<?xml version="1.0" encoding="UTF-8"?>
  <rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <atom:link href="https://thecyberwire.com/feeds/rss.xml" rel="self" type="application/rss+xml" />
      <lastBuildDate>Thu, 20 Aug 2026 02:16:34 GMT</lastBuildDate>
      <title>The CyberWire</title>
      <description>The CyberWire is an independent voice delivering concise, accessible, and relevant cyber security news to people all across the globe. We separate the signal from the noise.</description>
      <link>https://thecyberwire.com/index.html</link>
      <item>
      <guid isPermaLink="false">54739ddfa4554fa0a4880d4a631958b9</guid>
      <pubDate>Tue, 10 Feb 2026 07:00:00 GMT</pubDate>
      <title>Bringing it all together.</title>
      <category>Technology</category>
      <media:content url="https://dev.cicd.thecyberwire.comhttps://images.thecyberwire.com/hubfs/www/images/podcast/cisop/CISOP_070825_PUBLIC.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/cso-perspectives-public/111/notes</link>
      <description>In the season finale of CISOP, Kim Jones is joined by N2K’s own Ethan Cook to reflect on the conversations that shaped this season. Together, they revisit standout moments from Kim’s interviews, unpacking their significance and getting Ethan’s fresh perspective on the cybersecurity workforce challenge—as someone viewing the industry from the outside.

Since the mid-season reflection, Kim has explored a wide range of workforce issues, including skills mapping, talent identification, and the evolving strategies needed to close cybersecurity’s talent gap.</description>
    </item><item>
      <guid isPermaLink="false">13ad9b49eec844ddad2476725c309a91</guid>
      <pubDate>Thu, 05 Feb 2026 07:00:00 GMT</pubDate>
      <title>Security Success Stories You Haven&apos;t Heard</title>
      <category>Technology</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/pages/Palo-Alto-Threat-Vector.jpg" type="image/jpg" expression="full" width="2400" height="1256"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/threat-vector/103/notes</link>
      <description>What separates organizations that truly excel at cybersecurity from those that just spend money on it?
In this episode of Threat Vector, host ⁠David Moulton⁠ sits down with ⁠Isaias Telhado⁠, Senior Cybersecurity Customer Success Engineer at Palo Alto Networks, to explore what cybersecurity success actually looks like. With over 25 years in IT and security leadership across Nestlé, Zscaler, and now Palo Alto Networks, Isaias has seen firsthand what transforms organizations from vulnerable and reactive to confident and resilient.</description>
    </item><item>
      <guid isPermaLink="false">8ef033962cd542a5affc1e5863ab4163</guid>
      <pubDate>Thu, 05 Feb 2026 06:00:00 GMT</pubDate>
      <title>The algorithm is writing the rulebook now.</title>
      <category>Surveillance</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/pages/Caveat-Podcast-N2K.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/caveat/294/notes</link>
      <description>This week, we are joined by ⁠Tony Scott⁠, CEO of ⁠Intrusion⁠ and former federal CIO, sharing his perspective on evolving regulation and the realities behind critical policy shifts. Ben has a story on the promise of AI to automate compliance. Dave&apos;s got reports that the Trump administration plans on using AI to write federal regulations.</description>
    </item><item>
      <guid isPermaLink="false">3c396a1f053e427f9b926777572efdc7</guid>
      <pubDate>Thu, 05 Feb 2026 06:00:00 GMT</pubDate>
      <title>Trust me, I’m legit.</title>
      <category>Cybercrime</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/pages/HH-N2K.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/hacking-humans/372/notes</link>
      <description>This week, while ⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ (also host of the ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠T-Minus⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ Space Daily show) is out at a conference, hosts⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Joe Carrigan⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ are joined by friend of the show ⁠Michele Kellerman⁠, as they are sharing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. Our hosts start with some follow-up on Joe’s egg story, including his latest update and a brief detour into unexpected “big chicken news.” Joe’s story is on a massive USDA loan fraud scheme where Nikesh Patel fabricated fake government-backed farm loans, duped investment firms out of hundreds of millions of dollars, and continued running similar scams under aliases and even from prison, ultimately earning decades more in sentencing. Michele’s story is on a breaking report about the ShinyHunters group using targeted voice phishing and custom phishing kits to abuse Okta SSO, steal MFA credentials, and gain privileged access for data theft and extortion. Dave’s story is on LastPass warning users about an active phishing campaign impersonating the company, designed to steal master passwords and potentially expose all credentials stored in affected vaults. Our catch of the day comes from the Reddit, where two people we&apos;re approached by scammers through text messaging and both dealt with their scammers in different ways.</description>
    </item><item>
      <guid isPermaLink="false">1fafa5e8c41c43bc8685853e4db48d39</guid>
      <pubDate>Wed, 04 Feb 2026 21:10:00 GMT</pubDate>
      <title>A softer touch on cyber.</title>
      <category>News</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/social-media/2026/02/cw-podcast-020426.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/daily-podcast/2482/notes</link>
      <description>The White House preps a major overhaul of U.S. cybersecurity policy. A key Commerce security office loses staff as regulatory guardrails weaken. Lawmakers Press AT&amp;T and Verizon after months of silence on Salt Typhoon. A vulnerability in the React Native Metro development server is under active exploitation. Amaranth Dragon leverages a WinRAR flaw. A coordinated reconnaissance campaign targets Citrix NetScaler infrastructure. CISA warns a SolarWinds Web Help Desk flaw is under active exploitation. Zach Edwards, Senior Threat Researcher at Silent Push, is discussing a hole in the kill chain leaving law enforcement empty-handed. Cops in Northern Ireland get an unwanted data breach encore.</description>
    </item><item>
      <guid isPermaLink="false">8e3a04234501415f9621e3835c55136f</guid>
      <pubDate>Wed, 04 Feb 2026 21:00:00 GMT</pubDate>
      <title>LevelBlue will acquire MDR provider Alert Logic from Fortra.</title>
      <category>Business</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/pages/Business-Briefing-PRO.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/newsletters/business-briefing/8/5</link>
      <description>CyberFOX has secured &quot;a nine-figure growth investment&quot; from Level Equity. TRM Labs has raised $70 million in a Series C round led by Blockchain Capital.</description>
    </item><item>
      <guid isPermaLink="false">775d259fb58e415793cb068d2f5f9cef</guid>
      <pubDate>Wed, 04 Feb 2026 17:00:00 GMT</pubDate>
      <title>White House Cyber Director launches major overhaul of cybersecurity policy.</title>
      <category>News</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/social-media/2026/02/cw-briefing-020426.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/newsletters/daily-briefing/15/22</link>
      <description>CISA warns of actively exploited SolarWinds flaw. ShinyHunters extortion group leaks Panera Bread data.</description>
    </item><item>
      <guid isPermaLink="false">3fa3f592db59498ba8cda563beb5b04f</guid>
      <pubDate>Wed, 04 Feb 2026 06:00:00 GMT</pubDate>
      <title>Disinformation, Data, and... Romance Novels? A Conversation with Dan Lowden</title>
      <category>Marketing</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/pages/breaking-through-in-cybersecurity-marketing.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/breaking-through-in-cybersecurity-marketing/197/notes</link>
      <description>Dan Lowden has a pretty incredible track record—12 startups and eight exits to count—so when he talks about building a marketing engine from scratch, people listen. In this CMO Confidential segment, Dan joins Gianna and Charles to talk about his latest challenge at Blackbird.ai: defining the &quot;Narrative Intelligence&quot; category and helping companies fight disinformation.

They get into the real-world grit of going from leading a 70-person team back to being a solo marketer. Dan shares his &quot;punch above your weight&quot; playbook, including why he hired a former CBS news reporter to lead content and how he landed NATO as a marquee customer.

Listen to this episode if you are looking to make a small startup feel like an industry giant, build deep analyst credibility without a &quot;pay-to-play&quot; budget, or understand the next big CISO blind spot in narrative intelligence.</description>
    </item><item>
      <guid isPermaLink="false">aec5d0e35d524cb097d597198f4d4d67</guid>
      <pubDate>Tue, 03 Feb 2026 21:10:00 GMT</pubDate>
      <title>The algorithm gets questioned.</title>
      <category>News</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/social-media/2026/02/cw-podcast-020326.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/daily-podcast/2481/notes</link>
      <description>French police raid X’s Paris offices. The Feds take over $400 million from a dark web cryptocurrency mixer. The NSA says zero-trust goes beyond authentication. Researchers warn of a multi-stage phishing campaign targeting Dropbox credentials. A new GlassWorn campaign targets macOS developers. Critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile are under active exploitation. Researchers disclose a major data exposure on Moltbook, a social network built for AI agents. States bridge the gaps in election security. Nitrogen ransomware has a fatal flaw that permanently destroys data. Supersize your passwords — you want fries with that?</description>
    </item><item>
      <guid isPermaLink="false">5df095a03aab4bc9ba751f84819993a0</guid>
      <pubDate>Tue, 03 Feb 2026 17:00:00 GMT</pubDate>
      <title>French police raid X&apos;s Paris offices.</title>
      <category>News</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/social-media/2026/02/cw-briefing-020326.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/newsletters/daily-briefing/15/21</link>
      <description>Moltbook database exposed 1.5 million API authentication tokens. Nitrogen ransomware cannot be decrypted.</description>
    </item><item>
      <guid isPermaLink="false">9ccc2d168751478e83d62de35d7b06d8</guid>
      <pubDate>Tue, 03 Feb 2026 12:00:00 GMT</pubDate>
      <title>Building the US’s First Known Gang Intelligence Database in Latin America</title>
      <category>History</category>
      <media:content url="https://dev.cicd.thecyberwire.comhttps://images.thecyberwire.com/hubfs/www/images/podcast/spycast/SpyCast-Ep-53_Tabor.jpg" type="image/jpg" expression="full" width="2400" height="1256"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/spycast/718/notes</link>
      <description>As an agent with the Drug Enforcement Administration (DEA) who later embedded with the CIA, Wes Tabor worked to dismantle criminal networks in Central and South America - think gangs like MS-13, the Sinaloa Cartel, and Tren de Aragua. In 2006, he was stationed in Guatemala, a transit corridor for South American cocaine to enter the US. It was during this time that he created a gang intelligence system to help identify gang members, using biodata and records from regional prisons and police departments. As confirmed by two retired DEA agents, the FBI then took the database and made it their own. This is how it happened.</description>
    </item><item>
      <guid isPermaLink="false">280e429a59a240c7999542e2da35d3df</guid>
      <pubDate>Tue, 03 Feb 2026 11:00:00 GMT</pubDate>
      <title>When Hacktivists Target Water Utilities: Inside a Russian-Aligned OT Attack</title>
      <category>Technology</category>
      <media:content url="https://dev.cicd.thecyberwire.comhttps://images.thecyberwire.com/hubfs/www/images/podcast/data-security-decoded/Data-Security-Decoded-DanieldosSantos-20260203.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/data-security-decoded/44/notes</link>
      <description>Russian-aligned hacktivist groups are increasingly targeting industrial control systems and OT environments—and sometimes it’s shockingly easy. In this episode, ⁠Daniel dos Santos⁠, VP of Research at ⁠Forescout⁠, walks through how his team used a honeypot to observe an attack against a simulated water treatment facility. We explore attacker motivations, common entry points, and what defenders must prioritize now.</description>
    </item><item>
      <guid isPermaLink="false">84bc148a7f1949daa3cb83676b33b254</guid>
      <pubDate>Tue, 03 Feb 2026 08:05:00 GMT</pubDate>
      <title>Trust Is Patient Well-being: Rob Suárez on Cybersecurity in Healthcare</title>
      <category>Technology</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/pages/afternoon-cyber-tea.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/afternoon-cyber-tea/124/notes</link>
      <description>Rob Suárez, Vice President and Chief Information Security Officer at CareFirst BlueCross BlueShield joins Ann on this week’s episode of Afternoon Cyber Tea. In the conversation, Rob shares how his career path and personal philosophy have shaped a mission-driven approach to cybersecurity that places patient trust, safety, and privacy at the center of every decision. He discusses the unique challenges of securing a deeply interconnected healthcare ecosystem, the critical role of culture and cyber literacy across organizations, and why transparency and resilience are essential during incidents. The episode also explores secure-by-design principles, the ethical use of AI in healthcare, and how the CISO role is evolving toward a broader focus on trust, collaboration, and human impact.</description>
    </item><item>
      <guid isPermaLink="false">2a4851d7784c4518bc779c5715d3b450</guid>
      <pubDate>Tue, 03 Feb 2026 07:00:00 GMT</pubDate>
      <title>Mid season reflection with Kim Jones.</title>
      <category>Technology</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/social-media/cso-perspectives/CISOP_061025_PUBLIC.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/cso-perspectives-public/110/notes</link>
      <description>In this mid-season episode, Kim takes a step back to reflect on the journey so far—revisiting key conversations, standout moments, and recurring themes that have shaped the season. During the episode, Kim sits down with N2K&apos;s own Ethan Cook to connect the dots across episodes, uncovering deeper patterns and takeaways. Whether you&apos;re catching up or tuning in weekly, this episode offers a thoughtful recap and fresh perspective on where we&apos;ve been—and what&apos;s still to come.</description>
    </item><item>
      <guid isPermaLink="false">a98f593c66cf4ad192684b7467f51bb4</guid>
      <pubDate>Tue, 03 Feb 2026 06:00:00 GMT</pubDate>
      <title>When legit is the trick: Phishing’s sneaky new moves.</title>
      <category>Cybercrime</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/pages/OMITB.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/only-malware-in-the-building/20/notes</link>
      <description>Welcome in! You’ve entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today’s most interesting threats. Your host is ⁠⁠⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠⁠⁠DISCARDED⁠⁠⁠⁠⁠⁠⁠. Inspired by the residents of a building in New York’s exclusive upper west side, Selena is joined by her co-hosts ⁠⁠⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠⁠⁠Qintel⁠⁠⁠⁠⁠⁠.
Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. On this episode, our hosts discuss how attackers are increasingly abusing legitimate, trusted Microsoft workflows to make phishing campaigns more convincing and harder to spot. In device code phishing, victims are socially engineered into completing a real Microsoft OAuth login flow, inadvertently granting attackers valid access tokens without ever sharing a password. They also examined abuse of Microsoft 365 Direct Send, which allows threat actors to send phishing emails that appear to originate from inside an organization, reinforcing a broader shift toward weaponizing built-in cloud services rather than relying on obviously malicious infrastructure.</description>
    </item><item>
      <guid isPermaLink="false">868866dcc94046a28e4255709d0d2bb8</guid>
      <pubDate>Mon, 02 Feb 2026 21:10:00 GMT</pubDate>
      <title>Wind and solar take a cyber hit.</title>
      <category>News</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/social-media/2026/02/cw-podcast-020226.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/daily-podcast/2480/notes</link>
      <description>Poland says weak security left parts of its power grid exposed. A Russian-linked hacker alliance threatens Denmark with a promised cyber offensive. Fancy Bear moves fast on a new Microsoft Office flaw, hitting Ukrainian and EU targets. Researchers find a sprawling supply chain attack buried in the ClawdBot AI ecosystem. A new report looks at how threats are shaping the work of journalists and security researchers. A stealthy Windows malware campaign blends Pulsar RAT with Stealerv37. A former Google engineer is convicted of stealing AI trade secrets for China. The latest cybersecurity funding and deal news. On our Afternoon Cyber Tea segment, Microsoft’s Ann Johnson chats with Dr. Lorrie Cranor from Carnegie Mellon about security design. The AI dinosaur that knew too much.</description>
    </item><item>
      <guid isPermaLink="false">589098458a2d40a485d349a79138e892</guid>
      <pubDate>Mon, 02 Feb 2026 17:00:00 GMT</pubDate>
      <title>Poland&apos;s energy infrastructure lacked basic security measures, CERT Polska says.</title>
      <category>News</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/social-media/2026/02/cw-briefing-020226.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/newsletters/daily-briefing/15/20</link>
      <description>Suspected Chinese hackers hijacked Notepad++ update traffic. Former Google engineer convicted of stealing AI trade secrets for China.</description>
    </item><item>
      <guid isPermaLink="false">0f7a94e77e9f4b9795a25e57f99af0e4</guid>
      <pubDate>Sat, 31 Jan 2026 06:00:00 GMT</pubDate>
      <title>The link knows all.</title>
      <category>Research</category>
      <media:content url="https://dev.cicd.thecyberwire.comhttps://images.thecyberwire.com/hubfs/www/images/podcast/research-saturday/Research-Saturday-2026-01-31.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/research-saturday/410/notes</link>
      <description>Muhammad Danish, University of New Mexico lead author and cybersecurity researcher, discussing his team&apos;s work on &quot;Private Links, Public Leaks: Consequences of Frictionless User Experience on the Security and Privacy Posture of SMS-Delivered URLs&quot;. This paper examines how the push for frictionless user experiences has led many services to rely on SMS-delivered, single-click URLs—an inherently insecure channel that can be intercepted or leaked. 

Analyzing more than 322,000 unique URLs from 33 million messages, the researchers found widespread security failures, including exposed PII across 701 endpoints at 177 services due to weak, token-based authentication that treats possession of a link as sufficient authorization. The study also identified low-entropy tokens enabling mass URL enumeration and data overfetching issues, though disclosures prompted 18 services to fix flaws, improving privacy protections for at least 120 million users.</description>
    </item><item>
      <guid isPermaLink="false">d094aca407254dbc9f488318d3fc0d4d</guid>
      <pubDate>Sat, 31 Jan 2026 05:00:00 GMT</pubDate>
      <title>Sandworm blamed for cyberattack against Poland&apos;s energy grid.</title>
      <category>News</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/pages/WTW-N2K.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/newsletters/week-that-was/10/4</link>
      <description>Google disrupts major residential proxy network. Microsoft provided the FBI with BitLocker encryption keys after receiving a warrant.</description>
    </item><item>
      <guid isPermaLink="false">9f5c818389f845adba660fcfa3314d3a</guid>
      <pubDate>Fri, 30 Jan 2026 20:50:00 GMT</pubDate>
      <title>Leaky chats collide with shifting security standards.</title>
      <category>News</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/social-media/2026/01/cw-podcast-013026.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/daily-podcast/2479/notes</link>
      <description>A popular chatbot exposes millions of private user messages. The White House rescinds Biden-era federal software security guidance. A senior Secret Service official urges more scrutiny of domain registration. The President’s NSA pick champions section 702. France looks to reduce reliance on U.S. digital infrastructure. CISA shares guidance on insider threats. Hugging Face infrastructure was abused to distribute an Android RAT. Ivanti discloses a pair of critical zero-days. Popular dating sites suffer a data breach. Our guest is Tim Starks from CyberScoop, discussing how the US looks to push its view of AI cybersecurity standards to the rest of the world. The Nobel Committee blames hackers for a spoiler alert.</description>
    </item><item>
      <guid isPermaLink="false">8b27f55fe79247f6a9786a4ce734fddc</guid>
      <pubDate>Fri, 30 Jan 2026 17:00:00 GMT</pubDate>
      <title>Popular AI app exposes millions of users&apos; chat messages.</title>
      <category>News</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/social-media/2026/01/cw-briefing-013026.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/newsletters/daily-briefing/15/19</link>
      <description>White House rescinds Biden-era software security rules. Ivanti fixes two critical zero-days.</description>
    </item><item>
      <guid isPermaLink="false">56e4b43137e04a32b0e36e7b38a82249</guid>
      <pubDate>Fri, 30 Jan 2026 05:00:00 GMT</pubDate>
      <title>Sound, Fury, and Anonymity</title>
      <category>Human Factors</category>
      <media:content url="https://dev.cicd.thecyberwire.comhttps://images.thecyberwire.com/hubfs/www/images/podcast/the-faik-files/The-FAIK-Files-057.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/the-faik-files/67/notes</link>
      <description>In this week&apos;s episode: Apple and Google officially partner to bring Gemini-powered answers to Siri; We discuss QWEN 3 TTS, a new open-source model with no guardrails; A deep dive into GenAI.mil, the military&apos;s new secure AI platform; And, GHOSTLINE: A new tool for secure, anonymous, P2P video interviews.</description>
    </item><item>
      <guid isPermaLink="false">ba40fd1478834306ad854b1cbe408e66</guid>
      <pubDate>Thu, 29 Jan 2026 21:00:00 GMT</pubDate>
      <title>EU launches investigation into X and Grok.</title>
      <category>News</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/pages/Caveat-Briefing-PRO.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/newsletters/caveat-briefing/4/4</link>
      <description>SEC drops case against cryptocurrency firm.</description>
    </item><item>
      <guid isPermaLink="false">6b6f66ddfc034941b757639aca8bd47d</guid>
      <pubDate>Thu, 29 Jan 2026 20:50:00 GMT</pubDate>
      <title>Proxy wars and open doors.</title>
      <category>News</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/social-media/2026/01/cw-podcast-012926.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/daily-podcast/2478/notes</link>
      <description>Google dismantles a huge residential proxy network. Did the FBI take down the notorious RAMP cybercrime forum? A long running North Korea backed cyber operation has splintered into three specialized threat groups. U.S. military cyber operators carried out a covert operation to disrupt Russian troll networks ahead of the 2024 elections. Phishing campaigns target journalists using the Signal app. SolarWinds patches vulnerabilities in its Web Help Desk product. Amazon found CSAM in its AI training data. Initial access brokers switch up their preferred bot. China executes scam center kingpins. Our guest is Tom Pace, CEO of NetRise, explaining how open-source vulnerabilities are opening doors for nation-states. An unsecured webcam peers into Pyongyang.</description>
    </item><item>
      <guid isPermaLink="false">45f2f2e7f0394715b11c46895537950d</guid>
      <pubDate>Thu, 29 Jan 2026 17:00:00 GMT</pubDate>
      <title>Google disrupts major residential proxy network.</title>
      <category>News</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/social-media/2026/01/cw-briefing-012926.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/newsletters/daily-briefing/15/18</link>
      <description>RAMP cybercrime forum may have been shuttered by law enforcement. North Korea&apos;s LABYRINTH CHOLLIMA splinters into three separate groups.</description>
    </item><item>
      <guid isPermaLink="false">8d0ee9ba2aa7428baaa62a5367ccebb5</guid>
      <pubDate>Thu, 29 Jan 2026 07:00:00 GMT</pubDate>
      <title>Is Your AI Well-Engineered Enough to Be Trusted?</title>
      <category>Technology</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/pages/Palo-Alto-Threat-Vector.jpg" type="image/jpg" expression="full" width="2400" height="1256"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/threat-vector/102/notes</link>
      <description>Aaron Isaksen leads AI Research and Engineering at Palo Alto Networks, where he advances state-of-the-art AI in cybersecurity. In this episode of Threat Vector, host ⁠David Moulton⁠ sits down with ⁠Dr. Aaron Isaksen⁠ to explore why engineering excellence must precede ethical AI debates, how adversarial AI is reshaping cybersecurity, and what it actually takes to build AI systems resilient enough to operate in hostile environments.</description>
    </item><item>
      <guid isPermaLink="false">f1004a01b60f4f80b666e5f7167f0bde</guid>
      <pubDate>Thu, 29 Jan 2026 06:00:00 GMT</pubDate>
      <title>Cold weather, hot scams.</title>
      <category>Cybercrime</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/pages/HH-N2K.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/hacking-humans/371/notes</link>
      <description>This week, hosts⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠,⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Joe Carrigan⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, and ⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ (also host of the ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠T-Minus⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ Space Daily show) are sharing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. Joe has two stories this week, starting with scammers cashing in on a Verizon outage by luring customers with fake credits, and ending with a rare cybercrime comeback as a woman who lost nearly $1 million gets her money back and then some. Dave’s story looks at scammers cashing in on the Ozempic and GLP-1 craze, as Wisconsin consumers lose hundreds of dollars to fake weight loss drugs, deepfake ads, and shady online pharmacies exploiting high demand and high prices. Maria’s story warns that scammers are impersonating electric, gas, and water companies this winter, using urgent threats, fake refunds, and unusual payment demands to steal money and personal information, while officials remind customers to hang up and verify any contacts through official channels. Our catch of the day comes from Reddit where the chief of police is reaching out via text.</description>
    </item><item>
      <guid isPermaLink="false">3b8400e0de42465cb114c4217cb72a6b</guid>
      <pubDate>Thu, 29 Jan 2026 06:00:00 GMT</pubDate>
      <title>Compliance in the age of surveillance.</title>
      <category>Surveillance</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/pages/Caveat-Podcast-N2K.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/caveat/293/notes</link>
      <description>On today&apos;s episode of Caveat, we are joined by ⁠Matt Hillary⁠, Chief Information Security Officer at ⁠Drata⁠, discussing how AI is reshaping the compliance landscape and what it takes to build trust at AI speed. Ben has the story of Immigration and Customs Enforcement and their extensive use of modern surveillance tools. Dave discusses the Supreme Court’s taking of a case involving Facebook tracking pixels and video store rentals.</description>
    </item><item>
      <guid isPermaLink="false">5c9d9db031694a0b913d4cd22ecdca4c</guid>
      <pubDate>Wed, 28 Jan 2026 21:00:00 GMT</pubDate>
      <title>Upwind secures $250 million in a Series B round.</title>
      <category>Business</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/pages/Business-Briefing-PRO.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/newsletters/business-briefing/8/4</link>
      <description>Claroty raises $150 million in Series F round.</description>
    </item><item>
      <guid isPermaLink="false">698ee54f776f4650a356b983a0016b06</guid>
      <pubDate>Wed, 28 Jan 2026 20:50:00 GMT</pubDate>
      <title>When the Director uses the wrong chat window.</title>
      <category>News</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/social-media/2026/01/cw-podcast-012826.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/daily-podcast/2477/notes</link>
      <description>CISA’s interim director uploaded sensitive government material into the public version of ChatGPT. The cyberattack on Poland’s power grid compromised roughly 30 energy facilities. The EU and India sign a new partnership that includes expanded cyber cooperation. Meta rolls out enhanced WhatsApp security features. Researchers uncover a campaign targeting LLM service endpoints. Fortinet and OpenSSL patch multiple vulnerabilities. A high-severity WinRAR vulnerability continues to see widespread exploitation six months after it was patched. The SoundCloud data breach affected nearly 30 million users. Ben Yelin explains the California lawsuit accusing social media platforms of harming kids. A Spanish resort town gets hit with low-rent ransomware.</description>
    </item><item>
      <guid isPermaLink="false">01432b8504e948c599b035a3b9c525ea</guid>
      <pubDate>Wed, 28 Jan 2026 17:00:00 GMT</pubDate>
      <title>Cyberattack on Poland&apos;s energy infrastructure compromised around thirty facilities.</title>
      <category>News</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/social-media/2026/01/cw-briefing-012826.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/newsletters/daily-briefing/15/17</link>
      <description>Threat actors continue to exploit months-old WinRAR flaw. SoundCloud breach affected nearly 30 million accounts.</description>
    </item><item>
      <guid isPermaLink="false">a04e32c2e5864e0dadf86c810591a8e8</guid>
      <pubDate>Wed, 28 Jan 2026 08:05:00 GMT</pubDate>
      <title>Fact vs Hype: How Threat Actors Are Really Using AI Right Now</title>
      <category>Technology</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/pages/MTI-Podcast.jpg" type="image/jpg" expression="full" width="2400" height="1256"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/microsoft-threat-intelligence/61/notes</link>
      <description>In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠⁠Sherrod DeGrippo⁠ is joined by security researcher Crane Hassold and Digital Defense Report lead Chloe Mesdaghi for a grounded, practitioner-led discussion on where artificial intelligence actually stands today. Moving beyond hype and fear-driven narratives, the conversation examines how AI is realistically being used by threat actors, where its impact is often overstated, and why defenders currently stand to gain the most from AI-driven tooling.  

The episode explores AI’s strengths in detection, triage, and workflow acceleration, the psychology and incentives that shape attacker behavior, and emerging risks such as prompt injection and AI systems becoming direct attack targets.</description>
    </item><item>
      <guid isPermaLink="false">015e202c69db4c67bb3d38d1e6e96f2c</guid>
      <pubDate>Wed, 28 Jan 2026 06:00:00 GMT</pubDate>
      <title>The ROI of Recognition: How DataGrail Built a Brand Engine Through Awards</title>
      <category>Marketing</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/pages/breaking-through-in-cybersecurity-marketing.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/breaking-through-in-cybersecurity-marketing/196/notes</link>
      <description>What happens when a &quot;privacy freak&quot; takes over customer advocacy? You get the DataGrail’s Data Privacy Awards Program, an industry staple that doubles as a masterclass in community building and product research.

In this episode, Ian Phippen, Head of Content and Community Marketing at DataGrail, joins Gianna and Maria to pull back the curtain on running a high-impact awards program. Ian shares how they transformed a standard advocacy play into a mission-driven brand engine that attracts hundreds of nominations, of which only 40% are customers.

Whether you&apos;re launching your first awards ceremony or looking for more human ways to connect with your technical audience, Ian’s insights offer a roadmap for marketing with integrity.</description>
    </item><item>
      <guid isPermaLink="false">1d98e85ea2924007ae09374dc5cba6c1</guid>
      <pubDate>Tue, 27 Jan 2026 20:50:00 GMT</pubDate>
      <title>“The hackers made me do it,” or did they?</title>
      <category>News</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/social-media/2026/01/cw-podcast-012726.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/daily-podcast/2476/notes</link>
      <description>Microsoft rushes an emergency fix for an actively exploited Office zero-day. A suspected cyberattack halts rail service in Spain. The FBI probes Signal chats in Minnesota. The UK moves to overhaul policing for the cyber age. Romania investigates a hitman-for-hire site. A UK court awards $4.1 million in a Saudi spyware case. Google agrees to a voice assistant settlement. CISA maps post-quantum crypto readiness. Prosecutors charge an Illinois man over a Snapchat hacking scheme targeting hundreds of women. Our guest today is Cynthia Kaiser, SVP of the Ransomware Research Center at Halcyon, sharing some insight into the AI and quantum threats to cybersecurity and the national cyber strategy. A Best Buy guy tries a creative alibi.</description>
    </item><item>
      <guid isPermaLink="false">9bf254bfde1c4699affe5aed6879cdc4</guid>
      <pubDate>Tue, 27 Jan 2026 17:00:00 GMT</pubDate>
      <title>Microsoft patches actively exploited Office flaw.</title>
      <category>News</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/social-media/2026/01/cw-briefing-012726.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/newsletters/daily-briefing/15/16</link>
      <description>UK proposes a new national police force to address cybercrime. Google agrees to pay $68 million to settle a privacy-related lawsuit.</description>
    </item><item>
      <guid isPermaLink="false">6c13ff500fca46d7ad2d9e0ae628ba98</guid>
      <pubDate>Tue, 27 Jan 2026 12:00:00 GMT</pubDate>
      <title>Looking Back on the US Invasion of Panama</title>
      <category>History</category>
      <media:content url="https://dev.cicd.thecyberwire.comhttps://images.thecyberwire.com/hubfs/www/images/podcast/spycast/SpyCast-Ep-52_Costa.jpg" type="image/jpg" expression="full" width="2400" height="1256"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/spycast/717/notes</link>
      <description>This January marks the anniversary of the conclusion of Operation Just Cause, which began days before Christmas, on December 20th, 1989, when about 27,000 US troops deployed to Panama. Their mission was to capture Panama’s notorious dictator, General Manuel Noriega, whom the US had indicted for drug trafficking. Noriega had also been suppressing unarmed demonstrators, gathering intelligence on the local population, and harassing Americans- wielding weapons from the Soviet bloc. International Spy Museum Executive Director Chris Costa was an intelligence officer on the ground during the invasion, and he takes us from the first mortar to the moment when Noriega surrendered to US forces.</description>
    </item><item>
      <guid isPermaLink="false">be7bf0f1fa924857bbf5fc3841aeda9b</guid>
      <pubDate>Tue, 27 Jan 2026 07:00:00 GMT</pubDate>
      <title>How do you gain “experience” in cyber without a job in cyber?</title>
      <category>Technology</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/social-media/cso-perspectives/CISOP_042925_PUBLIC.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/cso-perspectives-public/109/notes</link>
      <description>While the cybersecurity industry has expanded and grown in recent years, newcomers still struggle to gain relevant &quot;experience&quot; before officially beginning their cyber careers. In this episode of CISO Perspectives, host ⁠Kim Jones⁠ sits down with ⁠Kathleen Smith⁠, the Chief Outreach Officer at ⁠clearedjobs.net⁠ and the co-host of ⁠Security Cleared Jobs⁠: Who’s Hiring &amp; How, to discuss this dilemma and what new entrants can do to account for these difficulties. Throughout the conversation, Kathleen and Kim will discuss the challenges associated with entry-level cyber positions, how to gain meaningful experience, and how the industry as a whole contributes to this problem.</description>
    </item><item>
      <guid isPermaLink="false">29e4c339271e401aaca1153e4e7973a2</guid>
      <pubDate>Mon, 26 Jan 2026 21:00:00 GMT</pubDate>
      <title>When encryption meets enforcement.</title>
      <category>News</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/social-media/2026/01/cw-podcast-012626.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/daily-podcast/2475/notes</link>
      <description>Microsoft granted the FBI access to laptops encrypted with BitLocker. The EU opens an investigation into Grok’s creation of sexually explicit images. Glimmers of access pierce Iran’s internet blackout. Koi Security warns npm fixes fall short against PackageGate exploits. Some Windows 11 devices fail to boot after installing the January Patch Tuesday updates. CISA warns of active exploitation of multiple vulnerabilities across widely used enterprise and developer software. ESET researchers have attributed the cyberattack on Poland’s energy sector to Russia’s Sandworm. This week&apos;s business breakdown. Brandon Karpf joins us to talk space and cyber. CISA sits out RSAC.</description>
    </item><item>
      <guid isPermaLink="false">3c5b6a5d10074af0b796d18a8cdbf246</guid>
      <pubDate>Mon, 26 Jan 2026 17:00:00 GMT</pubDate>
      <title>Sandworm blamed for attempted cyberattack against Poland&apos;s energy grid.</title>
      <category>News</category>
      <media:content url="https://dev.cicd.thecyberwire.com/images/social-media/2026/01/cw-briefing-012626.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/newsletters/daily-briefing/15/15</link>
      <description>Microsoft provided the FBI with BitLocker encryption keys after receiving a warrant. CISA flags critical VMware flaw as actively exploited.</description>
    </item><item>
      <guid isPermaLink="false">779e1e32c20444e9bdb5cf7fcfd883d5</guid>
      <pubDate>Sat, 24 Jan 2026 06:00:00 GMT</pubDate>
      <title>Caught in the funnel.</title>
      <category>Research</category>
      <media:content url="https://dev.cicd.thecyberwire.comhttps://images.thecyberwire.com/hubfs/www/images/podcast/research-saturday/Research-Saturday-2026-01-24.jpg" type="image/jpg" expression="full" width="2640" height="1320"></media:content>
      <link>https://dev.cicd.thecyberwire.com/podcasts/research-saturday/409/notes</link>
      <description>Today we have ⁠Andrew Northern⁠, Principal Security Researcher at ⁠Censys⁠, discussing &quot;From Evasion to Evidence: Exploiting the Funneling Behavior of Injects&quot;. This research explains how modern web malware campaigns use multi-stage JavaScript injections, redirects, and fake CAPTCHAs to selectively deliver payloads and evade detection. 

It shows that these attack chains rely on stable redirect and traffic-distribution chokepoints that can be monitored at scale. Using the SmartApe campaign as a case study, the report demonstrates how defenders can turn those chokepoints into high-confidence detection and tracking opportunities.</description>
    </item>
    </channel>
  </rss>