CyberWire Daily

You've been disconnected.

26 min
Jul 28, 202627 days ago
Listen to Episode
Summary

CyberWire Daily covers critical infrastructure vulnerabilities and policy responses, including Senator Wyden's push to eliminate legacy VPNs from federal networks, attacks on Minnesota water systems, and a 20-year-old IPMI flaw affecting 24,000 servers. The episode features John Chiappetta from Zona Systems discussing aviation cybersecurity gaps and secure remote access challenges in critical industries.

Insights
  • Legacy VPN architecture is fundamentally unsustainable for federal security; architectural redesign rather than patching is required for long-term resilience
  • Critical infrastructure operators face a cultural and technological paradox: systems cannot be taken offline for upgrades while simultaneously needing modernization to meet security standards
  • Orphaned vendor access credentials accumulate over time in large organizations due to process gaps, creating persistent security blind spots that discovery audits can reveal
  • Zero-trust principles are becoming regulatory expectations, not optional best practices, with procurement leverage being used to drive industry-wide adoption
  • AI-accelerated attack paths and identity tradecraft are emerging as priority training topics for security professionals at major conferences
Trends
Federal procurement rules being weaponized to enforce cybersecurity standards across vendor ecosystemsBlockchain-based command and control mechanisms making botnets more resilient and harder to disruptOffline backup systems and contingency payment infrastructure becoming critical resilience strategies for financial sectorsThreat actor naming standardization efforts continuing despite fragmentation, indicating industry maturity but also operational frictionZero-trust architecture shifting from optional framework to mandatory compliance requirement for federal contractorsCritical infrastructure sectors (aviation, energy, banking, water) facing simultaneous pressure to modernize while maintaining 24/7 operationsAI vulnerability detection models becoming competitive differentiators with measurable performance claimsFake cryptocurrency wallet attacks exploiting app store review processes as vector for large-scale financial theftWeak IoT device credentials and default passwords remaining primary botnet propagation vectors despite years of awareness
Companies
Microsoft
Launched MAI CyberOne Flash, its first AI model for cybersecurity vulnerability detection, claiming 50% cost reduction
Arista
Confirmed active exploitation of critical VeloCloud Orchestrator vulnerability with 10.0 CVSS rating affecting on-pre...
Google
Introduced new threat actor naming system replacing numeric identifiers with two-word cryptonyms for improved tracking
Apple
Faces lawsuit over fraudulent Sparrow wallet app on App Store that stole $1.8M in Bitcoin from three users
Cisco
VPN product cited by Senator Wyden as repeatedly exploited by nation-state campaigns, supporting legacy VPN elimination
Fortinet
VPN vendor mentioned as target of nation-state exploitation campaigns, supporting case for legacy VPN phase-out
Avanti
VPN vendor cited in Senator Wyden's letter as evidence of recurring nation-state exploitation of legacy remote access
OpenAI
Hosting talks at SpecterOps Kennel Club on AI-accelerated attack paths; mentioned as competitor in AI vulnerability d...
Zona Systems
Guest company specializing in secure remote access for critical infrastructure including aviation, energy, and manufa...
CISA
Urged to issue binding operational directive for legacy VPN elimination; added Arista flaw to known exploited vulnera...
NIST
Called to establish zero-trust technical standards emphasizing memory-safe languages and decentralized key management
OMB
Requested to update federal procurement rules restricting purchases to zero-trust compliant remote access products
TSA
Implemented 2023 cybersecurity guidelines requiring airport authorities to audit and evaluate remote access practices
Bloodhound
SpecterOps-created tool featured at Black Hat USA conference with workshops on AI-accelerated attack paths
UK AI Security Institute
Hosting talks at SpecterOps Kennel Club on AI security and attack path analysis
Anthropic
Mentioned as competitor in AI vulnerability detection models compared against Microsoft's MAI CyberOne Flash
IIT Madras
Website allegedly hacked by rejected cybersecurity student applicant claiming unfilled program seats and unaddressed ...
IIT Kanpur
Website allegedly hacked alongside IIT Madras by student applicant protesting admissions process
People
John Chiappetta
Guest discussing aviation cybersecurity gaps, FAA network security, and secure remote access challenges in critical i...
Dave Bittner
Hosts CyberWire Daily briefing and conducts interview with John Chiappetta on aviation cybersecurity
Ron Wyden
Urged CISA, OMB, and NIST to eliminate legacy VPNs from federal networks within two years and enforce zero-trust stan...
Quotes
"Repeated emergency patching of internet-facing VPN appliances is an unsustainable response to vulnerabilities rooted in their architecture"
Senator Ron Wyden (paraphrased from letter)Early in episode
"You have to change the oil while the engine is running and how much harder that is"
Dave BittnerInterview segment
"These aren't new organizations, it's not a startup which started yesterday, so there's certain things that are inherent to them and some of this is the infrastructure that they have can't be refreshed or turned off or upgraded overnight"
John ChiappettaInterview segment
"How do I guarantee that nothing touches these systems? The article that we're discussing actually mentioned NIST and the zero trust principles and guidelines that NIST produces"
John ChiappettaInterview segment
"All I need is just a fair chance"
IIT Madras rejected student (quoted from Reddit)Final story segment
Full Transcript
You're listening to the Cyber Wire Network, powered by N2K. This episode is supported by Black Hat USA. If you follow the research, you know a lot of it breaks on Black Hat stages. Hundreds of peer-reviewed briefings, more than 100 hands-on trainings, and the largest business hall in Black Hat's history. Six days to learn the skills you'll need tomorrow, August 1st through the 6th. Use code CYBERWIRE for $200 off your briefings pass at blackhat.com. We'll see you in Vegas. If you're heading to Black Hat USA this year, make plans to visit the Specter Ops Kennel Club. As creators of Bloodhound, the SpecterOps team will host talks with OpenAI and the UK AI Security Institute, as well as hands-on workshops aimed at helping you understand AI-accelerated attack paths and the latest in identity tradecraft. Visit specterops.io to pre-register and learn more. SpecterOps Kennel Club is adjacent to Libertine Social inside Mandalay Bay. While you're there, visit the N2K CyberWire podcast studio, where we'll be capturing expert perspectives and conversations from across Black Hat. A senator targets legacy VPNs. Minnesota water systems come under cyber attack. A 20-year-old flaw exposes 24,000 servers. Microsoft debuts its first cybersecurity AI model. A critical Velo cloud bug is under active attack. The dysphoria botnet tops 200,000 devices. Apple faces a lawsuit over a fake crypto wallet. Denmark builds a cyber resilient banking backup. Google gives threat actors yet another set of names. Our guest is John Chiappetta, Chief Revenue Officer of Zona Systems, discussing the Aviation Cybersecurity GAO report that highlights gaps in FAA network security and hacking the admission system in search of a fair chance. It's Tuesday, July 28th, 2026, one of my favorite days of the year. I'm Dave Bittner, and this is your CyberWire Intel Briefing. Thanks for joining us here today. It's great as always to have you with us. Senator Ron Wyden has urged CISA, the Office of Management and Budget, and NIST to take coordinated action to eliminate legacy VPNs from federal networks within two years and require vendors to certify that their remote access products meet zero-trust standards to remain eligible for federal contracts. Wyden argues that repeated emergency patching of interest Internet-facing VPN appliances is an unsustainable response to vulnerabilities rooted in their architecture. His proposal calls for CISA to issue a binding operational directive mandating migration, NIST to establish technical standards emphasizing outbound-only remote access, memory-safe programming languages, and decentralized key management, and OMB to update procurement rules so only compliant products can be purchased by federal agencies and defense contractors. The letter cites multiple nation-state campaigns exploiting VPN products from vendors, including Avanti, Cisco, and Fortinet, as evidence that legacy remote access technology has become a recurring national security risk. While the agencies are not obligated to act, The proposal aligns with CISA's recent zero-trust guidance and could significantly reshape the federal cybersecurity market if adopted. At least three Minnesota cities, Plymouth, South St. Paul, and Braham, are responding to cyberattacks targeting their water facilities, prompting assistance from state authorities. Plymouth reported attacks on water towers and lift stations. South St. Paul said its water utility system was affected, and Brahm experienced a brief outage at its water plant before crews restored operations. Officials believe other communities may have also been impacted, although it remains unclear whether the incidents are connected or the work of a single threat actor. All three cities say the effects have been limited, drinking water remains safe, and residents can continue normal water use. Minnesota IT Services is coordinating with local, state, and federal partners to assess the attacks, share threat intelligence, support response and recovery efforts, and determine the full scope of the ongoing investigation. Researchers have identified more than 24,000 Internet-exposed servers vulnerable to a long-standing weakness in the Intelligent Platform Management Interface, IPMI 2.0 protocol, that can expose password hashes for offline cracking. The flaw stems from a protocol design dating back to 2004 and affects baseboard management controllers, which provide low-level remote server administration. Lava researchers found that about one of affected systems used weak or predictable credentials including default passwords making compromise significantly easier Because BMCs operate below the operating system, successful attacks can provide deep control over physical servers and potentially broader management environments. The researchers urge organizations to keep IPMI interfaces off the public Internet, rotate default BMC passwords, isolate management networks, and disable legacy IPMI authentication to reduce exposure. Microsoft has introduced MAI CyberOne Flash, its first AI model built specifically for cybersecurity, designed to identify vulnerabilities in complex code. Integrated into the company's M-Multi-Agent platform, the model works alongside larger AI models to improve efficiency while reducing costs by 50%. Microsoft says testing showed the system outperformed competing cybersecurity AI models from Google, OpenAI, and Anthropic in vulnerability discovery. MAI CyberOne Flash will be available through Microsoft's Project Perception security platform, which enters public preview on August 3rd. Arista has confirmed active exploitation of a critical vulnerability affecting its on-premises VeloCloud Orchestrator software. The flaw with a 10.0 CVSS rating is an unauthenticated OS command injection vulnerability that can allow attackers to compromise the Orchestrator and potentially gain access to managed VeloCloud Edge devices. Because the web interface is exposed by default, Arista recommends restricting access to trusted management networks and blocking known malicious IP addresses until patches are applied. CISA has added the flaw to its known exploited vulnerabilities catalog, underscoring the urgency. The issue does not affect Arista's hosted VeloCloud service, and patched software versions are now available for affected on-premises deployments. Researchers have identified a botnet called dysphoria that has compromised an estimated 200,000 devices worldwide and is being used for DDoS attacks and traffic relay operations. According to Kionjin xLab, the malware employs a blockchain-based command and control mechanism using Ethereum and Solana naming services to make its infrastructure more resilient and difficult to disrupt. Since first appearing in March, dysphoria has rapidly evolved, adding multi-chain support, new command and control techniques, and separate variants for DDoS attacks and proxy services. The botnet spreads by exploiting weak telnet and SSH credentials and known vulnerabilities in routers, cameras, and other IoT devices. Researchers recommend patching firmware, changing default passwords, disabling unnecessary remote access, and strengthening device security settings to reduce the risk of compromise. Three Apple users have filed a lawsuit alleging they lost a combined $1.8 million in Bitcoin after downloading a fraudulent Sparrow wallet application from the App Store. The complaint claims the fake app impersonated the legitimate desktop-only cryptocurrency wallet, tricking users into entering their recovery seed phrases, which attackers then used to steal their funds. The plaintiffs argue Apple failed to adequately review and remove the fraudulent app despite prior warnings from Sparrow Wallet's developer and user reports. Apple said it removed the impersonating apps, terminated the associated developer accounts, and provided channels for reporting fraudulent software. The lawsuit seeks reimbursement for the stolen cryptocurrency, damages, and court-ordered improvements to Apple's App Store review process and fraud warnings. In Denmark, Denmark's national bank is developing a dormant energy bank, an offline backup banking system designed to keep critical financial services running during a major cyber attack. The initiative is part of the central bank's Emergency Preparedness for Critical Financial Sector Activities in Extreme Scenarios strategy, introduced in late 2025. If a cyberattack disables a major bank or Denmark's broader banking infrastructure, the DEB would allow businesses and consumers to continue receiving salaries, making transfers, and using payment cards until normal operations are restored. The plan also includes a card payment contingency system that enables retailers to accept physical cards and mobile wallets even during prolonged IT outages by storing transactions offline and settling them once connectivity returns. Currently being piloted nationwide, the offline payment capability is expected to be fully operational at grocery stores and pharmacies by the end of this year, strengthening Denmark's resilience against large-scale cyber disruptions. Google Threat Intelligence Group has introduced yet another threat actor naming system because the cybersecurity industry apparently didn't have enough aliases to keep track of already. The company is replacing numeric identifiers with two-word cryptonyms, pairing a memorable name with a category suffix that reflects attribution or motivation. Under the new scheme, China's groups end in Castle Russia in Relic North Korea in Neptune Iran in Ion and cybercrime gangs in Comet For example the group long tracked by Google as APT44 and by everyone else under a small library of different names, will now be known as Sandworm Relic. Google says the new taxonomy is intended to simplify tracking while preserving legacy names, MITRE attack mappings and other vendor aliases during what is sure to be another industry-wide exercise in cross-referencing threat actor names. Coming up after the break, my conversation with John Chiapetta from Zona Systems. We're discussing the Aviation Cybersecurity GAO report that highlights gaps in FAA network security and hacking the admissions system in search of a fair chance. Stay with us. John Chiappetta is Chief Revenue Officer at Zona Systems. We recently sat down to discuss the Aviation Cybersecurity GAO report that highlights gaps in FAA network security. Naturally, this is a very critical industry. That is primarily what we serve at Zona. So we are focused on critical industries, generally speaking, energy, even manufacturing. So this certainly falls into the scope of what we focus on. now when it comes to the report in itself it's interesting from a few different perspectives and i think what everybody needs to factor in is these aren't new organizations it's not a startup which started yesterday so there's certain things that are inherent to them and some of this is the infrastructure that they have can't be refreshed or turned off or upgraded overnight And so a lot of these industries are facing relatively similar challenges. Yeah, you know, when I think of aviation, it's kind of, you know, that old joke about you have to change the oil while the engine is running and how much harder that is. At the same time, I think we hear lots of stories about aviation having challenges with things like air traffic controllers and the technology that they use. I mean, is this a case of a vertical that is just a little behind when it comes to updating their technology? I wouldn't use the words a little behind necessarily. I think inherently it's an industry that's hard to move, right? Banking would be another one. Energy sector would be another one in that it's institutionalized. And so, you know, you mentioned kind of change the oil while it's running. I think that's absolutely accurate in the sense of this industry is starting to face the same challenges every other industry is facing right now, but it's new for this industry. These challenges did exist when a lot of this infrastructure was set up. And so, you know, it's yes, it's a technology piece, but it's also a culture piece. And it's how do you get ahead of that on really both sides at once? Well, I know you have a story to share about some work that you did with an airport authority and some of the surprises that you found within their systems. Surprise for me, for sure. Surprise for them, I think, as well. But this was actually driven and it's related because a few years ago, I want to say it was 2023, TSA came in with a number of changes when it came to cybersecurity, best practices, guidelines, all of that. And at the time, I was engaged with a very large airport authority working on a very similar project to what we do right now. So what we focus on is secure remote access. All of the organizations that we work with, and this is no different, they have systems that they don't manufacture themselves. It helps operate their business, but ultimately they have vendors and contractors and different people who support those systems who may not be on site. And so they need remote access into these systems. And so that was the project we were working on. And we were working with the operations side. So very typically, we'd either work with operations or IT slash cyber teams. And, you know, the combination of the two, this was exclusively with the operations side. And they were rather frustrated. And the frustration that they had, those individuals are tasked with keeping things moving, keeping the systems running, keeping people moving through the airport, keeping everything secure. And TSA at the time threw a bit of a wrench into that because they said, hey, I want you to evaluate how you're doing remote access today. Who's connecting to these networks? What's going on? Get a better handle on that is essentially the message that went out. So in that process, they were rather frustrated because they had to do that instead of focus on the work that they do on a daily basis, which, as we know, keeps them very busy. During that, they found out that they were only working with a number of vendors at this specific point in time. But when they looked at how vendors were accessing the network, there was a number, I think it was upwards of 30 different connections that were still able to access the network, even though they weren't dealing with those 30 different vendors, they were only dealing with a handful. And so rather surprising to them, certainly surprising to me, because just like you and I, we travel through the airport all the time. We got to jump through all kinds of hurdles. And it's interesting to see these doors were unlocked at the time. What do you suppose that story says about the broader situation that we find in the industry today Is this a typical kind of thing defined It is Less and less as the years go on But again you focused on or certainly we're focused on industries where if we go back 15, 20 years, they were never connected to the internet. They were never meant to connect to the internet. And then COVID certainly expedited that where all of a sudden systems that were never meant to connect to the internet in the first place, you had to connect them because they might be supported by a vendor who's in a different state or a different country. And when something goes wrong, you can't take everything offline. You need them to connect in and fix it right now. And so the way that different organizations address that was relatively the same, which is leverage what's called a VPN. At the end of the day, that's a big, long Ethernet core. And there's a number of challenges that come along with that. And what they found themselves in is a situation where they didn't have best practices. They didn't have guidelines around that. It was very common for connections to be spun up. But then nobody comes back to the IT team who spun up that connection to say, hey, we no longer work with that vendor. There's no need to have that. Everybody's busy. They got another job to do right after they complete this one. And those compound over the years. So what are your recommendations for organizations to best deal with this particular issue? It's a good question. And I wish there was a one size fits all type of approach to this. But as with anything, it's not that simple. What I would say is, first, you need to understand what is it that's on that network, right? You need to understand what's behind the doors, What are you ultimately protecting? And then work backwards to say, okay, how do I do this in a way where I'm doing it proactively and not reactively? We hear a lot about, you know, how do we understand the detection and monitoring piece? Well, that piece means something already got in, something already happened. And so how do you look at the front doors to say, how do I guarantee that nothing touches these systems? The article that we're discussing actually mentioned NIST and the zero trust principles and guidelines that NIST produces and the recommendation to follow that pretty tightly. I think that's fantastic. You know, then look at what are your high priority resources that, you know, those are the ones that keep you up at night that need to be protected at all costs. Who are the privileged users? And then make sure you fully understand how this maps together. But the key thing is be proactive about the security. Do not bake that in as an afterthought. That's John Chiapetta from Zona Systems. And finally, a would-be cybersecurity student has ignited an online debate after allegedly hacking the websites of IIT Madras and IIT Kanpur claiming the intrusion was less about causing damage than making a very pointed admissions appeal. In messages shared on Reddit, the individual said he was rejected from IIT Madras' Bachelor of Science in Cybersecurity program despite paying the application fee, submitting the required materials, and building years of cybersecurity experience. His central plea, all I need is just a fair chance. He also alleged that several program seats went unfilled and claimed, without independent verification, to have accessed sensitive institutional systems after repeated attempts to report security issues, and contact administrators went unanswered. Reports of website outages surfaced around the same time, although any connection remains unconfirmed. The episode has divided opinion, with critics condemning the alleged hack, while others questioned whether traditional admissions processes are overlooking practical cybersecurity talent. And that's the Cyber Wire. For links to all of today's stories, check out our daily briefing at thecyberwire.com. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire at n2k.com. N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazis. Our executive producer is Jennifer Iben. Peter Kilby is our publisher. And I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow. in the SpecterOps Kennel Club. If you're interested in joining us for a conversation or learning more about what we're recording throughout the week, stop by the studio and meet the N2K CyberWire team. SpecterOps's Kennel Club is adjacent to Libertine Social inside Mandalay Bay.