The CyberWire Daily Podcast 8.18.26
Ep 2617 | 8.18.26

Fake it till you exfiltrate it.

Transcript

A fake consultancy fronts an alleged Chinese spy campaign. Meta heads to court over claims it hooked young users. Researchers crack the mystery behind the French EncroChat hack. CISA warns ransomware gangs are exploiting a Windows flaw. Meet C2Looper, a new Rust-based backdoor. A critical WordPress plugin bug threatens hundreds of thousands of sites. MessiahGPT brings generative AI to cybercrime. A lender discloses a breach affecting 1.2 million people. A Ukrainian developer stands trial in Switzerland over alleged ransomware ties. Our guest is Ev Kontsevoy, CEO at Teleport, discussing how AI agents have nondeterministic behavior. The psychology of the endless scroll.

Today is Tuesday August 18th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

A Chinese espionage campaign imitates an Australian consultancy to lure U.S. experts. 

The Australian consultancy Horizzen became an unwitting target in an alleged Chinese espionage operation after criminals created a fake website impersonating the Brisbane firm and used it to recruit defence, trade, and political experts in the United States. Beginning in mid-2025, Horizzen received a flood of job applications, calls, and emails from people responding to positions the company had never advertised. A year later, the fake website was seized by the FBI as part of a US Department of Justice investigation into 13 websites allegedly linked to Chinese intelligence operations. According to the FBI, the sites used stolen identities, AI-generated images, and fabricated consultancy firms to recruit individuals with access to sensitive or classified information. China has denied the allegations, calling them baseless. The case highlights growing concerns that AI and convincing online impersonation can make espionage recruitment more effective, prompting Five Eyes intelligence agencies to urge businesses and job seekers to report suspicious recruiters and treat unexpected online approaches with caution.

Meta is in court facing claims they deliberately addict young users. 

Meta faces its first federal bellwether trial over claims that Facebook and Instagram were deliberately designed to addict young users and contribute to a youth mental health crisis. California, Colorado, Kentucky, and New Jersey allege the company violated federal child privacy and state consumer protection laws by promoting its platforms as safe while allegedly knowing their risks. If successful, the states could seek damages approaching $200 billion. Meta denies the claims, arguing it has implemented safeguards for teens, including privacy protections and messaging restrictions, and contends it is being unfairly singled out for industry-wide challenges. The six-to-eight-week trial is expected to feature testimony from CEO Mark Zuckerberg and internal company documents. The outcome could influence thousands of similar lawsuits and shape future regulation of social media platforms designed for younger users.

A Czech cybersecurity firm reverse-engineers French government malware. 

Computer Weekly reports that Czech cybersecurity firm Invasys has reverse-engineered the malware French authorities used to hack EncroChat phones in 2020, revealing details previously protected as a national security secret. Researchers found the French implant relied on the Android “Bad Binder” vulnerability, CVE-2019-2215, and the open source Frida toolkit. The malware gained root access, disabled security controls, and copied messages and other data directly from infected phones, often sending them to police within seconds. Invasys also found that much of the exploit code came from publicly available tools and described the malware as technically unsophisticated and prone to failure. The findings appear to support the position that police obtained messages through device interference rather than intercepting encrypted communications in transit. British and European lawyers say the new technical evidence could have major consequences for ongoing appeals and legal challenges concerning the admissibility and disclosure of EncroChat evidence.

CISA tags a high-severity Windows Task Host privilege escalation vulnerability. 

CISA says ransomware gangs are exploiting CVE-2025-60710, a high-severity Windows Task Host privilege escalation vulnerability Microsoft patched in November 2025. The flaw affects Windows 11 and Windows Server 2025 and can allow a local attacker with basic user permissions to gain SYSTEM privileges and take full control of an unpatched device. CISA first added the vulnerability to its Known Exploited Vulnerabilities catalog in April, then updated the listing Friday to confirm ransomware use. The agency has not disclosed details about specific attacks.

C2Looper is a new Rust-based malware family. 

Zscaler ThreatLabz has identified C2Looper, a new Rust-based malware family likely associated with ransomware operations and designed to establish an initial foothold on compromised systems. First observed in July 2026, the malware supports remote command execution, system reconnaissance, and deployment of additional payloads. Researchers believe, with low to medium confidence, that it is distributed through multi-stage ClickFix campaigns. C2Looper uses encrypted strings, dynamically resolves Windows APIs, and communicates with command-and-control servers over HTTP. A newer variant demonstrates ongoing development by replacing traditional infrastructure with GitHub-based command-and-control, adding new reconnaissance and file management capabilities, and improving command handling. According to ThreatLabz, the malware’s evolving feature set suggests it is intended to support lateral movement, data collection, and the deployment of follow-on malware, including ransomware.

A critical Wordpress plugin vulnerability gets patched. 

Defiant has disclosed a critical vulnerability, CVE-2026-15748, in the Forminator Forms WordPress plugin that could allow unauthenticated attackers to achieve remote code execution through arbitrary file uploads. The flaw affects versions up to 1.56.1 and was patched in version 1.56.2. While default configurations reduce the risk, sites using custom file upload storage may be vulnerable to complete compromise through uploaded webshells. The plugin has more than 600,000 installations, with an estimated 300,000 sites still running vulnerable versions. No active exploitation has been reported.

MessiahGPT is a new AI-powered malware generating platform. 

Trellix has identified MessiahGPT, an AI service advertised on BreachForums as an unrestricted platform for generating malware, phishing content, and other illicit material. The service offers free trial queries, paid subscriptions starting at $8 per month, cryptocurrency payments, and no identity verification. Its operators claim the model was built without common AI safety controls and trained on unrestricted data, although Trellix could not independently verify those claims. Researchers say MessiahGPT is part of a growing underground market for criminal AI tools, alongside services such as DarkGPT and APEX AI, as well as stolen access to legitimate AI platforms. The report highlights how cybercriminals are increasingly commercializing AI, offering dedicated services designed to support malicious activities while avoiding the safeguards imposed by mainstream providers.

A consumer lender notifies over 1.2 million people that their personal and financial information was stolen. 

Heights Finance Holdings is notifying more than 1.2 million individuals that personal and financial information was stolen after hackers breached a third-party cloud platform used to store customer data. Exposed information includes names, Social Security numbers, bank account details, government IDs, and dates of birth. The company says its core loan systems were unaffected and has found no evidence the stolen data has been posted online. Heights is offering 24 months of credit monitoring and identity protection to affected customers.

Swiss authorities accuse a Ukrainian developer of involvement in global ransomware operations. 

A Ukrainian software developer is on trial in Switzerland, where prosecutors are seeking a 12-year prison sentence over his alleged role in the LockerGoga, MegaCortex, and Nefilim ransomware operations. Authorities accuse the 52-year-old of helping develop malware used in attacks against companies including Stadler Rail, Crealogix, and Meier Tobler, causing an estimated 130 million Swiss francs in losses. The defendant denies any involvement, claiming ransomware source code found on his devices came from legitimate cybersecurity consulting work and challenging the handling of digital evidence. Prosecutors also seek to confiscate 1.8 million Swiss francs in alleged criminal proceeds and expel him from Switzerland for 12 years. The multinational investigation began after ransomware attacks in 2019, and a verdict is expected in September.

 

 

The psychology of the endless scroll. 

Doomscrolling has become a near-universal habit, turning idle moments into marathon sessions of TikToks, Instagram Reels, and endless feeds. While social media addiction is not officially recognized as a behavioral addiction in the DSM-5-TR, researchers say it shares striking similarities with gambling. Like a slot machine, the infinite scroll relies on unpredictable rewards: most posts are forgettable, but every so often one delivers the perfect joke, video, or insight, keeping users swiping in anticipation of the next hit. Scientists are also exploring dopamine’s role, but the evidence is surprisingly mixed, suggesting the brain’s response may be more complicated than commonly believed. Unlike gambling, social media offers many different rewards, from entertainment and novelty to social connection and relief from boredom, making it difficult to measure, and even harder to resist. In other words, the next great post is always just one more swipe away, which is exactly the problem.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

 

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.