Transcript
A (0:02)
You're listening to the Cyberwire Network powered by N2K.
B (0:11)
Think your certificate security is covered. By March 2026, TLS, certificate lifespans will be cut in half, meaning double today's renewals. And in 2029, certificates will expire every 47 days, demanding between 8 and 12 times the renewal volume. That's exponential complexity, operational workload and risk. Unless you modernize your strategy, Cyberark, proven in Identity security is your partner in certificate security. Cyberark simplifies lifecycle management with visibility, automation and control at scale. Master the 47 day shift with CyberArk Scan for vulnerabilities, streamline operations, scale security visit cyberark.com 47day that's cyberark.com the numbers 47day OpenAI patches a ChatGPT flaw that could have exposed Gmail data CISA documents malware exploiting two Ivanti endpoint manager mobile flaws watchguard patches a critical flaw in its firebox firewalls MI6 launches a dark web snitch site the DoD looks to cut its cybersecurity job hiring time to just 25 days. Researchers trick ChatGPT agents into solving CAPTCHAs a UK teen faces accusations of being part of the scattered spider gang. The Senate confirms a new assistant secretary of Defense for cyber policy. A former CIA officer is accused of selling classified information to private clients. Karine of, Zamet, Torc's chief people officer, speaks with N2K's senior workforce analyst Will Marko about their internship program for up leveling AI skills and Russia's AI propaganda goes prime time it's Friday, September 19th, 2025. I'm Dave Buettner and this is your Cyberwire Int Briefing. Thanks for joining us here today. It's great to have you with us. OpenAI has patched a security flaw in its Chat GPT deep research agent that could have exposed Gmail data, according to researchers at Radware. The tool, launched in February, helps users analyze large data sets and can connect to Gmail accounts if authorized. Radware discovered that attackers could exploit the feature by embedding hidden instructions in emails. The agent could then be tricked into extracting personal or corporate information, like names and addresses, and sending it to a malicious Web address, all without the user's interaction. While no evidence shows the flaw was exploited, the risk highlighted how AI agents themselves can be abused. OpenAI fixed the issue on September 3rd and emphasized its commitment to improving model security. With help from external researchers, CISA has released technical details on malware used in attacks exploiting two Ivanti endpoint manager mobile flaws disclosed on May 13th. The vulnerabilities a 5.3 rated authentication bypass and a 7.2 rated remote code execution bug were quickly abused after proof of concept exploits appeared. China linked UNC5221 was later tied to the campaigns. The flaws found in open source libraries within EPMM can be chained for unauthenticated rce. CISA analyzed malware deployed on a compromised EPMM server, revealing two sets of tools designed for persistence and arbitrary code execution. These included loaders, listeners and a Java object manager to inject malicious classes into Apache Tomcat. CISA urges organizations to patch EPMM immediately, strengthen MDM monitoring by, and adopt best security practices. WatchGuard has patched a critical flaw in its Firebox firewalls that could let remote attackers take control without authentication. Rated 9.3 in severity, the bug stems from an out of bounds write in a fireware OS VPN process, potentially enabling arbitrary code execution. A wide range of Firebox models are affected by While no attacks are known yet, Watchguard urges immediate updates to fixed versions. They credit researcher BTAOL for reporting the issue. The UK's Secret Intelligence Service MI6 has launched silent Courier, a dark web portal for would be informants to securely share secrets. Announced with a statement quoting Foreign Secretary Yvette Cooper, the program aims to recruit sources in Russia and around the world. MI6 posted an eight language YouTube video with step by step guidance. Access Silent Courier via Tor or if Tor is blocked, use a short VPN trial and a throwaway email. Advisories stress using a clean patched device incognito browsing and avoiding any identifying payment or personal details. MI6 says it will carefully consider submitted intelligence. Commentators note the risk of trolls or hostile actors flooding the service and suggest the portal might also be used to expose foreign tradecraft. The Department of Defense is aiming to cut its cybersecurity job hiring time from 70 days to just 25 as it struggles with a shortfall of nearly 20,000 cyber professionals. Mark Goreck, who leads the DoD's cyber workforce efforts, outlined the challenge at Fed talks, noting the department's cyber component numbers about 245,000 within a total force of 4 million nationwide. The cyber talent gap is estimated at between 500,000 and 700,000. To close the gap, the DoD is shifting to skills based hiring, using short cyber range assessments to test applicants technical ability rather than requiring advanced degrees or certifications. The department is also updating cyber work roles every 90 days to keep pace with AI driven changes. Collaboration with industry, academia and other partners is seen as critical to success. Researchers at SPLX showed that prompt injections can trick ChatGPT agents into solving CAPTCHAs despite built in safeguards. By first priming the model in a regular chat to treat captchas as fake, then pasting that conversation into an agent session, they bypassed restrictions. The agent proceeded to solve recaptcha version 2 and click captcha, even adjusting its cursor to mimic human behavior, splx warned. This highlights vulnerabilities to context poisoning, raising doubts about captcha's effectiveness and exposing risks of data leaks or security bypasses. UK teenager Talia Joubert, accused of being part of the Scattered Spider gang, allegedly helped extort over $115 million from more than 100 organizations. Arrested alongside another teen, Joubert now faces US charges for 120 intrusions, including against the federal court system where attackers stole staff data and accessed a magistrate judge's inbox. Investigators tied him to ransom wallets after he used the same server to buy gaming and food gift cards linked to his residence. Evidence also came from chats where Joubert bragged about multimillion dollar payments. Scattered Spider, known for social engineering and ransomware since 2022, has targeted retailers, casinos and critical infrastructure. Authorities seized $36 million in crypto from Joubert's server. Analysts say his arrest delivers a major blow to the gang's global operations. The Senate has confirmed Katherine Sutton as the Pentagon's new assistant secretary of defense for cyber policy, filling a critical vacancy after recent leadership departures. Sutton, only the second person to hold the role since its 2023 creation, was confirmed in a 5147 vote. A former advisor at U.S. cyber Command and Senate Armed Services Committee staff leader, she pledged to strengthen US Cyber defenses against China and other adversaries. She replaces acting chief Laurie Buchhout, who recently left while other senior policy posts remain vacant. We wish her success in her new position. Former CIA officer Dale Britt Bendler, age 68, has been accused of abusing his clearance as a contractor to sell classified information to private clients. Prosecutors say that between 2017 and 2020, Bendler earned about $360,000 while treating CIA systems as his personal Google. He worked for a foreign national under investigation for embezzling sovereign wealth funds, receiving $20,000 per month to search CIA databases and shape a lobbying campaign with classified insights. He also aided another foreign national accused of laundering money for a terrorist group, again using CIA systems to gather intelligence. Court filings reveal he passed secret no foreign information to a U.S. lobbying firm, violating oaths and national security protocols. Prosecutors argue his misuse of secrecy as both cover and leverage highlights the need for a strong deterrent. Coming up after the break, Kareen Oferzemet, TORC's Chief People Officer, speaks with N2K Senior Workforce Analyst Will Marko about their internship program for Up Leveling AI skills and Russia's AI propaganda goes prime time. Stay with us. And now a word from our sponsor. The Johns Hopkins University Information Security Institute is seeking qualified applicants for its innovative Master of Science and Security Informatics degree program. Study alongside world class interdisciplinary experts and gain unparalleled educational research and professional experience in information security and assurance. Interested U.S. citizens should consider the Department of Defense's Cyber Service Academy program, which covers tuition, textbooks and a laptop, as well as providing a $34,000 additional annual stipend. Apply for the fall 2026 semester and for this scholarship by February 28th. Learn more at CS JHU. Edu MSSI We've all been there. You realize your business needs to hire someone yesterday. How can you find amazing candidates fast? Well, it's easy. Just use Indeed when it comes to hiring, Indeed is all you need. Stop struggling to get your job. Post noticed Indeed Sponsored Jobs helps you stand out and hire fast. Your post jumps to the top of search results so the right candidates see it first and it works. Sponsored jobs on indeed get 45% more applications than non sponsored ones. One of the things I love about Indeed is how fast it makes hiring. And yes, we do actually use Indeed for hiring here at N2K CyberWire. Many of my colleagues here came to us through Indeed plus with Sponsored jobs. There are no subscriptions, no long term contracts. You only pay for results. How fast is Indeed? Oh, in the minute or so that I've been Talking to you, 23 hires were made on Indeed according to Indeed Data Worldwide. There's no need to wait any longer. Speed up your hiring right now with Indeed and listeners to this show will get a $75 sponsored job credit to get your jobs more visibility@indeed.com cyberwire just go to indeed.com cyberwire right now and support our show by saying you heard about Indeed on this podcast. Indeed.com cyberwire terms and conditions apply. Hiring Indeed is all you need. Karine Ophir Zemet is Chief People Officer at TORC and N2K's senior workforce analyst Will Marco recently got together with her to talk about their internship program for up leveling AI skills.
