Hackers ignore the ceasefire.
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “Hackers ignore the ceasefire.” inside PodZeus.
The CyberWire Daily episode on April 9, 2026, delivers a comprehensive briefing on escalating cyber threats amid geopolitical tensions, particularly focusing on Iran-linked hackers who continue cyber operations despite a fragile ceasefire. Pro-Iranian groups like Handala have paused attacks on U.S. targets but remain active against Israel, while U.S. authorities warn of ongoing infiltration into critical infrastructure via programmable logic controllers. Microsoft’s sudden suspension of open-source developer accounts sparked concern over delayed security updates, later attributed to missed verification deadlines. Meanwhile, John Deere reached a landmark $99 million settlement in a right-to-repair dispute, mandating digital repair tools for 10 years. High-severity vulnerabilities were patched by Palo Alto Networks and SonicWall, while new macOS malware targets crypto wallets, and a stealthy DDoS-for-hire botnet, Majesu, continues evolving. CISA issued an urgent patch for a critical Avanti flaw with active exploitation. In a sponsored interview, Nozomi Networks CEO Edgar Capdevielli discusses the growing convergence of nation-state threats and AI in OT security, emphasizing that while industrial systems remain legacy-bound, defensive strategies are maturing through better collaboration between IT and OT teams and proactive patching. He warns that AI is leveling the playing field, enabling less-skilled hackers to become sophisticated threats. A final segment reveals a hidden 49-day system freeze in macOS due to a 32-bit counter overflow, a silent but critical flaw affecting long-running systems.
Iran-linked hackers are continuing cyber operations despite a ceasefire, with attacks targeting critical infrastructure and Israel.
AI is accelerating threat capabilities, allowing less-skilled hackers to conduct sophisticated OT attacks.
Legacy industrial systems remain vulnerable due to long lifecycles and resistance to patching, but cultural and operational shifts are improving security posture.
Microsoft’s account suspensions disrupted open-source security updates, highlighting the need for clearer communication in vendor programs.
macOS has a hidden 49-day system freeze due to a kernel-level counter overflow, requiring reboot before expiration.
…and 3 more takeaways available in PodZeus
Sponsor: Rapid7 Global Cybersecurity Summit
Rapid7 invites CISOs and security practitioners to a free two-day virtual summit on May 12–13, 2026, focused on preemptive security, exposure management, MDR, and AI-driven threat disruption.
Iran-Linked Cyber Threats Continue Despite Ceasefire
“Iran-linked hackers have already infiltrated programmable logic controllers used in critical infrastructure such as ports, power plants, and water systems.”
Microsoft Suspends Open-Source Developer Accounts
“Developers said they received no warning or clear explanation and were unable to reach human support.”
John Deere Settles Right-to-Repair Lawsuit
“The agreement also requires DEER to provide digital tools needed for maintenance, diagnostics, and repairs on tractors and combines for 10 years.”
Emerging Threats: Zero Days, Malware, and Botnets
“The malware uses social engineering, including fake Google Docs errors and a trojanized wall space app to trick users into running malicious terminal commands.”
“A mediocre hacker with AI becomes a sophisticated hacker.”
“The days of number one, I believe the huge myth that my facilities are air gapped. That's no longer the case. That's a myth. That's a lie.”
“CISA added the issue to its known exploited vulnerabilities catalog and urged all organizations to prioritize patching immediately due to ongoing risk.”
Host
Guest
Edgar Capdevielli
person
Iran-linked hackers
other
Microsoft
organization
Nozomi Networks
organization
macOS
other
John Deere
organization
CISA
other
Avanti Endpoint Manager Mobile
product
NotNullOSX
other
Handala
other
Water sector feels the pressure.
CyberWire Daily • 26m • 3/31/2026
A war of missiles and messages.
CyberWire Daily • 30m • 4/1/2026
The WhatsApp impostor.
CyberWire Daily • 30m • 4/2/2026
War comes for the cloud.
CyberWire Daily • 30m • 4/3/2026
Startup surge sparks spy interest. [Research Saturday]
CyberWire Daily • 19m • 4/4/2026
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “Hackers ignore the ceasefire.” inside PodZeus.
Start discovering podcast insights today
Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.
No credit card required • 7-day trial • Cancel anytime
