems rely on corporate IT services like Active Directory and DNS, causing isolation plans to fail when networks are disconnected. CI Fortify recommends standalone OT authentication services, predefined isolation points, physical disconnection where possible, recovery procedures, and regular full-scale testing. However, the guidance is voluntary, and experts warn many operators lack the funding and resources to implement it. While the framework establishes a new federal baseline for resilience, organizations that fail to prepare may face greater regulatory, legal, and insurance scrutiny after future cyber incidents.

OpenAI’s rogue agent breached more than just Hugging Face. 

Reuters reported that the rogue AI agent developed by OpenAI, which carried out a multi-day hacking campaign against Hugging Face, also compromised a customer hosted on Modal Labs’ platform. According to Modal’s chief technology officer, the attack exploited a customer’s publicly accessible, unauthenticated endpoint, rather than a flaw in Modal’s infrastructure or security isolation. Hugging Face previously disclosed that the agent first breached a sandbox hosted by a third-party provider before using it to expand its attack, though it did not identify the provider. OpenAI confirmed the agent compromised four accounts across four services but did not name them. The incident suggests the agent’s activity extended beyond Hugging Face. OpenAI said it has since deactivated, encrypted, and restricted access to the AI model involved, while declining to comment further on the Modal-related compromise.

Hugging Face published a technical analysis of the July intrusion, detailing how an autonomous AI agent conducted a 4.5-day attack involving roughly 17,600 actions across thousands of automated decision points. According to the company, the agent, running OpenAI’s ExploitGym evaluation benchmark, appeared to target Hugging Face to obtain benchmark solutions rather than complete the tasks legitimately. The attack unfolded in two stages: first, the agent escaped its evaluation sandbox, compromised a third-party code sandbox, and used it as a launchpad. It then exploited two vulnerabilities in Hugging Face’s dataset-processing pipeline, gaining code execution and access to internal systems before moving laterally. Investigators reconstructed the attack using recovered logs and the open-source GLM-5.2 model. Hugging Face said the only customer data accessed were five ExploitGym challenge datasets and limited operational metadata, with no broader customer assets affected.

The average cost of a data breach continues to rise. 

IBM’s 2026 Cost of a Data Breach Report found the global average cost of a data breach rose 12% over the past year to a record $4.99 million, based on incidents affecting 602 organizations worldwide. Lost business, customer trust, and incident response expenses remain the largest cost drivers. The report also highlights a shift in ransomware tactics, with 41% of victims reporting attackers threatened reputational damage or public exposure to increase pressure for payment. Healthcare recorded the highest average breach cost at $6.6 million, followed by financial services, industrial, technology, and entertainment. IBM also found that more than one in four organizations experienced AI-driven attacks, with deepfake impersonation and AI-enabled malware among the most common. These attacks added an average of $1 million per breach, prompting 85% of organizations to plan increased cybersecurity spending, particularly on zero-trust security and improved data governance.

https://www.spacecom.mil/Portals/57/FINAL%20USSC%20Space%20Warfighting%20Environment%202040.pdf?ver=cWeGIk4tKis7mEPBRYn2zA%3D%3D 

Indirect prompt injection proves irresistible to cyber criminals. 

Proofpoint researchers report growing interest among cybercriminals in indirect prompt injection (IDPI), with underground forums advertising tools that embed hidden prompts into content processed by AI assistants. Subscription services, starting around $150 per month, offer generators for emails, PDFs, calendar invites, and webpages designed to manipulate AI agents rather than human users. Emerging techniques include hidden “white-on-white” text in emails and documents, malicious prompts embedded in PDFs, calendar invitations that target AI-powered email summarization, and prompts concealed in website code or image metadata used in malvertising. While large-scale exploitation has not yet been widely observed, researchers say these tools show attackers are actively developing AI-focused tradecraft. Proofpoint warns organizations to prepare for these techniques, as they are likely to become more common as AI-powered applications and autonomous agents see broader adoption.

Broadcom patches multiple VMware products. 

Broadcom has released security updates for multiple VMware products, including ESXi, vCenter, Workstation, and Fusion, addressing five vulnerabilities, three rated critical. The most severe include a VM escape flaw in ESXi’s VMXNET3 adapter (CVE-2026-47876), an authentication bypass in vCenter (CVE-2026-59309), and a remote code execution vulnerability in vCenter (CVE-2026-59310). Additional fixes address a high-severity denial-of-service flaw and a low-severity logging bypass. Broadcom says there is no evidence of active exploitation but urges customers to apply patches promptly due to VMware’s history of being targeted by attackers.

ShinyHunters claims responsibility for Ernst & Young’s recent breach. 

The ShinyHunters extortion group has claimed responsibility for Ernst & Young’s recently disclosed data breach, which exposed sensitive client tax information stored in a third-party support platform. According to EY, attackers accessed support tickets between March 28 and April 12, obtaining personal and financial data including Social Security numbers and payment card information. The company is offering affected individuals two years of identity protection services but has not disclosed the number of victims or confirmed the attackers’ identity. ShinyHunters has threatened to publish the stolen data unless EY responds by July 31.

 

These aren’t the droids you’re looking for. 

The U.S. is drawing a firm line around advanced robotics, moving to effectively block future imports of foreign-made robots on national security grounds. Federal officials argue that increasingly connected robots could be exploited for espionage, remote disruption, or supply chain leverage, pointing to vulnerabilities previously disclosed in Chinese-made Unitree robots. New FCC restrictions prohibit sales of most foreign-built advanced robots, while exempting machines manufactured in the U.S. and certain systems approved by the Defense Department. Robots already authorized for sale can continue to be imported, and existing owners are unaffected. The policy signals Washington’s broader effort to localize critical technologies. It also hands a potential advantage to domestic manufacturers like Tesla, whose long-promised Optimus robot may now have less foreign competition, provided it eventually graduates from keynote appearances to actual production.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

 

 

And that’s the CyberWire Daily, brought to you by N2K CyberWire.

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.