Loading summary
A
You're listening to the Cyberwire Network powered by N2K. This episode is supported by Black Hat usa. If you follow the research, you know a lot of it breaks on. Black Hat stages hundreds of peer reviewed briefings, more than 100 hands on trainings and the largest business hall in Black Hat's history. Six days to learn the skills you'll need tomorrow, August 1st through the 6th use code CYBERWIRE for $200 off your briefings pass@blackhat.com we'll see you in Vegas. China embraces open AI models, then worries it's become a national security the cyber attack on Minnesota water systems proves larger than first reported. CISA updates ITS SBoM guidance AI supercharges dangling DNS attacks. Researchers uncover a self propagating copilot worm. A critical Rails flaw demands urgent patching. Mac users are lured into installing malware through fake Claude guides. Amazon links a string of NPM compromises to North Korea. Russia charges Telegram's founder with aiding terrorism. Ben Yellen joins us with a border search case that's breaking new ground. And don't bite the North Korean hand that feeds you. It's Thursday, july 30, 2026. I'm dave buettner and this is your cyberwire intel brief. Thanks for joining us here today. It's great as always to have you with us. China has promoted itself as a leader in low cost open source artificial intelligence, arguing that AI should be widely accessible and criticizing US Efforts to restrict Chinese models. Open source systems from companies such as Alibaba and Moonshot have gained global adoption because they can be freely downloaded, modified and deployed. However, the New York Times reports that Beijing is increasingly concerned that the same openness could threaten national security and political stability. Officials worry advanced models could enable cyber attacks, scams, biological threats or Biden pass government censorship while also weakening the Communist Party's control over information. Reports suggest Chinese authorities are considering restrictions on exports or overseas access to their most advanced models, even as they continue promoting openness in principle. Analysts say China is trying to balance global influence with tighter control over strategically important AI technologies. The debate mirrors similar discussions in the US where companies disagree over whether open source or closed source AI offers the safest path forward, particularly as increasingly capable models emerge. As a follow up to Our earlier reporting, Minnesota officials say more than 30 community water systems were targeted in a coordinated CyberAttack or on July 26 and 27, the attacks focused on operational technology. But authorities say there's no evidence of public health risks and the investigation remains ongoing. State officials have launched a whole of state response, bringing together federal, state, local, tribal and private sector partners to investigate the incident, share threat intelligence and support affected utilities. Agencies involved include cisa, the epa, the FBI and Minnesota public safety and health officials. State Chief Information Security Officer John Israel said the coordinated response helped contain the incident quickly and demonstrated the value of Minnesota's cybersecurity investments and cross agency partnerships in protecting critical infrastructure. CISA, working with U.S. and international partners, has released its 2026 minimum elements for a software bill of materials, or SBoM. The updated guidance incorporates public feedback and expands to cover all software, including open source, artificial intelligence and software as a service. It adds new required data elements, clarifies existing ones and reflects lessons learned since the original 2021 guidance. CISA says the revisions will help organizations strengthen software supply chain visibility and make more informed cybersecurity risk management decisions. Researchers at Silent Push are warning that artificial intelligence could dramatically increase the threat posed by dangling DNS takeovers, a long known attack in which abandoned DNS records allow attackers to hijack subdomains. In research dubbed Dangleddon, the team used AI to automate domain discovery, identify exploitable targets and generate takeover scripts, reducing thousands of potential targets to hundreds of vulnerable systems in minutes. Safe demonstrations showed how exposed government, financial, manufacturing and pharmaceutical domains could be abused for phishing, malware, hosting or credential theft. Silent Push argues that while dangling DNS attacks have traditionally been used for financial gain, AI could make them far more attractive to nation state actors seeking widespread disruption. The researchers say the findings underscore the importance of promptly removing stale DNS records and decommissioned cloud resources. A researcher is warning of a new class of AI assisted attack that could allow malicious instructions hidden in Microsoft Word documents to spread through Copilot workflows. Hakon Malloy found that attacker controlled prompts embedded in a document can influence CoPilot generated content and silently copy themselves into newly created files, enabling a self propagating AI worm. Despite months of coordinated disclosure, Malloy says Microsoft has addressed specific proof of concept exploits, but not the broader vulnerability class. He argues the issue stems from a fundamental challenge with large language models processing untrusted content. Microsoft says it has implemented multiple safeguards and continues to strengthen its defenses, but recommends users treat external documents as untrusted, install updates and carefully review AI generated content before sharing it. Ruby on Rails developers are being urged to patch a critical active storage vulnerability that could let unauthenticated attackers read arbitrary files from affected servers. The flaw affects applications that use libvips for image processing and allows uploads from untrusted users. By uploading a specially crafted file, an attacker may be able to expose sensitive data, potentially leading to remote code execution or lateral movement. The recommended fix is to upgrade to a patched version of Active storage, then rotate all potentially exposed secrets for systems already running the current version. Administrators can also block vulnerable operations through configuration. As a temporary mitigation, researchers at Huntress say attackers disguised the Mac sync stealer and remote access tool as a Claude installation guide hosted on the legitimate Claude AI domain. Victims searching for Claude on a Mac encountered a paid Google advertisement leading to a public Claude share labeled as Apple Support. The page instructed users to paste a curl command into Terminal. That command launched a six stage infection chain, granting full disk access, stealing browser and keychain data, capturing validated account passwords, and installing a persistent remote access Trojan. The malware could also request screen recording access and modify installed cryptocurrency wallet applications to steal recovery phrases. Trusted platforms, sponsored search results and user executed commands can bypass traditional warning signs. Defenders should prioritize behavioral detections over file hashes, which change between builds. Amazon says a North Korea linked threat actor compromised several popular Node package manager or NPM libraries through maintainers, social engineering and malicious software updates. Amazon threat Intelligence links the Axios debug chalk and typo crypto incidents to the same actor with medium confidence. The campaigns use Trojanized packages, automatic post install scripts, reused code and shared command and control infrastructure. Researchers also observed attackers splitting malicious behavior across multiple packages and delaying activation through remotely controlled resources. Trusted open source dependencies can provide access to thousands of downstream environments. Security teams should examine runtime behavior and dependency relationships, not only individual packages or signatures. Amazon also warns that generative AI may help attackers create convincing packages and and manipulate automated code review systems. Russian authorities have charged Telegram founder and CEO Pavel Durov with aiding terrorism, accusing the messaging platform of failing to remove channels and bots allegedly used by Ukrainian intelligence and extremist groups to coordinate sabotage, terrorism and cyber fraud. Russia's Federal Security Service said the activity resulted in casualties and and claimed a Telegram based chatbot was used to recruit young Russians for attacks. Authorities have also placed Durov on international wanted lists, marking another step in the Kremlin's broader crackdown on online communications since the 2022 invasion of Ukraine. Coming up after the break, Ben Yellen joins us with a border search case that SP breaking new ground and don't bite the North Korean hand that feeds you. Stick around. It is always my pleasure to welcome back to the show Ben Yellen. He is from the University of Maryland center for Cyber Health and Hazard Strategies and also my co host on the Caveat podcast. Ben, welcome back.
B
Good to be with you again, Dave.
A
Interesting story. This is coming from the Guardian and it is about a gentleman who was stopped at the border, a gentleman named Sam Tunick who was on his way back from the Dominican Republic and police pulled him aside. He found himself on a terrorist watch list because of his alleged ties to a protest movement in Atlanta, a movement called Cop City. But the gist of what's happening here is that when police asked him to hand over his mobile device so they could search it and they asked him for his passcode, he gave it to them. But he was using graphene os, which is a privacy focused open source operating system, and when they put in the password, the phone wiped itself clean.
B
Yeah. So this is a fascinating story. The relevant federal law here makes it a crime to destroy property to prevent government seizure. So there's kind of the mens rea or criminal intent element here that the reason you are destroying that property is for the purpose of preventing government access to something. And here that would be the device. What makes this case unique is that all of the experts interviewed for this article were unaware of any previous case in which prosecutors had targeted a person because they use graphene or similar privacy focused operating systems to wipe their phones in a scenario like this. And this could have significant downstream effects. If the use of these graphene type tools is enough to cause law enforcement suspicion, then people who want to keep their communications private for whatever reason they mentioned, journalists or activists or lawyers, or people who are part of disfavored religious or other types of groups, people who are using privacy tools and security tools like graphene for their own purposes might be discouraged from doing so. And that would have a very deleterious impact. That goes against best practices. It goes against the recommendations of security experts who will tell people to employ these tools for their own protection. And the use of these tools is not in and of itself an indication that somebody is trying to facilitate criminal activity. And the fact that we have a prosecution here might create a dangerous precedent where the simple use of a privacy enhancing technology like this is inherently suspect. Now, what makes this very complicated is that this happened at the border. So airports count as the border. And the level of suspicion required to search people's devices, even for US Citizens, is lessened at the border because the government has a security, security interest in being able to protect the country from visitors and from US residents coming back from abroad. So they are generally given more leeway. There have been some disagreements among courts about how far that leeway extends. And generally courts have been reluctant to allow law enforcement without a warrant to do a full forensic search of a phone in the first place. But because we have that lesson standard, this case might not be so clear cut. I think if this had happened in a different context where it was not a border search. I think a judge might look at this and say a person's use of this privacy enhancing technology clearly shouldn't be enough to ignite criminal suspicion. And in and of itself can in no way support the charge that a person was trying to destroy property to prevent government seizure. But my concern is that because this happened at the border, everything law enforcement does at the border, I guess Customs and border Protection, everything they do at the border comes with a little bit more leeway because it is a border search. So I'm wondering how much of an impact that's going to have in this case.
A
Do you think it's fair to consider automatic data deletion to say that that is destruction of property?
B
I really don't because there is a legitimate privacy and security purpose to employing those types of tools. It's something that security professionals recommend. And so I think it would be a misreading of the statute to interpr interpret wiping one's device through the use of a graphene type tool as evidence that the person was trying to destroy property to prevent government seizure.
A
Let me play out another scenario here. So suppose instead of wiping the device, this passcode invoked extraordinarily strong encryption. Right. Uncrackable, strong encryption. So all the data is still there, but we've rendered it inaccessible. Is this a distinction without a difference? Is that, could that be considered destruction?
B
See, I think your example is a great one because I think it would be impossible for a prosecutor to argue that a person was destroying their property by employing encryption tools. But employing encryption tools has the same, like real world tangible effect of using graphene. Right?
A
Right.
B
In that moment, both of those tools are being employed to prevent government officials from looking at your device. So.
A
And that's what the law is about.
B
Exactly, exactly. But the fact that they're arguing here that one tool as opposed to the other one counts as destroying one's property, I think is suspicious. I mean, I don't think in our kind of normal understanding of what destroying property means, that it would necessarily include something like this graphing tool. I mean, it would obviously be destroying property if somebody took a baseball bat and tried to physically destroy their device. I think the statute was intended for government agents coming to your house looking for incriminating evidence and you burn the evidence. That's what this law was designed to prevent. And I think it's very possible this is just a misuse of that statute, applying it to a scenario that's completely inappropriate.
A
So do you suspect this could be a groundbreaking case? One to keep an eye on?
B
It is. I just again would raise my eyebrows at the co founding factors. It might be that this particular search was permissible because it happened at the border, but the court might take no position on whether the use of this federal statute as grounds for suspicion of criminal activity is acceptable in any other setting, if that makes sense.
A
Yeah.
B
So they might decide this on the narrow issue of, well, there's a decreased expectation of privacy for border searches and that wouldn't give us necessarily any indication of what would happen if there was a garden variety law enforcement investigation. You employed this tool and they said, look, they're trying to federal law prevents you from destroying property to prevent government seizure, so you're in trouble. It would be nice if we could have a groundbreaking case that was not at the border because the border just introduces all of these complications. So we might get that. But this is certainly a case to follow. But just warning about all these co founding factors that might make this particular case more difficult.
A
Yeah. Well, just a program note for our listeners, Ben and I discuss this in much greater detail over on this week's Caveat Podcast. So if you're interested, please do check that out. Ben Yellen is from the University of Maryland center for Cyber Health and Hazard Strategies. Ben, thanks so much for joining us.
B
Thank you, Dave.
A
If you're heading to Black Hat USA this year, make plans to visit the SpectreOps Kennel Club. As creators of Bloodhound, the SpectreOps team will host talks with OpenAI and the UK AI Security Institute, as well as hands on workshops aimed at helping you understand AI accelerated attack paths and the latest in identity tradecraft. Visit Spectrops IO to pre register and learn more. Spectrops Kennel Club is adjacent to Libertine Social inside Mandalay Bay. While you're there, visit the N2K CyberWire podcast studio where we'll be capturing expert perspectives and conversations from across blackhast. And finally, in a twist that might qualify as career limiting, some of North Korea's elite hackers allegedly turned their talents against the government that trained them. According to Daily nk, authorities arrested a group of former military cyber operators accused of stealing from the country's own central and foreign trade banks. The suspects, reportedly trained through the same system that produced the notorious Lazarus Group, allegedly recruited university graduates, infiltrated banking networks, siphoned off small amounts of state funds, converted the proceeds into cryptocurrency, and laundered the money through brokers in China. The scheme unraveled after officials noticed irregular foreign currency transactions and traced suspicious cryptocurrency activity to a location in Pyongyang, where investigators reportedly caught the group in the act. While the irony is hard to miss, the consequences are likely anything but amusing. Reports suggest the accused and potentially their families now face severe punishment under North Korea's system of collective responsibility. And that's the Cyber Wire. For links to all of today's stories, check out our daily briefing@thecyberwire.com we'd to like love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire2k.com N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazes. Our executive producer is Jennifer Ibin. Peter Kilpe is our publisher and I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow. Foreign. Usa the N2K CyberWire team will be on site recording from our podcast studio in the Spectrops Kennel Club. If you're interested in joining us for a conversation or learning more about what we're recording throughout the week, stop by the studio and meet the N2K CyberWire team. Spectrops Kennel Club is adjacent to Libertine Social inside Mandalay Bay.
Episode: Building a great firewall around AI
Date: July 30, 2026
Host: Dave Bittner (N2K Networks)
Special Guest: Ben Yellen (University of Maryland Center for Cyber Health and Hazard Strategies)
This episode provides a sweeping analysis of the latest developments in cybersecurity with a particular focus on the complex intersection of artificial intelligence (AI) governance, critical infrastructure threats, software supply chain security, and privacy rights at digital borders. Notable segments include China’s shifting stance on open source AI, cyberattacks on US water systems, and a deep dive into a legal case involving privacy tools at border checks.
[00:46 – 04:00]
Notable quote:
“China is trying to balance global influence with tighter control over strategically important AI technologies.” — [Host, 02:43]
[04:01 – 05:22]
[05:23 – 06:03]
[06:04 – 07:30]
Notable quote:
“AI could make [dangling DNS attacks] far more attractive to nation state actors seeking widespread disruption.” — [Host, 07:11]
[07:31 – 08:32]
[08:33 – 09:13]
[09:14 – 10:06]
[10:07 – 11:06]
[11:07 – 12:08]
Interview with Ben Yellen [12:09 – 19:52]:
Key quotes:
“The use of these tools is not in and of itself an indication that somebody is trying to facilitate criminal activity.” — Ben Yellen [13:45]
“It would be a misreading of the statute to interpret wiping one’s device…as evidence that the person was trying to destroy property to prevent government seizure.” — Ben Yellen [16:22]
“Employing encryption tools has the same, like, real world tangible effect of using Graphene.” — Ben Yellen [17:10]
“It would be nice if we could have a groundbreaking case that was not at the border because the border just introduces all of these complications.” — Ben Yellen [19:20]
[20:08 – 21:19]
Host’s summary:
“While the irony is hard to miss, the consequences are likely anything but amusing.” — [Host, 21:05]
This episode shines with high-impact news updates, technical insights, and legal analysis on cybersecurity’s most pressing problems. Discussion ranges from the international chessboard of AI openness, to practical threats like dangling DNS, to real-world legal dilemmas at the intersection of privacy and security. The interview with Ben Yellen offers a measured, critical look at privacy tech and law at the border, likely to spark debate among listeners.
Listeners gain not only a rundown of the week’s events, but a deeper understanding of the trade-offs and complexities shaping today’s cybersecurity landscape.