Loading summary
A
You're listening to the Cyberwire Network powered by N2K. This episode is supported by Black Hat usa. If you follow the research, you know a lot of it breaks on. Black Hat stages hundreds of peer reviewed briefings, more than 100 hands on trainings, and the largest business hall in Black Hat's history. Six days to learn the skills you'll need tomorrow, August 1st through the 6th, use code CYBERWIRE for $200 off your briefings pass@blackhat.com we'll see you in Vegas. Anthropic says Claude escaped the sandbox three times while a judge question the Pentagon's blacklist. The EU launches an AI enforcement team, the FTC targets a telehealth firm's tracking pixels, and a WordPress backdoor is stopped just in time. Care Cloud discloses a major data breach, a stealthy crypto miner hides in plain sight, ATM phishing surges against law firms, and Finland severs one more digital link to Russia. Our guest is Jan Shoshet Sevilli, Associate professor at Arizona State University, with a preview of his black hat 2026 keynot vulnerability research in the agentic age and AI scammers may deserve a promotion. It's Friday, july 31, 2026. I'm dave bittner and this is your cyberwire intel brief. Foreign. Thanks for joining us here today. Happy Friday. It is great as always to have you with us. Anthropic disclosed that a review of its CyberSecurity testing uncovered three cases in which its clawed AI models unintentionally hacked real world organizations after escaping what were supposed to be isolated testing environments. The company examined more than 141,000 evaluations following a similar disclosure by OpenAI and found incidents dating back to April. The breaches occurred during capture the flag exercises designed to test offensive cybersecurity capabilities due to a misunderstanding with evaluation partner Irregular. The environments had Internet access despite being presented to the models as offline simulations. Anthropic said older models continued attacking after reaching the open Internet, while its latest model recognized the mistake and stopped. The affected organizations were not identified, and neither they nor Anthropic initially detected the intrusions. The company said the models, which lacked normal public safeguards, exploited weak passwords to gain access. Anthropic acknowledged human errors contributed to the incidents and said future AI evaluations involving powerful autonomous systems will require much stronger security controls. Meanwhile, a federal judge expressed strong skepticism over the Pentagon's decision to blacklist Anthropic as a supply chain risk, suggesting the action may conflict with first amendment protections. During a hearing in Anthropic's lawsuit, Judge Rita Lynn questioned whether the Defense Department had retaliated against the company, while for its public stance on limiting military use of its AI models, including mass surveillance. Anthropic argues the designation threatens billions in revenue, while the Pentagon says it must make independent national security decisions and trust the AI technologies it deploys. Government attorneys maintained the designation was an internal contracting decision rather than regulatory action and argued AI presents unique security concerns because new models can introduce unknown capabilities. The judge said she will issue a written ruling. The hearing also clarified that the blacklist does not legally prohibit all Defense Department contractors from using Anthropic's models. The European Union has launched a new enforcement team to oversee compliance with its AI act, which takes effect Sunday, marking one of the world's most comprehensive efforts to regulate artificial intelligence. The expanded AI Office will monitor companies for violations such as AI generated misinformation, explicit content, cyber threats and other systemic risks, including threats to critical infrastructure and fundamental rights. AI providers must clearly label AI generated content through disclosures or digital watermarks. The EU has also introduced whistleblower and compliance tools to support investigations and can impose fines or restrict market access for violators. The initiative follows recent AI safety incidents involving anthropic and OpenAI and reflects the EU's broader strategy to strengthen oversight while reducing dependence on US and Chinese technology. The Federal Trade Commission has sued telehealth provider HIMS and Hers, alleging the company improperly shared customers sensitive medical and health information with advertising and technology companies including Meta, Snap, Microsoft, Pinterest, Reddit and X, while misleading users about its privacy practices. According to the complaint, tracking pixels embedded on the company's website collected and transmitted health related data and user activ despite privacy policy statements suggesting otherwise. The FTC also alleges Hims and Hers engaged in deceptive billing practices and made subscription cancellations unnecessarily difficult. Hims and hers says its privacy policy gives users choices over how their data is used and that it intends to vigorously defend itself against the allegations. The lawsuit continues the FTC's broader effort to crack down on healthcare companies accused of improperly sharing patient sensitive information with third party advertisers. A malicious backdoor was discovered in the most recent version of the advanced responsive video embedder WordPress plugin before it reached users through WordPress.org's automatic update system. Detected within two hours by Wordfence's Prism system, the critical vulnerability, with a CVSS score of 9.8, could have allowed attackers to gain administrator access using a single embedded authentication token. The malicious code also transmitted site information to an attacker controlled server. Wordfence believes the developer's account was likely compromised, allowing the malicious commitment. WordPress.org quickly removed the plugin from distribution, and its recently introduced update delay prevented automatic installation on most sites. Organizations running version 10.1.1, particularly if installed manually or from third party sources, should remove it immediately and review their systems for signs of compromise. Care Cloud is notifying at least 350,000 individuals that their personal, financial and medical information was stolen in a March 2026 data breach affecting an electronic health record environment. The company said attackers accessed one of its Amazon Web services environments between March 10 and March 16 and likely exfiltrated sensitive data, including Social Security numbers, financial information and health records. Care Cloud says it has no evidence the stolen data has been misused and is offering affected individuals 24 months of identity protection and credit monitoring. The company has not identified the threat actor or disclosed the total number of impacted individuals. Researchers at Group IB have identified a cryptojacking campaign that deliberately abandons root access on compromised Linux servers to evade detection after gaining root privileges through a trusted third party connection. The attackers used Linux pluggable authentication modules to impersonate low privileged users without passwords, allowing the malware to persist while avoiding security monitoring focused on administrator accounts. The campaign also disabled logging services, altered authentication logs, disguised malicious processes as legitimate ones, and masked mining traffic as normal web activity. The malware, a modified version of the XMRig Monero miner, deletes itself from a disk after launching and runs entirely in memory, complicating forensic analysis, Group IB recommends forwarding logs to tamper proof external systems, restricting third party access and using memory forensics to detect similar attacks. Adversary in the middle Phishing has become the leading initial access method targeting law firms accounting for just under 29% of attacks, according to a new E Centire Threat Intelligence report. The technique bypasses multi factor authentication by intercepting valid user sessions, reflecting attackers shift from stealing credentials to hijacking authenticated sessions. E Centire also reported a 20% year over year increase in attacks against the legal sector, with identity based threats making up more than half of all incidents. Other common tactics included click fix phishing lures that exploit filing deadlines, abuse of Microsoft Teams and malware such as NetSupport, Manager, RAT and Lumastealer. The report recommends phishing resistant authentication including Fido 2 security keys and passkeys, stronger conditional access policies and improved monitoring of identity systems to detect suspicious session activity. Finland's national grid operator Fingrid will disconnect a fiber optic telecommunications link to Russia when its lease expires at the end of the year, removing another remaining piece of cross border infrastructure following the end of electricity trading in 2022. The fiber connection was part of the former electricity transmission network between the two countries, which has since been dismantled. Fingrid said the impact on telecommunications connectivity is expected to be minimal, although Russian media reported operators are seeking alternative routes. The move comes as relations between Finland and Russia remain strained following Russia's invasion of Ukraine and Finland's accession to NATO. Finnish authorities have also warned of ongoing Russian influence operations and threats targeting critical infrastructure, including telecommunications networks. Coming up after the break, my conversation with Jan Shoshetazvili, associate professor at Arizona State University. He's previewing his Black Hat 2026 keynote and AI scammers may deserve a promotion. Stay with us. Janetevili is associate professor at Arizona State University. I caught up with him for a preview of his Black Hat 2026 keynote. Vulnerability research in the Agentic Age so
B
my lab has been doing vulnerability research for a very long time. I've been in that space since my graduate studies and I started my graduate studies in 2010. And basically ever since then I've been analyzing different types of systems at very deep levels for vulnerabilities. During this I created along with my colleagues the Anger Binary analysis Framework, a lot of other techniques and approaches to find bugs in software, to understand bugs in software, to remediate bugs in software. We've just been pushing the envelope for a long time. So along comes this new technology which is LLM inference for bug hunting. And you know, in about 2023, the first kind of rumbles of hey, this is actually pretty interestingly useful come along. And it's just accelerated since then, right? So now both in our research capacity and in actual, you know, security competitions, ODA competitions like the Style of Ponto and so on, we are very, very much everywhere using agentic security analysis to augment, sometimes supersede, but mostly augment our existing work. So I figured a lot of experience from my vantage point that I can draw on because, you know, as a faculty researcher, I work with dozens of students and other researchers in the space. There's a lot of lessons learned that we've taken away from a lot of different projects and it'd be cool to spread those lessons to the community.
A
Well, before we dig into the details of your presentation, help me understand how vulnerability research has been considered in the past. To what degree was it thought of as a technical capability. To what degree was it a craft or even an art form?
B
It's a great question because it's been considered all of these different things to different extents. When I started, it was 2010. I started as a graduate researcher, but of course I was into security before that in the CTF scene and so on to find bugs in software. When I started, you could rely on these static analyzers with high false positives, unclear usability. You could dig into the very, very early days of dynamic analysis with sending random inputs, hoping for the best, or generating file formats, hoping for the best, hoping to observe security flaws in an application. But really the majority of bug hunting back then was manual. You would stare at this software and you would understand it. And that was very much a kind of person against software. Like almost martial art. In fact, inspired by that sort of feeling of vulnerability research as a martial art in the early days, created a whole like martial art and security training with my Pone college platform that really it was inspired by this feeling like this is an art form. And then gradually this art form became a science as new technology came up. I would say the biggest one that created in my view, really a very well defined practice of this is kind of the science. The specific techniques would be the rise of very standardized fuzzers like American Fuzzy Lopez. There were some before that and a lot of rows right at the same time. But around the time of DARPA's Cyber Grand Challenge competition, the world of fuzzing kind of exploded. And now you have very well defined, like, hey, if you want to analyze this type of software, well, this is what you do. You set up this fuzzer, you add these types of seeds, you configure this type of sanitization, this type of code coverage. And it became much more step by step kind of science, let's say, than more vague art. There's still space for the art. So there's this merger of both, right? As people built up understanding of the software that they were analyzing, they could really dig in much more cleverly. There's a lot of space for this human expertise and intuition. There was a huge equalization. You could really, without knowing much about reverse engineering and so on, start finding bugs in real software. And we saw a huge increase in the number of vulnerabilities identified and disclosed and so on in that time. That era, I would claim is ending now, where hacker with a fuzzer is starting to be out competed by hackers wielding AI agents that are wielding fuzzers. And now in this newly kind of discovered area, we're in the art and invention phase of this, but it's going to resettle into its own very well regimented. This is how you analyze software in the modern day as well.
A
Does the person who has the background in vulnerability research, the person who in the previous world was a gifted artist, do they still have an advantage using the agentic tools?
B
Absolutely. Especially in this phase. I'm going to say something that can probably be, can certainly be criticized and I would probably call people out if they said stuff like this, but you know, in March, Anthropic released a sneak peek into Mythos right there. Super cyber capable model with a lot of fanfare. And this is how many bugs Mythos finds in this target. This is how many bugs Mythos finds in this target, and so on. And we were already also, of course, as was much of the rest of the world, doing agentic driven vulnerability research. And we look at these numbers, as did a lot of other people, and said, well wait, we're getting similar numbers without Mythos now. The difference of course, is the amount of kind of human expertise. Target specific expertise really seed not seeds in the traditional fuzzing sense of inputs into a program, test cases to drive different behavior, but seeds as in insights. Different insights given to the models and the agentic pipelines that enabled capabilities that seem well beyond the base capabilities and models. I have friends that achieve, quote, Mythos like results with open models. We've achieved in many different projects called Mythos, like results with frontier models and so on. The differentiator there is that human insight, human intuition. For now, it's unclear if that will remain. I don't see it fully going away anytime really soon. You're seeing a bit of a schism with hackers actually, and how they approach this. I'm very active in the competitive capture the flag community. I ran DEFCON CTF for a couple years. I've been a core member of Shellfish for like way too long Now, I think 17 years now. That's terrifying. So I've seen a lot of different trends in the CTF community. When we came out with the anchor binary analysis framework, I mentioned it Minorly compared to LLMs. Minorly in a minor way. Revolutionized the reverse engineering, capture the flag category. But, you know, and when decompilers came out and got good, they revolutionized the, you know, also reverse engineering and the, and the exploitation category, the binary exploitation category of CTFs as well as revolutionizing reverse engineering in the real world in ctf. What you saw what I saw because I have been in CTF for that long with the rise of decompilers is there were hackers that refused to adopt them that really liked looking at assembly instructions instead of pseudocode. And some of the best of them could keep up for a while, but if you didn't adopt the latest tools, you were eventually kind of forced to basically announce your retirement. And we're seeing that right now in the Capture the Flag community. All of these hackers are retiring because to them what they really loved about Capture the Flag, about that sort of applied high stakes security, is being kind of eaten away by the agents doing the nitty gritty like that they really loved to do. We're also seeing top CTF teams with the remaining players adapt to the modern paradigm because if you look at the scoreboard of the top CTFs of, for example, Defcon CTF qualifiers, there's a quick competition with bespoke software. So it's not fully representative of the real world, but there's a window to the real world at it. You see the top teams remain the top teams because they really invest in understanding how to have the human value add, how to properly harness the modern technology with agents and security analysis by agents to use their human expertise to improve over the purely agent expertise. And what I see, although less of this happens in the open outside of the CTF community, I see the same thing outside of the CTF community. I see the same thing in our research labs, I see the same thing in our spinoff companies. I see the same space for human ingenuity and insights and expertise to still be very, very, very valuable.
A
There is more to my conversation with Jan, more than we could fit in today's episode. So we'll be running a special edition of our conversation on Sunday. You can look for that in your Cyberwire daily feed. If you're heading to Black Hat USA this year, make plans to visit the Spectrops Kennel Club. As creators of Bloodhound, the Spectrops team will host talks with OpenAI and the UK AI Security Institute as well as hands on workshops aimed at helping you understand AI accelerated attack paths and the latest in identity tradecraft. Visit Spectrops IO to pre register and learn more. Spectrops Kennel Club is adjacent to Libertine Social inside Mandalay Bay. While you're there, visit the N2K CyberWire podcast studio where we'll be capturing expert perspectives and conversations from across Black Hat. And finally, artificial intelligence may soon be ready for a promotion from Scammer's assistant to scammer's co worker. A new study by researchers from four universities found that generative AI chatbots outperformed human scammers during the trust building phase of so called pig butchering scams where victims are gradually lured into fraudulent cryptocurrency investments. In a week long experiment, 46% of participants complied with an AI chatbots request to download an app compared with just 18% who followed a similar request from a human. Participants also reported higher levels of trust in the AI and sent most of their messages to the bot. Researchers say the findings suggest AI could automate much of the relationship building process, leaving humans to handle only the final investment pitch and potentially sidestep existing AI safeguards. While AI vendors say newer models include stronger anti fraud protections, researchers warn the industry could shift towards more autonomous scams, making operations harder to detect even if it means fewer scammers have to make awkward small talk for a living. And that's the Cyberwire. For links to all of today's stories, check out our daily briefing@thecyberwire.com be sure to check out this weekend's Research Saturday and my conversation with Marcus Hutchins, principal threat researcher at Expel. We're sharing their research, not very gentlemanly, analyzing a zero day exploit used by the gentleman ransomware to disable Target's EDRs. That's Research Saturday. Do check it out and hello, Maria
B
Ramaz is here on Sunday's T Minus Space Cyber Briefing.
A
My interview with Jen Sovada of Clarity about growing supply chain risks as the
B
space industry becomes increasingly globalized. That's Sunday on T Minus. Don't miss it.
A
We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire2k.com N2K's lead producers, Liz Stokes, were mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazes. Our executive producer is Jennifer Ibin. Peter Kilpe is our publisher and I'm Dave Bittner. Thanks for listening. We'll see you back here next week. Heading to Black Hat USA, the N2K CyberWire team will be on site recording from our podcast studio in the Spectrops Kennel Club. If you're interested in joining us for a conversation or learning more about what we're recording throughout the week. Stop by the studio and meet the N2K CyberWire team. Spectrops Kennel Club is adjacent to Libertine Social inside Mandalay Bay.
Date: July 31, 2026
Host: Dave Bittner, N2K Networks
Guest: Jan Shoshitaishvili, Associate Professor at Arizona State University
This episode delivers a packed roundup of cybersecurity news, from AI model mishaps to regulatory crackdowns and emerging threats. The central feature is an interview with prominent AI security researcher Jan Shoshitaishvili, previewing his Black Hat 2026 keynote on vulnerability research in the ‘agentic’ age of AI. The episode closes with a discussion of AI’s troubling new competence as an autonomous scammer.
Early Days: A Martial Art
Rise of Fuzzing & Automation
Current Era: AI Agents Changing the Game
Short Answer: Yes, Especially Now
Quote:
CTF (Capture the Flag) Community Trends
The teams and researchers who maximize synergy between human strategy and AI augmentation remain leaders. Open competitions reflect this hybrid future both in research and in industry.
Quote:
This episode provides a comprehensive scan of current cyber risk, focusing on the intersection of human expertise and accelerating automation in vulnerability research and cybercrime. AI’s growing role as both a tool and a threat underscores the importance of maintaining the “human value add” while preparing for a future of higher-stakes, agent-driven security challenges.
For further insights, listen to the special extended interview with Jan Shoshitaishvili in Sunday’s CyberWire Daily feed or check out Research Saturday for more deep-dive threat analysis.