In this Special Episode, Maria Varmazis and Dave Bittner are joined by friend of the show, Brandon Karpf, to unpack a new bipartisan congressional investigation into the lingering presence of Chinese state-owned telecommunications companies inside U.S. internet infrastructure.
The House Select Committee on China says China Mobile, China Unicom, and China Telecom remain deeply embedded in American networks even after federal regulators denied or revoked their authority to provide certain t
In this Special Episode, Maria Varmazis and Dave Bittner are joined by friend of the show, Brandon Karpf, to unpack a new bipartisan congressional investigation into the lingering presence of Chinese state-owned telecommunications companies inside U.S. internet infrastructure.
The House Select Committee on China says China Mobile, China Unicom, and China Telecom remain deeply embedded in American networks even after federal regulators denied or revoked their authority to provide certain telecommunications services over national security concerns. The investigation found that restrictions imposed by the FCC limited what the companies could sell, but did not necessarily remove their equipment, network connections, or commercial relationships from the U.S. internet ecosystem.
The accurate timing data from spacecraft has become an invaluable tool for nearly every critical infrastructure sector and a greater target for malicious actors.
Host Maria Varmazis and Andy Davis, Global Research Director at the NCC Group, discuss the importance of timing in space. The two look at how timing systems have continued to grow more important in everyday life and why attackers have begun to increasingly exploit these critical services.
The accurate timing data from spacecraft has become an invaluable tool for nearly every critical infrastructure sector and a greater target for malicious actors.
Host Maria Varmazis and Andy Davis, Global Research Director at the NCC Group, discuss the importance of timing in space. The two look at how timing systems have continued to grow more important in everyday life and why attackers have begun to increasingly exploit these critical services.
This week on T-Minus: Space-Cyber Briefing: we explore the role of timing in space and how vital these systems are for everyday functionality. Given their importance, attackers have become increasingly aware of how to exploit these systems.
This week on T-Minus: Space-Cyber Briefing: we explore the role of timing in space and how vital these systems are for everyday functionality. Given their importance, attackers have become increasingly aware of how to exploit these systems.
Ismael Valenzuela, Vice President of Labs, Threat Research and Intelligence at Arctic Wolf, sits down with Dave to discuss their work tracking Anubis. Arctic Wolf Labs details a series of 2026 Anubis ransomware intrusions, revealing affiliates using stolen VPN credentials and exploiting CitrixBleed 2 to gain initial access.
Attackers then blended into legitimate IT activity by deploying RMM tools, using RDP and PsExec for lateral movement, stealing credentials, and establishing tunnels and
Ismael Valenzuela, Vice President of Labs, Threat Research and Intelligence at Arctic Wolf, sits down with Dave to discuss their work tracking Anubis. Arctic Wolf Labs details a series of 2026 Anubis ransomware intrusions, revealing affiliates using stolen VPN credentials and exploiting CitrixBleed 2 to gain initial access.
Attackers then blended into legitimate IT activity by deploying RMM tools, using RDP and PsExec for lateral movement, stealing credentials, and establishing tunnels and proxies for persistence and exfiltration. The research highlights a repeatable attack chain defenders can disrupt before encryption, from suspicious remote access and unauthorized RMM deployment to credential theft, security-tool tampering, and ransomware execution.
The G7 and CISA prepare for the quantum threat. Nightmare Eclipse drops a CrowdStrike zero-day. The White House’s offensive hacking plan raises legal questions. CISA offers a playbook for communicating through cyber incidents. OpenAI puts a billion dollars behind AI-powered defense. Researchers uncover a serious PostgreSQL flaw. Google patches an exploited Chrome zero-day. Broadcom fixes VMware vulnerabilities. Attackers target a WordPress plugin flaw. Lawmakers tell license plate surveillance c
The G7 and CISA prepare for the quantum threat. Nightmare Eclipse drops a CrowdStrike zero-day. The White House’s offensive hacking plan raises legal questions. CISA offers a playbook for communicating through cyber incidents. OpenAI puts a billion dollars behind AI-powered defense. Researchers uncover a serious PostgreSQL flaw. Google patches an exploited Chrome zero-day. Broadcom fixes VMware vulnerabilities. Attackers target a WordPress plugin flaw. Lawmakers tell license plate surveillance cameras to “Flock off.” Our guest is Kevin Gosschalk, Founder and CEO of Arkose Labs, discussing his new book, After Bots, which questions the old assumption that automated traffic is inherently malicious. Camouflage for the algorithmic age.
A watchdog challenges the Trump administration’s secret frontier AI reviews. METR discloses two cyberattacks. Leaked documents reveal a Russian cyber training pipeline. Rogue ScreenConnect clients spread malware like a worm. A breach exposes appellate court records across the U.S. and Canada. Spring Ring impersonates IT support on Microsoft Teams. Plex urges users to patch, and Cisco warns of unpatched Secure Email flaws. Our guest is Rob van der Veer, Chief AI Officer at Software Improvement Gr
A watchdog challenges the Trump administration’s secret frontier AI reviews. METR discloses two cyberattacks. Leaked documents reveal a Russian cyber training pipeline. Rogue ScreenConnect clients spread malware like a worm. A breach exposes appellate court records across the U.S. and Canada. Spring Ring impersonates IT support on Microsoft Teams. Plex urges users to patch, and Cisco warns of unpatched Secure Email flaws. Our guest is Rob van der Veer, Chief AI Officer at Software Improvement Group, discussing how we are not keeping up with the AI attack surface. Robocall report cards.
This week, Dave and Ben look at two major AI stories. The first involves Anthropic winning one of its legal challenges regarding the Pentagon designating the company as a supply chain risk. The second story looks at a recent law introduced in Congress that seeks to give CISA the power to force AI kill switch adoption.
This week, Dave and Ben look at two major AI stories. The first involves Anthropic winning one of its legal challenges regarding the Pentagon designating the company as a supply chain risk. The second story looks at a recent law introduced in Congress that seeks to give CISA the power to force AI kill switch adoption.
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phish
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. We start with some follow-up from Anne, who writes in to share how much she enjoys the show, how she used the “Shields Up” message with her coworkers, and—most importantly another chicken update! Maria covers a pair of MyChart scams that use fake medical results and bogus Medicare giveaways to steal credentials, personal information, and payment details. Joe looks at two scams—one targeting a business through a massive Amazon fraud scheme and another warning residents about fake invoices designed to steal their money. Dave explores the surprising value of simply replying to a wrong-number text, as scammers use responses to identify active phone numbers and find potential targets for increasingly sophisticated fraud campaigns. Our Catch of the Day promises a piece of a mysterious $25 million overpayment. All you have to do is reply with your phone number and your desired cut—what could possibly go wrong?
Nexus sells driver’s license scans on the dark web. OpenAI says its models have reached a “Critical” capability threshold. International law enforcement disrupts a decades-old botnet. AI hallucinations fuel “slop squatting.” Plus, urgent patches for Cleo Harmony and Virtualizor, a Texas healthcare breach, and a Russian national accused of targeting thousands of freelancers with remote-access malware. Maria Varmazis shares the latest space-cyber news. Our guest is Rob Allen, Chief Product Officer
Nexus sells driver’s license scans on the dark web. OpenAI says its models have reached a “Critical” capability threshold. International law enforcement disrupts a decades-old botnet. AI hallucinations fuel “slop squatting.” Plus, urgent patches for Cleo Harmony and Virtualizor, a Texas healthcare breach, and a Russian national accused of targeting thousands of freelancers with remote-access malware. Maria Varmazis shares the latest space-cyber news. Our guest is Rob Allen, Chief Product Officer at Threat Locker, talking about protecting against AI in the workplace. AI threatens the government’s bug supply.
Rob Allen, Chief Product Officer at ThreatLocker, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices. Rob discusses how the conversation around agentic AI has quickly shifted from whether organizations should allow these tools to how they can use them safely. He explains why built-in guardrails aren't enough and how external controls, visibility, and a Zero Trust approach can help organizations embrace AI without giving agents unrestricted access to sensitive data
Rob Allen, Chief Product Officer at ThreatLocker, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices. Rob discusses how the conversation around agentic AI has quickly shifted from whether organizations should allow these tools to how they can use them safely. He explains why built-in guardrails aren't enough and how external controls, visibility, and a Zero Trust approach can help organizations embrace AI without giving agents unrestricted access to sensitive data and systems.
Brian Reed has been a CMO six times. He's also watched AI flatten marketing for the past two years and has said so out loud, including in a manifesto he published called AI is Flattening Marketing: Cue the Return of Mad Men.
On this CyberCMO Confidential episode, Brian, Gianna, and Charles Gold get into why storytelling and community are the two things AI cannot commoditize. Brian also talks about how he built a “crusty OT guy” persona to validate messaging authenticity, and what community-driv
Brian Reed has been a CMO six times. He's also watched AI flatten marketing for the past two years and has said so out loud, including in a manifesto he published called AI is Flattening Marketing: Cue the Return of Mad Men.
On this CyberCMO Confidential episode, Brian, Gianna, and Charles Gold get into why storytelling and community are the two things AI cannot commoditize. Brian also talks about how he built a “crusty OT guy” persona to validate messaging authenticity, and what community-driven marketing looks like when your buyers wear steel-toe boots and aren’t online very often.
Nightmare Eclipse drops a Kaspersky zero-day. The Financial Stability Board warns frontier AI could threaten the global financial system. Anthropic says it has tightened security. CISA adopts a risk-based approach to patching. A new Windows infostealer hides in fake AI models. A critical vulnerability in JFrog Artifactory is kneedeep in active exploitation. North Korean workers are still landing U.S. jobs. A classic NSA codebreaking machine. Our guest is Heather Ceylan, CISO at Box, discussing i
Nightmare Eclipse drops a Kaspersky zero-day. The Financial Stability Board warns frontier AI could threaten the global financial system. Anthropic says it has tightened security. CISA adopts a risk-based approach to patching. A new Windows infostealer hides in fake AI models. A critical vulnerability in JFrog Artifactory is kneedeep in active exploitation. North Korean workers are still landing U.S. jobs. A classic NSA codebreaking machine. Our guest is Heather Ceylan, CISO at Box, discussing if AI becomes agentic, governance could become a resilience issue. A robot vacuum sucks up evidence.
Heather Ceylan, CISO at Box, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices to discuss how autonomous AI agents are changing the enterprise risk landscape. She explains why organizations need to govern content, permissions, and agent actions from the start, and how CISOs can create secure pathways for AI adoption that enable innovation rather than stand in its way.
Heather Ceylan, CISO at Box, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices to discuss how autonomous AI agents are changing the enterprise risk landscape. She explains why organizations need to govern content, permissions, and agent actions from the start, and how CISOs can create secure pathways for AI adoption that enable innovation rather than stand in its way.