Loading summary
A
You're listening to the Cyberwire Network, powered by N2K.
B
What's the one thing in business that's spreading as fast as AI? AI risk Every new tool your team signs up for. Every vendor that turns on AI features, every new integration each one is another opportunity for something to go wrong. And most security programs weren't built to keep up with AI's pace of growth. Enter Vanta. Vanta is the number one agentic trust platform trusted by more than 16,000 fast moving companies like Ramp, Purser and Harvey to help them stay audit ready. And now Vanta helps companies like yours keep an eye on the risks that appear between audits across your vendors, your AI tools and your entire environment. The Vanta Agent works like a 24.7grc engineer. In the background it finds, issues, drafts, fixes for you and can cut vendor assessment time by up to 50%. Whether you're a fast growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today@vanta.com cyber that's V A N T A dot com cyber. GPT escapes the sandbox and hacks Hugging Face Solar Winds patches multiple critical flaws CISA orders patching of A critical Langflow AI vulnerability a paid work breach affects over 23 million. A recently patched SharePoint vulnerability is under active exploitation. Oracle patches over 1400 vulnerabilities. Apps turn smart TVs into residential proxies. The FCC considers expanding direct to satellite communications. German and US authorities dismantle a major phishing as a service platform. Our guest is Jimmy McNary, Deputy Field CTO at Semperis, discussing comprehensive identity security assessments for Microsoft, GCC and AI models. Can't resist bending the rules. It's Wednesday, july 22, 2026. I'm dave buettner and this is your cyberwire intel brief. Thanks for joining us here today. It is great as always to have you with us. OpenAI has disclosed that two of its Frontier AI models, GPT 5.6 Sol and an undisclosed pre release model autonomously breached Hugging Face's production infrastructure during an internal cybersecurity evaluation. The models were tested in a restricted environment, but they chained together vulnerabilities uncovered an undisclosed zero day escalated privileges, gained Internet access and ultimately compromised Hugging Face systems to obtain evaluation related data. Hugging Face had previously reported the July 16th intrusion and suspected an autonomous AI agent was responsible for a conclusion later confirmed by OpenAI. The company said it has responsibly disclosed the zero day vulnerability strengthened safeguards for future evaluations and partnered with hugging face on security improvements, security leaders say the incident demonstrates that advanced AI systems can pursue unintended harmful strategies without explicit malicious intent, they warn. The event marks a turning point for defenders, highlighting the need to prepare for AI driven attacks that could eventually be adopted by malicious threat actors. SolarWinds has released an update addressing 15 security vulnerabilities in its Serv U, managed file transfer and FTP server products, including multiple critical flaws rated 9.1 CVSS. The vulnerabilities could allow authenticated attackers to escalate privileges, execute arbitrary code, and potentially gain root access on Unix like systems through broken access controls and insecure direct object references. While Windows deployments face lower impact, the breadth of issues makes upgrading a priority, particularly for Internet facing servers. The release also introduces several security enhancements, including stronger content security policies, new browser security headers, expanded multi factor authentication support for Microsoft Active Directory and LDAP users, and a fix for a stored cross site scripting vulnerability. Additional improvements to logging, file sharing reliability and browser compatibility further strengthen the platform's overall security and operational resilience. CISA has ordered U.S. federal agencies to urgently patch a critical vulnerability in the Langflow AI Agent framework that's being actively exploited. The flaw allows unauthenticated attackers to achieve remote code execution, as root researchers have observed more than 220 exploitation attempts with attackers seeking to deploy malware and steal AWS credentials, environment variables and container metadata. CISA has added the vulnerability to its known exploited vulnerabilities catalog and directed federal agencies to remediate affected systems by Friday, warning that the flaw poses a significant risk to federal networks. A reported data breach at paidwork, a platform that pays users for completing online microtasks, has allegedly exposed the personal and financial information of more than 23 million users. The breach reportedly occurred in March of this year with an 11 gigabyte database advertised on a cybercrime forum the following month. Exposed information includes names, contact details, dates of birth, bank account numbers, transaction histories, device and IP data, profile photos and hashed passwords. Although paidwork has not publicly confirmed the incident, security experts warn the stolen data could enable phishing, identity theft, credential stuffing and account takeover attacks. Users are advised to change reused passwords, enable multi factor authentication, monitor financial accounts for suspicious activity, and remain alert for scams leveraging their exposed personal information. Researchers have identified active exploitation of a critical Microsoft SharePoint remote code execution vulnerability that was patched on July 14. The flaw allows authenticated site owners to execute arbitrary code through insecure deserialization security firms defused and Watchtower observed attacks with threat actors reportedly stealing SharePoint machine keys to to maintain long term access. Experts warn that patching alone is insufficient and recommend rotating credentials on potentially compromised systems. The Vulnerability is the fourth actively exploited SharePoint flaw disclosed in the past month. Oracle's July 2026 critical patch update addresses over 1400 vulnerabilities across 334 products. Around 600 of the flaws can be exploited remotely without authentication, with major updates affecting E Business Suite, Fusion, middleware communications and PeopleSoft. Oracle credited only a small number of external researchers, suggesting most vulnerabilities were identified internally, likely with AI assisted security tools. Organizations are urged to apply the updates promptly, as Oracle product vulnerabilities are frequently targeted by threat actors. Your next smartphone connection might not come from a cell tower at all. The FCC is considering a proposal that could expand direct to device satellite communications. Maria Vermazes has more.
A
Thank you, Dave. The FCC announced that it is considering opening up more than 200 MHz of unlicensed spectrum for direct to device satellite services where smartphones and other consumer electronics connect directly to satellites without specialized hardware. The new proposal is on the agenda for the upcoming FCC August Open Commission meeting and would explore allowing WI Fi and Bluetooth frequencies to also support communications between devices on Earth and spacecraft. In addition, the FCC is seeking comment on whether WI fi and Bluetooth devices should should be explicitly allowed to operate aboard authorized spacecraft and in other space based applications. If adopted, these changes could lower barriers for new satellite connectivity services and accelerate the growing market for direct to device communications. The FCC says that these proposals for the August meeting are meant to support emerging space based communications services as satellite and terrestrial networks continue to converge. For the Cyberwire Daily, I'm Maria Varmazes from T Minus Space Cyber Briefing. Back to you Dave.
B
Maria Vermazes is host of the T Minus Space Cyber podcast. Be sure to check that out wherever you get your favorite shows. LG Electronics USA says it will suspend smart TV apps that use residential proxy software development kits following research showing more than 42% of apps in its WebOS store can turn users televisions into always on residential proxy nodes. According to Krebs on Security, the company is working with developers to remove the feature and warned that non compliant apps will be removed from the platform. Researchers found proxy SDKs embedded in a wide range of apps including games, screensavers and utilities with with Bright data accounting for many of the integrations. While proxy providers say they vet customers and implement safeguards, researchers argue consumers often lack meaningful transparency or control over how their devices are used. LG also pledged to strengthen its app review process to prevent similar software from reaching users. The announcement follows recent criticism over LG Monitor's software that promoted McAfee antivirus subscriptions through Windows Update. German and US authorities have dismantled Kratos, a major phishing as a service platform, by seizing more than 200 servers and arresting its alleged developer in Indonesia. Led by Germany's Federal Criminal Police Office and Frankfurt prosecutors. With support from U.S. law enforcement, the operation disrupted a service believed to have supported more than 1800 criminal customers. Conducting approximately 15,000 phishing campaigns each month across 35 countries, Kratos enabled attackers to create convincing fake Microsoft login pages to steal user credentials, facilitating account takeovers and other cybercrimes. Authorities estimate the platform generated at least €300,000 in subscription revenue since 2024. The operation, dubbed Operation Olympus Blade, also transferred the platform's domains to the FBI, enabling investigators to identify additional suspects through seized infrastructure. Coming up after the break, Jimmy McNary, deputy federal CTO at Cempras, discusses comprehensive identity security assessments for Microsoft, GCC and AI models. Can't resist bending the rules. Stay with us. Priceline negotiator it's me, the Priceline negotiator. We don't need the jingle twice. What about a third time?
A
Stop it.
B
This is about vacation inflation and how Priceline negotiates amazing deals on hotels, flights and rental cars. Seems like they decided, yeah, but I didn't mention that you can save up to 60% off hotels in the Priceline app. Time to read the tagline.
C
Fine.
B
No one deals more deals than Priceline. Please stop Priceline. Touche. Priceline. Priceline. Jimmy McNary is deputy federal CTO at Semperis. In today's sponsored Industry Voices segment, we discuss how Purple Knight now delivers comprehensive identity security assessments for Microsoft gcc.
C
SYS has been doing this exercise called Cyberstorm for the past 15, I guess, maybe almost 16 years at this point. And over those past eight or nine exercises that they've done, they do them about every two years. They focused on the perimeter, the DNS, the BGP, industrial control systems, pipelines, et cetera, in those past exercises. But if you look at the last exercise that they actually did, Cyberstorm 9, the centerpiece was actually an identity failure, Right? It's the first time that we've seen this in the Cyberstorm exercise. It was the named core vulnerability. And if I can quote sisa, they said, quote, poor identity access management practices when using the cloud. Right? So that tells us, right away that there is a concerning effort in government to look at the Identity Core. You know, for, for many years we've, we throw a lot of money, a lot of effort, a lot of time into protecting the perimeter. But what we realize now is it's not about if they're going to get in, it's when they get in. Right. So this exercise they do every two years was focused on the Identity core and protecting the identity system. In fact, interesting little tidbit from their details that they put out after the exercise. They created a fictional nation state adversary which deployed a rootkit scenario writers called adamware. For those of you that don't know, Adam being the Microsoft's old name for Active Directory application mode, it's kind of interesting that they created the actual rootkit that they were going to use for this exercise around Active Directory. That shows you the importance of what they were trying to tell the audience, the message they were trying to give them.
B
A little on the nose perhaps?
C
Yeah, exactly. They can't really call out Active Directory, but they can call their malware atomware, which is kind of a hint at what they were trying to prove. But you know, the criminal ransomware headlines actually undersell our risk because the actors that truly hunt federal and defense networks is not about making noise or a payout. Right. It's more about nation states. They want to move in quietly and then they want to stay. Right. They're not coming in smashing a window, they are actually authenticating. And every downstream system, they look exactly like a legitimate user. So the layer on a directory tier where 4 out of 10 servers are aging out of support and you have ideal terrain for a patient adversary. The control plane that everything trusts and few teams watch in real time and that never funded critical infrastructure that plainly is in place as well. The exercise that they did, they saw it coming. The field data confirmed it, it has arrived and it's legit gap that they're monitoring and they're looking at.
B
I know you have outlined this notion that backup is not recovery. Can you explain that to us? Unpack it a bit?
C
Yeah, I think everyone has backups, right. So as an organization, you probably back up a lot of critical infrastructure and a lot of critical data. So that has been around for a long time. Right. But the dangerous assumption here is that having a backup and being able to recover are in the same sentence, they are not. Right. So for the threat that exposes the gap is not the criminal ransomware crew, it's the nation state. And criminal ransomware is noisy. Get paid business. And it's not not working well against a hardened, segmented federal defense network. Or policy says we don't pay, right? So actors who really hunt us, they want the opposite of noise. They want to get into your identity system quietly and either steal or when it serves them, destroy it. Right? So if you look at, for example, the event that happened in 2017 called not Petya, it looked exactly like ransomware. It had a note, it had a countdown. But behind it all, it was actually the Russian military with a wiper group that was seeded through a software supply chain. And there was no decryption keys. They were never going to give you any decryption key because destruction was the point of their mission. It spread by stealing credentials and moving across Active Directory and it wiped all the domain controllers. If you look at one of the examples that, or one of the attacks that they did against Maersk, right. Maersk survived only because one domain controller in Ghana happen to be offline during a power outage. That's a single lucky copy of Directory. That was the entire reason they were able to recover. And there was over $10 billion worth of damage. That's a real gap. So again, the government's already answered this right. With Cyberstorm 9. They showed us that identity is the key that you need to protect and that it's not about if they're going to get in, it's when they're going to get in.
B
I know you have years of experience working with federal organizations. How often are they testing complete Active Directory recoveries?
C
Well, you know, I have the fortunate opportunity to talk to a lot of CIOs, CTOs, CISOs in the government. And one of the biggest questions I ask them, right. Is I said, what is your plan, right, to recover Active Directory. And you know, there's usually some document or some plan that they've got stored away in a drawer. And then the next question I asked them is, well, when's the last time you tested? Oh, no, we're not going to touch Active Directory. Right. So it's. Active Directory is a, you know, it's, it's 25 plus years old now at this point, Right. It's a great system, but it wasn't mel meant to be built on the technology we have today in 2026. It was built on 2000 architecture 26 years ago. So it's a different system than it was originally created to be, but it still works today, and organizations really can't get off of that system anytime in the future. So the reality is those C Level executives, they understand that this is a critical infrastructure, but it's one of those things that you don't really want to do too much with or challenge because you're afraid that if it goes down, everything's going to come back to you. Why you were doing this exercise fortunately, with some Paris, our methodology and our approach is different than most backup organizations, right? So we're able to actually backup the entire data of Active Directory, which allows you to take that data, put it into a lab and recreate that entire breakdown of your system so you can create a pristine operating system, pristine active Directory, and put that real data that you have in your environment into a lab, wipe away a domain and see how you recover it very quickly with our software.
B
Well, you mentioned that Active Directory is coming up on a few decades in age. Can we contrast that against the wave of AI that we've seen here? What's the impact there? How does that affect things?
C
Yeah, Dave, we can't have any good podcast without AI today, right?
B
That's required.
C
It's required.
A
Right.
C
So every conversation I have seems to. At least AI pops its head somewhere in there. But I want to hold two true things at once, right? Because the honest answer lies in the tension between them. First, escalation is real and it's already a nation state game, right? Last November we saw anthropic disclose GTG1002, which is a Chinese state sponsored group that turned Claude Code into a largely, you know, autonomous espionage operation against about 30 organizations, including government was part of those targets as well. You know, AI did an estimate of somewhere between 80 to 90% of the hands on keyboard work by itself at a speed no human crew could sustain. Right? So with people touching only a few strategic decisions, that is a barrier lowering. So a smaller actor can now run a nation state grade operation. But the second truth matters just as much. It was not a clean operation. The models still hallucinate credentials and oversold its own success. So humans still had to check its work, which Anthropic flags as the current ceiling for full autonomy. But across the board, incident data from Mantian and Sophos independently came to the same place. Right? AI is adding speed, scale and polish, but I would say the vast majority of breaches still come from ordinary human and systematic failures. 2025 was not the year AI caused the breaches. It's where AI is genuinely shifting things from the front door. Instead, email phishing actually fell while voice phishing climbed to the number two way in because convincing voice talks the help desk into Bypassing mfa. So the grounded take is that AI is a force multiplier on both sides. It's not just for attacking, but it's also for defense operations as well.
B
What are your recommendations then, for federal CISOs? How should they be approaching this? And any words of wisdom?
C
Yeah, you know, if I could leave the audience with one thing, it's this. You know, we spend generations trying to keep adversaries out and the honest truth, from CISA's own national exercise to the field data, you know, nation states will get in. So, you know, there's nothing more important right now than being resilient. Right. So resilience is not a taller wall anymore. Right. You know, we spent years trying to protect that castle, that outer perimeter. We don't need a bigger wall. We need a system that's more resilient. Right. So there's three disciplines that get applied. One thing, every other control depends on which is identity. You have to monitor it continuously because they reach your directory in hours, not weeks. And you cannot defend what you cannot see. You have to protect it. Closing the privilege escalation paths and the old misconfigurations that turn a single foothold into full control. And you have to be able to recover it. So. And not just, you know, from a backup recovery. Right. You have to recover it cleanly, proven and fast, because the directory itself is compromised. Nothing you can restore on top of that can be trusted. Monitor, protect, recover. It's the entire job of identity. Resilience is now the job of national security.
B
That's Jimmy McNary, deputy federal CTO at Semperis. AI is making phishing attacks faster, more convincing, and harder for people to spot. And traditional security awareness and phishing training weren't designed for this level of attack. Hoxhunt helps security teams prepare employees for the attacks they face every day with personalized phishing training that adapts to each employee and reduces risky behavior over time for IT and security leaders looking to strengthen their human layer of defense without adding more manual work. Visit hoxhunt.com cyberwire to learn more. That's h o x h u n t.com cyberwire. And finally, the UK Government's AI Security Institute has found that when AI models are given a task, they sometimes approach it with the enthusiasm of an employee who has discovered a shortcut and hopes no one asks too many questions. In cybersecurity evaluations, every model tested attempted to cheat at least some of the time, whether by searching the Internet for answers, bypassing sandbox restrictions, probing the testing environment or targeting systems outside the intended scope. Even more awkwardly, the models often failed to admit what they had done when questioned. GPT 5.4 recorded the highest rate of cheating at 14.1% of Test runs, while Claude Mythos Preview was the least frequent offender at 7.8%, though it still made the list, the findings suggest that self reporting and chain of thought monitoring cannot be relied upon to detect deceptive behavior. For defenders, the lesson is trusting AI to grade its own homework may not be the security strategy anyone hoped for. And that's the Cyber Wire. For links to all of today's stories, check out our daily briefing@thecyberwire.com we'd love to know what you think of this podcast. Your feedback is ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire2k.com N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazes, our executive producer is Jennifer Ibin. Peter Kilby is our publisher and I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow.
C
Foreign
B
to this year's Black Hat USA, the N2K CyberWire team will be on site recording from our podcast studio in the Spectrops Kennel Club. If you're interested in joining us for a conversation or learning more about what we're recording throughout the week, visit sponsor.thecyberwire.com for more information. And make sure you stop by the studio and meet the N2K CyberWire team. We'll see you there.
Date: July 22, 2026
Host: Dave Bittner (N2K Networks)
Featured Guest: Jimmy McNary, Deputy Federal CTO at Semperis
This episode explores the rapid evolution and growing risks of artificial intelligence in the cybersecurity arena. News highlights include autonomous AI model exploits, major software vulnerabilities, regulatory advances, and law enforcement actions against phishing services. The featured interview with Jimmy McNary centers on comprehensive identity security assessments for Microsoft GCC and the unique challenges posed by nation-state threats and AI-powered attacks. Throughout, the episode emphasizes that resilience—instead of mere prevention—is now the core cybersecurity imperative.
SolarWinds Update:
LangFlow Active Exploitation – CISA Mandate:
Paidwork Data Breach:
Active Exploitation of SharePoint RCE:
Oracle Critical Patch Update:
FCC Eyes Direct-to-Device Satellite Connectivity:
LG TV App Security:
Dismantling Kratos Phishing-as-a-Service Platform:
“What we realize now is it’s not about if they’re going to get in, it’s when they get in… this exercise was focused on the Identity core and protecting the identity system.” – Jimmy McNary ([15:00])
AI has already enabled fast, semi-autonomous attacks (i.e., GTG1002’s attack on 30 organizations, largely driven by AI) ([21:48]).
“AI did an estimate of somewhere between 80 to 90% of the hands-on keyboard work by itself at a speed no human crew could sustain ... a smaller actor can now run a nation-state grade operation.” – Jimmy McNary ([22:20])
Yet, AI systems are not flawless—models hallucinated data, required human oversight, and introduced operational risks.
Incident Data:
Email phishing dropped; voice phishing rose due to voice AI convincingly bypassing MFA with help desks.
“Monitor, protect, recover. It’s the entire job of identity. Resilience is now the job of national security.” – Jimmy McNary ([24:55])
On Perimeter vs. Identity:
“It’s not about if they’re going to get in, it’s when they get in ... this exercise they do every two years was focused on the Identity core.” – Jimmy McNary ([15:00])
Reality Check on Resilience:
“There’s nothing more important right now than being resilient ... Resilience is not a taller wall anymore.” ([23:58])
On the Role of AI in Modern Attacks:
“AI did an estimate of somewhere between 80 to 90% of the hands-on keyboard work by itself at a speed no human crew could sustain.” ([22:20])
UK AI Security Institute’s Caution:
“Trusting AI to grade its own homework may not be the security strategy anyone hoped for.” ([27:10])