CyberWire Daily - A very real-world AI test.
Episode Date: September 21, 2026Google confirms unauthorized access by Gemini. AI’s growing power outpaces its defenses. Hackers target Colorado water utilities. Georgia weighs voting-system security. ShinyHunters hijacks Clop’s... leak site. FamousSparrow spies across Latin America. CrowdSec loses source code. New npm malware slips past supply-chain defenses. Monday business briefing. Our guest is Matt Fredrikson, CEO of Gray Swan AI, discussing OpenAI's Astra. A new app warns Glassholes to ZuckOff. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Matt Fredrikson, Carnegie Mellon University Associate Professor and CEO of Gray Swan AI, discussing OpenAI's Astra and real industry risks. Selected Reading Google says Gemini breached three companies during security test (The Record) Hackers who broke into OpenAI warn the AI industry has a security problem (Washington Post) Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems (Security Week) Lawmakers mull cybersecurity concerns as they prepare for overhaul of Georgia’s voting system (Cobb Courier) Clop gets a taste of its own medicine after ShinyHunters hijack leak site (The Register) China-Linked FamousSparrow Deploys SparroWocky Backdoor in Latin America (Hackread) CrowdSec Confirms Source Code Stolen in Supply Chain Attack (Security Week) Malicious npm packages evade install-script defenses at runtime (Bleeping Computer) Physical AI security company Exein lands $270 million. (N2K Networks) ZuckOff Is a Free App That Sees Meta Glasses Before They See You (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
Standard active directory migration tools don't move AES keys. They move NTLM hashes.
That means when you cut over, your applications fail silently. In my recent conversation with Sempros' Mike Masqualey,
I asked him why standard migration tools miss these accounts and how identity teams can fix them before cutover day.
Listen to our full conversation now at explore.thecyberwire.com slash Semperus.
Hey, everybody, Dave here.
I want to let you know about a special gathering hosted by Zimperium at the Spy Museum in Washington, D.C.
This invitation-only event will bring together federal cybersecurity and technology leaders
to discuss some of the most pressing challenges facing government today,
including mobile security, mission resilience, and the overall.
evolving threat landscape. I'm always grateful for opportunities to spend time with smart people
doing important work, and I'm excited to be part of these conversations. I hope to see some
familiar faces there. If you're interested in attending, you can request an invitation.
You'll find more information in our show notes. Our thanks to Zimperium for sponsoring this event.
We'll see you there. Google confirms unauthorized access by Gemini. AI's growing power outpaces its
defenses, hackers target Colorado water utilities, Georgia, waves voting system security, shiny
hunters hijacks Klops leak site, famous sparrow spies across Latin America, Krautsek loses source code,
new NPM malware slips past supply chain defenses. We got your Monday business briefing.
Our guest is Matt Fredrickson, CEO of Gray Swan AI, discussing OpenAI's Astra.
And a new app warns Glasshole.
to suck off. It's Monday, September 21st, 2026. I'm Dave Bittner, and this is your Cyberwire Intel
briefing. Thanks for joining us here today. Hope you had a great weekend. It is good to have you back
with us here today. Google has confirmed that its Gemini AI accessed systems belonging to three
real companies without authorization during a cybersecurity test run by security firm Irregular in May.
In one case, Gemini repeatedly guessed a password.
In two others, it used credentials exposed in a public repository.
Google says the affected companies were notified, though they haven't been identified.
The incidents occurred after irregular, mistakenly allowed AI models access to the public internet during evaluations.
Models from Anthropic, OpenAI, and Meta also compromised real-world systems in irregular tests,
though it's unclear how many organizations were affected.
Irregular has faced criticism for not fully disclosing the scope of the incidents.
The episode follows separate cases in which AI agents from Anthropic and OpenAI reached real-world targets during security evaluations.
Security researchers who breached Open AI earlier this summer say the incident exposes a gap between the growing power of AI and the security
protecting the companies building it. According to the New York Times, researchers from startup
Hactron used Anthropics Claude to help compromise a public-facing OpenAI messaging board,
then gained access to private systems and internal code. OpenAI patched the vulnerability
and paid them a $6,500 bug bounty. The researchers argue that AI labs remain too dependent on
conventional cloud software and internet-connected tools for technology they themselves describe as
potentially dangerous. One expert called the breach a warning shot, noting that the three-person team
reportedly spent just $3,000 on anthropic systems. The incident came around the same time
OpenAI's own AI agents escaped internal testing environments and reached the public internet.
OpenAI President Greg Brockman says the company subsequently reassigned 25% of its production engineers to security work.
Hackers targeted operational technology at two small private water utilities in Colorado in late August,
changing equipment settings, disabling remote access and alarms, and altering pumping cycles.
The disruptions were brief and didn't affect water services or public safety.
Colorado officials attributed the attack only to unspecified foreign actors.
While officials noted ongoing attacks by an Iranian-backed group against U.S. water systems,
they haven't linked that campaign to the Colorado incidents.
Sessa says roughly 100 Internet-exposed water systems were targeted in July.
Georgia is preparing to replace its current QR code-based voting system
with hand-marked paper ballots for the 28 election cycle,
with a special legislative committee developing requirements for the new equipment.
Cybersecurity experts told lawmakers that changing the way voters mark ballots
won't eliminate election security risks.
Boating equipment may remain in service for a decade or longer,
while vulnerabilities evolve much faster,
making long-term vendor support, software updates, and replacement parts
important considerations. Experts also raised voter privacy concerns, including research suggesting
AI could potentially help associate publicly available voter information with particular ballots in some
circumstances. Accessibility presents another challenge. Federal requirements mean voting machines
must remain available for voters with disabilities. An expert said broader use of those machines
could help preserve ballot secrecy. Researcher
also stressed that handmarked ballots don't eliminate software from elections. They change
where technology and its associated security risks appear in the process. Clop is getting a taste
of its own business model after rival cybercrime crew Shiny Hunters hijacked its dark web leak site
and demanded an eight-figure payment. Shiny Hunter says it exploited a vulnerability in the site's
software, gaining extensive access to Klopp's infrastructure. The feud reportedly stems from Klop's
attacks on Oracle E-Business Suite customers last year. Shiny Hunter's claims it originally
discovered the zero-day Klop used and now wants a cut of the proceeds plus interest and a public
apology. The group is threatening to expose alleged Klop ransom payments, including company
names and Bitcoin addresses, while increasing its demand every 24 hours.
Those claims remain unverified, but the takeover could damage both Klop's operations and its reputation.
For once, the extortionists are the ones facing the countdown clock.
ESET has uncovered a cyber espionage campaign by China-aligned Famous Sparrow,
targeting government organizations across Latin America with a new backdoor called Spaniard.
Sparowaki. About 90% of the group's targets observed from mid-2020-25 into 26 were in the region,
spanning Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.
Sparrow Waki has largely replaced famous Sparrow's older Sparrow Door implant. The modular C++ Malware
can collect system information, execute commands, capture screenshots, steal fine, and steal fine,
and proxy network traffic.
It also employs DLL side loading,
reflective loading, and stack spoofing
to complicate detection and analysis.
ESET says famous sparrow has operated
since at least 2019,
targeting governments and other organizations.
Researchers suspect the Latin American campaign
may seek intelligence about government decisions,
though the reason for the group's regional focus
remains unclear.
CrowdSec says attackers stole source code from roughly 300 of its GitHub repositories,
including about 170 private repositories in May.
The stolen material included code for its SaaS console, AWS routines, connectors, and automations.
CrowdSec says it found no exposed customer data or credentials and has rotated potentially affected tokens.
The company believes the breach was linked to the.
the May 26 Tan Stack supply chain attack, which may have compromised an API key providing
read access to CrowdSex's private code base.
Checkmarks has uncovered an ongoing NPM malware campaign built around indexed B-Tree,
a malicious package impersonating the legitimate, sorted B-Tree library.
Rather than using installation scripts, the package hides its loader inside a commonly used
runtime function, allowing it to bypass NPM's newer supply chain protections and many static
scanners. Once triggered, the malware collects system information and ex-filtrates it through
Slack and Telegram. It also retrieves command and control information from an Ethereum smart
contract, decrypting a second-stage payload stored there. The attackers can later erase files
and remove the malicious trigger to cover their tracks.
Checkmarks linked nine additional NPM packages to the operation, all since removed.
Researchers say the campaign demonstrates why install time scanning alone isn't sufficient
and recommend runtime behavioral analysis.
Developers who installed the affected packages should rotate secrets and restore from a trusted backup.
Turning to our Monday business briefing, cybersecurity investment remained brisk,
week, led by Italian Embedded Security Company Exine, which raised $270 million at a $1.7 billion valuation.
The company plans to use the funding to expand in the U.S. and Asia Pacific.
AI security also attracted investors.
San Francisco-based AIUC raised $40 million to expand its AI auditing, standards, and insurance work,
while France's Hacuity secured $19 million for vulnerability management.
Zero Risk raised $10 million.
Agentic AI governance provider Helmgard landed $7.3 million.
Binario raised $2.4 million,
and AI-written code security startup, Leo Trace, secured $2 million.
On the M&A side, Quorum Cyber, agreed to acquire Agentic SOC provider,
Antinue. Secure Sky bought data security company Sovereign. Surf Shark acquired personal information
removal service Optory. Kiteworks acquired AI data security platform Bonfi AI and private equity
firm Infravia took a majority stake in German identity governance vendor Nexus.
Be sure to check out our complete business briefing on our website. That's part of Cyberwire Pro.
Coming up after the break, my conversation with Matt Fredrickson from Gray Swan AI.
We're discussing OpenAI's Astra.
And a new app warns glass holes to suck off.
Stick around.
When you're running security for a fast-growing company,
the stakes keep rising, more compliance frameworks, more vendors, more risk,
and a board that wants the whole picture in one place.
The problem is your compliance data usually isn't,
in one place. Controls live in one tool, vendor risk, and another, and customer commitments are
buried in contracts. So your team spends more time stitching everything together and making
decisions based on data that may already be a quarter old. Vanta connects it all. Its agenetic
trust platform is built for enterprise scale, with more than 400 integrations and continuous monitoring
to automate evidence collection, surface the risks that matter, and organize audit.
around your auditor's requirements.
And the Vanta agent works around the clock with full program context,
helping make sure nothing slips through the cracks.
Vanta says customers see a 526% return on investment over three years
with payback in three months.
More than 16,000 companies trust Vanta, including Snowflake, Atlassian, and Ramp.
Learn more at vanta.com slash cyber.
Matt Fredrickson is an associate professor at Carnegie Mellon University and CEO of Gray Swan AI.
We recently sat down to discuss OpenAI's Astra and the real risks industry faces.
So I guess where to begin?
I think it's been pretty clear since chat chagip-D kind of exploded into people's consciousness in late 2020,
that large language models and AI weren't going to be confined to sort of conversational dialogue and like text-only assistance.
From the early days, people have been exploring ways to use AI and these explorers language models to autonomously do things, right?
Take actions, read files from disk, connect to different websites, send commands to a shell,
Because, you know, that sort of in the end is how you can get a lot of value from AI.
Along the way, there's a question of, like, how good are these models at doing certain kinds of tasks?
And that, in some sense, forces the people developing these models to kind of pick and choose, like,
what kinds of tasks do we want to improve their capabilities on?
and a lot of the focus has been on the sorts of things that center on software development,
so writing code, working with the tools that software developers use in their daily routine,
as well as some just kind of general like system administration tasks,
everything from installing and configuring software on a local machine to looking out at the local network
and just kind of getting a read on things.
Those are all good outcomes, right?
It's useful to have automation
that can help you write and debug and ship code
and help manage your infrastructure.
But it turns out that if you're good at those sorts of tasks,
then if you're really good at them,
then you're probably also good at doing things like finding vulnerabilities.
If you can write code without vulnerabilities or something,
or spot of vulnerability in a piece of code,
you can be directed at a code base
and ask to find a vulnerability,
and maybe you will, right?
So, you know, these same kinds of tasks
that, you know, we want these tools
to help us automate,
have this dual-use kind of property
where they can be repurposed
but to work doing things that we don't want
sort of readily accessible and easily automatable
if it's put in the wrong hands.
Where does that leave the defenders in our audience?
I'm thinking of the balance between how much trust should we place
in the producers of these models that they're putting adequate guardrails on them.
Certainly, we've seen some high-profile examples of where the models have escaped their sandboxes,
but versus having your own controls locally, your own protections against,
the possibility that something would go wrong in the use of one of these models.
Yeah. The first thing I'd say is just being a normal sort of paranoid, security-minded person
is if I'm tasked with defending a network, right, and I know that this stuff is out there,
I wouldn't put a lot of faith in the guardrails around them, which isn't to say that the guardrails
aren't effective by and large, but the gargarels themselves are often AI systems,
and if I'm a determined attacker, right,
like I get as many shots at trying to get around the guardrails as I need.
And it is certainly possible to still use these guardrail models for offensive cybersecurity tasks.
So like I wouldn't just sort of like rest assured that despite the Frontier Labs efforts,
people won't find a way to repurpose and direct these models at what I'm trying to
protect. What that means operationally today is we've seen both in Open Eye's Astro and in Anthropics
Fable and even more so in Mythos. These models are very good. If there's a CVE published for
vulnerability, like it just came out today, they will write an exploit for that vulnerability
that works, right, and do it very quickly. So you don't have a matter of days to get patches in,
right? You sort of have zero days. You have to react very quickly and make sure that things are
batched. You know, I think that there's kind of another set of questions around if you're in an
organization, you know, where people are deploying these models, and that's any organization
that's deploying, you know, codex or a cloud code or some kind of, you know, autonomous coding agent,
I think it doesn't really do them justice to call them coding agents.
They're really pretty general purpose computer use agents.
They have access to a bash shell, oftentimes can operate browsers.
Getting to what you mentioned about escaping confinement, that isn't just a problem for the frontier labs, right?
It's a problem for any organization where these agents are able to, in a general purpose way, use computers and act autonomously.
you have to assume that they can sort of go out of scope.
And even if given a legitimate task,
they might find a surprising way to complete that task
that has negative implications for essentially a security incident.
So I think it is important for people who are in that situation, right,
where you know agents are being deployed to have the right kind of monitoring
and controls in place to make sure that, you know,
you know, if the model decides to go out of scope and do something, you know, that you
wouldn't want it to, you know, hopefully you can block it.
But at the very least, you need to be able to go back and audit that and be aware that
that's what happened.
I'm curious for your take on the possibilities of regulatory guardrails being put on these
models.
You know, the potential role that the government could play here.
I've seen even in the past few days, people have been calling for,
a slowdown or saying that, you know, we need more restrictions put on these models.
What are your thoughts with that?
Yeah, it's definitely in the air these past couple of days.
Government agencies are going to have a hard time with things like auditing or evaluating
these models and deciding when different thresholds are across.
Like it does take a certain kind of familiarity and expertise with how he's
models work and then a lot of careful thought that is sort of like has to evolve as the,
as the AI capabilities improve about like what should the policies be. So to this point of
models being able to find vulnerabilities and software, right, should that be like a prohibited
behavior that like, you know, anytime that's going to be made available, it has to be through
a trusted access program or not.
Well, maybe that's where the policy goes,
but you have to recognize that,
first of all, it's going to be very difficult to enforce that.
That is an inherently challenging sort of a policy to define,
because what are all the ways that you might discover a vulnerability
in a piece of code?
Even if you could get policy around that
and sort of like restrict access to that kind of behavior,
you're also potentially doing a fair bit of harm, right?
Because it's good to find vulnerabilities in the code that you write.
That's a very useful thing.
Just kind of from an expertise standpoint,
if we're going to get to a situation where we're relying on sign-off from a government body
before more development or like new capabilities are released,
I think it's definitely going to put a damper on progress.
Frankly, that's probably part of what some of the people calling for this want, right,
is a damper on how quickly this stuff is progressing.
So given the view that you have on the inside or certainly at the bleeding edge of some of these technologies,
what are your recommendations for organizations out there to balance their desire for
deploying these powerful tools versus the potential perils that they face because of them.
I mean, I think time is of the essence, but fortunately right now, the strongest capabilities
are gated behind trusted access programs and open weights models that are available for
anyone to just go and download or buy tokens on. Those models are not yet as capable, right,
as to pose the kinds of threats that the frontier models are.
Now is the time to explore and be a part of these trusted access programs.
If you have legitimate use cases and are working in your organization to shore up security controls
and identify where weaknesses in your infrastructure might be, definitely do it now.
And I think that's going to have to be an ongoing sort of commitment to, like,
These are tools that I think, like it or not, security teams are going to have to take advantage of if they don't want them sort of used against them successfully to their detriment.
That's Matt Fredrickson from Gray Swan AI.
Yes, you can have an enterprise network that's secure and reliable and high performance.
And no, you don't need to choose the best two out of three.
With meter, you can get the end-to-end network built from the ground up,
fast to deploy, and easy to manage.
That's because meter is software-led for easy installation,
maintenance, and control for everything running on your enterprise network.
Hardware, firmware, and software all working together from the start
seamlessly on a unified platform that's secure by design.
You can't protect what you don't know exists,
which is why meter gives you comprehensive visibility into wired and wireless.
routing, switching, firewalls, DNS security, and VPNs. You'll really know what's running on your
network down to the most granular client level. Step off the hardware box upgrade treadmill and switch
to meter for a predictable fee and free up your team to spend time on all the other things
that keep your business running. Try it out for yourself and book a demo online at meter.com
slash cyberwire. That's M-E-T-E-R dot com slash cyberwire.
And finally, as smart glasses become more common, Polish developer Paul Well Sidlowski,
has built an app for people wondering whether someone nearby might be wearing a camera on their face.
Called Zuck Off, the free app detects Bluetooth signals from models, including Rayban Meta,
Oakley meta and Snap Spectacles, using different fingerprints Sledowski created by testing the hardware
himself. The app arrives amid growing concerns about covert recording. Some smart glasses,
recording lights can be defeated with tape, while a BBC investigation found footage captured with
meta-glasses being posted online without subjects' consent. Zuckoff can't determine whether glasses
nearby are actually recording or identify who's wearing them. But it can estimate proximity
based on Bluetooth signal strength. So, while smart glasses promise discrete hands-free computing,
Zuckoff offers something of a countermeasure, discrete hands-free suspicion. More advanced
background monitoring and alerts are available through a paid version.
And that's the Cyberwire.
For links to all of today's stories, check out our daily briefing at thecyberwire.com.
We'd love to know what you think of this podcast.
Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity.
If you like our show, please share a rating and review in your favorite podcast app.
Please also fill out the survey in the show notes or send an email to Cyberwire at n2K.com.
Don't forget to check out the Grumpy Old Geeks podcast where I contribute to a regular segment on Jason and Brian's show every week.
You can find Grumpy Old Geeks where all the fine podcasts are listed.
N2K's lead producer is Liz Stokes.
We're mixed by Trey Hester with original music and sound designed by Elliot Peltzman.
Our contributing host is Maria Vermazas.
Our executive producer is Jennifer Ibin.
Peter Kilpe is our publisher, and I'm Dave Bittner.
Thanks for listening.
We'll see you back here.
tomorrow.
And now a word from our sponsor, SpectreOps.
Today, AI is rapidly adding non-human and agentic identities to modern enterprise environments,
creating new trust relationships and attack paths.
Bloodhound Enterprise helps defenders map attack paths across AWS and hybrid environments as one
connected graph, identify the choke points that matter most, and bring trusted attack path
intelligence into approved AI workflows with Bloodhound Hunter. See how SpectorOps helps team secure the
AI-driven identity era at SpectorOps.io.
