The CyberWire Daily Podcast 8.14.26
Ep 2615 | 8.14.26

Apple has a message for you.

Transcript

Apple sends out threat notifications to users targeted by spyware. Trivy, not LiteLLM, was the original source of the 2,500-organization supply chain attack. French tax authority confirms data breach. Chinese hack-for-hire group conducts espionage and cybercrime simultaneously. Ukrainian police shut down 94 scam call centers. Former data analyst jailed for insider extortion plot. New macOS malware spreads via ClickFix. Today we are joined by Tom Kellermann, VP of AI Security at TrendAI, discussing the machine-speed war for financial control. And the glitch in the surveillance matrix.

Today is Friday August 14th, 2026. I’m Maria Varmazis. And this is your CyberWire Intel Briefing.

Apple sends out threat notifications to users targeted by spyware.

Apple yesterday sent out threat notifications to users in 110 countries, warning them that their devices may have been targeted by mercenary spyware often used by governments. The alerts will now appear on device lock screens as well as being delivered to users’ email addresses and on their Apple account pages. Apple recommends that users who have been targeted or believe they may be targeted enable Lockdown Mode on their devices, an extreme protection that reduces the attack surface by limiting many of the device’s functionalities. The company also advises targeted users to seek expert help, such as security assistance provided by the Digital Security Helpline at the nonprofit Access Now.

Trivy, not LiteLLM, was the original source of the 2,500-organization supply chain attack.

Researchers at SOCRadar say the supply chain attack that compromised over 2,500 organizations was primarily driven by a malicious build of Aqua Security's Trivy scanner rather than the LiteLLM package, as initially suspected. Data shows that 95% of the affected entities were exposed to the malware days before the poisoned LiteLLM packages were published. The Trivy attack is also attributed to the TeamPCP threat actor and led to the LiteLLM attack, but SOCRadar says the LiteLLM compromise “was the closing act, not the whole play.”

SOCRadar explains, “Attackers hijacked the trusted Trivy security scanner in LiteLLM’s build pipeline, used it to publish two poisoned LiteLLM releases to PyPI, then relied on a Python startup file to run a credential stealer on every host that installed them.”

French tax authority confirms data breach.

France's tax authority, the Directorate General of Public Finances, disclosed that it sustained a data breach in late June after an attacker used stolen credentials to gain access to its IT systems. Officials haven’t confirmed details of what was stolen, but said the intrusion allowed the attacker “to view and extract data belonging to individuals and businesses.” 

The incident was made public after a hacker under the alias ZeroBytes claimed to have stolen data on over 600,000 individuals, including names, tax IDs, and email addresses, family circumstances, and details about tax status. French authorities are investigating these claims, and will share more information in the future.

Chinese hack-for-hire group conducts espionage and cybercrime simultaneously.

Symantec has published a report on Jewelbug, a China-based hackers-for-hire group that conducts financially motivated cryptocurrency fraud alongside espionage campaigns targeting foreign governments and militaries. The threat actor, which is linked to a registered contractor in Hunan Province, uses the same control panel to conduct both criminal and nation-state espionage operations. Symantec notes that this “pairing is the signature of a hack-for-hire entity that is running for-profit crime on the side.”

Ukrainian police shut down 94 scam call centers.

Ukrainian authorities, in collaboration with international law enforcement, shut down 94 fraudulent call centers across the country following 411 police raids. Police seized over $2 million in cash, a kilogram of gold, luxury vehicles, and thousands of computers and phones. The scammers posed as bank officers, brokers, and law enforcement to trick victims into making fake investments, installing malware, or paying phony fees. Police are analyzing the seized equipment, which will likely lead to more arrests and the identification of the ringleaders.

Former data analyst jailed for insider extortion plot.

Cameron Curry, a 27-year-old data analyst contractor, has been sentenced to two years in prison in North Carolina for orchestrating an insider extortion attack against Brightly Software. Between August and December 2023, Curry exploited his access to steal sensitive corporate information, then threatened to expose the data, report the company to the SEC, or encourage lawsuits. After demanding a massive $2.5 million ransom, he ultimately extorted just $7,540.92.

New macOS malware spreads via ClickFix.

Jamf Threat Labs has discovered a new strain ofmacOS malware named” AmnesiaStealer,” a multi-stage Rust-based infostealer distributed via ClickFix attacks on GitHub. Once installed, the malware harvests sensitive data from the keychain, browsers, Apple Notes, and Telegram.

AmnesiaStealer differentiates itself from other macOS malware like Atomic or MacSync by using a builder-driven configuration, deploying OS-specific logic to exploit patched macOS bypasses, and muting the host system to conceal the noise of background file exfiltration.

 

Stay with us after the break Dave Bittner sits down with Tom Kellermann, VP of AI Security at TrendAI, to discuss the machine-speed war for financial control. And the glitch in the surveillance matrix. Stick with us. 

Tom Kellermann is the VP of AI Security at TrendAI and also occasional guest on the AI Security Briefing podcast, and he recently sat down with Dave Bittner to discuss the machine-speed war for financial control. Here’s their conversation. 

That was Tom Kellermann and Dave Bittner discussing the machine-speed war for financial control. If you enjoyed this conversation be sure to check out the AI Security Brief wherever you get your podcasts. 

The glitch in the surveillance matrix.

Security researcher Bill Swearingen has unveiled "noRecognition," a project that uses reinforcement learning to generate adversarial patterns that make people and objects invisible to AI surveillance systems. After roughly 31 million tests over the past year, the system produced computer-generated designs that successfully scramble the object and facial detection algorithms used by technologies like Flock license plate readers, Axon body cameras, and Clearview AI, without blocking the actual video recording. At DEF CON last week, Swearingen successfully demonstrated the concept by covering a Toyota Yaris in one of the patterns to evade a Flock camera. The patterns aren’t exactly exactly subtle, so you’ll be trading digital invisibility at the cost of real-world conspicuousness.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

Be sure to check out Research Saturday, where we are joined by Ian Goldin, Senior Lead Information Security Engineer, and Mike Horka, Principal Information Security Engineer, from Lumen's Black Lotus Labs, discussing their research entitled "Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation." That’s Research Saturday, check it out! 

This Sunday on The T-Minus Space Cyber Briefing, I’ll be sitting down with Brandon and Dave to unpack Google Earth’s latest experiment with AI—and what it could mean for the future of satellite imagery. Tune in Sunday for the full conversation.

Also be sure to tune into a Special Edition this Sunday where Dave Bittner sits down with Clint Gibler, Cyber Lead at OpenAI and Robby Winchester, Chief Global Professional Services Officer at SpecterOps to discuss frontier models and the future of cyber defense. You can find it wherever you get your favorite podcasts. 

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.