Loading summary
A
You're listening to the Cyberwire Network, powered by N2K.
B
What's the one thing in business that's spreading as fast as AI? AI risk Every new tool your team signs up for, every vendor that turns on AI features, every new integration each one is another opportunity for something to go wrong. And most security programs weren't built to keep up with AI's pace of growth. Enter Vanta. Vanta is the number one agentic trust platform trusted by more than 16,000 fast moving companies like Ramp, Purser and Harvey to help them stay audit ready. And now Vanta helps companies like yours keep an eye on the risks that appear between audits across your vendors, your AI tools and your entire environment. The Vanta Agent works like a 24.7grc engineer. In the background it finds, issues, drafts, fixes for you and can cut vendor assessment time by up to 50%. Whether you're a fast growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today@vanta.com cyber that's V A N T A dot com cyber.
A
Laundry Bear snuffles through unpatched Zimbra collaboration servers. The State Department puts visa restrictions on cybercriminals. Oracle drops a record 1449 security patches. Researchers disclose a critical vulnerability in OpenAI's ChatGPT workspace agents. A new benchmark evaluates Frontier AI model malware reverse engineering. Lunch Poke uses the Notepad application to establish persistence. A Swiss rail manufacturer refuses to pay the ransom and the AI goes to space. Today is Friday, July 24, 2026. I'm Maria Varmazes in for Dave Bittner today and this is your Cyber Wire Intel Briefing. Happy Friday everybody and thank you for joining me. Let's dive into it. First up, CISA is warning that the Russian state sponsored group Laundry Bear, also known as Void Blizzard, is targeting organizations using unpatched Zimbra collaboration servers. The attackers exploit CVE2025 666376 which is a cross site scripting vulnerability that allows malicious JavaScript embedded in HTML emails to execute automatically when the messages are viewed and enabling theft of emails, credentials, address books and two factor authentication tokens. The campaign also creates Zimbra application passcodes to maintain access while bypassing multi factor authentication. Stolen data is exfiltrated over DNS and HTTPs and the group also uses adversary in the middle phishing sites that impersonate Zimbra login portals. CISA urges organizations to patch Zimbra review indicators of compromise and investigate suspicious authentication activity, revoke unauthorized application passcodes and adopt phishing resistant multi factor authentication where possible. The State Department has announced new visa restrictions targeting individuals involved in foreign cybercrime networks along with their immediate family members. Secretary of State Marco Rubio unveiled the policy during a visit to Southeast Asia, where industrial scale scam centers have become a major regional concern. The restrictions apply to people responsible for or complicit in cyber enabled crimes, including online scams and sextortion scams, and build on President Trump's executive order aimed at combating cybercrime and fraud. Rubio said that many of these operations are tied to Chinese transnational criminal groups engaged in human trafficking, money laundering and financial scams that cost Americans an estimated $10 billion in 2024. The administration says the new policy is intended to deter cybercriminals by limiting their ability to travel to the United States. Oracle has released a record 1,449 security patches as part of its quarterly Critical Patch update, reflecting both the company's extensive product portfolio and its increased use of artificial intelligence for vulnerability discovery. Security experts say that the volume is less an indication of poor code quality than a growing trend toward AI assisted bug hunting, which is also driving larger patch releases across the industry. Oracle recently introduced monthly critical security patch updates to deliver fixes for the most urgent vulnerabilities between its quarterly releases. Among the highest priority flaws are several critical vulnerabilities affecting Oracle Fusion middleware and Oracle Database Server, and including bugs that could allow unauthenticated system compromise or remote code execution. Experts urge organizations to prioritize patching and use automated patch management tools where possible. Security researchers at Zenity Labs disclosed a now patched critical vulnerability in OpenAI's ChatGPT workspace agents dubbed Agent Forger that could have allowed attackers to create and remotely control invisible AI agents inside an organization's ChatGPT workspace. The attack relied on phishing a logged in user into clicking a specially crafted URL that abused the agent builder's initialization process to automatically create an autonomous agent with attacker defined instructions. If the victim already had authorized connectors such as Gmail or Outlook, the agent could execute commands delivered by email, access sensitive data, impersonate users, and perform other actions without additional authorization prompts. Zenity reported the issue to OpenAI, which acknowledged the vulnerability and deployed a fix within three days, preventing further exploitation of this flaw. SentinelOne has introduced a new benchmark to evaluate how well frontier AI models handle long term malware reverse engineering. Using its investigation of the Fast 16 malware as a real world test case. Rather than measuring isolated tasks, the benchmark assesses whether models can adapt as new evidence over overturns earlier conclusions. Among the models tested, GPT 5.6 SOL was the only one to successfully complete all eight investigation stages. Researchers found that while other models demonstrated strong technical analysis, they struggled to recover from incorrect assumptions. Sentinel 1 concluded that human reverse engineers remain essential as even the best performing model made significant errors and still required expert oversight. Score another one for the humans. Ukraine's CERT has identified a campaign by the UAC0099 threat group that uses the legitimate Notepad application alongside a malicious plugin called Lunchpoke to establish persistence on compromised systems. The attack begins with a phishing delivered VBS script that downloads an archive containing Notepad, a malicious DLL disguised as a plugin, and additional malware components. When Notepad launches, it loads the malicious plugin, which creates scheduled tasks, extracts additional payloads, and deploys the Bernie Bear and Matchboil version 2 malware loaders. Cert UA attributes the activity to UAC0099, which is a group previously linked to providing initial access for Sandworm operations. Administrators are advised to update Notepad, Winrar and 7zip to current versions and monitor for suspicious scheduled tasks and malicious plugin activity. Swiss rail manufacturer Staedtler Rail says it will not pay a 10 million Swiss franc or about US$12.3 million ransom after the Everest ransomware group stole technical documents from a supplier's file sharing platform. The company said that the breach resulted from compromised supplier credentials and did not affect Stadler's own systems operations or customer data production remains unaffected and there has been no impact on trains in service. Stadler has filed a criminal complaint and says it will not negotiate with the attackers. This marks the company's second public extortion attempt in recent years following a similar incident in 2020. Security experts note that paying ransoms often fails to end extortion, with many organizations later facing additional demands from the same attackers. In fact, a new Proofpoint survey of 953 organizations found that more than one third of companies that paid a ransomware demand were later targeted with a second extortion attempt. The findings reinforce long standing guidance from governments and cybersecurity experts that paying a ransom does not guarantee stolen data will be deleted or that the attacks will end. Researchers say that ransomware groups increasingly rely on repeated extortion, often retaining stolen data even after payment. Recent incidents, including breaches at Clue and Change Healthcare, illustrate how victims can remain Vulnerable despite paying. And that all underscores the risks of negotiating with cybercriminals. After the break, we're doing one of my favorite things and bending the space time continuum just a little bit. And before Dave Bittner left for the day, he turned the tables and interviewed me about why space cybersecurity deserves more attention. I'm a little biased, but it's a good conversation. So, yeah. And the AI goes to space. Stay with us. Now, normally, everybody, this is where host Dave Bittner would introduce his interview for the day. But since I'm filling in for him today, well, I'll just introduce myself. It's me, Maria Varmazes. And before Dave Bittner left, he sat down with me to talk about why space cybersecurity deserves more attention. Here's our conversation. All right. Well, Dave, it's great to speak to you today. Thanks for coming back on. Yeah, it's great your show.
B
And on my way out the door today, we were able to squeeze in one last conversation here. So I appreciate you taking the time as I had to be away for the main part of the show today, but I want to take today and just sort of get an update from you of some of the goings on with the T Minus podcast, which has really evolved over the past several months into a whole new thing. And it's pretty exciting. What do you got going on over there, Maria?
A
Well, Dave, we relaunched T minus what, in mid May, I want to say May 17, if I'm being really pedantic. And we went from a daily space news show and evolved into a space cyber briefing that's now weekly. And so in my mind, we've sort of camera wise tightened the focus, really, really gone laser focused with the show. And when we first made this change, I was wondering, are we gonna have a lot to talk about? Are we gonna get people who are interested in the show? And I'm so relieved and thrilled that it's been far more successful than my wildest dreams could have predicted, which has been just awesome. Like, the feedback's been great. We've been getting so many awesome guests and the conversations have been really fascinating. I've been learning a ton. And yes, there is more than enough going on in this niche of space cyber that, yes, we have plenty to talk about every week, which has been really thrilling. So, yeah, I'm here kind of going, woo, yeah.
B
Give us some of the backstory, though. What prompted the shift to focusing on the cyber side of space?
A
Well, it had been a good three years of covering the show of covering the space industry as a daily show. And there was an element going on throughout a lot of my conversations that I was noticing that the space cyber world was quickly evolving to meet the moment that it was in. But it still felt like it was a very baby little space. There were a lot of major players in it, but it wasn't being talked about as much as I would have expected, given the importance of what's going on there. You've got the confluence of space is not technically considered critical infrastructure, but it sort of is anyway. We are increasingly interdependent on space based systems. We've seen space based systems becoming disabled through cyber attacks in the geopolitical sphere in like the war in Ukraine, for example. It's. It's very important. And the importance of space cyber is only getting more and more great. And I'm hearing it all the time from not just people that I interview, but just around the world and again in the geopolitical sphere, in the military sphere, in the commercial sphere. So the drumbeat was getting louder for the last few years. And in my conversations with people who are in that world, I think the question for me was coming up more and more again, why aren't people talking about this more? It's so important. And then the answer eventually came, well, we should talk about it more. If nobody's talking about it, we should do that.
B
That's a solution.
A
Yeah. It's like I'll make my own podcast with Blackjack and you know, that's the Futurama quote I'll just abridge. But yeah, we just figured we're gonna do it and so we're doing it and it's been awesome.
B
Well, tell me about it. What is the format of the show?
A
The format of the show is a weekly sort of news magazine. We are every Sunday. So we're the Cyberwire Sunday show. And that's where we take about a half an hour and focus on a space cyber topic, whether it is an interview with an expert guest or I'm having a conversation with my producer Ethan Cook, and we're chit chatting about a more evergreen topic in the space cyber realm. One of our earlier episodes was about why GPS is so important to the global economy and why attacks against GPS are frankly really catastrophic. This is something that has been known in the military world for decades. But I think the importance of gps, for example, has been widely underappreciated in the broader world in terms of its importance outside of mere navigation. And we really just went into the weeds with this. And that's, that's what I really enjoy about it, is that we can get real deep into the weeds on these real nerdy space cyber conversations in a way that we couldn't do before. And it's been a journey of discovery, but I've been really enjoying it. And our latest conversation that Ethy and I have been doing with our second part coming out this Sunday actually is on European space sovereignty, which has been very politics wonky and it's just been really interesting. Yeah.
B
What's been the shift like for you switching from the cadence of a daily to a weekly?
A
I mean, you know what it's like to run a daily show, Dave?
B
I do.
A
That is a real intense schedule.
B
It's a marathon, not a sprint.
A
Truly. Truly it is. So the pace has slowed down for me, but it's been a lot more deliberate. We're able to be able to a lot more careful and choosy about the kind of topics that we're going to cover. We're not just trying to follow. And not that this is a bad thing, we're not just following the news, but we're going what's really interesting to me, what's really interesting to us right now and how can we go really deep on that? So for example, the space sovereignty discussion that we've been having the last two weeks, we touch on my trip to NATO and the NATO cyber headquarters in December that I did, which is not something I think we would normally bring up on the Daily Show. And the whole reason that we're talking about it is I had been noticing in some of the news stories that I'd been reading that a lot has been coming up about the EU Space law and EU Space act and a lot of legislation in the EU specifically. And I just got really curious about it and I wanted to know more about it. And I said, Ethan, why don't you. And I just kind of go real deep on the research for this, spend some time. I think we spend like a solid month just pouring over a lot of this and that helped brief our discussion and it ended up being like hours that we ended up having to trim down into a two episode two parter. But it's a different animal going from a daily show where we're trying to get things out the door and be timely to a weekly magazine approach where we're trying to go really deep on a subject. And that's been quite a shift for me personally, but it's different and I enjoy it.
B
Well, good for you. I mean it is absolutely good stuff. It just strikes me that there is a ton of crossover between cyber nerds and space nerds. Right. That chart overlaps.
A
Yeah. The Venn diagram is practically a circle. Yeah. And there are a lot of cyber folks who are just interested in space just as a curiosity. And that's great. And I think that's a lot of people who listen to the show. And there's an increasing cohort of cyber professionals who want to be in the space industry for a career. It's been really interesting hearing from those folks. And admittedly that is definitely a niche of a niche. But I think the thing that if there's one thing people will get out of this show who are just plain old cyber folks, space is coming for you. Space is coming in your job. Whether or not you're going to be in the space world. Space is coming to you. Space systems are coming to the world of networking if they're not already in it, you know, so it's something that is gonna be part of your realm. Even if it's not gonna be your specialization, it's gonna be in the goo of what you do. So it's something worth maybe having on the back burner as some knowledge for you to have. And that's sort of. That's maybe not a very compelling pitch, but that's the pitch I give people.
B
I think also, you know, if you're a Cyberwire Daily listener, I can see how taking on another daily when T minus was a daily might be a bit much, but now that it's a weekly, so it's a lot easier to fit into your listening schedule.
A
Yeah, we're your Sunday show, so you don't have to listen to us on Sunday, but you know, we're on your Sunday rotation and we try not to overwhelm and we go real deep on a topic per episode. So it's not lots of things. It's one thing. And feel free to pick and choose which episodes are interesting to you. They're not always gonna be. If you listen to it this week but miss it next week, it won't make sense. They tend to be more timeless. So I hope that helps with the digest. Cause the funny thing about space is that even though it is such a cutting edge field, it actually moves kind of slow, which is funny. The cyber world moves a lot more quickly, relatively speaking. So you can slow down a little bit with space stuff and learn about the landscape there and you can catch up and you won't be behind. So.
B
All right, well, thank you for having me here to discuss this. Thank you for having me be a guest on my own show.
A
Well, thanks for taking the time before you head out to chat with me about what I've been up to. I appreciate it, Dave.
B
All right, we'll see you soon. See you soon.
A
If you enjoyed that conversation that Dave and I just had, and if you want to hear Part one of the Space Sovereignty conversation on T minus that aired last week, just check out today's show notes for more links. Foreign.
B
Is making phishing attacks faster, more convincing, and harder for people to spot, and traditional security awareness and phishing training weren't designed for this level of attack. HOX Hunt helps security teams prepare employees for the attacks they face every day with personalized phishing training that adapts to each employee and reduces risky behavior over time for IT and security leaders looking to strengthen their human layer of defense without adding more manual work. Visit hoxhunt.com cyberwire to learn more. That's H O X H-U-N-T.com cyberwire.
A
And finally today, NASA's Jet Propulsion Laboratory has demonstrated that artificial intelligence doesn't need a warehouse full of GPUs to earn its place in orbit. Researchers successfully ran Google's lightweight Gemma 3 language model aboard Loft Orbital's Yam 9 satellite, where it analyzed images captured in space and answered natural language questions about what it saw. The Navi Orbital system lets you scientists guide image analysis with simple prompts instead of complex spacecraft commands, which is a shift that could make satellites far easier to operate. That'd be nice. And beyond convenience, Onboard AI could overcome bandwidth limitations by sending concise text summaries instead of massive gigs of image files, speeding applications like wildfire detection. But for now, the model is safely isolated from flight control, so no chatbot is flying the spacecraft just yet. Still, this demonstration does suggest that future satellites, and perhaps maybe even astronauts, could someday have an AI companion that's just ready to help rather than simply admiring the view. And that is the CyberWire. For links to all of today's stories, check out our daily briefing@the cyberwire.com this week on Research Saturday, Dave Bittner sits down with Andrej Kovovic, security awareness specialist from eset, as they discuss their research on frosty Neighbor, fresh Mischief, and digital shenanigans. That's Research Saturday. Check it out. That's the Cyberwire Daily, brought to you by N2K CyberWire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that can keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire2k.com N2K's lead producer is Liz Stokes, we're mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our executive producer is Jennifer Ibin, Peter Kilpe is our publisher, and I'm Maria Varmazis in for host Dave Vitner today. Thanks for listening and have a wonderful weekend.
B
Foreign. The N2K CyberWire team will be on site recording from our podcast studio in the Spectrops Kennel Club. If you're interested in joining us for a conversation or learning more about what we're recording throughout the week, stop by the studio and meet the N2K CyberWire team. Spectrops Kennel Club is adjacent to Libertine Social inside Mandalay Bay.
Episode Title: Laundry Bear gets the spin cycle
Host: Maria Varmazes (in for Dave Bittner)
Network: N2K Networks
Podcast Theme: The latest cybersecurity news, analysis, and industry expert interviews. This episode features an in-depth look at current cyber threats, a spotlight on the “T-Minus” podcast’s focus on space cybersecurity, and notable security research developments.
The episode centers around critical recent cyber threats and research, highlights the ongoing evolution of ransomware and state-backed campaigns, and features a special segment on the importance of cybersecurity in the space sector.
[01:39–03:00]
[03:00–04:15]
[04:15–05:00]
[05:00–05:55]
[05:55–06:42]
[06:42–07:44]
[07:44–09:00]
[08:40–09:20]
[11:41–20:41]
[22:03–23:30]
| Segment | Timestamp | |-------------------------------------------------------------|---------------| | Headline Roundup (incl. Zimbra, State Dept, Oracle) | 01:39–09:20 | | Special Interview: Space Cybersecurity/T-Minus Podcast | 11:41–20:41 | | NASA Deploys AI Model on Satellite | 22:03–23:30 |
This episode gave listeners a comprehensive update on urgent cyber threats, including fresh nation-state campaigns and the stubborn reality of ransomware extortion. The featured interview delivered insights into the growing relevance of cybersecurity in the space sector, forecasting that space systems will become an integral aspect of future cyber operations—a must-listen for both “cyber nerds” and “space nerds” alike.
Listeners are encouraged to check out the T-Minus podcast for more on space cyber issues, and review detailed links in the CyberWire daily briefing.