CyberWire Daily

The exploit that writes its own story.

May 6, 2026
Dov Yoran, CEO of Command Zero and security operations expert, discusses using AI to speed and standardize SOC investigations. He explains rapid onboarding of cloud AI tools, the need for guardrails and auditability, and how agentic workflows could boost analyst capabilities. The conversation focuses on practical AI adoption and governance in security operations.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

MuddyWater Masks Espionage As Ransomware

  • MuddyWater used Teams-based social engineering and screen-sharing to harvest credentials and avoid real ransomware deployment.
  • Rapid7 links the campaign to Iran-linked espionage that used chaos ransomware branding as a false flag.
INSIGHT

Fake OpenClaw Plugin Targets AI Workflows

  • Malicious OpenClaw plugin DeepSeekClaw targeted developers and autonomous AI agents to steal credentials and tokens.
  • Zscaler observed Remcos via DLL sideloading on Windows and obfuscated Node.js scripts on macOS/Linux.
INSIGHT

QLNX Aims At Software Supply Chains

  • QLNX is a Linux RAT focused on stealing developer and cloud credentials to poison software supply chains.
  • Trend Micro notes memory-only execution, rootkit features, log clearing, and PAM backdoors to maintain stealth and persistence.
Get the Snipd Podcast app to discover more snips from this episode
Get the app