Visualização normal

Hoje — 8 de Setembro de 2026The CyberWire
Ontem — 7 de Setembro de 2026The CyberWire
  • ✇The CyberWire
  • This call may be monitored.
    In this Special Episode, ⁠Maria Varmazis⁠ and ⁠Dave Bittner⁠ are joined by friend of the show, ⁠Brandon Karpf⁠, to unpack a new bipartisan congressional investigation into the lingering presence of Chinese state-owned telecommunications companies inside U.S. internet infrastructure. The House Select Committee on China says China Mobile, China Unicom, and China Telecom remain deeply embedded in American networks even after federal regulators denied or revoked their authority to provide certain t
     

This call may be monitored.

7 de Setembro de 2026, 02:00
In this Special Episode, ⁠Maria Varmazis⁠ and ⁠Dave Bittner⁠ are joined by friend of the show, ⁠Brandon Karpf⁠, to unpack a new bipartisan congressional investigation into the lingering presence of Chinese state-owned telecommunications companies inside U.S. internet infrastructure. The House Select Committee on China says China Mobile, China Unicom, and China Telecom remain deeply embedded in American networks even after federal regulators denied or revoked their authority to provide certain telecommunications services over national security concerns. The investigation found that restrictions imposed by the FCC limited what the companies could sell, but did not necessarily remove their equipment, network connections, or commercial relationships from the U.S. internet ecosystem.

Antes de ontemThe CyberWire
  • ✇The CyberWire
  • CyberWire Daily at 10: A decade of emerging threat actors and APTs.
    In this episode, ⁠Maria Varmazis⁠ and ⁠Dave Bittner⁠ from N2K Cyberwire get back together to discuss the evolution of advanced persistent threats (APTs), threat actor landscape, attribution changes, and the future of cyber espionage over the past decade. Join Dave and Maria as they explore how geopolitical factors, organizational professionalism, and emerging technologies like AI are shaping cybersecurity threats.
     

CyberWire Daily at 10: A decade of emerging threat actors and APTs.

30 de Agosto de 2026, 02:00
In this episode, ⁠Maria Varmazis⁠ and ⁠Dave Bittner⁠ from N2K Cyberwire get back together to discuss the evolution of advanced persistent threats (APTs), threat actor landscape, attribution changes, and the future of cyber espionage over the past decade. Join Dave and Maria as they explore how geopolitical factors, organizational professionalism, and emerging technologies like AI are shaping cybersecurity threats.

  • ✇The CyberWire
  • What does hospital downtime teach us about building AI-native organizations?
    Is your organization truly AI native, or did you just bolt AI onto existing infrastructure? Your answer could be an indicator to how much risk you’re carrying without realizing it. Zach Evans, Chief Technology Officer at Xsolis, has a simple test for telling the difference: strip out the AI and see if your process still works. If it does, you may be exposing your organization to security blind spots and workflows that quietly erode organizational knowledge and skills. Zach joins Johnny Hand an
     

What does hospital downtime teach us about building AI-native organizations?

27 de Agosto de 2026, 02:00
Is your organization truly AI native, or did you just bolt AI onto existing infrastructure? Your answer could be an indicator to how much risk you’re carrying without realizing it. Zach Evans, Chief Technology Officer at Xsolis, has a simple test for telling the difference: strip out the AI and see if your process still works. If it does, you may be exposing your organization to security blind spots and workflows that quietly erode organizational knowledge and skills. Zach joins Johnny Hand and Dustin Childs to unpack what it actually takes to build an AI-native organization, and why the stakes of getting agentic AI wrong can be unforgiving for every organization, not just those in healthcare.

  • ✇The CyberWire
  • JADEPUFFER: An End-to-End Agentic-Led Ransomware Attack
    In this episode of the Microsoft Threat Intelligence Podcast, we are joined by Sysdig’s Michael Clark and Crystal Morin to discuss ⁠JADEPUFFER⁠, one of the first documented cases of an LLM conducting an end-to-end ransomware operation. They break down how the agent, and the direction of a threat actor was identified, how AI is lowering the barrier to entry for ransomware, and why speed and adaptability are changing the threat landscape. Plus, they explore what organizations can do to defend agai
     

JADEPUFFER: An End-to-End Agentic-Led Ransomware Attack

26 de Agosto de 2026, 04:05
In this episode of the Microsoft Threat Intelligence Podcast, we are joined by Sysdig’s Michael Clark and Crystal Morin to discuss ⁠JADEPUFFER⁠, one of the first documented cases of an LLM conducting an end-to-end ransomware operation. They break down how the agent, and the direction of a threat actor was identified, how AI is lowering the barrier to entry for ransomware, and why speed and adaptability are changing the threat landscape. Plus, they explore what organizations can do to defend against AI-powered attacks, from basic security hygiene and exposure management to better understanding their growing AI infrastructure.

  • ✇The CyberWire
  • Frontier models and the future of cyber defense.
    In this special edition from Black Hat, Dave Bittner sits down with ⁠Clint Gibler⁠, Cyber Lead at ⁠OpenAI⁠, and ⁠Robby Winchester⁠, Chief Global Professional Services Officer at ⁠SpecterOps⁠, to explore how frontier AI models are changing the way defenders approach cybersecurity. The conversation moves beyond the hype to examine responsible AI deployment, AI red teaming, reducing noise in security workflows, and the balance between advanced models and human expertise. They also discuss OpenAI’s
     

Frontier models and the future of cyber defense.

16 de Agosto de 2026, 02:00
In this special edition from Black Hat, Dave Bittner sits down with ⁠Clint Gibler⁠, Cyber Lead at ⁠OpenAI⁠, and ⁠Robby Winchester⁠, Chief Global Professional Services Officer at ⁠SpecterOps⁠, to explore how frontier AI models are changing the way defenders approach cybersecurity. The conversation moves beyond the hype to examine responsible AI deployment, AI red teaming, reducing noise in security workflows, and the balance between advanced models and human expertise. They also discuss OpenAI’s Trusted Access for Cyber program and what it takes to give security practitioners access to powerful AI capabilities while managing the risks of misuse.

  • ✇The CyberWire
  • What do AI-driven ‘bank heist’ attacks mean for defenders?
    Attackers aren't just using AI to steal data; they're using it to fight back while you investigate them in real time. And once an adversary is inside, why would they ever want to leave? That's the unsettling reality Tom Kellermann, VP of AI Security and Threat Research at TrendAI, lays out in this episode. And the numbers prove it. According to a 2026 TrendAI survey of 46 financial-sector CISOs, more than 60% of respondents experienced counter-incident response, where adversaries actively disru
     

What do AI-driven ‘bank heist’ attacks mean for defenders?

13 de Agosto de 2026, 02:00
Attackers aren't just using AI to steal data; they're using it to fight back while you investigate them in real time. And once an adversary is inside, why would they ever want to leave? That's the unsettling reality Tom Kellermann, VP of AI Security and Threat Research at TrendAI, lays out in this episode. And the numbers prove it. According to a 2026 TrendAI survey of 46 financial-sector CISOs, more than 60% of respondents experienced counter-incident response, where adversaries actively disrupt live investigations. In addition, nearly 90% of these leaders reported more AI-enabled attacks year over year. Tom joins Johnny Hand and Dustin Childs to explain why the threats that hit banks first tend to hit everyone else next, and what defenders can do about it.

  • ✇The CyberWire
  • Shifts We Are Seeing Across Social Engineering, Post-Disruption Impact Report
    In this episode of the Microsoft Threat Intelligence Podcast, Microsoft Threat Intelligence Director⁠ Elliot Volkman is joined by Microsoft Principal Threat Intelligence Analyst Crane Hassold to explore how phishing and social engineering attacks are changing beyond email. They discuss the rise of QR code phishing, Microsoft Teams scams, SMS-based attacks, and why attackers continue to follow wherever people communicate. Crane also shares practical security recommendations for organizations an
     

Shifts We Are Seeing Across Social Engineering, Post-Disruption Impact Report

12 de Agosto de 2026, 04:05
In this episode of the Microsoft Threat Intelligence Podcast, Microsoft Threat Intelligence Director⁠ Elliot Volkman is joined by Microsoft Principal Threat Intelligence Analyst Crane Hassold to explore how phishing and social engineering attacks are changing beyond email. They discuss the rise of QR code phishing, Microsoft Teams scams, SMS-based attacks, and why attackers continue to follow wherever people communicate. Crane also shares practical security recommendations for organizations and explains how Microsoft's disruption of the Tycoon2FA phishing-as-a-service platform led to a dramatic decline in malicious activity while reshaping the broader phishing landscape.

  • ✇The CyberWire
  • Shifting Security Left
    In this episode of Threat Vector, David Moulton⁠ speaks with two cybersecurity leaders from Palo Alto Networks:⁠ Sarit Tager⁠, Vice President of Product Management, and⁠ Krithivasan Mecheri⁠ (Krithi), Senior Director of Product Security. Together, they dive into the urgent challenges of securing modern development in the age of AI. The discussion explores the rise of Application Security Posture Management (ASPM), how organizations can move from reactive patching to proactive prevention, and the
     

Shifting Security Left

23 de Outubro de 2025, 03:00
In this episode of Threat Vector, David Moulton⁠ speaks with two cybersecurity leaders from Palo Alto Networks:⁠ Sarit Tager⁠, Vice President of Product Management, and⁠ Krithivasan Mecheri⁠ (Krithi), Senior Director of Product Security. Together, they dive into the urgent challenges of securing modern development in the age of AI. The discussion explores the rise of Application Security Posture Management (ASPM), how organizations can move from reactive patching to proactive prevention, and the growing security crisis fueled by AI-generated code. With decades of combined experience in product security, cloud security, and DevSecOps, Sarit and Krithi share strategies for managing security backlogs, aligning executives and developers, and addressing the economics of technical debt. For decision-makers grappling with the balance between speed and resilience, this episode offers essential insights into securing the future of software development.

  • ✇The CyberWire
  • The New Frontlines of Cybersecurity: Lessons from the 2025 Digital Defense Report
    In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by Chloé Messdaghi and Crane Hassold to unpack the key findings of the 2025 Microsoft Digital Defense Report; a comprehensive look at how the cyber threat landscape is accelerating through AI, automation, and industrialized criminal networks. They explore how nation-state operations and cybercrime have fused into a continuous cycle of attack and adaptation, with actors sharing tooling, infrastructure,
     

The New Frontlines of Cybersecurity: Lessons from the 2025 Digital Defense Report

22 de Outubro de 2025, 04:05
In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by Chloé Messdaghi and Crane Hassold to unpack the key findings of the 2025 Microsoft Digital Defense Report; a comprehensive look at how the cyber threat landscape is accelerating through AI, automation, and industrialized criminal networks. They explore how nation-state operations and cybercrime have fused into a continuous cycle of attack and adaptation, with actors sharing tooling, infrastructure, and even business models. The conversation also examines AI’s growing impact, from deepfakes and influence operations to the defensive promise of AI-powered detection, and how identity compromise has become the front door to most intrusions, accounting for over 99% of observed attacks.

  • ✇The CyberWire
  • The changing face of fraud.
    Fraud has always been a consistent challenge. As the world has continued to become increasingly interconnected and as new technologies have become widely available, threat actors have continued to evolve their tactics. In this episode of CISO Perspectives, host ⁠Kim Jones⁠ sits down with Mel Lanning from the Better Business Bureau to discuss fraud and how it has been evolving in recent years. From exploiting cryptocurrencies to utilizing emerging technologies, Kim and Mel look into how threat
     

The changing face of fraud.

21 de Outubro de 2025, 03:00
Fraud has always been a consistent challenge. As the world has continued to become increasingly interconnected and as new technologies have become widely available, threat actors have continued to evolve their tactics. In this episode of CISO Perspectives, host ⁠Kim Jones⁠ sits down with Mel Lanning from the Better Business Bureau to discuss fraud and how it has been evolving in recent years. From exploiting cryptocurrencies to utilizing emerging technologies, Kim and Mel look into how threat actors are changing and refining tactics in the current threat landscape.

  • ✇The CyberWire
  • Securing Pre-K-12: A Tech Leader's Perspective
    In this episode of Threat Vector, ⁠David Moulton⁠ sits down with ⁠Mohammed Saleh⁠, Associate Chief Technology and Management Information Systems Officer at Paterson Public Schools. They explore how school districts can balance cybersecurity, accessibility, and affordability while navigating the evolving threat landscape in K-12 education. Mohammed shares his insights into implementing device management, training programs, and policy changes following a security incident, and how his district use
     

Securing Pre-K-12: A Tech Leader's Perspective

16 de Outubro de 2025, 03:00
In this episode of Threat Vector, ⁠David Moulton⁠ sits down with ⁠Mohammed Saleh⁠, Associate Chief Technology and Management Information Systems Officer at Paterson Public Schools. They explore how school districts can balance cybersecurity, accessibility, and affordability while navigating the evolving threat landscape in K-12 education. Mohammed shares his insights into implementing device management, training programs, and policy changes following a security incident, and how his district uses Chromebooks and SaaS tools to reduce attack surface. This conversation highlights the unique security challenges of public education and the innovative strategies being used to overcome them.

  • ✇The CyberWire
  • From Silos to Solutions: Building Trust Through Transparent Cybersecurity Communications with Microsoft's Frank Shaw
    Frank X. Shaw⁠, Chief Communications Officer at Microsoft, joins Ann on this week's episode of Afternoon Cyber Tea to explore the critical role of communication in cybersecurity. They discuss how transparency and trust shape effective response to cyber incidents, the importance of breaking down silos across teams, and how AI is transforming communication strategies. Frank shares insights on leadership, the power of internal communications, navigating misinformation in an era where perception mat
     

From Silos to Solutions: Building Trust Through Transparent Cybersecurity Communications with Microsoft's Frank Shaw

14 de Outubro de 2025, 04:04
Frank X. Shaw⁠, Chief Communications Officer at Microsoft, joins Ann on this week's episode of Afternoon Cyber Tea to explore the critical role of communication in cybersecurity. They discuss how transparency and trust shape effective response to cyber incidents, the importance of breaking down silos across teams, and how AI is transforming communication strategies. Frank shares insights on leadership, the power of internal communications, navigating misinformation in an era where perception matters as much as technical reality, and why building a culture of security awareness starts with clear, honest messaging—no fluff, no spin.

  • ✇The CyberWire
  • Privacy needs where you least expect it.
    When discussing privacy risks, many often look to implementing strong encryption, secure data storage practices, and data sanitization processes to help ensure sensitive information remains protected. Though these practices are good and should be prioritized, many often miss other key areas that need just as much focus. As the internet of things has only continued to grow larger and larger, so has the risk these devices inherently create as they collect and store more information than many would
     

Privacy needs where you least expect it.

14 de Outubro de 2025, 03:00
When discussing privacy risks, many often look to implementing strong encryption, secure data storage practices, and data sanitization processes to help ensure sensitive information remains protected. Though these practices are good and should be prioritized, many often miss other key areas that need just as much focus. As the internet of things has only continued to grow larger and larger, so has the risk these devices inherently create as they collect and store more information than many would instinctively assume. In this episode of CISO Perspectives, host ⁠Kim Jones⁠ sits down with Merry Marwig, the Vice President of Global Communications & Advocacy at Privacy4Cars, to explore how privacy risks are in places many do not think to look. Together, Merry and Kim discuss why security leaders need to rethink how they approach privacy and consider how the devices we use every day could inadvertently expose our sensitive information.

  • ✇The CyberWire
  • Securing Modern Workforce
    Hybrid work has changed the game, but has your security kept up? In this episode of Threat Vector,⁠ David Moulton⁠ sits down with⁠ Harish Singh⁠, Vice President and Global Head of Infrastructure and Application Management at Wipro, to unpack the evolving cybersecurity landscape at the intersection of digital transformation, SaaS expansion, and AI-powered operations. With decades of experience driving infrastructure modernization and risk mitigation across global enterprises, Harish brings a pra
     

Securing Modern Workforce

9 de Outubro de 2025, 03:00
Hybrid work has changed the game, but has your security kept up? In this episode of Threat Vector,⁠ David Moulton⁠ sits down with⁠ Harish Singh⁠, Vice President and Global Head of Infrastructure and Application Management at Wipro, to unpack the evolving cybersecurity landscape at the intersection of digital transformation, SaaS expansion, and AI-powered operations. With decades of experience driving infrastructure modernization and risk mitigation across global enterprises, Harish brings a pragmatic lens to today’s most urgent challenges. They explore how context-aware SASE, secure enterprise browsers, and automation can reduce security complexity while enhancing user experience. If you're a security leader navigating app sprawl, unmanaged endpoints, or GenAI blind spots—this is your blueprint for staying ahead.

  • ✇The CyberWire
  • Threat Landscape Update: Ransomware-as-a-Service and Advanced Modular Malware
    In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠⁠Sherrod DeGrippo⁠ is joined by Tori Murphy, Anna Seitz, and Chuong Dong to break down two threats: the modular backdoor PipeMagic and Medusa ransomware. They discuss how PipeMagic disguises itself as a ChatGPT desktop app to deliver malware, its sophisticated modular design, and what defenders can do to detect it. The team also explores Medusa’s evolution into a ransomware-as-a-service model, its use of double extortion ta
     

Threat Landscape Update: Ransomware-as-a-Service and Advanced Modular Malware

8 de Outubro de 2025, 04:05
In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠⁠Sherrod DeGrippo⁠ is joined by Tori Murphy, Anna Seitz, and Chuong Dong to break down two threats: the modular backdoor PipeMagic and Medusa ransomware. They discuss how PipeMagic disguises itself as a ChatGPT desktop app to deliver malware, its sophisticated modular design, and what defenders can do to detect it. The team also explores Medusa’s evolution into a ransomware-as-a-service model, its use of double extortion tactics, and the broader threat landscape shaped by ransomware groups, social engineering, and the abuse of legitimate tools.

  • ✇The CyberWire
  • Regulation takeaways with Ethan Cook.
    On this episode, host Kim Jones is joined by Ethan Cook, N2K’s lead analyst and editor, for a deeper, more reflective conversation on cybersecurity regulation, privacy, and the future of policy. This episode steps back from the news cycle to connect the dots and explore where the regulatory landscape is heading — and why it matters. Ethan, who will join the show regularly this season to provide big-picture analysis after major policy conversations, shares his perspective on the evolving balance
     

Regulation takeaways with Ethan Cook.

7 de Outubro de 2025, 03:00
On this episode, host Kim Jones is joined by Ethan Cook, N2K’s lead analyst and editor, for a deeper, more reflective conversation on cybersecurity regulation, privacy, and the future of policy. This episode steps back from the news cycle to connect the dots and explore where the regulatory landscape is heading — and why it matters. Ethan, who will join the show regularly this season to provide big-picture analysis after major policy conversations, shares his perspective on the evolving balance between government oversight, innovation, and individual responsibility.

  • ✇The CyberWire
  • The impact of data privacy on cyber.
    Privacy is one of the most universally valued rights. Yet, despite its importance, data breaches exposing millions of people's sensitive information have become routine. Many have come to assume that their personal data has already been, or inevitably will be, compromised. Despite this reality, prioritizing privacy is more important than ever. In this episode of CISO Perspectives, host ⁠Kim Jones⁠ sits down with Kristy Westphal, the Global Security Director of Spirent Communications, to explor
     

The impact of data privacy on cyber.

7 de Outubro de 2025, 03:00
Privacy is one of the most universally valued rights. Yet, despite its importance, data breaches exposing millions of people's sensitive information have become routine. Many have come to assume that their personal data has already been, or inevitably will be, compromised. Despite this reality, prioritizing privacy is more important than ever. In this episode of CISO Perspectives, host ⁠Kim Jones⁠ sits down with Kristy Westphal, the Global Security Director of Spirent Communications, to explore data privacy's impacts on cybersecurity efforts. Together, Kristy and Kim discuss why privacy cannot be an afterthought but rather must be something actively addressed through proactive security efforts, shifting security culture mindsets, and staying ahead of rapidly changing technologies.

  • ✇The CyberWire
  • 2025 DataTribe Challenge: Forging the future of cyber.
    The ⁠DataTribe Challenge⁠ is a launchpad for elite cybersecurity and cyber-adjacent startups ready to break out. 2025 marks the 8th annual edition of the event with a change in venue and some exciting new updates. We take you on a journey from inception with ⁠Leo Scott⁠, Managing Director and Chief Innovation Officer at ⁠DataTribe⁠, and 3 past DataTribe Challenge winners at different levels on their growth tracks following their participation in the event. You'll meet ⁠Anita D'Amico⁠, former CE
     

2025 DataTribe Challenge: Forging the future of cyber.

5 de Outubro de 2025, 03:00
The ⁠DataTribe Challenge⁠ is a launchpad for elite cybersecurity and cyber-adjacent startups ready to break out. 2025 marks the 8th annual edition of the event with a change in venue and some exciting new updates. We take you on a journey from inception with ⁠Leo Scott⁠, Managing Director and Chief Innovation Officer at ⁠DataTribe⁠, and 3 past DataTribe Challenge winners at different levels on their growth tracks following their participation in the event. You'll meet ⁠Anita D'Amico⁠, former CEO of Code DX (acquired by ⁠Synopsis⁠ in 2021) and 2019 winner; ⁠Greg Baker⁠, Co-Founder of ⁠Balance Theory⁠ and 2022 winner; and ⁠Brian Proctor⁠, Founder and CEO of ⁠Frenos⁠ and 2024 winner.

❌
❌