Loading summary
A
You're listening to the Cyberwire Network powered by N2K. If you are heading to Black Hat USA this year, make plans to visit the Spectre Ops Kennel Club. As the creators of Bloodhound, the Spectre Ops team will host talks, workshops and hands on sessions aimed at helping you understand AI accelerated attack paths, the latest identity tradecraft and how to build your own open graph collector. Visit Spectrops IO to pre register and learn more. While you're at the Spectrops Kennel club, visit the N2K CyberWire podcast studio where we'll be capturing expert perspectives and conversations from across Black Hat. We'll see you there. This episode is supported by Black Hat usa. If you follow the research, you know a lot of it breaks on Black Hat stages hundreds of peer reviewed briefings, more than a hundred hands on trainings and the largest business hall in Black Hat's history. Six days to learn the skills you'll need. Tomorrow, August 1st to the 6th, use code CYBERWIRE for 200 off your briefings pass@blackhat.com we'll see you in Vegas. The U.S. and its allies warn of Russian cyber threats targeting critical infrastructure as Europe rolls out new sanctions, Apple sues OpenAI over alleged trade secret theft, Progress investigates a potential share file security incident, Zimbra patches a critical flaw and researchers uncover the new crash stealer macOS malware. Plus the EPA tests water utility resilience scammers clone trusted news sites and our Monday Business Briefing. Our guest is Brandon Karp from ntt discussing the 11th Japan US Cyber Dialogue and Californians smash that Delete button. It's Monday, July 13, 2020 2026. I'm Dave Buettner and this is your Cyberwire Intel Briefing. Thanks for joining us here today. It's great as always to have you with us. Happy Monday. Cybersecurity agencies from the United States and eight allied countries have issued a joint advisory warning that Russian state sponsored hackers linked to the FSB's Center 16 are targeting vulnerable and poorly configured routers to gain access to critical infrastructure networks. The group scans Internet connected devices for default or weak SNMP credentials, steals router configuration files, and exploits known Cisco vulnerabilities, including the Smart install. Flawless sectors at greatest risk include energy, communications, healthcare, finance, defense and government. The advisory urges organizations to upgrade to SNMP version three, disable Cisco Smart install, use strong unique passwords, block SNMP and Trivial File Transfer Protocol traffic where appropriate, keep devices updated and replace end of life hardware. It also follows a separate international operation that disrupted Russian router based espionage infrastructure. The European Union and the United Kingdom have imposed new sanctions on dozens of Russian individuals and entities, accusing Moscow of directing a network of cyber operations targeting governments and critical infrastructure across Europe. The measures target Russian military intelligence officers, cybercriminals, private companies and members of the Lumasteeler malware operation and Rybar Media Network. The EU also publicly identified the FSB's 16th center as overseeing several hacking groups, including Tirla, which officials say has conducted espionage campaigns against European government and defense organizations for more than a decade. Authorities linked Tirla to a failed attack on Poland's energy infrastructure and cited other recent Russian cyber operations targeting Polish institutions. The sanctions coincide with broader European efforts to strengthen cybersecurity and counter state backed cyber threats. Apple has sued OpenAI in federal court, accusing the company of building its emerging AI hardware business using stolen trade secrets and confidential information from former Apple employees. The lawsuit centers on OpenAI's $6.4 billion acquisition of I O Products, co founded by former Apple executive Tang Yutan, who Apple alleges emailed himself confidential supplier information before leaving the company and later encouraged Apple job candidates to bring proprietary hardware details to interviews. Apple also accuses former employee Chang Lu of accessing its internal network after departing and downloading confidential files on unreleased products by exploiting an authentication flawless. Apple claims it warned OpenAI about its concerns in February but received no response and argues the alleged misconduct extends beyond the known cases. OpenAI denied the allegations, saying it has no interest in other companies trade secrets. The lawsuit could complicate OpenAI's planned initial public offering by raising legal and investor concerns. Progress Software has warned of a potential security incident affecting ShareFile storage zone controllers, its private enterprise storage solution, after detecting what it described as a credible external threat. As a precaution, the company temporarily disabled customer access and instructed organizations to shut down servers hosting affected storage zone controllers while investigations continue. Progress said it has found no evidence of unauthorized access to customer accounts or data and has not identified an active threat, although it has provided few details about the nature of the incident. Customer frustration grew after several days without public updates, fueling speculation about possible vulnerability exploitation, which the company has not confirmed. By July 12, cloud access had been restored, but customers were told to keep storage zone controllers offline pending the completion of Progress's internal and external security investigations. Zimbra has released patches for a critical vulnerability in its classic Web client that could allow zero click code execution when a user opens a specially crafted email. The stored cross site scripting flaw could expose mailbox data, session information and account settings. Although the vulnerability has not yet received a CVE identifier, Zimbra is urging all customers using the Classic Web client to upgrade. The flaw was reported by Google's Threat Analysis Group, which often identifies vulnerabilities exploited by state sponsored threat actors. The U.S. environmental Protection Agency conducted a national cybersecurity exercise to help water utilities prepare for a worst case communications outage caused by a simulated cyber attack on a major telecommunications provider based on intelligence about the Chinese threat group SALT Typhoon. The scenario forced utilities to consider how they would maintain safe water operations without Internet phone service, cloud applications or remote SCADA access. More than 200 utilities participated in discussions covering incident response, alternative communications, staffing and transitioning to manual or local operations. Participants highlighted challenges such as maintaining water quality, sustaining 24 hour staffing and balancing operational priorities during extended outages. The exercise underscored that preparedness varies widely among utilities depending on their size, infrastructure and reliance on remote operations, emphasizing the importance of planning for prolonged communications disruptions. Fraudsters are creating convincing clones of trusted news websites, including the Guardian, to lure victims into fake investment scams. The counterfeit articles feature fabricated stories about well known figures such as Jim Ratcliffe, David Attenborough and Martin Lewis, often using AI generated images and the bylines of real journalists to appear authentic. The stories include links to fake versions of legitimate trading platforms where victims are prompted to provide personal information before being persuaded by scammers to invest money in non existent opportunities. Security experts warn that the goal is simply to steal victims funds. Readers are advised to verify website URLs, be wary of sensational investment claims and remember that reputable news organizations do not endorse investment platforms. Companies such as Kraken say they actively work to remove impersonation sites and report those responsible to law enforcement. JAMF Threat Labs has identified a new macOS information stealing malware family dubbed Crash Stealer, which has evolved from an apparent development stage sample into an actively deployed threat. First spotted in May, the malware masquerades as Apple's crash reporting framework and is written in native C, distinguishing it from many other macOS stealers. Crash Dealer validates a victim's login password before collecting data from browsers, cryptocurrency wallets, password managers and the macOS keychain. It encrypts stolen information before exfiltrating it and establishes persistence by copying and re signing itself. Researchers also discovered assigned an Apple notarized dropper distributed as a disk image named Workbit Setup that bypasses gatekeeper downloads the payload and launches it. JAMF considers Crash Stealer a distinct malware family due to its unique architecture and capabilities. Turning to our Monday business briefing, cybersecurity companies continued to attract significant investment and consolidation activity this past week. Encryption management firm Keyfactor raised more than a billion dollars in a growth round led by Summit Partners to support product development, global expansion, acquisitions and hiring. Dutch managed security services provider iSecurity secured 60 million euros to expand across Europe and invest in AI capabilities, while AI surveillance firm Hakimo, identity security company Woltra and maritime cybersecurity startup Sitor also announced new funding rounds to fuel growth and international expansion. Merger and acquisition activity remained strong with seven deals across five countries. Notable transactions included Infoblox's planned acquisition of network observability company Kentic, Akamai's completion of its $205 million acquisition of enterprise browser security firm LayerX, Qualcomm's purchase of SAM Seamless Network, and Aikido's acquisition of Israeli container security startup Root. The deals reflect continued investment in AI, identity security, zero trust and infrastructure protection. Be sure to check out our complete business briefing that's part of Cyberwire Pro. You can find that on our website. Coming up after the break, Brandon Karp from ntt discusses the 11th Japan US Cyber Dialogue and Californians smash that delete button. Stay with us. What's the one thing in business that's spreading as fast as AI? AI risk. Every new tool your team signs up for. Every vendor that turns on AI features, every new integration. Each one is an opportunity for something to go wrong. And most security programs weren't built for AI's pace of growth. Enter Vanta. Vanta is the number one agentic trust platform used by over 16,000 fast moving companies like Ramp, Cursor and Harvey to ensure they're always audit ready. And now Vanta is helping companies like yours. Watch for the risks that show up between audits across your vendors, your AI tools and your whole environment. How the Vanta agent works like a 24.7grc engineer in the background, finding issues, drafting fixes and cutting vendor assessment time by up to 50%. Whether you're a fast growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today@vanta.com cyber that's V A N T A dot com cyber.
B
This episode is brought to you by Google Chrome. You think you know a browser, but Gemini and Chrome? That's new. It can help you with practically Anything on the web like restoring a vintage motorcycle from a 50 page restoration block or finally break down that long article you've had open for weeks. Gemini and Chrome is here for it, ready to make anything online make sense. There's no place like Chrome. Check responses, setup required compatibility and availability various 18.
A
It is always my pleasure to welcome back to the show Brandon Karp. He is the leader of international public private partnerships at ntt. Brandon, welcome back.
B
Dave, great to be here with you again.
A
So we recently had in Washington, D.C. the 11th Japan U.S. cyber Dialogue, which is kind of a boring name for an interesting thing.
B
Yes. Leave it to diplomats to make things super dry and sound uninteresting when there's tons of meat on that bone.
A
Right, right. Well, let's dig into it. I mean, you were there, correct?
B
Yeah, we participated. And NTT in particular, of course Particip participated being one of the or being the largest telecommunications company in Japan. And so we certainly had a role to play here. So did a number of other companies. And of course the governments of Japan and the US Participated.
A
Right. So unpack this meeting. What is this all about?
B
Yeah, so I mean, as you mentioned, this is the 11th one of these. So these have been held every year for more than a decade now. I would actually say that this is probably the one that is the clearest in terms of what was on the agenda and what is notably changing and for a couple reasons. First, I think the headline is what made it onto the agenda? And a couple key topic areas that I think are particularly important for the threat environment and technology environment. One of them is sovereign cloud, another one is post quantum cryptography. And then the third one that made the agenda that was particularly interesting was shutting down scam compounds in Southeast Asia. So there were some really interesting threat environment topics that kind of made the list for the diplomatic corps and the national cybersecurity leadership of the two countries to discuss through the two days of dialogues. What I think was particularly notable, right, is this comes a little more than a year after Japan signed the act of Cyber Defense Law, which was their creation of the National Cybersecurity Office that is coordinating cyber security, but also more kind of takedown operations and those types of activities, more kind of disruptive doctrine type aspects and operations that the Japanese government, specifically their national police and the national defense Forces will be enabled to conduct. And so this was the first dialogue that has really occurred since that act has been operationalized over the last year.
A
I should mention, just for our audience's sake, that before you were with ntt, you of course, were a US Naval officer and served at Cyber Command. How do you describe the relationship, the diplomatic relationship, between the US and Japan when it comes to cyber?
B
Strong and strengthening. So until this act that I mentioned was signed into law a year ago, Japan had kind of a fragmented cybersecurity and Cyber Operations Force that act centralized authorities and controls underneath the National Cyber Office, which is kind of a combination of our FBI Cyber Division plus our cisa, plus NSA and Cyber Command, kind of all under one big heading. And so they're responsible for intelligence collection and prioritization, they're responsible for policy and public private collaboration, and they're responsible for taking more defensive or even offensive type actions through cyberspace. What that actually means on the ground, we don't know yet, because they're still implementing all these things. But the relationship between the Japanese government and the US Government is very strong right now with Prime Minister Takaishi in Japan and her relationships with Washington, but also with folks like Yukio Saita, who is kind of the international strategist at the National Cybersecurity Office, working very closely with our State Department and our Department of Homeland Security. And so, you know, you see these people starting to come to the US more and more and building this kind of commitment to sharing, which is really what we saw in the joint statement that was released after the cyber dialogue from the State Department, U.S. state Department, but also the Japanese executive branch agencies and diplomatic corps where they're committing to sharing lessons learned, sharing intelligence, sharing policy priorities and coordinating policy priorities around cyber defense. To me, that is the first step towards moving in a direction of joint operations or coalition operations.
A
Can you take us behind the scenes a bit? How is an event like this organized and how do they set expectations for success?
B
Sure. So in the room you have US organizations like the National Security Council, the Office of the National Cyber Director, the Office of the Director of National Intelligence. Right. FBI, Homeland Security, cisa, even NIST and fcc, more around standards and telco. So that's all from the US side. Of course. The entire thing is being organized and put on by the Department of State in the US in collaboration with the Japanese organizations, so their Ministry of Defense, their telecom regulator, their diplomatic Corps, and METI and their version of FCC as well. And so it's kind of a total coalition plan where this is stood up. There's also quite a lot of interaction with private sector in relation to this. So there's a. The Japanese Business Council, which is an organization within the US that's kind of A sort of a trade association kind of bringing in Japanese corporations, but also the coordination and participation of US Companies who have business interests in Japan. Keep in mind, Japan is one of the world's largest economies. I think it's the third or fourth largest economy in the world. So there's a lot of business operations and activities here. And so this is totally a. A joint activity. Right. There's US Co chairs, Japanese co chairs, who are putting this on for the two days of dialogues along all those various topics. There are certainly more than the ones I mentioned, but the topics that I mentioned at the beginning here were kind of the key ones that I saw which were most important. That being said, of course, they talked about things like AI security, et cetera, et cetera. But, you know, I'm sure you talk about that plenty, so we don't need to go into that here.
A
So what was the feeling as things wrapped up? Did the participants consider this to be a success?
B
Yes, most definitely. Again, this one, I think, was seen as the most substantive in the history of this dialogue. And why is that? Again, part of it, I think, is the act of cyber defense and how much investment the Japanese government is putting towards cyber defense of not just the Japanese homeland, but the entire Asia Pacific region. But also, of course, I mean, we're just about two years post the salt typhoon and kind of revelations where we saw this Chinese threat actor really owned the global telco companies, you know, more than 200 targets globally, in 80 countries around the world. And, you know, those revelations really just started kind of hitting the public wires about two years ago or so. And of course, just more and more information over the last two years. And so that the context of the threat environment in that region, that's the Chinese threats, of course, the North Korean kind of crypto scams, the Southeast Asian cyber criminal groups, in terms of the kind of the scam farms and those. This threat environment is really starting to coalesce in that region of the world at the same time that Japan is investing more and more in their capabilities, and they're both the defensive and offensive and legal authorities. And so I think it's given the US And Japan leaders more to talk about and more to do and start thinking about how policy aligns, how public private collaboration aligns, and how we can take proactive actions against these types of threats.
A
All right, sounds like an optimistic tone.
B
I think there's a lot of reason to be optimistic in this topic in particular.
A
Yeah, Brandon Karp is the leader of international public private partnerships at ntt Brandon, thanks so much.
B
Thanks Dave.
A
Organizations spend years building incident response plans, but when a real crisis hits, many discover those plans were built for auditors, not for operating through disruption. We recently spoke with Courtney Gus, crisis management director at Sempras, about why true cyber resilience depends on more than compliance. She explains why organizations need to move beyond static playbooks, establish clear decision making authority, and prepare leaders for the moments when technology and the plan itself may fail. If you're responsible for incident response, business continuity or cyber resilience, this is a conversation you won't want to miss. Listen to the full interview@explore.thecyberwire.com Sempras. Foreign. Batteries the same that's like asking if all soccer players are the same. Take Messi, the most decorated player ever. Is there any other player who has achieved that? No, just him. Now take Duracell. Is there any other battery with power boost ingredients inside? No, just Duracell. Remember, goats only trust goats because they're built different and Messi only trusts Duracell right now get up to 15% off select storage solutions put heavy duty HDX totes to good use, protecting what's important to you. The solid, impact resistant design prevents cracking,
B
and the clear base and sides make
A
items easy to find even when the totes are stacked.
B
Find select shelving and Tote storage up
A
to 15% off at the Home Depot. To organize every room in your home from your garage to your attic, visit homedepot.com how doers get MORE done. And finally, more than 300,000 Californians have pressed what state officials call the great delete button in the sky, invoking the nation's first delete act to force hundreds of registered data brokers to erase their personal information. Beginning August 1st, brokers must start processing requests to delete sensitive data ranging from location histories to financial details to health information and demographic profiles, while also stopping future sales of that data. The law aims to curb an industry that quietly assembles digital dossiers from loyalty cards, Web browsing, social media and countless everyday interactions, often selling them to advertisers, governments, AI developers and, as officials dryly note, seemingly anyone with a credit card. Regulators are pursuing unregistered brokers and warning that companies ignoring deletion requests could face steep fines. The process takes only a few minutes, a small investment for anyone hoping their personal life stops circulating quite so enthusiastically. And that's the Cyberwire. For links to all of today's stories, check out our daily briefing@thecyberwire.com we'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire2k.com N2K's lead producer is Liz Stokes were mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazes. Our executive producer is Jennifer Ivan. Peter Kiltney is our publisher and I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow.
Podcast: CyberWire Daily
Host: N2K Networks
Episode Date: July 13, 2026
This episode delivers a comprehensive briefing on current major cybersecurity news, with a particular focus on the global threat landscape, critical infrastructure vulnerabilities, evolving cyber legislation, and international cooperation. Notably, the show features an in-depth interview with Brandon Karp of NTT, discussing outcomes and strategic significance of the 11th Japan-US Cyber Dialogue. The episode wraps up with key business developments in cybersecurity and a spotlight on new privacy legislation in California.
Russian State Cyber Threats
European & UK Sanctions on Russia
Apple Sues OpenAI ([~04:30])
Progress ShareFile Incident
Zimbra Vulnerability & Patch
EPA Water Utility Cyber Exercise
Fake News Site Scams
JAMF Crash Stealer macOS Malware ([~10:40])
Significance of Dialogue
Key Agenda Topics ([16:30])
Sovereign Cloud
Post-Quantum Cryptography
Scam Compound Disruption in Southeast Asia
“A couple key topic areas… one of them is sovereign cloud, another one is post quantum cryptography, and then… shutting down scam compounds in Southeast Asia.” — Brandon Karp [16:34]
Japan’s New Cyber Defense Law ([17:15])
US–Japan Cyber Partnership ([18:06])
Deepening ties: more intelligence and policy sharing, foundation for future joint or coalition operations.
“Strong and strengthening… the relationship between the Japanese government and the US Government is very strong right now…” — Brandon Karp [18:25]
Vision for mutual public-private sector engagement and harmonized cyber defense doctrine.
Operational & Diplomatic Context ([20:12])
“It’s totally a joint activity… the topics that I mentioned at the beginning here were kind of the key ones that I saw which were most important.” — Brandon Karp [21:21]
Outcomes & Atmosphere ([22:01])
Dialogue considered the most substantive and optimistic to date.
Motivated by recent events, like the emergence of SALT Typhoon (Chinese threat group) and wider regional threat convergence.
“This one… was seen as the most substantive in the history of this dialogue… the context of the threat environment in that region, that’s the Chinese threats, of course, the North Korean… the Southeast Asian cyber criminal groups…” — Brandon Karp [22:01, 22:30]
Optimism driven by growing capabilities, new laws, and frameworks for proactive collaboration.
“I think there’s a lot of reason to be optimistic in this topic in particular.” — Brandon Karp [23:41]
“…hundreds of registered data brokers to erase their personal information… curb an industry that quietly assembles digital dossiers from loyalty cards, Web browsing, social media and countless everyday interactions…” — [25:53]
“To me, that is the first step towards moving in a direction of joint operations or coalition operations.” — Brandon Karp [19:35]
“This threat environment is really starting to coalesce in that region of the world at the same time that Japan is investing more and more in their capabilities…” — Brandon Karp [22:30]
“I think there’s a lot of reason to be optimistic in this topic in particular.” — Brandon Karp [23:41]
“…brokers must start processing requests to delete sensitive data… a small investment for anyone hoping their personal life stops circulating quite so enthusiastically.” — Dave Bittner [25:53]
This episode delivers a thorough, nuanced look at both persistent and emerging cyber threats worldwide, industry and regulatory responses, and the strengthening of key international alliances—particularly between the US and Japan. The expert commentary and timely news provide actionable insights for cybersecurity professionals, policy makers, and engaged listeners alike.