Skip to content
TrackPodcasts
newsMar 9, 202630:30

From Tehran to the Apple II.

CyberWire Daily

About this episode

Israel claims a strike on Iran’s cyber warfare headquarters. The Trump administration releases a new national cyber strategy.  DHS shakes up its IT and cybersecurity leadership. Velvet Tempest uses ClickFix to drop loaders and RATs. Researchers uncover a Linux cryptocurrency clipboard hijacker. The DOJ brings a Ghanaian romance scammer to justice. Online advertising enables government tracking. Monday business breakdown. Our guest is Jon France, CISO from ISC2, sharing some insights and findings from their 2025 ISC2 Cybersecurity Workforce Study. An Apple II app gets audited by AI.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Joining us today is Jon France, CISO from ISC2, sharing some insights and findings from their 2025 ISC2 Cybersecurity Workforce Study. For further detail, you can also check out ISC2’s just released Women in Cybersecurity report. Selected Reading Iranian cyber warfare HQ allegedly hit by Israel | brief (SC Media) Iran internet blackout reaches 6th day as rights groups call for end to digital shutdown (The Record) The long-awaited Trump cyber strategy has arrived (CyberScoop) DHS CISO, deputy CISO exit amid reported IT leadership overhaul (FedScoop) Termite ransomware breaches linked to ClickFix CastleRAT attacks (Bleeping Computer) ClipXDaemon: Autonomous X11 Clipboard Hijacker Delivered Via Bincrypter-Based Loader (Cyble) Ghanaian Pleads Guilty to Role in $100m Romance Scam (Infosecurity Magazine) The Government Uses Targeted Advertising to Track Your Location. Here's What We Need to Do. (Electronic Frontier Foundation) Zurich Insurance Group intends to acquire UK cyber insurer Beazley for approximately $11 billion. (N2K Pro Business Briefing) Microsoft Azure CTO says Claude found vulns in Apple II code (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.   Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Interactive timestamps

Jump to segment

Get every episode summarized

Each time CyberWire Daily publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

180 searchable segments. Every word is indexed and playable.

From Tehran to the Apple II.

CyberWire Daily

0:00
30:30

Full transcript

CyberWire DailyFrom Tehran to the Apple II.. Machine-transcribed; use the interactive transcript above to jump the player to any line.

0:00You're listening to The CyberWire Network, powered by N2K. We're leaving today and entering a world of Mickey Mouse waving, princess meeting and greetings. Lightsaber clashing! The toilets on tower of terror dropping! Banshee flying! Space Mountain launching! Galaxy rewinding, what's the whole network galaxy rewinding? Fireworks igniting! World of other worlds! For whatever you love! Infinite worlds await at the most magical place on earth! Walt Disney World Resort! Israel claims a strike on Iran's cyber warfare headquarters. The Trump administration releases a new national cyber strategy. DHS shakes up its IT and cyber security leadership. Velvet Tempest uses click-fix to drop loaders and rats.

1:03Researchers uncover a Linux cryptocurrency clipboard hijacker. The DOJ brings a Ghanaian romance scammer to justice. Online advertising enables government tracking. We got our Monday business breakdown. Our guest is John France. CISO from ISC2. Sharing some insights and findings from their 2025 ISC2 cyber security workforce study. And an Apple II app gets audited by AI. It's Monday, March 9th, 2026. I'm Dave Bittner and this is your CyberWire Intel Briefing. Thanks for joining us here today. It's great as always to have you with us.

2:09Happy Monday. Israel says it struck a Tehran compound that allegedly housed Iran's cyber warfare headquarters. The intelligence directorate and other key military units, including elements of the Islamic Revolutionary Guard Corps. The Israel Defense Forces announced the operation but provided few operational details beyond a digital illustration of the site. While the strike targeted facilities linked to Iran's cyber operations, its actual impact on Tehran cyber capabilities remain unclear. Threat intelligence monitoring suggests cyber activity tied to Iran has continued despite the attack. Analysts note that cyber operations often rely on distributed infrastructure and remote operators, meaning physical facilities are not always critical to ongoing campaigns. Additionally, a nationwide internet blackout in Iran following February 28th US Israeli strikes appears to have disrupted connectivity more than the destruction of the compound itself.

3:11Security researchers warned that Iranian state-sponsored groups have already established access within regional networks before hostilities escalated. These prepositioned capabilities, along with externally operated infrastructure, could allow operations to continue even while domestic connectivity is degraded. The Trump administration released a new National Cyber Strategy Friday that emphasizes stronger offensive cyber operations, protection of federal networks and critical infrastructure, streamlined regulations, and expanded use of emerging technologies like AI and post-quantum cryptography. The document outlines six pillars, including shaping adversary behavior through both government and private sector cyber capabilities, modernizing federal systems with zero trust and advanced encryption, securing infrastructure and supply chains, and building a stronger cyber security workforce.

4:13The strategy also promotes reducing regulatory burdens while encouraging coordination between government and industry. Separately, President Trump signed an executive order directing agencies to prioritize prosecution of cyber crime and fraud, including efforts against foreign-backed criminal networks. Industry groups broadly welcome the strategy's focus on deterrence, innovation, and regulatory reform, though some lawmakers criticized it as vague and lacking a detailed implementation plan. The White House said more detailed guidance will follow in future policy documents. The Department of Homeland Security is undergoing a shake-up in its IT and cyber security leadership, with multiple senior officials departing amid a broader reorganization. Chief Information Security Officer, Hamant Bydwan, is expected to leave later this month following the February exit of Deputy CISO Amanda Day, who is joined Workday as Vice President of Cyber Security and Trust.

5:21Sources say the changes are part of a wider realignment led by DHS Chief Information Officer Antoine McCord, aimed at consolidating IT leadership across the Department's component agencies under the Central DHS CIO office. The effort reportedly includes placing headquarters personnel into key technology roles across agencies, such as FEMA and CISO. The leadership churn coincides with other high-level changes, including the departure of Homeland Security Secretary Kristi Nome. Some officials warned the upheaval could risk a brain drain at DHS during a period of heightened geopolitical tensions and cyber threats. The ransomware group Velvet Tempest is using the ClickFix social engineering technique and built-in windows tools to deploy doughnut loader malware and the castle rat back door, according to researchers at Malbecan.

6:21The activity was observed over 12 days in an emulated U.S. non-profit network with more than 3,000 endpoints. Attackers gained access through a malvertising campaign that presented a fake capture and instructed victims to paste an obfuscated command into the Windows Run dialog. The command launched nested command line processes that downloaded malware loaders, followed by PowerShell scripts used for reconnaissance, credential harvesting from Chrome, and staging additional payloads. The intrusion ultimately deployed doughnut loader and retrieved castle rat enabling persistent remote access. Although Velvet Tempest is known for deploying major ransomware strains such as Ryuk, R-Evil, Conti, and Lockbitt, researchers did not observe ransomware being executed in this case. Researchers at Cible Research and Intelligence Labs identified a new Linux malware strain called ClipX Damon and Autonomous Cryptocurrency Clipboard hijacker targeting X11-based environments delivered through a loader structure previously linked to shadowHS activity.

7:36The malware appears unrelated to that campaign with both likely using the same open source bin-cryptor encryption framework independently. ClipX Damon operates without command and control infrastructure or external communication. Instead, it monetises victims by monitoring the system Clipboard and replacing copied cryptocurrency wallet addresses with attacker-controlled ones, the malware targets multiple currencies, including Bitcoin and Ethereum. The attack chain uses a three-stage process, an encrypted loader, a memory resident dropper, and a persistent on-disc ELF payload. It employs stealth techniques such as process masquerading, demonization, and avoidance of wayland sessions operating only in X11 environments. Researchers say the campaign reflects a shift toward autonomous user-focused financial malware on Linux systems.

8:37A Ghanaian national, Derek Vanyabo, pleaded guilty to participating in a global fraud scheme involving romance scams and business email compromise according to the U.S. Justice Department. The Ghana-based operation caused more than $100 million in losses with about $10 million attributed to Van Yibal. Prosecutors say he posed as romantic partners to gain victims trust and convince them to send money and also impersonated business executives or suppliers in BEC scams to redirect corporate payments. He additionally helped launder proceeds from the fraud. Vanyabo pleaded guilty to conspiracy to commit wire fraud, which carries a maximum 20-year prison sentence and agreed to pay more than $10 million in restitution and forfeiture. New reporting shows U.S. Customs and Border Protection has used location data drawn from the online advertising ecosystem to track people's phones without warrants.

9:41Documents obtained by 404 media confirm the agency relied partly on data generated through real-time bidding, the advertising process that auctions add space on websites and apps. RTB broadcasts user information such as device identifiers and location data, the thousands of companies during add auctions, allowing data brokers to collect and sell that information. Law enforcement agencies have purchased this data to track individuals' movements, often bypassing traditional warrant requirements. Privacy advocates warn the practice exposes how surveillance-based advertising systems can enable government monitoring. Experts urge stronger privacy laws limits on precise location data in add systems and restrictions on the sale of sensitive data to authorities. Individuals can reduce exposure by disabling advertising IDs and limiting apps' location permissions.

10:44Turning to our Monday business breakdown, several cybersecurity startups announced major funding rounds as investors continue backing AI-driven security platforms and resilience technologies. Upguard raised $75 million in a series C-round to expand its AI-powered cyber-risk posture management platform and pursue acquisitions. Israeli firms Gambit Security and FIG Security emerged from stealth with $61 million and $38 million respectively to develop cyber resilience and SECOPS platforms. Jetstream Security launched with $34 million for AI governance and security tools while threat-aware secured $25 million to expand its cyber-asset management platform. Armor code raised $16 million to advance its AI-exposure management platform and SecFix obtained $12 million to grow its compliance automation services.

11:46In mergers and acquisitions, Zurich Insurance Group plans to acquire UK Cyberinsure Beasley from about $11 billion to expand cyber-risk coverage. Other deals include Echo acquiring OT Security firm Data Logics, myriad 360 buying technology provider AdVisex and Bastion Security Group acquiring Australian Security Engineering firm Astralis. Be sure to check out our weekly business briefing that's on our website and is part of CyberWire Pro. Coming up after the break, my conversation with John France from ISC2 with some of the insights and findings from their Cybersecurity Workforce study. And an Apple 2 app gets audited by AI. Stick around.

13:09Score more with the college branded Venmo debit card and earn up to 5% cash back with Venmo stash. Got paid back? With the Venmo debit card, you can instantly access your balance and spend on what you want, like game day snacks, gear, tickets, and more. The more you do, the more cash back you can earn. Plus, there's no monthly fear minimum balance. Sign up now at Venmo.com slash college card. The Venmo mastercard is issued by the bank court bank NA, select schools available. Venmo stash terms and exclusions apply at Venmo.me slash stash terms. Max $100 cash back per month. John France is Chief Information Security Officer at ISC2. I recently caught up with him for insights and findings from their 2025 ISC2 Cybersecurity Workforce study.

14:12We've actually been running this for a good number of years now, so it's kind of one of our year-to-year reports, so it's got referential integrity. You can look at the trend. Even if you disagree with the absolute figures, the trend is what's important and some of the insights that comes from it. It drills into a number of areas, technical skills, and covers around 16,000 cyber security professionals have input into the reports. Pretty big survey. Yeah, pretty big sample size there. Let's dig into some of the results here. What are some of the findings that caught your eye? Yeah, as a few cannot mention, cannot talk about technology. If you're not going to talk about AI, so AI is an in-demand skill, no surprise there. I think probably what's surprising is if you looked sort of two years ago, it was either not on the survey or very, very low down and now it's at least by the professionals, the number one desired technical skill.

15:13I think it's number two by hiring managers, so that's really leapt up to the four. That's one of the key findings. And really a shift from that, do we have enough people in the seats to actually do the people have the right skill sets that we need to protect society? And it's the latter. It's a focus on skills and skill sets rather than just the sheer number of people really came through loud and clear. And we started to see that trend come through the 2020 course survey as well, so it's reinforcing that that direction of travel. Can we dig into the notion of the skills shortages, because I think as you mentioned, that's been trending for a few years now, unpack that for me. What does that really mean for both the folks out there looking for jobs and the folks looking to hire? So I think there's sort of two components to it. One is cybersecurity profession requires and desires not just requires skilled professionals within it that are market current.

16:16I think that's what really comes to the forehand game that that leapfrog of AI shows that an in demand skill set or an in demand technology in the business sense. Translates to an in demand skill set in this is cybersecurity sense, not only using AI for good security outcomes, but obviously securing AI as well. So the business can go and execute on the opportunity in a risk managed way. And some of those skills are fast moving, AI being one of them. And we've actually seen really some of the non technical skills, so things like strong problem solving teamwork and collaboration skills come to the fore. Strong communication skills is now one of the most expressed desired non technical skills. And I think that shows an adaptability of what a cyber pro needs to be so technically proficient, absolutely in the relevant technologies and the relevant security stuff, but also now a true member of business able to communicate logically think and problem solved.

17:16I hear so many people out there saying that they're finding frustration when they're out there looking for these jobs. And yet on the other side, you'll hear hiring people who I guess the old chestnut has been that they're out there looking for unicorns. And so it's hard for the people who are just starting out to find their place. Is that reflected in the survey at all? Well, we didn't look at sort of the absolute numbers game, but I think there is a little bit of difference between high managers that looking for. And what so the number one non technical skilled demanded there was problem solving 29% versus professional view, which is problem solving 55% battery top there was the communication skills. So yet there's a little difference between the desire line and actuality. But I think if you sort of really unpack it, we've got some interesting macro economic conditions, so there's continuing pressure on resources and budgets.

18:18And therefore that means if you have a limited hiring opportunities, you're going to want to hire the people that are most compatible with what you're looking for. And that piece of rarity comes through and that that's maybe what's stressing the market a little little bit. You know, and if we concentrate on the non technical skills, those are things you can use to differentiate. Hard technical skills are learnable and teachable and trainable. The good pro quo is we should do that as a profession anyway and a good employer does but balance that against some of the non technical and develop those as equally. So there are jobs out there, but they may be looking for something slightly different. And you mentioned entry level, I think what we've seen in this year's survey and in in previous is really a focus on some some of the experiences that you bring not just the qualifications that you bring. And there's a number of good ways of going going to get them. So we're not precluding entry level at all. In fact, I know personally in my team, we've got to build the next generation.

19:28So you know, looking for entry level schools is one of those key things the profession has to do. But you mentioned AI, what sort of pressure is that putting on the folks in that entry level position there? Are we finding people displaced by the AI tools already? I think what we're starting to see is potentially a change in shape at the job. So I know there was a positive and many comments have said it's kind of disintermediate entry level positions. I don't think that's true. I think what the entry level position will do is slightly different technology has always been moving along at a pace and we've seen jobs change and react technology. And do we see the wholesale elimination of entry level jobs by technology? Very, very rarely, if at all. But what you do in that entry level position is definitely changing. So we're seeing AI as a desired skill for entry level positions as well, which is actually how to use it effectively.

20:29Using it for good security outcomes and we sort of talk a little bit about AI being used to get to a decision point quicker. So it's going to speed up and make you efficient in what you do. So again, embrace it. And I think entry level people are probably AI natives more more than, you know, like me and potentially you. So they're well equipped and well placed to adopt it rapidly. And I think that that's the other thing. AI is probably one of those skills that has been rapidly adopted. So from very little two years ago to pretty much the top in demand to his henceforth. So that rate of changes is probably the not not shocker. It's predictable sort of a little bit, but still no worthy. That rate of changes is going up. It's not going down. Yeah. John, I'm curious for your opinion on this. I mean, I was talking to someone not long ago, a senior level person who was concerned that it was going to be harder for people to accumulate the skills to become a senior level person.

21:42Is there a few opportunities on the way up? And perhaps AI displacing some of those folks. Do you share that view? No, not not wholesale. I think actually what's if you're going to make it to sit the senior echelons in cyber security, historically, it's been looked at as a very technical discipline and technical career path. Notion is somewhat suffering quite rightly. As we become closer to partnering for business, our business skills and acumen have to complement it at the senior level. So yes, understand technology risk control and all that good stuff, but balance that against being able to communicate talk and operate at a business level. I think actually as cyber professionals, especially at the senior level, it's about getting some of those opportunities and experiences in the sort of the arts of business, not just the arts of security. So I think I think it's a different landscape to what we traditionally seen maybe a decade ago. And one, actually, I wholeheartedly embrace yes, I'm a techie, but I love business as well. Technology is usually in service to a business outcome.

22:58When we talk about AI and the attractive skills that people are bringing to the table here, did there survey dig into that at all? Are there specific things that are going to have someone's resume put to the top of the pile? No, I mean, I don't think we've got a hard data on, you know, is it large language model, is it prompt injection, is it? It didn't go to that level. So we don't have that kind of empirical data to reflect back. But again, I come back to that repetitive change. So, you know, this week, it might be AI for incident response. And next week, it might be for something different. I think getting comfortable with using a modern tooling until sets and technologies, I think one of them is probably where you've got to really show show your metal as it were, which is comfortable in changing comfort in adopting new ways of working. Well, based on the information that you all have gathered here, what's your advice, what sort of words of wisdom do you have for the folks who are out there?

24:04I think it's actually employers and not just getting employed, but whilst you're in job, we're looking for a good balance between technical skilling empirical knowledge that's teachable, trainable. So certification is part of that. But also some of those non technical skills. In fact, that's they tend to be good differentiators. So strong problem solving skills, teamwork, collaboration, communication, critical logical thinking, those kind of things are a really, really good way to show adaptability. And really sort of go in with a balanced approach, so it's not all about technology, not all about business, it's about the intersection of those two and security pros is obviously about risk management ultimately. You can't, whilst the old phrase, you can't accumulate without speculation and speculation, you need to take some risk as well. So we are the purveyors of taking appropriate risk within appetite and later in the business, get what it needs to be done and actually being part of that change.

25:08And we'll have a link to ISC 2's 2025 ISC 2 cybersecurity workforce study in the show notes, our thanks to John France for joining us. It's not just something you made, it's the privilege that you get to work with your hands, it's building something that serves a purpose, proof that you have the grit to keep going. At Timberland, we understand you take your craft seriously and we do too, which is why our products are built to the highest quality. We put in the work so you can perfect yours with purpose in every detail and crafted with intention. Timberland, built on craft, visit Timberland.com to shop. Spring starts at the Home Depot and we are bringing the heat to your backyard this season. Fire up the flavor with our wide variety of grills for under $300, like the next grill for burner gas grill that's perfect for hosting your spring cookout.

26:13Then set the scene and turn your outdoor space into the go-to spot the patio sets for every budget. Bring it this season with grills that deliver flavor and patios that set the vibe from the Home Depot. Start your spring with low prices guaranteed at the Home Depot, exclusive supplies at home Depot.com slash price match for details. And finally, Microsoft Azure CTO, Mark Resinovich, recently decided to revisit a piece of his own programming history. A small Apple II utility he wrote in 1986, he gave it a modern audit courtesy of AI. The program called enhancer was written in 6502 machine code to extend Apple soft basic with more flexible go to and go sub commands. Resinovich fired up Claude Opus 4.6, which promptly decompiled the four decade old code and spotted several flaws, including a subtle bug where the program quietly misbehaved instead of throwing an error when a destination line wasn't found.

27:23The fix in hindsight was simple, check the carry flag. The discovery is mostly nostalgic trivia for Apple II enthusiasts, but it highlights a broader shift. Modern AI systems can now analyze low level code and uncover vulnerabilities in software that humans may not have examined for decades. That capability could help defenders patch old systems, though it also gives attackers a powerful new way to hunt for bugs lurking in the world's vast supply of aging firmware and legacy code. And that's the CyberWire, or links to all of today's stories, check out our daily briefing at the CyberWire.com. Don't forget to check out the Grumpy Old Geeks podcast where I contribute to a regular segment on Jason and Brian's show every week. You can find Grumpy Old Geeks where all the fine podcasts are listed.

28:24We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire at n2k.com. N2K's lead producer is Liz Stokes, where mixed by Tray Hester with original music and sound designed by Elliott Peltzman. Our contributing host is Maria Vermazus. Our executive producer is Jennifer Iban, Peter Kielpie is our publisher and I'm Dave Bitner. Thanks for listening. We'll see you back here tomorrow. Rinse knows that greatness takes time, but so does laundry. So rinse will take your laundry and hand deliver it to your door, expertly cleaned. And you can take the time pursuing your passions.

29:37Time one spent sorting and waiting, folding and queuing, now spent challenging and innovating and pushing your way to greatness. So pick up the Irish flute or those calligraphy pens or that daunting beef Wellington recipe card and leave the laundry to us. Rinse, it's time to be great.

More episodes

More from CyberWire Daily

View all episodes →