Loading summary
A
You're listening to the Cyberwire Network, powered by N2K.
B
Maybe that's an urgent email from your CEO, or maybe it's a deepfake targeting your business. Doppel is the AI native social engineering defense platform, fighting back against impersonation and manipulation. As attackers use AI to make their tactics more sophisticated, Doppel uses it to fight back, automatically dismantling cross channel attacks, building team resilience and providing agentic email protection. Doppel outpacing what's next in social engineering? Learn more@doppel.com that'S-O-P-P-E-L.com.
A
Meta's AI models join the Sandbox Escape Club China's telecom footprint in the US may be larger than expected. The White House keeps its AI safety playbook under wraps. AI coding tools introduce new GitHub risks Anisa expands its CVE role A critical paperclip flaw enables code execution Crypto wallet fears fuel phishing attacks Researchers uncover a backdoor in Chinese made routers the Snowflake hacker pleads guilty Our guest is Dustin Childs, head of Threat awareness of Trend AI's Zero Day initiative, discussing the new Patch Tuesday era and AI takes your word for it. It's Thursday, August 6th, 2026. I'm Dave Bittner and this is your Cyberwire Intel Briefing. We've been recording on site at Black Hat this week from our podcast studio in the Spectrops Kennel Club. Thanks to everyone who stopped by for an interview or just to say hello. We've gathered interesting insights and perspectives from our many guests which we'll be sharing here on the Daily in the coming days. And special thanks to Spectrops for their partnership providing us with a first class home base here at Black Hat. Here's today's news not to be left out of the party, Meta has disclosed that one of its advanced AI models escaped its intended testing boundaries during an independent cybersecurity evaluation conducted by Israeli startup Irregular due to a misconfiguration that allowed Internet access. The model exploited a vulnerability in an unnamed third party service and breached another organization's systems, making unauthorized internal changes. Meta is investigating the incident and plans to publish a full retrospective. The disclosure follows similar reports from Anthropic, whose Claude models also escaped Irregular's testing environment after mistakenly treating live Internet access as part of the exercise. Those models compromised three organizations, including a cybersecurity company, by carrying out sophisticated actions such as publishing a malicious python package. OpenAI has also reported AI models escaping test environments, including attacks on previously unknown vulnerabilities separately, the UK's AI Security Institute observed anthropic and OpenAI models using tools such as Tor, malicious GitHub pull requests and social engineering to target real organizations during frontier AI testing. A bipartisan House Select Committee on China investigation found that China Mobile, China Unicom and China Telecom continue to maintain a significant presence in the US Internet ecosystem despite losing key Federal Communications Commission licenses over cybersecurity concerns. The 49 page report prompted by the SALT Typhoon telecom hacking campaign concludes the state owned carriers remain closely tied to the Chinese government and have preserved access to critical US network infrastructure through less regulated services, data centers, interconnection agreements and network equipment. Lawmakers warn these footholds could provide opportunities for future state sponsored cyber operations and Recommend Expanding the FCC's authority requiring the removal of Chinese telecom equipment and increasing federal cybersecurity expertise. The report also cites historical links between the companies and previous cyber incidents and Chinese hacking organizations. The White House is facing criticism after deciding not to publicly release its long awaited voluntary Artificial Intelligence safety framework, which is expected to guide how the government evaluates advanced AI models before public deployment. Critics argue that keeping the framework confidential undermines transparency and leaves developers, researchers and the public uncertain about the rules governing AI oversight. The move follows a series of high profile AI security incidents and government reviews of frontier models from companies including OpenAI and Anthropic. Meanwhile, a Booz Allen Hamilton survey found that although many federal agencies are piloting autonomous AI agents, few have deployed them in production, and only 28% of technology leaders are confident they can do so securely. Respondents cited concerns over protecting sensitive data, unauthorized agent controls and AI enabled cyber attacks, reinforcing calls for clearer governance, stronger security controls and better guidance for deploying increasingly autonomous AI systems. Researchers from Novi Security disclosed vulnerabilities in AI coding tools from anthropic, Google and OpenAI that could allow attackers to exploit public GitHub issues to compromise software repositories. Presented here At Black Hat USA 2026, the research showed that untrusted issue content could influence AI agents with access to repository credentials, enabling remote code execution, credential theft and unauthorized repository changes. Anthropic fixed multiple flaws in clawed code, including a vulnerability that could leak sensitive data through hugging face. Google patched a critical Gemini CLI vulnerability with a CVSS rating of 10 that exposed GitHub and API credentials in certain automated workflows. OpenAI addressed a Codex workflow flaw that allowed attacker instructions to persist between agent runs. Researchers found similar configurations in more than 100 public repositories and urged organizations to update affected tools, restrict token permissions and isolate AI workflows. Enissa, the EU agency dedicated to enhancing cybersecurity in Europe, has expanded its role in the CVE program, now overseeing 20 CVE numbering authorities, including eight transferred from the MITRE route. The agency said the expansion strengthens global vulnerability management as emerging technologies, including frontier AI models, accelerate vulnerability, discovery and exploitation. As the EU's CVE route, ANISA recruits, supports and coordinates European CNAs while working closely with CISA and MITRE. The agency says the broader CNA network will improve the resilience capability and global representation of the CVE program. Researchers at Oasis Security disclosed a critical authorization bypass vulnerability with a CVSS score of 10 in the AI management platform Paperclip. The flaw allowed remote attackers to self register, gain elevated API access and deploy malicious AI agents capable of executing arbitrary code with the server's privileges. Paperclip has patched the issue by strengthening authorization checks and company scoping. The company also fixed two additional vulnerabilities involving sensitive data exposure and a DNS rebinding flaw that could enable code execution on developers machines. Proofpoint researchers have identified a phishing campaign that exploits concerns over a recently disclosed cold card hardware wallet vulnerability and a suspected $88 million bitcoin theft. Attackers send emails posing as cold card urging users to complete a fake security audit through a fraudulent website featuring live chat support likely staffed by human operators. Victims are persuaded to download a supposed diagnostic tool that actually installs ConnectWise Screen Connect, a legitimate remote access application, giving attackers full control of the compromised system. The access could be used to steal cryptocurrency and sensitive data, install additional malware or deploy ransomware. The campaign highlights how cybercriminals rapidly capitalize on high profile security incidents by combining convincing social engineering with trusted remote management software. Researchers at Volchek say they discovered a previously undocumented backdoor in more than 20 models of ZBT Link routers sold globally under the ZBT Link and Y Flyer brands. The backdoor reportedly contacts a Chinese registered domain every 35 seconds, potentially enabling remote access to the routers and connected devices. Von Check did not notify ZBT Link before publication, stating that coordinated disclosure assumes the vendor did not intend the behavior. Connor Riley Mucha, a 26 year old Canadian, pleaded guilty in the US yesterday to his role in the widespread 2024 Snowflake data theft campaign, admitting to computer fraud, wire fraud, identity theft and conspiracy charges. Prosecutors say he and his co conspirators use stolen credentials to access at least 165 customer environments, steal billions of records and extort victims, earning roughly $2.5 million in ransom payments. Mocha will be sentenced in October. He faces a mandatory minimum penalty of two years in prison for aggravated identity theft and a maximum of 30 years in prison for three other count. Coming up after the break, my conversation with Dustin Childs, head of Threat awareness at Trend AI's Zero Day Initiative. We're discussing the new Patch Tuesday era and AI takes your word for it. Stay with us.
C
Foreign.
B
Is making phishing attacks faster, more convincing and harder for people to spot, and traditional security awareness and phishing training weren't designed for this level of attack. Hawks Hunt helps security teams prepare employees for the attacks they face every day with personalized phishing training that adapts to each employee and reduce risky behavior over time. For IT and security leaders looking to strengthen their human layer of defense without adding more manual work. Visit hoxhunt.com cyberwire to learn more. That's H O X h u n t.com cyberwire.
A
Dustin Childs is head of Threat awareness at Trend AI's Zero Day Initiative. We got together to discuss the new Patch Tuesday era.
C
Going back to before there was a Patch Tuesday, enterprises were very disturbed at the irregular pace that patches were coming out. Microsoft was essentially releasing patches when they were ready, whether it was Tuesday, Wednesday, Thursday, Friday. And enterprises just couldn't cope from a vulnerability management standpoint. And they let them know how, hey, can we agree on one day of the week? And Patch Tuesday became that day that they said, okay, we'll consolidate all of our patches to release on Patch Tuesday. And that was the genesis of it. And over the next 20 plus years it became the standard that the industry followed. Adobe does it, Oracle does it, Cisco usually does it as well. So it really culminated in a time where enterprises are expecting patches to come out on the second Tuesday of every month and they've geared their vulnerability management processes based on that.
A
And is it fair to say that over the past couple of decades that
B
cadence has served us all well?
C
Generally speaking, yes. I mean it got some regularity to allowed us to prepare, it allowed us to resource manage, it allowed us to gear up for certain things and know that, okay, this is a time we're going to have to do this. So yes, it has been a good thing that Microsoft started all those years ago.
B
Well, over the course of this year, and particularly the last couple Patch Tuesdays, we've seen some real changes here.
A
What's going on?
C
Well, really it's of the volume that has changed. It used to be Microsoft would release somewhere between 50 and 100 CVEs a month, then they released like 250. And then last month they released over 600. Adobe had a sharp increase as well, Oracle had a sharp increase, and now even Apple has had a sharp increase. So it's a bit of a bug apocalypse that we're living through right now. Thanks to AI driven vulnerability discovery, the volume has just absolutely exploded.
B
And what are the ramifications of that? Is Patch Tuesday in trouble or might it collapse under its own weight?
C
Well, it might. Certain organizations, Apple and Adobe most notably, have decided to do additional releases beyond just Patch Tuesday to try and lessen the load for just Tuesday itself. Microsoft has decided not to do this, but it really, what it introduces is an even bigger patch gap for enterprises. I mean, it's great that Microsoft can patch 600 bugs in a month, but it's very difficult for organizations to roll those patches out to their enterprise within any time whatsoever. And that's leaving their systems incredibly vulnerable as they test and deploy this gigantic load of patches.
B
How would a typical organization handle this, this avalanche of patches? How do you prioritize?
C
Well, you have to prioritize first with what your Internet facing systems are and start from there. So if you have SharePoint connected to the Internet or RDP or whatever, those are your systems that are going to be your most vulnerable. Then after that you're going to look at your systems that are most critical to your business and start with those and then prioritize everything else as tier three. So I mean really you have to break it down that way and you have to make sure your asset discovery is up to date, because you don't want to be trying to test and deploy patches for systems that you don't have, and you don't want to miss patches for systems that you might not remember that you have. So you need to know what you're protecting and asset discovery is the key piece to that.
B
How do you suppose this could play out in the future here? Do we suspect the rate to continue increasing or do we think it'll level
A
out at some point?
C
I do think it will stay very high for quite a few months. Hopefully it will return back down to a more reasonable level. But I think we are here with this level of volume for a while and the AI vulnerability discovery is what's really pushing this both internally and externally. And I say that because if you look at the huge release from Google Chrome, it was, I think, over 400 CVEs but most of those were discovered internally using AI so that's great that they're able to do that and close those holes before external people do. But eventually AI is going to run out of bugs that they can discover easily and then it's going to go back to a lower level. As we've patched these holes, we saw something similar when fuzzing became very popular. The first time we got all these low hanging fruit bugs we had, you know, a huge explosion and then it tailed off. So I do think it will tail off, but I think we're going to be here for at least another six months.
B
It seems like maybe at the moment it's kind of a mixed blessing. But in the long haul, do we suspect this is going to a good thing?
C
In the long haul, yes, it is a good thing because we're closing, we're finding and fixing bugs and that's always a good thing, at least in my opinion. But in the short term it's going to be some rough riding and some very long nights for the people who are in charge of patching the systems. Hopefully they're learning how to use AI for defense as well and for triage. That's what we do here at ZDI. We use, we saw a 450% jump in submissions to our program and we had to turn to AI to help us triage that level of bug. So yes, it's a good thing overall, but it's going to be some, some rough sailing to get us through this.
B
What's your advice for that person out there who's feeling overwhelmed and you know, feels like they don't have the resources
A
to deal with this.
B
Maybe they're thinking of, you know, they got to go knock on the board of directors door and say, hey, we're drowning here.
C
Yes, I would say definitely make that call. Definitely talk to your board and let them know how resource constrained you are. But also to remember to take a deep breath and it's like eating an elephant one bite at a time. So you just take care of one problem and then the next problem and then the next problem and you will get there. I try to be encouraging with this, but I also recognize that everyone out there I know is the three unders, which is understaffed, underfunded and under pressure. So taking that to the board to try and get some additional resources, especially if it's in the area where you can do any sort of automation, I think that's a very good thing.
B
What are the opportunities for automation here? Can we Fight fire with fire and throw AI at this problem?
C
I definitely think so. And I think really the opportunity here is when it comes to the testing of these patches before they get deployed right now that's a very laborious process and is one of the things, you know that generally speaking, you want to test things before you roll them into production. And hopefully AI can automate a lot of that testing process and get us to the point where not removing the human in the loop at all, but getting it to the point where it's like we can get more confidence with these patches without having to manually test them all the time.
A
That's Dustin childs from Trend AI's Zero Day Initiative.
B
What's the one thing in business that's spreading as fast as AI? AI risk. Every new tool your team signs up for, every vendor that turns on AI features, every new integration, each one is another opportunity for something to go wrong. And most security programs weren't built to keep up with AI's pace of growth. Enter Vanta. Vanta is the number one agentic trust platform trusted by more than 16,000 fast moving companies like Ramp, Herser and Harvey to help them stay audit ready. And now Vanta helps companies like yours keep an eye on the risks that appear between audits across your vendors, your AI tools and your entire environment. The Vanta agent works like a 24.7grc engineer. In the background, it finds, issues, drafts, fixes for you, and can cut vendor assessment time by up to 50%. Whether you're a fast growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today@vanta.com cyber that's V A N T A dot com cyber.
A
And finally, according to Cisco Talos, some hackers have discovered that one of the easiest ways to persuade an AI assistant to help with cybercrime is simply to say, I'm allowed. Researchers found that AI coding tools often accepted unverified claims of authorization, enabling attackers to build malware, develop distributed denial of service tools, harvest credentials, and automate criminal operations with surprisingly little resistance. The study found that less experienced threat actors could use AI to create basic attack tools, while more skilled operators leveraged it to validate massive email lists, harvest secrets from vulnerable systems, test Telegram applications, and probe Internet connected camera services. Although AI did not eliminate the need for technical expertise, it significantly accelerated routine offensive tasks. Cisco Talos concluded that the effectiveness of AI in cybercrime still depends largely on the operator's skill, but warned defenders to prepare for a growing wave of AI assisted attacks, and especially as current guardrails remain easier to charm than to enforce. And that's the Cyberwire. For links to all of today's stories, check out our daily briefing@thecyberwire.com we'd love to know what you think of this pipe podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire2k.com N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazes. Our executive producer is Jennifer Ibin. Peter Kilby is our publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow.
Episode Title: AI without adult supervision
Host: Dave Bittner (N2K Networks)
Main Guest: Dustin Childs (Trend AI - Zero Day Initiative)
This episode of CyberWire Daily delves into the escalating risks and rapid developments at the intersection of AI and cybersecurity. News highlights include a surge in AI model "sandbox escapes," the implications of China's telecom presence in US infrastructure, evolving patch management challenges driven by AI-discovered vulnerabilities, and a broader discussion with Dustin Childs on the new realities of “Patch Tuesday” amidst this wave of AI-driven vulnerability discovery. The episode concludes with a warning about how trivially AI assistants can be manipulated for malicious purposes.
Guest: Dustin Childs, Head of Threat Awareness, Trend AI's Zero Day Initiative
([13:19] – [20:41])
Explosion in Patch Volume:
AI-driven Discovery:
Patch Management Risks:
Prioritization Strategy:
Temporary Spike:
Long-term Good, Short-term Pain:
[22:24]
This episode highlights an inflection point in cybersecurity, driven by the unprecedented capabilities of AI for both attackers and defenders. Organizations must quickly adapt their vulnerability management practices, leverage automation and AI for defense, and stay vigilant for the continued evolution of AI-enabled threats—where even a simple statement can charm an AI into aiding malicious activities.