Loading summary
A
You're listening to the Cyberwire Network powered by N2K.
B
This episode is supported by Black Hat usa. If you follow the research, you know a lot of it breaks on. Black Hat stages hundreds of peer reviewed briefings, more than 100 hands on trainings and the largest business hall in Black Hat's history. Six days to learn the skills you'll need tomorrow, August 1st through the 6th, use code CYBERWIRE for $200 off your briefings pass@blackhat.com we'll see you in Vegas. If you're heading to Black Hat USA this year, make plans to visit the Spectrops Kennel Club. As creators of Bloodhound, the Spectrops team will host talks with OpenAI and the UK AI Security Institute as well as hands on workshops aimed at helping you understand AI accelerated attack paths and the latest in identity trade craft. Visit Spectrops IO to pre register and learn more. SpectreOps Kennel Club is adjacent to Libertine Social inside Mandalay Bay. While you're there, visit the N2K CyberWire podcast studio where where we'll be capturing expert perspectives and conversations from across Black Hat. A Senator targets legacy VPNs Minnesota water systems come under cyber attack A 20 year old flaw exposes 24,000 servers Microsoft debuts its first cybersecurity security AI model A critical velocloud bug is under active attack. The Dysphoria botnet tops 200,000 devices Apple faces a lawsuit over a fake crypto wallet. Denmark builds a cyber resilient banking backup. Google gives threat actors yet another set of names. Our guest is John Chiapetta, Chief Revenue Officer of Zona Systems, discussing the Aviation Cybersecurity GAO report that highlights gaps in FAA network security and hacking. The Admission System in search of a fair chance. It's Tuesday, July 28, 2026, one of my favorite days of the year. I'm Dave Buettner and this is your Cyberwire Intel Brief. Thanks for joining us here today. It's great as always to have you with us. Senator Ron Wyden has urged cisa, the Office of Management and Budget and NIST to take coordinated action to eliminate legacy VPNs from federal networks within two years and require vendors to certify that their remote access products meet zero trust standards to remain eligible for federal contracts. Wyden argues that repeated emergency patching of Internet facing VPN appliances is an unsustainable response to vulnerabilities rooted in their architecture. His proposal calls for CISA to issue a binding operational directive mandating migration NIST to establish technical standards emphasizing outbound only remote access memory, safe programming languages and decentralized key management and OMB to update procurement rules so only compliant products can be purchased by federal agencies and defense contractors. The letter cites multiple nation state campaigns exploiting VPN products from vendors including Avanti, Cisco and Fortinet as evidence that legacy remote access technology has become a recurring national security risk. While the agencies are not obligated to act, the proposal aligns with CISA's recent zero trust guidance and could significantly reshape the federal cybersecurity market if adopted. At least three Minnesota cities Plymouth, South St. Paul and Braham are responding to cyberattacks targeting their water facilities, prompting assistance from state authorities. Plymouth reported attacks on water towers and lift stations, South St. Paul said its water utility system was affected and Bram experienced experienced a brief outage at its water plant before crews restored operations. Officials believe other communities may have also been impacted. Although it remains unclear whether the incidents are connected or the work of a single threat actor, all three cities say the effects have been limited drinking water remains safe and residents can continue normal water use. Minnesota IT Services is coordinating with local, state and federal partners to assess the attacks and share threat intelligence, support response and recovery efforts and determine the full scope of the ongoing investigation. Researchers have identified more than 24,000 Internet exposed servers vulnerable to a long standing weakness in the Intelligent platform management interface 2.0 protocol that can expose password hashes for offline cracking. The flaw stems from a protocol design dating back to 2004 and affects baseboard management controllers, which provide low level remote server administration. LAVA researchers found that about one third of affected systems used weak or predictable credentials, including default passwords, making compromise significantly easier. Because BMCs operate below the operating system, successful attacks can provide deep control over physical servers and potentially broader management environments. The researchers urge organizations to keep IPMI interfaces off the public Internet, rotate default BMC passwords, isolate management networks and disable legacy IPMI authentication. To reduce exposure, Microsoft has introduced Mai CyberOne Flash, its first AI model built specifically for cybersecurity. Designed to identify vulnerabilities in complex code integrated into the company's M Dash Multi Agent platform. The model works alongside larger AI models to improve efficiency while reducing costs by 50%. Microsoft says testing showed the system outperformed competing cybersecurity AI models from Google, OpenAI and Anthropic in vulnerability discovery. Mai CyberOne Flash will be available through Microsoft's Project Perception Security platform, which enters public preview on August 3rd. Arista has confirmed active exploitation of a critical vulnerability affecting its on premises Velo Cloud Orchestrator software. The flaw, with a 10.0 CVSS rating, is an unauthenticated OS command injection vulnerability that can allow attackers to compromise the Orchestrator and potentially gain access to managed Velo Cloud edge devices. Because the web interface is exposed by default, Arista recommends restricting access to trusted management networks and blocking known malicious IP addresses until patches are applied. CISA has added the flaw to its known Exploited Vulnerabilities catalog, underscoring the urgency. The issue does not affect Arista's hosted Velo Cloud service, and patched software versions are now available for affected on premises deployments. Researchers have identified a botnet called Dysphoria that has compromised an estimated 200,000 devices worldwide and is being used for DDoS attacks and traffic relay operations. According to Qianjin XLab, the malware employs a blockchain based command and control mechanism using Ethereum and Solana naming services to make its infrastructure more resilient and difficult to disrupt. Since first appearing in March, Dysphoria has rapidly evolved, adding multi chain support, new command and control techniques, and separate variants for DDoS attacks and proxy services. The botnet spreads by exploiting weak telnet and SSH credentials and known vulnerabilities in routers, cameras and other IoT devices. Researchers recommend patching firmware, changing default passwords, disabling unnecessary remote access, and strengthening device security settings to reduce the risk of compromise. Three Apple users have filed a lawsuit alleging they lost a combined $1.8 million in Bitcoin after downloading a fraudulent Sparrow Wallet application from the App Store. The complaint claims the fake app impersonated the legitimate Desktop Only Cryptocurrency Wallet, tricking users into entering their recovery seed phrases, which attackers then use to steal their funds. The plaintiffs argue Apple failed to adequately review and remove the fraudulent app despite prior warnings from Sparrow Wallet's developer and user reports. Apple said it removed the impersonating apps, terminated the associated developer accounts and provided channels for reporting from fraudulent software. The lawsuit seeks reimbursement for the stolen cryptocurrency damages and court ordered improvements to Apple's App Store review process and fraud warnings in Denmark Denmark's national bank is developing a Dormant Energy bank, an offline backup banking system designed to keep critical financial services running during a major cyber attack. The initiative is part of the central bank's Emergency Preparedness for Critical Financial Sector Activities in Extreme Scenarios strategy introduced in late 2025. If a cyber attack disables a major bank or Denmark's broader banking infrastructure. The DEB would allow businesses and consumers to continue receiving salaries, making transfers and using payment cards until normal operations are restored. The plan also includes a card payment contingency system that enables retailers to accept physical cards and mobile wallets even during prolonged IT outages by storing transactions offline and settling them once connectivity returns. Currently being piloted nationwide, the offline payment capability is expected to be fully operational at grocery stores and pharmacies by the end of this year, Strengthening Denmark's resilience against large scale cyber disruptions Google Threat Intelligence Group has introduced yet another threat actor naming system because the cybersecurity industry apparently didn't have enough aliases to keep track of. Already, the company is replacing numeric identifiers with two word cryptonyms, pairing a memorable name with a category suffix that reflects attribution or motivation. Under the new scheme, China's groups end in Castle, Russia's in Relic, North Korea's in Neptune, Iran's in Ion, and cybercrime gangs in Comet, for example. The group, long tracked by Google as APT44 and by everyone else under a small library of different names will now be known as Sandworm Relic. Google says the new taxonomy is intended to simplify tracking while preserving legacy names, mitre, ATT and CK mappings and other vendor aliases during what is sure to be another industry wide exercise in cross referencing threat actor names. Coming up after the break, my conversation with John Chiapetta from Zona Systems. We're discussing the Aviation cybersecurity GAO report that highlights gaps in FAA network security and hacking the admissions system in search of a fair chance. Stay with us. John Chiapetta is Chief Revenue Officer at Zona Systems. We recently sat down to discuss the Aviation cybersecurity GAO report that highlights gaps in FAA network security.
A
Naturally, this is a very critical industry that is primarily what we serve at Zona. So we are focused on critical industries, generally speaking, energy, even manufacturing. So this certainly falls into the scope of what we focus on now when it comes to the report in itself. It's interesting from a few different perspectives and I think what everybody needs to factor in is these aren't new organizations. It's not a startup which started yesterday. So there's certain things that are inherent to them and some of this is the infrastructure that they have can't be refreshed or turned off or upgraded overnight. And so a lot of these industries are facing relatively similar challenges.
B
Yeah, you know, when I think of aviation, it's kind of, you know that old joke about you have to change the oil while the engine is running and how much harder that is. At the same time, I think we hear lots of stories about aviation having challenges with things like air traffic controllers and the technology that they use. I mean, is this a case of a vertical that is just a little behind when it comes to updating their technology?
A
I wouldn't use the words a little behind necessarily. I think inherently it's an industry that's hard to move. Right. Banking would be another one, energy sector would be another one, and that it's institutionalized. And so, you know, you mentioned kind of change the oil while it's running. I think that's absolutely accurate in the sense of this industry is starting to face the same challenges every other industry is facing right now. But it's new for this industry. These challenges didn't exist when a lot of this infrastructure was set up. And so, you know, it's, yes, it's a technology piece, but it's also a culture piece. And it's. How do you get ahead of that on really both sides at once?
B
Well, I. I know you have a story to share about some work that you did with an airport authority and some of the surprises that you found within their systems.
A
Surprise for me, for sure. Surprise for them, I think, as well. But this was actually driven. And it's related because a few years ago, I want to say it was 2023, TSA came in with a number of changes when it came to cybersecurity best practices guidelines, all that. And at the time, I was engaged with a very large airport authority working on a very similar project to what we do right now. So what we focus on is secure remote access. All of the organizations that we work with, and this is no different, they have systems that they don't manufacture themselves. It helps operate their business, but ultimately they have vendors and contractors and different people who support those systems who may not be on site. And so they need remote access into these systems. And so that was the project we were working on, and we were working with the operations side. So very typically, we'd either work with operations or it slash cyber teams. And, you know, the combination of the two, this was exclusively with the operation side. They were rather frustrated and the frustration that they had. Those individuals are tasked with keeping things moving, keeping the systems running, keeping people moving through the airport, keeping everything secure. And TSA at the time threw a bit of a wrench into that because they say, said, hey, I want you to evaluate how you're doing remote access today. Who's connecting to these Networks, what's going on, get a better handle on that is essentially the message that went out in that process. They were rather frustrated because they had to do that instead of focus on the work that they do on a daily basis, which, as we know, keeps them very busy during that. They found out that they were only working with a number of vendors at this specific point in time. But when they looked at how vendors were accessing the network, there was a number, I think it was upwards of 30 different connections that were still able to access the network. Even though they weren't dealing with those 30 different vendors, they were only dealing with a handful. And so rather surprising to them, certainly surprising to me, because just like you and I, we travel through the airport all the time. We got to jump through all kinds of hurdles. And it's interesting to see these doors were unlocked at the time.
B
What do you suppose that story says about the broader situation that we find in the industry today? Is this. Is this a typical kind of thing defined?
A
It is less and less as the years go on. But again, you're. You're focused on, you know, or certainly we're focused on industries where, if we go back 15, 20 years, they were never connected to the Internet. They were never meant to connect to the Internet. And then Covid certainly expedited that, where all of a sudden, systems that were never meant to connect to the Internet in the first place, you had to connect them because they might be supported by a vendor who's in a different state or a different country. And when something goes wrong, you can't take everything offline. You need them to connect in and fix it right now. And so the way that different organizations address that was relatively the same, which is leverage. What's called a vpn. At the end of the day, that's a big, long ethernet cord. And there's a number of challenges that come along with that. And what they found themselves in is a situation where they didn't have best practices, they didn't have guidelines around that. It was very common for connections to be spun up. But then nobody comes back to the IT team who spun up that connection to say, hey, we no longer work with that vendor. There's no need to have that. Everybody's busy, they got another job to do right after they complete this one. And those compound over the years.
B
So what are your recommendations for organizations to best deal with this particular issue?
A
It's a good question, and I wish there was a one size fits all type of approach to this, but as with anything, IT'S not that simple. What I would say is first you need to understand what is it that's on that network, Right? You need to understand what's behind the doors, what are you ultimately protecting, and then work backwards to say, okay, how do I do this in a way where I'm doing it proactively and not reactively. We hear a lot about, you know, how do we understand the detection and monitoring piece? Well, that piece means something already got in, something already happened. And so how do you look at the front doors to say, how do I guarantee that nothing touches these systems? The article that we're discussing actually mentioned NIST and the zero trust principles and guidelines that NIST produces and the recommendation to follow that pretty tightly. I think that's fantastic. You know, then look at what are your high priority resources that you know, those are the ones that keep you up at night that need to be protected at all costs, who are the privileged users? And then make sure you fully understand how this maps together. But the key thing is be proactive about the security. Do not bake that in as an afterthought.
B
That's John Chiapetta from Zona Systems. And finally, a would be cybersecurity student has ignited an online debate after allegedly hacking the websites of IIT Madras and IIT Kanpur, claiming the intrusion was less about causing damage than making a very pointed admissions appeal. In messages shared on Reddit, the individual said he was rejected from IIT Madras Bachelor of Science in Cybersecurity Program, despite paying the application fee, submitting the required materials, and building years of cybersecurity experience. His central plea All I need is just a fair chance. He also alleged that several program seats went unfilled and claimed, without independent verification, to have accessed sensitive institutional systems. After repeated attempts to report security issues and contact administrators went unanswered, reports of website outages surfaced around the same time, although any connection remains unconfirmed. The episode has divided opinion, with critics condemning the alleged hack, while others questioned whether traditional admissions processes are overlooking practical cybersecurity talent. And that's the second Cyberwire. For links to all of today's stories, check out our daily briefing@thecyberwire.com we'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire2k.com N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazes. Our executive producer is Jennifer Ibin. Peter Kilby is our publisher and I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow. Foreign. Heading to Black Hat USA the N2K CyberWire team will be on site recording from our podcast studio in the Spectrops Kennel Club. If you're interested in joining us for a conversation or learning more about what we're recording throughout the week, stop by the studio and meet the N2K CyberWire team. Spectrops Kennel Club is adjacent to Libertine Social inside Mandalay Bay.
This episode delivers essential daily cybersecurity news updates with a focus on major events, emerging threats, impactful vulnerabilities, and industry developments. It also features an interview with John Chiapetta on gaps in aviation cybersecurity highlighted by the recent GAO report, providing expert analysis and actionable insights.
[02:20]
Notable Quote:
“Wyden argues that repeated emergency patching of Internet facing VPN appliances is an unsustainable response to vulnerabilities rooted in their architecture.”
— Dave Bittner [03:18]
[04:25]
[06:12]
[07:37]
[08:23]
[09:10]
[10:04]
[11:18]
[12:13]
With John Chiapetta, Chief Revenue Officer, Zona Systems
[13:43–21:07]
[21:07]
Packed with critical threat intelligence, policy trends, and expert perspectives, this episode not only highlights current attack campaigns and landmark vulnerabilities but also connects the dots to underlying systemic issues—from legacy infrastructure in critical sectors to the challenges of access management and the evolving nature of cyber resilience efforts. The interview with John Chiapetta offers practical, big-picture advice directly applicable to securing complex operational environments.