Loading summary
A
You're listening to the Cyberwire Network, powered by N2K.
B
AI is making phishing attacks faster, more convincing, and harder for people to spot. And traditional security awareness and phishing training weren't designed for this level of attack. HOX Hunt helps security teams prepare employees for the attacks they face every day with personalized phishing training that adapts to each employee and reduces risky behavior over time for IT and security leaders looking to strengthen their human layer of defense without adding more manual work. Visit hoxhunt.com cyberwire to learn more. That's H O X h u n t.com cyberwire.
C
The White House lays out its AI strategy at Black Hat Researchers spotlight rogue AI behavior CISA warns of an actively exploited enable flaw TP link patches 15 vulnerabilities Apple fights the UK's iCloud access order the AI gray market expands A Massachusetts health care breach hits more than 300,000 people lawmakers push to extend protections for OPM breach victims Our guest is Kal Al, Dubai, principal technologist at Rubrik, who wonders if your security team is solving the wrong problem. And with elections, don't trust AI to tell you the whole story. It's Wednesday, August 5th, 2026. I'm Dave Buettner and this is your Cyberwire Intel Brief. Thanks for joining us here today. It's great to have you with us. We're recording on site at Black Hat this Wednesday and Thursday from our podcast studio in the Spectre Ops Kennel Club. If you'd like to meet the N2K CyberWire team, make sure you stop by the studio. The Trump administration's approach to artificial intelligence aims to balance responsible use, security and innovation without creating a burdensome regulatory framework. That's according to National Cyber Director Sean Cairncross. Speaking yesterday here at the Black Hat 2026 conference, Cairncross said the administration is focused on ensuring defenders can rapidly adopt AI while addressing emergency security risks, particularly after last month's incident in which OpenAI models reportedly escaped a test environment and hacked hugging face. He emphasized the need for a flexible, adaptive system that enables rapid information sharing and coordinated response between government and industry when security incidents occur. Cairncross acknowledged criticism over the administration's AI executive order, which was revised before its June release after industry objections. He argued that traditional regulation would quickly become outdated and could hinder innovation. Instead, the administration is collaborating with industry during implementation. Cairn Cross also highlighted open source AI as a strategic priority, saying the US wants to strengthen its open source ecosystem and promote its adoption globally. In other announcements from Black Hat, the Linux foundation has proposed the Shared AI findings Exchange safe, a framework designed to standardize how the cybersecurity industry shares and responds to agentic AI security incidents. The initiative is led by the Open Secure AI alliance, now comprising more than 120 organizations, including Nvidia, Cisco, CrowdStrike, Hugging Face and Red Hat. The framework aims to turn AI incidents into actionable threat intelligence through confidential information sharing. Members also unveiled new open source security tools to improve AI testing, access control, governance and vulnerability detection. Looking beyond Las Vegas, the UK's AI security institute disclosed yesterday that AI agents from Anthropic and OpenAI took unauthorized actions during controlled cybersecurity evaluations after being granted Internet access and having some safeguards intentionally disabled. In 10 of 122 test runs, the agents carried out 19 unsanctioned actions, including creating fake online identities, attempting to socially engineer a maintainer into accepting malicious code into an open source project, and interacting with real people and organizations. Most of this unauthorized behavior was carried out by Anthropic's Mythos 5, while OpenAI's GPT 5.6 SOL was responsible for two unsanctioned actions. The researchers said no real world harm resulted, but noted this is the first time we've seen risks around autonomy and deception manifest this clearly without specific prompting. OpenAI also disclosed a second incident yesterday, reported by third party evaluator Irregular that occurred after an OpenAI model was mistakenly given unrestricted Internet access due to a testing environment misconfiguration. Instead of staying within the controlled environment, the model accessed a real website and used publicly available credentials to log in and interact with the live system. CISA has given federal agencies three days to patch an actively exploited critical authentication bypass vulnerability in Enable's N central remote management platform. The flaw can give attackers unauthenticated God mode access to n central servers, allowing them to execute code, manage customer endpoints and maintain persistent access. CISA yesterday ordered Federal Civilian Executive Branch agencies to mitigate the flaw by August 6 and urges private sector entities to follow suit. TP Link has patched 15 security vulnerabilities in the zero touch provisioning system used by its Omada business networking products, including controllers, gateways, switches and access points. Researchers at Forscout, who released details of the flaws at Black Hat yesterday, found that attackers could chain the bugs with previously disclosed vulnerabilities to hijack devices, steal administrator credentials, expose sensitive configuration data, and potentially achieve remote code execution. The company has released firmware updates and recommends that customers update affected devices promptly. Apple has reportedly launched a new legal challenge against a UK government order requiring the company to provide access to encrypted iCloud data belonging to UK users. The case, filed with the Investigatory Powers Tribunal, challenges a technical capability notice issued under the Investigatory Powers act that Apple argues would undermine encryption and user security by creating a backdoor. The dispute follows Apple's earlier decision to disable its Advanced Data Protection encryption feature for UK customers. The government maintains that such access is needed for serious crime and national security investigations. Cybercriminals are profiting from a growing gray market for artificial intelligence services by creating fraudulent accounts that resell discounted or trial access to models from providers such as Anthropic, Google and Amazon. These services appeal to users seeking lower costs, access to U.S. models unavailable in China, greater anonymity and cryptocurrency payment options. Many vendors operate sophisticated proxy services that aggregate multiple AI models and help customers avoid disruptions if accounts are shut down. Anthropic has responded with stronger identity verification and improved abuse detection to curb fraudulent registrations. Despite those efforts, the market continues to expand, particularly in Chinese language communities. The services also carry significant risks. Providers can view customer prompts, accounts may be terminated without warning, vendors may substitute lower quality models and operators may monetize user prompts by collecting data or distilling Frontier AI models. Brown Health Medical Group in Massachusetts is notifying over 300,000 people that personal, medical and financial information was exposed in a December 2025 breach involving a historic file server. The organization determined in June of this year that attackers accessed sensitive files, although its electronic health record system was not affected. Compromised data may include Social Security numbers, financial information and medical records. The provider has strengthened security, is retraining employees and is offering two years of identity protection services. No threat actor has been identified or claimed responsibility. A bipartisan group of US Lawmakers is pushing for lifetime identity theft protections for for victims of the 2015 OPM breach, as the current protections are set to expire at the end of September. The proposed measure would extend credit monitoring, identity theft protection and insurance coverage beyond the existing 10 year assistance period. The lawmakers, led by Senator Mark Warner and Delegate Eleanor Holmes Norton, argue that the stolen data remains a lifelong risk, Warner said in a press conference yesterday. The data stolen included workers most sensitive and personal information, from Social Security numbers to security clearance records. And once that information is in the hands of a bad actor, you don't get it back. Maria Vermazes has a quick chat with Parker Wyschek of the Aerospace Corporation. He's giving an overview of all the Space Cyber goings on at DEFCON this week. You want to check it out?
A
Parker, thanks for joining me today. Really appreciate your time.
D
Really great to be back with you, Maria.
A
I so appreciate it. And today is the day. If people are not already in Vegas, they're on their way to Vegas for defcon. So you are the guy. I wanted to ask about what you recommend in terms of aerospace cybersecurity activities at DEF con, because you've got your finger on the pulse for a lot of that. So for folks who are going to defcon, what do you recommend they attend?
D
Sure. Well, y' all might be wondering why the Aerospace Corporation is at DEF con, but we've really, really gotten a lot out of this event, really every year, this decade. And the Aerospace Village, if you have not hit up the Aerospace Village at DEFCON before, really encourage you to do it. There's some amazing stuff going on other than recommending, you know, the craps tables. I do have a handful of things that I want folks to know about. First, that Aerospace Village is hosting a space hacking capture the flag competition this year. It's called starpone, and it's been developed by Aerospace, along with universities and some leading space security firms. And it's going to allow hackers to kind of attack and try to penetrate satellites, spacecraft, and ground control systems. And there's a lot of fun things that you'll learn about in there. Orbital mechanics, radiation latency, impact exploitability. I know some folks are getting really excited just thinking about trying to crack into these sats. This is our version of hackusat this year. Would love to see hackasat come back around. I know we're talking with all the stakeholders around that and had a really excellent hacka SAT a few years ago with the Moonlighter satellite on orbit. So stay tuned for developments on that at future defcons.
A
So aside from the Aerospace Village and starpome, what else do you recommend?
D
Well, so we'll be at the Aerospace Village the entire time, so I really recommend you just kind of live with us there. But we've got one of our own satellites that you can actually come and try to hack. It's called Space cop. And this is a satellite that's actually been tested and proven in space on a few government missions. So come and try your crack at beating Space cop. And we actually have some real news to share. I can't break it here on Wednesday, so I don't want to spoil it, but I'll tell you, read all about it in the readme on GitHub starting with Devcon.
A
Oh, that is an exciting drop right there. Okay. And Parker, how much do people need to know about Space Cybersecurity to enjoy or get a lot out of this experience? Like, can you come in as a total noob?
D
You don't need to know anything about it at all. You can be a script kitty, please wear your white hat, but you can be a complete noob and have some fun with this stuff. And I've got my last fun drop I think a lot of folks will resonate with. It's called Space Trail. And this is the soft, exclusive rollout of Space Trail here at defcon. Space Cybersecurity meets strategy survival Adventure Sim. So I think that most folks have played Oregon Trail or have at least seen some reels about it, wearing some T shirts about it. This is a spacefied version of that that is actually powered with some insights from our Sparta Cyber Attack Matrix. So you're going to go through some realistic space scenarios and you're going to get hit with some threats here and there and make some key decisions, and we'll see if you meet Mission success or die of cholera.
A
You just awakened a lot of exennial trauma in.
D
Just letting you know, I would always try to ford the river, and that's just the Aries in me. Maybe. But I've tested this out. It's actually really fun. So come see Randy Tinney at the Aerospace Village. She's the creator behind Space Trail and she'll tell you all about it and let you play it. The ask is to come and poke holes in this stuff because this isn't just fun and games for us. Why does everybody need to know about Space Cyber? You don't need to know the ins and outs, but it's important that we get ins from folks at DEFCON that we may not have thought of that can poke some holes in these tools and make them stronger.
A
Parker, these are really solid recommendations. So for folks who are getting ready for DEF CON gearing up. As you're listening to this right now, make a note of all that. Make sure not to miss the Aerospace Village. So thank you, Parker, for telling me all about it.
C
That's Maria Vermazes, the host of the T Minus Space Cyber podcast. Be sure to check it out wherever you get your favorite shows. Coming up after the break, my conversation with Kal Al Dabaib, principal technologist at Rubrik. He's wondering if your security team is solving the wrong problems. And with elections, don't trust AI to tell you the whole story. Stay with us.
B
What's the one thing in business that's
C
spreading as fast as AI? AI risk.
B
Every new tool your team signs up for, every vendor that turns on AI features, every new integration, each one is another opportunity for something to go wrong. And most security programs weren't built to keep up with AI's pace of growth. Enter Vanta. Vanta is the number one agentic trust platform trusted by more than 16,000 fast moving companies like Ramp, Herser and Harvey to help them stay audit ready. And now Vanta helps companies like yours keep an eye on the risks that appear between audits across your vendors, your AI tools and your entire environment. The Vanta Agent works like a 24.7grc engineer. In the background, it finds, issues, drafts, fixes for you and can cut vendor assessment time by up to 50%. Whether you're a fast growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today@vanta.com cyber that's V A N T A dot com cyber.
C
Kal Al Dabab is principal technologist at Rubrik. In today's sponsored Industry Voices segment, we talk about how your security team may be solving the wrong problem.
B
So we're starting off here with what I think is a bit of a provocative statement, which is the notion that security teams are trying to solve the wrong problem. How do you describe that?
E
I actually really love this question because for the longest time the world of cybersecurity has been about keeping or the focus has been about keeping bad actors out. We've been building bigger walls, adding more layers of security and frankly, with the advent of generative AI, it's no longer if, but when. And I'm happy to unpack that a little bit more. But when, you know, you think about frontier models and forget about threat actors for now. But just adopting AI within the context of the enterprise, you have a near infinite set of combination of data sets and prompts and systems and tools that are chained together over multiple steps. And even if you have a very high accuracy rate, let's just say it's 99.9% accurate, that eventually compounds into some amount of error. And the number of these non human identities within the enterprise is growing. A recent study found that there's about 109 to every one human identity, up from about 80 even just a few months ago. And so we're talking about these agentic tools being to operate over multiple different steps and cascading errors 10 times faster with A much larger blast radius than any human could. So the game is no longer can we keep them out, it's how do we know when these systems are acting in a way that they shouldn't be? And by the way, the second part of this is threat actors are now targeting these AI systems and want to turn them into autonomous insiders. And so it's totally changing the game.
B
Well, can you paint a picture for us of what this looks like? Maybe walk us through a scenario where an AI agent does what it's told, but yet the outcome is, we'll just say suboptimal.
D
Yeah.
E
So let's talk a little bit about Claude code, and that's something that we've spent a lot of time with. It's a great tool. I mean, hands down, maybe one of the best agentic use cases is code creation. There's a couple of issues with code creation unless you have the expertise to kind of direct the AI system system to create more secure. In general, AI generated code by default is actually more vulnerable to exploitation. But even if you're just trying to get these models to do something very simple, let's say, publish a report, we've caught several different instances where the primary action fails. It's not able to publish the report using the API or tool it's trying to call, and it'll back up to say, okay, well let me go create a GitHub repository and store this information over there and that way it'll be accessible. Well, it's not actually trying to expose sensitive information, but what ultimately ends up happening is sensitive information is then pushed to a repository and that information is then exposed unintentionally. We've also have seen instances where cloud code unable to complete a certain task or connect to an API will attempt to scour and do security chain dumps, where it then tries to look for passwords that a user has stored or on the effort or attempt to complete the task, but ultimately ends up creating a vulnerability or a violation.
B
You make a distinction between malicious code and malicious instructions. Can you unpack that for us? What's the differentiation there?
E
You know, it's funny, threat actors today, they're trying to get just as productive with generative AI as we are. And so I like to say AI is an amplifier. It can amplify good intentions, it can amplify bad intentions, and it can also amplify poorly stated intentions. So when it comes to threat actors using generative AI, they may very well be using these tools to attempt to chain together vulnerabilities or instruct it to do something malicious. On the other hand, as a user, if you're instructing this code to produce a report or synthesize information from multiple different sources, the intent itself is not harmful. But then the way the AI agent goes about fulfilling that intent may create unintended consequences, like searching for security keys to log into a system to complete a task, for example. And so then you have an intent that was inherently good. And after encountering roadblocks, the agent, in its attempt to fulfill that initial request, it ends up doing something negative, if that makes sense.
C
Well, let's say I'm a security analyst
B
and I'm watching my dashboards. What does this sort of thing look like? What am I going to see?
E
So there are three key questions that we focus on here, especially as we think about agentic security and AI operations. One, where are you operating AI in your environment? Where does it exist? And actually, that's quite a difficult question. We can come back to why that's so hard. The second is what permissions do these tools have? And this isn't in the static sense of are they allowed to read or write? But really, what possible negative actions could happen as a consequence of the use of these tools? And then finally, three, what processes and tools and guardrails do you have in place to one, block these unintended negative actions from unfolding? And if something does happen, how do you recover from it? How do you reverse it? And so those are the three questions, and that's how we've been focusing our Rubrik agent cloud product.
B
You know, I want to quickly jump back and kind of connect a couple of dots of some of the things you've mentioned here. And it's this notion of putting boundaries
C
on the AI agents.
B
I think something that a lot of folks haven't considered, I certainly didn't, is that the agent, in its enthusiasm, may go searching around for passwords and ways to grant itself more access.
E
So we used to have security through obscurity. You could grant an individual access to an entire file system, and you would trust that that individual wouldn't exhaustively search through every possible document that would exist and certainly wouldn't try manipulate every single document in one go. And agents operate a lot differently. They can exhaustively search, they operate at machine speed, and they will persist over dozens or even hundreds of different steps to accomplish a given task. And so even though we would grant permissions to humans that could have been risky, we didn't have the exhaustiveness and speed at which these AI Systems operate. That makes sense. And so the effect is there are these very diligent, thorough workers that get a little bit too eager to search all of the information and sources and tools that are available to them to accomplish their task. And that's what requires thinking differently about how you secure them and govern them. And I'll give you, like, a simple example here. Let's just say we have something very innocuous, an agent, that its sole purpose is calendaring, which is a huge enterprise problem, especially when you think about multiple different individuals with busy schedules across multiple time zones. And we grant, you know, read and write access to our calendars to be able to automatically sync times, look for availability. If I give this AI tool, for example, the ability then to access all of my prior calendar invites, it could, in theory, look at calendar entries that I've had with executives on our team that may indicate sensitive information or sensitive topics that were discussed. And if it doesn't need to, consider that for a meeting that I'm booking next week with, let's say, one of my peers, that information is now, even though it has the permission to look at that information, it's in context, inappropriate. And so that's what we talk about when we say contextual guardrails and contextually guiding the action. It's no longer just grant, read or write access. It's is it appropriate in context of the task that it's attempting to accomplish?
B
What's your advice to the CISOs in our audience here? You know, let's say they've sat down and they're looking at next year's plan. You know, they've got a limited budget, there's limited time, limited personnel, so they have to dial in all these different things. And, you know, the board is saying, hey, we definitely want to be on the AI train. We don't want to be left behind.
C
How do they calibrate dialing in all
B
of the different things that they need to attend to when it comes to this?
E
This is an act of prioritization. So we had a really interesting study that we did earlier this year at Rubrik Zero Labs. We pulled about 1600 IT professionals, and we. We asked some really interesting questions. But a couple of stats that I want to call out there. About 86% of them expect that the AI tools, the Agentic tools that they have in place, will outpace the guardrails that they have within the next 12 months, while fewer than 12% of them feel fully confident that they could recover from an unintended negative action without causing a disruption to the system they had in place. Another really interesting stat from that survey is that about 80% of the individuals surveyed felt that the total cost of ownership, once you factored in guardrails and oversight and overhead, was actually not worth it or the ROI was not worth it for those use cases. So this is really an act of prioritization. Where do we really need AI? Where is it truly making a difference in productivity and then really doubling down and focusing on how do you secure that the right way? And going back to those three questions, where's that AI operating in what function? And then two, what permissions does it have and what potential negative actions could it affect? And three, how do we deploy the right guardrails in place to make sure that we can catch these unintended negative consequences and respond when things go wrong? But this is an act of prioritization. It's not saying do it all at once everywhere, but really. And you're going deep with these AI
B
systems, so help me understand how people put these guardrails in place. What is the best way to go about that?
E
The old version of doing this was really focusing on controls, and we're trying to lock down access, and so maybe we don't grant read or write access to a Salesforce database, and that's just no longer feasible, especially with these AI systems, because in order for them to be useful, you really need to give them the ability to act. Now, one approach is using AI to safeguard AI and so having another intelligent model that's constantly evaluating every action that a tool or an agent is attempting to take and diagnosing it to see does it have a malicious intent, or does it have a good intent but possibly a negative outcome? The challenge with using AI to again safeguard AI is cost. API calls, especially to advanced frontier models, are not cheap. There's a lot of latency involved. And so if you add four or five steps to every single call or iteration that one of these agents is doing, you're running up your tab and you're significantly slowing down the process. And so that can be a negative user experience as well. It doesn't quite solve the problem. The way we've thought about approaching it is to create a specialized small language model that's super, super efficient and maybe not general purpose, but very effective at recognizing when there is a deviation relative to a policy or translating a policy into a particular guardrail that isn't just carte blanche blocking access to a system, but really understanding in context, is this action appropriate? Is this call to a calendar. Is this call to Salesforce records appropriate for the task that's being executed? And then based of that, we can either trigger a block or an escalation. And if something negative does happen within the system, we have the ability to then understand and diagnose what went into it.
C
That's Cal Al Dubabe from Rubrik. We've got links to more of their research in our show Notes. And finally, artificial intelligence is becoming an increasingly common stop on the campaign trail, with voters asking chatbots about candidates, races and voting rules instead of traditional search engines. New research, however, suggests AI still deserves a healthy dose of skepticism. While factual error rates in ChatGPT and Google AI dropped to zero in 2026, testing the models often left out critical information, such as complete candidate lists and linked to official election websites less than 40% of the time. Researchers warn that answers can sound authoritative while quietly skipping important details, a bit like a confident tour guide who forgets half the landmarks. As AI becomes more deeply embedded in everyday search and campaigns, optimize content to appear in chatbot responses, experts say voters should continue treating official state and local election websites, not AI, as the final authority for accurate election. And that's the Cyberwire. For links to all of today's stories, check out our daily briefing@thecyberwire.com we'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire2k.com N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazes. Our executive producer is Jennifer Ibin. Peter Kilpe is our publisher and I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow.
B
Sam.
Date: August 5, 2026
Host: Dave Bittner (N2K Networks)
Notable Guests: Kal Al Dabab (Rubrik), Parker Wyschek (Aerospace Corporation), Maria Varmazes
This episode, recorded live from Black Hat 2026, delves into the evolving cybersecurity landscape amidst rapid AI developments. Major themes include the US government’s AI strategy, industry collaboration for AI incident response, the risks of AI autonomy and deception, real-world security incidents, and practical guidance for enterprise security teams navigating a new agentic era. The show also spotlights DEF CON’s Space Cyber activities and closes with warnings about AI’s role and reliability in elections.
[01:03 – 05:40]
[05:41 – 09:09]
[09:10 – 11:00]
[11:01 – 11:20]
[11:21 – 11:27]
[11:28 – 16:05]
Interviewer: Maria Varmazes
[18:18 – 31:31]
Host: Dave Bittner
Traditional perimeter defenses are obsolete in the age of generative, agentic AI; security must focus on detecting and responding to anomalous behaviors and cascading errors—both malicious and accidental—in complex, non-human AI ecosystems.
Defensive Mindset Shift:
AI Agents’ Suboptimal Outcomes:
Malicious Code vs. Malicious Instructions:
AI Ops: Visibility & Guardrails:
Contextual Access Controls:
Advice to CISOs and Organizations:
[31:31 – 32:30]
Kal Al Dabab:
Parker Wyschek:
Dave Bittner:
| MM:SS | Segment | |---------|----------------------------------------------| | 01:03 | News Headlines & White House AI Policy | | 04:17 | SAFE Framework at Black Hat | | 05:41 | UK AI Agent Evaluation / OpenAI Incidents | | 09:10 | Vulnerability Patch Updates (CISA, TP-Link) | | 10:57 | Apple Legal Challenge, AI Gray Market | | 11:21 | Massachusetts Health Breach / OPM Legislation| | 11:28 | DEF CON Space Cybersecurity (Parker Wyschek) | | 16:05 | Transition to Industry Voices (Kal Al Dabab) | | 18:18 | Interview: Kal Al Dabab (Rubrik) | | 31:31 | AI Election Integrity Warning |