meta_pixel
Tapesearch Logo
Log in
CyberWire Daily

Ghosted by Grafana [Research Saturday]

CyberWire Daily

N2K Networks, Inc.

News, Daily News, Tech News, Technology

4.81.1K Ratings

🗓️ 23 May 2026

⏱️ 28 minutes

🧾️ Download transcript

Summary

Today we are joined by ⁠Sasi Levi⁠, Security Research Lead at ⁠Noma Security⁠, sharing their team's work on "GrafanaGhost: The Phantom Stealing Your Data." Researchers at Noma Security disclosed “GrafanaGhost,” a vulnerability that could allow attackers to silently exfiltrate sensitive business data from Grafana dashboards using indirect prompt injection techniques. The attack chains together multiple bypasses, including protocol-relative URLs and AI guardrail manipulation, to trick Grafana into sending sensitive data to attacker-controlled servers without requiring user interaction. Researchers say the flaw highlights growing risks tied to AI-integrated enterprise platforms, where attackers increasingly target AI behavior and weak security controls instead of traditional software bugs. The research and executive brief can be found here: ⁠GrafanaGhost: The Phantom Stealing Your Data⁠ Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

You're listening to the Cyberwire Network, powered by N2K.

0:08.7

Do you know how the space and cybersecurity domains connect?

0:13.7

T-minus space-cyber briefing is your guide through the space-based systems that expand the attack surface.

0:20.2

I'm Maria Varmazis, host here at N2K Cyberwire,

0:23.9

and I'm excited to share that T-minus is back.

0:27.3

Now as a weekly podcast, the T-minus Space Cyber Briefing.

0:31.8

We have a new dedicated focus on two great things that are even better together,

0:36.9

space and cybersecurity.

0:39.3

Because whether we realize it or not, we all depend on space-based systems that are, by the way, increasingly Internet-enabled.

0:48.3

We're talking cybersecurity technologies, policies, and organizations that are securing the critical space-based infrastructure

0:55.2

that powers, protects, and connects our lives here on Earth. So join me for T-minus Space Cyber

1:01.9

Reefing, new episodes every Sunday.

1:15.9

Quick question. Have you watched Project Hail Mary yet?

1:21.7

Humanity is facing an existential threat and racing to solve it with the clock ticking.

1:45.7

For security teams, that probably hits close to home with AI use, rapidly spreading. Everyone's using AI, marketing, sales, engineering. Chris the intern without security even knowing about it. That's where Nudge security comes in. Nudge finds shadow AI apps, integrations, and agents on day one and helps you enforce policy without blocking productivity.

1:50.8

Try it free at nudgesecurity.com slash cyberwire. Hello everyone and welcome to the CyberWires Research Saturday.

2:04.8

I'm Dave Bittner, and this is our weekly conversation with researchers and analysts tracking down the threats and vulnerabilities,

2:12.7

solving some of the hard problems and protecting ourselves in our rapidly evolving cyberspace.

2:18.3

Thanks for joining us.

2:24.3

So Grafana is a product that can help you to see an anomaly of a request

2:33.3

or if there is an arrows, it can count it and show what was the problem.

2:40.0

It can read entry logs about your website, for example, or about internal system and monitoring.

...

Transcript will be available on the free plan in 16 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.