
Get every episode summarized
Each time CyberWire Daily publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
About this episode
CyberWire Daily is made possible by:
“When initial access vulnerabilities are cheap and automated, attackers can hit everything all the time. But at Black Hat, open AI's Clint Gibler and SpecterObs' Robby Winchester reminded me that we don't have to just fight AI with AI at machine speed.”From the transcript
Get every episode summarized
Each time CyberWire Daily publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
490 searchable segments. Every word is indexed and playable.
Full transcript
CyberWire Daily — A rough week for safety.. Machine-transcribed; use the interactive transcript above to jump the player to any line.
You're listening to the CyberWire network, powered by N2K. When initial access vulnerabilities are cheap and automated, attackers can hit everything all the time. But at Black Hat, open AI's Clint Gibler and SpecterObs' Robby Winchester reminded me that we don't have to just fight AI with AI at machine speed. By taking a preventative mindset, defenders can mitigate attack pathways so there's far less occurring at machine speed in the first place. Listen to our full Black Hat conversation at explore.thecyberwire.com slash SpecterObs. DLP sucks. Every syso knows it. 20 years of rules and reg X built for another era. Jazz is the DLP that deeply understands your business.
Melody, Jazz's agentic investigator, weighs every data movement against the data, systems, people, and process, then provides analyst with the few incidents fully investigated. In 30 days, 2 million signals in about 80 investigated incidents out. No rules written. Jazz won the 2026 CrowdStrike AWS and Nvidia Startup Accelerator from a nearly thousand applicants. See Melody in action at jazz.security slash N2K. Open AI fires safety researchers for mishandling sensitive information. Syso looks to secure the next 250 Dell patches six critical flaws while attackers exploit a 4-to-mail zero-day. Warlock ran somewhere expecting to be a new and a new one. The first time we've seen a new one, we've seen a new one, but we've seen a new one, but we've seen a new one, but we've seen a new one,
and we've seen a new one. bounty components available in this whole world circle. It's Friday, October 2nd, 2026. I'm Gabe Bittenner and this is your Cyberwire Intel briefing. Thanks for joining us here today. Happy Friday. It's great to have you with us. Open AI has fired three safety researchers for allegedly sharing confidential company information with an outside AI safety organization, the Wall Street Journal reports. The company says an internal investigation found the employees' mishandled sensitive information and outside established procedures violating company policies.
The departures come as open AI confronts broader concerns about increasingly capable AI systems. The company has recently reported incidents in which AI agents escaped containment, hacked company websites, and aggressively probed other sites. Earlier this week, open AI also scrapped the planned launch of its GPT 6.1 astramodel over safety concerns. Open AI says it has responded by introducing new monitoring for agent misbehavior, strengthening, testing guardrails, and sharing more information about problematic model behavior. The developments come amid a wider industry debate over AI safety andthropic CEO Dario Amode recently called for slowing the pace of advanced AI development, a position that drew agreement from open AI CEO Sam Altman and Elon Musk. Dell has patched six critical vulnerabilities in its container storage modules, which
connect Dell enterprise storage platforms to Kubernetes environments. Two maximum security flaws could allow unauthenticated remote attackers to bypass authorization and gain administrative control over storage infrastructure. More additional vulnerabilities could enable attackers to gain root access, forge authentication tokens, or access Kubernetes secrets. Dell says it has not identified active exploitation and recommends customers update to the latest versions as soon as possible. Fortinet is warning that attackers are actively exploiting a critical 4-to-mail zero day. The vulnerability rated 9.8 out of 10 affects the 4-to-mail management interface and allows an unauthenticated attacker to write arbitrary files through specially crafted HTTP or HTTPS requests, potentially enabling unauthorized code execution. Fortinet has released indicators of compromise associated with observed attacks, but hasn't
disclosed who's responsible when exploitation began or how many systems have been compromised. Patches are still pending for several affected 4-to-mail versions until they arrive, 4-to-net recommends disabling IBE support or restricting management interface access to trusted private networks. Sissa has added the vulnerability to its known exploited vulnerabilities catalog and ordered federal agencies to conduct forensic triage and mitigate the flaw by October 4. A Chinese ransomware group known as Warlock is targeting high-value organizations in Spanish and Portuguese-speaking regions. Also tracked as LongLegs and Storm 2603, the group has attacked organizations including a water utility, telecom provider, government body, and university. Warlock exploits Microsoft's SharePoint vulnerabilities for initial access, then uses techniques including DLL side loading and Visual Studio Code remote tunneling.
Researchers also observe the group staging ransomware in active directories SissVall Share using replication to distribute the payload efficiently to domain controllers. Microsoft says Russian state-backed hacking group Star Blizzard has significantly expanded its fishing operations this year, targeting more than 100 organizations primarily in the U.S. and the U.K. The FSB-linked group, also known as Callisto and Cold River, has moved from highly targeted spearfishing toward campaigns involving hundreds of emails, likely using an automated mass-mailing platform. We're initially targeting Ukrainian users with fake tax and fine notices. Star Blizzard expanded globally, impersonating think tanks, NGOs, and even internal colleagues. Microsoft has identified at least 13 large-scale campaigns since January. The group is also introduced a malware delivery technique Microsoft calls Red Flick.
Victims receive password protected archives that can install the cosmic pulse-backed door using scheduled tasks. Unlike Star Blizzard's earlier click-fix technique, Red Flick requires just one action from the victim, potentially increasing the group's chances of successful compromise. Researchers at Georgia Tech have mapped what they describe as the first global measurement of large area maritime GPS spoofing using real-world ship traffic, analyzing AIS data for more than 367,000 vessels. They identified 31 persistent zones of abnormal GPS activity, with 22 showing strong evidence of spoofing. Ships appeared to make impossible movements, jumping onto land, traveling at extreme speeds or following artificial circular and straight line tracks. The study detected nearly 18,000 abnormal episodes between November 2024 and February 2025,
spanning more than 31,000 hours. Notably, researchers found spoofing near Port Sudan five months before the MSC Antonia grounded in the Red Sea in May 2025, following an incident attributed to GPS spoofing. Solar activity appeared in the Strait of Hormuz, Black Sea, and elsewhere. The researchers cautioned that AIS data can reveal suspicious patterns, but cannot identify who generated the counterfeit GPS signals. An Iranian national accused of participating in a massive hacking campaign has been extra-dited from Montenegro to the United States. Montenegro authorities identified the suspect only as AB, but the details correspond with Amir Barati, an alleged member of Iran's Mabna Institute. U.S. prosecutors say the group hacked hundreds of universities, companies, and government agencies beginning in 2013, stealing more than 31 terabytes of academic and intellectual property.
The attacks allegedly support Iran's revolutionary guard and caused more than $3.4 billion in losses. European law enforcement has disrupted the Kilsack ransomware operation, arresting three suspects, including a 16-year-old believed to be the group's administrator and main operator. Kilsack has operated since 2024 and is suspected of roughly 1,000 attacks with at least 500 successful compromises. Led by German police, Operation Kill Switch seized five servers and the group's leak site domains, preventing about 110 terabytes of stolen data from being published. Authorities conducted searches in Spain, Greece, Romania, and the UK. Kilsack operated as both a ransomware as a service group and data broker, targeting organizations through software vulnerabilities and poorly secured cloud storage. Properly, U.S. authorities indicted Dutch national Faoud El Tsabrizy, also known as Archduke,
on hacking and extortion charges tied to Kilsack. He was arrested by British police on September 30th. Coming up after the break, my conversation with John Kiddervag and Dr. Chase Cunningham were discussing their new book, Cyber Resilience at Machine Speed, the Zero Trust Model for the AI era. And Clippy's back and this time he wants your wallet. Stay with us. This episode is brought to you by Google Chrome. You think you know a browser, but Gemini and Chrome, that's new. It can help you with practically anything on the web, like restoring a vintage motorcycle from a 50 page restoration block or finally break down that long article you've had open for weeks. Gemini and Chrome is here for it.
Ready to make anything online makes sense? There's no place like Chrome. Check responses set up require compatibility and availability, very 16 plus. Every time your team deploys a new cloud workload or AI agent, another identity gets permanent access to your critical systems. Legacy tools were built to manage human employees, leaving modern machine and AI access largely unmanaged. That's where IDIRA by Palo Alto Networks comes in. One machine, AI, one identity platform for all. IDIRA replaces permanent permissions with dynamic access so you can lock down every identity without slowing down your business. Secure every identity with IDIRA by Palo Alto Networks. Visit Palo Alto Networks slash IDIRA. Again, that's Palo Alto Networks.com slash IDIRA.
Your heart can tell you a lot about your health. Apple Watch Series 12 measures your heart rate every 5 seconds with the most accurate heart rate sensing and awareable. So your vital zap now with heart rate variability can tell you when something is off. And your readiness score can let you know when to rest and when to push. Here the story in every heartbeat with Apple Watch Series 12. The features described are for wellness purposes only and not for medical use. iPhone 11 or later require based on Apple conducted study of heart rate accuracy August 2026. Visit apple.com slash Apple Watch Series 12. Maybe that's an urgent email from your CEO or maybe it's a deep fake targeting your business. Doppel is the AI native social engineering defense platform fighting back against impersonation and manipulation. As attackers use AI to make their tactics more sophisticated, Doppel uses it to fight back automatically dismantling cross channel attacks, building team resilience and providing
a lot of support. John Kindervog and Dr. Chase Cunningham are among a group of authors of the new book Cyber Resilience at Machine Speed the zero trust model for the AI era. We got together for this preview. John I'd love to start with you. My understanding is this book was your brainchild. What prompted you to take on this topic? Well, I mean there was a lot of people asking me to take on the topic zero trust in the AI world because there's always a lot of people who were kind of naysayers and say zero trust won't work for this. There was a trust won't work for this and that.
And so I already knew that it was working for AI. But what I didn't want to do is be the sole author of it. So someone who was very wise told me years ago there are no great books, only great chapters. And so I reached out to 13 people that I really admire in this industry, including Dr. Chase Cunningham and asked them to contribute a chapter. And I think we got a great book out of that because I would have maybe written a great chapter, but we got a great book. Chase, what made you decide that this is a project that you wanted to sign on to? Well, it means to be perfectly frank. If John says, hey Chase, there's a building on fire. You should run in there. Like I'll do it because that's just how it works. I mean, I've been working with John for so long and he's been such a great mentor. But as far as the book goes, I genuinely enjoy writing. The topic area was really interesting to me. And I agree with John. I personally think that this is actually the greatest time in history for CT because
machines and all these AI agents, they don't have an HR department. And they're not kind of complaining about us telling them we don't trust them. So it really just lined up well. And John was kind enough to just kind of say, look, here's the broad scope. What I'd like you to write about and go. And I love writing. So when you turn me loose, I get after it. Well, John, what was your organizing principle here? How did you divvy out the assignments to your co-collaborators? Well, there's a five-step model for deploying zero trust. First, you define the protect surface. Then you map the transaction flows. After that, you architect the network, the environment. I decide what products need to go in, essentially. Step four is policy. So you instantiate the policy in the products and step five is monitoring, maintaining. So I just laid out the book in those five steps. And then I looked at who amongst the people that I think are really good at CT could
really contribute to that. And Chase had already written a book on policy and graph databases and how attackers think in graphs, but defenders think in lists. And I wanted him to just hone in on that for that one chapter. So he's part of that part of the book. And so I just went to different people who had expertise in different areas to write the chapters based upon the five-step model. Well, Chase, let's dig into your specific chapter. Can you walk us through the topic that you covered? Yeah, I mean, John's point on graph database and sort of the adversarial mindset, I think is what's missing in a lot of people's approach to the problem is interestingly enough. And we think about security. We're all usually thinking from a posture of defense and nothing bad ever happening and not allowing X to occur. And in truth, that's not going to, that's not the way things work.
You're always going to be in a position where you have to be able to respond and you have to understand how the adversaries are approaching things from there. And because that's where you, you know, in the military, we were afraid we'd meet the enemy at the door. And that's what you're trying to do. And so my contribution here was really to look at how would that be applicable in this particular context, especially in kind of the new era that we're falling into and then do those sort of legacy approaches around visualization and understanding and context apply. And absolutely they do. So that was kind of the overall impetus for that. And then, you know, getting the reader to understand the fundamentals of all the things we've talked about strategy still matter. It's just now you have a scope and speed that is beyond human speed. You mentioned lists and graphs. Can you unpack that a bit for us? Sure. So if you look at, you know, Sim and some of the legacy technologies and those types of things, what they usually show you is a big glorified spreadsheet of a bunch of things, doing a bunch
of stuff and it's a bunch of linky lights and you kind of hope that you can understand what's going on there. Whereas from the perspective of what is actually valuable and I've been a red team or I've been, I guess you could say pseudo bad guy, your goal is that person that entity is to be more contextual to understand the intricacies of what is being missed and then to know where the pivot points are and you don't get that from looking at a spreadsheet. You don't get that from looking at a bunch of alerts on a screen. You have to understand with total context where you go, what you do, what areas to avoid. And this in the militaristic approach also leans more towards understanding the battle space. And so I want you to contribute as well. So it all really lines up on getting people to keep their head in the game around what works and what is just kind of security theater. You know, John, one of the key elements of the book is this notion of cyber resilience. I've noticed personally in the past three months or so that cyber resilience has become
a hot topic. People are reaching out to us and it's something that they really want to talk about. How do you define it and why do you think it's become such a, it's come to the fore and the way that it has? Well, because, you know, as Chase says, we assume that an organization probably has been breached. They've got, you know, malicious actors inside the organization. That's dwell time. They're sitting there learning everything that they can do and they're deciding what they're going to attack, right? And so what resilience is is the ability to withstand an attack and get revert back to a good state, you know, and not completely go down. And so I even talk a little bit about going beyond resilience into anti fragility because one of the things that zero trust can do is make the environment stronger and stronger
over time when there's a lot of load. And so resilience, you know, and robustness is another thing people talk about. But what it means is that the, that our environment just won't just fall over when there's an attack. And too many environments completely fall over when there's an attack and when you see that over and over again, I mean, you think about target, you think about TJ Maxx or TJXX, you think about so many things that you think about land rover, Jaguar Land Rover. I mean, they could make a car from, I don't remember how long, but it was, it was weeks. And so they completely fell over because they weren't resilient environments and they allowed the attackers to go on a wild shooting spree, right? And I have a saying that all bad things happen inside of an allow rule and this gets back to what Jason was talking about in the list because in traditional security technology,
there's a list of policies. And generally the first policy that meets the criteria of the traffic gets instantiated, that may not be the best policy, right? But it's the first one in that list. And so if somebody puts a policy in a firewall, for example, in any, any allow rule, and this is, I've seen this more than once in my career, they put it as the first rule because that's, they put it into, to just get it up and running. And then they never took it out. And so they have a very expensive box called a firewall. It's doing absolutely nothing. You might as well just have the two jacks connected with a coupler for all the security you're getting. And that's because people don't understand policy. So we're so focused on products that we don't focus on policy and policy that comes from a graph perspective is better policy than policy that comes from a list perspective. Well, John, help me understand the relationship between cyber resilience and zero trust.
Is it a parallel relationship? Is there intersection there? How do you combine or have the two work to their best effect? So cyber resilience is an outcome. And zero trust is a way of achieving that outcome. You know, I had dinner last night with one of the other contributors of the book, actually a friend of Chase's as well, Leewell Young Coney. And he has this concept that zero trust is a verb. You do it, right? And so you as you're doing it, the process of doing it makes the environment more resilient, more anti-fragile, more stable because there's less opportunity for attackers to ride, you know, open, flat unrestricted networks and get access to sensitive data and assets. Chase, did you mention that you had some experiences of penetration tester?
Yeah, I was a red teamer for the government and then I was on the national cyber collegiate defense competition a few times. And on my, you know, individual career, I did a bunch of red teaming and I was acted as a bad guy, which is probably more of a comment on my own personality than anything else. I'm curious, from that experience, where there are times where you were called to question the traditional perimeter model, the days before the popularity of zero trust? Yeah, I mean, when I came over to Forster and John, you know, kind of told me I was going to follow up with his footsteps. It was interesting because immediately I was like, I don't want to carry someone else's laundry. But when I started looking at what the concept was and the approach as a red teamer, I looked at it and I was like, yeah, he was at on point like this is the stuff that would make me miserable. Like, I would quit what I was doing if the red teaming was still a thing. And I was working out of infrastructure built that way. So that was kind of a light bulb moment for me that, you know, strategy matters every
day and twice on Sunday. And then the reality of the space is it's meeting the adversary where the adversary is going to try and, you know, maneuver. And as long as you can do that, you stay with them now. Today, it's moving at light speed. But, you know, the bad guys don't own the patent on light speed. We can operate that speed too. And I think that's a real important point because we're at, we're at an inflection point in history because of AI, the post mythos world, whatever you want to call it, where we're not going to be able to take our time and manually make changes, do long change control meetings and all that kind of stuff. We're going to have to enable technology to take action at the same speed as the attack. And that's what happens in kinetic warfare. Chase is a veteran. He's done some stuff, as they say, and involved in some shenanigans.
Some things, yeah, shenanigans. And when you're, when the enemy is firing on you, you don't, you know, call back to base and say, hey, let's have a three hour meeting to see whether we should shoot back or not. Right? And so what we do in cybersecurity, and I've often used the example of an airbag, what if you tried to deploy an airbag the same way we do change control, right? You couldn't do it, right? You'd be, you'd be dead. Whole purpose is automation. And so the airbag goes off as soon as the sensor sees the problem and it protects you. And yeah, every once in a while, maybe in history, we've had a few airbags that just went off on their own, but it's much better to have an airbag than not to have an airbag. I think we all can agree on that. Well, we can work at that same speed in cybersecurity now because AI is a tool that defenders can
use as well as attackers. And I think a lot of people are recognizing this. And I think this is the key that you can use AI to say that's a real attack against real systems that are critical. So we're going to stop it right now by changing the policy and putting a deny rule in place and not allowing that traffic to get access to that data set for those assets. This John Kindervog and Dr. Chase Cunningham, the book is titled Cyber-Rezillion Set Machine Speed, the Zero Trust Model for the AI era. It's available now. Do check it out. This episode is brought to you by Google Chrome. You think you know a browser, but Gemini and Chrome, that's new. It can help you with practically anything on the web, like restoring a vintage motorcycle from a 50-page restoration block, or finally break down that long article you've had open
for weeks. Gemini and Chrome is here for it. Ready to make anything online makes sense? There's no place like Chrome. Check responses set up require compatibility and availability varies 18 plus. Hey everybody, Dave here. I want to let you know about a special gathering hosted by Zimperium at the Spy Museum in Washington DC. This invitation only event will bring together federal cybersecurity and technology leaders to discuss some of the most pressing challenges facing government today, including mobile security, mission resilience, and the evolving threat landscape. I'm always grateful for opportunities to spend time with smart people doing important work, and I'm excited to be part of these conversations. I hope to see some familiar faces there. If you're interested in attending, you can request an invitation. If you'll find more information in our show notes, our thanks to Zimperium for sponsoring this event, we'll see you there.
Your heart can tell you a lot about your health. Apple Watch Series 12 measures your heart rate every five seconds with the most accurate heart rate sensing and awareable. So your vital zap now with heart rate variability can tell you when something is off, and your readiness score can let you know when to rest and when to push. Enter the story in every heartbeat with Apple Watch Series 12. The features described are for wellness purposes only and not for medical use. iPhone 11 or later require based on Apple conducted study of heart rate accuracy August 2026. Visit apple.com slash Apple Watch Series 12. And now a word from our sponsor Spectorops. Today, AI is rapidly adding non-human and agentic identities to modern enterprise environments, creating new trust relationships and attack paths. Bloodhound Enterprise helps defenders map attack paths across AWS and hybrid environments as one connected graph. Identify the choke points that matter most and bring trusted attack path intelligence
into approved AI workflows with Bloodhound Hunter. See how Spectorops helps team secure the AI-driven identity era at Spectorops.io. And finally, Microsoft's official X Twitter account briefly traded software updates for crypto promotion Thursday. After someone gained unauthorized access to the account and brought Clippy along for the ride. The account with more than 13 million followers swapped its profile picture for Microsoft's famously persistent paper clip assistant and amplified an account promoting a Clippy cryptocurrency token. The post disappeared as did a short-lived apology stating that Microsoft neither supported
nor authorized the token. Microsoft later confirmed the compromise said it had secured the account and was investigating. While the attackers got in remains unknown, possibilities range from fishing and sim swapping to stolen session cookies or a compromise third party social media tool. For now, Clippy's latest comeback appears to be over. It seems the anthropomorphic paper clip was just trying to help with your investment portfolio. And that's the CyberWire for links to all of today's stories. Check out our daily briefing at the cyberwire.com. On behalf of my colleague, Maria Vermauzis, a program note, the T-space Cyber Briefing this Sunday, picks up where last week's left off. If you haven't listened to part one, I highly recommend you go and do that. But to refresh your memory, Maria Vermauzis speaks with two foundational experts in space
cyber security. The Lanko Star Chick and Andy Olcawa, both from Vision Space. Their new book is Hot Off the Presses. It's called the Space Craft Hacker's Handbook, exploiting ground stations, flight software and satellite terminals. Tune in Sunday to learn more. Be sure to check out this weekend's research Saturday. My conversation with Jean-Pierre Mouton, Senior Threat Intelligence Consultant at Guidepoint Security. We're discussing their research how play achieves encryption. That's Research Saturday. Check it out. We'd love to know what do you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cyber security. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwireatentuk.com. In two K's lead producer is Liz Stokes, who are mixed by Trey Hester with original music
and sound designed by Elliott Pounceman. Our contributing host is Maria Vermazas. Our executive producer is Jennifer Iban, Peter Kielpies our publisher and I'm Dave Bitner. Thanks for listening. We'll see you back here next week. Your heart can tell you a lot about your health. Apple Watch Series 12 measures your heart rate every five seconds with the most accurate heart rate sensing and awareable. So your vital zap now with heart rate variability can tell you when something is off. And your readiness score can let you know when to rest and when to push. Here's the story in every heartbeat with Apple Watch Series 12. The future is described for wellness purposes only and not for medical use. iPhone 11 or later required based on Apple conducted study of heart rate accuracy August 2026. Visit apple.com slash apple watch series 12.
Finding a doctor is hard enough. Finding the right doctor even harder. Someone who takes your insurance has an available appointment when you need one and feels like someone you can actually open up to. That's where Zock.com's in. Download the Zock.com app to search and compare doctors by specialty, insurance and availability. Read real patient reviews find the right fit for you and book instantly because getting seen by the right doctor matters. Zock. Ready to be seen? Download the Zock.com app today. Hi there. I am fully charged and here to tell you Toy Story 5 is now on Disney Flash. What do you think? It's been too long, Cowboy. What do you buzz and Jesse are back for a brand new adventure with some seriously cool new tech. What? Holy butter scotch. You said it, Jesse. So save your batteries and watch the global phenomenon at home and the best part it's perfect for the whole family. Power up your movie night and watch Disney and Pixar's Toy Story 5 now streaming on Disney Plus rated PG.
More episodes
More from CyberWire Daily

Earth’s expanding attack surface. [T-Minus: Space-Cyber Briefing]
CyberWire Daily

Play to win, pay to lose. [Research Saturday]
CyberWire Daily

The Pentagon’s roll call.
CyberWire Daily

The guardrails go to court.
CyberWire Daily