Loading summary
A
You're listening to the Cyberwire Network powered by N2K.
B
AI is making phishing attacks faster, more convincing and harder for people to spot. And traditional security awareness and phishing training weren't designed for this level of attack. HOX Hunt helps security teams prepare employees for the attacks they face every day with personalized phishing training that adapts to each employee and reduces risky behavior over time for IT and security leaders looking to strengthen their human layer of defense without adding more manual work. Visit hoxhunt.com cyberwire to learn more. That's H O X h u n t.com cyberwire.
A
New Shai Hulud campaign compromises popular NPM packages Easterly says small municipalities shouldn't have to fend for themselves Chinese threat groups accelerate exploits Samsung bans smart TV apps with residential proxies Hackers breach a Lichtenstein banking database Swiss government IT agency hit and suspected SharePoint attack Microsoft's bug bounty program awards record payouts Researchers expose privilege boundary flaw in AI driven CI CD workflows Roberta Anderson, an Air Force veteran and CISO at Ontaris, is sharing her Breaking the Firewall book and bug hunting turns into bug sorting. Today is Tuesday, August 4th, 2026. I'm Maria Varmazas in for Dave Buettner who is at Black Hat this week. This is your Cyberwire Intel Briefing. Thank you for joining me everybody. Let's get started. Researchers at Aikido are tracking a new Shai Hulud supply chain attack that has compromised at least 868 npm packages, which collectively receive over 2 billion downloads per month. The attackers compromised the GitHub account of the maintainer behind the key value storage library KI V and used the access to infect its entire package family. The injected malware is designed to harvest credentials and other secrets on the infected machines, the researchers state. Every package got a pre install hook that runs automatically on NPM install, silently downloads the bun runtime and harvests npm, GitHub, AWS and vault credentials. Because the attacker pushed to main and immediately cut a release, the poisoned versions shipped with valid Provenance signed by GitHub Actions. There's also active community spread to other maintainers and packages, including major organizations like Deliveroo, OneReach, Pixart and Click. In an opinion piece for the New York Times, former CISA director Jen Easterly argues that the recent cyber attacks on municipal water systems reveal a fundamental flaw in America's cybersecurity strategy and that local communities are being left to defend critical infrastructure against nation state ADVERSARIES While the attacks, which are attributed to Iranian affiliated hackers, did not contaminate drinking water, they exposed how vulnerable small water utilities remain. Easterly, who is now CEO of rsac, contends that blaming state or local officials misses the point. Foreign cyber threats are a national security issue that require a coordinated federal response, and she acknowledges that previous federal investments in guidance grants and incident response likely helped limit the damage, but warns that those gains are now at risk because of funding cuts and weakened federal support. Her prescription is rebuild the Cybersecurity and Infrastructure Security Agency, renew cybersecurity funding, modernize aging infrastructure, and extend information sharing protections. In her view, safeguarding America's water supply is a shared national responsibility and not a burden that small towns should should alone. CrowdStrike reports that China linked threat groups Vault Panda and Genesis Panda can exploit critical Software vulnerabilities within 24 hours of public disclosure, highlighting increasingly compressed attack timelines. The researchers observed both groups rapidly targeting the React to Shell vulnerability after it was disclosed in November 2025 using remote access tools and credential theft capabilities. More broadly, CrowdStrike found that 88% of exploited vulnerabilities in the first half of 2026 were targeted within 48 hours of disclosure, with AI expected to further accelerate exploitation and increase the volume of newly discovered flaws. The report also identified a rise in identity based attacks, including LLM jacking in which attackers abuse victims, AI platforms and as well as in AI enhanced vishing campaigns, which have become more prevalent because they are difficult for defenders to detect. New research from Norwegian cybersecurity firm Mimonic found that several Samsung Smart TV apps contain residential proxy software that can share a user's Internet connection with third parties, potentially exposing millions of devices to misuse. One affected app was a Samsung endorsed Pac man game that included proxy code from bright data. Researchers said the code activates only after users consent, but warned it could be enabled more broadly through server side changes. Residential proxy networks have legitimate uses, including bypassing censorship and supporting AI data collection, but they are also frequently abused by cybercriminals to conceal malicious activity. Following this disclosure, Samsung said it has banned new apps containing residential proxy functionality and and is removing existing apps that include that technology hackers breached Lichtenstein's Register of beneficial owners, copying data related to approximately 31,000 companies, foundations and trusts before authorities detected the intrusion and took the system offline. The register was established in 2021 to support anti money laundering efforts. Officials said that there is no indication that the data was altered or deleted and the Liechtenstein Bankers association confirmed no banks or customers customer data were affected. The government has formed a crisis task force and is notifying affected individuals while the investigation continues. Switzerland's Federal Office for Information Technology and Communications says hackers compromised roughly 200 user and service accounts after what officials believe was an attack against on premises Microsoft SharePoint servers. The intrusion was detected after unusual activity last week, and investigators suspect attackers exploited recently disclosed SharePoint vulnerabilities. Though the investigation remains ongoing, officials say that they have found no evidence so far that data beyond login credentials was accessed, but they're reinstalling affected servers as a precaution. The incident is another reminder that Internet facing SharePoint remains a high value target and that patching alone is not enough. Organizations also need to rotate IIS machine keys and hunt for signs of persistence after Comprom, Microsoft's bug bounty program awarded more than $20 million to 562 security researchers from 64 countries this year, marking the largest payout and broadest participation in the program's history. The company credited coordinated vulnerability disclosure with helping secure its cloud, AI, enterprise and consumer products before flaws could be exploited. Microsoft's Zero Day Quest generated nearly 700 vulnerability reports and $2.3 million in awards, while expanded bounty eligibility for open source and third party components resulted in more than 300 additional reports and over $800,000 in payouts. Microsoft said that the record results reflect the growing impact of its partnership with the global security research community. Security researchers at Pillars Security say that they have uncovered a new class of vulnerability affecting AI powered software development pipelines. Their research shows that AI agents collaborating in Google's Agent Development Kit can unintentionally trust one another across privileged boundaries, allowing malicious instructions introduced early in a CICD workflow to cascade through downstream agents. Rather than exploiting codes, the attack exploits assumptions, meaning that agents inherit the perceived authority of previous agents, potentially leading to unauthorized actions or code changes. The findings suggest that as organizations adopt agentic software development, they will need to treat AI agents as distinct identities with explicit trust boundaries, least privilege access and independent verification, instead of assuming agent to agent communication is inherently trustworthy. And that's the end of our briefing for today. Stay with us after the break when Dave Bittner sits down with Roberta Anderson, Air Force veteran and CISO at Ontaris, discussing her breaking the firewall book and bug hunting turns into bug sorting. Stay with us.
B
What's the one thing in business that's spreading as fast as AI? AI risk Every new tool your team signs up for every vendor that turns on AI features. Every new integration, each one is another opportunity for something to go wrong. And most security programs weren't built to keep up with AI's pace of growth. Enter Vanta. Vanta is the number one agentic trust platform trusted by more than 16,000 fast moving companies like Ramp, Purser and Harvey to help them stay audit ready. And now Vanta helps companies like yours keep an eye on the risks that appear between audits across your vendors, your AI tools and your entire environment. The Vanta Agent works like a 24.7grc engineer. In the background, it finds, issues, drafts, fixes for you, and can cut vendor assessment time by up to 50%. Whether you're a fast growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today@vanta.com cyber that's V-A-N T A.com cyber.
A
Dave Buettner recently sat down with Roberta Anderson, Air Force veteran and CISO at Ontaris as they discussed her new book, Breaking the Firewall.
C
So I've been in information security and CyberSecurity for over 25 years and really I've just seen a pattern. I love mentoring. It's really a huge passion of mine. But I kept getting the same questions over and over again and they were the same things that I was seeing throughout my career. And I kind of just thought, you know what, this would be a great opportunity for me to be able to help more people on a larger scale. So I've been mentoring everywhere that I've been. I'm paramilitary, so it's been in lots of areas, but it was just really a smaller scale. So I thought, you know, if I could write a book, I'd be able to help more people on a larger scale. So that really is the catalyst to the book. And it's been really great so far. Dave. Honestly, so many people have reached out to me saying, Roberta, it's like you're in my head. This is perfect. This is what we've been needing. And so it's really warmed my heart.
B
Well, let's start with the big picture here. I mean, cybersecurity has lots of opportunities out there, but you write that only about 7% of the CISOs out there are women. What's the story that that statistic is telling us?
C
Absolutely. So cybersecurity. And I just want to state this from the beginning, I think cybersecurity is an amazing field. It's offered so many opportunities to so many people but it definitely has a barrier of entry problem. And then once you're in there, it has a problem with allowing you to advance. So you're absolutely right. Throughout my entire career, I cannot even tell you, Dave, how many times I've been the only woman in the room at conferences, in training camps. And it's definitely getting better, but it has a lot of room to grow. So there are several issues, really, around the fact that there just aren't a lot of women. One of them is like, think about it. When you're a kid growing up, how many times are you even aware that cybersecurity is even one of the jobs that you can go into? And then even when you watch television shows, you know, the cool jobs are always. You see these hackers who are doing, like, these amazing things, but you don't hear about, like, the GRC professionals or the security and awareness training professionals. So a lot of it comes down to just the education at the very beginning, not even notifying people of the jobs that are out there. And then one of the things, and I talk about this in my book, is that sponsorship people, it's just human nature. Good, bad or indifferent people are more comfortable working with people with whom they can identify. And so the fact that males are predominantly the ones in there already, it makes it even more difficult for women to get that sponsorship to help them move forward or even to get into cybersecurity to begin with. So it's just one of those things that are. It's a compounding issue issue.
B
You say in the book, you describe how You've spent about 25 years climbing to that CISO role. I'm curious, in your own career path,
C
did I release you?
B
What's that? I'm still here.
C
Oh, sorry, I didn't hear you.
B
I'm curious, you know, looking at your own career path, was leadership one of your goals from the outset?
C
Absolutely. So I come from a military family. My dad was in the army for over 33 years. I was in the Air Force. So honestly, I think my personality is just kind of driven towards leading. But if you look at my own career path, it actually did not start in cybersecurity at all. So it wasn't like I had planned to become a ciso. I actually did not start in cybersecurity at all. So when I was younger, I never even wanted to be in security. I always knew that I was going to be a doctor. And so I write about this as well, that your path can come from anywhere. So I knew did nothing but set myself up to be a doctor. Studied Latin when I was in high school, took all the courses. Actually started out as pre med, but unfortunately When I was 19, my father passed away from medical error. It put me on this entirely different path, this entirely different trajectory. And I wound up in the military. And actually I was going to be a linguist because I have a love of languages. But they changed it so all linguists that I was studying had to be flight. And even though I was in the Air Force and everyone makes fun of me for this, I have a massive fear of flying. And so I was like, that is not going to work for me at all. So I actually ended up going into computers and that is how I got my start. Dave and I love to talk to people about this because some people feel like. And they come to me and say, Roberta, I, you know, I didn't start out loving computers as a kid. I hear that in order to get into IT or cyber security, you had to have built computers when you were young and been doing it since you were a baby. And I don't have a computer science degree and that is absolutely not true. You can get into this with so many different career paths. Look at mine. Like, I didn't even like computers when I was younger and I've been doing it now for over 25 years. Like, you can come as a teacher, you can come in from medical, you can come in from finance, you can come in from hr. That's what's so beautiful about this career. There is a path for everyone and all of those experiences are help you. They all are benefits to this career field. Someone coming in from teaching understands the FERPA roles and they also have an education background so they could be perfect for security and awareness training. Someone coming in from healthcare understands HIPAA and they would be perfect for understanding that regulated environment and doing GRC. Someone coming in from finance would understand SOCs and they would understand how the controls around the systems and auditing would go in perfectly. And then to your point about leadership, I love coaching people who are prior military because oftentimes they're told military experience doesn't translate. That's absolutely not true. You have so much valuable military experience with leadership, with handling stress, with following processes and procedures that that all translate and often that especially translates into management. So it's just like I said, there's so many opportunities in this career field for everyone.
B
You know, one of the things that struck me about the book is beyond the aspirational elements, you also tackle some really practical Things. Things like salary negotiations. I'm curious, why do you think that so many security professionals, and I think it's fair to say, especially women, struggle with advocating for themselves.
C
Absolutely. I think it's dual fold. And especially in this day and age, right. Like every other day you're hearing about layoffs and it's kind of that perception that, oh, I'm lucky to have a job. And yes, it is kind of a scary world out there, but that doesn't change your worth. And so I think it's twofold, where people are just kind of afraid and then they, they don't want to overspeak. But then also I think some of it, people just truly don't understand how much worth they are. So in my book, you're right, I have several chapters. One is about talking about how to negotiate. The other one it is to do your research. So there are lots of sites out there where you can go and you can figure out what is your certification, what is your education, what is your experience actually worth. ISAC is a great one. So is IIC Squared, where they do annual surveys to let you know, hey, what is the certification that you're holding actually worth out in the market? What are people nationally and even statewide getting for the certifications that you have? Another one is, and you're absolutely right, Dave. Women as a whole have just been conditioned again, good, bad or indifferent, that they have to have everything. They have to meet every criteria. So. And I mentor women about this all the time, right? Where they'll say, well, Roberta, you know, I only meet three of the five requirements on this job wreck. And so I'm not going to apply. And I'm like, no, don't do that. Don't apply. Don't discount yourself before anyone else gets the chance.
B
Right? Meanwhile, all the men are saying, hey, I have one qualification.
C
Exactly, exactly, Dan. It's like, just do it. And so then they're already shy before they even get there. So then they're definitely not going to negotiate. I'm like, you absolutely have to negotiate. You know what, I've been guilty about this too. It's only been the last few years where I even felt confident enough to say, you know what, I am going to ask for that sign on bonus. I am going to ask for more of the annual, the annual bonus. So it's just, it's a culture thing, you know, and it's kind of that confidence thing. So I spend a lot of time mentoring women that it is. Okay, you know, you don't have to you don't have to be afraid. You're worth it. It's not asking for a favor, it's acknowledging how qualified you are.
B
I'm curious what your advice is. I'm thinking of that. Maybe it's a young woman who's just on the cusp of their cybersecurity career, or maybe someone who's considering a career shift. Any words of wisdom for them to, to as they make this transition, this journey?
C
Yeah, absolutely. First, do it. Right. That's my first thing I'm saying, do it. You, you can do it. There is space out there for you. The next one is. This is one of the first things. And I'm not at all affiliated with any of the certification authorities, but I always advise people like there. It's just how it is. Like there is a barrier of entry. So if you're looking to get into cybersecurity, it still just stands now that honestly, like the Security plus is just kind of the way that the data holds now. And like the algorithms like your resume mostly won't even get looked at unless you have that security plus. So that's just kind of the first thing to do. The second thing is it's to try to reach out and find someone who's in the industry now and talk to them. My LinkedIn is open. Please, please reach out to. So open to talking to you about how to get in things to look at things to do and then look at your resume. And I have these things in my book, tailor your resume. A lot of people are underestimating the skills that they have and they're selling themselves short, Dave. And it's, it's a confidence thing, it's a lack of knowledge thing. But look at your resume. I guarantee you, you have skills that you are under selling. But my biggest thing is, is do it. Don't be afraid. This career field is amazing. It will withstand AI. A lot of people are afraid it won't. But you do have to tailor things so that you can work with AI. So what I mean by that is a lot of the entry level things absolutely are being impacted by AI. So you just have to make it so that you can work with AI, understand AI and be valuable in the age of AI.
A
That was Roberta Anderson and Dave Buettner discussing her book, Breaking the Firewall. If you enjoyed this conversation, please check out Roberta's book in the show notes. And finally today, Apple has discovered that the hardest part of bug hunting is no longer finding bugs. It's actually sorting through the avalanche of AI. Generated reports claiming to have found them. Faced with a flood of submissions, some accurate and some pure hallucination, the company has capped the number of open vulnerability reports each researcher can submit and added a 30 day cooldown period while allowing requests for higher limits. The change frustrated Italian startup binario, which said AI helped it uncover more than 50 macOS vulnerabilities in three weeks, including a serious privilege escalation exploit it initially could not report. Apple says it is now reviewing those findings and is also using AI internally to triage reports now. This whole thing just spotlights AI's double edged role in cybersecurity, where it's helping researchers uncover legitimate flaws at unprecedented speed while simultaneously burying security teams under a mountain of digital false alarms. And that is the Cyber Wire. For links to all of today's stories, make sure to check out our daily briefing@thecyberwire.com and keep in mind friends, we are recording on site at Black Hat this Wednesday and Thursday from our podcast studio in the Spectre Ops Kennel Club. If you'd like to meet the N2K CyberWire team, including the Dave Bittner, make sure you stop by the studio. We'd love to know what you think of our podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwiren2k.com N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our executive producer is Jennifer Ibin, Peter Kielfi is our publisher and I'm Maria Varmazis in for Dave Vitner today. Thanks for listening. We'll see you tomorrow.
Date: August 4, 2026
Host: Maria Varmazis (in for Dave Bittner)
Guest: Roberta Anderson, Air Force veteran & CISO at Ontaris
This episode of CyberWire Daily delivers the latest cybersecurity headlines, including a major supply chain attack affecting NPM packages, municipal infrastructure vulnerabilities, fast-moving nation-state exploits, and the challenges AI brings to cybersecurity both as a tool and a risk. The show also features an insightful interview with Roberta Anderson, focused on her book Breaking the Firewall and her career journey as a woman in cybersecurity.
"Every package got a pre install hook that runs automatically on NPM install, silently downloads the bun runtime and harvests npm, GitHub, AWS and vault credentials." (03:35)
"Safeguarding America's water supply is a shared national responsibility and not a burden that small towns should should [shoulder] alone." (05:09)
Timestamps: [11:46–24:54]
"So many people have reached out to me saying, Roberta, it's like you're in my head... It's really warmed my heart." (12:40)
"Good, bad or indifferent, people are more comfortable working with people with whom they can identify. And...males are predominantly the ones in there already...it makes it even more difficult for women to get that sponsorship." (14:16)
"I didn't even like computers when I was younger, and I've been doing it now for over 25 years...There is a path for everyone." (17:13)
"You absolutely have to negotiate. You know what, I've been guilty about this too. It's only been the last few years where I even felt confident...It's not asking for a favor, it's acknowledging how qualified you are." (21:15)
"Make it so that you can work with AI, understand AI and be valuable in the age of AI." (24:46)
Timestamps: [24:54–end]
"AI's double edged role in cybersecurity, where it's helping researchers uncover legitimate flaws at unprecedented speed while simultaneously burying security teams under a mountain of digital false alarms." (25:40)
"There is a path for everyone and all of those experiences are.. benefits to this career field." (17:13) — Roberta Anderson
"Sponsorship... people are more comfortable working with people with whom they can identify... it makes it even more difficult for women." (14:16) — Roberta Anderson
"It's helping researchers uncover legitimate flaws at unprecedented speed while simultaneously burying security teams under a mountain of digital false alarms." (25:40) — Maria Varmazis
| Story | Segment Time | Takeaway | |-----------------------------------------------|--------------|-----------------------------------------------------------| | NPM Shai Hulud supply chain attack | 01:04–03:55 | Major open source compromise via credential theft malware | | Water systems and U.S. cyber defense | 03:56–05:10 | Federal action needed; localities left exposed | | Chinese threat groups’ rapid exploits | 05:11–06:13 | Attack timelines shrinking; AI accelerates risk | | Samsung TV proxy apps | 06:14–07:03 | Residential proxies in smart TVs heighten privacy risk | | Liechtenstein banking register breach | 07:04–07:39 | Massive leak but no data alteration | | Swiss SharePoint attack | 07:40–08:25 | Patch quickly; hunt deeply | | Microsoft's record bug bounty year | 08:26–09:12 | $20M to researchers; open source bounties expand | | AI privilege boundary flaws in CI/CD | 09:13–09:56 | Don’t blindly trust AI agents—define controls | | Interview: Women, mentorship, and careers | 11:46–24:54 | Diverse paths, barriers, salary advocacy | | Apple bug bounty AI overload | 24:54–end | AI: boon and challenge for security |
This episode underscores the multiplying complexity of the cybersecurity landscape—where vulnerabilities, adversaries, and defensive challenges move ever faster, and AI is both a savior and headache. The interview with Roberta Anderson stands out for its realism, practical advice, and inspiration, especially for women and career-changers entering or advancing in cybersecurity.