3815 episodes
CyberWire Daily at 10: Critical infrastructure attacks over the last 10 years. [Special Edition]
20/09/2026 | 43 mins.In this Special Edition episode, Maria Varmazis and Dave Bittner from N2K Cyberwire get back together to reflect on the past decade of critical infrastructure attacks, evolving threats, and lessons learned from incidents like the Ukraine power grid attack and Colonial Pipeline ransomware. They discuss how these events have shaped current cybersecurity practices and the importance of resilience and preparedness.
Join Maria and Dave as they discuss:
The critical infrastructure evolution over the past 10 years.
Notable cyber attacks including the Ukraine power grid, NotPetya, and the Colonial Pipeline.
The shift from traditional ransomware attacks to attacks on infrastructure.
The emergence of space and satellite communications as targets.
Lessons learned and the future outlook for cybersecurity resilience.- Space infrastructure has become an increasingly important part of everyday life, which has also made it an increasingly attractive target for exploitation.
Host Maria Varmazis and Sean MacKirdy, Area Vice President for the National Security vertical at Elastic Government Solutions, sit down to discuss how space stakeholders need to reevaluate their approach to securing space systems. As space systems continue to grow more important, malicious actors are going to look to target them more often. By adopting a stronger universal framework and a consistent way to interpret data across all spacecraft, space cybersecurity practitioners will be able to standardize their practices and create more effective and timely responses.
Key Sources:
SPARTA v4.0
Maria Varmazis interviews Brandon Bailey about Space Attack Research and Tactic Analysis, or SPARTA matrix.
Like what you heard? Be sure to subscribe to our free Signals and Space Briefing, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space
Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to space@n2k.com. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P
T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com. - Today we are joined by Dr. Renée Burton, VP of Threat Intelligence at Infoblox, discussing their work on Lurking Lizard, "Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real." The research uncovers Lurking Lizard, a threat actor that has operated since at least 2022 by using fake software installers, VPNs, and lookalike domains to secretly turn victims’ devices into residential proxy nodes.
Researchers identified more than 230 related domains and connected seemingly separate campaigns—including fake 7-Zip, downloader tools, and WireVPN—through shared infrastructure, tracking URLs, deployment patterns, and APIs. The investigation suggests the actor runs an end-to-end proxy operation, recruiting compromised devices and then monetizing their bandwidth through proxy services and fake review sites, with WireVPN appearing to be the latest evolution of the campaign.
The research and executive brief can be found here:
Fake Installers, Fake Reviews, Fake Services - Real Proxies, Real Victims - Cisco patches a maximum-severity vulnerability in its Identity Services Engine. Court documents describe AI as “an astonishing theft of unprecedented proportions.” Researchers chain vulnerabilities to take over employee ChatGPT accounts. Microsoft and Check Point patch vulnerabilities. Manufacturing remains ransomware’s favorite target. Hackers compromise a Japanese image-sharing service. The Settra ransomware group leverages remote management software. An Australian think-tank warns of Chinese AI-enabled surveillance in Venezuela. Maria Varmazis joins me for a look back at ten years of critical infrastructure exploits. Everything you wanted to know about AI but were afraid to prompt.
Remember to leave us a 5-star rating and review in your favorite podcast app.
Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.
CyberWire Guest
Dave Bittner and Maria Varmazis reflect on the past decade of critical infrastructure attacks, looking at major incidents like the Ukraine power grid attack and Colonial Pipeline and the lessons they’ve taught the industry about resilience and preparedness. If you enjoyed this conversation, be sure to tune in this Sunday for a special edition of the show, where Dave and Maria continue the conversation.
Selected Reading
Cisco drops another exploited zero-day, this time a perfect 10 (The Register)
‘Doom Loop’: OpenAI and Microsoft Admits LLMs Are Destroying the Web and Built on Theft (404 Media)
AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code (SecurityWeek)
Microsoft Patches 18 Vulnerabilities in AI, Cloud Products (SecurityWeek)
New Check Point flaw lets hackers execute code with root privileges (Bleeping Computer)
Manufacturing Accounts for 22% of all Ransomware Victims (Infosecurity Magazine)
23 Million User Records Compromised in Gyazo Data Breach (SecurityWeek)
Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM (Huntress)
USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech (The Register)
Will A.I. Kill Us? Can It Hack My Bank Account? Your A.I. Questions Answered (New York Times)
Share your feedback.
What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.
Want to hear your company in the show?
N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.
The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. - AI goes to war. Iranian strikes leave AWS data unrecoverable. OpenAI discloses more model misbehavior. Researchers uncover 16 Wireshark vulnerabilities. TrustSink turns Entra authentication into a password trap. RatHat raids Android credentials. The FBI takes down a DDoS-for-hire service. A data broker loses its domains. U.S. Cyber Command names a new AI chief. Ethan Cook is joining Dave Bittner and Ben Yelin to discuss the industry-proposed and administration-opposed AI slowdown. CISA’s field of schemes.
Remember to leave us a 5-star rating and review in your favorite podcast app.
Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.
CyberWire Guest
Today, Ethan Cook, N2K’s lead analyst, joins Dave Bittner and Ben Yelin for a discussion about the industry-proposed and administration-opposed AI slowdown, exploring the policy debate and what it could mean for the future of AI. If you enjoyed this conversation, be sure to check out the full interview on Caveat here.
Selected Reading
The era of AI warfare has arrived (Financial Times)
Iran strikes on Amazon data centers caused permanent loss of customer data (Ars Technica)
OpenAI Discloses Six New Incidents of ‘Concerning' A.I. Behavior (The New York Times)
AISLE Discovers 16 CVEs in Wireshark, the World’s Most Popular Network Protocol Analyzer (AISLE)
TrustSink: How a Rogue External MFA Provider Steals Passwords (Varonis)
RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts (Zimperium)
US takes down NightmareStresser DDoS-for-hire platform (Bleeping Computer)
Data Broker Radaris Loses Domains in Privacy Fight (Krebs on Security)
Former NGA Executive Ronzelle Green Named USCYBERCOM Chief AI Officer (ExecutiveGov)
CISA releases Cyber Decoys guide detailing tripwires, honeytokens to strengthen critical infrastructure detection and response (Industrial Cyber)
Share your feedback.
What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.
Want to hear your company in the show?
N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com.
The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
More News podcasts
Trending News podcasts
About CyberWire Daily
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
Podcast websiteListen to CyberWire Daily, Black Box: The Chatbots and many other podcasts from around the world with the radio.net app
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features

CyberWire Daily
Scan code,
download the app,
start listening.
download the app,
start listening.
CyberWire Daily: Podcasts in Family
























