The CyberWire Daily Podcast 6.12.26
Ep 2572 | 6.12.26

Deadline-driven defense.

Transcript

CISA directs agencies to “patch smarter, not harder.” The House fails to extend FISA. Europol pulls over AudiA6. GitHub announces npm security updates. Anthropic rejects Fable 5 jailbreak claims. CISA gives feds three days to patch a critical Ivanti Sentry vulnerability. Google confirms ShinyHunters exploited a critical Oracle PeopleSoft vulnerability. FancyBear shifts part of its infrastructure to compromised edge devices. Pundits push for CyberCorps scholarship budgets. Our guest is Dr. Renée Burton, VP of Threat Intelligence at Infoblox, to discuss scams targeting the World Cup. Amazon drivers sweat through a software update.

Today is Friday June 12th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

CISA directs agencies to “patch smarter, not harder.” 

CISA has issued a new directive that requires federal agencies to prioritize vulnerability remediation based on four key risk factors: whether a vulnerability affects a public-facing asset, can be exploited automatically, enables full system compromise, or is being actively exploited in the wild. The move reflects a broader shift toward risk-based vulnerability management, which CISA describes as “patch smarter, not harder.”

Under the directive, vulnerabilities meeting all four criteria must be fixed within three days, and agencies must conduct forensic reviews to check for potential compromise. Agencies are also required to update vulnerability management policies immediately, revise remediation processes within 60 days, and fully comply with the new timelines within 180 days.

CISA says the policy is driven in part by artificial intelligence accelerating the discovery and weaponization of software flaws. Officials argue that focusing resources on the most dangerous vulnerabilities will improve security outcomes and reduce patching burdens. While the directive applies only to federal agencies, CISA is encouraging private-sector organizations to adopt a similar risk-based approach. Industry experts generally support the move, though some question whether aggressive three-day remediation deadlines will be achievable at scale.

The House fails to extend FISA. 

A House of Representatives effort to temporarily extend Section 702 of the Foreign Intelligence Surveillance Act (FISA) failed Thursday in a 218-198 vote, likely allowing the surveillance authority to expire for the first time since its creation after 9/11. Nineteen Republicans joined nearly all Democrats in opposing the measure.

The dispute centered on President Trump’s appointment of Bill Pulte, a mortgage agency director with no national security background, as acting director of national intelligence. Democrats argued that extending surveillance powers while Pulte oversees the intelligence community would pose a greater risk than allowing the program to lapse. Republicans countered that Section 702 is vital to national security and provides critical intelligence on foreign threats.

The failed vote came just before Trump nominated former SEC Chair Jay Clayton as a permanent intelligence chief. While a FISA court has ruled that Section 702 operations can continue temporarily even without congressional renewal, uncertainty remains over whether telecommunications providers will continue cooperating absent explicit legal authorization. The episode highlights ongoing tensions between national security priorities, privacy concerns, and political battles over intelligence oversight.

Europol pulls over AudiA6. 

An international law enforcement operation has dismantled “AudiA6,” a cryptocurrency laundering service accused of processing more than €336 million in illicit funds between 2022 and 2025 for ransomware gangs and other cybercriminals. Authorities believe the service acted as a major financial hub for criminals seeking to conceal the origins of stolen cryptocurrency.

The coordinated action, led by agencies including the U.S. Secret Service, IRS Criminal Investigation, Polish Police, Europol, and Eurojust, resulted in the arrest of two alleged administrators in Georgia, the seizure of more than 30 servers, takedown of 25 domains, confiscation of vehicles and properties, and the freezing or seizure of cryptocurrency assets.

Investigators say AudiA6 operated a professional laundering scheme using thousands of fraudulent exchange accounts and more than 6,000 Know Your Customer records tied to money mules. Europol linked the service to over 15 ransomware and cryptocurrency theft investigations worldwide. The case highlights the growing professionalization of crypto laundering, which has become a critical support service for the global cybercrime ecosystem.

GitHub announces npm security updates. 

GitHub’s npm team has announced major security changes coming in npm v12, scheduled for release in July 2026, aimed at reducing software supply chain attacks by shifting from implicit trust to explicit approval. The update will block three previously permitted behaviors by default: automatic execution of install scripts, dependencies pulled directly from Git repositories, and packages sourced from remote URLs outside official registries.

Developers can prepare now by upgrading to npm 11.16.0 or later, which includes warnings and a new npm approve-scripts tool for creating allowlists of trusted scripts.

Security experts largely welcomed the changes. Semgrep CEO Isaac Evans said stronger defaults are needed as supply chain attacks become cheaper and easier to execute. However, researchers also warned of potential downsides. Paul McCarty cautioned that developers may simply approve blocked scripts to avoid workflow disruptions, while attackers could shift their focus to private software repositories or hide malicious activity among legitimate workarounds created to bypass the new restrictions.

Anthropic rejects Fable 5 jailbreak claims. 

Anthropic has rejected claims that its newly released Claude Fable 5 model was successfully jailbroken. Researcher Pliny the Liberator claimed to bypass safety restrictions using advanced prompting techniques and published screenshots and an alleged system prompt. Anthropic responded that the examples did not demonstrate a true jailbreak, which would require bypassing independent safety classifiers and enabling meaningful assistance for high-risk activities. The company said some outputs were not generated by Fable 5, while others contained only publicly available information. Anthropic added that extensive red-teaming and post-release reviews found no evidence that its core safeguards had been circumvented.

CISA gives feds three days to patch a critical Ivanti Sentry vulnerability. 

CISA has ordered federal agencies to patch a critical Ivanti Sentry vulnerability, tracked as CVE-2026-10520, within three days under its new Binding Operational Directive 26-04. The maximum-severity flaw is an OS command injection vulnerability affecting Ivanti’s security gateway appliance, formerly known as MobileIron Sentry. The directive follows reports from Shadowserver that attackers had already compromised numerous internet-exposed Sentry gateways, just one day after Ivanti released patches and stated it had no evidence of active exploitation. The move highlights CISA’s new emphasis on rapid remediation of actively exploited, high-risk vulnerabilities.

Google confirms ShinyHunters exploited a critical Oracle PeopleSoft vulnerability. 

Google has confirmed that the ShinyHunters threat group exploited a critical Oracle PeopleSoft vulnerability, CVE-2026-35273, as a zero-day to steal data from organizations before mitigations were released. The unauthenticated remote code execution flaw affects PeopleSoft Enterprise PeopleTools and related applications. According to Mandiant and Google Threat Intelligence Group, attacks occurred between May 27 and June 9, primarily targeting higher education institutions. Google notified more than 100 potentially exposed organizations, with some experiencing data theft. The University of Nottingham is the first confirmed victim. Oracle has issued mitigations, but patches do not yet appear to be available.

FancyBear shifts part of its infrastructure to compromised edge devices. 

Researchers from Sekoia’s Threat Detection & Research (TDR) team report that the Russian GRU-linked APT28 group has shifted part of its infrastructure to compromised edge devices, including Ubiquiti EdgeRouters infected with the MooBot botnet and routers targeted in its FrostArmada campaign. Rather than relying primarily on cloud servers, APT28 is using compromised routers to relay stolen credentials, host phishing pages, proxy authentication traffic, and support mailbox takeover operations.

The approach provides stealth, resilience, and geographic diversity by blending malicious activity with legitimate residential and small-business internet traffic. Researchers also observed DNS hijacking techniques that redirect users to attacker-controlled infrastructure, enabling interception of authentication flows and potential theft of OAuth tokens.

Despite past law enforcement disruptions, compromised edge devices continue to support operations. The findings highlight the growing importance of securing routers, monitoring DNS changes, and detecting unusual authentication activity.

Pundits push for CyberCorps scholarship budgets. 

An opinion piece coauthored by retired Rear Admiral Mark Montgomery and Sophie McDowall from Foundation for Defense of Democracies argues that the federal CyberCorps: Scholarship for Service program is critical to preparing the U.S. cybersecurity workforce for the growing impact of artificial intelligence. The program, which has placed nearly 5,000 cybersecurity professionals into government roles over the past 25 years, provides scholarships and training in exchange for federal service.

The authors contend that AI is accelerating both cyber defense and cyber threats, making specialized expertise increasingly important. In response, CyberCorps now requires participants to develop skills in both applying AI to cybersecurity operations and securing AI systems themselves.

The piece criticizes the Trump administration’s proposed budget cuts, which would reduce program funding from congressional levels of roughly $63 million to $21.7 million. The authors praise Congress for restoring funding and encouraging greater AI integration, arguing that expanding CyberCorps is essential to addressing government cybersecurity workforce shortages and preparing for future AI-driven threats.

Amazon drivers sweat through a software update. 

Amazon delivery drivers are voicing frustration over a recent software update to Rivian-built electric delivery vans that changes how air conditioning operates during stops. Drivers say the system now shuts off cabin cooling if the sliding door remains open and the driver is out of the seat for more than 30 seconds, a common occurrence on routes that involve constant hopping in and out of the vehicle.

Amazon disputes the characterization, arguing the update actually extends climate control by keeping the AC running for up to 10 minutes after a driver exits, with the timer resetting at each stop. The catch, however, is that leaving the side door open triggers a battery-saving shutdown after 30 seconds.

For drivers racing through summer deliveries, that distinction feels a bit academic. Many say they spend more time outside the van than inside it, meaning the cabin often has ample opportunity to reheat itself between stops. In theory, the update improves comfort. In practice, some drivers say it has transformed the air conditioner into an enthusiastic but short-lived participant in the delivery process.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.