Transcript
A (0:02)
You're listening to the Cyberwire Network powered by N2K. If securing your network feels harder than it should be, you're not imagining it. Modern businesses need strong protection, but they don't always have the time, staff or patience for complex setups. That's where Nord layer comes in. Nordlayer is a toggle ready network security platform built for businesses. It brings VPN access control and threat protection together in one place. No hardware, no complicated configuration. You can deploy it in minutes and be up and running in less than 10. It's built on zero trust principles so only the right people can get access to the right resources. It works across all major platforms, scales easily as your teams grow and integrates with what you already use. And now Nordlayer goes even further through its partnership with CrowdStrike, combining Nordlayer's network security with Falcon Endpoint protection for small and mid sized businesses. Enterprise grade security made manageable Try Nordlayer risk free and get up to 22% off yearly plans plus an extra 10% with the code CYBERWIRE10. Visit nordlayer.com cyberwire daily to learn more. Microsoft rushes an emergency fix for an actively exploited Office Zero day A suspected cyber attack halts rail service in Spain. The FBI probes signal chats in Minnesota. The UK moves to overhaul policing for the cyber age. Romania investigates a hitman for hire site. A UK court awaits awards $4.1 million in a Saudi spyware case. Google agrees to a voice assistance settlement. CISA Maps post quantum crypto readiness Prosecutors charge an Illinois man over a Snapchat hacking scheme targeting hundreds of women. Our guest today is Cynthia Kaiser, senior vice president of the Ransomware Research center at Halcyon, sharing some insight into the AI and quantum threats to cybersecurity and the National Cyber Strategy. And a Best Buy guy tries a creative alib. It's Tuesday, january 27, 2026. I'm dave buettner and this is your cyberwire intel brief. Thanks for joining us here today. It's great to have you with us. Microsoft has issued emergency out of band security updates for an actively exploited zero day vulnerability in Microsoft Office, with a CVSS score of 7.8. The flaw allows attackers to bypass object linking and embedding or OLE security protections by abusing how Office handles untrusted inputs in malicious documents. Exploitation requires a user to open a specially crafted Office file, although the preview pane remains safe. The issue affects multiple Office versions as well as Microsoft 365 apps for enterprise for Microsoft 365 and Office 2021 and later a service side fix is already live and takes effect after restarting the applications. Older versions remain at risk until formal patches are released and users are advised to apply registry based mitigations. In the meantime, according to Microsoft, technical details about the attacks remain limited. Catalonia, Spain faced widespread travel disruption on Monday after a suspected cyber attack shut down regional rail services during the morning rush hour. Commuter and regional trains were abruptly suspended around 6:45am following system failures at Adif, Spain's rail infrastructure manager. Thousands of passengers were stranded, prompting the Catalan government to urge remote work and universities to reschedule exams. Spain's Transport Minister, Oscar Puente said a cyber attack was one possible cause, though this remains unconfirmed. Services later resumed intermittently, according to state rail operators, who cited a major computer malfunction. The incident compounded an already turbulent week for Spanish rail following multiple fatal injuries and injurious accidents nationwide. Barcelona Mayor Juame Colboni called the disruption unacceptable, while opposition figures blamed long term underinvestment and demanded accountability. FBI Director Kash Patel said Monday that the bureau has opened an investigation into Signal Group chats used by Minnesota residents to share information about federal immigration agents, citing concerns that such activity could put agents in danger. Speaking on a conservative podcast, Patel said the probe was prompted by claims that users shared agents locations and license plate numbers, though he did not specify which laws may have been violated. Free speech advocates quickly raised First Amendment concerns, arguing that sharing lawfully obtained information about law enforcement activity is constitutionally protected. Civil liberties groups warned the investigation could chill legitimate speech and public oversight of government actions. The chats hosted on the encrypted app Signal have been used by activists and community members to warn neighbors about immigration and Customs Enforcement activity. Patel acknowledged the free speech implications, but said the FBI would balance constitutional rights with potential violations of federal law. The UK Government has unveiled plans for a sweeping overhaul of policing aimed at tackling the surge in cybercrime, online fraud and other Internet enabled offenses. Proposals from the home office call for creating a new national police Service, described as Britain's equivalent of the FBI, to handle serious and cross border crimes increasingly beyond local forces reach. Officials say roughly 90% of crime now involves a digital element, with fraud accounting for about 44% of recorded offenses. Home Secretary Shabana Mahmood said the reforms reflect how crime has evolved in scale and sophistication, calling them the most significant changes in nearly 200 years. Under the plan, the national crime agency would be absorbed into the new service, while local forces remain focused on neighborhood policing. The government also plans major investments in digital tools, artificial intelligence and national coordination, alongside new oversight for technologies such as facial recognition. Romanian authorities are investigating two nationals suspected of running a hitman for hire website that allegedly allowed users to contract assassins online. Police conducted searches at the request of UK authorities seizing electronic devices, cryptocurrency worth about $650,000 and large sums of cash. Prosecutors say the platform used cryptocurrency and escrow style payments to conceal identities and transactions. The suspects face potential charges, including organized crime, incitement to murder and money laundering. Officials note such sites often prove fraudulent, though investigations are ongoing. A UK court has awarded more than $4.1 million to London based Saudi critic Ganem Al Masarir, ruling that his phones were hacked by spyware linked to the Saudi state judge Pushpinder Seni found a compelling basis that Al Masarir's phones were infected with Pegasus spyware and that the operation was directed or authorized by Saudi Arabia. The court said the hacking enabled extensive surveillance and caused severe psychological harm, forcing Al Nasrir to stop producing his popular YouTube content. Evidence from digital forensics researcher Bill Martzak of the Citizen Lab supported the findings. Saudi Arabia did not contest the case, leading the judge to enter summary judgment, calling the intrusions exceptionally grave invasions of privacy. Google has agreed to pay $68 million to settle a class action lawsuit alleging its voice assistant recorded users conversations without consent and shared them with advertisers. The proposed settlement, filed in federal court in California, awaits approval from U.S. district Judge Beth Labson Freeman. Plaintiffs claimed Google devices recorded private discussions even without the activation phrase. If approved, the fund will cover consumer claims and legal fees, with payouts varying by the number of valid claims. Google did not comment. CISA has released new guidance mapping post quantum cryptography standards to common enterprise hardware and software categories. Issued in response to a June 2025 executive order, the advisory is meant to help CIOs and security teams assess quantum safe readiness and plan long term migration. CISA identifies product classes already using or transitioning toward NIST PQC algorithms, including cloud services, collaboration tools, browsers and some endpoint security products. However, the agency stresses that none are fully quantum resistant. Yet most implementations focus on key establishment, not digital signatures or authentication. The guidance signals that PQC is becoming a practical procurement consideration while highlighting significant gaps enterprises must address as quantum safe standards mature. US Prosecutors have charged Illinois man Kyle Svara with running a phishing scheme that allegedly compromised nearly 600 women's Snapchat accounts between 2020 and 2021. Authorities say he impersonated SNAP employees to steal access codes, download private images, and sell or trade the material online, including via Reddit. One client was former Northeastern University coach Steve Waithy, later convicted of sextortion. Svara now faces federal fraud and identity theft charges and is scheduled to appear in court in Boston. Coming up after the break, my conversation with Cynthia Kaiser from Halcyon. We're talking about AI and quote, quantum threats to cybersecurity and a Best Buy guy tries a creative alibi. Stay with us. What's your 2am Security worry? Is it do I have the right controls in place? Maybe are my vendors secure or the one that really keeps you up at night? How do I get out from under these old tools and manual processes? That's where Vanta comes in. Vanta automates the manual work so you can stop sweating over spreadsheets, chasing audit evidence and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. And it fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit ready all the time. With Vanta, you get everything you need to move faster, scale confidently, and finally, get back to sleep. Get started@vanta.com cyber that's V A N T A dot com cyber. When it comes to mobile application security, good enough is a risk. A recent Survey shows that 72% of organizations reported at least one mobile application security incident last year and 92% of responders reported threat levels have increased in the past two years. Guard Square delivers the highest level of security for your mobile apps without compromising performance, time to market or user experience. Discover how Guard Square provides industry leading security for your Android and iOS apps at www.guardsquare.com. Cynthia Kaiser is Senior Vice President of the Ransomware Research center at Halcyon. I recently sat down with her to discuss AI and quantum threats to cybersecurity and the national Cyber Strategy. So Cynthia, it's always great to have you back. You know, I want to key off of the fact that not too long ago we saw some congressional hearings when it came to AI and quantum threats for cybersecurity. And I wanted to check in with you on that for your reaction to kind of what this indicates, the attention that Congress is taking when it comes to these issues.
