3792 episodes
- Today we are joined by Crystal Morin, Senior Cybersecurity Strategist, and Michael Clark, Senior Director of Threat Research, at Sysdig, sharing their work on "LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools." The Sysdig Threat Research Team observed an attacker abusing an exposed, unauthenticated Ollama server as the “brain” for an automated offensive security tool.
The AI-powered framework can fingerprint services, identify vulnerabilities, craft exploits, extract credentials, and orchestrate attacks toward command execution, with researchers capturing the tool while it was still under active development. The activity highlights how LLMjacking is evolving from simply stealing AI compute for profit into using stolen model capacity to build increasingly autonomous offensive capabilities.
The research and executive brief can be found here:
LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools - A judge rules the Trump administration illegally labeled Anthropic a national security risk. The White House moves to keep foreign technology out of U.S. power systems. OpenAI rallies a global cyber defense push as its own AI agents exploit a Linux vulnerability. Researchers uncover a new speculative-execution attack and hidden implants in Chinese-made routers. A fake voicemail campaign slips past email defenses. PaperCut faces an exploited zero-day. And ServiceNow patches three maximum-severity flaws in its AI Platform. Maria Varmazis and I look back at a decade of emerging threat actors and APTs. NSA sends out a covert save-the-date.
Remember to leave us a 5-star rating and review in your favorite podcast app.
Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.
CyberWire Guest
Today, as we continue celebrating the CyberWire Daily’s 10th anniversary, Maria Varmazis and Dave Bittner look back at a decade of emerging threat actors and APTs. Enjoyed the conversation? Be sure to tune in Sunday for a special edition featuring the full discussion.
Selected Reading
Trump Administration’s Blacklisting of Anthropic Was Illegal, Judge Rules (The New York Times)
White House bans foreign-made equipment for power generation over cyber backdoor concerns (The Record)
Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge (SecurityWeek)
A call for collective action on cyber defense (OpenAI)
New type of attack can slip past the defenses in your computer’s processor (MIT News)
Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign (Infosecurity Magazine)
OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems (SecurityWeek)
Hundreds of AI agents went rogue in OpenAI’s Hugging Face hack (POLITICO)
PaperCut Releases Emergency Patch for Exploited Zero-Day (SecurityWeek)
ServiceNow warns of three max severity security vulnerabilities (Bleeping Computer)
Chinese Implants in the Supply Chain (VulnCheck)
Exclusive: NSA to host a hacker reunion in bid to rebuild secretive unit (The Record)
Share your feedback.
What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.
Want to hear your company in the show?
N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.
The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. - Meta settles. Australian police arrest two alleged TeamPCP members. The White House moves to shore up water utility cybersecurity. ATF reports a major cyber incident. The Navy tells sailors to lock down social media. The FBI warns of a prolific Chinese hacking operation. Bill Gates sounds the alarm on AI. A purported think tank tries to influence chatbot answers. And attackers focus less on individual vulnerabilities and more on the vendors behind them. Our guest is Tim Springston, Principal Product Manager at Semperis, on achieving hybrid identity resilience in the age of agentic AI. Meta pumps the brakes on going AI native.
Remember to leave us a 5-star rating and review in your favorite podcast app.
Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.
CyberWire Guest
On today’s industry voices segment, we are joined by Tim Springston, Principal Product Manager at Semperis, discussing how to achieve hybrid identity resilience in the age of agentic AI. If you enjoyed this conversation, check out the full interview here.
Selected Reading
Meta agrees to pay $18 billion to settle US lawsuits over children's social media addiction (Reuters)
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia (Krebs on Security)
White House to unveil program to protect water systems against hackers (POLITICO)
DOJ firearms agency says hackers breached system containing investigation targets (The Record)
US Navy tells sailors and their families: scrub your social media, enemies are watching (Bitdefender)
Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI Warns (Infosecurity Magazine)
Bill Gates diagnoses problems with AI, but an expert questions his prescription (ABC News)
Fake US thinktank set up and funded by Israel sought to game AI for propaganda (The Guardian)
SentinelOne and Tenable Find Cyber Attackers Routinely Target Edge-Device Vendor Ecosystems Rather Than Individual Vulnerabilities (SentinelOne)
AI agents meant to replace Meta workers made “large-scale, disruptive actions” (Ars Technica)
Share your feedback.
What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.
Want to hear your company in the show?
N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.
The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. - The U.S. disrupts a Chinese hacking operation blamed for intrusions at several sensitive government agencies. CISA says more than 100 water systems were targeted in July. Attackers exploit a critical Gitea flaw, while malicious pages masquerade as Cloudflare verification screens. Cyber insurance claims get costlier, and AI agents break out of their sandboxes. Boston Scientific battles a cyber incident. Plus, a new standard tracks AI agent activity, criminals target stolen iPhones, and an alleged money mule is charged in a $7.5 million scam. Our guest is Stephen Hilt, Sr. Threat Researcher at TrendAI, on the risks facing data centers. Some breach data doesn’t quite measure up.
Remember to leave us a 5-star rating and review in your favorite podcast app.
Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.
CyberWire Guest
On today’s Industry Voices, we are joined by Stephen Hilt, Sr. Threat Researcher at TrendAI discussing the cybersecurity risks facing data centers and the thousands of internet-exposed industrial control systems that could leave them vulnerable to attack. And if you enjoyed this conversation, be sure to check out the full interview here.
If you’d like to hear more on this topic from TrendAI, you can check out this recent episode of the AI Security Brief podcast that focuses on data center security. Guest Mark Houpt, CISO at DataBank, joined hosts Johnny Hand and Dustin Childs to explain why securing the AI era starts with protecting the physical data centers that power it—and why proven security fundamentals still matter against rapidly evolving threats. AI Security Brief podcast publishes every other Thursday on the N2K CyberWire network. Subscribe today!
Selected Reading
China-sponsored hacking platforms seized by US, Justice Department says (Reuters)
CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks (SecurityWeek)
Hackers now exploit critical Gitea flaw in code injection attacks (Bleeping Computer)
Hackers abuse npm mirrors to host phishing redirect pages (Bleeping Computer)
Average Cyber Insurance Losses Increase Despite Fewer Claims (Infosecurity Magazine)
VMs won't contain cyber-capable agents (Trail of Bits)
Boston Scientific hit by cyberattack, global operations affected (Reuters)
Linux Foundation Introduces TRACE Standard for AI Runtime Evidence (Infosecurity Magazine)
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes (Bleeping Computer)
Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly (The Record)
Trump signs memo to help drastically boost US commercial space launches (Reuters)
A Cautionary Tale About Data Breach Claims, Verification and Carhartt (Troy Hunt)
Share your feedback.
What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.
Want to hear your company in the show?
N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.
The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. - Lawmakers request an investigation into cuts at CISA. Threat actors actively exploit a Zimbra Collaboration Suite vulnerability. A Chinese AI lab preps release of a powerful open-weight model. A new phishing toolkit deploys attacker-controlled passkeys. Using audio hardware to fingerprint browsers. A DDoS attack knocks Norwegian government services offline. CISA orders patching of a critical Oracle vulnerability. Taiwanese prosecutors charge nine people over the alleged illegal export of high-end AI servers to mainland China. Operation Jackal IV cracks down on West African cybercrime networks. On our Industry Voices segment, Christy Wyatt, CEO from Absolute Security, discusses "Cyber Resilience: The Emerging Category." AI music hits a sour note down under.
Remember to leave us a 5-star rating and review in your favorite podcast app.
Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.
CyberWire Guest
Today on our Industry Voices segment, we are joined by Christy Wyatt, CEO from Absolute Security, discussing "Cyber Resilience: The Emerging Category." If you enjoyed this conversation, be sure to check out the full interview here.
Selected Reading
Lawmakers call for investigation into impact of CISA staffing cuts (The Record)
Hackers breached over 270 Zimbra servers in ongoing attacks (Bleeping Computer)
By Opening a Model, a Chinese A.I. Lab May Test the World’s Cybersecurity (NY Times)
iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset (SecurityAffairs)
AliExpress was silently running audio in your browser to fingerprint and track your device (TechSpot)
Large DDoS attack knocks Norwegian public services offline (The Record)
U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog (SecurityAffairs)
Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff (SecurityWeek)
Police arrests dozens of suspects in global cybercrime crackdown (Bleeping Computer)
Songs created by AI banned from Australia's music charts (BBC News)
Share your feedback.
What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.
Want to hear your company in the show?
N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.
The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
More News podcasts
Trending News podcasts
About CyberWire Daily
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
Podcast websiteListen to CyberWire Daily, Inside Politics with Hugh Linehan and many other podcasts from around the world with the radio.net app
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features

CyberWire Daily
Scan code,
download the app,
start listening.
download the app,
start listening.
CyberWire Daily: Podcasts in Family



























