Loading summary
Dave Bittner
You're listening to the Cyberwire Network powered by N2K.
Sponsor Voice 1
This episode is brought to you by Google Chrome. You think you know a browser, but Gemini and Chrome? That's new. It can help you with practically anything on the web, like restoring a vintage motorcycle from a 50 page restoration block. Or finally break down that long article you've had open for weeks. Gemini and Chrome is here for it, ready to make anything online make sense. There's no place like Chrome. Check Responses Setup required compatibility and availability various 18/.
Host / Interviewer
This episode is supported by Black Hat usa. If you follow the research, you know a lot of it breaks on Black Hat stages hundreds of peer reviewed briefings, more than 100 hands on trainings, and the largest business hall in Black Hat's history. Six days to learn the skills you'll need tomorrow, August 1st through the 6th, use code CYBERWIRE for $200 off your briefings pass@blackhat.com we'll see you in Vegas. Treasury sanctions a VPN provider tied to ransomware the Pentagon hit pause on CMMC audits Critical flaws surface in Google Cloud's dialogflow CX Estee Lauder discloses a data breach Mobile networks become a battlefield for tracking US Personnel, Australia calls out big tech over child safety, SAP patches, critical bugs, CISA flags an actively exploited Cisco flaw and the federal government accelerates AI investments. Our guest is Bogdan Badazatu, senior director of threat research and reporting at bitdefender, talking about cyber threats to journalists and influencers and AI Cost savings come at a price. It's Tuesday, july 14, 2026. I'm dave buettner and this is your cyberwire intel brief.
Sponsor Voice 2
Foreign.
Host / Interviewer
Thanks for joining us here today. It's great as always to have you with us. The U.S. treasury Department's Office of Foreign Assets Control has sanctioned VPN provider First VPN Service, also known as One VPNS, its administrator and a Belarusian crypto seller former for supporting ransomware operations targeting US Organizations. According to Treasury, One VPNS marketed itself to cybercriminals by promising no user logs and no cooperation with law enforcement, while the operator allegedly used false identities to obtain hosting infrastructure. The sanctions follow the may takedown of 1 VPNs during the multinational operation at Safran, which resulted in server seizures, the operator's arrest and the exposure of thousands of suspected cybercriminal users. Treasury said ransomware campaigns using 1 VPNs caused billions in losses. Officials say the action targets the broader ecosystem of services that enable ransomware, not just the operators themselves. The Pentagon has suspended cybersecurity Maturity Model Certification Phase two requirements, delaying mandatory third party cybersecurity assessments that were set to take effect in November of this year. Defense officials said the move is intended to reduce administrative burdens, particularly for small and non traditional contractors, while maintaining existing cybersecurity standards. Companies will still be required to comply with NIST SP 800171 through self assessments, but the department is eliminating third party audits. During a 60 day review of the program, officials cited a shortage of certified assessors, noting that more than 100,000 defense contractors would have needed audits from only about 100 available assessors. The Pentagon says the review will seek a more practical approach that strengthens cybersecurity without slowing defense production or limiting participation by smaller companies. Researchers at Varonis uncovered critical vulnerabilities in Google Cloud's dialogflow CX that could have allowed attackers to hijack AI agents, steal credentials and access chat logs. The flaws stemmed from custom Python code blocks running in a shared cloud run environment with excessive privileges, potentially allowing a compromise of one agent to affect all others. In the same project, Google patched the issues between April and June 2026. Organizations are advised to review audit logs and inspect code blocks for unauthorized changes. The Estee Lauder Companies has disclosed a data breach that exposed sensitive personal and health information, according to a filing with the Vermont Attorney General. The compromised data may include Social Security numbers, health records, pharma financial account information and government issued identification numbers. The company has not disclosed how the breach occurred or how many individuals were affected. Estee Lauder said it is investigating the incident, working with law enforcement and notifying potentially impacted individuals. Recipients are encouraged to verify any breach notifications through the company's official channels. Middle Eastern telecom networks experienced a wave of cyberattacks during the conflict with Iran that appeared aimed at tracking the locations of U.S. military personnel and contractors, the Financial Times reports. According to telecom data reviewed by security researchers, attackers used SS7 location requests, a long standing vulnerability in mobile networks to target phones roaming outside their home networks. U.S. and regional officials suspect Iran or affiliated actors, though attribution has not been confirmed. Separate reports also suggest Iranian linked actors may have abused commercial smartphone advertising data to identify US Personnel. In Iraqi Kurdistan, lawmakers have renewed concerns that mobile network vulnerabilities and the commercial sale of location data expose military personnel to surveillance. U.S. central Command acknowledged receiving reports of adversaries exploiting commercial location data and said it implemented additional force protection measures while emphasizing that data tracking did not play a significant role in attacks on US forces. Australia's eSafety regulator says major technology companies including Apple Meta and Google continue to have significant shortcomings in preventing child sexual abuse and online sexual extortion. A new transparency report found that many platforms are not fully using available technologies such as language analysis tools to detect common coercion tactics used by offenders. The regulator also identified weaknesses in user reporting tools across services, including WhatsApp, iMessage, Discord and Google Messages. Between July and December of last year, ESAFETY received more than 2,000 reports of sexual extortion with young adults most affected. While the report highlights progress by companies including Google Meta, Microsoft, Snap and Discord in detecting abuse and grooming, it concludes that broader adoption of existing safety technologies remains insufficient to address the growing threat. SAP has released security updates addressing 16 vulnerabilities across multiple products, including three critical flaws affecting Netweaver, commerce, cloud and App router. The most severe is a memory corruption vulnerability in SAP netweaver application server ABAP that could allow an authenticated attacker to exploit memory management flaws, potentially leading to unauthorized data access, data modification or system outages. SAP said the vulnerability poses a high risk to the confidentiality, integrity and availability of affected systems. CISA has added a critical Cisco iOS vulnerability to its Known Exploited Vulnerabilities catalog, requiring US federal agencies to remediate it under Binding Operational Directive 2201. The flaw affects Cisco 871 integrated services routers and involves cross site request forgery vulnerabilities that could allow attackers to trick authenticated administrators into executing arbitrary commands. CISA also urges private organizations to review the KEV catalog and address affected systems to reduce cybersecurity risk. The Federal Technology Modernization Fund is moving quickly to invest in generative AI before its current funding Authority expires on September 30th. Federal agencies have until July 24th to submit proposals for AI and permitting technology products, with awards expected before the deadline. Acting Executive Director Jesse Pasilkin says the effort is intended to help agencies adopt AI responsibly while building on previous investments in cloud modernization, cybersecurity and automation. Developed with the General Services Administration's USAI team, the initiative will fund projects that improve AI ready infrastructure, prepare data, test emerging applications and deploy secure enterprise AI capabilities. The accelerated timeline reflects uncertainty over the fund's long term future. Since launching in 2017, the Technology Modernization Fund has invested more than $1 billion in rough 70 projects across the federal government. Coming up after the break, my conversation with Bogdan Bodhisattu, senior Director of Threat Research and reporting@bitdefender. We're talking about cyber threats to journalists and influencers and AI cost savings come at a price. Stick around. What's the one thing in business that's spreading as fast as AI? AI risk. Every new tool your team signs up for. Every vendor that turns on AI features, every new integration. Each one is an opportunity for something to go wrong. And most security programs weren't built for AI's pace of growth. Enter Vanta. Vanta is the number one agentic trust platform used by over 16,000 fast moving companies like Ramp, Cursor and Harvey to ensure they're always audit ready. And now Vanta is helping companies like yours watch for the risks that show up between audits across your vendors, your AI tools and your whole environment. How the Vanta agent works like a 24,7 GRC engineer in the background finding issues, drafting fixes and cutting vendor assessment time by up to 50%. Whether you're a fast growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today@vanta.com cyber that's V-A-N T A.com cyber. Bogdan Bodhisattu is Senior Director for Threat Research and reporting@bitdefender. We recently sat down to discuss cyber threats to journalists and influencers.
Bogdan Badazatu
Well, I'm a former journalist myself and I've been formally studying journalism for quite a while now. And even if I didn't have a whole history of reporting, for instance, I've done that in the university and as I remember back then it was a dangerous job even if technology wasn't a huge piece of the operational part. Now we have been invited every once in a while to discuss basic cybersecurity hygiene with college students and university students. Realize that the technological bar is so low now, I don't want to make this more obvious that it is, but journalism in itself is a trade and people who train in doing proper journalists don't have time to dissect the ins and outs of technology, even if this is probably one of the most important channels of communications that they have today. So we started easy building some sort of a curricula for freshman journalists to teach them basic cybersecurity hygiene. What phishing is how to tell a deep fake from a real video, how to interact with the Internet in a safe manner, how to limit their exposure of private information because at the end of the day an adversary will piece all this information together and use it against the journalists themselves.
Host / Interviewer
What is your sense for how well journalists are equipped these days to protect themselves against these sort of things.
Bogdan Badazatu
It's low. And this is not just because they are not tech savvy, because some of them are. I'd say that their ability to protect themselves is low because the adversaries have become more and more skill and most of the tools that these adversaries are using are sophisticated and readily available off the shelves. Before 2010, I'd say governments had to build their own spyware arsenal to target journalists. Now they can purchase one software development kit from a vendor, like, I'm not gonna mention vendors here. So journalists can become targets even to governments or to regular cybercriminals, because the hacking barrier has become so low because of the commoditization of malicious arsenals.
Host / Interviewer
And what is it about journalists that make them such an attractive target?
Bogdan Badazatu
I have great respect for this trade. They have sacrificed all their lives to bring to surface the truth. And in the society that we live today, it takes a lot of courage to unveil corruption, to report about the things in society that people in power want hidden. Journalists are now one of the most predilect targets because a like regular people, they normally are practical targets for regular cybercriminals, just like everybody else and biologists because they deal with information, with sensitive information, and that sensitive information normally exposes corruption. So people in positions of power would like them silenced, would like their sources to be identified, would like that the journalist's information expose whistleblowers and help these people control the narrative.
Host / Interviewer
Are there common mistakes that you see journalists making that the threat actors are able to take advantage of?
Bogdan Badazatu
Yes, One of the probably most important mistake is not knowing what you're not knowing. To put it simple, technology has evolved so fast and it's so blown now that journalists don't necessarily keep up with the latest innovations. One thing that popped into the questionnaire that we did before our workshop was do you believe that if you're using the Tor browser, for instance, to do research, can you be de anonymized or identified? And journalists, even the seasoned ones, were like, no, because this is the whole point of using Tor. It's an anonymous service that helps me and my sources stay anonymous. All it takes for somebody to de anonymize themselves is to modify the browser size, for instance, and all of a sudden they will be more easy to get identified in the whole noise of the to a browser.
Host / Interviewer
So there are basic things here that people take for granted that perhaps they shouldn't.
Bogdan Badazatu
Yes, definitely. And we are trying to correct these behaviors we are trying to give them a helping hand to stay safe while doing the job. Another thing that seems to be important now is that traveling as a journalist has become more and more dangerous. And I'm not saying that just for journalists traveling to countries that are known to be oppressive regimes like Russia or Belarus or parts of Africa. No, even when traveling in the United States, for instance, they can be subject to confiscation and searches even if they haven't done anything. The state's border patrol, for instance, has the right to refuse everybody access to the United States unless they go through mandatory device inspection. Journalists are no exception to that.
Host / Interviewer
Can you give us some insights as to the types of things that you've heard from some of the journalists who have gone through this program or examined this research?
Bogdan Badazatu
Well, we structured this workshop in three chapters, starting with basic digital hygiene and then moving into more seasoned reporting, people who have been working in in the newsroom for a while but are specializing in cybersecurity. And the last chapter closes the investigative part, where risks are higher, the stakes are higher, and journalists need to be a little bit more careful to what they're doing on the Internet. So because there was this heterogeneous mass of journalists of all types and experience levels, some of them were really, really amazed at how easy it is to conduct phishing or how easy they are to fall victim to social engineering. Some others knew about these already and they were less impressed by the basic part, but they were also more interested in learning about how state sponsored surveillance works or how much information they can disclose just by sticking decals on their car or on their work computers.
Host / Interviewer
Yeah, it's interesting to me that I think it's easy for folks to think that they don't have anything that anyone would be interested in. Right. But even if you're a journalist who's covering something that you may think is not particularly interesting, the person sitting at the desk next to you might be very interesting to the adversaries and maybe they're trying to get to them through you.
Bogdan Badazatu
Of course, that's a very highly likely situation. And deepfakes make it easier because now impersonating a colleague or an editor only requires a couple of minutes of video footage and all the audio footage and an open source generating model that can put a face and words on somebody else's body. Right.
Host / Interviewer
That's Bogdan Bonazatu from Bitdefender.
Dave Bittner
When you need to build up your team to handle the growing chaos at work, use indeed sponsor jobs. It gives your job post the boost. It needs to be seen and helps reach people with the right skills, certifications and more. Spend less time searching and more time actually interviewing candidates who check all your boxes. Listeners of this show will get a $75 sponsored job credit@ Indeed.com podcast. That's Indeed.com podcast. Terms and conditions apply. Need a hiring hero? This is a job for Indeed.
Sponsor Voice 1
Sponsored Jobs Pros Trust the Home Depot for heavy duty storage solutions for any job site or garage right now. Get up to 15% off select storage and organization Impact and water resistant totes and shelving built to hold up to £2,500. Storage systems have space for all your tools and protect them in the garage, on the job site and everywhere in between. Save time and maximize efficiency with adjustable shelving customized to your business's needs. Shop and save on pro grade storage at the Home Depot. How Pros get more Done Are all batteries the same? That's like asking if all soccer players are the same. Take Ms. The most decorated player ever. Is there any other player who has achieved that? No, just him. Now take Duracell. Is there any other battery with power boost ingredients inside? No, just Duracell. Remember, goats only trust goats because they're built different and Messi only trusts Duracell.
Dave Bittner
I get so many headaches every month. It could be chronic migraine 15 or more headache days a month, each lasting four hours or more.
Sponsor Voice 2
Botox Audubotulinum Toxin a prevents headaches in adults with chronic migraine. It's not for Those who have 14 or fewer headache days a month. Prescription Botox is injected by your doctor. Effects of Botox may spread hours to weeks after injection, causing serious symptoms. Alert your doctor right away as difficulty swallowing, speaking, breathing, eye problems or muscle weakness can be signs of a life threatening condition. Patients with these conditions before injection are at highest risk. Side effects may include allergic reactions, neck and injection site pain, fatigue and headaches. Allergic reactions can include rash, welts, asthma symptoms and dizziness. Don't receive Botox if there's a skin infection. Tell your doctor your medical history, muscle or nerve conditions including als, Lou Gehrig's disease, Myasthenia gravis or Lambert Eaton syndrome and medications including botulinum toxins, as these may increase the risk of serious side effects.
Dave Bittner
Why wait? Ask your doctor, visit botoxchronicmigraine.com or call 1-844botox to learn more.
Host / Interviewer
And finally, the AI honeymoon may be ending as enterprises discover that unlimited curiosity comes with a very real price tag. According to leaked internal communications obtained by 404 media companies, including Atlassian, Adobe, Amazon and Citi are reining in employee access to advanced AI models after usage costs ballooned. Some organizations are steering workers toward less powerful models, while others have temporarily disabled premium offerings or introduced dashboards to track AI spending. Atlassian's reported monthly AI bill climbed from roughly $5 million to more than 15 million, and some employees say token limits are now forcing them to rethink AI heavy workflows. Even Amazon reportedly replaced AI usage leaderboards with spending limits. The shift reflects a broader reality as enterprise AI pricing moves to usage based billing. Companies eager to embrace AI are now discovering that every prompt has a price, and token economics is becoming almost as important as the technology itself. There's a certain irony here. Many companies embraced AI as a way to reduce labor costs and do more with fewer people. Now they're discovering that replacing payroll with prompt bills isn't quite the bargain they imagined. It turns out AI may not be asking for vacation time, but it's proving remarkably good at running up the tab. And that's the Cyber Wire. For links to all of today's stories, check out our daily briefing@thecyberwire.com we'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire2k.com N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazes. Our executive producer is Jennifer Ibin. Peter Kilpe is our publisher and I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow.
Bogdan Badazatu
Hey, it's Ryan Reynolds here for Mint Mobile. Now, I was looking for fun ways to tell you that Mint's offer of unlimited premium wireless for $15 a month is back.
Host / Interviewer
So I thought it would be fun if we made $15 bills, but it turns out that's very illegal.
Bogdan Badazatu
So there goes my big idea for the commercial. Give it a try@mintmobile.com switch upfront payment
Dave Bittner
of $45 for three months, $90 for six months or $180 for a 12 month plan required $15 per month equivalent taxes and fees Extra initial plan term only greater than 50 gigabytes. Me slow when network is busy see terms.
Date: July 14, 2026
Host: Dave Bittner (N2K Networks)
Featured Guest: Bogdan Badazatu, Senior Director of Threat Research and Reporting, Bitdefender
This episode examines the rapidly evolving landscape of cyber threats, from major policy actions and critical vulnerabilities to the specific dangers facing journalists in the digital age. The show highlights U.S. and international regulatory news, industry breaches, and the operational realities of enterprise AI. The centerpiece is a deep-dive interview with Bogdan Badazatu focused on the cybersecurity challenges for journalists and influencers amidst ever-lowering barriers for threat actors.
Topic: Cyber Threats Facing Journalists and Influencers
[13:15 – 21:46]
Low Digital Security Baseline
Journalists’ Vulnerabilities Are Increasing
Why Journalists Are Targeted
Common Mistakes
Travel and Border Risks
Workshop Insights
The Risk of Collateral Targeting and Deepfakes
[24:37 – 25:56]
| Timestamp | Speaker | Quote | |-----------|-----------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------| | 13:33 | Bogdan Badazatu | “Journalism in itself is a trade and people who train in doing proper journalism don't have time to dissect the ins and outs of technology…” | | 15:03 | Bogdan Badazatu | “Their ability to protect themselves is low because the adversaries have become more and more skill and most of the tools that these adversaries are using are sophisticated and readily available off the shelves.” | | 16:06 | Bogdan Badazatu | “Journalists are now one of the most predilect targets…they deal with information, with sensitive information…so people in positions of power would like them silenced.” | | 17:16 | Bogdan Badazatu | “One of the probably most important mistakes is not knowing what you're not knowing. To put it simple, technology has evolved so fast…” | | 21:17 | Bogdan Badazatu | “…Deepfakes make it easier because now impersonating a colleague or an editor only requires a couple of minutes of video footage and all the audio footage and an open source generating model…” | | 25:27 | Host | “Every prompt has a price, and token economics is becoming almost as important as the technology itself.” |
This episode of CyberWire Daily highlights the interconnectedness of digital threats for institutions and individuals alike, from sweeping sanctions and enterprise vulnerabilities to the micro-level cybersecurity struggles of journalists on the front lines of information. Through both news coverage and expert interviews, it makes clear that defending information in 2026 requires vigilance, updated knowledge, and a healthy skepticism about the promises of both security tools and technological shortcuts.