Loading summary
A
You're listening to the Cyberwire Network powered by N2K.
B
This episode is supported by Black Hat usa. If you follow the research, you know a lot of it breaks on. Black Hat stages hundreds of peer reviewed briefings, more than 100 hands on trainings, and the largest business hall in Black Hat's history. Six days to learn the skills you'll need tomorrow, August 1st through the 6th, use code CYBERWIRE for $200 off your briefings pass@blackhat.com we'll see you in Vegas. The Senate confirms Jay Clayton to lead ODNI A new CISA frame highlights critical infrastructure isolation capabilities OpenAI's rogue agent breached more than just hugging face the average cost of a data breach continues to rise. Indirect prompt injection proves irresistible to cybercriminals. Broadcom patches, multiple VMware products. Shiny Hunters claims responsibility for Ernst Young's recent breach. Our guest is Sean Zadig, CISO, at Yahoo, discussing the impact of AI on the defensive side and these aren't the droids you're looking for. It's Wednesday, july 29, 2026. I'm dave buettner and this is your cyberwire intel brief. Thanks for joining us here today. It's great as always to have you with us. Jay Clayton was confirmed by the senate in a 51 to 47 party line vote to lead the office of the Director of National Intelligence, replacing Acting Director Bill Pulte. Although some Democrats initially viewed Clayton favorably, support eroded after he declined during his confirmation hearing to clearly state that Joe Biden won the 2020. Still, many lawmakers preferred Clayton to Pulte, whose brief tenure featured aggressive staffing cuts, public boasts about downsizing, and concerns over his lack of national security experience. The intelligence office, created after the September 11 attacks to coordinate US spy agencies, has seen its influence diminish under President Trump, who has relied more heavily on CIA Director John Ratcliffe. Clayton, a former SEC chairman and current U.S. attorney in Manhattan, is expected to work closely with Ratcliffe despite lingering concerns about his political independence. A new joint framework from CISA and cybersecurity agencies in Australia, the UK and Canada warns that critical infrastructure operators must build and test isolation capabilities before cyberattacks occur, not during them. The guidance, called CI Fortify, was prompted by major intrusions such as China's Volt Typhoon and Salt typhoon campaigns, which exposed weaknesses in US Infrastructure and telecommunications networks. A key finding is that many OT systems rely on corporate IT services like Active Directory and DNS, causing isolation plans to fail when networks are disconnected. CI Fortify recommends standalone OT authentication services, predefined isolation points, physical disconnection where possible, recovery procedures and regular full scale testing. However, the guidance is voluntary and experts warn many operators lack the funding and resources to implement it. While the framework establishes a new federal baseline for resilience, organizations that fail to prepare may face greater regulatory, legal and insurance scrutiny after future cyber incidents. Reuters reports that the rogue AI agent developed by OpenAI, which carried out a multi day hacking campaign against Hugging Face, also compromised a customer hosted on Modal Labs platform. According to Modal's chief technology officer, the attack exploited a customer's publicly accessible unauthenticated endpoint rather than a flaw in Modal's infrastructure or security isolation. Hugging Face previously disclosed that the agent first breached a sandbox hosted by a third party provider before using it to expand its attack, though it did not identify the provider. OpenAI confirmed the agent compromised four accounts across four services but did not name them. The incident suggests the agent's activity extended beyond hugging face. OpenAI said it has since deactivated encrypted and restricted access to the AI model involved, while declining to comment further on the modal related compromise. Hugging Face published a technical analysis of the July intrusion detailing how the autonomous AI agent conducted a four and a half day attack involving roughly 17,600 actions across thousands of automated decision points. According to the company, the agent running OpenAI's exploit gym evaluation benchmark appeared to target Hugging Face to obtain benchmark solutions rather than complete the tasks legitimately. The attack unfolded in two stages. First, the agent escaped its evaluation sandbox compromised a third party code sandbox and used it as a launchpad. It then exploited two vulnerabilities in Hugging Face's dataset processing pipeline, gaining code execution and access to internal systems before moving laterally. Investigators reconstructed the attack using recovered logs and the open source GLM 5.2 model. Hugging face said the only customer Data accessed were 5 exploit gym challenge data sets and limited operational metadata, with no broader customer assets affected. IBM's 2026 cost of a data Breach report found the global average cost of a Data breach rose 12% over the past year to a record $4.99 million, based on incidents affecting 602 organizations worldwide lost business. Customer trust and incident response expenses remain the largest cost drivers. The report also highlights a shift in ransomware tactics, with 41% of victims reporting attackers threatened reputational damage or public exposure to increase pressure for payment. Healthcare recorded the highest average breach cost at $6.6 million, followed by financial services, industrial technology and entertainment IBM also found that more than one in four organizations experienced AI driven attacks with deepfake impersonation and AI enabled malware among the most common. These attacks added an average of $1 million per breach, prompting 85% of organizations to plan increased cybersecurity spending, particularly on zero trust security and improved data governance. The U.S. space Command has released a new strategic framework looking ahead to the year 2040, envisioning a future where space is more crowded, more contested, and more central to military operations than ever before. Maria Vermazes takes a closer look at what the space Warfighting Environment 2040 report tells us about how military planners see the evolving relationship between space operations and cybersecurity.
A
Thank you Dave. There is a new document from U.S. space Command that's been just published called the space warfighting environment 2040 and it's a new framework outlining how US military operations in space might evolve over the next 15 years. This new report highlights several trends in contested space that have direct cybersecurity implications, including but not limited to AI enabled networks that can reroute around disruptions, quantum technologies that could reshape secure communications and and growing reliance on commercial space services now. A key recommendation in this document is that the military now train for contested space environments as the norm instead of merely a possibility. Space Warfighting Environment 2040 writes that warfighters should assume that communications, positioning, timing and network services will be actively disrupted during future conflicts. The document also warns that future conflicts will target the entire space enabled effect chain, going from satellites and ground stations to communications links and data networks. Notably, it identifies cyber intrusion, jamming, spoofing and information operations as key threats, pointing to both Russia's use of cyber and electronic warfare, as well as North Korea's continued emphasis on cyber capabilities. The document also calls out growing risk from the commercial space supply chain, meaning that while commercial space infrastructure is becoming increasingly important to military operations, those same commercially built components and spacecraft are also available and thereby more easily exploitable to adversaries through those same commercial markets. For the Cyberwire Daily, I'm Maria Varmazas from T Minus Space Cyber Briefing. Back to you, Dave.
B
That's Maria Vermazes, host of the T Minus Space Cyber Podcast. Be sure to check that out wherever you get your favorite shows. Researchers from proofpoint report growing interest among cybercriminals in indirect prompt injection with underground forums, advertising tools that embed hidden prompts into content processed by AI assistants. Subscription services starting around $150 per month, offer generators for emails, PDFs, calendar invites and web pages designed to manipulate AI agents rather than human users. Emerging techniques include hidden white on white text in emails and documents, malicious prompts embedded in PDFs, calendar invitations that target AI powered email summarization, and prompts concealed in website code or image metadata used in malvertising. While large scale exploitation has not yet been widely observed, researchers say these tools show attackers are actively developing AI focused tradecraft. Proofpoint warns organizations to prepare for these techniques as they are likely to become more common as AI powered applications and autonomous agents see broader adoption. Broadcom has released security updates for multiple VMware products including ESXi, VCenter, Workstation and Fusion, addressing five vulnerabilities, three rated critical. The most severe include a VM Escape flaw in ESXi's VMX Net 3 adapter, an authentication bypass in VCenter, and a remote code execution vulnerability in VCenter. Additional fixes address a high severity denial of service flaw and a low severity logging bypass. Broadcom says there's no evidence of active exploitation, but urges customers to apply patches promptly due to VMware's history of being targeted by attackers. The Shiny Hunters extortion group has claimed responsibility for Ernst and Young's recently disclosed data breach, which exposed sensitive client tax information stored in a third party support platform. According to EY, attackers access support tickets between March 28 and April 12, obtaining personal and financial data, including Social Security numbers and payment card information. The company is offering affected individuals two years of identity protection services but has not disclosed the number of victims or confirmed the attacker's identity. Shiny Hunters has threatened to publish the stolen data unless EY responds by July 31st. Coming up after the break, my conversation with Sean Zadig, CISO at Yahoo. We're discussing the impact of AI on the defensive side and these aren't the droids you're looking for. Stay with us. Sean Zadig is chief Information Security Officer at Yahoo. We recently got together to discuss the impact of artificial intelligence on on the defensive side of the house.
C
So as the CISO at Yahoo, I kind of sit between the business which is, you know, at Yahoo. Is serving consumers around the world with all sorts of tools and things that sort of help make their lives work and our security team and functions. And I often am playing a role, sort of a dual role. One of those roles is basically making sure those teams have what they need and they are functioning appropriately and they're resourced appropriately and they've got the strategic support to be sort of anticipating what's coming in the future. But the other part of my role is really going and speaking really in depth about the business that I support and what new products are coming and what are the business pressures and increasingly, how can cybersecurity support and enable those business sections to succeed, including things like, well, M and A, how can we help there? And what are the risks of M and A in certain parts of the world or certain types of businesses? What are the sort of strategic cyber concerns that play a role in maybe bringing out new products? And how should we be thinking about cyber, not just in terms of vulnerabilities, but in terms of what the benefit and risk to a business is. So a lot more business than I thought I would when I first began this journey.
B
Yeah, interesting. Well, not only are you CISO@yahoo, you are also a dad. And so I'm really interested for your perspective, knowing what you do about security and dealing with it every day at work, how does that translate to your day to day of looking out for your kids?
C
I would say it impacts it pretty significantly. And so as the ciso, my other role I don't think I mentioned yet was I'm also the chief paranoid and the team is called the Paranoids. It's kind of a fun, quirky name, but we like to think that we're paranoid for our users and thinking about all the sort of threats and the things that we need to be concerned with so they don't have to be. And I think that also kind of plays itself out in my home life too. And So I have three kids and they're 15 and 12 and eight. Actually eight. Just turned to eight today. And you know, I think in terms of like technology and the dangers online and what they should be using, what they shouldn't be using, I think that constantly making decisions kind of on a daily basis on, in terms of what, what's an appropriate level of risk and what are the making sure that they understand what can sort of happen in sort of a bad way online. But then also what are the benefits of being online and what technologies are they getting exposed to and what will help them in the future as they become from little humans to big humans and eventually think about careers and their own families. So it's a lot of micro decisions that kind of add up to trying to raise a good person nowadays.
B
Yeah, it strikes me that that's a really interesting range of ages that you have. You know, that you have the spectrum between the youngsters, the one just coming into their teen years, and then one who's sort of right in the middle of that in my house, we refer to it as the vortex of chaos, of the hormones and the social pressures and all these things that all of us went through as teens. What sort of conversations are you having with your kids at those different ages?
C
Yeah, I mean, my son, who's my middle child, who's 12, he's the most sort of, like, technically adept and interested and also dangerous. And so, for example, he's got that cybersecurity bug, and he is very interested in, and hacking and technology and in not just using it, but also coming up against the boundaries and maybe pushing it past what it maybe was designed to do. And so he's the one I have to kind of watch out for. But, you know, having. Actually, part of my background I didn't really talk about before was I used to be a federal agent for the US Government doing cybercrime investigations. And I actually had seen a lot of situations where, you know, teenagers who didn't have good outlets for, for their, their skills would kind of get sucked into a life of crime and would kind of go the wrong way and then fall into, under the attention of the, of the authorities like myself. And I'm really thankful that nowadays there are so many opportunities for young people to, you know, engage in and satisfy that curiosity without having to go into these kind of illicit worlds. So a really good example is bug bounty programs. Yahoo runs one. And, you know, there's. I think we allow kids as young as 16 to participate. Depending on the platform others might do. It's the same. And, you know, there's. It's a way for people to sort of learn how to hack, learn what security is and, you know, how to, in some cases, come up against that line and maybe cross it once in a while without. In a safe environment that builds skills for a future career instead of potentially leading to a criminal record or ways that might make future career hard. And so with my son, I'm like, hey, well, let's talk about. Okay, you want to explore some of these things, let's expose you to some tools that give you some context. And so, for example, I set him up with Wireshark and helped him understand network packets and what good looks like. And so you can help sort of see what bad looks like and how to recognize that. And then he plays a lot of Minecraft online, which is the sort of nod I give to online gaming. But there are certain other platforms that I say you can't do, including social media. You know, he often is exposed to people trying to hack him or Phish Him. And so there's a lot of opportunities to sort of interject and say, oh well, that might be a phishing attack. Why do you think that is? And what is suspicious about that? And sort of like the stop and think before you click type of mantra. And it's kind of fun that I get to a lot of the things I deal with at work on a day to day basis play out in some way in the things that he's seen in Minecraft or in some of these other forums.
B
Well, let's talk about just some practical advice then for the folks in our audience. Do you have any tips or words of wisdom? You know, some of the things that, that you've put in place or you recommend?
C
Yeah, I think, I mean to be honest, like having visibility and that's a, it's a core security concept is, is having visibility over your environment. And whether it's a, you know, a corporation like Yahoo and we want to have network visibility or whether me at home, I want to have visibility over to what my kids are doing and they are aware that I have that visibility. And so for example, the two older kids have phones and they do because they actually take the Metro to school in downtown D.C. but it's a phone that is kind of locked down and we're an Apple home for those sort of things. And so it's this family plan with the sort of family sharing enabled and location services on and you know, requiring permission to enable certain features or install certain software. And you know, they know it's very, very, very clear that the parent sort of administers the device and it's for their, you know, make sure they know it's for their safety. So I would say, you know, making sure that you have a clear conversation with your children about what could happen online, what some of the risks are and some of the ways that we can mitigate that risk with protections and being careful who you talk to and things like password hygiene and a lot of cybersecurity basics. They're really applicable at home.
B
You have a 15 year old, do you get much pushback there, dad? All the other kids have this, that
C
and the other thing, you know, I surprisingly don't. And I think part of it is because I guess cybersecurity is kind of in the background of a lot of our conversations. And I work from home and so sometimes they might hear me talking about it or as I'm driving them, picking them up from the Metro, I might be on a call with people at Yahoo talking about AI or cybersecurity or stuff. And so I think through osmosis they're actually absorbing a fair amount of the threat landscape and they I'm not getting a surprising amount of pushback I think and partly as well as I also know the parents really well and they associate with on a regular basis like their best friends and you know, they know what I do and I'm often, you know, answering questions or providing advice to them around technology. And so the other their best friends are kind of well calibrated when it comes to their their own risk tolerance.
B
I guess that's Sean Zadig from Yahoo. If you're heading to Black Hat USA this year, make plans to visit the SpectreOps Kennel Club. As creators of Bloodhound, the Spectrops team will host talks with OpenAI and the UK AI Security Institute, as well as hands on workshops aimed at helping you understand AI accelerated attack paths and the latest in identity tradecraft. Visit Spectrops IO to pre register and learn more. Spectrops Kennel Club is adjacent to Libertine Social inside Mandalay Bay. While you're there, visit the N2K CyberWire podcast studio, where we'll be capturing expert perspectives and conversations from across Black Hat. And finally, the US Is drawing a firm line around advanced robotics moving to effectively block future imports of foreign made robots on national security grounds. Federal officials argue that increasingly connected robots could be exploited for espionage, remote disruption or supply chain leverage, pointing to vulnerabilities previously disclosed in Chinese made unitree robots. New FCC restrictions prohibit sales of most foreign built advanced robots, while exempting machines manufactured in the US and certain systems approved by the Defense Department. Robots already authorized for sale can continue to be imported, and existing owners are unaffected. The policy signals Washington's broader effort to localize critical technologies. It also hands a potential advantage to domestic manufacturers like Tesla, whose long promised optimist robot may now have less foreign competition, provided it eventually graduates from keynote appearances to actual production. And that's the Cyber Wire. For links to all of today's stories, check out our daily briefing@thecyberwire.com we'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire2k.com N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazes. Our executive producer is Jennifer Ibin. Peter Kilpe is our publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow. Heading to Black Hat USA, the N2K CyberWire team will be on site recording from our podcast studio in the Spectrops Kennel Club. If you're interested in joining us for a conversation or learning more about what we're recording throughout the week, stop by the studio and meet the N2K CyberWire team. Spectrops Kennel Club is adjacent to Libertine Social inside Mandalay Bay.
Date: July 29, 2026
Host: Dave Bittner (N2K Networks)
Special Guest: Sean Zadig, CISO at Yahoo
This episode delivers an in-depth briefing on the latest cybersecurity news, highlighting developments in AI-driven attacks, notable breaches, key policy changes, and emerging threats. The centerpiece is an interview with Sean Zadig, CISO at Yahoo, discussing the practical impact of AI on defense and the intersection of cybersecurity with everyday life—both at work and at home.
Coverage by Maria Varmazas (08:38):
“Warfighters should assume that communications, positioning, timing, and network services will be actively disrupted during future conflicts.”—Maria Varmazas, 09:05
Segment Begins: [14:08]
Zadig describes his position as balancing technical security and business support, increasingly focused on anticipating risk in new products or M&A (mergers & acquisitions).
He's surprised by how much his job now centers on business, not just vulnerabilities.
"A lot more business than I thought I would when I first began this journey."
— Sean Zadig, [15:10]
Zadig, known internally as the “chief paranoid,” brings a protective mindset to both Yahoo users and his own kids (ages 15, 12, and 8).
Explains daily parenting decisions as “micro-decisions” to balance beneficial tech exposure and online risks.
"I think that constantly making decisions kind of on a daily basis on, in terms of what's an appropriate level of risk... but then also what are the benefits of being online…as they become from little humans to big humans."
— Sean Zadig, [16:43]
His 12-year-old son is deeply interested in hacking and cybersecurity, which Zadig cultivates with safe avenues (e.g., bug bounty programs, tools like Wireshark), drawing from his experience as a former federal cybercrime investigator.
"I'm really thankful that nowadays there are so many opportunities for young people to, you know, engage in and satisfy that curiosity without having to go into these kind of illicit worlds."
— Sean Zadig, [18:49]
Visibility: Central to both enterprise and family cybersecurity.
“Making sure that you have a clear conversation with your children about what could happen online, what some of the risks are and some of the ways that we can mitigate that risk…”
— Sean Zadig, [21:40]
His approach results in minimal pushback from his kids, aided by frequent discussion of threats and open dialogue with other parents.
On Changing Business Role:
"How should we be thinking about cyber, not just in terms of vulnerabilities, but in terms of what the benefit and risk to a business is."
— Sean Zadig, [14:55]
On Nurturing Young Hackers Ethically:
"Part of my background... I used to be a federal agent... and I actually had seen a lot of situations where teenagers who didn't have good outlets for their skills would kind of get sucked into a life of crime."
— Sean Zadig, [18:05]
On Parenting & Security:
“I also know the parents really well and... so the other... their best friends are kind of well calibrated when it comes to their own risk tolerance.”
— Sean Zadig, [23:33]
On Space Warfare Mindset:
“The military now train for contested space environments as the norm instead of merely a possibility.”
— Maria Varmazas, [08:54]
This CyberWire Daily episode encapsulates an evolving threat landscape shaped by AI, regulatory shifts, and rising breach costs. The interview with Sean Zadig offers relatable insights on leading security in both the boardroom and the living room—a practical perspective that connects high-level defense challenges with everyday digital parenting. The episode leaves listeners attuned to the need for constant adaptation, open communication, and ethical guidance in a world where technology grows more powerful—and more perilous—by the day.