
Building a great firewall around AI.
China embraces open AI models, then worries it’s become a national security risk. The cyberattack on Minnesota water systems proves larger than first reported. CISA updates its SBOM guidance. AI supercharges dangling DNS attacks. Researchers uncover a self-propagating Copilot worm. A critical Rails flaw demands urgent patching. Mac users are lured into installing malware through fake Claude guides. Amazon links a string of NPM compromises to North Korea. And Russia charges Telegram founder Pavel Durov with aiding terrorism. Ben Yelin joins us with a border search case that’s breaking new ground. Don’t bite the North Korean hand that feeds you.
Today is Thursday July 30th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.
China worries open AI models are a national security concern.
China has promoted itself as a leader in low-cost, open-source artificial intelligence, arguing that A.I. should be widely accessible and criticizing U.S. efforts to restrict Chinese models. Open-source systems from companies such as Alibaba and Moonshot have gained global adoption because they can be freely downloaded, modified, and deployed. However, the New York Times reports that Beijing is increasingly concerned that the same openness could threaten national security and political stability. Officials worry advanced models could enable cyberattacks, scams, biological threats, or bypass government censorship, while also weakening the Communist Party’s control over information. Reports suggest Chinese authorities are considering restrictions on exports or overseas access to their most advanced models, even as they continue promoting openness in principle. Analysts say China is trying to balance global influence with tighter control over strategically important A.I. technologies. The debate mirrors similar discussions in the United States, where companies disagree over whether open-source or closed-source A.I. offers the safest path forward, particularly as increasingly capable models emerge.
The cyberattack on Minnesota water systems was more extensive than originally anticipated.
As a follow-up to our earlier reporting, Minnesota officials say more than 30 community water systems were targeted in a coordinated cyberattack on July 26 and 27. The attacks focused on operational technology, but authorities say there is no evidence of public health risks, and the investigation remains ongoing. State officials have launched a whole-of-state response, bringing together federal, state, local, tribal, and private-sector partners to investigate the incident, share threat intelligence, and support affected utilities. Agencies involved include the Cybersecurity and Infrastructure Security Agency, the Environmental Protection Agency, the FBI, and Minnesota public safety and health officials. State Chief Information Security Officer John Israel said the coordinated response helped contain the incident quickly and demonstrated the value of Minnesota’s cybersecurity investments and cross-agency partnerships in protecting critical infrastructure.
CISA updates its SBOM guidance.
The Cybersecurity and Infrastructure Security Agency, working with U.S. and international partners, has released its 2026 Minimum Elements for a Software Bill of Materials, or SBOM. The updated guidance incorporates public feedback and expands to cover all software, including open source, artificial intelligence, and software-as-a-service. It adds new required data elements, clarifies existing ones, and reflects lessons learned since the original 2021 guidance. CISA says the revisions will help organizations strengthen software supply chain visibility and make more informed cybersecurity risk management decisions.
AI makes Dangling DNS a growing threat.
Researchers at Silent Push are warning that artificial intelligence could dramatically increase the threat posed by dangling DNS takeovers, a long-known attack in which abandoned DNS records allow attackers to hijack subdomains. In research dubbed “DangleGeddon,” the team used AI to automate domain discovery, identify exploitable targets, and generate takeover scripts, reducing thousands of potential targets to hundreds of vulnerable systems in minutes. Safe demonstrations showed how exposed government, financial, manufacturing, and pharmaceutical domains could be abused for phishing, malware hosting, or credential theft. Silent Push argues that while dangling DNS attacks have traditionally been used for financial gain, AI could make them far more attractive to nation-state actors seeking widespread disruption. The researchers say the findings underscore the importance of promptly removing stale DNS records and decommissioned cloud resources.
Malicious instructions hidden in Word documents spread through Copilot workflows.
A researcher is warning of a new class of AI-assisted attack that could allow malicious instructions hidden in Microsoft Word documents to spread through Copilot workflows. Håkon Måløy found that attacker-controlled prompts embedded in a document can influence Copilot-generated content and silently copy themselves into newly created files, enabling a self-propagating “AI worm.” Despite months of coordinated disclosure, Måløy says Microsoft has addressed specific proof-of-concept exploits but not the broader vulnerability class. He argues the issue stems from a fundamental challenge with large language models processing untrusted content. Microsoft says it has implemented multiple safeguards and continues to strengthen its defenses, but recommends users treat external documents as untrusted, install updates, and carefully review AI-generated content before sharing it.
Ruby on Rails developers are being urged to patch a critical Active Storage vulnerability.
Ruby on Rails developers are being urged to patch a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from affected servers. The flaw affects applications that use libvips for image processing and allow uploads from untrusted users. By uploading a specially crafted file, an attacker may be able to expose sensitive data, including secret_key_base, database credentials, cloud storage keys, and other application secrets, potentially leading to remote code execution or lateral movement. The recommended fix is to upgrade to a patched version of Active Storage and libvips 8.13 or later, then rotate all potentially exposed secrets. For systems already running libvips 8.13 or newer, administrators can also block vulnerable operations through configuration as a temporary mitigation.
Attackers disguise the MacSync stealer as a Claude installation guide.
Researchers at Huntress say attackers disguised the MacSync stealer and remote-access tool as a Claude installation guide hosted on the legitimate claude.ai domain.
Victims searching for Claude on a Mac encountered a paid Google advertisement leading to a public Claude share labeled as Apple Support. The page instructed users to paste a curl command into Terminal. That command launched a six-stage infection chain, granting Full Disk Access, stealing browser and keychain data, capturing validated account passwords, and installing a persistent remote-access trojan. The malware could also request Screen Recording access and modify installed cryptocurrency wallet applications to steal recovery phrases.
Trusted platforms, sponsored search results, and user-executed commands can bypass traditional warning signs. Defenders should prioritize behavioral detections over file hashes, which change between builds.
A North Korea-linked threat actor compromised popular NPM libraries.
Amazon says a North Korea-linked threat actor compromised several popular Node Package Manager, or NPM, libraries through maintainer social engineering and malicious software updates.
Amazon Threat Intelligence links the axios, debug, chalk, and typo-crypto incidents to the same actor with medium confidence. The campaigns used trojanized packages, automatic post-install scripts, reused code, and shared command-and-control infrastructure. Researchers also observed attackers splitting malicious behavior across multiple packages and delaying activation through remotely controlled resources.
Trusted open-source dependencies can provide access to thousands of downstream environments. Security teams should examine runtime behavior and dependency relationships, not only individual packages or signatures. Amazon also warns that generative AI may help attackers create convincing packages and manipulate automated code-review systems.
Russian authorities charge Telegram’s founder and CEO with aiding terrorism.
Russian authorities have charged Telegram founder and CEO Pavel Durov with aiding terrorism, accusing the messaging platform of failing to remove channels and bots allegedly used by Ukrainian intelligence and extremist groups to coordinate sabotage, terrorism, and cyber fraud. Russia’s Federal Security Service, or FSB, said the activity resulted in casualties and claimed a Telegram-based chatbot was used to recruit young Russians for attacks. Authorities have also placed Durov on international wanted lists, marking another step in the Kremlin’s broader crackdown on online communications since the 2022 invasion of Ukraine.
Don’t bite the North Korean hand that feeds you.
In a twist that might qualify as “career-limiting,” some of North Korea’s elite hackers allegedly turned their talents against the government that trained them. According to Daily NK, authorities arrested a group of former military cyber operators accused of stealing from the country’s own central and foreign trade banks. The suspects, reportedly trained through the same system that produced the notorious Lazarus Group, allegedly recruited university graduates, infiltrated banking networks, siphoned off small amounts of state funds, converted the proceeds into cryptocurrency, and laundered the money through brokers in China. The scheme unraveled after officials noticed irregular foreign currency transactions and traced suspicious cryptocurrency activity to a location in Pyongyang, where investigators reportedly caught the group in the act. While the irony is hard to miss, the consequences are likely anything but amusing. Reports suggest the accused, and potentially their families, now face severe punishment under North Korea’s system of collective responsibility.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry. Learn how at n2k.com.
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.
