
Get every episode summarized
Each time CyberWire Daily publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
About this episode
CyberWire Daily is made possible by:
“When initial access vulnerabilities are cheap and automated, attackers can hit everything all the time. But at Black Hat, open AI's Clint Gibler and Spectorops' Robby Winchester reminded me that we don't have to just fight AI with AI at machine speed.”From the transcript
Get every episode summarized
Each time CyberWire Daily publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
203 searchable segments. Every word is indexed and playable.
Full transcript
CyberWire Daily — The Pentagon’s roll call.. Machine-transcribed; use the interactive transcript above to jump the player to any line.
You're listening to the CyberWire network, powered by N2K. When initial access vulnerabilities are cheap and automated, attackers can hit everything all the time. But at Black Hat, open AI's Clint Gibler and Spectorops' Robby Winchester reminded me that we don't have to just fight AI with AI at machine speed. By taking a preventative mindset, defenders can mitigate attack pathways so there's far less occurring at machine speed in the first place. Listen to our full Black Hat conversation at explore.thecyberwire.com slash Spectorops. DLP sucks. Every syso knows it. 20 years of rules and reg X built for another era. Jazz is the DLP that deeply understands your business.
Melody, Jazz's agentic investigator, weighs every data movement against the data, systems, people, and process, then provides analyst with the few incidents fully investigated. In 30 days, 2 million signals in about 80 investigated incidents out. No rules written. Jazz won the 2026 CrowdStrike AWS and Nvidia Startup Accelerator from a nearly thousand applicants. See Melody in action at jazz.security slash N2K. A Pentagon breach exposes data on millions. Shiny Hunters goes dark. MI5 warns universities about Chinese espionage. AI agents find creative ways around their guardrails.
A fake zoom installer delivers macOS malware, Cisco patches and actively exploited SD-WAN flaw. OpenAI disrupts a distillation attack. Cybercommand confronts operator burnout. Treasury targets alleged ATM jackpotters. Our guest is Itamior by President of Threat Intelligence at Kato Networks with a reminder that your network is not a recycling bin. And prophecy as a service. It's Thursday, October 1st, 2026. I'm Dave Bittner and this is your CyberWire Intel briefing. Thanks for joining us here today. It is great to have you with us.
A month's long breach of the Pentagon's personnel records exposed sensitive information belonging to more than three million people with ties to the US military. The Defense Man-Power Data Center says unauthorized users exploited a vulnerability in a file sharing system between October 2025 and July 2026. The compromised unencrypted records included social security numbers, names, dates of birth, contact information, demographic details, and information about military jobs. A Pentagon official says the breach affected roughly 2.8 million living people and 294,000 deceased individuals. DMDC is a major defense department repository maintaining more than 60 million records covering service members, civilian employees, contractors, veterans, retirees, and military families. It also supports identity and credential management across the department.
The Pentagon says it has found no evidence so far that the stolen information has been misused. The identities of those responsible remain unknown. The website used by shiny hunters went offline Wednesday, one day after the Cyber Extortion Group's deadline for the FBI to retract or revise an advisory about its tactics. It's unclear why the site disappeared and the FBI declined to say whether it was involved. Shiny Hunters recently claimed it stole data on nearly all FBI agents as well as job applicants. Reuters' review of a sample found extensive personally identifiable information along with sensitive job, psychiatric, and medical data. The group said the attack was retaliation for a May FBI advisory it considered inaccurate, but later said it had achieved its goals and wouldn't publish the stolen data. Meanwhile, Dutch police arrested a man in connection with a shiny hunter's investigation,
the group denied any association with him. MI5 is warning UK universities that research collaborations linked to a Chinese institute may be helping Beijing improve its espionage capabilities. The agency says more than 100 UK-linked academics have contributed to projects funded by China's Ministry of State Security through the China General Technology Research Institute, also known as CAGT. Some researchers may not have known the ultimate source of the funding. The projects covered areas including artificial intelligence, cyber security, covert communications, and stegonography, which MI5 says can directly support Chinese intelligence operations. The agency is urging universities to review current and planned collaborations with CGTRI and trace funding behind partnerships with Chinese institutions.
MI5 also warned that knowingly assisting or receiving benefits from a foreign intelligence service could carry criminal consequences under the UK's National Security Act. Researchers investigating reported rogue open AI agent activity say the systems appear to have turned routine research tasks into something more troubling. Using public records, the team from asymmetric security found agents probing government health and other websites accessing some pre-production environments and testing reconnaissance techniques including searches for exposed configuration files and attempted SQL injection. The agents also found creative ways around their own sandbox restrictions. By chaining services such as HTTP bin and URL query, they effectively assembled browser capabilities, then used archives and notification services to retrieve data.
Researchers also found attempts to create disposable email addresses and private service accounts. The investigation found no confirmed theft of sensitive information, but because some private scans and temporary communications are no longer accessible, researchers say public evidence alone can't rule it out. JAMP Threat Labs has uncovered cloud-sink D or cloud-sinked, a new two-stage macOS implant disguised as a Zoom installer, researchers first spotted a development build on September 15th, then found versions connected to live command and control infrastructure two days later. The malware walks victims through bypassing Apple's gatekeeper protections, then presents a fake authorization prompt and validates the user's password. Rather than stealing that credential, cloud-sinked uses it to launch its second stage with elevated privileges.
The implant collects basic system information, regularly checks in with its command and control server, and can receive and execute additional mock-o payloads. JAMP didn't observe cloud-sinked establishing persistence, researchers say the malware attempts file-less execution and uses obfuscation and encrypted configuration data, but ultimately still relies on a decidedly traditional technique, persuading the user to enter their password. Cisco has issued urgent patches for a critical authentication bypass in Catalyst SD-WAN manager that's being actively exploited. The vulnerability carries a CVSS score of 9.8 and allows unauthenticated attackers to gain administrative API access using specially crafted HTTP requests. All deployments are affected with no workarounds available. Cisco has released fixed versions and indicators of compromise.
Cisco added the flaw to its known exploited vulnerabilities catalog, giving federal agencies three days to patch. OpenAI says it disrupted a month-long distillation attack that sought to extract its AI models reasoning at scale with a core cluster of activity linked to individuals associated with China's moon-shot AI. The campaign began July 1st and peaked July 24th and 25th when OpenAI observed 16,000 extraction-related requests for more than 4,000 users. Related activity ultimately involved more than 15,000 accounts. OpenAI says attackers didn't breach its systems or access stored conversations. Instead, they manipulated model interactions to expose protected reasoning that could potentially be used to train competing models. The company disrupted the campaign July 28th,
banned associated accounts, tightened sign-ups and infrastructure controls, and expanded monitoring. OpenAI argues that adversarial distillation poses safety risks because copied capabilities may not retain the original model's safeguards. Pentagon has ordered U.S. Cyber Command to accelerate efforts to protect personnel well-being, following reports of recent suicide deaths at the command. In an August memo, top cyber-policy official Catherine Sutton warned that continuous high-tempo cyber operations can impose cumulative cognitive and psychological strain while cyber teams often lack standardized recovery periods. Cyber Command must take seven steps, including reviewing four years of workplace climate data, expanding access to mental and behavioral health professionals, and creating a resiliency framework by mid-October.
The command is also being directed to develop more predictable recovery periods, reconsider consecutive operational tours, and balance campaign demands against long-term force health. Military cyber leaders have separately described efforts to give operators more time away from operations, noting that what began as an operational surge has increasingly become the normal pace. The U.S. Treasury Department has sanctioned Annabelle Alexander Cannellan Aguiere, known as Prometheus, who allegedly developed malware used in ATM jackpotting attacks linked to Trende Araguah. Treasury also sanctioned seven alleged associates and two Mexico-based companies. The network allegedly targets U.S. ATMs by installing malware, remotely bypassing security controls, and commanding machines to dispense their cash. Proceeds are then laundered, including through cryptocurrency, and transferred to TDA members.
Treasury says more than 1,500 recorded jackpotting attacks had caused over $40 million in U.S. losses as of August 2025. Cannellan Aguiere added to the FBI's 10 most wanted list in March became its first fugitive wanted for cybercrime. The Justice Department has indicted 119 people in connection with broader jackpotting conspiracy. Coming up after the break, my conversation with ETA-MAR from Kato Networks, he's got a reminder that your network is not a recycling bin, and prophecy as a service. Stay with us. Nordstrom Rack is celebrating 125 years of Nordstrom with 125 of the best deals up to 65 percent off.
In stores and online, we're talking incredible savings on brands you love like Vince, Sam Edelman, Rack and Bone, all Saints and more. They're only here while supplies last, so shop today. Go into Nordy Club to unlock exclusive discounts, shop new arrivals first and more. Plus buy online and pick up at your favorite rack store for free. Great brands, great prices. That's why you rack. Every time your team deploys a new cloud workload or AI agent, another identity gets permitted access to your critical systems. Legacy tools were built to manage human employees, leaving modern machine and AI access largely unmanaged. That's where IDRA by Palo Alto Networks comes in. Human, machine, AI, one identity platform for all. IDRA replaces permanent permissions with dynamic access, so you can lock down every identity without slowing down your business. Secure every identity with IDRA by Palo Alto Networks. Visit Palo Alto Networks slash IDRA. Again, that's Palo Alto Networks.com slash IDRA.
This episode is brought to you by Google Chrome. You think you know a browser, but Gemini and Chrome? That's new. It can help you with practically anything on the web, like restoring a vintage motorcycle from a 50-page restoration block or finally break down that long article you've had open for weeks. Gemini and Chrome is here for it. Ready to make anything online makes sense? There's no place like Chrome. Check responses set up required compatibility and availability varies 18 plus. Maybe that's an urgent email from your CEO or maybe it's a deep fake targeting your business. Doppel is the AI native social engineering defense platform fighting back against impersonation and manipulation. As attackers use AI to make their tactics more sophisticated, Doppel uses it to fight back, automatically dismantling cross-channel attacks, building team resilience and providing agentech email protection. Doppel, outtacing what's next in social engineering. Learn more at Doppel.com. That's D-O-P-P-E-L.com.
ETA Mayor is vice president of threat intelligence at Kato Networks. I recently sat down with him where he reminded us that your network is not a recycling bin. So today we're talking about some of the attacks that people are seeing with AI specifically the speed at which those are coming at folks. I would love to start off with a little bit of high level stuff here. From your point of view looking back on kind of what led us to where we find ourselves here with this is it fair to say a volatile situation when it comes to help people are adjusting to AI. If we're talking in regards to how companies are adjusting yes but not really surprising you know in the sense of we've been in this race in the past and it seems like it's always the defenders hours on the reactive side of things right.
Something comes up and we try to build something to counter it I think I though gives us a certain level of the plane field and allows us to do a lot more and actually you know perform even and have better security security posture security response when it comes to the things that the adversaries are throwing at us. When you say level the playing field what specifically do you mean in the past like I said we were always reactive and we had to try to keep pace and a lot of times this this keeping pace portion included days weeks sometimes even months let's take one of the you know well known statistics of how long it takes to detect all kinds of vulnerabilities or exploits where the adversaries don't have any. Problem in in sense of how fast they can deploy or checking things they're very fast and for us it's on the defensive side it takes a while I think AI used properly in multiple situations can actually help us be as fast as the threat actors which is actually no more a recommendation but you know with the way that criminals are using AI it's it's actually a must.
When you say used properly what do you propose that that means what sort of guardrails need to be in place. Is the whole discussion on its own but what I mean when I say properly it's actually not in the technical sense but more in the strategic sense I feel like we're starting to get into the same issues that we did about 15 years ago where we we had a point solution for every security problem that arose and what we ended up with is this huge number of products and services and organizations had a hard time implement. In fact if you look at all the reports for example like the IBM cost of a data breach for years the number one contributor for the cost of a data breach was not a ransomware group or some new tactic it was an organization's own security complexity and I feel in some sense that we're going towards AI complexity now with so many points solutions so many issues popping up whether it's the end point or the firewall or posture or or patching or exploitation
and when I say use it properly I mean have actually a platform in place that can allow you to use all these different AI tools in one place rather than just adding more and more tools and adding complexity to your own security organization I think that's a good place to start it. It's an interesting idea I mean is it sort of a to borrow a phrase you know one AI to rule them all. At least one platform to help consolidate and do everything in one place it's it's not very hard to make this kind of prediction that you know if we go next year to whatever it is our say black and whatever whichever conference of your choice i'm pretty sure we're going to start seeing vendors starting to talk and definitely organizations demanding some form of consolidation of different AI tools because there's just a boom in in AI security products and services and offerings which is great it's great. Amazing to see but again we have to think about how do we implement this all in a way that makes sense in a way that we can control and in a way that actually makes life easier for us for detection mitigation and prevention rather than ending endless integration projects and one product doesn't work with the other and so forth that's on the strategic level i'm also happy to go into the more operation on tactical level but that's what I mean by proper use.
Yeah well let's do that let's get into the operational and tactical considerations here what are your thoughts so many things you know if we're talking about you mentioned guardrails before right I think that's an important element that needs to be discussed because i'm sure people and listeners have heard about all these different breaches and all these articles of. AI my AI agent deleted my whole database right or my agent deleted the whole hard drive when I wanted to just delete one folder and you know when I was I have to tell you from a personal experience when I was reading these at some point I kind of something in me was was was very depressed. I'm not a psychological session but I have to share this I started asking myself why do we even have guardrails within these AI models if they're just going to ignore them and do bad things right you you'll see this in AI confessions that AI agents that did the bad things and then the programmer or the DP manager asks it why did you delete it and says yeah I know I'm not supposed to but I did it anyway and when I read those I was like so what's the point.
Why do we even have rules if the agent will ignore them and so I actually went down this rabbit hole and started looking into reward hacking and how these AI agents actually decide to do bad things and what I think organizations should take into account when implementing different AI solutions again going back to using it properly everybody's a code or now right everybody can buy code everybody can do can create software yeah but we need to understand what are these guardrails and the guardrails and the guardrails and the guardrails. The guardrails that the AI agents themselves have let's call them soft guardrails those are our guardrails that are determined within the same channel and are in the AI discretion so if you tell it don't delete or don't do bad stuff you're still don't like within the same channel that the AI operates you're doing it it's in its discretion and one thing that we've learned about AI is it cannot tell the difference between instructions and data when it's coming through the same channel that's why these injectors are not going to be able to do that.
So we have to implement hard guardrails those guardrails that looking to non human identities and say hey this is an agent accessing this folder I don't care what it thinks or wants to do deleting is not part of what it can do so if you think I know this kind of a long winded answer but if I kind of summarize it if you think about risk risk is the probability of something bad happening multiply it. So we have to do it by the impact. Soft guardrails help you lower the probability right don't do something bad I don't want you to do this it's lowering the probability of something bad happen hard guardrails they kept the blast radius. You simply don't allow it and you have to combine the two in order to really reduce the blast radius and the damage that AI can do there's a lot of great things with AI but there also a lot of risks when you're implement to you. Itte Mayor from Kato Networks.
Hey everybody Dave here I want to let you know about a special gathering hosted by Zimperium at the spy museum in Washington DC this invitation only event will bring together federal cyber security and technology leaders. To discuss some of the most pressing challenges facing government today including mobile security mission resilience and the evolving threat landscape I'm always grateful for opportunities to spend time with smart people doing important work and I'm excited to see you again. I hope to see some familiar faces there if you're interested in attending you can request an invitation you'll find more information in our show notes are thanks to Zimperium for sponsoring this event will be a great opportunity for you to join us.
We'll see you there. And now a word from our sponsor Spectorops today AI is rapidly adding non human and agentic identities to modern enterprise environments creating new trust relationships and attack paths. Bloodhound Enterprise helps defenders map attack paths across AWS and hybrid environments as one connected graph identify the choke points that matter most and bring trusted attack path intelligence into approved AI workflows with bloodhound hunter see how Spectorops helps team secure the AI driven identity era at Spectorops.io.
And finally as people increasingly turn to AI for advice researchers see an echo of something much older the oracle from Delphi to religious divination humans have long consulted mysterious systems when ordinary judgment runs out of road. Now chat bots are filling a similar niche answering questions ranging from practical decisions to moral dilemmas and emotional support. The comparison isn't that chat GPT is divine or even particularly good at prophecy rather AI shares one useful feature with traditional oracles opacity even their designers can't fully explain how complex models arrive at particular answers. That in screw to be may itself land AI and aura of authority there's even some historical symmetry Alan touring borrowed the term oracle for theoretical computing in nineteen thirty nine nearly a century later where once again asking the mysterious box for guidance Apollo has apparently been replaced by matrix multiplication of the questions keep coming.
And that's the cyber wire for links to all of today's stories check out our daily briefing at the cyber wire dot com. We'd love to know what you think of this podcast your feedback ensures we deliver the insights to keep you a step ahead in the rapidly changing world of cyber security. If you like our show please share a rating and review in your favorite podcast app please also fill out the survey in the show notes or send an email to cyber wire at n2k dot com. And to case lead producer is Liz Stokes were mixed by tray Hester with original music and sound designed by Elliott Peltzman our contributing host is Maria Vermauses our executive producer is Jennifer Ibn Peter Kielpia's our publisher and I gave bitner thanks for listening we'll see you back here tomorrow.
At Zock doc we know you care about your health you wouldn't do that early morning cardio if you didn't so the fact that your annual physical is overdue just shows how hard it can be to get seen by a doctor sorry that doctors not a network press one for more options you've reached us outside all business hours the next availability is in three months. But Zock doc makes finding the right doctor easy download the app and search by special team insurance and availability read real patient reviews then book instantly Zock doc ready to be seen.
More episodes
More from CyberWire Daily

Earth’s expanding attack surface. [T-Minus: Space-Cyber Briefing]
CyberWire Daily

Play to win, pay to lose. [Research Saturday]
CyberWire Daily

A rough week for safety.
CyberWire Daily

The guardrails go to court.
CyberWire Daily