Search the site
Industry Insights
Podcasts
Briefings
Stories
Events
Glossary
N2K Pro
CISO Perspectives
Podcasts
Briefings
Hash Table
1
st
Principles Course
About
Our Story
Press
Team
Testimonials
Sponsor
Partners
Dev
API
Account
Profile
Logout
Home
Search the site
Industry Insights
Podcasts
Briefings
Stories
Events
Glossary
N2K Pro
CISO Perspectives
Podcasts
Briefings
Hash Table
1
st
Principles Course
Dev
API
About
Our Story
Press
Team
Testimonials
Sponsor
Partners
August 1, 2026
Join Pro
LOGIN
16 hours ago
The driver's seat to ransomware.
This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs." Researchers examine how the Gentlemen ransomware group used a previously unknown zero-day vulnerability in a legacy Windows driver to disable endpoint detection and response (EDR) tools before deploying ransomware. The report details the group's advanced bring-your-own-vulnerable-driver (BYOVD) techniques, which bypass multiple Windows security protections to gain kernel-level access and terminate protected security software. It also outlines defensive measures organizations can take, including enabling Windows Defender Application Control (WDAC), virtualization-based security (VBS), and vulnerable driver blocklists to reduce the risk of similar attacks.
Research Saturday
16 hours ago
The driver's seat to ransomware.
This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs." Researchers examine how the Gentlemen ransomware group used a previously unknown zero-day vulnerability in a legacy Windows driver to disable endpoint detection and response (EDR) tools before deploying ransomware. The report details the group's advanced bring-your-own-vulnerable-driver (BYOVD) techniques, which bypass multiple Windows security protections to gain kernel-level access and terminate protected security software. It also outlines defensive measures organizations can take, including enabling Windows Defender Application Control (WDAC), virtualization-based security (VBS), and vulnerable driver blocklists to reduce the risk of similar attacks.
Research Saturday
Cybersecurity News
T-Minus
16 hours ago
The hidden risks in space supply chains.
As the space ecosystem continues to expand, the sector has become increasingly filled with new suppliers, manufacturers, and operators. However, while this development has led to the introduction of new technologies, it has also greatly expanded space's cyberattack surface. In this week's episode, host Maria Varmazis sits down with Jen Sovada, General Manager of Public Sector at Claroty. During the conversation, the two explore how vulnerabilities within the space supply chain can impact mission assurance. They discuss how the expanding space supply chain ecosystem has expanded the attack surface.
Week that Was
16 hours ago
Claude escaped the testing sandbox three times.
Minnesota cyberattack scale is more extensive than anticipated. OpenAI's agent breached more than Hugging Face. Senator Wyden looks to eliminate legacy VPNs from federal networks. Thailand's Ministry of Finance targeted by autonomous AI agent.
CyberWire Daily
Jul 31, 2026
Claude outside the lines.
Anthropic says Claude escaped the sandbox three times, while a judge questions the Pentagon’s blacklist. The EU launches an AI enforcement team, the FTC targets a telehealth firm’s tracking pixels, and a WordPress backdoor is stopped just in time. CareCloud discloses a major data breach, a stealthy cryptominer hides in plain sight, AiTM phishing surges against law firms, and Finland severs one more digital link to Russia. Our guest is Yan Shoshitaishvili, Associate Professor, Arizona State University, previewing his Black Hat 2026 keynote "Vulnerability Research in the Agentic Age." AI scammers may deserve a promotion.
Daily Briefing
Jul 31, 2026
Claude escaped the testing sandbox three times.
EU launches new team to monitor AI compliance.
CyberWire Daily
Jul 30, 2026
Building a great firewall around AI.
China embraces open AI models, then worries it’s become a national security risk. The cyberattack on Minnesota water systems proves larger than first reported. CISA updates its SBOM guidance. AI supercharges dangling DNS attacks. Researchers uncover a self-propagating Copilot worm. A critical Rails flaw demands urgent patching. Mac users are lured into installing malware through fake Claude guides. Amazon links a string of NPM compromises to North Korea. And Russia charges Telegram founder Pavel Durov with aiding terrorism. Ben Yelin joins us with a border search case that’s breaking new ground. Don’t bite the North Korean hand that feeds you.
Caveat
Jul 30, 2026
OpenAI model was hacking targets for days before being discovered.
FTC launches probe into Shein.
Daily Briefing
Jul 30, 2026
China lists open AI models as national security concern.
Cyberattack on Minnesota water systems more extensive than original estimates.
Caveat
Jul 30, 2026
AI’s latest security wake-up call.
This week, Dave and Ben discuss two major stories. The first story assess the recent incident where a rogue OpenAI agent escaped its environment and successfully targeted Hugging Face. Additionally, the two also look at an incident where a man was targeted after he reportedly wiped his phone using GrapheneOS. Afterwards, Dave sits down with Asha Palmer, SVP of Compliance Solutions at Skillsoft, to look at the lack of any federal AI law in the US.
AI Security Brief
Jul 30, 2026
Is AI security actually a physical problem?
While AI might seem abstract, something that lives in "the cloud" is concrete. The AI applications we use every day run on GPUs in physical buildings, and Mark Houpt secures them. As Chief Information Security Officer at DataBank, he's watched those data centers go from anonymous warehouses to national security targets almost overnight. Mark joins hosts Johnny Hand and Dustin Childs to make the case that the AI era is, at its core, a physical security problem, and why the security fundamentals you already know still work, even when applied to threats that didn't exist two years ago.
Hacking Humans
Jul 30, 2026
Nothing but the spoof.
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. We start with some follow-up on Joe's chicken coop project. Dave covers a new FBI warning about scammers impersonating FBI agents and the IC3 to target fraud victims a second time with convincing deepfakes, fake websites, and recovery scams. Joe shares the story of a retired man who lost £1,800 after two scammers worked together to convince him they were protecting his Amazon account from fraud. Maria breaks down a new UN report revealing that scam networks stole up to $114 billion across Asia-Pacific in 2025 and are evolving into global criminal enterprises powered by specialization and AI. Our Catch of the Day comes from a listener who blames being left unsupervised for one of the funniest scam-baiting exchanges we've seen yet.
CyberWire Daily
Jul 29, 2026
More than meets the AI.
The Senate confirms Jay Clayton to lead ODNI. A new CISA framework highlights critical infrastructure isolation capabilities. OpenAI’s rogue agent breached more than just Hugging Face. The average cost of a data breach continues to rise. Indirect prompt injection proves irresistible to cyber criminals. Broadcom patches multiple VMware products. ShinyHunters claims responsibility for Ernst & Young’s recent breach. Our guest is Sean Zadig, CISO at Yahoo, discussing the impact of AI on the defense side. These aren’t the droids you’re looking for.
Business
Jul 29, 2026
ThreatLocker secures $190 million in a Series F round led by Elephant
Act Security emerged from stealth with $60 million in total fundraising to create an action-centric cloud security platform. Cyera acquires Oasis Security in a $1 billion deal.
Load More
Gain instant access to our exclusive podcast and briefing content, the Pro Academy, live events and more by subscribing to N2K Pro.
Subscribe Now