The CyberWire Daily Podcast 8.10.26
Ep 2611 | 8.10.26

Now with extra vulnerabilities.

Transcript

Researchers find that only a quarter of AI-generated patches are fully successful. Ransomware attacks exploit critical N-able flaw. Atlassian fixes critical flaw in Rovo AI. LexisNexis disables some services following suspicious activity. US Senate confirms Adam Cassady as cyber ambassador. Meta ordered to pay an additional $567 million in child safety case. Water sector cyberattacks expand to new states. We got your Monday Business Briefing. On our Industry Voices, Dave Bittner sits down with Mujtaba Hamid, EVP, Product and Strategy at Booz Allen Hamilton at Black Hat discussing AI Speed Cyber Defense. And scammers set sail on The Odyssey.

Today is Monday, August 10th 2026. I’m Maria Varmazis in for Dave Bittner. And this is your CyberWire Intel Briefing.

Researchers find that only a quarter of AI-generated patches are fully successful.

Researchers at 1Password found that AI-generated security patches are still largely unreliable: when ChatGPT 5.5 and Claude Opus 4.8 were tested against six recently disclosed vulnerabilities, generating over six thousand patches, only 26% of the patches fully fixed the vulnerability without introducing new problems or altering application behavior. More than half of the time, the AI did not fix the flaw or introduced new vulnerabilities in the process.

The researchers conclude that “human expertise still plays an essential role in the process of fully resolving vulnerabilities in software without introducing unwanted side effects.”

Ransomware attacks exploit critical N-able flaw.

Microsoft has warned that a China-based cybercriminal gang is launching ransomware attacks by exploiting a critical vulnerability in N-able’s N-central software, a widely used remote monitoring and management tool. After exploiting the flaw to gain administrative access, the hackers deploy a new ransomware strain called "StormEncryptor.”

N-able released emergency patches earlier this month after the flaw was observed being exploited in zero-day attacks. The company then issued a second emergency hotfix on August 6th after attackers bypassed the first patch.

Atlassian fixes critical flaw in Rovo AI.

A critical vulnerability in Atlassian’s Rovo AI, dubbed RovoBlast, allowed attackers to use a specially crafted link to inject malicious instructions into a victim’s Rovo session without requiring a jailbreak or permission bypass. Because Rovo can access enterprise systems such as Jira, Confluence, SharePoint, Slack, and Microsoft 365, the flaw could have been used to retrieve and exfiltrate sensitive corporate data with a single click. Atlassian fixed the issue following a responsible disclosure by researchers at Varonis.

LexisNexis disables some services following suspicious activity.

Data analytics company LexisNexis has taken its Diligence, Metabase API, and Newsdesk services offline after detecting suspicious activity on servers managed by a third-party vendor. The company is investigating the issue and rebuilding the affected systems in a new environment before restoring service. The company hasn’t said whether customer data was compromised. Todd Larsen, president of the global Nexis Solutions division of LexisNexis, said in a statement, “Our investigation is ongoing, and we are working with a preeminent cybersecurity forensic firm on review and remediation.”

US Senate confirms Adam Cassady as cyber ambassador.

The US Senate has confirmed Adam Cassady as chief of the State Department’s Bureau of Cyberspace and Digital Policy, making him the second person to hold the position. The post had been vacant since Nathaniel Fick departed in January 2025.

Cassady, a senior official at the National Telecommunications and Information Administration, was confirmed in a 51-47 vote. The Record notes that it’s unclear how much influence the position still holds following a major State Department reorganization last year.

Meta ordered to pay an additional $567 million in child safety case.

A New Mexico court has ordered Meta to pay $567 million and make major changes to Facebook and Instagram to better protect children, bringing the company’s total liability in the case to $942 million. The ruling requires stronger age verification, limits on minors’ platform use, tighter controls on AI chatbot interactions, and measures to address child abuse and mental-health harms.

Meta plans to appeal the ruling; a company spokesperson stated, “We remain confident in our record of protecting teens online and will continue to defend ourselves against claims that misrepresent the facts.”

Water sector cyberattacks expand to new states.

As a follow-up to a story we’ve been covering, New Jersey and Alabama have joined the growing list of states whose water and wastewater facilities were targeted in a cyberattack campaign linked to Iranian hackers. The campaign, which began in late July, has reportedly affected at least 12 states. New Jersey’s Cape May and Woodbine water systems were targeted on July 27, disrupting phone systems but not water service. The same day, hackers targeted industrial control systems at Alabama’s Childersburg Water, Sewer and Gas system, but water services were not disrupted. So far, affected utilities have reported limited impact, and officials continue to say drinking water is safe. The attacks have targeted ICS devices made by Rockwell Automation and may involve equipment from other major vendors. The FBI confirmed at least seven states had been targeted as of July 30, but has not publicly provided further updates.

Monday’s Business Briefing.


Last week’s Business Breakdown highlights just over a staggering $1 billion raised across 17 investments and 1 acquisition.

For investments, Horizon3 raised $250 million in a Series E round led by NightDragon and NEA. The US-based autonomous pen testing company is now valued at $2 billion. Horizon3 plans to use the funding to scale its GTM operations, accelerate its product roadmap, and support its entry into both Singapore and Australia.

Additionally, Spur, the US-based IP intelligence provider, raised $200 million from Insight Partners. With the funding, the company is looking to expand investment across product development, intelligence coverage, integrations, and enterprise operations lines.

In acquisitions, Okta, the US-based IAM company, acquired Permiso Security. By acquiring the identity security platform, Okta is looking to expand its footprint beyond identity management and add core SOC capabilities, through Permiso’s P0 Labs. 

And that wraps up this week’s Business Breakdown. For deeper analysis on major business moves shaping the cybersecurity landscape, subscribe to N2K Pro and check out TheCyberWire.com every Wednesday for the latest updates.

 

Stick with us. After the break, Dave Bittner sits down with Mujtaba Hamid, EVP of Product and Strategy at Booz Allen Hamilton, at Black Hat USA to discuss AI-speed cyber defense. And scammers set sail on The Odyssey.

Recently at Black Hat Dave Bittner sat down with Mujtaba Hamid, EVP of Product and Strategy at Booz Allen Hamilton as they discussed AI-speed cyber defense. Here is their conversation. 

That was Mujtaba Hamid and Dave Bittner discussing AI-speed cyber defense, for more information on this conversation be sure to check out our show notes. 

Scammers set sail on The Odyssey.

Tell us, Muse, of the dangers of sailing the high seas. If you’ve been waiting to see The Odyssey but can’t make it to the cinema, beware of anyone offering you a shortcut. The highly anticipated film is being used as bait in a wave of fake streaming scams, with criminals setting up convincing websites, complete with phony reviews and even dubbed versions tailored to a visitor’s location. Victims are lured into signing up for “free” access, only to be asked for their bank details — and there’s no movie waiting on the other side. Instead, they could end up with money stolen from their accounts, malware on their computers, and a fresh invitation to future phishing scams. While Christopher Nolan may want you to experience his epic on the big screen — he probably didn't have a malware download in mind for the encore.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.