Loading summary
A
You're listening to the Cyberwire Network powered by N2K. This episode is supported by Black Hat usa. If you follow the research, you know a lot of it breaks on. Black Hat stages hundreds of peer reviewed briefings, more than 100 hands on trainings and the largest business hall in Black Hat's history. Six days to learn the skills you'll need tomorrow, August 1st through the 6th, use code CYBERWIRE for $200 off your briefings pass@blackhat.com we'll see you in Vegas. If you're heading to Black Hat USA this year, make plans to visit the Spectrops Kennel Club. As creators of Bloodhound, the Spectrops team will host talks with OpenAI and the UK AI Security Institute as well as hands on workshops aimed at helping you understand AI accelerated attack paths and the latest in identity trade craft. Visit Spectrops IO to pre register and learn more. SpectreOps Kennel Club is adjacent to Libertine Social inside Mandalay Bay. While you're there, visit the N2K CyberWire podcast studio where where we'll be capturing expert perspectives and conversations from across Black Hat. Hackers target Thailand's Ministry of Finance A new industry alliance hopes to improve AI security golden chickens lay four new malware families GitHub and PyPi introduced Taiwan based safeguards. Sour trade malvertising builds malware directly inside a victim's browser. Attackers target credentials of traveling corporate employees. EDR shutdown is now par for the course for leading ransomware groups. Russian threat actors exploit a Zimbra vulnerability for at least five months before it was patched. We've got your Monday business briefing. Our guest is Krishna SAI, CTO at SolarWinds with security lessons learned from the World cup. And when the feed ends, the fun begins. It's Monday, july 27, 2026. I'm dave bittner and this is your cyberwire intel briefing. Thanks for joining us here today. It's great as always to have you with us. Researchers at Huntio say hackers used an autonomous artificial agent during an apparent cyber espionage campaign targeting Thailand's Ministry of Finance. While the intrusion was underway, the attackers accidentally exposed hundreds of files on their own infrastructure, giving researchers an unusual look inside the operation. The files included malware, stolen credentials, attack scripts, AI agent logs, and evidence that multiple ministry systems had already been compromised. Huntio said the attackers relied heavily on Ermes, an open source AI agent configured to execute commands without human approval. The agent autonomously explored the ministry's network, gathered system information and searched for ways to ESCALATE privileges. Although researchers found no evidence of data exfiltration, the activity appears focused on reconnaissance, credential theft and preparing for future operations. Huntio has not attributed the campaign, but said several indicators suggest the operators were Chinese speaking. Nvidia and Dozens of technology, cybersecurity and enterprise software companies have launched the Open Secure AI Alliance, a new initiative focused on developing and sharing open source tools, models and techniques to improve AI security. The effort builds on work from the Linux Foundation's Akritis initiative and the Open Source Security Foundation. Founding members include major industry players such as Microsoft, IBM, Cisco, CrowdStrike, Palo Alto Networks and Hugging Face. The alliance argues that OpenAI security tools strengthen collective cyber defense and cautions that broad restrictions on open frontier AI could undermine those efforts, researchers say. The operators behind the golden Chickens Malware as a service platform have expanded their toolkit with four new malware families, according to Recorded Futures Insict Group. The new families, Tiny Egg, Chonky Chicken, a modularized Chonky Chicken variant, and Chrome Eggscalator, reflect a significant architectural evolution. Tiny Egg acts as a lightweight backdoor for initial access, while Chonky Chicken adds capabilities such as browser credential theft and live browser session control. The modularized version introduces a plugin based framework that can load 14 capabilities on demand, including key logging, screen capture and process management. Researchers say the move toward modular operator controlled malware improves defense evasion, reduces detection risk and offers customers more flexible capabilities within the malware as a service ecosystem. GitHub and the Python Package Index have introduced new time based safeguards designed to reduce software supply chain risk. GitHub's Dependabot now applies a default three day delay notice before automatically recommending newly released package updates, giving security researchers and maintainers more time to identify and remove malicious packages before they're widely adopted. The delay is configurable, and GitHub continues to recommend additional protections such as dependency pinning, restricted access tokens and limiting installation scripts. Meanwhile, PYPI will no longer allow maintainers to add new files to package releases more than 14 days after publication. The change is intended to prevent attackers from compromising trusted older releases, a technique known as release poisoning, even though no confirmed PIPI attacks have used that method to date, researchers at Confiant say. The Sour Trade Malvertising campaign has adopted a new technique that builds malware directly inside a victim's browser to evade detection. Active since 2024, the operation impersonates popular trading and cryptocurrency platforms including TradingView, Solana and Luno to lure investors with fake trading tips and cryptocurrency giveaways. Instead of delivering a complete malware file, the malicious site sends assembly instructions, downloads clean components from separate infrastructure, and reconstructs the final infostealer in the browser's memory. Because no complete malware file is transmitted over the network, traditional file based security tools are less likely to detect the attack. Researchers say the approach allows sour trade to vary the payload by victim or session, making the campaign more difficult to identify and disrupt. Researchers at RelayaQuest warn that attackers are compromising public WI fi gateway appliances used for captive portal Networks to steal Microsoft 365 credentials from traveling corporate employees. Active since at least June, the campaign targets WI fi systems at hotels, conference centers and other shared venues by altering DNS settings to redirect users to attacker controlled infrastructure. Using an adversary in the middle technique, the attackers can intercept traffic and harvest login credentials. ReliaQuest observed victims across multiple industries including financial services, health, healthcare, energy and retail, suggesting broad targeting rather than a sector specific campaign. While the activity resembles the previously reported Frost Armada operation linked to APT28, researchers say differences in infrastructure and tactics indicate either a separate threat actor or one reusing elements of APT28's trade craft. Researchers at Halcyon warn that disabling Endpoint Detection and Response, or EDR tools before encrypting systems has become standard practice for leading ransomware groups, significantly reducing defenders response time. The company's second quarter 2026 ransomware evolution report found that some groups, including the gentlemen, now build EDR and antivirus shutdown capabilities directly into their attack chains. Halcyon says the gentleman has incorporated techniques from other major ransomware families to improve encryption, code obfuscation and security. Tool evasion Although publicly claimed ransomware attacks declined 5.7% during the quarter, researchers observed increasingly sophisticated operations including rapid attacks, greater use of artificial intelligence throughout the attack chain and and continued exploitation of enterprise edge vulnerabilities. The report concludes that ransomware is becoming faster, more automated and more difficult to detect and contain. Proofpoint says Russia aligned threat actor TA488 exploited a previously unknown vulnerability in Zimbra collaboration suite mail servers for at least five months before it was patched. The group also used a so called half click exploit requiring victims only to open or preview a malicious email to trigger embedded code. According to Proofpoint, the attacks targeted Ukrainian government organizations as well as US government, defense and scientific entities. After gaining access, TA488 deployed malware dubbed Ximreaper to steal credentials, establish persistent access and exfiltrate emails from compromised accounts. Researchers say the campaign relied on obfuscated JavaScript, DNS based data exfiltration and app specific passwords to maintain access. Proofpoint assesses the activity as linked to Russian intelligence and notes the operation underscores continued targeting of webmail platforms for cyber espionage. Turning to our Monday business briefing, cybersecurity investment remained strong last week led by Israeli endpoint security startup Glo, which emerged from stealth with $180 million to expand US operations and research. Other major funding rounds included Neo with $100 million for Agentix software security, Riskledger with $32.2 million for AI enabled supply chain security 20 with an additional $30 million for offensive cyber technology and Empirical Security with $25 million for predictive vulnerability management. Smaller investments supported companies focused on security telemetry, autonomous penetration testing, identity verification, post quantum security, deepfake detection, email security and open source software security. Mergers and acquisitions were also active, with Palo Alto Networks announcing plans to acquire observability provider Embrace Aura, completing its acquisition of Coria and Veridas, agreeing to merge with fourthline. Additional acquisitions by Ningio, webisea and Amplex highlight continued industry consolidation as vendors broaden capabilities across software, security, identity training, procurement and digital risk management. Be sure to check out our complete Cyberwire Pro business briefing. You can find that on our website. Coming up after the break, my conversation with Krishna SAI, CTO at SolarWinds. We're discussing security lessons learned from the World cup and when the feed ends, the fun begins. Stay with us. Krishna Sai is Chief technology officer at SolarWinds. We recently got together to discuss some of the security lessons to be learned from the World Cup.
B
You know, whenever there's an event like the World cup it is very exciting. You have millions of people now actively involved in this and if you think about where the lens of a modern enterprise IT teams which has the challenge of supporting all the infrastructure and operations that goes towards making an event like this very successful. There are so many dimensions of that that happened like folks are streaming matches, using personal devices, accessing variety of cloud services to not only integrate and get themselves engaged with all the things that go on with a World cup like event. Responding to messages, participating in social media, there's a lot of activity that happens. All of this of course creates more traffic, but it also creates a lot of noise and you know when I wear my say security or IT ops angle that becomes a great environment for both a lot of excitement and energy, but also creates unique challenges for the folks who have the responsibility to keep this infrastructure alive so that an event like this can be successful. So there's a lot that goes on through that where, especially when it comes to, from a security perspective, the ability to distinguish excitement from all the challenges of congestions of networks, misconfiguration, fraud, active attacks, and so on. So there are a lot of positives and energies, which we're all excited about. But from an operations perspective, there's a lot of new challenges for IT and OPS teams as well.
A
One of the things I was thinking about in anticipation of our call was how, because this is an event that happens every few years, does that mean that this is a team that isn't working together all the time? But then I also thought, well, maybe this is one of those situations where as soon as one event finishes, they're on the preparation schedule for the next one, even though it's a few years down the road.
B
No, absolutely. And what happens is that when you think about what it takes to support an event like this in terms of systems and peoples and technology and processes, these are burst events, right? Like that happen and suddenly the infrastructure happens. And we see this in other places as well. Whenever there's a sports event, when there's a big music event as an example, our key celebrations and so on. And that's where I think the system needs to have a lot of the core characteristics that goes into being ready, so to speak, for an event like this or plan for the next event. That includes variety of things which include systems, people, processes and so on. But IT systems, which are the infrastructure systems that need to support this, have like a few characteristics. I mean, since we're talking about the World cup using an analogy like that, right. You need the ability to have observability, the ability to look at the whole field like the way Messi does as an example, you need agility to be able to respond, elasticity as conditions change, like Lamaine Emal as an example, right. Or you need Ronaldo's like reliability and discipline, where your systems and processes are matured, where you do have the ability to have an operationalizer system, you need be able to perform at scale. You need to have precision in being able to act on the right signals so that you can respond better. So I think a lot of these types of things that happen, of course, it's a team sport. Taking another soccer analogy, which means that in your systems you need to have layered controls, have the right communication paradigms, have the right levels of security overlays, whether it's related to identity or Threat vectors and so on. But I think from a system perspective, continually thinking about how the various aspects of your operations, network applications, cloud identity, databases, signals, so that they all come together and form this team sport is a very, very important aspect of how you need to actually think and plan for events like these.
A
What are the lessons that enterprise defenders can take from this? I think about things like resilience and availability with a major event like this. But those lessons can translate to the day to day of regular everyday folks.
B
100% right. Like the core challenges have continually, if you think about it, teams that prepare for demand spikes and address visibility gaps. And not only during events like this, but just in day to day operations, these types of events become forcing functions where teams can elevate their maturity levels or get prepared with new tools and processes and so on. But essentially the preparation is always the same, which is identifying key business services that you need in your day to day services that cannot fail. Like what do you need to do to protect, from a security perspective, identity for organizations, VPN access, collaboration tools, customer facing applications, and all the day to day workloads that IT and ops teams have to manage. And then be able to have a view of ensuring that you have complete visibility across the workloads that you need to manage and the service and dependencies tied to business outcomes so that you're able to put the systems and processes in place, whether that is observability tools or incident response tools, or big cloud operations tools, et cetera, that you need to be able to tackle ongoing challenges like this. But at the end of the day, it all maps down to how teams are able to shape themselves and mature themselves to be able to map business outcomes to tried and tested methodologies in terms of how you operationalize your IT and infrastructure across the board.
A
Well, let's extend the metaphor to building teams itself. Folks have sometimes they go out looking for superstars, or I think people refer to them sometimes as unicorns when they're out there trying to find that perfect person to hire for their team. And that extends to athletics as well, but at the same team at the same time. Rather, you need some balance there as well.
B
Absolutely. I mean, and that's why I keep reinforcing that this is a team sport and we see this in the soccer field all the time. The superstars are not only the ones that actually score the goals, but you know, oftentimes it's the assets that matter. Right. And we see this balance across teams as well. And it's so important. And that's why I think having a good understanding of what your the team shape is and how your team actually comes together to tackle a business outcome. Whether that is being able to respond to an event like this in terms of supporting the bandwidth requirements for streaming an event, or dealing with how do you deal with phishing attacks that may increase as a result of an event like this as part of your security team, or being able to ensure that you have adequate failover when systems fail to be able to respond to them quickly, whether that is through automation or through incident response. Like all of these things essentially come together in terms of how your teams are able to shape those business outcomes and have processes and tools in place to be able to tackle them.
A
That's Krishna Sai from SolarWinds. And finally, a week long New York festival called the Summer of Lud set out to prove that meaningful community doesn't require social media, smartphones or big tech platforms. Organized entirely through phone hotlines, posters, bookstores and word of mouth, the event featured phone free raves, workshops, theatrical protests and plenty of handmade gnome hats. One highlight was a mock trial of OpenAI and CEO Sam Altman, ending with participants gleefully stomping a giant cardboard smartphone because apparently the cardboard had it coming. Beneath the playful absurdity was a serious rebuild community through shared in person experiences rather than algorithm driven feeds. Organizers argued that public events, not viral posts, are the foundation of lasting social movements. While acknowledging the challenge of resisting commercialization and digital capture, the festival embraced joy over cynicism, suggesting that the most Radical act in 2026 might simply be showing up, looking around and leaving your phone in your pocket. And that's the Cyber Wire. For links to all of today's stories, check out our daily briefing@thecyberwire.com don't forget to check out the Grumpy Old Geeks podcast where I contribute to a regular segment on Jason and Brian Show. Every week. You can find Grumpy Old Geeks, where all the fine podcasts are listed. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or or send an email to cyberwire2k.com N2K's lead producers, Liz Stokes, were mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazes, our executive producer is Jennifer Ibin, Peter Kilpe is our publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow. Heading to Black Hat USA, the N2K CyberWire team will be on site recording from our podcast studio in the Spectrops Kennel Club. If you're interested in joining us for a conversation or learning more about what we're recording throughout the week, stop by the studio and meet the N2K CyberWire team. Spectrops Kennel Club is adjacent to Libertine Social inside Mandalay Bay.
Date: July 27, 2026
Host: Dave Bittner (N2K Networks)
Guest Interview: Krishna Sai, CTO, SolarWinds
This episode covers the latest in cybersecurity news, focusing on a rare operational blunder by hackers that exposed their own cyber espionage campaign, new trends in AI security, evolving malware and ransomware tactics, and how major events like the World Cup stress test both IT infrastructure and security teams. Notable industry deals and a unique social experiment in community-building without digital tech cap the broadcast. An interview with Krishna Sai provides deep insights into translating lessons from world-scale sports events to everyday security and IT operations.
"The attackers accidentally exposed hundreds of files on their own infrastructure, giving researchers an unusual look inside the operation." (A, 01:08)
Start: [14:02]
Highlights & Takeaways:
"The attackers accidentally exposed hundreds of files on their own infrastructure, giving researchers an unusual look inside the operation."
— Host (A), [01:08]
"You need the ability to have observability, the ability to look at the whole field like the way Messi does... elasticity as conditions change, like Lamine Yamal... Ronaldo's reliability and discipline...”
— Krishna Sai (B), [16:51]
“These types of events become forcing functions where teams can elevate their maturity levels or get prepared with new tools and processes…”
— Krishna Sai (B), [18:48]
“The superstars are not only the ones that actually score the goals, but ... it’s the assets that matter. Right. And we see this balance across teams as well.”
— Krishna Sai (B), [21:04]
| Segment | Timestamp | |--------------------------------------------------------|--------------| | Hacker OpSec Failure & Espionage Campaign | 00:55–03:00 | | Open Secure AI Alliance Launch | 03:00–04:00 | | Golden Chickens Malware Developments | 04:00–05:00 | | Software Supply Chain Safeguards (GitHub/PyPI) | 05:00–06:30 | | Sour Trade Malvertising Innovation | 06:30–07:30 | | Public Wi-Fi Gateway Attacks | 07:30–08:30 | | Ransomware EDR Shutdown Standardization | 08:30–10:00 | | Russian Exploitation of Zimbra | 10:00–11:30 | | Cybersecurity Investments + M&A | 11:30–13:20 | | Interview: Krishna Sai – IT Lessons from the World Cup | 14:02–22:12 | | Notable Community: "Summer of Lud" | 22:12–end |
This episode delivers a panorama of shifting cyber threats, defensive collaboration, and operational challenges, all punctuated by practical wisdom from both incident analysis and big-event IT management. Krishna Sai’s insights remind listeners that whether facing World Cup-scale surges or daily operations, successful defense relies on preparation, visibility, teamwork, and continual adaptation—a winning playbook for both sports and cybersecurity.