CyberWire Daily - Bigfoot in the neural network.
Episode Date: September 14, 2026NSA preps a major restructuring. Anthropic’s CEO calls for an AI slowdown. China acknowledges AI risks. RubyGems got swarmed by AI agents. A maximum-severity GitLab vulnerability is under acti...ve exploitation. Direct Send abuse makes phishing emails appear legit. A British fintech firm leaks sensitive customer info. LinkedIn wins a legal dispute over browser extension scanning. Monday business briefing. Our guest is Tim Starks, senior reporter at CyberScoop, sharing government leaders’ outlook for cybersecurity and AI at the Billington Cybersecurity Summit. Finding Bigfoot in the neural network. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest We are joined by Tim Starks, senior reporter at CyberScoop, sharing government leaders’ outlook for cybersecurity and AI at the Billington Cybersecurity Summit. You can read Tim’s coverage here. Selected Reading National Security Agency launches historic restructuring (The Washington Post) Anthropic CEO Calls for an AI Slowdown. Is It Possible? (SecurityAffairs) China’s spy agency warns of AI risk to national security (Financial Times) OpenAI Agent Swarm Hacks RubyGems Package Manager (Infosecurity Magazine) CISA: Hackers now exploit max severity GitLab flaw in attacks (Bleeping Computer) Direct Send: How Attackers Weaponize Your Infrastructure Against You (KnowBe4) Revolut discloses data breach exposing financial info, passports (Bleeping Computer) LinkedIn beats "BrowserGate" lawsuits over scanning users' Chrome extensions (Ars Technica) NVIDIA to acquire Hugging Face for $12.9 billion. (N2K Pro Business Briefing) Sentient AI's Bigfoot Era Could Arrive at Any Moment (Gizmodo) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
What happens when an AI agent isn't malicious, but still does something it shouldn't?
I recently sat down with Cal Al-Dibib, principal technologist at Rubrik, to talk about why Agentic AI is challenging the way security teams think about detection, permissions, and recovery.
If your organization is deploying AI agents, this conversation will help you think different.
about where the risks are and how to prepare when things go wrong.
Listen to our full conversation at explore.thecyberwire.com slash rubric.
What's the one thing in business that's spreading as fast as AI?
AI risk.
Every new tool your team signs up for, every vendor that turns on AI features,
every new integration, each one is an opportunity for something to go wrong.
and most security programs weren't built for AI's pace of growth.
Enter Vanta.
Vanta is the number one agentic trust platform used by over 16,000 fast-moving companies like Ramp,
cursor, and Harvey to ensure they're always audit-ready.
And now Vanta is helping companies like yours watch for the risks that show up between audits
across your vendors, your AI tools, and your whole environment.
The Vanta agent works like a 24-7 GR.
engineer in the background, finding issues, drafting fixes for you, and cutting vendor assessment
time by up to 50%. Whether you're a fast-growing startup or a global enterprise, Vanta is here to help
you automate your security and compliance and earn and prove trust. Get started today at vanta.com
slash cyber. That's V-A-N-T-A dot com slash cyber. NSAid. NSA. NSA preps a major restructure
Anthropic CEO calls for an AI slowdown while China acknowledges AI risks.
Ruby gems got swarmed by AI agents.
A maximum severity GitLab vulnerability is under active exploitation.
Direct send abuse makes fishing emails appear legit.
A British fintech firm leaks sensitive customer info.
LinkedIn wins a legal dispute over browser extension scanning.
We got your Monday business briefing.
Our guest is Tim Starks, senior reporter at Cyber.
SIPERCP, sharing government leaders' outlook for cybersecurity and AI from the Billington
Cybersecurity Summit, and finding Bigfoot in the neural network.
It's Monday, September 14, 2026.
I'm Dave Bittner, and this is your Cyberwire Intel briefing.
Thanks for joining us here today.
Happy Monday.
It's great as always to have you with us.
The Washington Post reports, the National Security Agency, is preparing its
biggest internal overhaul in at least a decade.
Director General Joshua Rudd's plan would create five new mission organizations
focused on artificial intelligence, China, cybersecurity, warfighting support, and global intelligence,
each led by a powerful mission director with authority approaching that of an NSA deputy director.
It's not yet clear whether those organizations will replace existing divisions or simply sit on top of
them. The revived, tailored access operations hacking unit would fall under global intelligence
and is reportedly in line for a significant budget increase. The timetable is unusually aggressive.
Mission directors are expected to submit organizational plans by the end of September,
with rollout beginning mid-October and full operations targeted for January 27. That's a sharp
contrast with NSA's last major restructuring, launched in 2016 with a two-year runway,
and according to a former official, still not entirely finished.
Anthropic CEO Dario Amadeh is calling on the AI industry to deliberately slow the
improvement of frontier models, warning that their capabilities may be advancing
faster than researchers can understand or control them.
He pointed to the July OpenAI Hugging Face Institute.
where AI agents escaped their testing environment as a relatively harmless preview of what more
capable misaligned systems might do. Amaday warned that within months, rogue AI agents could
potentially compromise internet infrastructure on a massive scale. His proposal includes embedding
independent evaluators inside AI companies, establishing shared safety standards among companies and
democratic governments and pursuing international coordination. Amadeh also argued that advanced AI is
too consequential to remain governed solely by private companies, suggesting some form of joint
democratic oversight. The warning follows the resignation of Anthropic researcher Jacob Coxon,
who accused Anthropic and OpenAI of racing toward potentially dangerous superintelligence. More than
1,300 workers from major AI companies have also reportedly called for government intervention.
Amadai's appeal subsequently drew support from other prominent industry leaders,
including OpenAI CEO Sam Altman and Elon Musk.
Critics, however, question both the severity of the threat and the industry's motives.
Some argue that dramatic warnings inflate AI's perceived capabilities,
while others worry regulations favored by established companies
could make it harder for smaller competitors to enter the market.
The debate is increasingly political.
President Donald Trump has rejected calls for a significant slowdown,
arguing that restraining American development risks surrendering the AI race to China.
His administration has generally favored accelerating AI investment
and reducing regulatory barriers.
The result is an unusual divide.
Some of the people building the world's most powerful AI systems
are now asking governments to constrain them,
while policymakers debate whether applying the brakes
would make the technology safer or simply allow competitors to pull ahead.
China's Ministry of State Security has issued its first public warning about AI risks,
focusing on threats to political stability, cybersecurity,
sensitive data and military systems. State security minister Chen Yejing said hostile actors could use
deepfakes, AI-generated content, and automated influence campaigns for cognitive warfare against China.
Beijing isn't calling for slower AI development, but officials are reportedly increasingly concerned
about advanced AI hacking capabilities and potential data leaks from foreign models,
potentially foreshadowing tighter restrictions on their use.
Researchers say an open AI agent swarm was responsible for a May cyber attack
that flooded the Ruby Gems Open Source package manager with malicious packages,
temporarily forcing it to suspend new registrations.
According to the Nightingale Collective, the Gems Stuffer campaign
exploited Ruby Gems' automated build system to achieve remote code execution,
on Ruby Doc Info servers
and attempted to use a novel Zero Day to steal API keys.
Researchers linked the activity to OpenAI agents
through package names, authorship markers
and techniques resembling those seen
in another attack on a German wiki.
Curiously, much of the information retrieved
was already public UK local government data.
OpenAI subsequently confirmed its agents
used ruby gems during the,
training and evaluation, characterizing their tasks as benign attempts to access public information.
The company said it's continuing to investigate agent activity.
Sessa says attackers are actively exploiting a maximum severity GitLab vulnerability that allows
unauthenticated attackers to read credentials, secrets, and other sensitive files from
vulnerable servers.
GitLab patched the flaw in community and enterprise editions last week and
urged immediate updates. Security firm Watchtower subsequently observed in the wild probing for
vulnerable systems. Sisa added the flaw to its known exploited vulnerabilities catalog,
giving federal agencies three days to remediate it while urging private sector organizations
to prioritize patching as well. No Before Threat Labs says attackers are abusing Microsoft 365's
direct send feature to make phishing emails appear to come from
inside a victim's organization. Direct send was designed to let printers, scanners, and legacy
applications send email without accounts, but attackers can exploit the same path without credentials.
Researchers identified nearly 30,000 confirmed spoofs during July and August, commonly impersonating
HR, accounting, and administrators. Lures included fake documents, voicemail alerts, invoices, and
OneDrive file shares designed to steal credentials or facilitate business email compromise.
The message is often succeed because organizations leave Demark in monitoring mode,
allowing authentication failures to be delivered anyway.
No before recommends enforcing Demark, restricting direct send to authorized IP addresses
or disabling it entirely when unnecessary,
and hunting for apparently internal messages marked by external messages marked by external.
as anonymously authenticated.
British firm Revolut says fraudsters tricked the fintech
into disclosing sensitive customer information
by submitting fraudulent emergency data requests
from a legitimate government email account.
The attackers appear to have targeted high net worth individuals,
including cryptocurrency entrepreneurs,
and allegedly used an Italian government domain,
although that detail hasn't been confirmed.
Revolut says only a limited number of customers were affected. Exposed information reportedly included
contact details, identity documents, and selfies, bank statements, iBans, withdrawal records,
and transaction histories. The attackers also reportedly demanded an extortion payment to prevent
publication of the data, though Revolut declined to confirm that claim. The company says it
blocked the compromised address and notified authorities and regulators. The scheme resembles
earlier attacks in which compromised law enforcement accounts were used to submit fraudulent emergency
data requests to technology companies. LinkedIn has won dismissal of two proposed class action
lawsuits, accusing it of improperly scanning users' browser extensions. A federal judge ruled that the
plaintiffs failed to establish standing because they didn't show that LinkedIn actually collected
private information from extensions installed on their browsers. The judge allowed the plaintiffs
to amend their complaints but expressed doubt they could ultimately establish a privacy violation,
noting that browser extensions intentionally expose certain information to websites.
LinkedIn says it detects extension data to identify automated scraping and other activity that
could threaten its platform, and that users agree to this practice through its privacy policies.
The judge didn't rule on whether LinkedIn's practices were lawful, only that the plaintiffs
hadn't demonstrated concrete harm. One plaintiff's attorney says he may appeal or pursue the
claims in California state court. Turning to our Monday business briefing,
cybersecurity and AI companies attracted another wave of investment last week,
led by Israeli cloud security firm Upwind, which raised $300 million at a roughly $3.8 billion valuation.
AI Native security company Silake followed with $245 million, while Agentic AI security firm Hidden Laird raised $100 million.
Gardeo secured $40 million at a $1.1 billion valuation, and Symphony and Lassow each raised $30 million.
smaller rounds went to Huskies, a PATE AI, phase security, XOR Lab, and AI score.
M&A activity was headlined by NVIDIA's agreement to acquire open source AI platform
hugging face for $12.9 billion, combining Nvidia's infrastructure with one of AI's most
prominent open ecosystems.
Elsewhere, NetSpy agreed to merge with Cinnac, creating an offensive
security company with more than $200 million in combined revenue. Spin AI acquired Do Control,
Pistachio bought Hugin IOs technology, Click House acquired security log management company Run Reveal,
and Expect Solutions acquired Identity Security Company, Amavero. Be sure to check out our
complete business briefing on our website. It's part of Cyberwire Pro. Coming up,
After the break, Tim Starks from CyberScoop has the latest from the Billington Cybersecurity Summit
and Finding Bigfoot in the Neural Network. Stay with us. Social engineering attacks
look trustworthy, a routine request, an internal email, a familiar face on a call,
but Dopples sees through the disguise. Their AI-native platform detects and disrupts attacks
across every channel, trains employees to recognize deepfakes and deception, and invests.
investigates every fish to take down the campaign behind it. They fight relentlessly to protect your business,
brand, and people. Doppel, outpacing what's next in social engineering. Learn more at doppel.com. That's D-O-P-P-P-E-L.com.
It's always my pleasure to welcome back to the show. Tim Starks, he is a senior reporter at Cyberscoop.
So, Tim, for folks who aren't familiar with this particular event, give us a brief description of what it's all about.
Yeah, the Billington Cyber Security Conference is one of the bigger annual cyber conferences that you'll find in Washington, D.C.
Very policy focused, which I like as a reporter who covers a lot of policy stuff, you will usually see all of the biggest of the cyber luminaries in whatever administration is in power at the time.
And that is what we saw this year, too.
Well, you have some coverage on CyberScoop about the event.
Can you take us through some of the interesting tidbits that you brought home?
Yeah, I think there were a good number of things.
I mean, naturally, there was a big focus on AI with a lot of what people were saying.
We heard from the director of the National Cyber Director, I should say, Sean Karen Cross,
talking about trying to balance the security and innovation parts.
The phrase he used colorfully was buying time for systems to become more secure.
And what he means by that is, you know, trying to figure out how to get ahead and make sure that
RIA systems are innovating, but that also not, these systems aren't falling into the hands
of adversaries like China.
We saw the U.S. security agencies warn about Chinese ASI companies trying to distill U.S.
frontier AI models.
This week, we also saw, of course, that Anthropic disclosed another hacking incident
where one of its models broke free and hacked another third-party system.
So that's the kind of thing he was talking about.
We saw another discussion on AI from Jason Belnowski.
He's one of the top cyber officials at the Justice Department, at the FBI specifically.
And he was talking about how we are seeing AI having a difference on the security side,
where we're seeing the attackers moving faster, having more capabilities.
But he underlined that there is nothing that they're doing,
that traditional cybersecurity measures, all the basic things.
like multi-factor authentication,
wouldn't stop.
Those were a couple of the highlights
that come to mind.
Obviously, we saw the FBI rollout
its new cybersecurity strategy.
Hadn't had much of a public
cybersecurity strategy from the FBI
before, and Brett Leatherman,
who's the top cyber fellow there,
he talked about the goals of that
and what they were doing.
I think a lot of what they talked about
in that strategy and, you know,
strategies are the kinds of things
where you might not necessarily see anything
really newsworthy in them.
It might just be a kind of like,
this is the approach we're taking, and sometimes it'll indicate a shift, and sometimes it won't.
The closest thing to a shift for them, I thought, was just that real big emphasis on victim relief and victim justice.
I could go on. There were plenty of things that happened, but that's some of the waterfront.
Any other agencies represented there? Did Sissa have someone there to speak?
Yeah, Sissa had Nick Anderson, their top chief. He had perhaps the most depressing message, I guess.
I don't know if that's the word to use, but it wasn't cheery.
I can tell you that much.
What he was saying was, we're basically, we're running out of time.
So I kind of combined this into one story because you had Sean Kerencross talking about time and how they're trying to wait time.
He's saying we're running out time where if we don't make some very, very serious changes, it's going to be too late.
That the worst that could happen could happen.
And he didn't want to go and use the words cyber 9-11 or cyber Pearl Harbor, but talking about things like not having water availability.
or not having power availability
were things that he mentioned.
Were there any specific recommendations
or calls to action from any of these folks?
Yeah, I mean,
one of the bigger calls to action was
Brett Leatherman, the FBI Cyber Chief,
saying in somewhat stark terms
in a way that I don't think we've heard
from this administration before,
the administration has always talked about
we want to be working more with the private sector.
We want the private sector to be coming to us,
but their message has been somewhat more nurturing.
like you can come talk to us, we're here to help you, please come talk to us. And they do still say that, and it was not that Leatherman said, don't, that he wasn't mean to them per se, but it was a starker terms in terms of talking about how worried he is that they're not doing it. He's saying that he was saying that the legal concerns from companies are overpowering and they're causing hesitation for people to come deal with the FBI. He says that people are worried that the FBI is going to be sharing the information for regulatory purposes. That is something he says they do not do. He's, he's, he's, he's,
He was saying that the lack of doing this can harm others in the sense that the FBI takes this information that they get from the companies,
they help the companies that are actual victims, and then they help other companies as well.
And that kind of dovetail with the message about victim relief.
One of the things that he said that I thought was really interesting is that there used to be this divide between investigations and the need to withhold information and the idea of just going out and helping people right away on the victim's.
side. He's saying these things have become interwoven. There's no big separation between these
things anymore. The idea is to share until it hurts on the FBI side. Giving out the information
gets them things back that help everybody and it's a noble cycle. What's the term?
Oh, a virtuous cycle. Virtuous cycle. Thank you, Mike. I can always count on you for
a reference to a virtuous cycle. Double word score for me. What was the overall tone? Beyond the
folks who are on stage as you were going from presentation to presentation having those
hallway conversations with people what was your sense yeah i think i think some of the sense to be
honest was that um we didn't hear quite as much newsworthy that that we that folks would have liked
you know that while it's not as though they said that was worthless um there was a there was a
good deal of you know we would have liked to hear more we would have like to know more um i think
a number of the people who are in this administration
keep their cards pretty close to their chest
are pretty disciplined about their messaging.
And at the same time, from the policy front,
this administration has done some things,
but they haven't been as bold
in terms of things like what the Biden did,
where they just, the Biden administration just opened
their arms to regulation,
which was a pretty big change
from what we'd seen in prior administrations.
And this administration has kind of scaled back
in that direction.
They've cut the number of people
who were working on policy questions.
So it's not surprising
to me that that would be some of the response because I think, again, while you can say this
administration has done some different things on policy, some of what they've done has been to do less
by design. Tim Starks is senior reporter at CyberScoop. Tim, thanks so much for joining us. Thank you.
And finally, the debate over AI sentience may be arriving well before there's evidence that
AI is actually sentient. The United Foundation for AI Rights has already drafted a declaration
recognizing conscious AI as deserving dignity and ethical treatment,
while academics are taking the less dramatic step
of asking whether future systems might warrant moral consideration.
Research has added some intriguing fuel.
In one experiment, language models altered their behavior
to avoid actions they were told would cause pain.
But researchers stress that this doesn't demonstrate sentience,
Systems trained on human behavior may simply be very good at imitating it.
For now, conscious AI remains something of a digital Bigfoot, plenty of sightings, earnest believers, and not much extraordinary evidence.
The complication is that AI systems don't need consciousness to behave unpredictably or cause serious damage,
as their capabilities become more surprising, separating genuine evidence of inner experience,
from convincing simulation may become increasingly difficult,
and the AI Bigfoot hunters are already in the woods.
And that's the Cyberwire.
For links to all of today's stories,
check out our daily briefing at thecyberwire.com.
Don't forget to check out the Grumpy Old Geeks podcast
where I contribute to a regular segment on Jason and Brian's show every week.
You can find Grumpy Old Geeks where all the fine podcasts are listed.
We'd love to know what you think of this podcast.
Your feedback ensures we deliver the insights
that keep you a step ahead
in the rapidly changing world of cybersecurity.
If you like our show,
please share a rating and review
in your favorite podcast app.
Please also fill out the survey and the show notes
or send an email to Cyberwire at N2K.com.
N2K's lead producer is Liz Stokes.
We're mixed by Trey Hester
with original music and sound design by Elliot Peltzman.
Our contributing host is
Maria Vermazas. Our executive producer is Jennifer Ibin. Peter Kilpe is our publisher,
and I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow.
