The CyberWire Daily Podcast 8.24.26
Ep 2621 | 8.24.26

The odds were classified.

Transcript

Polymarket traders win big on U.S. military insider information. Slovakia deactivates speed cameras with Russian backdoors. TikTok pays $400 million to settle kids' privacy allegations. Hackers infect Android-based car systems with botnet malware. CISA orders quick patching of an actively exploited Zimbra Collaboration Suite vulnerability. SynkLoader malware is built for stealthy access to corporate networks. Dutch authorities fine Uber over $900 million over automated hiring practices. An ATM jackpotter gets a record prison sentence. Monday business briefing. Our guest is Mark Beare, General Manager at Malwarebytes Consumer Business, looking at protecting your family in the age of AI. A privacy promise loses face.

Today is Monday August 24th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

Polymarket traders win big on insider U.S. military information. 

More than 150 Polymarket International wallets may have traded using inside U.S. military information, potentially broadcasting sensitive signals to outside observers, Reuters reports. 

The Anti-Corruption Data Collective, or ACDC, identified 152 highly successful wallets trading military and defense markets. Together, they made $8 million, with an average win rate of 97.2 percent. ACDC cautions that these patterns can have other explanations, including luck. Researchers also found signs that large traders and automated bots copied some suspicious wagers.

Public blockchain transactions can make unusual betting activity visible in real time. If suspicious trades reflect non-public military information, copycat activity could amplify those signals and increase potential national security risks. ACDC argues stronger identity requirements and restrictions on certain prediction markets may be needed.

Slovakia deactivates speed cameras with Russian backdoors. 

Slovakia has deactivated 279 newly installed speed cameras after its national security service identified multiple security vulnerabilities, including SMS-activated Russian backdoors.

The NBU found hardcoded Russian phone numbers that could reportedly trigger shell and network access by sending an SMS. Researchers also found ineffective SecureBoot protections. The cameras’ web portals exposed live streams to anyone with a device IP, without requiring a password. The NERO R-ONE cameras are thought to be rebranded Russian CORDON PRO.M systems.

Compromised traffic infrastructure could create security risks beyond traffic enforcement. Remote administrative access and exposed camera feeds could provide unauthorized parties with visibility or control. Slovakia’s Interior Ministry has deactivated the cameras pending an independent audit.

TikTok pays $400 million to settle kids' privacy allegations. 

TikTok will pay $400 million to settle a 2024 U.S. government lawsuit alleging violations of children’s online privacy protections.

The Justice Department and Federal Trade Commission accused TikTok of knowingly allowing children under 13 to create accounts and unlawfully collecting information from children using Kids Mode. TikTok will pay $300 million immediately, with another $100 million due after a court vacates an earlier consent decree involving Musical.ly.

The settlement reinforces the legal obligations companies face when handling children’s personal information. The Justice Department also acknowledged TikTok’s subsequent changes to privacy practices, age controls, parental oversight, ownership, management, and compliance.

According to the Justice Department, the agreement represents one of the largest recoveries obtained in a Children’s Online Privacy Protection Act case. 

Hackers infect Android-based car systems with botnet malware. 

Hackers are infecting Android-based car systems with malware designed to expand a botnet and route other people’s internet traffic through vehicles.

Kaspersky found the malware on DoFun head units, the computers controlling functions including navigation, music, and Bluetooth. Attackers reportedly abused TWCore, a legitimate system application, to silently install malware called JarService. One observed module turns compromised devices into reverse proxies, making routed traffic appear to originate from the vehicle’s connection.

Automotive computers represent another class of internet-connected devices that attackers can potentially recruit for fraud and traffic routing. Kaspersky says DoFun subsequently fixed the security issues.

According to Kaspersky, the campaign is attributed with high confidence to MoYu Group, linked to the BadBox operation. 

CISA orders quick patching of an actively exploited Zimbra Collaboration Suite vulnerability. 

CISA has ordered federal civilian agencies to patch an actively exploited Zimbra Collaboration Suite vulnerability within three days, setting an August 24 deadline.

Tracked as CVE-2026-73570, the command-injection flaw affects the Simple Network Management Protocol, or SNMP, notification component when notifications are enabled. Zimbra patched the issue in version 10.1.20. CERT Polska first reported active exploitation. Shadowserver later identified more than 270 compromised Zimbra instances while searching for exploitation artifacts.

Successful exploitation can let an unauthenticated attacker execute operating-system commands as the Zimbra user. Experts recommend reviewing logs and files for evidence of compromise.

SynkLoader malware is built for stealthy access to corporate networks. 

Researchers at Expel have uncovered SynkLoader, a new malware family delivered through Microsoft Teams phishing and built for stealthy, hands-on access to corporate networks.

The attack begins with someone posing as an IT helpdesk employee and convincing a user to install a malicious MSI package. SynkLoader then executes components largely in memory and bridges Python, PowerShell, C#, and C++. Researchers observed modules for system profiling, persistence, remote command execution, network tunneling, and screen control. Another module displays a fake Windows lock screen to steal login credentials.

The combination of stolen credentials and network tunneling could let attackers access internal and external systems through the victim’s machine, potentially reducing signs of unusual login locations.

Researchers assess with low-to-medium confidence that the toolkit may be associated with ransomware operators or an initial access broker. 

Dutch authorities fine Uber over $900 million over automated hiring practices. 

Dutch data protection authorities have fined Uber 825 million euros, or about $964 million, over automated driver suspensions.

The regulator says Uber violated the General Data Protection Regulation by allowing software to suspend driver accounts, sometimes permanently, without human review. It also says Uber failed to properly inform drivers about automated decision-making. The violations allegedly occurred from 2018 through 2022.

Automated decisions affecting people’s livelihoods remain subject to European privacy protections. Uber disputes the findings and says it will appeal.

An ATM jackpotter gets a record prison sentence. 

A Venezuelan national has received an eight-year federal prison sentence for participating in an ATM jackpotting scheme responsible for millions of dollars in losses.

The Justice Department says 27-year-old Juan Manuel Gouveia-Aguilera pleaded guilty to bank fraud, bank burglary, and cyber-enabled fraud charges. The court held him responsible for more than $3.5 million in losses. ATM jackpotting typically involves accessing a machine, connecting a laptop, and installing malware that commands the ATM to dispense its cash.

Malware-enabled jackpotting remains a significant threat to financial infrastructure. The FBI reported roughly 1,900 attacks since 2020, with losses exceeding $20 million last year.

Monday business briefing. 

Cybersecurity and AI companies announced several new funding rounds and acquisitions, with investment spanning data security, AI governance, penetration testing, and critical infrastructure protection.

Prevalent AI led the funding announcements with a $22 million growth investment, followed by Xpander at $7.5 million, Cytix at $7 million, and Neuromorphic Labs at $5.1 million. TopHat Security also announced an undisclosed Series A. On the acquisition front, Dynatrace agreed to acquire AI observability company Arize for $915 million. Datavault AI agreed to acquire CyberCatch Holdings for $94.5 million. Fortinet acquired Virtue AI, while Cribl acquired technology assets from Radiant Security’s AI SOC product.

The activity shows investors and established vendors directing capital toward AI security, governance, observability, and broader enterprise risk capabilities.

A privacy promise loses face. 

ClarityCheck tells users its reverse image search is “private and secure.” Security researcher Jeremiah Fowler found the company had apparently left more than nine million image files accessible online. Privacy, it seems, had encountered a configuration issue.

Fowler discovered roughly 450 gigabytes of profile pictures, screenshots, and other images, including photographs of children, in an unsecured Amazon S3 bucket. The files sat in folders labeled “faces” and “profiles.” A URL in ClarityCheck’s publicly available website code provided access without authentication. Fowler also found misconfigured APIs that could reveal potential email addresses, physical addresses, and phone numbers simply by manipulating website URLs.

ClarityCheck secured both issues after WIRED contacted the company. It disputes describing the data as “publicly exposed,” arguing that access required knowledge of a specific, unindexed URL. The company also says there is no evidence of malicious access.

Facial images are particularly sensitive. Passwords can be changed. Faces are somewhat less cooperative. Fowler warns exposed photographs could potentially be harvested for AI training, impersonation, or scams. Faces, it seems, still have limited reset options. 

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.