The CyberWire Daily Podcast 8.21.26
Ep 2620 | 8.21.26

The guest nobody invited.

Transcript

CISA orders patching of TrueConf Server vulnerabilities. LockBit threatens release of stolen banking data. Researchers disclose a critical type confusion vulnerability in a Node.js library. A new Agent Tesla v4 campaign introduces enhanced evasion techniques. A novel malware delivery technique abuses FTP server banners to hide commands. Apple patches a critical image-processing flaw. A North Korean software supply chain attack targets the Rust ecosystem. Latvian officials resign following a major data breach. Defense contractors are confident in compliance, less so in their ability to prove it. Our guest is Patrick Coughlin, Co-Founder and CEO of Savi Security. discussing the free utility he’s developed to protect the sandwich generation from AI-driven scams. When it comes to cyber extortion, who you gonna call?

Today is Friday August 21st 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

CISA orders patching of TrueConf Server vulnerabilities.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has directed federal agencies to urgently patch two critical, actively exploited vulnerabilities in the self-hosted TrueConf Server communications platform. The flaws, CVE-2026-72529 and CVE-2026-72530, allow unauthenticated attackers to achieve remote code execution, with one exploiting a missing authentication weakness and the other enabling sandbox escape through code injection. CISA added both to its Known Exploited Vulnerabilities (KEV) catalog and ordered Federal Civilian Executive Branch agencies to remediate them by September 3. While CISA has not disclosed attack details, Kaspersky reports the Head Mare hacktivist group has exploited both vulnerabilities since July to distribute backdoor malware through trojanized client installers, targeting Russian organizations across multiple sectors. The advisory follows earlier reports of separate zero-day attacks against TrueConf by suspected Chinese threat actors.

LockBit threatens release of stolen banking data. 

US Bank is investigating claims by the LockBit ransomware group that it breached the bank and stole data, which the attackers threaten to publish on September 3 unless an extortion demand is paid. The bank says it is aware of the claims but has found no evidence of unauthorized access to its network or impact to internal systems. LockBit posted the alleged breach on its leak site without disclosing the scope or nature of the purportedly stolen data. The incident comes despite law enforcement’s 2024 disruption of LockBit, which later resurfaced with its LockBit 5.0 ransomware. The claims also follow recent third-party data exposure incidents affecting US Bank customers, though those were linked to vendors rather than the bank’s own systems. US Bank says its investigation remains ongoing while it continues monitoring the situation.

Researchers disclose a critical type confusion vulnerability in a Node.js library. 

Researchers have disclosed a critical type confusion vulnerability in the widely used Node.js isolated-vm library that could allow remote code execution (RCE) on the host system. The flaw, which has not yet received a CVE identifier, affects the ExternalCopy function used to transfer data between V8 JavaScript Isolates. According to EndorLabs, the vulnerability stems from a time-of-check/time-of-use (TOCTOU) weakness that lets attackers manipulate the transfer process, potentially causing a denial-of-service crash or hijacking the host process to escape the sandbox. Systems that execute untrusted JavaScript and expose at least one ivm.Reference to the sandbox are particularly at risk. The issue has been patched in isolated-vm versions 6.2.0 and 7.0.1, which prevent user-controlled JavaScript from executing during the data-copy operation.

A new Agent Tesla v4 campaign introduces enhanced evasion techniques. 

KnowBe4 researchers have identified a new Agent Tesla v4 campaign that introduces enhanced evasion techniques and credential theft capabilities. Delivered through a business email compromise (BEC) lure targeting finance teams, the malware uses a JScript dropper containing Unicode emoji characters to evade signature-based detection and hinder manual analysis. Once executed, it injects the payload directly into memory, avoiding file-based scanners, and employs multiple anti-analysis techniques, including code obfuscation, debugger detection, and hardware fingerprinting. Agent Tesla v4 is designed to steal credentials from more than 40 applications, including web browsers, messaging platforms, and Windows credential stores, while also capturing keystrokes and clipboard data. Stolen information is exfiltrated within seconds to an attacker-controlled FTP server. KnowBe4 recommends updating email security and detection rules to identify the malware’s distinctive emoji-based obfuscation patterns.

A novel malware delivery technique abuses FTP server banners to hide commands.

Researchers have uncovered a novel malware delivery technique that abuses FTP server banners to hide commands used to deploy two previously undocumented remote access trojans, E4del and PINHOLE. FTP banners are text strings the server uses as a greeting message for connecting hosts before they log in. First observed by MalwareHunterTeam and further analyzed by SOCRadar, the campaign has been active since at least July 2026 and likely begins with phishing emails delivering ZIP archives containing malicious LNK files. These files retrieve PowerShell commands embedded in FTP greeting messages, enabling malware delivery without traditional command-and-control infrastructure. E4del is a Node.js-based RAT disguised as a Discord application, while PINHOLE retrieves additional configuration from Pinterest and SurveyMonkey and uses advanced memory-only execution techniques. Although FTP-based command delivery is less stealthy than web-based dead-drop resolvers, researchers warn it is flexible and could be adapted for future malware campaigns.

Apple patches a critical image-processing flaw. 

Apple has released security updates for iPhones, iPads, Macs, and other devices, addressing multiple vulnerabilities, including a critical image-processing flaw that security experts say resembles past spyware delivery vectors. The most significant fix, CVE-2026-65346, is an integer overflow vulnerability in Apple’s ImageIO framework that could allow arbitrary code execution when a malicious image is processed. Reported by Meta’s Red Team X, the flaw was mitigated through improved input validation. Experts recommend installing the updates promptly, noting that similar image-parsing vulnerabilities have previously been exploited in zero-click spyware campaigns. Apple also patched CVE-2026-65329, a Telephony authentication flaw that could allow attackers with privileged network access to intercept traffic. Additional security updates were released for older iPhones and iPads, as well as visionOS.

A North Korean software supply chain attack targets the Rust ecosystem. 

Wiz researchers have attributed a recent software supply chain attack targeting the Rust ecosystem to North Korean state-sponsored threat actors. The attackers compromised a trusted maintainer’s account on crates.io, modifying three widely used Rust libraries to silently import a malicious typosquatted dependency during the build process. Because the payload executed during compilation, developers and continuous integration (CI) systems could be compromised simply by building affected projects. The malware was designed to steal browser credentials, cryptocurrency wallet data, and developer secrets. Wiz found the campaign’s infrastructure closely matched previous North Korean operations attributed to the Sapphire Sleet group. The Rust Security Response Team removed the malicious packages and revoked the compromised account, but organizations are urged to inspect dependency lockfiles, treat affected build systems as compromised, and rotate exposed credentials and API keys.

Latvian officials resign following a major data breach. 

Latvia’s Road Traffic Safety Directorate (CSDD) has confirmed that a cyberattack exposed historical payment receipt data belonging to more than 1.2 million people and 200,000 businesses, affecting roughly two-thirds of the country’s population. The stolen data includes personal or company identification numbers, vehicle license plates, payment details, and some address information, though passwords, phone numbers, and email addresses were not compromised. Authorities say the attack exploited an internet-facing vulnerability and followed significant preparation by technically skilled attackers. While CSDD’s services remain operational and a subsequent attack was blocked, the breach has sparked political fallout, with Latvia’s president calling for the agency’s leadership to resign. Investigators continue to examine the incident, while CERT.LV warns the stolen information could be used in phishing and social engineering campaigns. Criminal and regulatory investigations remain underway.

Defense contractors are confident in compliance, less so in their ability to prove it. 

Two new industry surveys suggest defense contractors are increasingly confident in their cybersecurity compliance, but many still lack the evidence needed to prove it. Kiteworks found that while 96% of contractors believe their self-reported Supplier Performance Risk System (SPRS) scores would withstand scrutiny, only 29% could support that confidence with both a current SPRS submission and a FedRAMP-authorized platform. The survey also revealed widespread confusion following the Pentagon’s pause of CMMC 2.0 Phase 2 assessments, despite ongoing DFARS compliance obligations. Separately, CyberSheath reported SPRS scores reached a five-year high, but confidence in their accuracy declined sharply, and only 1% of respondents felt fully prepared for CMMC certification. Both surveys found broad support for maintaining independent verification while simplifying compliance requirements without sacrificing objective proof of cybersecurity readiness.

 

Next up, we are joined by Patrick Coughlin⁠, Co-Founder and CEO of ⁠Savi Security⁠. Patrick discusses protecting the sandwich generation from AI-driven scams and Scamwise, their free utility built with this purpose in mind.

We’ll be right back.

Welcome back. You can find information about Patrick's company's Scamwise tool in our show notes. 

When it comes to cyber extortion, who you gonna call? 

A curious new twist in the ransomware economy suggests there may be even less honor among thieves than usual. Researchers at GuidePoint Security say a group calling itself Ransom Busters has been approaching ransomware victims before attacks become public, offering to recover encrypted files and delete stolen data for far less than the original ransom demand. According to GuidePoint, the supposed rescuers are likely not independent cyber vigilantes but a ransomware affiliate diverting payments away from the very ransomware-as-a-service gangs it worked with. Investigators linked the activity to attacks involving DragonForce, Settra, and Anubis, finding identical forensic artifacts across incidents, including shared tools, the same backdoor account password, and a common attacker hostname. The findings suggest one affiliate may be working across multiple ransomware operations while quietly undercutting its criminal partners. As GuidePoint notes, paying these “helpers” offers no guarantee that stolen data will actually disappear, making this a particularly enterprising variation on cyber extortion.

 

And that’s the CyberWire Daily, brought to you by N2K CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

Tomorrow on Research Saturday, guest Aaron Beardslee⁠, Manager of Threat Research at ⁠Securonix⁠, shares an evolved version of the SHEETCREEP espionage campaign, using a diplomatic-themed ISO phishing lure to deliver a C# remote access trojan targeting Indian diplomatic interests.

This Sunday on The T-Minus Space Cyber Briefing, Maria Varmazis sits down with Filip Rezabek, Co-Founder and Technical Lead of SpaceComputer, to discuss how space offers something cryptography can't: physical isolation. Tune in Sunday for the full conversation.

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.