CyberWire Daily - Clear your calendar, it’s Patch Tuesday.
Episode Date: September 9, 2026Patch Tuesday is a doozy. The Feds warn China-based AI companies are distilling U.S. AI models. A new ClickFix campaign goes straight for the browser. Smart TVs get nosy. Hackers gift themselves a $47... million bug bounty. An Ohio man gets 15 years in federal prison for cyberstalking and sextortion. Andy Hornegold, Chief Security Technologist from Intruder, discusses what makes up a reliable AI pentests and the benefits and risks that come with AI-enabled security. Putting AI at the head of the class. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Andy Hornegold, Chief Security Technologist from Intruder, discussing what makes up a reliable AI pentests and the benefits and risks that come with AI-enabled security. Selected Reading Microsoft Patch Tuesday Fixes 966 Vulnerabilities, Including 2 Exploited 0-Days (Hackread) Ivanti Patches Critical Flaws Across Enterprise Security Products (SecurityWeek) Chrome 153 Patches Seventh Zero-Day of 2026 (SecurityWeek) Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day (SecurityWeek) ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws (SecurityWeek) CISA, NSA and FBI Warn Chinese AI Firms Are Targeting U.S. AI Models at Industrial Scale (HSToday) Europe's push for space sovereignty. (N2K Networks) History for European spaceflight: Isar Aerospace reaches orbit and deploys payloads on second flight (Isar Aerospace) ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 (Talos Intelligence) LG TVs caught spying even when offline or on standby (The Verge) 'White hat' hackers take $47 million bounty after $320 million crypto theft (The Record) Man gets 15 years for extorting women with AI-generated porn videos (Bleeping Computer) Alpha School’s AI teaching model is expanding. Does it work? (Scientific American) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
Yes, you can have an enterprise network that's secure and reliable and high performance.
And no, you don't need to choose the best two out of three.
With Meter, you can get the end-to-end network built from the ground up, fast to deploy, and easy to manage.
That's because Meter is software-led for easy installation, maintenance, and control for everything running on your enterprise network.
Hardware, firmware, and software all working together from the start seamlessly on a unified platform that's secure by design.
You can't protect what you don't know exists, which is why meter gives you comprehensive visibility into wired and wireless routing, switching, firewalls, DNS security, and VPNs.
You'll really know what's running on your network down to the most granular client level.
Step off the hardware box upgrade treadmill and switch to,
to meter for a predictable fee and free up your team to spend time on all the other things that
keep your business running. Try it out for yourself and book a demo online at meter.com
slash cyberwire. That's METER.com slash cyberwire. Patch Tuesday is a doozy. The feds-worn China-based
AI companies are distilling USAI models. A new click-fix campaign goes straight for the browser.
Smart TVs get nosy.
Packers gift themselves a $47 million bug bounty.
An Ohio man gets 15 years in federal prison for cyberstalking and sex distortion.
Our guest is Andy Horngold, Chief Security Technologist from Intruder, discussing what makes up a reliable AI pen test.
And putting AI at the head of the class.
It's Wednesday, September 9th, 2026.
I'm Dave Bittner, and this is your.
Cyberwire Intel Briefing.
Thanks for joining us here today.
It's great to have you with us.
Microsoft's September Patch Tuesday is its largest on record,
with the company reporting fixes for 966 vulnerabilities.
Independent tallies very slightly, but all point to an unusually heavy month.
105 vulnerabilities are rated critical.
258 involve remote code execution,
and 438 involve privilege escalation.
Two Windows Zero Days were already being exploited.
One affects the Windows Update stack and can allow a local attacker to gain system privileges.
Another, a buffer overflow in Windows ALPC, can let an attacker escape a low-pledge
app container and reach system.
Neither provides an initial remote foothold.
Both are useful for escalating privileges after a system.
has already been compromised.
Microsoft also patched critical vulnerabilities across core networking services,
including DNS, DHCP, NetLogon, Messaging Q, and NFS.
CrowdStrike identified at least 17 remote code execution flaws reachable over the network without authentication.
Office received 22 critical fixes, including vulnerabilities that could potentially execute code
when a malicious file is merely previewed.
Hyper V flaws could enable attacks from a compromised guest virtual machine against its host.
The broader September patch cycle is similarly busy.
Adobe fixed more than 170 vulnerabilities,
including an actively exploited, unauthenticated Commerce and Magento RCE Zero Day.
Google patched 230 Chrome vulnerabilities,
including the browser's seventh exploited zero day of 2026.
Evante addressed six critical RCE vulnerabilities in neurons for ITSM,
while Schneider Electric, Siemens, Aviva, and Rockwell Automation
issued updates covering industrial systems.
SISA, the NSA, and FBI are warning that China-based AI companies
have been systematically extracting capabilities from leading U.S.
AI models through large-scale knowledge distillation campaigns.
The agencies say DeepSeek, Moonshot AI, Alibaba, Minimax, Stepfund, and ZAI have extracted billions
of tokens through millions of requests involving models including Claude, GPT, Gemini,
and Grok since at least late 2024.
Knowledge distillation is a legitimate technique for training smaller models using outputs for
more capable ones, but the advisory says these campaigns violate U.S. providers' terms of service
and accelerate Chinese AI development. The agencies assess the activity is occurring likely with
Chinese government awareness. The advisory urges U.S. AI companies to improve detection of suspicious
accounts and usage patterns, alter responses to suspected distillation attempts to reduce their value,
and share intelligence across model providers, cloud platforms, and API aggregators.
Maria Vermazis is host of the T-minus Space Cyber Podcast.
She joins us each Wednesday with the latest news from space.
Today, it's about European sovereignty.
Thank you, Dave.
This past Saturday on September 5th, I saw Aerospace of Germany made history with the first
launched to orbit from the European continent. Isar's spectrum rocket launched from Andoia spaceport in
Norway and successfully deployed six satellites to low Earth orbit. Now, Isar is a commercial space
company with a large backing from the European Space Agency, and their successful launch from Norway
means Europe will now have launch options much closer to home beyond the Issa spaceport in Kuru,
French Guiana. With the proven ability to launch to orbit from European soil with homegrown European
rocketry, the push now is to scale up and increase launch cadence to meet growing demand from European
customers. Along those lines, Isar says four additional spectrum rockets are already in production
and that the company plans to manufacture up to 40 spectrum launch vehicles a year when their new
production facility is complete. In all, Isar's successful orbital,
launch is a major step forward for European space sovereignty, especially as Europe continues to build
out its high priority, secure satellite communications constellation, the iris squared.
For the CyberWire Daily, I'm Maria Vermazes from T-minus Space Cyber Briefing. Back to you, Dave.
Be sure to check out the T-minus Space Cyber podcast wherever you get your favorite shows.
Cisco Talos is tracking a cryptocurrency theft campaign that puts a twist on ClickFix social engineering.
Instead of persuading victims to execute commands on their computers, attackers convince them to inject malicious JavaScript directly into their browsers.
The lure is a fake vulnerability report promising bigger payouts from cryptocurrency exchanges.
Victims are instructed either to paste JavaScript into Chrome or, you know,
install it through the legitimate tamper monkey extension, which gives the malware persistence.
The attackers have promoted the supposed exploit through telegram, dark web forums, and
paste sites.
The injected code uses Google's visualization API to retrieve obfuscated JavaScript stored
in publicly accessible Google Sheets, making command and control traffic look like legitimate
browser activity.
Once running, the script acts as a web skill.
Gimmer, replacing cryptocurrency deposit addresses in website responses and the clipboard with
attacker-controlled wallets while displaying fake bonus information.
TALOS identified 49 Bitcoin addresses associated with the campaign and traced roughly $10,000
to known victim payments, though the actual hall may be higher.
An investigation by Gamer's Nexus, Level 1 techs, and independent security resources,
researchers found LG smart TVs extensively collecting information about owners and their homes.
Tests found the TV's scanning local networks for nearby devices, gathering location and
Wi-Fi data, and sending information to LG ad solutions.
Researchers also found the TVs could record microphone audio while in standby,
storing recordings offline until Internet access returned.
LG's automatic content recognition technology, additionally samples audio and video to identify content viewed through smart TV apps and connected devices, including HDI inputs.
A $320 million cryptocurrency theft from Liquid Network ended with the attackers returning most of the money and keeping about $47 million as a self-appointed bug bounty.
Liquid said purported white-hat hackers withdrew 4,000 Bitcoin from one of its wallets Sunday,
prompting operator Blockstream to pause deposits and withdrawals.
The attackers then opened negotiations through messages embedded in blockchain transactions,
claiming they were white hats and demanding that Blockstream patch an alleged vulnerability
before they returned the funds.
After roughly 12 hours of public and private exchanges,
The hackers returned about 266.5 million on Monday and retained 598.5 Bitcoin as their reward.
Blockstream said updated software had been deployed as it prepared to restart the system.
The vulnerability's source remains debated, although side-swap and several blockchain security experts have pointed to a flaw in elements,
the software underlying Blockstream's liquid side chain.
An Ohio man has been sentenced to 15 years in federal prison for a cyber-stalking and sex-stortion campaign
that used artificial intelligence to create sexually explicit material depicting his victims.
Prosecutors say 37-year-old James Stroller II used more than 100 AI models
across more than two dozen platforms to generate explicit images and videos.
Between December 2024 and June 2025, he harassed at least six adult women,
sending both authentic and AI-generated nude images,
threatening victims with sexual violence,
and sharing fabricated explicit material with their coworkers.
He also threatened victims' mothers in an effort to obtain nude photographs.
Investigators found more than 700 images Straller had posted to a child's sexual
abuse website, along with thousands of potentially abusive or violent files on his phone.
Straller pleaded guilty in April and became the first person convicted under the 2025
Take It Down Act, which prohibits publishing intimate images and AI-generated explicit forgeries
without consent.
Coming up after the break, my conversation with Andy Horngold from Intruder.
we're discussing what makes up a reliable AI pen test and putting AI at the head of the class.
Stick around.
What's the one thing in business that's spreading as fast as AI?
AI risk.
Every new tool your team signs up for, every vendor that turns on AI features, every new integration,
each one is an opportunity for something to go wrong.
And most security programs weren't built for AI's pace of growth.
Enter Vanta. Vanta is the number one agentic trust platform used by over 16,000 fast-moving companies like Ramp, Hursor, and Harvey to ensure they're always audit-ready.
And now Vanta is helping companies like yours watch for the risks that show up between audits across your vendors, your AI tools, and your whole environment.
The Vanta agent works like a 24-7 GRC engineer in the background, finding issues, drafting fixes for you,
and cutting vendor assessment time by up to 50%.
Whether you're a fast-growing startup or a global enterprise,
Vanta is here to help you automate your security and compliance
and earn and prove trust.
Get started today at vanta.com slash cyber.
That's V-A-N-T-A dot com slash cyber.
Andy Horngold is chief security technologist from Intruder.
We recently sat down to discuss what
makes up a reliable AI pen test.
Pen testing's come on leaps and bounds probably in the last, I'd say, 24 months.
I think everybody's come on leaps and bounds in the last eight, 12 months, right?
The whole world seems to have shifted.
But I think professional services and human-led pen testing has probably been under more
pressure as of late from product-led approaches to delivering security validation and security
assurance. Obviously, pen testing, human-led pen testing has pretty much been point in time for a
very long time. And anybody who is a pen tester who works in security will tell you that
continuous is definitely the way to go. But historically, it's been difficult to try and turn
a human-led approach into a continuous offering, just because human time is expensive. You're
capped by people being on a holiday and their availability. But with the advent of AI, being able to reason
across applications, being able to hold entire code bases and infrastructure configurations
and cloud configurations in its context window in one go, being able to reason across it.
There certainly shifted things. And finally, I think after probably a couple of decades
of people saying that continuous is definitely the right approach, it feels like it's finally
within grasp of having true security validation on continuously.
So the people who are tasked with pen testing, what are some of the specific things they need to be mindful of these days in this new environment?
I think in the new environment you're able to do things significantly quicker than you were previously.
Like I remember doing pen tests back in the day where you were asked to do source code reviews or at least code-assisted pen tests.
And you'd have to use one of the SAST scanners, the static code analysis tools that was out there and was available.
was always a headache. I don't think anybody, like, when I ran a pen testing team over a
context, nobody enjoyed doing that security, like code review side of things. I think there's
very few people in the world who do enjoy reading other people's code. But, you know, that's part
of what we need to do when it comes to informed pen testing. But now with the, you know, with AI that's
available, pen testers are able to do that more quickly. So they're able to, they're able to reason across
code. They're able to interrogate it. They're able to find answers to questions within a code
base that historically would have taken them time to query across. I think the professional
services industry is having a bit of a shake-up at the moment, and I put pen testing under
professional services. So I think there is some difficulty. The reason is just because AI pen testing,
I think, is going to take up some of that market space. That's not to say I think AI pen-testing is
going to hoover up every part of pen testing. I think there's still expertise-led, experience-led
components of pen testing that's really important, right? Like when you're dealing with safety
systems, ICS, OT, weird and wonderful networks, I think that's still going to be human-led pen testing.
But right now, I think we're going to start to see that human come out of that loop for the
day-to-day, probably more mundane business-as-usual style pen-testing. And I think that's definitely
going to impact the way people are operating within the professional services space.
I know you've advocated for the importance of benchmarks provided by an independent party here.
Can you explain that to us? Why is that important for AI pen testing?
Sure thing. I think coming from pen testing and red teaming myself, if you're a consumer,
if you're somebody who's going out to buy a pen test, you want to make sure that you have some level of assurance
of the quality of that pen test, of that red team, whatever it may be.
You need to know that I'm going to have somebody on my side
who is able to do what I need them to, right?
They're not just going to be some, for lack of a better phrase,
cowboy who's going to come on and potentially not do what they've told me
they can do or they should be doing.
And we've done that historically, right, using benchmarks and using qualifications.
So you'll often hear people say I have OSWE, like off-sec qualifications,
and as a consumer you can say, okay, the pen testing firm that I'm buying from has a certain level of certification.
That's not necessarily going to say that the individual pen tester that is assigned to your gig
is necessarily going to have all of those qualifications, but you know you're getting it from a legitimate firm.
Now, when it comes to the AI side of things, we don't really have any of that kind of,
understanding of what is the level of quality that each of these models with their harnesses,
these AI pen testers, are actually capable of delivering? Are they able to deliver at kind of a
certified level, at a high level, like a highly experienced pen tester would be able to deliver?
Or are they just going to be able to do the basic checks that we expect of, you know, junior pen testers,
graduates who are just coming out of university? And that's really important. It's really important to be
able to say with confidence that the pen test I've just received has some level of quality to it.
So that's why I think over the last few months we've been investigating, like, what does
certification look like for this new wave of AI pen testers? What does it take for somebody
to accept that the AI pen test that they've just had run for them is of quality?
No, don't get me wrong, the findings that we're seeing within AI pen testing are
eye-wateringly good. They are finding things that experienced pen testers haven't been able to find
for kind of the last five, six years. They're chaining together really complicated attack paths
and building this understanding of risk through applications and infrastructure that have kind of
laid dormant for years. So that kind of gives you some confidence that the quality is there,
but how do we benchmark it? And we're seeing kind of a combination
of things happen to give people that kind of trust.
We're seeing benchmarks from private organizations saying,
hey, this model performs slightly better at this benchmark than this other model does.
We're seeing private companies kind of compare themselves against each other,
but all of those are led predominantly by the marketing approach, right?
You're going to see some favoritism in there.
Now, in the UK and actually US, Australia as well,
One of the certification approaches we've had historically has been called Crest,
the Council for Registered Ethical Security Testers,
and they've put pencesters through exams, through assault courses,
to be able to say whether they reach a certain bar.
My opinion is that I think we need something independent, third party,
that can deliver the same kind of certification and benchmarking
for AI pen testers at large.
There's an increasing number of AI pen testing firms springing up.
So how do we have a third-party independent organization
that's able to give us that certification
rather than just hearing the noise that comes with a huge,
multi, hundreds of thousands of dollars marketing campaign?
In your opinion, what are the types of things
that organizations should be asking
of the folks that they're engaging with to do their pen testing.
I mean, if we're talking specifically around the kind of the AI pen testing approach,
I think there's a bunch of different questions you can ask.
One of which is kind of like, what is the history,
what is the heritage, if you will, of the organization that is providing this pen test?
Like, is it run by people who have security experience who have been in the trenches,
who have delivered pen tests in the past, who have run red teams?
Have they got a security team who have experience and expertise?
So they already qualified.
And now they're applying those qualifications and that knowledge to building this new technology.
I think that's super important.
As you start to see smaller businesses spring up out of nowhere and start to say they're delivering AI pen testing,
being able to make sure that there is a culture of quality that has come from years of security testing, in my opinion, is super important.
I don't know, Dave, if you've been involved on the pen testing procurement side of things and like the kinds of questions you've asked people in the past,
but have you thought about kind of the, I suppose, the heritage and the culture of the company that you're acquiring a pen test from?
I have never had the privilege, no, Andy.
That might be a good thing.
I can't say I stay up at night wishing that I was involved with that.
But I'm glad there are people out there who know the right questions to ask, such as yourself.
Thank you.
Yeah, I think that's one of the big questions I would ask.
There's obviously all of the technical questions.
We're starting to see as well, right?
We're starting to see people ask, you know, what are the models that you're using under the hood?
Like, what's the methodology that you're following?
And how can you guarantee the agents of following that methodology?
These are all kind of fun questions to answer,
and they're difficult to answer for pen testing,
AI pen testing firms in particular because AI agents and models are nondeterministic.
So when you try and steer these agents to follow a strict methodology,
they tend to get tunnel vision and they will only follow that methodology.
And as a result, within like open benchmarks or in your testing Eval suite,
you start to see the quality of that pen test deteriorate.
It finds less vulnerabilities.
than if you just let the agent reason over the entire code base
and follow its own nose.
It's kind of funny because it follows what a human pen tester would do as well, right?
Like, we've had methodologies for a long time.
We've had methodologies because we want to make sure
that the human pen tester is doing everything that they should be doing during
engagement.
But a good pen tester, a good red teamer, initially will follow their nose.
They'll understand the application.
They'll understand the environment that they're operating in,
work out how it's all bolted together and what the workflows and user journeys are.
And then they'll start to find vulnerabilities naturally.
And then towards the end of that assessment, that's when they'll refer to the methodology
and they'll start to say, okay, you know, I followed my nose.
I found some cool vulnerabilities and cool risk within this app, within this environment.
But now I just need to make sure I'm dotting the eyes and crossing the T's,
and I'll do that by referring back to the methodology.
An agent does the same thing, right?
It goes through that code base.
It reasons through it.
And it will find interesting vans.
But at the end of the day, you don't need to rely just on that agent to deliver that methodology
or deliver that AI-driven pen test, right?
The AI can do that cool reasoning.
But then you can layer on top of it heuristic tools and deterministic tools, like, you know,
checking for TLS ciphers, for example.
You don't need an agent to do that.
You could run an agent if you want to go really deep on pen testing.
like OpenSSL, for example.
But just to check whether a TLSCyfer or weak TLSCyfer is in use,
you can use testsessl.SH, just a tool that you can run
and you'll be able to get the output.
So using a combination of both the agent
and then those deterministic tools as well
gives you a pretty decent coverage of standard methodologies.
So that's where that question of like,
how are you ensuring coverage of my application is really important too?
That's Andy Horngold from Intruder.
And finally, an elite private school called Alpha School is betting that the future of education looks a little like a self-driving car.
Feed an AI enough examples of wrong turns, unexpected obstacles and student misconceptions, and eventually it learns to navigate.
At Alpha, students spend about two hours each morning.
with adaptive AI tutors,
followed by workshops in coding,
entrepreneurship, and other life skills.
The private school company,
where tuition can reach $75,000 a year,
plans to expand to roughly 50 U.S. campuses this fall.
There's evidence behind parts of the concept.
Research has found adaptive AI tutoring
can improve learning,
including a Harvard study
where students using an AI tutor
achieved more than twice the median learning gains of students using classroom active learning strategies.
But researchers caution that effective tutoring isn't necessarily effective schooling.
Critics worry about replacing trained teachers, weakening teacher-student relationships,
and producing knowledge that works inside the software but doesn't travel well outside it.
The AI tutor may know the route, whether it should drive the whole school bus, remains
another question.
And that's the Cyberwire.
For links to all of today's stories,
check out our daily briefing at thecyberwire.com.
We'd love to know what you think of this podcast.
Your feedback ensures we deliver the insights
that keep you a step ahead
in the rapidly changing world of cybersecurity.
If you like our show,
please share a rating and review
in your favorite podcast app.
Please also fill out the survey in the show notes
or send an email to Cyberwire at n2K.com.
N2K's lead producer is Liz Stokes.
We're mixed by Trey Hester
with original music and sound design
by Elliot Peltzman.
Our contributing host is Maria Vermazis.
Our executive producer is Jennifer Ibin.
Peter Kilby is our publisher.
And I'm Dave Bittner.
Thanks for listening.
We'll see you back here tomorrow.
