CyberWire Daily - AI is calling the shots.

Episode Date: September 17, 2026

AI goes to war. Iranian strikes leave AWS data unrecoverable. OpenAI discloses more model misbehavior. Researchers uncover 16 Wireshark vulnerabilities. TrustSink turns Entra authentication into a pas...sword trap. RatHat raids Android credentials. The FBI takes down a DDoS-for-hire service. A data broker loses its domains. U.S. Cyber Command names a new AI chief. Ethan Cook is joining Dave Bittner and Ben Yelin to discuss the industry-proposed and administration-opposed AI slowdown. CISA’s field of schemes.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today, Ethan Cook, N2K’s lead analyst, joins Dave Bittner and Ben Yelin for a discussion about the industry-proposed and administration-opposed AI slowdown, exploring the policy debate and what it could mean for the future of AI. If you enjoyed this conversation, be sure to check out the full interview on Caveat here. Selected Reading The era of AI warfare has arrived (Financial Times) Iran strikes on Amazon data centers caused permanent loss of customer data (Ars Technica) OpenAI Discloses Six New Incidents of ‘Concerning' A.I. Behavior (The New York Times) AISLE Discovers 16 CVEs in Wireshark, the World’s Most Popular Network Protocol Analyzer (AISLE) TrustSink: How a Rogue External MFA Provider Steals Passwords (Varonis) RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts (Zimperium) US takes down NightmareStresser DDoS-for-hire platform (Bleeping Computer) Data Broker Radaris Loses Domains in Privacy Fight (Krebs on Security) Former NGA Executive Ronzelle Green Named USCYBERCOM Chief AI Officer (ExecutiveGov) CISA releases Cyber Decoys guide detailing tripwires, honeytokens to strengthen critical infrastructure detection and response (Industrial Cyber) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. So what happens when an AI agent isn't malicious, but still does something it shouldn't? I recently sat down with Cal Al-Dubabe, principal technologist at Rubrik, to talk about why agentic AI is challenging the way security teams think about detection, permissions, and recovery. If your organization is deploying AI agents, this conversation will help you think differently about where the risks are and how to prepare when things go wrong. Listen to our full conversation at explore. thecyberwire.com slash rubric. What's the one thing in business that's spreading as fast as AI? AI risk. Every new tool your team signs up for, every vendor that turns on AI features, every new integration, each one is an opportunity for something to go wrong. And most security
Starting point is 00:01:05 programs weren't built for AI's pace of growth. Enter Vanta. Vanta is the number one agentic trust platform used by over 16,000 fast-moving companies like Ramp, Hercer, and Harvey to ensure they're always audit-ready. And now Vanta is helping companies like yours watch for the risks that show up between audits across your vendors, your AI tools, and your whole environment. The Vanta agent works like a 24-7 GRC engineer in the background, finding issues, drafting fixes for you, and cutting vendor assessment time by up to 50%. Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today at Vanta.com slash cyber. That's V-A-N-T-A-com slash
Starting point is 00:02:00 cyber. AI goes to war. Iranian strikes leave AWS data unrecoverable. OpenAI discloses more model misbehavior. Researchers uncover 16 wire shark vulnerabilities. Trust sync turns intra-authentication
Starting point is 00:02:31 into a password trap. Rat Hat raids Android credentials. The FBI takes down a DDoS for hire service. A data broker loses its domains. U.S. Cyber Command names a new chief. Ethan Cook and Ben Yellen join me to discuss the industry proposed and administration opposed
Starting point is 00:02:50 AI slowdown and SISA's field of schemes. It's Thursday, September 17th, 2026. I'm Dave Bittner, and this is your Cyberwire Intel briefing. Thanks for joining us here today. It is great as always to have you with us. Reporting from the Financial Times says artificial intelligence is moving deeper into the machinery of war, and Ukraine has become one of its most important proving grounds. The Saker Scout offers a glimpse of where that could lead. The Ukrainian quadcopter uses machine learning to recognize 47 categories of military equipment. An operator can define the targets, confidence threshold, and geographic killbox, after which
Starting point is 00:04:02 the drone can potentially identify and attack a target without a number. other human command. But it can't distinguish Ukrainian forces from Russian ones, making careful deployment essential. Across the battlefield, AI is already accelerating warfare. Systems process enormous volumes of sensor and intelligence data help prioritize targets and compress the time between detection and attack. AI-assisted navigation can also keep drones on target after jamming breaks their connection with operators. Ukraine says its AI-guided drone strikes have increased tenfold since the beginning of 2006, though fully autonomous targeting, remains relatively uncommon.
Starting point is 00:04:48 The technology hasn't broken the battlefield stalemate. Faster targeting and greater autonomy don't necessarily translate into strategic victory, and AI introduces potentially serious problems of its own. Targeting systems can operate on increased. complete, outdated, or misleading information, while accelerating decisions so dramatically that humans have little time to challenge their recommendations. That creates an accountability problem alongside the technical one. International humanitarian law still places responsibility on humans, even as automated systems take over more steps in the kill chain.
Starting point is 00:05:29 Ukraine's stated ambition is ultimately full autonomy, including AI systems capable of helping commanders develop battle plans. As increasingly capable models emerge, the question may shift from whether militaries want AI making more battlefield decisions to whether governments can reliably control how far that autonomy goes. Amazon Web Services says some customers' data hosted in Bahrain and the United Arab Emirates has been permanently lost following Iranian strikes on its data centers earlier this year. AWS says it can't restore data from one availability zone in the UAE or from any of its three availability zones in Bahrain,
Starting point is 00:06:16 where damage exceeded what its regional and multi-zone services were designed to withstand. Iran first struck AWS facilities in Bahrain and the UAE on March 1st, with additional attacks targeting Bahrain in April and July. Amazon urged customers to migrate workloads to other regions and restore inaccessible records from remote backups while reportedly issuing $150 million in customer credits. AWS is still rebuilding infrastructure and attempting to recover resources in two UAE availability zones.
Starting point is 00:06:53 The company says most affected Bahrain customers have already migrated their workplaces. elsewhere and expects to provide another update in early 2027. OpenAI has disclosed six incidents of what it calls AI misalignment involving systems hiding errors, fabricating data, and moving files onto the public internet without permission. The incidents occurred largely during development and testing over roughly the past six months. In one case, GPT 5.6 Sol wrote hidden notes instructing itself to conceal mistakes
Starting point is 00:07:31 and invent missing information. An unreleased model inserted instructions into its own notes telling itself to disregard constraints. Other systems used a programming key without permission, uploaded a file to the internet to generate a citation
Starting point is 00:07:47 and improvised communication channels using an internal code repository and public file sharing services. OpenAI says the cases don't indicate how frequently misalignment occurs. The company is introducing a framework for reporting future incidents and says serious cases should be shared with the federal government. AI security startup aisle says its systems discovered 16 vulnerabilities in WireShark,
Starting point is 00:08:18 including four high-severity flaws that can be exploited remotely without user interaction. The issues include buffer overflows, and out-of-bounds rights in Wireshark Protocol de Sectors, as well as a null-pointer de-reference. Ile demonstrated one vulnerability, crashing wire shark, and disrupting packet analysis, and they recommend users update to the latest version. Isle says the findings also demonstrate the advantages
Starting point is 00:08:46 of specialized multi-model AI systems for vulnerability research. Varonis Threat Labs has demonstrated a credential fishing technique called TrustSync that turns Microsoft Entra's external authentication methods into a persistent password trap. An attacker who has already compromised a global administrator or authentication policy administrator account can register a rogue authentication provider and insert a convincing Microsoft-style password prompt into the legitimate sign-in process. The fake provider captures the user's password in plain text, then returns a valid. signed token to ENTRA, allowing authentication to finish normally without raising an error.
Starting point is 00:09:34 Crucially, resetting the stolen password doesn't eliminate the threat. The malicious provider remains registered and can capture the replacement password during the next login. Veronis recommends monitoring changes to authentication policies, application registrations, service principles, and sign-in logs. Defenders should remove the rogue provider and associated infrastructure before resetting affected credentials. Zimperium's Z-Labs has uncovered Rat Hat, a new Android malware strain linked to threat actors believed to be operating in China, distributed through smishing, malicious advertising, and deceptive download sites.
Starting point is 00:10:18 Rat Hat combines accessibility service abuse with local Android debug bridge self-paring to gain shell-level privileges outside the normal Android app sandbox. That access gives Rat Hat unusually durable persistence. A native background service can survive removal of the malicious app and silently reinstall it with its permissions restored. The malware can steal banking credentials and one-time codes, while a hardware-level key logger constricts pins, passwords, and unlock patterns from raw touchscreen coordinates.
Starting point is 00:10:54 Rat Hat also uses generative AI to help navigate device interfaces dynamically rather than relying entirely on predefined scripts. A persistent reverse tunnel gives attackers continued remote access, making Rat Hat an adaptable platform for credential theft, surveillance, and device control. The FBI has seized domains used by Nightmare Stresser, a long-running DDoS for Hire service that allegedly enabled hundreds of thousands of attacks worldwide since 2022. The platform rented access to botnets of compromised routers and IoT devices and reportedly had more than 566,000 registered users and could launch attacks reaching 200 gigabits per second. The takedown was part of Operation Power Off, an international law enforcement campaign targeting DDoS for higher infrastructure that has dismantled numerous booter services and led to arrests around the world. A New Jersey judge has ordered radaris.com
Starting point is 00:12:04 and 13 related data broker domains transferred to privacy company Atlas Data Privacy, following a lawsuit alleging violations of Daniel's law, Krebs on Security Reports. The state law allows certain public officials, law enforcement personnel, judges, and their families to demand removal of their personal information from commercial databases, with potential fines of $1,000 per violation. Atlas accused Radaris of repeatedly ignoring removal requests while using shifting corporate entities and ownership claims to complicate litigation. Radaris is challenging the default judgment and domain transfer. Atlas says documents obtained during the case link Radaris and at least 25 other people search sites to a small group operating shared administrative, financial, and
Starting point is 00:12:59 technical infrastructure. The larger fight remains unresolved. Data brokers are challenging Daniel's law on First Amendment grounds, even as at least 14 other states have adopted similar legislation and calls continue for comprehensive federal privacy protections. U.S. Cyber Command has named Ronzel Green, its new chief artificial intelligence officer, making him the second person to hold the position. Green succeeds Brigadier General Reid Novotny, who became the command's first AI chief when the role was established in 2025. Green most recently led research and development at the National Geospatial Intelligence Agency and previously served as Chief Information Officer at the Defense Counterintelligence and Security Agency.
Starting point is 00:13:52 He has also held intelligence and technology positions with the Pentagon and serves as a senior U.S. Coast Guard Reserve officer. At Cyber Command, Green will oversee efforts to integrate AI into military cyber operations. The command has been pursuing AI to process large volumes of data, identify malicious activity, and help cyber operators respond to threats more quickly. Coming up after the break, Ethan Korn. Cook and Ben Yellen join me to discuss the industry proposed and administration opposed AI slowdown and Sissas field of schemes. Stay with us. Social engineering attacks look trustworthy, a routine request, an internal email, a familiar face on a call, but Dopple sees through the disguise.
Starting point is 00:15:02 Their AI native platform detects and disrupts attacks across every channel, trains employees to recognize deep fakes and deception and investigates every fish to take down the campaign behind it. They fight relentlessly to protect your business, brand, and people. Dopple, outpacing what's next in social engineering. Learn more at doppel.com. That's do pp-e-l.com. On this week's caveat podcast, Ethan Cook and Ben Yellen join me to discuss the industry proposed and administration-upposed AI slowdown.
Starting point is 00:15:52 Here's a section of this week's show. All right, gentlemen, we have a lot to talk about here today. But before we do, we got a little bit of follow-up here from someone who's referring to themselves as a cyber kid from Down Under. Says, hey, caveat team, long-time listener, and was happy to hear the Australia Algorithm law make caveat. Sometimes I worry caveat is heavy on the US and EU content, so well done. Fair enough. I'm thrilled at this individual emailing us If you know anybody in Melbourne
Starting point is 00:16:27 Now I know that's now I know that's how it's pronounced Who wants to host a special Australia edition of caveat It looks like an incredibly beautiful city And I'm all in I hope you guys are too Yeah so this person says we have cool cyber conferences CyberCon in October in Melbourne Or as we say Melbourne
Starting point is 00:16:48 And he's happy that the 49ers won the game for you, Ben. I am too. It was great. It was great. My opponent had all their players on fantasy, and it was fantastic. The Rams did not do well. They did not do anything. Yeah, no.
Starting point is 00:17:06 It turns out that flying in 24 hours before is not as effective as flying in a week before and acclimating yourself to the time difference. Jet lag is a real thing, despite some people's opinion. Right. What is some people refer to it as the jet lag bowl? It was the jet lag bowl. It was a great experiment in how do you do a, you know, 16-hour flight, whatever it is. It's a 17-hour time difference, but really it's kind of a seven-hour time difference because it's just the next day. No. Australia is a time machine. It's already tomorrow there. Rams look like they were still asleep. They were still on their flatbeds on Qantas Airlines. So I'll take it. All right. Well, again, thank you. you for writing in. We do appreciate the kind words. And, of course, we would love to hear from any of you out there. Our email address is caveat at n2k.com. All right. Let's jump into today's topic here. And we're doing a single topic episode here today. And we're coming off of the heels of a bunch of the folks who head up some of the big AI companies calling for a slowdown of AI development, as well.
Starting point is 00:18:18 as some pushback we've seen from the president himself and a lot of commentary coming from all over with all kinds of opinions of what exactly might be going on here so why don't we start off with just a little bit of the backstory here um Ethan do you want to start us off with uh what happened over the weekend we had was the head of Anthropic gave a compelling uh I guess uh interesting interview yeah I think you know at your point leaders across the AI space, whether that be from Open AI, Anthropics, etc., have all kind of sort of raising the alarm bell saying that maybe AI is getting a little out of control. Individually, each of them have been putting out press releases, briefings, not only calling
Starting point is 00:19:05 for stronger regulation, but also just kind of more, let's tone it back a little bit. And I think a lot of this ties back to, and if I'm right, many of them directly reference it, the model escapes have been happening almost seemingly weekly that have been published. Now, for reference, that doesn't mean they're happening weekly currently. Over the past, you know, about months and a half, every week we hear about a new model escape that happened several months ago. And that's not limited to any one model maker that's across the board, any frontier model maker has pretty much been having some incidents reported.
Starting point is 00:19:39 And some of these have been really concerning as to mildly concerning. I think the most famous one is the hugging face incident. That kind of is the incident that kicked it all off. But there have been several others. And Open AI has been kind of the one I've seen who has been in the spotlight the most. But again, this is not limited to them. And I think the reaction has been from the broad public as well as developers. This is really concerning because we thought we had a handle on this.
Starting point is 00:20:11 And it was very clear that for months we did not. and there has been a real-world impact on that. And I think the other kind of element there is, if this is where we're at now, what does this look like in five years when we're potentially talking about fully autonomous agents and not still kind of model prediction technology? Ethan, it's such adorable that you think we're going to be here in five years.
Starting point is 00:20:37 Yeah, I was just about to say, you are the optimist. Among Us. No, I mean, I think, just to add a slightly more context, and Ethan, you summarized it quite well, is there is a employee, somebody who had worked for Open AI in the past, and he was working for Anthropic, and he resigned. I think it was a week ago today as we're recording. Yeah, his name is Jacob Coxon. Yeah, he's become famous overnight. He's doing the rounds on cable news. And basically, it was a warning shot saying the frontier models are not taking this seriously enough. we're not blowing smoke up your new you know what we legitimately believe that there is perhaps a 10% chance this is going to wipe out humanity at some point in the next decade and there was another developer who still works for Anthropic who was like yeah that checks out what he's saying is is correct so I mean at least in my life I don't know about you guys like this raised a level of consciousness about AI safety that I have not seen yet yeah I think for sure hugging face was the warning shot to people in the know, people in the community who understand what hugging face was, who are technologically adept to realize like, okay, they escaped the sandbox and they exceeded their authority and they were communicating with one another and we're all going to die. And I think that was understandable to people who are in the field. But this is where it broke containment to use the same term in terms of,
Starting point is 00:22:11 of the public consciousness. And I had people in my life who I've never really talked to about this stuff being like, what is going on? And then I think Amadei and Altman this weekend were reacting to that reaction. And there was just this understood need to do something. I mean, there's a lot of responsibility on these frontier models. And I think the pressure was growing for them to put a pause on this. We had an open letter from more than 1,300 computer scientists.
Starting point is 00:22:41 that were calling for the industry to slow down and for the government to step in. And the article in New York Times pointed out that this seemed to be a deliberate echo of Albert Einstein's famous letter to Franklin D. Roosevelt about the potential power of nuclear weapons. Yeah, yeah, it's funny how history,
Starting point is 00:23:02 if it doesn't repeat itself, it rhymes. Right. I've seen a lot of analysis about nuclear weapons for a number of reasons. You know, the rationale of why we should not slow down is that China's not slowing down. And so it's sort of the same rationale we had during the arms race where, like, yes, these nuclear weapons might destroy the world.
Starting point is 00:23:19 But if we don't build them, the Russians are going to build them. And they're going to destroy us. So there's certainly some parallels there. And, yeah, to me, I saw somebody say this, and this resonated with me. This felt like kind of late February, early March 2020, when COVID was something that was kind of simmering beneath the surface among people who were plugged into public health, but didn't become an issue that resonated with the public
Starting point is 00:23:46 where there was this type of consciousness until these high-profile things started happening. Tom Hanks got it. And they had to shut down the NBA season. I feel like that's kind of where we landed this past week. Well, meanwhile, Ben, President Trump reacted to this. On social media, he posted in his own unique. style saying that it's full steam ahead.
Starting point is 00:24:14 Thank you for this tension to the matter. Exactly. This was, I know people who refer to his true social posts as bleats because they're not tweets. He's singular in his philosophy that our only goal, our primary goal and pretty much our only goal, as it relates to AI policy, is to out-compete China and to be the worldwide leader. in AI development. And so he's very critical of Amaday and Altman. I noticed he didn't mention Elon Musk, who also agreed with his fellow big tech overlords on this matter.
Starting point is 00:24:56 But Trump was basically saying that not only should we go full steam ahead, but that people are being irrational. People have this irrational fear of data centers, and that's motivating this. And then in his words, like, this is just another hoax. It's like the Russia, Russia, Russia, Russia hoax. He actually compared it to climate change, which he calls a hoax. Which he believes is a hoax.
Starting point is 00:25:17 Right, right. I do not want to get overly political here, except to say that, like, Trump takes everything personally. And so I think in his mind, like, this is a conspiracy to hurt his economy. If the frontier model starts to slow down and it's AI that's propping up GDP in the stock market, that'll end up having a negative impact. on him and his popularity. And so this is the same thing that happened in COVID.
Starting point is 00:25:45 He at some point decided that COVID wasn't real. It was a conspiracy to ruin the beautiful economy that he had built over his first term. And I think that colored his reaction to COVID and the policies that came from his administration. So I don't think there's a clear argument one way or another on these matters except to say that, like, I don't think Trump is really a trusted agent on this topic.
Starting point is 00:26:10 be sure to check out the complete caveat podcast wherever you get your favorite shows and finally sissa is encouraging critical infrastructure operators to make their networks a little more welcoming to attackers provided of course they welcome them into the wrong places the agency's new guidance outlines how cyber decoys can expose intruders who slip past conventional defenses, using legitimate credentials and living off the land techniques. Defenders can scatter tripwires, breadcrumbs, and honey tokens across their environments, fake credentials, tempting file shares, or systems that no legitimate user should ever touch. When an attacker takes the bait, defenders get a high-confidence alert instead of another entry in an already crowded sim. Using
Starting point is 00:27:20 Mitre engage and attack, Sisa offers a framework for designing decoys around actual adversary behavior, testing them and refining their placement over time. More advanced operations can deliberately waste an attacker's resources or observe their techniques inside controlled environments. The approach complements zero trust nicely, assume someone eventually gets inside, then leave them some carefully prepared wrong turns. And that's the Cyberwire. For links to all of today's story. check out our daily briefing at thecyberwire.com. We'd love to know what you think of this podcast.
Starting point is 00:28:12 Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey and the show notes or send an email to Cyberwire at n2K.com. N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music
Starting point is 00:28:36 and sound design by Elliot Peltzman. Our contributing host is Maria Vermazas. Our executive producer is Jennifer Ibn. Peter Kilpe is our publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.