Loading summary
A
You're listening to the Cyberwire Network powered by N2K.
B
AI is making phishing attacks faster, more convincing, and harder for people to spot, and traditional security awareness and phishing training weren't designed for this level of attack. HOX Hunt helps security teams prepare employees for the attacks they face every day with personalized phishing training that adapts to each employee and reduces risky behavior over time for IT and security leaders looking to strengthen their human layer of defense without adding more manual work. Visit hoxhunt.com cyberwire to learn more. That's H O x h u n t.com cyberwire. Cyber attacks hit US Water systems CISA tackles Open Source security China's surveillance machine is exposed Hotel WI fi gets a bit riskier Healthcare and police data Spill Online Fake SQLite vulnerabilities Fool Security databases we got your Monday business briefing. Our guest is Tim Starks from cyberscoop discussing the White House's quantum aspirations and AI is the hottest thing on campus. It's Monday, august 3rd, 2026. I'm dave bittner and this is your cyberwire intel brief. Thanks for joining us here today. Happy Monday. It's great to have you with us. Cyber attacks targeting US Water systems have expanded to at least seven states, with officials warning the campaign could be much broader. While no drinking water has been contaminated, hackers have targeted Internet connected industrial control systems used to manage water quality, chemical treatment and pressure. Minnesota first disclosed the activity and Michigan later confirmed attacks affecting multiple municipal systems, though officials said there were no public health impacts. Federal investigators consider Iran the leading suspect, citing an increase in Iranian cyber activity since the US And Israel's war with Iran began. But they stress the attribution remains preliminary and lacks definitive forensic proof. President Trump publicly disputed Iran's involvement, while state and federal officials continued to treat Iranian actors as the most likely source. CISA warned that water utilities of all sizes are at risk and urged operators to disconnect vulnerable controllers from the Internet. The incidents underscore longstanding concerns about the cybersecurity of aging resource constrained critical infrastructure. CISA has released new guidance to help federal agencies securely adopt, manage and contribute to open source software. The recommendations emphasize evaluating OSS before deployment, maintaining inventories of software components, tracking dependencies, monitoring for vulnerabilities, and applying patches promptly. CISA also encourages agencies to contribute security fixes and improvements back to the open source community or while ensuring sensitive information is not exposed. For software developed by federal agencies, CISA recommends planning for open source release where appropriate, following secure development practices and publishing supporting documentation and software bills of materials. The guidance also addresses open source AI, warning that artificial intelligence models lacking transparency into their training, data and development process should be treated as proprietary software with incomplete provenance and subjected to stricter risk management before deployment. A cybersecurity researcher uncovered an unsecured Chinese surveillance platform that appears to track thousands of foreigners in Zhangjiakou, revealing the breadth of China's monitoring capabilities beyond its own citizens. The database contained detailed personal information including passport data, phone numbers, travel records, camera sightings, hospital visits and social connections. It categorized individuals by nationality, religion and other attributes, including foreign journalists, students and residents from Hong Kong and Taiwan. Evidence reviewed by the New York Times suggests the platform was developed for the Zhang Xiakou Public Security Bureau by surveillance technology firm Origin Dynamic. Researchers said the exposed system highlights China's extensive integration of surveillance data and weak privacy safeguards with sensitive information left accessible online. Experts warned the incident reflects a broader expansion of China's surveillance infrastructure and the risks posed by poorly secured government systems. Microsoft is warning organizations to treat hotel, airport, conference and other public Wi fi networks as untrusted following the discovery of Captive Crunch, a global cyber campaign attributed to the Russian threat group Storm 2945, a subgroup of Midnight Blizzard, active since May. The campaign compromises hospitality network infrastructure to present fake login pages, software updates and verification prompts that steal credentials or install malware. In some cases, attackers abuse Microsoft's legitimate device code authentication process to gain account access without stealing passwords. Microsoft also found evidence that Android devices are being targeted with malicious app downloads. The company says the attackers used artificial intelligence to support the campaign. To reduce risk, Microsoft recommends using mobile hotspots or cellular connections instead of public Wi fi, avoiding software updates through captive portals, adopting phishing resistant authentication and disabling device code authentication where it is not needed. The timing is hard to miss. With Black Hat and DEFCON just getting underway, It's a fitting reminder that in Las Vegas, not every suspicious network is part of the conference agenda. Australian healthcare provider Partnered Health is investigating claims by the Cyber Extortion Group Inc. Ransom that it has stolen and published data from the organization's network. The group says 11 files containing personal information were posted on its Darknet leak site, though Partnered Health has obtained a court injunction restricting access to the data while investigators access its authenticity, which seems aspirational. The incident stems from a cyber attack disclosed in July that occurred on June 23, with additional patients and employees now believed to be affected. Partnered Health has notified impacted individuals and reported the incident to Australian authorities. Security experts warn the breach highlights the growing cyber risks facing healthcare organizations and advise patients to be vigilant for phishing attempts and fraudulent communications using potentially stolen personal information. Researchers at the University of New Haven have identified a high severity security vulnerability affecting DNA analysis software widely used in U.S. crime laboratories, potentially exposing digital forensic records dating back to 1995 to undetectable tampering. The flaw could allow an attacker with access to a lab's systems to alter DNA analysis files without leaving evidence of modification, raising concerns about the integrity of digital forensic evidence. Researchers demonstrated the attack using AI assisted code and publicly available decryption keys, though there is no evidence the vulnerability has been exploited in real cases after being notified. Thermo Fisher Scientific acknowledged the issue, worked with CISA and released a software update that adds digital signatures to help verify file integrity. Experts say the findings highlight the need for stronger cybersecurity protections and in forensic laboratories. Security researchers at JFrog say dozens of recently published SQLite vulnerability advisories appear to be fabricated, likely generated by large language models despite being assigned CVE identifiers and initially receiving high severity ratings from the National Vulnerability Database and other sources. After analyzing six reported SQLite flaws, researchers found the advisories referenced non existent functions, incorrect line numbers, invalid proof of concept exploits and fixes that never existed. None of the vulnerabilities appeared on SQLite's official advisory page and testing failed to reproduce the claimed issues. JFROG warns the incident exposes weaknesses in the current CVE ecosystem, where unverified submissions can propagate through vulnerability databases and automated security tools. The researchers recommend validating high impact CVEs against vendor advisories, source code and reproducible exploits before prioritizing remediation, particularly as AI generated content becomes more prevalent. A CyberAttack in the UK's Police National Legal Database has exposed the names and contact details of roughly 100,000 police officers on the dark web, raising serious safety concerns for law enforcement personnel. Authorities believe the hacking group Exfil Squad was responsible as part of a broader campaign targeting UK government agencies including the Ministry of Defense, Home Office, National Crime Agency and Crown Prosecution Service. The breach follows a separate attack on the Department for Education that exposed more than half a million records. Affected officers say the leak increases personal security risks, particularly for those involved in organized crime investigations. Turning to our Monday business briefing, cybersecurity and AI companies announced a wave of funding and acquisition activity this past week, led by ThreatLocker's $190 million Series F to expand its Zero Trust platform. Other notable funding rounds included ACT Security, with $60 million. Aegis AI at 36 million, Harmony AI with 34 million, Hush Security with 30 million, Abstract with 25 million, copysight with 3 million and Franos with $1.5 million with investment focused on cloud security, identity management, AI powered security operations and enterprise automation. On the mergers and acquisitions front, Ciera agreed to acquire identity security startup Oasis Security for $1 billion to combine data and identity protection. Leonardo DRS announced a $450 million acquisition of Mission software provider Raft, while Keyfactor plans to acquire UK based identity security firm Cofide to strengthen AI trust infrastructure. Vena Solutions also announced plans to acquire enterprise AI platform Morphio AI to enhance its AI capabilities. Be sure to check out our business briefing on our website that is part of Cyberwire Pro. Coming up after the break, Tim Starks from cyberscoop discusses the White House's quantum aspirations and AI is the hottest thing on campus. Stay with us. What's the one thing in business that's spreading as fast as AI? AI risk. Every new tool your team signs up for, every vendor that turns on AI features, every new integration, each one is another opportunity for something to go wrong. And most security programs weren't built to keep up with AI's pace of growth. Enter Vanta. Vanta is the number one agentic trust platform trusted by more than 16,000 fast moving companies like Ramp, Purser and Harvey to help them stay audit ready. And now Vanta helps companies like yours keep an eye on the risks that appear between audits across your vendors, your AI tools and your entire environment. The Vanta agent works like a 24.7grc engineer. In the background it finds, issues, drafts, fixes for you and can cut vendor assessment time by up to 50%. Whether you're a fast growing startup or a global enterprise or Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today@vanta.com cyber that's V A N T A dot com cyber. It is my pleasure to welcome back to the show Tim Starks. He is a senior reporter at cyberscoop. Tim, welcome back.
A
Hey, good to be back.
B
Looking at this recent article you wrote for cyberscoop, this is about the supply chain challenges that may loom large in the quantum race according to some folks from the White House. What's going on here Tim?
A
Yeah, we, we got some rare comments from someone we haven't heard much from publicly named Brad Blakestad. He's the director of the National Quantum Coordination Office that is housed within the White House Office of Science and technology Policy, if you're following me. That's a long title. But the idea is he's someone who was supposed to coordinate all of the quantum efforts that are happening on cyber. And he talked about some of the big challenges for dealing with all the things that are happening on Quantum for cyber listeners or readers. Obviously, the issue of quantum computing looms large. But one of the things he said that jumped out at us was talking about how the supply chain is one of the biggest challenges here.
B
How so?
A
What he was saying was, you know, there's no easy way to do quantum all in one place. So there's not like one single hardware platform for, you know, there's, there's, there's different technologies for quantum computing, for quantum sensing. They're all completely different. You have people who make these different components over here for this kind of quantum, for this other kind of quantum, and it. And it ends up being so diffuse that it's hard to bring it all together and make it so that you're building everything in a unified way. You know, specifically there was the issue he was discussing about that there's not just this diffuseness, but there's also just not a lot of it at all. That you have not enough quite economic demand yet or marketplace dynamics to make it so that people want to be getting into manufacturing widgets, quantum widgets, let's call them quidgets. Every time I talk about this subject, I think of it might have been a Rick and Morty episode where they're like, you can't just call something quantum and assume that that makes it science fiction now. Right. We're quantum in front of everything. But I'm kind of doing it in this conversation anyway. He's saying, you know, that there's not this kind of base that we have for other kinds of things that, you know, the supply chain that can really reliably start producing things. And that, that's the, that's one of the really biggest fundamental challenges he's, he's facing and that they're trying to address in this administration. They've had a couple executive orders on quantum in June. It was interesting to hear from him on this and how they're trying to get to the very fundamental building blocks of, of quantum and trying to make sure that, that it can be a thing that gets going at all.
B
Yeah. I'm curious, you know, you mentioned the funding issue. Isn't that just the kind of thing that a federal government should be able to fund, that sort of pure research to get us across the Finish line.
A
Conceivably, yes. It's something that. That the federal government could be doing. And he did mention one kind of role where the government could do that, where they can say, we'd like you to make the. He literally used the word widgets. So I'm not. When I used it earlier, I was not being facetious. Make these things to our specifications and we will buy them. And so that could be a way that that could happen. He did talk about funding limitations. You know, this administration has downsized federal government funding significantly in lots of ways, in lots of places. He mentioned the ideas of things like price challenges and other ways to kind of incentivize the market to get going.
B
Was there any kind of call to action from him for industry? Hmm.
A
Was there? No, not really. I would say not really. It wasn't that he was, you know, saying that they shouldn't do anything, but he wasn't saying, here's a list of things we want you to do.
B
Yeah, more of a State of the Union kind of address, perhaps.
A
Yeah, it was really meant more to be like, these are the things we are looking to do. You know, he talked about trying to do things to make it so. Just if anything, the closest he might have come to that is saying the US Needs to own this issue, if you will. One of the things that there has been a discussion about out there in the sort of think tank community and people who research this stuff is that the supply chain is not just a U.S. diffusion problem. It's an international diffusion problem that we're relying on parts from China, from Iran, and. And it's not like there's one or one country that's dominating this. And I think if there was one kind of call, it was like, the US Needs to dominate this. We need to be such that we're the. The place where this all starts, that this is the foundation of it all, and this is where other countries turn to us. So I think that would be the closest thing to a call. Call to industry. He really. He really was kind of giving an overarching view of what the administration is working on, on this and talking about what makes it a challenge. Among the things were supply chain, but, you know, talking about encryption. Of course, one of the things that was fascinating about the speech as well to me that I didn't mention in the story is that I think when I, as a reporter who covers cyber, think about quantum computing, I think about encryption, I think about breaking encryption. He was talking about that as important and meaningful. But also he said Candidly, we're more enthused about the economic impacts of quantum computing and other quantum technologies. That that's where they're focused on, on the economic gains of this. Less. Less so the national security risks. Not that he was saying that it didn't exist, but that he was. That was a point of emphasis for
B
the administration, that being the leader in that realm could be of great advantage to the US Economically.
A
Not just that, but also that the technological advances that could be unlocked by quantum could be something that we see with things like being able to break down things from, like being able to approach pharmaceuticals, other kinds of industries and use the advances of quantum technology to really push forward the technology in other areas.
B
I see. Well, watching his presentation was your sense that it was one of optimism?
A
Yes, it was. I would say, obviously, a lot of people who are in this administration talk up the president and what he's doing is unique here. I think this might be a case where that's the case. I mean, certainly quantum technology has been an emphasis for other administrations, but I don't know that we've seen this kind of high level attention from it. And I think that that is something that he was optimistic about from the standpoint of saying, look, this is something we're really focusing on. This is something we really want to do. And I think that, you know, some. Some credit is due to the administration for making that a big point of emphasis.
B
Yeah. All right. Well, Tim Starks is senior reporter at cyberscoop. Tim, thanks so much for taking the time for us. Thank. You. And finally, artificial intelligence is reshaping higher education in unexpected ways. As demand for traditional computer science degrees cools and entry level coding jobs face pressure from AI. Colleges are finding growing interest from students who never planned to study computer science in the first place. Psychology majors, musicians, biologists, and business students are adding AI minors, certificates and courses to build what universities increasingly view as a fundamental workplace skill. Schools are responding with AI literacy requirements, new interdisciplinary programs, and faster course development, reflecting the technology's rapid evolution. Educators argue that understanding AI is becoming as essential as reading or basic math, even as they caution against overreliance on the technology. The irony is hard to miss. AI may be writing some code that once justified a computer science degree, but it's also convincing students across nearly every other discipline that they need to learn enough about it to keep up. And that's the Cyberwire. For links to all of today's stories, check out our daily briefing@thecyberwire.com we're recording on site at Black Hat this Wednesday and Thursday from our podcast studio in the Spectre Ops Kennel Club. If you'd like to meet the N2K CyberWire team, make sure you stop by the studio. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead and the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire2k.com N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Heltzman. Our contributing host is Maria Vermazes. Our executive producer is Jennifer Ib. Peter Kilpe is our publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow.
Episode Title: Water you waiting for?
Date: August 3, 2026
Host: Dave Bittner (N2K Networks)
Featured Guest: Tim Starks (Senior Reporter, CyberScoop)
Main Theme: Comprehensive rundown of the latest cybersecurity news, with a specialized focus on attacks against U.S. water systems, supply chain challenges in the quantum computing sector, and how AI is transforming academia and the workplace.
This episode examines a surge of cyberattacks on U.S. water systems and the broader risks to critical infrastructure. The show also dives into recent cybersecurity developments relating to Open Source software, public Wi-Fi, high-profile data breaches, and fabricated vulnerability advisories. The featured interview with Tim Starks explores the U.S. government's quantum aspirations and the infrastructural and economic challenges faced in the quantum “race.” The episode concludes with how the proliferation of AI is reshaping university programs and job expectations.
[00:52 – 03:15]
"Federal investigators consider Iran the leading suspect...but they stress the attribution remains preliminary and lacks definitive forensic proof." – Dave Bittner ([01:42])
[03:16 – 04:30]
[04:31 – 05:35]
"Researchers said the exposed system highlights China’s extensive integration of surveillance data and weak privacy safeguards..." – Dave Bittner ([05:15])
[05:36 – 06:44]
"Microsoft recommends using mobile hotspots or cellular connections instead of public Wi-fi, avoiding software updates through captive portals, adopting phishing resistant authentication and disabling device code authentication where it is not needed." – Dave Bittner ([06:26])
[06:45 – 08:25]
[08:26 – 09:35]
"JFROG warns the incident exposes weaknesses in the current CVE ecosystem, where unverified submissions can propagate through vulnerability databases and automated security tools." – Dave Bittner ([09:16])
[09:36 – 11:19]
[15:05 – 21:58]
Timestamps: [15:05 – 21:58]
"There's no easy way to do quantum all in one place.... It ends up being so diffuse that it's hard to bring it all together and make it so that you're building everything in a unified way." – Tim Starks ([16:15])
"He literally used the word widgets...Make these things to our specifications and we will buy them." – Tim Starks ([18:13])
"We’re more enthused about the economic impacts of quantum computing and other quantum technologies. Less so the national security risks." – Tim Starks ([20:35])
"This is something we’re really focusing on. This is something we really want to do." – Tim Starks ([21:26])
[21:59 – End]
"AI may be writing some code that once justified a computer science degree, but it’s also convincing students across nearly every other discipline that they need to learn enough about it to keep up." – Dave Bittner ([22:48])
On Water Attacks:
"CISA warned that water utilities of all sizes are at risk and urged operators to disconnect vulnerable controllers from the Internet." – Dave Bittner ([02:01])
On the Quantum Supply Chain:
"It’s just not a lot of it at all. Not enough quite economic demand yet...That’s one of the really biggest fundamental challenges..." – Tim Starks ([16:55])
On AI in Education:
"Educators argue that understanding AI is becoming as essential as reading or basic math, even as they caution against overreliance on the technology." – Dave Bittner ([22:36])
This episode serves as a clear, up-to-the-minute snapshot of the most pressing cybersecurity news, combining practical guidance, industry developments, and expert analysis on quantum tech and AI’s evolving impact on society.