
Loading summary
A
Cybersecurity Today is brought to you by nordlayer. Teams today work across multiple tools and devices, but security often remains fragmented, and this is exactly what Nord layer can help you address. Nord layer gives your company centralized control over access by individuals and teams and keeps connection secure from anywhere with no additional hardware required. Visit Nordlayer.com cybersecurity today and use the discount code NLSUMMER26 for a special discount on your purchase.
B
The same AI model that finds a flaw in your code will often hand you a fix that may not work. Every version of WordPress ever shipped has a hole in its login screen, North Carolina's ports reduced to pen and paper after cyberattack. 36 million GPS trackers built to watch children can be hacked and other stories from Defcon 34 this is cybersecurity Today, and I'm your host David Shipley. Let's get started. The same AI model that can find flaws in your code will hand you a fix that often doesn't close it More than half of the time, cybersecurity firm 1Password stood up. A security research group called off Byone Labs across six recently disclosed CVEs, including a Linux privilege escalation, an unauthenticated RCE in XM, and an RCE in Gemini CLI. The team generated 6,480 patches using OpenAI's ChatGPT 5.5 with trusted access for cyber and Anthropic's Opus 4.8 with cyber verification program. 400 of the patches were immediately thrown out because the model went looking for a real fix and instead of writing its own of the 6080 actually scored, 26% closed the vulnerability without changing how the application behaves. Another 20% closed it while changing application behavior. The remaining 53.9% failed, introduced a new flaw, or did both. The team expected better than two thirds as a success rate they got just better than a quarter with a clean success. Attackers were already getting more out of AI tools than defenders were so far this year, the gap was seen as organizational, and some have argued the gap between attackers and defenders will close as businesses adjust to the AI revolution and refine how they work. This asymmetry between the ability of AI models to find flaws and fix them looks to be an even harder problem to solve. The systems that are good at finding a wide range of vulnerabilities are good at closing only a narrow slice of them. More than a third of the patches scored as successful were fragile, narrow checks on the input rather than major fixes to the code. OpenAI announced its project Daybreak in June, a collaboration aimed at patching the planet. Hoodlit says his team pulled failed and vulnerability introducing patches straight into that project's weekend set. They've since reported them. There's a new critical flaw in WordPress, and it reaches every version the project has ever shipped. It sits in the login page. No account, no password, no privileges of any kind. A crafted username hits the failed login error page and the attacker's JavaScript runs in the browser of whoever loaded it. The fix landed August 6 in version 7.0.3, backported through the 4.7 branch. It's tracked as CVE2026, 64, 638, and rated as an 8.9 on the CVSS. Anything older than version 4.7 stays vulnerable and sits outside of the project's Backport range for fixes, WordPress's own advisory but the flaw is conservative. The project notes that escalation to remote code execution depends on conditions outside of the attacker's control and requires successful social engineering plus explicit victim interaction. The evidence supports some of that conservatism. Pwn AI reproduced the login page XSS against 2 live WordPress 7.0.2 deployments in clean browser profiles, but the full chain to php execution was demonstrated only on a local installation. Version 7.0.2 is the release that fixed the last major WordPress emergency. That was WP2 shell patched July 17th, a pre auth remote code execution chain that needed no login and no plugins, and it was severe enough that WordPress force pushed updates worldwide. Public proof of concept code appeared within a day. CISA has added both WordPress CVEs to its known Exploited Vulnerabilities catalog and and researchers have watched attackers drop web shells and create backdoor admin accounts. That's two critical flaws in 20 days, PWN AI says. An autonomous system found and reproduced the chain in just under four days, running open source models in a multi agent workflow seeded with Paulo Cibello's 2022 same origin method execution research as a starting point. They reproduced the flaw on July 26th and reported it the next day. Here's hoping WordPress didn't count on AI to patch these flaws. The goal used to be leverage. Lock something up, get paid a ransom, give it back with decryption keys and tools. What some defenders say they're seeing now is an intent just to break equipment permanently. That was the message from a black hat panel of government and industry practitioners last week in Las Vegas. Matthew Rogers, operational technology cybersecurity lead at cisa, said there is a real desire and willingness to cause permanent damage at scale. Sherry Benedict, a cybersecurity and supply chain advisor in the White House office of the federal cio, said the targeting has moved off data and onto physical operations. Last week we went into a deep dive on the water utility hacking crisis, and the map has since filled out even further. Minnesota, Michigan, Georgia and New Jersey have all reported issues, along with at least eight more states. And water utility hacking isn't just an American problem. A small rural municipality in Quebec was hit by a Russian group calling it Z Pentest. Thankfully, none of the U.S. or Canadian intrusions compromised drinking water safety or quality, but that lack of impact wasn't from lack of intent. Rogers said the campaign to disable safety monitoring systems is the part that should scare people. A CISA advisory updated July 22, describes malware planted on a programmable logic controller at one organization that overrode the instruction sets holding the environment inside safe operating parameters. Critical infrastructure operators Rarely look at PLCs unless something visibly misbehaves, so malware implants can sit for years undetected. Rogers called it a ticking time bomb. Neil Pollard, a partner at Control Risks, said wiper malware has overtaken ransomware in some segments. Rogers said the biggest worry right now is code that permanently bricks industrial control systems because the replacement inventory for much of this equipment doesn't exist and none of these attacks required an elaborate zero day. Roger said the activity of the past several months didn't use a single CVE in the operational technology environment. Scary ones do exist that would make the attacks stealthier, but they didn't need to use them. Cargo is still moving through Wilmington, Moorhead City and Charlotte, N.C. following a major cyber attack on the ports. North Carolina port says its IT system was hacked late on Tuesday, August 4th by what a spokesperson describes as an outside actor or a burden. The IT team triggered the organization's cybersecurity plan and pulled in the state Department of Transportation, the state Department of Information Technology and the US Coast Guard. All three locations were affected, including the inland facility in Charlotte. The ports move more than 4 million tons of cargo a year. A spokesperson told recorded Future that the breach has been contained and the organization is now in recovery. Gates at the ports are running on a normal schedule, but operations are still being processed manually. An outside forensics team is working alongside the internal IT department to assess and restore systems. Asked directly whether it was ransomware, the spokesperson did not answer. Shippers found a way to get their jobs done in the ways that they usually do. Signs went up outside the port gates warning of delays due to system issues. No group has claimed responsibility for the attack. Ports across the U.S. europe and Asia have been hit repeatedly over the past five years as terminal operations digitize. And while we wait for the forensics, the politics seem to be moving fast. On Wednesday, US Senator Tom Cotton of Arkansas wrote to Treasury Secretary Scott Bessant asking him to push investment in modernizing America's critical operational technologies. Cotten called operational technology underfunded and outdated and and says it leaves water systems, power facilities and industrial plants exposed, particularly in rural states. This was my second year attending bsides, Las Vegas, Black Hat and defcon. Many of the B side talks will be on their YouTube channel in the next few months. I had the chance to attend Black Hat briefings for the first time, which were fascinating and in some cases a bit terrifying. It was my second year at defcon, and I'm happy to report it was it's as beautifully weird as it was last year and just as massive. Here are my three favorite talks Felipe Solforeni and Vangela Stykis titled their talk Tracking the How we took over 36 million GPS devices Protecting Children and Vehicles. They demonstrated their research on Wired reporter Andy Greenberg, who was wearing a $30 kids watch bought online. They tracked him across New York. His camera fired in an elevator and again at his desk. Microphones went live when he talked with a colleague and nothing showed on his watch face. When the GPS signal faltered, the watch kept reporting nearby WI fi networks, which gave away his location. Depending on the device, the researchers can also spoof location, intercept messages, send messages that appear to come from Parenthood, and replace the emergency contact numbers underneath more than 70 products. They found three Backends set tracker, new GPS 2012 and Sinotrack, dozens of brands and lots of faults in the lock and key. The researchers advice to parents who bought the affected watches and to companies that are using the affected GPS trackers, which could also be used to disable vehicles. Get rid of them. Corey Solovich called his talk you've got mail that was meant for no one. He bought noreply us in 2020 to protect his own privacy, then noticed other company systems were already sending mail to it. He added noreply.net in 2024. That domain has taken in 401,796 messages since he acquired it, about 700 a day, with 28,365 carrying attachments, some of Those emails included injury reports from a city government test platform, credentials, important government faxes. The researcher has since probed 7136 candidate placeholder domains and found 328 running live catch all inboxes. He and another researcher have bought more than 30 domains to try and keep them away from anyone else. Brian Krebs documented this same issue@donotreply.com almost 20 years ago. The fix here is simple a domain reserved never to resolve, which in this case is the dot invalid top level domain James Kettle called his talk Can AI do novel security research meet the HTTP terminator? He fed 138 HTTP and SMTP RFCs into an autonomous research system, split them into roughly 15,000 fragments and use those to generate 30,000 candidate HTTP desync vectors. He pointed his work at 30,000 authorized targets. It flagged 700 vulnerable ones, including banks, government infrastructure security products and an airport 1 multi part byte ranges technique worked across multiple server implementations and landed on more than 200 sites, including a US bank. The system collected bug bounties from production systems along the way. His key point in his talk was AI can help with novel research. His idea of a research cascade where you find really truly interesting and novel things still relies on a human in the loop working alongside AI. And as a bonus, because this particular speaker deserves it, one more top Talk Cliff Stoll took the stage Saturday afternoon with Stalking the wily hacker 40 years later, nearly 40 years to the day since a 75 cent accounting discrepancy at Lawrence Berkeley Lab set the then astronomer and system administrator chasing someone across the early Internet. The hunt itself took the better part of a year. It ended with Marcus Hess, a West German selling access to US Military networks to the kgb. Stohl's logbook became the first real documented case of network forensics. Then it led to a 1988 paper, then to the book the Cuckoo's Egg. The talk area at DEFCON for his speech was overflowing. The crowd included people in their 70s and 80s, down to kids at their first hacking conference, and Stoll had them all wrapped as he worked his way through the story. There were plenty of laughs and more than one standing ovation. His was a call to keep people at the center of any cybersecurity story. The talk had the feel of a torch passing from the first generation of cybersecurity professionals to the next. But Stoll would probably object to that framing. He says he's still at it, and still learning. And with that, he may have given the best lesson of all for DEF CON attendees. Never stop learning. And that's Cybersecurity today for Monday, August 10th. I've been your host, David Shipley. Thanks for listening. We appreciate all of your feedback. Feel free to reach us@technewsday.com or CA, or you can leave a comment under the YouTube video. I'll be back on Wednesday with the latest headlines. Until then, I hope you have a great week and stay safe.
A
Once again, we'd like to thank NORD Layer for their support in sponsoring this show. Teams today work across multiple tools and devices, but security often remains fragmented. This is exactly what NORD Layer can help you address. It provides a network security platform with easy to manage network access, monitoring and control, and without additional hardware or complex infrastructure. Nordlayer helps businesses of all sizes manage and secure access to company resources going beyond what traditional VPNs can offer. And it provides encrypted connectivity with visibility across your entire network environment. And did we mention no new hardware required? Visit nordlayer.com cybersecurity today and use the code NLSUMMER26 for a special discount during their summer sale.
Cybersecurity Today – Episode Summary
AI Writes Patches That Don't Work, WordPress Login Takeover, Researchers Hijack 36 Million Kids' GPS Trackers
Host: David Shipley
Date: August 10, 2026
Episode Overview
This episode of Cybersecurity Today, hosted by David Shipley, unpacks a range of recent cybersecurity incidents and research developments, with a strong focus on the evolving (and sometimes problematic) role of AI in vulnerability management, a disturbing new WordPress flaw, worrying attacks on critical infrastructure, and the privacy nightmare of compromised GPS trackers for children. Shipley draws on breaking stories from DEFCON 34 and Black Hat, analyzes breaches in critical sectors, and highlights key insights from renowned security researchers.
Key Discussion Points and Insights
[00:37 – 05:10]
“The systems that are good at finding a wide range of vulnerabilities are good at closing only a narrow slice of them.” – David Shipley [02:11]
[05:11 – 07:12]
Notable Quote:
“That’s two critical flaws in 20 days, PWN AI says. An autonomous system found and reproduced the chain in just under four days... Here’s hoping WordPress didn’t count on AI to patch these flaws.” – David Shipley [06:57]
[07:13 – 09:31]
Notable Quotes:
“Rogers said the campaign to disable safety monitoring systems is the part that should scare people.” [08:22]
“Code that permanently bricks industrial control systems… because the replacement inventory for much of this equipment doesn’t exist.” – David Shipley [09:10]
[09:32 – 10:34]
Notable Quote:
“Signs went up outside the port gates warning of delays due to system issues. No group has claimed responsibility for the attack.” – David Shipley [10:12]
[10:35 – 15:15]
A. 36 Million Hackable GPS Trackers (Kids, Cars, More)
B. Email Misdelivery via "noreply" Domains
Researcher: Corey Solovich
Fix: Use "[dot]invalid" TLD for placeholder domains to prevent accidental resolution.
C. AI for Novel Security Research – HTTP Terminator
D. Cliff Stoll’s Keynote: "Stalking the Wily Hacker – 40 Years Later"
Memorable Quotes & Moments
On AI Patch Reliability:
“They expected better than two thirds as a success rate… they got just better than a quarter with a clean success.” – David Shipley [01:35]
On Attacks on ICS Equipment:
“None of these attacks required an elaborate zero-day… Scary ones do exist that would make the attacks stealthier, but they didn’t need to use them.” – David Shipley [09:00]
Cliff Stoll’s Lesson:
“Never stop learning. And that’s Cybersecurity Today for Monday, August 10th. I’ve been your host, David Shipley.” [15:21]
Timestamps for Important Segments
Tone and Language Note
Shipley’s delivery is brisk, serious, and laced with pointed asides that underscore both the urgency and the sometimes-surreal nature of 2026’s security landscape. He highlights the practical (“get rid of them”), the worrying (“ticking time bomb”), and celebrates both new and old voices in the field (“never stop learning”).
Summary
This episode is a must-listen for CISOs, IT managers, parents using smart trackers, and anyone fascinated by both the pace and the pitfalls of current cybersecurity trends. Covering everything from AI shortcomings to critical infrastructure threats and legendary hacker tales, Shipley demonstrates the breadth of today’s cybersecurity battlefield—and the importance of human vigilance at every step.