The CyberWire Daily Podcast 8.4.26
Ep 2607 | 8.4.26

NPM? Not my problem.

Transcript

New Shai-Hulud campaign compromises popular npm packages. Easterly says small municipalities shouldn’t have to fend for themselves. Chinese threat groups accelerate exploits. Samsung bans smart TV apps with residential proxies. Hackers breach a Liechtenstein banking database. Swiss government IT agency hit in suspected SharePoint Attack. Microsoft’s bug bounty program awards record payouts. Researchers expose privilege boundary flaw in AI-driven CI/CD workflows. Roberta Anderson, Air Force veteran and CISO at Onterris is sharing her "Breaking the Firewall" book. And, bug hunting turns into bug sorting.

Today is Tuesday August 4th 2026. I’m Dave Bittner Maria Varmazis. And this is your CyberWire Intel Briefing.

New Shai-Hulud campaign compromises popular npm packages.

Researchers at Aikido are tracking a new Shai-Hulud supply chain attack that has compromised at least 868 npm packages, which collectively receive over 2 billion downloads per month. The attackers compromised the GitHub account of the maintainer behind the key-value storage library keyv and used the access to infect its entire package family. The injected malware is designed to harvest credentials and other secrets on the infected machines.

The researchers state, "Every package got a preinstall hook that runs automatically on npm install, silently downloads the Bun runtime, and harvests npm, GitHub, AWS, and Vault credentials. Because the attacker pushed to main and immediately cut a release, the poisoned versions shipped with valid provenance signed by GitHub Actions. There's also active community spread to other maintainers and packages, including major organisations like Deliveroo, OneReach, Picsart, and Qlik."

Easterly says small municipalities shouldn’t have to fend for themselves. 

In an opinion piece for The New York Times, former CISA director Jen Easterly argues that the recent cyberattacks on municipal water systems reveal a fundamental flaw in America’s cybersecurity strategy: local communities are being left to defend critical infrastructure against nation-state adversaries. While the attacks, attributed to Iranian-affiliated hackers, did not contaminate drinking water, they exposed how vulnerable small water utilities remain. Easterly, now CEO of RSAC, contends that blaming state or local officials misses the point. Foreign cyber threats are a national security issue that require a coordinated federal response. She acknowledges that previous federal investments in guidance, grants, and incident response likely helped limit the damage, but warns those gains are now at risk because of funding cuts and weakened federal support. Her prescription is clear: rebuild the Cybersecurity and Infrastructure Security Agency, renew cybersecurity funding, modernize aging infrastructure, and extend information-sharing protections. In her view, safeguarding America’s water supply is a shared national responsibility, not a burden that small towns should shoulder alone.

Chinese threat groups accelerate exploits. 

CrowdStrike reports that China-linked threat groups Vault Panda and Genesis Panda can exploit critical software vulnerabilities within 24 hours of public disclosure, highlighting increasingly compressed attack timelines. The researchers observed both groups rapidly targeting the React2Shell vulnerability after it was disclosed in December 2025, using remote access tools and credential theft capabilities. More broadly, CrowdStrike found that 88% of exploited vulnerabilities in the first half of 2026 were targeted within 48 hours of disclosure, with AI expected to further accelerate exploitation and increase the volume of newly discovered flaws. The report also identified a rise in identity-based attacks, including LLMJacking, in which attackers abuse victims’ AI platforms, as well as AI-enhanced vishing campaigns, which have become more prevalent because they are difficult for defenders to detect.

Samsung bans smart TV apps with residential proxies. 

New research from Norwegian cybersecurity firm Mnemonic found that several Samsung smart TV apps contain residential proxy software that can share a user’s internet connection with third parties, potentially exposing millions of devices to misuse. One affected app was a Samsung-endorsed Pac-Man game that included proxy code from Bright Data. Researchers said the code activates only after users consent, but warned it could be enabled more broadly through server-side changes. Residential proxy networks have legitimate uses, including bypassing censorship and supporting AI data collection, but they are also frequently abused by cybercriminals to conceal malicious activity. Following the disclosure, Samsung said it has banned new apps containing residential proxy functionality and is removing existing apps that include the technology.

Hackers breach a Liechtenstein banking database. 

Hackers breached Liechtenstein’s register of beneficial owners, copying data related to approximately 31,000 companies, foundations, and trusts before authorities detected the intrusion and took the system offline. The register was established in 2021 to support anti-money laundering efforts. Officials said there is no indication the data was altered or deleted, and the Liechtenstein Bankers Association confirmed no banks or customer data were affected. The government has formed a crisis task force and is notifying affected individuals while the investigation continues.

Swiss government IT agency hit in suspected SharePoint attack.

Switzerland's Federal Office for Information Technology and Communications says hackers compromised roughly 200 user and service accounts after what officials believe was an attack against on-premises Microsoft SharePoint servers. The intrusion was detected after unusual activity last week, and investigators suspect attackers exploited recently disclosed SharePoint vulnerabilities, though the investigation remains ongoing. Officials say they have found no evidence so far that data beyond login credentials was accessed, but they're reinstalling affected servers as a precaution. The incident is another reminder that internet-facing SharePoint remains a high-value target, and that patching alone isn't enough—organizations also need to rotate IIS machine keys and hunt for signs of persistence after compromise.

Microsoft’s bug bounty program awards record payouts. 

Microsoft’s Bug Bounty Program awarded more than $20 million to 562 security researchers from 64 countries this year, marking the largest payout and broadest participation in the program’s history. The company credited coordinated vulnerability disclosure with helping secure its cloud, AI, enterprise, and consumer products before flaws could be exploited. Microsoft’s Zero Day Quest generated nearly 700 vulnerability reports and $2.3 million in awards, while expanded bounty eligibility for open source and third-party components resulted in more than 300 additional reports and over $800,000 in payouts. Microsoft said the record results reflect the growing impact of its partnership with the global security research community.

Researchers expose privilege boundary flaw in AI-driven CI/CD workflows. 

Security researchers at Pillar Security say they've uncovered a new class of vulnerability affecting AI-powered software development pipelines. Their research shows that AI agents collaborating in Google's Agent Development Kit can unintentionally trust one another across privilege boundaries, allowing malicious instructions introduced early in a CI/CD workflow to cascade through downstream agents. Rather than exploiting code, the attack exploits assumptions—agents inherit the perceived authority of previous agents, potentially leading to unauthorized actions or code changes. The findings suggest that as organizations adopt agentic software development, they'll need to treat AI agents as distinct identities with explicit trust boundaries, least-privilege access, and independent verification instead of assuming agent-to-agent communication is inherently trustworthy.

 

Stay with us after the break Dave Bittner sits down with Roberta Anderson, Air Force veteran and CISO at Onterris, discussing her "Breaking the Firewall" book. And bug hunting turns into bug sorting. Stick with us. 

Dave Bittner recently sat down with Roberta Anderson, Air Force veteran and CISO at Onterris, as they discussed her "Breaking the Firewall" book.

That was Roberta Anderson and Dave Bittner discussing her book, Breaking the Firewall. If you enjoyed this conversation, check out Roberta’s book in the show notes. 

Bug hunting turns into bug sorting. 

Apple has discovered that the hardest part of bug hunting is no longer finding bugs, it is sorting through the avalanche of AI-generated reports claiming to have found them. Faced with a flood of submissions, some accurate and some pure hallucination, the company has capped the number of open vulnerability reports each researcher can submit and added a 30-day cooldown period, while allowing requests for higher limits. The change frustrated Italian startup Bynario, which said AI helped it uncover more than 50 macOS vulnerabilities in three weeks, including a serious privilege escalation exploit it initially could not report. Apple says it is now reviewing those findings and is also using AI internally to triage reports. This all spotlights AI’s double-edged role in cybersecurity: it is helping researchers uncover legitimate flaws at unprecedented speed, while simultaneously burying security teams under a mountain of digital false alarms.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

 

We're recording onsite at Black Hat this Wednesday and Thursday from our podcast studio in the SpecterOps Kennel Club. If you'd like to meet the N2K CyberWire team, make sure you stop by the studio.

 

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.