3799 afleveringen
- Ismael Valenzuela, Vice President of Labs, Threat Research and Intelligence at Arctic Wolf, sits down with Dave to discuss their work tracking Anubis. Arctic Wolf Labs details a series of 2026 Anubis ransomware intrusions, revealing affiliates using stolen VPN credentials and exploiting CitrixBleed 2 to gain initial access.
Attackers then blended into legitimate IT activity by deploying RMM tools, using RDP and PsExec for lateral movement, stealing credentials, and establishing tunnels and proxies for persistence and exfiltration. The research highlights a repeatable attack chain defenders can disrupt before encryption, from suspicious remote access and unauthorized RMM deployment to credential theft, security-tool tampering, and ransomware execution.
The research and executive brief can be found here:
From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks - The G7 and CISA prepare for the quantum threat. Nightmare Eclipse drops a CrowdStrike zero-day. The White House’s offensive hacking plan raises legal questions. CISA offers a playbook for communicating through cyber incidents. OpenAI puts a billion dollars behind AI-powered defense. Researchers uncover a serious PostgreSQL flaw. Google patches an exploited Chrome zero-day. Broadcom fixes VMware vulnerabilities. Attackers target a WordPress plugin flaw. Lawmakers tell license plate surveillance cameras to “Flock off.” Our guest is Kevin Gosschalk, Founder and CEO of Arkose Labs, discussing his new book, After Bots, which questions the old assumption that automated traffic is inherently malicious. Camouflage for the algorithmic age.
Remember to leave us a 5-star rating and review in your favorite podcast app.
Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.
CyberWire Guest
Kevin Gosschalk, Founder and CEO of Arkose Labs, joins us to discuss his new book, After Bots, and why the old assumption that automated traffic is inherently malicious no longer works.
Selected Reading
G7 urges organizations to prepare for quantum cyber threats (The Record)
Analysts: Trump Cyber Program Could Cost Firms Legal Shields (BankInfo Security)
Communicating Under Pressure: Best Practices for Service Providers (IC3)
OpenAI Pledges $1bn to Bring its AI Cybersecurity Tools to Essential S (Infosecurity Magazine)
12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover (SecurityWeek)
Google warns of new Chrome zero-day flaw exploited in attacks (Bleeping Computer)
VMware Workstation and Fusion Updates Patch Critical Vulnerability (SecurityWeek)
Critical Elementor Pro flaw exploited to take over WordPress sites (Bleeping Computer)
Flock Cameras Face Removal Nationwide Under New Bill (Newsweek)
Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC (The Register)
This 'Digital Camouflage' Shirt Confuses AI-Powered Surveillance Cameras (404 Media)
Share your feedback.
What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.
Want to hear your company in the show?
N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.
The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. - A watchdog challenges the Trump administration’s secret frontier AI reviews. METR discloses two cyberattacks. Leaked documents reveal a Russian cyber training pipeline. Rogue ScreenConnect clients spread malware like a worm. A breach exposes appellate court records across the U.S. and Canada. Spring Ring impersonates IT support on Microsoft Teams. Plex urges users to patch, and Cisco warns of unpatched Secure Email flaws. Our guest is Rob van der Veer, Chief AI Officer at Software Improvement Group, discussing how we are not keeping up with the AI attack surface. Robocall report cards.
Remember to leave us a 5-star rating and review in your favorite podcast app.
Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.
CyberWire Guest
Today we are joined by Rob van der Veer, Chief AI Officer at Software Improvement Group, discussing how we are not keeping up with AI attack surface.
Selected Reading
Trump may be forced to reveal secret rules feds use for AI safety testing (Ars Technica)
Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks (The Register)
2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators (Security Affairs)
Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity (Huntress)
A breach at Thomson Reuters reached appellate courts in twelve US jurisdictions (Thenextweb)
Spring Ring Vishing Attack Uses Fake IT Calls on Microsoft Teams to Install Malware (Hackread)
Plex warns users to patch security vulnerabilities immediately (Bleeping Computer)
Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities (SecurityWeek)
The FCC wants consumers to rate their telecom’s anti-robocall protections (CyberScoop)
Share your feedback.
What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.
Want to hear your company in the show?
N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.
The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. - Nexus sells driver’s license scans on the dark web. OpenAI says its models have reached a “Critical” capability threshold. International law enforcement disrupts a decades-old botnet. AI hallucinations fuel “slop squatting.” Plus, urgent patches for Cleo Harmony and Virtualizor, a Texas healthcare breach, and a Russian national accused of targeting thousands of freelancers with remote-access malware. Maria Varmazis shares the latest space-cyber news. Our guest is Rob Allen, Chief Product Officer at Threat Locker, talking about protecting against AI in the workplace. AI threatens the government’s bug supply.
Remember to leave us a 5-star rating and review in your favorite podcast app.
Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.
CyberWire Guest
On today’s Industry Voices we are joined by Rob Allen, Chief Product Officer at Threat Locker, talking about protecting against AI in the workplace. If you enjoyed this conversation, be sure to check out the full interview here.
Selected Reading
FBI Probes Service Selling 153M+ Drivers Licenses (Krebs on Security)
OpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity Threshold (SecurityWeek)
Sality botnet infrastructure dismantled in joint global takedown (Bleeping Computer)
Crooks Are Learning to Love AI Hallucinations (IEEE Spectrum)
MSSA Reference Architecture 2.0 (Mobile Satellite Services Association (MSSA))
Exploit Published for Fresh Cleo Harmony Vulnerability (SecurityWeek)
Malicious Virtualizor Update Served via BGP Hijacking (SecurityWeek)
Nutex Health Says Patient Data Stolen, Hackers Threaten Leak (Infosecurity Magazine)
US charges Russian for infecting 80,000 freelancers with malware (Bleeping Computer)
How AI could make it harder for governments to use hacking tools (TechCrunch)
Share your feedback.
What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.
Want to hear your company in the show?
N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.
The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. - Nightmare Eclipse drops a Kaspersky zero-day. The Financial Stability Board warns frontier AI could threaten the global financial system. Anthropic says it has tightened security. CISA adopts a risk-based approach to patching. A new Windows infostealer hides in fake AI models. A critical vulnerability in JFrog Artifactory is kneedeep in active exploitation. North Korean workers are still landing U.S. jobs. A classic NSA codebreaking machine. Our guest is Heather Ceylan, CISO at Box, discussing if AI becomes agentic, governance could become a resilience issue. A robot vacuum sucks up evidence.
Remember to leave us a 5-star rating and review in your favorite podcast app.
Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.
CyberWire Guest
Today on our Industry Voices, we are joined by Heather Ceylan, CISO at Box, discussing as AI becomes agentic, governance becomes a resilience issue. If you enjoyed this conversation, be sure to check out the full interview here.
Selected Reading
Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher (SecurityAffairs)
Financial Stability Board Sounds the Alarm Over Frontier AI Risks (Infosecurity Magazine)
Unit 42 warns AI has shifted balance of power from defenders to attackers (CyberScoop)
Improving our alignment and security practices (Anthropic)
CISA vulnerability directive designed to ‘buy back time’ against hackers (Federal News Network)
RevStealer malware spread through fake Claude Opus 5 download (SC Media)
Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild (SecurityWeek)
North Korea-linked IT Workers Are Getting Hired Inside Western Companies (SecurityAffairs)
IBM Built the Cold War's Most Powerful Code Breaker for the NSA (IEEE Spectrum)
Man uses robot vacuum to covertly record his wife's affair, wins divorce settlement but gets sentenced to prison for making an illegal recording — Husband lands behind bars after counter-suit over privacy rights (Tom's Hardware)
Share your feedback.
What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.
Want to hear your company in the show?
N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.
The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Meer Nieuws podcasts
Trending Nieuws -podcasts
Over CyberWire Daily
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
Podcast websiteLuister naar CyberWire Daily, De Dag en vele andere podcasts van over de hele wereld met de radio.net-app
Ontvang de gratis radio.net app
- Zenders en podcasts om te bookmarken
- Streamen via Wi-Fi of Bluetooth
- Ondersteunt Carplay & Android Auto
- Veel andere app-functies
Ontvang de gratis radio.net app
- Zenders en podcasts om te bookmarken
- Streamen via Wi-Fi of Bluetooth
- Ondersteunt Carplay & Android Auto
- Veel andere app-functies

CyberWire Daily
Scan de code,
download de app,
luisteren.
download de app,
luisteren.
CyberWire Daily: Podcasts in familie



























