Proposed cuts put CISA in focus.

CyberWire Daily28mApril 7, 2026

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “Proposed cuts put CISA in focus.” inside PodZeus.

AI-Generated Summary

This episode of CyberWire Daily examines a proposed $707 million budget cut to CISA for fiscal year 2027, which would refocus the agency on federal network protection while eliminating programs like school safety initiatives and international stakeholder engagement. The segment highlights growing concerns over Russian-Iranian cyber cooperation, with allegations of coordinated satellite surveillance and cyber operations targeting regional infrastructure. Meanwhile, emerging threats include new BPF door malware variants, a GPU-based Rohammer attack enabling privilege escalation, and a major cyberattack disrupting Northern Ireland’s school IT systems. In a featured Industry Voices segment, John Anthony Smith, founder and CISO of Phoenix 24, argues that organizations are failing to improve security despite investing in technology—because they neglect proper configuration, execution, and resilience. He emphasizes that most breaches are not due to missing tools but to poor implementation, alert fatigue, and a lack of survivable backups. Smith urges executives to shift focus from prevention to resiliency, advocating for orchestrated, multi-layered recovery strategies. The episode concludes with a frustrated researcher releasing exploit code for an unpatched Windows zero-day, underscoring the urgency of proactive defense and real-world threat readiness.

Key Takeaways
1

Organizations must prioritize resiliency over prevention—most security failures stem from poor configuration and recovery planning, not missing tools.

2

84% of organizations lack survivable backups, and many cannot recover from destructive attacks within acceptable RTOs/RPOs.

3

Threat actors increasingly exploit convenience-driven policies like remote SaaS access, exposing credentials and authentication tokens.

4

Complexity in security is necessary—but only when it supports orchestrated, multi-layered recovery and defense-in-depth strategies.

5

Alert fatigue is real and dangerous; many organizations ignore critical alerts, allowing attackers to dwell for hours or days.

…and 3 more takeaways available in PodZeus

Chapters
0:00
2 min

CISA Budget Cuts and Global Cyber Threats

The proposal would remove programs considered redundant, including school safety initiatives, and dissolve offices handling international affairs, stakeholder engagement, and efforts to counter misinformation.

Highlight
1:50
3 min

Emerging Malware and Cybercrime Trends

New BPF door malware variants are evading defenses using ICMP relays and stateless C2 routing. Cybercrime losses continue to rise, with over $262 million lost to account takeover fraud in 2025. Impersonation campaigns and spoofed websites remain key vectors.

5:00
5 min

Advanced Hardware-Based Attacks

Combined with memory safety flaws in NVIDIA drivers, the attack can escalate privileges to root-level system compromise.

Highlight
10:00
5 min

Northern Ireland School IT Breach

The Education Authority said it detected the incident last week and shut down system access to contain the breach.

Highlight
15:00
10 min

Why More Technology Isn’t Making Us Safer

Most of these tools are largely not configured in the context of what threat actors are able and willing to do.

Highlight
High-Impact Quotes
84% of organizations that we meet in breach—it's the first time we've ever met them to actually orchestrate their recovery from a disastrous exfiltration or destructive event.
John Anthony Smith14:56
Viral: 90.0
You're probably living in a farce. Actually, I can almost guarantee you're living in a farce.
John Anthony Smith23:28
Viral: 88.0
The researcher, posting as chaotic eclipse, declined to explain the exploit in detail, suggesting others could figure it out.
Narrator27:34
Viral: 87.0
Speakers

Host

Dave Bittner

Guest

John Anthony Smith
Topics Discussed
Cyber Resilience and Recovery95%CISA Budget Cuts90%GPU-Based Cyber Attacks88%Russian-Iranian Cyber Cooperation85%Zero-Day Exploits and Vendor Response80%BPF Door Malware Variants75%Alert Fatigue in SOCs70%Mobile Application Security60%
People & Brands

John Anthony Smith

person

20xPositive

CISA

organization

12xNeutral

BPF door malware

other

6xNegative

Phoenix 24

organization

5xPositive

Iranian hackers

other

5xNegative

Microsoft

organization

4xMixed

Northern Ireland Education Authority

organization

4xNeutral

GPU Breach

other

4xNegative

Russian satellites

other

4xNegative

Blue Hammer

other

4xNegative

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “Proposed cuts put CISA in focus.” inside PodZeus.

Start discovering podcast insights today

Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.

No credit card required • 7-day trial • Cancel anytime