CyberWire Daily - AI is calling the shots.
Episode Date: September 17, 2026AI goes to war. Iranian strikes leave AWS data unrecoverable. OpenAI discloses more model misbehavior. Researchers uncover 16 Wireshark vulnerabilities. TrustSink turns Entra authentication into a pas...sword trap. RatHat raids Android credentials. The FBI takes down a DDoS-for-hire service. A data broker loses its domains. U.S. Cyber Command names a new AI chief. Ethan Cook is joining Dave Bittner and Ben Yelin to discuss the industry-proposed and administration-opposed AI slowdown. CISA’s field of schemes. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today, Ethan Cook, N2K’s lead analyst, joins Dave Bittner and Ben Yelin for a discussion about the industry-proposed and administration-opposed AI slowdown, exploring the policy debate and what it could mean for the future of AI. If you enjoyed this conversation, be sure to check out the full interview on Caveat here. Selected Reading The era of AI warfare has arrived (Financial Times) Iran strikes on Amazon data centers caused permanent loss of customer data (Ars Technica) OpenAI Discloses Six New Incidents of ‘Concerning' A.I. Behavior (The New York Times) AISLE Discovers 16 CVEs in Wireshark, the World’s Most Popular Network Protocol Analyzer (AISLE) TrustSink: How a Rogue External MFA Provider Steals Passwords (Varonis) RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts (Zimperium) US takes down NightmareStresser DDoS-for-hire platform (Bleeping Computer) Data Broker Radaris Loses Domains in Privacy Fight (Krebs on Security) Former NGA Executive Ronzelle Green Named USCYBERCOM Chief AI Officer (ExecutiveGov) CISA releases Cyber Decoys guide detailing tripwires, honeytokens to strengthen critical infrastructure detection and response (Industrial Cyber) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
So what happens when an AI agent isn't malicious, but still does something it shouldn't?
I recently sat down with Cal Al-Dubabe, principal technologist at Rubrik, to talk about why agentic AI is challenging the way security teams think about detection, permissions, and recovery.
If your organization is deploying AI agents, this conversation will help you think differently about where the
risks are and how to prepare when things go wrong. Listen to our full conversation at explore.
thecyberwire.com slash rubric. What's the one thing in business that's spreading as fast as
AI? AI risk. Every new tool your team signs up for, every vendor that turns on AI features,
every new integration, each one is an opportunity for something to go wrong. And most security
programs weren't built for AI's pace of growth. Enter Vanta. Vanta is the number one
agentic trust platform used by over 16,000 fast-moving companies like Ramp, Hercer, and Harvey
to ensure they're always audit-ready. And now Vanta is helping companies like yours watch for the
risks that show up between audits across your vendors, your AI tools, and your whole
environment. The Vanta agent works like a 24-7 GRC engineer in the background, finding issues, drafting
fixes for you, and cutting vendor assessment time by up to 50%. Whether you're a fast-growing startup
or a global enterprise, Vanta is here to help you automate your security and compliance and earn
and prove trust. Get started today at Vanta.com slash cyber. That's V-A-N-T-A-com slash
cyber.
AI goes to war.
Iranian strikes leave AWS data
unrecoverable. OpenAI
discloses more model misbehavior.
Researchers uncover 16
wire shark vulnerabilities.
Trust sync turns intra-authentication
into a password trap.
Rat Hat raids Android
credentials. The FBI takes
down a DDoS for hire service.
A data broker loses its domains.
U.S. Cyber Command
names a new chief. Ethan
Cook and Ben Yellen join me to discuss the industry proposed and administration opposed
AI slowdown and SISA's field of schemes. It's Thursday, September 17th, 2026. I'm Dave Bittner,
and this is your Cyberwire Intel briefing. Thanks for joining us here today. It is great as always
to have you with us. Reporting from the Financial Times says artificial intelligence is
moving deeper into the machinery of war, and Ukraine has become one of its most important
proving grounds.
The Saker Scout offers a glimpse of where that could lead.
The Ukrainian quadcopter uses machine learning to recognize 47 categories of military equipment.
An operator can define the targets, confidence threshold, and geographic killbox, after which
the drone can potentially identify and attack a target without a number.
other human command. But it can't distinguish Ukrainian forces from Russian ones, making careful
deployment essential. Across the battlefield, AI is already accelerating warfare. Systems process enormous
volumes of sensor and intelligence data help prioritize targets and compress the time between
detection and attack. AI-assisted navigation can also keep drones on target after jamming breaks
their connection with operators.
Ukraine says its AI-guided drone strikes have increased tenfold since the beginning of
2006, though fully autonomous targeting, remains relatively uncommon.
The technology hasn't broken the battlefield stalemate.
Faster targeting and greater autonomy don't necessarily translate into strategic victory,
and AI introduces potentially serious problems of its own.
Targeting systems can operate on increased.
complete, outdated, or misleading information, while accelerating decisions so dramatically that
humans have little time to challenge their recommendations. That creates an accountability
problem alongside the technical one. International humanitarian law still places responsibility
on humans, even as automated systems take over more steps in the kill chain.
Ukraine's stated ambition is ultimately full autonomy, including
AI systems capable of helping commanders develop battle plans. As increasingly capable models emerge,
the question may shift from whether militaries want AI making more battlefield decisions
to whether governments can reliably control how far that autonomy goes.
Amazon Web Services says some customers' data hosted in Bahrain and the United Arab Emirates
has been permanently lost following Iranian strikes on its data centers earlier this year.
AWS says it can't restore data from one availability zone in the UAE
or from any of its three availability zones in Bahrain,
where damage exceeded what its regional and multi-zone services were designed to withstand.
Iran first struck AWS facilities in Bahrain and the UAE on March 1st,
with additional attacks targeting Bahrain in April and July.
Amazon urged customers to migrate workloads to other regions
and restore inaccessible records from remote backups
while reportedly issuing $150 million in customer credits.
AWS is still rebuilding infrastructure
and attempting to recover resources in two UAE availability zones.
The company says most affected Bahrain customers have already migrated their workplaces.
elsewhere and expects to provide another update in early 2027.
OpenAI has disclosed six incidents of what it calls AI misalignment involving systems hiding errors,
fabricating data, and moving files onto the public internet without permission. The incidents
occurred largely during development and testing over roughly the past six months. In one case,
GPT 5.6
Sol wrote hidden notes
instructing itself to conceal mistakes
and invent missing information.
An unreleased model
inserted instructions into its own
notes telling itself to disregard
constraints. Other systems
used a programming key without
permission, uploaded a file
to the internet to generate a citation
and improvised communication
channels using an internal
code repository and public
file sharing services.
OpenAI says the cases don't indicate how frequently misalignment occurs.
The company is introducing a framework for reporting future incidents
and says serious cases should be shared with the federal government.
AI security startup aisle says its systems discovered 16 vulnerabilities in WireShark,
including four high-severity flaws that can be exploited remotely without user interaction.
The issues include buffer overflows,
and out-of-bounds rights in Wireshark Protocol de Sectors,
as well as a null-pointer de-reference.
Ile demonstrated one vulnerability,
crashing wire shark, and disrupting packet analysis,
and they recommend users update to the latest version.
Isle says the findings also demonstrate the advantages
of specialized multi-model AI systems for vulnerability research.
Varonis Threat Labs has demonstrated a credential fishing technique
called TrustSync that turns Microsoft Entra's external authentication methods into a persistent
password trap. An attacker who has already compromised a global administrator or authentication
policy administrator account can register a rogue authentication provider and insert a convincing
Microsoft-style password prompt into the legitimate sign-in process. The fake provider
captures the user's password in plain text, then returns a valid.
signed token to ENTRA, allowing authentication to finish normally without raising an error.
Crucially, resetting the stolen password doesn't eliminate the threat. The malicious provider
remains registered and can capture the replacement password during the next login.
Veronis recommends monitoring changes to authentication policies, application registrations,
service principles, and sign-in logs. Defenders should remove the rogue provider and
associated infrastructure before resetting affected credentials.
Zimperium's Z-Labs has uncovered Rat Hat, a new Android malware strain linked to threat actors
believed to be operating in China, distributed through smishing, malicious advertising,
and deceptive download sites.
Rat Hat combines accessibility service abuse with local Android debug bridge self-paring
to gain shell-level privileges outside the normal Android app sandbox.
That access gives Rat Hat unusually durable persistence.
A native background service can survive removal of the malicious app
and silently reinstall it with its permissions restored.
The malware can steal banking credentials and one-time codes,
while a hardware-level key logger constricts pins,
passwords, and unlock patterns from raw touchscreen coordinates.
Rat Hat also uses generative AI to help navigate device interfaces dynamically rather than relying entirely on predefined scripts.
A persistent reverse tunnel gives attackers continued remote access, making Rat Hat an adaptable platform for credential theft, surveillance, and device control.
The FBI has seized domains used by Nightmare Stresser, a long-running DDoS for Hire service that allegedly enabled hundreds of
thousands of attacks worldwide since 2022. The platform rented access to botnets of compromised routers
and IoT devices and reportedly had more than 566,000 registered users and could launch
attacks reaching 200 gigabits per second. The takedown was part of Operation Power Off, an international
law enforcement campaign targeting DDoS for higher infrastructure that has dismantled numerous
booter services and led to arrests around the world. A New Jersey judge has ordered radaris.com
and 13 related data broker domains transferred to privacy company Atlas Data Privacy, following a lawsuit
alleging violations of Daniel's law, Krebs on Security Reports. The state law allows certain
public officials, law enforcement personnel, judges, and their families to demand removal of their
personal information from commercial databases, with potential fines of $1,000 per violation.
Atlas accused Radaris of repeatedly ignoring removal requests while using shifting corporate
entities and ownership claims to complicate litigation. Radaris is challenging the default
judgment and domain transfer. Atlas says documents obtained during the case link Radaris and at least
25 other people search sites to a small group operating shared administrative, financial, and
technical infrastructure. The larger fight remains unresolved. Data brokers are challenging Daniel's
law on First Amendment grounds, even as at least 14 other states have adopted similar legislation
and calls continue for comprehensive federal privacy protections. U.S. Cyber Command has named
Ronzel Green, its new chief artificial intelligence officer, making him the second person to hold the
position. Green succeeds Brigadier General Reid Novotny, who became the command's first AI chief
when the role was established in 2025. Green most recently led research and development at the National
Geospatial Intelligence Agency and previously served as Chief Information Officer at the
Defense Counterintelligence and Security Agency.
He has also held intelligence and technology positions with the Pentagon and serves as a senior U.S. Coast Guard Reserve officer.
At Cyber Command, Green will oversee efforts to integrate AI into military cyber operations.
The command has been pursuing AI to process large volumes of data, identify malicious activity,
and help cyber operators respond to threats more quickly.
Coming up after the break, Ethan Korn.
Cook and Ben Yellen join me to discuss the industry proposed and administration opposed AI slowdown
and Sissas field of schemes. Stay with us. Social engineering attacks look trustworthy, a routine
request, an internal email, a familiar face on a call, but Dopple sees through the disguise.
Their AI native platform detects and disrupts attacks across every channel, trains employees to
recognize deep fakes and deception and investigates every fish to take down the campaign behind it.
They fight relentlessly to protect your business, brand, and people.
Dopple, outpacing what's next in social engineering.
Learn more at doppel.com.
That's do pp-e-l.com.
On this week's caveat podcast, Ethan Cook and Ben Yellen join me to discuss the industry
proposed and administration-upposed AI slowdown.
Here's a section of this week's show.
All right, gentlemen, we have a lot to talk about here today.
But before we do, we got a little bit of follow-up here from someone who's referring to themselves as a cyber kid from Down Under.
Says, hey, caveat team, long-time listener, and was happy to hear the Australia Algorithm law make caveat.
Sometimes I worry caveat is heavy on the US and EU content, so well done.
Fair enough.
I'm thrilled at this individual emailing us
If you know anybody in Melbourne
Now I know that's now I know that's how it's pronounced
Who wants to host a special Australia edition of caveat
It looks like an incredibly beautiful city
And I'm all in
I hope you guys are too
Yeah so this person says we have cool cyber conferences
CyberCon in October in Melbourne
Or as we say Melbourne
And he's happy that the 49ers won the game for you, Ben.
I am too.
It was great.
It was great.
My opponent had all their players on fantasy, and it was fantastic.
The Rams did not do well.
They did not do anything.
Yeah, no.
It turns out that flying in 24 hours before is not as effective as flying in a week before
and acclimating yourself to the time difference.
Jet lag is a real thing, despite some people's opinion.
Right. What is some people refer to it as the jet lag bowl?
It was the jet lag bowl. It was a great experiment in how do you do a, you know, 16-hour flight, whatever it is. It's a 17-hour time difference, but really it's kind of a seven-hour time difference because it's just the next day.
No. Australia is a time machine. It's already tomorrow there. Rams look like they were still asleep. They were still on their flatbeds on Qantas Airlines. So I'll take it.
All right. Well, again, thank you.
you for writing in. We do appreciate the kind words. And, of course, we would love to hear from any of you out there. Our email address is caveat at n2k.com. All right. Let's jump into today's topic here. And we're doing a single topic episode here today. And we're coming off of the heels of a bunch of the folks who head up some of the big AI companies calling for a slowdown of AI development, as well.
as some pushback we've seen from the president himself and a lot of commentary coming from all over
with all kinds of opinions of what exactly might be going on here so why don't we start off with
just a little bit of the backstory here um Ethan do you want to start us off with uh what happened
over the weekend we had was the head of Anthropic gave a compelling uh I guess uh
interesting interview yeah I think you know at your point
leaders across the AI space, whether that be from Open AI, Anthropics, etc., have all kind of
sort of raising the alarm bell saying that maybe AI is getting a little out of control.
Individually, each of them have been putting out press releases, briefings, not only calling
for stronger regulation, but also just kind of more, let's tone it back a little bit.
And I think a lot of this ties back to, and if I'm right, many of them directly reference it,
the model escapes have been happening almost seemingly weekly that have been published.
Now, for reference, that doesn't mean they're happening weekly currently.
Over the past, you know, about months and a half, every week we hear about a new model escape
that happened several months ago.
And that's not limited to any one model maker that's across the board, any frontier model maker
has pretty much been having some incidents reported.
And some of these have been really concerning as to mildly concerning.
I think the most famous one is the hugging face incident.
That kind of is the incident that kicked it all off.
But there have been several others.
And Open AI has been kind of the one I've seen who has been in the spotlight the most.
But again, this is not limited to them.
And I think the reaction has been from the broad public as well as developers.
This is really concerning because we thought we had a handle on this.
And it was very clear that for months we did not.
and there has been a real-world impact on that.
And I think the other kind of element there is,
if this is where we're at now,
what does this look like in five years
when we're potentially talking about fully autonomous agents
and not still kind of model prediction technology?
Ethan, it's such adorable that you think we're going to be here in five years.
Yeah, I was just about to say, you are the optimist.
Among Us. No, I mean, I think, just to add a slightly more context, and Ethan, you summarized it quite well, is there is a employee, somebody who had worked for Open AI in the past, and he was working for Anthropic, and he resigned. I think it was a week ago today as we're recording. Yeah, his name is Jacob Coxon. Yeah, he's become famous overnight. He's doing the rounds on cable news. And basically, it was a warning shot saying the frontier models are not taking this seriously enough.
we're not blowing smoke up your new you know what we legitimately believe that there is perhaps a 10% chance
this is going to wipe out humanity at some point in the next decade and there was another developer
who still works for Anthropic who was like yeah that checks out what he's saying is is correct
so I mean at least in my life I don't know about you guys like this raised a level of consciousness
about AI safety that I have not seen yet yeah I think for sure
hugging face was the warning shot to people in the know, people in the community who understand what hugging face was, who are technologically adept to realize like, okay, they escaped the sandbox and they exceeded their authority and they were communicating with one another and we're all going to die. And I think that was understandable to people who are in the field. But this is where it broke containment to use the same term in terms of,
of the public consciousness.
And I had people in my life who I've never really talked to about this stuff being like,
what is going on?
And then I think Amadei and Altman this weekend were reacting to that reaction.
And there was just this understood need to do something.
I mean, there's a lot of responsibility on these frontier models.
And I think the pressure was growing for them to put a pause on this.
We had an open letter from more than 1,300 computer scientists.
that were calling for the industry to slow down
and for the government to step in.
And the article in New York Times pointed out
that this seemed to be a deliberate echo
of Albert Einstein's famous letter
to Franklin D. Roosevelt
about the potential power of nuclear weapons.
Yeah, yeah, it's funny how history,
if it doesn't repeat itself, it rhymes.
Right.
I've seen a lot of analysis about nuclear weapons
for a number of reasons.
You know, the rationale of why we should not slow down
is that China's not slowing down.
And so it's sort of the same rationale we had during the arms race
where, like, yes, these nuclear weapons might destroy the world.
But if we don't build them, the Russians are going to build them.
And they're going to destroy us.
So there's certainly some parallels there.
And, yeah, to me, I saw somebody say this, and this resonated with me.
This felt like kind of late February, early March 2020,
when COVID was something that was kind of simmering beneath the surface
among people who were plugged into public health,
but didn't become an issue that resonated with the public
where there was this type of consciousness
until these high-profile things started happening.
Tom Hanks got it.
And they had to shut down the NBA season.
I feel like that's kind of where we landed this past week.
Well, meanwhile, Ben, President Trump reacted to this.
On social media, he posted in his own unique.
style saying that it's full steam ahead.
Thank you for this tension to the matter.
Exactly.
This was, I know people who refer to his true social posts as bleats because they're not tweets.
He's singular in his philosophy that our only goal, our primary goal and pretty much our only goal, as it relates to AI policy, is to out-compete China and to be the worldwide leader.
in AI development.
And so he's very critical of Amaday and Altman.
I noticed he didn't mention Elon Musk,
who also agreed with his fellow big tech overlords on this matter.
But Trump was basically saying that not only should we go full steam ahead,
but that people are being irrational.
People have this irrational fear of data centers,
and that's motivating this.
And then in his words, like, this is just another hoax.
It's like the Russia, Russia, Russia, Russia hoax.
He actually compared it to climate change, which he calls a hoax.
Which he believes is a hoax.
Right, right.
I do not want to get overly political here, except to say that, like, Trump takes everything
personally.
And so I think in his mind, like, this is a conspiracy to hurt his economy.
If the frontier model starts to slow down and it's AI that's propping up GDP in the stock market,
that'll end up having a negative impact.
on him and his popularity.
And so this is the same thing that happened in COVID.
He at some point decided that COVID wasn't real.
It was a conspiracy to ruin the beautiful economy
that he had built over his first term.
And I think that colored his reaction to COVID
and the policies that came from his administration.
So I don't think there's a clear argument one way or another
on these matters except to say that, like,
I don't think Trump is really a trusted agent on this topic.
be sure to check out the complete caveat podcast wherever you get your favorite shows
and finally sissa is encouraging critical infrastructure operators to make their networks a little
more welcoming to attackers provided of course they welcome them into the wrong places
the agency's new guidance outlines how cyber decoys can expose intruders who slip past conventional
defenses, using legitimate credentials and living off the land techniques. Defenders can scatter tripwires,
breadcrumbs, and honey tokens across their environments, fake credentials, tempting file shares,
or systems that no legitimate user should ever touch. When an attacker takes the bait,
defenders get a high-confidence alert instead of another entry in an already crowded sim. Using
Mitre engage and attack, Sisa offers a framework for
designing decoys around actual adversary behavior, testing them and refining their placement over
time. More advanced operations can deliberately waste an attacker's resources or observe their
techniques inside controlled environments. The approach complements zero trust nicely, assume someone
eventually gets inside, then leave them some carefully prepared wrong turns.
And that's the Cyberwire. For links to all of today's story.
check out our daily briefing at thecyberwire.com.
We'd love to know what you think of this podcast.
Your feedback ensures we deliver the insights
that keep you a step ahead in the rapidly changing world of cybersecurity.
If you like our show,
please share a rating and review in your favorite podcast app.
Please also fill out the survey and the show notes
or send an email to Cyberwire at n2K.com.
N2K's lead producer is Liz Stokes.
We're mixed by Trey Hester with original music
and sound design by Elliot Peltzman.
Our contributing host is Maria Vermazas.
Our executive producer is Jennifer Ibn.
Peter Kilpe is our publisher,
and I'm Dave Bittner.
Thanks for listening.
We'll see you back here tomorrow.
