Loading summary
A
You're listening to the Cyberwire Network. Powered by n2k.
B
This episode is brought to you by Accenture. When your advertising operations fall out of sync, everything else follows. Spotify and Accenture are working together to reinvent the rhythm of ad sales using automation, analytics and smarter workflows to simplify campaign delivery and and access better data across the business. The result? Less time spent on operations, more time connecting brands with the moments and fandoms that matter most. Learn more@accenture.com Spotify
A
what's the one thing in business that's spreading as fast as AI? AI risk Every new tool your team signs up for. Every vendor that turns on AI features, every new integration. Each one is another opportunity for something to go wrong. And most security programs weren't built to keep up with AI's pace of growth. Enter Vanta. Vanta is the number one agentic trust platform trusted by more than 16,000 fast moving companies like Ramp, Purser and Harvey to help them stay audit ready. And now Vanta helps companies like yours keep an eye on the risks that appear between audits across your vendors, your AI tools and your entire environment. The Vanta 8 works like a 24.7GRC engineer. In the background, it finds, issues, drafts, fixes for you and can cut vendor assessment time by up to 50%. Whether you're a fast growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today@vanta.com cyber that's V A N T A dot com cyber. The president's latest AI leader resigns. The army burns through its AI tokens scammers impersonate IC3 personnel holograph malware uses a compromised Microsoft 365 calendar for C2 Keelin ransomware targets a critical Palo Alto networks flaw. A North Korean campaign targets Web3 and cryptocurrency professionals through fake job recruitment scams. Zimbra patches multiple critical bugs. ShadowAI creates regulatory headaches. Hackers wipe Romania's land registry database. Our guest is Errol Weiss, Chief Security Officer at the Health isac, setting the record straight on ransomware trends and patching the automotive security system. You didn't know you head. It's Tuesday, july 21st, 2026. I'm dave bittner and this is your cyberwire intel brief. Thanks for joining us here today. It's great as always to have you with us. Chris Fall has resigned as Director of the center for AI Standards and Innovation. Cassie after just three months continuing a period of leadership instability at the National Institute of Standards and Technology office. No reason was given for his departure. CASI is responsible for developing AI, testing standards and assessing cybersecurity risks, but it has recently appeared less central to the Trump administration's AI strategy. The Commerce Department's temporary restriction on Anthropic's AI models and the White House's new Gold Eagle AI safety initiative both proceeded without a prominent role for CASI. Meanwhile, industry leaders including Google DeepMind CEO Demis Hassabis have called for an independent AI standards body. Questions also remain about CASI's evaluation methods for Chinese open weight AI models, with federal agencies declining to provide details. With yet another quick departure, the job is starting to look a bit like Hogwarts Defense against the Dark Arts professorship, an important role that never seems to keep the same occupant for long. Just weeks after the Department of Defense announced that nearly half of its 3.5 million employees were using artificial intelligence at work, the army began warning personnel to conserve their AI usage after exhausting a shared pool of tokens. According to an internal email obtained by Wired, the Army's chief information office had to reinstate limits despite previously offering unlimited access, and future funding beyond October remains uncertain. The army uses the Ask Sage platform to access large language models from OpenAI, Google and Meta for administrative and operational tasks. Employees had been encouraged to increase AI use with additional tokens automatically allocated as needed. The episode mirrors similar pullback at companies including Meta and Uber after unexpectedly high AI usage. One army employee questioned the tool's reliability, saying they sometimes produced inaccurate results, and argued that broader deployment should be more deliberate and focused on appropriate use cases. The FBI is warning that scammers are impersonating agency personnel and the Internet Crime complaint center the IC3 to target people who have already been victims of fraud. The schemes use fake emails, phone calls, social media accounts, AI generated videos, and spoofed websites that closely resemble ic3.gov Victims are often directed to fraudulent complaint forms or messaging platforms where scammers attempt to steal additional personal and financial information or demand payment to recover stolen funds. The FBI emphasizes that IC3 has no social media presence and does not contact complainants through messaging apps, phone calls or online chats. Legitimate follow up comes only through FBI personnel or other law enforcement officers. The agency also stresses that it never charges fees or requests cryptocurrency gift cards or wire transfers to recover stolen money. Researchers at Group IB have identified a new malware strain dubbed Holograph that uses a compromised Microsoft 365 calendar as a covert command and control channel. Instead of communicating with attacker controlled servers, the malware leverages the Microsoft Graph API to receive instructions through calendar events and exfiltrate stolen data by creating its own encrypted calendar entries, blending malicious activity with legitimate Microsoft 365 traffic. It also uses DNS tunneling as a secondary channel to refresh configuration data and authentication credentials. Group IB identified 12 victims with evidence suggesting the campaign has been active since early June and primarily targets Israeli organizations. Researchers believe Holograph is part of a broader malware framework and and note technical similarities to the Iran linked threat group Lycium, although they say the current evidence is insufficient for a high confidence attribution. Arctic Wolf warns that affiliates of the Keelin ransomware operation are actively exploiting a critical Palo Alto network's Pan OS global Protect authentication bypass vulnerability to breach corporate networks. The flaw, patched in May, allows attackers to establish unauthorized VPN connections on unpatched systems. Investigations into multiple June incidents found the vulnerability led directly to keyland ransomware deployments ranging from rapid encryption attacks to double extortion campaigns. Researchers believe exploitation is ongoing, urging organizations to patch effective global protect appliances immediately, particularly given the large number of Internet exposed VPN instances. Researchers at Socradar have uncovered a North Korean campaign called Clickfake Interview targeting Web3 and cryptocurrency professionals through fake job recruitment scams attributed to the famous Colima threat Group. The operation uses fraudulent recruiters on LinkedIn, Telegram, Discord and email to lure candidates into fake online interviews. During a staged technical assessment, victims are prompted to run a diagnostic command to fix a fabricated camera or microphone issue, installing malware instead. Windows users receive the Pylang Ghost remote Access Trojan, while macOS users are infected with Golang Ghost and in some cases a credential stealing application. The malware targets browser based cryptocurrency wallets, password managers and sensitive credentials. Researchers warn the campaign also threatens organizations by potentially giving attackers access to corporate systems and digital assets through compromised employees. Zimbra has updated their collaboration suite to address multiple critical and high severity vulnerabilities, including a command injection flaw that could allow unauthenticated attackers to execute operating system commands on vulnerable email servers. The Update also fixes 4 cross site scripting vulnerabilities, a mail forwarding restriction bypass access control and authorization flaws, and a server side forgery issue in the nextcloud integration. While Zimbra has not reported any of the vulnerabilities being exploited in the wild, it is urging customers to upgrade as soon as possible. Security and Legal experts are warning that unauthorized use of artificial intelligence, often called shadow AI, is creating significant regulatory and litigation risks for organizations. The issue gained attention after Community bank in Pennsylvania disclosed that an employee used an unauthorized AI tool to process sensitive customer information, triggering SEC cybersecurity reporting requirements. Despite no external breach or system compromise, experts say AI related incidents increasingly center on unauthorized data exposure rather than traditional hacking, with companies potentially facing state breach notifications, regulatory scrutiny, lawsuits and reputational damage. They recommend integrating AI governance into cybersecurity data governance and incident response programs, while involving legal, finance and business leaders early when assessing materiality. Organizations should also improve visibility into AI use, provide approved alternatives to shadow AI tools, and train employees on responsible AI practices as evolving state laws and litigation risks are expected to persist regardless of future federal regulatory changes. Romania's national agency for cadastre and Real estate advertising is rebuilding its systems after a hacker allegedly breached the agency, failed to extort it and wiped its land registry database. The attack has disrupted Romania's real estate market for more than a week, leaving notaries unable to process property transactions and preventing citizens from accessing land ownership records. According to reports, the attacker used valid credentials to access the network, mapped internal systems and deleted data and backups. After the extortion attempt failed, stolen employee credentials, internal documents and IT network information were later offered for sale online. Officials say they are rebuilding the agency's infrastructure from scratch and appear to have retained offline backups, allowing recovery despite the destructive attacks. Coming up after the break, my conversation with Errol Weiss, chief security officer at the Health isac, setting the record straight on ransomware trends and patching the automotive security system you didn't know you had. Stay with us. Errol Weiss is chief security officer at the Health isac. We recently got together to provide him an opportunity to set the record straight on ransomware trends. Well, Errol, welcome back to the show. I want to share with our audience that during one of my recent 10th anniversary conversations with my co host Maria Vermazes, I offhandedly mentioned that ransomware was decreasing. And I think that made you sit forward in your chair and reach out because that did not track the data that you all were keeping an eye on at the Health isac, right?
C
Yeah. Dave, it's great to be back. Thanks so much for having me. Yeah, when I heard you say that, it reminded me of what happened at the end of 20. Because when we were tracking ransomware back then, there was reports at the end of 2024 saying, hey, great news, ransomware is down across all sectors. Wonderful Stuff. And I looked at the numbers that we had, and I said, you know what? 5743 ransomware victims is not good news. There's nothing to celebrate here. So when you said that, it kind of reminded me a little bit of it. But of course, we've gone a little further from then. But, yeah, the numbers we're tracking right now to continue to tell a bad story when it comes to ransomware, unfortunately.
A
Well, I'm glad you agreed to come and join us and set the record straight here. You know, of course, I look back to see what was it that it could have crossed my mind that I got it so wrong? And I guess some of the things we've been tracking, we've seen a decline in victims paying and perhaps the total criminal revenue. But you're absolutely right. The number of attacks continues to be on the rise.
C
Yeah. And 2026 is already turning out to be another record year, without a doubt. We're already seeing a 17% increase in the first half of 2026 over the second half of 2025 across all sectors. And then in health, we're already at 402 events this year so far. When we look back at 2025 compared to 590, if that trend continues, we'll exceed last year's levels by more than 36%. So it's no doubt going to be a record year.
A
Has there been any shift over the past few years in folks targeting the health care sector?
C
I'm so split on that. Like, in so many ways. I had been saying for a long time that it looked like it was truly the shotgun approach, where the ransomware actors were just launching their spam campaigns, ransomware campaigns, looking for victims across the entire Internet space. And then when they got a victim, they went ahead and tried to figure out how much they can monetize from them. And the victims essentially were from across all sectors. And I think some of that holds true still today, where we're tracking numbers across health care and our victims are still about 6.5% of the overall total when we look at all sectors. And that number, that 6.5% has been pretty steady for the past four years.
A
What does that indicate to you?
C
Well, it is telling me that it's still that shotgun approach. But then strange things happen to maybe double think that again. If we look back at 2024, we had a string of attacks against suppliers in the health sector. And they were wildly successful in ransomware and victims at that point. And they were causing major geographic issues across several Large areas. And it just, it made me think that that seemed to be a little bit more targeted at that point where they were going after suppliers and healthcare and really maximizing the ransomware potential payout.
A
What have you been tracking in the healthcare industry in terms of the sector making themselves a less attractive target to these actors and also increasing their resilience?
C
Yeah, it's a great question. And I think, you know, part of the outcome from all of this ransomware is that it is certainly driving awareness in the with CISOs that I talk to senior leadership of these organizations, driving a lot more awareness in terms of what the threats are and what the real impact could be if like a hospital, for example, gets hit by ransomware. And it's helping that conversation out when it comes to budget and resources that are needed to properly protect these organizations. And I think that one of the biggest challenges that CISOs and information security staff have in the hospital organizations, for example, is having enough adequate resources to properly protect their networks. And it's the technology that's needed, but also probably most importantly, the people, experienced infosec people to properly protect those networks. And that's one of the biggest challenges I think that they have today.
A
Where does the sector stand in terms of being able to attract those experienced people?
C
Yeah, definitely a big challenge still today in the health sector. And I think, interestingly, we just published the 2026 CISO Benchmarking Report and nearly half of the respondents said that budget still is the number one barrier when it comes to workforce recruiting and retention. So still budget challenges. Budgets are getting better, but I think that they're still having issues in terms of being able to attract and retain that talent. 25% said that one of the challenges was hiring skilled talent. So again, it goes back to having the appropriate people with the experiences needed to properly run all of those security systems that we need to properly protect the networks.
A
The health isac, of course, is all about sharing information with your members. How is that mission playing out industry wide? What's the level of collaboration that you're seeing?
C
I came from 13 years in the finance sector after working at places like Citibank and Bank of America, and much to the potential embarrassment of my former colleagues in the finance sector, I would say that the spirit and level of information sharing in the health sector is even better than what we saw happening in the finance sector. I think a lot of it stems from the fact that if you look at these organizations in the health sector, hospitals, medical device manufacturers, and on and on and on, their missions are all about helping people and saving people's lives. And when you look at the IT and security people in those organizations, they believe in that mission. So when it comes to information sharing, there's much more alignment, much more practicality when it comes to wanting to share and work with each other. So I think it all helps us fuel that argument.
A
That's Errol Weiss, Chief Security Officer at the Health isac. Our thanks to him for reaching out and for joining us here today.
D
At the Home Depot. Get up to 15% off all installed carpet projects for a limited time, featuring brands like LifeProof, LifeProof with pet proof Technology, Home Decorators Collection and Traffic Master. Take your pick of carpet built for real life and designed for real comfort. Plus with installations starting as low as $0.49 per square foot and a free measure to get you started, we'll handle the hard parts for you. Offer valid July 16, 2026 through August 2, 2026 exclusion supply for licenses see homedepot.com licensenumbers.
A
This episode is supported by Black Hat usa. If you follow the research, you know a lot of it breaks on Black Hat stages hundreds of peer reviewed briefings, more than 100 hands on trainings, and the largest business hall in Black Hat's history. Six days to learn the skills you'll need tomorrow August 1st to the 6th. Prices increase July 17th, so book before then. Use code CYBERWIRE for $200 off your briefing pass at blackhat.com we'll see you in Vegas. And finally, modern cars increasingly need software updates. But UC San Diego researchers have discovered an unusual twist. Millions of drivers may need to patch a security device they never knew they had. The culprit is the aftermarket car security system, often installed by dealerships before a car is sold. Even when buyers decline the feature, researchers found a flaw that lets anyone within Bluetooth range unlock doors, disable alarms, honk horns, flash lights or even prevent a vehicle from starting. The vulnerability stems from a shared authentication key embedded across all devices. Acrisure Protection Group has released a firmware update, but owners must install it themselves, assuming they know the device exists. Researchers estimate more than 2 million vehicles are affected, calling it one of the broadest automotive security risks to date. And for fans of Knight Rider, there's an ironic footnote here. Car was the show's rogue, malfunctioning counterpart to Kit. It seems this car has also developed a knack for making drivers lives unnecessarily. Interesting.
D
Gideon, let me show you what I
A
can really do, And that's the Cyber Wire for links to all of today's stories, check out our daily briefing@thecyberwire.com we'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire2k.com N2K's lead producers, Liz Stokes, were mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazes. Our executive producer is Jennifer Ibin, Peter Kilpe is our publisher and I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow. Heading to this year's Black Hat USA, the N2K CyberWire team will be on site recording from our podcast studio in the Spectrops Kennel Club. If you're interested in joining us for a conversation or learning more about what we're recording throughout the week, visit sponsor TheCyberWire.com for more information and make sure you stop by the studio and meet the N2K CyberWire team. We'll see you there.
Episode Title: The defense against the AI arts
Date: July 21, 2026
Host: Dave Bittner, N2K Networks
Featured Guest: Errol Weiss, Chief Security Officer at Health-ISAC
Theme: A roundup of pressing cyber threats including AI leadership shakeups, ransomware, novel malware, industry response, and expert insight on ransomware trends and sector resilience.
This episode tackles the fast-evolving landscape of cybersecurity threats, with a special focus on the impacts and regulation of artificial intelligence in security, the escalation of ransomware attacks, new and inventive malware strains, and persistent vulnerabilities affecting organizations worldwide. The show’s centerpiece interview is with Errol Weiss (Health-ISAC), who clarifies misconceptions about ransomware trends in the healthcare sector and discusses workforce and resilience challenges.
[02:01–03:20]
[03:20–04:20]
[04:21–05:20]
[05:21–06:20]
[06:21–07:10]
[07:11–08:15]
[08:16–09:14]
[09:15–10:46]
[10:47–12:01]
[14:24–20:48]
[22:50–23:38]
The episode delivers a comprehensive update on heightened cyberthreats in 2026, reinforcing the persistence of ransomware (especially in healthcare), the complexity of managing AI risks, sophisticated criminal tactics leveraging both tech and social engineering, and sectoral insights on mitigation, talent gaps, and the power of collaboration. Expert guest Errol Weiss’s commentary corrects misconceptions about ransomware’s trajectory and spotlights the ongoing struggle to harden healthcare cybersecurity defenses.