Loading summary
A
You're listening to the Cyberwire Network powered by N2K.
B
This episode is supported by Black Hat usa. If you follow the research, you know a lot of it breaks on Black Hat stages hundreds of peer reviewed briefings, more than 100 hands on trainings and the largest business hall in Black Hat's history. Six days to learn the skills you'll need tomorrow, August 1st through the 6th use code CYBERWIRE for $200 off your briefings pass@blackhat.com we'll see you in Vegas. Nightmare Eclipse drops another Windows Zero day the gentlemen take the ransomware CR CISA orders emergency fortinet patching Canada's surveillance bill faces US Scrutiny Meta's oversight board flags AI censorship Bias Commerce tops the cyber target list an active espionage campaign hits Bangladesh's military the Hewlett foundation commits $100 million to emerging tech security US prosecutors dismantle an alleged cyber enabled money laundering network Our guest is Nick Stolman, vice President of CJIS Strategy at Improvada, talking about CJIS readiness and the identity security challenges facing public safety agencies and leaked source code reveals an AI mixtape. It's Friday, july 17, 2026. I'm dave buettner and this is your cyberwire intel brief. Thanks for joining us here today. It's great as always to have you with us. Happy Friday. A security researcher using the handle Nightmare Eclipse has released Legacy Hive, a proof of concept zero day exploit that targets the Windows user profile service and enables privilege escalation on fully patched Windows systems. The vulnerability has not yet been assigned a cve. Unlike the researchers earlier releases, this proof of concept has been deliberately limited, requiring additional user credentials to reduce the risk of widespread abuse. Testing by security researchers Will Dorman and Kevin Beaumont confirmed the exploit works. Dorman said it could let a standard user modify an administrator's registry Hive, potentially enabling code execution when the administrator logs in, while Beaumont published Microsoft Defender for endpoint detection queries. Legacy Hive is the latest in a series of Windows Zero day disclosures from Nightmare Eclipse, whose previous releases have prompted Microsoft patches and public legal warnings. The ransomware landscape is shifting, with the gentleman emerging as the most active cyber extortion group. Between March and May of this year, according to ReliaQuest, researchers tracked 300 claimed victims linked to the group, surpassing Ken, which recorded 289 incidents after leaving ransomware activity throughout the previous year. Across 11 major ransomware operations, ReliaQuest identified 1368 victim claims spanning 99 countries. The report attributes the gentleman's rapid rise to aggressive affiliate recruitment AI assisted malware development and a well packaged ransomware as a service toolkit that lowers the barrier for new operators. The toolkit includes detailed attack playbooks and pre configured intrusion tools that help affiliates launch attacks more efficiently. ReliaQuest expects the group's momentum to continue and recommends organizations strengthen remote access controls, harden identity protections, enforce Microsoft's vulnerable driver blocklist, and monitor suspicious network activity. CISA has ordered federal agencies to urgently patch two actively exploited critical vulnerabilities in Fortinet FortiSandbox. The flaws patched by Fortinet in April and June allow unauthenticated remote code execution through command injection attacks that require no user interaction. Although Fortinet has not confirmed exploitation, Threat Intelligence firm diffused reported attacks in June and CISA has now added both vulnerabilities to its known exploited vulnerabilities catalog. Federal agencies must apply patches by July 19th. Senator Ron Wyden is urging Secretary of State Marco Rubio and Acting Attorney General Todd Blanch to oppose Canada's proposed Lawful Access act, warning it could threaten U.S. national security and the privacy of American citizens. In a letter, Wyden argued the legislation could compel U.S. technology companies to secretly assist Canadian surveillance by retaining user metadata, creating backdoors and modifying systems to facilitate lawful access requests. The bill has passed Canada's House of Commons and is awaiting Senate approval. Wyden called for a review of whether the proposal could force companies like Apple and Google to disclose Americans data and recommended using ongoing U S Canada Cloud act negotiations to prohibit such requirements. Canada's Citizen Lab has also raised constitutional concerns about elements of the legislation. A study by meta's independent oversight board found that leading AI models, including those from OpenAI and Anthropic, are significantly less likely to generate politically critical content about governments with restrictive speech laws than about more permissive countries. Across 10 models, researchers found refusals occurred 34% of the time for restrictive jurisdictions, compared with 14% for permissive ones. The board warned this could introduce bias into widely used AI systems and called for greater transparency in AI training, evaluation and human rights assessments. Akamai's latest State of the Internet report says commerce has become the world's most targeted industry for cyberattacks as AI powered shopping agents and autonomous tools reshape online retail. By the end of 2025, AI bots accounted for nearly 48% of all commerce traffic on Akamai's network, with AI training crawlers making up the majority. The report warns that attackers are increasingly exploiting AI through agent hijacking, synthetic identity fraud, and API attacks, while layer 7 Distributed Denial of service attacks continue to surge, particularly against retailers. Akamai also found widespread gaps in API visibility, with most organizations unable to identify sensitive data exposure. Meanwhile, phishing and malware activity have risen sharply, fueling account takeovers and loyalty fraud as attackers industrialize cybercrime against digital commerce platforms. Researchers at Sideris Howler Cell uncovered an active cyber espionage campaign targeting Bangladesh's military and defense sector and attributed it with high confidence to do not. Also known as APT C35, the operation begins with a spearfishing RTF document disguised as the biography of a Bangladesh Air Force officer. The document uses remote template injection to retrieve a malicious macro with server side geofencing, limiting delivery to intended regional targets. The malware executes through multiple encrypted stages before installing a DLL that establishes persistence, profiles the infected system, and communicates with command and control servers over encrypted HTTPs by interacting directly with the C2 infrastructure. Researchers retrieved a live second stage payload confirming the campaign remains active. Matching encryption keys, infrastructure and communication patterns further strengthen the attribution to do not and indicate an ongoing intelligence gathering operation targeting South Asian government and military organizations. The William and Flora Hewlett foundation has launched a $100 million emerging technology and Security Initiative to fund research and policy efforts through 2031 focused on the safe development of artificial intelligence, biotechnology and quantum computing. Announced at the Aspen Security Forum, the initiative will support universities, think tanks and civil society organizations working to protect critical infrastructure, address emerging technology risks and strengthen global governance. Building on earlier exploratory grants, the program aims to promote practical evidence based solutions that balance innovation with security through collaboration across government, industry and independent organizations. On a personal note, our own Research Saturday program was initially made possible by a Hewlett foundation grant. US Prosecutors have charged Zhouying Shen and Huajie Jiang, two New York residents, with operating a large scale money laundering network that allegedly moved at least $43 million in proceeds from cyber enabled investment fraud scams between 2020 and 2022. According to the indictment, the pair managed a network of more than a dozen associates who used approximately 140 bank accounts tied to 45 shell companies to transfer stolen funds to China. The underlying scams involved criminals building trust with victims through social media and messaging platforms before convincing them to invest in fake opportunities. If convicted of conspiracy to commit money laundering, the defendants face up to 20 years in prison. The case highlights the continued growth of investment fraud, which the FBI says caused $8.6 billion in reported losses in 2025. Coming up after the break my conversation with Nick Stolman from Improvada. We're talking about CJIS readiness and the identity security challenges facing public safety agencies. And leaked source code reveals an AI mixtape. Stay with us.
C
Foreign.
A
This episode is brought to you by Google Chrome. You think you know a browser, but Gemini and Chrome? That's new. It can help you with practically anything on the web, like restoring a vintage motorcycle from a 50 page restoration block. Or finally break down that long article you've had open for weeks. Gemini and Chrome is here for it, ready to make anything online make sense. There's no place like Chrome. Check responses, set up required compatibility and availability various 18 when you need to build up your team to handle the growing chaos at work, use Indeed Sponsored Jobs. It gives your job post the boost it needs to be seen and helps reach people with the right skills, certifications and more. Spend less time searching and more time actually interviewing candidates who check all your boxes. Listeners of this show will get a $75 sponsored job credit at indeed.com sponsored that's indeed.com podcast. Terms and conditions apply. Need a hiring hero? This is a job for Indeed Sponsored Jobs Are all batteries the same?
C
That's like asking if all soccer players are the same. Take Messi, the most decorated player ever. Is there any other player who has achieved that? No, just him.
B
Now take Duracell.
C
Is there any other battery with power boost ingredients inside? No, just Duracell. Remember, goats only trust goats because they're
B
built different and Messi only trusts Duracell. Right now get up to 15% off. Select storage solutions put heavy duty HDX totes to good use, protecting what's important to you. The solid impact resistant design prevents cracking and the clear base and sides make items easy to find even when the totes are stacked. Find select shelving and tote storage up to 15% off at the Home Depot. To organize every room in your home from your garage to your attic, visit homedepot.com how doers get more done. Nick Stolman is Vice President of cejis Strategy at Improvada. We recently sat down to talk about CEGIS readiness and and the identity security challenges facing public safety agencies.
C
We really wanted to get a temperature in the water where agencies were with their other CDs. Compliancy Journey. You know, in October 2024 the FBI released a document of 400 pages or more of requirements to meet compliancy and we wanted to find out how many people had started that process and started on their journey to find out. You know what's the real lay of the land out there? And so we decided, let's do a survey and ask agencies from multiple sizes, multiple types, and see where they're at when it comes to CETIS compliancy.
B
So CEJIS stands for Criminal Justice Information Services. For folks who may not be familiar with that. What does it mean and why does compliance here matter?
C
So CJIS is actually part of the FBI out of West Virginia. They employ about 3,000 different people within that section of the FBI. And their main focus is to provide and to secure access to criminal justice information databases that public safety agencies use on a daily basis, NCIC inlets and so forth, running your criminal history, running a driver's license through dmv, through ncic, finding out if there's any warrants on an individual or a piece of property. So all the databases that public safety access, we need to protect, and the FBI's focus is to make sure those databases are being accessed properly by the right personnel, those that have rights, and that the compliance is handled in a professional manner and that we're meeting those requirements that the FBI has put out.
B
So what are some of the challenges that public safety agencies face here to meet that compliance?
C
Yeah, you know, it comes down to cost and bandwidth a lot of the time. I was a former undersherif at a sheriff's office and I started my career as a drug enforcement agent and I always had to deal with CDIS compliance as well as an end user. But from a department standpoint, there's cost to be compliant, you have to buy the right tools, multi factor authentication tools, software, you know, and then you have to put those into practice, you have to implement them, and then you have to train and you have to have those end users, which is everybody at the department making sure that they're, they're, you know, obviously accessing the systems properly and that they're conducting themselves in a compliant manner. One of the things it really does come down to, it's not necessarily the agencies don't understand the priority of this and the necessity and need is finding the funding to buy the right software, the right technology, and then the training and so forth. And it's compliance. CJIS compliance is not a one fix. All you buy product and fix it. It's everyday practice and it's really an agency's responsibility. It's not an IT problem, it's an agency problem. And you're only as strong and only as compliant as your weakest user. So it really takes consistent training, consistent upkeep of the system you're using. And so obviously there's a cost with that and you know, there's. It has to be prioritized. And when you've got the, you know, look for fuel money for your patrol cars or buy some software, you know, you have to pick your, pick the priority there.
B
Right now it's my understanding that the Department of Homeland Security has a proposed framework here. Is it anchor cl, is that correct?
C
That's correct. They do have an initiative out there that they're working on which you know is going to be able. It's kind of like, you know, setting the guidelines and making it easier. And obviously when Homeland Security gets involved, you'll find that they also are a big provider of grant funding.
B
Right.
C
So that obviously can solve twofold. It can get compliancy in a more structured manner. But it also can provide a path to financing to be able to afford that.
B
For the public safety folks in our audience, what are your recommendations? What are the steps that you would suggest for folks to strengthen their identity security without trying to solve everything all at once?
C
Coming from running an agency, I would approach it like I do everything within the agency's jurisdiction and scope. Right. It's a mission. And when you have a mission, you get the right personnel involved. I would formulate a team from command staff, end users, power users and IT staff. And I'd evaluate our workflows and what do we really need to be compliant? Where's our weakest points? Is it password? Is it, you know, you share devices? Where are we weak? What workflows are causing us the opportunity to fall into the non practice of compliancy and become a victim? Just because you're a public safety agency doesn't mean you can't become a victim as well. Right. So I would put a team together and make it a focus, put a timeline to it. And I would advise them start researching what other agencies are doing. Make contact with the FBI. The FBI is their friend and their partner. And cdis compliancy ask for guidance from them, their state agency. You know, here in North Carolina, I would live, I would contact the sbi, state bureau investigations and get their input on compliancy and formulate a plan and look for a good partner, not a vendor. I look for a partner. You know, again I mentioned earlier that compliance is an ongoing everyday practice. So you need a partner. You're not buying some. It's not a transactional, transactional sale. It's a, it's a commitment. It's A journey. And you want to find a partner that's staying ahead of the game and is connected with the Bureau and connected with the state agencies and understands the market, understands the need and the pain points and understands where the FBI is going with future compliancy concerns. Every time technology changes, for example, when we went from on premise systems to cloud systems, that caused more compliancy concerns on how you access the cloud system. And now today we're dealing with AI, right? You hear AI through any type of vertical, any market out there. Well, it's obviously very strong, prevalent in public safety as well. So that creates new compliance concerns. So you need to find a partner that understands that and is not just trying to sell you a piece of product or a piece of software that's going to solve multi factor authentication. That's where it starts. But it goes much further than that.
B
It sounds to me, the way you're describing it, like there is a good amount of collaboration out there among the people who are using these tools. Is there a sense of collegiality out there among those folks?
C
I think so. I think this is always back historically, has always been on the shoulders of it. And I think now, because the true weakness is usually through our own end users, it can't be all on it. So you're starting to see that, that group of, that formation of teamwork and not just within the agency, other agencies and also other partners and vendors and also collaborating with the, with the FBI. The FBI, again, you know their job. They're trying to do the job and make you successful as well and make sure that you're compliant and that you don't put your agency at risk and the citizens you serve at risk. So it takes teamwork, it takes collaboration and it takes an understanding that we're all in this for the same mission. We want to protect those CJI databases, we want to protect, protect the citizens and we want to make sure the folks are out there serving them. Get home at night. And there's a lot of ways that can happen if you're where they could not get home at night, if you're not practicing CDISC compliance.
B
That's Nick Stolman from Improvada. What's the one thing in business that's spreading as fast as AI? AI risk. Every new tool your team signs up for. Every vendor that turns on AI features, every new integration, each one is another opportunity for something to go wrong. And most security programs weren't built to keep up with AI's pace of growth. Enter Vanta Vanta is the number one agentic trust platform trusted by more than 16,000 fast moving companies like Ramp, Purser and Harvey to help them stay audit ready. And now Vanta helps companies like yours keep an eye on the risks that appear between audits across your vendors, your AI tools and your entire environment. The Vanta agent works like a 24.7grc engineer. In the background, it finds, issues, drafts, fixes for you and can cut vendor assessment time by up to 50%. Whether you're a fast growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today@vanta.com cyber that's V A N T A dot com cyber. And finally, a hacker has pulled back the curtain on how AI music company Suno built its models, revealing source code that allegedly shows the platform scraped millions of songs, lyrics, podcasts and stock audio from services including YouTube Music, Deezer, Genius, Pond 5 and Jamendo. The leaked code appears to detail massive training datasets, automated scraping tools and techniques for finding vocal tracks, while also suggesting the use of proxy infrastructure to collect content at scale. The breach reportedly exposed customer contact information and limited stripe payment data, though Suno says the incident involved outdated code, was quickly contained and did not compromise full payment card numbers. The revelations add weight to ongoing copyright lawsuits accusing Suno of training on copyrighted music. It's a reminder that in AI, today's training playlist can become tomorrow's courtroom exhibit. And that's the Cyber Wire. For links to all of today's stories, check out our daily briefing@thecyberwire.com be sure to check out this weekend's Research Saturday in my conversation with Lauren Feivissen, senior threat researcher at Silent Push. The research is titled Meet Drive Surge a new threat actor using click Fix and fake update drive by attacks in thousands of compromised sites. That's Research Saturday.
A
Check it out and hello Maria Varmazas here on Sunday's T Minus Space Cyber Briefing, we're diving into Europe's push for space sovereignty. From data laws to independent launch and secure communications, T minus producer Ethan Cook and I have a conversation on why and how Europe is urgently pursuing space sovereignty. That is on Sunday on T Minus. See you then.
B
We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire2k.com N2K's lead producers, Liz Stokes, were mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazes. Our executive producer is Jennifer Ibin. Peter Kilpe is our publisher and I, Dave Bittner, thanks for listening. We'll see you back here next week.
A
Close your eyes, exhale, feel your body relax and let go of whatever you're carrying today. Well, I'm letting go of the worry that that I wouldn't get my new contacts in time for this class. I got them delivered free from 1-800-contacts. Oh my gosh, they're so fast. And breathe. Oh, sorry. I almost couldn't breathe when I saw the discount they gave me on my first order. Oh, sorry. Namaste. Visit 1-800-contacts.com today to save on your first order.
B
1-800-contacts.
A
Starting a business can seem like a daunting task unless you have a partner like Shopify. They have the tools you need to start and grow your business. From designing a website to marketing, to selling and beyond, Shopify can help with everything you need. There's a reason millions of companies like Mattel, Heinz and Allbirds continue to trust and use them. With Shopify on your side, turn your big business idea into Sign up for your $1 per month trial@shopify.com SpecialOffer
B
Heading to this year's Black Hat USA, the N2K CyberWire team will be on site recording from our podcast studio in the Spectrops Kennel Club. If you're interested in joining us for a conversation or learning more about what we're recording throughout the week, visit sponsor.thecyberwire.com for more information. And make sure you stop by the studio and meet the N2K CyberWire team. We'll see you there.
Episode Date: July 17, 2026
Host: Dave Bittner (N2K Networks)
Special Guest: Nick Stolman, VP of CJIS Strategy at Improvada
This episode delivers a comprehensive sweep of cybersecurity headlines, focusing on a newly disclosed Windows zero-day, the shifting ransomware landscape, urgent threats in law enforcement IT compliance, and notable developments in AI, commerce cybersecurity, and cyber-enabled crime. The show also features an in-depth interview with Nick Stolman of Improvada, who discusses the challenges of identity security for public safety agencies in the context of CJIS (Criminal Justice Information Services) compliance.
[00:55 - 03:05]
"Legacy Hive is the latest in a series of Windows Zero day disclosures from Nightmare Eclipse, whose previous releases have prompted Microsoft patches and public legal warnings." — Dave Bittner [01:45]
[03:05 - 04:10]
[04:10 - 04:38]
[04:38 - 05:15]
[05:15 - 05:48]
[05:48 - 06:31]
[06:31 - 07:36]
[07:36 - 08:19]
[08:19 - 09:01]
Guest: Nick Stolman, VP of CJIS Strategy, Improvada
[14:07 – 21:30]
Quote:
"CJIS compliance is not a one-fix all, you buy product and fix it. It's everyday practice and it's really an agency's responsibility. It's not an IT problem, it's an agency problem. And you're only as strong and only as compliant as your weakest user." — Nick Stolman [15:55]
Quote:
"I think... now, because the true weakness is usually through our own end users, it can't be all on IT. So you're starting to see that, that group... of teamwork... not just within the agency, other agencies, and also other partners and vendors and also collaborating with the FBI." — Nick Stolman [20:34]
[22:20 - 23:55]
Quote:
"It's a reminder that in AI, today's training playlist can become tomorrow's courtroom exhibit." — Dave Bittner [23:55]
Rise of AI in attacking commerce:
"By the end of 2025, AI bots accounted for nearly 48% of all commerce traffic..." — Dave Bittner [05:50]
On CJIS security being agency-wide:
"It's not an IT problem, it's an agency problem. And you're only as strong and only as compliant as your weakest user." — Nick Stolman [15:55]
On Suno’s AI training controversy:
"It's a reminder that in AI, today's training playlist can become tomorrow's courtroom exhibit." — Dave Bittner [23:55]
| Timestamp | Segment | |-----------|--------------------------------------------------| | 00:55 | Windows zero-day ("Legacy Hive") breakdown | | 03:05 | Ransomware update: "The Gentleman" | | 04:10 | Urgent Fortinet vulnerabilities | | 04:38 | US concerns over Canada’s surveillance bill | | 05:15 | AI censorship bias study | | 05:48 | Commerce under cyberattack (Akamai report) | | 06:31 | Bangladesh military espionage campaign | | 07:36 | Hewlett Foundation initiative | | 08:19 | US cyber-enabled money laundering charges | | 14:07 | Interview: Nick Stolman on CJIS & identity sec. | | 22:20 | Suno AI music leak & copyright implications |
This packed episode of CyberWire Daily offers timely intelligence on vulnerabilities in widely used systems, transformative ransomware tactics, evolving public safety compliance needs, and the risks posed by rapid AI adoption in commerce and creative industries. The conversation with Nick Stolman is particularly valuable for public safety IT and leadership, delivering pragmatic steps to achieve—and sustain—staunch CJIS compliance.
For listeners wanting to get ahead of cyber risks, understand regulatory headwinds, or grasp the stakes of compliance and technological change, this episode delivers essential insights from the front lines.